The join
Publics:
manifest_hash, time_bucket, note_root, party_root, program_root, n_fragments,
note_nullifiers[N*2], record_nullifiers[N*2], note_commitments[N*2], record_commitments[N*2],
fi_indices[N*2], policy_context_roots[N*2], total_fee, public_effect_digest, envelope_digest
Checks, for N ≤ 4 (unused fragment slots are proven dummies):
- Recursive verification of
Nkernel proofs under the fixed kernel VK. - All fragments carry the same
manifest_hash,time_bucket, and roots. - Every nonzero
flows_outentry equals exactly oneflows_inentry of a different fragment, and vice versa. Zero flows are unmatched dummies. - All nullifiers distinct across the transaction.
- The flattened outputs are the fragments' outputs in canonical fragment
order;
total_feeis the sum of fragment fees;envelope_digestbinds all fragments' digests. public_effect_digestequals the manifest's public-effect field (target, calldata hash, gas cap, success requirement), or zero.
J costs N recursive verifications plus its own logic. Whether it is a
chain of N UltraHonk recursions or a ClientIVC fold is the first spike
(§11): Barretenberg's ClientIVC exists for exactly this shape of kernel
chain.