Correctness of the circuit.
The equivalence between predicate and specification is proved automatically via the prime fields library rules.
The extension to the circuit is boilerplate.
Theorem:
(defthm field-sub-pred-to-spec (implies (and (primep prime) (pfield::fep x prime) (pfield::fep y prime) (pfield::fep z prime)) (equal (field-sub-pred x y z prime) (field-sub-spec x y z prime))))
Theorem:
(defthm field-sub-circuit-to-spec (implies (and (equal (pfcs::lookup-definition (pfname "field_sub") defs) (field-sub-circuit)) (primep prime) (pfield::fep x prime) (pfield::fep y prime) (pfield::fep z prime)) (equal (pfcs::definition-satp (pfname "field_sub") defs (list x y z) prime) (field-sub-spec x y z prime))))