runtime
spec_version: 51.
This release completes most of Phase 1: community governance and the CPS authority model, and starts the groundwork for embedded clients see docs/robonomics-5.0-roadmap.md.
Highlights
1. On-chain governance (OpenGov)
A minimal, permissionless OpenGov stack, controlled by XRT holders (#652, #629):
pallet-preimage,pallet-scheduler,pallet-referenda,pallet-conviction-voting,pallet-whitelist,pallet-collective.- Only two tracks:
- Root: the normal path for runtime upgrades and any privileged call.
- Whitelisted Caller: a fast track for technical changes. The Core Team collective can only whitelist a call hash. The call still needs a public XRT-holder referendum to run.
- No Council, no developer Root key.
This is stage A (bootstrap) of the handover. Sudo remains only as a recovery path. The next step is a runtime upgrade that removes Sudo, submitted and enacted through OpenGov itself (#633).
2. CPS v1.0: Scope and Access
pallet-robonomics-cps moves from per-node owners to the Scope / Access model (#653; #649, #654, #656, #661, #670–#672):
Nodes NodeId -> { parent, scope }
Children NodeId -> bounded child ids
Scopes ScopeId -> { owner, access_count }
Access ScopeId x (NodeId, AccountId) -> AccessFlags
- Scope is the administrative and economic boundary of a subtree. A node belongs to its nearest Scope ancestor. A nested Scope is a hard boundary for authority, Access and, later, resource accounting.
- A node's parent never changes.
move_nodeis removed. To relocate a node, create a new node and delete the old one. - Access delegates capabilities inside one Scope:
Writechanges a node'smetaandpayload.CreateScopecreates or replaces a Scope generation. This is also how control is handed over.GrantMode::Node | Subtreeapplies a grant to one node or to its descendants. A grant never crosses a nested Scope.
- Changing the owner creates a new generation. A fresh
ScopeIdis allocated and the old grants stop working immediately. The transfer/accept flow anddelete_scopeare removed. A Scope disappears only when its root is deleted, which is allowed only once the root has no children. - Bounded, synchronous cleanup. Each Scope can hold only a limited number of Access entries, so they are cleared in the same extrinsic. There is no background GC.
- Depth is limited per Scope, not globally.
MAX_SCOPE_DEPTHlimits the walk to the nearest Scope root. The whole tree can be deeper. - Weights follow data size.
create_node,set_metaandset_payloadare charged by actual bytes. Hard limits: 1 KiB formeta, 8 KiB forpayload. - Runtime API.
CpsApi::resolve_scope(node)returns{ id, root, owner }through the standard runtime call onpolkadot-omni-node. No custom RPC is needed (#651). It ships in the new cratepallet-robonomics-cps-runtime-api.
3. robonomics-runtime-metadata crate
Runtime metadata extraction and checking moved out of subxt-api into a separate crate. It is now the single source of truth for all API generators (#665, #663):
robonomics-runtime-metadata (METADATA: &[u8])
├── robonomics-runtime-subxt-api Rust / Subxt
└── robonomics-runtime-embed-api embedded tooling (next)
subxt-api forwards the build-metadata and check-metadata features, so existing commands keep working.
4. Engineering baseline
- Weight policy in CI.
scripts/check-weights.plfails any extrinsic that is not charged through a benchmarkedWeightInfo(#645). - try-runtime is mandatory whenever a storage version is bumped (#646). Security review checkpoints are defined (#647).
- The Robonomics 5.0 roadmap is now in the repository (#644).
- Local dev chain with no extra binaries.
scripts/build-development-spec.shpluspolkadot-omni-node --devstarts a single-node chain with pre-funded accounts onws://127.0.0.1:9944. - Dependency updates:
subxt0.51
Where we are on the roadmap
Phase 1 Runtime, Governance, CPS foundation
runtime separation (v50) done
OpenGov stack done <- this release
Sudo removal via governance next (#633)
CPS node model, immutable hierarchy done <- this release
Scope / Access / Write done <- this release
Phase 2 Subscription and Transactions in progress
account-scoped generations,
XRT-denominated transaction budget design ready (#657)
port of pallet-subscription (#381) almost done (#635)
runtime integration, governance params,
runtime API and tooling open (#636, #638, #639)
RWS -> Subscription migration plan done (#637)
embedded clients:
runtime metadata crate done (#663)
scale-embed C codec done (#664)
embed-api / embed-codegen / fingerprints open (#662, #666, #667)
Phase 3 Storage (Bulletin Chain) planned (E6-E8)
Phase 4 Compute (RISC Zero) research (#659)
Phase 5 Programmable CPS (Policy) planned
Next release: remove Sudo through OpenGov and land Subscription with Scope-funded transactions, so an owner-funded device can send its first transaction without holding XRT.
Upgrade notes
- Governance: after this upgrade, runtime upgrades go through Root or Whitelisted Caller referenda. Sudo remains only as a temporary recovery mechanism.
- CPS (breaking): the storage layout and the set of extrinsics have changed.
move_node,transfer_ownership,accept_ownershipanddelete_scopeare removed.resolve_ownershipis replaced byresolve_scope.metaabove 1 KiB andpayloadabove 8 KiB are rejected.
- Clients and
libcps: get the effective owner throughCpsApi::resolve_scopeinstead of walking the parent chain on the client side. - Integrators:
subxt-apinow needs subxt 0.51.x. For metadata, depend onrobonomics-runtime-metadatainstead ofsubxt-api.
Full Changelog: v50...v51
Runtime Info
🏋️ Runtime size: 1.243 MB (1,303,658 bytes)
🗜 Compressed: Yes, 83.49%
✨ Reserved meta: OK - [6D, 65, 74, 61]
🎁 Metadata version: V14
🔥 Core version: robonomics-51 (robonomics-airalab-1.tx4.au1)
#️⃣ Blake2-256 hash: 0xacb849eb6b1c21457c34e85c670ee15860cd6c7d6fcb3adcf82aef57f45ff88c