Skip to content
Open questions
- Recursion cost.
W verifying an UltraHonk proof is the dominant
gate cost. S0 measures it; if prohibitive, consider three
phase-specialized VK_Ws. Note that hiding accept versus reject
requires the two resolve VKs to live in one W.
- Path versus full-vector openings. Benchmark Poseidon2 gate cost in
the pinned Noir version before deciding whether v2 needs path mode at
all.
- Attestation kinds governance. Who publishes the kinds schema and how
do two FIs discover which kinds the other emits? Candidate: the registry
leaf gains an
attests_root advertising kinds.
- State sharding. Serialization per FI is fine for demos; a busy FI
may need sharded state roots (one per desk).
fiState could become a
small vector selected by a shard public.
- Sender settle callback. Should the sender FI get an optional phase
after resolution to un-count rejected or reclaimed holds? It costs one
more proof per payment and would let reclaim become uniform too.
- Reclaim uniformity. Reclaim is the one distinguishable resolution
(§4.13). Is that acceptable for v1, or does it need a no-op sender-FI
wrapper proof to match the resolve record?
- Privacy of
vk_root versus auditability. Regulators may want to
verify which template an FI runs; an optional disclose(vk_root preimage) off-chain flow is enough for v1.
- Time bucket size. 300 s balances proof reuse against rule
precision. Rules that need finer time are probably wrong for this layer.