pub fn prove_mlecheck_basefold<A, F, P, NTT, Channel, Data>(
witness: FieldVec<P, A>,
eval_point: &[F],
eval_claim: F,
batch_challenge: Option<F>,
outer_challenges: &[F],
fri_folder: FRIFoldProver<'_, F, P, NTT, Channel::Commitment, Data>,
channel: &mut Channel,
alloc: &A,
)where
A: Allocator,
F: BinaryField,
P: PackedField<Scalar = F>,
NTT: AdditiveNTT<Field = F> + Sync,
Channel: MerkleIPProverChannel<F>,
Data: Deref<Target = [P]>,Expand description
Proves a combined multilinear evaluation claim ๐(eval_point) = eval_claim by interleaving a
single multilinear-evaluation MLE-check with a single combined FRI over the
piecewise-concatenated oracle of the Batched ZK BaseFold construction (whitepaper ยง7.2 /
ยงsec:batched-basefold Step 2).
A prior batched sumcheck reduced the k masked opening claims to per-oracle point-evaluation
claims ฯ_i'(ฯ_i) = ฮฑ_i at a shared point r โ K^๐ง (๐ง = max_i n_i). The caller has collapsed
the oracle-index variables up front at sampled batching challenges r' into a single combined
multilinear ๐(X) = ฮฃ_i e[i]ยทฯ_i^โ(X), e the indicator expanded at r' (passed as
witness), with target s' = ๐(r). Here we run the degree-1 MLE-check on ๐ against r,
interleaved with the FRI codeword built (via FRIFoldProver::new_batch) from the k
committed interleaved [ฯ_i โ ฯ_i] codewords.
ยงArguments
witness- the combined oracle multilinear๐withlog_len = ๐งeval_point- the pointrwithlen = ๐ง, in low-to-high variable ordereval_claim- the combined targets' = ๐(r)batch_challenge- the masking challengeฮณ; folds each interleaved[ฯ_i โ ฯ_i]codeword down to the codeword ofฯ_i'in the FRI inner (unbatch) roundouter_challenges- the batching challengesr'(len = log_n_oracles); combine theklifted codewords in the FRI outer (oracle-combine) roundsfri_folder- the combined FRI fold prover, withn_rounds == ๐ง + 1 + log_n_oracleschannel- the Merkle channel carrying all prover interaction: round coefficients, challenges, commitments, and query openings
The final FRI value equals the final MLE-check value. The verifier asserts that equality when it runs the matching opening.