Reference
API reference
The public Rust API of StateSync-GKR, starting from the statesync_gkr facade and covering every re-exported module, with signatures, return values, errors and feature requirements.
This reference lists the public items reachable from the statesync_gkr crate in a normal build of the 1.1 documentation line, checked against the source. Most applications need only the facade. The lower modules matter when you build a custom frontend, inspect proof objects or work with the external wrap path.
Conventions#
- Paths are written from the facade, for example
statesync_gkr::compiler::SmtParams. - Items compiled only for the formal-verification toolchain (
cfg(creusot)) or only for tests (cfg(test)) are not part of the API and are omitted. Test-only types that other pages mention, such asDenseLayerOracle, are marked as such. - Requires
hostmarks items compiled only with thehostfeature. The feature is on by default; zkVM guests disable default features. - The workspace packages carry the Cargo version
0.1.0-devand are not published to crates.io (publish = false). Depend on the source, as described in Installation; Versioning explains how package and release versions relate. - Error types implement
DebugandClonebut notstd::fmt::Displayorstd::error::Error, so format them with{:?}. The two exceptions, noted below, are in host-only modules ofwrap.
Module map#
| Facade path | Workspace crate | Contents |
|---|---|---|
statesync_gkr | Facade, with types from ssgkr-verification | StateSyncProver, PreparedSync, configuration, request and result types |
statesync_gkr::primitives | ssgkr-primitives | Fields, Poseidon2 hashing and the Fiat-Shamir transcript |
statesync_gkr::sumcheck | ssgkr-sumcheck | Multilinear sumcheck prover and verifier |
statesync_gkr::gkr | ssgkr-protocol | Layered circuits, MLE helpers, GKR prover and verifier, wiring oracles |
statesync_gkr::compiler | ssgkr-compiler | SMT types, native semantics, circuit compiler and witness generation |
statesync_gkr::batching | ssgkr-batching | Job queue and deadline-aware batch scheduling |
statesync_gkr::wrap | ssgkr-wrap | Circuit commitment, inner-proof encoding, wrap statement, prepared material and external-route reference models |
ssgkr-commitment is reachable as statesync_gkr::wrap::commitment. The free functions of ssgkr-verification (circuit_for, prove_sync_op, prove_on, verify_sync_op, verify_sync_op_reference and verify_sync_op_with) are not re-exported; the facade exposes the same pipeline as methods of StateSyncProver.
The facade#
StateSyncProver#
pub struct StateSyncProver { pub config: StateSyncGkrConfig } implements Debug and Default. It does not implement Clone; to create another prover, clone the configuration.
Construction and preparation
| Method | Returns | Description |
|---|---|---|
new(config: StateSyncGkrConfig) | Self | Creates a prover for one configuration. |
prepare(&self, kind: SmtOpKind) | Result<PreparedSync, SyncError> | Compiles the circuit with hints, derives the wiring oracle and computes the full circuit commitment once for kind. Fails with SyncError::Compile for an unsupported configuration. |
prepare_pinned_d24_a_membership(&self, bytes: &[u8]) | Result<PreparedSync, wrap::prepared::PreparedMaterialError> | Builds prepared state from the reviewed depth-24, strategy-A, Membership material without compiling. Fails with ConfigMismatch unless the configuration is depth 24, leaf bound 31 and strategy A, and with a validation error for any other bytes. |
Proving
| Method | Returns | Description |
|---|---|---|
prove_sync_op(&self, request: &SyncRequest) | Result<SyncResult, SyncError> | Compiles, generates the witness, computes the commitment and proves one request. Fails with SyncError::Compile or SyncError::Witness. |
prove_sync_op_prepared(&self, prepared: &PreparedSync, request: &SyncRequest) | Result<SyncResult, SyncError> | Generates the witness and proves against prepared state. The proof bytes equal those of prove_sync_op. Fails with SyncError::Witness. |
Jobs and batches
| Method | Returns | Description |
|---|---|---|
make_job(&self, request: &SyncRequest) | Result<batching::ProveJob, SyncError> | Compiles and generates the witness for one job. |
make_job_prepared(&self, prepared: &PreparedSync, request: &SyncRequest) | Result<batching::ProveJob, SyncError> | Generates the witness for one job against prepared state. |
prove_batch(&self, kind: SmtOpKind, jobs: &[batching::ProveJob]) | Vec<gkr::GkrProof> | Compiles once and proves each job in order. Returns an empty vector when the configuration does not compile. |
prove_batch_prepared(&self, prepared: &PreparedSync, jobs: &[batching::ProveJob]) | Vec<gkr::GkrProof> | Proves the jobs sequentially over the prepared circuit, in input order. |
prove_batch_parallel(&self, prepared: &PreparedSync, jobs: &[batching::ProveJob]) | Vec<gkr::GkrProof> | Requires host. Proves the jobs on the current Rayon pool and returns the proofs in input order, identical to prove_batch_prepared. For a fixed worker count, build a pool with Rayon's ThreadPoolBuilder and call this method inside the pool's install. |
The prepared proving methods do not check in release builds that a request or job has the prepared operation kind; prove_sync_op_prepared and make_job_prepared check it only with a debug assertion. Check the kind before proving. Verification against the same prepared state returns false for a mismatched kind.
Verification
| Method | Returns | Description |
|---|---|---|
verify_sync_op(&self, request: &SyncRequest, result: &SyncResult) | bool | Compiles, derives the wiring and recomputes the commitment on every call, then verifies. |
verify_sync_op_prepared(&self, prepared: &PreparedSync, request: &SyncRequest, result: &SyncResult) | bool | Verifies with prepared state. Returns false when the request's kind differs from the prepared kind. |
verify_sync_op_reference(&self, request: &SyncRequest, result: &SyncResult) | bool | Verifies with the general TableWiring oracle; an audit reference for the derived oracle. |
Encoding
| Method | Returns | Description |
|---|---|---|
circuit_identity(&self, prepared: &PreparedSync) | Result<wrap::encoding::CircuitIdentity, wrap::encoding::EncodeError> | The inner-proof-v1 circuit identity of the prepared kind under this configuration. Fails with EncodeError::CountOverflow when leaf_max_fields does not fit in a u16. |
encode_sync_result(&self, prepared: &PreparedSync, result: &SyncResult) | Result<Vec<u8>, wrap::encoding::EncodeError> | Canonical inner-proof-v1 bytes. Never includes the witness. |
verify_encoded_sync_op(&self, prepared: &PreparedSync, request: &SyncRequest, bytes: &[u8]) | bool | Decodes strictly, compares the decoded identity with the locally computed one, then runs prepared verification against request. |
External wrap
| Method | Returns | Description |
|---|---|---|
wrap_relation(&self, prepared: &PreparedSync, request: &SyncRequest, encoded_inner: &[u8]) | Option<wrap::statement::WrapStatementV1> | Returns the wrap statement exactly when the bytes decode to this configuration's identity and the inner verifier accepts them for request. |
wrap_sync_op<B: wrap::WrapBackend>(&self, backend: &B, prepared: &PreparedSync, request: &SyncRequest, encoded_inner: &[u8]) | Result<wrap::WrappedProof, wrap::WrapError> | Checks wrap_relation first, calls the backend, and rejects a result whose statement differs from the locally computed one. |
Usage: Quickstart, Prepared execution, Batching and parallelism, Encoding and transport and the prove-and-verify example (opens in a new tab).
PreparedSync#
PreparedSync implements Clone and Debug and has private fields. It holds the compiled circuit, the derived wiring and the full circuit commitment for one operation kind and configuration. It is immutable after construction, so one instance can serve every worker thread.
| Method | Returns | Description |
|---|---|---|
kind(&self) | SmtOpKind | The operation kind this preparation serves. |
circuit_commitment(&self) | &Digest<BaseField> | The full circuit commitment that proofs made with this preparation absorb. |
Configuration and value types#
| Item | Definition | Notes |
|---|---|---|
StateSyncGkrConfig | struct with smt: compiler::SmtParams, layer_strategy: compiler::LayerStrategy, batching: batching::BatchPolicy | Clone, Debug, Default. Also at statesync_gkr::config. See Configuration. |
SyncRequest | struct with operation: compiler::SmtOperation, witness: compiler::SmtWitness, public_inputs: compiler::PublicInputs | Clone, Debug. Also at statesync_gkr::oss_interface. |
SyncResult | struct with public_inputs: compiler::PublicInputs, proof: gkr::GkrProof | Clone, Debug. Also at statesync_gkr::oss_interface. |
SyncError | enum: Compile(compiler::CompileError), Witness(compiler::SmtError) | Clone, Debug. |
DOMAIN_TAG_V01 | &[u8], the bytes statesync-gkr/v0.1 | The domain tag every proof transcript absorbs first. |
Host integration seam#
| Item | Definition | Notes |
|---|---|---|
OssCoreInterface | trait with fn next_request(&mut self) -> Option<SyncRequest> and fn deliver(&mut self, result: SyncResult) | The minimal contract a host core implements toward the prover: a source of requests and a sink of results. |
MockOssCore | struct with requests: Vec<SyncRequest>, delivered: Vec<SyncResult> | In-memory implementation for tests and development. next_request takes from the front of requests. |
Both are also at statesync_gkr::oss_interface.
statesync_gkr::compiler#
The SMT frontend: operation types, native semantics, compilation and witness generation.
Types#
| Item | Definition | Notes |
|---|---|---|
SmtParams | struct with depth: u32, leaf_max_fields: u32 | Default depth 24 and leaf bound 31. Copy, PartialEq. |
LayerStrategy | enum: A, B { merge_k: u32 }, C | Default A. Only A compiles. |
AssetId | struct AssetId(pub u64) | Tree key. Copy, Ord, Hash. |
LeafPayload | struct with sync_state: Vec<BaseField>, identity_digest: [u8; 32] | Payload of an occupied leaf. |
LeafState | enum: Empty, Occupied(LeafPayload), Tombstone | Default Empty. encode(&self) -> Vec<BaseField>. |
MerklePath | struct with siblings: Vec<Digest<BaseField>> | Leaf level first. See compute_root below. |
SmtOperation | enum: Membership { key, payload }, NonMembership { key }, Update { key, old_leaf, new_leaf } | kind(&self) -> SmtOpKind. |
SmtOpKind | enum: Membership, NonMembership, Update | Selects the circuit. Copy, Hash. |
SmtWitness | struct with leaf: LeafState, path: MerklePath | For an update, leaf is the old leaf. |
PublicInputs | struct with old_root, new_root, op_kind_tag: u8, asset_id: AssetId, value_digest | Roots and value digest are Digest<BaseField>. kind_tag(kind: SmtOpKind) -> u8 returns 0, 1 or 2. |
SmtError | enum: PathLengthMismatch { expected, found }, KeyOutOfRange { key, depth }, LeafEncoding(HashError) | Implements From<HashError>. |
CompileError | enum: UnsupportedConfig { reason: &'static str }, NonUnaryGate { layer, out } | |
InputLayout | struct with public kind, depth, input_width | new(kind, depth, leaf_max_fields) and offset accessors leaf_pre, leaf_lanes, acc(l), sib(l), key_bit(l), root, value_digest, leaf_pre2, acc2(l), root2, has_second. |
MerklePath::compute_root<H: HashGadget>(&self, hasher: &H, params: &SmtParams, key: AssetId, leaf: &LeafState) -> Result<Digest<BaseField>, SmtError> recomputes the root of a leaf under this path. It fails on a wrong path length, an out-of-range key or an unhashable leaf encoding.
Functions#
| Function | Returns | Description |
|---|---|---|
compile(params: &SmtParams, kind: SmtOpKind, strategy: LayerStrategy, template: &HashRoundTemplate) | Result<LayeredCircuit<BaseField>, CompileError> | Compiles the circuit for one kind. Rejects strategies other than A, depth 0 and a leaf_max_fields below 10 with UnsupportedConfig. |
compile_with_hints(params: &SmtParams, kind: SmtOpKind, strategy: LayerStrategy, _template: &HashRoundTemplate) | Result<(LayeredCircuit<BaseField>, WiringHints), CompileError> | The same circuit plus layout hints for DerivedRegularWiring. The template argument is not read; the facade passes the hasher's round_template(). |
generate_witness(params: &SmtParams, _strategy: LayerStrategy, circuit: &LayeredCircuit<BaseField>, op: &SmtOperation, public_inputs: &PublicInputs, witness: &SmtWitness) | Result<CircuitWitness<BaseField>, SmtError> | Builds the input vector and evaluates the circuit. The strategy argument is not read. |
build_input_vector(params: &SmtParams, input_width_bits: usize, op: &SmtOperation, public_inputs: &PublicInputs, witness: &SmtWitness) | Result<Vec<BaseField>, SmtError> | The circuit input vector, padded to 2^input_width_bits. The verifier uses it to discharge the input claims. |
smt_valid_native<H: HashGadget>(hasher: &H, params: &SmtParams, op: &SmtOperation, old_root: &Digest<BaseField>, new_root: &Digest<BaseField>, witness: &SmtWitness) | Result<bool, SmtError> | Native reference semantics. Checks a witness directly, without a circuit or proof. |
validate_unary_gates(circuit: &LayeredCircuit<BaseField>) | Result<(), CompileError> | Rejects Lin or Pow3 gates whose in2 differs from in1. |
is_accepting<F: Field>(witness: &CircuitWitness<F>) | bool | True when every output wire is zero. |
Circuit builder#
compiler::builder contains the auto-layering builder the compiler uses: Builder with new, scope, unscope, input, constant, affine, sum, sub, mul, pow3, combine, build and build_with_hints; the node handle NodeId; TapKind with Lin and Cube; and width_bits(n: usize) -> usize. The modules compiler::compile, compiler::params, compiler::smt and compiler::witness are public, and their items are re-exported at compiler.
statesync_gkr::primitives#
The thin adapter over Plonky3 0.4.3. It is the only crate that names Plonky3 paths.
Fields#
| Item | Definition |
|---|---|
BaseField | Type alias for KoalaBear, p = 2^31 - 2^24 + 1 |
ChallengeField | Type alias for BinomialExtensionField<BaseField, 4> |
CHALLENGE_EXT_DEGREE | usize constant, 4 |
These three are re-exported at primitives. The module primitives::field also re-exports the Plonky3 traits ExtensionField, Field, PrimeCharacteristicRing, PrimeField32 and PrimeField64, and the type BinomialExtensionField.
Hashing#
| Item | Definition | Notes |
|---|---|---|
DIGEST_WIDTH | usize constant, 8 | Field elements per digest |
LEAF_SPONGE_RATE | usize constant, 8 | Lanes absorbed per leaf-hash permutation |
DEFAULT_LEAF_MAX_FIELDS | usize constant, 31 | Default leaf encoding bound |
Digest<F> | struct Digest<F>(pub [F; DIGEST_WIDTH]) | Copy, PartialEq. Digest::zero() returns the all-zero digest. |
HashError | enum: EncodingTooLong { len, max }, EmptyEncoding | |
HashGadget | trait | compress(&self, left: &Digest<BaseField>, right: &Digest<BaseField>) -> Digest<BaseField>, hash_leaf(&self, payload: &[BaseField]) -> Result<Digest<BaseField>, HashError>, round_template(&self) -> HashRoundTemplate |
Poseidon2Gadget | struct implementing HashGadget | new(leaf_max_fields: usize), Default with bound 31, leaf_max_fields(&self) -> usize, permutation() returning the width-16 permutation, hash_leaf_pre(&self, pre: &[BaseField]) -> Digest<BaseField> |
DefaultHasher | Type alias for Poseidon2Gadget | |
HashRoundTemplate | struct with rounds: usize, layers_per_compression: usize | Advisory circuit metadata: 28 rounds and 29 layers per compression for Poseidon2 |
KeccakDigestBytes | Type alias for [u8; 32] | Off-circuit identity digest |
leaf_pre_width(leaf_max_fields: usize) -> usize | function | Leaf pre-image width: leaf_max_fields + 1 rounded up to a multiple of 8 |
leaf_fold(payload: &[BaseField], leaf_max_fields: usize) -> Result<Vec<BaseField>, HashError> | function | Fixed-width leaf pre-image: tag, length, encoding, zeros |
All of these are in primitives::hash. HashRoundTemplate and KeccakDigestBytes are only there; the others are also re-exported at primitives.
Transcript#
primitives::Transcript is the Fiat-Shamir transcript, a Poseidon2 duplex sponge. It implements sumcheck::ChallengeSource<ChallengeField>.
| Method | Description |
|---|---|
new(domain_tag: &[u8]) -> Self | Creates a transcript seeded with a domain tag, one field element per byte. |
observe_base(&mut self, x: BaseField) | Absorbs one base-field element. |
observe_digest(&mut self, d: &Digest<BaseField>) | Absorbs the eight elements of a digest. |
observe_many(&mut self, xs: &[BaseField]) | Absorbs a slice of base-field elements. |
observe_ext(&mut self, x: ChallengeField) | Absorbs the four basis coefficients of an extension element. |
sample_challenge(&mut self) -> ChallengeField | Draws one challenge from the extension field. |
Poseidon2 arithmetization#
primitives::poseidon2_arith exposes the permutation as plain field data for the compiler: the constants P2_WIDTH (16), P2_EXTERNAL_HALF_ROUNDS (4), P2_INTERNAL_ROUNDS (20) and P2_SBOX_DEGREE (3); the 16 by 16 linear-layer matrices external_matrix() and internal_matrix(); the round constants external_initial_rc(), external_final_rc() and internal_rc(); and permute(state: [BaseField; 16]) -> [BaseField; 16], the native reference permutation.
statesync_gkr::sumcheck#
The multilinear sumcheck protocol. It has no SMT dependency.
| Item | Definition | Notes |
|---|---|---|
SumcheckInstance<F> | struct with num_vars: usize, degree_bound: usize, claimed_sum: F | The public statement of one run |
SumcheckOracle<F: Field> | trait: num_vars(&self) -> usize, degree_bound(&self) -> usize, round_poly(&self) -> RoundPoly<F>, bind(&mut self, r: F) | The prover's polynomial; bind fixes the current variable |
ChallengeSource<F> | trait: observe_round_poly(&mut self, poly: &RoundPoly<F>), draw_challenge(&mut self) -> F | Implemented by primitives::Transcript for ChallengeField |
SumcheckProof<F> | struct with round_polys: Vec<RoundPoly<F>> | Round polynomials in round order |
Subclaim<F> | struct with point: Vec<F>, expected_eval: F | The residual claim the caller must discharge |
SumcheckError | enum: DegreeExceeded { round }, SumMismatch { round }, WrongRoundCount { expected, found } | |
prove | fn prove<F, O, C>(oracle: &mut O, challenges: &mut C) -> (SumcheckProof<F>, Subclaim<F>) where F: Field, O: SumcheckOracle<F>, C: ChallengeSource<F> | Drives the oracle through every round |
verify | fn verify<F, C>(instance: &SumcheckInstance<F>, proof: &SumcheckProof<F>, challenges: &mut C) -> Result<Subclaim<F>, SumcheckError> where F: Field, C: ChallengeSource<F> | Checks round count, degree and the running sum each round |
The module sumcheck::poly defines three more types, re-exported at sumcheck:
| Item | Methods | Notes |
|---|---|---|
MultilinearPoly<F> | from_evals(evals: Vec<F>) -> Result<Self, PolyError>, num_vars(&self) -> usize, evals(&self) -> &[F], evaluate(&self, point: &[F]) -> F, fix_first_var(&mut self, r: F) | Evaluation table of length 2^n. evaluate panics when the point length differs from num_vars; fix_first_var panics when no variable is left. |
RoundPoly<F> | from_coeffs(coeffs: Vec<F>) -> Self, coeffs(&self) -> &[F], degree(&self) -> usize, eval_at(&self, x: F) -> F | Ascending coefficients. degree is the coefficient count minus one, so trailing zeros count. |
PolyError | enum: NotPowerOfTwo { len } |
statesync_gkr::gkr#
The layered-circuit representation and the GKR protocol. It has no SMT dependency.
Proof objects and drivers#
| Item | Definition | Notes |
|---|---|---|
LayerProof | struct with sumcheck: SumcheckProof<ChallengeField>, eval_x: ChallengeField, eval_y: ChallengeField | One layer's messages |
GkrProof | struct with layer_proofs: Vec<LayerProof> | Output layer first. Clone, PartialEq. |
InputClaim | struct with point, expected_eval, point_y, expected_eval_y | Two residual claims on the input vector; the caller must check both |
GkrError | enum: Sumcheck { layer, source }, LayerClaimMismatch { layer }, ShapeMismatch | |
prove | fn prove(circuit: &LayeredCircuit<BaseField>, witness: &CircuitWitness<BaseField>, transcript: &mut Transcript) -> GkrProof | The transcript must already hold the caller's preamble and claimed outputs |
verify | fn verify<W: WiringOracle<ChallengeField>>(circuit: &LayeredCircuit<BaseField>, wiring: &W, claimed_outputs: &[BaseField], proof: &GkrProof, transcript: &mut Transcript) -> Result<InputClaim, GkrError> | The transcript must hold the same preamble as the prover's |
Circuits#
Defined in gkr::circuit and re-exported at gkr:
| Item | Definition | Notes |
|---|---|---|
GateKind | enum: Lin, Mul, Pow3 | |
Gate<F> | struct with kind: GateKind, out: u32, in1: u32, in2: u32, coeff: F | Unary kinds set in2 equal to in1 |
Layer<F> | struct with width_bits: usize, gates: Vec<Gate<F>>, consts: Vec<(u32, F)> | width(&self) -> usize |
LayeredCircuit<F> | struct with layers: Vec<Layer<F>>, input_width_bits: usize | Output layer first. depth(&self) -> usize |
CircuitWitness<F> | struct with layer_values: Vec<Vec<F>> | Output layer first, inputs last |
CircuitError | enum: InputWidthMismatch { expected, found }, WireOutOfRange { layer } | |
evaluate_circuit | fn evaluate_circuit<F: Field>(circuit: &LayeredCircuit<F>, inputs: &[F]) -> Result<CircuitWitness<F>, CircuitError> | Native circuit semantics |
gate_semantics | fn gate_semantics<F: Field>(kind: GateKind, a: F, b: F) -> F | Gate value before the coefficient |
Multilinear extensions#
gkr::mle: embed(x: BaseField) -> ChallengeField, cf_u64(k: u64) -> ChallengeField, eq_point_index(point: &[ChallengeField], idx: usize) -> ChallengeField, eq_points(a: &[ChallengeField], b: &[ChallengeField]) -> ChallengeField, eq3_points(a, b, c) -> ChallengeField, mle_eval_base(values: &[BaseField], point: &[ChallengeField]) -> ChallengeField and mle_eval_ext(values: &[ChallengeField], point: &[ChallengeField]) -> ChallengeField. Variable 0 is the most significant index bit, and a table must have 2^point.len() entries.
Layer reduction#
gkr::reduce contains LAYER_ROUND_DEGREE (4), the per-round degree bound of every layer sumcheck, and the prove and verify functions that gkr::prove and gkr::verify call. The production prover oracle, SparseLayerOracle, is private; DenseLayerOracle is test-only.
Wiring#
Defined in gkr::wiring. The items marked "root" are also re-exported at gkr.
| Item | Definition | Notes |
|---|---|---|
WiringOracle<F: Field> (root) | trait: out_width_bits(&self, layer: usize) -> usize, in_width_bits(&self, layer: usize) -> usize, eval_predicate_mle(&self, layer: usize, kind: GateKind, z: &[F], x: &[F], y: &[F]) -> F, eval_const_mle(&self, layer: usize, z: &[F]) -> F | What the GKR verifier asks of the circuit structure |
TableWiring<'a> | new(circuit: &'a LayeredCircuit<BaseField>) -> Self | General oracle over a concrete gate list |
DerivedRegularWiring (root) | derive(circuit: &LayeredCircuit<BaseField>, hints: &WiringHints) -> Self, expand_gates(&self, layer: usize) -> Vec<Gate<BaseField>>, expand_consts(&self, layer: usize) -> Vec<(u32, BaseField)>, stats(&self) -> DerivedStats | Production closed-form oracle; derivation never fails |
DerivedStats (root) | struct with groups, grouped_gates, sparse_gates, grouped_consts, sparse_consts | Closed-form coverage |
RegularWiring (root) | struct with layers: Vec<RegularLayer>; materialize(&self) -> LayeredCircuit<BaseField> | Template-based oracle for hand-built data-parallel circuits |
RegularLayer | struct with copy_bits, out_local_bits, in_local_bits, gates: Vec<LocalGate>, consts: Vec<(u32, BaseField)> | One template layer |
LocalGate | struct with kind, out, in1, in2, coeff: BaseField | Gate with block-local indices |
FamilyTag (root) | struct with family: u32, block: u32 | Layout hint for one gate or constant |
LayerHints (root) | struct with gates: Vec<Option<FamilyTag>>, consts: Vec<Option<FamilyTag>> | Hints for one layer |
WiringHints (root) | struct with layers: Vec<LayerHints> | Hints for a circuit, output layer first |
shifted_range_eq | fn shifted_range_eq(terms: &[(&[ChallengeField], u64)], count: u64) -> ChallengeField | Block-matching factor of the derived closed form |
statesync_gkr::batching#
| Item | Definition | Notes |
|---|---|---|
ProveJob | struct with kind: SmtOpKind, public_inputs: PublicInputs, witness: CircuitWitness<BaseField> | One queued job |
WitnessQueue | struct | new(), push(&mut self, job: ProveJob), len(&self, kind: SmtOpKind) -> usize, is_empty(&self) -> bool, drain(&mut self, kind: SmtOpKind, n: usize) -> Vec<ProveJob>; one FIFO lane per kind |
BatchPolicy | struct with max_batch_size: usize, deadline: Duration, min_batch_size: usize | Defaults 32, 200 ms and 2. See Configuration. |
DeadlineScheduler | struct with policy: BatchPolicy | decide_batch_size(&self, queue_len: usize, remaining: Duration) -> usize |
BatchResult | struct with proofs: Vec<GkrProof> | Proofs aligned with the drained jobs |
BatchProver | struct with scheduler: DeadlineScheduler | prove_round<F>(&mut self, queue: &mut WitnessQueue, remaining: Duration, prove_batch: F) -> Vec<BatchResult> where F: FnMut(SmtOpKind, &[ProveJob]) -> Vec<GkrProof> |
prove_round visits the kinds in the order Membership, NonMembership, Update and skips a kind whose decided batch size is 0. The proving function is injected, so pass a closure that calls a facade batch method for the matching prepared state.
statesync_gkr::wrap#
The external proof boundary.
Backends#
| Item | Definition | Notes |
|---|---|---|
WrapInput<'a> | struct with encoded_inner: &'a [u8], operation: &'a SmtOperation, witness: &'a SmtWitness | Everything a backend receives |
WrappedProof | struct with backend: &'static str, statement: WrapStatementV1, bytes: Vec<u8> | One outer proof |
WrapError | enum: BackendUnavailable { backend: &'static str }, Rejected { reason: String } | |
WrapBackend | trait: wrap(&self, input: &WrapInput<'_>) -> Result<WrappedProof, WrapError>, name(&self) -> &'static str | A backend may reject an input but must never accept one the wrap relation rejects |
MockWrapBackend | unit struct implementing WrapBackend | Echoes the correct statement with the fixed bytes MOCK-WRAP-NOT-A-PROOF; carries no cryptographic content |
wrap::commitment#
| Item | Definition | Notes |
|---|---|---|
CIRCUIT_COMMITMENT_DOMAIN_V1 | &[u8], the bytes ssgkr/circuit-commitment/v1 | |
gate_kind_tag | fn gate_kind_tag(kind: GateKind) -> u8 | Lin 0, Mul 1, Pow3 2 |
strategy_identity | fn strategy_identity(strategy: LayerStrategy) -> (u8, u32) | A is (0, 0), B { merge_k } is (1, merge_k), C is (2, 0) |
full_circuit_commitment | fn full_circuit_commitment(circuit: &LayeredCircuit<BaseField>, kind: SmtOpKind, params: &SmtParams, strategy: LayerStrategy) -> Digest<BaseField> | Panics if a count or index reaches the field order instead of reducing it |
wrap::encoding#
Constants MAGIC, PROOF_ENCODING_VERSION, PROTOCOL_VERSION, CIRCUIT_VERSION, LEAF_ENCODING_VERSION, PROOF_KIND_INNER_GKR, LAYER_STRATEGY_ID_A and ROUND_POLY_COEFFS; types CircuitIdentity, InnerProofEnvelope, EncodeError and DecodeError; and the functions encode_inner_proof(env: &InnerProofEnvelope) -> Result<Vec<u8>, EncodeError> and decode_inner_proof(bytes: &[u8]) -> Result<InnerProofEnvelope, DecodeError>. Wire format documents every value, field and error variant.
wrap::statement#
| Item | Definition | Notes |
|---|---|---|
WRAP_STATEMENT_VERSION | u16 constant, 1 | |
WRAP_STATEMENT_FRS | usize constant, 6 | Scalars per statement |
BN254_R_BE | [u8; 32] | The BN254 scalar-field modulus, big-endian |
Bn254Fr | struct Bn254Fr(pub [u8; 32]) | One BN254 scalar as little-endian bytes. to_be_bytes(self) -> [u8; 32] |
WrapStatementV1 | struct with frs: [Bn254Fr; 6] | |
pack_digest | fn pack_digest(d: &Digest<BaseField>) -> Bn254Fr | 31-bit-stride packing |
unpack_digest | fn unpack_digest(fr: &Bn254Fr) -> Option<Digest<BaseField>> | Exact inverse; None for any value that is not a packed digest |
wrap_statement_v1 | fn wrap_statement_v1(identity: &CircuitIdentity, pi: &PublicInputs) -> WrapStatementV1 | Builds the six scalars |
wrap::prepared#
Canonical prepared material for one fixed profile: depth 24, the default leaf bound, strategy A and the Membership kind. The material stores the compiled circuit and its hints; the derived wiring is always rebuilt locally and never read from the bytes.
| Group | Items |
|---|---|
| Types | PreparedMaterialV1, ValidatedPreparedMaterialV1, PreparedMaterialError, PreparedProfileAxis, GeneratorProvenanceV1 (with to_canonical_text and digest) |
| Building and coding | canonical_prepared_material_v1() -> Result<PreparedMaterialV1, PreparedMaterialError>, encode_prepared_material_v1(material: &PreparedMaterialV1) -> Result<Vec<u8>, PreparedMaterialError>, decode_prepared_material_v1(bytes: &[u8]) -> Result<PreparedMaterialV1, PreparedMaterialError> |
| Validation | validate_prepared_material_v1(bytes: &[u8]), validate_prepared_material_v1_against(bytes: &[u8], expected: &PreparedMaterialV1) and validate_pinned_d24_a_membership_material(bytes: &[u8]), each returning Result<ValidatedPreparedMaterialV1, PreparedMaterialError> |
| Digests | prepared_material_digest(bytes: &[u8]) -> [u8; 32], raw_sha256(bytes: &[u8]) -> [u8; 32] and circuit_commitment_bytes(commitment: &Digest<BaseField>) -> [u8; 32]; the checks verify_prepared_material_digest(bytes: &[u8], expected: &[u8; 32]), verify_compiled_a0_material_digest(bytes: &[u8]) and verify_generator_provenance(actual: &GeneratorProvenanceV1, expected: &GeneratorProvenanceV1), each returning Result<(), PreparedMaterialError> |
| Audit binding | PreparedMaterialBindingCoreAuditV1 (with route_id), PreparedBindingLifecycleAuditV1 and PreparedMaterialBindingAuditV1 (with new and validate), used by the repository's binding tests |
| Domains and magic | PREPARED_MATERIAL_MAGIC (the bytes SSGKRPM1), PREPARED_MATERIAL_DOMAIN, PREPARED_MATERIAL_DIGEST_DOMAIN, PREPARED_BINDING_AUDIT_DOMAIN, GENERATOR_PROVENANCE_DOMAIN |
| Profile versions and identifiers | PREPARED_MATERIAL_SCHEMA_VERSION, PREPARED_PROTOCOL_PROFILE_VERSION, PREPARED_CIRCUIT_PROFILE_VERSION, PREPARED_LEAF_PROFILE_VERSION, PREPARED_FIELD_PROFILE_KOALABEAR_U32, PREPARED_HASH_PROFILE_POSEIDON2_KOALABEAR_16, PREPARED_PCS_PROFILE_GKR_SPARSE_MLE_V1, PREPARED_CONFIG_PROFILE_D24_A, PREPARED_STRATEGY_A, PREPARED_OP_MEMBERSHIP, PREPARED_DEPTH (24), PREPARED_LEAF_MAX_FIELDS (31) |
| Pinned anchors | PINNED_D24_A_MEMBERSHIP_MATERIAL_BYTES (7,772,516), PINNED_D24_A_MEMBERSHIP_FRAMED_DIGEST, PINNED_D24_A_MEMBERSHIP_CIRCUIT_COMMITMENT |
| Record sizes | PREPARED_HEADER_BYTES (148), PREPARED_LAYER_HEADER_BYTES (24), PREPARED_GATE_BYTES (20), PREPARED_CONST_BYTES (8), PREPARED_HINT_BYTES (12) |
| Header byte offsets | OFFSET_SCHEMA_VERSION (40), OFFSET_PROTOCOL_VERSION (42), OFFSET_CIRCUIT_VERSION (44), OFFSET_LEAF_VERSION (46), OFFSET_OPERATION_KIND (51), OFFSET_CONFIG_PROFILE (52), OFFSET_STRATEGY_ID (53), OFFSET_HEADER_RESERVED (54), OFFSET_STRATEGY_ARG (56), OFFSET_DEPTH (60), OFFSET_LEAF_MAX_FIELDS (64), OFFSET_INPUT_WIDTH_BITS (68), OFFSET_LAYER_COUNT (72), OFFSET_TOTAL_LENGTH (76), OFFSET_FULL_CIRCUIT_COMMITMENT (116) |
Host-only reference models#
These modules require host. They are reference models for the external route of the fixed program identity: they fix data ownership, canonical bytes and fail-closed checks, and they do not authenticate live finality, read a chain or act as deployed contracts.
| Module | Main items |
|---|---|
wrap::settlement | CanonicalRawStatement, RouteManifestV1, PrimaryFinalityRecordV1, WrapSettlementClaimV1, ReceiptEvidenceV1, SettlementAuthorizationV1, SettlementAttemptV1, ReferenceSettlementConsumer, ContractError; the traits PrimaryFinalityVerifier and FinalizedReceiptRootSource, through which production authentication is injected; the supporting types Hash32, ActionKindV1, DestinationV1, RouteLifecycleState, NewAcceptancePolicy, RouteLifecycleEntry, PrimaryRecordState and RouteProofIdentityV1; the functions preclaim_hash, settlement_key, settlement_key_preimage, reference_digest_adapter_id, reference_pubs_adapter_id, project_public_values_digest, zkverify_pubs and zkverify_statement_leaf; and the constants RAW_WRAP_STATEMENT_BYTES, SETTLEMENT_MAGIC, SETTLEMENT_ENVELOPE_VERSION, CANONICAL_CODEC_VERSION, REFERENCE_MERKLE_PROFILE and SETTLEMENT_KEY_DOMAIN |
wrap::risc0_route_b_manifest | Risc0RouteBManifestV1, Risc0RouteBManifestVectorV1, ComputedRisc0RouteBVectorV1, Risc0RouteBManifestError (implements Display and std::error::Error) and RISC0_ROUTE_B_MANIFEST_DOMAIN |
wrap::risc0_destination_policy | ReceiptRootAuthorizationV1, ReceiptRootCoordinateV1, ReceiptRootAuthorityPolicyV1, RegisteredReceiptRootV1, RootRegistrationOutcome, ReceiptRootPolicyError (implements Display and std::error::Error), ReferenceReceiptRootRegistry, ReplayStateSnapshot, DestinationReplayError, ReferenceDestinationReplayRegistry, the vector types ReceiptRootQuorumVectorV1, ReceiptRootVectorExpectedOutcomeV1, ReceiptRootVectorNegativeCaseV1 and ComputedReceiptRootQuorumVectorV1, the type SignerIdentity, the functions recover_evm_signer, one_leaf_receipt_root, source_network_id, source_runtime_id and validate_receipt_attachment, and the constants RECEIPT_ROOT_QUORUM_DOMAIN, RECEIPT_ROOT_COORDINATE_DOMAIN, SOURCE_NETWORK_DOMAIN, SOURCE_RUNTIME_DOMAIN, RECEIPT_ROOT_HASH_ALGORITHM, RECEIPT_ROOT_INTEGER_ENCODING, INITIAL_AUTHORIZATION_NONCE and AUTHORIZATION_PREIMAGE_BYTES |
Developer binaries#
The root package also builds three development binaries. Their output is development measurement, not release performance evidence; see Benchmark methodology.
| Binary | Purpose | Command |
|---|---|---|
proof_digest | Proves fixed requests for each kind and prints one canonical proof digest per case. Two builds of the same source must print identical output. | cargo run --release --bin proof_digest |
measure | Development measurement harness over depths 24, 28 and 32. Requires host. | cargo run --release --bin measure |
profile | Development profile of the cost classes of one proof. | cargo run --release --bin profile |
Outside the public API#
- Contract items compiled only for the formal-verification toolchain (
cfg(creusot)), such as logic mirrors of the Isabelle model and then_varsandn_layerstrait members. - Test-only items, including
DenseLayerOracle. - Private items, including
SparseLayerOracleand the verifier's internal helpers. - The free functions of
ssgkr-verification, which the facade does not re-export.