apollo_starknet_os_program,starknet_os,blockifier: emit the single-proof digest in the OS output - #15064
Conversation
PR SummaryHigh Risk Overview OS: Invoke transactions with proof facts are recorded during execution; after the block, the OS enforces at most one such transaction, folds its proof facts into a multiverifier-style output digest (same leaf in both verifier slots), and writes Aggregator: Multi-block combine sums the three header fields across inner outputs and asserts the aggregated Rust / tests: Reviewed by Cursor Bugbot for commit ce22f27. Bugbot is set up for automated code reviews on this repo. Configure here. |
93dfeeb to
811a6c1
Compare
cb06bb9 to
d1023d1
Compare
d1023d1 to
7cc17ba
Compare
7cc17ba to
cb470b4
Compare
cb470b4 to
96dd329
Compare
96dd329 to
5f9bd84
Compare
5f9bd84 to
93f03f6
Compare
4a34ec5 to
db7bf69
Compare
95e3bff to
0be9141
Compare
0be9141 to
480f61a
Compare
c66685a to
f1e1134
Compare
f1e1134 to
54cf3d4
Compare
54cf3d4 to
7ea39ab
Compare
…oof digest in the OS output The OS records the proof facts of each invoke transaction that carries them. At the end of a block it asserts that there is at most one, and writes the packed output digest of its processed proof into the OS output header, with the number of such transactions. The transaction's proof facts fill both of the multiverifier's verifier slots. A block without one writes zeros, and so does the virtual OS, which supports no proof facts. The aggregator sums the three header fields over the blocks it combines, and asserts that the total number of transactions with proof facts is at most one, so the sums are the fields of the block that has one. The Rust side parses the new header fields and writes them in the aggregator's inner OS outputs, and the flow tests check every OS run's fields against the Rust mirror. The proof-facts flow test runs each of its variants in its own OS run. The program hashes, the allowed virtual OS program hash, and the invoke transaction's OS step cost are regenerated. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015X6kWZhBXFeNyPwSuKTohy
7ea39ab to
ce22f27
Compare
Part of the single-proof verification stack: the OS builds the proof-fact tree of a block's transaction with proof facts and emits its digest, which the aggregator verifies in #15162.
check_proof_factsalready validated). At the end of the block it asserts there is at most one, computes that transaction's processed-proof output digest (its proof facts fill both of the multiverifier's verifier slots), and writes it packed intoOsOutputHeadertogether with the transaction count (SIZE9 → 12). A block without one writes zeros, and so does the virtual OS, whosecheck_proof_factsalready rejects proof facts.combine_blocks_innersums the three header fields over the blocks, andcombine_blocksasserts the total count is at most one. A block without a proof-facts transaction has zeros there, so the sums are the fields of the block that has one.compute_leaf_output_digest,combine_leaf_digests,pack_output_digest).test_proof_facts_versions_and_program_hashessubmitted several proof-facts transactions in one block; it now runs each program-hash or proof-version variant in its own OS run.test_simulate_validate_charge_fee_mid_execution's two gas constants derived from it go up by the same 14.allowed_virtual_os_program_hashes[2](the current virtual OS hash, inconstants.cairoand the 0.14.5 versioned constants) and the versioned-constants diff-regression pin.Stack: #15092 ← #15086 ← #15164 ← #15161 ← #15166 ← #15167 ← #15168 ← #15169 ← #15163 ← this PR ← #15162
🤖 Generated with Claude Code
https://claude.ai/code/session_015X6kWZhBXFeNyPwSuKTohy