Project
Changelog
User-visible changes to the StateSync-GKR component, release by release, with unreleased changes listed first.
This changelog records user-visible changes to the StateSync-GKR component. It follows the Keep a Changelog (opens in a new tab) format, with the newest entries first. The entries are taken from CHANGELOG.md in the source repository (opens in a new tab). For what each version number means, see Versioning.
1.1.1#
The licensing revision of 1.1.0.
Changed#
- Licensing: The maintained branch and every version after 1.1.0 are licensed under the Business Source License 1.1. Its Additional Use Grant covers production use solely to verify proofs, and each version converts to the Apache License 2.0 three years after its first public distribution under that license. Rights already granted to recipients of 1.1.0 and earlier copies remain valid. The workspace manifests, CITATION.cff and the package inventory declare BUSL-1.1, and the historical program and proof identity is unchanged. See Licensing.
- Contribution terms: CONTRIBUTING.md records the contribution license grant that the Business Source License and commercial licensing require.
1.1.0 - 2026-10-04#
Published as a signed release under the MIT License or the Apache License 2.0, the terms in effect before the license change.
Added#
- Four Isabelle sessions that transfer the GKR soundness chain from the KoalaBear base field to the exact degree-four extension field used for verifier challenges: nonsquare certificates, the quartic field instance with cardinality
p^4and the base-field embedding, polynomial, multilinear-extension and circuit lifting, and the exact-field GKR soundness instance with a conditional uniform-coefficient pushforward. Verifier_Acceptance_Refinement, which relates a successful acceptance trace of the shipped Rust verifier to the reduction-chain event of the GKR assembly result and states the reverse direction as a non-claim.- An acceptance trace populated from the actual public-input, request-guard, zero-output, protocol-result and final input-MLE observations, with a proved classifier contract, compiled in the test and translation configurations only.
- Fail-closed shape guards in the protocol verifier for an empty circuit, a layer-proof count mismatch and an output width at or above the machine word width, each with a direct rejection test.
- Honest, tampered-public-input, tampered-sumcheck, false-carry and final input-MLE executable witnesses, and a direct last-layer protocol-boundary witness.
- A
release/v1.1baseline for the new program identity, with its own protected-source manifest, frozen-source allowlist and verifier. The verifier also holds the supersededrelease/v1.0baseline to one recorded digest so the earlier record cannot be edited. - Packaging-root tests for the controlled-identity payload validator, including one that pins the identity-bound source selection so that a silent drift fails in the ordinary test lane rather than at a rebuild.
Changed#
- The hosted Proofs workflow builds all six registered sessions.
- The sumcheck, per-layer GKR and facade verifier bodies no longer opt out of translation as a whole. Each opt-out was narrowed to the single foreign extension-field equality it needs, leaving the surrounding rejection and acceptance control flow translated as ordinary code.
- The controlled-identity payload validator accepts both an OCI index and a single manifest as the packaging root and separates packaging drift from payload drift.
- The two-clean-builds recipe anchors its ancestry check on the repository's own root commit, so it runs on the published repository, and its optional identity guard accepts either release line's expected-identity file.
- The release line moved to 1.1 with a new program identity.
release/v1.0stays byte-frozen as the record of the previous cycle.
Limits#
- The exact relation between Rust values and the off-cube polynomial representation is not discharged. This release adds no axiom, trusted claim, Fiat-Shamir theorem, compiled-Rust semantics, whole-program refinement, deployment or production-readiness claim.
- Two source-bound and task-bound type-invariant leaves remain open and carry no claim: the
mle_eval_baseresult type invariant and the shared verifier body's opaque derived-wiring entry type invariant. No third open leaf is accepted, and the trusted count is unchanged. - The ordinary build keeps the original short-circuit rejection form. The accumulating acceptance-trace form exists only in the test and translation configurations, and the equivalence of the two forms is part of the relation that is not discharged.
1.0.0 candidate - 2026-08-27#
A completed component baseline, retained as historical evidence. No tag or release was published for this candidate. Summary:
Added#
- Layered GKR proving and verification over compiled sparse-Merkle membership, non-membership and single-leaf update operations.
- Registered Isabelle sessions for GKR assembly and sparse-Merkle compiler correctness, building with no admitted proof, with concrete non-vacuity instances over the production field.
- Bounded Rust-to-model refinement evidence with explicit trusted and tool boundaries.
- Independent-job batching with pointwise single-job agreement checks and proof bytes that do not depend on worker count.
- Canonical prepared-material encoding with local reconstruction of derived wiring.
- A fixed RISC Zero program identity, a public proof content address and a saved-proof verification path.
- Canonical route, receipt, destination-policy and local candidate-transition encodings, with equality checks between the Rust and Python implementations.
- Release-surface tooling: an exact frozen-source manifest, a finite allowlist of historical source annotations, a public-surface verifier and a deterministic source archive recipe.
- Dual-license dispatcher, security policy, governance, support, contribution, citation and disclaimer documents.
Changed#
- Public documentation separates the component evidence from external receipt operation, deployed destination behavior, native rollup proving, parent settlement and finality on a destination chain.
- Public release evidence uses semantic names and content addresses.
Security#
- The published proof is bound to the exact protected source. A change to a protected byte is a new candidate identity and is never accepted by updating expected hashes.