Checkpoint the party/runtime stack before share-program and malicious-mode work.

Ship the TLS mesh, composer, Beaver/Yao/leaf MPC, prep/online paths, apps, and docs so the tree is pushable before elevating share_expr, security_mode, and prep resume.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Ryan Henry 2026-09-28 05:59:19 -06:00
parent 695f8e84f7
commit 0d22946a0e
1835 changed files with 170291 additions and 2849 deletions

View file

@ -39,7 +39,7 @@ namespace detail
/// @brief Integer value of an already-rounded finite double, as a 256-bit word.
/// Values that do not fit saturate to all-ones.
/// @param rounded the `rounded`
/// @param rounded already-rounded finite double
/// @return Integer value of an already-rounded finite double, as a 256-bit word
HEDLEY_NO_THROW
inline uint256_t uint256_from_rounded_double(double rounded) noexcept
@ -102,7 +102,7 @@ struct is_static_castable<To, From,
/// @brief Low `bits` of `wide`, saturated to all-ones when `wide` does not fit.
/// @tparam Raw underlying representation
/// @tparam Bits bits
/// @param wide the `wide`
/// @param wide wide integer before it is narrowed
/// @return Low `bits` of `wide`, saturated to all-ones when `wide` does not fit
template <typename Raw, std::size_t Bits>
HEDLEY_NO_THROW
@ -212,7 +212,7 @@ inline IntegralType rounded_double_to_integral(double rounded) noexcept
/// @tparam IntegralType underlying integral type
/// @tparam FractionalBits number of fractional bits
/// @tparam T value type
/// @param integer_value the `integer_value`
/// @param integer_value mathematical integer; stored as `integer_value << FractionalBits`
/// @return the returned `IntegralType`
template <typename IntegralType,
unsigned FractionalBits,
@ -240,7 +240,7 @@ inline constexpr bool is_signed_rep_v =
/// @brief Two's-complement negate via the unsigned width. Defined for the
/// most-negative value (wraps); signed `-x` would be UB there.
/// @tparam IntegralType underlying integral type
/// @param x the `x`
/// @param x the input value
/// @return Two's-complement negate via the unsigned width
template <typename IntegralType>
HEDLEY_ALWAYS_INLINE
@ -269,8 +269,8 @@ constexpr IntegralType raw_abs(IntegralType x) noexcept
/// @brief Remainder with the sign of `a` and magnitude `< |b|` (C++ `%` /
/// `std::fmod`). Zero divisor → 0; this type has no NaN.
/// @tparam IntegralType underlying integral type
/// @param a the `a`
/// @param b the `b`
/// @param a left-hand operand
/// @param b right-hand operand
/// @return Remainder with the sign of `a` and magnitude `< |b|` (C++ `%` / `std::fmod`)
template <typename IntegralType>
HEDLEY_ALWAYS_INLINE
@ -292,10 +292,20 @@ template <unsigned FractionalBits,
HEDLEY_NO_THROW
auto constexpr make_fixed_from_integral_type(IntegralType value) noexcept;
/// @tparam FractionalBits Number of fractional bits used in the fixed-point
/// @brief representation.
/// @tparam IntegralType The underlying integral type used for the fixed-point
/// representation.
/// @brief Fixed-point value with `FractionalBits` bits after the binary point.
/// @tparam FractionalBits Number of fractional bits. A DPF on this type has
/// depth equal to the backend width, not `FractionalBits`.
/// @tparam IntegralType Backend word. Defaults to `uint64_t`, so
/// `fixedpoint<16>` is a Q48.16 value.
/// @note `fixedpoint(3)` is the mathematical value 3, stored as
/// `3 << FractionalBits`. It is not a raw word. `from_raw` is bit-exact.
/// @note Leaf addition, subtraction, and multiplication act on that raw word
/// and do not shift the binary point. See `dpf::leaf_arithmetic`.
/// @note A signed backend flips the MSB when the value is a DPF input
/// (`dpf::utils::flip_msb_for_input`).
/// @see grotto::fixed_mul
/// @see [Input types](@ref input_types)
/// @see [Output types](@ref output_types)
template <unsigned FractionalBits,
typename IntegralType = GROTTO_FIXED_DEFAULT_INTEGRAL_REPRESENTATION>
struct fixedpoint
@ -341,7 +351,7 @@ public:
/// @brief Value c'tor
/// @details Initializes the fixed-point with the value determined by `desired`, using the <a href="https://en.cppreference.com/w/cpp/numeric/fenv/FE_round">current rounding mode</a> for the least-significant bit.
/// @param desired the `desired`
/// @param desired real value, rounded with the current rounding mode
HEDLEY_ALWAYS_INLINE
HEDLEY_NO_THROW
constexpr fixedpoint(double desired) noexcept // NOLINT (implicit c'tor)
@ -355,7 +365,7 @@ public:
/// Use `from_raw` for a bit-exact encoding.
/// @tparam T value type
/// @tparam T value type
/// @param integer_value the `integer_value`
/// @param integer_value mathematical integer; stored as `integer_value << FractionalBits`
template <typename T,
std::enable_if_t<
std::is_integral_v<T>
@ -370,6 +380,9 @@ public:
/// @brief Bit-exact construction from the backend integer encoding.
/// @param raw the underlying integer
/// @return Bit-exact construction from the backend integer encoding
/// \complexity `Θ(1)`. Copies the backend word. No shift and no rounding.
/// @note Bit-exact. Unlike `fixedpoint(3)`, this does not mean the mathematical value `raw`.
/// @see grotto::fixedpoint
HEDLEY_ALWAYS_INLINE
HEDLEY_NO_THROW
static constexpr fixedpoint from_raw(integral_type raw) noexcept
@ -401,7 +414,7 @@ public:
/// @brief Value assignment
/// @details Assigns the fixed-point with a value determined by `desired`, using the <a href="https://en.cppreference.com/w/cpp/numeric/fenv/FE_round">current rounding mode</a> for the least-significant bit..
/// @param desired the `desired`
/// @param desired real value, rounded with the current rounding mode
/// @return `*this`
HEDLEY_ALWAYS_INLINE
HEDLEY_NO_THROW
@ -557,6 +570,9 @@ public:
/// @details Computes the sum of two fixed-point numbers
/// @param rhs the right-hand operand
/// @return Binary addition operator
/// \complexity One backend-word operation. `Θ(1)` time and extra space in that word width.
/// @note Same-scale addition and subtraction add the raw words. That is the fixed-point sum; the binary point does not move.
/// @see grotto::fixed_mul
HEDLEY_ALWAYS_INLINE
HEDLEY_NO_THROW
HEDLEY_PURE
@ -579,6 +595,9 @@ public:
/// @brief Binary subtraction operator
/// @param rhs the right-hand operand
/// @return Binary subtraction operator
/// \complexity One backend-word operation. `Θ(1)` time and extra space in that word width.
/// @note Same-scale addition and subtraction add the raw words. That is the fixed-point sum; the binary point does not move.
/// @see grotto::fixed_mul
HEDLEY_ALWAYS_INLINE
HEDLEY_NO_THROW
HEDLEY_PURE
@ -602,6 +621,11 @@ public:
/// @tparam FractionalBits1 fractional bits1
/// @param rhs the right-hand operand
/// @return Binary multiplication operator
/// \complexity One product of the raw backend words. The result is `make_fixed_from_integral_type` at `FractionalBits + FractionalBits1` fractional bits.
/// `Θ(1)` in the backend width (the 64-bit or 128-bit branch in `multiplies` is the rescaling multiply; this operator does not loop).
/// @note This is not leaf multiply. Leaf multiply stays on the raw word and does not change `FractionalBits`.
/// @see grotto::fixed_mul
/// @see grotto::fixedpoint
template <unsigned FractionalBits1>
HEDLEY_ALWAYS_INLINE
HEDLEY_NO_THROW
@ -751,7 +775,7 @@ public:
// struct make_fixed_from_integral_type_tag {};
/// @brief Determine if a floating-point is within range
/// @param d the `d`
/// @param d real value
/// @return Determine if a floating-point is within range
HEDLEY_ALWAYS_INLINE
HEDLEY_NO_THROW
@ -790,7 +814,7 @@ public:
/// @tparam IntegralType underlying integral type
/// @tparam Mask mask
/// @param mask the bit mask
/// @param x the `x`
/// @param x the input value
/// @return Bit test with the mask on the left
template <unsigned FractionalBits,
typename IntegralType,
@ -829,6 +853,14 @@ operator>>(std::basic_istream<CharT, Traits> & is,
return is;
}
/// @brief Bit-exact fixed-point from a backend word.
/// @tparam FractionalBits number of fractional bits
/// @tparam IntegralType backend word type
/// @param value the raw encoding, not the mathematical integer
/// @return `fixedpoint::from_raw(value)`
/// @note This does not shift by `FractionalBits`. `make_fixed_from_integral_type(1)` is the raw word 1, whereas `fixedpoint(1)` is the value 1.
/// @see grotto::fixedpoint::from_raw
/// \complexity `Θ(1)`. One `from_raw`.
template <unsigned FractionalBits,
typename IntegralType>
HEDLEY_NO_THROW
@ -836,6 +868,9 @@ auto constexpr make_fixed_from_integral_type(IntegralType value) noexcept
{
return fixedpoint<FractionalBits, IntegralType>::from_raw(value);
}
/// \complexity One scale by `2^{FractionalBits}` (`ldexp`) and `nearbyint` under the current rounding mode. `Θ(1)`.
/// @note This is the real value, same as `fixedpoint(double)`. It is not `from_raw`.
/// @see grotto::fixedpoint
template <unsigned FractionalBits,
typename IntegralType = GROTTO_FIXED_DEFAULT_INTEGRAL_REPRESENTATION>
@ -845,6 +880,9 @@ static constexpr auto make_fixed(double d)
{
return fixedpoint<FractionalBits, IntegralType>(d);
}
/// \complexity One scale by `2^{FractionalBits}` (`ldexp`) and `nearbyint` under the current rounding mode. `Θ(1)`.
/// @note This is the real value, same as `fixedpoint(double)`. It is not `from_raw`.
/// @see grotto::fixedpoint
template <typename FixedType>
HEDLEY_ALWAYS_INLINE
@ -857,10 +895,12 @@ static constexpr auto make_fixed(double d)
/// @brief Creates a fixed-point number from a double with bounds checking.
/// @tparam FractionalBits number of fractional bits
/// @tparam IntegralType underlying integral type
/// @param d the `d`
/// @param d real value
/// @return Creates a fixed-point number from a double with bounds checking
/// @throws std::range_error if the input double is outside the representable
/// range of the fixed-point number.
/// \complexity Two comparisons against `numeric_limits`, then one `make_fixed`. `Θ(1)`.
/// @see grotto::make_fixed
template <unsigned FractionalBits,
typename IntegralType = GROTTO_FIXED_DEFAULT_INTEGRAL_REPRESENTATION>
HEDLEY_ALWAYS_INLINE
@ -881,6 +921,8 @@ static auto make_fixed_safe(double d)
return make_fixed<FractionalBits, IntegralType>(d);
}
/// \complexity One left or right shift of the raw word by the difference of the fractional widths. No rounding step. `Θ(1)`.
/// @see grotto::fixedpoint
template <unsigned ToFractionalBits,
unsigned FromFractionalBits,
@ -906,6 +948,8 @@ static constexpr auto precision_of(fixedpoint<FractionalBits, IntegralType>) noe
{
return FractionalBits;
}
/// \complexity Adds one to the raw word (one ULP). `Θ(1)`.
/// @see grotto::fixedpoint
template <unsigned FractionalBits,
typename IntegralType>
@ -916,6 +960,8 @@ constexpr auto nextafter(fixedpoint<FractionalBits, IntegralType> f) noexcept
{
return make_fixed_from_integral_type<FractionalBits, IntegralType>(f.integral_representation()+1);
}
/// \complexity Subtracts one from the raw word (one ULP). `Θ(1)`.
/// @see grotto::fixedpoint
template <unsigned FractionalBits,
typename IntegralType>
@ -926,6 +972,8 @@ constexpr auto nextbefore(fixedpoint<FractionalBits, IntegralType> f) noexcept
{
return make_fixed_from_integral_type<FractionalBits, IntegralType>(f.integral_representation()-1);
}
/// \complexity Two's-complement absolute value of the raw word via `raw_neg` when the backend is signed. `Θ(1)`.
/// @see grotto::fixedpoint
template <unsigned FractionalBits,
typename IntegralType>
@ -946,6 +994,8 @@ constexpr auto fabs(fixedpoint<FractionalBits, IntegralType> v) noexcept
}
return v;
}
/// \complexity `raw_fmod` on the backend words: remainder with the sign of the dividend. `Θ(1)` word operations. A zero modulus returns 0.
/// @see grotto::fixedpoint
template <unsigned FractionalBits,
typename IntegralType>
@ -959,6 +1009,8 @@ constexpr auto fmod(fixedpoint<FractionalBits, IntegralType> v,
detail::raw_fmod(v.integral_representation(),
modulus.integral_representation()));
}
/// \complexity `raw_fmod` on the backend words: remainder with the sign of the dividend. `Θ(1)` word operations. A zero modulus returns 0.
/// @see grotto::fixedpoint
template <unsigned FractionalBits,
typename IntegralType>
@ -970,6 +1022,8 @@ constexpr auto fmod(fixedpoint<FractionalBits, IntegralType> v,
{
return fmod(v, make_fixed<FractionalBits, IntegralType>(modulus));
}
/// \complexity `raw_fmod` on the backend words: remainder with the sign of the dividend. `Θ(1)` word operations. A zero modulus returns 0.
/// @see grotto::fixedpoint
template <unsigned FractionalBits,
typename IntegralType,
@ -996,6 +1050,12 @@ enum fixed_cast_policy
use_arg_sum //< for multiplies only
};
/// @brief Apply `BinaryOperator` after casting both fixed-point arguments to one fractional width.
/// @tparam BinaryOperator operation applied after the cast
/// @tparam Mode which operand's fractional width wins (`use_max_arg` by default)
/// @see grotto::precision_cast
/// @see grotto::multiplies
/// \complexity One `precision_cast` (a raw shift) when the fractional widths differ, then one call of `BinaryOperator`. `Θ(1)`.
template <typename BinaryOperator,
fixed_cast_policy Mode = use_max_arg>
struct binary_operator_precast_wrapper
@ -1042,6 +1102,12 @@ struct binary_operator_precast_wrapper
}
};
/// @brief Fixed-point product that chooses how many fractional bits to keep.
/// @tparam Mode which operand's fractional width the product uses; `use_arg_sum` keeps both
/// @see grotto::fixed_mul
/// @see grotto::fixedpoint
/// @note The raw product is shifted so the binary point matches `Mode`. That is a rescale. Leaf multiply does not do this.
/// \complexity One backend multiply (64-bit or 128-bit branch) and one shift. `Θ(1)` time and extra space.
template <fixed_cast_policy Mode = use_arg_sum>
struct multiplies
{
@ -1123,6 +1189,12 @@ struct multiplies
}
};
/// @name Comparisons with double on the left
/// @brief `double` compared with `fixedpoint` by reversing the member operator.
/// \complexity One call to the matching member comparison. `Θ(1)`.
/// @see grotto::fixedpoint
/// @{
template <unsigned FractionalBits,
typename IntegralType>
HEDLEY_ALWAYS_INLINE
@ -1173,6 +1245,13 @@ constexpr bool operator>=(double lhs, fixedpoint<FractionalBits, IntegralType> r
return (rhs <= lhs);
}
/// @}
/// @brief Horner polynomial in `fixedpoint` coefficients, constant term at index 0.
/// @tparam FixedPointType coefficient type
/// @tparam Degree number of coefficients (degree is one less when `Degree > 0`)
/// @see grotto::multiplies
/// \complexity `operator()` walks the coefficients once: `Θ(Degree)` fixed-point multiplies and adds. Extra space `Θ(1)`.
template <typename FixedPointType,
std::size_t Degree>
struct fixedpoint_polynomial : public std::array<FixedPointType, Degree>
@ -1203,6 +1282,20 @@ static constexpr auto evaluate(const fixedpoint_polynomial<FixedPointType, Degre
namespace fixedpoint_literals
{
/// @name Fixed-point literals
/// @brief `_fixed0` through `_fixed64` in `grotto::fixedpoint_literals`.
///
/// `1.5_fixed16` is `fixedpoint<16>` holding the value 1.5, via
/// `make_fixed<16>`. It is not a raw word. The DPF depth of the
/// result is the backend width (64 bits for the default), not `N`.
/// @param val the `long double` literal
/// @return `fixedpoint<N>` for the suffix `_fixedN`
/// @see grotto::make_fixed
/// @see grotto::fixedpoint
/// \complexity Each literal is one call to `make_fixed` (scale by
/// `2^N` and round). `Θ(1)` time and extra space. No protocol.
/// @{
constexpr auto operator "" _fixed0(long double val)
{
return grotto::make_fixed<0>(val);
@ -1497,6 +1590,8 @@ constexpr auto operator "" _fixed64(long double val)
return grotto::make_fixed<64>(val);
}
/// @}
} // namespace grotto::fixedpoint_literals
} // namespace grotto
@ -1597,6 +1692,9 @@ struct make_from_integral_value<grotto::fixedpoint<FractionalBits, IntegralType>
static_cast<IntegralType>(val));
}
};
/// \complexity One XOR of `msb_of_v<IntegralType>` into the raw word when `uses_signed_msb_v` is true. `Θ(1)`.
/// @note Signed backends flip that MSB on the way into a DPF input. Unsigned backends do not.
/// @see grotto::fixedpoint
template <unsigned FractionalBits,
typename IntegralType>
@ -1623,6 +1721,11 @@ struct flip_msb_for_input<grotto::fixedpoint<FractionalBits, IntegralType>>
namespace dpf::leaf_arithmetic
{
/// \complexity One SIMD 128-bit add of the raw backend words (`integral_representation()` for multiply).
/// `Θ(1)` time and extra space.
/// @note Does not shift by `FractionalBits`. The binary point of the leaf word stays where it was.
/// @see grotto::fixedpoint
/// @see grotto::fixed_mul
HEDLEY_PRAGMA(GCC diagnostic push)
HEDLEY_PRAGMA(GCC diagnostic ignored "-Wignored-attributes")
@ -1634,6 +1737,11 @@ struct add_t<grotto::fixedpoint<FractionalBits, IntegralType>, simde__m128i>
return add_t<IntegralType, simde__m128i>{}(a, b);
}
};
/// \complexity One SIMD 256-bit add of the raw backend words (`integral_representation()` for multiply).
/// `Θ(1)` time and extra space.
/// @note Does not shift by `FractionalBits`. The binary point of the leaf word stays where it was.
/// @see grotto::fixedpoint
/// @see grotto::fixed_mul
template <unsigned FractionalBits, typename IntegralType>
struct add_t<grotto::fixedpoint<FractionalBits, IntegralType>, simde__m256i>
@ -1643,6 +1751,11 @@ struct add_t<grotto::fixedpoint<FractionalBits, IntegralType>, simde__m256i>
return add_t<IntegralType, simde__m256i>{}(a, b);
}
};
/// \complexity One SIMD 128-bit subtract of the raw backend words (`integral_representation()` for multiply).
/// `Θ(1)` time and extra space.
/// @note Does not shift by `FractionalBits`. The binary point of the leaf word stays where it was.
/// @see grotto::fixedpoint
/// @see grotto::fixed_mul
template <unsigned FractionalBits, typename IntegralType>
struct subtract_t<grotto::fixedpoint<FractionalBits, IntegralType>, simde__m128i>
@ -1652,6 +1765,11 @@ struct subtract_t<grotto::fixedpoint<FractionalBits, IntegralType>, simde__m128i
return subtract_t<IntegralType, simde__m128i>{}(a, b);
}
};
/// \complexity One SIMD 256-bit subtract of the raw backend words (`integral_representation()` for multiply).
/// `Θ(1)` time and extra space.
/// @note Does not shift by `FractionalBits`. The binary point of the leaf word stays where it was.
/// @see grotto::fixedpoint
/// @see grotto::fixed_mul
template <unsigned FractionalBits, typename IntegralType>
struct subtract_t<grotto::fixedpoint<FractionalBits, IntegralType>, simde__m256i>
@ -1661,6 +1779,11 @@ struct subtract_t<grotto::fixedpoint<FractionalBits, IntegralType>, simde__m256i
return subtract_t<IntegralType, simde__m256i>{}(a, b);
}
};
/// \complexity One SIMD 128-bit multiply of the raw backend words (`integral_representation()` for multiply).
/// `Θ(1)` time and extra space.
/// @note Does not shift by `FractionalBits`. The binary point of the leaf word stays where it was.
/// @see grotto::fixedpoint
/// @see grotto::fixed_mul
template <unsigned FractionalBits, typename IntegralType>
struct multiply_t<grotto::fixedpoint<FractionalBits, IntegralType>, simde__m128i>
@ -1671,6 +1794,11 @@ struct multiply_t<grotto::fixedpoint<FractionalBits, IntegralType>, simde__m128i
return multiply_t<IntegralType, simde__m128i>{}(a, b.integral_representation());
}
};
/// \complexity One SIMD 256-bit multiply of the raw backend words (`integral_representation()` for multiply).
/// `Θ(1)` time and extra space.
/// @note Does not shift by `FractionalBits`. The binary point of the leaf word stays where it was.
/// @see grotto::fixedpoint
/// @see grotto::fixed_mul
template <unsigned FractionalBits, typename IntegralType>
struct multiply_t<grotto::fixedpoint<FractionalBits, IntegralType>, simde__m256i>