Barretenberg
The ZK-SNARK library at the core of Aztec
Loading...
Searching...
No Matches
avm2_recursion_constraint.test.cpp
Go to the documentation of this file.
2#ifndef DISABLE_AZTEC_VM
3
20
21#include <gtest/gtest.h>
22#include <memory>
23#include <vector>
24
25using namespace acir_format;
26using namespace bb;
27using namespace bb::avm2;
28
31 std::shared_ptr<AvmFlavor::VerificationKey> verification_key;
32 std::vector<FF> public_inputs_flat;
33};
34
35class AcirAvm2RecursionConstraint : public ::testing::Test {
36 public:
39
44
47
49
51 {
52 auto [trace, public_inputs] = avm2::testing::get_minimal_trace_with_pi();
53
54 InnerProver prover;
55 auto [proof, vk_data] = prover.prove(std::move(trace));
56 const auto verification_key = InnerProver::create_verification_key(vk_data);
57
58 const bool verified = prover.verify(proof, public_inputs, vk_data);
59 EXPECT_TRUE(verified) << "native proof verification failed";
60
61 const auto public_inputs_flat = PublicInputs::columns_to_flat(public_inputs.to_columns());
62
63 // TODO(#14234)[Unconditional PIs validation]: Remove next line
64 proof.insert(proof.begin(), 0);
65 return { proof, verification_key, public_inputs_flat };
66 }
67
72 {
73 std::vector<RecursionConstraint> avm_recursion_constraints;
74
75 AcirProgram program;
76
77 SlabVector<fr>& witness = program.witness;
78
79 for (const auto& inner_circuit_data : inner_circuits) {
80 const std::vector<fr> key_witnesses = inner_circuit_data.verification_key->to_field_elements();
81 const std::vector<fr> proof_witnesses = inner_circuit_data.proof;
82 const std::vector<fr> public_inputs_witnesses = inner_circuit_data.public_inputs_flat;
83
84 RecursionConstraint avm_recursion_constraint{
85 .key = add_to_witness_and_track_indices<bb::fr>(witness, key_witnesses),
86 .proof = add_to_witness_and_track_indices<bb::fr>(witness, proof_witnesses),
87 .public_inputs = add_to_witness_and_track_indices<bb::fr>(witness, public_inputs_witnesses),
88 .key_hash = 0, // not used
89 .proof_type = AVM,
90 };
91 avm_recursion_constraints.push_back(avm_recursion_constraint);
92 }
93
94 std::vector<size_t> avm_recursion_opcode_indices(avm_recursion_constraints.size());
95 std::iota(avm_recursion_opcode_indices.begin(), avm_recursion_opcode_indices.end(), 0);
96
97 AcirFormat& constraint_system = program.constraints;
98 constraint_system.varnum = static_cast<uint32_t>(witness.size());
99 constraint_system.num_acir_opcodes = static_cast<uint32_t>(avm_recursion_constraints.size());
100 constraint_system.avm_recursion_constraints = avm_recursion_constraints;
102
103 mock_opcode_indices(constraint_system);
104
105 return program;
106 }
107};
108
109TEST_F(AcirAvm2RecursionConstraint, TestBasicSingleAvm2RecursionConstraint)
110{
111 // Skip this test since it is redundant with the one below (which also does proving and verification for the AVM
112 // recursive verifier circuit) and both are expensive to run. It would be nice to reinstate this as a standalone in
113 // the future if possible.
114 GTEST_SKIP();
115
116 std::vector<InnerCircuitData> layer_1_circuits;
117 layer_1_circuits.push_back(create_inner_circuit_data());
118 AcirProgram avm_verifier_program = construct_avm_verifier_program(layer_1_circuits);
119 const ProgramMetadata metadata{ .honk_recursion = 1 };
120 auto layer_2_circuit = create_circuit(avm_verifier_program, metadata);
121
122 info("circuit gates = ", layer_2_circuit.get_estimated_num_finalized_gates());
123
124 auto proving_key = std::make_shared<OuterDeciderProvingKey>(layer_2_circuit);
125 auto verification_key = std::make_shared<OuterVerificationKey>(proving_key->get_precomputed());
126 OuterProver prover(proving_key, verification_key);
127 info("prover gates = ", proving_key->dyadic_size());
128 auto proof = prover.construct_proof();
129 VerifierCommitmentKey<curve::Grumpkin> ipa_verification_key(1 << CONST_ECCVM_LOG_N);
130 OuterVerifier verifier(verification_key, ipa_verification_key);
131 bool result = verifier.template verify_proof<bb::RollupIO>(proof, proving_key->ipa_proof).result;
132 EXPECT_TRUE(result);
133}
134
142TEST_F(AcirAvm2RecursionConstraint, TestGenerateVKFromConstraintsWithoutWitness)
143{
144 // Generate AVM proof, verification key and public inputs
145 InnerCircuitData avm_prover_output = create_inner_circuit_data();
146
147 // First, construct an AVM2 recursive verifier circuit VK by providing a valid program witness
149 {
150 AcirProgram avm_verifier_program = construct_avm_verifier_program({ avm_prover_output });
151 const ProgramMetadata metadata{ .honk_recursion = 2 };
152 auto layer_2_circuit = create_circuit(avm_verifier_program, metadata);
153
154 info("circuit gates = ", layer_2_circuit.get_estimated_num_finalized_gates());
155
156 auto proving_key = std::make_shared<OuterDeciderProvingKey>(layer_2_circuit);
157 expected_vk = std::make_shared<OuterVerificationKey>(proving_key->get_precomputed());
158 OuterProver prover(proving_key, expected_vk);
159 info("prover gates = ", proving_key->dyadic_size());
160
161 // Construct and verify a proof of the outer AVM verifier circuits
162 auto proof = prover.construct_proof();
163 VerifierCommitmentKey<curve::Grumpkin> ipa_verification_key(1 << CONST_ECCVM_LOG_N);
164 OuterVerifier verifier(expected_vk, ipa_verification_key);
165
166 bool result = verifier.template verify_proof<bb::RollupIO>(proof, proving_key->ipa_proof).result;
167 EXPECT_TRUE(result);
168 }
169
170 // Now, construct the AVM2 recursive verifier circuit VK by providing the program without a witness
172 {
173 AcirProgram avm_verifier_program = construct_avm_verifier_program({ avm_prover_output });
174
175 // Clear the program witness then construct the bberg circuit as normal
176 avm_verifier_program.witness.clear();
177 const ProgramMetadata metadata{ .honk_recursion = 2 };
178 auto layer_2_circuit = create_circuit(avm_verifier_program, metadata);
179
180 info("circuit gates = ", layer_2_circuit.get_estimated_num_finalized_gates());
181
182 auto proving_key = std::make_shared<OuterDeciderProvingKey>(layer_2_circuit);
183 actual_vk = std::make_shared<OuterVerificationKey>(proving_key->get_precomputed());
184 OuterProver prover(proving_key, actual_vk);
185 info("prover gates = ", proving_key->dyadic_size());
186 }
187
188 // Compare the VK constructed via running the IVC with the one constructed via mocking
189 EXPECT_EQ(*actual_vk.get(), *expected_vk.get());
190}
191
192#endif // DISABLE_AZTEC_VM
acir_format::AcirFormatOriginalOpcodeIndices create_empty_original_opcode_indices()
void mock_opcode_indices(acir_format::AcirFormat &constraint_system)
static AcirProgram construct_avm_verifier_program(const std::vector< InnerCircuitData > &inner_circuits)
Create a circuit that recursively verifies one or more inner avm2 circuits.
static InnerCircuitData create_inner_circuit_data()
A DeciderProvingKey is normally constructed from a finalized circuit and it contains all the informat...
The verification key is responsible for storing the commitments to the precomputed (non-witnessk) pol...
Representation of the Grumpkin Verifier Commitment Key inside a bn254 circuit.
bool verify(const Proof &proof, const PublicInputs &pi, const VkData &vk_data)
std::pair< Proof, VkData > prove(tracegen::TraceContainer &&trace)
static std::shared_ptr< AvmVerifier::VerificationKey > create_verification_key(const VkData &vk_data)
void info(Args... args)
Definition log.hpp:70
TestTraceContainer trace
UltraCircuitBuilder create_circuit(AcirProgram &program, const ProgramMetadata &metadata)
Specialization for creating an Ultra circuit from an acir program.
std::pair< tracegen::TraceContainer, PublicInputs > get_minimal_trace_with_pi()
Definition fixtures.cpp:182
std::filesystem::path bb_crs_path()
void init_file_crs_factory(const std::filesystem::path &path)
TEST_F(BoomerangGoblinRecursiveVerifierTests, graph_description_basic)
Construct and check a goblin recursive verification circuit.
Entry point for Barretenberg command-line interface.
std::vector< T, bb::ContainerSlabAllocator< T > > SlabVector
A vector that uses the slab allocator.
UltraCircuitBuilder_< UltraExecutionTraceBlocks > UltraCircuitBuilder
constexpr decltype(auto) get(::tuplet::tuple< T... > &&t) noexcept
Definition tuple.hpp:13
std::shared_ptr< AvmFlavor::VerificationKey > verification_key
AvmProvingHelper::Proof proof
AcirFormatOriginalOpcodeIndices original_opcode_indices
std::vector< RecursionConstraint > avm_recursion_constraints
RecursionConstraint struct contains information required to recursively verify a proof!
static std::vector< FF > columns_to_flat(std::vector< std::vector< FF > > const &columns)