Conversation
7f73849 to
f6457f1
Compare
|
@pgherveou @eugypalu all required checks are green, including Rust/Clippy, Android, iOS, browser artifacts, and license policy. Could one of you provide the required host-sdk-team approval so the merge queue can admit this dependency? |
pgherveou
left a comment
There was a problem hiding this comment.
can we remove the generated files in the new js packages. Can't these be built from the src files ?
for the new bindings we can also added then to .gitattributes with linguist-generated=true, so that at least they show up as generated artifacts in the code review
|
Addressed in b0e178e: removed the committed browser |
|
Cleanup CI is fully green; ready for rereview and merge queue admission. |
|
DQ: why do all these things need to live in host-rust-core, they don't seem to have dependency on the rust-core stuff, and could be shipped independently ? |
b0e178e to
e0f05c4
Compare
|
They share the Rust core directly rather than only co-locating artifacts:
They could be split, but that would duplicate the Rust source/pins and create independent browser, XCFramework, and AAR versioning with an ABI-drift boundary. Keeping the runtime here makes the host-neutral Rust implementation the single source for all three targets; Epoca/Dotli/Brevity/Desktop remain independent consumers. |
|
Does that shared Rust/UniFFI dependency path resolve the repository-placement concern, or do you want the runtime split into a separate repository before merge? |
|
Additional review completed. Fixed three concrete boundary issues:
Added behavioral browser tests for malformed launch inputs and cross-profile framebuffer submission. Full workspace result: 1,205 tests passed, Clippy Vendored commit |
|
PolkaVM dependency update:
|
23f50c6 to
d0e16fc
Compare
|
Rebased the full PVM series onto current Post-rebase verification:
The PR is now up to date with |
|
Added in 2c08d25:
Consumer cutovers:
Verification remains green: |
|
The repository-placement concern is now resolved by the extraction:
Generated browser output remains source-built and verified in the standalone repository; committed Swift/FFI bindings are marked generated. The full bridge matrix is green. |
8daab08 to
5e04221
Compare
# Conflicts: # rust/crates/truapi-host-cli/src/platform.rs # scripts/codegen.sh # scripts/snapshot-version.sh
|
This pull request touches an app, which is not built by default. Add a label for each build you want:
Each starts as soon as it is added and follows the branch from then on. |
# Conflicts: # js/packages/truapi-host/README.md # js/packages/truapi-host/src/wasm-module.ts # rust/crates/truapi/src/runtime/bulletin_rpc.rs
Current repair qualification — 2026-10-02
a572456b90dc6932476f2fb5a71985fbe9fcbd84. Canonical base artifact-generation and Wasm revisions are this same commit. Prior main-integration baselines are retained: nativebda6ac518c8cc59319491b12e4e23b96777375fd, frontendf4012c50c3400d1186c332ad2ae50298cefd153d.0a24db4aa189adad7b93f9ff508c7949e39196ee; dotli #185 atabca1e079e90781a97fa9492331ddb7ad669d2b7. Complete matching SDK/host packages remain 0.23.0; codegen and Wasm were rebuilt canonically. Generated client bytes are unchanged. Production features:wasm-signing-host; separate testing bundle:wasm-signing-host,test-host.3c060958d3bd519c7c8f5f706115fbb2108be640b2fa8777d50969e3851ef442dist/generated/client.js7ab13b5840a03360f9687d11b14090b5e8685dda6cea22bcee2fd14b9106597379a96ac9f24de2dae05e5e799a7b58d8d9c8f6289fbf31a17bf582331f2453607f794f459e52e50065b1e3a2371e4b5d6330b19185547ee582ee6a565058d7544823ce5910aae52c52f4e0e78436f28b62e4c22465fcb110cd5e64ebb4952cdfNative correction and causal limits
Bulletin mortal signatures now anchor to a finalized checkpoint, while nonce/runtime state comes from the freshest available signing snapshot. A checkpoint at least 64 blocks behind is rejected before broadcast. Regression coverage verifies the actual signature with a newer nonce and older finalized checkpoint, and the expiry boundary. Existing transaction retries/deadlines are unchanged; no chain error is suppressed. The affected test fixture uses
parking_lot::Mutex.The former Seity
Extrinsic marked as invalidrun used noncanonical best-block anchors, but retained evidence lacks the signed bytes and typed pool reason. Fork-sensitive mortality was a real correctness hazard; it is not claimed as the conclusively proved cause of that historical failure. Prior hosted Factory/Genesis timeout causes also remain unproved. No broker/readiness workaround, prewarming, extra retry, or timeout increase was added.Executed verification
-D warnings, CLI build, and canonical browser/testing Wasm packaging. Base full library: 1,246 passed.0a24db4aa189adad7b93f9ff508c7949e39196ee301a235ba13248ef4281e9e3d859919fb6cfbe06d3dc8a41807c36b8bcdf001c47eccb9735305499The Chat/Seity tested heads above precede documentation-only formatting merges; their native/Wasm pins and runtime code are unchanged. Final hosted frontend results are recorded on the linked consumer PRs, separately from these exact-head local results.
Final hosted retest: failures remain
error; it is not evidence of a chain rejection. Retained traces include People-chain/local development sockets but do not expose the Asset Hub gateway WebSocket exchange, so these new failures do not establish an upstream or broker cause.paseo-bulletin-next-ipfs.polkadot.io. The zero-failure host-settings gate correctly failed.Doom: criterion corrected, backend matrix still unqualified
The user explicitly approved 35 FPS sustained over 30 seconds, with one frame of sampling-boundary tolerance:
frames + 1 >= elapsedMs * 35 / 1000. This replaces the instantaneousFPS >= 35sample; it is an acceptance-criterion change, not a runtime speedup. Runtime and displayed FPS are unchanged; raw samples are not rounded to force a pass. Update p95 <28.6ms, cold/warm first-frame limits <3,000/<1,000ms, audio and translation-cache checks remain. The revised official RPC benchmark passed once before the vendor replacement.The later isolated matrix used the rebuilt base pair at frontend
238ab5fa739788b2eb948ba1f807a1876edbacad, with fresh owned Chrome profiles and no concurrent builds/E2E:Distinct diagnostics found no presentation loss in a later instrumented 24-second shared-worker sample and observed a successful hidden RPC new-document reload. Neither diagnostic supersedes the failures or qualifies performance. No evidence-proved runtime fix, guest rebuild, speculative tuning, or further unchanged gate rerun was made. The original strict RPC failure and every new failure remain retained. Next causal capture must instrument the original early 30-second window and distinguish warm lifecycle states before proposing a runtime fix.
Retention and rollout boundary
Local verification used
paseo-next-v2, the pinned host-playground fixturef56294cea4430163bf16ec068844b1327441073c, and existing private QA identities. All three corrected sequences paired on their first existing setup attempt. A prior local launch failure and a misconfigured Previewnet-product run (34 passed, 20 skipped, 8 Chain/Contract failures) are retained separately, not presented as reproductions of the hosted Genesis timeout. Private traces/auth/signers were not published.The first repair heads also exposed a README formatting failure (corrected by documentation-only commits) and a PVM cache-unit-test 5,000ms timeout. No cache runtime/test change, limit increase, or causal claim was made for that isolated timeout. Older in-flight runs superseded by the formatting correction remain recorded as cancelled, not passed.
No PR merge, force push, deployment, environment approval, SDK/npm/product/guest publication, or rollback was performed by this repair. JAM remains JAM-TEST-INSTANCE, never JAM-PUBLIC-DEVNET. The user-owned
deploy: paseo.fyilabel is retained; repair-triggered deployment runs 36970790399 and 36971286469 were cancelled before deployment. The earlier rollout audit is retained below: an older workflow deployed56cea5d37577bf82684fb5c6b6e4ba81d2142938; this record does not claim live remained unchanged historically.Historical integration qualification (superseded; retained verbatim)
Current main refresh and qualification — 2026-10-01
e0a8d59a07e72c4c7f36e6bab6c1db34c06d35dc. Native mainbda6ac518c8cc59319491b12e4e23b96777375fdis integrated; the frontend stack includes dotli mainf4012c50c3400d1186c332ad2ae50298cefd153d(merged chore(deps): bump postcss from 8.5.15 to 8.5.23 in /explorer #313). Histories and worktrees were preserved; pushes used fetched-head ancestry guards, never force.9dcf66544e02b3bb3994e05f3a1400738f742331. Later native changes are test/docs/iOS-only, not SDK/Wasm inputs, so the artifact pin intentionally differs from the current head. Complete matching client and host packages remain 0.23.0, generated rather than hand-edited. Browser signing Wasm usesweb-wasm-signing-hostwithouttest-host; testing Wasm is separate.70845db96bdd21409310daeff5e471b74ab5a1c9; dotli #185 at351e5d73fab803a0fd2a4007ce2d2557aebaff05.3c060958d3bd519c7c8f5f706115fbb2108be640b2fa8777d50969e3851ef442dist/generated/client.js(notdist/index.js)7ab13b5840a03360f9687d11b14090b5e8685dda6cea22bcee2fd14b910659737b4042f8d659e0f39d9eeeddf75963c0a8826578295634a92d37f17ff35f5bdd2de619b24ed76f302801290c12574bff53e27546294b19e719d1fd0285d4d834Qualification
Frontend #238 exact-head Tests: functional 79 passed; E2E 41 passed, 1 flaky, 20 skipped. Hosted E2E retained one flaky Preimage → Factory case: it failed on the first attempt and passed the existing CI retry. No retry setting was changed.
Frontend #185 exact-head Tests: functional 89 passed, 3 skipped; E2E 42 passed, 20 skipped. No flaky case in this final hosted Tests run.
Current-head Core CI: 24 required jobs green — 22 passed, 2 path-filter skips. This includes core Swift/Android coverage, not a claim that full iOS application CI ran at this head. The separate existing release-signing-credentials advisory failure remains distinct from Core CI.
Local: Rust workspace: 1,834 passed across 27 suites, 21 ignored. Client/host SDK: 280/285 passed. Canonical codegen and complete feature-specific package construction were qualified locally.
Browser/native proof: Actual browser/native terminal recovery passed: one original CoreWorker/client/transport and native connection remained open; an uncaught shared-worker error retired the worker, stopped the old follow, and a later real chain query succeeded through a new worker generation in 8,147ms. A new follow on the same client delivered 76 live NewBlock events. The old follow did not continue. Same-partition second-tab sharing was verified before and after replacement. Evidence:
main-refresh-terminal-verified-pvm.jsonand screenshot.Retained cross-stack limits
Extrinsic marked as invalid). Two existing native broadcast attempts were validated then invalidated; none was found included in the inspected canonical range. [INFERENCE] Noncanonical mortality anchors may explain invalidation; the exact cause is not established and signed extrinsic bytes were not retained. The earlier Factory deadline failure is also retained: inclusion took 47,516ms against the unchanged 30s product deadline. A separate unchanged manual Factory attempt passed in 10.918s. These failures are not erased by other passing checks..authcontents are included here.This refresh authorizes no deployment, environment approval, PR merge, SDK/npm publication, or guest/product publication. Its QA writes were testnet-only.
All three refresh-triggered JAM Deploy runs were cancelled before rollout; final-head cancellation proof is for frontend
dcdef40499119183aed82a39f784ef740d494341. No refreshed source head was deployed.The live environment changed during qualification: older Deploy run 36945647296, attempt 3 was approved under GitHub account
replghost, explicitly checked out baseline56cea5d37577bf82684fb5c6b6e4ba81d2142938, and recorded deployment success at 2026-10-02 01:19:01 UTC. Its later published-product smoke failed. The operator/client/session behind that account is unproven; this qualification granted no approval and performed no rollback. The observed live content hash changed from4a7caf047fb7f350c1833039b93ba634698a47c56f051b8c7fc0525d4c59a5c8to5882695ee20df5d24a6ed2feb9e997f176fe27ecf4eafe742fabb39eba92885f; these are content hashes, not Git SHAs, and their exact byte-level mapping to a source commit is unproven. Earlier revision/deployment records below remain historical evidence and do not override this current section.Execution callback ownership
createProvider(product, callbacks)binds platform callbacks to one execution of a shared native host. Retired executions cannot route later callbacks through the core's default callback scope; wallet authentication and storage retain core ownership. Native contacts installed after core construction remain available unless the execution supplies its own contacts adapter.Current head:
a4c2dd7ab45c7ac15b1cf7522553e9cd825a10b9. Canonical codegen, default web/testing Wasm, signing-only browser Wasm, host SDK tests, and harness typing are qualified. Hosted CI is green, including Rust workspace, Wasm bridge, Android compilation and iOS Swift/WebKit checks. No package publication.Earlier source and qualification (superseded)
Head
953519aa65f02412ae487ce2356d04ed56b5622dincludes mainaa6ae62ca038bf4a6356edae8eb78e595d52ce24through history-preserving merge commits. Client and host package manifests remain 0.23.0 with pending Changesets.Canonical pinned-nightly codegen, client/host TypeScript builds, CLI typecheck, release-version check, 280 client tests, 126 script tests, eight Rust Bulletin-lookup tests, and the no-default-features truapi/truapi-client build pass locally. The actual CLI fetched and verified an existing 66-byte Bulletin preimage through bitswap_v1_get. Release wallet WASM uses wasm-signing-host without test-host; the separately built testing bundle uses both features. The intended wallet-variant host suite passes 286 tests with Bun 1.4.2; the one default pairing-only negative export assertion is inapplicable to this explicit signing-host build and remains unchanged for default-build CI. Bun 1.3.14 caused six subprocess/server/packing failures; the same assertions pass under the CI-pinned Bun 1.4.2. Both npm packages remain 0.23.0, packed without publishing.
Current-head core CI passes, including Rust workspace, default WASM bridge, Android compile/unit checks, and iOS Swift + WebKit. Full local workspace/native qualification was interrupted by workstation disk exhaustion; the full current-head CI gate completes that qualification. Full iOS application CI also passes, including the in-tree core, application build, simulator preview, and tests. No PR was merged or approved, and no npm package was published. Deployment evidence below belongs to the explicitly named earlier revisions, not this source refresh.
Summary
Implements #507; tracked by #550.
truapi-polkavm-hostis an rlib-only composition crate exposing namespacedtruapiandpolkavm_host_runtimeAPIs. The basetruapihas no PolkaVM dependency.e60a6135be6e00c72c90ca4abe23d2002f4eb962.armeabi-v7a.Runtime and packaging boundaries
Protocol payloads build with no default features using
no_stdandalloc.host-apiexposes async traits for codegen bootstrap;runtimeincludes the host implementation. Native and WASM packaging explicitly request shared/static outputs, so guest dependencies need no host allocator or panic symbols.Published
truapi_serverartifact filenames are stable. The default web WASM bundle is pairing-only. A browser wallet selects--web-only --signing-host, without testing-only allocation shortcuts. Artifact tools use the Cargo-matched wasm-bindgen CLI and checksum-verified Binaryen 117. Each iOS static-library slice has its own Cargo invocation.Earlier qualification evidence
Head
597e9251238fcf51131791698700564d016c1b7cincludes mainc5158448f3c4575f40350017d466053d6b19dacb. Core CI passed. Full iOS CI passed, including the real in-tree core, simulator preview, application build, and tests.Local qualification includes the all-target/all-feature workspace check, 1,807 Rust tests, a compiled and instantiated no-std WASM guest performing codec round trips and rejecting trailing bytes, isolated no-default provider compilation, real pairing/testing WASM builds, host package tests, UniFFI generation, and the actual CLI help command. A throwaway native packaging probe produced both device and simulator static libraries and a two-slice XCFramework using the real build recipe and Xcode.
The playground bundles Instrument Serif, Geist, and JetBrains Mono with their upstream OFL notices, eliminating build-time Google Fonts CSS requests. Its production build passed with an unreachable HTTP/HTTPS proxy; Chromium loaded all four font faces locally and the rendered typography was visually checked.
SwiftPM selects the published host 0.23.0 XCFramework and its pinned checksum when no local artifact is present;
TRUAPI_USE_LOCAL_BINARY=1selects the locally built framework. Both selection paths were exercised withswift package dump-package. Native feature-branch testing still requires matching in-tree binaries.Consumers
Chat authority belongs to #709. The refreshed stack also includes #1001, #1010, and #1011. Dot.li consumers paritytech/dotli-community#185, paritytech/dotli-community#255, paritytech/dotli-community#287, paritytech/dotli-community#290, and paritytech/dotli-community#291 carry exact SDK/WASM source and artifact hashes; their 0.23 browser wallet builds do not enable
test-host. The combined browser deployment targets paseo.fyi.No PR approval or merge is performed by this refresh.