In brief
This page is source-sensitive. Treat application, covenant, proof, and readiness wording as bounded by the listed public sources and Open Questions.
What this page explains#
A failure matrix makes ZK safer by naming what must fail. This page sits in ZK, Groth16, And RISC Zero Succinct. It gives the topic a plain-language handle first, then shows the working idea, the mechanism, the source trail, and any limits that still matter. This category separates proof verification from application validity. Groth16 and RISC Zero Succinct can verify selected statements, while covenant scripts, successor checks, source limits, and accepted evidence still carry separate responsibility.
The writing follows a simple Kaspa documentation pattern: answer the practical question first, then link outward for details. The closest public sources for this page are RK-ZK-TAGS, RK-ZK-GROTH16, RK-ZK-GROTH16-ERRORS, RK-ZK-RISC0, RK-ZK-RISC0-ERRORS. Local notes can help choose what to explain, but public-facing references resolve to upstream websites, repositories, papers, release pages, or docs.
How to think about it#
The practical model starts by naming the layer that owns the topic: wallet use, node operation, consensus, transaction validation, Toccata script behavior, tooling, or research. From there, the page shows which public source can support the explanation and where the explanation becomes incomplete.
For Negative Cases And Failure Matrix, the model is built around these anchors: wrong tag or unknown tag; under-budget compute; malformed proof or verifier key; bad public input length or out-of-field value; stale covenant head, wrong successor, or wrong network remain app/readiness checks unless backed by covenant tests or public observations. This model is useful, but it does not encode every constant, branch, error type, or edge case. Those details belong in the source path and the source notes.
How it works#
1. wrong tag or unknown tag. ZK verification is a constrained script operation, not a general declaration that an application transition is sound. Tags select verifier paths, costs decide whether the transaction can afford the check, and public inputs or journals bind the proof to the state claim. The covenant or application still has to validate the surrounding transition, observe acceptance, and test negative cases.
2. under-budget compute. ZK verification is a constrained script operation, not a general declaration that an application transition is sound. Tags select verifier paths, costs decide whether the transaction can afford the check, and public inputs or journals bind the proof to the state claim. The covenant or application still has to validate the surrounding transition, observe acceptance, and test negative cases.
3. malformed proof or verifier key. ZK verification is a constrained script operation, not a general declaration that an application transition is sound. Tags select verifier paths, costs decide whether the transaction can afford the check, and public inputs or journals bind the proof to the state claim. The covenant or application still has to validate the surrounding transition, observe acceptance, and test negative cases.
4. bad public input length or out-of-field value. ZK verification is a constrained script operation, not a general declaration that an application transition is sound. Tags select verifier paths, costs decide whether the transaction can afford the check, and public inputs or journals bind the proof to the state claim. The covenant or application still has to validate the surrounding transition, observe acceptance, and test negative cases.
5. stale covenant head, wrong successor, or wrong network remain app/readiness checks unless backed by covenant tests or public observations. ZK-and-covenant pages are about binding a verified statement to the state transition the application actually cares about. The proof may check a statement, but the script still has to bind the prior state, successor output, verifier identity, public input or journal, fee/resource context, and accepted-state evidence.
This mechanism section separates proof verification from application validity. A verifier result still needs script binding, covenant checks, transaction validity, and accepted-state evidence before an app claim is closed.
How to check it#
| Step | Check | Evidence gate |
|---|---|---|
| 1 | Check wrong tag or unknown tag. | Read RK-ZK-TAGS, RK-ZK-GROTH16, RK-ZK-GROTH16-ERRORS; verify proof format, tag, cost, public input or journal binding, and script failure cases. |
| 2 | Check under-budget compute. | Read RK-ZK-TAGS, RK-ZK-GROTH16, RK-ZK-GROTH16-ERRORS; verify proof format, tag, cost, public input or journal binding, and script failure cases. |
| 3 | Check malformed proof or verifier key. | Read RK-ZK-TAGS, RK-ZK-GROTH16, RK-ZK-GROTH16-ERRORS; verify proof format, tag, cost, public input or journal binding, and script failure cases. |
| 4 | Check bad public input length or out-of-field value. | Read RK-ZK-TAGS, RK-ZK-GROTH16, RK-ZK-GROTH16-ERRORS; verify proof format, tag, cost, public input or journal binding, and script failure cases. |
| 5 | Check stale covenant head, wrong successor, or wrong network remain app/readiness checks unless backed by covenant tests or public observations. | Read RK-ZK-TAGS, RK-ZK-GROTH16, RK-ZK-GROTH16-ERRORS; verify proof format, tag, cost, public input or journal binding, and script failure cases. |
When using this page for ZK material, separate proof verification from application validity. Check the verifier path, proof format, public inputs or journal, compute cost, covenant binding, failure cases, and accepted evidence before claiming a transition is valid.
Related Pages#
- 08-proof-binding-to-covenant-state
- zk-groth16-risczero
- 10-groth16-transition-starter