Skip to main content

prove

Function prove 

Source
pub fn prove<A, F, P, Channel>(
    columns: [&[Word]; 4],
    channel: &mut Channel,
    alloc: &A,
) -> Result<IntMulOutput<F>, Error>
where A: Allocator, F: BinaryField<Underlier: Divisible<u64>>, P: PackedField<Scalar = F>, Channel: IOPProverChannel<P, A>,
Expand description

Proves the integer multiplication (IntMul) reduction over the four operand columns.

The four columns are the multiplicand a, the multiplicand b, and the product’s low and high words, in the order [a, b, lo, hi], all of equal length. This builds the Witness, drives an IntMulProver, and reduces the multiplication relation to per-bit evaluation claims on the four columns at a common point. See IntMulProver::prove for the protocol description and [IntMulOutput] for the output shape.

§Padding

The columns’ length need not be a power of two. The reduction runs over the constraint axis of 2^ceil(log2(n)) rows, with the rows past the columns’ end read as Word::ZERO; a zero row satisfies 0 * 0 = 0 || 0, so no claim moves. The padding is never materialized as words: every buffer built from the columns spans the whole axis and derives its own padding value, which is the multiplicative identity in the product-check trees and zero elsewhere.

§Errors

Returns an error when the operand columns’ lengths disagree.