Skip to content

apollo_starknet_os_program,starknet_os,blockifier: emit the single-proof digest in the OS output - #15064

Open
einat-starkware wants to merge 1 commit into
claude/privacy-proof-os-verify-gsxf2h-10-verifier-testfrom
claude/privacy-proof-os-verify-gsxf2h-3-os-output
Open

einat-starkware wants to merge 1 commit into
claude/privacy-proof-os-verify-gsxf2h-10-verifier-testfrom
claude/privacy-proof-os-verify-gsxf2h-3-os-output

Conversation

@einat-starkware

@einat-starkware einat-starkware commented Aug 27, 2026 •

Copy link
Copy Markdown
Contributor

Part of the single-proof verification stack: the OS builds the proof-fact tree of a block's transaction with proof facts and emits its digest, which the aggregator verifies in #15162.

  • OS: records the proof facts of each invoke transaction that carries them (the pointers check_proof_facts already validated). At the end of the block it asserts there is at most one, computes that transaction's processed-proof output digest (its proof facts fill both of the multiverifier's verifier slots), and writes it packed into OsOutputHeader together with the transaction count (SIZE 9 → 12). A block without one writes zeros, and so does the virtual OS, whose check_proof_facts already rejects proof facts.
  • Aggregator: combine_blocks_inner sums the three header fields over the blocks, and combine_blocks asserts the total count is at most one. A block without a proof-facts transaction has zeros there, so the sums are the fields of the block that has one.
  • Rust: parses the new header fields and writes them in the aggregator's inner OS outputs. The flow tests check every OS run's fields against the Rust mirror (compute_leaf_output_digest, combine_leaf_digests, pack_output_digest).
  • test_proof_facts_versions_and_program_hashes submitted several proof-facts transactions in one block; it now runs each program-hash or proof-version variant in its own OS run.
  • The invoke transaction's OS step cost goes up 4779 → 4793, so test_simulate_validate_charge_fee_mid_execution's two gas constants derived from it go up by the same 14.
  • Regenerated: program hashes, bytecode lengths, allowed_virtual_os_program_hashes[2] (the current virtual OS hash, in constants.cairo and the 0.14.5 versioned constants) and the versioned-constants diff-regression pin.

Stack: #15092 ← #15086 ← #15164 ← #15161 ← #15166 ← #15167 ← #15168 ← #15169 ← #15163 ← this PR ← #15162

🤖 Generated with Claude Code

https://claude.ai/code/session_015X6kWZhBXFeNyPwSuKTohy

@cursor

cursor Bot commented Aug 27, 2026 •

Copy link
Copy Markdown

PR Summary

High Risk
Changes OS output layout, aggregation semantics, and program hashes—core proving and L1 state-update paths must stay aligned with consumers and the follow-on aggregator verification PR.

Overview
Extends the Starknet OS output so downstream verification can read a packed processed-proof digest for blocks that include client-side proof facts (at most one invoke per block).

OS: Invoke transactions with proof facts are recorded during execution; after the block, the OS enforces at most one such transaction, folds its proof facts into a multiverifier-style output digest (same leaf in both verifier slots), and writes processed_proof_output_low, processed_proof_output_high, and n_proof_facts_transactions into OsOutputHeader (header size 9 → 12) and serialized output. Virtual OS always emits zeros for these fields.

Aggregator: Multi-block combine sums the three header fields across inner outputs and asserts the aggregated n_proof_facts_transactions is 0 or 1 (blocks without proof facts contribute zeros).

Rust / tests: CommonOsOutput parsing and aggregator hint wiring include the new fields; flow tests compare against the Rust proof_fact_fold helpers. Proof-facts version/hash coverage now runs one OS execution per variant because a run supports only one proof-facts transaction. Invoke OS step budget rises 4779 → 4793 (versioned constants and related blockifier tests updated). OS, virtual OS, and aggregator program hashes and allowed virtual OS hash slot [2] are regenerated.

Reviewed by Cursor Bugbot for commit ce22f27. Bugbot is set up for automated code reviews on this repo. Configure here.

@reviewable-StarkWare

Copy link
Copy Markdown

This change is Reviewable

@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-os-output branch from 93dfeeb to 811a6c1 Compare September 2, 2026 11:43
@einat-starkware
einat-starkware changed the base branch from claude/privacy-proof-os-verify-gsxf2h-2-cairo-fold to claude/privacy-proof-os-verify-gsxf2h-4-cairo-tree-fold September 2, 2026 11:43
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-os-output branch 2 times, most recently from cb06bb9 to d1023d1 Compare September 2, 2026 12:29
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-os-output branch from d1023d1 to 7cc17ba Compare September 2, 2026 12:45
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-os-output branch from 7cc17ba to cb470b4 Compare September 2, 2026 13:11
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-os-output branch from cb470b4 to 96dd329 Compare September 2, 2026 13:41
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-os-output branch from 96dd329 to 5f9bd84 Compare September 17, 2026 13:36
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-os-output branch from 5f9bd84 to 93f03f6 Compare September 22, 2026 09:22
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-os-output branch 2 times, most recently from 4a34ec5 to db7bf69 Compare September 23, 2026 12:59
@einat-starkware
einat-starkware changed the base branch from claude/privacy-proof-os-verify-gsxf2h-4-cairo-tree-fold to claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest September 28, 2026 08:16
@einat-starkware
einat-starkware added this pull request to stack #15156 September 28, 2026 08:17
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-os-output branch from 95e3bff to 0be9141 Compare September 28, 2026 10:51
@einat-starkware
einat-starkware removed this pull request from stack #15156 September 30, 2026 10:51
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-os-output branch from 0be9141 to 480f61a Compare September 30, 2026 11:07
@einat-starkware
einat-starkware changed the base branch from claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest to claude/privacy-proof-os-verify-gsxf2h-6-combined-verify September 30, 2026 11:07
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-os-output branch from c66685a to f1e1134 Compare September 30, 2026 15:46
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-os-output branch from f1e1134 to 54cf3d4 Compare October 1, 2026 10:02
@einat-starkware
einat-starkware changed the base branch from claude/privacy-proof-os-verify-gsxf2h-6-combined-verify to claude/privacy-proof-os-verify-gsxf2h-10-verifier-test October 1, 2026 10:03
@einat-starkware
einat-starkware added this pull request to stack #15165 October 1, 2026 10:19
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-os-output branch from 54cf3d4 to 7ea39ab Compare October 1, 2026 12:21
@einat-starkware
einat-starkware removed this pull request from stack #15165 October 1, 2026 12:49
…oof digest in the OS output

The OS records the proof facts of each invoke transaction that carries them. At the end of a
block it asserts that there is at most one, and writes the packed output digest of its processed
proof into the OS output header, with the number of such transactions. The transaction's proof
facts fill both of the multiverifier's verifier slots. A block without one writes zeros, and so
does the virtual OS, which supports no proof facts.

The aggregator sums the three header fields over the blocks it combines, and asserts that the
total number of transactions with proof facts is at most one, so the sums are the fields of the
block that has one.

The Rust side parses the new header fields and writes them in the aggregator's inner OS outputs,
and the flow tests check every OS run's fields against the Rust mirror. The proof-facts flow test
runs each of its variants in its own OS run. The program hashes, the allowed virtual OS program
hash, and the invoke transaction's OS step cost are regenerated.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015X6kWZhBXFeNyPwSuKTohy

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants