From 2667b42a65b1e65b4cf4dbffc4c97b20f97cd16e Mon Sep 17 00:00:00 2001 From: roethke Date: Fri, 25 Sep 2026 10:06:21 -0700 Subject: [PATCH 1/3] docs: correct Cobalt TEE feature summary to registration migration The Cobalt overview described the TEE feature as migrating Base infrastructure to run inside a TEE. The actual work, specified in #1953, replaces the RISC Zero and Boundless proving flow for registering new TEE signers with onchain AWS Nitro attestation verification using checked P-384 hints. Retitles the accordion to "TEE Registration Migration", rewrites the summary to match, links the Registrar specification, and updates the page description plus its llms.txt / llms-full.txt index lines. Generated with Claude Code Co-Authored-By: Claude --- docs/llms-full.txt | 2 +- docs/llms.txt | 2 +- docs/upgrades/cobalt/overview.mdx | 6 +++--- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/docs/llms-full.txt b/docs/llms-full.txt index 9e169959a..7a8d4edd5 100644 --- a/docs/llms-full.txt +++ b/docs/llms-full.txt @@ -508,7 +508,7 @@ const client = createPublicClient({ chain: base, transport: http() }) ### Cobalt -- [Overview](https://docs.base.org/upgrades/cobalt/overview): Cobalt improves the B20 token standard, adds validity transactions, introduces dynamic node upgrades, and migrates Base to a Trusted Execution Environment. +- [Overview](https://docs.base.org/upgrades/cobalt/overview): Cobalt improves the B20 token standard, adds validity transactions, introduces dynamic node upgrades, and migrates TEE signer registration to onchain attestation verification. - [Dynamic Upgrades](https://docs.base.org/upgrades/cobalt/dynamic-upgrades): An Ethereum smart contract stores upgrade timestamps for Base nodes, allowing forks to activate at the scheduled time with no client restart. diff --git a/docs/llms.txt b/docs/llms.txt index a57b722c5..4c360dc0b 100644 --- a/docs/llms.txt +++ b/docs/llms.txt @@ -442,7 +442,7 @@ ### Cobalt -- [Overview](https://docs.base.org/upgrades/cobalt/overview): Cobalt improves the B20 token standard, adds validity transactions, introduces dynamic node upgrades, and migrates Base to a Trusted Execution Environment. +- [Overview](https://docs.base.org/upgrades/cobalt/overview): Cobalt improves the B20 token standard, adds validity transactions, introduces dynamic node upgrades, and migrates TEE signer registration to onchain attestation verification. - [Dynamic Upgrades](https://docs.base.org/upgrades/cobalt/dynamic-upgrades): An Ethereum smart contract stores upgrade timestamps for Base nodes, allowing forks to activate at the scheduled time with no client restart. diff --git a/docs/upgrades/cobalt/overview.mdx b/docs/upgrades/cobalt/overview.mdx index b5a5824d3..975b6e594 100644 --- a/docs/upgrades/cobalt/overview.mdx +++ b/docs/upgrades/cobalt/overview.mdx @@ -1,6 +1,6 @@ --- title: "Overview" -description: "Cobalt improves the B20 token standard, adds validity transactions, introduces dynamic node upgrades, and migrates Base to a Trusted Execution Environment." +description: "Cobalt improves the B20 token standard, adds validity transactions, introduces dynamic node upgrades, and migrates TEE signer registration to onchain attestation verification." --- | | Status | Date | @@ -35,11 +35,11 @@ Dynamic Upgrades introduces an Ethereum smart contract that stores upgrade times - + **Base** · Infrastructure -Cobalt migrates Base infrastructure to run inside a Trusted Execution Environment (TEE). Detailed specifications will be published as the feature is finalized. +Cobalt changes how new Trusted Execution Environment (TEE) signers are registered: the registrar verifies AWS Nitro attestations onchain using checked P-384 hints, replacing the RISC Zero and Boundless proving flow. Registration is faster and no longer depends on an external proving service, and certificate caching drops a registration from five transactions to one once the chain is cached. Enclave key generation, PCR0 image selection, and proof verification are unchanged. See [Registrar](/specifications/base-protocol/proofs/registrar) for the full specification. From a82e058b462e746a2539c7c53deb2665d66f1c82 Mon Sep 17 00:00:00 2001 From: roethke Date: Fri, 25 Sep 2026 11:26:57 -0700 Subject: [PATCH 2/3] docs: apply review feedback to Cobalt TEE summary Per review: emphasize that verification is now trustless and fully onchain, clarify that the removed proving dependency was offchain, and drop the certificate-caching transaction counts as too nuanced for a high-level summary. Generated with Claude Code Co-Authored-By: Claude --- docs/upgrades/cobalt/overview.mdx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/upgrades/cobalt/overview.mdx b/docs/upgrades/cobalt/overview.mdx index 975b6e594..2af95e33a 100644 --- a/docs/upgrades/cobalt/overview.mdx +++ b/docs/upgrades/cobalt/overview.mdx @@ -39,7 +39,7 @@ Dynamic Upgrades introduces an Ethereum smart contract that stores upgrade times **Base** · Infrastructure -Cobalt changes how new Trusted Execution Environment (TEE) signers are registered: the registrar verifies AWS Nitro attestations onchain using checked P-384 hints, replacing the RISC Zero and Boundless proving flow. Registration is faster and no longer depends on an external proving service, and certificate caching drops a registration from five transactions to one once the chain is cached. Enclave key generation, PCR0 image selection, and proof verification are unchanged. See [Registrar](/specifications/base-protocol/proofs/registrar) for the full specification. +Cobalt changes how new Trusted Execution Environment (TEE) signers are registered: the registrar verifies AWS Nitro attestations trustlessly and fully onchain using checked P-384 hints, replacing the RISC Zero and Boundless proving flow. Registration is faster and no longer depends on an external offchain proving service. Enclave key generation, PCR0 image selection, and proof verification are unchanged. See [Registrar](/specifications/base-protocol/proofs/registrar) for the full specification. From 1cbc87b702e463139695b174666ce879163381f3 Mon Sep 17 00:00:00 2001 From: roethke Date: Fri, 25 Sep 2026 12:00:39 -0700 Subject: [PATCH 3/3] docs: reword TEE summary to attribute verification to onchain contracts The registrar is the offchain component; verification happens in the onchain contracts. Recast the clause in the passive to avoid implying the registrar performs the verification. --- docs/upgrades/cobalt/overview.mdx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/upgrades/cobalt/overview.mdx b/docs/upgrades/cobalt/overview.mdx index 2af95e33a..799e74f5e 100644 --- a/docs/upgrades/cobalt/overview.mdx +++ b/docs/upgrades/cobalt/overview.mdx @@ -39,7 +39,7 @@ Dynamic Upgrades introduces an Ethereum smart contract that stores upgrade times **Base** · Infrastructure -Cobalt changes how new Trusted Execution Environment (TEE) signers are registered: the registrar verifies AWS Nitro attestations trustlessly and fully onchain using checked P-384 hints, replacing the RISC Zero and Boundless proving flow. Registration is faster and no longer depends on an external offchain proving service. Enclave key generation, PCR0 image selection, and proof verification are unchanged. See [Registrar](/specifications/base-protocol/proofs/registrar) for the full specification. +Cobalt changes how new Trusted Execution Environment (TEE) signers are registered: AWS Nitro attestations are trustlessly verified fully onchain using checked P-384 hints, replacing the RISC Zero and Boundless proving flow. Registration is faster and no longer depends on an external offchain proving service. Enclave key generation, PCR0 image selection, and proof verification are unchanged. See [Registrar](/specifications/base-protocol/proofs/registrar) for the full specification.