crypto: Reuse V in the G2 point addition - #1636
Merged
Merged
Conversation
Y3 re-expanded U1 * H_squared, the term already bound to V one line above for X3. PR #1542 made this exact substitution in lin_func_and_add but did not reach add(). Cuts about 0.3% off the ECPAIRING instruction count.
There was a problem hiding this comment.
Pull request overview
Optimizes BN254 G2 point addition by reusing an existing intermediate value.
Changes:
- Reuses
Vwhen calculatingY3, avoiding a redundant field multiplication. - Aligns
add()with equivalent pairing and ECC formulas.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #1636 +/- ##
=======================================
Coverage 97.71% 97.71%
=======================================
Files 171 171
Lines 15607 15607
Branches 3610 3610
=======================================
Hits 15251 15251
Misses 269 269
Partials 87 87
Flags with carried forward coverage won't be shown. Click here to find out more.
🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Y3re-expandedU1 * H_squared, the term already bound toVone line abovefor
X3. This is the canonicaladd-1998-cmo-2formula, which definesVandreuses it in
Y3 = r·(V − X3) − S1·HHH— so it was never a different formulavariant, just one term written out longhand.
Vhas been there since theoriginal commit.
#1542 ("Trivial reuse of computed values in pairing helpers") made this exact
substitution in the sibling
lin_func_and_addbut did not reachadd(), whichis why the two disagreed.
ecc::addreuses itsvcorrectly too, so this wasthe only one of the three copies still expanding the term.
Worth about 0.3% of the ECPAIRING instruction count —
add()runs ~20 times perpair through
mul_by_X/g2_subgroup_check. Consistent with the +0.83% Mgas/s#1542 measured for the same substitution in the hotter function, and confirmation
that the compiler does not CSE this away on its own.
🤖 Generated with Claude Code