Skip to main content

compute_platform_sighash

Function compute_platform_sighash 

Source
pub fn compute_platform_sighash(
    bundle_commitment: &[u8; 32],
    extra_data: &[u8],
) -> [u8; 32]
Expand description

Computes the platform sighash from an Orchard bundle commitment and optional transparent field data.

The sighash is computed as: SHA-256(SIGHASH_DOMAIN || bundle_commitment || extra_data)

This binds transparent state transition fields (like output_address in unshield or output_script in shielded withdrawal) to the Orchard signatures, preventing replay attacks where an attacker substitutes transparent fields while reusing a valid Orchard bundle.

It also binds a bundle that has no transparent fields to the one context it was proved for, which an outputs-only bundle cannot do on its own: having no spends, its anchor is never checked against a pool — the client builds it against the empty tree — so it verifies against every pool.

The same computation must be used on both the signing (client) and verification (platform) sides. extra_data is empty only for the credit pool’s ShieldedTransfer, and for the credit pool’s outputs-only bundles at protocol versions that predate their binding (see shield_extra_sighash_data); each other transition has a builder in this module that spells out its layout. ShieldedTransfer is the one that needs no layout of its own: it spends, so it carries an anchor and nullifiers that pin it to one pool and one set of notes.