Skip to content

starknet_transaction_prover,starknet_os,workspace: run the circuit verifier as a bootloader task - #15088

Open
einat-starkware wants to merge 1 commit into
claude/privacy-proof-os-verify-gsxf2h-4-registry-pinfrom
claude/privacy-proof-os-verify-gsxf2h-5-verifier-task
Open

einat-starkware wants to merge 1 commit into
claude/privacy-proof-os-verify-gsxf2h-4-registry-pinfrom
claude/privacy-proof-os-verify-gsxf2h-5-verifier-task

Conversation

@einat-starkware

@einat-starkware einat-starkware commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Part 6 of the single-proof verification stack — this PR closes the milestone loop: a single transaction's proof is verified by the real Cairo1 circuit verifier, and the verifier's output digest is checked against the value the OS emits.

  • run_circuit_verifier_task: runs the privacy circuit verifier executable as a single simple-bootloader task on the transaction's processed proof and parses the bootloader's output page ([1, 10, verifier_program_hash, digest words 0..7]).
  • verify_circuit_verifier_task_output: recomputes the expected verification digest from the packed values the OS emits (apollo_starknet_os_program,starknet_os,blockifier: emit the single-proof digest in the OS output #15064) and compares, after checking the verifier program hash against a pinned value.
  • Fixture: the proving side's processing of the golden leaf, generated with stwo_run_and_prove_recursive_tree at proving commit b75d21f9 under the canonical_small registry. Its output digest matches the Rust compute_processed_proof_output_digest bit for bit, and the end-to-end test passes: bootloader-run verifier digest == digest recomputed from the transaction's proof facts. Invalid-proof, wrong-program-hash and wrong-digest paths are covered.

Stack: #15090 ← #15091 ← #15092 ← #15064 ← #15086 ← this PR ← #15095.

🤖 Generated with Claude Code

https://claude.ai/code/session_01XmPJM3Wph4QLmFmhcxVsh4

@reviewable-StarkWare

Copy link
Copy Markdown

This change is Reviewable

@cursor

cursor Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

PR Summary

High Risk
Introduces end-to-end circuit proof verification and digest binding to OS output; mistakes here would accept invalid proofs or reject valid ones.

Overview
Adds verifier_task to the transaction prover so a transaction’s processed proof is verified by running the Cairo1 circuit verifier as a simple-bootloader task via cairo-program-runner-lib, then parsing the bootloader output (program hash + verification digest).

verify_circuit_verifier_task_output ties that run to OS facts: it checks the pinned verifier program hash, unpacks the OS’s packed processed-proof output digest, recomputes the expected verification digest with compute_verification_digest, and compares it to the verifier output. unpack_output_digest (inverse of pack_output_digest) lives in proof_fact_fold with round-trip tests.

Workspace Cargo.lock changes pin cairo-program-runner-lib 1.3.1 for the prover while keeping 2.4.0 on the proving stack, plus transitive hashbrown bumps on proving crates. Integration tests use gzipped fixtures (bootloader, verifier executable, golden processed proof) and cover success, wrong hash/digest, and corrupted proof failure.

Reviewed by Cursor Bugbot for commit d4a5279. Bugbot is set up for automated code reviews on this repo. Configure here.

@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-5-verifier-task branch from 5ccc8b0 to 45d2292 Compare September 2, 2026 11:43
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-5-verifier-task branch from 45d2292 to ccdf52c Compare September 2, 2026 11:47
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-5-verifier-task branch from ccdf52c to 3ea9055 Compare September 2, 2026 12:13
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-5-verifier-task branch 2 times, most recently from 9c77ed6 to b628c29 Compare September 2, 2026 12:45
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-5-verifier-task branch 2 times, most recently from 9aecebb to c9f1861 Compare September 2, 2026 13:41
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-5-verifier-task branch from c9f1861 to fcf4042 Compare September 17, 2026 13:36
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-5-verifier-task branch from fcf4042 to 377b5b4 Compare September 22, 2026 09:22
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-5-verifier-task branch from 377b5b4 to 78719ea Compare September 23, 2026 09:17
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-5-verifier-task branch from 78719ea to 715f6db Compare September 23, 2026 12:59
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-5-verifier-task branch from 715f6db to f99428f Compare September 23, 2026 14:56
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-5-verifier-task branch from f99428f to 85939ce Compare September 24, 2026 08:11
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-5-verifier-task branch from 85939ce to 0d3dd94 Compare September 24, 2026 08:15
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-5-verifier-task branch 2 times, most recently from 44b22ee to cdf7d20 Compare September 24, 2026 17:20
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-5-verifier-task branch from cdf7d20 to cd0a0ba Compare September 28, 2026 08:01
@einat-starkware
einat-starkware removed this pull request from stack #15094 September 28, 2026 08:16
@einat-starkware
einat-starkware added this pull request to stack #15156 September 28, 2026 08:17
…rifier as a bootloader task

Runs the privacy circuit verifier executable as a single simple
bootloader task on a transaction's processed proof, parses the
bootloader's output page, and checks the verifier's output digest
against the verification digest recomputed from the packed values the
OS emits. The fixture processed proof is the proving side's processing
of the golden leaf, generated with stwo_run_and_prove_recursive_tree at
proving commit b75d21f9 under the canonical_small registry.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XmPJM3Wph4QLmFmhcxVsh4
@einat-starkware
einat-starkware force-pushed the claude/privacy-proof-os-verify-gsxf2h-5-verifier-task branch from cd0a0ba to d4a5279 Compare September 28, 2026 10:51

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants