Upgrade Notice
This minor release is for Mocha (mocha-5), built from the v10.x release branch. It includes celestia-core v0.42.3, Cosmos SDK v0.52.12, and Fibre security, storage, and reliability updates.
Release notes: All node operators upgrading from v10.2.0-mocha or an earlier version must read the v10 release notes and upgrade instructions before upgrading.
Upgrade existing nodes
Download the celestia-app and, if applicable, fibre archives for your platform and verify them against checksums.txt. For nodes already running v10, stop the node and Fibre, replace both binaries, and restart using the existing homes and database after reviewing the configuration below. Source builds require Go 1.26.6.
Nodes still on v9 must use the multiplexer celestia-app build and follow the coordinated v10 activation process in the upgrade notes. The multiplexer switches versions automatically at activation; do not use Cosmovisor. Start Fibre only after the chain reaches app version 10.
Update configuration
Run the new binary to add missing settings and documentation:
celestia-appd config sync --home ~/.celestia-app --fibre-home ~/.celestia-fibreUse your actual home directories. This updates config/config.toml and Fibre's config/server_config.toml, preserves existing values, and creates backups before changes. Missing files are skipped. Add --dry-run to preview additions. Synchronization is explicit and does not run on startup; app.toml must still be maintained separately.
Fibre signer transport
Remote signer connections now require mutual TLS by default. Configure the node's server certificate, key, and client CA, and Fibre's client certificate, key, and server CA. All three TLS fields must be configured together on each side; incomplete node TLS settings now fail startup. Follow the privval TLS guide and Fibre signing guide.
For a same-host plaintext signer, use an IP literal such as 127.0.0.1:26669 on both sides. The localhost hostname is no longer accepted as a loopback exemption by the node. Existing configurations retain their saved listener address; check that Fibre's signer address matches it.
For local development only, the explicit insecure overrides must be enabled on both the node and Fibre to use a non-loopback plaintext signer. Anyone who can reach an unprotected signing endpoint can request signatures. Application gRPC is a separate connection and remains plaintext; keep it on a trusted private network.
Other operator changes
- Fibre supports local or object storage and a configurable
min_upload_size(default 256 KiB). When switching storage backends, retain access to existing shards and the original object namespace until they are pruned. See the Fibre configuration guide. - Fibre connections rotate after approximately five minutes, with a two-minute grace period. Custom clients must reconnect and handle interrupted requests.
- The SDK store can recover an incomplete IAVL commit on restart. Try the updated binary before a manual rollback; this is not a general database-corruption repair.
- Genesis exports now preserve validator provider registrations and all zkISM message IDs. Regenerate exports intended for restarts or migrations if older exports omitted this data.
Supported operating systems
See the release README.
- Tested in CI: Ubuntu 24.04 LTS on x86_64.
- Prebuilt binaries: Linux and macOS,
amd64andarm64. arm64 binaries are cross-compiled and are not executed in CI. - Minimum glibc: 2.38 for Linux multiplexer builds. Ubuntu 22.04 and older are unsupported for these builds.
- Changes since the previous release: none.
What's Changed
- fix: bump embedded v9 binary to v9.0.8 (v10.x) by @rach-id in #7910
- chore: update embedded v3, v6, and v7 releases (v10.x) by @rach-id in #7912
- fix: update Corto genesis checksum (v10.x) by @rach-id in #7941
- feat(fibre): add validator-local minimum upload size (backport #7944) by @mergify[bot] in #7948
- fix(valaddr): preserve provider registry in genesis exports (backport #7969) by @mergify[bot] in #7970
- feat(fibre): Introduce ability to use object storage for storing blob shards (backport #7808) by @mergify[bot] in #7972
- fix(fibre): log missing blob shards at debug level (backport #7975) by @mergify[bot] in #7990
- feat(fibre): export the time of the last successful shard upload (backport #8013) by @mergify[bot] in #8014
- feat(fibre)!: support mTLS for the fibre signer gRPC connection (backport #7842) by @mergify[bot] in #8042
- chore: extend config sync to Fibre (backport #8039) by @mergify[bot] in #8046
- fix(fibre): cap gRPC connection age so stalled streams free slots (backport #8024) by @mergify[bot] in #8055
- fix(zkism): export all genesis messages per ISM (backport #7946) by @mergify[bot] in #8053
- fix(fibre): apply on-chain promise validation before signing (backport #8021) by @mergify[bot] in #8050
- fix(multiplexer): don't forward unsupported start flags to embedded binaries (backport #7991) by @mergify[bot] in #8054
- fix(deps): bump cosmos-sdk to v0.52.12 and store to v1.1.3-celestia.3 (backport #7995) by @mergify[bot] in #8051
- fix(fibre): retain cached connections during active requests (backport #7938) by @mergify[bot] in #8052
- chore(deps): bump celestia-core to v0.42.3 (backport #8058) by @mergify[bot] in #8059
Full Changelog: v10.2.0-mocha...v10.4.0-mocha