feat: add Goldilocks backend + two-field differential fixtures - #460
Merged
shreyas-londhe merged 9 commits intoJul 8, 2026
Merged
Conversation
|
@BornPsych is attempting to deploy a commit to the World Foundation Team on Vercel. A member of the Team first needs to authorize it. |
BornPsych
pushed a commit
that referenced
this pull request
Jun 30, 2026
Rebased onto PR #460 head (dual-commit + LogUp/multi-challenge fixtures). The base-field split breaks the challenge-bearing fixtures: they place ext challenge values in the witness, which a base witness can't hold (that needs the k-base LogUp construction, plan T12). Resolution: - GoldilocksField = Basefield<Field64_3> stays the canonical field (the real target); GoldilocksEfField = Identity<Field64_3> is an explicitly-TEMPORARY crutch, to be deleted once T12 lets challenge fixtures run on base. - Split the suite macros: roundtrip_suite!/soundness_suite! keep the base-compatible tests (run on GoldilocksField); new challenge_roundtrip_suite!/ challenge_soundness_suite! hold the LogUp/multi-challenge tests (run on GoldilocksEfField for goldilocks, Bn254Field for bn254). All fixtures green: goldilocks base suite on BaseField + challenge suite on Identity, bn254 full set. The planning signal for the frontend work: the LogUp/ dual-commit fixtures need T12 (base challenges, k=3 parallel repetition) to run under the real base-field target.
BornPsych
force-pushed
the
ys/goldilocks-backend-and-fixtures
branch
from
July 7, 2026 07:17
90bba45 to
afa2fae
Compare
shreyas-londhe
requested changes
Jul 7, 2026
zkfriendly
approved these changes
Jul 7, 2026
…ector soundness - field_hash: bump the public-inputs DST V1 -> V2 and refresh the frozen SHA256 KATs for the new tag - bytes: debug_assert each Goldilocks limb is canonical (< modulus) in bytes_to_field, and drop the misleading "never fails" doc — non-canonical limbs must become a hard rejection before this is on a real deser path - fixtures: prove and verify with the same wrong public input so the PR worldfnd#321 binding covector (not the hash-mismatch guard) is what rejects, at N=1 and N=2; add tampered_public_input_is_rejected to retain hash-guard coverage
BornPsych
force-pushed
the
ys/goldilocks-backend-and-fixtures
branch
from
July 7, 2026 22:21
afa2fae to
3f4def4
Compare
This was referenced Jul 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
provekit-backend-goldilocks, a second backend that instantiates the field-generic spine over the ~192-bit Goldilocks cubic extensionField64_3, and restructuresprovekit-fixturesso the prove→verify and soundness suites run over both bn254 and goldilocks from shared, field-generic test bodies. bn254 is unchanged.This is the backend half of the field-generic work: #458/#459 made the spine generic over
<P: ProofField>and added the scheme builder + fixtures; this PR shows a second, structurally different field plugs in with no spine edits.Why
The spine was made field-generic precisely so a non-bn254 field could be added as a backend crate plus an instantiation, with no changes to
common/prover/verifier. Goldilocks is the validation field: a 64-bit prime whose cubic extensionField64_3is large enough (~192 bits) to draw Fiat-Shamir challenges from. This PR is the proof that the seam holds — the backend is a marker type implementingProofField/FieldHashplus aregister()call, nothing more. (Pre-EF/BF the embedding isIdentity<Field64_3>, so base == ext for now; the base≠ext split lands once zkWHIR supports it.)What changed
provekit-backend-goldilocks(new):GoldilocksFieldwithEmbedding = Identity<Field64_3>; aFieldHashimpl with aSha256default hash, 24-byte little-endian canonical bytes, digest-spread hashing, and a transcript sponge;register()installs theField64_3NTT engine in whir's global registry. Mirrors theprovekit-backend-bn254layout.provekit-fixtures: the bn254-onlyroundtrip.rs/soundness.rsare replaced bytests/shared/mod.rs— field-generic<P: FieldHash>test bodies plusroundtrip_suite!/soundness_suite!macros — and four thin per-field instantiation files (bn254_*,goldilocks_*). The same assertions now run over both fields.Verification
cargo build --workspacegreen.provekit-fixtures: bn254 6 roundtrip + 4 soundness, goldilocks 6 roundtrip + 4 soundness — all pass; 2 benches ignored.provekit-backend-goldilocksunit tests (byte roundtrip) pass.Stacks on #459 (open); until that merges, the commit list above includes #459's commits — the Goldilocks-specific changes are the final 2 commits.