What's Changed
- [F15] refactor: diff bootstrap server and client message size limits by @Leo-Besancon in #4973
- [f72] gRPC get_blocks Enforces Incorrect Request Limit by @modship in #5123
- [F69] gRPC datastore entry queries silently drop malformed filters by @modship in #5124
- [F70] gRPC Read-Only Calls Ignore Provided Call Coins by @modship in #5129
- [F74] gRPC new_blocks silently skips lagged blocks by @modship in #5137
- [f92] fix balance underflow error msg by @peterjah in #5138
- [F4] JSON-RPC reports send failure after local pool admission by @modship in #5142
- [F71] Block slot-range filter caps by @modship in #5128
- feat: skip interpolation of first cycle if already completed by @Leo-Besancon in #5140
- [F60] make trace and transfer for slot written atomically by @peterjah in #5136
- [F93] (cache) reorder save_module to check lru_cache first by @peterjah in #5130
- [F108] add locally produced blocks to checked_headers by @peterjah in #5131
- ci: drop macOS from full test matrix by @damip in #5144
- fix(protocol): don't terminate retrieval threads on messages with trailing bytes (DoS) by @damip in #5105
- fix(protocol): don't panic on startup when initial peer set exceeds channel capacity by @damip in #5104
- fix(protocol): use matching channel-capacity config for block retrieval/propagation channels by @damip in #5101
- [F39] filter out readonly execute from cache-import block by @peterjah in #5133
- [F75] gRPC operation stream subscribes before handshake by @modship in #5139
- [F94] enforce max_module_length when loading temp module by @peterjah in #5134
- Fix rust-analyzer through rust-toolchain.toml by @Leo-Besancon in #5151
- [F101] make BootstrapPeers serialization canonical by sorting listeners by @peterjah in #5158
- [f123] fix O(n) prune scan in operation propagation by tracking a run… by @peterjah in #5156
- [f132] make Announcement::new listeners map match its signed payload by @peterjah in #5157
- [F61] Add ExecutionController::get_slot_abi_call_stack_and_transfers by @peterjah in #5135
- fix(grpc): avoid panic on zero throughput interval by @damip in #5080
- fix(ledger): validate key version and bounds-check prefix skip in KeyDeserializer by @damip in #5090
- fix(wallet): scope Wallet::save cleanup to managed wallet files only by @damip in #5091
- fix(event-cache): don't lose stop signal when a final batch is queued by @damip in #5094
- fix(bootstrap): keep ACL refresher alive when a list file fails to reload by @damip in #5096
- fix(bootstrap): canonicalize IPs on white/black list mutations by @damip in #5097
- fix(protocol): consume default outbound slot on dial success, not failure by @damip in #5102
- fix(execution): cancel worker-local readonly queue on shutdown by @damip in #5110
- [F50] Failed Read-Only Execution Can Leak Stale Execution Context by @modship in #5145
- fix(wallet): verify decrypted keypair matches declared address on load by @damip in #5092
- [F1] Apply the default 50-staker page whenever get_largest_stakers om… by @peterjah in #5163
- [F78] bind slot transfers to the trace broadcast event to avoid hybri… by @peterjah in #5162
- [F14] bound bootstrap update-section length and fold updates directly… by @peterjah in #5164
- [F143] Clone peernet send channels so send_to_peer can serialize with… by @peterjah in #5161
- [F5] [F6] bound the bootstrap resume cursor with max_consensus_block_ids i… by @peterjah in #5169
- 5018 f79 grpc send operations underestimates smart contract operation gas accepting operations exceeding the block gas limit by @peterjah in #5170
- docs(execution): record that async gas intentionally absorbs unused b… by @peterjah in #5171
- docs(execution): note that transactions can credit deployed SC addres… by @peterjah in #5172
- [F130] gate operation dedup cache on successful local retention by @peterjah in #5175
- fix(bootstrap): don't spin the listener on persistent accept errors by @damip in #5095
- [F124] track each propagated operation once to keep propagation queue… by @peterjah in #5183
- [F73] refuse to start the gRPC API when enable_mtls is set without en… by @peterjah in #5181
- [F122] enforce the operation announcement deadline under a continuous… by @peterjah in #5184
- [F114] bound the per-round endorsement propagation drain with a confi… by @peterjah in #5177
- [F127][F131] time-bound per-peer operation ask state to dedupe deferr… by @peterjah in #5188
- [F107] prune expired propagation entries before insert and warn on co… by @peterjah in #5182
- [F2] enforce max_arguments on the caller-supplied operation ids in ge… by @peterjah in #5191
- [F106] ban only peers that actually sent us a block, not everyone the… by @peterjah in #5176
- [PDF8] fix endorsement pool index desync and bound conflicting endors… by @peterjah in #5178
- [F144] document that massa-sdk's certificate_store setting is ignored… by @peterjah in #5179
- [F134] filter non-routable announced peer endpoints before probing an… by @peterjah in #5203
- [F8] bound bootstrap accepts per poll cycle and cap concurrent refusa… by @peterjah in #5200
- [F10] validate the network restart metadata sent by a bootstrap serve… by @peterjah in #5201
- [F117] drop stale endorsements before signature and PoS draw verifica… by @peterjah in #5209
- [F112] mark blocks invalid when their committed operations fail conte… by @peterjah in #5206
- [F136] reject future-dated peer announcements instead of treating the… by @peterjah in #5202
- fix(protocol): ban peers sending messages with trailing bytes by @0xB19 in #5210
- [F121] cap the aggregate serialized size of operation batches on both… by @peterjah in #5204
- ci: re-enable check_gas_cost_definitions xtask by @0xB19 in #5211
- fix(grpc): gate get_slot_transfers on blockclique block to match JSO… by @peterjah in #5168
- [F118] bound conflicting endorsements per draw on the protocol retrie… by @peterjah in #5208
- [F126] mark operations known by a peer only after the announcement wa… by @peterjah in #5174
- [F119] wire the ExecuteSC bytecode bound, not the op-datastore value … by @peterjah in #5205
- [F105] enforce the block-level aggregate operations size limit when d… by @peterjah in #5207
- [F116] bound endorsement slots by an acceptance window instead of ban… by @peterjah in #5187
- [F52] bound read-only request starvation behind slot execution backlog by @peterjah in #5185
- [F111] only mark a peer as knowing a block on request-correlated or v… by @peterjah in #5223
- [F115] validate the PoS endorsement draw on the public gRPC send_endo… by @peterjah in #5219
- 5006 f53 trigger based async messages can be armed outside their validity window and miss execution on validity end by @peterjah in #5225
- [F113] enforce endorsement freshness in the propagation thread so eve… by @peterjah in #5222
- [F19] apply bounded backpressure instead of dropping consensus comman… by @peterjah in #5226
- [F27] refactor: reorder blocks_db_changed and stats_tick by @Leo-Besancon in #5195
- [F12] feat: validate parent ids consistency in ExportActiveBlock by @Leo-Besancon in #5197
- feat(sdk): TLS and mTLS support for the gRPC client by @0xB19 in #5212
- fix(execution): cancel incoming requests when the read-only queue is full by @0xB19 in #5213
- [F24] feat: discard block if we detect multistake by @Leo-Besancon in #5196
- fix(bootstrap): keep the loaded access lists when their file becomes unreadable by @0xB19 in #5214
- [F68] feat: validate slot in DeferredCallRegistryChanges deserialization by @Leo-Besancon in #5246
- [F86] feat: validate operation_merkle_root in block deserialization by @Leo-Besancon in #5247
- [F87] document and refactor Block::verify_signature by @Leo-Besancon in #5248
- [F32] fix: reject malformed keys without panicking by @Leo-Besancon in #5193
- [F28] fix: refuse bootstrap with non-final blocks by @Leo-Besancon in #5194
- [F43] Document expected behaviour: denounced validators still receive slot rewards by @Leo-Besancon in #5192
- [F99] fix: validate rng seed length at startup instead of panicking at end of cycle by @Leo-Besancon in #5190
- [F135] Ensure banned peers do not pass the handshake by @Leo-Besancon in #5148
- [F91] feat: make chain() atomic in case of error by @Leo-Besancon in #5165
- [F83] feat: batch initial ledger loading by @Leo-Besancon in #5154
- [F62] feat: add metrics to detect underfllled blocks by @Leo-Besancon in #5249
- [F13] fix premature bootstrap completion by @Leo-Besancon in #5152
- [F82] feat: ensure ledger is empty before loading initial ledger by @Leo-Besancon in #5155
- [F46] feat: lock mip_store during finalization by @Leo-Besancon in #5240
- [F22] feat: early catch of bootstrap ContainerInconsistency by @Leo-Besancon in #5235
- [F138] Update signature verification chunk_size formula by @Leo-Besancon in #5150
- [F141] feat: gate peer dials depending on allow_local_peers config by @Leo-Besancon in #5234
- [F98] feat: document allowed malleability for deferred credits serialization by @Leo-Besancon in #5218
- [F35] feat: document allowed malleability for deferred calls serialization by @Leo-Besancon in #5239
- [F89] docs: add comments regarding not rejecting unsorted datastore keys in operations by @Leo-Besancon in #5220
- [F11] feat: check blocks validity against last_start_period and parents mismatch by @Leo-Besancon in #5238
- [F29] unbounded command flood can indefinitely delay slot ticks and consensus maintenance by @peterjah in #5253
- [F41] feat: implem cumulative budget for query_state by @Leo-Besancon in #5236
- [F100] feat: validate pos cycle history is valid when loading db by @Leo-Besancon in #5216
- [F34] feat: align deferred calls ser and deser config checks by @Leo-Besancon in #5237
- [F38] transfer_coins creditting failure documentation and small refactors by @Leo-Besancon in #5256
- [F9] feat: add max elements count for bootstrap batch by @Leo-Besancon in #5198
- [F20] feat: cap consensus bootstrap client cursor on reconnect by @Leo-Besancon in #5258
- [F65] feat: prevent using stale production_stats during network-restart by @Leo-Besancon in #5215
- [F84] fix: materialize canonical ledger entry when updating missing ledger address by @Leo-Besancon in #5232
- [F57] docs: add comment adressing executed denunciations lookup order by @Leo-Besancon in #5250
- [F110] feat: reorder check of header sig before endorsement by @Leo-Besancon in #5217
- [F33] feat: drop unused in_memory effective_total_gas field by @Leo-Besancon in #5231
- [F129] feat: do not accept ops exceding max block gas by @Leo-Besancon in #5153
- [F67] fix: reset whole db before retrying bootstrap by @Leo-Besancon in #5166
- [F63] fix: update shutdown timing to contain last_start_period by @Leo-Besancon in #5186
- [F66] feat: on single_cycle network restart path, feed selector if cycle completed by @Leo-Besancon in #5229
- [F104] Deduplicates requested operation IDs before cloning/assembling responses by @peterjah in #5132
- fix(protocol): record last_success on successful connection for peer prioritization by @damip in #5103
- fix(protocol): make BlockHandler::stop tolerant of a panicked thread by @damip in #5098
- fix(serialization): reject zero-denominator ratio on deserialization by @damip in #4978
- fix(execution): enforce block-dump retention cap across restarts by @damip in #5111
- fix(protocol): re-check operation size before propagation by @damip in #5100
- [F109] forward wishlisted block headers to consensus and gate content… by @peterjah in #5221
- [F21] docs: rework list_required_active_blocks doc comment by @peterjah in #5264
- [F25] fix(consensus-worker): defer denunciation and multistake side e… by @peterjah in #5262
- [F30] fix(consensus-worker): preserve side-effect queues on downstrea… by @peterjah in #5260
- [F97] feat: keep speculative ops in pool, but hard skip them by @Leo-Besancon in #5233
- [F23] feat: sync wishlist after pruning by @Leo-Besancon in #5263
- fix(channel): only unregister channel metrics when the last receiver clone drops by @damip in #5089
- [F47] feat: use min_gas_cost as fallback for deferred calls uninitialized slots by @Leo-Besancon in #5242
- [F26] fix(consensus-worker): preserve pruned future/dep-waiting block… by @peterjah in #5261
- [F3] fix(api): treat pool in_pool lookup failures as non-fatal in get… by @peterjah in #5267
- fix(protocol): don't log peer tester socket shutdown as error when th… by @peterjah in #5269
- fix(bootstrap): reject more than one AskBootstrapPeers per bootstrap … by @peterjah in #5271
- [F40] bound query_state batch work: shared event budget, atomic reads by @bilboquet in #5266
- fix(grpc): report the matching id limit in too-many-ids error message… by @peterjah in #5270
- [F40] feat(execution): add wall-clock deadline for query_state batches (#5272) by @bilboquet in #5274
- chore(deps): bump massa-sc-runtime and massa-proto-rs by @peterjah in #5275
- feat(api): expose max_datastore_keys_query in get_status by @peterjah in #5265
- fix: update bootstrap streaming behaviour when cursor is deleted by @Leo-Besancon in #5276
- 5278 bump rust toolchain by @peterjah in #5279
- [F40] fix(execution): cap datastore keys in get_addresses_infos (#5057 point 3) by @bilboquet in #5277
- chore(deps): move mockall_wrap in-tree as massa-mockall-wrap by @peterjah in #5280
- feat(massa-client): add --url and support full JSON-RPC URLs by @peterjah in #5281
- Remove dead aggregate (de)serializers left over from pre-DB bootstrap by @bilboquet in #5282
- perf(execution): bound scan_datastore internals to the requested count by @bilboquet in #5286
- [F36] Flushed event-cache queries ignore finality-only filters by @modship in #5143
- fix(models): don't reflect rejected Amount string in deserialization error by @damip in #5078
- fix(bootstrap): keep the client→server length prefix 4 bytes wide and… by @peterjah in #5287
- fix(bootstrap): refuse servers that do not know an already-started MI… by @peterjah in #5292
- [F42] propagate the configured datastore key query cap from RPC/gRPC parsing to the scan by @peterjah in #5189
- bump rust-rocksdb and align RocksDB jemalloc dependencies by @bilboquet in #5297
- fix(factory): never produce blocks or endorsements whose production instant is already past by @peterjah in #5296
- fix(event-cache) by @modship in #5298
- fix(event-cache): keep saved events visible while the writer moves them to the cache by @peterjah in #5299
- test(execution): cover readonly context cleanup after VM errors by @bilboquet in #5301
- test(execution): cover finite query-state response budgets by @bilboquet in #5300
- Inherit package version and edition from the workspace by @peterjah in #5304
- test(execution): cover query state key and event budgets by @bilboquet in #5307
- Bump cmake crate to 0.1.55 to support Visual Studio 2026 on Windows runners by @peterjah in #5310
- Breaking changes tracking PR by @Leo-Besancon in #5125
- Allow dispatching the CD workflow on a branch to build binaries without publishing by @peterjah in #5312
- Bump cmake crate to 0.1.57 to fix the Windows BoringSSL build by @peterjah in #5314
- Build the linux arm64 release natively on ubuntu-22.04-arm by @peterjah in #5316
Full Changelog: MAIN.5.0...DEVN.30.2