NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #2590 by repository stars
Last release 5 years ago
no release in 18 months
Ships unpredictably
gaps range from 8 days to 1.4 years
Nearly every release is documented
notes for 56 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
10 years old
196 releases · first in 2016
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Tendermint 0.33.2 and earlier does not limit the number of P2P connection requests. For each p2p connection, Tendermint allocates ~0.5MB. Even though
April 6, 2020
This security release fixes:
Tendermint 0.33.2 and earlier does not limit the number of P2P connection requests. For each p2p connection, Tendermint allocates ~0.5MB. Even though this memory is garbage collected once the connection is terminated (due to duplicate IP or reaching a maximum number of inbound peers), temporary memory spikes can lead to OOM (Out-Of-Memory) exceptions.
Tendermint 0.33.3, 0.32.10, and 0.31.12 limit the total number of P2P incoming
connection requests to to p2p.max_num_inbound_peers + len(p2p.unconditional_peer_ids).
Notes:
Tendermint 0.33.2 and earlier does not reclaim activeID of a peer after it's
removed in Mempool reactor. This does not happen all the time. It only
happens when a connection fails (for any reason) before the Peer is created and
added to all reactors. RemovePeer is therefore called before AddPeer, which
leads to always growing memory (activeIDs map). The activeIDs map has a
maximum size of 65535 and the node will panic if this map reaches the maximum.
An attacker can create a lot of connection attempts (exploiting Denial of
Service 1), which ultimately will lead to the node panicking.
Tendermint 0.33.3, 0.32.10, and 0.31.12 claim activeID for a peer in InitPeer,
which is executed before MConnection is started.
Notes:
InitPeer function was added to all reactors to combat a similar issue -
#3338;All clients are recommended to upgrade
Special thanks to fudongbai for finding and reporting this.
Friendly reminder, we have a bug bounty program.
This security release fixes a vulnerability found in the consensus package, where an attacker could construct a BlockPartMessage message in such a way…
October 18, 2019
This security release fixes a vulnerability found in the consensus package,
where an attacker could construct a BlockPartMessage message in such a way
that it will lead to consensus failure. A few similar issues have been
identified and fixed here.
All clients are recommended to upgrade
Special thanks to elvishacker for finding and reporting this.
Friendly reminder, we have a bug bounty program.
WAL#Write and WAL#WriteSync to return an error if
they fail to write a messageThe previous patch was insufficient because the attacker could still find a way to submit a nil pubkey by constructing a PubKeyMultisigThreshold pubke
October 8, 2019
The previous patch was insufficient because the attacker could still find a way
to submit a nil pubkey by constructing a PubKeyMultisigThreshold pubkey
with nil subpubkeys for example.
This release provides multiple fixes, which include recovering from panics when
accepting new peers and only allowing ed25519 pubkeys.
All clients are recommended to upgrade
Special thanks to fudongbai for pointing this out.
Friendly reminder, we have a bug bounty program.
This release fixes a major security vulnerability found in the p2p package. All clients are recommended to upgrade. See TODO for details.
September 30, 2019
This release fixes a major security vulnerability found in the p2p package.
All clients are recommended to upgrade. See TODO for
details.
Special thanks to fudongbai for discovering and reporting this issue.
Friendly reminder, we have a bug bounty program.
This releases fixes one bug in the PEX reactor and adds a recover to the Go's ABCI server, which allows it to properly cleanup.
July 29, 2019
This releases fixes one bug in the PEX reactor and adds a recover to the Go's
ABCI server, which allows it to properly cleanup.
server/socket_server.go to allow socket cleanup (@ruseinov)This releases fixes a regression in the mempool introduced in v0.31.6. The regression caused the invalid committed txs to be proposed in blocks over a
June 3, 2019
This releases fixes a regression in the mempool introduced in v0.31.6. The regression caused the invalid committed txs to be proposed in blocks over and over again.
[libs/common] Removed deprecated PanicSanity, PanicCrisis, PanicConsensus and PanicQ
May 31st, 2019
This release contains many fixes and improvements, primarily for p2p functionality. It also fixes a security issue in the mempool package.
With this release, Tendermint now supports boltdb, although in experimental mode. Feel free to try and report to us any findings/issues. Note also that the build tags for compiling CLevelDB have changed.
Special thanks to external contributors on this release: @guagualvcha, @james-ray, @gregdhill, @climber73, @yutianwu, @carlosflrs, @defunctzombie, @leoluk, @needkane, @CrocdileChan
PanicSanity, PanicCrisis,
PanicConsensus and PanicQMempool now an interface that lives in the mempool package.
See issue and PR for more details.Reactor#InitPeer method is added to Reactor interfaceCommit#VoteSignBytes signature was changednode.Mempool() method, which allows you to access mempool--keep-addr-book option to unsafe_reset_all cmd to not
clear the address book (@climber73)--config=<path-to-config> option to testnet cmd (@gregdhill)--hostname-suffix, --hostname and --random-monikers options to testnet
cmd for greater peer address/identity generation flexibility.AddSignatureFromPubKey errorcleveldb tag instead of gcc to compile Tendermint with CLevelDB or
use make build_c / make install_c (full instructions can be found at
https://tendermint.com/docs/introduction/install.html#compile-with-cleveldb-support)boltdb tag to compile Tendermint with bolt dbpersistent_peers list is invalid (except
when IP lookup fails)/dial_seeds & /dial_peers return errors if addresses are
incorrect (except when IP lookup fails)ResponseDeliverTx.Code == 0)RemovePeer is always called before InitPeer (upon a peer
reconnecting to our node)This release fixes a regression from v0.31.4 where, in existing chains that were upgraded, /validators could return an empty validator set. This is tr
April 16th, 2019
This release fixes a regression from v0.31.4 where, in existing chains that
were upgraded, /validators could return an empty validator set. This is true
for almost all heights, given the validator set remains the same.
Special thanks to external contributors on this release: @brapse, @guagualvcha, @dongsam, @phucc
CMap: slight optimization in Keys() and Values() (@phucc)This release fixes a regression from v0.31.3 which used the peer's SocketAddr to add the peer to the address book. This swallowed the peer's self-repo
April 12th, 2019
This release fixes a regression from v0.31.3 which used the peer's SocketAddr to add the peer to
the address book. This swallowed the peer's self-reported port which is important in case of reconnect.
It brings back NetAddress() to NodeInfo and uses it instead of SocketAddr for adding peers.
Additionally, it improves response time on the /validators or /status RPC endpoints.
As a side-effect it makes these RPC endpoint more difficult to DoS and fixes a performance degradation in ExecCommitBlock.
Also, it contains an ADR that proposes decoupling the
responsibility for peer behaviour from the p2p.Switch (by @brapse).
Special thanks to external contributors on this release: @brapse, @guagualvcha, @mydring
NetAddress() to NodeInfo and use it instead of peer's SocketAddr() when adding a peer to the PEXReactor (potential fix for #3532)/validators or /status RPC
endpoints. Before response time was growing linearly with height if no
changes were made to the validator set.ExecCommitBlock where we call
LoadValidators for each Evidence in the block.This release includes two security sensitive fixes: it ensures generated private keys are valid, and it prevents certain DNS lookups that would cause
April 1st, 2019
This release includes two security sensitive fixes: it ensures generated private keys are valid, and it prevents certain DNS lookups that would cause the node to panic if the lookup failed.
secp256k1.GenPrivKeySecp256k1 function has changed to guarantee that it returns a valid key, which means it
will return a different private key than in previous versions for the same secret.This release fixes a regression from v0.31.1 where Tendermint panics under mempool load for external ABCI apps.
March 30th, 2019
This release fixes a regression from v0.31.1 where Tendermint panics under mempool load for external ABCI apps.
Special thanks to external contributors on this release: @guagualvcha
CLI/RPC/Config
Apps
Go API
Group.Search, Group.FindLast, GroupReader.ReadLine, GroupReader.PushLine, MakeSimpleSearchFunc (@guagualvcha)Blockchain Protocol
P2P Protocol
This release contains a major improvement for the mempool that reduce the amount of sent data by about 30% (see some numbers below). It also fixes a m
March 27th, 2019
This release contains a major improvement for the mempool that reduce the amount of sent data by about 30% (see some numbers below). It also fixes a memory leak in the mempool and adds TLS support to the RPC server by providing a certificate and key in the config.
Special thanks to external contributors on this release: @brapse, @guagualvcha, @HaoyangLiu, @needkane, @TraceBundy
CLI/RPC/Config
Apps
Go API
Blockchain Protocol
P2P Protocol
rpc.tls_cert_file and rpc.tls_key_file are provided in the config (@guagualvcha)GetSelectionWithBias for addressbook (@guagualvcha)Special thanks to external contributors on this release: @danil-lashin, @guagualvcha, @siburu, @silasdavis, @srmo, @Stumble, @svenstaro
March 16th, 2019
Special thanks to external contributors on this release: @danil-lashin, @guagualvcha, @siburu, @silasdavis, @srmo, @Stumble, @svenstaro
This release is primarily about the new pubsub implementation, dubbed pubsub 2.0, and related changes,
like configurable limits on the number of active RPC subscriptions at a time (max_subscription_clients).
Pubsub 2.0 is an improved version of the older pubsub that is non-blocking and has a nicer API.
Note the improved pubsub API also resulted in some improvements to the HTTPClient interface and the API for WebSocket subscriptions.
This release also adds a configurable limit to the mempool size (max_txs_bytes, default 1GB)
and a configurable timeout for the /broadcast_tx_commit endpoint.
See the v0.31.0 Milestone for more details.
Friendly reminder, we have a bug bounty program.
CLI/RPC/Config
consensus.blocktime_iota parameterrpc.max_subscription_clientsrpc.max_subscriptions_per_client.rpc.timeout_broadcast_tx_commit in the config.EventsClient interface to reflect new pubsub/eventBus API ADR-33. This includes Subscribe, Unsubscribe, and UnsubscribeAll methods.Apps
Go API
Close() Batch to prevent memory leak when using ClevelDB. (@Stumble)StartHTTPServer / StartHTTPAndTLSServer now require a Config (use rpcserver.DefaultConfig)Blockchain Protocol
P2P Protocol
rpc.max_subscription_clients sets the maximum number of unique clients
with open subscriptionsrpc.max_subscriptions_per_clientsets the maximum number of unique
subscriptions from a given clientrpc.timeout_broadcast_tx_commit sets the time to wait for a tx to be committed during /broadcast_tx_committime_iota_ms to block's consensus parameters (not exposed to the application)/unsubscribe_all endpoint to unsubscribe from all eventsmempool.max_txs_bytes configuration value. Set to 1GB by default. The mempool's current txs_total_bytes is exposed via total_bytes field in
/num_unconfirmed_txs and /unconfirmed_txs RPC endpoints.BlockPool (@guagualvcha)testnet command's panic when creating non-validator configs (using --n flag) (@srmo)/validators and /abci_query proxy endpoints
(@guagualvcha)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release fixes a CLevelDB memory leak. It was happening because we were not closing the WriteBatch object after use. See levigo's godoc for the Cl
March 10th, 2019
This release fixes a CLevelDB memory leak. It was happening because we were not closing the WriteBatch object after use. See levigo's godoc for the Close method. Special thanks goes to @Stumble who both reported an issue in cosmos-sdk and provided a fix here.
Nothing published for this version
This release fixes a consensus halt and a DataCorruptionError after restart discovered in game_of_stakes_6. It also fixes a security issue in the p2p
February 20th, 2019
This release fixes a consensus halt and a DataCorruptionError after restart
discovered in game_of_stakes_6. It also fixes a security issue in the p2p
handshake by authenticating the NetAddress.ID of the peer we're dialing.
/net_info#peers#remote_ip format. New format spec:
show_validator when the private validator file does not exist.This release fixes yet another issue with the proposer selection algorithm. We hope it's the last one, but we won't be surprised if it's not. We plan
February 8th, 2019
This release fixes yet another issue with the proposer selection algorithm. We hope it's the last one, but we won't be surprised if it's not. We plan to one day expose the selection algorithm more directly to the application (#3285), and even to support randomness (#763). For more, see issues marked proposer-selection.
This release also includes a fix to prevent Tendermint from including the same piece of evidence in more than one block. This issue was reported by @chengwenxi in our bug bounty program.
Apps
ResponseEndBlock.ValidatorUpdates contains only one entry per pubkey.Go API
Add and Update methods from ValidatorSet in favor of new
UpdateWithChangeSet. This allows updates to be applied as a set, instead of
one at a time.Block Protocol
P2P Protocol
ResponseEndBlock.ValidatorUpdates.btcec.S256().N directly instead of hard coding a copy.Nothing published for this version
Nothing published for this version
Special thanks to external contributors on this release: @ackratos, @rickyyangz
February 7th, 2019
Special thanks to external contributors on this release: @ackratos, @rickyyangz
Note: This release contains security sensitive patches in the p2p and
crypto packages:
btcd and use the btcd/btcec library directly for
native secp256k1 signing. Note we still modify the signature encoding to
prevent malleability.go-ethereum/crypto/secp256k1 package.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Special thanks to external contributors on this release: @infinytum, @gauthamzz
January 24, 2019
Special thanks to external contributors on this release: @infinytum, @gauthamzz
This release contains two important fixes: one for p2p layer where we sometimes
were not closing connections and one for consensus layer where consensus with
no empty blocks (create_empty_blocks = false) could halt.
Friendly reminder, we have a bug bounty program.
triggered_timeout_commit in the /dump_consensus_stateNothing published for this version
Nothing published for this version
This release is primarily about making some breaking changes to the Block protocol version before Cosmos launch, and to fixing more issues in the prop…
January 21, 2019
Special thanks to external contributors on this release: @bradyjoestar, @kunaldhariwal, @gauthamzz, @hrharder
This release is primarily about making some breaking changes to the Block protocol version before Cosmos launch, and to fixing more issues in the proposer selection algorithm discovered on Cosmos testnets.
The Block protocol changes include using a standard Merkle tree format (RFC 6962), fixing some inconsistencies between field orders in Vote and Proposal structs, and constraining the hash of the ConsensusParams to include only a few fields.
The proposer selection algorithm saw significant progress, including a formal proof by @cwgoes for the base-case in Idris and a much more detailed specification (still in progress) by @ancazamfir.
Fixes to the proposer selection algorithm include normalizing the proposer priorities to mitigate the effects of large changes to the validator set. That said, we just discovered another bug, which will be fixed in the next breaking release.
While we are trying to stabilize the Block protocol to preserve compatibility with old chains, there may be some final changes yet to come before Cosmos launch as we continue to audit and test the software.
Friendly reminder, we have a bug bounty program.
CLI/RPC/Config
Apps
MaxInt64 / 8. Apps must ensure they do not return changes to the validator
set that cause this maximum to be exceeded.Go API
Blockchain Protocol
P2P Protocol
2*TotalVotingPower to mitigate unfair proposer selection
heavily preferring earlier joined validators in the case of an early bonded large validator unbondingper_page is greater than the max 100.chain_id label for all metricsNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Special thanks to external contributors on this release: @HaoyangLiu
January 18th, 2019
Special thanks to external contributors on this release: @HaoyangLiu
Friendly reminder, we have a bug bounty program.
Nothing published for this version
Special thanks to external contributors on this release: @fmauricios, @gianfelipe93, @husio, @needkane, @srmo, @yutianwu
January 16th, 2019
Special thanks to external contributors on this release: @fmauricios, @gianfelipe93, @husio, @needkane, @srmo, @yutianwu
This release is primarily about upgrades to the privval system -
separating the priv_validator.json into distinct config and data files, and
refactoring the socket validator to support reconnections.
Note: Please backup your existing priv_validator.json before using this
version.
See UPGRADING.md for more details.
CLI/RPC/Config
--proxy_app=dummy option. Use kvstore (persistent_kvstore) instead.--proxy_app=nilapp to --proxy_app=noop.allow_duplicate_ip is now set to falsepriv_validator.json into immutable (config/priv_validator_key.json) and mutable (data/priv_validator_state.json) parts (@yutianwu)PubKeyMsg into PubKeyRequest and PubKeyResponse to be consistent with other message typesApps
Go API
PrivValidator.GetAddress()Blockchain Protocol
P2P Protocol
/net_infoVersion field in build scripts (@husio)PubKeyMultisigThreshold unmarshalling into crypto.PubKey interface/tx_search when results are empty
(@gianfelipe93)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
[mempool] \#3036 Fix LRU cache by popping the least recently used item when the cache is full, not the most recently used one!
December 21st, 2018
[dep] \#3027 Revert to mainline Go crypto library, eliminating the modified bcrypt.GenerateFromPassword
December 16th, 2018
bcrypt.GenerateFromPassword[node] \#3025 Validate NodeInfo addresses on startup.
Special thanks to external contributors on this release: @danil-lashin, @hleb-albau, @james-ray, @leo-xinwang
December 15th, 2018
Special thanks to external contributors on this release: @danil-lashin, @hleb-albau, @james-ray, @leo-xinwang
UnconfirmedTxs(limit) and NumUnconfirmedTxs() methods to HTTP/Local clients (@danil-lashin)testnet command always sets addr_book_strict = falsenotifyTxsAvailable if there're txs left after committing a block, but recheck=falseSpecial thanks to external contributors on this release: @danil-lashin, @srmo
December 5th, 2018
Special thanks to external contributors on this release: @danil-lashin, @srmo
Special thanks to @dlguddus for discovering a major issue in the proposer selection algorithm.
Friendly reminder, we have a bug bounty program.
This release is primarily about fixes to the proposer selection algorithm
in preparation for the Cosmos Game of
Stakes.
It also makes use of the ConsensusParams.Validator.PubKeyTypes to restrict the
key types that can be used by validators, and removes the Heartbeat consensus
message.
CLI/RPC/Config
accum to proposer_priorityGo API
Blockchain Protocol
P2P Protocol
module=pex/net_info and the prometheus
metrics/broadcast_tx_commit: Fix "interface conversion: interface {} in nil, not EventDataTx" panic (could happen if somebody sent a tx using /broadcast_tx_commit while Tendermint was being stopped)-1.125*totalVotingPower
instead of 0, forcing them to wait before becoming the proposer. Also:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →