From be99e683bd8d4f5a35f6f4a1eb564930edb06ff3 Mon Sep 17 00:00:00 2001 From: Anthony Ettinger Date: Sat, 5 Sep 2026 19:12:45 -0700 Subject: [PATCH] Add pay2seed, paid2seed, pay2stream and paid2stream to the OpenSwarm family (#143) * Add pay2seed to the OpenSwarm family: consent at upload and a paid seed market OpenSwarm pays a seeder per verified piece served, and nothing pays anyone to stay. An archive, a backup, a dataset waiting for its buyer or a podcast's back catalogue earns nothing the month nobody downloads it, so it dies the way every swarm always has. And nothing in BitTorrent says who put a swarm there or whether they were allowed to, which is why a seeder is presumed to be doing something wrong. pay2seed is the member document for both halves. An attestation, signed at upload with a fixed basis (own, licensed, open-license, public-domain, personal) and a notice endpoint, is what a hub requires before it will list anything; public claims get a claim window and a standing, and a notice voids them. An offer escrows a budget at an ippay hub for a swarm, public or private, to be held by M seeders for N days at a price per GiB-month, bought over x402 exactly as a pass is. Seeders take leases, prove each period by storage challenge or by a probe over the ordinary wire, and are paid through the payee they already have. Public feeds ride on ipdb; ipfile.pin on c0mpute is the same offer on the auction. Also: the family table, stack diagram and registry rows; the ip seed command group; PRD 0006; the protocol row on /openswarm. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01SKAohrRkqLKVQL2cGCAkR5 * Split pay2seed into client and server halves, and add pay2stream and paid2stream The rule is now in the names. pay2* is the client protocol: the side that pays, over HTTPS, and plays. paid2* is the server protocol: the BitTorrent side that earns. One hub implements both halves of a pair; a requester or viewer implements only pay2*; a seeder, relay or gateway only paid2*. pay2seed keeps consent, offers, the requester's market and notices. paid2seed takes leases, storage challenges and probes over the wire, GiB-month accrual and receipts, the seeder client, and the ipfile.pin mapping. pay2stream and paid2stream do the same for a live channel over iplive. A broadcaster attests the channel (with the two rules that separate a licensed rebroadcast from a stolen feed), buys relays by the hour, and publishes listings; viewers buy tickets. Relays take leases and are proven present by a verifier that pulls segments as a peer; a gateway is a relay that also serves standard HLS, clear or sealed, with the M3U and XMLTV pair every IPTV app asks for, so VLC, TiviMate, Kodi and a television play a paid swarm with nothing installed. Ace Stream showed BitTorrent can carry live TV to millions; this is that with consent, payment and an open spec. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01SKAohrRkqLKVQL2cGCAkR5 * pay2seed: encrypted by default, access as the product, a README in every swarm The client encrypts by default and the hub never does: what the hub manages is who may decrypt. A team is a named set of member keys with a scope over the owner's swarms; the hub, as keeper, issues grants to members when the owner is offline, with invitations that expire, roles, an audit trail, and re-encryption on removal so the next version is closed to whoever left. A few seats are free; above that the hub charges per seat and per organisation, settled through the same pay plugins as everything else. Seeding is priced at disk; access is where a hub earns, and both sides earn: seeders rent disk, requesters sell access. Public is not a fallback. Encryption off is an explicit act, and a public swarm is attested, listed, kept and rendered exactly as a private one is; the only difference is who can read it. Every swarm on the market carries a README.md at its root, no exceptions, and the attestation carries its Markdown and the hash of the copy inside the swarm, so the hub renders it as the swarm's page without a key. Relative links resolve into the swarm and are gated the way the files are. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01SKAohrRkqLKVQL2cGCAkR5 * pay2seed: 1 percent, ads on the free tier, and agents as sellers Three things the specs did not say. The reference hub takes 1 percent of any payment that crosses it, charged to whoever is paying and never deducted from a seeder or a relay, so a quoted price is what the publisher gets and a promised floor is what the seeder is paid. Public swarms are free to fetch and free to list, and an advertisement on the swarm README page is what pays for that. The ad is on the hub page and nowhere else: never inside a swarm, never injected into a file, a segment or a playlist, and never in the catalogue or the market API. A requester who wants no ad buys a seat instead. A free-to-watch channel works the same way. And a requester is a key, not a person. An agent can attest what it made, price access, sell tickets, take payment through its own payee and spend what it earns keeping its own work online. The consent rules do not soften because a machine signed them, and the reference hub asks an agent public attestation to name a responsible operator key so somebody is reachable when a notice arrives. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01SKAohrRkqLKVQL2cGCAkR5 * Fix CI: number the PRD requirements and advance the next-id assertion Two checks the new PRD tripped, both by existing rather than by being wrong. The collection validator wants requirements as numbered R# entries and 0006 used a plain ordered list, so it reported OP-L-NO-REQUIREMENTS. Rewritten as R1 to R7 with priorities, one capability per entry, and the implementation tracking moved to a paragraph under them where it is not pretending to be a requirement. The MCP standards test asserts what the next free PRD id is, and its own comment says that advances with every PRD added. Adding 0006 makes it 0007. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01SKAohrRkqLKVQL2cGCAkR5 --------- Co-authored-by: Claude Fable 5.1 --- apps/logicsrc-web/src/app/openswarm/page.tsx | 6 +- docs/openswarm.md | 23 + docs/openswarm/cli.md | 38 ++ docs/openswarm/ippay.md | 10 +- docs/openswarm/paid2seed.md | 325 +++++++++++ docs/openswarm/paid2stream.md | 276 +++++++++ docs/openswarm/pay2seed.md | 554 +++++++++++++++++++ docs/openswarm/pay2stream.md | 260 +++++++++ docs/openswarm/spec.md | 13 + packages/logicsrc-mcp/src/standards.test.ts | 2 +- prd/0006-add-pay2seed-spec.md | 246 ++++++++ prd/README.md | 1 + 12 files changed, 1751 insertions(+), 3 deletions(-) create mode 100644 docs/openswarm/paid2seed.md create mode 100644 docs/openswarm/paid2stream.md create mode 100644 docs/openswarm/pay2seed.md create mode 100644 docs/openswarm/pay2stream.md create mode 100644 prd/0006-add-pay2seed-spec.md diff --git a/apps/logicsrc-web/src/app/openswarm/page.tsx b/apps/logicsrc-web/src/app/openswarm/page.tsx index b9b83be..9db3725 100644 --- a/apps/logicsrc-web/src/app/openswarm/page.tsx +++ b/apps/logicsrc-web/src/app/openswarm/page.tsx @@ -17,7 +17,11 @@ const PROTOCOLS: Array<[name: string, line: string]> = [ ["ipaudio", "Audio releases and tracks on ipfile swarms: renditions, seek tables, gapless, royalties"], ["ipvideo", "Video on demand: CMAF renditions, segment index, subtitles, thumbnails, an HLS bridge"], ["iplive", "Live streams: segment fan-out over paid relays with backpressure"], - ["ipname", "How a Moshpit name or a domain resolves to a publisher key and a catalogue"] + ["ipname", "How a Moshpit name or a domain resolves to a publisher key and a catalogue"], + ["pay2seed", "Client protocol for paid seeding: consent at upload, seed offers with escrowed budgets, the requester's market"], + ["paid2seed", "Server protocol for paid seeding: leases, storage challenges and probes over the wire, GiB-month settlement, the seeder client"], + ["pay2stream", "Client protocol for paid live streams: consent for channels, relay offers by the hour, tickets, watching on any HLS player"], + ["paid2stream", "Server protocol for paid live streams: relay leases, presence proofs, gateways serving standard HLS with an M3U and EPG"] ]; const ROLES: Array<[role: string, work: string, paid: string]> = [ diff --git a/docs/openswarm.md b/docs/openswarm.md index 61393a4..aedd2ae 100644 --- a/docs/openswarm.md +++ b/docs/openswarm.md @@ -34,6 +34,10 @@ a different product. The member protocols keep their `ip` names. | `ipvideo` | Video on demand on `ipfile` swarms: CMAF renditions, segment index, subtitles, thumbnails | [`ipvideo.md`](./openswarm/ipvideo.md) | | `iplive` | Live streams: segment fan-out over peers, paid relays, backpressure | [`iplive.md`](./openswarm/iplive.md) | | `ipname` | How a Moshpit name resolves to a publisher key and a catalogue | [`ipname.md`](./openswarm/ipname.md) | +| `pay2seed` | Client protocol for paid seeding: consent at upload, seed offers with escrowed budgets, the requester's market | [`pay2seed.md`](./openswarm/pay2seed.md) | +| `paid2seed` | Server protocol for paid seeding: leases, storage challenges and probes over the wire, GiB-month settlement, the seeder client | [`paid2seed.md`](./openswarm/paid2seed.md) | +| `pay2stream` | Client protocol for paid live streams: consent for channels, relay offers, tickets and listings, watching as a peer or on any HLS player | [`pay2stream.md`](./openswarm/pay2stream.md) | +| `paid2stream` | Server protocol for paid live streams: relay leases per hour, presence proofs, gateways serving standard HLS, M3U and EPG | [`paid2stream.md`](./openswarm/paid2stream.md) | Supporting documents: @@ -50,6 +54,10 @@ Supporting documents: | ipaudio ipvideo iplive ipdb (catalogue) | | releases titles channels feeds, entries | +---------------------------------------------------------------+ + | pay2seed / paid2seed | pay2stream / paid2stream | + | consent, offers, market | consent, relay offers, tickets | + | leases, challenges, payout | leases, presence, HLS gateways | + +------------------------------+--------------------------------+ | ipfile: manifest, per-file key pair, encrypted pieces, | | key grants, credit window, vouchers per served piece | +-------------------------------+-------------------------------+ @@ -132,6 +140,20 @@ serves more than the window unpaid. Its head is a BEP 44 mutable item under the feed key, so any DHT node can find the latest catalogue of any publisher with one `get`. +**One seed market, one stream market.** A `pay2seed` offer is money +escrowed at a hub for a swarm to be kept for a period, public or private, +and it cannot be listed without a signed attestation of who put the data +there and on what basis. On the `paid2seed` side, seeders take leases, +prove they hold and serve the pieces every period, and are paid per +GiB-month. `pay2stream` and `paid2stream` do the same for a live channel: +a broadcaster attests it and buys relays by the hour, relays and gateways +prove they are online and serving, and a gateway turns the swarm into +standard HLS so any television plays it. The naming is the rule: `pay2*` +is the client protocol, the side that pays over HTTPS; `paid2*` is the +server protocol, the BitTorrent side that earns. It is how a torrent +client becomes a legitimate file sharer: consent on the way in, proof on +the way out, and a payout for staying. + ## What it does not define A media player. Transcoding settings beyond what a manifest must declare. A @@ -146,6 +168,7 @@ key and the spec says so. | Browser WebTorrent player, hybrid Node seeder, wss trackers | `profullstack/media-streamer` (bittorrented.com) | Speaks the vanilla wire this family extends; needs the `ipfile` extension to pay | | DHT crawl (bitmagnet) and `/dht` browse | `profullstack/media-streamer`, `dht-infohash-crawler` | Observes `ipfile` swarms as opaque infohashes; `ipdb` is how it would learn what they are | | Pay-per-pass grants, HLS manifest sealing | `media-streamer` IPTV and seedbox rails | The central-proxy version of what `ippay` moves into the swarm | +| Headless seeder daemon with an add API and per-torrent seed time | `torlink` (`torlnk serve`) | The `pay2seed` seeder client, once it polls a market and answers challenges | | x402 v2 offer, `X-PAYMENT` proof, verify and settle | `profullstack/x402-gateway`, CoinPay | `ippay` pass purchase reuses it unchanged | | CloudEvents 1.0 + Standard Webhooks signing | `profullstack/autoblog` | Every OpenSwarm event uses the same envelope and headers | | MTP/1 post-quantum transport, name pins | `profullstack/moshpit-transport`, `moshpit-proxy` | Optional tunnel for native peer links; `ipname` pin kind | diff --git a/docs/openswarm/cli.md b/docs/openswarm/cli.md index b145352..3e01f68 100644 --- a/docs/openswarm/cli.md +++ b/docs/openswarm/cli.md @@ -130,6 +130,44 @@ ip node hello # diagnostic: handshake and p A c0mpute worker embeds the same library; `c0mpute worker start --openswarm` is the daemon form and `ip` is the operator's tool. +### 2.10 Seed and stream markets + +``` +ip seed attest ( | | ) --basis own|licensed|open-license|public-domain|personal + [--license ] [--notice ] [--description ] [--public | --private] +ip seed offer ( | | --feed ) --hub --days --seeders [,] + [--price ] [--proof-hours ] [--tracker ]... +ip seed offers [--hub ] [--public | --private] [--basis ] [--min-price ] [--max-size ] +ip seed take --hub # take a lease, fetch, seed until it ends +ip seed leases [--hub ] [--status proven|fetching|lapsed|ended] +ip seed status +ip seed void # requester: void and refund the unearned budget +ip seed notice --kind rights|illegal|personal-data|other --statement +ip team create --hub [--scope |--publisher ]... +ip team invite --to [--role admin|member|readonly] [--expires ] +ip team accept +ip team remove [--no-rotate] +ip team grant --file # a member fetching their sealed grant +ip team audit [--since