apollo_starknet_os_program: verify a processed proof with the circuit verifier - #15161
Conversation
PR SummaryMedium Risk Overview After the verifier runs, it unpacks the OS-provided processed-proof output digest from two 128-bit felts with Reviewed by Cursor Bugbot for commit be0d9cd. Bugbot is set up for automated code reviews on this repo. Configure here. |
a04a772 to
55a5754
Compare
|
Artifacts upload workflows: |
… verifier Adds verify_processed_proof, the aggregator's check of a processed proof against its packed output digest. It runs the circuit verifier on the processed proof as a simple bootloader task, writing the task's output to a scratch segment, and checks that the verifier's program hash is the pinned one and that its output is the verification digest of the output digest. The packed digest is unpacked with split_int, which range checks each 32-bit word. Nothing calls verify_processed_proof yet, so no program hash changes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015X6kWZhBXFeNyPwSuKTohy
55a5754 to
be0d9cd
Compare
Part of the single-proof verification stack. Adds the Cairo code that verifies a transaction's processed proof by running the circuit verifier. #15163 tests it, and the aggregator calls it once the OS output carries the digest (#15162).
verify_processed_proof(low, high)inaggregator/verify_processed_proof.cairo:run_simple_bootloader(apollo_starknet_os_program: copy the simple bootloader's task execution #15164), as a single Blake-hashed task. The caller puts the task in scope as thesimple_bootloader_inputhint variable.outputandrange_check, so they're never passed to it, and the bootloader validates that they didn't move.[1 task, size 10, CIRCUIT_VERIFIER_PROGRAM_HASH]. The task count is written by a hint, and the bootloader asserts the size cell equals how far the task moved the output pointer, so the size bounds the 8 digest words read next.lowandhighinto the 8 digest words with the common library'ssplit_int(4 words of 32 bits each, each range checked; a half at or above 2^128 is rejected), and asserts the verifier's 8 words equalcompute_verification_digestof them.Nothing calls
verify_processed_proofyet, so no program hash changes.Stack: #15092 ← #15086 ← #15164 ← this PR ← #15166 ← #15167 ← #15168 ← #15169 ← #15163 ← #15064 ← #15162
🤖 Generated with Claude Code
https://claude.ai/code/session_015X6kWZhBXFeNyPwSuKTohy