Skip to main content

circuit_tweak_hash

Function circuit_tweak_hash 

Source
pub fn circuit_tweak_hash(
    builder: &CircuitBuilder,
    public_param: &[Wire; 2],
    tweak_type: u8,
    sub_position: Wire,
    index: Wire,
    payload: &[Wire],
) -> [Wire; 2]
Expand description

In-circuit form of tweak_hash, returning the truncated digest as 64-bit little-endian wires.

The tweak type is a circuit constant at every call site. The sub-position is a wire: a Merkle node’s level is still a constant fed in as one, but a chain step’s position is computed, so a chain can spend hashes only where its digit says it must. Nothing about it is free for the prover to choose — the caller is what constrains it.

§Arguments

  • builder: circuit builder.
  • public_param: the per-signer parameter, eight bytes per wire.
  • tweak_type: one of the TWEAK_TYPE_* constants.
  • sub_position: chain position or Merkle level.
  • index: epoch or Merkle node index. Only its low four bytes reach the tweak, matching the u32 the reference takes.
  • payload: the hashed payload, eight bytes per wire.

§Returns

The 16-byte digest as DIGEST_WIRES 64-bit little-endian wires.