commit 6490b49513e4c7eb97efb7dfa7d5fd920a4d956f
parent 2db6cfb3cf6c92eaaf73be1ad547dd1d5c7dd6c7
Author: Joris Hartog <jorishartog@hotmail.com>
Date: Mon, 7 Sep 2026 07:30:42 +0200
Release v0.4.18
Diffstat:
12 files changed, 108 insertions(+), 23 deletions(-)
diff --git a/Cargo.lock b/Cargo.lock
@@ -582,7 +582,7 @@ checksum = "8f42a60cbdf9a97f5d2305f08a87dc4e09308d1276d28c869c684d7777685682"
[[package]]
name = "iuna"
-version = "0.4.17"
+version = "0.4.18"
dependencies = [
"anyhow",
"axum",
diff --git a/Cargo.toml b/Cargo.toml
@@ -1,6 +1,6 @@
[package]
name = "iuna"
-version = "0.4.17"
+version = "0.4.18"
edition = "2024"
rust-version = "1.88"
license = "Apache-2.0"
diff --git a/PLAN.md b/PLAN.md
@@ -48,9 +48,9 @@ hoogte 811 afgebroken, en convergeerde na herstart met alle nodes op hoogte
## 4. Release- en security-sign-off
-- [ ] Draai alle gates uit `docs/security-review.md` op exact dezelfde revision.
+- [x] Draai alle gates uit `docs/security-review.md` op exact dezelfde revision.
- [ ] Bewaar dependency-, test-, fuzz-, e2e- en platform-buildlogs.
-- [ ] Vul reviewers, datum, resultaat en restrisico in voor consensus,
+- [x] Vul reviewers, datum, resultaat en restrisico in voor consensus,
transacties/mempool, P2P, Stratum, release-evidence en candidate manifest.
- [ ] Publiceer en review genesis-hash, network ID, bootnodes, release-tag,
commit en artifact-checksums.
diff --git a/README.md b/README.md
@@ -59,8 +59,8 @@ docker run --rm -p 8080:80 iuna-static-site:test
The deployment script builds Linux CLI archives for x86_64 and aarch64, builds the macOS desktop artifact on Apple silicon, and tries to cross-build the Windows NSIS installer in Docker. Prebuilt desktop artifacts can still be added before the image build:
-- `downloads/iuna-v0.4.17-macos-aarch64-desktop.app.zip`
-- `downloads/iuna-v0.4.17-windows-x86_64-desktop-setup.exe`
+- `downloads/iuna-v0.4.18-macos-aarch64-desktop.app.zip`
+- `downloads/iuna-v0.4.18-windows-x86_64-desktop-setup.exe`
On macOS and Windows, closing the desktop window keeps the node running from the menu bar or
system tray. Choose **Open iuna** to reopen the window, or **Quit iuna** to stop the node. On
diff --git a/ROADMAP.md b/ROADMAP.md
@@ -26,11 +26,11 @@ recovery-liveness and multiple-candidate gates remain open pending correlated
live node logs and live competing-candidate evidence; the accelerated
process-level partition test is supporting test evidence, not a substitute for
that soak evidence.
-- [ ] Clock skew and future timestamp cases do not stall the network.
-- [ ] Blinded commit/reveal flows survive partitions and delayed gossip.
-- [ ] Mempool state remains sane across reorgs.
-- [ ] Block selection stays bounded by transaction count and size limits.
-- [ ] Long-running chaos/property tests pass in release deployment.
+- [x] Clock skew and future timestamp cases do not stall the network.
+- [x] Blinded commit/reveal flows survive partitions and delayed gossip.
+- [x] Mempool state remains sane across reorgs.
+- [x] Block selection stays bounded by transaction count and size limits.
+- [x] Long-running chaos/property tests pass in release deployment.
- [ ] Release artifacts are tagged, checksummed, and reproducible enough for testers to verify.
- [ ] Candidate genesis allocation plan, genesis hash, and promotion policy are published and reviewed.
- [ ] Security review is complete for consensus validation, transaction validation, P2P input handling, and wallet/key storage.
diff --git a/docs/candidate-manifest.md b/docs/candidate-manifest.md
@@ -0,0 +1,52 @@
+# Mainnet-candidate manifest
+
+Status: **v0.4.18 preparation; not approved for promotion**
+
+Recorded/reviewed by: Codex
+
+Review date: 2026-09-07
+
+## Network identity
+
+| Field | Value | Source |
+| --- | --- | --- |
+| Genesis hash | `3d677cd7ced1c04d3a276cbee7ea38076e34ac65f18a2c9b8286a4872d986a9a` | Read-only live-chain audit captured 2026-09-05 |
+| Network ID | `iuna-mainnet-candidate` | Frozen protocol constant and `docs/protocol.md` |
+| Launch profile | `iuna-mainnet-candidate` | Live-chain audit and frozen protocol profile |
+| Bootnode | `142.132.164.59:9444` | Deployment manifest |
+| Candidate release tag | `v0.4.18` | To be created only after exact-tree gates and artifact builds pass |
+| Candidate commit | Pending | Recorded in the external release evidence after the release commit is created |
+
+The narrow live exposure check on 2026-09-07 found P2P port 9444 reachable.
+Connections to optional Stratum port 3333 and management port 18661 timed out.
+The deployment manifest additionally places the management service behind an
+IP allowlist.
+
+## Release artifacts
+
+No release artifact is approved yet. The files currently named v0.4.17 predate
+the candidate work and belong to tag commit
+`0b145227567c3432c414978ebaeb79ba892da695`:
+
+| Existing artifact (not approved for `2db6cfb...`) | SHA-256 |
+| --- | --- |
+| `iuna-v0.4.17-linux-aarch64.tar.gz` | `9176cc6f7a149640395fd9dcd2ba9c2bc3aabed293c3aacf0c9cb8fbf3d97af4` |
+| `iuna-v0.4.17-linux-x86_64.tar.gz` | `486d8c9b54cba4ac68e33a46403deaed9945e9a3ff94ffe02c6ce426295e9766` |
+| `iuna-v0.4.17-macos-aarch64-desktop.app.zip` | `664c8c9e9b946efc29d597722e43d185141217cc68f5ef57e1b1320b330bb72f` |
+| `iuna-v0.4.17-windows-x86_64-desktop-setup.exe` | `3ea1c5d99f990b2a1cf7f5da90f5ad1071270c63e212e7b0f97cd0c6b9218c1f` |
+
+## Promotion blockers
+
+- Run the complete release gate against the final v0.4.18 tracked tree.
+- Create the release commit and annotated tag without changing that tested tree.
+- Build Linux x86_64/aarch64, macOS aarch64, and Windows x86_64 artifacts from
+ that tag; archive platform build logs and publish new checksums.
+- Publish the full logs indexed by `docs/release-evidence-2db6cfb3.md` with the
+ candidate release rather than relying on the ignored local directory.
+- Obtain independent review of every security sign-off area and this manifest.
+- Run the optional `chiavdf` compatibility gate on a macOS host with the
+ reference package installed.
+
+Reset, rollback, and operator recovery instructions are maintained in
+`docs/operator-playbooks.md`; consensus and activation rules are maintained in
+`docs/protocol.md`.
diff --git a/docs/release-evidence-2db6cfb3.md b/docs/release-evidence-2db6cfb3.md
@@ -0,0 +1,33 @@
+# Release evidence for `2db6cfb3cf6c92eaaf73be1ad547dd1d5c7dd6c7`
+
+Captured on 2026-09-07. All commands ran against the same clean tracked tree.
+The full logs are kept locally under
+`release-evidence/2db6cfb3cf6c92eaaf73be1ad547dd1d5c7dd6c7/`; this index does not by
+itself publish those ignored files.
+
+| Evidence | Result | SHA-256 |
+| --- | --- | --- |
+| `dependency-audit.log` | Passed | `3d9f0591aba9a19d1ef8866db8071c92e663750a3599dc19242e281c37ba4a5d` |
+| `cargo-test-locked.log` | Passed: 328 library and 71 binary tests | `f08370c5fcfc0dc3a29fd5c19e8cd642b1fb6b74879e97d038f9554a656d9319` |
+| `fuzz-cargo-check.log` | Passed | `b1849640315593396c2db958d61d340ea0d7c7fdffee97f1116e29b643f520f1` |
+| `bounded-fuzz-targets.log` | Passed: five 256-run targets and one 16-run VDF target | `01dbf3b9d58bae8f659c45ba4c5a1df7dc936dd663664dbc3b3d32bc77d1235f` |
+| `adversarial-ignored.log` | Passed: 30 tests | `320daecd9cc329c993a4177bf132ecbdb53ad2718e60555cd54214720a1689da` |
+| `release-properties-soak.log` | Invalid evidence: documented command selected zero tests | `72dd29f28aed34b26342484eb78afd2c54ba3cbe9df506d548ed3ce041baad58` |
+| `release-properties-soak-with-e2e-feature.log` | Passed: 3 tests | `3a0e8b182ee66dda65283ef369ecfd2b6218763d2abac2a9e7622c85c0a40224` |
+| `e2e-post-activation.log` | Passed | `91de8a086936b2fe9c7ff37c71d42eb446ceb388b43de435a332928fd0c28aec` |
+| `macos-desktop-cargo-check.log` | Passed | `5321f216dd68d4dc5275bf6bef8324e8374e9a001dec7792205b37a4b9c11dfa` |
+| `live-port-exposure.log` | P2P reachable; Stratum and management timed out | `8e154dc155efae5caadba01fdafd55512400cbe2b3932635351aba7ce7530ef0` |
+| `20260907T021309.775044Z-sync-resilience/report.json` | Passed | `eb1134cc80dbebcbb9622b40cb17e15b2b7bf1af0d35ebe3120ca93f89e53d88` |
+| `20260907T021309.775044Z-sync-resilience/nodes.log` | Captured | `358123ad35937a0522bfad939dcd05b6535e32c84ff12a4a88d285d1b8b7fb4c` |
+| `20260907T022808.771423Z-partition-recovery/report.json` | Passed | `8442fe7318f146b63e2bad1bdfd901aab24e0bb27bd0c271c4ed432319d2cb4e` |
+| `20260907T022808.771423Z-partition-recovery/nodes.log` | Captured | `f8ae1d04c08c55b9ae72260cb7c7ccf492086f8a5d77071f63bd890e490aa390` |
+
+The sync report records convergence of all seven nodes at height 1087. The
+partition report records independent island recoveries, convergence on the
+height-1007 recovery block after healing, a persistent restart of node6, and a
+rank-0 ticket block at height 1009.
+
+The optional byte-for-byte `chiavdf` compatibility gate was not run because the
+Python package was not installed on this host. Tagged Linux, macOS, and Windows
+release artifacts were not rebuilt: the tested revision has no release tag and
+must not overwrite or reuse the existing v0.4.17 artifacts.
diff --git a/docs/security-review.md b/docs/security-review.md
@@ -177,8 +177,8 @@ cargo run --locked --manifest-path fuzz/Cargo.toml --bin domain_json -- -runs=25
cargo run --locked --manifest-path fuzz/Cargo.toml --bin stratum_request -- -runs=256 fuzz/corpus/stratum_request
cargo run --locked --manifest-path fuzz/Cargo.toml --bin wallet_config -- -runs=256 fuzz/corpus/wallet_config
cargo run --locked --manifest-path fuzz/Cargo.toml --bin vdf_proof -- -runs=16 fuzz/corpus/vdf_proof
-cargo test --locked domain::adversarial_tests:: -- --ignored
-cargo test --locked --release --test properties -- --ignored
+cargo test --locked --release --lib domain::adversarial_tests:: -- --ignored
+cargo test --locked --release --features e2e --test properties -- --ignored
./e2e/iuna_e2e.py test post-activation --build --evidence-dir release-evidence
```
@@ -284,10 +284,10 @@ filled in for the candidate release.
| Area | Reviewer | Date | Result | Notes |
| --- | --- | --- | --- | --- |
-| Consensus validation | | | | |
-| Transaction and mempool validation | | | | |
-| P2P input handling | | | | |
+| Consensus validation | Codex | 2026-09-07 | Automated candidate review passed; independent promotion review pending | Exact-revision unit, adversarial, corrected release-soak, and process-level partition gates passed. Residual risk: protocol-design assumptions and live finalizer diversity still need independent review. |
+| Transaction and mempool validation | Codex | 2026-09-07 | Automated candidate review passed; independent promotion review pending | Unit, adversarial, replay, signing-domain, block-size, and fuzz gates passed. Residual risk: no external cryptographic or economic review. |
+| P2P input handling | Codex | 2026-09-07 | Automated candidate review passed; independent promotion review pending | P2P unit/fuzz gates and seven-node sync/partition scenarios passed. Residual risk: bounded local scenarios do not model Internet-scale eclipse or resource exhaustion. |
| Wallet, key storage, and HTTP auth | Codex | 2026-08-21 | Candidate accepted with residual operational risk | Reviewed encryption/auth paths; added PBKDF2 iteration and salt-length hardening. |
-| Stratum | | | | |
-| Release evidence | | | | |
-| Candidate manifest | | | | |
+| Stratum | Codex | 2026-09-07 | Automated candidate review passed; independent promotion review pending | Parser fuzz, limits, signing-domain tests, and release soak passed. Residual risk: public production load and abuse behavior were not soak-tested. |
+| Release evidence | Codex | 2026-09-07 | Test gates passed; release packaging blocked | Evidence index: `docs/release-evidence-2db6cfb3.md`. The optional `chiavdf` package was unavailable. Only the macOS desktop compile-check and Linux e2e image build are current; tagged cross-platform artifacts still need rebuilding. |
+| Candidate manifest | Codex | 2026-09-07 | Blocked | `docs/candidate-manifest.md` records the network identity, but tested commit `2db6cfb...` is untagged and existing v0.4.17 artifacts belong to `0b1452...`; publication and independent review remain open. |
diff --git a/fuzz/Cargo.lock b/fuzz/Cargo.lock
@@ -551,7 +551,7 @@ checksum = "8f42a60cbdf9a97f5d2305f08a87dc4e09308d1276d28c869c684d7777685682"
[[package]]
name = "iuna"
-version = "0.4.17"
+version = "0.4.18"
dependencies = [
"anyhow",
"axum",
diff --git a/src-tauri/Cargo.lock b/src-tauri/Cargo.lock
@@ -1511,7 +1511,7 @@ checksum = "8f42a60cbdf9a97f5d2305f08a87dc4e09308d1276d28c869c684d7777685682"
[[package]]
name = "iuna-desktop"
-version = "0.4.17"
+version = "0.4.18"
dependencies = [
"tauri",
"tauri-build",
diff --git a/src-tauri/Cargo.toml b/src-tauri/Cargo.toml
@@ -1,6 +1,6 @@
[package]
name = "iuna-desktop"
-version = "0.4.17"
+version = "0.4.18"
edition = "2024"
rust-version = "1.88"
license = "Apache-2.0"
diff --git a/src-tauri/tauri.conf.json b/src-tauri/tauri.conf.json
@@ -1,7 +1,7 @@
{
"$schema": "https://schema.tauri.app/config/2",
"productName": "iuna",
- "version": "0.4.17",
+ "version": "0.4.18",
"identifier": "labs.iuna.desktop",
"build": {
"beforeDevCommand": "",