Checkpoint the party/runtime stack before share-program and malicious-mode work.

Ship the TLS mesh, composer, Beaver/Yao/leaf MPC, prep/online paths, apps, and docs so the tree is pushable before elevating share_expr, security_mode, and prep resume.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Ryan Henry 2026-09-28 05:59:19 -06:00
parent 695f8e84f7
commit 0d22946a0e
1835 changed files with 170291 additions and 2849 deletions

View file

@ -10,11 +10,11 @@
#include "hedley/hedley.h"
#include <atomic>
#include <cstring>
#include <stdexcept>
#include <type_traits>
#include "dpf/prg_count.hpp"
#include "dpf/prg_aes.hpp"
#include "dpf/prg_aes_ccr.hpp"
#include "dpf/prg_chacha.hpp"
@ -68,6 +68,7 @@ auto expand_as_share(typename PRG::block_type seed,
} // namespace detail
/// \complexity `ceil(sizeof(T) / sizeof(block_type))` PRG evaluations (`expand_raw`), then a copy.
template <typename AesKey>
template <typename T, std::size_t Party>
HEDLEY_NO_THROW
@ -76,6 +77,7 @@ auto aes<AesKey>::expand(block_type seed, psnip_uint32_t pos) noexcept
return detail::expand_as_share<aes<AesKey>, T, Party>(seed, pos);
}
/// \complexity `ceil(sizeof(T) / sizeof(block_type))` PRG evaluations (`expand_raw`), then a copy.
template <typename T, std::size_t Party>
HEDLEY_NO_THROW
auto dummy::expand(block_type seed, psnip_uint32_t pos) noexcept
@ -83,6 +85,7 @@ auto dummy::expand(block_type seed, psnip_uint32_t pos) noexcept
return detail::expand_as_share<dummy, T, Party>(seed, pos);
}
/// \complexity `ceil(sizeof(T) / sizeof(block_type))` PRG evaluations (`expand_raw`), then a copy.
template <typename T, std::size_t Party>
HEDLEY_NO_THROW
auto lowmc128::expand(block_type seed, psnip_uint32_t pos) noexcept
@ -90,6 +93,7 @@ auto lowmc128::expand(block_type seed, psnip_uint32_t pos) noexcept
return detail::expand_as_share<lowmc128, T, Party>(seed, pos);
}
/// \complexity `ceil(sizeof(T) / sizeof(block_type))` PRG evaluations (`expand_raw`), then a copy.
template <typename T, std::size_t Party>
HEDLEY_NO_THROW
auto aes128_ccr::expand(block_type seed, psnip_uint32_t pos) noexcept
@ -97,6 +101,7 @@ auto aes128_ccr::expand(block_type seed, psnip_uint32_t pos) noexcept
return detail::expand_as_share<aes128_ccr, T, Party>(seed, pos);
}
/// \complexity `ceil(sizeof(T) / sizeof(block_type))` PRG evaluations (`expand_raw`), then a copy.
template <unsigned Rounds>
template <typename T, std::size_t Party>
HEDLEY_NO_THROW
@ -105,6 +110,9 @@ auto chacha<Rounds>::expand(block_type seed, psnip_uint32_t pos) noexcept
return detail::expand_as_share<chacha<Rounds>, T, Party>(seed, pos);
}
/// @brief PRG adapter that exposes the shared TLS eval counter.
/// @details Counting lives in the concrete `PRG::eval` paths via
/// `note_eval`. This wrapper forwards and reports `eval_count()`.
template <typename PRG>
struct counter_wrapper final
{
@ -114,7 +122,6 @@ struct counter_wrapper final
HEDLEY_ALWAYS_INLINE
static block_type eval(block_type seed, psnip_uint32_t pos) noexcept
{
count_.fetch_add(1, std::memory_order::memory_order_relaxed);
return PRG::eval(seed, pos);
}
@ -122,7 +129,6 @@ struct counter_wrapper final
HEDLEY_ALWAYS_INLINE
static auto eval01(block_type seed) noexcept
{
count_.fetch_add(2, std::memory_order::memory_order_relaxed);
return PRG::eval01(seed);
}
@ -130,12 +136,6 @@ struct counter_wrapper final
static void eval(block_type seed, block_type * HEDLEY_RESTRICT output,
psnip_uint32_t count, psnip_uint32_t pos = 0)
{
if (count > 1 &&
pos > static_cast<psnip_uint32_t>(~static_cast<psnip_uint32_t>(0)) - (count - 1u))
{
throw std::invalid_argument("prg lane index is out of range");
}
count_.fetch_add(count, std::memory_order::memory_order_relaxed);
PRG::eval(seed, output, count, pos);
}
@ -146,7 +146,6 @@ struct counter_wrapper final
block_type * HEDLEY_RESTRICT left,
block_type * HEDLEY_RESTRICT right) noexcept
{
count_.fetch_add(8, std::memory_order::memory_order_relaxed);
PRG::eval01_x4(seeds, left, right);
}
@ -156,7 +155,6 @@ struct counter_wrapper final
static void eval_x4(const block_type * HEDLEY_RESTRICT seeds,
block_type * HEDLEY_RESTRICT output, psnip_uint32_t pos = 0) noexcept
{
count_.fetch_add(4, std::memory_order::memory_order_relaxed);
PRG::eval_x4(seeds, output, pos);
}
@ -166,7 +164,6 @@ struct counter_wrapper final
static void eval_x8(const block_type * HEDLEY_RESTRICT seeds,
block_type * HEDLEY_RESTRICT output, psnip_uint32_t pos = 0) noexcept
{
count_.fetch_add(8, std::memory_order::memory_order_relaxed);
PRG::eval_x8(seeds, output, pos);
}
@ -175,10 +172,6 @@ struct counter_wrapper final
HEDLEY_ALWAYS_INLINE
static auto expand(block_type seed, psnip_uint32_t pos = 0) noexcept
{
count_.fetch_add(
static_cast<std::size_t>(
(sizeof(T) + sizeof(block_type) - 1) / sizeof(block_type)),
std::memory_order::memory_order_relaxed);
return detail::expand_as_share<PRG, T, Party>(seed, pos);
}
@ -186,11 +179,15 @@ struct counter_wrapper final
HEDLEY_ALWAYS_INLINE
static std::size_t count() noexcept
{
return count_;
return static_cast<std::size_t>(eval_count());
}
private:
inline static std::atomic_size_t count_{0};
HEDLEY_NO_THROW
HEDLEY_ALWAYS_INLINE
static void reset() noexcept
{
reset_eval_count();
}
}; // struct counter_wrapper
} // namespace prg