If I understand your proposals correctly, (3) seems most flexible and doesn’t entail any additional information leakage, but would carry some extra performance costs - is that accurate? Still, I think we should try it - we will need to heavily optimized Merkle tree lookup verifications anyways.