Skip to content

fix(sw_bls12377): accept the G1 point at infinity in the pairing - #1851

Merged
yelhousni merged 1 commit into
Consensys-Incorporated:masterfrom
FlashWayne:fix/bls12377-miller-loop-infinity
Sep 29, 2026
Merged

yelhousni merged 1 commit into
Consensys-Incorporated:masterfrom
FlashWayne:fix/bls12377-miller-loop-infinity

Conversation

@FlashWayne

Copy link
Copy Markdown
Contributor

The native BLS12-377 pairing (used for BLS12-377 in BW6-761 recursion) can't handle a G1 point at infinity. PairingCheck([0, 0], [Q1, Q2]) and Pair([0, P], [Q1, Q2]) have no valid witness, although gnark-crypto gives e(0, Q) = 1. An infinity point here comes up naturally, e.g. from a KZG commitment to the zero polynomial or an MSM that sums to zero.

Before:

PairingCheck: no inverse ... sw_bls12377 pairing.go:319
Pair:         no inverse ... sw_bls12377 pairing.go:62

After: both solve (test engine, r1cs and scs).

Both MillerLoop and PairingCheck precompute yInv = DivUnchecked(1, P.Y). This adds a small helper that selects yInv = 0 when P.Y == 0, the same way the emulated BN254/BLS12-381 pairings treat (0,0), so every line evaluated at that point becomes 1. The G2 side already handles infinity through divE2WithZeroGuard.

Cost: +4 (groth16) / +7 (plonk) constraints on the pairing_bls12377 stats row, latest_stats.csv regenerated.

Added TestPairingG1InfinityBLS377, which fails on master. std/algebra/native/..., internal/stats and the BLS12-in-BW6 recursion tests pass.

MillerLoop and PairingCheck compute DivUnchecked(1, P.Y), which has no
solution for the G1 point at infinity (0,0), so e(0,Q) = 1 can't be proven
with the native BLS12-377 pairing. Select yInv = 0 when Y is zero, which
makes the line evaluations for that point equal to 1.
@FlashWayne
FlashWayne requested a review from a team as a code owner September 28, 2026 17:25
@yelhousni yelhousni self-assigned this Sep 28, 2026
@yelhousni yelhousni added the type: bug Something isn't working label Sep 28, 2026
@yelhousni
yelhousni merged commit 188af39 into Consensys-Incorporated:master Sep 29, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type: bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants