Checkpoint the party/runtime stack before share-program and malicious-mode work.

Ship the TLS mesh, composer, Beaver/Yao/leaf MPC, prep/online paths, apps, and docs so the tree is pushable before elevating share_expr, security_mode, and prep resume.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Ryan Henry 2026-09-28 05:59:19 -06:00
parent 695f8e84f7
commit 0d22946a0e
1835 changed files with 170291 additions and 2849 deletions

View file

@ -1,4 +1,5 @@
#include <gtest/gtest.h>
#include <tuple>
#include "dpf.hpp"
@ -349,6 +350,10 @@ TEST(Geneval, FullDomainUint8)
}
EXPECT_EQ(recon(g.party0[alpha], g.party1[alpha]), y);
EXPECT_EQ(recon(g.party0[0], g.party1[0]), out_t{0});
EXPECT_TRUE(dpf::verify(g.proof0, g.proof1));
EXPECT_NE(recon(g.party1[alpha], g.party0[alpha]), y);
g.proof0[0] = simde_mm_xor_si128(g.proof0[0], simde_mm_set1_epi8(1));
EXPECT_FALSE(dpf::verify(g.proof0, g.proof1));
}
TEST(Geneval, EmptySequence)
@ -796,10 +801,10 @@ TEST(Geneval, FullMatchesWholeIntervalAndRejectsHugeDomain)
EXPECT_EQ(recon(full.party0[255], full.party1[255]), y);
EXPECT_EQ(recon(full.party0[0], full.party1[0]), out_t{0});
EXPECT_THROW((dpf::geneval_full(uint32_t{1}, uint32_t{2}, rng<uint32_t>(),
uint32_t{1})), std::length_error);
EXPECT_THROW((dpf::geneval_interval(in_t{5}, in_t{1}, in_t{4}, in_t{3},
rng<in_t>(), y)), std::invalid_argument);
EXPECT_THROW(dpf::geneval_full(uint32_t{1}, uint32_t{2}, rng<uint32_t>(),
uint32_t{1}), std::length_error);
EXPECT_THROW(dpf::geneval_interval(in_t{5}, in_t{1}, in_t{4}, in_t{3},
rng<in_t>(), y), std::invalid_argument);
}
TEST(Geneval, SequencePermutationKeepsWordsAndDuplicates)
@ -981,8 +986,8 @@ TEST(Geneval, ArithShareOverflowAndWrappingInterval)
in_t from = 250;
in_t to = 10;
EXPECT_THROW((dpf::geneval_interval(dpf::arith_input, x0, x1, from, to,
rng<in_t>(), y)), std::invalid_argument);
EXPECT_THROW(dpf::geneval_interval(dpf::arith_input, x0, x1, from, to,
rng<in_t>(), y), std::invalid_argument);
from = 250;
to = 255;
@ -1043,8 +1048,8 @@ TEST(Geneval, SignedRegressionsFromTheCornerPass)
out_t y = -7;
// An inverted signed range must not wrap the long way around.
EXPECT_THROW((dpf::geneval_interval(in_t{2}, in_t{1}, in_t{4}, in_t{-3},
rng<in_t>(), y)), std::invalid_argument);
EXPECT_THROW(dpf::geneval_interval(in_t{2}, in_t{1}, in_t{4}, in_t{-3},
rng<in_t>(), y), std::invalid_argument);
// [INT_MIN, INT_MAX] is numeric order; full is bit-pattern order.
// The words are the same trie. Each input's share matches either way.
@ -1402,3 +1407,37 @@ TEST(Geneval, ArithDoernerShelatAndCmpMatchDealer)
EXPECT_EQ(opened, ends[i] > secret ? beta : 0u) << int(ends[i]);
}
}
TEST(Geneval, ArithCarryLeavesXorShares)
{
// 250 + 13 = 7 (mod 256). The carry must not collapse the sharing to (7, 0).
auto split_u8 = [](std::uint64_t seed) {
Pad pad;
pad.n = seed;
dpf::detail::local_cw_protocol<Pad> proto{pad};
std::uint8_t x0 = 250;
std::uint8_t x1 = 13;
proto.encode_walk_shares(x0, x1, true);
// Seven carries. Each is one bit-Beaver from `sample_beaver2` on
// `xor_wrapper<uint8_t>`: `sample_fresh<2>` draws 7 ring elements
// and each element is 8 pad bits.
EXPECT_EQ(pad.n, seed + 7u * 7u * 8u);
EXPECT_EQ(static_cast<std::uint8_t>(x0 ^ x1), 7);
EXPECT_NE(x1, 0);
EXPECT_NE(x0, 7);
};
split_u8(1);
split_u8(50);
Pad pad;
dpf::detail::local_cw_protocol<Pad> proto{pad};
const std::int8_t secret = -20;
std::int8_t a0 = 100;
std::int8_t a1 = static_cast<std::int8_t>(secret - a0);
std::int8_t encoded = secret;
dpf::utils::flip_msb_if_signed_integral(encoded);
proto.encode_walk_shares(a0, a1, true);
EXPECT_EQ(static_cast<std::uint8_t>(a0) ^ static_cast<std::uint8_t>(a1),
static_cast<std::uint8_t>(encoded));
EXPECT_NE(a1, 0);
}