Conversation
Add the `profile` service. `profile.present({ reference })` asks the
host to show a profile the product holds a reference to. The host
resolves, decrypts and renders it in its own UI, so profile bytes and the
reference's key never return to the product; the call resolves once the
presentation is shown.
Hosts opt in through `ProfilePlatform`, a new optional trait on
`OptionalPlatform`, so codegen emits the dispatcher and the optional
`profile` callback group. The browser and Web Worker hosts install it;
native hosts and the CLI answer `Unsupported`.
The call is served by the local product runtime, not the Chat authority:
in pairing mode Chat operations run on the paired wallet, and a profile
must appear where the product is on screen. The core screens only the
reference's shape (non-empty, at most 2048 bytes, printable ASCII without
whitespace); parsing the format is the host's.
Contributor
|
CI Status: 24 required jobs green, 21 passed and 3 skipped by path filter. All job results
Signing credentials: failure as of 2026-10-02, a release may fail Commit |
Contributor
iOS simulator previewBuilt from gh run download 36743632311 --name simulator-preview-3d057d5de
unzip polkadot-app-*.app.zip
xcrun simctl install booted polkadot-app.app
xcrun simctl launch booted io.parity.polkadotapp.developOr download it in a browser, which arrives as a zip wrapping An arm64 simulator slice, so it needs an Apple Silicon Mac and does not |
…s by name
On top of `profile.present`:
- `disclose({ reference })` (method 1, App only) stores the user's own
reference with the product that disclosed it; `retract()` (2) withdraws
it, and only the discloser may.
- `presentContact({ peerIdentity })` (3) names a chat contact; the host
looks up the reference that contact's host sent and hands it to the
existing `ProfilePlatform::present_profile`. The product never holds a
contact's reference, so it cannot read, keep, forward or substitute it.
Both kinds of reference live in core storage: `ProfileDisclosure`
(wallet-owned) and `ProfileReferencesReceived { product_id }` (cleared with
the chat product, like its roster). The chat relay that fills the latter
comes next; its write helper is here and tested.
The CLI installs a presenter that records each presentation to
`TRUAPI_PROFILE_LOG` as a SHA-256 and format prefix, never the reference.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The Chat v2 half of profile disclosure, built on the actor's host-private
outbox that payments and rich files already use:
- Wire: `ProfileReference { discloser_product_id, reference: Option }` at
V2 content index 21 (a new shared wire index; needs agreeing with native
Chat before it ships).
- Send: `publish_profile_reference`, run on Initialize, seals one message
per ready peer whose watermark differs from the user's disclosure, as an
`OutgoingKind::ProfileReference` the product submits as opaque ciphertext.
The watermark (trailing `profile_shared`, absent from older snapshots)
advances at queue time; a withdrawal is sent to peers that hold one.
- Receive: the frame is classified and screened, stored per peer in
`ProfileReferencesReceived` for the chat product, and cut from the opened
plaintext (forcing a re-encode), so the product never sees it. Only live
frames update it, never compacted history. Products cannot prepare one.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The RFC for `disclose` / `retract` / `presentContact` and the Chat v2 relay on the host-private outbox, unnumbered and in draft. Its open questions are the known gaps of the prototype: the content-type index, several disclosing products, consent, other devices, reconcile timing, and where references are resolved. Each gap is also marked where it lives in the code. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Merged
peer_identity is [u8; 32], which the TypeScript client types as a 0x-prefixed hex string, so the generated playground example failed tsc.
replghost
added a commit
that referenced
this pull request
Sep 27, 2026
replghost
added a commit
that referenced
this pull request
Sep 27, 2026
replghost
added a commit
that referenced
this pull request
Sep 27, 2026
- Queue profile references best effort. They have their own outbox budget, one per peer, so they neither crowd out nor are blocked by other Chat traffic; a reference with no room waits for a later reconcile instead of failing Chat Initialize. - Drop an unacknowledged reference after one statement lifetime instead of re-signing it forever; a peer that predates content index 21 never acknowledges it. The watermark stays, so it is not resent until the disclosure changes. - Order received references by frame timestamp. Withdrawals are kept as rows and a frame that is not strictly newer is ignored, so an older disclosure opened after its withdrawal cannot restore it. Senders stamp each frame to a peer later than the last and give it a fresh request id. - Scope ProfileDisclosure and ProfileReferencesReceived to the wallet root key and Chat network, like the Chat roster. Profile calls with no one signed in answer NotConnected. - Ask once per product before disclose stores anything, through a new ProfileDisclosure confirmation review and permission; a refusal is PermissionDenied. - Correct the changeset: the relay is part of this change.
replghost
added a commit
that referenced
this pull request
Sep 28, 2026
# Conflicts: # rust/crates/truapi-client/src/generated.rs
Add `profile.placeContactAvatars` (Profile method 4). A chat App tells the host where it draws contacts' avatars: its surface size and, per avatar, a slot id, the contact's peer identity, a square rect and the clip it is cut to. The host draws each sharing contact's photo and mood ring there on its own layer; taps still reach the product. - The core keeps only slots whose contact holds a current reference in the caller's ProfileReferencesReceived and hands them, with those references, to the new ProfilePlatform::place_contact_avatars. Its default draws nothing. - The answer never depends on who shared: any well-formed placement from a signed-in App is Ok, a host drawing failure is not reported, and nothing about slots is logged. Only the host's own Unsupported is passed on. More than 64 slots, a surface side outside 1..=16384, a non-square avatar or one outside 1..=1024 a side, and repeated slot ids are refused as Unknown. - The last placement is kept per product connection. A received reference or withdrawal that changes storage redraws it with the same geometry; disposing the connection, or placing after sign-out, clears what the host drew.
replghost
added a commit
that referenced
this pull request
Sep 28, 2026
# Conflicts: # rust/crates/truapi-client/src/generated.rs # rust/crates/truapi/src/lib.rs
…layout Snapshots written before 571f348 end with watermarks that carry no frame timestamp or withdrawal marker, and no longer decoded, which paused Chat setup with StorageUnavailable. The trailing list now decodes in either layout. Legacy watermarks are dropped: contacts kept those references under a slot the host no longer reads, so the next reconcile sends every contact the disclosure again.
Contributor
|
This pull request touches an app, which is not built by default. Add a label for each build you want:
Each starts as soon as it is added and follows the branch from then on. |
# Conflicts: # js/packages/truapi-host/README.md
# Conflicts: # rust/crates/truapi-client/src/generated.rs # rust/crates/truapi/src/v02.rs
# Conflicts: # rust/crates/truapi-client/src/generated.rs
replghost
added a commit
that referenced
this pull request
Oct 3, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Current repair qualification — 2026-10-02
3a364f1157177f7d1ae4839241488d5c9276ed1d. Canonical seity artifact-generation and Wasm revisions are this same commit. Prior main-integration baselines are retained: nativebda6ac518c8cc59319491b12e4e23b96777375fd, frontendf4012c50c3400d1186c332ad2ae50298cefd153d.bdb7e068e1d2925e38dc9f7f5222536ddd5d07a8. Complete matching SDK/host packages remain 0.23.0; codegen and Wasm were rebuilt canonically. Generated client bytes are unchanged. Production features:wasm-signing-host; separate testing bundle:wasm-signing-host,test-host.5442571f6770f05d97a1ed3c3a0ab96ca1df7c15d77ee168130d53853523db2ddist/generated/client.js02e193761518364624e9dd53a41dd7cbddf4b5d8482f3e93489b51edd05766304442b38a45f987e38dfe1df98f04b57c4de90add4b1c182793556efdedc12edbd7934abc194e9ab30679498426ece50e331eefaa22e6ba830e2b4667b978761618cd9daa1b4d0ad970e968fed708bf3b310dc853c56f2545939aba54d9fba100Native correction and causal limits
Bulletin mortal signatures now anchor to a finalized checkpoint, while nonce/runtime state comes from the freshest available signing snapshot. A checkpoint at least 64 blocks behind is rejected before broadcast. Regression coverage verifies the actual signature with a newer nonce and older finalized checkpoint, and the expiry boundary. Existing transaction retries/deadlines are unchanged; no chain error is suppressed. The affected test fixture uses
parking_lot::Mutex.The former Seity
Extrinsic marked as invalidrun used noncanonical best-block anchors, but retained evidence lacks the signed bytes and typed pool reason. Fork-sensitive mortality was a real correctness hazard; it is not claimed as the conclusively proved cause of that historical failure. Prior hosted Factory/Genesis timeout causes also remain unproved. No broker/readiness workaround, prewarming, extra retry, or timeout increase was added.Executed verification
-D warnings, CLI build, and canonical browser/testing Wasm packaging. Base full library: 1,246 passed.0a24db4aa189adad7b93f9ff508c7949e39196ee301a235ba13248ef4281e9e3d859919fb6cfbe06d3dc8a41807c36b8bcdf001c47eccb9735305499The Chat/Seity tested heads above precede documentation-only formatting merges; their native/Wasm pins and runtime code are unchanged. Final hosted frontend results are recorded on the linked consumer PRs, separately from these exact-head local results.
Final hosted retest: failures remain
error; it is not evidence of a chain rejection. Retained traces include People-chain/local development sockets but do not expose the Asset Hub gateway WebSocket exchange, so these new failures do not establish an upstream or broker cause.paseo-bulletin-next-ipfs.polkadot.io. The zero-failure host-settings gate correctly failed.Doom: criterion corrected, backend matrix still unqualified
The user explicitly approved 35 FPS sustained over 30 seconds, with one frame of sampling-boundary tolerance:
frames + 1 >= elapsedMs * 35 / 1000. This replaces the instantaneousFPS >= 35sample; it is an acceptance-criterion change, not a runtime speedup. Runtime and displayed FPS are unchanged; raw samples are not rounded to force a pass. Update p95 <28.6ms, cold/warm first-frame limits <3,000/<1,000ms, audio and translation-cache checks remain. The revised official RPC benchmark passed once before the vendor replacement.The later isolated matrix used the rebuilt base pair at frontend
238ab5fa739788b2eb948ba1f807a1876edbacad, with fresh owned Chrome profiles and no concurrent builds/E2E:Distinct diagnostics found no presentation loss in a later instrumented 24-second shared-worker sample and observed a successful hidden RPC new-document reload. Neither diagnostic supersedes the failures or qualifies performance. No evidence-proved runtime fix, guest rebuild, speculative tuning, or further unchanged gate rerun was made. The original strict RPC failure and every new failure remain retained. Next causal capture must instrument the original early 30-second window and distinguish warm lifecycle states before proposing a runtime fix.
Retention and rollout boundary
Local verification used
paseo-next-v2, the pinned host-playground fixturef56294cea4430163bf16ec068844b1327441073c, and existing private QA identities. All three corrected sequences paired on their first existing setup attempt. A prior local launch failure and a misconfigured Previewnet-product run (34 passed, 20 skipped, 8 Chain/Contract failures) are retained separately, not presented as reproductions of the hosted Genesis timeout. Private traces/auth/signers were not published.The first repair heads also exposed a README formatting failure (corrected by documentation-only commits) and a PVM cache-unit-test 5,000ms timeout. No cache runtime/test change, limit increase, or causal claim was made for that isolated timeout. Older in-flight runs superseded by the formatting correction remain recorded as cancelled, not passed.
No PR merge, force push, deployment, environment approval, SDK/npm/product/guest publication, or rollback was performed by this repair. JAM remains JAM-TEST-INSTANCE, never JAM-PUBLIC-DEVNET. The user-owned
deploy: paseo.fyilabel is retained; repair-triggered deployment runs 36970790399 and 36971286469 were cancelled before deployment. The earlier rollout audit is retained below: an older workflow deployed56cea5d37577bf82684fb5c6b6e4ba81d2142938; this record does not claim live remained unchanged historically.Historical integration qualification (superseded; retained verbatim)
Current main refresh and qualification — 2026-10-01
94f597becce31682a374e4aabc546e4a9ad61103. Native mainbda6ac518c8cc59319491b12e4e23b96777375fdis integrated; the frontend stack includes dotli mainf4012c50c3400d1186c332ad2ae50298cefd153d(merged chore(deps): bump postcss from 8.5.15 to 8.5.23 in /explorer #313). Histories and worktrees were preserved; pushes used fetched-head ancestry guards, never force.978b7d3e46b92d8983e733a3f39b2862968d0ef5. Later native changes are test/docs/iOS-only, not SDK/Wasm inputs, so the artifact pin intentionally differs from the current head. Complete matching client and host packages remain 0.23.0, generated rather than hand-edited. Browser signing Wasm usesweb-wasm-signing-hostwithouttest-host; testing Wasm is separate.b03e83616857f4e4745d479776dde43cdfa6267a.5442571f6770f05d97a1ed3c3a0ab96ca1df7c15d77ee168130d53853523db2ddist/generated/client.js(notdist/index.js)02e193761518364624e9dd53a41dd7cbddf4b5d8482f3e93489b51edd05766308bd67c12ee9303c802b94d7b65c4c800c5cbe338a78311cb6786270a0c06ca63c47f65213982969e4a42ae02fdf08ae621fc50fcfc30f3feb74a5878260bed63Qualification
Frontend #287 exact-head Tests: functional 89 passed, 3 skipped; E2E 41 passed, 1 flaky, 20 skipped. Hosted E2E retained one flaky Chain → Chain Spec: Genesis Hash case: it failed on the first attempt and passed the existing CI retry. No retry setting was changed.
Current-head Core CI: 24 required jobs green — 22 passed, 2 path-filter skips. This includes core Swift/Android coverage, not a claim that full iOS application CI ran at this head. The separate existing release-signing-credentials advisory failure remains distinct from Core CI.
Local: Rust workspace: 2,253 passed across 34 suites, 24 ignored. Client/host SDK: 290/326 passed; local Swift and Android qualification passed. Canonical codegen and complete feature-specific package construction were qualified locally.
Browser/native proof: Real encrypted-content lifecycle passed: an 82-byte AES-256-GCM test ciphertext was submitted on Paseo, retrieved from Bulletin through the production profile loader, decrypted to the exact nonpersonal 1×1 PNG, and displayed. Closing revoked its blob URL; reopening created a new blob and exactly one drawer. This is not a full registered-user profile/contact-sharing round trip. Evidence:
main-refresh-seity-live.jsonand screenshot.Retained cross-stack limits
Extrinsic marked as invalid). Two existing native broadcast attempts were validated then invalidated; none was found included in the inspected canonical range. [INFERENCE] Noncanonical mortality anchors may explain invalidation; the exact cause is not established and signed extrinsic bytes were not retained. The earlier Factory deadline failure is also retained: inclusion took 47,516ms against the unchanged 30s product deadline. A separate unchanged manual Factory attempt passed in 10.918s. These failures are not erased by other passing checks..authcontents are included here.This refresh authorizes no deployment, environment approval, PR merge, SDK/npm publication, or guest/product publication. Its QA writes were testnet-only.
All three refresh-triggered JAM Deploy runs were cancelled before rollout; final-head cancellation proof is for frontend
dcdef40499119183aed82a39f784ef740d494341. No refreshed source head was deployed.The live environment changed during qualification: older Deploy run 36945647296, attempt 3 was approved under GitHub account
replghost, explicitly checked out baseline56cea5d37577bf82684fb5c6b6e4ba81d2142938, and recorded deployment success at 2026-10-02 01:19:01 UTC. Its later published-product smoke failed. The operator/client/session behind that account is unproven; this qualification granted no approval and performed no rollback. The observed live content hash changed from4a7caf047fb7f350c1833039b93ba634698a47c56f051b8c7fc0525d4c59a5c8to5882695ee20df5d24a6ed2feb9e997f176fe27ecf4eafe742fabb39eba92885f; these are content hashes, not Git SHAs, and their exact byte-level mapping to a source commit is unproven. Earlier revision/deployment records below remain historical evidence and do not override this current section.Earlier source and qualification (superseded)
Head
3d057d5de00751ff6c882c301434e64cb88f4930includes mainaa6ae62ca038bf4a6356edae8eb78e595d52ce24through history-preserving merge commits. Client and host package manifests remain 0.23.0 with pending Changesets.The branch includes the integrated main changes and preserves its feature boundary. Root and combined-stack canonical codegen and TypeScript qualification pass. This branch’s current-head Codegen CI job passes; its downloaded canonical output matches all 45 tracked generated files byte-for-byte. Full workspace/native qualification remains tracked by current-head CI.
Current-head core CI passes, including Rust workspace, default WASM bridge, Android compile/unit checks, and iOS Swift + WebKit. Full local workspace/native qualification was interrupted by workstation disk exhaustion; the full current-head core CI gate completes that qualification. Full iOS application CI also passes, including the in-tree core, application build, simulator preview, and tests. No PR was merged or approved, and no npm package was published. Deployment evidence below belongs to the explicitly named earlier revisions, not this source refresh.
Seity layer on top of #709.
Adds the
profileservice:profile.present({ reference })asks the host to show a profile the product holds a reference to (a Seity<cid>#<key><iv>blob reference today). The host fetches, decrypts and renders it in its own UI; profile bytes and the reference's key never return to the product. The call resolves once the presentation is shown.Profile(trait id 69) exposespresent,disclose,retract,presentContact,placeContactAvatars,ownStatus, andpresentOwnat method IDs 0 through 6. Thepresentrequest'sDebugredacts its reference.ChatApps,App, and selectedContactsaudiences; V2 contact presentation accepts a peer or opaque Contacts handle. V3 avatar placement adds the same selectors alongside the own-profile slot while preserving V1/V2 placement compatibility. Profile contents and references remain host-owned.ProfilePlatformcallbacks onOptionalPlatform, emitted by codegen. Browser and Web Worker hosts install them; native hosts and the CLI do not provide profile presentation.Integration and qualification
Based on #709, with main through
c5158448f3c4575f40350017d466053d6b19dacb. The profile service uses the unifiedtruapiruntime and canonical codegen catalog; UniFFI callbacks remain native-only.Refreshed TrUAPI client/host 0.23.0 and wallet/testing WASM artifacts are built from
f031658066d19e85b829aa786dad682e22b41197; consumer integration and exact archive/client/WASM digests are tracked in paritytech/dotli-community#287 and its vendor lock. They include V2 audience/contact-selector and V3 avatar-placement APIs, host-private Contacts integration, and the integrated Chat privacy and settlement fixes. The user explicitly selected rollout of the newer sharing contract on experimental paseo.fyi. Branch CI and deployed qualification remain separate; the current combined deployment is qualified below, without claiming live sharing coverage.Current local qualification passes canonical code generation, TypeScript client/host builds, release wallet/testing WASM builds, 1,492 core library tests, and all-target/all-feature TrUAPI Clippy with
-D warnings. The merge retains both private rich-frame removal and host-owned Profile-reference stripping before plaintext reaches the product.Core CI and the full iOS build, app tests, and preview pass at
f031658066d19e85b829aa786dad682e22b41197. The consumer's checks pass. A real browser/live-port smoke on combined paritytech/dotli-community#291 decoded the Profile domain rejection for a malformed reference; that smoke coveredpresent, not the new own-profile methods or a live Seity avatar-fetch scenario.All-target/all-feature
truapiclippy with-D warningsand seven avatar regression tests pass. The V1 response conversion still executes before the unit response is wrapped; no lint suppression or protocol shortcut is used.The iOS combined store uses model 53, retaining both historical main and Chat model-49 variants. Real SQLite migration smoke checks passed from main model 49, Chat model 49, and main model 52, preserving payment amounts, owner identity, and native Coinage ledger payloads. The permanent migration regression runs in the app suite. This iOS-only correction does not change the vendored browser SDK artifacts.
The iOS test lane retains xcresult, raw build/simulator logs, and available crash reports regardless of debug mode. Ruby syntax, workflow lint, and diagnostic export from a real retained simulator result pass. An earlier run reported 358 failures without retaining its result or crash diagnostics, so its cause is not established. The current complete iOS run passes; tests, retry behavior, and parallelism settings are unchanged.
The user-approved paseo.fyi deployment at
032e97128983570eac9c32d6cd9dd8a41d181bca, with combined host sourceaf087f734be4d65d9363e68e43bf134145ae0085, passes all eight published PolkaVM product scenarios and all 19 wallet-free TrUAPI capability checks. Product smoke opts in through real Settings; the production execution gate remains default-off. Independent fresh-context Chromium verification observed that exact release and passed feature discovery, JSON storage round-trip, and a live chain-genesis query. This does not qualify live Profile/Contacts/avatar-sharing, own-profile/avatar-fetch, or a new JAM-validator transport trial.