Repository navigation
Conversation
… Explore Buying and reading become two workflows with two datasets. A purchase names an item, a seller and the terms the buyer agreed to, and rests on chain terms alone; opening keeps the existing custody read path. - Chain-provider: resolve an item's operative and token URI, a content id's binding, every live offer (32-seller cap), an item-keyed access read (hasAccess(address,address,uint256)) and the verified listing. Every corroborated read pins its sources to the lowest finalized block they agree on. A rate-limited source is retried briefly, then read around for 60 s, and a read stops once two sources agree. - Listing object: POST /api/apps/marketplace/listing rebuilds an item's listing from a token URI, a content id or (ledger, tokenId), with every live seller's terms. The shared metadata.json and the KID binding are readability evidence only (verified, unverified, foreign or unknown), never a purchase gate. A proven KID contradiction is refused. - buy_offer: one copy on exactly the agreed terms; terms_changed, attempt_in_progress and own_offer answers. Ownership is checked on chain by item before paying. A buyer holds at most one open purchase per item across buy and buy_offer, created under a per-principal lock and updated or retired only by its own attempt; a declined or reverted attempt is retired. Wallet addresses are redacted from error detail. - Adoption: a completed purchase of an ElastOS-protected item becomes the records the open path reads, built from the shared metadata.json once its KID is proven; other items stay foreign. - Marketplace capsule: offer sheet with every live seller, buy from a link or from Explore, resumable recorded attempts, Download copy for a pending adoption, a Details view of a bought item's properties, owned labels that follow what this Home holds, and Explore opening on the market with one automatic retry. Modals open on Close. - Providers: an idled Kubo is restarted instead of failing every fetch; the market index gets time for a cold cache and one retry. Design: docs/audits/2026-09-24-protected-content-market-buy-design.md Report: docs/audits/2026-09-25-protected-content-market-buy-implementation-report.md
irzhywau
added this pull request to stack #61
September 25, 2026 19:08
Contributor
|
Thanks, Irzhy. We are keeping J5 listing and Buy work for later in 0.7.2 while we finish the focused release path. I have not reviewed this PR yet. Please keep it open for a separate review. |
…d of failing Custody releases a key share only on rights evidence read at the finalized block. On Base that trails a confirmed mint or purchase by 15-20 minutes, so an open attempted right after one spent a Wallet approval and three custody calls, then failed closed as "unavailable". The finalized-only rule stays; the open now recognises the wait and says so. - Chain-provider: resolve_protected_content_purchase_access takes an optional block (latest by default, so existing callers are unchanged). At finalized it asks exactly the question custody will ask. - Runtime open: for a copy confirmed less than an hour ago, before any Wallet request or custody call, access is read at finalized and then at the head. Granted only at the head answers the new typed `finalizing` stage (resumable, awaits nobody, with an estimated ready_at). Every other answer, including a failed read, leaves the open unchanged. - Reader and Player: wait through `finalizing`, asking every 15 s for up to 40 minutes, and show when the copy is expected to open. - Docs: why key release rests on finalized state rather than safe, what the wait costs, and how the open handles it.
… terminal cleanup proof is not adopted The assertion printed only the state, so a cleanup_pending answer could not say which fallback produced it. It now prints the whole response, reason included.
irzhywau
force-pushed
the
feat/protected-content-listing-buy
branch
2 times, most recently
from
September 28, 2026 11:30
224ad7c to
d181ffd
Compare
This was referenced Sep 29, 2026
3 of 7 tasks
5 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #62 (
feat/protected-content-0.7.1-followup). It merges only after, or together with, #62.What this does
A buyer can buy one copy of any protected item that has a live offer on chain, whoever minted it: this Runtime,
base.ela.cityor the SDK. The item can come from a pasted link or from Explore. The purchase rests on chain terms alone. Reading (open, playback) is a separate workflow with its own dataset, the sharedmetadata.json, and never blocks a purchase.docs/audits/2026-09-24-protected-content-market-buy-design.mddocs/audits/2026-09-25-protected-content-market-buy-implementation-report.mddocs/PROTECTED_CONTENT.md(steps 7–8, "Buying from an offer")TASKS.md, "Buy from any live offer"Changes
chain-provider reads corroborated by two sources pinned to a common finalized block:
hasAccess(address,address,uint256));A source that returns HTTP 429 gets a short retry, then a 60 s cooldown while the read goes on without it. A read stops once two sources agree.
Runtime:
POST /api/apps/marketplace/listingreturns aListingObjectbuilt from a token URI, a KID or(ledger, tokenId).buy_offerbuys on the agreed terms and answersterms_changed,attempt_in_progressorown_offerwhere they apply.buyandbuy_offer.metadata.json.Marketplace capsule:
Providers:
Verification
-D warningshome-entropy-check,git diff --checkMoney and security behaviour went through four independent reviews (security/money, protocol/spec, capsule UI, tests/quality) and a scoped re-review after each fix round. No Critical or Important finding is open.
Installed, Base mainnet, 25 September: a buyer Home bought an ERC-20 (USDC) offer from Explore. The item was minted on
base.ela.citywith Lit custody.approve, thenbuyAccess.0x4d8ba231db31d81239af3257832335b3d951578bd150eb4ba2a2aba4b971bc12.foreign, which is correct for Lit custody.Not covered yet
TASKS.md(R37).