pub fn circuit_xmss_multisig_committed(
builder: &CircuitBuilder,
wires: &CommittedMultiSigWires,
)Expand description
The aggregate verification against a committed signer set rather than a published one.
Three things are checked, and all three are needed:
- every signature verifies, as in the published form,
- the keys strictly increase, so no two signers are the same signer,
- they hash to the published commitment.
ยงWhy all three
Verification alone counts signatures, not signers: one key repeated across every slot passes it.
The commitment alone fixes a sequence, not a set. One set of keys in two orders gives two commitments, and so does one key repeated.
A verifier holding the set would not know which of them to expect.
Strict increase settles both at once. A repeat is not an increase, so repeats are out. One order survives per set, so the commitment commits to the set.