From 797bece7bddbab3b70bfbaa647437afc8b540429 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Fri, 1 Jul 2022 18:28:22 +0200 Subject: [PATCH 01/30] First attempt --- evm/src/cpu/kernel/aggregator.rs | 1 + evm/src/cpu/kernel/asm/curve_add.asm | 301 +++++++++++++++++++++++++++ evm/src/cpu/kernel/ast.rs | 6 +- 3 files changed, 307 insertions(+), 1 deletion(-) create mode 100644 evm/src/cpu/kernel/asm/curve_add.asm diff --git a/evm/src/cpu/kernel/aggregator.rs b/evm/src/cpu/kernel/aggregator.rs index bdef51f7..773842f8 100644 --- a/evm/src/cpu/kernel/aggregator.rs +++ b/evm/src/cpu/kernel/aggregator.rs @@ -10,6 +10,7 @@ pub(crate) fn combined_kernel() -> Kernel { let files = vec![ include_str!("asm/basic_macros.asm"), include_str!("asm/exp.asm"), + include_str!("asm/curve_add.asm"), include_str!("asm/storage_read.asm"), include_str!("asm/storage_write.asm"), ]; diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm new file mode 100644 index 00000000..bab709e3 --- /dev/null +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -0,0 +1,301 @@ +// #define N 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // BN254 base field order + +global ecadd: + JUMPDEST + // stack: x0, y0, x1, y1, retdest + DUP3 + // stack: y1, x0, y0, x1, y1, retdest + DUP3 + // stack: x1, y1, x0, y0, x1, y1, retdest + DUP3 + // stack: y0, x1, y1, x0, y0, x1, y1, retdest + DUP3 + // stack: x0, y0, x1, y1, x0, y0, x1, y1, retdest + %ec_check + // stack: isValid(x0, y0), x1, y1, x0, y0, x1, y1, retdest + PUSH ec_add_valid_first_point + // stack: ec_add_valid_first_point, isValid(x0, y0), x1, y1, x0, y0, x1, y1, retdest + JUMPI + // stack: x1, y1, x0, y0, x1, y1, retdest + POP + // stack: y1, x0, y0, x1, y1, retdest + POP + // stack: x0, y0, x1, y1, retdest + POP + // stack: y0, x1, y1, retdest + POP + // stack: x1, y1, retdest + POP + // stack: y1, retdest + POP + // stack: retdest + JUMP + + +ec_add_valid_first_point: + JUMPDEST + // stack: x1, y1, x0, y0, x1, y1, retdest + %ec_check + // stack: isValid(x1, y1), x0, y0, x1, y1, retdest + PUSH ec_add_valid_points + // stack: ec_add_valid_points, isValid(x1, y1), x0, y0, x1, y1, retdest + JUMPI + // stack: x0, y0, x1, y1, retdest + POP + // stack: y0, x1, y1, retdest + POP + // stack: x1, y1, retdest + POP + // stack: y1, retdest + POP + // stack: retdest + JUMP + +ec_add_valid_points: + JUMPDEST + // stack: x0, y0, x1, y1, retdest + DUP3 + // stack: x1, x0, y0, x1, y1, retdest + DUP2 + // stack: x0, x1, x0, y0, x1, y1, retdest + EQ + // stack: x0 == x1, x0, y0, x1, y1, retdest + PUSH ec_add_equal_first_coord + // stack: ec_add_equal_first_coord, x0 == x1, x0, y0, x1, y1, retdest + JUMPI + // stack: x0, y0, x1, y1, retdest + PUSH ec_add_valid_points_contd + // stack: ec_add_valid_points_contd, x0, y0, x1, y1, retdest + DUP5 + // stack: y1, ec_add_valid_points_contd, x0, y0, x1, y1, retdest + DUP4 + // stack: y0, y1, ec_add_valid_points_contd, x0, y0, x1, y1, retdest + PUSH submod + // stack: submod, y0, y1, ec_add_valid_points_contd, x0, y0, x1, y1, retdest + JUMP + +ec_add_valid_points_contd: + JUMPDEST + // stack: (y0 - y1) % N, x0, y0, x1, y1, retdest + PUSH ec_add_valid_points_contd2 + // stack: ec_add_valid_points_contd2, (y0 - y1) % N, x0, y0, x1, y1, retdest + DUP5 + // stack: x1, ec_add_valid_points_contd2, (y0 - y1) % N, x0, y0, x1, y1, retdest + DUP4 + // stack: x0, x1, ec_add_valid_points_contd2, (y0 - y1) % N, x0, y0, x1, y1, retdest + PUSH submod + // stack: submod, x0, x1, ec_add_valid_points_contd2, (y0 - y1) % N, x0, y0, x1, y1, retdest + JUMP + +ec_add_valid_points_contd2: + JUMPDEST + // stack: (x0 - x1) % N, (y0 - y1) % N, x0, y0, x1, y1, retdest + //MODDIV // TODO: Implement this + // stack: lambda, x0, y0, x1, y1, retdest + PUSH ec_add_valid_points_with_lambda + // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest + JUMP + +ec_add_valid_points_with_lambda: + JUMPDEST + // stack: lambda, x0, y0, x1, y1, retdest + PUSH ec_add_valid_points_contd4 + // stack: ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + DUP3 + // stack: x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + PUSH ec_add_valid_points_contd3 + // stack: ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + DUP7 + // stack: x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + DUP6 + // stack: lambda, N, x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + DUP1 + // stack: lambda, lambda, N, x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + MULMOD + // stack: lambda^2, x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + PUSH submod + // stack: submod, lambda^2, x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + JUMP + +ec_add_valid_points_contd3: + JUMPDEST + // stack: lambda^2 - x1, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + PUSH submod + // stack: submod, lambda^2 - x1, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + JUMP + +ec_add_valid_points_contd4: + JUMPDEST + // stack: x2, lambda, x0, y0, x1, y1, retdest + PUSH ec_add_valid_points_contd6 + // stack: ec_add_valid_points_contd6, x2, lambda, x0, y0, x1, y1, retdest + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, ec_add_valid_points_contd6, x2, lambda, x0, y0, x1, y1, retdest + PUSH ec_add_valid_points_contd5 + // stack: ec_add_valid_points_contd5, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, x1, y1, retdest + DUP4 + // stack: x2, ec_add_valid_points_contd5, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, x1, y1, retdest + SWAP8 + // stack: x1, x2, ec_add_valid_points_contd5, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + PUSH submod + // stack: submod, x1, x2, ec_add_valid_points_contd5, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + JUMP + +ec_add_valid_points_contd5: + JUMPDEST + // stack: x1 - x2, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + DUP5 + // stack: lambda, x1 - x2, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + MULMOD + // stack: lambda * (x1 - x2), ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + DUP7 + // stack: y1, lambda * (x1 - x2), ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + SWAP1 + // stack: lambda * (x1 - x2), y1, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + PUSH submod + // stack: submod, lambda * (x1 - x2), y1, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + JUMP + +ec_add_valid_points_contd6: + JUMPDEST + // stack: y2, x2, x0, y0, y1, retdest + SWAP4 + // stack: y1, x2, x0, y0, y2, retdest + POP + // stack: x2, x0, y0, y2, retdest + SWAP2 + // stack: y0, x0, x2, y2, retdest + POP + // stack: x0, x2, y2, retdest + POP + // stack: x2, y2, retdest + SWAP1 + // stack: y2, x2, retdest + SWAP2 + // stack: retdest, x2, y2 + JUMP + +ec_add_equal_first_coord: + JUMPDEST + // stack: x0, y0, x1, y1, retdest with x0 == x1 + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, x0, y0, x1, y1, retdest + DUP3 + // stack: y0, N, x0, y0, x1, y1, retdest + DUP6 + // stack: y1, y0, N, x0, y0, x1, y1, retdest + ADDMOD + // stack: y1 + y0, x0, y0, x1, y1, retdest + ISZERO + // stack: y1 + y0 == 0, x0, y0, x1, y1, retdest + PUSH ec_add_equal + // stack: ec_add_equal, y1 + y0 == 0, x0, y0, x1, y1, retdest + JUMPI + // stack: x0, y0, x1, y1, retdest + POP + // stack: y0, x1, y1, retdest + POP + // stack: x1, y1, retdest + POP + // stack: y1, retdest + POP + // stack: retdest + PUSH 0 + // stack: 0, retdest + PUSH 0 + // stack: 0, 0, retdest + SWAP2 + // stack: retdest, 0, 0 + JUMP + + +ec_add_equal: + JUMPDEST + // stack: x0, y0, x1, y1, retdest + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, x0, y0, x1, y1, retdest + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, N, x0, y0, x1, y1, retdest + DUP3 + // stack: x0, N, N, x0, y0, x1, y1, retdest + DUP1 + // stack: x0, x0, N, N, x0, y0, x1, y1, retdest + MULMOD + // stack: x0^2, N, x0, y0, x1, y1, retdest with + PUSH 0x183227397098d014dc2822db40c0ac2ecbc0b548b438e5469e10460b6c3e7ea5 // 3/2 in the base field + // stack: 3/2, x0^2, N, x0, y0, x1, y1, retdest + MULMOD + // stack: 3/2 * x0^2, x0, y0, x1, y1, retdest + DUP3 + // stack: y0, 3/2 * x0^2, x0, y0, x1, y1, retdest + //MODDIV // TODO: Implement this + // stack: lambda, x0, y0, x1, y1, retdest + PUSH ec_add_valid_points_with_lambda + // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest + JUMP + +submod: + JUMPDEST + // stack: x, y, retdest + SWAP1 + // stack: y, x, retdest + DUP1 + // stack: y, y, x, retdest + DUP3 + // stack: x, y, y, x, retdest + LT + // stack: x < y, y, x, retdest + PUSH submod + // stack: submod, x < y, y, x, retdest + JUMPI + // stack: y, x, retdest + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, y, x, retdest + SWAP2 + // stack: x, y, N, retdest + SUB + // stack: x - y, N, retdest, + MOD + // stack: (x - y) % N, retdest + SWAP1 + // stack: retdest, (x - y) % N + JUMP + +%macro ec_check + // stack: x0, y0 + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, x0, y0 + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, N, x0, y0 + SWAP2 + // stack: x0, N, N, y0 + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, x0, N, N, y0 + DUP2 + // stack: x0, N, x0, N, N, y0 + DUP1 + // stack: x0, x0, N, x0, N, N, y0 + MULMOD + // stack: x0^2 % N, x0, N, N, y0 + MULMOD + // stack: x0^3 % N, N, y0 + PUSH 3 + // stack: 3, x0^3 % N, N, y0 + ADDMOD + // stack: (x0^3 + 3) % N, y0 + SWAP1 + // stack: y0, (x0^3 + 3) % N + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, y0, (x0^3 + 3) % N + SWAP1 + // stack: y0, N, (x0^3 + 3) % N + DUP1 + // stack: y0, y0, N, (x0^3 + 3) % N + MULMOD + // stack: y0^2 % N, (x0^3 + 3) % N + EQ + // stack: y0^2 % N == (x0^3 + 3) % N +%endmacro + diff --git a/evm/src/cpu/kernel/ast.rs b/evm/src/cpu/kernel/ast.rs index cdb38018..8cf97879 100644 --- a/evm/src/cpu/kernel/ast.rs +++ b/evm/src/cpu/kernel/ast.rs @@ -40,7 +40,11 @@ pub(crate) enum Literal { impl Literal { pub(crate) fn to_trimmed_be_bytes(&self) -> Vec { let u256 = self.to_u256(); - let num_bytes = ceil_div_usize(u256.bits(), 8); + let num_bytes = if u256.is_zero() { + 1 // Hacky + } else { + ceil_div_usize(u256.bits(), 8) + }; // `byte` is little-endian, so we manually reverse it. (0..num_bytes).rev().map(|i| u256.byte(i)).collect() } From 683efc0d7422e8b140fdef869948fe31996823ab Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 10:45:26 +0200 Subject: [PATCH 02/30] Impl double --- evm/src/cpu/kernel/asm/curve_add.asm | 32 ++++++++++++++++++++-------- 1 file changed, 23 insertions(+), 9 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index bab709e3..a542eddf 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -1,15 +1,19 @@ // #define N 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // BN254 base field order global ecadd: + PUSH 2 + PUSH 1 + PUSH 2 + PUSH 1 JUMPDEST // stack: x0, y0, x1, y1, retdest - DUP3 + DUP4 // stack: y1, x0, y0, x1, y1, retdest - DUP3 + DUP4 // stack: x1, y1, x0, y0, x1, y1, retdest - DUP3 + DUP4 // stack: y0, x1, y1, x0, y0, x1, y1, retdest - DUP3 + DUP4 // stack: x0, y0, x1, y1, x0, y0, x1, y1, retdest %ec_check // stack: isValid(x0, y0), x1, y1, x0, y0, x1, y1, retdest @@ -188,10 +192,8 @@ ec_add_equal_first_coord: // stack: y1, y0, N, x0, y0, x1, y1, retdest ADDMOD // stack: y1 + y0, x0, y0, x1, y1, retdest - ISZERO - // stack: y1 + y0 == 0, x0, y0, x1, y1, retdest - PUSH ec_add_equal - // stack: ec_add_equal, y1 + y0 == 0, x0, y0, x1, y1, retdest + PUSH ec_add_equal_points + // stack: ec_add_equal_points, y1 + y0, x0, y0, x1, y1, retdest JUMPI // stack: x0, y0, x1, y1, retdest POP @@ -211,7 +213,8 @@ ec_add_equal_first_coord: JUMP -ec_add_equal: +// Assumption: x0 == x1 and y0 == y1 +ec_add_equal_points: JUMPDEST // stack: x0, y0, x1, y1, retdest PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 @@ -236,6 +239,17 @@ ec_add_equal: // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest JUMP +ec_double: + JUMPDEST + // stack: x0, y0, retdest + DUP2 + // stack: y0, x0, y0, retdest + DUP2 + // stack: x0, y0, x0, y0, retdest + PUSH ec_add_equal_points + // stack: ec_add_equal_points, x0, y0, x0, y0, retdest + JUMP + submod: JUMPDEST // stack: x, y, retdest From 6db8539bc8acc2b1d3a4b5b94cb086257eb23769 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 10:46:07 +0200 Subject: [PATCH 03/30] Minor --- evm/src/cpu/kernel/asm/curve_add.asm | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index a542eddf..329d8250 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -1,6 +1,6 @@ // #define N 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // BN254 base field order -global ecadd: +global ec_add: PUSH 2 PUSH 1 PUSH 2 @@ -239,7 +239,7 @@ ec_add_equal_points: // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest JUMP -ec_double: +global ec_double: JUMPDEST // stack: x0, y0, retdest DUP2 From 4cdbb8c1a9ae2b4b25bc18e98ccab77621b16c59 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 10:47:29 +0200 Subject: [PATCH 04/30] Minor --- evm/src/cpu/kernel/asm/curve_mul.asm | 0 1 file changed, 0 insertions(+), 0 deletions(-) create mode 100644 evm/src/cpu/kernel/asm/curve_mul.asm diff --git a/evm/src/cpu/kernel/asm/curve_mul.asm b/evm/src/cpu/kernel/asm/curve_mul.asm new file mode 100644 index 00000000..e69de29b From a5988d6c269cf5ad4f7b33e59c7b002ee93078ce Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 11:09:25 +0200 Subject: [PATCH 05/30] Simplify --- evm/src/cpu/kernel/asm/curve_add.asm | 156 +++++++++------------------ evm/src/cpu/kernel/asm/curve_mul.asm | 3 + 2 files changed, 56 insertions(+), 103 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index 329d8250..f2a57277 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -36,6 +36,7 @@ global ec_add: JUMP +// Assumption: (x0,y0) is a valid point. ec_add_valid_first_point: JUMPDEST // stack: x1, y1, x0, y0, x1, y1, retdest @@ -55,6 +56,7 @@ ec_add_valid_first_point: // stack: retdest JUMP +// Assumption: (x0,y0) and (x1,y1) are valid points. ec_add_valid_points: JUMPDEST // stack: x0, y0, x1, y1, retdest @@ -68,32 +70,18 @@ ec_add_valid_points: // stack: ec_add_equal_first_coord, x0 == x1, x0, y0, x1, y1, retdest JUMPI // stack: x0, y0, x1, y1, retdest - PUSH ec_add_valid_points_contd - // stack: ec_add_valid_points_contd, x0, y0, x1, y1, retdest - DUP5 - // stack: y1, ec_add_valid_points_contd, x0, y0, x1, y1, retdest DUP4 - // stack: y0, y1, ec_add_valid_points_contd, x0, y0, x1, y1, retdest - PUSH submod - // stack: submod, y0, y1, ec_add_valid_points_contd, x0, y0, x1, y1, retdest - JUMP - -ec_add_valid_points_contd: - JUMPDEST - // stack: (y0 - y1) % N, x0, y0, x1, y1, retdest - PUSH ec_add_valid_points_contd2 - // stack: ec_add_valid_points_contd2, (y0 - y1) % N, x0, y0, x1, y1, retdest - DUP5 - // stack: x1, ec_add_valid_points_contd2, (y0 - y1) % N, x0, y0, x1, y1, retdest + // stack: y1, x0, y0, x1, y1, retdest + DUP3 + // stack: y0, y1, x0, y0, x1, y1, retdest + %submod + // stack: y0 - y1, x0, y0, x1, y1, retdest DUP4 - // stack: x0, x1, ec_add_valid_points_contd2, (y0 - y1) % N, x0, y0, x1, y1, retdest - PUSH submod - // stack: submod, x0, x1, ec_add_valid_points_contd2, (y0 - y1) % N, x0, y0, x1, y1, retdest - JUMP - -ec_add_valid_points_contd2: - JUMPDEST - // stack: (x0 - x1) % N, (y0 - y1) % N, x0, y0, x1, y1, retdest + // stack: x1, y0 - y1, x0, y0, x1, y1, retdest + DUP3 + // stack: x0, x1, y0 - y1, x0, y0, x1, y1, retdest + %submod + // stack: x0 - x1, y0 - y1, x0, y0, x1, y1, retdest //MODDIV // TODO: Implement this // stack: lambda, x0, y0, x1, y1, retdest PUSH ec_add_valid_points_with_lambda @@ -103,67 +91,39 @@ ec_add_valid_points_contd2: ec_add_valid_points_with_lambda: JUMPDEST // stack: lambda, x0, y0, x1, y1, retdest - PUSH ec_add_valid_points_contd4 - // stack: ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - DUP3 - // stack: x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - PUSH ec_add_valid_points_contd3 - // stack: ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - DUP7 - // stack: x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - DUP6 - // stack: lambda, N, x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - DUP1 - // stack: lambda, lambda, N, x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - MULMOD - // stack: lambda^2, x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - PUSH submod - // stack: submod, lambda^2, x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - JUMP - -ec_add_valid_points_contd3: - JUMPDEST - // stack: lambda^2 - x1, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - PUSH submod - // stack: submod, lambda^2 - x1, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - JUMP - -ec_add_valid_points_contd4: - JUMPDEST - // stack: x2, lambda, x0, y0, x1, y1, retdest - PUSH ec_add_valid_points_contd6 - // stack: ec_add_valid_points_contd6, x2, lambda, x0, y0, x1, y1, retdest - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, ec_add_valid_points_contd6, x2, lambda, x0, y0, x1, y1, retdest - PUSH ec_add_valid_points_contd5 - // stack: ec_add_valid_points_contd5, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, x1, y1, retdest - DUP4 - // stack: x2, ec_add_valid_points_contd5, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, x1, y1, retdest - SWAP8 - // stack: x1, x2, ec_add_valid_points_contd5, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest - PUSH submod - // stack: submod, x1, x2, ec_add_valid_points_contd5, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest - JUMP - -ec_add_valid_points_contd5: - JUMPDEST - // stack: x1 - x2, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + DUP2 + // stack: x0, lambda, x0, y0, x1, y1, retdest DUP5 - // stack: lambda, x1 - x2, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + // stack: x1, x0, lambda, x0, y0, x1, y1, retdest + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, x1, x0, lambda, x0, y0, x1, y1, retdest + DUP4 + // stack: lambda, N, x1, x0, lambda, x0, y0, x1, y1, retdest + DUP1 + // stack: lambda, lambda, N, x1, x0, lambda, x0, y0, x1, y1, retdest MULMOD - // stack: lambda * (x1 - x2), ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest - DUP7 - // stack: y1, lambda * (x1 - x2), ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + // stack: lambda^2, x1, x0, lambda, x0, y0, x1, y1, retdest + %submod + // stack: lambda^2 - x1, x0, lambda, x0, y0, x1, y1, retdest + %submod + // stack: x2, lambda, x0, y0, x1, y1, retdest + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, x2, lambda, x0, y0, x1, y1, retdest + DUP2 + // stack: x2, N, x2, lambda, x0, y0, x1, y1, retdest + SWAP6 + // stack: x1, x2, N, x2, lambda, x0, y0, y1, retdest + %submod + // stack: x1 - x2, N, x2, lambda, x0, y0, y1, retdest + DUP4 + // stack: lambda, x1 - x2, N, x2, lambda, x0, y0, y1, retdest + MULMOD + // stack: lambda * (x1 - x2), x2, lambda, x0, y0, y1, retdest + DUP6 + // stack: y1, lambda * (x1 - x2), x2, lambda, x0, y0, y1, retdest SWAP1 // stack: lambda * (x1 - x2), y1, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest - PUSH submod - // stack: submod, lambda * (x1 - x2), y1, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest - JUMP - -ec_add_valid_points_contd6: - JUMPDEST + %submod // stack: y2, x2, x0, y0, y1, retdest SWAP4 // stack: y1, x2, x0, y0, y2, retdest @@ -250,32 +210,22 @@ global ec_double: // stack: ec_add_equal_points, x0, y0, x0, y0, retdest JUMP -submod: +%macro submod JUMPDEST - // stack: x, y, retdest - SWAP1 - // stack: y, x, retdest - DUP1 - // stack: y, y, x, retdest - DUP3 - // stack: x, y, y, x, retdest - LT - // stack: x < y, y, x, retdest - PUSH submod - // stack: submod, x < y, y, x, retdest - JUMPI - // stack: y, x, retdest + // stack: x, y PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, y, x, retdest - SWAP2 - // stack: x, y, N, retdest + // stack: N, x, y + ADD + // stack: N + x, y // Doesn't overflow since 2N < 2^256 SUB - // stack: x - y, N, retdest, - MOD - // stack: (x - y) % N, retdest + // stack: N + x - y // Doesn't underflow since y < N + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, N + x - y SWAP1 - // stack: retdest, (x - y) % N - JUMP + // stack: N + x - y, N + MOD + // stack: (N + x - y) % N = (x-y) % N +%endmacro %macro ec_check // stack: x0, y0 diff --git a/evm/src/cpu/kernel/asm/curve_mul.asm b/evm/src/cpu/kernel/asm/curve_mul.asm index e69de29b..11cc4c25 100644 --- a/evm/src/cpu/kernel/asm/curve_mul.asm +++ b/evm/src/cpu/kernel/asm/curve_mul.asm @@ -0,0 +1,3 @@ +global ec_mul: + JUMPDEST + // stack: x, y, s, retdest From 4d376857445ce9c3af8864bc8253771db2dbae97 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 11:12:56 +0200 Subject: [PATCH 06/30] Comment --- evm/src/cpu/kernel/asm/curve_add.asm | 2 ++ 1 file changed, 2 insertions(+) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index f2a57277..271c556c 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -210,6 +210,8 @@ global ec_double: // stack: ec_add_equal_points, x0, y0, x0, y0, retdest JUMP +// Assumption: x, y < N and 2N < 2^256. +// Note: Doesn't hold for Secp256k1 base field. %macro submod JUMPDEST // stack: x, y From 8a44c557c555f692d971a84abb4e4a46cfce0c82 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 12:11:35 +0200 Subject: [PATCH 07/30] Curve mul assembly --- evm/src/cpu/kernel/asm/curve_add.asm | 3 +- evm/src/cpu/kernel/asm/curve_mul.asm | 112 +++++++++++++++++++++++++++ 2 files changed, 114 insertions(+), 1 deletion(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index 271c556c..c585006f 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -57,7 +57,7 @@ ec_add_valid_first_point: JUMP // Assumption: (x0,y0) and (x1,y1) are valid points. -ec_add_valid_points: +global ec_add_valid_points: JUMPDEST // stack: x0, y0, x1, y1, retdest DUP3 @@ -199,6 +199,7 @@ ec_add_equal_points: // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest JUMP +// Assumption: (x0,y0) is a valid point. global ec_double: JUMPDEST // stack: x0, y0, retdest diff --git a/evm/src/cpu/kernel/asm/curve_mul.asm b/evm/src/cpu/kernel/asm/curve_mul.asm index 11cc4c25..cbd606ca 100644 --- a/evm/src/cpu/kernel/asm/curve_mul.asm +++ b/evm/src/cpu/kernel/asm/curve_mul.asm @@ -1,3 +1,115 @@ global ec_mul: JUMPDEST // stack: x, y, s, retdest + DUP2 + // stack: y, x, y, s, retdest + DUP2 + // stack: x, y, x, y, s, retdest + %ec_check + // stack: isValid(x, y), x, y, s, retdest + PUSH ec_mul_valid_point + // stack: ec_mul_valid_point, isValid(x, y), x, y, s, retdest + JUMPI + // stack: x, y, s, retdest + POP + // stack: y, s, retdest + POP + // stack: s, retdest + POP + // stack: retdest + JUMP + +// Same algorithm as `exp` +ec_mul_valid_point: + JUMPDEST + // stack: x, y, s, retdest + DUP3 + // stack: s, x, y, s, retdest + PUSH step_case + // stack: step_case, s, x, y, s, retdest + JUMPI + // stack: x, y, s, retdest + POP + // stack: y, s, retdest + POP + // stack: s, retdest + POP + // stack: retdest + PUSH 0 + // stack: 0, retdest + PUSH 0 + // stack: 0, 0, retdest + SWAP2 + // stack: retdest, 0, 0 + JUMP + +step_case: + JUMPDEST + // stack: x, y, s, retdest + PUSH recursion_return + // stack: recursion_return, x, y, s, retdest + PUSH 2 + // stack: 2, recursion_return, x, y, s, retdest + DUP5 + // stack: s, 2, recursion_return, x, y, s, retdest + DIV + // stack: s / 2, recursion_return, x, y, s, retdest + PUSH step_case_contd + // stack: step_case_contd, s / 2, recursion_return, x, y, s, retdest + DUP5 + // stack: y, step_case_contd, s / 2, recursion_return, x, y, s, retdest + DUP5 + // stack: x, y, step_case_contd, s / 2, recursion_return, x, y, s, retdest + PUSH ec_double + // stack: ec_double, x, y, step_case_contd, s / 2, recursion_return, x, y, s, retdest + JUMP + +// Assumption: 2(x,y) = (x',y') +step_case_contd: + JUMPDEST + // stack: x', y', s / 2, recursion_return, x, y, s, retdest + PUSH ec_mul_valid_point + // stack: ec_mul_valid_point, x', y', s / 2, recursion_return, x, y, s, retdest + JUMP + +recursion_return: + JUMPDEST + // stack: x', y', x, y, s, retdest + SWAP4 + // stack: s, y', x, y, x', retdest + PUSH 1 + // stack: 1, s, y', x, y, x', retdest + AND + // stack: s & 1, y', x, y, x', retdest + SWAP1 + // stack: y', s & 1, x, y, x', retdest + SWAP2 + // stack: x, s & 1, y', y, x', retdest + SWAP3 + // stack: y, s & 1, y', x, x', retdest + SWAP4 + // stack: x', s & 1, y', x, y, retdest + SWAP1 + // stack: s & 1, x', y', x, y, retdest + PUSH odd_scalar + // stack: odd_scalar, s & 1, x', y', x, y, retdest + JUMPI + // stack: x', y', x, y, retdest + SWAP3 + // stack: y, y', x, x', retdest + POP + // stack: y', x, x', retdest + SWAP1 + // stack: x, y', x', retdest + POP + // stack: y', x', retdest + SWAP2 + // stack: retdest, x', y' + JUMP + +odd_scalar: + JUMPDEST + // stack: x', y', x, y, retdest + PUSH ec_add_valid_points + // stack: ec_add_valid_points, x', y', x, y, retdest + JUMP From eed7cde388bd835396e877280d034b19a8ecd700 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 15:01:40 +0200 Subject: [PATCH 08/30] Add moddiv for testing --- evm/src/cpu/kernel/aggregator.rs | 11 +- evm/src/cpu/kernel/asm/curve_add.asm | 6 +- evm/src/cpu/kernel/asm/moddiv.asm | 500 +++++++++++++++++++++++++++ 3 files changed, 510 insertions(+), 7 deletions(-) create mode 100644 evm/src/cpu/kernel/asm/moddiv.asm diff --git a/evm/src/cpu/kernel/aggregator.rs b/evm/src/cpu/kernel/aggregator.rs index 773842f8..83e0eb38 100644 --- a/evm/src/cpu/kernel/aggregator.rs +++ b/evm/src/cpu/kernel/aggregator.rs @@ -9,10 +9,12 @@ use crate::cpu::kernel::parser::parse; pub(crate) fn combined_kernel() -> Kernel { let files = vec![ include_str!("asm/basic_macros.asm"), - include_str!("asm/exp.asm"), + // include_str!("asm/exp.asm"), include_str!("asm/curve_add.asm"), - include_str!("asm/storage_read.asm"), - include_str!("asm/storage_write.asm"), + // include_str!("asm/curve_mul.asm"), + include_str!("asm/moddiv.asm"), + // include_str!("asm/storage_read.asm"), + // include_str!("asm/storage_write.asm"), ]; let parsed_files = files.iter().map(|f| parse(f)).collect_vec(); @@ -26,6 +28,7 @@ mod tests { #[test] fn make_kernel() { // Make sure we can parse and assemble the entire kernel. - combined_kernel(); + let ker = combined_kernel(); + println!("{:?}", ker.code) } } diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index c585006f..2ee08d65 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -82,7 +82,7 @@ global ec_add_valid_points: // stack: x0, x1, y0 - y1, x0, y0, x1, y1, retdest %submod // stack: x0 - x1, y0 - y1, x0, y0, x1, y1, retdest - //MODDIV // TODO: Implement this + %moddiv // stack: lambda, x0, y0, x1, y1, retdest PUSH ec_add_valid_points_with_lambda // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest @@ -193,14 +193,14 @@ ec_add_equal_points: // stack: 3/2 * x0^2, x0, y0, x1, y1, retdest DUP3 // stack: y0, 3/2 * x0^2, x0, y0, x1, y1, retdest - //MODDIV // TODO: Implement this + %moddiv // stack: lambda, x0, y0, x1, y1, retdest PUSH ec_add_valid_points_with_lambda // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest JUMP -// Assumption: (x0,y0) is a valid point. global ec_double: +// Assumption: (x0,y0) is a valid point. JUMPDEST // stack: x0, y0, retdest DUP2 diff --git a/evm/src/cpu/kernel/asm/moddiv.asm b/evm/src/cpu/kernel/asm/moddiv.asm new file mode 100644 index 00000000..f1c025de --- /dev/null +++ b/evm/src/cpu/kernel/asm/moddiv.asm @@ -0,0 +1,500 @@ +/// Division modulo 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47, the BN254 base field order +/// To replace with more efficient method using non-determinism later. + +// Returns y * (x^-1) where the inverse is taken modulo N +%macro moddiv + // stack: x, y + %inverse + // stack: x^-1, y + %mulmodn +%endmacro + +%macro mulmodn + // stack: x, y + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, x, y + SWAP2 + // stack: y, x, N + MULMOD +%endmacro + +%macro squaremodn + // stack: x + DUP1 + // stack: x, x + %mulmodn +%endmacro + +%macro inverse + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn +%endmacro From 7364248e60c2ffca84714fbc2c5274c86b92adb4 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 15:43:41 +0200 Subject: [PATCH 09/30] Fixes --- evm/src/cpu/kernel/asm/curve_add.asm | 37 ++++++++++++++-------------- evm/src/cpu/kernel/asm/moddiv.asm | 5 ++++ 2 files changed, 23 insertions(+), 19 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index 2ee08d65..92541284 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -1,8 +1,8 @@ // #define N 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // BN254 base field order global ec_add: - PUSH 2 - PUSH 1 + PUSH 0x1bf9384aa3f0b3ad763aee81940cacdde1af71617c06f46e11510f14f3d5d121 + PUSH 0xe7313274bb29566ff0c8220eb9841de1d96c2923c6a4028f7dd3c6a14cee770 PUSH 2 PUSH 1 JUMPDEST @@ -111,31 +111,31 @@ ec_add_valid_points_with_lambda: // stack: N, x2, lambda, x0, y0, x1, y1, retdest DUP2 // stack: x2, N, x2, lambda, x0, y0, x1, y1, retdest - SWAP6 - // stack: x1, x2, N, x2, lambda, x0, y0, y1, retdest + DUP7 + // stack: x1, x2, N, x2, lambda, x0, y0, x1, y1, retdest %submod - // stack: x1 - x2, N, x2, lambda, x0, y0, y1, retdest + // stack: x1 - x2, N, x2, lambda, x0, y0, x1, y1, retdest DUP4 - // stack: lambda, x1 - x2, N, x2, lambda, x0, y0, y1, retdest + // stack: lambda, x1 - x2, N, x2, lambda, x0, y0, x1, y1, retdest MULMOD - // stack: lambda * (x1 - x2), x2, lambda, x0, y0, y1, retdest - DUP6 - // stack: y1, lambda * (x1 - x2), x2, lambda, x0, y0, y1, retdest + // stack: lambda * (x1 - x2), x2, lambda, x0, y0, x1, y1, retdest + DUP7 + // stack: y1, lambda * (x1 - x2), x2, lambda, x0, y0, x1, y1, retdest SWAP1 - // stack: lambda * (x1 - x2), y1, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + // stack: lambda * (x1 - x2), y1, x2, lambda, x0, y0, x1, y1, retdest %submod - // stack: y2, x2, x0, y0, y1, retdest + // stack: y2, x2, x0, y0, x1, y1, retdest SWAP4 - // stack: y1, x2, x0, y0, y2, retdest + // stack: x1, x2, x0, y0, y2, y1, retdest POP - // stack: x2, x0, y0, y2, retdest - SWAP2 - // stack: y0, x0, x2, y2, retdest + // stack: x2, x0, y0, y2, y1, retdest + SWAP4 + // stack: y1, x0, y0, y2, x2, retdest POP - // stack: x0, x2, y2, retdest + // stack: x0, y0, y2, x2, retdest + POP + // stack: y0, y2, x2, retdest POP - // stack: x2, y2, retdest - SWAP1 // stack: y2, x2, retdest SWAP2 // stack: retdest, x2, y2 @@ -265,4 +265,3 @@ global ec_double: EQ // stack: y0^2 % N == (x0^3 + 3) % N %endmacro - diff --git a/evm/src/cpu/kernel/asm/moddiv.asm b/evm/src/cpu/kernel/asm/moddiv.asm index f1c025de..2dd28fa7 100644 --- a/evm/src/cpu/kernel/asm/moddiv.asm +++ b/evm/src/cpu/kernel/asm/moddiv.asm @@ -26,6 +26,7 @@ %endmacro %macro inverse + DUP1 %squaremodn DUP2 %mulmodn @@ -497,4 +498,8 @@ %squaremodn DUP2 %mulmodn + SWAP1 + // stack: x, x^-1 + POP + // stack: x^-1 %endmacro From 8873eaba1107e3d2c42d31a3fd87ed47d9b883b3 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 16:11:55 +0200 Subject: [PATCH 10/30] Find labels before assembly --- evm/src/cpu/kernel/assembler.rs | 55 ++++++++++++++++++++++----------- 1 file changed, 37 insertions(+), 18 deletions(-) diff --git a/evm/src/cpu/kernel/assembler.rs b/evm/src/cpu/kernel/assembler.rs index fce2016c..82c62d65 100644 --- a/evm/src/cpu/kernel/assembler.rs +++ b/evm/src/cpu/kernel/assembler.rs @@ -1,5 +1,7 @@ use std::collections::HashMap; +use itertools::izip; + use super::ast::PushTarget; use crate::cpu::kernel::{ ast::{File, Item}, @@ -19,12 +21,24 @@ pub struct Kernel { pub(crate) fn assemble(files: Vec) -> Kernel { let macros = find_macros(&files); - let mut code = vec![]; let mut global_labels = HashMap::new(); + let mut offset = 0; + let mut expanded_files = Vec::with_capacity(files.len()); + let mut local_labels = Vec::with_capacity(files.len()); for file in files { let expanded_file = expand_macros(file.body, ¯os); - assemble_file(expanded_file, &mut code, &mut global_labels); + local_labels.push(find_labels(&expanded_file, &mut offset, &mut global_labels)); + expanded_files.push(expanded_file); } + let mut code = vec![]; + for (file, locals) in izip!(expanded_files, local_labels) { + assemble_file(file, &mut code, locals, &global_labels); + } + assert_eq!( + code.len(), + offset, + "Code length {} doesn't match offset {}." + ); Kernel { code, global_labels, @@ -67,30 +81,41 @@ fn expand_macros(body: Vec, macros: &HashMap>) -> Vec, code: &mut Vec, global_labels: &mut HashMap) { - // First discover the offset of each label in this file. +fn find_labels( + body: &[Item], + offset: &mut usize, + global_labels: &mut HashMap, +) -> HashMap { + // Discover the offset of each label in this file. let mut local_labels = HashMap::::new(); - let mut offset = code.len(); - for item in &body { + for item in body { match item { Item::MacroDef(_, _) | Item::MacroCall(_) => { panic!("Macros should have been expanded already") } Item::GlobalLabelDeclaration(label) => { - let old = global_labels.insert(label.clone(), offset); + let old = global_labels.insert(label.clone(), *offset); assert!(old.is_none(), "Duplicate global label: {}", label); } Item::LocalLabelDeclaration(label) => { - let old = local_labels.insert(label.clone(), offset); + let old = local_labels.insert(label.clone(), *offset); assert!(old.is_none(), "Duplicate local label: {}", label); } - Item::Push(target) => offset += 1 + push_target_size(target) as usize, - Item::StandardOp(_) => offset += 1, - Item::Bytes(bytes) => offset += bytes.len(), + Item::Push(target) => *offset += 1 + push_target_size(target) as usize, + Item::StandardOp(_) => *offset += 1, + Item::Bytes(bytes) => *offset += bytes.len(), } } + local_labels +} - // Now that we have label offsets, we can assemble the file. +fn assemble_file( + body: Vec, + code: &mut Vec, + local_labels: HashMap, + global_labels: &HashMap, +) { + // Assemble the file. for item in body { match item { Item::MacroDef(_, _) | Item::MacroCall(_) => { @@ -124,12 +149,6 @@ fn assemble_file(body: Vec, code: &mut Vec, global_labels: &mut HashMa Item::Bytes(bytes) => code.extend(bytes.iter().map(|b| b.to_u8())), } } - - assert_eq!( - code.len(), - offset, - "The two phases gave different code lengths" - ); } /// The size of a `PushTarget`, in bytes. From ee80fa4a396e8e9309e9bcddb5123ad1500643b3 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 16:19:23 +0200 Subject: [PATCH 11/30] Minor --- evm/src/cpu/kernel/assembler.rs | 6 +----- 1 file changed, 1 insertion(+), 5 deletions(-) diff --git a/evm/src/cpu/kernel/assembler.rs b/evm/src/cpu/kernel/assembler.rs index 82c62d65..d7e40f24 100644 --- a/evm/src/cpu/kernel/assembler.rs +++ b/evm/src/cpu/kernel/assembler.rs @@ -34,11 +34,7 @@ pub(crate) fn assemble(files: Vec) -> Kernel { for (file, locals) in izip!(expanded_files, local_labels) { assemble_file(file, &mut code, locals, &global_labels); } - assert_eq!( - code.len(), - offset, - "Code length {} doesn't match offset {}." - ); + assert_eq!(code.len(), offset, "Code length doesn't match offset."); Kernel { code, global_labels, From 8e711d413a63ec700f8aa3a3ba3e4166ff5e8881 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 16:41:28 +0200 Subject: [PATCH 12/30] Minor --- evm/src/cpu/kernel/asm/curve_add.asm | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index 92541284..b200817a 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -199,8 +199,8 @@ ec_add_equal_points: // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest JUMP -global ec_double: // Assumption: (x0,y0) is a valid point. +global ec_double: JUMPDEST // stack: x0, y0, retdest DUP2 @@ -214,7 +214,6 @@ global ec_double: // Assumption: x, y < N and 2N < 2^256. // Note: Doesn't hold for Secp256k1 base field. %macro submod - JUMPDEST // stack: x, y PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // stack: N, x, y From fd1d9fe85e696111fee60c694a51315da46589bf Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 17:37:34 +0200 Subject: [PATCH 13/30] Add range check --- evm/src/cpu/kernel/asm/curve_add.asm | 72 ++++++++++++++++++---------- 1 file changed, 46 insertions(+), 26 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index b200817a..0c256b3e 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -1,8 +1,8 @@ // #define N 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // BN254 base field order global ec_add: - PUSH 0x1bf9384aa3f0b3ad763aee81940cacdde1af71617c06f46e11510f14f3d5d121 - PUSH 0xe7313274bb29566ff0c8220eb9841de1d96c2923c6a4028f7dd3c6a14cee770 + PUSH 0 + PUSH 0 PUSH 2 PUSH 1 JUMPDEST @@ -233,34 +233,54 @@ global ec_double: // stack: x0, y0 PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // stack: N, x0, y0 - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, N, x0, y0 - SWAP2 - // stack: x0, N, N, y0 - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, x0, N, N, y0 DUP2 - // stack: x0, N, x0, N, N, y0 - DUP1 - // stack: x0, x0, N, x0, N, N, y0 - MULMOD - // stack: x0^2 % N, x0, N, N, y0 - MULMOD - // stack: x0^3 % N, N, y0 - PUSH 3 - // stack: 3, x0^3 % N, N, y0 - ADDMOD - // stack: (x0^3 + 3) % N, y0 - SWAP1 - // stack: y0, (x0^3 + 3) % N + // stack: x0, N, x0, y0 + LT + // stack: x0 < N, x0, y0 PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, y0, (x0^3 + 3) % N + // stack: N, x0 < N, x0, y0 + DUP4 + // stack: y0, N, x0 < N, x0, y0 + LT + // stack: y0 < N, x0 < N, x0, y0 + AND + // stack: (y0 < N) & (x0 < N), x0, y0 + SWAP2 + // stack: y0, x0, (y0 < N) & (x0 < N), x0 SWAP1 - // stack: y0, N, (x0^3 + 3) % N + // stack: x0, y0, (y0 < N) & (x0 < N) + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, x0, y0, b + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, N, x0, y0, b + SWAP2 + // stack: x0, N, N, y0, b + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, x0, N, N, y0, b + DUP2 + // stack: x0, N, x0, N, N, y0, b DUP1 - // stack: y0, y0, N, (x0^3 + 3) % N + // stack: x0, x0, N, x0, N, N, y0, b MULMOD - // stack: y0^2 % N, (x0^3 + 3) % N + // stack: x0^2 % N, x0, N, N, y0, b + MULMOD + // stack: x0^3 % N, N, y0, b + PUSH 3 + // stack: 3, x0^3 % N, N, y0, b + ADDMOD + // stack: (x0^3 + 3) % N, y0, b + SWAP1 + // stack: y0, (x0^3 + 3) % N, b + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, y0, (x0^3 + 3) % N, b + SWAP1 + // stack: y0, N, (x0^3 + 3) % N, b + DUP1 + // stack: y0, y0, N, (x0^3 + 3) % N, b + MULMOD + // stack: y0^2 % N, (x0^3 + 3) % N, b EQ - // stack: y0^2 % N == (x0^3 + 3) % N + // stack: y0^2 % N == (x0^3 + 3) % N, b + AND + // stack: y0^2 % N == (x0^3 + 3) % N & (x < N) & (y < N) %endmacro From 9e90d7d115b8889057ce07d04d6507b623230a52 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 20:27:55 +0200 Subject: [PATCH 14/30] Add check for zero point --- evm/src/cpu/kernel/asm/curve_add.asm | 130 ++++++++++++++++++++++++++- 1 file changed, 128 insertions(+), 2 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index 0c256b3e..dff74a5f 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -1,12 +1,44 @@ // #define N 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // BN254 base field order global ec_add: - PUSH 0 - PUSH 0 PUSH 2 PUSH 1 + PUSH 0 + PUSH 0 JUMPDEST // stack: x0, y0, x1, y1, retdest + DUP2 + // stack: y0, x0, y0, x1, y1, retdest + DUP2 + // stack: x0, y0, x0, y0, x1, y1, retdest + ISZERO + // stack: x0==0, y0, x0, y0, x1, y1, retdest + SWAP1 + // stack: y0, x0==0, x0, y0, x1, y1, retdest + ISZERO + // stack: y0==0, x0==0, x0, y0, x1, y1, retdest + AND + // stack: y0==0 & x0==0, x0, y0, x1, y1, retdest + PUSH ec_add_first_zero + // stack: ec_add_first_zero, y0==0 & x0==0, x0, y0, x1, y1, retdest + JUMPI + // stack: x0, y0, x1, y1, retdest + DUP4 + // stack: y1, x0, y0, x1, y1, retdest + DUP4 + // stack: x1, y1, x0, y0, x1, y1, retdest + ISZERO + // stack: x1==0, y1, x0, y0, x1, y1, retdest + SWAP1 + // stack: y1, x1==0, x0, y0, x1, y1, retdest + ISZERO + // stack: y1==0, x1==0, x0, y0, x1, y1, retdest + AND + // stack: y1==0 & x1==0, x0, y0, x1, y1, retdest + PUSH ec_add_snd_zero + // stack: ec_add_snd_zero, y1==0 & x1==0, x0, y0, x1, y1, retdest + JUMPI + // stack: x0, y0, x1, y1, retdest DUP4 // stack: y1, x0, y0, x1, y1, retdest DUP4 @@ -35,6 +67,100 @@ global ec_add: // stack: retdest JUMP +// Assumption (x0,y0) == (0,0) +ec_add_first_zero: + JUMPDEST + // stack: x0, y0, x1, y1, retdest + POP + // stack: y0, x1, y1, retdest + POP + // stack: x1, y1, retdest + DUP2 + // stack: y1, x1, y1, retdest + DUP2 + // stack: x1, y1, x1, y1, retdest + ISZERO + // stack: x1==0, y1, x1, y1, retdest + SWAP1 + // stack: y1, x1==0, x1, y1, retdest + ISZERO + // stack: y1==0, x1==0, x1, y1, retdest + AND + // stack: y1==0 & x1==0, x1, y1, retdest + PUSH ret_zero + // stack: ret_zero, y1==0 & x1==0, x1, y1, retdest + JUMPI + // stack: x1, y1, retdest + DUP2 + // stack: y1, x1, y1, retdest + DUP2 + // stack: x1, y1, x1, y1, retdest + %ec_check + // stack: isValid(x1, y1), x1, y1, retdest + PUSH ec_noop + // stack: ec_noop, isValid(x1, y1), x1, y1, retdest + JUMPI + // stack: x1, y1, retdest + POP + // stack: y1, retdest + POP + // stack: retdest + JUMP + +// Assumption (x1,y1) == (0,0) and (x0,y0) != (0,0) +ec_add_snd_zero: + JUMPDEST + // stack: x0, y0, x1, y1, retdest + SWAP2 + // stack: x1, y0, x0, y1, retdest + POP + // stack: y0, x0, y1, retdest + SWAP2 + // stack: y1, x0, y0, retdest + POP + // stack: x0, y0, retdest + DUP2 + // stack: y0, x0, y0, retdest + DUP2 + // stack: x0, y0, x0, y0, retdest + %ec_check + // stack: isValid(x0, y0), x0, y0, retdest + PUSH ec_noop + // stack: ec_noop, isValid(x0, y0), x0, y0, retdest + JUMPI + // stack: x0, y0, retdest + POP + // stack: y0, retdest + POP + // stack: retdest + JUMP + +ec_noop: + JUMPDEST + // x, y, retdest + SWAP1 + // y, x, retdest + SWAP2 + // retdest, x, y + JUMP + +ret_zero: + JUMPDEST + // stack: x, y, retdest + POP + // stack: y, retdest + POP + // stack: retdest + PUSH 0 + // stack: 0, retdest + PUSH 0 + // stack: 0, 0, retdest + SWAP2 + // stack: 0, retdest, 0 + SWAP1 + // stack: retdest, 0, 0 + JUMP + // Assumption: (x0,y0) is a valid point. ec_add_valid_first_point: From fb8a67b0d9c0be885e9ee90749da61859e99ea8f Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 21:12:11 +0200 Subject: [PATCH 15/30] Working ecmul --- evm/src/cpu/kernel/aggregator.rs | 2 +- evm/src/cpu/kernel/asm/curve_add.asm | 23 +++++++++++++---------- evm/src/cpu/kernel/asm/curve_mul.asm | 9 +++++++-- 3 files changed, 21 insertions(+), 13 deletions(-) diff --git a/evm/src/cpu/kernel/aggregator.rs b/evm/src/cpu/kernel/aggregator.rs index 83e0eb38..9b8a65c6 100644 --- a/evm/src/cpu/kernel/aggregator.rs +++ b/evm/src/cpu/kernel/aggregator.rs @@ -10,8 +10,8 @@ pub(crate) fn combined_kernel() -> Kernel { let files = vec![ include_str!("asm/basic_macros.asm"), // include_str!("asm/exp.asm"), + include_str!("asm/curve_mul.asm"), include_str!("asm/curve_add.asm"), - // include_str!("asm/curve_mul.asm"), include_str!("asm/moddiv.asm"), // include_str!("asm/storage_read.asm"), // include_str!("asm/storage_write.asm"), diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index dff74a5f..00e88495 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -1,10 +1,10 @@ // #define N 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // BN254 base field order global ec_add: - PUSH 2 - PUSH 1 - PUSH 0 - PUSH 0 + //PUSH 2 + //PUSH 1 + //PUSH 0x1bf9384aa3f0b3ad763aee81940cacdde1af71617c06f46e11510f14f3d5d121 + //PUSH 0xe7313274bb29566ff0c8220eb9841de1d96c2923c6a4028f7dd3c6a14cee770 JUMPDEST // stack: x0, y0, x1, y1, retdest DUP2 @@ -250,13 +250,15 @@ ec_add_valid_points_with_lambda: SWAP1 // stack: lambda * (x1 - x2), y1, x2, lambda, x0, y0, x1, y1, retdest %submod - // stack: y2, x2, x0, y0, x1, y1, retdest - SWAP4 - // stack: x1, x2, x0, y0, y2, y1, retdest + // stack: y2, x2, lambda, x0, y0, x1, y1, retdest + SWAP5 + // stack: x1, x2, lambda, x0, y0, y2, y1, retdest POP - // stack: x2, x0, y0, y2, y1, retdest - SWAP4 - // stack: y1, x0, y0, y2, x2, retdest + // stack: x2, lambda, x0, y0, y2, y1, retdest + SWAP5 + // stack: y1, lambda, x0, y0, y2, x2, retdest + POP + // stack: lambda, x0, y0, y2, x2, retdest POP // stack: x0, y0, y2, x2, retdest POP @@ -267,6 +269,7 @@ ec_add_valid_points_with_lambda: // stack: retdest, x2, y2 JUMP +// Assumption: (x0,y0) and (x1,y1) are valid points and x0 == x1 ec_add_equal_first_coord: JUMPDEST // stack: x0, y0, x1, y1, retdest with x0 == x1 diff --git a/evm/src/cpu/kernel/asm/curve_mul.asm b/evm/src/cpu/kernel/asm/curve_mul.asm index cbd606ca..3a3253e4 100644 --- a/evm/src/cpu/kernel/asm/curve_mul.asm +++ b/evm/src/cpu/kernel/asm/curve_mul.asm @@ -1,4 +1,9 @@ global ec_mul: + // Uncomment for test inputs. + // PUSH 0xdeadbeef + // PUSH 0xd + // PUSH 2 + // PUSH 1 JUMPDEST // stack: x, y, s, retdest DUP2 @@ -110,6 +115,6 @@ recursion_return: odd_scalar: JUMPDEST // stack: x', y', x, y, retdest - PUSH ec_add_valid_points - // stack: ec_add_valid_points, x', y', x, y, retdest + PUSH ec_add + // stack: ec_add, x', y', x, y, retdest JUMP From 8ffd25c1277e74b8ff672f9724cec4b909cc8003 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 21:22:05 +0200 Subject: [PATCH 16/30] Add zero case for mul --- evm/src/cpu/kernel/asm/curve_add.asm | 10 +++++---- evm/src/cpu/kernel/asm/curve_mul.asm | 33 ++++++++++++++++++++++++++++ 2 files changed, 39 insertions(+), 4 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index 00e88495..779f3b7c 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -1,10 +1,12 @@ // #define N 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // BN254 base field order global ec_add: - //PUSH 2 - //PUSH 1 - //PUSH 0x1bf9384aa3f0b3ad763aee81940cacdde1af71617c06f46e11510f14f3d5d121 - //PUSH 0xe7313274bb29566ff0c8220eb9841de1d96c2923c6a4028f7dd3c6a14cee770 + // Uncomment for test inputs. + // PUSH 0xdeadbeef + // PUSH 2 + // PUSH 1 + // PUSH 0x1bf9384aa3f0b3ad763aee81940cacdde1af71617c06f46e11510f14f3d5d121 + // PUSH 0xe7313274bb29566ff0c8220eb9841de1d96c2923c6a4028f7dd3c6a14cee770 JUMPDEST // stack: x0, y0, x1, y1, retdest DUP2 diff --git a/evm/src/cpu/kernel/asm/curve_mul.asm b/evm/src/cpu/kernel/asm/curve_mul.asm index 3a3253e4..bd092571 100644 --- a/evm/src/cpu/kernel/asm/curve_mul.asm +++ b/evm/src/cpu/kernel/asm/curve_mul.asm @@ -10,6 +10,22 @@ global ec_mul: // stack: y, x, y, s, retdest DUP2 // stack: x, y, x, y, s, retdest + ISZERO + // stack: x==0, y, x, y, s, retdest + SWAP1 + // stack: y, x==0, x, y, s, retdest + ISZERO + // stack: y==0, x==0, x, y, s, retdest + AND + // stack: y==0 & x==0, x, y, s, retdest + PUSH ret_zero + // stack: ret_zero, y==0 & x==0, x, y, s, retdest + JUMPI + // stack: x, y, s, retdest + DUP2 + // stack: y, x, y, s, retdest + DUP2 + // stack: x, y, x, y, s, retdest %ec_check // stack: isValid(x, y), x, y, s, retdest PUSH ec_mul_valid_point @@ -118,3 +134,20 @@ odd_scalar: PUSH ec_add // stack: ec_add, x', y', x, y, retdest JUMP + +ret_zero: + JUMPDEST + // stack: x, y, s, retdest + POP + // stack: y, s, retdest + POP + // stack: s, retdest + POP + // stack: retdest + PUSH 0 + // stack: 0, retdest + PUSH 0 + // stack: 0, 0, retdest + SWAP2 + // stack: retdest, 0, 0 + JUMP From 5bae732ea030ba64513c3e3628e75302239b5bbf Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 21:24:51 +0200 Subject: [PATCH 17/30] Minor --- evm/src/cpu/kernel/aggregator.rs | 9 ++++----- evm/src/cpu/kernel/asm/curve_add.asm | 4 ++-- evm/src/cpu/kernel/asm/curve_mul.asm | 2 +- 3 files changed, 7 insertions(+), 8 deletions(-) diff --git a/evm/src/cpu/kernel/aggregator.rs b/evm/src/cpu/kernel/aggregator.rs index 9b8a65c6..ac0d6f7c 100644 --- a/evm/src/cpu/kernel/aggregator.rs +++ b/evm/src/cpu/kernel/aggregator.rs @@ -9,12 +9,12 @@ use crate::cpu::kernel::parser::parse; pub(crate) fn combined_kernel() -> Kernel { let files = vec![ include_str!("asm/basic_macros.asm"), - // include_str!("asm/exp.asm"), + include_str!("asm/exp.asm"), include_str!("asm/curve_mul.asm"), include_str!("asm/curve_add.asm"), include_str!("asm/moddiv.asm"), - // include_str!("asm/storage_read.asm"), - // include_str!("asm/storage_write.asm"), + include_str!("asm/storage_read.asm"), + include_str!("asm/storage_write.asm"), ]; let parsed_files = files.iter().map(|f| parse(f)).collect_vec(); @@ -28,7 +28,6 @@ mod tests { #[test] fn make_kernel() { // Make sure we can parse and assemble the entire kernel. - let ker = combined_kernel(); - println!("{:?}", ker.code) + combined_kernel(); } } diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index 779f3b7c..0f230159 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -69,7 +69,7 @@ global ec_add: // stack: retdest JUMP -// Assumption (x0,y0) == (0,0) +// Assumption: (x0,y0) == (0,0) ec_add_first_zero: JUMPDEST // stack: x0, y0, x1, y1, retdest @@ -109,7 +109,7 @@ ec_add_first_zero: // stack: retdest JUMP -// Assumption (x1,y1) == (0,0) and (x0,y0) != (0,0) +// Assumption: (x1,y1) == (0,0) and (x0,y0) != (0,0) ec_add_snd_zero: JUMPDEST // stack: x0, y0, x1, y1, retdest diff --git a/evm/src/cpu/kernel/asm/curve_mul.asm b/evm/src/cpu/kernel/asm/curve_mul.asm index bd092571..440ebe8b 100644 --- a/evm/src/cpu/kernel/asm/curve_mul.asm +++ b/evm/src/cpu/kernel/asm/curve_mul.asm @@ -40,7 +40,7 @@ global ec_mul: // stack: retdest JUMP -// Same algorithm as `exp` +// Same algorithm as in `exp.asm` ec_mul_valid_point: JUMPDEST // stack: x, y, s, retdest From 9747343ac2b69ca67725ebae48e72f8b988c0958 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Wed, 6 Jul 2022 09:25:41 +0200 Subject: [PATCH 18/30] PR feedback --- evm/src/cpu/kernel/asm/curve_add.asm | 394 ++++++++++++--------------- evm/src/cpu/kernel/asm/curve_mul.asm | 16 +- 2 files changed, 185 insertions(+), 225 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index 0f230159..6d69fea9 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -13,14 +13,40 @@ global ec_add: // stack: y0, x0, y0, x1, y1, retdest DUP2 // stack: x0, y0, x0, y0, x1, y1, retdest - ISZERO - // stack: x0==0, y0, x0, y0, x1, y1, retdest - SWAP1 - // stack: y0, x0==0, x0, y0, x1, y1, retdest - ISZERO - // stack: y0==0, x0==0, x0, y0, x1, y1, retdest + %ec_check + // stack: isValid(x0, y0), x0, y0, x1, y1, retdest + DUP5 + // stack: x1, isValid(x0, y0), x0, y0, x1, y1, retdest + DUP5 + // stack: x1, y1, isValid(x0, y0), x0, y0, x1, y1, retdest + %ec_check + // stack: isValid(x1, y1), isValid(x0, y0), x0, y0, x1, y1, retdest AND - // stack: y0==0 & x0==0, x0, y0, x1, y1, retdest + // stack: isValid(x1, y1) & isValid(x0, y0), x0, y0, x1, y1, retdest + PUSH ec_add_valid_points + // stack: ec_add_valid_points, isValid(x1, y1) & isValid(x0, y0), x0, y0, x1, y1, retdest + JUMPI + // stack: x0, y0, x1, y1, retdest + POP + // stack: y0, x1, y1, retdest + POP + // stack: x1, y1, retdest + POP + // stack: y1, retdest + POP + // stack: retdest + %ec_invalid_input + +// Assumption: (x0,y0) and (x1,y1) are valid points. +global ec_add_valid_points: + JUMPDEST + // stack: x0, y0, x1, y1, retdest + DUP2 + // stack: y0, x0, y0, x1, y1, retdest + DUP2 + // stack: x0, y0, x0, y0, x1, y1, retdest + %ec_isidentity + // stack: (x0,y0)==(0,0), x0, y0, x1, y1, retdest PUSH ec_add_first_zero // stack: ec_add_first_zero, y0==0 & x0==0, x0, y0, x1, y1, retdest JUMPI @@ -29,165 +55,12 @@ global ec_add: // stack: y1, x0, y0, x1, y1, retdest DUP4 // stack: x1, y1, x0, y0, x1, y1, retdest - ISZERO - // stack: x1==0, y1, x0, y0, x1, y1, retdest - SWAP1 - // stack: y1, x1==0, x0, y0, x1, y1, retdest - ISZERO - // stack: y1==0, x1==0, x0, y0, x1, y1, retdest - AND - // stack: y1==0 & x1==0, x0, y0, x1, y1, retdest + %ec_isidentity + // stack: (x1,y1)==(0,0), x0, y0, x1, y1, retdest PUSH ec_add_snd_zero // stack: ec_add_snd_zero, y1==0 & x1==0, x0, y0, x1, y1, retdest JUMPI // stack: x0, y0, x1, y1, retdest - DUP4 - // stack: y1, x0, y0, x1, y1, retdest - DUP4 - // stack: x1, y1, x0, y0, x1, y1, retdest - DUP4 - // stack: y0, x1, y1, x0, y0, x1, y1, retdest - DUP4 - // stack: x0, y0, x1, y1, x0, y0, x1, y1, retdest - %ec_check - // stack: isValid(x0, y0), x1, y1, x0, y0, x1, y1, retdest - PUSH ec_add_valid_first_point - // stack: ec_add_valid_first_point, isValid(x0, y0), x1, y1, x0, y0, x1, y1, retdest - JUMPI - // stack: x1, y1, x0, y0, x1, y1, retdest - POP - // stack: y1, x0, y0, x1, y1, retdest - POP - // stack: x0, y0, x1, y1, retdest - POP - // stack: y0, x1, y1, retdest - POP - // stack: x1, y1, retdest - POP - // stack: y1, retdest - POP - // stack: retdest - JUMP - -// Assumption: (x0,y0) == (0,0) -ec_add_first_zero: - JUMPDEST - // stack: x0, y0, x1, y1, retdest - POP - // stack: y0, x1, y1, retdest - POP - // stack: x1, y1, retdest - DUP2 - // stack: y1, x1, y1, retdest - DUP2 - // stack: x1, y1, x1, y1, retdest - ISZERO - // stack: x1==0, y1, x1, y1, retdest - SWAP1 - // stack: y1, x1==0, x1, y1, retdest - ISZERO - // stack: y1==0, x1==0, x1, y1, retdest - AND - // stack: y1==0 & x1==0, x1, y1, retdest - PUSH ret_zero - // stack: ret_zero, y1==0 & x1==0, x1, y1, retdest - JUMPI - // stack: x1, y1, retdest - DUP2 - // stack: y1, x1, y1, retdest - DUP2 - // stack: x1, y1, x1, y1, retdest - %ec_check - // stack: isValid(x1, y1), x1, y1, retdest - PUSH ec_noop - // stack: ec_noop, isValid(x1, y1), x1, y1, retdest - JUMPI - // stack: x1, y1, retdest - POP - // stack: y1, retdest - POP - // stack: retdest - JUMP - -// Assumption: (x1,y1) == (0,0) and (x0,y0) != (0,0) -ec_add_snd_zero: - JUMPDEST - // stack: x0, y0, x1, y1, retdest - SWAP2 - // stack: x1, y0, x0, y1, retdest - POP - // stack: y0, x0, y1, retdest - SWAP2 - // stack: y1, x0, y0, retdest - POP - // stack: x0, y0, retdest - DUP2 - // stack: y0, x0, y0, retdest - DUP2 - // stack: x0, y0, x0, y0, retdest - %ec_check - // stack: isValid(x0, y0), x0, y0, retdest - PUSH ec_noop - // stack: ec_noop, isValid(x0, y0), x0, y0, retdest - JUMPI - // stack: x0, y0, retdest - POP - // stack: y0, retdest - POP - // stack: retdest - JUMP - -ec_noop: - JUMPDEST - // x, y, retdest - SWAP1 - // y, x, retdest - SWAP2 - // retdest, x, y - JUMP - -ret_zero: - JUMPDEST - // stack: x, y, retdest - POP - // stack: y, retdest - POP - // stack: retdest - PUSH 0 - // stack: 0, retdest - PUSH 0 - // stack: 0, 0, retdest - SWAP2 - // stack: 0, retdest, 0 - SWAP1 - // stack: retdest, 0, 0 - JUMP - - -// Assumption: (x0,y0) is a valid point. -ec_add_valid_first_point: - JUMPDEST - // stack: x1, y1, x0, y0, x1, y1, retdest - %ec_check - // stack: isValid(x1, y1), x0, y0, x1, y1, retdest - PUSH ec_add_valid_points - // stack: ec_add_valid_points, isValid(x1, y1), x0, y0, x1, y1, retdest - JUMPI - // stack: x0, y0, x1, y1, retdest - POP - // stack: y0, x1, y1, retdest - POP - // stack: x1, y1, retdest - POP - // stack: y1, retdest - POP - // stack: retdest - JUMP - -// Assumption: (x0,y0) and (x1,y1) are valid points. -global ec_add_valid_points: - JUMPDEST - // stack: x0, y0, x1, y1, retdest DUP3 // stack: x1, x0, y0, x1, y1, retdest DUP2 @@ -216,6 +89,63 @@ global ec_add_valid_points: // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest JUMP +// Assumption: (x0,y0) == (0,0) +ec_add_first_zero: + JUMPDEST + // stack: x0, y0, x1, y1, retdest + POP + // stack: y0, x1, y1, retdest + POP + // stack: x1, y1, retdest + DUP2 + // stack: y1, x1, y1, retdest + DUP2 + // stack: x1, y1, x1, y1, retdest + %ec_isidentity + // stack: (x1,y1)==(0,0), x1, y1, retdest + PUSH ret_zero + // stack: ret_zero, (x1,y1)==(0,0), x1, y1, retdest + JUMPI + // stack: x1, y1, retdest + SWAP1 + // stack: y1, x1, retdest + SWAP2 + // stack: retdest, x1, y1 + JUMP + +// Assumption: (x1,y1) == (0,0) and (x0,y0) != (0,0) +ec_add_snd_zero: + JUMPDEST + // stack: x0, y0, x1, y1, retdest + SWAP2 + // stack: x1, y0, x0, y1, retdest + POP + // stack: y0, x0, y1, retdest + SWAP2 + // stack: y1, x0, y0, retdest + POP + // stack: x0, y0, retdest + SWAP1 + // stack: y0, x0, retdest + SWAP2 + // stack: retdest, x0, y0 + JUMP + +ret_zero: + JUMPDEST + // stack: x, y, retdest + POP + // stack: y, retdest + POP + // stack: retdest + PUSH 0 + // stack: 0, retdest + PUSH 0 + // stack: 0, 0, retdest + SWAP2 + // stack: retdest, 0, 0 + JUMP + ec_add_valid_points_with_lambda: JUMPDEST // stack: lambda, x0, y0, x1, y1, retdest @@ -223,7 +153,7 @@ ec_add_valid_points_with_lambda: // stack: x0, lambda, x0, y0, x1, y1, retdest DUP5 // stack: x1, x0, lambda, x0, y0, x1, y1, retdest - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + %bn_base // stack: N, x1, x0, lambda, x0, y0, x1, y1, retdest DUP4 // stack: lambda, N, x1, x0, lambda, x0, y0, x1, y1, retdest @@ -235,7 +165,7 @@ ec_add_valid_points_with_lambda: // stack: lambda^2 - x1, x0, lambda, x0, y0, x1, y1, retdest %submod // stack: x2, lambda, x0, y0, x1, y1, retdest - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + %bn_base // stack: N, x2, lambda, x0, y0, x1, y1, retdest DUP2 // stack: x2, N, x2, lambda, x0, y0, x1, y1, retdest @@ -275,7 +205,7 @@ ec_add_valid_points_with_lambda: ec_add_equal_first_coord: JUMPDEST // stack: x0, y0, x1, y1, retdest with x0 == x1 - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + %bn_base // stack: N, x0, y0, x1, y1, retdest DUP3 // stack: y0, N, x0, y0, x1, y1, retdest @@ -291,16 +221,8 @@ ec_add_equal_first_coord: // stack: y0, x1, y1, retdest POP // stack: x1, y1, retdest - POP - // stack: y1, retdest - POP - // stack: retdest - PUSH 0 - // stack: 0, retdest - PUSH 0 - // stack: 0, 0, retdest - SWAP2 - // stack: retdest, 0, 0 + PUSH ret_zero + // stack: ret_zero, x1, y1, retdest JUMP @@ -308,9 +230,9 @@ ec_add_equal_first_coord: ec_add_equal_points: JUMPDEST // stack: x0, y0, x1, y1, retdest - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + %bn_base // stack: N, x0, y0, x1, y1, retdest - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + %bn_base // stack: N, N, x0, y0, x1, y1, retdest DUP3 // stack: x0, N, N, x0, y0, x1, y1, retdest @@ -342,17 +264,22 @@ global ec_double: // stack: ec_add_equal_points, x0, y0, x0, y0, retdest JUMP +// Push the order of the BN254 base field. +%macro bn_base + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 +%endmacro + // Assumption: x, y < N and 2N < 2^256. // Note: Doesn't hold for Secp256k1 base field. %macro submod // stack: x, y - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + %bn_base // stack: N, x, y ADD // stack: N + x, y // Doesn't overflow since 2N < 2^256 SUB // stack: N + x - y // Doesn't underflow since y < N - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + %bn_base // stack: N, N + x - y SWAP1 // stack: N + x - y, N @@ -360,58 +287,97 @@ global ec_double: // stack: (N + x - y) % N = (x-y) % N %endmacro +// Check if (x,y) is a valid curve point. +// Puts y^2 % N == (x^3 + 3) % N & (x < N) & (y < N) || (x,y)==(0,0) on top of the stack. %macro ec_check - // stack: x0, y0 - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, x0, y0 + // stack: x, y + %bn_base + // stack: N, x, y DUP2 - // stack: x0, N, x0, y0 + // stack: x, N, x, y LT - // stack: x0 < N, x0, y0 - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, x0 < N, x0, y0 + // stack: x < N, x, y + %bn_base + // stack: N, x < N, x, y DUP4 - // stack: y0, N, x0 < N, x0, y0 + // stack: y, N, x < N, x, y LT - // stack: y0 < N, x0 < N, x0, y0 + // stack: y < N, x < N, x, y AND - // stack: (y0 < N) & (x0 < N), x0, y0 + // stack: (y < N) & (x < N), x, y SWAP2 - // stack: y0, x0, (y0 < N) & (x0 < N), x0 + // stack: y, x, (y < N) & (x < N), x SWAP1 - // stack: x0, y0, (y0 < N) & (x0 < N) - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, x0, y0, b - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, N, x0, y0, b - SWAP2 - // stack: x0, N, N, y0, b - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, x0, N, N, y0, b + // stack: x, y, (y < N) & (x < N) + %bn_base + // stack: N, x, y, b + %bn_base + // stack: N, N, x, y, b + DUP3 + // stack: x, N, N, x, y, b + %bn_base + // stack: N, x, N, N, x, y, b DUP2 - // stack: x0, N, x0, N, N, y0, b + // stack: x, N, x, N, N, x, y, b DUP1 - // stack: x0, x0, N, x0, N, N, y0, b + // stack: x, x, N, x, N, N, x, y, b MULMOD - // stack: x0^2 % N, x0, N, N, y0, b + // stack: x^2 % N, x, N, N, x, y, b MULMOD - // stack: x0^3 % N, N, y0, b + // stack: x^3 % N, N, x, y, b PUSH 3 - // stack: 3, x0^3 % N, N, y0, b + // stack: 3, x^3 % N, N, x, y, b ADDMOD - // stack: (x0^3 + 3) % N, y0, b + // stack: (x^3 + 3) % N, x, y, b + DUP3 + // stack: y, (x^3 + 3) % N, x, y, b + %bn_base + // stack: N, y, (x^3 + 3) % N, x, y, b SWAP1 - // stack: y0, (x0^3 + 3) % N, b - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, y0, (x0^3 + 3) % N, b - SWAP1 - // stack: y0, N, (x0^3 + 3) % N, b + // stack: y, N, (x^3 + 3) % N, x, y, b DUP1 - // stack: y0, y0, N, (x0^3 + 3) % N, b + // stack: y, y, N, (x^3 + 3) % N, x, y, b MULMOD - // stack: y0^2 % N, (x0^3 + 3) % N, b + // stack: y^2 % N, (x^3 + 3) % N, x, y, b EQ - // stack: y0^2 % N == (x0^3 + 3) % N, b + // stack: y^2 % N == (x^3 + 3) % N, x, y, b + SWAP2 + // stack: y, x, y^2 % N == (x^3 + 3) % N, b + ISZERO + // stack: y==0, x, y^2 % N == (x^3 + 3) % N, b + SWAP1 + // stack: x, y==0, y^2 % N == (x^3 + 3) % N, b + ISZERO + // stack: x==0, y==0, y^2 % N == (x^3 + 3) % N, b AND - // stack: y0^2 % N == (x0^3 + 3) % N & (x < N) & (y < N) + // stack: (x,y)==(0,0), y^2 % N == (x^3 + 3) % N, b + SWAP2 + // stack: b, y^2 % N == (x^3 + 3) % N, (x,y)==(0,0) + AND + // stack: y^2 % N == (x^3 + 3) % N & (x < N) & (y < N), (x,y)==(0,0) + OR + // stack: y^2 % N == (x^3 + 3) % N & (x < N) & (y < N) || (x,y)==(0,0) %endmacro + +%macro ec_isidentity + // stack: x, y + ISZERO + // stack: x==0, y + SWAP1 + // stack: y, x==0 + ISZERO + // stack: y==0, x==0 + AND + // stack: y==0 & x==0 +%endmacro + +%macro ec_invalid_input + // stack: retdest + PUSH 0xffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff + // stack: u256::MAX, retdest + PUSH 0xffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff + // stack: u256::MAX, u256::MAX, retdest + SWAP2 + // stack: retdest, u256::MAX, u256::MAX + JUMP +%endmacro \ No newline at end of file diff --git a/evm/src/cpu/kernel/asm/curve_mul.asm b/evm/src/cpu/kernel/asm/curve_mul.asm index 440ebe8b..52e384d5 100644 --- a/evm/src/cpu/kernel/asm/curve_mul.asm +++ b/evm/src/cpu/kernel/asm/curve_mul.asm @@ -10,14 +10,8 @@ global ec_mul: // stack: y, x, y, s, retdest DUP2 // stack: x, y, x, y, s, retdest - ISZERO - // stack: x==0, y, x, y, s, retdest - SWAP1 - // stack: y, x==0, x, y, s, retdest - ISZERO - // stack: y==0, x==0, x, y, s, retdest - AND - // stack: y==0 & x==0, x, y, s, retdest + %ec_isidentity + // stack: (x,y)==(0,0), x, y, s, retdest PUSH ret_zero // stack: ret_zero, y==0 & x==0, x, y, s, retdest JUMPI @@ -38,7 +32,7 @@ global ec_mul: // stack: s, retdest POP // stack: retdest - JUMP + %ec_invalid_input // Same algorithm as in `exp.asm` ec_mul_valid_point: @@ -131,8 +125,8 @@ recursion_return: odd_scalar: JUMPDEST // stack: x', y', x, y, retdest - PUSH ec_add - // stack: ec_add, x', y', x, y, retdest + PUSH ec_add_valid_points + // stack: ec_add_valid_points, x', y', x, y, retdest JUMP ret_zero: From e2b1e512804a7f494ac633ec482e33babfdece7b Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Wed, 6 Jul 2022 09:40:11 +0200 Subject: [PATCH 19/30] Minor --- evm/src/cpu/kernel/asm/curve_mul.asm | 14 ++------------ 1 file changed, 2 insertions(+), 12 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_mul.asm b/evm/src/cpu/kernel/asm/curve_mul.asm index 52e384d5..ce77e972 100644 --- a/evm/src/cpu/kernel/asm/curve_mul.asm +++ b/evm/src/cpu/kernel/asm/curve_mul.asm @@ -44,18 +44,8 @@ ec_mul_valid_point: // stack: step_case, s, x, y, s, retdest JUMPI // stack: x, y, s, retdest - POP - // stack: y, s, retdest - POP - // stack: s, retdest - POP - // stack: retdest - PUSH 0 - // stack: 0, retdest - PUSH 0 - // stack: 0, 0, retdest - SWAP2 - // stack: retdest, 0, 0 + PUSH ret_zero + // stack: ret_zero, x, y, s, retdest JUMP step_case: From 434615a03c03c36780ffb0cceac8a8baaa058971 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Thu, 7 Jul 2022 08:26:57 +0200 Subject: [PATCH 20/30] PR feedback + comments --- evm/src/cpu/kernel/asm/curve_add.asm | 120 +++++++++++++++------------ evm/src/cpu/kernel/asm/curve_mul.asm | 2 + evm/src/cpu/kernel/asm/moddiv.asm | 1 + 3 files changed, 70 insertions(+), 53 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index 6d69fea9..fdbbf997 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -1,5 +1,7 @@ // #define N 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // BN254 base field order +// BN254 elliptic curve addition. +// Uses the standard affine addition formula. global ec_add: // Uncomment for test inputs. // PUSH 0xdeadbeef @@ -9,6 +11,8 @@ global ec_add: // PUSH 0xe7313274bb29566ff0c8220eb9841de1d96c2923c6a4028f7dd3c6a14cee770 JUMPDEST // stack: x0, y0, x1, y1, retdest + + // Check if points are valid BN254 points. DUP2 // stack: y0, x0, y0, x1, y1, retdest DUP2 @@ -27,6 +31,8 @@ global ec_add: // stack: ec_add_valid_points, isValid(x1, y1) & isValid(x0, y0), x0, y0, x1, y1, retdest JUMPI // stack: x0, y0, x1, y1, retdest + + // Otherwise return POP // stack: y0, x1, y1, retdest POP @@ -37,10 +43,13 @@ global ec_add: // stack: retdest %ec_invalid_input +// BN254 elliptic curve addition. // Assumption: (x0,y0) and (x1,y1) are valid points. global ec_add_valid_points: JUMPDEST // stack: x0, y0, x1, y1, retdest + + // Check if the first point is the identity. DUP2 // stack: y0, x0, y0, x1, y1, retdest DUP2 @@ -48,9 +57,11 @@ global ec_add_valid_points: %ec_isidentity // stack: (x0,y0)==(0,0), x0, y0, x1, y1, retdest PUSH ec_add_first_zero - // stack: ec_add_first_zero, y0==0 & x0==0, x0, y0, x1, y1, retdest + // stack: ec_add_first_zero, (x0,y0)==(0,0), x0, y0, x1, y1, retdest JUMPI // stack: x0, y0, x1, y1, retdest + + // Check if the first point is the identity. DUP4 // stack: y1, x0, y0, x1, y1, retdest DUP4 @@ -58,9 +69,11 @@ global ec_add_valid_points: %ec_isidentity // stack: (x1,y1)==(0,0), x0, y0, x1, y1, retdest PUSH ec_add_snd_zero - // stack: ec_add_snd_zero, y1==0 & x1==0, x0, y0, x1, y1, retdest + // stack: ec_add_snd_zero, (x1,y1)==(0,0), x0, y0, x1, y1, retdest JUMPI // stack: x0, y0, x1, y1, retdest + + // Check if both points have the same x-coordinate. DUP3 // stack: x1, x0, y0, x1, y1, retdest DUP2 @@ -71,6 +84,9 @@ global ec_add_valid_points: // stack: ec_add_equal_first_coord, x0 == x1, x0, y0, x1, y1, retdest JUMPI // stack: x0, y0, x1, y1, retdest + + // Otherwise, we can use the standard formula. + // Compute lambda = (y0 - y1)/(x0 - x1) DUP4 // stack: y1, x0, y0, x1, y1, retdest DUP3 @@ -89,34 +105,30 @@ global ec_add_valid_points: // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest JUMP +// BN254 elliptic curve addition. // Assumption: (x0,y0) == (0,0) ec_add_first_zero: JUMPDEST // stack: x0, y0, x1, y1, retdest + + // Just return (x1,y1) POP // stack: y0, x1, y1, retdest POP // stack: x1, y1, retdest - DUP2 - // stack: y1, x1, y1, retdest - DUP2 - // stack: x1, y1, x1, y1, retdest - %ec_isidentity - // stack: (x1,y1)==(0,0), x1, y1, retdest - PUSH ret_zero - // stack: ret_zero, (x1,y1)==(0,0), x1, y1, retdest - JUMPI - // stack: x1, y1, retdest SWAP1 // stack: y1, x1, retdest SWAP2 // stack: retdest, x1, y1 JUMP -// Assumption: (x1,y1) == (0,0) and (x0,y0) != (0,0) +// BN254 elliptic curve addition. +// Assumption: (x1,y1) == (0,0) ec_add_snd_zero: JUMPDEST // stack: x0, y0, x1, y1, retdest + + // Just return (x1,y1) SWAP2 // stack: x1, y0, x0, y1, retdest POP @@ -131,24 +143,13 @@ ec_add_snd_zero: // stack: retdest, x0, y0 JUMP -ret_zero: - JUMPDEST - // stack: x, y, retdest - POP - // stack: y, retdest - POP - // stack: retdest - PUSH 0 - // stack: 0, retdest - PUSH 0 - // stack: 0, 0, retdest - SWAP2 - // stack: retdest, 0, 0 - JUMP - +// BN254 elliptic curve addition. +// Assumption: lambda = (y0 - y1)/(x0 - x1) ec_add_valid_points_with_lambda: JUMPDEST // stack: lambda, x0, y0, x1, y1, retdest + + // Compute x2 = lambda^2 - x1 - x0 DUP2 // stack: x0, lambda, x0, y0, x1, y1, retdest DUP5 @@ -165,6 +166,8 @@ ec_add_valid_points_with_lambda: // stack: lambda^2 - x1, x0, lambda, x0, y0, x1, y1, retdest %submod // stack: x2, lambda, x0, y0, x1, y1, retdest + + // Compute y2 = lambda*(x1 - x2) - y1 %bn_base // stack: N, x2, lambda, x0, y0, x1, y1, retdest DUP2 @@ -183,6 +186,8 @@ ec_add_valid_points_with_lambda: // stack: lambda * (x1 - x2), y1, x2, lambda, x0, y0, x1, y1, retdest %submod // stack: y2, x2, lambda, x0, y0, x1, y1, retdest + + // Return x2,y2 SWAP5 // stack: x1, x2, lambda, x0, y0, y2, y1, retdest POP @@ -201,35 +206,50 @@ ec_add_valid_points_with_lambda: // stack: retdest, x2, y2 JUMP +// BN254 elliptic curve addition. // Assumption: (x0,y0) and (x1,y1) are valid points and x0 == x1 ec_add_equal_first_coord: JUMPDEST // stack: x0, y0, x1, y1, retdest with x0 == x1 - %bn_base - // stack: N, x0, y0, x1, y1, retdest - DUP3 - // stack: y0, N, x0, y0, x1, y1, retdest - DUP6 - // stack: y1, y0, N, x0, y0, x1, y1, retdest - ADDMOD - // stack: y1 + y0, x0, y0, x1, y1, retdest + + // Check if the points are equal + DUP2 + // stack: y0, x0, y0, x1, y1, retdest + DUP5 + // stack: y1, y0, x0, y0, x1, y1, retdest + EQ + // stack: y1 == y0, x0, y0, x1, y1, retdest PUSH ec_add_equal_points - // stack: ec_add_equal_points, y1 + y0, x0, y0, x1, y1, retdest + // stack: ec_add_equal_points, y1 == y0, x0, y0, x1, y1, retdest JUMPI // stack: x0, y0, x1, y1, retdest + + // Otherwise, one is the negation of the other so we can return (0,0). POP // stack: y0, x1, y1, retdest POP // stack: x1, y1, retdest - PUSH ret_zero - // stack: ret_zero, x1, y1, retdest + POP + // stack: y1, retdest + POP + // stack: retdest + PUSH 0 + // stack: 0, retdest + PUSH 0 + // stack: 0, 0, retdest + SWAP2 + // stack: retdest, 0, 0 JUMP +// BN254 elliptic curve addition. // Assumption: x0 == x1 and y0 == y1 +// Standard doubling formula. ec_add_equal_points: JUMPDEST // stack: x0, y0, x1, y1, retdest + + // Compute lambda = 3/2 * x0^2 / y0 %bn_base // stack: N, x0, y0, x1, y1, retdest %bn_base @@ -252,7 +272,9 @@ ec_add_equal_points: // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest JUMP +// BN254 elliptic curve doubling. // Assumption: (x0,y0) is a valid point. +// Standard doubling formula. global ec_double: JUMPDEST // stack: x0, y0, retdest @@ -343,13 +365,7 @@ global ec_double: // stack: y^2 % N == (x^3 + 3) % N, x, y, b SWAP2 // stack: y, x, y^2 % N == (x^3 + 3) % N, b - ISZERO - // stack: y==0, x, y^2 % N == (x^3 + 3) % N, b - SWAP1 - // stack: x, y==0, y^2 % N == (x^3 + 3) % N, b - ISZERO - // stack: x==0, y==0, y^2 % N == (x^3 + 3) % N, b - AND + %ec_isidentity // stack: (x,y)==(0,0), y^2 % N == (x^3 + 3) % N, b SWAP2 // stack: b, y^2 % N == (x^3 + 3) % N, (x,y)==(0,0) @@ -359,18 +375,16 @@ global ec_double: // stack: y^2 % N == (x^3 + 3) % N & (x < N) & (y < N) || (x,y)==(0,0) %endmacro +// Check if (x,y)==(0,0) %macro ec_isidentity // stack: x, y + OR + // stack: x | y ISZERO - // stack: x==0, y - SWAP1 - // stack: y, x==0 - ISZERO - // stack: y==0, x==0 - AND - // stack: y==0 & x==0 + // stack: (x,y) == (0,0) %endmacro +// Return (u256::MAX, u256::MAX) which is used to indicate the input was invalid. %macro ec_invalid_input // stack: retdest PUSH 0xffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff diff --git a/evm/src/cpu/kernel/asm/curve_mul.asm b/evm/src/cpu/kernel/asm/curve_mul.asm index ce77e972..0826b0e3 100644 --- a/evm/src/cpu/kernel/asm/curve_mul.asm +++ b/evm/src/cpu/kernel/asm/curve_mul.asm @@ -1,3 +1,5 @@ +// BN254 elliptic curve scalar multiplication. +// Recursive implementation, same algorithm as in `exp.asm`. global ec_mul: // Uncomment for test inputs. // PUSH 0xdeadbeef diff --git a/evm/src/cpu/kernel/asm/moddiv.asm b/evm/src/cpu/kernel/asm/moddiv.asm index 2dd28fa7..891897e5 100644 --- a/evm/src/cpu/kernel/asm/moddiv.asm +++ b/evm/src/cpu/kernel/asm/moddiv.asm @@ -25,6 +25,7 @@ %mulmodn %endmacro +// Computes the inverse modulo N using x^-1 = x^(N-2) mod N and square-and-multiply modular exponentiation. %macro inverse DUP1 %squaremodn From 3ec2d307e5302f30a658fb25c37d19f49574ce33 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Thu, 7 Jul 2022 16:53:06 +0200 Subject: [PATCH 21/30] EVM interpreter --- evm/src/cpu/kernel/interpreter.rs | 287 ++++++++++++++++++++++++++++++ evm/src/cpu/kernel/mod.rs | 3 + 2 files changed, 290 insertions(+) create mode 100644 evm/src/cpu/kernel/interpreter.rs diff --git a/evm/src/cpu/kernel/interpreter.rs b/evm/src/cpu/kernel/interpreter.rs new file mode 100644 index 00000000..f344befd --- /dev/null +++ b/evm/src/cpu/kernel/interpreter.rs @@ -0,0 +1,287 @@ +use ethereum_types::{U256, U512}; + +struct Interpreter { + code: Vec, + offset: usize, + stack: Vec, +} + +pub fn run(code: Vec, initial_offset: usize, initial_stack: Vec) -> Vec { + let mut interpreter = Interpreter { + code, + offset: initial_offset, + stack: initial_stack, + }; + while interpreter.offset < interpreter.code.len() { + interpreter.run_opcode(); + } + interpreter.stack +} + +impl Interpreter { + fn slice(&self, n: usize) -> &[u8] { + &self.code[self.offset..self.offset + n] + } + + fn incr(&mut self, n: usize) { + self.offset += n; + } + + fn push(&mut self, x: U256) { + self.stack.push(x); + } + + fn pop(&mut self) -> U256 { + self.stack.pop().expect("Pop on empty stack.") + } + + fn run_opcode(&mut self) { + let opcode = self.code[self.offset]; + self.incr(1); + match opcode { + 0x00 => todo!(), // "STOP", + 0x01 => self.run_add(), // "ADD", + 0x02 => self.run_mul(), // "MUL", + 0x03 => self.run_sub(), // "SUB", + 0x05 => todo!(), // "SDIV", + 0x06 => self.run_mod(), // "MOD", + 0x07 => todo!(), // "SMOD", + 0x08 => self.run_addmod(), // "ADDMOD", + 0x09 => self.run_mulmod(), // "MULMOD", + 0x0a => self.run_exp(), // "EXP", + 0x0b => todo!(), // "SIGNEXTEND", + 0x10 => self.run_lt(), // "LT", + 0x11 => self.run_gt(), // "GT", + 0x12 => todo!(), // "SLT", + 0x13 => todo!(), // "SGT", + 0x14 => self.run_eq(), // "EQ", + 0x15 => self.run_iszero(), // "ISZERO", + 0x16 => self.run_and(), // "AND", + 0x17 => self.run_or(), // "OR", + 0x18 => self.run_xor(), // "XOR", + 0x19 => self.run_not(), // "NOT", + 0x1a => todo!(), // "BYTE", + 0x1b => todo!(), // "SHL", + 0x1c => todo!(), // "SHR", + 0x1d => todo!(), // "SAR", + 0x20 => todo!(), // "KECCAK256", + 0x30 => todo!(), // "ADDRESS", + 0x31 => todo!(), // "BALANCE", + 0x32 => todo!(), // "ORIGIN", + 0x33 => todo!(), // "CALLER", + 0x34 => todo!(), // "CALLVALUE", + 0x35 => todo!(), // "CALLDATALOAD", + 0x36 => todo!(), // "CALLDATASIZE", + 0x37 => todo!(), // "CALLDATACOPY", + 0x38 => todo!(), // "CODESIZE", + 0x39 => todo!(), // "CODECOPY", + 0x3a => todo!(), // "GASPRICE", + 0x3b => todo!(), // "EXTCODESIZE", + 0x3c => todo!(), // "EXTCODECOPY", + 0x3d => todo!(), // "RETURNDATASIZE", + 0x3e => todo!(), // "RETURNDATACOPY", + 0x3f => todo!(), // "EXTCODEHASH", + 0x40 => todo!(), // "BLOCKHASH", + 0x41 => todo!(), // "COINBASE", + 0x42 => todo!(), // "TIMESTAMP", + 0x43 => todo!(), // "NUMBER", + 0x44 => todo!(), // "DIFFICULTY", + 0x45 => todo!(), // "GASLIMIT", + 0x46 => todo!(), // "CHAINID", + 0x48 => todo!(), // "BASEFEE", + 0x50 => todo!(), // "POP", + 0x51 => todo!(), // "MLOAD", + 0x52 => todo!(), // "MSTORE", + 0x53 => todo!(), // "MSTORE8", + 0x54 => todo!(), // "SLOAD", + 0x55 => todo!(), // "SSTORE", + 0x56 => self.run_jump(), // "JUMP", + 0x57 => self.run_jumpi(), // "JUMPI", + 0x58 => todo!(), // "GETPC", + 0x59 => todo!(), // "MSIZE", + 0x5a => todo!(), // "GAS", + 0x5b => self.incr(1), // "JUMPDEST", + x if (0x60..0x80).contains(&x) => self.run_push(x - 0x5f), // "PUSH" + x if (0x80..0x90).contains(&x) => self.run_dup(x - 0x7f), // "DUP" + x if (0x90..0xa0).contains(&x) => self.run_swap(x - 0x8f), // "SWAP" + 0xa0 => todo!(), // "LOG0", + 0xa1 => todo!(), // "LOG1", + 0xa2 => todo!(), // "LOG2", + 0xa3 => todo!(), // "LOG3", + 0xa4 => todo!(), // "LOG4", + 0xf0 => todo!(), // "CREATE", + 0xf1 => todo!(), // "CALL", + 0xf2 => todo!(), // "CALLCODE", + 0xf3 => todo!(), // "RETURN", + 0xf4 => todo!(), // "DELEGATECALL", + 0xf5 => todo!(), // "CREATE2", + 0xfa => todo!(), // "STATICCALL", + 0xfd => todo!(), // "REVERT", + 0xfe => todo!(), // "INVALID", + 0xff => todo!(), // "SELFDESTRUCT", + _ => panic!("Unrecognized mnemonic."), + }; + } + + fn run_add(&mut self) { + let x = self.pop(); + let y = self.pop(); + self.push(x + y); + self.incr(1); + } + + fn run_mul(&mut self) { + let x = self.pop(); + let y = self.pop(); + self.push(x * y); + self.incr(1); + } + + fn run_sub(&mut self) { + let x = self.pop(); + let y = self.pop(); + self.push(x - y); + self.incr(1); + } + + fn run_mod(&mut self) { + let x = self.pop(); + let y = self.pop(); + self.push(x % y); + self.incr(1); + } + + fn run_addmod(&mut self) { + let x = U512::from(self.pop()); + let y = U512::from(self.pop()); + let z = U512::from(self.pop()); + let res = (x + y) % z; + self.push(U256([0, 1, 2, 3].map(|i| res.0[i]))); + self.incr(1); + } + + fn run_mulmod(&mut self) { + let x = self.pop(); + let y = self.pop(); + let z = U512::from(self.pop()); + let res = x.full_mul(y) % z; + self.push(U256([0, 1, 2, 3].map(|i| res.0[i]))); + self.incr(1); + } + + fn run_exp(&mut self) { + let x = self.pop(); + let y = self.pop(); + self.push(x.pow(y)); + self.incr(1); + } + + fn run_lt(&mut self) { + let x = self.pop(); + let y = self.pop(); + self.push(if x < y { U256::one() } else { U256::zero() }); + self.incr(1); + } + + fn run_gt(&mut self) { + let x = self.pop(); + let y = self.pop(); + self.push(if x > y { U256::one() } else { U256::zero() }); + self.incr(1); + } + + fn run_eq(&mut self) { + let x = self.pop(); + let y = self.pop(); + self.push(if x == y { U256::one() } else { U256::zero() }); + self.incr(1); + } + + fn run_iszero(&mut self) { + let x = self.pop(); + self.push(if x.is_zero() { + U256::one() + } else { + U256::zero() + }); + self.incr(1); + } + + fn run_and(&mut self) { + let x = self.pop(); + let y = self.pop(); + self.push(x & y); + self.incr(1); + } + + fn run_or(&mut self) { + let x = self.pop(); + let y = self.pop(); + self.push(x | y); + self.incr(1); + } + + fn run_xor(&mut self) { + let x = self.pop(); + let y = self.pop(); + self.push(x ^ y); + self.incr(1); + } + + fn run_not(&mut self) { + let x = self.pop(); + self.push(!x); + self.incr(1); + } + + fn run_jump(&mut self) { + let x = self.pop().as_usize(); + self.offset = x; + assert_eq!( + self.code[self.offset], 0x5b, + "Destination is not a JUMPDEST." + ); + } + + fn run_jumpi(&mut self) { + let x = self.pop().as_usize(); + let b = self.pop(); + if !b.is_zero() { + self.offset = x; + assert_eq!( + self.code[self.offset], 0x5b, + "Destination is not a JUMPDEST." + ); + } else { + self.incr(1); + } + } + + fn run_push(&mut self, num_bytes: u8) { + let x = U256::from_big_endian(self.slice(num_bytes as usize)); + self.incr(num_bytes as usize); + self.push(x); + } + + fn run_dup(&mut self, n: u8) { + self.push(self.stack[n as usize - 1]); + self.incr(1); + } + + fn run_swap(&mut self, n: u8) { + self.stack.swap(0, n as usize); + self.incr(1); + } +} + +#[cfg(test)] +mod tests { + use crate::cpu::kernel::interpreter::run; + + #[test] + fn test_run() { + // PUSH1 1 PUSH1 2 ADD + let code = vec![0x60, 0x1, 0x60, 0x2, 0x1]; + assert_eq!(run(code, 0, vec![]), vec![0x3.into()]); + } +} diff --git a/evm/src/cpu/kernel/mod.rs b/evm/src/cpu/kernel/mod.rs index 4dcf9a6c..3e565d98 100644 --- a/evm/src/cpu/kernel/mod.rs +++ b/evm/src/cpu/kernel/mod.rs @@ -4,6 +4,9 @@ mod ast; mod opcodes; mod parser; +#[cfg(test)] +mod interpreter; + use assembler::assemble; use parser::parse; From beb8a9077324b9feb1f7c30e0fac38c3d723d505 Mon Sep 17 00:00:00 2001 From: Daniel Lubarov Date: Thu, 7 Jul 2022 08:59:53 -0700 Subject: [PATCH 22/30] Macros with arguments (#595) * Macros with arguments See `basic_macros.rs` for an example. * rename --- evm/src/cpu/kernel/aggregator.rs | 3 +- evm/src/cpu/kernel/asm/basic_macros.asm | 25 ++++++ evm/src/cpu/kernel/asm/exp.asm | 8 +- evm/src/cpu/kernel/assembler.rs | 105 ++++++++++++++++++++---- evm/src/cpu/kernel/ast.rs | 9 +- evm/src/cpu/kernel/evm_asm.pest | 11 ++- evm/src/cpu/kernel/parser.rs | 54 +++++++++--- 7 files changed, 176 insertions(+), 39 deletions(-) diff --git a/evm/src/cpu/kernel/aggregator.rs b/evm/src/cpu/kernel/aggregator.rs index ac0d6f7c..dc702140 100644 --- a/evm/src/cpu/kernel/aggregator.rs +++ b/evm/src/cpu/kernel/aggregator.rs @@ -28,6 +28,7 @@ mod tests { #[test] fn make_kernel() { // Make sure we can parse and assemble the entire kernel. - combined_kernel(); + let kernel = combined_kernel(); + println!("Kernel size: {} bytes", kernel.code.len()); } } diff --git a/evm/src/cpu/kernel/asm/basic_macros.asm b/evm/src/cpu/kernel/asm/basic_macros.asm index 8b6410c7..200aeea0 100644 --- a/evm/src/cpu/kernel/asm/basic_macros.asm +++ b/evm/src/cpu/kernel/asm/basic_macros.asm @@ -1,3 +1,28 @@ +%macro jump(dst) + push $dst + jump +%endmacro + +%macro jumpi(dst) + push $dst + jumpi +%endmacro + +%macro pop2 + pop + pop +%endmacro + +%macro pop3 + pop + %pop2 +%endmacro + +%macro pop4 + %pop2 + %pop2 +%endmacro + // If pred is zero, yields z; otherwise, yields nz %macro select // stack: pred, nz, z diff --git a/evm/src/cpu/kernel/asm/exp.asm b/evm/src/cpu/kernel/asm/exp.asm index 3e3b0f6f..abcb17e2 100644 --- a/evm/src/cpu/kernel/asm/exp.asm +++ b/evm/src/cpu/kernel/asm/exp.asm @@ -13,9 +13,7 @@ global exp: // stack: x, e, retdest dup2 // stack: e, x, e, retdest - push step_case - // stack: step_case, e, x, e, retdest - jumpi + %jumpi(step_case) // stack: x, e, retdest pop // stack: e, retdest @@ -41,9 +39,7 @@ step_case: // stack: x, e / 2, recursion_return, x, e, retdest %square // stack: x * x, e / 2, recursion_return, x, e, retdest - push exp - // stack: exp, x * x, e / 2, recursion_return, x, e, retdest - jump + %jump(exp) recursion_return: // stack: exp(x * x, e / 2), x, e, retdest push 2 diff --git a/evm/src/cpu/kernel/assembler.rs b/evm/src/cpu/kernel/assembler.rs index d7e40f24..096cf497 100644 --- a/evm/src/cpu/kernel/assembler.rs +++ b/evm/src/cpu/kernel/assembler.rs @@ -19,6 +19,20 @@ pub struct Kernel { global_labels: HashMap, } +struct Macro { + params: Vec, + items: Vec, +} + +impl Macro { + fn get_param_index(&self, param: &str) -> usize { + self.params + .iter() + .position(|p| p == param) + .unwrap_or_else(|| panic!("No such param: {} {:?}", param, &self.params)) + } +} + pub(crate) fn assemble(files: Vec) -> Kernel { let macros = find_macros(&files); let mut global_labels = HashMap::new(); @@ -41,33 +55,31 @@ pub(crate) fn assemble(files: Vec) -> Kernel { } } -fn find_macros(files: &[File]) -> HashMap> { +fn find_macros(files: &[File]) -> HashMap { let mut macros = HashMap::new(); for file in files { for item in &file.body { - if let Item::MacroDef(name, items) = item { - macros.insert(name.clone(), items.clone()); + if let Item::MacroDef(name, params, items) = item { + let _macro = Macro { + params: params.clone(), + items: items.clone(), + }; + macros.insert(name.clone(), _macro); } } } macros } -fn expand_macros(body: Vec, macros: &HashMap>) -> Vec { +fn expand_macros(body: Vec, macros: &HashMap) -> Vec { let mut expanded = vec![]; for item in body { match item { - Item::MacroDef(_, _) => { + Item::MacroDef(_, _, _) => { // At this phase, we no longer need macro definitions. } - Item::MacroCall(m) => { - let mut expanded_item = macros - .get(&m) - .cloned() - .unwrap_or_else(|| panic!("No such macro: {}", m)); - // Recursively expand any macros in the expanded code. - expanded_item = expand_macros(expanded_item, macros); - expanded.extend(expanded_item); + Item::MacroCall(m, args) => { + expanded.extend(expand_macro_call(m, args, macros)); } item => { expanded.push(item); @@ -77,6 +89,41 @@ fn expand_macros(body: Vec, macros: &HashMap>) -> Vec, + macros: &HashMap, +) -> Vec { + let _macro = macros + .get(&name) + .unwrap_or_else(|| panic!("No such macro: {}", name)); + + assert_eq!( + args.len(), + _macro.params.len(), + "Macro `{}`: expected {} arguments, got {}", + name, + _macro.params.len(), + args.len() + ); + + let expanded_item = _macro + .items + .iter() + .map(|item| { + if let Item::Push(PushTarget::MacroVar(var)) = item { + let param_index = _macro.get_param_index(var); + Item::Push(args[param_index].clone()) + } else { + item.clone() + } + }) + .collect(); + + // Recursively expand any macros in the expanded code. + expand_macros(expanded_item, macros) +} + fn find_labels( body: &[Item], offset: &mut usize, @@ -86,7 +133,7 @@ fn find_labels( let mut local_labels = HashMap::::new(); for item in body { match item { - Item::MacroDef(_, _) | Item::MacroCall(_) => { + Item::MacroDef(_, _, _) | Item::MacroCall(_, _) => { panic!("Macros should have been expanded already") } Item::GlobalLabelDeclaration(label) => { @@ -114,7 +161,7 @@ fn assemble_file( // Assemble the file. for item in body { match item { - Item::MacroDef(_, _) | Item::MacroCall(_) => { + Item::MacroDef(_, _, _) | Item::MacroCall(_, _) => { panic!("Macros should have been expanded already") } Item::GlobalLabelDeclaration(_) | Item::LocalLabelDeclaration(_) => { @@ -135,6 +182,7 @@ fn assemble_file( .map(|i| offset.to_le_bytes()[i as usize]) .collect() } + PushTarget::MacroVar(v) => panic!("Variable not in a macro: {}", v), }; code.push(get_push_opcode(target_bytes.len() as u8)); code.extend(target_bytes); @@ -152,6 +200,7 @@ fn push_target_size(target: &PushTarget) -> u8 { match target { PushTarget::Literal(lit) => lit.to_trimmed_be_bytes().len() as u8, PushTarget::Label(_) => BYTES_PER_OFFSET, + PushTarget::MacroVar(v) => panic!("Variable not in a macro: {}", v), } } @@ -281,6 +330,32 @@ mod tests { assert_eq!(kernel.code, vec![add, add]); } + #[test] + fn macro_with_vars() { + let kernel = parse_and_assemble(&[ + "%macro add(x, y) PUSH $x PUSH $y ADD %endmacro", + "%add(2, 3)", + ]); + let push1 = get_push_opcode(1); + let add = get_opcode("ADD"); + assert_eq!(kernel.code, vec![push1, 2, push1, 3, add]); + } + + #[test] + #[should_panic] + fn macro_with_wrong_vars() { + parse_and_assemble(&[ + "%macro add(x, y) PUSH $x PUSH $y ADD %endmacro", + "%add(2, 3, 4)", + ]); + } + + #[test] + #[should_panic] + fn var_not_in_macro() { + parse_and_assemble(&["push $abc"]); + } + fn parse_and_assemble(files: &[&str]) -> Kernel { let parsed_files = files.iter().map(|f| parse(f)).collect_vec(); assemble(parsed_files) diff --git a/evm/src/cpu/kernel/ast.rs b/evm/src/cpu/kernel/ast.rs index 1409b5d7..f011f1ff 100644 --- a/evm/src/cpu/kernel/ast.rs +++ b/evm/src/cpu/kernel/ast.rs @@ -8,10 +8,10 @@ pub(crate) struct File { #[derive(Clone, Debug)] pub(crate) enum Item { - /// Defines a new macro. - MacroDef(String, Vec), - /// Calls a macro. - MacroCall(String), + /// Defines a new macro: name, params, body. + MacroDef(String, Vec, Vec), + /// Calls a macro: name, args. + MacroCall(String, Vec), /// Declares a global label. GlobalLabelDeclaration(String), /// Declares a label that is local to the current file. @@ -29,6 +29,7 @@ pub(crate) enum Item { pub(crate) enum PushTarget { Literal(Literal), Label(String), + MacroVar(String), } #[derive(Clone, Debug)] diff --git a/evm/src/cpu/kernel/evm_asm.pest b/evm/src/cpu/kernel/evm_asm.pest index 587f87f1..8333a230 100644 --- a/evm/src/cpu/kernel/evm_asm.pest +++ b/evm/src/cpu/kernel/evm_asm.pest @@ -12,13 +12,18 @@ literal_decimal = @{ ASCII_DIGIT+ } literal_hex = @{ ^"0x" ~ ASCII_HEX_DIGIT+ } literal = { literal_hex | literal_decimal } +variable = ${ "$" ~ identifier } + item = { macro_def | macro_call | global_label | local_label | bytes_item | push_instruction | nullary_instruction } -macro_def = { ^"%macro" ~ identifier ~ item* ~ ^"%endmacro" } -macro_call = ${ "%" ~ !(^"macro" | ^"endmacro") ~ identifier } +macro_def = { ^"%macro" ~ identifier ~ macro_paramlist? ~ item* ~ ^"%endmacro" } +macro_call = ${ "%" ~ !(^"macro" | ^"endmacro") ~ identifier ~ macro_arglist? } +macro_paramlist = { "(" ~ identifier ~ ("," ~ identifier)* ~ ")" } +macro_arglist = !{ "(" ~ push_target ~ ("," ~ push_target)* ~ ")" } global_label = { ^"GLOBAL " ~ identifier ~ ":" } local_label = { identifier ~ ":" } bytes_item = { ^"BYTES " ~ literal ~ ("," ~ literal)* } -push_instruction = { ^"PUSH " ~ (literal | identifier) } +push_instruction = { ^"PUSH " ~ push_target } +push_target = { literal | identifier | variable } nullary_instruction = { identifier } file = { SOI ~ item* ~ silent_eoi } diff --git a/evm/src/cpu/kernel/parser.rs b/evm/src/cpu/kernel/parser.rs index ab928582..4145b5f0 100644 --- a/evm/src/cpu/kernel/parser.rs +++ b/evm/src/cpu/kernel/parser.rs @@ -18,14 +18,11 @@ pub(crate) fn parse(s: &str) -> File { } fn parse_item(item: Pair) -> Item { + assert_eq!(item.as_rule(), Rule::item); let item = item.into_inner().next().unwrap(); match item.as_rule() { - Rule::macro_def => { - let mut inner = item.into_inner(); - let name = inner.next().unwrap().as_str().into(); - Item::MacroDef(name, inner.map(parse_item).collect()) - } - Rule::macro_call => Item::MacroCall(item.into_inner().next().unwrap().as_str().into()), + Rule::macro_def => parse_macro_def(item), + Rule::macro_call => parse_macro_call(item), Rule::global_label => { Item::GlobalLabelDeclaration(item.into_inner().next().unwrap().as_str().into()) } @@ -39,11 +36,48 @@ fn parse_item(item: Pair) -> Item { } } +fn parse_macro_def(item: Pair) -> Item { + assert_eq!(item.as_rule(), Rule::macro_def); + let mut inner = item.into_inner().peekable(); + + let name = inner.next().unwrap().as_str().into(); + + // The parameter list is optional. + let params = if let Some(Rule::macro_paramlist) = inner.peek().map(|pair| pair.as_rule()) { + let params = inner.next().unwrap().into_inner(); + params.map(|param| param.as_str().to_string()).collect() + } else { + vec![] + }; + + Item::MacroDef(name, params, inner.map(parse_item).collect()) +} + +fn parse_macro_call(item: Pair) -> Item { + assert_eq!(item.as_rule(), Rule::macro_call); + let mut inner = item.into_inner(); + + let name = inner.next().unwrap().as_str().into(); + + // The arg list is optional. + let args = if let Some(arglist) = inner.next() { + assert_eq!(arglist.as_rule(), Rule::macro_arglist); + arglist.into_inner().map(parse_push_target).collect() + } else { + vec![] + }; + + Item::MacroCall(name, args) +} + fn parse_push_target(target: Pair) -> PushTarget { - match target.as_rule() { - Rule::identifier => PushTarget::Label(target.as_str().into()), - Rule::literal => PushTarget::Literal(parse_literal(target)), - _ => panic!("Unexpected {:?}", target.as_rule()), + assert_eq!(target.as_rule(), Rule::push_target); + let inner = target.into_inner().next().unwrap(); + match inner.as_rule() { + Rule::literal => PushTarget::Literal(parse_literal(inner)), + Rule::identifier => PushTarget::Label(inner.as_str().into()), + Rule::variable => PushTarget::MacroVar(inner.into_inner().next().unwrap().as_str().into()), + _ => panic!("Unexpected {:?}", inner.as_rule()), } } From 9c4947e0f0663eb7bc5801482e3bfac4bb094d43 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Thu, 7 Jul 2022 18:06:24 +0200 Subject: [PATCH 23/30] EC ops test --- evm/src/cpu/kernel/aggregator.rs | 138 ++++++++++++++++++++++++++++++ evm/src/cpu/kernel/assembler.rs | 2 +- evm/src/cpu/kernel/interpreter.rs | 48 +++++++---- 3 files changed, 169 insertions(+), 19 deletions(-) diff --git a/evm/src/cpu/kernel/aggregator.rs b/evm/src/cpu/kernel/aggregator.rs index ac0d6f7c..d58208fd 100644 --- a/evm/src/cpu/kernel/aggregator.rs +++ b/evm/src/cpu/kernel/aggregator.rs @@ -23,11 +23,149 @@ pub(crate) fn combined_kernel() -> Kernel { #[cfg(test)] mod tests { + use std::str::FromStr; + + use anyhow::Result; + use ethereum_types::U256; + use crate::cpu::kernel::aggregator::combined_kernel; + use crate::cpu::kernel::interpreter::run; #[test] fn make_kernel() { // Make sure we can parse and assemble the entire kernel. combined_kernel(); } + + fn u256ify<'a>(hexes: impl IntoIterator) -> Result> { + Ok(hexes + .into_iter() + .map(U256::from_str) + .collect::, _>>()?) + } + + #[test] + fn test_ec_ops() -> Result<()> { + // Make sure we can parse and assemble the entire kernel. + let kernel = combined_kernel(); + let ec_add = kernel.global_labels["ec_add"]; + let ec_double = kernel.global_labels["ec_double"]; + let ec_mul = kernel.global_labels["ec_mul"]; + let identity = ("0x0", "0x0"); + let invalid = ("0x0", "0x3"); // Not on curve + let point0 = ( + "0x1feee7ec986e198890cb83be8b8ba09ee953b3f149db6d9bfdaa5c308a33e58d", + "0x2051cc9a9edd46231604fd88f351e95ec72a285be93e289ac59cb48561efb2c6", + ); + let point1 = ( + "0x15b64d0a5f329fb672029298be8050f444626e6de11903caffa74b388075be1b", + "0x2d9e07340bd5cd7b70687b98f2500ff930a89a30d7b6a3e04b1b4d345319d234", + ); + // point2 = point0 + point1 + let point2 = ( + "0x18659c0e0a8fedcb8747cf463fc7cfa05f667d84e771d0a9521fc1a550688f0c", + "0x283ed10b42703e187e7a808aeb45c6b457bc4cc7d704e53b3348a1e3b0bfa55b", + ); + // point3 = 2 * point0 + let point3 = ( + "0x17da2b7b1a01c8dfdf0f5a6415833c7d755d219aa7e2c4cd0ac83d87d0ca4217", + "0xc9ace9de14aac8114541b50c19320eb40f0eeac3621526d9e34dbcf4c3a6c0f", + ); + let s = "0xabb2a34c0e7956cfe6cef9ddb7e810c45ea19a6ebadd79c21959af09f5ba480a"; + // point4 = s * point0 + let point4 = ( + "0xe519344959cc17021fe98878f947f5c1b1675325533a620c1684cfa6367e6c0", + "0x7496a7575b0b6a821e19ce780ecc3e0b156e605327798693defeb9f265b7a6f", + ); + + // Standard addition #1 + let initial_stack = u256ify(["0xdeadbeef", point0.1, point0.0, point1.1, point1.0])?; + let stack = run(&kernel.code, ec_add, initial_stack); + assert_eq!(stack, u256ify([point2.1, point2.0])?); + // Standard addition #2 + let initial_stack = u256ify(["0xdeadbeef", point1.1, point1.0, point0.1, point0.0])?; + let stack = run(&kernel.code, ec_add, initial_stack); + assert_eq!(stack, u256ify([point2.1, point2.0])?); + + // Standard doubling #1 + let initial_stack = u256ify(["0xdeadbeef", point0.1, point0.0, point0.1, point0.0])?; + let stack = run(&kernel.code, ec_add, initial_stack); + assert_eq!(stack, u256ify([point3.1, point3.0])?); + // Standard doubling #2 + let initial_stack = u256ify(["0xdeadbeef", point0.1, point0.0])?; + let stack = run(&kernel.code, ec_double, initial_stack); + assert_eq!(stack, u256ify([point3.1, point3.0])?); + // Standard doubling #3 + let initial_stack = u256ify(["0xdeadbeef", "0x2", point0.1, point0.0])?; + let stack = run(&kernel.code, ec_mul, initial_stack); + assert_eq!(stack, u256ify([point3.1, point3.0])?); + + // Addition with identity #1 + let initial_stack = u256ify(["0xdeadbeef", identity.1, identity.0, point1.1, point1.0])?; + let stack = run(&kernel.code, ec_add, initial_stack); + assert_eq!(stack, u256ify([point1.1, point1.0])?); + // Addition with identity #2 + let initial_stack = u256ify(["0xdeadbeef", point1.1, point1.0, identity.1, identity.0])?; + let stack = run(&kernel.code, ec_add, initial_stack); + assert_eq!(stack, u256ify([point1.1, point1.0])?); + // Addition with identity #3 + let initial_stack = + u256ify(["0xdeadbeef", identity.1, identity.0, identity.1, identity.0])?; + let stack = run(&kernel.code, ec_add, initial_stack); + assert_eq!(stack, u256ify([identity.1, identity.0])?); + + // Addition with invalid point(s) #1 + let initial_stack = u256ify(["0xdeadbeef", point0.1, point0.0, invalid.1, invalid.0])?; + let stack = run(&kernel.code, ec_add, initial_stack); + assert_eq!(stack, vec![U256::MAX, U256::MAX]); + // Addition with invalid point(s) #2 + let initial_stack = u256ify(["0xdeadbeef", invalid.1, invalid.0, point0.1, point0.0])?; + let stack = run(&kernel.code, ec_add, initial_stack); + assert_eq!(stack, vec![U256::MAX, U256::MAX]); + // Addition with invalid point(s) #3 + let initial_stack = u256ify(["0xdeadbeef", invalid.1, invalid.0, identity.1, identity.0])?; + let stack = run(&kernel.code, ec_add, initial_stack); + assert_eq!(stack, vec![U256::MAX, U256::MAX]); + // Addition with invalid point(s) #4 + let initial_stack = u256ify(["0xdeadbeef", invalid.1, invalid.0, invalid.1, invalid.0])?; + let stack = run(&kernel.code, ec_add, initial_stack); + assert_eq!(stack, vec![U256::MAX, U256::MAX]); + + // Scalar multiplication #1 + let initial_stack = u256ify(["0xdeadbeef", s, point0.1, point0.0])?; + let stack = run(&kernel.code, ec_mul, initial_stack); + assert_eq!(stack, u256ify([point4.1, point4.0])?); + // Scalar multiplication #2 + let initial_stack = u256ify(["0xdeadbeef", "0x0", point0.1, point0.0])?; + let stack = run(&kernel.code, ec_mul, initial_stack); + assert_eq!(stack, u256ify([identity.1, identity.0])?); + // Scalar multiplication #3 + let initial_stack = u256ify(["0xdeadbeef", "0x1", point0.1, point0.0])?; + let stack = run(&kernel.code, ec_mul, initial_stack); + assert_eq!(stack, u256ify([point0.1, point0.0])?); + // Scalar multiplication #4 + let initial_stack = u256ify(["0xdeadbeef", s, identity.1, identity.0])?; + let stack = run(&kernel.code, ec_mul, initial_stack); + assert_eq!(stack, u256ify([identity.1, identity.0])?); + // Scalar multiplication #5 + let initial_stack = u256ify(["0xdeadbeef", s, invalid.1, invalid.0])?; + let stack = run(&kernel.code, ec_mul, initial_stack); + assert_eq!(stack, vec![U256::MAX, U256::MAX]); + + // Multiple calls + let ec_mul_hex = format!("0x{:x}", ec_mul); + let initial_stack = u256ify([ + "0xdeadbeef", + s, + &ec_mul_hex, + identity.1, + identity.0, + point0.1, + point0.0, + ])?; + let stack = run(&kernel.code, ec_add, initial_stack); + assert_eq!(stack, u256ify([point4.1, point4.0])?); + + Ok(()) + } } diff --git a/evm/src/cpu/kernel/assembler.rs b/evm/src/cpu/kernel/assembler.rs index d7e40f24..91f64a42 100644 --- a/evm/src/cpu/kernel/assembler.rs +++ b/evm/src/cpu/kernel/assembler.rs @@ -16,7 +16,7 @@ const BYTES_PER_OFFSET: u8 = 3; #[derive(PartialEq, Eq, Debug)] pub struct Kernel { pub code: Vec, - global_labels: HashMap, + pub(crate) global_labels: HashMap, } pub(crate) fn assemble(files: Vec) -> Kernel { diff --git a/evm/src/cpu/kernel/interpreter.rs b/evm/src/cpu/kernel/interpreter.rs index f344befd..c1f69108 100644 --- a/evm/src/cpu/kernel/interpreter.rs +++ b/evm/src/cpu/kernel/interpreter.rs @@ -1,12 +1,12 @@ use ethereum_types::{U256, U512}; -struct Interpreter { - code: Vec, +struct Interpreter<'a> { + code: &'a [u8], offset: usize, stack: Vec, } -pub fn run(code: Vec, initial_offset: usize, initial_stack: Vec) -> Vec { +pub fn run(code: &[u8], initial_offset: usize, initial_stack: Vec) -> Vec { let mut interpreter = Interpreter { code, offset: initial_offset, @@ -18,7 +18,7 @@ pub fn run(code: Vec, initial_offset: usize, initial_stack: Vec) -> Ve interpreter.stack } -impl Interpreter { +impl<'a> Interpreter<'a> { fn slice(&self, n: usize) -> &[u8] { &self.code[self.offset..self.offset + n] } @@ -37,12 +37,12 @@ impl Interpreter { fn run_opcode(&mut self) { let opcode = self.code[self.offset]; - self.incr(1); match opcode { 0x00 => todo!(), // "STOP", 0x01 => self.run_add(), // "ADD", 0x02 => self.run_mul(), // "MUL", 0x03 => self.run_sub(), // "SUB", + 0x04 => self.run_div(), // "DIV", 0x05 => todo!(), // "SDIV", 0x06 => self.run_mod(), // "MOD", 0x07 => todo!(), // "SMOD", @@ -89,7 +89,7 @@ impl Interpreter { 0x45 => todo!(), // "GASLIMIT", 0x46 => todo!(), // "CHAINID", 0x48 => todo!(), // "BASEFEE", - 0x50 => todo!(), // "POP", + 0x50 => self.run_pop(), // "POP", 0x51 => todo!(), // "MLOAD", 0x52 => todo!(), // "MSTORE", 0x53 => todo!(), // "MSTORE8", @@ -119,7 +119,7 @@ impl Interpreter { 0xfd => todo!(), // "REVERT", 0xfe => todo!(), // "INVALID", 0xff => todo!(), // "SELFDESTRUCT", - _ => panic!("Unrecognized mnemonic."), + _ => panic!("Unrecognized opcode {}.", opcode), }; } @@ -144,6 +144,13 @@ impl Interpreter { self.incr(1); } + fn run_div(&mut self) { + let x = self.pop(); + let y = self.pop(); + self.push(x / y); + self.incr(1); + } + fn run_mod(&mut self) { let x = self.pop(); let y = self.pop(); @@ -234,13 +241,17 @@ impl Interpreter { self.incr(1); } + fn run_pop(&mut self) { + self.pop(); + self.incr(1); + } + fn run_jump(&mut self) { let x = self.pop().as_usize(); self.offset = x; - assert_eq!( - self.code[self.offset], 0x5b, - "Destination is not a JUMPDEST." - ); + if let Some(&landing_opcode) = self.code.get(self.offset) { + assert_eq!(landing_opcode, 0x5b, "Destination is not a JUMPDEST."); + } } fn run_jumpi(&mut self) { @@ -248,28 +259,29 @@ impl Interpreter { let b = self.pop(); if !b.is_zero() { self.offset = x; - assert_eq!( - self.code[self.offset], 0x5b, - "Destination is not a JUMPDEST." - ); + if let Some(&landing_opcode) = self.code.get(self.offset) { + assert_eq!(landing_opcode, 0x5b, "Destination is not a JUMPDEST."); + } } else { self.incr(1); } } fn run_push(&mut self, num_bytes: u8) { + self.incr(1); let x = U256::from_big_endian(self.slice(num_bytes as usize)); self.incr(num_bytes as usize); self.push(x); } fn run_dup(&mut self, n: u8) { - self.push(self.stack[n as usize - 1]); + self.push(self.stack[self.stack.len() - n as usize]); self.incr(1); } fn run_swap(&mut self, n: u8) { - self.stack.swap(0, n as usize); + let len = self.stack.len(); + self.stack.swap(len - 1, len - n as usize - 1); self.incr(1); } } @@ -282,6 +294,6 @@ mod tests { fn test_run() { // PUSH1 1 PUSH1 2 ADD let code = vec![0x60, 0x1, 0x60, 0x2, 0x1]; - assert_eq!(run(code, 0, vec![]), vec![0x3.into()]); + assert_eq!(run(&code, 0, vec![]), vec![0x3.into()]); } } From 267f4162dd67b0375131e71357783b3a98557191 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Thu, 7 Jul 2022 18:20:24 +0200 Subject: [PATCH 24/30] Minor --- evm/src/cpu/kernel/interpreter.rs | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/evm/src/cpu/kernel/interpreter.rs b/evm/src/cpu/kernel/interpreter.rs index c1f69108..29245fc9 100644 --- a/evm/src/cpu/kernel/interpreter.rs +++ b/evm/src/cpu/kernel/interpreter.rs @@ -12,7 +12,8 @@ pub fn run(code: &[u8], initial_offset: usize, initial_stack: Vec) -> Vec< offset: initial_offset, stack: initial_stack, }; - while interpreter.offset < interpreter.code.len() { + // Halt the execution if a jump to 0xdeadbeef was done. + while interpreter.offset != 0xdeadbeef { interpreter.run_opcode(); } interpreter.stack From f8987b7e80cd9b1e60806889d5adeef03bc4e48e Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Thu, 7 Jul 2022 18:20:24 +0200 Subject: [PATCH 25/30] Minor --- evm/src/cpu/kernel/interpreter.rs | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/evm/src/cpu/kernel/interpreter.rs b/evm/src/cpu/kernel/interpreter.rs index c1f69108..a099a48b 100644 --- a/evm/src/cpu/kernel/interpreter.rs +++ b/evm/src/cpu/kernel/interpreter.rs @@ -12,7 +12,8 @@ pub fn run(code: &[u8], initial_offset: usize, initial_stack: Vec) -> Vec< offset: initial_offset, stack: initial_stack, }; - while interpreter.offset < interpreter.code.len() { + // Halt the execution if a jump to 0xdeadbeef was done. + while interpreter.offset != 0xdeadbeef { interpreter.run_opcode(); } interpreter.stack @@ -292,8 +293,9 @@ mod tests { #[test] fn test_run() { - // PUSH1 1 PUSH1 2 ADD - let code = vec![0x60, 0x1, 0x60, 0x2, 0x1]; + let code = vec![ + 0x60, 0x1, 0x60, 0x2, 0x1, 0x63, 0xde, 0xad, 0xbe, 0xef, 0x56, + ]; // PUSH1, 1, PUSH1, 2, ADD, PUSH4 deadbeef, JUMP assert_eq!(run(&code, 0, vec![]), vec![0x3.into()]); } } From 7bf5118f69b1f36392c8e8865b44892a42af1fc0 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Thu, 7 Jul 2022 18:46:20 +0200 Subject: [PATCH 26/30] Test exp kernel function --- evm/src/cpu/kernel/aggregator.rs | 36 +++++++++++++++++++++++++++++++ evm/src/cpu/kernel/asm/exp.asm | 3 +++ evm/src/cpu/kernel/interpreter.rs | 8 +++---- 3 files changed, 43 insertions(+), 4 deletions(-) diff --git a/evm/src/cpu/kernel/aggregator.rs b/evm/src/cpu/kernel/aggregator.rs index d58208fd..a23e18b8 100644 --- a/evm/src/cpu/kernel/aggregator.rs +++ b/evm/src/cpu/kernel/aggregator.rs @@ -27,6 +27,7 @@ mod tests { use anyhow::Result; use ethereum_types::U256; + use rand::{thread_rng, Rng}; use crate::cpu::kernel::aggregator::combined_kernel; use crate::cpu::kernel::interpreter::run; @@ -43,6 +44,41 @@ mod tests { .map(U256::from_str) .collect::, _>>()?) } + #[test] + fn test_exp() -> Result<()> { + // Make sure we can parse and assemble the entire kernel. + let kernel = combined_kernel(); + let exp = kernel.global_labels["exp"]; + let mut rng = thread_rng(); + let a = U256([0; 4].map(|_| rng.gen())); + let b = U256([0; 4].map(|_| rng.gen())); + + // Random input + let initial_stack = vec![U256::from_str("0xdeadbeef")?, b, a]; + let stack_with_kernel = run(&kernel.code, exp, initial_stack); + let initial_stack = vec![b, a]; + let code = [0xa, 0x63, 0xde, 0xad, 0xbe, 0xef, 0x56]; // EXP, PUSH4 deadbeef, JUMP + let stack_with_opcode = run(&code, 0, initial_stack); + assert_eq!(stack_with_kernel, stack_with_opcode); + + // 0 base + let initial_stack = vec![U256::from_str("0xdeadbeef")?, b, U256::zero()]; + let stack_with_kernel = run(&kernel.code, exp, initial_stack); + let initial_stack = vec![b, U256::zero()]; + let code = [0xa, 0x63, 0xde, 0xad, 0xbe, 0xef, 0x56]; // EXP, PUSH4 deadbeef, JUMP + let stack_with_opcode = run(&code, 0, initial_stack); + assert_eq!(stack_with_kernel, stack_with_opcode); + + // 0 exponent + let initial_stack = vec![U256::from_str("0xdeadbeef")?, U256::zero(), a]; + let stack_with_kernel = run(&kernel.code, exp, initial_stack); + let initial_stack = vec![U256::zero(), a]; + let code = [0xa, 0x63, 0xde, 0xad, 0xbe, 0xef, 0x56]; // EXP, PUSH4 deadbeef, JUMP + let stack_with_opcode = run(&code, 0, initial_stack); + assert_eq!(stack_with_kernel, stack_with_opcode); + + Ok(()) + } #[test] fn test_ec_ops() -> Result<()> { diff --git a/evm/src/cpu/kernel/asm/exp.asm b/evm/src/cpu/kernel/asm/exp.asm index 3e3b0f6f..683e67c3 100644 --- a/evm/src/cpu/kernel/asm/exp.asm +++ b/evm/src/cpu/kernel/asm/exp.asm @@ -10,6 +10,7 @@ /// Note that this correctly handles exp(0, 0) == 1. global exp: + jumpdest // stack: x, e, retdest dup2 // stack: e, x, e, retdest @@ -28,6 +29,7 @@ global exp: jump step_case: + jumpdest // stack: x, e, retdest push recursion_return // stack: recursion_return, x, e, retdest @@ -45,6 +47,7 @@ step_case: // stack: exp, x * x, e / 2, recursion_return, x, e, retdest jump recursion_return: + jumpdest // stack: exp(x * x, e / 2), x, e, retdest push 2 // stack: 2, exp(x * x, e / 2), x, e, retdest diff --git a/evm/src/cpu/kernel/interpreter.rs b/evm/src/cpu/kernel/interpreter.rs index a099a48b..97fb5209 100644 --- a/evm/src/cpu/kernel/interpreter.rs +++ b/evm/src/cpu/kernel/interpreter.rs @@ -127,21 +127,21 @@ impl<'a> Interpreter<'a> { fn run_add(&mut self) { let x = self.pop(); let y = self.pop(); - self.push(x + y); + self.push(x.overflowing_add(y).0); self.incr(1); } fn run_mul(&mut self) { let x = self.pop(); let y = self.pop(); - self.push(x * y); + self.push(x.overflowing_mul(y).0); self.incr(1); } fn run_sub(&mut self) { let x = self.pop(); let y = self.pop(); - self.push(x - y); + self.push(x.overflowing_sub(y).0); self.incr(1); } @@ -180,7 +180,7 @@ impl<'a> Interpreter<'a> { fn run_exp(&mut self) { let x = self.pop(); let y = self.pop(); - self.push(x.pow(y)); + self.push(x.overflowing_pow(y).0); self.incr(1); } From 4316be96cda2e78fdc884c6e48c281dcc009c9c0 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Thu, 7 Jul 2022 19:15:39 +0200 Subject: [PATCH 27/30] Test exp kernel function --- evm/src/cpu/kernel/asm/curve_add.asm | 60 ++++++---------------------- evm/src/cpu/kernel/asm/curve_mul.asm | 33 ++++----------- 2 files changed, 19 insertions(+), 74 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index fdbbf997..4ac4e0e4 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -27,19 +27,11 @@ global ec_add: // stack: isValid(x1, y1), isValid(x0, y0), x0, y0, x1, y1, retdest AND // stack: isValid(x1, y1) & isValid(x0, y0), x0, y0, x1, y1, retdest - PUSH ec_add_valid_points - // stack: ec_add_valid_points, isValid(x1, y1) & isValid(x0, y0), x0, y0, x1, y1, retdest - JUMPI + %jumpi(ec_add_valid_points) // stack: x0, y0, x1, y1, retdest // Otherwise return - POP - // stack: y0, x1, y1, retdest - POP - // stack: x1, y1, retdest - POP - // stack: y1, retdest - POP + %pop4 // stack: retdest %ec_invalid_input @@ -56,9 +48,7 @@ global ec_add_valid_points: // stack: x0, y0, x0, y0, x1, y1, retdest %ec_isidentity // stack: (x0,y0)==(0,0), x0, y0, x1, y1, retdest - PUSH ec_add_first_zero - // stack: ec_add_first_zero, (x0,y0)==(0,0), x0, y0, x1, y1, retdest - JUMPI + %jumpi(ec_add_first_zero) // stack: x0, y0, x1, y1, retdest // Check if the first point is the identity. @@ -68,9 +58,7 @@ global ec_add_valid_points: // stack: x1, y1, x0, y0, x1, y1, retdest %ec_isidentity // stack: (x1,y1)==(0,0), x0, y0, x1, y1, retdest - PUSH ec_add_snd_zero - // stack: ec_add_snd_zero, (x1,y1)==(0,0), x0, y0, x1, y1, retdest - JUMPI + %jumpi(ec_add_snd_zero) // stack: x0, y0, x1, y1, retdest // Check if both points have the same x-coordinate. @@ -80,9 +68,7 @@ global ec_add_valid_points: // stack: x0, x1, x0, y0, x1, y1, retdest EQ // stack: x0 == x1, x0, y0, x1, y1, retdest - PUSH ec_add_equal_first_coord - // stack: ec_add_equal_first_coord, x0 == x1, x0, y0, x1, y1, retdest - JUMPI + %jumpi(ec_add_equal_first_coord) // stack: x0, y0, x1, y1, retdest // Otherwise, we can use the standard formula. @@ -101,9 +87,7 @@ global ec_add_valid_points: // stack: x0 - x1, y0 - y1, x0, y0, x1, y1, retdest %moddiv // stack: lambda, x0, y0, x1, y1, retdest - PUSH ec_add_valid_points_with_lambda - // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest - JUMP + %jump(ec_add_valid_points_with_lambda) // BN254 elliptic curve addition. // Assumption: (x0,y0) == (0,0) @@ -112,9 +96,7 @@ ec_add_first_zero: // stack: x0, y0, x1, y1, retdest // Just return (x1,y1) - POP - // stack: y0, x1, y1, retdest - POP + %pop2 // stack: x1, y1, retdest SWAP1 // stack: y1, x1, retdest @@ -194,13 +176,7 @@ ec_add_valid_points_with_lambda: // stack: x2, lambda, x0, y0, y2, y1, retdest SWAP5 // stack: y1, lambda, x0, y0, y2, x2, retdest - POP - // stack: lambda, x0, y0, y2, x2, retdest - POP - // stack: x0, y0, y2, x2, retdest - POP - // stack: y0, y2, x2, retdest - POP + %pop4 // stack: y2, x2, retdest SWAP2 // stack: retdest, x2, y2 @@ -219,19 +195,11 @@ ec_add_equal_first_coord: // stack: y1, y0, x0, y0, x1, y1, retdest EQ // stack: y1 == y0, x0, y0, x1, y1, retdest - PUSH ec_add_equal_points - // stack: ec_add_equal_points, y1 == y0, x0, y0, x1, y1, retdest - JUMPI + %jumpi(ec_add_equal_points) // stack: x0, y0, x1, y1, retdest // Otherwise, one is the negation of the other so we can return (0,0). - POP - // stack: y0, x1, y1, retdest - POP - // stack: x1, y1, retdest - POP - // stack: y1, retdest - POP + %pop4 // stack: retdest PUSH 0 // stack: 0, retdest @@ -268,9 +236,7 @@ ec_add_equal_points: // stack: y0, 3/2 * x0^2, x0, y0, x1, y1, retdest %moddiv // stack: lambda, x0, y0, x1, y1, retdest - PUSH ec_add_valid_points_with_lambda - // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest - JUMP + %jump(ec_add_valid_points_with_lambda) // BN254 elliptic curve doubling. // Assumption: (x0,y0) is a valid point. @@ -282,9 +248,7 @@ global ec_double: // stack: y0, x0, y0, retdest DUP2 // stack: x0, y0, x0, y0, retdest - PUSH ec_add_equal_points - // stack: ec_add_equal_points, x0, y0, x0, y0, retdest - JUMP + %jump(ec_add_equal_points) // Push the order of the BN254 base field. %macro bn_base diff --git a/evm/src/cpu/kernel/asm/curve_mul.asm b/evm/src/cpu/kernel/asm/curve_mul.asm index 0826b0e3..85469b65 100644 --- a/evm/src/cpu/kernel/asm/curve_mul.asm +++ b/evm/src/cpu/kernel/asm/curve_mul.asm @@ -28,12 +28,7 @@ global ec_mul: // stack: ec_mul_valid_point, isValid(x, y), x, y, s, retdest JUMPI // stack: x, y, s, retdest - POP - // stack: y, s, retdest - POP - // stack: s, retdest - POP - // stack: retdest + %pop3 %ec_invalid_input // Same algorithm as in `exp.asm` @@ -46,9 +41,7 @@ ec_mul_valid_point: // stack: step_case, s, x, y, s, retdest JUMPI // stack: x, y, s, retdest - PUSH ret_zero - // stack: ret_zero, x, y, s, retdest - JUMP + %jump(ret_zero) step_case: JUMPDEST @@ -67,17 +60,13 @@ step_case: // stack: y, step_case_contd, s / 2, recursion_return, x, y, s, retdest DUP5 // stack: x, y, step_case_contd, s / 2, recursion_return, x, y, s, retdest - PUSH ec_double - // stack: ec_double, x, y, step_case_contd, s / 2, recursion_return, x, y, s, retdest - JUMP + %jump(ec_double) // Assumption: 2(x,y) = (x',y') step_case_contd: JUMPDEST // stack: x', y', s / 2, recursion_return, x, y, s, retdest - PUSH ec_mul_valid_point - // stack: ec_mul_valid_point, x', y', s / 2, recursion_return, x, y, s, retdest - JUMP + %jump(ec_mul_valid_point) recursion_return: JUMPDEST @@ -98,9 +87,7 @@ recursion_return: // stack: x', s & 1, y', x, y, retdest SWAP1 // stack: s & 1, x', y', x, y, retdest - PUSH odd_scalar - // stack: odd_scalar, s & 1, x', y', x, y, retdest - JUMPI + %jumpi(odd_scalar) // stack: x', y', x, y, retdest SWAP3 // stack: y, y', x, x', retdest @@ -117,18 +104,12 @@ recursion_return: odd_scalar: JUMPDEST // stack: x', y', x, y, retdest - PUSH ec_add_valid_points - // stack: ec_add_valid_points, x', y', x, y, retdest - JUMP + %jump(ec_add_valid_points) ret_zero: JUMPDEST // stack: x, y, s, retdest - POP - // stack: y, s, retdest - POP - // stack: s, retdest - POP + %pop3 // stack: retdest PUSH 0 // stack: 0, retdest From a3c2e9a2959d2b2005396dc72f013edb24862acc Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Thu, 7 Jul 2022 19:28:11 +0200 Subject: [PATCH 28/30] More macros --- evm/src/cpu/kernel/asm/curve_mul.asm | 12 +++--------- 1 file changed, 3 insertions(+), 9 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_mul.asm b/evm/src/cpu/kernel/asm/curve_mul.asm index 85469b65..246946d9 100644 --- a/evm/src/cpu/kernel/asm/curve_mul.asm +++ b/evm/src/cpu/kernel/asm/curve_mul.asm @@ -14,9 +14,7 @@ global ec_mul: // stack: x, y, x, y, s, retdest %ec_isidentity // stack: (x,y)==(0,0), x, y, s, retdest - PUSH ret_zero - // stack: ret_zero, y==0 & x==0, x, y, s, retdest - JUMPI + %jumpi(ret_zero) // stack: x, y, s, retdest DUP2 // stack: y, x, y, s, retdest @@ -24,9 +22,7 @@ global ec_mul: // stack: x, y, x, y, s, retdest %ec_check // stack: isValid(x, y), x, y, s, retdest - PUSH ec_mul_valid_point - // stack: ec_mul_valid_point, isValid(x, y), x, y, s, retdest - JUMPI + %jumpi(ec_mul_valid_point) // stack: x, y, s, retdest %pop3 %ec_invalid_input @@ -37,9 +33,7 @@ ec_mul_valid_point: // stack: x, y, s, retdest DUP3 // stack: s, x, y, s, retdest - PUSH step_case - // stack: step_case, s, x, y, s, retdest - JUMPI + %jumpi(step_case) // stack: x, y, s, retdest %jump(ret_zero) From 12ca084620c1d1371336c612d7511dea85e2ed1c Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Fri, 8 Jul 2022 09:58:52 +0200 Subject: [PATCH 29/30] PR feedback --- evm/src/cpu/kernel/interpreter.rs | 59 ++++++++++++------------------- 1 file changed, 22 insertions(+), 37 deletions(-) diff --git a/evm/src/cpu/kernel/interpreter.rs b/evm/src/cpu/kernel/interpreter.rs index 97fb5209..500d4a8e 100644 --- a/evm/src/cpu/kernel/interpreter.rs +++ b/evm/src/cpu/kernel/interpreter.rs @@ -32,12 +32,17 @@ impl<'a> Interpreter<'a> { self.stack.push(x); } + fn push_bool(&mut self, x: bool) { + self.stack.push(if x { U256::one() } else { U256::zero() }); + } + fn pop(&mut self) -> U256 { self.stack.pop().expect("Pop on empty stack.") } fn run_opcode(&mut self) { let opcode = self.code[self.offset]; + self.incr(1); match opcode { 0x00 => todo!(), // "STOP", 0x01 => self.run_add(), // "ADD", @@ -101,7 +106,7 @@ impl<'a> Interpreter<'a> { 0x58 => todo!(), // "GETPC", 0x59 => todo!(), // "MSIZE", 0x5a => todo!(), // "GAS", - 0x5b => self.incr(1), // "JUMPDEST", + 0x5b => (), // "JUMPDEST", x if (0x60..0x80).contains(&x) => self.run_push(x - 0x5f), // "PUSH" x if (0x80..0x90).contains(&x) => self.run_dup(x - 0x7f), // "DUP" x if (0x90..0xa0).contains(&x) => self.run_swap(x - 0x8f), // "SWAP" @@ -128,123 +133,108 @@ impl<'a> Interpreter<'a> { let x = self.pop(); let y = self.pop(); self.push(x.overflowing_add(y).0); - self.incr(1); } fn run_mul(&mut self) { let x = self.pop(); let y = self.pop(); self.push(x.overflowing_mul(y).0); - self.incr(1); } fn run_sub(&mut self) { let x = self.pop(); let y = self.pop(); self.push(x.overflowing_sub(y).0); - self.incr(1); } fn run_div(&mut self) { let x = self.pop(); let y = self.pop(); - self.push(x / y); - self.incr(1); + self.push(if y.is_zero() { U256::zero() } else { x / y }); } fn run_mod(&mut self) { let x = self.pop(); let y = self.pop(); - self.push(x % y); - self.incr(1); + self.push(if y.is_zero() { U256::zero() } else { x % y }); } fn run_addmod(&mut self) { let x = U512::from(self.pop()); let y = U512::from(self.pop()); let z = U512::from(self.pop()); - let res = (x + y) % z; - self.push(U256([0, 1, 2, 3].map(|i| res.0[i]))); - self.incr(1); + self.push(if z.is_zero() { + U256::zero() + } else { + U256::try_from((x + y) % z).unwrap() + }); } fn run_mulmod(&mut self) { let x = self.pop(); let y = self.pop(); let z = U512::from(self.pop()); - let res = x.full_mul(y) % z; - self.push(U256([0, 1, 2, 3].map(|i| res.0[i]))); - self.incr(1); + self.push(if z.is_zero() { + U256::zero() + } else { + U256::try_from(x.full_mul(y) % z).unwrap() + }); } fn run_exp(&mut self) { let x = self.pop(); let y = self.pop(); self.push(x.overflowing_pow(y).0); - self.incr(1); } fn run_lt(&mut self) { let x = self.pop(); let y = self.pop(); - self.push(if x < y { U256::one() } else { U256::zero() }); - self.incr(1); + self.push_bool(x < y); } fn run_gt(&mut self) { let x = self.pop(); let y = self.pop(); - self.push(if x > y { U256::one() } else { U256::zero() }); - self.incr(1); + self.push_bool(x > y); } fn run_eq(&mut self) { let x = self.pop(); let y = self.pop(); - self.push(if x == y { U256::one() } else { U256::zero() }); - self.incr(1); + self.push_bool(x == y); } fn run_iszero(&mut self) { let x = self.pop(); - self.push(if x.is_zero() { - U256::one() - } else { - U256::zero() - }); - self.incr(1); + self.push_bool(x.is_zero()); } fn run_and(&mut self) { let x = self.pop(); let y = self.pop(); self.push(x & y); - self.incr(1); } fn run_or(&mut self) { let x = self.pop(); let y = self.pop(); self.push(x | y); - self.incr(1); } fn run_xor(&mut self) { let x = self.pop(); let y = self.pop(); self.push(x ^ y); - self.incr(1); } fn run_not(&mut self) { let x = self.pop(); self.push(!x); - self.incr(1); } fn run_pop(&mut self) { self.pop(); - self.incr(1); } fn run_jump(&mut self) { @@ -263,13 +253,10 @@ impl<'a> Interpreter<'a> { if let Some(&landing_opcode) = self.code.get(self.offset) { assert_eq!(landing_opcode, 0x5b, "Destination is not a JUMPDEST."); } - } else { - self.incr(1); } } fn run_push(&mut self, num_bytes: u8) { - self.incr(1); let x = U256::from_big_endian(self.slice(num_bytes as usize)); self.incr(num_bytes as usize); self.push(x); @@ -277,13 +264,11 @@ impl<'a> Interpreter<'a> { fn run_dup(&mut self, n: u8) { self.push(self.stack[self.stack.len() - n as usize]); - self.incr(1); } fn run_swap(&mut self, n: u8) { let len = self.stack.len(); self.stack.swap(len - 1, len - n as usize - 1); - self.incr(1); } } From 58889e764929606e7703557d5cd519d585a6a5fe Mon Sep 17 00:00:00 2001 From: Daniel Lubarov Date: Fri, 8 Jul 2022 08:56:46 -0700 Subject: [PATCH 30/30] Allow constants to be passed from Rust into our assembly (#598) Roughly like environment variables. So we don't have to declare things like segment IDs twice. --- evm/src/cpu/kernel/aggregator.rs | 11 ++++++- evm/src/cpu/kernel/assembler.rs | 51 ++++++++++++++++++++++++++++---- evm/src/cpu/kernel/ast.rs | 1 + evm/src/cpu/kernel/evm_asm.pest | 3 +- evm/src/cpu/kernel/mod.rs | 4 ++- evm/src/cpu/kernel/parser.rs | 1 + 6 files changed, 62 insertions(+), 9 deletions(-) diff --git a/evm/src/cpu/kernel/aggregator.rs b/evm/src/cpu/kernel/aggregator.rs index a5d46a28..2b96aaf3 100644 --- a/evm/src/cpu/kernel/aggregator.rs +++ b/evm/src/cpu/kernel/aggregator.rs @@ -1,10 +1,19 @@ //! Loads each kernel assembly file and concatenates them. +use std::collections::HashMap; + +use ethereum_types::U256; use itertools::Itertools; use super::assembler::{assemble, Kernel}; use crate::cpu::kernel::parser::parse; +pub fn evm_constants() -> HashMap { + let mut c = HashMap::new(); + c.insert("SEGMENT_ID_TXN_DATA".into(), 0.into()); // TODO: Replace with actual segment ID. + c +} + #[allow(dead_code)] // TODO: Should be used once witness generation is done. pub(crate) fn combined_kernel() -> Kernel { let files = vec![ @@ -18,7 +27,7 @@ pub(crate) fn combined_kernel() -> Kernel { ]; let parsed_files = files.iter().map(|f| parse(f)).collect_vec(); - assemble(parsed_files) + assemble(parsed_files, evm_constants()) } #[cfg(test)] diff --git a/evm/src/cpu/kernel/assembler.rs b/evm/src/cpu/kernel/assembler.rs index 59db93a3..800f5094 100644 --- a/evm/src/cpu/kernel/assembler.rs +++ b/evm/src/cpu/kernel/assembler.rs @@ -1,8 +1,10 @@ use std::collections::HashMap; +use ethereum_types::U256; use itertools::izip; use super::ast::PushTarget; +use crate::cpu::kernel::ast::Literal; use crate::cpu::kernel::{ ast::{File, Item}, opcodes::{get_opcode, get_push_opcode}, @@ -33,7 +35,7 @@ impl Macro { } } -pub(crate) fn assemble(files: Vec) -> Kernel { +pub(crate) fn assemble(files: Vec, constants: HashMap) -> Kernel { let macros = find_macros(&files); let mut global_labels = HashMap::new(); let mut offset = 0; @@ -41,6 +43,7 @@ pub(crate) fn assemble(files: Vec) -> Kernel { let mut local_labels = Vec::with_capacity(files.len()); for file in files { let expanded_file = expand_macros(file.body, ¯os); + let expanded_file = inline_constants(expanded_file, &constants); local_labels.push(find_labels(&expanded_file, &mut offset, &mut global_labels)); expanded_files.push(expanded_file); } @@ -124,6 +127,22 @@ fn expand_macro_call( expand_macros(expanded_item, macros) } +fn inline_constants(body: Vec, constants: &HashMap) -> Vec { + body.into_iter() + .map(|item| { + if let Item::Push(PushTarget::Constant(c)) = item { + let value = constants + .get(&c) + .unwrap_or_else(|| panic!("No such constant: {}", c)); + let literal = Literal::Decimal(value.to_string()); + Item::Push(PushTarget::Literal(literal)) + } else { + item + } + }) + .collect() +} + fn find_labels( body: &[Item], offset: &mut usize, @@ -183,6 +202,7 @@ fn assemble_file( .collect() } PushTarget::MacroVar(v) => panic!("Variable not in a macro: {}", v), + PushTarget::Constant(c) => panic!("Constant wasn't inlined: {}", c), }; code.push(get_push_opcode(target_bytes.len() as u8)); code.extend(target_bytes); @@ -201,6 +221,7 @@ fn push_target_size(target: &PushTarget) -> u8 { PushTarget::Literal(lit) => lit.to_trimmed_be_bytes().len() as u8, PushTarget::Label(_) => BYTES_PER_OFFSET, PushTarget::MacroVar(v) => panic!("Variable not in a macro: {}", v), + PushTarget::Constant(c) => panic!("Constant wasn't inlined: {}", c), } } @@ -266,7 +287,7 @@ mod tests { }; let program = vec![file_1, file_2]; - assert_eq!(assemble(program), expected_kernel); + assert_eq!(assemble(program, HashMap::new()), expected_kernel); } #[test] @@ -284,7 +305,7 @@ mod tests { Item::StandardOp("JUMPDEST".to_string()), ], }; - assemble(vec![file_1, file_2]); + assemble(vec![file_1, file_2], HashMap::new()); } #[test] @@ -298,7 +319,7 @@ mod tests { Item::StandardOp("ADD".to_string()), ], }; - assemble(vec![file]); + assemble(vec![file], HashMap::new()); } #[test] @@ -315,7 +336,7 @@ mod tests { ]), ], }; - let code = assemble(vec![file]).code; + let code = assemble(vec![file], HashMap::new()).code; assert_eq!(code, vec![0x12, 42, 0xfe, 255]); } @@ -356,8 +377,26 @@ mod tests { parse_and_assemble(&["push $abc"]); } + #[test] + fn constants() { + let code = &["PUSH @DEAD_BEEF"]; + let mut constants = HashMap::new(); + constants.insert("DEAD_BEEF".into(), 0xDEADBEEFu64.into()); + + let kernel = parse_and_assemble_with_constants(code, constants); + let push4 = get_push_opcode(4); + assert_eq!(kernel.code, vec![push4, 0xDE, 0xAD, 0xBE, 0xEF]); + } + fn parse_and_assemble(files: &[&str]) -> Kernel { + parse_and_assemble_with_constants(files, HashMap::new()) + } + + fn parse_and_assemble_with_constants( + files: &[&str], + constants: HashMap, + ) -> Kernel { let parsed_files = files.iter().map(|f| parse(f)).collect_vec(); - assemble(parsed_files) + assemble(parsed_files, constants) } } diff --git a/evm/src/cpu/kernel/ast.rs b/evm/src/cpu/kernel/ast.rs index f011f1ff..5025cd99 100644 --- a/evm/src/cpu/kernel/ast.rs +++ b/evm/src/cpu/kernel/ast.rs @@ -30,6 +30,7 @@ pub(crate) enum PushTarget { Literal(Literal), Label(String), MacroVar(String), + Constant(String), } #[derive(Clone, Debug)] diff --git a/evm/src/cpu/kernel/evm_asm.pest b/evm/src/cpu/kernel/evm_asm.pest index 8333a230..d7f4629a 100644 --- a/evm/src/cpu/kernel/evm_asm.pest +++ b/evm/src/cpu/kernel/evm_asm.pest @@ -13,6 +13,7 @@ literal_hex = @{ ^"0x" ~ ASCII_HEX_DIGIT+ } literal = { literal_hex | literal_decimal } variable = ${ "$" ~ identifier } +constant = ${ "@" ~ identifier } item = { macro_def | macro_call | global_label | local_label | bytes_item | push_instruction | nullary_instruction } macro_def = { ^"%macro" ~ identifier ~ macro_paramlist? ~ item* ~ ^"%endmacro" } @@ -23,7 +24,7 @@ global_label = { ^"GLOBAL " ~ identifier ~ ":" } local_label = { identifier ~ ":" } bytes_item = { ^"BYTES " ~ literal ~ ("," ~ literal)* } push_instruction = { ^"PUSH " ~ push_target } -push_target = { literal | identifier | variable } +push_target = { literal | identifier | variable | constant } nullary_instruction = { identifier } file = { SOI ~ item* ~ silent_eoi } diff --git a/evm/src/cpu/kernel/mod.rs b/evm/src/cpu/kernel/mod.rs index 3e565d98..dd75a68a 100644 --- a/evm/src/cpu/kernel/mod.rs +++ b/evm/src/cpu/kernel/mod.rs @@ -10,10 +10,12 @@ mod interpreter; use assembler::assemble; use parser::parse; +use crate::cpu::kernel::aggregator::evm_constants; + /// Assemble files, outputting bytes. /// This is for debugging the kernel only. pub fn assemble_to_bytes(files: &[String]) -> Vec { let parsed_files: Vec<_> = files.iter().map(|f| parse(f)).collect(); - let kernel = assemble(parsed_files); + let kernel = assemble(parsed_files, evm_constants()); kernel.code } diff --git a/evm/src/cpu/kernel/parser.rs b/evm/src/cpu/kernel/parser.rs index 4145b5f0..c6dd8392 100644 --- a/evm/src/cpu/kernel/parser.rs +++ b/evm/src/cpu/kernel/parser.rs @@ -77,6 +77,7 @@ fn parse_push_target(target: Pair) -> PushTarget { Rule::literal => PushTarget::Literal(parse_literal(inner)), Rule::identifier => PushTarget::Label(inner.as_str().into()), Rule::variable => PushTarget::MacroVar(inner.into_inner().next().unwrap().as_str().into()), + Rule::constant => PushTarget::Constant(inner.into_inner().next().unwrap().as_str().into()), _ => panic!("Unexpected {:?}", inner.as_rule()), } }