14#include <gtest/gtest.h>
64 for (
size_t idx = 0; idx < num_iterations; idx++) {
65 op_queue->add_accumulate(
a);
66 op_queue->mul_accumulate(
a, x);
67 op_queue->mul_accumulate(
b, x);
68 op_queue->mul_accumulate(
b, y);
69 op_queue->add_accumulate(
a);
70 op_queue->mul_accumulate(
b, x);
71 op_queue->eq_and_reset();
72 op_queue->add_accumulate(c);
73 op_queue->mul_accumulate(
a, x);
74 op_queue->mul_accumulate(
b, x);
75 op_queue->eq_and_reset();
76 op_queue->mul_accumulate(
a, x);
77 op_queue->mul_accumulate(
b, x);
78 op_queue->mul_accumulate(c, x);
96 ECCVMFlavor::PCS::compute_opening_proof(prover.
key->commitment_key, opening_claim, ipa_transcript);
97 HonkProof ipa_proof = ipa_transcript->export_proof();
101 info(
"ECCVM Recursive Verifier");
107 [[maybe_unused]]
auto recursive_opening_claim = verifier.verify_proof();
113 EXPECT_EQ(outer_circuit.
failed(),
false) << outer_circuit.
err();
120 native_verifier.
transcript->enable_manifest();
121 auto native_opening_claim = native_verifier.
verify_proof();
125 ipa_verify_transcript->load_proof(ipa_proof);
126 bool ipa_verified = ECCVMFlavor::PCS::reduce_verify(
127 native_verifier.
key->pcs_verification_key, native_opening_claim, ipa_verify_transcript);
130 EXPECT_TRUE(native_result);
131 auto recursive_manifest = verifier.transcript->get_manifest();
132 auto native_manifest = native_verifier.
transcript->get_manifest();
134 ASSERT_GT(recursive_manifest.size(), 0);
135 for (
size_t i = 0; i < recursive_manifest.size(); ++i) {
136 EXPECT_EQ(recursive_manifest[i], native_manifest[i])
137 <<
"Recursive Verifier/Verifier manifest discrepency in round " << i;
141 EXPECT_EQ(
static_cast<uint64_t
>(verifier.key->log_circuit_size.get_value()),
142 verification_key->log_circuit_size);
143 EXPECT_EQ(
static_cast<uint64_t
>(verifier.key->num_public_inputs.get_value()),
144 verification_key->num_public_inputs);
145 for (
auto [vk_poly, native_vk_poly] :
zip_view(verifier.key->get_all(), verification_key->get_all())) {
146 EXPECT_EQ(vk_poly.get_value(), native_vk_poly);
153 OuterProver prover(prover_instance, verification_key);
156 bool verified = verifier.template verify_proof<DefaultIO>(proof).result;
158 ASSERT_TRUE(verified);
162 uint32_t NUM_GATES_EXPECTED = 215193;
164 <<
"Ultra-arithmetized ECCVM Recursive verifier gate count changed! Update this value if you are sure this "
171 builder.op_queue->add_erroneous_equality_op_for_testing();
179 ECCVMFlavor::PCS::compute_opening_proof(prover.
key->commitment_key, opening_claim, ipa_transcript);
180 HonkProof ipa_proof = ipa_transcript->export_proof();
191 info(
"Recursive Verifier: estimated num finalized gates = ",
200 for (
size_t idx = 0; idx < 2; idx++) {
208 ECCVMFlavor::PCS::compute_opening_proof(prover.
key->commitment_key, opening_claim, ipa_transcript_prover);
209 HonkProof ipa_proof_native = ipa_transcript_prover->export_proof();
212 tamper_with_proof<InnerProver, InnerFlavor>(proof,
static_cast<bool>(idx));
232 &outer_circuit, 1UL << CONST_ECCVM_LOG_N, native_pcs_vk);
238 stdlib_pcs_vkey, recursive_opening_claim, ipa_transcript));
247 auto get_blocks = [](
size_t inner_size)
251 InnerProver inner_prover(inner_circuit, prover_transcript);
257 ECCVMFlavor::PCS::compute_opening_proof(inner_prover.
key->commitment_key, opening_claim, ipa_transcript);
258 HonkProof ipa_proof = ipa_transcript->export_proof();
267 [[maybe_unused]]
auto recursive_opening_claim = verifier.
verify_proof();
271 auto outer_verification_key =
274 return { outer_circuit.
blocks, outer_verification_key };
277 auto [blocks_20, verification_key_20] = get_blocks(20);
278 auto [blocks_40, verification_key_40] = get_blocks(40);
280 compare_ultra_blocks_and_verification_keys<OuterFlavor>({ blocks_20, blocks_40 },
281 { verification_key_20, verification_key_40 });
#define BB_DISABLE_ASSERTS()
Common transcript class for both parties. Stores the data for the current round, as well as the manif...
const std::string & err() const
The proving key is responsible for storing the polynomials used by the prover.
The verification key is responsible for storing the commitments to the precomputed (non-witnessk) pol...
typename Curve::ScalarField FF
ECCVMCircuitBuilder CircuitBuilder
typename G1::affine_element Commitment
typename Curve::BaseField BF
NativeTranscript Transcript
std::pair< Proof, OpeningClaim > construct_proof()
std::shared_ptr< ProvingKey > key
StdlibTranscript< CircuitBuilder > Transcript
UltraCircuitBuilder CircuitBuilder
static void test_recursive_verification()
static void test_recursive_verification_failure()
static InnerBuilder generate_circuit(numeric::RNG *engine=nullptr, const size_t num_iterations=1)
Adds operations in BN254 to the op_queue and then constructs and ECCVM circuit from the op_queue.
InnerFlavor::Commitment InnerG1
static void test_recursive_verification_failure_tampered_proof()
static void SetUpTestSuite()
std::conditional_t< IsMegaBuilder< OuterBuilder >, MegaFlavor, UltraFlavor > OuterFlavor
static void test_independent_vk_hash()
Unified ECCVM verifier class for both native and recursive verification.
bool translation_masking_consistency_checked
std::shared_ptr< Transcript > transcript
std::shared_ptr< VerificationKey > key
OpeningClaim< Curve > verify_proof()
Verifies an ECCVM Honk proof for given program settings.
IPA (inner product argument) commitment scheme class.
A ProverInstance is normally constructed from a finalized circuit and it contains all the information...
static bool check(const Builder &circuit)
Check the witness satisifies the circuit.
size_t get_num_finalized_gates() const override
Get the number of gates in a finalized circuit.
ExecutionTrace_ ExecutionTrace
size_t get_num_finalized_gates_inefficient(bool ensure_nonzero=true) const
Get the number of gates in the finalized version of the circuit.
Representation of the Grumpkin Verifier Commitment Key inside a bn254 circuit.
typename Group::element Element
A simple wrapper around a vector of stdlib field elements representing a proof.
static void add_default(Builder &builder)
Add default public inputs when they are not present.
RNG & get_debug_randomness(bool reset, std::uint_fast64_t seed)
std::filesystem::path bb_crs_path()
void init_file_crs_factory(const std::filesystem::path &path)
Entry point for Barretenberg command-line interface.
std::vector< fr > HonkProof
ECCVMVerifier_< ECCVMRecursiveFlavor > ECCVMRecursiveVerifier
TEST_F(IPATest, ChallengesAreZero)
ECCVMVerifier_< ECCVMFlavor > ECCVMVerifier
constexpr decltype(auto) get(::tuplet::tuple< T... > &&t) noexcept
static field random_element(numeric::RNG *engine=nullptr) noexcept