<oembed><type>rich</type><version>1.0</version><author_name>npub1tfk373zg9dnmtvxnpnq7s2dkdgj37rwfj3yrwld7830qltmv8qps8rfq0n</author_name><author_url>https://nostr.ae/npub1tfk373zg9dnmtvxnpnq7s2dkdgj37rwfj3yrwld7830qltmv8qps8rfq0n</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2017-10-01&#xA;📝 Original message:BIP 115 provides fork-independent opt-in replay protection, which can be used &#xA;in combination with the new signature condition scripts in this proposal.&#xA;&#xA;Perhaps the code can have a flag for new altcoins to easily make it mandatory &#xA;(and we can use it on testnet?).&#xA;&#xA;Luke&#xA;&#xA;&#xA;On Sunday 01 October 2017 11:22:30 AM Felix Weis wrote:&#xA;&gt; Just a simple suggestion since the signature format is changed. Can this be&#xA;&gt; designed so that possible future hard forks can simply change 1 constant in&#xA;&gt; the code and turn on cross chain replay protection?&#xA;&gt; &#xA;&gt; On Sun, Oct 1, 2017 at 1:05 PM Mark Friedenbach via bitcoin-dev &lt;&#xA;&gt; &#xA;&gt; bitcoin-dev at lists.linuxfoundation.org&gt; wrote:&#xA;&gt; &gt; Clean stack should be eliminated for other possible future uses, the most&#xA;&gt; &gt; obvious of which is recursive tail-call for general computation&#xA;&gt; &gt; capability. I’m not arguing for that at this time, just arguing that we&#xA;&gt; &gt; shouldn’t prematurely cut off an easy implementation of such should we&#xA;&gt; &gt; want to. Clean stack must still exist as policy for future soft-fork&#xA;&gt; &gt; safety, but being a consensus requirement was only to avoid witness&#xA;&gt; &gt; malleability, which committing to the size of the witness also&#xA;&gt; &gt; accomplishes.&#xA;&gt; &gt; &#xA;&gt; &gt; Committing to the number of witness elements is fully sufficient, and&#xA;&gt; &gt; using the number of elements avoids problems of not knowing the actual&#xA;&gt; &gt; size in bytes at the time of signing, e.g. because the witness contains&#xA;&gt; &gt; a merkle proof generated by another party from an unbalanced tree, and&#xA;&gt; &gt; unbalanced trees are expected to be common (so that elements can be&#xA;&gt; &gt; placed higher in the tree in accordance with their higher expected&#xA;&gt; &gt; probability of usage). Other future extensions might also have&#xA;&gt; &gt; variable-length proofs.&#xA;&gt; &gt; &#xA;&gt; &gt; &gt; On Sep 30, 2017, at 7:47 PM, Luke Dashjr &lt;luke at dashjr.org&gt; wrote:&#xA;&gt; &gt; &gt; &#xA;&gt; &gt; &gt; Should it perhaps commit to the length of the serialised witness data&#xA;&gt; &gt; &#xA;&gt; &gt; instead&#xA;&gt; &gt; &#xA;&gt; &gt; &gt; or additionally? Now that signatures are no longer variable-length,&#xA;&gt; &gt; &#xA;&gt; &gt; that&#39;d be&#xA;&gt; &gt; &#xA;&gt; &gt; &gt; possible...&#xA;&gt; &gt; &gt; &#xA;&gt; &gt; &gt; As far as tail-call needs are concerned, CLEANSTACK wouldn&#39;t have been&#xA;&gt; &gt; &#xA;&gt; &gt; checked&#xA;&gt; &gt; &#xA;&gt; &gt; &gt; until AFTER the tail-call in the first draft. But I suppose eliminating&#xA;&gt; &gt; &#xA;&gt; &gt; it for&#xA;&gt; &gt; &#xA;&gt; &gt; &gt; other possible future purposes is still useful.&#xA;&gt; &gt; &gt; &#xA;&gt; &gt; &gt; Luke&#xA;&gt; &gt; &#xA;&gt; &gt; _______________________________________________&#xA;&gt; &gt; bitcoin-dev mailing list&#xA;&gt; &gt; bitcoin-dev at lists.linuxfoundation.org&#xA;&gt; &gt; https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev</html></oembed>