Skip to main content

IOPVerifierChannel

Trait IOPVerifierChannel 

Source
pub trait IOPVerifierChannel<F: Field>: IPVerifierChannel<F, Elem: 'static> {
    type Oracle: Clone;

    // Required methods
    fn remaining_oracle_specs(&self) -> &[OracleSpec];
    fn recv_oracle(
        &mut self,
        log_msg_len: usize,
        is_witness_dependent: bool,
    ) -> Result<Self::Oracle, Error>;
    fn verify_oracle_relation(
        &mut self,
        oracle: Self::Oracle,
        transparent: TransparentEvalFn<Self::Elem>,
        claim: Self::Elem,
    ) -> Result<(), Error>;
}
Expand description

Channel for IOP verifiers that extends the IP verifier channel with oracle operations.

In an IOP, the verifier can:

  1. Receive field elements from the prover via recv_* methods (inherited)
  2. Sample random challenges via sample (inherited)
  3. Receive oracle commitments from the prover
  4. Query oracles at specific positions and verify opening proofs

§Contract

The caller must call recv_oracle() exactly remaining_oracle_specs().len() times before calling verify_oracle_relation(). The oracles must be received in order and match their specifications.

Required Associated Types§

Required Methods§

Source

fn remaining_oracle_specs(&self) -> &[OracleSpec]

Returns the specifications for the remaining oracles to be received.

This slice shrinks as oracles are received via recv_oracle().

Source

fn recv_oracle( &mut self, log_msg_len: usize, is_witness_dependent: bool, ) -> Result<Self::Oracle, Error>

Receives an oracle commitment from the prover.

The caller describes the oracle being received: log_msg_len is the log2 of the message length, and is_witness_dependent is whether the oracle’s contents depend on the witness. These let a channel record the oracle’s OracleSpec rather than requiring the specs to be supplied up front. The resulting oracle is zero-knowledge iff the channel is configured for ZK and the oracle is witness-dependent — a non-witness-dependent oracle (e.g. a pre-indexed commitment to the wiring matrix for succinctness, a planned feature) is never masked.

Source

fn verify_oracle_relation( &mut self, oracle: Self::Oracle, transparent: TransparentEvalFn<Self::Elem>, claim: Self::Elem, ) -> Result<(), Error>

Queues one oracle linear relation to be opened.

Implementations may either verify the relation immediately, or queue it and defer the actual opening (masking + sumcheck + FRI) to finish(). Either way, the relation asserts that <oracle_poly, transparent> = claim. An oracle may carry any number of relations.

§Preconditions
  • oracle must be a valid handle returned by recv_oracle().

Dyn Compatibility§

This trait is not dyn compatible.

In older versions of Rust, dyn compatibility was called "object safety".

Implementors§

Source§

impl<'a, F, C> IOPVerifierChannel<F> for MergeVerifierChannel<'a, F, C>
where F: Field, C: IOPVerifierChannel<F>,

Source§

impl<'a, F, Channel> IOPVerifierChannel<F> for BaseFoldVerifierChannel<'a, F, Channel>
where F: BinaryField, Channel: MerkleIPVerifierChannel<F, Elem: From<F> + 'static>,

Source§

impl<F, Challenger_> IOPVerifierChannel<F> for NaiveVerifierChannel<'_, F, Challenger_>
where F: Field, Challenger_: Challenger,

Source§

impl<F: Field> IOPVerifierChannel<F> for OracleSetupChannel