You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

3860 lines
211 KiB

8 years ago
5 years ago
6 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
p2p: introduce peerConn to simplify peer creation (#1226) * expose AuthEnc in the P2P config if AuthEnc is true, dialed peers must have a node ID in the address and it must match the persistent pubkey from the secret handshake. Refs #1157 * fixes after my own review * fix docs * fix build failure ``` p2p/pex/pex_reactor_test.go:288:88: cannot use seed.NodeInfo().NetAddress() (type *p2p.NetAddress) as type string in array or slice literal ``` * p2p: introduce peerConn to simplify peer creation * Introduce `peerConn` containing the known fields of `peer` * `peer` only created in `sw.addPeer` once handshake is complete and NodeInfo is checked * Eliminates some mutable variables and makes the code flow better * Simplifies the `newXxxPeer` funcs * Use ID instead of PubKey where possible. * SetPubKeyFilter -> SetIDFilter * nodeInfo.Validate takes ID * remove peer.PubKey() * persistent node ids * fixes from review * test: use ip_plus_id.sh more * fix invalid memory panic during fast_sync test ``` 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: panic: runtime error: invalid memory address or nil pointer dereference 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: [signal SIGSEGV: segmentation violation code=0x1 addr=0x20 pc=0x98dd3e] 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: goroutine 3432 [running]: 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: github.com/tendermint/tendermint/p2p.newOutboundPeerConn(0xc423fd1380, 0xc420933e00, 0x1, 0x1239a60, 0 xc420128c40, 0x2, 0x42caf6, 0xc42001f300, 0xc422831d98, 0xc4227951c0, ...) 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: #011/go/src/github.com/tendermint/tendermint/p2p/peer.go:123 +0x31e 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: github.com/tendermint/tendermint/p2p.(*Switch).addOutboundPeerWithConfig(0xc4200ad040, 0xc423fd1380, 0 xc420933e00, 0xc423f48801, 0x28, 0x2) 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: #011/go/src/github.com/tendermint/tendermint/p2p/switch.go:455 +0x12b 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: github.com/tendermint/tendermint/p2p.(*Switch).DialPeerWithAddress(0xc4200ad040, 0xc423fd1380, 0x1, 0x 0, 0x0) 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: #011/go/src/github.com/tendermint/tendermint/p2p/switch.go:371 +0xdc 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: github.com/tendermint/tendermint/p2p.(*Switch).reconnectToPeer(0xc4200ad040, 0x123e000, 0xc42007bb00) 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: #011/go/src/github.com/tendermint/tendermint/p2p/switch.go:290 +0x25f 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: created by github.com/tendermint/tendermint/p2p.(*Switch).StopPeerForError 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: #011/go/src/github.com/tendermint/tendermint/p2p/switch.go:256 +0x1b7 ```
7 years ago
p2p: introduce peerConn to simplify peer creation (#1226) * expose AuthEnc in the P2P config if AuthEnc is true, dialed peers must have a node ID in the address and it must match the persistent pubkey from the secret handshake. Refs #1157 * fixes after my own review * fix docs * fix build failure ``` p2p/pex/pex_reactor_test.go:288:88: cannot use seed.NodeInfo().NetAddress() (type *p2p.NetAddress) as type string in array or slice literal ``` * p2p: introduce peerConn to simplify peer creation * Introduce `peerConn` containing the known fields of `peer` * `peer` only created in `sw.addPeer` once handshake is complete and NodeInfo is checked * Eliminates some mutable variables and makes the code flow better * Simplifies the `newXxxPeer` funcs * Use ID instead of PubKey where possible. * SetPubKeyFilter -> SetIDFilter * nodeInfo.Validate takes ID * remove peer.PubKey() * persistent node ids * fixes from review * test: use ip_plus_id.sh more * fix invalid memory panic during fast_sync test ``` 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: panic: runtime error: invalid memory address or nil pointer dereference 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: [signal SIGSEGV: segmentation violation code=0x1 addr=0x20 pc=0x98dd3e] 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: goroutine 3432 [running]: 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: github.com/tendermint/tendermint/p2p.newOutboundPeerConn(0xc423fd1380, 0xc420933e00, 0x1, 0x1239a60, 0 xc420128c40, 0x2, 0x42caf6, 0xc42001f300, 0xc422831d98, 0xc4227951c0, ...) 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: #011/go/src/github.com/tendermint/tendermint/p2p/peer.go:123 +0x31e 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: github.com/tendermint/tendermint/p2p.(*Switch).addOutboundPeerWithConfig(0xc4200ad040, 0xc423fd1380, 0 xc420933e00, 0xc423f48801, 0x28, 0x2) 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: #011/go/src/github.com/tendermint/tendermint/p2p/switch.go:455 +0x12b 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: github.com/tendermint/tendermint/p2p.(*Switch).DialPeerWithAddress(0xc4200ad040, 0xc423fd1380, 0x1, 0x 0, 0x0) 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: #011/go/src/github.com/tendermint/tendermint/p2p/switch.go:371 +0xdc 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: github.com/tendermint/tendermint/p2p.(*Switch).reconnectToPeer(0xc4200ad040, 0x123e000, 0xc42007bb00) 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: #011/go/src/github.com/tendermint/tendermint/p2p/switch.go:290 +0x25f 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: created by github.com/tendermint/tendermint/p2p.(*Switch).StopPeerForError 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: #011/go/src/github.com/tendermint/tendermint/p2p/switch.go:256 +0x1b7 ```
7 years ago
p2p: introduce peerConn to simplify peer creation (#1226) * expose AuthEnc in the P2P config if AuthEnc is true, dialed peers must have a node ID in the address and it must match the persistent pubkey from the secret handshake. Refs #1157 * fixes after my own review * fix docs * fix build failure ``` p2p/pex/pex_reactor_test.go:288:88: cannot use seed.NodeInfo().NetAddress() (type *p2p.NetAddress) as type string in array or slice literal ``` * p2p: introduce peerConn to simplify peer creation * Introduce `peerConn` containing the known fields of `peer` * `peer` only created in `sw.addPeer` once handshake is complete and NodeInfo is checked * Eliminates some mutable variables and makes the code flow better * Simplifies the `newXxxPeer` funcs * Use ID instead of PubKey where possible. * SetPubKeyFilter -> SetIDFilter * nodeInfo.Validate takes ID * remove peer.PubKey() * persistent node ids * fixes from review * test: use ip_plus_id.sh more * fix invalid memory panic during fast_sync test ``` 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: panic: runtime error: invalid memory address or nil pointer dereference 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: [signal SIGSEGV: segmentation violation code=0x1 addr=0x20 pc=0x98dd3e] 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: goroutine 3432 [running]: 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: github.com/tendermint/tendermint/p2p.newOutboundPeerConn(0xc423fd1380, 0xc420933e00, 0x1, 0x1239a60, 0 xc420128c40, 0x2, 0x42caf6, 0xc42001f300, 0xc422831d98, 0xc4227951c0, ...) 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: #011/go/src/github.com/tendermint/tendermint/p2p/peer.go:123 +0x31e 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: github.com/tendermint/tendermint/p2p.(*Switch).addOutboundPeerWithConfig(0xc4200ad040, 0xc423fd1380, 0 xc420933e00, 0xc423f48801, 0x28, 0x2) 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: #011/go/src/github.com/tendermint/tendermint/p2p/switch.go:455 +0x12b 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: github.com/tendermint/tendermint/p2p.(*Switch).DialPeerWithAddress(0xc4200ad040, 0xc423fd1380, 0x1, 0x 0, 0x0) 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: #011/go/src/github.com/tendermint/tendermint/p2p/switch.go:371 +0xdc 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: github.com/tendermint/tendermint/p2p.(*Switch).reconnectToPeer(0xc4200ad040, 0x123e000, 0xc42007bb00) 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: #011/go/src/github.com/tendermint/tendermint/p2p/switch.go:290 +0x25f 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: created by github.com/tendermint/tendermint/p2p.(*Switch).StopPeerForError 2018-02-21T06:30:05Z box887.localdomain docker/local_testnet_4[14907]: #011/go/src/github.com/tendermint/tendermint/p2p/switch.go:256 +0x1b7 ```
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
7 years ago
8 years ago
7 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
8 years ago
  1. # Changelog
  2. Friendly reminder: We have a [bug bounty program](https://hackerone.com/cosmos).
  3. ## v0.35.0-rc2
  4. September 27, 2021
  5. ### BREAKING CHANGES
  6. - Go API
  7. - [crypto/armor]: [\#6963](https://github.com/tendermint/tendermint/pull/6963) remove package which is unused, and based on
  8. deprecated fundamentals. Downstream users should maintain this
  9. library. (@tychoish)
  10. - [state] [store] [proxy] [rpc/core]: [\#6937](https://github.com/tendermint/tendermint/pull/6937) move packages to
  11. `internal` to prevent consumption of these internal APIs by
  12. external users. (@tychoish)
  13. ### FEATURES
  14. - [\#6982](https://github.com/tendermint/tendermint/pull/6982) tendermint binary has built-in suppport for running the e2e application (with state sync support) (@cmwaters).
  15. ## v0.35.0-rc1
  16. September 8, 2021
  17. Special thanks to external contributors on this release: @JayT106, @bipulprasad, @alessio, @Yawning, @silasdavis,
  18. @cuonglm, @tanyabouman, @JoeKash, @githubsands, @jeebster, @crypto-facs, @liamsi, and @gotjoshua
  19. ### BREAKING CHANGES
  20. - CLI/RPC/Config
  21. - [pubsub/events] [\#6634](https://github.com/tendermint/tendermint/pull/6634) The `ResultEvent.Events` field is now of type `[]abci.Event` preserving event order instead of `map[string][]string`. (@alexanderbez)
  22. - [config] [\#5598](https://github.com/tendermint/tendermint/pull/5598) The `test_fuzz` and `test_fuzz_config` P2P settings have been removed. (@erikgrinaker)
  23. - [config] [\#5728](https://github.com/tendermint/tendermint/pull/5728) `fastsync.version = "v1"` is no longer supported (@melekes)
  24. - [cli] [\#5772](https://github.com/tendermint/tendermint/pull/5772) `gen_node_key` prints JSON-encoded `NodeKey` rather than ID and does not save it to `node_key.json` (@melekes)
  25. - [cli] [\#5777](https://github.com/tendermint/tendermint/pull/5777) use hyphen-case instead of snake_case for all cli commands and config parameters (@cmwaters)
  26. - [rpc] [\#6019](https://github.com/tendermint/tendermint/pull/6019) standardise RPC errors and return the correct status code (@bipulprasad & @cmwaters)
  27. - [rpc] [\#6168](https://github.com/tendermint/tendermint/pull/6168) Change default sorting to desc for `/tx_search` results (@melekes)
  28. - [cli] [\#6282](https://github.com/tendermint/tendermint/pull/6282) User must specify the node mode when using `tendermint init` (@cmwaters)
  29. - [state/indexer] [\#6382](https://github.com/tendermint/tendermint/pull/6382) reconstruct indexer, move txindex into the indexer package (@JayT106)
  30. - [cli] [\#6372](https://github.com/tendermint/tendermint/pull/6372) Introduce `BootstrapPeers` as part of the new p2p stack. Peers to be connected on startup (@cmwaters)
  31. - [config] [\#6462](https://github.com/tendermint/tendermint/pull/6462) Move `PrivValidator` configuration out of `BaseConfig` into its own section. (@tychoish)
  32. - [rpc] [\#6610](https://github.com/tendermint/tendermint/pull/6610) Add MaxPeerBlockHeight into /status rpc call (@JayT106)
  33. - [blocksync/rpc] [\#6620](https://github.com/tendermint/tendermint/pull/6620) Add TotalSyncedTime & RemainingTime to SyncInfo in /status RPC (@JayT106)
  34. - [rpc/grpc] [\#6725](https://github.com/tendermint/tendermint/pull/6725) Mark gRPC in the RPC layer as deprecated.
  35. - [blocksync/v2] [\#6730](https://github.com/tendermint/tendermint/pull/6730) Fast Sync v2 is deprecated, please use v0
  36. - [rpc] Add genesis_chunked method to support paginated and parallel fetching of large genesis documents.
  37. - [rpc/jsonrpc/server] [\#6785](https://github.com/tendermint/tendermint/pull/6785) `Listen` function updated to take an `int` argument, `maxOpenConnections`, instead of an entire config object. (@williambanfield)
  38. - [rpc] [\#6820](https://github.com/tendermint/tendermint/pull/6820) Update RPC methods to reflect changes in the p2p layer, disabling support for `UnsafeDialPeers` and `UnsafeDialPeers` when used with the new p2p layer, and changing the response format of the peer list in `NetInfo` for all users.
  39. - [cli] [\#6854](https://github.com/tendermint/tendermint/pull/6854) Remove deprecated snake case commands. (@tychoish)
  40. - Apps
  41. - [ABCI] [\#6408](https://github.com/tendermint/tendermint/pull/6408) Change the `key` and `value` fields from `[]byte` to `string` in the `EventAttribute` type. (@alexanderbez)
  42. - [ABCI] [\#5447](https://github.com/tendermint/tendermint/pull/5447) Remove `SetOption` method from `ABCI.Client` interface
  43. - [ABCI] [\#5447](https://github.com/tendermint/tendermint/pull/5447) Reset `Oneof` indexes for `Request` and `Response`.
  44. - [ABCI] [\#5818](https://github.com/tendermint/tendermint/pull/5818) Use protoio for msg length delimitation. Migrates from int64 to uint64 length delimiters.
  45. - [ABCI] [\#3546](https://github.com/tendermint/tendermint/pull/3546) Add `mempool_error` field to `ResponseCheckTx`. This field will contain an error string if Tendermint encountered an error while adding a transaction to the mempool. (@williambanfield)
  46. - [Version] [\#6494](https://github.com/tendermint/tendermint/pull/6494) `TMCoreSemVer` has been renamed to `TMVersion`.
  47. - It is not required any longer to set ldflags to set version strings
  48. - [abci/counter] [\#6684](https://github.com/tendermint/tendermint/pull/6684) Delete counter example app
  49. - Go API
  50. - [pubsub] [\#6634](https://github.com/tendermint/tendermint/pull/6634) The `Query#Matches` method along with other pubsub methods, now accepts a `[]abci.Event` instead of `map[string][]string`. (@alexanderbez)
  51. - [p2p] [\#6618](https://github.com/tendermint/tendermint/pull/6618) [\#6583](https://github.com/tendermint/tendermint/pull/6583) Move `p2p.NodeInfo`, `p2p.NodeID` and `p2p.NetAddress` into `types` to support use in external packages. (@tychoish)
  52. - [node] [\#6540](https://github.com/tendermint/tendermint/pull/6540) Reduce surface area of the `node` package by making most of the implementation details private. (@tychoish)
  53. - [p2p] [\#6547](https://github.com/tendermint/tendermint/pull/6547) Move the entire `p2p` package and all reactor implementations into `internal`. (@tychoish)
  54. - [libs/log] [\#6534](https://github.com/tendermint/tendermint/pull/6534) Remove the existing custom Tendermint logger backed by go-kit. The logging interface, `Logger`, remains. Tendermint still provides a default logger backed by the performant zerolog logger. (@alexanderbez)
  55. - [libs/time] [\#6495](https://github.com/tendermint/tendermint/pull/6495) Move types/time to libs/time to improve consistency. (@tychoish)
  56. - [mempool] [\#6529](https://github.com/tendermint/tendermint/pull/6529) The `Context` field has been removed from the `TxInfo` type. `CheckTx` now requires a `Context` argument. (@alexanderbez)
  57. - [abci/client, proxy] [\#5673](https://github.com/tendermint/tendermint/pull/5673) `Async` funcs return an error, `Sync` and `Async` funcs accept `context.Context` (@melekes)
  58. - [p2p] Remove unused function `MakePoWTarget`. (@erikgrinaker)
  59. - [libs/bits] [\#5720](https://github.com/tendermint/tendermint/pull/5720) Validate `BitArray` in `FromProto`, which now returns an error (@melekes)
  60. - [proto/p2p] Rename `DefaultNodeInfo` and `DefaultNodeInfoOther` to `NodeInfo` and `NodeInfoOther` (@erikgrinaker)
  61. - [proto/p2p] Rename `NodeInfo.default_node_id` to `node_id` (@erikgrinaker)
  62. - [libs/os] Kill() and {Must,}{Read,Write}File() functions have been removed. (@alessio)
  63. - [store] [\#5848](https://github.com/tendermint/tendermint/pull/5848) Remove block store state in favor of using the db iterators directly (@cmwaters)
  64. - [state] [\#5864](https://github.com/tendermint/tendermint/pull/5864) Use an iterator when pruning state (@cmwaters)
  65. - [types] [\#6023](https://github.com/tendermint/tendermint/pull/6023) Remove `tm2pb.Header`, `tm2pb.BlockID`, `tm2pb.PartSetHeader` and `tm2pb.NewValidatorUpdate`.
  66. - Each of the above types has a `ToProto` and `FromProto` method or function which replaced this logic.
  67. - [light] [\#6054](https://github.com/tendermint/tendermint/pull/6054) Move `MaxRetryAttempt` option from client to provider.
  68. - `NewWithOptions` now sets the max retry attempts and timeouts (@cmwaters)
  69. - [all] [\#6077](https://github.com/tendermint/tendermint/pull/6077) Change spelling from British English to American (@cmwaters)
  70. - Rename "Subscription.Cancelled()" to "Subscription.Canceled()" in libs/pubsub
  71. - Rename "behaviour" pkg to "behavior" and internalized it in blocksync v2
  72. - [rpc/client/http] [\#6176](https://github.com/tendermint/tendermint/pull/6176) Remove `endpoint` arg from `New`, `NewWithTimeout` and `NewWithClient` (@melekes)
  73. - [rpc/client/http] [\#6176](https://github.com/tendermint/tendermint/pull/6176) Unexpose `WSEvents` (@melekes)
  74. - [rpc/jsonrpc/client/ws_client] [\#6176](https://github.com/tendermint/tendermint/pull/6176) `NewWS` no longer accepts options (use `NewWSWithOptions` and `OnReconnect` funcs to configure the client) (@melekes)
  75. - [internal/libs] [\#6366](https://github.com/tendermint/tendermint/pull/6366) Move `autofile`, `clist`,`fail`,`flowrate`, `protoio`, `sync`, `tempfile`, `test` and `timer` lib packages to an internal folder
  76. - [libs/rand] [\#6364](https://github.com/tendermint/tendermint/pull/6364) Remove most of libs/rand in favour of standard lib's `math/rand` (@liamsi)
  77. - [mempool] [\#6466](https://github.com/tendermint/tendermint/pull/6466) The original mempool reactor has been versioned as `v0` and moved to a sub-package under the root `mempool` package.
  78. Some core types have been kept in the `mempool` package such as `TxCache` and it's implementations, the `Mempool` interface itself
  79. and `TxInfo`. (@alexanderbez)
  80. - [crypto/sr25519] [\#6526](https://github.com/tendermint/tendermint/pull/6526) Do not re-execute the Ed25519-style key derivation step when doing signing and verification. The derivation is now done once and only once. This breaks `sr25519.GenPrivKeyFromSecret` output compatibility. (@Yawning)
  81. - [types] [\#6627](https://github.com/tendermint/tendermint/pull/6627) Move `NodeKey` to types to make the type public.
  82. - [config] [\#6627](https://github.com/tendermint/tendermint/pull/6627) Extend `config` to contain methods `LoadNodeKeyID` and `LoadorGenNodeKeyID`
  83. - [blocksync] [\#6755](https://github.com/tendermint/tendermint/pull/6755) Rename `FastSync` and `Blockchain` package to `BlockSync` (@cmwaters)
  84. - Data Storage
  85. - [store/state/evidence/light] [\#5771](https://github.com/tendermint/tendermint/pull/5771) Use an order-preserving varint key encoding (@cmwaters)
  86. - [mempool] [\#6396](https://github.com/tendermint/tendermint/pull/6396) Remove mempool's write ahead log (WAL), (previously unused by the tendermint code). (@tychoish)
  87. - [state] [\#6541](https://github.com/tendermint/tendermint/pull/6541) Move pruneBlocks from consensus/state to state/execution. (@JayT106)
  88. - Tooling
  89. - [tools] [\#6498](https://github.com/tendermint/tendermint/pull/6498) Set OS home dir to instead of the hardcoded PATH. (@JayT106)
  90. - [cli/indexer] [\#6676](https://github.com/tendermint/tendermint/pull/6676) Reindex events command line tooling. (@JayT106)
  91. ### FEATURES
  92. - [config] Add `--mode` flag and config variable. See [ADR-52](https://github.com/tendermint/tendermint/blob/master/docs/architecture/adr-052-tendermint-mode.md) @dongsam
  93. - [rpc] [\#6329](https://github.com/tendermint/tendermint/pull/6329) Don't cap page size in unsafe mode (@gotjoshua, @cmwaters)
  94. - [pex] [\#6305](https://github.com/tendermint/tendermint/pull/6305) v2 pex reactor with backwards compatability. Introduces two new pex messages to
  95. accomodate for the new p2p stack. Removes the notion of seeds and crawling. All peer
  96. exchange reactors behave the same. (@cmwaters)
  97. - [crypto] [\#6376](https://github.com/tendermint/tendermint/pull/6376) Enable sr25519 as a validator key type
  98. - [mempool] [\#6466](https://github.com/tendermint/tendermint/pull/6466) Introduction of a prioritized mempool. (@alexanderbez)
  99. - `Priority` and `Sender` have been introduced into the `ResponseCheckTx` type, where the `priority` will determine the prioritization of
  100. the transaction when a proposer reaps transactions for a block proposal. The `sender` field acts as an index.
  101. - Operators may toggle between the legacy mempool reactor, `v0`, and the new prioritized reactor, `v1`, by setting the
  102. `mempool.version` configuration, where `v1` is the default configuration.
  103. - Applications that do not specify a priority, i.e. zero, will have transactions reaped by the order in which they are received by the node.
  104. - Transactions are gossiped in FIFO order as they are in `v0`.
  105. - [config/indexer] [\#6411](https://github.com/tendermint/tendermint/pull/6411) Introduce support for custom event indexing data sources, specifically PostgreSQL. (@JayT106)
  106. - [blocksync/event] [\#6619](https://github.com/tendermint/tendermint/pull/6619) Emit blocksync status event when switching consensus/blocksync (@JayT106)
  107. - [statesync/event] [\#6700](https://github.com/tendermint/tendermint/pull/6700) Emit statesync status start/end event (@JayT106)
  108. - [inspect] [\#6785](https://github.com/tendermint/tendermint/pull/6785) Add a new `inspect` command for introspecting the state and block store of a crashed tendermint node. (@williambanfield)
  109. ### IMPROVEMENTS
  110. - [libs/log] Console log formatting changes as a result of [\#6534](https://github.com/tendermint/tendermint/pull/6534) and [\#6589](https://github.com/tendermint/tendermint/pull/6589). (@tychoish)
  111. - [statesync] [\#6566](https://github.com/tendermint/tendermint/pull/6566) Allow state sync fetchers and request timeout to be configurable. (@alexanderbez)
  112. - [types] [\#6478](https://github.com/tendermint/tendermint/pull/6478) Add `block_id` to `newblock` event (@jeebster)
  113. - [crypto/ed25519] [\#5632](https://github.com/tendermint/tendermint/pull/5632) Adopt zip215 `ed25519` verification. (@marbar3778)
  114. - [crypto/ed25519] [\#6526](https://github.com/tendermint/tendermint/pull/6526) Use [curve25519-voi](https://github.com/oasisprotocol/curve25519-voi) for `ed25519` signing and verification. (@Yawning)
  115. - [crypto/sr25519] [\#6526](https://github.com/tendermint/tendermint/pull/6526) Use [curve25519-voi](https://github.com/oasisprotocol/curve25519-voi) for `sr25519` signing and verification. (@Yawning)
  116. - [privval] [\#5603](https://github.com/tendermint/tendermint/pull/5603) Add `--key` to `init`, `gen_validator`, `testnet` & `unsafe_reset_priv_validator` for use in generating `secp256k1` keys.
  117. - [privval] [\#5725](https://github.com/tendermint/tendermint/pull/5725) Add gRPC support to private validator.
  118. - [privval] [\#5876](https://github.com/tendermint/tendermint/pull/5876) `tendermint show-validator` will query the remote signer if gRPC is being used (@marbar3778)
  119. - [abci/client] [\#5673](https://github.com/tendermint/tendermint/pull/5673) `Async` requests return an error if queue is full (@melekes)
  120. - [mempool] [\#5673](https://github.com/tendermint/tendermint/pull/5673) Cancel `CheckTx` requests if RPC client disconnects or times out (@melekes)
  121. - [abci] [\#5706](https://github.com/tendermint/tendermint/pull/5706) Added `AbciVersion` to `RequestInfo` allowing applications to check ABCI version when connecting to Tendermint. (@marbar3778)
  122. - [blocksync/v1] [\#5728](https://github.com/tendermint/tendermint/pull/5728) Remove blocksync v1 (@melekes)
  123. - [blocksync/v0] [\#5741](https://github.com/tendermint/tendermint/pull/5741) Relax termination conditions and increase sync timeout (@melekes)
  124. - [cli] [\#5772](https://github.com/tendermint/tendermint/pull/5772) `gen_node_key` output now contains node ID (`id` field) (@melekes)
  125. - [blocksync/v2] [\#5774](https://github.com/tendermint/tendermint/pull/5774) Send status request when new peer joins (@melekes)
  126. - [store] [\#5888](https://github.com/tendermint/tendermint/pull/5888) store.SaveBlock saves using batches instead of transactions for now to improve ACID properties. This is a quick fix for underlying issues around tm-db and ACID guarantees. (@githubsands)
  127. - [consensus] [\#5987](https://github.com/tendermint/tendermint/pull/5987) and [\#5792](https://github.com/tendermint/tendermint/pull/5792) Remove the `time_iota_ms` consensus parameter. Merge `tmproto.ConsensusParams` and `abci.ConsensusParams`. (@marbar3778, @valardragon)
  128. - [types] [\#5994](https://github.com/tendermint/tendermint/pull/5994) Reduce the use of protobuf types in core logic. (@marbar3778)
  129. - `ConsensusParams`, `BlockParams`, `ValidatorParams`, `EvidenceParams`, `VersionParams`, `sm.Version` and `version.Consensus` have become native types. They still utilize protobuf when being sent over the wire or written to disk.
  130. - [rpc/client/http] [\#6163](https://github.com/tendermint/tendermint/pull/6163) Do not drop events even if the `out` channel is full (@melekes)
  131. - [node] [\#6059](https://github.com/tendermint/tendermint/pull/6059) Validate and complete genesis doc before saving to state store (@silasdavis)
  132. - [state] [\#6067](https://github.com/tendermint/tendermint/pull/6067) Batch save state data (@githubsands & @cmwaters)
  133. - [crypto] [\#6120](https://github.com/tendermint/tendermint/pull/6120) Implement batch verification interface for ed25519 and sr25519. (@marbar3778)
  134. - [types] [\#6120](https://github.com/tendermint/tendermint/pull/6120) use batch verification for verifying commits signatures.
  135. - If the key type supports the batch verification API it will try to batch verify. If the verification fails we will single verify each signature.
  136. - [privval/file] [\#6185](https://github.com/tendermint/tendermint/pull/6185) Return error on `LoadFilePV`, `LoadFilePVEmptyState`. Allows for better programmatic control of Tendermint.
  137. - [privval] [\#6240](https://github.com/tendermint/tendermint/pull/6240) Add `context.Context` to privval interface.
  138. - [rpc] [\#6265](https://github.com/tendermint/tendermint/pull/6265) set cache control in http-rpc response header (@JayT106)
  139. - [statesync] [\#6378](https://github.com/tendermint/tendermint/pull/6378) Retry requests for snapshots and add a minimum discovery time (5s) for new snapshots.
  140. - [node/state] [\#6370](https://github.com/tendermint/tendermint/pull/6370) graceful shutdown in the consensus reactor (@JayT106)
  141. - [crypto/merkle] [\#6443](https://github.com/tendermint/tendermint/pull/6443) Improve HashAlternatives performance (@cuonglm)
  142. - [crypto/merkle] [\#6513](https://github.com/tendermint/tendermint/pull/6513) Optimize HashAlternatives (@marbar3778)
  143. - [p2p/pex] [\#6509](https://github.com/tendermint/tendermint/pull/6509) Improve addrBook.hash performance (@cuonglm)
  144. - [consensus/metrics] [\#6549](https://github.com/tendermint/tendermint/pull/6549) Change block_size gauge to a histogram for better observability over time (@marbar3778)
  145. - [statesync] [\#6587](https://github.com/tendermint/tendermint/pull/6587) Increase chunk priority and re-request chunks that don't arrive (@cmwaters)
  146. - [state/privval] [\#6578](https://github.com/tendermint/tendermint/pull/6578) No GetPubKey retry beyond the proposal/voting window (@JayT106)
  147. - [rpc] [\#6615](https://github.com/tendermint/tendermint/pull/6615) Add TotalGasUsed to block_results response (@crypto-facs)
  148. - [cmd/tendermint/commands] [\#6623](https://github.com/tendermint/tendermint/pull/6623) replace `$HOME/.some/test/dir` with `t.TempDir` (@tanyabouman)
  149. - [statesync] \6807 Implement P2P state provider as an alternative to RPC (@cmwaters)
  150. ### BUG FIXES
  151. - [privval] [\#5638](https://github.com/tendermint/tendermint/pull/5638) Increase read/write timeout to 5s and calculate ping interval based on it (@JoeKash)
  152. - [evidence] [\#6375](https://github.com/tendermint/tendermint/pull/6375) Fix bug with inconsistent LightClientAttackEvidence hashing (cmwaters)
  153. - [rpc] [\#6507](https://github.com/tendermint/tendermint/pull/6507) Ensure RPC client can handle URLs without ports (@JayT106)
  154. - [statesync] [\#6463](https://github.com/tendermint/tendermint/pull/6463) Adds Reverse Sync feature to fetch historical light blocks after state sync in order to verify any evidence (@cmwaters)
  155. - [blocksync] [\#6590](https://github.com/tendermint/tendermint/pull/6590) Update the metrics during blocksync (@JayT106)
  156. ## v0.34.13
  157. *September 6, 2021*
  158. This release backports improvements to state synchronization and ABCI
  159. performance under concurrent load, and the PostgreSQL event indexer.
  160. ### IMPROVEMENTS
  161. - [statesync] [\#6881](https://github.com/tendermint/tendermint/issues/6881) improvements to stateprovider logic (@cmwaters)
  162. - [ABCI] [\#6873](https://github.com/tendermint/tendermint/issues/6873) change client to use multi-reader mutexes (@tychoish)
  163. - [indexing] [\#6906](https://github.com/tendermint/tendermint/issues/6906) enable the PostgreSQL indexer sink (@creachadair)
  164. ## v0.34.12
  165. *August 17, 2021*
  166. Special thanks to external contributors on this release: @JayT106.
  167. ### FEATURES
  168. - [rpc] [\#6717](https://github.com/tendermint/tendermint/pull/6717) introduce
  169. `/genesis_chunked` rpc endpoint for handling large genesis files by chunking them (@tychoish)
  170. ### IMPROVEMENTS
  171. - [rpc] [\#6825](https://github.com/tendermint/tendermint/issues/6825) Remove egregious INFO log from `ABCI#Query` RPC. (@alexanderbez)
  172. ### BUG FIXES
  173. - [light] [\#6685](https://github.com/tendermint/tendermint/pull/6685) fix bug
  174. with incorrectly handling contexts that would occasionally freeze state sync. (@cmwaters)
  175. - [privval] [\#6748](https://github.com/tendermint/tendermint/issues/6748) Fix vote timestamp to prevent chain halt (@JayT106)
  176. ## v0.34.11
  177. *June 18, 2021*
  178. This release improves the robustness of statesync; tweaking channel priorities and timeouts and
  179. adding two new parameters to the state sync config.
  180. ### BREAKING CHANGES
  181. - Apps
  182. - [Version] [\#6494](https://github.com/tendermint/tendermint/pull/6494) `TMCoreSemVer` is not required to be set as a ldflag any longer.
  183. ### IMPROVEMENTS
  184. - [statesync] [\#6566](https://github.com/tendermint/tendermint/pull/6566) Allow state sync fetchers and request timeout to be configurable. (@alexanderbez)
  185. - [statesync] [\#6378](https://github.com/tendermint/tendermint/pull/6378) Retry requests for snapshots and add a minimum discovery time (5s) for new snapshots. (@tychoish)
  186. - [statesync] [\#6582](https://github.com/tendermint/tendermint/pull/6582) Increase chunk priority and add multiple retry chunk requests (@cmwaters)
  187. ### BUG FIXES
  188. - [evidence] [\#6375](https://github.com/tendermint/tendermint/pull/6375) Fix bug with inconsistent LightClientAttackEvidence hashing (@cmwaters)
  189. ## v0.34.10
  190. *April 14, 2021*
  191. This release fixes a bug where peers would sometimes try to send messages
  192. on incorrect channels. Special thanks to our friends at Oasis Labs for surfacing
  193. this issue!
  194. - [p2p/node] [\#6339](https://github.com/tendermint/tendermint/issues/6339) Fix bug with using custom channels (@cmwaters)
  195. - [light] [\#6346](https://github.com/tendermint/tendermint/issues/6346) Correctly handle too high errors to improve client robustness (@cmwaters)
  196. ## v0.34.9
  197. *April 8, 2021*
  198. This release fixes a moderate severity security issue, Security Advisory Alderfly,
  199. which impacts all networks that rely on Tendermint light clients.
  200. Further details will be released once networks have upgraded.
  201. This release also includes a small Go API-breaking change, to reduce panics in the RPC layer.
  202. Special thanks to our external contributors on this release: @gchaincl
  203. ### BREAKING CHANGES
  204. - Go API
  205. - [rpc/jsonrpc/server] [\#6204](https://github.com/tendermint/tendermint/issues/6204) Modify `WriteRPCResponseHTTP(Error)` to return an error (@melekes)
  206. ### FEATURES
  207. - [rpc] [\#6226](https://github.com/tendermint/tendermint/issues/6226) Index block events and expose a new RPC method, `/block_search`, to allow querying for blocks by `BeginBlock` and `EndBlock` events (@alexanderbez)
  208. ### BUG FIXES
  209. - [rpc/jsonrpc/server] [\#6191](https://github.com/tendermint/tendermint/issues/6191) Correctly unmarshal `RPCRequest` when data is `null` (@melekes)
  210. - [p2p] [\#6289](https://github.com/tendermint/tendermint/issues/6289) Fix "unknown channels" bug on CustomReactors (@gchaincl)
  211. - [light/evidence] Adds logic to handle forward lunatic attacks (@cmwaters)
  212. ## v0.34.8
  213. *February 25, 2021*
  214. This release, in conjunction with [a fix in the Cosmos SDK](https://github.com/cosmos/cosmos-sdk/pull/8641),
  215. introduces changes that should mean the logs are much, much quieter. 🎉
  216. ### IMPROVEMENTS
  217. - [libs/log] [\#6174](https://github.com/tendermint/tendermint/issues/6174) Include timestamp (`ts` field; `time.RFC3339Nano` format) in JSON logger output (@melekes)
  218. ### BUG FIXES
  219. - [abci] [\#6124](https://github.com/tendermint/tendermint/issues/6124) Fixes a panic condition during callback execution in `ReCheckTx` during high tx load. (@alexanderbez)
  220. ## v0.34.7
  221. *February 18, 2021*
  222. This release fixes a downstream security issue which impacts Cosmos SDK
  223. users who are:
  224. * Using Cosmos SDK v0.40.0 or later, AND
  225. * Running validator nodes, AND
  226. * Using the file-based `FilePV` implementation for their consensus keys
  227. Users who fulfill all the above criteria were susceptible to leaking
  228. private key material in the logs. All other users are unaffected.
  229. The root cause was a discrepancy
  230. between the Tendermint Core (untyped) logger and the Cosmos SDK (typed) logger:
  231. Tendermint Core's logger automatically stringifies Go interfaces whenever possible;
  232. however, the Cosmos SDK's logger uses reflection to log the fields within a Go interface.
  233. The introduction of the typed logger meant that previously un-logged fields within
  234. interfaces are now sometimes logged, including the private key material inside the
  235. `FilePV` struct.
  236. Tendermint Core v0.34.7 fixes this issue; however, we strongly recommend that all validators
  237. use remote signer implementations instead of `FilePV` in production.
  238. Thank you to @joe-bowman for his assistance with this vulnerability and a particular
  239. shout-out to @marbar3778 for diagnosing it quickly.
  240. ### BUG FIXES
  241. - [consensus] [\#6128](https://github.com/tendermint/tendermint/pull/6128) Remove privValidator from log call (@tessr)
  242. ## v0.34.6
  243. *February 18, 2021*
  244. _Tendermint Core v0.34.5 and v0.34.6 have been recalled due to release tooling problems._
  245. ## v0.34.4
  246. *February 11, 2021*
  247. This release includes a fix for a memory leak in the evidence reactor (see #6068, below).
  248. All Tendermint clients are recommended to upgrade.
  249. Thank you to our friends at Crypto.com for the initial report of this memory leak!
  250. Special thanks to other external contributors on this release: @yayajacky, @odidev, @laniehei, and @c29r3!
  251. ### BUG FIXES
  252. - [light] [\#6022](https://github.com/tendermint/tendermint/pull/6022) Fix a bug when the number of validators equals 100 (@melekes)
  253. - [light] [\#6026](https://github.com/tendermint/tendermint/pull/6026) Fix a bug when height isn't provided for the rpc calls: `/commit` and `/validators` (@cmwaters)
  254. - [evidence] [\#6068](https://github.com/tendermint/tendermint/pull/6068) Terminate broadcastEvidenceRoutine when peer is stopped (@melekes)
  255. ## v0.34.3
  256. *January 19, 2021*
  257. This release includes a fix for a high-severity security vulnerability,
  258. a DoS-vector that impacted Tendermint Core v0.34.0-v0.34.2. For more details, see
  259. [Security Advisory Mulberry](https://github.com/tendermint/tendermint/security/advisories/GHSA-p658-8693-mhvg)
  260. or https://nvd.nist.gov/vuln/detail/CVE-2021-21271.
  261. Tendermint Core v0.34.3 also updates GoGo Protobuf to 1.3.2 in order to pick up the fix for
  262. https://nvd.nist.gov/vuln/detail/CVE-2021-3121.
  263. ### BUG FIXES
  264. - [evidence] [[security fix]](https://github.com/tendermint/tendermint/security/advisories/GHSA-p658-8693-mhvg) Use correct source of evidence time (@cmwaters)
  265. - [proto] [\#5886](https://github.com/tendermint/tendermint/pull/5889) Bump gogoproto to 1.3.2 (@marbar3778)
  266. ## v0.34.2
  267. *January 12, 2021*
  268. This release fixes a substantial bug in evidence handling where evidence could
  269. sometimes be broadcast before the block containing that evidence was fully committed,
  270. resulting in some nodes panicking when trying to verify said evidence.
  271. ### BREAKING CHANGES
  272. - Go API
  273. - [libs/os] [\#5871](https://github.com/tendermint/tendermint/issues/5871) `EnsureDir` now propagates IO errors and checks the file type (@erikgrinaker)
  274. ### BUG FIXES
  275. - [evidence] [\#5890](https://github.com/tendermint/tendermint/pull/5890) Add a buffer to evidence from consensus to avoid broadcasting and proposing evidence before the
  276. height of such an evidence has finished (@cmwaters)
  277. - [statesync] [\#5889](https://github.com/tendermint/tendermint/issues/5889) Set `LastHeightConsensusParamsChanged` when bootstrapping Tendermint state (@cmwaters)
  278. ## v0.34.1
  279. *January 6, 2021*
  280. Special thanks to external contributors on this release:
  281. @p4u from vocdoni.io reported that the mempool might behave incorrectly under a
  282. high load. The consequences can range from pauses between blocks to the peers
  283. disconnecting from this node. As a temporary remedy (until the mempool package
  284. is refactored), the `max-batch-bytes` was disabled. Transactions will be sent
  285. one by one without batching.
  286. ### BREAKING CHANGES
  287. - CLI/RPC/Config
  288. - [cli] [\#5786](https://github.com/tendermint/tendermint/issues/5786) deprecate snake_case commands for hyphen-case (@cmwaters)
  289. - Go API
  290. - [libs/protoio] [\#5868](https://github.com/tendermint/tendermint/issues/5868) Return number of bytes read in `Reader.ReadMsg()` (@erikgrinaker)
  291. ### IMPROVEMENTS
  292. - [mempool] [\#5813](https://github.com/tendermint/tendermint/issues/5813) Add `keep-invalid-txs-in-cache` config option. When set to true, mempool will keep invalid transactions in the cache (@p4u)
  293. ### BUG FIXES
  294. - [crypto] [\#5707](https://github.com/tendermint/tendermint/issues/5707) Fix infinite recursion in string formatting of Secp256k1 keys (@erikgrinaker)
  295. - [mempool] [\#5800](https://github.com/tendermint/tendermint/issues/5800) Disable `max-batch-bytes` (@melekes)
  296. - [p2p] [\#5868](https://github.com/tendermint/tendermint/issues/5868) Fix inbound traffic statistics and rate limiting in `MConnection` (@erikgrinaker)
  297. ## v0.34.0
  298. *November 19, 2020*
  299. Holy smokes, this is a big one! For a more reader-friendly overview of the changes in 0.34.0
  300. (and of the changes you need to accommodate as a user), check out [UPGRADING.md](UPGRADING.md).
  301. Special thanks to external contributors on this release: @james-ray, @fedekunze, @favadi, @alessio,
  302. @joe-bowman, @cuonglm, @SadPencil and @dongsam.
  303. ### BREAKING CHANGES
  304. - CLI/RPC/Config
  305. - [config] [\#5315](https://github.com/tendermint/tendermint/pull/5315) Rename `prof_laddr` to `pprof_laddr` and move it to `rpc` section (@melekes)
  306. - [evidence] [\#4959](https://github.com/tendermint/tendermint/pull/4959) Add JSON tags to `DuplicateVoteEvidence` (@marbar3778)
  307. - [light] [\#4946](https://github.com/tendermint/tendermint/pull/4946) `tendermint lite` command has been renamed to `tendermint light` (@marbar3778)
  308. - [privval] [\#4582](https://github.com/tendermint/tendermint/pull/4582) `round` in private_validator_state.json is no longer JSON string; instead it is a number (@marbar3778)
  309. - [rpc] [\#4792](https://github.com/tendermint/tendermint/pull/4792) `/validators` are now sorted by voting power (@melekes)
  310. - [rpc] [\#4947](https://github.com/tendermint/tendermint/pull/4947) Return an error when `page` pagination param is 0 in `/validators`, `tx_search` (@melekes)
  311. - [rpc] [\#5137](https://github.com/tendermint/tendermint/pull/5137) JSON tags of `gasWanted` and `gasUsed` in `ResponseCheckTx` and `ResponseDeliverTx` have been made snake_case (`gas_wanted` and `gas_used`) (@marbar3778)
  312. - [rpc] [\#5315](https://github.com/tendermint/tendermint/pull/5315) Remove `/unsafe_start_cpu_profiler`, `/unsafe_stop_cpu_profiler` and `/unsafe_write_heap_profile`. Please use pprof functionality instead (@melekes)
  313. - [rpc/client, rpc/jsonrpc/client] [\#5347](https://github.com/tendermint/tendermint/pull/5347) All client methods now accept `context.Context` as 1st param (@melekes)
  314. - Apps
  315. - [abci] [\#4704](https://github.com/tendermint/tendermint/pull/4704) Add ABCI methods `ListSnapshots`, `LoadSnapshotChunk`, `OfferSnapshot`, and `ApplySnapshotChunk` for state sync snapshots. `ABCIVersion` bumped to 0.17.0. (@erikgrinaker)
  316. - [abci] [\#4989](https://github.com/tendermint/tendermint/pull/4989) `Proof` within `ResponseQuery` has been renamed to `ProofOps` (@marbar3778)
  317. - [abci] [\#5096](https://github.com/tendermint/tendermint/pull/5096) `CheckTxType` Protobuf enum names are now uppercase, to follow Protobuf style guide (@erikgrinaker)
  318. - [abci] [\#5324](https://github.com/tendermint/tendermint/pull/5324) ABCI evidence type is now an enum with two types of possible evidence (@cmwaters)
  319. - P2P Protocol
  320. - [blockchain] [\#4637](https://github.com/tendermint/tendermint/pull/4637) Migrate blockchain reactor(s) to Protobuf encoding (@marbar3778)
  321. - [evidence] [\#4949](https://github.com/tendermint/tendermint/pull/4949) Migrate evidence reactor to Protobuf encoding (@marbar3778)
  322. - [mempool] [\#4940](https://github.com/tendermint/tendermint/pull/4940) Migrate mempool from to Protobuf encoding (@marbar3778)
  323. - [mempool] [\#5321](https://github.com/tendermint/tendermint/pull/5321) Batch transactions when broadcasting them to peers (@melekes)
  324. - `MaxBatchBytes` new config setting defines the max size of one batch.
  325. - [p2p/pex] [\#4973](https://github.com/tendermint/tendermint/pull/4973) Migrate `p2p/pex` reactor to Protobuf encoding (@marbar3778)
  326. - [statesync] [\#4943](https://github.com/tendermint/tendermint/pull/4943) Migrate state sync reactor to Protobuf encoding (@marbar3778)
  327. - Blockchain Protocol
  328. - [evidence] [\#4725](https://github.com/tendermint/tendermint/pull/4725) Remove `Pubkey` from `DuplicateVoteEvidence` (@marbar3778)
  329. - [evidence] [\#5499](https://github.com/tendermint/tendermint/pull/5449) Cap evidence to a maximum number of bytes (supercedes [\#4780](https://github.com/tendermint/tendermint/pull/4780)) (@cmwaters)
  330. - [merkle] [\#5193](https://github.com/tendermint/tendermint/pull/5193) Header hashes are no longer empty for empty inputs, notably `DataHash`, `EvidenceHash`, and `LastResultsHash` (@erikgrinaker)
  331. - [state] [\#4845](https://github.com/tendermint/tendermint/pull/4845) Include `GasWanted` and `GasUsed` into `LastResultsHash` (@melekes)
  332. - [types] [\#4792](https://github.com/tendermint/tendermint/pull/4792) Sort validators by voting power to enable faster commit verification (@melekes)
  333. - On-disk serialization
  334. - [state] [\#4679](https://github.com/tendermint/tendermint/pull/4679) Migrate state module to Protobuf encoding (@marbar3778)
  335. - `BlockStoreStateJSON` is now `BlockStoreState` and is encoded as binary in the database
  336. - [store] [\#4778](https://github.com/tendermint/tendermint/pull/4778) Migrate store module to Protobuf encoding (@marbar3778)
  337. - Light client, private validator
  338. - [light] [\#4964](https://github.com/tendermint/tendermint/pull/4964) Migrate light module migration to Protobuf encoding (@marbar3778)
  339. - [privval] [\#4985](https://github.com/tendermint/tendermint/pull/4985) Migrate `privval` module to Protobuf encoding (@marbar3778)
  340. - Go API
  341. - [consensus] [\#4582](https://github.com/tendermint/tendermint/pull/4582) RoundState: `Round`, `LockedRound` & `CommitRound` are now `int32` (@marbar3778)
  342. - [consensus] [\#4582](https://github.com/tendermint/tendermint/pull/4582) HeightVoteSet: `round` is now `int32` (@marbar3778)
  343. - [crypto] [\#4721](https://github.com/tendermint/tendermint/pull/4721) Remove `SimpleHashFromMap()` and `SimpleProofsFromMap()` (@erikgrinaker)
  344. - [crypto] [\#4940](https://github.com/tendermint/tendermint/pull/4940) All keys have become `[]byte` instead of `[<size>]byte`. The byte method no longer returns the marshaled value but just the `[]byte` form of the data. (@marbar3778)
  345. - [crypto] [\#4988](https://github.com/tendermint/tendermint/pull/4988) Removal of key type multisig (@marbar3778)
  346. - The key has been moved to the [Cosmos-SDK](https://github.com/cosmos/cosmos-sdk/blob/master/crypto/types/multisig/multisignature.go)
  347. - [crypto] [\#4989](https://github.com/tendermint/tendermint/pull/4989) Remove `Simple` prefixes from `SimpleProof`, `SimpleValueOp` & `SimpleProofNode`. (@marbar3778)
  348. - `merkle.Proof` has been renamed to `ProofOps`.
  349. - Protobuf messages `Proof` & `ProofOp` has been moved to `proto/crypto/merkle`
  350. - `SimpleHashFromByteSlices` has been renamed to `HashFromByteSlices`
  351. - `SimpleHashFromByteSlicesIterative` has been renamed to `HashFromByteSlicesIterative`
  352. - `SimpleProofsFromByteSlices` has been renamed to `ProofsFromByteSlices`
  353. - [crypto] [\#4941](https://github.com/tendermint/tendermint/pull/4941) Remove suffixes from all keys. (@marbar3778)
  354. - ed25519: type `PrivKeyEd25519` is now `PrivKey`
  355. - ed25519: type `PubKeyEd25519` is now `PubKey`
  356. - secp256k1: type`PrivKeySecp256k1` is now `PrivKey`
  357. - secp256k1: type`PubKeySecp256k1` is now `PubKey`
  358. - sr25519: type `PrivKeySr25519` is now `PrivKey`
  359. - sr25519: type `PubKeySr25519` is now `PubKey`
  360. - [crypto] [\#5214](https://github.com/tendermint/tendermint/pull/5214) Change `GenPrivKeySecp256k1` to `GenPrivKeyFromSecret` to be consistent with other keys (@marbar3778)
  361. - [crypto] [\#5236](https://github.com/tendermint/tendermint/pull/5236) `VerifyBytes` is now `VerifySignature` on the `crypto.PubKey` interface (@marbar3778)
  362. - [evidence] [\#5361](https://github.com/tendermint/tendermint/pull/5361) Add LightClientAttackEvidence and change evidence interface (@cmwaters)
  363. - [libs] [\#4831](https://github.com/tendermint/tendermint/pull/4831) Remove `Bech32` pkg from Tendermint. This pkg now lives in the [cosmos-sdk](https://github.com/cosmos/cosmos-sdk/tree/4173ea5ebad906dd9b45325bed69b9c655504867/types/bech32) (@marbar3778)
  364. - [light] [\#4946](https://github.com/tendermint/tendermint/pull/4946) Rename `lite2` pkg to `light`. Remove `lite` implementation. (@marbar3778)
  365. - [light] [\#5347](https://github.com/tendermint/tendermint/pull/5347) `NewClient`, `NewHTTPClient`, `VerifyHeader` and `VerifyLightBlockAtHeight` now accept `context.Context` as 1st param (@melekes)
  366. - [merkle] [\#5193](https://github.com/tendermint/tendermint/pull/5193) `HashFromByteSlices` and `ProofsFromByteSlices` now return a hash for empty inputs, following RFC6962 (@erikgrinaker)
  367. - [proto] [\#5025](https://github.com/tendermint/tendermint/pull/5025) All proto files have been moved to `/proto` directory. (@marbar3778)
  368. - Using the recommended the file layout from buf, [see here for more info](https://buf.build/docs/lint-checkers#file_layout)
  369. - [rpc/client] [\#4947](https://github.com/tendermint/tendermint/pull/4947) `Validators`, `TxSearch` `page`/`per_page` params become pointers (@melekes)
  370. - `UnconfirmedTxs` `limit` param is a pointer
  371. - [rpc/jsonrpc/server] [\#5141](https://github.com/tendermint/tendermint/pull/5141) Remove `WriteRPCResponseArrayHTTP` (use `WriteRPCResponseHTTP` instead) (@melekes)
  372. - [state] [\#4679](https://github.com/tendermint/tendermint/pull/4679) `TxResult` is a Protobuf type defined in `abci` types directory (@marbar3778)
  373. - [state] [\#5191](https://github.com/tendermint/tendermint/pull/5191) Add `State.InitialHeight` field to record initial block height, must be `1` (not `0`) to start from 1 (@erikgrinaker)
  374. - [state] [\#5231](https://github.com/tendermint/tendermint/pull/5231) `LoadStateFromDBOrGenesisFile()` and `LoadStateFromDBOrGenesisDoc()` no longer saves the state in the database if not found, the genesis state is simply returned (@erikgrinaker)
  375. - [state] [\#5348](https://github.com/tendermint/tendermint/pull/5348) Define an Interface for the state store. (@marbar3778)
  376. - [types] [\#4939](https://github.com/tendermint/tendermint/pull/4939) `SignedMsgType` has moved to a Protobuf enum types (@marbar3778)
  377. - [types] [\#4962](https://github.com/tendermint/tendermint/pull/4962) `ConsensusParams`, `BlockParams`, `EvidenceParams`, `ValidatorParams` & `HashedParams` are now Protobuf types (@marbar3778)
  378. - [types] [\#4852](https://github.com/tendermint/tendermint/pull/4852) Vote & Proposal `SignBytes` is now func `VoteSignBytes` & `ProposalSignBytes` (@marbar3778)
  379. - [types] [\#4798](https://github.com/tendermint/tendermint/pull/4798) Simplify `VerifyCommitTrusting` func + remove extra validation (@melekes)
  380. - [types] [\#4845](https://github.com/tendermint/tendermint/pull/4845) Remove `ABCIResult` (@melekes)
  381. - [types] [\#5029](https://github.com/tendermint/tendermint/pull/5029) Rename all values from `PartsHeader` to `PartSetHeader` to have consistency (@marbar3778)
  382. - [types] [\#4939](https://github.com/tendermint/tendermint/pull/4939) `Total` in `Parts` & `PartSetHeader` has been changed from a `int` to a `uint32` (@marbar3778)
  383. - [types] [\#4939](https://github.com/tendermint/tendermint/pull/4939) Vote: `ValidatorIndex` & `Round` are now `int32` (@marbar3778)
  384. - [types] [\#4939](https://github.com/tendermint/tendermint/pull/4939) Proposal: `POLRound` & `Round` are now `int32` (@marbar3778)
  385. - [types] [\#4939](https://github.com/tendermint/tendermint/pull/4939) Block: `Round` is now `int32` (@marbar3778)
  386. ### FEATURES
  387. - [abci] [\#5031](https://github.com/tendermint/tendermint/pull/5031) Add `AppVersion` to consensus parameters (@james-ray)
  388. - This makes it possible to update your ABCI application version via `EndBlock` response
  389. - [abci] [\#5174](https://github.com/tendermint/tendermint/pull/5174) Remove `MockEvidence` in favor of testing with actual evidence types (`DuplicateVoteEvidence` & `LightClientAttackEvidence`) (@cmwaters)
  390. - [abci] [\#5191](https://github.com/tendermint/tendermint/pull/5191) Add `InitChain.InitialHeight` field giving the initial block height (@erikgrinaker)
  391. - [abci] [\#5227](https://github.com/tendermint/tendermint/pull/5227) Add `ResponseInitChain.app_hash` which is recorded in genesis block (@erikgrinaker)
  392. - [config] [\#5147](https://github.com/tendermint/tendermint/pull/5147) Add `--consensus.double_sign_check_height` flag and `DoubleSignCheckHeight` config variable. See [ADR-51](https://github.com/tendermint/tendermint/blob/master/docs/architecture/adr-051-double-signing-risk-reduction.md) (@dongsam)
  393. - [db] [\#5233](https://github.com/tendermint/tendermint/pull/5233) Add support for `badgerdb` database backend (@erikgrinaker)
  394. - [evidence] [\#4532](https://github.com/tendermint/tendermint/pull/4532) Handle evidence from light clients (@melekes)
  395. - [evidence] [#4821](https://github.com/tendermint/tendermint/pull/4821) Amnesia (light client attack) evidence can be detected, verified and committed (@cmwaters)
  396. - [genesis] [\#5191](https://github.com/tendermint/tendermint/pull/5191) Add `initial_height` field to specify the initial chain height (defaults to `1`) (@erikgrinaker)
  397. - [libs/math] [\#5665](https://github.com/tendermint/tendermint/pull/5665) Make fractions unsigned integers (uint64) (@cmwaters)
  398. - [light] [\#5298](https://github.com/tendermint/tendermint/pull/5298) Morph validator set and signed header into light block (@cmwaters)
  399. - [p2p] [\#4981](https://github.com/tendermint/tendermint/pull/4981) Expose `SaveAs` func on NodeKey (@melekes)
  400. - [privval] [\#5239](https://github.com/tendermint/tendermint/pull/5239) Add `chainID` to requests from client. (@marbar3778)
  401. - [rpc] [\#4532](https://github.com/tendermint/tendermint/pull/4923) Support `BlockByHash` query (@fedekunze)
  402. - [rpc] [\#4979](https://github.com/tendermint/tendermint/pull/4979) Support EXISTS operator in `/tx_search` query (@melekes)
  403. - [rpc] [\#5017](https://github.com/tendermint/tendermint/pull/5017) Add `/check_tx` endpoint to check transactions without executing them or adding them to the mempool (@melekes)
  404. - [rpc] [\#5108](https://github.com/tendermint/tendermint/pull/5108) Subscribe using the websocket for new evidence events (@cmwaters)
  405. - [statesync] Add state sync support, where a new node can be rapidly bootstrapped by fetching state snapshots from peers instead of replaying blocks. See the `[statesync]` config section.
  406. - [evidence] [\#5361](https://github.com/tendermint/tendermint/pull/5361) Add LightClientAttackEvidence and refactor evidence lifecycle - for more information see [ADR-059](https://github.com/tendermint/tendermint/blob/master/docs/architecture/adr-059-evidence-composition-and-lifecycle.md) (@cmwaters)
  407. ### IMPROVEMENTS
  408. - [blockchain] [\#5278](https://github.com/tendermint/tendermint/pull/5278) Verify only +2/3 of the signatures in a block when fast syncing. (@marbar3778)
  409. - [consensus] [\#4578](https://github.com/tendermint/tendermint/pull/4578) Attempt to repair the consensus WAL file (`data/cs.wal/wal`) automatically in case of corruption (@alessio)
  410. - The original WAL file will be backed up to `data/cs.wal/wal.CORRUPTED`.
  411. - [consensus] [\#5143](https://github.com/tendermint/tendermint/pull/5143) Only call `privValidator.GetPubKey` once per block (@melekes)
  412. - [evidence] [\#4722](https://github.com/tendermint/tendermint/pull/4722) Consolidate evidence store and pool types to improve evidence DB (@cmwaters)
  413. - [evidence] [\#4839](https://github.com/tendermint/tendermint/pull/4839) Reject duplicate evidence from being proposed (@cmwaters)
  414. - [evidence] [\#5219](https://github.com/tendermint/tendermint/pull/5219) Change the source of evidence time to block time (@cmwaters)
  415. - [libs] [\#5126](https://github.com/tendermint/tendermint/pull/5126) Add a sync package which wraps sync.(RW)Mutex & deadlock.(RW)Mutex and use a build flag (deadlock) in order to enable deadlock checking (@marbar3778)
  416. - [light] [\#4935](https://github.com/tendermint/tendermint/pull/4935) Fetch and compare a new header with witnesses in parallel (@melekes)
  417. - [light] [\#4929](https://github.com/tendermint/tendermint/pull/4929) Compare header with witnesses only when doing bisection (@melekes)
  418. - [light] [\#4916](https://github.com/tendermint/tendermint/pull/4916) Validate basic for inbound validator sets and headers before further processing them (@cmwaters)
  419. - [mempool] Add RemoveTxByKey() exported function for custom mempool cleaning (@p4u)
  420. - [p2p/conn] [\#4795](https://github.com/tendermint/tendermint/pull/4795) Return err on `signChallenge()` instead of panic
  421. - [privval] [\#5437](https://github.com/tendermint/tendermint/pull/5437) `NewSignerDialerEndpoint` can now be given `SignerServiceEndpointOption` (@erikgrinaker)
  422. - [rpc] [\#4968](https://github.com/tendermint/tendermint/pull/4968) JSON encoding is now handled by `libs/json`, not Amino (@erikgrinaker)
  423. - [rpc] [\#5293](https://github.com/tendermint/tendermint/pull/5293) `/dial_peers` has added `private` and `unconditional` as parameters. (@marbar3778)
  424. - [state] [\#4781](https://github.com/tendermint/tendermint/pull/4781) Export `InitStateVersion` for the initial state version (@erikgrinaker)
  425. - [txindex] [\#4466](https://github.com/tendermint/tendermint/pull/4466) Allow to index an event at runtime (@favadi)
  426. - `abci.EventAttribute` replaces `KV.Pair`
  427. - [types] [\#4905](https://github.com/tendermint/tendermint/pull/4905) Add `ValidateBasic` to validator and validator set (@cmwaters)
  428. - [types] [\#5340](https://github.com/tendermint/tendermint/pull/5340) Add check in `Header.ValidateBasic()` for block protocol version (@marbar3778)
  429. - [types] [\#5490](https://github.com/tendermint/tendermint/pull/5490) Use `Commit` and `CommitSig` max sizes instead of vote max size to calculate the maximum block size. (@cmwaters)
  430. ### BUG FIXES
  431. - [abci/grpc] [\#5520](https://github.com/tendermint/tendermint/pull/5520) Return async responses in order, to avoid mempool panics. (@erikgrinaker)
  432. - [blockchain/v2] [\#4971](https://github.com/tendermint/tendermint/pull/4971) Correctly set block store base in status responses (@erikgrinaker)
  433. - [blockchain/v2] [\#5499](https://github.com/tendermint/tendermint/pull/5499) Fix "duplicate block enqueued by processor" panic (@melekes)
  434. - [blockchain/v2] [\#5530](https://github.com/tendermint/tendermint/pull/5530) Fix out of order block processing panic (@melekes)
  435. - [blockchain/v2] [\#5553](https://github.com/tendermint/tendermint/pull/5553) Make the removal of an already removed peer a noop (@melekes)
  436. - [consensus] [\#4895](https://github.com/tendermint/tendermint/pull/4895) Cache the address of the validator to reduce querying a remote KMS (@joe-bowman)
  437. - [consensus] [\#4970](https://github.com/tendermint/tendermint/pull/4970) Don't allow `LastCommitRound` to be negative (@cuonglm)
  438. - [consensus] [\#5329](https://github.com/tendermint/tendermint/pull/5329) Fix wrong proposer schedule for validators returned by `InitChain` (@erikgrinaker)
  439. - [docker] [\#5385](https://github.com/tendermint/tendermint/pull/5385) Fix incorrect `time_iota_ms` default setting causing block timestamp drift (@erikgrinaker)
  440. - [evidence] [\#5170](https://github.com/tendermint/tendermint/pull/5170) Change ABCI evidence time to the time the infraction happened not the time the evidence was committed on the block (@cmwaters)
  441. - [evidence] [\#5610](https://github.com/tendermint/tendermint/pull/5610) Make it possible for ABCI evidence to be formed from Tendermint evidence (@cmwaters)
  442. - [libs/rand] [\#5215](https://github.com/tendermint/tendermint/pull/5215) Fix out-of-memory error on unexpected argument of Str() (@SadPencil)
  443. - [light] [\#5307](https://github.com/tendermint/tendermint/pull/5307) Persist correct proposer priority in light client validator sets (@cmwaters)
  444. - [p2p] [\#5136](https://github.com/tendermint/tendermint/pull/5136) Fix error for peer with the same ID but different IPs (@valardragon)
  445. - [privval] [\#5638](https://github.com/tendermint/tendermint/pull/5638) Increase read/write timeout to 5s and calculate ping interval based on it (@JoeKash)
  446. - [proxy] [\#5078](https://github.com/tendermint/tendermint/pull/5078) Force Tendermint to exit when ABCI app crashes (@melekes)
  447. - [rpc] [\#5660](https://github.com/tendermint/tendermint/pull/5660) Set `application/json` as the `Content-Type` header in RPC responses. (@alexanderbez)
  448. - [store] [\#5382](https://github.com/tendermint/tendermint/pull/5382) Fix race conditions when loading/saving/pruning blocks (@erikgrinaker)
  449. ## v0.33.8
  450. *August 11, 2020*
  451. ### Go security update
  452. Go reported a security vulnerability that affected the `encoding/binary` package. The most recent binary for tendermint is using 1.14.6, for this
  453. reason the Tendermint engineering team has opted to conduct a release to aid users in using the correct version of Go. Read more about the security issue [here](https://github.com/golang/go/issues/40618).
  454. ## v0.33.7
  455. *August 4, 2020*
  456. ### BUG FIXES:
  457. - [go] Build release binary using Go 1.14.4, to avoid halt caused by Go 1.14.1 (https://github.com/golang/go/issues/38223)
  458. - [privval] [\#5140](https://github.com/tendermint/tendermint/pull/5140) `RemoteSignerError` from remote signers are no longer retried (@melekes)
  459. ## v0.33.6
  460. *July 2, 2020*
  461. This security release fixes:
  462. ### Denial of service
  463. Tendermint 0.33.0 and above allow block proposers to include signatures for the
  464. wrong block. This may happen naturally if you start a network, have it run for
  465. some time and restart it **without changing the chainID**. (It is a
  466. [misconfiguration](https://docs.tendermint.com/master/tendermint-core/using-tendermint.html)
  467. to reuse chainIDs.) Correct block proposers will accidentally include signatures
  468. for the wrong block if they see these signatures, and then commits won't validate,
  469. making all proposed blocks invalid. A malicious validator (even with a minimal
  470. amount of stake) can use this vulnerability to completely halt the network.
  471. Tendermint 0.33.6 checks all the signatures are for the block with +2/3
  472. majority before creating a commit.
  473. ### False Witness
  474. Tendermint 0.33.1 and above are no longer fully verifying commit signatures
  475. during block execution - they stop after +2/3. This means proposers can propose
  476. blocks that contain valid +2/3 signatures and then the rest of the signatures
  477. can be whatever they want. They can claim that all the other validators signed
  478. just by including a CommitSig with arbitrary signature data. While this doesn't
  479. seem to impact safety of Tendermint per se, it means that Commits may contain a
  480. lot of invalid data.
  481. _This was already true of blocks, since they could include invalid txs filled
  482. with garbage, but in that case the application knew that they are invalid and
  483. could punish the proposer. But since applications didn't--and don't--
  484. verify commit signatures directly (they trust Tendermint to do that),
  485. they won't be able to detect it._
  486. This can impact incentivization logic in the application that depends on the
  487. LastCommitInfo sent in BeginBlock, which includes which validators signed. For
  488. instance, Gaia incentivizes proposers with a bonus for including more than +2/3
  489. of the signatures. But a proposer can now claim that bonus just by including
  490. arbitrary data for the final -1/3 of validators without actually waiting for
  491. their signatures. There may be other tricks that can be played because of this.
  492. Tendermint 0.33.6 verifies all the signatures during block execution.
  493. _Please note that the light client does not check nil votes and exits as soon
  494. as 2/3+ of the signatures are checked._
  495. **All clients are recommended to upgrade.**
  496. Special thanks to @njmurarka at Bluzelle Networks for reporting this.
  497. ### SECURITY:
  498. - [consensus] Do not allow signatures for a wrong block in commits (@ebuchman)
  499. - [consensus] Verify all the signatures during block execution (@melekes)
  500. **Please note that the fix for the False Witness issue renames the `VerifyCommitTrusting`
  501. function to `VerifyCommitLightTrusting`. If you were relying on the light client, you may
  502. need to update your code.**
  503. ## v0.33.5
  504. *May 28, 2020*
  505. Special thanks to external contributors on this release: @tau3,
  506. ### BREAKING CHANGES:
  507. - Go API
  508. - [privval] [\#4744](https://github.com/tendermint/tendermint/pull/4744) Remove deprecated `OldFilePV` (@melekes)
  509. - [mempool] [\#4759](https://github.com/tendermint/tendermint/pull/4759) Modify `Mempool#InitWAL` to return an error (@melekes)
  510. - [node] [\#4832](https://github.com/tendermint/tendermint/pull/4832) `ConfigureRPC` returns an error (@melekes)
  511. - [rpc] [\#4836](https://github.com/tendermint/tendermint/pull/4836) Overhaul `lib` folder (@melekes)
  512. Move lib/ folder to jsonrpc/.
  513. Rename:
  514. rpc package -> jsonrpc package
  515. rpcclient package -> client package
  516. rpcserver package -> server package
  517. JSONRPCClient to Client
  518. JSONRPCRequestBatch to RequestBatch
  519. JSONRPCCaller to Caller
  520. StartHTTPServer to Serve
  521. StartHTTPAndTLSServer to ServeTLS
  522. NewURIClient to NewURI
  523. NewJSONRPCClient to New
  524. NewJSONRPCClientWithHTTPClient to NewWithHTTPClient
  525. NewWSClient to NewWS
  526. Unexpose ResponseWriterWrapper
  527. Remove unused http_params.go
  528. ### FEATURES:
  529. - [pex] [\#4439](https://github.com/tendermint/tendermint/pull/4439) Use highwayhash for pex buckets (@tau3)
  530. ### IMPROVEMENTS:
  531. - [abci/server] [\#4719](https://github.com/tendermint/tendermint/pull/4719) Print panic & stack trace to STDERR if logger is not set (@melekes)
  532. - [types] [\#4638](https://github.com/tendermint/tendermint/pull/4638) Implement `Header#ValidateBasic` (@alexanderbez)
  533. - [buildsystem] [\#4378](https://github.com/tendermint/tendermint/pull/4738) Replace build_c and install_c with TENDERMINT_BUILD_OPTIONS parsing. The following options are available:
  534. - nostrip: don't strip debugging symbols nor DWARF tables.
  535. - cleveldb: use cleveldb as db backend instead of goleveldb.
  536. - race: pass -race to go build and enable data race detection.
  537. - [mempool] [\#4759](https://github.com/tendermint/tendermint/pull/4759) Allow ReapX and CheckTx functions to run in parallel (@melekes)
  538. - [rpc/core] [\#4844](https://github.com/tendermint/tendermint/pull/4844) Do not lock consensus state in `/validators`, `/consensus_params` and `/status` (@melekes)
  539. ### BUG FIXES:
  540. - [blockchain/v2] [\#4761](https://github.com/tendermint/tendermint/pull/4761) Fix excessive CPU usage caused by spinning on closed channels (@erikgrinaker)
  541. - [blockchain/v2] Respect `fast_sync` option (@erikgrinaker)
  542. - [light] [\#4741](https://github.com/tendermint/tendermint/pull/4741) Correctly return `ErrSignedHeaderNotFound` and `ErrValidatorSetNotFound` on corresponding RPC errors (@erikgrinaker)
  543. - [rpc] [\#4805](https://github.com/tendermint/tendermint/issues/4805) Attempt to handle panics during panic recovery (@erikgrinaker)
  544. - [types] [\#4764](https://github.com/tendermint/tendermint/pull/4764) Return an error if voting power overflows in `VerifyCommitTrusting` (@melekes)
  545. - [privval] [\#4812](https://github.com/tendermint/tendermint/pull/4812) Retry `GetPubKey/SignVote/SignProposal` a few times before returning an error (@melekes)
  546. - [p2p] [\#4847](https://github.com/tendermint/tendermint/pull/4847) Return masked IP (not the actual IP) in addrbook#groupKey (@melekes)
  547. ## v0.33.4
  548. - Nodes are no longer guaranteed to contain all blocks up to the latest height. The ABCI app can now control which blocks to retain through the ABCI field `ResponseCommit.retain_height`, all blocks and associated data below this height will be removed.
  549. *April 21, 2020*
  550. Special thanks to external contributors on this release: @whylee259, @greg-szabo
  551. ### BREAKING CHANGES:
  552. - Go API
  553. - [lite2] [\#4616](https://github.com/tendermint/tendermint/pull/4616) Make `maxClockDrift` an option `Verify/VerifyAdjacent/VerifyNonAdjacent` now accept `maxClockDrift time.Duration` (@melekes).
  554. - [rpc/client] [\#4628](https://github.com/tendermint/tendermint/pull/4628) Split out HTTP and local clients into `http` and `local` packages (@erikgrinaker).
  555. ### FEATURES:
  556. - [abci] [\#4588](https://github.com/tendermint/tendermint/issues/4588) Add `ResponseCommit.retain_height` field, which will automatically remove blocks below this height. This bumps the ABCI version to 0.16.2 (@erikgrinaker).
  557. - [cmd] [\#4665](https://github.com/tendermint/tendermint/pull/4665) New `tendermint completion` command to generate Bash/Zsh completion scripts (@alessio).
  558. - [rpc] [\#4588](https://github.com/tendermint/tendermint/issues/4588) Add `/status` response fields for the earliest block available on the node (@erikgrinaker).
  559. - [rpc] [\#4611](https://github.com/tendermint/tendermint/pull/4611) Add `codespace` to `ResultBroadcastTx` (@whylee259).
  560. ### IMPROVEMENTS:
  561. - [all] [\#4608](https://github.com/tendermint/tendermint/pull/4608) Give reactors descriptive names when they're initialized (@tessr).
  562. - [blockchain] [\#4588](https://github.com/tendermint/tendermint/issues/4588) Add `Base` to blockchain reactor P2P messages `StatusRequest` and `StatusResponse` (@erikgrinaker).
  563. - [Docker] [\#4569](https://github.com/tendermint/tendermint/issues/4569) Default configuration added to docker image (you can still mount your own config the same way) (@greg-szabo).
  564. - [example/kvstore] [\#4588](https://github.com/tendermint/tendermint/issues/4588) Add `RetainBlocks` option to control block retention (@erikgrinaker).
  565. - [evidence] [\#4632](https://github.com/tendermint/tendermint/pull/4632) Inbound evidence checked if already existing (@cmwaters).
  566. - [lite2] [\#4575](https://github.com/tendermint/tendermint/pull/4575) Use bisection for within-range verification (@cmwaters).
  567. - [lite2] [\#4562](https://github.com/tendermint/tendermint/pull/4562) Cache headers when using bisection (@cmwaters).
  568. - [p2p] [\#4548](https://github.com/tendermint/tendermint/pull/4548) Add ban list to address book (@cmwaters).
  569. - [privval] [\#4534](https://github.com/tendermint/tendermint/issues/4534) Add `error` as a return value on`GetPubKey()` (@marbar3778).
  570. - [p2p] [\#4621](https://github.com/tendermint/tendermint/issues/4621) Ban peers when messages are unsolicited or too frequent (@cmwaters).
  571. - [rpc] [\#4703](https://github.com/tendermint/tendermint/pull/4703) Add `count` and `total` to `/validators` response (@melekes).
  572. - [tools] [\#4615](https://github.com/tendermint/tendermint/issues/4615) Allow developers to use Docker to generate proto stubs, via `make proto-gen-docker` (@erikgrinaker).
  573. ### BUG FIXES:
  574. - [rpc] [\#4568](https://github.com/tendermint/tendermint/issues/4568) Fix panic when `Subscribe` is called, but HTTP client is not running. `Subscribe`, `Unsubscribe(All)` methods return an error now (@melekes).
  575. ## v0.33.3
  576. *April 6, 2020*
  577. This security release fixes:
  578. ### Denial of service 1
  579. Tendermint 0.33.2 and earlier does not limit P2P connection requests number.
  580. For each p2p connection, Tendermint allocates ~0.5MB. Even though this
  581. memory is garbage collected once the connection is terminated (due to duplicate
  582. IP or reaching a maximum number of inbound peers), temporary memory spikes can
  583. lead to OOM (Out-Of-Memory) exceptions.
  584. Tendermint 0.33.3 (and 0.32.10) limits the total number of P2P incoming
  585. connection requests to to `p2p.max_num_inbound_peers +
  586. len(p2p.unconditional_peer_ids)`.
  587. Notes:
  588. - Tendermint does not rate limit P2P connection requests per IP (an attacker
  589. can saturate all the inbound slots);
  590. - Tendermint does not rate limit HTTP(S) requests. If you expose any RPC
  591. endpoints to the public, please make sure to put in place some protection
  592. (https://www.nginx.com/blog/rate-limiting-nginx/). We may implement this in
  593. the future ([\#1696](https://github.com/tendermint/tendermint/issues/1696)).
  594. ### Denial of service 2
  595. Tendermint 0.33.2 and earlier does not reclaim `activeID` of a peer after it's
  596. removed in `Mempool` reactor. This does not happen all the time. It only
  597. happens when a connection fails (for any reason) before the Peer is created and
  598. added to all reactors. `RemovePeer` is therefore called before `AddPeer`, which
  599. leads to always growing memory (`activeIDs` map). The `activeIDs` map has a
  600. maximum size of 65535 and the node will panic if this map reaches the maximum.
  601. An attacker can create a lot of connection attempts (exploiting Denial of
  602. service 1), which ultimately will lead to the node panicking.
  603. Tendermint 0.33.3 (and 0.32.10) claims `activeID` for a peer in `InitPeer`,
  604. which is executed before `MConnection` is started.
  605. Notes:
  606. - `InitPeer` function was added to all reactors to combat a similar issue -
  607. [\#3338](https://github.com/tendermint/tendermint/issues/3338);
  608. - Denial of service 2 is independent of Denial of service 1 and can be executed
  609. without it.
  610. **All clients are recommended to upgrade**
  611. Special thanks to [fudongbai](https://hackerone.com/fudongbai) for finding
  612. and reporting this.
  613. ### SECURITY:
  614. - [mempool] Reserve IDs in InitPeer instead of AddPeer (@tessr)
  615. - [p2p] Limit the number of incoming connections (@melekes)
  616. ## v0.33.2
  617. *March 11, 2020*
  618. Special thanks to external contributors on this release:
  619. @antho1404, @michaelfig, @gterzian, @tau3, @Shivani912
  620. ### BREAKING CHANGES:
  621. - CLI/RPC/Config
  622. - [cli] [\#4505](https://github.com/tendermint/tendermint/pull/4505) `tendermint lite` sub-command new syntax (@melekes):
  623. `lite cosmoshub-3 -p 52.57.29.196:26657 -w public-seed-node.cosmoshub.certus.one:26657
  624. --height 962118 --hash 28B97BE9F6DE51AC69F70E0B7BFD7E5C9CD1A595B7DC31AFF27C50D4948`
  625. - Go API
  626. - [lite2] [\#4535](https://github.com/tendermint/tendermint/pull/4535) Remove `Start/Stop` (@melekes)
  627. - [lite2] [\#4469](https://github.com/tendermint/tendermint/issues/4469) Remove `RemoveNoLongerTrustedHeaders` and `RemoveNoLongerTrustedHeadersPeriod` option (@cmwaters)
  628. - [lite2] [\#4473](https://github.com/tendermint/tendermint/issues/4473) Return height as a 2nd param in `TrustedValidatorSet` (@melekes)
  629. - [lite2] [\#4536](https://github.com/tendermint/tendermint/pull/4536) `Update` returns a signed header (1st param) (@melekes)
  630. ### IMPROVEMENTS:
  631. - [blockchain/v2] [\#4361](https://github.com/tendermint/tendermint/pull/4361) Add reactor (@brapse)
  632. - [cmd] [\#4515](https://github.com/tendermint/tendermint/issues/4515) Change `tendermint debug dump` sub-command archives filename's format (@melekes)
  633. - [consensus] [\#3583](https://github.com/tendermint/tendermint/issues/3583) Reduce `non-deterministic signature` log noise (@tau3)
  634. - [examples/kvstore] [\#4507](https://github.com/tendermint/tendermint/issues/4507) ABCI query now returns the proper height (@erikgrinaker)
  635. - [lite2] [\#4462](https://github.com/tendermint/tendermint/issues/4462) Add `NewHTTPClient` and `NewHTTPClientFromTrustedStore` (@cmwaters)
  636. - [lite2] [\#4329](https://github.com/tendermint/tendermint/issues/4329) modified bisection to loop (@cmwaters)
  637. - [lite2] [\#4385](https://github.com/tendermint/tendermint/issues/4385) Disconnect from bad nodes (@melekes)
  638. - [lite2] [\#4398](https://github.com/tendermint/tendermint/issues/4398) Add `VerifyAdjacent` and `VerifyNonAdjacent` funcs (@cmwaters)
  639. - [lite2] [\#4426](https://github.com/tendermint/tendermint/issues/4426) Don't save intermediate headers (@cmwaters)
  640. - [lite2] [\#4464](https://github.com/tendermint/tendermint/issues/4464) Cross-check first header (@cmwaters)
  641. - [lite2] [\#4470](https://github.com/tendermint/tendermint/issues/4470) Fix inconsistent header-validatorset pairing (@melekes)
  642. - [lite2] [\#4488](https://github.com/tendermint/tendermint/issues/4488) Allow local clock drift -10 sec. (@melekes)
  643. - [p2p] [\#4449](https://github.com/tendermint/tendermint/pull/4449) Use `curve25519.X25519()` instead of `ScalarMult` (@erikgrinaker)
  644. - [types] [\#4417](https://github.com/tendermint/tendermint/issues/4417) **VerifyCommitX() functions should return as soon as +2/3 threshold is reached** (@alessio).
  645. - [libs/kv] [\#4542](https://github.com/tendermint/tendermint/pull/4542) remove unused type KI64Pair (@tessr)
  646. ### BUG FIXES:
  647. - [cmd] [\#4303](https://github.com/tendermint/tendermint/issues/4303) Show useful error when Tendermint is not initialized (@melekes)
  648. - [cmd] [\#4515](https://github.com/tendermint/tendermint/issues/4515) **Fix `tendermint debug kill` sub-command** (@melekes)
  649. - [rpc] [\#3935](https://github.com/tendermint/tendermint/issues/3935) **Create buffered subscriptions on `/subscribe`** (@melekes)
  650. - [rpc] [\#4375](https://github.com/tendermint/tendermint/issues/4375) Stop searching for txs in `/tx_search` upon client timeout (@gterzian)
  651. - [rpc] [\#4406](https://github.com/tendermint/tendermint/pull/4406) Fix issue with multiple subscriptions on the websocket (@antho1404)
  652. - [rpc] [\#4432](https://github.com/tendermint/tendermint/issues/4432) Fix `/tx_search` pagination with ordered results (@erikgrinaker)
  653. - [rpc] [\#4492](https://github.com/tendermint/tendermint/issues/4492) Keep the original subscription "id" field when new RPCs come in (@michaelfig)
  654. ## v0.33.1
  655. *Feburary 13, 2020*
  656. Special thanks to external contributors on this release:
  657. @princesinha19
  658. ### FEATURES:
  659. - [rpc] [\#3333](https://github.com/tendermint/tendermint/issues/3333) Add `order_by` to `/tx_search` endpoint, allowing to change default ordering from asc to desc (@princesinha19)
  660. ### IMPROVEMENTS:
  661. - [proto] [\#4369](https://github.com/tendermint/tendermint/issues/4369) Add [buf](https://buf.build/) for usage with linting and checking if there are breaking changes with the master branch.
  662. - [proto] [\#4369](https://github.com/tendermint/tendermint/issues/4369) Add `make proto-gen` cmd to generate proto stubs outside of GOPATH.
  663. ### BUG FIXES:
  664. - [node] [\#4311](https://github.com/tendermint/tendermint/issues/4311) Use `GRPCMaxOpenConnections` when creating the gRPC server, not `MaxOpenConnections`
  665. - [rpc] [\#4319](https://github.com/tendermint/tendermint/issues/4319) Check `BlockMeta` is not nil in `/block` & `/block_by_hash`
  666. ## v0.33
  667. Special thanks to external contributors on this release: @mrekucci, @PSalant726, @princesinha19, @greg-szabo, @dongsam, @cuonglm, @jgimeno, @yenkhoon
  668. *January 14, 2020*
  669. This release contains breaking changes to the `Block#Header`, specifically
  670. `NumTxs` and `TotalTxs` were removed (\#2521). Here's how this change affects
  671. different modules:
  672. - apps: it breaks the ABCI header field numbering
  673. - state: it breaks the format of `State` on disk
  674. - RPC: all RPC requests which expose the header broke
  675. - Go API: the `Header` broke
  676. - P2P: since blocks go over the wire, technically the P2P protocol broke
  677. Also, blocks are significantly smaller 🔥 because we got rid of the redundant
  678. information in `Block#LastCommit`. `Commit` now mainly consists of a signature
  679. and a validator address plus a timestamp. Note we may remove the validator
  680. address & timestamp fields in the future (see ADR-25).
  681. `lite2` package has been added to solve `lite` issues and introduce weak
  682. subjectivity interface. Refer to the [spec](https://github.com/tendermint/spec/blob/master/spec/consensus/light-client.md) for complete details.
  683. `lite` package is now deprecated and will be removed in v0.34 release.
  684. ### BREAKING CHANGES:
  685. - CLI/RPC/Config
  686. - [rpc] [\#3471](https://github.com/tendermint/tendermint/issues/3471) Paginate `/validators` response (default: 30 vals per page)
  687. - [rpc] [\#3188](https://github.com/tendermint/tendermint/issues/3188) Remove `BlockMeta` in `ResultBlock` in favor of `BlockId` for `/block`
  688. - [rpc] `/block_results` response format updated (see RPC docs for details)
  689. ```
  690. {
  691. "jsonrpc": "2.0",
  692. "id": "",
  693. "result": {
  694. "height": "2109",
  695. "txs_results": null,
  696. "begin_block_events": null,
  697. "end_block_events": null,
  698. "validator_updates": null,
  699. "consensus_param_updates": null
  700. }
  701. }
  702. ```
  703. - [rpc] [\#4141](https://github.com/tendermint/tendermint/pull/4141) Remove `#event` suffix from the ID in event responses.
  704. `{"jsonrpc": "2.0", "id": 0, "result": ...}`
  705. - [rpc] [\#4141](https://github.com/tendermint/tendermint/pull/4141) Switch to integer IDs instead of `json-client-XYZ`
  706. ```
  707. id=0 method=/subscribe
  708. id=0 result=...
  709. id=1 method=/abci_query
  710. id=1 result=...
  711. ```
  712. - ID is unique for each request;
  713. - Request.ID is now optional. Notification is a Request without an ID. Previously ID="" or ID=0 were considered as notifications.
  714. - [config] [\#4046](https://github.com/tendermint/tendermint/issues/4046) Rename tag(s) to CompositeKey & places where tag is still present it was renamed to event or events. Find how a compositeKey is constructed [here](https://github.com/tendermint/tendermint/blob/6d05c531f7efef6f0619155cf10ae8557dd7832f/docs/app-dev/indexing-transactions.md)
  715. - You will have to generate a new config for your Tendermint node(s)
  716. - [genesis] [\#2565](https://github.com/tendermint/tendermint/issues/2565) Add `consensus_params.evidence.max_age_duration`. Rename
  717. `consensus_params.evidence.max_age` to `max_age_num_blocks`.
  718. - [cli] [\#1771](https://github.com/tendermint/tendermint/issues/1771) `tendermint lite` now uses new light client package (`lite2`)
  719. and has 3 more flags: `--trusting-period`, `--trusted-height` and
  720. `--trusted-hash`
  721. - Apps
  722. - [tm-bench] Removed tm-bench in favor of [tm-load-test](https://github.com/informalsystems/tm-load-test)
  723. - Go API
  724. - [rpc] [\#3953](https://github.com/tendermint/tendermint/issues/3953) Modify NewHTTP, NewXXXClient functions to return an error on invalid remote instead of panicking (@mrekucci)
  725. - [rpc/client] [\#3471](https://github.com/tendermint/tendermint/issues/3471) `Validators` now requires two more args: `page` and `perPage`
  726. - [libs/common] [\#3262](https://github.com/tendermint/tendermint/issues/3262) Make error the last parameter of `Task` (@PSalant726)
  727. - [cs/types] [\#3262](https://github.com/tendermint/tendermint/issues/3262) Rename `GotVoteFromUnwantedRoundError` to `ErrGotVoteFromUnwantedRound` (@PSalant726)
  728. - [libs/common] [\#3862](https://github.com/tendermint/tendermint/issues/3862) Remove `errors.go` from `libs/common`
  729. - [libs/common] [\#4230](https://github.com/tendermint/tendermint/issues/4230) Move `KV` out of common to its own pkg
  730. - [libs/common] [\#4230](https://github.com/tendermint/tendermint/issues/4230) Rename `cmn.KVPair(s)` to `kv.Pair(s)`s
  731. - [libs/common] [\#4232](https://github.com/tendermint/tendermint/issues/4232) Move `Service` & `BaseService` from `libs/common` to `libs/service`
  732. - [libs/common] [\#4232](https://github.com/tendermint/tendermint/issues/4232) Move `common/nil.go` to `types/utils.go` & make the functions private
  733. - [libs/common] [\#4231](https://github.com/tendermint/tendermint/issues/4231) Move random functions from `libs/common` into pkg `rand`
  734. - [libs/common] [\#4237](https://github.com/tendermint/tendermint/issues/4237) Move byte functions from `libs/common` into pkg `bytes`
  735. - [libs/common] [\#4237](https://github.com/tendermint/tendermint/issues/4237) Move throttletimer functions from `libs/common` into pkg `timer`
  736. - [libs/common] [\#4237](https://github.com/tendermint/tendermint/issues/4237) Move tempfile functions from `libs/common` into pkg `tempfile`
  737. - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move os functions from `libs/common` into pkg `os`
  738. - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move net functions from `libs/common` into pkg `net`
  739. - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move mathematical functions and types out of `libs/common` to `math` pkg
  740. - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move string functions out of `libs/common` to `strings` pkg
  741. - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move async functions out of `libs/common` to `async` pkg
  742. - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move bit functions out of `libs/common` to `bits` pkg
  743. - [libs/common] [\#4240](https://github.com/tendermint/tendermint/issues/4240) Move cmap functions out of `libs/common` to `cmap` pkg
  744. - [libs/common] [\#4258](https://github.com/tendermint/tendermint/issues/4258) Remove `Rand` from all `rand` pkg functions
  745. - [types] [\#2565](https://github.com/tendermint/tendermint/issues/2565) Remove `MockBadEvidence` & `MockGoodEvidence` in favor of `MockEvidence`
  746. - Blockchain Protocol
  747. - [abci] [\#2521](https://github.com/tendermint/tendermint/issues/2521) Remove `TotalTxs` and `NumTxs` from `Header`
  748. - [types] [\#4151](https://github.com/tendermint/tendermint/pull/4151) Enforce ordering of votes in DuplicateVoteEvidence to be lexicographically sorted on BlockID
  749. - [types] [\#1648](https://github.com/tendermint/tendermint/issues/1648) Change `Commit` to consist of just signatures
  750. - P2P Protocol
  751. - [p2p] [\#3668](https://github.com/tendermint/tendermint/pull/3668) Make `SecretConnection` non-malleable
  752. - [proto] [\#3986](https://github.com/tendermint/tendermint/pull/3986) Prefix protobuf types to avoid name conflicts.
  753. - ABCI becomes `tendermint.abci.types` with the new API endpoint `/tendermint.abci.types.ABCIApplication/`
  754. - core_grpc becomes `tendermint.rpc.grpc` with the new API endpoint `/tendermint.rpc.grpc.BroadcastAPI/`
  755. - merkle becomes `tendermint.crypto.merkle`
  756. - libs.common becomes `tendermint.libs.common`
  757. - proto3 becomes `tendermint.types.proto3`
  758. ### FEATURES:
  759. - [p2p] [\#4053](https://github.com/tendermint/tendermint/issues/4053) Add `unconditional_peer_ids` and `persistent_peers_max_dial_period` config variables (see ADR-050) (@dongsam)
  760. - [tools] [\#4227](https://github.com/tendermint/tendermint/pull/4227) Implement `tendermint debug kill` and
  761. `tendermint debug dump` commands for Tendermint node debugging functionality. See `--help` in both
  762. commands for further documentation and usage.
  763. - [cli] [\#4234](https://github.com/tendermint/tendermint/issues/4234) Add `--db_backend and --db_dir` flags (@princesinha19)
  764. - [cli] [\#4113](https://github.com/tendermint/tendermint/issues/4113) Add optional `--genesis_hash` flag to check genesis hash upon startup
  765. - [config] [\#3831](https://github.com/tendermint/tendermint/issues/3831) Add support for [RocksDB](https://rocksdb.org/) (@Stumble)
  766. - [rpc] [\#3985](https://github.com/tendermint/tendermint/issues/3985) Add new `/block_by_hash` endpoint, which allows to fetch a block by its hash (@princesinha19)
  767. - [metrics] [\#4263](https://github.com/tendermint/tendermint/issues/4263) Add
  768. - `consensus_validator_power`: track your validators power
  769. - `consensus_validator_last_signed_height`: track at which height the validator last signed
  770. - `consensus_validator_missed_blocks`: total amount of missed blocks for a validator
  771. as gauges in prometheus for validator specific metrics
  772. - [rpc/lib] [\#4248](https://github.com/tendermint/tendermint/issues/4248) RPC client basic authentication support (@greg-szabo)
  773. - [lite2] [\#1771](https://github.com/tendermint/tendermint/issues/1771) Light client with weak subjectivity
  774. ### IMPROVEMENTS:
  775. - [rpc] [\#3188](https://github.com/tendermint/tendermint/issues/3188) Added `block_size` to `BlockMeta` this is reflected in `/blockchain`
  776. - [types] [\#2521](https://github.com/tendermint/tendermint/issues/2521) Add `NumTxs` to `BlockMeta` and `EventDataNewBlockHeader`
  777. - [p2p] [\#4185](https://github.com/tendermint/tendermint/pull/4185) Simplify `SecretConnection` handshake with merlin
  778. - [cli] [\#4065](https://github.com/tendermint/tendermint/issues/4065) Add `--consensus.create_empty_blocks_interval` flag (@jgimeno)
  779. - [docs] [\#4065](https://github.com/tendermint/tendermint/issues/4065) Document `--consensus.create_empty_blocks_interval` flag (@jgimeno)
  780. - [crypto] [\#4190](https://github.com/tendermint/tendermint/pull/4190) Added SR25519 signature scheme
  781. - [abci] [\#4177] kvstore: Return `LastBlockHeight` and `LastBlockAppHash` in `Info` (@princesinha19)
  782. - [rpc] [\#2741](https://github.com/tendermint/tendermint/issues/2741) Add `proposer` to `/consensus_state` response (@princesinha19)
  783. - [deps] [\#4289](https://github.com/tendermint/tendermint/pull/4289) Update tm-db to 0.4.0, this includes major breaking changes in the dep that change how errors are handled.
  784. ### BUG FIXES:
  785. - [rpc/lib][\#4051](https://github.com/tendermint/tendermint/pull/4131) Fix RPC client, which was previously resolving https protocol to http (@yenkhoon)
  786. - [rpc] [\#4141](https://github.com/tendermint/tendermint/pull/4141) JSONRPCClient: validate that Response.ID matches Request.ID
  787. - [rpc] [\#4141](https://github.com/tendermint/tendermint/pull/4141) WSClient: check for unsolicited responses
  788. - [types] [\4164](https://github.com/tendermint/tendermint/pull/4164) Prevent temporary power overflows on validator updates
  789. - [cs] [\#4069](https://github.com/tendermint/tendermint/issues/4069) Don't panic when block meta is not found in store (@gregzaitsev)
  790. - [types] [\#4164](https://github.com/tendermint/tendermint/issues/4164) Prevent temporary power overflows on validator updates (joint
  791. efforts of @gchaincl and @ancazamfir)
  792. - [p2p] [\#4140](https://github.com/tendermint/tendermint/issues/4140) `SecretConnection`: use the transcript solely for authentication (i.e. MAC)
  793. - [consensus/types] [\#4243](https://github.com/tendermint/tendermint/issues/4243) fix BenchmarkRoundStateDeepCopy panics (@cuonglm)
  794. - [rpc] [\#4256](https://github.com/tendermint/tendermint/issues/4256) Pass `outCapacity` to `eventBus#Subscribe` when subscribing using a local client
  795. ## v0.32.13
  796. *August 5, 2020*
  797. ### BUG FIXES
  798. - [privval] [\#5112](https://github.com/tendermint/tendermint/issues/5112) If remote signer errors, don't retry (@melekes)
  799. ## v0.32.12
  800. *May 19, 2020*
  801. ### BUG FIXES
  802. - [p2p] [\#4847](https://github.com/tendermint/tendermint/pull/4847) Return masked IP (not the actual IP) in addrbook#groupKey (@melekes)
  803. ## v0.32.11
  804. *April 29, 2020*
  805. ### BUG FIXES:
  806. - [privval] [\#4275](https://github.com/tendermint/tendermint/issues/4275) Fix consensus failure when remote signer drops (@melekes)
  807. ## v0.32.10
  808. *April 6, 2020*
  809. This security release fixes:
  810. ### Denial of Service 1
  811. Tendermint 0.33.2 and earlier does not limit the number of P2P connection
  812. requests. For each p2p connection, Tendermint allocates ~0.5MB. Even though
  813. this memory is garbage collected once the connection is terminated (due to
  814. duplicate IP or reaching a maximum number of inbound peers), temporary memory
  815. spikes can lead to OOM (Out-Of-Memory) exceptions.
  816. Tendermint 0.33.3 (and 0.32.10) limits the total number of P2P incoming
  817. connection requests to to `p2p.max_num_inbound_peers +
  818. len(p2p.unconditional_peer_ids)`.
  819. Notes:
  820. - Tendermint does not rate limit P2P connection requests per IP (an attacker
  821. can saturate all the inbound slots);
  822. - Tendermint does not rate limit HTTP(S) requests. If you expose any RPC
  823. endpoints to the public, please make sure to put in place some protection
  824. (https://www.nginx.com/blog/rate-limiting-nginx/). We may implement this in
  825. the future ([\#1696](https://github.com/tendermint/tendermint/issues/1696)).
  826. ### Denial of Service 2
  827. Tendermint 0.33.2 and earlier does not reclaim `activeID` of a peer after it's
  828. removed in `Mempool` reactor. This does not happen all the time. It only
  829. happens when a connection fails (for any reason) before the Peer is created and
  830. added to all reactors. `RemovePeer` is therefore called before `AddPeer`, which
  831. leads to always growing memory (`activeIDs` map). The `activeIDs` map has a
  832. maximum size of 65535 and the node will panic if this map reaches the maximum.
  833. An attacker can create a lot of connection attempts (exploiting Denial of
  834. Service 1), which ultimately will lead to the node panicking.
  835. Tendermint 0.33.3 (and 0.32.10) claims `activeID` for a peer in `InitPeer`,
  836. which is executed before `MConnection` is started.
  837. Notes:
  838. - `InitPeer` function was added to all reactors to combat a similar issue -
  839. [\#3338](https://github.com/tendermint/tendermint/issues/3338);
  840. - Denial of Service 2 is independent of Denial of Service 1 and can be executed
  841. without it.
  842. **All clients are recommended to upgrade**
  843. Special thanks to [fudongbai](https://hackerone.com/fudongbai) for finding
  844. and reporting this.
  845. ### SECURITY:
  846. - [mempool] Reserve IDs in InitPeer instead of AddPeer (@tessr)
  847. - [p2p] Limit the number of incoming connections (@melekes)
  848. ## v0.32.9
  849. _January, 9, 2020_
  850. Special thanks to external contributors on this release: @greg-szabo, @gregzaitsev, @yenkhoon
  851. ### FEATURES:
  852. - [rpc/lib] [\#4248](https://github.com/tendermint/tendermint/issues/4248) RPC client basic authentication support (@greg-szabo)
  853. - [metrics] [\#4294](https://github.com/tendermint/tendermint/pull/4294) Add
  854. - `consensus_validator_power`: track your validators power
  855. - `consensus_validator_last_signed_height`: track at which height the validator last signed
  856. - `consensus_validator_missed_blocks`: total amount of missed blocks for a validator
  857. as gauges in prometheus for validator specific metrics
  858. ### BUG FIXES:
  859. - [rpc/lib] [\#4131](https://github.com/tendermint/tendermint/pull/4131) Fix RPC client, which was previously resolving https protocol to http (@yenkhoon)
  860. - [cs] [\#4069](https://github.com/tendermint/tendermint/issues/4069) Don't panic when block meta is not found in store (@gregzaitsev)
  861. ## v0.32.8
  862. *November 19, 2019*
  863. Special thanks to external contributors on this release: @erikgrinaker, @guagualvcha, @hsyis, @cosmostuba, @whunmr, @austinabell
  864. ### BREAKING CHANGES:
  865. - Go API
  866. - [libs/pubsub] [\#4070](https://github.com/tendermint/tendermint/pull/4070) `Query#(Matches|Conditions)` returns an error.
  867. ### IMPROVEMENTS:
  868. - [mempool] [\#4083](https://github.com/tendermint/tendermint/pull/4083) Added TxInfo parameter to CheckTx(), and removed CheckTxWithInfo() (@erikgrinaker)
  869. - [mempool] [\#4057](https://github.com/tendermint/tendermint/issues/4057) Include peer ID when logging rejected txns (@erikgrinaker)
  870. - [tools] [\#4023](https://github.com/tendermint/tendermint/issues/4023) Improved `tm-monitor` formatting of start time and avg tx throughput (@erikgrinaker)
  871. - [p2p] [\#3991](https://github.com/tendermint/tendermint/issues/3991) Log "has been established or dialed" as debug log instead of Error for connected peers (@whunmr)
  872. - [rpc] [\#4077](https://github.com/tendermint/tendermint/pull/4077) Added support for `EXISTS` clause to the Websocket query interface.
  873. - [privval] Add `SignerDialerEndpointRetryWaitInterval` option (@cosmostuba)
  874. - [crypto] Add `RegisterKeyType` to amino to allow external key types registration (@austinabell)
  875. ### BUG FIXES:
  876. - [libs/pubsub] [\#4070](https://github.com/tendermint/tendermint/pull/4070) Strip out non-numeric characters when attempting to match numeric values.
  877. - [libs/pubsub] [\#4070](https://github.com/tendermint/tendermint/pull/4070) No longer panic in Query#(Matches|Conditions) preferring to return an error instead.
  878. - [tools] [\#4023](https://github.com/tendermint/tendermint/issues/4023) Refresh `tm-monitor` health when validator count is updated (@erikgrinaker)
  879. - [state] [\#4104](https://github.com/tendermint/tendermint/pull/4104) txindex/kv: Fsync data to disk immediately after receiving it (@guagualvcha)
  880. - [state] [\#4095](https://github.com/tendermint/tendermint/pull/4095) txindex/kv: Return an error if there's one when the user searches for a tx (hash=X) (@hsyis)
  881. ## v0.32.7
  882. *October 18, 2019*
  883. This security release fixes a vulnerability found in the `consensus` package,
  884. where an attacker could construct a `BlockPartMessage` message in such a way
  885. that it will lead to consensus failure. A few similar issues have been
  886. identified and fixed here.
  887. **All clients are recommended to upgrade**
  888. Special thanks to [elvishacker](https://hackerone.com/elvishacker) for finding
  889. and reporting this.
  890. ### BREAKING CHANGES:
  891. - Go API
  892. - [consensus] Modify `WAL#Write` and `WAL#WriteSync` to return an error if
  893. they fail to write a message
  894. ### SECURITY:
  895. - [consensus] Validate incoming messages more throughly
  896. ## v0.32.6
  897. *October 8, 2019*
  898. The previous patch was insufficient because the attacker could still find a way
  899. to submit a `nil` pubkey by constructing a `PubKeyMultisigThreshold` pubkey
  900. with `nil` subpubkeys for example.
  901. This release provides multiple fixes, which include recovering from panics when
  902. accepting new peers and only allowing `ed25519` pubkeys.
  903. **All clients are recommended to upgrade**
  904. Special thanks to [fudongbai](https://hackerone.com/fudongbai) for pointing
  905. this out.
  906. ### SECURITY:
  907. - [p2p] [\#4030](https://github.com/tendermint/tendermint/issues/4030) Only allow ed25519 pubkeys when connecting
  908. ## v0.32.5
  909. *October 1, 2019*
  910. This release fixes a major security vulnerability found in the `p2p` package.
  911. All clients are recommended to upgrade. See
  912. [\#4030](https://github.com/tendermint/tendermint/issues/4030) for details.
  913. Special thanks to [fudongbai](https://hackerone.com/fudongbai) for discovering
  914. and reporting this issue.
  915. ### SECURITY:
  916. - [p2p] [\#4030](https://github.com/tendermint/tendermint/issues/4030) Fix for panic on nil public key send to a peer
  917. ## v0.32.4
  918. *September 19, 2019*
  919. Special thanks to external contributors on this release: @jon-certik, @gracenoah, @PSalant726, @gchaincl
  920. ### BREAKING CHANGES:
  921. - CLI/RPC/Config
  922. - [rpc] [\#3984](https://github.com/tendermint/tendermint/issues/3984) Add `MempoolClient` interface to `Client` interface
  923. ### IMPROVEMENTS:
  924. - [rpc] [\#2010](https://github.com/tendermint/tendermint/issues/2010) Add NewHTTPWithClient and NewJSONRPCClientWithHTTPClient (note these and NewHTTP, NewJSONRPCClient functions panic if remote is invalid) (@gracenoah)
  925. - [rpc] [\#3882](https://github.com/tendermint/tendermint/issues/3882) Add custom marshalers to proto messages to disable `omitempty`
  926. - [deps] [\#3952](https://github.com/tendermint/tendermint/pull/3952) bump github.com/go-kit/kit from 0.6.0 to 0.9.0
  927. - [deps] [\#3951](https://github.com/tendermint/tendermint/pull/3951) bump github.com/stretchr/testify from 1.3.0 to 1.4.0
  928. - [deps] [\#3945](https://github.com/tendermint/tendermint/pull/3945) bump github.com/gorilla/websocket from 1.2.0 to 1.4.1
  929. - [deps] [\#3948](https://github.com/tendermint/tendermint/pull/3948) bump github.com/libp2p/go-buffer-pool from 0.0.1 to 0.0.2
  930. - [deps] [\#3943](https://github.com/tendermint/tendermint/pull/3943) bump github.com/fortytw2/leaktest from 1.2.0 to 1.3.0
  931. - [deps] [\#3939](https://github.com/tendermint/tendermint/pull/3939) bump github.com/rs/cors from 1.6.0 to 1.7.0
  932. - [deps] [\#3937](https://github.com/tendermint/tendermint/pull/3937) bump github.com/magiconair/properties from 1.8.0 to 1.8.1
  933. - [deps] [\#3947](https://github.com/tendermint/tendermint/pull/3947) update gogo/protobuf version from v1.2.1 to v1.3.0
  934. - [deps] [\#4001](https://github.com/tendermint/tendermint/pull/4001) bump github.com/tendermint/tm-db from 0.1.1 to 0.2.0
  935. ### BUG FIXES:
  936. - [consensus] [\#3908](https://github.com/tendermint/tendermint/issues/3908) Wait `timeout_commit` to pass even if `create_empty_blocks` is `false`
  937. - [mempool] [\#3968](https://github.com/tendermint/tendermint/issues/3968) Fix memory loading error on 32-bit machines (@jon-certik)
  938. ## v0.32.3
  939. *August 28, 2019*
  940. @climber73 wrote the [Writing a Tendermint Core application in Java
  941. (gRPC)](https://github.com/tendermint/tendermint/blob/master/docs/guides/java.md)
  942. guide.
  943. Special thanks to external contributors on this release:
  944. @gchaincl, @bluele, @climber73
  945. ### IMPROVEMENTS:
  946. - [consensus] [\#3839](https://github.com/tendermint/tendermint/issues/3839) Reduce "Error attempting to add vote" message severity (Error -> Info)
  947. - [mempool] [\#3877](https://github.com/tendermint/tendermint/pull/3877) Make `max_tx_bytes` configurable instead of `max_msg_bytes` (@bluele)
  948. - [privval] [\#3370](https://github.com/tendermint/tendermint/issues/3370) Refactor and simplify validator/kms connection handling. Please refer to [this comment](https://github.com/tendermint/tendermint/pull/3370#issue-257360971) for details
  949. - [rpc] [\#3880](https://github.com/tendermint/tendermint/issues/3880) Document endpoints with `swagger`, introduce contract tests of implementation against documentation
  950. ### BUG FIXES:
  951. - [config] [\#3868](https://github.com/tendermint/tendermint/issues/3868) Move misplaced `max_msg_bytes` into mempool section (@bluele)
  952. - [rpc] [\#3910](https://github.com/tendermint/tendermint/pull/3910) Fix DATA RACE in HTTP client (@gchaincl)
  953. - [store] [\#3893](https://github.com/tendermint/tendermint/issues/3893) Fix "Unregistered interface types.Evidence" panic
  954. ## v0.32.2
  955. *July 31, 2019*
  956. Special thanks to external contributors on this release:
  957. @ruseinov, @bluele, @guagualvcha
  958. ### BREAKING CHANGES:
  959. - Go API
  960. - [libs] [\#3811](https://github.com/tendermint/tendermint/issues/3811) Remove `db` from libs in favor of `https://github.com/tendermint/tm-db`
  961. ### FEATURES:
  962. - [blockchain] [\#3561](https://github.com/tendermint/tendermint/issues/3561) Add early version of the new blockchain reactor, which is supposed to be more modular and testable compared to the old version. To try it, you'll have to change `version` in the config file, [here](https://github.com/tendermint/tendermint/blob/master/config/toml.go#L303) NOTE: It's not ready for a production yet. For further information, see [ADR-40](https://github.com/tendermint/tendermint/blob/master/docs/architecture/adr-040-blockchain-reactor-refactor.md) & [ADR-43](https://github.com/tendermint/tendermint/blob/master/docs/architecture/adr-043-blockchain-riri-org.md)
  963. - [mempool] [\#3826](https://github.com/tendermint/tendermint/issues/3826) Make `max_msg_bytes` configurable(@bluele)
  964. - [node] [\#3846](https://github.com/tendermint/tendermint/pull/3846) Allow replacing existing p2p.Reactor(s) using [`CustomReactors`
  965. option](https://godoc.org/github.com/tendermint/tendermint/node#CustomReactors).
  966. Warning: beware of accidental name clashes. Here is the list of existing
  967. reactors: MEMPOOL, BLOCKCHAIN, CONSENSUS, EVIDENCE, PEX.
  968. - [rpc] [\#3818](https://github.com/tendermint/tendermint/issues/3818) Make `max_body_bytes` and `max_header_bytes` configurable(@bluele)
  969. - [rpc] [\#2252](https://github.com/tendermint/tendermint/issues/2252) Add `/broadcast_evidence` endpoint to submit double signing and other types of evidence
  970. ### IMPROVEMENTS:
  971. - [abci] [\#3809](https://github.com/tendermint/tendermint/issues/3809) Recover from application panics in `server/socket_server.go` to allow socket cleanup (@ruseinov)
  972. - [p2p] [\#3664](https://github.com/tendermint/tendermint/issues/3664) p2p/conn: reuse buffer when write/read from secret connection(@guagualvcha)
  973. - [p2p] [\#3834](https://github.com/tendermint/tendermint/issues/3834) Do not write 'Couldn't connect to any seeds' error log if there are no seeds in config file
  974. - [rpc] [\#3076](https://github.com/tendermint/tendermint/issues/3076) Improve transaction search performance
  975. ### BUG FIXES:
  976. - [p2p] [\#3644](https://github.com/tendermint/tendermint/issues/3644) Fix error logging for connection stop (@defunctzombie)
  977. - [rpc] [\#3813](https://github.com/tendermint/tendermint/issues/3813) Return err if page is incorrect (less than 0 or greater than total pages)
  978. ## v0.32.1
  979. *July 15, 2019*
  980. Special thanks to external contributors on this release:
  981. @ParthDesai, @climber73, @jim380, @ashleyvega
  982. This release contains a minor enhancement to the ABCI and some breaking changes to our libs folder, namely:
  983. - CheckTx requests include a `CheckTxType` enum that can be set to `Recheck` to indicate to the application that this transaction was already checked/validated and certain expensive operations (like checking signatures) can be skipped
  984. - Removed various functions from `libs` pkgs
  985. ### BREAKING CHANGES:
  986. - Go API
  987. - [abci] [\#2127](https://github.com/tendermint/tendermint/issues/2127) The CheckTx and DeliverTx methods in the ABCI `Application` interface now take structs as arguments (RequestCheckTx and RequestDeliverTx, respectively), instead of just the raw tx bytes. This allows more information to be passed to these methods, for instance, indicating whether a tx has already been checked.
  988. - [libs] Remove unused `db/debugDB` and `common/colors.go` & `errors/errors.go` files (@marbar3778)
  989. - [libs] [\#2432](https://github.com/tendermint/tendermint/issues/2432) Remove unused `common/heap.go` file (@marbar3778)
  990. - [libs] Remove unused `date.go`, `io.go`. Remove `GoPath()`, `Prompt()` and `IsDirEmpty()` functions from `os.go` (@marbar3778)
  991. - [libs] Remove unused `FailRand()` func and minor clean up to `fail.go`(@marbar3778)
  992. ### FEATURES:
  993. - [node] Add variadic argument to `NewNode` to support functional options, allowing the Node to be more easily customized.
  994. - [node][\#3730](https://github.com/tendermint/tendermint/pull/3730) Add `CustomReactors` option to `NewNode` allowing caller to pass
  995. custom reactors to run inside Tendermint node (@ParthDesai)
  996. - [abci] [\#2127](https://github.com/tendermint/tendermint/issues/2127)RequestCheckTx has a new field, `CheckTxType`, which can take values of `CheckTxType_New` and `CheckTxType_Recheck`, indicating whether this is a new tx being checked for the first time or whether this tx is being rechecked after a block commit. This allows applications to skip certain expensive operations, like signature checking, if they've already been done once. see [docs](https://github.com/tendermint/tendermint/blob/eddb433d7c082efbeaf8974413a36641519ee895/docs/spec/abci/apps.md#mempool-connection)
  997. ### IMPROVEMENTS:
  998. - [rpc] [\#3700](https://github.com/tendermint/tendermint/issues/3700) Make possible to set absolute paths for TLS cert and key (@climber73)
  999. - [abci] [\#3513](https://github.com/tendermint/tendermint/issues/3513) Call the reqRes callback after the resCb so they always happen in the same order
  1000. ### BUG FIXES:
  1001. - [p2p] [\#3338](https://github.com/tendermint/tendermint/issues/3338) Prevent "sent next PEX request too soon" errors by not calling
  1002. ensurePeers outside of ensurePeersRoutine
  1003. - [behaviour] [\3772](https://github.com/tendermint/tendermint/pull/3772) Return correct reason in MessageOutOfOrder (@jim380)
  1004. - [config] [\#3723](https://github.com/tendermint/tendermint/issues/3723) Add consensus_params to testnet config generation; document time_iota_ms (@ashleyvega)
  1005. ## v0.32.0
  1006. *June 25, 2019*
  1007. Special thanks to external contributors on this release:
  1008. @needkane, @SebastianElvis, @andynog, @Yawning, @wooparadog
  1009. This release contains breaking changes to our build and release processes, ABCI,
  1010. and the RPC, namely:
  1011. - Use Go modules instead of dep
  1012. - Bring active development to the `master` Github branch
  1013. - ABCI Tags are now Events - see
  1014. [docs](https://github.com/tendermint/tendermint/blob/60827f75623b92eff132dc0eff5b49d2025c591e/docs/spec/abci/abci.md#events)
  1015. - Bind RPC to localhost by default, not to the public interface [UPGRADING/RPC_Changes](./UPGRADING.md#rpc_changes)
  1016. ### BREAKING CHANGES:
  1017. * CLI/RPC/Config
  1018. - [cli] [\#3613](https://github.com/tendermint/tendermint/issues/3613) Switch from golang/dep to Go Modules to resolve dependencies:
  1019. It is recommended to switch to Go Modules if your project has tendermint as
  1020. a dependency. Read more on Modules here:
  1021. https://github.com/golang/go/wiki/Modules
  1022. - [config] [\#3632](https://github.com/tendermint/tendermint/pull/3632) Removed `leveldb` as generic
  1023. option for `db_backend`. Must be `goleveldb` or `cleveldb`.
  1024. - [rpc] [\#3616](https://github.com/tendermint/tendermint/issues/3616) Fix field names for `/block_results` response (eg. `results.DeliverTx`
  1025. -> `results.deliver_tx`). See docs for details.
  1026. - [rpc] [\#3724](https://github.com/tendermint/tendermint/issues/3724) RPC now binds to `127.0.0.1` by default instead of `0.0.0.0`
  1027. * Apps
  1028. - [abci] [\#1859](https://github.com/tendermint/tendermint/issues/1859) `ResponseCheckTx`, `ResponseDeliverTx`, `ResponseBeginBlock`,
  1029. and `ResponseEndBlock` now include `Events` instead of `Tags`. Each `Event`
  1030. contains a `type` and a list of `attributes` (list of key-value pairs)
  1031. allowing for inclusion of multiple distinct events in each response.
  1032. * Go API
  1033. - [abci] [\#3193](https://github.com/tendermint/tendermint/issues/3193) Use RequestDeliverTx and RequestCheckTx in the ABCI
  1034. Application interface
  1035. - [libs/db] [\#3632](https://github.com/tendermint/tendermint/pull/3632) Removed deprecated `LevelDBBackend` const
  1036. If you have `db_backend` set to `leveldb` in your config file, please
  1037. change it to `goleveldb` or `cleveldb`.
  1038. - [p2p] [\#3521](https://github.com/tendermint/tendermint/issues/3521) Remove NewNetAddressStringWithOptionalID
  1039. * Blockchain Protocol
  1040. * P2P Protocol
  1041. ### FEATURES:
  1042. ### IMPROVEMENTS:
  1043. - [abci/examples] [\#3659](https://github.com/tendermint/tendermint/issues/3659) Change validator update tx format in the `persistent_kvstore` to use base64 for pubkeys instead of hex (@needkane)
  1044. - [consensus] [\#3656](https://github.com/tendermint/tendermint/issues/3656) Exit if SwitchToConsensus fails
  1045. - [p2p] [\#3666](https://github.com/tendermint/tendermint/issues/3666) Add per channel telemetry to improve reactor observability
  1046. - [rpc] [\#3686](https://github.com/tendermint/tendermint/pull/3686) `HTTPClient#Call` returns wrapped errors, so a caller could use `errors.Cause` to retrieve an error code. (@wooparadog)
  1047. ### BUG FIXES:
  1048. - [libs/db] [\#3717](https://github.com/tendermint/tendermint/issues/3717) Fixed the BoltDB backend's Batch.Delete implementation (@Yawning)
  1049. - [libs/db] [\#3718](https://github.com/tendermint/tendermint/issues/3718) Fixed the BoltDB backend's Get and Iterator implementation (@Yawning)
  1050. - [node] [\#3716](https://github.com/tendermint/tendermint/issues/3716) Fix a bug where `nil` is recorded as node's address
  1051. - [node] [\#3741](https://github.com/tendermint/tendermint/issues/3741) Fix profiler blocking the entire node
  1052. *Tendermint 0.31 release series has reached End-Of-Life and is no longer supported.*
  1053. ## v0.31.12
  1054. *April 6, 2020*
  1055. This security release fixes:
  1056. ### Denial of Service 1
  1057. Tendermint 0.33.2 and earlier does not limit the number of P2P connection requests.
  1058. For each p2p connection, Tendermint allocates ~0.5MB. Even though this
  1059. memory is garbage collected once the connection is terminated (due to duplicate
  1060. IP or reaching a maximum number of inbound peers), temporary memory spikes can
  1061. lead to OOM (Out-Of-Memory) exceptions.
  1062. Tendermint 0.33.3, 0.32.10, and 0.31.12 limit the total number of P2P incoming
  1063. connection requests to to `p2p.max_num_inbound_peers +
  1064. len(p2p.unconditional_peer_ids)`.
  1065. Notes:
  1066. - Tendermint does not rate limit P2P connection requests per IP (an attacker
  1067. can saturate all the inbound slots);
  1068. - Tendermint does not rate limit HTTP(S) requests. If you expose any RPC
  1069. endpoints to the public, please make sure to put in place some protection
  1070. (https://www.nginx.com/blog/rate-limiting-nginx/). We may implement this in
  1071. the future ([\#1696](https://github.com/tendermint/tendermint/issues/1696)).
  1072. ### Denial of Service 2
  1073. Tendermint 0.33.2 and earlier does not reclaim `activeID` of a peer after it's
  1074. removed in `Mempool` reactor. This does not happen all the time. It only
  1075. happens when a connection fails (for any reason) before the Peer is created and
  1076. added to all reactors. `RemovePeer` is therefore called before `AddPeer`, which
  1077. leads to always growing memory (`activeIDs` map). The `activeIDs` map has a
  1078. maximum size of 65535 and the node will panic if this map reaches the maximum.
  1079. An attacker can create a lot of connection attempts (exploiting Denial of
  1080. Service 1), which ultimately will lead to the node panicking.
  1081. Tendermint 0.33.3, 0.32.10, and 0.31.12 claim `activeID` for a peer in `InitPeer`,
  1082. which is executed before `MConnection` is started.
  1083. Notes:
  1084. - `InitPeer` function was added to all reactors to combat a similar issue -
  1085. [\#3338](https://github.com/tendermint/tendermint/issues/3338);
  1086. - Denial of Service 2 is independent of Denial of Service 1 and can be executed
  1087. without it.
  1088. **All clients are recommended to upgrade**
  1089. Special thanks to [fudongbai](https://hackerone.com/fudongbai) for finding
  1090. and reporting this.
  1091. ### SECURITY:
  1092. - [mempool] Reserve IDs in InitPeer instead of AddPeer (@tessr)
  1093. - [p2p] Limit the number of incoming connections (@melekes)
  1094. ## v0.31.11
  1095. *October 18, 2019*
  1096. This security release fixes a vulnerability found in the `consensus` package,
  1097. where an attacker could construct a `BlockPartMessage` message in such a way
  1098. that it will lead to consensus failure. A few similar issues have been
  1099. identified and fixed here.
  1100. **All clients are recommended to upgrade**
  1101. Special thanks to [elvishacker](https://hackerone.com/elvishacker) for finding
  1102. and reporting this.
  1103. ### BREAKING CHANGES:
  1104. - Go API
  1105. - [consensus] Modify `WAL#Write` and `WAL#WriteSync` to return an error if
  1106. they fail to write a message
  1107. ### SECURITY:
  1108. - [consensus] Validate incoming messages more throughly
  1109. ## v0.31.10
  1110. *October 8, 2019*
  1111. The previous patch was insufficient because the attacker could still find a way
  1112. to submit a `nil` pubkey by constructing a `PubKeyMultisigThreshold` pubkey
  1113. with `nil` subpubkeys for example.
  1114. This release provides multiple fixes, which include recovering from panics when
  1115. accepting new peers and only allowing `ed25519` pubkeys.
  1116. **All clients are recommended to upgrade**
  1117. Special thanks to [fudongbai](https://hackerone.com/fudongbai) for pointing
  1118. this out.
  1119. ### SECURITY:
  1120. - [p2p] [\#4030](https://github.com/tendermint/tendermint/issues/4030) Only allow ed25519 pubkeys when connecting
  1121. ## v0.31.9
  1122. *October 1, 2019*
  1123. This release fixes a major security vulnerability found in the `p2p` package.
  1124. All clients are recommended to upgrade. See
  1125. [\#4030](https://github.com/tendermint/tendermint/issues/4030) for details.
  1126. Special thanks to [fudongbai](https://hackerone.com/fudongbai) for discovering
  1127. and reporting this issue.
  1128. ### SECURITY:
  1129. - [p2p] [\#4030](https://github.com/tendermint/tendermint/issues/4030) Fix for panic on nil public key send to a peer
  1130. ### BUG FIXES:
  1131. - [node] [\#3716](https://github.com/tendermint/tendermint/issues/3716) Fix a bug where `nil` is recorded as node's address
  1132. - [node] [\#3741](https://github.com/tendermint/tendermint/issues/3741) Fix profiler blocking the entire node
  1133. ## v0.31.8
  1134. *July 29, 2019*
  1135. This releases fixes one bug in the PEX reactor and adds a `recover` to the Go's
  1136. ABCI server, which allows it to properly cleanup.
  1137. ### IMPROVEMENTS:
  1138. - [abci] [\#3809](https://github.com/tendermint/tendermint/issues/3809) Recover from application panics in `server/socket_server.go` to allow socket cleanup (@ruseinov)
  1139. ### BUG FIXES:
  1140. - [p2p] [\#3338](https://github.com/tendermint/tendermint/issues/3338) Prevent "sent next PEX request too soon" errors by not calling
  1141. ensurePeers outside of ensurePeersRoutine
  1142. ## v0.31.7
  1143. *June 3, 2019*
  1144. This releases fixes a regression in the mempool introduced in v0.31.6.
  1145. The regression caused the invalid committed txs to be proposed in blocks over and
  1146. over again.
  1147. ### BUG FIXES:
  1148. - [mempool] [\#3699](https://github.com/tendermint/tendermint/issues/3699) Remove all committed txs from the mempool.
  1149. This reverts the change from v0.31.6 where we only remove valid txs from the mempool.
  1150. Note this means malicious proposals can cause txs to be dropped from the
  1151. mempools of other nodes by including them in blocks before they are valid.
  1152. See [\#3322](https://github.com/tendermint/tendermint/issues/3322).
  1153. ## v0.31.6
  1154. *May 31st, 2019*
  1155. This release contains many fixes and improvements, primarily for p2p functionality.
  1156. It also fixes a security issue in the mempool package.
  1157. With this release, Tendermint now supports [boltdb](https://github.com/etcd-io/bbolt), although
  1158. in experimental mode. Feel free to try and report to us any findings/issues.
  1159. Note also that the build tags for compiling CLevelDB have changed.
  1160. Special thanks to external contributors on this release:
  1161. @guagualvcha, @james-ray, @gregdhill, @climber73, @yutianwu,
  1162. @carlosflrs, @defunctzombie, @leoluk, @needkane, @CrocdileChan
  1163. ### BREAKING CHANGES:
  1164. * Go API
  1165. - [libs/common] Removed deprecated `PanicSanity`, `PanicCrisis`,
  1166. `PanicConsensus` and `PanicQ`
  1167. - [mempool, state] [\#2659](https://github.com/tendermint/tendermint/issues/2659) `Mempool` now an interface that lives in the mempool package.
  1168. See issue and PR for more details.
  1169. - [p2p] [\#3346](https://github.com/tendermint/tendermint/issues/3346) `Reactor#InitPeer` method is added to `Reactor` interface
  1170. - [types] [\#1648](https://github.com/tendermint/tendermint/issues/1648) `Commit#VoteSignBytes` signature was changed
  1171. ### FEATURES:
  1172. - [node] [\#2659](https://github.com/tendermint/tendermint/issues/2659) Add `node.Mempool()` method, which allows you to access mempool
  1173. - [libs/db] [\#3604](https://github.com/tendermint/tendermint/pull/3604) Add experimental support for bolt db (etcd's fork of bolt) (@CrocdileChan)
  1174. ### IMPROVEMENTS:
  1175. - [cli] [\#3585](https://github.com/tendermint/tendermint/issues/3585) Add `--keep-addr-book` option to `unsafe_reset_all` cmd to not
  1176. clear the address book (@climber73)
  1177. - [cli] [\#3160](https://github.com/tendermint/tendermint/issues/3160) Add
  1178. `--config=<path-to-config>` option to `testnet` cmd (@gregdhill)
  1179. - [cli] [\#3661](https://github.com/tendermint/tendermint/pull/3661) Add
  1180. `--hostname-suffix`, `--hostname` and `--random-monikers` options to `testnet`
  1181. cmd for greater peer address/identity generation flexibility.
  1182. - [crypto] [\#3672](https://github.com/tendermint/tendermint/issues/3672) Return more info in the `AddSignatureFromPubKey` error
  1183. - [cs/replay] [\#3460](https://github.com/tendermint/tendermint/issues/3460) Check appHash for each block
  1184. - [libs/db] [\#3611](https://github.com/tendermint/tendermint/issues/3611) Conditional compilation
  1185. * Use `cleveldb` tag instead of `gcc` to compile Tendermint with CLevelDB or
  1186. use `make build_c` / `make install_c` (full instructions can be found at
  1187. https://docs.tendermint.com/master/introduction/install.html#compile-with-cleveldb-support)
  1188. * Use `boltdb` tag to compile Tendermint with bolt db
  1189. - [node] [\#3362](https://github.com/tendermint/tendermint/issues/3362) Return an error if `persistent_peers` list is invalid (except
  1190. when IP lookup fails)
  1191. - [p2p] [\#3463](https://github.com/tendermint/tendermint/pull/3463) Do not log "Can't add peer's address to addrbook" error for a private peer (@guagualvcha)
  1192. - [p2p] [\#3531](https://github.com/tendermint/tendermint/issues/3531) Terminate session on nonce wrapping (@climber73)
  1193. - [pex] [\#3647](https://github.com/tendermint/tendermint/pull/3647) Dial seeds, if any, instead of crawling peers first (@defunctzombie)
  1194. - [rpc] [\#3534](https://github.com/tendermint/tendermint/pull/3534) Add support for batched requests/responses in JSON RPC
  1195. - [rpc] [\#3362](https://github.com/tendermint/tendermint/issues/3362) `/dial_seeds` & `/dial_peers` return errors if addresses are
  1196. incorrect (except when IP lookup fails)
  1197. ### BUG FIXES:
  1198. - [consensus] [\#3067](https://github.com/tendermint/tendermint/issues/3067) Fix replay from appHeight==0 with validator set changes (@james-ray)
  1199. - [consensus] [\#3304](https://github.com/tendermint/tendermint/issues/3304) Create a peer state in consensus reactor before the peer
  1200. is started (@guagualvcha)
  1201. - [lite] [\#3669](https://github.com/tendermint/tendermint/issues/3669) Add context parameter to RPC Handlers in proxy routes (@yutianwu)
  1202. - [mempool] [\#3322](https://github.com/tendermint/tendermint/issues/3322) When a block is committed, only remove committed txs from the mempool
  1203. that were valid (ie. `ResponseDeliverTx.Code == 0`)
  1204. - [p2p] [\#3338](https://github.com/tendermint/tendermint/issues/3338) Ensure `RemovePeer` is always called before `InitPeer` (upon a peer
  1205. reconnecting to our node)
  1206. - [p2p] [\#3532](https://github.com/tendermint/tendermint/issues/3532) Limit the number of attempts to connect to a peer in seed mode
  1207. to 16 (as a result, the node will stop retrying after a 35 hours time window)
  1208. - [p2p] [\#3362](https://github.com/tendermint/tendermint/issues/3362) Allow inbound peers to be persistent, including for seed nodes.
  1209. - [pex] [\#3603](https://github.com/tendermint/tendermint/pull/3603) Dial seeds when addrbook needs more addresses (@defunctzombie)
  1210. ### OTHERS:
  1211. - [networks] fixes ansible integration script (@carlosflrs)
  1212. ## v0.31.5
  1213. *April 16th, 2019*
  1214. This release fixes a regression from v0.31.4 where, in existing chains that
  1215. were upgraded, `/validators` could return an empty validator set. This is true
  1216. for almost all heights, given the validator set remains the same.
  1217. Special thanks to external contributors on this release:
  1218. @brapse, @guagualvcha, @dongsam, @phucc
  1219. ### IMPROVEMENTS:
  1220. - [libs/common] `CMap`: slight optimization in `Keys()` and `Values()` (@phucc)
  1221. - [gitignore] gitignore: add .vendor-new (@dongsam)
  1222. ### BUG FIXES:
  1223. - [state] [\#3537](https://github.com/tendermint/tendermint/pull/3537#issuecomment-482711833)
  1224. `LoadValidators`: do not return an empty validator set
  1225. - [blockchain] [\#3457](https://github.com/tendermint/tendermint/issues/3457)
  1226. Fix "peer did not send us anything" in `fast_sync` mode when under high pressure
  1227. ## v0.31.4
  1228. *April 12th, 2019*
  1229. This release fixes a regression from v0.31.3 which used the peer's `SocketAddr` to add the peer to
  1230. the address book. This swallowed the peer's self-reported port which is important in case of reconnect.
  1231. It brings back `NetAddress()` to `NodeInfo` and uses it instead of `SocketAddr` for adding peers.
  1232. Additionally, it improves response time on the `/validators` or `/status` RPC endpoints.
  1233. As a side-effect it makes these RPC endpoint more difficult to DoS and fixes a performance degradation in `ExecCommitBlock`.
  1234. Also, it contains an [ADR](https://github.com/tendermint/tendermint/pull/3539) that proposes decoupling the
  1235. responsibility for peer behaviour from the `p2p.Switch` (by @brapse).
  1236. Special thanks to external contributors on this release:
  1237. @brapse, @guagualvcha, @mydring
  1238. ### IMPROVEMENTS:
  1239. - [p2p] [\#3463](https://github.com/tendermint/tendermint/pull/3463) Do not log "Can't add peer's address to addrbook" error for a private peer
  1240. - [p2p] [\#3547](https://github.com/tendermint/tendermint/pull/3547) Fix a couple of annoying typos (@mdyring)
  1241. ### BUG FIXES:
  1242. - [docs] [\#3514](https://github.com/tendermint/tendermint/issues/3514) Fix block.Header.Time description (@melekes)
  1243. - [p2p] [\#2716](https://github.com/tendermint/tendermint/issues/2716) Check if we're already connected to peer right before dialing it (@melekes)
  1244. - [p2p] [\#3545](https://github.com/tendermint/tendermint/issues/3545) Add back `NetAddress()` to `NodeInfo` and use it instead of peer's `SocketAddr()` when adding a peer to the `PEXReactor` (potential fix for [\#3532](https://github.com/tendermint/tendermint/issues/3532))
  1245. - [state] [\#3438](https://github.com/tendermint/tendermint/pull/3438)
  1246. Persist validators every 100000 blocks even if no changes to the set
  1247. occurred (@guagualvcha). This
  1248. 1) Prevents possible DoS attack using `/validators` or `/status` RPC
  1249. endpoints. Before response time was growing linearly with height if no
  1250. changes were made to the validator set.
  1251. 2) Fixes performance degradation in `ExecCommitBlock` where we call
  1252. `LoadValidators` for each `Evidence` in the block.
  1253. ## v0.31.3
  1254. *April 1st, 2019*
  1255. This release includes two security sensitive fixes: it ensures generated private
  1256. keys are valid, and it prevents certain DNS lookups that would cause the node to
  1257. panic if the lookup failed.
  1258. ### BREAKING CHANGES:
  1259. * Go API
  1260. - [crypto/secp256k1] [\#3439](https://github.com/tendermint/tendermint/issues/3439)
  1261. The `secp256k1.GenPrivKeySecp256k1` function has changed to guarantee that it returns a valid key, which means it
  1262. will return a different private key than in previous versions for the same secret.
  1263. ### BUG FIXES:
  1264. - [crypto/secp256k1] [\#3439](https://github.com/tendermint/tendermint/issues/3439)
  1265. Ensure generated private keys are valid by randomly sampling until a valid key is found.
  1266. Previously, it was possible (though rare!) to generate keys that exceeded the curve order.
  1267. Such keys would lead to invalid signatures.
  1268. - [p2p] [\#3522](https://github.com/tendermint/tendermint/issues/3522) Memoize
  1269. socket address in peer connections to avoid DNS lookups. Previously, failed
  1270. DNS lookups could cause the node to panic.
  1271. ## v0.31.2
  1272. *March 30th, 2019*
  1273. This release fixes a regression from v0.31.1 where Tendermint panics under
  1274. mempool load for external ABCI apps.
  1275. Special thanks to external contributors on this release:
  1276. @guagualvcha
  1277. ### BREAKING CHANGES:
  1278. * CLI/RPC/Config
  1279. * Apps
  1280. * Go API
  1281. - [libs/autofile] [\#3504](https://github.com/tendermint/tendermint/issues/3504) Remove unused code in autofile package. Deleted functions: `Group.Search`, `Group.FindLast`, `GroupReader.ReadLine`, `GroupReader.PushLine`, `MakeSimpleSearchFunc` (@guagualvcha)
  1282. * Blockchain Protocol
  1283. * P2P Protocol
  1284. ### FEATURES:
  1285. ### IMPROVEMENTS:
  1286. - [circle] [\#3497](https://github.com/tendermint/tendermint/issues/3497) Move release management to CircleCI
  1287. ### BUG FIXES:
  1288. - [mempool] [\#3512](https://github.com/tendermint/tendermint/issues/3512) Fix panic from concurrent access to txsMap, a regression for external ABCI apps introduced in v0.31.1
  1289. ## v0.31.1
  1290. *March 27th, 2019*
  1291. This release contains a major improvement for the mempool that reduce the amount of sent data by about 30%
  1292. (see some numbers below).
  1293. It also fixes a memory leak in the mempool and adds TLS support to the RPC server by providing a certificate and key in the config.
  1294. Special thanks to external contributors on this release:
  1295. @brapse, @guagualvcha, @HaoyangLiu, @needkane, @TraceBundy
  1296. ### BREAKING CHANGES:
  1297. * CLI/RPC/Config
  1298. * Apps
  1299. * Go API
  1300. - [crypto] [\#3426](https://github.com/tendermint/tendermint/pull/3426) Remove `Ripemd160` helper method (@needkane)
  1301. - [libs/common] [\#3429](https://github.com/tendermint/tendermint/pull/3429) Remove `RepeatTimer` (also `TimerMaker` and `Ticker` interface)
  1302. - [rpc/client] [\#3458](https://github.com/tendermint/tendermint/issues/3458) Include `NetworkClient` interface into `Client` interface
  1303. - [types] [\#3448](https://github.com/tendermint/tendermint/issues/3448) Remove method `PB2TM.ConsensusParams`
  1304. * Blockchain Protocol
  1305. * P2P Protocol
  1306. ### FEATURES:
  1307. - [rpc] [\#3419](https://github.com/tendermint/tendermint/issues/3419) Start HTTPS server if `rpc.tls_cert_file` and `rpc.tls_key_file` are provided in the config (@guagualvcha)
  1308. ### IMPROVEMENTS:
  1309. - [docs] [\#3140](https://github.com/tendermint/tendermint/issues/3140) Formalize proposer election algorithm properties
  1310. - [docs] [\#3482](https://github.com/tendermint/tendermint/issues/3482) Fix broken links (@brapse)
  1311. - [mempool] [\#2778](https://github.com/tendermint/tendermint/issues/2778) No longer send txs back to peers who sent it to you.
  1312. Also, limit to 65536 active peers.
  1313. This vastly improves the bandwidth consumption of nodes.
  1314. For instance, for a 4 node localnet, in a test sending 250byte txs for 120 sec. at 500 txs/sec (total of 15MB):
  1315. - total bytes received from 1st node:
  1316. - before: 42793967 (43MB)
  1317. - after: 30003256 (30MB)
  1318. - total bytes sent to 1st node:
  1319. - before: 30569339 (30MB)
  1320. - after: 19304964 (19MB)
  1321. - [p2p] [\#3475](https://github.com/tendermint/tendermint/issues/3475) Simplify `GetSelectionWithBias` for addressbook (@guagualvcha)
  1322. - [rpc/lib/client] [\#3430](https://github.com/tendermint/tendermint/issues/3430) Disable compression for HTTP client to prevent GZIP-bomb DoS attacks (@guagualvcha)
  1323. ### BUG FIXES:
  1324. - [blockchain] [\#2699](https://github.com/tendermint/tendermint/issues/2699) Update the maxHeight when a peer is removed
  1325. - [mempool] [\#3478](https://github.com/tendermint/tendermint/issues/3478) Fix memory-leak related to `broadcastTxRoutine` (@HaoyangLiu)
  1326. ## v0.31.0
  1327. *March 16th, 2019*
  1328. Special thanks to external contributors on this release:
  1329. @danil-lashin, @guagualvcha, @siburu, @silasdavis, @srmo, @Stumble, @svenstaro
  1330. This release is primarily about the new pubsub implementation, dubbed `pubsub 2.0`, and related changes,
  1331. like configurable limits on the number of active RPC subscriptions at a time (`max_subscription_clients`).
  1332. Pubsub 2.0 is an improved version of the older pubsub that is non-blocking and has a nicer API.
  1333. Note the improved pubsub API also resulted in some improvements to the HTTPClient interface and the API for WebSocket subscriptions.
  1334. This release also adds a configurable limit to the mempool size (`max_txs_bytes`, default 1GB)
  1335. and a configurable timeout for the `/broadcast_tx_commit` endpoint.
  1336. See the [v0.31.0
  1337. Milestone](https://github.com/tendermint/tendermint/milestone/19?closed=1) for
  1338. more details.
  1339. ### BREAKING CHANGES:
  1340. * CLI/RPC/Config
  1341. - [config] [\#2920](https://github.com/tendermint/tendermint/issues/2920) Remove `consensus.blocktime_iota` parameter
  1342. - [rpc] [\#3227](https://github.com/tendermint/tendermint/issues/3227) New PubSub design does not block on clients when publishing
  1343. messages. Slow clients may miss messages and receive an error, terminating
  1344. the subscription.
  1345. - [rpc] [\#3269](https://github.com/tendermint/tendermint/issues/2826) Limit number of unique clientIDs with open subscriptions. Configurable via `rpc.max_subscription_clients`
  1346. - [rpc] [\#3269](https://github.com/tendermint/tendermint/issues/2826) Limit number of unique queries a given client can subscribe to at once. Configurable via `rpc.max_subscriptions_per_client`.
  1347. - [rpc] [\#3435](https://github.com/tendermint/tendermint/issues/3435) Default ReadTimeout and WriteTimeout changed to 10s. WriteTimeout can increased by setting `rpc.timeout_broadcast_tx_commit` in the config.
  1348. - [rpc/client] [\#3269](https://github.com/tendermint/tendermint/issues/3269) Update `EventsClient` interface to reflect new pubsub/eventBus API [ADR-33](https://github.com/tendermint/tendermint/blob/develop/docs/architecture/adr-033-pubsub.md). This includes `Subscribe`, `Unsubscribe`, and `UnsubscribeAll` methods.
  1349. * Apps
  1350. - [abci] [\#3403](https://github.com/tendermint/tendermint/issues/3403) Remove `time_iota_ms` from BlockParams. This is a
  1351. ConsensusParam but need not be exposed to the app for now.
  1352. - [abci] [\#2920](https://github.com/tendermint/tendermint/issues/2920) Rename `consensus_params.block_size` to `consensus_params.block` in ABCI ConsensusParams
  1353. * Go API
  1354. - [libs/common] TrapSignal accepts logger as a first parameter and does not block anymore
  1355. * previously it was dumping "captured ..." msg to os.Stdout
  1356. * TrapSignal should not be responsible for blocking thread of execution
  1357. - [libs/db] [\#3397](https://github.com/tendermint/tendermint/pull/3397) Add possibility to `Close()` `Batch` to prevent memory leak when using ClevelDB. (@Stumble)
  1358. - [types] [\#3354](https://github.com/tendermint/tendermint/issues/3354) Remove RoundState from EventDataRoundState
  1359. - [rpc] [\#3435](https://github.com/tendermint/tendermint/issues/3435) `StartHTTPServer` / `StartHTTPAndTLSServer` now require a Config (use `rpcserver.DefaultConfig`)
  1360. * Blockchain Protocol
  1361. * P2P Protocol
  1362. ### FEATURES:
  1363. - [config] [\#3269](https://github.com/tendermint/tendermint/issues/2826) New configuration values for controlling RPC subscriptions:
  1364. - `rpc.max_subscription_clients` sets the maximum number of unique clients
  1365. with open subscriptions
  1366. - `rpc.max_subscriptions_per_client`sets the maximum number of unique
  1367. subscriptions from a given client
  1368. - `rpc.timeout_broadcast_tx_commit` sets the time to wait for a tx to be committed during `/broadcast_tx_commit`
  1369. - [types] [\#2920](https://github.com/tendermint/tendermint/issues/2920) Add `time_iota_ms` to block's consensus parameters (not exposed to the application)
  1370. - [lite] [\#3269](https://github.com/tendermint/tendermint/issues/3269) Add `/unsubscribe_all` endpoint to unsubscribe from all events
  1371. - [mempool] [\#3079](https://github.com/tendermint/tendermint/issues/3079) Bound mempool memory usage via the `mempool.max_txs_bytes` configuration value. Set to 1GB by default. The mempool's current `txs_total_bytes` is exposed via `total_bytes` field in
  1372. `/num_unconfirmed_txs` and `/unconfirmed_txs` RPC endpoints.
  1373. ### IMPROVEMENTS:
  1374. - [all] [\#3385](https://github.com/tendermint/tendermint/issues/3385), [\#3386](https://github.com/tendermint/tendermint/issues/3386) Various linting improvements
  1375. - [crypto] [\#3371](https://github.com/tendermint/tendermint/issues/3371) Copy in secp256k1 package from go-ethereum instead of importing
  1376. go-ethereum (@silasdavis)
  1377. - [deps] [\#3382](https://github.com/tendermint/tendermint/issues/3382) Don't pin repos without releases
  1378. - [deps] [\#3357](https://github.com/tendermint/tendermint/issues/3357), [\#3389](https://github.com/tendermint/tendermint/issues/3389), [\#3392](https://github.com/tendermint/tendermint/issues/3392) Update gogo/protobuf, golang/protobuf, levigo, golang.org/x/crypto
  1379. - [libs/common] [\#3238](https://github.com/tendermint/tendermint/issues/3238) exit with zero (0) code upon receiving SIGTERM/SIGINT
  1380. - [libs/db] [\#3378](https://github.com/tendermint/tendermint/issues/3378) CLevelDB#Stats now returns the following properties:
  1381. - leveldb.num-files-at-level{n}
  1382. - leveldb.stats
  1383. - leveldb.sstables
  1384. - leveldb.blockpool
  1385. - leveldb.cachedblock
  1386. - leveldb.openedtables
  1387. - leveldb.alivesnaps
  1388. - leveldb.aliveiters
  1389. - [privval] [\#3351](https://github.com/tendermint/tendermint/pull/3351) First part of larger refactoring that clarifies and separates concerns in the privval package.
  1390. ### BUG FIXES:
  1391. - [blockchain] [\#3358](https://github.com/tendermint/tendermint/pull/3358) Fix timer leak in `BlockPool` (@guagualvcha)
  1392. - [cmd] [\#3408](https://github.com/tendermint/tendermint/issues/3408) Fix `testnet` command's panic when creating non-validator configs (using `--n` flag) (@srmo)
  1393. - [libs/db/remotedb/grpcdb] [\#3402](https://github.com/tendermint/tendermint/issues/3402) Close Iterator/ReverseIterator after use
  1394. - [libs/pubsub] [\#951](https://github.com/tendermint/tendermint/issues/951), [\#1880](https://github.com/tendermint/tendermint/issues/1880) Use non-blocking send when dispatching messages [ADR-33](https://github.com/tendermint/tendermint/blob/develop/docs/architecture/adr-033-pubsub.md)
  1395. - [lite] [\#3364](https://github.com/tendermint/tendermint/issues/3364) Fix `/validators` and `/abci_query` proxy endpoints
  1396. (@guagualvcha)
  1397. - [p2p/conn] [\#3347](https://github.com/tendermint/tendermint/issues/3347) Reject all-zero shared secrets in the Diffie-Hellman step of secret-connection
  1398. - [p2p] [\#3369](https://github.com/tendermint/tendermint/issues/3369) Do not panic when filter times out
  1399. - [p2p] [\#3359](https://github.com/tendermint/tendermint/pull/3359) Fix reconnecting report duplicate ID error due to race condition between adding peer to peerSet and starting it (@guagualvcha)
  1400. ## v0.30.2
  1401. *March 10th, 2019*
  1402. This release fixes a CLevelDB memory leak. It was happening because we were not
  1403. closing the WriteBatch object after use. See [levigo's
  1404. godoc](https://godoc.org/github.com/jmhodges/levigo#WriteBatch.Close) for the
  1405. Close method. Special thanks goes to @Stumble who both reported an issue in
  1406. [cosmos-sdk](https://github.com/cosmos/cosmos-sdk/issues/3842) and provided a
  1407. fix here.
  1408. ### BREAKING CHANGES:
  1409. * Go API
  1410. - [libs/db] [\#3842](https://github.com/cosmos/cosmos-sdk/issues/3842) Add Close() method to Batch interface (@Stumble)
  1411. ### BUG FIXES:
  1412. - [libs/db] [\#3842](https://github.com/cosmos/cosmos-sdk/issues/3842) Fix CLevelDB memory leak (@Stumble)
  1413. ## v0.30.1
  1414. *February 20th, 2019*
  1415. This release fixes a consensus halt and a DataCorruptionError after restart
  1416. discovered in `game_of_stakes_6`. It also fixes a security issue in the p2p
  1417. handshake by authenticating the NetAddress.ID of the peer we're dialing.
  1418. ### IMPROVEMENTS:
  1419. * [config] [\#3291](https://github.com/tendermint/tendermint/issues/3291) Make
  1420. config.ResetTestRootWithChainID() create concurrency-safe test directories.
  1421. ### BUG FIXES:
  1422. * [consensus] [\#3295](https://github.com/tendermint/tendermint/issues/3295)
  1423. Flush WAL on stop to prevent data corruption during graceful shutdown.
  1424. * [consensus] [\#3302](https://github.com/tendermint/tendermint/issues/3302)
  1425. Fix possible halt by resetting TriggeredTimeoutPrecommit before starting next height.
  1426. * [rpc] [\#3251](https://github.com/tendermint/tendermint/issues/3251) Fix
  1427. `/net_info#peers#remote_ip` format. New format spec:
  1428. * dotted decimal ("192.0.2.1"), if ip is an IPv4 or IP4-mapped IPv6 address
  1429. * IPv6 ("2001:db8::1"), if ip is a valid IPv6 address
  1430. * [cmd] [\#3314](https://github.com/tendermint/tendermint/issues/3314) Return
  1431. an error on `show_validator` when the private validator file does not exist.
  1432. * [p2p] [\#3010](https://github.com/tendermint/tendermint/issues/3010#issuecomment-464287627)
  1433. Authenticate a peer against its NetAddress.ID when dialing.
  1434. ## v0.30.0
  1435. *February 8th, 2019*
  1436. This release fixes yet another issue with the proposer selection algorithm.
  1437. We hope it's the last one, but we won't be surprised if it's not.
  1438. We plan to one day expose the selection algorithm more directly to
  1439. the application ([\#3285](https://github.com/tendermint/tendermint/issues/3285)), and even to support randomness ([\#763](https://github.com/tendermint/tendermint/issues/763)).
  1440. For more, see issues marked
  1441. [proposer-selection](https://github.com/tendermint/tendermint/labels/proposer-selection).
  1442. This release also includes a fix to prevent Tendermint from including the same
  1443. piece of evidence in more than one block. This issue was reported by @chengwenxi in our
  1444. [bug bounty program](https://hackerone.com/tendermint).
  1445. ### BREAKING CHANGES:
  1446. * Apps
  1447. - [state] [\#3222](https://github.com/tendermint/tendermint/issues/3222)
  1448. Duplicate updates for the same validator are forbidden. Apps must ensure
  1449. that a given `ResponseEndBlock.ValidatorUpdates` contains only one entry per pubkey.
  1450. * Go API
  1451. - [types] [\#3222](https://github.com/tendermint/tendermint/issues/3222)
  1452. Remove `Add` and `Update` methods from `ValidatorSet` in favor of new
  1453. `UpdateWithChangeSet`. This allows updates to be applied as a set, instead of
  1454. one at a time.
  1455. * Block Protocol
  1456. - [state] [\#3286](https://github.com/tendermint/tendermint/issues/3286) Blocks that include already committed evidence are invalid.
  1457. * P2P Protocol
  1458. - [consensus] [\#3222](https://github.com/tendermint/tendermint/issues/3222)
  1459. Validator updates are applied as a set, instead of one at a time, thus
  1460. impacting the proposer priority calculation. This ensures that the proposer
  1461. selection algorithm does not depend on the order of updates in
  1462. `ResponseEndBlock.ValidatorUpdates`.
  1463. ### IMPROVEMENTS:
  1464. - [crypto] [\#3279](https://github.com/tendermint/tendermint/issues/3279) Use `btcec.S256().N` directly instead of hard coding a copy.
  1465. ### BUG FIXES:
  1466. - [state] [\#3222](https://github.com/tendermint/tendermint/issues/3222) Fix validator set updates so they are applied as a set, rather
  1467. than one at a time. This makes the proposer selection algorithm independent of
  1468. the order of updates in `ResponseEndBlock.ValidatorUpdates`.
  1469. - [evidence] [\#3286](https://github.com/tendermint/tendermint/issues/3286) Don't add committed evidence to evidence pool.
  1470. ## v0.29.2
  1471. *February 7th, 2019*
  1472. Special thanks to external contributors on this release:
  1473. @ackratos, @rickyyangz
  1474. **Note**: This release contains security sensitive patches in the `p2p` and
  1475. `crypto` packages:
  1476. - p2p:
  1477. - Partial fix for MITM attacks on the p2p connection. MITM conditions may
  1478. still exist. See [\#3010](https://github.com/tendermint/tendermint/issues/3010).
  1479. - crypto:
  1480. - Eliminate our fork of `btcd` and use the `btcd/btcec` library directly for
  1481. native secp256k1 signing. Note we still modify the signature encoding to
  1482. prevent malleability.
  1483. - Support the libsecp256k1 library via CGo through the `go-ethereum/crypto/secp256k1` package.
  1484. - Eliminate MixEntropy functions
  1485. ### BREAKING CHANGES:
  1486. * Go API
  1487. - [crypto] [\#3278](https://github.com/tendermint/tendermint/issues/3278) Remove
  1488. MixEntropy functions
  1489. - [types] [\#3245](https://github.com/tendermint/tendermint/issues/3245) Commit uses `type CommitSig Vote` instead of `Vote` directly.
  1490. In preparation for removing redundant fields from the commit [\#1648](https://github.com/tendermint/tendermint/issues/1648)
  1491. ### IMPROVEMENTS:
  1492. - [consensus] [\#3246](https://github.com/tendermint/tendermint/issues/3246) Better logging and notes on recovery for corrupted WAL file
  1493. - [crypto] [\#3163](https://github.com/tendermint/tendermint/issues/3163) Use ethereum's libsecp256k1 go-wrapper for signatures when cgo is available
  1494. - [crypto] [\#3162](https://github.com/tendermint/tendermint/issues/3162) Wrap btcd instead of forking it to keep up with fixes (used if cgo is not available)
  1495. - [makefile] [\#3233](https://github.com/tendermint/tendermint/issues/3233) Use golangci-lint instead of go-metalinter
  1496. - [tools] [\#3218](https://github.com/tendermint/tendermint/issues/3218) Add go-deadlock tool to help detect deadlocks
  1497. - [tools] [\#3106](https://github.com/tendermint/tendermint/issues/3106) Add tm-signer-harness test harness for remote signers
  1498. - [tests] [\#3258](https://github.com/tendermint/tendermint/issues/3258) Fixed a bunch of non-deterministic test failures
  1499. ### BUG FIXES:
  1500. - [node] [\#3186](https://github.com/tendermint/tendermint/issues/3186) EventBus and indexerService should be started before first block (for replay last block on handshake) execution (@ackratos)
  1501. - [p2p] [\#3232](https://github.com/tendermint/tendermint/issues/3232) Fix infinite loop leading to addrbook deadlock for seed nodes
  1502. - [p2p] [\#3247](https://github.com/tendermint/tendermint/issues/3247) Fix panic in SeedMode when calling FlushStop and OnStop
  1503. concurrently
  1504. - [p2p] [\#3040](https://github.com/tendermint/tendermint/issues/3040) Fix MITM on secret connection by checking low-order points
  1505. - [privval] [\#3258](https://github.com/tendermint/tendermint/issues/3258) Fix race between sign requests and ping requests in socket that was causing messages to be corrupted
  1506. ## v0.29.1
  1507. *January 24, 2019*
  1508. Special thanks to external contributors on this release:
  1509. @infinytum, @gauthamzz
  1510. This release contains two important fixes: one for p2p layer where we sometimes
  1511. were not closing connections and one for consensus layer where consensus with
  1512. no empty blocks (`create_empty_blocks = false`) could halt.
  1513. ### IMPROVEMENTS:
  1514. - [pex] [\#3037](https://github.com/tendermint/tendermint/issues/3037) Only log "Reached max attempts to dial" once
  1515. - [rpc] [\#3159](https://github.com/tendermint/tendermint/issues/3159) Expose
  1516. `triggered_timeout_commit` in the `/dump_consensus_state`
  1517. ### BUG FIXES:
  1518. - [consensus] [\#3199](https://github.com/tendermint/tendermint/issues/3199) Fix consensus halt with no empty blocks from not resetting triggeredTimeoutCommit
  1519. - [p2p] [\#2967](https://github.com/tendermint/tendermint/issues/2967) Fix file descriptor leak
  1520. ## v0.29.0
  1521. *January 21, 2019*
  1522. Special thanks to external contributors on this release:
  1523. @bradyjoestar, @kunaldhariwal, @gauthamzz, @hrharder
  1524. This release is primarily about making some breaking changes to
  1525. the Block protocol version before Cosmos launch, and to fixing more issues
  1526. in the proposer selection algorithm discovered on Cosmos testnets.
  1527. The Block protocol changes include using a standard Merkle tree format (RFC 6962),
  1528. fixing some inconsistencies between field orders in Vote and Proposal structs,
  1529. and constraining the hash of the ConsensusParams to include only a few fields.
  1530. The proposer selection algorithm saw significant progress,
  1531. including a [formal proof by @cwgoes for the base-case in Idris](https://github.com/cwgoes/tm-proposer-idris)
  1532. and a [much more detailed specification (still in progress) by
  1533. @ancazamfir](https://github.com/tendermint/tendermint/pull/3140).
  1534. Fixes to the proposer selection algorithm include normalizing the proposer
  1535. priorities to mitigate the effects of large changes to the validator set.
  1536. That said, we just discovered [another bug](https://github.com/tendermint/tendermint/issues/3181),
  1537. which will be fixed in the next breaking release.
  1538. While we are trying to stabilize the Block protocol to preserve compatibility
  1539. with old chains, there may be some final changes yet to come before Cosmos
  1540. launch as we continue to audit and test the software.
  1541. ### BREAKING CHANGES:
  1542. * CLI/RPC/Config
  1543. * Apps
  1544. - [state] [\#3049](https://github.com/tendermint/tendermint/issues/3049) Total voting power of the validator set is upper bounded by
  1545. `MaxInt64 / 8`. Apps must ensure they do not return changes to the validator
  1546. set that cause this maximum to be exceeded.
  1547. * Go API
  1548. - [node] [\#3082](https://github.com/tendermint/tendermint/issues/3082) MetricsProvider now requires you to pass a chain ID
  1549. - [types] [\#2713](https://github.com/tendermint/tendermint/issues/2713) Rename `TxProof.LeafHash` to `TxProof.Leaf`
  1550. - [crypto/merkle] [\#2713](https://github.com/tendermint/tendermint/issues/2713) `SimpleProof.Verify` takes a `leaf` instead of a
  1551. `leafHash` and performs the hashing itself
  1552. * Blockchain Protocol
  1553. * [crypto/merkle] [\#2713](https://github.com/tendermint/tendermint/issues/2713) Merkle trees now match the RFC 6962 specification
  1554. * [types] [\#3078](https://github.com/tendermint/tendermint/issues/3078) Re-order Timestamp and BlockID in CanonicalVote so it's
  1555. consistent with CanonicalProposal (BlockID comes
  1556. first)
  1557. * [types] [\#3165](https://github.com/tendermint/tendermint/issues/3165) Hash of ConsensusParams only includes BlockSize.MaxBytes and
  1558. BlockSize.MaxGas
  1559. * P2P Protocol
  1560. - [consensus] [\#3049](https://github.com/tendermint/tendermint/issues/3049) Normalize priorities to not exceed `2*TotalVotingPower` to mitigate unfair proposer selection
  1561. heavily preferring earlier joined validators in the case of an early bonded large validator unbonding
  1562. ### FEATURES:
  1563. ### IMPROVEMENTS:
  1564. - [rpc] [\#3065](https://github.com/tendermint/tendermint/issues/3065) Return maxPerPage (100), not defaultPerPage (30) if `per_page` is greater than the max 100.
  1565. - [instrumentation] [\#3082](https://github.com/tendermint/tendermint/issues/3082) Add `chain_id` label for all metrics
  1566. ### BUG FIXES:
  1567. - [crypto] [\#3164](https://github.com/tendermint/tendermint/issues/3164) Update `btcd` fork for rare signRFC6979 bug
  1568. - [lite] [\#3171](https://github.com/tendermint/tendermint/issues/3171) Fix verifying large validator set changes
  1569. - [log] [\#3125](https://github.com/tendermint/tendermint/issues/3125) Fix year format
  1570. - [mempool] [\#3168](https://github.com/tendermint/tendermint/issues/3168) Limit tx size to fit in the max reactor msg size
  1571. - [scripts] [\#3147](https://github.com/tendermint/tendermint/issues/3147) Fix json2wal for large block parts (@bradyjoestar)
  1572. ## v0.28.1
  1573. *January 18th, 2019*
  1574. Special thanks to external contributors on this release:
  1575. @HaoyangLiu
  1576. ### BUG FIXES:
  1577. - [consensus] Fix consensus halt from proposing blocks with too much evidence
  1578. ## v0.28.0
  1579. *January 16th, 2019*
  1580. Special thanks to external contributors on this release:
  1581. @fmauricios, @gianfelipe93, @husio, @needkane, @srmo, @yutianwu
  1582. This release is primarily about upgrades to the `privval` system -
  1583. separating the `priv_validator.json` into distinct config and data files, and
  1584. refactoring the socket validator to support reconnections.
  1585. **Note:** Please backup your existing `priv_validator.json` before using this
  1586. version.
  1587. See [UPGRADING.md](UPGRADING.md) for more details.
  1588. ### BREAKING CHANGES:
  1589. * CLI/RPC/Config
  1590. - [cli] Removed `--proxy_app=dummy` option. Use `kvstore` (`persistent_kvstore`) instead.
  1591. - [cli] Renamed `--proxy_app=nilapp` to `--proxy_app=noop`.
  1592. - [config] [\#2992](https://github.com/tendermint/tendermint/issues/2992) `allow_duplicate_ip` is now set to false
  1593. - [privval] [\#1181](https://github.com/tendermint/tendermint/issues/1181) Split `priv_validator.json` into immutable (`config/priv_validator_key.json`) and mutable (`data/priv_validator_state.json`) parts (@yutianwu)
  1594. - [privval] [\#2926](https://github.com/tendermint/tendermint/issues/2926) Split up `PubKeyMsg` into `PubKeyRequest` and `PubKeyResponse` to be consistent with other message types
  1595. - [privval] [\#2923](https://github.com/tendermint/tendermint/issues/2923) Listen for unix socket connections instead of dialing them
  1596. * Apps
  1597. * Go API
  1598. - [types] [\#2981](https://github.com/tendermint/tendermint/issues/2981) Remove `PrivValidator.GetAddress()`
  1599. * Blockchain Protocol
  1600. * P2P Protocol
  1601. ### FEATURES:
  1602. - [rpc] [\#3052](https://github.com/tendermint/tendermint/issues/3052) Include peer's remote IP in `/net_info`
  1603. ### IMPROVEMENTS:
  1604. - [consensus] [\#3086](https://github.com/tendermint/tendermint/issues/3086) Log peerID on ignored votes (@srmo)
  1605. - [docs] [\#3061](https://github.com/tendermint/tendermint/issues/3061) Added specification for signing consensus msgs at
  1606. ./docs/spec/consensus/signing.md
  1607. - [privval] [\#2948](https://github.com/tendermint/tendermint/issues/2948) Memoize pubkey so it's only requested once on startup
  1608. - [privval] [\#2923](https://github.com/tendermint/tendermint/issues/2923) Retry RemoteSigner connections on error
  1609. ### BUG FIXES:
  1610. - [build] [\#3085](https://github.com/tendermint/tendermint/issues/3085) Fix `Version` field in build scripts (@husio)
  1611. - [crypto/multisig] [\#3102](https://github.com/tendermint/tendermint/issues/3102) Fix multisig keys address length
  1612. - [crypto/encoding] [\#3101](https://github.com/tendermint/tendermint/issues/3101) Fix `PubKeyMultisigThreshold` unmarshaling into `crypto.PubKey` interface
  1613. - [p2p/conn] [\#3111](https://github.com/tendermint/tendermint/issues/3111) Make SecretConnection thread safe
  1614. - [rpc] [\#3053](https://github.com/tendermint/tendermint/issues/3053) Fix internal error in `/tx_search` when results are empty
  1615. (@gianfelipe93)
  1616. - [types] [\#2926](https://github.com/tendermint/tendermint/issues/2926) Do not panic if retrieving the privval's public key fails
  1617. ## v0.27.4
  1618. *December 21st, 2018*
  1619. ### BUG FIXES:
  1620. - [mempool] [\#3036](https://github.com/tendermint/tendermint/issues/3036) Fix
  1621. LRU cache by popping the least recently used item when the cache is full,
  1622. not the most recently used one!
  1623. ## v0.27.3
  1624. *December 16th, 2018*
  1625. ### BREAKING CHANGES:
  1626. * Go API
  1627. - [dep] [\#3027](https://github.com/tendermint/tendermint/issues/3027) Revert to mainline Go crypto library, eliminating the modified
  1628. `bcrypt.GenerateFromPassword`
  1629. ## v0.27.2
  1630. *December 16th, 2018*
  1631. ### IMPROVEMENTS:
  1632. - [node] [\#3025](https://github.com/tendermint/tendermint/issues/3025) Validate NodeInfo addresses on startup.
  1633. ### BUG FIXES:
  1634. - [p2p] [\#3025](https://github.com/tendermint/tendermint/pull/3025) Revert to using defers in addrbook. Fixes deadlocks in pex and consensus upon invalid ExternalAddr/ListenAddr configuration.
  1635. ## v0.27.1
  1636. *December 15th, 2018*
  1637. Special thanks to external contributors on this release:
  1638. @danil-lashin, @hleb-albau, @james-ray, @leo-xinwang
  1639. ### FEATURES:
  1640. - [rpc] [\#2964](https://github.com/tendermint/tendermint/issues/2964) Add `UnconfirmedTxs(limit)` and `NumUnconfirmedTxs()` methods to HTTP/Local clients (@danil-lashin)
  1641. - [docs] [\#3004](https://github.com/tendermint/tendermint/issues/3004) Enable full-text search on docs pages
  1642. ### IMPROVEMENTS:
  1643. - [consensus] [\#2971](https://github.com/tendermint/tendermint/issues/2971) Return error if ValidatorSet is empty after InitChain
  1644. (@leo-xinwang)
  1645. - [ci/cd] [\#3005](https://github.com/tendermint/tendermint/issues/3005) Updated CircleCI job to trigger website build when docs are updated
  1646. - [docs] Various updates
  1647. ### BUG FIXES:
  1648. - [cmd] [\#2983](https://github.com/tendermint/tendermint/issues/2983) `testnet` command always sets `addr_book_strict = false`
  1649. - [config] [\#2980](https://github.com/tendermint/tendermint/issues/2980) Fix CORS options formatting
  1650. - [kv indexer] [\#2912](https://github.com/tendermint/tendermint/issues/2912) Don't ignore key when executing CONTAINS
  1651. - [mempool] [\#2961](https://github.com/tendermint/tendermint/issues/2961) Call `notifyTxsAvailable` if there're txs left after committing a block, but recheck=false
  1652. - [mempool] [\#2994](https://github.com/tendermint/tendermint/issues/2994) Reject txs with negative GasWanted
  1653. - [p2p] [\#2990](https://github.com/tendermint/tendermint/issues/2990) Fix a bug where seeds don't disconnect from a peer after 3h
  1654. - [consensus] [\#3006](https://github.com/tendermint/tendermint/issues/3006) Save state after InitChain only when stateHeight is also 0 (@james-ray)
  1655. ## v0.27.0
  1656. *December 5th, 2018*
  1657. Special thanks to external contributors on this release:
  1658. @danil-lashin, @srmo
  1659. Special thanks to @dlguddus for discovering a [major
  1660. issue](https://github.com/tendermint/tendermint/issues/2718#issuecomment-440888677)
  1661. in the proposer selection algorithm.
  1662. This release is primarily about fixes to the proposer selection algorithm
  1663. in preparation for the [Cosmos Game of
  1664. Stakes](https://blog.cosmos.network/the-game-of-stakes-is-open-for-registration-83a404746ee6).
  1665. It also makes use of the `ConsensusParams.Validator.PubKeyTypes` to restrict the
  1666. key types that can be used by validators, and removes the `Heartbeat` consensus
  1667. message.
  1668. ### BREAKING CHANGES:
  1669. * CLI/RPC/Config
  1670. - [rpc] [\#2932](https://github.com/tendermint/tendermint/issues/2932) Rename `accum` to `proposer_priority`
  1671. * Go API
  1672. - [db] [\#2913](https://github.com/tendermint/tendermint/pull/2913)
  1673. ReverseIterator API change: start < end, and end is exclusive.
  1674. - [types] [\#2932](https://github.com/tendermint/tendermint/issues/2932) Rename `Validator.Accum` to `Validator.ProposerPriority`
  1675. * Blockchain Protocol
  1676. - [state] [\#2714](https://github.com/tendermint/tendermint/issues/2714) Validators can now only use pubkeys allowed within
  1677. ConsensusParams.Validator.PubKeyTypes
  1678. * P2P Protocol
  1679. - [consensus] [\#2871](https://github.com/tendermint/tendermint/issues/2871)
  1680. Remove *ProposalHeartbeat* message as it serves no real purpose (@srmo)
  1681. - [state] Fixes for proposer selection:
  1682. - [\#2785](https://github.com/tendermint/tendermint/issues/2785) Accum for new validators is `-1.125*totalVotingPower` instead of 0
  1683. - [\#2941](https://github.com/tendermint/tendermint/issues/2941) val.Accum is preserved during ValidatorSet.Update to avoid being
  1684. reset to 0
  1685. ### IMPROVEMENTS:
  1686. - [state] [\#2929](https://github.com/tendermint/tendermint/issues/2929) Minor refactor of updateState logic (@danil-lashin)
  1687. - [node] [\#2959](https://github.com/tendermint/tendermint/issues/2959) Allow node to start even if software's BlockProtocol is
  1688. different from state's BlockProtocol
  1689. - [pex] [\#2959](https://github.com/tendermint/tendermint/issues/2959) Pex reactor logger uses `module=pex`
  1690. ### BUG FIXES:
  1691. - [p2p] [\#2968](https://github.com/tendermint/tendermint/issues/2968) Panic on transport error rather than continuing to run but not
  1692. accept new connections
  1693. - [p2p] [\#2969](https://github.com/tendermint/tendermint/issues/2969) Fix mismatch in peer count between `/net_info` and the prometheus
  1694. metrics
  1695. - [rpc] [\#2408](https://github.com/tendermint/tendermint/issues/2408) `/broadcast_tx_commit`: Fix "interface conversion: interface {} in nil, not EventDataTx" panic (could happen if somebody sent a tx using `/broadcast_tx_commit` while Tendermint was being stopped)
  1696. - [state] [\#2785](https://github.com/tendermint/tendermint/issues/2785) Fix accum for new validators to be `-1.125*totalVotingPower`
  1697. instead of 0, forcing them to wait before becoming the proposer. Also:
  1698. - do not batch clip
  1699. - keep accums averaged near 0
  1700. - [txindex/kv] [\#2925](https://github.com/tendermint/tendermint/issues/2925) Don't return false positives when range searching for a prefix of a tag value
  1701. - [types] [\#2938](https://github.com/tendermint/tendermint/issues/2938) Fix regression in v0.26.4 where we panic on empty
  1702. genDoc.Validators
  1703. - [types] [\#2941](https://github.com/tendermint/tendermint/issues/2941) Preserve val.Accum during ValidatorSet.Update to avoid it being
  1704. reset to 0 every time a validator is updated
  1705. ## v0.26.4
  1706. *November 27th, 2018*
  1707. Special thanks to external contributors on this release:
  1708. @ackratos, @goolAdapter, @james-ray, @joe-bowman, @kostko,
  1709. @nagarajmanjunath, @tomtau
  1710. ### FEATURES:
  1711. - [rpc] [\#2747](https://github.com/tendermint/tendermint/issues/2747) Enable subscription to tags emitted from `BeginBlock`/`EndBlock` (@kostko)
  1712. - [types] [\#2747](https://github.com/tendermint/tendermint/issues/2747) Add `ResultBeginBlock` and `ResultEndBlock` fields to `EventDataNewBlock`
  1713. and `EventDataNewBlockHeader` to support subscriptions (@kostko)
  1714. - [types] [\#2918](https://github.com/tendermint/tendermint/issues/2918) Add Marshal, MarshalTo, Unmarshal methods to various structs
  1715. to support Protobuf compatibility (@nagarajmanjunath)
  1716. ### IMPROVEMENTS:
  1717. - [config] [\#2877](https://github.com/tendermint/tendermint/issues/2877) Add `blocktime_iota` to the config.toml (@ackratos)
  1718. - NOTE: this should be a ConsensusParam, not part of the config, and will be
  1719. removed from the config at a later date
  1720. ([\#2920](https://github.com/tendermint/tendermint/issues/2920).
  1721. - [mempool] [\#2882](https://github.com/tendermint/tendermint/issues/2882) Add txs from Update to cache
  1722. - [mempool] [\#2891](https://github.com/tendermint/tendermint/issues/2891) Remove local int64 counter from being stored in every tx
  1723. - [node] [\#2866](https://github.com/tendermint/tendermint/issues/2866) Add ability to instantiate IPCVal (@joe-bowman)
  1724. ### BUG FIXES:
  1725. - [blockchain] [\#2731](https://github.com/tendermint/tendermint/issues/2731) Retry both blocks if either is bad to avoid getting stuck during fast sync (@goolAdapter)
  1726. - [consensus] [\#2893](https://github.com/tendermint/tendermint/issues/2893) Use genDoc.Validators instead of state.NextValidators on replay when appHeight==0 (@james-ray)
  1727. - [log] [\#2868](https://github.com/tendermint/tendermint/issues/2868) Fix `module=main` setting overriding all others
  1728. - NOTE: this changes the default logging behaviour to be much less verbose.
  1729. Set `log_level="info"` to restore the previous behaviour.
  1730. - [rpc] [\#2808](https://github.com/tendermint/tendermint/issues/2808) Fix `accum` field in `/validators` by calling `IncrementAccum` if necessary
  1731. - [rpc] [\#2811](https://github.com/tendermint/tendermint/issues/2811) Allow integer IDs in JSON-RPC requests (@tomtau)
  1732. - [txindex/kv] [\#2759](https://github.com/tendermint/tendermint/issues/2759) Fix tx.height range queries
  1733. - [txindex/kv] [\#2775](https://github.com/tendermint/tendermint/issues/2775) Order tx results by index if height is the same
  1734. - [txindex/kv] [\#2908](https://github.com/tendermint/tendermint/issues/2908) Don't return false positives when searching for a prefix of a tag value
  1735. ## v0.26.3
  1736. *November 17th, 2018*
  1737. Special thanks to external contributors on this release:
  1738. @danil-lashin, @kevlubkcm, @krhubert, @srmo
  1739. ### BREAKING CHANGES:
  1740. * Go API
  1741. - [rpc] [\#2791](https://github.com/tendermint/tendermint/issues/2791) Functions that start HTTP servers are now blocking:
  1742. - Impacts `StartHTTPServer`, `StartHTTPAndTLSServer`, and `StartGRPCServer`
  1743. - These functions now take a `net.Listener` instead of an address
  1744. - [rpc] [\#2767](https://github.com/tendermint/tendermint/issues/2767) Subscribing to events
  1745. `NewRound` and `CompleteProposal` return new types `EventDataNewRound` and
  1746. `EventDataCompleteProposal`, respectively, instead of the generic `EventDataRoundState`. (@kevlubkcm)
  1747. ### FEATURES:
  1748. - [log] [\#2843](https://github.com/tendermint/tendermint/issues/2843) New `log_format` config option, which can be set to 'plain' for colored
  1749. text or 'json' for JSON output
  1750. - [types] [\#2767](https://github.com/tendermint/tendermint/issues/2767) New event types EventDataNewRound (with ProposerInfo) and EventDataCompleteProposal (with BlockID). (@kevlubkcm)
  1751. ### IMPROVEMENTS:
  1752. - [dep] [\#2844](https://github.com/tendermint/tendermint/issues/2844) Dependencies are no longer pinned to an exact version in the
  1753. Gopkg.toml:
  1754. - Serialization libs are allowed to vary by patch release
  1755. - Other libs are allowed to vary by minor release
  1756. - [p2p] [\#2857](https://github.com/tendermint/tendermint/issues/2857) "Send failed" is logged at debug level instead of error.
  1757. - [rpc] [\#2780](https://github.com/tendermint/tendermint/issues/2780) Add read and write timeouts to HTTP servers
  1758. - [state] [\#2848](https://github.com/tendermint/tendermint/issues/2848) Make "Update to validators" msg value pretty (@danil-lashin)
  1759. ### BUG FIXES:
  1760. - [consensus] [\#2819](https://github.com/tendermint/tendermint/issues/2819) Don't send proposalHearbeat if not a validator
  1761. - [docs] [\#2859](https://github.com/tendermint/tendermint/issues/2859) Fix ConsensusParams details in spec
  1762. - [libs/autofile] [\#2760](https://github.com/tendermint/tendermint/issues/2760) Comment out autofile permissions check - should fix
  1763. running Tendermint on Windows
  1764. - [p2p] [\#2869](https://github.com/tendermint/tendermint/issues/2869) Set connection config properly instead of always using default
  1765. - [p2p/pex] [\#2802](https://github.com/tendermint/tendermint/issues/2802) Seed mode fixes:
  1766. - Only disconnect from inbound peers
  1767. - Use FlushStop instead of Sleep to ensure all messages are sent before
  1768. disconnecting
  1769. ## v0.26.2
  1770. *November 15th, 2018*
  1771. Special thanks to external contributors on this release: @hleb-albau, @zhuzeyu
  1772. ### FEATURES:
  1773. - [rpc] [\#2582](https://github.com/tendermint/tendermint/issues/2582) Enable CORS on RPC API (@hleb-albau)
  1774. ### BUG FIXES:
  1775. - [abci] [\#2748](https://github.com/tendermint/tendermint/issues/2748) Unlock mutex in localClient so even when app panics (e.g. during CheckTx), consensus continue working
  1776. - [abci] [\#2748](https://github.com/tendermint/tendermint/issues/2748) Fix DATA RACE in localClient
  1777. - [amino] [\#2822](https://github.com/tendermint/tendermint/issues/2822) Update to v0.14.1 to support compiling on 32-bit platforms
  1778. - [rpc] [\#2748](https://github.com/tendermint/tendermint/issues/2748) Drain channel before calling Unsubscribe(All) in `/broadcast_tx_commit`
  1779. ## v0.26.1
  1780. *November 11, 2018*
  1781. Special thanks to external contributors on this release: @katakonst
  1782. ### IMPROVEMENTS:
  1783. - [consensus] [\#2704](https://github.com/tendermint/tendermint/issues/2704) Simplify valid POL round logic
  1784. - [docs] [\#2749](https://github.com/tendermint/tendermint/issues/2749) Deduplicate some ABCI docs
  1785. - [mempool] More detailed log messages
  1786. - [\#2724](https://github.com/tendermint/tendermint/issues/2724)
  1787. - [\#2762](https://github.com/tendermint/tendermint/issues/2762)
  1788. ### BUG FIXES:
  1789. - [autofile] [\#2703](https://github.com/tendermint/tendermint/issues/2703) Do not panic when checking Head size
  1790. - [crypto/merkle] [\#2756](https://github.com/tendermint/tendermint/issues/2756) Fix crypto/merkle ProofOperators.Verify to check bounds on keypath parts.
  1791. - [mempool] fix a bug where we create a WAL despite `wal_dir` being empty
  1792. - [p2p] [\#2771](https://github.com/tendermint/tendermint/issues/2771) Fix `peer-id` label name to `peer_id` in prometheus metrics
  1793. - [p2p] [\#2797](https://github.com/tendermint/tendermint/pull/2797) Fix IDs in peer NodeInfo and require them for addresses
  1794. in AddressBook
  1795. - [p2p] [\#2797](https://github.com/tendermint/tendermint/pull/2797) Do not close conn immediately after sending pex addrs in seed mode. Partial fix for [\#2092](https://github.com/tendermint/tendermint/issues/2092).
  1796. ## v0.26.0
  1797. *November 2, 2018*
  1798. Special thanks to external contributors on this release:
  1799. @bradyjoestar, @connorwstein, @goolAdapter, @HaoyangLiu,
  1800. @james-ray, @overbool, @phymbert, @Slamper, @Uzair1995, @yutianwu.
  1801. Special thanks to @Slamper for a series of bug reports in our [bug bounty
  1802. program](https://hackerone.com/tendermint) which are fixed in this release.
  1803. This release is primarily about adding Version fields to various data structures,
  1804. optimizing consensus messages for signing and verification in
  1805. restricted environments (like HSMs and the Ethereum Virtual Machine), and
  1806. aligning the consensus code with the [specification](https://arxiv.org/abs/1807.04938).
  1807. It also includes our first take at a generalized merkle proof system, and
  1808. changes the length of hashes used for hashing data structures from 20 to 32
  1809. bytes.
  1810. See the [UPGRADING.md](UPGRADING.md#v0.26.0) for details on upgrading to the new
  1811. version.
  1812. Please note that we are still making breaking changes to the protocols.
  1813. While the new Version fields should help us to keep the software backwards compatible
  1814. even while upgrading the protocols, we cannot guarantee that new releases will
  1815. be compatible with old chains just yet. We expect there will be another breaking
  1816. release or two before the Cosmos Hub launch, but we will otherwise be paying
  1817. increasing attention to backwards compatibility. Thanks for bearing with us!
  1818. ### BREAKING CHANGES:
  1819. * CLI/RPC/Config
  1820. * [config] [\#2232](https://github.com/tendermint/tendermint/issues/2232) Timeouts are now strings like "3s" and "100ms", not ints
  1821. * [config] [\#2505](https://github.com/tendermint/tendermint/issues/2505) Remove Mempool.RecheckEmpty (it was effectively useless anyways)
  1822. * [config] [\#2490](https://github.com/tendermint/tendermint/issues/2490) `mempool.wal` is disabled by default
  1823. * [privval] [\#2459](https://github.com/tendermint/tendermint/issues/2459) Split `SocketPVMsg`s implementations into Request and Response, where the Response may contain a error message (returned by the remote signer)
  1824. * [state] [\#2644](https://github.com/tendermint/tendermint/issues/2644) Add Version field to State, breaking the format of State as
  1825. encoded on disk.
  1826. * [rpc] [\#2298](https://github.com/tendermint/tendermint/issues/2298) `/abci_query` takes `prove` argument instead of `trusted` and switches the default
  1827. behaviour to `prove=false`
  1828. * [rpc] [\#2654](https://github.com/tendermint/tendermint/issues/2654) Remove all `node_info.other.*_version` fields in `/status` and
  1829. `/net_info`
  1830. * [rpc] [\#2636](https://github.com/tendermint/tendermint/issues/2636) Remove
  1831. `_params` suffix from fields in `consensus_params`.
  1832. * Apps
  1833. * [abci] [\#2298](https://github.com/tendermint/tendermint/issues/2298) ResponseQuery.Proof is now a structured merkle.Proof, not just
  1834. arbitrary bytes
  1835. * [abci] [\#2644](https://github.com/tendermint/tendermint/issues/2644) Add Version to Header and shift all fields by one
  1836. * [abci] [\#2662](https://github.com/tendermint/tendermint/issues/2662) Bump the field numbers for some `ResponseInfo` fields to make room for
  1837. `AppVersion`
  1838. * [abci] [\#2636](https://github.com/tendermint/tendermint/issues/2636) Updates to ConsensusParams
  1839. * Remove `Params` suffix from field names
  1840. * Add `Params` suffix to message types
  1841. * Add new field and type, `Validator ValidatorParams`, to control what types of validator keys are allowed.
  1842. * Go API
  1843. * [config] [\#2232](https://github.com/tendermint/tendermint/issues/2232) Timeouts are time.Duration, not ints
  1844. * [crypto/merkle & lite] [\#2298](https://github.com/tendermint/tendermint/issues/2298) Various changes to accomodate General Merkle trees
  1845. * [crypto/merkle] [\#2595](https://github.com/tendermint/tendermint/issues/2595) Remove all Hasher objects in favor of byte slices
  1846. * [crypto/merkle] [\#2635](https://github.com/tendermint/tendermint/issues/2635) merkle.SimpleHashFromTwoHashes is no longer exported
  1847. * [node] [\#2479](https://github.com/tendermint/tendermint/issues/2479) Remove node.RunForever
  1848. * [rpc/client] [\#2298](https://github.com/tendermint/tendermint/issues/2298) `ABCIQueryOptions.Trusted` -> `ABCIQueryOptions.Prove`
  1849. * [types] [\#2298](https://github.com/tendermint/tendermint/issues/2298) Remove `Index` and `Total` fields from `TxProof`.
  1850. * [types] [\#2598](https://github.com/tendermint/tendermint/issues/2598)
  1851. `VoteTypeXxx` are now of type `SignedMsgType byte` and named `XxxType`, eg.
  1852. `PrevoteType`, `PrecommitType`.
  1853. * [types] [\#2636](https://github.com/tendermint/tendermint/issues/2636) Rename fields in ConsensusParams to remove `Params` suffixes
  1854. * [types] [\#2735](https://github.com/tendermint/tendermint/issues/2735) Simplify Proposal message to align with spec
  1855. * Blockchain Protocol
  1856. * [crypto/tmhash] [\#2732](https://github.com/tendermint/tendermint/issues/2732) TMHASH is now full 32-byte SHA256
  1857. * All hashes in the block header and Merkle trees are now 32-bytes
  1858. * PubKey Addresses are still only 20-bytes
  1859. * [state] [\#2587](https://github.com/tendermint/tendermint/issues/2587) Require block.Time of the fist block to be genesis time
  1860. * [state] [\#2644](https://github.com/tendermint/tendermint/issues/2644) Require block.Version to match state.Version
  1861. * [types] Update SignBytes for `Vote`/`Proposal`/`Heartbeat`:
  1862. * [\#2459](https://github.com/tendermint/tendermint/issues/2459) Use amino encoding instead of JSON in `SignBytes`.
  1863. * [\#2598](https://github.com/tendermint/tendermint/issues/2598) Reorder fields and use fixed sized encoding.
  1864. * [\#2598](https://github.com/tendermint/tendermint/issues/2598) Change `Type` field from `string` to `byte` and use new
  1865. `SignedMsgType` to enumerate.
  1866. * [types] [\#2730](https://github.com/tendermint/tendermint/issues/2730) Use
  1867. same order for fields in `Vote` as in the SignBytes
  1868. * [types] [\#2732](https://github.com/tendermint/tendermint/issues/2732) Remove the address field from the validator hash
  1869. * [types] [\#2644](https://github.com/tendermint/tendermint/issues/2644) Add Version struct to Header
  1870. * [types] [\#2609](https://github.com/tendermint/tendermint/issues/2609) ConsensusParams.Hash() is the hash of the amino encoded
  1871. struct instead of the Merkle tree of the fields
  1872. * [types] [\#2670](https://github.com/tendermint/tendermint/issues/2670) Header.Hash() builds Merkle tree out of fields in the same
  1873. order they appear in the header, instead of sorting by field name
  1874. * [types] [\#2682](https://github.com/tendermint/tendermint/issues/2682) Use proto3 `varint` encoding for ints that are usually unsigned (instead of zigzag encoding).
  1875. * [types] [\#2636](https://github.com/tendermint/tendermint/issues/2636) Add Validator field to ConsensusParams
  1876. (Used to control which pubkey types validators can use, by abci type).
  1877. * P2P Protocol
  1878. * [consensus] [\#2652](https://github.com/tendermint/tendermint/issues/2652)
  1879. Replace `CommitStepMessage` with `NewValidBlockMessage`
  1880. * [consensus] [\#2735](https://github.com/tendermint/tendermint/issues/2735) Simplify `Proposal` message to align with spec
  1881. * [consensus] [\#2730](https://github.com/tendermint/tendermint/issues/2730)
  1882. Add `Type` field to `Proposal` and use same order of fields as in the
  1883. SignBytes for both `Proposal` and `Vote`
  1884. * [p2p] [\#2654](https://github.com/tendermint/tendermint/issues/2654) Add `ProtocolVersion` struct with protocol versions to top of
  1885. DefaultNodeInfo and require `ProtocolVersion.Block` to match during peer handshake
  1886. ### FEATURES:
  1887. - [abci] [\#2557](https://github.com/tendermint/tendermint/issues/2557) Add `Codespace` field to `Response{CheckTx, DeliverTx, Query}`
  1888. - [abci] [\#2662](https://github.com/tendermint/tendermint/issues/2662) Add `BlockVersion` and `P2PVersion` to `RequestInfo`
  1889. - [crypto/merkle] [\#2298](https://github.com/tendermint/tendermint/issues/2298) General Merkle Proof scheme for chaining various types of Merkle trees together
  1890. - [docs/architecture] [\#1181](https://github.com/tendermint/tendermint/issues/1181) S
  1891. plit immutable and mutable parts of priv_validator.json
  1892. ### IMPROVEMENTS:
  1893. - Additional Metrics
  1894. - [consensus] [\#2169](https://github.com/cosmos/cosmos-sdk/issues/2169)
  1895. - [p2p] [\#2169](https://github.com/cosmos/cosmos-sdk/issues/2169)
  1896. - [config] [\#2232](https://github.com/tendermint/tendermint/issues/2232) Added ValidateBasic method, which performs basic checks
  1897. - [crypto/ed25519] [\#2558](https://github.com/tendermint/tendermint/issues/2558) Switch to use latest `golang.org/x/crypto` through our fork at
  1898. github.com/tendermint/crypto
  1899. - [libs/log] [\#2707](https://github.com/tendermint/tendermint/issues/2707) Add year to log format (@yutianwu)
  1900. - [tools] [\#2238](https://github.com/tendermint/tendermint/issues/2238) Binary dependencies are now locked to a specific git commit
  1901. ### BUG FIXES:
  1902. - [\#2711](https://github.com/tendermint/tendermint/issues/2711) Validate all incoming reactor messages. Fixes various bugs due to negative ints.
  1903. - [autofile] [\#2428](https://github.com/tendermint/tendermint/issues/2428) Group.RotateFile need call Flush() before rename (@goolAdapter)
  1904. - [common] [\#2533](https://github.com/tendermint/tendermint/issues/2533) Fixed a bug in the `BitArray.Or` method
  1905. - [common] [\#2506](https://github.com/tendermint/tendermint/issues/2506) Fixed a bug in the `BitArray.Sub` method (@james-ray)
  1906. - [common] [\#2534](https://github.com/tendermint/tendermint/issues/2534) Fix `BitArray.PickRandom` to choose uniformly from true bits
  1907. - [consensus] [\#1690](https://github.com/tendermint/tendermint/issues/1690) Wait for
  1908. timeoutPrecommit before starting next round
  1909. - [consensus] [\#1745](https://github.com/tendermint/tendermint/issues/1745) Wait for
  1910. Proposal or timeoutProposal before entering prevote
  1911. - [consensus] [\#2642](https://github.com/tendermint/tendermint/issues/2642) Only propose ValidBlock, not LockedBlock
  1912. - [consensus] [\#2642](https://github.com/tendermint/tendermint/issues/2642) Initialized ValidRound and LockedRound to -1
  1913. - [consensus] [\#1637](https://github.com/tendermint/tendermint/issues/1637) Limit the amount of evidence that can be included in a
  1914. block
  1915. - [consensus] [\#2652](https://github.com/tendermint/tendermint/issues/2652) Ensure valid block property with faulty proposer
  1916. - [evidence] [\#2515](https://github.com/tendermint/tendermint/issues/2515) Fix db iter leak (@goolAdapter)
  1917. - [libs/event] [\#2518](https://github.com/tendermint/tendermint/issues/2518) Fix event concurrency flaw (@goolAdapter)
  1918. - [node] [\#2434](https://github.com/tendermint/tendermint/issues/2434) Make node respond to signal interrupts while sleeping for genesis time
  1919. - [state] [\#2616](https://github.com/tendermint/tendermint/issues/2616) Pass nil to NewValidatorSet() when genesis file's Validators field is nil
  1920. - [p2p] [\#2555](https://github.com/tendermint/tendermint/issues/2555) Fix p2p switch FlushThrottle value (@goolAdapter)
  1921. - [p2p] [\#2668](https://github.com/tendermint/tendermint/issues/2668) Reconnect to originally dialed address (not self-reported address) for persistent peers
  1922. ## v0.25.0
  1923. *September 22, 2018*
  1924. Special thanks to external contributors on this release:
  1925. @scriptionist, @bradyjoestar, @WALL-E
  1926. This release is mostly about the ConsensusParams - removing fields and enforcing MaxGas.
  1927. It also addresses some issues found via security audit, removes various unused
  1928. functions from `libs/common`, and implements
  1929. [ADR-012](https://github.com/tendermint/tendermint/blob/develop/docs/architecture/adr-012-peer-transport.md).
  1930. BREAKING CHANGES:
  1931. * CLI/RPC/Config
  1932. * [rpc] [\#2391](https://github.com/tendermint/tendermint/issues/2391) /status `result.node_info.other` became a map
  1933. * [types] [\#2364](https://github.com/tendermint/tendermint/issues/2364) Remove `TxSize` and `BlockGossip` from `ConsensusParams`
  1934. * Maximum tx size is now set implicitly via the `BlockSize.MaxBytes`
  1935. * The size of block parts in the consensus is now fixed to 64kB
  1936. * Apps
  1937. * [mempool] [\#2360](https://github.com/tendermint/tendermint/issues/2360) Mempool tracks the `ResponseCheckTx.GasWanted` and
  1938. `ConsensusParams.BlockSize.MaxGas` and enforces:
  1939. - `GasWanted <= MaxGas` for every tx
  1940. - `(sum of GasWanted in block) <= MaxGas` for block proposal
  1941. * Go API
  1942. * [libs/common] [\#2431](https://github.com/tendermint/tendermint/issues/2431) Remove Word256 due to lack of use
  1943. * [libs/common] [\#2452](https://github.com/tendermint/tendermint/issues/2452) Remove the following functions due to lack of use:
  1944. * byteslice.go: cmn.IsZeros, cmn.RightPadBytes, cmn.LeftPadBytes, cmn.PrefixEndBytes
  1945. * strings.go: cmn.IsHex, cmn.StripHex
  1946. * int.go: Uint64Slice, all put/get int64 methods
  1947. FEATURES:
  1948. - [rpc] [\#2415](https://github.com/tendermint/tendermint/issues/2415) New `/consensus_params?height=X` endpoint to query the consensus
  1949. params at any height (@scriptonist)
  1950. - [types] [\#1714](https://github.com/tendermint/tendermint/issues/1714) Add Address to GenesisValidator
  1951. - [metrics] [\#2337](https://github.com/tendermint/tendermint/issues/2337) `consensus.block_interval_metrics` is now gauge, not histogram (you will be able to see spikes, if any)
  1952. - [libs] [\#2286](https://github.com/tendermint/tendermint/issues/2286) Panic if `autofile` or `db/fsdb` permissions change from 0600.
  1953. IMPROVEMENTS:
  1954. - [libs/db] [\#2371](https://github.com/tendermint/tendermint/issues/2371) Output error instead of panic when the given `db_backend` is not initialized (@bradyjoestar)
  1955. - [mempool] [\#2399](https://github.com/tendermint/tendermint/issues/2399) Make mempool cache a proper LRU (@bradyjoestar)
  1956. - [p2p] [\#2126](https://github.com/tendermint/tendermint/issues/2126) Introduce PeerTransport interface to improve isolation of concerns
  1957. - [libs/common] [\#2326](https://github.com/tendermint/tendermint/issues/2326) Service returns ErrNotStarted
  1958. BUG FIXES:
  1959. - [node] [\#2294](https://github.com/tendermint/tendermint/issues/2294) Delay starting node until Genesis time
  1960. - [consensus] [\#2048](https://github.com/tendermint/tendermint/issues/2048) Correct peer statistics for marking peer as good
  1961. - [rpc] [\#2460](https://github.com/tendermint/tendermint/issues/2460) StartHTTPAndTLSServer() now passes StartTLS() errors back to the caller rather than hanging forever.
  1962. - [p2p] [\#2047](https://github.com/tendermint/tendermint/issues/2047) Accept new connections asynchronously
  1963. - [tm-bench] [\#2410](https://github.com/tendermint/tendermint/issues/2410) Enforce minimum transaction size (@WALL-E)
  1964. ## 0.24.0
  1965. *September 6th, 2018*
  1966. Special thanks to external contributors with PRs included in this release: ackratos, james-ray, bradyjoestar,
  1967. peerlink, Ahmah2009, bluele, b00f.
  1968. This release includes breaking upgrades in the block header,
  1969. including the long awaited changes for delaying validator set updates by one
  1970. block to better support light clients.
  1971. It also fixes enforcement on the maximum size of blocks, and includes a BFT
  1972. timestamp in each block that can be safely used by applications.
  1973. There are also some minor breaking changes to the rpc, config, and ABCI.
  1974. See the [UPGRADING.md](UPGRADING.md#v0.24.0) for details on upgrading to the new
  1975. version.
  1976. From here on, breaking changes will be broken down to better reflect how users
  1977. are affected by a change.
  1978. A few more breaking changes are in the works - each will come with a clear
  1979. Architecture Decision Record (ADR) explaining the change. You can review ADRs
  1980. [here](https://github.com/tendermint/tendermint/tree/develop/docs/architecture)
  1981. or in the [open Pull Requests](https://github.com/tendermint/tendermint/pulls).
  1982. You can also check in on the [issues marked as
  1983. breaking](https://github.com/tendermint/tendermint/issues?q=is%3Aopen+is%3Aissue+label%3Abreaking).
  1984. BREAKING CHANGES:
  1985. * CLI/RPC/Config
  1986. - [config] [\#2169](https://github.com/tendermint/tendermint/issues/2169) Replace MaxNumPeers with MaxNumInboundPeers and MaxNumOutboundPeers
  1987. - [config] [\#2300](https://github.com/tendermint/tendermint/issues/2300) Reduce default mempool size from 100k to 5k, until ABCI rechecking is implemented.
  1988. - [rpc] [\#1815](https://github.com/tendermint/tendermint/issues/1815) `/commit` returns a `signed_header` field instead of everything being top-level
  1989. * Apps
  1990. - [abci] Added address of the original proposer of the block to Header
  1991. - [abci] Change ABCI Header to match Tendermint exactly
  1992. - [abci] [\#2159](https://github.com/tendermint/tendermint/issues/2159) Update use of `Validator` (see
  1993. [ADR-018](https://github.com/tendermint/tendermint/blob/develop/docs/architecture/adr-018-ABCI-Validators.md)):
  1994. - Remove PubKey from `Validator` (so it's just Address and Power)
  1995. - Introduce `ValidatorUpdate` (with just PubKey and Power)
  1996. - InitChain and EndBlock use ValidatorUpdate
  1997. - Update field names and types in BeginBlock
  1998. - [state] [\#1815](https://github.com/tendermint/tendermint/issues/1815) Validator set changes are now delayed by one block
  1999. - updates returned in ResponseEndBlock for block H will be included in RequestBeginBlock for block H+2
  2000. * Go API
  2001. - [lite] [\#1815](https://github.com/tendermint/tendermint/issues/1815) Complete refactor of the package
  2002. - [node] [\#2212](https://github.com/tendermint/tendermint/issues/2212) NewNode now accepts a `*p2p.NodeKey` (@bradyjoestar)
  2003. - [libs/common] [\#2199](https://github.com/tendermint/tendermint/issues/2199) Remove Fmt, in favor of fmt.Sprintf
  2004. - [libs/common] SplitAndTrim was deleted
  2005. - [libs/common] [\#2274](https://github.com/tendermint/tendermint/issues/2274) Remove unused Math functions like MaxInt, MaxInt64,
  2006. MinInt, MinInt64 (@Ahmah2009)
  2007. - [libs/clist] Panics if list extends beyond MaxLength
  2008. - [crypto] [\#2205](https://github.com/tendermint/tendermint/issues/2205) Rename AminoRoute variables to no longer be prefixed by signature type.
  2009. * Blockchain Protocol
  2010. - [state] [\#1815](https://github.com/tendermint/tendermint/issues/1815) Validator set changes are now delayed by one block (!)
  2011. - Add NextValidatorSet to State, changes on-disk representation of state
  2012. - [state] [\#2184](https://github.com/tendermint/tendermint/issues/2184) Enforce ConsensusParams.BlockSize.MaxBytes (See
  2013. [ADR-020](https://github.com/tendermint/tendermint/blob/develop/docs/architecture/adr-020-block-size.md)).
  2014. - Remove ConsensusParams.BlockSize.MaxTxs
  2015. - Introduce maximum sizes for all components of a block, including ChainID
  2016. - [types] Updates to the block Header:
  2017. - [\#1815](https://github.com/tendermint/tendermint/issues/1815) NextValidatorsHash - hash of the validator set for the next block,
  2018. so the current validators actually sign over the hash for the new
  2019. validators
  2020. - [\#2106](https://github.com/tendermint/tendermint/issues/2106) ProposerAddress - address of the block's original proposer
  2021. - [consensus] [\#2203](https://github.com/tendermint/tendermint/issues/2203) Implement BFT time
  2022. - Timestamp in block must be monotonic and equal the median of timestamps in block's LastCommit
  2023. - [crypto] [\#2239](https://github.com/tendermint/tendermint/issues/2239) Secp256k1 signature changes (See
  2024. [ADR-014](https://github.com/tendermint/tendermint/blob/develop/docs/architecture/adr-014-secp-malleability.md)):
  2025. - format changed from DER to `r || s`, both little endian encoded as 32 bytes.
  2026. - malleability removed by requiring `s` to be in canonical form.
  2027. * P2P Protocol
  2028. - [p2p] [\#2263](https://github.com/tendermint/tendermint/issues/2263) Update secret connection to use a little endian encoded nonce
  2029. - [blockchain] [\#2213](https://github.com/tendermint/tendermint/issues/2213) Fix Amino routes for blockchain reactor messages
  2030. (@peerlink)
  2031. FEATURES:
  2032. - [types] [\#2015](https://github.com/tendermint/tendermint/issues/2015) Allow genesis file to have 0 validators (@b00f)
  2033. - Initial validator set can be determined by the app in ResponseInitChain
  2034. - [rpc] [\#2161](https://github.com/tendermint/tendermint/issues/2161) New event `ValidatorSetUpdates` for when the validator set changes
  2035. - [crypto/multisig] [\#2164](https://github.com/tendermint/tendermint/issues/2164) Introduce multisig pubkey and signature format
  2036. - [libs/db] [\#2293](https://github.com/tendermint/tendermint/issues/2293) Allow passing options through when creating instances of leveldb dbs
  2037. IMPROVEMENTS:
  2038. - [docs] Lint documentation with `write-good` and `stop-words`.
  2039. - [docs] [\#2249](https://github.com/tendermint/tendermint/issues/2249) Refactor, deduplicate, and improve the ABCI docs and spec (with thanks to @ttmc).
  2040. - [scripts] [\#2196](https://github.com/tendermint/tendermint/issues/2196) Added json2wal tool, which is supposed to help our users restore (@bradyjoestar)
  2041. corrupted WAL files and compose test WAL files (@bradyjoestar)
  2042. - [mempool] [\#2234](https://github.com/tendermint/tendermint/issues/2234) Now stores txs by hash inside of the cache, to mitigate memory leakage
  2043. - [mempool] [\#2166](https://github.com/tendermint/tendermint/issues/2166) Set explicit capacity for map when updating txs (@bluele)
  2044. BUG FIXES:
  2045. - [config] [\#2284](https://github.com/tendermint/tendermint/issues/2284) Replace `db_path` with `db_dir` from automatically generated configuration files.
  2046. - [mempool] [\#2188](https://github.com/tendermint/tendermint/issues/2188) Fix OOM issue from cache map and list getting out of sync
  2047. - [state] [\#2051](https://github.com/tendermint/tendermint/issues/2051) KV store index supports searching by `tx.height` (@ackratos)
  2048. - [rpc] [\#2327](https://github.com/tendermint/tendermint/issues/2327) `/dial_peers` does not try to dial existing peers
  2049. - [node] [\#2323](https://github.com/tendermint/tendermint/issues/2323) Filter empty strings from config lists (@james-ray)
  2050. - [abci/client] [\#2236](https://github.com/tendermint/tendermint/issues/2236) Fix closing GRPC connection (@bradyjoestar)
  2051. ## 0.23.1
  2052. *August 22nd, 2018*
  2053. BUG FIXES:
  2054. - [libs/autofile] [\#2261](https://github.com/tendermint/tendermint/issues/2261) Fix log rotation so it actually happens.
  2055. - Fixes issues with consensus WAL growing unbounded ala [\#2259](https://github.com/tendermint/tendermint/issues/2259)
  2056. ## 0.23.0
  2057. *August 5th, 2018*
  2058. This release includes breaking upgrades in our P2P encryption,
  2059. some ABCI messages, and how we encode time and signatures.
  2060. A few more changes are still coming to the Header, ABCI,
  2061. and validator set handling to better support light clients, BFT time, and
  2062. upgrades. Most notably, validator set changes will be delayed by one block (see
  2063. [#1815][i1815]).
  2064. We also removed `make ensure_deps` in favour of `make get_vendor_deps`.
  2065. BREAKING CHANGES:
  2066. - [abci] Changed time format from int64 to google.protobuf.Timestamp
  2067. - [abci] Changed Validators to LastCommitInfo in RequestBeginBlock
  2068. - [abci] Removed Fee from ResponseDeliverTx and ResponseCheckTx
  2069. - [crypto] Switch crypto.Signature from interface to []byte for space efficiency
  2070. [#2128](https://github.com/tendermint/tendermint/pull/2128)
  2071. - NOTE: this means signatures no longer have the prefix bytes in Amino
  2072. binary nor the `type` field in Amino JSON. They're just bytes.
  2073. - [p2p] Remove salsa and ripemd primitives, in favor of using chacha as a stream cipher, and hkdf [#2054](https://github.com/tendermint/tendermint/pull/2054)
  2074. - [tools] Removed `make ensure_deps` in favor of `make get_vendor_deps`
  2075. - [types] CanonicalTime uses nanoseconds instead of clipping to ms
  2076. - breaks serialization/signing of all messages with a timestamp
  2077. FEATURES:
  2078. - [tools] Added `make check_dep`
  2079. - ensures gopkg.lock is synced with gopkg.toml
  2080. - ensures no branches are used in the gopkg.toml
  2081. IMPROVEMENTS:
  2082. - [blockchain] Improve fast-sync logic
  2083. [#1805](https://github.com/tendermint/tendermint/pull/1805)
  2084. - tweak params
  2085. - only process one block at a time to avoid starving
  2086. - [common] bit array functions which take in another parameter are now thread safe
  2087. - [crypto] Switch hkdfchachapoly1305 to xchachapoly1305
  2088. - [p2p] begin connecting to peers as soon a seed node provides them to you ([#2093](https://github.com/tendermint/tendermint/issues/2093))
  2089. BUG FIXES:
  2090. - [common] Safely handle cases where atomic write files already exist [#2109](https://github.com/tendermint/tendermint/issues/2109)
  2091. - [privval] fix a deadline for accepting new connections in socket private
  2092. validator.
  2093. - [p2p] Allow startup if a configured seed node's IP can't be resolved ([#1716](https://github.com/tendermint/tendermint/issues/1716))
  2094. - [node] Fully exit when CTRL-C is pressed even if consensus state panics [#2072](https://github.com/tendermint/tendermint/issues/2072)
  2095. [i1815]: https://github.com/tendermint/tendermint/pull/1815
  2096. ## 0.22.8
  2097. *July 26th, 2018*
  2098. BUG FIXES
  2099. - [consensus, blockchain] Fix 0.22.7 below.
  2100. ## 0.22.7
  2101. *July 26th, 2018*
  2102. BUG FIXES
  2103. - [consensus, blockchain] Register the Evidence interface so it can be
  2104. marshalled/unmarshalled by the blockchain and consensus reactors
  2105. ## 0.22.6
  2106. *July 24th, 2018*
  2107. BUG FIXES
  2108. - [rpc] Fix `/blockchain` endpoint
  2109. - (#2049) Fix OOM attack by returning error on negative input
  2110. - Fix result length to have max 20 (instead of 21) block metas
  2111. - [rpc] Validate height is non-negative in `/abci_query`
  2112. - [consensus] (#2050) Include evidence in proposal block parts (previously evidence was
  2113. not being included in blocks!)
  2114. - [p2p] (#2046) Close rejected inbound connections so file descriptor doesn't
  2115. leak
  2116. - [Gopkg] (#2053) Fix versions in the toml
  2117. ## 0.22.5
  2118. *July 23th, 2018*
  2119. BREAKING CHANGES:
  2120. - [crypto] Refactor `tendermint/crypto` into many subpackages
  2121. - [libs/common] remove exponentially distributed random numbers
  2122. IMPROVEMENTS:
  2123. - [abci, libs/common] Generated gogoproto static marshaller methods
  2124. - [config] Increase default send/recv rates to 5 mB/s
  2125. - [p2p] reject addresses coming from private peers
  2126. - [p2p] allow persistent peers to be private
  2127. BUG FIXES:
  2128. - [mempool] fixed a race condition when `create_empty_blocks=false` where a
  2129. transaction is published at an old height.
  2130. - [p2p] dial external IP setup by `persistent_peers`, not internal NAT IP
  2131. - [rpc] make `/status` RPC endpoint resistant to consensus halt
  2132. ## 0.22.4
  2133. *July 14th, 2018*
  2134. BREAKING CHANGES:
  2135. - [genesis] removed deprecated `app_options` field.
  2136. - [types] Genesis.AppStateJSON -> Genesis.AppState
  2137. FEATURES:
  2138. - [tools] Merged in from github.com/tendermint/tools
  2139. BUG FIXES:
  2140. - [tools/tm-bench] Various fixes
  2141. - [consensus] Wait for WAL to stop on shutdown
  2142. - [abci] Fix #1891, pending requests cannot hang when abci server dies.
  2143. Previously a crash in BeginBlock could leave tendermint in broken state.
  2144. ## 0.22.3
  2145. *July 10th, 2018*
  2146. IMPROVEMENTS
  2147. - Update dependencies
  2148. * pin all values in Gopkg.toml to version or commit
  2149. * update golang/protobuf to v1.1.0
  2150. ## 0.22.2
  2151. *July 10th, 2018*
  2152. IMPROVEMENTS
  2153. - More cleanup post repo merge!
  2154. - [docs] Include `ecosystem.json` and `tendermint-bft.md` from deprecated `aib-data` repository.
  2155. - [config] Add `instrumentation.max_open_connections`, which limits the number
  2156. of requests in flight to Prometheus server (if enabled). Default: 3.
  2157. BUG FIXES
  2158. - [rpc] Allow unquoted integers in requests
  2159. - NOTE: this is only for URI requests. JSONRPC requests and all responses
  2160. will use quoted integers (the proto3 JSON standard).
  2161. - [consensus] Fix halt on shutdown
  2162. ## 0.22.1
  2163. *July 5th, 2018*
  2164. IMPROVEMENTS
  2165. * Cleanup post repo-merge.
  2166. * [docs] Various improvements.
  2167. BUG FIXES
  2168. * [state] Return error when EndBlock returns a 0-power validator that isn't
  2169. already in the validator set.
  2170. * [consensus] Shut down WAL properly.
  2171. ## 0.22.0
  2172. *July 2nd, 2018*
  2173. BREAKING CHANGES:
  2174. - [config]
  2175. * Remove `max_block_size_txs` and `max_block_size_bytes` in favor of
  2176. consensus params from the genesis file.
  2177. * Rename `skip_upnp` to `upnp`, and turn it off by default.
  2178. * Change `max_packet_msg_size` back to `max_packet_msg_payload_size`
  2179. - [rpc]
  2180. * All integers are encoded as strings (part of the update for Amino v0.10.1)
  2181. * `syncing` is now called `catching_up`
  2182. - [types] Update Amino to v0.10.1
  2183. * Amino is now fully proto3 compatible for the basic types
  2184. * JSON-encoded types now use the type name instead of the prefix bytes
  2185. * Integers are encoded as strings
  2186. - [crypto] Update go-crypto to v0.10.0 and merge into `crypto`
  2187. * privKey.Sign returns error.
  2188. * ed25519 address changed to the first 20-bytes of the SHA256 of the raw pubkey bytes
  2189. * `tmlibs/merkle` -> `crypto/merkle`. Uses SHA256 instead of RIPEMD160
  2190. - [tmlibs] Update to v0.9.0 and merge into `libs`
  2191. * remove `merkle` package (moved to `crypto/merkle`)
  2192. FEATURES
  2193. - [cmd] Added metrics (served under `/metrics` using a Prometheus client;
  2194. disabled by default). See the new `instrumentation` section in the config and
  2195. [metrics](https://tendermint.readthedocs.io/projects/tools/en/develop/metrics.html)
  2196. guide.
  2197. - [p2p] Add IPv6 support to peering.
  2198. - [p2p] Add `external_address` to config to allow specifying the address for
  2199. peers to dial
  2200. IMPROVEMENT
  2201. - [rpc/client] Supports https and wss now.
  2202. - [crypto] Make public key size into public constants
  2203. - [mempool] Log tx hash, not entire tx
  2204. - [abci] Merged in github.com/tendermint/abci
  2205. - [crypto] Merged in github.com/tendermint/go-crypto
  2206. - [libs] Merged in github.com/tendermint/tmlibs
  2207. - [docs] Move from .rst to .md
  2208. BUG FIXES:
  2209. - [rpc] Limit maximum number of HTTP/WebSocket connections
  2210. (`rpc.max_open_connections`) and gRPC connections
  2211. (`rpc.grpc_max_open_connections`). Check out "Running In Production" guide if
  2212. you want to increase them.
  2213. - [rpc] Limit maximum request body size to 1MB (header is limited to 1MB).
  2214. - [consensus] Fix a halting bug where `create_empty_blocks=false`
  2215. - [p2p] Fix panic in seed mode
  2216. ## 0.21.0
  2217. *June 21th, 2018*
  2218. BREAKING CHANGES
  2219. - [config] Change default ports from 4665X to 2665X. Ports over 32768 are
  2220. ephemeral and reserved for use by the kernel.
  2221. - [cmd] `unsafe_reset_all` removes the addrbook.json
  2222. IMPROVEMENT
  2223. - [pubsub] Set default capacity to 0
  2224. - [docs] Various improvements
  2225. BUG FIXES
  2226. - [consensus] Fix an issue where we don't make blocks after `fast_sync` when `create_empty_blocks=false`
  2227. - [mempool] Fix #1761 where we don't process txs if `cache_size=0`
  2228. - [rpc] Fix memory leak in Websocket (when using `/subscribe` method)
  2229. - [config] Escape paths in config - fixes config paths on Windows
  2230. ## 0.20.0
  2231. *June 6th, 2018*
  2232. This is the first in a series of breaking releases coming to Tendermint after
  2233. soliciting developer feedback and conducting security audits.
  2234. This release does not break any blockchain data structures or
  2235. protocols other than the ABCI messages between Tendermint and the application.
  2236. Applications that upgrade for ABCI v0.11.0 should be able to continue running Tendermint
  2237. v0.20.0 on blockchains created with v0.19.X
  2238. BREAKING CHANGES
  2239. - [abci] Upgrade to
  2240. [v0.11.0](https://github.com/tendermint/abci/blob/master/CHANGELOG.md#0110)
  2241. - [abci] Change Query path for filtering peers by node ID from
  2242. `p2p/filter/pubkey/<id>` to `p2p/filter/id/<id>`
  2243. ## 0.19.9
  2244. *June 5th, 2018*
  2245. BREAKING CHANGES
  2246. - [types/priv_validator] Moved to top level `privval` package
  2247. FEATURES
  2248. - [config] Collapse PeerConfig into P2PConfig
  2249. - [docs] Add quick-install script
  2250. - [docs/spec] Add table of Amino prefixes
  2251. BUG FIXES
  2252. - [rpc] Return 404 for unknown endpoints
  2253. - [consensus] Flush WAL on stop
  2254. - [evidence] Don't send evidence to peers that are behind
  2255. - [p2p] Fix memory leak on peer disconnects
  2256. - [rpc] Fix panic when `per_page=0`
  2257. ## 0.19.8
  2258. *June 4th, 2018*
  2259. BREAKING:
  2260. - [p2p] Remove `auth_enc` config option, peer connections are always auth
  2261. encrypted. Technically a breaking change but seems no one was using it and
  2262. arguably a bug fix :)
  2263. BUG FIXES
  2264. - [mempool] Fix deadlock under high load when `skip_timeout_commit=true` and
  2265. `create_empty_blocks=false`
  2266. ## 0.19.7
  2267. *May 31st, 2018*
  2268. BREAKING:
  2269. - [libs/pubsub] TagMap#Get returns a string value
  2270. - [libs/pubsub] NewTagMap accepts a map of strings
  2271. FEATURES
  2272. - [rpc] the RPC documentation is now published to https://tendermint.github.io/slate
  2273. - [p2p] AllowDuplicateIP config option to refuse connections from same IP.
  2274. - true by default for now, false by default in next breaking release
  2275. - [docs] Add docs for query, tx indexing, events, pubsub
  2276. - [docs] Add some notes about running Tendermint in production
  2277. IMPROVEMENTS:
  2278. - [consensus] Consensus reactor now receives events from a separate synchronous event bus,
  2279. which is not dependant on external RPC load
  2280. - [consensus/wal] do not look for height in older files if we've seen height - 1
  2281. - [docs] Various cleanup and link fixes
  2282. ## 0.19.6
  2283. *May 29th, 2018*
  2284. BUG FIXES
  2285. - [blockchain] Fix fast-sync deadlock during high peer turnover
  2286. BUG FIX:
  2287. - [evidence] Dont send peers evidence from heights they haven't synced to yet
  2288. - [p2p] Refuse connections to more than one peer with the same IP
  2289. - [docs] Various fixes
  2290. ## 0.19.5
  2291. *May 20th, 2018*
  2292. BREAKING CHANGES
  2293. - [rpc/client] TxSearch and UnconfirmedTxs have new arguments (see below)
  2294. - [rpc/client] TxSearch returns ResultTxSearch
  2295. - [version] Breaking changes to Go APIs will not be reflected in breaking
  2296. version change, but will be included in changelog.
  2297. FEATURES
  2298. - [rpc] `/tx_search` takes `page` (starts at 1) and `per_page` (max 100, default 30) args to paginate results
  2299. - [rpc] `/unconfirmed_txs` takes `limit` (max 100, default 30) arg to limit the output
  2300. - [config] `mempool.size` and `mempool.cache_size` options
  2301. IMPROVEMENTS
  2302. - [docs] Lots of updates
  2303. - [consensus] Only Fsync() the WAL before executing msgs from ourselves
  2304. BUG FIXES
  2305. - [mempool] Enforce upper bound on number of transactions
  2306. ## 0.19.4 (May 17th, 2018)
  2307. IMPROVEMENTS
  2308. - [state] Improve tx indexing by using batches
  2309. - [consensus, state] Improve logging (more consensus logs, fewer tx logs)
  2310. - [spec] Moved to `docs/spec` (TODO cleanup the rest of the docs ...)
  2311. BUG FIXES
  2312. - [consensus] Fix issue #1575 where a late proposer can get stuck
  2313. ## 0.19.3 (May 14th, 2018)
  2314. FEATURES
  2315. - [rpc] New `/consensus_state` returns just the votes seen at the current height
  2316. IMPROVEMENTS
  2317. - [rpc] Add stringified votes and fraction of power voted to `/dump_consensus_state`
  2318. - [rpc] Add PeerStateStats to `/dump_consensus_state`
  2319. BUG FIXES
  2320. - [cmd] Set GenesisTime during `tendermint init`
  2321. - [consensus] fix ValidBlock rules
  2322. ## 0.19.2 (April 30th, 2018)
  2323. FEATURES:
  2324. - [p2p] Allow peers with different Minor versions to connect
  2325. - [rpc] `/net_info` includes `n_peers`
  2326. IMPROVEMENTS:
  2327. - [p2p] Various code comments, cleanup, error types
  2328. - [p2p] Change some Error logs to Debug
  2329. BUG FIXES:
  2330. - [p2p] Fix reconnect to persistent peer when first dial fails
  2331. - [p2p] Validate NodeInfo.ListenAddr
  2332. - [p2p] Only allow (MaxNumPeers - MaxNumOutboundPeers) inbound peers
  2333. - [p2p/pex] Limit max msg size to 64kB
  2334. - [p2p] Fix panic when pex=false
  2335. - [p2p] Allow multiple IPs per ID in AddrBook
  2336. - [p2p] Fix before/after bugs in addrbook isBad()
  2337. ## 0.19.1 (April 27th, 2018)
  2338. Note this release includes some small breaking changes in the RPC and one in the
  2339. config that are really bug fixes. v0.19.1 will work with existing chains, and make Tendermint
  2340. easier to use and debug. With <3
  2341. BREAKING (MINOR)
  2342. - [config] Removed `wal_light` setting. If you really needed this, let us know
  2343. FEATURES:
  2344. - [networks] moved in tooling from devops repo: terraform and ansible scripts for deploying testnets !
  2345. - [cmd] Added `gen_node_key` command
  2346. BUG FIXES
  2347. Some of these are breaking in the RPC response, but they're really bugs!
  2348. - [spec] Document address format and pubkey encoding pre and post Amino
  2349. - [rpc] Lower case JSON field names
  2350. - [rpc] Fix missing entries, improve, and lower case the fields in `/dump_consensus_state`
  2351. - [rpc] Fix NodeInfo.Channels format to hex
  2352. - [rpc] Add Validator address to `/status`
  2353. - [rpc] Fix `prove` in ABCIQuery
  2354. - [cmd] MarshalJSONIndent on init
  2355. ## 0.19.0 (April 13th, 2018)
  2356. BREAKING:
  2357. - [cmd] improved `testnet` command; now it can fill in `persistent_peers` for you in the config file and much more (see `tendermint testnet --help` for details)
  2358. - [cmd] `show_node_id` now returns an error if there is no node key
  2359. - [rpc]: changed the output format for the `/status` endpoint (see https://godoc.org/github.com/tendermint/tendermint/rpc/core#Status)
  2360. Upgrade from go-wire to go-amino. This is a sweeping change that breaks everything that is
  2361. serialized to disk or over the network.
  2362. See github.com/tendermint/go-amino for details on the new format.
  2363. See `scripts/wire2amino.go` for a tool to upgrade
  2364. genesis/priv_validator/node_key JSON files.
  2365. FEATURES
  2366. - [test] docker-compose for local testnet setup (thanks Greg!)
  2367. ## 0.18.0 (April 6th, 2018)
  2368. BREAKING:
  2369. - [types] Merkle tree uses different encoding for varints (see tmlibs v0.8.0)
  2370. - [types] ValidtorSet.GetByAddress returns -1 if no validator found
  2371. - [p2p] require all addresses come with an ID no matter what
  2372. - [rpc] Listening address must contain tcp:// or unix:// prefix
  2373. FEATURES:
  2374. - [rpc] StartHTTPAndTLSServer (not used yet)
  2375. - [rpc] Include validator's voting power in `/status`
  2376. - [rpc] `/tx` and `/tx_search` responses now include the transaction hash
  2377. - [rpc] Include peer NodeIDs in `/net_info`
  2378. IMPROVEMENTS:
  2379. - [config] trim whitespace from elements of lists (like `persistent_peers`)
  2380. - [rpc] `/tx_search` results are sorted by height
  2381. - [p2p] do not try to connect to ourselves (ok, maybe only once)
  2382. - [p2p] seeds respond with a bias towards good peers
  2383. BUG FIXES:
  2384. - [rpc] fix subscribing using an abci.ResponseDeliverTx tag
  2385. - [rpc] fix tx_indexers matchRange
  2386. - [rpc] fix unsubscribing (see tmlibs v0.8.0)
  2387. ## 0.17.1 (March 27th, 2018)
  2388. BUG FIXES:
  2389. - [types] Actually support `app_state` in genesis as `AppStateJSON`
  2390. ## 0.17.0 (March 27th, 2018)
  2391. BREAKING:
  2392. - [types] WriteSignBytes -> SignBytes
  2393. IMPROVEMENTS:
  2394. - [all] renamed `dummy` (`persistent_dummy`) to `kvstore` (`persistent_kvstore`) (name "dummy" is deprecated and will not work in the next breaking release)
  2395. - [docs] note on determinism (docs/determinism.rst)
  2396. - [genesis] `app_options` field is deprecated. please rename it to `app_state` in your genesis file(s). `app_options` will not work in the next breaking release
  2397. - [p2p] dial seeds directly without potential peers
  2398. - [p2p] exponential backoff for addrs in the address book
  2399. - [p2p] mark peer as good if it contributed enough votes or block parts
  2400. - [p2p] stop peer if it sends incorrect data, msg to unknown channel, msg we did not expect
  2401. - [p2p] when `auth_enc` is true, all dialed peers must have a node ID in their address
  2402. - [spec] various improvements
  2403. - switched from glide to dep internally for package management
  2404. - [wire] prep work for upgrading to new go-wire (which is now called go-amino)
  2405. FEATURES:
  2406. - [config] exposed `auth_enc` flag to enable/disable encryption
  2407. - [config] added the `--p2p.private_peer_ids` flag and `PrivatePeerIDs` config variable (see config for description)
  2408. - [rpc] added `/health` endpoint, which returns empty result for now
  2409. - [types/priv_validator] new format and socket client, allowing for remote signing
  2410. BUG FIXES:
  2411. - [consensus] fix liveness bug by introducing ValidBlock mechanism
  2412. ## 0.16.0 (February 20th, 2018)
  2413. BREAKING CHANGES:
  2414. - [config] use $TMHOME/config for all config and json files
  2415. - [p2p] old `--p2p.seeds` is now `--p2p.persistent_peers` (persistent peers to which TM will always connect to)
  2416. - [p2p] now `--p2p.seeds` only used for getting addresses (if addrbook is empty; not persistent)
  2417. - [p2p] NodeInfo: remove RemoteAddr and add Channels
  2418. - we must have at least one overlapping channel with peer
  2419. - we only send msgs for channels the peer advertised
  2420. - [p2p/conn] pong timeout
  2421. - [lite] comment out IAVL related code
  2422. FEATURES:
  2423. - [p2p] added new `/dial_peers&persistent=_` **unsafe** endpoint
  2424. - [p2p] persistent node key in `$THMHOME/config/node_key.json`
  2425. - [p2p] introduce peer ID and authenticate peers by ID using addresses like `ID@IP:PORT`
  2426. - [p2p/pex] new seed mode crawls the network and serves as a seed.
  2427. - [config] MempoolConfig.CacheSize
  2428. - [config] P2P.SeedMode (`--p2p.seed_mode`)
  2429. IMPROVEMENT:
  2430. - [p2p/pex] stricter rules in the PEX reactor for better handling of abuse
  2431. - [p2p] various improvements to code structure including subpackages for `pex` and `conn`
  2432. - [docs] new spec!
  2433. - [all] speed up the tests!
  2434. BUG FIX:
  2435. - [blockchain] StopPeerForError on timeout
  2436. - [consensus] StopPeerForError on a bad Maj23 message
  2437. - [state] flush mempool conn before calling commit
  2438. - [types] fix priv val signing things that only differ by timestamp
  2439. - [mempool] fix memory leak causing zombie peers
  2440. - [p2p/conn] fix potential deadlock
  2441. ## 0.15.0 (December 29, 2017)
  2442. BREAKING CHANGES:
  2443. - [p2p] enable the Peer Exchange reactor by default
  2444. - [types] add Timestamp field to Proposal/Vote
  2445. - [types] add new fields to Header: TotalTxs, ConsensusParamsHash, LastResultsHash, EvidenceHash
  2446. - [types] add Evidence to Block
  2447. - [types] simplify ValidateBasic
  2448. - [state] updates to support changes to the header
  2449. - [state] Enforce <1/3 of validator set can change at a time
  2450. FEATURES:
  2451. - [state] Send indices of absent validators and addresses of byzantine validators in BeginBlock
  2452. - [state] Historical ConsensusParams and ABCIResponses
  2453. - [docs] Specification for the base Tendermint data structures.
  2454. - [evidence] New evidence reactor for gossiping and managing evidence
  2455. - [rpc] `/block_results?height=X` returns the DeliverTx results for a given height.
  2456. IMPROVEMENTS:
  2457. - [consensus] Better handling of corrupt WAL file
  2458. BUG FIXES:
  2459. - [lite] fix race
  2460. - [state] validate block.Header.ValidatorsHash
  2461. - [p2p] allow seed addresses to be prefixed with eg. `tcp://`
  2462. - [p2p] use consistent key to refer to peers so we dont try to connect to existing peers
  2463. - [cmd] fix `tendermint init` to ignore files that are there and generate files that aren't.
  2464. ## 0.14.0 (December 11, 2017)
  2465. BREAKING CHANGES:
  2466. - consensus/wal: removed separator
  2467. - rpc/client: changed Subscribe/Unsubscribe/UnsubscribeAll funcs signatures to be identical to event bus.
  2468. FEATURES:
  2469. - new `tendermint lite` command (and `lite/proxy` pkg) for running a light-client RPC proxy.
  2470. NOTE it is currently insecure and its APIs are not yet covered by semver
  2471. IMPROVEMENTS:
  2472. - rpc/client: can act as event bus subscriber (See https://github.com/tendermint/tendermint/issues/945).
  2473. - p2p: use exponential backoff from seconds to hours when attempting to reconnect to persistent peer
  2474. - config: moniker defaults to the machine's hostname instead of "anonymous"
  2475. BUG FIXES:
  2476. - p2p: no longer exit if one of the seed addresses is incorrect
  2477. ## 0.13.0 (December 6, 2017)
  2478. BREAKING CHANGES:
  2479. - abci: update to v0.8 using gogo/protobuf; includes tx tags, vote info in RequestBeginBlock, data.Bytes everywhere, use int64, etc.
  2480. - types: block heights are now `int64` everywhere
  2481. - types & node: EventSwitch and EventCache have been replaced by EventBus and EventBuffer; event types have been overhauled
  2482. - node: EventSwitch methods now refer to EventBus
  2483. - rpc/lib/types: RPCResponse is no longer a pointer; WSRPCConnection interface has been modified
  2484. - rpc/client: WaitForOneEvent takes an EventsClient instead of types.EventSwitch
  2485. - rpc/client: Add/RemoveListenerForEvent are now Subscribe/Unsubscribe
  2486. - rpc/core/types: ResultABCIQuery wraps an abci.ResponseQuery
  2487. - rpc: `/subscribe` and `/unsubscribe` take `query` arg instead of `event`
  2488. - rpc: `/status` returns the LatestBlockTime in human readable form instead of in nanoseconds
  2489. - mempool: cached transactions return an error instead of an ABCI response with BadNonce
  2490. FEATURES:
  2491. - rpc: new `/unsubscribe_all` WebSocket RPC endpoint
  2492. - rpc: new `/tx_search` endpoint for filtering transactions by more complex queries
  2493. - p2p/trust: new trust metric for tracking peers. See ADR-006
  2494. - config: TxIndexConfig allows to set what DeliverTx tags to index
  2495. IMPROVEMENTS:
  2496. - New asynchronous events system using `tmlibs/pubsub`
  2497. - logging: Various small improvements
  2498. - consensus: Graceful shutdown when app crashes
  2499. - tests: Fix various non-deterministic errors
  2500. - p2p: more defensive programming
  2501. BUG FIXES:
  2502. - consensus: fix panic where prs.ProposalBlockParts is not initialized
  2503. - p2p: fix panic on bad channel
  2504. ## 0.12.1 (November 27, 2017)
  2505. BUG FIXES:
  2506. - upgrade tmlibs dependency to enable Windows builds for Tendermint
  2507. ## 0.12.0 (October 27, 2017)
  2508. BREAKING CHANGES:
  2509. - rpc/client: websocket ResultsCh and ErrorsCh unified in ResponsesCh.
  2510. - rpc/client: ABCIQuery no longer takes `prove`
  2511. - state: remove GenesisDoc from state.
  2512. - consensus: new binary WAL format provides efficiency and uses checksums to detect corruption
  2513. - use scripts/wal2json to convert to json for debugging
  2514. FEATURES:
  2515. - new `Verifiers` pkg contains the tendermint light-client library (name subject to change)!
  2516. - rpc: `/genesis` includes the `app_options` .
  2517. - rpc: `/abci_query` takes an additional `height` parameter to support historical queries.
  2518. - rpc/client: new ABCIQueryWithOptions supports options like `trusted` (set false to get a proof) and `height` to query a historical height.
  2519. IMPROVEMENTS:
  2520. - rpc: `/genesis` result includes `app_options`
  2521. - rpc/lib/client: add jitter to reconnects.
  2522. - rpc/lib/types: `RPCError` satisfies the `error` interface.
  2523. BUG FIXES:
  2524. - rpc/client: fix ws deadlock after stopping
  2525. - blockchain: fix panic on AddBlock when peer is nil
  2526. - mempool: fix sending on TxsAvailable when a tx has been invalidated
  2527. - consensus: dont run WAL catchup if we fast synced
  2528. ## 0.11.1 (October 10, 2017)
  2529. IMPROVEMENTS:
  2530. - blockchain/reactor: respondWithNoResponseMessage for missing height
  2531. BUG FIXES:
  2532. - rpc: fixed client WebSocket timeout
  2533. - rpc: client now resubscribes on reconnection
  2534. - rpc: fix panics on missing params
  2535. - rpc: fix `/dump_consensus_state` to have normal json output (NOTE: technically breaking, but worth a bug fix label)
  2536. - types: fixed out of range error in VoteSet.addVote
  2537. - consensus: fix wal autofile via https://github.com/tendermint/tmlibs/blob/master/CHANGELOG.md#032-october-2-2017
  2538. ## 0.11.0 (September 22, 2017)
  2539. BREAKING:
  2540. - genesis file: validator `amount` is now `power`
  2541. - abci: Info, BeginBlock, InitChain all take structs
  2542. - rpc: various changes to match JSONRPC spec (http://www.jsonrpc.org/specification), including breaking ones:
  2543. - requests that previously returned HTTP code 4XX now return 200 with an error code in the JSONRPC.
  2544. - `rpctypes.RPCResponse` uses new `RPCError` type instead of `string`.
  2545. - cmd: if there is no genesis, exit immediately instead of waiting around for one to show.
  2546. - types: `Signer.Sign` returns an error.
  2547. - state: every validator set change is persisted to disk, which required some changes to the `State` structure.
  2548. - p2p: new `p2p.Peer` interface used for all reactor methods (instead of `*p2p.Peer` struct).
  2549. FEATURES:
  2550. - rpc: `/validators?height=X` allows querying of validators at previous heights.
  2551. - rpc: Leaving the `height` param empty for `/block`, `/validators`, and `/commit` will return the value for the latest height.
  2552. IMPROVEMENTS:
  2553. - docs: Moved all docs from the website and tools repo in, converted to `.rst`, and cleaned up for presentation on `tendermint.readthedocs.io`
  2554. BUG FIXES:
  2555. - fix WAL openning issue on Windows
  2556. ## 0.10.4 (September 5, 2017)
  2557. IMPROVEMENTS:
  2558. - docs: Added Slate docs to each rpc function (see rpc/core)
  2559. - docs: Ported all website docs to Read The Docs
  2560. - config: expose some p2p params to tweak performance: RecvRate, SendRate, and MaxMsgPacketPayloadSize
  2561. - rpc: Upgrade the websocket client and server, including improved auto reconnect, and proper ping/pong
  2562. BUG FIXES:
  2563. - consensus: fix panic on getVoteBitArray
  2564. - consensus: hang instead of panicking on byzantine consensus failures
  2565. - cmd: dont load config for version command
  2566. ## 0.10.3 (August 10, 2017)
  2567. FEATURES:
  2568. - control over empty block production:
  2569. - new flag, `--consensus.create_empty_blocks`; when set to false, blocks are only created when there are txs or when the AppHash changes.
  2570. - new config option, `consensus.create_empty_blocks_interval`; an empty block is created after this many seconds.
  2571. - in normal operation, `create_empty_blocks = true` and `create_empty_blocks_interval = 0`, so blocks are being created all the time (as in all previous versions of tendermint). The number of empty blocks can be reduced by increasing `create_empty_blocks_interval` or by setting `create_empty_blocks = false`.
  2572. - new `TxsAvailable()` method added to Mempool that returns a channel which fires when txs are available.
  2573. - new heartbeat message added to consensus reactor to notify peers that a node is waiting for txs before entering propose step.
  2574. - rpc: Add `syncing` field to response returned by `/status`. Is `true` while in fast-sync mode.
  2575. IMPROVEMENTS:
  2576. - various improvements to documentation and code comments
  2577. BUG FIXES:
  2578. - mempool: pass height into constructor so it doesn't always start at 0
  2579. ## 0.10.2 (July 10, 2017)
  2580. FEATURES:
  2581. - Enable lower latency block commits by adding consensus reactor sleep durations and p2p flush throttle timeout to the config
  2582. IMPROVEMENTS:
  2583. - More detailed logging in the consensus reactor and state machine
  2584. - More in-code documentation for many exposed functions, especially in consensus/reactor.go and p2p/switch.go
  2585. - Improved readability for some function definitions and code blocks with long lines
  2586. ## 0.10.1 (June 28, 2017)
  2587. FEATURES:
  2588. - Use `--trace` to get stack traces for logged errors
  2589. - types: GenesisDoc.ValidatorHash returns the hash of the genesis validator set
  2590. - types: GenesisDocFromFile parses a GenesiDoc from a JSON file
  2591. IMPROVEMENTS:
  2592. - Add a Code of Conduct
  2593. - Variety of improvements as suggested by `megacheck` tool
  2594. - rpc: deduplicate tests between rpc/client and rpc/tests
  2595. - rpc: addresses without a protocol prefix default to `tcp://`. `http://` is also accepted as an alias for `tcp://`
  2596. - cmd: commands are more easily reuseable from other tools
  2597. - DOCKER: automate build/push
  2598. BUG FIXES:
  2599. - Fix log statements using keys with spaces (logger does not currently support spaces)
  2600. - rpc: set logger on websocket connection
  2601. - rpc: fix ws connection stability by setting write deadline on pings
  2602. ## 0.10.0 (June 2, 2017)
  2603. Includes major updates to configuration, logging, and json serialization.
  2604. Also includes the Grand Repo-Merge of 2017.
  2605. BREAKING CHANGES:
  2606. - Config and Flags:
  2607. - The `config` map is replaced with a [`Config` struct](https://github.com/tendermint/tendermint/blob/master/config/config.go#L11),
  2608. containing substructs: `BaseConfig`, `P2PConfig`, `MempoolConfig`, `ConsensusConfig`, `RPCConfig`
  2609. - This affects the following flags:
  2610. - `--seeds` is now `--p2p.seeds`
  2611. - `--node_laddr` is now `--p2p.laddr`
  2612. - `--pex` is now `--p2p.pex`
  2613. - `--skip_upnp` is now `--p2p.skip_upnp`
  2614. - `--rpc_laddr` is now `--rpc.laddr`
  2615. - `--grpc_laddr` is now `--rpc.grpc_laddr`
  2616. - Any configuration option now within a substract must come under that heading in the `config.toml`, for instance:
  2617. ```
  2618. [p2p]
  2619. laddr="tcp://1.2.3.4:46656"
  2620. [consensus]
  2621. timeout_propose=1000
  2622. ```
  2623. - Use viper and `DefaultConfig() / TestConfig()` functions to handle defaults, and remove `config/tendermint` and `config/tendermint_test`
  2624. - Change some function and method signatures to
  2625. - Change some [function and method signatures](https://gist.github.com/ebuchman/640d5fc6c2605f73497992fe107ebe0b) accomodate new config
  2626. - Logger
  2627. - Replace static `log15` logger with a simple interface, and provide a new implementation using `go-kit`.
  2628. See our new [logging library](https://github.com/tendermint/tmlibs/log) and [blog post](https://tendermint.com/blog/abstracting-the-logger-interface-in-go) for more details
  2629. - Levels `warn` and `notice` are removed (you may need to change them in your `config.toml`!)
  2630. - Change some [function and method signatures](https://gist.github.com/ebuchman/640d5fc6c2605f73497992fe107ebe0b) to accept a logger
  2631. - JSON serialization:
  2632. - Replace `[TypeByte, Xxx]` with `{"type": "some-type", "data": Xxx}` in RPC and all `.json` files by using `go-wire/data`. For instance, a public key is now:
  2633. ```
  2634. "pub_key": {
  2635. "type": "ed25519",
  2636. "data": "83DDF8775937A4A12A2704269E2729FCFCD491B933C4B0A7FFE37FE41D7760D0"
  2637. }
  2638. ```
  2639. - Remove type information about RPC responses, so `[TypeByte, {"jsonrpc": "2.0", ... }]` is now just `{"jsonrpc": "2.0", ... }`
  2640. - Change `[]byte` to `data.Bytes` in all serialized types (for hex encoding)
  2641. - Lowercase the JSON tags in `ValidatorSet` fields
  2642. - Introduce `EventDataInner` for serializing events
  2643. - Other:
  2644. - Send InitChain message in handshake if `appBlockHeight == 0`
  2645. - Do not include the `Accum` field when computing the validator hash. This makes the ValidatorSetHash unique for a given validator set, rather than changing with every block (as the Accum changes)
  2646. - Unsafe RPC calls are not enabled by default. This includes `/dial_seeds`, and all calls prefixed with `unsafe`. Use the `--rpc.unsafe` flag to enable.
  2647. FEATURES:
  2648. - Per-module log levels. For instance, the new default is `state:info,*:error`, which means the `state` package logs at `info` level, and everything else logs at `error` level
  2649. - Log if a node is validator or not in every consensus round
  2650. - Use ldflags to set git hash as part of the version
  2651. - Ignore `address` and `pub_key` fields in `priv_validator.json` and overwrite them with the values derrived from the `priv_key`
  2652. IMPROVEMENTS:
  2653. - Merge `tendermint/go-p2p -> tendermint/tendermint/p2p` and `tendermint/go-rpc -> tendermint/tendermint/rpc/lib`
  2654. - Update paths for grand repo merge:
  2655. - `go-common -> tmlibs/common`
  2656. - `go-data -> go-wire/data`
  2657. - All other `go-` libs, except `go-crypto` and `go-wire`, are merged under `tmlibs`
  2658. - No global loggers (loggers are passed into constructors, or preferably set with a SetLogger method)
  2659. - Return HTTP status codes with errors for RPC responses
  2660. - Limit `/blockchain_info` call to return a maximum of 20 blocks
  2661. - Use `.Wrap()` and `.Unwrap()` instead of eg. `PubKeyS` for `go-crypto` types
  2662. - RPC JSON responses use pretty printing (via `json.MarshalIndent`)
  2663. - Color code different instances of the consensus for tests
  2664. - Isolate viper to `cmd/tendermint/commands` and do not read config from file for tests
  2665. ## 0.9.2 (April 26, 2017)
  2666. BUG FIXES:
  2667. - Fix bug in `ResetPrivValidator` where we were using the global config and log (causing external consumers, eg. basecoin, to fail).
  2668. ## 0.9.1 (April 21, 2017)
  2669. FEATURES:
  2670. - Transaction indexing - txs are indexed by their hash using a simple key-value store; easily extended to more advanced indexers
  2671. - New `/tx?hash=X` endpoint to query for transactions and their DeliverTx result by hash. Optionally returns a proof of the tx's inclusion in the block
  2672. - `tendermint testnet` command initializes files for a testnet
  2673. IMPROVEMENTS:
  2674. - CLI now uses Cobra framework
  2675. - TMROOT is now TMHOME (TMROOT will stop working in 0.10.0)
  2676. - `/broadcast_tx_XXX` also returns the Hash (can be used to query for the tx)
  2677. - `/broadcast_tx_commit` also returns the height the block was committed in
  2678. - ABCIResponses struct persisted to disk before calling Commit; makes handshake replay much cleaner
  2679. - WAL uses #ENDHEIGHT instead of #HEIGHT (#HEIGHT will stop working in 0.10.0)
  2680. - Peers included via `--seeds`, under `seeds` in the config, or in `/dial_seeds` are now persistent, and will be reconnected to if the connection breaks
  2681. BUG FIXES:
  2682. - Fix bug in fast-sync where we stop syncing after a peer is removed, even if they're re-added later
  2683. - Fix handshake replay to handle validator set changes and results of DeliverTx when we crash after app.Commit but before state.Save()
  2684. ## 0.9.0 (March 6, 2017)
  2685. BREAKING CHANGES:
  2686. - Update ABCI to v0.4.0, where Query is now `Query(RequestQuery) ResponseQuery`, enabling precise proofs at particular heights:
  2687. ```
  2688. message RequestQuery{
  2689. bytes data = 1;
  2690. string path = 2;
  2691. uint64 height = 3;
  2692. bool prove = 4;
  2693. }
  2694. message ResponseQuery{
  2695. CodeType code = 1;
  2696. int64 index = 2;
  2697. bytes key = 3;
  2698. bytes value = 4;
  2699. bytes proof = 5;
  2700. uint64 height = 6;
  2701. string log = 7;
  2702. }
  2703. ```
  2704. - `BlockMeta` data type unifies its Hash and PartSetHash under a `BlockID`:
  2705. ```
  2706. type BlockMeta struct {
  2707. BlockID BlockID `json:"block_id"` // the block hash and partsethash
  2708. Header *Header `json:"header"` // The block's Header
  2709. }
  2710. ```
  2711. - `ValidatorSet.Proposer` is exposed as a field and persisted with the `State`. Use `GetProposer()` to initialize or update after validator-set changes.
  2712. - `tendermint gen_validator` command output is now pure JSON
  2713. FEATURES:
  2714. - New RPC endpoint `/commit?height=X` returns header and commit for block at height `X`
  2715. - Client API for each endpoint, including mocks for testing
  2716. IMPROVEMENTS:
  2717. - `Node` is now a `BaseService`
  2718. - Simplified starting Tendermint in-process from another application
  2719. - Better organized Makefile
  2720. - Scripts for auto-building binaries across platforms
  2721. - Docker image improved, slimmed down (using Alpine), and changed from tendermint/tmbase to tendermint/tendermint
  2722. - New repo files: `CONTRIBUTING.md`, Github `ISSUE_TEMPLATE`, `CHANGELOG.md`
  2723. - Improvements on CircleCI for managing build/test artifacts
  2724. - Handshake replay is doen through the consensus package, possibly using a mockApp
  2725. - Graceful shutdown of RPC listeners
  2726. - Tests for the PEX reactor and DialSeeds
  2727. BUG FIXES:
  2728. - Check peer.Send for failure before updating PeerState in consensus
  2729. - Fix panic in `/dial_seeds` with invalid addresses
  2730. - Fix proposer selection logic in ValidatorSet by taking the address into account in the `accumComparable`
  2731. - Fix inconcistencies with `ValidatorSet.Proposer` across restarts by persisting it in the `State`
  2732. ## 0.8.0 (January 13, 2017)
  2733. BREAKING CHANGES:
  2734. - New data type `BlockID` to represent blocks:
  2735. ```
  2736. type BlockID struct {
  2737. Hash []byte `json:"hash"`
  2738. PartsHeader PartSetHeader `json:"parts"`
  2739. }
  2740. ```
  2741. - `Vote` data type now includes validator address and index:
  2742. ```
  2743. type Vote struct {
  2744. ValidatorAddress []byte `json:"validator_address"`
  2745. ValidatorIndex int `json:"validator_index"`
  2746. Height int `json:"height"`
  2747. Round int `json:"round"`
  2748. Type byte `json:"type"`
  2749. BlockID BlockID `json:"block_id"` // zero if vote is nil.
  2750. Signature crypto.Signature `json:"signature"`
  2751. }
  2752. ```
  2753. - Update TMSP to v0.3.0, where it is now called ABCI and AppendTx is DeliverTx
  2754. - Hex strings in the RPC are now "0x" prefixed
  2755. FEATURES:
  2756. - New message type on the ConsensusReactor, `Maj23Msg`, for peers to alert others they've seen a Maj23,
  2757. in order to track and handle conflicting votes intelligently to prevent Byzantine faults from causing halts:
  2758. ```
  2759. type VoteSetMaj23Message struct {
  2760. Height int
  2761. Round int
  2762. Type byte
  2763. BlockID types.BlockID
  2764. }
  2765. ```
  2766. - Configurable block part set size
  2767. - Validator set changes
  2768. - Optionally skip TimeoutCommit if we have all the votes
  2769. - Handshake between Tendermint and App on startup to sync latest state and ensure consistent recovery from crashes
  2770. - GRPC server for BroadcastTx endpoint
  2771. IMPROVEMENTS:
  2772. - Less verbose logging
  2773. - Better test coverage (37% -> 49%)
  2774. - Canonical SignBytes for signable types
  2775. - Write-Ahead Log for Mempool and Consensus via tmlibs/autofile
  2776. - Better in-process testing for the consensus reactor and byzantine faults
  2777. - Better crash/restart testing for individual nodes at preset failure points, and of networks at arbitrary points
  2778. - Better abstraction over timeout mechanics
  2779. BUG FIXES:
  2780. - Fix memory leak in mempool peer
  2781. - Fix panic on POLRound=-1
  2782. - Actually set the CommitTime
  2783. - Actually send BeginBlock message
  2784. - Fix a liveness issues caused by Byzantine proposals/votes. Uses the new `Maj23Msg`.
  2785. ## 0.7.4 (December 14, 2016)
  2786. FEATURES:
  2787. - Enable the Peer Exchange reactor with the `--pex` flag for more resilient gossip network (feature still in development, beware dragons)
  2788. IMPROVEMENTS:
  2789. - Remove restrictions on RPC endpoint `/dial_seeds` to enable manual network configuration
  2790. ## 0.7.3 (October 20, 2016)
  2791. IMPROVEMENTS:
  2792. - Type safe FireEvent
  2793. - More WAL/replay tests
  2794. - Cleanup some docs
  2795. BUG FIXES:
  2796. - Fix deadlock in mempool for synchronous apps
  2797. - Replay handles non-empty blocks
  2798. - Fix race condition in HeightVoteSet
  2799. ## 0.7.2 (September 11, 2016)
  2800. BUG FIXES:
  2801. - Set mustConnect=false so tendermint will retry connecting to the app
  2802. ## 0.7.1 (September 10, 2016)
  2803. FEATURES:
  2804. - New TMSP connection for Query/Info
  2805. - New RPC endpoints:
  2806. - `tmsp_query`
  2807. - `tmsp_info`
  2808. - Allow application to filter peers through Query (off by default)
  2809. IMPROVEMENTS:
  2810. - TMSP connection type enforced at compile time
  2811. - All listen/client urls use a "tcp://" or "unix://" prefix
  2812. BUG FIXES:
  2813. - Save LastSignature/LastSignBytes to `priv_validator.json` for recovery
  2814. - Fix event unsubscribe
  2815. - Fix fastsync/blockchain reactor
  2816. ## 0.7.0 (August 7, 2016)
  2817. BREAKING CHANGES:
  2818. - Strict SemVer starting now!
  2819. - Update to ABCI v0.2.0
  2820. - Validation types now called Commit
  2821. - NewBlock event only returns the block header
  2822. FEATURES:
  2823. - TMSP and RPC support TCP and UNIX sockets
  2824. - Addition config options including block size and consensus parameters
  2825. - New WAL mode `cswal_light`; logs only the validator's own votes
  2826. - New RPC endpoints:
  2827. - for starting/stopping profilers, and for updating config
  2828. - `/broadcast_tx_commit`, returns when tx is included in a block, else an error
  2829. - `/unsafe_flush_mempool`, empties the mempool
  2830. IMPROVEMENTS:
  2831. - Various optimizations
  2832. - Remove bad or invalidated transactions from the mempool cache (allows later duplicates)
  2833. - More elaborate testing using CircleCI including benchmarking throughput on 4 digitalocean droplets
  2834. BUG FIXES:
  2835. - Various fixes to WAL and replay logic
  2836. - Various race conditions
  2837. ## PreHistory
  2838. Strict versioning only began with the release of v0.7.0, in late summer 2016.
  2839. The project itself began in early summer 2014 and was workable decentralized cryptocurrency software by the end of that year.
  2840. Through the course of 2015, in collaboration with Eris Industries (now Monax Industries),
  2841. many additional features were integrated, including an implementation from scratch of the Ethereum Virtual Machine.
  2842. That implementation now forms the heart of [Burrow](https://github.com/hyperledger/burrow).
  2843. In the later half of 2015, the consensus algorithm was upgraded with a more asynchronous design and a more deterministic and robust implementation.
  2844. By late 2015, frustration with the difficulty of forking a large monolithic stack to create alternative cryptocurrency designs led to the
  2845. invention of the Application Blockchain Interface (ABCI), then called the Tendermint Socket Protocol (TMSP).
  2846. The Ethereum Virtual Machine and various other transaction features were removed, and Tendermint was whittled down to a core consensus engine
  2847. driving an application running in another process.
  2848. The ABCI interface and implementation were iterated on and improved over the course of 2016,
  2849. until versioned history kicked in with v0.7.0.