Contracts
Written, not deployed. Custody is the Postgres ledger and the code requires you to say so.
The contracts are written and not deployed. Settlement runs on a double-entry Postgres ledger, and RialoLedger will not start without being handed one.
export type RialoLedgerOptions = {
custody: LedgerClient; // required, by design
};What is written
contracts/verifier — the PolkaVM program that would evaluate a spec inside the
REX enclave. It is source, not a deployed binary. Building it needs a Rust
toolchain that has not been run here.
Until it is deployed there is no enclave to evaluate in, which is why the
attestation reads rialo:host-evaluated: — see REX.
What is not written
There is no custody contract. Nothing onchain holds, releases or refunds funds.
RialoLedger implements the LedgerClient interface and splits cleanly in two:
| Method | Where it runs |
|---|---|
recordTrace | Onchain, now. Anchoring needs no custom program. |
hold | Delegated to the injected custody. |
release | Delegated to the injected custody. |
refund | Delegated to the injected custody. |
custody is a required constructor option, not an optional one with a
fallback. That is deliberate: an optional custody would let someone construct a
RialoLedger that looks onchain and silently is not. Making it required means
the composition root has to name what is actually holding the money, and today
that is PostgresLedger.
WARRANT_CHAIN=rialo does not mean onchain settlement
Under rialo, traces anchor to testnet and custody still delegates to Postgres.
Money moves between available, held, payee and external rows, with every
tx_ref netting to zero.
If you are evaluating Warrant on the basis that funds are held by a contract, they are not. The interface is in place so that they can be later without anything above the chain layer changing — which is a different claim, and a weaker one.
What deploying custody would require
Stated concretely rather than as a roadmap:
- a program holding balances per organisation
- an authorisation path for release that does not amount to a key which can drain the pool
- a two-way mapping between
tx_refand an onchain transaction - reconciliation between the ledger and chain state, and a rule for which wins when they disagree
- a decision on who pays network fees — see fees, also undecided
Verifying the claim yourself
The attestation string is the check. If a trace's attestation begins
rialo:host-evaluated:, evaluation happened on the host. Nothing in this
codebase produces rialo:enclave:, and nothing will until the program is
deployed.
Custody is checkable the same way: sum the ledger entries for a settled warrant and the figures net to zero across two Postgres accounts. There is no onchain transaction to find, because there is not one.
Amounts
Unchanged: integer strings of the asset's smallest unit, ^[0-9]+$.
"8400000" 8.40 USDC
8400000 rejected — a JSON number
"8.40" rejected — not the smallest unit