Checkpoint the party/runtime stack before share-program and malicious-mode work.

Ship the TLS mesh, composer, Beaver/Yao/leaf MPC, prep/online paths, apps, and docs so the tree is pushable before elevating share_expr, security_mode, and prep resume.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Ryan Henry 2026-09-28 05:59:19 -06:00
parent 695f8e84f7
commit 0d22946a0e
1835 changed files with 170291 additions and 2849 deletions

View file

@ -107,6 +107,13 @@ struct extractable
static constexpr bool is_extractable_tag = true;
};
/// @brief Phantom pack element: keep a beaver-backed leaf so the payload can
/// be rewritten without regenerating the path to `α`.
struct updatable
{
static constexpr bool is_updatable_tag = true;
};
template <typename T>
struct is_verifiable_tag : std::false_type
{ };
@ -127,6 +134,64 @@ template <typename T>
inline constexpr bool is_extractable_tag_v =
is_extractable_tag<std::decay_t<T>>::value;
template <typename T>
struct is_updatable_tag : std::false_type
{ };
template <>
struct is_updatable_tag<updatable> : std::true_type
{ };
template <typename T>
inline constexpr bool is_updatable_tag_v =
is_updatable_tag<std::decay_t<T>>::value;
/// @brief Compile-time switch for verifiable / extractable / output-MAC checks.
/// @details Default `auth_profile<>` is semi-honest: no correction seeds and
/// no leaf XOF. `verifiable` and `extractable` become phantom tags
/// for `make_dpf_profile`. `output_mac` stays on the profile for
/// Beaver and carry sessions; key generation does not consume it.
template <bool Verifiable = false, bool Extractable = false,
bool OutputMac = false>
struct auth_profile
{
static constexpr bool verifiable = Verifiable;
static constexpr bool extractable = Extractable;
static constexpr bool output_mac = OutputMac;
};
using semi_honest = auth_profile<false, false, false>;
using checked = auth_profile<true, true, true>;
/// @brief Tuple of phantom tags requested by `Profile` (may be empty).
/// @tparam Profile an `auth_profile` specialization
/// @return `verifiable` and/or `extractable`, or an empty tuple.
/// `Profile::output_mac` is not a key tag.
template <typename Profile = semi_honest>
HEDLEY_CONST
HEDLEY_NO_THROW
constexpr auto key_tags_tuple() noexcept
{
if constexpr (Profile::verifiable && Profile::extractable)
return std::tuple{verifiable{}, extractable{}};
else if constexpr (Profile::verifiable)
return std::tuple{verifiable{}};
else if constexpr (Profile::extractable)
return std::tuple{extractable{}};
else
return std::tuple{};
}
/// @brief Alias for `key_tags_tuple` (use with `std::apply` / `make_dpf_profile`).
/// @tparam Profile an `auth_profile` specialization
/// @return the same tuple as `key_tags_tuple<Profile>()`
/// @see key_tags_tuple
template <typename Profile = semi_honest>
HEDLEY_CONST
HEDLEY_NO_THROW
constexpr auto key_tags() noexcept
{
return key_tags_tuple<Profile>();
}
namespace detail
{
namespace incr
@ -145,10 +210,12 @@ struct unwrap_placed_output
using type = T;
};
template <std::size_t N, typename OutputT>
template <std::size_t N, typename OutputT, bool PublicAddend = false>
struct placed
{
static constexpr std::size_t prefix = N;
/// @brief When true, party 0 absorbs `addend` (eq / eq_at if_false) at eval.
static constexpr bool has_public_addend = PublicAddend;
/// @brief Stored argument type (may be `arith_beta<T>`).
using stored_type = OutputT;
/// @brief Key / leaf payload type (`T` when stored is `arith_beta<T>`).
@ -158,11 +225,19 @@ struct placed
};
template <typename T> struct is_placed : std::false_type {};
template <std::size_t N, typename O>
struct is_placed<placed<N, O>> : std::true_type {};
template <std::size_t N, typename O, bool A>
struct is_placed<placed<N, O, A>> : std::true_type {};
template <typename T>
inline constexpr bool is_placed_v = is_placed<std::decay_t<T>>::value;
template <typename Tuple>
struct any_public_addend : std::false_type {};
template <typename ...Ps>
struct any_public_addend<std::tuple<Ps...>>
: std::bool_constant<(Ps::has_public_addend || ...)> {};
template <typename Tuple>
inline constexpr bool any_public_addend_v = any_public_addend<Tuple>::value;
/// @brief Heavy-hitters incremental point function: one payload per prefix length.
/// @details `levels[i]` is the bit length of slot `i`.
/// @tparam LevelSeq level seq
@ -470,10 +545,10 @@ struct normalize_one
static constexpr bool is_verifiable = false;
static constexpr bool is_extractable = false;
};
template <std::size_t BitLen, std::size_t N, typename T>
struct normalize_one<BitLen, placed<N, T>>
template <std::size_t BitLen, std::size_t N, typename T, bool A>
struct normalize_one<BitLen, placed<N, T, A>>
{
using placed_tuple = std::tuple<placed<N, T>>;
using placed_tuple = std::tuple<placed<N, T, A>>;
static constexpr std::size_t cmp_depth = 0;
static constexpr std::size_t cmp_out_bits = 0;
static constexpr bool cmp_wild = false;
@ -520,6 +595,18 @@ struct normalize_one<BitLen, extractable>
static constexpr bool is_verifiable = false;
static constexpr bool is_extractable = true;
};
template <std::size_t BitLen>
struct normalize_one<BitLen, updatable>
{
using placed_tuple = std::tuple<>;
static constexpr std::size_t cmp_depth = 0;
static constexpr std::size_t cmp_out_bits = 0;
static constexpr bool cmp_wild = false;
static constexpr std::size_t cmp_block = 0;
static constexpr bool cmp_idcf = false;
static constexpr bool is_verifiable = false;
static constexpr bool is_extractable = false;
};
template <std::size_t BitLen, typename ...Elems>
struct normalize_pack
@ -561,7 +648,8 @@ struct normalize_pack<BitLen>
template <typename ...Elems>
inline constexpr bool is_classic_pack_v =
!((is_placed_v<Elems> || is_cmp_channel_tag_v<Elems>
|| is_verifiable_tag_v<Elems> || is_extractable_tag_v<Elems>) || ...);
|| is_verifiable_tag_v<Elems> || is_extractable_tag_v<Elems>
|| is_updatable_tag_v<Elems>) || ...);
} // namespace incr
} // namespace detail