Skip to content
LogoLogo

Kernel checks

Witness: the method proof and its VK; program leaf and path; consumed records' and notes' openings, leaf indices, and paths; created records' and notes' openings; flows' openings; actors' ak, signatures, party leaves and paths; stakeholders' party leaves and paths; envelope randomness; method args.

  1. Program leaf opens under program_root; hash(method_vk) opens under its methods_vk_root.
  2. Recursive verification of the method proof with inner public app_context_root, which K recomputes from the same plaintext (§5.8), so the method judged exactly what the kernel enforces.
  3. Every consumed record's template_id is in the program's templates_root; every created record's is too. Consumed records and notes open under note_root; nullifiers computed as in §4.1.
  4. Bound notes: each consumed bound note's owner is a consumed record in this fragment; each created bound note's owner is a created record.
  5. Authorization rule of §4.3.
  6. Admission: every actor and every stakeholder of a created record opens under party_root; each actor's fi_index is one of fi_indices.
  7. Conservation per asset over notes in, notes out, flows in, flows out, and fee. Up to 4 distinct assets per fragment.
  8. Delivery: for each created record and note and each of its stakeholders, the envelope ciphertext is the Poseidon2 stream encryption of the opening under that stakeholder's epk (§6); envelope_digest binds all ciphertexts.
  9. Policy contexts: for each nonzero fi_index, policy_context_roots[i] is the root of the fragment context (§5.8) for that FI's customer.