Barretenberg
The ZK-SNARK library at the core of Aztec
Loading...
Searching...
No Matches
recursive_verifier_instance.hpp
Go to the documentation of this file.
1// === AUDIT STATUS ===
2// internal: { status: not started, auditors: [], date: YYYY-MM-DD }
3// external_1: { status: not started, auditors: [], date: YYYY-MM-DD }
4// external_2: { status: not started, auditors: [], date: YYYY-MM-DD }
5// =====================
6
7#pragma once
12
14
18template <IsRecursiveFlavor Flavor_> class RecursiveVerifierInstance_ {
19 public:
20 using Flavor = Flavor_;
21 using FF = typename Flavor::FF;
22 using NativeFF = typename Flavor::Curve::ScalarFieldNative;
25 using VKAndHash = typename Flavor::VKAndHash;
30 using NativeFlavor = typename Flavor::NativeFlavor;
33 using VerifierCommitmentKey = typename NativeFlavor::VerifierCommitmentKey;
35
37
38 std::shared_ptr<VKAndHash> vk_and_hash;
39
40 bool is_complete = false; // whether this instance has been completely populated
41 std::vector<FF> public_inputs; // to be extracted from the corresponding proof
42
43 // An array {1, α₁, …, αₖ}, where k = NUM_SUBRELATIONS - 1.
46 std::vector<FF> gate_challenges;
47 // The target sum, which is typically nonzero for a ProtogalaxyProver's accmumulator
49
52
55
56 // Constructor from native vk
62
63 // Constructor from stdlib vk and hash
67
72 std::shared_ptr<VerificationKey> get_vk() const { return vk_and_hash->vk; }
73
74 // Constructor from native verifier instance
76 : RecursiveVerifierInstance_(builder, verification_key->vk)
77 {
78 is_complete = verification_key->is_complete;
79 if (is_complete) {
80 for (size_t alpha_idx = 0; alpha_idx < Flavor::NUM_SUBRELATIONS - 1; alpha_idx++) {
81 alphas[alpha_idx] = FF::from_witness(builder, verification_key->alphas[alpha_idx]);
82 }
83
84 auto other_comms = verification_key->witness_commitments.get_all();
85 size_t comm_idx = 0;
86 for (auto& comm : witness_commitments.get_all()) {
87 comm = Commitment::from_witness(builder, other_comms[comm_idx]);
88 comm_idx++;
89 }
90 target_sum = FF::from_witness(builder, verification_key->target_sum);
91 size_t challenge_idx = 0;
92 gate_challenges = std::vector<FF>(verification_key->gate_challenges.size());
93 for (auto& challenge : gate_challenges) {
94 challenge = FF::from_witness(builder, verification_key->gate_challenges[challenge_idx]);
95 challenge_idx++;
96 }
97 relation_parameters.eta = FF::from_witness(builder, verification_key->relation_parameters.eta);
98 relation_parameters.eta_two = FF::from_witness(builder, verification_key->relation_parameters.eta_two);
99 relation_parameters.eta_three = FF::from_witness(builder, verification_key->relation_parameters.eta_three);
100 relation_parameters.beta = FF::from_witness(builder, verification_key->relation_parameters.beta);
101 relation_parameters.gamma = FF::from_witness(builder, verification_key->relation_parameters.gamma);
103 FF::from_witness(builder, verification_key->relation_parameters.public_input_delta);
104 }
105 }
106
115 {
117 auto native_honk_vk = std::make_shared<NativeVerificationKey>();
118 native_honk_vk->log_circuit_size = static_cast<uint64_t>(vk_and_hash->vk->log_circuit_size.get_value());
119 native_honk_vk->num_public_inputs = static_cast<uint64_t>(vk_and_hash->vk->num_public_inputs.get_value());
120 native_honk_vk->pub_inputs_offset = static_cast<uint64_t>(vk_and_hash->vk->pub_inputs_offset.get_value());
121
122 for (auto [vk, final_verifier_inst] : zip_view(vk_and_hash->vk->get_all(), native_honk_vk->get_all())) {
123 final_verifier_inst = vk.get_value();
124 }
125
126 NativeVerifierInstance verifier_inst(native_honk_vk);
127 verifier_inst.is_complete = is_complete;
128
129 for (auto [alpha, inst_alpha] : zip_view(alphas, verifier_inst.alphas)) {
130 inst_alpha = alpha.get_value();
131 }
132
133 for (auto [comm, inst_comm] :
134 zip_view(witness_commitments.get_all(), verifier_inst.witness_commitments.get_all())) {
135 inst_comm = comm.get_value();
136 }
137 verifier_inst.target_sum = target_sum.get_value();
138
140 for (auto [challenge, inst_challenge] : zip_view(gate_challenges, verifier_inst.gate_challenges)) {
141 inst_challenge = challenge.get_value();
142 }
143
144 verifier_inst.relation_parameters.eta = relation_parameters.eta.get_value();
145 verifier_inst.relation_parameters.eta_two = relation_parameters.eta_two.get_value();
147 verifier_inst.relation_parameters.beta = relation_parameters.beta.get_value();
148 verifier_inst.relation_parameters.gamma = relation_parameters.gamma.get_value();
150 return verifier_inst;
151 }
152
153 FF hash_through_transcript(const std::string& domain_separator, Transcript& transcript) const
154 {
155 BB_ASSERT_EQ(is_complete, true, "Trying to hash a recursive verifier instance that has not been completed.");
156 transcript.add_to_independent_hash_buffer(domain_separator + "verifier_inst_log_circuit_size",
157 this->vk_and_hash->vk->log_circuit_size);
158 transcript.add_to_independent_hash_buffer(domain_separator + "verifier_inst_num_public_inputs",
159 this->vk_and_hash->vk->num_public_inputs);
160 transcript.add_to_independent_hash_buffer(domain_separator + "verifier_inst_pub_inputs_offset",
161 this->vk_and_hash->vk->pub_inputs_offset);
162
163 for (const Commitment& commitment : this->vk_and_hash->vk->get_all()) {
164 transcript.add_to_independent_hash_buffer(domain_separator + "verifier_inst_precomputed_comm", commitment);
165 }
166 for (const Commitment& comm : witness_commitments.get_all()) {
167 transcript.add_to_independent_hash_buffer(domain_separator + "verifier_inst_wit_comm", comm);
168 }
169 transcript.add_to_independent_hash_buffer(domain_separator + "verifier_inst_alphas", this->alphas);
170 transcript.add_to_independent_hash_buffer(domain_separator + "verifier_inst_eta",
171 this->relation_parameters.eta);
172 transcript.add_to_independent_hash_buffer(domain_separator + "verifier_inst_eta_two",
173 this->relation_parameters.eta_two);
174 transcript.add_to_independent_hash_buffer(domain_separator + "verifier_inst_eta_three",
175 this->relation_parameters.eta_three);
176 transcript.add_to_independent_hash_buffer(domain_separator + "verifier_inst_beta",
177 this->relation_parameters.beta);
178 transcript.add_to_independent_hash_buffer(domain_separator + "verifier_inst_gamma",
179 this->relation_parameters.gamma);
180 transcript.add_to_independent_hash_buffer(domain_separator + "verifier_inst_public_input_delta",
181 this->relation_parameters.public_input_delta);
182 transcript.add_to_independent_hash_buffer(domain_separator + "verifier_inst_target_sum", this->target_sum);
183 transcript.add_to_independent_hash_buffer(domain_separator + "verifier_inst_gate_challenges",
184 this->gate_challenges);
185
186 return transcript.hash_independent_buffer();
187 }
188};
189} // namespace bb::stdlib::recursion::honk
#define BB_ASSERT_EQ(actual, expected,...)
Definition assert.hpp:88
void add_to_independent_hash_buffer(const std::string &label, const T &element)
Adds an element to an independent hash buffer.
DataType hash_independent_buffer()
Hashes the independent hash buffer and clears it.
A container for commitment labels.
The verification key is responsible for storing the commitments to the precomputed (non-witness) poly...
WitnessEntities< Commitment > WitnessCommitments
A container for the witness commitments.
Curve::ScalarField FF
std::array< FF, NUM_SUBRELATIONS - 1 > SubrelationSeparators
static constexpr size_t NUM_SUBRELATIONS
NativeTranscript Transcript
MegaCircuitBuilder CircuitBuilder
Curve::AffineElement Commitment
The VerifierInstance encapsulates all the necessary information for a Mega Honk Verifier to verify a ...
std::vector< FF > gate_challenges
WitnessCommitments witness_commitments
SubrelationSeparators alphas
RelationParameters< FF > relation_parameters
The stdlib counterpart of VerifierInstance, used in recursive folding verification.
RecursiveVerifierInstance_(Builder *builder, std::shared_ptr< VKAndHash > vk_and_hash)
RecursiveVerifierInstance_(Builder *builder, std::shared_ptr< NativeVerifierInstance > verification_key)
typename NativeFlavor::VerifierCommitmentKey VerifierCommitmentKey
typename Flavor::NativeFlavor::VerificationKey NativeVerificationKey
RecursiveVerifierInstance_(Builder *builder, std::shared_ptr< NativeVerificationKey > vk)
FF hash_through_transcript(const std::string &domain_separator, Transcript &transcript) const
NativeVerifierInstance get_value()
Return the underlying native VerifierInstance.
std::shared_ptr< VerificationKey > get_vk() const
Get the verification key.
Base class templates for structures that contain data parameterized by the fundamental polynomials of...
void hash(State &state) noexcept
VerifierCommitmentKey< Curve > vk
STL namespace.
constexpr decltype(auto) get(::tuplet::tuple< T... > &&t) noexcept
Definition tuple.hpp:13
Container for parameters used by the grand product (permutation, lookup) Honk relations.