Przeglądaj źródła

Update to the released sigma-proofs 0.4 API

Migrate generated protocols to the draft-v3 API using released sigma-proofs
0.4 and spongefish 0.8. Update group, curve, and RNG dependencies and APIs
to match the released versions.
Michele Orrù 3 tygodni temu
rodzic
commit
229274437b

Plik diff jest za duży
+ 154 - 900
Cargo.lock


+ 5 - 7
Cargo.toml

@@ -7,15 +7,15 @@ repository = "https://git-crysp.uwaterloo.ca/SigmaProtocol/sigma-compiler"
 description = "Crate for automatically generating code for sigma zero-knowledge proof protocols of more complex statements than are supported by the sigma-proofs crate.  The statements given to this crate are compiled into statements about linear combinations of points, and transformed into the sigma-proofs API."
 description = "Crate for automatically generating code for sigma zero-knowledge proof protocols of more complex statements than are supported by the sigma-proofs crate.  The statements given to this crate are compiled into statements about linear combinations of points, and transformed into the sigma-proofs API."
 
 
 [dependencies]
 [dependencies]
-group = "0.13"
-rand = "0.8.5"
+group = "0.14"
+rand = "0.10"
 sigma-compiler-derive = "=0.2.3"
 sigma-compiler-derive = "=0.2.3"
-sigma-proofs = "0.3.2"
+sigma-proofs = "0.4.0"
 subtle = "2.6"
 subtle = "2.6"
 
 
 [dev-dependencies]
 [dev-dependencies]
-curve25519-dalek = { version = "4", features = [ "group", "rand_core", "digest" ] }
-sha2 = "0.10"
+curve25519-dalek = { version = "5", features = [ "group", "rand_core", "digest" ] }
+sha2 = "0.11"
 
 
 [features]
 [features]
 # Dump (to stdout or to a string) the value of the instance on both the
 # Dump (to stdout or to a string) the value of the instance on both the
@@ -26,5 +26,3 @@ dump = [ "sigma-compiler-derive/dump" ]
 [patch.crates-io]
 [patch.crates-io]
 sigma-compiler-derive = { path = "sigma-compiler-derive" }
 sigma-compiler-derive = { path = "sigma-compiler-derive" }
 sigma-compiler-core = { path = "sigma-compiler-core" }
 sigma-compiler-core = { path = "sigma-compiler-core" }
-# sigma-proofs = { path = "../sigma-proofs" }
-# spongefish = { path = "../spongefish/spongefish" }

+ 12 - 11
README.md

@@ -23,9 +23,8 @@ The pieces are as follows:
      structures and code associated with this sigma protocol.
      structures and code associated with this sigma protocol.
   - `<Grp>`: an optional indication of the mathematical group to use
   - `<Grp>`: an optional indication of the mathematical group to use
     (a set of `Point`s and associated `Scalar`s) for this sigma
     (a set of `Point`s and associated `Scalar`s) for this sigma
-    protocol.  The group must implement the
-    [`PrimeGroup`]
-    trait.  If `<Grp>` is omitted, it defaults to assuming there is
+    protocol.  The group must implement the [`PrimeGroup`] 
+    trait. If `<Grp>` is omitted, it defaults to assuming there is
     a group called `G` in the current scope.
     a group called `G` in the current scope.
   - `scalar_list` is a list of variables representing `Scalar`s.
   - `scalar_list` is a list of variables representing `Scalar`s.
     Each variable can be optionally tagged with one or more of the
     Each variable can be optionally tagged with one or more of the
@@ -179,8 +178,8 @@ The macro creates a submodule with the name specified by
         instance: &Instance,
         instance: &Instance,
         witness: &Witness,
         witness: &Witness,
         session_id: &[u8],
         session_id: &[u8],
-        rng: &mut (impl CryptoRng + RngCore),
-    ) -> sigma_proofs::errors::Result<Vec<u8>>
+        rng: &mut (impl CryptoRng + Rng),
+    ) -> Result<Vec<u8>, sigma_proofs::errors::InvalidWitness>
     ```
     ```
     The parameter `instance` contains the public variables (also
     The parameter `instance` contains the public variables (also
     known to the verifier).  The parameter `witness` contains the
     known to the verifier).  The parameter `witness` contains the
@@ -189,15 +188,17 @@ The macro creates a submodule with the name specified by
     byte slice, and the verifier must use the same byte slice in
     byte slice, and the verifier must use the same byte slice in
     order to verify the proof.  The parameter `rng` is a random
     order to verify the proof.  The parameter `rng` is a random
     number generator that implements the [`CryptoRng`] and
     number generator that implements the [`CryptoRng`] and
-    [`RngCore`] traits.  The output, if successful, is the proof as
-    a byte vector.
+    [`Rng`] traits and supplies compiler-generated random scalars.
+    The underlying sigma proof obtains its randomness from the OS through
+    `sigma_proofs::prove_compact`.  The output, if successful, is the proof
+    as a byte vector.
   - A function `verify` with the signature
   - A function `verify` with the signature
     ```
     ```
     pub fn verify(
     pub fn verify(
         instance: &Instance,
         instance: &Instance,
         proof: &[u8],
         proof: &[u8],
         session_id: &[u8],
         session_id: &[u8],
-    ) -> sigma_proofs::errors::Result<()>
+    ) -> Result<(), sigma_proofs::errors::VerificationError>
     ```
     ```
     The parameter `instance` contains the public variables, and must
     The parameter `instance` contains the public variables, and must
     be the same as passed to the `prove` function.  The parameter
     be the same as passed to the `prove` function.  The parameter
@@ -209,7 +210,7 @@ The macro creates a submodule with the name specified by
     `Instance` struct) are all true, but the verifier does not learn
     `Instance` struct) are all true, but the verifier does not learn
     any other information about that `Witness` struct.
     any other information about that `Witness` struct.
 
 
-[`PrimeGroup`]: https://docs.rs/group/0.13.0/group/prime/trait.PrimeGroup.html
-[`CryptoRng`]: https://docs.rs/rand/0.8.5/rand/trait.CryptoRng.html
-[`RngCore`]: https://docs.rs/rand/0.8.5/rand/trait.RngCore.html
+[`PrimeGroup`]: https://docs.rs/group/0.14.0/group/prime/trait.PrimeGroup.html
+[`CryptoRng`]: https://docs.rs/rand/0.10.3/rand/trait.CryptoRng.html
+[`Rng`]: https://docs.rs/rand/0.10.3/rand/trait.Rng.html
 [`i128`]: https://doc.rust-lang.org/1.78.0/std/primitive.i128.html
 [`i128`]: https://doc.rust-lang.org/1.78.0/std/primitive.i128.html

+ 11 - 10
sigma-compiler-core/src/codegen.rs

@@ -411,8 +411,8 @@ impl CodeGen {
                     #instance_var: &Instance,
                     #instance_var: &Instance,
                     #witness_var: &Witness,
                     #witness_var: &Witness,
                     #sid_var: &[u8],
                     #sid_var: &[u8],
-                    #rng_var: &mut (impl CryptoRng + RngCore),
-                ) -> Result<Vec<u8>, SigmaError> {
+                    #rng_var: &mut (impl CryptoRng + Rng),
+                ) -> Result<Vec<u8>, InvalidWitness> {
                     #dumper
                     #dumper
                     let Instance { #instance_ids } = #instance_var.clone();
                     let Instance { #instance_ids } = #instance_var.clone();
                     let Witness { #witness_ids } = #witness_var.clone();
                     let Witness { #witness_ids } = #witness_var.clone();
@@ -431,7 +431,6 @@ impl CodeGen {
                             &#codegen_instance_var,
                             &#codegen_instance_var,
                             &#codegen_witness_var,
                             &#codegen_witness_var,
                             #sid_var,
                             #sid_var,
-                            #rng_var,
                         )?
                         )?
                     );
                     );
                     Ok(#proof_var)
                     Ok(#proof_var)
@@ -468,7 +467,7 @@ impl CodeGen {
                         let #id: Point = {
                         let #id: Point = {
                             let end = #offset_var + #element_len_var;
                             let end = #offset_var + #element_len_var;
                             if #proof_var.len() < end {
                             if #proof_var.len() < end {
-                                return Err(SigmaError::VerificationFailure);
+                                return Err(VerificationError);
                             }
                             }
                             let mut repr = <Point as group::GroupEncoding>::Repr::default();
                             let mut repr = <Point as group::GroupEncoding>::Repr::default();
                             repr.as_mut()
                             repr.as_mut()
@@ -477,7 +476,7 @@ impl CodeGen {
                             Option::<Point>::from(
                             Option::<Point>::from(
                                 <Point as group::GroupEncoding>::from_bytes(&repr)
                                 <Point as group::GroupEncoding>::from_bytes(&repr)
                             )
                             )
-                            .ok_or(SigmaError::VerificationFailure)?
+                            .ok_or(VerificationError)?
                         };
                         };
                     },
                     },
                     StructField::VecPoint(id) => quote! {
                     StructField::VecPoint(id) => quote! {
@@ -487,7 +486,7 @@ impl CodeGen {
                             for _ in 0..expected_len {
                             for _ in 0..expected_len {
                                 let end = #offset_var + #element_len_var;
                                 let end = #offset_var + #element_len_var;
                                 if #proof_var.len() < end {
                                 if #proof_var.len() < end {
-                                    return Err(SigmaError::VerificationFailure);
+                                    return Err(VerificationError);
                                 }
                                 }
                                 let mut repr =
                                 let mut repr =
                                     <Point as group::GroupEncoding>::Repr::default();
                                     <Point as group::GroupEncoding>::Repr::default();
@@ -497,7 +496,7 @@ impl CodeGen {
                                 let point = Option::<Point>::from(
                                 let point = Option::<Point>::from(
                                     <Point as group::GroupEncoding>::from_bytes(&repr)
                                     <Point as group::GroupEncoding>::from_bytes(&repr)
                                 )
                                 )
-                                .ok_or(SigmaError::VerificationFailure)?;
+                                .ok_or(VerificationError)?;
                                 points.push(point);
                                 points.push(point);
                             }
                             }
                             #id = points;
                             #id = points;
@@ -538,7 +537,7 @@ impl CodeGen {
                     #instance_var: &Instance,
                     #instance_var: &Instance,
                     #proof_var: &[u8],
                     #proof_var: &[u8],
                     #sid_var: &[u8],
                     #sid_var: &[u8],
-                ) -> Result<(), SigmaError> {
+                ) -> Result<(), VerificationError> {
                     #dumper
                     #dumper
                     let Instance { #instance_ids } = #instance_var.clone();
                     let Instance { #instance_ids } = #instance_var.clone();
                     #verify_pre_instance_code
                     #verify_pre_instance_code
@@ -574,9 +573,11 @@ impl CodeGen {
                 use super::sigma_compiler;
                 use super::sigma_compiler;
                 use sigma_compiler::group::Group;
                 use sigma_compiler::group::Group;
                 use sigma_compiler::group::ff::{Field, PrimeField};
                 use sigma_compiler::group::ff::{Field, PrimeField};
-                use sigma_compiler::rand::{CryptoRng, RngCore};
+                use sigma_compiler::rand::{CryptoRng, Rng};
                 use sigma_compiler::sigma_proofs;
                 use sigma_compiler::sigma_proofs;
-                use sigma_compiler::sigma_proofs::errors::Error as SigmaError;
+                use sigma_compiler::sigma_proofs::errors::{
+                    InvalidInstance, InvalidWitness, VerificationError,
+                };
                 use sigma_compiler::subtle::ConditionallySelectable;
                 use sigma_compiler::subtle::ConditionallySelectable;
                 use sigma_compiler::vecutils::*;
                 use sigma_compiler::vecutils::*;
                 use std::ops::Neg;
                 use std::ops::Neg;

+ 1 - 1
sigma-compiler-core/src/notequals.rs

@@ -273,7 +273,7 @@ pub fn transform(
             let #Lx_var = #Lx_code;
             let #Lx_var = #Lx_code;
             let #j_var = <Scalar as Field>::invert(&#Lx_var)
             let #j_var = <Scalar as Field>::invert(&#Lx_var)
                 .into_option()
                 .into_option()
-                .ok_or(SigmaError::VerificationFailure)?;
+                .ok_or(InvalidWitness)?;
             let #s_var = -#rand_var * #j_var;
             let #s_var = -#rand_var * #j_var;
         });
         });
 
 

+ 4 - 1
sigma-compiler-core/src/pubscalareq.rs

@@ -80,7 +80,10 @@ pub fn transform(
                                     // verifier to directly check the statement.
                                     // verifier to directly check the statement.
                                     codegen.prove_verify_append(quote! {
                                     codegen.prove_verify_append(quote! {
                                         if #id != #right_tokens {
                                         if #id != #right_tokens {
-                                            return Err(SigmaError::VerificationFailure);
+                                            return Err(InvalidInstance::new(concat!(
+                                                "public scalar equality does not hold: ",
+                                                stringify!(#id),
+                                            )).into());
                                         }
                                         }
                                     });
                                     });
 
 

+ 3 - 1
sigma-compiler-core/src/rangeproof.rs

@@ -403,7 +403,9 @@ pub fn transform(
             if #bitrep_scalars_var.is_empty() {
             if #bitrep_scalars_var.is_empty() {
                 // The upper bound was either less than 2, or more than
                 // The upper bound was either less than 2, or more than
                 // i128::MAX
                 // i128::MAX
-                return Err(SigmaError::VerificationFailure);
+                return Err(InvalidInstance::new(
+                    "range upper bound has no bit representation",
+                ).into());
             }
             }
             let #nbits_var = #bitrep_scalars_var.len();
             let #nbits_var = #bitrep_scalars_var.len();
         });
         });

+ 29 - 39
sigma-compiler-core/src/sigma/codegen.rs

@@ -202,10 +202,10 @@ impl<'a> CodeGen<'a> {
     }
     }
 
 
     /// Generate the code for the `protocol` and `protocol_witness`
     /// Generate the code for the `protocol` and `protocol_witness`
-    /// functions that create the `ComposedRelation` and `ComposedWitness`
+    /// functions that create the `ComposedInstance` and `ComposedWitness`
     /// structs, respectively, given a slice of [`Expr`]s that will be
     /// structs, respectively, given a slice of [`Expr`]s that will be
     /// bundled into a single `LinearRelation`.  The `protocol` code
     /// bundled into a single `LinearRelation`.  The `protocol` code
-    /// must evaluate to a `Result<ComposedRelation>` and the `protocol_witness`
+    /// must evaluate to a `Result<ComposedInstance>` and the `protocol_witness`
     /// code must evaluate to a `Result<ComposedWitness>`.
     /// code must evaluate to a `Result<ComposedWitness>`.
     fn linear_relation_codegen(&self, exprs: &[&Expr]) -> (TokenStream, TokenStream) {
     fn linear_relation_codegen(&self, exprs: &[&Expr]) -> (TokenStream, TokenStream) {
         let instance_var = format_ident!("{}instance", self.unique_prefix);
         let instance_var = format_ident!("{}instance", self.unique_prefix);
@@ -386,12 +386,11 @@ impl<'a> CodeGen<'a> {
                     param_vec_code = quote! {
                     param_vec_code = quote! {
                         #param_vec_code
                         #param_vec_code
                         if #vec_len_var != #instance_var.#thisvar.len() {
                         if #vec_len_var != #instance_var.#thisvar.len() {
-                            eprintln!(
+                            return Err(InvalidInstance::new(format!(
                                 "Instance variables {} and {} must have the same length",
                                 "Instance variables {} and {} must have the same length",
                                 stringify!(#firstvar),
                                 stringify!(#firstvar),
                                 stringify!(#thisvar),
                                 stringify!(#thisvar),
-                            );
-                            return Err(SigmaError::VerificationFailure);
+                            )));
                         }
                         }
                     };
                     };
                 }
                 }
@@ -410,7 +409,7 @@ impl<'a> CodeGen<'a> {
                                 stringify!(#firstvar),
                                 stringify!(#firstvar),
                                 stringify!(#witvar),
                                 stringify!(#witvar),
                             );
                             );
-                            return Err(SigmaError::VerificationFailure);
+                            return Err(InvalidWitness);
                         }
                         }
                     }
                     }
                 }
                 }
@@ -453,7 +452,7 @@ impl<'a> CodeGen<'a> {
                     #eq_code
                     #eq_code
                     #element_assigns
                     #element_assigns
 
 
-                    SigmaOk(ComposedRelation::try_from(#lr_var).unwrap())
+                    ComposedInstance::try_from(#lr_var)
                 }
                 }
             },
             },
             quote! {
             quote! {
@@ -461,7 +460,7 @@ impl<'a> CodeGen<'a> {
                     #witness_vec_code
                     #witness_vec_code
                     let mut witnessvec = Vec::new();
                     let mut witnessvec = Vec::new();
                     #witness_code
                     #witness_code
-                    SigmaOk(ComposedWitness::Simple(witnessvec))
+                    Result::<_, InvalidWitness>::Ok(ComposedWitness::Simple(witnessvec))
                 }
                 }
             },
             },
         )
         )
@@ -481,10 +480,10 @@ impl<'a> CodeGen<'a> {
             // leaf "true")
             // leaf "true")
             StatementTree::Leaf(_) if statement.is_leaf_true() => (
             StatementTree::Leaf(_) if statement.is_leaf_true() => (
                 quote! {
                 quote! {
-                    Ok(ComposedRelation::try_from(LinearRelation::<Point>::new()).unwrap())
+                    ComposedInstance::try_from(LinearRelation::<Point>::new())
                 },
                 },
                 quote! {
                 quote! {
-                    Ok(ComposedWitness::Simple(vec![]))
+                    Result::<_, InvalidWitness>::Ok(ComposedWitness::Simple(vec![]))
                 },
                 },
             ),
             ),
             // The StatementTree is a single statement.  Generate a
             // The StatementTree is a single statement.  Generate a
@@ -516,13 +515,13 @@ impl<'a> CodeGen<'a> {
                             .unzip();
                             .unzip();
                     (
                     (
                         quote! {
                         quote! {
-                            SigmaOk(ComposedRelation::and([
+                            ComposedInstance::and([
                                 #proto_code?,
                                 #proto_code?,
                                 #(#others_proto?,)*
                                 #(#others_proto?,)*
-                            ]))
+                            ])
                         },
                         },
                         quote! {
                         quote! {
-                            SigmaOk(ComposedWitness::and([
+                            Result::<_, InvalidWitness>::Ok(ComposedWitness::and([
                                 #witness_code?,
                                 #witness_code?,
                                 #(#others_witness?,)*
                                 #(#others_witness?,)*
                             ]))
                             ]))
@@ -537,12 +536,12 @@ impl<'a> CodeGen<'a> {
                     .unzip();
                     .unzip();
                 (
                 (
                     quote! {
                     quote! {
-                        SigmaOk(ComposedRelation::or([
+                        ComposedInstance::or([
                             #(#proto?,)*
                             #(#proto?,)*
-                        ]))
+                        ])
                     },
                     },
                     quote! {
                     quote! {
-                        SigmaOk(ComposedWitness::or([
+                        Result::<_, InvalidWitness>::Ok(ComposedWitness::or([
                             #(#witness?,)*
                             #(#witness?,)*
                         ]))
                         ]))
                     },
                     },
@@ -555,12 +554,12 @@ impl<'a> CodeGen<'a> {
                     .unzip();
                     .unzip();
                 (
                 (
                     quote! {
                     quote! {
-                        SigmaOk(ComposedRelation::threshold(#thresh, [
+                        ComposedInstance::threshold(#thresh, [
                             #(#proto?,)*
                             #(#proto?,)*
-                        ]))
+                        ])
                     },
                     },
                     quote! {
                     quote! {
-                        SigmaOk(ComposedWitness::threshold([
+                        Result::<_, InvalidWitness>::Ok(ComposedWitness::threshold([
                             #(#witness?,)*
                             #(#witness?,)*
                         ]))
                         ]))
                     },
                     },
@@ -666,7 +665,7 @@ impl<'a> CodeGen<'a> {
             quote! {
             quote! {
                 fn protocol(
                 fn protocol(
                     #instance_var: &Instance,
                     #instance_var: &Instance,
-                ) -> SigmaResult<ComposedRelation<Point>> {
+                ) -> Result<ComposedInstance<Point>, InvalidInstance> {
                     #protocol_code
                     #protocol_code
                 }
                 }
             }
             }
@@ -678,7 +677,7 @@ impl<'a> CodeGen<'a> {
                 fn protocol_witness(
                 fn protocol_witness(
                     instance: &Instance,
                     instance: &Instance,
                     witness: &Witness,
                     witness: &Witness,
-                ) -> SigmaResult<ComposedWitness<Point>> {
+                ) -> Result<ComposedWitness<Point>, InvalidWitness> {
                     #witness_code
                     #witness_code
                 }
                 }
             }
             }
@@ -691,23 +690,20 @@ impl<'a> CodeGen<'a> {
             let instance_var = format_ident!("{}instance", self.unique_prefix);
             let instance_var = format_ident!("{}instance", self.unique_prefix);
             let witness_var = format_ident!("{}witness", self.unique_prefix);
             let witness_var = format_ident!("{}witness", self.unique_prefix);
             let session_id_var = format_ident!("{}session_id", self.unique_prefix);
             let session_id_var = format_ident!("{}session_id", self.unique_prefix);
-            let rng_var = format_ident!("{}rng", self.unique_prefix);
             let proto_var = format_ident!("{}proto", self.unique_prefix);
             let proto_var = format_ident!("{}proto", self.unique_prefix);
             let proto_witness_var = format_ident!("{}proto_witness", self.unique_prefix);
             let proto_witness_var = format_ident!("{}proto_witness", self.unique_prefix);
-            let nizk_var = format_ident!("{}nizk", self.unique_prefix);
 
 
             quote! {
             quote! {
                 pub fn prove(
                 pub fn prove(
                     #instance_var: &Instance,
                     #instance_var: &Instance,
                     #witness_var: &Witness,
                     #witness_var: &Witness,
                     #session_id_var: &[u8],
                     #session_id_var: &[u8],
-                    #rng_var: &mut (impl CryptoRng + RngCore),
-                ) -> SigmaResult<Vec<u8>> {
+                ) -> Result<Vec<u8>, InvalidWitness> {
                     let #proto_var = protocol(#instance_var)?;
                     let #proto_var = protocol(#instance_var)?;
                     let #proto_witness_var = protocol_witness(#instance_var, #witness_var)?;
                     let #proto_witness_var = protocol_witness(#instance_var, #witness_var)?;
-                    let #nizk_var = #proto_var.into_nizk(#session_id_var);
-
-                    #nizk_var.prove_compact(&#proto_witness_var, #rng_var)
+                    sigma_proofs::prove_compact(
+                        #session_id_var, &#proto_var, &#proto_witness_var,
+                    )
                 }
                 }
             }
             }
         } else {
         } else {
@@ -720,18 +716,15 @@ impl<'a> CodeGen<'a> {
             let proof_var = format_ident!("{}proof", self.unique_prefix);
             let proof_var = format_ident!("{}proof", self.unique_prefix);
             let session_id_var = format_ident!("{}session_id", self.unique_prefix);
             let session_id_var = format_ident!("{}session_id", self.unique_prefix);
             let proto_var = format_ident!("{}proto", self.unique_prefix);
             let proto_var = format_ident!("{}proto", self.unique_prefix);
-            let nizk_var = format_ident!("{}nizk", self.unique_prefix);
 
 
             quote! {
             quote! {
                 pub fn verify(
                 pub fn verify(
                     #instance_var: &Instance,
                     #instance_var: &Instance,
                     #proof_var: &[u8],
                     #proof_var: &[u8],
                     #session_id_var: &[u8],
                     #session_id_var: &[u8],
-                ) -> SigmaResult<()> {
+                ) -> Result<(), VerificationError> {
                     let #proto_var = protocol(#instance_var)?;
                     let #proto_var = protocol(#instance_var)?;
-                    let #nizk_var = #proto_var.into_nizk(#session_id_var);
-
-                    #nizk_var.verify_compact(#proof_var)
+                    sigma_proofs::verify_compact(#session_id_var, &#proto_var, #proof_var)
                 }
                 }
             }
             }
         } else {
         } else {
@@ -752,15 +745,12 @@ impl<'a> CodeGen<'a> {
                 use super::sigma_compiler;
                 use super::sigma_compiler;
                 use sigma_compiler::sigma_proofs;
                 use sigma_compiler::sigma_proofs;
                 use sigma_compiler::group::ff::PrimeField;
                 use sigma_compiler::group::ff::PrimeField;
-                use sigma_compiler::rand::{CryptoRng, RngCore};
                 use sigma_compiler::subtle::CtOption;
                 use sigma_compiler::subtle::CtOption;
                 use sigma_compiler::vecutils::*;
                 use sigma_compiler::vecutils::*;
                 use sigma_proofs::{
                 use sigma_proofs::{
-                    composition::{ComposedRelation, ComposedWitness},
-                    errors::Error as SigmaError,
-                    errors::Ok as SigmaOk,
-                    errors::Result as SigmaResult,
-                    LinearRelation, Nizk,
+                    composition::{ComposedInstance, ComposedWitness},
+                    errors::{InvalidInstance, InvalidWitness, VerificationError},
+                    LinearRelation,
                 };
                 };
                 use std::ops::Neg;
                 use std::ops::Neg;
                 #dump_use
                 #dump_use

+ 1 - 1
sigma-compiler-core/src/substitution.rs

@@ -156,7 +156,7 @@ pub fn transform(
                                 // for illegal inputs (but is constant time for
                                 // for illegal inputs (but is constant time for
                                 // valid inputs)
                                 // valid inputs)
                                 if #id != #right_tokens {
                                 if #id != #right_tokens {
-                                    return Err(SigmaError::VerificationFailure);
+                                    return Err(InvalidWitness);
                                 }
                                 }
                             });
                             });
                         }
                         }

+ 2 - 2
sigma-compiler-core/src/syntax.rs

@@ -243,10 +243,10 @@ pub struct SigmaCompSpec {
     pub proto_name: Ident,
     pub proto_name: Ident,
 
 
     /// An identifier for the mathematical
     /// An identifier for the mathematical
-    /// [`PrimeGroup`](https://docs.rs/group/0.13.0/group/prime/trait.PrimeGroup.html)
+    /// [`PrimeGroup`](https://docs.rs/group/0.14.0/group/prime/trait.PrimeGroup.html)
     /// being used (if none is specified, it is assumed there is a
     /// being used (if none is specified, it is assumed there is a
     /// default type called `G` in scope that implements the
     /// default type called `G` in scope that implements the
-    /// [`PrimeGroup`](https://docs.rs/group/0.13.0/group/prime/trait.PrimeGroup.html)
+    /// [`PrimeGroup`](https://docs.rs/group/0.14.0/group/prime/trait.PrimeGroup.html)
     /// trait)
     /// trait)
     pub group_name: Ident,
     pub group_name: Ident,
 
 

+ 13 - 10
src/rangeutils.rs

@@ -2,7 +2,7 @@
 //! processing of range statements.
 //! processing of range statements.
 
 
 use group::ff::PrimeField;
 use group::ff::PrimeField;
-use sigma_proofs::errors::Error;
+use sigma_proofs::errors::InvalidInstance;
 use subtle::Choice;
 use subtle::Choice;
 
 
 /// Convert a [`Scalar`] to an [`u128`], assuming it fits in an [`i128`]
 /// Convert a [`Scalar`] to an [`u128`], assuming it fits in an [`i128`]
@@ -10,7 +10,7 @@ use subtle::Choice;
 /// [`Scalar`].  This version assumes that `s` is public, and so does
 /// [`Scalar`].  This version assumes that `s` is public, and so does
 /// not need to run in constant time.
 /// not need to run in constant time.
 ///
 ///
-/// [`Scalar`]: https://docs.rs/group/0.13.0/group/trait.Group.html#associatedtype.Scalar
+/// [`Scalar`]: https://docs.rs/group/0.14.0/group/trait.Group.html#associatedtype.Scalar
 pub fn bit_decomp_vartime<S: PrimeField>(mut s: S) -> Option<(u128, u32)> {
 pub fn bit_decomp_vartime<S: PrimeField>(mut s: S) -> Option<(u128, u32)> {
     let mut val = 0u128;
     let mut val = 0u128;
     let mut bitnum = 0u32;
     let mut bitnum = 0u32;
@@ -35,7 +35,7 @@ pub fn bit_decomp_vartime<S: PrimeField>(mut s: S) -> Option<(u128, u32)> {
 /// [`Choice`].  The first element of the vector is the low bit.  This
 /// [`Choice`].  The first element of the vector is the low bit.  This
 /// version runs in constant time.
 /// version runs in constant time.
 ///
 ///
-/// [`Scalar`]: https://docs.rs/group/0.13.0/group/trait.Group.html#associatedtype.Scalar
+/// [`Scalar`]: https://docs.rs/group/0.14.0/group/trait.Group.html#associatedtype.Scalar
 pub fn bit_decomp<S: PrimeField>(mut s: S, nbits: u32) -> Vec<Choice> {
 pub fn bit_decomp<S: PrimeField>(mut s: S, nbits: u32) -> Vec<Choice> {
     let mut bits = Vec::with_capacity(nbits as usize);
     let mut bits = Vec::with_capacity(nbits as usize);
     let mut bitnum = 0u32;
     let mut bitnum = 0u32;
@@ -66,14 +66,15 @@ pub fn bit_decomp<S: PrimeField>(mut s: S, nbits: u32) -> Vec<Choice> {
 /// It is assumed that `upper` is public, and so this function is not
 /// It is assumed that `upper` is public, and so this function is not
 /// constant time.
 /// constant time.
 ///
 ///
-/// [`Scalar`]: https://docs.rs/group/0.13.0/group/trait.Group.html#associatedtype.Scalar
-pub fn bitrep_scalars_vartime<S: PrimeField>(upper: S) -> Result<Vec<S>, Error> {
+/// [`Scalar`]: https://docs.rs/group/0.14.0/group/trait.Group.html#associatedtype.Scalar
+pub fn bitrep_scalars_vartime<S: PrimeField>(upper: S) -> Result<Vec<S>, InvalidInstance> {
     // Get the `u128` value of `upper`, and its number of bits `nbits`
     // Get the `u128` value of `upper`, and its number of bits `nbits`
-    let (upper_val, mut nbits) = bit_decomp_vartime(upper).ok_or(Error::VerificationFailure)?;
+    let (upper_val, mut nbits) = bit_decomp_vartime(upper)
+        .ok_or_else(|| InvalidInstance::new("range upper bound exceeds i128::MAX"))?;
 
 
     // Ensure `nbits` is at least 2.
     // Ensure `nbits` is at least 2.
     if nbits < 2 {
     if nbits < 2 {
-        return Err(Error::VerificationFailure);
+        return Err(InvalidInstance::new("range upper bound must be at least 2"));
     }
     }
 
 
     // If upper is exactly a power of 2, use one fewer bit
     // If upper is exactly a power of 2, use one fewer bit
@@ -105,7 +106,7 @@ pub fn bitrep_scalars_vartime<S: PrimeField>(upper: S) -> Result<Vec<S>, Error>
 /// will not (and indeed cannot) equal the sum of the chosen elements of
 /// will not (and indeed cannot) equal the sum of the chosen elements of
 /// `bitrep_scalars`.
 /// `bitrep_scalars`.
 ///
 ///
-/// [`Scalar`]: https://docs.rs/group/0.13.0/group/trait.Group.html#associatedtype.Scalar
+/// [`Scalar`]: https://docs.rs/group/0.14.0/group/trait.Group.html#associatedtype.Scalar
 pub fn compute_bitrep<S: PrimeField>(mut x: S, bitrep_scalars: &[S]) -> Vec<Choice> {
 pub fn compute_bitrep<S: PrimeField>(mut x: S, bitrep_scalars: &[S]) -> Vec<Choice> {
     // We know the length of bitrep_scalars is at most 127.
     // We know the length of bitrep_scalars is at most 127.
     let nbits: u32 = bitrep_scalars.len().try_into().unwrap();
     let nbits: u32 = bitrep_scalars.len().try_into().unwrap();
@@ -207,7 +208,7 @@ mod tests {
     // Obliviously test whether x is in 0..upper (that is, 0 <= x <
     // Obliviously test whether x is in 0..upper (that is, 0 <= x <
     // upper) using bit decomposition.  `upper` is considered public,
     // upper) using bit decomposition.  `upper` is considered public,
     // but `x` is private.  `upper` must be at least 2.
     // but `x` is private.  `upper` must be at least 2.
-    fn bitrep_tester(upper: Scalar, x: Scalar, expected: bool) -> Result<(), Error> {
+    fn bitrep_tester(upper: Scalar, x: Scalar, expected: bool) -> Result<(), InvalidInstance> {
         let rep_scalars = bitrep_scalars_vartime(upper)?;
         let rep_scalars = bitrep_scalars_vartime(upper)?;
         let bitrep = compute_bitrep(x, &rep_scalars);
         let bitrep = compute_bitrep(x, &rep_scalars);
 
 
@@ -219,7 +220,9 @@ mod tests {
         }
         }
 
 
         if (x == x_out) != expected {
         if (x == x_out) != expected {
-            return Err(Error::VerificationFailure);
+            return Err(InvalidInstance::new(
+                "bit representation disagrees with the range",
+            ));
         }
         }
 
 
         Ok(())
         Ok(())

+ 3 - 3
tests/basic.rs

@@ -6,7 +6,7 @@ use sha2::Sha512;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
 #[test]
 #[test]
-fn basic_test() -> sigma_proofs::errors::Result<()> {
+fn basic_test() -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (x, z, rand r, rand s),
         (x, z, rand r, rand s),
         (C, D, const cind A, const cind B),
         (C, D, const cind A, const cind B),
@@ -16,7 +16,7 @@ fn basic_test() -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let r = Scalar::random(&mut rng);
     let r = Scalar::random(&mut rng);
@@ -30,5 +30,5 @@ fn basic_test() -> sigma_proofs::errors::Result<()> {
     let witness = proof::Witness { x, z, r, s };
     let witness = proof::Witness { x, z, r, s };
 
 
     let proof = proof::prove(&instance, &witness, b"basic_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"basic_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"basic_test")
+    Ok(proof::verify(&instance, &proof, b"basic_test")?)
 }
 }

+ 3 - 3
tests/basic_sum.rs

@@ -5,7 +5,7 @@ use group::Group;
 use sha2::Sha512;
 use sha2::Sha512;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
-fn basic_sum_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result<()> {
+fn basic_sum_test_vecsize(vecsize: usize) -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (vec x, y, rand vec r, rand s),
         (vec x, y, rand vec r, rand s),
         (vec C, D, const cind A, const cind B),
         (vec C, D, const cind A, const cind B),
@@ -15,7 +15,7 @@ fn basic_sum_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let r: Vec<Scalar> = (0..vecsize).map(|_| Scalar::random(&mut rng)).collect();
     let r: Vec<Scalar> = (0..vecsize).map(|_| Scalar::random(&mut rng)).collect();
@@ -29,7 +29,7 @@ fn basic_sum_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result<()> {
     let witness = proof::Witness { x, y, r, s };
     let witness = proof::Witness { x, y, r, s };
 
 
     let proof = proof::prove(&instance, &witness, b"basic_sum_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"basic_sum_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"basic_sum_test")
+    Ok(proof::verify(&instance, &proof, b"basic_sum_test")?)
 }
 }
 
 
 #[test]
 #[test]

+ 3 - 3
tests/basic_vec.rs

@@ -5,7 +5,7 @@ use group::Group;
 use sha2::Sha512;
 use sha2::Sha512;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
-fn basic_vec_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result<()> {
+fn basic_vec_test_vecsize(vecsize: usize) -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (vec x, rand vec r),
         (vec x, rand vec r),
         (vec C, const cind A, const cind B),
         (vec C, const cind A, const cind B),
@@ -13,7 +13,7 @@ fn basic_vec_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let r: Vec<Scalar> = (0..vecsize).map(|_| Scalar::random(&mut rng)).collect();
     let r: Vec<Scalar> = (0..vecsize).map(|_| Scalar::random(&mut rng)).collect();
@@ -24,7 +24,7 @@ fn basic_vec_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result<()> {
     let witness = proof::Witness { x, r };
     let witness = proof::Witness { x, r };
 
 
     let proof = proof::prove(&instance, &witness, b"basic_vec_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"basic_vec_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"basic_vec_test")
+    Ok(proof::verify(&instance, &proof, b"basic_vec_test")?)
 }
 }
 
 
 #[test]
 #[test]

+ 2 - 2
tests/disj.rs

@@ -6,7 +6,7 @@ use sha2::Sha512;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
 #[test]
 #[test]
-fn disj_test() -> sigma_proofs::errors::Result<()> {
+fn disj_test() -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (x, rand r),
         (x, rand r),
         (C, const cind A, const cind B),
         (C, const cind A, const cind B),
@@ -18,7 +18,7 @@ fn disj_test() -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let r = Scalar::random(&mut rng);
     let r = Scalar::random(&mut rng);

+ 3 - 3
tests/disj_vec.rs

@@ -5,7 +5,7 @@ use group::Group;
 use sha2::Sha512;
 use sha2::Sha512;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
-fn disj_vec_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result<()> {
+fn disj_vec_test_vecsize(vecsize: usize) -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (vec x, vec y, pub vec a, rand vec r, rand vec s),
         (vec x, vec y, pub vec a, rand vec r, rand vec s),
         (vec C, vec D, const cind A, const cind B),
         (vec C, vec D, const cind A, const cind B),
@@ -18,7 +18,7 @@ fn disj_vec_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let r: Vec<Scalar> = (0..vecsize).map(|_| Scalar::random(&mut rng)).collect();
     let r: Vec<Scalar> = (0..vecsize).map(|_| Scalar::random(&mut rng)).collect();
@@ -39,7 +39,7 @@ fn disj_vec_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result<()> {
     let witness = proof::Witness { x, y, r, s };
     let witness = proof::Witness { x, y, r, s };
 
 
     let proof = proof::prove(&instance, &witness, b"disj_vec_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"disj_vec_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"disj_vec_test")
+    Ok(proof::verify(&instance, &proof, b"disj_vec_test")?)
 }
 }
 
 
 #[test]
 #[test]

+ 6 - 6
tests/dl.rs

@@ -4,7 +4,7 @@ use group::Group;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
 #[test]
 #[test]
-fn dl_zero_test() -> sigma_proofs::errors::Result<()> {
+fn dl_zero_test() -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (x),
         (x),
         (C, const B),
         (C, const B),
@@ -12,7 +12,7 @@ fn dl_zero_test() -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let B = G::generator();
     let B = G::generator();
     let x = Scalar::random(&mut rng);
     let x = Scalar::random(&mut rng);
     let C = (x + Scalar::ZERO) * B;
     let C = (x + Scalar::ZERO) * B;
@@ -21,11 +21,11 @@ fn dl_zero_test() -> sigma_proofs::errors::Result<()> {
     let witness = proof::Witness { x };
     let witness = proof::Witness { x };
 
 
     let proof = proof::prove(&instance, &witness, b"dl_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"dl_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"dl_test")
+    Ok(proof::verify(&instance, &proof, b"dl_test")?)
 }
 }
 
 
 #[test]
 #[test]
-fn dl_one_test() -> sigma_proofs::errors::Result<()> {
+fn dl_one_test() -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (x),
         (x),
         (C, const B),
         (C, const B),
@@ -33,7 +33,7 @@ fn dl_one_test() -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let B = G::generator();
     let B = G::generator();
     let x = Scalar::random(&mut rng);
     let x = Scalar::random(&mut rng);
     let C = (x + Scalar::ONE) * B;
     let C = (x + Scalar::ONE) * B;
@@ -42,5 +42,5 @@ fn dl_one_test() -> sigma_proofs::errors::Result<()> {
     let witness = proof::Witness { x };
     let witness = proof::Witness { x };
 
 
     let proof = proof::prove(&instance, &witness, b"dl_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"dl_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"dl_test")
+    Ok(proof::verify(&instance, &proof, b"dl_test")?)
 }
 }

+ 3 - 3
tests/dot_product.rs

@@ -3,7 +3,7 @@ use curve25519_dalek::ristretto::RistrettoPoint as G;
 use group::Group;
 use group::Group;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
-fn dot_product_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result<()> {
+fn dot_product_test_vecsize(vecsize: usize) -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (vec x, pub vec a),
         (vec x, pub vec a),
         (C, D, E, F, vec A, B),
         (C, D, E, F, vec A, B),
@@ -15,7 +15,7 @@ fn dot_product_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result<()>
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A: Vec<G> = (0..vecsize).map(|_| G::random(&mut rng)).collect();
     let A: Vec<G> = (0..vecsize).map(|_| G::random(&mut rng)).collect();
     let B = G::generator();
     let B = G::generator();
     let x: Vec<Scalar> = (0..vecsize).map(|_| Scalar::random(&mut rng)).collect();
     let x: Vec<Scalar> = (0..vecsize).map(|_| Scalar::random(&mut rng)).collect();
@@ -37,7 +37,7 @@ fn dot_product_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result<()>
     let witness = proof::Witness { x };
     let witness = proof::Witness { x };
 
 
     let proof = proof::prove(&instance, &witness, b"dot_product_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"dot_product_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"dot_product_test")
+    Ok(proof::verify(&instance, &proof, b"dot_product_test")?)
 }
 }
 
 
 #[test]
 #[test]

+ 3 - 3
tests/emptystatement.rs

@@ -3,17 +3,17 @@ use curve25519_dalek::ristretto::RistrettoPoint as G;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
 #[test]
 #[test]
-fn emptystatement_test() -> sigma_proofs::errors::Result<()> {
+fn emptystatement_test() -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (),
         (),
         (),
         (),
     }
     }
 
 
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
 
 
     let instance = proof::Instance {};
     let instance = proof::Instance {};
     let witness = proof::Witness {};
     let witness = proof::Witness {};
 
 
     let proof = proof::prove(&instance, &witness, b"emptystatement_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"emptystatement_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"emptystatement_test")
+    Ok(proof::verify(&instance, &proof, b"emptystatement_test")?)
 }
 }

+ 6 - 6
tests/left_expr.rs

@@ -6,7 +6,7 @@ use sha2::Sha512;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
 #[test]
 #[test]
-fn left_expr_test() -> sigma_proofs::errors::Result<()> {
+fn left_expr_test() -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (x, y, pub a, rand r, rand s),
         (x, y, pub a, rand r, rand s),
         (C, D, const cind A, const cind B),
         (C, D, const cind A, const cind B),
@@ -15,7 +15,7 @@ fn left_expr_test() -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let r = Scalar::random(&mut rng);
     let r = Scalar::random(&mut rng);
@@ -30,11 +30,11 @@ fn left_expr_test() -> sigma_proofs::errors::Result<()> {
     let witness = proof::Witness { x, y, r, s };
     let witness = proof::Witness { x, y, r, s };
 
 
     let proof = proof::prove(&instance, &witness, b"left_expr_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"left_expr_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"left_expr_test")
+    Ok(proof::verify(&instance, &proof, b"left_expr_test")?)
 }
 }
 
 
 #[test]
 #[test]
-fn left_expr_vec_test() -> sigma_proofs::errors::Result<()> {
+fn left_expr_vec_test() -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (vec x, vec y, z, pub vec a, pub b, rand vec r, rand vec s, rand t),
         (vec x, vec y, z, pub vec a, pub b, rand vec r, rand vec s, rand t),
         (vec C, vec D, E, const cind A, const cind B),
         (vec C, vec D, E, const cind A, const cind B),
@@ -44,7 +44,7 @@ fn left_expr_vec_test() -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let vlen = 5usize;
     let vlen = 5usize;
@@ -78,5 +78,5 @@ fn left_expr_vec_test() -> sigma_proofs::errors::Result<()> {
     let witness = proof::Witness { x, y, z, r, s, t };
     let witness = proof::Witness { x, y, z, r, s, t };
 
 
     let proof = proof::prove(&instance, &witness, b"left_expr_vec_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"left_expr_vec_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"left_expr_vec_test")
+    Ok(proof::verify(&instance, &proof, b"left_expr_vec_test")?)
 }
 }

+ 3 - 3
tests/notequals.rs

@@ -5,7 +5,7 @@ use group::Group;
 use sha2::Sha512;
 use sha2::Sha512;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
-fn do_test(x_u128: u128) -> sigma_proofs::errors::Result<()> {
+fn do_test(x_u128: u128) -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (x, rand r),
         (x, rand r),
         (C, const cind A, const cind B),
         (C, const cind A, const cind B),
@@ -14,7 +14,7 @@ fn do_test(x_u128: u128) -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let r = Scalar::random(&mut rng);
     let r = Scalar::random(&mut rng);
@@ -25,7 +25,7 @@ fn do_test(x_u128: u128) -> sigma_proofs::errors::Result<()> {
     let witness = proof::Witness { x, r };
     let witness = proof::Witness { x, r };
 
 
     let proof = proof::prove(&instance, &witness, b"notequals_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"notequals_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"notequals_test")
+    Ok(proof::verify(&instance, &proof, b"notequals_test")?)
 }
 }
 
 
 #[test]
 #[test]

+ 3 - 3
tests/pubscalars.rs

@@ -5,7 +5,7 @@ use group::Group;
 use sha2::Sha512;
 use sha2::Sha512;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
-fn pubscalars_test_val(b_val: u128) -> sigma_proofs::errors::Result<()> {
+fn pubscalars_test_val(b_val: u128) -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (x, z, rand r, rand s, pub a, pub b),
         (x, z, rand r, rand s, pub a, pub b),
         (C, D, const cind A, const cind B),
         (C, D, const cind A, const cind B),
@@ -16,7 +16,7 @@ fn pubscalars_test_val(b_val: u128) -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let r = Scalar::random(&mut rng);
     let r = Scalar::random(&mut rng);
@@ -32,7 +32,7 @@ fn pubscalars_test_val(b_val: u128) -> sigma_proofs::errors::Result<()> {
     let witness = proof::Witness { x, z, r, s };
     let witness = proof::Witness { x, z, r, s };
 
 
     let proof = proof::prove(&instance, &witness, b"pubscalars_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"pubscalars_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"pubscalars_test")
+    Ok(proof::verify(&instance, &proof, b"pubscalars_test")?)
 }
 }
 
 
 #[test]
 #[test]

+ 3 - 3
tests/pubscalars_or.rs

@@ -5,7 +5,7 @@ use group::Group;
 use sha2::Sha512;
 use sha2::Sha512;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
-fn pubscalars_or_test_val(b_val: u128) -> sigma_proofs::errors::Result<()> {
+fn pubscalars_or_test_val(b_val: u128) -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (x, rand r, pub a, pub b),
         (x, rand r, pub a, pub b),
         (C, const cind A, const cind B),
         (C, const cind A, const cind B),
@@ -17,7 +17,7 @@ fn pubscalars_or_test_val(b_val: u128) -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let r = Scalar::random(&mut rng);
     let r = Scalar::random(&mut rng);
@@ -30,7 +30,7 @@ fn pubscalars_or_test_val(b_val: u128) -> sigma_proofs::errors::Result<()> {
     let witness = proof::Witness { x, r };
     let witness = proof::Witness { x, r };
 
 
     let proof = proof::prove(&instance, &witness, b"pubscalars_or_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"pubscalars_or_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"pubscalars_or_test")
+    Ok(proof::verify(&instance, &proof, b"pubscalars_or_test")?)
 }
 }
 
 
 #[test]
 #[test]

+ 3 - 3
tests/pubscalars_or_and.rs

@@ -5,7 +5,7 @@ use group::Group;
 use sha2::Sha512;
 use sha2::Sha512;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
-fn pubscalars_or_and_test_val(x_val: u128, b_val: u128) -> sigma_proofs::errors::Result<()> {
+fn pubscalars_or_and_test_val(x_val: u128, b_val: u128) -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (x, rand r, pub a, pub b),
         (x, rand r, pub a, pub b),
         (C, const cind A, const cind B),
         (C, const cind A, const cind B),
@@ -23,7 +23,7 @@ fn pubscalars_or_and_test_val(x_val: u128, b_val: u128) -> sigma_proofs::errors:
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let r = Scalar::random(&mut rng);
     let r = Scalar::random(&mut rng);
@@ -36,7 +36,7 @@ fn pubscalars_or_and_test_val(x_val: u128, b_val: u128) -> sigma_proofs::errors:
     let witness = proof::Witness { x, r };
     let witness = proof::Witness { x, r };
 
 
     let proof = proof::prove(&instance, &witness, b"pubscalars_or_and_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"pubscalars_or_and_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"pubscalars_or_and_test")
+    Ok(proof::verify(&instance, &proof, b"pubscalars_or_and_test")?)
 }
 }
 
 
 #[test]
 #[test]

+ 3 - 3
tests/pubscalars_or_and_vec.rs

@@ -9,7 +9,7 @@ fn pubscalars_or_vec_test_vecsize_val(
     vecsize: usize,
     vecsize: usize,
     b_val: u128,
     b_val: u128,
     x_val: Option<u128>,
     x_val: Option<u128>,
-) -> sigma_proofs::errors::Result<()> {
+) -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (vec x, vec y, pub vec a, pub vec b, rand vec r, rand vec s),
         (vec x, vec y, pub vec a, pub vec b, rand vec r, rand vec s),
         (vec C, vec D, const cind A, const cind B),
         (vec C, vec D, const cind A, const cind B),
@@ -28,7 +28,7 @@ fn pubscalars_or_vec_test_vecsize_val(
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let r: Vec<Scalar> = (0..vecsize).map(|_| Scalar::random(&mut rng)).collect();
     let r: Vec<Scalar> = (0..vecsize).map(|_| Scalar::random(&mut rng)).collect();
@@ -56,7 +56,7 @@ fn pubscalars_or_vec_test_vecsize_val(
     let witness = proof::Witness { x, y, r, s };
     let witness = proof::Witness { x, y, r, s };
 
 
     let proof = proof::prove(&instance, &witness, b"pubscalars_vec_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"pubscalars_vec_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"pubscalars_vec_test")
+    Ok(proof::verify(&instance, &proof, b"pubscalars_vec_test")?)
 }
 }
 
 
 fn pubscalars_or_vec_emptyvec() {
 fn pubscalars_or_vec_emptyvec() {

+ 3 - 3
tests/pubscalars_or_vec.rs

@@ -8,7 +8,7 @@ use sigma_compiler::*;
 fn pubscalars_or_vec_test_vecsize_val(
 fn pubscalars_or_vec_test_vecsize_val(
     vecsize: usize,
     vecsize: usize,
     b_val: u128,
     b_val: u128,
-) -> sigma_proofs::errors::Result<()> {
+) -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (vec x, pub vec a, pub vec b, rand vec r),
         (vec x, pub vec a, pub vec b, rand vec r),
         (vec C, const cind A, const cind B),
         (vec C, const cind A, const cind B),
@@ -20,7 +20,7 @@ fn pubscalars_or_vec_test_vecsize_val(
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let r: Vec<Scalar> = (0..vecsize).map(|_| Scalar::random(&mut rng)).collect();
     let r: Vec<Scalar> = (0..vecsize).map(|_| Scalar::random(&mut rng)).collect();
@@ -37,7 +37,7 @@ fn pubscalars_or_vec_test_vecsize_val(
     let witness = proof::Witness { x, r };
     let witness = proof::Witness { x, r };
 
 
     let proof = proof::prove(&instance, &witness, b"pubscalars_vec_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"pubscalars_vec_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"pubscalars_vec_test")
+    Ok(proof::verify(&instance, &proof, b"pubscalars_vec_test")?)
 }
 }
 
 
 #[test]
 #[test]

+ 3 - 3
tests/pubscalars_vec.rs

@@ -5,7 +5,7 @@ use group::Group;
 use sha2::Sha512;
 use sha2::Sha512;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
-fn pubscalars_vec_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result<()> {
+fn pubscalars_vec_test_vecsize(vecsize: usize) -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (vec x, vec y, pub vec a, pub vec b, rand vec r, rand vec s),
         (vec x, vec y, pub vec a, pub vec b, rand vec r, rand vec s),
         (vec C, vec D, const cind A, const cind B),
         (vec C, vec D, const cind A, const cind B),
@@ -16,7 +16,7 @@ fn pubscalars_vec_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result<(
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let r: Vec<Scalar> = (0..vecsize).map(|_| Scalar::random(&mut rng)).collect();
     let r: Vec<Scalar> = (0..vecsize).map(|_| Scalar::random(&mut rng)).collect();
@@ -36,7 +36,7 @@ fn pubscalars_vec_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result<(
     let witness = proof::Witness { x, y, r, s };
     let witness = proof::Witness { x, y, r, s };
 
 
     let proof = proof::prove(&instance, &witness, b"pubscalars_vec_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"pubscalars_vec_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"pubscalars_vec_test")
+    Ok(proof::verify(&instance, &proof, b"pubscalars_vec_test")?)
 }
 }
 
 
 #[test]
 #[test]

+ 3 - 3
tests/pubstatements.rs

@@ -5,7 +5,7 @@ use group::Group;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
 #[test]
 #[test]
-fn pubstatements_test() -> sigma_proofs::errors::Result<()> {
+fn pubstatements_test() -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (x, pub a),
         (x, pub a),
         (C, D, const cind B),
         (C, D, const cind B),
@@ -14,7 +14,7 @@ fn pubstatements_test() -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let B = G::generator();
     let B = G::generator();
     let x = Scalar::from_u128(5);
     let x = Scalar::from_u128(5);
     let a = Scalar::from_u128(0);
     let a = Scalar::from_u128(0);
@@ -25,5 +25,5 @@ fn pubstatements_test() -> sigma_proofs::errors::Result<()> {
     let witness = proof::Witness { x };
     let witness = proof::Witness { x };
 
 
     let proof = proof::prove(&instance, &witness, b"pubstatements_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"pubstatements_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"pubstatements_test")
+    Ok(proof::verify(&instance, &proof, b"pubstatements_test")?)
 }
 }

+ 3 - 3
tests/pubstatements_vec.rs

@@ -4,7 +4,7 @@ use group::ff::PrimeField;
 use group::Group;
 use group::Group;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
-fn pubstatements_vec_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result<()> {
+fn pubstatements_vec_test_vecsize(vecsize: usize) -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (vec x, pub vec a),
         (vec x, pub vec a),
         (vec C, vec D, const cind B),
         (vec C, vec D, const cind B),
@@ -13,7 +13,7 @@ fn pubstatements_vec_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Resul
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let B = G::generator();
     let B = G::generator();
     let a: Vec<Scalar> = (0..vecsize).map(|i| Scalar::from_u128(i as u128)).collect();
     let a: Vec<Scalar> = (0..vecsize).map(|i| Scalar::from_u128(i as u128)).collect();
     let x: Vec<Scalar> = (0..vecsize).map(|i| Scalar::from_u128(i as u128)).collect();
     let x: Vec<Scalar> = (0..vecsize).map(|i| Scalar::from_u128(i as u128)).collect();
@@ -24,7 +24,7 @@ fn pubstatements_vec_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Resul
     let witness = proof::Witness { x };
     let witness = proof::Witness { x };
 
 
     let proof = proof::prove(&instance, &witness, b"pubstatements_vec_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"pubstatements_vec_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"pubstatements_vec_test")
+    Ok(proof::verify(&instance, &proof, b"pubstatements_vec_test")?)
 }
 }
 
 
 #[test]
 #[test]

+ 3 - 3
tests/range.rs

@@ -6,7 +6,7 @@ use sha2::Sha512;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
 #[test]
 #[test]
-fn range_test() -> sigma_proofs::errors::Result<()> {
+fn range_test() -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (x, y, pub a, rand r),
         (x, y, pub a, rand r),
         (C, D, const cind A, const cind B),
         (C, D, const cind A, const cind B),
@@ -17,7 +17,7 @@ fn range_test() -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let a = Scalar::from_u128(3);
     let a = Scalar::from_u128(3);
@@ -31,5 +31,5 @@ fn range_test() -> sigma_proofs::errors::Result<()> {
     let witness = proof::Witness { x, y, r };
     let witness = proof::Witness { x, y, r };
 
 
     let proof = proof::prove(&instance, &witness, b"range_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"range_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"range_test")
+    Ok(proof::verify(&instance, &proof, b"range_test")?)
 }
 }

+ 3 - 3
tests/range_dump.rs

@@ -7,7 +7,7 @@ use sha2::Sha512;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
 #[test]
 #[test]
-fn range_dump_test() -> sigma_proofs::errors::Result<()> {
+fn range_dump_test() -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (x, y, pub a, rand r),
         (x, y, pub a, rand r),
         (C, D, const cind A, const cind B),
         (C, D, const cind A, const cind B),
@@ -18,7 +18,7 @@ fn range_dump_test() -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let a = Scalar::from_u128(3);
     let a = Scalar::from_u128(3);
@@ -39,5 +39,5 @@ fn range_dump_test() -> sigma_proofs::errors::Result<()> {
     let buf = sigma_compiler::dumper::dump_buffer();
     let buf = sigma_compiler::dumper::dump_buffer();
     print!("{buf}");
     print!("{buf}");
 
 
-    res
+    Ok(res?)
 }
 }

+ 2 - 2
tests/simple_or.rs

@@ -5,7 +5,7 @@ use sha2::Sha512;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
 #[test]
 #[test]
-fn simple_or_test() -> sigma_proofs::errors::Result<()> {
+fn simple_or_test() -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (x, y),
         (x, y),
         (C, const cind A, const cind B),
         (C, const cind A, const cind B),
@@ -16,7 +16,7 @@ fn simple_or_test() -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let x = Scalar::random(&mut rng);
     let x = Scalar::random(&mut rng);

+ 3 - 3
tests/substitution_or.rs

@@ -6,7 +6,7 @@ use sha2::Sha512;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
 #[test]
 #[test]
-fn substitution_or_test() -> sigma_proofs::errors::Result<()> {
+fn substitution_or_test() -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (x, z, rand r, rand s),
         (x, z, rand r, rand s),
         (C, D, const cind A, const cind B),
         (C, D, const cind A, const cind B),
@@ -19,7 +19,7 @@ fn substitution_or_test() -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let r = Scalar::random(&mut rng);
     let r = Scalar::random(&mut rng);
@@ -33,5 +33,5 @@ fn substitution_or_test() -> sigma_proofs::errors::Result<()> {
     let witness = proof::Witness { x, z, r, s };
     let witness = proof::Witness { x, z, r, s };
 
 
     let proof = proof::prove(&instance, &witness, b"substitution_or_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"substitution_or_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"substitution_or_test")
+    Ok(proof::verify(&instance, &proof, b"substitution_or_test")?)
 }
 }

+ 3 - 3
tests/substitution_vec.rs

@@ -5,7 +5,7 @@ use group::Group;
 use sha2::Sha512;
 use sha2::Sha512;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
-fn substitution_vec_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result<()> {
+fn substitution_vec_test_vecsize(vecsize: usize) -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (vec x, vec y, rand vec r, rand vec s),
         (vec x, vec y, rand vec r, rand vec s),
         (vec C, vec D, const cind A, const cind B),
         (vec C, vec D, const cind A, const cind B),
@@ -15,7 +15,7 @@ fn substitution_vec_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let r: Vec<Scalar> = (0..vecsize).map(|_| Scalar::random(&mut rng)).collect();
     let r: Vec<Scalar> = (0..vecsize).map(|_| Scalar::random(&mut rng)).collect();
@@ -29,7 +29,7 @@ fn substitution_vec_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result
     let witness = proof::Witness { x, y, r, s };
     let witness = proof::Witness { x, y, r, s };
 
 
     let proof = proof::prove(&instance, &witness, b"substitution_vec_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"substitution_vec_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"substitution_vec_test")
+    Ok(proof::verify(&instance, &proof, b"substitution_vec_test")?)
 }
 }
 
 
 #[test]
 #[test]

+ 3 - 3
tests/subtract.rs

@@ -4,7 +4,7 @@ use group::Group;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
 #[test]
 #[test]
-fn subtract_test() -> sigma_proofs::errors::Result<()> {
+fn subtract_test() -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (x),
         (x),
         (C, const cind B),
         (C, const cind B),
@@ -12,7 +12,7 @@ fn subtract_test() -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let B = G::generator();
     let B = G::generator();
     let x = Scalar::random(&mut rng);
     let x = Scalar::random(&mut rng);
     let C = (x - Scalar::ONE) * B;
     let C = (x - Scalar::ONE) * B;
@@ -21,5 +21,5 @@ fn subtract_test() -> sigma_proofs::errors::Result<()> {
     let witness = proof::Witness { x };
     let witness = proof::Witness { x };
 
 
     let proof = proof::prove(&instance, &witness, b"subtract_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"subtract_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"subtract_test")
+    Ok(proof::verify(&instance, &proof, b"subtract_test")?)
 }
 }

+ 3 - 3
tests/subtract_vec.rs

@@ -5,7 +5,7 @@ use group::Group;
 use sha2::Sha512;
 use sha2::Sha512;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
-fn subtract_vec_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result<()> {
+fn subtract_vec_test_vecsize(vecsize: usize) -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (vec x),
         (vec x),
         (vec C, vec D, vec E, const cind A, const cind B),
         (vec C, vec D, vec E, const cind A, const cind B),
@@ -15,7 +15,7 @@ fn subtract_vec_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result<()>
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let x: Vec<Scalar> = (0..vecsize)
     let x: Vec<Scalar> = (0..vecsize)
@@ -33,7 +33,7 @@ fn subtract_vec_test_vecsize(vecsize: usize) -> sigma_proofs::errors::Result<()>
     let witness = proof::Witness { x };
     let witness = proof::Witness { x };
 
 
     let proof = proof::prove(&instance, &witness, b"subtract_vec_test", &mut rng)?;
     let proof = proof::prove(&instance, &witness, b"subtract_vec_test", &mut rng)?;
-    proof::verify(&instance, &proof, b"subtract_vec_test")
+    Ok(proof::verify(&instance, &proof, b"subtract_vec_test")?)
 }
 }
 
 
 #[test]
 #[test]

+ 7 - 6
tests/threshold.rs

@@ -5,7 +5,7 @@ use sha2::Sha512;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
 #[test]
 #[test]
-fn threshold_test() -> sigma_proofs::errors::Result<()> {
+fn threshold_test() -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { thresh3,
     sigma_compiler! { thresh3,
         (x1, x2, x3, x4, x5, rand r),
         (x1, x2, x3, x4, x5, rand r),
         (C, const cind G0, const cind G1, const cind G2, const cind G3,
         (C, const cind G0, const cind G1, const cind G2, const cind G3,
@@ -15,7 +15,7 @@ fn threshold_test() -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let G0 = G::generator();
     let G0 = G::generator();
     let G1 = G::hash_from_bytes::<Sha512>(b"Generator G1");
     let G1 = G::hash_from_bytes::<Sha512>(b"Generator G1");
     let G2 = G::hash_from_bytes::<Sha512>(b"Generator G2");
     let G2 = G::hash_from_bytes::<Sha512>(b"Generator G2");
@@ -54,14 +54,15 @@ fn threshold_test() -> sigma_proofs::errors::Result<()> {
         };
         };
 
 
         match thresh3::prove(&instance, &witness, b"thresh_test", &mut rng) {
         match thresh3::prove(&instance, &witness, b"thresh_test", &mut rng) {
-            Ok(_) if num_true < 3 => {
-                panic!("THRESH passed when it should have failed (true_pattern = {true_pattern})")
-            }
             Err(_) if num_true >= 3 => {
             Err(_) if num_true >= 3 => {
                 panic!("THRESH failed when it should have passed (true_pattern = {true_pattern})")
                 panic!("THRESH failed when it should have passed (true_pattern = {true_pattern})")
             }
             }
             Ok(proof) => {
             Ok(proof) => {
-                thresh3::verify(&instance, &proof, b"thresh_test")?;
+                assert_eq!(
+                    thresh3::verify(&instance, &proof, b"thresh_test").is_ok(),
+                    num_true >= 3,
+                    "incorrect threshold verdict (true_pattern = {true_pattern})",
+                );
             }
             }
             Err(_) => {}
             Err(_) => {}
         }
         }

+ 7 - 6
tests/threshold_pubscalars.rs

@@ -5,7 +5,7 @@ use sha2::Sha512;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
 #[test]
 #[test]
-fn threshold_pubscalars_test() -> sigma_proofs::errors::Result<()> {
+fn threshold_pubscalars_test() -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { thresh3,
     sigma_compiler! { thresh3,
         (pub x1, pub x2, pub x3, pub x4, pub x5, rand r),
         (pub x1, pub x2, pub x3, pub x4, pub x5, rand r),
         (C, const cind G0, const cind G1, const cind G2, const cind G3,
         (C, const cind G0, const cind G1, const cind G2, const cind G3,
@@ -15,7 +15,7 @@ fn threshold_pubscalars_test() -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let G0 = G::generator();
     let G0 = G::generator();
     let G1 = G::hash_from_bytes::<Sha512>(b"Generator G1");
     let G1 = G::hash_from_bytes::<Sha512>(b"Generator G1");
     let G2 = G::hash_from_bytes::<Sha512>(b"Generator G2");
     let G2 = G::hash_from_bytes::<Sha512>(b"Generator G2");
@@ -52,14 +52,15 @@ fn threshold_pubscalars_test() -> sigma_proofs::errors::Result<()> {
         let witness = thresh3::Witness { r };
         let witness = thresh3::Witness { r };
 
 
         match thresh3::prove(&instance, &witness, b"thresh_pubscalars_test", &mut rng) {
         match thresh3::prove(&instance, &witness, b"thresh_pubscalars_test", &mut rng) {
-            Ok(_) if num_true < 3 => {
-                panic!("THRESH passed when it should have failed (true_pattern = {true_pattern})")
-            }
             Err(_) if num_true >= 3 => {
             Err(_) if num_true >= 3 => {
                 panic!("THRESH failed when it should have passed (true_pattern = {true_pattern})")
                 panic!("THRESH failed when it should have passed (true_pattern = {true_pattern})")
             }
             }
             Ok(proof) => {
             Ok(proof) => {
-                thresh3::verify(&instance, &proof, b"thresh_pubscalars_test")?;
+                assert_eq!(
+                    thresh3::verify(&instance, &proof, b"thresh_pubscalars_test").is_ok(),
+                    num_true >= 3,
+                    "incorrect threshold verdict (true_pattern = {true_pattern})",
+                );
             }
             }
             Err(_) => {}
             Err(_) => {}
         }
         }

+ 2 - 2
tests/two_true.rs

@@ -5,7 +5,7 @@ use sha2::Sha512;
 use sigma_compiler::*;
 use sigma_compiler::*;
 
 
 #[test]
 #[test]
-fn two_true_test() -> sigma_proofs::errors::Result<()> {
+fn two_true_test() -> Result<(), Box<dyn std::error::Error>> {
     sigma_compiler! { proof,
     sigma_compiler! { proof,
         (x, y),
         (x, y),
         (C, D, const cind A, const cind B),
         (C, D, const cind A, const cind B),
@@ -16,7 +16,7 @@ fn two_true_test() -> sigma_proofs::errors::Result<()> {
     }
     }
 
 
     type Scalar = <G as Group>::Scalar;
     type Scalar = <G as Group>::Scalar;
-    let mut rng = rand::thread_rng();
+    let mut rng = rand::rng();
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let A = G::hash_from_bytes::<Sha512>(b"Generator A");
     let B = G::generator();
     let B = G::generator();
     let x = Scalar::random(&mut rng);
     let x = Scalar::random(&mut rng);

Niektóre pliki nie zostały wyświetlone z powodu dużej ilości zmienionych plików