Pair each server-returned checkpoint PSBT with the locally built checkpoint
of the same txid, rejecting anything else.
The ark tx signed just above spends each checkpoint at checkpointTxid:0, so
the response is only usable if it carries the same txids: a checkpoint with
any other txid leaves that ark tx unspendable. The two sets are therefore
equal by construction, and this pairing is what the signing step below
consumes.
Matching is by txid rather than by position — nothing in the wire contract
promises arkd echoes checkpoints in submission order — while the result keeps
the server's order, so nothing downstream is reordered.
Comparing txids is sound while checkpoint inputs are taproot-only: witness
data does not affect the txid, so the server's signature cannot change it. A
future P2SH-wrapped/scriptSig input could acquire a finalScriptSig
server-side and legitimately change txid; that protocol shape would need a
different comparison target.
Pair each server-returned checkpoint PSBT with the locally built checkpoint of the same txid, rejecting anything else.
The ark tx signed just above spends each checkpoint at
checkpointTxid:0, so the response is only usable if it carries the same txids: a checkpoint with any other txid leaves that ark tx unspendable. The two sets are therefore equal by construction, and this pairing is what the signing step below consumes.Matching is by txid rather than by position — nothing in the wire contract promises arkd echoes checkpoints in submission order — while the result keeps the server's order, so nothing downstream is reordered.
Comparing txids is sound while checkpoint inputs are taproot-only: witness data does not affect the txid, so the server's signature cannot change it. A future P2SH-wrapped/scriptSig input could acquire a
finalScriptSigserver-side and legitimately change txid; that protocol shape would need a different comparison target.