Manifest
The manifest is the canonical serialization of: chain id, pool address,
protocol version, validity bucket range, the ordered fragment statements
with proofs and signatures removed, the public effect, the fee bounds, and
the submitter. manifest_hash = H(MANIFEST, ...). Rules, from RFC-019:
- Signatures and proofs are excluded; the pool reconstructs the hash from calldata and its own live roots.
- Wallet display terms must be derived from the same bytes. The SDK renders the manifest; nothing else is signed.
- Private execution binds exact effects. A public effect binds target, calldata, gas cap, and required success. Nothing may widen either.
- All effects apply or none do, including the public effect. Gas and the submitter's nonce are consumed regardless.
- Off-chain or cross-chain steps are evidence plus committed pending records, never part of the atomic boundary.
Actors sign manifest_hash before proving. An aborted transaction leaks its
fragments' statements to the coordinator only, and statements contain only
commitments, so the coordinator learns the graph shape and nothing else.