Checkpoint the party/runtime stack before share-program and malicious-mode work.

Ship the TLS mesh, composer, Beaver/Yao/leaf MPC, prep/online paths, apps, and docs so the tree is pushable before elevating share_expr, security_mode, and prep resume.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Ryan Henry 2026-09-28 05:59:19 -06:00
parent 695f8e84f7
commit 0d22946a0e
1835 changed files with 170291 additions and 2849 deletions

View file

@ -12,6 +12,7 @@
#include <array>
#include <cstddef>
#include <cstdint>
#include <cstring>
#include <type_traits>
#include <utility>
@ -27,6 +28,12 @@ namespace dpf
/// @brief `N` lanes of `T`, combined componentwise with no carry between lanes.
/// @tparam T lane type. Its `+`, `-`, and `*` are used per lane
/// @tparam N number of lanes
/// @note Not a DPF domain. Lane 0 is the least-significant lane. `operator+`
/// is one operation of `T` per lane, O(N), and does not carry.
/// @see dpf::twobit
/// @see dpf::nyble
/// @see dpf::modint
/// @see dpf::xint
template <typename T, std::size_t N>
struct vec
{
@ -44,6 +51,43 @@ struct vec
HEDLEY_NO_THROW
constexpr vec() noexcept = default;
/// @brief Stretch a PRG block into one group element, lane 0 first.
/// @details Deterministic. Comparison keygen calls this on each child
/// node, so both parties derive the same element. Extra lanes are a
/// public mix of that block, not a second tree.
/// @param bytes the PRG output
/// @param n the number of bytes available
/// @return the vector
HEDLEY_NO_THROW
static vec from_seed(const void * bytes, std::size_t n) noexcept
{
unsigned char block[16]{};
if (bytes != nullptr && n != 0)
std::memcpy(block, bytes, n < sizeof(block) ? n : sizeof(block));
std::uint64_t s0 = 0;
std::uint64_t s1 = 0;
std::memcpy(&s0, block, 8);
std::memcpy(&s1, block + 8, 8);
auto rotl = [](std::uint64_t x, int k) noexcept {
return (x << k) | (x >> (64 - k));
};
vec out;
auto * dst = reinterpret_cast<unsigned char *>(out.lanes.data());
std::size_t filled = 0;
constexpr std::size_t need = sizeof(out.lanes);
while (filled < need)
{
const std::uint64_t r = s0 + s1;
s1 ^= s0;
s0 = rotl(s0, 24) ^ s1 ^ (s1 << 16);
s1 = rotl(s1, 37);
const std::size_t take = std::min<std::size_t>(8, need - filled);
std::memcpy(dst + filled, &r, take);
filled += take;
}
return out;
}
/// @brief Mutable lane `i`.
/// @param i the lane index
/// @return a reference to that lane