1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
//! # kyn-vdf
//!
//! A pure Rust, WebAssembly-compatible implementation of Wesolowski Verifiable Delay Function
//! (VDF) verification over Imaginary Quadratic Class Groups.
//!
//! ## Key Features
//! - **Pure Rust / Zero FFI**: No C/C++ compiler, `libgmp`, or OS dependencies required.
//! - **WebAssembly Native**: Compiles to `wasm32-unknown-unknown` for in-browser and mobile
//! light client verification.
//! - **Shanks' NUCOMP / NUDUPL**: Sub-quadratic binary quadratic form composition and squaring
//! with partial Euclidean reduction.
//! - **Chia-Compatible**: 100% test-vector compatible with the Chia Network VDF specification.
//! - **$\mathcal{O}(\log T)$ Verification**: Verification time is constant with respect to $T$
//! (bounded by the 264-bit Fiat-Shamir prime $B$, not the iteration count).
//! - **No Panics**: All fallible operations return `Result<_, KynVdfError>` — safe for WASM
//! and adversarial inputs.
//!
//! ## Quick Start
//! ```rust
//! use kyn_vdf::verify_chia_vdf;
//!
//! # fn example(challenge: &[u8], proof_bytes: &[u8]) -> Result<(), kyn_vdf::KynVdfError> {
//! let is_valid = verify_chia_vdf(challenge, proof_bytes, 100_000, 1024)?;
//! assert!(is_valid);
//! # Ok(())
//! # }
//! ```
pub use ;
pub use KynVdfError;
pub use ;
/// Verifies a Chia-compatible Wesolowski VDF proof from raw byte slices.
///
/// This is the primary entry point for most callers. It handles discriminant
/// generation, form deserialization, and the Wesolowski verification equation
/// in a single call.
///
/// # Parameters
/// - `challenge_seed`: The challenge byte slice used to derive the discriminant and
/// generator form. Typically 32 bytes (e.g. a block hash).
/// - `proof_bytes`: The serialized proof in Chia wire format — exactly 200 bytes
/// containing the VDF output `y` (bytes 0–99) concatenated with the proof `π`
/// (bytes 100–199), each in 100-byte BQFC format.
/// - `iterations`: Number of sequential squarings $T$ that were evaluated.
/// Must be ≥ 1.
/// - `discriminant_size_bits`: Bit-size of the class group discriminant (e.g. `1024`).
/// Must be a non-zero multiple of 8. Use `1024` unless you have a specific reason
/// to use a different size.
///
/// # Returns
/// - `Ok(true)` — proof is mathematically valid.
/// - `Ok(false)` — proof is rejected (valid inputs but incorrect proof).
/// - `Err(KynVdfError)` — inputs are malformed (wrong lengths, invalid seed, etc.).
///
/// # Errors
/// - [`KynVdfError::InvalidIterations`] if `iterations == 0`.
/// - [`KynVdfError::InvalidProofLength`] if `proof_bytes.len() < 200`.
/// - [`KynVdfError::InvalidDiscriminantSize`] if `discriminant_size_bits` is invalid.
/// - [`KynVdfError::FormDeserializationError`] if the proof bytes are corrupted.
/// - [`KynVdfError::InvalidDiscriminantIdentity`] if a form fails the discriminant check.
/// Pure Rust Wesolowski VDF verifier.
///
/// A thin stateful wrapper around [`verify_chia_vdf`] that holds the discriminant
/// size so callers don't need to pass it on every verification call.
///
/// # Example
/// ```rust
/// use kyn_vdf::KynVdfVerifier;
///
/// # fn example(challenge: &[u8], proof: &[u8]) -> Result<(), kyn_vdf::KynVdfError> {
/// let verifier = KynVdfVerifier::new(); // 1024-bit discriminant
/// let is_valid = verifier.verify(challenge, proof, 100_000)?;
/// # Ok(())
/// # }
/// ```