Skip to content

v1.0.0

Latest

Choose a tag to compare

@github-actions github-actions released this 07 Aug 14:27
641187e

Changelog - singularity v1.0.0 "Cygnus"

Welcome to the first major release since v0.5.17. This release brings
experimental PDP/DDO support, a wallet/actor model split, a new database story, a trustless IPFS gateway, and a
broad dependency refresh.

Please carefully read the Migration Guide and Breaking Changes

v1.0.0 is named after Cyg X-1 and future releases will carry the names of celestial objects in this class

Highlights

PDP warm storage on FWSS registry. New --deal-type pdp schedules A new PDP tracker materializes PDPVerifier events into a local view for proofset tracking.
Experimental in v1.0 -- onboarding-to-active is verified
end-to-end on calibnet; termination tracking is pending FIP-0112.
See Infrastructure Notes.

DDO cold storage New --deal-type ddo
schedules submit allocations to a configurable on-chain contract,
paid in an ERC20 token (USDFC by default on calibnet). The legacy
f05 verified-deal flow still works and remains the default for
production mainnet workloads. Experimental in v1.0 -- onboarding
works against FIP-0109-enabled networks; Curio's mk20 onboarding
pipeline is partially in place, the full documented path is still
forming. See
Infrastructure Notes.

Trustless IPFS gateway on the content-provider: /ipfs/ endpoint backed by boxo/gateway for content CID retrieval

Preparation deletes complete in bounded time: deferred batch-based cleanup with SET NULL and reaper task instead of cascades

Devcontainer-based CI on podman: near-isomorphic (because github runners) testing between local dev and CI

Before upgrading: read the Migration Guide and
the Breaking Changes sections at the bottom of
this document. The schema migration is auto-applied by
singularity admin init (or implicitly on the next run ...
startup), but the initial run for this release can take several
minutes due to index rebuilds; halt other singularity services and
run admin init standalone the first time. Operators on MongoDB or
MySQL need an offline data migration before upgrading -- see the
migration guide.

New --no-automigrate flag to disable implicit per-process AutoMigrate if admin init is run in prestart task


Features

PDP deal type

Status: experimental in v1.0. Requires Curio v1.27.4+ (first release
where PDP is on the main release train). Termination is not yet
tracked -- deals remain state=active after the underlying proof set
is removed, until FIP-0112 activates. See
Infrastructure readiness for
the full caveats and operator gotchas.

  • End-to-end PDP path -- new --deal-type pdp schedule mode that
    drives the FWSS pull flow via Curio's /pdp/piece/pull and
    /pdp/data-sets/create-and-add endpoints. SP fetches pieces from
    singularity's content provider, then submits the on-chain commit from
    its own wallet with the recordKeeper (FWSS) as listener. (#678,
    #628, #623, #617)
  • PDP shovel indexer -- materialized view of PDPVerifier events
    (DataSetCreated, PiecesAdded, StorageProviderChanged,
    PiecesRemoved) into pdp_proof_sets for fast tracker queries.
    (#617)
  • PDP deal tracker -- f41 deal support, polls FWSS state, surfaces
    next-challenge epoch and proof-set status per deal. (#609, #612)
  • PDP config knobs -- --pdp-batch-size,
    --pdp-max-pieces-per-proofset, --pdp-pull-timeout,
    --pdp-source-url-base, --pdp-record-keeper on deal-pusher. The
    --pdp-source-url-base is required when running PDP schedules and
    must point at an HTTPS host where Curio can fetch pieces by
    PieceCIDv2 (<base>/piece/<v2>).
  • send-manual-pdp command -- single-piece push for diagnostic /
    e2e use; mirrors the scheduler path through PullPiecesToFWSS.
  • content-provider accepts v2 CIDs -- the singularity
    content-provider can now serve pieces under their PieceCIDv2 path so
    Curio's pull validation succeeds. (#688)

DDO deal type

Status: experimental in v1.0. Onboarding-to-active works against
FIP-0109-enabled networks (calibnet nv27+, mainnet nv27+); SP-side
mk20 support is partially in place but the documented production
setup path is still forming. Termination is not yet tracked. Set
--duration to match the SP's sector lifetime (--duration 1555200
for Curio's default) to avoid stalled ProveCommits. See
Infrastructure readiness.

  • DDO as third deal type -- --deal-type ddo schedules submit
    allocations to a configurable Diamond proxy, wait for confirmation,
    and create Deal rows tagged with DealTypeDDO and a payment-rail
    ID. (#644)
  • DDO config knobs -- --ddo-contract, --ddo-payments-contract,
    --ddo-payment-token, --ddo-batch-size, --ddo-confirmation-depth,
    --ddo-poll-interval, --ddo-term-min, --ddo-term-max,
    --ddo-expiration-offset on deal-pusher.
  • DDO E2E integration tests -- Anvil-based on-chain fixture that
    exercises the full create-allocation -> wait -> deal-record flow.
    (#655, #653)
  • Payment-token balance warnings -- DDO scheduling logs warnings
    when the payer's USDFC (or configured token) balance is below the
    one-month rate. (#656)
  • Term-max clamping --
    reject legacy price-per-epoch flags that don't apply to DDO. (#666)
  • DDO docs + wallet funding prerequisite call-out in the runbook.

Trustless IPFS gateway

  • /ipfs/ endpoint on content-provider -- boxo-backed gateway over
    the same rclone storage handler used for direct piece fetches;
    content-addressed block retrieval with no spurious side-loads. (#646)
  • Parallel span reads for block retrieval -- the gateway blockstore
    fetches each block via an offset/length span read, with bounded
    parallel prefetch and an LRU block cache, rather than holding a single
    reader open per storage. Scales across concurrent /ipfs requests
    instead of serializing on one handle. (#683)
  • rclone v1.73.2 via patched fork -- per-storage handler pool, pacer
    optimization, cache-invalidation and rawData fixes. (#646)

Schedules + deal-pusher

  • Explicit deal_type per schedule -- --deal-type market (legacy), --deal-type pdp, --deal-type ddo. (#623, #644)
  • create-batch simplification -- repeatable --deal-type replaces
    the old --replication semantics; loop nesting fixed so policies
    iterate before providers. (#652)
  • schedule list --group filter for grouped schedules. (#654)
  • Cleaner final-state handling -- stale error messages on a
    schedule are cleared once it completes successfully. (#637)

Storage + dataprep

  • prep delete-piece -- delete specific pieces from a preparation
    by CID. (#602)
  • Small piece padding -- pad pieces below the Curio verified deal minimum with
    literal zeroes (materialized in non-inline mode and on the fly for inline) (#595,
    #597)
  • add-piece lookup by CID -- consolidates pieces across
    preparations by reusing an existing piece record when the CID matches.
    (#607)
  • Non-deterministic inline DAG fix -- inline preparations now
    produce deterministic piece CIDs across regeneration. (#657)

Wallet model

  • Wallet/Actor split -- a Wallet is the key-bearing entity (1:1
    with a keystore entry), an Actor is the on-chain miner identity. A
    preparation is wired to a single wallet (1:1, no more random
    chooser). Migration runs automatically via admin init +
    export-keys. (#629, #627, #622, #650)
  • Keystore-relative key paths -- wallets.key_path stores names
    rather than absolute paths so keystore relocation works. (#661)
  • go-synapse signer -- replaces go-filsigner; one signer handles
    both Filecoin-native signing and FEVM EIP-712 typed data via
    SignDigest. (#622)
  • Wallet funding prerequisite docs for DDO scheduling.

Performance + correctness

Database

  • Nullable FKs for bulk deletes -- car_blocks.file_id,
    car_blocks.car_id, etc. are nullable pointers; deletion of a parent
    sets them NULL instead of cascading, and a separate reaper task
    cleans up orphans in bounded batches. Makes preparation-delete and
    job-delete linear in the table size you actually want to clear, not
    in the orphan set. (#600)
  • Index on car_blocks.file_id -- fixes the FK cascade scan that
    blocked completion of large preparation deletes. (#665)
  • Index on files.attachment_id -- same story for cleanup of
    attachment trees.
  • SKIP LOCKED job claiming -- no more deadlocks between
    concurrent workers claiming jobs; associations loaded after the claim
    to keep the lock window short.
  • Auto sequence-reset on Postgres -- admin init detects stale
    sequences (common after data imports with explicit IDs) and fixes
    them. Standalone script
    scripts/fix-sequences-after-import.sql for manual runs. (#583)
  • Piece-type auto-classification -- admin init infers
    piece_type (data vs dag) for CAR files that predate the column.
    Required for Curio compatibility on DAG-only pieces. (#583)
  • GORM v1.31 -- fixes around cascade behavior, transaction safety.
  • stripWalletAssignmentFKs errors checked -- previously silently
    ignored. (#674)

Bug fixes

  • car_blocks.file_id IS NULL no longer mistaken for orphan --
    null file_id is valid intermediate data and must not be deleted on
    that filter alone. (#662)
  • Skip orphan cars during piece metadata lookup -- prevent
    crashes from cars whose preparation has been deleted but whose
    car_blocks remain.
  • Out-of-bounds in lone-error handler returns -- API path that
    returned an error response in a single-element slice was indexing
    before checking. (#670)
  • Err order + %d/string mismatch in ListPiecesHandler -- error
    was constructed after the early return; format string mismatched the
    value type. (#673)
  • dealtracker shadowed err -- inner result.Error was returned
    via the wrong identifier, masking failures. (#671)
  • datasetworker MaxInterval default -- applied to the right
    field; previously a typo silently left the interval at zero. (#672)
  • add-piece parser bug -- positional args were being treated as
    subcommands. (#607)
  • urfave/cli duplicate provider flag panic -- guard before
    registration.

Infrastructure

CI + dev environment

  • Devcontainer-based CI on podman -- replaces the older
    matrix-of-images workflow with a single devcontainer that includes
    PostgreSQL (and MySQL while it lasted) plus the toolchain. Same
    container the maintainers use locally, so dialect-specific test
    failures are reproducible. (#586, #620)
  • Skip codegen when inputs unchanged -- CI no longer regenerates
    swagger/clients when none of the codegen input paths changed. (#619)
  • forge alongside anvil in the devcontainer for DDO/PDP test
    fixtures. (#675)
  • gotestsum junit output -- test results reported back to GitHub
    Actions as proper junit failures.
  • Cross-compiled release binaries -- goreleaser builds linux/windows
    via CGO + zig cross-compilation and macOS natively. (#681)
  • Vendored FVM-solidity mocks -- DDO test fixtures no longer fetch
    external solidity sources; mocks shipped in-repo with CBOR metadata
    stripped to keep deterministic bytecode. (#669, #676, #667)
  • MySQL/MariaDB removed wholesale -- not just the driver but the
    mysql-specific deadlock-debug tracing (database/deadlock_debug.go,
    util/testutil/deadlock.go), the deadlock test fixtures in
    handler/dataprep and service/healthcheck, the
    .devcontainer/init-mysql.sh / start-mysql.sh startup scripts, the
    CI's mysql DSN env in .github/actions/go-test-setup, the
    mysql-specific FK migration branches in model/migrate.go, and the
    mysql DSN branches in database/connstring*.go. Net -484 lines.
    (#658)

Container image

  • Distroless cc-debian12 runner -- smaller image, fewer CVEs;
    builder stage matched to the runner toolchain. (#592)
  • Container build gated on green CI or release -- avoids
    publishing red images. (#611)

Dependencies

Significant bumps; full list in go.mod. Highlights:

  • gorm v1.31 with cascade fixes
  • boxo v0.35 (and lassie vendored without bitswap)
  • rclone v1.73.2 via parkan/rclone fork (cache + pacer fixes)
  • libp2p, go-swagger v0.33.1, golang.org/x/crypto/net/text
  • pgx v5.9.2 + a security-focused dependency refresh for the release
    cut (#685)
  • go-synapse as the FEVM/PDP SDK
  • toolchain bumped to Go 1.26.5 (go.mod, release + devcontainer images)

Breaking Changes

These all require operator action; see the Migration Guide
for the exact steps.

Legacy database backends dropped

  • MongoDB import removed. Imports from singularity v1's MongoDB
    store are no longer supported. Migrate via v0.6.0-RC2 first, then upgrade. (#588)
  • MySQL / MariaDB removed. Diagnosing and working around dialect quirks and deadlocks has been taking a significant developer toll with no known users. Please export your data to Postgres before upgrading.

Wallet model split

  • actors and wallets are now separate tables. Pre-v1.0 conflated both concepts under wallets and stored private keys in DB, blocking introduction of new deal types and creating security risks with database backups. You will be guided in exporting keys to a local keystore (#622,
    #650)
  • No more random wallet picker. Random wallet assignment to preparations served no apparent purpose and has been removed (#629)

Schedule / deal flag changes

  • Schedules carry an explicit deal_type. Legacy schedules
    without one are inferred as market on first read of the new
    column, but new schedules must set --deal-type (one of market,
    pdp, ddo).
  • --replication N is gone from create-batch. Use repeated
    --deal-type instead (or --provider per copy).

Wire-level changes

  • Foreign keys flipped to SET NULL on car_blocks.car_id,
    car_blocks.file_id, cars.preparation_id, cars.attachment_id,
    files.attachment_id, directories.attachment_id,
    jobs.attachment_id. GORM doesn't update existing constraints on
    AutoMigrate, so admin init drops and re-creates them.
  • Deal.ClientID no longer has an FK to actors -- removed so
    PDP/DDO deals can carry an EVM-derived client identifier that doesn't
    correspond to an Actor row.
  • Deal.WalletID is the authoritative wallet pointer for new
    deals.

API defaults (operator-only)

The API is meant for operator/localhost use, and its defaults now match
that:

  • Default bind is 127.0.0.1:9090 (was 0.0.0.0:9090). Pass
    --bind 0.0.0.0:9090 to restore listening on all interfaces.
  • Wildcard CORS middleware removed. The dashboard and swagger UI are
    served same-origin; a separate-origin console needs its own proxy.
  • Secret-named config values are masked in JSON API responses. Values
    whose key matches IsSecretConfigName render as [redacted]; storage
    persistence and backend setup are unchanged.

Migration Guide

From v0.5.x

  1. Stop all singularity processes and double-check with ps/pgrep. We also recommend pausing all schedules before this (and resuming them after migration completion).
  2. HIGHLY RECOMMENDED: Back up your database. The upgrade process has been battle tested in large-scale production and best efforts have been made to ensure atomicity and idempotency, however major upgrades always carry inherent risks. If you unable to snapshot your DB and are concerned about critical data loss please describe the situation in Slack. An automated rollback path is not provided.
  3. If you are on MySQL/MariaDB: dump your data and restore into
    Postgres or YugabyteDB before upgrading. pgloader has been tested successfully for this.
  4. Run singularity admin init standalone to:
    • rename the legacy wallets table to actors
    • create wallets table and migrate wallet_assignments
    • fix Postgres sequence positions if they drifted (typical after
      data imports)
    • infer piece_type for cars that predate the column
    • drop and re-create FK constraints as SET NULL
    • add new indexes on car_blocks.file_id, files.attachment_id,
      and the jobs/preps FK columns
      This will best-effort resume if interrupted, but try to avoid terminating the process. May take a while depending on data volume and DB backing, be patient.
  5. Perform the private key export: assuming you had existing wallets in database, you should see the following message
  Error: <N> actor(s) have private keys in the database that are not usable by
  current code.
  Run 'singularity wallet export-keys' to migrate them to the filesystem keystore

Please pay attention during this process, it is straightforward but destructively redacts private keys from the database and may require manual key injection into your secret store in advanced setups (managed cluster deployments) and has thus been broken out into an interactive flow.

$ singularity wallet export-keys
  exported: <N>
  skipped:  <M> (wallet already exists)         # on repeated runs (action is idempotent until drop confirmation) 
  errors:   <K>                                 
    - actor f1xxx: invalid key format: ...      # only on malformed keys; stop and seek support if encountered
    - actor f1yyy: keystore write failed: ...
    ...
  Drop private_key column? [y/N]

Keys will be written to ~/.singularity/keystore in lotus hex format (overridable with $SINGULARITY_KEYSTORE or falls back to ./.singularity/keystore if default/supplied path isn't writeable) on the machine running the singularity client. In a single-node cluster, simply verify that expected keys have been written and answer "y[ENTER]".

ADVANCED:
In a cluster or remote management setup, you will want to pass through the keystore to your daemons, by copying them to the worker or injecting via secrets manager. Only deal-pusher loads the keys for security reasons. For example, in a gitlab + nomad setup, you might write something like this (with a corresponding NOMAD_VAR_WALLET_KEY_f1xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx):

  template {
    data        = "${var.WALLET_KEY_f1xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx}"
    destination = "secrets/f1xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
    perms       = "0600"
    change_mode = "restart"
  }

Please consult the documentation for your orchestration system for more details. Further advanced options are available in the help text for wallet export-keys.

At this time you may also adjust your orchestration to run admin init as a prestart task for the pod/group and pass --no-automigrate to the individual daemons. This is a minor optimization as the no-op automigrate is very lightweight.

  1. OPTIONAL: enable pdp-tracker: if you intend to make PDP deals, enable the new pdp-tracker service, which uses shovel to track onchain PDP lifecycle events.
  2. Resume services and continue onboarding!
  3. Lastly, once normal operation is confirmed (deals being successfully made, etc) you may want to review your backup strategy. A secure, offline backup of the keystore is highly recommended. The retention policy of the previous DB snapshots, which contain private keys, should be carefully evaluated as per your risk profile.

Optional: run the standalone scripts manually

Some helper scripts are available, though you should not need to use them directly if the migration process was carried out correctly:

  • scripts/fix-sequences-after-import.sql -- Postgres sequence reset
  • scripts/infer_piece_type.sql -- classify untyped pieces as
    data / dag
  • scripts/cid_decode.sql -- PL/pgSQL helpers to decode bytea CID
    columns to canonical CIDv0/v1 strings inside a SELECT (#687)

Enabling PDP

Before turning this on, read
Infrastructure readiness.
PDP in v1.0 is experimental; termination tracking is pending
FIP-0112. Suitable for pilots, not mainnet revenue workloads.

Required: a Curio v1.27.4+ instance running default NullAuth (the
shipping default), registered in ServiceProviderRegistry with a PDP
product whose serviceURL is reachable over HTTPS, and a payee that
matches the SP's wallet. The recordKeeper allowlist on Curio must
include the calibnet/mainnet FWSS contract; both are on the allowlist
by default.

Singularity-side:

  • HTTPS content-provider reachable as <base>/piece/<pieceCidV2>.
    singularity run content-provider accepts both v1 commP and v2 piece
    CIDs (#688); put it behind a TLS-terminating reverse proxy (caddy,
    nginx, etc.)
  • singularity run deal-pusher --eth-rpc ... --pdp-source-url-base https://<base> ...
  • A schedule with --deal-type pdp and --provider <SP's f4 address>

Enabling DDO

Before turning this on, read
Infrastructure readiness --
DDO in v1.0 is experimental and the Curio mk20 onboarding path is
still partially documented. Set --duration to match your SP's
sector lifetime (--duration 1555200 for Curio defaults) to avoid
stalled ProveCommits with locked precommit deposits.

  • A wallet funded with the configured payment token (USDFC on calibnet
    by default) and a Diamond proxy contract address from your DDO
    deployment
  • singularity run deal-pusher --eth-rpc ... --ddo-contract 0x... ...
  • A schedule with --deal-type ddo and --duration 1555200 (or
    whatever matches your SP's sector lifetime)

See DDO Contract Deal Guide for the full setup.

Infrastructure readiness (PDP and DDO)

PDP and DDO ship in v1.0 as experimental. The onboarding-to-active
path works end-to-end and is verified against calibnet; lifecycle
observability (termination, faults) is not yet provided by the
underlying network primitives, so it's not surfaced in singularity
either. Production mainnet workloads sized for revenue should continue
on legacy f05 until upstream FIPs activate.

What works

  • PDP: --deal-type pdp schedules drive Curio's /pdp/piece/pull
    and trigger the SP-side on-chain commit; pdp-tracker materializes
    PDPVerifier events locally and flips proposed -> active once the
    SP ProveCommit's the first piece. Verified against Curio v1.27.4.
  • DDO: --deal-type ddo schedules allocate against the configured
    Diamond contract and create payment rails. With FIP-0109 (activated
    nv27, Sept 2025), the contract receives a dataSetCreated callback
    on sector commit; deal-tracker reads it to flip proposed -> active. Verified against a local lotus-miner SP.

What does not work yet

  • Termination tracking is missing for both PDP and DDO. The
    miner actor does not push a termination notification to the DDO
    contract or PDPVerifier; pull-style ValidateSectorStatus
    (FIP-0112) is accepted but not activated as of the v1.0 release. Deals
    stay state=active after the underlying sector is terminated, and
    FilecoinPay rails keep accruing. To stop the accrual, call
    FilecoinPay.terminateRail(railId) manually. Design parked at
    PLAN_DDO_TERMINATION_TRACKING.md for when FIP-0112 lands.
  • SP-side software is in transition. PDP is on Curio's main
    release train as of v1.27.4 (April 2026); earlier Curio versions
    do not have it. Curio mk20 DDO onboarding is partially in place
    but the documented production setup path is still forming -- local
    testing against the lotus-miner DDO plugin works today.
  • Public PDP subgraphs have known indexing gaps on the FWSS listener
    field.
    Tracking issue: FilOzone/pdp-explorer#103. Use
    singularity's Shovel-indexed pdp-tracker as the source of truth
    for deal status rather than the public dashboards.

Operator gotchas

issue what an operator must do
DDO --duration must match the SP's sector lifetime. Mismatch leaves the SP's precommit deposit locked until the precommit expires. Use --duration 1555200 (~540 days) to match Curio's default sector lifetime, or coordinate a shorter CommittedCapacitySectorLifetime with your SP.
SP worker wallet funding is not preflighted by singularity. Monitor your SP's worker balance independently. lotus-miner sectors list showing PreCommitFailed is the symptom.
Curio PreCommit batching defaults to a 24-hour wait -- a single-sector DDO schedule won't ProveCommit until that window closes. On the SP, set [Sealing] BatchPreCommits = false and AggregateAboveBaseFee = "0", or run lotus-miner sectors batching precommit --publish-now manually.
Sector termination is not observable via StateSectorGetInfo because compaction is voluntary and most SPs never run it. For termination/liveness checks, use partition bitfields (AllSectors AND NOT LiveSectors) rather than the SectorOnChainInfo lookup.

Recommendation by use case

use case recommendation
Mainnet production deals, sized for revenue Legacy f05 market deals. Mature observability, well-understood failure modes, reliable termination tracking.
Pilot / staging workloads on PDP or DDO Supported in v1.0 with manual operational discipline. Good for ecosystem validation and building operational familiarity.
Mainnet production PDP/DDO at scale Wait. Track FIP-0112 activation and the FilOzone PoRepService PR (#459). When both are in production, singularity will ship the termination tracker per PLAN_DDO_TERMINATION_TRACKING.md.

The matrix above is the operator-facing summary; the full version with
FIP citations and deeper background lives in the maintainers' internal
infrastructure-readiness notes.


PRs Included (v0.5.17..v1.0.0)

PR Title
#689 PDP pull fixups: addPieces nonce/payload/metadata + shovel null blocks
#688 content-provider: accept v2 piece CID in /piece/
#687 psql helpers for CID inspection
#686 pre-release follow-up fixes
#685 chore: dep bump for final release cut
#684 cleanup: pre-release sweep
#683 blockstore: parallel span reads for content retrieval
#682 use self-hosted forest RPC instead of GLIF
#681 goreleaser: CGO + zig cross builds
#678 refactor PDP to use SP-side pull
#676 sol: strip CBOR metadata from mock bytecode
#675 devcontainer: add forge alongside anvil
#674 migrate: check errors in stripWalletAssignmentFKs
#673 dataprep: fix err order and %d/string in ListPiecesHandler
#672 datasetworker: apply MaxInterval default to the right field
#671 dealtracker: return result.Error, not shadowed outer err
#670 api: fix out-of-bounds on lone-error handler returns
#669 vendor fvm-solidity mocks; convert DDO test off MockAllocationFacet
#667 Consolidate FVM precompile test helpers
#666 ddo: clamp term-max via schedule.Duration; reject legacy price flags
#665 index car_blocks.file_id to fix FK cascade scans
#662 skip orphan cars in piece metadata lookup
#661 store keystore-relative names in wallets.key_path
#660 log wallet_assignments migration progress in export-keys
#658 remove mysql support
#657 fix non-deterministic piece CID for inline DAG regeneration
#656 Add DDO payment token low-balance warnings
#655 Add DDO E2E integration tests with Anvil fork helpers
#654 Add --group filter to schedule list
#653 Add DDO integration test skeleton and EVM wallet funding helper
#652 Simplify create-batch: replace --replication with repeatable --deal-type
#650 sane migration path for wallet/actor mapping
#647 complete key migration code
#646 add trustless IPFS gateway, use patched rclone, remove bitswap
#645 fix flaky TestIntegration_FullResync
#644 add DDO as third deal type
#642 remove --pdp-contract-address flag
#641 remove stale workflows
#640 pdp: propose proof set transfer to sp after filling
#639 fix PDP quirks
#637 fix: clear stale schedule error message after successful completion
#629 simplify wallet-preparation to 1:1, remove random chooser
#628 Wire deal-pusher to on-chain PDP adapter
#627 add Deal.WalletID, decouple from Actor FK
#624 Use writable MariaDB tmpdir in devcontainer scripts
#623 Add explicit deal type support for schedules
#622 wire go-synapse signer into keystore (vs go-filsigner)
#620 upgrade github-actions to v3, enable podman storage cache
#619 skip go generate when codegen inputs unchanged
#617 feat/pdp shovel indexer
#612 chore/pdptracker-rpc-wiring
#611 gate container build on green CI or release
#609 feat/f41 deal tracker
#608 bump go-swagger to v0.33.1
#607 fix add-piece to lookup existing pieces by CID
#606 dedupe fields in storage types codegen
#605 remove hardcoded @host in swagger
#602 feat: add prep delete-piece command
#601 hotfix: avoid re-scanning known valid FKs
#600 give in and use nullable FKs/pointers for massive deletes
#599 harmonize download flags, closes #460
#598 fix: correctly rename cars on S3 type remotes
#597 hotfix: use local tmpfile for padding small pieces
#596 fix remaining deadlocks + prep deletion
#595 Pad very small pieces with literal zeroes
#592 update runner image
#591 improve lotus API test survivability
#589 chore/update
#588 remove legacy mongodb
#586 Devcontainer-based CI flow
#526 fix docker-compose.yml singularity_init container env var
#519 chore: bump version to v0.6.0-RC3
#516 Fix: restore version.json to v0.6.0-RC2
#479 Feat/allow small pieces
#467 chore/linter
#460 harmonize download flags (closed via #599)

For posterity: an SP Pool replication policy and an f05-paid scaffolding
were prototyped on this branch in March 2026 and then reverted; the v1.0
deal-type model in #644/#652 is the path that stuck.