Skip to content

v2.2.2.513

Choose a tag to compare

@sowle sowle released this 20 Sep 00:45
· 34 commits to master since this release
2ab8448

A maintenance and hardening release on top of HF6. Highlights:

  • GUI migrated to Qt 6;
  • default alias per address: auto-selected for the UI when an address has several aliases;
  • continued gateway address work: txs are validated before signing/relay, client-side history decryption, richer gateway RPC;
  • decoy-selection and PoS stake-maturity fixes;
  • security hardening: wallet-KDF cost bounds, a password policy, no sensitive data in logs, proof-verification guards, and an ARM32 ChaCha crash fix;
  • alt-block retention cut from one week to two hours.

Changelog:
[+] core: default alias per address, a default alias is now tracked on-chain and returned via RPC (default_alias) so the UI can pick one when an address owns several aliases
[*] core: fixed an HF6-specific issue in generate_asset_surjection_proof_hf6() when a gateway output precedes a confidential (ZC) one
[*] core: alt-block retention (CURRENCY_ALT_BLOCK_LIVETIME_COUNT) reduced from one week to two hours (blockchain-storage minor version bumped to 3)
[*] core: hardened proof verification; added guards around verify_CLSAG_GGX and made verify_asset_surjection_proof() and verify_BGE_proof() noexcept
[*] core: additional hardening of bad-tx blacklisting in handle_block_to_main_chain; added validate_tx_semantic to the alt-chain tx validation path; hardened check_tx_input
[*] core: fixed the lock region for the median-timestamp cache (thread-safety)
[+] core: added a blockchain-storage startup performance check
[+] crypto: introduced crypto::wipe for secure erasure of sensitive memory
[*] crypto: fixed an unaligned ChaCha IV/key access crash on ARM32 (#727)
[*] serialization: fixed JSON serialization of base-class fields (CHAIN_BASE) for transactions, blocks and alias entries
[*] p2p: fixed chain-synchronization edge cases (clear stale last-fetched block ids on empty responses and when another thread advanced the chain), preventing sync stalls during deep splits; added default values for proxy_diagnostic_info
[+] p2p: implemented a sync-speed calculator
[*] rpc: validate gateway transactions before signing and relay (gateway hardening);
[*] rpc: gateway_create_transfer now returns the tx secret key and the list of output addresses (for use with decrypt_tx_outs_and_update_op); decrypt_tx_details fixed for gateway outputs
[-] rpc: removed legacy getrandom_outs1 (pre-HF4 PoS block building moved to v3)
[*] rpc: allow duplicate output addresses in decrypt_tx_details; hardened request checks in on_get_blocks_direct / on_get_blocks and on_getblockhash
[*] wallet rpc: get_payments and get_bulk_payments made assets-aware
[*] wallet rpc: decrypt_data hardened to check the return value of decrypt_buffer
[-] wallet rpc: removed the deprecated push_payer and hide_receiver
[*] wallet: reworked decoy selection, fixed getrandomouts4 (removed 2x height sampling, bounded HF4 distributions to max_h), fixed stake maturity
[*] wallet: migrated sweep_below to decoy selection v4
[+] gateway: client-side decryption of gateway-address history via the local proxy
[*] wallet: validate ROMix KDF cost parameters before decryption (added an upper bound, N_log2_max = 22)
[*] wallet: fixed handling of intrinsic payment IDs and gateway addresses carrying a PID in the sender-side history
[*] wallet: prevent unconfirmed payments from persisting in m_payments
[*] wallet: truncate the wallet creation timestamp to weeks for RPC needs
[+] wallet: report incompatible_server in get_connectivity_status (plain-wallet / GUI)
[+] wallet: added PoS staking status fields (progress/estimate) and unified the PoS mining cycle (fixes current_pos_attempts)
[*] wallet: added a password policy (min 8 / max 256 chars) with an optional command-line option to allow an unsecure password
[*] wallet: fixed macOS sleep-related issues in the wallets manager
[*] simplewallet: sensitive output (tx secret keys, seed doctor, check_all_tx_keys) made cout-only, no longer written to the log
[*] simplewallet: fixed payments lookup for hex-encoded payment IDs; fixed a crash when started without command-line options; --derive-custom-seed now accepts dashes
[+] gui: migrated the GUI to Qt 6 (with macOS CI)
[*] gui: migrated secure-config encryption to the ROMix-Keccak KDF
[*] gui: isolated the WebChannel API behind a dedicated bridge and fixed Qt warnings
[+] gui: added log-size reporting and clearing APIs (surfaced in Settings)
[*] gui: validate the browser extension id in the HTTP origin check; stopped writing double-hashed passwords to the log
[*] gui: fixed an empty resulting tx returned by wallets_manager::transfer()
[*] gui: UI updates: staking progress & estimate, password validation & master-password handling, Create-Wallet form behavior, log controls in Settings, plus assorted design/UX fixes (zano_ui PRs 180-188)
[+] general: the Linux AppImage can now run zanod and simplewallet (not just the GUI)
[+] builds: added ARM64 release builds (Linux, and Windows CLI) and macOS build/signing CI

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Windows:
INST: https://build.zano.org/builds/zano-win-x64-installer-release-v2.2.2.513[2ab8448].exe
sha256: cdec2669cd3bd398a07cb6bd27b4b4d428799edbd4672672e7c7653a931b404d

ZIP: https://build.zano.org/builds/zano-win-x64-gui-release-v2.2.2.513[2ab8448].zip
sha256: 094d55bf05d02b24322ead9a65efaf06189a8aafe38cd71ba8d8cfeeae803d11

macOS:
https://build.zano.org/builds/zano-macos-x64-gui-release-v2.2.2.513[2ab8448].dmg
sha256: 0b3df205e2117e0bbbf455c3fd9b5b96301095122c6fcea5c9b0de1164f54764

Linux:
https://build.zano.org/builds/zano-linux-x64-gui-release-v2.2.2.513[2ab8448].AppImage
sha256: cf27c5627eadf2b8a5f48041c094d2d72b26cf7fc0f8fd1af6e565d0987ecb65
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQSAlUHSyV95S5huh5+pK4bC95+XGgUCaq8sIAAKCRCpK4bC95+X
GsEBAP0Tcc6XJHYz24nDNTNwNyPbxIqMYwz2EJGq0lhrQiqirwEAi9q4hpqkPdhH
zs9qc3q81EDNpecNDll76+SVUYsGZws=
=yok7
-----END PGP SIGNATURE-----

How to verify downloaded builds