⚠️ Disclaimer ⚠️
This version serves as the foundation for the production release and is currently undergoing security and correctness audits.
Although extensive testing and validation have been performed, additional bugs or vulnerabilities may still be discovered. Users should evaluate the software according to their own requirements and use it at their own discretion and responsibility.
Feedback and bug reports are highly appreciated and help improve the reliability of the project.
Summary
- JumpDest soundness fixes
- Memory soundness fix
- BLAKE2b, BLAKE2s and BLAKE3f soundness fixes
- Setup versioning and compatibility validation
- Fixed host memory leak per final SNARK proof
- CI security hardening on self-hosted runners
JumpDest Soundness Fixes
This release includes important soundness fixes in the JumpDest precompile
- Fixed four soundness issues in the JumpDest precompile related to bitmap termination, empty blocks and segment boundaries.
- Added constraints ensuring that every active JumpDest block consumes data and that the final segment closes the sequence correctly.
Thanks to @amiabix for reporting this issue.
Memory Soundness Fix
This release includes important soundness fix in the memory state machine.
- Strengthened memory step validation by binding every mutable memory lane to the bus and enforcing explicit bounds on memory steps.
- Improved memory padding handling and segment-boundary validation to prevent invalid step ranges and field wrapping.
BLAKE2 and BLAKE3 Soundness Fixes
The BLAKE precompiles have been hardened against a carry-bit soundness issue in the final rotation operation.
- Fixed carry-bit binding in BLAKE2b, BLAKE2s and BLAKE3f.
- Added range constraints tying the carry bit to the actual top bit of the corresponding byte.
- Updated lookup accounting and operation costs to reflect the additional constraints.
- Strengthened output-row validation where the rotated value is written directly to memory.
Setup Versioning and Compatibility
Setup artifacts now include explicit version information to prevent incompatible proving keys from being used.
- Added setup-version metadata to generated proving keys and setup artifacts.
- Added runtime compatibility checks between the prover and the installed setup.
- Updated setup generation, installation, caching and packaging to use setup version information.
Final SNARK Memory Leak Fix
Every final SNARK proof leaked roughly 600 MiB of host memory. Reported in #596 by @antonbaliasnikov, fixed in #597.
- The final witness context destructor now releases
signalValues(~596 MiB for the ZisK final circuit),componentMemory,inputSignalAssignedand component 0's arrays, which were previously never freed. - The recursivef zkin JSON returned by
genRecursiveProofBN128is now freed through the newfree_recursivef_proof.
CI Security Hardening
The CI workflows and test environment have been hardened following a supply-chain risk on self-hosted runners, reported by @evilgensec through a security advisory https://github.com/0xPolygonHermez/zisk/security/advisories/GHSA-hcx6-xm47-gcmv.
- Pull requests from forks no longer run on self-hosted runners; they only run on GitHub-hosted runners.
- The CI test container now runs unprivileged: no
--privileged, no host cgroup namespace or host cgroup mounts. - Removed the in-container Docker daemon; CI now uses the committed
ziskfloatartifacts instead of rebuilding them in Docker.