Fragment statement
Fixed arity in v1: K_N = 2 notes in, M_N = 2 notes out, K_R = 2
records in, M_R = 2 records out, F = 2 flows out, F = 2 flows in,
A = 4 actors, E = 8 envelopes, up to 2 vouching FIs. Unused slots hold
dummies: a random nullifier, a commitment to a zero record or note with a
random salt, a zero flow, a zero FI index. Dummy commitments are appended
to the tree like real ones so the shape is uniform.
Publics of the kernel proof for one fragment:
manifest_hash, time_bucket, note_root, party_root, program_root,
note_nullifiers[2], record_nullifiers[2],
note_commitments[2], record_commitments[2],
flows_out[2], flows_in[2],
fi_indices[2], policy_context_roots[2],
fee, envelope_digest