Skip to content
LogoLogo

The join

Publics:

manifest_hash, time_bucket, note_root, party_root, program_root, n_fragments,
note_nullifiers[N*2], record_nullifiers[N*2], note_commitments[N*2], record_commitments[N*2],
fi_indices[N*2], policy_context_roots[N*2], total_fee, public_effect_digest, envelope_digest

Checks, for N ≤ 4 (unused fragment slots are proven dummies):

  1. Recursive verification of N kernel proofs under the fixed kernel VK.
  2. All fragments carry the same manifest_hash, time_bucket, and roots.
  3. Every nonzero flows_out entry equals exactly one flows_in entry of a different fragment, and vice versa. Zero flows are unmatched dummies.
  4. All nullifiers distinct across the transaction.
  5. The flattened outputs are the fragments' outputs in canonical fragment order; total_fee is the sum of fragment fees; envelope_digest binds all fragments' digests.
  6. public_effect_digest equals the manifest's public-effect field (target, calldata hash, gas cap, success requirement), or zero.

J costs N recursive verifications plus its own logic. Whether it is a chain of N UltraHonk recursions or a ClientIVC fold is the first spike (§11): Barretenberg's ClientIVC exists for exactly this shape of kernel chain.