Skip to main content

WordIPVerifierChannel

Trait WordIPVerifierChannel 

Source
pub trait WordIPVerifierChannel<F: Field>: IPVerifierChannel<F> {
    type Word: Clone + From<Word> + Shr<u32, Output = Self::Word>;

    // Required methods
    fn observe_words(&mut self, words: &[Word]) -> Vec<Self::Word>;
    fn subset_sum(
        &mut self,
        elems: &[Self::Elem],
        word: &Self::Word,
    ) -> Self::Elem;
    fn select(&mut self, elems: &[Self::Elem], word: &Self::Word) -> Self::Elem;
    fn sample_bits(&mut self, bits: usize) -> Self::Word;
    fn pack_words(&mut self, words: &[Self::Word]) -> Vec<Self::Elem>;
}
Expand description

A verifier channel whose protocol carries 64-bit words alongside field elements.

Some values a verifier handles are words rather than field elements: the public inputs of a Binius64 constraint system, and the query indices a code proximity test samples. A channel that symbolically executes a verifier to build a circuit carries those as wires, so protocol code cannot name a concrete word type and goes through Self::Word instead.

Self::subset_sum and Self::select are how protocol code reaches the bits of a word. A channel over concrete values reads them directly; a circuit-building one emits a sub-circuit.

Required Associated Types§

Source

type Word: Clone + From<Word> + Shr<u32, Output = Self::Word>

The word type this channel carries.

A channel over concrete values uses Word. A channel that builds a circuit uses a wire type that folds the operations below over a builder.

From<Word> lifts a word the protocol description fixes, such as a constraint system constant, and Shr is the index arithmetic a code proximity test performs between fold rounds. Both are plain operations on the type rather than channel methods, so protocol code writes word.into() and word >> n whatever the channel is. The shift amount is a u32 to match Word’s own Shl and Shr impls.

Required Methods§

Source

fn observe_words(&mut self, words: &[Word]) -> Vec<Self::Word>

Feeds words into the Fiat-Shamir state, each as eight little-endian bytes, and returns them as this channel’s word type.

The words go in concrete, because the statement is fixed data the verifier is handed rather than something the protocol derives. They come back as Self::Word, which is where a channel that carries words as wires introduces them: it allocates the wires here, and the protocol sees the statement symbolically from this point on. A channel over concrete values hands the same words straight back.

Source

fn subset_sum(&mut self, elems: &[Self::Elem], word: &Self::Word) -> Self::Elem

Returns the sum of the elems selected by the low bits of word, low bit first.

This is the inner product of elems with the bit decomposition of word. Bits of word at or above elems.len() do not contribute.

§Preconditions
  • elems.len() must be at most 64.
Source

fn select(&mut self, elems: &[Self::Elem], word: &Self::Word) -> Self::Elem

Returns the element of elems at the index in the low bits of word.

Bits of word at or above log2(elems.len()) are ignored.

§Preconditions
  • elems must be non-empty and its length must be a power of two.
Source

fn sample_bits(&mut self, bits: usize) -> Self::Word

Samples a uniform word of the given bit width.

The result is masked to bits bits. Protocols rely on that bound, so an implementation must enforce it rather than assume the sampled value already fits.

Source

fn pack_words(&mut self, words: &[Self::Word]) -> Vec<Self::Elem>

Packs words into field elements, as many words to an element as one holds.

Word i occupies bits [Word::BITS * i, Word::BITS * (i + 1)) of element i / words_per_elem, so the packed form reads the same way the committed trace does: the low bit-index coordinates address the bit within a word, the next the word within its element. A word count that does not fill the last element leaves its high words zero.

This is a channel method rather than a free function because the words may be wires: a channel over concrete values computes the elements, and a circuit-building one emits the gates that assemble them.

Dyn Compatibility§

This trait is not dyn compatible.

In older versions of Rust, dyn compatibility was called "object safety".

Implementations on Foreign Types§

Source§

impl<F, Challenger_> WordIPVerifierChannel<F> for VerifierTranscript<Challenger_>
where F: BinaryField, Challenger_: Challenger,

Source§

type Word = Word

Source§

fn observe_words(&mut self, words: &[Word]) -> Vec<Word>

Source§

fn subset_sum(&mut self, elems: &[F], word: &Word) -> F

Source§

fn select(&mut self, elems: &[F], word: &Word) -> F

Source§

fn sample_bits(&mut self, bits: usize) -> Word

Source§

fn pack_words(&mut self, words: &[Word]) -> Vec<F>

Implementors§