Repository navigation
Conversation
An input wire that no gate uses, or that is exported, is both in c.ins and c.outs. AddInstance appended a value to its assignment once as an input and once as an output, so the wire ended up with 2n values for n instances and the verifier failed with 2 or more instances. For such wires return the input value and don't record it a second time.
Bugbot needs on-demand usage enabledBugbot uses usage-based billing for this team and requires on-demand usage to be enabled. A team admin can enable on-demand usage in the Cursor dashboard. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A GKR circuit built with
gkrapifails to verify as soon as it has two or more instances and one of its input wires is also an output, either because no gate reads it or because it was passed toExport. With two instances the in-circuit verifier panics withindex out of range [0] with length 0inMultiLin.Evaluate, with three instances anAssertIsEqualfails. A single instance works, which is probably why it went unnoticed.Circuit.Outputs()treats a wire as an output when nothing consumes it or when it is exported, and that includes input wires. Such a wire ends up in bothc.insandc.outs, andAddInstanceappends toc.assignments[w]twice per instance: the input value in the first loop and the solver output in the second. The wire then has 2n values for n instances and the multilinear extension used by the verifier has the wrong size.For wires that are inputs,
AddInstancenow returns the input value in the output map and doesn't append a second assignment. Returning the input value rather than the blueprint output also avoids handing back a variable that the GKR proof doesn't cover for that wire.TestInputAsOutputcovers an unused input and an exported input with 1, 2, 3 and 5 instances, and checks thatout[y]equals the input. It fails on master for 2 instances in both cases and passes with the change. I also checked the same circuit compiled with r1cs and scs.std/gkrapi,internal/gkr/...,std/hash/...andinternal/statstests pass.