Skip to content

fix(sw_bw6761): handle a G1 point at infinity in the Miller loop - #1850

Merged
yelhousni merged 1 commit into
Consensys-Incorporated:masterfrom
FlashWayne:fix/bw6761-miller-loop-infinity
Sep 29, 2026
Merged

yelhousni merged 1 commit into
Consensys-Incorporated:masterfrom
FlashWayne:fix/bw6761-miller-loop-infinity

Conversation

@FlashWayne

Copy link
Copy Markdown
Contributor

On BW6-761, Pair, PairingCheck and MillerLoop fail when one of the G1 points is the point at infinity (0,0). gnark-crypto accepts the same inputs.

Before:

TestPairG1Infinity           NewHint: input and modulus not relatively primes
                             emulated.(*Field).Inverse ... sw_bw6761.(*Pairing).millerLoopLines pairing.go:458
TestPairingCheckG1Infinity   (same)

After: both pass.

millerLoopLines computes 1/P.Y directly. The BN254 and BLS12-381 pairings select yInv = 0 when P.Y == 0 (added in #1559), which makes every line evaluation for that point equal to 1 so the point contributes nothing to the product. BW6-761 didn't get that guard; this adds the same three lines.

The BW6-761 pairing row in internal/stats/latest_stats.csv goes up by 74 (groth16) / 145 (plonk) constraints and is regenerated.

Tests: TestPairG1Infinity (e(0,Q1)·e(P2,Q2) compared to gnark-crypto) and TestPairingCheckG1Infinity (e(0,Q1)·e(0,Q2) == 1), both failing on master. std/algebra/emulated/sw_bw6761, internal/stats and the BW6-in-BN254 recursion tests pass.

millerLoopLines inverts P.Y without a guard, so a G1 point at infinity
(0,0) makes Pair, PairingCheck and MillerLoop unsatisfiable on BW6-761.
BN254 and BLS12-381 already select yInv=0 for Y=0 (Consensys-Incorporated#1559), which turns the
lines for that point into 1. Do the same here.
@FlashWayne
FlashWayne requested a review from a team as a code owner September 28, 2026 17:22
@yelhousni yelhousni self-assigned this Sep 28, 2026
@yelhousni yelhousni added the type: bug Something isn't working label Sep 28, 2026
@yelhousni
yelhousni merged commit aa06609 into Consensys-Incorporated:master Sep 29, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type: bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants