github.com/vipernet-xyz/tm@v0.34.24/CHANGELOG.md (about) 1 # Changelog 2 3 Friendly reminder, we have a [bug bounty program](https://hackerone.com/cosmos). 4 5 ## v0.34.24 6 7 *Nov 21, 2022* 8 9 Apart from one minor bug fix, this release aims to optimize the output of the 10 RPC (both HTTP and WebSocket endpoints). See our [upgrading 11 guidelines](./UPGRADING.md#v03424) for more details. 12 13 ### IMPROVEMENTS 14 15 - `[rpc]` [\#9724](https://github.com/vipernet-xyz/tm/issues/9724) Remove 16 useless whitespace in RPC output (@adizere, @thanethomson) 17 18 ### BUG FIXES 19 20 - `[rpc]` [\#9692](https://github.com/vipernet-xyz/tm/issues/9692) Remove 21 `Cache-Control` header response from `/check_tx` endpoint (@JayT106) 22 23 ## v0.34.23 24 25 *Nov 9, 2022* 26 27 This release introduces some new Prometheus metrics to help in determining what 28 kinds of messages are consuming the most P2P bandwidth. This builds towards our 29 broader goal of optimizing Tendermint bandwidth consumption, and will give us 30 meaningful insights once we can establish these metrics for a number of chains. 31 32 We now also return `Cache-Control` headers for select RPC endpoints to help 33 facilitate caching. 34 35 Special thanks to external contributors on this release: @JayT106 36 37 ### IMPROVEMENTS 38 - `[p2p]` [\#9641](https://github.com/vipernet-xyz/tm/issues/9641) Add new 39 Envelope type and associated methods for sending and receiving Envelopes 40 instead of raw bytes. This also adds new metrics, 41 `tendermint_p2p_message_send_bytes_total` and 42 `tendermint_p2p_message_receive_bytes_total`, that expose how many bytes of 43 each message type have been sent. 44 - `[rpc]` [\#9666](https://github.com/vipernet-xyz/tm/issues/9666) Enable 45 caching of RPC responses (@JayT106) 46 47 The following RPC endpoints will return `Cache-Control` headers with a maximum 48 age of 1 day: 49 50 - `/abci_info` 51 - `/block`, if `height` is supplied 52 - `/block_by_hash` 53 - `/block_results`, if `height` is supplied 54 - `/blockchain` 55 - `/check_tx` 56 - `/commit`, if `height` is supplied 57 - `/consensus_params`, if `height` is supplied 58 - `/genesis` 59 - `/genesis_chunked` 60 - `/tx` 61 - `/validators`, if `height` is supplied 62 63 ## v0.34.22 64 65 This release includes several bug fixes, [one of 66 which](https://github.com/vipernet-xyz/tm/pull/9518) we discovered while 67 building up a baseline for v0.34 against which to compare our upcoming v0.37 68 release during our [QA process](./docs/qa/). 69 70 Special thanks to external contributors on this release: @RiccardoM 71 72 ### FEATURES 73 74 - [rpc] [\#9423](https://github.com/vipernet-xyz/tm/pull/9423) Support 75 HTTPS URLs from the WebSocket client (@RiccardoM, @cmwaters) 76 77 ### BUG FIXES 78 79 - [config] [\#9483](https://github.com/vipernet-xyz/tm/issues/9483) 80 Calling `tendermint init` would incorrectly leave out the new `[storage]` 81 section delimiter in the generated configuration file - this has now been 82 fixed 83 - [p2p] [\#9500](https://github.com/vipernet-xyz/tm/issues/9500) Prevent 84 peers who have errored being added to the peer set (@jmalicevic) 85 - [indexer] [\#9473](https://github.com/vipernet-xyz/tm/issues/9473) Fix 86 bug that caused the psql indexer to index empty blocks whenever one of the 87 transactions returned a non zero code. The relevant deduplication logic has 88 been moved within the kv indexer only (@cmwaters) 89 - [blocksync] [\#9518](https://github.com/vipernet-xyz/tm/issues/9518) A 90 block sync stall was observed during our QA process whereby the node was 91 unable to make progress. Retrying block requests after a timeout fixes this. 92 93 ## v0.34.21 94 95 Release highlights include: 96 97 - A new `[storage]` configuration section and flag `discard_abci_responses`, 98 which, if enabled, discards all ABCI responses except the latest one in order 99 to reduce disk space usage in the state store. When enabled, the 100 `block_results` RPC endpoint can no longer function and will return an error. 101 - A new CLI command, `reindex-event`, to re-index block and tx events to the 102 event sinks. You can run this command when the event store backend 103 dropped/disconnected or you want to replace the backend. When 104 `discard_abci_responses` is enabled, you will not be able to use this command. 105 106 Special thanks to external contributors on this release: @rootwarp & @animart 107 108 ### FEATURES 109 110 - [cli] [\#9083](https://github.com/vipernet-xyz/tm/issues/9083) Backport command to reindex missed events (@cmwaters) 111 - [cli] [\#9107](https://github.com/vipernet-xyz/tm/issues/9107) Add the `p2p.external-address` argument to set the node P2P external address (@amimart) 112 113 ### IMPROVEMENTS 114 115 - [config] [\#9054](https://github.com/vipernet-xyz/tm/issues/9054) `discard_abci_responses` flag added to discard all ABCI 116 responses except the last in order to save on storage space in the state 117 store (@samricotta) 118 119 ### BUG FIXES 120 121 - [mempool] [\#9033](https://github.com/vipernet-xyz/tm/issues/9033) Rework lock discipline to mitigate callback deadlocks in the 122 priority mempool 123 - [cli] [\#9103](https://github.com/vipernet-xyz/tm/issues/9103) fix unsafe-reset-all for working with home path (@rootwarp) 124 125 ## v0.34.20 126 127 Special thanks to external contributors on this release: @joeabbey @yihuang 128 129 This release introduces a prioritized mempool. Further notes can be found in UPGRADING.md. 130 131 NOTE: There's a known issue when combining the prioritized mempool with the ABCI socket client, that the team are curently working to resolve. Read more about the issue [here](https://github.com/vipernet-xyz/tm/pull/9030). 132 133 ### BUG FIXES 134 135 - [blocksync] [\#8496](https://github.com/vipernet-xyz/tm/pull/8496) validate block against state before persisting it to disk (@cmwaters) 136 - [indexer] [#8625](https://github.com/vipernet-xyz/tm/pull/8625) Fix overriding tx index of duplicated txs. (@yihuang) 137 - [mempool] [\#8962](https://github.com/vipernet-xyz/tm/issues/8962) Backport priority mempool fixes from v0.35.x to v0.34.x (@creachadair). 138 139 ### FEATURES 140 141 - [cli] [\#8674] Add command to force compact goleveldb databases (@cmwaters) 142 - [mempool] [\#8695] Port back the priority mempool. (@alexanderbez, @jmalicevic, @cmwaters) 143 144 ### IMPROVEMENTS 145 146 - [logging] [\#8845](https://github.com/vipernet-xyz/tm/issues/8845) Add "Lazy" Stringers to defer Sprintf and Hash until logs print. (@joeabbey) 147 148 ## v0.34.19 149 150 ### BUG FIXES 151 152 - [cli] [\#8270](https://github.com/vipernet-xyz/tm/issues/8270) fix reset commands (@alexanderbez). 153 154 ## v0.34.18 155 156 ### BREAKING CHANGES 157 158 - CLI/RPC/Config 159 - [cli] [\#8258](https://github.com/vipernet-xyz/tm/pull/8258) Fix a bug in the cli that caused `unsafe-reset-all` to panic 160 161 ## v0.34.17 162 163 ### BREAKING CHANGES 164 165 - CLI/RPC/Config 166 167 - [cli] [\#8081](https://github.com/vipernet-xyz/tm/issues/8081) make the reset command safe to use (@marbar3778). 168 169 ### BUG FIXES 170 171 - [consensus] [\#8079](https://github.com/vipernet-xyz/tm/issues/8079) start the timeout ticker before relay (backport #7844) (@creachadair). 172 - [consensus] [\#7992](https://github.com/vipernet-xyz/tm/issues/7992) [\#7994](https://github.com/vipernet-xyz/tm/issues/7994) change lock handling in handleMsg and reactor to alleviate issues gossiping during long ABCI calls (@williambanfield). 173 174 ## v0.34.16 175 176 Special thanks to external contributors on this release: @yihuang 177 178 ### BUG FIXES 179 180 - [consensus] [\#7617](https://github.com/vipernet-xyz/tm/issues/7617) calculate prevote message delay metric (backport #7551) (@williambanfield). 181 - [consensus] [\#7631](https://github.com/vipernet-xyz/tm/issues/7631) check proposal non-nil in prevote message delay metric (backport #7625) (@williambanfield). 182 - [statesync] [\#7885](https://github.com/vipernet-xyz/tm/issues/7885) statesync: assert app version matches (backport #7856) (@cmwaters). 183 - [statesync] [\#7881](https://github.com/vipernet-xyz/tm/issues/7881) fix app hash in state rollback (backport #7837) (@cmwaters). 184 - [cli] [#7837](https://github.com/vipernet-xyz/tm/pull/7837) fix app hash in state rollback. (@yihuang). 185 186 ## v0.34.15 187 188 Special thanks to external contributors on this release: @thanethomson 189 190 ### BUG FIXES 191 192 - [\#7368](https://github.com/vipernet-xyz/tm/issues/7368) cmd: add integration test for rollback functionality (@cmwaters). 193 - [\#7309](https://github.com/vipernet-xyz/tm/issues/7309) pubsub: Report a non-nil error when shutting down (fixes #7306). 194 - [\#7057](https://github.com/vipernet-xyz/tm/pull/7057) Import Postgres driver support for the psql indexer (@creachadair). 195 - [\#7106](https://github.com/vipernet-xyz/tm/pull/7106) Revert mutex change to ABCI Clients (@tychoish). 196 197 ### IMPROVEMENTS 198 199 - [config] [\#7230](https://github.com/vipernet-xyz/tm/issues/7230) rpc: Add experimental config params to allow for subscription buffer size control (@thanethomson). 200 201 ## v0.34.14 202 203 This release backports the `rollback` feature to allow recovery in the event of an incorrect app hash. 204 205 ### FEATURES 206 207 - [\#6982](https://github.com/vipernet-xyz/tm/pull/6982) The tendermint binary now has built-in suppport for running the end-to-end test application (with state sync support) (@cmwaters). 208 - [cli] [#7033](https://github.com/vipernet-xyz/tm/pull/7033) Add a `rollback` command to rollback to the previous tendermint state. This may be useful in the event of non-determinstic app hash or when reverting an upgrade. @cmwaters 209 210 ### IMPROVEMENTS 211 212 - [\#7103](https://github.com/vipernet-xyz/tm/pull/7104) Remove IAVL dependency (backport of #6550) (@cmwaters) 213 214 ### BUG FIXES 215 216 - [\#7057](https://github.com/vipernet-xyz/tm/pull/7057) Import Postgres driver support for the psql indexer (@creachadair). 217 - [ABCI] [\#7110](https://github.com/vipernet-xyz/tm/issues/7110) Revert "change client to use multi-reader mutexes (#6873)" (@tychoish). 218 219 ## v0.34.13 220 221 This release backports improvements to state synchronization and ABCI 222 performance under concurrent load, and the PostgreSQL event indexer. 223 224 ### IMPROVEMENTS 225 226 - [statesync] [\#6881](https://github.com/vipernet-xyz/tm/issues/6881) improvements to stateprovider logic (@cmwaters) 227 - [ABCI] [\#6873](https://github.com/vipernet-xyz/tm/issues/6873) change client to use multi-reader mutexes (@tychoish) 228 - [indexing] [\#6906](https://github.com/vipernet-xyz/tm/issues/6906) enable the PostgreSQL indexer sink (@creachadair) 229 230 ## v0.34.12 231 232 Special thanks to external contributors on this release: @JayT106. 233 234 ### FEATURES 235 236 - [rpc] [\#6717](https://github.com/vipernet-xyz/tm/pull/6717) introduce 237 `/genesis_chunked` rpc endpoint for handling large genesis files by chunking them (@tychoish) 238 239 ### IMPROVEMENTS 240 241 - [rpc] [\#6825](https://github.com/vipernet-xyz/tm/issues/6825) Remove egregious INFO log from `ABCI#Query` RPC. (@alexanderbez) 242 243 ### BUG FIXES 244 245 - [light] [\#6685](https://github.com/vipernet-xyz/tm/pull/6685) fix bug 246 with incorrectly handling contexts that would occasionally freeze state sync. (@cmwaters) 247 - [privval] [\#6748](https://github.com/vipernet-xyz/tm/issues/6748) Fix vote timestamp to prevent chain halt (@JayT106) 248 249 ## v0.34.11 250 251 *June 18, 2021* 252 253 This release improves the robustness of statesync; tweaking channel priorities and timeouts and 254 adding two new parameters to the state sync config. 255 256 ### BREAKING CHANGES 257 258 - Apps 259 - [Version] [\#6494](https://github.com/vipernet-xyz/tm/issues/6494) `TMCoreSemVer` is not required to be set as a ldflag any longer. 260 261 ### IMPROVEMENTS 262 263 - [statesync] [\#6566](https://github.com/vipernet-xyz/tm/issues/6566) Allow state sync fetchers and request timeout to be configurable. (@alexanderbez) 264 - [statesync] [\#6378](https://github.com/vipernet-xyz/tm/issues/6378) Retry requests for snapshots and add a minimum discovery time (5s) for new snapshots. (@tychoish) 265 - [statesync] [\#6582](https://github.com/vipernet-xyz/tm/issues/6582) Increase chunk priority and add multiple retry chunk requests (@cmwaters) 266 267 ### BUG FIXES 268 269 - [evidence] [\#6375](https://github.com/vipernet-xyz/tm/issues/6375) Fix bug with inconsistent LightClientAttackEvidence hashing (@cmwaters) 270 271 ## v0.34.10 272 273 *April 14, 2021* 274 275 This release fixes a bug where peers would sometimes try to send messages 276 on incorrect channels. Special thanks to our friends at Oasis Labs for surfacing 277 this issue! 278 279 - [p2p/node] [\#6339](https://github.com/vipernet-xyz/tm/issues/6339) Fix bug with using custom channels (@cmwaters) 280 - [light] [\#6346](https://github.com/vipernet-xyz/tm/issues/6346) Correctly handle too high errors to improve client robustness (@cmwaters) 281 282 ## v0.34.9 283 284 *April 8, 2021* 285 286 This release fixes a moderate severity security issue, Security Advisory Alderfly, 287 which impacts all networks that rely on Tendermint light clients. 288 Further details will be released once networks have upgraded. 289 290 This release also includes a small Go API-breaking change, to reduce panics in the RPC layer. 291 292 Special thanks to our external contributors on this release: @gchaincl 293 294 ### BREAKING CHANGES 295 296 - Go API 297 - [rpc/jsonrpc/server] [\#6204](https://github.com/vipernet-xyz/tm/issues/6204) Modify `WriteRPCResponseHTTP(Error)` to return an error (@melekes) 298 299 ### FEATURES 300 301 - [rpc] [\#6226](https://github.com/vipernet-xyz/tm/issues/6226) Index block events and expose a new RPC method, `/block_search`, to allow querying for blocks by `BeginBlock` and `EndBlock` events (@alexanderbez) 302 303 ### BUG FIXES 304 305 - [rpc/jsonrpc/server] [\#6191](https://github.com/vipernet-xyz/tm/issues/6191) Correctly unmarshal `RPCRequest` when data is `null` (@melekes) 306 - [p2p] [\#6289](https://github.com/vipernet-xyz/tm/issues/6289) Fix "unknown channels" bug on CustomReactors (@gchaincl) 307 - [light/evidence] Adds logic to handle forward lunatic attacks (@cmwaters) 308 309 ## v0.34.8 310 311 *February 25, 2021* 312 313 This release, in conjunction with [a fix in the Cosmos SDK](https://github.com/cosmos/cosmos-sdk/pull/8641), 314 introduces changes that should mean the logs are much, much quieter. 🎉 315 316 ### IMPROVEMENTS 317 318 - [libs/log] [\#6174](https://github.com/vipernet-xyz/tm/issues/6174) Include timestamp (`ts` field; `time.RFC3339Nano` format) in JSON logger output (@melekes) 319 320 ### BUG FIXES 321 322 - [abci] [\#6124](https://github.com/vipernet-xyz/tm/issues/6124) Fixes a panic condition during callback execution in `ReCheckTx` during high tx load. (@alexanderbez) 323 324 ## v0.34.7 325 326 *February 18, 2021* 327 328 This release fixes a downstream security issue which impacts Cosmos SDK 329 users who are: 330 331 * Using Cosmos SDK v0.40.0 or later, AND 332 * Running validator nodes, AND 333 * Using the file-based `FilePV` implementation for their consensus keys 334 335 Users who fulfill all the above criteria were susceptible to leaking 336 private key material in the logs. All other users are unaffected. 337 338 The root cause was a discrepancy 339 between the Tendermint Core (untyped) logger and the Cosmos SDK (typed) logger: 340 Tendermint Core's logger automatically stringifies Go interfaces whenever possible; 341 however, the Cosmos SDK's logger uses reflection to log the fields within a Go interface. 342 343 The introduction of the typed logger meant that previously un-logged fields within 344 interfaces are now sometimes logged, including the private key material inside the 345 `FilePV` struct. 346 347 Tendermint Core v0.34.7 fixes this issue; however, we strongly recommend that all validators 348 use remote signer implementations instead of `FilePV` in production. 349 350 Thank you to @joe-bowman for his assistance with this vulnerability and a particular 351 shout-out to @marbar3778 for diagnosing it quickly. 352 353 ### BUG FIXES 354 355 - [consensus] [\#6128](https://github.com/vipernet-xyz/tm/pull/6128) Remove privValidator from log call (@tessr) 356 357 ## v0.34.6 358 359 *February 18, 2021* 360 361 _Tendermint Core v0.34.5 and v0.34.6 have been recalled due to build tooling problems._ 362 363 ## v0.34.4 364 365 *February 11, 2021* 366 367 This release includes a fix for a memory leak in the evidence reactor (see #6068, below). 368 All Tendermint clients are recommended to upgrade. 369 Thank you to our friends at Crypto.com for the initial report of this memory leak! 370 371 Special thanks to other external contributors on this release: @yayajacky, @odidev, @laniehei, and @c29r3! 372 373 ### BUG FIXES 374 375 - [light] [\#6022](https://github.com/vipernet-xyz/tm/pull/6022) Fix a bug when the number of validators equals 100 (@melekes) 376 - [light] [\#6026](https://github.com/vipernet-xyz/tm/pull/6026) Fix a bug when height isn't provided for the rpc calls: `/commit` and `/validators` (@cmwaters) 377 - [evidence] [\#6068](https://github.com/vipernet-xyz/tm/pull/6068) Terminate broadcastEvidenceRoutine when peer is stopped (@melekes) 378 379 380 ## v0.34.3 381 382 *January 19, 2021* 383 384 This release includes a fix for a high-severity security vulnerability, 385 a DoS-vector that impacted Tendermint Core v0.34.0-v0.34.2. For more details, see 386 [Security Advisory Mulberry](https://github.com/vipernet-xyz/tm/security/advisories/GHSA-p658-8693-mhvg) 387 or https://nvd.nist.gov/vuln/detail/CVE-2021-21271. 388 389 Tendermint Core v0.34.3 also updates GoGo Protobuf to 1.3.2 in order to pick up the fix for 390 https://nvd.nist.gov/vuln/detail/CVE-2021-3121. 391 392 ### BUG FIXES 393 394 - [evidence] [[security fix]](https://github.com/vipernet-xyz/tm/security/advisories/GHSA-p658-8693-mhvg) Use correct source of evidence time (@cmwaters) 395 - [proto] [\#5886](https://github.com/vipernet-xyz/tm/pull/5889) Bump gogoproto to 1.3.2 (@marbar3778) 396 397 ## v0.34.2 398 399 *January 12, 2021* 400 401 This release fixes a substantial bug in evidence handling where evidence could 402 sometimes be broadcast before the block containing that evidence was fully committed, 403 resulting in some nodes panicking when trying to verify said evidence. 404 405 ### BREAKING CHANGES 406 407 - Go API 408 - [libs/os] [\#5871](https://github.com/vipernet-xyz/tm/issues/5871) `EnsureDir` now propagates IO errors and checks the file type (@erikgrinaker) 409 410 ### BUG FIXES 411 412 - [evidence] [\#5890](https://github.com/vipernet-xyz/tm/pull/5890) Add a buffer to evidence from consensus to avoid broadcasting and proposing evidence before the 413 height of such an evidence has finished (@cmwaters) 414 - [statesync] [\#5889](https://github.com/vipernet-xyz/tm/issues/5889) Set `LastHeightConsensusParamsChanged` when bootstrapping Tendermint state (@cmwaters) 415 416 ## v0.34.1 417 418 *January 6, 2021* 419 420 Special thanks to external contributors on this release: 421 422 @p4u from vocdoni.io reported that the mempool might behave incorrectly under a 423 high load. The consequences can range from pauses between blocks to the peers 424 disconnecting from this node. As a temporary remedy (until the mempool package 425 is refactored), the `max-batch-bytes` was disabled. Transactions will be sent 426 one by one without batching. 427 428 ### BREAKING CHANGES 429 430 - CLI/RPC/Config 431 - [cli] [\#5786](https://github.com/vipernet-xyz/tm/issues/5786) deprecate snake_case commands for hyphen-case (@cmwaters) 432 433 - Go API 434 - [libs/protoio] [\#5868](https://github.com/vipernet-xyz/tm/issues/5868) Return number of bytes read in `Reader.ReadMsg()` (@erikgrinaker) 435 436 ### IMPROVEMENTS 437 438 - [mempool] [\#5813](https://github.com/vipernet-xyz/tm/issues/5813) Add `keep-invalid-txs-in-cache` config option. When set to true, mempool will keep invalid transactions in the cache (@p4u) 439 440 ### BUG FIXES 441 442 - [crypto] [\#5707](https://github.com/vipernet-xyz/tm/issues/5707) Fix infinite recursion in string formatting of Secp256k1 keys (@erikgrinaker) 443 - [mempool] [\#5800](https://github.com/vipernet-xyz/tm/issues/5800) Disable `max-batch-bytes` (@melekes) 444 - [p2p] [\#5868](https://github.com/vipernet-xyz/tm/issues/5868) Fix inbound traffic statistics and rate limiting in `MConnection` (@erikgrinaker) 445 446 ## v0.34.0 447 448 *November 19, 2020* 449 450 Holy smokes, this is a big one! For a more reader-friendly overview of the changes in 0.34.0 451 (and of the changes you need to accommodate as a user), check out [UPGRADING.md](UPGRADING.md). 452 453 Special thanks to external contributors on this release: @james-ray, @fedekunze, @favadi, @alessio, 454 @joe-bowman, @cuonglm, @SadPencil and @dongsam. 455 456 ### BREAKING CHANGES 457 458 - CLI/RPC/Config 459 460 - [config] [\#5315](https://github.com/vipernet-xyz/tm/pull/5315) Rename `prof_laddr` to `pprof_laddr` and move it to `rpc` section (@melekes) 461 - [evidence] [\#4959](https://github.com/vipernet-xyz/tm/pull/4959) Add JSON tags to `DuplicateVoteEvidence` (@marbar3778) 462 - [light] [\#4946](https://github.com/vipernet-xyz/tm/pull/4946) `tendermint lite` command has been renamed to `tendermint light` (@marbar3778) 463 - [privval] [\#4582](https://github.com/vipernet-xyz/tm/pull/4582) `round` in private_validator_state.json is no longer JSON string; instead it is a number (@marbar3778) 464 - [rpc] [\#4792](https://github.com/vipernet-xyz/tm/pull/4792) `/validators` are now sorted by voting power (@melekes) 465 - [rpc] [\#4947](https://github.com/vipernet-xyz/tm/pull/4947) Return an error when `page` pagination param is 0 in `/validators`, `tx_search` (@melekes) 466 - [rpc] [\#5137](https://github.com/vipernet-xyz/tm/pull/5137) JSON tags of `gasWanted` and `gasUsed` in `ResponseCheckTx` and `ResponseDeliverTx` have been made snake_case (`gas_wanted` and `gas_used`) (@marbar3778) 467 - [rpc] [\#5315](https://github.com/vipernet-xyz/tm/pull/5315) Remove `/unsafe_start_cpu_profiler`, `/unsafe_stop_cpu_profiler` and `/unsafe_write_heap_profile`. Please use pprof functionality instead (@melekes) 468 - [rpc/client, rpc/jsonrpc/client] [\#5347](https://github.com/vipernet-xyz/tm/pull/5347) All client methods now accept `context.Context` as 1st param (@melekes) 469 470 - Apps 471 472 - [abci] [\#4704](https://github.com/vipernet-xyz/tm/pull/4704) Add ABCI methods `ListSnapshots`, `LoadSnapshotChunk`, `OfferSnapshot`, and `ApplySnapshotChunk` for state sync snapshots. `ABCIVersion` bumped to 0.17.0. (@erikgrinaker) 473 - [abci] [\#4989](https://github.com/vipernet-xyz/tm/pull/4989) `Proof` within `ResponseQuery` has been renamed to `ProofOps` (@marbar3778) 474 - [abci] [\#5096](https://github.com/vipernet-xyz/tm/pull/5096) `CheckTxType` Protobuf enum names are now uppercase, to follow Protobuf style guide (@erikgrinaker) 475 - [abci] [\#5324](https://github.com/vipernet-xyz/tm/pull/5324) ABCI evidence type is now an enum with two types of possible evidence (@cmwaters) 476 477 - P2P Protocol 478 479 - [blockchain] [\#4637](https://github.com/vipernet-xyz/tm/pull/4637) Migrate blockchain reactor(s) to Protobuf encoding (@marbar3778) 480 - [evidence] [\#4949](https://github.com/vipernet-xyz/tm/pull/4949) Migrate evidence reactor to Protobuf encoding (@marbar3778) 481 - [mempool] [\#4940](https://github.com/vipernet-xyz/tm/pull/4940) Migrate mempool from to Protobuf encoding (@marbar3778) 482 - [mempool] [\#5321](https://github.com/vipernet-xyz/tm/pull/5321) Batch transactions when broadcasting them to peers (@melekes) 483 - `MaxBatchBytes` new config setting defines the max size of one batch. 484 - [p2p/pex] [\#4973](https://github.com/vipernet-xyz/tm/pull/4973) Migrate `p2p/pex` reactor to Protobuf encoding (@marbar3778) 485 - [statesync] [\#4943](https://github.com/vipernet-xyz/tm/pull/4943) Migrate state sync reactor to Protobuf encoding (@marbar3778) 486 487 - Blockchain Protocol 488 489 - [evidence] [\#4725](https://github.com/vipernet-xyz/tm/pull/4725) Remove `Pubkey` from `DuplicateVoteEvidence` (@marbar3778) 490 - [evidence] [\#5499](https://github.com/vipernet-xyz/tm/pull/5449) Cap evidence to a maximum number of bytes (supercedes [\#4780](https://github.com/vipernet-xyz/tm/pull/4780)) (@cmwaters) 491 - [merkle] [\#5193](https://github.com/vipernet-xyz/tm/pull/5193) Header hashes are no longer empty for empty inputs, notably `DataHash`, `EvidenceHash`, and `LastResultsHash` (@erikgrinaker) 492 - [state] [\#4845](https://github.com/vipernet-xyz/tm/pull/4845) Include `GasWanted` and `GasUsed` into `LastResultsHash` (@melekes) 493 - [types] [\#4792](https://github.com/vipernet-xyz/tm/pull/4792) Sort validators by voting power to enable faster commit verification (@melekes) 494 495 - On-disk serialization 496 497 - [state] [\#4679](https://github.com/vipernet-xyz/tm/pull/4679) Migrate state module to Protobuf encoding (@marbar3778) 498 - `BlockStoreStateJSON` is now `BlockStoreState` and is encoded as binary in the database 499 - [store] [\#4778](https://github.com/vipernet-xyz/tm/pull/4778) Migrate store module to Protobuf encoding (@marbar3778) 500 501 - Light client, private validator 502 503 - [light] [\#4964](https://github.com/vipernet-xyz/tm/pull/4964) Migrate light module migration to Protobuf encoding (@marbar3778) 504 - [privval] [\#4985](https://github.com/vipernet-xyz/tm/pull/4985) Migrate `privval` module to Protobuf encoding (@marbar3778) 505 506 - Go API 507 508 - [consensus] [\#4582](https://github.com/vipernet-xyz/tm/pull/4582) RoundState: `Round`, `LockedRound` & `CommitRound` are now `int32` (@marbar3778) 509 - [consensus] [\#4582](https://github.com/vipernet-xyz/tm/pull/4582) HeightVoteSet: `round` is now `int32` (@marbar3778) 510 - [crypto] [\#4721](https://github.com/vipernet-xyz/tm/pull/4721) Remove `SimpleHashFromMap()` and `SimpleProofsFromMap()` (@erikgrinaker) 511 - [crypto] [\#4940](https://github.com/vipernet-xyz/tm/pull/4940) All keys have become `[]byte` instead of `[<size>]byte`. The byte method no longer returns the marshaled value but just the `[]byte` form of the data. (@marbar3778) 512 - [crypto] [\#4988](https://github.com/vipernet-xyz/tm/pull/4988) Removal of key type multisig (@marbar3778) 513 - The key has been moved to the [Cosmos-SDK](https://github.com/cosmos/cosmos-sdk/blob/master/crypto/types/multisig/multisignature.go) 514 - [crypto] [\#4989](https://github.com/vipernet-xyz/tm/pull/4989) Remove `Simple` prefixes from `SimpleProof`, `SimpleValueOp` & `SimpleProofNode`. (@marbar3778) 515 - `merkle.Proof` has been renamed to `ProofOps`. 516 - Protobuf messages `Proof` & `ProofOp` has been moved to `proto/crypto/merkle` 517 - `SimpleHashFromByteSlices` has been renamed to `HashFromByteSlices` 518 - `SimpleHashFromByteSlicesIterative` has been renamed to `HashFromByteSlicesIterative` 519 - `SimpleProofsFromByteSlices` has been renamed to `ProofsFromByteSlices` 520 - [crypto] [\#4941](https://github.com/vipernet-xyz/tm/pull/4941) Remove suffixes from all keys. (@marbar3778) 521 - ed25519: type `PrivKeyEd25519` is now `PrivKey` 522 - ed25519: type `PubKeyEd25519` is now `PubKey` 523 - secp256k1: type`PrivKeySecp256k1` is now `PrivKey` 524 - secp256k1: type`PubKeySecp256k1` is now `PubKey` 525 - sr25519: type `PrivKeySr25519` is now `PrivKey` 526 - sr25519: type `PubKeySr25519` is now `PubKey` 527 - [crypto] [\#5214](https://github.com/vipernet-xyz/tm/pull/5214) Change `GenPrivKeySecp256k1` to `GenPrivKeyFromSecret` to be consistent with other keys (@marbar3778) 528 - [crypto] [\#5236](https://github.com/vipernet-xyz/tm/pull/5236) `VerifyBytes` is now `VerifySignature` on the `crypto.PubKey` interface (@marbar3778) 529 - [evidence] [\#5361](https://github.com/vipernet-xyz/tm/pull/5361) Add LightClientAttackEvidence and change evidence interface (@cmwaters) 530 - [libs] [\#4831](https://github.com/vipernet-xyz/tm/pull/4831) Remove `Bech32` pkg from Tendermint. This pkg now lives in the [cosmos-sdk](https://github.com/cosmos/cosmos-sdk/tree/4173ea5ebad906dd9b45325bed69b9c655504867/types/bech32) (@marbar3778) 531 - [light] [\#4946](https://github.com/vipernet-xyz/tm/pull/4946) Rename `lite2` pkg to `light`. Remove `lite` implementation. (@marbar3778) 532 - [light] [\#5347](https://github.com/vipernet-xyz/tm/pull/5347) `NewClient`, `NewHTTPClient`, `VerifyHeader` and `VerifyLightBlockAtHeight` now accept `context.Context` as 1st param (@melekes) 533 - [merkle] [\#5193](https://github.com/vipernet-xyz/tm/pull/5193) `HashFromByteSlices` and `ProofsFromByteSlices` now return a hash for empty inputs, following RFC6962 (@erikgrinaker) 534 - [proto] [\#5025](https://github.com/vipernet-xyz/tm/pull/5025) All proto files have been moved to `/proto` directory. (@marbar3778) 535 - Using the recommended the file layout from buf, [see here for more info](https://buf.build/docs/lint-checkers#file_layout) 536 - [rpc/client] [\#4947](https://github.com/vipernet-xyz/tm/pull/4947) `Validators`, `TxSearch` `page`/`per_page` params become pointers (@melekes) 537 - `UnconfirmedTxs` `limit` param is a pointer 538 - [rpc/jsonrpc/server] [\#5141](https://github.com/vipernet-xyz/tm/pull/5141) Remove `WriteRPCResponseArrayHTTP` (use `WriteRPCResponseHTTP` instead) (@melekes) 539 - [state] [\#4679](https://github.com/vipernet-xyz/tm/pull/4679) `TxResult` is a Protobuf type defined in `abci` types directory (@marbar3778) 540 - [state] [\#5191](https://github.com/vipernet-xyz/tm/pull/5191) Add `State.InitialHeight` field to record initial block height, must be `1` (not `0`) to start from 1 (@erikgrinaker) 541 - [state] [\#5231](https://github.com/vipernet-xyz/tm/pull/5231) `LoadStateFromDBOrGenesisFile()` and `LoadStateFromDBOrGenesisDoc()` no longer saves the state in the database if not found, the genesis state is simply returned (@erikgrinaker) 542 - [state] [\#5348](https://github.com/vipernet-xyz/tm/pull/5348) Define an Interface for the state store. (@marbar3778) 543 - [types] [\#4939](https://github.com/vipernet-xyz/tm/pull/4939) `SignedMsgType` has moved to a Protobuf enum types (@marbar3778) 544 - [types] [\#4962](https://github.com/vipernet-xyz/tm/pull/4962) `ConsensusParams`, `BlockParams`, `EvidenceParams`, `ValidatorParams` & `HashedParams` are now Protobuf types (@marbar3778) 545 - [types] [\#4852](https://github.com/vipernet-xyz/tm/pull/4852) Vote & Proposal `SignBytes` is now func `VoteSignBytes` & `ProposalSignBytes` (@marbar3778) 546 - [types] [\#4798](https://github.com/vipernet-xyz/tm/pull/4798) Simplify `VerifyCommitTrusting` func + remove extra validation (@melekes) 547 - [types] [\#4845](https://github.com/vipernet-xyz/tm/pull/4845) Remove `ABCIResult` (@melekes) 548 - [types] [\#5029](https://github.com/vipernet-xyz/tm/pull/5029) Rename all values from `PartsHeader` to `PartSetHeader` to have consistency (@marbar3778) 549 - [types] [\#4939](https://github.com/vipernet-xyz/tm/pull/4939) `Total` in `Parts` & `PartSetHeader` has been changed from a `int` to a `uint32` (@marbar3778) 550 - [types] [\#4939](https://github.com/vipernet-xyz/tm/pull/4939) Vote: `ValidatorIndex` & `Round` are now `int32` (@marbar3778) 551 - [types] [\#4939](https://github.com/vipernet-xyz/tm/pull/4939) Proposal: `POLRound` & `Round` are now `int32` (@marbar3778) 552 - [types] [\#4939](https://github.com/vipernet-xyz/tm/pull/4939) Block: `Round` is now `int32` (@marbar3778) 553 554 ### FEATURES 555 556 - [abci] [\#5031](https://github.com/vipernet-xyz/tm/pull/5031) Add `AppVersion` to consensus parameters (@james-ray) 557 - This makes it possible to update your ABCI application version via `EndBlock` response 558 - [abci] [\#5174](https://github.com/vipernet-xyz/tm/pull/5174) Remove `MockEvidence` in favor of testing with actual evidence types (`DuplicateVoteEvidence` & `LightClientAttackEvidence`) (@cmwaters) 559 - [abci] [\#5191](https://github.com/vipernet-xyz/tm/pull/5191) Add `InitChain.InitialHeight` field giving the initial block height (@erikgrinaker) 560 - [abci] [\#5227](https://github.com/vipernet-xyz/tm/pull/5227) Add `ResponseInitChain.app_hash` which is recorded in genesis block (@erikgrinaker) 561 - [config] [\#5147](https://github.com/vipernet-xyz/tm/pull/5147) Add `--consensus.double_sign_check_height` flag and `DoubleSignCheckHeight` config variable. See [ADR-51](https://github.com/vipernet-xyz/tm/blob/main/docs/architecture/adr-051-double-signing-risk-reduction.md) (@dongsam) 562 - [db] [\#5233](https://github.com/vipernet-xyz/tm/pull/5233) Add support for `badgerdb` database backend (@erikgrinaker) 563 - [evidence] [\#4532](https://github.com/vipernet-xyz/tm/pull/4532) Handle evidence from light clients (@melekes) 564 - [evidence] [#4821](https://github.com/vipernet-xyz/tm/pull/4821) Amnesia (light client attack) evidence can be detected, verified and committed (@cmwaters) 565 - [genesis] [\#5191](https://github.com/vipernet-xyz/tm/pull/5191) Add `initial_height` field to specify the initial chain height (defaults to `1`) (@erikgrinaker) 566 - [libs/math] [\#5665](https://github.com/vipernet-xyz/tm/pull/5665) Make fractions unsigned integers (uint64) (@cmwaters) 567 - [light] [\#5298](https://github.com/vipernet-xyz/tm/pull/5298) Morph validator set and signed header into light block (@cmwaters) 568 - [p2p] [\#4981](https://github.com/vipernet-xyz/tm/pull/4981) Expose `SaveAs` func on NodeKey (@melekes) 569 - [privval] [\#5239](https://github.com/vipernet-xyz/tm/pull/5239) Add `chainID` to requests from client. (@marbar3778) 570 - [rpc] [\#4532](https://github.com/vipernet-xyz/tm/pull/4923) Support `BlockByHash` query (@fedekunze) 571 - [rpc] [\#4979](https://github.com/vipernet-xyz/tm/pull/4979) Support EXISTS operator in `/tx_search` query (@melekes) 572 - [rpc] [\#5017](https://github.com/vipernet-xyz/tm/pull/5017) Add `/check_tx` endpoint to check transactions without executing them or adding them to the mempool (@melekes) 573 - [rpc] [\#5108](https://github.com/vipernet-xyz/tm/pull/5108) Subscribe using the websocket for new evidence events (@cmwaters) 574 - [statesync] Add state sync support, where a new node can be rapidly bootstrapped by fetching state snapshots from peers instead of replaying blocks. See the `[statesync]` config section. 575 - [evidence] [\#5361](https://github.com/vipernet-xyz/tm/pull/5361) Add LightClientAttackEvidence and refactor evidence lifecycle - for more information see [ADR-059](https://github.com/vipernet-xyz/tm/blob/main/docs/architecture/adr-059-evidence-composition-and-lifecycle.md) (@cmwaters) 576 577 ### IMPROVEMENTS 578 579 - [blockchain] [\#5278](https://github.com/vipernet-xyz/tm/pull/5278) Verify only +2/3 of the signatures in a block when fast syncing. (@marbar3778) 580 - [consensus] [\#4578](https://github.com/vipernet-xyz/tm/pull/4578) Attempt to repair the consensus WAL file (`data/cs.wal/wal`) automatically in case of corruption (@alessio) 581 - The original WAL file will be backed up to `data/cs.wal/wal.CORRUPTED`. 582 - [consensus] [\#5143](https://github.com/vipernet-xyz/tm/pull/5143) Only call `privValidator.GetPubKey` once per block (@melekes) 583 - [evidence] [\#4722](https://github.com/vipernet-xyz/tm/pull/4722) Consolidate evidence store and pool types to improve evidence DB (@cmwaters) 584 - [evidence] [\#4839](https://github.com/vipernet-xyz/tm/pull/4839) Reject duplicate evidence from being proposed (@cmwaters) 585 - [evidence] [\#5219](https://github.com/vipernet-xyz/tm/pull/5219) Change the source of evidence time to block time (@cmwaters) 586 - [libs] [\#5126](https://github.com/vipernet-xyz/tm/pull/5126) Add a sync package which wraps sync.(RW)Mutex & deadlock.(RW)Mutex and use a build flag (deadlock) in order to enable deadlock checking (@marbar3778) 587 - [light] [\#4935](https://github.com/vipernet-xyz/tm/pull/4935) Fetch and compare a new header with witnesses in parallel (@melekes) 588 - [light] [\#4929](https://github.com/vipernet-xyz/tm/pull/4929) Compare header with witnesses only when doing bisection (@melekes) 589 - [light] [\#4916](https://github.com/vipernet-xyz/tm/pull/4916) Validate basic for inbound validator sets and headers before further processing them (@cmwaters) 590 - [mempool] Add RemoveTxByKey() exported function for custom mempool cleaning (@p4u) 591 - [p2p/conn] [\#4795](https://github.com/vipernet-xyz/tm/pull/4795) Return err on `signChallenge()` instead of panic 592 - [privval] [\#5437](https://github.com/vipernet-xyz/tm/pull/5437) `NewSignerDialerEndpoint` can now be given `SignerServiceEndpointOption` (@erikgrinaker) 593 - [rpc] [\#4968](https://github.com/vipernet-xyz/tm/pull/4968) JSON encoding is now handled by `libs/json`, not Amino (@erikgrinaker) 594 - [rpc] [\#5293](https://github.com/vipernet-xyz/tm/pull/5293) `/dial_peers` has added `private` and `unconditional` as parameters. (@marbar3778) 595 - [state] [\#4781](https://github.com/vipernet-xyz/tm/pull/4781) Export `InitStateVersion` for the initial state version (@erikgrinaker) 596 - [txindex] [\#4466](https://github.com/vipernet-xyz/tm/pull/4466) Allow to index an event at runtime (@favadi) 597 - `abci.EventAttribute` replaces `KV.Pair` 598 - [types] [\#4905](https://github.com/vipernet-xyz/tm/pull/4905) Add `ValidateBasic` to validator and validator set (@cmwaters) 599 - [types] [\#5340](https://github.com/vipernet-xyz/tm/pull/5340) Add check in `Header.ValidateBasic()` for block protocol version (@marbar3778) 600 - [types] [\#5490](https://github.com/vipernet-xyz/tm/pull/5490) Use `Commit` and `CommitSig` max sizes instead of vote max size to calculate the maximum block size. (@cmwaters) 601 602 603 ### BUG FIXES 604 605 - [abci/grpc] [\#5520](https://github.com/vipernet-xyz/tm/pull/5520) Return async responses in order, to avoid mempool panics. (@erikgrinaker) 606 - [blockchain/v2] [\#4971](https://github.com/vipernet-xyz/tm/pull/4971) Correctly set block store base in status responses (@erikgrinaker) 607 - [blockchain/v2] [\#5499](https://github.com/vipernet-xyz/tm/pull/5499) Fix "duplicate block enqueued by processor" panic (@melekes) 608 - [blockchain/v2] [\#5530](https://github.com/vipernet-xyz/tm/pull/5530) Fix out of order block processing panic (@melekes) 609 - [blockchain/v2] [\#5553](https://github.com/vipernet-xyz/tm/pull/5553) Make the removal of an already removed peer a noop (@melekes) 610 - [consensus] [\#4895](https://github.com/vipernet-xyz/tm/pull/4895) Cache the address of the validator to reduce querying a remote KMS (@joe-bowman) 611 - [consensus] [\#4970](https://github.com/vipernet-xyz/tm/pull/4970) Don't allow `LastCommitRound` to be negative (@cuonglm) 612 - [consensus] [\#5329](https://github.com/vipernet-xyz/tm/pull/5329) Fix wrong proposer schedule for validators returned by `InitChain` (@erikgrinaker) 613 - [docker] [\#5385](https://github.com/vipernet-xyz/tm/pull/5385) Fix incorrect `time_iota_ms` default setting causing block timestamp drift (@erikgrinaker) 614 - [evidence] [\#5170](https://github.com/vipernet-xyz/tm/pull/5170) Change ABCI evidence time to the time the infraction happened not the time the evidence was committed on the block (@cmwaters) 615 - [evidence] [\#5610](https://github.com/vipernet-xyz/tm/pull/5610) Make it possible for ABCI evidence to be formed from Tendermint evidence (@cmwaters) 616 - [libs/rand] [\#5215](https://github.com/vipernet-xyz/tm/pull/5215) Fix out-of-memory error on unexpected argument of Str() (@SadPencil) 617 - [light] [\#5307](https://github.com/vipernet-xyz/tm/pull/5307) Persist correct proposer priority in light client validator sets (@cmwaters) 618 - [p2p] [\#5136](https://github.com/vipernet-xyz/tm/pull/5136) Fix error for peer with the same ID but different IPs (@valardragon) 619 - [privval] [\#5638](https://github.com/vipernet-xyz/tm/pull/5638) Increase read/write timeout to 5s and calculate ping interval based on it (@JoeKash) 620 - [proxy] [\#5078](https://github.com/vipernet-xyz/tm/pull/5078) Force Tendermint to exit when ABCI app crashes (@melekes) 621 - [rpc] [\#5660](https://github.com/vipernet-xyz/tm/pull/5660) Set `application/json` as the `Content-Type` header in RPC responses. (@alexanderbez) 622 - [store] [\#5382](https://github.com/vipernet-xyz/tm/pull/5382) Fix race conditions when loading/saving/pruning blocks (@erikgrinaker) 623 624 ## v0.33.8 625 626 *August 11, 2020* 627 628 ### Go security update 629 630 Go reported a security vulnerability that affected the `encoding/binary` package. The most recent binary for tendermint is using 1.14.6, for this 631 reason the Tendermint engineering team has opted to conduct a release to aid users in using the correct version of Go. Read more about the security issue [here](https://github.com/golang/go/issues/40618). 632 633 634 ## v0.33.7 635 636 *August 4, 2020* 637 638 ### BUG FIXES: 639 640 - [go] Build release binary using Go 1.14.4, to avoid halt caused by Go 1.14.1 (https://github.com/golang/go/issues/38223) 641 - [privval] [\#5140](https://github.com/vipernet-xyz/tm/pull/5140) `RemoteSignerError` from remote signers are no longer retried (@melekes) 642 643 644 ## v0.33.6 645 646 *July 2, 2020* 647 648 This security release fixes: 649 650 ### Denial of service 651 652 Tendermint 0.33.0 and above allow block proposers to include signatures for the 653 wrong block. This may happen naturally if you start a network, have it run for 654 some time and restart it **without changing the chainID**. (It is a 655 [misconfiguration](https://docs.tendermint.com/v0.33/tendermint-core/using-tendermint.html) 656 to reuse chainIDs.) Correct block proposers will accidentally include signatures 657 for the wrong block if they see these signatures, and then commits won't validate, 658 making all proposed blocks invalid. A malicious validator (even with a minimal 659 amount of stake) can use this vulnerability to completely halt the network. 660 661 Tendermint 0.33.6 checks all the signatures are for the block with +2/3 662 majority before creating a commit. 663 664 ### False Witness 665 666 Tendermint 0.33.1 and above are no longer fully verifying commit signatures 667 during block execution - they stop after +2/3. This means proposers can propose 668 blocks that contain valid +2/3 signatures and then the rest of the signatures 669 can be whatever they want. They can claim that all the other validators signed 670 just by including a CommitSig with arbitrary signature data. While this doesn't 671 seem to impact safety of Tendermint per se, it means that Commits may contain a 672 lot of invalid data. 673 674 _This was already true of blocks, since they could include invalid txs filled 675 with garbage, but in that case the application knew that they are invalid and 676 could punish the proposer. But since applications didn't--and don't-- 677 verify commit signatures directly (they trust Tendermint to do that), 678 they won't be able to detect it._ 679 680 This can impact incentivization logic in the application that depends on the 681 LastCommitInfo sent in BeginBlock, which includes which validators signed. For 682 instance, Gaia incentivizes proposers with a bonus for including more than +2/3 683 of the signatures. But a proposer can now claim that bonus just by including 684 arbitrary data for the final -1/3 of validators without actually waiting for 685 their signatures. There may be other tricks that can be played because of this. 686 687 Tendermint 0.33.6 verifies all the signatures during block execution. 688 689 _Please note that the light client does not check nil votes and exits as soon 690 as 2/3+ of the signatures are checked._ 691 692 **All clients are recommended to upgrade.** 693 694 Special thanks to @njmurarka at Bluzelle Networks for reporting this. 695 696 ### SECURITY: 697 698 - [consensus] Do not allow signatures for a wrong block in commits (@ebuchman) 699 - [consensus] Verify all the signatures during block execution (@melekes) 700 701 **Please note that the fix for the False Witness issue renames the `VerifyCommitTrusting` 702 function to `VerifyCommitLightTrusting`. If you were relying on the light client, you may 703 need to update your code.** 704 705 ## v0.33.5 706 707 *May 28, 2020* 708 709 Special thanks to external contributors on this release: @tau3, 710 711 ### BREAKING CHANGES: 712 713 - Go API 714 715 - [privval] [\#4744](https://github.com/vipernet-xyz/tm/pull/4744) Remove deprecated `OldFilePV` (@melekes) 716 - [mempool] [\#4759](https://github.com/vipernet-xyz/tm/pull/4759) Modify `Mempool#InitWAL` to return an error (@melekes) 717 - [node] [\#4832](https://github.com/vipernet-xyz/tm/pull/4832) `ConfigureRPC` returns an error (@melekes) 718 - [rpc] [\#4836](https://github.com/vipernet-xyz/tm/pull/4836) Overhaul `lib` folder (@melekes) 719 Move lib/ folder to jsonrpc/. 720 Rename: 721 rpc package -> jsonrpc package 722 rpcclient package -> client package 723 rpcserver package -> server package 724 JSONRPCClient to Client 725 JSONRPCRequestBatch to RequestBatch 726 JSONRPCCaller to Caller 727 StartHTTPServer to Serve 728 StartHTTPAndTLSServer to ServeTLS 729 NewURIClient to NewURI 730 NewJSONRPCClient to New 731 NewJSONRPCClientWithHTTPClient to NewWithHTTPClient 732 NewWSClient to NewWS 733 Unexpose ResponseWriterWrapper 734 Remove unused http_params.go 735 736 737 ### FEATURES: 738 739 - [pex] [\#4439](https://github.com/vipernet-xyz/tm/pull/4439) Use highwayhash for pex buckets (@tau3) 740 741 ### IMPROVEMENTS: 742 743 - [abci/server] [\#4719](https://github.com/vipernet-xyz/tm/pull/4719) Print panic & stack trace to STDERR if logger is not set (@melekes) 744 - [types] [\#4638](https://github.com/vipernet-xyz/tm/pull/4638) Implement `Header#ValidateBasic` (@alexanderbez) 745 - [buildsystem] [\#4378](https://github.com/vipernet-xyz/tm/pull/4738) Replace build_c and install_c with TENDERMINT_BUILD_OPTIONS parsing. The following options are available: 746 - nostrip: don't strip debugging symbols nor DWARF tables. 747 - cleveldb: use cleveldb as db backend instead of goleveldb. 748 - race: pass -race to go build and enable data race detection. 749 - [mempool] [\#4759](https://github.com/vipernet-xyz/tm/pull/4759) Allow ReapX and CheckTx functions to run in parallel (@melekes) 750 - [rpc/core] [\#4844](https://github.com/vipernet-xyz/tm/pull/4844) Do not lock consensus state in `/validators`, `/consensus_params` and `/status` (@melekes) 751 752 ### BUG FIXES: 753 754 - [blockchain/v2] [\#4761](https://github.com/vipernet-xyz/tm/pull/4761) Fix excessive CPU usage caused by spinning on closed channels (@erikgrinaker) 755 - [blockchain/v2] Respect `fast_sync` option (@erikgrinaker) 756 - [light] [\#4741](https://github.com/vipernet-xyz/tm/pull/4741) Correctly return `ErrSignedHeaderNotFound` and `ErrValidatorSetNotFound` on corresponding RPC errors (@erikgrinaker) 757 - [rpc] [\#4805](https://github.com/vipernet-xyz/tm/issues/4805) Attempt to handle panics during panic recovery (@erikgrinaker) 758 - [types] [\#4764](https://github.com/vipernet-xyz/tm/pull/4764) Return an error if voting power overflows in `VerifyCommitTrusting` (@melekes) 759 - [privval] [\#4812](https://github.com/vipernet-xyz/tm/pull/4812) Retry `GetPubKey/SignVote/SignProposal` a few times before returning an error (@melekes) 760 - [p2p] [\#4847](https://github.com/vipernet-xyz/tm/pull/4847) Return masked IP (not the actual IP) in addrbook#groupKey (@melekes) 761 762 ## v0.33.4 763 764 - Nodes are no longer guaranteed to contain all blocks up to the latest height. The ABCI app can now control which blocks to retain through the ABCI field `ResponseCommit.retain_height`, all blocks and associated data below this height will be removed. 765 766 *April 21, 2020* 767 768 Special thanks to external contributors on this release: @whylee259, @greg-szabo 769 770 ### BREAKING CHANGES: 771 772 - Go API 773 774 - [lite2] [\#4616](https://github.com/vipernet-xyz/tm/pull/4616) Make `maxClockDrift` an option `Verify/VerifyAdjacent/VerifyNonAdjacent` now accept `maxClockDrift time.Duration` (@melekes). 775 - [rpc/client] [\#4628](https://github.com/vipernet-xyz/tm/pull/4628) Split out HTTP and local clients into `http` and `local` packages (@erikgrinaker). 776 777 ### FEATURES: 778 779 - [abci] [\#4588](https://github.com/vipernet-xyz/tm/issues/4588) Add `ResponseCommit.retain_height` field, which will automatically remove blocks below this height. This bumps the ABCI version to 0.16.2 (@erikgrinaker). 780 - [cmd] [\#4665](https://github.com/vipernet-xyz/tm/pull/4665) New `tendermint completion` command to generate Bash/Zsh completion scripts (@alessio). 781 - [rpc] [\#4588](https://github.com/vipernet-xyz/tm/issues/4588) Add `/status` response fields for the earliest block available on the node (@erikgrinaker). 782 - [rpc] [\#4611](https://github.com/vipernet-xyz/tm/pull/4611) Add `codespace` to `ResultBroadcastTx` (@whylee259). 783 784 ### IMPROVEMENTS: 785 786 - [all] [\#4608](https://github.com/vipernet-xyz/tm/pull/4608) Give reactors descriptive names when they're initialized (@tessr). 787 - [blockchain] [\#4588](https://github.com/vipernet-xyz/tm/issues/4588) Add `Base` to blockchain reactor P2P messages `StatusRequest` and `StatusResponse` (@erikgrinaker). 788 - [Docker] [\#4569](https://github.com/vipernet-xyz/tm/issues/4569) Default configuration added to docker image (you can still mount your own config the same way) (@greg-szabo). 789 - [example/kvstore] [\#4588](https://github.com/vipernet-xyz/tm/issues/4588) Add `RetainBlocks` option to control block retention (@erikgrinaker). 790 - [evidence] [\#4632](https://github.com/vipernet-xyz/tm/pull/4632) Inbound evidence checked if already existing (@cmwaters). 791 - [lite2] [\#4575](https://github.com/vipernet-xyz/tm/pull/4575) Use bisection for within-range verification (@cmwaters). 792 - [lite2] [\#4562](https://github.com/vipernet-xyz/tm/pull/4562) Cache headers when using bisection (@cmwaters). 793 - [p2p] [\#4548](https://github.com/vipernet-xyz/tm/pull/4548) Add ban list to address book (@cmwaters). 794 - [privval] [\#4534](https://github.com/vipernet-xyz/tm/issues/4534) Add `error` as a return value on`GetPubKey()` (@marbar3778). 795 - [p2p] [\#4621](https://github.com/vipernet-xyz/tm/issues/4621) Ban peers when messages are unsolicited or too frequent (@cmwaters). 796 - [rpc] [\#4703](https://github.com/vipernet-xyz/tm/pull/4703) Add `count` and `total` to `/validators` response (@melekes). 797 - [tools] [\#4615](https://github.com/vipernet-xyz/tm/issues/4615) Allow developers to use Docker to generate proto stubs, via `make proto-gen-docker` (@erikgrinaker). 798 799 ### BUG FIXES: 800 801 - [rpc] [\#4568](https://github.com/vipernet-xyz/tm/issues/4568) Fix panic when `Subscribe` is called, but HTTP client is not running. `Subscribe`, `Unsubscribe(All)` methods return an error now (@melekes). 802 803 ## v0.33.3 804 805 *April 6, 2020* 806 807 This security release fixes: 808 809 ### Denial of service 1 810 811 Tendermint 0.33.2 and earlier does not limit P2P connection requests number. 812 For each p2p connection, Tendermint allocates ~0.5MB. Even though this 813 memory is garbage collected once the connection is terminated (due to duplicate 814 IP or reaching a maximum number of inbound peers), temporary memory spikes can 815 lead to OOM (Out-Of-Memory) exceptions. 816 817 Tendermint 0.33.3 (and 0.32.10) limits the total number of P2P incoming 818 connection requests to to `p2p.max_num_inbound_peers + 819 len(p2p.unconditional_peer_ids)`. 820 821 Notes: 822 823 - Tendermint does not rate limit P2P connection requests per IP (an attacker 824 can saturate all the inbound slots); 825 - Tendermint does not rate limit HTTP(S) requests. If you expose any RPC 826 endpoints to the public, please make sure to put in place some protection 827 (https://www.nginx.com/blog/rate-limiting-nginx/). We may implement this in 828 the future ([\#1696](https://github.com/vipernet-xyz/tm/issues/1696)). 829 830 ### Denial of service 2 831 832 Tendermint 0.33.2 and earlier does not reclaim `activeID` of a peer after it's 833 removed in `Mempool` reactor. This does not happen all the time. It only 834 happens when a connection fails (for any reason) before the Peer is created and 835 added to all reactors. `RemovePeer` is therefore called before `AddPeer`, which 836 leads to always growing memory (`activeIDs` map). The `activeIDs` map has a 837 maximum size of 65535 and the node will panic if this map reaches the maximum. 838 An attacker can create a lot of connection attempts (exploiting Denial of 839 service 1), which ultimately will lead to the node panicking. 840 841 Tendermint 0.33.3 (and 0.32.10) claims `activeID` for a peer in `InitPeer`, 842 which is executed before `MConnection` is started. 843 844 Notes: 845 846 - `InitPeer` function was added to all reactors to combat a similar issue - 847 [\#3338](https://github.com/vipernet-xyz/tm/issues/3338); 848 - Denial of service 2 is independent of Denial of service 1 and can be executed 849 without it. 850 851 **All clients are recommended to upgrade** 852 853 Special thanks to [fudongbai](https://hackerone.com/fudongbai) for finding 854 and reporting this. 855 856 ### SECURITY: 857 858 - [mempool] Reserve IDs in InitPeer instead of AddPeer (@tessr) 859 - [p2p] Limit the number of incoming connections (@melekes) 860 861 ## v0.33.2 862 863 *March 11, 2020* 864 865 Special thanks to external contributors on this release: 866 @antho1404, @michaelfig, @gterzian, @tau3, @Shivani912 867 868 ### BREAKING CHANGES: 869 870 - CLI/RPC/Config 871 - [cli] [\#4505](https://github.com/vipernet-xyz/tm/pull/4505) `tendermint lite` sub-command new syntax (@melekes): 872 `lite cosmoshub-3 -p 52.57.29.196:26657 -w public-seed-node.cosmoshub.certus.one:26657 873 --height 962118 --hash 28B97BE9F6DE51AC69F70E0B7BFD7E5C9CD1A595B7DC31AFF27C50D4948` 874 875 - Go API 876 - [lite2] [\#4535](https://github.com/vipernet-xyz/tm/pull/4535) Remove `Start/Stop` (@melekes) 877 - [lite2] [\#4469](https://github.com/vipernet-xyz/tm/issues/4469) Remove `RemoveNoLongerTrustedHeaders` and `RemoveNoLongerTrustedHeadersPeriod` option (@cmwaters) 878 - [lite2] [\#4473](https://github.com/vipernet-xyz/tm/issues/4473) Return height as a 2nd param in `TrustedValidatorSet` (@melekes) 879 - [lite2] [\#4536](https://github.com/vipernet-xyz/tm/pull/4536) `Update` returns a signed header (1st param) (@melekes) 880 881 882 ### IMPROVEMENTS: 883 884 - [blockchain/v2] [\#4361](https://github.com/vipernet-xyz/tm/pull/4361) Add reactor (@brapse) 885 - [cmd] [\#4515](https://github.com/vipernet-xyz/tm/issues/4515) Change `tendermint debug dump` sub-command archives filename's format (@melekes) 886 - [consensus] [\#3583](https://github.com/vipernet-xyz/tm/issues/3583) Reduce `non-deterministic signature` log noise (@tau3) 887 - [examples/kvstore] [\#4507](https://github.com/vipernet-xyz/tm/issues/4507) ABCI query now returns the proper height (@erikgrinaker) 888 - [lite2] [\#4462](https://github.com/vipernet-xyz/tm/issues/4462) Add `NewHTTPClient` and `NewHTTPClientFromTrustedStore` (@cmwaters) 889 - [lite2] [\#4329](https://github.com/vipernet-xyz/tm/issues/4329) modified bisection to loop (@cmwaters) 890 - [lite2] [\#4385](https://github.com/vipernet-xyz/tm/issues/4385) Disconnect from bad nodes (@melekes) 891 - [lite2] [\#4398](https://github.com/vipernet-xyz/tm/issues/4398) Add `VerifyAdjacent` and `VerifyNonAdjacent` funcs (@cmwaters) 892 - [lite2] [\#4426](https://github.com/vipernet-xyz/tm/issues/4426) Don't save intermediate headers (@cmwaters) 893 - [lite2] [\#4464](https://github.com/vipernet-xyz/tm/issues/4464) Cross-check first header (@cmwaters) 894 - [lite2] [\#4470](https://github.com/vipernet-xyz/tm/issues/4470) Fix inconsistent header-validatorset pairing (@melekes) 895 - [lite2] [\#4488](https://github.com/vipernet-xyz/tm/issues/4488) Allow local clock drift -10 sec. (@melekes) 896 - [p2p] [\#4449](https://github.com/vipernet-xyz/tm/pull/4449) Use `curve25519.X25519()` instead of `ScalarMult` (@erikgrinaker) 897 - [types] [\#4417](https://github.com/vipernet-xyz/tm/issues/4417) **VerifyCommitX() functions should return as soon as +2/3 threshold is reached** (@alessio). 898 - [libs/kv] [\#4542](https://github.com/vipernet-xyz/tm/pull/4542) remove unused type KI64Pair (@tessr) 899 900 ### BUG FIXES: 901 902 - [cmd] [\#4303](https://github.com/vipernet-xyz/tm/issues/4303) Show useful error when Tendermint is not initialized (@melekes) 903 - [cmd] [\#4515](https://github.com/vipernet-xyz/tm/issues/4515) **Fix `tendermint debug kill` sub-command** (@melekes) 904 - [rpc] [\#3935](https://github.com/vipernet-xyz/tm/issues/3935) **Create buffered subscriptions on `/subscribe`** (@melekes) 905 - [rpc] [\#4375](https://github.com/vipernet-xyz/tm/issues/4375) Stop searching for txs in `/tx_search` upon client timeout (@gterzian) 906 - [rpc] [\#4406](https://github.com/vipernet-xyz/tm/pull/4406) Fix issue with multiple subscriptions on the websocket (@antho1404) 907 - [rpc] [\#4432](https://github.com/vipernet-xyz/tm/issues/4432) Fix `/tx_search` pagination with ordered results (@erikgrinaker) 908 - [rpc] [\#4492](https://github.com/vipernet-xyz/tm/issues/4492) Keep the original subscription "id" field when new RPCs come in (@michaelfig) 909 910 911 ## v0.33.1 912 913 *Feburary 13, 2020* 914 915 Special thanks to external contributors on this release: 916 @princesinha19 917 918 ### FEATURES: 919 920 - [rpc] [\#3333](https://github.com/vipernet-xyz/tm/issues/3333) Add `order_by` to `/tx_search` endpoint, allowing to change default ordering from asc to desc (@princesinha19) 921 922 ### IMPROVEMENTS: 923 924 - [proto] [\#4369](https://github.com/vipernet-xyz/tm/issues/4369) Add [buf](https://buf.build/) for usage with linting and checking if there are breaking changes with the master branch. 925 - [proto] [\#4369](https://github.com/vipernet-xyz/tm/issues/4369) Add `make proto-gen` cmd to generate proto stubs outside of GOPATH. 926 927 ### BUG FIXES: 928 929 - [node] [\#4311](https://github.com/vipernet-xyz/tm/issues/4311) Use `GRPCMaxOpenConnections` when creating the gRPC server, not `MaxOpenConnections` 930 - [rpc] [\#4319](https://github.com/vipernet-xyz/tm/issues/4319) Check `BlockMeta` is not nil in `/block` & `/block_by_hash` 931 932 ## v0.33 933 934 Special thanks to external contributors on this release: @mrekucci, @PSalant726, @princesinha19, @greg-szabo, @dongsam, @cuonglm, @jgimeno, @yenkhoon 935 936 *January 14, 2020* 937 938 This release contains breaking changes to the `Block#Header`, specifically 939 `NumTxs` and `TotalTxs` were removed (\#2521). Here's how this change affects 940 different modules: 941 942 - apps: it breaks the ABCI header field numbering 943 - state: it breaks the format of `State` on disk 944 - RPC: all RPC requests which expose the header broke 945 - Go API: the `Header` broke 946 - P2P: since blocks go over the wire, technically the P2P protocol broke 947 948 Also, blocks are significantly smaller 🔥 because we got rid of the redundant 949 information in `Block#LastCommit`. `Commit` now mainly consists of a signature 950 and a validator address plus a timestamp. Note we may remove the validator 951 address & timestamp fields in the future (see ADR-25). 952 953 `lite2` package has been added to solve `lite` issues and introduce weak 954 subjectivity interface. Refer to the [spec](https://github.com/vipernet-xyz/tm/blob/v0.34.x/spec/consensus/light-client.md) for complete details. 955 `lite` package is now deprecated and will be removed in v0.34 release. 956 957 ### BREAKING CHANGES: 958 959 - CLI/RPC/Config 960 961 - [rpc] [\#3471](https://github.com/vipernet-xyz/tm/issues/3471) Paginate `/validators` response (default: 30 vals per page) 962 - [rpc] [\#3188](https://github.com/vipernet-xyz/tm/issues/3188) Remove `BlockMeta` in `ResultBlock` in favor of `BlockId` for `/block` 963 - [rpc] `/block_results` response format updated (see RPC docs for details) 964 ``` 965 { 966 "jsonrpc": "2.0", 967 "id": "", 968 "result": { 969 "height": "2109", 970 "txs_results": null, 971 "begin_block_events": null, 972 "end_block_events": null, 973 "validator_updates": null, 974 "consensus_param_updates": null 975 } 976 } 977 ``` 978 - [rpc] [\#4141](https://github.com/vipernet-xyz/tm/pull/4141) Remove `#event` suffix from the ID in event responses. 979 `{"jsonrpc": "2.0", "id": 0, "result": ...}` 980 - [rpc] [\#4141](https://github.com/vipernet-xyz/tm/pull/4141) Switch to integer IDs instead of `json-client-XYZ` 981 ``` 982 id=0 method=/subscribe 983 id=0 result=... 984 id=1 method=/abci_query 985 id=1 result=... 986 ``` 987 - ID is unique for each request; 988 - Request.ID is now optional. Notification is a Request without an ID. Previously ID="" or ID=0 were considered as notifications. 989 990 - [config] [\#4046](https://github.com/vipernet-xyz/tm/issues/4046) Rename tag(s) to CompositeKey & places where tag is still present it was renamed to event or events. Find how a compositeKey is constructed [here](https://github.com/vipernet-xyz/tm/blob/6d05c531f7efef6f0619155cf10ae8557dd7832f/docs/app-dev/indexing-transactions.md) 991 - You will have to generate a new config for your Tendermint node(s) 992 - [genesis] [\#2565](https://github.com/vipernet-xyz/tm/issues/2565) Add `consensus_params.evidence.max_age_duration`. Rename 993 `consensus_params.evidence.max_age` to `max_age_num_blocks`. 994 - [cli] [\#1771](https://github.com/vipernet-xyz/tm/issues/1771) `tendermint lite` now uses new light client package (`lite2`) 995 and has 3 more flags: `--trusting-period`, `--trusted-height` and 996 `--trusted-hash` 997 998 - Apps 999 1000 - [tm-bench] Removed tm-bench in favor of [tm-load-test](https://github.com/informalsystems/tm-load-test) 1001 1002 - Go API 1003 1004 - [rpc] [\#3953](https://github.com/vipernet-xyz/tm/issues/3953) Modify NewHTTP, NewXXXClient functions to return an error on invalid remote instead of panicking (@mrekucci) 1005 - [rpc/client] [\#3471](https://github.com/vipernet-xyz/tm/issues/3471) `Validators` now requires two more args: `page` and `perPage` 1006 - [libs/common] [\#3262](https://github.com/vipernet-xyz/tm/issues/3262) Make error the last parameter of `Task` (@PSalant726) 1007 - [cs/types] [\#3262](https://github.com/vipernet-xyz/tm/issues/3262) Rename `GotVoteFromUnwantedRoundError` to `ErrGotVoteFromUnwantedRound` (@PSalant726) 1008 - [libs/common] [\#3862](https://github.com/vipernet-xyz/tm/issues/3862) Remove `errors.go` from `libs/common` 1009 - [libs/common] [\#4230](https://github.com/vipernet-xyz/tm/issues/4230) Move `KV` out of common to its own pkg 1010 - [libs/common] [\#4230](https://github.com/vipernet-xyz/tm/issues/4230) Rename `cmn.KVPair(s)` to `kv.Pair(s)`s 1011 - [libs/common] [\#4232](https://github.com/vipernet-xyz/tm/issues/4232) Move `Service` & `BaseService` from `libs/common` to `libs/service` 1012 - [libs/common] [\#4232](https://github.com/vipernet-xyz/tm/issues/4232) Move `common/nil.go` to `types/utils.go` & make the functions private 1013 - [libs/common] [\#4231](https://github.com/vipernet-xyz/tm/issues/4231) Move random functions from `libs/common` into pkg `rand` 1014 - [libs/common] [\#4237](https://github.com/vipernet-xyz/tm/issues/4237) Move byte functions from `libs/common` into pkg `bytes` 1015 - [libs/common] [\#4237](https://github.com/vipernet-xyz/tm/issues/4237) Move throttletimer functions from `libs/common` into pkg `timer` 1016 - [libs/common] [\#4237](https://github.com/vipernet-xyz/tm/issues/4237) Move tempfile functions from `libs/common` into pkg `tempfile` 1017 - [libs/common] [\#4240](https://github.com/vipernet-xyz/tm/issues/4240) Move os functions from `libs/common` into pkg `os` 1018 - [libs/common] [\#4240](https://github.com/vipernet-xyz/tm/issues/4240) Move net functions from `libs/common` into pkg `net` 1019 - [libs/common] [\#4240](https://github.com/vipernet-xyz/tm/issues/4240) Move mathematical functions and types out of `libs/common` to `math` pkg 1020 - [libs/common] [\#4240](https://github.com/vipernet-xyz/tm/issues/4240) Move string functions out of `libs/common` to `strings` pkg 1021 - [libs/common] [\#4240](https://github.com/vipernet-xyz/tm/issues/4240) Move async functions out of `libs/common` to `async` pkg 1022 - [libs/common] [\#4240](https://github.com/vipernet-xyz/tm/issues/4240) Move bit functions out of `libs/common` to `bits` pkg 1023 - [libs/common] [\#4240](https://github.com/vipernet-xyz/tm/issues/4240) Move cmap functions out of `libs/common` to `cmap` pkg 1024 - [libs/common] [\#4258](https://github.com/vipernet-xyz/tm/issues/4258) Remove `Rand` from all `rand` pkg functions 1025 - [types] [\#2565](https://github.com/vipernet-xyz/tm/issues/2565) Remove `MockBadEvidence` & `MockGoodEvidence` in favor of `MockEvidence` 1026 1027 - Blockchain Protocol 1028 1029 - [abci] [\#2521](https://github.com/vipernet-xyz/tm/issues/2521) Remove `TotalTxs` and `NumTxs` from `Header` 1030 - [types] [\#4151](https://github.com/vipernet-xyz/tm/pull/4151) Enforce ordering of votes in DuplicateVoteEvidence to be lexicographically sorted on BlockID 1031 - [types] [\#1648](https://github.com/vipernet-xyz/tm/issues/1648) Change `Commit` to consist of just signatures 1032 1033 - P2P Protocol 1034 1035 - [p2p] [\#3668](https://github.com/vipernet-xyz/tm/pull/3668) Make `SecretConnection` non-malleable 1036 1037 - [proto] [\#3986](https://github.com/vipernet-xyz/tm/pull/3986) Prefix protobuf types to avoid name conflicts. 1038 - ABCI becomes `tendermint.abci.types` with the new API endpoint `/tendermint.abci.types.ABCIApplication/` 1039 - core_grpc becomes `tendermint.rpc.grpc` with the new API endpoint `/tendermint.rpc.grpc.BroadcastAPI/` 1040 - merkle becomes `tendermint.crypto.merkle` 1041 - libs.common becomes `tendermint.libs.common` 1042 - proto3 becomes `tendermint.types.proto3` 1043 1044 ### FEATURES: 1045 1046 - [p2p] [\#4053](https://github.com/vipernet-xyz/tm/issues/4053) Add `unconditional_peer_ids` and `persistent_peers_max_dial_period` config variables (see ADR-050) (@dongsam) 1047 - [tools] [\#4227](https://github.com/vipernet-xyz/tm/pull/4227) Implement `tendermint debug kill` and 1048 `tendermint debug dump` commands for Tendermint node debugging functionality. See `--help` in both 1049 commands for further documentation and usage. 1050 - [cli] [\#4234](https://github.com/vipernet-xyz/tm/issues/4234) Add `--db_backend and --db_dir` flags (@princesinha19) 1051 - [cli] [\#4113](https://github.com/vipernet-xyz/tm/issues/4113) Add optional `--genesis_hash` flag to check genesis hash upon startup 1052 - [config] [\#3831](https://github.com/vipernet-xyz/tm/issues/3831) Add support for [RocksDB](https://rocksdb.org/) (@Stumble) 1053 - [rpc] [\#3985](https://github.com/vipernet-xyz/tm/issues/3985) Add new `/block_by_hash` endpoint, which allows to fetch a block by its hash (@princesinha19) 1054 - [metrics] [\#4263](https://github.com/vipernet-xyz/tm/issues/4263) Add 1055 - `consensus_validator_power`: track your validators power 1056 - `consensus_validator_last_signed_height`: track at which height the validator last signed 1057 - `consensus_validator_missed_blocks`: total amount of missed blocks for a validator 1058 as gauges in prometheus for validator specific metrics 1059 - [rpc/lib] [\#4248](https://github.com/vipernet-xyz/tm/issues/4248) RPC client basic authentication support (@greg-szabo) 1060 - [lite2] [\#1771](https://github.com/vipernet-xyz/tm/issues/1771) Light client with weak subjectivity 1061 1062 ### IMPROVEMENTS: 1063 1064 - [rpc] [\#3188](https://github.com/vipernet-xyz/tm/issues/3188) Added `block_size` to `BlockMeta` this is reflected in `/blockchain` 1065 - [types] [\#2521](https://github.com/vipernet-xyz/tm/issues/2521) Add `NumTxs` to `BlockMeta` and `EventDataNewBlockHeader` 1066 - [p2p] [\#4185](https://github.com/vipernet-xyz/tm/pull/4185) Simplify `SecretConnection` handshake with merlin 1067 - [cli] [\#4065](https://github.com/vipernet-xyz/tm/issues/4065) Add `--consensus.create_empty_blocks_interval` flag (@jgimeno) 1068 - [docs] [\#4065](https://github.com/vipernet-xyz/tm/issues/4065) Document `--consensus.create_empty_blocks_interval` flag (@jgimeno) 1069 - [crypto] [\#4190](https://github.com/vipernet-xyz/tm/pull/4190) Added SR25519 signature scheme 1070 - [abci] [\#4177] kvstore: Return `LastBlockHeight` and `LastBlockAppHash` in `Info` (@princesinha19) 1071 - [rpc] [\#2741](https://github.com/vipernet-xyz/tm/issues/2741) Add `proposer` to `/consensus_state` response (@princesinha19) 1072 - [deps] [\#4289](https://github.com/vipernet-xyz/tm/pull/4289) Update tm-db to 0.4.0, this includes major breaking changes in the dep that change how errors are handled. 1073 1074 ### BUG FIXES: 1075 1076 - [rpc/lib][\#4051](https://github.com/vipernet-xyz/tm/pull/4131) Fix RPC client, which was previously resolving https protocol to http (@yenkhoon) 1077 - [rpc] [\#4141](https://github.com/vipernet-xyz/tm/pull/4141) JSONRPCClient: validate that Response.ID matches Request.ID 1078 - [rpc] [\#4141](https://github.com/vipernet-xyz/tm/pull/4141) WSClient: check for unsolicited responses 1079 - [types] [\4164](https://github.com/vipernet-xyz/tm/pull/4164) Prevent temporary power overflows on validator updates 1080 - [cs] [\#4069](https://github.com/vipernet-xyz/tm/issues/4069) Don't panic when block meta is not found in store (@gregzaitsev) 1081 - [types] [\#4164](https://github.com/vipernet-xyz/tm/issues/4164) Prevent temporary power overflows on validator updates (joint 1082 efforts of @gchaincl and @ancazamfir) 1083 - [p2p] [\#4140](https://github.com/vipernet-xyz/tm/issues/4140) `SecretConnection`: use the transcript solely for authentication (i.e. MAC) 1084 - [consensus/types] [\#4243](https://github.com/vipernet-xyz/tm/issues/4243) fix BenchmarkRoundStateDeepCopy panics (@cuonglm) 1085 - [rpc] [\#4256](https://github.com/vipernet-xyz/tm/issues/4256) Pass `outCapacity` to `eventBus#Subscribe` when subscribing using a local client 1086 1087 ## v0.32.13 1088 1089 *August 5, 2020* 1090 1091 ### BUG FIXES 1092 1093 - [privval] [\#5112](https://github.com/vipernet-xyz/tm/issues/5112) If remote signer errors, don't retry (@melekes) 1094 1095 ## v0.32.12 1096 1097 *May 19, 2020* 1098 1099 ### BUG FIXES 1100 1101 - [p2p] [\#4847](https://github.com/vipernet-xyz/tm/pull/4847) Return masked IP (not the actual IP) in addrbook#groupKey (@melekes) 1102 1103 ## v0.32.11 1104 1105 *April 29, 2020* 1106 1107 ### BUG FIXES: 1108 1109 - [privval] [\#4275](https://github.com/vipernet-xyz/tm/issues/4275) Fix consensus failure when remote signer drops (@melekes) 1110 1111 ## v0.32.10 1112 1113 *April 6, 2020* 1114 1115 This security release fixes: 1116 1117 ### Denial of Service 1 1118 1119 Tendermint 0.33.2 and earlier does not limit the number of P2P connection 1120 requests. For each p2p connection, Tendermint allocates ~0.5MB. Even though 1121 this memory is garbage collected once the connection is terminated (due to 1122 duplicate IP or reaching a maximum number of inbound peers), temporary memory 1123 spikes can lead to OOM (Out-Of-Memory) exceptions. 1124 1125 Tendermint 0.33.3 (and 0.32.10) limits the total number of P2P incoming 1126 connection requests to to `p2p.max_num_inbound_peers + 1127 len(p2p.unconditional_peer_ids)`. 1128 1129 Notes: 1130 1131 - Tendermint does not rate limit P2P connection requests per IP (an attacker 1132 can saturate all the inbound slots); 1133 - Tendermint does not rate limit HTTP(S) requests. If you expose any RPC 1134 endpoints to the public, please make sure to put in place some protection 1135 (https://www.nginx.com/blog/rate-limiting-nginx/). We may implement this in 1136 the future ([\#1696](https://github.com/vipernet-xyz/tm/issues/1696)). 1137 1138 ### Denial of Service 2 1139 1140 Tendermint 0.33.2 and earlier does not reclaim `activeID` of a peer after it's 1141 removed in `Mempool` reactor. This does not happen all the time. It only 1142 happens when a connection fails (for any reason) before the Peer is created and 1143 added to all reactors. `RemovePeer` is therefore called before `AddPeer`, which 1144 leads to always growing memory (`activeIDs` map). The `activeIDs` map has a 1145 maximum size of 65535 and the node will panic if this map reaches the maximum. 1146 An attacker can create a lot of connection attempts (exploiting Denial of 1147 Service 1), which ultimately will lead to the node panicking. 1148 1149 Tendermint 0.33.3 (and 0.32.10) claims `activeID` for a peer in `InitPeer`, 1150 which is executed before `MConnection` is started. 1151 1152 Notes: 1153 1154 - `InitPeer` function was added to all reactors to combat a similar issue - 1155 [\#3338](https://github.com/vipernet-xyz/tm/issues/3338); 1156 - Denial of Service 2 is independent of Denial of Service 1 and can be executed 1157 without it. 1158 1159 **All clients are recommended to upgrade** 1160 1161 Special thanks to [fudongbai](https://hackerone.com/fudongbai) for finding 1162 and reporting this. 1163 1164 ### SECURITY: 1165 1166 - [mempool] Reserve IDs in InitPeer instead of AddPeer (@tessr) 1167 - [p2p] Limit the number of incoming connections (@melekes) 1168 1169 ## v0.32.9 1170 1171 _January, 9, 2020_ 1172 1173 Special thanks to external contributors on this release: @greg-szabo, @gregzaitsev, @yenkhoon 1174 1175 ### FEATURES: 1176 1177 - [rpc/lib] [\#4248](https://github.com/vipernet-xyz/tm/issues/4248) RPC client basic authentication support (@greg-szabo) 1178 1179 - [metrics] [\#4294](https://github.com/vipernet-xyz/tm/pull/4294) Add 1180 - `consensus_validator_power`: track your validators power 1181 - `consensus_validator_last_signed_height`: track at which height the validator last signed 1182 - `consensus_validator_missed_blocks`: total amount of missed blocks for a validator 1183 as gauges in prometheus for validator specific metrics 1184 1185 ### BUG FIXES: 1186 1187 - [rpc/lib] [\#4131](https://github.com/vipernet-xyz/tm/pull/4131) Fix RPC client, which was previously resolving https protocol to http (@yenkhoon) 1188 - [cs] [\#4069](https://github.com/vipernet-xyz/tm/issues/4069) Don't panic when block meta is not found in store (@gregzaitsev) 1189 1190 ## v0.32.8 1191 1192 *November 19, 2019* 1193 1194 Special thanks to external contributors on this release: @erikgrinaker, @guagualvcha, @hsyis, @cosmostuba, @whunmr, @austinabell 1195 1196 1197 ### BREAKING CHANGES: 1198 1199 - Go API 1200 1201 - [libs/pubsub] [\#4070](https://github.com/vipernet-xyz/tm/pull/4070) `Query#(Matches|Conditions)` returns an error. 1202 1203 ### IMPROVEMENTS: 1204 1205 - [mempool] [\#4083](https://github.com/vipernet-xyz/tm/pull/4083) Added TxInfo parameter to CheckTx(), and removed CheckTxWithInfo() (@erikgrinaker) 1206 - [mempool] [\#4057](https://github.com/vipernet-xyz/tm/issues/4057) Include peer ID when logging rejected txns (@erikgrinaker) 1207 - [tools] [\#4023](https://github.com/vipernet-xyz/tm/issues/4023) Improved `tm-monitor` formatting of start time and avg tx throughput (@erikgrinaker) 1208 - [p2p] [\#3991](https://github.com/vipernet-xyz/tm/issues/3991) Log "has been established or dialed" as debug log instead of Error for connected peers (@whunmr) 1209 - [rpc] [\#4077](https://github.com/vipernet-xyz/tm/pull/4077) Added support for `EXISTS` clause to the Websocket query interface. 1210 - [privval] Add `SignerDialerEndpointRetryWaitInterval` option (@cosmostuba) 1211 - [crypto] Add `RegisterKeyType` to amino to allow external key types registration (@austinabell) 1212 1213 ### BUG FIXES: 1214 1215 - [libs/pubsub] [\#4070](https://github.com/vipernet-xyz/tm/pull/4070) Strip out non-numeric characters when attempting to match numeric values. 1216 - [libs/pubsub] [\#4070](https://github.com/vipernet-xyz/tm/pull/4070) No longer panic in Query#(Matches|Conditions) preferring to return an error instead. 1217 - [tools] [\#4023](https://github.com/vipernet-xyz/tm/issues/4023) Refresh `tm-monitor` health when validator count is updated (@erikgrinaker) 1218 - [state] [\#4104](https://github.com/vipernet-xyz/tm/pull/4104) txindex/kv: Fsync data to disk immediately after receiving it (@guagualvcha) 1219 - [state] [\#4095](https://github.com/vipernet-xyz/tm/pull/4095) txindex/kv: Return an error if there's one when the user searches for a tx (hash=X) (@hsyis) 1220 1221 ## v0.32.7 1222 1223 *October 18, 2019* 1224 1225 This security release fixes a vulnerability found in the `consensus` package, 1226 where an attacker could construct a `BlockPartMessage` message in such a way 1227 that it will lead to consensus failure. A few similar issues have been 1228 identified and fixed here. 1229 1230 **All clients are recommended to upgrade** 1231 1232 Special thanks to [elvishacker](https://hackerone.com/elvishacker) for finding 1233 and reporting this. 1234 1235 ### BREAKING CHANGES: 1236 1237 - Go API 1238 - [consensus] Modify `WAL#Write` and `WAL#WriteSync` to return an error if 1239 they fail to write a message 1240 1241 ### SECURITY: 1242 1243 - [consensus] Validate incoming messages more throughly 1244 1245 ## v0.32.6 1246 1247 *October 8, 2019* 1248 1249 The previous patch was insufficient because the attacker could still find a way 1250 to submit a `nil` pubkey by constructing a `PubKeyMultisigThreshold` pubkey 1251 with `nil` subpubkeys for example. 1252 1253 This release provides multiple fixes, which include recovering from panics when 1254 accepting new peers and only allowing `ed25519` pubkeys. 1255 1256 **All clients are recommended to upgrade** 1257 1258 Special thanks to [fudongbai](https://hackerone.com/fudongbai) for pointing 1259 this out. 1260 1261 ### SECURITY: 1262 1263 - [p2p] [\#4030](https://github.com/vipernet-xyz/tm/issues/4030) Only allow ed25519 pubkeys when connecting 1264 1265 ## v0.32.5 1266 1267 *October 1, 2019* 1268 1269 This release fixes a major security vulnerability found in the `p2p` package. 1270 All clients are recommended to upgrade. See 1271 [\#4030](https://github.com/vipernet-xyz/tm/issues/4030) for details. 1272 1273 Special thanks to [fudongbai](https://hackerone.com/fudongbai) for discovering 1274 and reporting this issue. 1275 1276 ### SECURITY: 1277 1278 - [p2p] [\#4030](https://github.com/vipernet-xyz/tm/issues/4030) Fix for panic on nil public key send to a peer 1279 1280 ## v0.32.4 1281 1282 *September 19, 2019* 1283 1284 Special thanks to external contributors on this release: @jon-certik, @gracenoah, @PSalant726, @gchaincl 1285 1286 ### BREAKING CHANGES: 1287 1288 - CLI/RPC/Config 1289 - [rpc] [\#3984](https://github.com/vipernet-xyz/tm/issues/3984) Add `MempoolClient` interface to `Client` interface 1290 1291 ### IMPROVEMENTS: 1292 1293 - [rpc] [\#2010](https://github.com/vipernet-xyz/tm/issues/2010) Add NewHTTPWithClient and NewJSONRPCClientWithHTTPClient (note these and NewHTTP, NewJSONRPCClient functions panic if remote is invalid) (@gracenoah) 1294 - [rpc] [\#3882](https://github.com/vipernet-xyz/tm/issues/3882) Add custom marshalers to proto messages to disable `omitempty` 1295 - [deps] [\#3952](https://github.com/vipernet-xyz/tm/pull/3952) bump github.com/go-kit/kit from 0.6.0 to 0.9.0 1296 - [deps] [\#3951](https://github.com/vipernet-xyz/tm/pull/3951) bump github.com/stretchr/testify from 1.3.0 to 1.4.0 1297 - [deps] [\#3945](https://github.com/vipernet-xyz/tm/pull/3945) bump github.com/gorilla/websocket from 1.2.0 to 1.4.1 1298 - [deps] [\#3948](https://github.com/vipernet-xyz/tm/pull/3948) bump github.com/libp2p/go-buffer-pool from 0.0.1 to 0.0.2 1299 - [deps] [\#3943](https://github.com/vipernet-xyz/tm/pull/3943) bump github.com/fortytw2/leaktest from 1.2.0 to 1.3.0 1300 - [deps] [\#3939](https://github.com/vipernet-xyz/tm/pull/3939) bump github.com/rs/cors from 1.6.0 to 1.7.0 1301 - [deps] [\#3937](https://github.com/vipernet-xyz/tm/pull/3937) bump github.com/magiconair/properties from 1.8.0 to 1.8.1 1302 - [deps] [\#3947](https://github.com/vipernet-xyz/tm/pull/3947) update gogo/protobuf version from v1.2.1 to v1.3.0 1303 - [deps] [\#4001](https://github.com/vipernet-xyz/tm/pull/4001) bump github.com/tendermint/tm-db from 0.1.1 to 0.2.0 1304 1305 ### BUG FIXES: 1306 1307 - [consensus] [\#3908](https://github.com/vipernet-xyz/tm/issues/3908) Wait `timeout_commit` to pass even if `create_empty_blocks` is `false` 1308 - [mempool] [\#3968](https://github.com/vipernet-xyz/tm/issues/3968) Fix memory loading error on 32-bit machines (@jon-certik) 1309 1310 ## v0.32.3 1311 1312 *August 28, 2019* 1313 1314 @climber73 wrote the [Writing a Tendermint Core application in Java 1315 (gRPC)](https://github.com/vipernet-xyz/tm/blob/v0.32.x/docs/guides/java.md) 1316 guide. 1317 1318 Special thanks to external contributors on this release: 1319 @gchaincl, @bluele, @climber73 1320 1321 ### IMPROVEMENTS: 1322 1323 - [consensus] [\#3839](https://github.com/vipernet-xyz/tm/issues/3839) Reduce "Error attempting to add vote" message severity (Error -> Info) 1324 - [mempool] [\#3877](https://github.com/vipernet-xyz/tm/pull/3877) Make `max_tx_bytes` configurable instead of `max_msg_bytes` (@bluele) 1325 - [privval] [\#3370](https://github.com/vipernet-xyz/tm/issues/3370) Refactor and simplify validator/kms connection handling. Please refer to [this comment](https://github.com/vipernet-xyz/tm/pull/3370#issue-257360971) for details 1326 - [rpc] [\#3880](https://github.com/vipernet-xyz/tm/issues/3880) Document endpoints with `swagger`, introduce contract tests of implementation against documentation 1327 1328 ### BUG FIXES: 1329 1330 - [config] [\#3868](https://github.com/vipernet-xyz/tm/issues/3868) Move misplaced `max_msg_bytes` into mempool section (@bluele) 1331 - [rpc] [\#3910](https://github.com/vipernet-xyz/tm/pull/3910) Fix DATA RACE in HTTP client (@gchaincl) 1332 - [store] [\#3893](https://github.com/vipernet-xyz/tm/issues/3893) Fix "Unregistered interface types.Evidence" panic 1333 1334 ## v0.32.2 1335 1336 *July 31, 2019* 1337 1338 Special thanks to external contributors on this release: 1339 @ruseinov, @bluele, @guagualvcha 1340 1341 ### BREAKING CHANGES: 1342 1343 - Go API 1344 - [libs] [\#3811](https://github.com/vipernet-xyz/tm/issues/3811) Remove `db` from libs in favor of `https://github.com/tendermint/tm-db` 1345 1346 ### FEATURES: 1347 1348 - [blockchain] [\#3561](https://github.com/vipernet-xyz/tm/issues/3561) Add early version of the new blockchain reactor, which is supposed to be more modular and testable compared to the old version. To try it, you'll have to change `version` in the config file, [here](https://github.com/vipernet-xyz/tm/blob/v0.34.x/config/toml.go#L303) NOTE: It's not ready for a production yet. For further information, see [ADR-40](https://github.com/vipernet-xyz/tm/blob/main/docs/architecture/adr-040-blockchain-reactor-refactor.md) & [ADR-43](https://github.com/vipernet-xyz/tm/blob/main/docs/architecture/adr-043-blockchain-riri-org.md) 1349 - [mempool] [\#3826](https://github.com/vipernet-xyz/tm/issues/3826) Make `max_msg_bytes` configurable(@bluele) 1350 - [node] [\#3846](https://github.com/vipernet-xyz/tm/pull/3846) Allow replacing existing p2p.Reactor(s) using [`CustomReactors` 1351 option](https://godoc.org/github.com/vipernet-xyz/tm/node#CustomReactors). 1352 Warning: beware of accidental name clashes. Here is the list of existing 1353 reactors: MEMPOOL, BLOCKCHAIN, CONSENSUS, EVIDENCE, PEX. 1354 - [rpc] [\#3818](https://github.com/vipernet-xyz/tm/issues/3818) Make `max_body_bytes` and `max_header_bytes` configurable(@bluele) 1355 - [rpc] [\#2252](https://github.com/vipernet-xyz/tm/issues/2252) Add `/broadcast_evidence` endpoint to submit double signing and other types of evidence 1356 1357 ### IMPROVEMENTS: 1358 1359 - [abci] [\#3809](https://github.com/vipernet-xyz/tm/issues/3809) Recover from application panics in `server/socket_server.go` to allow socket cleanup (@ruseinov) 1360 - [p2p] [\#3664](https://github.com/vipernet-xyz/tm/issues/3664) p2p/conn: reuse buffer when write/read from secret connection(@guagualvcha) 1361 - [p2p] [\#3834](https://github.com/vipernet-xyz/tm/issues/3834) Do not write 'Couldn't connect to any seeds' error log if there are no seeds in config file 1362 - [rpc] [\#3076](https://github.com/vipernet-xyz/tm/issues/3076) Improve transaction search performance 1363 1364 ### BUG FIXES: 1365 1366 - [p2p] [\#3644](https://github.com/vipernet-xyz/tm/issues/3644) Fix error logging for connection stop (@defunctzombie) 1367 - [rpc] [\#3813](https://github.com/vipernet-xyz/tm/issues/3813) Return err if page is incorrect (less than 0 or greater than total pages) 1368 1369 ## v0.32.1 1370 1371 *July 15, 2019* 1372 1373 Special thanks to external contributors on this release: 1374 @ParthDesai, @climber73, @jim380, @ashleyvega 1375 1376 This release contains a minor enhancement to the ABCI and some breaking changes to our libs folder, namely: 1377 - CheckTx requests include a `CheckTxType` enum that can be set to `Recheck` to indicate to the application that this transaction was already checked/validated and certain expensive operations (like checking signatures) can be skipped 1378 - Removed various functions from `libs` pkgs 1379 1380 ### BREAKING CHANGES: 1381 1382 - Go API 1383 1384 - [abci] [\#2127](https://github.com/vipernet-xyz/tm/issues/2127) The CheckTx and DeliverTx methods in the ABCI `Application` interface now take structs as arguments (RequestCheckTx and RequestDeliverTx, respectively), instead of just the raw tx bytes. This allows more information to be passed to these methods, for instance, indicating whether a tx has already been checked. 1385 - [libs] Remove unused `db/debugDB` and `common/colors.go` & `errors/errors.go` files (@marbar3778) 1386 - [libs] [\#2432](https://github.com/vipernet-xyz/tm/issues/2432) Remove unused `common/heap.go` file (@marbar3778) 1387 - [libs] Remove unused `date.go`, `io.go`. Remove `GoPath()`, `Prompt()` and `IsDirEmpty()` functions from `os.go` (@marbar3778) 1388 - [libs] Remove unused `FailRand()` func and minor clean up to `fail.go`(@marbar3778) 1389 1390 ### FEATURES: 1391 1392 - [node] Add variadic argument to `NewNode` to support functional options, allowing the Node to be more easily customized. 1393 - [node][\#3730](https://github.com/vipernet-xyz/tm/pull/3730) Add `CustomReactors` option to `NewNode` allowing caller to pass 1394 custom reactors to run inside Tendermint node (@ParthDesai) 1395 - [abci] [\#2127](https://github.com/vipernet-xyz/tm/issues/2127)RequestCheckTx has a new field, `CheckTxType`, which can take values of `CheckTxType_New` and `CheckTxType_Recheck`, indicating whether this is a new tx being checked for the first time or whether this tx is being rechecked after a block commit. This allows applications to skip certain expensive operations, like signature checking, if they've already been done once. see [docs](https://github.com/vipernet-xyz/tm/blob/eddb433d7c082efbeaf8974413a36641519ee895/docs/spec/abci/apps.md#mempool-connection) 1396 1397 ### IMPROVEMENTS: 1398 1399 - [rpc] [\#3700](https://github.com/vipernet-xyz/tm/issues/3700) Make possible to set absolute paths for TLS cert and key (@climber73) 1400 - [abci] [\#3513](https://github.com/vipernet-xyz/tm/issues/3513) Call the reqRes callback after the resCb so they always happen in the same order 1401 1402 ### BUG FIXES: 1403 1404 - [p2p] [\#3338](https://github.com/vipernet-xyz/tm/issues/3338) Prevent "sent next PEX request too soon" errors by not calling 1405 ensurePeers outside of ensurePeersRoutine 1406 - [behaviour] [\3772](https://github.com/vipernet-xyz/tm/pull/3772) Return correct reason in MessageOutOfOrder (@jim380) 1407 - [config] [\#3723](https://github.com/vipernet-xyz/tm/issues/3723) Add consensus_params to testnet config generation; document time_iota_ms (@ashleyvega) 1408 1409 1410 ## v0.32.0 1411 1412 *June 25, 2019* 1413 1414 Special thanks to external contributors on this release: 1415 @needkane, @SebastianElvis, @andynog, @Yawning, @wooparadog 1416 1417 This release contains breaking changes to our build and release processes, ABCI, 1418 and the RPC, namely: 1419 - Use Go modules instead of dep 1420 - Bring active development to the `master` Github branch 1421 - ABCI Tags are now Events - see 1422 [docs](https://github.com/vipernet-xyz/tm/blob/60827f75623b92eff132dc0eff5b49d2025c591e/docs/spec/abci/abci.md#events) 1423 - Bind RPC to localhost by default, not to the public interface [UPGRADING/RPC_Changes](./UPGRADING.md#rpc_changes) 1424 1425 ### BREAKING CHANGES: 1426 1427 * CLI/RPC/Config 1428 - [cli] [\#3613](https://github.com/vipernet-xyz/tm/issues/3613) Switch from golang/dep to Go Modules to resolve dependencies: 1429 It is recommended to switch to Go Modules if your project has tendermint as 1430 a dependency. Read more on Modules here: 1431 https://github.com/golang/go/wiki/Modules 1432 - [config] [\#3632](https://github.com/vipernet-xyz/tm/pull/3632) Removed `leveldb` as generic 1433 option for `db_backend`. Must be `goleveldb` or `cleveldb`. 1434 - [rpc] [\#3616](https://github.com/vipernet-xyz/tm/issues/3616) Fix field names for `/block_results` response (eg. `results.DeliverTx` 1435 -> `results.deliver_tx`). See docs for details. 1436 - [rpc] [\#3724](https://github.com/vipernet-xyz/tm/issues/3724) RPC now binds to `127.0.0.1` by default instead of `0.0.0.0` 1437 1438 * Apps 1439 - [abci] [\#1859](https://github.com/vipernet-xyz/tm/issues/1859) `ResponseCheckTx`, `ResponseDeliverTx`, `ResponseBeginBlock`, 1440 and `ResponseEndBlock` now include `Events` instead of `Tags`. Each `Event` 1441 contains a `type` and a list of `attributes` (list of key-value pairs) 1442 allowing for inclusion of multiple distinct events in each response. 1443 1444 * Go API 1445 - [abci] [\#3193](https://github.com/vipernet-xyz/tm/issues/3193) Use RequestDeliverTx and RequestCheckTx in the ABCI 1446 Application interface 1447 - [libs/db] [\#3632](https://github.com/vipernet-xyz/tm/pull/3632) Removed deprecated `LevelDBBackend` const 1448 If you have `db_backend` set to `leveldb` in your config file, please 1449 change it to `goleveldb` or `cleveldb`. 1450 - [p2p] [\#3521](https://github.com/vipernet-xyz/tm/issues/3521) Remove NewNetAddressStringWithOptionalID 1451 1452 * Blockchain Protocol 1453 1454 * P2P Protocol 1455 1456 ### FEATURES: 1457 1458 ### IMPROVEMENTS: 1459 - [abci/examples] [\#3659](https://github.com/vipernet-xyz/tm/issues/3659) Change validator update tx format in the `persistent_kvstore` to use base64 for pubkeys instead of hex (@needkane) 1460 - [consensus] [\#3656](https://github.com/vipernet-xyz/tm/issues/3656) Exit if SwitchToConsensus fails 1461 - [p2p] [\#3666](https://github.com/vipernet-xyz/tm/issues/3666) Add per channel telemetry to improve reactor observability 1462 - [rpc] [\#3686](https://github.com/vipernet-xyz/tm/pull/3686) `HTTPClient#Call` returns wrapped errors, so a caller could use `errors.Cause` to retrieve an error code. (@wooparadog) 1463 1464 ### BUG FIXES: 1465 - [libs/db] [\#3717](https://github.com/vipernet-xyz/tm/issues/3717) Fixed the BoltDB backend's Batch.Delete implementation (@Yawning) 1466 - [libs/db] [\#3718](https://github.com/vipernet-xyz/tm/issues/3718) Fixed the BoltDB backend's Get and Iterator implementation (@Yawning) 1467 - [node] [\#3716](https://github.com/vipernet-xyz/tm/issues/3716) Fix a bug where `nil` is recorded as node's address 1468 - [node] [\#3741](https://github.com/vipernet-xyz/tm/issues/3741) Fix profiler blocking the entire node 1469 1470 *Tendermint 0.31 release series has reached End-Of-Life and is no longer supported.* 1471 1472 ## v0.31.12 1473 1474 *April 6, 2020* 1475 1476 This security release fixes: 1477 1478 ### Denial of Service 1 1479 1480 Tendermint 0.33.2 and earlier does not limit the number of P2P connection requests. 1481 For each p2p connection, Tendermint allocates ~0.5MB. Even though this 1482 memory is garbage collected once the connection is terminated (due to duplicate 1483 IP or reaching a maximum number of inbound peers), temporary memory spikes can 1484 lead to OOM (Out-Of-Memory) exceptions. 1485 1486 Tendermint 0.33.3, 0.32.10, and 0.31.12 limit the total number of P2P incoming 1487 connection requests to to `p2p.max_num_inbound_peers + 1488 len(p2p.unconditional_peer_ids)`. 1489 1490 Notes: 1491 1492 - Tendermint does not rate limit P2P connection requests per IP (an attacker 1493 can saturate all the inbound slots); 1494 - Tendermint does not rate limit HTTP(S) requests. If you expose any RPC 1495 endpoints to the public, please make sure to put in place some protection 1496 (https://www.nginx.com/blog/rate-limiting-nginx/). We may implement this in 1497 the future ([\#1696](https://github.com/vipernet-xyz/tm/issues/1696)). 1498 1499 ### Denial of Service 2 1500 1501 Tendermint 0.33.2 and earlier does not reclaim `activeID` of a peer after it's 1502 removed in `Mempool` reactor. This does not happen all the time. It only 1503 happens when a connection fails (for any reason) before the Peer is created and 1504 added to all reactors. `RemovePeer` is therefore called before `AddPeer`, which 1505 leads to always growing memory (`activeIDs` map). The `activeIDs` map has a 1506 maximum size of 65535 and the node will panic if this map reaches the maximum. 1507 An attacker can create a lot of connection attempts (exploiting Denial of 1508 Service 1), which ultimately will lead to the node panicking. 1509 1510 Tendermint 0.33.3, 0.32.10, and 0.31.12 claim `activeID` for a peer in `InitPeer`, 1511 which is executed before `MConnection` is started. 1512 1513 Notes: 1514 1515 - `InitPeer` function was added to all reactors to combat a similar issue - 1516 [\#3338](https://github.com/vipernet-xyz/tm/issues/3338); 1517 - Denial of Service 2 is independent of Denial of Service 1 and can be executed 1518 without it. 1519 1520 **All clients are recommended to upgrade** 1521 1522 Special thanks to [fudongbai](https://hackerone.com/fudongbai) for finding 1523 and reporting this. 1524 1525 ### SECURITY: 1526 1527 - [mempool] Reserve IDs in InitPeer instead of AddPeer (@tessr) 1528 - [p2p] Limit the number of incoming connections (@melekes) 1529 1530 ## v0.31.11 1531 1532 *October 18, 2019* 1533 1534 This security release fixes a vulnerability found in the `consensus` package, 1535 where an attacker could construct a `BlockPartMessage` message in such a way 1536 that it will lead to consensus failure. A few similar issues have been 1537 identified and fixed here. 1538 1539 **All clients are recommended to upgrade** 1540 1541 Special thanks to [elvishacker](https://hackerone.com/elvishacker) for finding 1542 and reporting this. 1543 1544 ### BREAKING CHANGES: 1545 1546 - Go API 1547 - [consensus] Modify `WAL#Write` and `WAL#WriteSync` to return an error if 1548 they fail to write a message 1549 1550 ### SECURITY: 1551 1552 - [consensus] Validate incoming messages more throughly 1553 1554 ## v0.31.10 1555 1556 *October 8, 2019* 1557 1558 The previous patch was insufficient because the attacker could still find a way 1559 to submit a `nil` pubkey by constructing a `PubKeyMultisigThreshold` pubkey 1560 with `nil` subpubkeys for example. 1561 1562 This release provides multiple fixes, which include recovering from panics when 1563 accepting new peers and only allowing `ed25519` pubkeys. 1564 1565 **All clients are recommended to upgrade** 1566 1567 Special thanks to [fudongbai](https://hackerone.com/fudongbai) for pointing 1568 this out. 1569 1570 ### SECURITY: 1571 1572 - [p2p] [\#4030](https://github.com/vipernet-xyz/tm/issues/4030) Only allow ed25519 pubkeys when connecting 1573 1574 ## v0.31.9 1575 1576 *October 1, 2019* 1577 1578 This release fixes a major security vulnerability found in the `p2p` package. 1579 All clients are recommended to upgrade. See 1580 [\#4030](https://github.com/vipernet-xyz/tm/issues/4030) for details. 1581 1582 Special thanks to [fudongbai](https://hackerone.com/fudongbai) for discovering 1583 and reporting this issue. 1584 1585 ### SECURITY: 1586 1587 - [p2p] [\#4030](https://github.com/vipernet-xyz/tm/issues/4030) Fix for panic on nil public key send to a peer 1588 1589 ### BUG FIXES: 1590 1591 - [node] [\#3716](https://github.com/vipernet-xyz/tm/issues/3716) Fix a bug where `nil` is recorded as node's address 1592 - [node] [\#3741](https://github.com/vipernet-xyz/tm/issues/3741) Fix profiler blocking the entire node 1593 1594 ## v0.31.8 1595 1596 *July 29, 2019* 1597 1598 This releases fixes one bug in the PEX reactor and adds a `recover` to the Go's 1599 ABCI server, which allows it to properly cleanup. 1600 1601 ### IMPROVEMENTS: 1602 - [abci] [\#3809](https://github.com/vipernet-xyz/tm/issues/3809) Recover from application panics in `server/socket_server.go` to allow socket cleanup (@ruseinov) 1603 1604 ### BUG FIXES: 1605 - [p2p] [\#3338](https://github.com/vipernet-xyz/tm/issues/3338) Prevent "sent next PEX request too soon" errors by not calling 1606 ensurePeers outside of ensurePeersRoutine 1607 1608 ## v0.31.7 1609 1610 *June 3, 2019* 1611 1612 This releases fixes a regression in the mempool introduced in v0.31.6. 1613 The regression caused the invalid committed txs to be proposed in blocks over and 1614 over again. 1615 1616 ### BUG FIXES: 1617 - [mempool] [\#3699](https://github.com/vipernet-xyz/tm/issues/3699) Remove all committed txs from the mempool. 1618 This reverts the change from v0.31.6 where we only remove valid txs from the mempool. 1619 Note this means malicious proposals can cause txs to be dropped from the 1620 mempools of other nodes by including them in blocks before they are valid. 1621 See [\#3322](https://github.com/vipernet-xyz/tm/issues/3322). 1622 1623 ## v0.31.6 1624 1625 *May 31st, 2019* 1626 1627 This release contains many fixes and improvements, primarily for p2p functionality. 1628 It also fixes a security issue in the mempool package. 1629 1630 With this release, Tendermint now supports [boltdb](https://github.com/etcd-io/bbolt), although 1631 in experimental mode. Feel free to try and report to us any findings/issues. 1632 Note also that the build tags for compiling CLevelDB have changed. 1633 1634 Special thanks to external contributors on this release: 1635 @guagualvcha, @james-ray, @gregdhill, @climber73, @yutianwu, 1636 @carlosflrs, @defunctzombie, @leoluk, @needkane, @CrocdileChan 1637 1638 ### BREAKING CHANGES: 1639 1640 * Go API 1641 - [libs/common] Removed deprecated `PanicSanity`, `PanicCrisis`, 1642 `PanicConsensus` and `PanicQ` 1643 - [mempool, state] [\#2659](https://github.com/vipernet-xyz/tm/issues/2659) `Mempool` now an interface that lives in the mempool package. 1644 See issue and PR for more details. 1645 - [p2p] [\#3346](https://github.com/vipernet-xyz/tm/issues/3346) `Reactor#InitPeer` method is added to `Reactor` interface 1646 - [types] [\#1648](https://github.com/vipernet-xyz/tm/issues/1648) `Commit#VoteSignBytes` signature was changed 1647 1648 ### FEATURES: 1649 - [node] [\#2659](https://github.com/vipernet-xyz/tm/issues/2659) Add `node.Mempool()` method, which allows you to access mempool 1650 - [libs/db] [\#3604](https://github.com/vipernet-xyz/tm/pull/3604) Add experimental support for bolt db (etcd's fork of bolt) (@CrocdileChan) 1651 1652 ### IMPROVEMENTS: 1653 - [cli] [\#3585](https://github.com/vipernet-xyz/tm/issues/3585) Add `--keep-addr-book` option to `unsafe_reset_all` cmd to not 1654 clear the address book (@climber73) 1655 - [cli] [\#3160](https://github.com/vipernet-xyz/tm/issues/3160) Add 1656 `--config=<path-to-config>` option to `testnet` cmd (@gregdhill) 1657 - [cli] [\#3661](https://github.com/vipernet-xyz/tm/pull/3661) Add 1658 `--hostname-suffix`, `--hostname` and `--random-monikers` options to `testnet` 1659 cmd for greater peer address/identity generation flexibility. 1660 - [crypto] [\#3672](https://github.com/vipernet-xyz/tm/issues/3672) Return more info in the `AddSignatureFromPubKey` error 1661 - [cs/replay] [\#3460](https://github.com/vipernet-xyz/tm/issues/3460) Check appHash for each block 1662 - [libs/db] [\#3611](https://github.com/vipernet-xyz/tm/issues/3611) Conditional compilation 1663 * Use `cleveldb` tag instead of `gcc` to compile Tendermint with CLevelDB or 1664 use `make build_c` / `make install_c` (full instructions can be found at 1665 <https://docs.tendermint.com/>) 1666 * Use `boltdb` tag to compile Tendermint with bolt db 1667 - [node] [\#3362](https://github.com/vipernet-xyz/tm/issues/3362) Return an error if `persistent_peers` list is invalid (except 1668 when IP lookup fails) 1669 - [p2p] [\#3463](https://github.com/vipernet-xyz/tm/pull/3463) Do not log "Can't add peer's address to addrbook" error for a private peer (@guagualvcha) 1670 - [p2p] [\#3531](https://github.com/vipernet-xyz/tm/issues/3531) Terminate session on nonce wrapping (@climber73) 1671 - [pex] [\#3647](https://github.com/vipernet-xyz/tm/pull/3647) Dial seeds, if any, instead of crawling peers first (@defunctzombie) 1672 - [rpc] [\#3534](https://github.com/vipernet-xyz/tm/pull/3534) Add support for batched requests/responses in JSON RPC 1673 - [rpc] [\#3362](https://github.com/vipernet-xyz/tm/issues/3362) `/dial_seeds` & `/dial_peers` return errors if addresses are 1674 incorrect (except when IP lookup fails) 1675 1676 ### BUG FIXES: 1677 - [consensus] [\#3067](https://github.com/vipernet-xyz/tm/issues/3067) Fix replay from appHeight==0 with validator set changes (@james-ray) 1678 - [consensus] [\#3304](https://github.com/vipernet-xyz/tm/issues/3304) Create a peer state in consensus reactor before the peer 1679 is started (@guagualvcha) 1680 - [lite] [\#3669](https://github.com/vipernet-xyz/tm/issues/3669) Add context parameter to RPC Handlers in proxy routes (@yutianwu) 1681 - [mempool] [\#3322](https://github.com/vipernet-xyz/tm/issues/3322) When a block is committed, only remove committed txs from the mempool 1682 that were valid (ie. `ResponseDeliverTx.Code == 0`) 1683 - [p2p] [\#3338](https://github.com/vipernet-xyz/tm/issues/3338) Ensure `RemovePeer` is always called before `InitPeer` (upon a peer 1684 reconnecting to our node) 1685 - [p2p] [\#3532](https://github.com/vipernet-xyz/tm/issues/3532) Limit the number of attempts to connect to a peer in seed mode 1686 to 16 (as a result, the node will stop retrying after a 35 hours time window) 1687 - [p2p] [\#3362](https://github.com/vipernet-xyz/tm/issues/3362) Allow inbound peers to be persistent, including for seed nodes. 1688 - [pex] [\#3603](https://github.com/vipernet-xyz/tm/pull/3603) Dial seeds when addrbook needs more addresses (@defunctzombie) 1689 1690 ### OTHERS: 1691 - [networks] fixes ansible integration script (@carlosflrs) 1692 1693 ## v0.31.5 1694 1695 *April 16th, 2019* 1696 1697 This release fixes a regression from v0.31.4 where, in existing chains that 1698 were upgraded, `/validators` could return an empty validator set. This is true 1699 for almost all heights, given the validator set remains the same. 1700 1701 Special thanks to external contributors on this release: 1702 @brapse, @guagualvcha, @dongsam, @phucc 1703 1704 ### IMPROVEMENTS: 1705 1706 - [libs/common] `CMap`: slight optimization in `Keys()` and `Values()` (@phucc) 1707 - [gitignore] gitignore: add .vendor-new (@dongsam) 1708 1709 ### BUG FIXES: 1710 1711 - [state] [\#3537](https://github.com/vipernet-xyz/tm/pull/3537#issuecomment-482711833) 1712 `LoadValidators`: do not return an empty validator set 1713 - [blockchain] [\#3457](https://github.com/vipernet-xyz/tm/issues/3457) 1714 Fix "peer did not send us anything" in `fast_sync` mode when under high pressure 1715 1716 ## v0.31.4 1717 1718 *April 12th, 2019* 1719 1720 This release fixes a regression from v0.31.3 which used the peer's `SocketAddr` to add the peer to 1721 the address book. This swallowed the peer's self-reported port which is important in case of reconnect. 1722 It brings back `NetAddress()` to `NodeInfo` and uses it instead of `SocketAddr` for adding peers. 1723 Additionally, it improves response time on the `/validators` or `/status` RPC endpoints. 1724 As a side-effect it makes these RPC endpoint more difficult to DoS and fixes a performance degradation in `ExecCommitBlock`. 1725 Also, it contains an [ADR](https://github.com/vipernet-xyz/tm/pull/3539) that proposes decoupling the 1726 responsibility for peer behaviour from the `p2p.Switch` (by @brapse). 1727 1728 Special thanks to external contributors on this release: 1729 @brapse, @guagualvcha, @mydring 1730 1731 ### IMPROVEMENTS: 1732 1733 - [p2p] [\#3463](https://github.com/vipernet-xyz/tm/pull/3463) Do not log "Can't add peer's address to addrbook" error for a private peer 1734 - [p2p] [\#3547](https://github.com/vipernet-xyz/tm/pull/3547) Fix a couple of annoying typos (@mdyring) 1735 1736 ### BUG FIXES: 1737 1738 - [docs] [\#3514](https://github.com/vipernet-xyz/tm/issues/3514) Fix block.Header.Time description (@melekes) 1739 - [p2p] [\#2716](https://github.com/vipernet-xyz/tm/issues/2716) Check if we're already connected to peer right before dialing it (@melekes) 1740 - [p2p] [\#3545](https://github.com/vipernet-xyz/tm/issues/3545) Add back `NetAddress()` to `NodeInfo` and use it instead of peer's `SocketAddr()` when adding a peer to the `PEXReactor` (potential fix for [\#3532](https://github.com/vipernet-xyz/tm/issues/3532)) 1741 - [state] [\#3438](https://github.com/vipernet-xyz/tm/pull/3438) 1742 Persist validators every 100000 blocks even if no changes to the set 1743 occurred (@guagualvcha). This 1744 1) Prevents possible DoS attack using `/validators` or `/status` RPC 1745 endpoints. Before response time was growing linearly with height if no 1746 changes were made to the validator set. 1747 2) Fixes performance degradation in `ExecCommitBlock` where we call 1748 `LoadValidators` for each `Evidence` in the block. 1749 1750 ## v0.31.3 1751 1752 *April 1st, 2019* 1753 1754 This release includes two security sensitive fixes: it ensures generated private 1755 keys are valid, and it prevents certain DNS lookups that would cause the node to 1756 panic if the lookup failed. 1757 1758 ### BREAKING CHANGES: 1759 * Go API 1760 - [crypto/secp256k1] [\#3439](https://github.com/vipernet-xyz/tm/issues/3439) 1761 The `secp256k1.GenPrivKeySecp256k1` function has changed to guarantee that it returns a valid key, which means it 1762 will return a different private key than in previous versions for the same secret. 1763 1764 ### BUG FIXES: 1765 1766 - [crypto/secp256k1] [\#3439](https://github.com/vipernet-xyz/tm/issues/3439) 1767 Ensure generated private keys are valid by randomly sampling until a valid key is found. 1768 Previously, it was possible (though rare!) to generate keys that exceeded the curve order. 1769 Such keys would lead to invalid signatures. 1770 - [p2p] [\#3522](https://github.com/vipernet-xyz/tm/issues/3522) Memoize 1771 socket address in peer connections to avoid DNS lookups. Previously, failed 1772 DNS lookups could cause the node to panic. 1773 1774 ## v0.31.2 1775 1776 *March 30th, 2019* 1777 1778 This release fixes a regression from v0.31.1 where Tendermint panics under 1779 mempool load for external ABCI apps. 1780 1781 Special thanks to external contributors on this release: 1782 @guagualvcha 1783 1784 ### BREAKING CHANGES: 1785 1786 * CLI/RPC/Config 1787 1788 * Apps 1789 1790 * Go API 1791 - [libs/autofile] [\#3504](https://github.com/vipernet-xyz/tm/issues/3504) Remove unused code in autofile package. Deleted functions: `Group.Search`, `Group.FindLast`, `GroupReader.ReadLine`, `GroupReader.PushLine`, `MakeSimpleSearchFunc` (@guagualvcha) 1792 1793 * Blockchain Protocol 1794 1795 * P2P Protocol 1796 1797 ### FEATURES: 1798 1799 ### IMPROVEMENTS: 1800 1801 - [circle] [\#3497](https://github.com/vipernet-xyz/tm/issues/3497) Move release management to CircleCI 1802 1803 ### BUG FIXES: 1804 1805 - [mempool] [\#3512](https://github.com/vipernet-xyz/tm/issues/3512) Fix panic from concurrent access to txsMap, a regression for external ABCI apps introduced in v0.31.1 1806 1807 ## v0.31.1 1808 1809 *March 27th, 2019* 1810 1811 This release contains a major improvement for the mempool that reduce the amount of sent data by about 30% 1812 (see some numbers below). 1813 It also fixes a memory leak in the mempool and adds TLS support to the RPC server by providing a certificate and key in the config. 1814 1815 Special thanks to external contributors on this release: 1816 @brapse, @guagualvcha, @HaoyangLiu, @needkane, @TraceBundy 1817 1818 ### BREAKING CHANGES: 1819 1820 * CLI/RPC/Config 1821 1822 * Apps 1823 1824 * Go API 1825 - [crypto] [\#3426](https://github.com/vipernet-xyz/tm/pull/3426) Remove `Ripemd160` helper method (@needkane) 1826 - [libs/common] [\#3429](https://github.com/vipernet-xyz/tm/pull/3429) Remove `RepeatTimer` (also `TimerMaker` and `Ticker` interface) 1827 - [rpc/client] [\#3458](https://github.com/vipernet-xyz/tm/issues/3458) Include `NetworkClient` interface into `Client` interface 1828 - [types] [\#3448](https://github.com/vipernet-xyz/tm/issues/3448) Remove method `PB2TM.ConsensusParams` 1829 1830 * Blockchain Protocol 1831 1832 * P2P Protocol 1833 1834 ### FEATURES: 1835 1836 - [rpc] [\#3419](https://github.com/vipernet-xyz/tm/issues/3419) Start HTTPS server if `rpc.tls_cert_file` and `rpc.tls_key_file` are provided in the config (@guagualvcha) 1837 1838 ### IMPROVEMENTS: 1839 1840 - [docs] [\#3140](https://github.com/vipernet-xyz/tm/issues/3140) Formalize proposer election algorithm properties 1841 - [docs] [\#3482](https://github.com/vipernet-xyz/tm/issues/3482) Fix broken links (@brapse) 1842 - [mempool] [\#2778](https://github.com/vipernet-xyz/tm/issues/2778) No longer send txs back to peers who sent it to you. 1843 Also, limit to 65536 active peers. 1844 This vastly improves the bandwidth consumption of nodes. 1845 For instance, for a 4 node localnet, in a test sending 250byte txs for 120 sec. at 500 txs/sec (total of 15MB): 1846 - total bytes received from 1st node: 1847 - before: 42793967 (43MB) 1848 - after: 30003256 (30MB) 1849 - total bytes sent to 1st node: 1850 - before: 30569339 (30MB) 1851 - after: 19304964 (19MB) 1852 - [p2p] [\#3475](https://github.com/vipernet-xyz/tm/issues/3475) Simplify `GetSelectionWithBias` for addressbook (@guagualvcha) 1853 - [rpc/lib/client] [\#3430](https://github.com/vipernet-xyz/tm/issues/3430) Disable compression for HTTP client to prevent GZIP-bomb DoS attacks (@guagualvcha) 1854 1855 ### BUG FIXES: 1856 1857 - [blockchain] [\#2699](https://github.com/vipernet-xyz/tm/issues/2699) Update the maxHeight when a peer is removed 1858 - [mempool] [\#3478](https://github.com/vipernet-xyz/tm/issues/3478) Fix memory-leak related to `broadcastTxRoutine` (@HaoyangLiu) 1859 1860 1861 ## v0.31.0 1862 1863 *March 16th, 2019* 1864 1865 Special thanks to external contributors on this release: 1866 @danil-lashin, @guagualvcha, @siburu, @silasdavis, @srmo, @Stumble, @svenstaro 1867 1868 This release is primarily about the new pubsub implementation, dubbed `pubsub 2.0`, and related changes, 1869 like configurable limits on the number of active RPC subscriptions at a time (`max_subscription_clients`). 1870 Pubsub 2.0 is an improved version of the older pubsub that is non-blocking and has a nicer API. 1871 Note the improved pubsub API also resulted in some improvements to the HTTPClient interface and the API for WebSocket subscriptions. 1872 This release also adds a configurable limit to the mempool size (`max_txs_bytes`, default 1GB) 1873 and a configurable timeout for the `/broadcast_tx_commit` endpoint. 1874 1875 See the [v0.31.0 1876 Milestone](https://github.com/vipernet-xyz/tm/milestone/19?closed=1) for 1877 more details. 1878 1879 ### BREAKING CHANGES: 1880 1881 * CLI/RPC/Config 1882 - [config] [\#2920](https://github.com/vipernet-xyz/tm/issues/2920) Remove `consensus.blocktime_iota` parameter 1883 - [rpc] [\#3227](https://github.com/vipernet-xyz/tm/issues/3227) New PubSub design does not block on clients when publishing 1884 messages. Slow clients may miss messages and receive an error, terminating 1885 the subscription. 1886 - [rpc] [\#3269](https://github.com/vipernet-xyz/tm/issues/2826) Limit number of unique clientIDs with open subscriptions. Configurable via `rpc.max_subscription_clients` 1887 - [rpc] [\#3269](https://github.com/vipernet-xyz/tm/issues/2826) Limit number of unique queries a given client can subscribe to at once. Configurable via `rpc.max_subscriptions_per_client`. 1888 - [rpc] [\#3435](https://github.com/vipernet-xyz/tm/issues/3435) Default ReadTimeout and WriteTimeout changed to 10s. WriteTimeout can increased by setting `rpc.timeout_broadcast_tx_commit` in the config. 1889 - [rpc/client] [\#3269](https://github.com/vipernet-xyz/tm/issues/3269) Update `EventsClient` interface to reflect new pubsub/eventBus API [ADR-33](https://github.com/vipernet-xyz/tm/blob/main/docs/architecture/adr-033-pubsub.md). This includes `Subscribe`, `Unsubscribe`, and `UnsubscribeAll` methods. 1890 1891 * Apps 1892 - [abci] [\#3403](https://github.com/vipernet-xyz/tm/issues/3403) Remove `time_iota_ms` from BlockParams. This is a 1893 ConsensusParam but need not be exposed to the app for now. 1894 - [abci] [\#2920](https://github.com/vipernet-xyz/tm/issues/2920) Rename `consensus_params.block_size` to `consensus_params.block` in ABCI ConsensusParams 1895 1896 * Go API 1897 - [libs/common] TrapSignal accepts logger as a first parameter and does not block anymore 1898 * previously it was dumping "captured ..." msg to os.Stdout 1899 * TrapSignal should not be responsible for blocking thread of execution 1900 - [libs/db] [\#3397](https://github.com/vipernet-xyz/tm/pull/3397) Add possibility to `Close()` `Batch` to prevent memory leak when using ClevelDB. (@Stumble) 1901 - [types] [\#3354](https://github.com/vipernet-xyz/tm/issues/3354) Remove RoundState from EventDataRoundState 1902 - [rpc] [\#3435](https://github.com/vipernet-xyz/tm/issues/3435) `StartHTTPServer` / `StartHTTPAndTLSServer` now require a Config (use `rpcserver.DefaultConfig`) 1903 1904 * Blockchain Protocol 1905 1906 * P2P Protocol 1907 1908 ### FEATURES: 1909 - [config] [\#3269](https://github.com/vipernet-xyz/tm/issues/2826) New configuration values for controlling RPC subscriptions: 1910 - `rpc.max_subscription_clients` sets the maximum number of unique clients 1911 with open subscriptions 1912 - `rpc.max_subscriptions_per_client`sets the maximum number of unique 1913 subscriptions from a given client 1914 - `rpc.timeout_broadcast_tx_commit` sets the time to wait for a tx to be committed during `/broadcast_tx_commit` 1915 - [types] [\#2920](https://github.com/vipernet-xyz/tm/issues/2920) Add `time_iota_ms` to block's consensus parameters (not exposed to the application) 1916 - [lite] [\#3269](https://github.com/vipernet-xyz/tm/issues/3269) Add `/unsubscribe_all` endpoint to unsubscribe from all events 1917 - [mempool] [\#3079](https://github.com/vipernet-xyz/tm/issues/3079) Bound mempool memory usage via the `mempool.max_txs_bytes` configuration value. Set to 1GB by default. The mempool's current `txs_total_bytes` is exposed via `total_bytes` field in 1918 `/num_unconfirmed_txs` and `/unconfirmed_txs` RPC endpoints. 1919 1920 ### IMPROVEMENTS: 1921 - [all] [\#3385](https://github.com/vipernet-xyz/tm/issues/3385), [\#3386](https://github.com/vipernet-xyz/tm/issues/3386) Various linting improvements 1922 - [crypto] [\#3371](https://github.com/vipernet-xyz/tm/issues/3371) Copy in secp256k1 package from go-ethereum instead of importing 1923 go-ethereum (@silasdavis) 1924 - [deps] [\#3382](https://github.com/vipernet-xyz/tm/issues/3382) Don't pin repos without releases 1925 - [deps] [\#3357](https://github.com/vipernet-xyz/tm/issues/3357), [\#3389](https://github.com/vipernet-xyz/tm/issues/3389), [\#3392](https://github.com/vipernet-xyz/tm/issues/3392) Update gogo/protobuf, golang/protobuf, levigo, golang.org/x/crypto 1926 - [libs/common] [\#3238](https://github.com/vipernet-xyz/tm/issues/3238) exit with zero (0) code upon receiving SIGTERM/SIGINT 1927 - [libs/db] [\#3378](https://github.com/vipernet-xyz/tm/issues/3378) CLevelDB#Stats now returns the following properties: 1928 - leveldb.num-files-at-level{n} 1929 - leveldb.stats 1930 - leveldb.sstables 1931 - leveldb.blockpool 1932 - leveldb.cachedblock 1933 - leveldb.openedtables 1934 - leveldb.alivesnaps 1935 - leveldb.aliveiters 1936 - [privval] [\#3351](https://github.com/vipernet-xyz/tm/pull/3351) First part of larger refactoring that clarifies and separates concerns in the privval package. 1937 1938 ### BUG FIXES: 1939 - [blockchain] [\#3358](https://github.com/vipernet-xyz/tm/pull/3358) Fix timer leak in `BlockPool` (@guagualvcha) 1940 - [cmd] [\#3408](https://github.com/vipernet-xyz/tm/issues/3408) Fix `testnet` command's panic when creating non-validator configs (using `--n` flag) (@srmo) 1941 - [libs/db/remotedb/grpcdb] [\#3402](https://github.com/vipernet-xyz/tm/issues/3402) Close Iterator/ReverseIterator after use 1942 - [libs/pubsub] [\#951](https://github.com/vipernet-xyz/tm/issues/951), [\#1880](https://github.com/vipernet-xyz/tm/issues/1880) Use non-blocking send when dispatching messages [ADR-33](https://github.com/vipernet-xyz/tm/blob/main/docs/architecture/adr-033-pubsub.md) 1943 - [lite] [\#3364](https://github.com/vipernet-xyz/tm/issues/3364) Fix `/validators` and `/abci_query` proxy endpoints 1944 (@guagualvcha) 1945 - [p2p/conn] [\#3347](https://github.com/vipernet-xyz/tm/issues/3347) Reject all-zero shared secrets in the Diffie-Hellman step of secret-connection 1946 - [p2p] [\#3369](https://github.com/vipernet-xyz/tm/issues/3369) Do not panic when filter times out 1947 - [p2p] [\#3359](https://github.com/vipernet-xyz/tm/pull/3359) Fix reconnecting report duplicate ID error due to race condition between adding peer to peerSet and starting it (@guagualvcha) 1948 1949 ## v0.30.2 1950 1951 *March 10th, 2019* 1952 1953 This release fixes a CLevelDB memory leak. It was happening because we were not 1954 closing the WriteBatch object after use. See [levigo's 1955 godoc](https://godoc.org/github.com/jmhodges/levigo#WriteBatch.Close) for the 1956 Close method. Special thanks goes to @Stumble who both reported an issue in 1957 [cosmos-sdk](https://github.com/cosmos/cosmos-sdk/issues/3842) and provided a 1958 fix here. 1959 1960 ### BREAKING CHANGES: 1961 1962 * Go API 1963 - [libs/db] [\#3842](https://github.com/cosmos/cosmos-sdk/issues/3842) Add Close() method to Batch interface (@Stumble) 1964 1965 ### BUG FIXES: 1966 - [libs/db] [\#3842](https://github.com/cosmos/cosmos-sdk/issues/3842) Fix CLevelDB memory leak (@Stumble) 1967 1968 ## v0.30.1 1969 1970 *February 20th, 2019* 1971 1972 This release fixes a consensus halt and a DataCorruptionError after restart 1973 discovered in `game_of_stakes_6`. It also fixes a security issue in the p2p 1974 handshake by authenticating the NetAddress.ID of the peer we're dialing. 1975 1976 ### IMPROVEMENTS: 1977 1978 * [config] [\#3291](https://github.com/vipernet-xyz/tm/issues/3291) Make 1979 config.ResetTestRootWithChainID() create concurrency-safe test directories. 1980 1981 ### BUG FIXES: 1982 1983 * [consensus] [\#3295](https://github.com/vipernet-xyz/tm/issues/3295) 1984 Flush WAL on stop to prevent data corruption during graceful shutdown. 1985 * [consensus] [\#3302](https://github.com/vipernet-xyz/tm/issues/3302) 1986 Fix possible halt by resetting TriggeredTimeoutPrecommit before starting next height. 1987 * [rpc] [\#3251](https://github.com/vipernet-xyz/tm/issues/3251) Fix 1988 `/net_info#peers#remote_ip` format. New format spec: 1989 * dotted decimal ("192.0.2.1"), if ip is an IPv4 or IP4-mapped IPv6 address 1990 * IPv6 ("2001:db8::1"), if ip is a valid IPv6 address 1991 * [cmd] [\#3314](https://github.com/vipernet-xyz/tm/issues/3314) Return 1992 an error on `show_validator` when the private validator file does not exist. 1993 * [p2p] [\#3010](https://github.com/vipernet-xyz/tm/issues/3010#issuecomment-464287627) 1994 Authenticate a peer against its NetAddress.ID when dialing. 1995 1996 ## v0.30.0 1997 1998 *February 8th, 2019* 1999 2000 This release fixes yet another issue with the proposer selection algorithm. 2001 We hope it's the last one, but we won't be surprised if it's not. 2002 We plan to one day expose the selection algorithm more directly to 2003 the application ([\#3285](https://github.com/vipernet-xyz/tm/issues/3285)), and even to support randomness ([\#763](https://github.com/vipernet-xyz/tm/issues/763)). 2004 For more, see issues marked 2005 [proposer-selection](https://github.com/vipernet-xyz/tm/labels/proposer-selection). 2006 2007 This release also includes a fix to prevent Tendermint from including the same 2008 piece of evidence in more than one block. This issue was reported by @chengwenxi in our 2009 [bug bounty program](https://hackerone.com/cosmos). 2010 2011 ### BREAKING CHANGES: 2012 2013 * Apps 2014 - [state] [\#3222](https://github.com/vipernet-xyz/tm/issues/3222) 2015 Duplicate updates for the same validator are forbidden. Apps must ensure 2016 that a given `ResponseEndBlock.ValidatorUpdates` contains only one entry per pubkey. 2017 2018 * Go API 2019 - [types] [\#3222](https://github.com/vipernet-xyz/tm/issues/3222) 2020 Remove `Add` and `Update` methods from `ValidatorSet` in favor of new 2021 `UpdateWithChangeSet`. This allows updates to be applied as a set, instead of 2022 one at a time. 2023 2024 * Block Protocol 2025 - [state] [\#3286](https://github.com/vipernet-xyz/tm/issues/3286) Blocks that include already committed evidence are invalid. 2026 2027 * P2P Protocol 2028 - [consensus] [\#3222](https://github.com/vipernet-xyz/tm/issues/3222) 2029 Validator updates are applied as a set, instead of one at a time, thus 2030 impacting the proposer priority calculation. This ensures that the proposer 2031 selection algorithm does not depend on the order of updates in 2032 `ResponseEndBlock.ValidatorUpdates`. 2033 2034 ### IMPROVEMENTS: 2035 - [crypto] [\#3279](https://github.com/vipernet-xyz/tm/issues/3279) Use `btcec.S256().N` directly instead of hard coding a copy. 2036 2037 ### BUG FIXES: 2038 - [state] [\#3222](https://github.com/vipernet-xyz/tm/issues/3222) Fix validator set updates so they are applied as a set, rather 2039 than one at a time. This makes the proposer selection algorithm independent of 2040 the order of updates in `ResponseEndBlock.ValidatorUpdates`. 2041 - [evidence] [\#3286](https://github.com/vipernet-xyz/tm/issues/3286) Don't add committed evidence to evidence pool. 2042 2043 ## v0.29.2 2044 2045 *February 7th, 2019* 2046 2047 Special thanks to external contributors on this release: 2048 @ackratos, @rickyyangz 2049 2050 **Note**: This release contains security sensitive patches in the `p2p` and 2051 `crypto` packages: 2052 - p2p: 2053 - Partial fix for MITM attacks on the p2p connection. MITM conditions may 2054 still exist. See [\#3010](https://github.com/vipernet-xyz/tm/issues/3010). 2055 - crypto: 2056 - Eliminate our fork of `btcd` and use the `btcd/btcec` library directly for 2057 native secp256k1 signing. Note we still modify the signature encoding to 2058 prevent malleability. 2059 - Support the libsecp256k1 library via CGo through the `go-ethereum/crypto/secp256k1` package. 2060 - Eliminate MixEntropy functions 2061 2062 ### BREAKING CHANGES: 2063 2064 * Go API 2065 - [crypto] [\#3278](https://github.com/vipernet-xyz/tm/issues/3278) Remove 2066 MixEntropy functions 2067 - [types] [\#3245](https://github.com/vipernet-xyz/tm/issues/3245) Commit uses `type CommitSig Vote` instead of `Vote` directly. 2068 In preparation for removing redundant fields from the commit [\#1648](https://github.com/vipernet-xyz/tm/issues/1648) 2069 2070 ### IMPROVEMENTS: 2071 - [consensus] [\#3246](https://github.com/vipernet-xyz/tm/issues/3246) Better logging and notes on recovery for corrupted WAL file 2072 - [crypto] [\#3163](https://github.com/vipernet-xyz/tm/issues/3163) Use ethereum's libsecp256k1 go-wrapper for signatures when cgo is available 2073 - [crypto] [\#3162](https://github.com/vipernet-xyz/tm/issues/3162) Wrap btcd instead of forking it to keep up with fixes (used if cgo is not available) 2074 - [makefile] [\#3233](https://github.com/vipernet-xyz/tm/issues/3233) Use golangci-lint instead of go-metalinter 2075 - [tools] [\#3218](https://github.com/vipernet-xyz/tm/issues/3218) Add go-deadlock tool to help detect deadlocks 2076 - [tools] [\#3106](https://github.com/vipernet-xyz/tm/issues/3106) Add tm-signer-harness test harness for remote signers 2077 - [tests] [\#3258](https://github.com/vipernet-xyz/tm/issues/3258) Fixed a bunch of non-deterministic test failures 2078 2079 ### BUG FIXES: 2080 - [node] [\#3186](https://github.com/vipernet-xyz/tm/issues/3186) EventBus and indexerService should be started before first block (for replay last block on handshake) execution (@ackratos) 2081 - [p2p] [\#3232](https://github.com/vipernet-xyz/tm/issues/3232) Fix infinite loop leading to addrbook deadlock for seed nodes 2082 - [p2p] [\#3247](https://github.com/vipernet-xyz/tm/issues/3247) Fix panic in SeedMode when calling FlushStop and OnStop 2083 concurrently 2084 - [p2p] [\#3040](https://github.com/vipernet-xyz/tm/issues/3040) Fix MITM on secret connection by checking low-order points 2085 - [privval] [\#3258](https://github.com/vipernet-xyz/tm/issues/3258) Fix race between sign requests and ping requests in socket that was causing messages to be corrupted 2086 2087 ## v0.29.1 2088 2089 *January 24, 2019* 2090 2091 Special thanks to external contributors on this release: 2092 @infinytum, @gauthamzz 2093 2094 This release contains two important fixes: one for p2p layer where we sometimes 2095 were not closing connections and one for consensus layer where consensus with 2096 no empty blocks (`create_empty_blocks = false`) could halt. 2097 2098 ### IMPROVEMENTS: 2099 - [pex] [\#3037](https://github.com/vipernet-xyz/tm/issues/3037) Only log "Reached max attempts to dial" once 2100 - [rpc] [\#3159](https://github.com/vipernet-xyz/tm/issues/3159) Expose 2101 `triggered_timeout_commit` in the `/dump_consensus_state` 2102 2103 ### BUG FIXES: 2104 - [consensus] [\#3199](https://github.com/vipernet-xyz/tm/issues/3199) Fix consensus halt with no empty blocks from not resetting triggeredTimeoutCommit 2105 - [p2p] [\#2967](https://github.com/vipernet-xyz/tm/issues/2967) Fix file descriptor leak 2106 2107 ## v0.29.0 2108 2109 *January 21, 2019* 2110 2111 Special thanks to external contributors on this release: 2112 @bradyjoestar, @kunaldhariwal, @gauthamzz, @hrharder 2113 2114 This release is primarily about making some breaking changes to 2115 the Block protocol version before Cosmos launch, and to fixing more issues 2116 in the proposer selection algorithm discovered on Cosmos testnets. 2117 2118 The Block protocol changes include using a standard Merkle tree format (RFC 6962), 2119 fixing some inconsistencies between field orders in Vote and Proposal structs, 2120 and constraining the hash of the ConsensusParams to include only a few fields. 2121 2122 The proposer selection algorithm saw significant progress, 2123 including a [formal proof by @cwgoes for the base-case in Idris](https://github.com/cwgoes/tm-proposer-idris) 2124 and a [much more detailed specification (still in progress) by 2125 @ancazamfir](https://github.com/vipernet-xyz/tm/pull/3140). 2126 2127 Fixes to the proposer selection algorithm include normalizing the proposer 2128 priorities to mitigate the effects of large changes to the validator set. 2129 That said, we just discovered [another bug](https://github.com/vipernet-xyz/tm/issues/3181), 2130 which will be fixed in the next breaking release. 2131 2132 While we are trying to stabilize the Block protocol to preserve compatibility 2133 with old chains, there may be some final changes yet to come before Cosmos 2134 launch as we continue to audit and test the software. 2135 2136 ### BREAKING CHANGES: 2137 2138 * CLI/RPC/Config 2139 2140 * Apps 2141 - [state] [\#3049](https://github.com/vipernet-xyz/tm/issues/3049) Total voting power of the validator set is upper bounded by 2142 `MaxInt64 / 8`. Apps must ensure they do not return changes to the validator 2143 set that cause this maximum to be exceeded. 2144 2145 * Go API 2146 - [node] [\#3082](https://github.com/vipernet-xyz/tm/issues/3082) MetricsProvider now requires you to pass a chain ID 2147 - [types] [\#2713](https://github.com/vipernet-xyz/tm/issues/2713) Rename `TxProof.LeafHash` to `TxProof.Leaf` 2148 - [crypto/merkle] [\#2713](https://github.com/vipernet-xyz/tm/issues/2713) `SimpleProof.Verify` takes a `leaf` instead of a 2149 `leafHash` and performs the hashing itself 2150 2151 * Blockchain Protocol 2152 * [crypto/merkle] [\#2713](https://github.com/vipernet-xyz/tm/issues/2713) Merkle trees now match the RFC 6962 specification 2153 * [types] [\#3078](https://github.com/vipernet-xyz/tm/issues/3078) Re-order Timestamp and BlockID in CanonicalVote so it's 2154 consistent with CanonicalProposal (BlockID comes 2155 first) 2156 * [types] [\#3165](https://github.com/vipernet-xyz/tm/issues/3165) Hash of ConsensusParams only includes BlockSize.MaxBytes and 2157 BlockSize.MaxGas 2158 2159 * P2P Protocol 2160 - [consensus] [\#3049](https://github.com/vipernet-xyz/tm/issues/3049) Normalize priorities to not exceed `2*TotalVotingPower` to mitigate unfair proposer selection 2161 heavily preferring earlier joined validators in the case of an early bonded large validator unbonding 2162 2163 ### FEATURES: 2164 2165 ### IMPROVEMENTS: 2166 - [rpc] [\#3065](https://github.com/vipernet-xyz/tm/issues/3065) Return maxPerPage (100), not defaultPerPage (30) if `per_page` is greater than the max 100. 2167 - [instrumentation] [\#3082](https://github.com/vipernet-xyz/tm/issues/3082) Add `chain_id` label for all metrics 2168 2169 ### BUG FIXES: 2170 - [crypto] [\#3164](https://github.com/vipernet-xyz/tm/issues/3164) Update `btcd` fork for rare signRFC6979 bug 2171 - [lite] [\#3171](https://github.com/vipernet-xyz/tm/issues/3171) Fix verifying large validator set changes 2172 - [log] [\#3125](https://github.com/vipernet-xyz/tm/issues/3125) Fix year format 2173 - [mempool] [\#3168](https://github.com/vipernet-xyz/tm/issues/3168) Limit tx size to fit in the max reactor msg size 2174 - [scripts] [\#3147](https://github.com/vipernet-xyz/tm/issues/3147) Fix json2wal for large block parts (@bradyjoestar) 2175 2176 ## v0.28.1 2177 2178 *January 18th, 2019* 2179 2180 Special thanks to external contributors on this release: 2181 @HaoyangLiu 2182 2183 ### BUG FIXES: 2184 - [consensus] Fix consensus halt from proposing blocks with too much evidence 2185 2186 ## v0.28.0 2187 2188 *January 16th, 2019* 2189 2190 Special thanks to external contributors on this release: 2191 @fmauricios, @gianfelipe93, @husio, @needkane, @srmo, @yutianwu 2192 2193 This release is primarily about upgrades to the `privval` system - 2194 separating the `priv_validator.json` into distinct config and data files, and 2195 refactoring the socket validator to support reconnections. 2196 2197 **Note:** Please backup your existing `priv_validator.json` before using this 2198 version. 2199 2200 See [UPGRADING.md](UPGRADING.md) for more details. 2201 2202 ### BREAKING CHANGES: 2203 2204 * CLI/RPC/Config 2205 - [cli] Removed `--proxy_app=dummy` option. Use `kvstore` (`persistent_kvstore`) instead. 2206 - [cli] Renamed `--proxy_app=nilapp` to `--proxy_app=noop`. 2207 - [config] [\#2992](https://github.com/vipernet-xyz/tm/issues/2992) `allow_duplicate_ip` is now set to false 2208 - [privval] [\#1181](https://github.com/vipernet-xyz/tm/issues/1181) Split `priv_validator.json` into immutable (`config/priv_validator_key.json`) and mutable (`data/priv_validator_state.json`) parts (@yutianwu) 2209 - [privval] [\#2926](https://github.com/vipernet-xyz/tm/issues/2926) Split up `PubKeyMsg` into `PubKeyRequest` and `PubKeyResponse` to be consistent with other message types 2210 - [privval] [\#2923](https://github.com/vipernet-xyz/tm/issues/2923) Listen for unix socket connections instead of dialing them 2211 2212 * Apps 2213 2214 * Go API 2215 - [types] [\#2981](https://github.com/vipernet-xyz/tm/issues/2981) Remove `PrivValidator.GetAddress()` 2216 2217 * Blockchain Protocol 2218 2219 * P2P Protocol 2220 2221 ### FEATURES: 2222 - [rpc] [\#3052](https://github.com/vipernet-xyz/tm/issues/3052) Include peer's remote IP in `/net_info` 2223 2224 ### IMPROVEMENTS: 2225 - [consensus] [\#3086](https://github.com/vipernet-xyz/tm/issues/3086) Log peerID on ignored votes (@srmo) 2226 - [docs] [\#3061](https://github.com/vipernet-xyz/tm/issues/3061) Added specification for signing consensus msgs at 2227 ./docs/spec/consensus/signing.md 2228 - [privval] [\#2948](https://github.com/vipernet-xyz/tm/issues/2948) Memoize pubkey so it's only requested once on startup 2229 - [privval] [\#2923](https://github.com/vipernet-xyz/tm/issues/2923) Retry RemoteSigner connections on error 2230 2231 ### BUG FIXES: 2232 2233 - [build] [\#3085](https://github.com/vipernet-xyz/tm/issues/3085) Fix `Version` field in build scripts (@husio) 2234 - [crypto/multisig] [\#3102](https://github.com/vipernet-xyz/tm/issues/3102) Fix multisig keys address length 2235 - [crypto/encoding] [\#3101](https://github.com/vipernet-xyz/tm/issues/3101) Fix `PubKeyMultisigThreshold` unmarshalling into `crypto.PubKey` interface 2236 - [p2p/conn] [\#3111](https://github.com/vipernet-xyz/tm/issues/3111) Make SecretConnection thread safe 2237 - [rpc] [\#3053](https://github.com/vipernet-xyz/tm/issues/3053) Fix internal error in `/tx_search` when results are empty 2238 (@gianfelipe93) 2239 - [types] [\#2926](https://github.com/vipernet-xyz/tm/issues/2926) Do not panic if retrieving the privval's public key fails 2240 2241 ## v0.27.4 2242 2243 *December 21st, 2018* 2244 2245 ### BUG FIXES: 2246 2247 - [mempool] [\#3036](https://github.com/vipernet-xyz/tm/issues/3036) Fix 2248 LRU cache by popping the least recently used item when the cache is full, 2249 not the most recently used one! 2250 2251 ## v0.27.3 2252 2253 *December 16th, 2018* 2254 2255 ### BREAKING CHANGES: 2256 2257 * Go API 2258 - [dep] [\#3027](https://github.com/vipernet-xyz/tm/issues/3027) Revert to mainline Go crypto library, eliminating the modified 2259 `bcrypt.GenerateFromPassword` 2260 2261 ## v0.27.2 2262 2263 *December 16th, 2018* 2264 2265 ### IMPROVEMENTS: 2266 2267 - [node] [\#3025](https://github.com/vipernet-xyz/tm/issues/3025) Validate NodeInfo addresses on startup. 2268 2269 ### BUG FIXES: 2270 2271 - [p2p] [\#3025](https://github.com/vipernet-xyz/tm/pull/3025) Revert to using defers in addrbook. Fixes deadlocks in pex and consensus upon invalid ExternalAddr/ListenAddr configuration. 2272 2273 ## v0.27.1 2274 2275 *December 15th, 2018* 2276 2277 Special thanks to external contributors on this release: 2278 @danil-lashin, @hleb-albau, @james-ray, @leo-xinwang 2279 2280 ### FEATURES: 2281 - [rpc] [\#2964](https://github.com/vipernet-xyz/tm/issues/2964) Add `UnconfirmedTxs(limit)` and `NumUnconfirmedTxs()` methods to HTTP/Local clients (@danil-lashin) 2282 - [docs] [\#3004](https://github.com/vipernet-xyz/tm/issues/3004) Enable full-text search on docs pages 2283 2284 ### IMPROVEMENTS: 2285 - [consensus] [\#2971](https://github.com/vipernet-xyz/tm/issues/2971) Return error if ValidatorSet is empty after InitChain 2286 (@leo-xinwang) 2287 - [ci/cd] [\#3005](https://github.com/vipernet-xyz/tm/issues/3005) Updated CircleCI job to trigger website build when docs are updated 2288 - [docs] Various updates 2289 2290 ### BUG FIXES: 2291 - [cmd] [\#2983](https://github.com/vipernet-xyz/tm/issues/2983) `testnet` command always sets `addr_book_strict = false` 2292 - [config] [\#2980](https://github.com/vipernet-xyz/tm/issues/2980) Fix CORS options formatting 2293 - [kv indexer] [\#2912](https://github.com/vipernet-xyz/tm/issues/2912) Don't ignore key when executing CONTAINS 2294 - [mempool] [\#2961](https://github.com/vipernet-xyz/tm/issues/2961) Call `notifyTxsAvailable` if there're txs left after committing a block, but recheck=false 2295 - [mempool] [\#2994](https://github.com/vipernet-xyz/tm/issues/2994) Reject txs with negative GasWanted 2296 - [p2p] [\#2990](https://github.com/vipernet-xyz/tm/issues/2990) Fix a bug where seeds don't disconnect from a peer after 3h 2297 - [consensus] [\#3006](https://github.com/vipernet-xyz/tm/issues/3006) Save state after InitChain only when stateHeight is also 0 (@james-ray) 2298 2299 ## v0.27.0 2300 2301 *December 5th, 2018* 2302 2303 Special thanks to external contributors on this release: 2304 @danil-lashin, @srmo 2305 2306 Special thanks to @dlguddus for discovering a [major 2307 issue](https://github.com/vipernet-xyz/tm/issues/2718#issuecomment-440888677) 2308 in the proposer selection algorithm. 2309 2310 This release is primarily about fixes to the proposer selection algorithm 2311 in preparation for the [Cosmos Game of 2312 Stakes](https://blog.cosmos.network/the-game-of-stakes-is-open-for-registration-83a404746ee6). 2313 It also makes use of the `ConsensusParams.Validator.PubKeyTypes` to restrict the 2314 key types that can be used by validators, and removes the `Heartbeat` consensus 2315 message. 2316 2317 ### BREAKING CHANGES: 2318 2319 * CLI/RPC/Config 2320 - [rpc] [\#2932](https://github.com/vipernet-xyz/tm/issues/2932) Rename `accum` to `proposer_priority` 2321 2322 * Go API 2323 - [db] [\#2913](https://github.com/vipernet-xyz/tm/pull/2913) 2324 ReverseIterator API change: start < end, and end is exclusive. 2325 - [types] [\#2932](https://github.com/vipernet-xyz/tm/issues/2932) Rename `Validator.Accum` to `Validator.ProposerPriority` 2326 2327 * Blockchain Protocol 2328 - [state] [\#2714](https://github.com/vipernet-xyz/tm/issues/2714) Validators can now only use pubkeys allowed within 2329 ConsensusParams.Validator.PubKeyTypes 2330 2331 * P2P Protocol 2332 - [consensus] [\#2871](https://github.com/vipernet-xyz/tm/issues/2871) 2333 Remove *ProposalHeartbeat* message as it serves no real purpose (@srmo) 2334 - [state] Fixes for proposer selection: 2335 - [\#2785](https://github.com/vipernet-xyz/tm/issues/2785) Accum for new validators is `-1.125*totalVotingPower` instead of 0 2336 - [\#2941](https://github.com/vipernet-xyz/tm/issues/2941) val.Accum is preserved during ValidatorSet.Update to avoid being 2337 reset to 0 2338 2339 ### IMPROVEMENTS: 2340 2341 - [state] [\#2929](https://github.com/vipernet-xyz/tm/issues/2929) Minor refactor of updateState logic (@danil-lashin) 2342 - [node] [\#2959](https://github.com/vipernet-xyz/tm/issues/2959) Allow node to start even if software's BlockProtocol is 2343 different from state's BlockProtocol 2344 - [pex] [\#2959](https://github.com/vipernet-xyz/tm/issues/2959) Pex reactor logger uses `module=pex` 2345 2346 ### BUG FIXES: 2347 2348 - [p2p] [\#2968](https://github.com/vipernet-xyz/tm/issues/2968) Panic on transport error rather than continuing to run but not 2349 accept new connections 2350 - [p2p] [\#2969](https://github.com/vipernet-xyz/tm/issues/2969) Fix mismatch in peer count between `/net_info` and the prometheus 2351 metrics 2352 - [rpc] [\#2408](https://github.com/vipernet-xyz/tm/issues/2408) `/broadcast_tx_commit`: Fix "interface conversion: interface {} in nil, not EventDataTx" panic (could happen if somebody sent a tx using `/broadcast_tx_commit` while Tendermint was being stopped) 2353 - [state] [\#2785](https://github.com/vipernet-xyz/tm/issues/2785) Fix accum for new validators to be `-1.125*totalVotingPower` 2354 instead of 0, forcing them to wait before becoming the proposer. Also: 2355 - do not batch clip 2356 - keep accums averaged near 0 2357 - [txindex/kv] [\#2925](https://github.com/vipernet-xyz/tm/issues/2925) Don't return false positives when range searching for a prefix of a tag value 2358 - [types] [\#2938](https://github.com/vipernet-xyz/tm/issues/2938) Fix regression in v0.26.4 where we panic on empty 2359 genDoc.Validators 2360 - [types] [\#2941](https://github.com/vipernet-xyz/tm/issues/2941) Preserve val.Accum during ValidatorSet.Update to avoid it being 2361 reset to 0 every time a validator is updated 2362 2363 ## v0.26.4 2364 2365 *November 27th, 2018* 2366 2367 Special thanks to external contributors on this release: 2368 @ackratos, @goolAdapter, @james-ray, @joe-bowman, @kostko, 2369 @nagarajmanjunath, @tomtau 2370 2371 ### FEATURES: 2372 2373 - [rpc] [\#2747](https://github.com/vipernet-xyz/tm/issues/2747) Enable subscription to tags emitted from `BeginBlock`/`EndBlock` (@kostko) 2374 - [types] [\#2747](https://github.com/vipernet-xyz/tm/issues/2747) Add `ResultBeginBlock` and `ResultEndBlock` fields to `EventDataNewBlock` 2375 and `EventDataNewBlockHeader` to support subscriptions (@kostko) 2376 - [types] [\#2918](https://github.com/vipernet-xyz/tm/issues/2918) Add Marshal, MarshalTo, Unmarshal methods to various structs 2377 to support Protobuf compatibility (@nagarajmanjunath) 2378 2379 ### IMPROVEMENTS: 2380 2381 - [config] [\#2877](https://github.com/vipernet-xyz/tm/issues/2877) Add `blocktime_iota` to the config.toml (@ackratos) 2382 - NOTE: this should be a ConsensusParam, not part of the config, and will be 2383 removed from the config at a later date 2384 ([\#2920](https://github.com/vipernet-xyz/tm/issues/2920). 2385 - [mempool] [\#2882](https://github.com/vipernet-xyz/tm/issues/2882) Add txs from Update to cache 2386 - [mempool] [\#2891](https://github.com/vipernet-xyz/tm/issues/2891) Remove local int64 counter from being stored in every tx 2387 - [node] [\#2866](https://github.com/vipernet-xyz/tm/issues/2866) Add ability to instantiate IPCVal (@joe-bowman) 2388 2389 ### BUG FIXES: 2390 2391 - [blockchain] [\#2731](https://github.com/vipernet-xyz/tm/issues/2731) Retry both blocks if either is bad to avoid getting stuck during fast sync (@goolAdapter) 2392 - [consensus] [\#2893](https://github.com/vipernet-xyz/tm/issues/2893) Use genDoc.Validators instead of state.NextValidators on replay when appHeight==0 (@james-ray) 2393 - [log] [\#2868](https://github.com/vipernet-xyz/tm/issues/2868) Fix `module=main` setting overriding all others 2394 - NOTE: this changes the default logging behaviour to be much less verbose. 2395 Set `log_level="info"` to restore the previous behaviour. 2396 - [rpc] [\#2808](https://github.com/vipernet-xyz/tm/issues/2808) Fix `accum` field in `/validators` by calling `IncrementAccum` if necessary 2397 - [rpc] [\#2811](https://github.com/vipernet-xyz/tm/issues/2811) Allow integer IDs in JSON-RPC requests (@tomtau) 2398 - [txindex/kv] [\#2759](https://github.com/vipernet-xyz/tm/issues/2759) Fix tx.height range queries 2399 - [txindex/kv] [\#2775](https://github.com/vipernet-xyz/tm/issues/2775) Order tx results by index if height is the same 2400 - [txindex/kv] [\#2908](https://github.com/vipernet-xyz/tm/issues/2908) Don't return false positives when searching for a prefix of a tag value 2401 2402 ## v0.26.3 2403 2404 *November 17th, 2018* 2405 2406 Special thanks to external contributors on this release: 2407 @danil-lashin, @kevlubkcm, @krhubert, @srmo 2408 2409 ### BREAKING CHANGES: 2410 2411 * Go API 2412 - [rpc] [\#2791](https://github.com/vipernet-xyz/tm/issues/2791) Functions that start HTTP servers are now blocking: 2413 - Impacts `StartHTTPServer`, `StartHTTPAndTLSServer`, and `StartGRPCServer` 2414 - These functions now take a `net.Listener` instead of an address 2415 - [rpc] [\#2767](https://github.com/vipernet-xyz/tm/issues/2767) Subscribing to events 2416 `NewRound` and `CompleteProposal` return new types `EventDataNewRound` and 2417 `EventDataCompleteProposal`, respectively, instead of the generic `EventDataRoundState`. (@kevlubkcm) 2418 2419 ### FEATURES: 2420 2421 - [log] [\#2843](https://github.com/vipernet-xyz/tm/issues/2843) New `log_format` config option, which can be set to 'plain' for colored 2422 text or 'json' for JSON output 2423 - [types] [\#2767](https://github.com/vipernet-xyz/tm/issues/2767) New event types EventDataNewRound (with ProposerInfo) and EventDataCompleteProposal (with BlockID). (@kevlubkcm) 2424 2425 ### IMPROVEMENTS: 2426 2427 - [dep] [\#2844](https://github.com/vipernet-xyz/tm/issues/2844) Dependencies are no longer pinned to an exact version in the 2428 Gopkg.toml: 2429 - Serialization libs are allowed to vary by patch release 2430 - Other libs are allowed to vary by minor release 2431 - [p2p] [\#2857](https://github.com/vipernet-xyz/tm/issues/2857) "Send failed" is logged at debug level instead of error. 2432 - [rpc] [\#2780](https://github.com/vipernet-xyz/tm/issues/2780) Add read and write timeouts to HTTP servers 2433 - [state] [\#2848](https://github.com/vipernet-xyz/tm/issues/2848) Make "Update to validators" msg value pretty (@danil-lashin) 2434 2435 ### BUG FIXES: 2436 - [consensus] [\#2819](https://github.com/vipernet-xyz/tm/issues/2819) Don't send proposalHearbeat if not a validator 2437 - [docs] [\#2859](https://github.com/vipernet-xyz/tm/issues/2859) Fix ConsensusParams details in spec 2438 - [libs/autofile] [\#2760](https://github.com/vipernet-xyz/tm/issues/2760) Comment out autofile permissions check - should fix 2439 running Tendermint on Windows 2440 - [p2p] [\#2869](https://github.com/vipernet-xyz/tm/issues/2869) Set connection config properly instead of always using default 2441 - [p2p/pex] [\#2802](https://github.com/vipernet-xyz/tm/issues/2802) Seed mode fixes: 2442 - Only disconnect from inbound peers 2443 - Use FlushStop instead of Sleep to ensure all messages are sent before 2444 disconnecting 2445 2446 ## v0.26.2 2447 2448 *November 15th, 2018* 2449 2450 Special thanks to external contributors on this release: @hleb-albau, @zhuzeyu 2451 2452 ### FEATURES: 2453 2454 - [rpc] [\#2582](https://github.com/vipernet-xyz/tm/issues/2582) Enable CORS on RPC API (@hleb-albau) 2455 2456 ### BUG FIXES: 2457 2458 - [abci] [\#2748](https://github.com/vipernet-xyz/tm/issues/2748) Unlock mutex in localClient so even when app panics (e.g. during CheckTx), consensus continue working 2459 - [abci] [\#2748](https://github.com/vipernet-xyz/tm/issues/2748) Fix DATA RACE in localClient 2460 - [amino] [\#2822](https://github.com/vipernet-xyz/tm/issues/2822) Update to v0.14.1 to support compiling on 32-bit platforms 2461 - [rpc] [\#2748](https://github.com/vipernet-xyz/tm/issues/2748) Drain channel before calling Unsubscribe(All) in `/broadcast_tx_commit` 2462 2463 ## v0.26.1 2464 2465 *November 11, 2018* 2466 2467 Special thanks to external contributors on this release: @katakonst 2468 2469 ### IMPROVEMENTS: 2470 2471 - [consensus] [\#2704](https://github.com/vipernet-xyz/tm/issues/2704) Simplify valid POL round logic 2472 - [docs] [\#2749](https://github.com/vipernet-xyz/tm/issues/2749) Deduplicate some ABCI docs 2473 - [mempool] More detailed log messages 2474 - [\#2724](https://github.com/vipernet-xyz/tm/issues/2724) 2475 - [\#2762](https://github.com/vipernet-xyz/tm/issues/2762) 2476 2477 ### BUG FIXES: 2478 2479 - [autofile] [\#2703](https://github.com/vipernet-xyz/tm/issues/2703) Do not panic when checking Head size 2480 - [crypto/merkle] [\#2756](https://github.com/vipernet-xyz/tm/issues/2756) Fix crypto/merkle ProofOperators.Verify to check bounds on keypath parts. 2481 - [mempool] fix a bug where we create a WAL despite `wal_dir` being empty 2482 - [p2p] [\#2771](https://github.com/vipernet-xyz/tm/issues/2771) Fix `peer-id` label name to `peer_id` in prometheus metrics 2483 - [p2p] [\#2797](https://github.com/vipernet-xyz/tm/pull/2797) Fix IDs in peer NodeInfo and require them for addresses 2484 in AddressBook 2485 - [p2p] [\#2797](https://github.com/vipernet-xyz/tm/pull/2797) Do not close conn immediately after sending pex addrs in seed mode. Partial fix for [\#2092](https://github.com/vipernet-xyz/tm/issues/2092). 2486 2487 ## v0.26.0 2488 2489 *November 2, 2018* 2490 2491 Special thanks to external contributors on this release: 2492 @bradyjoestar, @connorwstein, @goolAdapter, @HaoyangLiu, 2493 @james-ray, @overbool, @phymbert, @Slamper, @Uzair1995, @yutianwu. 2494 2495 Special thanks to @Slamper for a series of bug reports in our [bug bounty 2496 program](https://hackerone.com/cosmos) which are fixed in this release. 2497 2498 This release is primarily about adding Version fields to various data structures, 2499 optimizing consensus messages for signing and verification in 2500 restricted environments (like HSMs and the Ethereum Virtual Machine), and 2501 aligning the consensus code with the [specification](https://arxiv.org/abs/1807.04938). 2502 It also includes our first take at a generalized merkle proof system, and 2503 changes the length of hashes used for hashing data structures from 20 to 32 2504 bytes. 2505 2506 See the [UPGRADING.md](UPGRADING.md#v0.26.0) for details on upgrading to the new 2507 version. 2508 2509 Please note that we are still making breaking changes to the protocols. 2510 While the new Version fields should help us to keep the software backwards compatible 2511 even while upgrading the protocols, we cannot guarantee that new releases will 2512 be compatible with old chains just yet. We expect there will be another breaking 2513 release or two before the Cosmos Hub launch, but we will otherwise be paying 2514 increasing attention to backwards compatibility. Thanks for bearing with us! 2515 2516 ### BREAKING CHANGES: 2517 2518 * CLI/RPC/Config 2519 * [config] [\#2232](https://github.com/vipernet-xyz/tm/issues/2232) Timeouts are now strings like "3s" and "100ms", not ints 2520 * [config] [\#2505](https://github.com/vipernet-xyz/tm/issues/2505) Remove Mempool.RecheckEmpty (it was effectively useless anyways) 2521 * [config] [\#2490](https://github.com/vipernet-xyz/tm/issues/2490) `mempool.wal` is disabled by default 2522 * [privval] [\#2459](https://github.com/vipernet-xyz/tm/issues/2459) Split `SocketPVMsg`s implementations into Request and Response, where the Response may contain a error message (returned by the remote signer) 2523 * [state] [\#2644](https://github.com/vipernet-xyz/tm/issues/2644) Add Version field to State, breaking the format of State as 2524 encoded on disk. 2525 * [rpc] [\#2298](https://github.com/vipernet-xyz/tm/issues/2298) `/abci_query` takes `prove` argument instead of `trusted` and switches the default 2526 behaviour to `prove=false` 2527 * [rpc] [\#2654](https://github.com/vipernet-xyz/tm/issues/2654) Remove all `node_info.other.*_version` fields in `/status` and 2528 `/net_info` 2529 * [rpc] [\#2636](https://github.com/vipernet-xyz/tm/issues/2636) Remove 2530 `_params` suffix from fields in `consensus_params`. 2531 2532 * Apps 2533 * [abci] [\#2298](https://github.com/vipernet-xyz/tm/issues/2298) ResponseQuery.Proof is now a structured merkle.Proof, not just 2534 arbitrary bytes 2535 * [abci] [\#2644](https://github.com/vipernet-xyz/tm/issues/2644) Add Version to Header and shift all fields by one 2536 * [abci] [\#2662](https://github.com/vipernet-xyz/tm/issues/2662) Bump the field numbers for some `ResponseInfo` fields to make room for 2537 `AppVersion` 2538 * [abci] [\#2636](https://github.com/vipernet-xyz/tm/issues/2636) Updates to ConsensusParams 2539 * Remove `Params` suffix from field names 2540 * Add `Params` suffix to message types 2541 * Add new field and type, `Validator ValidatorParams`, to control what types of validator keys are allowed. 2542 2543 * Go API 2544 * [config] [\#2232](https://github.com/vipernet-xyz/tm/issues/2232) Timeouts are time.Duration, not ints 2545 * [crypto/merkle & lite] [\#2298](https://github.com/vipernet-xyz/tm/issues/2298) Various changes to accomodate General Merkle trees 2546 * [crypto/merkle] [\#2595](https://github.com/vipernet-xyz/tm/issues/2595) Remove all Hasher objects in favor of byte slices 2547 * [crypto/merkle] [\#2635](https://github.com/vipernet-xyz/tm/issues/2635) merkle.SimpleHashFromTwoHashes is no longer exported 2548 * [node] [\#2479](https://github.com/vipernet-xyz/tm/issues/2479) Remove node.RunForever 2549 * [rpc/client] [\#2298](https://github.com/vipernet-xyz/tm/issues/2298) `ABCIQueryOptions.Trusted` -> `ABCIQueryOptions.Prove` 2550 * [types] [\#2298](https://github.com/vipernet-xyz/tm/issues/2298) Remove `Index` and `Total` fields from `TxProof`. 2551 * [types] [\#2598](https://github.com/vipernet-xyz/tm/issues/2598) 2552 `VoteTypeXxx` are now of type `SignedMsgType byte` and named `XxxType`, eg. 2553 `PrevoteType`, `PrecommitType`. 2554 * [types] [\#2636](https://github.com/vipernet-xyz/tm/issues/2636) Rename fields in ConsensusParams to remove `Params` suffixes 2555 * [types] [\#2735](https://github.com/vipernet-xyz/tm/issues/2735) Simplify Proposal message to align with spec 2556 2557 * Blockchain Protocol 2558 * [crypto/tmhash] [\#2732](https://github.com/vipernet-xyz/tm/issues/2732) TMHASH is now full 32-byte SHA256 2559 * All hashes in the block header and Merkle trees are now 32-bytes 2560 * PubKey Addresses are still only 20-bytes 2561 * [state] [\#2587](https://github.com/vipernet-xyz/tm/issues/2587) Require block.Time of the fist block to be genesis time 2562 * [state] [\#2644](https://github.com/vipernet-xyz/tm/issues/2644) Require block.Version to match state.Version 2563 * [types] Update SignBytes for `Vote`/`Proposal`/`Heartbeat`: 2564 * [\#2459](https://github.com/vipernet-xyz/tm/issues/2459) Use amino encoding instead of JSON in `SignBytes`. 2565 * [\#2598](https://github.com/vipernet-xyz/tm/issues/2598) Reorder fields and use fixed sized encoding. 2566 * [\#2598](https://github.com/vipernet-xyz/tm/issues/2598) Change `Type` field from `string` to `byte` and use new 2567 `SignedMsgType` to enumerate. 2568 * [types] [\#2730](https://github.com/vipernet-xyz/tm/issues/2730) Use 2569 same order for fields in `Vote` as in the SignBytes 2570 * [types] [\#2732](https://github.com/vipernet-xyz/tm/issues/2732) Remove the address field from the validator hash 2571 * [types] [\#2644](https://github.com/vipernet-xyz/tm/issues/2644) Add Version struct to Header 2572 * [types] [\#2609](https://github.com/vipernet-xyz/tm/issues/2609) ConsensusParams.Hash() is the hash of the amino encoded 2573 struct instead of the Merkle tree of the fields 2574 * [types] [\#2670](https://github.com/vipernet-xyz/tm/issues/2670) Header.Hash() builds Merkle tree out of fields in the same 2575 order they appear in the header, instead of sorting by field name 2576 * [types] [\#2682](https://github.com/vipernet-xyz/tm/issues/2682) Use proto3 `varint` encoding for ints that are usually unsigned (instead of zigzag encoding). 2577 * [types] [\#2636](https://github.com/vipernet-xyz/tm/issues/2636) Add Validator field to ConsensusParams 2578 (Used to control which pubkey types validators can use, by abci type). 2579 2580 * P2P Protocol 2581 * [consensus] [\#2652](https://github.com/vipernet-xyz/tm/issues/2652) 2582 Replace `CommitStepMessage` with `NewValidBlockMessage` 2583 * [consensus] [\#2735](https://github.com/vipernet-xyz/tm/issues/2735) Simplify `Proposal` message to align with spec 2584 * [consensus] [\#2730](https://github.com/vipernet-xyz/tm/issues/2730) 2585 Add `Type` field to `Proposal` and use same order of fields as in the 2586 SignBytes for both `Proposal` and `Vote` 2587 * [p2p] [\#2654](https://github.com/vipernet-xyz/tm/issues/2654) Add `ProtocolVersion` struct with protocol versions to top of 2588 DefaultNodeInfo and require `ProtocolVersion.Block` to match during peer handshake 2589 2590 2591 ### FEATURES: 2592 - [abci] [\#2557](https://github.com/vipernet-xyz/tm/issues/2557) Add `Codespace` field to `Response{CheckTx, DeliverTx, Query}` 2593 - [abci] [\#2662](https://github.com/vipernet-xyz/tm/issues/2662) Add `BlockVersion` and `P2PVersion` to `RequestInfo` 2594 - [crypto/merkle] [\#2298](https://github.com/vipernet-xyz/tm/issues/2298) General Merkle Proof scheme for chaining various types of Merkle trees together 2595 - [docs/architecture] [\#1181](https://github.com/vipernet-xyz/tm/issues/1181) S 2596 plit immutable and mutable parts of priv_validator.json 2597 2598 ### IMPROVEMENTS: 2599 - Additional Metrics 2600 - [consensus] [\#2169](https://github.com/cosmos/cosmos-sdk/issues/2169) 2601 - [p2p] [\#2169](https://github.com/cosmos/cosmos-sdk/issues/2169) 2602 - [config] [\#2232](https://github.com/vipernet-xyz/tm/issues/2232) Added ValidateBasic method, which performs basic checks 2603 - [crypto/ed25519] [\#2558](https://github.com/vipernet-xyz/tm/issues/2558) Switch to use latest `golang.org/x/crypto` through our fork at 2604 github.com/tendermint/crypto 2605 - [libs/log] [\#2707](https://github.com/vipernet-xyz/tm/issues/2707) Add year to log format (@yutianwu) 2606 - [tools] [\#2238](https://github.com/vipernet-xyz/tm/issues/2238) Binary dependencies are now locked to a specific git commit 2607 2608 ### BUG FIXES: 2609 - [\#2711](https://github.com/vipernet-xyz/tm/issues/2711) Validate all incoming reactor messages. Fixes various bugs due to negative ints. 2610 - [autofile] [\#2428](https://github.com/vipernet-xyz/tm/issues/2428) Group.RotateFile need call Flush() before rename (@goolAdapter) 2611 - [common] [\#2533](https://github.com/vipernet-xyz/tm/issues/2533) Fixed a bug in the `BitArray.Or` method 2612 - [common] [\#2506](https://github.com/vipernet-xyz/tm/issues/2506) Fixed a bug in the `BitArray.Sub` method (@james-ray) 2613 - [common] [\#2534](https://github.com/vipernet-xyz/tm/issues/2534) Fix `BitArray.PickRandom` to choose uniformly from true bits 2614 - [consensus] [\#1690](https://github.com/vipernet-xyz/tm/issues/1690) Wait for 2615 timeoutPrecommit before starting next round 2616 - [consensus] [\#1745](https://github.com/vipernet-xyz/tm/issues/1745) Wait for 2617 Proposal or timeoutProposal before entering prevote 2618 - [consensus] [\#2642](https://github.com/vipernet-xyz/tm/issues/2642) Only propose ValidBlock, not LockedBlock 2619 - [consensus] [\#2642](https://github.com/vipernet-xyz/tm/issues/2642) Initialized ValidRound and LockedRound to -1 2620 - [consensus] [\#1637](https://github.com/vipernet-xyz/tm/issues/1637) Limit the amount of evidence that can be included in a 2621 block 2622 - [consensus] [\#2652](https://github.com/vipernet-xyz/tm/issues/2652) Ensure valid block property with faulty proposer 2623 - [evidence] [\#2515](https://github.com/vipernet-xyz/tm/issues/2515) Fix db iter leak (@goolAdapter) 2624 - [libs/event] [\#2518](https://github.com/vipernet-xyz/tm/issues/2518) Fix event concurrency flaw (@goolAdapter) 2625 - [node] [\#2434](https://github.com/vipernet-xyz/tm/issues/2434) Make node respond to signal interrupts while sleeping for genesis time 2626 - [state] [\#2616](https://github.com/vipernet-xyz/tm/issues/2616) Pass nil to NewValidatorSet() when genesis file's Validators field is nil 2627 - [p2p] [\#2555](https://github.com/vipernet-xyz/tm/issues/2555) Fix p2p switch FlushThrottle value (@goolAdapter) 2628 - [p2p] [\#2668](https://github.com/vipernet-xyz/tm/issues/2668) Reconnect to originally dialed address (not self-reported address) for persistent peers 2629 2630 ## v0.25.0 2631 2632 *September 22, 2018* 2633 2634 Special thanks to external contributors on this release: 2635 @scriptionist, @bradyjoestar, @WALL-E 2636 2637 This release is mostly about the ConsensusParams - removing fields and enforcing MaxGas. 2638 It also addresses some issues found via security audit, removes various unused 2639 functions from `libs/common`, and implements 2640 [ADR-012](https://github.com/vipernet-xyz/tm/blob/main/docs/architecture/adr-012-peer-transport.md). 2641 2642 BREAKING CHANGES: 2643 2644 * CLI/RPC/Config 2645 * [rpc] [\#2391](https://github.com/vipernet-xyz/tm/issues/2391) /status `result.node_info.other` became a map 2646 * [types] [\#2364](https://github.com/vipernet-xyz/tm/issues/2364) Remove `TxSize` and `BlockGossip` from `ConsensusParams` 2647 * Maximum tx size is now set implicitly via the `BlockSize.MaxBytes` 2648 * The size of block parts in the consensus is now fixed to 64kB 2649 2650 * Apps 2651 * [mempool] [\#2360](https://github.com/vipernet-xyz/tm/issues/2360) Mempool tracks the `ResponseCheckTx.GasWanted` and 2652 `ConsensusParams.BlockSize.MaxGas` and enforces: 2653 - `GasWanted <= MaxGas` for every tx 2654 - `(sum of GasWanted in block) <= MaxGas` for block proposal 2655 2656 * Go API 2657 * [libs/common] [\#2431](https://github.com/vipernet-xyz/tm/issues/2431) Remove Word256 due to lack of use 2658 * [libs/common] [\#2452](https://github.com/vipernet-xyz/tm/issues/2452) Remove the following functions due to lack of use: 2659 * byteslice.go: cmn.IsZeros, cmn.RightPadBytes, cmn.LeftPadBytes, cmn.PrefixEndBytes 2660 * strings.go: cmn.IsHex, cmn.StripHex 2661 * int.go: Uint64Slice, all put/get int64 methods 2662 2663 FEATURES: 2664 - [rpc] [\#2415](https://github.com/vipernet-xyz/tm/issues/2415) New `/consensus_params?height=X` endpoint to query the consensus 2665 params at any height (@scriptonist) 2666 - [types] [\#1714](https://github.com/vipernet-xyz/tm/issues/1714) Add Address to GenesisValidator 2667 - [metrics] [\#2337](https://github.com/vipernet-xyz/tm/issues/2337) `consensus.block_interval_metrics` is now gauge, not histogram (you will be able to see spikes, if any) 2668 - [libs] [\#2286](https://github.com/vipernet-xyz/tm/issues/2286) Panic if `autofile` or `db/fsdb` permissions change from 0600. 2669 2670 IMPROVEMENTS: 2671 - [libs/db] [\#2371](https://github.com/vipernet-xyz/tm/issues/2371) Output error instead of panic when the given `db_backend` is not initialised (@bradyjoestar) 2672 - [mempool] [\#2399](https://github.com/vipernet-xyz/tm/issues/2399) Make mempool cache a proper LRU (@bradyjoestar) 2673 - [p2p] [\#2126](https://github.com/vipernet-xyz/tm/issues/2126) Introduce PeerTransport interface to improve isolation of concerns 2674 - [libs/common] [\#2326](https://github.com/vipernet-xyz/tm/issues/2326) Service returns ErrNotStarted 2675 2676 BUG FIXES: 2677 - [node] [\#2294](https://github.com/vipernet-xyz/tm/issues/2294) Delay starting node until Genesis time 2678 - [consensus] [\#2048](https://github.com/vipernet-xyz/tm/issues/2048) Correct peer statistics for marking peer as good 2679 - [rpc] [\#2460](https://github.com/vipernet-xyz/tm/issues/2460) StartHTTPAndTLSServer() now passes StartTLS() errors back to the caller rather than hanging forever. 2680 - [p2p] [\#2047](https://github.com/vipernet-xyz/tm/issues/2047) Accept new connections asynchronously 2681 - [tm-bench] [\#2410](https://github.com/vipernet-xyz/tm/issues/2410) Enforce minimum transaction size (@WALL-E) 2682 2683 ## 0.24.0 2684 2685 *September 6th, 2018* 2686 2687 Special thanks to external contributors with PRs included in this release: ackratos, james-ray, bradyjoestar, 2688 peerlink, Ahmah2009, bluele, b00f. 2689 2690 This release includes breaking upgrades in the block header, 2691 including the long awaited changes for delaying validator set updates by one 2692 block to better support light clients. 2693 It also fixes enforcement on the maximum size of blocks, and includes a BFT 2694 timestamp in each block that can be safely used by applications. 2695 There are also some minor breaking changes to the rpc, config, and ABCI. 2696 2697 See the [UPGRADING.md](UPGRADING.md#v0.24.0) for details on upgrading to the new 2698 version. 2699 2700 From here on, breaking changes will be broken down to better reflect how users 2701 are affected by a change. 2702 2703 A few more breaking changes are in the works - each will come with a clear 2704 Architecture Decision Record (ADR) explaining the change. You can review ADRs 2705 [here](https://github.com/vipernet-xyz/tm/tree/develop/docs/architecture) 2706 or in the [open Pull Requests](https://github.com/vipernet-xyz/tm/pulls). 2707 You can also check in on the [issues marked as 2708 breaking](https://github.com/vipernet-xyz/tm/issues?q=is%3Aopen+is%3Aissue+label%3Abreaking). 2709 2710 BREAKING CHANGES: 2711 2712 * CLI/RPC/Config 2713 - [config] [\#2169](https://github.com/vipernet-xyz/tm/issues/2169) Replace MaxNumPeers with MaxNumInboundPeers and MaxNumOutboundPeers 2714 - [config] [\#2300](https://github.com/vipernet-xyz/tm/issues/2300) Reduce default mempool size from 100k to 5k, until ABCI rechecking is implemented. 2715 - [rpc] [\#1815](https://github.com/vipernet-xyz/tm/issues/1815) `/commit` returns a `signed_header` field instead of everything being top-level 2716 2717 * Apps 2718 - [abci] Added address of the original proposer of the block to Header 2719 - [abci] Change ABCI Header to match Tendermint exactly 2720 - [abci] [\#2159](https://github.com/vipernet-xyz/tm/issues/2159) Update use of `Validator` (see 2721 [ADR-018](https://github.com/vipernet-xyz/tm/blob/main/docs/architecture/adr-018-ABCI-Validators.md)): 2722 - Remove PubKey from `Validator` (so it's just Address and Power) 2723 - Introduce `ValidatorUpdate` (with just PubKey and Power) 2724 - InitChain and EndBlock use ValidatorUpdate 2725 - Update field names and types in BeginBlock 2726 - [state] [\#1815](https://github.com/vipernet-xyz/tm/issues/1815) Validator set changes are now delayed by one block 2727 - updates returned in ResponseEndBlock for block H will be included in RequestBeginBlock for block H+2 2728 2729 * Go API 2730 - [lite] [\#1815](https://github.com/vipernet-xyz/tm/issues/1815) Complete refactor of the package 2731 - [node] [\#2212](https://github.com/vipernet-xyz/tm/issues/2212) NewNode now accepts a `*p2p.NodeKey` (@bradyjoestar) 2732 - [libs/common] [\#2199](https://github.com/vipernet-xyz/tm/issues/2199) Remove Fmt, in favor of fmt.Sprintf 2733 - [libs/common] SplitAndTrim was deleted 2734 - [libs/common] [\#2274](https://github.com/vipernet-xyz/tm/issues/2274) Remove unused Math functions like MaxInt, MaxInt64, 2735 MinInt, MinInt64 (@Ahmah2009) 2736 - [libs/clist] Panics if list extends beyond MaxLength 2737 - [crypto] [\#2205](https://github.com/vipernet-xyz/tm/issues/2205) Rename AminoRoute variables to no longer be prefixed by signature type. 2738 2739 * Blockchain Protocol 2740 - [state] [\#1815](https://github.com/vipernet-xyz/tm/issues/1815) Validator set changes are now delayed by one block (!) 2741 - Add NextValidatorSet to State, changes on-disk representation of state 2742 - [state] [\#2184](https://github.com/vipernet-xyz/tm/issues/2184) Enforce ConsensusParams.BlockSize.MaxBytes (See 2743 [ADR-020](https://github.com/vipernet-xyz/tm/blob/main/docs/architecture/adr-020-block-size.md)). 2744 - Remove ConsensusParams.BlockSize.MaxTxs 2745 - Introduce maximum sizes for all components of a block, including ChainID 2746 - [types] Updates to the block Header: 2747 - [\#1815](https://github.com/vipernet-xyz/tm/issues/1815) NextValidatorsHash - hash of the validator set for the next block, 2748 so the current validators actually sign over the hash for the new 2749 validators 2750 - [\#2106](https://github.com/vipernet-xyz/tm/issues/2106) ProposerAddress - address of the block's original proposer 2751 - [consensus] [\#2203](https://github.com/vipernet-xyz/tm/issues/2203) Implement BFT time 2752 - Timestamp in block must be monotonic and equal the median of timestamps in block's LastCommit 2753 - [crypto] [\#2239](https://github.com/vipernet-xyz/tm/issues/2239) Secp256k1 signature changes (See 2754 [ADR-014](https://github.com/vipernet-xyz/tm/blob/main/docs/architecture/adr-014-secp-malleability.md)): 2755 - format changed from DER to `r || s`, both little endian encoded as 32 bytes. 2756 - malleability removed by requiring `s` to be in canonical form. 2757 2758 * P2P Protocol 2759 - [p2p] [\#2263](https://github.com/vipernet-xyz/tm/issues/2263) Update secret connection to use a little endian encoded nonce 2760 - [blockchain] [\#2213](https://github.com/vipernet-xyz/tm/issues/2213) Fix Amino routes for blockchain reactor messages 2761 (@peerlink) 2762 2763 2764 FEATURES: 2765 - [types] [\#2015](https://github.com/vipernet-xyz/tm/issues/2015) Allow genesis file to have 0 validators (@b00f) 2766 - Initial validator set can be determined by the app in ResponseInitChain 2767 - [rpc] [\#2161](https://github.com/vipernet-xyz/tm/issues/2161) New event `ValidatorSetUpdates` for when the validator set changes 2768 - [crypto/multisig] [\#2164](https://github.com/vipernet-xyz/tm/issues/2164) Introduce multisig pubkey and signature format 2769 - [libs/db] [\#2293](https://github.com/vipernet-xyz/tm/issues/2293) Allow passing options through when creating instances of leveldb dbs 2770 2771 IMPROVEMENTS: 2772 - [docs] Lint documentation with `write-good` and `stop-words`. 2773 - [docs] [\#2249](https://github.com/vipernet-xyz/tm/issues/2249) Refactor, deduplicate, and improve the ABCI docs and spec (with thanks to @ttmc). 2774 - [scripts] [\#2196](https://github.com/vipernet-xyz/tm/issues/2196) Added json2wal tool, which is supposed to help our users restore (@bradyjoestar) 2775 corrupted WAL files and compose test WAL files (@bradyjoestar) 2776 - [mempool] [\#2234](https://github.com/vipernet-xyz/tm/issues/2234) Now stores txs by hash inside of the cache, to mitigate memory leakage 2777 - [mempool] [\#2166](https://github.com/vipernet-xyz/tm/issues/2166) Set explicit capacity for map when updating txs (@bluele) 2778 2779 BUG FIXES: 2780 - [config] [\#2284](https://github.com/vipernet-xyz/tm/issues/2284) Replace `db_path` with `db_dir` from automatically generated configuration files. 2781 - [mempool] [\#2188](https://github.com/vipernet-xyz/tm/issues/2188) Fix OOM issue from cache map and list getting out of sync 2782 - [state] [\#2051](https://github.com/vipernet-xyz/tm/issues/2051) KV store index supports searching by `tx.height` (@ackratos) 2783 - [rpc] [\#2327](https://github.com/vipernet-xyz/tm/issues/2327) `/dial_peers` does not try to dial existing peers 2784 - [node] [\#2323](https://github.com/vipernet-xyz/tm/issues/2323) Filter empty strings from config lists (@james-ray) 2785 - [abci/client] [\#2236](https://github.com/vipernet-xyz/tm/issues/2236) Fix closing GRPC connection (@bradyjoestar) 2786 2787 ## 0.23.1 2788 2789 *August 22nd, 2018* 2790 2791 BUG FIXES: 2792 - [libs/autofile] [\#2261](https://github.com/vipernet-xyz/tm/issues/2261) Fix log rotation so it actually happens. 2793 - Fixes issues with consensus WAL growing unbounded ala [\#2259](https://github.com/vipernet-xyz/tm/issues/2259) 2794 2795 ## 0.23.0 2796 2797 *August 5th, 2018* 2798 2799 This release includes breaking upgrades in our P2P encryption, 2800 some ABCI messages, and how we encode time and signatures. 2801 2802 A few more changes are still coming to the Header, ABCI, 2803 and validator set handling to better support light clients, BFT time, and 2804 upgrades. Most notably, validator set changes will be delayed by one block (see 2805 [#1815][i1815]). 2806 2807 We also removed `make ensure_deps` in favour of `make get_vendor_deps`. 2808 2809 BREAKING CHANGES: 2810 - [abci] Changed time format from int64 to google.protobuf.Timestamp 2811 - [abci] Changed Validators to LastCommitInfo in RequestBeginBlock 2812 - [abci] Removed Fee from ResponseDeliverTx and ResponseCheckTx 2813 - [crypto] Switch crypto.Signature from interface to []byte for space efficiency 2814 [#2128](https://github.com/vipernet-xyz/tm/pull/2128) 2815 - NOTE: this means signatures no longer have the prefix bytes in Amino 2816 binary nor the `type` field in Amino JSON. They're just bytes. 2817 - [p2p] Remove salsa and ripemd primitives, in favor of using chacha as a stream cipher, and hkdf [#2054](https://github.com/vipernet-xyz/tm/pull/2054) 2818 - [tools] Removed `make ensure_deps` in favor of `make get_vendor_deps` 2819 - [types] CanonicalTime uses nanoseconds instead of clipping to ms 2820 - breaks serialization/signing of all messages with a timestamp 2821 2822 FEATURES: 2823 - [tools] Added `make check_dep` 2824 - ensures gopkg.lock is synced with gopkg.toml 2825 - ensures no branches are used in the gopkg.toml 2826 2827 IMPROVEMENTS: 2828 - [blockchain] Improve fast-sync logic 2829 [#1805](https://github.com/vipernet-xyz/tm/pull/1805) 2830 - tweak params 2831 - only process one block at a time to avoid starving 2832 - [common] bit array functions which take in another parameter are now thread safe 2833 - [crypto] Switch hkdfchachapoly1305 to xchachapoly1305 2834 - [p2p] begin connecting to peers as soon a seed node provides them to you ([#2093](https://github.com/vipernet-xyz/tm/issues/2093)) 2835 2836 BUG FIXES: 2837 - [common] Safely handle cases where atomic write files already exist [#2109](https://github.com/vipernet-xyz/tm/issues/2109) 2838 - [privval] fix a deadline for accepting new connections in socket private 2839 validator. 2840 - [p2p] Allow startup if a configured seed node's IP can't be resolved ([#1716](https://github.com/vipernet-xyz/tm/issues/1716)) 2841 - [node] Fully exit when CTRL-C is pressed even if consensus state panics [#2072](https://github.com/vipernet-xyz/tm/issues/2072) 2842 2843 [i1815]: https://github.com/vipernet-xyz/tm/pull/1815 2844 2845 ## 0.22.8 2846 2847 *July 26th, 2018* 2848 2849 BUG FIXES 2850 2851 - [consensus, blockchain] Fix 0.22.7 below. 2852 2853 ## 0.22.7 2854 2855 *July 26th, 2018* 2856 2857 BUG FIXES 2858 2859 - [consensus, blockchain] Register the Evidence interface so it can be 2860 marshalled/unmarshalled by the blockchain and consensus reactors 2861 2862 ## 0.22.6 2863 2864 *July 24th, 2018* 2865 2866 BUG FIXES 2867 2868 - [rpc] Fix `/blockchain` endpoint 2869 - (#2049) Fix OOM attack by returning error on negative input 2870 - Fix result length to have max 20 (instead of 21) block metas 2871 - [rpc] Validate height is non-negative in `/abci_query` 2872 - [consensus] (#2050) Include evidence in proposal block parts (previously evidence was 2873 not being included in blocks!) 2874 - [p2p] (#2046) Close rejected inbound connections so file descriptor doesn't 2875 leak 2876 - [Gopkg] (#2053) Fix versions in the toml 2877 2878 ## 0.22.5 2879 2880 *July 23th, 2018* 2881 2882 BREAKING CHANGES: 2883 - [crypto] Refactor `tendermint/crypto` into many subpackages 2884 - [libs/common] remove exponentially distributed random numbers 2885 2886 IMPROVEMENTS: 2887 - [abci, libs/common] Generated gogoproto static marshaller methods 2888 - [config] Increase default send/recv rates to 5 mB/s 2889 - [p2p] reject addresses coming from private peers 2890 - [p2p] allow persistent peers to be private 2891 2892 BUG FIXES: 2893 - [mempool] fixed a race condition when `create_empty_blocks=false` where a 2894 transaction is published at an old height. 2895 - [p2p] dial external IP setup by `persistent_peers`, not internal NAT IP 2896 - [rpc] make `/status` RPC endpoint resistant to consensus halt 2897 2898 ## 0.22.4 2899 2900 *July 14th, 2018* 2901 2902 BREAKING CHANGES: 2903 - [genesis] removed deprecated `app_options` field. 2904 - [types] Genesis.AppStateJSON -> Genesis.AppState 2905 2906 FEATURES: 2907 - [tools] Merged in from github.com/tendermint/tools 2908 2909 BUG FIXES: 2910 - [tools/tm-bench] Various fixes 2911 - [consensus] Wait for WAL to stop on shutdown 2912 - [abci] Fix #1891, pending requests cannot hang when abci server dies. 2913 Previously a crash in BeginBlock could leave tendermint in broken state. 2914 2915 ## 0.22.3 2916 2917 *July 10th, 2018* 2918 2919 IMPROVEMENTS 2920 - Update dependencies 2921 * pin all values in Gopkg.toml to version or commit 2922 * update golang/protobuf to v1.1.0 2923 2924 ## 0.22.2 2925 2926 *July 10th, 2018* 2927 2928 IMPROVEMENTS 2929 - More cleanup post repo merge! 2930 - [docs] Include `ecosystem.json` and `tendermint-bft.md` from deprecated `aib-data` repository. 2931 - [config] Add `instrumentation.max_open_connections`, which limits the number 2932 of requests in flight to Prometheus server (if enabled). Default: 3. 2933 2934 2935 BUG FIXES 2936 - [rpc] Allow unquoted integers in requests 2937 - NOTE: this is only for URI requests. JSONRPC requests and all responses 2938 will use quoted integers (the proto3 JSON standard). 2939 - [consensus] Fix halt on shutdown 2940 2941 ## 0.22.1 2942 2943 *July 5th, 2018* 2944 2945 IMPROVEMENTS 2946 2947 * Cleanup post repo-merge. 2948 * [docs] Various improvements. 2949 2950 BUG FIXES 2951 2952 * [state] Return error when EndBlock returns a 0-power validator that isn't 2953 already in the validator set. 2954 * [consensus] Shut down WAL properly. 2955 2956 2957 ## 0.22.0 2958 2959 *July 2nd, 2018* 2960 2961 BREAKING CHANGES: 2962 - [config] 2963 * Remove `max_block_size_txs` and `max_block_size_bytes` in favor of 2964 consensus params from the genesis file. 2965 * Rename `skip_upnp` to `upnp`, and turn it off by default. 2966 * Change `max_packet_msg_size` back to `max_packet_msg_payload_size` 2967 - [rpc] 2968 * All integers are encoded as strings (part of the update for Amino v0.10.1) 2969 * `syncing` is now called `catching_up` 2970 - [types] Update Amino to v0.10.1 2971 * Amino is now fully proto3 compatible for the basic types 2972 * JSON-encoded types now use the type name instead of the prefix bytes 2973 * Integers are encoded as strings 2974 - [crypto] Update go-crypto to v0.10.0 and merge into `crypto` 2975 * privKey.Sign returns error. 2976 * ed25519 address changed to the first 20-bytes of the SHA256 of the raw pubkey bytes 2977 * `tmlibs/merkle` -> `crypto/merkle`. Uses SHA256 instead of RIPEMD160 2978 - [tmlibs] Update to v0.9.0 and merge into `libs` 2979 * remove `merkle` package (moved to `crypto/merkle`) 2980 2981 FEATURES 2982 - [cmd] Added metrics (served under `/metrics` using a Prometheus client; 2983 disabled by default). See the new `instrumentation` section in the config and 2984 [metrics](https://tendermint.readthedocs.io/projects/tools/en/develop/metrics.html) 2985 guide. 2986 - [p2p] Add IPv6 support to peering. 2987 - [p2p] Add `external_address` to config to allow specifying the address for 2988 peers to dial 2989 2990 IMPROVEMENT 2991 - [rpc/client] Supports https and wss now. 2992 - [crypto] Make public key size into public constants 2993 - [mempool] Log tx hash, not entire tx 2994 - [abci] Merged in github.com/tendermint/abci 2995 - [crypto] Merged in github.com/tendermint/go-crypto 2996 - [libs] Merged in github.com/tendermint/tmlibs 2997 - [docs] Move from .rst to .md 2998 2999 BUG FIXES: 3000 - [rpc] Limit maximum number of HTTP/WebSocket connections 3001 (`rpc.max_open_connections`) and gRPC connections 3002 (`rpc.grpc_max_open_connections`). Check out "Running In Production" guide if 3003 you want to increase them. 3004 - [rpc] Limit maximum request body size to 1MB (header is limited to 1MB). 3005 - [consensus] Fix a halting bug where `create_empty_blocks=false` 3006 - [p2p] Fix panic in seed mode 3007 3008 ## 0.21.0 3009 3010 *June 21th, 2018* 3011 3012 BREAKING CHANGES 3013 3014 - [config] Change default ports from 4665X to 2665X. Ports over 32768 are 3015 ephemeral and reserved for use by the kernel. 3016 - [cmd] `unsafe_reset_all` removes the addrbook.json 3017 3018 IMPROVEMENT 3019 3020 - [pubsub] Set default capacity to 0 3021 - [docs] Various improvements 3022 3023 BUG FIXES 3024 3025 - [consensus] Fix an issue where we don't make blocks after `fast_sync` when `create_empty_blocks=false` 3026 - [mempool] Fix #1761 where we don't process txs if `cache_size=0` 3027 - [rpc] Fix memory leak in Websocket (when using `/subscribe` method) 3028 - [config] Escape paths in config - fixes config paths on Windows 3029 3030 ## 0.20.0 3031 3032 *June 6th, 2018* 3033 3034 This is the first in a series of breaking releases coming to Tendermint after 3035 soliciting developer feedback and conducting security audits. 3036 3037 This release does not break any blockchain data structures or 3038 protocols other than the ABCI messages between Tendermint and the application. 3039 3040 Applications that upgrade for ABCI v0.11.0 should be able to continue running Tendermint 3041 v0.20.0 on blockchains created with v0.19.X 3042 3043 BREAKING CHANGES 3044 3045 - [abci] Upgrade to 3046 [v0.11.0](https://github.com/tendermint/abci/blob/master/CHANGELOG.md#0110) 3047 - [abci] Change Query path for filtering peers by node ID from 3048 `p2p/filter/pubkey/<id>` to `p2p/filter/id/<id>` 3049 3050 ## 0.19.9 3051 3052 *June 5th, 2018* 3053 3054 BREAKING CHANGES 3055 3056 - [types/priv_validator] Moved to top level `privval` package 3057 3058 FEATURES 3059 3060 - [config] Collapse PeerConfig into P2PConfig 3061 - [docs] Add quick-install script 3062 - [docs/spec] Add table of Amino prefixes 3063 3064 BUG FIXES 3065 3066 - [rpc] Return 404 for unknown endpoints 3067 - [consensus] Flush WAL on stop 3068 - [evidence] Don't send evidence to peers that are behind 3069 - [p2p] Fix memory leak on peer disconnects 3070 - [rpc] Fix panic when `per_page=0` 3071 3072 ## 0.19.8 3073 3074 *June 4th, 2018* 3075 3076 BREAKING: 3077 3078 - [p2p] Remove `auth_enc` config option, peer connections are always auth 3079 encrypted. Technically a breaking change but seems no one was using it and 3080 arguably a bug fix :) 3081 3082 BUG FIXES 3083 3084 - [mempool] Fix deadlock under high load when `skip_timeout_commit=true` and 3085 `create_empty_blocks=false` 3086 3087 ## 0.19.7 3088 3089 *May 31st, 2018* 3090 3091 BREAKING: 3092 3093 - [libs/pubsub] TagMap#Get returns a string value 3094 - [libs/pubsub] NewTagMap accepts a map of strings 3095 3096 FEATURES 3097 3098 - [rpc] the RPC documentation is now published to https://tendermint.github.io/slate 3099 - [p2p] AllowDuplicateIP config option to refuse connections from same IP. 3100 - true by default for now, false by default in next breaking release 3101 - [docs] Add docs for query, tx indexing, events, pubsub 3102 - [docs] Add some notes about running Tendermint in production 3103 3104 IMPROVEMENTS: 3105 3106 - [consensus] Consensus reactor now receives events from a separate synchronous event bus, 3107 which is not dependant on external RPC load 3108 - [consensus/wal] do not look for height in older files if we've seen height - 1 3109 - [docs] Various cleanup and link fixes 3110 3111 ## 0.19.6 3112 3113 *May 29th, 2018* 3114 3115 BUG FIXES 3116 3117 - [blockchain] Fix fast-sync deadlock during high peer turnover 3118 3119 BUG FIX: 3120 3121 - [evidence] Dont send peers evidence from heights they haven't synced to yet 3122 - [p2p] Refuse connections to more than one peer with the same IP 3123 - [docs] Various fixes 3124 3125 ## 0.19.5 3126 3127 *May 20th, 2018* 3128 3129 BREAKING CHANGES 3130 3131 - [rpc/client] TxSearch and UnconfirmedTxs have new arguments (see below) 3132 - [rpc/client] TxSearch returns ResultTxSearch 3133 - [version] Breaking changes to Go APIs will not be reflected in breaking 3134 version change, but will be included in changelog. 3135 3136 FEATURES 3137 3138 - [rpc] `/tx_search` takes `page` (starts at 1) and `per_page` (max 100, default 30) args to paginate results 3139 - [rpc] `/unconfirmed_txs` takes `limit` (max 100, default 30) arg to limit the output 3140 - [config] `mempool.size` and `mempool.cache_size` options 3141 3142 IMPROVEMENTS 3143 3144 - [docs] Lots of updates 3145 - [consensus] Only Fsync() the WAL before executing msgs from ourselves 3146 3147 BUG FIXES 3148 3149 - [mempool] Enforce upper bound on number of transactions 3150 3151 ## 0.19.4 (May 17th, 2018) 3152 3153 IMPROVEMENTS 3154 3155 - [state] Improve tx indexing by using batches 3156 - [consensus, state] Improve logging (more consensus logs, fewer tx logs) 3157 - [spec] Moved to `docs/spec` (TODO cleanup the rest of the docs ...) 3158 3159 BUG FIXES 3160 3161 - [consensus] Fix issue #1575 where a late proposer can get stuck 3162 3163 ## 0.19.3 (May 14th, 2018) 3164 3165 FEATURES 3166 3167 - [rpc] New `/consensus_state` returns just the votes seen at the current height 3168 3169 IMPROVEMENTS 3170 3171 - [rpc] Add stringified votes and fraction of power voted to `/dump_consensus_state` 3172 - [rpc] Add PeerStateStats to `/dump_consensus_state` 3173 3174 BUG FIXES 3175 3176 - [cmd] Set GenesisTime during `tendermint init` 3177 - [consensus] fix ValidBlock rules 3178 3179 ## 0.19.2 (April 30th, 2018) 3180 3181 FEATURES: 3182 3183 - [p2p] Allow peers with different Minor versions to connect 3184 - [rpc] `/net_info` includes `n_peers` 3185 3186 IMPROVEMENTS: 3187 3188 - [p2p] Various code comments, cleanup, error types 3189 - [p2p] Change some Error logs to Debug 3190 3191 BUG FIXES: 3192 3193 - [p2p] Fix reconnect to persistent peer when first dial fails 3194 - [p2p] Validate NodeInfo.ListenAddr 3195 - [p2p] Only allow (MaxNumPeers - MaxNumOutboundPeers) inbound peers 3196 - [p2p/pex] Limit max msg size to 64kB 3197 - [p2p] Fix panic when pex=false 3198 - [p2p] Allow multiple IPs per ID in AddrBook 3199 - [p2p] Fix before/after bugs in addrbook isBad() 3200 3201 ## 0.19.1 (April 27th, 2018) 3202 3203 Note this release includes some small breaking changes in the RPC and one in the 3204 config that are really bug fixes. v0.19.1 will work with existing chains, and make Tendermint 3205 easier to use and debug. With <3 3206 3207 BREAKING (MINOR) 3208 3209 - [config] Removed `wal_light` setting. If you really needed this, let us know 3210 3211 FEATURES: 3212 3213 - [networks] moved in tooling from devops repo: terraform and ansible scripts for deploying testnets ! 3214 - [cmd] Added `gen_node_key` command 3215 3216 BUG FIXES 3217 3218 Some of these are breaking in the RPC response, but they're really bugs! 3219 3220 - [spec] Document address format and pubkey encoding pre and post Amino 3221 - [rpc] Lower case JSON field names 3222 - [rpc] Fix missing entries, improve, and lower case the fields in `/dump_consensus_state` 3223 - [rpc] Fix NodeInfo.Channels format to hex 3224 - [rpc] Add Validator address to `/status` 3225 - [rpc] Fix `prove` in ABCIQuery 3226 - [cmd] MarshalJSONIndent on init 3227 3228 ## 0.19.0 (April 13th, 2018) 3229 3230 BREAKING: 3231 - [cmd] improved `testnet` command; now it can fill in `persistent_peers` for you in the config file and much more (see `tendermint testnet --help` for details) 3232 - [cmd] `show_node_id` now returns an error if there is no node key 3233 - [rpc]: changed the output format for the `/status` endpoint (see https://godoc.org/github.com/vipernet-xyz/tm/rpc/core#Status) 3234 3235 Upgrade from go-wire to go-amino. This is a sweeping change that breaks everything that is 3236 serialized to disk or over the network. 3237 3238 See github.com/tendermint/go-amino for details on the new format. 3239 3240 See `scripts/wire2amino.go` for a tool to upgrade 3241 genesis/priv_validator/node_key JSON files. 3242 3243 FEATURES 3244 3245 - [test] docker-compose for local testnet setup (thanks Greg!) 3246 3247 ## 0.18.0 (April 6th, 2018) 3248 3249 BREAKING: 3250 3251 - [types] Merkle tree uses different encoding for varints (see tmlibs v0.8.0) 3252 - [types] ValidtorSet.GetByAddress returns -1 if no validator found 3253 - [p2p] require all addresses come with an ID no matter what 3254 - [rpc] Listening address must contain tcp:// or unix:// prefix 3255 3256 FEATURES: 3257 3258 - [rpc] StartHTTPAndTLSServer (not used yet) 3259 - [rpc] Include validator's voting power in `/status` 3260 - [rpc] `/tx` and `/tx_search` responses now include the transaction hash 3261 - [rpc] Include peer NodeIDs in `/net_info` 3262 3263 IMPROVEMENTS: 3264 - [config] trim whitespace from elements of lists (like `persistent_peers`) 3265 - [rpc] `/tx_search` results are sorted by height 3266 - [p2p] do not try to connect to ourselves (ok, maybe only once) 3267 - [p2p] seeds respond with a bias towards good peers 3268 3269 BUG FIXES: 3270 - [rpc] fix subscribing using an abci.ResponseDeliverTx tag 3271 - [rpc] fix tx_indexers matchRange 3272 - [rpc] fix unsubscribing (see tmlibs v0.8.0) 3273 3274 ## 0.17.1 (March 27th, 2018) 3275 3276 BUG FIXES: 3277 - [types] Actually support `app_state` in genesis as `AppStateJSON` 3278 3279 ## 0.17.0 (March 27th, 2018) 3280 3281 BREAKING: 3282 - [types] WriteSignBytes -> SignBytes 3283 3284 IMPROVEMENTS: 3285 - [all] renamed `dummy` (`persistent_dummy`) to `kvstore` (`persistent_kvstore`) (name "dummy" is deprecated and will not work in the next breaking release) 3286 - [docs] note on determinism (docs/determinism.rst) 3287 - [genesis] `app_options` field is deprecated. please rename it to `app_state` in your genesis file(s). `app_options` will not work in the next breaking release 3288 - [p2p] dial seeds directly without potential peers 3289 - [p2p] exponential backoff for addrs in the address book 3290 - [p2p] mark peer as good if it contributed enough votes or block parts 3291 - [p2p] stop peer if it sends incorrect data, msg to unknown channel, msg we did not expect 3292 - [p2p] when `auth_enc` is true, all dialed peers must have a node ID in their address 3293 - [spec] various improvements 3294 - switched from glide to dep internally for package management 3295 - [wire] prep work for upgrading to new go-wire (which is now called go-amino) 3296 3297 FEATURES: 3298 - [config] exposed `auth_enc` flag to enable/disable encryption 3299 - [config] added the `--p2p.private_peer_ids` flag and `PrivatePeerIDs` config variable (see config for description) 3300 - [rpc] added `/health` endpoint, which returns empty result for now 3301 - [types/priv_validator] new format and socket client, allowing for remote signing 3302 3303 BUG FIXES: 3304 - [consensus] fix liveness bug by introducing ValidBlock mechanism 3305 3306 ## 0.16.0 (February 20th, 2018) 3307 3308 BREAKING CHANGES: 3309 - [config] use $TMHOME/config for all config and json files 3310 - [p2p] old `--p2p.seeds` is now `--p2p.persistent_peers` (persistent peers to which TM will always connect to) 3311 - [p2p] now `--p2p.seeds` only used for getting addresses (if addrbook is empty; not persistent) 3312 - [p2p] NodeInfo: remove RemoteAddr and add Channels 3313 - we must have at least one overlapping channel with peer 3314 - we only send msgs for channels the peer advertised 3315 - [p2p/conn] pong timeout 3316 - [lite] comment out IAVL related code 3317 3318 FEATURES: 3319 - [p2p] added new `/dial_peers&persistent=_` **unsafe** endpoint 3320 - [p2p] persistent node key in `$THMHOME/config/node_key.json` 3321 - [p2p] introduce peer ID and authenticate peers by ID using addresses like `ID@IP:PORT` 3322 - [p2p/pex] new seed mode crawls the network and serves as a seed. 3323 - [config] MempoolConfig.CacheSize 3324 - [config] P2P.SeedMode (`--p2p.seed_mode`) 3325 3326 IMPROVEMENT: 3327 - [p2p/pex] stricter rules in the PEX reactor for better handling of abuse 3328 - [p2p] various improvements to code structure including subpackages for `pex` and `conn` 3329 - [docs] new spec! 3330 - [all] speed up the tests! 3331 3332 BUG FIX: 3333 - [blockchain] StopPeerForError on timeout 3334 - [consensus] StopPeerForError on a bad Maj23 message 3335 - [state] flush mempool conn before calling commit 3336 - [types] fix priv val signing things that only differ by timestamp 3337 - [mempool] fix memory leak causing zombie peers 3338 - [p2p/conn] fix potential deadlock 3339 3340 ## 0.15.0 (December 29, 2017) 3341 3342 BREAKING CHANGES: 3343 - [p2p] enable the Peer Exchange reactor by default 3344 - [types] add Timestamp field to Proposal/Vote 3345 - [types] add new fields to Header: TotalTxs, ConsensusParamsHash, LastResultsHash, EvidenceHash 3346 - [types] add Evidence to Block 3347 - [types] simplify ValidateBasic 3348 - [state] updates to support changes to the header 3349 - [state] Enforce <1/3 of validator set can change at a time 3350 3351 FEATURES: 3352 - [state] Send indices of absent validators and addresses of byzantine validators in BeginBlock 3353 - [state] Historical ConsensusParams and ABCIResponses 3354 - [docs] Specification for the base Tendermint data structures. 3355 - [evidence] New evidence reactor for gossiping and managing evidence 3356 - [rpc] `/block_results?height=X` returns the DeliverTx results for a given height. 3357 3358 IMPROVEMENTS: 3359 - [consensus] Better handling of corrupt WAL file 3360 3361 BUG FIXES: 3362 - [lite] fix race 3363 - [state] validate block.Header.ValidatorsHash 3364 - [p2p] allow seed addresses to be prefixed with eg. `tcp://` 3365 - [p2p] use consistent key to refer to peers so we dont try to connect to existing peers 3366 - [cmd] fix `tendermint init` to ignore files that are there and generate files that aren't. 3367 3368 ## 0.14.0 (December 11, 2017) 3369 3370 BREAKING CHANGES: 3371 - consensus/wal: removed separator 3372 - rpc/client: changed Subscribe/Unsubscribe/UnsubscribeAll funcs signatures to be identical to event bus. 3373 3374 FEATURES: 3375 - new `tendermint lite` command (and `lite/proxy` pkg) for running a light-client RPC proxy. 3376 NOTE it is currently insecure and its APIs are not yet covered by semver 3377 3378 IMPROVEMENTS: 3379 - rpc/client: can act as event bus subscriber (See https://github.com/vipernet-xyz/tm/issues/945). 3380 - p2p: use exponential backoff from seconds to hours when attempting to reconnect to persistent peer 3381 - config: moniker defaults to the machine's hostname instead of "anonymous" 3382 3383 BUG FIXES: 3384 - p2p: no longer exit if one of the seed addresses is incorrect 3385 3386 ## 0.13.0 (December 6, 2017) 3387 3388 BREAKING CHANGES: 3389 - abci: update to v0.8 using gogo/protobuf; includes tx tags, vote info in RequestBeginBlock, data.Bytes everywhere, use int64, etc. 3390 - types: block heights are now `int64` everywhere 3391 - types & node: EventSwitch and EventCache have been replaced by EventBus and EventBuffer; event types have been overhauled 3392 - node: EventSwitch methods now refer to EventBus 3393 - rpc/lib/types: RPCResponse is no longer a pointer; WSRPCConnection interface has been modified 3394 - rpc/client: WaitForOneEvent takes an EventsClient instead of types.EventSwitch 3395 - rpc/client: Add/RemoveListenerForEvent are now Subscribe/Unsubscribe 3396 - rpc/core/types: ResultABCIQuery wraps an abci.ResponseQuery 3397 - rpc: `/subscribe` and `/unsubscribe` take `query` arg instead of `event` 3398 - rpc: `/status` returns the LatestBlockTime in human readable form instead of in nanoseconds 3399 - mempool: cached transactions return an error instead of an ABCI response with BadNonce 3400 3401 FEATURES: 3402 - rpc: new `/unsubscribe_all` WebSocket RPC endpoint 3403 - rpc: new `/tx_search` endpoint for filtering transactions by more complex queries 3404 - p2p/trust: new trust metric for tracking peers. See ADR-006 3405 - config: TxIndexConfig allows to set what DeliverTx tags to index 3406 3407 IMPROVEMENTS: 3408 - New asynchronous events system using `tmlibs/pubsub` 3409 - logging: Various small improvements 3410 - consensus: Graceful shutdown when app crashes 3411 - tests: Fix various non-deterministic errors 3412 - p2p: more defensive programming 3413 3414 BUG FIXES: 3415 - consensus: fix panic where prs.ProposalBlockParts is not initialized 3416 - p2p: fix panic on bad channel 3417 3418 ## 0.12.1 (November 27, 2017) 3419 3420 BUG FIXES: 3421 - upgrade tmlibs dependency to enable Windows builds for Tendermint 3422 3423 ## 0.12.0 (October 27, 2017) 3424 3425 BREAKING CHANGES: 3426 - rpc/client: websocket ResultsCh and ErrorsCh unified in ResponsesCh. 3427 - rpc/client: ABCIQuery no longer takes `prove` 3428 - state: remove GenesisDoc from state. 3429 - consensus: new binary WAL format provides efficiency and uses checksums to detect corruption 3430 - use scripts/wal2json to convert to json for debugging 3431 3432 FEATURES: 3433 - new `Verifiers` pkg contains the tendermint light-client library (name subject to change)! 3434 - rpc: `/genesis` includes the `app_options` . 3435 - rpc: `/abci_query` takes an additional `height` parameter to support historical queries. 3436 - rpc/client: new ABCIQueryWithOptions supports options like `trusted` (set false to get a proof) and `height` to query a historical height. 3437 3438 IMPROVEMENTS: 3439 - rpc: `/genesis` result includes `app_options` 3440 - rpc/lib/client: add jitter to reconnects. 3441 - rpc/lib/types: `RPCError` satisfies the `error` interface. 3442 3443 BUG FIXES: 3444 - rpc/client: fix ws deadlock after stopping 3445 - blockchain: fix panic on AddBlock when peer is nil 3446 - mempool: fix sending on TxsAvailable when a tx has been invalidated 3447 - consensus: dont run WAL catchup if we fast synced 3448 3449 ## 0.11.1 (October 10, 2017) 3450 3451 IMPROVEMENTS: 3452 - blockchain/reactor: respondWithNoResponseMessage for missing height 3453 3454 BUG FIXES: 3455 - rpc: fixed client WebSocket timeout 3456 - rpc: client now resubscribes on reconnection 3457 - rpc: fix panics on missing params 3458 - rpc: fix `/dump_consensus_state` to have normal json output (NOTE: technically breaking, but worth a bug fix label) 3459 - types: fixed out of range error in VoteSet.addVote 3460 - consensus: fix wal autofile via https://github.com/tendermint/tmlibs/blob/master/CHANGELOG.md#032-october-2-2017 3461 3462 ## 0.11.0 (September 22, 2017) 3463 3464 BREAKING: 3465 - genesis file: validator `amount` is now `power` 3466 - abci: Info, BeginBlock, InitChain all take structs 3467 - rpc: various changes to match JSONRPC spec (http://www.jsonrpc.org/specification), including breaking ones: 3468 - requests that previously returned HTTP code 4XX now return 200 with an error code in the JSONRPC. 3469 - `rpctypes.RPCResponse` uses new `RPCError` type instead of `string`. 3470 3471 - cmd: if there is no genesis, exit immediately instead of waiting around for one to show. 3472 - types: `Signer.Sign` returns an error. 3473 - state: every validator set change is persisted to disk, which required some changes to the `State` structure. 3474 - p2p: new `p2p.Peer` interface used for all reactor methods (instead of `*p2p.Peer` struct). 3475 3476 FEATURES: 3477 - rpc: `/validators?height=X` allows querying of validators at previous heights. 3478 - rpc: Leaving the `height` param empty for `/block`, `/validators`, and `/commit` will return the value for the latest height. 3479 3480 IMPROVEMENTS: 3481 - docs: Moved all docs from the website and tools repo in, converted to `.rst`, and cleaned up for presentation on `tendermint.readthedocs.io` 3482 3483 BUG FIXES: 3484 - fix WAL openning issue on Windows 3485 3486 ## 0.10.4 (September 5, 2017) 3487 3488 IMPROVEMENTS: 3489 - docs: Added Slate docs to each rpc function (see rpc/core) 3490 - docs: Ported all website docs to Read The Docs 3491 - config: expose some p2p params to tweak performance: RecvRate, SendRate, and MaxMsgPacketPayloadSize 3492 - rpc: Upgrade the websocket client and server, including improved auto reconnect, and proper ping/pong 3493 3494 BUG FIXES: 3495 - consensus: fix panic on getVoteBitArray 3496 - consensus: hang instead of panicking on byzantine consensus failures 3497 - cmd: dont load config for version command 3498 3499 ## 0.10.3 (August 10, 2017) 3500 3501 FEATURES: 3502 - control over empty block production: 3503 - new flag, `--consensus.create_empty_blocks`; when set to false, blocks are only created when there are txs or when the AppHash changes. 3504 - new config option, `consensus.create_empty_blocks_interval`; an empty block is created after this many seconds. 3505 - in normal operation, `create_empty_blocks = true` and `create_empty_blocks_interval = 0`, so blocks are being created all the time (as in all previous versions of tendermint). The number of empty blocks can be reduced by increasing `create_empty_blocks_interval` or by setting `create_empty_blocks = false`. 3506 - new `TxsAvailable()` method added to Mempool that returns a channel which fires when txs are available. 3507 - new heartbeat message added to consensus reactor to notify peers that a node is waiting for txs before entering propose step. 3508 - rpc: Add `syncing` field to response returned by `/status`. Is `true` while in fast-sync mode. 3509 3510 IMPROVEMENTS: 3511 - various improvements to documentation and code comments 3512 3513 BUG FIXES: 3514 - mempool: pass height into constructor so it doesn't always start at 0 3515 3516 ## 0.10.2 (July 10, 2017) 3517 3518 FEATURES: 3519 - Enable lower latency block commits by adding consensus reactor sleep durations and p2p flush throttle timeout to the config 3520 3521 IMPROVEMENTS: 3522 - More detailed logging in the consensus reactor and state machine 3523 - More in-code documentation for many exposed functions, especially in consensus/reactor.go and p2p/switch.go 3524 - Improved readability for some function definitions and code blocks with long lines 3525 3526 ## 0.10.1 (June 28, 2017) 3527 3528 FEATURES: 3529 - Use `--trace` to get stack traces for logged errors 3530 - types: GenesisDoc.ValidatorHash returns the hash of the genesis validator set 3531 - types: GenesisDocFromFile parses a GenesiDoc from a JSON file 3532 3533 IMPROVEMENTS: 3534 - Add a Code of Conduct 3535 - Variety of improvements as suggested by `megacheck` tool 3536 - rpc: deduplicate tests between rpc/client and rpc/tests 3537 - rpc: addresses without a protocol prefix default to `tcp://`. `http://` is also accepted as an alias for `tcp://` 3538 - cmd: commands are more easily reuseable from other tools 3539 - DOCKER: automate build/push 3540 3541 BUG FIXES: 3542 - Fix log statements using keys with spaces (logger does not currently support spaces) 3543 - rpc: set logger on websocket connection 3544 - rpc: fix ws connection stability by setting write deadline on pings 3545 3546 ## 0.10.0 (June 2, 2017) 3547 3548 Includes major updates to configuration, logging, and json serialization. 3549 Also includes the Grand Repo-Merge of 2017. 3550 3551 BREAKING CHANGES: 3552 3553 - Config and Flags: 3554 - The `config` map is replaced with a [`Config` struct](https://github.com/vipernet-xyz/tm/blob/v0.10.0/config/config.go#L11), 3555 containing substructs: `BaseConfig`, `P2PConfig`, `MempoolConfig`, `ConsensusConfig`, `RPCConfig` 3556 - This affects the following flags: 3557 - `--seeds` is now `--p2p.seeds` 3558 - `--node_laddr` is now `--p2p.laddr` 3559 - `--pex` is now `--p2p.pex` 3560 - `--skip_upnp` is now `--p2p.skip_upnp` 3561 - `--rpc_laddr` is now `--rpc.laddr` 3562 - `--grpc_laddr` is now `--rpc.grpc_laddr` 3563 - Any configuration option now within a substract must come under that heading in the `config.toml`, for instance: 3564 ``` 3565 [p2p] 3566 laddr="tcp://1.2.3.4:46656" 3567 3568 [consensus] 3569 timeout_propose=1000 3570 ``` 3571 - Use viper and `DefaultConfig() / TestConfig()` functions to handle defaults, and remove `config/tendermint` and `config/tendermint_test` 3572 - Change some function and method signatures to 3573 - Change some [function and method signatures](https://gist.github.com/ebuchman/640d5fc6c2605f73497992fe107ebe0b) accomodate new config 3574 3575 - Logger 3576 - Replace static `log15` logger with a simple interface, and provide a new implementation using `go-kit`. 3577 See our new [logging library](https://github.com/tendermint/tmlibs/log) and [blog post](https://tendermint.com/blog/abstracting-the-logger-interface-in-go) for more details 3578 - Levels `warn` and `notice` are removed (you may need to change them in your `config.toml`!) 3579 - Change some [function and method signatures](https://gist.github.com/ebuchman/640d5fc6c2605f73497992fe107ebe0b) to accept a logger 3580 3581 - JSON serialization: 3582 - Replace `[TypeByte, Xxx]` with `{"type": "some-type", "data": Xxx}` in RPC and all `.json` files by using `go-wire/data`. For instance, a public key is now: 3583 ``` 3584 "pub_key": { 3585 "type": "ed25519", 3586 "data": "83DDF8775937A4A12A2704269E2729FCFCD491B933C4B0A7FFE37FE41D7760D0" 3587 } 3588 ``` 3589 - Remove type information about RPC responses, so `[TypeByte, {"jsonrpc": "2.0", ... }]` is now just `{"jsonrpc": "2.0", ... }` 3590 - Change `[]byte` to `data.Bytes` in all serialized types (for hex encoding) 3591 - Lowercase the JSON tags in `ValidatorSet` fields 3592 - Introduce `EventDataInner` for serializing events 3593 3594 - Other: 3595 - Send InitChain message in handshake if `appBlockHeight == 0` 3596 - Do not include the `Accum` field when computing the validator hash. This makes the ValidatorSetHash unique for a given validator set, rather than changing with every block (as the Accum changes) 3597 - Unsafe RPC calls are not enabled by default. This includes `/dial_seeds`, and all calls prefixed with `unsafe`. Use the `--rpc.unsafe` flag to enable. 3598 3599 3600 FEATURES: 3601 3602 - Per-module log levels. For instance, the new default is `state:info,*:error`, which means the `state` package logs at `info` level, and everything else logs at `error` level 3603 - Log if a node is validator or not in every consensus round 3604 - Use ldflags to set git hash as part of the version 3605 - Ignore `address` and `pub_key` fields in `priv_validator.json` and overwrite them with the values derrived from the `priv_key` 3606 3607 IMPROVEMENTS: 3608 3609 - Merge `tendermint/go-p2p -> tendermint/tendermint/p2p` and `tendermint/go-rpc -> tendermint/tendermint/rpc/lib` 3610 - Update paths for grand repo merge: 3611 - `go-common -> tmlibs/common` 3612 - `go-data -> go-wire/data` 3613 - All other `go-` libs, except `go-crypto` and `go-wire`, are merged under `tmlibs` 3614 - No global loggers (loggers are passed into constructors, or preferably set with a SetLogger method) 3615 - Return HTTP status codes with errors for RPC responses 3616 - Limit `/blockchain_info` call to return a maximum of 20 blocks 3617 - Use `.Wrap()` and `.Unwrap()` instead of eg. `PubKeyS` for `go-crypto` types 3618 - RPC JSON responses use pretty printing (via `json.MarshalIndent`) 3619 - Color code different instances of the consensus for tests 3620 - Isolate viper to `cmd/tendermint/commands` and do not read config from file for tests 3621 3622 3623 ## 0.9.2 (April 26, 2017) 3624 3625 BUG FIXES: 3626 3627 - Fix bug in `ResetPrivValidator` where we were using the global config and log (causing external consumers, eg. basecoin, to fail). 3628 3629 ## 0.9.1 (April 21, 2017) 3630 3631 FEATURES: 3632 3633 - Transaction indexing - txs are indexed by their hash using a simple key-value store; easily extended to more advanced indexers 3634 - New `/tx?hash=X` endpoint to query for transactions and their DeliverTx result by hash. Optionally returns a proof of the tx's inclusion in the block 3635 - `tendermint testnet` command initializes files for a testnet 3636 3637 IMPROVEMENTS: 3638 3639 - CLI now uses Cobra framework 3640 - TMROOT is now TMHOME (TMROOT will stop working in 0.10.0) 3641 - `/broadcast_tx_XXX` also returns the Hash (can be used to query for the tx) 3642 - `/broadcast_tx_commit` also returns the height the block was committed in 3643 - ABCIResponses struct persisted to disk before calling Commit; makes handshake replay much cleaner 3644 - WAL uses #ENDHEIGHT instead of #HEIGHT (#HEIGHT will stop working in 0.10.0) 3645 - Peers included via `--seeds`, under `seeds` in the config, or in `/dial_seeds` are now persistent, and will be reconnected to if the connection breaks 3646 3647 BUG FIXES: 3648 3649 - Fix bug in fast-sync where we stop syncing after a peer is removed, even if they're re-added later 3650 - Fix handshake replay to handle validator set changes and results of DeliverTx when we crash after app.Commit but before state.Save() 3651 3652 ## 0.9.0 (March 6, 2017) 3653 3654 BREAKING CHANGES: 3655 3656 - Update ABCI to v0.4.0, where Query is now `Query(RequestQuery) ResponseQuery`, enabling precise proofs at particular heights: 3657 3658 ``` 3659 message RequestQuery{ 3660 bytes data = 1; 3661 string path = 2; 3662 uint64 height = 3; 3663 bool prove = 4; 3664 } 3665 3666 message ResponseQuery{ 3667 CodeType code = 1; 3668 int64 index = 2; 3669 bytes key = 3; 3670 bytes value = 4; 3671 bytes proof = 5; 3672 uint64 height = 6; 3673 string log = 7; 3674 } 3675 ``` 3676 3677 3678 - `BlockMeta` data type unifies its Hash and PartSetHash under a `BlockID`: 3679 3680 ``` 3681 type BlockMeta struct { 3682 BlockID BlockID `json:"block_id"` // the block hash and partsethash 3683 Header *Header `json:"header"` // The block's Header 3684 } 3685 ``` 3686 3687 - `ValidatorSet.Proposer` is exposed as a field and persisted with the `State`. Use `GetProposer()` to initialize or update after validator-set changes. 3688 3689 - `tendermint gen_validator` command output is now pure JSON 3690 3691 FEATURES: 3692 3693 - New RPC endpoint `/commit?height=X` returns header and commit for block at height `X` 3694 - Client API for each endpoint, including mocks for testing 3695 3696 IMPROVEMENTS: 3697 3698 - `Node` is now a `BaseService` 3699 - Simplified starting Tendermint in-process from another application 3700 - Better organized Makefile 3701 - Scripts for auto-building binaries across platforms 3702 - Docker image improved, slimmed down (using Alpine), and changed from tendermint/tmbase to tendermint/tendermint 3703 - New repo files: `CONTRIBUTING.md`, Github `ISSUE_TEMPLATE`, `CHANGELOG.md` 3704 - Improvements on CircleCI for managing build/test artifacts 3705 - Handshake replay is doen through the consensus package, possibly using a mockApp 3706 - Graceful shutdown of RPC listeners 3707 - Tests for the PEX reactor and DialSeeds 3708 3709 BUG FIXES: 3710 3711 - Check peer.Send for failure before updating PeerState in consensus 3712 - Fix panic in `/dial_seeds` with invalid addresses 3713 - Fix proposer selection logic in ValidatorSet by taking the address into account in the `accumComparable` 3714 - Fix inconcistencies with `ValidatorSet.Proposer` across restarts by persisting it in the `State` 3715 3716 3717 ## 0.8.0 (January 13, 2017) 3718 3719 BREAKING CHANGES: 3720 3721 - New data type `BlockID` to represent blocks: 3722 3723 ``` 3724 type BlockID struct { 3725 Hash []byte `json:"hash"` 3726 PartsHeader PartSetHeader `json:"parts"` 3727 } 3728 ``` 3729 3730 - `Vote` data type now includes validator address and index: 3731 3732 ``` 3733 type Vote struct { 3734 ValidatorAddress []byte `json:"validator_address"` 3735 ValidatorIndex int `json:"validator_index"` 3736 Height int `json:"height"` 3737 Round int `json:"round"` 3738 Type byte `json:"type"` 3739 BlockID BlockID `json:"block_id"` // zero if vote is nil. 3740 Signature crypto.Signature `json:"signature"` 3741 } 3742 ``` 3743 3744 - Update TMSP to v0.3.0, where it is now called ABCI and AppendTx is DeliverTx 3745 - Hex strings in the RPC are now "0x" prefixed 3746 3747 3748 FEATURES: 3749 3750 - New message type on the ConsensusReactor, `Maj23Msg`, for peers to alert others they've seen a Maj23, 3751 in order to track and handle conflicting votes intelligently to prevent Byzantine faults from causing halts: 3752 3753 ``` 3754 type VoteSetMaj23Message struct { 3755 Height int 3756 Round int 3757 Type byte 3758 BlockID types.BlockID 3759 } 3760 ``` 3761 3762 - Configurable block part set size 3763 - Validator set changes 3764 - Optionally skip TimeoutCommit if we have all the votes 3765 - Handshake between Tendermint and App on startup to sync latest state and ensure consistent recovery from crashes 3766 - GRPC server for BroadcastTx endpoint 3767 3768 IMPROVEMENTS: 3769 3770 - Less verbose logging 3771 - Better test coverage (37% -> 49%) 3772 - Canonical SignBytes for signable types 3773 - Write-Ahead Log for Mempool and Consensus via tmlibs/autofile 3774 - Better in-process testing for the consensus reactor and byzantine faults 3775 - Better crash/restart testing for individual nodes at preset failure points, and of networks at arbitrary points 3776 - Better abstraction over timeout mechanics 3777 3778 BUG FIXES: 3779 3780 - Fix memory leak in mempool peer 3781 - Fix panic on POLRound=-1 3782 - Actually set the CommitTime 3783 - Actually send BeginBlock message 3784 - Fix a liveness issues caused by Byzantine proposals/votes. Uses the new `Maj23Msg`. 3785 3786 3787 ## 0.7.4 (December 14, 2016) 3788 3789 FEATURES: 3790 3791 - Enable the Peer Exchange reactor with the `--pex` flag for more resilient gossip network (feature still in development, beware dragons) 3792 3793 IMPROVEMENTS: 3794 3795 - Remove restrictions on RPC endpoint `/dial_seeds` to enable manual network configuration 3796 3797 ## 0.7.3 (October 20, 2016) 3798 3799 IMPROVEMENTS: 3800 3801 - Type safe FireEvent 3802 - More WAL/replay tests 3803 - Cleanup some docs 3804 3805 BUG FIXES: 3806 3807 - Fix deadlock in mempool for synchronous apps 3808 - Replay handles non-empty blocks 3809 - Fix race condition in HeightVoteSet 3810 3811 ## 0.7.2 (September 11, 2016) 3812 3813 BUG FIXES: 3814 3815 - Set mustConnect=false so tendermint will retry connecting to the app 3816 3817 ## 0.7.1 (September 10, 2016) 3818 3819 FEATURES: 3820 3821 - New TMSP connection for Query/Info 3822 - New RPC endpoints: 3823 - `tmsp_query` 3824 - `tmsp_info` 3825 - Allow application to filter peers through Query (off by default) 3826 3827 IMPROVEMENTS: 3828 3829 - TMSP connection type enforced at compile time 3830 - All listen/client urls use a "tcp://" or "unix://" prefix 3831 3832 BUG FIXES: 3833 3834 - Save LastSignature/LastSignBytes to `priv_validator.json` for recovery 3835 - Fix event unsubscribe 3836 - Fix fastsync/blockchain reactor 3837 3838 ## 0.7.0 (August 7, 2016) 3839 3840 BREAKING CHANGES: 3841 3842 - Strict SemVer starting now! 3843 - Update to ABCI v0.2.0 3844 - Validation types now called Commit 3845 - NewBlock event only returns the block header 3846 3847 3848 FEATURES: 3849 3850 - TMSP and RPC support TCP and UNIX sockets 3851 - Addition config options including block size and consensus parameters 3852 - New WAL mode `cswal_light`; logs only the validator's own votes 3853 - New RPC endpoints: 3854 - for starting/stopping profilers, and for updating config 3855 - `/broadcast_tx_commit`, returns when tx is included in a block, else an error 3856 - `/unsafe_flush_mempool`, empties the mempool 3857 3858 3859 IMPROVEMENTS: 3860 3861 - Various optimizations 3862 - Remove bad or invalidated transactions from the mempool cache (allows later duplicates) 3863 - More elaborate testing using CircleCI including benchmarking throughput on 4 digitalocean droplets 3864 3865 BUG FIXES: 3866 3867 - Various fixes to WAL and replay logic 3868 - Various race conditions 3869 3870 ## PreHistory 3871 3872 Strict versioning only began with the release of v0.7.0, in late summer 2016. 3873 The project itself began in early summer 2014 and was workable decentralized cryptocurrency software by the end of that year. 3874 Through the course of 2015, in collaboration with Eris Industries (now Monax Industries), 3875 many additional features were integrated, including an implementation from scratch of the Ethereum Virtual Machine. 3876 That implementation now forms the heart of [Burrow](https://github.com/hyperledger/burrow). 3877 In the later half of 2015, the consensus algorithm was upgraded with a more asynchronous design and a more deterministic and robust implementation. 3878 3879 By late 2015, frustration with the difficulty of forking a large monolithic stack to create alternative cryptocurrency designs led to the 3880 invention of the Application Blockchain Interface (ABCI), then called the Tendermint Socket Protocol (TMSP). 3881 The Ethereum Virtual Machine and various other transaction features were removed, and Tendermint was whittled down to a core consensus engine 3882 driving an application running in another process. 3883 The ABCI interface and implementation were iterated on and improved over the course of 2016, 3884 until versioned history kicked in with v0.7.0.