Fix: Remove manual witness allocation in SHA256 compression #227
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Problem
SHA256 compression functions were manually allocating witnesses and pushing builders, bypassing the standard
add_witness_builder()flow. This caused R1CS to allocate more witnesses than builders tracked, resulting in unused witness slots being filled with random values.Root cause:
Solution
Replace manual allocations with
add_witness_builder()to maintain consistency between R1CS witness count and builder tracking.Affected functions:
add_u32_addition(lines 36-50, 103-108, 120-125)add_ch(lines 358-363)Impact
Testing
Verified on passport validity circuit: witness count now matches builder count exactly (3,358,873 witnesses, 0 random fills from SHA256).