Conversation
Adds TrUAPI trait 21, PeerTransport: host-terminated JAMNP-S streams to
JAM peers (dial/open/send/recv/reset/close/events). The host terminates
QUIC or WebTransport, builds the jamnp-s ALPN from the declared genesis
and pins the peer's certificate identity; the guest verifies every byte
it receives.
A host may grant it only to an execution whose App manifest v2 declares
capabilities.network.jam = { genesis }, for that genesis only, with
bounded connections, streams and message sizes. The default
implementation, including the Rust product runtime, returns NotGranted.
Ships the browser WebTransport session and the deterministic PolkaJAM
certificate-hash derivation under @parity/truapi/peer-transport, with
SCALE codec vectors pinned against the Rust types.
…ment # Conflicts: # rust/crates/truapi-client/src/generated.rs # rust/crates/truapi-server/src/runtime/capabilities/resources.rs
# Conflicts: # rust/crates/truapi-client/src/generated.rs
Contributor
|
CI Status: 24 required jobs green, 22 passed and 2 skipped by path filter. All job results
Signing credentials: failure as of 2026-10-02, a release may fail Commit |
Contributor
iOS simulator previewBuilt from gh run download 36743659542 --name simulator-preview-4b8a264c9
unzip polkadot-app-*.app.zip
xcrun simctl install booted polkadot-app.app
xcrun simctl launch booted io.parity.polkadotapp.developOr download it in a browser, which arrives as a zip wrapping An arm64 simulator slice, so it needs an Apple Silicon Mac and does not |
Peer access is now a runtime permission rather than an App-manifest
capability, matching the rest of TrUAPI (Remote, WebRtc, ChainSubmit).
RemotePermission gains JamPeers { genesis }, appended as variant 5 so
every earlier index is unchanged; its decision is stored per product and
genesis like any other remote permission.
ProductRuntimeHost::require_jam_peers checks the stored decision,
prompts while it is undetermined and persists the answer, keeping a
one-use grant for the execution so a light client dialing several
validators is asked once per genesis. The product runtime's
PeerTransport still answers NotGranted. The manifest grant and its
parser are gone; the genesis parser and ALPN helper stay.
The browser session takes an authorize(genesis) callback instead of a
fixed genesis, asks once per genesis per session and shares a pending
answer between concurrent dials. The Android and iOS product bridges
deny JamPeers without a prompt, as neither ships a JAM transport.
Brings #1010's switch from the manifest grant to the RemotePermission::JamPeers runtime permission into the Seity layer. Kept both sides of the permission storage-key test (Chat authority and JamPeers keys); regenerated the client catalog wire hash with codegen.
A dial waiting on the JamPeers prompt could outlast the guest's request timeout; the guest retried and the original dial later opened a connection nobody knew about, holding a slot until the session closed. Dials now answer within 10 s (prompt + handshake), CANCEL withdraws an in-flight dial with Cancelled, and anything opened after withdrawal is closed without holding a slot. The permission decision is still remembered.
replghost
added a commit
to paritytech/dotli-community
that referenced
this pull request
Sep 27, 2026
Brings in the JamPeerTransport rename (#290 at 8980057). Only vendor/ conflicted; it is rebuilt from paritytech/trinity-user-agents#1011 (feat/jam-peer-transport-on-seity) at c85c26b6, the --no-ff merge of the renamed #1010. Wire-identical: trait 23, methods 0..6, JamPeers.
…7df169ec821ff1a21a8081ab89bc4f02c816' into HEAD
…e5c44850a5f87606bf065a7603a17c342ed8' into HEAD
…ransport-on-seity
…inalized-anchor-20261002 # Conflicts: # rust/crates/truapi-client/src/generated.rs # rust/crates/truapi/src/host_core.rs
# Conflicts: # rust/crates/truapi/Cargo.toml
# Conflicts: # rust/crates/truapi/Cargo.toml
# Conflicts: # js/packages/truapi-host/README.md
…egration # Conflicts: # rust/crates/truapi-client/src/generated.rs
# Conflicts: # rust/crates/truapi-client/src/generated.rs
# Conflicts: # rust/crates/truapi-client/src/generated.rs
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Current repair qualification — 2026-10-02
95d0c3242f173b22578d34f1fea03abfd3754789. Canonical jam artifact-generation and Wasm revisions are this same commit. Prior main-integration baselines are retained: nativebda6ac518c8cc59319491b12e4e23b96777375fd, frontendf4012c50c3400d1186c332ad2ae50298cefd153d.0efd81fdf91163b240a4e34a41d9b2349d3c9ffd. Complete matching SDK/host packages remain 0.23.0; codegen and Wasm were rebuilt canonically. Generated client bytes are unchanged. Production features:wasm-signing-host; separate testing bundle:wasm-signing-host,test-host.1103910932941a1d57deb4b7278b40c22c1489bbd11c609e398dd4418922d850dist/generated/client.js79d8b4a1ec6c94af558cd7ad59e52aa4c8fb3c3634bb8dd3c0cb46126b4fab78c9e03bf25117f8ed6783bca1c52b624dd8c0e3306006ce82758b7874381e3a6c1d632066a6f170216925472c920c002efb9150413facd5b65b7fd57c51b7e044581737d50b36a0b86fc12406686ad007d1ea5ebce02c2d07e82d5be8469ed97bNative correction and causal limits
Bulletin mortal signatures now anchor to a finalized checkpoint, while nonce/runtime state comes from the freshest available signing snapshot. A checkpoint at least 64 blocks behind is rejected before broadcast. Regression coverage verifies the actual signature with a newer nonce and older finalized checkpoint, and the expiry boundary. Existing transaction retries/deadlines are unchanged; no chain error is suppressed. The affected test fixture uses
parking_lot::Mutex.The former Seity
Extrinsic marked as invalidrun used noncanonical best-block anchors, but retained evidence lacks the signed bytes and typed pool reason. Fork-sensitive mortality was a real correctness hazard; it is not claimed as the conclusively proved cause of that historical failure. Prior hosted Factory/Genesis timeout causes also remain unproved. No broker/readiness workaround, prewarming, extra retry, or timeout increase was added.Executed verification
-D warnings, CLI build, and canonical browser/testing Wasm packaging. Base full library: 1,246 passed.0a24db4aa189adad7b93f9ff508c7949e39196ee301a235ba13248ef4281e9e3d859919fb6cfbe06d3dc8a41807c36b8bcdf001c47eccb9735305499The Chat/Seity tested heads above precede documentation-only formatting merges; their native/Wasm pins and runtime code are unchanged. Final hosted frontend results are recorded on the linked consumer PRs, separately from these exact-head local results.
Final hosted retest: failures remain
error; it is not evidence of a chain rejection. Retained traces include People-chain/local development sockets but do not expose the Asset Hub gateway WebSocket exchange, so these new failures do not establish an upstream or broker cause.paseo-bulletin-next-ipfs.polkadot.io. The zero-failure host-settings gate correctly failed.Doom: criterion corrected, backend matrix still unqualified
The user explicitly approved 35 FPS sustained over 30 seconds, with one frame of sampling-boundary tolerance:
frames + 1 >= elapsedMs * 35 / 1000. This replaces the instantaneousFPS >= 35sample; it is an acceptance-criterion change, not a runtime speedup. Runtime and displayed FPS are unchanged; raw samples are not rounded to force a pass. Update p95 <28.6ms, cold/warm first-frame limits <3,000/<1,000ms, audio and translation-cache checks remain. The revised official RPC benchmark passed once before the vendor replacement.The later isolated matrix used the rebuilt base pair at frontend
238ab5fa739788b2eb948ba1f807a1876edbacad, with fresh owned Chrome profiles and no concurrent builds/E2E:Distinct diagnostics found no presentation loss in a later instrumented 24-second shared-worker sample and observed a successful hidden RPC new-document reload. Neither diagnostic supersedes the failures or qualifies performance. No evidence-proved runtime fix, guest rebuild, speculative tuning, or further unchanged gate rerun was made. The original strict RPC failure and every new failure remain retained. Next causal capture must instrument the original early 30-second window and distinguish warm lifecycle states before proposing a runtime fix.
Retention and rollout boundary
Local verification used
paseo-next-v2, the pinned host-playground fixturef56294cea4430163bf16ec068844b1327441073c, and existing private QA identities. All three corrected sequences paired on their first existing setup attempt. A prior local launch failure and a misconfigured Previewnet-product run (34 passed, 20 skipped, 8 Chain/Contract failures) are retained separately, not presented as reproductions of the hosted Genesis timeout. Private traces/auth/signers were not published.The first repair heads also exposed a README formatting failure (corrected by documentation-only commits) and a PVM cache-unit-test 5,000ms timeout. No cache runtime/test change, limit increase, or causal claim was made for that isolated timeout. Older in-flight runs superseded by the formatting correction remain recorded as cancelled, not passed.
No PR merge, force push, deployment, environment approval, SDK/npm/product/guest publication, or rollback was performed by this repair. JAM remains JAM-TEST-INSTANCE, never JAM-PUBLIC-DEVNET. The user-owned
deploy: paseo.fyilabel is retained; repair-triggered deployment runs 36970790399 and 36971286469 were cancelled before deployment. The earlier rollout audit is retained below: an older workflow deployed56cea5d37577bf82684fb5c6b6e4ba81d2142938; this record does not claim live remained unchanged historically.Historical integration qualification (superseded; retained verbatim)
Current main refresh and qualification — 2026-10-01
7e65d2eb8d73b7db49ef1f3681377a0db8998db2. Native mainbda6ac518c8cc59319491b12e4e23b96777375fdis integrated; the frontend stack includes dotli mainf4012c50c3400d1186c332ad2ae50298cefd153d(merged chore(deps): bump postcss from 8.5.15 to 8.5.23 in /explorer #313). Histories and worktrees were preserved; pushes used fetched-head ancestry guards, never force.e51563a447a03666316c2f3e99e734866696b4cd. Later native changes are test/docs/iOS-only, not SDK/Wasm inputs, so the artifact pin intentionally differs from the current head. Complete matching client and host packages remain 0.23.0, generated rather than hand-edited. Browser signing Wasm usesweb-wasm-signing-hostwithouttest-host; testing Wasm is separate.dcdef40499119183aed82a39f784ef740d494341.1103910932941a1d57deb4b7278b40c22c1489bbd11c609e398dd4418922d850dist/generated/client.js(notdist/index.js)79d8b4a1ec6c94af558cd7ad59e52aa4c8fb3c3634bb8dd3c0cb46126b4fab7806f4b0798c02bb4ba17f346ca897b02a5943b30773c92c1f42eeec0f2460de3028e16236f7396fd188e7a2b8df98fe7d150957c3f5b3b21f2ba8b71d373e9439Qualification
Frontend #291 exact-head Tests: functional 91 passed, 3 skipped; E2E 42 passed, 20 skipped. No flaky case in this final hosted Tests run.
Current-head Core CI: 24 required jobs green — 22 passed, 2 path-filter skips. This includes core Swift/Android coverage, not a claim that full iOS application CI ran at this head. The separate existing release-signing-credentials advisory failure remains distinct from Core CI.
Local: Full local formatting, build, clippy and Rust tests passed. Client/host SDK: 330/326 passed; local Swift and Android qualification passed. Live JAM test passed (1 test, 0.86s). Canonical codegen and complete feature-specific package construction were qualified locally.
Browser/native proof: Both feature boundaries remain intact. The combined branch passed real certificate-verified JAM-TEST-INSTANCE WebTransport/UP0 through the installed PVM host-frame-request path, full-genesis trusted consent, grant isolation, close/reset, pagehide disposal/stale-frame rejection, and replacement-execution re-consent. Genesis:
0x10c123f02eb6df4c01397d797a112055be691883baa2e82f83b618ed6ce45e46. No TLS bypass or new published guest. Evidence:main-refresh-jam-pvm-live.jsonand screenshots; Seity encrypted-content evidence is separately scoped above the Chat layer.Retained cross-stack limits
Extrinsic marked as invalid). Two existing native broadcast attempts were validated then invalidated; none was found included in the inspected canonical range. [INFERENCE] Noncanonical mortality anchors may explain invalidation; the exact cause is not established and signed extrinsic bytes were not retained. The earlier Factory deadline failure is also retained: inclusion took 47,516ms against the unchanged 30s product deadline. A separate unchanged manual Factory attempt passed in 10.918s. These failures are not erased by other passing checks..authcontents are included here.This refresh authorizes no deployment, environment approval, PR merge, SDK/npm publication, or guest/product publication. Its QA writes were testnet-only.
All three refresh-triggered JAM Deploy runs were cancelled before rollout; final-head cancellation proof is for frontend
dcdef40499119183aed82a39f784ef740d494341. No refreshed source head was deployed.The live environment changed during qualification: older Deploy run 36945647296, attempt 3 was approved under GitHub account
replghost, explicitly checked out baseline56cea5d37577bf82684fb5c6b6e4ba81d2142938, and recorded deployment success at 2026-10-02 01:19:01 UTC. Its later published-product smoke failed. The operator/client/session behind that account is unproven; this qualification granted no approval and performed no rollback. The observed live content hash changed from4a7caf047fb7f350c1833039b93ba634698a47c56f051b8c7fc0525d4c59a5c8to5882695ee20df5d24a6ed2feb9e997f176fe27ecf4eafe742fabb39eba92885f; these are content hashes, not Git SHAs, and their exact byte-level mapping to a source commit is unproven. Earlier revision/deployment records below remain historical evidence and do not override this current section.Earlier source and qualification (superseded)
Head
4b8a264c917b26df96e5e72e416060612d014326includes mainaa6ae62ca038bf4a6356edae8eb78e595d52ce24through history-preserving merge commits. Client and host package manifests remain 0.23.0 with pending Changesets.Canonical pinned-nightly codegen, client/host TypeScript builds, CLI typecheck, release-version check, pinned rustfmt, and 330 client tests pass locally. An actual Swift storage smoke proves granted foreign reads reach the owner while writes and clears remain caller-scoped. Profile trait 69, JAM trait 111, Chat authority and no-std guest boundaries remain separate.
Current-head core CI passes, including Rust workspace, default WASM bridge, Android compile/unit checks, and iOS Swift + WebKit. Full local workspace/native qualification was interrupted by workstation disk exhaustion; the full current-head core CI gate completes that qualification. Full iOS application CI also passes, including the in-tree core, application build, simulator preview, and tests. No PR was merged or approved, and no npm package was published. Deployment evidence below belongs to the explicitly named earlier revisions, not this source refresh.
Summary
Deployment integration of Seity #1001 and JamPeerTransport #1010. Feature implementations remain reviewed in the parent PRs; this layer integrates them with canonical generated bindings.
Stack
#540 → #709 → #1001 → this PR, with #1010 merged in. Main is integrated through
c5158448f3c4575f40350017d466053d6b19dacb. Published branch history is preserved with merge commits.This layer is not intended to merge into #1001. Once #1010 flows through the base and reaches Seity, this integration layer can be closed.
Contract and artifacts
af087f734be4d65d9363e68e43bf134145ae0085. Consumer integration and qualification are tracked in chore(deploy): Seity layer + JamPeerTransport (#287 + #290) dotli-community#291; its vendor lock records the published archive, generated-client/WASM digests, and build features.Earlier qualification evidence
Local native all-target/all-feature checking and wallet/testing WASM builds pass. A real Chromium session with the combined consumer rendered the published guest, completed a canonical SDK handshake over its live host port, and decoded a Profile domain rejection for a malformed reference.
The user-approved paseo.fyi deployment at
032e97128983570eac9c32d6cd9dd8a41d181bca, with combined host sourceaf087f734be4d65d9363e68e43bf134145ae0085, passes all eight published PolkaVM product scenarios and all 19 wallet-free TrUAPI capability checks. Product smoke opts in through real Settings; the production execution gate remains default-off. Independent fresh-context Chromium verification observed that exact release and passed feature discovery, JSON storage round-trip, and a live chain-genesis query. This does not qualify live Profile/Contacts/avatar-sharing, own-profile/avatar-fetch, or a new JAM-validator transport trial.The previous deployment
57aaf948a7b9d9fb6f35b9a731ad9cad9856a859and run36640362244remain historical qualification, not evidence reassigned to the newer artifact contract.At
af087f734be4d65d9363e68e43bf134145ae0085, all host PR checks pass, including core CI and full iOS build, tests, and preview. Canonical code generation, TypeScript client/host builds, and release wallet/testing WASM builds pass locally for this source. The integrated iOS workflow retains xcresult, raw logs, and crash diagnostics on failure; no tests or retry behavior are weakened.Shared permission descriptions, icons, and settings titles are centralized on
ProductPermission, preserving the distinct JAM prompt wording. Strict scoped SwiftLint reports zero violations, and the full iOS warning ratchet passes without baseline changes or suppressions.The iOS combined store uses model 53, retaining both historical main and Chat model-49 variants. Real SQLite migration smoke checks passed from main model 49, Chat model 49, and main model 52, preserving payment amounts, owner identity, and native Coinage ledger payloads. The permanent migration regression runs in the app suite. This iOS-only correction does not change the vendored browser SDK artifacts.