Correctness of the circuit.
The equivalence between predicate and specification is proved automatically via the prime fields library rules.
The extension to the circuit is boilerplate.
Theorem:
(defthm field-add-pred-to-spec (implies (and (primep prime) (pfield::fep x prime) (pfield::fep y prime) (pfield::fep z prime)) (equal (field-add-pred x y z prime) (field-add-spec x y z prime))))
Theorem:
(defthm field-add-circuit-to-spec (implies (and (equal (pfcs::lookup-definition (pfname "field_add") defs) (field-add-circuit)) (primep prime) (pfield::fep x prime) (pfield::fep y prime) (pfield::fep z prime)) (equal (pfcs::definition-satp (pfname "field_add") defs (list x y z) prime) (field-add-spec x y z prime))))