REX
The request is sealed to the live TEE key. The evaluation runs on the host, and the attestation says so.
REX confidentiality is half-built, and the attestation string is where the half you get is stated: rialo:host-evaluated:, never rialo:enclave:.
rialo:host-evaluated:1786788003:2418:b1946ac92492d2347c6235b4d2611184
└── where it ran └── epoch └── length └── digestWhat REX is meant to do
Pull the deliverable and check it inside a trusted execution environment, so
that neither Warrant nor the agent ever sees the payload or the credentials used
to fetch it. The verifier program that would run inside the enclave is written —
contracts/verifier — and is not deployed, because building a PolkaVM binary
needs a Rust toolchain that has not been run here.
Until it is deployed there is no enclave to run the check in.
What is real today
Confidentiality of the request. The spec and any credentials are sealed to
the live TEE key with HPKE, through the CDK's encryptForRex. The key is
fetched from the node rather than hardcoded — a hardcoded enclave key is
indistinguishable from a wrong one — and the sealed bytes are exactly what a
deployed program would consume, unchanged. This runs against the live testnet.
Evaluation. The same evaluateSpec the mock uses, so the two cannot drift
and every fixture that proved the eight clause kinds still proves them here.
Today it runs in the API process.
What the attestation means to you
This is the part worth reading carefully if you are looking at a trace.
| Prefix | Means |
|---|---|
rialo:host-evaluated: | The clauses were evaluated on the host. Confidentiality of the request holds; the evaluation was not attested. |
rialo:enclave: | Would mean evaluation happened inside the attested enclave. Not currently produced by anything. |
Read host-evaluated as: the record proves what was evaluated and when,
and does not prove where. Both matter, and only one is currently true.
If you are relying on Warrant for a claim like "the payload was never visible to the operator", that claim is not yet supported for the evaluation step, and the attestation string is what tells you so. It will change to say otherwise only when it is otherwise.
The string is a contract, not a label
host-evaluated is not a placeholder that will be swapped for something
stronger while meaning the same thing. It is the honest description of an
intermediate state, and anything reading a trace can tell the two apart. That is
the only acceptable way to ship this partially.
Turning it on
WARRANT_CHAIN=rialo
RIALO_RPC_URL=…
REX_ENDPOINT=…
RIALO_ANCHOR_SECRET_KEY=…WARRANT_CHAIN defaults to mock, which keeps tests offline and deterministic.
rialo constructs the real clients. Anything else is rejected at boot rather
than silently falling back.
Under rialo, custody still delegates to the Postgres ledger — see
contracts.
Amounts
Unchanged by any of this: integer strings of the asset's smallest unit,
^[0-9]+$.
"8400000" 8.40 USDC
8400000 rejected — a JSON number
"8.40" rejected — not the smallest unit