49 const AllEntities& in,
51 const FF& scaling_factor)
54 using View =
typename Accumulator::View;
56 const auto& x1 = View(in.msm_x1);
57 const auto& y1 = View(in.msm_y1);
58 const auto& x2 = View(in.msm_x2);
59 const auto& y2 = View(in.msm_y2);
60 const auto& x3 = View(in.msm_x3);
61 const auto& y3 = View(in.msm_y3);
62 const auto& x4 = View(in.msm_x4);
63 const auto& y4 = View(in.msm_y4);
64 const auto& collision_inverse1 = View(in.msm_collision_x1);
65 const auto& collision_inverse2 = View(in.msm_collision_x2);
66 const auto& collision_inverse3 = View(in.msm_collision_x3);
67 const auto& collision_inverse4 = View(in.msm_collision_x4);
68 const auto& lambda1 = View(in.msm_lambda1);
69 const auto& lambda2 = View(in.msm_lambda2);
70 const auto& lambda3 = View(in.msm_lambda3);
71 const auto& lambda4 = View(in.msm_lambda4);
72 const auto& lagrange_first = View(in.lagrange_first);
73 const auto& add1 = View(in.msm_add1);
74 const auto& add1_shift = View(in.msm_add1_shift);
75 const auto& add2 = View(in.msm_add2);
76 const auto& add3 = View(in.msm_add3);
77 const auto& add4 = View(in.msm_add4);
78 const auto& acc_x = View(in.msm_accumulator_x);
79 const auto& acc_y = View(in.msm_accumulator_y);
80 const auto& acc_x_shift = View(in.msm_accumulator_x_shift);
81 const auto& acc_y_shift = View(in.msm_accumulator_y_shift);
82 const auto& slice1 = View(in.msm_slice1);
83 const auto& slice2 = View(in.msm_slice2);
84 const auto& slice3 = View(in.msm_slice3);
85 const auto& slice4 = View(in.msm_slice4);
86 const auto& msm_transition = View(in.msm_transition);
87 const auto& msm_transition_shift = View(in.msm_transition_shift);
88 const auto& round = View(in.msm_round);
89 const auto& round_shift = View(in.msm_round_shift);
90 const auto& q_add = View(in.msm_add);
91 const auto& q_add_shift = View(in.msm_add_shift);
92 const auto& q_skew = View(in.msm_skew);
93 const auto& q_skew_shift = View(in.msm_skew_shift);
94 const auto& q_double = View(in.msm_double);
95 const auto& q_double_shift = View(in.msm_double_shift);
96 const auto& msm_size = View(in.msm_size_of_msm);
97 const auto& pc = View(in.msm_pc);
98 const auto& pc_shift = View(in.msm_pc_shift);
99 const auto& count = View(in.msm_count);
100 const auto& count_shift = View(in.msm_count_shift);
101 auto is_not_first_row = (-lagrange_first + 1);
267 auto add = [&](
auto& xb,
274 auto& collision_relation) {
278 relation += selector * (lambda * (xb - xa - 1) - (yb - ya)) + lambda;
279 collision_relation += selector * (xb - xa);
283 auto x_out = lambda.sqr() + (-xb - xa - xa) * selector + xa;
287 auto y_out = lambda * (xa - x_out) + (-ya - ya) * selector + ya;
305 auto first_add = [&](
auto& xb,
312 auto& collision_relation) {
315 constexpr uint256_t oxu = offset_generator.x;
316 constexpr uint256_t oyu = offset_generator.y;
317 const Accumulator xo(oxu);
318 const Accumulator yo(oyu);
320 auto x = xo * selector + xb * (-selector + 1);
321 auto y = yo * selector + yb * (-selector + 1);
322 relation += lambda * (x - xa) - (y - ya);
323 collision_relation += (xa - x);
324 auto x_out = lambda * lambda + (-x - xa);
325 auto y_out = lambda * (xa - x_out) - ya;
330 Accumulator add_relation(0);
331 Accumulator x1_collision_relation(0);
332 Accumulator x2_collision_relation(0);
333 Accumulator x3_collision_relation(0);
334 Accumulator x4_collision_relation(0);
338 first_add(acc_x, acc_y, x1, y1, lambda1, msm_transition, add_relation, x1_collision_relation);
339 auto [x_t2, y_t2] = add(x2, y2, x_t1, y_t1, lambda2, add2, add_relation, x2_collision_relation);
340 auto [x_t3, y_t3] = add(x3, y3, x_t2, y_t2, lambda3, add3, add_relation, x3_collision_relation);
341 auto [x_t4, y_t4] = add(x4, y4, x_t3, y_t3, lambda4, add4, add_relation, x4_collision_relation);
344 std::get<0>(accumulator) += q_add * (acc_x_shift - x_t4) * scaling_factor;
345 std::get<1>(accumulator) += q_add * (acc_y_shift - y_t4) * scaling_factor;
346 std::get<2>(accumulator) += q_add * add_relation * scaling_factor;
355 auto dbl = [&](
auto& x,
auto& y,
auto& lambda,
auto& relation) {
357 relation += lambda * (y + y) - (two_x + x) * x;
358 auto x_out = lambda.sqr() - two_x;
359 auto y_out = lambda * (x - x_out) - y;
378 Accumulator double_relation(0);
379 auto [x_d1, y_d1] = dbl(acc_x, acc_y, lambda1, double_relation);
380 auto [x_d2, y_d2] = dbl(x_d1, y_d1, lambda2, double_relation);
381 auto [x_d3, y_d3] = dbl(x_d2, y_d2, lambda3, double_relation);
382 auto [x_d4, y_d4] = dbl(x_d3, y_d3, lambda4, double_relation);
383 std::get<10>(accumulator) += q_double * (acc_x_shift - x_d4) * scaling_factor;
384 std::get<11>(accumulator) += q_double * (acc_y_shift - y_d4) * scaling_factor;
385 std::get<12>(accumulator) += q_double * double_relation * scaling_factor;
400 Accumulator skew_relation(0);
402 auto skew1_select = slice1 * inverse_seven;
403 auto skew2_select = slice2 * inverse_seven;
404 auto skew3_select = slice3 * inverse_seven;
405 auto skew4_select = slice4 * inverse_seven;
406 Accumulator x1_skew_collision_relation(0);
407 Accumulator x2_skew_collision_relation(0);
408 Accumulator x3_skew_collision_relation(0);
409 Accumulator x4_skew_collision_relation(0);
415 auto [x_s1, y_s1] = add(x1, y1, acc_x, acc_y, lambda1, skew1_select, skew_relation, x1_skew_collision_relation);
416 auto [x_s2, y_s2] = add(x2, y2, x_s1, y_s1, lambda2, skew2_select, skew_relation, x2_skew_collision_relation);
417 auto [x_s3, y_s3] = add(x3, y3, x_s2, y_s2, lambda3, skew3_select, skew_relation, x3_skew_collision_relation);
418 auto [x_s4, y_s4] = add(x4, y4, x_s3, y_s3, lambda4, skew4_select, skew_relation, x4_skew_collision_relation);
421 std::get<3>(accumulator) += q_skew * (acc_x_shift - x_s4) * scaling_factor;
422 std::get<4>(accumulator) += q_skew * (acc_y_shift - y_s4) * scaling_factor;
423 std::get<5>(accumulator) += q_skew * skew_relation * scaling_factor;
428 const auto add_first_point = add1 * q_add + q_skew * skew1_select;
429 const auto add_second_point = add2 * q_add + q_skew * skew2_select;
430 const auto add_third_point = add3 * q_add + q_skew * skew3_select;
431 const auto add_fourth_point = add4 * q_add + q_skew * skew4_select;
434 const auto x1_delta = x1_skew_collision_relation * q_skew + x1_collision_relation * q_add;
435 const auto x2_delta = x2_skew_collision_relation * q_skew + x2_collision_relation * q_add;
436 const auto x3_delta = x3_skew_collision_relation * q_skew + x3_collision_relation * q_add;
437 const auto x4_delta = x4_skew_collision_relation * q_skew + x4_collision_relation * q_add;
439 std::get<6>(accumulator) += (x1_delta * collision_inverse1 - add_first_point) * scaling_factor;
440 std::get<7>(accumulator) += (x2_delta * collision_inverse2 - add_second_point) * scaling_factor;
441 std::get<8>(accumulator) += (x3_delta * collision_inverse3 - add_third_point) * scaling_factor;
442 std::get<9>(accumulator) += (x4_delta * collision_inverse4 - add_fourth_point) * scaling_factor;
445 std::get<13>(accumulator) += (-add1 + 1) * slice1 * scaling_factor;
446 std::get<14>(accumulator) += (-add2 + 1) * slice2 * scaling_factor;
447 std::get<15>(accumulator) += (-add3 + 1) * slice3 * scaling_factor;
448 std::get<16>(accumulator) += (-add4 + 1) * slice4 * scaling_factor;
453 std::get<17>(accumulator) += (q_add * q_double + q_add * q_skew + q_double * q_skew) * scaling_factor;
457 std::get<32>(accumulator) += (add1 - q_add - q_skew) * scaling_factor;
463 const auto round_delta = round_shift - round;
472 const auto round_transition = round_delta * (-msm_transition_shift + 1);
473 std::get<18>(accumulator) += round_transition * (round_delta - 1) * scaling_factor;
488 std::get<19>(accumulator) += round_transition * q_skew_shift * (round - 31) * scaling_factor;
489 std::get<20>(accumulator) += round_transition * (q_skew_shift + q_double_shift - 1) * scaling_factor;
490 std::get<35>(accumulator) += (-round_delta + 1) * q_double_shift * scaling_factor;
493 std::get<21>(accumulator) += round_transition * (-q_double_shift + 1) * (-q_skew_shift + 1) * scaling_factor;
500 std::get<22>(accumulator) += q_double * (-q_add_shift + 1) * scaling_factor;
510 std::get<33>(accumulator) += (-msm_transition_shift + 1) * q_skew * (-q_skew_shift + 1) * scaling_factor;
513 std::get<34>(accumulator) += q_skew * (-round + 32) * scaling_factor;
519 std::get<23>(accumulator) += round_delta * count_shift * scaling_factor;
522 std::get<24>(accumulator) += (-msm_transition_shift + 1) * (-round_delta + 1) *
523 (count_shift - count - add1 - add2 - add3 - add4) * scaling_factor;
531 is_not_first_row * (-msm_transition_shift + 1) * round_delta * count_shift * scaling_factor;
534 std::get<26>(accumulator) += msm_transition * round * scaling_factor;
538 std::get<27>(accumulator) += is_not_first_row * msm_transition_shift * (msm_size + pc_shift - pc) * scaling_factor;
548 std::get<28>(accumulator) += add2 * (-add1 + 1) * scaling_factor;
549 std::get<29>(accumulator) += add3 * (-add2 + 1) * scaling_factor;
550 std::get<30>(accumulator) += add4 * (-add3 + 1) * scaling_factor;
560 (q_add * q_add_shift + q_skew * q_skew_shift) * (-add4 + 1) * add1_shift * scaling_factor;