Skip to content

Rust-core port follow-ups - #77

Merged
valentinfernandez1 merged 67 commits into
mainfrom
codex/dotli-rust-port-follow-ups
Jul 28, 2026
Merged

Rust-core port follow-ups#77
valentinfernandez1 merged 67 commits into
mainfrom
codex/dotli-rust-port-follow-ups

Conversation

@pgherveou

@pgherveou pgherveou commented Jul 15, 2026

Copy link
Copy Markdown
Collaborator

Summary

Follow-ups to the Rust-core port (#70, merged). Two kinds of work: features that were split out of that PR to keep its review focused, and fixes for what the port review and a later audit turned up.

What's new

  • Topbar explains login failures in plain words (statement-store slot exhaustion, rejected registrations, RPC errors), keeping the raw reason as a detail line.
  • Debug panel taps TrUAPI wire frames, so its timeline shows real traffic again.
  • AllowanceKeys slots are AES-GCM encrypted at res, fresh random nonce per write, and the read path re-encrypts any legacy plaintext slot it finds.
  • Permission and notification prompts share one 20-per-10s budget, so a product can't flood the host with modals.

What's fixed

  • Bulletin: bumped @parity/truapi-host to 0.2.1, which fixes the allowance-propagation race that made a bulletin allocation come back NotAvailable (and preimage submit fail) in smoldot-direct. The dotli side needed no change, the fix is in the core.
  • Legacy Nova products: follow-bound ops route to the exact follow they're bound to, so concurrent follows on one genesis don't cross-talk. All legacy shim code is tagged remove-legacy-nova for one-grep removal once products migrate.
  • Broker: upstream tokens shared by several sessions are ref-counted, early subscription events are buffered (and drops logged), and chainSend flush failures come back as JSON-RPC errors instead of hanging.
  • Preimage lookups survive transient backend failures and stop polling once cached.
  • Review hardening: the session UI-state cache is validated instead of cast, missing permission statuses default to "ask", and an unused location param is gone.

pgherveou added 14 commits July 15, 2026 11:03
Replace the Nova host-container, auth, and signing path with the worker-backed Rust core. Keep dotli responsible only for browser policy, persistence, UI, and physical chain transports.
Notification grants do not alter iframe Permissions Policy. Reloading disposed the in-flight Rust request before its response reached the product.
The pending-message flush drops send failures silently, matching the
pre-port behavior. Surfacing them as JSON-RPC errors moves to a
follow-up PR with test coverage.
…follow-up

Keep @polkadot-api/signer and @polkadot-labs/hdkd{,-helpers} declared
(unused since before the port) and limit rpc-chain tests to the new
core gateway provider surface. Removing the dead deps and adding
coverage for pre-existing chain checks moves to a follow-up PR.
Keep the base panel top offset and suffix-based terminator matching
(minus the removed host-papp events). The offset correction, the
exact-match terminator set, and the @dotli/config dependency
declaration move to a follow-up PR.
Prompts always reach the modal, matching the pre-port behavior. The
sliding-window limiter returns in a follow-up PR together with the
denied-path semantics and a test that trips the window.
AllowanceKeys persist as plain hex through the same path as every
other core storage key. The at-rest cipher moves to a follow-up PR
where the scheme (per-write nonce, plain-hex read fallback) can get a
focused security review.
The bridge emits only the first_inbound/first_outbound lifecycle
events. The per-frame TrUAPI tap that feeds the debug panel timeline
returns in a follow-up PR; the panel's truapi event handling stays in
place and receives no events until then.
… follow-up

Login failures fall back to the raw reason except for the base
OriginPersonProviderError mapping, and the permissions popover renders
last-write-wins without a staleness guard or unavailable-state hint.
The failure-message pack and popover hardening move to a follow-up PR.
…i-host 0.1.0

The published packages replace the temporary personal-scope npm
aliases used while the port was in review.
@github-actions

Copy link
Copy Markdown
Contributor

⚡ Performance Report

⚠️ No baseline found on main. This PR's results are recorded but cannot be compared.
Merge to main to establish a baseline.

@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown
Contributor

Bundle Size Report

Chunks over 500 KB:

File Raw Brotli Gzip
host/assets/paseo.smol-DboPaEh1.json 1.84 MB 941.7 KB 1019.4 KB
host/assets/paseo-people-next.smol.json 3.36 MB 1.68 MB 1.82 MB
host/assets/previewnet.smol.json 1.88 MB 181.4 KB 353.0 KB
host/assets/smoldot.js 2.98 MB 2.21 MB (+664 B) 2.22 MB
host/assets/smoldot_worker.js 2.95 MB 2.21 MB 2.21 MB
host/assets/wasm/web/truapi_server_bg.wasm 1.97 MB (+13.8 KB) 623.3 KB (+6.0 KB) 818.7 KB (+6.0 KB)
Total 15.92 MB (+27.2 KB) 8.12 MB (+10.2 KB) (-49%) 8.74 MB (+9.7 KB)
All files
File Raw Brotli Gzip
host/.well-known/apple-app-site-association 738 B 738 B 738 B
host/.well-known/assetlinks.json 1.3 KB 317 B 391 B
host/assets/bridge.js 75.2 KB (+3.4 KB) 20.3 KB (+737 B) 23.3 KB (+847 B)
host/assets/browser.js 22.9 KB 7.6 KB (+4 B) 8.6 KB
host/assets/client.js 100.1 KB 29.4 KB (+55 B) 32.4 KB (+2 B)
host/assets/dist.js 39.0 KB 12.9 KB (+49 B) 14.6 KB (-2 B)
host/assets/dotli-debug-bus.js 710 B (+64 B) 710 B (+64 B) 710 B (+64 B)
host/assets/get-sync-provider.js 2.8 KB 1.1 KB (+2 B) 1.2 KB (-1 B)
host/assets/hex.js 153 B 153 B 153 B
host/assets/index.css 44.8 KB 7.1 KB 7.9 KB
host/assets/index.js 140.7 KB (+3.7 KB) 38.3 KB (+980 B) 44.8 KB (+1.0 KB)
host/assets/manifest.js 22.5 KB 7.2 KB (+4 B) 7.9 KB (+1 B)
host/assets/panel.js 72.6 KB (+91 B) 19.7 KB (+9 B) 22.3 KB (+11 B)
host/assets/paseo.smol-DboPaEh1.json 1.84 MB 941.7 KB 1019.4 KB
host/assets/paseo-people-next.smol.json 3.36 MB 1.68 MB 1.82 MB
host/assets/paseo.smol.json 25.4 KB 4.9 KB 5.6 KB
host/assets/previewnet.smol.json 1.88 MB 181.4 KB 353.0 KB
host/assets/resolve.js 128 B 128 B 128 B
host/assets/rpc-resolve.js 2.4 KB 1.0 KB (+12 B) 1.1 KB (-2 B)
host/assets/shared-mode.js 1.8 KB 751 B (+1 B) 852 B (+1 B)
host/assets/smoldot.js 2.98 MB 2.21 MB (+664 B) 2.22 MB
host/assets/smoldot_worker.js 2.95 MB 2.21 MB 2.21 MB
host/assets/src.js 1.8 KB 857 B 945 B (-1 B)
host/assets/styles.css 15.1 KB 3.2 KB 3.8 KB
host/assets/wasm/web/README.md 10.9 KB 10.9 KB 10.9 KB
host/assets/wasm/web/package.json 371 B 371 B 371 B
host/assets/wasm/web/truapi_server.d.ts 6.9 KB 6.9 KB 6.9 KB
host/assets/wasm/web/truapi_server.js 35.6 KB 6.3 KB (+5 B) 7.2 KB (+3 B)
host/assets/wasm/web/truapi_server_bg.wasm 1.97 MB (+13.8 KB) 623.3 KB (+6.0 KB) 818.7 KB (+6.0 KB)
host/assets/wasm/web/truapi_server_bg.wasm.d.ts 2.5 KB 2.5 KB 2.5 KB
host/assets/web.js 13.2 KB 3.5 KB (-11 B) 4.0 KB (+1 B)
host/assets/worker-runtime.js 6.3 KB (+6.2 KB) 1.6 KB (+1.5 KB) 1.8 KB (+1.7 KB)
host/assets/worker-runtime.js 106 B 106 B 106 B
host/assets/ws.js 23.1 KB 7.5 KB (-5 B) 8.2 KB
host/dotli.png 11.5 KB 11.5 KB 11.5 KB
host/favicon.svg 1.8 KB 1.8 KB 1.8 KB
host/host-sw.js 2.7 KB 1.1 KB (+30 B) 1.2 KB (+3 B)
host/icon-192.png 12.5 KB 12.5 KB 12.5 KB
host/icon-512.png 42.8 KB 42.8 KB 42.8 KB
host/index.html 19.9 KB 4.4 KB 5.4 KB (-1 B)
host/manifest.webmanifest 441 B 441 B 441 B
host/workbox.js 14.8 KB 4.6 KB 5.1 KB
sandbox/app-sw.js 9.6 KB 3.1 KB (-4 B) 3.5 KB (-2 B)
sandbox/assets/bitswap-bridge.js 840 B 840 B 840 B
sandbox/assets/fetch.js 3.4 KB 1.2 KB 1.4 KB (+1 B)
sandbox/assets/index.js 118.0 KB 33.7 KB (+62 B) 39.6 KB
sandbox/assets/index.css 44.8 KB 7.1 KB 7.9 KB
sandbox/favicon.svg 1.8 KB 1.8 KB 1.8 KB
sandbox/index.html 1.7 KB 583 B (-1 B) 786 B (-1 B)
Total 15.92 MB (+27.2 KB) 8.12 MB (+10.2 KB) (-49%) 8.74 MB (+9.7 KB)

Commit: d5e26bc

origin/main gained the squash-merge of #70, whose tree is identical to
commit 1edd74e already in this branch's history; -s ours records the
merge without changing the tree.
@leonardocustodio

Copy link
Copy Markdown
Member

Only issues that I saw when testing on https://host-playground.dotli.dev on smoldot-direct mode were:

  • BulletinAllowance
[Allocate Bulletin Allowance]
Received 1 outcome(s)
[
  {
    "resource": "BulletinAllowance",
    "outcome": "NotAvailable"
  }
]
  • Submit PreImage
10:55:19.155
error
[Submit Preimage]
preimage submit failed: Unknown: bulletin allowance is not available

Ofc allocating all resources would fail the bulletin step:

10:58:48.798
success
[Allocate All Resources]
Received 3 outcome(s)
[
  {
    "resource": "StatementStoreAllowance",
    "outcome": "Allocated"
  },
  {
    "resource": "BulletinAllowance",
    "outcome": "NotAvailable"
  },
  {
    "resource": "SmartContractAllowance",
    "outcome": "Allocated"
  }
]

Let me know if this will be handled elsewhere.

@TarikGul TarikGul left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Compiled my review with claude here: https://gist.github.com/TarikGul/36916b1a6c2a2b4c2a7f989b22ac9ead

Includes reproducibles, and examples.

@socket-security

socket-security Bot commented Jul 27, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​parity/​truapi-host@​0.2.0 ⏵ 0.2.1781009594 +2100

View full report

@valentinfernandez1

valentinfernandez1 commented Jul 27, 2026

Copy link
Copy Markdown
Collaborator

@leonardocustodio This PR resolves the issue regarding bulletin allowance with smoldot-direct, the fix was on the core so here we just consume the new truapi release. The change is already deployed on dotli.dev so feel free to verify the fix. Should also improve some stability issues with smoldot.

@leonardocustodio leonardocustodio left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm, seems all bulletin methods and resources allocation are working fine through smoldot, great work

@TarikGul TarikGul left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 Nice job - lgtm

@leonardocustodio leonardocustodio left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@valentinfernandez1
valentinfernandez1 merged commit e83002c into main Jul 28, 2026
18 of 21 checks passed
@valentinfernandez1
valentinfernandez1 deleted the codex/dotli-rust-port-follow-ups branch July 28, 2026 15:31
pgherveou pushed a commit that referenced this pull request Jul 28, 2026
#70 (Switch to Rust core) and #77 (Rust-core port follow-ups) landed on main
in between. #70 was squash-merged, so this branch and main carried the same
port content under different commits, and every file the port added conflicted
add/add.

Resolution: main is authoritative for everything except the four commits that
are unique to this branch (aa229af, 72bda6c, 99549e2, ae4112b). Those were
reapplied on top of main's tree, so the branch diff against main is now the
chain-ownership change alone.

Conflicts of substance:

- broker.ts: kept #77's ref-counted token release (loop over every local token
  sharing the upstream token) and its early-subscription buffering, and added
  this branch's terminal `transactionWatch_v1_watchEvent` events to the
  release condition.
- client.ts: took the new `createPapiChainProvider` adapter. #77's only change
  here added JSON-RPC error responses when a queued `chainSend` flush failed;
  that code path is deleted, and the adapter's `failOutstanding` covers the
  same case for every outstanding request, not just flushed ones.
- bulletin-bitswap.ts: kept #77's RPC-gateway warning, dropped its
  `isRemoteChainSupported` branch. Bulletin is always in the supported set, so
  that branch was dead; unsupported chains now surface as `UNSUPPORTED_CHAIN`
  from the protocol runtime at connect time.
- resolver/tests/rpc-chain.test.ts: kept #77's People and unknown-genesis
  cases, renamed to `isRpcUpstreamSupported` / `createRpcUpstreamProvider`.
- network.ts: refreshed two comments that still described the Rust-core
  callback as the thing choosing chains.
smohan-dw added a commit to smohan-dw/dotli-community that referenced this pull request Jul 29, 2026
… input validation paritytech#122) into commons-0.9.9

# Conflicts:
#	packages/resolver/tests/chains.test.ts
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants