Skip to content

Commit c372414

Browse files
committed
Publish Calibration direct-read dashboard evidence
1 parent ff85d8e commit c372414

10 files changed

Lines changed: 352 additions & 95 deletions

README.md

Lines changed: 30 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,29 @@ workspace.
3737

3838
See [`spec.md`](./spec.md).
3939

40-
The design is not production-ready, but it now selects a v1 implementation path to validate: platform EOA/KMS payer, FOC session-key coordinator, hosted coordination, onchain request/object/usage/receipt state, and a Token Host Builder-first scaffold for the generated app, admin/read surfaces, upload adapters, manifests, and sponsored transaction wiring. The workspace includes a local registry artifact/read model, a dev-only upload spine test that exercises request, start, deterministic mocked receipt finalization, object reads, usage reads, and log projection, plus read-only admin/reconciliation projections for object, usage, dataset, provider, coordinator, and mismatch views. The next admin/dashboard buildout targets direct onchain registry pagination: list/count views enumerate objects, accounts, coordinators, relayers, and dataset keys, while detail views fetch the current contract state. Event projections remain audit/fixture/fallback inputs rather than the current-state dashboard source of truth. A partial Phase 0 Calibration run has deployed and verified the registry bytecode on chain `314159`; see [`docs/phase0-calibration-report.md`](./docs/phase0-calibration-report.md). The full FOC/Synapse/session-key compatibility matrix remains open, so future payment and coordinator modes remain compatibility-gated by Phase 0 evidence. The current security and operations boundary is captured in [`docs/production-hardening-runbook.md`](./docs/production-hardening-runbook.md).
40+
The design is not production-ready, but it now selects a v1 implementation path
41+
to validate: platform EOA/KMS payer, FOC session-key coordinator, hosted
42+
coordination, onchain request/object/usage/receipt state, and a Token Host
43+
Builder-first scaffold for the generated app, admin/read surfaces, upload
44+
adapters, manifests, and sponsored transaction wiring. The workspace includes a
45+
local registry artifact/read model, a dev-only upload spine test that exercises
46+
request, start, deterministic mocked receipt finalization, object reads, usage
47+
reads, and log projection, plus read-only admin/reconciliation projections for
48+
object, usage, dataset, provider, coordinator, and mismatch views. The current
49+
admin/dashboard buildout uses direct onchain registry pagination: list/count
50+
views enumerate objects, accounts, coordinators, relayers, and dataset keys,
51+
while detail views fetch the current contract state. Event projections remain
52+
audit/fixture/fallback inputs rather than the current-state dashboard source of
53+
truth. A historical Phase 0 Calibration run deployed and verified registry
54+
bytecode on chain `314159`; see
55+
[`docs/phase0-calibration-report.md`](./docs/phase0-calibration-report.md).
56+
The current Worker evidence additionally publishes a committed object and
57+
direct dashboard read proof; see
58+
[`docs/calibration-worker-demo.md`](./docs/calibration-worker-demo.md). The
59+
full FOC/Synapse/session-key compatibility matrix remains open, so future
60+
payment and coordinator modes remain compatibility-gated by Phase 0 evidence.
61+
The current security and operations boundary is captured in
62+
[`docs/production-hardening-runbook.md`](./docs/production-hardening-runbook.md).
4163

4264
## Related projects
4365

@@ -89,13 +111,13 @@ the dashboard; `/api/admin/overview`, `/api/admin/files`,
89111
`/api/admin/reconciliation` expose JSON rows backed by direct registry
90112
count/list/detail reads. Overview uses bounded contract count reads; table
91113
routes expose page metadata with `cursor` or `offset`, and filters are
92-
page-scoped to keep Worker requests bounded. The committed demo config still points at live Calibration
93-
evidence for registry object `1`, provider/dataset/piece `4`/`12524`/`34`, and
94-
a committed registry finalization; issue #33 owns publishing updated public
95-
evidence for the direct pagination ABI. Until that registry/runtime evidence
96-
matches the current artifact hash, the dashboard defaults to skipped read-only
97-
API responses instead of live dashboard reads; use `?live=true` only against an
98-
upgraded pagination-capable registry. The deployed demo is available at
114+
page-scoped to keep Worker requests bounded. The committed demo config points
115+
at live Calibration evidence for registry object `1`,
116+
provider/dataset/piece `4`/`12524`/`34`, a committed registry finalization, and
117+
direct pagination-capable registry reads whose runtime hash matches the current
118+
artifact. Dashboard APIs now default to live direct reads; append `?live=false`
119+
for route smoke checks that should not call public RPC. The deployed demo is
120+
available at
99121
`https://foc-platform-calibration-demo.snissn.workers.dev`. Run
100122
`pnpm worker:dev` for a local Worker and `pnpm worker:dry-run` to validate the
101123
deploy bundle. The Worker must not receive private keys or session keys;

artifacts/calibration/demo-evidence.json

Lines changed: 69 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,14 @@
11
{
22
"schemaVersion": 1,
3-
"generatedAt": "2026-07-01T14:29:04.326Z",
3+
"generatedAt": "2026-07-02T02:30:32.494Z",
44
"mode": "calibration_live_evidence",
55
"network": "filecoin_calibration",
66
"chainId": 314159,
77
"registry": {
8-
"address": "0x7771d916a9d742B1D60597a332C7ABBd5796609c",
9-
"deployTxHash": "0xb6a4469ae4bff657326d25dd9989ebae54f03467c8ddee19001b1c114fe70552",
10-
"deployBlock": "3852147",
11-
"runtimeSha256": "0xed478a27e255a1b27989ffa4f2fcbf38f1a9ec61a84c8d3e20aceb4e26f72040",
8+
"address": "0x8F6563Bb9E53aeDfE9d87d4C1E162f0371649c18",
9+
"deployTxHash": "0xae42c13c50c1b268a1d38389e27d8fa776264b405e28a1cf11a974dd4b178eae",
10+
"deployBlock": "3854411",
11+
"runtimeSha256": "0x2c49443e7a9ebf3337453240e706df249d29f4f217ec948d6c10e9502a199d1f",
1212
"rootAddress": "0xF00DCE36817586672B47480FB48C94177A97278B"
1313
},
1414
"demo": {
@@ -23,11 +23,12 @@
2323
"uploadTxHash": null,
2424
"uploadEvidence": "FOC MCP upload call timed out locally, but dataset read shows piece metadata.",
2525
"registryTxHashes": {
26-
"setCoordinator": "0xcf21feda99029624d18bcf17035f0f5d0f9c7bc67680ca0d32f210d6acf370ce",
27-
"requestUpload": "0x552b1da9b049dc1301effcc34c497625a1e09934b25bec7e5a3fe607ba3382fd",
28-
"startUpload": "0x1d1104fb0807ff05f4a4c9045dcfc888a54bd6d143edab25e19ec6d4bd6a8bb1",
29-
"recordDataset": "0x3ec159924041a28531652a23ca4343f7aa8186da47f5c27cc6e8410bee5a3ea3",
30-
"finalizeUpload": "0xebbf1d335df22f3607e9552753360d80d48fd28d199ef0afa19f052d5fd57608"
26+
"setCoordinator": "0x22a29586247fa39e8d3277c754a42466f1936a3377f2d62ab50ddf1337035cd1",
27+
"setRelayer": "0x93153de2f1653b1e632dff19f2dfd632f5f2a6390af20b39097a53607c162570",
28+
"requestUpload": "0x35c561f8b6278b63deb1d272b8cc2b7663a45eb3cc564e75092bbeb5ebf12ccf",
29+
"startUpload": "0x6c57ded5248162049d64d372c2d1bde7e37c788edeedafc454bbbd2e3f841f38",
30+
"recordDataset": "0xb65836f00e8b7a24734e3d5e62d64ad305e3234fd879e2a435b1665d273b6669",
31+
"finalizeUpload": "0xe046f47af71e7da40ed475aba0e3ba8ac94677ae2de7341e1b59e2f8e367a2a4"
3132
},
3233
"request": {
3334
"accountId": "0xfaa4a252e3d762275f3bb2baccba097024ed47a08845bee0de79a2ee58514e01",
@@ -79,9 +80,9 @@
7980
"actualCost": "0",
8081
"status": 3,
8182
"coordinator": "0xF00DCE36817586672B47480FB48C94177A97278B",
82-
"requestExpiresAt": "1783002330",
83-
"createdAt": "1782915930",
84-
"updatedAt": "1782916110",
83+
"requestExpiresAt": "1783045620",
84+
"createdAt": "1782959220",
85+
"updatedAt": "1782959400",
8586
"receiptHash": "0xce534bd735f5dea29729cd9a25ebcf5e1ff469b0979317d5e50dce75fccbb3c0"
8687
},
8788
"usage": {
@@ -113,23 +114,67 @@
113114
"datasetId": "12524",
114115
"storageClass": "0x0e6acc625c140754b256b76ddbbb54fdac3cbed1a8405e4b477401bd17f16282",
115116
"withCDN": false,
116-
"createdAt": "1782916050",
117-
"updatedAt": "1782916050"
117+
"createdAt": "1782959340",
118+
"updatedAt": "1782959340"
119+
}
120+
},
121+
"dashboard": {
122+
"sourceOfTruth": "FocPlatformRegistry direct contract count/list/detail/readBatch views",
123+
"counts": {
124+
"objectCount": "1",
125+
"accountCount": "1",
126+
"datasetRecordCount": "1",
127+
"coordinatorCount": "1",
128+
"relayerCount": "1"
129+
},
130+
"pages": {
131+
"objectIds": [
132+
"1"
133+
],
134+
"accountIds": [
135+
"0xfaa4a252e3d762275f3bb2baccba097024ed47a08845bee0de79a2ee58514e01"
136+
],
137+
"accountObjectIds": [
138+
"1"
139+
],
140+
"datasetKeys": [
141+
{
142+
"accountId": "0xfaa4a252e3d762275f3bb2baccba097024ed47a08845bee0de79a2ee58514e01",
143+
"providerId": "4",
144+
"datasetId": "12524"
145+
}
146+
],
147+
"coordinatorAddresses": [
148+
"0xF00DCE36817586672B47480FB48C94177A97278B"
149+
],
150+
"relayerAddresses": [
151+
"0xF00DCE36817586672B47480FB48C94177A97278B"
152+
]
153+
},
154+
"detailReads": {
155+
"objectId": "1",
156+
"coordinatorPolicy": {
157+
"allowed": true,
158+
"maxFinalizeDelay": "86400",
159+
"sessionKeyExpiresAt": "0",
160+
"permissionsHash": "0x0000000000000000000000000000000000000000000000000000000000000000"
161+
},
162+
"relayer": {
163+
"address": "0xF00DCE36817586672B47480FB48C94177A97278B",
164+
"allowed": true
165+
}
166+
},
167+
"readBatch": {
168+
"method": "readBatch",
169+
"callCount": 5,
170+
"resultCount": 5
118171
}
119172
}
120173
},
121174
"worker": {
122175
"mode": "read_only_public_evidence",
123176
"privilegedActions": false,
124-
"servesPrivateKeys": false,
125-
"url": "https://foc-platform-calibration-demo.snissn.workers.dev",
126-
"versionId": "bee0fdaf-f4ac-4a6a-8556-46842d76c6cb",
127-
"startupTimeMs": 14,
128-
"validatedEndpoints": [
129-
"/api/health",
130-
"/api/demo/evidence",
131-
"/api/demo/registry"
132-
]
177+
"servesPrivateKeys": false
133178
},
134179
"tokenHost": {
135180
"mode": "hand_written_registry_wrapper",

docs/calibration-worker-demo.md

Lines changed: 35 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,9 @@ Issue #15 exposes the Calibration demo through a Cloudflare Worker. Issue #32
44
turns the Worker first screen into a read-only admin dashboard for the
55
configured `FocPlatformRegistry`: it serves public evidence, reads dashboard
66
rows through direct registry list/detail views, and links to generated Token
7-
Host wrapper metadata. It must not upload files, pay FOC, withdraw funds, or
8-
submit registry transactions.
7+
Host wrapper metadata. Issue #33 publishes the current Calibration evidence for
8+
the direct count/list/detail/readBatch dashboard path. The Worker must not
9+
upload files, pay FOC, withdraw funds, or submit registry transactions.
910

1011
## Worker Commands
1112

@@ -55,15 +56,10 @@ before changing or redeploying it. The security and recovery boundary is
5556
documented in
5657
[`docs/production-hardening-runbook.md`](./production-hardening-runbook.md).
5758

58-
The current deployed Worker and registry evidence predate the direct pagination
59-
ABI. The Worker code now has direct-onchain dashboard routes, but the deployed
60-
public evidence still points at the earlier registry. For that configuration,
61-
the dashboard defaults to skipped read-only API responses instead of attempting
62-
live dashboard reads against missing count/list methods. `?live=true` should be
63-
used only with a registry whose runtime hash matches the current pagination ABI.
64-
Issue #33 must publish updated evidence from a registry build that includes the
65-
pagination ABI before the dashboard stack can claim end-to-end public
66-
Calibration direct-read proof.
59+
The committed Worker config points at a Calibration registry whose runtime hash
60+
matches the current pagination ABI. Dashboard APIs therefore default to live
61+
direct reads. Append `?live=false` when you need a route-level smoke check
62+
without public RPC calls.
6763

6864
## Public Endpoints
6965

@@ -130,6 +126,10 @@ After the local evidence run, update only public values:
130126
```jsonc
131127
{
132128
"FOC_PLATFORM_DEMO_MODE": "calibration_live_evidence",
129+
"FOC_PLATFORM_REGISTRY_ADDRESS": "<registry address>",
130+
"FOC_PLATFORM_REGISTRY_DEPLOY_TX": "<registry deploy tx hash>",
131+
"FOC_PLATFORM_REGISTRY_DEPLOY_BLOCK": "<registry deploy block>",
132+
"FOC_PLATFORM_REGISTRY_RUNTIME_SHA256": "<deployed runtime SHA-256>",
133133
"FOC_PLATFORM_DEMO_STATUS": "Committed",
134134
"FOC_PLATFORM_DEMO_OBJECT_ID": "<registry object id>",
135135
"FOC_PLATFORM_DEMO_ACCOUNT_ID": "<bytes32 account id>",
@@ -158,13 +158,16 @@ if [[ "$PRIVATE_KEY" != 0x* ]]; then
158158
fi
159159

160160
export FILECOIN_CALIBRATION_RPC_URL="https://api.calibration.node.glif.io/rpc/v1"
161-
export FOC_PLATFORM_REGISTRY_ADDRESS="0x7771d916a9d742B1D60597a332C7ABBd5796609c"
161+
export FOC_PLATFORM_REGISTRY_ADDRESS="0x8F6563Bb9E53aeDfE9d87d4C1E162f0371649c18"
162+
export FOC_PLATFORM_REGISTRY_DEPLOY_TX="0xae42c13c50c1b268a1d38389e27d8fa776264b405e28a1cf11a974dd4b178eae"
163+
export FOC_PLATFORM_REGISTRY_DEPLOY_BLOCK="3854411"
164+
export FOC_PLATFORM_REGISTRY_RUNTIME_SHA256="0x2c49443e7a9ebf3337453240e706df249d29f4f217ec948d6c10e9502a199d1f"
162165
export FOC_PLATFORM_DEMO_PAYLOAD_PATH="/tmp/foc-platform-calibration-demo.bin"
163166
export FOC_PLATFORM_DEMO_PROVIDER_ID="4"
164167
export FOC_PLATFORM_DEMO_DATASET_ID="12524"
165-
export FOC_PLATFORM_DEMO_PIECE_ID="<piece id>"
166-
export FOC_PLATFORM_DEMO_PIECE_CID="<piece CID>"
167-
export FOC_PLATFORM_DEMO_RETRIEVAL_URL="<provider retrieval URL>"
168+
export FOC_PLATFORM_DEMO_PIECE_ID="34"
169+
export FOC_PLATFORM_DEMO_PIECE_CID="bafkzcibeqcad6egqwuynxmfu6jof2lzkfdp65aelknasuautd4mmjgpvujkaq2ytey"
170+
export FOC_PLATFORM_DEMO_RETRIEVAL_URL="https://caliberation-pdp.infrafolio.com/piece/bafkzcibeqcad6egqwuynxmfu6jof2lzkfdp65aelknasuautd4mmjgpvujkaq2ytey"
168171

169172
node scripts/run-calibration-registry-demo.mjs --write
170173
```
@@ -180,31 +183,37 @@ The committed demo evidence now points at a live Calibration object:
180183

181184
| Field | Value |
182185
| --- | --- |
186+
| Generated at | `2026-07-02T02:30:32.494Z` |
187+
| Registry | `0x8F6563Bb9E53aeDfE9d87d4C1E162f0371649c18` |
188+
| Registry deploy tx | `0xae42c13c50c1b268a1d38389e27d8fa776264b405e28a1cf11a974dd4b178eae` |
189+
| Registry deploy block | `3854411` |
190+
| Registry runtime SHA-256 | `0x2c49443e7a9ebf3337453240e706df249d29f4f217ec948d6c10e9502a199d1f` |
183191
| Registry object | `1` |
184192
| Status | `Committed` |
185193
| Account id | `0xfaa4a252e3d762275f3bb2baccba097024ed47a08845bee0de79a2ee58514e01` |
186194
| Provider/dataset/piece | `4` / `12524` / `34` |
187195
| Piece CID | `bafkzcibeqcad6egqwuynxmfu6jof2lzkfdp65aelknasuautd4mmjgpvujkaq2ytey` |
188196
| Retrieval URL | `https://caliberation-pdp.infrafolio.com/piece/bafkzcibeqcad6egqwuynxmfu6jof2lzkfdp65aelknasuautd4mmjgpvujkaq2ytey` |
189197
| Worker URL | `https://foc-platform-calibration-demo.snissn.workers.dev` |
190-
| Worker version | `bee0fdaf-f4ac-4a6a-8556-46842d76c6cb` |
198+
| Worker version | `c83bd91f-164e-4a48-9d0a-06518cd51212` |
199+
| Dashboard direct-read proof | `objectCount=1`, `accountCount=1`, `datasetRecordCount=1`, `coordinatorCount=1`, `relayerCount=1`, `readBatch.resultCount=5` |
191200

192201
Public registry transaction hashes:
193202

194-
- `setCoordinator`: `0xcf21feda99029624d18bcf17035f0f5d0f9c7bc67680ca0d32f210d6acf370ce`
195-
- `requestUpload`: `0x552b1da9b049dc1301effcc34c497625a1e09934b25bec7e5a3fe607ba3382fd`
196-
- `startUpload`: `0x1d1104fb0807ff05f4a4c9045dcfc888a54bd6d143edab25e19ec6d4bd6a8bb1`
197-
- `recordDataset`: `0x3ec159924041a28531652a23ca4343f7aa8186da47f5c27cc6e8410bee5a3ea3`
198-
- `finalizeUpload`: `0xebbf1d335df22f3607e9552753360d80d48fd28d199ef0afa19f052d5fd57608`
203+
- `setCoordinator`: `0x22a29586247fa39e8d3277c754a42466f1936a3377f2d62ab50ddf1337035cd1`
204+
- `setRelayer`: `0x93153de2f1653b1e632dff19f2dfd632f5f2a6390af20b39097a53607c162570`
205+
- `requestUpload`: `0x35c561f8b6278b63deb1d272b8cc2b7663a45eb3cc564e75092bbeb5ebf12ccf`
206+
- `startUpload`: `0x6c57ded5248162049d64d372c2d1bde7e37c788edeedafc454bbbd2e3f841f38`
207+
- `recordDataset`: `0xb65836f00e8b7a24734e3d5e62d64ad305e3234fd879e2a435b1665d273b6669`
208+
- `finalizeUpload`: `0xe046f47af71e7da40ed475aba0e3ba8ac94677ae2de7341e1b59e2f8e367a2a4`
199209

200210
The FOC MCP upload call timed out before returning an add-piece transaction hash
201211
or cost field, but a read of dataset `12524` showed piece `34` with matching
202212
metadata and retrieval URL. The registry receipt therefore records zero
203213
`actualCost` and a zero `addPieceTxHash`, with that limitation preserved in
204214
`artifacts/calibration/demo-evidence.json`.
205215

206-
This run still does not prove a real session-key coordinator or expiry/revoke
207-
path. The local dev root address was allowlisted as coordinator to complete the
208-
public end-to-end Worker demo. It also does not prove the later direct
209-
pagination/list-read ABI; use it as historical Worker evidence until issue #33
210-
publishes updated list/detail/dashboard proof.
216+
This run proves the direct pagination/list/detail/readBatch ABI used by the
217+
Worker dashboard. It still does not prove a real session-key coordinator or
218+
expiry/revoke path. The local dev root address was allowlisted as coordinator
219+
and relayer to complete the public end-to-end Worker demo.

docs/deployment.md

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -93,6 +93,13 @@ Calibration registry deployment and runtime bytecode verification only. It does
9393
not prove FOC funding/approval, Synapse upload, session-key authorization,
9494
dataset attribution, receipt finalization, or expiry/revocation behavior.
9595

96+
The current direct-onchain Worker demo evidence is recorded in
97+
[`artifacts/calibration/demo-evidence.json`](../artifacts/calibration/demo-evidence.json)
98+
and [`docs/calibration-worker-demo.md`](./calibration-worker-demo.md). That
99+
evidence points at the pagination-capable Calibration registry used by the
100+
public dashboard and proves bounded count/list/detail/readBatch reads for the
101+
configured object.
102+
96103
## Read Model
97104

98105
`src/registry/read-model.mjs` exposes:

docs/platform-api.md

Lines changed: 6 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -112,10 +112,9 @@ GET /admin/storage/reconciliation
112112
```
113113

114114
Admin responses are built by `src/admin/reconciliation.mjs` from registry
115-
contract views or reconstructed event state today. The target direct-onchain
116-
dashboard path must enumerate current rows from `FocPlatformRegistry`
117-
list/count views and then fetch detail state from point reads or bounded
118-
`readBatch` calls:
115+
contract views or reconstructed event state. Current direct-onchain dashboard
116+
reads enumerate rows from `FocPlatformRegistry` list/count views and then fetch
117+
detail state from point reads or bounded `readBatch` calls:
119118

120119
- objects: `listStorageObjectIds` / `listAccountObjectIds` plus
121120
`getStorageObject`;
@@ -126,8 +125,8 @@ list/count views and then fetch detail state from point reads or bounded
126125
- receipts: `getCopyReceipts` and `receiptPayer`.
127126

128127
Event reconstruction may supplement audit/history screens and local fixtures,
129-
but it must not replace direct contract reads for current admin rows once the
130-
pagination ABI is available. Optional FOC evidence can be supplied by a
131-
wrapper; without it, stored-object reconciliation reports
128+
but it must not replace direct contract reads for current admin rows. Optional
129+
FOC evidence can be supplied by a wrapper; without it, stored-object
130+
reconciliation reports
132131
`foc_evidence_not_checked` rather than claiming live FOC verification. See
133132
[`docs/admin-reconciliation.md`](./admin-reconciliation.md).

0 commit comments

Comments
 (0)