Skip to content

Argon2 on x86-64: prove complete segment setup and filling - #509

Closed
reaperhulk wants to merge 1 commit into
argon2-fill-segmentfrom
argon2-segment-setup
Closed

reaperhulk wants to merge 1 commit into
argon2-fill-segmentfrom
argon2-segment-setup

Conversation

@reaperhulk

Copy link
Copy Markdown
Member

Fill a complete segment from its public pass, slice and lane. Reset its independent-address cache counter to zero; begin at index two only for slice zero of pass zero, preserving the initialized cells. Check the index before entering the active loop so the minimum-memory first segment can have an empty suffix.

Prove the matrix equals the reviewed fold over the entire segment, including its skipped initialized prefix. Retain the allocation, public parameters, final position, cache validity, memory frame, permissions and MXCSR. Prove the complete setup and loop trace depends only on public parameters and the specified reference log, including reset and empty-suffix handling. An index-independent context also carries the final position into the enclosing loops.

Builds on #506. Inline implementation and proofs only; no specification, TCB, public API or generated assembly changes.

Validation: targeted Lean correctness and trace builds, standard-axiom and compiler-override audits, specification-origin audit, Lean import/proof-speed checks, and git diff --check. Full checks run in CI.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant