Skip to content

fv: machine-check all 104 chip determinism theorems in Lean - #537

Merged
eigmax merged 1 commit into
mainfrom
feat/fv-determinism
Oct 2, 2026
Merged

eigmax merged 1 commit into
mainfrom
feat/fv-determinism

Conversation

@eigmax

@eigmax eigmax commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Summary

Every core chip with a determinism statement (57 chips, 104 theorems) is machine-checked in Lean 4: for each, #print axioms lists only propext, Classical.choice and Quot.sound (no sorry, no added axiom). The statements exposed three soundness gaps, now closed in the constraints (#534, #535, #536).

  • Determinism replay (crates/fv/picus): the analyser's derivation of every output column is replayed as Lean step lemmas; gadget summaries (field operations, byte comparison, leading-one, canonical word, septic chord/sqrt) are library theorems proved once, and accelerator snippets are generated per chip by family generators, shipped in the archive below. The propagation maps are BTreeMaps, so generation is deterministic.
  • Regeneration and parallel check: regen_all.sh (regenerates every chip file and the 24 generated snippets, byte-identical across runs) and check.sh (splits a chip file into dependency-ordered modules, rewrites the large proofs, and builds them in parallel under a 30-minute cap per module) are not in this PR; they and the snippet generators ship in the archive below (src/crates/fv/lean4/check, src/crates/fv/lean4/snippets/tools) and land in a follow-up PR. The chip files are generated, so they are no longer committed.
  • Paper (docs/paper): one arithmetisation section (frame, buses and chips); "Putting it all together" after the components, with an end-to-end block-proof protocol; one Security section (proved relation and open hypotheses, soundness accounting, composition, key binding, digest assumption, trace uniqueness, conformance and determinism, post-quantum); six review passes.
  • Toolchain: pinned to nightly-2026-09-17, the date of the latest zkm toolchain release; the lints it adds are fixed (recursion limit in zkm-curves and zkm-core-machine, two index loops in zkm-pcs).
  • Other: the PLONK verifier template defines VK_ROOT() and keeps hashPublicValues' doc comment; SysLinux and the Global gadgets gain doc comments and analyser marks only; README drops the AI-assistant acknowledgement. No AIR, verifying key or recursion program changes.

The checked chip files and snippets, with a per-chip table (STATUS.md, CLOSED.txt), are archived at https://zkm-toolchain.s3.amazonaws.com/fv/ziren-fv-lean-20261001b.tar.gz (.sha256 beside it); BASE_COMMIT.txt names this commit.

Test plan

  • regen_all.sh run three times: chip files and snippets byte-identical across runs.
  • Every chip file checked with check.sh on one 124-core machine: 104/104 deterministic theorems with standard axioms only; all 7,414 modules of the 62 chip files build with rc=0 and no sorry; slowest module 1,300 s under the 30-minute cap. The archived files are the ones checked.
  • CI test job on the self-hosted box with nightly-2026-09-17: fmt, clippy (workspace and ark), the twelve-package cargo test -r loop, zkm-picus tests, zkm-core-machine cost and Weierstrass tests, verifier malformed-input tests under both feature sets — all passed.
  • Paper builds with no errors, undefined references or overfull boxes (60 pages); seven review passes.

@eigmax
eigmax force-pushed the feat/fv-determinism branch 4 times, most recently from 5be8083 to 3098a87 Compare October 1, 2026 18:21
Every core chip with a determinism statement (57 chips, 104 theorems) is
machine-checked in Lean 4; `#print axioms` lists only propext,
Classical.choice and Quot.sound for each.

- zkm-picus replays the analyser's derivation of every output column as
  Lean step lemmas, with gadget summaries proved once as library theorems
  and generated accelerator snippets; its propagation maps are BTreeMaps,
  so the generated files are byte-identical across runs.
- crates/fv/lean4/check: regen_all.sh regenerates every chip file and the
  generated snippets from the checkout (they are no longer committed);
  check.sh splits a chip file into dependency-ordered modules, lifts and
  flattens the large proofs, and builds them in parallel under a 30-minute
  cap per module.
- Paper: one Security section and one arithmetisation section, the
  determinism results and the three soundness gaps the statements exposed
  (#534, #535, #536), and the fifth review pass.
- Toolchain pinned to nightly-2026-09-17, the date of the latest zkm
  toolchain release, with the lints it adds fixed (recursion limit in
  zkm-curves and zkm-core-machine, two index loops in zkm-pcs).
- The PLONK verifier template defines VK_ROOT() and keeps
  hashPublicValues' doc comment; README drops the AI-assistant
  acknowledgement.

No AIR, verifying key or recursion program changes.
@eigmax
eigmax force-pushed the feat/fv-determinism branch from 3098a87 to 2102bcf Compare October 1, 2026 18:24
@eigmax
eigmax merged commit f20eafb into main Oct 2, 2026
3 checks passed
@eigmax
eigmax deleted the feat/fv-determinism branch October 2, 2026 00:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant