Skip to content

apollo_starknet_os_program,starknet_os: add the Cairo0 processed-proof digests - #15092

Open
einat-starkware wants to merge 1 commit into
mainfrom
claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest
Open

einat-starkware wants to merge 1 commit into
mainfrom
claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest

Conversation

@einat-starkware

@einat-starkware einat-starkware commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Part 3 of the single-proof verification stack (single transaction, single proof facts; no combining).

The Cairo0 mirror of #15091: the proof output digest over a transaction's proof facts, the processed proof's output digest over two verified proofs' facts (matching the Rust signature — the single transaction's caller passes the same proof facts into both of the multiverifier's verifier slots), the verification digest, and the two circuit hash constants. Straight-line computations — no entry structs, no circuit tables or indexes. Compiled standalone as a test program; not yet reachable from the OS program (that lands in #15064).

The Cairo leaf, processed-proof and verification digests are tested against the proving side's goldens, and the leaf combination also against the Rust mirror over two different leaves, which the golden can't distinguish.

Stack: #15090 ← #15091 ← this PR ← #15086 ← #15164 ← #15161 ← #15166 ← #15167 ← #15168 ← #15169 ← #15163 ← #15064 ← #15162

🤖 Generated with Claude Code

https://claude.ai/code/session_01XmPJM3Wph4QLmFmhcxVsh4

@cursor

cursor Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
Test-only Cairo mirror and VM parity tests; no changes to production OS execution paths or auth/data handling.

Overview
Adds a standalone Cairo0 proof_fact_fold test program that mirrors the existing Rust proof-fact folding logic for single-proof verification: leaf output digest from proof facts (Blake2s over program-hash onward), processed proof output from two leaf digests via the leaf verifier circuit hash, verification digest from the multiverifier circuit hash, plus pack_output_digest and hard-coded leaf/multiverifier circuit hashes.

The build wires proof_fact_fold.cairo into compile_test_contracts and exposes PROOF_FACT_FOLD_BYTES for tests. proof_fact_fold_test now runs each digest function through the Cairo VM and asserts bit-exact agreement with Rust on proving-side goldens, and adds a combine_leaf_digests case with two different leaves so swapped-slot bugs are not masked by the symmetric golden.

The program is compiled for tests only; it is not linked into the main OS program yet (follow-up PR).

Reviewed by Cursor Bugbot for commit 56efe34. Bugbot is set up for automated code reviews on this repo. Configure here.

@reviewable-StarkWare

Copy link
Copy Markdown

This change is Reviewable

@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest branch from 3893cae to b23d2c2 Compare September 2, 2026 12:13
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest branch 2 times, most recently from f0196fe to ed8eb88 Compare September 2, 2026 12:45
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest branch 2 times, most recently from d33ec72 to efaa234 Compare September 2, 2026 13:41
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest branch from efaa234 to 1fcfd19 Compare September 17, 2026 13:36
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest branch from 1fcfd19 to 02eab67 Compare September 22, 2026 09:22
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest branch from 02eab67 to c8828fe Compare September 23, 2026 09:17
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest branch from c8828fe to 0ce5d55 Compare September 23, 2026 12:59
@einat-starkware einat-starkware changed the title apollo_starknet_os_program,starknet_os: add the Cairo0 proof-fact leaf digest apollo_starknet_os_program,starknet_os: add the Cairo0 single-proof root entry Sep 23, 2026
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest branch from 0ce5d55 to b4dbf64 Compare September 23, 2026 14:56
@einat-starkware einat-starkware changed the title apollo_starknet_os_program,starknet_os: add the Cairo0 single-proof root entry apollo_starknet_os_program,starknet_os: add the Cairo0 processed-proof digests Sep 23, 2026
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest branch from b4dbf64 to 997d51e Compare September 24, 2026 13:28
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest branch 2 times, most recently from 749e90b to 4514e83 Compare September 28, 2026 08:01
@einat-starkware
einat-starkware removed this pull request from stack #15094 September 28, 2026 08:16
@einat-starkware
einat-starkware added this pull request to stack #15156 September 28, 2026 08:17
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest branch from 4514e83 to 6928755 Compare September 28, 2026 10:51
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-3-cairo-leaf-digest branch from 6928755 to 130c34b Compare September 30, 2026 07:47
Base automatically changed from claude/privacy-proof-os-verify-gsxf2h-2-rust-tree-fold to main September 30, 2026 09:38
…f digests

The Cairo0 mirror of the single-transaction processed-proof digests: the
proof output digest over the transaction's proof facts, the processed
proof's output digest, and the verification digest the circuit verifier
outputs for it. Compiled standalone as a test program; not yet reachable
from the OS program.

The Cairo and Rust digests are tested against the proving side's
goldens, and the leaf combination also against the Rust mirror for two
different leaves, which the golden cannot distinguish.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XmPJM3Wph4QLmFmhcxVsh4

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants