Files
magnetar/scripts/check-high-assurance.sh
Hanzo AI 0f6ac37cfc magnetar v1.1: high-assurance orchestrator + BLOCKERS + CHANGELOG + README
scripts/check-high-assurance.sh: updated v1.0 -> v1.1 framing.
Orchestrator now drives four per-push gates:

  - scripts/checks/go-tests.sh (unchanged from v1.0).
  - scripts/checks/strict-atom-ast.sh (NEW): runs the v1.1 audit grep
    verbatim + the Go AST gate TestThbsSE_StrictAtom_NoTransientSeed.
  - scripts/checks/easycrypt-smoke.sh (NEW): theory-shell presence +
    structural smoke check; full EC type-check at release time only.
  - scripts/checks/dudect-smoke.sh (NEW): drives the Go-side CT static
    check via `go test -tags ct ./ct/dudect/...`.

BLOCKERS.md: close MAGNETAR-STRICT-ATOM-V11 + MAGNETAR-PROOF-TRACK-V11
+ MAGNETAR-DUDECT-V11 at v1.1. Honest residual gap documented
(transient SHAKE-absorb bytes; closing requires either full MPC or a
TEE in the TCB --- both out of scope for the permissionless Magnetar
surface). MAGNETAR-PVSS-DKG-V11 + MAGNETAR-EXTERNAL-AUDIT-V11 remain
open at v1.1 (PVSS-DKG and external audit).

CHANGELOG.md: [1.1.0] release notes. Headline: strict-atom Combine,
wire-format-stable refactor (v1.0.0 consumers bump transparently),
strict-atom discipline statement (audit grep returns zero),
byte-identity to circl FIPS 205 (pinned per SHAKE mode), proof track
restoration (5 substantive admits), dudect harness restoration,
benchmark numbers (strict-atom is 8-51% FASTER than v1.0-equivalent),
honest residual gap.

README.md: v1.0 -> v1.1 framing in the headline.
2026-06-01 17:13:53 -07:00

60 lines
1.9 KiB
Bash
Executable File

#!/usr/bin/env bash
# Magnetar high-assurance gate --- orchestrator (per-push).
#
# At v1.1.0 Magnetar's high-assurance scope is:
#
# - Single-party SLH-DSA via cloudflare/circl/sign/slhdsa v1.6.3.
# CT posture inherits CIRCL for the per-validator standalone path.
# See ct/README.md.
# - THBS-SE share arithmetic over GF(257). Straight-line modular
# arithmetic with constant-time intent (no secret-dependent
# branches). See thbsse_field.go.
# - THBS-SE strict-atom Combine path: Magnetar-internal FIPS 205
# sec 5/6/7/8 walk over a positional SHAKE-expansion buffer with
# no named transient seed binder. See thbsse_assemble.go +
# slhdsa_internal.go.
# - dudect harness on the strict-atom path (ct/dudect/).
# - EasyCrypt theory shells covering the strict-atom byte-equality
# theorem (proofs/easycrypt/Magnetar_N1_StrictAtom.ec) + the FIPS
# 205 SHAKE expansion + the Magnetar-internal refinement to circl.
#
# Any per-check failure (exit 2) fails the orchestrator with the
# same code. Per-check skips (exit 0 with a [skip] message) do not
# fail the gate.
set -euo pipefail
REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
cd "$REPO_ROOT"
CHECKS=(
"scripts/checks/go-tests.sh"
"scripts/checks/strict-atom-ast.sh"
"scripts/checks/easycrypt-smoke.sh"
"scripts/checks/dudect-smoke.sh"
)
echo "==> Magnetar high-assurance track (v1.1.0 scope)"
echo " construction: per-validator standalone + THBS-SE strict-atom"
echo " proof track : EasyCrypt + Lean bridge (strict-atom byte-equality)"
echo " CT track : dudect on strict-atom Combine path"
echo
OVERALL=0
for check in "${CHECKS[@]}"; do
rc=0
bash "$REPO_ROOT/$check" || rc=$?
if [[ $rc -ne 0 ]]; then
OVERALL=$rc
echo
echo "==> $check exited rc=$rc --- aborting gate"
break
fi
echo
done
if [[ $OVERALL -eq 0 ]]; then
echo "==> done --- high-assurance gate green"
fi
exit $OVERALL