Skip to main content

prove

Function prove 

Source
pub fn prove<F, P, Channel, A>(
    bitand: impl MleCheckProver<F>,
    bitand_claim: F,
    lagrange: &[F],
    operands: &[OperandWitness<'_, F>],
    channel: &mut Channel,
    alloc: &A,
) -> RerandOutput<F>
where F: BinaryField, P: PackedField<Scalar = F>, Channel: IPProverChannel<F>, A: Allocator,
Expand description

Proves the BitAnd sumcheck batched with the operand-column MLE-checks.

Every summand runs as a sumcheck in plain form, zero-padded on its high variables to the longest summand’s variable count. The evaluations go out flat in summand order: [a, b, c, sigma_1, ..., sigma_n].

§Arguments

  • bitand - the BitAnd MLE-check prover, from the univariate skip’s fold.
  • bitand_claim - its claim, the univariate-skip polynomial at z.
  • lagrange - the Lagrange weights at z on the 64-point domain.
  • operands - the operand columns of each multiplication reduction, with their claims.

The per-bit claims of operands must be in the transcript before z was drawn, matching [binius_verifier::protocols::rerand::verify].

§Preconditions

  • each operand’s column count equals its claim count
  • each column’s length rounds up to 2^point.len() for its reduction’s point