Claiming the SHA-512 family from #1, in separate PRs per `CLAUDE.md`: 1. TCB: x86-64 64-bit `ror`/`shr` by an immediate, `bswap r64`, and `mov r64, imm64` (`movabs`), on top of #4 2. Spec: `Spec/Sha512.lean` (FIPS 180-4) + the x86-64 contract of the compression function, on top of #4 3. x86-64 impl + proof + artifact + Rust API (`Sha384`, `Sha512`, `Sha512_224`, `Sha512_256`), reusing #6's proof framework Other architectures later, one PR each. Not claiming HMAC/PBKDF2 (#7/#8 are generic over the hash). If someone lands a piece first I'll build on it.
Claiming the SHA-512 family from #1, in separate PRs per
CLAUDE.md:ror/shrby an immediate,bswap r64, andmov r64, imm64(movabs), on top of TCB: x86-64 32-bit instructions (mov, store, ALU, ror/shr, bswap) and Region.Disjoint #4Spec/Sha512.lean(FIPS 180-4) + the x86-64 contract of the compression function, on top of TCB: x86-64 32-bit instructions (mov, store, ALU, ror/shr, bswap) and Region.Disjoint #4Sha384,Sha512,Sha512_224,Sha512_256), reusing SHA-256 on x86-64: verified compression function and the Sha256 API #6's proof frameworkOther architectures later, one PR each. Not claiming HMAC/PBKDF2 (#7/#8 are generic over the hash). If someone lands a piece first I'll build on it.