Checkpoint the party/runtime stack before share-program and malicious-mode work.

Ship the TLS mesh, composer, Beaver/Yao/leaf MPC, prep/online paths, apps, and docs so the tree is pushable before elevating share_expr, security_mode, and prep resume.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Ryan Henry 2026-09-28 05:59:19 -06:00
parent 695f8e84f7
commit 0d22946a0e
1835 changed files with 170291 additions and 2849 deletions

View file

@ -1,5 +1,25 @@
/// @file dpf/offset_wrapper.hpp
/// @brief An output value shifted by a public offset.
/// @brief The input offset stored on a key.
/// @details A concrete input ignores the stored word. A wildcard input
/// plants a mask at keygen. Parties open `mask - alpha` with
/// `compute_and_get_share` and `reconstruct`. `operator()` throws
/// `std::runtime_error` ("offset not set") until that finishes.
///
/// Additive blinding means evaluation uses tree coordinates
/// `x ↦ x + δ` once `δ` is ready (`offset_x`). Eager `eval_interval`
/// folds that map into the traversed range. Interval memoizers and
/// output buffers built from a key (`make_basic_interval_memoizer(dpf,
/// from, to)`, `make_output_buffer_for_interval(dpf, from, to)`) size
/// against those tree coordinates: leaf packing depends on alignment
/// after `δ`, so sizing only on the logical endpoints can undersize.
/// When `δ` is not yet known, use `defer_eval_interval` /
/// `defer_eval_full`: evaluate the full domain at identity, then after
/// assign materialize a view rotated by `offset_x(0)` (see
/// `deferred_rotated_subinterval`).
/// @see dpf::wildcard_value
/// @see dpf::leaf_wrapper
/// @see dpf::deferred_rotated_subinterval
/// @see dpf::defer_eval_interval
/// @author Ryan Henry <ryan.henry@ucalgary.ca>
/// @copyright Copyright (c) 2019-2024 Ryan Henry and [others](@ref authors)
/// @license Released under a GNU General Public v2.0 (GPLv2) license;