pub struct InclusionProof {
pub tree_size: u64,
pub leaf_index: u64,
pub inclusion_path: Vec<[u8; 32]>,
}Expand description
A decoded RFC9162_SHA256 inclusion proof.
The wire form is a bstr wrapping the CBOR array
[tree_size: uint, leaf_index: uint, inclusion_path: [+ bstr]]
(RFC 9942 Section 5.2). Note the field order: tree_size precedes
leaf_index.
Fields§
§tree_size: u64Size of the tree whose root this proof reconstructs.
leaf_index: u64Index of the proven leaf, relative to tree_size.
inclusion_path: Vec<[u8; 32]>Sibling hashes on the path from the leaf to the root.
Implementations§
Source§impl InclusionProof
impl InclusionProof
Sourcepub fn from_wrapped_cbor(wrapped: &[u8]) -> Result<Self>
pub fn from_wrapped_cbor(wrapped: &[u8]) -> Result<Self>
Decodes one inclusion proof from the CBOR inside its bstr wrapper.
§Errors
Returns Error::Receipt if the bytes are not the CBOR three-element
array RFC 9942 Section 5.2 specifies, if either count is not an
unsigned integer, if the path is empty, or if any path element is not
exactly 32 bytes. An empty inclusion_path is rejected because the
CDDL requires at least one element ([+ bstr]); a single-leaf tree
still carries a proof, and a genuinely empty array is a malformed
proof rather than a proof of a one-entry log.
Sourcepub fn reconstruct_root(&self, leaf: [u8; 32]) -> Result<[u8; 32]>
pub fn reconstruct_root(&self, leaf: [u8; 32]) -> Result<[u8; 32]>
Reconstructs the Merkle root this proof claims, given the proven leaf hash.
This is RFC 9162 Section 2.1.3.2 verbatim, up to but not including its
final comparison against a known root. The comparison is left to the
caller because in the detached-payload case there is no known root to
compare against: the reconstructed root becomes the COSE_Sign1
payload, and the signature check is what binds it.
§Errors
Returns Error::Receipt when leaf_index >= tree_size, when the
path is longer than the tree can justify, or when the path runs out
before the root is reached.