Skip to content

refactor(GKR): Remove the Z/pZ assumption - #1859

Open
Tabaie wants to merge 8 commits into
masterfrom
feat/gkr/extensions
Open

Tabaie wants to merge 8 commits into
masterfrom
feat/gkr/extensions

Conversation

@Tabaie

@Tabaie Tabaie commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

This PR refactors the GKR codebase, in particular gate testing infrastructure and code generation, so that they accommodate extension fields.

NOTE: Pinning an unmerged gnark-crypto. Only to be merged after that.


Note

Medium Risk
Changes Fiat–Shamir binding encoding (Marshal vs Bytes) and gate compilation metadata logic, which are security-sensitive for proof soundness; scope is broad across curves but heavily covered by existing GKR/sumcheck tests.

Overview
GKR is refactored so compilation, gate metadata, and Fiat–Shamir transcripts are not tied to prime fields only, paving the way for extension-field circuits.

Field model: CompileGateFunction, RawCircuit.Compile, gate registry, and gkrapi.API.Compile now take gkrcore.Field (with PrimeField(p) for F_p) instead of *big.Int. Gate degree/solvability testing runs over F_p[X]/(f) via an expanded gateTester, not plain mod-p arithmetic.

Transcript: Per-curve duplicate transcript types are removed; all curve GKR packages use gkrcore.NewHashTranscript with Challenge() / Bind() and element Marshal() (replacing Bytes() and getChallenge). resources.transcript is a pointer passed through prove/verify and BindGkrFinalEvalProof.

Codegen & tests: Generator templates and test-vector tooling switch small_rational → rational, unify setElement via big.Rat, and align fake-hash block sizing with Marshal. Benchmarks use Poseidon2; gkrtesting.NewCache takes a Field. gnark-crypto is bumped (PR note: depends on unmerged crypto).

Reviewed by Cursor Bugbot for commit f4cdc80. Bugbot is set up for automated code reviews on this repo. Configure here.

Tabaie added 7 commits October 1, 2026 08:36
Signed-off-by: Arya Tabaie <arya.pourtabatabaie@gmail.com>
Signed-off-by: Arya Tabaie <arya.pourtabatabaie@gmail.com>
Signed-off-by: Arya Tabaie <arya.pourtabatabaie@gmail.com>
Signed-off-by: Arya Tabaie <arya.pourtabatabaie@gmail.com>
Signed-off-by: Arya Tabaie <arya.pourtabatabaie@gmail.com>
Signed-off-by: Arya Tabaie <arya.pourtabatabaie@gmail.com>
Signed-off-by: Arya Tabaie <arya.pourtabatabaie@gmail.com>
@Tabaie
Tabaie requested a review from a team as a code owner October 2, 2026 02:40
@socket-security

socket-security Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedgolang/​github.com/​consensys/​gnark-crypto@​v0.21.1-0.20260913224755-1409fe592052 ⏵ v0.21.1-0.20261001213005-bfa51d3c359f76 +1100100100100

View full report

Signed-off-by: Arya Tabaie <arya.pourtabatabaie@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant