Skip to content

fix: don't record gkrapi input wires twice when they are also outputs - #1848

Open
Bruce039 wants to merge 1 commit into
Consensys-Incorporated:masterfrom
Bruce039:fix/gkrapi-input-output-wire
Open

Bruce039 wants to merge 1 commit into
Consensys-Incorporated:masterfrom
Bruce039:fix/gkrapi-input-output-wire

Conversation

@Bruce039

Copy link
Copy Markdown
Contributor

A GKR circuit built with gkrapi fails to verify as soon as it has two or more instances and one of its input wires is also an output, either because no gate reads it or because it was passed to Export. With two instances the in-circuit verifier panics with index out of range [0] with length 0 in MultiLin.Evaluate, with three instances an AssertIsEqual fails. A single instance works, which is probably why it went unnoticed.

Circuit.Outputs() treats a wire as an output when nothing consumes it or when it is exported, and that includes input wires. Such a wire ends up in both c.ins and c.outs, and AddInstance appends to c.assignments[w] twice per instance: the input value in the first loop and the solver output in the second. The wire then has 2n values for n instances and the multilinear extension used by the verifier has the wrong size.

For wires that are inputs, AddInstance now returns the input value in the output map and doesn't append a second assignment. Returning the input value rather than the blueprint output also avoids handing back a variable that the GKR proof doesn't cover for that wire.

TestInputAsOutput covers an unused input and an exported input with 1, 2, 3 and 5 instances, and checks that out[y] equals the input. It fails on master for 2 instances in both cases and passes with the change. I also checked the same circuit compiled with r1cs and scs. std/gkrapi, internal/gkr/..., std/hash/... and internal/stats tests pass.

An input wire that no gate uses, or that is exported, is both in c.ins and
c.outs. AddInstance appended a value to its assignment once as an input and
once as an output, so the wire ended up with 2n values for n instances and
the verifier failed with 2 or more instances. For such wires return the
input value and don't record it a second time.
@Bruce039
Bruce039 requested a review from a team as a code owner September 28, 2026 17:14
@cursor

cursor Bot commented Sep 28, 2026

Copy link
Copy Markdown

Bugbot needs on-demand usage enabled

Bugbot uses usage-based billing for this team and requires on-demand usage to be enabled.

A team admin can enable on-demand usage in the Cursor dashboard.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant