Skip to content

apollo_starknet_os_program: verify a processed proof with the circuit verifier - #15161

Open
einat-starkware wants to merge 1 commit into
claude/privacy-proof-os-verify-gsxf2h-7-copy-bootloaderfrom
claude/privacy-proof-os-verify-gsxf2h-8-cairo-unpack
Open

einat-starkware wants to merge 1 commit into
claude/privacy-proof-os-verify-gsxf2h-7-copy-bootloaderfrom
claude/privacy-proof-os-verify-gsxf2h-8-cairo-unpack

Conversation

@einat-starkware

@einat-starkware einat-starkware commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Part of the single-proof verification stack. Adds the Cairo code that verifies a transaction's processed proof by running the circuit verifier. #15163 tests it, and the aggregator calls it once the OS output carries the digest (#15162).

verify_processed_proof(low, high) in aggregator/verify_processed_proof.cairo:

  1. Runs the circuit verifier on the processed proof with the copied run_simple_bootloader (apollo_starknet_os_program: copy the simple bootloader's task execution #15164), as a single Blake-hashed task. The caller puts the task in scope as the simple_bootloader_input hint variable.
  2. Writes the bootloader's output to a scratch segment, not to the aggregator's output.
  3. Passes placeholder pointers for the builtins the aggregator doesn't have (ecdsa, bitwise, keccak, range_check96, add_mod, mul_mod). The verifier's program hash is pinned and its program uses only output and range_check, so they're never passed to it, and the bootloader validates that they didn't move.
  4. Asserts the bootloader output starts with [1 task, size 10, CIRCUIT_VERIFIER_PROGRAM_HASH]. The task count is written by a hint, and the bootloader asserts the size cell equals how far the task moved the output pointer, so the size bounds the 8 digest words read next.
  5. Unpacks low and high into the 8 digest words with the common library's split_int (4 words of 32 bits each, each range checked; a half at or above 2^128 is rejected), and asserts the verifier's 8 words equal compute_verification_digest of them.

Nothing calls verify_processed_proof yet, so no program hash changes.

Stack: #15092 ← #15086 ← #15164 ← this PR ← #15166 ← #15167 ← #15168 ← #15169 ← #15163 ← #15064 ← #15162

🤖 Generated with Claude Code

https://claude.ai/code/session_015X6kWZhBXFeNyPwSuKTohy

@cursor

cursor Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
New proof-verification path with pinned verifier hash and digest checks; not wired into the aggregator yet, but mistakes here would affect trust in processed proofs once integrated.

Overview
Adds verify_processed_proof in the Starknet aggregator Cairo layer as the hook for single-proof verification: it runs the pinned circuit verifier as a one-task simple bootloader job (input via the simple_bootloader_input hint), captures output in a scratch segment, and enforces that the task count, output size, and Blake program hash match expectations.

After the verifier runs, it unpacks the OS-provided processed-proof output digest from two 128-bit felts with split_int (rejecting halves ≥ 2^128), recomputes the expected digest via compute_verification_digest, and asserts word-for-word equality with the verifier’s 8-word output. A pinned CIRCUIT_VERIFIER_PROGRAM_HASH is used for now (noted TODO for production verifier). Nothing in-tree calls this yet, so aggregator program hashes are unchanged in this PR.

Reviewed by Cursor Bugbot for commit be0d9cd. Bugbot is set up for automated code reviews on this repo. Configure here.

@reviewable-StarkWare

Copy link
Copy Markdown

This change is Reviewable

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Artifacts upload workflows:

… verifier

Adds verify_processed_proof, the aggregator's check of a processed proof against its packed
output digest. It runs the circuit verifier on the processed proof as a simple bootloader task,
writing the task's output to a scratch segment, and checks that the verifier's program hash is
the pinned one and that its output is the verification digest of the output digest. The packed
digest is unpacked with split_int, which range checks each 32-bit word.

Nothing calls verify_processed_proof yet, so no program hash changes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015X6kWZhBXFeNyPwSuKTohy
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-8-cairo-unpack branch from 55a5754 to be0d9cd Compare October 1, 2026 12:21
@einat-starkware einat-starkware changed the title apollo_starknet_os_program,starknet_os: verify a processed proof with the circuit verifier apollo_starknet_os_program: verify a processed proof with the circuit verifier Oct 1, 2026
@einat-starkware
einat-starkware removed this pull request from stack #15165 October 1, 2026 12:49
@einat-starkware
einat-starkware added this pull request to stack #15170 October 1, 2026 13:06

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants