From 797bece7bddbab3b70bfbaa647437afc8b540429 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Fri, 1 Jul 2022 18:28:22 +0200 Subject: [PATCH 01/18] First attempt --- evm/src/cpu/kernel/aggregator.rs | 1 + evm/src/cpu/kernel/asm/curve_add.asm | 301 +++++++++++++++++++++++++++ evm/src/cpu/kernel/ast.rs | 6 +- 3 files changed, 307 insertions(+), 1 deletion(-) create mode 100644 evm/src/cpu/kernel/asm/curve_add.asm diff --git a/evm/src/cpu/kernel/aggregator.rs b/evm/src/cpu/kernel/aggregator.rs index bdef51f7..773842f8 100644 --- a/evm/src/cpu/kernel/aggregator.rs +++ b/evm/src/cpu/kernel/aggregator.rs @@ -10,6 +10,7 @@ pub(crate) fn combined_kernel() -> Kernel { let files = vec![ include_str!("asm/basic_macros.asm"), include_str!("asm/exp.asm"), + include_str!("asm/curve_add.asm"), include_str!("asm/storage_read.asm"), include_str!("asm/storage_write.asm"), ]; diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm new file mode 100644 index 00000000..bab709e3 --- /dev/null +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -0,0 +1,301 @@ +// #define N 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // BN254 base field order + +global ecadd: + JUMPDEST + // stack: x0, y0, x1, y1, retdest + DUP3 + // stack: y1, x0, y0, x1, y1, retdest + DUP3 + // stack: x1, y1, x0, y0, x1, y1, retdest + DUP3 + // stack: y0, x1, y1, x0, y0, x1, y1, retdest + DUP3 + // stack: x0, y0, x1, y1, x0, y0, x1, y1, retdest + %ec_check + // stack: isValid(x0, y0), x1, y1, x0, y0, x1, y1, retdest + PUSH ec_add_valid_first_point + // stack: ec_add_valid_first_point, isValid(x0, y0), x1, y1, x0, y0, x1, y1, retdest + JUMPI + // stack: x1, y1, x0, y0, x1, y1, retdest + POP + // stack: y1, x0, y0, x1, y1, retdest + POP + // stack: x0, y0, x1, y1, retdest + POP + // stack: y0, x1, y1, retdest + POP + // stack: x1, y1, retdest + POP + // stack: y1, retdest + POP + // stack: retdest + JUMP + + +ec_add_valid_first_point: + JUMPDEST + // stack: x1, y1, x0, y0, x1, y1, retdest + %ec_check + // stack: isValid(x1, y1), x0, y0, x1, y1, retdest + PUSH ec_add_valid_points + // stack: ec_add_valid_points, isValid(x1, y1), x0, y0, x1, y1, retdest + JUMPI + // stack: x0, y0, x1, y1, retdest + POP + // stack: y0, x1, y1, retdest + POP + // stack: x1, y1, retdest + POP + // stack: y1, retdest + POP + // stack: retdest + JUMP + +ec_add_valid_points: + JUMPDEST + // stack: x0, y0, x1, y1, retdest + DUP3 + // stack: x1, x0, y0, x1, y1, retdest + DUP2 + // stack: x0, x1, x0, y0, x1, y1, retdest + EQ + // stack: x0 == x1, x0, y0, x1, y1, retdest + PUSH ec_add_equal_first_coord + // stack: ec_add_equal_first_coord, x0 == x1, x0, y0, x1, y1, retdest + JUMPI + // stack: x0, y0, x1, y1, retdest + PUSH ec_add_valid_points_contd + // stack: ec_add_valid_points_contd, x0, y0, x1, y1, retdest + DUP5 + // stack: y1, ec_add_valid_points_contd, x0, y0, x1, y1, retdest + DUP4 + // stack: y0, y1, ec_add_valid_points_contd, x0, y0, x1, y1, retdest + PUSH submod + // stack: submod, y0, y1, ec_add_valid_points_contd, x0, y0, x1, y1, retdest + JUMP + +ec_add_valid_points_contd: + JUMPDEST + // stack: (y0 - y1) % N, x0, y0, x1, y1, retdest + PUSH ec_add_valid_points_contd2 + // stack: ec_add_valid_points_contd2, (y0 - y1) % N, x0, y0, x1, y1, retdest + DUP5 + // stack: x1, ec_add_valid_points_contd2, (y0 - y1) % N, x0, y0, x1, y1, retdest + DUP4 + // stack: x0, x1, ec_add_valid_points_contd2, (y0 - y1) % N, x0, y0, x1, y1, retdest + PUSH submod + // stack: submod, x0, x1, ec_add_valid_points_contd2, (y0 - y1) % N, x0, y0, x1, y1, retdest + JUMP + +ec_add_valid_points_contd2: + JUMPDEST + // stack: (x0 - x1) % N, (y0 - y1) % N, x0, y0, x1, y1, retdest + //MODDIV // TODO: Implement this + // stack: lambda, x0, y0, x1, y1, retdest + PUSH ec_add_valid_points_with_lambda + // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest + JUMP + +ec_add_valid_points_with_lambda: + JUMPDEST + // stack: lambda, x0, y0, x1, y1, retdest + PUSH ec_add_valid_points_contd4 + // stack: ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + DUP3 + // stack: x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + PUSH ec_add_valid_points_contd3 + // stack: ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + DUP7 + // stack: x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + DUP6 + // stack: lambda, N, x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + DUP1 + // stack: lambda, lambda, N, x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + MULMOD + // stack: lambda^2, x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + PUSH submod + // stack: submod, lambda^2, x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + JUMP + +ec_add_valid_points_contd3: + JUMPDEST + // stack: lambda^2 - x1, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + PUSH submod + // stack: submod, lambda^2 - x1, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest + JUMP + +ec_add_valid_points_contd4: + JUMPDEST + // stack: x2, lambda, x0, y0, x1, y1, retdest + PUSH ec_add_valid_points_contd6 + // stack: ec_add_valid_points_contd6, x2, lambda, x0, y0, x1, y1, retdest + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, ec_add_valid_points_contd6, x2, lambda, x0, y0, x1, y1, retdest + PUSH ec_add_valid_points_contd5 + // stack: ec_add_valid_points_contd5, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, x1, y1, retdest + DUP4 + // stack: x2, ec_add_valid_points_contd5, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, x1, y1, retdest + SWAP8 + // stack: x1, x2, ec_add_valid_points_contd5, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + PUSH submod + // stack: submod, x1, x2, ec_add_valid_points_contd5, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + JUMP + +ec_add_valid_points_contd5: + JUMPDEST + // stack: x1 - x2, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + DUP5 + // stack: lambda, x1 - x2, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + MULMOD + // stack: lambda * (x1 - x2), ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + DUP7 + // stack: y1, lambda * (x1 - x2), ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + SWAP1 + // stack: lambda * (x1 - x2), y1, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + PUSH submod + // stack: submod, lambda * (x1 - x2), y1, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + JUMP + +ec_add_valid_points_contd6: + JUMPDEST + // stack: y2, x2, x0, y0, y1, retdest + SWAP4 + // stack: y1, x2, x0, y0, y2, retdest + POP + // stack: x2, x0, y0, y2, retdest + SWAP2 + // stack: y0, x0, x2, y2, retdest + POP + // stack: x0, x2, y2, retdest + POP + // stack: x2, y2, retdest + SWAP1 + // stack: y2, x2, retdest + SWAP2 + // stack: retdest, x2, y2 + JUMP + +ec_add_equal_first_coord: + JUMPDEST + // stack: x0, y0, x1, y1, retdest with x0 == x1 + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, x0, y0, x1, y1, retdest + DUP3 + // stack: y0, N, x0, y0, x1, y1, retdest + DUP6 + // stack: y1, y0, N, x0, y0, x1, y1, retdest + ADDMOD + // stack: y1 + y0, x0, y0, x1, y1, retdest + ISZERO + // stack: y1 + y0 == 0, x0, y0, x1, y1, retdest + PUSH ec_add_equal + // stack: ec_add_equal, y1 + y0 == 0, x0, y0, x1, y1, retdest + JUMPI + // stack: x0, y0, x1, y1, retdest + POP + // stack: y0, x1, y1, retdest + POP + // stack: x1, y1, retdest + POP + // stack: y1, retdest + POP + // stack: retdest + PUSH 0 + // stack: 0, retdest + PUSH 0 + // stack: 0, 0, retdest + SWAP2 + // stack: retdest, 0, 0 + JUMP + + +ec_add_equal: + JUMPDEST + // stack: x0, y0, x1, y1, retdest + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, x0, y0, x1, y1, retdest + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, N, x0, y0, x1, y1, retdest + DUP3 + // stack: x0, N, N, x0, y0, x1, y1, retdest + DUP1 + // stack: x0, x0, N, N, x0, y0, x1, y1, retdest + MULMOD + // stack: x0^2, N, x0, y0, x1, y1, retdest with + PUSH 0x183227397098d014dc2822db40c0ac2ecbc0b548b438e5469e10460b6c3e7ea5 // 3/2 in the base field + // stack: 3/2, x0^2, N, x0, y0, x1, y1, retdest + MULMOD + // stack: 3/2 * x0^2, x0, y0, x1, y1, retdest + DUP3 + // stack: y0, 3/2 * x0^2, x0, y0, x1, y1, retdest + //MODDIV // TODO: Implement this + // stack: lambda, x0, y0, x1, y1, retdest + PUSH ec_add_valid_points_with_lambda + // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest + JUMP + +submod: + JUMPDEST + // stack: x, y, retdest + SWAP1 + // stack: y, x, retdest + DUP1 + // stack: y, y, x, retdest + DUP3 + // stack: x, y, y, x, retdest + LT + // stack: x < y, y, x, retdest + PUSH submod + // stack: submod, x < y, y, x, retdest + JUMPI + // stack: y, x, retdest + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, y, x, retdest + SWAP2 + // stack: x, y, N, retdest + SUB + // stack: x - y, N, retdest, + MOD + // stack: (x - y) % N, retdest + SWAP1 + // stack: retdest, (x - y) % N + JUMP + +%macro ec_check + // stack: x0, y0 + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, x0, y0 + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, N, x0, y0 + SWAP2 + // stack: x0, N, N, y0 + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, x0, N, N, y0 + DUP2 + // stack: x0, N, x0, N, N, y0 + DUP1 + // stack: x0, x0, N, x0, N, N, y0 + MULMOD + // stack: x0^2 % N, x0, N, N, y0 + MULMOD + // stack: x0^3 % N, N, y0 + PUSH 3 + // stack: 3, x0^3 % N, N, y0 + ADDMOD + // stack: (x0^3 + 3) % N, y0 + SWAP1 + // stack: y0, (x0^3 + 3) % N + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, y0, (x0^3 + 3) % N + SWAP1 + // stack: y0, N, (x0^3 + 3) % N + DUP1 + // stack: y0, y0, N, (x0^3 + 3) % N + MULMOD + // stack: y0^2 % N, (x0^3 + 3) % N + EQ + // stack: y0^2 % N == (x0^3 + 3) % N +%endmacro + diff --git a/evm/src/cpu/kernel/ast.rs b/evm/src/cpu/kernel/ast.rs index cdb38018..8cf97879 100644 --- a/evm/src/cpu/kernel/ast.rs +++ b/evm/src/cpu/kernel/ast.rs @@ -40,7 +40,11 @@ pub(crate) enum Literal { impl Literal { pub(crate) fn to_trimmed_be_bytes(&self) -> Vec { let u256 = self.to_u256(); - let num_bytes = ceil_div_usize(u256.bits(), 8); + let num_bytes = if u256.is_zero() { + 1 // Hacky + } else { + ceil_div_usize(u256.bits(), 8) + }; // `byte` is little-endian, so we manually reverse it. (0..num_bytes).rev().map(|i| u256.byte(i)).collect() } From 683efc0d7422e8b140fdef869948fe31996823ab Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 10:45:26 +0200 Subject: [PATCH 02/18] Impl double --- evm/src/cpu/kernel/asm/curve_add.asm | 32 ++++++++++++++++++++-------- 1 file changed, 23 insertions(+), 9 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index bab709e3..a542eddf 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -1,15 +1,19 @@ // #define N 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // BN254 base field order global ecadd: + PUSH 2 + PUSH 1 + PUSH 2 + PUSH 1 JUMPDEST // stack: x0, y0, x1, y1, retdest - DUP3 + DUP4 // stack: y1, x0, y0, x1, y1, retdest - DUP3 + DUP4 // stack: x1, y1, x0, y0, x1, y1, retdest - DUP3 + DUP4 // stack: y0, x1, y1, x0, y0, x1, y1, retdest - DUP3 + DUP4 // stack: x0, y0, x1, y1, x0, y0, x1, y1, retdest %ec_check // stack: isValid(x0, y0), x1, y1, x0, y0, x1, y1, retdest @@ -188,10 +192,8 @@ ec_add_equal_first_coord: // stack: y1, y0, N, x0, y0, x1, y1, retdest ADDMOD // stack: y1 + y0, x0, y0, x1, y1, retdest - ISZERO - // stack: y1 + y0 == 0, x0, y0, x1, y1, retdest - PUSH ec_add_equal - // stack: ec_add_equal, y1 + y0 == 0, x0, y0, x1, y1, retdest + PUSH ec_add_equal_points + // stack: ec_add_equal_points, y1 + y0, x0, y0, x1, y1, retdest JUMPI // stack: x0, y0, x1, y1, retdest POP @@ -211,7 +213,8 @@ ec_add_equal_first_coord: JUMP -ec_add_equal: +// Assumption: x0 == x1 and y0 == y1 +ec_add_equal_points: JUMPDEST // stack: x0, y0, x1, y1, retdest PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 @@ -236,6 +239,17 @@ ec_add_equal: // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest JUMP +ec_double: + JUMPDEST + // stack: x0, y0, retdest + DUP2 + // stack: y0, x0, y0, retdest + DUP2 + // stack: x0, y0, x0, y0, retdest + PUSH ec_add_equal_points + // stack: ec_add_equal_points, x0, y0, x0, y0, retdest + JUMP + submod: JUMPDEST // stack: x, y, retdest From 6db8539bc8acc2b1d3a4b5b94cb086257eb23769 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 10:46:07 +0200 Subject: [PATCH 03/18] Minor --- evm/src/cpu/kernel/asm/curve_add.asm | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index a542eddf..329d8250 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -1,6 +1,6 @@ // #define N 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // BN254 base field order -global ecadd: +global ec_add: PUSH 2 PUSH 1 PUSH 2 @@ -239,7 +239,7 @@ ec_add_equal_points: // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest JUMP -ec_double: +global ec_double: JUMPDEST // stack: x0, y0, retdest DUP2 From 4cdbb8c1a9ae2b4b25bc18e98ccab77621b16c59 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 10:47:29 +0200 Subject: [PATCH 04/18] Minor --- evm/src/cpu/kernel/asm/curve_mul.asm | 0 1 file changed, 0 insertions(+), 0 deletions(-) create mode 100644 evm/src/cpu/kernel/asm/curve_mul.asm diff --git a/evm/src/cpu/kernel/asm/curve_mul.asm b/evm/src/cpu/kernel/asm/curve_mul.asm new file mode 100644 index 00000000..e69de29b From a5988d6c269cf5ad4f7b33e59c7b002ee93078ce Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 11:09:25 +0200 Subject: [PATCH 05/18] Simplify --- evm/src/cpu/kernel/asm/curve_add.asm | 156 +++++++++------------------ evm/src/cpu/kernel/asm/curve_mul.asm | 3 + 2 files changed, 56 insertions(+), 103 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index 329d8250..f2a57277 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -36,6 +36,7 @@ global ec_add: JUMP +// Assumption: (x0,y0) is a valid point. ec_add_valid_first_point: JUMPDEST // stack: x1, y1, x0, y0, x1, y1, retdest @@ -55,6 +56,7 @@ ec_add_valid_first_point: // stack: retdest JUMP +// Assumption: (x0,y0) and (x1,y1) are valid points. ec_add_valid_points: JUMPDEST // stack: x0, y0, x1, y1, retdest @@ -68,32 +70,18 @@ ec_add_valid_points: // stack: ec_add_equal_first_coord, x0 == x1, x0, y0, x1, y1, retdest JUMPI // stack: x0, y0, x1, y1, retdest - PUSH ec_add_valid_points_contd - // stack: ec_add_valid_points_contd, x0, y0, x1, y1, retdest - DUP5 - // stack: y1, ec_add_valid_points_contd, x0, y0, x1, y1, retdest DUP4 - // stack: y0, y1, ec_add_valid_points_contd, x0, y0, x1, y1, retdest - PUSH submod - // stack: submod, y0, y1, ec_add_valid_points_contd, x0, y0, x1, y1, retdest - JUMP - -ec_add_valid_points_contd: - JUMPDEST - // stack: (y0 - y1) % N, x0, y0, x1, y1, retdest - PUSH ec_add_valid_points_contd2 - // stack: ec_add_valid_points_contd2, (y0 - y1) % N, x0, y0, x1, y1, retdest - DUP5 - // stack: x1, ec_add_valid_points_contd2, (y0 - y1) % N, x0, y0, x1, y1, retdest + // stack: y1, x0, y0, x1, y1, retdest + DUP3 + // stack: y0, y1, x0, y0, x1, y1, retdest + %submod + // stack: y0 - y1, x0, y0, x1, y1, retdest DUP4 - // stack: x0, x1, ec_add_valid_points_contd2, (y0 - y1) % N, x0, y0, x1, y1, retdest - PUSH submod - // stack: submod, x0, x1, ec_add_valid_points_contd2, (y0 - y1) % N, x0, y0, x1, y1, retdest - JUMP - -ec_add_valid_points_contd2: - JUMPDEST - // stack: (x0 - x1) % N, (y0 - y1) % N, x0, y0, x1, y1, retdest + // stack: x1, y0 - y1, x0, y0, x1, y1, retdest + DUP3 + // stack: x0, x1, y0 - y1, x0, y0, x1, y1, retdest + %submod + // stack: x0 - x1, y0 - y1, x0, y0, x1, y1, retdest //MODDIV // TODO: Implement this // stack: lambda, x0, y0, x1, y1, retdest PUSH ec_add_valid_points_with_lambda @@ -103,67 +91,39 @@ ec_add_valid_points_contd2: ec_add_valid_points_with_lambda: JUMPDEST // stack: lambda, x0, y0, x1, y1, retdest - PUSH ec_add_valid_points_contd4 - // stack: ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - DUP3 - // stack: x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - PUSH ec_add_valid_points_contd3 - // stack: ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - DUP7 - // stack: x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - DUP6 - // stack: lambda, N, x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - DUP1 - // stack: lambda, lambda, N, x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - MULMOD - // stack: lambda^2, x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - PUSH submod - // stack: submod, lambda^2, x1, ec_add_valid_points_contd3, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - JUMP - -ec_add_valid_points_contd3: - JUMPDEST - // stack: lambda^2 - x1, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - PUSH submod - // stack: submod, lambda^2 - x1, x0, ec_add_valid_points_contd4, lambda, x0, y0, x1, y1, retdest - JUMP - -ec_add_valid_points_contd4: - JUMPDEST - // stack: x2, lambda, x0, y0, x1, y1, retdest - PUSH ec_add_valid_points_contd6 - // stack: ec_add_valid_points_contd6, x2, lambda, x0, y0, x1, y1, retdest - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, ec_add_valid_points_contd6, x2, lambda, x0, y0, x1, y1, retdest - PUSH ec_add_valid_points_contd5 - // stack: ec_add_valid_points_contd5, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, x1, y1, retdest - DUP4 - // stack: x2, ec_add_valid_points_contd5, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, x1, y1, retdest - SWAP8 - // stack: x1, x2, ec_add_valid_points_contd5, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest - PUSH submod - // stack: submod, x1, x2, ec_add_valid_points_contd5, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest - JUMP - -ec_add_valid_points_contd5: - JUMPDEST - // stack: x1 - x2, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + DUP2 + // stack: x0, lambda, x0, y0, x1, y1, retdest DUP5 - // stack: lambda, x1 - x2, N, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + // stack: x1, x0, lambda, x0, y0, x1, y1, retdest + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, x1, x0, lambda, x0, y0, x1, y1, retdest + DUP4 + // stack: lambda, N, x1, x0, lambda, x0, y0, x1, y1, retdest + DUP1 + // stack: lambda, lambda, N, x1, x0, lambda, x0, y0, x1, y1, retdest MULMOD - // stack: lambda * (x1 - x2), ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest - DUP7 - // stack: y1, lambda * (x1 - x2), ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + // stack: lambda^2, x1, x0, lambda, x0, y0, x1, y1, retdest + %submod + // stack: lambda^2 - x1, x0, lambda, x0, y0, x1, y1, retdest + %submod + // stack: x2, lambda, x0, y0, x1, y1, retdest + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, x2, lambda, x0, y0, x1, y1, retdest + DUP2 + // stack: x2, N, x2, lambda, x0, y0, x1, y1, retdest + SWAP6 + // stack: x1, x2, N, x2, lambda, x0, y0, y1, retdest + %submod + // stack: x1 - x2, N, x2, lambda, x0, y0, y1, retdest + DUP4 + // stack: lambda, x1 - x2, N, x2, lambda, x0, y0, y1, retdest + MULMOD + // stack: lambda * (x1 - x2), x2, lambda, x0, y0, y1, retdest + DUP6 + // stack: y1, lambda * (x1 - x2), x2, lambda, x0, y0, y1, retdest SWAP1 // stack: lambda * (x1 - x2), y1, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest - PUSH submod - // stack: submod, lambda * (x1 - x2), y1, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest - JUMP - -ec_add_valid_points_contd6: - JUMPDEST + %submod // stack: y2, x2, x0, y0, y1, retdest SWAP4 // stack: y1, x2, x0, y0, y2, retdest @@ -250,32 +210,22 @@ global ec_double: // stack: ec_add_equal_points, x0, y0, x0, y0, retdest JUMP -submod: +%macro submod JUMPDEST - // stack: x, y, retdest - SWAP1 - // stack: y, x, retdest - DUP1 - // stack: y, y, x, retdest - DUP3 - // stack: x, y, y, x, retdest - LT - // stack: x < y, y, x, retdest - PUSH submod - // stack: submod, x < y, y, x, retdest - JUMPI - // stack: y, x, retdest + // stack: x, y PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, y, x, retdest - SWAP2 - // stack: x, y, N, retdest + // stack: N, x, y + ADD + // stack: N + x, y // Doesn't overflow since 2N < 2^256 SUB - // stack: x - y, N, retdest, - MOD - // stack: (x - y) % N, retdest + // stack: N + x - y // Doesn't underflow since y < N + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, N + x - y SWAP1 - // stack: retdest, (x - y) % N - JUMP + // stack: N + x - y, N + MOD + // stack: (N + x - y) % N = (x-y) % N +%endmacro %macro ec_check // stack: x0, y0 diff --git a/evm/src/cpu/kernel/asm/curve_mul.asm b/evm/src/cpu/kernel/asm/curve_mul.asm index e69de29b..11cc4c25 100644 --- a/evm/src/cpu/kernel/asm/curve_mul.asm +++ b/evm/src/cpu/kernel/asm/curve_mul.asm @@ -0,0 +1,3 @@ +global ec_mul: + JUMPDEST + // stack: x, y, s, retdest From 4d376857445ce9c3af8864bc8253771db2dbae97 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 11:12:56 +0200 Subject: [PATCH 06/18] Comment --- evm/src/cpu/kernel/asm/curve_add.asm | 2 ++ 1 file changed, 2 insertions(+) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index f2a57277..271c556c 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -210,6 +210,8 @@ global ec_double: // stack: ec_add_equal_points, x0, y0, x0, y0, retdest JUMP +// Assumption: x, y < N and 2N < 2^256. +// Note: Doesn't hold for Secp256k1 base field. %macro submod JUMPDEST // stack: x, y From 8a44c557c555f692d971a84abb4e4a46cfce0c82 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 12:11:35 +0200 Subject: [PATCH 07/18] Curve mul assembly --- evm/src/cpu/kernel/asm/curve_add.asm | 3 +- evm/src/cpu/kernel/asm/curve_mul.asm | 112 +++++++++++++++++++++++++++ 2 files changed, 114 insertions(+), 1 deletion(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index 271c556c..c585006f 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -57,7 +57,7 @@ ec_add_valid_first_point: JUMP // Assumption: (x0,y0) and (x1,y1) are valid points. -ec_add_valid_points: +global ec_add_valid_points: JUMPDEST // stack: x0, y0, x1, y1, retdest DUP3 @@ -199,6 +199,7 @@ ec_add_equal_points: // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest JUMP +// Assumption: (x0,y0) is a valid point. global ec_double: JUMPDEST // stack: x0, y0, retdest diff --git a/evm/src/cpu/kernel/asm/curve_mul.asm b/evm/src/cpu/kernel/asm/curve_mul.asm index 11cc4c25..cbd606ca 100644 --- a/evm/src/cpu/kernel/asm/curve_mul.asm +++ b/evm/src/cpu/kernel/asm/curve_mul.asm @@ -1,3 +1,115 @@ global ec_mul: JUMPDEST // stack: x, y, s, retdest + DUP2 + // stack: y, x, y, s, retdest + DUP2 + // stack: x, y, x, y, s, retdest + %ec_check + // stack: isValid(x, y), x, y, s, retdest + PUSH ec_mul_valid_point + // stack: ec_mul_valid_point, isValid(x, y), x, y, s, retdest + JUMPI + // stack: x, y, s, retdest + POP + // stack: y, s, retdest + POP + // stack: s, retdest + POP + // stack: retdest + JUMP + +// Same algorithm as `exp` +ec_mul_valid_point: + JUMPDEST + // stack: x, y, s, retdest + DUP3 + // stack: s, x, y, s, retdest + PUSH step_case + // stack: step_case, s, x, y, s, retdest + JUMPI + // stack: x, y, s, retdest + POP + // stack: y, s, retdest + POP + // stack: s, retdest + POP + // stack: retdest + PUSH 0 + // stack: 0, retdest + PUSH 0 + // stack: 0, 0, retdest + SWAP2 + // stack: retdest, 0, 0 + JUMP + +step_case: + JUMPDEST + // stack: x, y, s, retdest + PUSH recursion_return + // stack: recursion_return, x, y, s, retdest + PUSH 2 + // stack: 2, recursion_return, x, y, s, retdest + DUP5 + // stack: s, 2, recursion_return, x, y, s, retdest + DIV + // stack: s / 2, recursion_return, x, y, s, retdest + PUSH step_case_contd + // stack: step_case_contd, s / 2, recursion_return, x, y, s, retdest + DUP5 + // stack: y, step_case_contd, s / 2, recursion_return, x, y, s, retdest + DUP5 + // stack: x, y, step_case_contd, s / 2, recursion_return, x, y, s, retdest + PUSH ec_double + // stack: ec_double, x, y, step_case_contd, s / 2, recursion_return, x, y, s, retdest + JUMP + +// Assumption: 2(x,y) = (x',y') +step_case_contd: + JUMPDEST + // stack: x', y', s / 2, recursion_return, x, y, s, retdest + PUSH ec_mul_valid_point + // stack: ec_mul_valid_point, x', y', s / 2, recursion_return, x, y, s, retdest + JUMP + +recursion_return: + JUMPDEST + // stack: x', y', x, y, s, retdest + SWAP4 + // stack: s, y', x, y, x', retdest + PUSH 1 + // stack: 1, s, y', x, y, x', retdest + AND + // stack: s & 1, y', x, y, x', retdest + SWAP1 + // stack: y', s & 1, x, y, x', retdest + SWAP2 + // stack: x, s & 1, y', y, x', retdest + SWAP3 + // stack: y, s & 1, y', x, x', retdest + SWAP4 + // stack: x', s & 1, y', x, y, retdest + SWAP1 + // stack: s & 1, x', y', x, y, retdest + PUSH odd_scalar + // stack: odd_scalar, s & 1, x', y', x, y, retdest + JUMPI + // stack: x', y', x, y, retdest + SWAP3 + // stack: y, y', x, x', retdest + POP + // stack: y', x, x', retdest + SWAP1 + // stack: x, y', x', retdest + POP + // stack: y', x', retdest + SWAP2 + // stack: retdest, x', y' + JUMP + +odd_scalar: + JUMPDEST + // stack: x', y', x, y, retdest + PUSH ec_add_valid_points + // stack: ec_add_valid_points, x', y', x, y, retdest + JUMP From eed7cde388bd835396e877280d034b19a8ecd700 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 15:01:40 +0200 Subject: [PATCH 08/18] Add moddiv for testing --- evm/src/cpu/kernel/aggregator.rs | 11 +- evm/src/cpu/kernel/asm/curve_add.asm | 6 +- evm/src/cpu/kernel/asm/moddiv.asm | 500 +++++++++++++++++++++++++++ 3 files changed, 510 insertions(+), 7 deletions(-) create mode 100644 evm/src/cpu/kernel/asm/moddiv.asm diff --git a/evm/src/cpu/kernel/aggregator.rs b/evm/src/cpu/kernel/aggregator.rs index 773842f8..83e0eb38 100644 --- a/evm/src/cpu/kernel/aggregator.rs +++ b/evm/src/cpu/kernel/aggregator.rs @@ -9,10 +9,12 @@ use crate::cpu::kernel::parser::parse; pub(crate) fn combined_kernel() -> Kernel { let files = vec![ include_str!("asm/basic_macros.asm"), - include_str!("asm/exp.asm"), + // include_str!("asm/exp.asm"), include_str!("asm/curve_add.asm"), - include_str!("asm/storage_read.asm"), - include_str!("asm/storage_write.asm"), + // include_str!("asm/curve_mul.asm"), + include_str!("asm/moddiv.asm"), + // include_str!("asm/storage_read.asm"), + // include_str!("asm/storage_write.asm"), ]; let parsed_files = files.iter().map(|f| parse(f)).collect_vec(); @@ -26,6 +28,7 @@ mod tests { #[test] fn make_kernel() { // Make sure we can parse and assemble the entire kernel. - combined_kernel(); + let ker = combined_kernel(); + println!("{:?}", ker.code) } } diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index c585006f..2ee08d65 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -82,7 +82,7 @@ global ec_add_valid_points: // stack: x0, x1, y0 - y1, x0, y0, x1, y1, retdest %submod // stack: x0 - x1, y0 - y1, x0, y0, x1, y1, retdest - //MODDIV // TODO: Implement this + %moddiv // stack: lambda, x0, y0, x1, y1, retdest PUSH ec_add_valid_points_with_lambda // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest @@ -193,14 +193,14 @@ ec_add_equal_points: // stack: 3/2 * x0^2, x0, y0, x1, y1, retdest DUP3 // stack: y0, 3/2 * x0^2, x0, y0, x1, y1, retdest - //MODDIV // TODO: Implement this + %moddiv // stack: lambda, x0, y0, x1, y1, retdest PUSH ec_add_valid_points_with_lambda // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest JUMP -// Assumption: (x0,y0) is a valid point. global ec_double: +// Assumption: (x0,y0) is a valid point. JUMPDEST // stack: x0, y0, retdest DUP2 diff --git a/evm/src/cpu/kernel/asm/moddiv.asm b/evm/src/cpu/kernel/asm/moddiv.asm new file mode 100644 index 00000000..f1c025de --- /dev/null +++ b/evm/src/cpu/kernel/asm/moddiv.asm @@ -0,0 +1,500 @@ +/// Division modulo 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47, the BN254 base field order +/// To replace with more efficient method using non-determinism later. + +// Returns y * (x^-1) where the inverse is taken modulo N +%macro moddiv + // stack: x, y + %inverse + // stack: x^-1, y + %mulmodn +%endmacro + +%macro mulmodn + // stack: x, y + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, x, y + SWAP2 + // stack: y, x, N + MULMOD +%endmacro + +%macro squaremodn + // stack: x + DUP1 + // stack: x, x + %mulmodn +%endmacro + +%macro inverse + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + %squaremodn + %squaremodn + DUP2 + %mulmodn + %squaremodn + %squaremodn + DUP2 + %mulmodn +%endmacro From 7364248e60c2ffca84714fbc2c5274c86b92adb4 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 15:43:41 +0200 Subject: [PATCH 09/18] Fixes --- evm/src/cpu/kernel/asm/curve_add.asm | 37 ++++++++++++++-------------- evm/src/cpu/kernel/asm/moddiv.asm | 5 ++++ 2 files changed, 23 insertions(+), 19 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index 2ee08d65..92541284 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -1,8 +1,8 @@ // #define N 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // BN254 base field order global ec_add: - PUSH 2 - PUSH 1 + PUSH 0x1bf9384aa3f0b3ad763aee81940cacdde1af71617c06f46e11510f14f3d5d121 + PUSH 0xe7313274bb29566ff0c8220eb9841de1d96c2923c6a4028f7dd3c6a14cee770 PUSH 2 PUSH 1 JUMPDEST @@ -111,31 +111,31 @@ ec_add_valid_points_with_lambda: // stack: N, x2, lambda, x0, y0, x1, y1, retdest DUP2 // stack: x2, N, x2, lambda, x0, y0, x1, y1, retdest - SWAP6 - // stack: x1, x2, N, x2, lambda, x0, y0, y1, retdest + DUP7 + // stack: x1, x2, N, x2, lambda, x0, y0, x1, y1, retdest %submod - // stack: x1 - x2, N, x2, lambda, x0, y0, y1, retdest + // stack: x1 - x2, N, x2, lambda, x0, y0, x1, y1, retdest DUP4 - // stack: lambda, x1 - x2, N, x2, lambda, x0, y0, y1, retdest + // stack: lambda, x1 - x2, N, x2, lambda, x0, y0, x1, y1, retdest MULMOD - // stack: lambda * (x1 - x2), x2, lambda, x0, y0, y1, retdest - DUP6 - // stack: y1, lambda * (x1 - x2), x2, lambda, x0, y0, y1, retdest + // stack: lambda * (x1 - x2), x2, lambda, x0, y0, x1, y1, retdest + DUP7 + // stack: y1, lambda * (x1 - x2), x2, lambda, x0, y0, x1, y1, retdest SWAP1 - // stack: lambda * (x1 - x2), y1, ec_add_valid_points_contd6, x2, lambda, x0, y0, y1, retdest + // stack: lambda * (x1 - x2), y1, x2, lambda, x0, y0, x1, y1, retdest %submod - // stack: y2, x2, x0, y0, y1, retdest + // stack: y2, x2, x0, y0, x1, y1, retdest SWAP4 - // stack: y1, x2, x0, y0, y2, retdest + // stack: x1, x2, x0, y0, y2, y1, retdest POP - // stack: x2, x0, y0, y2, retdest - SWAP2 - // stack: y0, x0, x2, y2, retdest + // stack: x2, x0, y0, y2, y1, retdest + SWAP4 + // stack: y1, x0, y0, y2, x2, retdest POP - // stack: x0, x2, y2, retdest + // stack: x0, y0, y2, x2, retdest + POP + // stack: y0, y2, x2, retdest POP - // stack: x2, y2, retdest - SWAP1 // stack: y2, x2, retdest SWAP2 // stack: retdest, x2, y2 @@ -265,4 +265,3 @@ global ec_double: EQ // stack: y0^2 % N == (x0^3 + 3) % N %endmacro - diff --git a/evm/src/cpu/kernel/asm/moddiv.asm b/evm/src/cpu/kernel/asm/moddiv.asm index f1c025de..2dd28fa7 100644 --- a/evm/src/cpu/kernel/asm/moddiv.asm +++ b/evm/src/cpu/kernel/asm/moddiv.asm @@ -26,6 +26,7 @@ %endmacro %macro inverse + DUP1 %squaremodn DUP2 %mulmodn @@ -497,4 +498,8 @@ %squaremodn DUP2 %mulmodn + SWAP1 + // stack: x, x^-1 + POP + // stack: x^-1 %endmacro From 8e711d413a63ec700f8aa3a3ba3e4166ff5e8881 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 16:41:28 +0200 Subject: [PATCH 10/18] Minor --- evm/src/cpu/kernel/asm/curve_add.asm | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index 92541284..b200817a 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -199,8 +199,8 @@ ec_add_equal_points: // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest JUMP -global ec_double: // Assumption: (x0,y0) is a valid point. +global ec_double: JUMPDEST // stack: x0, y0, retdest DUP2 @@ -214,7 +214,6 @@ global ec_double: // Assumption: x, y < N and 2N < 2^256. // Note: Doesn't hold for Secp256k1 base field. %macro submod - JUMPDEST // stack: x, y PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // stack: N, x, y From fd1d9fe85e696111fee60c694a51315da46589bf Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 17:37:34 +0200 Subject: [PATCH 11/18] Add range check --- evm/src/cpu/kernel/asm/curve_add.asm | 72 ++++++++++++++++++---------- 1 file changed, 46 insertions(+), 26 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index b200817a..0c256b3e 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -1,8 +1,8 @@ // #define N 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // BN254 base field order global ec_add: - PUSH 0x1bf9384aa3f0b3ad763aee81940cacdde1af71617c06f46e11510f14f3d5d121 - PUSH 0xe7313274bb29566ff0c8220eb9841de1d96c2923c6a4028f7dd3c6a14cee770 + PUSH 0 + PUSH 0 PUSH 2 PUSH 1 JUMPDEST @@ -233,34 +233,54 @@ global ec_double: // stack: x0, y0 PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // stack: N, x0, y0 - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, N, x0, y0 - SWAP2 - // stack: x0, N, N, y0 - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, x0, N, N, y0 DUP2 - // stack: x0, N, x0, N, N, y0 - DUP1 - // stack: x0, x0, N, x0, N, N, y0 - MULMOD - // stack: x0^2 % N, x0, N, N, y0 - MULMOD - // stack: x0^3 % N, N, y0 - PUSH 3 - // stack: 3, x0^3 % N, N, y0 - ADDMOD - // stack: (x0^3 + 3) % N, y0 - SWAP1 - // stack: y0, (x0^3 + 3) % N + // stack: x0, N, x0, y0 + LT + // stack: x0 < N, x0, y0 PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, y0, (x0^3 + 3) % N + // stack: N, x0 < N, x0, y0 + DUP4 + // stack: y0, N, x0 < N, x0, y0 + LT + // stack: y0 < N, x0 < N, x0, y0 + AND + // stack: (y0 < N) & (x0 < N), x0, y0 + SWAP2 + // stack: y0, x0, (y0 < N) & (x0 < N), x0 SWAP1 - // stack: y0, N, (x0^3 + 3) % N + // stack: x0, y0, (y0 < N) & (x0 < N) + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, x0, y0, b + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, N, x0, y0, b + SWAP2 + // stack: x0, N, N, y0, b + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, x0, N, N, y0, b + DUP2 + // stack: x0, N, x0, N, N, y0, b DUP1 - // stack: y0, y0, N, (x0^3 + 3) % N + // stack: x0, x0, N, x0, N, N, y0, b MULMOD - // stack: y0^2 % N, (x0^3 + 3) % N + // stack: x0^2 % N, x0, N, N, y0, b + MULMOD + // stack: x0^3 % N, N, y0, b + PUSH 3 + // stack: 3, x0^3 % N, N, y0, b + ADDMOD + // stack: (x0^3 + 3) % N, y0, b + SWAP1 + // stack: y0, (x0^3 + 3) % N, b + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + // stack: N, y0, (x0^3 + 3) % N, b + SWAP1 + // stack: y0, N, (x0^3 + 3) % N, b + DUP1 + // stack: y0, y0, N, (x0^3 + 3) % N, b + MULMOD + // stack: y0^2 % N, (x0^3 + 3) % N, b EQ - // stack: y0^2 % N == (x0^3 + 3) % N + // stack: y0^2 % N == (x0^3 + 3) % N, b + AND + // stack: y0^2 % N == (x0^3 + 3) % N & (x < N) & (y < N) %endmacro From 9e90d7d115b8889057ce07d04d6507b623230a52 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 20:27:55 +0200 Subject: [PATCH 12/18] Add check for zero point --- evm/src/cpu/kernel/asm/curve_add.asm | 130 ++++++++++++++++++++++++++- 1 file changed, 128 insertions(+), 2 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index 0c256b3e..dff74a5f 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -1,12 +1,44 @@ // #define N 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // BN254 base field order global ec_add: - PUSH 0 - PUSH 0 PUSH 2 PUSH 1 + PUSH 0 + PUSH 0 JUMPDEST // stack: x0, y0, x1, y1, retdest + DUP2 + // stack: y0, x0, y0, x1, y1, retdest + DUP2 + // stack: x0, y0, x0, y0, x1, y1, retdest + ISZERO + // stack: x0==0, y0, x0, y0, x1, y1, retdest + SWAP1 + // stack: y0, x0==0, x0, y0, x1, y1, retdest + ISZERO + // stack: y0==0, x0==0, x0, y0, x1, y1, retdest + AND + // stack: y0==0 & x0==0, x0, y0, x1, y1, retdest + PUSH ec_add_first_zero + // stack: ec_add_first_zero, y0==0 & x0==0, x0, y0, x1, y1, retdest + JUMPI + // stack: x0, y0, x1, y1, retdest + DUP4 + // stack: y1, x0, y0, x1, y1, retdest + DUP4 + // stack: x1, y1, x0, y0, x1, y1, retdest + ISZERO + // stack: x1==0, y1, x0, y0, x1, y1, retdest + SWAP1 + // stack: y1, x1==0, x0, y0, x1, y1, retdest + ISZERO + // stack: y1==0, x1==0, x0, y0, x1, y1, retdest + AND + // stack: y1==0 & x1==0, x0, y0, x1, y1, retdest + PUSH ec_add_snd_zero + // stack: ec_add_snd_zero, y1==0 & x1==0, x0, y0, x1, y1, retdest + JUMPI + // stack: x0, y0, x1, y1, retdest DUP4 // stack: y1, x0, y0, x1, y1, retdest DUP4 @@ -35,6 +67,100 @@ global ec_add: // stack: retdest JUMP +// Assumption (x0,y0) == (0,0) +ec_add_first_zero: + JUMPDEST + // stack: x0, y0, x1, y1, retdest + POP + // stack: y0, x1, y1, retdest + POP + // stack: x1, y1, retdest + DUP2 + // stack: y1, x1, y1, retdest + DUP2 + // stack: x1, y1, x1, y1, retdest + ISZERO + // stack: x1==0, y1, x1, y1, retdest + SWAP1 + // stack: y1, x1==0, x1, y1, retdest + ISZERO + // stack: y1==0, x1==0, x1, y1, retdest + AND + // stack: y1==0 & x1==0, x1, y1, retdest + PUSH ret_zero + // stack: ret_zero, y1==0 & x1==0, x1, y1, retdest + JUMPI + // stack: x1, y1, retdest + DUP2 + // stack: y1, x1, y1, retdest + DUP2 + // stack: x1, y1, x1, y1, retdest + %ec_check + // stack: isValid(x1, y1), x1, y1, retdest + PUSH ec_noop + // stack: ec_noop, isValid(x1, y1), x1, y1, retdest + JUMPI + // stack: x1, y1, retdest + POP + // stack: y1, retdest + POP + // stack: retdest + JUMP + +// Assumption (x1,y1) == (0,0) and (x0,y0) != (0,0) +ec_add_snd_zero: + JUMPDEST + // stack: x0, y0, x1, y1, retdest + SWAP2 + // stack: x1, y0, x0, y1, retdest + POP + // stack: y0, x0, y1, retdest + SWAP2 + // stack: y1, x0, y0, retdest + POP + // stack: x0, y0, retdest + DUP2 + // stack: y0, x0, y0, retdest + DUP2 + // stack: x0, y0, x0, y0, retdest + %ec_check + // stack: isValid(x0, y0), x0, y0, retdest + PUSH ec_noop + // stack: ec_noop, isValid(x0, y0), x0, y0, retdest + JUMPI + // stack: x0, y0, retdest + POP + // stack: y0, retdest + POP + // stack: retdest + JUMP + +ec_noop: + JUMPDEST + // x, y, retdest + SWAP1 + // y, x, retdest + SWAP2 + // retdest, x, y + JUMP + +ret_zero: + JUMPDEST + // stack: x, y, retdest + POP + // stack: y, retdest + POP + // stack: retdest + PUSH 0 + // stack: 0, retdest + PUSH 0 + // stack: 0, 0, retdest + SWAP2 + // stack: 0, retdest, 0 + SWAP1 + // stack: retdest, 0, 0 + JUMP + // Assumption: (x0,y0) is a valid point. ec_add_valid_first_point: From fb8a67b0d9c0be885e9ee90749da61859e99ea8f Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 21:12:11 +0200 Subject: [PATCH 13/18] Working ecmul --- evm/src/cpu/kernel/aggregator.rs | 2 +- evm/src/cpu/kernel/asm/curve_add.asm | 23 +++++++++++++---------- evm/src/cpu/kernel/asm/curve_mul.asm | 9 +++++++-- 3 files changed, 21 insertions(+), 13 deletions(-) diff --git a/evm/src/cpu/kernel/aggregator.rs b/evm/src/cpu/kernel/aggregator.rs index 83e0eb38..9b8a65c6 100644 --- a/evm/src/cpu/kernel/aggregator.rs +++ b/evm/src/cpu/kernel/aggregator.rs @@ -10,8 +10,8 @@ pub(crate) fn combined_kernel() -> Kernel { let files = vec![ include_str!("asm/basic_macros.asm"), // include_str!("asm/exp.asm"), + include_str!("asm/curve_mul.asm"), include_str!("asm/curve_add.asm"), - // include_str!("asm/curve_mul.asm"), include_str!("asm/moddiv.asm"), // include_str!("asm/storage_read.asm"), // include_str!("asm/storage_write.asm"), diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index dff74a5f..00e88495 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -1,10 +1,10 @@ // #define N 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // BN254 base field order global ec_add: - PUSH 2 - PUSH 1 - PUSH 0 - PUSH 0 + //PUSH 2 + //PUSH 1 + //PUSH 0x1bf9384aa3f0b3ad763aee81940cacdde1af71617c06f46e11510f14f3d5d121 + //PUSH 0xe7313274bb29566ff0c8220eb9841de1d96c2923c6a4028f7dd3c6a14cee770 JUMPDEST // stack: x0, y0, x1, y1, retdest DUP2 @@ -250,13 +250,15 @@ ec_add_valid_points_with_lambda: SWAP1 // stack: lambda * (x1 - x2), y1, x2, lambda, x0, y0, x1, y1, retdest %submod - // stack: y2, x2, x0, y0, x1, y1, retdest - SWAP4 - // stack: x1, x2, x0, y0, y2, y1, retdest + // stack: y2, x2, lambda, x0, y0, x1, y1, retdest + SWAP5 + // stack: x1, x2, lambda, x0, y0, y2, y1, retdest POP - // stack: x2, x0, y0, y2, y1, retdest - SWAP4 - // stack: y1, x0, y0, y2, x2, retdest + // stack: x2, lambda, x0, y0, y2, y1, retdest + SWAP5 + // stack: y1, lambda, x0, y0, y2, x2, retdest + POP + // stack: lambda, x0, y0, y2, x2, retdest POP // stack: x0, y0, y2, x2, retdest POP @@ -267,6 +269,7 @@ ec_add_valid_points_with_lambda: // stack: retdest, x2, y2 JUMP +// Assumption: (x0,y0) and (x1,y1) are valid points and x0 == x1 ec_add_equal_first_coord: JUMPDEST // stack: x0, y0, x1, y1, retdest with x0 == x1 diff --git a/evm/src/cpu/kernel/asm/curve_mul.asm b/evm/src/cpu/kernel/asm/curve_mul.asm index cbd606ca..3a3253e4 100644 --- a/evm/src/cpu/kernel/asm/curve_mul.asm +++ b/evm/src/cpu/kernel/asm/curve_mul.asm @@ -1,4 +1,9 @@ global ec_mul: + // Uncomment for test inputs. + // PUSH 0xdeadbeef + // PUSH 0xd + // PUSH 2 + // PUSH 1 JUMPDEST // stack: x, y, s, retdest DUP2 @@ -110,6 +115,6 @@ recursion_return: odd_scalar: JUMPDEST // stack: x', y', x, y, retdest - PUSH ec_add_valid_points - // stack: ec_add_valid_points, x', y', x, y, retdest + PUSH ec_add + // stack: ec_add, x', y', x, y, retdest JUMP From 8ffd25c1277e74b8ff672f9724cec4b909cc8003 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 21:22:05 +0200 Subject: [PATCH 14/18] Add zero case for mul --- evm/src/cpu/kernel/asm/curve_add.asm | 10 +++++---- evm/src/cpu/kernel/asm/curve_mul.asm | 33 ++++++++++++++++++++++++++++ 2 files changed, 39 insertions(+), 4 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index 00e88495..779f3b7c 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -1,10 +1,12 @@ // #define N 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // BN254 base field order global ec_add: - //PUSH 2 - //PUSH 1 - //PUSH 0x1bf9384aa3f0b3ad763aee81940cacdde1af71617c06f46e11510f14f3d5d121 - //PUSH 0xe7313274bb29566ff0c8220eb9841de1d96c2923c6a4028f7dd3c6a14cee770 + // Uncomment for test inputs. + // PUSH 0xdeadbeef + // PUSH 2 + // PUSH 1 + // PUSH 0x1bf9384aa3f0b3ad763aee81940cacdde1af71617c06f46e11510f14f3d5d121 + // PUSH 0xe7313274bb29566ff0c8220eb9841de1d96c2923c6a4028f7dd3c6a14cee770 JUMPDEST // stack: x0, y0, x1, y1, retdest DUP2 diff --git a/evm/src/cpu/kernel/asm/curve_mul.asm b/evm/src/cpu/kernel/asm/curve_mul.asm index 3a3253e4..bd092571 100644 --- a/evm/src/cpu/kernel/asm/curve_mul.asm +++ b/evm/src/cpu/kernel/asm/curve_mul.asm @@ -10,6 +10,22 @@ global ec_mul: // stack: y, x, y, s, retdest DUP2 // stack: x, y, x, y, s, retdest + ISZERO + // stack: x==0, y, x, y, s, retdest + SWAP1 + // stack: y, x==0, x, y, s, retdest + ISZERO + // stack: y==0, x==0, x, y, s, retdest + AND + // stack: y==0 & x==0, x, y, s, retdest + PUSH ret_zero + // stack: ret_zero, y==0 & x==0, x, y, s, retdest + JUMPI + // stack: x, y, s, retdest + DUP2 + // stack: y, x, y, s, retdest + DUP2 + // stack: x, y, x, y, s, retdest %ec_check // stack: isValid(x, y), x, y, s, retdest PUSH ec_mul_valid_point @@ -118,3 +134,20 @@ odd_scalar: PUSH ec_add // stack: ec_add, x', y', x, y, retdest JUMP + +ret_zero: + JUMPDEST + // stack: x, y, s, retdest + POP + // stack: y, s, retdest + POP + // stack: s, retdest + POP + // stack: retdest + PUSH 0 + // stack: 0, retdest + PUSH 0 + // stack: 0, 0, retdest + SWAP2 + // stack: retdest, 0, 0 + JUMP From 5bae732ea030ba64513c3e3628e75302239b5bbf Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Tue, 5 Jul 2022 21:24:51 +0200 Subject: [PATCH 15/18] Minor --- evm/src/cpu/kernel/aggregator.rs | 9 ++++----- evm/src/cpu/kernel/asm/curve_add.asm | 4 ++-- evm/src/cpu/kernel/asm/curve_mul.asm | 2 +- 3 files changed, 7 insertions(+), 8 deletions(-) diff --git a/evm/src/cpu/kernel/aggregator.rs b/evm/src/cpu/kernel/aggregator.rs index 9b8a65c6..ac0d6f7c 100644 --- a/evm/src/cpu/kernel/aggregator.rs +++ b/evm/src/cpu/kernel/aggregator.rs @@ -9,12 +9,12 @@ use crate::cpu::kernel::parser::parse; pub(crate) fn combined_kernel() -> Kernel { let files = vec![ include_str!("asm/basic_macros.asm"), - // include_str!("asm/exp.asm"), + include_str!("asm/exp.asm"), include_str!("asm/curve_mul.asm"), include_str!("asm/curve_add.asm"), include_str!("asm/moddiv.asm"), - // include_str!("asm/storage_read.asm"), - // include_str!("asm/storage_write.asm"), + include_str!("asm/storage_read.asm"), + include_str!("asm/storage_write.asm"), ]; let parsed_files = files.iter().map(|f| parse(f)).collect_vec(); @@ -28,7 +28,6 @@ mod tests { #[test] fn make_kernel() { // Make sure we can parse and assemble the entire kernel. - let ker = combined_kernel(); - println!("{:?}", ker.code) + combined_kernel(); } } diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index 779f3b7c..0f230159 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -69,7 +69,7 @@ global ec_add: // stack: retdest JUMP -// Assumption (x0,y0) == (0,0) +// Assumption: (x0,y0) == (0,0) ec_add_first_zero: JUMPDEST // stack: x0, y0, x1, y1, retdest @@ -109,7 +109,7 @@ ec_add_first_zero: // stack: retdest JUMP -// Assumption (x1,y1) == (0,0) and (x0,y0) != (0,0) +// Assumption: (x1,y1) == (0,0) and (x0,y0) != (0,0) ec_add_snd_zero: JUMPDEST // stack: x0, y0, x1, y1, retdest diff --git a/evm/src/cpu/kernel/asm/curve_mul.asm b/evm/src/cpu/kernel/asm/curve_mul.asm index bd092571..440ebe8b 100644 --- a/evm/src/cpu/kernel/asm/curve_mul.asm +++ b/evm/src/cpu/kernel/asm/curve_mul.asm @@ -40,7 +40,7 @@ global ec_mul: // stack: retdest JUMP -// Same algorithm as `exp` +// Same algorithm as in `exp.asm` ec_mul_valid_point: JUMPDEST // stack: x, y, s, retdest From 9747343ac2b69ca67725ebae48e72f8b988c0958 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Wed, 6 Jul 2022 09:25:41 +0200 Subject: [PATCH 16/18] PR feedback --- evm/src/cpu/kernel/asm/curve_add.asm | 394 ++++++++++++--------------- evm/src/cpu/kernel/asm/curve_mul.asm | 16 +- 2 files changed, 185 insertions(+), 225 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index 0f230159..6d69fea9 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -13,14 +13,40 @@ global ec_add: // stack: y0, x0, y0, x1, y1, retdest DUP2 // stack: x0, y0, x0, y0, x1, y1, retdest - ISZERO - // stack: x0==0, y0, x0, y0, x1, y1, retdest - SWAP1 - // stack: y0, x0==0, x0, y0, x1, y1, retdest - ISZERO - // stack: y0==0, x0==0, x0, y0, x1, y1, retdest + %ec_check + // stack: isValid(x0, y0), x0, y0, x1, y1, retdest + DUP5 + // stack: x1, isValid(x0, y0), x0, y0, x1, y1, retdest + DUP5 + // stack: x1, y1, isValid(x0, y0), x0, y0, x1, y1, retdest + %ec_check + // stack: isValid(x1, y1), isValid(x0, y0), x0, y0, x1, y1, retdest AND - // stack: y0==0 & x0==0, x0, y0, x1, y1, retdest + // stack: isValid(x1, y1) & isValid(x0, y0), x0, y0, x1, y1, retdest + PUSH ec_add_valid_points + // stack: ec_add_valid_points, isValid(x1, y1) & isValid(x0, y0), x0, y0, x1, y1, retdest + JUMPI + // stack: x0, y0, x1, y1, retdest + POP + // stack: y0, x1, y1, retdest + POP + // stack: x1, y1, retdest + POP + // stack: y1, retdest + POP + // stack: retdest + %ec_invalid_input + +// Assumption: (x0,y0) and (x1,y1) are valid points. +global ec_add_valid_points: + JUMPDEST + // stack: x0, y0, x1, y1, retdest + DUP2 + // stack: y0, x0, y0, x1, y1, retdest + DUP2 + // stack: x0, y0, x0, y0, x1, y1, retdest + %ec_isidentity + // stack: (x0,y0)==(0,0), x0, y0, x1, y1, retdest PUSH ec_add_first_zero // stack: ec_add_first_zero, y0==0 & x0==0, x0, y0, x1, y1, retdest JUMPI @@ -29,165 +55,12 @@ global ec_add: // stack: y1, x0, y0, x1, y1, retdest DUP4 // stack: x1, y1, x0, y0, x1, y1, retdest - ISZERO - // stack: x1==0, y1, x0, y0, x1, y1, retdest - SWAP1 - // stack: y1, x1==0, x0, y0, x1, y1, retdest - ISZERO - // stack: y1==0, x1==0, x0, y0, x1, y1, retdest - AND - // stack: y1==0 & x1==0, x0, y0, x1, y1, retdest + %ec_isidentity + // stack: (x1,y1)==(0,0), x0, y0, x1, y1, retdest PUSH ec_add_snd_zero // stack: ec_add_snd_zero, y1==0 & x1==0, x0, y0, x1, y1, retdest JUMPI // stack: x0, y0, x1, y1, retdest - DUP4 - // stack: y1, x0, y0, x1, y1, retdest - DUP4 - // stack: x1, y1, x0, y0, x1, y1, retdest - DUP4 - // stack: y0, x1, y1, x0, y0, x1, y1, retdest - DUP4 - // stack: x0, y0, x1, y1, x0, y0, x1, y1, retdest - %ec_check - // stack: isValid(x0, y0), x1, y1, x0, y0, x1, y1, retdest - PUSH ec_add_valid_first_point - // stack: ec_add_valid_first_point, isValid(x0, y0), x1, y1, x0, y0, x1, y1, retdest - JUMPI - // stack: x1, y1, x0, y0, x1, y1, retdest - POP - // stack: y1, x0, y0, x1, y1, retdest - POP - // stack: x0, y0, x1, y1, retdest - POP - // stack: y0, x1, y1, retdest - POP - // stack: x1, y1, retdest - POP - // stack: y1, retdest - POP - // stack: retdest - JUMP - -// Assumption: (x0,y0) == (0,0) -ec_add_first_zero: - JUMPDEST - // stack: x0, y0, x1, y1, retdest - POP - // stack: y0, x1, y1, retdest - POP - // stack: x1, y1, retdest - DUP2 - // stack: y1, x1, y1, retdest - DUP2 - // stack: x1, y1, x1, y1, retdest - ISZERO - // stack: x1==0, y1, x1, y1, retdest - SWAP1 - // stack: y1, x1==0, x1, y1, retdest - ISZERO - // stack: y1==0, x1==0, x1, y1, retdest - AND - // stack: y1==0 & x1==0, x1, y1, retdest - PUSH ret_zero - // stack: ret_zero, y1==0 & x1==0, x1, y1, retdest - JUMPI - // stack: x1, y1, retdest - DUP2 - // stack: y1, x1, y1, retdest - DUP2 - // stack: x1, y1, x1, y1, retdest - %ec_check - // stack: isValid(x1, y1), x1, y1, retdest - PUSH ec_noop - // stack: ec_noop, isValid(x1, y1), x1, y1, retdest - JUMPI - // stack: x1, y1, retdest - POP - // stack: y1, retdest - POP - // stack: retdest - JUMP - -// Assumption: (x1,y1) == (0,0) and (x0,y0) != (0,0) -ec_add_snd_zero: - JUMPDEST - // stack: x0, y0, x1, y1, retdest - SWAP2 - // stack: x1, y0, x0, y1, retdest - POP - // stack: y0, x0, y1, retdest - SWAP2 - // stack: y1, x0, y0, retdest - POP - // stack: x0, y0, retdest - DUP2 - // stack: y0, x0, y0, retdest - DUP2 - // stack: x0, y0, x0, y0, retdest - %ec_check - // stack: isValid(x0, y0), x0, y0, retdest - PUSH ec_noop - // stack: ec_noop, isValid(x0, y0), x0, y0, retdest - JUMPI - // stack: x0, y0, retdest - POP - // stack: y0, retdest - POP - // stack: retdest - JUMP - -ec_noop: - JUMPDEST - // x, y, retdest - SWAP1 - // y, x, retdest - SWAP2 - // retdest, x, y - JUMP - -ret_zero: - JUMPDEST - // stack: x, y, retdest - POP - // stack: y, retdest - POP - // stack: retdest - PUSH 0 - // stack: 0, retdest - PUSH 0 - // stack: 0, 0, retdest - SWAP2 - // stack: 0, retdest, 0 - SWAP1 - // stack: retdest, 0, 0 - JUMP - - -// Assumption: (x0,y0) is a valid point. -ec_add_valid_first_point: - JUMPDEST - // stack: x1, y1, x0, y0, x1, y1, retdest - %ec_check - // stack: isValid(x1, y1), x0, y0, x1, y1, retdest - PUSH ec_add_valid_points - // stack: ec_add_valid_points, isValid(x1, y1), x0, y0, x1, y1, retdest - JUMPI - // stack: x0, y0, x1, y1, retdest - POP - // stack: y0, x1, y1, retdest - POP - // stack: x1, y1, retdest - POP - // stack: y1, retdest - POP - // stack: retdest - JUMP - -// Assumption: (x0,y0) and (x1,y1) are valid points. -global ec_add_valid_points: - JUMPDEST - // stack: x0, y0, x1, y1, retdest DUP3 // stack: x1, x0, y0, x1, y1, retdest DUP2 @@ -216,6 +89,63 @@ global ec_add_valid_points: // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest JUMP +// Assumption: (x0,y0) == (0,0) +ec_add_first_zero: + JUMPDEST + // stack: x0, y0, x1, y1, retdest + POP + // stack: y0, x1, y1, retdest + POP + // stack: x1, y1, retdest + DUP2 + // stack: y1, x1, y1, retdest + DUP2 + // stack: x1, y1, x1, y1, retdest + %ec_isidentity + // stack: (x1,y1)==(0,0), x1, y1, retdest + PUSH ret_zero + // stack: ret_zero, (x1,y1)==(0,0), x1, y1, retdest + JUMPI + // stack: x1, y1, retdest + SWAP1 + // stack: y1, x1, retdest + SWAP2 + // stack: retdest, x1, y1 + JUMP + +// Assumption: (x1,y1) == (0,0) and (x0,y0) != (0,0) +ec_add_snd_zero: + JUMPDEST + // stack: x0, y0, x1, y1, retdest + SWAP2 + // stack: x1, y0, x0, y1, retdest + POP + // stack: y0, x0, y1, retdest + SWAP2 + // stack: y1, x0, y0, retdest + POP + // stack: x0, y0, retdest + SWAP1 + // stack: y0, x0, retdest + SWAP2 + // stack: retdest, x0, y0 + JUMP + +ret_zero: + JUMPDEST + // stack: x, y, retdest + POP + // stack: y, retdest + POP + // stack: retdest + PUSH 0 + // stack: 0, retdest + PUSH 0 + // stack: 0, 0, retdest + SWAP2 + // stack: retdest, 0, 0 + JUMP + ec_add_valid_points_with_lambda: JUMPDEST // stack: lambda, x0, y0, x1, y1, retdest @@ -223,7 +153,7 @@ ec_add_valid_points_with_lambda: // stack: x0, lambda, x0, y0, x1, y1, retdest DUP5 // stack: x1, x0, lambda, x0, y0, x1, y1, retdest - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + %bn_base // stack: N, x1, x0, lambda, x0, y0, x1, y1, retdest DUP4 // stack: lambda, N, x1, x0, lambda, x0, y0, x1, y1, retdest @@ -235,7 +165,7 @@ ec_add_valid_points_with_lambda: // stack: lambda^2 - x1, x0, lambda, x0, y0, x1, y1, retdest %submod // stack: x2, lambda, x0, y0, x1, y1, retdest - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + %bn_base // stack: N, x2, lambda, x0, y0, x1, y1, retdest DUP2 // stack: x2, N, x2, lambda, x0, y0, x1, y1, retdest @@ -275,7 +205,7 @@ ec_add_valid_points_with_lambda: ec_add_equal_first_coord: JUMPDEST // stack: x0, y0, x1, y1, retdest with x0 == x1 - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + %bn_base // stack: N, x0, y0, x1, y1, retdest DUP3 // stack: y0, N, x0, y0, x1, y1, retdest @@ -291,16 +221,8 @@ ec_add_equal_first_coord: // stack: y0, x1, y1, retdest POP // stack: x1, y1, retdest - POP - // stack: y1, retdest - POP - // stack: retdest - PUSH 0 - // stack: 0, retdest - PUSH 0 - // stack: 0, 0, retdest - SWAP2 - // stack: retdest, 0, 0 + PUSH ret_zero + // stack: ret_zero, x1, y1, retdest JUMP @@ -308,9 +230,9 @@ ec_add_equal_first_coord: ec_add_equal_points: JUMPDEST // stack: x0, y0, x1, y1, retdest - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + %bn_base // stack: N, x0, y0, x1, y1, retdest - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + %bn_base // stack: N, N, x0, y0, x1, y1, retdest DUP3 // stack: x0, N, N, x0, y0, x1, y1, retdest @@ -342,17 +264,22 @@ global ec_double: // stack: ec_add_equal_points, x0, y0, x0, y0, retdest JUMP +// Push the order of the BN254 base field. +%macro bn_base + PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 +%endmacro + // Assumption: x, y < N and 2N < 2^256. // Note: Doesn't hold for Secp256k1 base field. %macro submod // stack: x, y - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + %bn_base // stack: N, x, y ADD // stack: N + x, y // Doesn't overflow since 2N < 2^256 SUB // stack: N + x - y // Doesn't underflow since y < N - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 + %bn_base // stack: N, N + x - y SWAP1 // stack: N + x - y, N @@ -360,58 +287,97 @@ global ec_double: // stack: (N + x - y) % N = (x-y) % N %endmacro +// Check if (x,y) is a valid curve point. +// Puts y^2 % N == (x^3 + 3) % N & (x < N) & (y < N) || (x,y)==(0,0) on top of the stack. %macro ec_check - // stack: x0, y0 - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, x0, y0 + // stack: x, y + %bn_base + // stack: N, x, y DUP2 - // stack: x0, N, x0, y0 + // stack: x, N, x, y LT - // stack: x0 < N, x0, y0 - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, x0 < N, x0, y0 + // stack: x < N, x, y + %bn_base + // stack: N, x < N, x, y DUP4 - // stack: y0, N, x0 < N, x0, y0 + // stack: y, N, x < N, x, y LT - // stack: y0 < N, x0 < N, x0, y0 + // stack: y < N, x < N, x, y AND - // stack: (y0 < N) & (x0 < N), x0, y0 + // stack: (y < N) & (x < N), x, y SWAP2 - // stack: y0, x0, (y0 < N) & (x0 < N), x0 + // stack: y, x, (y < N) & (x < N), x SWAP1 - // stack: x0, y0, (y0 < N) & (x0 < N) - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, x0, y0, b - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, N, x0, y0, b - SWAP2 - // stack: x0, N, N, y0, b - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, x0, N, N, y0, b + // stack: x, y, (y < N) & (x < N) + %bn_base + // stack: N, x, y, b + %bn_base + // stack: N, N, x, y, b + DUP3 + // stack: x, N, N, x, y, b + %bn_base + // stack: N, x, N, N, x, y, b DUP2 - // stack: x0, N, x0, N, N, y0, b + // stack: x, N, x, N, N, x, y, b DUP1 - // stack: x0, x0, N, x0, N, N, y0, b + // stack: x, x, N, x, N, N, x, y, b MULMOD - // stack: x0^2 % N, x0, N, N, y0, b + // stack: x^2 % N, x, N, N, x, y, b MULMOD - // stack: x0^3 % N, N, y0, b + // stack: x^3 % N, N, x, y, b PUSH 3 - // stack: 3, x0^3 % N, N, y0, b + // stack: 3, x^3 % N, N, x, y, b ADDMOD - // stack: (x0^3 + 3) % N, y0, b + // stack: (x^3 + 3) % N, x, y, b + DUP3 + // stack: y, (x^3 + 3) % N, x, y, b + %bn_base + // stack: N, y, (x^3 + 3) % N, x, y, b SWAP1 - // stack: y0, (x0^3 + 3) % N, b - PUSH 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 - // stack: N, y0, (x0^3 + 3) % N, b - SWAP1 - // stack: y0, N, (x0^3 + 3) % N, b + // stack: y, N, (x^3 + 3) % N, x, y, b DUP1 - // stack: y0, y0, N, (x0^3 + 3) % N, b + // stack: y, y, N, (x^3 + 3) % N, x, y, b MULMOD - // stack: y0^2 % N, (x0^3 + 3) % N, b + // stack: y^2 % N, (x^3 + 3) % N, x, y, b EQ - // stack: y0^2 % N == (x0^3 + 3) % N, b + // stack: y^2 % N == (x^3 + 3) % N, x, y, b + SWAP2 + // stack: y, x, y^2 % N == (x^3 + 3) % N, b + ISZERO + // stack: y==0, x, y^2 % N == (x^3 + 3) % N, b + SWAP1 + // stack: x, y==0, y^2 % N == (x^3 + 3) % N, b + ISZERO + // stack: x==0, y==0, y^2 % N == (x^3 + 3) % N, b AND - // stack: y0^2 % N == (x0^3 + 3) % N & (x < N) & (y < N) + // stack: (x,y)==(0,0), y^2 % N == (x^3 + 3) % N, b + SWAP2 + // stack: b, y^2 % N == (x^3 + 3) % N, (x,y)==(0,0) + AND + // stack: y^2 % N == (x^3 + 3) % N & (x < N) & (y < N), (x,y)==(0,0) + OR + // stack: y^2 % N == (x^3 + 3) % N & (x < N) & (y < N) || (x,y)==(0,0) %endmacro + +%macro ec_isidentity + // stack: x, y + ISZERO + // stack: x==0, y + SWAP1 + // stack: y, x==0 + ISZERO + // stack: y==0, x==0 + AND + // stack: y==0 & x==0 +%endmacro + +%macro ec_invalid_input + // stack: retdest + PUSH 0xffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff + // stack: u256::MAX, retdest + PUSH 0xffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff + // stack: u256::MAX, u256::MAX, retdest + SWAP2 + // stack: retdest, u256::MAX, u256::MAX + JUMP +%endmacro \ No newline at end of file diff --git a/evm/src/cpu/kernel/asm/curve_mul.asm b/evm/src/cpu/kernel/asm/curve_mul.asm index 440ebe8b..52e384d5 100644 --- a/evm/src/cpu/kernel/asm/curve_mul.asm +++ b/evm/src/cpu/kernel/asm/curve_mul.asm @@ -10,14 +10,8 @@ global ec_mul: // stack: y, x, y, s, retdest DUP2 // stack: x, y, x, y, s, retdest - ISZERO - // stack: x==0, y, x, y, s, retdest - SWAP1 - // stack: y, x==0, x, y, s, retdest - ISZERO - // stack: y==0, x==0, x, y, s, retdest - AND - // stack: y==0 & x==0, x, y, s, retdest + %ec_isidentity + // stack: (x,y)==(0,0), x, y, s, retdest PUSH ret_zero // stack: ret_zero, y==0 & x==0, x, y, s, retdest JUMPI @@ -38,7 +32,7 @@ global ec_mul: // stack: s, retdest POP // stack: retdest - JUMP + %ec_invalid_input // Same algorithm as in `exp.asm` ec_mul_valid_point: @@ -131,8 +125,8 @@ recursion_return: odd_scalar: JUMPDEST // stack: x', y', x, y, retdest - PUSH ec_add - // stack: ec_add, x', y', x, y, retdest + PUSH ec_add_valid_points + // stack: ec_add_valid_points, x', y', x, y, retdest JUMP ret_zero: From e2b1e512804a7f494ac633ec482e33babfdece7b Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Wed, 6 Jul 2022 09:40:11 +0200 Subject: [PATCH 17/18] Minor --- evm/src/cpu/kernel/asm/curve_mul.asm | 14 ++------------ 1 file changed, 2 insertions(+), 12 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_mul.asm b/evm/src/cpu/kernel/asm/curve_mul.asm index 52e384d5..ce77e972 100644 --- a/evm/src/cpu/kernel/asm/curve_mul.asm +++ b/evm/src/cpu/kernel/asm/curve_mul.asm @@ -44,18 +44,8 @@ ec_mul_valid_point: // stack: step_case, s, x, y, s, retdest JUMPI // stack: x, y, s, retdest - POP - // stack: y, s, retdest - POP - // stack: s, retdest - POP - // stack: retdest - PUSH 0 - // stack: 0, retdest - PUSH 0 - // stack: 0, 0, retdest - SWAP2 - // stack: retdest, 0, 0 + PUSH ret_zero + // stack: ret_zero, x, y, s, retdest JUMP step_case: From 434615a03c03c36780ffb0cceac8a8baaa058971 Mon Sep 17 00:00:00 2001 From: wborgeaud Date: Thu, 7 Jul 2022 08:26:57 +0200 Subject: [PATCH 18/18] PR feedback + comments --- evm/src/cpu/kernel/asm/curve_add.asm | 120 +++++++++++++++------------ evm/src/cpu/kernel/asm/curve_mul.asm | 2 + evm/src/cpu/kernel/asm/moddiv.asm | 1 + 3 files changed, 70 insertions(+), 53 deletions(-) diff --git a/evm/src/cpu/kernel/asm/curve_add.asm b/evm/src/cpu/kernel/asm/curve_add.asm index 6d69fea9..fdbbf997 100644 --- a/evm/src/cpu/kernel/asm/curve_add.asm +++ b/evm/src/cpu/kernel/asm/curve_add.asm @@ -1,5 +1,7 @@ // #define N 0x30644e72e131a029b85045b68181585d97816a916871ca8d3c208c16d87cfd47 // BN254 base field order +// BN254 elliptic curve addition. +// Uses the standard affine addition formula. global ec_add: // Uncomment for test inputs. // PUSH 0xdeadbeef @@ -9,6 +11,8 @@ global ec_add: // PUSH 0xe7313274bb29566ff0c8220eb9841de1d96c2923c6a4028f7dd3c6a14cee770 JUMPDEST // stack: x0, y0, x1, y1, retdest + + // Check if points are valid BN254 points. DUP2 // stack: y0, x0, y0, x1, y1, retdest DUP2 @@ -27,6 +31,8 @@ global ec_add: // stack: ec_add_valid_points, isValid(x1, y1) & isValid(x0, y0), x0, y0, x1, y1, retdest JUMPI // stack: x0, y0, x1, y1, retdest + + // Otherwise return POP // stack: y0, x1, y1, retdest POP @@ -37,10 +43,13 @@ global ec_add: // stack: retdest %ec_invalid_input +// BN254 elliptic curve addition. // Assumption: (x0,y0) and (x1,y1) are valid points. global ec_add_valid_points: JUMPDEST // stack: x0, y0, x1, y1, retdest + + // Check if the first point is the identity. DUP2 // stack: y0, x0, y0, x1, y1, retdest DUP2 @@ -48,9 +57,11 @@ global ec_add_valid_points: %ec_isidentity // stack: (x0,y0)==(0,0), x0, y0, x1, y1, retdest PUSH ec_add_first_zero - // stack: ec_add_first_zero, y0==0 & x0==0, x0, y0, x1, y1, retdest + // stack: ec_add_first_zero, (x0,y0)==(0,0), x0, y0, x1, y1, retdest JUMPI // stack: x0, y0, x1, y1, retdest + + // Check if the first point is the identity. DUP4 // stack: y1, x0, y0, x1, y1, retdest DUP4 @@ -58,9 +69,11 @@ global ec_add_valid_points: %ec_isidentity // stack: (x1,y1)==(0,0), x0, y0, x1, y1, retdest PUSH ec_add_snd_zero - // stack: ec_add_snd_zero, y1==0 & x1==0, x0, y0, x1, y1, retdest + // stack: ec_add_snd_zero, (x1,y1)==(0,0), x0, y0, x1, y1, retdest JUMPI // stack: x0, y0, x1, y1, retdest + + // Check if both points have the same x-coordinate. DUP3 // stack: x1, x0, y0, x1, y1, retdest DUP2 @@ -71,6 +84,9 @@ global ec_add_valid_points: // stack: ec_add_equal_first_coord, x0 == x1, x0, y0, x1, y1, retdest JUMPI // stack: x0, y0, x1, y1, retdest + + // Otherwise, we can use the standard formula. + // Compute lambda = (y0 - y1)/(x0 - x1) DUP4 // stack: y1, x0, y0, x1, y1, retdest DUP3 @@ -89,34 +105,30 @@ global ec_add_valid_points: // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest JUMP +// BN254 elliptic curve addition. // Assumption: (x0,y0) == (0,0) ec_add_first_zero: JUMPDEST // stack: x0, y0, x1, y1, retdest + + // Just return (x1,y1) POP // stack: y0, x1, y1, retdest POP // stack: x1, y1, retdest - DUP2 - // stack: y1, x1, y1, retdest - DUP2 - // stack: x1, y1, x1, y1, retdest - %ec_isidentity - // stack: (x1,y1)==(0,0), x1, y1, retdest - PUSH ret_zero - // stack: ret_zero, (x1,y1)==(0,0), x1, y1, retdest - JUMPI - // stack: x1, y1, retdest SWAP1 // stack: y1, x1, retdest SWAP2 // stack: retdest, x1, y1 JUMP -// Assumption: (x1,y1) == (0,0) and (x0,y0) != (0,0) +// BN254 elliptic curve addition. +// Assumption: (x1,y1) == (0,0) ec_add_snd_zero: JUMPDEST // stack: x0, y0, x1, y1, retdest + + // Just return (x1,y1) SWAP2 // stack: x1, y0, x0, y1, retdest POP @@ -131,24 +143,13 @@ ec_add_snd_zero: // stack: retdest, x0, y0 JUMP -ret_zero: - JUMPDEST - // stack: x, y, retdest - POP - // stack: y, retdest - POP - // stack: retdest - PUSH 0 - // stack: 0, retdest - PUSH 0 - // stack: 0, 0, retdest - SWAP2 - // stack: retdest, 0, 0 - JUMP - +// BN254 elliptic curve addition. +// Assumption: lambda = (y0 - y1)/(x0 - x1) ec_add_valid_points_with_lambda: JUMPDEST // stack: lambda, x0, y0, x1, y1, retdest + + // Compute x2 = lambda^2 - x1 - x0 DUP2 // stack: x0, lambda, x0, y0, x1, y1, retdest DUP5 @@ -165,6 +166,8 @@ ec_add_valid_points_with_lambda: // stack: lambda^2 - x1, x0, lambda, x0, y0, x1, y1, retdest %submod // stack: x2, lambda, x0, y0, x1, y1, retdest + + // Compute y2 = lambda*(x1 - x2) - y1 %bn_base // stack: N, x2, lambda, x0, y0, x1, y1, retdest DUP2 @@ -183,6 +186,8 @@ ec_add_valid_points_with_lambda: // stack: lambda * (x1 - x2), y1, x2, lambda, x0, y0, x1, y1, retdest %submod // stack: y2, x2, lambda, x0, y0, x1, y1, retdest + + // Return x2,y2 SWAP5 // stack: x1, x2, lambda, x0, y0, y2, y1, retdest POP @@ -201,35 +206,50 @@ ec_add_valid_points_with_lambda: // stack: retdest, x2, y2 JUMP +// BN254 elliptic curve addition. // Assumption: (x0,y0) and (x1,y1) are valid points and x0 == x1 ec_add_equal_first_coord: JUMPDEST // stack: x0, y0, x1, y1, retdest with x0 == x1 - %bn_base - // stack: N, x0, y0, x1, y1, retdest - DUP3 - // stack: y0, N, x0, y0, x1, y1, retdest - DUP6 - // stack: y1, y0, N, x0, y0, x1, y1, retdest - ADDMOD - // stack: y1 + y0, x0, y0, x1, y1, retdest + + // Check if the points are equal + DUP2 + // stack: y0, x0, y0, x1, y1, retdest + DUP5 + // stack: y1, y0, x0, y0, x1, y1, retdest + EQ + // stack: y1 == y0, x0, y0, x1, y1, retdest PUSH ec_add_equal_points - // stack: ec_add_equal_points, y1 + y0, x0, y0, x1, y1, retdest + // stack: ec_add_equal_points, y1 == y0, x0, y0, x1, y1, retdest JUMPI // stack: x0, y0, x1, y1, retdest + + // Otherwise, one is the negation of the other so we can return (0,0). POP // stack: y0, x1, y1, retdest POP // stack: x1, y1, retdest - PUSH ret_zero - // stack: ret_zero, x1, y1, retdest + POP + // stack: y1, retdest + POP + // stack: retdest + PUSH 0 + // stack: 0, retdest + PUSH 0 + // stack: 0, 0, retdest + SWAP2 + // stack: retdest, 0, 0 JUMP +// BN254 elliptic curve addition. // Assumption: x0 == x1 and y0 == y1 +// Standard doubling formula. ec_add_equal_points: JUMPDEST // stack: x0, y0, x1, y1, retdest + + // Compute lambda = 3/2 * x0^2 / y0 %bn_base // stack: N, x0, y0, x1, y1, retdest %bn_base @@ -252,7 +272,9 @@ ec_add_equal_points: // stack: ec_add_valid_points_with_lambda, lambda, x0, y0, x1, y1, retdest JUMP +// BN254 elliptic curve doubling. // Assumption: (x0,y0) is a valid point. +// Standard doubling formula. global ec_double: JUMPDEST // stack: x0, y0, retdest @@ -343,13 +365,7 @@ global ec_double: // stack: y^2 % N == (x^3 + 3) % N, x, y, b SWAP2 // stack: y, x, y^2 % N == (x^3 + 3) % N, b - ISZERO - // stack: y==0, x, y^2 % N == (x^3 + 3) % N, b - SWAP1 - // stack: x, y==0, y^2 % N == (x^3 + 3) % N, b - ISZERO - // stack: x==0, y==0, y^2 % N == (x^3 + 3) % N, b - AND + %ec_isidentity // stack: (x,y)==(0,0), y^2 % N == (x^3 + 3) % N, b SWAP2 // stack: b, y^2 % N == (x^3 + 3) % N, (x,y)==(0,0) @@ -359,18 +375,16 @@ global ec_double: // stack: y^2 % N == (x^3 + 3) % N & (x < N) & (y < N) || (x,y)==(0,0) %endmacro +// Check if (x,y)==(0,0) %macro ec_isidentity // stack: x, y + OR + // stack: x | y ISZERO - // stack: x==0, y - SWAP1 - // stack: y, x==0 - ISZERO - // stack: y==0, x==0 - AND - // stack: y==0 & x==0 + // stack: (x,y) == (0,0) %endmacro +// Return (u256::MAX, u256::MAX) which is used to indicate the input was invalid. %macro ec_invalid_input // stack: retdest PUSH 0xffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff diff --git a/evm/src/cpu/kernel/asm/curve_mul.asm b/evm/src/cpu/kernel/asm/curve_mul.asm index ce77e972..0826b0e3 100644 --- a/evm/src/cpu/kernel/asm/curve_mul.asm +++ b/evm/src/cpu/kernel/asm/curve_mul.asm @@ -1,3 +1,5 @@ +// BN254 elliptic curve scalar multiplication. +// Recursive implementation, same algorithm as in `exp.asm`. global ec_mul: // Uncomment for test inputs. // PUSH 0xdeadbeef diff --git a/evm/src/cpu/kernel/asm/moddiv.asm b/evm/src/cpu/kernel/asm/moddiv.asm index 2dd28fa7..891897e5 100644 --- a/evm/src/cpu/kernel/asm/moddiv.asm +++ b/evm/src/cpu/kernel/asm/moddiv.asm @@ -25,6 +25,7 @@ %mulmodn %endmacro +// Computes the inverse modulo N using x^-1 = x^(N-2) mod N and square-and-multiply modular exponentiation. %macro inverse DUP1 %squaremodn