github.com/lazyledger/lazyledger-core@v0.35.0-dev.0.20210613111200-4c651f053571/CHANGELOG.md (about)

     1  # Changelog
     2  
     3  <<<<<<< HEAD
     4  ## v0.34.0-rc5
     5  
     6  *October 13, 2020*
     7  
     8  
     9  Friendly reminder, we have a [bug bounty program](https://hackerone.com/tendermint).
    10  
    11  ### BREAKING CHANGES
    12  
    13  - CLI/RPC/Config
    14  
    15  - Apps
    16      - [ABCI] \#5447 Remove `SetOption` method from `ABCI.Client` interface
    17  
    18  - P2P Protocol
    19  
    20  - Go API
    21      - [evidence] [\#5499](https://github.com/tendermint/tendermint/pull/5449) `MaxNum` evidence consensus parameter has been changed to `MaxBytes` (@cmwaters)
    22  
    23  - Blockchain Protocol
    24  
    25  ### FEATURES
    26  
    27  ### IMPROVEMENTS
    28  
    29  - [privval] \#5434 `NewSignerDialerEndpoint` can now be given `SignerServiceEndpointOption` (@erikgrinaker)
    30  
    31  - [config] \#5433 `statesync.rpc_servers` is now properly set when writing the configuration file (@erikgrinaker)
    32  
    33  ### BUG FIXES
    34  
    35  - [privval] \#5441 Fix faulty ping message encoding causing nil message errors in logs (@erikgrinaker)
    36  
    37  ## v0.34.0-rc4
    38  =======
    39  ## v0.34.0
    40  >>>>>>> 1547a7e6c12539bfe7d7ba00f9637a455c227b21
    41  
    42  *November 19, 2020*
    43  
    44  <<<<<<< HEAD
    45  Friendly reminder, we have a [bug bounty program](https://hackerone.com/tendermint).
    46  
    47  ### BREAKING CHANGES
    48  
    49  - CLI/RPC/Config
    50      - [config] [\#5315](https://github.com/tendermint/tendermint/issues/5315) Rename `prof_laddr` to `pprof_laddr` and move it to `rpc` section (@melekes)
    51      - [rpc] [\#5315](https://github.com/tendermint/tendermint/issues/5315) Remove `/unsafe_start_cpu_profiler`, `/unsafe_stop_cpu_profiler` and `/unsafe_write_heap_profile`. Please use pprof functionality instead (@melekes)
    52      - [rpc/client, rpc/jsonrpc/client] [\#5347](https://github.com/tendermint/tendermint/issues/5347) All client methods now accept `context.Context` as 1st param (@melekes)
    53  
    54  - Apps
    55      - [abci] [\#5324](https://github.com/tendermint/tendermint/pull/5324) abci evidence type is an enum with two types of possible evidence (@cmwaters)
    56  
    57  - P2P Protocol
    58      - [mempool] [\#5321](https://github.com/tendermint/tendermint/issues/5321) Batch transactions when broadcasting them to peers (@melekes) `MaxBatchBytes` new config setting defines the max size of one batch.
    59  
    60  - Go API
    61      - [evidence] [\#5317](https://github.com/tendermint/tendermint/issues/5317) Remove ConflictingHeaders evidence type & CompositeEvidence Interface. (@marbar3778)
    62      - [evidence] [\#5318](https://github.com/tendermint/tendermint/issues/5318) Remove LunaticValidator evidence type. (@marbar3778)
    63      - [evidence] [\#5319](https://github.com/tendermint/tendermint/issues/5319) Remove Amnesia & potentialAmnesia evidence types and removed POLC. (@marbar3778)
    64      - [evidence] [\#5361](https://github.com/tendermint/tendermint/pull/5361) Add LightClientAttackEvidence and change evidence interface (@cmwaters)
    65      - [params] [\#5319](https://github.com/tendermint/tendermint/issues/5319) Remove `ProofofTrialPeriod` from evidence params (@marbar3778)
    66      - [light] [\#5347](https://github.com/tendermint/tendermint/issues/5347) `NewClient`, `NewHTTPClient`, `VerifyHeader` and `VerifyLightBlockAtHeight` now accept `context.Context` as 1st param (@melekes)
    67      - [state] [\#5348](https://github.com/tendermint/tendermint/issues/5348) Define an Interface for the state store. (@marbar3778)
    68  
    69  ### FEATURES
    70  
    71  - [privval] [\#5239](https://github.com/tendermint/tendermint/issues/5239) Add `chainID` to requests from client. (@marbar3778)
    72  - [config] [\#5147](https://github.com/tendermint/tendermint/issues/5147) Add `--consensus.double_sign_check_height` flag and `DoubleSignCheckHeight` config variable. See [ADR-51](https://github.com/tendermint/tendermint/blob/master/docs/architecture/adr-051-double-signing-risk-reduction.md)
    73  - [light] [\#5298](https://github.com/tendermint/tendermint/pull/5298) Morph validator set and signed header into light block (@cmwaters)
    74  - [evidence] [\#5361](https://github.com/tendermint/tendermint/pull/5361) Add LightClientAttackEvidence and refactor evidence lifecycle (@cmwaters)
    75  
    76  ### IMPROVEMENTS
    77  
    78  - [blockchain] [\#5278](https://github.com/tendermint/tendermint/issues/5278) Verify only +2/3 of the signatures in a block when fast syncing. (@marbar3778)
    79  - [rpc] [\#5293](https://github.com/tendermint/tendermint/issues/5293) `/dial_peers` has added `private` and `unconditional` as parameters. (@marbar3778)
    80  - [types] [\#5340](https://github.com/tendermint/tendermint/issues/5340) Add check in `Header.ValidateBasic()` for block protocol version (@marbar3778)
    81  - [statesync] [\#5399](https://github.com/tendermint/tendermint/issues/5399) Add `discovery_time` configuration setting, and reduce default to 15s. (@erikgrinaker)
    82  
    83  ### BUG FIXES
    84  
    85  - [blockchain] [\#5249](https://github.com/tendermint/tendermint/issues/5249) Fix fast sync halt with initial height > 1 (@erikgrinaker)
    86  - [statesync] [\#5302](https://github.com/tendermint/tendermint/issues/5302) Fix genesis state propagation to state sync routine (@erikgrinaker)
    87  - [statesync] [\#5320](https://github.com/tendermint/tendermint/issues/5320) Broadcast snapshot request to all pre-connected peers on start (@erikgrinaker)
    88  - [consensus] [\#5329](https://github.com/tendermint/tendermint/issues/5329) Fix wrong proposer schedule for validators returned by `InitChain` (@erikgrinaker)
    89  - [store] [\#5382](https://github.com/tendermint/tendermint/issues/5382) Fix race conditions when loading/saving/pruning blocks (@erikgrinaker)
    90  - [light] [\#5307](https://github.com/tendermint/tendermint/pull/5307) Persist correct proposer priority in light client validator sets (@cmwaters)
    91  - [docker] [\#5385](https://github.com/tendermint/tendermint/issues/5385) Fix incorrect `time_iota_ms` default setting causing block timestamp drift (@erikgrinaker)
    92  - [abci] [\#5395](https://github.com/tendermint/tendermint/issues/5395) Fix socket client error for state sync responses (@erikgrinaker)
    93  
    94  
    95  ## v0.34.0-rc3
    96  
    97  *August 13, 2020*
    98  
    99  Special thanks to external contributors on this release: @SadPencil
   100  
   101  Friendly reminder, we have a [bug bounty program](https://hackerone.com/tendermint).
   102  
   103  ### BREAKING CHANGES:
   104  
   105  - Blockchain Protocol
   106      - [\#5193](https://github.com/tendermint/tendermint/pull/5193) Header hashes are no longer empty for empty inputs, notably `DataHash`, `EvidenceHash`, and `LastResultsHash` (@erikgrinaker)
   107  
   108  - Go API
   109      - [evidence] [\#5181](https://github.com/tendermint/tendermint/pull/5181) Phantom validator evidence was removed (@cmwaters)
   110      - [merkle] [\#5193](https://github.com/tendermint/tendermint/pull/5193) `HashFromByteSlices` and `ProofsFromByteSlices` now return a hash for empty inputs, following RFC6962 (@erikgrinaker)
   111      - [crypto] [\#5214](https://github.com/tendermint/tendermint/issues/5214) Change `GenPrivKeySecp256k1` to `GenPrivKeyFromSecret` to be consistent with other keys (@marbar3778)
   112      - [state] [\#5191](https://github.com/tendermint/tendermint/pull/5191) Add `State.InitialHeight` field to record initial block height, must be `1` (not `0`) to start from 1 (@erikgrinaker)
   113      - [state] [\#5231](https://github.com/tendermint/tendermint/issues/5231) `LoadStateFromDBOrGenesisFile()` and `LoadStateFromDBOrGenesisDoc()` no longer saves the state in the database if not found, the genesis state is simply returned (@erikgrinaker)
   114      - [crypto] [\#5236](https://github.com/tendermint/tendermint/issues/5236) `VerifyBytes` is now `VerifySignature` on the `crypto.PubKey` interface (@marbar3778)
   115  
   116  ### FEATURES:
   117  
   118  - [abci] [\#5174](https://github.com/tendermint/tendermint/pull/5174) Add amnesia evidence and remove mock and potential amnesia evidence from abci (@cmwaters)
   119  - [abci] [\#5191](https://github.com/tendermint/tendermint/pull/5191) Add `InitChain.InitialHeight` field giving the initial block height (@erikgrinaker)
   120  - [abci] [\#5227](https://github.com/tendermint/tendermint/pull/5227) Add `ResponseInitChain.app_hash` which is recorded in genesis block (@erikgrinaker)
   121  - [genesis] [\#5191](https://github.com/tendermint/tendermint/pull/5191) Add `initial_height` field to specify the initial chain height (defaults to `1`) (@erikgrinaker)
   122  - [db] [\#5233](https://github.com/tendermint/tendermint/issues/5233) Add support for `badgerdb` database backend (@erikgrinaker)
   123  
   124  ### IMPROVEMENTS:
   125  
   126  - [evidence] [\#5219](https://github.com/tendermint/tendermint/pull/5219) Change the source of evidence time to block time (@cmwaters)
   127  
   128  ### BUG FIXES:
   129  
   130  - [evidence] [\#5170](https://github.com/tendermint/tendermint/pull/5170) change abci evidence time to the time the infraction happened not the time the evidence was committed on the block (@cmwaters)
   131  - [node] [\#5211](https://github.com/tendermint/tendermint/issues/5211) Don't attempt fast sync when the ABCI application specifies ourself as the only validator via `InitChain` (@erikgrinaker)
   132  - [libs/rand] [\#5215](https://github.com/tendermint/tendermint/pull/5215) Fix out-of-memory error on unexpected argument of Str() (@SadPencil)
   133  
   134  
   135  ## v0.34.0-rc2
   136  
   137  *July 30, 2020*
   138  =======
   139  Holy smokes, this is a big one! For a more reader-friendly overview of the changes in 0.34.0
   140  (and of the changes you need to accommodate as a user), check out [UPGRADING.md](UPGRADING.md).
   141  >>>>>>> 1547a7e6c12539bfe7d7ba00f9637a455c227b21
   142  
   143  Special thanks to external contributors on this release: @james-ray, @fedekunze, @favadi, @alessio,
   144  @joe-bowman, @cuonglm, @SadPencil and @dongsam.
   145  
   146  And as always, friendly reminder, that we have a [bug bounty program](https://hackerone.com/tendermint).
   147  
   148  ### BREAKING CHANGES
   149  
   150  - CLI/RPC/Config
   151  
   152     - [config] [\#5315](https://github.com/tendermint/tendermint/pull/5315) Rename `prof_laddr` to `pprof_laddr` and move it to `rpc` section (@melekes)
   153    - [evidence] [\#4959](https://github.com/tendermint/tendermint/pull/4959) Add JSON tags to `DuplicateVoteEvidence` (@marbar3778)
   154    - [light] [\#4946](https://github.com/tendermint/tendermint/pull/4946) `tendermint lite` command has been renamed to `tendermint light` (@marbar3778)
   155    - [privval] [\#4582](https://github.com/tendermint/tendermint/pull/4582) `round` in private_validator_state.json is no longer JSON string; instead it is a number (@marbar3778)
   156    - [rpc] [\#4792](https://github.com/tendermint/tendermint/pull/4792) `/validators` are now sorted by voting power (@melekes)
   157    - [rpc] [\#4947](https://github.com/tendermint/tendermint/pull/4947) Return an error when `page` pagination param is 0 in `/validators`, `tx_search` (@melekes)
   158    - [rpc] [\#5137](https://github.com/tendermint/tendermint/pull/5137) JSON tags of `gasWanted` and `gasUsed` in `ResponseCheckTx` and `ResponseDeliverTx` have been made snake_case (`gas_wanted` and `gas_used`) (@marbar3778)
   159    - [rpc] [\#5315](https://github.com/tendermint/tendermint/pull/5315) Remove `/unsafe_start_cpu_profiler`, `/unsafe_stop_cpu_profiler` and `/unsafe_write_heap_profile`. Please use pprof functionality instead (@melekes)
   160    - [rpc/client, rpc/jsonrpc/client] [\#5347](https://github.com/tendermint/tendermint/pull/5347) All client methods now accept `context.Context` as 1st param (@melekes)
   161  
   162  - Apps
   163  
   164    - [abci] [\#4704](https://github.com/tendermint/tendermint/pull/4704) Add ABCI methods `ListSnapshots`, `LoadSnapshotChunk`, `OfferSnapshot`, and `ApplySnapshotChunk` for state sync snapshots. `ABCIVersion` bumped to 0.17.0. (@erikgrinaker)
   165    - [abci] [\#4989](https://github.com/tendermint/tendermint/pull/4989) `Proof` within `ResponseQuery` has been renamed to `ProofOps`  (@marbar3778)
   166    - [abci] [\#5096](https://github.com/tendermint/tendermint/pull/5096) `CheckTxType` Protobuf enum names are now uppercase, to follow Protobuf style guide (@erikgrinaker)
   167    - [abci] [\#5324](https://github.com/tendermint/tendermint/pull/5324) ABCI evidence type is now an enum with two types of possible evidence (@cmwaters)
   168  
   169  - P2P Protocol
   170  
   171    - [blockchain] [\#4637](https://github.com/tendermint/tendermint/pull/4637) Migrate blockchain reactor(s) to Protobuf encoding (@marbar3778)
   172    - [evidence] [\#4949](https://github.com/tendermint/tendermint/pull/4949) Migrate evidence reactor to Protobuf encoding (@marbar3778)
   173    - [mempool] [\#4940](https://github.com/tendermint/tendermint/pull/4940) Migrate mempool from to Protobuf encoding (@marbar3778)
   174    - [mempool] [\#5321](https://github.com/tendermint/tendermint/pull/5321) Batch transactions when broadcasting them to peers (@melekes) 
   175       - `MaxBatchBytes` new config setting defines the max size of one batch.
   176    - [p2p/pex] [\#4973](https://github.com/tendermint/tendermint/pull/4973) Migrate `p2p/pex` reactor to Protobuf encoding (@marbar3778)
   177    - [statesync] [\#4943](https://github.com/tendermint/tendermint/pull/4943) Migrate state sync reactor to Protobuf encoding (@marbar3778)
   178  
   179  - Blockchain Protocol
   180  
   181    - [evidence] [\#4725](https://github.com/tendermint/tendermint/pull/4725) Remove `Pubkey` from `DuplicateVoteEvidence` (@marbar3778) 
   182    - [evidence] [\#5499](https://github.com/tendermint/tendermint/pull/5449) Cap evidence to a maximum number of bytes (supercedes [\#4780](https://github.com/tendermint/tendermint/pull/4780)) (@cmwaters)
   183    - [merkle] [\#5193](https://github.com/tendermint/tendermint/pull/5193) Header hashes are no longer empty for empty inputs, notably `DataHash`, `EvidenceHash`, and `LastResultsHash` (@erikgrinaker)
   184    - [state] [\#4845](https://github.com/tendermint/tendermint/pull/4845) Include `GasWanted` and `GasUsed` into `LastResultsHash` (@melekes)
   185    - [types] [\#4792](https://github.com/tendermint/tendermint/pull/4792) Sort validators by voting power to enable faster commit verification (@melekes)
   186  
   187  - On-disk serialization
   188  
   189    - [state] [\#4679](https://github.com/tendermint/tendermint/pull/4679) Migrate state module to Protobuf encoding (@marbar3778)
   190      - `BlockStoreStateJSON` is now `BlockStoreState` and is encoded as binary in the database
   191    - [store] [\#4778](https://github.com/tendermint/tendermint/pull/4778) Migrate store module to Protobuf encoding (@marbar3778)
   192  
   193  - Light client, private validator
   194  
   195    - [light] [\#4964](https://github.com/tendermint/tendermint/pull/4964) Migrate light module migration to Protobuf encoding (@marbar3778)
   196    - [privval] [\#4985](https://github.com/tendermint/tendermint/pull/4985) Migrate `privval` module to Protobuf encoding (@marbar3778)
   197  
   198  - Go API
   199  
   200    - [consensus] [\#4582](https://github.com/tendermint/tendermint/pull/4582) RoundState: `Round`, `LockedRound` & `CommitRound` are now `int32` (@marbar3778)
   201    - [consensus] [\#4582](https://github.com/tendermint/tendermint/pull/4582) HeightVoteSet: `round` is now `int32` (@marbar3778)
   202    - [crypto] [\#4721](https://github.com/tendermint/tendermint/pull/4721) Remove `SimpleHashFromMap()` and `SimpleProofsFromMap()` (@erikgrinaker)
   203    - [crypto] [\#4940](https://github.com/tendermint/tendermint/pull/4940) All keys have become `[]byte` instead of `[<size>]byte`. The byte method no longer returns the marshaled value but just the `[]byte` form of the data. (@marbar3778)
   204    - [crypto] [\#4988](https://github.com/tendermint/tendermint/pull/4988) Removal of key type multisig (@marbar3778)
   205      - The key has been moved to the [Cosmos-SDK](https://github.com/cosmos/cosmos-sdk/blob/master/crypto/types/multisig/multisignature.go)
   206    - [crypto] [\#4989](https://github.com/tendermint/tendermint/pull/4989) Remove `Simple` prefixes from `SimpleProof`, `SimpleValueOp` & `SimpleProofNode`. (@marbar3778)
   207      - `merkle.Proof` has been renamed to `ProofOps`.
   208      - Protobuf messages `Proof` & `ProofOp` has been moved to `proto/crypto/merkle`
   209      - `SimpleHashFromByteSlices` has been renamed to `HashFromByteSlices`
   210      - `SimpleHashFromByteSlicesIterative` has been renamed to `HashFromByteSlicesIterative`
   211      - `SimpleProofsFromByteSlices` has been renamed to `ProofsFromByteSlices`
   212    - [crypto] [\#4941](https://github.com/tendermint/tendermint/pull/4941) Remove suffixes from all keys. (@marbar3778)
   213      - ed25519: type `PrivKeyEd25519` is now `PrivKey`
   214      - ed25519: type `PubKeyEd25519` is now `PubKey`
   215      - secp256k1: type`PrivKeySecp256k1` is now `PrivKey`
   216      - secp256k1: type`PubKeySecp256k1` is now `PubKey`
   217      - sr25519: type `PrivKeySr25519` is now `PrivKey`
   218      - sr25519: type `PubKeySr25519` is now `PubKey`
   219    - [crypto] [\#5214](https://github.com/tendermint/tendermint/pull/5214) Change `GenPrivKeySecp256k1` to `GenPrivKeyFromSecret` to be consistent with other keys (@marbar3778)
   220    - [crypto] [\#5236](https://github.com/tendermint/tendermint/pull/5236) `VerifyBytes` is now `VerifySignature` on the `crypto.PubKey` interface (@marbar3778)
   221    - [evidence] [\#5361](https://github.com/tendermint/tendermint/pull/5361) Add LightClientAttackEvidence and change evidence interface (@cmwaters)
   222    - [libs] [\#4831](https://github.com/tendermint/tendermint/pull/4831) Remove `Bech32` pkg from Tendermint. This pkg now lives in the [cosmos-sdk](https://github.com/cosmos/cosmos-sdk/tree/4173ea5ebad906dd9b45325bed69b9c655504867/types/bech32) (@marbar3778)
   223    - [light] [\#4946](https://github.com/tendermint/tendermint/pull/4946) Rename `lite2` pkg to `light`. Remove `lite` implementation. (@marbar3778)
   224    - [light] [\#5347](https://github.com/tendermint/tendermint/pull/5347) `NewClient`, `NewHTTPClient`, `VerifyHeader` and `VerifyLightBlockAtHeight` now accept `context.Context` as 1st param (@melekes)
   225    - [merkle] [\#5193](https://github.com/tendermint/tendermint/pull/5193) `HashFromByteSlices` and `ProofsFromByteSlices` now return a hash for empty inputs, following RFC6962 (@erikgrinaker)
   226    - [proto] [\#5025](https://github.com/tendermint/tendermint/pull/5025) All proto files have been moved to `/proto` directory. (@marbar3778)
   227      - Using the recommended the file layout from buf, [see here for more info](https://buf.build/docs/lint-checkers#file_layout)
   228    - [rpc/client] [\#4947](https://github.com/tendermint/tendermint/pull/4947) `Validators`, `TxSearch` `page`/`per_page` params become pointers (@melekes)
   229      - `UnconfirmedTxs` `limit` param is a pointer
   230    - [rpc/jsonrpc/server] [\#5141](https://github.com/tendermint/tendermint/pull/5141) Remove `WriteRPCResponseArrayHTTP` (use `WriteRPCResponseHTTP` instead) (@melekes)
   231    - [state] [\#4679](https://github.com/tendermint/tendermint/pull/4679) `TxResult` is a Protobuf type defined in `abci` types directory (@marbar3778)
   232    - [state] [\#5191](https://github.com/tendermint/tendermint/pull/5191) Add `State.InitialHeight` field to record initial block height, must be `1` (not `0`) to start from 1 (@erikgrinaker)
   233    - [state] [\#5231](https://github.com/tendermint/tendermint/pull/5231) `LoadStateFromDBOrGenesisFile()` and `LoadStateFromDBOrGenesisDoc()` no longer saves the state in the database if not found, the genesis state is simply returned (@erikgrinaker)
   234    - [state] [\#5348](https://github.com/tendermint/tendermint/pull/5348) Define an Interface for the state store. (@marbar3778)
   235    - [types] [\#4939](https://github.com/tendermint/tendermint/pull/4939)  `SignedMsgType` has moved to a Protobuf enum types (@marbar3778)
   236    - [types] [\#4962](https://github.com/tendermint/tendermint/pull/4962) `ConsensusParams`, `BlockParams`, `EvidenceParams`, `ValidatorParams` & `HashedParams` are now Protobuf types (@marbar3778)
   237    - [types] [\#4852](https://github.com/tendermint/tendermint/pull/4852) Vote & Proposal `SignBytes` is now func `VoteSignBytes` & `ProposalSignBytes` (@marbar3778)
   238    - [types] [\#4798](https://github.com/tendermint/tendermint/pull/4798) Simplify `VerifyCommitTrusting` func + remove extra validation (@melekes)
   239    - [types] [\#4845](https://github.com/tendermint/tendermint/pull/4845) Remove `ABCIResult` (@melekes)
   240    - [types] [\#5029](https://github.com/tendermint/tendermint/pull/5029) Rename all values from `PartsHeader` to `PartSetHeader` to have consistency (@marbar3778) 
   241    - [types] [\#4939](https://github.com/tendermint/tendermint/pull/4939) `Total` in `Parts` & `PartSetHeader` has been changed from a `int` to a `uint32` (@marbar3778)
   242    - [types] [\#4939](https://github.com/tendermint/tendermint/pull/4939) Vote: `ValidatorIndex` & `Round` are now `int32` (@marbar3778)
   243    - [types] [\#4939](https://github.com/tendermint/tendermint/pull/4939) Proposal: `POLRound` & `Round` are now `int32` (@marbar3778)
   244    - [types] [\#4939](https://github.com/tendermint/tendermint/pull/4939) Block: `Round` is now `int32` (@marbar3778)
   245  
   246  ### FEATURES
   247  
   248  - [abci] [\#5031](https://github.com/tendermint/tendermint/pull/5031) Add `AppVersion` to consensus parameters (@james-ray)
   249    - This makes it possible to update your ABCI application version via `EndBlock` response
   250  - [abci] [\#5174](https://github.com/tendermint/tendermint/pull/5174) Remove `MockEvidence` in favor of testing with actual evidence types (`DuplicateVoteEvidence` & `LightClientAttackEvidence`) (@cmwaters)
   251  - [abci] [\#5191](https://github.com/tendermint/tendermint/pull/5191) Add `InitChain.InitialHeight` field giving the initial block height (@erikgrinaker)
   252  - [abci] [\#5227](https://github.com/tendermint/tendermint/pull/5227) Add `ResponseInitChain.app_hash` which is recorded in genesis block (@erikgrinaker)
   253  - [config] [\#5147](https://github.com/tendermint/tendermint/pull/5147) Add `--consensus.double_sign_check_height` flag and `DoubleSignCheckHeight` config variable. See [ADR-51](https://github.com/tendermint/tendermint/blob/master/docs/architecture/adr-051-double-signing-risk-reduction.md) (@dongsam)
   254  - [db] [\#5233](https://github.com/tendermint/tendermint/pull/5233) Add support for `badgerdb` database backend (@erikgrinaker)
   255  - [evidence] [\#4532](https://github.com/tendermint/tendermint/pull/4532) Handle evidence from light clients (@melekes)
   256  - [evidence] [#4821](https://github.com/tendermint/tendermint/pull/4821) Amnesia (light client attack) evidence can be detected, verified and committed (@cmwaters)
   257  - [genesis] [\#5191](https://github.com/tendermint/tendermint/pull/5191) Add `initial_height` field to specify the initial chain height (defaults to `1`) (@erikgrinaker)
   258  - [libs/math] [\#5665](https://github.com/tendermint/tendermint/pull/5665) Make fractions unsigned integers (uint64) (@cmwaters)
   259  - [light] [\#5298](https://github.com/tendermint/tendermint/pull/5298) Morph validator set and signed header into light block (@cmwaters)
   260  - [p2p] [\#4981](https://github.com/tendermint/tendermint/pull/4981) Expose `SaveAs` func on NodeKey (@melekes)
   261  - [privval] [\#5239](https://github.com/tendermint/tendermint/pull/5239) Add `chainID` to requests from client. (@marbar3778)
   262  - [rpc] [\#4532](https://github.com/tendermint/tendermint/pull/4923) Support `BlockByHash` query (@fedekunze)
   263  - [rpc] [\#4979](https://github.com/tendermint/tendermint/pull/4979) Support EXISTS operator in `/tx_search` query (@melekes)
   264  - [rpc] [\#5017](https://github.com/tendermint/tendermint/pull/5017) Add `/check_tx` endpoint to check transactions without executing them or adding them to the mempool (@melekes)
   265  - [rpc] [\#5108](https://github.com/tendermint/tendermint/pull/5108) Subscribe using the websocket for new evidence events (@cmwaters)
   266  - [statesync] Add state sync support, where a new node can be rapidly bootstrapped by fetching state snapshots from peers instead of replaying blocks. See the `[statesync]` config section.
   267  - [evidence] [\#5361](https://github.com/tendermint/tendermint/pull/5361) Add LightClientAttackEvidence and refactor evidence lifecycle - for more information see [ADR-059](https://github.com/tendermint/tendermint/blob/master/docs/architecture/adr-059-evidence-composition-and-lifecycle.md) (@cmwaters)
   268  
   269  ### IMPROVEMENTS
   270  
   271  - [blockchain] [\#5278](https://github.com/tendermint/tendermint/pull/5278) Verify only +2/3 of the signatures in a block when fast syncing. (@marbar3778)
   272  - [consensus] [\#4578](https://github.com/tendermint/tendermint/pull/4578) Attempt to repair the consensus WAL file (`data/cs.wal/wal`) automatically in case of corruption (@alessio)
   273    - The original WAL file will be backed up to `data/cs.wal/wal.CORRUPTED`.
   274  - [consensus] [\#5143](https://github.com/tendermint/tendermint/pull/5143) Only call `privValidator.GetPubKey` once per block (@melekes)
   275  - [evidence] [\#4722](https://github.com/tendermint/tendermint/pull/4722) Consolidate evidence store and pool types to improve evidence DB (@cmwaters)
   276  - [evidence] [\#4839](https://github.com/tendermint/tendermint/pull/4839) Reject duplicate evidence from being proposed (@cmwaters)
   277  - [evidence] [\#5219](https://github.com/tendermint/tendermint/pull/5219) Change the source of evidence time to block time (@cmwaters)
   278  - [libs] [\#5126](https://github.com/tendermint/tendermint/pull/5126) Add a sync package which wraps sync.(RW)Mutex & deadlock.(RW)Mutex and use a build flag (deadlock) in order to enable deadlock checking (@marbar3778) 
   279  - [light] [\#4935](https://github.com/tendermint/tendermint/pull/4935) Fetch and compare a new header with witnesses in parallel (@melekes)
   280  - [light] [\#4929](https://github.com/tendermint/tendermint/pull/4929) Compare header with witnesses only when doing bisection (@melekes)
   281  - [light] [\#4916](https://github.com/tendermint/tendermint/pull/4916) Validate basic for inbound validator sets and headers before further processing them (@cmwaters)
   282  - [mempool] Add RemoveTxByKey() exported function for custom mempool cleaning (@p4u)
   283  - [p2p/conn] [\#4795](https://github.com/tendermint/tendermint/pull/4795) Return err on `signChallenge()` instead of panic
   284  - [privval] [\#5437](https://github.com/tendermint/tendermint/pull/5437) `NewSignerDialerEndpoint` can now be given `SignerServiceEndpointOption` (@erikgrinaker)
   285  - [rpc] [\#4968](https://github.com/tendermint/tendermint/pull/4968) JSON encoding is now handled by `libs/json`, not Amino (@erikgrinaker)
   286  - [rpc] [\#5293](https://github.com/tendermint/tendermint/pull/5293) `/dial_peers` has added `private` and `unconditional` as parameters. (@marbar3778)
   287  - [state] [\#4781](https://github.com/tendermint/tendermint/pull/4781) Export `InitStateVersion` for the initial state version (@erikgrinaker)
   288  - [txindex] [\#4466](https://github.com/tendermint/tendermint/pull/4466) Allow to index an event at runtime (@favadi)
   289    - `abci.EventAttribute` replaces `KV.Pair`
   290  - [types] [\#4905](https://github.com/tendermint/tendermint/pull/4905) Add `ValidateBasic` to validator and validator set (@cmwaters)
   291  - [types] [\#5340](https://github.com/tendermint/tendermint/pull/5340) Add check in `Header.ValidateBasic()` for block protocol version (@marbar3778)
   292  - [types] [\#5490](https://github.com/tendermint/tendermint/pull/5490) Use `Commit` and `CommitSig` max sizes instead of vote max size to calculate the maximum block size. (@cmwaters)
   293  
   294  
   295  ### BUG FIXES
   296  
   297  - [abci/grpc] [\#5520](https://github.com/tendermint/tendermint/pull/5520) Return async responses in order, to avoid mempool panics. (@erikgrinaker)
   298  - [blockchain/v2] [\#4971](https://github.com/tendermint/tendermint/pull/4971) Correctly set block store base in status responses (@erikgrinaker)
   299  - [blockchain/v2] [\#5499](https://github.com/tendermint/tendermint/pull/5499) Fix "duplicate block enqueued by processor" panic (@melekes)
   300  - [blockchain/v2] [\#5530](https://github.com/tendermint/tendermint/pull/5530) Fix out of order block processing panic (@melekes)
   301  - [blockchain/v2] [\#5553](https://github.com/tendermint/tendermint/pull/5553) Make the removal of an already removed peer a noop (@melekes)
   302  - [consensus] [\#4895](https://github.com/tendermint/tendermint/pull/4895) Cache the address of the validator to reduce querying a remote KMS (@joe-bowman)
   303  - [consensus] [\#4970](https://github.com/tendermint/tendermint/pull/4970) Don't allow `LastCommitRound` to be negative (@cuonglm)
   304  - [consensus] [\#5329](https://github.com/tendermint/tendermint/pull/5329) Fix wrong proposer schedule for validators returned by `InitChain` (@erikgrinaker)
   305  - [docker] [\#5385](https://github.com/tendermint/tendermint/pull/5385) Fix incorrect `time_iota_ms` default setting causing block timestamp drift (@erikgrinaker)
   306  - [evidence] [\#5170](https://github.com/tendermint/tendermint/pull/5170) Change ABCI evidence time to the time the infraction happened not the time the evidence was committed on the block (@cmwaters)
   307  - [evidence] [\#5610](https://github.com/tendermint/tendermint/pull/5610) Make it possible for ABCI evidence to be formed from Tendermint evidence (@cmwaters)
   308  - [libs/rand] [\#5215](https://github.com/tendermint/tendermint/pull/5215) Fix out-of-memory error on unexpected argument of Str() (@SadPencil)
   309  - [light] [\#5307](https://github.com/tendermint/tendermint/pull/5307) Persist correct proposer priority in light client validator sets (@cmwaters)
   310  - [p2p] [\#5136](https://github.com/tendermint/tendermint/pull/5136) Fix error for peer with the same ID but different IPs (@valardragon)
   311  - [privval] [\#5638](https://github.com/tendermint/tendermint/pull/5638) Increase read/write timeout to 5s and calculate ping interval based on it (@JoeKash)
   312  - [proxy] [\#5078](https://github.com/tendermint/tendermint/pull/5078) Force Tendermint to exit when ABCI app crashes  (@melekes)
   313  - [rpc] [\#5660](https://github.com/tendermint/tendermint/pull/5660) Set `application/json` as the `Content-Type` header in RPC responses. (@alexanderbez)
   314  - [store] [\#5382](https://github.com/tendermint/tendermint/pull/5382) Fix race conditions when loading/saving/pruning blocks (@erikgrinaker)
   315  
   316  ## v0.33.8
   317  
   318  *August 11, 2020*
   319  
   320  ### Go security update
   321  
   322  Go reported a security vulnerability that affected the `encoding/binary` package. The most recent binary for tendermint is using 1.14.6, for this
   323  reason the Tendermint engineering team has opted to conduct a release to aid users in using the correct version of Go. Read more about the security issue [here](https://github.com/golang/go/issues/40618).
   324  
   325  
   326  ## v0.33.7
   327  
   328   *August 4, 2020*
   329  
   330   ### BUG FIXES:
   331  
   332   - [go] Build release binary using Go 1.14.4, to avoid halt caused by Go 1.14.1 (https://github.com/golang/go/issues/38223)
   333   - [privval] [\#5140](https://github.com/tendermint/tendermint/pull/5140) `RemoteSignerError` from remote signers are no longer retried (@melekes)
   334  
   335  
   336  ## v0.33.6
   337  
   338  *July 2, 2020*
   339  
   340  This security release fixes:
   341  
   342  ### Denial of service
   343  
   344  Tendermint 0.33.0 and above allow block proposers to include signatures for the
   345  wrong block. This may happen naturally if you start a network, have it run for
   346  some time and restart it **without changing the chainID**. (It is a
   347  [misconfiguration](https://docs.tendermint.com/master/tendermint-core/using-tendermint.html)
   348  to reuse chainIDs.) Correct block proposers will accidentally include signatures
   349  for the wrong block if they see these signatures, and then commits won't validate,
   350  making all proposed blocks invalid. A malicious validator (even with a minimal
   351  amount of stake) can use this vulnerability to completely halt the network.
   352  
   353  Tendermint 0.33.6 checks all the signatures are for the block with +2/3
   354  majority before creating a commit.
   355  
   356  ### False Witness
   357  
   358  Tendermint 0.33.1 and above are no longer fully verifying commit signatures
   359  during block execution - they stop after +2/3. This means proposers can propose
   360  blocks that contain valid +2/3 signatures and then the rest of the signatures
   361  can be whatever they want. They can claim that all the other validators signed
   362  just by including a CommitSig with arbitrary signature data. While this doesn't
   363  seem to impact safety of Tendermint per se, it means that Commits may contain a
   364  lot of invalid data.
   365  
   366  _This was already true of blocks, since they could include invalid txs filled
   367  with garbage, but in that case the application knew that they are invalid and
   368  could punish the proposer. But since applications didn't--and don't--
   369  verify commit signatures directly (they trust Tendermint to do that),
   370  they won't be able to detect it._
   371  
   372  This can impact incentivization logic in the application that depends on the
   373  LastCommitInfo sent in BeginBlock, which includes which validators signed. For
   374  instance, Gaia incentivizes proposers with a bonus for including more than +2/3
   375  of the signatures. But a proposer can now claim that bonus just by including
   376  arbitrary data for the final -1/3 of validators without actually waiting for
   377  their signatures. There may be other tricks that can be played because of this.
   378  
   379  Tendermint 0.33.6 verifies all the signatures during block execution.
   380  
   381  _Please note that the light client does not check nil votes and exits as soon
   382  as 2/3+ of the signatures are checked._
   383  
   384  **All clients are recommended to upgrade.**
   385  
   386  Special thanks to @njmurarka at Bluzelle Networks for reporting this.
   387  
   388  Friendly reminder, we have a [bug bounty
   389  program](https://hackerone.com/tendermint).
   390  
   391  ### SECURITY:
   392  
   393  - [consensus] Do not allow signatures for a wrong block in commits (@ebuchman)
   394  - [consensus] Verify all the signatures during block execution (@melekes)
   395  
   396  **Please note that the fix for the False Witness issue renames the `VerifyCommitTrusting`
   397  function to `VerifyCommitLightTrusting`. If you were relying on the light client, you may
   398  need to update your code.**
   399  
   400  ## v0.33.5
   401  
   402  *May 28, 2020*
   403  
   404  Special thanks to external contributors on this release: @tau3,
   405  
   406  Friendly reminder, we have a [bug bounty program](https://hackerone.com/tendermint).
   407  
   408  ### BREAKING CHANGES:
   409  
   410  - Go API
   411  
   412    - [privval] [\#4744](https://github.com/tendermint/tendermint/pull/4744) Remove deprecated `OldFilePV` (@melekes)
   413    - [mempool] [\#4759](https://github.com/tendermint/tendermint/pull/4759) Modify `Mempool#InitWAL` to return an error (@melekes)
   414    - [node] [\#4832](https://github.com/tendermint/tendermint/pull/4832) `ConfigureRPC` returns an error (@melekes)
   415    - [rpc] [\#4836](https://github.com/tendermint/tendermint/pull/4836) Overhaul `lib` folder (@melekes)
   416      Move lib/ folder to jsonrpc/.
   417      Rename:
   418        rpc package -> jsonrpc package
   419        rpcclient package -> client package
   420        rpcserver package -> server package
   421        JSONRPCClient to Client
   422        JSONRPCRequestBatch to RequestBatch
   423        JSONRPCCaller to Caller
   424        StartHTTPServer to Serve
   425        StartHTTPAndTLSServer to ServeTLS
   426        NewURIClient to NewURI
   427        NewJSONRPCClient to New
   428        NewJSONRPCClientWithHTTPClient to NewWithHTTPClient
   429        NewWSClient to NewWS
   430      Unexpose ResponseWriterWrapper
   431      Remove unused http_params.go
   432  
   433  
   434  ### FEATURES:
   435  
   436  - [pex] [\#4439](https://github.com/tendermint/tendermint/pull/4439) Use highwayhash for pex buckets (@tau3)
   437  
   438  ### IMPROVEMENTS:
   439  
   440  - [abci/server] [\#4719](https://github.com/tendermint/tendermint/pull/4719) Print panic & stack trace to STDERR if logger is not set (@melekes)
   441  - [types] [\#4638](https://github.com/tendermint/tendermint/pull/4638) Implement `Header#ValidateBasic` (@alexanderbez)
   442  - [buildsystem] [\#4378](https://github.com/tendermint/tendermint/pull/4738) Replace build_c and install_c with TENDERMINT_BUILD_OPTIONS parsing. The following options are available:
   443    - nostrip: don't strip debugging symbols nor DWARF tables.
   444    - cleveldb: use cleveldb as db backend instead of goleveldb.
   445    - race: pass -race to go build and enable data race detection.
   446  - [mempool] [\#4759](https://github.com/tendermint/tendermint/pull/4759) Allow ReapX and CheckTx functions to run in parallel (@melekes)
   447  - [rpc/core] [\#4844](https://github.com/tendermint/tendermint/pull/4844) Do not lock consensus state in `/validators`, `/consensus_params` and `/status` (@melekes)
   448  
   449  ### BUG FIXES:
   450  
   451  - [blockchain/v2] [\#4761](https://github.com/tendermint/tendermint/pull/4761) Fix excessive CPU usage caused by spinning on closed channels (@erikgrinaker)
   452  - [blockchain/v2] Respect `fast_sync` option (@erikgrinaker)
   453  - [light] [\#4741](https://github.com/tendermint/tendermint/pull/4741) Correctly return  `ErrSignedHeaderNotFound` and `ErrValidatorSetNotFound` on corresponding RPC errors (@erikgrinaker)
   454  - [rpc] [\#4805](https://github.com/tendermint/tendermint/issues/4805) Attempt to handle panics during panic recovery (@erikgrinaker)
   455  - [types] [\#4764](https://github.com/tendermint/tendermint/pull/4764) Return an error if voting power overflows in `VerifyCommitTrusting` (@melekes)
   456  - [privval] [\#4812](https://github.com/tendermint/tendermint/pull/4812) Retry `GetPubKey/SignVote/SignProposal` a few times before returning an error (@melekes)
   457  - [p2p] [\#4847](https://github.com/tendermint/tendermint/pull/4847) Return masked IP (not the actual IP) in addrbook#groupKey (@melekes)
   458  
   459  ## v0.33.4
   460  
   461  - Nodes are no longer guaranteed to contain all blocks up to the latest height. The ABCI app can now control which blocks to retain through the ABCI field `ResponseCommit.retain_height`, all blocks and associated data below this height will be removed.
   462  
   463  *April 21, 2020*
   464  
   465  Special thanks to external contributors on this release: @whylee259, @greg-szabo
   466  
   467  Friendly reminder, we have a [bug bounty program](https://hackerone.com/tendermint).
   468  
   469  ### BREAKING CHANGES:
   470  
   471  - Go API
   472  
   473    - [lite2] [\#4616](https://github.com/tendermint/tendermint/pull/4616) Make `maxClockDrift` an option `Verify/VerifyAdjacent/VerifyNonAdjacent` now accept `maxClockDrift time.Duration` (@melekes).
   474    - [rpc/client] [\#4628](https://github.com/tendermint/tendermint/pull/4628) Split out HTTP and local clients into `http` and `local` packages (@erikgrinaker).
   475  
   476  ### FEATURES:
   477  
   478  - [abci] [\#4588](https://github.com/tendermint/tendermint/issues/4588) Add `ResponseCommit.retain_height` field, which will automatically remove blocks below this height. This bumps the ABCI version to 0.16.2 (@erikgrinaker).
   479  - [cmd] [\#4665](https://github.com/tendermint/tendermint/pull/4665) New `tendermint completion` command to generate Bash/Zsh completion scripts (@alessio).
   480  - [rpc] [\#4588](https://github.com/tendermint/tendermint/issues/4588) Add `/status` response fields for the earliest block available on the node (@erikgrinaker).
   481  - [rpc] [\#4611](https://github.com/tendermint/tendermint/pull/4611) Add `codespace` to `ResultBroadcastTx` (@whylee259).
   482  
   483  ### IMPROVEMENTS:
   484  
   485  - [all] [\#4608](https://github.com/tendermint/tendermint/pull/4608) Give reactors descriptive names when they're initialized (@tessr).
   486  - [blockchain] [\#4588](https://github.com/tendermint/tendermint/issues/4588) Add `Base` to blockchain reactor P2P messages `StatusRequest` and `StatusResponse` (@erikgrinaker).
   487  - [Docker] [\#4569](https://github.com/tendermint/tendermint/issues/4569) Default configuration added to docker image (you can still mount your own config the same way) (@greg-szabo).
   488  - [example/kvstore] [\#4588](https://github.com/tendermint/tendermint/issues/4588) Add `RetainBlocks` option to control block retention (@erikgrinaker).
   489  - [evidence] [\#4632](https://github.com/tendermint/tendermint/pull/4632) Inbound evidence checked if already existing (@cmwaters).
   490  - [lite2] [\#4575](https://github.com/tendermint/tendermint/pull/4575) Use bisection for within-range verification (@cmwaters).
   491  - [lite2] [\#4562](https://github.com/tendermint/tendermint/pull/4562) Cache headers when using bisection (@cmwaters).
   492  - [p2p] [\#4548](https://github.com/tendermint/tendermint/pull/4548) Add ban list to address book (@cmwaters).
   493  - [privval] [\#4534](https://github.com/tendermint/tendermint/issues/4534) Add `error` as a return value on`GetPubKey()` (@marbar3778).
   494  - [p2p] [\#4621](https://github.com/tendermint/tendermint/issues/4621) Ban peers when messages are unsolicited or too frequent (@cmwaters).
   495  - [rpc] [\#4703](https://github.com/tendermint/tendermint/pull/4703) Add `count` and `total` to `/validators` response (@melekes).
   496  - [tools] [\#4615](https://github.com/tendermint/tendermint/issues/4615) Allow developers to use Docker to generate proto stubs, via `make proto-gen-docker` (@erikgrinaker).
   497  
   498  ### BUG FIXES:
   499  
   500  - [rpc] [\#4568](https://github.com/tendermint/tendermint/issues/4568) Fix panic when `Subscribe` is called, but HTTP client is not running. `Subscribe`, `Unsubscribe(All)` methods return an error now (@melekes).
   501  
   502  ## v0.33.3
   503  
   504  *April 6, 2020*
   505  
   506  This security release fixes:
   507  
   508  ### Denial of service 1
   509  
   510  Tendermint 0.33.2 and earlier does not limit P2P connection requests number.
   511  For each p2p connection, Tendermint allocates ~0.5MB. Even though this
   512  memory is garbage collected once the connection is terminated (due to duplicate
   513  IP or reaching a maximum number of inbound peers), temporary memory spikes can
   514  lead to OOM (Out-Of-Memory) exceptions.
   515  
   516  Tendermint 0.33.3 (and 0.32.10) limits the total number of P2P incoming
   517  connection requests to to `p2p.max_num_inbound_peers +
   518  len(p2p.unconditional_peer_ids)`.
   519  
   520  Notes:
   521  
   522  - Tendermint does not rate limit P2P connection requests per IP (an attacker
   523    can saturate all the inbound slots);
   524  - Tendermint does not rate limit HTTP(S) requests. If you expose any RPC
   525    endpoints to the public, please make sure to put in place some protection
   526    (https://www.nginx.com/blog/rate-limiting-nginx/). We may implement this in
   527    the future ([\#1696](https://github.com/tendermint/tendermint/issues/1696)).
   528  
   529  ### Denial of service 2
   530  
   531  Tendermint 0.33.2 and earlier does not reclaim `activeID` of a peer after it's
   532  removed in `Mempool` reactor. This does not happen all the time. It only
   533  happens when a connection fails (for any reason) before the Peer is created and
   534  added to all reactors. `RemovePeer` is therefore called before `AddPeer`, which
   535  leads to always growing memory (`activeIDs` map). The `activeIDs` map has a
   536  maximum size of 65535 and the node will panic if this map reaches the maximum.
   537  An attacker can create a lot of connection attempts (exploiting Denial of
   538  service 1), which ultimately will lead to the node panicking.
   539  
   540  Tendermint 0.33.3 (and 0.32.10) claims `activeID` for a peer in `InitPeer`,
   541  which is executed before `MConnection` is started.
   542  
   543  Notes:
   544  
   545  - `InitPeer` function was added to all reactors to combat a similar issue -
   546    [\#3338](https://github.com/tendermint/tendermint/issues/3338);
   547  - Denial of service 2 is independent of Denial of service 1 and can be executed
   548    without it.
   549  
   550  **All clients are recommended to upgrade**
   551  
   552  Special thanks to [fudongbai](https://hackerone.com/fudongbai) for finding
   553  and reporting this.
   554  
   555  Friendly reminder, we have a [bug bounty
   556  program](https://hackerone.com/tendermint).
   557  
   558  ### SECURITY:
   559  
   560  - [mempool] Reserve IDs in InitPeer instead of AddPeer (@tessr)
   561  - [p2p] Limit the number of incoming connections (@melekes)
   562  
   563  ## v0.33.2
   564  
   565  *March 11, 2020*
   566  
   567  Special thanks to external contributors on this release:
   568  @antho1404, @michaelfig, @gterzian, @tau3, @Shivani912
   569  
   570  Friendly reminder, we have a [bug bounty program](https://hackerone.com/tendermint).
   571  
   572  ### BREAKING CHANGES:
   573  
   574  - CLI/RPC/Config
   575    - [cli] [\#4505](https://github.com/tendermint/tendermint/pull/4505) `tendermint lite` sub-command new syntax (@melekes):
   576      `lite cosmoshub-3 -p 52.57.29.196:26657 -w public-seed-node.cosmoshub.certus.one:26657
   577      --height 962118 --hash 28B97BE9F6DE51AC69F70E0B7BFD7E5C9CD1A595B7DC31AFF27C50D4948`
   578  
   579  - Go API
   580    - [lite2] [\#4535](https://github.com/tendermint/tendermint/pull/4535) Remove `Start/Stop` (@melekes)
   581    - [lite2] [\#4469](https://github.com/tendermint/tendermint/issues/4469) Remove `RemoveNoLongerTrustedHeaders` and `RemoveNoLongerTrustedHeadersPeriod` option (@cmwaters)
   582    - [lite2] [\#4473](https://github.com/tendermint/tendermint/issues/4473) Return height as a 2nd param in `TrustedValidatorSet` (@melekes)
   583    - [lite2] [\#4536](https://github.com/tendermint/tendermint/pull/4536) `Update` returns a signed header (1st param) (@melekes)
   584  
   585  
   586  ### IMPROVEMENTS:
   587  
   588  - [blockchain/v2] [\#4361](https://github.com/tendermint/tendermint/pull/4361) Add reactor (@brapse)
   589  - [cmd] [\#4515](https://github.com/tendermint/tendermint/issues/4515) Change `tendermint debug dump` sub-command archives filename's format (@melekes)
   590  - [consensus] [\#3583](https://github.com/tendermint/tendermint/issues/3583) Reduce `non-deterministic signature` log noise (@tau3)
   591  - [examples/kvstore] [\#4507](https://github.com/tendermint/tendermint/issues/4507) ABCI query now returns the proper height (@erikgrinaker)
   592  - [lite2] [\#4462](https://github.com/tendermint/tendermint/issues/4462) Add `NewHTTPClient` and `NewHTTPClientFromTrustedStore` (@cmwaters)
   593  - [lite2] [\#4329](https://github.com/tendermint/tendermint/issues/4329) modified bisection to loop (@cmwaters)
   594  - [lite2] [\#4385](https://github.com/tendermint/tendermint/issues/4385) Disconnect from bad nodes (@melekes)
   595  - [lite2] [\#4398](https://github.com/tendermint/tendermint/issues/4398) Add `VerifyAdjacent` and `VerifyNonAdjacent` funcs (@cmwaters)
   596  - [lite2] [\#4426](https://github.com/tendermint/tendermint/issues/4426) Don't save intermediate headers (@cmwaters)
   597  - [lite2] [\#4464](https://github.com/tendermint/tendermint/issues/4464) Cross-check first header (@cmwaters)
   598  - [lite2] [\#4470](https://github.com/tendermint/tendermint/issues/4470) Fix inconsistent header-validatorset pairing (@melekes)
   599  - [lite2] [\#4488](https://github.com/tendermint/tendermint/issues/4488) Allow local clock drift -10 sec. (@melekes)
   600  - [p2p] [\#4449](https://github.com/tendermint/tendermint/pull/4449) Use `curve25519.X25519()` instead of `ScalarMult` (@erikgrinaker)
   601  - [types] [\#4417](https://github.com/tendermint/tendermint/issues/4417) **VerifyCommitX() functions should return as soon as +2/3 threshold is reached** (@alessio).
   602  - [libs/kv] [\#4542](https://github.com/tendermint/tendermint/pull/4542) remove unused type KI64Pair (@tessr)
   603  
   604  ### BUG FIXES:
   605  
   606  - [cmd] [\#4303](https://github.com/tendermint/tendermint/issues/4303) Show useful error when Tendermint is not initialized (@melekes)
   607  - [cmd] [\#4515](https://github.com/tendermint/tendermint/issues/4515) **Fix `tendermint debug kill` sub-command** (@melekes)
   608  - [rpc] [\#3935](https://github.com/tendermint/tendermint/issues/3935) **Create buffered subscriptions on `/subscribe`** (@melekes)
   609  - [rpc] [\#4375](https://github.com/tendermint/tendermint/issues/4375) Stop searching for txs in `/tx_search` upon client timeout (@gterzian)
   610  - [rpc] [\#4406](https://github.com/tendermint/tendermint/pull/4406) Fix issue with multiple subscriptions on the websocket (@antho1404)
   611  - [rpc] [\#4432](https://github.com/tendermint/tendermint/issues/4432) Fix `/tx_search` pagination with ordered results (@erikgrinaker)
   612  - [rpc] [\#4492](https://github.com/tendermint/tendermint/issues/4492) Keep the original subscription "id" field when new RPCs come in (@michaelfig)
   613  
   614  
   615  ## v0.33.1
   616  
   617  *Feburary 13, 2020*
   618  
   619  Special thanks to external contributors on this release:
   620  @princesinha19
   621  
   622  Friendly reminder, we have a [bug bounty
   623  program](https://hackerone.com/tendermint).
   624  
   625  ### FEATURES:
   626  
   627  - [rpc] [\#3333](https://github.com/tendermint/tendermint/issues/3333) Add `order_by` to `/tx_search` endpoint, allowing to change default ordering from asc to desc (@princesinha19)
   628  
   629  ### IMPROVEMENTS:
   630  
   631  - [proto] [\#4369](https://github.com/tendermint/tendermint/issues/4369) Add [buf](https://buf.build/) for usage with linting and checking if there are breaking changes with the master branch.
   632  - [proto] [\#4369](https://github.com/tendermint/tendermint/issues/4369) Add `make proto-gen` cmd to generate proto stubs outside of GOPATH.
   633  
   634  ### BUG FIXES:
   635  
   636  - [node] [\#4311](https://github.com/tendermint/tendermint/issues/4311) Use `GRPCMaxOpenConnections` when creating the gRPC server, not `MaxOpenConnections`
   637  - [rpc] [\#4319](https://github.com/tendermint/tendermint/issues/4319) Check `BlockMeta` is not nil in `/block` & `/block_by_hash`
   638  
   639  ## v0.33
   640  
   641  Special thanks to external contributors on this release: @mrekucci, @PSalant726, @princesinha19, @greg-szabo, @dongsam, @cuonglm, @jgimeno, @yenkhoon
   642  
   643  Friendly reminder, we have a [bug bounty
   644  program.](https://hackerone.com/tendermint).
   645  
   646  *January 14, 2020*
   647  
   648  This release contains breaking changes to the `Block#Header`, specifically
   649  `NumTxs` and `TotalTxs` were removed (\#2521). Here's how this change affects
   650  different modules:
   651  
   652  - apps: it breaks the ABCI header field numbering
   653  - state: it breaks the format of `State` on disk
   654  - RPC: all RPC requests which expose the header broke
   655  - Go API: the `Header` broke
   656  - P2P: since blocks go over the wire, technically the P2P protocol broke
   657  
   658  Also, blocks are significantly smaller 🔥 because we got rid of the redundant
   659  information in `Block#LastCommit`. `Commit` now mainly consists of a signature
   660  and a validator address plus a timestamp. Note we may remove the validator
   661  address & timestamp fields in the future (see ADR-25).
   662  
   663  `lite2` package has been added to solve `lite` issues and introduce weak
   664  subjectivity interface. Refer to the [spec](https://github.com/tendermint/spec/blob/master/spec/consensus/light-client.md) for complete details.
   665  `lite` package is now deprecated and will be removed in v0.34 release.
   666  
   667  ### BREAKING CHANGES:
   668  
   669  - CLI/RPC/Config
   670  
   671    - [rpc] [\#3471](https://github.com/tendermint/tendermint/issues/3471) Paginate `/validators` response (default: 30 vals per page)
   672    - [rpc] [\#3188](https://github.com/tendermint/tendermint/issues/3188) Remove `BlockMeta` in `ResultBlock` in favor of `BlockId` for `/block`
   673    - [rpc] `/block_results` response format updated (see RPC docs for details)
   674      ```
   675      {
   676        "jsonrpc": "2.0",
   677        "id": "",
   678        "result": {
   679          "height": "2109",
   680          "txs_results": null,
   681          "begin_block_events": null,
   682          "end_block_events": null,
   683          "validator_updates": null,
   684          "consensus_param_updates": null
   685        }
   686      }
   687      ```
   688    - [rpc] [\#4141](https://github.com/tendermint/tendermint/pull/4141) Remove `#event` suffix from the ID in event responses.
   689      `{"jsonrpc": "2.0", "id": 0, "result": ...}`
   690    - [rpc] [\#4141](https://github.com/tendermint/tendermint/pull/4141) Switch to integer IDs instead of `json-client-XYZ`
   691      ```
   692      id=0 method=/subscribe
   693      id=0 result=...
   694      id=1 method=/abci_query
   695      id=1 result=...
   696      ```
   697      - ID is unique for each request;
   698      - Request.ID is now optional. Notification is a Request without an ID. Previously ID="" or ID=0 were considered as notifications.
   699  
   700    - [config] [\#4046](https://github.com/tendermint/tendermint/issues/4046) Rename tag(s) to CompositeKey & places where tag is still present it was renamed to event or events. Find how a compositeKey is constructed [here](https://github.com/tendermint/tendermint/blob/6d05c531f7efef6f0619155cf10ae8557dd7832f/docs/app-dev/indexing-transactions.md)
   701      - You will have to generate a new config for your Tendermint node(s)
   702    - [genesis] [\#2565](https://github.com/tendermint/tendermint/issues/2565) Add `consensus_params.evidence.max_age_duration`. Rename
   703      `consensus_params.evidence.max_age` to `max_age_num_blocks`.
   704    - [cli] [\#1771](https://github.com/tendermint/tendermint/issues/1771) `tendermint lite` now uses new light client package (`lite2`)
   705      and has 3 more flags: `--trusting-period`, `--trusted-height` and
   706      `--trusted-hash`
   707  
   708  - Apps
   709  
   710    - [tm-bench] Removed tm-bench in favor of [tm-load-test](https://github.com/informalsystems/tm-load-test)
   711  
   712  - Go API
   713  
   714    - [rpc] [\#3953](https://github.com/tendermint/tendermint/issues/3953) Modify NewHTTP, NewXXXClient functions to return an error on invalid remote instead of panicking (@mrekucci)
   715    - [rpc/client] [\#3471](https://github.com/tendermint/tendermint/issues/3471) `Validators` now requires two more args: `page` and `perPage`
   716    - [libs/common] [\#3262](https://github.com/tendermint/tendermint/issues/3262) Make error the last parameter of `Task` (@PSalant726)
   717    - [cs/types] [\#3262](https://github.com/tendermint/tendermint/issues/3262) Rename `GotVoteFromUnwantedRoundError` to `ErrGotVoteFromUnwantedRound` (@PSalant726)
   718    - [libs/common] [\#3862](https://github.com/tendermint/tendermint/issues/3862) Remove `errors.go` from `libs/common`
   719    - [libs/common] [\#4230](https://github.com/tendermint/tendermint/issues/4230) Move `KV` out of common to its own pkg
   720    - [libs/common] [\#4230](https://github.com/tendermint/tendermint/issues/4230) Rename `cmn.KVPair(s)` to `kv.Pair(s)`s
   721    - [libs/common] [\#4232](https://github.com/tendermint/tendermint/issues/4232) Move `Service` & `BaseService` from `libs/common` to `libs/service`
   722    - [libs/common] [\#4232](https://github.com/tendermint/tendermint/issues/4232) Move `common/nil.go` to `types/utils.go` & make the functions private
   723    - [libs/common] [\#4231](https://github.com/tendermint/tendermint/issues/4231) Move random functions from `libs/common` into pkg `rand`
   724    - [libs/common] [\#4237](https://github.com/tendermint/tendermint/issues/4237) Move byte functions from `libs/common` into pkg `bytes`
   725    - [libs/common] [\#4237](https://github.com/tendermint/tendermint/issues/4237) Move throttletimer functions from `libs/common` into pkg `timer`
   726    - [libs/common] [\#4237](https://github.com/tendermint/tendermint/issues/4237) Move tempfile functions from `libs/common` into pkg `tempfile`
   727    - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move os functions from `libs/common` into pkg `os`
   728    - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move net functions from `libs/common` into pkg `net`
   729    - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move mathematical functions and types out of `libs/common` to `math` pkg
   730    - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move string functions out of `libs/common` to `strings` pkg
   731    - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move async functions out of `libs/common` to `async` pkg
   732    - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move bit functions out of `libs/common` to `bits` pkg
   733    - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move cmap functions out of `libs/common` to `cmap` pkg
   734    - [libs/common] [\#4258](https://github.com/tendermint/tendermint/issues/4258) Remove `Rand` from all `rand` pkg functions
   735    - [types] [\#2565](https://github.com/tendermint/tendermint/issues/2565) Remove `MockBadEvidence` & `MockGoodEvidence` in favor of `MockEvidence`
   736  
   737  - Blockchain Protocol
   738  
   739    - [abci] [\#2521](https://github.com/tendermint/tendermint/issues/2521) Remove `TotalTxs` and `NumTxs` from `Header`
   740    - [types] [\#4151](https://github.com/tendermint/tendermint/pull/4151) Enforce ordering of votes in DuplicateVoteEvidence to be lexicographically sorted on BlockID
   741    - [types] [\#1648](https://github.com/tendermint/tendermint/issues/1648) Change `Commit` to consist of just signatures
   742  
   743  - P2P Protocol
   744  
   745    - [p2p] [\#3668](https://github.com/tendermint/tendermint/pull/3668) Make `SecretConnection` non-malleable
   746  
   747  - [proto] [\#3986](https://github.com/tendermint/tendermint/pull/3986) Prefix protobuf types to avoid name conflicts.
   748    - ABCI becomes `tendermint.abci.types` with the new API endpoint `/tendermint.abci.types.ABCIApplication/`
   749    - core_grpc becomes `tendermint.rpc.grpc` with the new API endpoint `/tendermint.rpc.grpc.BroadcastAPI/`
   750    - merkle becomes `tendermint.crypto.merkle`
   751    - libs.common becomes `tendermint.libs.common`
   752    - proto3 becomes `tendermint.types.proto3`
   753  
   754  ### FEATURES:
   755  
   756  - [p2p] [\#4053](https://github.com/tendermint/tendermint/issues/4053) Add `unconditional_peer_ids` and `persistent_peers_max_dial_period` config variables (see ADR-050) (@dongsam)
   757  - [tools] [\#4227](https://github.com/tendermint/tendermint/pull/4227) Implement `tendermint debug kill` and
   758    `tendermint debug dump` commands for Tendermint node debugging functionality. See `--help` in both
   759    commands for further documentation and usage.
   760  - [cli] [\#4234](https://github.com/tendermint/tendermint/issues/4234) Add `--db_backend and --db_dir` flags (@princesinha19)
   761  - [cli] [\#4113](https://github.com/tendermint/tendermint/issues/4113) Add optional `--genesis_hash` flag to check genesis hash upon startup
   762  - [config] [\#3831](https://github.com/tendermint/tendermint/issues/3831) Add support for [RocksDB](https://rocksdb.org/) (@Stumble)
   763  - [rpc] [\#3985](https://github.com/tendermint/tendermint/issues/3985) Add new `/block_by_hash` endpoint, which allows to fetch a block by its hash (@princesinha19)
   764  - [metrics] [\#4263](https://github.com/tendermint/tendermint/issues/4263) Add
   765    - `consensus_validator_power`: track your validators power
   766    - `consensus_validator_last_signed_height`: track at which height the validator last signed
   767    - `consensus_validator_missed_blocks`: total amount of missed blocks for a validator
   768    as gauges in prometheus for validator specific metrics
   769  - [rpc/lib] [\#4248](https://github.com/tendermint/tendermint/issues/4248) RPC client basic authentication support (@greg-szabo)
   770  - [lite2] [\#1771](https://github.com/tendermint/tendermint/issues/1771) Light client with weak subjectivity
   771  
   772  ### IMPROVEMENTS:
   773  
   774  - [rpc] [\#3188](https://github.com/tendermint/tendermint/issues/3188) Added `block_size` to `BlockMeta` this is reflected in `/blockchain`
   775  - [types] [\#2521](https://github.com/tendermint/tendermint/issues/2521) Add `NumTxs` to `BlockMeta` and `EventDataNewBlockHeader`
   776  - [p2p] [\#4185](https://github.com/tendermint/tendermint/pull/4185) Simplify `SecretConnection` handshake with merlin
   777  - [cli] [\#4065](https://github.com/tendermint/tendermint/issues/4065) Add `--consensus.create_empty_blocks_interval` flag (@jgimeno)
   778  - [docs] [\#4065](https://github.com/tendermint/tendermint/issues/4065) Document `--consensus.create_empty_blocks_interval` flag (@jgimeno)
   779  - [crypto] [\#4190](https://github.com/tendermint/tendermint/pull/4190) Added SR25519 signature scheme
   780  - [abci] [\#4177] kvstore: Return `LastBlockHeight` and `LastBlockAppHash` in `Info` (@princesinha19)
   781  - [rpc] [\#2741](https://github.com/tendermint/tendermint/issues/2741) Add `proposer` to `/consensus_state` response (@princesinha19)
   782  - [deps] [\#4289](https://github.com/tendermint/tendermint/pull/4289) Update tm-db to 0.4.0, this includes major breaking changes in the dep that change how errors are handled.
   783  
   784  ### BUG FIXES:
   785  
   786  - [rpc/lib][\#4051](https://github.com/tendermint/tendermint/pull/4131) Fix RPC client, which was previously resolving https protocol to http (@yenkhoon)
   787  - [rpc] [\#4141](https://github.com/tendermint/tendermint/pull/4141) JSONRPCClient: validate that Response.ID matches Request.ID
   788  - [rpc] [\#4141](https://github.com/tendermint/tendermint/pull/4141) WSClient: check for unsolicited responses
   789  - [types] [\4164](https://github.com/tendermint/tendermint/pull/4164) Prevent temporary power overflows on validator updates
   790  - [cs] [\#4069](https://github.com/tendermint/tendermint/issues/4069) Don't panic when block meta is not found in store (@gregzaitsev)
   791  - [types] [\#4164](https://github.com/tendermint/tendermint/issues/4164) Prevent temporary power overflows on validator updates (joint
   792    efforts of @gchaincl and @ancazamfir)
   793  - [p2p] [\#4140](https://github.com/tendermint/tendermint/issues/4140) `SecretConnection`: use the transcript solely for authentication (i.e. MAC)
   794  - [consensus/types] [\#4243](https://github.com/tendermint/tendermint/issues/4243) fix BenchmarkRoundStateDeepCopy panics (@cuonglm)
   795  - [rpc] [\#4256](https://github.com/tendermint/tendermint/issues/4256) Pass `outCapacity` to `eventBus#Subscribe` when subscribing using a local client
   796  
   797  ## v0.32.13
   798  
   799  *August 5, 2020*
   800  
   801   ### BUG FIXES
   802  
   803   - [privval] [\#5112](https://github.com/tendermint/tendermint/issues/5112) If remote signer errors, don't retry (@melekes)
   804  
   805  ## v0.32.12
   806  
   807  *May 19, 2020*
   808  
   809  ### BUG FIXES
   810  
   811  - [p2p] [\#4847](https://github.com/tendermint/tendermint/pull/4847) Return masked IP (not the actual IP) in addrbook#groupKey (@melekes)
   812  
   813  ## v0.32.11
   814  
   815  *April 29, 2020*
   816  
   817  ### BUG FIXES:
   818  
   819  - [privval] [\#4275](https://github.com/tendermint/tendermint/issues/4275) Fix consensus failure when remote signer drops (@melekes)
   820  
   821  ## v0.32.10
   822  
   823  *April 6, 2020*
   824  
   825  This security release fixes:
   826  
   827  ### Denial of Service 1
   828  
   829  Tendermint 0.33.2 and earlier does not limit the number of P2P connection
   830  requests. For each p2p connection, Tendermint allocates ~0.5MB. Even though
   831  this memory is garbage collected once the connection is terminated (due to
   832  duplicate IP or reaching a maximum number of inbound peers), temporary memory
   833  spikes can lead to OOM (Out-Of-Memory) exceptions.
   834  
   835  Tendermint 0.33.3 (and 0.32.10) limits the total number of P2P incoming
   836  connection requests to to `p2p.max_num_inbound_peers +
   837  len(p2p.unconditional_peer_ids)`.
   838  
   839  Notes:
   840  
   841  - Tendermint does not rate limit P2P connection requests per IP (an attacker
   842    can saturate all the inbound slots);
   843  - Tendermint does not rate limit HTTP(S) requests. If you expose any RPC
   844    endpoints to the public, please make sure to put in place some protection
   845    (https://www.nginx.com/blog/rate-limiting-nginx/). We may implement this in
   846    the future ([\#1696](https://github.com/tendermint/tendermint/issues/1696)).
   847  
   848  ### Denial of Service 2
   849  
   850  Tendermint 0.33.2 and earlier does not reclaim `activeID` of a peer after it's
   851  removed in `Mempool` reactor. This does not happen all the time. It only
   852  happens when a connection fails (for any reason) before the Peer is created and
   853  added to all reactors. `RemovePeer` is therefore called before `AddPeer`, which
   854  leads to always growing memory (`activeIDs` map). The `activeIDs` map has a
   855  maximum size of 65535 and the node will panic if this map reaches the maximum.
   856  An attacker can create a lot of connection attempts (exploiting Denial of
   857  Service 1), which ultimately will lead to the node panicking.
   858  
   859  Tendermint 0.33.3 (and 0.32.10) claims `activeID` for a peer in `InitPeer`,
   860  which is executed before `MConnection` is started.
   861  
   862  Notes:
   863  
   864  - `InitPeer` function was added to all reactors to combat a similar issue -
   865    [\#3338](https://github.com/tendermint/tendermint/issues/3338);
   866  - Denial of Service 2 is independent of Denial of Service 1 and can be executed
   867    without it.
   868  
   869  **All clients are recommended to upgrade**
   870  
   871  Special thanks to [fudongbai](https://hackerone.com/fudongbai) for finding
   872  and reporting this.
   873  
   874  Friendly reminder, we have a [bug bounty
   875  program](https://hackerone.com/tendermint).
   876  
   877  ### SECURITY:
   878  
   879  - [mempool] Reserve IDs in InitPeer instead of AddPeer (@tessr)
   880  - [p2p] Limit the number of incoming connections (@melekes)
   881  
   882  ## v0.32.9
   883  
   884  _January, 9, 2020_
   885  
   886  Special thanks to external contributors on this release: @greg-szabo, @gregzaitsev, @yenkhoon
   887  
   888  Friendly reminder, we have a [bug bounty
   889  program](https://hackerone.com/tendermint).
   890  
   891  ### FEATURES:
   892  
   893  - [rpc/lib] [\#4248](https://github.com/tendermint/tendermint/issues/4248) RPC client basic authentication support (@greg-szabo)
   894  
   895  - [metrics] [\#4294](https://github.com/tendermint/tendermint/pull/4294) Add
   896    - `consensus_validator_power`: track your validators power
   897    - `consensus_validator_last_signed_height`: track at which height the validator last signed
   898    - `consensus_validator_missed_blocks`: total amount of missed blocks for a validator
   899      as gauges in prometheus for validator specific metrics
   900  
   901  ### BUG FIXES:
   902  
   903  - [rpc/lib] [\#4131](https://github.com/tendermint/tendermint/pull/4131) Fix RPC client, which was previously resolving https protocol to http (@yenkhoon)
   904  - [cs] [\#4069](https://github.com/tendermint/tendermint/issues/4069) Don't panic when block meta is not found in store (@gregzaitsev)
   905  
   906  ## v0.32.8
   907  
   908  *November 19, 2019*
   909  
   910  Special thanks to external contributors on this release: @erikgrinaker, @guagualvcha, @hsyis, @cosmostuba, @whunmr, @austinabell
   911  
   912  Friendly reminder, we have a [bug bounty
   913  program.](https://hackerone.com/tendermint).
   914  
   915  
   916  ### BREAKING CHANGES:
   917  
   918  - Go API
   919  
   920    - [libs/pubsub] [\#4070](https://github.com/tendermint/tendermint/pull/4070) `Query#(Matches|Conditions)` returns an error.
   921  
   922  ### IMPROVEMENTS:
   923  
   924  - [mempool] [\#4083](https://github.com/tendermint/tendermint/pull/4083) Added TxInfo parameter to CheckTx(), and removed CheckTxWithInfo() (@erikgrinaker)
   925  - [mempool] [\#4057](https://github.com/tendermint/tendermint/issues/4057) Include peer ID when logging rejected txns (@erikgrinaker)
   926  - [tools] [\#4023](https://github.com/tendermint/tendermint/issues/4023) Improved `tm-monitor` formatting of start time and avg tx throughput (@erikgrinaker)
   927  - [p2p] [\#3991](https://github.com/tendermint/tendermint/issues/3991) Log "has been established or dialed" as debug log instead of Error for connected peers (@whunmr)
   928  - [rpc] [\#4077](https://github.com/tendermint/tendermint/pull/4077) Added support for `EXISTS` clause to the Websocket query interface.
   929  - [privval] Add `SignerDialerEndpointRetryWaitInterval` option (@cosmostuba)
   930  - [crypto] Add `RegisterKeyType` to amino to allow external key types registration (@austinabell)
   931  
   932  ### BUG FIXES:
   933  
   934  - [libs/pubsub] [\#4070](https://github.com/tendermint/tendermint/pull/4070) Strip out non-numeric characters when attempting to match numeric values.
   935  - [libs/pubsub] [\#4070](https://github.com/tendermint/tendermint/pull/4070) No longer panic in Query#(Matches|Conditions) preferring to return an error instead.
   936  - [tools] [\#4023](https://github.com/tendermint/tendermint/issues/4023) Refresh `tm-monitor` health when validator count is updated (@erikgrinaker)
   937  - [state] [\#4104](https://github.com/tendermint/tendermint/pull/4104) txindex/kv: Fsync data to disk immediately after receiving it (@guagualvcha)
   938  - [state] [\#4095](https://github.com/tendermint/tendermint/pull/4095) txindex/kv: Return an error if there's one when the user searches for a tx (hash=X) (@hsyis)
   939  
   940  ## v0.32.7
   941  
   942  *October 18, 2019*
   943  
   944  This security release fixes a vulnerability found in the `consensus` package,
   945  where an attacker could construct a `BlockPartMessage` message in such a way
   946  that it will lead to consensus failure. A few similar issues have been
   947  identified and fixed here.
   948  
   949  **All clients are recommended to upgrade**
   950  
   951  Special thanks to [elvishacker](https://hackerone.com/elvishacker) for finding
   952  and reporting this.
   953  
   954  Friendly reminder, we have a [bug bounty
   955  program](https://hackerone.com/tendermint).
   956  
   957  ### BREAKING CHANGES:
   958  
   959  - Go API
   960    - [consensus] Modify `WAL#Write` and `WAL#WriteSync` to return an error if
   961      they fail to write a message
   962  
   963  ### SECURITY:
   964  
   965  - [consensus] Validate incoming messages more throughly
   966  
   967  ## v0.32.6
   968  
   969  *October 8, 2019*
   970  
   971  The previous patch was insufficient because the attacker could still find a way
   972  to submit a `nil` pubkey by constructing a `PubKeyMultisigThreshold` pubkey
   973  with `nil` subpubkeys for example.
   974  
   975  This release provides multiple fixes, which include recovering from panics when
   976  accepting new peers and only allowing `ed25519` pubkeys.
   977  
   978  **All clients are recommended to upgrade**
   979  
   980  Special thanks to [fudongbai](https://hackerone.com/fudongbai) for pointing
   981  this out.
   982  
   983  Friendly reminder, we have a [bug bounty
   984  program](https://hackerone.com/tendermint).
   985  
   986  ### SECURITY:
   987  
   988  - [p2p] [\#4030](https://github.com/tendermint/tendermint/issues/4030) Only allow ed25519 pubkeys when connecting
   989  
   990  ## v0.32.5
   991  
   992  *October 1, 2019*
   993  
   994  This release fixes a major security vulnerability found in the `p2p` package.
   995  All clients are recommended to upgrade. See
   996  [\#4030](https://github.com/tendermint/tendermint/issues/4030) for details.
   997  
   998  Special thanks to [fudongbai](https://hackerone.com/fudongbai) for discovering
   999  and reporting this issue.
  1000  
  1001  Friendly reminder, we have a [bug bounty
  1002  program](https://hackerone.com/tendermint).
  1003  
  1004  ### SECURITY:
  1005  
  1006  - [p2p] [\#4030](https://github.com/tendermint/tendermint/issues/4030) Fix for panic on nil public key send to a peer
  1007  
  1008  ## v0.32.4
  1009  
  1010  *September 19, 2019*
  1011  
  1012  Special thanks to external contributors on this release: @jon-certik, @gracenoah, @PSalant726, @gchaincl
  1013  
  1014  Friendly reminder, we have a [bug bounty
  1015  program](https://hackerone.com/tendermint).
  1016  
  1017  ### BREAKING CHANGES:
  1018  
  1019  - CLI/RPC/Config
  1020    - [rpc] [\#3984](https://github.com/tendermint/tendermint/issues/3984) Add `MempoolClient` interface to `Client` interface
  1021  
  1022  ### IMPROVEMENTS:
  1023  
  1024  - [rpc] [\#2010](https://github.com/tendermint/tendermint/issues/2010) Add NewHTTPWithClient and NewJSONRPCClientWithHTTPClient (note these and NewHTTP, NewJSONRPCClient functions panic if remote is invalid) (@gracenoah)
  1025  - [rpc] [\#3882](https://github.com/tendermint/tendermint/issues/3882) Add custom marshalers to proto messages to disable `omitempty`
  1026  - [deps] [\#3952](https://github.com/tendermint/tendermint/pull/3952) bump github.com/go-kit/kit from 0.6.0 to 0.9.0
  1027  - [deps] [\#3951](https://github.com/tendermint/tendermint/pull/3951) bump github.com/stretchr/testify from 1.3.0 to 1.4.0
  1028  - [deps] [\#3945](https://github.com/tendermint/tendermint/pull/3945) bump github.com/gorilla/websocket from 1.2.0 to 1.4.1
  1029  - [deps] [\#3948](https://github.com/tendermint/tendermint/pull/3948) bump github.com/libp2p/go-buffer-pool from 0.0.1 to 0.0.2
  1030  - [deps] [\#3943](https://github.com/tendermint/tendermint/pull/3943) bump github.com/fortytw2/leaktest from 1.2.0 to 1.3.0
  1031  - [deps] [\#3939](https://github.com/tendermint/tendermint/pull/3939) bump github.com/rs/cors from 1.6.0 to 1.7.0
  1032  - [deps] [\#3937](https://github.com/tendermint/tendermint/pull/3937) bump github.com/magiconair/properties from 1.8.0 to 1.8.1
  1033  - [deps] [\#3947](https://github.com/tendermint/tendermint/pull/3947) update gogo/protobuf version from v1.2.1 to v1.3.0
  1034  - [deps] [\#4001](https://github.com/tendermint/tendermint/pull/4001) bump github.com/tendermint/tm-db from 0.1.1 to 0.2.0
  1035  
  1036  ### BUG FIXES:
  1037  
  1038  - [consensus] [\#3908](https://github.com/tendermint/tendermint/issues/3908) Wait `timeout_commit` to pass even if `create_empty_blocks` is `false`
  1039  - [mempool] [\#3968](https://github.com/tendermint/tendermint/issues/3968) Fix memory loading error on 32-bit machines (@jon-certik)
  1040  
  1041  ## v0.32.3
  1042  
  1043  *August 28, 2019*
  1044  
  1045  @climber73 wrote the [Writing a Tendermint Core application in Java
  1046  (gRPC)](https://github.com/tendermint/tendermint/blob/master/docs/guides/java.md)
  1047  guide.
  1048  
  1049  Special thanks to external contributors on this release:
  1050  @gchaincl, @bluele, @climber73
  1051  
  1052  Friendly reminder, we have a [bug bounty
  1053  program](https://hackerone.com/tendermint).
  1054  
  1055  ### IMPROVEMENTS:
  1056  
  1057  - [consensus] [\#3839](https://github.com/tendermint/tendermint/issues/3839) Reduce "Error attempting to add vote" message severity (Error -> Info)
  1058  - [mempool] [\#3877](https://github.com/tendermint/tendermint/pull/3877) Make `max_tx_bytes` configurable instead of `max_msg_bytes` (@bluele)
  1059  - [privval] [\#3370](https://github.com/tendermint/tendermint/issues/3370) Refactor and simplify validator/kms connection handling. Please refer to [this comment](https://github.com/tendermint/tendermint/pull/3370#issue-257360971) for details
  1060  - [rpc] [\#3880](https://github.com/tendermint/tendermint/issues/3880) Document endpoints with `swagger`, introduce contract tests of implementation against documentation
  1061  
  1062  ### BUG FIXES:
  1063  
  1064  - [config] [\#3868](https://github.com/tendermint/tendermint/issues/3868) Move misplaced `max_msg_bytes` into mempool section (@bluele)
  1065  - [rpc] [\#3910](https://github.com/tendermint/tendermint/pull/3910) Fix DATA RACE in HTTP client (@gchaincl)
  1066  - [store] [\#3893](https://github.com/tendermint/tendermint/issues/3893) Fix "Unregistered interface types.Evidence" panic
  1067  
  1068  ## v0.32.2
  1069  
  1070  *July 31, 2019*
  1071  
  1072  Special thanks to external contributors on this release:
  1073  @ruseinov, @bluele, @guagualvcha
  1074  
  1075  Friendly reminder, we have a [bug bounty
  1076  program](https://hackerone.com/tendermint).
  1077  
  1078  ### BREAKING CHANGES:
  1079  
  1080  - Go API
  1081    - [libs] [\#3811](https://github.com/tendermint/tendermint/issues/3811) Remove `db` from libs in favor of `https://github.com/tendermint/tm-db`
  1082  
  1083  ### FEATURES:
  1084  
  1085  - [blockchain] [\#3561](https://github.com/tendermint/tendermint/issues/3561) Add early version of the new blockchain reactor, which is supposed to be more modular and testable compared to the old version. To try it, you'll have to change `version` in the config file, [here](https://github.com/tendermint/tendermint/blob/master/config/toml.go#L303) NOTE: It's not ready for a production yet. For further information, see [ADR-40](https://github.com/tendermint/tendermint/blob/master/docs/architecture/adr-040-blockchain-reactor-refactor.md) & [ADR-43](https://github.com/tendermint/tendermint/blob/master/docs/architecture/adr-043-blockchain-riri-org.md)
  1086  - [mempool] [\#3826](https://github.com/tendermint/tendermint/issues/3826) Make `max_msg_bytes` configurable(@bluele)
  1087  - [node] [\#3846](https://github.com/tendermint/tendermint/pull/3846) Allow replacing existing p2p.Reactor(s) using [`CustomReactors`
  1088    option](https://godoc.org/github.com/tendermint/tendermint/node#CustomReactors).
  1089    Warning: beware of accidental name clashes. Here is the list of existing
  1090    reactors: MEMPOOL, BLOCKCHAIN, CONSENSUS, EVIDENCE, PEX.
  1091  - [rpc] [\#3818](https://github.com/tendermint/tendermint/issues/3818) Make `max_body_bytes` and `max_header_bytes` configurable(@bluele)
  1092  - [rpc] [\#2252](https://github.com/tendermint/tendermint/issues/2252) Add `/broadcast_evidence` endpoint to submit double signing and other types of evidence
  1093  
  1094  ### IMPROVEMENTS:
  1095  
  1096  - [abci] [\#3809](https://github.com/tendermint/tendermint/issues/3809) Recover from application panics in `server/socket_server.go` to allow socket cleanup (@ruseinov)
  1097  - [p2p] [\#3664](https://github.com/tendermint/tendermint/issues/3664) p2p/conn: reuse buffer when write/read from secret connection(@guagualvcha)
  1098  - [p2p] [\#3834](https://github.com/tendermint/tendermint/issues/3834) Do not write 'Couldn't connect to any seeds' error log if there are no seeds in config file
  1099  - [rpc] [\#3076](https://github.com/tendermint/tendermint/issues/3076) Improve transaction search performance
  1100  
  1101  ### BUG FIXES:
  1102  
  1103  - [p2p] [\#3644](https://github.com/tendermint/tendermint/issues/3644) Fix error logging for connection stop (@defunctzombie)
  1104  - [rpc] [\#3813](https://github.com/tendermint/tendermint/issues/3813) Return err if page is incorrect (less than 0 or greater than total pages)
  1105  
  1106  ## v0.32.1
  1107  
  1108  *July 15, 2019*
  1109  
  1110  Special thanks to external contributors on this release:
  1111  @ParthDesai, @climber73, @jim380, @ashleyvega
  1112  
  1113  This release contains a minor enhancement to the ABCI and some breaking changes to our libs folder, namely:
  1114  - CheckTx requests include a `CheckTxType` enum that can be set to `Recheck` to indicate to the application that this transaction was already checked/validated and certain expensive operations (like checking signatures) can be skipped
  1115  - Removed various functions from `libs` pkgs
  1116  
  1117  Friendly reminder, we have a [bug bounty
  1118  program](https://hackerone.com/tendermint).
  1119  
  1120  ### BREAKING CHANGES:
  1121  
  1122  - Go API
  1123  
  1124    -  [abci] [\#2127](https://github.com/tendermint/tendermint/issues/2127) The CheckTx and DeliverTx methods in the ABCI `Application` interface now take structs  as arguments (RequestCheckTx and RequestDeliverTx, respectively), instead of just the raw tx bytes. This allows more information to be passed to these methods, for instance, indicating whether a tx has already been checked.
  1125    - [libs] Remove unused `db/debugDB` and `common/colors.go` & `errors/errors.go` files (@marbar3778)
  1126    - [libs] [\#2432](https://github.com/tendermint/tendermint/issues/2432) Remove unused `common/heap.go` file (@marbar3778)
  1127    - [libs] Remove unused `date.go`, `io.go`. Remove `GoPath()`, `Prompt()` and `IsDirEmpty()` functions from `os.go` (@marbar3778)
  1128    - [libs] Remove unused `FailRand()` func and minor clean up to `fail.go`(@marbar3778)
  1129  
  1130  ### FEATURES:
  1131  
  1132  - [node] Add variadic argument to `NewNode` to support functional options, allowing the Node to be more easily customized.
  1133  - [node][\#3730](https://github.com/tendermint/tendermint/pull/3730) Add `CustomReactors` option to `NewNode` allowing caller to pass
  1134    custom reactors to run inside Tendermint node (@ParthDesai)
  1135  - [abci] [\#2127](https://github.com/tendermint/tendermint/issues/2127)RequestCheckTx has a new field, `CheckTxType`, which can take values of `CheckTxType_New` and `CheckTxType_Recheck`, indicating whether this is a new tx being checked for the first time or whether this tx is being rechecked after a block commit. This allows applications to skip certain expensive operations, like signature checking, if they've already been done once. see [docs](https://github.com/tendermint/tendermint/blob/eddb433d7c082efbeaf8974413a36641519ee895/docs/spec/abci/apps.md#mempool-connection)
  1136  
  1137  ### IMPROVEMENTS:
  1138  
  1139  - [rpc] [\#3700](https://github.com/tendermint/tendermint/issues/3700) Make possible to set absolute paths for TLS cert and key (@climber73)
  1140  - [abci] [\#3513](https://github.com/tendermint/tendermint/issues/3513) Call the reqRes callback after the resCb so they always happen in the same order
  1141  
  1142  ### BUG FIXES:
  1143  
  1144  - [p2p] [\#3338](https://github.com/tendermint/tendermint/issues/3338) Prevent "sent next PEX request too soon" errors by not calling
  1145    ensurePeers outside of ensurePeersRoutine
  1146  - [behaviour] [\3772](https://github.com/tendermint/tendermint/pull/3772) Return correct reason in MessageOutOfOrder (@jim380)
  1147  - [config] [\#3723](https://github.com/tendermint/tendermint/issues/3723) Add consensus_params to testnet config generation; document time_iota_ms (@ashleyvega)
  1148  
  1149  
  1150  ## v0.32.0
  1151  
  1152  *June 25, 2019*
  1153  
  1154  Special thanks to external contributors on this release:
  1155  @needkane, @SebastianElvis, @andynog, @Yawning, @wooparadog
  1156  
  1157  This release contains breaking changes to our build and release processes, ABCI,
  1158  and the RPC, namely:
  1159  - Use Go modules instead of dep
  1160  - Bring active development to the `master` Github branch
  1161  - ABCI Tags are now Events - see
  1162    [docs](https://github.com/tendermint/tendermint/blob/60827f75623b92eff132dc0eff5b49d2025c591e/docs/spec/abci/abci.md#events)
  1163  - Bind RPC to localhost by default, not to the public interface [UPGRADING/RPC_Changes](./UPGRADING.md#rpc_changes)
  1164  
  1165  Friendly reminder, we have a [bug bounty
  1166  program](https://hackerone.com/tendermint).
  1167  
  1168  ### BREAKING CHANGES:
  1169  
  1170  * CLI/RPC/Config
  1171    - [cli] [\#3613](https://github.com/tendermint/tendermint/issues/3613) Switch from golang/dep to Go Modules to resolve dependencies:
  1172      It is recommended to switch to Go Modules if your project has tendermint as
  1173      a dependency. Read more on Modules here:
  1174      https://github.com/golang/go/wiki/Modules
  1175    - [config] [\#3632](https://github.com/tendermint/tendermint/pull/3632) Removed `leveldb` as generic
  1176      option for `db_backend`. Must be `goleveldb` or `cleveldb`.
  1177    - [rpc] [\#3616](https://github.com/tendermint/tendermint/issues/3616) Fix field names for `/block_results` response (eg. `results.DeliverTx`
  1178      -> `results.deliver_tx`). See docs for details.
  1179    - [rpc] [\#3724](https://github.com/tendermint/tendermint/issues/3724) RPC now binds to `127.0.0.1` by default instead of `0.0.0.0`
  1180  
  1181  * Apps
  1182    - [abci] [\#1859](https://github.com/tendermint/tendermint/issues/1859) `ResponseCheckTx`, `ResponseDeliverTx`, `ResponseBeginBlock`,
  1183      and `ResponseEndBlock` now include `Events` instead of `Tags`. Each `Event`
  1184      contains a `type` and a list of `attributes` (list of key-value pairs)
  1185      allowing for inclusion of multiple distinct events in each response.
  1186  
  1187  * Go API
  1188    - [abci] [\#3193](https://github.com/tendermint/tendermint/issues/3193) Use RequestDeliverTx and RequestCheckTx in the ABCI
  1189      Application interface
  1190    - [libs/db] [\#3632](https://github.com/tendermint/tendermint/pull/3632) Removed deprecated `LevelDBBackend` const
  1191      If you have `db_backend` set to `leveldb` in your config file, please
  1192      change it to `goleveldb` or `cleveldb`.
  1193    - [p2p] [\#3521](https://github.com/tendermint/tendermint/issues/3521) Remove NewNetAddressStringWithOptionalID
  1194  
  1195  * Blockchain Protocol
  1196  
  1197  * P2P Protocol
  1198  
  1199  ### FEATURES:
  1200  
  1201  ### IMPROVEMENTS:
  1202  - [abci/examples] [\#3659](https://github.com/tendermint/tendermint/issues/3659) Change validator update tx format in the `persistent_kvstore` to use base64 for pubkeys instead of hex (@needkane)
  1203  - [consensus] [\#3656](https://github.com/tendermint/tendermint/issues/3656) Exit if SwitchToConsensus fails
  1204  - [p2p] [\#3666](https://github.com/tendermint/tendermint/issues/3666) Add per channel telemetry to improve reactor observability
  1205  - [rpc] [\#3686](https://github.com/tendermint/tendermint/pull/3686) `HTTPClient#Call` returns wrapped errors, so a caller could use `errors.Cause` to retrieve an error code. (@wooparadog)
  1206  
  1207  ### BUG FIXES:
  1208  - [libs/db] [\#3717](https://github.com/tendermint/tendermint/issues/3717) Fixed the BoltDB backend's Batch.Delete implementation (@Yawning)
  1209  - [libs/db] [\#3718](https://github.com/tendermint/tendermint/issues/3718) Fixed the BoltDB backend's Get and Iterator implementation (@Yawning)
  1210  - [node] [\#3716](https://github.com/tendermint/tendermint/issues/3716) Fix a bug where `nil` is recorded as node's address
  1211  - [node] [\#3741](https://github.com/tendermint/tendermint/issues/3741) Fix profiler blocking the entire node
  1212  
  1213  *Tendermint 0.31 release series has reached End-Of-Life and is no longer supported.*
  1214  
  1215  ## v0.31.12
  1216  
  1217  *April 6, 2020*
  1218  
  1219  This security release fixes:
  1220  
  1221  ### Denial of Service 1
  1222  
  1223  Tendermint 0.33.2 and earlier does not limit the number of P2P connection requests.
  1224  For each p2p connection, Tendermint allocates ~0.5MB. Even though this
  1225  memory is garbage collected once the connection is terminated (due to duplicate
  1226  IP or reaching a maximum number of inbound peers), temporary memory spikes can
  1227  lead to OOM (Out-Of-Memory) exceptions.
  1228  
  1229  Tendermint 0.33.3, 0.32.10, and 0.31.12 limit the total number of P2P incoming
  1230  connection requests to to `p2p.max_num_inbound_peers +
  1231  len(p2p.unconditional_peer_ids)`.
  1232  
  1233  Notes:
  1234  
  1235  - Tendermint does not rate limit P2P connection requests per IP (an attacker
  1236    can saturate all the inbound slots);
  1237  - Tendermint does not rate limit HTTP(S) requests. If you expose any RPC
  1238    endpoints to the public, please make sure to put in place some protection
  1239    (https://www.nginx.com/blog/rate-limiting-nginx/). We may implement this in
  1240    the future ([\#1696](https://github.com/tendermint/tendermint/issues/1696)).
  1241  
  1242  ### Denial of Service 2
  1243  
  1244  Tendermint 0.33.2 and earlier does not reclaim `activeID` of a peer after it's
  1245  removed in `Mempool` reactor. This does not happen all the time. It only
  1246  happens when a connection fails (for any reason) before the Peer is created and
  1247  added to all reactors. `RemovePeer` is therefore called before `AddPeer`, which
  1248  leads to always growing memory (`activeIDs` map). The `activeIDs` map has a
  1249  maximum size of 65535 and the node will panic if this map reaches the maximum.
  1250  An attacker can create a lot of connection attempts (exploiting Denial of
  1251  Service 1), which ultimately will lead to the node panicking.
  1252  
  1253  Tendermint 0.33.3, 0.32.10, and 0.31.12 claim `activeID` for a peer in `InitPeer`,
  1254  which is executed before `MConnection` is started.
  1255  
  1256  Notes:
  1257  
  1258  - `InitPeer` function was added to all reactors to combat a similar issue -
  1259    [\#3338](https://github.com/tendermint/tendermint/issues/3338);
  1260  - Denial of Service 2 is independent of Denial of Service 1 and can be executed
  1261    without it.
  1262  
  1263  **All clients are recommended to upgrade**
  1264  
  1265  Special thanks to [fudongbai](https://hackerone.com/fudongbai) for finding
  1266  and reporting this.
  1267  
  1268  Friendly reminder, we have a [bug bounty
  1269  program](https://hackerone.com/tendermint).
  1270  
  1271  ### SECURITY:
  1272  
  1273  - [mempool] Reserve IDs in InitPeer instead of AddPeer (@tessr)
  1274  - [p2p] Limit the number of incoming connections (@melekes)
  1275  
  1276  ## v0.31.11
  1277  
  1278  *October 18, 2019*
  1279  
  1280  This security release fixes a vulnerability found in the `consensus` package,
  1281  where an attacker could construct a `BlockPartMessage` message in such a way
  1282  that it will lead to consensus failure. A few similar issues have been
  1283  identified and fixed here.
  1284  
  1285  **All clients are recommended to upgrade**
  1286  
  1287  Special thanks to [elvishacker](https://hackerone.com/elvishacker) for finding
  1288  and reporting this.
  1289  
  1290  Friendly reminder, we have a [bug bounty
  1291  program](https://hackerone.com/tendermint).
  1292  
  1293  ### BREAKING CHANGES:
  1294  
  1295  - Go API
  1296    - [consensus] Modify `WAL#Write` and `WAL#WriteSync` to return an error if
  1297      they fail to write a message
  1298  
  1299  ### SECURITY:
  1300  
  1301  - [consensus] Validate incoming messages more throughly
  1302  
  1303  ## v0.31.10
  1304  
  1305  *October 8, 2019*
  1306  
  1307  The previous patch was insufficient because the attacker could still find a way
  1308  to submit a `nil` pubkey by constructing a `PubKeyMultisigThreshold` pubkey
  1309  with `nil` subpubkeys for example.
  1310  
  1311  This release provides multiple fixes, which include recovering from panics when
  1312  accepting new peers and only allowing `ed25519` pubkeys.
  1313  
  1314  **All clients are recommended to upgrade**
  1315  
  1316  Special thanks to [fudongbai](https://hackerone.com/fudongbai) for pointing
  1317  this out.
  1318  
  1319  Friendly reminder, we have a [bug bounty
  1320  program](https://hackerone.com/tendermint).
  1321  
  1322  ### SECURITY:
  1323  
  1324  - [p2p] [\#4030](https://github.com/tendermint/tendermint/issues/4030) Only allow ed25519 pubkeys when connecting
  1325  
  1326  ## v0.31.9
  1327  
  1328  *October 1, 2019*
  1329  
  1330  This release fixes a major security vulnerability found in the `p2p` package.
  1331  All clients are recommended to upgrade. See
  1332  [\#4030](https://github.com/tendermint/tendermint/issues/4030) for details.
  1333  
  1334  Special thanks to [fudongbai](https://hackerone.com/fudongbai) for discovering
  1335  and reporting this issue.
  1336  
  1337  Friendly reminder, we have a [bug bounty
  1338  program](https://hackerone.com/tendermint).
  1339  
  1340  ### SECURITY:
  1341  
  1342  - [p2p] [\#4030](https://github.com/tendermint/tendermint/issues/4030) Fix for panic on nil public key send to a peer
  1343  
  1344  ### BUG FIXES:
  1345  
  1346  - [node] [\#3716](https://github.com/tendermint/tendermint/issues/3716) Fix a bug where `nil` is recorded as node's address
  1347  - [node] [\#3741](https://github.com/tendermint/tendermint/issues/3741) Fix profiler blocking the entire node
  1348  
  1349  ## v0.31.8
  1350  
  1351  *July 29, 2019*
  1352  
  1353  This releases fixes one bug in the PEX reactor and adds a `recover` to the Go's
  1354  ABCI server, which allows it to properly cleanup.
  1355  
  1356  ### IMPROVEMENTS:
  1357  - [abci] [\#3809](https://github.com/tendermint/tendermint/issues/3809) Recover from application panics in `server/socket_server.go` to allow socket cleanup (@ruseinov)
  1358  
  1359  ### BUG FIXES:
  1360  - [p2p] [\#3338](https://github.com/tendermint/tendermint/issues/3338) Prevent "sent next PEX request too soon" errors by not calling
  1361    ensurePeers outside of ensurePeersRoutine
  1362  
  1363  ## v0.31.7
  1364  
  1365  *June 3, 2019*
  1366  
  1367  This releases fixes a regression in the mempool introduced in v0.31.6.
  1368  The regression caused the invalid committed txs to be proposed in blocks over and
  1369  over again.
  1370  
  1371  ### BUG FIXES:
  1372  - [mempool] [\#3699](https://github.com/tendermint/tendermint/issues/3699) Remove all committed txs from the mempool.
  1373      This reverts the change from v0.31.6 where we only remove valid txs from the mempool.
  1374      Note this means malicious proposals can cause txs to be dropped from the
  1375      mempools of other nodes by including them in blocks before they are valid.
  1376      See [\#3322](https://github.com/tendermint/tendermint/issues/3322).
  1377  
  1378  ## v0.31.6
  1379  
  1380  *May 31st, 2019*
  1381  
  1382  This release contains many fixes and improvements, primarily for p2p functionality.
  1383  It also fixes a security issue in the mempool package.
  1384  
  1385  With this release, Tendermint now supports [boltdb](https://github.com/etcd-io/bbolt), although
  1386  in experimental mode. Feel free to try and report to us any findings/issues.
  1387  Note also that the build tags for compiling CLevelDB have changed.
  1388  
  1389  Special thanks to external contributors on this release:
  1390  @guagualvcha, @james-ray, @gregdhill, @climber73, @yutianwu,
  1391  @carlosflrs, @defunctzombie, @leoluk, @needkane, @CrocdileChan
  1392  
  1393  ### BREAKING CHANGES:
  1394  
  1395  * Go API
  1396    - [libs/common] Removed deprecated `PanicSanity`, `PanicCrisis`,
  1397      `PanicConsensus` and `PanicQ`
  1398    - [mempool, state] [\#2659](https://github.com/tendermint/tendermint/issues/2659) `Mempool` now an interface that lives in the mempool package.
  1399      See issue and PR for more details.
  1400    - [p2p] [\#3346](https://github.com/tendermint/tendermint/issues/3346) `Reactor#InitPeer` method is added to `Reactor` interface
  1401    - [types] [\#1648](https://github.com/tendermint/tendermint/issues/1648) `Commit#VoteSignBytes` signature was changed
  1402  
  1403  ### FEATURES:
  1404  - [node] [\#2659](https://github.com/tendermint/tendermint/issues/2659) Add `node.Mempool()` method, which allows you to access mempool
  1405  - [libs/db] [\#3604](https://github.com/tendermint/tendermint/pull/3604) Add experimental support for bolt db (etcd's fork of bolt) (@CrocdileChan)
  1406  
  1407  ### IMPROVEMENTS:
  1408  - [cli] [\#3585](https://github.com/tendermint/tendermint/issues/3585) Add `--keep-addr-book` option to `unsafe_reset_all` cmd to not
  1409    clear the address book (@climber73)
  1410  - [cli] [\#3160](https://github.com/tendermint/tendermint/issues/3160) Add
  1411    `--config=<path-to-config>` option to `testnet` cmd (@gregdhill)
  1412  - [cli] [\#3661](https://github.com/tendermint/tendermint/pull/3661) Add
  1413    `--hostname-suffix`, `--hostname` and `--random-monikers` options to `testnet`
  1414    cmd for greater peer address/identity generation flexibility.
  1415  - [crypto] [\#3672](https://github.com/tendermint/tendermint/issues/3672) Return more info in the `AddSignatureFromPubKey` error
  1416  - [cs/replay] [\#3460](https://github.com/tendermint/tendermint/issues/3460) Check appHash for each block
  1417  - [libs/db] [\#3611](https://github.com/tendermint/tendermint/issues/3611) Conditional compilation
  1418    * Use `cleveldb` tag instead of `gcc` to compile Tendermint with CLevelDB or
  1419      use `make build_c` / `make install_c` (full instructions can be found at
  1420      https://docs.tendermint.com/master/introduction/install.html#compile-with-cleveldb-support)
  1421    * Use `boltdb` tag to compile Tendermint with bolt db
  1422  - [node] [\#3362](https://github.com/tendermint/tendermint/issues/3362) Return an error if `persistent_peers` list is invalid (except
  1423    when IP lookup fails)
  1424  - [p2p] [\#3463](https://github.com/tendermint/tendermint/pull/3463) Do not log "Can't add peer's address to addrbook" error for a private peer (@guagualvcha)
  1425  - [p2p] [\#3531](https://github.com/tendermint/tendermint/issues/3531) Terminate session on nonce wrapping (@climber73)
  1426  - [pex] [\#3647](https://github.com/tendermint/tendermint/pull/3647) Dial seeds, if any, instead of crawling peers first (@defunctzombie)
  1427  - [rpc] [\#3534](https://github.com/tendermint/tendermint/pull/3534) Add support for batched requests/responses in JSON RPC
  1428  - [rpc] [\#3362](https://github.com/tendermint/tendermint/issues/3362) `/dial_seeds` & `/dial_peers` return errors if addresses are
  1429    incorrect (except when IP lookup fails)
  1430  
  1431  ### BUG FIXES:
  1432  - [consensus] [\#3067](https://github.com/tendermint/tendermint/issues/3067) Fix replay from appHeight==0 with validator set changes (@james-ray)
  1433  - [consensus] [\#3304](https://github.com/tendermint/tendermint/issues/3304) Create a peer state in consensus reactor before the peer
  1434    is started (@guagualvcha)
  1435  - [lite] [\#3669](https://github.com/tendermint/tendermint/issues/3669) Add context parameter to RPC Handlers in proxy routes (@yutianwu)
  1436  - [mempool] [\#3322](https://github.com/tendermint/tendermint/issues/3322) When a block is committed, only remove committed txs from the mempool
  1437  that were valid (ie. `ResponseDeliverTx.Code == 0`)
  1438  - [p2p] [\#3338](https://github.com/tendermint/tendermint/issues/3338) Ensure `RemovePeer` is always called before `InitPeer` (upon a peer
  1439    reconnecting to our node)
  1440  - [p2p] [\#3532](https://github.com/tendermint/tendermint/issues/3532) Limit the number of attempts to connect to a peer in seed mode
  1441    to 16 (as a result, the node will stop retrying after a 35 hours time window)
  1442  - [p2p] [\#3362](https://github.com/tendermint/tendermint/issues/3362) Allow inbound peers to be persistent, including for seed nodes.
  1443  - [pex] [\#3603](https://github.com/tendermint/tendermint/pull/3603) Dial seeds when addrbook needs more addresses (@defunctzombie)
  1444  
  1445  ### OTHERS:
  1446  - [networks] fixes ansible integration script (@carlosflrs)
  1447  
  1448  ## v0.31.5
  1449  
  1450  *April 16th, 2019*
  1451  
  1452  This release fixes a regression from v0.31.4 where, in existing chains that
  1453  were upgraded, `/validators` could return an empty validator set. This is true
  1454  for almost all heights, given the validator set remains the same.
  1455  
  1456  Special thanks to external contributors on this release:
  1457  @brapse, @guagualvcha, @dongsam, @phucc
  1458  
  1459  ### IMPROVEMENTS:
  1460  
  1461  - [libs/common] `CMap`: slight optimization in `Keys()` and `Values()` (@phucc)
  1462  - [gitignore] gitignore: add .vendor-new (@dongsam)
  1463  
  1464  ### BUG FIXES:
  1465  
  1466  - [state] [\#3537](https://github.com/tendermint/tendermint/pull/3537#issuecomment-482711833)
  1467    `LoadValidators`: do not return an empty validator set
  1468  - [blockchain] [\#3457](https://github.com/tendermint/tendermint/issues/3457)
  1469    Fix "peer did not send us anything" in `fast_sync` mode when under high pressure
  1470  
  1471  ## v0.31.4
  1472  
  1473  *April 12th, 2019*
  1474  
  1475  This release fixes a regression from v0.31.3 which used the peer's `SocketAddr` to add the peer to
  1476  the address book. This swallowed the peer's self-reported port which is important in case of reconnect.
  1477  It brings back `NetAddress()` to `NodeInfo` and uses it instead of `SocketAddr` for adding peers.
  1478  Additionally, it improves response time on the `/validators` or `/status` RPC endpoints.
  1479  As a side-effect it makes these RPC endpoint more difficult to DoS and fixes a performance degradation in `ExecCommitBlock`.
  1480  Also, it contains an [ADR](https://github.com/tendermint/tendermint/pull/3539) that proposes decoupling the
  1481  responsibility for peer behaviour from the `p2p.Switch` (by @brapse).
  1482  
  1483  Special thanks to external contributors on this release:
  1484  @brapse, @guagualvcha, @mydring
  1485  
  1486  ### IMPROVEMENTS:
  1487  
  1488  - [p2p] [\#3463](https://github.com/tendermint/tendermint/pull/3463) Do not log "Can't add peer's address to addrbook" error for a private peer
  1489  - [p2p] [\#3547](https://github.com/tendermint/tendermint/pull/3547) Fix a couple of annoying typos (@mdyring)
  1490  
  1491  ### BUG FIXES:
  1492  
  1493  - [docs] [\#3514](https://github.com/tendermint/tendermint/issues/3514) Fix block.Header.Time description (@melekes)
  1494  - [p2p] [\#2716](https://github.com/tendermint/tendermint/issues/2716) Check if we're already connected to peer right before dialing it (@melekes)
  1495  - [p2p] [\#3545](https://github.com/tendermint/tendermint/issues/3545) Add back `NetAddress()` to `NodeInfo` and use it instead of peer's `SocketAddr()` when adding a peer to the `PEXReactor` (potential fix for [\#3532](https://github.com/tendermint/tendermint/issues/3532))
  1496  - [state] [\#3438](https://github.com/tendermint/tendermint/pull/3438)
  1497    Persist validators every 100000 blocks even if no changes to the set
  1498    occurred (@guagualvcha). This
  1499    1) Prevents possible DoS attack using `/validators` or `/status` RPC
  1500    endpoints. Before response time was growing linearly with height if no
  1501    changes were made to the validator set.
  1502    2) Fixes performance degradation in `ExecCommitBlock` where we call
  1503    `LoadValidators` for each `Evidence` in the block.
  1504  
  1505  ## v0.31.3
  1506  
  1507  *April 1st, 2019*
  1508  
  1509  This release includes two security sensitive fixes: it ensures generated private
  1510  keys are valid, and it prevents certain DNS lookups that would cause the node to
  1511  panic if the lookup failed.
  1512  
  1513  ### BREAKING CHANGES:
  1514  * Go API
  1515    - [crypto/secp256k1] [\#3439](https://github.com/tendermint/tendermint/issues/3439)
  1516      The `secp256k1.GenPrivKeySecp256k1` function has changed to guarantee that it returns a valid key, which means it
  1517      will return a different private key than in previous versions for the same secret.
  1518  
  1519  ### BUG FIXES:
  1520  
  1521  - [crypto/secp256k1] [\#3439](https://github.com/tendermint/tendermint/issues/3439)
  1522      Ensure generated private keys are valid by randomly sampling until a valid key is found.
  1523      Previously, it was possible (though rare!) to generate keys that exceeded the curve order.
  1524      Such keys would lead to invalid signatures.
  1525  - [p2p] [\#3522](https://github.com/tendermint/tendermint/issues/3522) Memoize
  1526    socket address in peer connections to avoid DNS lookups. Previously, failed
  1527    DNS lookups could cause the node to panic.
  1528  
  1529  ## v0.31.2
  1530  
  1531  *March 30th, 2019*
  1532  
  1533  This release fixes a regression from v0.31.1 where Tendermint panics under
  1534  mempool load for external ABCI apps.
  1535  
  1536  Special thanks to external contributors on this release:
  1537  @guagualvcha
  1538  
  1539  ### BREAKING CHANGES:
  1540  
  1541  * CLI/RPC/Config
  1542  
  1543  * Apps
  1544  
  1545  * Go API
  1546    - [libs/autofile] [\#3504](https://github.com/tendermint/tendermint/issues/3504) Remove unused code in autofile package. Deleted functions: `Group.Search`, `Group.FindLast`, `GroupReader.ReadLine`, `GroupReader.PushLine`, `MakeSimpleSearchFunc` (@guagualvcha)
  1547  
  1548  * Blockchain Protocol
  1549  
  1550  * P2P Protocol
  1551  
  1552  ### FEATURES:
  1553  
  1554  ### IMPROVEMENTS:
  1555  
  1556  - [circle] [\#3497](https://github.com/tendermint/tendermint/issues/3497) Move release management to CircleCI
  1557  
  1558  ### BUG FIXES:
  1559  
  1560  - [mempool] [\#3512](https://github.com/tendermint/tendermint/issues/3512) Fix panic from concurrent access to txsMap, a regression for external ABCI apps introduced in v0.31.1
  1561  
  1562  ## v0.31.1
  1563  
  1564  *March 27th, 2019*
  1565  
  1566  This release contains a major improvement for the mempool that reduce the amount of sent data by about 30%
  1567  (see some numbers below).
  1568  It also fixes a memory leak in the mempool and adds TLS support to the RPC server by providing a certificate and key in the config.
  1569  
  1570  Special thanks to external contributors on this release:
  1571  @brapse, @guagualvcha, @HaoyangLiu, @needkane, @TraceBundy
  1572  
  1573  ### BREAKING CHANGES:
  1574  
  1575  * CLI/RPC/Config
  1576  
  1577  * Apps
  1578  
  1579  * Go API
  1580    - [crypto] [\#3426](https://github.com/tendermint/tendermint/pull/3426) Remove `Ripemd160` helper method (@needkane)
  1581    - [libs/common] [\#3429](https://github.com/tendermint/tendermint/pull/3429) Remove `RepeatTimer` (also `TimerMaker` and `Ticker` interface)
  1582    - [rpc/client] [\#3458](https://github.com/tendermint/tendermint/issues/3458) Include `NetworkClient` interface into `Client` interface
  1583    - [types] [\#3448](https://github.com/tendermint/tendermint/issues/3448) Remove method `PB2TM.ConsensusParams`
  1584  
  1585  * Blockchain Protocol
  1586  
  1587  * P2P Protocol
  1588  
  1589  ### FEATURES:
  1590  
  1591   - [rpc] [\#3419](https://github.com/tendermint/tendermint/issues/3419) Start HTTPS server if `rpc.tls_cert_file` and `rpc.tls_key_file` are provided in the config (@guagualvcha)
  1592  
  1593  ### IMPROVEMENTS:
  1594  
  1595  - [docs] [\#3140](https://github.com/tendermint/tendermint/issues/3140) Formalize proposer election algorithm properties
  1596  - [docs] [\#3482](https://github.com/tendermint/tendermint/issues/3482) Fix broken links (@brapse)
  1597  - [mempool] [\#2778](https://github.com/tendermint/tendermint/issues/2778) No longer send txs back to peers who sent it to you.
  1598  Also, limit to 65536 active peers.
  1599  This vastly improves the bandwidth consumption of nodes.
  1600  For instance, for a 4 node localnet, in a test sending 250byte txs for 120 sec. at 500 txs/sec (total of 15MB):
  1601    - total bytes received from 1st node:
  1602       - before: 42793967 (43MB)
  1603       - after: 30003256 (30MB)
  1604    - total bytes sent to 1st node:
  1605       - before: 30569339 (30MB)
  1606       - after: 19304964 (19MB)
  1607  - [p2p] [\#3475](https://github.com/tendermint/tendermint/issues/3475) Simplify `GetSelectionWithBias` for addressbook (@guagualvcha)
  1608  - [rpc/lib/client] [\#3430](https://github.com/tendermint/tendermint/issues/3430) Disable compression for HTTP client to prevent GZIP-bomb DoS attacks (@guagualvcha)
  1609  
  1610  ### BUG FIXES:
  1611  
  1612  - [blockchain] [\#2699](https://github.com/tendermint/tendermint/issues/2699) Update the maxHeight when a peer is removed
  1613  - [mempool] [\#3478](https://github.com/tendermint/tendermint/issues/3478) Fix memory-leak related to `broadcastTxRoutine` (@HaoyangLiu)
  1614  
  1615  
  1616  ## v0.31.0
  1617  
  1618  *March 16th, 2019*
  1619  
  1620  Special thanks to external contributors on this release:
  1621  @danil-lashin, @guagualvcha, @siburu, @silasdavis, @srmo, @Stumble, @svenstaro
  1622  
  1623  This release is primarily about the new pubsub implementation, dubbed `pubsub 2.0`, and related changes,
  1624  like configurable limits on the number of active RPC subscriptions at a time (`max_subscription_clients`).
  1625  Pubsub 2.0 is an improved version of the older pubsub that is non-blocking and has a nicer API.
  1626  Note the improved pubsub API also resulted in some improvements to the HTTPClient interface and the API for WebSocket subscriptions.
  1627  This release also adds a configurable limit to the mempool size (`max_txs_bytes`, default 1GB)
  1628  and a configurable timeout for the `/broadcast_tx_commit` endpoint.
  1629  
  1630  See the [v0.31.0
  1631  Milestone](https://github.com/tendermint/tendermint/milestone/19?closed=1) for
  1632  more details.
  1633  
  1634  Friendly reminder, we have a [bug bounty
  1635  program](https://hackerone.com/tendermint).
  1636  
  1637  ### BREAKING CHANGES:
  1638  
  1639  * CLI/RPC/Config
  1640    - [config] [\#2920](https://github.com/tendermint/tendermint/issues/2920) Remove `consensus.blocktime_iota` parameter
  1641    - [rpc] [\#3227](https://github.com/tendermint/tendermint/issues/3227) New PubSub design does not block on clients when publishing
  1642      messages. Slow clients may miss messages and receive an error, terminating
  1643      the subscription.
  1644    - [rpc] [\#3269](https://github.com/tendermint/tendermint/issues/2826) Limit number of unique clientIDs with open subscriptions. Configurable via `rpc.max_subscription_clients`
  1645    - [rpc] [\#3269](https://github.com/tendermint/tendermint/issues/2826) Limit number of unique queries a given client can subscribe to at once. Configurable via `rpc.max_subscriptions_per_client`.
  1646    - [rpc] [\#3435](https://github.com/tendermint/tendermint/issues/3435) Default ReadTimeout and WriteTimeout changed to 10s. WriteTimeout can increased by setting `rpc.timeout_broadcast_tx_commit` in the config.
  1647    - [rpc/client] [\#3269](https://github.com/tendermint/tendermint/issues/3269) Update `EventsClient` interface to reflect new pubsub/eventBus API [ADR-33](https://github.com/tendermint/tendermint/blob/develop/docs/architecture/adr-033-pubsub.md). This includes `Subscribe`, `Unsubscribe`, and `UnsubscribeAll` methods.
  1648  
  1649  * Apps
  1650    - [abci] [\#3403](https://github.com/tendermint/tendermint/issues/3403) Remove `time_iota_ms` from BlockParams. This is a
  1651      ConsensusParam but need not be exposed to the app for now.
  1652    - [abci] [\#2920](https://github.com/tendermint/tendermint/issues/2920) Rename `consensus_params.block_size` to `consensus_params.block` in ABCI ConsensusParams
  1653  
  1654  * Go API
  1655    - [libs/common] TrapSignal accepts logger as a first parameter and does not block anymore
  1656      * previously it was dumping "captured ..." msg to os.Stdout
  1657      * TrapSignal should not be responsible for blocking thread of execution
  1658    - [libs/db] [\#3397](https://github.com/tendermint/tendermint/pull/3397) Add possibility to `Close()` `Batch` to prevent memory leak when using ClevelDB. (@Stumble)
  1659    - [types] [\#3354](https://github.com/tendermint/tendermint/issues/3354) Remove RoundState from EventDataRoundState
  1660    - [rpc] [\#3435](https://github.com/tendermint/tendermint/issues/3435) `StartHTTPServer` / `StartHTTPAndTLSServer` now require a Config (use `rpcserver.DefaultConfig`)
  1661  
  1662  * Blockchain Protocol
  1663  
  1664  * P2P Protocol
  1665  
  1666  ### FEATURES:
  1667  - [config] [\#3269](https://github.com/tendermint/tendermint/issues/2826) New configuration values for controlling RPC subscriptions:
  1668      - `rpc.max_subscription_clients` sets the maximum number of unique clients
  1669        with open subscriptions
  1670      - `rpc.max_subscriptions_per_client`sets the maximum number of unique
  1671        subscriptions from a given client
  1672      - `rpc.timeout_broadcast_tx_commit` sets the time to wait for a tx to be committed during `/broadcast_tx_commit`
  1673  - [types] [\#2920](https://github.com/tendermint/tendermint/issues/2920) Add `time_iota_ms` to block's consensus parameters (not exposed to the application)
  1674  - [lite] [\#3269](https://github.com/tendermint/tendermint/issues/3269) Add `/unsubscribe_all` endpoint to unsubscribe from all events
  1675  - [mempool] [\#3079](https://github.com/tendermint/tendermint/issues/3079) Bound mempool memory usage via the `mempool.max_txs_bytes` configuration value. Set to 1GB by default. The mempool's current `txs_total_bytes` is exposed via `total_bytes` field in
  1676    `/num_unconfirmed_txs` and `/unconfirmed_txs` RPC endpoints.
  1677  
  1678  ### IMPROVEMENTS:
  1679  - [all] [\#3385](https://github.com/tendermint/tendermint/issues/3385), [\#3386](https://github.com/tendermint/tendermint/issues/3386) Various linting improvements
  1680  - [crypto] [\#3371](https://github.com/tendermint/tendermint/issues/3371) Copy in secp256k1 package from go-ethereum instead of importing
  1681    go-ethereum (@silasdavis)
  1682  - [deps] [\#3382](https://github.com/tendermint/tendermint/issues/3382) Don't pin repos without releases
  1683  - [deps] [\#3357](https://github.com/tendermint/tendermint/issues/3357), [\#3389](https://github.com/tendermint/tendermint/issues/3389), [\#3392](https://github.com/tendermint/tendermint/issues/3392) Update gogo/protobuf, golang/protobuf, levigo, golang.org/x/crypto
  1684  - [libs/common] [\#3238](https://github.com/tendermint/tendermint/issues/3238) exit with zero (0) code upon receiving SIGTERM/SIGINT
  1685  - [libs/db] [\#3378](https://github.com/tendermint/tendermint/issues/3378) CLevelDB#Stats now returns the following properties:
  1686    - leveldb.num-files-at-level{n}
  1687    - leveldb.stats
  1688    - leveldb.sstables
  1689    - leveldb.blockpool
  1690    - leveldb.cachedblock
  1691    - leveldb.openedtables
  1692    - leveldb.alivesnaps
  1693    - leveldb.aliveiters
  1694  - [privval] [\#3351](https://github.com/tendermint/tendermint/pull/3351) First part of larger refactoring that clarifies and separates concerns in the privval package.
  1695  
  1696  ### BUG FIXES:
  1697  - [blockchain] [\#3358](https://github.com/tendermint/tendermint/pull/3358) Fix timer leak in `BlockPool` (@guagualvcha)
  1698  - [cmd] [\#3408](https://github.com/tendermint/tendermint/issues/3408) Fix `testnet` command's panic when creating non-validator configs (using `--n` flag) (@srmo)
  1699  - [libs/db/remotedb/grpcdb] [\#3402](https://github.com/tendermint/tendermint/issues/3402) Close Iterator/ReverseIterator after use
  1700  - [libs/pubsub] [\#951](https://github.com/tendermint/tendermint/issues/951), [\#1880](https://github.com/tendermint/tendermint/issues/1880) Use non-blocking send when dispatching messages [ADR-33](https://github.com/tendermint/tendermint/blob/develop/docs/architecture/adr-033-pubsub.md)
  1701  - [lite] [\#3364](https://github.com/tendermint/tendermint/issues/3364) Fix `/validators` and `/abci_query` proxy endpoints
  1702    (@guagualvcha)
  1703  - [p2p/conn] [\#3347](https://github.com/tendermint/tendermint/issues/3347) Reject all-zero shared secrets in the Diffie-Hellman step of secret-connection
  1704  - [p2p] [\#3369](https://github.com/tendermint/tendermint/issues/3369) Do not panic when filter times out
  1705  - [p2p] [\#3359](https://github.com/tendermint/tendermint/pull/3359) Fix reconnecting report duplicate ID error due to race condition between adding peer to peerSet and starting it (@guagualvcha)
  1706  
  1707  ## v0.30.2
  1708  
  1709  *March 10th, 2019*
  1710  
  1711  This release fixes a CLevelDB memory leak. It was happening because we were not
  1712  closing the WriteBatch object after use. See [levigo's
  1713  godoc](https://godoc.org/github.com/jmhodges/levigo#WriteBatch.Close) for the
  1714  Close method. Special thanks goes to @Stumble who both reported an issue in
  1715  [cosmos-sdk](https://github.com/cosmos/cosmos-sdk/issues/3842) and provided a
  1716  fix here.
  1717  
  1718  ### BREAKING CHANGES:
  1719  
  1720  * Go API
  1721    - [libs/db] [\#3842](https://github.com/cosmos/cosmos-sdk/issues/3842) Add Close() method to Batch interface (@Stumble)
  1722  
  1723  ### BUG FIXES:
  1724  - [libs/db] [\#3842](https://github.com/cosmos/cosmos-sdk/issues/3842) Fix CLevelDB memory leak (@Stumble)
  1725  
  1726  ## v0.30.1
  1727  
  1728  *February 20th, 2019*
  1729  
  1730  This release fixes a consensus halt and a DataCorruptionError after restart
  1731  discovered in `game_of_stakes_6`. It also fixes a security issue in the p2p
  1732  handshake by authenticating the NetAddress.ID of the peer we're dialing.
  1733  
  1734  ### IMPROVEMENTS:
  1735  
  1736  * [config] [\#3291](https://github.com/tendermint/tendermint/issues/3291) Make
  1737    config.ResetTestRootWithChainID() create concurrency-safe test directories.
  1738  
  1739  ### BUG FIXES:
  1740  
  1741  * [consensus] [\#3295](https://github.com/tendermint/tendermint/issues/3295)
  1742    Flush WAL on stop to prevent data corruption during graceful shutdown.
  1743  * [consensus] [\#3302](https://github.com/tendermint/tendermint/issues/3302)
  1744    Fix possible halt by resetting TriggeredTimeoutPrecommit before starting next height.
  1745  * [rpc] [\#3251](https://github.com/tendermint/tendermint/issues/3251) Fix
  1746    `/net_info#peers#remote_ip` format. New format spec:
  1747    * dotted decimal ("192.0.2.1"), if ip is an IPv4 or IP4-mapped IPv6 address
  1748    * IPv6 ("2001:db8::1"), if ip is a valid IPv6 address
  1749  * [cmd] [\#3314](https://github.com/tendermint/tendermint/issues/3314) Return
  1750    an error on `show_validator` when the private validator file does not exist.
  1751  * [p2p] [\#3010](https://github.com/tendermint/tendermint/issues/3010#issuecomment-464287627)
  1752    Authenticate a peer against its NetAddress.ID when dialing.
  1753  
  1754  ## v0.30.0
  1755  
  1756  *February 8th, 2019*
  1757  
  1758  This release fixes yet another issue with the proposer selection algorithm.
  1759  We hope it's the last one, but we won't be surprised if it's not.
  1760  We plan to one day expose the selection algorithm more directly to
  1761  the application ([\#3285](https://github.com/tendermint/tendermint/issues/3285)), and even to support randomness ([\#763](https://github.com/tendermint/tendermint/issues/763)).
  1762  For more, see issues marked
  1763  [proposer-selection](https://github.com/tendermint/tendermint/labels/proposer-selection).
  1764  
  1765  This release also includes a fix to prevent Tendermint from including the same
  1766  piece of evidence in more than one block. This issue was reported by @chengwenxi in our
  1767  [bug bounty program](https://hackerone.com/tendermint).
  1768  
  1769  ### BREAKING CHANGES:
  1770  
  1771  * Apps
  1772    - [state] [\#3222](https://github.com/tendermint/tendermint/issues/3222)
  1773      Duplicate updates for the same validator are forbidden. Apps must ensure
  1774      that a given `ResponseEndBlock.ValidatorUpdates` contains only one entry per pubkey.
  1775  
  1776  * Go API
  1777    - [types] [\#3222](https://github.com/tendermint/tendermint/issues/3222)
  1778      Remove `Add` and `Update` methods from `ValidatorSet` in favor of new
  1779      `UpdateWithChangeSet`. This allows updates to be applied as a set, instead of
  1780      one at a time.
  1781  
  1782  * Block Protocol
  1783    - [state] [\#3286](https://github.com/tendermint/tendermint/issues/3286) Blocks that include already committed evidence are invalid.
  1784  
  1785  * P2P Protocol
  1786    - [consensus] [\#3222](https://github.com/tendermint/tendermint/issues/3222)
  1787      Validator updates are applied as a set, instead of one at a time, thus
  1788      impacting the proposer priority calculation. This ensures that the proposer
  1789      selection algorithm does not depend on the order of updates in
  1790      `ResponseEndBlock.ValidatorUpdates`.
  1791  
  1792  ### IMPROVEMENTS:
  1793  - [crypto] [\#3279](https://github.com/tendermint/tendermint/issues/3279) Use `btcec.S256().N` directly instead of hard coding a copy.
  1794  
  1795  ### BUG FIXES:
  1796  - [state] [\#3222](https://github.com/tendermint/tendermint/issues/3222) Fix validator set updates so they are applied as a set, rather
  1797    than one at a time. This makes the proposer selection algorithm independent of
  1798    the order of updates in `ResponseEndBlock.ValidatorUpdates`.
  1799  - [evidence] [\#3286](https://github.com/tendermint/tendermint/issues/3286) Don't add committed evidence to evidence pool.
  1800  
  1801  ## v0.29.2
  1802  
  1803  *February 7th, 2019*
  1804  
  1805  Special thanks to external contributors on this release:
  1806  @ackratos, @rickyyangz
  1807  
  1808  **Note**: This release contains security sensitive patches in the `p2p` and
  1809  `crypto` packages:
  1810  - p2p:
  1811    - Partial fix for MITM attacks on the p2p connection. MITM conditions may
  1812      still exist. See [\#3010](https://github.com/tendermint/tendermint/issues/3010).
  1813  - crypto:
  1814    - Eliminate our fork of `btcd` and use the `btcd/btcec` library directly for
  1815      native secp256k1 signing. Note we still modify the signature encoding to
  1816      prevent malleability.
  1817    - Support the libsecp256k1 library via CGo through the `go-ethereum/crypto/secp256k1` package.
  1818    - Eliminate MixEntropy functions
  1819  
  1820  ### BREAKING CHANGES:
  1821  
  1822  * Go API
  1823    - [crypto] [\#3278](https://github.com/tendermint/tendermint/issues/3278) Remove
  1824      MixEntropy functions
  1825    - [types] [\#3245](https://github.com/tendermint/tendermint/issues/3245) Commit uses `type CommitSig Vote` instead of `Vote` directly.
  1826      In preparation for removing redundant fields from the commit [\#1648](https://github.com/tendermint/tendermint/issues/1648)
  1827  
  1828  ### IMPROVEMENTS:
  1829  - [consensus] [\#3246](https://github.com/tendermint/tendermint/issues/3246) Better logging and notes on recovery for corrupted WAL file
  1830  - [crypto] [\#3163](https://github.com/tendermint/tendermint/issues/3163) Use ethereum's libsecp256k1 go-wrapper for signatures when cgo is available
  1831  - [crypto] [\#3162](https://github.com/tendermint/tendermint/issues/3162) Wrap btcd instead of forking it to keep up with fixes (used if cgo is not available)
  1832  - [makefile] [\#3233](https://github.com/tendermint/tendermint/issues/3233) Use golangci-lint instead of go-metalinter
  1833  - [tools] [\#3218](https://github.com/tendermint/tendermint/issues/3218) Add go-deadlock tool to help detect deadlocks
  1834  - [tools] [\#3106](https://github.com/tendermint/tendermint/issues/3106) Add tm-signer-harness test harness for remote signers
  1835  - [tests] [\#3258](https://github.com/tendermint/tendermint/issues/3258) Fixed a bunch of non-deterministic test failures
  1836  
  1837  ### BUG FIXES:
  1838  - [node] [\#3186](https://github.com/tendermint/tendermint/issues/3186) EventBus and indexerService should be started before first block (for replay last block on handshake) execution (@ackratos)
  1839  - [p2p] [\#3232](https://github.com/tendermint/tendermint/issues/3232) Fix infinite loop leading to addrbook deadlock for seed nodes
  1840  - [p2p] [\#3247](https://github.com/tendermint/tendermint/issues/3247) Fix panic in SeedMode when calling FlushStop and OnStop
  1841    concurrently
  1842  - [p2p] [\#3040](https://github.com/tendermint/tendermint/issues/3040) Fix MITM on secret connection by checking low-order points
  1843  - [privval] [\#3258](https://github.com/tendermint/tendermint/issues/3258) Fix race between sign requests and ping requests in socket that was causing messages to be corrupted
  1844  
  1845  ## v0.29.1
  1846  
  1847  *January 24, 2019*
  1848  
  1849  Special thanks to external contributors on this release:
  1850  @infinytum, @gauthamzz
  1851  
  1852  This release contains two important fixes: one for p2p layer where we sometimes
  1853  were not closing connections and one for consensus layer where consensus with
  1854  no empty blocks (`create_empty_blocks = false`) could halt.
  1855  
  1856  Friendly reminder, we have a [bug bounty
  1857  program](https://hackerone.com/tendermint).
  1858  
  1859  ### IMPROVEMENTS:
  1860  - [pex] [\#3037](https://github.com/tendermint/tendermint/issues/3037) Only log "Reached max attempts to dial" once
  1861  - [rpc] [\#3159](https://github.com/tendermint/tendermint/issues/3159) Expose
  1862    `triggered_timeout_commit` in the `/dump_consensus_state`
  1863  
  1864  ### BUG FIXES:
  1865  - [consensus] [\#3199](https://github.com/tendermint/tendermint/issues/3199) Fix consensus halt with no empty blocks from not resetting triggeredTimeoutCommit
  1866  - [p2p] [\#2967](https://github.com/tendermint/tendermint/issues/2967) Fix file descriptor leak
  1867  
  1868  ## v0.29.0
  1869  
  1870  *January 21, 2019*
  1871  
  1872  Special thanks to external contributors on this release:
  1873  @bradyjoestar, @kunaldhariwal, @gauthamzz, @hrharder
  1874  
  1875  This release is primarily about making some breaking changes to
  1876  the Block protocol version before Cosmos launch, and to fixing more issues
  1877  in the proposer selection algorithm discovered on Cosmos testnets.
  1878  
  1879  The Block protocol changes include using a standard Merkle tree format (RFC 6962),
  1880  fixing some inconsistencies between field orders in Vote and Proposal structs,
  1881  and constraining the hash of the ConsensusParams to include only a few fields.
  1882  
  1883  The proposer selection algorithm saw significant progress,
  1884  including a [formal proof by @cwgoes for the base-case in Idris](https://github.com/cwgoes/tm-proposer-idris)
  1885  and a [much more detailed specification (still in progress) by
  1886  @ancazamfir](https://github.com/tendermint/tendermint/pull/3140).
  1887  
  1888  Fixes to the proposer selection algorithm include normalizing the proposer
  1889  priorities to mitigate the effects of large changes to the validator set.
  1890  That said, we just discovered [another bug](https://github.com/tendermint/tendermint/issues/3181),
  1891  which will be fixed in the next breaking release.
  1892  
  1893  While we are trying to stabilize the Block protocol to preserve compatibility
  1894  with old chains, there may be some final changes yet to come before Cosmos
  1895  launch as we continue to audit and test the software.
  1896  
  1897  Friendly reminder, we have a [bug bounty
  1898  program](https://hackerone.com/tendermint).
  1899  
  1900  ### BREAKING CHANGES:
  1901  
  1902  * CLI/RPC/Config
  1903  
  1904  * Apps
  1905    - [state] [\#3049](https://github.com/tendermint/tendermint/issues/3049) Total voting power of the validator set is upper bounded by
  1906      `MaxInt64 / 8`. Apps must ensure they do not return changes to the validator
  1907      set that cause this maximum to be exceeded.
  1908  
  1909  * Go API
  1910    - [node] [\#3082](https://github.com/tendermint/tendermint/issues/3082) MetricsProvider now requires you to pass a chain ID
  1911    - [types] [\#2713](https://github.com/tendermint/tendermint/issues/2713) Rename `TxProof.LeafHash` to `TxProof.Leaf`
  1912    - [crypto/merkle] [\#2713](https://github.com/tendermint/tendermint/issues/2713) `SimpleProof.Verify` takes a `leaf` instead of a
  1913      `leafHash` and performs the hashing itself
  1914  
  1915  * Blockchain Protocol
  1916    * [crypto/merkle] [\#2713](https://github.com/tendermint/tendermint/issues/2713) Merkle trees now match the RFC 6962 specification
  1917    * [types] [\#3078](https://github.com/tendermint/tendermint/issues/3078) Re-order Timestamp and BlockID in CanonicalVote so it's
  1918      consistent with CanonicalProposal (BlockID comes
  1919      first)
  1920    * [types] [\#3165](https://github.com/tendermint/tendermint/issues/3165) Hash of ConsensusParams only includes BlockSize.MaxBytes and
  1921      BlockSize.MaxGas
  1922  
  1923  * P2P Protocol
  1924    - [consensus] [\#3049](https://github.com/tendermint/tendermint/issues/3049) Normalize priorities to not exceed `2*TotalVotingPower` to mitigate unfair proposer selection
  1925      heavily preferring earlier joined validators in the case of an early bonded large validator unbonding
  1926  
  1927  ### FEATURES:
  1928  
  1929  ### IMPROVEMENTS:
  1930  - [rpc] [\#3065](https://github.com/tendermint/tendermint/issues/3065) Return maxPerPage (100), not defaultPerPage (30) if `per_page` is greater than the max 100.
  1931  - [instrumentation] [\#3082](https://github.com/tendermint/tendermint/issues/3082) Add `chain_id` label for all metrics
  1932  
  1933  ### BUG FIXES:
  1934  - [crypto] [\#3164](https://github.com/tendermint/tendermint/issues/3164) Update `btcd` fork for rare signRFC6979 bug
  1935  - [lite] [\#3171](https://github.com/tendermint/tendermint/issues/3171) Fix verifying large validator set changes
  1936  - [log] [\#3125](https://github.com/tendermint/tendermint/issues/3125) Fix year format
  1937  - [mempool] [\#3168](https://github.com/tendermint/tendermint/issues/3168) Limit tx size to fit in the max reactor msg size
  1938  - [scripts] [\#3147](https://github.com/tendermint/tendermint/issues/3147) Fix json2wal for large block parts (@bradyjoestar)
  1939  
  1940  ## v0.28.1
  1941  
  1942  *January 18th, 2019*
  1943  
  1944  Special thanks to external contributors on this release:
  1945  @HaoyangLiu
  1946  
  1947  Friendly reminder, we have a [bug bounty
  1948  program](https://hackerone.com/tendermint).
  1949  
  1950  ### BUG FIXES:
  1951  - [consensus] Fix consensus halt from proposing blocks with too much evidence
  1952  
  1953  ## v0.28.0
  1954  
  1955  *January 16th, 2019*
  1956  
  1957  Special thanks to external contributors on this release:
  1958  @fmauricios, @gianfelipe93, @husio, @needkane, @srmo, @yutianwu
  1959  
  1960  This release is primarily about upgrades to the `privval` system -
  1961  separating the `priv_validator.json` into distinct config and data files, and
  1962  refactoring the socket validator to support reconnections.
  1963  
  1964  **Note:** Please backup your existing `priv_validator.json` before using this
  1965  version.
  1966  
  1967  See [UPGRADING.md](UPGRADING.md) for more details.
  1968  
  1969  ### BREAKING CHANGES:
  1970  
  1971  * CLI/RPC/Config
  1972    - [cli] Removed `--proxy_app=dummy` option. Use `kvstore` (`persistent_kvstore`) instead.
  1973    - [cli] Renamed `--proxy_app=nilapp` to `--proxy_app=noop`.
  1974    - [config] [\#2992](https://github.com/tendermint/tendermint/issues/2992) `allow_duplicate_ip` is now set to false
  1975    - [privval] [\#1181](https://github.com/tendermint/tendermint/issues/1181) Split `priv_validator.json` into immutable (`config/priv_validator_key.json`) and mutable (`data/priv_validator_state.json`) parts (@yutianwu)
  1976    - [privval] [\#2926](https://github.com/tendermint/tendermint/issues/2926) Split up `PubKeyMsg` into `PubKeyRequest` and `PubKeyResponse` to be consistent with other message types
  1977    - [privval] [\#2923](https://github.com/tendermint/tendermint/issues/2923) Listen for unix socket connections instead of dialing them
  1978  
  1979  * Apps
  1980  
  1981  * Go API
  1982    - [types] [\#2981](https://github.com/tendermint/tendermint/issues/2981) Remove `PrivValidator.GetAddress()`
  1983  
  1984  * Blockchain Protocol
  1985  
  1986  * P2P Protocol
  1987  
  1988  ### FEATURES:
  1989  - [rpc] [\#3052](https://github.com/tendermint/tendermint/issues/3052) Include peer's remote IP in `/net_info`
  1990  
  1991  ### IMPROVEMENTS:
  1992  - [consensus] [\#3086](https://github.com/tendermint/tendermint/issues/3086) Log peerID on ignored votes (@srmo)
  1993  - [docs] [\#3061](https://github.com/tendermint/tendermint/issues/3061) Added specification for signing consensus msgs at
  1994    ./docs/spec/consensus/signing.md
  1995  - [privval] [\#2948](https://github.com/tendermint/tendermint/issues/2948) Memoize pubkey so it's only requested once on startup
  1996  - [privval] [\#2923](https://github.com/tendermint/tendermint/issues/2923) Retry RemoteSigner connections on error
  1997  
  1998  ### BUG FIXES:
  1999  
  2000  - [build] [\#3085](https://github.com/tendermint/tendermint/issues/3085) Fix `Version` field in build scripts (@husio)
  2001  - [crypto/multisig] [\#3102](https://github.com/tendermint/tendermint/issues/3102) Fix multisig keys address length
  2002  - [crypto/encoding] [\#3101](https://github.com/tendermint/tendermint/issues/3101) Fix `PubKeyMultisigThreshold` unmarshalling into `crypto.PubKey` interface
  2003  - [p2p/conn] [\#3111](https://github.com/tendermint/tendermint/issues/3111) Make SecretConnection thread safe
  2004  - [rpc] [\#3053](https://github.com/tendermint/tendermint/issues/3053) Fix internal error in `/tx_search` when results are empty
  2005    (@gianfelipe93)
  2006  - [types] [\#2926](https://github.com/tendermint/tendermint/issues/2926) Do not panic if retrieving the privval's public key fails
  2007  
  2008  ## v0.27.4
  2009  
  2010  *December 21st, 2018*
  2011  
  2012  ### BUG FIXES:
  2013  
  2014  - [mempool] [\#3036](https://github.com/tendermint/tendermint/issues/3036) Fix
  2015    LRU cache by popping the least recently used item when the cache is full,
  2016    not the most recently used one!
  2017  
  2018  ## v0.27.3
  2019  
  2020  *December 16th, 2018*
  2021  
  2022  ### BREAKING CHANGES:
  2023  
  2024  * Go API
  2025    - [dep] [\#3027](https://github.com/tendermint/tendermint/issues/3027) Revert to mainline Go crypto library, eliminating the modified
  2026      `bcrypt.GenerateFromPassword`
  2027  
  2028  ## v0.27.2
  2029  
  2030  *December 16th, 2018*
  2031  
  2032  ### IMPROVEMENTS:
  2033  
  2034  - [node] [\#3025](https://github.com/tendermint/tendermint/issues/3025) Validate NodeInfo addresses on startup.
  2035  
  2036  ### BUG FIXES:
  2037  
  2038  - [p2p] [\#3025](https://github.com/tendermint/tendermint/pull/3025) Revert to using defers in addrbook.  Fixes deadlocks in pex and consensus upon invalid ExternalAddr/ListenAddr configuration.
  2039  
  2040  ## v0.27.1
  2041  
  2042  *December 15th, 2018*
  2043  
  2044  Special thanks to external contributors on this release:
  2045  @danil-lashin, @hleb-albau, @james-ray, @leo-xinwang
  2046  
  2047  ### FEATURES:
  2048  - [rpc] [\#2964](https://github.com/tendermint/tendermint/issues/2964) Add `UnconfirmedTxs(limit)` and `NumUnconfirmedTxs()` methods to HTTP/Local clients (@danil-lashin)
  2049  - [docs] [\#3004](https://github.com/tendermint/tendermint/issues/3004) Enable full-text search on docs pages
  2050  
  2051  ### IMPROVEMENTS:
  2052  - [consensus] [\#2971](https://github.com/tendermint/tendermint/issues/2971) Return error if ValidatorSet is empty after InitChain
  2053    (@leo-xinwang)
  2054  - [ci/cd] [\#3005](https://github.com/tendermint/tendermint/issues/3005) Updated CircleCI job to trigger website build when docs are updated
  2055  - [docs] Various updates
  2056  
  2057  ### BUG FIXES:
  2058  - [cmd] [\#2983](https://github.com/tendermint/tendermint/issues/2983) `testnet` command always sets `addr_book_strict = false`
  2059  - [config] [\#2980](https://github.com/tendermint/tendermint/issues/2980) Fix CORS options formatting
  2060  - [kv indexer] [\#2912](https://github.com/tendermint/tendermint/issues/2912) Don't ignore key when executing CONTAINS
  2061  - [mempool] [\#2961](https://github.com/tendermint/tendermint/issues/2961) Call `notifyTxsAvailable` if there're txs left after committing a block, but recheck=false
  2062  - [mempool] [\#2994](https://github.com/tendermint/tendermint/issues/2994) Reject txs with negative GasWanted
  2063  - [p2p] [\#2990](https://github.com/tendermint/tendermint/issues/2990) Fix a bug where seeds don't disconnect from a peer after 3h
  2064  - [consensus] [\#3006](https://github.com/tendermint/tendermint/issues/3006) Save state after InitChain only when stateHeight is also 0 (@james-ray)
  2065  
  2066  ## v0.27.0
  2067  
  2068  *December 5th, 2018*
  2069  
  2070  Special thanks to external contributors on this release:
  2071  @danil-lashin, @srmo
  2072  
  2073  Special thanks to @dlguddus for discovering a [major
  2074  issue](https://github.com/tendermint/tendermint/issues/2718#issuecomment-440888677)
  2075  in the proposer selection algorithm.
  2076  
  2077  Friendly reminder, we have a [bug bounty
  2078  program](https://hackerone.com/tendermint).
  2079  
  2080  This release is primarily about fixes to the proposer selection algorithm
  2081  in preparation for the [Cosmos Game of
  2082  Stakes](https://blog.cosmos.network/the-game-of-stakes-is-open-for-registration-83a404746ee6).
  2083  It also makes use of the `ConsensusParams.Validator.PubKeyTypes` to restrict the
  2084  key types that can be used by validators, and removes the `Heartbeat` consensus
  2085  message.
  2086  
  2087  ### BREAKING CHANGES:
  2088  
  2089  * CLI/RPC/Config
  2090    - [rpc] [\#2932](https://github.com/tendermint/tendermint/issues/2932) Rename `accum` to `proposer_priority`
  2091  
  2092  * Go API
  2093    - [db] [\#2913](https://github.com/tendermint/tendermint/pull/2913)
  2094      ReverseIterator API change: start < end, and end is exclusive.
  2095    - [types] [\#2932](https://github.com/tendermint/tendermint/issues/2932) Rename `Validator.Accum` to `Validator.ProposerPriority`
  2096  
  2097  * Blockchain Protocol
  2098    - [state] [\#2714](https://github.com/tendermint/tendermint/issues/2714) Validators can now only use pubkeys allowed within
  2099      ConsensusParams.Validator.PubKeyTypes
  2100  
  2101  * P2P Protocol
  2102    - [consensus] [\#2871](https://github.com/tendermint/tendermint/issues/2871)
  2103      Remove *ProposalHeartbeat* message as it serves no real purpose (@srmo)
  2104    - [state] Fixes for proposer selection:
  2105      - [\#2785](https://github.com/tendermint/tendermint/issues/2785) Accum for new validators is `-1.125*totalVotingPower` instead of 0
  2106      - [\#2941](https://github.com/tendermint/tendermint/issues/2941) val.Accum is preserved during ValidatorSet.Update to avoid being
  2107        reset to 0
  2108  
  2109  ### IMPROVEMENTS:
  2110  
  2111  - [state] [\#2929](https://github.com/tendermint/tendermint/issues/2929) Minor refactor of updateState logic (@danil-lashin)
  2112  - [node] [\#2959](https://github.com/tendermint/tendermint/issues/2959) Allow node to start even if software's BlockProtocol is
  2113    different from state's BlockProtocol
  2114  - [pex] [\#2959](https://github.com/tendermint/tendermint/issues/2959) Pex reactor logger uses `module=pex`
  2115  
  2116  ### BUG FIXES:
  2117  
  2118  - [p2p] [\#2968](https://github.com/tendermint/tendermint/issues/2968) Panic on transport error rather than continuing to run but not
  2119    accept new connections
  2120  - [p2p] [\#2969](https://github.com/tendermint/tendermint/issues/2969) Fix mismatch in peer count between `/net_info` and the prometheus
  2121    metrics
  2122  - [rpc] [\#2408](https://github.com/tendermint/tendermint/issues/2408) `/broadcast_tx_commit`: Fix "interface conversion: interface {} in nil, not EventDataTx" panic (could happen if somebody sent a tx using `/broadcast_tx_commit` while Tendermint was being stopped)
  2123  - [state] [\#2785](https://github.com/tendermint/tendermint/issues/2785) Fix accum for new validators to be `-1.125*totalVotingPower`
  2124    instead of 0, forcing them to wait before becoming the proposer. Also:
  2125      - do not batch clip
  2126      - keep accums averaged near 0
  2127  - [txindex/kv] [\#2925](https://github.com/tendermint/tendermint/issues/2925) Don't return false positives when range searching for a prefix of a tag value
  2128  - [types] [\#2938](https://github.com/tendermint/tendermint/issues/2938) Fix regression in v0.26.4 where we panic on empty
  2129    genDoc.Validators
  2130  - [types] [\#2941](https://github.com/tendermint/tendermint/issues/2941) Preserve val.Accum during ValidatorSet.Update to avoid it being
  2131    reset to 0 every time a validator is updated
  2132  
  2133  ## v0.26.4
  2134  
  2135  *November 27th, 2018*
  2136  
  2137  Special thanks to external contributors on this release:
  2138  @ackratos, @goolAdapter, @james-ray, @joe-bowman, @kostko,
  2139  @nagarajmanjunath, @tomtau
  2140  
  2141  Friendly reminder, we have a [bug bounty
  2142  program](https://hackerone.com/tendermint).
  2143  
  2144  ### FEATURES:
  2145  
  2146  - [rpc] [\#2747](https://github.com/tendermint/tendermint/issues/2747) Enable subscription to tags emitted from `BeginBlock`/`EndBlock` (@kostko)
  2147  - [types] [\#2747](https://github.com/tendermint/tendermint/issues/2747) Add `ResultBeginBlock` and `ResultEndBlock` fields to `EventDataNewBlock`
  2148      and `EventDataNewBlockHeader` to support subscriptions (@kostko)
  2149  - [types] [\#2918](https://github.com/tendermint/tendermint/issues/2918) Add Marshal, MarshalTo, Unmarshal methods to various structs
  2150    to support Protobuf compatibility (@nagarajmanjunath)
  2151  
  2152  ### IMPROVEMENTS:
  2153  
  2154  - [config] [\#2877](https://github.com/tendermint/tendermint/issues/2877) Add `blocktime_iota` to the config.toml (@ackratos)
  2155      - NOTE: this should be a ConsensusParam, not part of the config, and will be
  2156        removed from the config at a later date
  2157        ([\#2920](https://github.com/tendermint/tendermint/issues/2920).
  2158  - [mempool] [\#2882](https://github.com/tendermint/tendermint/issues/2882) Add txs from Update to cache
  2159  - [mempool] [\#2891](https://github.com/tendermint/tendermint/issues/2891) Remove local int64 counter from being stored in every tx
  2160  - [node] [\#2866](https://github.com/tendermint/tendermint/issues/2866) Add ability to instantiate IPCVal (@joe-bowman)
  2161  
  2162  ### BUG FIXES:
  2163  
  2164  - [blockchain] [\#2731](https://github.com/tendermint/tendermint/issues/2731) Retry both blocks if either is bad to avoid getting stuck during fast sync (@goolAdapter)
  2165  - [consensus] [\#2893](https://github.com/tendermint/tendermint/issues/2893) Use genDoc.Validators instead of state.NextValidators on replay when appHeight==0 (@james-ray)
  2166  - [log] [\#2868](https://github.com/tendermint/tendermint/issues/2868) Fix `module=main` setting overriding all others
  2167      - NOTE: this changes the default logging behaviour to be much less verbose.
  2168        Set `log_level="info"` to restore the previous behaviour.
  2169  - [rpc] [\#2808](https://github.com/tendermint/tendermint/issues/2808) Fix `accum` field in `/validators` by calling `IncrementAccum` if necessary
  2170  - [rpc] [\#2811](https://github.com/tendermint/tendermint/issues/2811) Allow integer IDs in JSON-RPC requests (@tomtau)
  2171  - [txindex/kv] [\#2759](https://github.com/tendermint/tendermint/issues/2759) Fix tx.height range queries
  2172  - [txindex/kv] [\#2775](https://github.com/tendermint/tendermint/issues/2775) Order tx results by index if height is the same
  2173  - [txindex/kv] [\#2908](https://github.com/tendermint/tendermint/issues/2908) Don't return false positives when searching for a prefix of a tag value
  2174  
  2175  ## v0.26.3
  2176  
  2177  *November 17th, 2018*
  2178  
  2179  Special thanks to external contributors on this release:
  2180  @danil-lashin, @kevlubkcm, @krhubert, @srmo
  2181  
  2182  Friendly reminder, we have a [bug bounty
  2183  program](https://hackerone.com/tendermint).
  2184  
  2185  ### BREAKING CHANGES:
  2186  
  2187  * Go API
  2188    - [rpc] [\#2791](https://github.com/tendermint/tendermint/issues/2791) Functions that start HTTP servers are now blocking:
  2189      - Impacts `StartHTTPServer`, `StartHTTPAndTLSServer`, and `StartGRPCServer`
  2190      - These functions now take a `net.Listener` instead of an address
  2191    - [rpc] [\#2767](https://github.com/tendermint/tendermint/issues/2767) Subscribing to events
  2192    `NewRound` and `CompleteProposal` return new types `EventDataNewRound` and
  2193    `EventDataCompleteProposal`, respectively, instead of the generic `EventDataRoundState`. (@kevlubkcm)
  2194  
  2195  ### FEATURES:
  2196  
  2197  - [log] [\#2843](https://github.com/tendermint/tendermint/issues/2843) New `log_format` config option, which can be set to 'plain' for colored
  2198    text or 'json' for JSON output
  2199  - [types] [\#2767](https://github.com/tendermint/tendermint/issues/2767) New event types EventDataNewRound (with ProposerInfo) and EventDataCompleteProposal (with BlockID). (@kevlubkcm)
  2200  
  2201  ### IMPROVEMENTS:
  2202  
  2203  - [dep] [\#2844](https://github.com/tendermint/tendermint/issues/2844) Dependencies are no longer pinned to an exact version in the
  2204    Gopkg.toml:
  2205    - Serialization libs are allowed to vary by patch release
  2206    - Other libs are allowed to vary by minor release
  2207  - [p2p] [\#2857](https://github.com/tendermint/tendermint/issues/2857) "Send failed" is logged at debug level instead of error.
  2208  - [rpc] [\#2780](https://github.com/tendermint/tendermint/issues/2780) Add read and write timeouts to HTTP servers
  2209  - [state] [\#2848](https://github.com/tendermint/tendermint/issues/2848) Make "Update to validators" msg value pretty (@danil-lashin)
  2210  
  2211  ### BUG FIXES:
  2212  - [consensus] [\#2819](https://github.com/tendermint/tendermint/issues/2819) Don't send proposalHearbeat if not a validator
  2213  - [docs] [\#2859](https://github.com/tendermint/tendermint/issues/2859) Fix ConsensusParams details in spec
  2214  - [libs/autofile] [\#2760](https://github.com/tendermint/tendermint/issues/2760) Comment out autofile permissions check - should fix
  2215    running Tendermint on Windows
  2216  - [p2p] [\#2869](https://github.com/tendermint/tendermint/issues/2869) Set connection config properly instead of always using default
  2217  - [p2p/pex] [\#2802](https://github.com/tendermint/tendermint/issues/2802) Seed mode fixes:
  2218    - Only disconnect from inbound peers
  2219    - Use FlushStop instead of Sleep to ensure all messages are sent before
  2220      disconnecting
  2221  
  2222  ## v0.26.2
  2223  
  2224  *November 15th, 2018*
  2225  
  2226  Special thanks to external contributors on this release: @hleb-albau, @zhuzeyu
  2227  
  2228  Friendly reminder, we have a [bug bounty program](https://hackerone.com/tendermint).
  2229  
  2230  ### FEATURES:
  2231  
  2232  - [rpc] [\#2582](https://github.com/tendermint/tendermint/issues/2582) Enable CORS on RPC API (@hleb-albau)
  2233  
  2234  ### BUG FIXES:
  2235  
  2236  - [abci] [\#2748](https://github.com/tendermint/tendermint/issues/2748) Unlock mutex in localClient so even when app panics (e.g. during CheckTx), consensus continue working
  2237  - [abci] [\#2748](https://github.com/tendermint/tendermint/issues/2748) Fix DATA RACE in localClient
  2238  - [amino] [\#2822](https://github.com/tendermint/tendermint/issues/2822) Update to v0.14.1 to support compiling on 32-bit platforms
  2239  - [rpc] [\#2748](https://github.com/tendermint/tendermint/issues/2748) Drain channel before calling Unsubscribe(All) in `/broadcast_tx_commit`
  2240  
  2241  ## v0.26.1
  2242  
  2243  *November 11, 2018*
  2244  
  2245  Special thanks to external contributors on this release: @katakonst
  2246  
  2247  Friendly reminder, we have a [bug bounty program](https://hackerone.com/tendermint).
  2248  
  2249  ### IMPROVEMENTS:
  2250  
  2251  - [consensus] [\#2704](https://github.com/tendermint/tendermint/issues/2704) Simplify valid POL round logic
  2252  - [docs] [\#2749](https://github.com/tendermint/tendermint/issues/2749) Deduplicate some ABCI docs
  2253  - [mempool] More detailed log messages
  2254      - [\#2724](https://github.com/tendermint/tendermint/issues/2724)
  2255      - [\#2762](https://github.com/tendermint/tendermint/issues/2762)
  2256  
  2257  ### BUG FIXES:
  2258  
  2259  - [autofile] [\#2703](https://github.com/tendermint/tendermint/issues/2703) Do not panic when checking Head size
  2260  - [crypto/merkle] [\#2756](https://github.com/tendermint/tendermint/issues/2756) Fix crypto/merkle ProofOperators.Verify to check bounds on keypath parts.
  2261  - [mempool] fix a bug where we create a WAL despite `wal_dir` being empty
  2262  - [p2p] [\#2771](https://github.com/tendermint/tendermint/issues/2771) Fix `peer-id` label name to `peer_id` in prometheus metrics
  2263  - [p2p] [\#2797](https://github.com/tendermint/tendermint/pull/2797) Fix IDs in peer NodeInfo and require them for addresses
  2264    in AddressBook
  2265  - [p2p] [\#2797](https://github.com/tendermint/tendermint/pull/2797) Do not close conn immediately after sending pex addrs in seed mode. Partial fix for [\#2092](https://github.com/tendermint/tendermint/issues/2092).
  2266  
  2267  ## v0.26.0
  2268  
  2269  *November 2, 2018*
  2270  
  2271  Special thanks to external contributors on this release:
  2272  @bradyjoestar, @connorwstein, @goolAdapter, @HaoyangLiu,
  2273  @james-ray, @overbool, @phymbert, @Slamper, @Uzair1995, @yutianwu.
  2274  
  2275  Special thanks to @Slamper for a series of bug reports in our [bug bounty
  2276  program](https://hackerone.com/tendermint) which are fixed in this release.
  2277  
  2278  This release is primarily about adding Version fields to various data structures,
  2279  optimizing consensus messages for signing and verification in
  2280  restricted environments (like HSMs and the Ethereum Virtual Machine), and
  2281  aligning the consensus code with the [specification](https://arxiv.org/abs/1807.04938).
  2282  It also includes our first take at a generalized merkle proof system, and
  2283  changes the length of hashes used for hashing data structures from 20 to 32
  2284  bytes.
  2285  
  2286  See the [UPGRADING.md](UPGRADING.md#v0.26.0) for details on upgrading to the new
  2287  version.
  2288  
  2289  Please note that we are still making breaking changes to the protocols.
  2290  While the new Version fields should help us to keep the software backwards compatible
  2291  even while upgrading the protocols, we cannot guarantee that new releases will
  2292  be compatible with old chains just yet. We expect there will be another breaking
  2293  release or two before the Cosmos Hub launch, but we will otherwise be paying
  2294  increasing attention to backwards compatibility. Thanks for bearing with us!
  2295  
  2296  ### BREAKING CHANGES:
  2297  
  2298  * CLI/RPC/Config
  2299    * [config] [\#2232](https://github.com/tendermint/tendermint/issues/2232) Timeouts are now strings like "3s" and "100ms", not ints
  2300    * [config] [\#2505](https://github.com/tendermint/tendermint/issues/2505) Remove Mempool.RecheckEmpty (it was effectively useless anyways)
  2301    * [config] [\#2490](https://github.com/tendermint/tendermint/issues/2490) `mempool.wal` is disabled by default
  2302    * [privval] [\#2459](https://github.com/tendermint/tendermint/issues/2459) Split `SocketPVMsg`s implementations into Request and Response, where the Response may contain a error message (returned by the remote signer)
  2303    * [state] [\#2644](https://github.com/tendermint/tendermint/issues/2644) Add Version field to State, breaking the format of State as
  2304      encoded on disk.
  2305    * [rpc] [\#2298](https://github.com/tendermint/tendermint/issues/2298) `/abci_query` takes `prove` argument instead of `trusted` and switches the default
  2306      behaviour to `prove=false`
  2307    * [rpc] [\#2654](https://github.com/tendermint/tendermint/issues/2654) Remove all `node_info.other.*_version` fields in `/status` and
  2308      `/net_info`
  2309    * [rpc] [\#2636](https://github.com/tendermint/tendermint/issues/2636) Remove
  2310      `_params` suffix from fields in `consensus_params`.
  2311  
  2312  * Apps
  2313    * [abci] [\#2298](https://github.com/tendermint/tendermint/issues/2298) ResponseQuery.Proof is now a structured merkle.Proof, not just
  2314      arbitrary bytes
  2315    * [abci] [\#2644](https://github.com/tendermint/tendermint/issues/2644) Add Version to Header and shift all fields by one
  2316    * [abci] [\#2662](https://github.com/tendermint/tendermint/issues/2662) Bump the field numbers for some `ResponseInfo` fields to make room for
  2317        `AppVersion`
  2318    * [abci] [\#2636](https://github.com/tendermint/tendermint/issues/2636) Updates to ConsensusParams
  2319      * Remove `Params` suffix from field names
  2320      * Add `Params` suffix to message types
  2321      * Add new field and type, `Validator ValidatorParams`, to control what types of validator keys are allowed.
  2322  
  2323  * Go API
  2324    * [config] [\#2232](https://github.com/tendermint/tendermint/issues/2232) Timeouts are time.Duration, not ints
  2325    * [crypto/merkle & lite] [\#2298](https://github.com/tendermint/tendermint/issues/2298) Various changes to accomodate General Merkle trees
  2326    * [crypto/merkle] [\#2595](https://github.com/tendermint/tendermint/issues/2595) Remove all Hasher objects in favor of byte slices
  2327    * [crypto/merkle] [\#2635](https://github.com/tendermint/tendermint/issues/2635) merkle.SimpleHashFromTwoHashes is no longer exported
  2328    * [node] [\#2479](https://github.com/tendermint/tendermint/issues/2479) Remove node.RunForever
  2329    * [rpc/client] [\#2298](https://github.com/tendermint/tendermint/issues/2298) `ABCIQueryOptions.Trusted` -> `ABCIQueryOptions.Prove`
  2330    * [types] [\#2298](https://github.com/tendermint/tendermint/issues/2298) Remove `Index` and `Total` fields from `TxProof`.
  2331    * [types] [\#2598](https://github.com/tendermint/tendermint/issues/2598)
  2332      `VoteTypeXxx` are now of type `SignedMsgType byte` and named `XxxType`, eg.
  2333      `PrevoteType`, `PrecommitType`.
  2334    * [types] [\#2636](https://github.com/tendermint/tendermint/issues/2636) Rename fields in ConsensusParams to remove `Params` suffixes
  2335    * [types] [\#2735](https://github.com/tendermint/tendermint/issues/2735) Simplify Proposal message to align with spec
  2336  
  2337  * Blockchain Protocol
  2338    * [crypto/tmhash] [\#2732](https://github.com/tendermint/tendermint/issues/2732) TMHASH is now full 32-byte SHA256
  2339      * All hashes in the block header and Merkle trees are now 32-bytes
  2340      * PubKey Addresses are still only 20-bytes
  2341    * [state] [\#2587](https://github.com/tendermint/tendermint/issues/2587) Require block.Time of the fist block to be genesis time
  2342    * [state] [\#2644](https://github.com/tendermint/tendermint/issues/2644) Require block.Version to match state.Version
  2343    * [types] Update SignBytes for `Vote`/`Proposal`/`Heartbeat`:
  2344      * [\#2459](https://github.com/tendermint/tendermint/issues/2459) Use amino encoding instead of JSON in `SignBytes`.
  2345      * [\#2598](https://github.com/tendermint/tendermint/issues/2598) Reorder fields and use fixed sized encoding.
  2346      * [\#2598](https://github.com/tendermint/tendermint/issues/2598) Change `Type` field from `string` to `byte` and use new
  2347        `SignedMsgType` to enumerate.
  2348    * [types] [\#2730](https://github.com/tendermint/tendermint/issues/2730) Use
  2349      same order for fields in `Vote` as in the SignBytes
  2350    * [types] [\#2732](https://github.com/tendermint/tendermint/issues/2732) Remove the address field from the validator hash
  2351    * [types] [\#2644](https://github.com/tendermint/tendermint/issues/2644) Add Version struct to Header
  2352    * [types] [\#2609](https://github.com/tendermint/tendermint/issues/2609) ConsensusParams.Hash() is the hash of the amino encoded
  2353      struct instead of the Merkle tree of the fields
  2354    * [types] [\#2670](https://github.com/tendermint/tendermint/issues/2670) Header.Hash() builds Merkle tree out of fields in the same
  2355      order they appear in the header, instead of sorting by field name
  2356    * [types] [\#2682](https://github.com/tendermint/tendermint/issues/2682) Use proto3 `varint` encoding for ints that are usually unsigned (instead of zigzag encoding).
  2357    * [types] [\#2636](https://github.com/tendermint/tendermint/issues/2636) Add Validator field to ConsensusParams
  2358        (Used to control which pubkey types validators can use, by abci type).
  2359  
  2360  * P2P Protocol
  2361    * [consensus] [\#2652](https://github.com/tendermint/tendermint/issues/2652)
  2362      Replace `CommitStepMessage` with `NewValidBlockMessage`
  2363    * [consensus] [\#2735](https://github.com/tendermint/tendermint/issues/2735) Simplify `Proposal` message to align with spec
  2364    * [consensus] [\#2730](https://github.com/tendermint/tendermint/issues/2730)
  2365      Add `Type` field to `Proposal` and use same order of fields as in the
  2366      SignBytes for both `Proposal` and `Vote`
  2367    * [p2p] [\#2654](https://github.com/tendermint/tendermint/issues/2654) Add `ProtocolVersion` struct with protocol versions to top of
  2368      DefaultNodeInfo and require `ProtocolVersion.Block` to match during peer handshake
  2369  
  2370  
  2371  ### FEATURES:
  2372  - [abci] [\#2557](https://github.com/tendermint/tendermint/issues/2557) Add `Codespace` field to `Response{CheckTx, DeliverTx, Query}`
  2373  - [abci] [\#2662](https://github.com/tendermint/tendermint/issues/2662) Add `BlockVersion` and `P2PVersion` to `RequestInfo`
  2374  - [crypto/merkle] [\#2298](https://github.com/tendermint/tendermint/issues/2298) General Merkle Proof scheme for chaining various types of Merkle trees together
  2375  - [docs/architecture] [\#1181](https://github.com/tendermint/tendermint/issues/1181) S
  2376  plit immutable and mutable parts of priv_validator.json
  2377  
  2378  ### IMPROVEMENTS:
  2379  - Additional Metrics
  2380      - [consensus] [\#2169](https://github.com/cosmos/cosmos-sdk/issues/2169)
  2381      - [p2p] [\#2169](https://github.com/cosmos/cosmos-sdk/issues/2169)
  2382  - [config] [\#2232](https://github.com/tendermint/tendermint/issues/2232) Added ValidateBasic method, which performs basic checks
  2383  - [crypto/ed25519] [\#2558](https://github.com/tendermint/tendermint/issues/2558) Switch to use latest `golang.org/x/crypto` through our fork at
  2384    github.com/tendermint/crypto
  2385  - [libs/log] [\#2707](https://github.com/tendermint/tendermint/issues/2707) Add year to log format (@yutianwu)
  2386  - [tools] [\#2238](https://github.com/tendermint/tendermint/issues/2238) Binary dependencies are now locked to a specific git commit
  2387  
  2388  ### BUG FIXES:
  2389  - [\#2711](https://github.com/tendermint/tendermint/issues/2711) Validate all incoming reactor messages. Fixes various bugs due to negative ints.
  2390  - [autofile] [\#2428](https://github.com/tendermint/tendermint/issues/2428) Group.RotateFile need call Flush() before rename (@goolAdapter)
  2391  - [common] [\#2533](https://github.com/tendermint/tendermint/issues/2533) Fixed a bug in the `BitArray.Or` method
  2392  - [common] [\#2506](https://github.com/tendermint/tendermint/issues/2506) Fixed a bug in the `BitArray.Sub` method (@james-ray)
  2393  - [common] [\#2534](https://github.com/tendermint/tendermint/issues/2534) Fix `BitArray.PickRandom` to choose uniformly from true bits
  2394  - [consensus] [\#1690](https://github.com/tendermint/tendermint/issues/1690) Wait for
  2395    timeoutPrecommit before starting next round
  2396  - [consensus] [\#1745](https://github.com/tendermint/tendermint/issues/1745) Wait for
  2397    Proposal or timeoutProposal before entering prevote
  2398  - [consensus] [\#2642](https://github.com/tendermint/tendermint/issues/2642) Only propose ValidBlock, not LockedBlock
  2399  - [consensus] [\#2642](https://github.com/tendermint/tendermint/issues/2642) Initialized ValidRound and LockedRound to -1
  2400  - [consensus] [\#1637](https://github.com/tendermint/tendermint/issues/1637) Limit the amount of evidence that can be included in a
  2401    block
  2402  - [consensus] [\#2652](https://github.com/tendermint/tendermint/issues/2652) Ensure valid block property with faulty proposer
  2403  - [evidence] [\#2515](https://github.com/tendermint/tendermint/issues/2515) Fix db iter leak (@goolAdapter)
  2404  - [libs/event] [\#2518](https://github.com/tendermint/tendermint/issues/2518) Fix event concurrency flaw (@goolAdapter)
  2405  - [node] [\#2434](https://github.com/tendermint/tendermint/issues/2434) Make node respond to signal interrupts while sleeping for genesis time
  2406  - [state] [\#2616](https://github.com/tendermint/tendermint/issues/2616) Pass nil to NewValidatorSet() when genesis file's Validators field is nil
  2407  - [p2p] [\#2555](https://github.com/tendermint/tendermint/issues/2555) Fix p2p switch FlushThrottle value (@goolAdapter)
  2408  - [p2p] [\#2668](https://github.com/tendermint/tendermint/issues/2668) Reconnect to originally dialed address (not self-reported address) for persistent peers
  2409  
  2410  ## v0.25.0
  2411  
  2412  *September 22, 2018*
  2413  
  2414  Special thanks to external contributors on this release:
  2415  @scriptionist, @bradyjoestar, @WALL-E
  2416  
  2417  This release is mostly about the ConsensusParams - removing fields and enforcing MaxGas.
  2418  It also addresses some issues found via security audit, removes various unused
  2419  functions from `libs/common`, and implements
  2420  [ADR-012](https://github.com/tendermint/tendermint/blob/develop/docs/architecture/adr-012-peer-transport.md).
  2421  
  2422  Friendly reminder, we have a [bug bounty program](https://hackerone.com/tendermint).
  2423  
  2424  BREAKING CHANGES:
  2425  
  2426  * CLI/RPC/Config
  2427    * [rpc] [\#2391](https://github.com/tendermint/tendermint/issues/2391) /status `result.node_info.other` became a map
  2428    * [types] [\#2364](https://github.com/tendermint/tendermint/issues/2364) Remove `TxSize` and `BlockGossip` from `ConsensusParams`
  2429      * Maximum tx size is now set implicitly via the `BlockSize.MaxBytes`
  2430      * The size of block parts in the consensus is now fixed to 64kB
  2431  
  2432  * Apps
  2433    * [mempool] [\#2360](https://github.com/tendermint/tendermint/issues/2360) Mempool tracks the `ResponseCheckTx.GasWanted` and
  2434      `ConsensusParams.BlockSize.MaxGas` and enforces:
  2435      - `GasWanted <= MaxGas` for every tx
  2436      - `(sum of GasWanted in block) <= MaxGas` for block proposal
  2437  
  2438  * Go API
  2439    * [libs/common] [\#2431](https://github.com/tendermint/tendermint/issues/2431) Remove Word256 due to lack of use
  2440    * [libs/common] [\#2452](https://github.com/tendermint/tendermint/issues/2452) Remove the following functions due to lack of use:
  2441      * byteslice.go: cmn.IsZeros, cmn.RightPadBytes, cmn.LeftPadBytes, cmn.PrefixEndBytes
  2442      * strings.go: cmn.IsHex, cmn.StripHex
  2443      * int.go: Uint64Slice, all put/get int64 methods
  2444  
  2445  FEATURES:
  2446  - [rpc] [\#2415](https://github.com/tendermint/tendermint/issues/2415) New `/consensus_params?height=X` endpoint to query the consensus
  2447    params at any height (@scriptonist)
  2448  - [types] [\#1714](https://github.com/tendermint/tendermint/issues/1714) Add Address to GenesisValidator
  2449  - [metrics] [\#2337](https://github.com/tendermint/tendermint/issues/2337) `consensus.block_interval_metrics` is now gauge, not histogram (you will be able to see spikes, if any)
  2450  - [libs] [\#2286](https://github.com/tendermint/tendermint/issues/2286) Panic if `autofile` or `db/fsdb` permissions change from 0600.
  2451  
  2452  IMPROVEMENTS:
  2453  - [libs/db] [\#2371](https://github.com/tendermint/tendermint/issues/2371) Output error instead of panic when the given `db_backend` is not initialised (@bradyjoestar)
  2454  - [mempool] [\#2399](https://github.com/tendermint/tendermint/issues/2399) Make mempool cache a proper LRU (@bradyjoestar)
  2455  - [p2p] [\#2126](https://github.com/tendermint/tendermint/issues/2126) Introduce PeerTransport interface to improve isolation of concerns
  2456  - [libs/common] [\#2326](https://github.com/tendermint/tendermint/issues/2326) Service returns ErrNotStarted
  2457  
  2458  BUG FIXES:
  2459  - [node] [\#2294](https://github.com/tendermint/tendermint/issues/2294) Delay starting node until Genesis time
  2460  - [consensus] [\#2048](https://github.com/tendermint/tendermint/issues/2048) Correct peer statistics for marking peer as good
  2461  - [rpc] [\#2460](https://github.com/tendermint/tendermint/issues/2460) StartHTTPAndTLSServer() now passes StartTLS() errors back to the caller rather than hanging forever.
  2462  - [p2p] [\#2047](https://github.com/tendermint/tendermint/issues/2047) Accept new connections asynchronously
  2463  - [tm-bench] [\#2410](https://github.com/tendermint/tendermint/issues/2410) Enforce minimum transaction size (@WALL-E)
  2464  
  2465  ## 0.24.0
  2466  
  2467  *September 6th, 2018*
  2468  
  2469  Special thanks to external contributors with PRs included in this release: ackratos, james-ray, bradyjoestar,
  2470  peerlink, Ahmah2009, bluele, b00f.
  2471  
  2472  This release includes breaking upgrades in the block header,
  2473  including the long awaited changes for delaying validator set updates by one
  2474  block to better support light clients.
  2475  It also fixes enforcement on the maximum size of blocks, and includes a BFT
  2476  timestamp in each block that can be safely used by applications.
  2477  There are also some minor breaking changes to the rpc, config, and ABCI.
  2478  
  2479  See the [UPGRADING.md](UPGRADING.md#v0.24.0) for details on upgrading to the new
  2480  version.
  2481  
  2482  From here on, breaking changes will be broken down to better reflect how users
  2483  are affected by a change.
  2484  
  2485  A few more breaking changes are in the works - each will come with a clear
  2486  Architecture Decision Record (ADR) explaining the change. You can review ADRs
  2487  [here](https://github.com/tendermint/tendermint/tree/develop/docs/architecture)
  2488  or in the [open Pull Requests](https://github.com/tendermint/tendermint/pulls).
  2489  You can also check in on the [issues marked as
  2490  breaking](https://github.com/tendermint/tendermint/issues?q=is%3Aopen+is%3Aissue+label%3Abreaking).
  2491  
  2492  BREAKING CHANGES:
  2493  
  2494  * CLI/RPC/Config
  2495    - [config] [\#2169](https://github.com/tendermint/tendermint/issues/2169) Replace MaxNumPeers with MaxNumInboundPeers and MaxNumOutboundPeers
  2496    - [config] [\#2300](https://github.com/tendermint/tendermint/issues/2300) Reduce default mempool size from 100k to 5k, until ABCI rechecking is implemented.
  2497    - [rpc] [\#1815](https://github.com/tendermint/tendermint/issues/1815) `/commit` returns a `signed_header` field instead of everything being top-level
  2498  
  2499  * Apps
  2500    - [abci] Added address of the original proposer of the block to Header
  2501    - [abci] Change ABCI Header to match Tendermint exactly
  2502    - [abci] [\#2159](https://github.com/tendermint/tendermint/issues/2159) Update use of `Validator` (see
  2503      [ADR-018](https://github.com/tendermint/tendermint/blob/develop/docs/architecture/adr-018-ABCI-Validators.md)):
  2504      - Remove PubKey from `Validator` (so it's just Address and Power)
  2505      - Introduce `ValidatorUpdate` (with just PubKey and Power)
  2506      - InitChain and EndBlock use ValidatorUpdate
  2507      - Update field names and types in BeginBlock
  2508    - [state] [\#1815](https://github.com/tendermint/tendermint/issues/1815) Validator set changes are now delayed by one block
  2509      - updates returned in ResponseEndBlock for block H will be included in RequestBeginBlock for block H+2
  2510  
  2511  * Go API
  2512    - [lite] [\#1815](https://github.com/tendermint/tendermint/issues/1815) Complete refactor of the package
  2513    - [node] [\#2212](https://github.com/tendermint/tendermint/issues/2212) NewNode now accepts a `*p2p.NodeKey` (@bradyjoestar)
  2514    - [libs/common] [\#2199](https://github.com/tendermint/tendermint/issues/2199) Remove Fmt, in favor of fmt.Sprintf
  2515    - [libs/common] SplitAndTrim was deleted
  2516    - [libs/common] [\#2274](https://github.com/tendermint/tendermint/issues/2274) Remove unused Math functions like MaxInt, MaxInt64,
  2517      MinInt, MinInt64 (@Ahmah2009)
  2518    - [libs/clist] Panics if list extends beyond MaxLength
  2519    - [crypto] [\#2205](https://github.com/tendermint/tendermint/issues/2205) Rename AminoRoute variables to no longer be prefixed by signature type.
  2520  
  2521  * Blockchain Protocol
  2522    - [state] [\#1815](https://github.com/tendermint/tendermint/issues/1815) Validator set changes are now delayed by one block (!)
  2523      - Add NextValidatorSet to State, changes on-disk representation of state
  2524    - [state] [\#2184](https://github.com/tendermint/tendermint/issues/2184) Enforce ConsensusParams.BlockSize.MaxBytes (See
  2525      [ADR-020](https://github.com/tendermint/tendermint/blob/develop/docs/architecture/adr-020-block-size.md)).
  2526      - Remove ConsensusParams.BlockSize.MaxTxs
  2527      - Introduce maximum sizes for all components of a block, including ChainID
  2528    - [types] Updates to the block Header:
  2529      - [\#1815](https://github.com/tendermint/tendermint/issues/1815) NextValidatorsHash - hash of the validator set for the next block,
  2530        so the current validators actually sign over the hash for the new
  2531        validators
  2532      - [\#2106](https://github.com/tendermint/tendermint/issues/2106) ProposerAddress - address of the block's original proposer
  2533    - [consensus] [\#2203](https://github.com/tendermint/tendermint/issues/2203) Implement BFT time
  2534      - Timestamp in block must be monotonic and equal the median of timestamps in block's LastCommit
  2535    - [crypto] [\#2239](https://github.com/tendermint/tendermint/issues/2239) Secp256k1 signature changes (See
  2536      [ADR-014](https://github.com/tendermint/tendermint/blob/develop/docs/architecture/adr-014-secp-malleability.md)):
  2537      - format changed from DER to `r || s`, both little endian encoded as 32 bytes.
  2538      - malleability removed by requiring `s` to be in canonical form.
  2539  
  2540  * P2P Protocol
  2541    - [p2p] [\#2263](https://github.com/tendermint/tendermint/issues/2263) Update secret connection to use a little endian encoded nonce
  2542    - [blockchain] [\#2213](https://github.com/tendermint/tendermint/issues/2213) Fix Amino routes for blockchain reactor messages
  2543      (@peerlink)
  2544  
  2545  
  2546  FEATURES:
  2547  - [types] [\#2015](https://github.com/tendermint/tendermint/issues/2015) Allow genesis file to have 0 validators (@b00f)
  2548    - Initial validator set can be determined by the app in ResponseInitChain
  2549  - [rpc] [\#2161](https://github.com/tendermint/tendermint/issues/2161) New event `ValidatorSetUpdates` for when the validator set changes
  2550  - [crypto/multisig] [\#2164](https://github.com/tendermint/tendermint/issues/2164) Introduce multisig pubkey and signature format
  2551  - [libs/db] [\#2293](https://github.com/tendermint/tendermint/issues/2293) Allow passing options through when creating instances of leveldb dbs
  2552  
  2553  IMPROVEMENTS:
  2554  - [docs] Lint documentation with `write-good` and `stop-words`.
  2555  - [docs] [\#2249](https://github.com/tendermint/tendermint/issues/2249) Refactor, deduplicate, and improve the ABCI docs and spec (with thanks to @ttmc).
  2556  - [scripts] [\#2196](https://github.com/tendermint/tendermint/issues/2196) Added json2wal tool, which is supposed to help our users restore (@bradyjoestar)
  2557    corrupted WAL files and compose test WAL files (@bradyjoestar)
  2558  - [mempool] [\#2234](https://github.com/tendermint/tendermint/issues/2234) Now stores txs by hash inside of the cache, to mitigate memory leakage
  2559  - [mempool] [\#2166](https://github.com/tendermint/tendermint/issues/2166) Set explicit capacity for map when updating txs (@bluele)
  2560  
  2561  BUG FIXES:
  2562  - [config] [\#2284](https://github.com/tendermint/tendermint/issues/2284) Replace `db_path` with `db_dir` from automatically generated configuration files.
  2563  - [mempool] [\#2188](https://github.com/tendermint/tendermint/issues/2188) Fix OOM issue from cache map and list getting out of sync
  2564  - [state] [\#2051](https://github.com/tendermint/tendermint/issues/2051) KV store index supports searching by `tx.height` (@ackratos)
  2565  - [rpc] [\#2327](https://github.com/tendermint/tendermint/issues/2327) `/dial_peers` does not try to dial existing peers
  2566  - [node] [\#2323](https://github.com/tendermint/tendermint/issues/2323) Filter empty strings from config lists (@james-ray)
  2567  - [abci/client] [\#2236](https://github.com/tendermint/tendermint/issues/2236) Fix closing GRPC connection (@bradyjoestar)
  2568  
  2569  ## 0.23.1
  2570  
  2571  *August 22nd, 2018*
  2572  
  2573  BUG FIXES:
  2574  - [libs/autofile] [\#2261](https://github.com/tendermint/tendermint/issues/2261) Fix log rotation so it actually happens.
  2575      - Fixes issues with consensus WAL growing unbounded ala [\#2259](https://github.com/tendermint/tendermint/issues/2259)
  2576  
  2577  ## 0.23.0
  2578  
  2579  *August 5th, 2018*
  2580  
  2581  This release includes breaking upgrades in our P2P encryption,
  2582  some ABCI messages, and how we encode time and signatures.
  2583  
  2584  A few more changes are still coming to the Header, ABCI,
  2585  and validator set handling to better support light clients, BFT time, and
  2586  upgrades. Most notably, validator set changes will be delayed by one block (see
  2587  [#1815][i1815]).
  2588  
  2589  We also removed `make ensure_deps` in favour of `make get_vendor_deps`.
  2590  
  2591  BREAKING CHANGES:
  2592  - [abci] Changed time format from int64 to google.protobuf.Timestamp
  2593  - [abci] Changed Validators to LastCommitInfo in RequestBeginBlock
  2594  - [abci] Removed Fee from ResponseDeliverTx and ResponseCheckTx
  2595  - [crypto] Switch crypto.Signature from interface to []byte for space efficiency
  2596    [#2128](https://github.com/tendermint/tendermint/pull/2128)
  2597      - NOTE: this means signatures no longer have the prefix bytes in Amino
  2598        binary nor the `type` field in Amino JSON. They're just bytes.
  2599  - [p2p] Remove salsa and ripemd primitives, in favor of using chacha as a stream cipher, and hkdf [#2054](https://github.com/tendermint/tendermint/pull/2054)
  2600  - [tools] Removed `make ensure_deps` in favor of `make get_vendor_deps`
  2601  - [types] CanonicalTime uses nanoseconds instead of clipping to ms
  2602      - breaks serialization/signing of all messages with a timestamp
  2603  
  2604  FEATURES:
  2605  - [tools] Added `make check_dep`
  2606      - ensures gopkg.lock is synced with gopkg.toml
  2607      - ensures no branches are used in the gopkg.toml
  2608  
  2609  IMPROVEMENTS:
  2610  - [blockchain] Improve fast-sync logic
  2611    [#1805](https://github.com/tendermint/tendermint/pull/1805)
  2612      - tweak params
  2613      - only process one block at a time to avoid starving
  2614  - [common] bit array functions which take in another parameter are now thread safe
  2615  - [crypto] Switch hkdfchachapoly1305 to xchachapoly1305
  2616  - [p2p] begin connecting to peers as soon a seed node provides them to you ([#2093](https://github.com/tendermint/tendermint/issues/2093))
  2617  
  2618  BUG FIXES:
  2619  - [common] Safely handle cases where atomic write files already exist [#2109](https://github.com/tendermint/tendermint/issues/2109)
  2620  - [privval] fix a deadline for accepting new connections in socket private
  2621    validator.
  2622  - [p2p] Allow startup if a configured seed node's IP can't be resolved ([#1716](https://github.com/tendermint/tendermint/issues/1716))
  2623  - [node] Fully exit when CTRL-C is pressed even if consensus state panics [#2072](https://github.com/tendermint/tendermint/issues/2072)
  2624  
  2625  [i1815]: https://github.com/tendermint/tendermint/pull/1815
  2626  
  2627  ## 0.22.8
  2628  
  2629  *July 26th, 2018*
  2630  
  2631  BUG FIXES
  2632  
  2633  - [consensus, blockchain] Fix 0.22.7 below.
  2634  
  2635  ## 0.22.7
  2636  
  2637  *July 26th, 2018*
  2638  
  2639  BUG FIXES
  2640  
  2641  - [consensus, blockchain] Register the Evidence interface so it can be
  2642    marshalled/unmarshalled by the blockchain and consensus reactors
  2643  
  2644  ## 0.22.6
  2645  
  2646  *July 24th, 2018*
  2647  
  2648  BUG FIXES
  2649  
  2650  - [rpc] Fix `/blockchain` endpoint
  2651      - (#2049) Fix OOM attack by returning error on negative input
  2652      - Fix result length to have max 20 (instead of 21) block metas
  2653  - [rpc] Validate height is non-negative in `/abci_query`
  2654  - [consensus] (#2050) Include evidence in proposal block parts (previously evidence was
  2655    not being included in blocks!)
  2656  - [p2p] (#2046) Close rejected inbound connections so file descriptor doesn't
  2657    leak
  2658  - [Gopkg] (#2053) Fix versions in the toml
  2659  
  2660  ## 0.22.5
  2661  
  2662  *July 23th, 2018*
  2663  
  2664  BREAKING CHANGES:
  2665  - [crypto] Refactor `tendermint/crypto` into many subpackages
  2666  - [libs/common] remove exponentially distributed random numbers
  2667  
  2668  IMPROVEMENTS:
  2669  - [abci, libs/common] Generated gogoproto static marshaller methods
  2670  - [config] Increase default send/recv rates to 5 mB/s
  2671  - [p2p] reject addresses coming from private peers
  2672  - [p2p] allow persistent peers to be private
  2673  
  2674  BUG FIXES:
  2675  - [mempool] fixed a race condition when `create_empty_blocks=false` where a
  2676    transaction is published at an old height.
  2677  - [p2p] dial external IP setup by `persistent_peers`, not internal NAT IP
  2678  - [rpc] make `/status` RPC endpoint resistant to consensus halt
  2679  
  2680  ## 0.22.4
  2681  
  2682  *July 14th, 2018*
  2683  
  2684  BREAKING CHANGES:
  2685  - [genesis] removed deprecated `app_options` field.
  2686  - [types] Genesis.AppStateJSON -> Genesis.AppState
  2687  
  2688  FEATURES:
  2689  - [tools] Merged in from github.com/tendermint/tools
  2690  
  2691  BUG FIXES:
  2692  - [tools/tm-bench] Various fixes
  2693  - [consensus] Wait for WAL to stop on shutdown
  2694  - [abci] Fix #1891, pending requests cannot hang when abci server dies.
  2695    Previously a crash in BeginBlock could leave tendermint in broken state.
  2696  
  2697  ## 0.22.3
  2698  
  2699  *July 10th, 2018*
  2700  
  2701  IMPROVEMENTS
  2702  - Update dependencies
  2703      * pin all values in Gopkg.toml to version or commit
  2704      * update golang/protobuf to v1.1.0
  2705  
  2706  ## 0.22.2
  2707  
  2708  *July 10th, 2018*
  2709  
  2710  IMPROVEMENTS
  2711  - More cleanup post repo merge!
  2712  - [docs] Include `ecosystem.json` and `tendermint-bft.md` from deprecated `aib-data` repository.
  2713  - [config] Add `instrumentation.max_open_connections`, which limits the number
  2714    of requests in flight to Prometheus server (if enabled). Default: 3.
  2715  
  2716  
  2717  BUG FIXES
  2718  - [rpc] Allow unquoted integers in requests
  2719      - NOTE: this is only for URI requests. JSONRPC requests and all responses
  2720        will use quoted integers (the proto3 JSON standard).
  2721  - [consensus] Fix halt on shutdown
  2722  
  2723  ## 0.22.1
  2724  
  2725  *July 5th, 2018*
  2726  
  2727  IMPROVEMENTS
  2728  
  2729  * Cleanup post repo-merge.
  2730  * [docs] Various improvements.
  2731  
  2732  BUG FIXES
  2733  
  2734  * [state] Return error when EndBlock returns a 0-power validator that isn't
  2735    already in the validator set.
  2736  * [consensus] Shut down WAL properly.
  2737  
  2738  
  2739  ## 0.22.0
  2740  
  2741  *July 2nd, 2018*
  2742  
  2743  BREAKING CHANGES:
  2744  - [config]
  2745      * Remove `max_block_size_txs` and `max_block_size_bytes` in favor of
  2746          consensus params from the genesis file.
  2747      * Rename `skip_upnp` to `upnp`, and turn it off by default.
  2748      * Change `max_packet_msg_size` back to `max_packet_msg_payload_size`
  2749  - [rpc]
  2750      * All integers are encoded as strings (part of the update for Amino v0.10.1)
  2751      * `syncing` is now called `catching_up`
  2752  - [types] Update Amino to v0.10.1
  2753      * Amino is now fully proto3 compatible for the basic types
  2754      * JSON-encoded types now use the type name instead of the prefix bytes
  2755      * Integers are encoded as strings
  2756  - [crypto] Update go-crypto to v0.10.0 and merge into `crypto`
  2757      * privKey.Sign returns error.
  2758      * ed25519 address changed to the first 20-bytes of the SHA256 of the raw pubkey bytes
  2759      * `tmlibs/merkle` -> `crypto/merkle`. Uses SHA256 instead of RIPEMD160
  2760  - [tmlibs] Update to v0.9.0 and merge into `libs`
  2761      * remove `merkle` package (moved to `crypto/merkle`)
  2762  
  2763  FEATURES
  2764  - [cmd] Added metrics (served under `/metrics` using a Prometheus client;
  2765    disabled by default). See the new `instrumentation` section in the config and
  2766    [metrics](https://tendermint.readthedocs.io/projects/tools/en/develop/metrics.html)
  2767    guide.
  2768  - [p2p] Add IPv6 support to peering.
  2769  - [p2p] Add `external_address` to config to allow specifying the address for
  2770    peers to dial
  2771  
  2772  IMPROVEMENT
  2773  - [rpc/client] Supports https and wss now.
  2774  - [crypto] Make public key size into public constants
  2775  - [mempool] Log tx hash, not entire tx
  2776  - [abci] Merged in github.com/tendermint/abci
  2777  - [crypto] Merged in github.com/tendermint/go-crypto
  2778  - [libs] Merged in github.com/tendermint/tmlibs
  2779  - [docs] Move from .rst to .md
  2780  
  2781  BUG FIXES:
  2782  - [rpc] Limit maximum number of HTTP/WebSocket connections
  2783    (`rpc.max_open_connections`) and gRPC connections
  2784    (`rpc.grpc_max_open_connections`). Check out "Running In Production" guide if
  2785    you want to increase them.
  2786  - [rpc] Limit maximum request body size to 1MB (header is limited to 1MB).
  2787  - [consensus] Fix a halting bug where `create_empty_blocks=false`
  2788  - [p2p] Fix panic in seed mode
  2789  
  2790  ## 0.21.0
  2791  
  2792  *June 21th, 2018*
  2793  
  2794  BREAKING CHANGES
  2795  
  2796  - [config] Change default ports from 4665X to 2665X. Ports over 32768 are
  2797    ephemeral and reserved for use by the kernel.
  2798  - [cmd] `unsafe_reset_all` removes the addrbook.json
  2799  
  2800  IMPROVEMENT
  2801  
  2802  - [pubsub] Set default capacity to 0
  2803  - [docs] Various improvements
  2804  
  2805  BUG FIXES
  2806  
  2807  - [consensus] Fix an issue where we don't make blocks after `fast_sync` when `create_empty_blocks=false`
  2808  - [mempool] Fix #1761 where we don't process txs if `cache_size=0`
  2809  - [rpc] Fix memory leak in Websocket (when using `/subscribe` method)
  2810  - [config] Escape paths in config - fixes config paths on Windows
  2811  
  2812  ## 0.20.0
  2813  
  2814  *June 6th, 2018*
  2815  
  2816  This is the first in a series of breaking releases coming to Tendermint after
  2817  soliciting developer feedback and conducting security audits.
  2818  
  2819  This release does not break any blockchain data structures or
  2820  protocols other than the ABCI messages between Tendermint and the application.
  2821  
  2822  Applications that upgrade for ABCI v0.11.0 should be able to continue running Tendermint
  2823  v0.20.0 on blockchains created with v0.19.X
  2824  
  2825  BREAKING CHANGES
  2826  
  2827  - [abci] Upgrade to
  2828    [v0.11.0](https://github.com/tendermint/abci/blob/master/CHANGELOG.md#0110)
  2829  - [abci] Change Query path for filtering peers by node ID from
  2830    `p2p/filter/pubkey/<id>` to `p2p/filter/id/<id>`
  2831  
  2832  ## 0.19.9
  2833  
  2834  *June 5th, 2018*
  2835  
  2836  BREAKING CHANGES
  2837  
  2838  - [types/priv_validator] Moved to top level `privval` package
  2839  
  2840  FEATURES
  2841  
  2842  - [config] Collapse PeerConfig into P2PConfig
  2843  - [docs] Add quick-install script
  2844  - [docs/spec] Add table of Amino prefixes
  2845  
  2846  BUG FIXES
  2847  
  2848  - [rpc] Return 404 for unknown endpoints
  2849  - [consensus] Flush WAL on stop
  2850  - [evidence] Don't send evidence to peers that are behind
  2851  - [p2p] Fix memory leak on peer disconnects
  2852  - [rpc] Fix panic when `per_page=0`
  2853  
  2854  ## 0.19.8
  2855  
  2856  *June 4th, 2018*
  2857  
  2858  BREAKING:
  2859  
  2860  - [p2p] Remove `auth_enc` config option, peer connections are always auth
  2861    encrypted. Technically a breaking change but seems no one was using it and
  2862    arguably a bug fix :)
  2863  
  2864  BUG FIXES
  2865  
  2866  - [mempool] Fix deadlock under high load when `skip_timeout_commit=true` and
  2867    `create_empty_blocks=false`
  2868  
  2869  ## 0.19.7
  2870  
  2871  *May 31st, 2018*
  2872  
  2873  BREAKING:
  2874  
  2875  - [libs/pubsub] TagMap#Get returns a string value
  2876  - [libs/pubsub] NewTagMap accepts a map of strings
  2877  
  2878  FEATURES
  2879  
  2880  - [rpc] the RPC documentation is now published to https://tendermint.github.io/slate
  2881  - [p2p] AllowDuplicateIP config option to refuse connections from same IP.
  2882      - true by default for now, false by default in next breaking release
  2883  - [docs] Add docs for query, tx indexing, events, pubsub
  2884  - [docs] Add some notes about running Tendermint in production
  2885  
  2886  IMPROVEMENTS:
  2887  
  2888  - [consensus] Consensus reactor now receives events from a separate synchronous event bus,
  2889    which is not dependant on external RPC load
  2890  - [consensus/wal] do not look for height in older files if we've seen height - 1
  2891  - [docs] Various cleanup and link fixes
  2892  
  2893  ## 0.19.6
  2894  
  2895  *May 29th, 2018*
  2896  
  2897  BUG FIXES
  2898  
  2899  - [blockchain] Fix fast-sync deadlock during high peer turnover
  2900  
  2901  BUG FIX:
  2902  
  2903  - [evidence] Dont send peers evidence from heights they haven't synced to yet
  2904  - [p2p] Refuse connections to more than one peer with the same IP
  2905  - [docs] Various fixes
  2906  
  2907  ## 0.19.5
  2908  
  2909  *May 20th, 2018*
  2910  
  2911  BREAKING CHANGES
  2912  
  2913  - [rpc/client] TxSearch and UnconfirmedTxs have new arguments (see below)
  2914  - [rpc/client] TxSearch returns ResultTxSearch
  2915  - [version] Breaking changes to Go APIs will not be reflected in breaking
  2916    version change, but will be included in changelog.
  2917  
  2918  FEATURES
  2919  
  2920  - [rpc] `/tx_search` takes `page` (starts at 1) and `per_page` (max 100, default 30) args to paginate results
  2921  - [rpc] `/unconfirmed_txs` takes `limit` (max 100, default 30) arg to limit the output
  2922  - [config] `mempool.size` and `mempool.cache_size` options
  2923  
  2924  IMPROVEMENTS
  2925  
  2926  - [docs] Lots of updates
  2927  - [consensus] Only Fsync() the WAL before executing msgs from ourselves
  2928  
  2929  BUG FIXES
  2930  
  2931  - [mempool] Enforce upper bound on number of transactions
  2932  
  2933  ## 0.19.4 (May 17th, 2018)
  2934  
  2935  IMPROVEMENTS
  2936  
  2937  - [state] Improve tx indexing by using batches
  2938  - [consensus, state] Improve logging (more consensus logs, fewer tx logs)
  2939  - [spec] Moved to `docs/spec` (TODO cleanup the rest of the docs ...)
  2940  
  2941  BUG FIXES
  2942  
  2943  - [consensus] Fix issue #1575 where a late proposer can get stuck
  2944  
  2945  ## 0.19.3 (May 14th, 2018)
  2946  
  2947  FEATURES
  2948  
  2949  - [rpc] New `/consensus_state` returns just the votes seen at the current height
  2950  
  2951  IMPROVEMENTS
  2952  
  2953  - [rpc] Add stringified votes and fraction of power voted to `/dump_consensus_state`
  2954  - [rpc] Add PeerStateStats to `/dump_consensus_state`
  2955  
  2956  BUG FIXES
  2957  
  2958  - [cmd] Set GenesisTime during `tendermint init`
  2959  - [consensus] fix ValidBlock rules
  2960  
  2961  ## 0.19.2 (April 30th, 2018)
  2962  
  2963  FEATURES:
  2964  
  2965  - [p2p] Allow peers with different Minor versions to connect
  2966  - [rpc] `/net_info` includes `n_peers`
  2967  
  2968  IMPROVEMENTS:
  2969  
  2970  - [p2p] Various code comments, cleanup, error types
  2971  - [p2p] Change some Error logs to Debug
  2972  
  2973  BUG FIXES:
  2974  
  2975  - [p2p] Fix reconnect to persistent peer when first dial fails
  2976  - [p2p] Validate NodeInfo.ListenAddr
  2977  - [p2p] Only allow (MaxNumPeers - MaxNumOutboundPeers) inbound peers
  2978  - [p2p/pex] Limit max msg size to 64kB
  2979  - [p2p] Fix panic when pex=false
  2980  - [p2p] Allow multiple IPs per ID in AddrBook
  2981  - [p2p] Fix before/after bugs in addrbook isBad()
  2982  
  2983  ## 0.19.1 (April 27th, 2018)
  2984  
  2985  Note this release includes some small breaking changes in the RPC and one in the
  2986  config that are really bug fixes. v0.19.1 will work with existing chains, and make Tendermint
  2987  easier to use and debug. With <3
  2988  
  2989  BREAKING (MINOR)
  2990  
  2991  - [config] Removed `wal_light` setting. If you really needed this, let us know
  2992  
  2993  FEATURES:
  2994  
  2995  - [networks] moved in tooling from devops repo: terraform and ansible scripts for deploying testnets !
  2996  - [cmd] Added `gen_node_key` command
  2997  
  2998  BUG FIXES
  2999  
  3000  Some of these are breaking in the RPC response, but they're really bugs!
  3001  
  3002  - [spec] Document address format and pubkey encoding pre and post Amino
  3003  - [rpc] Lower case JSON field names
  3004  - [rpc] Fix missing entries, improve, and lower case the fields in `/dump_consensus_state`
  3005  - [rpc] Fix NodeInfo.Channels format to hex
  3006  - [rpc] Add Validator address to `/status`
  3007  - [rpc] Fix `prove` in ABCIQuery
  3008  - [cmd] MarshalJSONIndent on init
  3009  
  3010  ## 0.19.0 (April 13th, 2018)
  3011  
  3012  BREAKING:
  3013  - [cmd] improved `testnet` command; now it can fill in `persistent_peers` for you in the config file and much more (see `tendermint testnet --help` for details)
  3014  - [cmd] `show_node_id` now returns an error if there is no node key
  3015  - [rpc]: changed the output format for the `/status` endpoint (see https://godoc.org/github.com/tendermint/tendermint/rpc/core#Status)
  3016  
  3017  Upgrade from go-wire to go-amino. This is a sweeping change that breaks everything that is
  3018  serialized to disk or over the network.
  3019  
  3020  See github.com/tendermint/go-amino for details on the new format.
  3021  
  3022  See `scripts/wire2amino.go` for a tool to upgrade
  3023  genesis/priv_validator/node_key JSON files.
  3024  
  3025  FEATURES
  3026  
  3027  - [test] docker-compose for local testnet setup (thanks Greg!)
  3028  
  3029  ## 0.18.0 (April 6th, 2018)
  3030  
  3031  BREAKING:
  3032  
  3033  - [types] Merkle tree uses different encoding for varints (see tmlibs v0.8.0)
  3034  - [types] ValidtorSet.GetByAddress returns -1 if no validator found
  3035  - [p2p] require all addresses come with an ID no matter what
  3036  - [rpc] Listening address must contain tcp:// or unix:// prefix
  3037  
  3038  FEATURES:
  3039  
  3040  - [rpc] StartHTTPAndTLSServer (not used yet)
  3041  - [rpc] Include validator's voting power in `/status`
  3042  - [rpc] `/tx` and `/tx_search` responses now include the transaction hash
  3043  - [rpc] Include peer NodeIDs in `/net_info`
  3044  
  3045  IMPROVEMENTS:
  3046  - [config] trim whitespace from elements of lists (like `persistent_peers`)
  3047  - [rpc] `/tx_search` results are sorted by height
  3048  - [p2p] do not try to connect to ourselves (ok, maybe only once)
  3049  - [p2p] seeds respond with a bias towards good peers
  3050  
  3051  BUG FIXES:
  3052  - [rpc] fix subscribing using an abci.ResponseDeliverTx tag
  3053  - [rpc] fix tx_indexers matchRange
  3054  - [rpc] fix unsubscribing (see tmlibs v0.8.0)
  3055  
  3056  ## 0.17.1 (March 27th, 2018)
  3057  
  3058  BUG FIXES:
  3059  - [types] Actually support `app_state` in genesis as `AppStateJSON`
  3060  
  3061  ## 0.17.0 (March 27th, 2018)
  3062  
  3063  BREAKING:
  3064  - [types] WriteSignBytes -> SignBytes
  3065  
  3066  IMPROVEMENTS:
  3067  - [all] renamed `dummy` (`persistent_dummy`) to `kvstore` (`persistent_kvstore`) (name "dummy" is deprecated and will not work in the next breaking release)
  3068  - [docs] note on determinism (docs/determinism.rst)
  3069  - [genesis] `app_options` field is deprecated. please rename it to `app_state` in your genesis file(s). `app_options` will not work in the next breaking release
  3070  - [p2p] dial seeds directly without potential peers
  3071  - [p2p] exponential backoff for addrs in the address book
  3072  - [p2p] mark peer as good if it contributed enough votes or block parts
  3073  - [p2p] stop peer if it sends incorrect data, msg to unknown channel, msg we did not expect
  3074  - [p2p] when `auth_enc` is true, all dialed peers must have a node ID in their address
  3075  - [spec] various improvements
  3076  - switched from glide to dep internally for package management
  3077  - [wire] prep work for upgrading to new go-wire (which is now called go-amino)
  3078  
  3079  FEATURES:
  3080  - [config] exposed `auth_enc` flag to enable/disable encryption
  3081  - [config] added the `--p2p.private_peer_ids` flag and `PrivatePeerIDs` config variable (see config for description)
  3082  - [rpc] added `/health` endpoint, which returns empty result for now
  3083  - [types/priv_validator] new format and socket client, allowing for remote signing
  3084  
  3085  BUG FIXES:
  3086  - [consensus] fix liveness bug by introducing ValidBlock mechanism
  3087  
  3088  ## 0.16.0 (February 20th, 2018)
  3089  
  3090  BREAKING CHANGES:
  3091  - [config] use $TMHOME/config for all config and json files
  3092  - [p2p] old `--p2p.seeds` is now `--p2p.persistent_peers` (persistent peers to which TM will always connect to)
  3093  - [p2p] now `--p2p.seeds` only used for getting addresses (if addrbook is empty; not persistent)
  3094  - [p2p] NodeInfo: remove RemoteAddr and add Channels
  3095      - we must have at least one overlapping channel with peer
  3096      - we only send msgs for channels the peer advertised
  3097  - [p2p/conn] pong timeout
  3098  - [lite] comment out IAVL related code
  3099  
  3100  FEATURES:
  3101  - [p2p] added new `/dial_peers&persistent=_` **unsafe** endpoint
  3102  - [p2p] persistent node key in `$THMHOME/config/node_key.json`
  3103  - [p2p] introduce peer ID and authenticate peers by ID using addresses like `ID@IP:PORT`
  3104  - [p2p/pex] new seed mode crawls the network and serves as a seed.
  3105  - [config] MempoolConfig.CacheSize
  3106  - [config] P2P.SeedMode (`--p2p.seed_mode`)
  3107  
  3108  IMPROVEMENT:
  3109  - [p2p/pex] stricter rules in the PEX reactor for better handling of abuse
  3110  - [p2p] various improvements to code structure including subpackages for `pex` and `conn`
  3111  - [docs] new spec!
  3112  - [all] speed up the tests!
  3113  
  3114  BUG FIX:
  3115  - [blockchain] StopPeerForError on timeout
  3116  - [consensus] StopPeerForError on a bad Maj23 message
  3117  - [state] flush mempool conn before calling commit
  3118  - [types] fix priv val signing things that only differ by timestamp
  3119  - [mempool] fix memory leak causing zombie peers
  3120  - [p2p/conn] fix potential deadlock
  3121  
  3122  ## 0.15.0 (December 29, 2017)
  3123  
  3124  BREAKING CHANGES:
  3125  - [p2p] enable the Peer Exchange reactor by default
  3126  - [types] add Timestamp field to Proposal/Vote
  3127  - [types] add new fields to Header: TotalTxs, ConsensusParamsHash, LastResultsHash, EvidenceHash
  3128  - [types] add Evidence to Block
  3129  - [types] simplify ValidateBasic
  3130  - [state] updates to support changes to the header
  3131  - [state] Enforce <1/3 of validator set can change at a time
  3132  
  3133  FEATURES:
  3134  - [state] Send indices of absent validators and addresses of byzantine validators in BeginBlock
  3135  - [state] Historical ConsensusParams and ABCIResponses
  3136  - [docs] Specification for the base Tendermint data structures.
  3137  - [evidence] New evidence reactor for gossiping and managing evidence
  3138  - [rpc] `/block_results?height=X` returns the DeliverTx results for a given height.
  3139  
  3140  IMPROVEMENTS:
  3141  - [consensus] Better handling of corrupt WAL file
  3142  
  3143  BUG FIXES:
  3144  - [lite] fix race
  3145  - [state] validate block.Header.ValidatorsHash
  3146  - [p2p] allow seed addresses to be prefixed with eg. `tcp://`
  3147  - [p2p] use consistent key to refer to peers so we dont try to connect to existing peers
  3148  - [cmd] fix `tendermint init` to ignore files that are there and generate files that aren't.
  3149  
  3150  ## 0.14.0 (December 11, 2017)
  3151  
  3152  BREAKING CHANGES:
  3153  - consensus/wal: removed separator
  3154  - rpc/client: changed Subscribe/Unsubscribe/UnsubscribeAll funcs signatures to be identical to event bus.
  3155  
  3156  FEATURES:
  3157  - new `tendermint lite` command (and `lite/proxy` pkg) for running a light-client RPC proxy.
  3158      NOTE it is currently insecure and its APIs are not yet covered by semver
  3159  
  3160  IMPROVEMENTS:
  3161  - rpc/client: can act as event bus subscriber (See https://github.com/tendermint/tendermint/issues/945).
  3162  - p2p: use exponential backoff from seconds to hours when attempting to reconnect to persistent peer
  3163  - config: moniker defaults to the machine's hostname instead of "anonymous"
  3164  
  3165  BUG FIXES:
  3166  - p2p: no longer exit if one of the seed addresses is incorrect
  3167  
  3168  ## 0.13.0 (December 6, 2017)
  3169  
  3170  BREAKING CHANGES:
  3171  - abci: update to v0.8 using gogo/protobuf; includes tx tags, vote info in RequestBeginBlock, data.Bytes everywhere, use int64, etc.
  3172  - types: block heights are now `int64` everywhere
  3173  - types & node: EventSwitch and EventCache have been replaced by EventBus and EventBuffer; event types have been overhauled
  3174  - node: EventSwitch methods now refer to EventBus
  3175  - rpc/lib/types: RPCResponse is no longer a pointer; WSRPCConnection interface has been modified
  3176  - rpc/client: WaitForOneEvent takes an EventsClient instead of types.EventSwitch
  3177  - rpc/client: Add/RemoveListenerForEvent are now Subscribe/Unsubscribe
  3178  - rpc/core/types: ResultABCIQuery wraps an abci.ResponseQuery
  3179  - rpc: `/subscribe` and `/unsubscribe` take `query` arg instead of `event`
  3180  - rpc: `/status` returns the LatestBlockTime in human readable form instead of in nanoseconds
  3181  - mempool: cached transactions return an error instead of an ABCI response with BadNonce
  3182  
  3183  FEATURES:
  3184  - rpc: new `/unsubscribe_all` WebSocket RPC endpoint
  3185  - rpc: new `/tx_search` endpoint for filtering transactions by more complex queries
  3186  - p2p/trust: new trust metric for tracking peers. See ADR-006
  3187  - config: TxIndexConfig allows to set what DeliverTx tags to index
  3188  
  3189  IMPROVEMENTS:
  3190  - New asynchronous events system using `tmlibs/pubsub`
  3191  - logging: Various small improvements
  3192  - consensus: Graceful shutdown when app crashes
  3193  - tests: Fix various non-deterministic errors
  3194  - p2p: more defensive programming
  3195  
  3196  BUG FIXES:
  3197  - consensus: fix panic where prs.ProposalBlockParts is not initialized
  3198  - p2p: fix panic on bad channel
  3199  
  3200  ## 0.12.1 (November 27, 2017)
  3201  
  3202  BUG FIXES:
  3203  - upgrade tmlibs dependency to enable Windows builds for Tendermint
  3204  
  3205  ## 0.12.0 (October 27, 2017)
  3206  
  3207  BREAKING CHANGES:
  3208   - rpc/client: websocket ResultsCh and ErrorsCh unified in ResponsesCh.
  3209   - rpc/client: ABCIQuery no longer takes `prove`
  3210   - state: remove GenesisDoc from state.
  3211   - consensus: new binary WAL format provides efficiency and uses checksums to detect corruption
  3212      - use scripts/wal2json to convert to json for debugging
  3213  
  3214  FEATURES:
  3215   - new `Verifiers` pkg contains the tendermint light-client library (name subject to change)!
  3216   - rpc: `/genesis` includes the `app_options` .
  3217   - rpc: `/abci_query` takes an additional `height` parameter to support historical queries.
  3218   - rpc/client: new ABCIQueryWithOptions supports options like `trusted` (set false to get a proof) and `height` to query a historical height.
  3219  
  3220  IMPROVEMENTS:
  3221   - rpc: `/genesis` result includes `app_options`
  3222   - rpc/lib/client: add jitter to reconnects.
  3223   - rpc/lib/types: `RPCError` satisfies the `error` interface.
  3224  
  3225  BUG FIXES:
  3226   - rpc/client: fix ws deadlock after stopping
  3227   - blockchain: fix panic on AddBlock when peer is nil
  3228   - mempool: fix sending on TxsAvailable when a tx has been invalidated
  3229   - consensus: dont run WAL catchup if we fast synced
  3230  
  3231  ## 0.11.1 (October 10, 2017)
  3232  
  3233  IMPROVEMENTS:
  3234   - blockchain/reactor: respondWithNoResponseMessage for missing height
  3235  
  3236  BUG FIXES:
  3237   - rpc: fixed client WebSocket timeout
  3238   - rpc: client now resubscribes on reconnection
  3239   - rpc: fix panics on missing params
  3240   - rpc: fix `/dump_consensus_state` to have normal json output (NOTE: technically breaking, but worth a bug fix label)
  3241   - types: fixed out of range error in VoteSet.addVote
  3242   - consensus: fix wal autofile via https://github.com/tendermint/tmlibs/blob/master/CHANGELOG.md#032-october-2-2017
  3243  
  3244  ## 0.11.0 (September 22, 2017)
  3245  
  3246  BREAKING:
  3247   - genesis file: validator `amount` is now `power`
  3248   - abci: Info, BeginBlock, InitChain all take structs
  3249   - rpc: various changes to match JSONRPC spec (http://www.jsonrpc.org/specification), including breaking ones:
  3250      - requests that previously returned HTTP code 4XX now return 200 with an error code in the JSONRPC.
  3251      - `rpctypes.RPCResponse` uses new `RPCError` type instead of `string`.
  3252  
  3253   - cmd: if there is no genesis, exit immediately instead of waiting around for one to show.
  3254   - types: `Signer.Sign` returns an error.
  3255   - state: every validator set change is persisted to disk, which required some changes to the `State` structure.
  3256   - p2p: new `p2p.Peer` interface used for all reactor methods (instead of `*p2p.Peer` struct).
  3257  
  3258  FEATURES:
  3259   - rpc: `/validators?height=X` allows querying of validators at previous heights.
  3260   - rpc: Leaving the `height` param empty for `/block`, `/validators`, and `/commit` will return the value for the latest height.
  3261  
  3262  IMPROVEMENTS:
  3263   - docs: Moved all docs from the website and tools repo in, converted to `.rst`, and cleaned up for presentation on `tendermint.readthedocs.io`
  3264  
  3265  BUG FIXES:
  3266   - fix WAL openning issue on Windows
  3267  
  3268  ## 0.10.4 (September 5, 2017)
  3269  
  3270  IMPROVEMENTS:
  3271  - docs: Added Slate docs to each rpc function (see rpc/core)
  3272  - docs: Ported all website docs to Read The Docs
  3273  - config: expose some p2p params to tweak performance: RecvRate, SendRate, and MaxMsgPacketPayloadSize
  3274  - rpc: Upgrade the websocket client and server, including improved auto reconnect, and proper ping/pong
  3275  
  3276  BUG FIXES:
  3277  - consensus: fix panic on getVoteBitArray
  3278  - consensus: hang instead of panicking on byzantine consensus failures
  3279  - cmd: dont load config for version command
  3280  
  3281  ## 0.10.3 (August 10, 2017)
  3282  
  3283  FEATURES:
  3284  - control over empty block production:
  3285    - new flag, `--consensus.create_empty_blocks`; when set to false, blocks are only created when there are txs or when the AppHash changes.
  3286    - new config option, `consensus.create_empty_blocks_interval`; an empty block is created after this many seconds.
  3287    - in normal operation, `create_empty_blocks = true` and `create_empty_blocks_interval = 0`, so blocks are being created all the time (as in all previous versions of tendermint). The number of empty blocks can be reduced by increasing `create_empty_blocks_interval` or by setting `create_empty_blocks = false`.
  3288    - new `TxsAvailable()` method added to Mempool that returns a channel which fires when txs are available.
  3289    - new heartbeat message added to consensus reactor to notify peers that a node is waiting for txs before entering propose step.
  3290  - rpc: Add `syncing` field to response returned by `/status`. Is `true` while in fast-sync mode.
  3291  
  3292  IMPROVEMENTS:
  3293  - various improvements to documentation and code comments
  3294  
  3295  BUG FIXES:
  3296  - mempool: pass height into constructor so it doesn't always start at 0
  3297  
  3298  ## 0.10.2 (July 10, 2017)
  3299  
  3300  FEATURES:
  3301  - Enable lower latency block commits by adding consensus reactor sleep durations and p2p flush throttle timeout to the config
  3302  
  3303  IMPROVEMENTS:
  3304  - More detailed logging in the consensus reactor and state machine
  3305  - More in-code documentation for many exposed functions, especially in consensus/reactor.go and p2p/switch.go
  3306  - Improved readability for some function definitions and code blocks with long lines
  3307  
  3308  ## 0.10.1 (June 28, 2017)
  3309  
  3310  FEATURES:
  3311  - Use `--trace` to get stack traces for logged errors
  3312  - types: GenesisDoc.ValidatorHash returns the hash of the genesis validator set
  3313  - types: GenesisDocFromFile parses a GenesiDoc from a JSON file
  3314  
  3315  IMPROVEMENTS:
  3316  - Add a Code of Conduct
  3317  - Variety of improvements as suggested by `megacheck` tool
  3318  - rpc: deduplicate tests between rpc/client and rpc/tests
  3319  - rpc: addresses without a protocol prefix default to `tcp://`. `http://` is also accepted as an alias for `tcp://`
  3320  - cmd: commands are more easily reuseable from other tools
  3321  - DOCKER: automate build/push
  3322  
  3323  BUG FIXES:
  3324  - Fix log statements using keys with spaces (logger does not currently support spaces)
  3325  - rpc: set logger on websocket connection
  3326  - rpc: fix ws connection stability by setting write deadline on pings
  3327  
  3328  ## 0.10.0 (June 2, 2017)
  3329  
  3330  Includes major updates to configuration, logging, and json serialization.
  3331  Also includes the Grand Repo-Merge of 2017.
  3332  
  3333  BREAKING CHANGES:
  3334  
  3335  - Config and Flags:
  3336    - The `config` map is replaced with a [`Config` struct](https://github.com/tendermint/tendermint/blob/master/config/config.go#L11),
  3337  containing substructs: `BaseConfig`, `P2PConfig`, `MempoolConfig`, `ConsensusConfig`, `RPCConfig`
  3338    - This affects the following flags:
  3339      - `--seeds` is now `--p2p.seeds`
  3340      - `--node_laddr` is now `--p2p.laddr`
  3341      - `--pex` is now `--p2p.pex`
  3342      - `--skip_upnp` is now `--p2p.skip_upnp`
  3343      - `--rpc_laddr` is now `--rpc.laddr`
  3344      - `--grpc_laddr` is now `--rpc.grpc_laddr`
  3345    - Any configuration option now within a substract must come under that heading in the `config.toml`, for instance:
  3346      ```
  3347      [p2p]
  3348      laddr="tcp://1.2.3.4:46656"
  3349  
  3350      [consensus]
  3351      timeout_propose=1000
  3352      ```
  3353    - Use viper and `DefaultConfig() / TestConfig()` functions to handle defaults, and remove `config/tendermint` and `config/tendermint_test`
  3354    - Change some function and method signatures to
  3355    - Change some [function and method signatures](https://gist.github.com/ebuchman/640d5fc6c2605f73497992fe107ebe0b) accomodate new config
  3356  
  3357  - Logger
  3358    - Replace static `log15` logger with a simple interface, and provide a new implementation using `go-kit`.
  3359  See our new [logging library](https://github.com/tendermint/tmlibs/log) and [blog post](https://tendermint.com/blog/abstracting-the-logger-interface-in-go) for more details
  3360    - Levels `warn` and `notice` are removed (you may need to change them in your `config.toml`!)
  3361    - Change some [function and method signatures](https://gist.github.com/ebuchman/640d5fc6c2605f73497992fe107ebe0b) to accept a logger
  3362  
  3363  - JSON serialization:
  3364    - Replace `[TypeByte, Xxx]` with `{"type": "some-type", "data": Xxx}` in RPC and all `.json` files by using `go-wire/data`. For instance, a public key is now:
  3365      ```
  3366      "pub_key": {
  3367        "type": "ed25519",
  3368        "data": "83DDF8775937A4A12A2704269E2729FCFCD491B933C4B0A7FFE37FE41D7760D0"
  3369      }
  3370      ```
  3371    - Remove type information about RPC responses, so `[TypeByte, {"jsonrpc": "2.0", ... }]` is now just `{"jsonrpc": "2.0", ... }`
  3372    - Change `[]byte` to `data.Bytes` in all serialized types (for hex encoding)
  3373    - Lowercase the JSON tags in `ValidatorSet` fields
  3374    - Introduce `EventDataInner` for serializing events
  3375  
  3376  - Other:
  3377    - Send InitChain message in handshake if `appBlockHeight == 0`
  3378    - Do not include the `Accum` field when computing the validator hash. This makes the ValidatorSetHash unique for a given validator set, rather than changing with every block (as the Accum changes)
  3379    - Unsafe RPC calls are not enabled by default. This includes `/dial_seeds`, and all calls prefixed with `unsafe`. Use the `--rpc.unsafe` flag to enable.
  3380  
  3381  
  3382  FEATURES:
  3383  
  3384  - Per-module log levels. For instance, the new default is `state:info,*:error`, which means the `state` package logs at `info` level, and everything else logs at `error` level
  3385  - Log if a node is validator or not in every consensus round
  3386  - Use ldflags to set git hash as part of the version
  3387  - Ignore `address` and `pub_key` fields in `priv_validator.json` and overwrite them with the values derrived from the `priv_key`
  3388  
  3389  IMPROVEMENTS:
  3390  
  3391  - Merge `tendermint/go-p2p -> tendermint/tendermint/p2p` and `tendermint/go-rpc -> tendermint/tendermint/rpc/lib`
  3392  - Update paths for grand repo merge:
  3393    - `go-common -> tmlibs/common`
  3394    - `go-data -> go-wire/data`
  3395    - All other `go-` libs, except `go-crypto` and `go-wire`, are merged under `tmlibs`
  3396  - No global loggers (loggers are passed into constructors, or preferably set with a SetLogger method)
  3397  - Return HTTP status codes with errors for RPC responses
  3398  - Limit `/blockchain_info` call to return a maximum of 20 blocks
  3399  - Use `.Wrap()` and `.Unwrap()` instead of eg. `PubKeyS` for `go-crypto` types
  3400  - RPC JSON responses use pretty printing (via `json.MarshalIndent`)
  3401  - Color code different instances of the consensus for tests
  3402  - Isolate viper to `cmd/tendermint/commands` and do not read config from file for tests
  3403  
  3404  
  3405  ## 0.9.2 (April 26, 2017)
  3406  
  3407  BUG FIXES:
  3408  
  3409  - Fix bug in `ResetPrivValidator` where we were using the global config and log (causing external consumers, eg. basecoin, to fail).
  3410  
  3411  ## 0.9.1 (April 21, 2017)
  3412  
  3413  FEATURES:
  3414  
  3415  - Transaction indexing - txs are indexed by their hash using a simple key-value store; easily extended to more advanced indexers
  3416  - New `/tx?hash=X` endpoint to query for transactions and their DeliverTx result by hash. Optionally returns a proof of the tx's inclusion in the block
  3417  - `tendermint testnet` command initializes files for a testnet
  3418  
  3419  IMPROVEMENTS:
  3420  
  3421  - CLI now uses Cobra framework
  3422  - TMROOT is now TMHOME (TMROOT will stop working in 0.10.0)
  3423  - `/broadcast_tx_XXX` also returns the Hash (can be used to query for the tx)
  3424  - `/broadcast_tx_commit` also returns the height the block was committed in
  3425  - ABCIResponses struct persisted to disk before calling Commit; makes handshake replay much cleaner
  3426  - WAL uses #ENDHEIGHT instead of #HEIGHT (#HEIGHT will stop working in 0.10.0)
  3427  - Peers included via `--seeds`, under `seeds` in the config, or in `/dial_seeds` are now persistent, and will be reconnected to if the connection breaks
  3428  
  3429  BUG FIXES:
  3430  
  3431  - Fix bug in fast-sync where we stop syncing after a peer is removed, even if they're re-added later
  3432  - Fix handshake replay to handle validator set changes and results of DeliverTx when we crash after app.Commit but before state.Save()
  3433  
  3434  ## 0.9.0 (March 6, 2017)
  3435  
  3436  BREAKING CHANGES:
  3437  
  3438  - Update ABCI to v0.4.0, where Query is now `Query(RequestQuery) ResponseQuery`, enabling precise proofs at particular heights:
  3439  
  3440  ```
  3441  message RequestQuery{
  3442  	bytes data = 1;
  3443  	string path = 2;
  3444  	uint64 height = 3;
  3445  	bool prove = 4;
  3446  }
  3447  
  3448  message ResponseQuery{
  3449  	CodeType          code        = 1;
  3450  	int64             index       = 2;
  3451  	bytes             key         = 3;
  3452  	bytes             value       = 4;
  3453  	bytes             proof       = 5;
  3454  	uint64            height      = 6;
  3455  	string            log         = 7;
  3456  }
  3457  ```
  3458  
  3459  
  3460  - `BlockMeta` data type unifies its Hash and PartSetHash under a `BlockID`:
  3461  
  3462  ```
  3463  type BlockMeta struct {
  3464  	BlockID BlockID `json:"block_id"` // the block hash and partsethash
  3465  	Header  *Header `json:"header"`   // The block's Header
  3466  }
  3467  ```
  3468  
  3469  - `ValidatorSet.Proposer` is exposed as a field and persisted with the `State`. Use `GetProposer()` to initialize or update after validator-set changes.
  3470  
  3471  - `tendermint gen_validator` command output is now pure JSON
  3472  
  3473  FEATURES:
  3474  
  3475  - New RPC endpoint `/commit?height=X` returns header and commit for block at height `X`
  3476  - Client API for each endpoint, including mocks for testing
  3477  
  3478  IMPROVEMENTS:
  3479  
  3480  - `Node` is now a `BaseService`
  3481  - Simplified starting Tendermint in-process from another application
  3482  - Better organized Makefile
  3483  - Scripts for auto-building binaries across platforms
  3484  - Docker image improved, slimmed down (using Alpine), and changed from tendermint/tmbase to tendermint/tendermint
  3485  - New repo files: `CONTRIBUTING.md`, Github `ISSUE_TEMPLATE`, `CHANGELOG.md`
  3486  - Improvements on CircleCI for managing build/test artifacts
  3487  - Handshake replay is doen through the consensus package, possibly using a mockApp
  3488  - Graceful shutdown of RPC listeners
  3489  - Tests for the PEX reactor and DialSeeds
  3490  
  3491  BUG FIXES:
  3492  
  3493  - Check peer.Send for failure before updating PeerState in consensus
  3494  - Fix panic in `/dial_seeds` with invalid addresses
  3495  - Fix proposer selection logic in ValidatorSet by taking the address into account in the `accumComparable`
  3496  - Fix inconcistencies with `ValidatorSet.Proposer` across restarts by persisting it in the `State`
  3497  
  3498  
  3499  ## 0.8.0 (January 13, 2017)
  3500  
  3501  BREAKING CHANGES:
  3502  
  3503  - New data type `BlockID` to represent blocks:
  3504  
  3505  ```
  3506  type BlockID struct {
  3507  	Hash        []byte        `json:"hash"`
  3508  	PartsHeader PartSetHeader `json:"parts"`
  3509  }
  3510  ```
  3511  
  3512  - `Vote` data type now includes validator address and index:
  3513  
  3514  ```
  3515  type Vote struct {
  3516  	ValidatorAddress []byte           `json:"validator_address"`
  3517  	ValidatorIndex   int              `json:"validator_index"`
  3518  	Height           int              `json:"height"`
  3519  	Round            int              `json:"round"`
  3520  	Type             byte             `json:"type"`
  3521  	BlockID          BlockID          `json:"block_id"` // zero if vote is nil.
  3522  	Signature        crypto.Signature `json:"signature"`
  3523  }
  3524  ```
  3525  
  3526  - Update TMSP to v0.3.0, where it is now called ABCI and AppendTx is DeliverTx
  3527  - Hex strings in the RPC are now "0x" prefixed
  3528  
  3529  
  3530  FEATURES:
  3531  
  3532  - New message type on the ConsensusReactor, `Maj23Msg`, for peers to alert others they've seen a Maj23,
  3533  in order to track and handle conflicting votes intelligently to prevent Byzantine faults from causing halts:
  3534  
  3535  ```
  3536  type VoteSetMaj23Message struct {
  3537  	Height  int
  3538  	Round   int
  3539  	Type    byte
  3540  	BlockID types.BlockID
  3541  }
  3542  ```
  3543  
  3544  - Configurable block part set size
  3545  - Validator set changes
  3546  - Optionally skip TimeoutCommit if we have all the votes
  3547  - Handshake between Tendermint and App on startup to sync latest state and ensure consistent recovery from crashes
  3548  - GRPC server for BroadcastTx endpoint
  3549  
  3550  IMPROVEMENTS:
  3551  
  3552  - Less verbose logging
  3553  - Better test coverage (37% -> 49%)
  3554  - Canonical SignBytes for signable types
  3555  - Write-Ahead Log for Mempool and Consensus via tmlibs/autofile
  3556  - Better in-process testing for the consensus reactor and byzantine faults
  3557  - Better crash/restart testing for individual nodes at preset failure points, and of networks at arbitrary points
  3558  - Better abstraction over timeout mechanics
  3559  
  3560  BUG FIXES:
  3561  
  3562  - Fix memory leak in mempool peer
  3563  - Fix panic on POLRound=-1
  3564  - Actually set the CommitTime
  3565  - Actually send BeginBlock message
  3566  - Fix a liveness issues caused by Byzantine proposals/votes. Uses the new `Maj23Msg`.
  3567  
  3568  
  3569  ## 0.7.4 (December 14, 2016)
  3570  
  3571  FEATURES:
  3572  
  3573  - Enable the Peer Exchange reactor with the `--pex` flag for more resilient gossip network (feature still in development, beware dragons)
  3574  
  3575  IMPROVEMENTS:
  3576  
  3577  - Remove restrictions on RPC endpoint `/dial_seeds` to enable manual network configuration
  3578  
  3579  ## 0.7.3 (October 20, 2016)
  3580  
  3581  IMPROVEMENTS:
  3582  
  3583  - Type safe FireEvent
  3584  - More WAL/replay tests
  3585  - Cleanup some docs
  3586  
  3587  BUG FIXES:
  3588  
  3589  - Fix deadlock in mempool for synchronous apps
  3590  - Replay handles non-empty blocks
  3591  - Fix race condition in HeightVoteSet
  3592  
  3593  ## 0.7.2 (September 11, 2016)
  3594  
  3595  BUG FIXES:
  3596  
  3597  - Set mustConnect=false so tendermint will retry connecting to the app
  3598  
  3599  ## 0.7.1 (September 10, 2016)
  3600  
  3601  FEATURES:
  3602  
  3603  - New TMSP connection for Query/Info
  3604  - New RPC endpoints:
  3605  	- `tmsp_query`
  3606  	- `tmsp_info`
  3607  - Allow application to filter peers through Query (off by default)
  3608  
  3609  IMPROVEMENTS:
  3610  
  3611  - TMSP connection type enforced at compile time
  3612  - All listen/client urls use a "tcp://" or "unix://" prefix
  3613  
  3614  BUG FIXES:
  3615  
  3616  - Save LastSignature/LastSignBytes to `priv_validator.json` for recovery
  3617  - Fix event unsubscribe
  3618  - Fix fastsync/blockchain reactor
  3619  
  3620  ## 0.7.0 (August 7, 2016)
  3621  
  3622  BREAKING CHANGES:
  3623  
  3624  - Strict SemVer starting now!
  3625  - Update to ABCI v0.2.0
  3626  - Validation types now called Commit
  3627  - NewBlock event only returns the block header
  3628  
  3629  
  3630  FEATURES:
  3631  
  3632  - TMSP and RPC support TCP and UNIX sockets
  3633  - Addition config options including block size and consensus parameters
  3634  - New WAL mode `cswal_light`; logs only the validator's own votes
  3635  - New RPC endpoints:
  3636  	- for starting/stopping profilers, and for updating config
  3637  	- `/broadcast_tx_commit`, returns when tx is included in a block, else an error
  3638  	- `/unsafe_flush_mempool`, empties the mempool
  3639  
  3640  
  3641  IMPROVEMENTS:
  3642  
  3643  - Various optimizations
  3644  - Remove bad or invalidated transactions from the mempool cache (allows later duplicates)
  3645  - More elaborate testing using CircleCI including benchmarking throughput on 4 digitalocean droplets
  3646  
  3647  BUG FIXES:
  3648  
  3649  - Various fixes to WAL and replay logic
  3650  - Various race conditions
  3651  
  3652  ## PreHistory
  3653  
  3654  Strict versioning only began with the release of v0.7.0, in late summer 2016.
  3655  The project itself began in early summer 2014 and was workable decentralized cryptocurrency software by the end of that year.
  3656  Through the course of 2015, in collaboration with Eris Industries (now Monax Industries),
  3657  many additional features were integrated, including an implementation from scratch of the Ethereum Virtual Machine.
  3658  That implementation now forms the heart of [Burrow](https://github.com/hyperledger/burrow).
  3659  In the later half of 2015, the consensus algorithm was upgraded with a more asynchronous design and a more deterministic and robust implementation.
  3660  
  3661  By late 2015, frustration with the difficulty of forking a large monolithic stack to create alternative cryptocurrency designs led to the
  3662  invention of the Application Blockchain Interface (ABCI), then called the Tendermint Socket Protocol (TMSP).
  3663  The Ethereum Virtual Machine and various other transaction features were removed, and Tendermint was whittled down to a core consensus engine
  3664  driving an application running in another process.
  3665  The ABCI interface and implementation were iterated on and improved over the course of 2016,
  3666  until versioned history kicked in with v0.7.0.