pub struct BaseFoldProverCompiler<P, NTT>{ /* private fields */ }Expand description
A compiler that creates BaseFold ZK prover channels with precomputed parameters.
This compiler builds a single combined FRI over all oracles, with ZK oracles configured for zero-knowledge mode.
Implementations§
Source§impl<F, P, NTT> BaseFoldProverCompiler<P, NTT>
impl<F, P, NTT> BaseFoldProverCompiler<P, NTT>
Sourcepub fn new<H>(
ntt: NTT,
merkle_scheme: &BinaryMerkleTreeScheme<F, H>,
oracle_specs: Vec<OracleSpec>,
log_inv_rate: usize,
n_test_queries: usize,
) -> Selfwhere
H: ParallelHashSuite,
pub fn new<H>(
ntt: NTT,
merkle_scheme: &BinaryMerkleTreeScheme<F, H>,
oracle_specs: Vec<OracleSpec>,
log_inv_rate: usize,
n_test_queries: usize,
) -> Selfwhere
H: ParallelHashSuite,
Creates a new compiler with precomputed combined FRI parameters.
The merkle_scheme is consulted only for proof-size estimation while choosing the FRI
parameters; it is not stored. Each oracle’s batch size is derived from its ZK flag: a ZK
oracle fixes log_batch_size = 1 (message ‖ equal-length mask), a non-ZK oracle takes a
flexible batch size.
Sourcepub fn from_verifier_compiler(
verifier_compiler: &BaseFoldVerifierCompiler<F>,
ntt: NTT,
) -> Self
pub fn from_verifier_compiler( verifier_compiler: &BaseFoldVerifierCompiler<F>, ntt: NTT, ) -> Self
Creates a prover compiler from a verifier compiler.
This reuses the precomputed FRI parameters and oracle specifications.
Sourcepub fn oracle_specs(&self) -> &[OracleSpec]
pub fn oracle_specs(&self) -> &[OracleSpec]
Returns a reference to the oracle specifications.
Sourcepub const fn fri_params(&self) -> &FRIParams<F>
pub const fn fri_params(&self) -> &FRIParams<F>
Returns a reference to the precomputed combined FRI parameters.
Sourcepub fn create_channel<Channel, A>(
&self,
channel: Channel,
rng: impl CryptoRng,
alloc: A,
) -> BaseFoldProverChannel<'_, F, P, NTT, Channel, A>where
Channel: MerkleIPProverChannel<F>,
A: Allocator,
pub fn create_channel<Channel, A>(
&self,
channel: Channel,
rng: impl CryptoRng,
alloc: A,
) -> BaseFoldProverChannel<'_, F, P, NTT, Channel, A>where
Channel: MerkleIPProverChannel<F>,
A: Allocator,
Creates a ZK prover channel over the given Merkle channel and an RNG.
The returned channel drives all prover interaction through channel, committing and opening
oracles with this compiler’s NTT, oracle specs, and combined FRI parameters. The caller
constructs the Merkle channel, so it decides how commitments are produced.
The RNG seeds the channel’s own generator, whose only output is the ZK masks. A mask is what hides a committed witness at the positions the verifier opens. Hiding is therefore only as strong as this RNG, so it must be a cryptographic one.
Sourcepub fn create_channel_without_zk<Channel, A>(
&self,
channel: Channel,
alloc: A,
) -> BaseFoldProverChannel<'_, F, P, NTT, Channel, A>where
Channel: MerkleIPProverChannel<F>,
A: Allocator,
pub fn create_channel_without_zk<Channel, A>(
&self,
channel: Channel,
alloc: A,
) -> BaseFoldProverChannel<'_, F, P, NTT, Channel, A>where
Channel: MerkleIPProverChannel<F>,
A: Allocator,
Creates a prover channel for a compiler whose oracles are all non-ZK.
A mask is drawn from the channel’s RNG only when committing a ZK oracle. With no ZK oracle the RNG is never read, so its seed cannot affect the proof. The seed is therefore fixed, and no randomness needs to be supplied by the caller.
§Panics
Panics if any configured oracle is ZK. A ZK oracle would draw its mask from the fixed seed, which destroys the hiding property. So this constructor refuses to build a channel that could mask deterministically.
Sourcepub fn create_channel_from_transcript<H, Challenger_, T, A>(
&self,
transcript: T,
rng: impl CryptoRng,
alloc: A,
) -> TranscriptBaseFoldProverChannel<'_, F, P, NTT, T, Challenger_, H, A>where
H: ParallelHashSuite,
Challenger_: Challenger,
T: BorrowMut<ProverTranscript<Challenger_>>,
Output<H::LeafHash>: SerializeBytes,
A: Allocator,
pub fn create_channel_from_transcript<H, Challenger_, T, A>(
&self,
transcript: T,
rng: impl CryptoRng,
alloc: A,
) -> TranscriptBaseFoldProverChannel<'_, F, P, NTT, T, Challenger_, H, A>where
H: ParallelHashSuite,
Challenger_: Challenger,
T: BorrowMut<ProverTranscript<Challenger_>>,
Output<H::LeafHash>: SerializeBytes,
A: Allocator,
Creates a ZK prover channel over a transcript, for the common case.
The transcript may be owned or mutably borrowed.
It is wrapped in a ProverMerkleTranscriptChannel for the given hash suite.
That channel is then passed to Self::create_channel.
alloc backs both the channel’s working buffers and the nodes of every Merkle tree it
commits, so one pool serves the whole opening.
Sourcepub fn create_channel_without_zk_from_transcript<H, Challenger_, T, A>(
&self,
transcript: T,
alloc: A,
) -> TranscriptBaseFoldProverChannel<'_, F, P, NTT, T, Challenger_, H, A>where
H: ParallelHashSuite,
Challenger_: Challenger,
T: BorrowMut<ProverTranscript<Challenger_>>,
Output<H::LeafHash>: SerializeBytes,
A: Allocator,
pub fn create_channel_without_zk_from_transcript<H, Challenger_, T, A>(
&self,
transcript: T,
alloc: A,
) -> TranscriptBaseFoldProverChannel<'_, F, P, NTT, T, Challenger_, H, A>where
H: ParallelHashSuite,
Challenger_: Challenger,
T: BorrowMut<ProverTranscript<Challenger_>>,
Output<H::LeafHash>: SerializeBytes,
A: Allocator,
Creates a non-ZK prover channel over a transcript, for the common case.
The transcript handling matches Self::create_channel_from_transcript; the channel is
built with Self::create_channel_without_zk and panics under the same conditions.
Trait Implementations§
Source§impl<P, NTT> Debug for BaseFoldProverCompiler<P, NTT>where
P: PackedField<Scalar: BinaryField> + Debug,
NTT: AdditiveNTT<Field = P::Scalar> + Sync + Debug,
P::Scalar: Debug,
impl<P, NTT> Debug for BaseFoldProverCompiler<P, NTT>where
P: PackedField<Scalar: BinaryField> + Debug,
NTT: AdditiveNTT<Field = P::Scalar> + Sync + Debug,
P::Scalar: Debug,
Auto Trait Implementations§
impl<P, NTT> Freeze for BaseFoldProverCompiler<P, NTT>
impl<P, NTT> RefUnwindSafe for BaseFoldProverCompiler<P, NTT>where
<<P as FieldOps>::Scalar as UnderlierView>::Underlier: Sized,
<P as FieldOps>::Scalar: Sized + RefUnwindSafe,
NTT: RefUnwindSafe,
P: RefUnwindSafe,
impl<P, NTT> Send for BaseFoldProverCompiler<P, NTT>
impl<P, NTT> Sync for BaseFoldProverCompiler<P, NTT>
impl<P, NTT> Unpin for BaseFoldProverCompiler<P, NTT>
impl<P, NTT> UnsafeUnpin for BaseFoldProverCompiler<P, NTT>where
<<P as FieldOps>::Scalar as UnderlierView>::Underlier: Sized,
<P as FieldOps>::Scalar: Sized,
NTT: UnsafeUnpin,
impl<P, NTT> UnwindSafe for BaseFoldProverCompiler<P, NTT>where
<<P as FieldOps>::Scalar as UnderlierView>::Underlier: Sized,
<P as FieldOps>::Scalar: Sized + UnwindSafe,
NTT: UnwindSafe,
P: UnwindSafe,
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more