starknet_os: add the digests of a single transaction's processed proof - #15091
Conversation
PR SummaryMedium Risk Overview Adds Tests are refactored around shared golden proof facts and assert leaf, processed-proof (same golden leaf in both multiverifier slots), and verification digests against proving-side goldens. Reviewed by Cursor Bugbot for commit 161b81e. Bugbot is set up for automated code reviews on this repo. Configure here. |
09152c9 to
f914da4
Compare
4b3a51b to
d4070d3
Compare
d4070d3 to
8654747
Compare
03569d2 to
e667ed1
Compare
e667ed1 to
3b5bea4
Compare
a494c30 to
050ae2f
Compare
Yoni-Starkware
left a comment
There was a problem hiding this comment.
@Yoni-Starkware reviewed 2 files and all commit messages, and made 1 comment.
Reviewable status:complete! all files reviewed, all discussions resolved (waiting on einat-starkware).
The proving side processes a transaction's proof into a proof of the multiverifier circuit, whose output packs the verified proof's circuit hash and output digest twice. This adds the Rust computation of that processed proof's output digest and of the verification digest the circuit verifier outputs for it, over a single transaction's proof facts. Golden values are reproduced from the proving side over the leaf fixture of stwo_run_and_prove_recursive_tree. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XmPJM3Wph4QLmFmhcxVsh4
050ae2f to
161b81e
Compare
|
Security scan complete — no issues detected. Generated by Claude Code |
Part 2 of the single-proof verification stack: one transaction's proof, verified against the OS output. Combining proof facts across transactions is out of scope and deferred to a later phase — the code here treats the problem as a single transaction with a single proof facts array.
The proving side processes proofs into a proof of the multiverifier circuit, whose output packs the circuit hash and output digest of each of the proofs verified in its two verifier slots. This PR adds the Rust computation of:
compute_processed_proof_output_digest: the processed proof's output digest over two verified proofs' facts. The function is general (two proof-facts arguments); a single transaction's proof fills both slots, so callers pass the same proof facts twice.compute_verification_digest: the digest the circuit verifier outputs when run on the processed proof —blake2s(multiverifier circuit hash ‖ the processed proof's output digest).Golden values are proving-side confirmed:
stwo_run_and_prove_recursive_tree(proving commitb75d21f9) over the golden leaf reproduces the processed proof's output digest exactly (see #15088's fixture).Per review preference, the code carries no comments beyond short doc lines.
Stack: #15090 ← this PR ← #15092 ← #15064 ← #15086 ← #15088 ← #15095.
🤖 Generated with Claude Code
https://claude.ai/code/session_01XmPJM3Wph4QLmFmhcxVsh4