The executor runs any contiguous range of a segment from a carried-in position and emits a boundary per transaction (cumulative gas and pgas, the carry link, the state root natively); the planner cuts at transaction boundaries to at most S_p pgas (provisional S_p = B_p / 4, the specification has no number yet), deterministically from the trace. Witnesses are partial Merkle Patricia tries (touched leaves in full, every untouched subtree as a hash, collapse-safe siblings carried) for the account trie and each touched storage trie; the guest rebuilds the pre-root from them, refuses any read they do not cover, and rebuilds the post-root after execution. The shard statement commits the prover's payout address (ledger P12) and the carry links; the block statement verifies the shard proofs in order, chains roots, links and transaction commitments, and carries the provers and the shard program id (design 5.1, 5.3). Port moved to igneum-exec b7fca5a0 (spec 7.5 pgas cap and abort).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>