pub trait IOPProverChannel<P: PackedField, A: Allocator>: IPProverChannel<P::Scalar> {
type Oracle: Clone;
// Required methods
fn remaining_oracle_specs(&self) -> &[OracleSpec];
fn send_oracle(&mut self, buffer: FieldSlice<'_, P>) -> Self::Oracle;
fn prove_oracle_relation(
&mut self,
oracle: Self::Oracle,
transparent: StructuredBuffer<P, A::Vec<P>>,
claim: P::Scalar,
);
fn finalize_oracle(&mut self, oracle: Self::Oracle, buffer: FieldVec<P, A>);
}Expand description
Channel for IOP provers that extends the IP prover channel with oracle operations.
In an IOP, the prover can:
- Send field elements to the verifier via
send_*methods (inherited) - Sample random challenges via
sample(inherited) - Commit oracles to the verifier
- Respond to oracle queries with opening proofs
§Contract
The caller must call send_oracle() exactly remaining_oracle_specs().len() times before
calling prove_oracle_relation(). Each oracle buffer must match the corresponding
specification. Every committed oracle must be handed back to the channel exactly once with
finalize_oracle().
Required Associated Types§
Required Methods§
Sourcefn remaining_oracle_specs(&self) -> &[OracleSpec]
fn remaining_oracle_specs(&self) -> &[OracleSpec]
Returns the specifications for the remaining oracles to be committed.
This slice shrinks as oracles are committed via send_oracle().
Sourcefn send_oracle(&mut self, buffer: FieldSlice<'_, P>) -> Self::Oracle
fn send_oracle(&mut self, buffer: FieldSlice<'_, P>) -> Self::Oracle
Commits an oracle to the verifier.
§Preconditions
remaining_oracle_specs()must be non-empty.buffer.log_len()must match the expected length from the next oracle spec.
Sourcefn prove_oracle_relation(
&mut self,
oracle: Self::Oracle,
transparent: StructuredBuffer<P, A::Vec<P>>,
claim: P::Scalar,
)
fn prove_oracle_relation( &mut self, oracle: Self::Oracle, transparent: StructuredBuffer<P, A::Vec<P>>, claim: P::Scalar, )
Generates an opening proof for one oracle linear relation.
The relation asserts that <oracle_poly, transparent> = claim. An oracle may carry any
number of relations.
The transparent may be zero outside one aligned block, and say so through its structure. A channel that understands the structure skips the zeros; any other materializes it.
The channel owns the transparent multilinear until the opening runs, so it is drawn from
the caller’s allocator A — a pooled buffer stays pooled all the way through the opening.
§Preconditions
remaining_oracle_specs()must be empty (all oracles committed).oraclemust be a valid handle returned bysend_oracle().transparent.log_len()must match the oracle’s message length.- The claim must already be bound to the transcript, since the coefficient that batches the queued relations is drawn only after the queue closes.
Sourcefn finalize_oracle(&mut self, oracle: Self::Oracle, buffer: FieldVec<P, A>)
fn finalize_oracle(&mut self, oracle: Self::Oracle, buffer: FieldVec<P, A>)
Gives ownership of the oracle buffer to the channel.
The Self::send_oracle method takes a borrowed reference to an oracle buffer and returns
a handle to it. In order to prove the oracle relations without unnecessarily cloning the
buffer, some channel implementations require ownership of the buffer.
§Preconditions
oraclemust be a valid handle returned bysend_oracle(), not already finalized.buffermust equal the buffer previously committed viasend_oracle().
Dyn Compatibility§
This trait is not dyn compatible.
In older versions of Rust, dyn compatibility was called "object safety".