bip352: fix up undefined index in Overview section #2302

pull ViniciusCestarii wants to merge 1 commits into bitcoin:master from ViniciusCestarii:bip-0352-overview changing 1 files +4 −3
  1. ViniciusCestarii commented at 9:06 PM on September 24, 2026: contributor

    Notation-only changes to the overview section. They are:

    P<sub>i</sub> -> P<sub>k</sub>. The index i is never defined, and the output is derived from the counter k.

    Define A = a·G right after a is redefined as the sum of the input private keys. Then use A in input_hash = hash(outpoint<sub>L</sub> || A) instead of (a·G). The BIP uses uppercase for public keys, and this was the only place where a public key appeared in the middle of an operation as (a·G). It also matches the sender spec, which writes "A = a·G".

  2. in bip-0352.mediawiki:78 in 71fa71ba17 outdated
      74 | @@ -75,7 +75,7 @@ In order to allow Alice to create more than one output for Bob<ref name="why_mor
      75 |  * Let ''P<sub>0</sub> = B + hash(a·B || k)·G''
      76 |  * For additional outputs:
      77 |  ** Increment ''k'' by one (''k++'')
      78 | -** Let ''P<sub>i</sub> = B + hash(a·B || k)·G''
      79 | +** Let ''P<sub>k</sub> = B + hash(a·B || k)·G''
    


    jonatack commented at 9:19 PM on September 24, 2026:

    Would P<sub>i</sub> in line 90 need to be updated as well?


    ViniciusCestarii commented at 10:03 PM on September 24, 2026:

    Yes, thanks for spotting it. Done on a99b3d36a7eb612911cac08ecda66a07285170ff.

  3. jonatack added the label Fixups on Sep 24, 2026
  4. bip352: fix notation inconsistencies in overview a99b3d36a7
  5. in bip-0352.mediawiki:104 in 71fa71ba17 outdated
     100 | @@ -101,7 +101,8 @@ In our simplified example we have been referring to Alice's transactions as havi
     101 |  Alice performs the tweak with the sum of her input private keys in the following manner:
     102 |  
     103 |  * Let ''a = a<sub>1</sub> + a<sub>2</sub> + ... + a<sub>n</sub>''
     104 | -* Let ''input_hash = hash(outpoint<sub>L</sub> || (a·G))'', where ''outpoint<sub>L</sub>'' is the smallest outpoint lexicographically<ref name="why_smallest_outpoint">'''Why use the lexicographically smallest outpoint for the hash?''' Recall that the purpose of including the input hash is so that the sender and receiver can both come up with a deterministic nonce that ensures that a unique address is generated each time, even when reusing the same scriptPubKey as an input. Choosing the smallest outpoint lexicographically satisfies this requirement, while also ensuring that the generated output is not dependent on the final ordering of inputs in the transaction. Using a single outpoint also works well with memory constrained devices (such as hardware signing devices) as it does not require the device to have the entire transaction in memory in order to generate the silent payment output.</ref>
     105 | +* Let ''A = a·G''
    


    jonatack commented at 9:23 PM on September 24, 2026:

    Not sure this is needed, but no strong opinion.


    ViniciusCestarii commented at 10:14 PM on September 24, 2026:

    Ops, I forgot to mention the reasoning for this one: the BIP uses uppercase for public keys, and this was the only place where a public key appeared in the middle of an operation as (a·G). It also matches the sender spec, which writes "A = a·G".

  6. ViniciusCestarii force-pushed on Sep 24, 2026
  7. jonatack renamed this:
    bip352: fix notation inconsistencies in overview
    bip352: fix up undefined index in Overview section
    on Sep 25, 2026
  8. jonatack commented at 4:04 PM on September 25, 2026: member

    ACK, thank you for the rapid responses.

  9. jonatack merged this on Sep 25, 2026
  10. jonatack closed this on Sep 25, 2026

  11. ViniciusCestarii deleted the branch on Sep 25, 2026
  12. ViniciusCestarii commented at 5:30 PM on September 25, 2026: contributor

    Thanks for the rapid response and review as well!

Labels

github-metadata-mirror

This is a metadata mirror of the GitHub repository bitcoin/bips. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2026-09-30 16:10 UTC

This site is hosted by @0xB10C
More mirrored repositories can be found on mirror.b10c.me