From 0ca6da8d252a6cc8a829e132461365cc3829b02f Mon Sep 17 00:00:00 2001
From: "github-actions[bot]"
<41898282+github-actions[bot]@users.noreply.github.com>
Date: Sat, 3 Oct 2026 06:12:04 +0000
Subject: [PATCH 1/2] chore(hosts): open a backport work order for android
hosts/android is 5 commits behind its source, 7c239096b65b62b9d1de1b1cdef6ab4f7fba202e to edc2867a91cd427e1c225fb203b0b4ce18fb8174. BACKPORT-android.md carries the range and what has to be done; it is deleted by whoever completes this.
---
BACKPORT-android.md | 61 +++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 61 insertions(+)
create mode 100644 BACKPORT-android.md
diff --git a/BACKPORT-android.md b/BACKPORT-android.md
new file mode 100644
index 0000000000..7b4f1d360f
--- /dev/null
+++ b/BACKPORT-android.md
@@ -0,0 +1,61 @@
+# Backport hosts/android
+
+Work order. Everything below describes what is missing from this repository; nothing here has been applied yet.
+
+Changes move one way, from `https://github.com/paritytech/polkadot-android-community` into `hosts/android`. Nothing in this repository is sent back the other way.
+
+| | |
+| --- | --- |
+| source | https://github.com/paritytech/polkadot-android-community (`main`) |
+| from | `7c239096b65b62b9d1de1b1cdef6ab4f7fba202e` |
+| to | `edc2867a91cd427e1c225fb203b0b4ce18fb8174` |
+| commits | 5 |
+
+## Pull requests in the range
+
+Taken from the commit subjects, so a commit that landed without a number is not listed here. The full list is below it.
+
+- [#226](https://github.com/paritytech/polkadot-android-community/pull/226)
+
+
+All 5 commits
+
+```
+a66140aba chore(product-sample): regenerate package-lock.json from the npm registry
+0e03f0465 chore(bindings): declare GPL-3.0-or-later in the Rust crate manifests
+450ed32e6 docs(readme): surface the root README as the repo front page and add the DYOR clause
+51299c0d3 docs(coinage): refer to the coinage reference implementation without naming the repo
+edc2867a9 Merge pull request #226 from paritytech/chore/opensourcing-audit-fixes
+```
+
+
+
+## How to finish this
+
+You are completing this pull request. Work on its branch and push to it.
+
+1. Run the refresh. Do not merge the trees by hand:
+
+ ```bash
+ scripts/refresh-host-import.sh refresh android
+ ```
+
+ It replaces `hosts/android` with the source's tree, re-applies this repository's adaptations as a three-way patch, and compares every path against the source by blob hash in both directions. That comparison is the point: it is what catches upstream work silently dropped and adaptations that no longer apply. A hand-merge produces a plausible tree and none of those checks.
+
+2. Read what it reports before committing.
+
+ - A conflict is left unmerged on purpose, so git refuses to commit it. Resolve each one, keeping this repository's adaptation unless the source has clearly superseded it.
+ - `adaptation left no difference` means either the source adopted that change or it did not apply. Check which, and say so in the pull request.
+ - If the script refuses the result outright, do not force it. Recover with `git reset --hard HEAD` and say what happened.
+
+3. Build what the change touches. An upstream change that adds a requirement to a protocol will not show up as a conflict, because the comparison reads content and not types; it shows up as a conformer in this repository that no longer compiles.
+
+4. Decide whether this backport is a breaking change. Read the pull requests listed above against `.claude/skills/semver-pr-title/SKILL.md`. If any of them makes a tester lose data or a session, reinstall, or find a feature gone, or makes a product change its code, retitle this pull request with `!`, for example `chore(hosts)!: backport 5 commits into hosts/android`, and name what breaks in its description. The nightly announcement lists `!` titles first.
+
+5. Delete this file. It is the work order, not part of the tree:
+
+ ```bash
+ git rm BACKPORT-android.md
+ ```
+
+6. Commit the refreshed tree, `hosts/imports.json` with its new ref, and the deletion together, then push. That push is what starts CI on this pull request.
From 903bf34b627abc68f0b2063beee9fdf151707f0a Mon Sep 17 00:00:00 2001
From: tarikgul
Date: Sun, 4 Oct 2026 18:24:52 -0400
Subject: [PATCH 2/2] chore(hosts): backport 5 commits into hosts/android
Refresh hosts/android to polkadot-android-community edc2867a9 (#226). No
conflicts, and every difference from the source is one of this
repository's adaptations.
---
BACKPORT-android.md | 61 -------------------
hosts/android/.github/{README.md => CI.md} | 0
hosts/android/README.md | 2 +-
.../bandersnatch-crypto/rust/Cargo.toml | 2 +-
.../bindings/hydra-dx-math/rust/Cargo.toml | 2 +-
.../bindings/sr25519-vrf/rust/Cargo.toml | 2 +-
.../products/product-sample/package-lock.json | 40 ++++++------
.../pocket/coins/CoinageAssetStore.kt | 6 +-
.../pocket/coins/CoinageStripLayout.kt | 4 +-
.../pocket/coins/CoinageConformanceTest.kt | 5 +-
.../resources/coinage/conformance/README.md | 6 +-
hosts/imports.json | 2 +-
12 files changed, 36 insertions(+), 96 deletions(-)
delete mode 100644 BACKPORT-android.md
rename hosts/android/.github/{README.md => CI.md} (100%)
diff --git a/BACKPORT-android.md b/BACKPORT-android.md
deleted file mode 100644
index 7b4f1d360f..0000000000
--- a/BACKPORT-android.md
+++ /dev/null
@@ -1,61 +0,0 @@
-# Backport hosts/android
-
-Work order. Everything below describes what is missing from this repository; nothing here has been applied yet.
-
-Changes move one way, from `https://github.com/paritytech/polkadot-android-community` into `hosts/android`. Nothing in this repository is sent back the other way.
-
-| | |
-| --- | --- |
-| source | https://github.com/paritytech/polkadot-android-community (`main`) |
-| from | `7c239096b65b62b9d1de1b1cdef6ab4f7fba202e` |
-| to | `edc2867a91cd427e1c225fb203b0b4ce18fb8174` |
-| commits | 5 |
-
-## Pull requests in the range
-
-Taken from the commit subjects, so a commit that landed without a number is not listed here. The full list is below it.
-
-- [#226](https://github.com/paritytech/polkadot-android-community/pull/226)
-
-
-All 5 commits
-
-```
-a66140aba chore(product-sample): regenerate package-lock.json from the npm registry
-0e03f0465 chore(bindings): declare GPL-3.0-or-later in the Rust crate manifests
-450ed32e6 docs(readme): surface the root README as the repo front page and add the DYOR clause
-51299c0d3 docs(coinage): refer to the coinage reference implementation without naming the repo
-edc2867a9 Merge pull request #226 from paritytech/chore/opensourcing-audit-fixes
-```
-
-
-
-## How to finish this
-
-You are completing this pull request. Work on its branch and push to it.
-
-1. Run the refresh. Do not merge the trees by hand:
-
- ```bash
- scripts/refresh-host-import.sh refresh android
- ```
-
- It replaces `hosts/android` with the source's tree, re-applies this repository's adaptations as a three-way patch, and compares every path against the source by blob hash in both directions. That comparison is the point: it is what catches upstream work silently dropped and adaptations that no longer apply. A hand-merge produces a plausible tree and none of those checks.
-
-2. Read what it reports before committing.
-
- - A conflict is left unmerged on purpose, so git refuses to commit it. Resolve each one, keeping this repository's adaptation unless the source has clearly superseded it.
- - `adaptation left no difference` means either the source adopted that change or it did not apply. Check which, and say so in the pull request.
- - If the script refuses the result outright, do not force it. Recover with `git reset --hard HEAD` and say what happened.
-
-3. Build what the change touches. An upstream change that adds a requirement to a protocol will not show up as a conflict, because the comparison reads content and not types; it shows up as a conformer in this repository that no longer compiles.
-
-4. Decide whether this backport is a breaking change. Read the pull requests listed above against `.claude/skills/semver-pr-title/SKILL.md`. If any of them makes a tester lose data or a session, reinstall, or find a feature gone, or makes a product change its code, retitle this pull request with `!`, for example `chore(hosts)!: backport 5 commits into hosts/android`, and name what breaks in its description. The nightly announcement lists `!` titles first.
-
-5. Delete this file. It is the work order, not part of the tree:
-
- ```bash
- git rm BACKPORT-android.md
- ```
-
-6. Commit the refreshed tree, `hosts/imports.json` with its new ref, and the deletion together, then push. That push is what starts CI on this pull request.
diff --git a/hosts/android/.github/README.md b/hosts/android/.github/CI.md
similarity index 100%
rename from hosts/android/.github/README.md
rename to hosts/android/.github/CI.md
diff --git a/hosts/android/README.md b/hosts/android/README.md
index 375d7b1efb..56f179115a 100644
--- a/hosts/android/README.md
+++ b/hosts/android/README.md
@@ -1,5 +1,5 @@
> [!WARNING]
-> This is an experimental proof-of-concept: a prototype and reference implementation developed and published by Parity. This open source code is provided for research, experimentation, and developer education only. It has not been audited, is actively experimental, and may contain bugs, vulnerabilities, or incomplete features. The app is a self-custodial wallet that can hold real assets — use at your own risk.
+> This is an experimental proof-of-concept: a prototype and reference implementation developed and published by Parity. This open source code is provided for research, experimentation, and developer education only. It has not been audited, is actively experimental, and may contain bugs, vulnerabilities, or incomplete features. The app is a self-custodial wallet that can hold real assets — use at your own risk and obtain legal advice as appropriate — DYOR.
>
> Parity does not deploy or operate this code and does not run any service behind it; it may update the code based on community feedback. If you experience problems with an app that was built from or distributed using this code, contact the party who built and distributed it, not Parity.
diff --git a/hosts/android/bindings/bandersnatch-crypto/rust/Cargo.toml b/hosts/android/bindings/bandersnatch-crypto/rust/Cargo.toml
index 5016a3346f..6c4eecece6 100644
--- a/hosts/android/bindings/bandersnatch-crypto/rust/Cargo.toml
+++ b/hosts/android/bindings/bandersnatch-crypto/rust/Cargo.toml
@@ -1,7 +1,7 @@
[package]
authors = ['Parity Technologies']
edition = '2021'
-license = 'Apache 2.0'
+license = 'GPL-3.0-or-later'
name = "bandersnatch-crypto"
repository = 'https://github.com/paritytech/polkadot-android-community'
version = "0.1.0"
diff --git a/hosts/android/bindings/hydra-dx-math/rust/Cargo.toml b/hosts/android/bindings/hydra-dx-math/rust/Cargo.toml
index 364a3086aa..bab5d958ea 100644
--- a/hosts/android/bindings/hydra-dx-math/rust/Cargo.toml
+++ b/hosts/android/bindings/hydra-dx-math/rust/Cargo.toml
@@ -1,7 +1,7 @@
[package]
authors = ['Parity Technologies']
edition = '2021'
-license = 'Apache 2.0'
+license = 'GPL-3.0-or-later'
name = "hydra-dx-math-java"
repository = 'https://github.com/paritytech/polkadot-android-community'
version = "0.1.0"
diff --git a/hosts/android/bindings/sr25519-vrf/rust/Cargo.toml b/hosts/android/bindings/sr25519-vrf/rust/Cargo.toml
index 54770d26e5..1bf963ce75 100644
--- a/hosts/android/bindings/sr25519-vrf/rust/Cargo.toml
+++ b/hosts/android/bindings/sr25519-vrf/rust/Cargo.toml
@@ -1,7 +1,7 @@
[package]
authors = ['Parity Technologies']
edition = '2021'
-license = 'Apache 2.0'
+license = 'GPL-3.0-or-later'
name = "sr25519-vrf"
repository = 'https://github.com/paritytech/polkadot-android-community'
version = "0.1.0"
diff --git a/hosts/android/feature/products/product-sample/package-lock.json b/hosts/android/feature/products/product-sample/package-lock.json
index abf8c0a6c2..458d5dd7f0 100644
--- a/hosts/android/feature/products/product-sample/package-lock.json
+++ b/hosts/android/feature/products/product-sample/package-lock.json
@@ -9,10 +9,10 @@
"version": "1.0.0",
"hasInstallScript": true,
"dependencies": {
- "@novasamatech/host-api": "file:/Users/valentun/WebstormProjects/triangle-js-sdks/local-tarballs/novasamatech-host-api-0.11.0-local.20260911131013.tgz",
- "@novasamatech/host-api-wrapper": "file:/Users/valentun/WebstormProjects/triangle-js-sdks/local-tarballs/novasamatech-host-api-wrapper-0.11.0-local.20260911131013.tgz",
- "@novasamatech/product-react-renderer": "file:/Users/valentun/WebstormProjects/triangle-js-sdks/local-tarballs/novasamatech-product-react-renderer-0.11.0-local.20260911131013.tgz",
- "@novasamatech/scale": "file:/Users/valentun/WebstormProjects/triangle-js-sdks/local-tarballs/novasamatech-scale-0.11.0-local.20260911131013.tgz",
+ "@novasamatech/host-api": "0.12.0",
+ "@novasamatech/host-api-wrapper": "0.12.0",
+ "@novasamatech/product-react-renderer": "0.12.0",
+ "@novasamatech/scale": "0.12.0",
"@polkadot-api/descriptors": "file:.papi/descriptors",
"@polkadot-api/json-rpc-provider": "^0.2.0",
"@polkadot-api/pjs-signer": "^0.6.19",
@@ -487,12 +487,12 @@
}
},
"node_modules/@novasamatech/host-api": {
- "version": "0.11.0-local.20260911131013",
- "resolved": "file:../../../../../WebstormProjects/triangle-js-sdks/local-tarballs/novasamatech-host-api-0.11.0-local.20260911131013.tgz",
- "integrity": "sha512-SdgYN8gf0Eupq7nmraH3WPOC7GIvGzE4yyGgZN9MD24X5XosY0CWCb7Yc2jdYtl5+QVJB8ginTfE/z1V5RrbnQ==",
+ "version": "0.12.0",
+ "resolved": "https://registry.npmjs.org/@novasamatech/host-api/-/host-api-0.12.0.tgz",
+ "integrity": "sha512-1wvhk/3zz8tQ0Xp+Us9k7NDMmSkRkx4v7l3+5bkdEg1Ia1CShclRVx8IpRl7YVAD52v4oNVmYEo5MLNjBtAeEw==",
"license": "Apache-2.0",
"dependencies": {
- "@novasamatech/scale": "0.11.0-local.20260911131013",
+ "@novasamatech/scale": "0.12.0",
"nanoevents": "10.0.0",
"nanoid": "6.0.1",
"neverthrow": "^8.2.0",
@@ -500,12 +500,12 @@
}
},
"node_modules/@novasamatech/host-api-wrapper": {
- "version": "0.11.0-local.20260911131013",
- "resolved": "file:../../../../../WebstormProjects/triangle-js-sdks/local-tarballs/novasamatech-host-api-wrapper-0.11.0-local.20260911131013.tgz",
- "integrity": "sha512-ex9VGVRvz8Y2AWqC+/yDwEGYVXdPTZt0e1aoVAlwgifkcIGLeLeNd8aPJVHC8YqaqmWLrKGMUs9b8kVEoPolcw==",
+ "version": "0.12.0",
+ "resolved": "https://registry.npmjs.org/@novasamatech/host-api-wrapper/-/host-api-wrapper-0.12.0.tgz",
+ "integrity": "sha512-2kuxEcv1ogU8X/I7xr+L2omUa+7IMg/TuCCaVP4iRnvwp4s4HEtewBOf3aMtkZPykJheRv9rXi1IGcE8UWZSmQ==",
"license": "Apache-2.0",
"dependencies": {
- "@novasamatech/host-api": "0.11.0-local.20260911131013",
+ "@novasamatech/host-api": "0.12.0",
"@polkadot-api/json-rpc-provider-proxy": "^0.4.0",
"@polkadot-api/signers-common": "^0.3.0",
"@polkadot-api/substrate-bindings": "^0.21.0",
@@ -540,13 +540,13 @@
}
},
"node_modules/@novasamatech/product-react-renderer": {
- "version": "0.11.0-local.20260911131013",
- "resolved": "file:../../../../../WebstormProjects/triangle-js-sdks/local-tarballs/novasamatech-product-react-renderer-0.11.0-local.20260911131013.tgz",
- "integrity": "sha512-nBKPGOlDkKc/Er98xtxSn5YmCMlAO8tNXW9+pv/H05yZXxZ3v6GA2FrWVkhomGfLiCAc60t2XOpYw4PniVLXSQ==",
+ "version": "0.12.0",
+ "resolved": "https://registry.npmjs.org/@novasamatech/product-react-renderer/-/product-react-renderer-0.12.0.tgz",
+ "integrity": "sha512-WvPwSDzfdQXU70f2nGAnKtZ6Owbqx2IO8JNAm+ZrKVy1EE2gTxS3hGKeSHAgO6yNz4dfw0PRXzu6A1vJsHAuxg==",
"license": "Apache-2.0",
"dependencies": {
- "@novasamatech/host-api": "0.11.0-local.20260911131013",
- "@novasamatech/host-api-wrapper": "0.11.0-local.20260911131013",
+ "@novasamatech/host-api": "0.12.0",
+ "@novasamatech/host-api-wrapper": "0.12.0",
"react-reconciler": "0.33.0",
"scale-ts": "1.6.1"
},
@@ -555,9 +555,9 @@
}
},
"node_modules/@novasamatech/scale": {
- "version": "0.11.0-local.20260911131013",
- "resolved": "file:../../../../../WebstormProjects/triangle-js-sdks/local-tarballs/novasamatech-scale-0.11.0-local.20260911131013.tgz",
- "integrity": "sha512-x/OirPqgAcEQMv0N4eSmPzNmLXhBBAAlofkD5k6/4NdRagaZe/uV9IuNpsgFf0/DaG9deYgHZUTiGlDFQKZ3sA==",
+ "version": "0.12.0",
+ "resolved": "https://registry.npmjs.org/@novasamatech/scale/-/scale-0.12.0.tgz",
+ "integrity": "sha512-LwqkDLfeK82hdbOxEDfq7huMbeq/UXKhNPtkbkU68keLY0wvHrZ2rw1ibzDqspM6KWUPAxuWXbmGEM+cZJyxBg==",
"license": "Apache-2.0",
"dependencies": {
"@polkadot-api/utils": "^0.4.0",
diff --git a/hosts/android/feature/wallet/impl/src/main/java/io/paritytech/polkadotapp/feature_wallet_impl/presentation/pocket/coins/CoinageAssetStore.kt b/hosts/android/feature/wallet/impl/src/main/java/io/paritytech/polkadotapp/feature_wallet_impl/presentation/pocket/coins/CoinageAssetStore.kt
index 1a5a9a6376..6cfc4b988c 100644
--- a/hosts/android/feature/wallet/impl/src/main/java/io/paritytech/polkadotapp/feature_wallet_impl/presentation/pocket/coins/CoinageAssetStore.kt
+++ b/hosts/android/feature/wallet/impl/src/main/java/io/paritytech/polkadotapp/feature_wallet_impl/presentation/pocket/coins/CoinageAssetStore.kt
@@ -13,9 +13,9 @@ import java.util.concurrent.Executors
* Everything the coin renderer draws with, decoded once: the meshes, the struck-relief atlas, the studio
* environment, the shaders and the constants the material reads.
*
- * All of it is exported by `paritytech/coinage-viz` (`npm run export:native`, which writes
- * `public/native/assets`) and vendored under `assets/coinage`. The constants arrive as data rather than as
- * code, so a material change is a file change here.
+ * All of it is exported by the maintainers' internal coinage reference implementation and vendored under
+ * `assets/coinage`. The constants arrive as data rather than as code, so a material change is a file change
+ * here.
*
* That project has done its job and nothing regenerates these files. Changing a coin face, a shape or the
* studio means reproducing the export, and it needs four things that were never upstreamed. Written down
diff --git a/hosts/android/feature/wallet/impl/src/main/java/io/paritytech/polkadotapp/feature_wallet_impl/presentation/pocket/coins/CoinageStripLayout.kt b/hosts/android/feature/wallet/impl/src/main/java/io/paritytech/polkadotapp/feature_wallet_impl/presentation/pocket/coins/CoinageStripLayout.kt
index 306c6d09ae..6343c06f32 100644
--- a/hosts/android/feature/wallet/impl/src/main/java/io/paritytech/polkadotapp/feature_wallet_impl/presentation/pocket/coins/CoinageStripLayout.kt
+++ b/hosts/android/feature/wallet/impl/src/main/java/io/paritytech/polkadotapp/feature_wallet_impl/presentation/pocket/coins/CoinageStripLayout.kt
@@ -10,8 +10,8 @@ import kotlin.math.sqrt
/**
* The summary strip: every coin at a fixed height, in a fixed width.
*
- * Ported line for line from `src/layout/strip.js` in the `coinage-viz` reference and checked against its
- * conformance vectors, so the two stay the same strip.
+ * Ported line for line from the strip layout in the maintainers' internal coinage reference implementation
+ * and checked against its conformance vectors, so the two stay the same strip.
*
* As coins are added the strip gives ground in a fixed order. First the margins close, from ten points
* toward four, which is why ten coins keep their full margin and nothing jumps at the coin that first does
diff --git a/hosts/android/feature/wallet/impl/src/test/java/io/paritytech/polkadotapp/feature_wallet_impl/presentation/pocket/coins/CoinageConformanceTest.kt b/hosts/android/feature/wallet/impl/src/test/java/io/paritytech/polkadotapp/feature_wallet_impl/presentation/pocket/coins/CoinageConformanceTest.kt
index a6c5934469..0b9fcf5daf 100644
--- a/hosts/android/feature/wallet/impl/src/test/java/io/paritytech/polkadotapp/feature_wallet_impl/presentation/pocket/coins/CoinageConformanceTest.kt
+++ b/hosts/android/feature/wallet/impl/src/test/java/io/paritytech/polkadotapp/feature_wallet_impl/presentation/pocket/coins/CoinageConformanceTest.kt
@@ -7,8 +7,9 @@ import org.junit.Test
import kotlin.math.abs
/**
- * Checks the ported layout and motion against the vectors `coinage-viz` exports, so the strip on the phone is
- * the strip in the reference rather than something that merely resembles it.
+ * Checks the ported layout and motion against the vectors the maintainers' internal coinage reference
+ * implementation exports, so the strip on the phone is the strip in the reference rather than something that
+ * merely resembles it.
*
* The vectors are vendored verbatim under `resources/coinage/conformance` and shared with the iOS port, so a
* drift between the two platforms shows up here rather than on a screen.
diff --git a/hosts/android/feature/wallet/impl/src/test/resources/coinage/conformance/README.md b/hosts/android/feature/wallet/impl/src/test/resources/coinage/conformance/README.md
index 513ce73dfc..4fd1670e15 100644
--- a/hosts/android/feature/wallet/impl/src/test/resources/coinage/conformance/README.md
+++ b/hosts/android/feature/wallet/impl/src/test/resources/coinage/conformance/README.md
@@ -1,3 +1,3 @@
-Conformance vectors copied verbatim from `paritytech/coinage-viz`
-(`public/native/assets/conformance/`). Regenerate them there with
-`npm run export:native`; do not hand-edit them here.
+Conformance vectors copied verbatim from the maintainers' internal
+coinage reference implementation. Regenerated and re-exported by the
+maintainers; do not hand-edit them here.
diff --git a/hosts/imports.json b/hosts/imports.json
index ef70421ba3..37e5a753ee 100644
--- a/hosts/imports.json
+++ b/hosts/imports.json
@@ -1,7 +1,7 @@
{
"android": {
"branch": "main",
- "ref": "7c239096b65b62b9d1de1b1cdef6ab4f7fba202e",
+ "ref": "edc2867a91cd427e1c225fb203b0b4ce18fb8174",
"source": "https://github.com/paritytech/polkadot-android-community.git"
},
"ios": {