Skip to content

TapeAPI 1.3.0

Choose a tag to compare

@BruceLanLan BruceLanLan released this 30 Sep 02:29
· 7 commits to main since this release

中文

TapeAPI 1.3.0:在 1.x 基础上只做新增,按 1.0 文档写的代码无需修改。新功能都标为实验性,默认关闭。发布前又做了四路实测排查和两轮独立审查,查出的问题都已修复,并补了回归测试。

新增

  • 默克尔证明模式(借鉴波卡轻客户端的思路):createTapeAPI({ pin: true, proofs: true | 'strict' })。
    • 做法:SDK 取回电路持有人、处理器登记、清单文件信息的 eth_getProof 证明,对照多家独立运营方共同确认的区块状态根,自己核验,不再只凭节点给出的答案。
    • 严格模式:即使所有节点串通给出同一个假答案,也会被识破。
    • 挡不住的情况:TapeOut 升级合约(那是真实的链上状态),以及所有运营方一起伪造区块头。
    • 独立审查:变异测试用例 7.7 万多个、对整个解析流程做攻击模拟,都没有找到伪造证明的路径。
    • 提供证明的默认节点(2026-09-30):BSC 有 Alchemy,Base 有 dRPC,X Layer 暂时没有,要在 X Layer 上用严格模式,请自己加入能出证明的节点。
  • 服务方目录:https://tapeapi.fun/directory/
    • 服务方通过 tapeapi-doctor 的检查后,自己提 PR 上架。
    • 每天自动做一次只读复核,不需要任何密钥。
    • 上架只代表通过了自动检查,不代表推荐、担保或审计。 不排名、不收费、不自动下架;TapeAPI 不替任何人上架,也不代付任何费用。

修复(来自 1.2.0 在三条主网上的实测)

  • 限流:节点限流不再被误判为"节点分歧"。Base 上 Coinbase、dRPC 的限流回答以前会报 RPC_DISAGREE。
  • 落后节点:节点落后、还没有被钉住的区块时,按"没有作答"处理。
  • 钉块时限按实测调整:X Layer 放宽到 600 秒,BSC 收紧到 120 秒。
  • 断线重试:连接断开的请求会重试一次,默认间隔 250 毫秒。X Layer 只有两家独立运营方,以前一次连接重置就会失败。
  • 格式 2 群聊(实验性):
    • 群主换钥时,复用未变成员的核验结论,128 人的群从 127 次核验降到 0 次;
    • 格式 2 的快照改为 v: 2,旧版会明确拒绝,不会再把群拆成两半;
    • 同一身份在两台设备上使用时,会给出明确提示。
  • tapeapi-doctor:给出的下一条命令与运行方式一致;按地址检查时,探测的是你输入的地址;诊断提示更对症;补上了 Windows(PowerShell)写法。
  • 文档与网站:第 0 步先运行 npm ci;文档写明公共中继只用于测试和小规模使用;公开源码里不再出现内部文件名。

默认情况下你会注意到的变化

  • 连接断开的请求会自动重试一次,最多多等 250 毫秒。
  • 用格式 2 建群的群主升级到 1.3.0 后,快照不能再回退给 1.2.0 使用(会明确报错)。

安装

npm install https://github.com/BruceLanLan/tapeapi/releases/download/v1.3.0/tapeapi-sdk-1.3.0.tgz

如果要单独安装 server,先装同一版本的 SDK tgz。完整变更见 CHANGELOG。本项目未经第三方审计。

感谢 @Theairresearch 提出最初的想法。


English

TapeAPI 1.3.0 is additive over 1.x: code written against the 1.0 docs keeps working unchanged. Everything new is experimental and off by default. Before this release we ran four live test sweeps and two independent reviews; every finding is fixed, each with a regression test.

Added

  • Merkle proof mode (the light-client idea, borrowed from Polkadot): createTapeAPI({ pin: true, proofs: true | 'strict' }).
    • How it works: the SDK fetches eth_getProof proofs for the circuit holder, the processor registry and the manifest's file info, and checks them itself against a block state root that several independent operators agree on, instead of relying only on what nodes answer.
    • Strict mode: it catches a false answer even when every node gives the same one.
    • What it cannot catch: an upgrade of TapeOut's contracts (that is real on-chain state), or every operator forging a block header together.
    • Independent review: over 77,000 fuzzed cases and attack simulations against the whole resolution found no way to forge a proof.
    • Default nodes that serve proofs (2026-09-30): Alchemy on BNB Smart Chain and dRPC on Base; none yet on X Layer. To use strict mode on X Layer, add a node that serves proofs.
  • Provider directory: https://tapeapi.fun/directory/
    • A service lists itself by pull request once tapeapi-doctor passes.
    • Every entry is rechecked once a day, read-only and with no key.
    • A listing only means the automated checks passed; it is not a recommendation, an endorsement or an audit. There is no ranking, no fee and no automatic removal. TapeAPI lists nobody itself and pays for nothing.

Fixed (from testing 1.2.0 on three mainnets)

  • Rate limits: a rate-limited node is no longer mistaken for a disagreement. On Base, rate-limit answers from Coinbase and dRPC used to fail with RPC_DISAGREE.
  • Lagging nodes: a node that has not yet reached the pinned block counts as not answering.
  • Pin age limits, set from measurements: 600 s on X Layer (was 300 s) and 120 s on BNB Smart Chain (was 180 s).
  • Broken connections: a request whose connection breaks is retried once, after 250 ms by default. X Layer has only two independent operators, so a single reset used to fail the read.
  • Groups, format 2 (experimental):
    • When the owner starts a new epoch, it reuses the checks of members that did not change: a 128-member group goes from 127 checks to 0.
    • Format-2 snapshots are now v: 2, which older versions refuse with a clear error instead of splitting the group.
    • One identity used on two devices is now flagged.
  • tapeapi-doctor: the next command it suggests matches how you ran it; URL mode probes the address you gave; diagnoses are more specific; PowerShell forms are included.
  • Docs and website: step 0 runs npm ci first; the docs say the public relay is for testing and small-scale use; the public source no longer names internal files.

What you will notice by default

  • A request whose connection breaks is retried once, adding at most 250 ms.
  • A format-2 group owner that upgrades to 1.3.0 cannot hand its snapshot back to 1.2.0 (1.2.0 refuses it with a clear error).

Install

npm install https://github.com/BruceLanLan/tapeapi/releases/download/v1.3.0/tapeapi-sdk-1.3.0.tgz

To install the server package on its own, first install the SDK tgz from the same release. The full list of changes is in the CHANGELOG. Nothing here has had a third-party audit.

Thanks to @Theairresearch for the original idea.