Skip to main content

FRIFoldProver

Struct FRIFoldProver 

Source
pub struct FRIFoldProver<'a, F, P, NTT, C, Data = Vec<P>>
where F: BinaryField, P: PackedField<Scalar = F>, Data: Deref<Target = [P]>,
{ /* private fields */ }
Expand description

A stateful prover for the FRI fold phase.

Fold-round codewords are committed by sending them over a Merkle channel with commitment handle type C, matching the channel’s Commitment associated type.

Implementations§

Source§

impl<'a, F, P, NTT, C, Data> FRIFoldProver<'a, F, P, NTT, C, Data>
where F: BinaryField, P: PackedField<Scalar = F>, NTT: AdditiveNTT<Field = F> + Sync, Data: Deref<Target = [P]>,

Source

pub fn new( params: &'a FRIParams<F>, ntt: &'a NTT, committed_codeword: FieldBuffer<P, Data>, commitment: C, ) -> Self

Constructs a new folder for a single committed input oracle.

Source

pub fn new_batch( params: &'a FRIParams<F>, ntt: &'a NTT, committed_codewords: Vec<(FieldBuffer<P, Data>, C)>, ) -> Self

Constructs a new folder for a batch of committed input oracles.

The input oracles share the Reed-Solomon code but may have differing batch sizes; they are folded and combined into a single first-round codeword. The codewords must be supplied in the same order as FRIParams::input_oracles, each with the commitment handle produced when it was sent over the Merkle channel.

§Preconditions
  • committed_codewords.len() must equal params.input_oracles().len().
  • Each input oracle’s dimension (rs_code().log_dim() - log_lift) must be at most params.rs_code().log_dim().
  • Each codeword’s length must equal its oracle’s Reed-Solomon code length plus its batch size (rs_code().log_dim() - log_lift + log_batch_size + log_inv_rate), and its commitment’s leaf size must be one interleaved coset (2^log_batch_size scalars).
Source

pub const fn n_rounds(&self) -> usize

Number of fold rounds, including the final fold.

Source

pub fn receive_challenge(&mut self, challenge: F)

Records the folding challenge for the current round and advances the round counter.

The challenge is buffered, not applied immediately. Buffered challenges are consumed lazily at the next commit round. This avoids materializing intermediate folded codewords.

The challenge order is a hard contract, shared with the verifier’s fold order. Feed challenges in the protocol’s round order:

  1. the shared mask challenge gamma, once, if any oracle is ZK (the inner unbatch round);
  2. the log_n_oracles outer batching challenges (the oracle-combine rounds);
  3. one challenge per MLE-check round over the combined oracle’s variables.

Steps 1 and 2 are fed up front. Step 3 is interleaved with the fold rounds: one challenge after each fold. The total number of challenges must equal the number of fold rounds.

Source

pub fn execute_fold_round<Channel>(&mut self, channel: &mut Channel)
where Channel: MerkleIPProverChannel<F, Commitment = C>,

Executes the next fold round, committing the folded codeword over the channel if this is a commitment round.

On a commitment round, the folded codeword’s Merkle commitment is computed and its root is written to the channel as an observed message. Call this after writing any other messages belonging to the same round (e.g. sumcheck round coefficients), so the root lands after them in the transcript.

As a memory efficient optimization, this method may not actually do the folding, but instead accumulate the folding challenge for processing at a later time. This saves us from storing intermediate folded codewords.

Source

pub fn finalize(self) -> (FieldBuffer<F>, C, FRIQueryProver<F, P, C, Data>)

Finalizes the FRI folding process.

This step will process any unprocessed folding challenges to produce the final folded codeword. Then it will decode this final folded codeword to get the final message.

This returns the terminal codeword, its commitment handle (for sending it in full over a Merkle channel), and a query prover instance.

§Preconditions
  • All fold rounds must have been executed (curr_round == n_rounds()).
Source

pub fn finish_proof<Channel>(self, channel: &mut Channel)
where Channel: MerkleIPProverChannel<F, Commitment = C>,

Runs the FRI query phase over the channel.

Samples the query indices, sends the per-oracle batched query openings, and sends the terminal codeword in full.

§Preconditions
  • All fold rounds must have been executed (curr_round == n_rounds()).

Auto Trait Implementations§

§

impl<'a, F, P, NTT, C, Data> Freeze for FRIFoldProver<'a, F, P, NTT, C, Data>
where <F as UnderlierView>::Underlier: Sized, C: Freeze,

§

impl<'a, F, P, NTT, C, Data> RefUnwindSafe for FRIFoldProver<'a, F, P, NTT, C, Data>

§

impl<'a, F, P, NTT, C, Data> Send for FRIFoldProver<'a, F, P, NTT, C, Data>
where <F as UnderlierView>::Underlier: Sized, NTT: Sync, C: Send, Data: Send,

§

impl<'a, F, P, NTT, C, Data> Sync for FRIFoldProver<'a, F, P, NTT, C, Data>
where <F as UnderlierView>::Underlier: Sized, NTT: Sync, C: Sync, Data: Sync,

§

impl<'a, F, P, NTT, C, Data> Unpin for FRIFoldProver<'a, F, P, NTT, C, Data>
where <F as UnderlierView>::Underlier: Sized, C: Unpin, F: Unpin, Data: Unpin,

§

impl<'a, F, P, NTT, C, Data> UnsafeUnpin for FRIFoldProver<'a, F, P, NTT, C, Data>

§

impl<'a, F, P, NTT, C, Data> UnwindSafe for FRIFoldProver<'a, F, P, NTT, C, Data>

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
§

impl<T> Pointable for T

§

const ALIGN: usize

The alignment of pointer.
§

type Init = T

The type for initializers.
§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more