From ff5f5ddf2339445cc21321291a48f0d4521da210 Mon Sep 17 00:00:00 2001 From: DanS Date: Sun, 2 Aug 2026 12:06:02 -0500 Subject: [PATCH] docs: add CHANGELOG with daemon-startup hardening release notes MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Introduces CHANGELOG.md (Keep a Changelog style, Unreleased section) covering this batch, with F8's breaking change — remote plaintext RPC now refused by default — called out front and center along with the rpctls=1 / rpcallowplaintext=1 recovery steps. Also records the Security / Fixed / Added entries for F1-F7. Updates the tracking doc's status to reflect the completed release-notes + i18n back-fill and the remaining pre-release items (F1/F2 manual repros, CJK subset-font rebuild). Co-Authored-By: Claude Opus 4.8 --- CHANGELOG.md | 58 ++++++++++++++++++++++++++++++++ docs/daemon-startup-hardening.md | 13 +++++-- 2 files changed, 68 insertions(+), 3 deletions(-) create mode 100644 CHANGELOG.md diff --git a/CHANGELOG.md b/CHANGELOG.md new file mode 100644 index 0000000..65b951c --- /dev/null +++ b/CHANGELOG.md @@ -0,0 +1,58 @@ +# Changelog + +All notable user-facing changes to ObsidianDragon are documented here. The format loosely +follows [Keep a Changelog](https://keepachangelog.com/); the project uses Conventional Commits. + +## [Unreleased] + +### ⚠️ Breaking changes + +- **Remote RPC over plain HTTP is now refused by default.** If your wallet is configured to + reach a **remote** `rpchost`/`rpcconnect` **without TLS**, it will no longer connect — it + previously sent your `rpcuser`/`rpcpassword` in cleartext (capturable by anyone on the + network path) after only a dismissible warning. To reconnect, either: + - add **`rpctls=1`** to `DRAGONX.conf` (preferred, if your daemon supports TLS), or + - add **`rpcallowplaintext=1`** to `DRAGONX.conf` to explicitly accept the plaintext link. + + Local and embedded daemons (`127.0.0.0/8`, `localhost`, `::1`) are unaffected. + +### Security + +- Refuse remote plaintext RPC credential transmission by default (see Breaking changes above). +- Tightened localhost detection: a hostname that merely *starts* with `127.` (e.g. + `127.evil.com`) is no longer mistaken for a loopback address, so it can no longer bypass the + plaintext-RPC protection. +- Sapling parameters are now integrity-checked (SHA-256) against pinned canonical digests + before use, instead of only checking that the files exist. A truncated or corrupt parameter + file is caught up front rather than surfacing later as a confusing shielded-operation failure. + (Cached via a `size:mtime` marker so it doesn't re-hash ~48 MB on every launch.) + +### Fixed + +- Daemon crashes are no longer occasionally missed: a race between the UI thread and the + process monitor could consume the daemon's exit status, hiding a crash and defeating the + automatic-restart cap. The monitor is now the sole reaper. +- A daemon that fails to launch (missing execute permission, wrong architecture, corrupt + binary) now reports a precise error immediately instead of briefly showing "running" and + then a generic "exited unexpectedly (exit code 127)". +- A quick stop→start no longer triggers a restart storm: the wallet now waits briefly for a + previous daemon to release the data-directory lock and shows a clear, non-crash message + instead of exhausting the crash-restart budget. +- Failures while writing the daemon binaries or Sapling parameters (disk full, permission + denied) are now surfaced clearly up front instead of failing opaquely when the daemon later + can't start. +- Directory-creation failures on startup (read-only home, permission denied) now produce a + clear "Cannot create " message instead of a confusing downstream "config missing" / + "binary not found" error (or, in one path, an uncaught exception). + +### Added + +- A "Taking longer than expected" notice now appears if the daemon is reachable but hasn't + finished initializing after ~45 s (configurable via `ui.toml`), with guidance to restart the + daemon or open the Console — instead of an indefinite silent spinner. It clears itself + automatically once the daemon connects. + +--- + +Engineering detail and the finding-by-finding rationale for this batch live in +`docs/daemon-startup-hardening.md`. diff --git a/docs/daemon-startup-hardening.md b/docs/daemon-startup-hardening.md index 2f0076a..22f1c15 100644 --- a/docs/daemon-startup-hardening.md +++ b/docs/daemon-startup-hardening.md @@ -17,9 +17,16 @@ Status legend: ☐ not started · ◐ in progress · ☑ landed & verified **Status: all 8 landed & verified** (build-clean, `ctest` green after each) across four commits on `dev` — lifecycle cluster (F1/F2/F4), filesystem+params cluster (F7/F6/F5), F3, and F8. Six new -pure-helper unit tests added. Still owed before release: the F1/F2 manual repros (`kill -SEGV` / -non-executable binary — not unit-testable), the deferred `res/lang/*.json` i18n back-fill (one -`add_missing_translations.py` run), and **release notes for F8's breaking default flip**. +pure-helper unit tests added. + +**Wrap-up done:** release notes added (`CHANGELOG.md`, F8 breaking change front and center); i18n +back-fill applied additively to `res/lang/*.json` (42 keys — all 6 for es/de/fr/pt/ru; 6 zh/ja/ko +entries whose glyphs aren't in the current `NotoSansCJK-Subset.ttf` were left on English fallback +rather than render as tofu). + +**Still owed before release:** the F1/F2 manual repros (`kill -SEGV` / non-executable binary — not +unit-testable), and a **CJK subset-font rebuild** (`scripts/build_cjk_subset.py`, needs the Noto +CJK source font) to cover those 6 deferred zh/ja/ko strings. ---