Skip to content

Add Composer::component_mul_point_pair - #1017

Closed
HDauven wants to merge 1 commit into
feat/mul-generator-pairfrom
feat/mul-point-pair
Closed

HDauven wants to merge 1 commit into
feat/mul-generator-pairfrom
feat/mul-point-pair

Conversation

@HDauven

@HDauven HDauven commented Oct 8, 2026

Copy link
Copy Markdown
Member

Resolves #1015

Stacked on #1016.

component_mul_point_pair(jubjub, point_a, point_b) returns jubjub · point_a and jubjub · point_b from one bit decomposition. It emits component_mul_point's gates for the first point, then a second ladder whose selection rows read the same 252 boolean bit witnesses. The scalar bound is the single call's, jubjub < 2^252; a test checks that the single call and the pair accept and reject the same values.

It takes 3529 gates instead of 2 × 2017. With both pairs, jubjub-schnorr's verify_signature_double drops from 6758 to 6181 gates.

Tests:

  • a golden digest, and layout checks;
  • honest round trips;
  • forgeries that flip one bit for either ladder (first, middle or last round), or use non-boolean bits that recompose to the public scalar. Each is rejected with CircuitUnsatisfied.

make cq, make test, make no-std, make doc and make doc-internal pass locally, as does the MSRV check.

Multiply two points by one scalar from a single bit decomposition. The
gadget emits component_mul_point for the first point verbatim, then a
second double-and-add ladder whose selection rows read the same bit
witnesses. The second multiplication shares the 505-gate decomposition:
3529 gates against 4034 for two single calls. The scalar bound is the
single gadget's: below 2^252, not the canonical Jubjub interval.

The emission of component_mul_point is unchanged; its golden digest
holds. The soundness suite gains forgeries that run either ladder on
another scalar's bits or fill the shared decomposition with non-boolean
bits, a golden digest for the pair, and a check that the pair starts
with the single gadget.
@HDauven
HDauven requested review from Neotamandua, moCello and xevisalle and a balanced review from Copilot October 8, 2026 16:03

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The implementation appears consistent and well-tested, but it changes soundness-critical cryptographic constraint generation.

0 open findings

What changed in this PR

Adds paired variable-base scalar multiplication, complementing #1016’s fixed-base pair API while sharing one scalar decomposition.

Changes:

  • Adds Composer::component_mul_point_pair.
  • Extracts reusable ladder gate emission.
  • Adds bounds, layout, correctness, and soundness tests.
File Description
src/​composer/​point.rs Implements paired multiplication and shared ladder logic.
src/​composer/​constraint_system/​ecc.rs Documents subgroup-preserving behavior.
src/​composer/​tests/​soundness/​point.rs Adds layout and soundness regression tests.
tests/​ecc.rs Adds integration and scalar-bound tests.
CHANGELOG.md Records the new public API.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

@codecov

codecov Bot commented Oct 8, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 92.72727% with 20 lines in your changes missing coverage. Please review.
✅ Project coverage is 92.34%. Comparing base (6a59ede) to head (402d70e).

Files with missing lines Patch % Lines
src/composer/tests/soundness/point.rs 93.63% 10 Missing ⚠️
tests/ecc.rs 90.82% 10 Missing ⚠️
Additional details and impacted files

Impacted file tree graph

@@                     Coverage Diff                     @@
##           feat/mul-generator-pair    #1017      +/-   ##
===========================================================
+ Coverage                    92.33%   92.34%   +0.01%     
===========================================================
  Files                           81       81              
  Lines                         9162     9437     +275     
===========================================================
+ Hits                          8460     8715     +255     
- Misses                         702      722      +20     
Files with missing lines Coverage Δ
src/composer/constraint_system/ecc.rs 0.00% <ø> (ø)
src/composer/point.rs 100.00% <100.00%> (ø)
src/composer/tests/soundness/point.rs 94.17% <93.63%> (-0.18%) ⬇️
tests/ecc.rs 94.16% <90.82%> (-0.94%) ⬇️

Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 6a59ede...402d70e. Read the comment docs.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@HDauven
HDauven marked this pull request as draft October 8, 2026 16:34
@HDauven

HDauven commented Oct 8, 2026

Copy link
Copy Markdown
Member Author

None of our circuits lands in a smaller proving domain with these savings, so they would not speed up proving. Closing; 0.24.1 ships without them. The branch stays in case a later circuit needs it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants