revm_precompile/secp256k1/
k256.rs

1use k256::ecdsa::{Error, RecoveryId, Signature, VerifyingKey};
2use primitives::{alloy_primitives::B512, keccak256, B256};
3
4pub fn ecrecover(sig: &B512, mut recid: u8, msg: &B256) -> Result<B256, Error> {
5    // parse signature
6    let mut sig = Signature::from_slice(sig.as_slice())?;
7
8    // normalize signature and flip recovery id if needed.
9    if let Some(sig_normalized) = sig.normalize_s() {
10        sig = sig_normalized;
11        recid ^= 1;
12    }
13    let recid = RecoveryId::from_byte(recid).expect("recovery ID is valid");
14
15    // recover key
16    let recovered_key = VerifyingKey::recover_from_prehash(&msg[..], &sig, recid)?;
17    // hash it
18    let mut hash = keccak256(
19        &recovered_key
20            .to_encoded_point(/* compress = */ false)
21            .as_bytes()[1..],
22    );
23
24    // truncate to 20 bytes
25    hash[..12].fill(0);
26    Ok(hash)
27}