Skip to content

Release v0.43.0 - #11402

Draft
lidel wants to merge 56 commits into
releasefrom
release-v0.43.0
Draft

Release v0.43.0#11402
lidel wants to merge 56 commits into
releasefrom
release-v0.43.0

Conversation

@lidel

@lidel lidel commented Jul 22, 2026

Copy link
Copy Markdown
Member

lidel and others added 30 commits May 27, 2026 15:32
* chore(deps): bump github.com/ipshipyard/p2p-forge

Bumps the ipfs-ecosystem group with 1 update in the / directory: [github.com/ipshipyard/p2p-forge](https://github.com/ipshipyard/p2p-forge).


Updates `github.com/ipshipyard/p2p-forge` from 0.8.0 to 0.9.0
- [Release notes](https://github.com/ipshipyard/p2p-forge/releases)
- [Changelog](https://github.com/ipshipyard/p2p-forge/blob/main/CHANGELOG.md)
- [Commits](ipshipyard/p2p-forge@v0.8.0...v0.9.0)

---
updated-dependencies:
- dependency-name: github.com/ipshipyard/p2p-forge
  dependency-version: 0.8.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ipfs-ecosystem
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore: run make mod_tidy

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Fork builds previously announced as plain `kubo/<ver>/<commit>`,
indistinguishable from upstream in ecosystem dashboards. When
`Version.AgentSuffix` and `--agent-version-suffix` are both unset,
kubo now derives a default from the build origin so fork traffic
self-identifies in the swarm.

- mk/git.mk, cmd/ipfs/Rules.mk: normalize `git remote get-url origin`
  to `host/org/repo` and inject as `buildOrigin` ldflag
- version.go: ImplicitAgentSuffix prefers buildOrigin, falls back to
  debug.ReadBuildInfo Main.Path; suffixFromForkPath strips known
  forges (github, gitlab, codeberg, bitbucket) and trailing `/kubo`
- cmd/ipfs/kubo/daemon.go: use as fallback when explicit values empty
- AGENTS.md: state builds must use `make build` so ldflags are set
- docs/config.md: document the implicit-suffix behavior

Co-authored-by: Guillaume Michel <guillaumemichel@users.noreply.github.com>
* fix(libp2p): quieter dead-listener check

Scope the v0.42 dead-listener ERROR to explicit listens in
Addresses.Swarm: a server-profile node with default `/ip4/0.0.0.0`
and `/ip6/::` listens otherwise logged ERROR for every loopback,
Docker bridge, ULA, or other private interface the wildcard
expanded into, drowning the actual gotcha (a `/ip4/127.0.0.1/tcp/.../ws`
listener fronted by a local reverse proxy).

Log routing:

- AddrFilters + explicit listen: ERROR (whole listener unreachable).
- AddrFilters + wildcard expansion: DEBUG (other interfaces still
  serve).
- NoAnnounce match: DEBUG (operator intent, useful when tracing
  identify or DHT contents).

* fix(libp2p): match explicit listens by full addr

Explicit-ness keyed on the listener IP alone, so a wildcard listen
expanding onto an interface whose IP was also bound explicitly on
another port (server profile plus a /ip4/127.0.0.1/.../ws reverse
proxy) was logged as a spurious ERROR. Match the full resolved
multiaddr instead: InterfaceListenAddresses echoes a specific-IP
listen verbatim while a wildcard never resolves to itself.

* fix(libp2p): match explicit listens by socket

Classify a dead listener as explicit by its bound socket (IP, transport,
port) instead of the full multiaddr string. A listener is reported under a
different multiaddr than its Addresses.Swarm entry once a transport
rewrites trailing components: WebTransport appends /certhash, WebSocket
turns /wss into /tls/ws. The string compare missed these and silently
downgraded the affected explicit listeners from ERROR to DEBUG, hiding the
reverse-proxy gotcha the check exists to surface.

The transport is part of the key because TCP and QUIC share a port number
by default (4001), so a pinned QUIC listener must not promote the same-port
TCP wildcard expansion to ERROR.
* chore: bump boxo to test ipfs/boxo#1166

Bumps github.com/ipfs/boxo to the tip of fix/ipns-cache-control-expiry
(55fd621d1872) to exercise the IPNS cache-control/TTL/EOL fixes from
ipfs/boxo#1166. Root, docs/examples, and test/dependencies modules
tidied via make mod_tidy.

Signed-off-by: Marcin Rataj <lidel@lidel.org>

* fix: validate ipns lifetime and ttl settings

ipfs name publish now sanitizes its duration flags instead of emitting
a record that fails verification later: a non-positive --lifetime and a
negative --ttl are rejected, an explicit --ttl over --lifetime is
rejected, and an omitted --ttl is capped to --lifetime. The --lifetime
and --ttl defaults are applied server-side so an explicit value is
distinguishable from the default.

The daemon also refuses to start when Ipns.RecordLifetime is shorter
than Ipns.RepublishPeriod, which would let records expire before they
are republished.

Signed-off-by: Marcin Rataj <lidel@lidel.org>

* switch to boxo@main with fix #1166

---------

Signed-off-by: Marcin Rataj <lidel@lidel.org>
Co-authored-by: gammazero <11790789+gammazero@users.noreply.github.com>
boxo's Traverse already dedups each root with its own seen set, so the
command-level cid.Set held a second copy of every CID in the DAG. On a
multi-hundred-GiB root that doubled the dedup memory and OOM-killed
daemons mid-stat.

- allocate the set only for multiple roots (cross-root dedup needs it)
- single root derives UniqueBlocks from the per-root block count
Detect carrier-grade or double NAT at startup and log a one-time stderr
notice, turning the recurring "running IPFS kills my home internet"
symptom into a clear cause: a busy node fills the ISP's shared NAT table.

- classify host addresses; a private or shared (RFC 6598 100.64.0.0/10)
  NAT-mapped WAN address that is not a local interface means CGNAT or
  double NAT. overlay addresses on a local interface (tailscale, zerotier)
  and publicly reachable nodes are ignored, so the notice stays quiet.
- add Internal.CGNATCheck and Internal.DeadListenerCheck (both default
  true) to silence the CGNAT notice and the v0.42 dead-listener check.
- expose the classification as the nat field of ipfs swarm addrs autonat.
- docs: config.md entries and v0.43 changelog highlight.

Closes #11326

Co-authored-by: Andrew Gillis <11790789+gammazero@users.noreply.github.com>
* chore: upgrade to boxo v0.41.0
* use tagged release
)

Bumps [github.com/tidwall/gjson](https://github.com/tidwall/gjson) from 1.18.0 to 1.19.0.
- [Commits](tidwall/gjson@v1.18.0...v1.19.0)

---
updated-dependencies:
- dependency-name: github.com/tidwall/gjson
  dependency-version: 1.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* docs: optimistic provide is on by default

Optimistic provide has been enabled by default since v0.39, when the
sweep provider became the default, so it has not really been off for
typical nodes. Rewrite the State section in plain language, note that
the Experimental.OptimisticProvide flag only affects the legacy
provider, and link the ProbeLab explainer.

* docs: use non-default ports for experiments

Manual experiments and benchmark daemons must bind non-default ports and
use their own IPFS_PATH so they do not collide with a node already
running on the defaults (4001/5001/8080).
Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 6.0.1 to 7.0.0.
- [Release notes](https://github.com/codecov/codecov-action/releases)
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)
- [Commits](codecov/codecov-action@e79a696...fb8b358)

---
updated-dependencies:
- dependency-name: codecov/codecov-action
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…lang-x group across 1 directory (#11346)

* chore(deps): bump golang.org/x/crypto

Bumps the golang-x group with 1 update in the / directory: [golang.org/x/crypto](https://github.com/golang/crypto).


Updates `golang.org/x/crypto` from 0.51.0 to 0.52.0
- [Commits](golang/crypto@v0.51.0...v0.52.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-version: 0.52.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: golang-x
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore: run make mod_tidy

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Andrew Gillis <11790789+gammazero@users.noreply.github.com>
* fix(l1): return error instead of log.Fatal in HolePunching

Signed-off-by: reflecttypefor <reflecttypefor@outlook.com>

* test: cover HolePunching flag combinations

* docs: highlight clearer hole punching error

The Changelog section is generated at release time, so hand-written
notes belong under Highlights instead.

---------

Signed-off-by: reflecttypefor <reflecttypefor@outlook.com>
Co-authored-by: Marcin Rataj <lidel@lidel.org>
Pulls the AutoTLS DNS-01 registration fix: the client now keeps a
cookie jar so a load-balanced forge endpoint (registration.libp2p.direct)
keeps both PeerID-auth requests on one backend, instead of the second
request hitting a backend that never issued the challenge and failing
with a 401.
* commands: derive peer ID on config replace

Signed-off-by: morning-verlu <258725120+morning-verlu@users.noreply.github.com>

* feat: validate Identity.PeerID against node key

Setting Identity.PeerID to a value that disagrees with the node's
private key produces a config the node refuses to start with. The
config command now validates the field against the stored key, the
same way config replace re-derives it.

- reject a mismatched Identity.PeerID and point at `ipfs key rotate`;
  accept the node's own PeerID in any base58 or CIDv1 form and store
  the canonical base58 string
- share the PeerID derivation between the set path and config replace
- document the identity fields and `ipfs key rotate` in docs/config.md
- cover the set-path guard and base36 normalization in test/cli
- switch the t0070 sharness probe off Identity.PeerID, now validated

---------

Signed-off-by: morning-verlu <258725120+morning-verlu@users.noreply.github.com>
Co-authored-by: morning-verlu <258725120+morning-verlu@users.noreply.github.com>
Co-authored-by: Guillaume Michel <guillaumemichel@users.noreply.github.com>
Co-authored-by: Andrew Gillis <11790789+gammazero@users.noreply.github.com>
Co-authored-by: Marcin Rataj <lidel@lidel.org>
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/cache](https://github.com/actions/cache) from 5 to 6.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v5...v6)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* test: cover ipfs get paths containing closing bracket

* test: move get punctuation coverage to test/cli

ipfs get must retrieve UnixFS paths whose segments contain
punctuation that is valid on Linux, macOS, and Windows but is
sensitive to a POSIX shell (issue #9369, where a "]" segment
failed). AGENTS.md prefers test/cli for new integration tests,
and driving ipfs directly avoids the shell-quoting limits of the
sharness loop.

- add test/cli/get_test.go: add a directory with one file per
  segment, then get each "<cid>/<segment>" and compare bytes,
  exercised both offline and against a daemon
- cover the apostrophe segment, which the single-quoted sharness
  test body could not include
- drop the now-redundant punctuation block from t0090-get.sh

---------

Co-authored-by: Guillaume Michel <guillaumemichel@users.noreply.github.com>
Co-authored-by: Marcin Rataj <lidel@lidel.org>
* fix(daemon): return config errors instead of calling log.Fatal

Signed-off-by: blackflytech <blackflytech@outlook.com>

* Update cmd/ipfs/kubo/daemon_config_test.go

---------

Signed-off-by: blackflytech <blackflytech@outlook.com>
Co-authored-by: Andrew Gillis <11790789+gammazero@users.noreply.github.com>
The hole-punching and daemon-config highlights describe the same
user-facing change, a named startup error instead of an abrupt exit,
so fold them into one entry and drop the internal `log.Fatal` wording.
* feat: make telemetry opt-in

Telemetry no longer runs by default. It stays off unless an operator
sets the mode to `on` and configures an `Endpoint`, and Kubo ships with
no built-in telemetry URL, so a default node never phones home.

- plugin: default mode is off; the legacy `auto` and any unrecognized
  value also stay off
- plugin: the implicit default does no work, not even disk IO; only an
  explicit `off` removes a stored telemetry identifier
- plugin: enabling without an endpoint warns and sends nothing; the
  destination comes only from config
- docs: note the opt-in default in the `IPFS_TELEMETRY` reference, the
  plugins table, and the changelog
- tests: cover off-by-default, the auto alias, missing-endpoint, and
  explicit opt-out cleanup, and opt in where the send path runs

* docs: rewrite telemetry.md for opt-in

Rework the telemetry page around the opt-in plugin: how to enable it and
point it at your own collector, the modes and config reference, the HTTP
endpoint API and payload schema, and the privacy model. Match the
plainer style of the sibling docs, with no emoji headers and a table of
contents.

* chore(telemetry): log opt-in enable event

Log when telemetry is enabled, since that's the notable event. The
opt-out branch already logs UUID removal, so the redundant disable
log is dropped.

Co-authored-by: Andrew Gillis <11790789+gammazero@users.noreply.github.com>

---------

Co-authored-by: Andrew Gillis <11790789+gammazero@users.noreply.github.com>
* feat: accept native ipfs:// and ipns:// URIs

Commands that take a content path or CID now also accept native IPFS
URIs (ipfs://cid, ipns://name, and the schemeless ipfs:/ipns: forms),
so a URI copied from a browser or another tool works as-is.

- cmdutils: PathOrCidPath parses via boxo NewPathFromURI; new
  CidFromArg for raw-CID commands takes the root CID and rejects
  sub-paths and mutable IPNS.
- files: cp/stat sources and getNodeFromPath accept URIs and content
  paths; chroot takes its CID via CidFromArg.
- resolve and name resolve normalize URIs before the namespace checks;
  name resolve stays IPNS-only.
- routing, provide, filestore, pin remote: raw-CID args via CidFromArg.

Depends on boxo NewPathFromURI (ipfs/boxo#1182); go.mod pins the PR
commit until it is released.

* depend on boxo@main

* test: fix telemetry opt-out assertions

#11374 made telemetry opt-in and rewrote the explicit "off" mode to no
longer log "telemetry disabled via opt-out", but the opt-out subtests
still assert that string, so TestTelemetry is red on master. Assert the
"telemetry collection skipped: opted out" message the daemon emits
whenever telemetry is off.

* ci: inject .aegir.js for helia interop

@helia/interop v11.0.0+ ships without .aegir.js (ipfs/helia#1049), so
aegir test finds no specs and the interop job fails. Inject a minimal
config pointing at the prebuilt dist specs when it is missing.

Helia's own .aegir.js can't be reused as-is: it globs source .ts specs
that Node won't run from node_modules. The same omission regressed
before (ipfs/helia#1001, fixed by ipfs/helia#1003); see the comment.

* ci: force mocha exit after helia interop run

The node interop specs leave kubo daemon and libp2p handles open, so
mocha prints "N passing" and then hangs until the job timeout instead
of exiting. Pass --exit so mocha quits once the run completes.

---------

Co-authored-by: Andrew Gillis <11790789+gammazero@users.noreply.github.com>
* chore(deps): bump go-libp2p-kad-dht to v0.41.0

Cuts peak memory during reprovides on nodes announcing many CIDs, so
low-memory consumer devices are less likely to be out-of-memory killed
(libp2p/go-libp2p-kad-dht#1259). Pulls quic-go v0.59.1 transitively.

* chore: tidy secondary go modules for kad-dht 0.41

* ci: fix helia-interop for @helia/interop 11.0.3

The .aegir.js restored upstream in ipfs/helia#1066 globs the TypeScript
sources, which node refuses to run from inside node_modules, so the
inject-if-missing workaround skipped it and the job failed. Replace the
config whenever it is missing or globs .ts files, and leave a usable one
untouched so the step self-heals once upstream ships a node_modules-safe
config.

Also drop the IPIP-499 --grep/--invert exclusion: helia implemented the
missing MFS features (ipfs/helia#972) and the test passes now.
#11380)

* chore(deps): bump the golang-x group across 1 directory with 5 updates

Bumps the golang-x group with 2 updates in the / directory: [golang.org/x/crypto](https://github.com/golang/crypto) and [golang.org/x/mod](https://github.com/golang/mod).


Updates `golang.org/x/crypto` from 0.52.0 to 0.53.0
- [Commits](golang/crypto@v0.52.0...v0.53.0)

Updates `golang.org/x/mod` from 0.36.0 to 0.37.0
- [Commits](golang/mod@v0.36.0...v0.37.0)

Updates `golang.org/x/sync` from 0.20.0 to 0.21.0
- [Commits](golang/sync@v0.20.0...v0.21.0)

Updates `golang.org/x/sys` from 0.45.0 to 0.46.0
- [Commits](golang/sys@v0.45.0...v0.46.0)

Updates `golang.org/x/term` from 0.43.0 to 0.44.0
- [Commits](golang/term@v0.43.0...v0.44.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-version: 0.53.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: golang-x
- dependency-name: golang.org/x/mod
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: golang-x
- dependency-name: golang.org/x/sync
  dependency-version: 0.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: golang-x
- dependency-name: golang.org/x/sys
  dependency-version: 0.46.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: golang-x
- dependency-name: golang.org/x/term
  dependency-version: 0.44.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: golang-x
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore: run make mod_tidy

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Adel-Ayoub and others added 14 commits July 7, 2026 19:32
…11387)

* fix(key): restore secp256k1 keygen and add PEM PKCS8 import/export

* fix(key): validate --size for fixed-size key types

ed25519 and secp256k1 keys have a single valid size, so a --size
(--bits for init) that does not match it is now an error instead of
being accepted and ignored.

core/coreapi Generate and config.CreateIdentity share a new
options.CheckKeySize helper, so key gen, key rotate, and init accept
--size only when it equals the fixed 256 bits. RSA keeps its variable
size.

* test(cli): cover key lifecycle for all key types

Adds end-to-end CLI coverage of the key commands (gen, list, export,
import, rename, rm, rotate) for rsa, ed25519, and secp256k1. This
mirrors the sharness keystore and rotate suites and extends them to
secp256k1, which they never exercised.

- OpenSSL fixtures under testdata/ pin byte-identical PKCS#8 export
  and import in both directions
- rotate checks the previous identity survives, usable, under the
  backup name
- reserved-name ('self') and restricted-type imports assert the
  specific refusal, not just a non-zero exit

* chore(deps): note secp256k1 version alignment

go-libp2p/core/crypto's key types alias this package, so the direct
and transitive pins must stay on one version to avoid two copies in
the build. The go.mod comment flags that for future dependency bumps.

---------

Co-authored-by: Marcin Rataj <lidel@lidel.org>
Gateway recipes now lead with the decision that matters most for a
public gateway: does it fetch any CID from the network, or serve only
content the node already hosts? They move from the config reference into
the gateway guide, where operators look for them.

- gateway.md: new "Gateway recipes" section (serve-only-your-own-content
  via NoFetch, open recursive gateway, and subdomain/path/DNSLink URL
  styles as linkable sub-headings), a table of contents, and fixes to the
  Directories ordering and the /ipns/ subdomain redirect example; public
  gateways point to the public-utilities and checker pages and the
  self-hosting guide instead of naming hosts
- config.md: recipes replaced by a pointer to the gateway guide
- content-blocking.md: suggest an allowlist (NoFetch) over reactive
  denylist whack-a-mole
* chore(deps): bump go-libp2p and go-libp2p-pubsub

Both are pinned to master pseudo-versions ahead of tagged releases,
with a TODO in go.mod to switch once the tags ship.

go-libp2p adds webrtc-direct v2 handshake support, keeps /certhash
stable across restarts, and stops stale addresses from accumulating
in the peerstore and in published signed peer records. It also fixes
a data race that could take the daemon down mid-response during
ipfs routing findprovs, findpeer, and dht query.

go-libp2p-pubsub frees topic state once the last peer leaves a
topic, closing an unbounded memory growth path (libp2p/go-libp2p-pubsub#705,
the Go counterpart of CVE-2026-46679). Only nodes that opt into
Pubsub.Enabled or Ipns.UsePubsub run the pubsub stack and are
affected.

* feat(config): Internal.NonPublicAddrPublishing

Exposes go-libp2p's NonPublicAddrPublishing as an Internal flag, so a
node can be told to stop publishing addresses the wider internet cannot
reach: private, CGNAT, link-local, loopback, ULA, reserved IPv6, and
special-use DNS names such as .local.

Left unset, kubo passes no option and go-libp2p's default decides. The
default has shifted before (libp2p/go-libp2p#3460), so the flag gives
operators a way to pin the behavior, and makes it easy to see exactly
what a node publishes while chasing a routing problem.

Only the peerstore self-entry and the signed peer record are filtered.
Listening and dialing are untouched, so `ipfs id` keeps reporting the
full set.
Minor dependency updates, no changes to kubo.

- go-block-format v0.2.4
- go-cid v0.6.2
- go-cidutil v0.1.2
- go-datastore v0.9.2
- go-ds-flatfs v0.6.1
- go-ipld-format v0.6.4
- golang.org/x/...
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
https://github.com/ipfs/ipfs-webui/releases/tag/v4.13.0

Also restores the changelog TOC entry for the IPNS lifetime and TTL
highlight, which was left out when that section was added.
- Use new `go-test/random` API
  - no global seed values
  - reuse generator where appropriate
- Fix tests to match new random data generation
  - update expected deterministic values
  - fix t0040-add-and-cat.sh
  - fix t0043-add-w.sh
  - fix t0045-ls.sh
  - fix t0087-repo-robust-gc.sh
  - fix t0270-filestore.sh
  - fix t0271-filestore-utils.sh
  - fix t0272-urlstore.sh
- Migrate from `/math/rand' to `/math/rand/v2`
  - random seeds are now `[32]byte` and not `uint64`
  - use `StringToSeed` or `Uint64ToSeed` to create random seeds for deterministic output
* feat(autotls): skip issuance when broker is down

Bump github.com/ipshipyard/p2p-forge to the head of
ipshipyard/p2p-forge#91: before first-time ACME issuance the client
now confirms the broker responds with HTTP 204 on /v1/health, after
the registration delay and once the node is publicly reachable.
While the broker keeps failing the check, certificate setup is
postponed with one ERROR and an hourly re-check (respecting
Retry-After, capped at 24h) instead of doomed ACME retries for weeks.

Ephemeral nodes (CI runners) still produce no broker traffic at all,
and nodes with a certificate in storage are unaffected.

* chore: update p2p-forge to v0.10.0
* chore: bump go-libp2p-kad-dht to v0.42.0

* bump kad-dht

* fix(init): stop publishing an empty-directory IPNS record

* bump kad-dht to v0.42.1

* bump boxo

* chore: bump boxo, clarify IPNS storage changelog

Bumps boxo, bringing the offline router retention change (records are
served until their EOL, no receive-age cap by default; ipfs/boxo#1189)
and a gateway 304 cache-freshness fix (ipfs/boxo#1188).

The v0.43 "Unified IPNS record storage" highlight now spells out how
retention works: with the offline router and the DHT sharing the /dht
datastore prefix, online nodes drop value records 48h after storage
(the DHT's value-store GC) while offline nodes keep them until EOL.

* fix: sync DHT purge once after deletion

* bump boxo

* depend on boxo@master

* chore: bump boxo to main, align module pins

Pick up boxo main HEAD (4794174d), which includes the merged offline
router value-store change (ipfs/boxo#1189). This brings the root module,
the kubo-as-a-library example, and test/dependencies onto one boxo pin;
they previously pointed at three different commits.

- go-libp2p moves to ec408fcc as a transitive floor required by boxo
- changelog: note the one-time full-datastore key scan on first start
  after upgrading, and update the pinned boxo and go-libp2p hashes

* chore: require make mod_tidy before commit/push

Spell out that the repo has three go.mod files that must stay on the
same dependency versions, and that a bare `go mod tidy` only tidies one
module and lets pins drift between them.

---------

Co-authored-by: Marcin Rataj <lidel@lidel.org>
* chore: upgrade to boxo v0.42.0

* use tagged release

* update changelog

* docs: expand v0.43 changelog highlights

Cover the user-facing changes the boxo v0.42.0 and go-libp2p bumps
pull in since v0.42.0, and group the security fixes so operators can
decide whether to update.

- add a security section for the pubsub, libp2p resource-cap,
  routing-query crash, and OTLP exporter fixes, with their CVEs
- reframe the DNSLink caching note as a TTL and expiration revamp
  spanning IPNS records, DNSLink, and 304 revalidation
- credit boxo v0.41.0 and its bitswap fetch-stall fix
- drop dependency-section prose that repeats the highlights

---------

Co-authored-by: Marcin Rataj <lidel@lidel.org>
Give a new maintainer the guardrails that keep contributions safe as
people come and go. AGENTS.md carries the hard rules a change must not
cross; CONTRIBUTING.md carries the why and who the project is for.

- AGENTS.md: stability rules for the /api/v0 RPC, the HTTP Gateway,
  default CIDs, and protocol changes via IPIP, each with a way to
  verify it; boxo-vs-kubo boundary; configurable-endpoint rule for
  user agency; note that CLI/RPC reference docs are generated from
  help text; PRs need a description and tests, test/cli over sharness;
  release tooling is off-limits outside a release
- CONTRIBUTING.md: what Kubo optimizes for (the self-hoster first), and
  a pointer to AGENTS.md for humans working with an LLM assistant
* chore: bump go to 1.26.5

latest 1.26.x patch; keeps go.mod, sub-module go.mods, and the
Dockerfile GO_VERSION default in sync.

* chore(deps): bump go-ipld-cbor, go-ds-measure

part of the ipfs-ecosystem dependabot group (#11395); go-test in that
group is skipped since master is already on v0.4.1.

- go-ipld-cbor v0.2.1 -> v0.3.0
- go-ds-measure v0.2.2 -> v0.2.3
@lidel lidel added the skip/changelog This change does NOT require a changelog entry label Jul 22, 2026
dependabot Bot and others added 6 commits July 27, 2026 16:48
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6 to 7.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](actions/setup-go@v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-go
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
(cherry picked from commit cae994a)
…n the ipfs-ecosystem group across 1 directory (#11405)

* chore(deps): bump github.com/ipfs/go-ds-leveldb

Bumps the ipfs-ecosystem group with 1 update in the / directory: [github.com/ipfs/go-ds-leveldb](https://github.com/ipfs/go-ds-leveldb).

Updates `github.com/ipfs/go-ds-leveldb` from 0.5.2 to 0.5.3
- [Release notes](https://github.com/ipfs/go-ds-leveldb/releases)
- [Commits](ipfs/go-ds-leveldb@v0.5.2...v0.5.3)

---
updated-dependencies:
- dependency-name: github.com/ipfs/go-ds-leveldb
  dependency-version: 0.5.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ipfs-ecosystem
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore: run make mod_tidy

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
(cherry picked from commit 867cdc5)
upgrade to go-ipld-git v0.1.2

(cherry picked from commit bb563a7)
* fix: recover from panics in detached goroutines

ls, dag get and dag export each hand their work to a goroutine and read
the result back over a channel or pipe. Decoding and encoding there runs
whatever codec a block's CID names, so it runs third-party code, and a
panic on a detached goroutine ends the daemon rather than the command.

Each now recovers, logs, and reports through the channel it already
uses. In dag export the recover is registered after the existing cleanup
defer so it runs first, while errCh is still open.

* chore: update boxo, go-ipld-git and go-unixfsnode

Picks up the CAR streaming and object parsing work from ipfs/boxo#1197,
ipfs/go-ipld-git#77 and ipfs/go-unixfsnode#100. All three are pinned to
their branches for now; swap for the tagged releases before merging.

* chore: update boxo, go-ipld-git and go-unixfsnode

go-ipld-git and go-unixfsnode are on their tagged releases. boxo is
pinned to main, which carries ipfs/boxo#1197 but has not been released
yet, so this still needs a boxo release before it can merge.

Notes the CAR truncation marker in the v0.43 changelog, since that is
the user-visible part of the boxo update.

Also stops a slow Ubuntu mirror from failing the ipfs-webui job. That
job installed Playwright OS dependencies for every browser although it
declares no projects and so only ever runs chromium, and the install had
no timeout of its own. When the mirror served 10.7 MB of package indices
at 39 kB/s, apt-get update alone outlasted the job's 20 minute budget and
the run was cancelled before any test started. The install is now scoped
to chromium, capped, and best effort: the runner image already ships what
headless chromium needs, and a library that really is missing surfaces
when the browser fails to launch.

(cherry picked from commit f9baf8f)
* chore: upgrade to boxo v0.42.1
* use tagged release

(cherry picked from commit 9462845)
* fix: update go-libp2p to patch webtransport CVE

Picks up webtransport-go v0.11.1 and quic-go v0.60.0 through go-libp2p
v0.49.0. webtransport-go v0.11.1 fixes CVE-2026-57497, unbounded
buffering of unknown WebTransport capsules, which a peer could use to
exhaust memory on any node with WebTransport enabled. Kubo enables it
by default.

v0.11.x also speaks WebTransport draft-15, so the server answers both
the current browser handshake and the newer one Firefox is
implementing. The tradeoff is that kubo can no longer dial peers
running older go-libp2p over WebTransport. Those peers can still dial
kubo, and go-to-go connections use /quic-v1 anyway.

* docs: expand 0.43 changelog for go-libp2p 0.49

Reframe the webrtc-direct and WebTransport highlights around keeping
browser retrieval working, and add the user-visible 0.49 fixes the
changelog missed:

- confirmed /webrtc-direct address dropped on the shared UDP port
- Safari 26.4+ WebTransport handshake requirement
- go-to-go WebTransport dial regression
- relay backoff after losing a working relay, two shutdown races
- quic-go HTTP/3 trailer CVE-2026-40898 in the security section

* chore: bump boxo to v0.42.1

Moves the pin from a pre-release commit to the tag; the only commits
between them are boxo's own go-libp2p v0.49.0 upgrade and release
mechanics. Changelog: note the v0.42.1 fixes (IPv6 HTTP providers,
shorter /routing/v1 stale windows) and the default CAR traversal
depth cap of 1024 the gateway now inherits.

(cherry picked from commit 6020ab9)
@lidel lidel mentioned this pull request Jul 28, 2026
52 tasks
lidel added 5 commits July 29, 2026 19:12
* chore: bump go-libp2p for sorted confirmed addrs

Pin the head commit of libp2p/go-libp2p#3526: AutoNAT V2's
ConfirmedAddrs returned unsorted buckets, and removeNotInSource
silently dropped webrtc-direct from the confirmed set. Switch to a
master pseudo-version once the PR merges.

* fix: keep browser transports in provider records

Provider records sent to HTTP routers were narrowed to the addresses
AutoNAT V2 confirmed reachable, which silently dropped the only two
transports a browser can dial: the AutoTLS /tls/ws address and
webrtc-direct. A publicly reachable node was invisible to browser and
Helia clients that found it through a delegated router, even though
ipfs id and the DHT both advertised those addresses.

AutoNAT only ever sees listen addresses, so the AutoTLS address, which
the AddrsFactory synthesizes afterwards, can never reach the confirmed
set. webrtc-direct does get confirmed, but go-libp2p loses it again in
getConfirmedAddrs, which feeds an unsorted slice to a scan that assumes
sorted input; that one is fixed upstream in libp2p/go-libp2p#3526.

Announce host.Addrs() instead, the same set identify sends to peers and
the DHT already publishes, narrowed to globally routable addresses so
loopback and LAN entries stay out of a public index. Nodes with no
public address keep announcing what they have, so LAN-only setups
pointing at a local router are unaffected.

- core/node/libp2p/routingopt.go: drop the ConfirmedAddrs branch from
  httpRouterAddrFunc, filter host.Addrs() with manet.IsPublicAddr;
  AppendAnnounce is emitted exactly once and does not count toward
  the public-addr check
- core/commands/swarm_addrs_autonat.go: take over the BasicHost
  compile-time assertion, now the only ConfirmedAddrs consumer

Fixes #11369

* docs: move highlight to v0.43 and scope it

The fix ships in v0.43, so the entry moves out of v0.44.md and in
next to the other browser-retrieval highlights.

- names the config it applies to: Routing.Type=custom with a provide
  method on an HTTP router. Default auto provides over the DHT alone
  and is unaffected, since constructDefaultHTTPRouters leaves
  ProvideRouter as a noop.
- cites bitsocial.net, which runs libp2p in the browser and uses
  delegated routers to find peers, as the app the gap broke

(cherry picked from commit 4b7a94f)
Telemetry reports to https://telemetry.ipshipyard.dev by default again,
as it did through v0.42. This is a stopgap: it holds while the devgrant
support window is active. Every way to turn telemetry off now lives in
one place, so ending it later is a config change or a one-line diff
rather than a rewrite.

- endpoint is a linker-settable var: building with -ldflags "-X
  ...telemetry.defaultEndpoint=" yields a binary with no destination,
  which collects nothing and writes no identifier
- DO_NOT_TRACK is honored, ranking between IPFS_TELEMETRY and the
  config Mode, so one variable opts a machine out of every tool
- a collector answering 410 Gone retires itself: the node drops its
  identifier and never sends there again, on this run or a later one,
  which stops reporting across deployed nodes without a release
- first-run notice names DO_NOT_TRACK next to the Kubo switches
- docs/telemetry.md leads with how to disable, including at build time
- AGENTS.md: telemetry opt-outs are a rule, not a courtesy
- changelog: drop the opt-in highlight, v0.43 ships no telemetry change

(cherry picked from commit f64c770)
* fix(routing): keep peers found before the timeout

The DHT returns the closest peers it reached together with the context
error when a lookup runs past its deadline. We dropped both, so any
lookup slower than the routing server's per-request timeout came back as
HTTP 500 with nothing in it, indistinguishable from a lookup that found
no peers at all. Return what we have, and only error when the set is
empty.

* test: use local dht swarm for routing v1 test

GetClosestPeers joined the public Amino DHT with real bootstrap peers,
so the assertions depended on a CI runner reaching bootstrap.libp2p.io
from a cold repo. When it could not, the test retried for five minutes
and failed; ten such failures since v0.42.0, every one green on re-run.

Bootstrap from the harness's in-process DHT peers instead, which the
provider tests already use and this one predates. The window drops from
five minutes to sixty seconds because there is no longer anything slow
to wait for, and passing runs go from tens of seconds to under one.

* test: stop handing out ports the kernel reuses

NewRandPort binds port zero, notes the number, closes the socket and
hands the number to the caller, which leaves a window for anything else
on the machine to take it. The number also came from the ephemeral
range, the same pool every outgoing connection draws from, and the CLI
suite opens a lot of those. Both TestP2PForeground tunnel subtests died
on "bind: address already in use" for a server the test binds itself.

- NewTCPListener hands back the bound listener, closing that window for
  callers that listen in-process
- ports for daemons we spawn now come from below the ephemeral range, so
  an outgoing connection cannot land on one

* test: sync gc tests to the adder, not the clock

TestAddGCLive asserted that gc had not started yet, but the only thing
it waited for was the first file's output event. Between that event and
the adder reaching the next file there is a gap, and the adder hands the
pin lock to a waiting gc at exactly that boundary, so on a loaded runner
gc really had started and the assertion was right to fail.

Wrap the pipe so the test learns when the adder is inside the hanging
file, and poll GCRequested instead of sleeping 100ms to know gc is
queued. TestAddMultipleGCLive gets the same treatment for its two
sleeps: too short there means gc never gets the lock and the test waits
out its five second timeout instead.

* test: move watched file in atomically

os.WriteFile creates the file and fills it in two steps, and ipfswatch
adds whatever is on disk when the create event wakes it. Catch it
between the two and it adds an empty file, so the CID the test pulls out
of the log reads back as nothing. Stage the file outside the watched
directory and rename it in, which the watcher sees as one event for a
file that is already complete.

* test(sharness): poll the daemon request log

The test backgrounded "ipfs log tail", slept 100ms and expected the
daemon to be listing the request. The daemon only sees it once the
client has started up and connected, which on a loaded runner takes
longer than that, and then both the active and the inactive assertion
fail together because the entry never appears at all.

Poll for each state instead. The extra requests that polling makes push
the daemon closer to the point where it drops finished entries from the
log, so keep them with "diag cmds set-time" first.

* test(sharness): drop stale peer count check

The connect case opened by re-asserting that the previous case had left
zero peers connected. Disconnecting is not permanent: the DHT keeps the
other node in its routing table and re-dials it on any refresh, so that
count is only true for as long as nothing else runs. What this case is
named for, connecting with a bare /p2p/ address, is still covered by the
connect itself and the peer count after it.

* test(fuse): mount one node at a time

Every parallel subtest does identical setup before mounting, so they all
reach the mount together and around twenty setuid fusermount helpers
open /dev/fuse inside the same instant. One occasionally comes back with
a bare exit status 1.

Take a lock for the mount call itself, which the subtests only hold for
tens of milliseconds. Also report the failure instead of panicking: a
panic failed all 37 tests in the package and left daemons behind, and
the daemon's stderr, where fusermount says what actually went wrong, was
captured and then thrown away.

* test: compare cat output byte for byte

The payload is 100 random bytes and the comparison ran through
Trimmed(), which strips one trailing newline. Roughly one run in 256
ends in 0x0a and loses it.

* test: wait for the fast-provide log line

The daemon writes the line before it answers the RPC, but the test reads
a buffer that a goroutine fills by copying the daemon's stderr, and that
copy can still be behind when the command returns. Wait for the line
rather than assuming it has landed.

* test: allow for ipns republish mid-test

A minute after the daemon starts, the republisher re-signs every key and
publishes it again, giving the same value a new signature and expiry.
The test captured one PUT body and compared it byte for byte with what
routing returned, so a run slow enough to straddle that minute compared
the first record against the second.

Keep every record the mock is sent and require that routing's answer is
one of them, which is what the assertion was reaching for.

* fix(examples): turn off mdns in library example

The example connects its two nodes by address, but left mDNS on, so
local discovery could connect them first. A connection opened while a
node is still being built is invisible to that node's bitswap, which
only learns about connections made after it registers its notifier, and
with no routing configured there is nothing to fall back on. The final
fetch then waited forever and the test died on its two minute timeout
with no clue why.

Turning mDNS off makes the explicit dial the only way the two can meet,
and keeps the example off the reader's LAN. Alongside that:

- connectToPeers returns dial errors instead of logging and continuing
  into a fetch that cannot succeed
- the example's own deadline now fits inside the test budget, so a stall
  names the step that hung
- CommandContext so a hung child does not outlive the test

* ci: make helia-interop job resilient

Seven failures since v0.42.0 came from this job's setup rather than from
any incompatibility. It installs whatever @helia/interop published last,
and upstream shipped three packages in a row whose test config does not
work from inside node_modules; a GitHub blip took out the rest.

- find the compiled specs and pass them to aegir, instead of patching
  the config upstream ships into node_modules and grepping its text
- pin node to a major: setup-node resolves an lts/ alias through a
  GitHub manifest with no retry and no fallback, and newer node rejects
  a flag aegir sets unconditionally
- retry the registry lookup and fail loudly, since the old one-liner
  could not fail and left an empty cache key behind
- install the exact version the cache key names, and only save the cache
  once the install is known good
- drop the playwright apt packages, unused since this job stopped
  running browser targets

(cherry picked from commit 8ee3dcb)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip/changelog This change does NOT require a changelog entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants