This proposal submits the v1.0.2 upgrade for the Hippo Protocol mainnet. This is a mandatory, state-breaking security release. It addresses critical vulnerabilities in both the consensus engine (CometBFT) and the application state machine (Cosmos SDK), specifically targeting potential chain-halt vectors.
The v1.0.2 upgrade strengthens the network against Denial-of-Service (DoS) attacks and state-machine failures. The primary fixes included are:
The motivation for this upgrade is strictly security and stability. Leaving the network on the current version exposes it to known vectors that can result in a total network stoppage.
The update to Cosmos SDK v0.50.14 is required to fix GHSA-p22h-3m2v-cmgh. Without this patch, the chain risks halting if the historical rewards pool overflows—a known issue affecting chains using the standard distribution module.
The update to CometBFT v0.38.19 resolves GHSA-hrhf-2vcr-ghch. This mitigates a high-severity DoS vector where malformed consensus messages could crash validator nodes.
Updates mitigate severe vulnerabilities identified in Dependabot Alert.
The nature of the x/distribution fix in Cosmos SDK v0.50.14 is state-breaking. It alters how historical rewards are calculated/stored to prevent overflows. Therefore, a coordinated network upgrade is the only safe way to apply this patch. Delaying this upgrade increases the probability of an accidental or malicious chain halt as the network grows.
|
Field
|
Data
|
|---|---|
|
info
|
{"binaries": {"darwin/amd64": "https://github.com/hippo-protocol/hippo-protocol/releases/download/v1.0.2/hippod-v1.0.2-darwin-amd64?checksum=sha256:cfe8b386407471e4810dd8a1d5b8030f55e02cfd6c78c2d084dfe7688aede30e", "linux/amd64": "https://github.com/hippo-protocol/hippo-protocol/releases/download/v1.0.2/hippod-v1.0.2-linux-amd64?checksum=sha256:cafdb6bcc3c507ba9314cc848ec0a3e8a352070086ebfe9c6c4a9fd73886bac4", "linux/arm64": "https://github.com/hippo-protocol/hippo-protocol/releases/download/v1.0.2/hippod-v1.0.2-linux-arm64?checksum=sha256:c0056660213583705da2d0f818a2c36e32d4d67b47b4e04544ac29b643394f99"}} |
|
name
|
v1.0.2 |
|
time
|
0001-01-01T00:00:00Z |
|
height
|
3847000 |
|
upgraded_client_state
|