Skip to main content

Node v1.0.400 release notes

For the complete documentation index, see llms.txt
  • Version: v1.0.400
  • Date: October 6, 2026
  • Components: node-1.0.400, toolkit-1.0.400, runtime-1.0.300

Docker images​

docker pull midnightntwrk/midnight-node:1.0.400
docker pull midnightntwrk/midnight-node-toolkit:1.0.400

High-level summary​

Node v1.0.400 is a security patch on the v1.0.0 GA line. It moves the node's ledger 8 dependency from 8.1.2 to 8.1.3, which fixes the critical advisory GHSA-wr7g-rr4v-jmj8. Upgrade every node, starting with block producers.

The release also includes a fix for the v1.0.300 known issue where a node that syncs Mainnet from genesis stops at block 1788979. The runtime stays at 1.0.300, so this is a binary-only upgrade with no runtime upgrade, governance action, reset, or resync.

The changes below are the delta from v1.0.300, taken from the comparison between the two tags.


Audience​

This release note is relevant for users who:

  • Run a Midnight node on Preview, Preprod, or Mainnet, especially a block producer. A node on v1.0.400 rejects some contract calls that a node on v1.0.300 accepts.
  • Sync a Mainnet node from genesis, including a node that feeds an indexer.
  • Use the node toolkit to build or replay transactions.
  • Maintain a smart contract that guards payouts, withdrawals, or mints with sets or maps whose keys contain a Field.

DApp developers do not need to change how they build transactions. Transactions built with the Compact compiler and Midnight.js versions in the compatibility matrix do not contain the values or operations that ledger 8.1.3 rejects.


What changed (Summary of updates)​

The updates below describe the key changes introduced in this release.

  • Moved the ledger 8 dependency from 8.1.2 to 8.1.3, a security release that rejects contract calls whose transcripts contain non-canonical values or operations. It fixes the critical advisory GHSA-wr7g-rr4v-jmj8.
  • Picked up the ledger 8.1.3 crate set: midnight-ledger and midnight-zswap 8.1.3, midnight-onchain-runtime 3.1.2, midnight-onchain-state 3.0.2, midnight-onchain-vm 3.1.2, and midnight-base-crypto 1.0.2.
  • Added a fallback to the block timestamp (tblock) correction, so a node that syncs Mainnet from genesis gets past block 1788979.
  • Moved the toolkit to 1.0.400 on the same ledger crates, and removed the shx and shelljs npm packages from the toolkit image.
  • Left the runtime at 1.0.300, so you do not need a runtime upgrade. No RPC methods, configuration settings, or chain specifications change.

New features​

No new features in this release.


Breaking changes​

Stricter contract call checks​

Ledger 8.1.3 narrows what counts as a well-formed contract call. A node on v1.0.400 rejects contract calls whose transcripts contain non-canonical values or operations, while a node on v1.0.300 accepts them. Block producers on different versions can therefore disagree about which blocks are valid, so move every block producer to v1.0.400 together. For the exact rules, see the ledger v8.1.3 release notes.

The node interface stays the same: this release changes no RPC methods, configuration settings, or chain specifications.

Upgrade to v1.0.400​

You do not need to reset or resync your node, and there is no runtime upgrade or governance action.

  1. Pull midnightntwrk/midnight-node:1.0.400, or download the node tarball for your architecture from the node-1.0.400 release and check it against the SHA256SUMS file.
  2. Restart the node with the new image or binary.
  3. If you use the toolkit, switch to midnightntwrk/midnight-node-toolkit:1.0.400 or the toolkit tarball from the same release.

To confirm the upgrade, call these RPC methods on your node:

  • system_version returns a value that starts with 1.0.400.
  • state_getRuntimeVersion still returns specVersion 1000300, transactionVersion 3, and systemVersion 3.
  • midnight_ledgerVersion returns =8.1.3. This method reports the ledger 8 version compiled into the node binary. It is not a property of the on-chain runtime, so each node reports its own build.

Bug fixes and quality improvements​

Ledger 8.1.3 security fix​

The critical advisory GHSA-wr7g-rr4v-jmj8 affects ledger 8.1.2 and earlier. A contract call could carry values that its proof treats as equal but that the contract's on-chain state treats as different. On an affected smart contract, a caller could use this to repeat an action that the contract allows only once, such as a payout. Ledger 8.1.3 rejects contract calls with these non-canonical values in their transcripts. (#2238)

The node runs ledger 8 in its native host functions, not in the on-chain runtime, so the node binary carries the fix.

The fix stops new contract calls with non-canonical values, but it does not repair contract state that earlier transactions wrote. If your smart contract guards payouts, withdrawals, or mints with sets or maps whose keys contain a Field, read the advisory and inspect the contract's state.

Mainnet sync from genesis​

Node v1.0.300 added a block timestamp (tblock) correction for blocks produced before the runtime 1.0.300 upgrade (#1924). The node validates the first ledger transaction of each such block at the parent block time plus 12 seconds. The first ledger transaction in Mainnet block 1788980 fails that check. On v1.0.300, a node that syncs Mainnet from genesis stops at block 1788979 with Intent TTL has expired (#2229).

When the corrected check fails, node v1.0.400 retries the transaction at the block's own timestamp, so the sync gets past block 1788979. Blocks produced after the runtime upgrade, which took effect on Mainnet at block 2738210, never take this path. (#2238)

If your node stopped at block 1788979 on v1.0.300, restart it on v1.0.400.

Toolkit 1.0.400​

Toolkit 1.0.400 ships with this release as the midnightntwrk/midnight-node-toolkit:1.0.400 image and as tarballs on the GitHub release. It uses the same ledger 8.1.3 crates as the node, so it applies the same rules when it builds or replays transactions. Toolkit 1.0.300 still reads blocks from the unchanged runtime, but use toolkit 1.0.400 with node v1.0.400.

The toolkit version command prints Node: 1.0.400, Ledger: =7.0.3, and Compactc: 0.30.0. The Ledger line shows the ledger 7 version that the toolkit also contains, not ledger 8.1.3.

The toolkit image no longer includes the shx and shelljs npm packages or the dependencies that only they used. Removing the shx development dependency from the toolkit JavaScript harness clears the npm audit findings that it raised. (#2238)


Known issues​

No known issues in this release. If a node that syncs Mainnet from genesis on v1.0.400 stops at a later block, report it in the midnight-node issue tracker.