merkle mode
One proof can commit a whole list. Merkle mode folds the list into one 32-byte root, and on verify the program checks your answer.
A normal proof holds one fact. Say you have a list of a thousand scores. A thousand proofs would cost a thousand deposits. Merkle mode does it with one.
the folding trick
Hash each item in the list to get its fingerprint. Pair the fingerprints up and hash each pair together. Keep pairing and hashing until one fingerprint is left. That last one is the root, a fingerprint of the entire list. Change any single item and the root changes. That structure is a merkle tree.
In merkle mode, you prove the root and set the enforce_merkle flag when you prove. One proof, one deposit, the whole list committed.
the quiz version of verify
Chapter 3 called a plain verify a handshake. Nothing gets checked. Merkle mode is the quiz. To verify a merkle proof you bring two things:
- A leaf. The 32-byte fingerprint of one item from the list.
- The path. The neighbor fingerprints needed to fold your leaf back up to the root. This is the
merkle_proofargument.
The program does the folding on chain. If your leaf and path fold up to the stored root, the verify goes through. If not, the program rejects it with InvalidMerkleProof.
The leaf you verified becomes the attestation, so the permanent receipt records which item from the list you proved.
one shot per proof
Verify still closes the proof, so each merkle proof gets one leaf reveal. Pick the item that matters, prove it, done. Need several reveals from one list? Post several proofs. Each one needs its own 32-byte data value, so build a distinct tree for each, for example by mixing an index into the leaves before hashing.