Repository navigation
node 1.0.400
Metadata
- Release type: patch
- Version delta 1.0.300 -> 1.0.400 leaves major and minor unchanged (commit 8081e4b).
- Date: 2026-10-05 (owner-confirmed 2026-10-05)
- Ships in bundle: — this release is not part of a bundle (owner-confirmed 2026-10-05)
- Sister-line note: — (owner-confirmed 2026-10-05)
- Environment: Preview, Preprod and Mainnet - the fix is already running on all three (owner-confirmed 2026-10-05)
- Released artifact(s): https://github.com/midnightntwrk/midnight-node/releases/tag/node-1.0.400 - seven artifacts publish at this tag; see Artifacts below.
- Component class: core/infra
- Upgrade scope: binary only (detail under Deployment information)
- Reset required: No (detail under Deployment information)
- Governance action required: No - there is no runtime to enact (commit 8081e4b)
High-level summary
This is the public release of a security patch already deployed on Preview, Preprod and Mainnet (owner-confirmed 2026-10-05). It moves
the node's ledger 8 host functions to ledger 8.1.3, which fixes the critical advisory
GHSA-wr7g-rr4v-jmj8
and also rejects noop 0 in contract call transcripts (commit 8081e4b). It also fixes the mainnet fresh-sync halt at
block #1788979 that 1.0.300 listed as a known issue (commit 5defaf5, issue #2229). The upgrade is binary-only: the
on-chain runtime is untouched and spec_version stays 1_000_300 (commit 8081e4b).
Audience
These notes are for:
- Validators and block producers on every network, who should move to this binary together.
- Full Node Operators, in particular anyone syncing mainnet from genesis.
- External integrators and dApp developers whose contract calls reach the ledger through the node.
- The Midnight Foundation and Shielded Technologies engineering and SRE teams.
Dependencies
Component-local hard requirements:
- Block producers should run the same ledger version. A node on ledger 8.1.3 rejects contract calls that a node on 8.1.2 accepts (commit 8081e4b).
- Runs against the already-enacted 1.0.300 runtime (
spec_version1_000_300). The statically linked runtime is not used on mainnet, at all times the on chain runtime will be used. In this release no new on-chain runtime ships.
For every other interop question, see the bundle dependency matrix.
Downstream impact (cascading effects).
- A contract call whose transcript carries a non-canonical
fieldvalue, ornoop 0, is rejected by 1.0.400 nodes as malformed, where earlier nodes accepted it (commit 8081e4b). Supported compactc and midnight-js output never produces these encodings, so dApp developers have nothing to change (owner-confirmed 2026-10-05). - The toolkit at this tag is built on the same ledger 8.1.3 crates, so it applies the same stricter rules when building or replaying transactions (commit 8081e4b).
Tested-with versions
Build pins read from the workspace manifest and Cargo.lock at the release commit: build pins — not QA-verified.
| Component | Tested-with version |
|---|---|
midnight-ledger (v8) |
8.1.3 (commit 3acfd2e) |
midnight-ledger (v7) |
7.0.3 (commit 3acfd2e) |
midnight-zswap (v8 / v7) |
8.1.3 / 7.0.3 (commit 3acfd2e) |
midnight-onchain-runtime |
3.1.2 (v8) / 2.0.1 (v7) (commit 3acfd2e) |
midnight-onchain-state |
3.0.2 (v8) / 2.0.1 (v7) (commit 3acfd2e) |
midnight-onchain-vm |
3.1.2 (v8) / 1.0.2 (v7) (commit 3acfd2e) |
midnight-base-crypto |
1.0.2 (commit 3acfd2e) |
midnight-storage |
2.0.3 (v8) / 1.1.1 (v7) (commit 3acfd2e) |
polkadot-sdk |
polkadot-stable2603 (commit 3acfd2e) |
compactc |
0.30.0 (commit 3acfd2e) |
partner-chains |
vendored in-tree, no released version pin (commit 3acfd2e) |
Deployment information
- Upgrade scope: binary only - a new node binary or image.
spec_versionstays 1_000_300 and the enacted runtime is unchanged (commit 8081e4b). - Reset required: No - no runtime, chain-spec or genesis file changed between 1.0.300 and this release (commit 3acfd2e). A node halted at #1788979 resumes importing once restarted on 1.0.400, with no resync (owner-confirmed 2026-10-05).
- Governance action required: No - nothing to enact on chain (commit 8081e4b).
- Downtime / coordination: Per-node binary swap with no runtime step, but block producers should switch together because 8.1.3 and 8.1.2 nodes disagree on which contract calls are well-formed (commit 8081e4b). On Preview, Preprod and Mainnet this has already happened (owner-confirmed 2026-10-05).
Artifacts
Binaries (sha256 from the release assets, cross-checked against SHA256SUMS):
midnight-node-1.0.400-linux-amd64.tar.gz- node binary, x86-64 (sha256:8098481824fa511d0a37554e44eaca524f5c74bced1885e5224cd90c0761914c, release body).midnight-node-1.0.400-linux-arm64.tar.gz- node binary, arm64 (sha256:4724691ed0204b1b3ccb0541da9d72b6e35ae7f6f5db0435048744a7ff85447f, release body).midnight-node-toolkit-1.0.400-linux-amd64.tar.gz- toolkit binary, x86-64 (sha256:b3a320218e68b9544a30f3670fee884686728fce036318385656476772236f74, release body).midnight-node-toolkit-1.0.400-linux-arm64.tar.gz- toolkit binary, arm64 (sha256:dbdc8ce90bbb80c90c7590dcb228dd35f4115c107aadfe2f2b474025c240f3d6, release body).
Verification:
SHA256SUMS- checksum manifest for the four tarballs (sha256:3e4367b93a2ecbf7ba23b7ca4eb76e37dfd7901495ec3a08e40bb1cb44d86605, release body).
No runtime wasm or srtool-digest.json ships: the runtime is the 1.0.300 one already on chain (commit 8081e4b).
Images (Docker Hub digests):
midnightntwrk/midnight-node:1.0.400- node image, multi-arch indexsha256:915b117f955859a0ab7f34230ca12b43ef7474c84e29463256efcfc7b757040f; linux/amd64sha256:cbb4dcfbf8bc628f6c246532a60496c55c9684237da15152dc5984a95b337b55, linux/arm64sha256:eeaf8e3c5b6bb4a6eb53daa3d15c66e68e751014890fb76f42f3c021da7cebf5. Per-arch tags1.0.400-amd64and1.0.400-arm64carry the same digests.midnightntwrk/midnight-node-toolkit:1.0.400- toolkit image, multi-arch indexsha256:b2d26c6759e9fba2402b362fa0180740178b0e41d8ab8a90b12619786dd561e3; linux/amd64sha256:52ba1c3006e556a5ae7622446becdc52cf15fba944d12cc5c61f14cd0c71bf8b, linux/arm64sha256:fb9a7fb008a03918dd17a11038a2b7c589afc97e36a7ad02562fd51470f67a3c. Per-arch tags1.0.400-amd64and1.0.400-arm64carry the same digests.
What changed
- Node upgrade. Bump ledger 8 to 8.1.3: contract call transcripts must embed canonical field values, so a
fieldatom encodingx + pis rejected inpush,pushsandidx-style path keys - the fix for critical advisory GHSA-wr7g-rr4v-jmj8 (PR #2238, commit 8081e4b). - Node upgrade. Through the same bump,
noop 0in a contract call transcript is rejected as not normalized (commit 8081e4b). - Node upgrade. Crate versions after the bump:
midnight-ledgerandmidnight-zswap8.1.3,midnight-onchain-runtime3.1.2,midnight-onchain-state3.0.2,midnight-onchain-vm3.1.2,midnight-base-crypto1.0.2. Themidnight-base-cryptochange is additive only, so ledger 7, which shares it, is unaffected (commit 8081e4b). - Node upgrade. When a historical block's first ledger transaction fails
well_formedat the correctedtblock(parent block time + 12 s), retry it at the block's owntblock. This unblocks a fresh mainnet sync that halted at #1788979 withIntent TTL has expired; the retry is only reachable under host-function v1, so it never applies to blocks after the v2 runtime upgrade at mainnet #2738210 (commit 5defaf5). - Node upgrade. Regression tests for that retry, including a fixture of mainnet block #1788980's first transaction (commit e913d44, commit 28edf6a).
- Housekeeping: version bumps across the workspace and
docs/openrpc.json(commit 8081e4b),axiosandbrace-expansionlockfile bumps in the local test environment (commit 568b6f0), and a CI workflow permissions fix (PR #2243). - Toolkit. Drop the
shxdev dependency from the toolkit's JS harness, which was raising audit issues (commit 568b6f0).
New features
None.
New features requiring configuration updates
None - no config preset, chain spec or node-config key changed between 1.0.300 and this release (commit 3acfd2e).
Improvements
None.
Deprecations
None.
Breaking changes
Breaking change stricter contract call well-formedness
What changed: Ledger 8.1.3 narrows what counts as a well-formed contract call. A field atom encoding x + p (where p is the field modulus) in push, pushs or idx-style path keys, and noop 0, are now rejected (commit 8081e4b).
What breaks: A contract call carrying either is rejected as malformed by a 1.0.400 node, where a 1.0.300 node accepted it. Block producers on mixed versions would disagree on such calls (commit 8081e4b).
Required actions: operators and developers have separate steps.
- Operators: move every block producer onto 1.0.400 together (commit 8081e4b).
- Developers: nothing to do - supported compactc and midnight-js output never produces these encodings (owner-confirmed 2026-10-05).
Code example: — none applies; this is a validity rule, not an API migration.
Known issues
None (owner-confirmed 2026-10-05).
Links and references
- QA test coverage / test evidence: — (owner-confirmed 2026-10-05)
- PRs: node-1.0.300...node-1.0.400 - PR #2238, PR #2243
- Engineering docs: —
- Migration guides: —
- SDK docs: —
- Known issues board: https://github.com/midnightntwrk/midnight-node/issues
- Public schema: https://github.com/midnightntwrk/midnight-node/blob/node-1.0.400/docs/openrpc.json
- API documentation: the node serves the same document at runtime through the
rpc.discoverJSON-RPC method.
Fixed defect list
| Defect number | Description |
|---|---|
| GHSA-wr7g-rr4v-jmj8 | Critical GHSA-wr7g-rr4v-jmj8: non-canonical field encodings (x + p) in contract call transcripts were accepted; fixed by ledger 8.1.3 (commit 8081e4b). |
| ledger 8.1.3 | noop 0 in a contract call transcript was accepted although not normalized (commit 8081e4b). |
| issue #2229 | A fresh mainnet sync halted at #1788979 with Intent TTL has expired (commit 5defaf5); follows up the v1 tblock correction from issue #1924. |
| commit 568b6f0 | Audit issues raised by the shx dev dependency in the toolkit's JS harness. |