Notes, tree, nullifiers
commitment = H(NOTE, asset, amount, pk_d.x, pk_d.y, rho)
nullifier = H(NULL, nk, leaf_index)
Append-only Poseidon2 Merkle tree of depth 32 for commitments, with a root
history window of R_NOTE recent roots; a nullifier set on chain. Spend
arity K = 2 inputs. Initiate produces 1 change note plus a hold; resolve
and reclaim each produce exactly 1 note.
There is no lock set. Inputs are nullified at initiate (§4.4), so a hold cannot be double-spent and there is nothing to release.