Skip to content

*: v1.11.0-rc3 - #4651

Merged
KaloyanTanev merged 13 commits into
main-v1.11from
kalo/v1.11.0-rc3
Aug 19, 2026
Merged

*: v1.11.0-rc3#4651
KaloyanTanev merged 13 commits into
main-v1.11from
kalo/v1.11.0-rc3

Conversation

@KaloyanTanev

Copy link
Copy Markdown
Collaborator

As per the title

category: misc
ticket: none

KaloyanTanev and others added 13 commits August 19, 2026 16:30
* app/log: fix slog handler panic on named types

Stringify all slog values via fmt.Sprint instead of using
zapcore.ReflectType, which panics in the logfmt encoder on
named types like protocol.ID. Add a recover guard in Handle
so future encoding panics drop the log line instead of
crashing the process.

* app/log: log slog handler panics through charon logger

Route the recover output through Error() instead of raw
stderr so it appears in Loki and structured log output.
Also fix test comment accuracy and add bool assertion.

* app/log: add nested recover for slog panic logging

Wrap the Error() call in the recover handler with its own
defer/recover so that if the structured logger itself panics
we fall back to stderr instead of crashing.
* core/validatorapi: preserve SyncCommitteeSelections response order

Build the response by iterating the original request slice instead of
the internal Go map, so response[i] corresponds to request[i]. Prysm
matches aggregated selection proofs to requests by array index; random
map iteration attached proofs to wrong subcommittees, causing
"signature not verified" 500s on submit_contribution_and_proofs.

* core/validatorapi: clone ValidatorSetA in ordering test

Avoid mutating shared package-level map state.
* dkg: validate cluster definition threshold

Reject cluster definitions with a threshold below 2 or above the number
of operators, and log a warning when the threshold differs from the
recommended ceil(2n/3) value. Previously charon dkg ran the ceremony
silently with any threshold, unlike charon create dkg which validates
and warns.

category: bug
ticket: none

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* app/log: make ForT log initializers safe and restorable

Wrap the test write syncer with zapcore.Lock and restore the previous
global logger on test cleanup. Previously Init*ForT replaced the global
logger permanently, so tests running afterwards in the same package
wrote to the test buffer, racing on unsynchronized writers when logging
concurrently (caught by CI in dkg TestFrostDKG after TestCheckThreshold).
Reject cluster definitions containing operators whose ENRs encode the
same public key. Peers previously deduplicated operators by ENR string
only, so distinct ENRs sharing a key (and thus a peer ID) passed
verification and collapsed the peer index map built during DKG setup,
causing an index out-of-range panic in newFrostP2P.

category: bug
ticket: none
Validate the parsed deposit amounts instead of the zero-valued named
return in the v1.8, v1.9 and v1.10-11 definition unmarshalers. The
checks called VerifyDepositAmounts on the empty named return value, so
they always passed and definitions with invalid deposit amounts
unmarshaled without error. The v1.10-11 unmarshaler now also passes the
parsed compounding flag.

category: bug
ticket: none
* dkg/bcast: bind broadcast signatures to cluster session

Bind reliable-broadcast signatures to the cluster session and message
ID. Previously the signed hash covered only the protobuf type URL and
value, so signatures remained valid across DKG sessions and message
IDs, allowing replay of captured messages into other ceremonies.

* dkg/bcast: propagate hash write errors
The priority protocol handler used the duty slot straight off the wire.
A cluster peer could retain a deadliner entry and a request buffer per
distinct slot, neither of which is released until the (attacker chosen)
deadline expires.

Gate received duties with core.DutyGaterFunc before allocating any
per-duty state, as parsigex and the consensus components already do.
Duties initiated locally stay ungated, they come from the scheduler.

category: bug
ticket: none

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Relay address resolution read the HTTP response body with io.ReadAll and no
size limit, using a zero-value http.Client with no timeout, in a loop that
runs for the process lifetime. A malicious or compromised configured relay
could stream an endless response and grow the heap until the node was
OOM killed.

Limit the response to 64KB, which is well above a valid ENR string or
multiaddr array, set a 10s per-attempt client timeout, and close the response
body on the non-2xx retry path where it was leaked.

category: bug
ticket: none
…in the go-dependencies group (#4644)

* build(deps): Bump google.golang.org/protobuf

Bumps the go-dependencies group with 1 update: google.golang.org/protobuf.


Updates `google.golang.org/protobuf` from 1.36.11 to 1.36.12

---
updated-dependencies:
- dependency-name: google.golang.org/protobuf
  dependency-version: 1.36.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: go-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>

* *: regenerate protobuf files for v1.36.12

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: kalo <24719519+KaloyanTanev@users.noreply.github.com>
* dkg: improved reshare logging

* Logging progression for normal DKG as well
… updates (#4648)

Bumps the go-dependencies group with 4 updates in the / directory: [github.com/stretchr/testify](https://github.com/stretchr/testify), [golang.org/x/crypto](https://github.com/golang/crypto), [golang.org/x/net](https://github.com/golang/net) and [golang.org/x/tools](https://github.com/golang/tools).


Updates `github.com/stretchr/testify` from 1.11.1 to 1.12.0
- [Release notes](https://github.com/stretchr/testify/releases)
- [Commits](stretchr/testify@v1.11.1...v1.12.0)

Updates `golang.org/x/crypto` from 0.54.0 to 0.55.0
- [Commits](golang/crypto@v0.54.0...v0.55.0)

Updates `golang.org/x/net` from 0.57.0 to 0.58.0
- [Commits](golang/net@v0.57.0...v0.58.0)

Updates `golang.org/x/text` from 0.40.0 to 0.41.0
- [Release notes](https://github.com/golang/text/releases)
- [Commits](golang/text@v0.40.0...v0.41.0)

Updates `golang.org/x/tools` from 0.48.0 to 0.49.0
- [Release notes](https://github.com/golang/tools/releases)
- [Commits](golang/tools@v0.48.0...v0.49.0)

---
updated-dependencies:
- dependency-name: github.com/stretchr/testify
  dependency-version: 1.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: golang.org/x/crypto
  dependency-version: 0.55.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: golang.org/x/net
  dependency-version: 0.58.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: golang.org/x/text
  dependency-version: 0.41.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
- dependency-name: golang.org/x/tools
  dependency-version: 0.49.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: go-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…with 1 update (#4649)

Bumps the docker-dependencies group with 1 update in the / directory: golang.
Bumps the docker-dependencies group with 1 update in the /testutil/promrated directory: golang.


Updates `golang` from 1.26.5-trixie to 1.26.6-trixie

Updates `golang` from 1.26.5-trixie to 1.26.6-trixie

Updates `golang` from 1.26.5-alpine to 1.26.6-alpine

Updates `golang` from 1.26.5-alpine to 1.26.6-alpine

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.6-trixie
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: docker-dependencies
- dependency-name: golang
  dependency-version: 1.26.6-trixie
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: docker-dependencies
- dependency-name: golang
  dependency-version: 1.26.6-alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: docker-dependencies
- dependency-name: golang
  dependency-version: 1.26.6-alpine
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: docker-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@sonarqubecloud

Copy link
Copy Markdown

@KaloyanTanev
KaloyanTanev enabled auto-merge (squash) August 19, 2026 13:34
@KaloyanTanev
KaloyanTanev disabled auto-merge August 19, 2026 13:40
@codecov

codecov Bot commented Aug 19, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 81.18812% with 19 lines in your changes missing coverage. Please review.
✅ Project coverage is 58.39%. Comparing base (0861d82) to head (caa2ab3).

Files with missing lines Patch % Lines
app/log/slog.go 25.00% 5 Missing and 1 partial ⚠️
core/validatorapi/validatorapi.go 71.42% 2 Missing and 2 partials ⚠️
dkg/bcast/impl.go 75.00% 2 Missing and 2 partials ⚠️
app/app.go 0.00% 2 Missing ⚠️
dkg/dkg.go 84.61% 1 Missing and 1 partial ⚠️
core/priority/component.go 0.00% 1 Missing ⚠️
Additional details and impacted files
@@              Coverage Diff               @@
##           main-v1.11    #4651      +/-   ##
==============================================
+ Coverage       58.18%   58.39%   +0.20%     
==============================================
  Files             247      247              
  Lines           34056    34094      +38     
==============================================
+ Hits            19816    19908      +92     
+ Misses          11765    11714      -51     
+ Partials         2475     2472       -3     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@KaloyanTanev
KaloyanTanev merged commit 80fc00f into main-v1.11 Aug 19, 2026
11 checks passed
@KaloyanTanev
KaloyanTanev deleted the kalo/v1.11.0-rc3 branch August 19, 2026 13:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants