Spec: COPY accelerator - #986
nicole-graus wants to merge 30 commits into
Conversation
Kimi Code ReviewAutomated review by Kimi (Moonshot AI) |
Codex Code Review
|
Kimi Code ReviewAutomated review by Kimi (Moonshot AI) |
Codex Code Review
|
erik-3milabs
left a comment
There was a problem hiding this comment.
First set of comments. Primary change request: the COMMIT chip should be completely integrated into the MEMMOVE chip; no COMMIT chip should be needed after this PR is done.
Once this is done, I'd be happy to give this another review!
Co-authored-by: Erik <159244975+erik-3milabs@users.noreply.github.com>
…m the functionality selector
Co-authored-by: Robin Jadoul <robin.jadoul@gmail.com>
Co-authored-by: Erik <159244975+erik-3milabs@users.noreply.github.com>
Co-authored-by: Robin Jadoul <robin.jadoul@gmail.com>
5bc5bec to
58ce060
Compare
|
/ai-review |
AI ReviewPR #986 · 7 changed files FindingsNo non-rejected structured findings were reported. Reviewer Lanes
Native Codex and Claude reviews run separately and post their own comments. They are not included in this structured provenance report. Raw lane outputs, candidates, final issues, and model metrics are uploaded as workflow artifacts. |
Codex Code Review
No other concrete safety, correctness, or significant performance issues found in the PR diff. Review was static; no builds or tests were run. |
| kind = "interaction" | ||
| tag = "MEMW" | ||
| input = [["*", 2, "is_write"], "dst", "value", ["+", "timestamp", ["-", 1, "is_set"]], 0, 0, ["not", "single"]] | ||
| multiplicity = ["-", "μ", ["idx", "count_borrows", 1]] |
There was a problem hiding this comment.
High: the first MEMW argument looks like a type mismatch, and domain 2 is no longer explained.
- The
MEMWsignature's first input isis_register: Bit. Passing2 * is_writegives it the value 2. Either the signature should become a domain selector (BaseField, which also affects CPU/MEMW_A callers), or this needs a different interaction. - The deleted COMMIT chapter explained how the verifier initializes and finalizes domain 2 (
(2, index, 0/1, value)tuples, with L2G bringing values forward), and that it checks the finalx254. Here,writedoes an ordinaryMEMWwrite into domain 2, which consumes whatever token was there before. The spec no longer says who initializes domain-2 addresses, or how the verifier ties the final domain-2 contents andx254to the public output. Without that, the soundness of committed output isn't specified anywhere. Please carry that explanation over into this chapter or into the memory chapter.
Review summary (static review of the spec diff)Critical
High
PR description out of date
Checked and looks correct
Minor
|
Description
Specifies the accelerator implemented in #984.
MEMMOVEchapter coveringmemcpy,memmove,memsetandcommit. The destination domain and the read/write timestamp order are decoded from the entry point, never chosen by the caller:is_setfrom the syscall number,is_commitfrom which bus the first row accepted from, both carried insideMEMMOVE_NEXTso a sequence cannot change functionality midway.COMMITis now one row per ecall: it keeps the syscall number and thex254update, and defers the byte loop overCOMMIT_DEFER.CNBis retired.ADDNWtemplate, which is what rules out a sequence closing into a ring.-30(copy) and-32(memset), and lists-31as reserved forHINTso it is not handed out twice.