Flat component (in effective bytes at the per-byte storage rate) for the identity-side write an
IdentityTopUpFromShieldedPool performs on top of its per-action nullifier and note writes:
the single AddToIdentityBalance operation, charged as part of the pool-paid flat fee (built
like SHIELDED_UNSHIELD_ADDRESS_STORAGE_BYTES).
Flat component (in effective bytes at the per-byte storage rate) for the recipient’s token
balance item a TokenUnshieldWithShieldedFee writes on top of its per-action nullifier and
note writes.
Calibrated effective storage-byte cost of the single AddBalanceToAddress write an Unshield
performs, crediting the net (unshielding_amount − fee) to the output platform address.
Domain tag of a credit pool Shield bundle. The credit pool’s outputs-only tags continue the
token pool range above: they share the same preimage slot at the same length, so every tag
in both sets must stay distinct from each other and from every StateTransitionType byte.
credit_pool_outputs_only_tags_cannot_collide_with_state_transition_types and
outputs_only_bundle_tags_are_pairwise_distinct hold both reservations.
The state transition type byte the token bundle of a TokenShieldedTransferWithShieldedFee
commits to (StateTransitionType::TokenShieldedTransferWithShieldedFee).
Domain tag an outputs-only token pool bundle commits to. Unlike the three constants above
these are not StateTransitionType bytes — every one of these bundles rides inside a batch
transition — yet they share a preimage slot with them at the same length. They are drawn
from a high range that space has not reached, which nothing in the type system enforces:
StateTransitionType is repr(u8) and could be given one of these bytes. What holds the
reservation is outputs_only_token_pool_tags_cannot_collide_with_state_transition_types,
which asks the enum and fails the build’s tests the day one is assigned here.
Computes the conservative admission floor (in credits) for ShieldFromIdentity:
compute_minimum_shielded_fee plus the versioned per-action and flat
identity-write allowances, priced at the per-byte storage rate. The allowances
cover the complete execution-event admission estimate, including the estimated
note/nullifier and identity writes and the validation context.
Computes the IdentityCreateFromShieldedPool fee (in credits): compute_minimum_shielded_fee
PLUS the variable storage cost of the AddNewIdentity write (identity record + balance +
revision + N key subtrees), which scales with the number of public keys.
Computes the Unshield fee (in credits): compute_minimum_shielded_fee PLUS the flat
storage cost of the single AddBalanceToAddress write an Unshield performs.
Computes the ShieldedWithdrawal fee (in credits): compute_minimum_shielded_fee PLUS the
flat storage cost of the Core withdrawal document a ShieldedWithdrawal inserts.
Computes the fee of an identity-less token pool transition (in credits): two bundles are
verified and stored, so it is compute_minimum_shielded_fee of the fee bundle PLUS the
same base for the token bundle, plus extra_storage_bytes of flat per-transition storage
priced at the storage rate (the balance items the transition writes outside the pools).
The fee of a TokenUnshieldWithShieldedFee: both bundles plus the recipient’s token
balance item, priced as the insert it is for a recipient who has never held this token.
Version 0 layout of the credit pool’s outputs-only bundles — Shield, ShieldFromIdentity and
ShieldFromAssetLock: bundle tag (1) || owner (32). Frozen: never mutate; a layout change
requires a new credit_pool_bundle_binding version.
Extra sighash data of a document action paid from a token shielded pool
(TokenPaymentInfo::V1): the token id, the batch owner, the document’s contract and id
and the amount paid, so a bundle proven for one document cannot be replayed for another
document, batch owner, token or cost.
Version 0 layout: token_id (32) || owner_id (32) || data_contract_id (32) || document_id (32) || amount (8, little endian). Frozen: never mutate; a layout change
requires a new _v1 + version bump.
Builds the transparent extra_data bound into an IdentityTopUpFromShieldedPool’s platform
sighash, with the byte layout identity_id (32) || top_up_amount (u64 LE).
A digest of serialized Orchard actions in wire order: every field of every action, hashed
once. A group action stores it so every signer commits to exactly the same notes, and a
pool mint or burn folds it into its group action id.
Extra sighash data of a credit pool Shield bundle: its kind tag and a digest of the platform
addresses that fund it. See credit_pool_output_only_extra_sighash_data_v0 for why the
credit pool’s outputs-only bundles bind anything at all.
v0 byte layout of shielded_withdrawal_extra_sighash_data (see that function’s doc comment for
the layout and rationale). Frozen: never mutate; a layout change requires a new _v1 + version.
Extra sighash data of a batch TokenBurnFromPool: the token id, the burner and the amount
destroyed, so a bundle proven for one burn cannot be replayed for another token, burner or
amount (72 bytes; no other layout has that length).
Extra sighash data of the credit pool fee bundle of an identity-less token pool transition:
the state transition type, the token id and a digest of the token bundle’s actions, so the
fee bundle can only ever pay for that exact token bundle.
Extra sighash data of an outputs-only token pool bundle — TokenShield, TokenMintToPool,
TokenClaimToPool and TokenDirectPurchaseToPool: the bundle’s domain tag, the token id
and the identity the bundle is attributed to.
Extra sighash data of the token bundle of a TokenPurchaseFromShieldedPool: the state
transition type, the token id, the token count and the agreed price.
Extra sighash data of the token bundle of a TokenShieldedTransferWithShieldedFee: the
state transition type and the token id, so the bundle is pinned to one token pool and one
transition kind.
Extra sighash data of the token bundle of a TokenUnshieldWithShieldedFee: the state
transition type, the token id, the recipient and the amount, so the bundle cannot be
replayed against another token, recipient or amount.
v0 byte layout of unshield_extra_sighash_data (see that function’s doc comment for the layout
and rationale). Frozen: never mutate; a layout change requires a new _v1 + version bump.