Repository navigation
Conversation
Multiply two points by one scalar from a single bit decomposition. The gadget emits component_mul_point for the first point verbatim, then a second double-and-add ladder whose selection rows read the same bit witnesses. The second multiplication shares the 505-gate decomposition: 3529 gates against 4034 for two single calls. The scalar bound is the single gadget's: below 2^252, not the canonical Jubjub interval. The emission of component_mul_point is unchanged; its golden digest holds. The soundness suite gains forgeries that run either ladder on another scalar's bits or fill the shared decomposition with non-boolean bits, a golden digest for the pair, and a check that the pair starts with the single gadget.
There was a problem hiding this comment.
🔵 Needs a closer look
The implementation appears consistent and well-tested, but it changes soundness-critical cryptographic constraint generation.
0 open findings
What changed in this PR
Adds paired variable-base scalar multiplication, complementing #1016’s fixed-base pair API while sharing one scalar decomposition.
Changes:
- Adds
Composer::component_mul_point_pair. - Extracts reusable ladder gate emission.
- Adds bounds, layout, correctness, and soundness tests.
| File | Description |
|---|---|
src/composer/point.rs |
Implements paired multiplication and shared ladder logic. |
src/composer/constraint_system/ecc.rs |
Documents subgroup-preserving behavior. |
src/composer/tests/soundness/point.rs |
Adds layout and soundness regression tests. |
tests/ecc.rs |
Adds integration and scalar-bound tests. |
CHANGELOG.md |
Records the new public API. |
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## feat/mul-generator-pair #1017 +/- ##
===========================================================
+ Coverage 92.33% 92.34% +0.01%
===========================================================
Files 81 81
Lines 9162 9437 +275
===========================================================
+ Hits 8460 8715 +255
- Misses 702 722 +20
Continue to review full report in Codecov by Harness.
🚀 New features to boost your workflow:
|
|
None of our circuits lands in a smaller proving domain with these savings, so they would not speed up proving. Closing; 0.24.1 ships without them. The branch stays in case a later circuit needs it. |
Resolves #1015
Stacked on #1016.
component_mul_point_pair(jubjub, point_a, point_b)returnsjubjub · point_aandjubjub · point_bfrom one bit decomposition. It emitscomponent_mul_point's gates for the first point, then a second ladder whose selection rows read the same 252 boolean bit witnesses. The scalar bound is the single call's,jubjub < 2^252; a test checks that the single call and the pair accept and reject the same values.It takes 3529 gates instead of 2 × 2017. With both pairs, jubjub-schnorr's
verify_signature_doubledrops from 6758 to 6181 gates.Tests:
CircuitUnsatisfied.make cq,make test,make no-std,make docandmake doc-internalpass locally, as does the MSRV check.