Logos Collective Weekly Summary

Week 35, 2026 (August 31, 2026)

5
Teams Reporting
250+
PRs & Updates

Key Highlights

Messaging

logos-delivery-module v0.2.1 released — shipping multiple bugfixes and an update of the underlying logos-delivery library, plus a migration to the nim-ffi 0.3 C ABI.

Messaging

Mobile platforms deliverable closed — Android and iOS builds repaired and gated in CI; three fleet-stability fixes merged and the nim-libp2p 2.3.1 migration landed on master.

AnonComms

λAccount identity primitive hit first review milestones — initial draft of the AccountLogs specification and a base Rust implementation in libchat both up for review.

AnonComms

First end-to-end LEZ-based RLN test in Logos Delivery passed — delivery and RLN membership modules both registered on the LEZ testnet, then generated and verified proofs.

Logos Core

Human-approved signing replaces the unlocked-signer cache in the EVM wallet stack — sign_* deleted from the keystore contract, admission tiered by caller identity, and signer_ui proven end-to-end against a live secp256k1 signature.

Logos Core

App-to-app intents shipped — three frozen QML symbols over a host-side broker that checks each caller's uses declaration; provides landed in the package format and intent names carried through downloader, bundler and templates.

Storage

Mix transport now carries data transfers — a new multinode testing harness runs 100+ node experiments with 80+ concurrent downloads in a fault-free network.

Storage

Storage moved to the nim-libp2p Kademlia DHT — discovery runs over the node's existing switch and TCP transport, retiring the whole second UDP stack and bringing us closer to a unified Logos codebase.

Blockchain

Proof of Work integrated end to end: mining thread pool, deployment settings, claim test #3398, #3400, #3403

Blockchain

Compressed Block Proposal RFC merged logos-lips#389

Blockchain

Block Rewards RFC merged: pooling, distributing, and releasing replace burning and minting logos-lips#375

Messaging API — General Availability

^

Reliable Channel API — Beta

^

Chat — Beta

^

Implement full identity model

Deliver user-facing chat features

Status: Logos Delivery Integration

^

Support mobile platforms in logos-delivery (CLOSED)

  • Closed deliverable — mobile support: fix: android support, fix: ios support — both builds had been broken since the Nimble migration with no CI job to catch it; liblogosdelivery now builds for Android and iOS on every PR

Integrate Messaging API in status-go

  • Go bindings: define Nim dependency using Nimble — #121; provide access to Kernel API when using Messaging API — #122
  • Kernel suite passes and now runs on every PR — #125, #126, #127
  • Consistently surface payload fields as base64-encoded — #4170
  • Link liblogosdelivery through Go bindings using Nimble — status-go #7731 — blocked by #7757, which moves status-go's Nim dependencies onto Nimble

Maintenance

^

Fixes & Improvements

Create a basic service discovery module

^

Integrate the standalone service discovery module into Logos Delivery

  • Refactored the discovery interface in logos-delivery into a common interface covering discv5, internal Kad discovery, and plugin-based Kad discovery
  • Implemented the discovery plugin interface on the FFI surface (PR train of 6)
  • Implement the logos-delivery-module libp2p-module / service discovery provider interface

Establish libp2p mixnet

^

Implement local reputation mechanism and research advanced DoS protection

  • Finish the rate differentiation implementation
  • Finish local reputation research

Deliver de-MLS for p2p group messaging

^

Integrating de-MLS into libchat

  • Finished the member id rework, merged on the de-mls side (PR 145); final review pending on the libchat side
  • Reworked the peer scoring mechanism — de-mls PR 148 (merged)
  • Continued work on reliability and fork prevention with the libchat team
  • Simulated different reliability scenarios (no commit and want flag, quorum, and heartbeat mode) to measure success ratios
  • Review the architecture and initiate discussion about possible reorganisations
  • Continue work on fork prevention
  • Add more reliability simulation scenarios if needed

Implement RLN membership allocation service

^

Migrate Logos Delivery to LEZ-based RLN using the RLN membership management module

  • First end-to-end test running the logos-delivery-module alongside the logos-rln-module — both nodes register on the LEZ testnet, generate proofs, and verify proofs using the module

Decentralised Oracle Network

^

Implementing Oracle Zone

  • Completed the oracle node and oracle register integration; multiple price provider support in progress
  • Complete multiple price provider support
  • Run the indexer

Maintain and expand Zerokit

^

Integrate and benchmark Poseidon2 hash function

  • Continued Poseidon2 integration (zerokit PR 437) and implemented a first draft of the Poseidon2 circom circuit
  • Continue the Poseidon2 circuit implementation

Develop the λAccount identity primitive

^

Specify basic λAccount protocol

Implement basic λAccount library

  • Base implementation for AccountLogs and Accounts implemented in Rust and opened for review

logos-evm-keystore-module

Human-approved signing replaces the unlocked-signer cache — sign_* deleted from the contract, admission tiered by caller identity, and the vault password derives the key inside approve() and is zeroized before it returns.

#6

logos-evm-signer-ui

Made signer_ui work and proven end to end against a live secp256k1 signature; five defects found by running it rather than reading it.

#2

logos-evm-wallet-backend-module

Wallet backend became a pure requester of human-approved signatures; fees taken from fee_module; RAILGUN dropped until migrated off keystore.sign_digest.

logos-evm-wallet-ui

Stopped handling the vault password; Private (RAILGUN) tab dropped until railgun is migrated; leaf modules pinned to the backend's own locked inputs.

logos-view-module-runtime

App-to-app intents frozen surface added (logos.request, logos.intentRequested, logos.respond); ui-host adopts the parent's credential through the shared verb.

logos-basecamp

App-to-app intent broker on the host/shell split; bundled modules_state; version-range enforcement in the sidebar; consumer admission via the shared verb; MCP-driven UI test preparation.

logos-package

provides field for intents; consumers can carry a package's signature and check it against a DID of their own; installed packages can be checked; hyphen ranges documented.

logos-package-downloader

Intent name support; resolver fix so a signer pin cannot bind to an unverified signature; multi-download concurrency enabled.

logos-package-downloader-module

Concurrency enabled; empty-signer pin fix taken; signer-binding fix taken.

logos-package-manager

Dependency version-range evaluation without masking deeper mismatches; unknown signing key surfaces a real message; read-only bits cleared and partial installs rolled back; variant table taken from logos-package.

logos-package-manager-module

Dependency constraints put on the wire; relocks and package-manager bumps.

logos-package-manager-ui

Requests Settings → Repositories via an intent; Basecamp↔PMUI install/uninstall/upgrade ack handshake removed.

logos-liblogos

Module lifecycle turned into sequenced facts fed to modules_state; dependency version ranges enforced at load; ready kept across snapshot; protocol 0.8 and 303ab08 across all three carriers.

logos-modules-state-module (NEW)

Gate ingest on WHO the caller is, not what it knows — retiring an ingest-token nonce and the ModuleDescriptor.env plumbing it would have required.

#1

logos-protocol

INBOUND and OUTBOUND tokens separated without moving a single byte; private store created empty rather than seeded with the host anchor; onEventWhenAvailable takes the wildcard.

logos-plugin-qt

logos::admitConsumer shared verb; informModuleToken routed through the INBOUND door; void-refusal fixes in both generated sites; protocol 303ab08 wildcard.

logos-cpp-sdk

logos_module_accept_inbound_token defined for cdylibs; argument count bounded above and an lp reply the consumer cannot read handled.

logos-qt-sdk

A Qt-consumer reply it cannot read must not be reported as a provider refusal; relocks and protocol 303ab08.

logos-rust-sdk

A module announces its OWN name, not core; argument count bounded above and the identity arm gated.

logos-module-builder

Intent template support; SDK relocks for the arity bound and the result decode; record-codec qualification; protocol 0.8 module-stack relock.

logos-module-loader-qt

Outbound core/capability tokens documented at load; qt-sdk stack relock.

logos-capability-module

Identifies the requestModule caller from the RPC token; caller-aware module-builder relock.

logos-libp2p-module

Inbound accept queue restored; peer id reported and pingPeer added; context pointer guarded against a concurrent destroy; integration tests build again.

logos-delivery-module

Migrated to the nim-ffi 0.3 C ABI, released as 0.2.1, bumped in the release set.

logos-delivery-demo

Bumped delivery_module to v0.2.1 and cut release v0.2.1.

logos-modules-release

Bumped delivery module to 0.2.1 and added delivery demo; blockchain module 0.2.3.

logos-modules-release-tool

Docs updated to mention intents.

#7

logos-storage-module

version() renamed to libstorageVersion() (breaking).

#81

logos-execution-zone-module

Persistent path exposed via LogosModuleContext.

#53

logos-logoscore-cli

Draws the line at LOADED for both watch and call; CLI daemon files client token as INBOUND; catalog versions and one version per row in package search; protocol 0.9.

logos-logoscore-py

Conformance: the consumer axis in Python, two relocks and the two races they exposed.

#22

logos-test-framework

Exposes logos::CallCaller from logos_test.h.

#7

logos-test-modules

Consumer axis in the ext table (44 × 2 × 1 → 44 × 2 × 3) via Qt proxy fixture, plus null-vs-failure classes as cells, echoOptional shape unification and isolate rule cleanup.

logos-module

The module is the directory it is installed in; signer half of malformedConstraint covered.

logos-standalone-app

Logs to stderr by default; loads the backend library the plugin actually declares; consumers admitted through the shared verb.

logos-tutorial

Tutorials updated so UI modules use QML hot reloading correctly; documentation and tests for the implemented intents mechanism.

logos-chat-ui

New designs landed across the chat surface.

#59

logos-blockchain-ui

New designs landed across the blockchain surface.

#61

lez-explorer-ui

New designs landed across the LEZ explorer surface.

#21

logos-execution-zone-wallet-ui

Moved onto LogosDesignSystem components; onboarding reworked into two paths (create a wallet, or use an existing one); tests turned on in CI.

nix-bundle-lgx

Intent name support; logos-package bump.

#13

Large Data Transport Layer for Mix

^

Mix Transport

  • Finished data transfer over the Mix transport
  • Started adding reliability features: SURB management and refills
  • Initial implementation of a multinode testing harness — after some bug fixing, can run 100+ node experiments with 80+ concurrent downloads
  • Re-transmissions of outbound packets
  • Introduce the "push" model to SURB replenishment (may extend, complement, or replace the current "pull" strategy — subject to investigation)
  • Remote closing and cleanup of sessions and streams

Hidden Services Over Mix

^

Hidden Services Over Mix

  • Evaluated Tor's hidden service path selection strategy in the Mix setting and threat model using Tor's vanguard simulator
  • Experimented with different parameters and configuration to find optimal params, configuration and path lifetime for mix hidden services, and found a promising approach
  • Write down the research outcome in a forum post and possibly a paper
  • Include the optimal strategy in the path selection spec

Switch to Kad-DHT

^

Switch to Kad-DHT

  • Replaced codexdht/discv5 with the nim-libp2p Kademlia DHT — discovery now runs over the node's existing switch and TCP transport instead of a second UDP stack with its own identity and port
  • Retired the whole UDP side, the derived UDP announce addresses, and the UDP NAT port mapping
  • Full test suite passes, including the NAT/hole-punch integration scenarios

Bedrock — Research

^

Cryptarchia

  • Compressed Block Proposal LIP merged: block proposals carry 16-byte transaction reference prefixes logos-lips#389; reference-prefix length priced instead of bounded, with benchmark-backed report merged research#8
  • Revised block proposal compression RFC reworked: short IDs switched to truncated Blake2b with the reference key derived from Proof of Leadership public inputs, combination cap raised to 8192, measured Raspberry Pi 5 and validator-class rehash figures replace estimates (in-review) logos-lips#408
  • Mempool RFC extended: transaction maturity established by pull confirmation (draft) logos-lips#415; consensus-level transaction validity window (draft) logos-lips#416
  • Spec clarifications merged: execution and validation steps made explicitly sequential logos-lips#417, genesis block validation rule specified logos-lips#419, epoch number fixed to uint32 everywhere logos-lips#420, channel configurations ordered and replay prevented logos-lips#396
  • Locked notes renamed to service notes in the specs logos-lips#423 and the node #3430
  • Blend token evaluation and active-message encoding fix merged, with the blend digest width derived from the quota requirement logos-lips#405; Blend connection traffic bounded at the receiver (draft) logos-lips#421
  • SDP active and withdraw_at epochs record RFC opened: epoch of an active message defined, withdraw_at renamed to withdrawn, last served epoch paid (in-review) logos-lips#422
  • Blend PRNG replaced with ChaCha20: RFC merged logos-lips#425, implementation (in-review) #3435

Total Stake Inference

  • Total Stake Inference research merged: fork-loss claims validated at the deployed operating point research#2; uncle-reference verification depth bounded via a parent-anchored window with W = 12 and four simulator defects fixed research#4, research#10

EmPoWering

  • Block Rewards RFC merged: burning and minting replaced with pooling, distributing, and releasing logos-lips#375
  • Tokenomics simulations and report merged with pow_quota settled at 3 research#5; participation simulator, cost estimator, and strategies report merged with the emission split settled and the bond fixed at 1,000 tokens research#6; de novo model merged: two regimes, three parameters, and the simulations validating them research#7
  • EmPoWering moved onto the pooling substrate of the Block Rewards RFC, gate suites mutation-tested and reports rewritten for a lay reader (in-review) research#9
  • Microscopic tokenomics model simulated, tracking individual newcomers, stakeholders, Blend providers, and external miners across Proof of Work, Proof of Stake, and service participation: Proof of Work bootstraps tokenless newcomers, but incumbents and professional miners can capture a substantial share of rewards doc

Post-Quantum

  • Post-Quantum primitive benchmark with sender/receiver asymmetry under load merged research#3
  • Post-Quantum Transport Security phase 0 RFC opened: hybrid key exchange for QUIC (in-review) logos-lips#429; supporting QUIC handshake benchmarks on the quinn and rustls stack, classical vs hybrid (in-review) research#11
  • Post-Quantum migration blog post completed, ready for review doc
  • Post-Quantum ZK transition paths rewritten around new measurements doc

Bedrock — Engineering

^

Blend

  • Blend state recovery logic improved #3394
  • Proof of Work proof generation moved to a rayon thread pool instead of a Tokio blocking task #3399
  • Blend stack crates split and restructured #3404
  • Proof of Quota usage improved: encapsulation proceeds with fewer proofs than the expected number of layers instead of discarding the whole set #3411
  • Epoch-bound components grouped into their own types on epoch transitions #3417, on core service shutdown #3422, and for both core and edge services #3432
  • Out-of-sync block proposals and Proof of Leadership winning-slot streams handled, with the code made cancellation-safe #3418
  • Recoverable and unrecoverable libp2p dial errors distinguished for core-node connections and edge-node sends #3440

Node

  • Proof of Work stack completed: dedicated mining thread pool #3398, Proof of Work constants threaded in as deployment settings #3400, claim cucumber test #3403
  • Channel config lineage enforced via parent message id merged #3272
  • ZK batch verification benchmarked at the ledger level #3355
  • SDP active message resubmission #3415 and activity intent tracked until finalized #3450 merged
  • Wallet backfills missing LIB updates instead of panicking #3437
  • Boundedness hardening: oversized bounded sequences rejected early during deserialization #3424, fixed-size deserialization hardened #3425, bounded serialization API added #3423
  • Blend info exposed over FFI #3397
  • Legacy sequencer archival demo removed, about 5,000 lines #3416; TUI Zone code removed #3439
  • Orphan downloader no longer caches rejected blocks with invalid signatures (in-review) #3452

Testing

  • Accelerated Blend diagnostic cucumber scenarios merged #3395
  • Cucumber world state #3421 and steps #3443 reorganized by domain

Zone SDK

  • Config lineage zone-sdk support merged #3408, #3414; inscription info expanded with signer information #3420
  • Deposit with atomic inscribe (in-review) #3448; multi-signature config (in-review) #3455
  • λSQL merged: channel write application #3333, inscription encoding #3348, nondeterministic function result capture for deterministic replay #3361, fork-aware live state recovery #3406, #3454

Logos Core

  • Blockchain module exposes Proof of Work (in-review) logos-blockchain-module#72 and Blend info (in-review) logos-blockchain-module#73
  • Zone SDK client reworked so blockchain-related code is generated inside the blockchain module, letting zone-sdk and other Rust projects call the module without building with nix (WIP) code
  • Testnet nodes redeployed with new provider and zk ids and SDP services redeclared

Logos Execution Zone

^

Sequencer

  • Slashing v1 merged, adapted to the new zone-sdk API #737; multi-sequencing stress-tested locally with a committee of about 8 sequencers taking turns keeping a consistent Logos Execution Zone state, transaction gossiping included
  • Actor architecture phase 2: rocksdb communication moved into the Storage actor (in-review) #798

Fees

  • Fee logic redesigned around stateful transaction transitions instead of raw state mutations, and the eight-PR stack consolidated into a single PR (in-review) #801; producer checked against the L1 inscription (in-review) #816
  • Producer reward payout redesigned to reuse the staking sequencer's producer established by slashing, removing the injected auto-initialization
  • Issues raised from the fees implementation: Fee/Balance/Gas/Cycles aliasing #794, block-building guard folded into metered settlement #796, gossip-ingested transactions screened through fee admission #797, cross-zone dispatch fee model #799, bridge deposits not verified against L1 #809

Cross-Zone

  • Cross-zone guardrails merged, concluding the cross-zone work: lifetime mint caps per peer source and dead-letter requeue #805, committee floor suspending a peer below its minimum accredited committee #806, guardrail riders, bridge-lock holding PDAs, builtin gating, and seed normalization #807

Accounts

  • Events merged end to end: events field and core semantics #705, protocol-level selectors #707, indexer re-derivation #709, RPC #713, FFI #714, deposit/withdraw events #716, event filters against indexer state bloat #785, integration #802
  • Programs as accounts: Deploy bytecode batched across multiple transactions #748, segmented across multiple PDA accounts #740, Deploy execution and transmission made more efficient #739; program storage as a linked, arbitrarily-addressed segment chain (in-review) #812; program loader wallet CLI and FFI support (in-review) #815
  • Incremental updates scoped down for the release candidate: ChainedCall pre-states replaced with pre-state references (in-review) #790, programs wired to diff-native execution (in-review) #791; predicate/auxiliary design chosen as the opt-in fix for the defect found in incremental updates
  • Environment unification: namespaced account state proof of concept (draft) #789
  • Critical chained-call processing bug found in the PPC, a missing equality check between protocol-level and user-level data: fed pre-states now checked against chained call references (in-review) #813; execution refactor cutting about 500 lines of production code started (draft) #804

Testing

  • Integration tests pinned to one deterministic Bedrock version (in-review) #793

Nimbos

^

Nimbos

  • SRP and Blend rewards merged nimbos#172
  • Kademlia discovery layer finalized: discovery loops, bootstrap lifecycle maintenance, eclipse-attack defense via minimum outbound peers, private address filtering, and dynamic peer discovery during initial block download (in-review) nimbos#28
  • libp2p GossipSub integration with topic subscriptions and message validation opened (draft) nimbos#177
  • Legacy eth/net/nat and NatConfig removed in favor of Logos-native reachability and AutoNAT v2 (in-review) nimbos#176
  • Stateless Mantle transaction validation (in-review) nimbos#183