Programs, templates, methods
program leaf = H(PROG, program_id, templates_root, methods_vk_root, publisher, salt)
templates_root = merkle_8(template_id ...)
methods_vk_root= merkle_16(hash(method_vk) ...)
instance = H(INST, program_id, config_root, init_nonce)
A program registry (Poseidon2 Merkle tree, depth 20, root window R_PROG)
holds one leaf per program. A method circuit belongs to one program and may
consume only records whose template_id is in that program's
templates_root and create only such records. Cross-program interaction
happens by fragments and flows, never inside one fragment. This is RFC-020's
"programs consume their own instance's records" rule, made structural.
Instances are immutable. A record binds its instance, so configuration (prices, expiry, counterparties) is fixed at creation and readable by the method as constants.