|
| 1 | +// In-memory Merkle Tree which implements an authenticated list. |
| 2 | +package mt |
| 3 | + |
| 4 | +import ( |
| 5 | + "crypto/sha256" |
| 6 | + "fmt" |
| 7 | + "iter" |
| 8 | +) |
| 9 | + |
| 10 | +type Digest = [sha256.Size]byte |
| 11 | + |
| 12 | +var MerklePlaceholderDigest = Digest([]byte("MERKLE_PLACEHOLDER_HASH_________")) |
| 13 | +var LeafSeparator = []byte("MT::LeafNode") |
| 14 | +var InternalSeparator = []byte("MT::InternalNode") |
| 15 | + |
| 16 | +func digestInternal(leftChildDigest Digest, rightChildDigest Digest) Digest { |
| 17 | + hash := sha256.New() |
| 18 | + hash.Write(InternalSeparator) |
| 19 | + hash.Write(leftChildDigest[:]) |
| 20 | + hash.Write(rightChildDigest[:]) |
| 21 | + return Digest(hash.Sum(nil)) |
| 22 | +} |
| 23 | + |
| 24 | +func digestLeaf(preimage []byte) Digest { |
| 25 | + hash := sha256.New() |
| 26 | + hash.Write(LeafSeparator) |
| 27 | + hash.Write(preimage) |
| 28 | + return Digest(hash.Sum(nil)) |
| 29 | +} |
| 30 | + |
| 31 | +func buildTreeLevels(leafPreimages [][]byte) iter.Seq[[]Digest] { |
| 32 | + return func(yield func([]Digest) bool) { |
| 33 | + leafCount := len(leafPreimages) |
| 34 | + if leafCount == 0 { |
| 35 | + if !yield([]Digest{MerklePlaceholderDigest}) { |
| 36 | + return |
| 37 | + } |
| 38 | + } |
| 39 | + |
| 40 | + // Start with the leaf digests |
| 41 | + currentLayer := make([]Digest, leafCount) |
| 42 | + for i, leafPreimage := range leafPreimages { |
| 43 | + currentLayer[i] = digestLeaf(leafPreimage) |
| 44 | + } |
| 45 | + if !yield(currentLayer) { |
| 46 | + return |
| 47 | + } |
| 48 | + |
| 49 | + // Build the tree upwards, padding with placeholders when odd number of nodes |
| 50 | + for len(currentLayer) > 1 { |
| 51 | + nextLayerSize := (len(currentLayer) + 1) / 2 // Ceiling division |
| 52 | + nextLayer := make([]Digest, 0, nextLayerSize) |
| 53 | + |
| 54 | + for i := 0; i < len(currentLayer); i += 2 { |
| 55 | + leftDigest := currentLayer[i] |
| 56 | + rightDigest := MerklePlaceholderDigest |
| 57 | + if i+1 < len(currentLayer) { |
| 58 | + rightDigest = currentLayer[i+1] |
| 59 | + } |
| 60 | + nextLayer = append(nextLayer, digestInternal(leftDigest, rightDigest)) |
| 61 | + } |
| 62 | + currentLayer = nextLayer |
| 63 | + if !yield(currentLayer) { |
| 64 | + return |
| 65 | + } |
| 66 | + } |
| 67 | + } |
| 68 | +} |
| 69 | + |
| 70 | +// Root computes the Merkle tree root from leaf preimages. |
| 71 | +func Root(leafPreimages [][]byte) Digest { |
| 72 | + var rootDigest Digest |
| 73 | + for treeLevel := range buildTreeLevels(leafPreimages) { |
| 74 | + if len(treeLevel) == 1 { |
| 75 | + rootDigest = treeLevel[0] |
| 76 | + } |
| 77 | + } |
| 78 | + return rootDigest |
| 79 | +} |
| 80 | + |
| 81 | +// Prove generates a Merkle inclusion proof that the leafPreimage at index is |
| 82 | +// included in the tree rooted at Root(leafPreimages). |
| 83 | +func Prove(leafPreimages [][]byte, index uint64) ([]Digest, error) { |
| 84 | + leafCount := len(leafPreimages) |
| 85 | + if leafCount == 0 { |
| 86 | + return nil, fmt.Errorf("cannot prove inclusion in empty tree") |
| 87 | + } |
| 88 | + if index >= uint64(leafCount) { |
| 89 | + return nil, fmt.Errorf("index %d is out of bounds for %d leaves", index, leafCount) |
| 90 | + } |
| 91 | + |
| 92 | + var proof []Digest |
| 93 | + currentIndex := index |
| 94 | + |
| 95 | + for treeLevel := range buildTreeLevels(leafPreimages) { |
| 96 | + if len(treeLevel) <= 1 { |
| 97 | + break |
| 98 | + } |
| 99 | + siblingIndex := currentIndex ^ 1 |
| 100 | + siblingDigest := MerklePlaceholderDigest |
| 101 | + if siblingIndex < uint64(len(treeLevel)) { |
| 102 | + siblingDigest = treeLevel[siblingIndex] |
| 103 | + } |
| 104 | + proof = append(proof, siblingDigest) |
| 105 | + currentIndex /= 2 |
| 106 | + } |
| 107 | + |
| 108 | + return proof, nil |
| 109 | +} |
| 110 | + |
| 111 | +// Verify verifies that leafPreimage is preimage of the index-th leaf in the |
| 112 | +// Merkle tree rooted at expectedRootDigest. |
| 113 | +func Verify(expectedRootDigest Digest, index uint64, leafPreimage []byte, proof []Digest) error { |
| 114 | + currentDigest := digestLeaf(leafPreimage) |
| 115 | + currentIndex := index |
| 116 | + |
| 117 | + for _, siblingDigest := range proof { |
| 118 | + if currentIndex%2 == 0 { |
| 119 | + // Current node is left child, sibling is right |
| 120 | + currentDigest = digestInternal(currentDigest, siblingDigest) |
| 121 | + } else { |
| 122 | + // Current node is right child, sibling is left |
| 123 | + currentDigest = digestInternal(siblingDigest, currentDigest) |
| 124 | + } |
| 125 | + currentIndex /= 2 |
| 126 | + } |
| 127 | + |
| 128 | + if currentDigest != expectedRootDigest { |
| 129 | + return fmt.Errorf("computed root digest mismatch: computed %x, expected %x", currentDigest, expectedRootDigest) |
| 130 | + } |
| 131 | + |
| 132 | + return nil |
| 133 | +} |
0 commit comments