315 lines
11 KiB
Rust
Raw Normal View History

use std::collections::HashMap;
use eth_trie_utils::partial_trie::{HashedPartialTrie, PartialTrie};
2023-03-12 21:35:04 -07:00
use ethereum_types::{Address, BigEndianHash, H256, U256};
use plonky2::field::extension::Extendable;
use plonky2::field::polynomial::PolynomialValues;
use plonky2::hash::hash_types::RichField;
2022-12-02 14:49:32 -08:00
use plonky2::timed;
use plonky2::util::timing::TimingTree;
use serde::{Deserialize, Serialize};
2022-12-02 13:56:52 -08:00
use GlobalMetadata::{
ReceiptTrieRootDigestAfter, ReceiptTrieRootDigestBefore, StateTrieRootDigestAfter,
StateTrieRootDigestBefore, TransactionTrieRootDigestAfter, TransactionTrieRootDigestBefore,
};
2022-08-26 10:12:45 +02:00
use crate::all_stark::{AllStark, NUM_TABLES};
2022-08-26 18:30:26 +02:00
use crate::config::StarkConfig;
use crate::cpu::bootstrap_kernel::generate_bootstrap_kernel;
use crate::cpu::columns::CpuColumnsView;
2022-11-30 12:55:41 -08:00
use crate::cpu::kernel::aggregator::KERNEL;
2022-10-03 12:08:29 -07:00
use crate::cpu::kernel::constants::global_metadata::GlobalMetadata;
use crate::generation::outputs::{get_outputs, GenerationOutputs};
2022-12-01 11:15:51 -08:00
use crate::generation::state::GenerationState;
2022-08-25 12:24:22 -07:00
use crate::memory::segments::Segment;
2023-08-21 23:32:53 +01:00
use crate::proof::{BlockHashes, BlockMetadata, ExtraBlockData, PublicValues, TrieRoots};
use crate::util::h2u;
use crate::witness::memory::{MemoryAddress, MemoryChannel};
2022-11-30 12:55:41 -08:00
use crate::witness::transition::transition;
2022-12-03 21:09:57 -08:00
pub mod mpt;
pub mod outputs;
pub(crate) mod prover_input;
2022-09-29 23:09:32 -07:00
pub(crate) mod rlp;
pub(crate) mod state;
mod trie_extractor;
2023-03-12 21:35:04 -07:00
use crate::witness::util::mem_write_log;
2022-08-25 22:11:25 -07:00
/// Inputs needed for trace generation.
#[derive(Clone, Debug, Deserialize, Serialize, Default)]
2022-08-25 22:11:25 -07:00
pub struct GenerationInputs {
pub txn_number_before: U256,
pub gas_used_before: U256,
pub block_bloom_before: [U256; 8],
pub gas_used_after: U256,
pub block_bloom_after: [U256; 8],
2022-08-25 12:24:22 -07:00
pub signed_txns: Vec<Vec<u8>>,
2022-09-22 20:09:48 -07:00
pub tries: TrieInputs,
/// Expected trie roots after the transactions are executed.
pub trie_roots_after: TrieRoots,
2022-09-22 20:09:48 -07:00
/// Mapping between smart contract code hashes and the contract byte code.
/// All account smart contracts that are invoked will have an entry present.
pub contract_code: HashMap<H256, Vec<u8>>,
pub block_metadata: BlockMetadata,
2023-03-16 14:08:31 -07:00
2023-08-21 23:32:53 +01:00
pub block_hashes: BlockHashes,
2023-03-16 14:08:31 -07:00
/// A list of known addresses in the input state trie (which itself doesn't hold addresses,
/// only state keys). This is only useful for debugging, so that we can return addresses in the
/// post-state rather than state keys. (See `GenerationOutputs`, and in particular
/// `AddressOrStateKey`.) If the caller is not interested in the post-state, this can be left
/// empty.
pub addresses: Vec<Address>,
2022-09-22 20:09:48 -07:00
}
#[derive(Clone, Debug, Deserialize, Serialize, Default)]
pub struct TrieInputs {
2022-08-25 23:35:38 -07:00
/// A partial version of the state trie prior to these transactions. It should include all nodes
/// that will be accessed by these transactions.
pub state_trie: HashedPartialTrie,
2022-08-25 23:35:38 -07:00
/// A partial version of the transaction trie prior to these transactions. It should include all
/// nodes that will be accessed by these transactions.
pub transactions_trie: HashedPartialTrie,
2022-08-25 23:35:38 -07:00
/// A partial version of the receipt trie prior to these transactions. It should include all nodes
/// that will be accessed by these transactions.
pub receipts_trie: HashedPartialTrie,
2022-08-25 23:35:38 -07:00
/// A partial version of each storage trie prior to these transactions. It should include all
/// storage tries, and nodes therein, that will be accessed by these transactions.
pub storage_tries: Vec<(H256, HashedPartialTrie)>,
}
fn apply_metadata_and_tries_memops<F: RichField + Extendable<D>, const D: usize>(
2023-03-12 21:35:04 -07:00
state: &mut GenerationState<F>,
inputs: &GenerationInputs,
2023-03-12 21:35:04 -07:00
) {
let metadata = &inputs.block_metadata;
let tries = &inputs.tries;
let trie_roots_after = &inputs.trie_roots_after;
2023-03-12 21:35:04 -07:00
let fields = [
(
GlobalMetadata::BlockBeneficiary,
U256::from_big_endian(&metadata.block_beneficiary.0),
),
(GlobalMetadata::BlockTimestamp, metadata.block_timestamp),
(GlobalMetadata::BlockNumber, metadata.block_number),
(GlobalMetadata::BlockDifficulty, metadata.block_difficulty),
(GlobalMetadata::BlockGasLimit, metadata.block_gaslimit),
(GlobalMetadata::BlockChainId, metadata.block_chain_id),
(GlobalMetadata::BlockBaseFee, metadata.block_base_fee),
2023-08-21 23:32:53 +01:00
(
GlobalMetadata::BlockCurrentHash,
2023-09-05 09:53:40 +01:00
h2u(inputs.block_hashes.cur_hash),
2023-08-21 23:32:53 +01:00
),
(GlobalMetadata::BlockGasUsed, metadata.block_gas_used),
(GlobalMetadata::BlockGasUsedBefore, inputs.gas_used_before),
(GlobalMetadata::BlockGasUsedAfter, inputs.gas_used_after),
(GlobalMetadata::TxnNumberBefore, inputs.txn_number_before),
(
GlobalMetadata::TxnNumberAfter,
inputs.txn_number_before + inputs.signed_txns.len(),
),
(
GlobalMetadata::StateTrieRootDigestBefore,
h2u(tries.state_trie.hash()),
),
(
GlobalMetadata::TransactionTrieRootDigestBefore,
h2u(tries.transactions_trie.hash()),
),
(
GlobalMetadata::ReceiptTrieRootDigestBefore,
h2u(tries.receipts_trie.hash()),
),
(
GlobalMetadata::StateTrieRootDigestAfter,
h2u(trie_roots_after.state_root),
),
(
GlobalMetadata::TransactionTrieRootDigestAfter,
h2u(trie_roots_after.transactions_root),
),
(
GlobalMetadata::ReceiptTrieRootDigestAfter,
h2u(trie_roots_after.receipts_root),
),
];
let channel = MemoryChannel::GeneralPurpose(0);
let mut ops = fields
.map(|(field, val)| {
mem_write_log(
channel,
MemoryAddress::new(0, Segment::GlobalMetadata, field as usize),
state,
val,
)
})
.to_vec();
// Write the block's final block bloom filter.
ops.extend((0..8).map(|i| {
mem_write_log(
channel,
MemoryAddress::new(0, Segment::GlobalBlockBloom, i),
state,
metadata.block_bloom[i],
)
}));
// Write the block's bloom filter before the current transaction.
ops.extend(
(0..8)
.map(|i| {
mem_write_log(
channel,
MemoryAddress::new(0, Segment::GlobalBlockBloom, i + 8),
state,
inputs.block_bloom_before[i],
)
})
.collect::<Vec<_>>(),
);
// Write the block's bloom filter after the current transaction.
ops.extend(
(0..8)
.map(|i| {
mem_write_log(
channel,
MemoryAddress::new(0, Segment::GlobalBlockBloom, i + 16),
state,
inputs.block_bloom_after[i],
)
})
.collect::<Vec<_>>(),
);
2023-08-21 23:32:53 +01:00
// Write previous block hashes.
ops.extend(
(0..256)
.map(|i| {
mem_write_log(
channel,
MemoryAddress::new(0, Segment::BlockHashes, i),
state,
h2u(inputs.block_hashes.prev_hashes[i]),
)
})
.collect::<Vec<_>>(),
);
state.memory.apply_ops(&ops);
state.traces.memory_ops.extend(ops);
}
pub fn generate_traces<F: RichField + Extendable<D>, const D: usize>(
all_stark: &AllStark<F, D>,
2022-08-25 22:11:25 -07:00
inputs: GenerationInputs,
2022-08-26 18:30:26 +02:00
config: &StarkConfig,
timing: &mut TimingTree,
) -> anyhow::Result<(
[Vec<PolynomialValues<F>>; NUM_TABLES],
PublicValues,
GenerationOutputs,
)> {
2022-12-01 11:15:51 -08:00
let mut state = GenerationState::<F>::new(inputs.clone(), &KERNEL.code);
2023-05-10 17:35:28 -04:00
apply_metadata_and_tries_memops(&mut state, &inputs);
2023-03-12 21:35:04 -07:00
2022-12-01 11:15:51 -08:00
generate_bootstrap_kernel::<F>(&mut state);
2023-02-25 07:59:51 -08:00
timed!(timing, "simulate CPU", simulate_cpu(&mut state)?);
2022-08-25 12:24:22 -07:00
2023-03-17 13:10:58 -07:00
assert!(
state.mpt_prover_inputs.is_empty(),
"All MPT data should have been consumed"
);
2022-12-03 22:58:51 -08:00
log::info!(
"Trace lengths (before padding): {:?}",
state.traces.get_lengths()
2022-12-03 22:58:51 -08:00
);
2022-12-03 22:44:54 -08:00
let outputs = get_outputs(&mut state);
let read_metadata = |field| state.memory.read_global_metadata(field);
2022-08-25 12:24:22 -07:00
let trie_roots_before = TrieRoots {
2022-12-02 13:56:52 -08:00
state_root: H256::from_uint(&read_metadata(StateTrieRootDigestBefore)),
transactions_root: H256::from_uint(&read_metadata(TransactionTrieRootDigestBefore)),
receipts_root: H256::from_uint(&read_metadata(ReceiptTrieRootDigestBefore)),
2022-08-25 12:24:22 -07:00
};
let trie_roots_after = TrieRoots {
2022-12-02 13:56:52 -08:00
state_root: H256::from_uint(&read_metadata(StateTrieRootDigestAfter)),
transactions_root: H256::from_uint(&read_metadata(TransactionTrieRootDigestAfter)),
receipts_root: H256::from_uint(&read_metadata(ReceiptTrieRootDigestAfter)),
2022-08-25 12:24:22 -07:00
};
let gas_used_after = read_metadata(GlobalMetadata::BlockGasUsedAfter);
let txn_number_after = read_metadata(GlobalMetadata::TxnNumberAfter);
let extra_block_data = ExtraBlockData {
txn_number_before: inputs.txn_number_before,
txn_number_after,
gas_used_before: inputs.gas_used_before,
gas_used_after,
block_bloom_before: inputs.block_bloom_before,
block_bloom_after: inputs.block_bloom_after,
};
2022-08-25 12:24:22 -07:00
let public_values = PublicValues {
trie_roots_before,
trie_roots_after,
block_metadata: inputs.block_metadata,
2023-08-21 23:32:53 +01:00
block_hashes: inputs.block_hashes,
extra_block_data,
2022-08-25 12:24:22 -07:00
};
2022-12-02 14:49:32 -08:00
let tables = timed!(
timing,
"convert trace data to tables",
2022-12-02 17:06:30 -08:00
state.traces.into_tables(all_stark, config, timing)
2022-12-02 14:49:32 -08:00
);
Ok((tables, public_values, outputs))
2022-12-02 14:49:32 -08:00
}
2023-02-25 07:59:51 -08:00
fn simulate_cpu<F: RichField + Extendable<D>, const D: usize>(
state: &mut GenerationState<F>,
) -> anyhow::Result<()> {
let halt_pc = KERNEL.global_labels["halt"];
2022-12-02 14:49:32 -08:00
loop {
// If we've reached the kernel's halt routine, and our trace length is a power of 2, stop.
let pc = state.registers.program_counter;
let halt = state.registers.is_kernel && pc == halt_pc;
if halt {
2022-12-02 14:49:32 -08:00
log::info!("CPU halted after {} cycles", state.traces.clock());
2022-12-09 10:35:00 -08:00
// Padding
let mut row = CpuColumnsView::<F>::default();
row.clock = F::from_canonical_usize(state.traces.clock());
row.context = F::from_canonical_usize(state.registers.context);
row.program_counter = F::from_canonical_usize(pc);
row.is_kernel_mode = F::ONE;
row.gas = F::from_canonical_u64(state.registers.gas_used);
row.stack_len = F::from_canonical_usize(state.registers.stack_len);
loop {
state.traces.push_cpu(row);
row.clock += F::ONE;
if state.traces.clock().is_power_of_two() {
break;
}
}
2022-12-02 14:49:32 -08:00
log::info!("CPU trace padded to {} cycles", state.traces.clock());
return Ok(());
2022-12-02 14:49:32 -08:00
}
2023-02-25 07:59:51 -08:00
transition(state)?;
}
}