Skip to main content

MergeVerifierChannel

Struct MergeVerifierChannel 

Source
pub struct MergeVerifierChannel<'a, F, C>
where F: Field, C: IOPVerifierChannel<F>,
{ /* private fields */ }
Expand description

A verifier channel decorator that merges one round’s oracles into one combined oracle.

§Overview

An interaction round is the run of oracle receipts between two challenge samples.

Committing each oracle separately costs one commitment per oracle. One Merkle tree per oracle, for example.

This decorator buffers a round’s oracles instead. It commits them together as one larger oracle. That cuts the cost to one commitment per round.

§Merging

A round’s oracles are sorted from largest to smallest. They are laid out end to end.

Every oracle’s size is a power of two. Write the sizes as 2^n_1, 2^n_2, ..., 2^n_k. Sort them so n_1 >= n_2 >= ... >= n_k.

The combined oracle’s size is 2^N. N is the smallest exponent that covers the total.

combined oracle, size 2^N:

    [ oracle 1 (2^n_1) | oracle 2 (2^n_2) | ... | oracle k (2^n_k) | unused padding ]
      offset 0           offset 2^n_1                                total size 2^N

Sorting largest to smallest makes this layout exact.

Every earlier oracle is at least as large as the current one. So their combined space is a whole multiple of the current oracle’s size. The current oracle therefore starts on a boundary of its own size. Its position is then a whole number of its-own-size blocks. That whole number is its block index.

A round of a single oracle needs no combining. It is forwarded unchanged, at zero cost.

A round is witness-dependent as soon as any of its oracles is.

A commitment is masked as a whole, never partly. So a structural oracle sharing a round with a witness-carrying one is masked too.

§Timing

A round’s oracles are committed the moment its last oracle arrives.

The OracleSchedule says where each round ends, so no challenge sample is needed to find the boundary. A real Fiat-Shamir transcript can therefore absorb the commitment before the next challenge.

§Opening

A constituent oracle’s claim is an inner product. It pairs the oracle’s data with a transparent polynomial.

That claim becomes a claim about the combined oracle too. Extend the transparent polynomial with an equality check. The check is one over the constituent’s own block, zero elsewhere.

extended transparent(x) = original transparent(low bits of x) * is_this_block(high bits of x)

The check is zero outside the constituent’s own block. So the combined inner product only ever sees this oracle’s own data. It equals the original claim exactly.

Implementations§

Source§

impl<'a, F, C> MergeVerifierChannel<'a, F, C>
where F: Field, C: IOPVerifierChannel<F>,

Source

pub fn new(inner: C, schedule: &'a OracleSchedule) -> Self

Creates a new merging verifier channel over an underlying channel.

§Arguments
  • inner — the channel every combined oracle is committed to, already configured with schedule.merged_specs().
  • schedule — every oracle this channel’s caller will pass through, grouped into rounds.
§Panics

Panics if inner is not configured with schedule.merged_specs().

Source

pub fn into_inner(self) -> C

Returns the underlying channel.

§Panics

Panics if any declared oracle has not yet been received.

Trait Implementations§

Source§

impl<'a, F, C> IOPVerifierChannel<F> for MergeVerifierChannel<'a, F, C>
where F: Field, C: IOPVerifierChannel<F>,

Source§

type Oracle = MergeOracle

Source§

fn remaining_oracle_specs(&self) -> &[OracleSpec]

Returns the specifications for the remaining oracles to be received. Read more
Source§

fn recv_oracle( &mut self, log_msg_len: usize, is_witness_dependent: bool, ) -> Result<Self::Oracle, Error>

Receives an oracle commitment from the prover. Read more
Source§

fn verify_oracle_relation( &mut self, oracle: Self::Oracle, transparent: TransparentEvalFn<Self::Elem>, claim: Self::Elem, ) -> Result<(), Error>

Queues one oracle linear relation to be opened. Read more
Source§

impl<F, C> IPVerifierChannel<F> for MergeVerifierChannel<'_, F, C>
where F: Field, C: IOPVerifierChannel<F>,

Source§

type Elem = <C as IPVerifierChannel<F>>::Elem

The element type returned by receive and sample methods.
Source§

fn recv_one(&mut self) -> Result<Self::Elem, Error>

Receives a single field element from the prover.
Source§

fn recv_many(&mut self, n: usize) -> Result<Vec<Self::Elem>, Error>

Receives n field elements from the prover.
Source§

fn recv_array<const N: usize>(&mut self) -> Result<[Self::Elem; N], Error>

Receives a fixed-size array of field elements from the prover.
Source§

fn recv_public_claim(&mut self) -> Result<Self::Elem, Error>

Receives a value the verifier could compute for itself, taken as advice. Read more
Source§

fn sample(&mut self) -> Self::Elem

Samples a random challenge. Read more
Source§

fn observe_one(&mut self, val: F) -> Self::Elem

Observes a single field element, feeding it into the Fiat-Shamir state. Read more
Source§

fn observe_many(&mut self, vals: &[F]) -> Vec<Self::Elem>

Observes multiple field elements, feeding them into the Fiat-Shamir state. Read more
Source§

fn assert_zero(&mut self, val: Self::Elem) -> Result<(), Error>

Asserts that a value is zero. Read more
Source§

fn sample_many(&mut self, n: usize) -> Vec<Self::Elem>

Samples n random challenges.
Source§

fn sample_array<const N: usize>(&mut self) -> [Self::Elem; N]

Samples a fixed-size array of random challenges.
Source§

impl<F, C> WordIPVerifierChannel<F> for MergeVerifierChannel<'_, F, C>

Source§

type Word = <C as WordIPVerifierChannel<F>>::Word

The word type this channel carries. Read more
Source§

fn observe_words(&mut self, words: &[Word]) -> Vec<Self::Word>

Feeds words into the Fiat-Shamir state, each as eight little-endian bytes, and returns them as this channel’s word type. Read more
Source§

fn subset_sum(&mut self, elems: &[Self::Elem], word: &Self::Word) -> Self::Elem

Returns the sum of the elems selected by the low bits of word, low bit first. Read more
Source§

fn select(&mut self, elems: &[Self::Elem], word: &Self::Word) -> Self::Elem

Returns the element of elems at the index in the low bits of word. Read more
Source§

fn sample_bits(&mut self, bits: usize) -> Self::Word

Samples a uniform word of the given bit width. Read more
Source§

fn pack_words(&mut self, words: &[Self::Word]) -> Vec<Self::Elem>

Packs words into field elements, as many words to an element as one holds. Read more

Auto Trait Implementations§

§

impl<'a, F, C> Freeze for MergeVerifierChannel<'a, F, C>
where C: Freeze,

§

impl<'a, F, C> RefUnwindSafe for MergeVerifierChannel<'a, F, C>

§

impl<'a, F, C> Send for MergeVerifierChannel<'a, F, C>
where C: Send, <C as IOPVerifierChannel<F>>::Oracle: Send,

§

impl<'a, F, C> Sync for MergeVerifierChannel<'a, F, C>
where C: Sync, <C as IOPVerifierChannel<F>>::Oracle: Sync,

§

impl<'a, F, C> Unpin for MergeVerifierChannel<'a, F, C>
where C: Unpin, <C as IOPVerifierChannel<F>>::Oracle: Unpin,

§

impl<'a, F, C> UnsafeUnpin for MergeVerifierChannel<'a, F, C>
where C: UnsafeUnpin,

§

impl<'a, F, C> UnwindSafe for MergeVerifierChannel<'a, F, C>

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
§

impl<T> Pointable for T

§

const ALIGN: usize

The alignment of pointer.
§

type Init = T

The type for initializers.
§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more