Repository navigation
[Release] FWSS v1.3.1 + SPR v1.2.0 Mainnet Upgrade (includes Calibnet) #561
Description
Activity
- changed the title
[-][Release] FWSS v1.3.1 Mainnet Upgrade (includes Calibnet)[/-][+][Release] FWSS v1.3.1 + SPR v1.2.0 Mainnet Upgrade (includes Calibnet)[/+]on Jul 31, 2026 Phase 1 kickoff evidence — 2026-07-31
Release preparation is based on
main@a242f8600f1806be50e77a903a233ab9b6c16f92on branchphi/prep-fwss-v1.3.1-release; the current scope-correction commit is3a1d52a.Completed locally:
- Bumped FWSS to
1.3.1and ServiceProviderRegistry to1.2.0. - Drafted the combined changelog/release notes with rollout status delegated to the GitHub Release page.
- Updated the three existing hard-coded version assertions required by the new constants.
- Verified the current live SPR proxies remain v1.1.0, counter 2, owned by the expected Safe, with no pending plan.
Validation evidence for the corrected release-prep scope:
forge test --offline --via-ir: 822 passed, 0 failed- Existing
FilecoinWarmStorageServiceUpgradeTest: 7 passed, 0 failed - Existing
ServiceProviderRegistryTest: 25 passed, 0 failed - FWSS and SPR
forge inspect ... storageLayout: completed bash tools/check_storage_layout.sh: passed (23 → 23 entries)forge build --offlineandgit diff --check: passed
Environment note: non-offline Forge execution hits the local macOS SystemConfiguration proxy crash; the equivalent offline checks pass.
Process notes:
- The generated issue was FWSS-only and needed the explicit SPR companion exception.
- Experimental production-shaped tests and the broad SPR tooling rewrite were removed from PR chore: prep FWSS v1.3.1 + SPR v1.2.0 release #562 after scope review. Operational gaps will be surfaced and tracked when their checklist phase is reached.
- The issue was intentionally created before the release branch so this rollout can expose checklist gaps; the process deviation is documented in the issue body.
No deployment, Safe proposal, announcement, tag, release, or other live-network mutation has been performed.
- Bumped FWSS to
Draft release-prep PR: #562
Source:
main@a242f8600f1806be50e77a903a233ab9b6c16f92
Current head:3a1d52a
Scope: combined changelog, FWSS v1.3.1, SPR v1.2.0, and three existing version assertion updates.The effective PR diff is 49 additions and 9 deletions across six files. Local validation is recorded in the PR: 822 tests passed, both storage layouts were inspected, the FWSS layout check passed 23 → 23, the build passed, and
git diff --checkpassed. GitHub CI is running again on the narrowed diff.No release branch, tag, deployment, Safe proposal, or on-chain action has been created.
Phase 1 read-only audit — 2026-07-31
Audited release ref:
release-v1.3.1at4d8f21a. No live transaction, deployment, tag, or release action was performed.Dependency snapshot
Live reads were pinned at Calibnet block
3,939,384and Mainnet block6,240,050. No discrepancy was found between the current FWSS getters, live proxy state, and the expected addresses.- PDPVerifier stays live at
3.4.0: Calibnet proxy0x85e366Cf9DD2c0aE37E963d9556F5f4718d6417C, implementation0xd60b90f6D3C42B26a246E141ec701a20Dde2fA61; Mainnet proxy0xBADd0B92C1c71d02E7d520f64c0876538fa2557F, implementation0xb41A97FEDD2D9497C639A643ec75E56CbCeDe8BA. - FilecoinPay stays unchanged at source
v1.0.0/f0a40fe: Calibnet0x09a0fDc2723fAd1A7b8e3e00eE5DF73841df55a0; Mainnet0x23b1e018F08BB982348b15a86ee926eEBf7F4DAa. Both networks have identical live runtime hashes. - SessionKeyRegistry stays at ref
74fc4e94500859709a97b1c64981cfae52f9bdfe: Calibnet0x518411c2062E119Aaf7A8B12A2eDf9a939347655; Mainnet0x74FD50525A958aF5d484601E252271f9625231aB. Executable bytecode is identical after stripping compiler metadata. - SPR proxies are preserved and currently run
1.1.0, counter2: Calibnet implementation0x0A2E79efFC7DB1D15912E4F6722F527F493F18Ef; Mainnet implementation0x01293CaFdE24DE89fF26d1A19Bfc4E36CBF74F9B. Target implementations for1.2.0remain Phase 2 outputs. - Current FWSS implementations are Calibnet
0x9e4e6699d8F67dFc883d6b0A7344Bd56F7E80B46(1.3.0, counter8) and Mainnet0xaF996097790c17D3C23Cc45A3035a29D293d1492(1.3.0, counter4). Pending plans are cleared. - Current StateView, USDFC, FilBeam beneficiary, and Safe owner values also match the release inventory.
The release branch contains a newer PDP source submodule ref, but this rollout does not deploy or upgrade PDP. Technical-owner confirmation is still required for every unchanged target and for the SPR target.
Cross-repository impact
FilOzone/synapse-sdk: generated ABI/types must be updated from this release. Run the manual Update Synapse SDK workflow after the deploy ref is frozen/tagged; merge the PR and require a successful integration build before Mainnet unless explicitly waived.FilOzone/pdp: no on-chain PDP rollout or new PDP release is proposed; confirm compatibility with live3.4.0.filecoin-project/curio: #1353 is a post-upgrade/version-gated cleanup. A technical-owner decision is still required for open compatibility item #1356: either waive it as a Mainnet blocker or require a Curio PR/release.FilOzone/filecoin-cloud: no pre-switch change identified; its address-sync PR is expected after live deployments are recorded.filecoin-project/filecoin-pin: no code change identified, but the successful post-Calibnetaddgate remains required. Open #615 is an operational risk for that validation.
Rollback
Rollback is conditional, not yet approved. For FWSS and SPR, announce the previous implementation and then use
upgradeToAndCall(previousImplementation, 0x)with value0. Do not call oldmigrate: forward migration raises FWSS counters to9/5and SPR counters to3, so prior reinitializers cannot be replayed. The current execute helpers always include migration calldata and therefore are not rollback helpers.Before approval, rehearse forward upgrade, representative state transitions, empty-calldata rollback, invariant checks, and the selected roll-forward path on pinned Calibnet and Mainnet forks. The semantic regression risk after post-upgrade state transitions needs explicit owner acceptance.
Validation status
- Pricing suite:
forge test --offline --match-contract PriceListTest— 127 passed, 0 failed on the release branch. - foc-devnet: current scenarios validate fresh deployment, not partial post-upgrade state. foc-devnet #121 still tracks the missing partial-upgrade leg. This gate needs either a bespoke pinned two-stage upgrade scenario or a written technical-owner exception. A normal frontier run is useful supplementary evidence but does not satisfy the post-upgrade-state gate.
Decisions still required before Phase 1 can close
- Name the technical owner.
- Decide the Curio #1356 Mainnet requirement.
- Approve the unchanged dependency targets and preserved SPR proxies.
- Approve a fork-tested rollback/runbook.
- Supply foc-devnet post-upgrade evidence or approve the documented exception.
- Then freeze/tag the deploy commit, create the pre-release, and run the Synapse ABI workflow/build.
- PDPVerifier stays live at
Hi @rjan90 : thanks for driving this forward. A few things looking at this fresh (but I didn't go super deep on it):
- Generally there is a lot of text here so it makes it a bigger pill to swallow to follow the release details and plan. A couple of ways to maybe cut:
- If there is no StateView change, maybe remove the "Optional StateView Switch" section?
- "Operating Rules" and "Upgrade Guidance" are good things which I am sure are instructive/useful for an agent, but I am wondering if they belong in the release itself vs. on the side so the release issue isn't as cluttered.
- How are we going to do the devnet testing before upgrading? Can we get someone on CI: add partial-upgrade test leg to catch cross-component version skew foc-devnet#121 so we can have higher confidence here?
- How are we handling the synapse side of being in limbo during a release and having a version that can be tested (Support stable install URL for pre-release/RC builds synapse-sdk#845 )?
Phase 1 supplementary foc-devnet evidence — 2026-08-03
Exact release-candidate run: FilOzone/foc-devnet Actions #30802517410 — passed in 17m22s.
The focused workflow support is in draft foc-devnet #167, stacked on mixed-profile PR #154. The dispatch skipped the normal six-profile matrix and ran only
stability-frontier-filecoin-serviceswith the candidate override.Verified dependency selection:
Dependency Resolved ref/version Commit filecoin-services exact release candidate 4d8f21a96eceddf29619a606f57665ab1a0b9369PDP stable gitlink from filecoin-services v1.3.0b8ae60d12490d9821c86781f37470037fcc4dc10Lotus v1.36.2c6f4d02400dba55ebc5ab3677ef2ae5a5f4d1aefCurio v1.28.231073fa3b8be05df55e2a2ba42878bdf0b3747adSynapse SDK synapse-sdk-v1.1.1a1d44296ad27b4a2631cb744de95a6a94c8097a7filecoin-pin 1.2.0npm release The resolver and actual cloned checkouts both verified successfully. Scenario result: 6 passed, 0 failed — containers, balances,
createDataSet, storage upload/replication/retrieval, multi-copy upload, and caching subsystem.Artifact:
scenario-report-filecoin-services-release-candidate, ID8851873163, digestsha256:ec0e3f7ef93c963e22f46bb4671d8de864f17bb6b83b516864e0aafdd41a1a70.This is strong exact-source fresh-deployment compatibility evidence, but it does not simulate upgrading proxies with existing state. The Phase 1 post-upgrade-state checkbox therefore remains open pending a pinned two-stage run for foc-devnet #121 or a written exception from technical owner @Kubuxu.
No filecoin-services tag, GitHub Release, deployment, Safe proposal, or live-network transaction was created.
Rollback decision — 2026-08-05
Based on discussion with @Kubuxu and @BigLep, rollback is considered safe and supported for the FWSS v1.3.1 and SPR v1.2.0 rollout.
The release issue now records this procedure:
- Announce the previous implementation and wait for the observed epoch.
- Execute
upgradeToAndCall(previousImplementation, 0x)with value0. - Never replay the old
migratecall. - Use the proposed reverse rollback order: FWSS, then SPR.
- A subsequent roll-forward must also use empty calldata because the new reinitializer has already been consumed.
The exact operator runbook and targeted Calibnet/Mainnet fork-rehearsal evidence remain pending before any live announcement.
@Kubuxu @BigLep, please confirm this accurately captures the decision, especially whether rollback is supported after post-upgrade state-changing traffic or only before normal traffic resumes.
Phase 1 deployment-scope planning correction — 2026-08-05
The initial metadata-aware deployment plans now run in Phase 1, before Cross-Repo/Dependency approval and before the deploy SHA is frozen:
- Run
contract=Warm Storage stack,dry_run=truefor both Calibnet and Mainnet from candidate42238fe. - Record and approve the complete
Would deploy/Up to date/Pinned/preservedinventory. - Stop and fix reviewed source/deployment metadata, then rerun both plans, if either inventory differs from the intended scope.
Phase 2 retains a second dry-run from the immutable
v1.3.1tag immediately before each live deployment. That run is a drift check against the Phase 1 approved inventory, not scope discovery.The planner is authoritative for what will deploy. A
Pinned/preservedresult does not by itself report whether that pinned artifact changed in source; existing diff, ABI, storage-layout, and compatibility checks remain applicable. More detailed pinned-artifact reporting can be considered in the follow-up process PR without blocking this rollout.No deployment, tag, release, Safe proposal, or on-chain transaction was performed by this issue update.
- Run
Phase 1 deployment inventory dry-runs — 2026-08-05
Both metadata-aware plans completed successfully from
release-v1.3.1@42238fe174f8baa0d201bb2bfc3a15b247dc6df3withcontract=Warm Storage stackanddry_run=true. No deployer keystore was created and no transaction was broadcast.Network Workflow Current counters Next implementation counters Result Calibnet run 30981340603 PDP 3, SPR2, FWSS8PDP 4, SPR3, FWSS9Passed Mainnet run 30981345657 PDP 3, SPR2, FWSS4PDP 4, SPR3, FWSS5Passed Approved-scope comparison
Both networks produced the same deployment decisions:
Would deploy because initcode changed
- ServiceProviderRegistry implementation
Rails- FilecoinWarmStorageService implementation
Preserved / reused
- SessionKeyRegistry: existing address
- FilecoinPay: pinned/preserved
- PDPVerifier implementation: pinned/preserved
- PDPVerifier proxy: existing address
- ServiceProviderRegistry proxy: existing address
- SignatureVerificationLib: up to date
- FilecoinWarmStorageService proxy: existing address
- FilecoinWarmStorageServiceStateView: pinned/preserved; no View switch planned
- ProviderIdSet: existing address
- USDFC and FilBeam configuration: unchanged
This exactly matches the expected v1.3.1 + SPR v1.2.0 scope. The implementation and library addresses printed by the dry-run are dummy planner addresses, not live deployment candidates.
The run-completion and no-unexpected-deployment boxes can be checked. Formal inventory approval remains pending from technical owner @Kubuxu.
Cross-repo disposition — 2026-08-05
The Cross-Repo Impact section is now complete for progression into later checklist work:
- Synapse SDK: #845 is explicitly not required for this rollout. The generated ABI/type PR and successful integration build remain required before Mainnet. Review the generated PDPVerifier ABI against live v3.4.0 and explicitly accept or pin/filter the ahead-of-live administrative entrypoint before merging.
- Curio: clarification for #1356 is pending in Slack. This does not block Phase 1, Phase 2, or Calibnet; record the answer or an explicit waiver before Mainnet announcement. #1353 remains post-upgrade cleanup.
- PDP: compatibility with the preserved live PDPVerifier v3.4.0 deployment is confirmed; no PDP PR, release, deployment, or proxy change is required.
- filecoin-cloud: no pre-switch change; automated address sync remains post-rollout.
- filecoin-pin: no code/release prerequisite; successful post-Calibnet default-path validation remains a Mainnet gate, with feat: add ERC-8167 dispatcher with delayed selector routing upgrades #615 tracked as an operational risk.
- Other: no additional consumer change is required to enter later phases.
The Phase 1
Fill Cross-Repo Impactcheckbox is checked. This disposition does not waive the named Synapse build, Curio Mainnet decision, filecoin-pin validation, or post-rollout cloud-sync gates.Refreshed Phase 1 deployment inventory after #567 — 2026-08-05
PR #567 merged as
7f7037f, andrelease-v1.3.1was fast-forwarded to that commit.Both metadata-aware plans completed successfully from
release-v1.3.1@7f7037f5621d57528f30899581aaea8427b0e43cwithcontract=Warm Storage stackanddry_run=true. No deployer keystore was created and no transaction was broadcast.Network Workflow Current counters Next implementation counters Result Calibnet run 30992125865 PDP 3, SPR2, FWSS8PDP 4, SPR3, FWSS9Passed Mainnet run 30992132491 PDP 3, SPR2, FWSS4PDP 4, SPR3, FWSS5Passed Automatic deployment plan
Both networks still plan to deploy only:
- ServiceProviderRegistry implementation
Rails- FilecoinWarmStorageService implementation
No unexpected component was added to the automatic deployment plan.
Newly visible pinned candidate drift
PR #567 now reports source/artifact drift even when deployment metadata preserves a component:
Component Calibnet preserved address Mainnet preserved address Disposition FilecoinPay 0x09a0fDc2723fAd1A7b8e3e00eE5DF73841df55a00x23b1e018F08BB982348b15a86ee926eEBf7F4DAaExplicit preserve/deploy review required PDPVerifier implementation 0xd60b90f6D3C42B26a246E141ec701a20Dde2fA610xb41A97FEDD2D9497C639A643ec75E56CbCeDe8BAExplicit preserve/deploy review required; PDP remains outside the proposed rollout FilecoinWarmStorageServiceStateView 0xF4B446171b3677fD2B9b183a9fB76d517365700a0xAD28BBF18A72f728Ed816D07F5a1d7Ec40D68b5eExplicit deploy-or-preserve decision required StateView remains pinned, so the workflow does not deploy it automatically. However, the candidate StateView includes the challenge-window calculation for reactivating a previously activated dataset, while the deployed v1.3.0 behavior reverts with
ProvingPeriodNotInitializedwhen there is no proving deadline.The previous inventory approval predated these pinned-drift signals. The no-unexpected-deployment check remains satisfied, but complete-inventory approval is reopened pending the technical owner's explicit dispositions. If StateView is included, add the scope exception plus the deployment, verification, and
setViewContractplan before Phase 2.Pinned-drift disposition and StateView scope expansion — 2026-08-05
The release-operator disposition is:
- Preserve FilecoinPay at the existing Calibnet and Mainnet addresses; keep it pinned.
- Preserve PDPVerifier at the existing v3.4.0 proxies/implementations; keep it pinned.
- Deploy and switch FilecoinWarmStorageServiceStateView on both networks so the View exposes the reactivation-window behavior expected by FWSS v1.3.1.
Draft scope PR #568 removes only the two
FWSS_VIEWpolicy pins. It does not change any live address, proxy, FilecoinPay policy, or PDPVerifier policy.Branch-scoped metadata-aware dry-runs passed from
fad5dde:Network Workflow Result Calibnet run 30993578391 Passed Mainnet run 30993590820 Passed Both plans now:
- deploy the ServiceProviderRegistry implementation;
- deploy
Rails; - deploy the FilecoinWarmStorageService implementation;
- deploy a new StateView;
- preserve FilecoinPay and PDPVerifier as pinned despite reported candidate drift; and
- emit
New StateView requires a separate Safe setViewContract transactionfor the existing FWSS proxy.
No deployer keystore was created and no transaction was broadcast.
After #568 is approved and merged, refresh
release-v1.3.1frommain, rerun both plans from that release ref, and record the new candidate SHA before technical-owner freeze/tag approval. The complete-inventory checkbox remains open until that final inventory and the preserve/expanded-scope dispositions are confirmed by technical owner @Kubuxu.Final expanded Phase 1 deployment inventory — 2026-08-05
PR #568 merged as
aea9357, andrelease-v1.3.1was fast-forwarded to that commit.Both metadata-aware plans completed successfully from
release-v1.3.1@aea9357d82c1df41d43fd58ba58c1fdeacc5f3f9withcontract=Warm Storage stackanddry_run=true. No deployer keystore was created and no transaction was broadcast.Network Workflow Current counters Next implementation counters Result Calibnet run 30996922868 PDP 3, SPR2, FWSS8PDP 4, SPR3, FWSS9Passed Mainnet run 30996922569 PDP 3, SPR2, FWSS4PDP 4, SPR3, FWSS5Passed Both release-ref plans produce the intended final inventory:
Deploy
- ServiceProviderRegistry implementation
Rails- FilecoinWarmStorageService implementation
- FilecoinWarmStorageServiceStateView
Preserve
- FilecoinPay remains pinned at the existing network address despite reported candidate drift.
- PDPVerifier implementation remains pinned at the existing network address despite reported candidate drift; both PDP proxies and live v3.4.0 remain unchanged.
- Every proxy and all other dependency/configuration addresses remain unchanged.
Both plans emit
New StateView requires a separate Safe setViewContract transactionfor the existing FWSS proxy. The dummy dry-run StateView address is not a deployment candidate; the real address is a Phase 2 output.Candidate
aea9357is now recorded for technical-owner inventory/freeze approval. Do not tag or start a live deployment until the remaining Phase 1 gates are resolved or explicitly waived.Phase 1 operator acceptance and deferred technical-owner gate — 2026-08-05
To unblock Phase 2 contract deployment, the release operator accepts the following Phase 1 dispositions:
- Final inventory: candidate
aea9357is accepted. Deploy ServiceProviderRegistry implementation,Rails, FilecoinWarmStorageService implementation, and StateView; preserve FilecoinPay, PDPVerifier, every proxy, and all other dependency/configuration addresses. - Dependency compatibility: the targets and observed Calibnet/Mainnet state in this issue are accepted for entering Phase 2.
- Rollback: the documented empty-calldata rollback procedure is accepted as safe for this rollout. A separate targeted fork rehearsal is waived as a prerequisite to candidate deployment.
- foc-devnet: the existing 6/6 exact-source fresh-deployment run is accepted as sufficient supplementary evidence for entering Phase 2. The missing two-stage existing-proxy upgrade scenario is explicitly waived as a pre-deployment gate.
This exception is deliberately limited to tagging, publishing the pre-release, ABI integration work, and deploying candidate contracts. Those actions do not change either live proxy implementation or the FWSS StateView pointer.
Technical-owner review by @Kubuxu is deferred to the Safe review/go-no-go stage and remains mandatory before any live
announcePlannedUpgrade, implementation switch, orsetViewContracttransaction is signed or executed. Any objection at that gate stops the rollout before live proxy state changes.No live deployment or Safe transaction was performed by this issue update.
- Final inventory: candidate
23 remaining items
Mainnet SPR + FWSS announcement — executed and verified
Execution: transaction
0xeebb…e4c2, successful at Mainnet epoch6,270,876(2026-08-11T07:18:00Z).Batch verification
The Safe called the expected two targets in deterministic SPR → FWSS order, both with value
0:- ServiceProviderRegistry proxy
0xf55dDbf63F1b55c3F1D4FA7e339a68AB7b64A5eB - FilecoinWarmStorageService proxy
0x8408502033C418E1bbC97cE9ac48E5528F371A9f
Both emitted the planned-upgrade event with the intended candidate and shared epoch.
Live pending plans
- SPR
nextUpgrade()= (0x1Bb676392272313598930FEf8D5B66FFECcE02F0,6274616) - FWSS
nextUpgrade()through current StateView = (0x3583e9fc40243924C6f8eBE3d17e5364Bb6A01a9,6274616)
The observed
afterEpochexactly matches the reviewed Safe payload. The announcement executed with3,740epochs (approximately 31 hours 10 minutes) remaining, preserving more than the required 2,880-epoch notice.Active state remains unchanged
- SPR implementation remains
0x01293CaFdE24DE89fF26d1A19Bfc4E36CBF74F9B(1.1.0). - FWSS implementation remains
0xaF996097790c17D3C23Cc45A3035a29D293d1492(1.3.0). - FWSS StateView remains
0xAD28BBF18A72f728Ed816D07F5a1d7Ec40D68b5e.
This is the expected announcement-only state.
Decision and next gates
The announcement is verified; proceed to the waiting period. Do not execute either implementation upgrade before epoch
6,274,616(approximately2026-08-12T14:28:00Z).Before implementation execution, close or explicitly waive the still-open Phase 4 gates:
- record Kubuxu's Mainnet implementation go/no-go;
- review/merge synapse-sdk#911, or record an explicit waiver;
- publish the Mainnet status-page notice; and
- notify stakeholders, including FilB.
The implementation execution batch may be generated and staged for review while waiting, in SPR → FWSS order. The StateView switch remains a separate later Safe transaction and must execute only after the implementation batch succeeds and immediate FWSS checks pass.
- ServiceProviderRegistry proxy
Mainnet status-page maintenance published
Published Mainnet FWSS v1.3.1 contract upgrade execution on the
Contract upgrades / maintenancecomponent.- Network/date: Filecoin Mainnet, August 12, 2026
- Maintenance start:
2026-08-12T14:15:00Z - Announced execution epoch:
6,274,616(approximately14:28 UTC) - Automatic end:
2026-08-12T23:59:00Z - Subscriber notifications: enabled
- Details link: v1.3.1 pre-release
The notice is visible as scheduled maintenance now, while the component remains operational until tomorrow's start. The end time covers the implementation execution, separate StateView switch, and post-upgrade validation window, preventing the notice from auto-resolving before tomorrow's work. If validation extends past
23:59 UTC, extend the maintenance before that deadline rather than allowing automatic resolution.Stakeholder/FilB notification gate completed: the release operator confirmed on 2026-08-11 that the Mainnet upgrade notice was posted in Slack, with links to the on-chain announcement, public status page, v1.3.1 pre-release, and changelog. The Phase 4 checkbox and Go/No-Go summary have been updated accordingly.
Mainnet implementation execution — Safe staging / fork rehearsal
Prepared from the exact rollout ref
v1.3.1-rollout.1/c1ae9e5. This is a reviewable Safe batch only; do not execute it until the live chain is at or beyondafterEpoch=6274616and the technical owner records Mainnet GO.At generation epoch
6273667, the live pending plans still matched the announced candidates and shared threshold:- SPR:
0x1Bb676392272313598930FEf8D5B66FFECcE02F0,afterEpoch=6274616 - FWSS:
0x3583e9fc40243924C6f8eBE3d17e5364Bb6A01a9,afterEpoch=6274616
Safe batch
Safe:
0x6386622B4915B027900d65560b0ab84F8a1ff2AAon Filecoin Mainnet. Both calls use value0and normalCALLoperation.-
ServiceProviderRegistry implementation
- Target:
0xf55dDbf63F1b55c3F1D4FA7e339a68AB7b64A5eB - Function:
upgradeToAndCall(address,bytes) - New implementation:
0x1Bb676392272313598930FEf8D5B66FFECcE02F0 - Inner call:
migrate("1.2.0") - Calldata:
0x4f1ef2860000000000000000000000001bb676392272313598930fef8d5b66ffecce02f000000000000000000000000000000000000000000000000000000000000000400000000000000000000000000000000000000000000000000000000000000064c9c5b5b400000000000000000000000000000000000000000000000000000000000000200000000000000000000000000000000000000000000000000000000000000005312e322e3000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
- Target:
-
FilecoinWarmStorageService implementation
- Target:
0x8408502033C418E1bbC97cE9ac48E5528F371A9f - Function:
upgradeToAndCall(address,bytes) - New implementation:
0x3583e9fc40243924C6f8eBE3d17e5364Bb6A01a9 - Inner call:
migrate(address(0)), deliberately preserving the currently selected StateView - Calldata:
0x4f1ef2860000000000000000000000003583e9fc40243924c6f8ebe3d17e5364bb6a01a900000000000000000000000000000000000000000000000000000000000000400000000000000000000000000000000000000000000000000000000000000024ce5494bb000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
- Target:
Do not add
setViewContractto this batch. The Mainnet StateView candidate remains a separate transaction after the implementation batch succeeds and immediate FWSS reads pass.Validation
The exact payloads above were executed in SPR → FWSS order on a disposable Mainnet fork advanced to epoch
6274616:- Both transactions succeeded.
- SPR implementation slot became
0x1Bb676392272313598930FEf8D5B66FFECcE02F0;VERSION()=1.2.0; initializer event reported counter3;nextUpgrade()cleared. - FWSS implementation slot became
0x3583e9fc40243924C6f8eBE3d17e5364Bb6A01a9;VERSION()=1.3.1; initializer event reported counter5;nextUpgrade()cleared. - FWSS
viewContractAddress()remained0xAD28BBF18A72f728Ed816D07F5a1d7Ec40D68b5e, as intended for the immediate post-implementation validation gate.
Cross-repo disposition: Synapse SDK #911 has passed checks and downstream review; Rod confirmed it can merge after the contract upgrade. Its merge remains a tracked post-upgrade follow-up. Technical-owner acceptance is still required before executing this implementation batch.
- SPR:
Mainnet SPR + FWSS implementation execution — verified
Execution: Safe nonce 16 / tx
0x8a3b…1b66, successful at epoch6274884(2026-08-12T16:42:00Z). This was 268 epochs after the observedafterEpoch=6274616. The Safe advanced to nonce17.ServiceProviderRegistry
- Implementation slot:
0x1Bb676392272313598930FEf8D5B66FFECcE02F0 VERSION() = 1.2.0; initializer counter3- Owner preserved:
0x6386622B4915B027900d65560b0ab84F8a1ff2AA nextUpgrade() = (0x0, 0)- Registry state preserved: provider count
35, next provider ID36, and the completegetProvidersByIds([1..35])response (15,200 encoded bytes) was byte-for-byte identical at blocks6274883and6274884.
FilecoinWarmStorageService
- Implementation slot:
0x3583e9fc40243924C6f8eBE3d17e5364Bb6A01a9 VERSION() = 1.3.1; initializer counter5- Owner preserved:
0x6386622B4915B027900d65560b0ab84F8a1ff2AA nextUpgrade() = (0x0, 0)through the current View- Current View deliberately preserved for this validation gate:
0xAD28BBF18A72f728Ed816D07F5a1d7Ec40D68b5e - Immutable dependencies match the approved deployment: PDPVerifier
0xBADd0B92C1c71d02E7d520f64c0876538fa2557F, FilecoinPay0x23b1e018F08BB982348b15a86ee926eEBf7F4DAa, USDFC0x80B98d3aa09ffff255c3ba4A241111Ff1262F045, beneficiary0x1D60d2F5960Af6341e842C539985FA297E10d6eA, SPR proxy0xf55dDbf63F1b55c3F1D4FA7e339a68AB7b64A5eB, and SessionKeyRegistry0x74FD50525A958aF5d484601E252271f9625231aB. - FWSS approved-provider state was byte-for-byte identical across the execution block: count
3, IDs[1, 5, 7]. getPriceList()was byte-for-byte identical across the execution block and decodes to the intended release constants: storage2.5USDFC/TiB/month, dataset fee0.024USDFC/month, CDN/cache-miss egress7USDFC/TiB each, and the expected operation fees and lockups.- Stored PDP configuration remains max proving period
2880, challenge window60, and challenges per proof5; the calculated next start advanced by one epoch with the block as expected.
StateView gate
- Immediate implementation checks pass.
- Safe nonce 17 is the previously reviewed single
setViewContract(0xdDd8F083a3fe9C66547D46bee24e5AaF56BCa0ab)call. - Candidate View
service()points to the existing FWSS proxy.
Decision: immediate post-implementation checks pass; GO to execute Safe nonce 17. After execution, verify the View binding and reads before beginning Mainnet smoke/E2E and
filecoin-pinvalidation.- Implementation slot:
Mainnet StateView switch — executed and verified
Execution: Safe nonce 17 / tx
0xec92…dc2c, successful at epoch6274898(2026-08-12T16:49:00Z). The transaction emitted the expectedViewContractSet(0xdDd8F083a3fe9C66547D46bee24e5AaF56BCa0ab)event, and the Safe advanced to nonce18.Post-switch reads:
viewContractAddress()=0xdDd8F083a3fe9C66547D46bee24e5AaF56BCa0ab- New View
service()= existing FWSS proxy0x8408502033C418E1bbC97cE9ac48E5528F371A9f - FWSS implementation remains
0x3583e9fc40243924C6f8eBE3d17e5364Bb6A01a9 VERSION()remains1.3.1; initializer counter remains5; owner remains the Mainnet SafenextUpgrade()through the new View is cleared(0x0, 0)- Pricing and approved-provider responses are byte-for-byte identical through the old and new Views; approved provider IDs remain
[1, 5, 7] - PDP configuration reads successfully: max proving period
2880, challenge window60, challenges per proof5 - Active data set
1468reads successfully through the new View: live, active status, activation epoch6274659, proving deadline6277539, and next challenge-window start6280359; the old and new Views agree on this active-state result
Reactivation-window validation
A read-only scan of Mainnet data-set IDs
1..1468found 61 current fixtures with proving history (provingActivationEpoch > 0) and no active proving deadline (provingDeadline == 0). Data set1445was selected as a representative live fixture.At block
6274910for data set1445:- PDP data set is live and FWSS status is active
provingActivationEpoch = 6258757provingDeadline = 0- Old deployed View reverts on
nextPDPChallengeWindowStart(1445), reproducing the compatibility gap - New View returns
6278857 - Independent canonical calculation using the v1.3.1 formula also returns
6278857
Decision: the Mainnet implementation and StateView gates pass. Proceed to Mainnet smoke/E2E and the unique default-path
filecoin-pin add --network mainnetvalidation before completing the rollout status and release promotion steps.Mainnet smoke /
filecoin-pindisposition and explorer verificationThe release operator explicitly deferred the live Mainnet
filecoin-pin addsmoke/E2E transaction on 2026-08-12 because the upgraded path will be exercised by Dealbot shortly. This is a non-blocking post-upgrade evidence follow-up, not a claim that the live upload test passed.The non-spending preflight was completed with
filecoin-pin 1.2.0against the upgraded Mainnet deployment using unique metadatasmoke_run=fwss-v1.3.1-mainnet-20260812T170320Z:- File validated and packed successfully; root CID
bafkreihxolyrdlkltoe6zxvqob5sk6nypvrguor3txsuvk3677cgiw5pge - No existing Data Set matched the unique metadata
- Default path selected two copies / two new Data Sets with FilBeam enabled
- Cost estimate completed: storage
0.0480 USDFC/month, one-time fees0.0516 USDFC, lockup2.2480 USDFC, estimated deposit2.9360 USDFC - Dry-run only: no upload, funds movement, session authorization, or transaction occurred
Dealbot evidence should be linked here when available, including resulting Data Set/piece IDs, provider IDs, transactions, and retrieval outcome.
Mainnet Blockscout verification also passes:
- FWSS proxy is a fully verified EIP-1967 proxy resolving to
0x3583e9fc40243924C6f8eBE3d17e5364Bb6A01a9(FilecoinWarmStorageService) - SPR proxy is a fully verified EIP-1967 proxy resolving to
0x1Bb676392272313598930FEf8D5B66FFECcE02F0(ServiceProviderRegistry) - StateView is source-verified as
FilecoinWarmStorageServiceStateView
Disposition: the on-chain Mainnet rollout and its immediate contract/View/explorer checks are complete. Continue release/status close-out; retain Dealbot smoke/E2E evidence as an owned post-upgrade follow-up before closing the release issue.
- File validated and packed successfully; root CID
Phase 5 — Mainnet deployment snapshot
Opened draft PR #576 to publish the live Mainnet v1.3.1 deployment state from successful deployment run 31097910469.
The PR records the live SPR implementation, Rails, FWSS implementation, and StateView addresses plus the exact rollout commit, deployment timestamp, constructor metadata, linked library, and initcode hashes. After building the exact rollout source,
verify-deployments.sh --chain 314 --eth-callreportedOK (deployed)for FWSS, StateView, Rails, SPR, and SignatureVerificationLib.The Mainnet Dealbot/filecoin-pin smoke disposition is unchanged: explicitly deferred, not marked as passed.
Phase 5 — merged deployment snapshot and manual Synapse final-address update
Mainnet deployment snapshot #576 merged as
022171c. The mergedservice_contracts/deployments.jsonis byte-identical to the reviewed PR branch, andverify-deployments.sh --eth-callpassed for both chain314and314159.Synapse #911 had already been merged from the earlier Calibnet address snapshot. A same-tag workflow rerun would reuse
chore/update-filecoin-services-v1.3.1and resolve the closed #911 instead of opening a new PR. Per the release operator decision, the final Phase 5 update was reproduced manually rather than changing the workflow for this rollout.Draft Synapse #916 points
FILECOIN_SERVICES_GIT_REFat022171c, regenerates synapse-core, and changes the generated Mainnet StateView from the previous address to live v1.3.1 View0xdDd8F083a3fe9C66547D46bee24e5AaF56BCa0ab. The generated ABI itself is unchanged. Localgenerate-abi, lint, build, andgit diff --checkpassed; CI/review and merge remain pending.I think this issue can be closed now as I believe all the followup has been done, but I need to double check. @Kubuxu if you have insight, feel free to comment. Otherwise I will look.
I think it is can be closed.
Overview
v1.3.1RoutineMainnet SPR/FWSS implementations and StateView are live and verified. Live Mainnet filecoin-pin smoke is explicitly deferred to upcoming Dealbot evidence and is not claimed as passed. Phase 5 close-out is next; Synapse and filecoin-cloud follow-ups are merged, while Curio remains tracked post-upgradeRelease Tracking
The filecoin-services GitHub release version is the stack version. It may differ from an individual contract
VERSION()when the stack changes without an FWSS code change.v1.3.1/aea9357. Exact deployed rollout ref:v1.3.1-rollout.1/c1ae9e5. Only the deploy-all tooling differs.v1.3.1 — FWSS + ServiceProviderRegistry Upgrade— promoted to latest on 2026-08-1314:15–23:59 UTC, after epoch6274616; resolved after the successful rolloutLatest release; Calibnet and Mainnet rollout verified; Synapse and filecoin-cloud follow-ups merged; live Mainnet filecoin-pin smoke deferred to upcoming Dealbot evidence; process PR and issue close-out pendingdeployments.jsonPR(s)022171c; final two-network live verification passed)44ffc12. Manual exception and validation evidence.filecoin-cloudPRe67e9f3.Field ownership for duplicated rollout data:
service_contracts/deployments.jsononmainComponent Versions
filecoin-services)v1.3.1FilecoinWarmStorageService1.3.11.3.0ServiceProviderRegistry1.2.01.1.0PDPVerifierUpgrade Schedule
AFTER_EPOCHlegacy2880 notice + 2000 signing buffer (4880 total)39613873956643; implementations executed at epoch3967890; StateView switched at epoch3967915; smoke/E2E validatedlegacy2880 notice + 2880 signing buffer (5760 total)62746166270876; implementations executed at epoch6274884; immediate checks passed; StateView switched at epoch6274898and verified.Set the requested delay before proposing the Safe transaction. For the normal delay-based flow, fill in the actual
AFTER_EPOCHfromnextUpgrade()after the announcement executes. The observed value is the source of truth for the execute step and external communications.Run Log
The Run Log is this release issue's operator journal for rollout facts discovered during execution: deployed addresses, transaction links, validation outputs, exceptions, and owner decisions.
Keep this table current as values become known.
afterEpoch0x51Bc9fB1e20280D57460a0a69a7077a9682AA1640x9BF9e67e83EC8613883FDdDec4D3b38AEE937177at epoch3967915(Safe nonce 18)3961387VERSION()=1.3.1, initializer9, dependencies/pricing/state preserved; StateView checks passed: new View selected and bound, active reads healthy, no current live reactivation-state fixture; smoke/E2E + filecoin-pin passed: Data Sets26657/26658live on providers4/2, active pieces and byte-identical retrieval verified0x3583e9fc40243924C6f8eBE3d17e5364Bb6A01a90xdDd8F083a3fe9C66547D46bee24e5AaF56BCa0abat epoch6274898(Safe nonce 17)627087662746166274884Scope
FilecoinWarmStorageServiceimplementation upgrade behind the existing FWSS proxy.FilecoinWarmStorageServiceStateView,ServiceProviderRegistry,PDPVerifier,FilecoinPay, andSessionKeyRegistry.Exception — ServiceProviderRegistry v1.2.0 companion rollout
This release explicitly includes a ServiceProviderRegistry implementation upgrade so future upgrades can use
announceUpgradePlan(address,uint96). Existing SPR proxy addresses and registry state must be preserved; no replacement proxy is allowed.0x839e5c9988e4e9977d40708d0094103c0839Ac9D0x0A2E79efFC7DB1D15912E4F6722F527F493F18EfVERSION()=1.1.0; initializer2;nextUpgrade=(0x0,0); Safe owner matches Network Constants0xf55dDbf63F1b55c3F1D4FA7e339a68AB7b64A5eB0x01293CaFdE24DE89fF26d1A19Bfc4E36CBF74F9BVERSION()=1.1.0; initializer2;nextUpgrade=(0x0,0); Safe owner matches Network ConstantsSPR-specific release gates:
VERSION():1.2.0; deployment constructor reinitializer:3, derived and cross-checked from live counter2 + 1.contract=Warm Storage stack: run the metadata-aware dry-run first, approve the complete inventory, then use the live stack run to obtain and record the actual implementation address. The dry-run records deployment decisions and counters; it does not predict a real CREATE address.aea9357: deploy the ServiceProviderRegistry implementation,Rails, the FilecoinWarmStorageService implementation, and a new StateView; preserve every proxy plus FilecoinPay, PDPVerifier, and unchanged dependency addresses. FilecoinPay and PDPVerifier remain pinned. StateView is intentionally unpinned and requires a separate SafesetViewContractaction after the FWSS implementation switch. Technical-owner final inventory approval remains pending.announcePlannedUpgradecall because v1.1.0 does not expose the relative-delay entrypoint. Include a Safe-signing buffer, then verify the exact pending implementation and epoch on-chain.upgradeToAndCall(..., migrate("1.2.0")). Verify implementation slot, version, owner, initializer3, registry state, and cleared plan.2after the proxy counter reaches3; a subsequent roll-forward must also use empty calldata because reinitializer3has already been consumed.SPR Run Log
afterEpoch0x0dF90c9a20b3f1E383c7196C06943565396c09563961387VERSION()=1.2.0, initializer3, owner/registry state preserved, plan cleared0x1Bb676392272313598930FEf8D5B66FFECcE02F062708766274616VERSION()=1.2.0, initializer3, owner/registry state preserved, plan clearedException — FilecoinWarmStorageServiceStateView companion rollout
This release includes a new immutable StateView on both networks so clients can use the reactivation behavior introduced by FWSS v1.3.1. The upgraded FWSS preserves the original proving activation epoch and enforces the canonical reactivation window. The candidate StateView calculates that same window, while the currently deployed v1.3.0 View reverts with
ProvingPeriodNotInitializedwhen no proving deadline is active.StateView-specific release gates:
FWSS_VIEWfor Calibnet and Mainnet. FilecoinPay and PDPVerifier remain pinned and preserved. Final release-ref evidence: Calibnet run 30996922868 and Mainnet run 30996922569, both passed fromaea9357.contract=Warm Storage stackrun; do not use a separate deployment path.setViewContract(newView)only after the FWSS v1.3.1 implementation is live and its immediate post-upgrade reads pass. VerifyviewContractAddress()and reactivation-window reads afterward.setViewContractSafe action.Cross-Repo Impact
Each pre-seeded row now has an explicit disposition, tracker, and later gate. Completing this section allows the rollout to proceed; it does not complete the Synapse build or post-rollout follow-ups. The post-Calibnet filecoin-pin validation is complete. Audit evidence: Phase 1 read-only audit and cross-repo disposition.
FilOzone/synapse-sdkFilOzone/pdpNone: no PDP deployment or new release. Compatibility with live PDPVerifier3.4.0is confirmed for this rollout.filecoin-project/curioFilOzone/filecoin-cloudNonebefore proxy switches; merge the automated address-sync PR after live deployment state is recordede67e9f3filecoin-project/filecoin-pinfilecoin-pin addpassed with two new Data Sets and byte-identical retrieval.None: no other event-shape, ABI, linked-library, or proxy-address consumer change is required to enter later phasesDependency Targets and Compatibility
Record the intended deployed dependency versions or addresses, then verify actual deployed state against those targets before go/no-go. Reads below were pinned at Calibnet block
3,939,384and Mainnet block6,240,050; details are in the Phase 1 audit.PDPVerifierVERSION()=3.4.00x85e366Cf9DD2c0aE37E963d9556F5f4718d6417C; impl0xd60b90f6D3C42B26a246E141ec701a20Dde2fA61;3.4.00xBADd0B92C1c71d02E7d520f64c0876538fa2557F; impl0xb41A97FEDD2D9497C639A643ec75E56CbCeDe8BA;3.4.0FilecoinPayv1.0.0atf0a40fe0x09a0fDc2723fAd1A7b8e3e00eE5DF73841df55a00x23b1e018F08BB982348b15a86ee926eEBf7F4DAaServiceProviderRegistry1.2.00x839e5c9988e4e9977d40708d0094103c0839Ac9D; current impl0x0A2E79efFC7DB1D15912E4F6722F527F493F18Ef;1.1.0, counter20xf55dDbf63F1b55c3F1D4FA7e339a68AB7b64A5eB; current impl0x01293CaFdE24DE89fF26d1A19Bfc4E36CBF74F9B;1.1.0, counter2SessionKeyRegistry74fc4e94500859709a97b1c64981cfae52f9bdfe0x518411c2062E119Aaf7A8B12A2eDf9a9393476550x74FD50525A958aF5d484601E252271f9625231aBFilecoinWarmStorageServiceStateViewsetViewContract0xF4B446171b3677fD2B9b183a9fB76d517365700a; new address is a Phase 2 output0xAD28BBF18A72f728Ed816D07F5a1d7Ec40D68b5e; new address is a Phase 2 outputUSDFC0xb3042734b608a1B16e9e86B374A3f3e389B4cDf00x80B98d3aa09ffff255c3ba4A241111Ff1262F0450x1D60d2F5960Af6341e842C539985FA297E10d6eARollback Plan
State whether rollback is safe before any live announce transaction. Link the approved rollback procedure or script when available.
Accepted for Phase 2 — rollback uses an announced empty-calldata UUPS rollback. The release operator waived a separate targeted fork rehearsal as a candidate-deployment prerequisite; technical-owner review remains mandatory before announce/switch transactions0x9e4e6699d8F67dFc883d6b0A7344Bd56F7E80B46(1.3.0, counter8); Mainnet0xaF996097790c17D3C23Cc45A3035a29D293d1492(1.3.0, counter4)0x0A2E79efFC7DB1D15912E4F6722F527F493F18Ef(1.1.0, counter2); Mainnet0x01293CaFdE24DE89fF26d1A19Bfc4E36CBF74F9B(1.1.0, counter2)setViewContract(previousView)and verify it. Announce the previous implementation, wait for the observed epoch, then callupgradeToAndCall(previousImplementation, 0x)with value0. Reverse rollback order: StateView, FWSS, then SPR. Never call an old migration. Current execute helpers are not rollback helpers. See audit mechanics9, FWSS Mainnet5, and SPR3. A subsequent roll-forward uses empty calldata because the new reinitializers have already been consumed.Pre-Live Validation
Record validation that proves the planned upgrade works against the full contract, Curio, and Synapse state before live rollout.
4d8f21a. It does not simulate upgrading proxies with existing state. The release operator explicitly accepts this evidence and waives the missing two-stage scenario as a Phase 2 candidate-deployment prerequisite; technical-owner review is deferred to the pre-announce gate. Exceptionforge test --offline --match-contract PriceListTest— 127 passed, 0 failed. Recorded evidence69b8ef7, passed lint/build, and opened #911. Review/merge remains required or explicitly waived before Mainnet announcement.Network Constants
314159https://api.calibration.node.glif.io/rpc/v10x02925630df557F957f70E112bA06e50965417CA00x6386622B4915B027900d65560b0ab84F8a1ff2AA314https://api.node.glif.io/rpc/v10x8408502033C418E1bbC97cE9ac48E5528F371A9f0x6386622B4915B027900d65560b0ab84F8a1ff2AAOperating Rules
vX.Y.Ztag is immutable and points to the frozen deploy commit used for contract deployment and bytecode verification. Post-deploy rollout facts such as live addresses, epochs, tx links, anddeployments.jsonfollow-up PRs are not folded back into the tag. They live onmain, the release issue Run Log, and the GitHub Release page. Do not create a second "final release" tag.vX.Y.Ztag for the source that produced the deployed bytecode. Use on-chain reads from the FWSS proxy for live state, including the implementation slot and address getters such asviewContractAddress(),pdpVerifierAddress(),paymentsContractAddress(),serviceProviderRegistry(),sessionKeyRegistry(),usdfcTokenAddress(), andfilBeamBeneficiaryAddress(). Use the GitHub Release rollout table for the historical record of what was live for this release.service_contracts/deployments.jsonon a release branch orvX.Y.Ztag is the copy that existed at branch-cut/tag time and may be stale after Calibnet/Mainnet proxy or View switches. Do not use it as live state. Updatedeployments.jsononmainthrough the follow-up PR flow, but treat chain state and linked execute transactions as the live verification source.CALLDATA_ONLY=trueand submit it through Safe Transaction Builder.0, and data is the printed calldata.filecoin-pinData Set creation validation are complete.service_contracts/deployments.jsonreflects what is live behind proxies and View contracts. Update it only after the relevant proxy switch and, if applicable, View switch are complete, normally through follow-up PR(s) tomain, and record PR links in Release Tracking.nextUpgrade()and record its exactafterEpochas the source of truth.Notice Guidance
2880epochs (~24h)20160epochs (~1 week)Calibnet can use a shorter window for rehearsal and validation, but use enough time for signers to coordinate. Select a positive operational delay; the contract's one-epoch floor is an emergency safety bound, not the routine notice policy.
Temporary Bootstrap Compatibility
FWSS v1.3.0 is currently deployed on Calibnet and Mainnet and does not expose
announceUpgradePlan(address,uint96). The v1.3.0 -> v1.3.1 rollout must announce throughannouncePlannedUpgrade((address,uint96)). UseANNOUNCEMENT_MODE=legacywith an absoluteAFTER_EPOCHfor both networks and include a conservative Safe-signing buffer so the proposal is still in the future when it executes.This is a v1.3.1 bootstrap exception, not a second long-term workflow. Treat legacy mode as deprecated once v1.3.1 is live on both networks, then use the Phase 5 cleanup item to remove it when rollback to v1.3.0 is retired.
Post-Upgrade Evidence Required
For each network, record evidence that:
VERSION()returns the expected FWSS contract version without the leadingv.nextUpgrade()is cleared.filecoin-pinaddflow succeeds after the upgrade with unique Data Set metadata, forcing creation of a new Data Set on the target network. Record the command output, metadata, Data Set ID, tx/link, SP, and timestamp in the Run Log.Changes
1.3.0to1.3.1with the fixes and metadata additions tracked by FWSS M4.5 GA Fast Follow Contract Upgrade #549.1.1.0to1.2.0as the documented companion exception.Action Required for Integrators
announceUpgradePlan(address,uint96)after v1.3.1/v1.2.0 are live.setViewContractSafe action may proceed until Kubuxu completes the deferred technical-owner review.Process deviation — issue created early for checklist-driven discovery
Issue #561 was intentionally created before the release-prep PR and release branch so this rollout could expose checklist gaps. The release branch
release-v1.3.1was originally cut frommainat4d8f21aafter PR #562 merged, fast-forwarded to42238feafter deployment-tooling PR #565, refreshed to7f7037fafter pinned-drift reporting PR #567, then refreshed to candidateaea9357after StateView scope PR #568. The reusable checklist changed during this sequence, so this rendered issue was reconciled manually rather than creating a duplicate. The issue-creation checklist item remains removed from this release instance.Release Checklist
Phase 1: Branch, Issue, PR, and Checks
main(tracker FWSS M4.5 GA Fast Follow Contract Upgrade #549; required PRs fix: allow abandonment and consensual termination of underfunded data sets #520, fix: non-reverting upgrade announcement #547, and feat: introduce IFilecoinServiceMetadata and apply it in FWSS #551)FilecoinWarmStorageServiceVERSION()bump. For PDP-only stack releases, use the PDP/submodule bump PR and leave the FWSSVERSION()unchanged. Suggested title:chore: prep FWSS v1.3.1 releasemaincontains the final release notes and applicable version/submodule changes before creating the release branchmainafter the release-prep PR(s) land:release-v1.3.1. Refreshed by fast-forward to candidateaea9357after chore: include StateView in v1.3.1 rollout #568 merged.aea9357, run the Deploy Contract workflow once for Calibnet and once for Mainnet withcontract=Warm Storage stackanddry_run=true. Recorded evidence: Calibnet run 30996922868 and Mainnet run 30996922569.aea9357plans preserve FilecoinPay and PDPVerifier and deploy ServiceProviderRegistry implementation,Rails, FilecoinWarmStorageService implementation, and StateView. Technical-owner review is deferred to the mandatory pre-announce/Safe gate. Operator exception.aea9357plans exactly match the intended four-component deploy set and preserve dispositions. Recorded final inventory.None— dispositions recorded above; Synapse remains a pre-Mainnet gate, while Curio and cloud work are owned non-blocking follow-ups and filecoin-pin validation completed 2026-08-10v1.3.1/aea9357; exact rollout tagv1.3.1-rollout.1/c1ae9e5v1.3.1, mark it as a pre-release, and include component versions plus a FWSS rollout status table:GitHub Release creation commands
Phase 2: Deploy Contracts
Deploy both networks before any announce/execute.
v1.3.1tag for that network and confirm it exactly matches the Phase 1 approved inventory. Stop and return to scope review if it differs; do not broadcast or change pins ad hoc.contract=Warm Storage stackanddry_run=false. The metadata-aware stack run deploys every approved changed, unpinned component in nonce order; do not select components manually or run separate FWSS/SPR deployment paths.service_contracts/tools/verify-deployments.sh --chain <CHAIN>for each target network after deployment metadata is available. Resolve or explicitly waive any bytecode/metadata mismatch before live announce.Deployment metadata checks
Use the deploy dry-run output to distinguish contracts that are
Pinned/preserved,Up to date, orWould deploy. Record the final deploy set before any live announce transaction.SignatureVerificationLib,Rails, orFilecoinWarmStorageServicecontract=Warm Storage stacklive run deploys each changed, unpinned component automatically and records its addressServiceProviderRegistrycontract=Warm Storage stackrun deploy itPDPVerifier,FilecoinPay,ProviderIdSet, orFilecoinWarmStorageServiceStateViewSessionKeyRegistrycontract=SessionKeyRegistryworkflow option and add an exception section to this issueCalibnet Warm Storage Stack
v1.3.1withnetwork=Calibnet,contract=Warm Storage stack,dry_run=truedry_run=falseCALI_NEW_IMPL, plusCALI_NEW_SPR_IMPL, new library addresses, andCALI_NEW_VIEWwhen those components are in the approved inventory, and add them to the Run LogMainnet Warm Storage Stack
v1.3.1withnetwork=Mainnet,contract=Warm Storage stack,dry_run=truedry_run=falseMAIN_NEW_IMPL, plusMAIN_NEW_SPR_IMPL, new library addresses, andMAIN_NEW_VIEWwhen those components are in the approved inventory, and add them to the Run Logservice_contracts/deployments.jsonuntil proxy slots are live.Verification command pattern:
Repeat for every address in the approved live inventory, including a new StateView or other library when present. Supply explorer-specific constructor/library arguments when required, and record any verification failure or waiver in the Run Log.
Optional StateView Switch
FilecoinWarmStorageServiceStateView, confirm it was deployed by the approved live stack run; do not run a second StateView deploymentCALI_NEW_VIEWand/orMAIN_NEW_VIEW, record the deployed StateView address and verification status in the Run Log, and add the StateView address to the GitHub pre-release rollout tablesetViewContract(address)calldata for each affected network and stage it in Safe UI. Execute the stagedsetViewContracttransaction after the corresponding FWSS proxy upgrade execute transaction unless the technical owner approves a different ordering. Calibnet executed successfully as Safe nonce 18; Mainnet executed successfully as Safe nonce 17, both after immediate implementation checks.setViewContracttransaction lands, record its tx link in the Run Log and verifyviewContractAddress()equals the new StateView address. Calibnet recorded and verified; Mainnet recorded and verified.StateView setViewContract calldata and verification
In Safe Transaction Builder, set target to the printed FWSS proxy, value to
0, and data to the printed calldata.Phase 3: Calibnet Announce + Execute
Announce
If this release has a ServiceProviderRegistry exception, generate its Calibnet bootstrap announcement with
NEW_SERVICE_PROVIDER_REGISTRY_IMPLEMENTATION_ADDRESS="$CALI_NEW_SPR_IMPL" AFTER_EPOCH=<absolute-epoch> CALLDATA_ONLY=true ./service-provider-registry-announce-upgrade.sh, execute it through the owner Safe, then verify and record the exact implementation andafterEpochreturned bynextUpgrade()before any execute transaction. This legacy absolute-epoch path is only for upgrading a registry that does not yet expose the relative-delay entrypoint.Set the Calibnet requested delay and update the schedule table. v1.3.1 bootstrap only: record the announcement mode as
legacy; upgrades from v1.3.1 onward always usedelay.Generate announce calldata and submit/sign/execute in Safe UI:
For the normal delay-based flow:
For the v1.3.0 -> v1.3.1 bootstrap rollout only, use this configuration instead:
Generate the transaction after selecting exactly one configuration above:
0, and data to the printed calldataafterEpochin the schedule and Run LogafterEpochExecute
afterEpochNEW_SERVICE_PROVIDER_REGISTRY_IMPLEMENTATION_ADDRESS="$CALI_NEW_SPR_IMPL" NEW_VERSION=<version> CALLDATA_ONLY=true ./service-provider-registry-execute-upgrade.sh, execute it in the approved transaction order, then verify and record its implementation slot,VERSION(), initializer counter, preserved registry state, and clearednextUpgrade()0, and data to the printed calldataCALI_NEW_IMPLVERSION()returns the expected FWSS contract versionviewContractAddress()equalsCALI_NEW_VIEWif a StateView switch was expected, or the unchanged View address otherwisenextUpgrade()is clearedgetPriceList(), matches the intended release pricing and record the command/output in the Run Logfilecoin-pin addwith--network calibrationand unique--data-set-metadata, then record the command output, metadata, Data Set ID, tx/link, SP, and timestamp in the Run Log — Data Sets26657and26658Calibnet filecoin-pin validation
The unique
smoke_runmetadata is required so this validates new Data Set creation rather than reusing an existing Data Set.0x51Bc9fB1e20280D57460a0a69a7077a9682AA164; SPR proxy resolves to0x0dF90c9a20b3f1E383c7196C06943565396c0956; both implementations and StateView are verifiedmainforservice_contracts/deployments.jsonafter the Calibnet proxy switch and, if applicable, View switch are live, then record the PR link in Release Tracking. Opened #573 from the successful deployment-run snapshot after both switches were live.Phase 4: Mainnet Announce + Execute
Announce
Technical owner records Mainnet go/no-go after reviewing Calibnet evidence, rollback status, dependency targets, and cross-repo status
Confirm required cross-repo changes are merged/released or explicitly waived by the technical owner — Synapse #911 has passed checks and downstream review and may merge post-upgrade per Rod; close this gate with the technical-owner go/no-go acceptance
Create or update the public operational notice on status.filecoin.cloud before or alongside stakeholder notification. Mainnet maintenance is scheduled for 2026-08-12
14:15–23:59 UTC, covers the implementation/StateView/validation window, links the v1.3.1 pre-release, and notifies subscribers. The component remains operational until the scheduled start.Notify stakeholders before announcing Mainnet, including FilB so they can propagate the upgrade notice — operator confirmed Slack notification posted 2026-08-11 with the on-chain announcement, public status page, pre-release, and changelog links
If this release has a ServiceProviderRegistry exception, generate its Mainnet bootstrap announcement with
NEW_SERVICE_PROVIDER_REGISTRY_IMPLEMENTATION_ADDRESS="$MAIN_NEW_SPR_IMPL" AFTER_EPOCH=<absolute-epoch> CALLDATA_ONLY=true ./service-provider-registry-announce-upgrade.sh, execute it through the owner Safe, then verify and record the exact implementation andafterEpochreturned bynextUpgrade()before any execute transaction. Executed at epoch6270876; live plan is candidate0x1Bb676392272313598930FEf8D5B66FFECcE02F0,afterEpoch=6274616.Set the Mainnet requested delay and update the schedule table. v1.3.1 bootstrap only:
legacy, with2880notice +2880Safe-signing buffer; proposed absolute epoch6274616generated at epoch6268856. Execute by epoch6271736to preserve the full notice or regenerate both payloads. Upgrades from v1.3.1 onward always usedelay.Generate announce calldata and submit/sign/execute in Safe UI — batch executed successfully in SPR → FWSS order:
For the normal delay-based flow:
For the v1.3.0 -> v1.3.1 bootstrap rollout only, use this configuration instead:
Generate the transaction after selecting exactly one configuration above:
0, and data to the printed calldata — exact batch decoded and executed as proposed0x1Bb676392272313598930FEf8D5B66FFECcE02F0; FWSS0x3583e9fc40243924C6f8eBE3d17e5364Bb6A01a9; sharedafterEpoch=6274616:afterEpochin the schedule and Run Log — tx, execution epoch6270876, observedafterEpoch=6274616afterEpochExecute
afterEpoch— execution occurred at epoch6274884, after6274616NEW_SERVICE_PROVIDER_REGISTRY_IMPLEMENTATION_ADDRESS="$MAIN_NEW_SPR_IMPL" NEW_VERSION=<version> CALLDATA_ONLY=true ./service-provider-registry-execute-upgrade.sh, execute it in the approved transaction order, then verify and record its implementation slot,VERSION(), initializer counter, preserved registry state, and clearednextUpgrade()0, and data to the printed calldata6274884MAIN_NEW_IMPLVERSION()returns the expected FWSS contract versionviewContractAddress()equalsMAIN_NEW_VIEWif a StateView switch was expected, or the unchanged View address otherwise — switched and verifiednextUpgrade()is clearedgetPriceList(), matches the intended release pricing and record the command/output in the Run Log — byte-identical pre/post evidencefilecoin-pin addwith--network mainnetand unique--data-set-metadata, then record the command output, metadata, Data Set ID, tx/link, SP, and timestamp in the Run Log — explicitly deferred to upcoming Dealbot evidence; preflight selected two new Data Sets without spendingMainnet filecoin-pin validation
The unique
smoke_runmetadata is required so this validates new Data Set creation rather than reusing an existing Data Set.0x3583e9fc40243924C6f8eBE3d17e5364Bb6A01a9; SPR proxy resolves to verified implementation0x1Bb676392272313598930FEf8D5B66FFECcE02F0; StateView source is verified. EvidencePhase 5: Promote Release and Close Out
announceUpgradePlan(address,uint96)flow before the next SPR upgrade, and record the cleanup PR link. — focused cleanup #579 merged aseec58d8.ANNOUNCEMENT_MODE=legacyas deprecated and decide whether rollback to v1.3.0 is still supported. Once that rollback path is retired, open and merge a follow-up PR that removes the legacy mode, itsAFTER_EPOCHhandling, the temporary announcement-mode schedule column and bootstrap clauses, the README bootstrap example, and the Temporary Bootstrap Compatibility instructions; record the cleanup PR link. If v1.3.0 rollback remains supported, retain legacy mode or document the exact v1.3.1-tagged helper that operators must use. — Decision: v1.3.0 rollback remains supported for this release. Mainline legacy mode remains deprecated; use the immutablev1.3.1-rollout.1helper for that rollback path until support is retired.mainforservice_contracts/deployments.jsonafter the relevant Calibnet/Mainnet proxy switches and, if applicable, View switches are live. Include live implementation addresses, View addresses, deployment bytecode metadata, andpdp_version/fwss_versionfields for each updated network. Calibnet #573 and Mainnet #576 are merged; final two-network live verification passed.service_contracts/deployments.jsonPR link(s) in Release Tracking, then merge after checksum validation, bytecode metadata verification, and live-slot verification — Calibnet #573 and Mainnet #576 mergedservice_contracts/deployments.jsonbytecode metadata matches the live deployed contracts after all proxy and View switches are complete — merged snapshot and two-network verification evidenceDeployment bytecode metadata verification commands
ABI update commands
022171copened #916. Evidence.e67e9f344ffc12service_contracts/tools/UPGRADE-CHECKLIST.mdif the process should change — process PR #578 is rebased onto merged chore: use relative delays for SPR upgrades #579 and ready for review; it tracks issue-first release setup, the status-page lifecycle, removal of FWSS v1.3.1 bootstrap-only instructions, and collapsible pre-checklist context for easier human review; mark complete after mergeResources