Checkpoint the party/runtime stack before share-program and malicious-mode work.

Ship the TLS mesh, composer, Beaver/Yao/leaf MPC, prep/online paths, apps, and docs so the tree is pushable before elevating share_expr, security_mode, and prep resume.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Ryan Henry 2026-09-28 05:59:19 -06:00
parent 695f8e84f7
commit 0d22946a0e
1835 changed files with 170291 additions and 2849 deletions

View file

@ -29,11 +29,13 @@ namespace grotto
/// integer part. Both discards are the low or high residue modulo a power of
/// two, so a negative value is floored onto the output ulp.
///
/// A Beaver triple replaces only the multiply in `Z/2^multiply_bits Z`.
/// Reducing each operand into that ring is local when it is a truncation or a
/// zero-extend. Sign-extending a narrower signed operand, and replicating the
/// product sign when `modulus_bits > multiply_bits`, are plaintext steps the
/// MPC protocol has to reproduce (they are not local on additive shares).
/// A Beaver triple replaces only the multiply in `Z/2^multiply_bits Z`
/// (`grotto::eval_fixed_mul_beaver`). Dropping bits above that ring is local.
/// A narrower share is lifted by cancelling the carry out of the operand
/// width; a signed lift also replicates the sign. The same correction
/// replicates the product sign when `modulus_bits > multiply_bits` and
/// supplies the right shift by `align_shift`. Each of those lifts extends
/// by at most 64 bits, and the shift discards at most 64 bits.
/// @tparam IntegerBits number of integer bits, including the sign
/// @tparam FractionalBits number of fractional bits
/// @tparam LhsFractionalBits lhs fractional bits
@ -206,11 +208,11 @@ constexpr void store_raw_limbs(const T & value, std::uint64_t out[4]) noexcept
/// @brief Low `dest_bits` of `value`, sign-extended when `value` is a narrower signed integer.
/// @tparam T value type
/// @param value the value to convert or store
/// @param src_bits the `src_bits`
/// @param is_signed the `is_signed`
/// @param dest_bits the `dest_bits`
/// @param src_bits width of `value` before extension
/// @param is_signed whether `value` is a signed integer of `src_bits` bits
/// @param dest_bits width of the destination word
/// @param dest the destination
/// @param nlimbs the `nlimbs`
/// @param nlimbs number of 64-bit limbs kept in the product
template <typename T>
HEDLEY_NO_THROW
constexpr void reduce_operand(const T & value, unsigned src_bits, bool is_signed,
@ -239,7 +241,7 @@ constexpr void reduce_operand(const T & value, unsigned src_bits, bool is_signed
/// @param out the output buffer
/// @param lhs the left-hand operand
/// @param rhs the right-hand operand
/// @param nlimbs the `nlimbs`
/// @param nlimbs number of 64-bit limbs kept in the product
HEDLEY_NO_THROW
constexpr void mul_low_limbs(std::uint64_t * out, const std::uint64_t * lhs,
const std::uint64_t * rhs, unsigned nlimbs) noexcept
@ -360,6 +362,11 @@ constexpr T limbs_to_integral(const std::uint64_t * limbs) noexcept
/// @param lhs the left-hand operand
/// @param rhs the right-hand operand
/// @return the product at the requested width
/// \complexity `mul_low_limbs` multiplies `L` 64-bit limbs, `L = fixed_mul_plan::limbs`, with loops `i < L` and `i + j < L`: `Θ(L²)` limb products.
/// Reducing each operand and the align shift are `Θ(L)`. Scratch is a fixed limb buffer in this header (the 8-word arrays plus `fixed_mul_buf_limbs`).
/// @see grotto::fixedpoint
/// @note Plaintext. `grotto::eval_fixed_mul_beaver` is the same window on additive shares: one Beaver product in `Z/2^{multiply_bits}Z`, then the lifts and the aligning shift.
/// @see grotto::eval_fixed_mul_beaver
template <unsigned IntegerBits,
unsigned FractionalBits,
unsigned LhsFractionalBits,