TapeAPI 1.3.0
中文
TapeAPI 1.3.0:在 1.x 基础上只做新增,按 1.0 文档写的代码无需修改。新功能都标为实验性,默认关闭。发布前又做了四路实测排查和两轮独立审查,查出的问题都已修复,并补了回归测试。
新增
- 默克尔证明模式(借鉴波卡轻客户端的思路):
createTapeAPI({ pin: true, proofs: true | 'strict' })。- 做法:SDK 取回电路持有人、处理器登记、清单文件信息的
eth_getProof证明,对照多家独立运营方共同确认的区块状态根,自己核验,不再只凭节点给出的答案。 - 严格模式:即使所有节点串通给出同一个假答案,也会被识破。
- 挡不住的情况:TapeOut 升级合约(那是真实的链上状态),以及所有运营方一起伪造区块头。
- 独立审查:变异测试用例 7.7 万多个、对整个解析流程做攻击模拟,都没有找到伪造证明的路径。
- 提供证明的默认节点(2026-09-30):BSC 有 Alchemy,Base 有 dRPC,X Layer 暂时没有,要在 X Layer 上用严格模式,请自己加入能出证明的节点。
- 做法:SDK 取回电路持有人、处理器登记、清单文件信息的
- 服务方目录:https://tapeapi.fun/directory/
- 服务方通过
tapeapi-doctor的检查后,自己提 PR 上架。 - 每天自动做一次只读复核,不需要任何密钥。
- 上架只代表通过了自动检查,不代表推荐、担保或审计。 不排名、不收费、不自动下架;TapeAPI 不替任何人上架,也不代付任何费用。
- 服务方通过
修复(来自 1.2.0 在三条主网上的实测)
- 限流:节点限流不再被误判为"节点分歧"。Base 上 Coinbase、dRPC 的限流回答以前会报
RPC_DISAGREE。 - 落后节点:节点落后、还没有被钉住的区块时,按"没有作答"处理。
- 钉块时限按实测调整:X Layer 放宽到 600 秒,BSC 收紧到 120 秒。
- 断线重试:连接断开的请求会重试一次,默认间隔 250 毫秒。X Layer 只有两家独立运营方,以前一次连接重置就会失败。
- 格式 2 群聊(实验性):
- 群主换钥时,复用未变成员的核验结论,128 人的群从 127 次核验降到 0 次;
- 格式 2 的快照改为
v: 2,旧版会明确拒绝,不会再把群拆成两半; - 同一身份在两台设备上使用时,会给出明确提示。
tapeapi-doctor:给出的下一条命令与运行方式一致;按地址检查时,探测的是你输入的地址;诊断提示更对症;补上了 Windows(PowerShell)写法。- 文档与网站:第 0 步先运行
npm ci;文档写明公共中继只用于测试和小规模使用;公开源码里不再出现内部文件名。
默认情况下你会注意到的变化
- 连接断开的请求会自动重试一次,最多多等 250 毫秒。
- 用格式 2 建群的群主升级到 1.3.0 后,快照不能再回退给 1.2.0 使用(会明确报错)。
安装
npm install https://github.com/BruceLanLan/tapeapi/releases/download/v1.3.0/tapeapi-sdk-1.3.0.tgz如果要单独安装 server,先装同一版本的 SDK tgz。完整变更见 CHANGELOG。本项目未经第三方审计。
感谢 @Theairresearch 提出最初的想法。
English
TapeAPI 1.3.0 is additive over 1.x: code written against the 1.0 docs keeps working unchanged. Everything new is experimental and off by default. Before this release we ran four live test sweeps and two independent reviews; every finding is fixed, each with a regression test.
Added
- Merkle proof mode (the light-client idea, borrowed from Polkadot):
createTapeAPI({ pin: true, proofs: true | 'strict' }).- How it works: the SDK fetches
eth_getProofproofs for the circuit holder, the processor registry and the manifest's file info, and checks them itself against a block state root that several independent operators agree on, instead of relying only on what nodes answer. - Strict mode: it catches a false answer even when every node gives the same one.
- What it cannot catch: an upgrade of TapeOut's contracts (that is real on-chain state), or every operator forging a block header together.
- Independent review: over 77,000 fuzzed cases and attack simulations against the whole resolution found no way to forge a proof.
- Default nodes that serve proofs (2026-09-30): Alchemy on BNB Smart Chain and dRPC on Base; none yet on X Layer. To use strict mode on X Layer, add a node that serves proofs.
- How it works: the SDK fetches
- Provider directory: https://tapeapi.fun/directory/
- A service lists itself by pull request once
tapeapi-doctorpasses. - Every entry is rechecked once a day, read-only and with no key.
- A listing only means the automated checks passed; it is not a recommendation, an endorsement or an audit. There is no ranking, no fee and no automatic removal. TapeAPI lists nobody itself and pays for nothing.
- A service lists itself by pull request once
Fixed (from testing 1.2.0 on three mainnets)
- Rate limits: a rate-limited node is no longer mistaken for a disagreement. On Base, rate-limit answers from Coinbase and dRPC used to fail with
RPC_DISAGREE. - Lagging nodes: a node that has not yet reached the pinned block counts as not answering.
- Pin age limits, set from measurements: 600 s on X Layer (was 300 s) and 120 s on BNB Smart Chain (was 180 s).
- Broken connections: a request whose connection breaks is retried once, after 250 ms by default. X Layer has only two independent operators, so a single reset used to fail the read.
- Groups, format 2 (experimental):
- When the owner starts a new epoch, it reuses the checks of members that did not change: a 128-member group goes from 127 checks to 0.
- Format-2 snapshots are now
v: 2, which older versions refuse with a clear error instead of splitting the group. - One identity used on two devices is now flagged.
tapeapi-doctor: the next command it suggests matches how you ran it; URL mode probes the address you gave; diagnoses are more specific; PowerShell forms are included.- Docs and website: step 0 runs
npm cifirst; the docs say the public relay is for testing and small-scale use; the public source no longer names internal files.
What you will notice by default
- A request whose connection breaks is retried once, adding at most 250 ms.
- A format-2 group owner that upgrades to 1.3.0 cannot hand its snapshot back to 1.2.0 (1.2.0 refuses it with a clear error).
Install
npm install https://github.com/BruceLanLan/tapeapi/releases/download/v1.3.0/tapeapi-sdk-1.3.0.tgzTo install the server package on its own, first install the SDK tgz from the same release. The full list of changes is in the CHANGELOG. Nothing here has had a third-party audit.
Thanks to @Theairresearch for the original idea.