Skip to main content

MergeProverChannel

Struct MergeProverChannel 

Source
pub struct MergeProverChannel<'a, P, A, C>
where P: PackedField, A: Allocator, C: IOPProverChannel<P, A>,
{ /* private fields */ }
Expand description

A prover channel decorator that merges one round’s oracles into one combined oracle.

§Overview

An interaction round is the run of oracles sent between two challenge samples.

Committing each oracle separately costs one commitment per oracle. One Merkle tree per oracle, for example.

This decorator buffers a round’s oracles instead. It commits them together as one larger oracle. That cuts the cost to one commitment per round.

A round’s oracles are sorted from largest to smallest, then laid out end to end. That ordering makes every oracle’s position exact.

Every earlier oracle is at least as large as the current one. So their combined space is a whole multiple of the current oracle’s size.

A round of a single oracle needs no combining. It is forwarded unchanged, at zero cost.

A round is masked as a whole, never partly.

So a round carrying any witness data is masked in full by the underlying channel. The verifier-side decorator is where that choice is made.

§Timing

A round’s oracles are committed the moment its last oracle arrives.

The OracleSchedule says where each round ends, so no challenge sample is needed to find the boundary. A real Fiat-Shamir transcript can therefore absorb the commitment before the next challenge.

The combined buffer is finalized on the underlying channel right after it is committed. So finalizing a constituent oracle here just drops the buffer handed back.

§Opening

A verifier only ever holds a formula for a transparent polynomial.

This side holds the actual coefficients instead. A constituent’s own transparent polynomial becomes one for the combined oracle. It is the constituent’s values at the constituent’s own block, and zero everywhere else. This side forwards it to the underlying channel as a zero-padded structure, never writing the zeros.

That placement is the same polynomial a verifier reaches by formula. One side holds the block as explicit values. The other evaluates it on demand.

Implementations§

Source§

impl<'a, P, A, C> MergeProverChannel<'a, P, A, C>
where P: PackedField, A: Allocator, C: IOPProverChannel<P, A>,

Source

pub fn new(inner: C, schedule: &'a OracleSchedule, alloc: A) -> Self

Creates a new merging prover channel over an underlying channel.

§Arguments
  • inner — the channel every combined oracle is committed to, already configured with schedule.merged_specs().
  • schedule — every oracle this channel’s caller will pass through, grouped into rounds.
  • alloc — where this channel draws its combined buffers from.
§Panics

Panics if inner is not configured with schedule.merged_specs().

Source

pub fn into_inner(self) -> C

Returns the underlying channel.

§Panics

Panics if any declared oracle has not yet been sent.

Trait Implementations§

Source§

impl<'a, F, P, A, C> IOPProverChannel<P, A> for MergeProverChannel<'a, P, A, C>
where F: Field, P: PackedField<Scalar = F>, A: Allocator, C: IOPProverChannel<P, A>,

Source§

type Oracle = MergeOracle

Source§

fn remaining_oracle_specs(&self) -> &[OracleSpec]

Returns the specifications for the remaining oracles to be committed. Read more
Source§

fn send_oracle(&mut self, buffer: FieldSlice<'_, P>) -> Self::Oracle

Commits an oracle to the verifier. Read more
Source§

fn prove_oracle_relation( &mut self, oracle: Self::Oracle, transparent: StructuredBuffer<P, A::Vec<P>>, claim: P::Scalar, )

Generates an opening proof for one oracle linear relation. Read more
Source§

fn finalize_oracle(&mut self, _oracle: Self::Oracle, _buffer: FieldVec<P, A>)

Gives ownership of the oracle buffer to the channel. Read more
Source§

impl<F, P, A, C> IPProverChannel<F> for MergeProverChannel<'_, P, A, C>
where F: Field, P: PackedField<Scalar = F>, A: Allocator, C: IOPProverChannel<P, A>,

Source§

fn send_one(&mut self, elem: F)

Sends a single field element to the verifier.
Source§

fn send_many(&mut self, elems: &[F])

Sends multiple field elements to the verifier.
Source§

fn observe_one(&mut self, val: F)

Observes a single field element, feeding it into the Fiat-Shamir state.
Source§

fn observe_many(&mut self, vals: &[F])

Observes multiple field elements, feeding them into the Fiat-Shamir state.
Source§

fn sample(&mut self) -> F

Samples a random challenge. Read more
Source§

fn send_public_claim(&mut self, elem: F)

Sends a value the verifier could compute for itself, as advice. Read more
Source§

fn sample_many(&mut self, n: usize) -> Vec<F>

Samples n random challenges.
Source§

fn sample_array<const N: usize>(&mut self) -> [F; N]

Samples a fixed-size array of random challenges.
Source§

impl<F, P, A, C> WordIPProverChannel<F> for MergeProverChannel<'_, P, A, C>
where F: Field, P: PackedField<Scalar = F>, A: Allocator, C: IOPProverChannel<P, A> + WordIPProverChannel<F>,

Source§

type Word = <C as WordIPProverChannel<F>>::Word

The word type this channel carries. Read more
Source§

fn observe_words(&mut self, words: &[Self::Word])

Feeds words into the Fiat-Shamir state, each as eight little-endian bytes.
Source§

fn sample_bits(&mut self, bits: usize) -> Self::Word

Samples a uniform word of the given bit width, matching what the verifier samples. Read more

Auto Trait Implementations§

§

impl<'a, P, A, C> Freeze for MergeProverChannel<'a, P, A, C>
where C: Freeze, A: Freeze, <A as Allocator>::Vec<P>: Freeze,

§

impl<'a, P, A, C> RefUnwindSafe for MergeProverChannel<'a, P, A, C>

§

impl<'a, P, A, C> Send for MergeProverChannel<'a, P, A, C>
where C: Send, A: Send, <C as IOPProverChannel<P, A>>::Oracle: Send,

§

impl<'a, P, A, C> Sync for MergeProverChannel<'a, P, A, C>
where C: Sync, <A as Allocator>::Vec<P>: Sync, <C as IOPProverChannel<P, A>>::Oracle: Sync,

§

impl<'a, P, A, C> Unpin for MergeProverChannel<'a, P, A, C>
where C: Unpin, A: Unpin, <A as Allocator>::Vec<P>: Unpin, <C as IOPProverChannel<P, A>>::Oracle: Unpin,

§

impl<'a, P, A, C> UnsafeUnpin for MergeProverChannel<'a, P, A, C>
where C: UnsafeUnpin, A: UnsafeUnpin, <A as Allocator>::Vec<P>: UnsafeUnpin,

§

impl<'a, P, A, C> UnwindSafe for MergeProverChannel<'a, P, A, C>
where C: UnwindSafe, A: UnwindSafe, <A as Allocator>::Vec<P>: UnwindSafe, <C as IOPProverChannel<P, A>>::Oracle: UnwindSafe,

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
§

impl<T> Pointable for T

§

const ALIGN: usize

The alignment of pointer.
§

type Init = T

The type for initializers.
§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more