pub fn circuit_tweak_hash(
builder: &CircuitBuilder,
public_param: &[Wire; 2],
tweak_type: u8,
sub_position: Wire,
index: Wire,
payload: &[Wire],
) -> [Wire; 2]Expand description
In-circuit form of tweak_hash, returning the truncated digest as 64-bit little-endian
wires.
The tweak type is a circuit constant at every call site. The sub-position is a wire: a Merkle node’s level is still a constant fed in as one, but a chain step’s position is computed, so a chain can spend hashes only where its digit says it must. Nothing about it is free for the prover to choose — the caller is what constrains it.
§Arguments
builder: circuit builder.public_param: the per-signer parameter, eight bytes per wire.tweak_type: one of theTWEAK_TYPE_*constants.sub_position: chain position or Merkle level.index: epoch or Merkle node index. Only its low four bytes reach the tweak, matching theu32the reference takes.payload: the hashed payload, eight bytes per wire.
§Returns
The 16-byte digest as DIGEST_WIRES 64-bit little-endian wires.