Skip to main content

verify_reduction_transparent

Function verify_reduction_transparent 

Source
pub fn verify_reduction_transparent<'a, F, C>(
    gamma: &C::Elem,
    tables: impl IntoIterator<Item = TableLookup<'a, C::Elem>>,
    channel: &mut C,
) -> Result<LogupTransparentOutput<C::Elem>, Error>
where F: Field + ExtensionField<BinaryField1b>, C: IPVerifierChannel<F>, C::Elem: From<F> + 'a,
Expand description

Verify a logUp* reduction over transparent tables, leaving the table side open.

The same reduction as verify_reduction, stopped one step short of the pushforward sumcheck. Each table ends with two claims on its pushforward and none on itself:

    <Y_t, eq_{z_t}> = Y_t(z_t)      the fractional-addition leaf claim
    <Y_t, T_t>      = e_t           the product claim

Both are linear relations on the one multilinear Y_t. A caller holding Y_t as a committed oracle opens the two together against that commitment. Skipping the sumcheck drops max m rounds of round polynomials and two evaluations per table. It asks the verifier to evaluate T_t itself, so a committed table must use verify_reduction.

§Arguments

§Transcript layout

Steps 1 to 4 of verify_reduction’s layout, and nothing after them.

§Soundness

The returned product claims are unchecked: this routine never reads a table. A lookup claim is proved only once its caller opens <Y_t, T_t> = e_t. Everything else — the logUp identity that pins Y_t to the pushforward — is checked here.

§Preconditions

The preconditions of verify_reduction.

§Errors

The errors of verify_reduction, less the pushforward reduction, which does not run here.