Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
132 commits
Select commit Hold shift + click to select a range
cf7d4af
fix(wallet): hide restoration error before setup
replghost Sep 16, 2026
ec3367d
fix(debug): keep wallet claim controls reachable
replghost Sep 16, 2026
3907085
Merge remote-tracking branch 'origin/feat/pvm-wasm' into fix/chat-aut…
replghost Sep 16, 2026
498e31c
Merge branch 'integrate/wallet-runtime-followup-20260914' into integr…
replghost Sep 17, 2026
1294340
Merge branch 'integrate/wallet-runtime-followup-20260914' into integr…
replghost Sep 17, 2026
e211942
fix(chat): reapply isolated Chat authority above runtime-only base
replghost Sep 17, 2026
d9096ae
Merge refreshed runtime base into Chat host
replghost Sep 17, 2026
88d8711
Merge final runtime revision into Chat host
replghost Sep 17, 2026
b6bd29c
Merge Wasm-gated runtime host into Chat
replghost Sep 17, 2026
67d7dca
Merge wallet claim progress into Chat with matching host SDK
replghost Sep 17, 2026
14ffd9d
Merge remote-tracking branch 'origin/feat/pvm-wasm' into refresh/pr23…
replghost Sep 18, 2026
a87c74a
chore(truapi): commit vendor modules the dist ignore skipped
replghost Sep 18, 2026
75ffd8e
Merge remote-tracking branch 'origin/feat/pvm-wasm' into refresh/pr23…
replghost Sep 18, 2026
1464e9c
Merge remote-tracking branch 'origin/feat/pvm-wasm' into refresh/pr23…
replghost Sep 18, 2026
651c0fd
Merge remote-tracking branch 'origin/feat/pvm-wasm' into refresh/pr23…
replghost Sep 18, 2026
819e31a
Merge remote-tracking branch 'origin/feat/pvm-wasm' into refresh/pr23…
replghost Sep 18, 2026
8ef4cec
Merge remote-tracking branch 'origin/feat/pvm-wasm' into refresh/pr23…
replghost Sep 18, 2026
0f80c74
Merge remote-tracking branch 'origin/feat/pvm-wasm' into refresh/pr23…
replghost Sep 18, 2026
b5b2978
Merge remote-tracking branch 'origin/feat/pvm-wasm' into refresh/pr23…
replghost Sep 19, 2026
ea36222
Merge comfortable-play runtime from #185 into #255
replghost Sep 19, 2026
fe5339d
Merge reviewed control validation from #185 into #255
replghost Sep 19, 2026
1136ced
Forward #185 menu alignment into #255; preserve PR stack
replghost Sep 19, 2026
9a88ed7
Forward #185 large-program runtime into #255 for paseo.fyi
replghost Sep 20, 2026
c23fd5d
Merge PolkaVM boundary-test lint correction into Chat integration
replghost Sep 20, 2026
474c798
feat(chat): integrate shared main-purse host custody and verified art…
replghost Sep 22, 2026
c2f298a
Merge wallet identity proxy rollout through PolkaVM into Chat integra…
replghost Sep 22, 2026
902b82f
fix(chat): qualify browser custody and native host integration
replghost Sep 22, 2026
ff212c9
Merge commit 'c2f298a03b3d2dbef1ebea581f76c079a517d670' into integrat…
replghost Sep 22, 2026
ad93c56
Merge remote-tracking branch 'origin/feat/pvm-wasm' into integrate/is…
replghost Sep 23, 2026
e8956fb
Merge remote-tracking branch 'origin/feat/pvm-wasm' into integrate/is…
replghost Sep 23, 2026
a963b7a
Merge manifest resolution fix from #185
replghost Sep 23, 2026
cd671d0
Merge manifest resolution lint fix from #185
replghost Sep 23, 2026
6ef4652
chore: forward the truapi 0.20 refresh and vendor the Chat-capable core
replghost Sep 23, 2026
8c9f006
Merge commit 'cd18d42c6ea74d80c8fb0aadbd49615a72750075' into HEAD
replghost Sep 23, 2026
3d6ec55
Merge reviewed background servicing from feat/pvm-wasm into Chat
replghost Sep 24, 2026
12a9bcd
chore(vendor): refresh truapi-host with the bounded own-account callb…
replghost Sep 24, 2026
8744ae4
Merge latest PolkaVM wallet into Chat v2 runtime
replghost Sep 24, 2026
fd37c5c
test(e2e): refresh host playground fixture
replghost Sep 24, 2026
b68d975
Merge feat/pvm-wasm (wallet allowance inspection) into feat/chat-v2-h…
replghost Sep 25, 2026
15b139a
Merge remote-tracking branch 'origin/feat/pvm-wasm' into HEAD
replghost Sep 27, 2026
8d4603e
fix(wallet): let a second tab take over the test wallet instead of fa…
replghost Sep 27, 2026
2e37dd7
Merge feat/pvm-wasm (#185) into feat/chat-v2-host-runtime: surface me…
replghost Sep 27, 2026
6025aff
Merge remote-tracking branch 'origin/feat/pvm-wasm' into HEAD
replghost Sep 27, 2026
e6bf2ae
Merge remote-tracking branch 'origin/feat/pvm-wasm' into HEAD
replghost Sep 27, 2026
6bbaaf8
feat(wallet): move the test wallet between tabs automatically
replghost Sep 27, 2026
e495e2c
Merge feat/pvm-wasm (TrUAPI 0.21) into feat/chat-v2-host-runtime
replghost Sep 27, 2026
4aa99f0
Revert "feat(wallet): move the test wallet between tabs automatically"
replghost Sep 27, 2026
2a2491f
chore(vendor): Chat SDK with SSO messages at 200-205 (host-rust-core#…
replghost Sep 28, 2026
44c6b9c
Merge feat/pvm-wasm (test wallet single-tab owner) into feat/chat-v2-…
replghost Sep 28, 2026
d7129ea
Merge feat/pvm-wasm (#185) into feat/chat-v2-host-runtime: full-heigh…
replghost Sep 28, 2026
845b10e
Merge feat/pvm-wasm (take the wallet back on a click into a focused a…
replghost Sep 28, 2026
74acbe8
Merge updated PolkaVM base
replghost Sep 28, 2026
d2f54e2
Merge feat/pvm-wasm (Safari per-app test wallet notice) into feat/cha…
replghost Sep 28, 2026
4814225
Merge feat/pvm-wasm into feat/chat-v2-host-runtime
replghost Sep 29, 2026
355dc79
chore(vendor): repack the host from host-rust-core#709 at a5502aab
replghost Sep 29, 2026
dfb1d24
Merge revert of the light-client E2E switch into feat/chat-v2-host-ru…
replghost Sep 29, 2026
203c09c
Merge refreshed PolkaVM base into Chat runtime
replghost Sep 29, 2026
14c0981
Merge commit '7999fe67' into HEAD
replghost Sep 29, 2026
c594e50
Merge commit '8858795d' into HEAD
replghost Sep 29, 2026
f50f74c
Merge commit '2b25898a' into HEAD
replghost Sep 29, 2026
be57cf6
Refresh the Chat wallet SDK from the unified 0.23 runtime
replghost Sep 29, 2026
92cd04d
feat: gate PolkaVM apps behind user setting
replghost Sep 29, 2026
b287d17
test: cover PolkaVM runtime opt-in transition
replghost Sep 29, 2026
bedc6c2
ci: recognize the public resolver mapping-slot vector
replghost Sep 29, 2026
6e115a4
Merge feat/pvm-wasm into feat/chat-v2-host-runtime
replghost Sep 29, 2026
c01068b
ci: retain deployed product smoke diagnostics
replghost Sep 29, 2026
97b1d8d
fix(host): settle protocol startup and exercise demand-driven Chat
replghost Sep 29, 2026
f895386
Merge commit '87cd09cdd35f74c2e9640c01e475851a436bb040' into HEAD
replghost Sep 29, 2026
04b8bad
style: normalize Chat smoke documentation spacing
replghost Sep 29, 2026
3c7744c
feat(chat): host-owned Contacts picker backed by native Chat directory
replghost Sep 30, 2026
eecd1d5
chore(vendor): refresh Chat runtime from qualified source 437a46c5
replghost Sep 30, 2026
fd84229
test(smoke): opt deployed PolkaVM smoke into experimental apps
replghost Sep 30, 2026
e7d982f
test(smoke): enable PolkaVM through user settings before execution
replghost Sep 30, 2026
cec0150
Merge concurrent smoke opt-in using the verified Settings interaction
replghost Sep 30, 2026
17ad8b0
fix(settings): PolkaVM apps on by default outside production
replghost Sep 30, 2026
feec9de
Merge commit 'dd110e71' into HEAD
replghost Sep 30, 2026
77cb602
test(settings): remove superseded default helper import
replghost Sep 30, 2026
11df158
Merge commit '98376ca4049fb0cc96974d8564060272bf030af8' into HEAD
replghost Sep 30, 2026
101b2b6
Merge commit '7f99ce47678dde7d1d0e466e092db97229adb949' into HEAD
replghost Sep 30, 2026
753841e
Merge provider refresh into Chat authority runtime
replghost Sep 30, 2026
4b9dec9
Merge SDK provenance guidance while retaining Chat artifacts
replghost Sep 30, 2026
598e497
Merge source-pinned E2E toolchain setup from PVM
replghost Sep 30, 2026
a0de426
Merge provider-compatible Previewnet trust roots from PVM
replghost Sep 30, 2026
b25f923
Merge current main and PVM into native Chat
replghost Oct 1, 2026
474e770
Apply strict native Chat configuration and test contracts
replghost Oct 1, 2026
93043ae
fix(rpc): preserve idle subscriptions and propagate transport loss
replghost Oct 1, 2026
836f702
Merge gateway subscription recovery from PolkaVM into Chat
replghost Oct 1, 2026
6047abf
Merge shared-core consent retirement while preserving Chat custody
replghost Oct 1, 2026
6222266
Merge commit '8db88b04fee2b1b33fea09647d44745bd09de941' into HEAD
replghost Oct 1, 2026
feb65b8
Merge commit '836f702d568c6f5376419f33595567a0a367117c' into HEAD
replghost Oct 1, 2026
0cddc13
Merge commit '952e3b41bf7b1f3bd630bd243042cf57d362b740' into HEAD
replghost Oct 1, 2026
baa34f2
Merge commit '825a391348a9d3489fadc52ebb1f16bee5973c37' into HEAD
replghost Oct 1, 2026
4f011d0
Merge commit 'ce4ebdf04f80eff5d427ddca4d17e58e9ff8c296' into HEAD
replghost Oct 1, 2026
19253c2
Merge commit '026cbedeffe2a2f6a98c40c9b6dcb0c3b6b711c0' into HEAD
replghost Oct 1, 2026
a76966e
Merge commit 'fef26cd136c8e6c142ef644cc7640dd83d0fa58d' into HEAD
replghost Oct 1, 2026
1d1000f
Merge commit '76314cd7ab368c2035e9d48b02b87dccedb0a229' into HEAD
replghost Oct 1, 2026
cd3aad1
Merge commit '3898d80afba6fcf01c28c0b61d8bca6f217e5a41' into HEAD
replghost Oct 1, 2026
4130d62
Merge commit 'e592e99313a10edbcb9f822a1197932703c74d11' into HEAD
replghost Oct 1, 2026
e103de7
Merge commit '69d255a3e5a2c8ac4567833894df482d20c17e8f' into HEAD
replghost Oct 1, 2026
2cfe08e
chore: refresh canonical native-main Chat SDK artifacts
replghost Oct 1, 2026
b0e7c4b
Merge commit '289d0b1399f524fdd036d3a6be5dae04b4fcfa38' into HEAD
replghost Oct 1, 2026
49af684
Merge commit 'a864a60348984c0cb2ae0b4895517a455b96c4b6' into HEAD
replghost Oct 1, 2026
bef37bf
Merge commit '5aae6ba5d8ad5cad932e1a06e9e3b1e873b584c8' into HEAD
replghost Oct 1, 2026
ef8e703
Merge commit '0afb7feb122702e476d21d1f440917e81a2256c1' into HEAD
replghost Oct 1, 2026
79c3240
merge: inherit qualified stopped-chain recovery
replghost Oct 2, 2026
2d0a125
merge: inherit shared-worker generation recovery
replghost Oct 2, 2026
d0e8994
merge: inherit proven recovery guidance
replghost Oct 2, 2026
071c295
merge: inherit real-RPC recovery regression cutover
replghost Oct 2, 2026
bb9ad3d
merge: inherit isolated bitswap fixture setup
replghost Oct 2, 2026
301a235
Merge corrected upstream and refresh canonical chat artifacts
replghost Oct 2, 2026
6ef2aa6
Merge commit 'abca1e079e90781a97fa9492331ddb7ad669d2b7' into HEAD
replghost Oct 2, 2026
256815b
Merge refreshed runtime into browser Chat
replghost Oct 2, 2026
5589cc6
docs: qualify current Chat on top-level paseo.fyi integration
replghost Oct 2, 2026
756767c
docs: name current echat product in smoke guidance
replghost Oct 2, 2026
04753b9
Merge refreshed runtime and matching native Chat packages
replghost Oct 2, 2026
649dced
Merge refreshed browser runtime into Chat
replghost Oct 2, 2026
c46dcc7
Merge refreshed runtime and matched Chat native artifacts
replghost Oct 2, 2026
b95739d
Merge runtime cache regression compatibility into Chat
replghost Oct 2, 2026
8fb07f7
Merge final runtime formatting into Chat
replghost Oct 2, 2026
7acba8e
Merge persisted cache compatibility correction into Chat
replghost Oct 2, 2026
e1a85a3
Merge runtime archive fixture correction into Chat
replghost Oct 2, 2026
912a1b3
merge: forward generic locale support into Chat
replghost Oct 2, 2026
353004a
build: vendor Chat SDK with local timestamp support
replghost Oct 2, 2026
a0bd69a
merge: forward generic SDK refresh retaining Chat-native artifacts
replghost Oct 2, 2026
382b4a3
merge: forward generic locale documentation into Chat
replghost Oct 2, 2026
db8f4dd
merge: forward locale timer test correction into Chat
replghost Oct 2, 2026
f9080f8
merge: forward locale convention fixes into Chat
replghost Oct 2, 2026
89d3df0
merge: forward bridge SDK mock repair into Chat
replghost Oct 2, 2026
3b2916b
build(vendor): record the generated client digest
replghost Oct 3, 2026
34f7061
Merge refreshed PolkaVM runtime into Chat
replghost Oct 3, 2026
ec5c631
Merge approved Duke pointer-lock smoke correction into browser #255
replghost Oct 3, 2026
231cfb0
fix(contacts): hide account IDs in the host picker
replghost Oct 3, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 9 additions & 1 deletion .github/workflows/deploy.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
name: Deploy

on:
workflow_dispatch:
pull_request:
types: [labeled, synchronize]
push:
Expand Down Expand Up @@ -34,6 +35,11 @@ jobs:
# Environments a PR label is allowed to target (development only).
ALLOWED='["paseoli.dev","paseo.fyi"]'
case "$EVENT_NAME" in
workflow_dispatch)
echo 'environments=["westendli.dev"]' >> "$GITHUB_OUTPUT"
echo 'smoke_environments=["westendli.dev"]' >> "$GITHUB_OUTPUT"
echo "ref=$GITHUB_SHA" >> "$GITHUB_OUTPUT"
;;
release)
echo 'environments=["paseo.li","testnet.li"]' >> "$GITHUB_OUTPUT"
echo "ref=$RELEASE_TAG" >> "$GITHUB_OUTPUT"
Expand Down Expand Up @@ -75,6 +81,8 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ needs.plan.outputs.ref || github.sha }}

- uses: ./.github/actions/setup-node

Expand Down Expand Up @@ -117,7 +125,7 @@ jobs:
env:
VITE_APP_URL: ${{ vars.APP_URL }}
VITE_APP_DEBUG: ${{ vars.APP_DEBUG }}
VITE_COMMIT_SHA: ${{ github.sha }}
VITE_COMMIT_SHA: ${{ needs.plan.outputs.ref || github.sha }}
VITE_SENTRY_DSN: ${{ secrets.SENTRY_DSN }}
VITE_METRICS: ${{ secrets.VITE_METRICS }}
VITE_NETWORKS: ${{ vars.NETWORKS }}
Expand Down
68 changes: 68 additions & 0 deletions DEPLOYMENT.md
Original file line number Diff line number Diff line change
Expand Up @@ -143,11 +143,79 @@ reloads the whole server configuration. `nginx -t` must pass before reload; a fa
operator repair but does not reload the running service. This is not an atomic rollback or a full provisioning path.

After frontend upload, the opted-in job performs a public read-only GET to

`https://<site>/__dotli-identity/paseo/attester`, matching its environment. It requires successful HTTP status and a
JSON object containing a 32-byte hex `attester`; frontend HTML with status 200 fails. No authentication challenge,
token, or username is created by the smoke check. Unset `DEPLOY_NGINX` to return to dist-only CI; this does not remove
an already installed proxy.

## Qualify and deploy Chat on paseo.fyi

Chat-specific browser integration belongs to `paritytech/dotli-community#255`, head `feat/chat-v2-host-runtime`, base
`feat/pvm-wasm`. Keep that base and forward changes through Seity #287 into the deploy integration #291,
`feat/jam-peer-transport-on-seity` (base `feat/chat-seity-profile`). Only #291 carries `deploy: paseo.fyi`; never put
that label on #238, #185, #255, #287, or #290. Updating these branches does not merge their feature PRs into their
bases.

Each browser layer must vendor a matching client/host package set from its corresponding native layer:

| Browser layer | Native host source |
| ----------------------- | --------------------------------------------------------- |
| #185 PolkaVM runtime | `host-rust-core#540`, `feat/pvm-app-runtime` |
| #255 Chat | `host-rust-core#709`, `feat/chat-v2-product-authority` |
| #287 Seity profiles | `host-rust-core#1001`, `feat/chat-seity-profile` |
| #290 JAM PeerTransport | `host-rust-core#1010`, `feat/pvm-peer-transport` |
| #291 Deploy integration | `host-rust-core#1011`, `feat/jam-peer-transport-on-seity` |

Keep #291 and native #1011 integration-only: merge their refreshed Seity and PeerTransport parents with `--no-ff`, then
refresh the matching vendored packages. Never copy Chat, Seity, or PeerTransport APIs into a lower layer.

Before publishing the Chat layer:

1. Build `@parity/truapi` and `@parity/truapi-host` from the same committed `host-rust-core#709` source, including
codegen and the browser WASM build. Version `0.17.0` alone is not proof of the method-12 native Chat actor API.
Replace the two vendored package archives together, retain `@parity/truapi=file:../truapi` in the vendored host
package, and update `vendor/truapi-host.lock.json` with the actual source and WASM revision, archive SHA-256 values,
the hash of `vendor/truapi/dist/generated/client.js`, and the uncompressed
`vendor/truapi-host/dist/wasm/web/truapi_server_bg.wasm` hash. If package dependency metadata changes, refresh
`package-lock.json` with Node 26/npm 12 and `npm install`; otherwise retain the existing lock. Never invent pins.
2. Run the repository quality gate against the candidate head and verify the vendored generated client exposes
`account.deviceChat` (method 12), `MainPurseChatPayment` review, private storage slots through `NativeChatProducts`,
and per-product platform callbacks on the shared signing runtime. The independent PolkaVM renderer/runtime asset lock
is not a substitute for the Host WASM pin.
3. Use a debug build with `VITE_NETWORKS=paseo-next-v2`. Confirm People genesis
`0x4a2b5b737de1da59e209b0000a876ec2fa20035dc34fd292a848da32d255ad48`, Coinage instance `0` (`pUSD`, six chain
decimals), and bare identity suffix `paseo`. Inspect the configured chain metadata rather than inferring an asset
from a UI name. The browser uses the inherited experimental wallet, not a product-owned wallet; it does not claim
hardware-backed spending approval.
4. In the actual browser surface, qualify invitation/acceptance, text and attachments, then a rejected payment. Every
spend must show the exact requesting product, recipient identity, amount, maximum debit, chain, asset instance and
operation. A prior Chat grant must not skip this review. Only an explicitly authorized real-funds exercise may
approve a payment; check actual settlement in both directions, not merely a sent message.
5. Close the product connection while keeping the page core's wallet lease open; receive in the background. Products and
host controls lease the same native core; changing the page product retires the old signing authority before
acquiring its replacement. Reload and verify authorized native Chat devices resume without prompting. Verify pending
payments reconcile rather than being displayed as cleared. Move the wallet to a competing tab: the former owner must
stop its worker and release custody before the new tab can sign. Concurrent custody attempts must fail unavailable,
not create a second signer or overwrite inventory. Test storage/crypto failures in an isolated profile, never by
clearing an existing wallet's storage. The wallet owner is exclusive across host subdomains/tabs. Private core
records are authenticated-encrypted in the root-origin store; immutable attachment source Blobs remain host-private
but are not encrypted at rest, matching the SDK source store's existing policy.

After qualifying each source layer, forward both #287 and #290 into #291 and rebuild its matching native #1011 package
set. Run the quality gate and browser qualification again on the final #291 candidate. Verify the repository, PR number,
head, base, vendor provenance, and deployment label before publishing the approved candidate to **#291's existing head
branch**. Its `pull_request/synchronize` event selects `paseo.fyi` from that label and deploys the PR head SHA after the
quality gate. Confirm that no other deployment label is present before triggering a synchronization. Observe both
published-product and TrUAPI smoke jobs, then repeat the Chat surface checks on paseo.fyi with the separately qualified,
payment-capable `echat.paseo` product release. An older `egui-chat` build is not a substitute for the current product or
evidence that payments work.

Do not use `workflow_dispatch` for this operation: this workflow routes manual dispatch to **westendli.dev**, not
paseo.fyi. Do not fall back to another environment if paseo.fyi qualification or deployment fails. The wallet's
same-origin identity proxy must already be configured, or its separately authorized `DEPLOY_NGINX` opt-in must target
`fyi-paseo` as documented above.

## Checking what is deployed

Every origin serves its own build's `host_version.json` at the root:
Expand Down
48 changes: 36 additions & 12 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -248,10 +248,12 @@ be tested without publishing a manifest.

Custom messages (`ChatMessageContent::Custom`) render live: when a custom message cell scrolls into view, the panel asks
the product to draw it through the Renderer service (`renderer.render`, with a `ChatMessage` render context) and renders
the streamed tree with the host's own design system (`src/chat/custom-renderer.ts`). The tree is a closed vocabulary of
layouts and design tokens, so a product can never inject markup, styles, or URLs. Button taps and text-field edits
inside a rendered tree flow back on `renderer.action_subscribe`; taps on `Actions`-content buttons flow back as
`ActionTriggered` chat actions.
the streamed tree with the host's Solid components (`packages/ui/src/components/chat/CustomMessage.tsx` and
`CustomNode.tsx`). The tree is a closed vocabulary of layouts and design tokens, so a product can never inject markup,
styles, or URLs. Button taps and text-field edits inside a rendered tree flow back on `renderer.action_subscribe`; taps
on `Actions`-content buttons flow back as `ActionTriggered` chat actions. Replacing a streamed tree aborts its image
loads and revokes its object URLs; scrolling a message out of view or closing the panel releases its render subscription
and tree resources.

### App iframe model

Expand Down Expand Up @@ -444,6 +446,10 @@ scenarios exercise a fresh visit without opting in. On production `dot.li`, the
**Save & Apply** first. An existing saved choice, including an opt-out on a testnet, remains authoritative. The site
default applies only when no valid preference has been saved.

The `echat` smoke stays signed out: it cancels the initial sign-in request, uses the guest's Retry button to open a
fresh host prompt, cancels again, and checks redraw and resize. An idle, demand-driven UI need not publish continuous
update telemetry. The game scenarios retain their continuous rendering, audio, and input checks.

```bash
cd apps/host
DOTLI_SMOKE_ROOT=paseo.fyi DOTLI_WEBGPU=1 npm run test:smoke:products -- --output=test-results/products
Expand Down Expand Up @@ -550,6 +556,22 @@ native resource-allocation API and require an explicit request confirmation; nat
exposes allocation outcomes, not remaining quota, balances, amounts or fees. Results are labeled as last observed
outcomes, and uncertain results are not retried automatically.

Native Chat uses the wallet-owned main purse, private device records and a durable product index in the protocol
origin's IndexedDB. Closing a product connection does not stop receiving while the page's wallet core remains alive. A
page-product change retires the previous signer and releases its custody before starting the replacement; reload
restores only previously authorized devices, without prompting for fresh Chat authority in the background. Each payment
requires a new host review of the authenticated product and recipient, exact amount, maximum debit including fees,
selected chain and Coinage asset, and payment operation. Chat or automatic-signing grants never approve spending.
Private core records are authenticated-encrypted at rest; immutable attachment source Blobs are private to the trusted
host but are not encrypted at rest. They never enter product storage or the product RPC interface.

Contacts are read from the active native wallet and People-chain binding, never from a product-provided roster. The
Solid host picker cancels when its connection closes or the session, roster, wallet or network changes, and revalidates
a selection before returning a contact handle. Product prompts have connection-owned modal scopes; authentication,
private storage and attachment custody stay with the one page core.

Picker rows show verified contact names, with a generic label for unnamed contacts; raw account IDs are not displayed.

Use the existing **List**, **Timeline**, and **Resolution** tabs for activity and diagnostics. Wallet does not duplicate
their event viewer or capture controls.

Expand All @@ -561,14 +583,16 @@ deletion controls are confined to Recovery.

**Import / replace test wallet** accepts checksum-valid English BIP-39 phrases of 12, 15, 18, 21 or 24 words, without a
passphrase or custom derivation path. It uses native Polkadot host/Substrate derivation, not Bitcoin/Ethereum seed
derivation. Importing an exported phrase restores the same account keys on the same network, but not permissions; use
**Check username** to rediscover its registered name. Back up the previous test wallet before replacing it. Successful
import replaces the shared wallet for trusted product hosts, clears wallet-bound experimental session/signing grants,
activates the imported wallet and reloads open tabs; Mobile pairing and grants remain separate.

**Delete test wallet** requires confirmation and removes the shared wallet's stored entropy, experimental
session/signing grants and this origin's preserved legacy copy. Without a recovery phrase backup, deleting the wallet or
clearing site data permanently loses access.
derivation. Importing an exported phrase restores the same account keys on the same network, but not permissions; its
registered username is looked up automatically. Back up the previous test wallet before replacing it. Successful import
replaces the shared wallet for trusted product hosts, clears wallet-bound experimental session/signing grants, activates
the imported wallet and reloads open tabs; Mobile pairing and grants remain separate.

**Delete test wallet** requires confirmation and removes the shared wallet's stored entropy and this origin's preserved
legacy copy, while retiring experimental session/signing grants. Wallet-scoped purse and Chat records are retained
separately, not silently erased by identity replacement or deletion; restoring the same identity still requires fresh
permissions. A recovery phrase restores identity keys, not a backup of private purse or Chat records. Clearing site data
can therefore destroy private state even when the phrase is backed up.

Only one tab of a browser profile runs the test wallet at a time, because two tabs starting their own wallet cores would
claim allowances twice and overwrite each other's state. Opening an app with the test wallet in another tab moves it
Expand Down
18 changes: 16 additions & 2 deletions THIRD_PARTY_NOTICES.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,10 +10,24 @@ outbound license. The vendored `@useragent-kit/polkavm-runtime` browser artifact
notices, per-file hashes, and source provenance ship beside the runtime. Build-time-only tooling under source-available
FSL-1.1-MIT terms is not redistributed as part of the application.

The vendored `@parity/truapi` client is MIT-licensed. The `@parity/truapi-host` distribution is `MIT AND AGPL-3.0-only`,
not MIT-only: its Rust signing runtime/WASM includes the native Chat, HOP and Coinage implementations. Both packages
come from
[host-rust-core revision `437a46c5af88b3c4a962d763f8fa5732e9c48183`](https://github.com/paritytech/host-rust-core/commit/437a46c5af88b3c4a962d763f8fa5732e9c48183).
Archive and installed artifact hashes are recorded in `vendor/truapi-host.lock.json`, including the local dependency
override. The Host's `LICENSE`, `LICENSE-AGPL-3.0` and `NOTICE` are retained in `vendor/truapi-host/`; the notice
identifies the adapted components and their source revisions. Corresponding Source for redistribution must include that
exact Host source, its component provenance and build instructions, plus any local modifications; a repository URL alone
does not supply unpublished changes.

> Generated from the resolved dependency tree (841 distinct third-party packages) by `scripts/third-party-notices.ts`.
> Platform-specific binary packages (for example `*-darwin-arm64`, `@esbuild/*`, `@rolldown/*`) reflect the build host;
> other platforms resolve their own equivalents under the same licenses. Regenerate after dependency changes.

## MIT AND AGPL-3.0-only

@parity/truapi-host

## MIT

@apideck/better-ajv-errors, @astrojs/astro2tsx, @astrojs/check, @astrojs/compiler-binding,
Expand Down Expand Up @@ -62,8 +76,8 @@ FSL-1.1-MIT terms is not redistributed as part of the application.
@esbuild/darwin-arm64, @eslint-community/eslint-utils, @eslint-community/regexpp, @eslint/js, @img/colour,
@jridgewell/gen-mapping, @jridgewell/remapping, @jridgewell/resolve-uri, @jridgewell/source-map,
@jridgewell/sourcemap-codec, @jridgewell/trace-mapping, @keyv/bigmap, @keyv/serialize, @napi-rs/wasm-runtime,
@noble/ciphers, @noble/curves, @noble/hashes, @oslojs/encoding, @oxc-project/types, @parity/truapi, @parity/truapi-host,
@pkgr/core, @polkadot-api/cli, @polkadot-api/codegen, @polkadot-api/ink-contracts, @polkadot-api/json-rpc-provider,
@noble/ciphers, @noble/curves, @noble/hashes, @oslojs/encoding, @oxc-project/types, @parity/truapi, @pkgr/core,
@polkadot-api/cli, @polkadot-api/codegen, @polkadot-api/ink-contracts, @polkadot-api/json-rpc-provider,
@polkadot-api/json-rpc-provider-proxy, @polkadot-api/known-chains, @polkadot-api/logs-provider,
@polkadot-api/merkleize-metadata, @polkadot-api/metadata-builders, @polkadot-api/metadata-compatibility,
@polkadot-api/observable-client, @polkadot-api/pjs-signer, @polkadot-api/raw-client, @polkadot-api/raw-tx-creator,
Expand Down
4 changes: 2 additions & 2 deletions apps/host/src/errors.ts
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
// Copyright 2026 Parity Technologies (UK) Ltd.
// SPDX-License-Identifier: AGPL-3.0-only

import { WALLET_OWNER_BUSY_ERROR } from '@dotli/protocol';
import { CORE_CUSTODY_BUSY_ERROR, WALLET_OWNER_BUSY_ERROR } from '@dotli/protocol';
import { ProtocolFatalError, ProtocolInitFailedError } from '@dotli/protocol';
import { getActiveServicesConfig, BACKEND_LABELS } from '@dotli/config';

Expand Down Expand Up @@ -184,7 +184,7 @@ function classifyError(
// compile error rather than a silently unkeyed error page.
const msg = err instanceof Error ? err.message : String(err);

if (err instanceof Error && err.name === WALLET_OWNER_BUSY_ERROR) {
if (err instanceof Error && (err.name === WALLET_OWNER_BUSY_ERROR || err.name === CORE_CUSTODY_BUSY_ERROR)) {
return walletInOtherTab();
}
if (err instanceof ProtocolFatalError) {
Expand Down
Loading
Loading