Conversation
decrypto21
left a comment
There was a problem hiding this comment.
Check ordering looks right everywhere. One substantive issue.
1. productDeviceChat reuses a permission meant for something much weaker
It gates on IdentityDisclosure (runtime.rs:576) — the same slot get_user_id uses for "show this product your username" (capabilities/account.rs:513). The key is product-scoped only (truapi-platform/src/lib.rs:1399), nothing marks which capability is asking, and truapi-platform/ has no diff here. But this call binds the wallet's Chat identity and grants a standing Seal/Open oracle against any peer key the product names.
- Signing-host (
host_core.rs:597, viaframe_server.rs:177): only gate, sinceSigningHost::product_device_chat(signing_host.rs:995) checks only the session. A product with an olderget_user_idgrant gets Bind/Seal/Open with no prompt — reproduced on this branch (pre-seeded grant → proceeds, prompt count 0; no grant →Rejected). - Two-device SSO:
sso_responder.rs:934does prompt the first time, but shows "wants to know it's you" for identity binding plus an encryption oracle. Silent after that.
Worth a dedicated PermissionAuthorizationRequest variant with its own review copy, like the neighbouring AccountAccess. If the reuse is deliberate, the doc comment (truapi-platform/src/lib.rs:1029) and prompt copy should say so.
2. Minor
sso_pairing.rs:399 switches success: *success to (*success).clone() on a struct holding identity_chat_private_key. If that was for the new Drop impl, it isn't needed — box-deref-move compiles fine with Drop. Keeping the move avoids a second live copy.
# Conflicts: # rust/crates/truapi-codegen/tests/golden/wire_table.rs # rust/crates/truapi-server/src/host_logic/sso/messages.rs # rust/crates/truapi-server/src/host_logic/sso/messages/v1.rs # rust/crates/truapi-server/src/runtime/authority.rs # rust/crates/truapi-server/src/runtime/capabilities/account.rs # rust/crates/truapi-server/src/runtime/pairing_host.rs # rust/crates/truapi-server/src/runtime/pairing_host/sso_channel.rs # rust/crates/truapi-server/src/runtime/signing_host.rs # rust/crates/truapi-server/src/runtime/signing_host/sso_responder.rs
…e/chat-receive # Conflicts: # CHANGELOG.md
…y-review-709 # Conflicts: # rust/crates/truapi-codegen/tests/golden/dispatcher.rs # rust/crates/truapi-codegen/tests/golden/wire_table.rs
Keep username disclosure separate from Chat consent. Exercise approval, denial, cached consent, and revocation through local and SSO APIs; move the secret-bearing pairing result instead of cloning it.
…n scope Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…into fix/pr709-review-3
|
Thanks. All seven addressed:
|
# Conflicts: # rust/crates/truapi-codegen/tests/golden/host-callbacks.ts # rust/crates/truapi-codegen/tests/golden_rust_emit.rs # rust/crates/truapi-host-cli/src/platform.rs
# Conflicts: # README.md
|
This pull request touches an app, which is not built by default. Add a label for each build you want:
Each starts as soon as it is added and follows the branch from then on. |
# Conflicts: # README.md
# Conflicts: # js/packages/truapi-host/src/wasm-module.ts # rust/crates/truapi/src/runtime/authority.rs # rust/crates/truapi/src/runtime/signing_host.rs # rust/crates/truapi/src/runtime/signing_host/sso_responder.rs # rust/crates/truapi/src/runtime/statement_store_rpc.rs
# Conflicts: # README.md
# Conflicts: # android/truapi-host/README.md # js/packages/truapi-host/src/test-support.ts # rust/crates/truapi-client/src/generated.rs
# Conflicts: # rust/crates/truapi-codegen/tests/deterministic_emit.rs
Current repair qualification — 2026-10-02
726ef76bcce42b91d664d753ac4225df0a093472. Canonical chat artifact-generation and Wasm revisions are this same commit. Prior main-integration baselines are retained: nativebda6ac518c8cc59319491b12e4e23b96777375fd, frontendf4012c50c3400d1186c332ad2ae50298cefd153d.6ef2aa616b6e771c236a37f36743212472ad0b38. Complete matching SDK/host packages remain 0.23.0; codegen and Wasm were rebuilt canonically. Generated client bytes are unchanged. Production features:wasm-signing-host; separate testing bundle:wasm-signing-host,test-host.d8e759c51c8e49dd829efbd3d5227217aeac9bd8d9b8952397716fe8bdd8f95cdist/generated/client.js6c48f48837ceda0c80163dbbc208a365e44230fd55e4b472b634bb3ac2a77aa38ecea2f14eecf6bdde983f04c1d28d1c7c6bffddef639d6a31cf5a7f38ec50b90f10b028409e4d17f6256f3f4fc08fec1fd9bf6a2102f19e77e2e91a567e4a6fe21b93f44979f8a46f5f066e1dca6259984334ff4f41dd1e71f09781b5402efaNative correction and causal limits
Bulletin mortal signatures now anchor to a finalized checkpoint, while nonce/runtime state comes from the freshest available signing snapshot. A checkpoint at least 64 blocks behind is rejected before broadcast. Regression coverage verifies the actual signature with a newer nonce and older finalized checkpoint, and the expiry boundary. Existing transaction retries/deadlines are unchanged; no chain error is suppressed. The affected test fixture uses
parking_lot::Mutex.The former Seity
Extrinsic marked as invalidrun used noncanonical best-block anchors, but retained evidence lacks the signed bytes and typed pool reason. Fork-sensitive mortality was a real correctness hazard; it is not claimed as the conclusively proved cause of that historical failure. Prior hosted Factory/Genesis timeout causes also remain unproved. No broker/readiness workaround, prewarming, extra retry, or timeout increase was added.Executed verification
-D warnings, CLI build, and canonical browser/testing Wasm packaging. Base full library: 1,246 passed.0a24db4aa189adad7b93f9ff508c7949e39196ee301a235ba13248ef4281e9e3d859919fb6cfbe06d3dc8a41807c36b8bcdf001c47eccb9735305499The Chat/Seity tested heads above precede documentation-only formatting merges; their native/Wasm pins and runtime code are unchanged. Final hosted frontend results are recorded on the linked consumer PRs, separately from these exact-head local results.
Final hosted retest: failures remain
error; it is not evidence of a chain rejection. Retained traces include People-chain/local development sockets but do not expose the Asset Hub gateway WebSocket exchange, so these new failures do not establish an upstream or broker cause.paseo-bulletin-next-ipfs.polkadot.io. The zero-failure host-settings gate correctly failed.Doom: criterion corrected, backend matrix still unqualified
The user explicitly approved 35 FPS sustained over 30 seconds, with one frame of sampling-boundary tolerance:
frames + 1 >= elapsedMs * 35 / 1000. This replaces the instantaneousFPS >= 35sample; it is an acceptance-criterion change, not a runtime speedup. Runtime and displayed FPS are unchanged; raw samples are not rounded to force a pass. Update p95 <28.6ms, cold/warm first-frame limits <3,000/<1,000ms, audio and translation-cache checks remain. The revised official RPC benchmark passed once before the vendor replacement.The later isolated matrix used the rebuilt base pair at frontend
238ab5fa739788b2eb948ba1f807a1876edbacad, with fresh owned Chrome profiles and no concurrent builds/E2E:Distinct diagnostics found no presentation loss in a later instrumented 24-second shared-worker sample and observed a successful hidden RPC new-document reload. Neither diagnostic supersedes the failures or qualifies performance. No evidence-proved runtime fix, guest rebuild, speculative tuning, or further unchanged gate rerun was made. The original strict RPC failure and every new failure remain retained. Next causal capture must instrument the original early 30-second window and distinguish warm lifecycle states before proposing a runtime fix.
Retention and rollout boundary
Local verification used
paseo-next-v2, the pinned host-playground fixturef56294cea4430163bf16ec068844b1327441073c, and existing private QA identities. All three corrected sequences paired on their first existing setup attempt. A prior local launch failure and a misconfigured Previewnet-product run (34 passed, 20 skipped, 8 Chain/Contract failures) are retained separately, not presented as reproductions of the hosted Genesis timeout. Private traces/auth/signers were not published.The first repair heads also exposed a README formatting failure (corrected by documentation-only commits) and a PVM cache-unit-test 5,000ms timeout. No cache runtime/test change, limit increase, or causal claim was made for that isolated timeout. Older in-flight runs superseded by the formatting correction remain recorded as cancelled, not passed.
No PR merge, force push, deployment, environment approval, SDK/npm/product/guest publication, or rollback was performed by this repair. JAM remains JAM-TEST-INSTANCE, never JAM-PUBLIC-DEVNET. The user-owned
deploy: paseo.fyilabel is retained; repair-triggered deployment runs 36970790399 and 36971286469 were cancelled before deployment. The earlier rollout audit is retained below: an older workflow deployed56cea5d37577bf82684fb5c6b6e4ba81d2142938; this record does not claim live remained unchanged historically.Historical integration qualification (superseded; retained verbatim)
Current main refresh and qualification — 2026-10-01
6d97c7932f26cf190dd6c506ed5f4da110bada74. Native mainbda6ac518c8cc59319491b12e4e23b96777375fdis integrated; the frontend stack includes dotli mainf4012c50c3400d1186c332ad2ae50298cefd153d(merged chore(deps): bump postcss from 8.5.15 to 8.5.23 in /explorer #313). Histories and worktrees were preserved; pushes used fetched-head ancestry guards, never force.08bddf36912d61fcfa76e4fb733fd585c6b22bca. Later native changes are test/docs/iOS-only, not SDK/Wasm inputs, so the artifact pin intentionally differs from the current head. Complete matching client and host packages remain 0.23.0, generated rather than hand-edited. Browser signing Wasm usesweb-wasm-signing-hostwithouttest-host; testing Wasm is separate.bb9ad3d8921c63cf62c98b9029289f458b1a67a2.d8e759c51c8e49dd829efbd3d5227217aeac9bd8d9b8952397716fe8bdd8f95cdist/generated/client.js(notdist/index.js)6c48f48837ceda0c80163dbbc208a365e44230fd55e4b472b634bb3ac2a77aa3a725bcbd6ff17a92bea89bb11868a45b6b3fdb178cb037cb00da1c46105526c90778dfa5255092bbfc7607dc226d1fc9a2d2d0315ffb669258341fa307556485Qualification
Frontend #255 exact-head Tests: functional 89 passed, 3 skipped; E2E 41 passed, 1 flaky, 20 skipped. Hosted E2E retained one flaky Chain → Chain Spec: Genesis Hash case: it failed on the first attempt and passed the existing CI retry. No retry setting was changed.
Current-head Core CI: 24 required jobs green — 22 passed, 2 path-filter skips. This includes core Swift/Android coverage, not a claim that full iOS application CI ran at this head. The separate existing release-signing-credentials advisory failure remains distinct from Core CI.
Local: Rust workspace: 2,267 passed across 29 suites, 21 ignored. Client/host SDK: 283/326 passed; local Swift and Android qualification passed. Canonical codegen and complete feature-specific package construction were qualified locally.
Browser/native proof: Actual canonical SDK Chat Initialize passed over the authenticated product port. Separate ChatIdentityAuthority Allow-once consent was required. After a full host reload and new Allow-once consent, public device metadata was identical. Evidence:
main-refresh-native-chat.json. No published guest/product was created.Retained cross-stack limits
Extrinsic marked as invalid). Two existing native broadcast attempts were validated then invalidated; none was found included in the inspected canonical range. [INFERENCE] Noncanonical mortality anchors may explain invalidation; the exact cause is not established and signed extrinsic bytes were not retained. The earlier Factory deadline failure is also retained: inclusion took 47,516ms against the unchanged 30s product deadline. A separate unchanged manual Factory attempt passed in 10.918s. These failures are not erased by other passing checks..authcontents are included here.This refresh authorizes no deployment, environment approval, PR merge, SDK/npm publication, or guest/product publication. Its QA writes were testnet-only.
All three refresh-triggered JAM Deploy runs were cancelled before rollout; final-head cancellation proof is for frontend
dcdef40499119183aed82a39f784ef740d494341. No refreshed source head was deployed.The live environment changed during qualification: older Deploy run 36945647296, attempt 3 was approved under GitHub account
replghost, explicitly checked out baseline56cea5d37577bf82684fb5c6b6e4ba81d2142938, and recorded deployment success at 2026-10-02 01:19:01 UTC. Its later published-product smoke failed. The operator/client/session behind that account is unproven; this qualification granted no approval and performed no rollback. The observed live content hash changed from4a7caf047fb7f350c1833039b93ba634698a47c56f051b8c7fc0525d4c59a5c8to5882695ee20df5d24a6ed2feb9e997f176fe27ecf4eafe742fabb39eba92885f; these are content hashes, not Git SHAs, and their exact byte-level mapping to a source commit is unproven. Earlier revision/deployment records below remain historical evidence and do not override this current section.Earlier source and qualification (superseded)
Head
4b241e8cfa7b6cdbc6ce90e56866087fc31331f6includes mainaa6ae62ca038bf4a6356edae8eb78e595d52ce24through history-preserving merge commits. Client and host package manifests remain 0.23.0 with pending Changesets.The branch includes the integrated main changes and preserves its feature boundary. Root and combined-stack canonical codegen and TypeScript qualification pass. This branch’s current-head Codegen CI job passes; its downloaded canonical output matches all 45 tracked generated files byte-for-byte. Full workspace/native qualification remains tracked by current-head CI.
Current-head core CI passes, including Rust workspace, default WASM bridge, Android compile/unit checks, and iOS Swift + WebKit. Full local workspace/native qualification was interrupted by workstation disk exhaustion; the full current-head core CI gate completes that qualification. Full iOS application CI also passes, including the in-tree core, application build, simulator preview, and tests. No PR was merged or approved, and no npm package was published. Deployment evidence below belongs to the explicitly named earlier revisions, not this source refresh.
Summary
Adds Chat-specific product authority above the generic PolkaVM host integration in #540. Chat cryptographic authority, device binding, request signing, sealing, and opening remain outside the generic host PR.
Authorization boundary
product_device_chatnow requires dedicatedChatAuthorityconsent instead of reusingIdentityDisclosure/username consentget_user_idkeeps its separate identity-disclosure permission; no legacy username grant is migrated into Chat authoritySuccessout of its box instead of cloning itStack and downstream artifacts
Based on #540, with main through
c5158448f3c4575f40350017d466053d6b19dacb. Seity remains in #1001; peer transport remains a separate #1010 layer.437a46c5af88b3c4a962d763f8fa5732e9c48183. Browser integration and qualification of these artifacts are tracked in feat(chat): restore separate Chat authority integration above PolkaVM dotli-community#255. The runtime update includes the concurrent Contacts, private attachment-frame, session-consent, per-peer-bound, and claim-settlement fixes; older artifact pins do not include all of those fixes.vendor/truapi-host.lock.json.wasm-signing-host; the default web bundle is pairing-only. Testing is a separate bundle.Earlier qualification evidence
Initial refresh qualification included 1,469 core tests, 324 SDK tests, native/WASM checks, license validation, and real browser rendering plus a canonical SDK handshake through the refreshed consumer. The codegen executable produced deterministic output across two independent executions. Canonical code generation and release wallet/testing WASM builds also pass for the current source.
At
437a46c5af88b3c4a962d763f8fa5732e9c48183, all PR checks pass, including core CI and full iOS CI. The full iOS run includes the persisted-store migration regression. Consumer checks are tracked in paritytech/dotli-community#255; the combined paseo.fyi deployment is qualified separately in paritytech/dotli-community#291. No on-device Chat message, wallet funding, or payment was performed for this refresh.Native retests must build the matching TrUAPIHost and TrUAPIProvider artifacts from source; changing an SPM revision alone does not replace prebuilt SDK binaries.
The iOS combined store uses model 53, retaining both historical main and Chat model-49 variants. Real SQLite migration smoke checks passed from main model 49, Chat model 49, and main model 52, preserving payment amounts, owner identity, and native Coinage ledger payloads. The permanent migration regression passes in the app suite. This iOS-only correction does not change the vendored browser SDK artifacts.
The iOS test lane now retains xcresult, raw logs, and crash diagnostics on failure. Run
36654074336reported 365 failures without a named assertion in its formatted log and did not retain its test result; its cause is not established. The current complete iOS run passes. Diagnostic retention does not weaken tests, change retry behavior, or establish a fix for that earlier failure.