Skip to main content

verify_mlecheck_basefold

Function verify_mlecheck_basefold 

Source
pub fn verify_mlecheck_basefold<F, Channel>(
    fri_params: &FRIParams<F>,
    codeword_commitments: &[Channel::Commitment],
    eval_claim: Channel::Elem,
    eval_point: &[Channel::Elem],
    batch_challenge: Option<Channel::Elem>,
    outer_challenges: &[Channel::Elem],
    channel: &mut Channel,
) -> Result<(), Error>
where F: BinaryField, Channel: MerkleIPVerifierChannel<F>, Channel::Elem: From<F>,
Expand description

Verifies a combined multilinear-evaluation BaseFold opening: a single degree-1 MLE-check interleaved with a single FRI over the piecewise-concatenated oracle of the Batched ZK BaseFold construction (whitepaper §7.2 / §sec:batched-basefold Step 2).

This is the verifier counterpart of binius_iop_prover::basefold::prove_mlecheck_basefold. A prior batched sumcheck has reduced the k masked opening claims to per-oracle point-evaluation claims π_i'(ρ_i) = α_i at a shared point r ∈ K^𝐧 (𝐧 = max_i n_i). The oracle-index variables are then collapsed up front at sampled batching challenges r' into a single combined multilinear 𝛑(X) = Σ_i e[i] · π_i^↑(X), e the indicator expanded at r', with target s' = 𝛑(r); this routine checks 𝛑(r) = s' against the k committed codewords via one combined FRI.

§Arguments

  • codeword_commitments - one per oracle, in the same order as FRIParams::input_oracles, as commitment handles previously received over channel (via MerkleIPVerifierChannel::recv_merkle_commitment).
  • eval_claim - the combined target s'.
  • eval_point - the point r (length 𝐧 = fri_params.rs_code().log_dim()), low-to-high order.
  • batch_challenge - the masking challenge γ used in the FRI inner (unbatch) round.
  • outer_challenges - the batching challenges r' (length log_n_oracles) used in the FRI outer (oracle-combine) rounds.
  • channel - the Merkle channel carrying all prover interaction: round coefficients, challenges, commitments, and query openings.

The final consistency check is asserted internally, so Ok means the opening verified.

The MLE-check folds the equality-indicator factor into its round-proof recovery. So the final reduced value is the plain multilinear evaluation of the combined oracle at r. On an honest opening that value equals the final FRI value. This routine asserts their equality and rejects on any mismatch.