Reference

API reference

The public Rust API of StateSync-GKR, starting from the statesync_gkr facade and covering every re-exported module, with signatures, return values, errors and feature requirements.

This reference lists the public items reachable from the statesync_gkr crate in a normal build of the 1.1 documentation line, checked against the source. Most applications need only the facade. The lower modules matter when you build a custom frontend, inspect proof objects or work with the external wrap path.

Conventions#

  • Paths are written from the facade, for example statesync_gkr::compiler::SmtParams.
  • Items compiled only for the formal-verification toolchain (cfg(creusot)) or only for tests (cfg(test)) are not part of the API and are omitted. Test-only types that other pages mention, such as DenseLayerOracle, are marked as such.
  • Requires host marks items compiled only with the host feature. The feature is on by default; zkVM guests disable default features.
  • The workspace packages carry the Cargo version 0.1.0-dev and are not published to crates.io (publish = false). Depend on the source, as described in Installation; Versioning explains how package and release versions relate.
  • Error types implement Debug and Clone but not std::fmt::Display or std::error::Error, so format them with {:?}. The two exceptions, noted below, are in host-only modules of wrap.

Module map#

Facade pathWorkspace crateContents
statesync_gkrFacade, with types from ssgkr-verificationStateSyncProver, PreparedSync, configuration, request and result types
statesync_gkr::primitivesssgkr-primitivesFields, Poseidon2 hashing and the Fiat-Shamir transcript
statesync_gkr::sumcheckssgkr-sumcheckMultilinear sumcheck prover and verifier
statesync_gkr::gkrssgkr-protocolLayered circuits, MLE helpers, GKR prover and verifier, wiring oracles
statesync_gkr::compilerssgkr-compilerSMT types, native semantics, circuit compiler and witness generation
statesync_gkr::batchingssgkr-batchingJob queue and deadline-aware batch scheduling
statesync_gkr::wrapssgkr-wrapCircuit commitment, inner-proof encoding, wrap statement, prepared material and external-route reference models

ssgkr-commitment is reachable as statesync_gkr::wrap::commitment. The free functions of ssgkr-verification (circuit_for, prove_sync_op, prove_on, verify_sync_op, verify_sync_op_reference and verify_sync_op_with) are not re-exported; the facade exposes the same pipeline as methods of StateSyncProver.

The facade#

StateSyncProver#

pub struct StateSyncProver { pub config: StateSyncGkrConfig } implements Debug and Default. It does not implement Clone; to create another prover, clone the configuration.

Construction and preparation

MethodReturnsDescription
new(config: StateSyncGkrConfig)SelfCreates a prover for one configuration.
prepare(&self, kind: SmtOpKind)Result<PreparedSync, SyncError>Compiles the circuit with hints, derives the wiring oracle and computes the full circuit commitment once for kind. Fails with SyncError::Compile for an unsupported configuration.
prepare_pinned_d24_a_membership(&self, bytes: &[u8])Result<PreparedSync, wrap::prepared::PreparedMaterialError>Builds prepared state from the reviewed depth-24, strategy-A, Membership material without compiling. Fails with ConfigMismatch unless the configuration is depth 24, leaf bound 31 and strategy A, and with a validation error for any other bytes.

Proving

MethodReturnsDescription
prove_sync_op(&self, request: &SyncRequest)Result<SyncResult, SyncError>Compiles, generates the witness, computes the commitment and proves one request. Fails with SyncError::Compile or SyncError::Witness.
prove_sync_op_prepared(&self, prepared: &PreparedSync, request: &SyncRequest)Result<SyncResult, SyncError>Generates the witness and proves against prepared state. The proof bytes equal those of prove_sync_op. Fails with SyncError::Witness.

Jobs and batches

MethodReturnsDescription
make_job(&self, request: &SyncRequest)Result<batching::ProveJob, SyncError>Compiles and generates the witness for one job.
make_job_prepared(&self, prepared: &PreparedSync, request: &SyncRequest)Result<batching::ProveJob, SyncError>Generates the witness for one job against prepared state.
prove_batch(&self, kind: SmtOpKind, jobs: &[batching::ProveJob])Vec<gkr::GkrProof>Compiles once and proves each job in order. Returns an empty vector when the configuration does not compile.
prove_batch_prepared(&self, prepared: &PreparedSync, jobs: &[batching::ProveJob])Vec<gkr::GkrProof>Proves the jobs sequentially over the prepared circuit, in input order.
prove_batch_parallel(&self, prepared: &PreparedSync, jobs: &[batching::ProveJob])Vec<gkr::GkrProof>Requires host. Proves the jobs on the current Rayon pool and returns the proofs in input order, identical to prove_batch_prepared. For a fixed worker count, build a pool with Rayon's ThreadPoolBuilder and call this method inside the pool's install.

The prepared proving methods do not check in release builds that a request or job has the prepared operation kind; prove_sync_op_prepared and make_job_prepared check it only with a debug assertion. Check the kind before proving. Verification against the same prepared state returns false for a mismatched kind.

Verification

MethodReturnsDescription
verify_sync_op(&self, request: &SyncRequest, result: &SyncResult)boolCompiles, derives the wiring and recomputes the commitment on every call, then verifies.
verify_sync_op_prepared(&self, prepared: &PreparedSync, request: &SyncRequest, result: &SyncResult)boolVerifies with prepared state. Returns false when the request's kind differs from the prepared kind.
verify_sync_op_reference(&self, request: &SyncRequest, result: &SyncResult)boolVerifies with the general TableWiring oracle; an audit reference for the derived oracle.

Encoding

MethodReturnsDescription
circuit_identity(&self, prepared: &PreparedSync)Result<wrap::encoding::CircuitIdentity, wrap::encoding::EncodeError>The inner-proof-v1 circuit identity of the prepared kind under this configuration. Fails with EncodeError::CountOverflow when leaf_max_fields does not fit in a u16.
encode_sync_result(&self, prepared: &PreparedSync, result: &SyncResult)Result<Vec<u8>, wrap::encoding::EncodeError>Canonical inner-proof-v1 bytes. Never includes the witness.
verify_encoded_sync_op(&self, prepared: &PreparedSync, request: &SyncRequest, bytes: &[u8])boolDecodes strictly, compares the decoded identity with the locally computed one, then runs prepared verification against request.

External wrap

MethodReturnsDescription
wrap_relation(&self, prepared: &PreparedSync, request: &SyncRequest, encoded_inner: &[u8])Option<wrap::statement::WrapStatementV1>Returns the wrap statement exactly when the bytes decode to this configuration's identity and the inner verifier accepts them for request.
wrap_sync_op<B: wrap::WrapBackend>(&self, backend: &B, prepared: &PreparedSync, request: &SyncRequest, encoded_inner: &[u8])Result<wrap::WrappedProof, wrap::WrapError>Checks wrap_relation first, calls the backend, and rejects a result whose statement differs from the locally computed one.

Usage: Quickstart, Prepared execution, Batching and parallelism, Encoding and transport and the prove-and-verify example (opens in a new tab).

PreparedSync#

PreparedSync implements Clone and Debug and has private fields. It holds the compiled circuit, the derived wiring and the full circuit commitment for one operation kind and configuration. It is immutable after construction, so one instance can serve every worker thread.

MethodReturnsDescription
kind(&self)SmtOpKindThe operation kind this preparation serves.
circuit_commitment(&self)&Digest<BaseField>The full circuit commitment that proofs made with this preparation absorb.

Configuration and value types#

ItemDefinitionNotes
StateSyncGkrConfigstruct with smt: compiler::SmtParams, layer_strategy: compiler::LayerStrategy, batching: batching::BatchPolicyClone, Debug, Default. Also at statesync_gkr::config. See Configuration.
SyncRequeststruct with operation: compiler::SmtOperation, witness: compiler::SmtWitness, public_inputs: compiler::PublicInputsClone, Debug. Also at statesync_gkr::oss_interface.
SyncResultstruct with public_inputs: compiler::PublicInputs, proof: gkr::GkrProofClone, Debug. Also at statesync_gkr::oss_interface.
SyncErrorenum: Compile(compiler::CompileError), Witness(compiler::SmtError)Clone, Debug.
DOMAIN_TAG_V01&[u8], the bytes statesync-gkr/v0.1The domain tag every proof transcript absorbs first.

Host integration seam#

ItemDefinitionNotes
OssCoreInterfacetrait with fn next_request(&mut self) -> Option<SyncRequest> and fn deliver(&mut self, result: SyncResult)The minimal contract a host core implements toward the prover: a source of requests and a sink of results.
MockOssCorestruct with requests: Vec<SyncRequest>, delivered: Vec<SyncResult>In-memory implementation for tests and development. next_request takes from the front of requests.

Both are also at statesync_gkr::oss_interface.

statesync_gkr::compiler#

The SMT frontend: operation types, native semantics, compilation and witness generation.

Types#

ItemDefinitionNotes
SmtParamsstruct with depth: u32, leaf_max_fields: u32Default depth 24 and leaf bound 31. Copy, PartialEq.
LayerStrategyenum: A, B { merge_k: u32 }, CDefault A. Only A compiles.
AssetIdstruct AssetId(pub u64)Tree key. Copy, Ord, Hash.
LeafPayloadstruct with sync_state: Vec<BaseField>, identity_digest: [u8; 32]Payload of an occupied leaf.
LeafStateenum: Empty, Occupied(LeafPayload), TombstoneDefault Empty. encode(&self) -> Vec<BaseField>.
MerklePathstruct with siblings: Vec<Digest<BaseField>>Leaf level first. See compute_root below.
SmtOperationenum: Membership { key, payload }, NonMembership { key }, Update { key, old_leaf, new_leaf }kind(&self) -> SmtOpKind.
SmtOpKindenum: Membership, NonMembership, UpdateSelects the circuit. Copy, Hash.
SmtWitnessstruct with leaf: LeafState, path: MerklePathFor an update, leaf is the old leaf.
PublicInputsstruct with old_root, new_root, op_kind_tag: u8, asset_id: AssetId, value_digestRoots and value digest are Digest<BaseField>. kind_tag(kind: SmtOpKind) -> u8 returns 0, 1 or 2.
SmtErrorenum: PathLengthMismatch { expected, found }, KeyOutOfRange { key, depth }, LeafEncoding(HashError)Implements From<HashError>.
CompileErrorenum: UnsupportedConfig { reason: &'static str }, NonUnaryGate { layer, out }
InputLayoutstruct with public kind, depth, input_widthnew(kind, depth, leaf_max_fields) and offset accessors leaf_pre, leaf_lanes, acc(l), sib(l), key_bit(l), root, value_digest, leaf_pre2, acc2(l), root2, has_second.

MerklePath::compute_root<H: HashGadget>(&self, hasher: &H, params: &SmtParams, key: AssetId, leaf: &LeafState) -> Result<Digest<BaseField>, SmtError> recomputes the root of a leaf under this path. It fails on a wrong path length, an out-of-range key or an unhashable leaf encoding.

Functions#

FunctionReturnsDescription
compile(params: &SmtParams, kind: SmtOpKind, strategy: LayerStrategy, template: &HashRoundTemplate)Result<LayeredCircuit<BaseField>, CompileError>Compiles the circuit for one kind. Rejects strategies other than A, depth 0 and a leaf_max_fields below 10 with UnsupportedConfig.
compile_with_hints(params: &SmtParams, kind: SmtOpKind, strategy: LayerStrategy, _template: &HashRoundTemplate)Result<(LayeredCircuit<BaseField>, WiringHints), CompileError>The same circuit plus layout hints for DerivedRegularWiring. The template argument is not read; the facade passes the hasher's round_template().
generate_witness(params: &SmtParams, _strategy: LayerStrategy, circuit: &LayeredCircuit<BaseField>, op: &SmtOperation, public_inputs: &PublicInputs, witness: &SmtWitness)Result<CircuitWitness<BaseField>, SmtError>Builds the input vector and evaluates the circuit. The strategy argument is not read.
build_input_vector(params: &SmtParams, input_width_bits: usize, op: &SmtOperation, public_inputs: &PublicInputs, witness: &SmtWitness)Result<Vec<BaseField>, SmtError>The circuit input vector, padded to 2^input_width_bits. The verifier uses it to discharge the input claims.
smt_valid_native<H: HashGadget>(hasher: &H, params: &SmtParams, op: &SmtOperation, old_root: &Digest<BaseField>, new_root: &Digest<BaseField>, witness: &SmtWitness)Result<bool, SmtError>Native reference semantics. Checks a witness directly, without a circuit or proof.
validate_unary_gates(circuit: &LayeredCircuit<BaseField>)Result<(), CompileError>Rejects Lin or Pow3 gates whose in2 differs from in1.
is_accepting<F: Field>(witness: &CircuitWitness<F>)boolTrue when every output wire is zero.

Circuit builder#

compiler::builder contains the auto-layering builder the compiler uses: Builder with new, scope, unscope, input, constant, affine, sum, sub, mul, pow3, combine, build and build_with_hints; the node handle NodeId; TapKind with Lin and Cube; and width_bits(n: usize) -> usize. The modules compiler::compile, compiler::params, compiler::smt and compiler::witness are public, and their items are re-exported at compiler.

statesync_gkr::primitives#

The thin adapter over Plonky3 0.4.3. It is the only crate that names Plonky3 paths.

Fields#

ItemDefinition
BaseFieldType alias for KoalaBear, p = 2^31 - 2^24 + 1
ChallengeFieldType alias for BinomialExtensionField<BaseField, 4>
CHALLENGE_EXT_DEGREEusize constant, 4

These three are re-exported at primitives. The module primitives::field also re-exports the Plonky3 traits ExtensionField, Field, PrimeCharacteristicRing, PrimeField32 and PrimeField64, and the type BinomialExtensionField.

Hashing#

ItemDefinitionNotes
DIGEST_WIDTHusize constant, 8Field elements per digest
LEAF_SPONGE_RATEusize constant, 8Lanes absorbed per leaf-hash permutation
DEFAULT_LEAF_MAX_FIELDSusize constant, 31Default leaf encoding bound
Digest<F>struct Digest<F>(pub [F; DIGEST_WIDTH])Copy, PartialEq. Digest::zero() returns the all-zero digest.
HashErrorenum: EncodingTooLong { len, max }, EmptyEncoding
HashGadgettraitcompress(&self, left: &Digest<BaseField>, right: &Digest<BaseField>) -> Digest<BaseField>, hash_leaf(&self, payload: &[BaseField]) -> Result<Digest<BaseField>, HashError>, round_template(&self) -> HashRoundTemplate
Poseidon2Gadgetstruct implementing HashGadgetnew(leaf_max_fields: usize), Default with bound 31, leaf_max_fields(&self) -> usize, permutation() returning the width-16 permutation, hash_leaf_pre(&self, pre: &[BaseField]) -> Digest<BaseField>
DefaultHasherType alias for Poseidon2Gadget
HashRoundTemplatestruct with rounds: usize, layers_per_compression: usizeAdvisory circuit metadata: 28 rounds and 29 layers per compression for Poseidon2
KeccakDigestBytesType alias for [u8; 32]Off-circuit identity digest
leaf_pre_width(leaf_max_fields: usize) -> usizefunctionLeaf pre-image width: leaf_max_fields + 1 rounded up to a multiple of 8
leaf_fold(payload: &[BaseField], leaf_max_fields: usize) -> Result<Vec<BaseField>, HashError>functionFixed-width leaf pre-image: tag, length, encoding, zeros

All of these are in primitives::hash. HashRoundTemplate and KeccakDigestBytes are only there; the others are also re-exported at primitives.

Transcript#

primitives::Transcript is the Fiat-Shamir transcript, a Poseidon2 duplex sponge. It implements sumcheck::ChallengeSource<ChallengeField>.

MethodDescription
new(domain_tag: &[u8]) -> SelfCreates a transcript seeded with a domain tag, one field element per byte.
observe_base(&mut self, x: BaseField)Absorbs one base-field element.
observe_digest(&mut self, d: &Digest<BaseField>)Absorbs the eight elements of a digest.
observe_many(&mut self, xs: &[BaseField])Absorbs a slice of base-field elements.
observe_ext(&mut self, x: ChallengeField)Absorbs the four basis coefficients of an extension element.
sample_challenge(&mut self) -> ChallengeFieldDraws one challenge from the extension field.

Poseidon2 arithmetization#

primitives::poseidon2_arith exposes the permutation as plain field data for the compiler: the constants P2_WIDTH (16), P2_EXTERNAL_HALF_ROUNDS (4), P2_INTERNAL_ROUNDS (20) and P2_SBOX_DEGREE (3); the 16 by 16 linear-layer matrices external_matrix() and internal_matrix(); the round constants external_initial_rc(), external_final_rc() and internal_rc(); and permute(state: [BaseField; 16]) -> [BaseField; 16], the native reference permutation.

statesync_gkr::sumcheck#

The multilinear sumcheck protocol. It has no SMT dependency.

ItemDefinitionNotes
SumcheckInstance<F>struct with num_vars: usize, degree_bound: usize, claimed_sum: FThe public statement of one run
SumcheckOracle<F: Field>trait: num_vars(&self) -> usize, degree_bound(&self) -> usize, round_poly(&self) -> RoundPoly<F>, bind(&mut self, r: F)The prover's polynomial; bind fixes the current variable
ChallengeSource<F>trait: observe_round_poly(&mut self, poly: &RoundPoly<F>), draw_challenge(&mut self) -> FImplemented by primitives::Transcript for ChallengeField
SumcheckProof<F>struct with round_polys: Vec<RoundPoly<F>>Round polynomials in round order
Subclaim<F>struct with point: Vec<F>, expected_eval: FThe residual claim the caller must discharge
SumcheckErrorenum: DegreeExceeded { round }, SumMismatch { round }, WrongRoundCount { expected, found }
provefn prove<F, O, C>(oracle: &mut O, challenges: &mut C) -> (SumcheckProof<F>, Subclaim<F>) where F: Field, O: SumcheckOracle<F>, C: ChallengeSource<F>Drives the oracle through every round
verifyfn verify<F, C>(instance: &SumcheckInstance<F>, proof: &SumcheckProof<F>, challenges: &mut C) -> Result<Subclaim<F>, SumcheckError> where F: Field, C: ChallengeSource<F>Checks round count, degree and the running sum each round

The module sumcheck::poly defines three more types, re-exported at sumcheck:

ItemMethodsNotes
MultilinearPoly<F>from_evals(evals: Vec<F>) -> Result<Self, PolyError>, num_vars(&self) -> usize, evals(&self) -> &[F], evaluate(&self, point: &[F]) -> F, fix_first_var(&mut self, r: F)Evaluation table of length 2^n. evaluate panics when the point length differs from num_vars; fix_first_var panics when no variable is left.
RoundPoly<F>from_coeffs(coeffs: Vec<F>) -> Self, coeffs(&self) -> &[F], degree(&self) -> usize, eval_at(&self, x: F) -> FAscending coefficients. degree is the coefficient count minus one, so trailing zeros count.
PolyErrorenum: NotPowerOfTwo { len }

statesync_gkr::gkr#

The layered-circuit representation and the GKR protocol. It has no SMT dependency.

Proof objects and drivers#

ItemDefinitionNotes
LayerProofstruct with sumcheck: SumcheckProof<ChallengeField>, eval_x: ChallengeField, eval_y: ChallengeFieldOne layer's messages
GkrProofstruct with layer_proofs: Vec<LayerProof>Output layer first. Clone, PartialEq.
InputClaimstruct with point, expected_eval, point_y, expected_eval_yTwo residual claims on the input vector; the caller must check both
GkrErrorenum: Sumcheck { layer, source }, LayerClaimMismatch { layer }, ShapeMismatch
provefn prove(circuit: &LayeredCircuit<BaseField>, witness: &CircuitWitness<BaseField>, transcript: &mut Transcript) -> GkrProofThe transcript must already hold the caller's preamble and claimed outputs
verifyfn verify<W: WiringOracle<ChallengeField>>(circuit: &LayeredCircuit<BaseField>, wiring: &W, claimed_outputs: &[BaseField], proof: &GkrProof, transcript: &mut Transcript) -> Result<InputClaim, GkrError>The transcript must hold the same preamble as the prover's

Circuits#

Defined in gkr::circuit and re-exported at gkr:

ItemDefinitionNotes
GateKindenum: Lin, Mul, Pow3
Gate<F>struct with kind: GateKind, out: u32, in1: u32, in2: u32, coeff: FUnary kinds set in2 equal to in1
Layer<F>struct with width_bits: usize, gates: Vec<Gate<F>>, consts: Vec<(u32, F)>width(&self) -> usize
LayeredCircuit<F>struct with layers: Vec<Layer<F>>, input_width_bits: usizeOutput layer first. depth(&self) -> usize
CircuitWitness<F>struct with layer_values: Vec<Vec<F>>Output layer first, inputs last
CircuitErrorenum: InputWidthMismatch { expected, found }, WireOutOfRange { layer }
evaluate_circuitfn evaluate_circuit<F: Field>(circuit: &LayeredCircuit<F>, inputs: &[F]) -> Result<CircuitWitness<F>, CircuitError>Native circuit semantics
gate_semanticsfn gate_semantics<F: Field>(kind: GateKind, a: F, b: F) -> FGate value before the coefficient

Multilinear extensions#

gkr::mle: embed(x: BaseField) -> ChallengeField, cf_u64(k: u64) -> ChallengeField, eq_point_index(point: &[ChallengeField], idx: usize) -> ChallengeField, eq_points(a: &[ChallengeField], b: &[ChallengeField]) -> ChallengeField, eq3_points(a, b, c) -> ChallengeField, mle_eval_base(values: &[BaseField], point: &[ChallengeField]) -> ChallengeField and mle_eval_ext(values: &[ChallengeField], point: &[ChallengeField]) -> ChallengeField. Variable 0 is the most significant index bit, and a table must have 2^point.len() entries.

Layer reduction#

gkr::reduce contains LAYER_ROUND_DEGREE (4), the per-round degree bound of every layer sumcheck, and the prove and verify functions that gkr::prove and gkr::verify call. The production prover oracle, SparseLayerOracle, is private; DenseLayerOracle is test-only.

Wiring#

Defined in gkr::wiring. The items marked "root" are also re-exported at gkr.

ItemDefinitionNotes
WiringOracle<F: Field> (root)trait: out_width_bits(&self, layer: usize) -> usize, in_width_bits(&self, layer: usize) -> usize, eval_predicate_mle(&self, layer: usize, kind: GateKind, z: &[F], x: &[F], y: &[F]) -> F, eval_const_mle(&self, layer: usize, z: &[F]) -> FWhat the GKR verifier asks of the circuit structure
TableWiring<'a>new(circuit: &'a LayeredCircuit<BaseField>) -> SelfGeneral oracle over a concrete gate list
DerivedRegularWiring (root)derive(circuit: &LayeredCircuit<BaseField>, hints: &WiringHints) -> Self, expand_gates(&self, layer: usize) -> Vec<Gate<BaseField>>, expand_consts(&self, layer: usize) -> Vec<(u32, BaseField)>, stats(&self) -> DerivedStatsProduction closed-form oracle; derivation never fails
DerivedStats (root)struct with groups, grouped_gates, sparse_gates, grouped_consts, sparse_constsClosed-form coverage
RegularWiring (root)struct with layers: Vec<RegularLayer>; materialize(&self) -> LayeredCircuit<BaseField>Template-based oracle for hand-built data-parallel circuits
RegularLayerstruct with copy_bits, out_local_bits, in_local_bits, gates: Vec<LocalGate>, consts: Vec<(u32, BaseField)>One template layer
LocalGatestruct with kind, out, in1, in2, coeff: BaseFieldGate with block-local indices
FamilyTag (root)struct with family: u32, block: u32Layout hint for one gate or constant
LayerHints (root)struct with gates: Vec<Option<FamilyTag>>, consts: Vec<Option<FamilyTag>>Hints for one layer
WiringHints (root)struct with layers: Vec<LayerHints>Hints for a circuit, output layer first
shifted_range_eqfn shifted_range_eq(terms: &[(&[ChallengeField], u64)], count: u64) -> ChallengeFieldBlock-matching factor of the derived closed form

statesync_gkr::batching#

ItemDefinitionNotes
ProveJobstruct with kind: SmtOpKind, public_inputs: PublicInputs, witness: CircuitWitness<BaseField>One queued job
WitnessQueuestructnew(), push(&mut self, job: ProveJob), len(&self, kind: SmtOpKind) -> usize, is_empty(&self) -> bool, drain(&mut self, kind: SmtOpKind, n: usize) -> Vec<ProveJob>; one FIFO lane per kind
BatchPolicystruct with max_batch_size: usize, deadline: Duration, min_batch_size: usizeDefaults 32, 200 ms and 2. See Configuration.
DeadlineSchedulerstruct with policy: BatchPolicydecide_batch_size(&self, queue_len: usize, remaining: Duration) -> usize
BatchResultstruct with proofs: Vec<GkrProof>Proofs aligned with the drained jobs
BatchProverstruct with scheduler: DeadlineSchedulerprove_round<F>(&mut self, queue: &mut WitnessQueue, remaining: Duration, prove_batch: F) -> Vec<BatchResult> where F: FnMut(SmtOpKind, &[ProveJob]) -> Vec<GkrProof>

prove_round visits the kinds in the order Membership, NonMembership, Update and skips a kind whose decided batch size is 0. The proving function is injected, so pass a closure that calls a facade batch method for the matching prepared state.

statesync_gkr::wrap#

The external proof boundary.

Backends#

ItemDefinitionNotes
WrapInput<'a>struct with encoded_inner: &'a [u8], operation: &'a SmtOperation, witness: &'a SmtWitnessEverything a backend receives
WrappedProofstruct with backend: &'static str, statement: WrapStatementV1, bytes: Vec<u8>One outer proof
WrapErrorenum: BackendUnavailable { backend: &'static str }, Rejected { reason: String }
WrapBackendtrait: wrap(&self, input: &WrapInput<'_>) -> Result<WrappedProof, WrapError>, name(&self) -> &'static strA backend may reject an input but must never accept one the wrap relation rejects
MockWrapBackendunit struct implementing WrapBackendEchoes the correct statement with the fixed bytes MOCK-WRAP-NOT-A-PROOF; carries no cryptographic content

wrap::commitment#

ItemDefinitionNotes
CIRCUIT_COMMITMENT_DOMAIN_V1&[u8], the bytes ssgkr/circuit-commitment/v1
gate_kind_tagfn gate_kind_tag(kind: GateKind) -> u8Lin 0, Mul 1, Pow3 2
strategy_identityfn strategy_identity(strategy: LayerStrategy) -> (u8, u32)A is (0, 0), B { merge_k } is (1, merge_k), C is (2, 0)
full_circuit_commitmentfn full_circuit_commitment(circuit: &LayeredCircuit<BaseField>, kind: SmtOpKind, params: &SmtParams, strategy: LayerStrategy) -> Digest<BaseField>Panics if a count or index reaches the field order instead of reducing it

wrap::encoding#

Constants MAGIC, PROOF_ENCODING_VERSION, PROTOCOL_VERSION, CIRCUIT_VERSION, LEAF_ENCODING_VERSION, PROOF_KIND_INNER_GKR, LAYER_STRATEGY_ID_A and ROUND_POLY_COEFFS; types CircuitIdentity, InnerProofEnvelope, EncodeError and DecodeError; and the functions encode_inner_proof(env: &InnerProofEnvelope) -> Result<Vec<u8>, EncodeError> and decode_inner_proof(bytes: &[u8]) -> Result<InnerProofEnvelope, DecodeError>. Wire format documents every value, field and error variant.

wrap::statement#

ItemDefinitionNotes
WRAP_STATEMENT_VERSIONu16 constant, 1
WRAP_STATEMENT_FRSusize constant, 6Scalars per statement
BN254_R_BE[u8; 32]The BN254 scalar-field modulus, big-endian
Bn254Frstruct Bn254Fr(pub [u8; 32])One BN254 scalar as little-endian bytes. to_be_bytes(self) -> [u8; 32]
WrapStatementV1struct with frs: [Bn254Fr; 6]
pack_digestfn pack_digest(d: &Digest<BaseField>) -> Bn254Fr31-bit-stride packing
unpack_digestfn unpack_digest(fr: &Bn254Fr) -> Option<Digest<BaseField>>Exact inverse; None for any value that is not a packed digest
wrap_statement_v1fn wrap_statement_v1(identity: &CircuitIdentity, pi: &PublicInputs) -> WrapStatementV1Builds the six scalars

wrap::prepared#

Canonical prepared material for one fixed profile: depth 24, the default leaf bound, strategy A and the Membership kind. The material stores the compiled circuit and its hints; the derived wiring is always rebuilt locally and never read from the bytes.

GroupItems
TypesPreparedMaterialV1, ValidatedPreparedMaterialV1, PreparedMaterialError, PreparedProfileAxis, GeneratorProvenanceV1 (with to_canonical_text and digest)
Building and codingcanonical_prepared_material_v1() -> Result<PreparedMaterialV1, PreparedMaterialError>, encode_prepared_material_v1(material: &PreparedMaterialV1) -> Result<Vec<u8>, PreparedMaterialError>, decode_prepared_material_v1(bytes: &[u8]) -> Result<PreparedMaterialV1, PreparedMaterialError>
Validationvalidate_prepared_material_v1(bytes: &[u8]), validate_prepared_material_v1_against(bytes: &[u8], expected: &PreparedMaterialV1) and validate_pinned_d24_a_membership_material(bytes: &[u8]), each returning Result<ValidatedPreparedMaterialV1, PreparedMaterialError>
Digestsprepared_material_digest(bytes: &[u8]) -> [u8; 32], raw_sha256(bytes: &[u8]) -> [u8; 32] and circuit_commitment_bytes(commitment: &Digest<BaseField>) -> [u8; 32]; the checks verify_prepared_material_digest(bytes: &[u8], expected: &[u8; 32]), verify_compiled_a0_material_digest(bytes: &[u8]) and verify_generator_provenance(actual: &GeneratorProvenanceV1, expected: &GeneratorProvenanceV1), each returning Result<(), PreparedMaterialError>
Audit bindingPreparedMaterialBindingCoreAuditV1 (with route_id), PreparedBindingLifecycleAuditV1 and PreparedMaterialBindingAuditV1 (with new and validate), used by the repository's binding tests
Domains and magicPREPARED_MATERIAL_MAGIC (the bytes SSGKRPM1), PREPARED_MATERIAL_DOMAIN, PREPARED_MATERIAL_DIGEST_DOMAIN, PREPARED_BINDING_AUDIT_DOMAIN, GENERATOR_PROVENANCE_DOMAIN
Profile versions and identifiersPREPARED_MATERIAL_SCHEMA_VERSION, PREPARED_PROTOCOL_PROFILE_VERSION, PREPARED_CIRCUIT_PROFILE_VERSION, PREPARED_LEAF_PROFILE_VERSION, PREPARED_FIELD_PROFILE_KOALABEAR_U32, PREPARED_HASH_PROFILE_POSEIDON2_KOALABEAR_16, PREPARED_PCS_PROFILE_GKR_SPARSE_MLE_V1, PREPARED_CONFIG_PROFILE_D24_A, PREPARED_STRATEGY_A, PREPARED_OP_MEMBERSHIP, PREPARED_DEPTH (24), PREPARED_LEAF_MAX_FIELDS (31)
Pinned anchorsPINNED_D24_A_MEMBERSHIP_MATERIAL_BYTES (7,772,516), PINNED_D24_A_MEMBERSHIP_FRAMED_DIGEST, PINNED_D24_A_MEMBERSHIP_CIRCUIT_COMMITMENT
Record sizesPREPARED_HEADER_BYTES (148), PREPARED_LAYER_HEADER_BYTES (24), PREPARED_GATE_BYTES (20), PREPARED_CONST_BYTES (8), PREPARED_HINT_BYTES (12)
Header byte offsetsOFFSET_SCHEMA_VERSION (40), OFFSET_PROTOCOL_VERSION (42), OFFSET_CIRCUIT_VERSION (44), OFFSET_LEAF_VERSION (46), OFFSET_OPERATION_KIND (51), OFFSET_CONFIG_PROFILE (52), OFFSET_STRATEGY_ID (53), OFFSET_HEADER_RESERVED (54), OFFSET_STRATEGY_ARG (56), OFFSET_DEPTH (60), OFFSET_LEAF_MAX_FIELDS (64), OFFSET_INPUT_WIDTH_BITS (68), OFFSET_LAYER_COUNT (72), OFFSET_TOTAL_LENGTH (76), OFFSET_FULL_CIRCUIT_COMMITMENT (116)

Host-only reference models#

These modules require host. They are reference models for the external route of the fixed program identity: they fix data ownership, canonical bytes and fail-closed checks, and they do not authenticate live finality, read a chain or act as deployed contracts.

ModuleMain items
wrap::settlementCanonicalRawStatement, RouteManifestV1, PrimaryFinalityRecordV1, WrapSettlementClaimV1, ReceiptEvidenceV1, SettlementAuthorizationV1, SettlementAttemptV1, ReferenceSettlementConsumer, ContractError; the traits PrimaryFinalityVerifier and FinalizedReceiptRootSource, through which production authentication is injected; the supporting types Hash32, ActionKindV1, DestinationV1, RouteLifecycleState, NewAcceptancePolicy, RouteLifecycleEntry, PrimaryRecordState and RouteProofIdentityV1; the functions preclaim_hash, settlement_key, settlement_key_preimage, reference_digest_adapter_id, reference_pubs_adapter_id, project_public_values_digest, zkverify_pubs and zkverify_statement_leaf; and the constants RAW_WRAP_STATEMENT_BYTES, SETTLEMENT_MAGIC, SETTLEMENT_ENVELOPE_VERSION, CANONICAL_CODEC_VERSION, REFERENCE_MERKLE_PROFILE and SETTLEMENT_KEY_DOMAIN
wrap::risc0_route_b_manifestRisc0RouteBManifestV1, Risc0RouteBManifestVectorV1, ComputedRisc0RouteBVectorV1, Risc0RouteBManifestError (implements Display and std::error::Error) and RISC0_ROUTE_B_MANIFEST_DOMAIN
wrap::risc0_destination_policyReceiptRootAuthorizationV1, ReceiptRootCoordinateV1, ReceiptRootAuthorityPolicyV1, RegisteredReceiptRootV1, RootRegistrationOutcome, ReceiptRootPolicyError (implements Display and std::error::Error), ReferenceReceiptRootRegistry, ReplayStateSnapshot, DestinationReplayError, ReferenceDestinationReplayRegistry, the vector types ReceiptRootQuorumVectorV1, ReceiptRootVectorExpectedOutcomeV1, ReceiptRootVectorNegativeCaseV1 and ComputedReceiptRootQuorumVectorV1, the type SignerIdentity, the functions recover_evm_signer, one_leaf_receipt_root, source_network_id, source_runtime_id and validate_receipt_attachment, and the constants RECEIPT_ROOT_QUORUM_DOMAIN, RECEIPT_ROOT_COORDINATE_DOMAIN, SOURCE_NETWORK_DOMAIN, SOURCE_RUNTIME_DOMAIN, RECEIPT_ROOT_HASH_ALGORITHM, RECEIPT_ROOT_INTEGER_ENCODING, INITIAL_AUTHORIZATION_NONCE and AUTHORIZATION_PREIMAGE_BYTES

Developer binaries#

The root package also builds three development binaries. Their output is development measurement, not release performance evidence; see Benchmark methodology.

BinaryPurposeCommand
proof_digestProves fixed requests for each kind and prints one canonical proof digest per case. Two builds of the same source must print identical output.cargo run --release --bin proof_digest
measureDevelopment measurement harness over depths 24, 28 and 32. Requires host.cargo run --release --bin measure
profileDevelopment profile of the cost classes of one proof.cargo run --release --bin profile

Outside the public API#

  • Contract items compiled only for the formal-verification toolchain (cfg(creusot)), such as logic mirrors of the Isabelle model and the n_vars and n_layers trait members.
  • Test-only items, including DenseLayerOracle.
  • Private items, including SparseLayerOracle and the verifier's internal helpers.
  • The free functions of ssgkr-verification, which the facade does not re-export.