Changed
- The block ingestor no longer exits when
getbestblockhashfails. A single
failed call (for example HTTP 429 "Too many connections" from a loaded
zebrad or zakura backend) used to callLog.Fatal, dropping every
in-flight client stream; replicas sharing one backend then exited and
reconnected together, adding to the overload. It now logs a warning and
retries with a capped exponential backoff (1s to 30s), raises the log to
Error after 5 minutes of continuous failures, and logs once when the RPC
recovers. Malformed replies stay fatal. (#604) - The Docker image is built in a separate stage and ships only the static
binary ondebian:13-slim(plusca-certificates), instead of the full
golang:1.25build image. The image drops from 1.9 GB to 193 MB and from
1890 to 135 scanner findings. The uid 2002lightwalletduser, data
directory ownership,/bin/bashand entrypoint are unchanged. The runtime
image no longer containscurl,git,perlor the Go toolchain.
Added
- Gauge
lightwalletd_getbestblockhash_last_success_timestamp_seconds, the
time of the last successfulgetbestblockhash. Since failures are now
retried instead of exiting, a lightwalletd whose backend keeps failing
serves a stale tip; this lets operators alert on it. (#605)
Security
golang.org/x/textto v0.41.0 (CVE-2026-56852, denial of service via
invalid UTF-8).golang.org/x/netto v0.57.0 (CVE-2026-46600, denial of service in
dns/dnsmessage).golang.org/x/cryptoto v0.55.0 (CVE-2026-56854). GO-2026-5932
(x/crypto/openpgpunmaintained) remains; it has no fixed version and
lightwalletd does not import the package directly.google.golang.org/grpcto v1.83.2.
Fixed
- CI: the release step that mirrors the image to
zodlinc/lightwalletd
had never completed; it now authenticates to the destination only and
usescrane copycorrectly.