binius_transcript/lib.rs
1// Copyright 2025 Irreducible Inc.
2
3#![warn(rustdoc::missing_crate_level_docs)]
4
5//! Objects used to read and write proof strings.
6//!
7//! A Binius proof consists of the transcript of the simulated interaction between the prover and
8//! the verifier. Using the Fiat-Shamir heuristic, the prover and verifier can simulate the
9//! verifier's messages, which are deterministically computed based on the sequence of prover
10//! messages and calls to sample verifier challenges. The interaction consists of two parallel
11//! tapes, the _transcript_ tape and the _advice_ tape. The values in the transcript tape affect
12//! the Fiat-Shamir state, whereas values in the advice tape do not. **The decommitment tape must
13//! only be used for values that were previously committed to in the transcript tape.** For
14//! example, it is secure to write a Merkle tree root to the transcript tape, sample a random
15//! index, then provide the Merkle leaf opening at that index in the advice tape.
16
17mod error;
18pub mod fiat_shamir;
19mod transcript;
20
21pub use bytes::{Buf, BufMut};
22pub use error::*;
23pub use transcript::*;