Private Swap circuit
The exact 22-element public input vector and witness relations constrained by the production Private Swap circuit.
The frozen production circuit has 14,394 constraints and 22 public field inputs. In the following order, each byte string is encoded as a BN254 field element; 32-byte public keys are split into two 128-bit limbs.
Public input order
| Index | Value |
|---|---|
| 0 | Private Swap protocol domain 0x5a4b43504d4d0003 |
| 1–2 | Pool public key high and low limbs |
| 3–4 | Input asset mint high and low limbs |
| 5–6 | Output asset mint high and low limbs |
| 7 | Accepted input Merkle root |
| 8 | Root sequence |
| 9 | Input tree generation |
| 10 | Input note nullifier |
| 11–12 | Input-side and output-side CPMM reserves before settlement |
| 13 | Fee tier in bps |
| 14 | amount_in used by the swap |
| 15 | amount_out from the CPMM |
| 16 | change_amount |
| 17 | Change commitment (zero field when there is no change) |
| 18 | Output commitment |
| 19 | Direction (0 A→B, 1 B→A) |
| 20 | Circuit statement version constant 1 |
| 21 | Pool swap_nonce |
The program derives the same vector from its accounts, instruction values and current pool nonce before invoking the verifier. The transaction does not get to supply a different reserve snapshot or public input blob.
Private witness
The witness includes input spend secret and randomness; the input commitment's 16 Merkle siblings, index and generation; then change and output spend secrets and randomness. The SDK currently creates output notes for the same wallet owner and uses fresh randomness. These secrets stay in local proving inputs and are not relayed as transaction fields.
Circuit relations
The circuit constrains:
- Owner commitment from the input spend-secret limbs.
- Input note commitment from pool, asset,
amount_in + change_amount, owner commitment and input randomness. - Merkle path ordering and the final root.
- Nullifier derivation from pool, input asset, spend secret and randomness.
- Fee tier membership in
{100, 200, 300}and fee-adjusted integer CPMM output. - 64-bit ranges for amounts/reserves and the circuit's bounded arithmetic intermediates.
- Change commitment when change is nonzero; output commitment for the new output amount.
Core then performs the stateful checks the circuit cannot own: live root history, canonical accounts, unused spent PDA, account-page append and SPL Token settlement. See Private Swap for the protocol-level transition.