Checkpoint the party/runtime stack before share-program and malicious-mode work.

Ship the TLS mesh, composer, Beaver/Yao/leaf MPC, prep/online paths, apps, and docs so the tree is pushable before elevating share_expr, security_mode, and prep resume.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Ryan Henry 2026-09-28 05:59:19 -06:00
parent 695f8e84f7
commit 0d22946a0e
1835 changed files with 170291 additions and 2849 deletions

View file

@ -12,7 +12,8 @@
/// `verify` checks the opened Naor roots. Correction words travel with the
/// opened key. `check_well_formed` checks both keys of a replica the
/// committer still holds, and `audit` reruns generation from a seed.
/// Evaluation walks the domain, so the input bitlength is at most 16.
/// Evaluation stores one entry per domain point, so the input bitlength
/// is at most 20. The full-domain walk is `eval_full`.
/// The manual is [Point-programmable vector commitments](@ref ppvc_manual).
/// @copyright Copyright (c) 2019-2026 Ryan Henry and [others](@ref authors)
/// @license Released under a GNU General Public v2.0 (GPLv2) license;
@ -38,6 +39,7 @@
#include "dpf/bit.hpp"
#include "dpf/dpf_key.hpp"
#include "dpf/eval_full.hpp"
#include "dpf/eval_point.hpp"
#include "dpf/prg.hpp"
#include "dpf/random.hpp"
@ -79,7 +81,7 @@ struct ppvc
static_assert(m_bits % 8 == 0, "ppvc Naor string must be a whole number of bytes");
static_assert(domain_bits >= dpf::lg_outputs_per_leaf_v<dpf::bit, block_type>,
"ppvc domain must cover one packed leaf");
static_assert(domain_bits <= 16, "ppvc evaluation materializes the domain");
static_assert(domain_bits <= 20, "ppvc evaluation materializes one entry per domain point");
/// @brief `m`-bit string, the codomain of Naor's `G`.
struct naor_string
@ -221,18 +223,31 @@ struct ppvc
const std::size_t hidden = index_of(st.i);
std::array<bool, Width> u{};
for (std::size_t j = 0; j < Width; ++j)
u[j] = bit_at(key_of(st, j, 0), hidden);
value_type target = tau;
if (mu == 1)
if (mu == 0)
{
for (std::size_t j = 0; j < Width; ++j)
u[j] = bit_at(key_of(st, j, 0), hidden);
}
else
{
std::array<std::vector<std::uint8_t>, Width> columns{};
for (std::size_t j = 0; j < Width; ++j)
columns[j] = full_bits(key_of(st, j, 0));
value_type off_sum = 0;
for (std::size_t y = 0; y < domain_size; ++y)
{
value_type column = 0;
for (std::size_t j = 0; j < Width; ++j)
{
if (columns[j][y] != 0)
column |= value_type{1} << j;
}
if (y == hidden)
continue;
off_sum = (off_sum + column_at(st, 0, y)) & value_mask();
for (std::size_t j = 0; j < Width; ++j)
u[j] = columns[j][y] != 0;
else
off_sum = (off_sum + column) & value_mask();
}
target = (tau - off_sum) & value_mask();
}
@ -271,15 +286,20 @@ struct ppvc
/// @brief One-sided vector in the hidden indexing, one entry per domain point.
static std::vector<value_type> eval(const opening & op)
{
std::array<std::vector<std::uint8_t>, Width> columns{};
for (std::size_t j = 0; j < Width; ++j)
{
if (!op.keys[j])
throw std::invalid_argument("ppvc: opening is missing a key");
columns[j] = full_bits(*op.keys[j]);
}
std::vector<value_type> x(domain_size);
for (std::size_t y = 0; y < domain_size; ++y)
{
value_type column = 0;
for (std::size_t j = 0; j < Width; ++j)
{
if (!op.keys[j])
throw std::invalid_argument("ppvc: opening is missing a key");
if (bit_at(*op.keys[j], y))
if (columns[j][y] != 0)
column |= value_type{1} << j;
}
x[y] = column;
@ -347,11 +367,13 @@ struct ppvc
if (!shared_corrections(left, right))
return false;
const auto left_bits = full_bits(left);
const auto right_bits = full_bits(right);
int spikes = 0;
std::size_t where = 0;
for (std::size_t y = 0; y < domain_size; ++y)
{
if (bit_at(left, y) != bit_at(right, y))
if (left_bits[y] != right_bits[y])
{
++spikes;
where = y;
@ -498,15 +520,17 @@ struct ppvc
}
HEDLEY_WARN_UNUSED_RESULT
static value_type column_at(const state & st, unsigned side, std::size_t index)
static std::vector<std::uint8_t> full_bits(const bare_key & key)
{
value_type column = 0;
for (std::size_t j = 0; j < Width; ++j)
{
if (bit_at(key_of(st, j, side), index))
column |= value_type{1} << j;
}
return column;
auto evaluated = dpf::eval_full(key);
std::vector<std::uint8_t> bits;
bits.reserve(domain_size);
for (auto it = std::cbegin(evaluated.second);
it != std::cend(evaluated.second); ++it)
bits.push_back(static_cast<bool>(*it) ? std::uint8_t{1} : std::uint8_t{0});
if (bits.size() != domain_size)
throw std::logic_error("ppvc: full-domain evaluation has the wrong length");
return bits;
}
HEDLEY_WARN_UNUSED_RESULT