Skip to content

feat(truapi): show product-referenced profiles in host UI - #1001

Draft
replghost wants to merge 77 commits into
feat/chat-v2-product-authorityfrom
feat/chat-seity-profile
Draft

replghost wants to merge 77 commits into
feat/chat-v2-product-authorityfrom
feat/chat-seity-profile

Conversation

@replghost

@replghost replghost commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Current repair qualification — 2026-10-02

  • Current source: 3a364f1157177f7d1ae4839241488d5c9276ed1d. Canonical seity artifact-generation and Wasm revisions are this same commit. Prior main-integration baselines are retained: native bda6ac518c8cc59319491b12e4e23b96777375fd, frontend f4012c50c3400d1186c332ad2ae50298cefd153d.
  • Consumers: dotli #287 at bdb7e068e1d2925e38dc9f7f5222536ddd5d07a8. Complete matching SDK/host packages remain 0.23.0; codegen and Wasm were rebuilt canonically. Generated client bytes are unchanged. Production features: wasm-signing-host; separate testing bundle: wasm-signing-host,test-host.
Canonical artifact SHA-256
Client npm archive 5442571f6770f05d97a1ed3c3a0ab96ca1df7c15d77ee168130d53853523db2d
Client dist/generated/client.js 02e193761518364624e9dd53a41dd7cbddf4b5d8482f3e93489b51edd0576630
Host npm archive 4442b38a45f987e38dfe1df98f04b57c4de90add4b1c182793556efdedc12edb
Browser signing Wasm d7934abc194e9ab30679498426ece50e331eefaa22e6ba830e2b4667b9787616
Local QA CLI 18cd9daa1b4d0ad970e968fed708bf3b310dc853c56f2545939aba54d9fba100

Native correction and causal limits

Bulletin mortal signatures now anchor to a finalized checkpoint, while nonce/runtime state comes from the freshest available signing snapshot. A checkpoint at least 64 blocks behind is rejected before broadcast. Regression coverage verifies the actual signature with a newer nonce and older finalized checkpoint, and the expiry boundary. Existing transaction retries/deadlines are unchanged; no chain error is suppressed. The affected test fixture uses parking_lot::Mutex.

The former Seity Extrinsic marked as invalid run used noncanonical best-block anchors, but retained evidence lacks the signed bytes and typed pool reason. Fork-sensitive mortality was a real correctness hazard; it is not claimed as the conclusively proved cause of that historical failure. Prior hosted Factory/Genesis timeout causes also remain unproved. No broker/readiness workaround, prewarming, extra retry, or timeout increase was added.

Executed verification

  • Exact-head native CI: success, 23 successful jobs, 3 skipped (Workflow lint; Android provider (kotlin compile); E2E (playground inside dotli)); job totals include control jobs. This is the CI workflow result, not an assertion that every advisory PR check or release credential is green.
  • Each of the five native variants passed 21 Bulletin RPC regression tests, all-target Clippy with -D warnings, CLI build, and canonical browser/testing Wasm packaging. Base full library: 1,246 passed.
  • All six frontend consumers passed configured build, typecheck and lint. The later frontend-only formatting correction passed targeted Prettier checks; it did not change runtime source or canonical native artifacts.
Local original sequence Tested frontend head Result, retries=0 Genesis after navigation Factory Submit
#238 0a24db4aa189adad7b93f9ff508c7949e39196ee 42 passed, 20 skipped; no failed/flaky cases 1107ms 9625ms 6057ms
#255 301a235ba13248ef4281e9e3d859919fb6cfbe06 42 passed, 20 skipped; no failed/flaky cases 1045ms 11023ms 13548ms
#287 d3dc8a41807c36b8bcdf001c47eccb9735305499 42 passed, 20 skipped; no failed/flaky cases 1029ms 6496ms 5530ms

The Chat/Seity tested heads above precede documentation-only formatting merges; their native/Wasm pins and runtime code are unchanged. Final hosted frontend results are recorded on the linked consumer PRs, separately from these exact-head local results.

Final hosted retest: failures remain

Frontend PR Tests workflow Functional E2E
#238 success 79 passed 42 passed, 20 skipped
#185 success 89 passed, 3 skipped 41 passed, 1 flaky, 20 skipped
#255 success 89 passed, 3 skipped 42 passed, 20 skipped
#287 failure 85 passed, 4 failed, 3 skipped 42 passed, 20 skipped
#290 success 87 passed, 2 failed, 3 skipped 42 passed, 20 skipped
#291 failure 86 passed, 5 failed, 3 skipped 41 passed, 1 flaky, 20 skipped
  • PVM and JAM Genesis Hash still flaked after navigation: the product stayed pending for the helper's existing 20 seconds; the existing CI retry passed. The helper reports this timeout as error; it is not evidence of a chain rejection. Retained traces include People-chain/local development sockets but do not expose the Asset Hub gateway WebSocket exchange, so these new failures do not establish an upstream or broker cause.
  • Peer: two navigation product-render timeouts at 45 seconds. The existing threshold tolerates these, so its green workflow is not a clean functional suite.
  • Seity: cache-off RPC-gateway resolution timed out; two navigation renders timed out; another navigation case reported failure to connect to trusted provider paseo-bulletin-next-ipfs.polkadot.io. The zero-failure host-settings gate correctly failed.
  • JAM: cache-on reload and two navigation cases reported that same provider connection error; two more navigation cases timed out. The zero-failure host-settings gate correctly failed. These logs do not establish whether the underlying cause was provider availability, runner networking, CORS, or another transport failure.
  • All six final Static Analysis and hosted cold-start Performance workflows passed; all five native CI workflows passed. That does not clear the red functional gates, Genesis flakes, or Doom matrix. No additional CI rerun, timeout/retry increase, threshold relaxation, or speculative transport patch was made.

Doom: criterion corrected, backend matrix still unqualified

The user explicitly approved 35 FPS sustained over 30 seconds, with one frame of sampling-boundary tolerance: frames + 1 >= elapsedMs * 35 / 1000. This replaces the instantaneous FPS >= 35 sample; it is an acceptance-criterion change, not a runtime speedup. Runtime and displayed FPS are unchanged; raw samples are not rounded to force a pass. Update p95 <28.6ms, cold/warm first-frame limits <3,000/<1,000ms, audio and translation-cache checks remain. The revised official RPC benchmark passed once before the vendor replacement.

The later isolated matrix used the rebuilt base pair at frontend 238ab5fa739788b2eb948ba1f807a1876edbacad, with fresh owned Chrome profiles and no concurrent builds/E2E:

Backend Observed result Qualification
smoldot-direct 1,050 frames / 30,001.1ms; p95 17.7ms; cold/warm 202.9/152.8ms; audio/cache passed PASS under the approved criterion
smoldot-shared-worker 1,038 frames / 30,001.4ms = 34.5983854 FPS; p95 17ms; cold/warm 186.4/158.4ms; other checks passed FAIL: cadence deficit retained
rpc-gateway Warm-readiness helper timed out. Its null snapshot conflated missing frame, missing canvas and evaluation errors, and earlier cold/cadence values were not retained by that helper NOT QUALIFIED; iframe disappearance is not established

Distinct diagnostics found no presentation loss in a later instrumented 24-second shared-worker sample and observed a successful hidden RPC new-document reload. Neither diagnostic supersedes the failures or qualifies performance. No evidence-proved runtime fix, guest rebuild, speculative tuning, or further unchanged gate rerun was made. The original strict RPC failure and every new failure remain retained. Next causal capture must instrument the original early 30-second window and distinguish warm lifecycle states before proposing a runtime fix.

Retention and rollout boundary

Local verification used paseo-next-v2, the pinned host-playground fixture f56294cea4430163bf16ec068844b1327441073c, and existing private QA identities. All three corrected sequences paired on their first existing setup attempt. A prior local launch failure and a misconfigured Previewnet-product run (34 passed, 20 skipped, 8 Chain/Contract failures) are retained separately, not presented as reproductions of the hosted Genesis timeout. Private traces/auth/signers were not published.

The first repair heads also exposed a README formatting failure (corrected by documentation-only commits) and a PVM cache-unit-test 5,000ms timeout. No cache runtime/test change, limit increase, or causal claim was made for that isolated timeout. Older in-flight runs superseded by the formatting correction remain recorded as cancelled, not passed.

No PR merge, force push, deployment, environment approval, SDK/npm/product/guest publication, or rollback was performed by this repair. JAM remains JAM-TEST-INSTANCE, never JAM-PUBLIC-DEVNET. The user-owned deploy: paseo.fyi label is retained; repair-triggered deployment runs 36970790399 and 36971286469 were cancelled before deployment. The earlier rollout audit is retained below: an older workflow deployed 56cea5d37577bf82684fb5c6b6e4ba81d2142938; this record does not claim live remained unchanged historically.

Historical integration qualification (superseded; retained verbatim)

Current main refresh and qualification — 2026-10-01

  • Current source: 94f597becce31682a374e4aabc546e4a9ad61103. Native main bda6ac518c8cc59319491b12e4e23b96777375fd is integrated; the frontend stack includes dotli main f4012c50c3400d1186c332ad2ae50298cefd153d (merged chore(deps): bump postcss from 8.5.15 to 8.5.23 in /explorer #313). Histories and worktrees were preserved; pushes used fetched-head ancestry guards, never force.
  • Canonical seity artifact-generation revision: 978b7d3e46b92d8983e733a3f39b2862968d0ef5. Later native changes are test/docs/iOS-only, not SDK/Wasm inputs, so the artifact pin intentionally differs from the current head. Complete matching client and host packages remain 0.23.0, generated rather than hand-edited. Browser signing Wasm uses web-wasm-signing-host without test-host; testing Wasm is separate.
  • Browser consumers: dotli #287 at b03e83616857f4e4745d479776dde43cdfa6267a.
Canonical artifact SHA-256
Client npm archive 5442571f6770f05d97a1ed3c3a0ab96ca1df7c15d77ee168130d53853523db2d
Client dist/generated/client.js (not dist/index.js) 02e193761518364624e9dd53a41dd7cbddf4b5d8482f3e93489b51edd0576630
Host npm archive 8bd67c12ee9303c802b94d7b65c4c800c5cbe338a78311cb6786270a0c06ca63
Browser signing Wasm c47f65213982969e4a42ae02fdf08ae621fc50fcfc30f3feb74a5878260bed63

Qualification

  • Frontend #287 exact-head Tests: functional 89 passed, 3 skipped; E2E 41 passed, 1 flaky, 20 skipped. Hosted E2E retained one flaky Chain → Chain Spec: Genesis Hash case: it failed on the first attempt and passed the existing CI retry. No retry setting was changed.

  • Current-head Core CI: 24 required jobs green — 22 passed, 2 path-filter skips. This includes core Swift/Android coverage, not a claim that full iOS application CI ran at this head. The separate existing release-signing-credentials advisory failure remains distinct from Core CI.

  • Local: Rust workspace: 2,253 passed across 34 suites, 24 ignored. Client/host SDK: 290/326 passed; local Swift and Android qualification passed. Canonical codegen and complete feature-specific package construction were qualified locally.

  • Browser/native proof: Real encrypted-content lifecycle passed: an 82-byte AES-256-GCM test ciphertext was submitted on Paseo, retrieved from Bulletin through the production profile loader, decrypted to the exact nonpersonal 1×1 PNG, and displayed. Closing revoked its blob URL; reopening created a new blob and exactly one drawer. This is not a full registered-user profile/contact-sharing round trip. Evidence: main-refresh-seity-live.json and screenshot.

Retained cross-stack limits

  • The isolated strict Doom matrix is not fully green: RPC measured 34.54231433545555 FPS against ≥35 FPS. Direct smoldot measured 35.06721215581914 and shared-worker smoldot 35.48895899032775. All three passed p95/cold/warm/cache/audio criteria; warm runs used a new document and zero translation. No threshold, clock, timeout, or retry policy was weakened.
  • Latest local Seity E2E attempt: 41 passed, 20 existing skips, 1 Submit failure (Extrinsic marked as invalid). Two existing native broadcast attempts were validated then invalidated; none was found included in the inspected canonical range. [INFERENCE] Noncanonical mortality anchors may explain invalidation; the exact cause is not established and signed extrinsic bytes were not retained. The earlier Factory deadline failure is also retained: inclusion took 47,516ms against the unchanged 30s product deadline. A separate unchanged manual Factory attempt passed in 10.918s. These failures are not erased by other passing checks.
  • Evidence JSON/screenshots are retained beside the refresh worktrees; private browser profiles and throwaway harnesses were removed. No bearer references, keys, signing configuration, or .auth contents are included here.

This refresh authorizes no deployment, environment approval, PR merge, SDK/npm publication, or guest/product publication. Its QA writes were testnet-only.

All three refresh-triggered JAM Deploy runs were cancelled before rollout; final-head cancellation proof is for frontend dcdef40499119183aed82a39f784ef740d494341. No refreshed source head was deployed.

The live environment changed during qualification: older Deploy run 36945647296, attempt 3 was approved under GitHub account replghost, explicitly checked out baseline 56cea5d37577bf82684fb5c6b6e4ba81d2142938, and recorded deployment success at 2026-10-02 01:19:01 UTC. Its later published-product smoke failed. The operator/client/session behind that account is unproven; this qualification granted no approval and performed no rollback. The observed live content hash changed from 4a7caf047fb7f350c1833039b93ba634698a47c56f051b8c7fc0525d4c59a5c8 to 5882695ee20df5d24a6ed2feb9e997f176fe27ecf4eafe742fabb39eba92885f; these are content hashes, not Git SHAs, and their exact byte-level mapping to a source commit is unproven. Earlier revision/deployment records below remain historical evidence and do not override this current section.

Earlier source and qualification (superseded)

Head 3d057d5de00751ff6c882c301434e64cb88f4930 includes main aa6ae62ca038bf4a6356edae8eb78e595d52ce24 through history-preserving merge commits. Client and host package manifests remain 0.23.0 with pending Changesets.

The branch includes the integrated main changes and preserves its feature boundary. Root and combined-stack canonical codegen and TypeScript qualification pass. This branch’s current-head Codegen CI job passes; its downloaded canonical output matches all 45 tracked generated files byte-for-byte. Full workspace/native qualification remains tracked by current-head CI.

Current-head core CI passes, including Rust workspace, default WASM bridge, Android compile/unit checks, and iOS Swift + WebKit. Full local workspace/native qualification was interrupted by workstation disk exhaustion; the full current-head core CI gate completes that qualification. Full iOS application CI also passes, including the in-tree core, application build, simulator preview, and tests. No PR was merged or approved, and no npm package was published. Deployment evidence below belongs to the explicitly named earlier revisions, not this source refresh.

Seity layer on top of #709.

Adds the profile service: profile.present({ reference }) asks the host to show a profile the product holds a reference to (a Seity <cid>#<key><iv> blob reference today). The host fetches, decrypts and renders it in its own UI; profile bytes and the reference's key never return to the product. The call resolves once the presentation is shown.

  • Wire trait Profile (trait id 69) exposes present, disclose, retract, presentContact, placeContactAvatars, ownStatus, and presentOwn at method IDs 0 through 6. The present request's Debug redacts its reference.
  • Own-profile status returns only a boolean. V2 disclosure supports independent ChatApps, App, and selected Contacts audiences; V2 contact presentation accepts a peer or opaque Contacts handle. V3 avatar placement adds the same selectors alongside the own-profile slot while preserving V1/V2 placement compatibility. Profile contents and references remain host-owned.
  • App-scoped and personal grants coexist. Personal relay uses separate authenticated Chat content and wallet/network-scoped storage, with durable revisions and withdrawal tombstones. Delivery still requires a ready authenticated channel and a running transport product.
  • Presentation uses optional ProfilePlatform callbacks on OptionalPlatform, emitted by codegen. Browser and Web Worker hosts install them; native hosts and the CLI do not provide profile presentation.
  • Served by the local product runtime, not the Chat authority: in pairing mode Chat operations run on the paired wallet, and the profile has to appear where the product is on screen.
  • The core screens only the reference's shape (non-empty, ≤ 2048 bytes, printable ASCII without whitespace). Parsing the format is the host's.

Integration and qualification

Based on #709, with main through c5158448f3c4575f40350017d466053d6b19dacb. The profile service uses the unified truapi runtime and canonical codegen catalog; UniFFI callbacks remain native-only.

Refreshed TrUAPI client/host 0.23.0 and wallet/testing WASM artifacts are built from f031658066d19e85b829aa786dad682e22b41197; consumer integration and exact archive/client/WASM digests are tracked in paritytech/dotli-community#287 and its vendor lock. They include V2 audience/contact-selector and V3 avatar-placement APIs, host-private Contacts integration, and the integrated Chat privacy and settlement fixes. The user explicitly selected rollout of the newer sharing contract on experimental paseo.fyi. Branch CI and deployed qualification remain separate; the current combined deployment is qualified below, without claiming live sharing coverage.

Current local qualification passes canonical code generation, TypeScript client/host builds, release wallet/testing WASM builds, 1,492 core library tests, and all-target/all-feature TrUAPI Clippy with -D warnings. The merge retains both private rich-frame removal and host-owned Profile-reference stripping before plaintext reaches the product.

Core CI and the full iOS build, app tests, and preview pass at f031658066d19e85b829aa786dad682e22b41197. The consumer's checks pass. A real browser/live-port smoke on combined paritytech/dotli-community#291 decoded the Profile domain rejection for a malformed reference; that smoke covered present, not the new own-profile methods or a live Seity avatar-fetch scenario.

All-target/all-feature truapi clippy with -D warnings and seven avatar regression tests pass. The V1 response conversion still executes before the unit response is wrapped; no lint suppression or protocol shortcut is used.

The iOS combined store uses model 53, retaining both historical main and Chat model-49 variants. Real SQLite migration smoke checks passed from main model 49, Chat model 49, and main model 52, preserving payment amounts, owner identity, and native Coinage ledger payloads. The permanent migration regression runs in the app suite. This iOS-only correction does not change the vendored browser SDK artifacts.

The iOS test lane retains xcresult, raw build/simulator logs, and available crash reports regardless of debug mode. Ruby syntax, workflow lint, and diagnostic export from a real retained simulator result pass. An earlier run reported 358 failures without retaining its result or crash diagnostics, so its cause is not established. The current complete iOS run passes; tests, retry behavior, and parallelism settings are unchanged.

The user-approved paseo.fyi deployment at 032e97128983570eac9c32d6cd9dd8a41d181bca, with combined host source af087f734be4d65d9363e68e43bf134145ae0085, passes all eight published PolkaVM product scenarios and all 19 wallet-free TrUAPI capability checks. Product smoke opts in through real Settings; the production execution gate remains default-off. Independent fresh-context Chromium verification observed that exact release and passed feature discovery, JSON storage round-trip, and a live chain-genesis query. This does not qualify live Profile/Contacts/avatar-sharing, own-profile/avatar-fetch, or a new JAM-validator transport trial.

Add the `profile` service. `profile.present({ reference })` asks the
host to show a profile the product holds a reference to. The host
resolves, decrypts and renders it in its own UI, so profile bytes and the
reference's key never return to the product; the call resolves once the
presentation is shown.

Hosts opt in through `ProfilePlatform`, a new optional trait on
`OptionalPlatform`, so codegen emits the dispatcher and the optional
`profile` callback group. The browser and Web Worker hosts install it;
native hosts and the CLI answer `Unsupported`.

The call is served by the local product runtime, not the Chat authority:
in pairing mode Chat operations run on the paired wallet, and a profile
must appear where the product is on screen. The core screens only the
reference's shape (non-empty, at most 2048 bytes, printable ASCII without
whitespace); parsing the format is the host's.
@github-actions github-actions Bot added javascript Pull requests that update javascript code rust Pull requests that update rust code labels Sep 25, 2026
@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

CI Status: 24 required jobs green, 21 passed and 3 skipped by path filter.

All job results
job result
android-bindings success
bundle-size success
changes success
changeset-guard success
cli-package success
codegen success
e2e skipped
explorer success
headless-install success
host-android-bindings success
host-android-detekt success
host-wasm success
ios-bindings success
ios-swift success
licenses success
playground success
provider-android-bindings skipped
release-guard success
rust success
ts-client success
ts-debugger success
ts-host success
wasm-provider success
workflow-lint skipped

Signing credentials: failure as of 2026-10-02, a release may fail

Commit bd55ec2a · run log

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

iOS simulator preview

Built from 3d057d5de, stamped with it in TrUAPICommit.

gh run download 36743632311 --name simulator-preview-3d057d5de
unzip polkadot-app-*.app.zip
xcrun simctl install booted polkadot-app.app
xcrun simctl launch booted io.parity.polkadotapp.develop

Or download it in a browser, which arrives as a zip wrapping
the .app.zip, so it needs unzipping twice.

An arm64 simulator slice, so it needs an Apple Silicon Mac and does not
install on a device. Kept for 14 days, after which the link stops
resolving and a new push rebuilds it.

corey-hathaway and others added 3 commits September 26, 2026 15:18
…s by name

On top of `profile.present`:

- `disclose({ reference })` (method 1, App only) stores the user's own
  reference with the product that disclosed it; `retract()` (2) withdraws
  it, and only the discloser may.
- `presentContact({ peerIdentity })` (3) names a chat contact; the host
  looks up the reference that contact's host sent and hands it to the
  existing `ProfilePlatform::present_profile`. The product never holds a
  contact's reference, so it cannot read, keep, forward or substitute it.

Both kinds of reference live in core storage: `ProfileDisclosure`
(wallet-owned) and `ProfileReferencesReceived { product_id }` (cleared with
the chat product, like its roster). The chat relay that fills the latter
comes next; its write helper is here and tested.

The CLI installs a presenter that records each presentation to
`TRUAPI_PROFILE_LOG` as a SHA-256 and format prefix, never the reference.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The Chat v2 half of profile disclosure, built on the actor's host-private
outbox that payments and rich files already use:

- Wire: `ProfileReference { discloser_product_id, reference: Option }` at
  V2 content index 21 (a new shared wire index; needs agreeing with native
  Chat before it ships).
- Send: `publish_profile_reference`, run on Initialize, seals one message
  per ready peer whose watermark differs from the user's disclosure, as an
  `OutgoingKind::ProfileReference` the product submits as opaque ciphertext.
  The watermark (trailing `profile_shared`, absent from older snapshots)
  advances at queue time; a withdrawal is sent to peers that hold one.
- Receive: the frame is classified and screened, stored per peer in
  `ProfileReferencesReceived` for the chat product, and cut from the opened
  plaintext (forcing a re-encode), so the product never sees it. Only live
  frames update it, never compacted history. Products cannot prepare one.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The RFC for `disclose` / `retract` / `presentContact` and the Chat v2 relay
on the host-private outbox, unnumbered and in draft. Its open questions are
the known gaps of the prototype: the content-type index, several disclosing
products, consent, other devices, reconcile timing, and where references
are resolved. Each gap is also marked where it lives in the code.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Trait 20 is also claimed by Contacts (#17) and Game (#990), both headed
for main; whichever lands second is likely to take 21. 22 keeps Profile
clear of both.
@github-actions github-actions Bot added documentation Improvements or additions to documentation rfc labels Sep 26, 2026
peer_identity is [u8; 32], which the TypeScript client types as a
0x-prefixed hex string, so the generated playground example failed tsc.
replghost added a commit that referenced this pull request Sep 27, 2026
- Queue profile references best effort. They have their own outbox
  budget, one per peer, so they neither crowd out nor are blocked by other
  Chat traffic; a reference with no room waits for a later reconcile
  instead of failing Chat Initialize.
- Drop an unacknowledged reference after one statement lifetime instead of
  re-signing it forever; a peer that predates content index 21 never
  acknowledges it. The watermark stays, so it is not resent until the
  disclosure changes.
- Order received references by frame timestamp. Withdrawals are kept as
  rows and a frame that is not strictly newer is ignored, so an older
  disclosure opened after its withdrawal cannot restore it. Senders stamp
  each frame to a peer later than the last and give it a fresh request id.
- Scope ProfileDisclosure and ProfileReferencesReceived to the wallet root
  key and Chat network, like the Chat roster. Profile calls with no one
  signed in answer NotConnected.
- Ask once per product before disclose stores anything, through a new
  ProfileDisclosure confirmation review and permission; a refusal is
  PermissionDenied.
- Correct the changeset: the relay is part of this change.
@github-actions github-actions Bot added host-ios Touches the iOS host tree host-android Touches the Android host tree labels Sep 28, 2026
replghost added a commit that referenced this pull request Sep 28, 2026
# Conflicts:
#	rust/crates/truapi-client/src/generated.rs
Add `profile.placeContactAvatars` (Profile method 4). A chat App tells
the host where it draws contacts' avatars: its surface size and, per
avatar, a slot id, the contact's peer identity, a square rect and the
clip it is cut to. The host draws each sharing contact's photo and mood
ring there on its own layer; taps still reach the product.

- The core keeps only slots whose contact holds a current reference in
  the caller's ProfileReferencesReceived and hands them, with those
  references, to the new ProfilePlatform::place_contact_avatars. Its
  default draws nothing.
- The answer never depends on who shared: any well-formed placement from
  a signed-in App is Ok, a host drawing failure is not reported, and
  nothing about slots is logged. Only the host's own Unsupported is
  passed on. More than 64 slots, a surface side outside 1..=16384, a
  non-square avatar or one outside 1..=1024 a side, and repeated slot
  ids are refused as Unknown.
- The last placement is kept per product connection. A received
  reference or withdrawal that changes storage redraws it with the same
  geometry; disposing the connection, or placing after sign-out, clears
  what the host drew.
replghost added a commit that referenced this pull request Sep 28, 2026
# Conflicts:
#	rust/crates/truapi-client/src/generated.rs
#	rust/crates/truapi/src/lib.rs
…layout

Snapshots written before 571f348 end with watermarks that carry no frame timestamp or withdrawal marker, and no longer decoded, which paused Chat setup with StorageUnavailable. The trailing list now decodes in either layout. Legacy watermarks are dropped: contacts kept those references under a slot the host no longer reads, so the next reconcile sends every contact the disclosure again.
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

This pull request touches an app, which is not built by default. Add a label for each build you want:

  • iOS simulator build, ios-simulator-build: builds the iOS app, runs its tests and attaches a build for the iOS Simulator on a Mac.
  • iOS device build, ios-device-build: attaches a signed build that installs on a registered iPhone or iPad.
  • Android build, android-device-build: attaches an APK that installs on an Android phone or an emulator.

Each starts as soon as it is added and follows the branch from then on.

# Conflicts:
#	js/packages/truapi-host/README.md
# Conflicts:
#	rust/crates/truapi-client/src/generated.rs
#	rust/crates/truapi/src/v02.rs
# Conflicts:
#	rust/crates/truapi-client/src/generated.rs
replghost added a commit that referenced this pull request Oct 3, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation github_actions Pull requests that update GitHub Actions code host-android Touches the Android host tree host-ios Touches the iOS host tree javascript Pull requests that update javascript code rfc rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants