Files
magnetar/scripts/checks/strict-atom-ast.sh
T
Antje Worring df4c537c16 magnetar: remove proof-by-rename + circular proofs; honest threshold status
True no-reconstruction threshold SLH-DSA is impossible in the no-dealer /
no-preprocessing model a public, leaderless, permissionless chain needs
(Kondi-Kumar-Vanegas: extractable hash-based signatures cannot be thresholded
by black-box hash use). Stop pretending otherwise.

De-cheat:
  - DELETE the circular/vacuous proofs that manufactured false assurance:
    Magnetar_N1_Atom_Refinement.ec, Magnetar_N1_SHAKE_Expand.ec,
    Magnetar_N4_KeyDeriveStable.ec, lemmas/{Magnetar_CT,SLHDSA_Functional}.ec.
    The headline "strict-atom byte-equality" theorem was `apply <axiom that
    restates the theorem>`; the Lean side was `sorry`/`:= True`.
  - Re-open MAGNETAR-STRICT-ATOM (BLOCKERS): the public combiner DOES
    reconstruct the full FIPS 205 master every signature; the v1.1 "closure"
    only renamed identifiers. PROOF-CLAIMS / AXIOM-INVENTORY / TCB docs now say
    what the code does.
  - Re-label the name-grep "strict-atom" / "CT" checks as identifier-hygiene
    lint, NOT security or constant-time properties.
  - PVSS-DKG open-reveal (publishes the master to any observer) is gated as a
    TEST-ONLY path with HONEST LIMITATIONS; production does not rely on it.
  - Remove dead htRootCompute; staticcheck clean.

Honest three-leg posture (SPEC 1.0, BLOCKERS):
  - Permissionless production = INDEPENDENT FIPS 205 sigs + the weighted quorum
    certificate (luxfi/consensus), optionally STARK/FRI-compressed (luxfi/p3q).
    No key sharing, no reconstruction.
  - Trusted-hardware custody = TEE-attested combiner (trust-relocation, NOT MPC).
  - THBS-SE = RESEARCH-ONLY (transient seed reconstruction at the combiner);
    the T-SLH-DSA-MPC track (MPC over SHAKE) is the other research escape hatch.

Tests green (CGO=1, 71s). Net -923 lines.
2026-06-21 13:06:57 -07:00

57 lines
2.1 KiB
Bash
Executable File

#!/usr/bin/env bash
# strict-atom-ast.sh --- identifier-hygiene LINT (NOT a security gate).
#
# This runs a NAME lint over the Combine emit path
# (ref/go/pkg/magnetar/thbsse_assemble.go): it asserts the source does
# not SPELL a variable `seed`/`skSeed`/`skPrf`/... . It does NOT show
# the FIPS 205 master is absent from memory --- assembleSignatureBytes
# reconstructs the master into `derivedMaterial` regardless of variable
# naming (see ASSEMBLE-INVARIANT.md and
# BLOCKERS.md::MAGNETAR-STRICT-ATOM-V11). Passing this lint is a style
# check, not a no-leak proof.
#
# It runs the Go-side lint (TestThbsSE_AssembleIdentHygiene) which:
#
# 1. Parses thbsse_assemble.go as Go AST.
# 2. Walks every identifier node and asserts none matches the named
# set {seed, skSeed, skPrf, SkSeed, SkPrf, PrfKey, prfKey,
# sk_seed, sk_prf}.
# 3. Scans the comment-stripped file bytes for the name-pattern grep
# (`SK\.seed|SK\.prf|sk_seed|sk_prf`).
set -euo pipefail
REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
cd "$REPO_ROOT"
ASSEMBLE_PATH="ref/go/pkg/magnetar/thbsse_assemble.go"
echo "==> strict-atom-ast: identifier-hygiene NAME lint (NOT a security gate)"
if [[ ! -f "$ASSEMBLE_PATH" ]]; then
echo " [error] $ASSEMBLE_PATH not found"
exit 2
fi
# Step 1: raw name-pattern grep.
echo " [step 1] grep -rE \"SK\\.seed|SK\\.prf|sk_seed|sk_prf\" $ASSEMBLE_PATH"
if grep -rE "SK\.seed|SK\.prf|sk_seed|sk_prf" "$ASSEMBLE_PATH"; then
echo " [fail] ident-hygiene lint: $ASSEMBLE_PATH contains a flagged name pattern"
exit 2
fi
echo " [ok] no flagged name patterns in $ASSEMBLE_PATH"
# Step 2: Go lint that wraps both the AST walk and the comment-
# stripped grep.
echo " [step 2] go test -count=1 -run TestThbsSE_AssembleIdentHygiene"
cd ref/go
if ! go test -count=1 -run TestThbsSE_AssembleIdentHygiene ./pkg/magnetar/...; then
echo " [fail] TestThbsSE_AssembleIdentHygiene failed"
exit 2
fi
echo " [ok] TestThbsSE_AssembleIdentHygiene PASS"
cd "$REPO_ROOT"
echo "==> strict-atom-ast: NAME LINT GREEN (style only; not a no-leak proof)"
exit 0