Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

doc: add comments to permutation prover structs #355

Merged
merged 6 commits into from
Sep 26, 2024
Merged
Changes from 2 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 19 additions & 3 deletions halo2_backend/src/plonk/permutation/prover.rs
Original file line number Diff line number Diff line change
Expand Up @@ -20,18 +20,34 @@ use crate::{
use halo2_middleware::circuit::Any;
use halo2_middleware::poly::Rotation;

// TODO: Document a bit these types
// https://github.com/privacy-scaling-explorations/halo2/issues/264

/// Single permutation product polynomial, which has been **committed**.
///
/// This struct contains two fields:
/// - `permutation_product_poly`: A (coefficient-form) polynomial representing the permutation grand product.
/// - `permutation_product_blind`: A scalar value used for blinding, in the commitment of the `permutation_product_poly`.
///
/// It stores a single `Z_P` in [permutation argument specification](https://zcash.github.io/halo2/design/proving-system/permutation.html#argument-specification).
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for adding a link the the halo2 specification!

pub(crate) struct CommittedSet<C: CurveAffine> {
pub(crate) permutation_product_poly: Polynomial<C::Scalar, Coeff>,
permutation_product_blind: Blind<C::Scalar>,
}

/// Set of permutation product polynomials, which have been **committed**.
///
/// This struct is to contain all the permutation product commitments, from a single circuit.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This structs only contains a vector of CommittedSet, which in turn, just holds polynomials that have been committed to, plus their blinders. So, the actual commitments are not store here, right? 🤔

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, exactly. @davidnevadoc
The real commitments are computed & stored into transcript in this part.
The CommittedSet just holds the polynomial which has been committed, and its blinder.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This struct is to contain all the permutation product commitments
Then I think we should change or remove this.

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I change the doc, as recommended, here. 23ada39

///
/// It stores multiple `Z_P` in [permutation argument specification](https://zcash.github.io/halo2/design/proving-system/permutation.html#spanning-a-large-number-of-columns).
pub(crate) struct Committed<C: CurveAffine> {
pub(crate) sets: Vec<CommittedSet<C>>,
}

/// Set of permutation product polynomials, which have been **evaluated**.
///
/// This struct is, in essence, the same as [`Committed`].
///
/// It indicates that the permutation product polynomials([`Committed`]) have been evaluated in the evaluation domain, and converted to [`Evaluated`](see [`Committed::evaluate`]).
///
/// It also indicates that the permuted product polynomials([`Evaluated`]) can be **opened** (see [`Evaluated::open`]).
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
/// It also indicates that the permuted product polynomials([`Evaluated`]) can be **opened** (see [`Evaluated::open`]).
/// It also indicates that the permuted product polynomials([`Evaluated`]) can be **opened** (see [`Evaluated::open`]).

Good point!

pub(crate) struct Evaluated<C: CurveAffine> {
constructed: Committed<C>,
}
Expand Down
Loading