Skip to content

Spec: COPY accelerator - #986

Open
nicole-graus wants to merge 30 commits into
spec/mainfrom
spec/unify-accelerators
Open

nicole-graus wants to merge 30 commits into
spec/mainfrom
spec/unify-accelerators

Conversation

@nicole-graus

@nicole-graus nicole-graus commented Sep 11, 2026 •

Copy link
Copy Markdown
Collaborator

Description

Specifies the accelerator implemented in #984.

  • New MEMMOVE chapter covering memcpy, memmove, memset and commit. The destination domain and the read/write timestamp order are decoded from the entry point, never chosen by the caller: is_set from the syscall number, is_commit from which bus the first row accepted from, both carried inside MEMMOVE_NEXT so a sequence cannot change functionality midway.
  • COMMIT is now one row per ecall: it keeps the syscall number and the x254 update, and defers the byte loop over COMMIT_DEFER. CNB is retired.
  • Adds the ADDNW template, which is what rules out a sequence closing into a ring.
  • Allocates ECALL -30 (copy) and -32 (memset), and lists -31 as reserved for HINT so it is not handed out twice.

@github-actions

Copy link
Copy Markdown

Kimi Code Review

⚠️ Review failed: Kimi API request failed with status 401


Automated review by Kimi (Moonshot AI)

@github-actions

Copy link
Copy Markdown

Codex Code Review

  • Medium — Commitment indexing becomes inconsistent above 4 GiB. In memmove.toml:350, ADDNW normalizes dst_incr into two 32-bit limbs, but COMMIT and the existing commitment-domain convention represent indices as [index, 0]. After crossing 2^32, subsequent rows emit addresses such as [8, 1] instead of [2^32 + 8, 0]. These are different memory tuples, so otherwise valid commitments cannot balance against the verifier’s output. Preserve scalar indexing for commitments, or update the producer and verifier to use normalized indices consistently.

@nicole-graus
nicole-graus marked this pull request as ready for review September 11, 2026 15:53
@github-actions

Copy link
Copy Markdown

Kimi Code Review

⚠️ Review failed: Kimi API request failed with status 401


Automated review by Kimi (Moonshot AI)

@github-actions

Copy link
Copy Markdown

Codex Code Review

  • Medium — Commitment indices change representation after 4 GiB (memmove.toml). dst_incr normalizes the commitment index into two 32-bit limbs, while COMMIT and the verifier use [index, 0]. A write spanning index 2^32 therefore emits [0, 1] where the verifier expects [2^32, 0], making valid output unprovable. Preserve the existing field-valued index arithmetic for commitments, or update the producer and verifier to use the same normalized representation.

@erik-3milabs erik-3milabs left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

First set of comments. Primary change request: the COMMIT chip should be completely integrated into the MEMMOVE chip; no COMMIT chip should be needed after this PR is done.

Once this is done, I'd be happy to give this another review!

Comment thread spec/src/commit.toml Outdated
Comment thread spec/src/memmove.toml Outdated
Comment thread spec/src/memmove.toml Outdated
Comment thread spec/src/memmove.toml Outdated
Comment thread spec/src/memmove.toml Outdated
Comment thread spec/src/memmove.toml Outdated
Comment thread spec/chapters/memmove.typ Outdated
Comment thread spec/chapters/memmove.typ Outdated
Comment thread spec/chapters/memmove.typ Outdated
Comment thread spec/chapters/memmove.typ Outdated
@erik-3milabs erik-3milabs added the spec Updates and improvements to the spec document label Sep 21, 2026
@erik-3milabs erik-3milabs mentioned this pull request Sep 22, 2026
@erik-3milabs erik-3milabs changed the title Spec: unified MEMMOVE accelerator Spec: COPY accelerator Sep 29, 2026
Comment thread spec/chapters/about_ecalls.typ Outdated
Comment thread spec/chapters/add.typ Outdated
Comment thread spec/chapters/add.typ Outdated
Comment thread spec/chapters/add.typ Outdated
Comment thread spec/chapters/is_whh.typ
Comment thread spec/src/copy.toml
Comment thread spec/chapters/copy.typ
Comment thread spec/chapters/copy.typ Outdated
Comment thread spec/chapters/copy.typ Outdated
Comment thread spec/chapters/copy.typ Outdated
Comment thread spec/chapters/add.typ Outdated
Comment thread spec/chapters/add.typ Outdated
Comment thread spec/chapters/add.typ Outdated
Comment thread spec/chapters/commit.typ Outdated
Comment thread spec/chapters/copy.typ Outdated
Comment thread spec/chapters/copy.typ
Comment thread spec/chapters/copy.typ Outdated
Comment thread spec/src/copy.toml
Comment thread spec/src/copy.toml
Comment thread spec/chapters/is_whh.typ
@erik-3milabs erik-3milabs self-assigned this Oct 1, 2026
Comment thread spec/src/signatures.toml Outdated
Comment thread spec/src/signatures.toml Outdated
Comment thread spec/chapters/is_whh.typ
Comment thread spec/src/copy.toml
Comment thread spec/meta.typ Outdated
Comment thread spec/chapters/copy.typ Outdated
Comment thread spec/chapters/copy.typ Outdated
Comment thread spec/chapters/copy.typ Outdated
Comment thread spec/chapters/copy.typ Outdated
Comment thread spec/chapters/copy.typ Outdated
erik-3milabs and others added 9 commits October 2, 2026 15:22
Co-authored-by: Robin Jadoul <robin.jadoul@gmail.com>
Co-authored-by: Erik <159244975+erik-3milabs@users.noreply.github.com>
Co-authored-by: Robin Jadoul <robin.jadoul@gmail.com>
@erik-3milabs
erik-3milabs force-pushed the spec/unify-accelerators branch from 5bc5bec to 58ce060 Compare October 2, 2026 13:22
@RobinJadoul

Copy link
Copy Markdown
Collaborator

/ai-review

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

AI Review

PR #986 · 7 changed files

Findings

No non-rejected structured findings were reported.

Reviewer Lanes

Lane Model Prompt Status Findings

Native Codex and Claude reviews run separately and post their own comments. They are not included in this structured provenance report.

Raw lane outputs, candidates, final issues, and model metrics are uploaded as workflow artifacts.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Codex Code Review

  • Low — Duplicate IS_WHH signature (spec/src/signatures.toml:167): This signature already exists at line 186. The signatures chapter renders both entries and counts the same template twice. Remove the added duplicate.

No other concrete safety, correctness, or significant performance issues found in the PR diff. Review was static; no builds or tests were run.

Comment thread spec/chapters/about_ecalls.typ
Comment thread spec/src/copy.toml
kind = "interaction"
tag = "MEMW"
input = [["*", 2, "is_write"], "dst", "value", ["+", "timestamp", ["-", 1, "is_set"]], 0, 0, ["not", "single"]]
multiplicity = ["-", "μ", ["idx", "count_borrows", 1]]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

High: the first MEMW argument looks like a type mismatch, and domain 2 is no longer explained.

  1. The MEMW signature's first input is is_register: Bit. Passing 2 * is_write gives it the value 2. Either the signature should become a domain selector (BaseField, which also affects CPU/MEMW_A callers), or this needs a different interaction.
  2. The deleted COMMIT chapter explained how the verifier initializes and finalizes domain 2 ((2, index, 0/1, value) tuples, with L2G bringing values forward), and that it checks the final x254. Here, write does an ordinary MEMW write into domain 2, which consumes whatever token was there before. The spec no longer says who initializes domain-2 addresses, or how the verifier ties the final domain-2 contents and x254 to the public output. Without that, the soundness of committed output isn't specified anywhere. Please carry that explanation over into this chapter or into the memory chapter.

Comment thread spec/src/copy.toml
@claude

claude Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Review summary (static review of the spec diff)

Critical

  • memset uses ECALL -31, which is already HINT's number (hint.rs: u64::MAX - 30). Two receivers on the same ECALL number let the prover choose which chip balances the CPU's send. The PR description says memset is -32 and -31 is reserved for HINT, but the code doesn't match. See the inline comment.

High

  • write_value passes 2*is_write into MEMW, whose first input is typed is_register: Bit.
  • The explanation of how domain 2 (committed output) is initialized and finalized by the verifier, and of the verifier's check on x254, was removed along with commit.typ and wasn't carried over.

PR description out of date

  • It describes a MEMMOVE chapter, is_commit, COMMIT_DEFER, an ADDNW template and a kept one-row COMMIT chip. None of these are in this diff, which instead adds a single COPY chip, deletes COMMIT and uses prover-hinted is_set/is_write. Please update the description, or push the missing commits.

Checked and looks correct

  • Termination logic: end exactly when count = step or a zero-length first row.
  • Memmove overlap: all reads at t, all writes at t+1, so overlapping ranges still see the original source bytes.
  • Memset: the reversed read/write order together with the dst = src + 8 gap repeats the first 8 bytes.
  • Padding rows: they satisfy the unconditioned ADD constraints.
  • Flag carry-over: is_set and is_write are passed through COPY_NEXT, so a sequence can't switch mode midway.

Minor

  • dst_res_is_write and range_dst_res could use first_write instead of is_write as their condition, since dst_res is only consumed on first rows.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

spec Updates and improvements to the spec document

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants