Architecture
┌────────────────────────────── on chain ──────────────────────────────┐
│ Pool (holds, note tree, nullifiers, fiState[]) Registry (FI leaves) │
│ Verifiers: VK_shield VK_init VK_resolve VK_reclaim VK_unshield VK_W │
└────────────┬────────────────────────────────────────┬────────────────┘
│ main proofs (wallet) │ policy proofs (FI)
┌────────────┴────────────┐ ┌───────────┴─────────────────┐
│ protocol/circuits │ │ FI policy (3 Nargo bins, │
│ shield, initiate, │ context │ generated by `weld build`) │
│ resolve, reclaim, │───root────────▶│ + wrapper W │
│ unshield │ │ framework/weld (Rule, Ctx, │
│ protocol/lib (gadgets) │ │ Verdict, State, combinators, │
└─────────────────────────┘ │ #[weld::*] attributes) │
└───────────┬─────────────────┘
┌───────────────────────────────────────────────────────┴──────────────┐
│ reference/ (Rust): crypto, schema, context tree, golden world, │
│ conformance vectors, codegen templates │
│ cli/ (Rust): weld build/test/register/params/codegen │
│ sdk-ts/, sdk-rs/: generated witness builders + pool client │
└──────────────────────────────────────────────────────────────────────┘
Two provers, two proof families, one shared object (the context) with one root that both sides can recompute.