Skip to content

feat(profile): show product-referenced Seity profiles in a host drawer - #287

Draft
replghost wants to merge 122 commits into
feat/chat-v2-host-runtimefrom
feat/chat-seity-profile
Draft

replghost wants to merge 122 commits into
feat/chat-v2-host-runtimefrom
feat/chat-seity-profile

Conversation

@replghost

@replghost replghost commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Current repair qualification — 2026-10-02

  • Frontend head: bdb7e068e1d2925e38dc9f7f5222536ddd5d07a8. Prior main baseline: f4012c50c3400d1186c332ad2ae50298cefd153d.
  • Native source and canonical artifact-generation pin: host-rust-core #1001 at 3a364f1157177f7d1ae4839241488d5c9276ed1d (seity). Complete matching SDK/host packages remain 0.23.0; no mixed or hand-patched Wasm bundle. Generated client bytes are unchanged. Production: wasm-signing-host; separate testing bundle: wasm-signing-host,test-host.
Canonical artifact SHA-256
Client npm archive 5442571f6770f05d97a1ed3c3a0ab96ca1df7c15d77ee168130d53853523db2d
Client dist/generated/client.js 02e193761518364624e9dd53a41dd7cbddf4b5d8482f3e93489b51edd0576630
Host npm archive 4442b38a45f987e38dfe1df98f04b57c4de90add4b1c182793556efdedc12edb
Browser signing Wasm d7934abc194e9ab30679498426ece50e331eefaa22e6ba830e2b4667b9787616
Local QA CLI 18cd9daa1b4d0ad970e968fed708bf3b310dc853c56f2545939aba54d9fba100

Native correction and causal limits

Bulletin mortal signatures now anchor to a finalized checkpoint, while nonce/runtime state comes from the freshest available signing snapshot. A checkpoint at least 64 blocks behind is rejected before broadcast. Regression coverage verifies the actual signature with a newer nonce and older finalized checkpoint, and the expiry boundary. Existing transaction retries/deadlines are unchanged; no chain error is suppressed. The affected test fixture uses parking_lot::Mutex.

The former Seity Extrinsic marked as invalid run used noncanonical best-block anchors, but retained evidence lacks the signed bytes and typed pool reason. Fork-sensitive mortality was a real correctness hazard; it is not claimed as the conclusively proved cause of that historical failure. Prior hosted Factory/Genesis timeout causes also remain unproved. No broker/readiness workaround, prewarming, extra retry, or timeout increase was added.

Final exact-head hosted checks

Workflow Result
Dependency Audit success
Secret Scan success
Bundle Size success
Static Analysis success
Performance Tests success
Tests failure
  • Functional: 85 passed, 4 failed, 3 skipped.
  • E2E: 42 passed, 20 skipped.
  • Performance: 3 passed in the cold-start suite. This hosted suite measures cold start, not the Doom backend matrix.
  • No flaky-test summary in this exact-head hosted Tests log.
  • Corresponding native CI: success. Each of five native variants passed 21 Bulletin regressions and all-target Clippy; base full library passed 1,246 tests.

Real-runtime local verification

All six consumers passed configured build, typecheck and lint. The later README-only formatting correction passed targeted Prettier checks and did not change runtime source or canonical native package bytes. Original full Wallet→Chat→Seity test sequences, without test retries, added waits, or prewarming:

Local original sequence Tested frontend head Result, retries=0 Genesis after navigation Factory Submit
#238 0a24db4aa189adad7b93f9ff508c7949e39196ee 42 passed, 20 skipped; no failed/flaky cases 1107ms 9625ms 6057ms
#255 301a235ba13248ef4281e9e3d859919fb6cfbe06 42 passed, 20 skipped; no failed/flaky cases 1045ms 11023ms 13548ms
#287 d3dc8a41807c36b8bcdf001c47eccb9735305499 42 passed, 20 skipped; no failed/flaky cases 1029ms 6496ms 5530ms

Wallet's tested head is final. Chat and Seity tested heads precede documentation-only formatting merges; native/Wasm pins and runtime code are unchanged. Factory, Genesis-after-navigation and Submit passed on all three. These bounded passes do not establish the cause or elimination of the older hosted timeouts. Prior SharedWorker lifecycle, Chat/profile, Peer and JAM runtime proofs remain historical at their recorded heads; they were not all rerun on these artifacts.

Final hosted retest: failures remain

Frontend PR Tests workflow Functional E2E
#238 success 79 passed 42 passed, 20 skipped
#185 success 89 passed, 3 skipped 41 passed, 1 flaky, 20 skipped
#255 success 89 passed, 3 skipped 42 passed, 20 skipped
#287 failure 85 passed, 4 failed, 3 skipped 42 passed, 20 skipped
#290 success 87 passed, 2 failed, 3 skipped 42 passed, 20 skipped
#291 failure 86 passed, 5 failed, 3 skipped 41 passed, 1 flaky, 20 skipped
  • PVM and JAM Genesis Hash still flaked after navigation: the product stayed pending for the helper's existing 20 seconds; the existing CI retry passed. The helper reports this timeout as error; it is not evidence of a chain rejection. Retained traces include People-chain/local development sockets but do not expose the Asset Hub gateway WebSocket exchange, so these new failures do not establish an upstream or broker cause.
  • Peer: two navigation product-render timeouts at 45 seconds. The existing threshold tolerates these, so its green workflow is not a clean functional suite.
  • Seity: cache-off RPC-gateway resolution timed out; two navigation renders timed out; another navigation case reported failure to connect to trusted provider paseo-bulletin-next-ipfs.polkadot.io. The zero-failure host-settings gate correctly failed.
  • JAM: cache-on reload and two navigation cases reported that same provider connection error; two more navigation cases timed out. The zero-failure host-settings gate correctly failed. These logs do not establish whether the underlying cause was provider availability, runner networking, CORS, or another transport failure.
  • All six final Static Analysis and hosted cold-start Performance workflows passed; all five native CI workflows passed. That does not clear the red functional gates, Genesis flakes, or Doom matrix. No additional CI rerun, timeout/retry increase, threshold relaxation, or speculative transport patch was made.

Doom: criterion corrected, backend matrix still unqualified

The user explicitly approved 35 FPS sustained over 30 seconds, with one frame of sampling-boundary tolerance: frames + 1 >= elapsedMs * 35 / 1000. This replaces the instantaneous FPS >= 35 sample; it is an acceptance-criterion change, not a runtime speedup. Runtime and displayed FPS are unchanged; raw samples are not rounded to force a pass. Update p95 <28.6ms, cold/warm first-frame limits <3,000/<1,000ms, audio and translation-cache checks remain. The revised official RPC benchmark passed once before the vendor replacement.

The later isolated matrix used the rebuilt base pair at frontend 238ab5fa739788b2eb948ba1f807a1876edbacad, with fresh owned Chrome profiles and no concurrent builds/E2E:

Backend Observed result Qualification
smoldot-direct 1,050 frames / 30,001.1ms; p95 17.7ms; cold/warm 202.9/152.8ms; audio/cache passed PASS under the approved criterion
smoldot-shared-worker 1,038 frames / 30,001.4ms = 34.5983854 FPS; p95 17ms; cold/warm 186.4/158.4ms; other checks passed FAIL: cadence deficit retained
rpc-gateway Warm-readiness helper timed out. Its null snapshot conflated missing frame, missing canvas and evaluation errors, and earlier cold/cadence values were not retained by that helper NOT QUALIFIED; iframe disappearance is not established

Distinct diagnostics found no presentation loss in a later instrumented 24-second shared-worker sample and observed a successful hidden RPC new-document reload. Neither diagnostic supersedes the failures or qualifies performance. No evidence-proved runtime fix, guest rebuild, speculative tuning, or further unchanged gate rerun was made. The original strict RPC failure and every new failure remain retained. Next causal capture must instrument the original early 30-second window and distinguish warm lifecycle states before proposing a runtime fix.

Retention and rollout boundary

Local verification used paseo-next-v2, the pinned host-playground fixture f56294cea4430163bf16ec068844b1327441073c, and existing private QA identities. All three corrected sequences paired on their first existing setup attempt. A prior local launch failure and a misconfigured Previewnet-product run (34 passed, 20 skipped, 8 Chain/Contract failures) are retained separately, not presented as reproductions of the hosted Genesis timeout. Private traces/auth/signers were not published.

The first repair heads also exposed a README formatting failure (corrected by documentation-only commits) and a PVM cache-unit-test 5,000ms timeout. No cache runtime/test change, limit increase, or causal claim was made for that isolated timeout. Older in-flight runs superseded by the formatting correction remain recorded as cancelled, not passed.

No PR merge, force push, deployment, environment approval, SDK/npm/product/guest publication, or rollback was performed by this repair. JAM remains JAM-TEST-INSTANCE, never JAM-PUBLIC-DEVNET. The user-owned deploy: paseo.fyi label is retained; repair-triggered deployment runs 36970790399 and 36971286469 were cancelled before deployment. The earlier rollout audit is retained below: an older workflow deployed 56cea5d37577bf82684fb5c6b6e4ba81d2142938; this record does not claim live remained unchanged historically.

Historical integration qualification (superseded; retained verbatim)

Current merged-main refresh and qualification — 2026-10-01

Canonical artifact SHA-256
Client npm archive 5442571f6770f05d97a1ed3c3a0ab96ca1df7c15d77ee168130d53853523db2d
Client dist/generated/client.js (not dist/index.js) 02e193761518364624e9dd53a41dd7cbddf4b5d8482f3e93489b51edd0576630
Host npm archive 8bd67c12ee9303c802b94d7b65c4c800c5cbe338a78311cb6786270a0c06ca63
Browser signing Wasm c47f65213982969e4a42ae02fdf08ae621fc50fcfc30f3feb74a5878260bed63

Stack and hosted qualification

Wallet → PVM → Chat → Seity; PVM → Peer; JAM contains both Seity and Peer. All updates used fresh-fetch ancestry checks and ordinary pushes. User worktrees, metadata and canonical repositories were preserved.

  • #238: 70845db96bdd21409310daeff5e471b74ab5a1c9.
  • #185: 351e5d73fab803a0fd2a4007ce2d2557aebaff05.
  • #255: bb9ad3d8921c63cf62c98b9029289f458b1a67a2.
  • #287: b03e83616857f4e4745d479776dde43cdfa6267a.
  • #290: 44ed4f830a2c8f86990e02fb061c802aa389b0bc.
  • #291: dcdef40499119183aed82a39f784ef740d494341.

Exact-head hosted results: functional 89 passed, 3 skipped; E2E 41 passed, 1 flaky, 20 skipped; 3 passed in the cold-start suite. Tests run.

Hosted E2E retained one flaky Chain → Chain Spec: Genesis Hash case: it failed on the first attempt and passed the existing CI retry. No retry setting was changed.

Performance Tests runs the cold-start suite, not the strict Doom matrix below. Existing thresholds, retries, deadlines and skips were not relaxed. Native current-head Core CI has 22 passed jobs and 2 path-filter skips; full iOS application CI is not claimed for the latest native heads.

Local and actual-runtime evidence

  • Typecheck, lint, format, full unit suites and builds passed across all six frontend variants. The final runtime-code cutover is unchanged; later test/docs-only fixes removed the obsolete whole-resolver mock at PVM and moved fresh bitswap module loading into per-case setup before provider fixtures are installed. The timed-out cold-import continuation can no longer issue requests through the following case’s provider. All 17 targeted bitswap cases and the root full gates passed without changing a test timeout, retry/discovery bound, assertion value or skip. The actual stopped-follow browser regression passed on every corrected descendant with the unchanged 10s deadline.
  • Wallet functional suite: 79/79 passed. Corrected PVM full functional suite: 89 passed, 3 existing artifact-dependent skips. Combined JAM functional suite: 91 passed, 3 existing artifact-dependent skips, including both strict cached-host upgrade scenarios; final JAM changes after that full run are ancestry/docs-only. Combined local E2E: 42 passed, 20 existing skips. These are separately scoped runs, not fabricated per-branch full-suite counts.
  • Real RPC fault injection stops a configured node’s active chainHead storage read; the application loads with exactly one fresh follow and no domain error. The canonical resolver owns the one retry and the remaining original sync budget. An earlier hosted Peer run failed before collection because the obsolete mock duplicated this regression title; that integration error was fixed at PVM and propagated through all descendants, without changing a gate.
  • Browser/native terminal recovery: the original CoreWorker/client/transport and native connection remained open after a real uncaught SharedWorker error. The old follow stopped; a later real chain query recovered through a new URL generation in 8,147ms, and a new follow on the same client delivered 76 live NewBlock events. Same-partition cross-tab sharing was verified before and after replacement. This does not claim continuity of the stopped follow. Evidence: main-refresh-terminal-verified-pvm.json / screenshot.
  • Real transient RPC closure/replay was also observed with one consumer receiving post-reconnect statement data and remaining alive for 130s. Evidence: main-refresh-pvm-transport.json / screenshot.
  • Feature-specific proof: Real encrypted-content lifecycle passed: an 82-byte AES-256-GCM test ciphertext was submitted on Paseo, retrieved from Bulletin through the production profile loader, decrypted to the exact nonpersonal 1×1 PNG, and displayed. Closing revoked its blob URL; reopening created a new blob and exactly one drawer. This is not a full registered-user profile/contact-sharing round trip. Evidence: main-refresh-seity-live.json and screenshot.
  • Live probes used the canonical feature bundles before final test/docs-only changes; temporary drivers/profiles were removed and public JSON/screenshots retained beside the refresh worktrees. Testnet-only identities, statements, preimages and allowances were permitted; no mainnet write was performed.

Strict Doom matrix — retained failure

Fresh isolated visible headless Chromium profiles; cold cache miss, real compiler, nonzero audio, and 360 frame updates for each backend. Warm reload uses a new document in the owned iframe: cache hit and zero translation. Gates remain FPS ≥35, p95 <28.6ms, cold first frame <3000ms, warm first frame <1000ms.

Backend FPS p95 ms Cold first ms Warm first ms Result
rpc-gateway 34.54231433545555 13.1 163.8 128.6 FAIL: FPS
smoldot-direct 35.06721215581914 13.2 173.7 110.1 PASS
smoldot-shared-worker 35.48895899032775 11.8 164.3 100.3 PASS

Evidence: main-refresh-isolated-doom-{rpc-gateway,smoldot-direct,smoldot-shared-worker}.json and screenshots. Earlier hidden-tab and concurrent-QA failures remain recorded; no clock/rounding/threshold change or failure-only rerun was used to erase them.

Other retained limits

  • Latest local Seity E2E attempt: 41 passed, 20 existing skips, 1 Submit failure (Extrinsic marked as invalid). One UI call caused the existing two native broadcast attempts; both validated then invalidated. No matching included Submit was found in the inspected canonical block range. [INFERENCE] Noncanonical mortality anchors may explain invalidation, but the exact cause is unproved without the unretained signed extrinsic bytes. Evidence: main-refresh-seity-submit-diagnosis.json. Passing hosted E2E does not erase this local failure.
  • Earlier Seity Factory hit its unchanged 30s product deadline; its original payload was later included after 47,516ms. A separate unchanged manual Factory attempt passed in 10.918s, and Factory passed in the later full local suite. Evidence: main-refresh-seity-factory-diagnosis.json. No added retries, deadline changes, or unsupported cause claim.
  • Seity’s positive encrypted-content proof is not a full registered-user profile/contact-sharing round trip. Peer/JAM proof used the installed PVM host-frame-request path with a throwaway canonical SDK driver, not a newly published guest. Some validators refused connections; successful connections used actual certificate-verified WebTransport.

Rollout boundary

Not an all-green rollout qualification. The refreshed heads were not deployed, and this qualification granted no environment approval. No PR merge, SDK/npm publication, or guest/product publication was performed. JAM remains JAM-TEST-INSTANCE. All three refresh-triggered JAM Deploy runs were cancelled before rollout; latest final-head cancellation. Other branches have no deployment labels.

The live environment changed during qualification: older Deploy run 36945647296, attempt 3 was approved under GitHub account replghost, explicitly checked out baseline 56cea5d37577bf82684fb5c6b6e4ba81d2142938, and recorded deployment success at 2026-10-02 01:19:01 UTC. Its later published-product smoke failed. The operator/client/session behind that account is unproven; this qualification granted no approval and performed no rollback. The observed live content hash changed from 4a7caf047fb7f350c1833039b93ba634698a47c56f051b8c7fc0525d4c59a5c8 to 5882695ee20df5d24a6ed2feb9e997f176fe27ecf4eafe742fabb39eba92885f; these are content hashes, not Git SHAs, and their exact byte-level mapping to a source commit is unproven.

Earlier deployment authorizations/results below are historical evidence, not approval to deploy this refreshed stack.

Historical integration qualification (superseded; retained verbatim)

Current-main integration qualification (2026-10-01)

  • Published head: abb08d91deadd79e00c652b5ffd69d30232547e5. Includes main 74bb603e518ace149a846124f6e7353aca198c57, propagated through feat(wallet): add an opt-in debug-only browser test wallet #238 → feat(polkavm): run App Manifest v2 runtimes in Dotli #185 → feat(chat): restore separate Chat authority integration above PolkaVM #255 → feat(profile): show product-referenced Seity profiles in a host drawer #287 and feat(polkavm): run App Manifest v2 runtimes in Dotli #185 → feat(polkavm): JamPeerTransport over WebTransport for JAM apps (layer atop #185) #290, then combined in chore(deploy): Seity layer + JamPeerTransport (#287 + #290) #291. All six heads are published by normal ancestry-guarded pushes; no history rewrite.
  • Preserves main’s Astro/Solid architecture, explicit package APIs, strict NodeNext, one shared native page core, execution-local callbacks/consent, and host-owned block/archive cache. Retiring an execution does not retire core-owned authentication. Concurrent quiet-RPC/transport-loss fixes for Trusted Providers silently loses Statement Store subscriptions after 120 seconds of inactivity #308 are preserved throughout the stack, including Chat/Seity/JAM HOP support.
  • Canonical client/host SDK 0.23.0 source: f031658066d19e85b829aa786dad682e22b41197; complete feature-specific artifacts, signing-only browser Wasm, and separate testing Wasm. Native base #540 CI and Peer #1010 CI are green. No npm or guest publication.
  • Native integration proof (before the stylesheet-only follow-up): Final workspace checks/build and root checks/format passed. Actual native Profile consent attribution, Escape versus explicit Deny, retry behavior, real-registry empty-profile drawer, and execution retirement passed on RPC and SharedWorker without browser exceptions. Earlier positive-content proof exercised real decryption/avatar/mood rendering using the explicitly identified encrypted fixture.
  • Final-head CI gates pass, including Unit, Functional, and E2E. Functional: 89 passed, 0 failed, 3 skipped. E2E: 41 passed, 1 flaky (passed on retry), 20 skipped. The Chain Spec: Genesis Hash E2E initially returned error and passed on the existing retry. The three functional skips are existing artifact-dependent cases. No failure threshold or retry policy was relaxed.
  • Limits: No usable registered Profile/received-share session was available. Positive avatar/mood proof is fixture-backed, not a registered-user round trip.
  • Fixture-only CI follow-up: persisted settings can precede address-bar canonicalization. The two browser assertions now await the actual URL condition; no timeout increase, production change, or threshold relaxation. Ten Wallet and ten combined production browser iterations passed, followed by host type/lint and repository formatting checks. The corrected settings cases passed final-head hosted qualification.
  • Debug stylesheet follow-up: actual deployed inspection reproduced a 156 px unused gap caused by measuring the lazy debug panel before its CSS arrived. The Wallet-root fix imports CSS with the lazy module before mounting; obsolete manual-link injection and test workarounds are removed. The delayed-CSS behavioral regression failed before the fix and passes locally and on every final hosted head. All 91 focused debug-panel tests passed. Type/lint/format checks passed. Actual local RPC and SharedWorker Doom now meet the 360 px panel without a gap. Native artifacts are unchanged by this follow-up.
  • Rollout: Deployed only to paseo.fyi at combined chore(deploy): Seity layer + JamPeerTransport (#287 + #290) #291 117ef1eb2928a470e65e48c05b5bf22e8ab29c02 (successful deployment and smoke, deployment ID 6778272827). Hosted smoke passed 8/8 published products and 19/19 wallet-free capabilities. Independent fresh HTTPS Chromium sessions confirmed Build 0.6.0 (117ef1e) and playable Doom with advancing frames/input/audio on smoldot-direct, RPC gateway, and an actual SharedWorker, with zero browser exceptions. All three screenshots and geometry checks show the 384 px frame meeting the 360 px debug panel without a gap. An actual retained production c4a08e9 session waited for consent, navigated exactly once after Reload, retained the URL plus localStorage/IndexedDB/product-cache markers, and resumed playable Doom on 117ef1e with an activated controlling worker, no waiting worker, and zero exceptions. This is an actual release upgrade, not a substituted worker-script test. Local JSON/screenshots are retained under dotli-community-worktrees/paseo-fixed-doom-* and paseo-debug-fix-retained-*. No other environment was approved; no PR merge, force push, npm release, or on-chain guest publication.

Earlier sections are historical implementation and qualification records.

Latest dependency refresh qualification (2026-09-30)

  • Published head: 3b7b95e4bf5fdcf71976dcc48a51c0addca68efa; normal merges and ancestry-guarded pushes only, no history rewrite.
  • SDK: TrUAPI client + host 0.23.0, source f031658066d19e85b829aa786dad682e22b41197. Feature-specific 0.23.0 client/host/WASM artifacts remain unchanged; this source pin is intentionally not relabeled as the refreshed upstream branch head.
  • Provider: 0.3.1, including buffered-RPC lifecycle handling. Previewnet's four genesis hashes now match the provider catalogue and upstream reset #995; DotNS addresses/slots, suffix, and endpoints are unchanged.
  • Real-browser Previewnet check: relay, Asset Hub, Bulletin, and People each returned its configured genesis and synchronized health with a peer. This is provider-level proof, not Previewnet product-publication or identity-registration qualification.
  • Local migration format/lint/typecheck/unit/build checks passed. The final network change additionally passed all 54 configuration tests, config lint/typecheck, and the four-chain browser smoke.
  • Real-browser Browse rendered; relay, Asset Hub, People, and Bulletin reported peers/readiness through the new provider.
  • Final hosted checks passed for this head, including E2E: https://github.com/paritytech/dotli-community/actions/runs/36750612637. Functional results: 47 passed, 0 failed, 3 skipped. The E2E workflow installs rustfmt for the checked-out signing-host source's declared nightly-toolchain (older feature sources retain their existing nightly behavior).

Earlier implementation and qualification history follows; the versions and heads above describe this refresh.

Seity layer on top of #255. Consumes paritytech/trinity-user-agents#1001 (profile service).

What it does

  • Serves the optional profile host callbacks. profile.present({ reference }) opens a bottom-sheet drawer attributed to the calling product, fetches the referenced blob through the host's own preimage path (bitswap or the configured gateway, CID-verified), decrypts it (AES-256-GCM) and renders the avatar.
  • Resolves once the drawer is up. Fetch/decrypt failures are shown in the drawer; neither the image nor the reference's key returns to the product. Only PNG/JPEG/GIF/WebP render.
  • Reference format: Seity profile-core's <cid>#<key><iv> blob reference, pinned by a vector produced with profile-core's primitives.
  • Debug builds: window.__dotliPresentProfile(reference) opens the same drawer without a product.

Vendor

  • TrUAPI client/host 0.23.0 rebuilt from host-rust-core f031658066d19e85b829aa786dad682e22b41197 (#1001), including matching wallet WASM with wasm-signing-host, not test-host.
  • Profile uses canonical wire trait 69. vendor/truapi-host.lock.json pins archives, generated-client/WASM digests, features, and source provenance.

Scope limits

  • Mood/display name depends on Seity's two-field envelope reference.
  • The egui-chat caller belongs to the separate polkavm-app-kit layer.

Qualification

Branch-CI-qualified head: cc8845395006c4b21435c334b381caf19de7c99c.

Current-head checks pass, including unit, functional, and live E2E, type-checking, production builds, and full-history secret scanning. This qualifies branch CI, not deployment of the new Profile contract. Deployment evidence is qualified separately in #291.

After pulling these local-file SDK dependencies, use bun install --force --frozen-lockfile to replace Bun's cached packages.

Artifact and release boundary: the prior refresh-qualified SDK source was 6778214613f0b9d1db1ccc1029cd078d7ff0139d; the final lock now pins f031658066d19e85b829aa786dad682e22b41197, including the subsequent native Chat review fixes. Client/host archives were packed from canonical generated and compiled outputs of that exact source, with matching wallet/testing WASM. The generated client is byte-identical to the intermediate sharing build; the wallet runtime was refreshed. Exact archive/client/WASM digests are recorded in the lock.

Package version 0.23.0 does not mean the old wire contract is unchanged. The generated client declares TrUAPI version 3, Profile disclose/presentContact V2 and placeContactAvatars V3, including ChatApps, App, and Contacts audiences. Browser integration includes the Contacts picker, audience-wide consent, and encrypted wallet/chain-scoped ProfilePersonalReferencesReceived storage.

The user explicitly selected Deploy new sharing APIs to experimental paseo.fyi. The earlier combined #291 deployment at 032e97128983570eac9c32d6cd9dd8a41d181bca, built from host source af087f734be4d65d9363e68e43bf134145ae0085, passes 8/8 product scenarios and 19/19 wallet-free capabilities. Independent fresh Chromium verification of that combined release passes feature discovery, JSON storage round-trip, and live chain-genesis lookup. This does not qualify a live Profile/Contacts/avatar-sharing or own-profile/avatar-fetch scenario, nor is it a fresh-browser smoke of this branch alone.

The earlier combined #291 malformed-reference smoke remains limited to that rejection path. Historical deployment 57aaf948a7b9d9fb6f35b9a731ad9cad9856a859 and host source 08a08fbd921b56fd3ce36f6db3aad6f993bba784 retain their own evidence; those results are not reassigned to the newer artifact set.

Startup applies URL-selected protocol settings before wallet/debug hooks and drains shared-mode writes before iframe replacement or startup-triggered reload. Testnet published-product smoke starts without opting in; production dot.li remains default-off and its smoke uses Settings and Save & Apply and existing product assertions are unchanged. Failure-only deployed smoke traces and screenshots are retained for three days.

Secret scanning retains the default rules and full-history scan. The public resolver mapping-slot vector is exempted only when both its exact value and test path match; a boundary smoke confirms changed values and the same value elsewhere remain detectable.

Experimental execution defaults

PolkaVM execution defaults on for test environments (paseo.fyi, paseo.li, previews, and localhost) and off for production dot.li. Settings → Experimental → PolkaVM apps explicitly overrides either default; existing saved opt-outs and opt-ins remain authoritative. This is an execution gate, not build-time exclusion of runtime assets or Firebase-controlled eligibility. Product permissions remain separate from the execution setting.

Testnet product smoke exercises fresh visits without opting in; production dot.li still uses the explicit Settings opt-in.

The current combined default-on release, 76eb846e, passes 8/8 published products without a testnet opt-in and 19/19 wallet-free capabilities. Independent fresh Chromium observed that exact release, ran Doom with the default enabled, and preserved an existing testnet opt-out across reload. This is combined #291 deployment evidence, not a deployed smoke of this branch alone.

…1001)

Packs @parity/truapi and @parity/truapi-host at 95614da7, which adds the
`profile` service and the optional `profile` host callbacks. The web
WASM keeps the signing host, as before; lock hashes updated.
Serve the `profile` host callbacks. `profile.present` opens a bottom
sheet attributed to the calling product, fetches the referenced blob
through the host's own preimage path (bitswap or the configured gateway,
CID-verified), decrypts it with AES-256-GCM and renders the avatar. The
call resolves once the drawer is up; fetch and decrypt failures show in
the drawer, and neither the image nor the reference's key returns to the
product. Only raster formats render.

References use Seity profile-core's `<cid>#<key><iv>` blob format,
pinned by a vector produced with profile-core's primitives. Debug builds
expose `window.__dotliPresentProfile(reference)` to open the same drawer
without a product.
@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Bundle Size Report

Warning

Bundle budget exceeded — not a blocker, but please confirm the regression is intentional.

  • host-eager-path exceeded budget: 171988 B gzip > 168000 B
  • sandbox-eager-path exceeded budget: 105694 B gzip > 87000 B

Eager path (module entry + modulepreloaded chunks):

Path Raw Brotli Gzip
host/(eager path) 438.8 KB (+33.4 KB) 147.2 KB (+12.1 KB) 168.0 KB (+13.6 KB)
sandbox/(eager path) 316.8 KB (+77.8 KB) 89.2 KB (+21.0 KB) 103.2 KB (+24.3 KB)

Chunks over 500 KB:

File Raw Brotli Gzip
host/assets/bridge.js 815.2 KB (+717.1 KB) 178.2 KB (+156.4 KB) 228.9 KB (+202.4 KB)
host/assets/truapi_provider_bg.wasm 4.01 MB 955.7 KB 1.27 MB
host/assets/truapi_server_bg.wasm 4.46 MB (+1.78 MB) 1.23 MB (+531.8 KB) 1.66 MB (+743.3 KB)
host/assets/truapi_verifiable_bg.wasm 4.89 MB (+703 B) 4.61 MB (-9 B) 4.64 MB (+128 B)
sandbox/polkavm-runtime/THIRD_PARTY_LICENSES.txt 1009.4 KB 1009.4 KB 1009.4 KB
sandbox/polkavm-runtime/polkavm-browser-runtime.wasm 1.08 MB 187.7 KB 253.5 KB
Total 18.15 MB (+4.95 MB) 8.73 MB (+1.94 MB) (compression rate: 52%) 9.71 MB (+2.27 MB)
All files
File Raw Brotli Gzip
host/.well-known/apple-app-site-association 505 B 505 B 505 B
host/.well-known/assetlinks.json 2.1 KB 343 B 427 B
host/assets/AccountContent.js 2.0 KB (+426 B) 905 B (+73 B) 1.0 KB (+89 B)
host/assets/AuthModal.js 5.1 KB (-431 B) 2.0 KB (-238 B) 2.3 KB (-273 B)
host/assets/Chain.js 29.3 KB (+5.6 KB) 7.8 KB (+1.5 KB) 8.6 KB (+1.6 KB)
host/assets/ChainsContent.js 6.0 KB (-885 B) 2.2 KB (-283 B) 2.5 KB (-352 B)
host/assets/ChatDock.js 2.3 KB (+24 B) 1.1 KB (-4 B) 1.2 KB (+4 B)
host/assets/ChatPanel.js 21.8 KB (+1010 B) 6.7 KB (+370 B) 7.6 KB (+369 B)
host/assets/Dialog.js 1.1 KB 595 B 706 B
host/assets/Landing.js 7.1 KB (-301 B) 2.8 KB (-162 B) 3.3 KB (-241 B)
host/assets/LandingPage.js 2.0 KB (+117 B) 912 B (+43 B) 1023 B (+48 B)
host/assets/LoadingScreen.js 3.8 KB (-269 B) 1.5 KB (-205 B) 1.8 KB (-295 B)
host/assets/PermissionsContent.js 9.5 KB (+442 B) 2.7 KB (-42 B) 3.0 KB (-61 B)
host/assets/Popover.js 4.9 KB (-391 B) 1.9 KB (-121 B) 2.2 KB (-167 B)
host/assets/ProfileDrawer.js 3.7 KB 1.5 KB 1.7 KB
host/assets/SessionStore.js 53.2 KB 15.4 KB 18.9 KB
host/assets/SettingsContent.js 8.3 KB (+2.2 KB) 2.9 KB (+680 B) 3.4 KB (+780 B)
host/assets/ThemeToggle.js 9.5 KB (-378 B) 2.9 KB (-118 B) 3.3 KB (-112 B)
host/assets/Topbar.astro_astro_type_script_index_0_lang.js 591 B (-12 B) 591 B (-12 B) 591 B (-12 B)
host/assets/TopbarActions.js 9.9 KB (+167 B) 3.3 KB (+127 B) 3.7 KB (+133 B)
host/assets/TopbarReveal.js 831 B (-34 B) 831 B (-34 B) 831 B (-34 B)
host/assets/UrlPill.astro_astro_type_script_index_0_lang.js 526 B (-2 B) 526 B (-2 B) 526 B (-2 B)
host/assets/UrlPillShield.js 2.2 KB (-344 B) 956 B (-184 B) 1.0 KB (-187 B)
host/assets/VerificationContent.js 1.6 KB (-493 B) 533 B (-296 B) 632 B (-349 B)
host/assets/_md.js 1.6 KB (-2 B) 799 B (+1 B) 867 B (-1 B)
host/assets/_u64.js 768 B 768 B 768 B
host/assets/account.js 990 B (+194 B) 990 B (+194 B) 990 B (+194 B)
host/assets/active.CPsmhfHv.js 238 B 238 B 238 B
host/assets/app-roots.js 314 B (-37 B) 314 B (-37 B) 314 B (-37 B)
host/assets/auth-controller.js 5.1 KB (+70 B) 1.9 KB (-33 B) 2.2 KB (-24 B)
host/assets/auth.js 372 B (-17 B) 372 B (-17 B) 372 B (-17 B)
host/assets/base.js 4.6 KB 1.9 KB 2.0 KB
host/assets/blake2.js (×2) 12.7 KB (-480 B) 4.9 KB (-182 B) 5.6 KB (-180 B)
host/assets/block-watch.js 1.1 KB (+75 B) 566 B (+21 B) 642 B (+30 B)
host/assets/bridge.js 815.2 KB (+717.1 KB) 178.2 KB (+156.4 KB) 228.9 KB (+202.4 KB)
host/assets/browser.js 22.6 KB 7.4 KB (-1 B) 8.4 KB (-1 B)
host/assets/chain-sync.js 3.1 KB (+199 B) 1.2 KB (+41 B) 1.4 KB (+91 B)
host/assets/chat-panel.js 2.7 KB (-18 B) 1.0 KB (-5 B) 1.1 KB (-10 B)
host/assets/cid-cache.js 3.1 KB (+651 B) 1.0 KB (+43 B) 1.2 KB (+56 B)
host/assets/client.js (×2) 13.2 KB (+1.1 KB) 4.5 KB (+256 B) 5.1 KB (+318 B)
host/assets/create-popover.js 4.6 KB 1.6 KB (+1 B) 1.8 KB
host/assets/create-store.js 106.1 KB (-872 B) 31.7 KB (-271 B) 35.5 KB (-293 B)
host/assets/db.js 1.9 KB (-281 B) 683 B (-113 B) 797 B (-127 B)
host/assets/device.js 235 B 235 B 235 B
host/assets/dist.js 65 B 65 B 65 B
host/assets/dotli-debug-bus.js (×2) 1.1 KB (+367 B) 1.1 KB (+367 B) 1.1 KB (+367 B)
host/assets/drag.js 430 B 430 B 430 B
host/assets/errors.js (×2) 3.1 KB (-369 B) 1.6 KB (-323 B) 1.7 KB (-322 B)
host/assets/fetch.js 64.6 KB (-195 B) 16.7 KB (-23 B) 19.2 KB (-60 B)
host/assets/focus.js 1.0 KB 435 B 534 B
host/assets/hex.js 160 B 160 B 160 B
host/assets/html.js 574 B 574 B 574 B
host/assets/idle.js 323 B 323 B 323 B
host/assets/index.css 70.9 KB (+53.7 KB) 11.3 KB (+7.8 KB) 13.1 KB (+9.1 KB)
host/assets/index.astro_astro_type_script_index_0_lang.js 42.3 KB (-295 B) 13.5 KB (+9 B) 15.0 KB (+28 B)
host/assets/ipfs.js 743 B (-211 B) 743 B (-211 B) 743 B (-211 B)
host/assets/lazy.js (×2) 1.4 KB (-9.8 KB) 1.4 KB (-2.6 KB) 1.4 KB (-3.1 KB)
host/assets/loading.js 242 B (-10 B) 242 B (-10 B) 242 B (-10 B)
host/assets/log.js 3.8 KB (+2.2 KB) 1.5 KB (+866 B) 1.7 KB (+959 B)
host/assets/manifest-types.js 7.1 KB (+3.4 KB) 2.2 KB (+1.0 KB) 2.4 KB (+1.1 KB)
host/assets/mode.js 2.0 KB (+193 B) 713 B (+71 B) 787 B (+85 B)
host/assets/mount.js (×2) 146.1 KB (+28.1 KB) 41.2 KB (+7.6 KB) 47.5 KB (+8.7 KB)
host/assets/mount.css 22.8 KB (-1.0 KB) 4.7 KB (-417 B) 5.3 KB (-576 B)
host/assets/network.js (×2) 6.5 KB (+339 B) 2.5 KB (+146 B) 2.9 KB (+159 B)
host/assets/overlay-root.js 179 B 179 B 179 B
host/assets/perf.js 148 B 148 B 148 B
host/assets/permission-changes.js 342 B 342 B 342 B
host/assets/permissions.js (×2) 2.5 KB (+261 B) 1.0 KB (+59 B) 1.2 KB (+81 B)
host/assets/preload-helper.js 1.3 KB 606 B 731 B
host/assets/product-frame-layout.js 1.2 KB 536 B (-9 B) 603 B (-1 B)
host/assets/product.js 412 B (-10 B) 412 B (-10 B) 412 B (-10 B)
host/assets/profile-record.js 8.4 KB 3.6 KB 3.9 KB
host/assets/proofs.js 26.0 KB 7.5 KB (-8 B) 8.3 KB (+1 B)
host/assets/provider.js 22.2 KB (-11 B) 5.9 KB (-15 B) 6.7 KB (-25 B)
host/assets/recent-labels.js 4.9 KB (-25 B) 2.1 KB (-46 B) 2.4 KB (-51 B)
host/assets/resolve.js 4.1 KB (-458 B) 1.6 KB (-192 B) 1.7 KB (-234 B)
host/assets/rolldown-runtime.js 898 B (+182 B) 898 B (+182 B) 898 B (+182 B)
host/assets/root.js 441 B (-36 B) 441 B (-36 B) 441 B (-36 B)
host/assets/rpc-chain.js 28.9 KB 9.3 KB (+3 B) 10.2 KB (+3 B)
host/assets/rpc-resolve.js 2.8 KB (+540 B) 1.1 KB (+179 B) 1.3 KB (+194 B)
host/assets/runtime-config.js 13.0 KB (+8.2 KB) 4.5 KB (+3.0 KB) 5.0 KB (+3.2 KB)
host/assets/scale-ts.js 4.8 KB 1.9 KB 2.1 KB
host/assets/scale.js 1.6 KB (-559 B) 740 B (-259 B) 849 B (-277 B)
host/assets/scheduled-notifications.js 8.8 KB 3.0 KB 3.3 KB
host/assets/seity.DvANEjoc.js 22.7 KB 7.4 KB 8.2 KB
host/assets/settings-actions.js 10.4 KB 3.8 KB 4.2 KB
host/assets/settings.js 399 B (+48 B) 399 B (+48 B) 399 B (+48 B)
host/assets/sha2.js 1.9 KB 968 B 1.1 KB
host/assets/shared-mode.js (×2) 2.0 KB (+152 B) 968 B (+121 B) 1.0 KB (+124 B)
host/assets/solid.js 48.0 KB 16.5 KB 18.0 KB
host/assets/spans.js 741 B (-24 B) 741 B (-24 B) 741 B (-24 B)
host/assets/src.js 79.9 KB (+32 B) 25.1 KB (+59 B) 27.8 KB (+17 B)
host/assets/theme-controller.js 801 B (-8 B) 801 B (-8 B) 801 B (-8 B)
host/assets/toasts.js 4.4 KB (-20 B) 1.6 KB (-13 B) 1.8 KB (-11 B)
host/assets/topbar.CCuKK--C.js 2.3 KB 950 B 1.1 KB
host/assets/topbar.Bq-n4Klp.js 196 B 196 B 196 B
host/assets/topbar.js 620 B (-9 B) 620 B (-9 B) 620 B (-9 B)
host/assets/truapi_provider_bg.wasm 4.01 MB 955.7 KB 1.27 MB
host/assets/truapi_server_bg.wasm 4.46 MB (+1.78 MB) 1.23 MB (+531.8 KB) 1.66 MB (+743.3 KB)
host/assets/truapi_verifiable.js 14.3 KB 2.8 KB 3.2 KB
host/assets/truapi_verifiable_bg.wasm 4.89 MB (+703 B) 4.61 MB (-9 B) 4.64 MB (+128 B)
host/assets/twoX.js 8.5 KB 3.0 KB (+1 B) 3.3 KB
host/assets/ui.js 4.1 KB (-67 B) 1.4 KB (-98 B) 1.6 KB (-76 B)
host/assets/url-pill.js 371 B (-11 B) 371 B (-11 B) 371 B (-11 B)
host/assets/use-store.js 368 B 368 B 368 B
host/assets/utils.js 3.5 KB 1.4 KB 1.5 KB
host/assets/verification-glyphs.js 259 B 259 B 259 B
host/assets/verify.js (×2) 12.7 KB (-2.2 KB) 4.3 KB (-972 B) 4.7 KB (-1.3 KB)
host/assets/web.js 24.9 KB (-24.6 KB) 8.1 KB (-6.5 KB) 8.9 KB (-7.3 KB)
host/assets/worker-runtime.js 53.3 KB (-18.8 KB) 12.0 KB (-5.4 KB) 13.7 KB (-6.0 KB)
host/dotli.png 11.5 KB 11.5 KB 11.5 KB
host/favicon.svg 1.8 KB 1.8 KB 1.8 KB
host/host-sw.js 7.4 KB (-328 B) 2.1 KB (-20 B) 2.4 KB (-30 B)
host/host_version.json 109 B 109 B 109 B
host/icon-192.png 12.5 KB 12.5 KB 12.5 KB
host/icon-512.png 42.8 KB 42.8 KB 42.8 KB
host/index.html 33.4 KB (-7.4 KB) 9.1 KB (-2.0 KB) 10.8 KB (-2.3 KB)
host/manifest.webmanifest 441 B 441 B 441 B
host/workbox.js 14.8 KB 4.6 KB 5.1 KB
sandbox/app-sw.js 6.0 KB (+919 B) 2.2 KB (+268 B) 2.5 KB (+308 B)
sandbox/assets/bitswap-bridge.js 1.0 KB (-141 B) 559 B (-25 B) 620 B (-52 B)
sandbox/assets/fetch.js 3.7 KB (-344 B) 1.3 KB (-89 B) 1.5 KB (-87 B)
sandbox/assets/index.css 70.9 KB (+66.0 KB) 11.3 KB (+10.0 KB) 13.1 KB (+11.5 KB)
sandbox/assets/index.js 313.1 KB (+78.1 KB) 87.8 KB (+21.1 KB) 102.0 KB (+24.4 KB)
sandbox/assets/mount.js 55.4 KB (+1.0 KB) 18.7 KB (+257 B) 20.5 KB (+288 B)
sandbox/favicon.svg 1.8 KB 1.8 KB 1.8 KB
sandbox/host_version.json 108 B 108 B 108 B
sandbox/index.html 2.6 KB (+1010 B) 776 B (+376 B) 1.0 KB (+442 B)
sandbox/polkavm-runtime/LICENSE-MPL-2.0 16.3 KB 16.3 KB 16.3 KB
sandbox/polkavm-runtime/SHA256SUMS 1.2 KB 1.2 KB 1.2 KB
sandbox/polkavm-runtime/SOURCE.json 507 B 507 B 507 B
sandbox/polkavm-runtime/THIRD_PARTY_LICENSES.txt 1009.4 KB 1009.4 KB 1009.4 KB
sandbox/polkavm-runtime/THIRD_PARTY_NOTICES.md 8.7 KB 8.7 KB 8.7 KB
sandbox/polkavm-runtime/polkavm-browser-runtime.wasm 1.08 MB 187.7 KB 253.5 KB
sandbox/polkavm-runtime/polkavm-gpu-worker.js 67.5 KB 11.5 KB 13.4 KB
sandbox/polkavm-runtime/polkavm-worker.js 117.1 KB 18.6 KB 22.6 KB
Total 18.15 MB (+4.95 MB) 8.73 MB (+1.94 MB) (compression rate: 52%) 9.71 MB (+2.27 MB)

Commit: 810ca70

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

⚡ Performance Report

Cold Start

Overall: 🟢 improved  |  p50: 11.91s → 8.87s (-25.5%)  |  p95: 13.31s → 9.28s (-30.3%)  |  Mann-Whitney: z=4.40 ✅ significant

Phase breakdown
Phase Base p50 PR p50 p50 Δ Base p95 PR p95 p95 Δ Verdict
End-to-end 11.91s 8.87s -3043ms (-25.5%) 13.31s 9.28s -4031ms (-30.3%) 🟢 improved
Host total 8.38s 6.60s -1779ms (-21.2%) 9.37s 6.96s -2412ms (-25.7%) 🟢 improved
Name resolution 8.18s 6.15s -2034ms (-24.9%) 9.13s 6.57s -2565ms (-28.1%) 🟢 improved
App total 2.98s 2.22s -766ms (-25.7%) 4.25s 2.51s -1740ms (-40.9%) 🟢 improved

Warm Start

Overall: 🔴 regressed  |  p50: 406ms → 6.24s (+1436.9%)  |  p95: 451ms → 6.57s (+1357.0%)  |  Mann-Whitney: z=4.40 ✅ significant

Phase breakdown
Phase Base p50 PR p50 p50 Δ Base p95 PR p95 p95 Δ Verdict
End-to-end 406ms 6.24s +5.83s (+1436.9%) 451ms 6.57s +6.12s (+1357.0%) 🔴 regressed
Host total 127ms 5.91s +5.78s (+4553.5%) 156ms 6.24s +6.09s (+3901.9%) 🔴 regressed
Name resolution — 5.74s new — — — —
App total 259ms 297ms +38ms (+14.7%) 276ms 306ms +30ms (+10.9%) 🔴 regressed

Lukewarm Start (different site, same session)

Overall: 🟢 improved  |  p50: 13.92s → 10.74s (-22.8%)  |  p95: 14.86s → 11.30s (-23.9%)  |  Mann-Whitney: z=4.40 ✅ significant

Phase breakdown
Phase Base p50 PR p50 p50 Δ Base p95 PR p95 p95 Δ Verdict
End-to-end 13.92s 10.74s -3180ms (-22.8%) 14.86s 11.30s -3551ms (-23.9%) 🟢 improved
Host total 9.37s 7.06s -2315ms (-24.7%) 10.53s 7.66s -2872ms (-27.3%) 🟢 improved
Name resolution 7.53s 5.41s -2116ms (-28.1%) 8.51s 6.08s -2426ms (-28.5%) 🟢 improved
App total 4.20s 3.36s -838ms (-20.0%) 5.08s 4.13s -946ms (-18.6%) 🟢 improved

Commit: 810ca70  |  Outliers (>2x best) discarded before stats

@replghost replghost added the deploy: paseo.fyi Deploy this pull request to paseo.fyi label Sep 26, 2026
corey-hathaway and others added 4 commits September 26, 2026 14:28
…d record, mood ring

A `seity-contacts:v1:<lookupKey><seed>` reference names a registry slot, not
a blob, so it stays the same while the profile behind it changes. The drawer
now resolves one: read the slot from Seity's registry through raw contract
storage (no runtime call), fetch and open the sealed record through the host
preimage path, then fetch the avatar the record names as before. A bare
`cid#key` reference keeps its existing path.

The record's mood is drawn as a ring around the avatar (one WebGL program,
static fallback, still under reduced motion) and lapses after its TTL.

Pinned by Seity profile-core's contacts vector and by the registry's own
storage-layout test.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The host page does not own a light client; the protocol worker does, and
the host reaches it by request, as name resolution already does. Add
`resolveSeitySlot` beside `resolveOwner` (client proxy, iframe and shared
worker handlers, request map, timeout) and have the drawer use it. The
slot version crosses as a decimal string.

Log why a drawer load failed (name and message only; nothing on that
path carries the reference), which is how this was found.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ust-core cbh/seity-contacts)

Rebuild `vendor/truapi` and `vendor/truapi-host` from host-rust-core
`298cf4286` (on #1001): `profile.disclose` / `retract` / `presentContact`,
the Chat v2 profile relay, and the `ProfileDisclosure` and
`ProfileReferencesReceived` core-storage slots. The web WASM keeps the
signing host (`--no-default-features --features wasm-signing-host`); the
lock carries the archive, client and WASM hashes of this build.

Host storage policy for the two new slots: generation-scoped in private
custody, their own local-storage keys (received references per chat
product), and encrypted at rest as secret material, since both hold
bearer capabilities.

`turbo run typecheck lint test`: 39/39.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The vendored host is built from cbh/seity-contacts, which is #1009 (stacked
on #1001).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ust-core#1001)

Packs @parity/truapi and @parity/truapi-host at dcd38a0b: the Profile
service moves from trait 20 to 22, clear of Contacts (#17) and Game (#990).
Includes the Seity contacts methods folded in from #1009.
WebCrypto and the envelope decode run outside the fake clock, so a fixed
number of timer advances raced them under CI load. Poll with vi.waitFor,
which advances the fake timers per check and yields real time between.
replghost added a commit that referenced this pull request Sep 27, 2026
Forward browser #255 and refresh native vendor packages from #1001 at bd55ec2af4b5db75afaf827404f63d11f6881a02.
# Conflicts:
#	README.md
#	packages/ui/src/components/overlays/SigningDialog.tsx
#	packages/ui/src/host-callbacks/Contacts.ts
#	packages/ui/src/styles/signing.css

This branch had an error being deployed

1 failed (outdated) deployment
paseo.fyi — 7dad5e68 Deployed Sep 26, 2026 by replghost via Deploy paseo.fyi #1391
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants