Pool welds
Per transaction the pool verifies one J proof and one W proof per
nonzero fi_index, then checks by plain equality:
manifest_hashrecomputed from calldata equals the public.time_bucket ∈ {now, now − 1}; roots in their windows;!revoked[fi_index]for every listed FI;!revokedParty[actor]is enforced insideKvia the party window plus a direct pool check on the actors' party ids, which the manifest lists.- No listed nullifier is in the set; then all are inserted.
- All listed commitments appended in order.
- For each
W_i: itspayment_rootpublic equalspolicy_context_roots[i], itsfi_indexequalsfi_indices[i], itsphase_class = 1with witnessedphase = 3,state_in == fiState[fi_index], andfiStateis written afterwards. - Envelopes in calldata hash to
envelope_digest. - If
public_effect_digest ≠ 0, the bounded call is made under a shared reentrancy guard; failure reverts everything. total_feeis credited to the submitter.
Public effects
One bounded callback per transaction, as RFC-020: target, calldata,
gas ∈ [25k, 1M], required success. No delegatecall, no
custody-authorized calls, no token return values as evidence of backing
movement. Multi-call and typed effects are deferred.