Skip to main content

binius_iop/channel/
grinding.rs

1// Copyright 2026 The Binius Developers
2
3//! Proof-of-work grinding, as a capability a verifier channel may carry.
4//!
5//! A grind is a nonce the prover had to search for and the verifier re-checks cheaply.
6//! It taxes re-rolling the challenge that follows it, and that tax is the whole point.
7//! Grinding is the one lever that moves a proximity bound no number of queries can reach.
8
9use binius_transcript::Error;
10
11/// A verifier channel that can check a proof of work its prover paid into the transcript.
12///
13/// Grinding acts on the Fiat-Shamir state rather than on anything committed.
14/// So it is a trait of its own, asked for alongside the channel bound a protocol already needs.
15/// A channel with no way to express a proof of work is then rejected at the type level.
16///
17/// # Contract
18///
19/// A difficulty of zero is not a grind: it leaves the proof tape and the challenger untouched.
20/// So a protocol configured to grind nothing writes exactly the transcript it wrote before.
21/// That rule lives here rather than at the call sites, where the two sides could drift apart.
22/// A grind is sound only when prover and verifier apply it at the same point in the transcript.
23pub trait GrindingVerifierChannel {
24	/// Checks the proof of work of `bits` difficulty standing at this point in the transcript.
25	///
26	/// ## Errors
27	///
28	/// Returns [`Error::InsufficientWork`] when the nonce the prover sent does not meet `bits`.
29	/// Returns a deserialization error when the proof carries no nonce here.
30	///
31	/// ## Preconditions
32	///
33	/// * `bits` is at most [`MAX_GRINDING_BITS`](binius_transcript::MAX_GRINDING_BITS).
34	fn verify_grind(&mut self, bits: usize) -> Result<(), Error>;
35}