Repository navigation
feat(zk-verifier): register a native Groth16 host function (register_only) - #163
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
feat(zk-verifier): register a native Groth16 host function (register_only)
Node 0.4.0 registers
bn254_groth16_verify, which runs Groth16 verification natively from a key in its prepared form (#162). No runtime calls it yet: it ships#[version(1, register_only)], the patternsp-iouses to introduce host functions. Spec 19 turns it on once every node runs a release that has it.Why two steps
A runtime that imports a host function the node lacks cannot be instantiated: that node stops importing at the upgrade block, for good. Reproduced on a dev node:
runtime requires function imports which are not present on the host: 'env:ext_groth_16_host_interface_bn254_groth16_verify_version_1', stuck at the upgrade block. So:lastAuthorVersion); Root setssetMinAuthorVersion(0.4.0); RPC and archive operators upgraderegister_onlyand calls itWhat changes
orbinum-zk-verifier3.2.0:host_interface(featuregroth16-native, indefault):Groth16HostInterface::bn254_groth16_verify(prepared_vk, proof, inputs) -> bool.#[version(2)], and version 1 is never edited or removed, because syncing nodes re-execute blocks that call it.verify_prepared(prepared_vk, proof, inputs): the one verification both paths run (the runtime in Wasm today, the node behind the host function in spec 19), so their answers cannot differ.PROOF_BYTES, inputs are a multiple of 32 bytes and exactly the key's arity, the prepared key's layout fits. Anything malformed isfalse.prepared_arity: a prepared key's input count, read from its layout without deserializing a point.pallet-zk-verifier0.17.1:verify_prepared.verify_proof(raw inputs) refuses inputs that do not fill the key before the pairing, as statement verification already did. It used to leave the count to the verifier.Node:
template/node/src/service.rsregisters the host function in all fourHostFunctionsvariants, benchmarks included. Registering a function no runtime imports is harmless.Guards
the_runtime_does_not_import_the_groth16_host_function_yet(runtime)the_node_registers_the_groth16_host_function(node)runtime-benchmarksvariants)the_registered_symbol_is_frozen(primitives)Testing
Unit and property:
verify_preparedmatches an independent oracle (the raw key prepared from scratch) on a real proof: valid statement, wrong input, non-canonical input.A↔Cswapped;false, with no panic.orbinum-zk-verifier: 92 + 10.pallet-zk-verifier: 158 (166 withruntime-benchmarks,skip-proof-verification).pallet-shielded-pool,pallet-evm-precompile-shielded-poolandorbinum-runtimepass. clippy-D warnings(node included), fmt, taplo,try-runtime,no_stdandwasm32builds clean.Live dev nodes:
verify_proofwith 1, 8 and 10 inputsBenchmarks: both pallets regenerate without failures and the output compiles.
verify_proofmeasures 2.36 ms here, unchanged: verification is still in Wasm in spec 18. With the runtime calling the host function it is 0.61 ms.weights.rsis untouched.Upgrade notes
setCode, every node must be on 0.4.0+. The steps are documented inRUNTIME_VERSIONS.md§4.