1548 Commits

Author SHA1 Message Date
wborgeaud
e78630ae81 PR feedback 2022-01-28 05:02:31 +01:00
wborgeaud
b6cb72b629 Comments 2022-01-27 13:27:06 +01:00
wborgeaud
1770e83c63 Clippy 2022-01-27 13:02:36 +01:00
wborgeaud
4a2681034e Working prover 2022-01-27 12:58:56 +01:00
wborgeaud
3e0cb36063 Added test stark 2022-01-27 07:56:22 +01:00
wborgeaud
d54cc9a7c8 First try 2022-01-26 16:08:04 +01:00
Daniel Lubarov
c0ac79e2e1
Beginning of STARK implementation (#413)
* Beginning of STARK implementation

* PR feedback

* minor

* Suppress warnings for now
2022-01-26 00:09:29 -08:00
Jakub Nabaglo
483799746b
Jemalloc warnings in Readme (#448) 2022-01-24 13:35:26 -08:00
Daniel Lubarov
2af85ccb8d
Make set_proof_target publicly accessible (#447)
* Make `set_proof_target` publicly accessible

Same code as before, except I broke it into a few functions and renamed a couple things.

* fmt
2022-01-24 11:16:38 -08:00
Daniel Lubarov
a6e64d1c7e
Replace proof_to_proof_target (#445)
* Replace `proof_to_proof_target`

With a `add_virtual_proof_with_pis` method that uses the inner circuit data, but does not require constructing a proof.

Note that this doesn't support IVC yet. For that, I think we can add a variant of `add_virtual_proof_with_pis` that takes several parameters like FRI arities, but does not involve `CommonCircuitData` (since no circuit has been build yet). It might also be best to avoid large objects like `FriParams`, and pass just the data we need.

Then there will be some nontrivial work to do recursion with "estimated" parameters (degree, arities, etc), check if the estimates were correct, and try again if not.

* PR feedback
2022-01-23 23:27:26 -08:00
Jakub Nabaglo
04fbb05d7c
Swap loops in compute_quotient_polys (#444) 2022-01-21 15:55:24 -08:00
Jakub Nabaglo
5f0eee1a9b
Bit-order reversal optimizations (#442)
* Bit-order in-place reversal optimizations

* optimization/simplification

* Done modulo documentation and testing on x86

* Minor type fixes on non-ARM

* Minor x86

* Transpose docs

* Docs

* Make rustfmt happy

* Bug fixes + tests

* Minor docs + lints
2022-01-21 10:44:46 -08:00
Jakub Nabaglo
86dc4c933a
Make all FFTs in-place (#439)
* Make all FFTs in-place

* Delete leftover marker
2022-01-21 10:26:43 -08:00
Daniel Lubarov
2e3a682bde metadata 2022-01-21 10:14:44 -08:00
Daniel Lubarov
d69220e2a7 metadata 2022-01-21 10:06:40 -08:00
wborgeaud
8df9e7ec77
Merge pull request #436 from mir-protocol/fix_ldt_degree
Fix degree of polynomial used in LDT
2022-01-21 06:24:28 +01:00
wborgeaud
094e35b0bb
Merge pull request #440 from mir-protocol/simplify_compute_quotient
Remove `compute_quotient` and update division tests
2022-01-21 06:12:37 +01:00
Jakub Nabaglo
f98a6adfbf
Bit-order reversal benchmarks (#441) 2022-01-19 17:51:20 -08:00
wborgeaud
5255c04c70 Remove compute_quotient and update division tests 2022-01-19 12:31:20 +01:00
wborgeaud
27ebc21faf Add comments for LDT fix in verifier 2022-01-19 11:57:46 +01:00
Daniel Lubarov
dcf63f536e
Have hash functions take references to avoid cloning (#438)
And other tweaks to `MerkleTree::new`
2022-01-18 12:51:04 -08:00
Hamish Ivey-Law
fcdcc86569
Move profile defns to root workspace toml. (#437) 2022-01-18 11:41:08 +11:00
wborgeaud
2bb0c4f4e7 Fix comment 2022-01-17 06:44:05 +01:00
wborgeaud
6f65620ff2 Add fix for recursive verifier. 2022-01-17 06:33:23 +01:00
wborgeaud
ec474efe12 Minor 2022-01-17 06:25:03 +01:00
Jakub Nabaglo
2aa46e148c
Optimize + test log2 functions (#434)
* Speed up log2 functions

* Move tests to `util` crate

* Trick
2022-01-16 15:15:25 -08:00
wborgeaud
fe0c232d6d Working (not yet for recursion) 2022-01-14 07:56:06 +01:00
Sebastien La Duca
fe5a30ede1
make HashOutTarget internals public (#430) 2022-01-13 12:12:59 -08:00
Daniel Lubarov
0ff8365827 timing 2022-01-12 19:07:33 -08:00
Daniel Lubarov
9f09a2aace
Add Merkle tree benchmark (#429)
And one for a single Keccak hash
2022-01-12 16:25:12 -08:00
Daniel Lubarov
9ecdc4d30f note about toolchain 2022-01-11 19:36:32 -08:00
Daniel Lubarov
6c25fb9717 wording 2022-01-09 09:53:54 -08:00
Daniel Lubarov
ac59f2bc45 readme updates 2022-01-09 09:52:19 -08:00
Daniel Lubarov
3ab0a37af3
No longer need to store number of PP polynomials (#424)
* No longer need to store number of PP polynomials

It's unused after the refactoring we did.

* PR feedback
2022-01-09 09:44:13 -08:00
Daniel Lubarov
bde6114428
Replace AlgebraicConfig with GenericConfig (#425)
It works fine if we bound recursion methods with `C::Hasher: AlgebraicHasher<F>`. This bound feels natural to me - it's like saying "the recursion methods assume the inner hasher has a circuit implementation".
2022-01-09 08:33:12 -08:00
Daniel Lubarov
8ec78fc0c1 tweak len 2022-01-08 23:44:12 -08:00
Daniel Lubarov
3fc5ff4fff
Remove old binaries (#423)
FFTs became proper benches, while recursion became tests. We might consider having either bins or benches for recursion in the future, but the code in this old recursion bin won't be useful, so might as well delete it for now.
2022-01-07 10:24:54 -08:00
Daniel Lubarov
f48d8c92bd
Finish making FRI generic (#422)
* Finish making FRI generic

* fix quotient poly factor

* Bound quotient degree factor
2022-01-06 23:04:33 -08:00
Jakub Nabaglo
4e532f04fa
AVX2 Poseidon S-box optimizations (#421) 2022-01-06 15:50:56 -08:00
Daniel Lubarov
bf30fed701
Make FRI more generic (#419)
* Make FRI more generic

* PR feedback
2022-01-06 11:40:08 -08:00
Jakub Nabaglo
f072d09ae4
AVX-512 packed Goldilocks (#400)
* WIP AVX-512 Goldilocks

* Fix tests

* fmt

* Hamish PR comment
2022-01-06 09:19:32 -08:00
Jakub Nabaglo
a6e1f7ccad
Aarch64: Minor optimization to Poseidon full layers (#420)
* Aarch64: Minor optimization to Poseidon full layers

* Daniel PR comment
2022-01-06 09:16:54 -08:00
Jakub Nabaglo
5825893845
Remove feature(asm_sym) (#418) 2022-01-06 08:37:34 -08:00
Daniel Lubarov
4f2ac97b0a consistent order 2022-01-04 00:01:53 -08:00
Daniel Lubarov
1d576f2046 licensing note 2022-01-03 10:00:15 -08:00
Daniel Lubarov
3de8d36c3a
Use single-point opening expressions (#416)
I.e. instead of opening `Z` at `zeta` and `g zeta` by running FRI on a quotient involving an interpolant, we just run FRI on two separate opening expressions, one for `zeta` and one for `g zeta`.

A few motivations for this:
- I think this will make it slightly easier to generalize our FRI code to work with STARKs. I.e. if we have an object representing the structure of polynomial openings in an IOP, that object will be slightly simpler.
- It's less code. We could potentially remove some more code, e.g. the generality of `compute_quotient` is no longer needed, but I left it for now.
- It saves 3 gates!
2022-01-03 08:34:44 -08:00
Daniel Lubarov
6991257da5
Simpler Keccak pseudo-permutation (#415)
* Simpler Keccak pseudo-permutation

After rejecting a value, I think it's a little simpler to continue the hash chain vs retrying with an incremented nonce.

* PR feedback

* fix byte order
2022-01-02 21:36:41 -08:00
Daniel Lubarov
23f0e49c87
Separate some circuit logic from FRI code (#414)
My goal is to make the FRI code independent of circuit objects like `CommonCircuitData`, so that it can be reused by STARK code which won't involve those objects.

A few changes here:

- Move `rate_bits` and `cap_height` into `FriConfig`.
- Move `degree_bits` into `FriParameters` (since it's instance size specific).
- Make `FriParams` contain `FriConfig`, so FRI methods can take just the former and access fields in both.
- Replace `CommonCircuitConfig` with `FriParams` in FRI prover methods.

The FRI verifier methods still involve circuit objects, as they have PLONK logic in `fri_combine_initial`. Will think about how to deal with that after this.
2022-01-02 11:26:26 -08:00
wborgeaud
a452da523b
Merge pull request #407 from mir-protocol/challenger_outer_hash
Use the outer hash in the challenger
2022-01-02 10:24:29 +01:00
wborgeaud
7b03ebe1b8 PR feedback 2022-01-02 10:16:35 +01:00