github.com/project-88388/tendermint-v0.34.14-terra.2@v1.0.0/CHANGELOG.md (about) 1 # Changelog 2 3 Friendly reminder, we have a [bug bounty program](https://hackerone.com/cosmos). 4 5 ## v0.34.14 6 7 This release backports the `rollback` feature to allow recovery in the event of an incorrect app hash. 8 9 ### FEATURES 10 11 - [\#6982](https://github.com/tendermint/tendermint/pull/6982) The tendermint binary now has built-in suppport for running the end-to-end test application (with state sync support) (@cmwaters). 12 - [cli] [#7033](https://github.com/tendermint/tendermint/pull/7033) Add a `rollback` command to rollback to the previous tendermint state. This may be useful in the event of non-determinstic app hash or when reverting an upgrade. @cmwaters 13 14 ### IMPROVEMENTS 15 16 - [\#7103](https://github.com/tendermint/tendermint/pull/7104) Remove IAVL dependency (backport of #6550) (@cmwaters) 17 18 ### BUG FIXES 19 20 - [\#7057](https://github.com/tendermint/tendermint/pull/7057) Import Postgres driver support for the psql indexer (@creachadair). 21 - [ABCI] [\#7110](https://github.com/tendermint/tendermint/issues/7110) Revert "change client to use multi-reader mutexes (#6873)" (@tychoish). 22 23 ## v0.34.13 24 25 This release backports improvements to state synchronization and ABCI 26 performance under concurrent load, and the PostgreSQL event indexer. 27 28 ### IMPROVEMENTS 29 30 - [statesync] [\#6881](https://github.com/tendermint/tendermint/issues/6881) improvements to stateprovider logic (@cmwaters) 31 - [ABCI] [\#6873](https://github.com/tendermint/tendermint/issues/6873) change client to use multi-reader mutexes (@tychoish) 32 - [indexing] [\#6906](https://github.com/tendermint/tendermint/issues/6906) enable the PostgreSQL indexer sink (@creachadair) 33 34 ## v0.34.12 35 36 Special thanks to external contributors on this release: @JayT106. 37 38 ### FEATURES 39 40 - [rpc] [\#6717](https://github.com/tendermint/tendermint/pull/6717) introduce 41 `/genesis_chunked` rpc endpoint for handling large genesis files by chunking them (@tychoish) 42 43 ### IMPROVEMENTS 44 45 - [rpc] [\#6825](https://github.com/tendermint/tendermint/issues/6825) Remove egregious INFO log from `ABCI#Query` RPC. (@alexanderbez) 46 47 ### BUG FIXES 48 49 - [light] [\#6685](https://github.com/tendermint/tendermint/pull/6685) fix bug 50 with incorrectly handling contexts that would occasionally freeze state sync. (@cmwaters) 51 - [privval] [\#6748](https://github.com/tendermint/tendermint/issues/6748) Fix vote timestamp to prevent chain halt (@JayT106) 52 53 ## v0.34.11 54 55 *June 18, 2021* 56 57 This release improves the robustness of statesync; tweaking channel priorities and timeouts and 58 adding two new parameters to the state sync config. 59 60 ### BREAKING CHANGES 61 62 - Apps 63 - [Version] [\#6494](https://github.com/tendermint/tendermint/issues/6494) `TMCoreSemVer` is not required to be set as a ldflag any longer. 64 65 ### IMPROVEMENTS 66 67 - [statesync] [\#6566](https://github.com/tendermint/tendermint/issues/6566) Allow state sync fetchers and request timeout to be configurable. (@alexanderbez) 68 - [statesync] [\#6378](https://github.com/tendermint/tendermint/issues/6378) Retry requests for snapshots and add a minimum discovery time (5s) for new snapshots. (@tychoish) 69 - [statesync] [\#6582](https://github.com/tendermint/tendermint/issues/6582) Increase chunk priority and add multiple retry chunk requests (@cmwaters) 70 71 ### BUG FIXES 72 73 - [evidence] [\#6375](https://github.com/tendermint/tendermint/issues/6375) Fix bug with inconsistent LightClientAttackEvidence hashing (@cmwaters) 74 75 ## v0.34.10 76 77 *April 14, 2021* 78 79 This release fixes a bug where peers would sometimes try to send messages 80 on incorrect channels. Special thanks to our friends at Oasis Labs for surfacing 81 this issue! 82 83 - [p2p/node] [\#6339](https://github.com/tendermint/tendermint/issues/6339) Fix bug with using custom channels (@cmwaters) 84 - [light] [\#6346](https://github.com/tendermint/tendermint/issues/6346) Correctly handle too high errors to improve client robustness (@cmwaters) 85 86 ## v0.34.9 87 88 *April 8, 2021* 89 90 This release fixes a moderate severity security issue, Security Advisory Alderfly, 91 which impacts all networks that rely on Tendermint light clients. 92 Further details will be released once networks have upgraded. 93 94 This release also includes a small Go API-breaking change, to reduce panics in the RPC layer. 95 96 Special thanks to our external contributors on this release: @gchaincl 97 98 ### BREAKING CHANGES 99 100 - Go API 101 - [rpc/jsonrpc/server] [\#6204](https://github.com/tendermint/tendermint/issues/6204) Modify `WriteRPCResponseHTTP(Error)` to return an error (@melekes) 102 103 ### FEATURES 104 105 - [rpc] [\#6226](https://github.com/tendermint/tendermint/issues/6226) Index block events and expose a new RPC method, `/block_search`, to allow querying for blocks by `BeginBlock` and `EndBlock` events (@alexanderbez) 106 107 ### BUG FIXES 108 109 - [rpc/jsonrpc/server] [\#6191](https://github.com/tendermint/tendermint/issues/6191) Correctly unmarshal `RPCRequest` when data is `null` (@melekes) 110 - [p2p] [\#6289](https://github.com/tendermint/tendermint/issues/6289) Fix "unknown channels" bug on CustomReactors (@gchaincl) 111 - [light/evidence] Adds logic to handle forward lunatic attacks (@cmwaters) 112 113 ## v0.34.8 114 115 *February 25, 2021* 116 117 This release, in conjunction with [a fix in the Cosmos SDK](https://github.com/cosmos/cosmos-sdk/pull/8641), 118 introduces changes that should mean the logs are much, much quieter. 🎉 119 120 ### IMPROVEMENTS 121 122 - [libs/log] [\#6174](https://github.com/tendermint/tendermint/issues/6174) Include timestamp (`ts` field; `time.RFC3339Nano` format) in JSON logger output (@melekes) 123 124 ### BUG FIXES 125 126 - [abci] [\#6124](https://github.com/tendermint/tendermint/issues/6124) Fixes a panic condition during callback execution in `ReCheckTx` during high tx load. (@alexanderbez) 127 128 ## v0.34.7 129 130 *February 18, 2021* 131 132 This release fixes a downstream security issue which impacts Cosmos SDK 133 users who are: 134 135 * Using Cosmos SDK v0.40.0 or later, AND 136 * Running validator nodes, AND 137 * Using the file-based `FilePV` implementation for their consensus keys 138 139 Users who fulfill all the above criteria were susceptible to leaking 140 private key material in the logs. All other users are unaffected. 141 142 The root cause was a discrepancy 143 between the Tendermint Core (untyped) logger and the Cosmos SDK (typed) logger: 144 Tendermint Core's logger automatically stringifies Go interfaces whenever possible; 145 however, the Cosmos SDK's logger uses reflection to log the fields within a Go interface. 146 147 The introduction of the typed logger meant that previously un-logged fields within 148 interfaces are now sometimes logged, including the private key material inside the 149 `FilePV` struct. 150 151 Tendermint Core v0.34.7 fixes this issue; however, we strongly recommend that all validators 152 use remote signer implementations instead of `FilePV` in production. 153 154 Thank you to @joe-bowman for his assistance with this vulnerability and a particular 155 shout-out to @marbar3778 for diagnosing it quickly. 156 157 ### BUG FIXES 158 159 - [consensus] [\#6128](https://github.com/tendermint/tendermint/pull/6128) Remove privValidator from log call (@tessr) 160 161 ## v0.34.6 162 163 *February 18, 2021* 164 165 _Tendermint Core v0.34.5 and v0.34.6 have been recalled due to build tooling problems._ 166 167 ## v0.34.4 168 169 *February 11, 2021* 170 171 This release includes a fix for a memory leak in the evidence reactor (see #6068, below). 172 All Tendermint clients are recommended to upgrade. 173 Thank you to our friends at Crypto.com for the initial report of this memory leak! 174 175 Special thanks to other external contributors on this release: @yayajacky, @odidev, @laniehei, and @c29r3! 176 177 ### BUG FIXES 178 179 - [light] [\#6022](https://github.com/tendermint/tendermint/pull/6022) Fix a bug when the number of validators equals 100 (@melekes) 180 - [light] [\#6026](https://github.com/tendermint/tendermint/pull/6026) Fix a bug when height isn't provided for the rpc calls: `/commit` and `/validators` (@cmwaters) 181 - [evidence] [\#6068](https://github.com/tendermint/tendermint/pull/6068) Terminate broadcastEvidenceRoutine when peer is stopped (@melekes) 182 183 184 ## v0.34.3 185 186 *January 19, 2021* 187 188 This release includes a fix for a high-severity security vulnerability, 189 a DoS-vector that impacted Tendermint Core v0.34.0-v0.34.2. For more details, see 190 [Security Advisory Mulberry](https://github.com/tendermint/tendermint/security/advisories/GHSA-p658-8693-mhvg) 191 or https://nvd.nist.gov/vuln/detail/CVE-2021-21271. 192 193 Tendermint Core v0.34.3 also updates GoGo Protobuf to 1.3.2 in order to pick up the fix for 194 https://nvd.nist.gov/vuln/detail/CVE-2021-3121. 195 196 ### BUG FIXES 197 198 - [evidence] [[security fix]](https://github.com/tendermint/tendermint/security/advisories/GHSA-p658-8693-mhvg) Use correct source of evidence time (@cmwaters) 199 - [proto] [\#5886](https://github.com/tendermint/tendermint/pull/5889) Bump gogoproto to 1.3.2 (@marbar3778) 200 201 ## v0.34.2 202 203 *January 12, 2021* 204 205 This release fixes a substantial bug in evidence handling where evidence could 206 sometimes be broadcast before the block containing that evidence was fully committed, 207 resulting in some nodes panicking when trying to verify said evidence. 208 209 ### BREAKING CHANGES 210 211 - Go API 212 - [libs/os] [\#5871](https://github.com/tendermint/tendermint/issues/5871) `EnsureDir` now propagates IO errors and checks the file type (@erikgrinaker) 213 214 ### BUG FIXES 215 216 - [evidence] [\#5890](https://github.com/tendermint/tendermint/pull/5890) Add a buffer to evidence from consensus to avoid broadcasting and proposing evidence before the 217 height of such an evidence has finished (@cmwaters) 218 - [statesync] [\#5889](https://github.com/tendermint/tendermint/issues/5889) Set `LastHeightConsensusParamsChanged` when bootstrapping Tendermint state (@cmwaters) 219 220 ## v0.34.1 221 222 *January 6, 2021* 223 224 Special thanks to external contributors on this release: 225 226 @p4u from vocdoni.io reported that the mempool might behave incorrectly under a 227 high load. The consequences can range from pauses between blocks to the peers 228 disconnecting from this node. As a temporary remedy (until the mempool package 229 is refactored), the `max-batch-bytes` was disabled. Transactions will be sent 230 one by one without batching. 231 232 ### BREAKING CHANGES 233 234 - CLI/RPC/Config 235 - [cli] [\#5786](https://github.com/tendermint/tendermint/issues/5786) deprecate snake_case commands for hyphen-case (@cmwaters) 236 237 - Go API 238 - [libs/protoio] [\#5868](https://github.com/tendermint/tendermint/issues/5868) Return number of bytes read in `Reader.ReadMsg()` (@erikgrinaker) 239 240 ### IMPROVEMENTS 241 242 - [mempool] [\#5813](https://github.com/tendermint/tendermint/issues/5813) Add `keep-invalid-txs-in-cache` config option. When set to true, mempool will keep invalid transactions in the cache (@p4u) 243 244 ### BUG FIXES 245 246 - [crypto] [\#5707](https://github.com/tendermint/tendermint/issues/5707) Fix infinite recursion in string formatting of Secp256k1 keys (@erikgrinaker) 247 - [mempool] [\#5800](https://github.com/tendermint/tendermint/issues/5800) Disable `max-batch-bytes` (@melekes) 248 - [p2p] [\#5868](https://github.com/tendermint/tendermint/issues/5868) Fix inbound traffic statistics and rate limiting in `MConnection` (@erikgrinaker) 249 250 ## v0.34.0 251 252 *November 19, 2020* 253 254 Holy smokes, this is a big one! For a more reader-friendly overview of the changes in 0.34.0 255 (and of the changes you need to accommodate as a user), check out [UPGRADING.md](UPGRADING.md). 256 257 Special thanks to external contributors on this release: @james-ray, @fedekunze, @favadi, @alessio, 258 @joe-bowman, @cuonglm, @SadPencil and @dongsam. 259 260 ### BREAKING CHANGES 261 262 - CLI/RPC/Config 263 264 - [config] [\#5315](https://github.com/tendermint/tendermint/pull/5315) Rename `prof_laddr` to `pprof_laddr` and move it to `rpc` section (@melekes) 265 - [evidence] [\#4959](https://github.com/tendermint/tendermint/pull/4959) Add JSON tags to `DuplicateVoteEvidence` (@marbar3778) 266 - [light] [\#4946](https://github.com/tendermint/tendermint/pull/4946) `tendermint lite` command has been renamed to `tendermint light` (@marbar3778) 267 - [privval] [\#4582](https://github.com/tendermint/tendermint/pull/4582) `round` in private_validator_state.json is no longer JSON string; instead it is a number (@marbar3778) 268 - [rpc] [\#4792](https://github.com/tendermint/tendermint/pull/4792) `/validators` are now sorted by voting power (@melekes) 269 - [rpc] [\#4947](https://github.com/tendermint/tendermint/pull/4947) Return an error when `page` pagination param is 0 in `/validators`, `tx_search` (@melekes) 270 - [rpc] [\#5137](https://github.com/tendermint/tendermint/pull/5137) JSON tags of `gasWanted` and `gasUsed` in `ResponseCheckTx` and `ResponseDeliverTx` have been made snake_case (`gas_wanted` and `gas_used`) (@marbar3778) 271 - [rpc] [\#5315](https://github.com/tendermint/tendermint/pull/5315) Remove `/unsafe_start_cpu_profiler`, `/unsafe_stop_cpu_profiler` and `/unsafe_write_heap_profile`. Please use pprof functionality instead (@melekes) 272 - [rpc/client, rpc/jsonrpc/client] [\#5347](https://github.com/tendermint/tendermint/pull/5347) All client methods now accept `context.Context` as 1st param (@melekes) 273 274 - Apps 275 276 - [abci] [\#4704](https://github.com/tendermint/tendermint/pull/4704) Add ABCI methods `ListSnapshots`, `LoadSnapshotChunk`, `OfferSnapshot`, and `ApplySnapshotChunk` for state sync snapshots. `ABCIVersion` bumped to 0.17.0. (@erikgrinaker) 277 - [abci] [\#4989](https://github.com/tendermint/tendermint/pull/4989) `Proof` within `ResponseQuery` has been renamed to `ProofOps` (@marbar3778) 278 - [abci] [\#5096](https://github.com/tendermint/tendermint/pull/5096) `CheckTxType` Protobuf enum names are now uppercase, to follow Protobuf style guide (@erikgrinaker) 279 - [abci] [\#5324](https://github.com/tendermint/tendermint/pull/5324) ABCI evidence type is now an enum with two types of possible evidence (@cmwaters) 280 281 - P2P Protocol 282 283 - [blockchain] [\#4637](https://github.com/tendermint/tendermint/pull/4637) Migrate blockchain reactor(s) to Protobuf encoding (@marbar3778) 284 - [evidence] [\#4949](https://github.com/tendermint/tendermint/pull/4949) Migrate evidence reactor to Protobuf encoding (@marbar3778) 285 - [mempool] [\#4940](https://github.com/tendermint/tendermint/pull/4940) Migrate mempool from to Protobuf encoding (@marbar3778) 286 - [mempool] [\#5321](https://github.com/tendermint/tendermint/pull/5321) Batch transactions when broadcasting them to peers (@melekes) 287 - `MaxBatchBytes` new config setting defines the max size of one batch. 288 - [p2p/pex] [\#4973](https://github.com/tendermint/tendermint/pull/4973) Migrate `p2p/pex` reactor to Protobuf encoding (@marbar3778) 289 - [statesync] [\#4943](https://github.com/tendermint/tendermint/pull/4943) Migrate state sync reactor to Protobuf encoding (@marbar3778) 290 291 - Blockchain Protocol 292 293 - [evidence] [\#4725](https://github.com/tendermint/tendermint/pull/4725) Remove `Pubkey` from `DuplicateVoteEvidence` (@marbar3778) 294 - [evidence] [\#5499](https://github.com/tendermint/tendermint/pull/5449) Cap evidence to a maximum number of bytes (supercedes [\#4780](https://github.com/tendermint/tendermint/pull/4780)) (@cmwaters) 295 - [merkle] [\#5193](https://github.com/tendermint/tendermint/pull/5193) Header hashes are no longer empty for empty inputs, notably `DataHash`, `EvidenceHash`, and `LastResultsHash` (@erikgrinaker) 296 - [state] [\#4845](https://github.com/tendermint/tendermint/pull/4845) Include `GasWanted` and `GasUsed` into `LastResultsHash` (@melekes) 297 - [types] [\#4792](https://github.com/tendermint/tendermint/pull/4792) Sort validators by voting power to enable faster commit verification (@melekes) 298 299 - On-disk serialization 300 301 - [state] [\#4679](https://github.com/tendermint/tendermint/pull/4679) Migrate state module to Protobuf encoding (@marbar3778) 302 - `BlockStoreStateJSON` is now `BlockStoreState` and is encoded as binary in the database 303 - [store] [\#4778](https://github.com/tendermint/tendermint/pull/4778) Migrate store module to Protobuf encoding (@marbar3778) 304 305 - Light client, private validator 306 307 - [light] [\#4964](https://github.com/tendermint/tendermint/pull/4964) Migrate light module migration to Protobuf encoding (@marbar3778) 308 - [privval] [\#4985](https://github.com/tendermint/tendermint/pull/4985) Migrate `privval` module to Protobuf encoding (@marbar3778) 309 310 - Go API 311 312 - [consensus] [\#4582](https://github.com/tendermint/tendermint/pull/4582) RoundState: `Round`, `LockedRound` & `CommitRound` are now `int32` (@marbar3778) 313 - [consensus] [\#4582](https://github.com/tendermint/tendermint/pull/4582) HeightVoteSet: `round` is now `int32` (@marbar3778) 314 - [crypto] [\#4721](https://github.com/tendermint/tendermint/pull/4721) Remove `SimpleHashFromMap()` and `SimpleProofsFromMap()` (@erikgrinaker) 315 - [crypto] [\#4940](https://github.com/tendermint/tendermint/pull/4940) All keys have become `[]byte` instead of `[<size>]byte`. The byte method no longer returns the marshaled value but just the `[]byte` form of the data. (@marbar3778) 316 - [crypto] [\#4988](https://github.com/tendermint/tendermint/pull/4988) Removal of key type multisig (@marbar3778) 317 - The key has been moved to the [Cosmos-SDK](https://github.com/cosmos/cosmos-sdk/blob/master/crypto/types/multisig/multisignature.go) 318 - [crypto] [\#4989](https://github.com/tendermint/tendermint/pull/4989) Remove `Simple` prefixes from `SimpleProof`, `SimpleValueOp` & `SimpleProofNode`. (@marbar3778) 319 - `merkle.Proof` has been renamed to `ProofOps`. 320 - Protobuf messages `Proof` & `ProofOp` has been moved to `proto/crypto/merkle` 321 - `SimpleHashFromByteSlices` has been renamed to `HashFromByteSlices` 322 - `SimpleHashFromByteSlicesIterative` has been renamed to `HashFromByteSlicesIterative` 323 - `SimpleProofsFromByteSlices` has been renamed to `ProofsFromByteSlices` 324 - [crypto] [\#4941](https://github.com/tendermint/tendermint/pull/4941) Remove suffixes from all keys. (@marbar3778) 325 - ed25519: type `PrivKeyEd25519` is now `PrivKey` 326 - ed25519: type `PubKeyEd25519` is now `PubKey` 327 - secp256k1: type`PrivKeySecp256k1` is now `PrivKey` 328 - secp256k1: type`PubKeySecp256k1` is now `PubKey` 329 - sr25519: type `PrivKeySr25519` is now `PrivKey` 330 - sr25519: type `PubKeySr25519` is now `PubKey` 331 - [crypto] [\#5214](https://github.com/tendermint/tendermint/pull/5214) Change `GenPrivKeySecp256k1` to `GenPrivKeyFromSecret` to be consistent with other keys (@marbar3778) 332 - [crypto] [\#5236](https://github.com/tendermint/tendermint/pull/5236) `VerifyBytes` is now `VerifySignature` on the `crypto.PubKey` interface (@marbar3778) 333 - [evidence] [\#5361](https://github.com/tendermint/tendermint/pull/5361) Add LightClientAttackEvidence and change evidence interface (@cmwaters) 334 - [libs] [\#4831](https://github.com/tendermint/tendermint/pull/4831) Remove `Bech32` pkg from Tendermint. This pkg now lives in the [cosmos-sdk](https://github.com/cosmos/cosmos-sdk/tree/4173ea5ebad906dd9b45325bed69b9c655504867/types/bech32) (@marbar3778) 335 - [light] [\#4946](https://github.com/tendermint/tendermint/pull/4946) Rename `lite2` pkg to `light`. Remove `lite` implementation. (@marbar3778) 336 - [light] [\#5347](https://github.com/tendermint/tendermint/pull/5347) `NewClient`, `NewHTTPClient`, `VerifyHeader` and `VerifyLightBlockAtHeight` now accept `context.Context` as 1st param (@melekes) 337 - [merkle] [\#5193](https://github.com/tendermint/tendermint/pull/5193) `HashFromByteSlices` and `ProofsFromByteSlices` now return a hash for empty inputs, following RFC6962 (@erikgrinaker) 338 - [proto] [\#5025](https://github.com/tendermint/tendermint/pull/5025) All proto files have been moved to `/proto` directory. (@marbar3778) 339 - Using the recommended the file layout from buf, [see here for more info](https://buf.build/docs/lint-checkers#file_layout) 340 - [rpc/client] [\#4947](https://github.com/tendermint/tendermint/pull/4947) `Validators`, `TxSearch` `page`/`per_page` params become pointers (@melekes) 341 - `UnconfirmedTxs` `limit` param is a pointer 342 - [rpc/jsonrpc/server] [\#5141](https://github.com/tendermint/tendermint/pull/5141) Remove `WriteRPCResponseArrayHTTP` (use `WriteRPCResponseHTTP` instead) (@melekes) 343 - [state] [\#4679](https://github.com/tendermint/tendermint/pull/4679) `TxResult` is a Protobuf type defined in `abci` types directory (@marbar3778) 344 - [state] [\#5191](https://github.com/tendermint/tendermint/pull/5191) Add `State.InitialHeight` field to record initial block height, must be `1` (not `0`) to start from 1 (@erikgrinaker) 345 - [state] [\#5231](https://github.com/tendermint/tendermint/pull/5231) `LoadStateFromDBOrGenesisFile()` and `LoadStateFromDBOrGenesisDoc()` no longer saves the state in the database if not found, the genesis state is simply returned (@erikgrinaker) 346 - [state] [\#5348](https://github.com/tendermint/tendermint/pull/5348) Define an Interface for the state store. (@marbar3778) 347 - [types] [\#4939](https://github.com/tendermint/tendermint/pull/4939) `SignedMsgType` has moved to a Protobuf enum types (@marbar3778) 348 - [types] [\#4962](https://github.com/tendermint/tendermint/pull/4962) `ConsensusParams`, `BlockParams`, `EvidenceParams`, `ValidatorParams` & `HashedParams` are now Protobuf types (@marbar3778) 349 - [types] [\#4852](https://github.com/tendermint/tendermint/pull/4852) Vote & Proposal `SignBytes` is now func `VoteSignBytes` & `ProposalSignBytes` (@marbar3778) 350 - [types] [\#4798](https://github.com/tendermint/tendermint/pull/4798) Simplify `VerifyCommitTrusting` func + remove extra validation (@melekes) 351 - [types] [\#4845](https://github.com/tendermint/tendermint/pull/4845) Remove `ABCIResult` (@melekes) 352 - [types] [\#5029](https://github.com/tendermint/tendermint/pull/5029) Rename all values from `PartsHeader` to `PartSetHeader` to have consistency (@marbar3778) 353 - [types] [\#4939](https://github.com/tendermint/tendermint/pull/4939) `Total` in `Parts` & `PartSetHeader` has been changed from a `int` to a `uint32` (@marbar3778) 354 - [types] [\#4939](https://github.com/tendermint/tendermint/pull/4939) Vote: `ValidatorIndex` & `Round` are now `int32` (@marbar3778) 355 - [types] [\#4939](https://github.com/tendermint/tendermint/pull/4939) Proposal: `POLRound` & `Round` are now `int32` (@marbar3778) 356 - [types] [\#4939](https://github.com/tendermint/tendermint/pull/4939) Block: `Round` is now `int32` (@marbar3778) 357 358 ### FEATURES 359 360 - [abci] [\#5031](https://github.com/tendermint/tendermint/pull/5031) Add `AppVersion` to consensus parameters (@james-ray) 361 - This makes it possible to update your ABCI application version via `EndBlock` response 362 - [abci] [\#5174](https://github.com/tendermint/tendermint/pull/5174) Remove `MockEvidence` in favor of testing with actual evidence types (`DuplicateVoteEvidence` & `LightClientAttackEvidence`) (@cmwaters) 363 - [abci] [\#5191](https://github.com/tendermint/tendermint/pull/5191) Add `InitChain.InitialHeight` field giving the initial block height (@erikgrinaker) 364 - [abci] [\#5227](https://github.com/tendermint/tendermint/pull/5227) Add `ResponseInitChain.app_hash` which is recorded in genesis block (@erikgrinaker) 365 - [config] [\#5147](https://github.com/tendermint/tendermint/pull/5147) Add `--consensus.double_sign_check_height` flag and `DoubleSignCheckHeight` config variable. See [ADR-51](https://github.com/tendermint/tendermint/blob/master/docs/architecture/adr-051-double-signing-risk-reduction.md) (@dongsam) 366 - [db] [\#5233](https://github.com/tendermint/tendermint/pull/5233) Add support for `badgerdb` database backend (@erikgrinaker) 367 - [evidence] [\#4532](https://github.com/tendermint/tendermint/pull/4532) Handle evidence from light clients (@melekes) 368 - [evidence] [#4821](https://github.com/tendermint/tendermint/pull/4821) Amnesia (light client attack) evidence can be detected, verified and committed (@cmwaters) 369 - [genesis] [\#5191](https://github.com/tendermint/tendermint/pull/5191) Add `initial_height` field to specify the initial chain height (defaults to `1`) (@erikgrinaker) 370 - [libs/math] [\#5665](https://github.com/tendermint/tendermint/pull/5665) Make fractions unsigned integers (uint64) (@cmwaters) 371 - [light] [\#5298](https://github.com/tendermint/tendermint/pull/5298) Morph validator set and signed header into light block (@cmwaters) 372 - [p2p] [\#4981](https://github.com/tendermint/tendermint/pull/4981) Expose `SaveAs` func on NodeKey (@melekes) 373 - [privval] [\#5239](https://github.com/tendermint/tendermint/pull/5239) Add `chainID` to requests from client. (@marbar3778) 374 - [rpc] [\#4532](https://github.com/tendermint/tendermint/pull/4923) Support `BlockByHash` query (@fedekunze) 375 - [rpc] [\#4979](https://github.com/tendermint/tendermint/pull/4979) Support EXISTS operator in `/tx_search` query (@melekes) 376 - [rpc] [\#5017](https://github.com/tendermint/tendermint/pull/5017) Add `/check_tx` endpoint to check transactions without executing them or adding them to the mempool (@melekes) 377 - [rpc] [\#5108](https://github.com/tendermint/tendermint/pull/5108) Subscribe using the websocket for new evidence events (@cmwaters) 378 - [statesync] Add state sync support, where a new node can be rapidly bootstrapped by fetching state snapshots from peers instead of replaying blocks. See the `[statesync]` config section. 379 - [evidence] [\#5361](https://github.com/tendermint/tendermint/pull/5361) Add LightClientAttackEvidence and refactor evidence lifecycle - for more information see [ADR-059](https://github.com/tendermint/tendermint/blob/master/docs/architecture/adr-059-evidence-composition-and-lifecycle.md) (@cmwaters) 380 381 ### IMPROVEMENTS 382 383 - [blockchain] [\#5278](https://github.com/tendermint/tendermint/pull/5278) Verify only +2/3 of the signatures in a block when fast syncing. (@marbar3778) 384 - [consensus] [\#4578](https://github.com/tendermint/tendermint/pull/4578) Attempt to repair the consensus WAL file (`data/cs.wal/wal`) automatically in case of corruption (@alessio) 385 - The original WAL file will be backed up to `data/cs.wal/wal.CORRUPTED`. 386 - [consensus] [\#5143](https://github.com/tendermint/tendermint/pull/5143) Only call `privValidator.GetPubKey` once per block (@melekes) 387 - [evidence] [\#4722](https://github.com/tendermint/tendermint/pull/4722) Consolidate evidence store and pool types to improve evidence DB (@cmwaters) 388 - [evidence] [\#4839](https://github.com/tendermint/tendermint/pull/4839) Reject duplicate evidence from being proposed (@cmwaters) 389 - [evidence] [\#5219](https://github.com/tendermint/tendermint/pull/5219) Change the source of evidence time to block time (@cmwaters) 390 - [libs] [\#5126](https://github.com/tendermint/tendermint/pull/5126) Add a sync package which wraps sync.(RW)Mutex & deadlock.(RW)Mutex and use a build flag (deadlock) in order to enable deadlock checking (@marbar3778) 391 - [light] [\#4935](https://github.com/tendermint/tendermint/pull/4935) Fetch and compare a new header with witnesses in parallel (@melekes) 392 - [light] [\#4929](https://github.com/tendermint/tendermint/pull/4929) Compare header with witnesses only when doing bisection (@melekes) 393 - [light] [\#4916](https://github.com/tendermint/tendermint/pull/4916) Validate basic for inbound validator sets and headers before further processing them (@cmwaters) 394 - [mempool] Add RemoveTxByKey() exported function for custom mempool cleaning (@p4u) 395 - [p2p/conn] [\#4795](https://github.com/tendermint/tendermint/pull/4795) Return err on `signChallenge()` instead of panic 396 - [privval] [\#5437](https://github.com/tendermint/tendermint/pull/5437) `NewSignerDialerEndpoint` can now be given `SignerServiceEndpointOption` (@erikgrinaker) 397 - [rpc] [\#4968](https://github.com/tendermint/tendermint/pull/4968) JSON encoding is now handled by `libs/json`, not Amino (@erikgrinaker) 398 - [rpc] [\#5293](https://github.com/tendermint/tendermint/pull/5293) `/dial_peers` has added `private` and `unconditional` as parameters. (@marbar3778) 399 - [state] [\#4781](https://github.com/tendermint/tendermint/pull/4781) Export `InitStateVersion` for the initial state version (@erikgrinaker) 400 - [txindex] [\#4466](https://github.com/tendermint/tendermint/pull/4466) Allow to index an event at runtime (@favadi) 401 - `abci.EventAttribute` replaces `KV.Pair` 402 - [types] [\#4905](https://github.com/tendermint/tendermint/pull/4905) Add `ValidateBasic` to validator and validator set (@cmwaters) 403 - [types] [\#5340](https://github.com/tendermint/tendermint/pull/5340) Add check in `Header.ValidateBasic()` for block protocol version (@marbar3778) 404 - [types] [\#5490](https://github.com/tendermint/tendermint/pull/5490) Use `Commit` and `CommitSig` max sizes instead of vote max size to calculate the maximum block size. (@cmwaters) 405 406 407 ### BUG FIXES 408 409 - [abci/grpc] [\#5520](https://github.com/tendermint/tendermint/pull/5520) Return async responses in order, to avoid mempool panics. (@erikgrinaker) 410 - [blockchain/v2] [\#4971](https://github.com/tendermint/tendermint/pull/4971) Correctly set block store base in status responses (@erikgrinaker) 411 - [blockchain/v2] [\#5499](https://github.com/tendermint/tendermint/pull/5499) Fix "duplicate block enqueued by processor" panic (@melekes) 412 - [blockchain/v2] [\#5530](https://github.com/tendermint/tendermint/pull/5530) Fix out of order block processing panic (@melekes) 413 - [blockchain/v2] [\#5553](https://github.com/tendermint/tendermint/pull/5553) Make the removal of an already removed peer a noop (@melekes) 414 - [consensus] [\#4895](https://github.com/tendermint/tendermint/pull/4895) Cache the address of the validator to reduce querying a remote KMS (@joe-bowman) 415 - [consensus] [\#4970](https://github.com/tendermint/tendermint/pull/4970) Don't allow `LastCommitRound` to be negative (@cuonglm) 416 - [consensus] [\#5329](https://github.com/tendermint/tendermint/pull/5329) Fix wrong proposer schedule for validators returned by `InitChain` (@erikgrinaker) 417 - [docker] [\#5385](https://github.com/tendermint/tendermint/pull/5385) Fix incorrect `time_iota_ms` default setting causing block timestamp drift (@erikgrinaker) 418 - [evidence] [\#5170](https://github.com/tendermint/tendermint/pull/5170) Change ABCI evidence time to the time the infraction happened not the time the evidence was committed on the block (@cmwaters) 419 - [evidence] [\#5610](https://github.com/tendermint/tendermint/pull/5610) Make it possible for ABCI evidence to be formed from Tendermint evidence (@cmwaters) 420 - [libs/rand] [\#5215](https://github.com/tendermint/tendermint/pull/5215) Fix out-of-memory error on unexpected argument of Str() (@SadPencil) 421 - [light] [\#5307](https://github.com/tendermint/tendermint/pull/5307) Persist correct proposer priority in light client validator sets (@cmwaters) 422 - [p2p] [\#5136](https://github.com/tendermint/tendermint/pull/5136) Fix error for peer with the same ID but different IPs (@valardragon) 423 - [privval] [\#5638](https://github.com/tendermint/tendermint/pull/5638) Increase read/write timeout to 5s and calculate ping interval based on it (@JoeKash) 424 - [proxy] [\#5078](https://github.com/tendermint/tendermint/pull/5078) Force Tendermint to exit when ABCI app crashes (@melekes) 425 - [rpc] [\#5660](https://github.com/tendermint/tendermint/pull/5660) Set `application/json` as the `Content-Type` header in RPC responses. (@alexanderbez) 426 - [store] [\#5382](https://github.com/tendermint/tendermint/pull/5382) Fix race conditions when loading/saving/pruning blocks (@erikgrinaker) 427 428 ## v0.33.8 429 430 *August 11, 2020* 431 432 ### Go security update 433 434 Go reported a security vulnerability that affected the `encoding/binary` package. The most recent binary for tendermint is using 1.14.6, for this 435 reason the Tendermint engineering team has opted to conduct a release to aid users in using the correct version of Go. Read more about the security issue [here](https://github.com/golang/go/issues/40618). 436 437 438 ## v0.33.7 439 440 *August 4, 2020* 441 442 ### BUG FIXES: 443 444 - [go] Build release binary using Go 1.14.4, to avoid halt caused by Go 1.14.1 (https://github.com/golang/go/issues/38223) 445 - [privval] [\#5140](https://github.com/tendermint/tendermint/pull/5140) `RemoteSignerError` from remote signers are no longer retried (@melekes) 446 447 448 ## v0.33.6 449 450 *July 2, 2020* 451 452 This security release fixes: 453 454 ### Denial of service 455 456 Tendermint 0.33.0 and above allow block proposers to include signatures for the 457 wrong block. This may happen naturally if you start a network, have it run for 458 some time and restart it **without changing the chainID**. (It is a 459 [misconfiguration](https://docs.tendermint.com/master/tendermint-core/using-tendermint.html) 460 to reuse chainIDs.) Correct block proposers will accidentally include signatures 461 for the wrong block if they see these signatures, and then commits won't validate, 462 making all proposed blocks invalid. A malicious validator (even with a minimal 463 amount of stake) can use this vulnerability to completely halt the network. 464 465 Tendermint 0.33.6 checks all the signatures are for the block with +2/3 466 majority before creating a commit. 467 468 ### False Witness 469 470 Tendermint 0.33.1 and above are no longer fully verifying commit signatures 471 during block execution - they stop after +2/3. This means proposers can propose 472 blocks that contain valid +2/3 signatures and then the rest of the signatures 473 can be whatever they want. They can claim that all the other validators signed 474 just by including a CommitSig with arbitrary signature data. While this doesn't 475 seem to impact safety of Tendermint per se, it means that Commits may contain a 476 lot of invalid data. 477 478 _This was already true of blocks, since they could include invalid txs filled 479 with garbage, but in that case the application knew that they are invalid and 480 could punish the proposer. But since applications didn't--and don't-- 481 verify commit signatures directly (they trust Tendermint to do that), 482 they won't be able to detect it._ 483 484 This can impact incentivization logic in the application that depends on the 485 LastCommitInfo sent in BeginBlock, which includes which validators signed. For 486 instance, Gaia incentivizes proposers with a bonus for including more than +2/3 487 of the signatures. But a proposer can now claim that bonus just by including 488 arbitrary data for the final -1/3 of validators without actually waiting for 489 their signatures. There may be other tricks that can be played because of this. 490 491 Tendermint 0.33.6 verifies all the signatures during block execution. 492 493 _Please note that the light client does not check nil votes and exits as soon 494 as 2/3+ of the signatures are checked._ 495 496 **All clients are recommended to upgrade.** 497 498 Special thanks to @njmurarka at Bluzelle Networks for reporting this. 499 500 ### SECURITY: 501 502 - [consensus] Do not allow signatures for a wrong block in commits (@ebuchman) 503 - [consensus] Verify all the signatures during block execution (@melekes) 504 505 **Please note that the fix for the False Witness issue renames the `VerifyCommitTrusting` 506 function to `VerifyCommitLightTrusting`. If you were relying on the light client, you may 507 need to update your code.** 508 509 ## v0.33.5 510 511 *May 28, 2020* 512 513 Special thanks to external contributors on this release: @tau3, 514 515 ### BREAKING CHANGES: 516 517 - Go API 518 519 - [privval] [\#4744](https://github.com/tendermint/tendermint/pull/4744) Remove deprecated `OldFilePV` (@melekes) 520 - [mempool] [\#4759](https://github.com/tendermint/tendermint/pull/4759) Modify `Mempool#InitWAL` to return an error (@melekes) 521 - [node] [\#4832](https://github.com/tendermint/tendermint/pull/4832) `ConfigureRPC` returns an error (@melekes) 522 - [rpc] [\#4836](https://github.com/tendermint/tendermint/pull/4836) Overhaul `lib` folder (@melekes) 523 Move lib/ folder to jsonrpc/. 524 Rename: 525 rpc package -> jsonrpc package 526 rpcclient package -> client package 527 rpcserver package -> server package 528 JSONRPCClient to Client 529 JSONRPCRequestBatch to RequestBatch 530 JSONRPCCaller to Caller 531 StartHTTPServer to Serve 532 StartHTTPAndTLSServer to ServeTLS 533 NewURIClient to NewURI 534 NewJSONRPCClient to New 535 NewJSONRPCClientWithHTTPClient to NewWithHTTPClient 536 NewWSClient to NewWS 537 Unexpose ResponseWriterWrapper 538 Remove unused http_params.go 539 540 541 ### FEATURES: 542 543 - [pex] [\#4439](https://github.com/tendermint/tendermint/pull/4439) Use highwayhash for pex buckets (@tau3) 544 545 ### IMPROVEMENTS: 546 547 - [abci/server] [\#4719](https://github.com/tendermint/tendermint/pull/4719) Print panic & stack trace to STDERR if logger is not set (@melekes) 548 - [types] [\#4638](https://github.com/tendermint/tendermint/pull/4638) Implement `Header#ValidateBasic` (@alexanderbez) 549 - [buildsystem] [\#4378](https://github.com/tendermint/tendermint/pull/4738) Replace build_c and install_c with TENDERMINT_BUILD_OPTIONS parsing. The following options are available: 550 - nostrip: don't strip debugging symbols nor DWARF tables. 551 - cleveldb: use cleveldb as db backend instead of goleveldb. 552 - race: pass -race to go build and enable data race detection. 553 - [mempool] [\#4759](https://github.com/tendermint/tendermint/pull/4759) Allow ReapX and CheckTx functions to run in parallel (@melekes) 554 - [rpc/core] [\#4844](https://github.com/tendermint/tendermint/pull/4844) Do not lock consensus state in `/validators`, `/consensus_params` and `/status` (@melekes) 555 556 ### BUG FIXES: 557 558 - [blockchain/v2] [\#4761](https://github.com/tendermint/tendermint/pull/4761) Fix excessive CPU usage caused by spinning on closed channels (@erikgrinaker) 559 - [blockchain/v2] Respect `fast_sync` option (@erikgrinaker) 560 - [light] [\#4741](https://github.com/tendermint/tendermint/pull/4741) Correctly return `ErrSignedHeaderNotFound` and `ErrValidatorSetNotFound` on corresponding RPC errors (@erikgrinaker) 561 - [rpc] [\#4805](https://github.com/tendermint/tendermint/issues/4805) Attempt to handle panics during panic recovery (@erikgrinaker) 562 - [types] [\#4764](https://github.com/tendermint/tendermint/pull/4764) Return an error if voting power overflows in `VerifyCommitTrusting` (@melekes) 563 - [privval] [\#4812](https://github.com/tendermint/tendermint/pull/4812) Retry `GetPubKey/SignVote/SignProposal` a few times before returning an error (@melekes) 564 - [p2p] [\#4847](https://github.com/tendermint/tendermint/pull/4847) Return masked IP (not the actual IP) in addrbook#groupKey (@melekes) 565 566 ## v0.33.4 567 568 - Nodes are no longer guaranteed to contain all blocks up to the latest height. The ABCI app can now control which blocks to retain through the ABCI field `ResponseCommit.retain_height`, all blocks and associated data below this height will be removed. 569 570 *April 21, 2020* 571 572 Special thanks to external contributors on this release: @whylee259, @greg-szabo 573 574 ### BREAKING CHANGES: 575 576 - Go API 577 578 - [lite2] [\#4616](https://github.com/tendermint/tendermint/pull/4616) Make `maxClockDrift` an option `Verify/VerifyAdjacent/VerifyNonAdjacent` now accept `maxClockDrift time.Duration` (@melekes). 579 - [rpc/client] [\#4628](https://github.com/tendermint/tendermint/pull/4628) Split out HTTP and local clients into `http` and `local` packages (@erikgrinaker). 580 581 ### FEATURES: 582 583 - [abci] [\#4588](https://github.com/tendermint/tendermint/issues/4588) Add `ResponseCommit.retain_height` field, which will automatically remove blocks below this height. This bumps the ABCI version to 0.16.2 (@erikgrinaker). 584 - [cmd] [\#4665](https://github.com/tendermint/tendermint/pull/4665) New `tendermint completion` command to generate Bash/Zsh completion scripts (@alessio). 585 - [rpc] [\#4588](https://github.com/tendermint/tendermint/issues/4588) Add `/status` response fields for the earliest block available on the node (@erikgrinaker). 586 - [rpc] [\#4611](https://github.com/tendermint/tendermint/pull/4611) Add `codespace` to `ResultBroadcastTx` (@whylee259). 587 588 ### IMPROVEMENTS: 589 590 - [all] [\#4608](https://github.com/tendermint/tendermint/pull/4608) Give reactors descriptive names when they're initialized (@tessr). 591 - [blockchain] [\#4588](https://github.com/tendermint/tendermint/issues/4588) Add `Base` to blockchain reactor P2P messages `StatusRequest` and `StatusResponse` (@erikgrinaker). 592 - [Docker] [\#4569](https://github.com/tendermint/tendermint/issues/4569) Default configuration added to docker image (you can still mount your own config the same way) (@greg-szabo). 593 - [example/kvstore] [\#4588](https://github.com/tendermint/tendermint/issues/4588) Add `RetainBlocks` option to control block retention (@erikgrinaker). 594 - [evidence] [\#4632](https://github.com/tendermint/tendermint/pull/4632) Inbound evidence checked if already existing (@cmwaters). 595 - [lite2] [\#4575](https://github.com/tendermint/tendermint/pull/4575) Use bisection for within-range verification (@cmwaters). 596 - [lite2] [\#4562](https://github.com/tendermint/tendermint/pull/4562) Cache headers when using bisection (@cmwaters). 597 - [p2p] [\#4548](https://github.com/tendermint/tendermint/pull/4548) Add ban list to address book (@cmwaters). 598 - [privval] [\#4534](https://github.com/tendermint/tendermint/issues/4534) Add `error` as a return value on`GetPubKey()` (@marbar3778). 599 - [p2p] [\#4621](https://github.com/tendermint/tendermint/issues/4621) Ban peers when messages are unsolicited or too frequent (@cmwaters). 600 - [rpc] [\#4703](https://github.com/tendermint/tendermint/pull/4703) Add `count` and `total` to `/validators` response (@melekes). 601 - [tools] [\#4615](https://github.com/tendermint/tendermint/issues/4615) Allow developers to use Docker to generate proto stubs, via `make proto-gen-docker` (@erikgrinaker). 602 603 ### BUG FIXES: 604 605 - [rpc] [\#4568](https://github.com/tendermint/tendermint/issues/4568) Fix panic when `Subscribe` is called, but HTTP client is not running. `Subscribe`, `Unsubscribe(All)` methods return an error now (@melekes). 606 607 ## v0.33.3 608 609 *April 6, 2020* 610 611 This security release fixes: 612 613 ### Denial of service 1 614 615 Tendermint 0.33.2 and earlier does not limit P2P connection requests number. 616 For each p2p connection, Tendermint allocates ~0.5MB. Even though this 617 memory is garbage collected once the connection is terminated (due to duplicate 618 IP or reaching a maximum number of inbound peers), temporary memory spikes can 619 lead to OOM (Out-Of-Memory) exceptions. 620 621 Tendermint 0.33.3 (and 0.32.10) limits the total number of P2P incoming 622 connection requests to to `p2p.max_num_inbound_peers + 623 len(p2p.unconditional_peer_ids)`. 624 625 Notes: 626 627 - Tendermint does not rate limit P2P connection requests per IP (an attacker 628 can saturate all the inbound slots); 629 - Tendermint does not rate limit HTTP(S) requests. If you expose any RPC 630 endpoints to the public, please make sure to put in place some protection 631 (https://www.nginx.com/blog/rate-limiting-nginx/). We may implement this in 632 the future ([\#1696](https://github.com/tendermint/tendermint/issues/1696)). 633 634 ### Denial of service 2 635 636 Tendermint 0.33.2 and earlier does not reclaim `activeID` of a peer after it's 637 removed in `Mempool` reactor. This does not happen all the time. It only 638 happens when a connection fails (for any reason) before the Peer is created and 639 added to all reactors. `RemovePeer` is therefore called before `AddPeer`, which 640 leads to always growing memory (`activeIDs` map). The `activeIDs` map has a 641 maximum size of 65535 and the node will panic if this map reaches the maximum. 642 An attacker can create a lot of connection attempts (exploiting Denial of 643 service 1), which ultimately will lead to the node panicking. 644 645 Tendermint 0.33.3 (and 0.32.10) claims `activeID` for a peer in `InitPeer`, 646 which is executed before `MConnection` is started. 647 648 Notes: 649 650 - `InitPeer` function was added to all reactors to combat a similar issue - 651 [\#3338](https://github.com/tendermint/tendermint/issues/3338); 652 - Denial of service 2 is independent of Denial of service 1 and can be executed 653 without it. 654 655 **All clients are recommended to upgrade** 656 657 Special thanks to [fudongbai](https://hackerone.com/fudongbai) for finding 658 and reporting this. 659 660 ### SECURITY: 661 662 - [mempool] Reserve IDs in InitPeer instead of AddPeer (@tessr) 663 - [p2p] Limit the number of incoming connections (@melekes) 664 665 ## v0.33.2 666 667 *March 11, 2020* 668 669 Special thanks to external contributors on this release: 670 @antho1404, @michaelfig, @gterzian, @tau3, @Shivani912 671 672 ### BREAKING CHANGES: 673 674 - CLI/RPC/Config 675 - [cli] [\#4505](https://github.com/tendermint/tendermint/pull/4505) `tendermint lite` sub-command new syntax (@melekes): 676 `lite cosmoshub-3 -p 52.57.29.196:26657 -w public-seed-node.cosmoshub.certus.one:26657 677 --height 962118 --hash 28B97BE9F6DE51AC69F70E0B7BFD7E5C9CD1A595B7DC31AFF27C50D4948` 678 679 - Go API 680 - [lite2] [\#4535](https://github.com/tendermint/tendermint/pull/4535) Remove `Start/Stop` (@melekes) 681 - [lite2] [\#4469](https://github.com/tendermint/tendermint/issues/4469) Remove `RemoveNoLongerTrustedHeaders` and `RemoveNoLongerTrustedHeadersPeriod` option (@cmwaters) 682 - [lite2] [\#4473](https://github.com/tendermint/tendermint/issues/4473) Return height as a 2nd param in `TrustedValidatorSet` (@melekes) 683 - [lite2] [\#4536](https://github.com/tendermint/tendermint/pull/4536) `Update` returns a signed header (1st param) (@melekes) 684 685 686 ### IMPROVEMENTS: 687 688 - [blockchain/v2] [\#4361](https://github.com/tendermint/tendermint/pull/4361) Add reactor (@brapse) 689 - [cmd] [\#4515](https://github.com/tendermint/tendermint/issues/4515) Change `tendermint debug dump` sub-command archives filename's format (@melekes) 690 - [consensus] [\#3583](https://github.com/tendermint/tendermint/issues/3583) Reduce `non-deterministic signature` log noise (@tau3) 691 - [examples/kvstore] [\#4507](https://github.com/tendermint/tendermint/issues/4507) ABCI query now returns the proper height (@erikgrinaker) 692 - [lite2] [\#4462](https://github.com/tendermint/tendermint/issues/4462) Add `NewHTTPClient` and `NewHTTPClientFromTrustedStore` (@cmwaters) 693 - [lite2] [\#4329](https://github.com/tendermint/tendermint/issues/4329) modified bisection to loop (@cmwaters) 694 - [lite2] [\#4385](https://github.com/tendermint/tendermint/issues/4385) Disconnect from bad nodes (@melekes) 695 - [lite2] [\#4398](https://github.com/tendermint/tendermint/issues/4398) Add `VerifyAdjacent` and `VerifyNonAdjacent` funcs (@cmwaters) 696 - [lite2] [\#4426](https://github.com/tendermint/tendermint/issues/4426) Don't save intermediate headers (@cmwaters) 697 - [lite2] [\#4464](https://github.com/tendermint/tendermint/issues/4464) Cross-check first header (@cmwaters) 698 - [lite2] [\#4470](https://github.com/tendermint/tendermint/issues/4470) Fix inconsistent header-validatorset pairing (@melekes) 699 - [lite2] [\#4488](https://github.com/tendermint/tendermint/issues/4488) Allow local clock drift -10 sec. (@melekes) 700 - [p2p] [\#4449](https://github.com/tendermint/tendermint/pull/4449) Use `curve25519.X25519()` instead of `ScalarMult` (@erikgrinaker) 701 - [types] [\#4417](https://github.com/tendermint/tendermint/issues/4417) **VerifyCommitX() functions should return as soon as +2/3 threshold is reached** (@alessio). 702 - [libs/kv] [\#4542](https://github.com/tendermint/tendermint/pull/4542) remove unused type KI64Pair (@tessr) 703 704 ### BUG FIXES: 705 706 - [cmd] [\#4303](https://github.com/tendermint/tendermint/issues/4303) Show useful error when Tendermint is not initialized (@melekes) 707 - [cmd] [\#4515](https://github.com/tendermint/tendermint/issues/4515) **Fix `tendermint debug kill` sub-command** (@melekes) 708 - [rpc] [\#3935](https://github.com/tendermint/tendermint/issues/3935) **Create buffered subscriptions on `/subscribe`** (@melekes) 709 - [rpc] [\#4375](https://github.com/tendermint/tendermint/issues/4375) Stop searching for txs in `/tx_search` upon client timeout (@gterzian) 710 - [rpc] [\#4406](https://github.com/tendermint/tendermint/pull/4406) Fix issue with multiple subscriptions on the websocket (@antho1404) 711 - [rpc] [\#4432](https://github.com/tendermint/tendermint/issues/4432) Fix `/tx_search` pagination with ordered results (@erikgrinaker) 712 - [rpc] [\#4492](https://github.com/tendermint/tendermint/issues/4492) Keep the original subscription "id" field when new RPCs come in (@michaelfig) 713 714 715 ## v0.33.1 716 717 *Feburary 13, 2020* 718 719 Special thanks to external contributors on this release: 720 @princesinha19 721 722 ### FEATURES: 723 724 - [rpc] [\#3333](https://github.com/tendermint/tendermint/issues/3333) Add `order_by` to `/tx_search` endpoint, allowing to change default ordering from asc to desc (@princesinha19) 725 726 ### IMPROVEMENTS: 727 728 - [proto] [\#4369](https://github.com/tendermint/tendermint/issues/4369) Add [buf](https://buf.build/) for usage with linting and checking if there are breaking changes with the master branch. 729 - [proto] [\#4369](https://github.com/tendermint/tendermint/issues/4369) Add `make proto-gen` cmd to generate proto stubs outside of GOPATH. 730 731 ### BUG FIXES: 732 733 - [node] [\#4311](https://github.com/tendermint/tendermint/issues/4311) Use `GRPCMaxOpenConnections` when creating the gRPC server, not `MaxOpenConnections` 734 - [rpc] [\#4319](https://github.com/tendermint/tendermint/issues/4319) Check `BlockMeta` is not nil in `/block` & `/block_by_hash` 735 736 ## v0.33 737 738 Special thanks to external contributors on this release: @mrekucci, @PSalant726, @princesinha19, @greg-szabo, @dongsam, @cuonglm, @jgimeno, @yenkhoon 739 740 *January 14, 2020* 741 742 This release contains breaking changes to the `Block#Header`, specifically 743 `NumTxs` and `TotalTxs` were removed (\#2521). Here's how this change affects 744 different modules: 745 746 - apps: it breaks the ABCI header field numbering 747 - state: it breaks the format of `State` on disk 748 - RPC: all RPC requests which expose the header broke 749 - Go API: the `Header` broke 750 - P2P: since blocks go over the wire, technically the P2P protocol broke 751 752 Also, blocks are significantly smaller 🔥 because we got rid of the redundant 753 information in `Block#LastCommit`. `Commit` now mainly consists of a signature 754 and a validator address plus a timestamp. Note we may remove the validator 755 address & timestamp fields in the future (see ADR-25). 756 757 `lite2` package has been added to solve `lite` issues and introduce weak 758 subjectivity interface. Refer to the [spec](https://github.com/tendermint/spec/blob/master/spec/consensus/light-client.md) for complete details. 759 `lite` package is now deprecated and will be removed in v0.34 release. 760 761 ### BREAKING CHANGES: 762 763 - CLI/RPC/Config 764 765 - [rpc] [\#3471](https://github.com/tendermint/tendermint/issues/3471) Paginate `/validators` response (default: 30 vals per page) 766 - [rpc] [\#3188](https://github.com/tendermint/tendermint/issues/3188) Remove `BlockMeta` in `ResultBlock` in favor of `BlockId` for `/block` 767 - [rpc] `/block_results` response format updated (see RPC docs for details) 768 ``` 769 { 770 "jsonrpc": "2.0", 771 "id": "", 772 "result": { 773 "height": "2109", 774 "txs_results": null, 775 "begin_block_events": null, 776 "end_block_events": null, 777 "validator_updates": null, 778 "consensus_param_updates": null 779 } 780 } 781 ``` 782 - [rpc] [\#4141](https://github.com/tendermint/tendermint/pull/4141) Remove `#event` suffix from the ID in event responses. 783 `{"jsonrpc": "2.0", "id": 0, "result": ...}` 784 - [rpc] [\#4141](https://github.com/tendermint/tendermint/pull/4141) Switch to integer IDs instead of `json-client-XYZ` 785 ``` 786 id=0 method=/subscribe 787 id=0 result=... 788 id=1 method=/abci_query 789 id=1 result=... 790 ``` 791 - ID is unique for each request; 792 - Request.ID is now optional. Notification is a Request without an ID. Previously ID="" or ID=0 were considered as notifications. 793 794 - [config] [\#4046](https://github.com/tendermint/tendermint/issues/4046) Rename tag(s) to CompositeKey & places where tag is still present it was renamed to event or events. Find how a compositeKey is constructed [here](https://github.com/tendermint/tendermint/blob/6d05c531f7efef6f0619155cf10ae8557dd7832f/docs/app-dev/indexing-transactions.md) 795 - You will have to generate a new config for your Tendermint node(s) 796 - [genesis] [\#2565](https://github.com/tendermint/tendermint/issues/2565) Add `consensus_params.evidence.max_age_duration`. Rename 797 `consensus_params.evidence.max_age` to `max_age_num_blocks`. 798 - [cli] [\#1771](https://github.com/tendermint/tendermint/issues/1771) `tendermint lite` now uses new light client package (`lite2`) 799 and has 3 more flags: `--trusting-period`, `--trusted-height` and 800 `--trusted-hash` 801 802 - Apps 803 804 - [tm-bench] Removed tm-bench in favor of [tm-load-test](https://github.com/informalsystems/tm-load-test) 805 806 - Go API 807 808 - [rpc] [\#3953](https://github.com/tendermint/tendermint/issues/3953) Modify NewHTTP, NewXXXClient functions to return an error on invalid remote instead of panicking (@mrekucci) 809 - [rpc/client] [\#3471](https://github.com/tendermint/tendermint/issues/3471) `Validators` now requires two more args: `page` and `perPage` 810 - [libs/common] [\#3262](https://github.com/tendermint/tendermint/issues/3262) Make error the last parameter of `Task` (@PSalant726) 811 - [cs/types] [\#3262](https://github.com/tendermint/tendermint/issues/3262) Rename `GotVoteFromUnwantedRoundError` to `ErrGotVoteFromUnwantedRound` (@PSalant726) 812 - [libs/common] [\#3862](https://github.com/tendermint/tendermint/issues/3862) Remove `errors.go` from `libs/common` 813 - [libs/common] [\#4230](https://github.com/tendermint/tendermint/issues/4230) Move `KV` out of common to its own pkg 814 - [libs/common] [\#4230](https://github.com/tendermint/tendermint/issues/4230) Rename `cmn.KVPair(s)` to `kv.Pair(s)`s 815 - [libs/common] [\#4232](https://github.com/tendermint/tendermint/issues/4232) Move `Service` & `BaseService` from `libs/common` to `libs/service` 816 - [libs/common] [\#4232](https://github.com/tendermint/tendermint/issues/4232) Move `common/nil.go` to `types/utils.go` & make the functions private 817 - [libs/common] [\#4231](https://github.com/tendermint/tendermint/issues/4231) Move random functions from `libs/common` into pkg `rand` 818 - [libs/common] [\#4237](https://github.com/tendermint/tendermint/issues/4237) Move byte functions from `libs/common` into pkg `bytes` 819 - [libs/common] [\#4237](https://github.com/tendermint/tendermint/issues/4237) Move throttletimer functions from `libs/common` into pkg `timer` 820 - [libs/common] [\#4237](https://github.com/tendermint/tendermint/issues/4237) Move tempfile functions from `libs/common` into pkg `tempfile` 821 - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move os functions from `libs/common` into pkg `os` 822 - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move net functions from `libs/common` into pkg `net` 823 - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move mathematical functions and types out of `libs/common` to `math` pkg 824 - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move string functions out of `libs/common` to `strings` pkg 825 - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move async functions out of `libs/common` to `async` pkg 826 - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move bit functions out of `libs/common` to `bits` pkg 827 - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move cmap functions out of `libs/common` to `cmap` pkg 828 - [libs/common] [\#4258](https://github.com/tendermint/tendermint/issues/4258) Remove `Rand` from all `rand` pkg functions 829 - [types] [\#2565](https://github.com/tendermint/tendermint/issues/2565) Remove `MockBadEvidence` & `MockGoodEvidence` in favor of `MockEvidence` 830 831 - Blockchain Protocol 832 833 - [abci] [\#2521](https://github.com/tendermint/tendermint/issues/2521) Remove `TotalTxs` and `NumTxs` from `Header` 834 - [types] [\#4151](https://github.com/tendermint/tendermint/pull/4151) Enforce ordering of votes in DuplicateVoteEvidence to be lexicographically sorted on BlockID 835 - [types] [\#1648](https://github.com/tendermint/tendermint/issues/1648) Change `Commit` to consist of just signatures 836 837 - P2P Protocol 838 839 - [p2p] [\#3668](https://github.com/tendermint/tendermint/pull/3668) Make `SecretConnection` non-malleable 840 841 - [proto] [\#3986](https://github.com/tendermint/tendermint/pull/3986) Prefix protobuf types to avoid name conflicts. 842 - ABCI becomes `tendermint.abci.types` with the new API endpoint `/tendermint.abci.types.ABCIApplication/` 843 - core_grpc becomes `tendermint.rpc.grpc` with the new API endpoint `/tendermint.rpc.grpc.BroadcastAPI/` 844 - merkle becomes `tendermint.crypto.merkle` 845 - libs.common becomes `tendermint.libs.common` 846 - proto3 becomes `tendermint.types.proto3` 847 848 ### FEATURES: 849 850 - [p2p] [\#4053](https://github.com/tendermint/tendermint/issues/4053) Add `unconditional_peer_ids` and `persistent_peers_max_dial_period` config variables (see ADR-050) (@dongsam) 851 - [tools] [\#4227](https://github.com/tendermint/tendermint/pull/4227) Implement `tendermint debug kill` and 852 `tendermint debug dump` commands for Tendermint node debugging functionality. See `--help` in both 853 commands for further documentation and usage. 854 - [cli] [\#4234](https://github.com/tendermint/tendermint/issues/4234) Add `--db_backend and --db_dir` flags (@princesinha19) 855 - [cli] [\#4113](https://github.com/tendermint/tendermint/issues/4113) Add optional `--genesis_hash` flag to check genesis hash upon startup 856 - [config] [\#3831](https://github.com/tendermint/tendermint/issues/3831) Add support for [RocksDB](https://rocksdb.org/) (@Stumble) 857 - [rpc] [\#3985](https://github.com/tendermint/tendermint/issues/3985) Add new `/block_by_hash` endpoint, which allows to fetch a block by its hash (@princesinha19) 858 - [metrics] [\#4263](https://github.com/tendermint/tendermint/issues/4263) Add 859 - `consensus_validator_power`: track your validators power 860 - `consensus_validator_last_signed_height`: track at which height the validator last signed 861 - `consensus_validator_missed_blocks`: total amount of missed blocks for a validator 862 as gauges in prometheus for validator specific metrics 863 - [rpc/lib] [\#4248](https://github.com/tendermint/tendermint/issues/4248) RPC client basic authentication support (@greg-szabo) 864 - [lite2] [\#1771](https://github.com/tendermint/tendermint/issues/1771) Light client with weak subjectivity 865 866 ### IMPROVEMENTS: 867 868 - [rpc] [\#3188](https://github.com/tendermint/tendermint/issues/3188) Added `block_size` to `BlockMeta` this is reflected in `/blockchain` 869 - [types] [\#2521](https://github.com/tendermint/tendermint/issues/2521) Add `NumTxs` to `BlockMeta` and `EventDataNewBlockHeader` 870 - [p2p] [\#4185](https://github.com/tendermint/tendermint/pull/4185) Simplify `SecretConnection` handshake with merlin 871 - [cli] [\#4065](https://github.com/tendermint/tendermint/issues/4065) Add `--consensus.create_empty_blocks_interval` flag (@jgimeno) 872 - [docs] [\#4065](https://github.com/tendermint/tendermint/issues/4065) Document `--consensus.create_empty_blocks_interval` flag (@jgimeno) 873 - [crypto] [\#4190](https://github.com/tendermint/tendermint/pull/4190) Added SR25519 signature scheme 874 - [abci] [\#4177] kvstore: Return `LastBlockHeight` and `LastBlockAppHash` in `Info` (@princesinha19) 875 - [rpc] [\#2741](https://github.com/tendermint/tendermint/issues/2741) Add `proposer` to `/consensus_state` response (@princesinha19) 876 - [deps] [\#4289](https://github.com/tendermint/tendermint/pull/4289) Update tm-db to 0.4.0, this includes major breaking changes in the dep that change how errors are handled. 877 878 ### BUG FIXES: 879 880 - [rpc/lib][\#4051](https://github.com/tendermint/tendermint/pull/4131) Fix RPC client, which was previously resolving https protocol to http (@yenkhoon) 881 - [rpc] [\#4141](https://github.com/tendermint/tendermint/pull/4141) JSONRPCClient: validate that Response.ID matches Request.ID 882 - [rpc] [\#4141](https://github.com/tendermint/tendermint/pull/4141) WSClient: check for unsolicited responses 883 - [types] [\4164](https://github.com/tendermint/tendermint/pull/4164) Prevent temporary power overflows on validator updates 884 - [cs] [\#4069](https://github.com/tendermint/tendermint/issues/4069) Don't panic when block meta is not found in store (@gregzaitsev) 885 - [types] [\#4164](https://github.com/tendermint/tendermint/issues/4164) Prevent temporary power overflows on validator updates (joint 886 efforts of @gchaincl and @ancazamfir) 887 - [p2p] [\#4140](https://github.com/tendermint/tendermint/issues/4140) `SecretConnection`: use the transcript solely for authentication (i.e. MAC) 888 - [consensus/types] [\#4243](https://github.com/tendermint/tendermint/issues/4243) fix BenchmarkRoundStateDeepCopy panics (@cuonglm) 889 - [rpc] [\#4256](https://github.com/tendermint/tendermint/issues/4256) Pass `outCapacity` to `eventBus#Subscribe` when subscribing using a local client 890 891 ## v0.32.13 892 893 *August 5, 2020* 894 895 ### BUG FIXES 896 897 - [privval] [\#5112](https://github.com/tendermint/tendermint/issues/5112) If remote signer errors, don't retry (@melekes) 898 899 ## v0.32.12 900 901 *May 19, 2020* 902 903 ### BUG FIXES 904 905 - [p2p] [\#4847](https://github.com/tendermint/tendermint/pull/4847) Return masked IP (not the actual IP) in addrbook#groupKey (@melekes) 906 907 ## v0.32.11 908 909 *April 29, 2020* 910 911 ### BUG FIXES: 912 913 - [privval] [\#4275](https://github.com/tendermint/tendermint/issues/4275) Fix consensus failure when remote signer drops (@melekes) 914 915 ## v0.32.10 916 917 *April 6, 2020* 918 919 This security release fixes: 920 921 ### Denial of Service 1 922 923 Tendermint 0.33.2 and earlier does not limit the number of P2P connection 924 requests. For each p2p connection, Tendermint allocates ~0.5MB. Even though 925 this memory is garbage collected once the connection is terminated (due to 926 duplicate IP or reaching a maximum number of inbound peers), temporary memory 927 spikes can lead to OOM (Out-Of-Memory) exceptions. 928 929 Tendermint 0.33.3 (and 0.32.10) limits the total number of P2P incoming 930 connection requests to to `p2p.max_num_inbound_peers + 931 len(p2p.unconditional_peer_ids)`. 932 933 Notes: 934 935 - Tendermint does not rate limit P2P connection requests per IP (an attacker 936 can saturate all the inbound slots); 937 - Tendermint does not rate limit HTTP(S) requests. If you expose any RPC 938 endpoints to the public, please make sure to put in place some protection 939 (https://www.nginx.com/blog/rate-limiting-nginx/). We may implement this in 940 the future ([\#1696](https://github.com/tendermint/tendermint/issues/1696)). 941 942 ### Denial of Service 2 943 944 Tendermint 0.33.2 and earlier does not reclaim `activeID` of a peer after it's 945 removed in `Mempool` reactor. This does not happen all the time. It only 946 happens when a connection fails (for any reason) before the Peer is created and 947 added to all reactors. `RemovePeer` is therefore called before `AddPeer`, which 948 leads to always growing memory (`activeIDs` map). The `activeIDs` map has a 949 maximum size of 65535 and the node will panic if this map reaches the maximum. 950 An attacker can create a lot of connection attempts (exploiting Denial of 951 Service 1), which ultimately will lead to the node panicking. 952 953 Tendermint 0.33.3 (and 0.32.10) claims `activeID` for a peer in `InitPeer`, 954 which is executed before `MConnection` is started. 955 956 Notes: 957 958 - `InitPeer` function was added to all reactors to combat a similar issue - 959 [\#3338](https://github.com/tendermint/tendermint/issues/3338); 960 - Denial of Service 2 is independent of Denial of Service 1 and can be executed 961 without it. 962 963 **All clients are recommended to upgrade** 964 965 Special thanks to [fudongbai](https://hackerone.com/fudongbai) for finding 966 and reporting this. 967 968 ### SECURITY: 969 970 - [mempool] Reserve IDs in InitPeer instead of AddPeer (@tessr) 971 - [p2p] Limit the number of incoming connections (@melekes) 972 973 ## v0.32.9 974 975 _January, 9, 2020_ 976 977 Special thanks to external contributors on this release: @greg-szabo, @gregzaitsev, @yenkhoon 978 979 ### FEATURES: 980 981 - [rpc/lib] [\#4248](https://github.com/tendermint/tendermint/issues/4248) RPC client basic authentication support (@greg-szabo) 982 983 - [metrics] [\#4294](https://github.com/tendermint/tendermint/pull/4294) Add 984 - `consensus_validator_power`: track your validators power 985 - `consensus_validator_last_signed_height`: track at which height the validator last signed 986 - `consensus_validator_missed_blocks`: total amount of missed blocks for a validator 987 as gauges in prometheus for validator specific metrics 988 989 ### BUG FIXES: 990 991 - [rpc/lib] [\#4131](https://github.com/tendermint/tendermint/pull/4131) Fix RPC client, which was previously resolving https protocol to http (@yenkhoon) 992 - [cs] [\#4069](https://github.com/tendermint/tendermint/issues/4069) Don't panic when block meta is not found in store (@gregzaitsev) 993 994 ## v0.32.8 995 996 *November 19, 2019* 997 998 Special thanks to external contributors on this release: @erikgrinaker, @guagualvcha, @hsyis, @cosmostuba, @whunmr, @austinabell 999 1000 1001 ### BREAKING CHANGES: 1002 1003 - Go API 1004 1005 - [libs/pubsub] [\#4070](https://github.com/tendermint/tendermint/pull/4070) `Query#(Matches|Conditions)` returns an error. 1006 1007 ### IMPROVEMENTS: 1008 1009 - [mempool] [\#4083](https://github.com/tendermint/tendermint/pull/4083) Added TxInfo parameter to CheckTx(), and removed CheckTxWithInfo() (@erikgrinaker) 1010 - [mempool] [\#4057](https://github.com/tendermint/tendermint/issues/4057) Include peer ID when logging rejected txns (@erikgrinaker) 1011 - [tools] [\#4023](https://github.com/tendermint/tendermint/issues/4023) Improved `tm-monitor` formatting of start time and avg tx throughput (@erikgrinaker) 1012 - [p2p] [\#3991](https://github.com/tendermint/tendermint/issues/3991) Log "has been established or dialed" as debug log instead of Error for connected peers (@whunmr) 1013 - [rpc] [\#4077](https://github.com/tendermint/tendermint/pull/4077) Added support for `EXISTS` clause to the Websocket query interface. 1014 - [privval] Add `SignerDialerEndpointRetryWaitInterval` option (@cosmostuba) 1015 - [crypto] Add `RegisterKeyType` to amino to allow external key types registration (@austinabell) 1016 1017 ### BUG FIXES: 1018 1019 - [libs/pubsub] [\#4070](https://github.com/tendermint/tendermint/pull/4070) Strip out non-numeric characters when attempting to match numeric values. 1020 - [libs/pubsub] [\#4070](https://github.com/tendermint/tendermint/pull/4070) No longer panic in Query#(Matches|Conditions) preferring to return an error instead. 1021 - [tools] [\#4023](https://github.com/tendermint/tendermint/issues/4023) Refresh `tm-monitor` health when validator count is updated (@erikgrinaker) 1022 - [state] [\#4104](https://github.com/tendermint/tendermint/pull/4104) txindex/kv: Fsync data to disk immediately after receiving it (@guagualvcha) 1023 - [state] [\#4095](https://github.com/tendermint/tendermint/pull/4095) txindex/kv: Return an error if there's one when the user searches for a tx (hash=X) (@hsyis) 1024 1025 ## v0.32.7 1026 1027 *October 18, 2019* 1028 1029 This security release fixes a vulnerability found in the `consensus` package, 1030 where an attacker could construct a `BlockPartMessage` message in such a way 1031 that it will lead to consensus failure. A few similar issues have been 1032 identified and fixed here. 1033 1034 **All clients are recommended to upgrade** 1035 1036 Special thanks to [elvishacker](https://hackerone.com/elvishacker) for finding 1037 and reporting this. 1038 1039 ### BREAKING CHANGES: 1040 1041 - Go API 1042 - [consensus] Modify `WAL#Write` and `WAL#WriteSync` to return an error if 1043 they fail to write a message 1044 1045 ### SECURITY: 1046 1047 - [consensus] Validate incoming messages more throughly 1048 1049 ## v0.32.6 1050 1051 *October 8, 2019* 1052 1053 The previous patch was insufficient because the attacker could still find a way 1054 to submit a `nil` pubkey by constructing a `PubKeyMultisigThreshold` pubkey 1055 with `nil` subpubkeys for example. 1056 1057 This release provides multiple fixes, which include recovering from panics when 1058 accepting new peers and only allowing `ed25519` pubkeys. 1059 1060 **All clients are recommended to upgrade** 1061 1062 Special thanks to [fudongbai](https://hackerone.com/fudongbai) for pointing 1063 this out. 1064 1065 ### SECURITY: 1066 1067 - [p2p] [\#4030](https://github.com/tendermint/tendermint/issues/4030) Only allow ed25519 pubkeys when connecting 1068 1069 ## v0.32.5 1070 1071 *October 1, 2019* 1072 1073 This release fixes a major security vulnerability found in the `p2p` package. 1074 All clients are recommended to upgrade. See 1075 [\#4030](https://github.com/tendermint/tendermint/issues/4030) for details. 1076 1077 Special thanks to [fudongbai](https://hackerone.com/fudongbai) for discovering 1078 and reporting this issue. 1079 1080 ### SECURITY: 1081 1082 - [p2p] [\#4030](https://github.com/tendermint/tendermint/issues/4030) Fix for panic on nil public key send to a peer 1083 1084 ## v0.32.4 1085 1086 *September 19, 2019* 1087 1088 Special thanks to external contributors on this release: @jon-certik, @gracenoah, @PSalant726, @gchaincl 1089 1090 ### BREAKING CHANGES: 1091 1092 - CLI/RPC/Config 1093 - [rpc] [\#3984](https://github.com/tendermint/tendermint/issues/3984) Add `MempoolClient` interface to `Client` interface 1094 1095 ### IMPROVEMENTS: 1096 1097 - [rpc] [\#2010](https://github.com/tendermint/tendermint/issues/2010) Add NewHTTPWithClient and NewJSONRPCClientWithHTTPClient (note these and NewHTTP, NewJSONRPCClient functions panic if remote is invalid) (@gracenoah) 1098 - [rpc] [\#3882](https://github.com/tendermint/tendermint/issues/3882) Add custom marshalers to proto messages to disable `omitempty` 1099 - [deps] [\#3952](https://github.com/tendermint/tendermint/pull/3952) bump github.com/go-kit/kit from 0.6.0 to 0.9.0 1100 - [deps] [\#3951](https://github.com/tendermint/tendermint/pull/3951) bump github.com/stretchr/testify from 1.3.0 to 1.4.0 1101 - [deps] [\#3945](https://github.com/tendermint/tendermint/pull/3945) bump github.com/gorilla/websocket from 1.2.0 to 1.4.1 1102 - [deps] [\#3948](https://github.com/tendermint/tendermint/pull/3948) bump github.com/libp2p/go-buffer-pool from 0.0.1 to 0.0.2 1103 - [deps] [\#3943](https://github.com/tendermint/tendermint/pull/3943) bump github.com/fortytw2/leaktest from 1.2.0 to 1.3.0 1104 - [deps] [\#3939](https://github.com/tendermint/tendermint/pull/3939) bump github.com/rs/cors from 1.6.0 to 1.7.0 1105 - [deps] [\#3937](https://github.com/tendermint/tendermint/pull/3937) bump github.com/magiconair/properties from 1.8.0 to 1.8.1 1106 - [deps] [\#3947](https://github.com/tendermint/tendermint/pull/3947) update gogo/protobuf version from v1.2.1 to v1.3.0 1107 - [deps] [\#4001](https://github.com/tendermint/tendermint/pull/4001) bump github.com/tendermint/tm-db from 0.1.1 to 0.2.0 1108 1109 ### BUG FIXES: 1110 1111 - [consensus] [\#3908](https://github.com/tendermint/tendermint/issues/3908) Wait `timeout_commit` to pass even if `create_empty_blocks` is `false` 1112 - [mempool] [\#3968](https://github.com/tendermint/tendermint/issues/3968) Fix memory loading error on 32-bit machines (@jon-certik) 1113 1114 ## v0.32.3 1115 1116 *August 28, 2019* 1117 1118 @climber73 wrote the [Writing a Tendermint Core application in Java 1119 (gRPC)](https://github.com/tendermint/tendermint/blob/master/docs/guides/java.md) 1120 guide. 1121 1122 Special thanks to external contributors on this release: 1123 @gchaincl, @bluele, @climber73 1124 1125 ### IMPROVEMENTS: 1126 1127 - [consensus] [\#3839](https://github.com/tendermint/tendermint/issues/3839) Reduce "Error attempting to add vote" message severity (Error -> Info) 1128 - [mempool] [\#3877](https://github.com/tendermint/tendermint/pull/3877) Make `max_tx_bytes` configurable instead of `max_msg_bytes` (@bluele) 1129 - [privval] [\#3370](https://github.com/tendermint/tendermint/issues/3370) Refactor and simplify validator/kms connection handling. Please refer to [this comment](https://github.com/tendermint/tendermint/pull/3370#issue-257360971) for details 1130 - [rpc] [\#3880](https://github.com/tendermint/tendermint/issues/3880) Document endpoints with `swagger`, introduce contract tests of implementation against documentation 1131 1132 ### BUG FIXES: 1133 1134 - [config] [\#3868](https://github.com/tendermint/tendermint/issues/3868) Move misplaced `max_msg_bytes` into mempool section (@bluele) 1135 - [rpc] [\#3910](https://github.com/tendermint/tendermint/pull/3910) Fix DATA RACE in HTTP client (@gchaincl) 1136 - [store] [\#3893](https://github.com/tendermint/tendermint/issues/3893) Fix "Unregistered interface types.Evidence" panic 1137 1138 ## v0.32.2 1139 1140 *July 31, 2019* 1141 1142 Special thanks to external contributors on this release: 1143 @ruseinov, @bluele, @guagualvcha 1144 1145 ### BREAKING CHANGES: 1146 1147 - Go API 1148 - [libs] [\#3811](https://github.com/tendermint/tendermint/issues/3811) Remove `db` from libs in favor of `https://github.com/tendermint/tm-db` 1149 1150 ### FEATURES: 1151 1152 - [blockchain] [\#3561](https://github.com/tendermint/tendermint/issues/3561) Add early version of the new blockchain reactor, which is supposed to be more modular and testable compared to the old version. To try it, you'll have to change `version` in the config file, [here](https://github.com/tendermint/tendermint/blob/master/config/toml.go#L303) NOTE: It's not ready for a production yet. For further information, see [ADR-40](https://github.com/tendermint/tendermint/blob/master/docs/architecture/adr-040-blockchain-reactor-refactor.md) & [ADR-43](https://github.com/tendermint/tendermint/blob/master/docs/architecture/adr-043-blockchain-riri-org.md) 1153 - [mempool] [\#3826](https://github.com/tendermint/tendermint/issues/3826) Make `max_msg_bytes` configurable(@bluele) 1154 - [node] [\#3846](https://github.com/tendermint/tendermint/pull/3846) Allow replacing existing p2p.Reactor(s) using [`CustomReactors` 1155 option](https://godoc.org/github.com/tendermint/tendermint/node#CustomReactors). 1156 Warning: beware of accidental name clashes. Here is the list of existing 1157 reactors: MEMPOOL, BLOCKCHAIN, CONSENSUS, EVIDENCE, PEX. 1158 - [rpc] [\#3818](https://github.com/tendermint/tendermint/issues/3818) Make `max_body_bytes` and `max_header_bytes` configurable(@bluele) 1159 - [rpc] [\#2252](https://github.com/tendermint/tendermint/issues/2252) Add `/broadcast_evidence` endpoint to submit double signing and other types of evidence 1160 1161 ### IMPROVEMENTS: 1162 1163 - [abci] [\#3809](https://github.com/tendermint/tendermint/issues/3809) Recover from application panics in `server/socket_server.go` to allow socket cleanup (@ruseinov) 1164 - [p2p] [\#3664](https://github.com/tendermint/tendermint/issues/3664) p2p/conn: reuse buffer when write/read from secret connection(@guagualvcha) 1165 - [p2p] [\#3834](https://github.com/tendermint/tendermint/issues/3834) Do not write 'Couldn't connect to any seeds' error log if there are no seeds in config file 1166 - [rpc] [\#3076](https://github.com/tendermint/tendermint/issues/3076) Improve transaction search performance 1167 1168 ### BUG FIXES: 1169 1170 - [p2p] [\#3644](https://github.com/tendermint/tendermint/issues/3644) Fix error logging for connection stop (@defunctzombie) 1171 - [rpc] [\#3813](https://github.com/tendermint/tendermint/issues/3813) Return err if page is incorrect (less than 0 or greater than total pages) 1172 1173 ## v0.32.1 1174 1175 *July 15, 2019* 1176 1177 Special thanks to external contributors on this release: 1178 @ParthDesai, @climber73, @jim380, @ashleyvega 1179 1180 This release contains a minor enhancement to the ABCI and some breaking changes to our libs folder, namely: 1181 - CheckTx requests include a `CheckTxType` enum that can be set to `Recheck` to indicate to the application that this transaction was already checked/validated and certain expensive operations (like checking signatures) can be skipped 1182 - Removed various functions from `libs` pkgs 1183 1184 ### BREAKING CHANGES: 1185 1186 - Go API 1187 1188 - [abci] [\#2127](https://github.com/tendermint/tendermint/issues/2127) The CheckTx and DeliverTx methods in the ABCI `Application` interface now take structs as arguments (RequestCheckTx and RequestDeliverTx, respectively), instead of just the raw tx bytes. This allows more information to be passed to these methods, for instance, indicating whether a tx has already been checked. 1189 - [libs] Remove unused `db/debugDB` and `common/colors.go` & `errors/errors.go` files (@marbar3778) 1190 - [libs] [\#2432](https://github.com/tendermint/tendermint/issues/2432) Remove unused `common/heap.go` file (@marbar3778) 1191 - [libs] Remove unused `date.go`, `io.go`. Remove `GoPath()`, `Prompt()` and `IsDirEmpty()` functions from `os.go` (@marbar3778) 1192 - [libs] Remove unused `FailRand()` func and minor clean up to `fail.go`(@marbar3778) 1193 1194 ### FEATURES: 1195 1196 - [node] Add variadic argument to `NewNode` to support functional options, allowing the Node to be more easily customized. 1197 - [node][\#3730](https://github.com/tendermint/tendermint/pull/3730) Add `CustomReactors` option to `NewNode` allowing caller to pass 1198 custom reactors to run inside Tendermint node (@ParthDesai) 1199 - [abci] [\#2127](https://github.com/tendermint/tendermint/issues/2127)RequestCheckTx has a new field, `CheckTxType`, which can take values of `CheckTxType_New` and `CheckTxType_Recheck`, indicating whether this is a new tx being checked for the first time or whether this tx is being rechecked after a block commit. This allows applications to skip certain expensive operations, like signature checking, if they've already been done once. see [docs](https://github.com/tendermint/tendermint/blob/eddb433d7c082efbeaf8974413a36641519ee895/docs/spec/abci/apps.md#mempool-connection) 1200 1201 ### IMPROVEMENTS: 1202 1203 - [rpc] [\#3700](https://github.com/tendermint/tendermint/issues/3700) Make possible to set absolute paths for TLS cert and key (@climber73) 1204 - [abci] [\#3513](https://github.com/tendermint/tendermint/issues/3513) Call the reqRes callback after the resCb so they always happen in the same order 1205 1206 ### BUG FIXES: 1207 1208 - [p2p] [\#3338](https://github.com/tendermint/tendermint/issues/3338) Prevent "sent next PEX request too soon" errors by not calling 1209 ensurePeers outside of ensurePeersRoutine 1210 - [behaviour] [\3772](https://github.com/tendermint/tendermint/pull/3772) Return correct reason in MessageOutOfOrder (@jim380) 1211 - [config] [\#3723](https://github.com/tendermint/tendermint/issues/3723) Add consensus_params to testnet config generation; document time_iota_ms (@ashleyvega) 1212 1213 1214 ## v0.32.0 1215 1216 *June 25, 2019* 1217 1218 Special thanks to external contributors on this release: 1219 @needkane, @SebastianElvis, @andynog, @Yawning, @wooparadog 1220 1221 This release contains breaking changes to our build and release processes, ABCI, 1222 and the RPC, namely: 1223 - Use Go modules instead of dep 1224 - Bring active development to the `master` Github branch 1225 - ABCI Tags are now Events - see 1226 [docs](https://github.com/tendermint/tendermint/blob/60827f75623b92eff132dc0eff5b49d2025c591e/docs/spec/abci/abci.md#events) 1227 - Bind RPC to localhost by default, not to the public interface [UPGRADING/RPC_Changes](./UPGRADING.md#rpc_changes) 1228 1229 ### BREAKING CHANGES: 1230 1231 * CLI/RPC/Config 1232 - [cli] [\#3613](https://github.com/tendermint/tendermint/issues/3613) Switch from golang/dep to Go Modules to resolve dependencies: 1233 It is recommended to switch to Go Modules if your project has tendermint as 1234 a dependency. Read more on Modules here: 1235 https://github.com/golang/go/wiki/Modules 1236 - [config] [\#3632](https://github.com/tendermint/tendermint/pull/3632) Removed `leveldb` as generic 1237 option for `db_backend`. Must be `goleveldb` or `cleveldb`. 1238 - [rpc] [\#3616](https://github.com/tendermint/tendermint/issues/3616) Fix field names for `/block_results` response (eg. `results.DeliverTx` 1239 -> `results.deliver_tx`). See docs for details. 1240 - [rpc] [\#3724](https://github.com/tendermint/tendermint/issues/3724) RPC now binds to `127.0.0.1` by default instead of `0.0.0.0` 1241 1242 * Apps 1243 - [abci] [\#1859](https://github.com/tendermint/tendermint/issues/1859) `ResponseCheckTx`, `ResponseDeliverTx`, `ResponseBeginBlock`, 1244 and `ResponseEndBlock` now include `Events` instead of `Tags`. Each `Event` 1245 contains a `type` and a list of `attributes` (list of key-value pairs) 1246 allowing for inclusion of multiple distinct events in each response. 1247 1248 * Go API 1249 - [abci] [\#3193](https://github.com/tendermint/tendermint/issues/3193) Use RequestDeliverTx and RequestCheckTx in the ABCI 1250 Application interface 1251 - [libs/db] [\#3632](https://github.com/tendermint/tendermint/pull/3632) Removed deprecated `LevelDBBackend` const 1252 If you have `db_backend` set to `leveldb` in your config file, please 1253 change it to `goleveldb` or `cleveldb`. 1254 - [p2p] [\#3521](https://github.com/tendermint/tendermint/issues/3521) Remove NewNetAddressStringWithOptionalID 1255 1256 * Blockchain Protocol 1257 1258 * P2P Protocol 1259 1260 ### FEATURES: 1261 1262 ### IMPROVEMENTS: 1263 - [abci/examples] [\#3659](https://github.com/tendermint/tendermint/issues/3659) Change validator update tx format in the `persistent_kvstore` to use base64 for pubkeys instead of hex (@needkane) 1264 - [consensus] [\#3656](https://github.com/tendermint/tendermint/issues/3656) Exit if SwitchToConsensus fails 1265 - [p2p] [\#3666](https://github.com/tendermint/tendermint/issues/3666) Add per channel telemetry to improve reactor observability 1266 - [rpc] [\#3686](https://github.com/tendermint/tendermint/pull/3686) `HTTPClient#Call` returns wrapped errors, so a caller could use `errors.Cause` to retrieve an error code. (@wooparadog) 1267 1268 ### BUG FIXES: 1269 - [libs/db] [\#3717](https://github.com/tendermint/tendermint/issues/3717) Fixed the BoltDB backend's Batch.Delete implementation (@Yawning) 1270 - [libs/db] [\#3718](https://github.com/tendermint/tendermint/issues/3718) Fixed the BoltDB backend's Get and Iterator implementation (@Yawning) 1271 - [node] [\#3716](https://github.com/tendermint/tendermint/issues/3716) Fix a bug where `nil` is recorded as node's address 1272 - [node] [\#3741](https://github.com/tendermint/tendermint/issues/3741) Fix profiler blocking the entire node 1273 1274 *Tendermint 0.31 release series has reached End-Of-Life and is no longer supported.* 1275 1276 ## v0.31.12 1277 1278 *April 6, 2020* 1279 1280 This security release fixes: 1281 1282 ### Denial of Service 1 1283 1284 Tendermint 0.33.2 and earlier does not limit the number of P2P connection requests. 1285 For each p2p connection, Tendermint allocates ~0.5MB. Even though this 1286 memory is garbage collected once the connection is terminated (due to duplicate 1287 IP or reaching a maximum number of inbound peers), temporary memory spikes can 1288 lead to OOM (Out-Of-Memory) exceptions. 1289 1290 Tendermint 0.33.3, 0.32.10, and 0.31.12 limit the total number of P2P incoming 1291 connection requests to to `p2p.max_num_inbound_peers + 1292 len(p2p.unconditional_peer_ids)`. 1293 1294 Notes: 1295 1296 - Tendermint does not rate limit P2P connection requests per IP (an attacker 1297 can saturate all the inbound slots); 1298 - Tendermint does not rate limit HTTP(S) requests. If you expose any RPC 1299 endpoints to the public, please make sure to put in place some protection 1300 (https://www.nginx.com/blog/rate-limiting-nginx/). We may implement this in 1301 the future ([\#1696](https://github.com/tendermint/tendermint/issues/1696)). 1302 1303 ### Denial of Service 2 1304 1305 Tendermint 0.33.2 and earlier does not reclaim `activeID` of a peer after it's 1306 removed in `Mempool` reactor. This does not happen all the time. It only 1307 happens when a connection fails (for any reason) before the Peer is created and 1308 added to all reactors. `RemovePeer` is therefore called before `AddPeer`, which 1309 leads to always growing memory (`activeIDs` map). The `activeIDs` map has a 1310 maximum size of 65535 and the node will panic if this map reaches the maximum. 1311 An attacker can create a lot of connection attempts (exploiting Denial of 1312 Service 1), which ultimately will lead to the node panicking. 1313 1314 Tendermint 0.33.3, 0.32.10, and 0.31.12 claim `activeID` for a peer in `InitPeer`, 1315 which is executed before `MConnection` is started. 1316 1317 Notes: 1318 1319 - `InitPeer` function was added to all reactors to combat a similar issue - 1320 [\#3338](https://github.com/tendermint/tendermint/issues/3338); 1321 - Denial of Service 2 is independent of Denial of Service 1 and can be executed 1322 without it. 1323 1324 **All clients are recommended to upgrade** 1325 1326 Special thanks to [fudongbai](https://hackerone.com/fudongbai) for finding 1327 and reporting this. 1328 1329 ### SECURITY: 1330 1331 - [mempool] Reserve IDs in InitPeer instead of AddPeer (@tessr) 1332 - [p2p] Limit the number of incoming connections (@melekes) 1333 1334 ## v0.31.11 1335 1336 *October 18, 2019* 1337 1338 This security release fixes a vulnerability found in the `consensus` package, 1339 where an attacker could construct a `BlockPartMessage` message in such a way 1340 that it will lead to consensus failure. A few similar issues have been 1341 identified and fixed here. 1342 1343 **All clients are recommended to upgrade** 1344 1345 Special thanks to [elvishacker](https://hackerone.com/elvishacker) for finding 1346 and reporting this. 1347 1348 ### BREAKING CHANGES: 1349 1350 - Go API 1351 - [consensus] Modify `WAL#Write` and `WAL#WriteSync` to return an error if 1352 they fail to write a message 1353 1354 ### SECURITY: 1355 1356 - [consensus] Validate incoming messages more throughly 1357 1358 ## v0.31.10 1359 1360 *October 8, 2019* 1361 1362 The previous patch was insufficient because the attacker could still find a way 1363 to submit a `nil` pubkey by constructing a `PubKeyMultisigThreshold` pubkey 1364 with `nil` subpubkeys for example. 1365 1366 This release provides multiple fixes, which include recovering from panics when 1367 accepting new peers and only allowing `ed25519` pubkeys. 1368 1369 **All clients are recommended to upgrade** 1370 1371 Special thanks to [fudongbai](https://hackerone.com/fudongbai) for pointing 1372 this out. 1373 1374 ### SECURITY: 1375 1376 - [p2p] [\#4030](https://github.com/tendermint/tendermint/issues/4030) Only allow ed25519 pubkeys when connecting 1377 1378 ## v0.31.9 1379 1380 *October 1, 2019* 1381 1382 This release fixes a major security vulnerability found in the `p2p` package. 1383 All clients are recommended to upgrade. See 1384 [\#4030](https://github.com/tendermint/tendermint/issues/4030) for details. 1385 1386 Special thanks to [fudongbai](https://hackerone.com/fudongbai) for discovering 1387 and reporting this issue. 1388 1389 ### SECURITY: 1390 1391 - [p2p] [\#4030](https://github.com/tendermint/tendermint/issues/4030) Fix for panic on nil public key send to a peer 1392 1393 ### BUG FIXES: 1394 1395 - [node] [\#3716](https://github.com/tendermint/tendermint/issues/3716) Fix a bug where `nil` is recorded as node's address 1396 - [node] [\#3741](https://github.com/tendermint/tendermint/issues/3741) Fix profiler blocking the entire node 1397 1398 ## v0.31.8 1399 1400 *July 29, 2019* 1401 1402 This releases fixes one bug in the PEX reactor and adds a `recover` to the Go's 1403 ABCI server, which allows it to properly cleanup. 1404 1405 ### IMPROVEMENTS: 1406 - [abci] [\#3809](https://github.com/tendermint/tendermint/issues/3809) Recover from application panics in `server/socket_server.go` to allow socket cleanup (@ruseinov) 1407 1408 ### BUG FIXES: 1409 - [p2p] [\#3338](https://github.com/tendermint/tendermint/issues/3338) Prevent "sent next PEX request too soon" errors by not calling 1410 ensurePeers outside of ensurePeersRoutine 1411 1412 ## v0.31.7 1413 1414 *June 3, 2019* 1415 1416 This releases fixes a regression in the mempool introduced in v0.31.6. 1417 The regression caused the invalid committed txs to be proposed in blocks over and 1418 over again. 1419 1420 ### BUG FIXES: 1421 - [mempool] [\#3699](https://github.com/tendermint/tendermint/issues/3699) Remove all committed txs from the mempool. 1422 This reverts the change from v0.31.6 where we only remove valid txs from the mempool. 1423 Note this means malicious proposals can cause txs to be dropped from the 1424 mempools of other nodes by including them in blocks before they are valid. 1425 See [\#3322](https://github.com/tendermint/tendermint/issues/3322). 1426 1427 ## v0.31.6 1428 1429 *May 31st, 2019* 1430 1431 This release contains many fixes and improvements, primarily for p2p functionality. 1432 It also fixes a security issue in the mempool package. 1433 1434 With this release, Tendermint now supports [boltdb](https://github.com/etcd-io/bbolt), although 1435 in experimental mode. Feel free to try and report to us any findings/issues. 1436 Note also that the build tags for compiling CLevelDB have changed. 1437 1438 Special thanks to external contributors on this release: 1439 @guagualvcha, @james-ray, @gregdhill, @climber73, @yutianwu, 1440 @carlosflrs, @defunctzombie, @leoluk, @needkane, @CrocdileChan 1441 1442 ### BREAKING CHANGES: 1443 1444 * Go API 1445 - [libs/common] Removed deprecated `PanicSanity`, `PanicCrisis`, 1446 `PanicConsensus` and `PanicQ` 1447 - [mempool, state] [\#2659](https://github.com/tendermint/tendermint/issues/2659) `Mempool` now an interface that lives in the mempool package. 1448 See issue and PR for more details. 1449 - [p2p] [\#3346](https://github.com/tendermint/tendermint/issues/3346) `Reactor#InitPeer` method is added to `Reactor` interface 1450 - [types] [\#1648](https://github.com/tendermint/tendermint/issues/1648) `Commit#VoteSignBytes` signature was changed 1451 1452 ### FEATURES: 1453 - [node] [\#2659](https://github.com/tendermint/tendermint/issues/2659) Add `node.Mempool()` method, which allows you to access mempool 1454 - [libs/db] [\#3604](https://github.com/tendermint/tendermint/pull/3604) Add experimental support for bolt db (etcd's fork of bolt) (@CrocdileChan) 1455 1456 ### IMPROVEMENTS: 1457 - [cli] [\#3585](https://github.com/tendermint/tendermint/issues/3585) Add `--keep-addr-book` option to `unsafe_reset_all` cmd to not 1458 clear the address book (@climber73) 1459 - [cli] [\#3160](https://github.com/tendermint/tendermint/issues/3160) Add 1460 `--config=<path-to-config>` option to `testnet` cmd (@gregdhill) 1461 - [cli] [\#3661](https://github.com/tendermint/tendermint/pull/3661) Add 1462 `--hostname-suffix`, `--hostname` and `--random-monikers` options to `testnet` 1463 cmd for greater peer address/identity generation flexibility. 1464 - [crypto] [\#3672](https://github.com/tendermint/tendermint/issues/3672) Return more info in the `AddSignatureFromPubKey` error 1465 - [cs/replay] [\#3460](https://github.com/tendermint/tendermint/issues/3460) Check appHash for each block 1466 - [libs/db] [\#3611](https://github.com/tendermint/tendermint/issues/3611) Conditional compilation 1467 * Use `cleveldb` tag instead of `gcc` to compile Tendermint with CLevelDB or 1468 use `make build_c` / `make install_c` (full instructions can be found at 1469 https://docs.tendermint.com/master/introduction/install.html#compile-with-cleveldb-support) 1470 * Use `boltdb` tag to compile Tendermint with bolt db 1471 - [node] [\#3362](https://github.com/tendermint/tendermint/issues/3362) Return an error if `persistent_peers` list is invalid (except 1472 when IP lookup fails) 1473 - [p2p] [\#3463](https://github.com/tendermint/tendermint/pull/3463) Do not log "Can't add peer's address to addrbook" error for a private peer (@guagualvcha) 1474 - [p2p] [\#3531](https://github.com/tendermint/tendermint/issues/3531) Terminate session on nonce wrapping (@climber73) 1475 - [pex] [\#3647](https://github.com/tendermint/tendermint/pull/3647) Dial seeds, if any, instead of crawling peers first (@defunctzombie) 1476 - [rpc] [\#3534](https://github.com/tendermint/tendermint/pull/3534) Add support for batched requests/responses in JSON RPC 1477 - [rpc] [\#3362](https://github.com/tendermint/tendermint/issues/3362) `/dial_seeds` & `/dial_peers` return errors if addresses are 1478 incorrect (except when IP lookup fails) 1479 1480 ### BUG FIXES: 1481 - [consensus] [\#3067](https://github.com/tendermint/tendermint/issues/3067) Fix replay from appHeight==0 with validator set changes (@james-ray) 1482 - [consensus] [\#3304](https://github.com/tendermint/tendermint/issues/3304) Create a peer state in consensus reactor before the peer 1483 is started (@guagualvcha) 1484 - [lite] [\#3669](https://github.com/tendermint/tendermint/issues/3669) Add context parameter to RPC Handlers in proxy routes (@yutianwu) 1485 - [mempool] [\#3322](https://github.com/tendermint/tendermint/issues/3322) When a block is committed, only remove committed txs from the mempool 1486 that were valid (ie. `ResponseDeliverTx.Code == 0`) 1487 - [p2p] [\#3338](https://github.com/tendermint/tendermint/issues/3338) Ensure `RemovePeer` is always called before `InitPeer` (upon a peer 1488 reconnecting to our node) 1489 - [p2p] [\#3532](https://github.com/tendermint/tendermint/issues/3532) Limit the number of attempts to connect to a peer in seed mode 1490 to 16 (as a result, the node will stop retrying after a 35 hours time window) 1491 - [p2p] [\#3362](https://github.com/tendermint/tendermint/issues/3362) Allow inbound peers to be persistent, including for seed nodes. 1492 - [pex] [\#3603](https://github.com/tendermint/tendermint/pull/3603) Dial seeds when addrbook needs more addresses (@defunctzombie) 1493 1494 ### OTHERS: 1495 - [networks] fixes ansible integration script (@carlosflrs) 1496 1497 ## v0.31.5 1498 1499 *April 16th, 2019* 1500 1501 This release fixes a regression from v0.31.4 where, in existing chains that 1502 were upgraded, `/validators` could return an empty validator set. This is true 1503 for almost all heights, given the validator set remains the same. 1504 1505 Special thanks to external contributors on this release: 1506 @brapse, @guagualvcha, @dongsam, @phucc 1507 1508 ### IMPROVEMENTS: 1509 1510 - [libs/common] `CMap`: slight optimization in `Keys()` and `Values()` (@phucc) 1511 - [gitignore] gitignore: add .vendor-new (@dongsam) 1512 1513 ### BUG FIXES: 1514 1515 - [state] [\#3537](https://github.com/tendermint/tendermint/pull/3537#issuecomment-482711833) 1516 `LoadValidators`: do not return an empty validator set 1517 - [blockchain] [\#3457](https://github.com/tendermint/tendermint/issues/3457) 1518 Fix "peer did not send us anything" in `fast_sync` mode when under high pressure 1519 1520 ## v0.31.4 1521 1522 *April 12th, 2019* 1523 1524 This release fixes a regression from v0.31.3 which used the peer's `SocketAddr` to add the peer to 1525 the address book. This swallowed the peer's self-reported port which is important in case of reconnect. 1526 It brings back `NetAddress()` to `NodeInfo` and uses it instead of `SocketAddr` for adding peers. 1527 Additionally, it improves response time on the `/validators` or `/status` RPC endpoints. 1528 As a side-effect it makes these RPC endpoint more difficult to DoS and fixes a performance degradation in `ExecCommitBlock`. 1529 Also, it contains an [ADR](https://github.com/tendermint/tendermint/pull/3539) that proposes decoupling the 1530 responsibility for peer behaviour from the `p2p.Switch` (by @brapse). 1531 1532 Special thanks to external contributors on this release: 1533 @brapse, @guagualvcha, @mydring 1534 1535 ### IMPROVEMENTS: 1536 1537 - [p2p] [\#3463](https://github.com/tendermint/tendermint/pull/3463) Do not log "Can't add peer's address to addrbook" error for a private peer 1538 - [p2p] [\#3547](https://github.com/tendermint/tendermint/pull/3547) Fix a couple of annoying typos (@mdyring) 1539 1540 ### BUG FIXES: 1541 1542 - [docs] [\#3514](https://github.com/tendermint/tendermint/issues/3514) Fix block.Header.Time description (@melekes) 1543 - [p2p] [\#2716](https://github.com/tendermint/tendermint/issues/2716) Check if we're already connected to peer right before dialing it (@melekes) 1544 - [p2p] [\#3545](https://github.com/tendermint/tendermint/issues/3545) Add back `NetAddress()` to `NodeInfo` and use it instead of peer's `SocketAddr()` when adding a peer to the `PEXReactor` (potential fix for [\#3532](https://github.com/tendermint/tendermint/issues/3532)) 1545 - [state] [\#3438](https://github.com/tendermint/tendermint/pull/3438) 1546 Persist validators every 100000 blocks even if no changes to the set 1547 occurred (@guagualvcha). This 1548 1) Prevents possible DoS attack using `/validators` or `/status` RPC 1549 endpoints. Before response time was growing linearly with height if no 1550 changes were made to the validator set. 1551 2) Fixes performance degradation in `ExecCommitBlock` where we call 1552 `LoadValidators` for each `Evidence` in the block. 1553 1554 ## v0.31.3 1555 1556 *April 1st, 2019* 1557 1558 This release includes two security sensitive fixes: it ensures generated private 1559 keys are valid, and it prevents certain DNS lookups that would cause the node to 1560 panic if the lookup failed. 1561 1562 ### BREAKING CHANGES: 1563 * Go API 1564 - [crypto/secp256k1] [\#3439](https://github.com/tendermint/tendermint/issues/3439) 1565 The `secp256k1.GenPrivKeySecp256k1` function has changed to guarantee that it returns a valid key, which means it 1566 will return a different private key than in previous versions for the same secret. 1567 1568 ### BUG FIXES: 1569 1570 - [crypto/secp256k1] [\#3439](https://github.com/tendermint/tendermint/issues/3439) 1571 Ensure generated private keys are valid by randomly sampling until a valid key is found. 1572 Previously, it was possible (though rare!) to generate keys that exceeded the curve order. 1573 Such keys would lead to invalid signatures. 1574 - [p2p] [\#3522](https://github.com/tendermint/tendermint/issues/3522) Memoize 1575 socket address in peer connections to avoid DNS lookups. Previously, failed 1576 DNS lookups could cause the node to panic. 1577 1578 ## v0.31.2 1579 1580 *March 30th, 2019* 1581 1582 This release fixes a regression from v0.31.1 where Tendermint panics under 1583 mempool load for external ABCI apps. 1584 1585 Special thanks to external contributors on this release: 1586 @guagualvcha 1587 1588 ### BREAKING CHANGES: 1589 1590 * CLI/RPC/Config 1591 1592 * Apps 1593 1594 * Go API 1595 - [libs/autofile] [\#3504](https://github.com/tendermint/tendermint/issues/3504) Remove unused code in autofile package. Deleted functions: `Group.Search`, `Group.FindLast`, `GroupReader.ReadLine`, `GroupReader.PushLine`, `MakeSimpleSearchFunc` (@guagualvcha) 1596 1597 * Blockchain Protocol 1598 1599 * P2P Protocol 1600 1601 ### FEATURES: 1602 1603 ### IMPROVEMENTS: 1604 1605 - [circle] [\#3497](https://github.com/tendermint/tendermint/issues/3497) Move release management to CircleCI 1606 1607 ### BUG FIXES: 1608 1609 - [mempool] [\#3512](https://github.com/tendermint/tendermint/issues/3512) Fix panic from concurrent access to txsMap, a regression for external ABCI apps introduced in v0.31.1 1610 1611 ## v0.31.1 1612 1613 *March 27th, 2019* 1614 1615 This release contains a major improvement for the mempool that reduce the amount of sent data by about 30% 1616 (see some numbers below). 1617 It also fixes a memory leak in the mempool and adds TLS support to the RPC server by providing a certificate and key in the config. 1618 1619 Special thanks to external contributors on this release: 1620 @brapse, @guagualvcha, @HaoyangLiu, @needkane, @TraceBundy 1621 1622 ### BREAKING CHANGES: 1623 1624 * CLI/RPC/Config 1625 1626 * Apps 1627 1628 * Go API 1629 - [crypto] [\#3426](https://github.com/tendermint/tendermint/pull/3426) Remove `Ripemd160` helper method (@needkane) 1630 - [libs/common] [\#3429](https://github.com/tendermint/tendermint/pull/3429) Remove `RepeatTimer` (also `TimerMaker` and `Ticker` interface) 1631 - [rpc/client] [\#3458](https://github.com/tendermint/tendermint/issues/3458) Include `NetworkClient` interface into `Client` interface 1632 - [types] [\#3448](https://github.com/tendermint/tendermint/issues/3448) Remove method `PB2TM.ConsensusParams` 1633 1634 * Blockchain Protocol 1635 1636 * P2P Protocol 1637 1638 ### FEATURES: 1639 1640 - [rpc] [\#3419](https://github.com/tendermint/tendermint/issues/3419) Start HTTPS server if `rpc.tls_cert_file` and `rpc.tls_key_file` are provided in the config (@guagualvcha) 1641 1642 ### IMPROVEMENTS: 1643 1644 - [docs] [\#3140](https://github.com/tendermint/tendermint/issues/3140) Formalize proposer election algorithm properties 1645 - [docs] [\#3482](https://github.com/tendermint/tendermint/issues/3482) Fix broken links (@brapse) 1646 - [mempool] [\#2778](https://github.com/tendermint/tendermint/issues/2778) No longer send txs back to peers who sent it to you. 1647 Also, limit to 65536 active peers. 1648 This vastly improves the bandwidth consumption of nodes. 1649 For instance, for a 4 node localnet, in a test sending 250byte txs for 120 sec. at 500 txs/sec (total of 15MB): 1650 - total bytes received from 1st node: 1651 - before: 42793967 (43MB) 1652 - after: 30003256 (30MB) 1653 - total bytes sent to 1st node: 1654 - before: 30569339 (30MB) 1655 - after: 19304964 (19MB) 1656 - [p2p] [\#3475](https://github.com/tendermint/tendermint/issues/3475) Simplify `GetSelectionWithBias` for addressbook (@guagualvcha) 1657 - [rpc/lib/client] [\#3430](https://github.com/tendermint/tendermint/issues/3430) Disable compression for HTTP client to prevent GZIP-bomb DoS attacks (@guagualvcha) 1658 1659 ### BUG FIXES: 1660 1661 - [blockchain] [\#2699](https://github.com/tendermint/tendermint/issues/2699) Update the maxHeight when a peer is removed 1662 - [mempool] [\#3478](https://github.com/tendermint/tendermint/issues/3478) Fix memory-leak related to `broadcastTxRoutine` (@HaoyangLiu) 1663 1664 1665 ## v0.31.0 1666 1667 *March 16th, 2019* 1668 1669 Special thanks to external contributors on this release: 1670 @danil-lashin, @guagualvcha, @siburu, @silasdavis, @srmo, @Stumble, @svenstaro 1671 1672 This release is primarily about the new pubsub implementation, dubbed `pubsub 2.0`, and related changes, 1673 like configurable limits on the number of active RPC subscriptions at a time (`max_subscription_clients`). 1674 Pubsub 2.0 is an improved version of the older pubsub that is non-blocking and has a nicer API. 1675 Note the improved pubsub API also resulted in some improvements to the HTTPClient interface and the API for WebSocket subscriptions. 1676 This release also adds a configurable limit to the mempool size (`max_txs_bytes`, default 1GB) 1677 and a configurable timeout for the `/broadcast_tx_commit` endpoint. 1678 1679 See the [v0.31.0 1680 Milestone](https://github.com/tendermint/tendermint/milestone/19?closed=1) for 1681 more details. 1682 1683 ### BREAKING CHANGES: 1684 1685 * CLI/RPC/Config 1686 - [config] [\#2920](https://github.com/tendermint/tendermint/issues/2920) Remove `consensus.blocktime_iota` parameter 1687 - [rpc] [\#3227](https://github.com/tendermint/tendermint/issues/3227) New PubSub design does not block on clients when publishing 1688 messages. Slow clients may miss messages and receive an error, terminating 1689 the subscription. 1690 - [rpc] [\#3269](https://github.com/tendermint/tendermint/issues/2826) Limit number of unique clientIDs with open subscriptions. Configurable via `rpc.max_subscription_clients` 1691 - [rpc] [\#3269](https://github.com/tendermint/tendermint/issues/2826) Limit number of unique queries a given client can subscribe to at once. Configurable via `rpc.max_subscriptions_per_client`. 1692 - [rpc] [\#3435](https://github.com/tendermint/tendermint/issues/3435) Default ReadTimeout and WriteTimeout changed to 10s. WriteTimeout can increased by setting `rpc.timeout_broadcast_tx_commit` in the config. 1693 - [rpc/client] [\#3269](https://github.com/tendermint/tendermint/issues/3269) Update `EventsClient` interface to reflect new pubsub/eventBus API [ADR-33](https://github.com/tendermint/tendermint/blob/develop/docs/architecture/adr-033-pubsub.md). This includes `Subscribe`, `Unsubscribe`, and `UnsubscribeAll` methods. 1694 1695 * Apps 1696 - [abci] [\#3403](https://github.com/tendermint/tendermint/issues/3403) Remove `time_iota_ms` from BlockParams. This is a 1697 ConsensusParam but need not be exposed to the app for now. 1698 - [abci] [\#2920](https://github.com/tendermint/tendermint/issues/2920) Rename `consensus_params.block_size` to `consensus_params.block` in ABCI ConsensusParams 1699 1700 * Go API 1701 - [libs/common] TrapSignal accepts logger as a first parameter and does not block anymore 1702 * previously it was dumping "captured ..." msg to os.Stdout 1703 * TrapSignal should not be responsible for blocking thread of execution 1704 - [libs/db] [\#3397](https://github.com/tendermint/tendermint/pull/3397) Add possibility to `Close()` `Batch` to prevent memory leak when using ClevelDB. (@Stumble) 1705 - [types] [\#3354](https://github.com/tendermint/tendermint/issues/3354) Remove RoundState from EventDataRoundState 1706 - [rpc] [\#3435](https://github.com/tendermint/tendermint/issues/3435) `StartHTTPServer` / `StartHTTPAndTLSServer` now require a Config (use `rpcserver.DefaultConfig`) 1707 1708 * Blockchain Protocol 1709 1710 * P2P Protocol 1711 1712 ### FEATURES: 1713 - [config] [\#3269](https://github.com/tendermint/tendermint/issues/2826) New configuration values for controlling RPC subscriptions: 1714 - `rpc.max_subscription_clients` sets the maximum number of unique clients 1715 with open subscriptions 1716 - `rpc.max_subscriptions_per_client`sets the maximum number of unique 1717 subscriptions from a given client 1718 - `rpc.timeout_broadcast_tx_commit` sets the time to wait for a tx to be committed during `/broadcast_tx_commit` 1719 - [types] [\#2920](https://github.com/tendermint/tendermint/issues/2920) Add `time_iota_ms` to block's consensus parameters (not exposed to the application) 1720 - [lite] [\#3269](https://github.com/tendermint/tendermint/issues/3269) Add `/unsubscribe_all` endpoint to unsubscribe from all events 1721 - [mempool] [\#3079](https://github.com/tendermint/tendermint/issues/3079) Bound mempool memory usage via the `mempool.max_txs_bytes` configuration value. Set to 1GB by default. The mempool's current `txs_total_bytes` is exposed via `total_bytes` field in 1722 `/num_unconfirmed_txs` and `/unconfirmed_txs` RPC endpoints. 1723 1724 ### IMPROVEMENTS: 1725 - [all] [\#3385](https://github.com/tendermint/tendermint/issues/3385), [\#3386](https://github.com/tendermint/tendermint/issues/3386) Various linting improvements 1726 - [crypto] [\#3371](https://github.com/tendermint/tendermint/issues/3371) Copy in secp256k1 package from go-ethereum instead of importing 1727 go-ethereum (@silasdavis) 1728 - [deps] [\#3382](https://github.com/tendermint/tendermint/issues/3382) Don't pin repos without releases 1729 - [deps] [\#3357](https://github.com/tendermint/tendermint/issues/3357), [\#3389](https://github.com/tendermint/tendermint/issues/3389), [\#3392](https://github.com/tendermint/tendermint/issues/3392) Update gogo/protobuf, golang/protobuf, levigo, golang.org/x/crypto 1730 - [libs/common] [\#3238](https://github.com/tendermint/tendermint/issues/3238) exit with zero (0) code upon receiving SIGTERM/SIGINT 1731 - [libs/db] [\#3378](https://github.com/tendermint/tendermint/issues/3378) CLevelDB#Stats now returns the following properties: 1732 - leveldb.num-files-at-level{n} 1733 - leveldb.stats 1734 - leveldb.sstables 1735 - leveldb.blockpool 1736 - leveldb.cachedblock 1737 - leveldb.openedtables 1738 - leveldb.alivesnaps 1739 - leveldb.aliveiters 1740 - [privval] [\#3351](https://github.com/tendermint/tendermint/pull/3351) First part of larger refactoring that clarifies and separates concerns in the privval package. 1741 1742 ### BUG FIXES: 1743 - [blockchain] [\#3358](https://github.com/tendermint/tendermint/pull/3358) Fix timer leak in `BlockPool` (@guagualvcha) 1744 - [cmd] [\#3408](https://github.com/tendermint/tendermint/issues/3408) Fix `testnet` command's panic when creating non-validator configs (using `--n` flag) (@srmo) 1745 - [libs/db/remotedb/grpcdb] [\#3402](https://github.com/tendermint/tendermint/issues/3402) Close Iterator/ReverseIterator after use 1746 - [libs/pubsub] [\#951](https://github.com/tendermint/tendermint/issues/951), [\#1880](https://github.com/tendermint/tendermint/issues/1880) Use non-blocking send when dispatching messages [ADR-33](https://github.com/tendermint/tendermint/blob/develop/docs/architecture/adr-033-pubsub.md) 1747 - [lite] [\#3364](https://github.com/tendermint/tendermint/issues/3364) Fix `/validators` and `/abci_query` proxy endpoints 1748 (@guagualvcha) 1749 - [p2p/conn] [\#3347](https://github.com/tendermint/tendermint/issues/3347) Reject all-zero shared secrets in the Diffie-Hellman step of secret-connection 1750 - [p2p] [\#3369](https://github.com/tendermint/tendermint/issues/3369) Do not panic when filter times out 1751 - [p2p] [\#3359](https://github.com/tendermint/tendermint/pull/3359) Fix reconnecting report duplicate ID error due to race condition between adding peer to peerSet and starting it (@guagualvcha) 1752 1753 ## v0.30.2 1754 1755 *March 10th, 2019* 1756 1757 This release fixes a CLevelDB memory leak. It was happening because we were not 1758 closing the WriteBatch object after use. See [levigo's 1759 godoc](https://godoc.org/github.com/jmhodges/levigo#WriteBatch.Close) for the 1760 Close method. Special thanks goes to @Stumble who both reported an issue in 1761 [cosmos-sdk](https://github.com/cosmos/cosmos-sdk/issues/3842) and provided a 1762 fix here. 1763 1764 ### BREAKING CHANGES: 1765 1766 * Go API 1767 - [libs/db] [\#3842](https://github.com/cosmos/cosmos-sdk/issues/3842) Add Close() method to Batch interface (@Stumble) 1768 1769 ### BUG FIXES: 1770 - [libs/db] [\#3842](https://github.com/cosmos/cosmos-sdk/issues/3842) Fix CLevelDB memory leak (@Stumble) 1771 1772 ## v0.30.1 1773 1774 *February 20th, 2019* 1775 1776 This release fixes a consensus halt and a DataCorruptionError after restart 1777 discovered in `game_of_stakes_6`. It also fixes a security issue in the p2p 1778 handshake by authenticating the NetAddress.ID of the peer we're dialing. 1779 1780 ### IMPROVEMENTS: 1781 1782 * [config] [\#3291](https://github.com/tendermint/tendermint/issues/3291) Make 1783 config.ResetTestRootWithChainID() create concurrency-safe test directories. 1784 1785 ### BUG FIXES: 1786 1787 * [consensus] [\#3295](https://github.com/tendermint/tendermint/issues/3295) 1788 Flush WAL on stop to prevent data corruption during graceful shutdown. 1789 * [consensus] [\#3302](https://github.com/tendermint/tendermint/issues/3302) 1790 Fix possible halt by resetting TriggeredTimeoutPrecommit before starting next height. 1791 * [rpc] [\#3251](https://github.com/tendermint/tendermint/issues/3251) Fix 1792 `/net_info#peers#remote_ip` format. New format spec: 1793 * dotted decimal ("192.0.2.1"), if ip is an IPv4 or IP4-mapped IPv6 address 1794 * IPv6 ("2001:db8::1"), if ip is a valid IPv6 address 1795 * [cmd] [\#3314](https://github.com/tendermint/tendermint/issues/3314) Return 1796 an error on `show_validator` when the private validator file does not exist. 1797 * [p2p] [\#3010](https://github.com/tendermint/tendermint/issues/3010#issuecomment-464287627) 1798 Authenticate a peer against its NetAddress.ID when dialing. 1799 1800 ## v0.30.0 1801 1802 *February 8th, 2019* 1803 1804 This release fixes yet another issue with the proposer selection algorithm. 1805 We hope it's the last one, but we won't be surprised if it's not. 1806 We plan to one day expose the selection algorithm more directly to 1807 the application ([\#3285](https://github.com/tendermint/tendermint/issues/3285)), and even to support randomness ([\#763](https://github.com/tendermint/tendermint/issues/763)). 1808 For more, see issues marked 1809 [proposer-selection](https://github.com/tendermint/tendermint/labels/proposer-selection). 1810 1811 This release also includes a fix to prevent Tendermint from including the same 1812 piece of evidence in more than one block. This issue was reported by @chengwenxi in our 1813 [bug bounty program](https://hackerone.com/cosmos). 1814 1815 ### BREAKING CHANGES: 1816 1817 * Apps 1818 - [state] [\#3222](https://github.com/tendermint/tendermint/issues/3222) 1819 Duplicate updates for the same validator are forbidden. Apps must ensure 1820 that a given `ResponseEndBlock.ValidatorUpdates` contains only one entry per pubkey. 1821 1822 * Go API 1823 - [types] [\#3222](https://github.com/tendermint/tendermint/issues/3222) 1824 Remove `Add` and `Update` methods from `ValidatorSet` in favor of new 1825 `UpdateWithChangeSet`. This allows updates to be applied as a set, instead of 1826 one at a time. 1827 1828 * Block Protocol 1829 - [state] [\#3286](https://github.com/tendermint/tendermint/issues/3286) Blocks that include already committed evidence are invalid. 1830 1831 * P2P Protocol 1832 - [consensus] [\#3222](https://github.com/tendermint/tendermint/issues/3222) 1833 Validator updates are applied as a set, instead of one at a time, thus 1834 impacting the proposer priority calculation. This ensures that the proposer 1835 selection algorithm does not depend on the order of updates in 1836 `ResponseEndBlock.ValidatorUpdates`. 1837 1838 ### IMPROVEMENTS: 1839 - [crypto] [\#3279](https://github.com/tendermint/tendermint/issues/3279) Use `btcec.S256().N` directly instead of hard coding a copy. 1840 1841 ### BUG FIXES: 1842 - [state] [\#3222](https://github.com/tendermint/tendermint/issues/3222) Fix validator set updates so they are applied as a set, rather 1843 than one at a time. This makes the proposer selection algorithm independent of 1844 the order of updates in `ResponseEndBlock.ValidatorUpdates`. 1845 - [evidence] [\#3286](https://github.com/tendermint/tendermint/issues/3286) Don't add committed evidence to evidence pool. 1846 1847 ## v0.29.2 1848 1849 *February 7th, 2019* 1850 1851 Special thanks to external contributors on this release: 1852 @ackratos, @rickyyangz 1853 1854 **Note**: This release contains security sensitive patches in the `p2p` and 1855 `crypto` packages: 1856 - p2p: 1857 - Partial fix for MITM attacks on the p2p connection. MITM conditions may 1858 still exist. See [\#3010](https://github.com/tendermint/tendermint/issues/3010). 1859 - crypto: 1860 - Eliminate our fork of `btcd` and use the `btcd/btcec` library directly for 1861 native secp256k1 signing. Note we still modify the signature encoding to 1862 prevent malleability. 1863 - Support the libsecp256k1 library via CGo through the `go-ethereum/crypto/secp256k1` package. 1864 - Eliminate MixEntropy functions 1865 1866 ### BREAKING CHANGES: 1867 1868 * Go API 1869 - [crypto] [\#3278](https://github.com/tendermint/tendermint/issues/3278) Remove 1870 MixEntropy functions 1871 - [types] [\#3245](https://github.com/tendermint/tendermint/issues/3245) Commit uses `type CommitSig Vote` instead of `Vote` directly. 1872 In preparation for removing redundant fields from the commit [\#1648](https://github.com/tendermint/tendermint/issues/1648) 1873 1874 ### IMPROVEMENTS: 1875 - [consensus] [\#3246](https://github.com/tendermint/tendermint/issues/3246) Better logging and notes on recovery for corrupted WAL file 1876 - [crypto] [\#3163](https://github.com/tendermint/tendermint/issues/3163) Use ethereum's libsecp256k1 go-wrapper for signatures when cgo is available 1877 - [crypto] [\#3162](https://github.com/tendermint/tendermint/issues/3162) Wrap btcd instead of forking it to keep up with fixes (used if cgo is not available) 1878 - [makefile] [\#3233](https://github.com/tendermint/tendermint/issues/3233) Use golangci-lint instead of go-metalinter 1879 - [tools] [\#3218](https://github.com/tendermint/tendermint/issues/3218) Add go-deadlock tool to help detect deadlocks 1880 - [tools] [\#3106](https://github.com/tendermint/tendermint/issues/3106) Add tm-signer-harness test harness for remote signers 1881 - [tests] [\#3258](https://github.com/tendermint/tendermint/issues/3258) Fixed a bunch of non-deterministic test failures 1882 1883 ### BUG FIXES: 1884 - [node] [\#3186](https://github.com/tendermint/tendermint/issues/3186) EventBus and indexerService should be started before first block (for replay last block on handshake) execution (@ackratos) 1885 - [p2p] [\#3232](https://github.com/tendermint/tendermint/issues/3232) Fix infinite loop leading to addrbook deadlock for seed nodes 1886 - [p2p] [\#3247](https://github.com/tendermint/tendermint/issues/3247) Fix panic in SeedMode when calling FlushStop and OnStop 1887 concurrently 1888 - [p2p] [\#3040](https://github.com/tendermint/tendermint/issues/3040) Fix MITM on secret connection by checking low-order points 1889 - [privval] [\#3258](https://github.com/tendermint/tendermint/issues/3258) Fix race between sign requests and ping requests in socket that was causing messages to be corrupted 1890 1891 ## v0.29.1 1892 1893 *January 24, 2019* 1894 1895 Special thanks to external contributors on this release: 1896 @infinytum, @gauthamzz 1897 1898 This release contains two important fixes: one for p2p layer where we sometimes 1899 were not closing connections and one for consensus layer where consensus with 1900 no empty blocks (`create_empty_blocks = false`) could halt. 1901 1902 ### IMPROVEMENTS: 1903 - [pex] [\#3037](https://github.com/tendermint/tendermint/issues/3037) Only log "Reached max attempts to dial" once 1904 - [rpc] [\#3159](https://github.com/tendermint/tendermint/issues/3159) Expose 1905 `triggered_timeout_commit` in the `/dump_consensus_state` 1906 1907 ### BUG FIXES: 1908 - [consensus] [\#3199](https://github.com/tendermint/tendermint/issues/3199) Fix consensus halt with no empty blocks from not resetting triggeredTimeoutCommit 1909 - [p2p] [\#2967](https://github.com/tendermint/tendermint/issues/2967) Fix file descriptor leak 1910 1911 ## v0.29.0 1912 1913 *January 21, 2019* 1914 1915 Special thanks to external contributors on this release: 1916 @bradyjoestar, @kunaldhariwal, @gauthamzz, @hrharder 1917 1918 This release is primarily about making some breaking changes to 1919 the Block protocol version before Cosmos launch, and to fixing more issues 1920 in the proposer selection algorithm discovered on Cosmos testnets. 1921 1922 The Block protocol changes include using a standard Merkle tree format (RFC 6962), 1923 fixing some inconsistencies between field orders in Vote and Proposal structs, 1924 and constraining the hash of the ConsensusParams to include only a few fields. 1925 1926 The proposer selection algorithm saw significant progress, 1927 including a [formal proof by @cwgoes for the base-case in Idris](https://github.com/cwgoes/tm-proposer-idris) 1928 and a [much more detailed specification (still in progress) by 1929 @ancazamfir](https://github.com/tendermint/tendermint/pull/3140). 1930 1931 Fixes to the proposer selection algorithm include normalizing the proposer 1932 priorities to mitigate the effects of large changes to the validator set. 1933 That said, we just discovered [another bug](https://github.com/tendermint/tendermint/issues/3181), 1934 which will be fixed in the next breaking release. 1935 1936 While we are trying to stabilize the Block protocol to preserve compatibility 1937 with old chains, there may be some final changes yet to come before Cosmos 1938 launch as we continue to audit and test the software. 1939 1940 ### BREAKING CHANGES: 1941 1942 * CLI/RPC/Config 1943 1944 * Apps 1945 - [state] [\#3049](https://github.com/tendermint/tendermint/issues/3049) Total voting power of the validator set is upper bounded by 1946 `MaxInt64 / 8`. Apps must ensure they do not return changes to the validator 1947 set that cause this maximum to be exceeded. 1948 1949 * Go API 1950 - [node] [\#3082](https://github.com/tendermint/tendermint/issues/3082) MetricsProvider now requires you to pass a chain ID 1951 - [types] [\#2713](https://github.com/tendermint/tendermint/issues/2713) Rename `TxProof.LeafHash` to `TxProof.Leaf` 1952 - [crypto/merkle] [\#2713](https://github.com/tendermint/tendermint/issues/2713) `SimpleProof.Verify` takes a `leaf` instead of a 1953 `leafHash` and performs the hashing itself 1954 1955 * Blockchain Protocol 1956 * [crypto/merkle] [\#2713](https://github.com/tendermint/tendermint/issues/2713) Merkle trees now match the RFC 6962 specification 1957 * [types] [\#3078](https://github.com/tendermint/tendermint/issues/3078) Re-order Timestamp and BlockID in CanonicalVote so it's 1958 consistent with CanonicalProposal (BlockID comes 1959 first) 1960 * [types] [\#3165](https://github.com/tendermint/tendermint/issues/3165) Hash of ConsensusParams only includes BlockSize.MaxBytes and 1961 BlockSize.MaxGas 1962 1963 * P2P Protocol 1964 - [consensus] [\#3049](https://github.com/tendermint/tendermint/issues/3049) Normalize priorities to not exceed `2*TotalVotingPower` to mitigate unfair proposer selection 1965 heavily preferring earlier joined validators in the case of an early bonded large validator unbonding 1966 1967 ### FEATURES: 1968 1969 ### IMPROVEMENTS: 1970 - [rpc] [\#3065](https://github.com/tendermint/tendermint/issues/3065) Return maxPerPage (100), not defaultPerPage (30) if `per_page` is greater than the max 100. 1971 - [instrumentation] [\#3082](https://github.com/tendermint/tendermint/issues/3082) Add `chain_id` label for all metrics 1972 1973 ### BUG FIXES: 1974 - [crypto] [\#3164](https://github.com/tendermint/tendermint/issues/3164) Update `btcd` fork for rare signRFC6979 bug 1975 - [lite] [\#3171](https://github.com/tendermint/tendermint/issues/3171) Fix verifying large validator set changes 1976 - [log] [\#3125](https://github.com/tendermint/tendermint/issues/3125) Fix year format 1977 - [mempool] [\#3168](https://github.com/tendermint/tendermint/issues/3168) Limit tx size to fit in the max reactor msg size 1978 - [scripts] [\#3147](https://github.com/tendermint/tendermint/issues/3147) Fix json2wal for large block parts (@bradyjoestar) 1979 1980 ## v0.28.1 1981 1982 *January 18th, 2019* 1983 1984 Special thanks to external contributors on this release: 1985 @HaoyangLiu 1986 1987 ### BUG FIXES: 1988 - [consensus] Fix consensus halt from proposing blocks with too much evidence 1989 1990 ## v0.28.0 1991 1992 *January 16th, 2019* 1993 1994 Special thanks to external contributors on this release: 1995 @fmauricios, @gianfelipe93, @husio, @needkane, @srmo, @yutianwu 1996 1997 This release is primarily about upgrades to the `privval` system - 1998 separating the `priv_validator.json` into distinct config and data files, and 1999 refactoring the socket validator to support reconnections. 2000 2001 **Note:** Please backup your existing `priv_validator.json` before using this 2002 version. 2003 2004 See [UPGRADING.md](UPGRADING.md) for more details. 2005 2006 ### BREAKING CHANGES: 2007 2008 * CLI/RPC/Config 2009 - [cli] Removed `--proxy_app=dummy` option. Use `kvstore` (`persistent_kvstore`) instead. 2010 - [cli] Renamed `--proxy_app=nilapp` to `--proxy_app=noop`. 2011 - [config] [\#2992](https://github.com/tendermint/tendermint/issues/2992) `allow_duplicate_ip` is now set to false 2012 - [privval] [\#1181](https://github.com/tendermint/tendermint/issues/1181) Split `priv_validator.json` into immutable (`config/priv_validator_key.json`) and mutable (`data/priv_validator_state.json`) parts (@yutianwu) 2013 - [privval] [\#2926](https://github.com/tendermint/tendermint/issues/2926) Split up `PubKeyMsg` into `PubKeyRequest` and `PubKeyResponse` to be consistent with other message types 2014 - [privval] [\#2923](https://github.com/tendermint/tendermint/issues/2923) Listen for unix socket connections instead of dialing them 2015 2016 * Apps 2017 2018 * Go API 2019 - [types] [\#2981](https://github.com/tendermint/tendermint/issues/2981) Remove `PrivValidator.GetAddress()` 2020 2021 * Blockchain Protocol 2022 2023 * P2P Protocol 2024 2025 ### FEATURES: 2026 - [rpc] [\#3052](https://github.com/tendermint/tendermint/issues/3052) Include peer's remote IP in `/net_info` 2027 2028 ### IMPROVEMENTS: 2029 - [consensus] [\#3086](https://github.com/tendermint/tendermint/issues/3086) Log peerID on ignored votes (@srmo) 2030 - [docs] [\#3061](https://github.com/tendermint/tendermint/issues/3061) Added specification for signing consensus msgs at 2031 ./docs/spec/consensus/signing.md 2032 - [privval] [\#2948](https://github.com/tendermint/tendermint/issues/2948) Memoize pubkey so it's only requested once on startup 2033 - [privval] [\#2923](https://github.com/tendermint/tendermint/issues/2923) Retry RemoteSigner connections on error 2034 2035 ### BUG FIXES: 2036 2037 - [build] [\#3085](https://github.com/tendermint/tendermint/issues/3085) Fix `Version` field in build scripts (@husio) 2038 - [crypto/multisig] [\#3102](https://github.com/tendermint/tendermint/issues/3102) Fix multisig keys address length 2039 - [crypto/encoding] [\#3101](https://github.com/tendermint/tendermint/issues/3101) Fix `PubKeyMultisigThreshold` unmarshalling into `crypto.PubKey` interface 2040 - [p2p/conn] [\#3111](https://github.com/tendermint/tendermint/issues/3111) Make SecretConnection thread safe 2041 - [rpc] [\#3053](https://github.com/tendermint/tendermint/issues/3053) Fix internal error in `/tx_search` when results are empty 2042 (@gianfelipe93) 2043 - [types] [\#2926](https://github.com/tendermint/tendermint/issues/2926) Do not panic if retrieving the privval's public key fails 2044 2045 ## v0.27.4 2046 2047 *December 21st, 2018* 2048 2049 ### BUG FIXES: 2050 2051 - [mempool] [\#3036](https://github.com/tendermint/tendermint/issues/3036) Fix 2052 LRU cache by popping the least recently used item when the cache is full, 2053 not the most recently used one! 2054 2055 ## v0.27.3 2056 2057 *December 16th, 2018* 2058 2059 ### BREAKING CHANGES: 2060 2061 * Go API 2062 - [dep] [\#3027](https://github.com/tendermint/tendermint/issues/3027) Revert to mainline Go crypto library, eliminating the modified 2063 `bcrypt.GenerateFromPassword` 2064 2065 ## v0.27.2 2066 2067 *December 16th, 2018* 2068 2069 ### IMPROVEMENTS: 2070 2071 - [node] [\#3025](https://github.com/tendermint/tendermint/issues/3025) Validate NodeInfo addresses on startup. 2072 2073 ### BUG FIXES: 2074 2075 - [p2p] [\#3025](https://github.com/tendermint/tendermint/pull/3025) Revert to using defers in addrbook. Fixes deadlocks in pex and consensus upon invalid ExternalAddr/ListenAddr configuration. 2076 2077 ## v0.27.1 2078 2079 *December 15th, 2018* 2080 2081 Special thanks to external contributors on this release: 2082 @danil-lashin, @hleb-albau, @james-ray, @leo-xinwang 2083 2084 ### FEATURES: 2085 - [rpc] [\#2964](https://github.com/tendermint/tendermint/issues/2964) Add `UnconfirmedTxs(limit)` and `NumUnconfirmedTxs()` methods to HTTP/Local clients (@danil-lashin) 2086 - [docs] [\#3004](https://github.com/tendermint/tendermint/issues/3004) Enable full-text search on docs pages 2087 2088 ### IMPROVEMENTS: 2089 - [consensus] [\#2971](https://github.com/tendermint/tendermint/issues/2971) Return error if ValidatorSet is empty after InitChain 2090 (@leo-xinwang) 2091 - [ci/cd] [\#3005](https://github.com/tendermint/tendermint/issues/3005) Updated CircleCI job to trigger website build when docs are updated 2092 - [docs] Various updates 2093 2094 ### BUG FIXES: 2095 - [cmd] [\#2983](https://github.com/tendermint/tendermint/issues/2983) `testnet` command always sets `addr_book_strict = false` 2096 - [config] [\#2980](https://github.com/tendermint/tendermint/issues/2980) Fix CORS options formatting 2097 - [kv indexer] [\#2912](https://github.com/tendermint/tendermint/issues/2912) Don't ignore key when executing CONTAINS 2098 - [mempool] [\#2961](https://github.com/tendermint/tendermint/issues/2961) Call `notifyTxsAvailable` if there're txs left after committing a block, but recheck=false 2099 - [mempool] [\#2994](https://github.com/tendermint/tendermint/issues/2994) Reject txs with negative GasWanted 2100 - [p2p] [\#2990](https://github.com/tendermint/tendermint/issues/2990) Fix a bug where seeds don't disconnect from a peer after 3h 2101 - [consensus] [\#3006](https://github.com/tendermint/tendermint/issues/3006) Save state after InitChain only when stateHeight is also 0 (@james-ray) 2102 2103 ## v0.27.0 2104 2105 *December 5th, 2018* 2106 2107 Special thanks to external contributors on this release: 2108 @danil-lashin, @srmo 2109 2110 Special thanks to @dlguddus for discovering a [major 2111 issue](https://github.com/tendermint/tendermint/issues/2718#issuecomment-440888677) 2112 in the proposer selection algorithm. 2113 2114 This release is primarily about fixes to the proposer selection algorithm 2115 in preparation for the [Cosmos Game of 2116 Stakes](https://blog.cosmos.network/the-game-of-stakes-is-open-for-registration-83a404746ee6). 2117 It also makes use of the `ConsensusParams.Validator.PubKeyTypes` to restrict the 2118 key types that can be used by validators, and removes the `Heartbeat` consensus 2119 message. 2120 2121 ### BREAKING CHANGES: 2122 2123 * CLI/RPC/Config 2124 - [rpc] [\#2932](https://github.com/tendermint/tendermint/issues/2932) Rename `accum` to `proposer_priority` 2125 2126 * Go API 2127 - [db] [\#2913](https://github.com/tendermint/tendermint/pull/2913) 2128 ReverseIterator API change: start < end, and end is exclusive. 2129 - [types] [\#2932](https://github.com/tendermint/tendermint/issues/2932) Rename `Validator.Accum` to `Validator.ProposerPriority` 2130 2131 * Blockchain Protocol 2132 - [state] [\#2714](https://github.com/tendermint/tendermint/issues/2714) Validators can now only use pubkeys allowed within 2133 ConsensusParams.Validator.PubKeyTypes 2134 2135 * P2P Protocol 2136 - [consensus] [\#2871](https://github.com/tendermint/tendermint/issues/2871) 2137 Remove *ProposalHeartbeat* message as it serves no real purpose (@srmo) 2138 - [state] Fixes for proposer selection: 2139 - [\#2785](https://github.com/tendermint/tendermint/issues/2785) Accum for new validators is `-1.125*totalVotingPower` instead of 0 2140 - [\#2941](https://github.com/tendermint/tendermint/issues/2941) val.Accum is preserved during ValidatorSet.Update to avoid being 2141 reset to 0 2142 2143 ### IMPROVEMENTS: 2144 2145 - [state] [\#2929](https://github.com/tendermint/tendermint/issues/2929) Minor refactor of updateState logic (@danil-lashin) 2146 - [node] [\#2959](https://github.com/tendermint/tendermint/issues/2959) Allow node to start even if software's BlockProtocol is 2147 different from state's BlockProtocol 2148 - [pex] [\#2959](https://github.com/tendermint/tendermint/issues/2959) Pex reactor logger uses `module=pex` 2149 2150 ### BUG FIXES: 2151 2152 - [p2p] [\#2968](https://github.com/tendermint/tendermint/issues/2968) Panic on transport error rather than continuing to run but not 2153 accept new connections 2154 - [p2p] [\#2969](https://github.com/tendermint/tendermint/issues/2969) Fix mismatch in peer count between `/net_info` and the prometheus 2155 metrics 2156 - [rpc] [\#2408](https://github.com/tendermint/tendermint/issues/2408) `/broadcast_tx_commit`: Fix "interface conversion: interface {} in nil, not EventDataTx" panic (could happen if somebody sent a tx using `/broadcast_tx_commit` while Tendermint was being stopped) 2157 - [state] [\#2785](https://github.com/tendermint/tendermint/issues/2785) Fix accum for new validators to be `-1.125*totalVotingPower` 2158 instead of 0, forcing them to wait before becoming the proposer. Also: 2159 - do not batch clip 2160 - keep accums averaged near 0 2161 - [txindex/kv] [\#2925](https://github.com/tendermint/tendermint/issues/2925) Don't return false positives when range searching for a prefix of a tag value 2162 - [types] [\#2938](https://github.com/tendermint/tendermint/issues/2938) Fix regression in v0.26.4 where we panic on empty 2163 genDoc.Validators 2164 - [types] [\#2941](https://github.com/tendermint/tendermint/issues/2941) Preserve val.Accum during ValidatorSet.Update to avoid it being 2165 reset to 0 every time a validator is updated 2166 2167 ## v0.26.4 2168 2169 *November 27th, 2018* 2170 2171 Special thanks to external contributors on this release: 2172 @ackratos, @goolAdapter, @james-ray, @joe-bowman, @kostko, 2173 @nagarajmanjunath, @tomtau 2174 2175 ### FEATURES: 2176 2177 - [rpc] [\#2747](https://github.com/tendermint/tendermint/issues/2747) Enable subscription to tags emitted from `BeginBlock`/`EndBlock` (@kostko) 2178 - [types] [\#2747](https://github.com/tendermint/tendermint/issues/2747) Add `ResultBeginBlock` and `ResultEndBlock` fields to `EventDataNewBlock` 2179 and `EventDataNewBlockHeader` to support subscriptions (@kostko) 2180 - [types] [\#2918](https://github.com/tendermint/tendermint/issues/2918) Add Marshal, MarshalTo, Unmarshal methods to various structs 2181 to support Protobuf compatibility (@nagarajmanjunath) 2182 2183 ### IMPROVEMENTS: 2184 2185 - [config] [\#2877](https://github.com/tendermint/tendermint/issues/2877) Add `blocktime_iota` to the config.toml (@ackratos) 2186 - NOTE: this should be a ConsensusParam, not part of the config, and will be 2187 removed from the config at a later date 2188 ([\#2920](https://github.com/tendermint/tendermint/issues/2920). 2189 - [mempool] [\#2882](https://github.com/tendermint/tendermint/issues/2882) Add txs from Update to cache 2190 - [mempool] [\#2891](https://github.com/tendermint/tendermint/issues/2891) Remove local int64 counter from being stored in every tx 2191 - [node] [\#2866](https://github.com/tendermint/tendermint/issues/2866) Add ability to instantiate IPCVal (@joe-bowman) 2192 2193 ### BUG FIXES: 2194 2195 - [blockchain] [\#2731](https://github.com/tendermint/tendermint/issues/2731) Retry both blocks if either is bad to avoid getting stuck during fast sync (@goolAdapter) 2196 - [consensus] [\#2893](https://github.com/tendermint/tendermint/issues/2893) Use genDoc.Validators instead of state.NextValidators on replay when appHeight==0 (@james-ray) 2197 - [log] [\#2868](https://github.com/tendermint/tendermint/issues/2868) Fix `module=main` setting overriding all others 2198 - NOTE: this changes the default logging behaviour to be much less verbose. 2199 Set `log_level="info"` to restore the previous behaviour. 2200 - [rpc] [\#2808](https://github.com/tendermint/tendermint/issues/2808) Fix `accum` field in `/validators` by calling `IncrementAccum` if necessary 2201 - [rpc] [\#2811](https://github.com/tendermint/tendermint/issues/2811) Allow integer IDs in JSON-RPC requests (@tomtau) 2202 - [txindex/kv] [\#2759](https://github.com/tendermint/tendermint/issues/2759) Fix tx.height range queries 2203 - [txindex/kv] [\#2775](https://github.com/tendermint/tendermint/issues/2775) Order tx results by index if height is the same 2204 - [txindex/kv] [\#2908](https://github.com/tendermint/tendermint/issues/2908) Don't return false positives when searching for a prefix of a tag value 2205 2206 ## v0.26.3 2207 2208 *November 17th, 2018* 2209 2210 Special thanks to external contributors on this release: 2211 @danil-lashin, @kevlubkcm, @krhubert, @srmo 2212 2213 ### BREAKING CHANGES: 2214 2215 * Go API 2216 - [rpc] [\#2791](https://github.com/tendermint/tendermint/issues/2791) Functions that start HTTP servers are now blocking: 2217 - Impacts `StartHTTPServer`, `StartHTTPAndTLSServer`, and `StartGRPCServer` 2218 - These functions now take a `net.Listener` instead of an address 2219 - [rpc] [\#2767](https://github.com/tendermint/tendermint/issues/2767) Subscribing to events 2220 `NewRound` and `CompleteProposal` return new types `EventDataNewRound` and 2221 `EventDataCompleteProposal`, respectively, instead of the generic `EventDataRoundState`. (@kevlubkcm) 2222 2223 ### FEATURES: 2224 2225 - [log] [\#2843](https://github.com/tendermint/tendermint/issues/2843) New `log_format` config option, which can be set to 'plain' for colored 2226 text or 'json' for JSON output 2227 - [types] [\#2767](https://github.com/tendermint/tendermint/issues/2767) New event types EventDataNewRound (with ProposerInfo) and EventDataCompleteProposal (with BlockID). (@kevlubkcm) 2228 2229 ### IMPROVEMENTS: 2230 2231 - [dep] [\#2844](https://github.com/tendermint/tendermint/issues/2844) Dependencies are no longer pinned to an exact version in the 2232 Gopkg.toml: 2233 - Serialization libs are allowed to vary by patch release 2234 - Other libs are allowed to vary by minor release 2235 - [p2p] [\#2857](https://github.com/tendermint/tendermint/issues/2857) "Send failed" is logged at debug level instead of error. 2236 - [rpc] [\#2780](https://github.com/tendermint/tendermint/issues/2780) Add read and write timeouts to HTTP servers 2237 - [state] [\#2848](https://github.com/tendermint/tendermint/issues/2848) Make "Update to validators" msg value pretty (@danil-lashin) 2238 2239 ### BUG FIXES: 2240 - [consensus] [\#2819](https://github.com/tendermint/tendermint/issues/2819) Don't send proposalHearbeat if not a validator 2241 - [docs] [\#2859](https://github.com/tendermint/tendermint/issues/2859) Fix ConsensusParams details in spec 2242 - [libs/autofile] [\#2760](https://github.com/tendermint/tendermint/issues/2760) Comment out autofile permissions check - should fix 2243 running Tendermint on Windows 2244 - [p2p] [\#2869](https://github.com/tendermint/tendermint/issues/2869) Set connection config properly instead of always using default 2245 - [p2p/pex] [\#2802](https://github.com/tendermint/tendermint/issues/2802) Seed mode fixes: 2246 - Only disconnect from inbound peers 2247 - Use FlushStop instead of Sleep to ensure all messages are sent before 2248 disconnecting 2249 2250 ## v0.26.2 2251 2252 *November 15th, 2018* 2253 2254 Special thanks to external contributors on this release: @hleb-albau, @zhuzeyu 2255 2256 ### FEATURES: 2257 2258 - [rpc] [\#2582](https://github.com/tendermint/tendermint/issues/2582) Enable CORS on RPC API (@hleb-albau) 2259 2260 ### BUG FIXES: 2261 2262 - [abci] [\#2748](https://github.com/tendermint/tendermint/issues/2748) Unlock mutex in localClient so even when app panics (e.g. during CheckTx), consensus continue working 2263 - [abci] [\#2748](https://github.com/tendermint/tendermint/issues/2748) Fix DATA RACE in localClient 2264 - [amino] [\#2822](https://github.com/tendermint/tendermint/issues/2822) Update to v0.14.1 to support compiling on 32-bit platforms 2265 - [rpc] [\#2748](https://github.com/tendermint/tendermint/issues/2748) Drain channel before calling Unsubscribe(All) in `/broadcast_tx_commit` 2266 2267 ## v0.26.1 2268 2269 *November 11, 2018* 2270 2271 Special thanks to external contributors on this release: @katakonst 2272 2273 ### IMPROVEMENTS: 2274 2275 - [consensus] [\#2704](https://github.com/tendermint/tendermint/issues/2704) Simplify valid POL round logic 2276 - [docs] [\#2749](https://github.com/tendermint/tendermint/issues/2749) Deduplicate some ABCI docs 2277 - [mempool] More detailed log messages 2278 - [\#2724](https://github.com/tendermint/tendermint/issues/2724) 2279 - [\#2762](https://github.com/tendermint/tendermint/issues/2762) 2280 2281 ### BUG FIXES: 2282 2283 - [autofile] [\#2703](https://github.com/tendermint/tendermint/issues/2703) Do not panic when checking Head size 2284 - [crypto/merkle] [\#2756](https://github.com/tendermint/tendermint/issues/2756) Fix crypto/merkle ProofOperators.Verify to check bounds on keypath parts. 2285 - [mempool] fix a bug where we create a WAL despite `wal_dir` being empty 2286 - [p2p] [\#2771](https://github.com/tendermint/tendermint/issues/2771) Fix `peer-id` label name to `peer_id` in prometheus metrics 2287 - [p2p] [\#2797](https://github.com/tendermint/tendermint/pull/2797) Fix IDs in peer NodeInfo and require them for addresses 2288 in AddressBook 2289 - [p2p] [\#2797](https://github.com/tendermint/tendermint/pull/2797) Do not close conn immediately after sending pex addrs in seed mode. Partial fix for [\#2092](https://github.com/tendermint/tendermint/issues/2092). 2290 2291 ## v0.26.0 2292 2293 *November 2, 2018* 2294 2295 Special thanks to external contributors on this release: 2296 @bradyjoestar, @connorwstein, @goolAdapter, @HaoyangLiu, 2297 @james-ray, @overbool, @phymbert, @Slamper, @Uzair1995, @yutianwu. 2298 2299 Special thanks to @Slamper for a series of bug reports in our [bug bounty 2300 program](https://hackerone.com/cosmos) which are fixed in this release. 2301 2302 This release is primarily about adding Version fields to various data structures, 2303 optimizing consensus messages for signing and verification in 2304 restricted environments (like HSMs and the Ethereum Virtual Machine), and 2305 aligning the consensus code with the [specification](https://arxiv.org/abs/1807.04938). 2306 It also includes our first take at a generalized merkle proof system, and 2307 changes the length of hashes used for hashing data structures from 20 to 32 2308 bytes. 2309 2310 See the [UPGRADING.md](UPGRADING.md#v0.26.0) for details on upgrading to the new 2311 version. 2312 2313 Please note that we are still making breaking changes to the protocols. 2314 While the new Version fields should help us to keep the software backwards compatible 2315 even while upgrading the protocols, we cannot guarantee that new releases will 2316 be compatible with old chains just yet. We expect there will be another breaking 2317 release or two before the Cosmos Hub launch, but we will otherwise be paying 2318 increasing attention to backwards compatibility. Thanks for bearing with us! 2319 2320 ### BREAKING CHANGES: 2321 2322 * CLI/RPC/Config 2323 * [config] [\#2232](https://github.com/tendermint/tendermint/issues/2232) Timeouts are now strings like "3s" and "100ms", not ints 2324 * [config] [\#2505](https://github.com/tendermint/tendermint/issues/2505) Remove Mempool.RecheckEmpty (it was effectively useless anyways) 2325 * [config] [\#2490](https://github.com/tendermint/tendermint/issues/2490) `mempool.wal` is disabled by default 2326 * [privval] [\#2459](https://github.com/tendermint/tendermint/issues/2459) Split `SocketPVMsg`s implementations into Request and Response, where the Response may contain a error message (returned by the remote signer) 2327 * [state] [\#2644](https://github.com/tendermint/tendermint/issues/2644) Add Version field to State, breaking the format of State as 2328 encoded on disk. 2329 * [rpc] [\#2298](https://github.com/tendermint/tendermint/issues/2298) `/abci_query` takes `prove` argument instead of `trusted` and switches the default 2330 behaviour to `prove=false` 2331 * [rpc] [\#2654](https://github.com/tendermint/tendermint/issues/2654) Remove all `node_info.other.*_version` fields in `/status` and 2332 `/net_info` 2333 * [rpc] [\#2636](https://github.com/tendermint/tendermint/issues/2636) Remove 2334 `_params` suffix from fields in `consensus_params`. 2335 2336 * Apps 2337 * [abci] [\#2298](https://github.com/tendermint/tendermint/issues/2298) ResponseQuery.Proof is now a structured merkle.Proof, not just 2338 arbitrary bytes 2339 * [abci] [\#2644](https://github.com/tendermint/tendermint/issues/2644) Add Version to Header and shift all fields by one 2340 * [abci] [\#2662](https://github.com/tendermint/tendermint/issues/2662) Bump the field numbers for some `ResponseInfo` fields to make room for 2341 `AppVersion` 2342 * [abci] [\#2636](https://github.com/tendermint/tendermint/issues/2636) Updates to ConsensusParams 2343 * Remove `Params` suffix from field names 2344 * Add `Params` suffix to message types 2345 * Add new field and type, `Validator ValidatorParams`, to control what types of validator keys are allowed. 2346 2347 * Go API 2348 * [config] [\#2232](https://github.com/tendermint/tendermint/issues/2232) Timeouts are time.Duration, not ints 2349 * [crypto/merkle & lite] [\#2298](https://github.com/tendermint/tendermint/issues/2298) Various changes to accomodate General Merkle trees 2350 * [crypto/merkle] [\#2595](https://github.com/tendermint/tendermint/issues/2595) Remove all Hasher objects in favor of byte slices 2351 * [crypto/merkle] [\#2635](https://github.com/tendermint/tendermint/issues/2635) merkle.SimpleHashFromTwoHashes is no longer exported 2352 * [node] [\#2479](https://github.com/tendermint/tendermint/issues/2479) Remove node.RunForever 2353 * [rpc/client] [\#2298](https://github.com/tendermint/tendermint/issues/2298) `ABCIQueryOptions.Trusted` -> `ABCIQueryOptions.Prove` 2354 * [types] [\#2298](https://github.com/tendermint/tendermint/issues/2298) Remove `Index` and `Total` fields from `TxProof`. 2355 * [types] [\#2598](https://github.com/tendermint/tendermint/issues/2598) 2356 `VoteTypeXxx` are now of type `SignedMsgType byte` and named `XxxType`, eg. 2357 `PrevoteType`, `PrecommitType`. 2358 * [types] [\#2636](https://github.com/tendermint/tendermint/issues/2636) Rename fields in ConsensusParams to remove `Params` suffixes 2359 * [types] [\#2735](https://github.com/tendermint/tendermint/issues/2735) Simplify Proposal message to align with spec 2360 2361 * Blockchain Protocol 2362 * [crypto/tmhash] [\#2732](https://github.com/tendermint/tendermint/issues/2732) TMHASH is now full 32-byte SHA256 2363 * All hashes in the block header and Merkle trees are now 32-bytes 2364 * PubKey Addresses are still only 20-bytes 2365 * [state] [\#2587](https://github.com/tendermint/tendermint/issues/2587) Require block.Time of the fist block to be genesis time 2366 * [state] [\#2644](https://github.com/tendermint/tendermint/issues/2644) Require block.Version to match state.Version 2367 * [types] Update SignBytes for `Vote`/`Proposal`/`Heartbeat`: 2368 * [\#2459](https://github.com/tendermint/tendermint/issues/2459) Use amino encoding instead of JSON in `SignBytes`. 2369 * [\#2598](https://github.com/tendermint/tendermint/issues/2598) Reorder fields and use fixed sized encoding. 2370 * [\#2598](https://github.com/tendermint/tendermint/issues/2598) Change `Type` field from `string` to `byte` and use new 2371 `SignedMsgType` to enumerate. 2372 * [types] [\#2730](https://github.com/tendermint/tendermint/issues/2730) Use 2373 same order for fields in `Vote` as in the SignBytes 2374 * [types] [\#2732](https://github.com/tendermint/tendermint/issues/2732) Remove the address field from the validator hash 2375 * [types] [\#2644](https://github.com/tendermint/tendermint/issues/2644) Add Version struct to Header 2376 * [types] [\#2609](https://github.com/tendermint/tendermint/issues/2609) ConsensusParams.Hash() is the hash of the amino encoded 2377 struct instead of the Merkle tree of the fields 2378 * [types] [\#2670](https://github.com/tendermint/tendermint/issues/2670) Header.Hash() builds Merkle tree out of fields in the same 2379 order they appear in the header, instead of sorting by field name 2380 * [types] [\#2682](https://github.com/tendermint/tendermint/issues/2682) Use proto3 `varint` encoding for ints that are usually unsigned (instead of zigzag encoding). 2381 * [types] [\#2636](https://github.com/tendermint/tendermint/issues/2636) Add Validator field to ConsensusParams 2382 (Used to control which pubkey types validators can use, by abci type). 2383 2384 * P2P Protocol 2385 * [consensus] [\#2652](https://github.com/tendermint/tendermint/issues/2652) 2386 Replace `CommitStepMessage` with `NewValidBlockMessage` 2387 * [consensus] [\#2735](https://github.com/tendermint/tendermint/issues/2735) Simplify `Proposal` message to align with spec 2388 * [consensus] [\#2730](https://github.com/tendermint/tendermint/issues/2730) 2389 Add `Type` field to `Proposal` and use same order of fields as in the 2390 SignBytes for both `Proposal` and `Vote` 2391 * [p2p] [\#2654](https://github.com/tendermint/tendermint/issues/2654) Add `ProtocolVersion` struct with protocol versions to top of 2392 DefaultNodeInfo and require `ProtocolVersion.Block` to match during peer handshake 2393 2394 2395 ### FEATURES: 2396 - [abci] [\#2557](https://github.com/tendermint/tendermint/issues/2557) Add `Codespace` field to `Response{CheckTx, DeliverTx, Query}` 2397 - [abci] [\#2662](https://github.com/tendermint/tendermint/issues/2662) Add `BlockVersion` and `P2PVersion` to `RequestInfo` 2398 - [crypto/merkle] [\#2298](https://github.com/tendermint/tendermint/issues/2298) General Merkle Proof scheme for chaining various types of Merkle trees together 2399 - [docs/architecture] [\#1181](https://github.com/tendermint/tendermint/issues/1181) S 2400 plit immutable and mutable parts of priv_validator.json 2401 2402 ### IMPROVEMENTS: 2403 - Additional Metrics 2404 - [consensus] [\#2169](https://github.com/cosmos/cosmos-sdk/issues/2169) 2405 - [p2p] [\#2169](https://github.com/cosmos/cosmos-sdk/issues/2169) 2406 - [config] [\#2232](https://github.com/tendermint/tendermint/issues/2232) Added ValidateBasic method, which performs basic checks 2407 - [crypto/ed25519] [\#2558](https://github.com/tendermint/tendermint/issues/2558) Switch to use latest `golang.org/x/crypto` through our fork at 2408 github.com/tendermint/crypto 2409 - [libs/log] [\#2707](https://github.com/tendermint/tendermint/issues/2707) Add year to log format (@yutianwu) 2410 - [tools] [\#2238](https://github.com/tendermint/tendermint/issues/2238) Binary dependencies are now locked to a specific git commit 2411 2412 ### BUG FIXES: 2413 - [\#2711](https://github.com/tendermint/tendermint/issues/2711) Validate all incoming reactor messages. Fixes various bugs due to negative ints. 2414 - [autofile] [\#2428](https://github.com/tendermint/tendermint/issues/2428) Group.RotateFile need call Flush() before rename (@goolAdapter) 2415 - [common] [\#2533](https://github.com/tendermint/tendermint/issues/2533) Fixed a bug in the `BitArray.Or` method 2416 - [common] [\#2506](https://github.com/tendermint/tendermint/issues/2506) Fixed a bug in the `BitArray.Sub` method (@james-ray) 2417 - [common] [\#2534](https://github.com/tendermint/tendermint/issues/2534) Fix `BitArray.PickRandom` to choose uniformly from true bits 2418 - [consensus] [\#1690](https://github.com/tendermint/tendermint/issues/1690) Wait for 2419 timeoutPrecommit before starting next round 2420 - [consensus] [\#1745](https://github.com/tendermint/tendermint/issues/1745) Wait for 2421 Proposal or timeoutProposal before entering prevote 2422 - [consensus] [\#2642](https://github.com/tendermint/tendermint/issues/2642) Only propose ValidBlock, not LockedBlock 2423 - [consensus] [\#2642](https://github.com/tendermint/tendermint/issues/2642) Initialized ValidRound and LockedRound to -1 2424 - [consensus] [\#1637](https://github.com/tendermint/tendermint/issues/1637) Limit the amount of evidence that can be included in a 2425 block 2426 - [consensus] [\#2652](https://github.com/tendermint/tendermint/issues/2652) Ensure valid block property with faulty proposer 2427 - [evidence] [\#2515](https://github.com/tendermint/tendermint/issues/2515) Fix db iter leak (@goolAdapter) 2428 - [libs/event] [\#2518](https://github.com/tendermint/tendermint/issues/2518) Fix event concurrency flaw (@goolAdapter) 2429 - [node] [\#2434](https://github.com/tendermint/tendermint/issues/2434) Make node respond to signal interrupts while sleeping for genesis time 2430 - [state] [\#2616](https://github.com/tendermint/tendermint/issues/2616) Pass nil to NewValidatorSet() when genesis file's Validators field is nil 2431 - [p2p] [\#2555](https://github.com/tendermint/tendermint/issues/2555) Fix p2p switch FlushThrottle value (@goolAdapter) 2432 - [p2p] [\#2668](https://github.com/tendermint/tendermint/issues/2668) Reconnect to originally dialed address (not self-reported address) for persistent peers 2433 2434 ## v0.25.0 2435 2436 *September 22, 2018* 2437 2438 Special thanks to external contributors on this release: 2439 @scriptionist, @bradyjoestar, @WALL-E 2440 2441 This release is mostly about the ConsensusParams - removing fields and enforcing MaxGas. 2442 It also addresses some issues found via security audit, removes various unused 2443 functions from `libs/common`, and implements 2444 [ADR-012](https://github.com/tendermint/tendermint/blob/develop/docs/architecture/adr-012-peer-transport.md). 2445 2446 BREAKING CHANGES: 2447 2448 * CLI/RPC/Config 2449 * [rpc] [\#2391](https://github.com/tendermint/tendermint/issues/2391) /status `result.node_info.other` became a map 2450 * [types] [\#2364](https://github.com/tendermint/tendermint/issues/2364) Remove `TxSize` and `BlockGossip` from `ConsensusParams` 2451 * Maximum tx size is now set implicitly via the `BlockSize.MaxBytes` 2452 * The size of block parts in the consensus is now fixed to 64kB 2453 2454 * Apps 2455 * [mempool] [\#2360](https://github.com/tendermint/tendermint/issues/2360) Mempool tracks the `ResponseCheckTx.GasWanted` and 2456 `ConsensusParams.BlockSize.MaxGas` and enforces: 2457 - `GasWanted <= MaxGas` for every tx 2458 - `(sum of GasWanted in block) <= MaxGas` for block proposal 2459 2460 * Go API 2461 * [libs/common] [\#2431](https://github.com/tendermint/tendermint/issues/2431) Remove Word256 due to lack of use 2462 * [libs/common] [\#2452](https://github.com/tendermint/tendermint/issues/2452) Remove the following functions due to lack of use: 2463 * byteslice.go: cmn.IsZeros, cmn.RightPadBytes, cmn.LeftPadBytes, cmn.PrefixEndBytes 2464 * strings.go: cmn.IsHex, cmn.StripHex 2465 * int.go: Uint64Slice, all put/get int64 methods 2466 2467 FEATURES: 2468 - [rpc] [\#2415](https://github.com/tendermint/tendermint/issues/2415) New `/consensus_params?height=X` endpoint to query the consensus 2469 params at any height (@scriptonist) 2470 - [types] [\#1714](https://github.com/tendermint/tendermint/issues/1714) Add Address to GenesisValidator 2471 - [metrics] [\#2337](https://github.com/tendermint/tendermint/issues/2337) `consensus.block_interval_metrics` is now gauge, not histogram (you will be able to see spikes, if any) 2472 - [libs] [\#2286](https://github.com/tendermint/tendermint/issues/2286) Panic if `autofile` or `db/fsdb` permissions change from 0600. 2473 2474 IMPROVEMENTS: 2475 - [libs/db] [\#2371](https://github.com/tendermint/tendermint/issues/2371) Output error instead of panic when the given `db_backend` is not initialised (@bradyjoestar) 2476 - [mempool] [\#2399](https://github.com/tendermint/tendermint/issues/2399) Make mempool cache a proper LRU (@bradyjoestar) 2477 - [p2p] [\#2126](https://github.com/tendermint/tendermint/issues/2126) Introduce PeerTransport interface to improve isolation of concerns 2478 - [libs/common] [\#2326](https://github.com/tendermint/tendermint/issues/2326) Service returns ErrNotStarted 2479 2480 BUG FIXES: 2481 - [node] [\#2294](https://github.com/tendermint/tendermint/issues/2294) Delay starting node until Genesis time 2482 - [consensus] [\#2048](https://github.com/tendermint/tendermint/issues/2048) Correct peer statistics for marking peer as good 2483 - [rpc] [\#2460](https://github.com/tendermint/tendermint/issues/2460) StartHTTPAndTLSServer() now passes StartTLS() errors back to the caller rather than hanging forever. 2484 - [p2p] [\#2047](https://github.com/tendermint/tendermint/issues/2047) Accept new connections asynchronously 2485 - [tm-bench] [\#2410](https://github.com/tendermint/tendermint/issues/2410) Enforce minimum transaction size (@WALL-E) 2486 2487 ## 0.24.0 2488 2489 *September 6th, 2018* 2490 2491 Special thanks to external contributors with PRs included in this release: ackratos, james-ray, bradyjoestar, 2492 peerlink, Ahmah2009, bluele, b00f. 2493 2494 This release includes breaking upgrades in the block header, 2495 including the long awaited changes for delaying validator set updates by one 2496 block to better support light clients. 2497 It also fixes enforcement on the maximum size of blocks, and includes a BFT 2498 timestamp in each block that can be safely used by applications. 2499 There are also some minor breaking changes to the rpc, config, and ABCI. 2500 2501 See the [UPGRADING.md](UPGRADING.md#v0.24.0) for details on upgrading to the new 2502 version. 2503 2504 From here on, breaking changes will be broken down to better reflect how users 2505 are affected by a change. 2506 2507 A few more breaking changes are in the works - each will come with a clear 2508 Architecture Decision Record (ADR) explaining the change. You can review ADRs 2509 [here](https://github.com/tendermint/tendermint/tree/develop/docs/architecture) 2510 or in the [open Pull Requests](https://github.com/tendermint/tendermint/pulls). 2511 You can also check in on the [issues marked as 2512 breaking](https://github.com/tendermint/tendermint/issues?q=is%3Aopen+is%3Aissue+label%3Abreaking). 2513 2514 BREAKING CHANGES: 2515 2516 * CLI/RPC/Config 2517 - [config] [\#2169](https://github.com/tendermint/tendermint/issues/2169) Replace MaxNumPeers with MaxNumInboundPeers and MaxNumOutboundPeers 2518 - [config] [\#2300](https://github.com/tendermint/tendermint/issues/2300) Reduce default mempool size from 100k to 5k, until ABCI rechecking is implemented. 2519 - [rpc] [\#1815](https://github.com/tendermint/tendermint/issues/1815) `/commit` returns a `signed_header` field instead of everything being top-level 2520 2521 * Apps 2522 - [abci] Added address of the original proposer of the block to Header 2523 - [abci] Change ABCI Header to match Tendermint exactly 2524 - [abci] [\#2159](https://github.com/tendermint/tendermint/issues/2159) Update use of `Validator` (see 2525 [ADR-018](https://github.com/tendermint/tendermint/blob/develop/docs/architecture/adr-018-ABCI-Validators.md)): 2526 - Remove PubKey from `Validator` (so it's just Address and Power) 2527 - Introduce `ValidatorUpdate` (with just PubKey and Power) 2528 - InitChain and EndBlock use ValidatorUpdate 2529 - Update field names and types in BeginBlock 2530 - [state] [\#1815](https://github.com/tendermint/tendermint/issues/1815) Validator set changes are now delayed by one block 2531 - updates returned in ResponseEndBlock for block H will be included in RequestBeginBlock for block H+2 2532 2533 * Go API 2534 - [lite] [\#1815](https://github.com/tendermint/tendermint/issues/1815) Complete refactor of the package 2535 - [node] [\#2212](https://github.com/tendermint/tendermint/issues/2212) NewNode now accepts a `*p2p.NodeKey` (@bradyjoestar) 2536 - [libs/common] [\#2199](https://github.com/tendermint/tendermint/issues/2199) Remove Fmt, in favor of fmt.Sprintf 2537 - [libs/common] SplitAndTrim was deleted 2538 - [libs/common] [\#2274](https://github.com/tendermint/tendermint/issues/2274) Remove unused Math functions like MaxInt, MaxInt64, 2539 MinInt, MinInt64 (@Ahmah2009) 2540 - [libs/clist] Panics if list extends beyond MaxLength 2541 - [crypto] [\#2205](https://github.com/tendermint/tendermint/issues/2205) Rename AminoRoute variables to no longer be prefixed by signature type. 2542 2543 * Blockchain Protocol 2544 - [state] [\#1815](https://github.com/tendermint/tendermint/issues/1815) Validator set changes are now delayed by one block (!) 2545 - Add NextValidatorSet to State, changes on-disk representation of state 2546 - [state] [\#2184](https://github.com/tendermint/tendermint/issues/2184) Enforce ConsensusParams.BlockSize.MaxBytes (See 2547 [ADR-020](https://github.com/tendermint/tendermint/blob/develop/docs/architecture/adr-020-block-size.md)). 2548 - Remove ConsensusParams.BlockSize.MaxTxs 2549 - Introduce maximum sizes for all components of a block, including ChainID 2550 - [types] Updates to the block Header: 2551 - [\#1815](https://github.com/tendermint/tendermint/issues/1815) NextValidatorsHash - hash of the validator set for the next block, 2552 so the current validators actually sign over the hash for the new 2553 validators 2554 - [\#2106](https://github.com/tendermint/tendermint/issues/2106) ProposerAddress - address of the block's original proposer 2555 - [consensus] [\#2203](https://github.com/tendermint/tendermint/issues/2203) Implement BFT time 2556 - Timestamp in block must be monotonic and equal the median of timestamps in block's LastCommit 2557 - [crypto] [\#2239](https://github.com/tendermint/tendermint/issues/2239) Secp256k1 signature changes (See 2558 [ADR-014](https://github.com/tendermint/tendermint/blob/develop/docs/architecture/adr-014-secp-malleability.md)): 2559 - format changed from DER to `r || s`, both little endian encoded as 32 bytes. 2560 - malleability removed by requiring `s` to be in canonical form. 2561 2562 * P2P Protocol 2563 - [p2p] [\#2263](https://github.com/tendermint/tendermint/issues/2263) Update secret connection to use a little endian encoded nonce 2564 - [blockchain] [\#2213](https://github.com/tendermint/tendermint/issues/2213) Fix Amino routes for blockchain reactor messages 2565 (@peerlink) 2566 2567 2568 FEATURES: 2569 - [types] [\#2015](https://github.com/tendermint/tendermint/issues/2015) Allow genesis file to have 0 validators (@b00f) 2570 - Initial validator set can be determined by the app in ResponseInitChain 2571 - [rpc] [\#2161](https://github.com/tendermint/tendermint/issues/2161) New event `ValidatorSetUpdates` for when the validator set changes 2572 - [crypto/multisig] [\#2164](https://github.com/tendermint/tendermint/issues/2164) Introduce multisig pubkey and signature format 2573 - [libs/db] [\#2293](https://github.com/tendermint/tendermint/issues/2293) Allow passing options through when creating instances of leveldb dbs 2574 2575 IMPROVEMENTS: 2576 - [docs] Lint documentation with `write-good` and `stop-words`. 2577 - [docs] [\#2249](https://github.com/tendermint/tendermint/issues/2249) Refactor, deduplicate, and improve the ABCI docs and spec (with thanks to @ttmc). 2578 - [scripts] [\#2196](https://github.com/tendermint/tendermint/issues/2196) Added json2wal tool, which is supposed to help our users restore (@bradyjoestar) 2579 corrupted WAL files and compose test WAL files (@bradyjoestar) 2580 - [mempool] [\#2234](https://github.com/tendermint/tendermint/issues/2234) Now stores txs by hash inside of the cache, to mitigate memory leakage 2581 - [mempool] [\#2166](https://github.com/tendermint/tendermint/issues/2166) Set explicit capacity for map when updating txs (@bluele) 2582 2583 BUG FIXES: 2584 - [config] [\#2284](https://github.com/tendermint/tendermint/issues/2284) Replace `db_path` with `db_dir` from automatically generated configuration files. 2585 - [mempool] [\#2188](https://github.com/tendermint/tendermint/issues/2188) Fix OOM issue from cache map and list getting out of sync 2586 - [state] [\#2051](https://github.com/tendermint/tendermint/issues/2051) KV store index supports searching by `tx.height` (@ackratos) 2587 - [rpc] [\#2327](https://github.com/tendermint/tendermint/issues/2327) `/dial_peers` does not try to dial existing peers 2588 - [node] [\#2323](https://github.com/tendermint/tendermint/issues/2323) Filter empty strings from config lists (@james-ray) 2589 - [abci/client] [\#2236](https://github.com/tendermint/tendermint/issues/2236) Fix closing GRPC connection (@bradyjoestar) 2590 2591 ## 0.23.1 2592 2593 *August 22nd, 2018* 2594 2595 BUG FIXES: 2596 - [libs/autofile] [\#2261](https://github.com/tendermint/tendermint/issues/2261) Fix log rotation so it actually happens. 2597 - Fixes issues with consensus WAL growing unbounded ala [\#2259](https://github.com/tendermint/tendermint/issues/2259) 2598 2599 ## 0.23.0 2600 2601 *August 5th, 2018* 2602 2603 This release includes breaking upgrades in our P2P encryption, 2604 some ABCI messages, and how we encode time and signatures. 2605 2606 A few more changes are still coming to the Header, ABCI, 2607 and validator set handling to better support light clients, BFT time, and 2608 upgrades. Most notably, validator set changes will be delayed by one block (see 2609 [#1815][i1815]). 2610 2611 We also removed `make ensure_deps` in favour of `make get_vendor_deps`. 2612 2613 BREAKING CHANGES: 2614 - [abci] Changed time format from int64 to google.protobuf.Timestamp 2615 - [abci] Changed Validators to LastCommitInfo in RequestBeginBlock 2616 - [abci] Removed Fee from ResponseDeliverTx and ResponseCheckTx 2617 - [crypto] Switch crypto.Signature from interface to []byte for space efficiency 2618 [#2128](https://github.com/tendermint/tendermint/pull/2128) 2619 - NOTE: this means signatures no longer have the prefix bytes in Amino 2620 binary nor the `type` field in Amino JSON. They're just bytes. 2621 - [p2p] Remove salsa and ripemd primitives, in favor of using chacha as a stream cipher, and hkdf [#2054](https://github.com/tendermint/tendermint/pull/2054) 2622 - [tools] Removed `make ensure_deps` in favor of `make get_vendor_deps` 2623 - [types] CanonicalTime uses nanoseconds instead of clipping to ms 2624 - breaks serialization/signing of all messages with a timestamp 2625 2626 FEATURES: 2627 - [tools] Added `make check_dep` 2628 - ensures gopkg.lock is synced with gopkg.toml 2629 - ensures no branches are used in the gopkg.toml 2630 2631 IMPROVEMENTS: 2632 - [blockchain] Improve fast-sync logic 2633 [#1805](https://github.com/tendermint/tendermint/pull/1805) 2634 - tweak params 2635 - only process one block at a time to avoid starving 2636 - [common] bit array functions which take in another parameter are now thread safe 2637 - [crypto] Switch hkdfchachapoly1305 to xchachapoly1305 2638 - [p2p] begin connecting to peers as soon a seed node provides them to you ([#2093](https://github.com/tendermint/tendermint/issues/2093)) 2639 2640 BUG FIXES: 2641 - [common] Safely handle cases where atomic write files already exist [#2109](https://github.com/tendermint/tendermint/issues/2109) 2642 - [privval] fix a deadline for accepting new connections in socket private 2643 validator. 2644 - [p2p] Allow startup if a configured seed node's IP can't be resolved ([#1716](https://github.com/tendermint/tendermint/issues/1716)) 2645 - [node] Fully exit when CTRL-C is pressed even if consensus state panics [#2072](https://github.com/tendermint/tendermint/issues/2072) 2646 2647 [i1815]: https://github.com/tendermint/tendermint/pull/1815 2648 2649 ## 0.22.8 2650 2651 *July 26th, 2018* 2652 2653 BUG FIXES 2654 2655 - [consensus, blockchain] Fix 0.22.7 below. 2656 2657 ## 0.22.7 2658 2659 *July 26th, 2018* 2660 2661 BUG FIXES 2662 2663 - [consensus, blockchain] Register the Evidence interface so it can be 2664 marshalled/unmarshalled by the blockchain and consensus reactors 2665 2666 ## 0.22.6 2667 2668 *July 24th, 2018* 2669 2670 BUG FIXES 2671 2672 - [rpc] Fix `/blockchain` endpoint 2673 - (#2049) Fix OOM attack by returning error on negative input 2674 - Fix result length to have max 20 (instead of 21) block metas 2675 - [rpc] Validate height is non-negative in `/abci_query` 2676 - [consensus] (#2050) Include evidence in proposal block parts (previously evidence was 2677 not being included in blocks!) 2678 - [p2p] (#2046) Close rejected inbound connections so file descriptor doesn't 2679 leak 2680 - [Gopkg] (#2053) Fix versions in the toml 2681 2682 ## 0.22.5 2683 2684 *July 23th, 2018* 2685 2686 BREAKING CHANGES: 2687 - [crypto] Refactor `tendermint/crypto` into many subpackages 2688 - [libs/common] remove exponentially distributed random numbers 2689 2690 IMPROVEMENTS: 2691 - [abci, libs/common] Generated gogoproto static marshaller methods 2692 - [config] Increase default send/recv rates to 5 mB/s 2693 - [p2p] reject addresses coming from private peers 2694 - [p2p] allow persistent peers to be private 2695 2696 BUG FIXES: 2697 - [mempool] fixed a race condition when `create_empty_blocks=false` where a 2698 transaction is published at an old height. 2699 - [p2p] dial external IP setup by `persistent_peers`, not internal NAT IP 2700 - [rpc] make `/status` RPC endpoint resistant to consensus halt 2701 2702 ## 0.22.4 2703 2704 *July 14th, 2018* 2705 2706 BREAKING CHANGES: 2707 - [genesis] removed deprecated `app_options` field. 2708 - [types] Genesis.AppStateJSON -> Genesis.AppState 2709 2710 FEATURES: 2711 - [tools] Merged in from github.com/tendermint/tools 2712 2713 BUG FIXES: 2714 - [tools/tm-bench] Various fixes 2715 - [consensus] Wait for WAL to stop on shutdown 2716 - [abci] Fix #1891, pending requests cannot hang when abci server dies. 2717 Previously a crash in BeginBlock could leave tendermint in broken state. 2718 2719 ## 0.22.3 2720 2721 *July 10th, 2018* 2722 2723 IMPROVEMENTS 2724 - Update dependencies 2725 * pin all values in Gopkg.toml to version or commit 2726 * update golang/protobuf to v1.1.0 2727 2728 ## 0.22.2 2729 2730 *July 10th, 2018* 2731 2732 IMPROVEMENTS 2733 - More cleanup post repo merge! 2734 - [docs] Include `ecosystem.json` and `tendermint-bft.md` from deprecated `aib-data` repository. 2735 - [config] Add `instrumentation.max_open_connections`, which limits the number 2736 of requests in flight to Prometheus server (if enabled). Default: 3. 2737 2738 2739 BUG FIXES 2740 - [rpc] Allow unquoted integers in requests 2741 - NOTE: this is only for URI requests. JSONRPC requests and all responses 2742 will use quoted integers (the proto3 JSON standard). 2743 - [consensus] Fix halt on shutdown 2744 2745 ## 0.22.1 2746 2747 *July 5th, 2018* 2748 2749 IMPROVEMENTS 2750 2751 * Cleanup post repo-merge. 2752 * [docs] Various improvements. 2753 2754 BUG FIXES 2755 2756 * [state] Return error when EndBlock returns a 0-power validator that isn't 2757 already in the validator set. 2758 * [consensus] Shut down WAL properly. 2759 2760 2761 ## 0.22.0 2762 2763 *July 2nd, 2018* 2764 2765 BREAKING CHANGES: 2766 - [config] 2767 * Remove `max_block_size_txs` and `max_block_size_bytes` in favor of 2768 consensus params from the genesis file. 2769 * Rename `skip_upnp` to `upnp`, and turn it off by default. 2770 * Change `max_packet_msg_size` back to `max_packet_msg_payload_size` 2771 - [rpc] 2772 * All integers are encoded as strings (part of the update for Amino v0.10.1) 2773 * `syncing` is now called `catching_up` 2774 - [types] Update Amino to v0.10.1 2775 * Amino is now fully proto3 compatible for the basic types 2776 * JSON-encoded types now use the type name instead of the prefix bytes 2777 * Integers are encoded as strings 2778 - [crypto] Update go-crypto to v0.10.0 and merge into `crypto` 2779 * privKey.Sign returns error. 2780 * ed25519 address changed to the first 20-bytes of the SHA256 of the raw pubkey bytes 2781 * `tmlibs/merkle` -> `crypto/merkle`. Uses SHA256 instead of RIPEMD160 2782 - [tmlibs] Update to v0.9.0 and merge into `libs` 2783 * remove `merkle` package (moved to `crypto/merkle`) 2784 2785 FEATURES 2786 - [cmd] Added metrics (served under `/metrics` using a Prometheus client; 2787 disabled by default). See the new `instrumentation` section in the config and 2788 [metrics](https://tendermint.readthedocs.io/projects/tools/en/develop/metrics.html) 2789 guide. 2790 - [p2p] Add IPv6 support to peering. 2791 - [p2p] Add `external_address` to config to allow specifying the address for 2792 peers to dial 2793 2794 IMPROVEMENT 2795 - [rpc/client] Supports https and wss now. 2796 - [crypto] Make public key size into public constants 2797 - [mempool] Log tx hash, not entire tx 2798 - [abci] Merged in github.com/tendermint/abci 2799 - [crypto] Merged in github.com/tendermint/go-crypto 2800 - [libs] Merged in github.com/tendermint/tmlibs 2801 - [docs] Move from .rst to .md 2802 2803 BUG FIXES: 2804 - [rpc] Limit maximum number of HTTP/WebSocket connections 2805 (`rpc.max_open_connections`) and gRPC connections 2806 (`rpc.grpc_max_open_connections`). Check out "Running In Production" guide if 2807 you want to increase them. 2808 - [rpc] Limit maximum request body size to 1MB (header is limited to 1MB). 2809 - [consensus] Fix a halting bug where `create_empty_blocks=false` 2810 - [p2p] Fix panic in seed mode 2811 2812 ## 0.21.0 2813 2814 *June 21th, 2018* 2815 2816 BREAKING CHANGES 2817 2818 - [config] Change default ports from 4665X to 2665X. Ports over 32768 are 2819 ephemeral and reserved for use by the kernel. 2820 - [cmd] `unsafe_reset_all` removes the addrbook.json 2821 2822 IMPROVEMENT 2823 2824 - [pubsub] Set default capacity to 0 2825 - [docs] Various improvements 2826 2827 BUG FIXES 2828 2829 - [consensus] Fix an issue where we don't make blocks after `fast_sync` when `create_empty_blocks=false` 2830 - [mempool] Fix #1761 where we don't process txs if `cache_size=0` 2831 - [rpc] Fix memory leak in Websocket (when using `/subscribe` method) 2832 - [config] Escape paths in config - fixes config paths on Windows 2833 2834 ## 0.20.0 2835 2836 *June 6th, 2018* 2837 2838 This is the first in a series of breaking releases coming to Tendermint after 2839 soliciting developer feedback and conducting security audits. 2840 2841 This release does not break any blockchain data structures or 2842 protocols other than the ABCI messages between Tendermint and the application. 2843 2844 Applications that upgrade for ABCI v0.11.0 should be able to continue running Tendermint 2845 v0.20.0 on blockchains created with v0.19.X 2846 2847 BREAKING CHANGES 2848 2849 - [abci] Upgrade to 2850 [v0.11.0](https://github.com/tendermint/abci/blob/master/CHANGELOG.md#0110) 2851 - [abci] Change Query path for filtering peers by node ID from 2852 `p2p/filter/pubkey/<id>` to `p2p/filter/id/<id>` 2853 2854 ## 0.19.9 2855 2856 *June 5th, 2018* 2857 2858 BREAKING CHANGES 2859 2860 - [types/priv_validator] Moved to top level `privval` package 2861 2862 FEATURES 2863 2864 - [config] Collapse PeerConfig into P2PConfig 2865 - [docs] Add quick-install script 2866 - [docs/spec] Add table of Amino prefixes 2867 2868 BUG FIXES 2869 2870 - [rpc] Return 404 for unknown endpoints 2871 - [consensus] Flush WAL on stop 2872 - [evidence] Don't send evidence to peers that are behind 2873 - [p2p] Fix memory leak on peer disconnects 2874 - [rpc] Fix panic when `per_page=0` 2875 2876 ## 0.19.8 2877 2878 *June 4th, 2018* 2879 2880 BREAKING: 2881 2882 - [p2p] Remove `auth_enc` config option, peer connections are always auth 2883 encrypted. Technically a breaking change but seems no one was using it and 2884 arguably a bug fix :) 2885 2886 BUG FIXES 2887 2888 - [mempool] Fix deadlock under high load when `skip_timeout_commit=true` and 2889 `create_empty_blocks=false` 2890 2891 ## 0.19.7 2892 2893 *May 31st, 2018* 2894 2895 BREAKING: 2896 2897 - [libs/pubsub] TagMap#Get returns a string value 2898 - [libs/pubsub] NewTagMap accepts a map of strings 2899 2900 FEATURES 2901 2902 - [rpc] the RPC documentation is now published to https://tendermint.github.io/slate 2903 - [p2p] AllowDuplicateIP config option to refuse connections from same IP. 2904 - true by default for now, false by default in next breaking release 2905 - [docs] Add docs for query, tx indexing, events, pubsub 2906 - [docs] Add some notes about running Tendermint in production 2907 2908 IMPROVEMENTS: 2909 2910 - [consensus] Consensus reactor now receives events from a separate synchronous event bus, 2911 which is not dependant on external RPC load 2912 - [consensus/wal] do not look for height in older files if we've seen height - 1 2913 - [docs] Various cleanup and link fixes 2914 2915 ## 0.19.6 2916 2917 *May 29th, 2018* 2918 2919 BUG FIXES 2920 2921 - [blockchain] Fix fast-sync deadlock during high peer turnover 2922 2923 BUG FIX: 2924 2925 - [evidence] Dont send peers evidence from heights they haven't synced to yet 2926 - [p2p] Refuse connections to more than one peer with the same IP 2927 - [docs] Various fixes 2928 2929 ## 0.19.5 2930 2931 *May 20th, 2018* 2932 2933 BREAKING CHANGES 2934 2935 - [rpc/client] TxSearch and UnconfirmedTxs have new arguments (see below) 2936 - [rpc/client] TxSearch returns ResultTxSearch 2937 - [version] Breaking changes to Go APIs will not be reflected in breaking 2938 version change, but will be included in changelog. 2939 2940 FEATURES 2941 2942 - [rpc] `/tx_search` takes `page` (starts at 1) and `per_page` (max 100, default 30) args to paginate results 2943 - [rpc] `/unconfirmed_txs` takes `limit` (max 100, default 30) arg to limit the output 2944 - [config] `mempool.size` and `mempool.cache_size` options 2945 2946 IMPROVEMENTS 2947 2948 - [docs] Lots of updates 2949 - [consensus] Only Fsync() the WAL before executing msgs from ourselves 2950 2951 BUG FIXES 2952 2953 - [mempool] Enforce upper bound on number of transactions 2954 2955 ## 0.19.4 (May 17th, 2018) 2956 2957 IMPROVEMENTS 2958 2959 - [state] Improve tx indexing by using batches 2960 - [consensus, state] Improve logging (more consensus logs, fewer tx logs) 2961 - [spec] Moved to `docs/spec` (TODO cleanup the rest of the docs ...) 2962 2963 BUG FIXES 2964 2965 - [consensus] Fix issue #1575 where a late proposer can get stuck 2966 2967 ## 0.19.3 (May 14th, 2018) 2968 2969 FEATURES 2970 2971 - [rpc] New `/consensus_state` returns just the votes seen at the current height 2972 2973 IMPROVEMENTS 2974 2975 - [rpc] Add stringified votes and fraction of power voted to `/dump_consensus_state` 2976 - [rpc] Add PeerStateStats to `/dump_consensus_state` 2977 2978 BUG FIXES 2979 2980 - [cmd] Set GenesisTime during `tendermint init` 2981 - [consensus] fix ValidBlock rules 2982 2983 ## 0.19.2 (April 30th, 2018) 2984 2985 FEATURES: 2986 2987 - [p2p] Allow peers with different Minor versions to connect 2988 - [rpc] `/net_info` includes `n_peers` 2989 2990 IMPROVEMENTS: 2991 2992 - [p2p] Various code comments, cleanup, error types 2993 - [p2p] Change some Error logs to Debug 2994 2995 BUG FIXES: 2996 2997 - [p2p] Fix reconnect to persistent peer when first dial fails 2998 - [p2p] Validate NodeInfo.ListenAddr 2999 - [p2p] Only allow (MaxNumPeers - MaxNumOutboundPeers) inbound peers 3000 - [p2p/pex] Limit max msg size to 64kB 3001 - [p2p] Fix panic when pex=false 3002 - [p2p] Allow multiple IPs per ID in AddrBook 3003 - [p2p] Fix before/after bugs in addrbook isBad() 3004 3005 ## 0.19.1 (April 27th, 2018) 3006 3007 Note this release includes some small breaking changes in the RPC and one in the 3008 config that are really bug fixes. v0.19.1 will work with existing chains, and make Tendermint 3009 easier to use and debug. With <3 3010 3011 BREAKING (MINOR) 3012 3013 - [config] Removed `wal_light` setting. If you really needed this, let us know 3014 3015 FEATURES: 3016 3017 - [networks] moved in tooling from devops repo: terraform and ansible scripts for deploying testnets ! 3018 - [cmd] Added `gen_node_key` command 3019 3020 BUG FIXES 3021 3022 Some of these are breaking in the RPC response, but they're really bugs! 3023 3024 - [spec] Document address format and pubkey encoding pre and post Amino 3025 - [rpc] Lower case JSON field names 3026 - [rpc] Fix missing entries, improve, and lower case the fields in `/dump_consensus_state` 3027 - [rpc] Fix NodeInfo.Channels format to hex 3028 - [rpc] Add Validator address to `/status` 3029 - [rpc] Fix `prove` in ABCIQuery 3030 - [cmd] MarshalJSONIndent on init 3031 3032 ## 0.19.0 (April 13th, 2018) 3033 3034 BREAKING: 3035 - [cmd] improved `testnet` command; now it can fill in `persistent_peers` for you in the config file and much more (see `tendermint testnet --help` for details) 3036 - [cmd] `show_node_id` now returns an error if there is no node key 3037 - [rpc]: changed the output format for the `/status` endpoint (see https://godoc.org/github.com/tendermint/tendermint/rpc/core#Status) 3038 3039 Upgrade from go-wire to go-amino. This is a sweeping change that breaks everything that is 3040 serialized to disk or over the network. 3041 3042 See github.com/tendermint/go-amino for details on the new format. 3043 3044 See `scripts/wire2amino.go` for a tool to upgrade 3045 genesis/priv_validator/node_key JSON files. 3046 3047 FEATURES 3048 3049 - [test] docker-compose for local testnet setup (thanks Greg!) 3050 3051 ## 0.18.0 (April 6th, 2018) 3052 3053 BREAKING: 3054 3055 - [types] Merkle tree uses different encoding for varints (see tmlibs v0.8.0) 3056 - [types] ValidtorSet.GetByAddress returns -1 if no validator found 3057 - [p2p] require all addresses come with an ID no matter what 3058 - [rpc] Listening address must contain tcp:// or unix:// prefix 3059 3060 FEATURES: 3061 3062 - [rpc] StartHTTPAndTLSServer (not used yet) 3063 - [rpc] Include validator's voting power in `/status` 3064 - [rpc] `/tx` and `/tx_search` responses now include the transaction hash 3065 - [rpc] Include peer NodeIDs in `/net_info` 3066 3067 IMPROVEMENTS: 3068 - [config] trim whitespace from elements of lists (like `persistent_peers`) 3069 - [rpc] `/tx_search` results are sorted by height 3070 - [p2p] do not try to connect to ourselves (ok, maybe only once) 3071 - [p2p] seeds respond with a bias towards good peers 3072 3073 BUG FIXES: 3074 - [rpc] fix subscribing using an abci.ResponseDeliverTx tag 3075 - [rpc] fix tx_indexers matchRange 3076 - [rpc] fix unsubscribing (see tmlibs v0.8.0) 3077 3078 ## 0.17.1 (March 27th, 2018) 3079 3080 BUG FIXES: 3081 - [types] Actually support `app_state` in genesis as `AppStateJSON` 3082 3083 ## 0.17.0 (March 27th, 2018) 3084 3085 BREAKING: 3086 - [types] WriteSignBytes -> SignBytes 3087 3088 IMPROVEMENTS: 3089 - [all] renamed `dummy` (`persistent_dummy`) to `kvstore` (`persistent_kvstore`) (name "dummy" is deprecated and will not work in the next breaking release) 3090 - [docs] note on determinism (docs/determinism.rst) 3091 - [genesis] `app_options` field is deprecated. please rename it to `app_state` in your genesis file(s). `app_options` will not work in the next breaking release 3092 - [p2p] dial seeds directly without potential peers 3093 - [p2p] exponential backoff for addrs in the address book 3094 - [p2p] mark peer as good if it contributed enough votes or block parts 3095 - [p2p] stop peer if it sends incorrect data, msg to unknown channel, msg we did not expect 3096 - [p2p] when `auth_enc` is true, all dialed peers must have a node ID in their address 3097 - [spec] various improvements 3098 - switched from glide to dep internally for package management 3099 - [wire] prep work for upgrading to new go-wire (which is now called go-amino) 3100 3101 FEATURES: 3102 - [config] exposed `auth_enc` flag to enable/disable encryption 3103 - [config] added the `--p2p.private_peer_ids` flag and `PrivatePeerIDs` config variable (see config for description) 3104 - [rpc] added `/health` endpoint, which returns empty result for now 3105 - [types/priv_validator] new format and socket client, allowing for remote signing 3106 3107 BUG FIXES: 3108 - [consensus] fix liveness bug by introducing ValidBlock mechanism 3109 3110 ## 0.16.0 (February 20th, 2018) 3111 3112 BREAKING CHANGES: 3113 - [config] use $TMHOME/config for all config and json files 3114 - [p2p] old `--p2p.seeds` is now `--p2p.persistent_peers` (persistent peers to which TM will always connect to) 3115 - [p2p] now `--p2p.seeds` only used for getting addresses (if addrbook is empty; not persistent) 3116 - [p2p] NodeInfo: remove RemoteAddr and add Channels 3117 - we must have at least one overlapping channel with peer 3118 - we only send msgs for channels the peer advertised 3119 - [p2p/conn] pong timeout 3120 - [lite] comment out IAVL related code 3121 3122 FEATURES: 3123 - [p2p] added new `/dial_peers&persistent=_` **unsafe** endpoint 3124 - [p2p] persistent node key in `$THMHOME/config/node_key.json` 3125 - [p2p] introduce peer ID and authenticate peers by ID using addresses like `ID@IP:PORT` 3126 - [p2p/pex] new seed mode crawls the network and serves as a seed. 3127 - [config] MempoolConfig.CacheSize 3128 - [config] P2P.SeedMode (`--p2p.seed_mode`) 3129 3130 IMPROVEMENT: 3131 - [p2p/pex] stricter rules in the PEX reactor for better handling of abuse 3132 - [p2p] various improvements to code structure including subpackages for `pex` and `conn` 3133 - [docs] new spec! 3134 - [all] speed up the tests! 3135 3136 BUG FIX: 3137 - [blockchain] StopPeerForError on timeout 3138 - [consensus] StopPeerForError on a bad Maj23 message 3139 - [state] flush mempool conn before calling commit 3140 - [types] fix priv val signing things that only differ by timestamp 3141 - [mempool] fix memory leak causing zombie peers 3142 - [p2p/conn] fix potential deadlock 3143 3144 ## 0.15.0 (December 29, 2017) 3145 3146 BREAKING CHANGES: 3147 - [p2p] enable the Peer Exchange reactor by default 3148 - [types] add Timestamp field to Proposal/Vote 3149 - [types] add new fields to Header: TotalTxs, ConsensusParamsHash, LastResultsHash, EvidenceHash 3150 - [types] add Evidence to Block 3151 - [types] simplify ValidateBasic 3152 - [state] updates to support changes to the header 3153 - [state] Enforce <1/3 of validator set can change at a time 3154 3155 FEATURES: 3156 - [state] Send indices of absent validators and addresses of byzantine validators in BeginBlock 3157 - [state] Historical ConsensusParams and ABCIResponses 3158 - [docs] Specification for the base Tendermint data structures. 3159 - [evidence] New evidence reactor for gossiping and managing evidence 3160 - [rpc] `/block_results?height=X` returns the DeliverTx results for a given height. 3161 3162 IMPROVEMENTS: 3163 - [consensus] Better handling of corrupt WAL file 3164 3165 BUG FIXES: 3166 - [lite] fix race 3167 - [state] validate block.Header.ValidatorsHash 3168 - [p2p] allow seed addresses to be prefixed with eg. `tcp://` 3169 - [p2p] use consistent key to refer to peers so we dont try to connect to existing peers 3170 - [cmd] fix `tendermint init` to ignore files that are there and generate files that aren't. 3171 3172 ## 0.14.0 (December 11, 2017) 3173 3174 BREAKING CHANGES: 3175 - consensus/wal: removed separator 3176 - rpc/client: changed Subscribe/Unsubscribe/UnsubscribeAll funcs signatures to be identical to event bus. 3177 3178 FEATURES: 3179 - new `tendermint lite` command (and `lite/proxy` pkg) for running a light-client RPC proxy. 3180 NOTE it is currently insecure and its APIs are not yet covered by semver 3181 3182 IMPROVEMENTS: 3183 - rpc/client: can act as event bus subscriber (See https://github.com/tendermint/tendermint/issues/945). 3184 - p2p: use exponential backoff from seconds to hours when attempting to reconnect to persistent peer 3185 - config: moniker defaults to the machine's hostname instead of "anonymous" 3186 3187 BUG FIXES: 3188 - p2p: no longer exit if one of the seed addresses is incorrect 3189 3190 ## 0.13.0 (December 6, 2017) 3191 3192 BREAKING CHANGES: 3193 - abci: update to v0.8 using gogo/protobuf; includes tx tags, vote info in RequestBeginBlock, data.Bytes everywhere, use int64, etc. 3194 - types: block heights are now `int64` everywhere 3195 - types & node: EventSwitch and EventCache have been replaced by EventBus and EventBuffer; event types have been overhauled 3196 - node: EventSwitch methods now refer to EventBus 3197 - rpc/lib/types: RPCResponse is no longer a pointer; WSRPCConnection interface has been modified 3198 - rpc/client: WaitForOneEvent takes an EventsClient instead of types.EventSwitch 3199 - rpc/client: Add/RemoveListenerForEvent are now Subscribe/Unsubscribe 3200 - rpc/core/types: ResultABCIQuery wraps an abci.ResponseQuery 3201 - rpc: `/subscribe` and `/unsubscribe` take `query` arg instead of `event` 3202 - rpc: `/status` returns the LatestBlockTime in human readable form instead of in nanoseconds 3203 - mempool: cached transactions return an error instead of an ABCI response with BadNonce 3204 3205 FEATURES: 3206 - rpc: new `/unsubscribe_all` WebSocket RPC endpoint 3207 - rpc: new `/tx_search` endpoint for filtering transactions by more complex queries 3208 - p2p/trust: new trust metric for tracking peers. See ADR-006 3209 - config: TxIndexConfig allows to set what DeliverTx tags to index 3210 3211 IMPROVEMENTS: 3212 - New asynchronous events system using `tmlibs/pubsub` 3213 - logging: Various small improvements 3214 - consensus: Graceful shutdown when app crashes 3215 - tests: Fix various non-deterministic errors 3216 - p2p: more defensive programming 3217 3218 BUG FIXES: 3219 - consensus: fix panic where prs.ProposalBlockParts is not initialized 3220 - p2p: fix panic on bad channel 3221 3222 ## 0.12.1 (November 27, 2017) 3223 3224 BUG FIXES: 3225 - upgrade tmlibs dependency to enable Windows builds for Tendermint 3226 3227 ## 0.12.0 (October 27, 2017) 3228 3229 BREAKING CHANGES: 3230 - rpc/client: websocket ResultsCh and ErrorsCh unified in ResponsesCh. 3231 - rpc/client: ABCIQuery no longer takes `prove` 3232 - state: remove GenesisDoc from state. 3233 - consensus: new binary WAL format provides efficiency and uses checksums to detect corruption 3234 - use scripts/wal2json to convert to json for debugging 3235 3236 FEATURES: 3237 - new `Verifiers` pkg contains the tendermint light-client library (name subject to change)! 3238 - rpc: `/genesis` includes the `app_options` . 3239 - rpc: `/abci_query` takes an additional `height` parameter to support historical queries. 3240 - rpc/client: new ABCIQueryWithOptions supports options like `trusted` (set false to get a proof) and `height` to query a historical height. 3241 3242 IMPROVEMENTS: 3243 - rpc: `/genesis` result includes `app_options` 3244 - rpc/lib/client: add jitter to reconnects. 3245 - rpc/lib/types: `RPCError` satisfies the `error` interface. 3246 3247 BUG FIXES: 3248 - rpc/client: fix ws deadlock after stopping 3249 - blockchain: fix panic on AddBlock when peer is nil 3250 - mempool: fix sending on TxsAvailable when a tx has been invalidated 3251 - consensus: dont run WAL catchup if we fast synced 3252 3253 ## 0.11.1 (October 10, 2017) 3254 3255 IMPROVEMENTS: 3256 - blockchain/reactor: respondWithNoResponseMessage for missing height 3257 3258 BUG FIXES: 3259 - rpc: fixed client WebSocket timeout 3260 - rpc: client now resubscribes on reconnection 3261 - rpc: fix panics on missing params 3262 - rpc: fix `/dump_consensus_state` to have normal json output (NOTE: technically breaking, but worth a bug fix label) 3263 - types: fixed out of range error in VoteSet.addVote 3264 - consensus: fix wal autofile via https://github.com/tendermint/tmlibs/blob/master/CHANGELOG.md#032-october-2-2017 3265 3266 ## 0.11.0 (September 22, 2017) 3267 3268 BREAKING: 3269 - genesis file: validator `amount` is now `power` 3270 - abci: Info, BeginBlock, InitChain all take structs 3271 - rpc: various changes to match JSONRPC spec (http://www.jsonrpc.org/specification), including breaking ones: 3272 - requests that previously returned HTTP code 4XX now return 200 with an error code in the JSONRPC. 3273 - `rpctypes.RPCResponse` uses new `RPCError` type instead of `string`. 3274 3275 - cmd: if there is no genesis, exit immediately instead of waiting around for one to show. 3276 - types: `Signer.Sign` returns an error. 3277 - state: every validator set change is persisted to disk, which required some changes to the `State` structure. 3278 - p2p: new `p2p.Peer` interface used for all reactor methods (instead of `*p2p.Peer` struct). 3279 3280 FEATURES: 3281 - rpc: `/validators?height=X` allows querying of validators at previous heights. 3282 - rpc: Leaving the `height` param empty for `/block`, `/validators`, and `/commit` will return the value for the latest height. 3283 3284 IMPROVEMENTS: 3285 - docs: Moved all docs from the website and tools repo in, converted to `.rst`, and cleaned up for presentation on `tendermint.readthedocs.io` 3286 3287 BUG FIXES: 3288 - fix WAL openning issue on Windows 3289 3290 ## 0.10.4 (September 5, 2017) 3291 3292 IMPROVEMENTS: 3293 - docs: Added Slate docs to each rpc function (see rpc/core) 3294 - docs: Ported all website docs to Read The Docs 3295 - config: expose some p2p params to tweak performance: RecvRate, SendRate, and MaxMsgPacketPayloadSize 3296 - rpc: Upgrade the websocket client and server, including improved auto reconnect, and proper ping/pong 3297 3298 BUG FIXES: 3299 - consensus: fix panic on getVoteBitArray 3300 - consensus: hang instead of panicking on byzantine consensus failures 3301 - cmd: dont load config for version command 3302 3303 ## 0.10.3 (August 10, 2017) 3304 3305 FEATURES: 3306 - control over empty block production: 3307 - new flag, `--consensus.create_empty_blocks`; when set to false, blocks are only created when there are txs or when the AppHash changes. 3308 - new config option, `consensus.create_empty_blocks_interval`; an empty block is created after this many seconds. 3309 - in normal operation, `create_empty_blocks = true` and `create_empty_blocks_interval = 0`, so blocks are being created all the time (as in all previous versions of tendermint). The number of empty blocks can be reduced by increasing `create_empty_blocks_interval` or by setting `create_empty_blocks = false`. 3310 - new `TxsAvailable()` method added to Mempool that returns a channel which fires when txs are available. 3311 - new heartbeat message added to consensus reactor to notify peers that a node is waiting for txs before entering propose step. 3312 - rpc: Add `syncing` field to response returned by `/status`. Is `true` while in fast-sync mode. 3313 3314 IMPROVEMENTS: 3315 - various improvements to documentation and code comments 3316 3317 BUG FIXES: 3318 - mempool: pass height into constructor so it doesn't always start at 0 3319 3320 ## 0.10.2 (July 10, 2017) 3321 3322 FEATURES: 3323 - Enable lower latency block commits by adding consensus reactor sleep durations and p2p flush throttle timeout to the config 3324 3325 IMPROVEMENTS: 3326 - More detailed logging in the consensus reactor and state machine 3327 - More in-code documentation for many exposed functions, especially in consensus/reactor.go and p2p/switch.go 3328 - Improved readability for some function definitions and code blocks with long lines 3329 3330 ## 0.10.1 (June 28, 2017) 3331 3332 FEATURES: 3333 - Use `--trace` to get stack traces for logged errors 3334 - types: GenesisDoc.ValidatorHash returns the hash of the genesis validator set 3335 - types: GenesisDocFromFile parses a GenesiDoc from a JSON file 3336 3337 IMPROVEMENTS: 3338 - Add a Code of Conduct 3339 - Variety of improvements as suggested by `megacheck` tool 3340 - rpc: deduplicate tests between rpc/client and rpc/tests 3341 - rpc: addresses without a protocol prefix default to `tcp://`. `http://` is also accepted as an alias for `tcp://` 3342 - cmd: commands are more easily reuseable from other tools 3343 - DOCKER: automate build/push 3344 3345 BUG FIXES: 3346 - Fix log statements using keys with spaces (logger does not currently support spaces) 3347 - rpc: set logger on websocket connection 3348 - rpc: fix ws connection stability by setting write deadline on pings 3349 3350 ## 0.10.0 (June 2, 2017) 3351 3352 Includes major updates to configuration, logging, and json serialization. 3353 Also includes the Grand Repo-Merge of 2017. 3354 3355 BREAKING CHANGES: 3356 3357 - Config and Flags: 3358 - The `config` map is replaced with a [`Config` struct](https://github.com/tendermint/tendermint/blob/master/config/config.go#L11), 3359 containing substructs: `BaseConfig`, `P2PConfig`, `MempoolConfig`, `ConsensusConfig`, `RPCConfig` 3360 - This affects the following flags: 3361 - `--seeds` is now `--p2p.seeds` 3362 - `--node_laddr` is now `--p2p.laddr` 3363 - `--pex` is now `--p2p.pex` 3364 - `--skip_upnp` is now `--p2p.skip_upnp` 3365 - `--rpc_laddr` is now `--rpc.laddr` 3366 - `--grpc_laddr` is now `--rpc.grpc_laddr` 3367 - Any configuration option now within a substract must come under that heading in the `config.toml`, for instance: 3368 ``` 3369 [p2p] 3370 laddr="tcp://1.2.3.4:46656" 3371 3372 [consensus] 3373 timeout_propose=1000 3374 ``` 3375 - Use viper and `DefaultConfig() / TestConfig()` functions to handle defaults, and remove `config/tendermint` and `config/tendermint_test` 3376 - Change some function and method signatures to 3377 - Change some [function and method signatures](https://gist.github.com/ebuchman/640d5fc6c2605f73497992fe107ebe0b) accomodate new config 3378 3379 - Logger 3380 - Replace static `log15` logger with a simple interface, and provide a new implementation using `go-kit`. 3381 See our new [logging library](https://github.com/tendermint/tmlibs/log) and [blog post](https://tendermint.com/blog/abstracting-the-logger-interface-in-go) for more details 3382 - Levels `warn` and `notice` are removed (you may need to change them in your `config.toml`!) 3383 - Change some [function and method signatures](https://gist.github.com/ebuchman/640d5fc6c2605f73497992fe107ebe0b) to accept a logger 3384 3385 - JSON serialization: 3386 - Replace `[TypeByte, Xxx]` with `{"type": "some-type", "data": Xxx}` in RPC and all `.json` files by using `go-wire/data`. For instance, a public key is now: 3387 ``` 3388 "pub_key": { 3389 "type": "ed25519", 3390 "data": "83DDF8775937A4A12A2704269E2729FCFCD491B933C4B0A7FFE37FE41D7760D0" 3391 } 3392 ``` 3393 - Remove type information about RPC responses, so `[TypeByte, {"jsonrpc": "2.0", ... }]` is now just `{"jsonrpc": "2.0", ... }` 3394 - Change `[]byte` to `data.Bytes` in all serialized types (for hex encoding) 3395 - Lowercase the JSON tags in `ValidatorSet` fields 3396 - Introduce `EventDataInner` for serializing events 3397 3398 - Other: 3399 - Send InitChain message in handshake if `appBlockHeight == 0` 3400 - Do not include the `Accum` field when computing the validator hash. This makes the ValidatorSetHash unique for a given validator set, rather than changing with every block (as the Accum changes) 3401 - Unsafe RPC calls are not enabled by default. This includes `/dial_seeds`, and all calls prefixed with `unsafe`. Use the `--rpc.unsafe` flag to enable. 3402 3403 3404 FEATURES: 3405 3406 - Per-module log levels. For instance, the new default is `state:info,*:error`, which means the `state` package logs at `info` level, and everything else logs at `error` level 3407 - Log if a node is validator or not in every consensus round 3408 - Use ldflags to set git hash as part of the version 3409 - Ignore `address` and `pub_key` fields in `priv_validator.json` and overwrite them with the values derrived from the `priv_key` 3410 3411 IMPROVEMENTS: 3412 3413 - Merge `tendermint/go-p2p -> tendermint/tendermint/p2p` and `tendermint/go-rpc -> tendermint/tendermint/rpc/lib` 3414 - Update paths for grand repo merge: 3415 - `go-common -> tmlibs/common` 3416 - `go-data -> go-wire/data` 3417 - All other `go-` libs, except `go-crypto` and `go-wire`, are merged under `tmlibs` 3418 - No global loggers (loggers are passed into constructors, or preferably set with a SetLogger method) 3419 - Return HTTP status codes with errors for RPC responses 3420 - Limit `/blockchain_info` call to return a maximum of 20 blocks 3421 - Use `.Wrap()` and `.Unwrap()` instead of eg. `PubKeyS` for `go-crypto` types 3422 - RPC JSON responses use pretty printing (via `json.MarshalIndent`) 3423 - Color code different instances of the consensus for tests 3424 - Isolate viper to `cmd/tendermint/commands` and do not read config from file for tests 3425 3426 3427 ## 0.9.2 (April 26, 2017) 3428 3429 BUG FIXES: 3430 3431 - Fix bug in `ResetPrivValidator` where we were using the global config and log (causing external consumers, eg. basecoin, to fail). 3432 3433 ## 0.9.1 (April 21, 2017) 3434 3435 FEATURES: 3436 3437 - Transaction indexing - txs are indexed by their hash using a simple key-value store; easily extended to more advanced indexers 3438 - New `/tx?hash=X` endpoint to query for transactions and their DeliverTx result by hash. Optionally returns a proof of the tx's inclusion in the block 3439 - `tendermint testnet` command initializes files for a testnet 3440 3441 IMPROVEMENTS: 3442 3443 - CLI now uses Cobra framework 3444 - TMROOT is now TMHOME (TMROOT will stop working in 0.10.0) 3445 - `/broadcast_tx_XXX` also returns the Hash (can be used to query for the tx) 3446 - `/broadcast_tx_commit` also returns the height the block was committed in 3447 - ABCIResponses struct persisted to disk before calling Commit; makes handshake replay much cleaner 3448 - WAL uses #ENDHEIGHT instead of #HEIGHT (#HEIGHT will stop working in 0.10.0) 3449 - Peers included via `--seeds`, under `seeds` in the config, or in `/dial_seeds` are now persistent, and will be reconnected to if the connection breaks 3450 3451 BUG FIXES: 3452 3453 - Fix bug in fast-sync where we stop syncing after a peer is removed, even if they're re-added later 3454 - Fix handshake replay to handle validator set changes and results of DeliverTx when we crash after app.Commit but before state.Save() 3455 3456 ## 0.9.0 (March 6, 2017) 3457 3458 BREAKING CHANGES: 3459 3460 - Update ABCI to v0.4.0, where Query is now `Query(RequestQuery) ResponseQuery`, enabling precise proofs at particular heights: 3461 3462 ``` 3463 message RequestQuery{ 3464 bytes data = 1; 3465 string path = 2; 3466 uint64 height = 3; 3467 bool prove = 4; 3468 } 3469 3470 message ResponseQuery{ 3471 CodeType code = 1; 3472 int64 index = 2; 3473 bytes key = 3; 3474 bytes value = 4; 3475 bytes proof = 5; 3476 uint64 height = 6; 3477 string log = 7; 3478 } 3479 ``` 3480 3481 3482 - `BlockMeta` data type unifies its Hash and PartSetHash under a `BlockID`: 3483 3484 ``` 3485 type BlockMeta struct { 3486 BlockID BlockID `json:"block_id"` // the block hash and partsethash 3487 Header *Header `json:"header"` // The block's Header 3488 } 3489 ``` 3490 3491 - `ValidatorSet.Proposer` is exposed as a field and persisted with the `State`. Use `GetProposer()` to initialize or update after validator-set changes. 3492 3493 - `tendermint gen_validator` command output is now pure JSON 3494 3495 FEATURES: 3496 3497 - New RPC endpoint `/commit?height=X` returns header and commit for block at height `X` 3498 - Client API for each endpoint, including mocks for testing 3499 3500 IMPROVEMENTS: 3501 3502 - `Node` is now a `BaseService` 3503 - Simplified starting Tendermint in-process from another application 3504 - Better organized Makefile 3505 - Scripts for auto-building binaries across platforms 3506 - Docker image improved, slimmed down (using Alpine), and changed from tendermint/tmbase to tendermint/tendermint 3507 - New repo files: `CONTRIBUTING.md`, Github `ISSUE_TEMPLATE`, `CHANGELOG.md` 3508 - Improvements on CircleCI for managing build/test artifacts 3509 - Handshake replay is doen through the consensus package, possibly using a mockApp 3510 - Graceful shutdown of RPC listeners 3511 - Tests for the PEX reactor and DialSeeds 3512 3513 BUG FIXES: 3514 3515 - Check peer.Send for failure before updating PeerState in consensus 3516 - Fix panic in `/dial_seeds` with invalid addresses 3517 - Fix proposer selection logic in ValidatorSet by taking the address into account in the `accumComparable` 3518 - Fix inconcistencies with `ValidatorSet.Proposer` across restarts by persisting it in the `State` 3519 3520 3521 ## 0.8.0 (January 13, 2017) 3522 3523 BREAKING CHANGES: 3524 3525 - New data type `BlockID` to represent blocks: 3526 3527 ``` 3528 type BlockID struct { 3529 Hash []byte `json:"hash"` 3530 PartsHeader PartSetHeader `json:"parts"` 3531 } 3532 ``` 3533 3534 - `Vote` data type now includes validator address and index: 3535 3536 ``` 3537 type Vote struct { 3538 ValidatorAddress []byte `json:"validator_address"` 3539 ValidatorIndex int `json:"validator_index"` 3540 Height int `json:"height"` 3541 Round int `json:"round"` 3542 Type byte `json:"type"` 3543 BlockID BlockID `json:"block_id"` // zero if vote is nil. 3544 Signature crypto.Signature `json:"signature"` 3545 } 3546 ``` 3547 3548 - Update TMSP to v0.3.0, where it is now called ABCI and AppendTx is DeliverTx 3549 - Hex strings in the RPC are now "0x" prefixed 3550 3551 3552 FEATURES: 3553 3554 - New message type on the ConsensusReactor, `Maj23Msg`, for peers to alert others they've seen a Maj23, 3555 in order to track and handle conflicting votes intelligently to prevent Byzantine faults from causing halts: 3556 3557 ``` 3558 type VoteSetMaj23Message struct { 3559 Height int 3560 Round int 3561 Type byte 3562 BlockID types.BlockID 3563 } 3564 ``` 3565 3566 - Configurable block part set size 3567 - Validator set changes 3568 - Optionally skip TimeoutCommit if we have all the votes 3569 - Handshake between Tendermint and App on startup to sync latest state and ensure consistent recovery from crashes 3570 - GRPC server for BroadcastTx endpoint 3571 3572 IMPROVEMENTS: 3573 3574 - Less verbose logging 3575 - Better test coverage (37% -> 49%) 3576 - Canonical SignBytes for signable types 3577 - Write-Ahead Log for Mempool and Consensus via tmlibs/autofile 3578 - Better in-process testing for the consensus reactor and byzantine faults 3579 - Better crash/restart testing for individual nodes at preset failure points, and of networks at arbitrary points 3580 - Better abstraction over timeout mechanics 3581 3582 BUG FIXES: 3583 3584 - Fix memory leak in mempool peer 3585 - Fix panic on POLRound=-1 3586 - Actually set the CommitTime 3587 - Actually send BeginBlock message 3588 - Fix a liveness issues caused by Byzantine proposals/votes. Uses the new `Maj23Msg`. 3589 3590 3591 ## 0.7.4 (December 14, 2016) 3592 3593 FEATURES: 3594 3595 - Enable the Peer Exchange reactor with the `--pex` flag for more resilient gossip network (feature still in development, beware dragons) 3596 3597 IMPROVEMENTS: 3598 3599 - Remove restrictions on RPC endpoint `/dial_seeds` to enable manual network configuration 3600 3601 ## 0.7.3 (October 20, 2016) 3602 3603 IMPROVEMENTS: 3604 3605 - Type safe FireEvent 3606 - More WAL/replay tests 3607 - Cleanup some docs 3608 3609 BUG FIXES: 3610 3611 - Fix deadlock in mempool for synchronous apps 3612 - Replay handles non-empty blocks 3613 - Fix race condition in HeightVoteSet 3614 3615 ## 0.7.2 (September 11, 2016) 3616 3617 BUG FIXES: 3618 3619 - Set mustConnect=false so tendermint will retry connecting to the app 3620 3621 ## 0.7.1 (September 10, 2016) 3622 3623 FEATURES: 3624 3625 - New TMSP connection for Query/Info 3626 - New RPC endpoints: 3627 - `tmsp_query` 3628 - `tmsp_info` 3629 - Allow application to filter peers through Query (off by default) 3630 3631 IMPROVEMENTS: 3632 3633 - TMSP connection type enforced at compile time 3634 - All listen/client urls use a "tcp://" or "unix://" prefix 3635 3636 BUG FIXES: 3637 3638 - Save LastSignature/LastSignBytes to `priv_validator.json` for recovery 3639 - Fix event unsubscribe 3640 - Fix fastsync/blockchain reactor 3641 3642 ## 0.7.0 (August 7, 2016) 3643 3644 BREAKING CHANGES: 3645 3646 - Strict SemVer starting now! 3647 - Update to ABCI v0.2.0 3648 - Validation types now called Commit 3649 - NewBlock event only returns the block header 3650 3651 3652 FEATURES: 3653 3654 - TMSP and RPC support TCP and UNIX sockets 3655 - Addition config options including block size and consensus parameters 3656 - New WAL mode `cswal_light`; logs only the validator's own votes 3657 - New RPC endpoints: 3658 - for starting/stopping profilers, and for updating config 3659 - `/broadcast_tx_commit`, returns when tx is included in a block, else an error 3660 - `/unsafe_flush_mempool`, empties the mempool 3661 3662 3663 IMPROVEMENTS: 3664 3665 - Various optimizations 3666 - Remove bad or invalidated transactions from the mempool cache (allows later duplicates) 3667 - More elaborate testing using CircleCI including benchmarking throughput on 4 digitalocean droplets 3668 3669 BUG FIXES: 3670 3671 - Various fixes to WAL and replay logic 3672 - Various race conditions 3673 3674 ## PreHistory 3675 3676 Strict versioning only began with the release of v0.7.0, in late summer 2016. 3677 The project itself began in early summer 2014 and was workable decentralized cryptocurrency software by the end of that year. 3678 Through the course of 2015, in collaboration with Eris Industries (now Monax Industries), 3679 many additional features were integrated, including an implementation from scratch of the Ethereum Virtual Machine. 3680 That implementation now forms the heart of [Burrow](https://github.com/hyperledger/burrow). 3681 In the later half of 2015, the consensus algorithm was upgraded with a more asynchronous design and a more deterministic and robust implementation. 3682 3683 By late 2015, frustration with the difficulty of forking a large monolithic stack to create alternative cryptocurrency designs led to the 3684 invention of the Application Blockchain Interface (ABCI), then called the Tendermint Socket Protocol (TMSP). 3685 The Ethereum Virtual Machine and various other transaction features were removed, and Tendermint was whittled down to a core consensus engine 3686 driving an application running in another process. 3687 The ABCI interface and implementation were iterated on and improved over the course of 2016, 3688 until versioned history kicked in with v0.7.0.