Checkpoint the party/runtime stack before share-program and malicious-mode work.

Ship the TLS mesh, composer, Beaver/Yao/leaf MPC, prep/online paths, apps, and docs so the tree is pushable before elevating share_expr, security_mode, and prep resume.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Ryan Henry 2026-09-28 05:59:19 -06:00
parent 695f8e84f7
commit 0d22946a0e
1835 changed files with 170291 additions and 2849 deletions

View file

@ -5,13 +5,20 @@
/// outputs, and what is revealed. A protocol may open a masked value or a
/// public offset; that appears in the figure only when the parties learn it.
///
/// \htmlonly
/// <div class="eli5"><b>ELI5.</b> An ideal functionality is the specification the protocol is measured against: who holds what, what goes in, what comes out, and which values become public.</div>
/// \endhtmlonly
///
///
/// ## Sharing
///
///
/// - \ref secret_share.hpp "F_Open"
/// - \ref shamir3.hpp "F_Shamir"
///
/// ## Dealer keys
///
///
/// - \ref dpf_key.hpp "F_DPF"
/// - \ref incremental.hpp "F_IDPF"
/// - \ref grow.hpp "F_Grow"
@ -23,15 +30,20 @@
///
/// ## Two-party generation and evaluation
///
///
/// - \ref iknp.hpp "F_IKNP"
/// - \ref doerner_shelat.hpp "F_DS"
/// - \ref grow_ds.hpp "F_GrowDS"
/// - \ref geneval.hpp "F_GenEval"
/// - \ref beaver.hpp "F_Beaver and F_BeaverAuth"
/// - \ref yao.hpp "F_Yao"
/// - \ref yao_share.hpp "F_YaoShare"
/// - \ref constrained_cmp.hpp "F_CCMP"
/// - \ref verifiable.hpp "F_VDPF, F_Sketch, and F_OblivHash"
///
/// ## Three evaluators
///
///
/// - \ref dpf3.hpp "F_DPF3"
/// - \ref dpf3_ds.hpp "F_DPF3DS"
/// - \ref dpf3_cmp.hpp "F_DPF3CMP"
@ -39,6 +51,7 @@
///
/// ## Offset corrections
///
///
/// - \ref offset_horner.hpp "F_Horner"
/// - \ref offset_poly.hpp "F_Poly"
/// - \ref offset_jet.hpp "F_Jet"
@ -266,6 +279,25 @@
/// }
/// \enddot
/// @file dpf/iknp.hpp
///
/// @par Ideal functionality
/// \dot "Functionality F_IKNP"
/// digraph F_IKNP {
/// graph [bgcolor="transparent"];
/// node [shape=plaintext, fontname="Helvetica", fontsize=11];
/// F [label=<
/// <TABLE BORDER="1" CELLBORDER="0" CELLSPACING="0" CELLPADDING="7" COLOR="#1e293b" BGCOLOR="#f8fafc">
/// <TR><TD ALIGN="LEFT" BGCOLOR="#1e293b"><FONT COLOR="white" POINT-SIZE="12"><B>F_IKNP</B></FONT></TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> P0 and P1. Semi-honest. Base OT is Chou-Orlandi.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> sample: both parties pass the same lengths<BR/>(bit x block, bit x bit, B2A, correction-word pads).<BR/>transfer_labels: the sender holds two 128-bit strings per row;<BR/>the receiver holds a choice bit per row.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> sample gives each party its share of the pads:<BR/>bit x block, bit AND, a daBit, and a correction-word gamma<BR/>that hides the peer pad bit.<BR/>transfer_labels gives the receiver exactly the chosen string.<BR/>The sender's output buffer is cleared. An empty transfer sends nothing.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> Lengths are public. Choice bits, the unchosen string,<BR/>and the peer pad bit stay hidden.<BR/>One role_state is one direction; the first call runs the base OT.</TD></TR>
/// </TABLE>
/// >];
/// }
/// \enddot
/// @file dpf/doerner_shelat.hpp
///
/// @par Ideal functionality
@ -617,3 +649,45 @@
/// >];
/// }
/// \enddot
/// @file dpf/yao.hpp
///
/// @par Ideal functionality
/// \dot "Functionality F_Yao"
/// digraph F_Yao {
/// graph [bgcolor="transparent"];
/// node [shape=plaintext, fontname="Helvetica", fontsize=11];
/// F [label=<
/// <TABLE BORDER="1" CELLBORDER="0" CELLSPACING="0" CELLPADDING="7" COLOR="#1e293b" BGCOLOR="#f8fafc">
/// <TR><TD ALIGN="LEFT" BGCOLOR="#1e293b"><FONT COLOR="white" POINT-SIZE="12"><B>F_Yao</B></FONT></TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> P0 garbles. P1 evaluates. Semi-honest.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> A public straight-line bit netlist.<BR/>Each shared input is an XOR share of that bit.<BR/>A private input is known to one party.<BR/>The usual source of those bits is a DPF leaf, via F_YaoShare.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> XOR shares of each output bit.<BR/>P0's share is the permute bit of the zero label.<BR/>P1's share is the color of the label it holds.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> None beyond the output shares.<BR/>Tables are one-time. P1 does not learn Delta.<BR/>P0 does not learn P1's private bits or P1's shares.</TD></TR>
/// </TABLE>
/// >];
/// }
/// \enddot
/// @file dpf/yao_share.hpp
///
/// @par Ideal functionality
/// \dot "Functionality F_YaoShare"
/// digraph F_YaoShare {
/// graph [bgcolor="transparent"];
/// node [shape=plaintext, fontname="Helvetica", fontsize=11];
/// F [label=<
/// <TABLE BORDER="1" CELLBORDER="0" CELLSPACING="0" CELLPADDING="7" COLOR="#1e293b" BGCOLOR="#f8fafc">
/// <TR><TD ALIGN="LEFT" BGCOLOR="#1e293b"><FONT COLOR="white" POINT-SIZE="12"><B>F_YaoShare</B></FONT></TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Parties.</B> P0 and P1. For a replicated leaf, P2 is idle.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Input.</B> One share each of an integer the DPF already produced:<BR/>subtractive (point leaf), additive (comparison leaf),<BR/>an fss_share, or the party-0 and party-1 replicated views.<BR/>The reverse calls take XOR shares of the low width bits.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Output.</B> XOR shares of those bits, least-significant bit first,<BR/>or ring shares of the integer the bits encode, in the leaf's scheme.<BR/>y2rss deals a fresh replicated triple of that integer.</TD></TR>
/// <TR><TD ALIGN="LEFT"><B>Leakage.</B> A2B opens a masked x - r. B2A opens a masked bit.<BR/>Both masks are uniform. The integer stays shared.<BR/>This is not the local (3,3) cast dpf::rss2y / dpf::y2rss.</TD></TR>
/// </TABLE>
/// >];
/// }
/// \enddot
/// \htmlonly
/// <div class="tldr"><b>TL;DR.</b> Each figure states the parties, the inputs, the outputs, and what is revealed. A masked value or a public offset appears only when the parties learn it.</div>
/// \endhtmlonly