Skip to content

netstack v0.3.1

Choose a tag to compare

@tomismeta tomismeta released this 20 Sep 14:34
· 3 commits to main since this release

THE BOOK research and clearer Sleeve accounting

netstack 0.3.1 adds THE BOOK coverage, a small source-pinned read/event interface, the complete Loopback Morpho market identity, and source-pinned official Sleeve memo accounting. It improves bounded public research without adding a Book runner or changing the existing LP, Predict and House runners.

What improves for users and agents

  • Research THE BOOK with clearer evidence. SportsBookDesk and SportsBookZap identities, launch evidence, publisher rules and a minimal ABI support market, participation and accounting questions. Risk-off principal, risk-on wagers, fees and realized yield stay separate. Publisher models are not verified deployed Solidity.
  • Preserve useful snapshots under rate limits. The recipe defaults to paced sequential requests, bounded backoff and a 30-second collection allowance that includes recovery. Core state and valuation precede bounded placement/fee history; selected bet reads are optional. Failed logs remain unknown, not zero, and the final block-header check retains its own reserve.
  • Avoid misleading money and outcome totals. Distinct wallets account for mode overlap. Stored risk-on amounts are treated as fee-net under the publisher model; event/pot amount basis still needs evidence. Conditional same-block USDG marks are not verified dollars or exit proceeds. Pushes, voids, unsettled bets, internal credits and external withdrawals remain distinct.
  • Reconcile the official Sleeve memo. Reports includes the Sleeve's Predict House Vault claim and THE BOOK house pot alongside its other positions and scoped Credit debt deductions. Book exposure is off-wallet wsNET marked through the sNET index and Reports' NET/USDG price input, not direct NET in the Safe. The app counts the house pot once and derives free cover without adding reserved cover or player escrow. The reviewed Reports price input is a pair-oracle TWAP despite its spot label. Registry gates, skipped positions and fallback values can leave a displayed total incomplete. The memo remains outside contractual Core RFV/backing and is not guaranteed liquid net equity.
  • Resolve Loopback precisely. The full wsNET/USDG market ID, singleton route and five parameters are tied to block 67,956,523 and a matching Keccak identity hash. This scoped check does not establish current liquidity, oracle health or operation, and does not upgrade the six stock markets' verification status.
  • Make answers portable and installs identifiable. User-facing citations use public links and observation dates. Collection, recovery and full response timing are separate. Candidate installs are identified by immutable commit and manifest hashes, not the version label alone. The catalog contains 185 distinct contract addresses, seven Morpho market IDs and 166 sources.

Update your installed copy

Download netstack-0.3.1.zip and install the complete manifest-listed package plus release-manifest.json. Back up customizations outside the active skill folder, then replace the old copy cleanly. Do not overlay files, update only SKILL.md, or install tests, audit artifacts, .git or local handoffs.

Verify file hashes and the loaded path/revision. Reload the skill using the host's supported mechanism; start a fresh conversation if it retains the old context. No automatic update is performed. General knowledge needs no Python; the unchanged optional LP/Predict/House runner uses Python 3.10+ on macOS or Linux under normal host permissions.

Scope and verification

netstack remains read-only research tooling, not a transaction tool or host-wide sandbox. No wallet connection, signing, broadcasting, credentials, provider bypass or Book runner is added.

  • 35 regression tests passed, including against the extracted install archive. Six new codec tests exercise signed spreads, integer widths, unknown enums, settlement fields and fee allocations.
  • 11 prior-candidate offline synthetic acceptance replays exercised scale, shared-budget exhaustion, batch rejection/429 recovery decisions, failed getters/logs, duplicate events, identity mismatches, settlement distinctions, citations and timing. These are instruction/decoder checks, not deployed settlement or native-host certification.
  • Two additional adversarial Sleeve reviews closed all reported blockers, following the earlier two Book-readiness reviews. Corrections document registry omissions, zero fallbacks, the Reports TWAP/spot-label discrepancy, index scaling, derived versus independently read free capital, and LP/TURBO scope limits. All review scopes and dispositions are retained.
  • Four post-review source-only Sleeve answer probes passed composition, raw-unit arithmetic, custody/reservation separation, price provenance and missing-data cases. These use synthetic inputs, not a fresh live balance-sheet reconciliation.
  • A paced live read-only smoke at block 67,974,702 completed core state, valuation inputs and bounded placement history in 26.86 seconds / 20 RPC members, including pacing. It stopped before FeeSplit to preserve a successful same-block header recheck and reported the uncollected history as unknown. This is collection time, not end-to-end response time or a performance guarantee.

Settlement fixtures remain synthetic. Full settlement, actual withdrawals, solvency and deployed enforcement are not certified. Earlier user-reported Hermes dogfood applies to its recorded candidate revision, not a fresh native-host run of this final release.

Security review

The same pinned local security tooling used in prior releases was rerun against this exact package, with raw findings retained and no suppressions:

Check Result and limits
Cisco Skill Scanner 2.1.0 Automated gate failed: 1 CRITICAL, 5 MEDIUM, 1 LOW. All six local analyzers completed, including analysis of the four Python files.
Hermes Skills Guard Safe; installation allowed without force. Three MEDIUM findings retained: file count, the manual clone example, and a policy-text signature. Standalone scan only.
OpenClaw validator/packager Passed. All 144 packaged members matched the frozen input. Format/local packaging, not native-host certification.
Gitleaks 8.30.1 Zero unresolved credentials. Twelve package and twenty history findings across 25 commits were classified as exact public addresses or independently recomputed file hashes.

Cisco's critical finding is disclosed, not suppressed. Its signature matches DNS/socket networking in the existing analytics runner, byte-identical to v0.3.0. Source review traced a fixed public-RPC destination, public-address validation, verified TLS, read-only payload restrictions and redirect refusal; no private-data exfiltration chain was identified in that reviewed path. The maintainer explicitly accepted publication with this finding retained. This is not a clean Cisco verdict, an independent human audit or a guarantee against unknown defects.

Other retained Cisco findings concern the HTTPS primitive, compatibility-field interoperability, reference depth and file count. Cisco expects top-level compatibility, while the pinned OpenClaw validator rejects that field; network requirements remain explicitly documented in the accepted nested metadata and user-facing guidance. No security wording or rules were weakened to obtain a green result.

Scans ran locally with network disabled and tested process-level restrictions. No cloud/LLM security analyzer or native-host sandbox certification is claimed. The audit archive contains tool versions/hashes, exact-input receipts, raw findings, review dispositions and coverage limits.

Release assets: netstack-0.3.1.zip is the installable package. netstack-audit-0.3.1.zip contains separate review evidence and synthetic acceptance inputs, not an installable skill. Verify both with SHA256SUMS.