pub fn compute_platform_sighash(
bundle_commitment: &[u8; 32],
extra_data: &[u8],
) -> [u8; 32]Expand description
Computes the platform sighash from an Orchard bundle commitment and optional transparent field data.
The sighash is computed as:
SHA-256(SIGHASH_DOMAIN || bundle_commitment || extra_data)
This binds transparent state transition fields (like output_address in unshield
or output_script in shielded withdrawal) to the Orchard signatures, preventing
replay attacks where an attacker substitutes transparent fields while reusing a
valid Orchard bundle.
It also binds a bundle that has no transparent fields to the one context it was proved for, which an outputs-only bundle cannot do on its own: having no spends, its anchor is never checked against a pool — the client builds it against the empty tree — so it verifies against every pool.
The same computation must be used on both the signing (client) and verification (platform)
sides. extra_data is empty only for the credit pool’s ShieldedTransfer, and for the credit
pool’s outputs-only bundles at protocol versions that predate their binding (see
shield_extra_sighash_data); each other transition has a builder in this module that
spells out its layout. ShieldedTransfer is the one that needs no layout of its own: it
spends, so it carries an anchor and nullifiers that pin it to one pool and one set of notes.