Skip to main content

binius_ip_prover/logup_star/
mod.rs

1// Copyright 2026 The Binius Developers
2
3//! Prover for the logUp* indexed-lookup reduction of knowledge.
4//!
5//! This is the prover counterpart of the verifier in [`binius_ip::logup_star`].
6//! See that module for the protocol, its soundness, and the index embedding.
7//!
8//! logUp* proves an indexed lookup `(I^* T)[i] = T[index[i]]`, for one or more lookers reading one
9//! or more tables (batched by a random linear combination over the looker numerators).
10//! - It never commits the looked-up vectors `I_j^* T`, which would have `2^n` entries each.
11//! - Instead it commits each table's pushforward `Y_t`, which has only `2^m_t` entries.
12//! - This rests on the duality `(I^* T)(r) = <I^* T, eq_r> = <T, I_* eq_r> = <T, Y>`.
13//!
14//! # What this prover does
15//!
16//! Given the tables `T_t`, the index columns, the evaluation points `r_j`, and the claims `e_j`,
17//! it:
18//!
19//! 1. samples the looker batching challenge `gamma` and builds the numerators and pushforwards,
20//! 2. samples one logUp challenge `c_t` per table,
21//! 3. builds one fractional-addition circuit per looker and per table, and one top circuit summing
22//!    their root fractions, then sends that sum's denominator alone — its numerator is zero exactly
23//!    when the lookup identities hold,
24//! 4. runs the whole thing as one batched GKR down to the leaves,
25//! 5. proves one batched sumcheck closing every table's pushforward and product claims.
26//!
27//! The result is the same [`LogupOutput`] the verifier returns.
28//! It holds reduced evaluation claims on each `T_t`, on each `Y_t`, and on the index multilinears.
29//! The caller verifies those claims separately.
30
31mod prove;
32mod pushforward;
33pub mod witness;
34
35pub use binius_ip::logup_star::{
36	LogupOutput, LogupTableOutput, LogupTransparentOutput, LogupTransparentTableOutput,
37};
38
39pub use self::prove::{
40	Looker, TableLookup, prove, prove_reduction, prove_reduction_transparent, prove_transparent,
41};