pub fn circuit_xmss_verify(
builder: &CircuitBuilder,
public_param: &[Wire; 2],
merkle_root: &[Wire; 2],
message: &[Wire; 4],
epoch: Wire,
signature: &XmssSignatureWires,
)Expand description
In-circuit form of xmss_verify.
Three checks are stacked:
- the randomness encodes to a valid codeword, and the chains walk from their tips to the Winternitz public key,
- those chain ends hash into the Merkle leaf,
- the authentication path links that leaf to the committed root.
Every digest is derived from the inputs, so this emits constraints and returns nothing.
§Arguments
builder: circuit builder.public_param: the signer’s public parameter.merkle_root: the signer’s committed root.message: the 32-byte message.epoch: the leaf index the signature is at.signature: the signature’s witness wires.