Releases: iftech/nim-libp2p
Release list
v2.4.1
What's Changed
- fix(nameresolving): tolerate duplicate DNS responses by @richard-ramos in #3224
Full Changelog: v2.4.0...v2.4.1
v2.3.7
What's Changed
- fix(nameresolving): tolerate duplicate DNS responses by @richard-ramos in #3224
Full Changelog: v2.3.6...v2.3.7
v2.3.6
What's Changed
- fix(kademlia): track provider RPCs immediately and preserve keys on refresh by @richard-ramos in #3073
- test(kad): pin backoff exclusion from lookup results by @gmelodie in #3151
- fix(kad): make success-first reply order independent of enum order by @gmelodie in #3150
- fix(kad): race in lookup test by @gmelodie in #3152
- test(kad): RPC handler fault paths and liveness probe races by @gmelodie in #3158
- chore(kad): simplify
maintainLivenessby @vladopajic in #3172 - fix(kad): liveness loop spins on finished probes by @gmelodie in #3171
- fix(kad): let probed peers rotate full buckets by @gmelodie in #3180
Full Changelog: v2.3.5...v2.3.6
v2.4.0
Highlights
- Address announcement is now coordinated by a switch-owned
AddressManager. Listen addresses, explicit announcements, NAT mappings, relay addresses, and Identify observations feed a shared candidate set, with periodic reachability verification. Repeated observations from the same peer no longer count as independent confirmation. - Dialing gained optional address ranking and per-address/per-peer failure backoff. Ranked dialing overlaps DNS resolution with connection attempts, tries direct addresses without waiting for slow names, and processes DNS results as they arrive. Enable these features with
withDialRanking()andwithDialBackoff(). - AutoTLS received extensive issuance and renewal fixes, including certificate-expiry handling, retry accounting, DNS retries, ACME POST-as-GET requests, CSR encoding, and authentication edge cases. ACME requests are restricted to the directory origin, and Docker integration tests cover the issuance flow.
- Multiaddresses now support
/sni, and secure WebSocket dialing can use an explicit TLS server name. TCP dual-stack address reuse, WebSocket shutdown reporting, and SOCKS5 response and hostname validation were also fixed. - Kademlia routing-table admission and maintenance were hardened with per-bucket IP diversity limits, failed-probe backoff, automatic re-seeding of undersized tables, and safer handling when admission-probe capacity is exhausted. Service-table lookups no longer double-hash their targets, provider RPCs are tracked immediately, and refreshes preserve provider keys.
- Service Discovery now filters undialable addresses, republishes advertisements when addresses change, preserves advertisement sequence numbers across rotations, and uses Unix seconds for ticket timestamps. Registrar admission follows the shared Kademlia path, local advertisements are checked first, cancellation propagates correctly, and provider-discovery latency is measured.
- PubSub handling was hardened with malformed-message overhead accounting in FloodSub, a bounded FloodSub seen cache, graylisted-peer RPC rejection in GossipSub, and correct handling of non-canonical Peer ID aliases. Peer background tasks are stopped before connection teardown.
- Stream and connection cleanup was improved across BufferStream, Mplex, yamux, and negotiation paths. Fixes release read buffers, wake blocked readers and writers on close, preserve buffered data and EOF, and clean up failed negotiations and interrupted stream opens.
- AutoNAT dial-back validation now requires fresh inbound connections and validates successful response address indexes. Reachability classification distinguishes IPv4 from IPv6, while relay reservation and hole-punching tasks receive more reliable shutdown cleanup.
- Rendezvous now bounds its namespace table, prunes empty namespaces, releases expired registrations on the cleanup heartbeat, and avoids allocating an index for every registration during discovery.
- Logging now uses more consistent severities and fields, rate limits selected recurring messages, and shortens large values. Sensitive key and secret types are redacted during diagnostic formatting and generic JSON serialization. Public-key parsing and CID validation and hashing were also tightened.
- C bindings now include the remote Peer ID in incoming-stream events, require a running switch for service-discovery operations, and use nim-ffi 0.3.0. Dependency requirements were updated to nim-websock 0.4.1 and nim-libplum 0.6.2.
Integration notes
The largest changes affect which addresses a node advertises, how AutoNATv2 proves inbound reachability, and when KadDHT startup completes. Dial ranking and general dial backoff are available as opt-in features. Applications that call KadDHT APIs directly should also review the new Key and Value types.
Address management, dialing, stream cleanup, and diagnostics affect the shared networking stack. AutoNAT, KadDHT, Service Discovery, AutoTLS, PubSub, Rendezvous, and C-binding changes apply when your application uses those components. The sections below identify configuration-dependent behavior so users can distinguish automatic changes from features they must enable.
Address announcements: one shared view of how peers can reach the node
The switch now owns an AddressManager shared by Identify, NAT mapping, AutoNAT, relay services, and address announcement. These components contribute addresses to the same candidate set, retaining both their source and verification state.
Observable behavior:
- Repeated reports from one peer no longer establish consensus. Identify observations count distinct Peer IDs; a newer report replaces that peer's previous report. The default threshold remains three agreeing peers, with up to ten peer observations retained. Reconnecting repeatedly to the same peer cannot satisfy that threshold.
- An inferred address is not automatically a proven address. With AutoNATv2 candidate derivation enabled, addresses inferred solely from Identify are advertised only after a successful verification. Listen addresses and addresses contributed by other sources can still be advertised while unverified.
- Failed verification can change the advertised address list. Public candidates marked unreachable are excluded from automatic announcements. Private addresses are retained because a failed external dial-back does not establish whether LAN peers can reach them. The configured address policy still controls visibility.
- Relay announcements can give way to direct addresses. Once a public direct address is confirmed, automatic announcements omit relay addresses with the same IP family. Confirmation over IPv6 does not suppress an IPv4 relay address, or vice versa.
- Addresses disappear when their source withdraws them. An expired mapping or lost relay reservation removes that source's contribution. A candidate remains if another source still supplies it.
- Explicit announcements remain an operator override. A nonempty explicit announce list takes precedence over the manager's automatic selection, including its reachability filtering. Do not assume an explicitly configured address has passed verification.
Verification is optional: creating a switch does not itself install a verifier. AutoNATv2 supplies one when its service starts. The manager defaults to a five-minute verification interval and a two-minute budget for each pass; an inconclusive result retains the previous state. Generating additional probe candidates from Identify observations remains opt-in (enableDialableCandidates = false), as in v2.3.0. Previously, enabling it prepended inferred addresses to the service's multi-address dial requests; now it adds them to the shared manager for individual verification. The flag does not disable recording observations or using them in the address mapper after the node is classified reachable.
Integration implication: advertised addresses can evolve after startup. Applications that publish or cache their own discovery records should check whether those records follow local address updates or capture the startup list once. Tests that infer an external address by repeating observations from one Peer ID need distinct observers. Explicit announce lists need separate operational validation.
AutoNAT: stronger proof of inbound reachability
AutoNATv2 fixes false-positive reachability checks caused by connection reuse. The protocol calls for the server to dial the selected address and return the request's nonce over that connection. A stream on an already established connection does not prove that the requested address accepts a new inbound connection. nim-libp2p now forces a new connection on the server and rejects client-side dial-backs unless their underlying transport connection is inbound and opened after the pending request began.
This implements the protocol's intended reachability test; it is not a new protocol requirement. The spec does not explicitly mandate the connection-age check. go-libp2p's server uses a separate dialer host and closes its dial-back connection after the attempt, while the inspected Go client checks the nonce and address consistency without nim-libp2p's explicit inbound-direction and connection-age checks.
A successful response is checked against the requested address and the local address where the dial-back arrived. Out-of-range or inconsistent address indexes are rejected. An omitted index is interpreted as zero and still validated; omission does not bypass the check.
The AutoNATv2 verifier asks eligible outbound-connected peers, excludes peers with an existing inbound connection, and skips verification when fewer than two incoming connection slots remain. No eligible peer, timeout, or protocol error produces no new verdict. The node may therefore remain Unknown until it can obtain useful evidence.
Address eligibility now uses IP-family-aware classification: IPv6 private and link-local addresses are not treated as globally routable simply because they are not IPv4 private addresses. AutoNATv2's server also checks that it supports the requested address family and refuses nonglobal dial-back targets, including DNS and relay addresses at that eligibility check. The service still exposes an aggregate reachability status; a reachable node is not a promise that every advertised address or both IP families work.
Integration implication: AutoNATv2 can stop reporting success in setups that previously succeeded by reusing an existing connection. Reachability tests need a genuine inbound dial-back and spare incoming capacity. Check which AutoNAT version your application enables: the verifier and fresh-connection changes above are specifically v2 behavior.
KadDHT: startup returns sooner, unreachable peers stop consuming retries
- Startup no longer waits for bootstrap to finish. KadDHT starts bootstrap in the backgro...
v2.3.5
What's Changed
- fix(kad): non-blocking bootstrap by @gmelodie in #3134
- fix(kad): stop retrying unreachable peers during bootstrap by @gmelodie in #3135
- chore(logs): tune logs for kademlia & service-discovery by @vladopajic in #3140
Full Changelog: v2.3.4...v2.3.5
v2.3.4
What's Changed
Full Changelog: v2.3.3...v2.3.4
v2.3.3
What's Changed
Full Changelog: v2.3.2...v2.3.3
v2.3.2
What's Changed
- fix: handle disconnect while opening stream by @etan-status in #3015
- fix(quic): avoid caching partially constructed dial endpoints by @richard-ramos in #3111
- chore: bump lsquic by @richard-ramos in #3116
- test(dialer): expect connection limit rejection by @richard-ramos ([f43fb9d](f43fb9d))
Full Changelog: v2.3.1...v2.3.2
v2.2.2
What's Changed
- fix(pubsub): bound seen cache and add overhead observability by @richard-ramos (d6c4f7f)
Full Changelog: v2.2.1...v2.2.2
v2.1.7
What's Changed
- chore(pubsub): adjust incoming message validation order by @richard-ramos (#2647)
- fix(pubsub): bound seen cache and add overhead observability by @richard-ramos (5724d66)