Checkpoint the party/runtime stack before share-program and malicious-mode work.

Ship the TLS mesh, composer, Beaver/Yao/leaf MPC, prep/online paths, apps, and docs so the tree is pushable before elevating share_expr, security_mode, and prep resume.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Ryan Henry 2026-09-28 05:59:19 -06:00
parent 695f8e84f7
commit 0d22946a0e
1835 changed files with 170291 additions and 2849 deletions

View file

@ -68,6 +68,10 @@ auto async_post(ExecutorT executor, Function && func, CompletionToken && token)
// make_dpf
//
/// \complexity Local `make_dpf` is O(n) per key, then one write of each key. n is `depth`.
/// \rounds 1 per key. Each party is a single `asio::write` of six buffers; there is no reply.
/// \communication Per key, two copies (one per peer) of the correction-word array (n nodes), the advice array (n bytes), one root, the leaf tuple, the beaver tuple, and the offset word.
/// \preprocessing none beyond the local keygen. The dealer holds the clear point.
template <typename InteriorPRG = dpf::prg::aes128,
typename ExteriorPRG = InteriorPRG,
typename PeerT,
@ -123,6 +127,10 @@ auto make_dpf(PeerT & peer0, PeerT & peer1, std::size_t count, dpfargs<InputT, O
return std::make_tuple(bytes_written0, bytes_written1, count);
}
/// \complexity Local `make_dpf` is O(n) per key, then one write of each key. n is `depth`.
/// \rounds 1 per key. Each party is a single `asio::write` of six buffers; there is no reply.
/// \communication Per key, two copies (one per peer) of the correction-word array (n nodes), the advice array (n bytes), one root, the leaf tuple, the beaver tuple, and the offset word.
/// \preprocessing none beyond the local keygen. The dealer holds the clear point.
template <typename InteriorPRG = dpf::prg::aes128,
typename ExteriorPRG = InteriorPRG,
typename PeerT,
@ -138,6 +146,10 @@ auto make_dpf(PeerT & peer0, PeerT & peer1, std::size_t count, dpfargs<InputT, O
return ret;
}
/// \complexity Local `make_dpf` is O(n) per key, then one write of each key. n is `depth`.
/// \rounds 1 per key. Each party is a single `asio::write` of six buffers; there is no reply.
/// \communication Per key, two copies (one per peer) of the correction-word array (n nodes), the advice array (n bytes), one root, the leaf tuple, the beaver tuple, and the offset word.
/// \preprocessing none beyond the local keygen. The dealer holds the clear point.
template <typename InteriorPRG = dpf::prg::aes128,
typename ExteriorPRG = InteriorPRG,
typename PeerT,
@ -152,6 +164,10 @@ auto make_dpf(PeerT & peer0, PeerT & peer1, dpfargs<InputT, OutputT, OutputTs...
return std::make_tuple(bytes_written0, bytes_written1);
}
/// \complexity Local `make_dpf` is O(n) per key, then one write of each key. n is `depth`.
/// \rounds 1 per key. Each party is a single `asio::write` of six buffers; there is no reply.
/// \communication Per key, two copies (one per peer) of the correction-word array (n nodes), the advice array (n bytes), one root, the leaf tuple, the beaver tuple, and the offset word.
/// \preprocessing none beyond the local keygen. The dealer holds the clear point.
template <typename InteriorPRG = dpf::prg::aes128,
typename ExteriorPRG = InteriorPRG,
typename PeerT,
@ -646,6 +662,10 @@ auto async_read_dpf(DealerT & dealer, Emplaceable & output, CompletionToken && t
// assign_wildcard_input
//
/// \complexity O(1) arithmetic besides the socket transfer.
/// \rounds 1. One write of the local share, one read of the peer share (`async_assign_wildcard_input`).
/// \communication `sizeof(input_type)` bytes each way.
/// \preprocessing The mask in `offset_x` was sampled at `make_dpf`. This exchange opens mask − alpha.
template <typename PeerT,
typename DpfKey,
typename InputType>
@ -675,6 +695,10 @@ auto assign_wildcard_input(PeerT & peer_in, PeerT & peer_out, DpfKey & dpf,
return std::make_tuple(offset_share, bytes_written, bytes_read);
}
/// \complexity O(1) arithmetic besides the socket transfer.
/// \rounds 1. One write of the local share, one read of the peer share (`async_assign_wildcard_input`).
/// \communication `sizeof(input_type)` bytes each way.
/// \preprocessing The mask in `offset_x` was sampled at `make_dpf`. This exchange opens mask − alpha.
template <typename PeerT,
typename DpfKey,
typename InputType>
@ -686,6 +710,10 @@ auto assign_wildcard_input(PeerT & peer, DpfKey & dpf, InputType && input_share,
std::forward<InputType>(input_share), error);
}
/// \complexity O(1) arithmetic besides the socket transfer.
/// \rounds 1. One write of the local share, one read of the peer share (`async_assign_wildcard_input`).
/// \communication `sizeof(input_type)` bytes each way.
/// \preprocessing The mask in `offset_x` was sampled at `make_dpf`. This exchange opens mask − alpha.
template <typename PeerT,
typename DpfKey,
typename InputType>
@ -700,6 +728,10 @@ auto assign_wildcard_input(PeerT & peer_in, PeerT & peer_out, DpfKey & dpf,
return ret;
}
/// \complexity O(1) arithmetic besides the socket transfer.
/// \rounds 1. One write of the local share, one read of the peer share (`async_assign_wildcard_input`).
/// \communication `sizeof(input_type)` bytes each way.
/// \preprocessing The mask in `offset_x` was sampled at `make_dpf`. This exchange opens mask − alpha.
template <typename PeerT,
typename DpfKey,
typename InputType>
@ -717,6 +749,10 @@ auto assign_wildcard_input(PeerT & peer, DpfKey & dpf, InputType && input_share)
// async_assign_wildcard_input
//
/// \complexity O(1) arithmetic besides the socket transfer.
/// \rounds 1. One write of the local share, one read of the peer share (`async_assign_wildcard_input`).
/// \communication `sizeof(input_type)` bytes each way.
/// \preprocessing The mask in `offset_x` was sampled at `make_dpf`. This exchange opens mask − alpha.
template <typename PeerT,
typename ExecutorT,
typename DpfKey,
@ -796,6 +832,10 @@ auto async_assign_wildcard_input(PeerT & peer_in, PeerT & peer_out,
#include <asio/unyield.hpp>
}
/// \complexity O(1) arithmetic besides the socket transfer.
/// \rounds 1. One write of the local share, one read of the peer share (`async_assign_wildcard_input`).
/// \communication `sizeof(input_type)` bytes each way.
/// \preprocessing The mask in `offset_x` was sampled at `make_dpf`. This exchange opens mask − alpha.
template <typename PeerT,
typename ExecutorT,
typename DpfKey,
@ -811,6 +851,10 @@ auto async_assign_wildcard_input(PeerT & peer, ExecutorT work_executor,
std::forward<CompletionToken>(token));
}
/// \complexity O(1) arithmetic besides the socket transfer.
/// \rounds 1. One write of the local share, one read of the peer share (`async_assign_wildcard_input`).
/// \communication `sizeof(input_type)` bytes each way.
/// \preprocessing The mask in `offset_x` was sampled at `make_dpf`. This exchange opens mask − alpha.
template <typename PeerT,
typename DpfKey,
typename InputType,
@ -826,6 +870,10 @@ auto async_assign_wildcard_input(PeerT & peer_in, PeerT & peer_out,
std::forward<CompletionToken>(token));
}
/// \complexity O(1) arithmetic besides the socket transfer.
/// \rounds 1. One write of the local share, one read of the peer share (`async_assign_wildcard_input`).
/// \communication `sizeof(input_type)` bytes each way.
/// \preprocessing The mask in `offset_x` was sampled at `make_dpf`. This exchange opens mask − alpha.
template <typename PeerT,
typename DpfKey,
typename InputType,
@ -844,6 +892,10 @@ auto async_assign_wildcard_input(PeerT & peer, DpfKey & dpf, InputType && input_
// assign_wildcard_output
//
/// \complexity O(leaf bytes) for the Beaver leaf arithmetic, plus the transfers.
/// \rounds 2. Write/read the blinded output share, then write/read the leaf share (`async_assign_wildcard_output`).
/// \communication `sizeof(output_type)` plus `sizeof(leaf_type)` each way.
/// \preprocessing The leaf Beaver triple (`vector_blind`, `output_blind`, `blinded_vector`) was stored at keygen.
template <std::size_t I = 0,
typename PeerT,
typename DpfKey,
@ -861,7 +913,11 @@ auto assign_wildcard_output(PeerT & peer_in, PeerT & peer_out, DpfKey & dpf,
constexpr bool is_packed = true;
auto & leaf_wrapper = utils::get<I>(dpf.leaf_nodes);
// Second (and later) assigns install β'−β on top of the ready leaf.
if (leaf_wrapper.is_ready())
leaf_wrapper.begin_update();
auto blinded_output = leaf_wrapper.compute_and_get_blinded_output_share(output_share);
bytes_written += ::asio::write(peer_out, ::asio::buffer(&blinded_output, sizeof(output_type)), error);
if (error)
@ -898,6 +954,10 @@ auto assign_wildcard_output(PeerT & peer_in, PeerT & peer_out, DpfKey & dpf,
return std::make_tuple(leaf_share, bytes_written, bytes_read);
}
/// \complexity O(leaf bytes) for the Beaver leaf arithmetic, plus the transfers.
/// \rounds 2. Write/read the blinded output share, then write/read the leaf share (`async_assign_wildcard_output`).
/// \communication `sizeof(output_type)` plus `sizeof(leaf_type)` each way.
/// \preprocessing The leaf Beaver triple (`vector_blind`, `output_blind`, `blinded_vector`) was stored at keygen.
template <std::size_t I = 0,
typename PeerT,
typename DpfKey,
@ -910,6 +970,10 @@ auto assign_wildcard_output(PeerT & peer, DpfKey & dpf,
std::forward<OutputType>(output_share), error);
}
/// \complexity O(leaf bytes) for the Beaver leaf arithmetic, plus the transfers.
/// \rounds 2. Write/read the blinded output share, then write/read the leaf share (`async_assign_wildcard_output`).
/// \communication `sizeof(output_type)` plus `sizeof(leaf_type)` each way.
/// \preprocessing The leaf Beaver triple (`vector_blind`, `output_blind`, `blinded_vector`) was stored at keygen.
template <std::size_t I = 0,
typename PeerT,
typename DpfKey,
@ -925,6 +989,10 @@ auto assign_wildcard_output(PeerT & peer_in, PeerT & peer_out, DpfKey & dpf,
return ret;
}
/// \complexity O(leaf bytes) for the Beaver leaf arithmetic, plus the transfers.
/// \rounds 2. Write/read the blinded output share, then write/read the leaf share (`async_assign_wildcard_output`).
/// \communication `sizeof(output_type)` plus `sizeof(leaf_type)` each way.
/// \preprocessing The leaf Beaver triple (`vector_blind`, `output_blind`, `blinded_vector`) was stored at keygen.
template <std::size_t I = 0,
typename PeerT,
typename DpfKey,
@ -943,6 +1011,10 @@ auto assign_wildcard_output(PeerT & peer, DpfKey & dpf, OutputType && output_sha
// async_assign_wildcard_output
//
/// \complexity O(leaf bytes) for the Beaver leaf arithmetic, plus the transfers.
/// \rounds 2. Write/read the blinded output share, then write/read the leaf share (`async_assign_wildcard_output`).
/// \communication `sizeof(output_type)` plus `sizeof(leaf_type)` each way.
/// \preprocessing The leaf Beaver triple (`vector_blind`, `output_blind`, `blinded_vector`) was stored at keygen.
template <std::size_t I = 0,
typename PeerT,
typename ExecutorT,
@ -987,6 +1059,8 @@ auto async_assign_wildcard_output(PeerT & peer_in, PeerT & peer_out,
{
yield async_post(work_executor, [&leaf, output_share]() mutable
{
if (leaf.is_ready())
leaf.begin_update();
*output_share = leaf.compute_and_get_blinded_output_share(*output_share);
}, std::move(self));
@ -1059,6 +1133,10 @@ auto async_assign_wildcard_output(PeerT & peer_in, PeerT & peer_out,
#include <asio/unyield.hpp>
}
/// \complexity O(leaf bytes) for the Beaver leaf arithmetic, plus the transfers.
/// \rounds 2. Write/read the blinded output share, then write/read the leaf share (`async_assign_wildcard_output`).
/// \communication `sizeof(output_type)` plus `sizeof(leaf_type)` each way.
/// \preprocessing The leaf Beaver triple (`vector_blind`, `output_blind`, `blinded_vector`) was stored at keygen.
template <std::size_t I = 0,
typename PeerT,
typename ExecutorT,
@ -1075,6 +1153,10 @@ auto async_assign_wildcard_output(PeerT & peer, ExecutorT work_executor,
std::forward<CompletionToken>(token));
}
/// \complexity O(leaf bytes) for the Beaver leaf arithmetic, plus the transfers.
/// \rounds 2. Write/read the blinded output share, then write/read the leaf share (`async_assign_wildcard_output`).
/// \communication `sizeof(output_type)` plus `sizeof(leaf_type)` each way.
/// \preprocessing The leaf Beaver triple (`vector_blind`, `output_blind`, `blinded_vector`) was stored at keygen.
template <std::size_t I = 0,
typename PeerT,
typename DpfKey,
@ -1091,6 +1173,10 @@ auto async_assign_wildcard_output(PeerT & peer_in, PeerT & peer_out,
std::forward<CompletionToken>(token));
}
/// \complexity O(leaf bytes) for the Beaver leaf arithmetic, plus the transfers.
/// \rounds 2. Write/read the blinded output share, then write/read the leaf share (`async_assign_wildcard_output`).
/// \communication `sizeof(output_type)` plus `sizeof(leaf_type)` each way.
/// \preprocessing The leaf Beaver triple (`vector_blind`, `output_blind`, `blinded_vector`) was stored at keygen.
template <std::size_t I = 0,
typename PeerT,
typename DpfKey,
@ -1101,7 +1187,6 @@ HEDLEY_ALWAYS_INLINE
auto async_assign_wildcard_output(PeerT & peer, DpfKey & dpf,
OutputType && output_share, CompletionToken && token)
{
auto work_executor = ::asio::system_executor();
return async_assign_wildcard_output<I>(peer, peer, dpf,
std::forward<OutputType>(output_share),
std::forward<CompletionToken>(token));