Release Notes
This release is backwards-compatible with the existing v2.0.x series and is
not consensus-breaking. Nodes running v2.0.6, v2.0.7 and v2.0.8 can
coexist on the network. APP_VERSION is unchanged at 11. There is no upgrade
height and no coordination is needed.
Penumbra is now maintained by Rotko Networks. Releases are published from
rotkonetworks/penumbra.
New: pd migrate prune, chain-state pruning for node operators
pd now ships an offline pruning command that collapses the historical
versions of the Jellyfish Merkle Tree to the latest version. On mainnet this
reduces the pd database from roughly 350 GB to roughly 30 GB. The root hash
is unchanged and every pruned key is verified against it with range proofs
during the rebuild.
Measured on a copy of mainnet state at version 12,561,008: 350 GB to 30 GB in
59 minutes on a single core with 4.7 GB peak memory. The result was then run
under stock pd 2.0.6 and CometBFT 0.37.16, which handshook at the original
root hash and synced live mainnet blocks.
How to prune a validator
The node is fully offline while the prune runs. Both pd and CometBFT
must be stopped; the prune needs exclusive access to the database. Expect
about an hour on NVMe for a mainnet store, longer on slower disks. The node
resumes at the same height afterwards and catches up from peers.
Coordinate with other validators and do not prune at the same time. If
more than one third of voting power is offline, the chain stops producing
blocks. Before you start, check that no other validator is pruning and that
the network has comfortably more than two thirds of stake online without you.
If your validator alone holds more than one third of voting power, do not
prune at all. Stopping it halts the chain for the duration. Wait until stake
is spread further, or reduce your share first.
- Install the
pd2.0.8 binary (see below). It is a drop-in replacement. - Make sure at least 35 GB is free next to the
pddata directory. - Stop both services. CometBFT exits when its ABCI connection to
pdgoes
away, and under systemd it would otherwise crash-loop for the duration.sudo systemctl stop cometbft penumbra
- Run the prune as the user that owns the
pddata directory, with a raised
open-file limit.--homeis thepdhome, the directory that contains
rocksdb. Always pass it explicitly.The log ends withsudo -u penumbra bash -c 'ulimit -n 65536; pd migrate --home /path/to/node0/pd prune'JMT pruning complete root_hash=.... That root hash must
match the one printed at the start instarting JMT pruning. - Start
pdfirst, then CometBFT, and confirm the node is signing again.sudo systemctl start penumbra sudo systemctl start cometbft
- The unpruned database is kept at
<pd home>/rocksdb_old. Once the node has
been signing for a while, remove it to reclaim the space:A second prune refuses to run whilerm -rf /path/to/node0/pd/rocksdb_old
rocksdb_oldexists.
Options: --chunk-size N (default 100000) trades memory for proof work;
--delete-old-db removes rocksdb_old automatically instead of keeping it.
If the prune is interrupted, nothing is lost. Both pd migrate prune and
pd start detect an interrupted directory swap and print the exact command to
restore the database.
Who should prune
- Validators: yes. Consensus only reads the latest state version.
- RPC and archive nodes: preferably not. Pruning removes every historical
version of the state tree, so a pruned node can only serve state proofs from
the prune point onwards. IBC relayers query proofs at specific recent heights
and explorers may query state at a given height; point them at an unpruned
node. Rotko keepspenumbra.rotko.netunpruned for this reason. If you do
prune an RPC node, expect relayer queries to fail for the first minutes after
the prune, until new versions accumulate again.
What is not pruned, on purpose
- CometBFT's block store (about 65 GB on mainnet).
pdstill tells CometBFT to
retain every block.pdhas no state sync, so new nodes join by replaying
blocks from peers; if every node pruned its block store no new node could
ever join. Block retention will be enabled once state sync exists. pd's per-height transaction and compact block data, which wallets need to
sync. RPC operators must never prune these.
Expect a pruned validator to use about 90 GB in total. See docs/pruning.md
for the full policy.
Security: dependency advisories
cargo audit against the 2.0.7 lockfile reported 26 RustSec advisories. The
ones fixable without breaking changes on the Rust 1.83 toolchain this series
pins are patched in this release:
h20.4.7 to 0.4.19 (RUSTSEC-2026-0258, unbounded empty DATA frames). This is
the HTTP/2 implementation underpd's public gRPC endpoint, so it is the one
RPC operators should care about.bytes1.9.0 to 1.12.1 (RUSTSEC-2026-0007, integer overflow inreserve).openssl0.10.64 to 0.10.81 (RUSTSEC-2024-0357, 2025-0004, 2025-0022).ring0.17.8 to 0.17.14 (RUSTSEC-2025-0009).tar0.4.41 to 0.4.46 (RUSTSEC-2026-0067, 2026-0068).aws-lc-sys0.25.0 to 0.41.0 (RUSTSEC-2026-0045 to 0048); only used by the
optional--grpc-auto-httpsTLS termination.crossbeam-epoch0.9.18 to 0.9.21,tracing-subscriber0.3.18 to 0.3.20,
rustls0.23.21 to 0.23.23.
Still open, all requiring either a semver-breaking upgrade or a newer Rust
toolchain than 1.83, and tracked for the next release: rustls-webpki 0.101
and 0.102 (only reachable through --grpc-auto-https), h2 0.3 (legacy
hyper 0.14 path), time 0.3.44 (0.3.45+ needs cargo 1.85), idna 0.5,
tracing-subscriber 0.2 (via ledger-lib), and rsa 0.9 (no upstream fix;
not linked into pd).
CometBFT: run v0.37.18 or later. It fixes CSA-2026-001 (critical) and
ASA-2025-003. Note the 0.37.18 binary reports itself as 0.37.16.
Also in this release
pcli: honor--sourcewhen selecting positions inclose-alland
withdraw-all(from 2.0.7).cnidarium0.83.1, carried onrotkonetworks/cnidarium, adds the verified
pruning API. No existing storage or proof code path is modified.
pd 2.0.8
Install pd 2.0.8
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/rotkonetworks/penumbra/releases/download/v2.0.8/pd-installer.sh | shDownload pd 2.0.8
| File | Platform | Checksum |
|---|---|---|
| pd-aarch64-apple-darwin.tar.gz | Apple Silicon macOS | checksum |
| pd-x86_64-apple-darwin.tar.gz | Intel macOS | checksum |
| pd-aarch64-unknown-linux-gnu.tar.gz | ARM64 Linux | checksum |
| pd-x86_64-unknown-linux-gnu.tar.gz | x64 Linux | checksum |
summonerd 2.0.8
Install summonerd 2.0.8
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/rotkonetworks/penumbra/releases/download/v2.0.8/summonerd-installer.sh | shDownload summonerd 2.0.8
| File | Platform | Checksum |
|---|---|---|
| summonerd-aarch64-apple-darwin.tar.gz | Apple Silicon macOS | checksum |
| summonerd-x86_64-apple-darwin.tar.gz | Intel macOS | checksum |
| summonerd-aarch64-unknown-linux-gnu.tar.gz | ARM64 Linux | checksum |
| summonerd-x86_64-unknown-linux-gnu.tar.gz | x64 Linux | checksum |
pmonitor 2.0.8
Install pmonitor 2.0.8
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/rotkonetworks/penumbra/releases/download/v2.0.8/pmonitor-installer.sh | shDownload pmonitor 2.0.8
| File | Platform | Checksum |
|---|---|---|
| pmonitor-aarch64-apple-darwin.tar.gz | Apple Silicon macOS | checksum |
| pmonitor-x86_64-apple-darwin.tar.gz | Intel macOS | checksum |
| pmonitor-aarch64-unknown-linux-gnu.tar.gz | ARM64 Linux | checksum |
| pmonitor-x86_64-unknown-linux-gnu.tar.gz | x64 Linux | checksum |
pcli 2.0.8
Install pcli 2.0.8
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/rotkonetworks/penumbra/releases/download/v2.0.8/pcli-installer.sh | shDownload pcli 2.0.8
| File | Platform | Checksum |
|---|---|---|
| pcli-aarch64-apple-darwin.tar.gz | Apple Silicon macOS | checksum |
| pcli-x86_64-apple-darwin.tar.gz | Intel macOS | checksum |
| pcli-aarch64-unknown-linux-gnu.tar.gz | ARM64 Linux | checksum |
| pcli-x86_64-unknown-linux-gnu.tar.gz | x64 Linux | checksum |
pclientd 2.0.8
Install pclientd 2.0.8
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/rotkonetworks/penumbra/releases/download/v2.0.8/pclientd-installer.sh | shDownload pclientd 2.0.8
| File | Platform | Checksum |
|---|---|---|
| pclientd-aarch64-apple-darwin.tar.gz | Apple Silicon macOS | checksum |
| pclientd-x86_64-apple-darwin.tar.gz | Intel macOS | checksum |
| pclientd-aarch64-unknown-linux-gnu.tar.gz | ARM64 Linux | checksum |
| pclientd-x86_64-unknown-linux-gnu.tar.gz | x64 Linux | checksum |
elcuity 2.0.8
Install elcuity 2.0.8
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/rotkonetworks/penumbra/releases/download/v2.0.8/elcuity-installer.sh | shDownload elcuity 2.0.8
| File | Platform | Checksum |
|---|---|---|
| elcuity-aarch64-apple-darwin.tar.gz | Apple Silicon macOS | checksum |
| elcuity-x86_64-apple-darwin.tar.gz | Intel macOS | checksum |
| elcuity-aarch64-unknown-linux-gnu.tar.gz | ARM64 Linux | checksum |
| elcuity-x86_64-unknown-linux-gnu.tar.gz | x64 Linux | checksum |
pindexer 2.0.8
Install pindexer 2.0.8
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/rotkonetworks/penumbra/releases/download/v2.0.8/pindexer-installer.sh | shDownload pindexer 2.0.8
| File | Platform | Checksum |
|---|---|---|
| pindexer-aarch64-apple-darwin.tar.gz | Apple Silicon macOS | checksum |
| pindexer-x86_64-apple-darwin.tar.gz | Intel macOS | checksum |
| pindexer-aarch64-unknown-linux-gnu.tar.gz | ARM64 Linux | checksum |
| pindexer-x86_64-unknown-linux-gnu.tar.gz | x64 Linux | checksum |
picturesque 2.0.8
Install picturesque 2.0.8
Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/rotkonetworks/penumbra/releases/download/v2.0.8/picturesque-installer.sh | shDownload picturesque 2.0.8
| File | Platform | Checksum |
|---|---|---|
| picturesque-aarch64-apple-darwin.tar.gz | Apple Silicon macOS | checksum |
| picturesque-x86_64-apple-darwin.tar.gz | Intel macOS | checksum |
| picturesque-aarch64-unknown-linux-gnu.tar.gz | ARM64 Linux | checksum |
| picturesque-x86_64-unknown-linux-gnu.tar.gz | x64 Linux | checksum |