Question on the verifier steps that attempt at computing a commitment for the polynomial r:
I’m wondering why the verifier uses commitments to q_M, q_L, etc. Can’t we do the same as we did with Z_H(x) and x^n and x^2n and use q_M(z), q_L(z), etc.?
Also, why use a commitment to S_sigma3 ? Why not have the prover also send that evaluation?