This repository was archived by the owner on Aug 4, 2026. It is now read-only.

Repository files navigation

ginger-lib: a RUST library for recursive SNARKs using Darlin

Ginger-lib (in Italian zen-zero) is a high-performance library for building succinct zero-knowledge arguments by means of the Darlin protocol suite. The core piece of the protocol suite is the Darlin argument system, a recursion-friendly variant of the Marlin zk-SNARK for rank-1 constraint systems (R1CS). Darlin relies on the dlog polynomial commitment scheme and uses an aggregation technique similar to Halo for amortizing the computational costs of both prover and verifier over time. The scheme requires no trusted setup and allows ordinary sized elliptic curves. See our reference paper HGB for details.

The library is based on a fork from arkworks, and is adapted to the specific needs of the Darlin protocol suite.

Overview

The full protocol suite comes with a variety of proof systems to support a wide range of applications. These are

  • Coboundary Marlin for simple non-recursive proofs,
  • Darlin for recursion, including a standard set of circuits for proof composition,
  • Rainbow Marlin, yet another Marlin variant, which transforms Darlin proofs into ordinary Coboundary Marlin proofs.

A detailed specification of Coboundary Marlin and Darlin, including security proofs are given in HGB. In short, Coboundary Marlin is an optimization of Marlin. It uses a simpler "sumcheck" argument, and applies a different matrix arithmetization based on the normalized Lagrange kernel. Darlin is Coboundary Marlin turned into a recursive argument (or, accumulator SNARK) which aggregates both the dlog hard parts as well as Marlin's inner sumchecks over "time". Inner sumcheck aggregation is done across circuits, and a Darlin proof includes an inner sumcheck aggregator (or, Rainbow Accumulator) which supports a given pre-defined family of circuits.

Rainbow Marlin is used to verify a previous Darlin proof by running a cross-circuit inner sumcheck argument for its Rainbow Accumulator, overall transforming Darlin proofs into simple Marlin proofs.

The library comes with a collection of circuits, manually optimized for a lower R1CS density whenever needed.

Directory structure

The high-level structure of the repository is as follows:

  • algebra: implements the mathematical base components: large integers, finite fields, elliptic curves, and fast Fourier transform.
  • primitives: serves basic cryptographic primitives (such as hash functions and Merkle trees, signature schemes, verifiable random functions).
  • proof-systems: This is the main crate for the Darlin protocol suite. It provides the traits and structs for proof carrying data and the above mentioned proof systems. Groth16 and GM17 proving systems have been kept too for backward compatibility.
  • r1cs-core: Defines core functionalities for rank-1 constraint systems (the circuit synthesizer).
  • r1cs-std: This crate contains elementary "standard" circuits (or, "gadgets"): Boolean operations, native field and elliptic curve arithmetics.
  • r1cs-crypto: Provides the circuits for various cryptographic primitives, such as the Poseidon hash, signature schemes, and SNARK verifiers.

In addition, there is a bench-utils crate which contains an infrastructure for benchmarking, including macros for timing code segments.

Release Note

However, it does not yet serve proof composition. The proof-systems subcrate darlin prepares for the full Darlin protocol suite by providing the traits and structs necessary for proof carrying data, and puts simple Coboundary Marlin proofs from marlin into this framework. It further contains additional tools for scaling verification:

  • A batch verifier for Darlin/Marlin proofs, and
  • a post-processor for batches of Darlin/Marlin proofs, which aggregates their dlog hard parts into a single one.

Build instructions

The library compiles on the 1.51.0 stable toolchain of the Rust compiler.

git clone https://github.com/HorizenOfficial/ginger-lib.git
cd ginger-lib
cargo build --release

Run tests using

cargo test --all-features 

More detailed information can be found in our build guide.

About

Ginger-lib is a general purpose zk-SNARK library that supports recursive proof composition

Resources

Contributing

Stars

85 stars

Watchers

17 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
This repository was archived by the owner on Aug 4, 2026. It is now read-only.

Repository files navigation

ginger-lib: a RUST library for recursive SNARKs using Darlin

Ginger-lib (in Italian zen-zero) is a high-performance library for building succinct zero-knowledge arguments by means of the Darlin protocol suite. The core piece of the protocol suite is the Darlin argument system, a recursion-friendly variant of the Marlin zk-SNARK for rank-1 constraint systems (R1CS). Darlin relies on the dlog polynomial commitment scheme and uses an aggregation technique similar to Halo for amortizing the computational costs of both prover and verifier over time. The scheme requires no trusted setup and allows ordinary sized elliptic curves. See our reference paper HGB for details.

The library is based on a fork from arkworks, and is adapted to the specific needs of the Darlin protocol suite.

Overview

The full protocol suite comes with a variety of proof systems to support a wide range of applications. These are

  • Coboundary Marlin for simple non-recursive proofs,
  • Darlin for recursion, including a standard set of circuits for proof composition,
  • Rainbow Marlin, yet another Marlin variant, which transforms Darlin proofs into ordinary Coboundary Marlin proofs.

A detailed specification of Coboundary Marlin and Darlin, including security proofs are given in HGB. In short, Coboundary Marlin is an optimization of Marlin. It uses a simpler "sumcheck" argument, and applies a different matrix arithmetization based on the normalized Lagrange kernel. Darlin is Coboundary Marlin turned into a recursive argument (or, accumulator SNARK) which aggregates both the dlog hard parts as well as Marlin's inner sumchecks over "time". Inner sumcheck aggregation is done across circuits, and a Darlin proof includes an inner sumcheck aggregator (or, Rainbow Accumulator) which supports a given pre-defined family of circuits.

Rainbow Marlin is used to verify a previous Darlin proof by running a cross-circuit inner sumcheck argument for its Rainbow Accumulator, overall transforming Darlin proofs into simple Marlin proofs.

The library comes with a collection of circuits, manually optimized for a lower R1CS density whenever needed.

Directory structure

The high-level structure of the repository is as follows:

  • algebra: implements the mathematical base components: large integers, finite fields, elliptic curves, and fast Fourier transform.
  • primitives: serves basic cryptographic primitives (such as hash functions and Merkle trees, signature schemes, verifiable random functions).
  • proof-systems: This is the main crate for the Darlin protocol suite. It provides the traits and structs for proof carrying data and the above mentioned proof systems. Groth16 and GM17 proving systems have been kept too for backward compatibility.
  • r1cs-core: Defines core functionalities for rank-1 constraint systems (the circuit synthesizer).
  • r1cs-std: This crate contains elementary "standard" circuits (or, "gadgets"): Boolean operations, native field and elliptic curve arithmetics.
  • r1cs-crypto: Provides the circuits for various cryptographic primitives, such as the Poseidon hash, signature schemes, and SNARK verifiers.

In addition, there is a bench-utils crate which contains an infrastructure for benchmarking, including macros for timing code segments.

Release Note

However, it does not yet serve proof composition. The proof-systems subcrate darlin prepares for the full Darlin protocol suite by providing the traits and structs necessary for proof carrying data, and puts simple Coboundary Marlin proofs from marlin into this framework. It further contains additional tools for scaling verification:

  • A batch verifier for Darlin/Marlin proofs, and
  • a post-processor for batches of Darlin/Marlin proofs, which aggregates their dlog hard parts into a single one.

Build instructions

The library compiles on the 1.51.0 stable toolchain of the Rust compiler.

git clone https://github.com/HorizenOfficial/ginger-lib.git
cd ginger-lib
cargo build --release

Run tests using

cargo test --all-features 

More detailed information can be found in our build guide.

About

Ginger-lib is a general purpose zk-SNARK library that supports recursive proof composition

Resources

Contributing

Stars

85 stars

Watchers

17 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Aug 4, 2026. It is now read-only.

Repository files navigation

ginger-lib: a RUST library for recursive SNARKs using Darlin

Ginger-lib (in Italian zen-zero) is a high-performance library for building succinct zero-knowledge arguments by means of the Darlin protocol suite. The core piece of the protocol suite is the Darlin argument system, a recursion-friendly variant of the Marlin zk-SNARK for rank-1 constraint systems (R1CS). Darlin relies on the dlog polynomial commitment scheme and uses an aggregation technique similar to Halo for amortizing the computational costs of both prover and verifier over time. The scheme requires no trusted setup and allows ordinary sized elliptic curves. See our reference paper HGB for details.

The library is based on a fork from arkworks, and is adapted to the specific needs of the Darlin protocol suite.

Overview

The full protocol suite comes with a variety of proof systems to support a wide range of applications. These are

  • Coboundary Marlin for simple non-recursive proofs,
  • Darlin for recursion, including a standard set of circuits for proof composition,
  • Rainbow Marlin, yet another Marlin variant, which transforms Darlin proofs into ordinary Coboundary Marlin proofs.

A detailed specification of Coboundary Marlin and Darlin, including security proofs are given in HGB. In short, Coboundary Marlin is an optimization of Marlin. It uses a simpler "sumcheck" argument, and applies a different matrix arithmetization based on the normalized Lagrange kernel. Darlin is Coboundary Marlin turned into a recursive argument (or, accumulator SNARK) which aggregates both the dlog hard parts as well as Marlin's inner sumchecks over "time". Inner sumcheck aggregation is done across circuits, and a Darlin proof includes an inner sumcheck aggregator (or, Rainbow Accumulator) which supports a given pre-defined family of circuits.

Rainbow Marlin is used to verify a previous Darlin proof by running a cross-circuit inner sumcheck argument for its Rainbow Accumulator, overall transforming Darlin proofs into simple Marlin proofs.

The library comes with a collection of circuits, manually optimized for a lower R1CS density whenever needed.

Directory structure

The high-level structure of the repository is as follows:

  • algebra: implements the mathematical base components: large integers, finite fields, elliptic curves, and fast Fourier transform.
  • primitives: serves basic cryptographic primitives (such as hash functions and Merkle trees, signature schemes, verifiable random functions).
  • proof-systems: This is the main crate for the Darlin protocol suite. It provides the traits and structs for proof carrying data and the above mentioned proof systems. Groth16 and GM17 proving systems have been kept too for backward compatibility.
  • r1cs-core: Defines core functionalities for rank-1 constraint systems (the circuit synthesizer).
  • r1cs-std: This crate contains elementary "standard" circuits (or, "gadgets"): Boolean operations, native field and elliptic curve arithmetics.
  • r1cs-crypto: Provides the circuits for various cryptographic primitives, such as the Poseidon hash, signature schemes, and SNARK verifiers.

In addition, there is a bench-utils crate which contains an infrastructure for benchmarking, including macros for timing code segments.

Release Note

However, it does not yet serve proof composition. The proof-systems subcrate darlin prepares for the full Darlin protocol suite by providing the traits and structs necessary for proof carrying data, and puts simple Coboundary Marlin proofs from marlin into this framework. It further contains additional tools for scaling verification:

  • A batch verifier for Darlin/Marlin proofs, and
  • a post-processor for batches of Darlin/Marlin proofs, which aggregates their dlog hard parts into a single one.

Build instructions

The library compiles on the 1.51.0 stable toolchain of the Rust compiler.

git clone https://github.com/HorizenOfficial/ginger-lib.git
cd ginger-lib
cargo build --release

Run tests using

cargo test --all-features 

More detailed information can be found in our build guide.

About

Ginger-lib is a general purpose zk-SNARK library that supports recursive proof composition

Resources

Contributing

Stars

85 stars

Watchers

17 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Aug 4, 2026. It is now read-only.

Repository files navigation

ginger-lib: a RUST library for recursive SNARKs using Darlin

Ginger-lib (in Italian zen-zero) is a high-performance library for building succinct zero-knowledge arguments by means of the Darlin protocol suite. The core piece of the protocol suite is the Darlin argument system, a recursion-friendly variant of the Marlin zk-SNARK for rank-1 constraint systems (R1CS). Darlin relies on the dlog polynomial commitment scheme and uses an aggregation technique similar to Halo for amortizing the computational costs of both prover and verifier over time. The scheme requires no trusted setup and allows ordinary sized elliptic curves. See our reference paper HGB for details.

The library is based on a fork from arkworks, and is adapted to the specific needs of the Darlin protocol suite.

Overview

The full protocol suite comes with a variety of proof systems to support a wide range of applications. These are

  • Coboundary Marlin for simple non-recursive proofs,
  • Darlin for recursion, including a standard set of circuits for proof composition,
  • Rainbow Marlin, yet another Marlin variant, which transforms Darlin proofs into ordinary Coboundary Marlin proofs.

A detailed specification of Coboundary Marlin and Darlin, including security proofs are given in HGB. In short, Coboundary Marlin is an optimization of Marlin. It uses a simpler "sumcheck" argument, and applies a different matrix arithmetization based on the normalized Lagrange kernel. Darlin is Coboundary Marlin turned into a recursive argument (or, accumulator SNARK) which aggregates both the dlog hard parts as well as Marlin's inner sumchecks over "time". Inner sumcheck aggregation is done across circuits, and a Darlin proof includes an inner sumcheck aggregator (or, Rainbow Accumulator) which supports a given pre-defined family of circuits.

Rainbow Marlin is used to verify a previous Darlin proof by running a cross-circuit inner sumcheck argument for its Rainbow Accumulator, overall transforming Darlin proofs into simple Marlin proofs.

The library comes with a collection of circuits, manually optimized for a lower R1CS density whenever needed.

Directory structure

The high-level structure of the repository is as follows:

  • algebra: implements the mathematical base components: large integers, finite fields, elliptic curves, and fast Fourier transform.
  • primitives: serves basic cryptographic primitives (such as hash functions and Merkle trees, signature schemes, verifiable random functions).
  • proof-systems: This is the main crate for the Darlin protocol suite. It provides the traits and structs for proof carrying data and the above mentioned proof systems. Groth16 and GM17 proving systems have been kept too for backward compatibility.
  • r1cs-core: Defines core functionalities for rank-1 constraint systems (the circuit synthesizer).
  • r1cs-std: This crate contains elementary "standard" circuits (or, "gadgets"): Boolean operations, native field and elliptic curve arithmetics.
  • r1cs-crypto: Provides the circuits for various cryptographic primitives, such as the Poseidon hash, signature schemes, and SNARK verifiers.

In addition, there is a bench-utils crate which contains an infrastructure for benchmarking, including macros for timing code segments.

Release Note

However, it does not yet serve proof composition. The proof-systems subcrate darlin prepares for the full Darlin protocol suite by providing the traits and structs necessary for proof carrying data, and puts simple Coboundary Marlin proofs from marlin into this framework. It further contains additional tools for scaling verification:

  • A batch verifier for Darlin/Marlin proofs, and
  • a post-processor for batches of Darlin/Marlin proofs, which aggregates their dlog hard parts into a single one.

Build instructions

The library compiles on the 1.51.0 stable toolchain of the Rust compiler.

git clone https://github.com/HorizenOfficial/ginger-lib.git
cd ginger-lib
cargo build --release

Run tests using

cargo test --all-features 

More detailed information can be found in our build guide.

About

Ginger-lib is a general purpose zk-SNARK library that supports recursive proof composition

Resources

Contributing

Stars

85 stars

Watchers

17 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
This repository was archived by the owner on Aug 4, 2026. It is now read-only.

Repository files navigation

ginger-lib: a RUST library for recursive SNARKs using Darlin

Ginger-lib (in Italian zen-zero) is a high-performance library for building succinct zero-knowledge arguments by means of the Darlin protocol suite. The core piece of the protocol suite is the Darlin argument system, a recursion-friendly variant of the Marlin zk-SNARK for rank-1 constraint systems (R1CS). Darlin relies on the dlog polynomial commitment scheme and uses an aggregation technique similar to Halo for amortizing the computational costs of both prover and verifier over time. The scheme requires no trusted setup and allows ordinary sized elliptic curves. See our reference paper HGB for details.

The library is based on a fork from arkworks, and is adapted to the specific needs of the Darlin protocol suite.

Overview

The full protocol suite comes with a variety of proof systems to support a wide range of applications. These are

  • Coboundary Marlin for simple non-recursive proofs,
  • Darlin for recursion, including a standard set of circuits for proof composition,
  • Rainbow Marlin, yet another Marlin variant, which transforms Darlin proofs into ordinary Coboundary Marlin proofs.

A detailed specification of Coboundary Marlin and Darlin, including security proofs are given in HGB. In short, Coboundary Marlin is an optimization of Marlin. It uses a simpler "sumcheck" argument, and applies a different matrix arithmetization based on the normalized Lagrange kernel. Darlin is Coboundary Marlin turned into a recursive argument (or, accumulator SNARK) which aggregates both the dlog hard parts as well as Marlin's inner sumchecks over "time". Inner sumcheck aggregation is done across circuits, and a Darlin proof includes an inner sumcheck aggregator (or, Rainbow Accumulator) which supports a given pre-defined family of circuits.

Rainbow Marlin is used to verify a previous Darlin proof by running a cross-circuit inner sumcheck argument for its Rainbow Accumulator, overall transforming Darlin proofs into simple Marlin proofs.

The library comes with a collection of circuits, manually optimized for a lower R1CS density whenever needed.

Directory structure

The high-level structure of the repository is as follows:

  • algebra: implements the mathematical base components: large integers, finite fields, elliptic curves, and fast Fourier transform.
  • primitives: serves basic cryptographic primitives (such as hash functions and Merkle trees, signature schemes, verifiable random functions).
  • proof-systems: This is the main crate for the Darlin protocol suite. It provides the traits and structs for proof carrying data and the above mentioned proof systems. Groth16 and GM17 proving systems have been kept too for backward compatibility.
  • r1cs-core: Defines core functionalities for rank-1 constraint systems (the circuit synthesizer).
  • r1cs-std: This crate contains elementary "standard" circuits (or, "gadgets"): Boolean operations, native field and elliptic curve arithmetics.
  • r1cs-crypto: Provides the circuits for various cryptographic primitives, such as the Poseidon hash, signature schemes, and SNARK verifiers.

In addition, there is a bench-utils crate which contains an infrastructure for benchmarking, including macros for timing code segments.

Release Note

However, it does not yet serve proof composition. The proof-systems subcrate darlin prepares for the full Darlin protocol suite by providing the traits and structs necessary for proof carrying data, and puts simple Coboundary Marlin proofs from marlin into this framework. It further contains additional tools for scaling verification:

  • A batch verifier for Darlin/Marlin proofs, and
  • a post-processor for batches of Darlin/Marlin proofs, which aggregates their dlog hard parts into a single one.

Build instructions

The library compiles on the 1.51.0 stable toolchain of the Rust compiler.

git clone https://github.com/HorizenOfficial/ginger-lib.git
cd ginger-lib
cargo build --release

Run tests using

cargo test --all-features 

More detailed information can be found in our build guide.

About

Ginger-lib is a general purpose zk-SNARK library that supports recursive proof composition

Resources

Contributing

Stars

85 stars

Watchers

17 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Aug 4, 2026. It is now read-only.

Repository files navigation

ginger-lib: a RUST library for recursive SNARKs using Darlin

Ginger-lib (in Italian zen-zero) is a high-performance library for building succinct zero-knowledge arguments by means of the Darlin protocol suite. The core piece of the protocol suite is the Darlin argument system, a recursion-friendly variant of the Marlin zk-SNARK for rank-1 constraint systems (R1CS). Darlin relies on the dlog polynomial commitment scheme and uses an aggregation technique similar to Halo for amortizing the computational costs of both prover and verifier over time. The scheme requires no trusted setup and allows ordinary sized elliptic curves. See our reference paper HGB for details.

The library is based on a fork from arkworks, and is adapted to the specific needs of the Darlin protocol suite.

Overview

The full protocol suite comes with a variety of proof systems to support a wide range of applications. These are

  • Coboundary Marlin for simple non-recursive proofs,
  • Darlin for recursion, including a standard set of circuits for proof composition,
  • Rainbow Marlin, yet another Marlin variant, which transforms Darlin proofs into ordinary Coboundary Marlin proofs.

A detailed specification of Coboundary Marlin and Darlin, including security proofs are given in HGB. In short, Coboundary Marlin is an optimization of Marlin. It uses a simpler "sumcheck" argument, and applies a different matrix arithmetization based on the normalized Lagrange kernel. Darlin is Coboundary Marlin turned into a recursive argument (or, accumulator SNARK) which aggregates both the dlog hard parts as well as Marlin's inner sumchecks over "time". Inner sumcheck aggregation is done across circuits, and a Darlin proof includes an inner sumcheck aggregator (or, Rainbow Accumulator) which supports a given pre-defined family of circuits.

Rainbow Marlin is used to verify a previous Darlin proof by running a cross-circuit inner sumcheck argument for its Rainbow Accumulator, overall transforming Darlin proofs into simple Marlin proofs.

The library comes with a collection of circuits, manually optimized for a lower R1CS density whenever needed.

Directory structure

The high-level structure of the repository is as follows:

  • algebra: implements the mathematical base components: large integers, finite fields, elliptic curves, and fast Fourier transform.
  • primitives: serves basic cryptographic primitives (such as hash functions and Merkle trees, signature schemes, verifiable random functions).
  • proof-systems: This is the main crate for the Darlin protocol suite. It provides the traits and structs for proof carrying data and the above mentioned proof systems. Groth16 and GM17 proving systems have been kept too for backward compatibility.
  • r1cs-core: Defines core functionalities for rank-1 constraint systems (the circuit synthesizer).
  • r1cs-std: This crate contains elementary "standard" circuits (or, "gadgets"): Boolean operations, native field and elliptic curve arithmetics.
  • r1cs-crypto: Provides the circuits for various cryptographic primitives, such as the Poseidon hash, signature schemes, and SNARK verifiers.

In addition, there is a bench-utils crate which contains an infrastructure for benchmarking, including macros for timing code segments.

Release Note

However, it does not yet serve proof composition. The proof-systems subcrate darlin prepares for the full Darlin protocol suite by providing the traits and structs necessary for proof carrying data, and puts simple Coboundary Marlin proofs from marlin into this framework. It further contains additional tools for scaling verification:

  • A batch verifier for Darlin/Marlin proofs, and
  • a post-processor for batches of Darlin/Marlin proofs, which aggregates their dlog hard parts into a single one.

Build instructions

The library compiles on the 1.51.0 stable toolchain of the Rust compiler.

git clone https://github.com/HorizenOfficial/ginger-lib.git
cd ginger-lib
cargo build --release

Run tests using

cargo test --all-features 

More detailed information can be found in our build guide.

About

Ginger-lib is a general purpose zk-SNARK library that supports recursive proof composition

Resources

Contributing

Stars

85 stars

Watchers

17 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Aug 4, 2026. It is now read-only.

Repository files navigation

ginger-lib: a RUST library for recursive SNARKs using Darlin

Ginger-lib (in Italian zen-zero) is a high-performance library for building succinct zero-knowledge arguments by means of the Darlin protocol suite. The core piece of the protocol suite is the Darlin argument system, a recursion-friendly variant of the Marlin zk-SNARK for rank-1 constraint systems (R1CS). Darlin relies on the dlog polynomial commitment scheme and uses an aggregation technique similar to Halo for amortizing the computational costs of both prover and verifier over time. The scheme requires no trusted setup and allows ordinary sized elliptic curves. See our reference paper HGB for details.

The library is based on a fork from arkworks, and is adapted to the specific needs of the Darlin protocol suite.

Overview

The full protocol suite comes with a variety of proof systems to support a wide range of applications. These are

  • Coboundary Marlin for simple non-recursive proofs,
  • Darlin for recursion, including a standard set of circuits for proof composition,
  • Rainbow Marlin, yet another Marlin variant, which transforms Darlin proofs into ordinary Coboundary Marlin proofs.

A detailed specification of Coboundary Marlin and Darlin, including security proofs are given in HGB. In short, Coboundary Marlin is an optimization of Marlin. It uses a simpler "sumcheck" argument, and applies a different matrix arithmetization based on the normalized Lagrange kernel. Darlin is Coboundary Marlin turned into a recursive argument (or, accumulator SNARK) which aggregates both the dlog hard parts as well as Marlin's inner sumchecks over "time". Inner sumcheck aggregation is done across circuits, and a Darlin proof includes an inner sumcheck aggregator (or, Rainbow Accumulator) which supports a given pre-defined family of circuits.

Rainbow Marlin is used to verify a previous Darlin proof by running a cross-circuit inner sumcheck argument for its Rainbow Accumulator, overall transforming Darlin proofs into simple Marlin proofs.

The library comes with a collection of circuits, manually optimized for a lower R1CS density whenever needed.

Directory structure

The high-level structure of the repository is as follows:

  • algebra: implements the mathematical base components: large integers, finite fields, elliptic curves, and fast Fourier transform.
  • primitives: serves basic cryptographic primitives (such as hash functions and Merkle trees, signature schemes, verifiable random functions).
  • proof-systems: This is the main crate for the Darlin protocol suite. It provides the traits and structs for proof carrying data and the above mentioned proof systems. Groth16 and GM17 proving systems have been kept too for backward compatibility.
  • r1cs-core: Defines core functionalities for rank-1 constraint systems (the circuit synthesizer).
  • r1cs-std: This crate contains elementary "standard" circuits (or, "gadgets"): Boolean operations, native field and elliptic curve arithmetics.
  • r1cs-crypto: Provides the circuits for various cryptographic primitives, such as the Poseidon hash, signature schemes, and SNARK verifiers.

In addition, there is a bench-utils crate which contains an infrastructure for benchmarking, including macros for timing code segments.

Release Note

However, it does not yet serve proof composition. The proof-systems subcrate darlin prepares for the full Darlin protocol suite by providing the traits and structs necessary for proof carrying data, and puts simple Coboundary Marlin proofs from marlin into this framework. It further contains additional tools for scaling verification:

  • A batch verifier for Darlin/Marlin proofs, and
  • a post-processor for batches of Darlin/Marlin proofs, which aggregates their dlog hard parts into a single one.

Build instructions

The library compiles on the 1.51.0 stable toolchain of the Rust compiler.

git clone https://github.com/HorizenOfficial/ginger-lib.git
cd ginger-lib
cargo build --release

Run tests using

cargo test --all-features 

More detailed information can be found in our build guide.

About

Ginger-lib is a general purpose zk-SNARK library that supports recursive proof composition

Resources

Contributing

Stars

85 stars

Watchers

17 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
This repository was archived by the owner on Aug 4, 2026. It is now read-only.

Repository files navigation

ginger-lib: a RUST library for recursive SNARKs using Darlin

Ginger-lib (in Italian zen-zero) is a high-performance library for building succinct zero-knowledge arguments by means of the Darlin protocol suite. The core piece of the protocol suite is the Darlin argument system, a recursion-friendly variant of the Marlin zk-SNARK for rank-1 constraint systems (R1CS). Darlin relies on the dlog polynomial commitment scheme and uses an aggregation technique similar to Halo for amortizing the computational costs of both prover and verifier over time. The scheme requires no trusted setup and allows ordinary sized elliptic curves. See our reference paper HGB for details.

The library is based on a fork from arkworks, and is adapted to the specific needs of the Darlin protocol suite.

Overview

The full protocol suite comes with a variety of proof systems to support a wide range of applications. These are

  • Coboundary Marlin for simple non-recursive proofs,
  • Darlin for recursion, including a standard set of circuits for proof composition,
  • Rainbow Marlin, yet another Marlin variant, which transforms Darlin proofs into ordinary Coboundary Marlin proofs.

A detailed specification of Coboundary Marlin and Darlin, including security proofs are given in HGB. In short, Coboundary Marlin is an optimization of Marlin. It uses a simpler "sumcheck" argument, and applies a different matrix arithmetization based on the normalized Lagrange kernel. Darlin is Coboundary Marlin turned into a recursive argument (or, accumulator SNARK) which aggregates both the dlog hard parts as well as Marlin's inner sumchecks over "time". Inner sumcheck aggregation is done across circuits, and a Darlin proof includes an inner sumcheck aggregator (or, Rainbow Accumulator) which supports a given pre-defined family of circuits.

Rainbow Marlin is used to verify a previous Darlin proof by running a cross-circuit inner sumcheck argument for its Rainbow Accumulator, overall transforming Darlin proofs into simple Marlin proofs.

The library comes with a collection of circuits, manually optimized for a lower R1CS density whenever needed.

Directory structure

The high-level structure of the repository is as follows:

  • algebra: implements the mathematical base components: large integers, finite fields, elliptic curves, and fast Fourier transform.
  • primitives: serves basic cryptographic primitives (such as hash functions and Merkle trees, signature schemes, verifiable random functions).
  • proof-systems: This is the main crate for the Darlin protocol suite. It provides the traits and structs for proof carrying data and the above mentioned proof systems. Groth16 and GM17 proving systems have been kept too for backward compatibility.
  • r1cs-core: Defines core functionalities for rank-1 constraint systems (the circuit synthesizer).
  • r1cs-std: This crate contains elementary "standard" circuits (or, "gadgets"): Boolean operations, native field and elliptic curve arithmetics.
  • r1cs-crypto: Provides the circuits for various cryptographic primitives, such as the Poseidon hash, signature schemes, and SNARK verifiers.

In addition, there is a bench-utils crate which contains an infrastructure for benchmarking, including macros for timing code segments.

Release Note

However, it does not yet serve proof composition. The proof-systems subcrate darlin prepares for the full Darlin protocol suite by providing the traits and structs necessary for proof carrying data, and puts simple Coboundary Marlin proofs from marlin into this framework. It further contains additional tools for scaling verification:

  • A batch verifier for Darlin/Marlin proofs, and
  • a post-processor for batches of Darlin/Marlin proofs, which aggregates their dlog hard parts into a single one.

Build instructions

The library compiles on the 1.51.0 stable toolchain of the Rust compiler.

git clone https://github.com/HorizenOfficial/ginger-lib.git
cd ginger-lib
cargo build --release

Run tests using

cargo test --all-features 

More detailed information can be found in our build guide.

About

Ginger-lib is a general purpose zk-SNARK library that supports recursive proof composition

Resources

Contributing

Stars

85 stars

Watchers

17 watching

Forks

Releases

Packages

Used by

Contributors

Languages