gnark icon indicating copy to clipboard operation
gnark copied to clipboard

bits.ToBinary producing unexpected output

Open tiagofneto opened this issue 2 years ago • 2 comments

Description

I have encountered an issue when using the bits.ToBinary function where the output is not as expected.

Steps to Reproduce

Here's the scenario I am facing:

  1. I am calling the bits.ToBinary function with the following number:
0x3761ab92011074a873e2f15bc14e376c0464cfa56d1e2588e739cfbb5071433d
  1. The expected output after using bits.ToBinary should be (binary representation of the number):
[1, 1, 0, 1, 1, 1, 0, 1, 1, 0, 0, 0, 0, 1, 1, 0, 1, 0, 1, 0, 1, 1, 1, 0, 0, 1, 0, 0, 1, 0, 0, 0, 0, 0, 0, 0, 0, 1, 0, 0, 0, 1, 0, 0, 0, 0, 0, 1, 1, 1, 0, 1, 0, 0, 1, 0, 1, 0, 1, 0, 0, 0, 0, 1, 1, 1, 0, 0, 1, 1, 1, 1, 1, 0, 0, 0, 1, 0, 1, 1, 1, 1, 0, 0, 0, 1, 0, 1, 0, 1, 1, 0, 1, 1, 1, 1, 0, 0, 0, 0, 0, 1, 0, 1, 0, 0, 1, 1, 1, 0, 0, 0, 1, 1, 0, 1, 1, 1, 0, 1, 1, 0, 1, 1, 0, 0, 0, 0, 0, 0, 0, 1, 0, 0, 0, 1, 1, 0, 0, 1, 0, 0, 1, 1, 0, 0, 1, 1, 1, 1, 1, 0, 1, 0, 0, 1, 0, 1, 0, 1, 1, 0, 1, 1, 0, 1, 0, 0, 0, 1, 1, 1, 1, 0, 0, 0, 1, 0, 0, 1, 0, 1, 1, 0, 0, 0, 1, 0, 0, 0, 1, 1, 1, 0, 0, 1, 1, 1, 0, 0, 1, 1, 1, 0, 0, 1, 1, 1, 0, 0, 1, 1, 1, 1, 1, 0, 1, 1, 1, 0, 1, 1, 0, 1, 0, 1, 0, 0, 0, 0, 0, 1, 1, 1, 0, 0, 0, 1, 0, 1, 0, 0, 0, 0, 1, 1, 0, 0, 1, 1, 1, 1, 0, 1]
  1. However, the actual output I receive is:
[1, 1, 0, 1, 1, 1, 0, 1, 1, 0, 0, 0, 0, 1, 1, 0, 1, 0, 1, 0, 1, 1, 1, 0, 0, 1, 0, 0, 1, 0, 0, 0, 0, 0, 0, 0, 0, 1, 0, 0, 0, 1, 0, 0, 0, 0, 0, 1, 1, 1, 0, 1, 0, 0, 1, 0, 1, 0, 1, 0, 0, 0, 0, 1, 1, 1, 0, 0, 1, 1, 1, 1, 1, 0, 0, 0, 1, 0, 1, 1, 1, 1, 0, 0, 0, 1, 0, 1, 0, 1, 1, 0, 1, 1, 1, 1, 0, 0, 0, 0, 0, 1, 0, 1, 0, 0, 1, 1, 1, 0, 0, 0, 1, 1, 0, 1, 1, 1, 0, 1, 1, 0, 1, 1, 0, 0, 0, 0, 0, 0, 0, 1, 0, 0, 0, 1, 1, 0, 0, 1, 0, 0, 1, 1, 0, 0, 1, 1, 1, 1, 1, 0, 1, 0, 0, 1, 0, 1, 0, 1, 1, 0, 1, 1, 0, 1, 0, 0, 0, 1, 1, 1, 1, 0, 0, 0, 1, 0, 0, 1, 0, 1, 1, 0, 0, 0, 1, 0, 0, 0, 1, 1, 1, 0, 0, 1, 1, 1, 0, 0, 1, 1, 1, 0, 0, 1, 1, 1, 0, 0, 1, 1, 1, 1, 1, 0, 1, 1, 1, 0, 1, 1, 0, 1, 0, 1, 0, 0, 0, 0, 0, 1, 1, 1, 0, 0, 0, 1, 0, 1, 0, 0, 0, 0, 1, 1, 0, 0, 1, 1, 1, 1, 0, 1]

Expected vs Actual Result

I understand that the output is expected to be expressed in little endian, but even considering that, there does not seem to be a direct relation between the expected and actual output.

I am unsure if this is a bug or if the output is simply in an unexpected format. Any clarification or guidance on this would be greatly appreciated.

tiagofneto avatar Jun 08 '23 04:06 tiagofneto

Hi,

0x3761ab92011074a873e2f15bc14e376c0464cfa56d1e2588e739cfbb5071433d is larger than 0x30644e72e131a029b85045b68181585d2833e84879b9709143e1f593f0000001 , bn254 fr modulus, so I assume you are just overflowing the modulus 👍

gbotrel avatar Jun 09 '23 18:06 gbotrel

Maybe interesting to have an option to avoid truncating inputs (or warn?) larger than the curve modulus, especially for public inputs?

hussein-aitlahcen avatar Aug 04 '23 15:08 hussein-aitlahcen

Fixed with https://github.com/Consensys/gnark/security/advisories/GHSA-498w-5j49-vqjg

ivokub avatar Apr 05 '24 09:04 ivokub