ElastOS Weekly Shipping Report — Week of August 1 – August 7, 2026 #32
SashaMIT
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Elacity Labs — Weekly Team Update for the World Computer Initiative (WCI)
August 1 – August 7, 2026
Priority this week: Runtime, chain security, DKMS/content rails, and marketplace — not side tooling. Coming out of #31 (mainnet recovery + Runtime v0.6 on
main): Home / Sparks H3 dogfood onexperiment/home-studio-h3-dogfood(Live SSE, Inbox/library, Waves 4–6, Studio Generate/Storyboard/Character) — not formainyet;feat/dkms-esp-portREADY-FOR-MANUAL-MERGE against the 0.7-dev roadmap (content creation/playback ~75% functional — custody / protected content / commerce); Runtimemaingot a VZ TURN-ownership correctness fix; ELA tip ~2,267,480 (past gate 2,265,000) with private v1.0.3 security-readiness work recommending a narrow urgent cut then a follow-up (no public finding dump); drm-api backported Base 0.11 getLogs/CACHER to ESC (release/next, PR #4) and elacity-web 4.5.0 merged; Elastos.Node v1.2.3 fixedela rewoundfor post-v1.0.0 recovery builds; marketplace-adjacent hardening on ddrm-reader, events-watcher, drm CI. Hyper + hey-engine kept shipping. PC2 product-quiet. Formal Runtime v0.6.0 GitHub Release/tag still outstanding.Community status (8 Aug): mainchain producing blocks under BPoS and still being hardened. ESC / EID / Arbiter / bridge remain closed on purpose. Do not send funds into paused sidechain or bridge flows until official reopen. Details below and in the mainchain postmortem.
Key Links This Week
maintipd358ded·experiment/home-studio-h3-dogfoodtip2d33644· CHANGELOG [0.6.0] onmain· GitHub Release still v0.4.0bash <(curl -fsSL https://raw.githubusercontent.com/Elacity/pc2.net/main/scripts/update.sh)curl -fsSL https://elastos.elacitylabs.com/install.sh | bashTable of Contents
mainTail + Home Dogfood + DKMS/ESP Port1. The Big Picture — Runtime, Security, DKMS, Marketplace First
This week’s public story is the product and security spine of the World Computer stack — not the supporting ops tooling.
Zeroth — what is open and what is not. Mainchain recovered through halt → patch → rewind → restart → BPoS. ESC, EID, Arbiter, and the bridge stay closed until repair, accounting, and rehearsal clear a higher bar. See §2.
First — Runtime. Home / Sparks H3 dogfood on
experiment/home-studio-h3-dogfood(Live SSE, Inbox/library, Waves 4–6, Studio Generate/Storyboard/Character) — not formainuntil secure converge. In parallel,feat/dkms-esp-portis READY-FOR-MANUAL-MERGE vsupstream/0.7-dev: custody / protected content / commerce ~75% functional.mainitself only took a VZ TURN-ownership fix. See §3.Second — chain security hardening. Private v1.0.3 readiness work recommends a narrow urgent cut for the highest-urgency unauthenticated remote-abuse class, then a stated v1.0.4 for soak-heavy items — without publishing a finding register while related classes may still be live. Node v1.2.3 unblocks operator recovery tooling. See §4.
Third — marketplace. drm-api 0.11 → ESC indexer readiness (PR #4); elacity-web 4.5.0 merged; ddrm-reader / events-watcher / drm CI hardening in flight. ESC user reopen is still closed (§2). See §5.
Also shipping: Hyper / hey-engine (calls, radio, relay; one edition, no Play). PC2 product-quiet. A grant-backed continuous monitoring + admin review lane exists as supporting ops (§7) — useful IP for the ecosystem after the recent attacks; not the headline of this weekly.
2. Elastos Status (8 Aug) — Mainchain Online, Sidechains Closed on Purpose
Community framing from Elastos DAO / incident coordination (engineering led by the incident technical team). Not an “everything is fine” line — a clear account of what has been done since July, and what stays shut until it deserves confidence.
What we are recovering from
In July, Elastos faced serious security events on more than one layer.
Long form: Mainchain postmortem (August) · July security updates / Jul-15 notice on the Elastos blog as previously published · honest recovery log (engineering).
Mainchain — online, still being hardened
Recovery was a sequence, not a switch: emergency stop → consensus and money-path fixes → coordinated rewind → restart on upgraded software → return to BPoS with validators and Council process → height-gated safety improvements so history stays consistent while new protections activate cleanly going forward.
Today: mainchain is producing blocks again under BPoS (tip ~2,267,480 — past gate 2,265,000). Continuous work continues behind that: edge-case review, validating fixes against real behaviour, further hardening, and refusing to treat “chain is moving” as “all risk is gone.” More review and packaging for independent audit is still in flight.
If mainchain feels “back” while other parts of the ecosystem still feel frozen — that is intentional sequencing, not neglect of ESC or the bridge.
ESC, EID, Arbiter, and the bridge — still closed, for a reason
ESC, EID, the Arbiter / bridge relay, and related cross-chain paths remain closed to normal user activity.
The bridge is not one simple pipe:
A careless restart is dangerous: some paths can become active as soon as software is live, while others may still be broken or unsafe. The standard is not “turn it on and hope.” The standard is: understand the full defect surface, repair what must be repaired before first start, protect users who already have funds in awkward states, and rehearse restart conditions before inviting deposits and withdrawals again.
Actively in this lane (without a vulnerability catalogue): full pass over known concerns against production code; distinguishing real issues from false alarms; height-forward repairs that do not invalidate settled history; treating ESC and EID as related but not identical; accounting and user-impact work so reopen does not create double-pays, unpaid stuck transfers, or preventable new deposits into closed rooms; evidence preservation and operational steps on Council / relay machines before a clean restart; building toward a rehearsal environment so “is restart safe?” is answered by running the scenario.
Until that bar is met: do not expect bridge deposits/withdrawals, and do not send funds into sidechain or bridge flows “just in case.” Reopen will be announced — people will not be surprised into a half-open bridge. Gaming / PG chain operators and wallet UX that still point users at closed paths are part of the same ops conversation: stop growing avoidable stuck balances while the door is shut.
Governance — verified harm, not exploit proceeds
Cyber Republic / Council process has been running an Incident Recovery program: sequential CRC proposals for verified make-whole and partner continuity. That is not a payout of exploit proceeds or a reward for fabricated balances. Voting has been progressing across the tranche series. Exact counterparty settlement figures stay confidential while partner processes continue; the public commitment is the program itself, the postmortem framing, and later fuller accounting when it is safe to publish. Slow on purpose.
Independent security review
Multiple external security firms are engaged under NDA for phased review of the corrected mainchain (and related) work. The repository remains closed until a locked patch set is handed over — so reviewers are not chasing a moving target, and unfinished attack surface is not published while fixes are still landing. Sidechain / bridge review depth is on its own reopen clock.
Exchanges, partners, and market protection
Continuous private coordination with exchange and partner channels on reconciliation, risk controls, and protecting ordinary users from further harm related to incident-linked balances and accounting mismatches after the rewind. Markets and users should not absorb a second wave of damage because someone was impatient to unlock everything. Partner make-whole and technical reopen are both part of restoring trust — they are not substitutes for each other.
What this means for you right now
“Why isn’t ESC back if mainchain is back?” — fair question. Answer: different risk, automatic paths on restart, unfinished repair and rehearsal. That is diligence, not delay for its own sake.
A small set of engineers, Council members, operators, and coordinators have been working this incident stack for weeks — often in parallel, often with little sleep. Judge the work by its scope: protect users first, reopen only when the stack deserves confidence, and say plainly when a door is still shut on purpose.
Further public posts when there is a concrete ESC / bridge milestone, a locked audit handoff the community should know about, or a governance milestone that changes the public picture.
3. Runtime —
mainTail + Home Dogfood + DKMS/ESP PortThree Runtime stories this cycle: a small
maincorrectness fix; Home / Studio dogfood on an experiment line; and a DKMS/ESP content-rails port marked READY-FOR-MANUAL-MERGE against the 0.7-dev roadmap.main—d358dedfix(vz): scope TURN cleanup to launch ownership (+19/−2)TURN listener/relay port probes now run only when this owner may have started TURN (
Owned/Indeterminate). A foreign listener on the TURN port no longer forges a cleanup obligation. (Portable stdin classification and hanging-close test scaffolding from late last week remain onmain.)0.6 GitHub Release/tag: still not published (latest Release object v0.4.0). Decide whether the tagged build includes
d358dedor freezes earlier.experiment/home-studio-h3-dogfood— Home-agent waves + Sparks H3 (not formain)Tip
2d33644(2026-08-08). Ahead ofmainwith Wave 0 sync of 0.6 browser/wallet/VZ plus this week’s product dogfood. Authors: SashaMIT / Sash. Framing: experimental AI-harness dogfood; not formain; refine against runtime principles and CTO infra before a secure converge.main(0.6 browser/wallet/VZ)library.readonce loop; honest ADE Diff/Term/Help Browser copyweb.searchExit/net fail-closed stubtag:/#tagsession search; honest vision-attach stubCREATIVE_*bridge, clip library, prepare/stitch, Studio UI)feat/dkms-esp-port— content rails vsupstream/0.7-devroadmap (7 Aug)Team roadmap coverage — tip
e2cc4229(5 commits), status READY-FOR-MANUAL-MERGE. Functional % vs Aligned % (discount for ESP target model: facts/verbs conversation plane, Runtime-owned authority, capsule interaction contracts). Work is ready for manual merge; not onmainyet.In the content section:
feat/elastos-dkms-custodyfeat/elastos-protected-contentfeat/elastos-content-commercefeat/elastos-webspace-interopESP alignment in one sentence: data and authority planes are on the target model (provider hostcalls, manifests/catalog, viewers/creator as web-projections, money verbs under Home — no new authority path). The conversation plane is not — commerce/viewer still REST-ish gateway + bespoke postMessage, same debt main’s wallet/system surfaces owe; belongs to
feat/shell-ui-esp, not a dkms rework. Biggest in-section gap to “chain-mode-live”:RequiredHomeLaunchToken/ subject-resolution threading.Scheduling note:
feat/elastos-egress-policy~45% pre-seeded (crosvm egress audit/firewall + tests) — consider pulling earlier. When shell-ui ESP verbs land, commerce/protected-content aligned % converges up with little dkms-side work.Also still open on longer shell lines:
feat/shell-ui-esp-on-protocol-extended-ai-work,feat/shell-ui-esp-on-protocol,feat/shell-ui-v1, and related protocol work — carried forward, not the focus of this week’s landings.4. Ecosystem — Node v1.2.3 + ELA Tip + v1.0.3 Security Readiness (High Level)
Elastos.Node — v1.2.3 (2026-08-03)
ela rewoundrejected every build after v1.0.0. The binary check matched the version string exactly, so a node correctly running v1.0.2 was told it could not perform recovery and never reported READY. Point releases after the recovery build are the normal case once the chain is running again.Fix: accept v1.0.0 or later, compared as version numbers (not strings). String compare fails both ways (
1.0.2<1.0.0,0.9.9.6>1.0.0, etc.). Prerelease builds are accepted but reported as such.ELA mainnet tip
Public RPC height ~2,267,480 (Aug 8 check). Gate two (2,265,000 — ELA-only reward mint / arbiter fee base from the recovery log) is behind tip. Promote those two recovery items toward proven live when the honest-log scan band is republished across the gate (do not invent mint figures here).
Elastos.ELA: live binary remains v1.0.2. The public tree stays quiet while a locked point-release package is prepared — same posture as §2’s audit handoff note.
ELA v1.0.3 security readiness — high level only (team, 6 Aug)
Decision: do not publish the finding register or attack recipes here. A teammate release-readiness brief (independent multi-pass adversarial review of a private v1.0.3 candidate tree) confirms there is still urgent hardening work before a broad “ship everything” cut. For the community weekly we keep only sequencing and process — not a vulnerability catalogue.
What is safe and useful to say:
If leadership later wants a short community advisory after the urgent cut is live, that is a separate post — not this weekly’s job.
5. Marketplace — drm-api 0.11 → ESC + web 4.5.0 + Hardening Branches
drm-api-layer — PR #4 merged →
release/next(ESC)Last week’s “worth continuing” item: port Base 0.11 adaptive
eth_getLogs+ CACHER pack to ESC. Done surgically (not a FF of Base tip — Base is ~247 commits ahead with Base-only product).fromBlock0)resolveCacher+ TTL clamp; db.mixin cache-clean broadcast (best-effort)blockNumberBatch50000,logScan.maxChunk5MContext: this is marketplace / indexer readiness against ESC’s chain ID and scan model — not an announcement that ESC or the bridge are open for users. ESC remains closed pending the reopen bar in §2.
Open: PR #5 — CI guard against exposing server-key-signed payable actions without authorization.
elacity-web — PR #25 merged (2026-08-03)
GitHub now matches last week’s deploy report: 4.5.0 on
release/base-network(bump commit84d729a+ polish merge). Light-mode / sell-flow / withdraw / offline toast from prior cycle are on the release line.Marketplace-adjacent hardening branches
Not all merged to default yet:
fix/reader-fetch-hardeningfeat/discovery-max-trackersdiscovery_max_trackersci/server-key-action-guard6. Hyper + Hey-engine — Calls, Radio, Relay
Hyper (6 · HeyElastos)
Hey-engine (18 · HeyElastos)
net_reportwhile backgrounded; stop asking a non-existent gateway for port mapping; do not dial a peer already directly connected; stop shouting at impossible addresses7. Supporting Ops — Continuous Monitoring Admin (Grant Lane)
Secondary this week — supporting the ecosystem after the recent attacks, not the product headline.
Under a grant-backed lane, ElacityLabsWeb continues building a private continuous code-monitoring admin: watch our ecosystem repositories for bug-class findings, surface them for human review, and drive PRs that fix what is confirmed — a fast feedback loop so Elastos / Elacity stack code does not wait on ad-hoc discovery alone. Unified
/adminshell, sprint lanes (including awaiting-review / merged-only Done / Archived), severity chips, session hardening (httpOnly cookie dual-read), deploy-resilient lazy chunks, and discovery cadence for that monitoring pipeline.This is our ecosystem’s monitoring + triage + fix-PR workflow in response to the July incident stack. The same machinery is reusable IP elsewhere by design; that is not the focus of this weekly.
Admin auth/resilience polish this cycle (cookie sessions, Translate/DOM guards, finding-create defaults, cron alignment) keeps the review surface usable for operators. Details stay ops-internal; no finding catalogues in this post.
8. PC2 — Convergence Continues (Docs Only)
Product landings: quiet this week. Operator line remains v1.4.0. PC2 lessons continue to live inside Runtime; quiet weeks are expected.
9. Release Engineering — 0.6 Tag Still Pending
mainmerged358dedmainthis cycle10. Convergence Lens
experiment/home-studio-h3-dogfood)feat/dkms-esp-portREADY-FOR-MANUAL-MERGE (~75%)mainyetReading: lead with Runtime + chain security + DKMS + marketplace. Supporting monitoring admin is real grant work after the attacks — keep it in the appendix of the narrative, not the lede.
11. Looking Ahead
mainmergefeat/dkms-esp-portmanual merge — visible tip; land vs 0.7-dev;RequiredHomeLaunchTokenis the chain-mode gate; ESP conversation plane withfeat/shell-ui-espv0.6.0release/nextpost-0.11; land drm CI server-key guard; ddrm-reader / events-watcher hardening12. Summary Statistics
Week of August 1 – August 7, 2026 (community status note 8 August).
experiment/home-studio-h3-dogfood(tip2d33644)feat/dkms-esp-port@e2cc4229— content ~75% / ~70% alignedmaind358dedTURN cleanup ownershipmain) · HeyElastos (Hyper/hey-engine) · 4HM3DMD (Node) · irzhywau (drm/web) · team DKMS + ELA readiness work13. Notes
Quick fact card
mainyetCadence: weekly updates. Previous report — Week of July 24 – July 31, 2026 (#31). This report — #32.
All reactions