TapeAPI 1.2.0
中文
TapeAPI 1.2.0:在 1.x 基础上只做新增,按 1.0 文档写的代码无需修改。本版新功能都标为实验性,默认关闭或只给出警告。发布前经过两轮独立审查,查出的 18 个问题都已修复,并补了回归测试。
AI 中转站:从零到上线,每一步都能自检
- 本地试跑:在仓库检出里先运行
npm ci,再运行node examples/relay-trial/trial.mjs。不需要密钥,不需要电路,也不花钱,就能看到签名回答、回执核验,以及一个字节被篡改后当场被识破。 tapeapi-doctor:随 SDK 安装的新命令行工具,按顺序检查一个 AI 服务的 13 项,从名字、电路、容器、清单、委托剩余天数,到端点、TLS、CORS、回执。每项失败都给出中英双语的修复提示。- 退出码可直接用于 CI。
- 用
--key-env做真实调用时,密钥只发往被检查的主机,只走 https,并且在所有输出中都显示为***。
- 指南开头新增“从零到上线”清单:每一步写明谁付钱、用什么命令检查。所有
42.1013.tape的示例都注明了是示例名。 - TapeAPI 不托管任何人的旁路,也不代付电路、容器或 gas。
安全加固(借鉴波卡的共享安全思路,不造链、不发币)
pin:一次解析的全部读取都钉在同一个区块上,这个区块由多家运营方共同确认;区块过旧时报RPC_STALE。- 身份根哨兵:检查 TapeOut 核心合约(DeWebHub、SiteRegistry)的实现是否是已知版本,并在本地推导容器地址做交叉核对。能发现升级,阻止不了升级。
- 可选的清单内容签名(TAP-20 §3.10):开启
requireContentSig后,能写站点的人无法在委托有效期内悄悄改掉ai.baseUrl或价格。 - 矛盾证据(ContradictionRecord v1):提供者对同一请求给出互相矛盾的签名回答时,会留下任何人都能核验的证据。另外提供随机抽查(默认关闭)和委托下限。
更大的群聊(实验性)
- 成员核验改为并行:32 人的群冷启动,在每个请求 280 ms 的条件下,从约 45 秒降到约 6 秒。
- TAP-27 §3.8 新增格式 2:一个群最多 128 人。成员核验改为按需进行,尚未核验的发送者会被标为“未核验”。
- 默认仍是格式 1,字节布局不变。
- 旧版客户端遇到格式 2 的群,会收到明确的
GROUP_INVALID错误。
默认情况下你会注意到的变化
- 哨兵默认只警告:如果 TapeOut 将来升级了核心合约,在 SDK 更新之前,每个客户端会为每个合约各打印一次
console.warn,解析本身不受影响。不想要这个警告,可以设置sentinel: 'off'。 - 首次解析(冷启动)的请求数:对本链合约的一次冷启动解析,从 12 个请求增加到 18 个。多出来的是哨兵读取实现槽的请求,结果缓存 300 秒,轮数不变。
- 读取钉在具体区块上时(包括
rpc.call传入十六进制块号),如果某个节点还没同步到该区块,它会被当作“没有作答”,不再判为节点分歧。
安装
npm install https://github.com/BruceLanLan/tapeapi/releases/download/v1.2.0/tapeapi-sdk-1.2.0.tgz如果要单独安装 server,先装同一版本的 SDK tgz。完整变更见 CHANGELOG。本项目未经第三方审计。
感谢 @Theairresearch 提出最初的想法。
English
TapeAPI 1.2.0 is additive over 1.x: code written against the 1.0 docs keeps working unchanged. Everything new in this release is experimental and is either off or warn-only by default. Two independent reviews ran before release; all 18 findings are fixed, each with a regression test.
AI relays: from nothing to live, with a check at every step
- Local trial: in a checkout, run
npm ci, thennode examples/relay-trial/trial.mjs. With no key, no circuit and no cost, you see signed answers, verified receipts, and a one-byte tamper caught. tapeapi-doctor: a new command installed with the SDK. It checks an AI service in 13 ordered steps, from name, circuit, container, manifest and days left on the delegation to endpoints, TLS, CORS and receipts. Each failure comes with a fix in English and Chinese.- The exit status is usable in CI.
- With
--key-env, the key goes only to the checked host, only over https, and shows as***in every output.
- The AI providers guide now opens with "From zero to live": each step, who pays, and the command that checks it. Every
42.1013.tapeexample is marked as an example name. - TapeAPI hosts nobody's sidecar and pays for nobody's circuits, containers or gas.
Security hardening (ideas from Polkadot's shared security; no chain, no token)
pin: every read of one resolution is pinned to one block confirmed by several operators; a block that is too old is refused withRPC_STALE.- Identity-root sentinel: checks that TapeOut's core contracts (DeWebHub, SiteRegistry) run known implementations, and cross-checks the container address against a local derivation. It notices an upgrade; it cannot prevent one.
- Optional holder-signed manifest content (TAP-20 §3.10): with
requireContentSig, whoever can write the site cannot quietly changeai.baseUrlor prices while the delegation is valid. - Contradiction evidence (ContradictionRecord v1): when providers sign conflicting answers to the same request, they leave evidence anyone can check. Also included: spot checks (off by default) and a delegation floor.
Larger groups (experimental)
- Member checks run in parallel: a 32-member cold start at 280 ms per request goes from about 45 s to about 6 s.
- TAP-27 §3.8 format 2: up to 128 members in one group. Member checks happen on demand, and senders not yet checked are marked "unverified".
- Format 1 stays the default, and its byte layout is unchanged.
- Older clients that meet a format-2 group get a clear
GROUP_INVALIDerror.
What you will notice by default
- The sentinel only warns by default. If TapeOut upgrades its core contracts, every client prints one
console.warnper contract until the SDK is updated; resolution itself is not affected. To turn the warning off, setsentinel: 'off'. - Requests on a cold resolve. A cold resolve on the chain's own contracts now sends 18 requests instead of 12. The extra requests are the sentinel's implementation-slot reads; the result is cached for 300 s, and the number of rounds is unchanged.
- When a read is pinned to a specific block (including
rpc.callwith a hex block number), a node that has not reached that block yet counts as not answering, not as a disagreement.
Install
npm install https://github.com/BruceLanLan/tapeapi/releases/download/v1.2.0/tapeapi-sdk-1.2.0.tgzTo install the server package on its own, first install the SDK tgz from the same release. The full list of changes is in the CHANGELOG. Nothing here has had a third-party audit.
Thanks to @Theairresearch for the original idea.