Skip to content

starknet_os: add the digests of a single transaction's processed proof - #15091

Merged
einat-starkware merged 1 commit into
claude/privacy-proof-os-verify-gsxf2h-1-rust-leaf-digestfrom
claude/privacy-proof-os-verify-gsxf2h-2-rust-tree-fold
Sep 30, 2026
Merged

einat-starkware merged 1 commit into
claude/privacy-proof-os-verify-gsxf2h-1-rust-leaf-digestfrom
claude/privacy-proof-os-verify-gsxf2h-2-rust-tree-fold

Conversation

@einat-starkware

@einat-starkware einat-starkware commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Part 2 of the single-proof verification stack: one transaction's proof, verified against the OS output. Combining proof facts across transactions is out of scope and deferred to a later phase — the code here treats the problem as a single transaction with a single proof facts array.

The proving side processes proofs into a proof of the multiverifier circuit, whose output packs the circuit hash and output digest of each of the proofs verified in its two verifier slots. This PR adds the Rust computation of:

  • compute_processed_proof_output_digest: the processed proof's output digest over two verified proofs' facts. The function is general (two proof-facts arguments); a single transaction's proof fills both slots, so callers pass the same proof facts twice.
  • compute_verification_digest: the digest the circuit verifier outputs when run on the processed proof — blake2s(multiverifier circuit hash ‖ the processed proof's output digest).
  • The leaf verifier and multiverifier circuit hash constants (pinned to the vendored registry in apollo_starknet_os_program,starknet_os: cite the circuit hashes' source and add todos #15086).

Golden values are proving-side confirmed: stwo_run_and_prove_recursive_tree (proving commit b75d21f9) over the golden leaf reproduces the processed proof's output digest exactly (see #15088's fixture).

Per review preference, the code carries no comments beyond short doc lines.

Stack: #15090 ← this PR ← #15092 ← #15064 ← #15086 ← #15088 ← #15095.

🤖 Generated with Claude Code

https://claude.ai/code/session_01XmPJM3Wph4QLmFmhcxVsh4

@cursor

cursor Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
New cryptographic digest logic must match the prover exactly; wrong constants or hashing would break verification, though behavior is pinned by proving-side golden tests and circuit hashes are explicitly temporary.

Overview
Extends proof_fact_fold with the processed-proof and verification digest steps for single-transaction proof checking, matching the proving side’s recursive multiverifier tree.

Adds LEAF_VERIFIER_CIRCUIT_HASH and MULTIVERIFIER_CIRCUIT_HASH (currently canonical_small placeholders; TODO to swap for production registry values). combine_leaf_digests hashes two leaf outputs by Blake2s over (leaf circuit hash ‖ leaf digest) for each side and concatenating. compute_verification_digest is Blake2s over multiverifier circuit hash ‖ processed proof output digest.

Tests are refactored around shared golden proof facts and assert leaf, processed-proof (same golden leaf in both multiverifier slots), and verification digests against proving-side goldens.

Reviewed by Cursor Bugbot for commit 161b81e. Bugbot is set up for automated code reviews on this repo. Configure here.

@reviewable-StarkWare

Copy link
Copy Markdown

This change is Reviewable

@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-2-rust-tree-fold branch 2 times, most recently from 09152c9 to f914da4 Compare September 2, 2026 12:29
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-2-rust-tree-fold branch 2 times, most recently from 4b3a51b to d4070d3 Compare September 2, 2026 13:11
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-2-rust-tree-fold branch from d4070d3 to 8654747 Compare September 15, 2026 13:35
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-2-rust-tree-fold branch 4 times, most recently from 03569d2 to e667ed1 Compare September 23, 2026 12:59
@einat-starkware einat-starkware changed the title starknet_os: add the privacy proof-fact fold tree starknet_os: add the privacy single-proof root entry and digest Sep 23, 2026
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-2-rust-tree-fold branch from e667ed1 to 3b5bea4 Compare September 23, 2026 14:56
@einat-starkware einat-starkware changed the title starknet_os: add the privacy single-proof root entry and digest starknet_os: add the digests of a single transaction's processed proof Sep 23, 2026
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-2-rust-tree-fold branch 3 times, most recently from a494c30 to 050ae2f Compare September 28, 2026 08:01
@einat-starkware
einat-starkware removed this pull request from stack #15094 September 28, 2026 08:16
@einat-starkware
einat-starkware added this pull request to stack #15156 September 28, 2026 08:17

@Yoni-Starkware Yoni-Starkware left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:lgtm:

@Yoni-Starkware reviewed 2 files and all commit messages, and made 1 comment.
Reviewable status: :shipit: complete! all files reviewed, all discussions resolved (waiting on einat-starkware).

The proving side processes a transaction's proof into a proof of the
multiverifier circuit, whose output packs the verified proof's circuit
hash and output digest twice. This adds the Rust computation of that
processed proof's output digest and of the verification digest the
circuit verifier outputs for it, over a single transaction's proof
facts. Golden values are reproduced from the proving side over the leaf
fixture of stwo_run_and_prove_recursive_tree.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XmPJM3Wph4QLmFmhcxVsh4
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-2-rust-tree-fold branch from 050ae2f to 161b81e Compare September 30, 2026 07:47
@einat-starkware
einat-starkware added this pull request to the merge queue Sep 30, 2026
Merged via the queue into main with commit 7723950 Sep 30, 2026
24 of 26 checks passed

Copy link
Copy Markdown
Contributor

Security scan complete — no issues detected.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants