diff --git a/src/content/docs/updates/developer/2026-09-14-to-2026-09-21.md b/src/content/docs/updates/developer/2026-09-14-to-2026-09-21.md new file mode 100644 index 0000000..26bf46f --- /dev/null +++ b/src/content/docs/updates/developer/2026-09-14-to-2026-09-21.md @@ -0,0 +1,85 @@ +--- +title: "September 14–21, 2026" +description: "Verified Dusk engineering progress from the previous seven days, with disclosure-safe summaries and public source links." +sidebar: + hidden: true +--- + +[← Developer Updates](/updates/developer/) + +This update covers verified engineering progress during the previous seven days. Work in private repositories is summarized without private links or implementation identities; links to public changes appear directly beside the summaries they support. + +## Rusk + + +### Core (Private Repo) + +Reduced archive bookkeeping and consolidated shared node logic to simplify maintenance and testing. +- Removed temporary archive benchmarks and retained the maintained performance-test suite. +- Reused Rust compilation outputs between compatible CI jobs and checked benchmark targets in their intended build configuration. +- Shared finalized archive lookup data and applied only each block's new entries after its database write succeeded, avoiding repeated copies of growing dictionaries. +- Documented finalized-event ordering and added checks for pagination, restart and retry behavior. +- Centralized upgrade-rule definitions to reduce duplicated maintenance. +### Wallet (Private Repo) + +Strengthened wallet operations for more dependable account handling. +### Piecrust (Private Repo) + +Strengthened contract execution handling for more dependable application behavior. + +## Bls12\_381 + +Expanded curve-point validation and regression coverage to strengthen the library's handling of untrusted inputs. +- Prepared version 0.15.0 metadata and its changelog, corrected the documented Rust minimum, and excluded CI configuration from the package. ([PR #186](https://github.com/dusk-network/bls12_381/pull/186)) +- Added public-API tests for malformed point encodings, curve boundaries, scalar arithmetic and multi-scalar multiplication across serial and parallel configurations. ([PR #187](https://github.com/dusk-network/bls12_381/pull/187), [PR #182](https://github.com/dusk-network/bls12_381/pull/182)) +- Bounded hash-expansion lengths and decoded fixed-size hexadecimal values into stack arrays, reducing avoidable allocations while preserving accepted formats. ([PR #185](https://github.com/dusk-network/bls12_381/pull/185)) +- Added opt-in checks for individual and nested archived curve points, checked multi-scalar multiplication inputs, and required pairing caches to be reconstructed from validated points. ([PR #181](https://github.com/dusk-network/bls12_381/pull/181), [PR #180](https://github.com/dusk-network/bls12_381/pull/180)) + +## Jubjub + +Expanded scalar and point regression tests to check encoding, arithmetic and coordinate conversions without changing production behavior. ([PR #174](https://github.com/dusk-network/jubjub/pull/174)) + +## Connect + +Validated provider-supplied settings and preserved connection state to make application reads and wallet selection more dependable. +- Updated the SDK's Vitest test dependency from 4.1.4 to 4.1.11. ([PR #40](https://github.com/dusk-network/connect/pull/40)) +- Restricted discovered wallet icons to embedded image data, preventing the picker from requesting remote icon URLs. ([PR #50](https://github.com/dusk-network/connect/pull/50)) +- Validated node URLs, added bounded read timeouts and an explicit application read-node setting, and presented discovered wallet branding as self-reported. ([PR #47](https://github.com/dusk-network/connect/pull/47)) +- Rejected delayed profile and address results after a session changed, while preserving valid overlapping reads and submitted transaction results. ([PR #39](https://github.com/dusk-network/connect/pull/39)) + +## Wallet + +Improved wallet unlocking, private-balance recovery and account-index validation to preserve user state across asynchronous operations. +- Moved wallet tests from Vitest 4.1.9 to 4.1.11. ([PR #111](https://github.com/dusk-network/wallet/pull/111)) +- Restricted BLS account indices to whole numbers from 0 to 255 and added checks that signing approvals remained isolated between requesting sites. ([PR #118](https://github.com/dusk-network/wallet/pull/118)) +- Preserved password entry and focus during passive unlock-screen updates, cleared the form on completion, and prevented duplicate submissions. ([PR #116](https://github.com/dusk-network/wallet/pull/116)) +- Linked private-balance caches to block hashes, rebuilt invalid caches, saved scan progress with note data, and cancelled outdated synchronization work while preserving pending spending reservations. ([PR #109](https://github.com/dusk-network/wallet/pull/109)) + +## Wallet discovery + +Split temporary wallet identities from saved preferences and stabilized provider selection across the SDK and wallet. +- Separated temporary wallet identities from saved product preferences. When identities collided, the SDK retained the first valid provider without treating discovery metadata as authentication. ([PR #48](https://github.com/dusk-network/connect/pull/48), [PR #43](https://github.com/dusk-network/connect/pull/43)) +- Assigned each page's wallet provider a temporary discovery identifier while retaining its separate message-routing identity. ([PR #115](https://github.com/dusk-network/wallet/pull/115)) + +## Typed-data signing + +Added shared typed-data signing across the SDK and wallet, with bounded encoding, explicit approval details and application-verification guidance. +- Added automated checks against encoded reference data and native BLS signatures, and clarified prominent site display and application contract scoping. ([PR #12](https://github.com/dusk-network/typed-data/pull/12)) +- Added shared-library signing with trusted site and network checks and an expandable full request view. Disabled signing when the displayed request couldn't be verified or exceeded display limits. ([PR #114](https://github.com/dusk-network/wallet/pull/114), [PR #112](https://github.com/dusk-network/wallet/pull/112)) +- Integrated the shared signing library through optional imports, keeping cryptographic code out of the main SDK and requiring trusted network and site expectations for verification. ([PR #41](https://github.com/dusk-network/connect/pull/41)) +- Prepared package metadata and changelog entries for version 0.1.0-rc.0 without changing encoder behavior; the protocol specification remained a draft. ([Commit b46ac9ea](https://github.com/dusk-network/typed-data/commit/b46ac9ea020376d8f805d229cdf70b5310c304d5)) +- Limited message structure and repeated processing while preserving accepted encodings. Documented application checks for the expected signer, network, site, contract and validity period, with single-use approvals consumed in one operation. ([PR #9](https://github.com/dusk-network/typed-data/pull/9), [PR #8](https://github.com/dusk-network/typed-data/pull/8)) + +## Web-wallet + +Removed retained account references on reset and blocked delayed synchronization or unlock results from restoring a previous wallet session. ([PR #953](https://github.com/dusk-network/web-wallet/pull/953)) + +## Safe + +Changed hashing to reuse validated input so custom adapters couldn't substitute different data between checking and use. ([PR #41](https://github.com/dusk-network/safe/pull/41)) + +## Jubjub-schnorr + +Required canonical signature responses in the VarGen circuit; adopting the change requires matching proving and verification keys. ([PR #85](https://github.com/dusk-network/jubjub-schnorr/pull/85)) + +[← Back to Developer Updates](/updates/developer/) diff --git a/src/content/docs/updates/developer/index.mdx b/src/content/docs/updates/developer/index.mdx index 8ee3cd1..2e735a1 100644 --- a/src/content/docs/updates/developer/index.mdx +++ b/src/content/docs/updates/developer/index.mdx @@ -5,6 +5,10 @@ description: Browse periodic Dusk engineering updates by publication date and co Developer updates summarize engineering work over a stated interval. Updates are listed newest first. +## [September 14–21, 2026](/updates/developer/2026-09-14-to-2026-09-21/) + +Verified engineering progress across 8 public repositories, plus disclosure-safe summaries of qualifying private development. + ## [September 7–14, 2026](/updates/developer/2026-09-07-to-2026-09-14/) Verified engineering progress across 9 public repositories.