Skip to content

node-1.0.400

Latest

Choose a tag to compare

@github-actions github-actions released this 06 Oct 10:24
3acfd2e

node 1.0.400

Metadata

  • Release type: patch
    • Version delta 1.0.300 -> 1.0.400 leaves major and minor unchanged (commit 8081e4b).
  • Date: 2026-10-05 (owner-confirmed 2026-10-05)
  • Ships in bundle: — this release is not part of a bundle (owner-confirmed 2026-10-05)
  • Sister-line note: — (owner-confirmed 2026-10-05)
  • Environment: Preview, Preprod and Mainnet - the fix is already running on all three (owner-confirmed 2026-10-05)
  • Released artifact(s): https://github.com/midnightntwrk/midnight-node/releases/tag/node-1.0.400 - seven artifacts publish at this tag; see Artifacts below.
  • Component class: core/infra
  • Upgrade scope: binary only (detail under Deployment information)
  • Reset required: No (detail under Deployment information)
  • Governance action required: No - there is no runtime to enact (commit 8081e4b)

High-level summary

This is the public release of a security patch already deployed on Preview, Preprod and Mainnet (owner-confirmed 2026-10-05). It moves
the node's ledger 8 host functions to ledger 8.1.3, which fixes the critical advisory
GHSA-wr7g-rr4v-jmj8
and also rejects noop 0 in contract call transcripts (commit 8081e4b). It also fixes the mainnet fresh-sync halt at
block #1788979 that 1.0.300 listed as a known issue (commit 5defaf5, issue #2229). The upgrade is binary-only: the
on-chain runtime is untouched and spec_version stays 1_000_300 (commit 8081e4b).

Audience

These notes are for:

  • Validators and block producers on every network, who should move to this binary together.
  • Full Node Operators, in particular anyone syncing mainnet from genesis.
  • External integrators and dApp developers whose contract calls reach the ledger through the node.
  • The Midnight Foundation and Shielded Technologies engineering and SRE teams.

Dependencies

Component-local hard requirements:

  • Block producers should run the same ledger version. A node on ledger 8.1.3 rejects contract calls that a node on 8.1.2 accepts (commit 8081e4b).
  • Runs against the already-enacted 1.0.300 runtime (spec_version 1_000_300). The statically linked runtime is not used on mainnet, at all times the on chain runtime will be used. In this release no new on-chain runtime ships.

For every other interop question, see the bundle dependency matrix.

Downstream impact (cascading effects).

  • A contract call whose transcript carries a non-canonical field value, or noop 0, is rejected by 1.0.400 nodes as malformed, where earlier nodes accepted it (commit 8081e4b). Supported compactc and midnight-js output never produces these encodings, so dApp developers have nothing to change (owner-confirmed 2026-10-05).
  • The toolkit at this tag is built on the same ledger 8.1.3 crates, so it applies the same stricter rules when building or replaying transactions (commit 8081e4b).

Tested-with versions

Build pins read from the workspace manifest and Cargo.lock at the release commit: build pins — not QA-verified.

Component Tested-with version
midnight-ledger (v8) 8.1.3 (commit 3acfd2e)
midnight-ledger (v7) 7.0.3 (commit 3acfd2e)
midnight-zswap (v8 / v7) 8.1.3 / 7.0.3 (commit 3acfd2e)
midnight-onchain-runtime 3.1.2 (v8) / 2.0.1 (v7) (commit 3acfd2e)
midnight-onchain-state 3.0.2 (v8) / 2.0.1 (v7) (commit 3acfd2e)
midnight-onchain-vm 3.1.2 (v8) / 1.0.2 (v7) (commit 3acfd2e)
midnight-base-crypto 1.0.2 (commit 3acfd2e)
midnight-storage 2.0.3 (v8) / 1.1.1 (v7) (commit 3acfd2e)
polkadot-sdk polkadot-stable2603 (commit 3acfd2e)
compactc 0.30.0 (commit 3acfd2e)
partner-chains vendored in-tree, no released version pin (commit 3acfd2e)

Deployment information

  • Upgrade scope: binary only - a new node binary or image. spec_version stays 1_000_300 and the enacted runtime is unchanged (commit 8081e4b).
  • Reset required: No - no runtime, chain-spec or genesis file changed between 1.0.300 and this release (commit 3acfd2e). A node halted at #1788979 resumes importing once restarted on 1.0.400, with no resync (owner-confirmed 2026-10-05).
  • Governance action required: No - nothing to enact on chain (commit 8081e4b).
  • Downtime / coordination: Per-node binary swap with no runtime step, but block producers should switch together because 8.1.3 and 8.1.2 nodes disagree on which contract calls are well-formed (commit 8081e4b). On Preview, Preprod and Mainnet this has already happened (owner-confirmed 2026-10-05).

Artifacts

Binaries (sha256 from the release assets, cross-checked against SHA256SUMS):

  • midnight-node-1.0.400-linux-amd64.tar.gz - node binary, x86-64 (sha256:8098481824fa511d0a37554e44eaca524f5c74bced1885e5224cd90c0761914c, release body).
  • midnight-node-1.0.400-linux-arm64.tar.gz - node binary, arm64 (sha256:4724691ed0204b1b3ccb0541da9d72b6e35ae7f6f5db0435048744a7ff85447f, release body).
  • midnight-node-toolkit-1.0.400-linux-amd64.tar.gz - toolkit binary, x86-64 (sha256:b3a320218e68b9544a30f3670fee884686728fce036318385656476772236f74, release body).
  • midnight-node-toolkit-1.0.400-linux-arm64.tar.gz - toolkit binary, arm64 (sha256:dbdc8ce90bbb80c90c7590dcb228dd35f4115c107aadfe2f2b474025c240f3d6, release body).

Verification:

  • SHA256SUMS - checksum manifest for the four tarballs (sha256:3e4367b93a2ecbf7ba23b7ca4eb76e37dfd7901495ec3a08e40bb1cb44d86605, release body).

No runtime wasm or srtool-digest.json ships: the runtime is the 1.0.300 one already on chain (commit 8081e4b).

Images (Docker Hub digests):

  • midnightntwrk/midnight-node:1.0.400 - node image, multi-arch index sha256:915b117f955859a0ab7f34230ca12b43ef7474c84e29463256efcfc7b757040f; linux/amd64 sha256:cbb4dcfbf8bc628f6c246532a60496c55c9684237da15152dc5984a95b337b55, linux/arm64 sha256:eeaf8e3c5b6bb4a6eb53daa3d15c66e68e751014890fb76f42f3c021da7cebf5. Per-arch tags 1.0.400-amd64 and 1.0.400-arm64 carry the same digests.
  • midnightntwrk/midnight-node-toolkit:1.0.400 - toolkit image, multi-arch index sha256:b2d26c6759e9fba2402b362fa0180740178b0e41d8ab8a90b12619786dd561e3; linux/amd64 sha256:52ba1c3006e556a5ae7622446becdc52cf15fba944d12cc5c61f14cd0c71bf8b, linux/arm64 sha256:fb9a7fb008a03918dd17a11038a2b7c589afc97e36a7ad02562fd51470f67a3c. Per-arch tags 1.0.400-amd64 and 1.0.400-arm64 carry the same digests.

What changed

  • Node upgrade. Bump ledger 8 to 8.1.3: contract call transcripts must embed canonical field values, so a field atom encoding x + p is rejected in push, pushs and idx-style path keys - the fix for critical advisory GHSA-wr7g-rr4v-jmj8 (PR #2238, commit 8081e4b).
  • Node upgrade. Through the same bump, noop 0 in a contract call transcript is rejected as not normalized (commit 8081e4b).
  • Node upgrade. Crate versions after the bump: midnight-ledger and midnight-zswap 8.1.3, midnight-onchain-runtime 3.1.2, midnight-onchain-state 3.0.2, midnight-onchain-vm 3.1.2, midnight-base-crypto 1.0.2. The midnight-base-crypto change is additive only, so ledger 7, which shares it, is unaffected (commit 8081e4b).
  • Node upgrade. When a historical block's first ledger transaction fails well_formed at the corrected tblock (parent block time + 12 s), retry it at the block's own tblock. This unblocks a fresh mainnet sync that halted at #1788979 with Intent TTL has expired; the retry is only reachable under host-function v1, so it never applies to blocks after the v2 runtime upgrade at mainnet #2738210 (commit 5defaf5).
  • Node upgrade. Regression tests for that retry, including a fixture of mainnet block #1788980's first transaction (commit e913d44, commit 28edf6a).
  • Housekeeping: version bumps across the workspace and docs/openrpc.json (commit 8081e4b), axios and brace-expansion lockfile bumps in the local test environment (commit 568b6f0), and a CI workflow permissions fix (PR #2243).
  • Toolkit. Drop the shx dev dependency from the toolkit's JS harness, which was raising audit issues (commit 568b6f0).

New features

None.

New features requiring configuration updates

None - no config preset, chain spec or node-config key changed between 1.0.300 and this release (commit 3acfd2e).

Improvements

None.

Deprecations

None.

Breaking changes

Breaking change stricter contract call well-formedness

What changed: Ledger 8.1.3 narrows what counts as a well-formed contract call. A field atom encoding x + p (where p is the field modulus) in push, pushs or idx-style path keys, and noop 0, are now rejected (commit 8081e4b).

What breaks: A contract call carrying either is rejected as malformed by a 1.0.400 node, where a 1.0.300 node accepted it. Block producers on mixed versions would disagree on such calls (commit 8081e4b).

Required actions: operators and developers have separate steps.

  • Operators: move every block producer onto 1.0.400 together (commit 8081e4b).
  • Developers: nothing to do - supported compactc and midnight-js output never produces these encodings (owner-confirmed 2026-10-05).

Code example: — none applies; this is a validity rule, not an API migration.

Known issues

None (owner-confirmed 2026-10-05).

Links and references

Fixed defect list

Defect number Description
GHSA-wr7g-rr4v-jmj8 Critical GHSA-wr7g-rr4v-jmj8: non-canonical field encodings (x + p) in contract call transcripts were accepted; fixed by ledger 8.1.3 (commit 8081e4b).
ledger 8.1.3 noop 0 in a contract call transcript was accepted although not normalized (commit 8081e4b).
issue #2229 A fresh mainnet sync halted at #1788979 with Intent TTL has expired (commit 5defaf5); follows up the v1 tblock correction from issue #1924.
commit 568b6f0 Audit issues raised by the shx dev dependency in the toolkit's JS harness.