Aere Network public source. Everything here can be checked against the live chain (chain id 2800, https://rpc.aere.network). Scope note, stated up front rather than buried: consensus on chain 2800 is classical secp256k1 ECDSA QBFT. The post-quantum work in this repository is at the signature, precompile, account and transport layers. Nothing here makes the consensus post-quantum, and no document in it should be read as claiming so.
4.2 KiB
SP1-recursion AIR port spec: research summary
Deliverable written: aerenew/docs/AERE-STARK-SP1-RECURSION-AIR-PORT-SPEC.md (planning doc, NOT an
implementation). Top-level 0x0AE8 untouched, stays fail-closed.
Pinned version
- SP1 facade crates
= "=6.1.0"(rollup-evm-validity/, batch-prover-recovered/). - Upstream tag
v6.1.0, commitd454975ac7c1126097e36eceda9bce2cb9899da4. - Repo's OWN resolved lock (rollup-evm-validity/host/Cargo.lock): SP1 6.1.0 facade sits on
sp1-hypercube 6.3.1,sp1-recursion-machine 6.3.1,sp1-recursion-executor 6.3.1,slop-basefold/jagged/multilinear/sumcheck 6.3.1.
HEADLINE FINDING (correctness)
SP1 6.1.0 is Hypercube, not Turbo. Its inner recursion proof is NOT a BabyBear FRI ShardProof. It is a KoalaBear multilinear proof: BaseFold + Stacked + Jagged PCS, sumcheck zerocheck (not DEEP-ALI), LogUp-GKR interaction with a degree-7 septic-curve global digest.
- SP1Field = KoalaBear (0x7F000001), ext degree 4, Poseidon2 width 16 / 30 rounds (crates/primitives/src/lib.rs @ v6.1.0).
- The generic skeleton (BabyBear + FRI + p3-uni-stark DEEP-ALI, Plonky3 0.4.3-succinct) was confirmed against the WRONG stack for SP1 6.1.0. Only Poseidon2/Merkle/challenger SHAPES carry over (need KoalaBear re-field + new constants); FRI and DEEP-ALI do not apply at all.
- The 0.4.3-succinct p3 crates in the repo lock are Aere's OWN Plonky3 circuits (zk-circuits/*), not the SP1 recursion proof.
Recursion AIR chip set (crates/recursion/machine/src/machine.rs @ v6.1.0)
Full: MemoryConst, MemoryVar, BaseAlu, ExtAlu, Poseidon2Wide, Poseidon2LinearLayer, Poseidon2SBox, ExtFeltConvert, PrefixSumChecks, Select, PublicValues.
- compress_machine: 8 chips (Poseidon2Wide, no split, no ExtFeltConvert).
- wrap_machine: 9 chips (split Poseidon2 linear-layer + sbox, ExtFeltConvert, no PrefixSumChecks).
- NO FriFold / ExpReverseBits / BatchFRI (Turbo-only) -> confirms recursion no longer runs FRI.
Interaction argument (biggest specific add)
LogUp-GKR (crates/hypercube/src/logup_gkr, lookup) + SepticDigest: elliptic curve over degree-7 "septic" extension of KoalaBear; offset-corrected cumulative sum (sqrt2/sqrt3 start points) for the cross-chip/global multiset bus (crates/hypercube/src/septic_digest.rs @ v6.1.0).
ShardProof shape (crates/hypercube/src/verifier/shard.rs @ v6.1.0)
main_commitment, opened_values (multilinear point, no univariate zeta), zerocheck_proof (sumcheck), logup_gkr_proof, evaluation_proof (Jagged/BaseFold), public_values.
vk + public values
- MachineVerifyingKey: preprocessed_commit, pc_start, initial_global_cumulative_sum (septic point), enable_untrusted_programs. Digest = hash_koalabear() Poseidon2->[SP1Field;8]; hash_bn254() via koalabears_to_bn254 (hashable_key.rs). Export doc's hash_babybear() is WRONG -> hash_koalabear().
- RecursionPublicValues (crates/recursion/executor/src/public_values.rs): committed_value_digest, sp1_vk_digest, vk_root, global_cumulative_sum, is_complete, exit_code, pc_start/next_pc, timestamps, digest, proof_nonce, etc. Count = RECURSIVE_PROOF_NUM_PV_ELTS ([VERIFY] exact int).
Reference to follow
github.com/succinctlabs/hypercube-verifier (crates: basefold, jagged, stacked, sumcheck, tensor, multilinear, merkle-tree, stark, recursion). Clean standalone verifier for exactly this system. Caveat: 2025-05-20 research prototype; reconcile constants vs pinned 6.3.1 [VERIFY].
Total realistic remaining
~22 to 32 person-weeks (~5 to 8 months) single specialist + external audit. Hardest: LogUp-GKR+septic, BaseFold+Jagged PCS, sumcheck zerocheck, RecursionAir chips. Recommend wrapping a pinned native build of the Rust reference over hand-porting into Java.
[VERIFY]/[MEASURE] flags
version-skew pin (6.1.0 facade on 6.3.1 internals); per-chip constraint counts + DEGREE + VAR_EVENTS_PER_ROW; RECURSIVE_PROOF_NUM_PV_ELTS int + PV order; BaseFold/Jagged params (blowup/arity/ queries/pow) for compress/shrink/wrap + whether CircuitWrapConfig differs; septic curve constants + interaction-kind encoding + challenge order; hash_koalabear input list + limb packing; KoalaBear Poseidon2 round split within 30 + constants; hypercube-verifier prototype vs 6.3.1 conformance; end-to-end KAT needs a real exported proof (no offline substitute).