apollo_starknet_os_program,starknet_os: verify the processed proof in the aggregator - #15162
Conversation
… the aggregator When the aggregated blocks contain a proof-facts transaction, the aggregator runs the circuit verifier on its processed proof as a simple bootloader task, writing the task's output to a scratch segment rather than to the aggregator's output. It then checks the verifier's program hash against a pinned value and the verifier's output against the verification digest of the processed proof output digest the blocks emitted. The aggregator hint processor is wrapped by the bootloader hint processor of cairo-program-runner-lib, which runs the bootloader's hints and the verifier's Cairo1 hints. The aggregator input gains the circuit verifier task (the verifier executable and the processed proof). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015X6kWZhBXFeNyPwSuKTohy
PR SummaryHigh Risk Overview After On the Rust side, aggregator runs go through Tests cover a successful golden processed proof, rejection when proof facts do not match, and failure when proof facts are present without a verifier task. Reviewed by Cursor Bugbot for commit e2da678. Bugbot is set up for automated code reviews on this repo. Configure here. |
|
Artifacts upload workflows: |
Part of milestone 3 of the single-proof verification stack, and its main PR: the aggregator verifies the processed proof of the aggregated blocks' proof-facts transaction in Cairo0, so the proof of the aggregator run covers the check.
Cairo (
aggregator/verify_processed_proof.cairo, called frommain.cairoaftercombine_blocks): when the combined header'sn_proof_facts_transactionsis 1, the aggregator:run_simple_bootloader(apollo_starknet_os_program: copy the simple bootloader's task execution #15160), as a single Blake-hashed task.outputandrange_check, so they're never passed to it, and the bootloader validates that they didn't move.[1 task, size 10, CIRCUIT_VERIFIER_PROGRAM_HASH, 8 digest words]. The task count is written by a hint, so it's checked before the output is read.compute_verification_digest(unpack_output_digest(low, high))(apollo_starknet_os_program,starknet_os: unpack the processed-proof output digest in Cairo #15161).Rust:
run_aggregator_programwraps the aggregator hint processor incairo-program-runner-lib'sBootloaderHintProcessoras itsextra_hint_processor. The aggregator's own hints and the Cairo0 core hints still go to the aggregator hint processor first. The bootloader's hints and the verifier's Cairo1 hints go to the bootloader hint processor.run_programno longer requiresCommonHintProcessor, which it never used.AggregatorInput.circuit_verifier_task: Option<CircuitVerifierTaskInput>, holding the verifier executable path and the processed proof path.EnterCircuitVerifierTaskScopeaggregator hint builds the task (create_cairo1_program_task). It fails withMissingCircuitVerifierTaskif the blocks contain a proof-facts transaction and the input has no task.starkware.cairo.bootloaders.simple_bootloadermodule, whichcairo-program-runner-libruns.Tests (in
aggregator/test.rs, using #15088's verifier and processed-proof fixtures):test_aggregator_verifies_processed_proof: the golden leaf's processed digest in a block's header. The run succeeds, and the aggregator's output is unchanged apart from the header fields, so the verifier's output doesn't leak into it.test_aggregator_rejects_processed_proof_of_other_proof_facts: the digest of other proof facts fails inassert_digests_equal. With the digest comparison removed, this test fails.test_aggregator_requires_circuit_verifier_task_for_proof_facts.The aggregator program hashes change; the OS and virtual OS hashes don't.
Not in this PR: producing the processed proof and passing it into the aggregator input in production, publishing (or not) the digest in the aggregator's output, and the production verifier's program hash (TODO next to the pinned canonical_small value).
Stack: ← #15064 ← #15160 ← #15161 ← this PR
🤖 Generated with Claude Code
https://claude.ai/code/session_015X6kWZhBXFeNyPwSuKTohy
Generated by Claude Code