pub struct FRIFoldProver<'a, F, P, NTT, C, Data = Vec<P>>{ /* private fields */ }Expand description
A stateful prover for the FRI fold phase.
Fold-round codewords are committed by sending them over a Merkle channel with commitment
handle type C, matching the channel’s Commitment associated type.
Implementations§
Source§impl<'a, F, P, NTT, C, Data> FRIFoldProver<'a, F, P, NTT, C, Data>where
F: BinaryField,
P: PackedField<Scalar = F>,
NTT: AdditiveNTT<Field = F> + Sync,
Data: Deref<Target = [P]>,
impl<'a, F, P, NTT, C, Data> FRIFoldProver<'a, F, P, NTT, C, Data>where
F: BinaryField,
P: PackedField<Scalar = F>,
NTT: AdditiveNTT<Field = F> + Sync,
Data: Deref<Target = [P]>,
Sourcepub fn new(
params: &'a FRIParams<F>,
ntt: &'a NTT,
committed_codeword: FieldBuffer<P, Data>,
commitment: C,
) -> Self
pub fn new( params: &'a FRIParams<F>, ntt: &'a NTT, committed_codeword: FieldBuffer<P, Data>, commitment: C, ) -> Self
Constructs a new folder for a single committed input oracle.
Sourcepub fn new_batch(
params: &'a FRIParams<F>,
ntt: &'a NTT,
committed_codewords: Vec<(FieldBuffer<P, Data>, C)>,
) -> Self
pub fn new_batch( params: &'a FRIParams<F>, ntt: &'a NTT, committed_codewords: Vec<(FieldBuffer<P, Data>, C)>, ) -> Self
Constructs a new folder for a batch of committed input oracles.
The input oracles share the Reed-Solomon code but may have differing batch sizes; they are
folded and combined into a single first-round codeword. The codewords must be supplied in
the same order as FRIParams::input_oracles, each with the commitment handle produced
when it was sent over the Merkle channel.
§Preconditions
committed_codewords.len()must equalparams.input_oracles().len().- Each input oracle’s dimension (
rs_code().log_dim() - log_lift) must be at mostparams.rs_code().log_dim(). - Each codeword’s length must equal its oracle’s Reed-Solomon code length plus its batch
size (
rs_code().log_dim() - log_lift + log_batch_size + log_inv_rate), and its commitment’s leaf size must be one interleaved coset (2^log_batch_sizescalars).
Sourcepub fn receive_challenge(&mut self, challenge: F)
pub fn receive_challenge(&mut self, challenge: F)
Records the folding challenge for the current round and advances the round counter.
The challenge is buffered, not applied immediately. Buffered challenges are consumed lazily at the next commit round. This avoids materializing intermediate folded codewords.
The challenge order is a hard contract, shared with the verifier’s fold order. Feed challenges in the protocol’s round order:
- the shared mask challenge
gamma, once, if any oracle is ZK (the inner unbatch round); - the
log_n_oraclesouter batching challenges (the oracle-combine rounds); - one challenge per MLE-check round over the combined oracle’s variables.
Steps 1 and 2 are fed up front. Step 3 is interleaved with the fold rounds: one challenge after each fold. The total number of challenges must equal the number of fold rounds.
Sourcepub fn execute_fold_round<Channel>(&mut self, channel: &mut Channel)where
Channel: MerkleIPProverChannel<F, Commitment = C>,
pub fn execute_fold_round<Channel>(&mut self, channel: &mut Channel)where
Channel: MerkleIPProverChannel<F, Commitment = C>,
Executes the next fold round, committing the folded codeword over the channel if this is a commitment round.
On a commitment round, the folded codeword’s Merkle commitment is computed and its root is written to the channel as an observed message. Call this after writing any other messages belonging to the same round (e.g. sumcheck round coefficients), so the root lands after them in the transcript.
As a memory efficient optimization, this method may not actually do the folding, but instead accumulate the folding challenge for processing at a later time. This saves us from storing intermediate folded codewords.
Sourcepub fn finalize(self) -> (FieldBuffer<F>, C, FRIQueryProver<F, P, C, Data>)
pub fn finalize(self) -> (FieldBuffer<F>, C, FRIQueryProver<F, P, C, Data>)
Finalizes the FRI folding process.
This step will process any unprocessed folding challenges to produce the final folded codeword. Then it will decode this final folded codeword to get the final message.
This returns the terminal codeword, its commitment handle (for sending it in full over a Merkle channel), and a query prover instance.
§Preconditions
- All fold rounds must have been executed (
curr_round == n_rounds()).
Sourcepub fn finish_proof<Channel>(self, channel: &mut Channel)where
Channel: MerkleIPProverChannel<F, Commitment = C>,
pub fn finish_proof<Channel>(self, channel: &mut Channel)where
Channel: MerkleIPProverChannel<F, Commitment = C>,
Runs the FRI query phase over the channel.
Samples the query indices, sends the per-oracle batched query openings, and sends the terminal codeword in full.
§Preconditions
- All fold rounds must have been executed (
curr_round == n_rounds()).
Auto Trait Implementations§
impl<'a, F, P, NTT, C, Data> Freeze for FRIFoldProver<'a, F, P, NTT, C, Data>
impl<'a, F, P, NTT, C, Data> RefUnwindSafe for FRIFoldProver<'a, F, P, NTT, C, Data>where
<F as UnderlierView>::Underlier: Sized,
NTT: RefUnwindSafe,
C: RefUnwindSafe,
F: RefUnwindSafe,
Data: RefUnwindSafe,
impl<'a, F, P, NTT, C, Data> Send for FRIFoldProver<'a, F, P, NTT, C, Data>
impl<'a, F, P, NTT, C, Data> Sync for FRIFoldProver<'a, F, P, NTT, C, Data>
impl<'a, F, P, NTT, C, Data> Unpin for FRIFoldProver<'a, F, P, NTT, C, Data>
impl<'a, F, P, NTT, C, Data> UnsafeUnpin for FRIFoldProver<'a, F, P, NTT, C, Data>
impl<'a, F, P, NTT, C, Data> UnwindSafe for FRIFoldProver<'a, F, P, NTT, C, Data>where
<F as UnderlierView>::Underlier: Sized,
NTT: RefUnwindSafe,
C: UnwindSafe,
F: UnwindSafe + RefUnwindSafe,
Data: UnwindSafe,
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more