The policy ABI
A policy circuit for phase p has exactly five public inputs, in this
order. There is no phase public: phase is fixed by which VK the wrapper
selects.
context_root in the phase-p context root ([§4.5](/protocol/context-tree))
params_commitment in H(PARAMS, schema_hash, salt, params...) — equals the FI leaf's
state_in in fiState[fi_index] before this transition (0 = empty)
state_out out new state root (== state_in for stateless policies)
attestation_out out a salted commitment the pool stores and feeds to the
next phase as attestation_in (0 if none)
Everything else is witness. A policy is satisfied if it proves; it has no verdict value on chain. "Reject is permitted" means the reject circuit is provable.