README.md
gno.land/p/moul/x/daily/commitreveal/v0
Commit–reveal scheme — Commit, MustCommit, Verify, Open,
ValidCommitment, MinSaltLen, MaxValueLen, DigestLen.
1import "gno.land/p/moul/x/daily/commitreveal/v0"
2
3c, _ := commitreveal.Commit("rock", "alice-secret-salt-1") // phase 1: publish c
4commitreveal.Open(c, "rock", "alice-secret-salt-1") // phase 2: nil
5commitreveal.Open(c, "paper", "alice-secret-salt-1") // ErrMismatch
A transaction is public before it executes, so a naive sealed-bid auction or
simultaneous-move game lets whoever moves last read everyone else's move and win
for free. Commit–reveal splits the action: publish H(value ‖ salt) first, open
it later.
The salt is enforced, not advised. Rock-paper-scissors has three possible
moves, so an unsalted commitment has three possible hashes and is broken by
trying all of them. Commit refuses a salt shorter than MinSaltLen (16), and
Verify enforces the same floor — a short salt cannot be smuggled past it.
Two details that are easy to get wrong, both tested:
- Length-prefixed hashing. With plain concatenation
("ab","cd…")and("abc","d…")produce identical bytes, so one commitment could be opened two different ways. The lengths are hashed in. - Constant-time digest comparison. A short-circuiting check leaks, through timing, how many leading bytes of a guess were right — enough to reconstruct a commitment byte by byte.
This package computes and checks commitments. It stores nothing and knows nothing about phases or deadlines; the realm owns that.
Live demo: r/moul/x/daily/commitrevealdemo
· render it at /r/moul/x/daily/commitrevealdemo/v0.
Part of moul/gno-contracts — moul's versioned gno.land contracts. See the repository for the full catalog, build/test tooling, and usage.
🧪 Highly experimental — potentially vibe-coded. Not audited; may break, change, or be removed at any time. Do not use with anything of value. Full disclaimer: DISCLAIMER.