Overview
Important
This is a recommended release for all chains. It contains a derivation fix for malformed batches that only a faulty batcher could produce, stricter handling of execution errors, an EVM update, a TLS security fix, and preimage server fixes. Run it with the kona-client v1.8.0 absolute prestates.
Other changes
Derivation
- After Holocene, kona now checks each singular batch's parent hash against the safe head, as op-node does. Previously the check always passed, so a malformed batch from a faulty batcher could make kona derive a different chain from op-node. Fault proofs are unaffected unless the batcher misbehaves (#23071)
Proof execution
- A block is now replaced with a deposit-only block (or dropped, before Holocene) only when its payload is actually invalid. Errors that do not prove the payload invalid, such as missing preimage or witness data, now stop the program instead of producing a deposit-only block, matching op-node (#23012)
- revm is updated from 41 to 42 with reth v2.5.2. This fixes state cleanup when a transaction fails during finalization and storage handling for destroyed accounts (#22495)
Host
- rustls is updated to 0.23.45 for RUSTSEC-2026-0285, where a TLS 1.3 peer could send handshake messages in plaintext that should have been encrypted. It affects kona-host's TLS connections to L1, L2 and beacon RPCs (#22898)
- In
--servermode, an I/O error on a preimage pipe no longer closes the pipe's file descriptor (#23038) - kona-host now exits with an error when the blob provider cannot be initialised, instead of continuing without it (#22791)
isSystemTxon Bedrock system deposits fetched over JSON RPC is now decoded as a boolean, so proofs over Bedrock-era blocks expect a current op-reth or op-geth endpoint (#22946)
Full Changelog: kona-host/v1.7.0...kona-host/v1.8.0
🚢 Docker Image: