Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
59 commits
Select commit Hold shift + click to select a range
0a25092
Switch to explicit serializability annotations (#6703)
moritzkiefer-da Aug 7, 2026
754fc71
daml: address Quanstamp 2026 report findings (#6586)
meiersi-da Aug 12, 2026
3bd5266
Allow external CI on forks for staging bases (#6860)
nicu-da Aug 19, 2026
3988646
Actually enable ci for staging bases (#6863)
nicu-da Aug 19, 2026
39f12c1
Daml: add fund manager blacklist and dev fund coupon mint delay (#6793)
zheli Aug 21, 2026
e4a9dd4
Merge remote-tracking branch 'origin/main' into staging-0.8.0
cocreature Aug 24, 2026
ed443c5
Merge main into staging-0.8.0 (#6937)
moritzkiefer-da Aug 25, 2026
20b6af4
Remove deprecated transfer command functionality (#6959)
moritzkiefer-da Aug 26, 2026
a4ea43a
[static] enable sweet security on all scratchnets (#7008)
isegall-da Aug 28, 2026
82b447c
Helm charts hardening: don't mount k8s API tokens by default (#7017)
martinflorian-da Aug 31, 2026
3418ac7
Traffic-based App Rewards: Switch on for default test network (#6000)
adetokunbo Aug 31, 2026
3aba4db
Pin network banner to the top of the viewport (#7014)
pawelperek-da Aug 31, 2026
cab6e6f
Switch to stable canton library version (#7024)
moritzkiefer-da Aug 31, 2026
623d38a
Add ability to override rate limiter per IP CIDR (#7028)
nicu-da Aug 31, 2026
6ab5358
CometBFT watchdog improvements (#7032)
moritzkiefer-da Aug 31, 2026
d831b91
Merge remote-tracking branch 'origin/staging-0.8.0'
cocreature Sep 1, 2026
90bc437
Merge staging-0.8.0 into main (#7037)
moritzkiefer-da Sep 1, 2026
cc88e83
Remove duplicate, unused vitest config. (#7016)
mrdziuban Sep 1, 2026
7802ae1
Broaden BFT bootstrap WARN ignore to span-name scoping (#7036)
adetokunbo Sep 1, 2026
d5b780b
add switch over time field to configs (#7039)
JYC11 Sep 1, 2026
2958091
Simplify istio rate limits (#6933)
nicu-da Sep 1, 2026
b0b7dc3
Don't warn for parties that have no vetted amulet version
cocreature Sep 1, 2026
97dba1b
remove redundant log ignores
cocreature Sep 1, 2026
4e6cb2d
Don't warn for parties that have no vetted amulet version (#7041)
moritzkiefer-da Sep 1, 2026
46d90ef
helm: allow setting priorityClassName on node pods (#6801)
SLoeuillet Sep 1, 2026
b7931a6
Persist docker compose and Postgres logs (#7033)
mrdziuban Sep 1, 2026
51879be
Improve istio rate limits (#7042)
nicu-da Sep 1, 2026
d437116
Fix non-exhaustive match (#7018)
rautenrieth-da Sep 2, 2026
58a729d
Add UI support for fund manager blacklist and dev fund coupon mint de…
zheli Sep 2, 2026
b45148e
upgrade canton to 3.5.16-snapshot.20260901.19217.0.v1ed99f4c (#7057)
mblaze-da Sep 2, 2026
3049b04
Don't return featured app right in token standard contexts from scan …
moritzkiefer-da Sep 2, 2026
36b22ed
remove canton-network SV deployment and split-SV migration IaC (#6936)
mblaze-da Sep 2, 2026
ed7caed
Fix image hashes for canton docker images (#7066)
moritzkiefer-da Sep 2, 2026
af32f6b
Unflake app upgrade test (#7065)
moritzkiefer-da Sep 2, 2026
c542ce6
add istio rate limits for the sequencer (#7064)
nicu-da Sep 2, 2026
9082ef2
helm: make the Postgres role and bootstrap database configurable for …
SLoeuillet Sep 2, 2026
af3fe06
Kill dead pods in node restore (#6985)
OriolMunoz-da Sep 2, 2026
b8c9aae
Test handling of multiple verdicts with the same update_id (#7007)
mrdziuban Sep 2, 2026
79e56f4
remove split sv config as it becomes default (#7071)
mblaze-da Sep 2, 2026
553b2c3
Extend "Restarting stream ... Channel shutdown" log ignore (#7074)
martinflorian-da Sep 2, 2026
44afd18
Mark `splice-domain` Helm chart as deprecated (#7072)
martinflorian-da Sep 3, 2026
51e7a89
Use `DbStorage.toInClause` and remove `inClause`. (#6963)
mrdziuban Sep 3, 2026
be2643b
Apply custom istio flow control to internal APIs (#7088)
moritzkiefer-da Sep 3, 2026
214940a
Canton config cleanups (#7035)
martinflorian-da Sep 3, 2026
165558b
[ci] bump GHA runner version to the latest (auto-generated) (#7038)
canton-network-da Sep 3, 2026
94b0e96
Fix gRPC rate limits (#7093)
nicu-da Sep 3, 2026
0ea0f6a
Add script for SV operators to collect resolved node configs (#7092)
martinflorian-da Sep 3, 2026
2c12508
Fix flow control settings (#7094)
moritzkiefer-da Sep 3, 2026
dc2d1f2
Working cloud armour (#7067)
nicu-da Sep 3, 2026
e7e6efa
Add backed off FE retries on rate limit errors (#7087)
pawelperek-da Sep 3, 2026
b442ddd
Helm: Drop dead `sequencer.driver.type: "postgres"` code from `splice…
martinflorian-da Sep 3, 2026
3fab383
Pin postgres version in compose, localnet, splice-postgres & pulumi (…
OriolMunoz-da Sep 3, 2026
db32e21
upgrade canton to 3.5.16-snapshot.20260902.19223.0.v7ed204a4 (#7105)
mblaze-da Sep 3, 2026
0fb7e5f
add network backend that ensures cantonbft traffic bypasses cloud arm…
nicu-da Sep 3, 2026
fff5ae3
feat: add checks for FROM directives (#7068)
krzysztofczyz-da Sep 3, 2026
3063ad6
upgrade canton to 3.5.16 (#7110)
mblaze-da Sep 3, 2026
61474ba
adjust scan/sequencer rate limits (#7112)
nicu-da Sep 3, 2026
91a0bae
Merge remote-tracking branch 'origin/main' into staging-0.9.0
cocreature Sep 4, 2026
dd929af
try bumping cache version
cocreature Sep 4, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 1 addition & 1 deletion .github/workflows/build.daml_test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ jobs:
id: setup
uses: ./.github/actions/tests/common_test_setup
with:
cache_version: 8
cache_version: 10

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

don't ask me why it was at 8 before everything else was at 9. Bumping everything consistently seemed less confusing.

test_name: daml_test

- name: Run Daml tests
Expand Down
7 changes: 6 additions & 1 deletion .github/workflows/build.deployment_test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ jobs:
- name: Setup
uses: ./.github/actions/tests/common_test_setup
with:
cache_version: 9
cache_version: 10
test_name: deployment_test
with_sbt: false

Expand All @@ -40,6 +40,11 @@ jobs:
cmd_retry_count: 5 # Retry in case of dependency download errors
cmd: make cluster/pulumi/test
cmd_before_retry: git reset --hard # revert changes before retrying, because make cluster/pulumi/test actually "fixes" the test pulumi files in-place

- name: Check that pinned docker images are multi-arch
uses: ./.github/actions/nix/run_bash_command_in_nix
with:
cmd: ./scripts/check-multiarch-images.py

- name: Report Failures on Slack & Github
if: failure() && (github.event_name == 'push' || github.event_name == 'schedule')
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/build.docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ jobs:
id: setup
uses: ./.github/actions/tests/common_test_setup
with:
cache_version: 9
cache_version: 10
test_name: docs
save_nix_cache: true
save_nix_cache_to_gcp: ${{ github.ref == 'refs/heads/main' && github.event_name == 'push' }}
Expand All @@ -48,7 +48,7 @@ jobs:
- name: Post-SBT job
uses: ./.github/actions/sbt/post_sbt
with:
cache_version: 9
cache_version: 10
setup_sbt_cache_hits: ${{ steps.setup.outputs.sbt_cache_hits }}

- name: Report Failures on Slack & Github
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/build.scala_test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -137,7 +137,7 @@ jobs:
- name: Run Tests
uses: ./.github/actions/tests/scala_test
with:
cache_version: 9
cache_version: 10
with_canton: ${{ inputs.with_canton }}
start_canton_options: ${{ inputs.start_canton_options }}
test_suite_name: ${{ inputs.test_name }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/build.scala_test_for_compose.yml
Original file line number Diff line number Diff line change
Expand Up @@ -104,7 +104,7 @@ jobs:
- name: Run Tests
uses: ./.github/actions/tests/scala_test
with:
cache_version: 9
cache_version: 10
start_canton_options: ${{ inputs.start_canton_options }}
test_suite_name: ${{ inputs.test_name }}
test_names: ${{ needs.split_tests.outputs.test_names }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/build.scala_test_with_cometbft.yml
Original file line number Diff line number Diff line change
Expand Up @@ -120,7 +120,7 @@ jobs:
- name: Run Tests
uses: ./.github/actions/tests/scala_test
with:
cache_version: 9
cache_version: 10
start_canton_options: -F -w
test_suite_name: ${{ inputs.test_name }}
test_names: ${{ needs.split_tests.outputs.test_names }}
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/build.static_tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ jobs:
- name: Setup Nix
uses: ./.github/actions/tests/common_test_setup
with:
cache_version: 9
cache_version: 10
test_name: canton_consistency
target: 'static_tests'

Expand Down Expand Up @@ -87,7 +87,7 @@ jobs:
id: setup
uses: ./.github/actions/tests/common_test_setup
with:
cache_version: 9
cache_version: 10
test_name: static_tests
target: 'static_tests'

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/build.ts_cli_tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@ jobs:
if: steps.skip.outputs.skip != 'true'
uses: ./.github/actions/tests/common_test_setup
with:
cache_version: 9
cache_version: 10
test_name: ts_cli

- name: Run Token Standard CLI tests
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/build.ui_tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@ jobs:
if: steps.skip.outputs.skip != 'true'
uses: ./.github/actions/tests/common_test_setup
with:
cache_version: 9
cache_version: 10
test_name: ui_tests

- name: Run UI tests
Expand All @@ -62,7 +62,7 @@ jobs:
if: steps.skip.outputs.skip != 'true'
uses: ./.github/actions/sbt/post_sbt
with:
cache_version: 9
cache_version: 10
setup_sbt_cache_hits: ${{ steps.setup.outputs.sbt_cache_hits }}

- name: Upload logs
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/bump_gha_runner_version.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ jobs:
- name: Set up Nix (Self hosted)
uses: ./.github/actions/nix/setup_nix
with:
cache_version: 9
cache_version: 10
target: default

- name: Check for the latest version and create a PR to splice
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/performance_tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ jobs:
id: setup
uses: ./.github/actions/tests/common_test_setup
with:
cache_version: 9
cache_version: 10
test_name: ingestion_performance_tests

# Authenticate to GCP for read access to GCS
Expand Down Expand Up @@ -137,7 +137,7 @@ jobs:
id: setup
uses: ./.github/actions/tests/common_test_setup
with:
cache_version: 9
cache_version: 10
test_name: read_performance_tests

# Authenticate to GCP for read access to GCS
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/pr_check_github_scripts.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ jobs:
- name: Set up Nix
uses: ./.github/actions/nix/setup_nix
with:
cache_version: 9
cache_version: 10
- name: Check github scripts
uses: ./.github/actions/nix/run_bash_command_in_nix
with:
Expand Down
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -82,3 +82,6 @@ docs/src/deployment/observability/metrics_reference.rst
/.vagrant/
/vagrant-nix-cache/
lnav*work

# VS Code
.vscode/
2 changes: 1 addition & 1 deletion Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ $(app-bundle): $(canton-amulet-dar) $(wallet-payments-dar)
sbt --client --batch bundle

$(canton-amulet-dar) $(wallet-payments-dar) &:
sbt --batch 'splice-amulet-daml'/damlBuild 'splice-wallet-payments-daml'/damlBuild
sbt --client --batch 'splice-amulet-daml/damlBuild; splice-wallet-payments-daml/damlBuild'

$(load-tester):
cd "${SPLICE_ROOT}/load-tester" && npm ci && npm run build
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -206,6 +206,9 @@ object ConfigTransforms {
_.copy(rewardOperationRoundsCloseBufferDuration = NonNegativeFiniteDuration.ofMillis(100))
),
disableDevelopmentFund(),
// Tests default to TrafficBasedAppRewards. Networks (which don't apply
// ConfigTransforms.defaults) fall back to the FeaturedAppMarkers default
withTrafficBasedAppRewards,
)
}

Expand Down Expand Up @@ -795,6 +798,9 @@ object ConfigTransforms {
}
}

def withNoSvOperationsSwitchOverTimes: ConfigTransform =
updateAllSvAppFoundDsoConfigs_(_.copy(initialSvOperationsSwitchOverTimes = None))

def withValidatorFaucetCap(cap: BigDecimal): ConfigTransform =
updateAllSvAppFoundDsoConfigs_(c => c.copy(optValidatorFaucetCap = Some(cap)))

Expand All @@ -809,6 +815,24 @@ object ConfigTransforms {
): ConfigTransform =
updateAllSvAppFoundDsoConfigs_(c => c.copy(initialRewardConfig = Some(rewardConfig)))

// Tests mint TBAR without dry-run — the network default enables TBAR dry-run
// alongside FeaturedAppMarkers minting, but tests already exercise TBAR
// directly so a dry-run would be redundant.
def withTrafficBasedAppRewards: ConfigTransform =
updateAllSvAppFoundDsoConfigs_(c =>
c.copy(initialRewardConfig =
Some(
InitialRewardConfig(
mintingVersion = "RewardVersion_TrafficBasedAppRewards",
dryRunVersion = None,
)
)
)
)

def withFeaturedAppMarkers: ConfigTransform =
updateAllSvAppFoundDsoConfigs_(c => c.copy(initialRewardConfig = None))

private def portTransform(bump: Int, c: AdminServerConfig): AdminServerConfig =
c.copy(internalPort = c.internalPort.map(_ + bump))

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,7 @@ import org.lfdecentralizedtrust.splice.sv.SvAppClientConfig
import org.lfdecentralizedtrust.splice.sv.config.SvOnboardingConfig.FoundDso
import org.lfdecentralizedtrust.splice.util.{
Codec,
IpCidrRateLimits,
PerAttributeRateLimitConfig,
SpliceRateLimitConfig,
}
Expand Down Expand Up @@ -74,7 +75,14 @@ import com.typesafe.config.ConfigException.UnresolvedSubstitution
import org.slf4j.{Logger, LoggerFactory}
import pureconfig.configurable.{genericMapReader, genericMapWriter}
import pureconfig.generic.{CoproductHint, FieldCoproductHint, ProductHint}
import pureconfig.{ConfigCursor, ConfigReader, ConfigWriter}
import pureconfig.{
CamelCase,
ConfigCursor,
ConfigFieldMapping,
ConfigReader,
ConfigWriter,
KebabCase,
}
import pureconfig.error.{CannotConvert, FailureReason}
import pureconfig.module.cats.{nonEmptyListReader, nonEmptyListWriter}
import io.circe.parser.*
Expand Down Expand Up @@ -376,6 +384,15 @@ object SpliceConfig {

import pureconfig.generic.semiauto.*

private val perClientIpRateLimitHint: ProductHint[PerAttributeRateLimitConfig] =
ProductHint[PerAttributeRateLimitConfig](
ConfigFieldMapping {
case "attributeOverrides" => "ip-overrides"
case other => ConfigFieldMapping(CamelCase, KebabCase)(other)
},
allowUnknownKeys = false,
)

private val cantonConfigReaders = new CantonConfig.ConfigReaders()(elc)

class ConfigReaders(implicit
Expand Down Expand Up @@ -433,11 +450,22 @@ object SpliceConfig {
deriveReader[SpliceParametersConfig]
implicit val spliceRateLimiterSimpleConfig: ConfigReader[SpliceRateLimitConfig.Simple] =
deriveReader[SpliceRateLimitConfig.Simple]
implicit val clientIpRateLimitHint: ProductHint[PerAttributeRateLimitConfig] =
SpliceConfig.perClientIpRateLimitHint
implicit val clientIpRateLimitConfig: ConfigReader[PerAttributeRateLimitConfig] =
deriveReader[PerAttributeRateLimitConfig]
implicit val spliceRateLimiterWithPerClientIpConfig
: ConfigReader[SpliceRateLimitConfig.WithPerClientIp] =
deriveReader[SpliceRateLimitConfig.WithPerClientIp]
deriveReader[PerAttributeRateLimitConfig].emap { config =>
Try(IpCidrRateLimits.tryValidate(config)).toEither.left
.map[FailureReason](err =>
CannotConvert(
config.attributeOverrides.keys.mkString("[", ", ", "]"),
"ip-overrides",
err.getMessage,
)
)
.map(_ => config)
}
implicit val spliceRateLimiterWithPerClientIpConfig: ConfigReader[PerClientIpRateLimitConfig] =
deriveReader[PerClientIpRateLimitConfig]
implicit val rateLimitersConfig: ConfigReader[RateLimitersConfig] =
deriveReader[RateLimitersConfig]
implicit val enabledFeaturesConfigReader: ConfigReader[EnabledFeaturesConfig] =
Expand Down Expand Up @@ -959,11 +987,12 @@ object SpliceConfig {

implicit val spliceRateLimiterSimpleConfig: ConfigWriter[SpliceRateLimitConfig.Simple] =
deriveWriter[SpliceRateLimitConfig.Simple]
implicit val clientIpRateLimitHint: ProductHint[PerAttributeRateLimitConfig] =
SpliceConfig.perClientIpRateLimitHint
implicit val clientIpRateLimitConfig: ConfigWriter[PerAttributeRateLimitConfig] =
deriveWriter[PerAttributeRateLimitConfig]
implicit val spliceRateLimiterWithPerClientIpConfig
: ConfigWriter[SpliceRateLimitConfig.WithPerClientIp] =
deriveWriter[SpliceRateLimitConfig.WithPerClientIp]
implicit val spliceRateLimiterWithPerClientIpConfig: ConfigWriter[PerClientIpRateLimitConfig] =
deriveWriter[PerClientIpRateLimitConfig]
implicit val rateLimitersConfig: ConfigWriter[RateLimitersConfig] =
deriveWriter[RateLimitersConfig]

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -247,50 +247,6 @@ abstract class ValidatorAppReference(
}
}

@Help.Summary("Prepare TransferPreapproval send")
def prepareTransferPreapprovalSend(
senderPartyId: PartyId,
receiverPartyId: PartyId,
amount: BigDecimal,
expiresAt: CantonTimestamp,
nonce: Long,
description: Option[String],
verboseHashing: Boolean = false,
): definitions.PrepareTransferPreapprovalSendResponse = {
consoleEnvironment.run {
httpCommand(
HttpValidatorAdminAppClient.PrepareTransferPreapprovalSend(
senderPartyId,
receiverPartyId,
amount,
expiresAt,
nonce,
description,
verboseHashing,
)
)
}
}

@Help.Summary("Submit TransferPreapproval send")
def submitTransferPreapprovalSend(
senderPartyId: PartyId,
transaction: String,
signature: String,
publicKey: String,
): String = {
consoleEnvironment.run {
httpCommand(
HttpValidatorAdminAppClient.SubmitTransferPreapprovalSend(
senderPartyId,
transaction,
signature,
publicKey,
)
)
}
}

def getExternalPartyBalance(partyId: PartyId): definitions.ExternalPartyBalanceResponse = {
consoleEnvironment.run {
httpCommand(
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -709,6 +709,7 @@ abstract class WalletAppReference(
amount: BigDecimal,
expiresAt: CantonTimestamp,
reason: String,
mintAfter: Option[CantonTimestamp] = None,
): AllocateDevelopmentFundCouponResponse =
consoleEnvironment.run {
httpCommand(
Expand All @@ -717,6 +718,7 @@ abstract class WalletAppReference(
amount,
expiresAt,
reason,
mintAfter,
)
)
}
Expand Down
4 changes: 0 additions & 4 deletions apps/app/src/test/resources/include/mediators.conf
Original file line number Diff line number Diff line change
Expand Up @@ -19,10 +19,6 @@ _mediator_template {
}
topology {
validate-initial-topology-snapshot = true
# enable after issue is fixed in canton
enable-topology-state-cache-consistency-checks = true
use-new-processor = true
use-new-client = true
}
parameters {
delayed-verdict-sender {
Expand Down
4 changes: 0 additions & 4 deletions apps/app/src/test/resources/include/participants.conf
Original file line number Diff line number Diff line change
Expand Up @@ -96,9 +96,5 @@ _participant_template {
topology {
broadcast-batch-size = 1
validate-initial-topology-snapshot = true
# enable after issue is fixed in canton
enable-topology-state-cache-consistency-checks = true
use-new-processor = true
use-new-client = true
}
}
Loading
Loading