Skip to content

fix(emulated): pad a constant custom modulus to the full number of limbs - #1854

Open
FlashWayne wants to merge 1 commit into
Consensys-Incorporated:masterfrom
FlashWayne:fix/emulated-constant-modulus
Open

FlashWayne wants to merge 1 commit into
Consensys-Incorporated:masterfrom
FlashWayne:fix/emulated-constant-modulus

Conversation

@FlashWayne

Copy link
Copy Markdown
Contributor

ModMul, ModAdd, ModExp and ModAssertIsEqual say the modulus can be a witness or a constant, but a small constant modulus doesn't work:

f.ModMulCanonical(a, b, f.NewElement(7)) // 3*5 mod 7

Before:

ModMul:                          constraint #1375 is not satisfied (r1cs) / [assertIsEqual] 15 == 0 (engine)
ModAdd, ModExp, ModAssertIsEqual: NewHint: input length mismatch

After: all four work with a constant modulus (test engine, r1cs, scs).

NewElement stores a constant on the minimal number of limbs (1 limb for 7), while callMulHint / mulHint and computeSubPaddingHint always read NbLimbs() modulus limbs from their inputs, so they either pick up the wrong inputs or get the wrong input count. checkModulus now returns the modulus padded with zero limbs up to NbLimbs(), and the four methods use that. A witness modulus already has all its limbs and is returned unchanged.

Added TestConstantModulus (Secp256k1Fp and Mod1e512, ModMulCanonical / ModAdd / ModAssertIsEqual / ModExp with a 20-bit constant modulus). It fails on master. std/math/emulated, the MODEXP precompile tests and internal/stats (no change) pass.

The variable-modulus methods document that the modulus may be a constant,
but NewElement stores a constant on the minimal number of limbs while the
hints (mulHint, computeSubPaddingHint) read NbLimbs modulus limbs from their
inputs. With a small constant modulus they read the wrong inputs: ModMul
fails its check and ModAdd/ModExp/ModAssertIsEqual fail with "input length
mismatch". Pad the modulus with zero limbs in checkModulus.
@FlashWayne
FlashWayne requested a review from a team as a code owner September 29, 2026 05:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant