A proof should break when the program changes
How Auths Proof translates its production Rust authority kernel through Charon and Aeneas, refines it against a readable Lean specification, and makes semantic drift fail CI.
5 entries exploring this thread.
How Auths Proof translates its production Rust authority kernel through Charon and Aeneas, refines it against a readable Lean specification, and makes semantic drift fail CI.
A capsec diff of two published Rust crate versions shows why dependency review should include newly reachable filesystem, network, process, and FFI behavior.
How capsec makes filesystem and network authority visible in Rust types, what the compiler rejects, and where audit must take over.
Why auths-proof separates identity evidence, delegated authority, and application execution behind one offline verification contract.
How auths-proof turns layer direction, offline verification, deterministic CBOR, and protocol bounds into executable repository checks.