Skip to content

chore: udon common migration - #888

Merged
TalDerei merged 14 commits into
mainfrom
udon-common
Sep 29, 2026
Merged

TalDerei merged 14 commits into
mainfrom
udon-common

Conversation

@TalDerei

@TalDerei TalDerei commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Upstream migration for zakura-core/common#523, and uses udon 0.1.0 tagged release.

  • Replaces ragu_arithmetic and ragu_pasta with Udon.
  • Enables Udon’s unstable traits feature while keeping generic arithmetic calls on its optimized Pasta implementations.
  • Removes direct ff and group dependencies; retain pasta_curves only for build-time hash-to-curve.
  • Keeps Coeff in ragu_core and move generator baking into ragu_pcd (temporarily), using Bento to write and embed Udon points; use Udon’s cycle types and Poseidon parameters.
  • Adapts ragu_circuits to Udon’s FFT and polynomial APIs.
  • Delegates MSM directly to Udon in our backend crates.

Use the standalone Udon ragu-surface revision for fields, curves, FFTs,
cycle traits and Poseidon parameters. Remove the arithmetic and Pasta
crates and migrate consumers, macros, QA tools and target features.

Keep Coeff in ragu_core and Ragu-specific generator derivation and
loading in ragu_pcd. Keep sparse-polynomial adapters and registry storage
in ragu_circuits, and delegate MSM directly to Udon.

Retain pasta_curves only for build-time hash-to-curve, convert its output
to Udon points, and bake them through Bento POD. Preserve the original
generator values and remove direct ff and group dependencies.
Update dependency examples, baked parameter setup and architecture
docs to describe Udon's arithmetic and parameter interfaces and Ragu's
generator ownership. Point Poseidon provenance documentation at the
pinned Udon tables.
Pin Udon and Bento to e9bf1f9 for the shared batch-inversion kernel,
optimized field FFT dispatch, and MSM without the scalar-multiplication
fallback. Keep the isolated fuzz workspace, both lockfiles, and the
getting-started dependency example aligned.

Mark native product-sum loops that can use deferred accumulation, including
Poseidon MDS evaluation, linear expressions, and registry weighted sums.
Note reusable scratch, tables, and executor integration at FFT and MSM
callers.
Pin Udon and Bento to b70477e and opt into Udon's unstable consumer traits
in the main and fuzz workspaces. Keep both lockfiles and the dependency
example aligned.

Import prime-field and endomorphism capabilities under the existing Field
and Affine names where needed, make capability bounds explicit, and borrow
the generalized field encodings. Use explicit reference transforms for
polynomial-valued FFT tests; generic field FFTs and MSM still dispatch to
Udon's optimized Pasta implementations.
Pin Udon and Bento to dea665b in the main and fuzz workspaces. Use the
polynomial module, field domain factory, batch inversion method, and
borrowed Poseidon parameter rows directly.

Update the Halo2 fixture generator and fuzz oracle for typed rows while
preserving every parameter and test-vector value. Align the book's
revision, API links, and polynomial multiplication description.
Pin Udon and Bento to 609e5d8 after rebasing Udon PR #1 onto main.
Keep the workspace, fuzz workspace, and book references on the same
revision, with Udon's optional traits feature enabled.
Route linear combinations and registry evaluations through Udon's product
accumulators, and reuse its polynomial evaluation and multiply-add APIs.
Require DeferredField in execution callers that keep an accumulator,
while preserving cheap coefficient cases.

Extend signed-sum property coverage to both Pasta fields and update
fuzzing, formal extraction, and custom-driver examples for these bounds.
Update Udon and Bento to the consumer API that folds the field capability
traits into one Field and moves operators onto adapter wrappers.

- Name Field in place of PrimeField, FftField, DeferredField, and
  CubeRootField, dropping bounds that Driver and Affine already imply.
- Point the Pasta aliases at FieldAdapter, AffineAdapter, and
  ProjectiveAdapter; sample through Field::random and wrap native hex
  constants, including the regenerated halo2 vectors.
- Twiddle reference FFTs with native Pasta elements, drop the book's
  section on the removed polynomial multiplication, and note that Ragu's
  MSM and FFT don't use Udon's scratch-buffer APIs.
Pick up Udon's explicit-equality documentation and fixture fix; the
consumer API is unchanged.
Define Fp, Fq, EpAffine, and EqAffine as the Pasta cycle's associated
types, and Ep and Eq as their projective forms, so the aliases cannot
drift from Udon's cycle.

Make the identity test helpers generic over the field: rustc does not
normalize the projection aliases inside their higher-ranked routine
bounds.
Udon now gates its cycle and Poseidon modules behind a separate
`poseidon` feature, so enable it alongside `traits`.
Transplant TalDerei/ragu-private#2 onto current Ragu main, preserving the
original port commits and the newer recursion, registry-tag, and parallel
evaluation changes.

Use crates.io patches for Udon and all Bento crates at the exact head of
zakura-core/common#523 (95fa3cc764c9db6b7ab8c1ab364c884df4b48250) in both
the root and isolated fuzz workspaces.

Adapt the newer circuits, QA tools, and regressions to Udon's field and
curve traits. Retain coarse parallel joins in ragu_pcd and explicitly
register the migrated generator compatibility test.
@TalDerei TalDerei self-assigned this Sep 28, 2026
@TalDerei
TalDerei marked this pull request as ready for review September 28, 2026 22:56
@TalDerei
TalDerei requested a review from ebfull as a code owner September 28, 2026 22:56
@TalDerei

Copy link
Copy Markdown
Collaborator Author

@v12sec review this

@v12-auditor

v12-auditor Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Note

Complete: Audit complete. V12 found one issue worth reviewing.

Open the full results here.

FindingSeverityDetails
F-296519 🔵 Low
Point operation documents reversed operands

The public contract for double_and_add_incomplete says the method computes [2]Q + P, but the implementation treats the receiver as P and other as Q. Its first slope and x_r formulas construct self + other, then the second slope and output formulas add self again, yielding 2*self + other. For non-exceptional distinct points where 2P + Q != P + 2Q, calling P.double_and_add_incomplete(..., &Q, ...) therefore returns the opposite operand weighting from the documented relation. Current in-repository endoscaling callers and tests use the implementation's 2*self + other behavior, so no existing proof constraint break was found. The defect is nevertheless security-relevant API ambiguity because downstream circuit authors can encode the wrong group relation by following the public contract.

And two more auto-invalidated findings.

Analyzed 207 files, diff 0f4686b...afa5f44.

Remove the temporary Common revision patches from the main and fuzz
workspaces now that Udon and all Bento crates are published at 0.1.0.
Keep the resolved versions unchanged and record crates.io checksums in
both lockfiles.

Update setup instructions and source links for the published release.
Replace Git-only cargo-vet policies with version-specific exemptions for
the four crates.
Run backend equivalence on Linux, Windows, and macOS while keeping
Clippy on Linux.

Use the imported Udon Field trait in handwritten bounds, adding the
import where needed.
@TalDerei
TalDerei merged commit 94785ff into main Sep 29, 2026
31 checks passed
@TalDerei
TalDerei deleted the udon-common branch September 29, 2026 05:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants