pub trait WordIPVerifierChannel<F: Field>: IPVerifierChannel<F> {
type Word: Clone + From<Word> + Shr<u32, Output = Self::Word>;
// Required methods
fn observe_words(&mut self, words: &[Word]) -> Vec<Self::Word>;
fn subset_sum(
&mut self,
elems: &[Self::Elem],
word: &Self::Word,
) -> Self::Elem;
fn select(&mut self, elems: &[Self::Elem], word: &Self::Word) -> Self::Elem;
fn sample_bits(&mut self, bits: usize) -> Self::Word;
fn pack_words(&mut self, words: &[Self::Word]) -> Vec<Self::Elem>;
}Expand description
A verifier channel whose protocol carries 64-bit words alongside field elements.
Some values a verifier handles are words rather than field elements: the public inputs of a
Binius64 constraint system, and the query indices a code proximity test samples. A channel that
symbolically executes a verifier to build a circuit carries those as wires, so protocol code
cannot name a concrete word type and goes through Self::Word instead.
Self::subset_sum and Self::select are how protocol code reaches the bits of a word. A
channel over concrete values reads them directly; a circuit-building one emits a sub-circuit.
Required Associated Types§
Sourcetype Word: Clone + From<Word> + Shr<u32, Output = Self::Word>
type Word: Clone + From<Word> + Shr<u32, Output = Self::Word>
The word type this channel carries.
A channel over concrete values uses Word. A channel that builds a circuit uses a wire
type that folds the operations below over a builder.
From<Word> lifts a word the protocol description fixes, such as a constraint
system constant, and Shr is the index arithmetic a code proximity test performs between
fold rounds. Both are plain operations on the type rather than channel methods, so protocol
code writes word.into() and word >> n whatever the channel is. The shift amount is a
u32 to match Word’s own Shl and Shr impls.
Required Methods§
Sourcefn observe_words(&mut self, words: &[Word]) -> Vec<Self::Word>
fn observe_words(&mut self, words: &[Word]) -> Vec<Self::Word>
Feeds words into the Fiat-Shamir state, each as eight little-endian bytes, and returns them as this channel’s word type.
The words go in concrete, because the statement is fixed data the verifier is handed rather
than something the protocol derives. They come back as Self::Word, which is where a
channel that carries words as wires introduces them: it allocates the wires here, and the
protocol sees the statement symbolically from this point on. A channel over concrete values
hands the same words straight back.
Sourcefn subset_sum(&mut self, elems: &[Self::Elem], word: &Self::Word) -> Self::Elem
fn subset_sum(&mut self, elems: &[Self::Elem], word: &Self::Word) -> Self::Elem
Returns the sum of the elems selected by the low bits of word, low bit first.
This is the inner product of elems with the bit decomposition of word. Bits of word
at or above elems.len() do not contribute.
§Preconditions
elems.len()must be at most 64.
Sourcefn select(&mut self, elems: &[Self::Elem], word: &Self::Word) -> Self::Elem
fn select(&mut self, elems: &[Self::Elem], word: &Self::Word) -> Self::Elem
Returns the element of elems at the index in the low bits of word.
Bits of word at or above log2(elems.len()) are ignored.
§Preconditions
elemsmust be non-empty and its length must be a power of two.
Sourcefn sample_bits(&mut self, bits: usize) -> Self::Word
fn sample_bits(&mut self, bits: usize) -> Self::Word
Samples a uniform word of the given bit width.
The result is masked to bits bits. Protocols rely on that bound, so an implementation
must enforce it rather than assume the sampled value already fits.
Sourcefn pack_words(&mut self, words: &[Self::Word]) -> Vec<Self::Elem>
fn pack_words(&mut self, words: &[Self::Word]) -> Vec<Self::Elem>
Packs words into field elements, as many words to an element as one holds.
Word i occupies bits [Word::BITS * i, Word::BITS * (i + 1)) of element
i / words_per_elem, so the packed form reads the same way the committed trace does: the
low bit-index coordinates address the bit within a word, the next the word within its
element. A word count that does not fill the last element leaves its high words zero.
This is a channel method rather than a free function because the words may be wires: a channel over concrete values computes the elements, and a circuit-building one emits the gates that assemble them.
Dyn Compatibility§
This trait is not dyn compatible.
In older versions of Rust, dyn compatibility was called "object safety".