starknet_transaction_prover,starknet_os,workspace: run the circuit verifier as a bootloader task - #15088
Conversation
PR SummaryHigh Risk Overview
Workspace Reviewed by Cursor Bugbot for commit d4a5279. Bugbot is set up for automated code reviews on this repo. Configure here. |
5ccc8b0 to
45d2292
Compare
45d2292 to
ccdf52c
Compare
ccdf52c to
3ea9055
Compare
9c77ed6 to
b628c29
Compare
9aecebb to
c9f1861
Compare
c9f1861 to
fcf4042
Compare
fcf4042 to
377b5b4
Compare
377b5b4 to
78719ea
Compare
78719ea to
715f6db
Compare
715f6db to
f99428f
Compare
f99428f to
85939ce
Compare
85939ce to
0d3dd94
Compare
44b22ee to
cdf7d20
Compare
cdf7d20 to
cd0a0ba
Compare
…rifier as a bootloader task Runs the privacy circuit verifier executable as a single simple bootloader task on a transaction's processed proof, parses the bootloader's output page, and checks the verifier's output digest against the verification digest recomputed from the packed values the OS emits. The fixture processed proof is the proving side's processing of the golden leaf, generated with stwo_run_and_prove_recursive_tree at proving commit b75d21f9 under the canonical_small registry. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XmPJM3Wph4QLmFmhcxVsh4
cd0a0ba to
d4a5279
Compare
Part 6 of the single-proof verification stack — this PR closes the milestone loop: a single transaction's proof is verified by the real Cairo1 circuit verifier, and the verifier's output digest is checked against the value the OS emits.
run_circuit_verifier_task: runs the privacy circuit verifier executable as a single simple-bootloader task on the transaction's processed proof and parses the bootloader's output page ([1, 10, verifier_program_hash, digest words 0..7]).verify_circuit_verifier_task_output: recomputes the expected verification digest from the packed values the OS emits (apollo_starknet_os_program,starknet_os,blockifier: emit the single-proof digest in the OS output #15064) and compares, after checking the verifier program hash against a pinned value.stwo_run_and_prove_recursive_treeat proving commitb75d21f9under thecanonical_smallregistry. Its output digest matches the Rustcompute_processed_proof_output_digestbit for bit, and the end-to-end test passes: bootloader-run verifier digest == digest recomputed from the transaction's proof facts. Invalid-proof, wrong-program-hash and wrong-digest paths are covered.Stack: #15090 ← #15091 ← #15092 ← #15064 ← #15086 ← this PR ← #15095.
🤖 Generated with Claude Code
https://claude.ai/code/session_01XmPJM3Wph4QLmFmhcxVsh4