Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
35 commits
Select commit Hold shift + click to select a range
a8cccff
Merge #7298: fix(qt): keep PoSe score visible when hiding banned mast…
PastaPastaPasta May 28, 2026
48f72be
Merge #7360: fix: empty platformP2PPort deprecated field in protx lis…
PastaPastaPasta Jun 13, 2026
8f8616b
Merge #7372: backport: bitcoin/bitcoin#32693: depends: fix cmake comp…
PastaPastaPasta Jun 26, 2026
97c3dd1
Merge #7394: fix: stabilize par help text in manpages
PastaPastaPasta Jun 30, 2026
b003cdc
Merge #7395: ci: update GitHub Actions pins for Node 24
PastaPastaPasta Jul 1, 2026
90b5473
Merge #7396: fix: run of circular-dependencies with python3.15
PastaPastaPasta Jul 7, 2026
2915142
backport: bitcoin#27608 - p2p: Avoid prematurely clearing download st…
thepastaclaw Mar 19, 2026
8ffdf7f
Merge #7398: backport: compact block relay hardening (bitcoin#26898, …
PastaPastaPasta Jul 7, 2026
0ea6532
Merge #7387: test: migrate governance inv cache coverage to unit tests
PastaPastaPasta Jul 7, 2026
3ef3a5b
Merge #7408: fix: bound DKG contribution blob intake
PastaPastaPasta Jul 28, 2026
05cfe27
Merge #7351: fix: limit signing share sessions per peer
PastaPastaPasta Jun 25, 2026
44c396d
Merge #7402: fix: bound pending recovered sig queue to prevent remote…
PastaPastaPasta Jul 7, 2026
89bdf7c
Merge #7414: fix(net): throttle per-object governance vote sync requests
PastaPastaPasta Jul 8, 2026
9921621
Merge #7439: refactor: add bounded vector deserialization
PastaPastaPasta Jul 10, 2026
e118d0c
Merge #7259: fix: dangling point to cj client
PastaPastaPasta Jul 10, 2026
5b310df
Merge #7438: fix: bound SPORK signature deserialization
PastaPastaPasta Jul 10, 2026
da42f50
Merge #7424: fix: bound ChainLock seen cache
PastaPastaPasta Jul 10, 2026
9bbe808
Merge #7416: fix(net): bound quorum data response vectors
PastaPastaPasta Jul 10, 2026
5b5c6fb
Merge #7415: fix: bound pending sig share queue
PastaPastaPasta Jul 11, 2026
f855b13
Merge #7444: fix(net): bound bloom message vectors before allocation
PastaPastaPasta Jul 11, 2026
4b4d96a
Merge #7442: fix(net): authorize governance inv responses via the net…
PastaPastaPasta Jul 12, 2026
f011c80
Merge #7440: fix(net): bound governance vote signature deserialization
PastaPastaPasta Jul 10, 2026
7cc2cca
Merge #7450: test: make governance vote fixtures wire-valid
PastaPastaPasta Jul 12, 2026
5f5b960
Merge #7418: fix(net): bound signing message vector intake
PastaPastaPasta Jul 13, 2026
e203710
Merge #7419: fix(net): bound CoinJoin message vector intake
PastaPastaPasta Jul 20, 2026
550caf7
Merge #7465: fix(qt): handle pixel-sized fonts when scaling widgets
PastaPastaPasta Jul 29, 2026
f5c72c3
Merge #7347: fix: punish invalid dstx messages
PastaPastaPasta Jun 20, 2026
2194248
Merge #7348: fix: penalize oversized notfound messages
PastaPastaPasta Jun 25, 2026
24920a0
chore: prepare v23.1.8 release
PastaPastaPasta Jul 29, 2026
9be4f4a
Merge #7493: release: prepare v23.1.8
PastaPastaPasta Jul 30, 2026
6c1f611
fix: skip already-removed conflicts when a ProTx key change clears th…
PastaPastaPasta Jul 25, 2026
a801d3f
fix(llmq): reject unregistered LLMQ types from qsigshare before quoru…
PastaPastaPasta Jul 25, 2026
ca56af8
fix(llmq): reject parentless quorum base blocks instead of terminating
PastaPastaPasta Jul 25, 2026
728f505
doc: record the v23.1.8 critical crash fixes in the release notes
PastaPastaPasta Jul 25, 2026
e15bb64
Merge remote-tracking branch 'upstream/master' (v23.1.8) into develop
PastaPastaPasta Aug 3, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion configure.ac
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ AC_PREREQ([2.69])
dnl Don't forget to push a corresponding tag when updating any of _CLIENT_VERSION_* numbers
define(_CLIENT_VERSION_MAJOR, 23)
define(_CLIENT_VERSION_MINOR, 1)
define(_CLIENT_VERSION_BUILD, 7)
define(_CLIENT_VERSION_BUILD, 8)
define(_CLIENT_VERSION_IS_RELEASE, false)
define(_COPYRIGHT_YEAR, 2026)
define(_COPYRIGHT_HOLDERS,[The %s developers])
Expand Down
1 change: 1 addition & 0 deletions contrib/flatpak/org.dash.dash-core.metainfo.xml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,7 @@
</screenshot>
</screenshots>
<releases>
<release date="2026-07-30" version="23.1.8"/>
<release date="2026-06-30" version="23.1.7"/>
<release date="2026-06-19" version="23.1.5"/>
<release date="2026-06-13" version="23.1.4"/>
Expand Down
6 changes: 3 additions & 3 deletions doc/man/dash-cli.1
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
.\" DO NOT MODIFY THIS FILE! It was generated by help2man 1.49.3.
.TH DASH-CLI "1" "June 2026" "dash-cli v23.1.7" "User Commands"
.TH DASH-CLI "1" "July 2026" "dash-cli v23.1.8" "User Commands"
.SH NAME
dash-cli \- manual page for dash-cli v23.1.7
dash-cli \- manual page for dash-cli v23.1.8
.SH SYNOPSIS
.B dash-cli
[\fI\,options\/\fR] \fI\,<command> \/\fR[\fI\,params\/\fR] \fI\,Send command to Dash Core\/\fR
Expand All @@ -15,7 +15,7 @@ dash-cli \- manual page for dash-cli v23.1.7
.B dash-cli
[\fI\,options\/\fR] \fI\,help <command> Get help for a command\/\fR
.SH DESCRIPTION
Dash Core RPC client version v23.1.7
Dash Core RPC client version v23.1.8
.SH OPTIONS
.HP
\-?
Expand Down
14 changes: 7 additions & 7 deletions doc/man/dash-qt.1
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
.\" DO NOT MODIFY THIS FILE! It was generated by help2man 1.49.3.
.TH DASH-QT "1" "June 2026" "dash-qt v23.1.7" "User Commands"
.TH DASH-QT "1" "July 2026" "dash-qt v23.1.8" "User Commands"
.SH NAME
dash-qt \- manual page for dash-qt v23.1.7
dash-qt \- manual page for dash-qt v23.1.8
.SH SYNOPSIS
.B dash-qt
[\fI\,command-line options\/\fR] [\fI\,URI\/\fR]
.SH DESCRIPTION
Dash Core version v23.1.7
Dash Core version v23.1.8
.PP
Optional URI is a Dash address in BIP21 URI format.
.SH OPTIONS
Expand Down Expand Up @@ -128,13 +128,13 @@ Do not keep transactions in the mempool longer than <n> hours (default:
.HP
\fB\-par=\fR<n>
.IP
Set the number of script verification threads (0 = auto, <0 = leave that many
cores free, max: 15, default: 0)
Set the number of script verification threads (0 = auto, <0 = leave that
many cores free, max: 15, default: 0)
.HP
\fB\-parbls=\fR<n>
.IP
Set the number of BLS verification threads (0 = auto, <0 = leave that many
cores free, max: 33, default: 0)
Set the number of BLS verification threads (0 = auto, <0 = leave that
many cores free, max: 33, default: 0)
.HP
\fB\-persistmempool\fR
.IP
Expand Down
6 changes: 3 additions & 3 deletions doc/man/dash-tx.1
Original file line number Diff line number Diff line change
@@ -1,15 +1,15 @@
.\" DO NOT MODIFY THIS FILE! It was generated by help2man 1.49.3.
.TH DASH-TX "1" "June 2026" "dash-tx v23.1.7" "User Commands"
.TH DASH-TX "1" "July 2026" "dash-tx v23.1.8" "User Commands"
.SH NAME
dash-tx \- manual page for dash-tx v23.1.7
dash-tx \- manual page for dash-tx v23.1.8
.SH SYNOPSIS
.B dash-tx
[\fI\,options\/\fR] \fI\,<hex-tx> \/\fR[\fI\,commands\/\fR] \fI\,Update hex-encoded dash transaction\/\fR
.br
.B dash-tx
[\fI\,options\/\fR] \fI\,-create \/\fR[\fI\,commands\/\fR] \fI\,Create hex-encoded dash transaction\/\fR
.SH DESCRIPTION
Dash Core dash\-tx utility version v23.1.7
Dash Core dash\-tx utility version v23.1.8
.SH OPTIONS
.HP
\-?
Expand Down
6 changes: 3 additions & 3 deletions doc/man/dash-util.1
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
.\" DO NOT MODIFY THIS FILE! It was generated by help2man 1.49.3.
.TH DASH-UTIL "1" "June 2026" "dash-util v23.1.7" "User Commands"
.TH DASH-UTIL "1" "July 2026" "dash-util v23.1.8" "User Commands"
.SH NAME
dash-util \- manual page for dash-util v23.1.7
dash-util \- manual page for dash-util v23.1.8
.SH SYNOPSIS
.B dash-util
[\fI\,options\/\fR] [\fI\,commands\/\fR] \fI\,Do stuff\/\fR
.SH DESCRIPTION
Dash Core dash\-util utility version v23.1.7
Dash Core dash\-util utility version v23.1.8
.SH OPTIONS
.HP
\-?
Expand Down
6 changes: 3 additions & 3 deletions doc/man/dash-wallet.1
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
.\" DO NOT MODIFY THIS FILE! It was generated by help2man 1.49.3.
.TH DASH-WALLET "1" "June 2026" "dash-wallet v23.1.7" "User Commands"
.TH DASH-WALLET "1" "July 2026" "dash-wallet v23.1.8" "User Commands"
.SH NAME
dash-wallet \- manual page for dash-wallet v23.1.7
dash-wallet \- manual page for dash-wallet v23.1.8
.SH DESCRIPTION
Dash Core dash\-wallet version v23.1.7
Dash Core dash\-wallet version v23.1.8
.PP
dash\-wallet is an offline tool for creating and interacting with Dash Core wallet files.
By default dash\-wallet will act on wallets in the default mainnet wallet directory in the datadir.
Expand Down
14 changes: 7 additions & 7 deletions doc/man/dashd.1
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
.\" DO NOT MODIFY THIS FILE! It was generated by help2man 1.49.3.
.TH DASHD "1" "June 2026" "dashd v23.1.7" "User Commands"
.TH DASHD "1" "July 2026" "dashd v23.1.8" "User Commands"
.SH NAME
dashd \- manual page for dashd v23.1.7
dashd \- manual page for dashd v23.1.8
.SH SYNOPSIS
.B dashd
[\fI\,options\/\fR] \fI\,Start Dash Core\/\fR
.SH DESCRIPTION
Dash Core version v23.1.7
Dash Core version v23.1.8
.SH OPTIONS
.HP
\-?
Expand Down Expand Up @@ -126,13 +126,13 @@ Do not keep transactions in the mempool longer than <n> hours (default:
.HP
\fB\-par=\fR<n>
.IP
Set the number of script verification threads (0 = auto, <0 = leave that many
cores free, max: 15, default: 0)
Set the number of script verification threads (0 = auto, <0 = leave that
many cores free, max: 15, default: 0)
.HP
\fB\-parbls=\fR<n>
.IP
Set the number of BLS verification threads (0 = auto, <0 = leave that many
cores free, max: 33, default: 0)
Set the number of BLS verification threads (0 = auto, <0 = leave that
many cores free, max: 33, default: 0)
.HP
\fB\-persistmempool\fR
.IP
Expand Down
125 changes: 97 additions & 28 deletions doc/release-notes.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,10 @@
# Dash Core version v23.1.7
# Dash Core version v23.1.8

This is a new patch version release, bringing security hardening and build fixes
for newer compiler toolchains.
This release is **recommended** for all nodes, and especially for masternodes.
This is a new patch version release, fixing three remotely reachable crashes and
bringing further hardening of the peer-to-peer message handlers along with
networking, RPC and build fixes.
Upgrading is **strongly recommended** for all nodes, and required for
masternodes.

Please report bugs using the issue tracker at GitHub:

Expand All @@ -26,43 +28,109 @@ require a reindex.

# Release Notes

## Critical fixes

This release fixes three crashes that a remote party could trigger. None of
them affect consensus rules or put funds at risk, but each one can take a node
offline, so all operators should upgrade promptly.

- Fixed a crash while removing provider transactions that a masternode's
operator-key change invalidates. Those transactions are collected before any
of them are removed, so when one was an in-mempool descendant of another it
was already erased along with its ancestor, and the stale entry was then
dereferenced. Such entries are now skipped. This is reachable whenever a block
carries a provider registrar update or revocation for a masternode that has
chained service updates pending in the mempool.
- Fixed a crash caused by an unvalidated LLMQ type in a `qsigshare` message. A
masternode that received a signature share naming an LLMQ type its chain does
not register would index a per-type quorum cache that is only populated for
known types, aborting the process. Unregistered types are now rejected before
the lookup, and the affected cache lookups no longer create missing entries.
- Fixed a crash caused by a quorum commitment naming a block with no parent,
such as the genesis block. The parentless block index reached a non-null
precondition and terminated the process instead of failing validation, which
no exception handler could contain. Commitments with a parentless quorum base
block are now rejected, and the LLMQ activation check treats a null
predecessor as "not enabled" rather than a contract violation.

## Security

This release hardens several peer-to-peer message handlers against
This release continues the hardening of peer-to-peer message handlers against
denial-of-service from remote peers. These issues do not affect consensus and do
not put funds at risk, but they could be used to crash or degrade nodes -
masternodes in particular - so upgrading is recommended.

- Networking: a peer whose receive buffer filled up could keep the socket-handler
thread spinning at 100% CPU for the duration of the backpressure. The thread now
falls back to its normal poll wait while such peers are paused.
- LLMQ / DKG: pushed DKG messages are now accepted only from verified masternodes,
are bounded in size, and are structurally validated before being retained;
malformed signatures can no longer trigger an assertion failure during batch
signature verification.
- BLS: verifying a DKG contribution share whose verification vector was never
received no longer dereferences a null pointer.
- InstantSend: locks with an oversized input set are now rejected before any
expensive processing, and the queues holding not-yet-verified and
awaiting-transaction locks are bounded to prevent unbounded memory growth.
- Governance: vote-sync requests carrying a bloom filter outside the permitted size
are rejected, preventing a CPU-amplification stall of P2P message processing.

## Build

- Fixed GCC 16 build failures in warning-enabled builds by tightening header
includes and initializing LevelDB compaction output size.

# v23.1.7 Change log
- LLMQ / signing: the queues of not-yet-verified recovered signatures and
signature shares are now bounded, and the vectors carried by the QSIGSHARE,
QSIGSESANN, QSIGSHARESINV, QGETSIGSHARES and QBSIGSHARES messages are bounded
before any allocation or decoding takes place. The number of signing share
sessions a single peer may announce is also capped, so a peer can no longer
grow that per-peer state without limit (dash#7351).
- LLMQ / DKG: the number of encrypted contribution blobs in a DKG contribution
is now checked against the quorum's lower bound as well as its upper bound.
- LLMQ / quorum data: the verification vector and encrypted contribution
vectors in QDATA responses are validated against their expected sizes before
any BLS decoding is performed.
- Transaction relay: an oversized `notfound` message is now penalised rather
than silently ignored (dash#7348).
- ChainLocks: the cache of seen ChainLock signatures is now bounded.
- Governance: per-object vote sync requests are now throttled per peer, and
governance object and vote responses are only accepted from a peer if that
peer announced them or they were requested from it, using the net-layer
per-peer request tracker. Governance vote signatures are bounded when read
from the network and must use one of the two legitimate encodings.
- CoinJoin: the vectors carried by CoinJoin mixing messages are bounded before
allocation, and a non-participant can no longer abort another session's
signing phase. An invalid `dstx` message now carries a misbehaviour score
instead of being dropped for free (dash#7347).
- Bloom filters: filterload and filteradd payloads are bounded before
allocation.
- Sporks: spork signatures are bounded during deserialization, and malformed
spork messages now attribute misbehaviour to the sending peer.
- Compact block relay: batched hardening backported from upstream Bitcoin Core
(dash#7398), including detection of mutated blocks as a defence-in-depth
measure.

## RPC

- `protx listdiff` no longer reports an always-zero `platformP2PPort` /
`platformHTTPPort` for masternodes registered with extended addresses; the
live Platform ports are reported instead.

## GUI

- The PoSe score column is no longer hidden together with banned masternodes in
the masternode list.
- Fixed an abort when scaling widgets whose font was set in pixels rather than
points (for example by a stylesheet's `font-size: Npx`); such fonts are now
converted to a point size instead of being assumed to have one (dash#7465).

## Build and CI

- Fixed a CMake compatibility error when building the freetype dependency with
newer CMake (dash#7372).
- Stabilized the `-par` / `-parbls` help text (and the generated man pages) so
they no longer embed the core count of the build machine.
- Updated GitHub Actions pins for the Node 24 runtime.
- Fixed the circular-dependencies lint script under Python 3.15.

## Tests

- Governance inventory cache coverage moved from a functional test to unit
tests, and governance vote test fixtures are now wire-valid.

# v23.1.8 Change log

See detailed [set of changes][set-of-changes].

# Credits

Thanks to everyone who directly contributed to this release:

- knst
- Konstantin Akimov
- PastaClaw
- PastaPastaPasta
- UdjinM6

As well as everyone that submitted issues, reviewed pull requests and helped
debug the release candidates.
Expand All @@ -71,6 +139,7 @@ debug the release candidates.

These releases are considered obsolete. Old release notes can be found here:

- [v23.1.7](https://github.com/dashpay/dash/blob/master/doc/release-notes/dash/release-notes-23.1.7.md) released Jun/30/2026
- [v23.1.5](https://github.com/dashpay/dash/blob/master/doc/release-notes/dash/release-notes-23.1.5.md) released Jun/19/2026
- [v23.1.4](https://github.com/dashpay/dash/blob/master/doc/release-notes/dash/release-notes-23.1.4.md) released Jun/18/2026
- [v23.1.3](https://github.com/dashpay/dash/blob/master/doc/release-notes/dash/release-notes-23.1.3.md) released May/28/2026
Expand All @@ -89,4 +158,4 @@ These releases are considered obsolete. Old release notes can be found here:
- [v21.0.0](https://github.com/dashpay/dash/blob/master/doc/release-notes/dash/release-notes-21.0.0.md) released Jul/25/2024
- [v20.1.1](https://github.com/dashpay/dash/blob/master/doc/release-notes/dash/release-notes-20.1.1.md) released April/3/2024

[set-of-changes]: https://github.com/dashpay/dash/compare/v23.1.5...dashpay:v23.1.7
[set-of-changes]: https://github.com/dashpay/dash/compare/v23.1.7...dashpay:v23.1.8
Loading
Loading