*: v1.11.0-rc3 - #4651
Merged
Merged
Conversation
* app/log: fix slog handler panic on named types Stringify all slog values via fmt.Sprint instead of using zapcore.ReflectType, which panics in the logfmt encoder on named types like protocol.ID. Add a recover guard in Handle so future encoding panics drop the log line instead of crashing the process. * app/log: log slog handler panics through charon logger Route the recover output through Error() instead of raw stderr so it appears in Loki and structured log output. Also fix test comment accuracy and add bool assertion. * app/log: add nested recover for slog panic logging Wrap the Error() call in the recover handler with its own defer/recover so that if the structured logger itself panics we fall back to stderr instead of crashing.
* core/validatorapi: preserve SyncCommitteeSelections response order Build the response by iterating the original request slice instead of the internal Go map, so response[i] corresponds to request[i]. Prysm matches aggregated selection proofs to requests by array index; random map iteration attached proofs to wrong subcommittees, causing "signature not verified" 500s on submit_contribution_and_proofs. * core/validatorapi: clone ValidatorSetA in ordering test Avoid mutating shared package-level map state.
* dkg: validate cluster definition threshold Reject cluster definitions with a threshold below 2 or above the number of operators, and log a warning when the threshold differs from the recommended ceil(2n/3) value. Previously charon dkg ran the ceremony silently with any threshold, unlike charon create dkg which validates and warns. category: bug ticket: none Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * app/log: make ForT log initializers safe and restorable Wrap the test write syncer with zapcore.Lock and restore the previous global logger on test cleanup. Previously Init*ForT replaced the global logger permanently, so tests running afterwards in the same package wrote to the test buffer, racing on unsynchronized writers when logging concurrently (caught by CI in dkg TestFrostDKG after TestCheckThreshold).
Reject cluster definitions containing operators whose ENRs encode the same public key. Peers previously deduplicated operators by ENR string only, so distinct ENRs sharing a key (and thus a peer ID) passed verification and collapsed the peer index map built during DKG setup, causing an index out-of-range panic in newFrostP2P. category: bug ticket: none
Validate the parsed deposit amounts instead of the zero-valued named return in the v1.8, v1.9 and v1.10-11 definition unmarshalers. The checks called VerifyDepositAmounts on the empty named return value, so they always passed and definitions with invalid deposit amounts unmarshaled without error. The v1.10-11 unmarshaler now also passes the parsed compounding flag. category: bug ticket: none
* dkg/bcast: bind broadcast signatures to cluster session Bind reliable-broadcast signatures to the cluster session and message ID. Previously the signed hash covered only the protobuf type URL and value, so signatures remained valid across DKG sessions and message IDs, allowing replay of captured messages into other ceremonies. * dkg/bcast: propagate hash write errors
The priority protocol handler used the duty slot straight off the wire. A cluster peer could retain a deadliner entry and a request buffer per distinct slot, neither of which is released until the (attacker chosen) deadline expires. Gate received duties with core.DutyGaterFunc before allocating any per-duty state, as parsigex and the consensus components already do. Duties initiated locally stay ungated, they come from the scheduler. category: bug ticket: none Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Relay address resolution read the HTTP response body with io.ReadAll and no size limit, using a zero-value http.Client with no timeout, in a loop that runs for the process lifetime. A malicious or compromised configured relay could stream an endless response and grow the heap until the node was OOM killed. Limit the response to 64KB, which is well above a valid ENR string or multiaddr array, set a 10s per-attempt client timeout, and close the response body on the non-2xx retry path where it was leaked. category: bug ticket: none
…in the go-dependencies group (#4644) * build(deps): Bump google.golang.org/protobuf Bumps the go-dependencies group with 1 update: google.golang.org/protobuf. Updates `google.golang.org/protobuf` from 1.36.11 to 1.36.12 --- updated-dependencies: - dependency-name: google.golang.org/protobuf dependency-version: 1.36.12 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: go-dependencies ... Signed-off-by: dependabot[bot] <support@github.com> * *: regenerate protobuf files for v1.36.12 --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: kalo <24719519+KaloyanTanev@users.noreply.github.com>
* dkg: improved reshare logging * Logging progression for normal DKG as well
… updates (#4648) Bumps the go-dependencies group with 4 updates in the / directory: [github.com/stretchr/testify](https://github.com/stretchr/testify), [golang.org/x/crypto](https://github.com/golang/crypto), [golang.org/x/net](https://github.com/golang/net) and [golang.org/x/tools](https://github.com/golang/tools). Updates `github.com/stretchr/testify` from 1.11.1 to 1.12.0 - [Release notes](https://github.com/stretchr/testify/releases) - [Commits](stretchr/testify@v1.11.1...v1.12.0) Updates `golang.org/x/crypto` from 0.54.0 to 0.55.0 - [Commits](golang/crypto@v0.54.0...v0.55.0) Updates `golang.org/x/net` from 0.57.0 to 0.58.0 - [Commits](golang/net@v0.57.0...v0.58.0) Updates `golang.org/x/text` from 0.40.0 to 0.41.0 - [Release notes](https://github.com/golang/text/releases) - [Commits](golang/text@v0.40.0...v0.41.0) Updates `golang.org/x/tools` from 0.48.0 to 0.49.0 - [Release notes](https://github.com/golang/tools/releases) - [Commits](golang/tools@v0.48.0...v0.49.0) --- updated-dependencies: - dependency-name: github.com/stretchr/testify dependency-version: 1.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: golang.org/x/crypto dependency-version: 0.55.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: golang.org/x/net dependency-version: 0.58.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: golang.org/x/text dependency-version: 0.41.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies - dependency-name: golang.org/x/tools dependency-version: 0.49.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: go-dependencies ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…with 1 update (#4649) Bumps the docker-dependencies group with 1 update in the / directory: golang. Bumps the docker-dependencies group with 1 update in the /testutil/promrated directory: golang. Updates `golang` from 1.26.5-trixie to 1.26.6-trixie Updates `golang` from 1.26.5-trixie to 1.26.6-trixie Updates `golang` from 1.26.5-alpine to 1.26.6-alpine Updates `golang` from 1.26.5-alpine to 1.26.6-alpine --- updated-dependencies: - dependency-name: golang dependency-version: 1.26.6-trixie dependency-type: direct:production update-type: version-update:semver-patch dependency-group: docker-dependencies - dependency-name: golang dependency-version: 1.26.6-trixie dependency-type: direct:production update-type: version-update:semver-patch dependency-group: docker-dependencies - dependency-name: golang dependency-version: 1.26.6-alpine dependency-type: direct:production update-type: version-update:semver-patch dependency-group: docker-dependencies - dependency-name: golang dependency-version: 1.26.6-alpine dependency-type: direct:production update-type: version-update:semver-patch dependency-group: docker-dependencies ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
|
pinebit
approved these changes
Aug 19, 2026
KaloyanTanev
enabled auto-merge (squash)
August 19, 2026 13:34
KaloyanTanev
disabled auto-merge
August 19, 2026 13:40
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## main-v1.11 #4651 +/- ##
==============================================
+ Coverage 58.18% 58.39% +0.20%
==============================================
Files 247 247
Lines 34056 34094 +38
==============================================
+ Hits 19816 19908 +92
+ Misses 11765 11714 -51
+ Partials 2475 2472 -3 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



As per the title
category: misc
ticket: none