Conversation
MillerLoop and PairingCheck compute DivUnchecked(1, P.Y), which has no solution for the G1 point at infinity (0,0), so e(0,Q) = 1 can't be proven with the native BLS12-377 pairing. Select yInv = 0 when Y is zero, which makes the line evaluations for that point equal to 1.
yelhousni
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The native BLS12-377 pairing (used for BLS12-377 in BW6-761 recursion) can't handle a G1 point at infinity.
PairingCheck([0, 0], [Q1, Q2])andPair([0, P], [Q1, Q2])have no valid witness, although gnark-crypto givese(0, Q) = 1. An infinity point here comes up naturally, e.g. from a KZG commitment to the zero polynomial or an MSM that sums to zero.Before:
After: both solve (test engine, r1cs and scs).
Both
MillerLoopandPairingCheckprecomputeyInv = DivUnchecked(1, P.Y). This adds a small helper that selectsyInv = 0whenP.Y == 0, the same way the emulated BN254/BLS12-381 pairings treat (0,0), so every line evaluated at that point becomes 1. The G2 side already handles infinity throughdivE2WithZeroGuard.Cost: +4 (groth16) / +7 (plonk) constraints on the
pairing_bls12377stats row,latest_stats.csvregenerated.Added
TestPairingG1InfinityBLS377, which fails on master.std/algebra/native/...,internal/statsand the BLS12-in-BW6 recursion tests pass.