| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
[Tracking] Eidos integration (#3879) * vm: switch native hashing and proof transcripts to Eidos Make Eidos the VM-native hash across program, MAST, package, Merkle, advice-map, kernel, signature, AEAD, deferred-node, and proof-transcript commitments. Replace HPERM with COMPRESS and implement Eidos compression AEAD stream execution throughout assembly, the processor, trace generation, AIR, proving, verification, and recursive verification. Split the proof statement into the Core, Chiplets, EidosCompression, and And8Lookup components, with the fixed And8 table also serving range checks. Migrate deferred precompile nodes and the PVM to registered four-slot Eidos framing. Bind each chain head to its selector, payload length, two arguments, and reserved zero lane. * refactor: tighten Eidos VM integration Make the shared MVM/PVM compression structure easier to audit by centralizing narrow lookup-slot metadata and adding differential coverage for their common constraints. Nest AEAD stream flags under the bitwise selector interface, clarify trace matrix cloning, and remove redundant hasher forwarding layers. Pin the fixed Eidos preprocessed commitment to its canonical PCS blowup and strengthen adjacent validation, documentation, and MMR error tests. * chore: fix failing CI * chore: fix lint * chore: resolve remaining lints * feat: align the Eidos VM cutover with typed domains * refactor(air): simplify Eidos constraint definitions Consolidate AEAD phase, equality, XOR, and packing logic, and align bitwise layout names with the byte-oriented trace. * feat: complete the Eidos native-hash cutover Replace Poseidon2-based native hashing with Eidos across the VM, deferred computation, signatures, AEAD, and proof transcripts. Introduce checked EidosFrame framing and a CV-only deferred event ABI, bind PVM compression chains by head and tail, optimize generated MASM, and regenerate the affected AIR, verifier, proof, and fixture artifacts. * docs: clean up and improve structure of docs and comments * docs: align VM design documentation * fix: resolve Eidos stack integration lints * chore: fix failing examples * fix(core): align typed MASM interfaces * refactor(air): reuse the Eidos odd-lane mask * fix: adapt the Eidos cutover to next * fix(eidos): validate memory ranges and streaming inputs * fix(eidos): require payload validation and correct MASM contracts * refactor: standardize PVM LogUp on centered residues * verifier: derive recursive geometry from AIR layouts * perf(pvm): cache proof-order auxiliary pointers * air: narrow And8 lookup auxiliary trace to five columns Pair the ten And8, rotation, and range-table interactions into five two-fraction LogUp columns. This narrows the standalone And8 auxiliary trace from 10 to 5 columns and the PVM BytePairAnd8 composite from 12 to 7 while preserving typed buses and independent residues. * air: narrow MVM Core main trace to 48 columns Replace the decoder's three operation-batch flags with a full-batch flag and compact short-batch code. * precompiles: narrow KeccakRound auxiliary trace to 12 columns Use the committed raw B bytes in BytePairLut messages and batch the byte and Range16 interactions four per LogUp column. This reduces the KeccakRound auxiliary trace from 20 to 12 extension columns while preserving degree 5 and log quotient degree 2. * precompiles: narrow UintStoreMul auxiliary trace to 27 columns * precompiles: narrow ChunkNodeSponge main trace to 99 columns * precompiles: narrow ChunkNodeSponge auxiliary trace to 24 columns * precompiles: narrow EcMsm auxiliary trace from 15 to 14 columns * precompiles: narrow EcMsm main trace from 46 to 41 columns * precompiles: narrow TranscriptEval auxiliary trace from 14 to 12 columns * air: reconcile width reductions with production guards * refactor: migrate PVM AIRs to shared LogUp implementation * refactor: unify PVM byte-pair lookups * air: narrow VM and PVM byte-pair tables to 7/5/4 * air: reconcile width reductions and regenerate verifier artifacts * chore: fix lints * bench: add reusable Eidos composition scaling campaign * air: reduce the Eidos lookup interface to two columns Pack EidosBlock and FullCv into one degree-three LogUp column while retaining the head-aware Init/Out boundary column. Pin the inactive packed witness and move frame-derived CV construction to transcript ownership. * test: isolate Eidos support helpers * bench: harden Eidos comparison provenance checks * docs: align documentation with current contracts * air: narrow transcript flags and EC ordering witnesses * air: share Keccak sponge XOR lookup columns * update docs * docs(precompiles): minor clean ups * refactor(air): share the Eidos compression core * refactor(air): share Eidos byte-pair rotation logic * refactor(air): share Eidos compression trace generation * perf(prover): parallelize PVM Eidos trace generation * fix(bench): require manual host setup * fix(air): tighten width-reduction invariants and trace generation * refactor: share Eidos footer constraint sequencing * fix: refresh the Eidos benchmark baseline * docs: restore changelog section spacing * feat(ace-codegen): add canonical multi-AIR ACE circuit builder Adds a layout, pipeline, and air-crate wrapper for a single order-invariant multi-AIR circuit shared by every proof order. Per-AIR fold coefficients are staged as beta^(N-1-pos(k)), computed from the height-sorted proof position, instead of read from a per-order registry entry. * feat(vm): evaluate the canonical ACE circuit in the recursive verifier Replaces the VM recursive verifier's per-proof-order registry lookup with evaluation of the single canonical circuit. Out-of-domain row segments and aux-bus boundary sums are scattered to their canonical addresses via dynexec at ingest time, the VM relation digest is re-minted against the canonical circuit digest, and the ACE circuit registry is deleted. * feat(pvm): evaluate the canonical ACE circuit in the recursive verifier Mirrors the VM cutover for the precompiles VM: builds the canonical recursive-verifier ACE circuit, scatters OOD segments and boundary values to canonical addresses, gates the evaluator on ingest being order-invariant, and deletes the factored per-order circuit machinery and proof-order tag storage. * docs(ace): describe the order-invariant cutover and drop stale registry references Documents the verifier ABI, proof-order handling, and PVM crate layout as they now stand; records the breaking change in CHANGELOG.md; deletes the dead order-tag derivation and the remaining stale registry references left over from the cutover. * fix(ace-codegen): double-word align MASM ACE read regions LayoutPolicy::masm() previously end-aligned READ regions to two EF variables (four base felts). adv_pipe moves eight felts, so layouts ending at the half-block boundary produced a misaligned circuit-stream base. Align to four EF variables and regenerate the VM/PVM circuits, protocol constants, verifier roots, generated docs, and pinned PVM proof fixture against final PR3. * docs: align canonical ACE contracts and harden scatter routing * fix(pvm): reconcile canonical ACE artifacts after width reductions * perf(ace): derive proof-order maps once per proof * fix(pvm): make constant regeneration rustfmt-safe * fix(ace): harden artifact regeneration * fix(ace): align order-map feature gates and documentation * refactor: simplify order-invariant ACE generation * fix(ace): correct test feature gate and verifier documentation * perf(ace): share one Lagrange basis across periodic columns of a period * fix columns accounting * docs(ace): clarify shared periodic basis evaluation * fix(eidos): account for restricted Fiat-Shamir challenges Use Eidos's 126-bit challenge sampling support in native and recursive MVM/PVM security estimates, with independent regression tests. * fix(eidos): preserve wire and storage compatibility * refactor(precompiles-prover): remove unused code * test(eidos): correct batch proof security expectation * perf(vm): reuse And8 trace and precompute its commitments * docs(air): align table columns across AIR documentation * refactor(air): group AEAD and Merkle lookup interactions * feat(lmcs): construct typed batch proofs directly from trees * refactor(crypto): simplify Eidos random-coin sampling * chore: clean up documentation and formatting after rebase * chore: resolve CI failures * fix(lifted-stark): support quotient domains smaller than SIMD packs * docs(changelog): restore Eidos notes and document LMCS changes * chore: eemove dead code * chore: fix ci * fix(serialization): version Merkle state and precompile witnesses --------- Co-authored-by: Robin Salen <salenrobin@gmail.com> | 5 天前 | |
Remove custom random sampling APIs (#3873) * refactor: remove custom random samplers * test: keep no-std feature coverage * docs: link random sampler changelog entry * test: sample random array elements * fix(field): retain Felt representation coverage | 16 天前 | |
[Tracking] Eidos integration (#3879) * vm: switch native hashing and proof transcripts to Eidos Make Eidos the VM-native hash across program, MAST, package, Merkle, advice-map, kernel, signature, AEAD, deferred-node, and proof-transcript commitments. Replace HPERM with COMPRESS and implement Eidos compression AEAD stream execution throughout assembly, the processor, trace generation, AIR, proving, verification, and recursive verification. Split the proof statement into the Core, Chiplets, EidosCompression, and And8Lookup components, with the fixed And8 table also serving range checks. Migrate deferred precompile nodes and the PVM to registered four-slot Eidos framing. Bind each chain head to its selector, payload length, two arguments, and reserved zero lane. * refactor: tighten Eidos VM integration Make the shared MVM/PVM compression structure easier to audit by centralizing narrow lookup-slot metadata and adding differential coverage for their common constraints. Nest AEAD stream flags under the bitwise selector interface, clarify trace matrix cloning, and remove redundant hasher forwarding layers. Pin the fixed Eidos preprocessed commitment to its canonical PCS blowup and strengthen adjacent validation, documentation, and MMR error tests. * chore: fix failing CI * chore: fix lint * chore: resolve remaining lints * feat: align the Eidos VM cutover with typed domains * refactor(air): simplify Eidos constraint definitions Consolidate AEAD phase, equality, XOR, and packing logic, and align bitwise layout names with the byte-oriented trace. * feat: complete the Eidos native-hash cutover Replace Poseidon2-based native hashing with Eidos across the VM, deferred computation, signatures, AEAD, and proof transcripts. Introduce checked EidosFrame framing and a CV-only deferred event ABI, bind PVM compression chains by head and tail, optimize generated MASM, and regenerate the affected AIR, verifier, proof, and fixture artifacts. * docs: clean up and improve structure of docs and comments * docs: align VM design documentation * fix: resolve Eidos stack integration lints * chore: fix failing examples * fix(core): align typed MASM interfaces * refactor(air): reuse the Eidos odd-lane mask * fix: adapt the Eidos cutover to next * fix(eidos): validate memory ranges and streaming inputs * fix(eidos): require payload validation and correct MASM contracts * refactor: standardize PVM LogUp on centered residues * verifier: derive recursive geometry from AIR layouts * perf(pvm): cache proof-order auxiliary pointers * air: narrow And8 lookup auxiliary trace to five columns Pair the ten And8, rotation, and range-table interactions into five two-fraction LogUp columns. This narrows the standalone And8 auxiliary trace from 10 to 5 columns and the PVM BytePairAnd8 composite from 12 to 7 while preserving typed buses and independent residues. * air: narrow MVM Core main trace to 48 columns Replace the decoder's three operation-batch flags with a full-batch flag and compact short-batch code. * precompiles: narrow KeccakRound auxiliary trace to 12 columns Use the committed raw B bytes in BytePairLut messages and batch the byte and Range16 interactions four per LogUp column. This reduces the KeccakRound auxiliary trace from 20 to 12 extension columns while preserving degree 5 and log quotient degree 2. * precompiles: narrow UintStoreMul auxiliary trace to 27 columns * precompiles: narrow ChunkNodeSponge main trace to 99 columns * precompiles: narrow ChunkNodeSponge auxiliary trace to 24 columns * precompiles: narrow EcMsm auxiliary trace from 15 to 14 columns * precompiles: narrow EcMsm main trace from 46 to 41 columns * precompiles: narrow TranscriptEval auxiliary trace from 14 to 12 columns * air: reconcile width reductions with production guards * refactor: migrate PVM AIRs to shared LogUp implementation * refactor: unify PVM byte-pair lookups * air: narrow VM and PVM byte-pair tables to 7/5/4 * air: reconcile width reductions and regenerate verifier artifacts * chore: fix lints * bench: add reusable Eidos composition scaling campaign * air: reduce the Eidos lookup interface to two columns Pack EidosBlock and FullCv into one degree-three LogUp column while retaining the head-aware Init/Out boundary column. Pin the inactive packed witness and move frame-derived CV construction to transcript ownership. * test: isolate Eidos support helpers * bench: harden Eidos comparison provenance checks * docs: align documentation with current contracts * air: narrow transcript flags and EC ordering witnesses * air: share Keccak sponge XOR lookup columns * update docs * docs(precompiles): minor clean ups * refactor(air): share the Eidos compression core * refactor(air): share Eidos byte-pair rotation logic * refactor(air): share Eidos compression trace generation * perf(prover): parallelize PVM Eidos trace generation * fix(bench): require manual host setup * fix(air): tighten width-reduction invariants and trace generation * refactor: share Eidos footer constraint sequencing * fix: refresh the Eidos benchmark baseline * docs: restore changelog section spacing * feat(ace-codegen): add canonical multi-AIR ACE circuit builder Adds a layout, pipeline, and air-crate wrapper for a single order-invariant multi-AIR circuit shared by every proof order. Per-AIR fold coefficients are staged as beta^(N-1-pos(k)), computed from the height-sorted proof position, instead of read from a per-order registry entry. * feat(vm): evaluate the canonical ACE circuit in the recursive verifier Replaces the VM recursive verifier's per-proof-order registry lookup with evaluation of the single canonical circuit. Out-of-domain row segments and aux-bus boundary sums are scattered to their canonical addresses via dynexec at ingest time, the VM relation digest is re-minted against the canonical circuit digest, and the ACE circuit registry is deleted. * feat(pvm): evaluate the canonical ACE circuit in the recursive verifier Mirrors the VM cutover for the precompiles VM: builds the canonical recursive-verifier ACE circuit, scatters OOD segments and boundary values to canonical addresses, gates the evaluator on ingest being order-invariant, and deletes the factored per-order circuit machinery and proof-order tag storage. * docs(ace): describe the order-invariant cutover and drop stale registry references Documents the verifier ABI, proof-order handling, and PVM crate layout as they now stand; records the breaking change in CHANGELOG.md; deletes the dead order-tag derivation and the remaining stale registry references left over from the cutover. * fix(ace-codegen): double-word align MASM ACE read regions LayoutPolicy::masm() previously end-aligned READ regions to two EF variables (four base felts). adv_pipe moves eight felts, so layouts ending at the half-block boundary produced a misaligned circuit-stream base. Align to four EF variables and regenerate the VM/PVM circuits, protocol constants, verifier roots, generated docs, and pinned PVM proof fixture against final PR3. * docs: align canonical ACE contracts and harden scatter routing * fix(pvm): reconcile canonical ACE artifacts after width reductions * perf(ace): derive proof-order maps once per proof * fix(pvm): make constant regeneration rustfmt-safe * fix(ace): harden artifact regeneration * fix(ace): align order-map feature gates and documentation * refactor: simplify order-invariant ACE generation * fix(ace): correct test feature gate and verifier documentation * perf(ace): share one Lagrange basis across periodic columns of a period * fix columns accounting * docs(ace): clarify shared periodic basis evaluation * fix(eidos): account for restricted Fiat-Shamir challenges Use Eidos's 126-bit challenge sampling support in native and recursive MVM/PVM security estimates, with independent regression tests. * fix(eidos): preserve wire and storage compatibility * refactor(precompiles-prover): remove unused code * test(eidos): correct batch proof security expectation * perf(vm): reuse And8 trace and precompute its commitments * docs(air): align table columns across AIR documentation * refactor(air): group AEAD and Merkle lookup interactions * feat(lmcs): construct typed batch proofs directly from trees * refactor(crypto): simplify Eidos random-coin sampling * chore: clean up documentation and formatting after rebase * chore: resolve CI failures * fix(lifted-stark): support quotient domains smaller than SIMD packs * docs(changelog): restore Eidos notes and document LMCS changes * chore: eemove dead code * chore: fix ci * fix(serialization): version Merkle state and precompile witnesses --------- Co-authored-by: Robin Salen <salenrobin@gmail.com> | 5 天前 | |
feat: AdviceInputs constructors and ProgramExecutor trait (#3540) * feat(core/advice): add AdviceInputs::new and From<AdviceMap> constructors Add a full constructor that assembles AdviceInputs from owned parts, and a From<AdviceMap> impl that defaults the stack and store. These complement the existing builder-style accessors (with_advice_stack, with_map, with_merkle_store). * refactor(processor)!: remove free execute()/execute_sync() functions No downstream consumer calls these. The only callers were in-repo tests and the miden-vm re-export. The prover and miden-base use FastProcessor directly because they need the trace or package-debug path. Removed the free functions and the miden-vm re-export, and moved every caller onto FastProcessor::new_with_options(...).execute[_sync](...). BREAKING CHANGE: use FastProcessor::new_with_options(...) followed by execute()/execute_sync() instead of the free functions. Refs #3538 * feat(processor): add ProgramExecutor trait with FastProcessor default impl Introduces a pluggable program-execution abstraction in miden-processor so that alternative execution backends (debuggers, instrumented executors, or other VMs) can be swapped in without touching the surrounding executor wiring. The trait is byte-for-byte faithful to the one already in miden-tx (which carries a TODO to move it into miden-vm), so downstream can later delete its local copy and re-export this one. FastProcessor is the default implementation: - new() wraps FastProcessor::new_with_options(), panicking on invalid advice inputs (matching the existing infallible-from-the-trait contract). - execute() delegates to FastProcessor::execute(). - execute_with_package_debug_info() routes to the package-debug entrypoints, selecting the source-node-anchored variant when an entrypoint node is given and falling back to the package-rooted variant otherwise. Documented on new() that, for the concrete FastProcessor type, the trait constructor is shadowed by the inherent 1-arg FastProcessor::new and so must be invoked via fully-qualified syntax <FastProcessor as ProgramExecutor>::new. Added three trait-dispatch tests: the default execute() path, the no-entrypoint-node fallback in execute_with_package_debug_info(), and the Some(entrypoint_source_node) arm routed through the trait (mirroring the existing package_source_debug_execution_uses_manifest_entrypoint_source_node inherent-method test). Refs #3538 * chore: Changelog * docs(miden-vm): fix README doctest after execute_sync removal The execution example doctest imported the free execute_sync from miden_vm and called it directly. That function was removed when the free execute()/ execute_sync() entrypoints were dropped in favor of FastProcessor. Rewrite the example to construct a FastProcessor via new_with_options and call execute_sync on it, matching the new API. Fixes the doc-tests CI failure on #3540. * refactor: address PR review feedback * chore: fix nightly formatting | 1 个月前 | |
Clean up processor error handling (#3230) * chore(processor): fold diagnostic help into errors * refactor(processor): name malformed mast error path * refactor(processor): consolidate binary value errors * chore: Changelog * test(vm): update loop binary value error match | 3 个月前 | |
Split debug info out of MastForest (#3221) * refactor(assembly): share metadata ref allocation * feat(assembly): track source mast occurrences * feat(package): emit source debug graph section * feat(package): emit source-keyed debug rows * feat(assembly): preserve source block ranges * feat(package): strip package debug sections * feat(package): add source debug lookups * fix(package): distrust wire debug info * feat(package): expose package debug info * fix(assembly): trim package source debug paths * feat(processor): add package source error context * feat(package): add source graph navigation * feat(package): add positional source child lookup * feat(package): add source debug cursor * feat(processor): thread package source debug context * Split debug info from MAST forests * Address debug info review findings * Fix source debug root preservation * Preserve package debug context during execution * Preserve source context for step and external resumes * Keep package source context on external load errors * Cover external package source error preservation * Fix split debuginfo CI checks * Cover static debug info linking * Fix package source debug invariants * Fix source child occurrence fallback * Cover duplicate source child fallback * Cover debug info metadata merge regressions * Reject legacy debug-bearing MastForest payloads * Remove source debug cursor API * Narrow FastProcessor source debug APIs * chore: Changelog * chore: Remove source graph dead code allowances * chore: Remove legacy MastForest DebugInfo * fix: Gate source path rewriting on std * fix: Discard untrusted package debug sections * fix: Document package debug trust policy * fix: Satisfy package debug CI lints * Remove source child exec lookup * Narrow source debug section APIs * Remove source exec lookup helper * test: Cover debugless package execution * refactor: remove unused debug context arguments * fix: preserve package debug assertion messages * perf: split pure processor execution path * refactor: tighten package debug source APIs * refactor: rename processor source node IDs * refactor: drop caller debug lookup for externals * refactor: trim debug info API surface * fix: adapt debug info split to path semantics * fix: reject trailing MastForest bytes * fix: make package file reads untrusted by default * fix: degrade ambiguous debug source lookups * fix: preserve package entrypoint source roots * fix: validate debug source operation ranges * fix: validate package debug table indices * docs: explain debug source node identity * refactor: move package debug errors * refactor: remove package debug serde derives * feat: deduplicate source map locations * feat: intern source map strings * test: cover untrusted package file mast validation * test: cover source debug selection for identical static calls * feat: port inline calls to source debug map * chore: clippy * docs: clarify unchecked package reader trust boundary * fix: address source debug review findings * test: fix static debug var assertion after block merge * feat: preserve loaded package debug info * fix: preserve package debug info across loading * fix: preserve source spans for malformed external packages * perf: reduce debug test build cost | 3 个月前 | |
fix: constrain U32DIV outputs in the AIR (#3604) | 1 个月前 | |
fix(ace): lower upper bound on number of wires allocated for ACE circuit evaluation (#3908) * Limit eval_circuit to 32,768 wires * docs: note eval_circuit wire limit in changelog * fix(ace): cap recorded circuit evaluations at 1024 * fix(ace): lower witness invocation limit to 32 --------- Co-authored-by: al <82364884+Al-Kindi-0@users.noreply.github.com> | 11 天前 | |
[Tracking] Eidos integration (#3879) * vm: switch native hashing and proof transcripts to Eidos Make Eidos the VM-native hash across program, MAST, package, Merkle, advice-map, kernel, signature, AEAD, deferred-node, and proof-transcript commitments. Replace HPERM with COMPRESS and implement Eidos compression AEAD stream execution throughout assembly, the processor, trace generation, AIR, proving, verification, and recursive verification. Split the proof statement into the Core, Chiplets, EidosCompression, and And8Lookup components, with the fixed And8 table also serving range checks. Migrate deferred precompile nodes and the PVM to registered four-slot Eidos framing. Bind each chain head to its selector, payload length, two arguments, and reserved zero lane. * refactor: tighten Eidos VM integration Make the shared MVM/PVM compression structure easier to audit by centralizing narrow lookup-slot metadata and adding differential coverage for their common constraints. Nest AEAD stream flags under the bitwise selector interface, clarify trace matrix cloning, and remove redundant hasher forwarding layers. Pin the fixed Eidos preprocessed commitment to its canonical PCS blowup and strengthen adjacent validation, documentation, and MMR error tests. * chore: fix failing CI * chore: fix lint * chore: resolve remaining lints * feat: align the Eidos VM cutover with typed domains * refactor(air): simplify Eidos constraint definitions Consolidate AEAD phase, equality, XOR, and packing logic, and align bitwise layout names with the byte-oriented trace. * feat: complete the Eidos native-hash cutover Replace Poseidon2-based native hashing with Eidos across the VM, deferred computation, signatures, AEAD, and proof transcripts. Introduce checked EidosFrame framing and a CV-only deferred event ABI, bind PVM compression chains by head and tail, optimize generated MASM, and regenerate the affected AIR, verifier, proof, and fixture artifacts. * docs: clean up and improve structure of docs and comments * docs: align VM design documentation * fix: resolve Eidos stack integration lints * chore: fix failing examples * fix(core): align typed MASM interfaces * refactor(air): reuse the Eidos odd-lane mask * fix: adapt the Eidos cutover to next * fix(eidos): validate memory ranges and streaming inputs * fix(eidos): require payload validation and correct MASM contracts * refactor: standardize PVM LogUp on centered residues * verifier: derive recursive geometry from AIR layouts * perf(pvm): cache proof-order auxiliary pointers * air: narrow And8 lookup auxiliary trace to five columns Pair the ten And8, rotation, and range-table interactions into five two-fraction LogUp columns. This narrows the standalone And8 auxiliary trace from 10 to 5 columns and the PVM BytePairAnd8 composite from 12 to 7 while preserving typed buses and independent residues. * air: narrow MVM Core main trace to 48 columns Replace the decoder's three operation-batch flags with a full-batch flag and compact short-batch code. * precompiles: narrow KeccakRound auxiliary trace to 12 columns Use the committed raw B bytes in BytePairLut messages and batch the byte and Range16 interactions four per LogUp column. This reduces the KeccakRound auxiliary trace from 20 to 12 extension columns while preserving degree 5 and log quotient degree 2. * precompiles: narrow UintStoreMul auxiliary trace to 27 columns * precompiles: narrow ChunkNodeSponge main trace to 99 columns * precompiles: narrow ChunkNodeSponge auxiliary trace to 24 columns * precompiles: narrow EcMsm auxiliary trace from 15 to 14 columns * precompiles: narrow EcMsm main trace from 46 to 41 columns * precompiles: narrow TranscriptEval auxiliary trace from 14 to 12 columns * air: reconcile width reductions with production guards * refactor: migrate PVM AIRs to shared LogUp implementation * refactor: unify PVM byte-pair lookups * air: narrow VM and PVM byte-pair tables to 7/5/4 * air: reconcile width reductions and regenerate verifier artifacts * chore: fix lints * bench: add reusable Eidos composition scaling campaign * air: reduce the Eidos lookup interface to two columns Pack EidosBlock and FullCv into one degree-three LogUp column while retaining the head-aware Init/Out boundary column. Pin the inactive packed witness and move frame-derived CV construction to transcript ownership. * test: isolate Eidos support helpers * bench: harden Eidos comparison provenance checks * docs: align documentation with current contracts * air: narrow transcript flags and EC ordering witnesses * air: share Keccak sponge XOR lookup columns * update docs * docs(precompiles): minor clean ups * refactor(air): share the Eidos compression core * refactor(air): share Eidos byte-pair rotation logic * refactor(air): share Eidos compression trace generation * perf(prover): parallelize PVM Eidos trace generation * fix(bench): require manual host setup * fix(air): tighten width-reduction invariants and trace generation * refactor: share Eidos footer constraint sequencing * fix: refresh the Eidos benchmark baseline * docs: restore changelog section spacing * feat(ace-codegen): add canonical multi-AIR ACE circuit builder Adds a layout, pipeline, and air-crate wrapper for a single order-invariant multi-AIR circuit shared by every proof order. Per-AIR fold coefficients are staged as beta^(N-1-pos(k)), computed from the height-sorted proof position, instead of read from a per-order registry entry. * feat(vm): evaluate the canonical ACE circuit in the recursive verifier Replaces the VM recursive verifier's per-proof-order registry lookup with evaluation of the single canonical circuit. Out-of-domain row segments and aux-bus boundary sums are scattered to their canonical addresses via dynexec at ingest time, the VM relation digest is re-minted against the canonical circuit digest, and the ACE circuit registry is deleted. * feat(pvm): evaluate the canonical ACE circuit in the recursive verifier Mirrors the VM cutover for the precompiles VM: builds the canonical recursive-verifier ACE circuit, scatters OOD segments and boundary values to canonical addresses, gates the evaluator on ingest being order-invariant, and deletes the factored per-order circuit machinery and proof-order tag storage. * docs(ace): describe the order-invariant cutover and drop stale registry references Documents the verifier ABI, proof-order handling, and PVM crate layout as they now stand; records the breaking change in CHANGELOG.md; deletes the dead order-tag derivation and the remaining stale registry references left over from the cutover. * fix(ace-codegen): double-word align MASM ACE read regions LayoutPolicy::masm() previously end-aligned READ regions to two EF variables (four base felts). adv_pipe moves eight felts, so layouts ending at the half-block boundary produced a misaligned circuit-stream base. Align to four EF variables and regenerate the VM/PVM circuits, protocol constants, verifier roots, generated docs, and pinned PVM proof fixture against final PR3. * docs: align canonical ACE contracts and harden scatter routing * fix(pvm): reconcile canonical ACE artifacts after width reductions * perf(ace): derive proof-order maps once per proof * fix(pvm): make constant regeneration rustfmt-safe * fix(ace): harden artifact regeneration * fix(ace): align order-map feature gates and documentation * refactor: simplify order-invariant ACE generation * fix(ace): correct test feature gate and verifier documentation * perf(ace): share one Lagrange basis across periodic columns of a period * fix columns accounting * docs(ace): clarify shared periodic basis evaluation * fix(eidos): account for restricted Fiat-Shamir challenges Use Eidos's 126-bit challenge sampling support in native and recursive MVM/PVM security estimates, with independent regression tests. * fix(eidos): preserve wire and storage compatibility * refactor(precompiles-prover): remove unused code * test(eidos): correct batch proof security expectation * perf(vm): reuse And8 trace and precompute its commitments * docs(air): align table columns across AIR documentation * refactor(air): group AEAD and Merkle lookup interactions * feat(lmcs): construct typed batch proofs directly from trees * refactor(crypto): simplify Eidos random-coin sampling * chore: clean up documentation and formatting after rebase * chore: resolve CI failures * fix(lifted-stark): support quotient domains smaller than SIMD packs * docs(changelog): restore Eidos notes and document LMCS changes * chore: eemove dead code * chore: fix ci * fix(serialization): version Merkle state and precompile witnesses --------- Co-authored-by: Robin Salen <salenrobin@gmail.com> | 5 天前 |
| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
| 5 天前 | ||
| 16 天前 | ||
| 5 天前 | ||
| 1 个月前 | ||
| 3 个月前 | ||
| 3 个月前 | ||
| 1 个月前 | ||
| 11 天前 | ||
| 5 天前 |