-
Notifications
You must be signed in to change notification settings - Fork 231
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request from GHSA-xqqc-c5gw-c5r5
* Add the is_matching_chain_id() predicate * Add TrustedBlockState::chain_id field * Implement matching chain-id check in verifier * Add test * Add test for verifier * Bump light client verifier and dependent crates to v0.28.0-pre.1 Signed-off-by: Thane Thomson <[email protected]> * Bump kvstore test light client dependency Signed-off-by: Thane Thomson <[email protected]> * Bump version to v0.28.0 Signed-off-by: Thane Thomson <[email protected]> * Add changelog entries for security fix Signed-off-by: Thane Thomson <[email protected]> * Prepare v0.28.0 release changelog Signed-off-by: Thane Thomson <[email protected]> * Rebuild changelog Signed-off-by: Thane Thomson <[email protected]> * Update release date in changelog Signed-off-by: Thane Thomson <[email protected]> Signed-off-by: Thane Thomson <[email protected]> Co-authored-by: Thane Thomson <[email protected]>
- Loading branch information
1 parent
60d003b
commit 5c32f31
Showing
30 changed files
with
210 additions
and
41 deletions.
There are no files selected for viewing
3 changes: 3 additions & 0 deletions
3
.changelog/v0.28.0/breaking/1249-light-client-verification-preds.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,3 @@ | ||
- `[tendermint-light-client-verifier]` Add `is_matching_chain_id` | ||
method to the `VerificationPredicates` trait | ||
([#1249](https://github.com/informalsystems/tendermint-rs/pull/1249)) |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,3 @@ | ||
- `[tendermint-light-client-verifier]` Add a | ||
`chain_id` field to the `TrustedBlockState` struct | ||
([#1249](https://github.com/informalsystems/tendermint-rs/pull/1249)) |
File renamed without changes.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,3 @@ | ||
- `[tendermint-light-client]` Fix an issue where the light client was not | ||
checking that the chain ID of the trusted and untrusted headers match | ||
([#1249](https://github.com/informalsystems/tendermint-rs/pull/1249)) |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,7 @@ | ||
*Dec 13, 2022* | ||
|
||
This is primarily a security-related release, and although it's a breaking | ||
release, the breaking changes are relatively minor. | ||
|
||
It is highly recommended that all tendermint-rs light client users upgrade to | ||
this version immediately. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,6 +1,6 @@ | ||
[package] | ||
name = "tendermint-abci" | ||
version = "0.27.0" | ||
version = "0.28.0" | ||
authors = ["Informal Systems <[email protected]>"] | ||
edition = "2018" | ||
license = "Apache-2.0" | ||
|
@@ -33,7 +33,7 @@ binary = [ | |
[dependencies] | ||
bytes = { version = "1.0", default-features = false } | ||
prost = { version = "0.11", default-features = false } | ||
tendermint-proto = { version = "0.27.0", default-features = false, path = "../proto" } | ||
tendermint-proto = { version = "0.28.0", default-features = false, path = "../proto" } | ||
tracing = { version = "0.1", default-features = false } | ||
flex-error = { version = "0.4.4", default-features = false } | ||
structopt = { version = "0.3", optional = true, default-features = false } | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,6 +1,6 @@ | ||
[package] | ||
name = "tendermint-light-client-js" | ||
version = "0.27.0" | ||
version = "0.28.0" | ||
authors = ["Informal Systems <[email protected]>"] | ||
edition = "2018" | ||
license = "Apache-2.0" | ||
|
@@ -22,8 +22,8 @@ default = ["console_error_panic_hook"] | |
[dependencies] | ||
serde = { version = "1.0", default-features = false, features = [ "derive" ] } | ||
serde_json = { version = "1.0", default-features = false } | ||
tendermint = { version = "0.27.0", default-features = false, path = "../tendermint" } | ||
tendermint-light-client-verifier = { version = "0.27.0", default-features = false, path = "../light-client-verifier" } | ||
tendermint = { version = "0.28.0", default-features = false, path = "../tendermint" } | ||
tendermint-light-client-verifier = { version = "0.28.0", default-features = false, path = "../light-client-verifier" } | ||
wasm-bindgen = { version = "0.2.63", default-features = false, features = [ "serde-serialize" ] } | ||
serde-wasm-bindgen = { version = "0.4.5", default-features = false } | ||
|
||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,6 +1,6 @@ | ||
[package] | ||
name = "tendermint-pbt-gen" | ||
version = "0.27.0" | ||
version = "0.28.0" | ||
authors = ["Informal Systems <[email protected]>"] | ||
edition = "2018" | ||
license = "Apache-2.0" | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,6 +1,6 @@ | ||
[package] | ||
name = "tendermint-proto" | ||
version = "0.27.0" | ||
version = "0.28.0" | ||
authors = ["Informal Systems <[email protected]>"] | ||
edition = "2018" | ||
license = "Apache-2.0" | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.