Skip to content
Warrantv0.1

REX

The request is sealed to the live TEE key. The evaluation runs on the host, and the attestation says so.

REX confidentiality is half-built, and the attestation string is where the half you get is stated: rialo:host-evaluated:, never rialo:enclave:.

rialo:host-evaluated:1786788003:2418:b1946ac92492d2347c6235b4d2611184
       └── where it ran   └── epoch  └── length  └── digest

What REX is meant to do

Pull the deliverable and check it inside a trusted execution environment, so that neither Warrant nor the agent ever sees the payload or the credentials used to fetch it. The verifier program that would run inside the enclave is written — contracts/verifier — and is not deployed, because building a PolkaVM binary needs a Rust toolchain that has not been run here.

Until it is deployed there is no enclave to run the check in.

What is real today

Confidentiality of the request. The spec and any credentials are sealed to the live TEE key with HPKE, through the CDK's encryptForRex. The key is fetched from the node rather than hardcoded — a hardcoded enclave key is indistinguishable from a wrong one — and the sealed bytes are exactly what a deployed program would consume, unchanged. This runs against the live testnet.

Evaluation. The same evaluateSpec the mock uses, so the two cannot drift and every fixture that proved the eight clause kinds still proves them here. Today it runs in the API process.

What the attestation means to you

This is the part worth reading carefully if you are looking at a trace.

PrefixMeans
rialo:host-evaluated:The clauses were evaluated on the host. Confidentiality of the request holds; the evaluation was not attested.
rialo:enclave:Would mean evaluation happened inside the attested enclave. Not currently produced by anything.

Read host-evaluated as: the record proves what was evaluated and when, and does not prove where. Both matter, and only one is currently true.

If you are relying on Warrant for a claim like "the payload was never visible to the operator", that claim is not yet supported for the evaluation step, and the attestation string is what tells you so. It will change to say otherwise only when it is otherwise.

The string is a contract, not a label

host-evaluated is not a placeholder that will be swapped for something stronger while meaning the same thing. It is the honest description of an intermediate state, and anything reading a trace can tell the two apart. That is the only acceptable way to ship this partially.

Turning it on

WARRANT_CHAIN=rialo
RIALO_RPC_URL=…
REX_ENDPOINT=…
RIALO_ANCHOR_SECRET_KEY=…

WARRANT_CHAIN defaults to mock, which keeps tests offline and deterministic. rialo constructs the real clients. Anything else is rejected at boot rather than silently falling back.

Under rialo, custody still delegates to the Postgres ledger — see contracts.

Amounts

Unchanged by any of this: integer strings of the asset's smallest unit, ^[0-9]+$.

"8400000"    8.40 USDC
8400000      rejected — a JSON number
"8.40"       rejected — not the smallest unit