Sapling-related functionality.

These data structures enforce the structural validity of Sapling-related consensus-critical objects.

Consensus rule:

These data structures ensure that ZIP-216, canonical Jubjub point encodings, are enforced everywhere where Jubjub points occur, and non-canonical point encodings are rejected. This is enforced by the jubjub crate, which is also used by the redjubjub crate.




  • The randomness used in the Pedersen Hash for note commitment.
  • A ciphertext component for encrypted output notes.
  • A Note represents that a value is spendable by the recipient who holds the spending key corresponding to a given shielded payment address.
  • Note commitments for the output notes.
  • A Nullifier for Sapling transactions
  • A Homomorphic Pedersen commitment to the value of a note.
