github celestiaorg/celestia-core v0.42.3

3 hours ago

Hardens privval gRPC signing, block and proof validation, and RPC resource limits. Partial signer TLS settings now fail at startup. For plaintext loopback signers, use an IP literal such as 127.0.0.1; the localhost hostname now requires mutual TLS or priv_validator_grpc_allow_insecure = true. See the TLS guide.

What's Changed

  • fix(privval): reject SignRawBytes for other chain IDs (backport #3374) by @mergify[bot] in #3405
  • fix(config)!: don't treat localhost hostname as loopback for privval gRPC (backport #3379) by @mergify[bot] in #3406
  • fix(consensus/propagation): reject WantParts bit arrays larger than the max part count (backport #3344) by @mergify[bot] in #3407
  • fix(types): validate commit BlockID in Commit.ValidateBasic (backport #3350) by @mergify[bot] in #3409
  • fix(types): reject duplicate validator addresses in ValidatorSetFromExistingValidators (backport #3351) by @mergify[bot] in #3410
  • fix(types): validate share proof entries before using them (backport #3352) by @mergify[bot] in #3411
  • fix(light/rpc): bind hash-selected responses to the requested hash (backport #3357) by @mergify[bot] in #3412
  • fix(rpc/core): gate genesis routes behind the heavy-request budget (backport #3399) by @mergify[bot] in #3413
  • fix(rpc/core): enforce max query length in block_search (backport #3349) by @mergify[bot] in #3414
  • fix(mempool/cat): guard against zero total gas in txSet aggregation (backport #3355) by @mergify[bot] in #3415
  • fix(rpc/jsonrpc): cap JSON-RPC client response body size (backport #3356) by @mergify[bot] in #3416
  • fix(types): bind row proof Merkle indexes to the claimed rows (backport #3345) by @mergify[bot] in #3408
  • fix(privval): cap connections and handshake time on the gRPC server (backport #3380) by @mergify[bot] in #3403
  • fix(privval): reject partial gRPC TLS config at startup (backport #3404) by @mergify[bot] in #3417

Full Changelog: v0.42.2...v0.42.3

Don't miss a new celestia-core release

NewReleases is sending notifications on new releases.