Skip to content
Warrantv0.1

Contracts

Written, not deployed. Custody is the Postgres ledger and the code requires you to say so.

The contracts are written and not deployed. Settlement runs on a double-entry Postgres ledger, and RialoLedger will not start without being handed one.

export type RialoLedgerOptions = {
  custody: LedgerClient;   // required, by design
};

What is written

contracts/verifier — the PolkaVM program that would evaluate a spec inside the REX enclave. It is source, not a deployed binary. Building it needs a Rust toolchain that has not been run here.

Until it is deployed there is no enclave to evaluate in, which is why the attestation reads rialo:host-evaluated: — see REX.

What is not written

There is no custody contract. Nothing onchain holds, releases or refunds funds.

RialoLedger implements the LedgerClient interface and splits cleanly in two:

MethodWhere it runs
recordTraceOnchain, now. Anchoring needs no custom program.
holdDelegated to the injected custody.
releaseDelegated to the injected custody.
refundDelegated to the injected custody.

custody is a required constructor option, not an optional one with a fallback. That is deliberate: an optional custody would let someone construct a RialoLedger that looks onchain and silently is not. Making it required means the composition root has to name what is actually holding the money, and today that is PostgresLedger.

WARRANT_CHAIN=rialo does not mean onchain settlement

Under rialo, traces anchor to testnet and custody still delegates to Postgres. Money moves between available, held, payee and external rows, with every tx_ref netting to zero.

If you are evaluating Warrant on the basis that funds are held by a contract, they are not. The interface is in place so that they can be later without anything above the chain layer changing — which is a different claim, and a weaker one.

What deploying custody would require

Stated concretely rather than as a roadmap:

  • a program holding balances per organisation
  • an authorisation path for release that does not amount to a key which can drain the pool
  • a two-way mapping between tx_ref and an onchain transaction
  • reconciliation between the ledger and chain state, and a rule for which wins when they disagree
  • a decision on who pays network fees — see fees, also undecided

Verifying the claim yourself

The attestation string is the check. If a trace's attestation begins rialo:host-evaluated:, evaluation happened on the host. Nothing in this codebase produces rialo:enclave:, and nothing will until the program is deployed.

Custody is checkable the same way: sum the ledger entries for a settled warrant and the figures net to zero across two Postgres accounts. There is no onchain transaction to find, because there is not one.

Amounts

Unchanged: integer strings of the asset's smallest unit, ^[0-9]+$.

"8400000"    8.40 USDC
8400000      rejected — a JSON number
"8.40"       rejected — not the smallest unit