37 static constexpr size_t comm_frs = FrCodec::calc_num_fields<Commitment>();
38 static constexpr size_t eval_frs = FrCodec::calc_num_fields<FF>();
51 table_commitments[0] = table_commitments[0] *
FF(2);
62 const size_t idx = translator_proof.size() - tail_size;
65 translator_proof[idx] = translator_proof[idx] + translator_proof[idx];
75 static constexpr size_t evals_after_op = 3;
76 const size_t op_eval_idx = eccvm_proof.size() - evals_after_op;
79 eccvm_proof[op_eval_idx] +=
FF(1);
94 auto goblin_proof = goblin.
prove();
98 auto ultra_ops_table_columns = goblin.
op_queue->construct_ultra_ops_table_columns();
101 table_commitments[idx] = pcs_commitment_key.
commit(ultra_ops_table_columns[idx]);
106 recursive_table_commitments[idx] = RecursiveCommitment::from_witness(outer_builder, table_commitments[idx]);
109 recursive_table_commitments[idx].unset_free_witness_tag();
113 return { goblin_proof, table_commitments, recursive_table_commitments };
125 auto [proof, table_commitments, recursive_table_commitments] = create_goblin_avm_prover_output(&
builder);
130 auto output = verifier.reduce_to_pairing_check_and_ipa_opening();
133 inputs.pairing_inputs = output.translator_pairing_points;
134 inputs.ipa_claim = output.ipa_claim;
137 builder.ipa_proof = output.ipa_proof.get_value();
139 info(
"Recursive Verifier: num gates = ",
builder.num_gates());
148 auto verification_key =
151 OuterProver prover(prover_instance, verification_key);
152 OuterVerifier verifier(vk_and_hash);
153 auto proof = prover.construct_proof();
154 bool verified = verifier.verify_proof(proof).result;
156 ASSERT_TRUE(verified);
169 auto [proof, table_commitments, recursive_table_commitments] = create_goblin_avm_prover_output(&
builder);
172 for (
auto& val : proof.eccvm_proof) {
182 auto goblin_rec_verifier_output = verifier.reduce_to_pairing_check_and_ipa_opening();
193 EXPECT_FALSE(native_result);
206 auto [proof, table_commitments, _] = create_goblin_avm_prover_output(&
builder);
207 TableCommitments tampered_table_commitments = table_commitments;
208 tamper_with_op_commitment(tampered_table_commitments);
210 RecursiveTableCommitments recursive_table_commitments;
212 recursive_table_commitments[idx] =
213 RecursiveCommitment::from_witness(&
builder, tampered_table_commitments[idx]);
214 recursive_table_commitments[idx].fix_witness();
220 auto goblin_rec_verifier_output = verifier.reduce_to_pairing_check_and_ipa_opening();
227 goblin_rec_verifier_output.translator_pairing_points.P0.get_value(),
228 goblin_rec_verifier_output.translator_pairing_points.P1.get_value());
229 bool pairing_result = native_pairing_points.
check();
230 EXPECT_FALSE(pairing_result);
236 auto [proof, table_commitments, recursive_table_commitments] = create_goblin_avm_prover_output(&
builder);
237 auto tampered_proof = proof;
238 tamper_with_libra_eval(tampered_proof.translator_proof);
243 [[maybe_unused]]
auto goblin_rec_verifier_output = verifier.reduce_to_pairing_check_and_ipa_opening();
256 auto [proof, table_commitments, recursive_table_commitments] = create_goblin_avm_prover_output(&
builder);
258 tamper_with_eccvm_op_eval(proof.eccvm_proof);
263 [[maybe_unused]]
auto goblin_rec_verifier_output = verifier.reduce_to_pairing_check_and_ipa_opening();
#define BB_DISABLE_ASSERTS()
Common transcript class for both parties. Stores the data for the current round, as well as the manif...
CommitmentKey object over a pairing group 𝔾₁.
Commitment commit(PolynomialSpan< const Fr > polynomial) const
Uses the ProverSRS to create a commitment to p(X)
Simple verification key class for fixed-size circuits (ECCVM, Translator).
Specialization of Goblin for the AVM.
GoblinAvmProof prove()
Constuct a full GoblinAvm proof (ECCVM, Translator)
TranslatorFlavor::VerificationKey TranslatorVerificationKey
ECCVMFlavor::VerificationKey ECCVMVerificationKey
Curve::AffineElement Commitment
std::array< Commitment, UltraCircuitBuilder::NUM_WIRES > TableCommitments
std::shared_ptr< OpQueue > op_queue
IPA (inner product argument) commitment scheme class.
static constexpr size_t NUM_WIRES
static void construct_arithmetic_circuit(Builder &builder, const size_t target_log2_dyadic_size=4, bool include_public_inputs=true)
Populate a builder with a specified number of arithmetic gates; includes a PI.
Unverified claim (C,r,v) for some witness polynomial p(X) such that.
auto get_native_opening_claim() const
An object storing two EC points that represent the inputs to a pairing check.
bool check() const
Perform the pairing check.
A ProverInstance is normally constructed from a finalized circuit and it contains all the information...
static bool check(const Builder &circuit)
Check the witness satisifies the circuit.
Curve::AffineElement Commitment
UltraCircuitBuilder CircuitBuilder
UltraRollupFlavor extends UltraFlavor with IPA proof support.
Representation of the Grumpkin Verifier Commitment Key inside a bn254 circuit.
bb::GoblinAvmRecursiveVerifier::Commitment RecursiveCommitment
UltraRollupFlavor::Commitment Commitment
bb::GoblinAvmRecursiveVerifier::TableCommitments RecursiveTableCommitments
static void tamper_with_libra_eval(HonkProof &translator_proof)
static void SetUpTestSuite()
static ProverOutput create_goblin_avm_prover_output(OuterBuilder *outer_builder)
Create a goblin proof and the VM verification keys needed by the goblin recursive verifier.
static constexpr size_t comm_frs
std::array< Commitment, UltraCircuitBuilder::NUM_WIRES > TableCommitments
static constexpr size_t eval_frs
static void tamper_with_op_commitment(TableCommitments &table_commitments)
static void tamper_with_eccvm_op_eval(HonkProof &eccvm_proof)
The data that is propagated on the public inputs of a rollup circuit.
std::filesystem::path bb_crs_path()
void init_file_crs_factory(const std::filesystem::path &path)
std::shared_ptr< factories::CrsFactory< curve::Grumpkin > > get_grumpkin_crs_factory()
TEST_F(BoomerangGoblinRecursiveVerifierTests, graph_description_basic)
Construct and check a goblin recursive verification circuit.
std::vector< fr > HonkProof
BaseTranscript< stdlib::StdlibCodec< stdlib::field_t< UltraCircuitBuilder > >, stdlib::poseidon2< UltraCircuitBuilder > > UltraStdlibTranscript
MegaCircuitBuilder_< field< Bn254FrParams > > MegaCircuitBuilder
constexpr decltype(auto) get(::tuplet::tuple< T... > &&t) noexcept
RecursiveTableCommitments recursive_table_commitments
TableCommitments table_commitments