Skip to content

chore(deploy): Seity layer + JamPeerTransport (#1001 + #1010) - #1011

Draft
replghost wants to merge 123 commits into
feat/chat-seity-profilefrom
feat/jam-peer-transport-on-seity
Draft

replghost wants to merge 123 commits into
feat/chat-seity-profilefrom
feat/jam-peer-transport-on-seity

Conversation

@replghost

@replghost replghost commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Current repair qualification — 2026-10-02

  • Current source: 95d0c3242f173b22578d34f1fea03abfd3754789. Canonical jam artifact-generation and Wasm revisions are this same commit. Prior main-integration baselines are retained: native bda6ac518c8cc59319491b12e4e23b96777375fd, frontend f4012c50c3400d1186c332ad2ae50298cefd153d.
  • Consumers: dotli #291 at 0efd81fdf91163b240a4e34a41d9b2349d3c9ffd. Complete matching SDK/host packages remain 0.23.0; codegen and Wasm were rebuilt canonically. Generated client bytes are unchanged. Production features: wasm-signing-host; separate testing bundle: wasm-signing-host,test-host.
Canonical artifact SHA-256
Client npm archive 1103910932941a1d57deb4b7278b40c22c1489bbd11c609e398dd4418922d850
Client dist/generated/client.js 79d8b4a1ec6c94af558cd7ad59e52aa4c8fb3c3634bb8dd3c0cb46126b4fab78
Host npm archive c9e03bf25117f8ed6783bca1c52b624dd8c0e3306006ce82758b7874381e3a6c
Browser signing Wasm 1d632066a6f170216925472c920c002efb9150413facd5b65b7fd57c51b7e044
Local QA CLI 581737d50b36a0b86fc12406686ad007d1ea5ebce02c2d07e82d5be8469ed97b

Native correction and causal limits

Bulletin mortal signatures now anchor to a finalized checkpoint, while nonce/runtime state comes from the freshest available signing snapshot. A checkpoint at least 64 blocks behind is rejected before broadcast. Regression coverage verifies the actual signature with a newer nonce and older finalized checkpoint, and the expiry boundary. Existing transaction retries/deadlines are unchanged; no chain error is suppressed. The affected test fixture uses parking_lot::Mutex.

The former Seity Extrinsic marked as invalid run used noncanonical best-block anchors, but retained evidence lacks the signed bytes and typed pool reason. Fork-sensitive mortality was a real correctness hazard; it is not claimed as the conclusively proved cause of that historical failure. Prior hosted Factory/Genesis timeout causes also remain unproved. No broker/readiness workaround, prewarming, extra retry, or timeout increase was added.

Executed verification

  • Exact-head native CI: success, 24 successful jobs, 2 skipped (Workflow lint; E2E (playground inside dotli)); job totals include control jobs. This is the CI workflow result, not an assertion that every advisory PR check or release credential is green.
  • Each of the five native variants passed 21 Bulletin RPC regression tests, all-target Clippy with -D warnings, CLI build, and canonical browser/testing Wasm packaging. Base full library: 1,246 passed.
  • All six frontend consumers passed configured build, typecheck and lint. The later frontend-only formatting correction passed targeted Prettier checks; it did not change runtime source or canonical native artifacts.
Local original sequence Tested frontend head Result, retries=0 Genesis after navigation Factory Submit
#238 0a24db4aa189adad7b93f9ff508c7949e39196ee 42 passed, 20 skipped; no failed/flaky cases 1107ms 9625ms 6057ms
#255 301a235ba13248ef4281e9e3d859919fb6cfbe06 42 passed, 20 skipped; no failed/flaky cases 1045ms 11023ms 13548ms
#287 d3dc8a41807c36b8bcdf001c47eccb9735305499 42 passed, 20 skipped; no failed/flaky cases 1029ms 6496ms 5530ms

The Chat/Seity tested heads above precede documentation-only formatting merges; their native/Wasm pins and runtime code are unchanged. Final hosted frontend results are recorded on the linked consumer PRs, separately from these exact-head local results.

Final hosted retest: failures remain

Frontend PR Tests workflow Functional E2E
#238 success 79 passed 42 passed, 20 skipped
#185 success 89 passed, 3 skipped 41 passed, 1 flaky, 20 skipped
#255 success 89 passed, 3 skipped 42 passed, 20 skipped
#287 failure 85 passed, 4 failed, 3 skipped 42 passed, 20 skipped
#290 success 87 passed, 2 failed, 3 skipped 42 passed, 20 skipped
#291 failure 86 passed, 5 failed, 3 skipped 41 passed, 1 flaky, 20 skipped
  • PVM and JAM Genesis Hash still flaked after navigation: the product stayed pending for the helper's existing 20 seconds; the existing CI retry passed. The helper reports this timeout as error; it is not evidence of a chain rejection. Retained traces include People-chain/local development sockets but do not expose the Asset Hub gateway WebSocket exchange, so these new failures do not establish an upstream or broker cause.
  • Peer: two navigation product-render timeouts at 45 seconds. The existing threshold tolerates these, so its green workflow is not a clean functional suite.
  • Seity: cache-off RPC-gateway resolution timed out; two navigation renders timed out; another navigation case reported failure to connect to trusted provider paseo-bulletin-next-ipfs.polkadot.io. The zero-failure host-settings gate correctly failed.
  • JAM: cache-on reload and two navigation cases reported that same provider connection error; two more navigation cases timed out. The zero-failure host-settings gate correctly failed. These logs do not establish whether the underlying cause was provider availability, runner networking, CORS, or another transport failure.
  • All six final Static Analysis and hosted cold-start Performance workflows passed; all five native CI workflows passed. That does not clear the red functional gates, Genesis flakes, or Doom matrix. No additional CI rerun, timeout/retry increase, threshold relaxation, or speculative transport patch was made.

Doom: criterion corrected, backend matrix still unqualified

The user explicitly approved 35 FPS sustained over 30 seconds, with one frame of sampling-boundary tolerance: frames + 1 >= elapsedMs * 35 / 1000. This replaces the instantaneous FPS >= 35 sample; it is an acceptance-criterion change, not a runtime speedup. Runtime and displayed FPS are unchanged; raw samples are not rounded to force a pass. Update p95 <28.6ms, cold/warm first-frame limits <3,000/<1,000ms, audio and translation-cache checks remain. The revised official RPC benchmark passed once before the vendor replacement.

The later isolated matrix used the rebuilt base pair at frontend 238ab5fa739788b2eb948ba1f807a1876edbacad, with fresh owned Chrome profiles and no concurrent builds/E2E:

Backend Observed result Qualification
smoldot-direct 1,050 frames / 30,001.1ms; p95 17.7ms; cold/warm 202.9/152.8ms; audio/cache passed PASS under the approved criterion
smoldot-shared-worker 1,038 frames / 30,001.4ms = 34.5983854 FPS; p95 17ms; cold/warm 186.4/158.4ms; other checks passed FAIL: cadence deficit retained
rpc-gateway Warm-readiness helper timed out. Its null snapshot conflated missing frame, missing canvas and evaluation errors, and earlier cold/cadence values were not retained by that helper NOT QUALIFIED; iframe disappearance is not established

Distinct diagnostics found no presentation loss in a later instrumented 24-second shared-worker sample and observed a successful hidden RPC new-document reload. Neither diagnostic supersedes the failures or qualifies performance. No evidence-proved runtime fix, guest rebuild, speculative tuning, or further unchanged gate rerun was made. The original strict RPC failure and every new failure remain retained. Next causal capture must instrument the original early 30-second window and distinguish warm lifecycle states before proposing a runtime fix.

Retention and rollout boundary

Local verification used paseo-next-v2, the pinned host-playground fixture f56294cea4430163bf16ec068844b1327441073c, and existing private QA identities. All three corrected sequences paired on their first existing setup attempt. A prior local launch failure and a misconfigured Previewnet-product run (34 passed, 20 skipped, 8 Chain/Contract failures) are retained separately, not presented as reproductions of the hosted Genesis timeout. Private traces/auth/signers were not published.

The first repair heads also exposed a README formatting failure (corrected by documentation-only commits) and a PVM cache-unit-test 5,000ms timeout. No cache runtime/test change, limit increase, or causal claim was made for that isolated timeout. Older in-flight runs superseded by the formatting correction remain recorded as cancelled, not passed.

No PR merge, force push, deployment, environment approval, SDK/npm/product/guest publication, or rollback was performed by this repair. JAM remains JAM-TEST-INSTANCE, never JAM-PUBLIC-DEVNET. The user-owned deploy: paseo.fyi label is retained; repair-triggered deployment runs 36970790399 and 36971286469 were cancelled before deployment. The earlier rollout audit is retained below: an older workflow deployed 56cea5d37577bf82684fb5c6b6e4ba81d2142938; this record does not claim live remained unchanged historically.

Historical integration qualification (superseded; retained verbatim)

Current main refresh and qualification — 2026-10-01

  • Current source: 7e65d2eb8d73b7db49ef1f3681377a0db8998db2. Native main bda6ac518c8cc59319491b12e4e23b96777375fd is integrated; the frontend stack includes dotli main f4012c50c3400d1186c332ad2ae50298cefd153d (merged chore(deps): bump postcss from 8.5.15 to 8.5.23 in /explorer #313). Histories and worktrees were preserved; pushes used fetched-head ancestry guards, never force.
  • Canonical jam artifact-generation revision: e51563a447a03666316c2f3e99e734866696b4cd. Later native changes are test/docs/iOS-only, not SDK/Wasm inputs, so the artifact pin intentionally differs from the current head. Complete matching client and host packages remain 0.23.0, generated rather than hand-edited. Browser signing Wasm uses web-wasm-signing-host without test-host; testing Wasm is separate.
  • Browser consumers: dotli #291 at dcdef40499119183aed82a39f784ef740d494341.
Canonical artifact SHA-256
Client npm archive 1103910932941a1d57deb4b7278b40c22c1489bbd11c609e398dd4418922d850
Client dist/generated/client.js (not dist/index.js) 79d8b4a1ec6c94af558cd7ad59e52aa4c8fb3c3634bb8dd3c0cb46126b4fab78
Host npm archive 06f4b0798c02bb4ba17f346ca897b02a5943b30773c92c1f42eeec0f2460de30
Browser signing Wasm 28e16236f7396fd188e7a2b8df98fe7d150957c3f5b3b21f2ba8b71d373e9439

Qualification

  • Frontend #291 exact-head Tests: functional 91 passed, 3 skipped; E2E 42 passed, 20 skipped. No flaky case in this final hosted Tests run.

  • Current-head Core CI: 24 required jobs green — 22 passed, 2 path-filter skips. This includes core Swift/Android coverage, not a claim that full iOS application CI ran at this head. The separate existing release-signing-credentials advisory failure remains distinct from Core CI.

  • Local: Full local formatting, build, clippy and Rust tests passed. Client/host SDK: 330/326 passed; local Swift and Android qualification passed. Live JAM test passed (1 test, 0.86s). Canonical codegen and complete feature-specific package construction were qualified locally.

  • Browser/native proof: Both feature boundaries remain intact. The combined branch passed real certificate-verified JAM-TEST-INSTANCE WebTransport/UP0 through the installed PVM host-frame-request path, full-genesis trusted consent, grant isolation, close/reset, pagehide disposal/stale-frame rejection, and replacement-execution re-consent. Genesis: 0x10c123f02eb6df4c01397d797a112055be691883baa2e82f83b618ed6ce45e46. No TLS bypass or new published guest. Evidence: main-refresh-jam-pvm-live.json and screenshots; Seity encrypted-content evidence is separately scoped above the Chat layer.

Retained cross-stack limits

  • The isolated strict Doom matrix is not fully green: RPC measured 34.54231433545555 FPS against ≥35 FPS. Direct smoldot measured 35.06721215581914 and shared-worker smoldot 35.48895899032775. All three passed p95/cold/warm/cache/audio criteria; warm runs used a new document and zero translation. No threshold, clock, timeout, or retry policy was weakened.
  • Latest local Seity E2E attempt: 41 passed, 20 existing skips, 1 Submit failure (Extrinsic marked as invalid). Two existing native broadcast attempts were validated then invalidated; none was found included in the inspected canonical range. [INFERENCE] Noncanonical mortality anchors may explain invalidation; the exact cause is not established and signed extrinsic bytes were not retained. The earlier Factory deadline failure is also retained: inclusion took 47,516ms against the unchanged 30s product deadline. A separate unchanged manual Factory attempt passed in 10.918s. These failures are not erased by other passing checks.
  • Evidence JSON/screenshots are retained beside the refresh worktrees; private browser profiles and throwaway harnesses were removed. No bearer references, keys, signing configuration, or .auth contents are included here.

This refresh authorizes no deployment, environment approval, PR merge, SDK/npm publication, or guest/product publication. Its QA writes were testnet-only.

All three refresh-triggered JAM Deploy runs were cancelled before rollout; final-head cancellation proof is for frontend dcdef40499119183aed82a39f784ef740d494341. No refreshed source head was deployed.

The live environment changed during qualification: older Deploy run 36945647296, attempt 3 was approved under GitHub account replghost, explicitly checked out baseline 56cea5d37577bf82684fb5c6b6e4ba81d2142938, and recorded deployment success at 2026-10-02 01:19:01 UTC. Its later published-product smoke failed. The operator/client/session behind that account is unproven; this qualification granted no approval and performed no rollback. The observed live content hash changed from 4a7caf047fb7f350c1833039b93ba634698a47c56f051b8c7fc0525d4c59a5c8 to 5882695ee20df5d24a6ed2feb9e997f176fe27ecf4eafe742fabb39eba92885f; these are content hashes, not Git SHAs, and their exact byte-level mapping to a source commit is unproven. Earlier revision/deployment records below remain historical evidence and do not override this current section.

Earlier source and qualification (superseded)

Head 4b8a264c917b26df96e5e72e416060612d014326 includes main aa6ae62ca038bf4a6356edae8eb78e595d52ce24 through history-preserving merge commits. Client and host package manifests remain 0.23.0 with pending Changesets.

Canonical pinned-nightly codegen, client/host TypeScript builds, CLI typecheck, release-version check, pinned rustfmt, and 330 client tests pass locally. An actual Swift storage smoke proves granted foreign reads reach the owner while writes and clears remain caller-scoped. Profile trait 69, JAM trait 111, Chat authority and no-std guest boundaries remain separate.

Current-head core CI passes, including Rust workspace, default WASM bridge, Android compile/unit checks, and iOS Swift + WebKit. Full local workspace/native qualification was interrupted by workstation disk exhaustion; the full current-head core CI gate completes that qualification. Full iOS application CI also passes, including the in-tree core, application build, simulator preview, and tests. No PR was merged or approved, and no npm package was published. Deployment evidence below belongs to the explicitly named earlier revisions, not this source refresh.

Summary

Deployment integration of Seity #1001 and JamPeerTransport #1010. Feature implementations remain reviewed in the parent PRs; this layer integrates them with canonical generated bindings.

Stack

#540 → #709 → #1001 → this PR, with #1010 merged in. Main is integrated through c5158448f3c4575f40350017d466053d6b19dacb. Published branch history is preserved with merge commits.

This layer is not intended to merge into #1001. Once #1010 flows through the base and reaches Seity, this integration layer can be closed.

Contract and artifacts

  • Profile uses wire trait 69; JamPeerTransport uses wire trait 111. Both use the canonical codegen catalog.
  • Chat authority and genesis-scoped peer permission keys remain separate. Stored denial remains authoritative. The integration retains the latest Chat per-peer bounds, session-consent and claim-settlement fixes, plus both private rich-frame and Profile-reference stripping.
  • Active browser consumer: chore(deploy): Seity layer + JamPeerTransport (#287 + #290) dotli-community#291.
  • Refreshed browser artifacts: matching TrUAPI client/host 0.23.0 and wallet/testing WASM built from af087f734be4d65d9363e68e43bf134145ae0085. Consumer integration and qualification are tracked in chore(deploy): Seity layer + JamPeerTransport (#287 + #290) dotli-community#291; its vendor lock records the published archive, generated-client/WASM digests, and build features.
  • Native source and the refreshed browser artifacts include Profile disclosure V2 with independent app/contact audiences, contact presentation V2 selectors, avatar placement V3, and host-private Contacts integration. The user explicitly selected rollout of this newer sharing contract on experimental paseo.fyi; its deployment qualification is tracked separately from the historical evidence below.

Earlier qualification evidence

Local native all-target/all-feature checking and wallet/testing WASM builds pass. A real Chromium session with the combined consumer rendered the published guest, completed a canonical SDK handshake over its live host port, and decoded a Profile domain rejection for a malformed reference.

The user-approved paseo.fyi deployment at 032e97128983570eac9c32d6cd9dd8a41d181bca, with combined host source af087f734be4d65d9363e68e43bf134145ae0085, passes all eight published PolkaVM product scenarios and all 19 wallet-free TrUAPI capability checks. Product smoke opts in through real Settings; the production execution gate remains default-off. Independent fresh-context Chromium verification observed that exact release and passed feature discovery, JSON storage round-trip, and a live chain-genesis query. This does not qualify live Profile/Contacts/avatar-sharing, own-profile/avatar-fetch, or a new JAM-validator transport trial.

The previous deployment 57aaf948a7b9d9fb6f35b9a731ad9cad9856a859 and run 36640362244 remain historical qualification, not evidence reassigned to the newer artifact contract.

At af087f734be4d65d9363e68e43bf134145ae0085, all host PR checks pass, including core CI and full iOS build, tests, and preview. Canonical code generation, TypeScript client/host builds, and release wallet/testing WASM builds pass locally for this source. The integrated iOS workflow retains xcresult, raw logs, and crash diagnostics on failure; no tests or retry behavior are weakened.

Shared permission descriptions, icons, and settings titles are centralized on ProductPermission, preserving the distinct JAM prompt wording. Strict scoped SwiftLint reports zero violations, and the full iOS warning ratchet passes without baseline changes or suppressions.

The iOS combined store uses model 53, retaining both historical main and Chat model-49 variants. Real SQLite migration smoke checks passed from main model 49, Chat model 49, and main model 52, preserving payment amounts, owner identity, and native Coinage ledger payloads. The permanent migration regression runs in the app suite. This iOS-only correction does not change the vendored browser SDK artifacts.

Adds TrUAPI trait 21, PeerTransport: host-terminated JAMNP-S streams to
JAM peers (dial/open/send/recv/reset/close/events). The host terminates
QUIC or WebTransport, builds the jamnp-s ALPN from the declared genesis
and pins the peer's certificate identity; the guest verifies every byte
it receives.

A host may grant it only to an execution whose App manifest v2 declares
capabilities.network.jam = { genesis }, for that genesis only, with
bounded connections, streams and message sizes. The default
implementation, including the Rust product runtime, returns NotGranted.

Ships the browser WebTransport session and the deterministic PolkaJAM
certificate-hash derivation under @parity/truapi/peer-transport, with
SCALE codec vectors pinned against the Rust types.
Contacts (#17) and Game (#990) both claim trait 20, so whichever lands
second is expected to take 21, and Profile holds 22. 23 keeps
PeerTransport clear of all three before any guest bakes the id in.
…ment

# Conflicts:
#	rust/crates/truapi-client/src/generated.rs
#	rust/crates/truapi-server/src/runtime/capabilities/resources.rs
# Conflicts:
#	rust/crates/truapi-client/src/generated.rs
@github-actions github-actions Bot added javascript Pull requests that update javascript code rust Pull requests that update rust code labels Sep 26, 2026
@github-actions

github-actions Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

CI Status: 24 required jobs green, 22 passed and 2 skipped by path filter.

All job results
job result
android-bindings success
bundle-size success
changes success
changeset-guard success
cli-package success
codegen success
e2e skipped
explorer success
headless-install success
host-android-bindings success
host-android-detekt success
host-wasm success
ios-bindings success
ios-swift success
licenses success
playground success
provider-android-bindings success
release-guard success
rust success
ts-client success
ts-debugger success
ts-host success
wasm-provider success
workflow-lint skipped

Signing credentials: failure as of 2026-10-02, a release may fail

Commit f7ac212c · run log

@github-actions

github-actions Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

iOS simulator preview

Built from 4b8a264c9, stamped with it in TrUAPICommit.

gh run download 36743659542 --name simulator-preview-4b8a264c9
unzip polkadot-app-*.app.zip
xcrun simctl install booted polkadot-app.app
xcrun simctl launch booted io.parity.polkadotapp.develop

Or download it in a browser, which arrives as a zip wrapping
the .app.zip, so it needs unzipping twice.

An arm64 simulator slice, so it needs an Apple Silicon Mac and does not
install on a device. Kept for 14 days, after which the link stops
resolving and a new push rebuilds it.

Peer access is now a runtime permission rather than an App-manifest
capability, matching the rest of TrUAPI (Remote, WebRtc, ChainSubmit).
RemotePermission gains JamPeers { genesis }, appended as variant 5 so
every earlier index is unchanged; its decision is stored per product and
genesis like any other remote permission.

ProductRuntimeHost::require_jam_peers checks the stored decision,
prompts while it is undetermined and persists the answer, keeping a
one-use grant for the execution so a light client dialing several
validators is asked once per genesis. The product runtime's
PeerTransport still answers NotGranted. The manifest grant and its
parser are gone; the genesis parser and ALPN helper stay.

The browser session takes an authorize(genesis) callback instead of a
fixed genesis, asks once per genesis per session and shares a pending
answer between concurrent dials. The Android and iOS product bridges
deny JamPeers without a prompt, as neither ships a JAM transport.
Brings #1010's switch from the manifest grant to the
RemotePermission::JamPeers runtime permission into the Seity layer.
Kept both sides of the permission storage-key test (Chat authority and
JamPeers keys); regenerated the client catalog wire hash with codegen.
@github-actions github-actions Bot added documentation Improvements or additions to documentation rfc host-ios Touches the iOS host tree host-android Touches the Android host tree labels Sep 27, 2026
A dial waiting on the JamPeers prompt could outlast the guest's request
timeout; the guest retried and the original dial later opened a
connection nobody knew about, holding a slot until the session closed.
Dials now answer within 10 s (prompt + handshake), CANCEL withdraws an
in-flight dial with Cancelled, and anything opened after withdrawal is
closed without holding a slot. The permission decision is still
remembered.
@replghost replghost changed the title chore(deploy): Seity layer + PeerTransport (#1001 + #1010) chore(deploy): Seity layer + JamPeerTransport (#1001 + #1010) Sep 27, 2026
replghost added a commit to paritytech/dotli-community that referenced this pull request Sep 27, 2026
Brings in the JamPeerTransport rename (#290 at 8980057). Only vendor/
conflicted; it is rebuilt from paritytech/trinity-user-agents#1011
(feat/jam-peer-transport-on-seity) at c85c26b6, the --no-ff merge of the
renamed #1010. Wire-identical: trait 23, methods 0..6, JamPeers.
…7df169ec821ff1a21a8081ab89bc4f02c816' into HEAD
…e5c44850a5f87606bf065a7603a17c342ed8' into HEAD
…inalized-anchor-20261002

# Conflicts:
#	rust/crates/truapi-client/src/generated.rs
#	rust/crates/truapi/src/host_core.rs
# Conflicts:
#	rust/crates/truapi/Cargo.toml
# Conflicts:
#	rust/crates/truapi/Cargo.toml
# Conflicts:
#	js/packages/truapi-host/README.md
…egration

# Conflicts:
#	rust/crates/truapi-client/src/generated.rs
# Conflicts:
#	rust/crates/truapi-client/src/generated.rs
# Conflicts:
#	rust/crates/truapi-client/src/generated.rs

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation github_actions Pull requests that update GitHub Actions code host-android Touches the Android host tree host-ios Touches the iOS host tree javascript Pull requests that update javascript code rfc rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants