Kernel checks
Witness: the method proof and its VK; program leaf and path; consumed
records' and notes' openings, leaf indices, and paths; created records' and
notes' openings; flows' openings; actors' ak, signatures, party leaves and
paths; stakeholders' party leaves and paths; envelope randomness; method
args.
- Program leaf opens under
program_root;hash(method_vk)opens under itsmethods_vk_root. - Recursive verification of the method proof with inner public
app_context_root, whichKrecomputes from the same plaintext (§5.8), so the method judged exactly what the kernel enforces. - Every consumed record's
template_idis in the program'stemplates_root; every created record's is too. Consumed records and notes open undernote_root; nullifiers computed as in §4.1. - Bound notes: each consumed bound note's owner is a consumed record in this fragment; each created bound note's owner is a created record.
- Authorization rule of §4.3.
- Admission: every actor and every stakeholder of a created record opens
under
party_root; each actor'sfi_indexis one offi_indices. - Conservation per asset over notes in, notes out, flows in, flows out,
and
fee. Up to 4 distinct assets per fragment. - Delivery: for each created record and note and each of its
stakeholders, the envelope ciphertext is the Poseidon2 stream encryption
of the opening under that stakeholder's
epk(§6);envelope_digestbinds all ciphertexts. - Policy contexts: for each nonzero
fi_index,policy_context_roots[i]is the root of the fragment context (§5.8) for that FI's customer.