0
Teams
0
GitHub Links
Link Types:GitHubInternal (roadmap.vac.dev)ExternalTask ID

IFT-TS 2026/09/07

top highlights

  • DST team completed a Logos Delivery packet-loss study and observed a crash under load at 1,000 nodes; a fix landed upstream that day.
  • NIM team merged the Nim book into the development branch and presented it at the Townhall.
  • INFRA team upgraded the Rocketpool oDAO node to release 1.22.1.
  • SEC team reported five high-severity and six medium-severity LEZ audit findings.

team highlights

  • BI: Prepared the automatic Keycard report.
  • BI: Updated log extraction for Logos Blockchain monitoring.
  • BI: Fixed Status Engagement Bot bugs and worked on release preparation.
  • DST: Rebuilt nim-libp2p regression nodes with reproducible builds and updated lockfiles.
  • DST: Identified a potential anoncomms service-discovery issue in runs with nim-libp2p v2.3.0.
  • DST: Investigated a persistent Blend bug apparently related to the number of proposed blocks.
  • DST: Confirmed matching CPU configurations and tested governor changes for slow-proof workloads.
  • DST: Completed a Logos Delivery packet-loss study; the supplied build crashed under load at 1,000 nodes.
  • DST: Added packet-loss controls and updated log parsing for message-delivery experiments.
  • INFRA: Upgraded the Rocketpool oDAO node to release 1.22.1.
  • INFRA: Migrated four Lido hosts to the TYO2 data center and deployed new validator keys.
  • INFRA: Deployed Nimbus execution-layer infrastructure on Sepolia for ERE file generation.
  • INFRA: Deployed NBS Nim to CI hosts to reduce Status build times.
  • INFRA: Worked on reinstalling compromised macOS CI hosts and developed their Wazuh monitoring role.
  • INFRA: Completed Elasticsearch security and TLS transport configuration.
  • NIM: Merged Nimble lockfile URL fixes and PubGrub explanations for failed dependency resolution.
  • NIM: Added Chronos Win32 CI and fixed calling-convention errors on Windows i386.
  • NIM: Enabled garbage-collected task results in nim-taskpools.
  • NIM: Fixed a Chronos hang when waiting for child processes on Windows.
  • NIM: Merged the Nim book into the development branch and presented it at the Townhall.
  • P2P: Advanced nim-libp2p reliability fixes for dialing, rendezvous, message handling, and stream setup.
  • P2P: Integrated Delivery-based RLN coordination into Mix-RLN components.
  • P2P: Standardized nim-libp2p log fields and added a severity policy.
  • P2P: Merged dialing backoffs and overlapped ranked dialing with name resolution.
  • P2P: Reduced nim-ffi CI from 104 jobs to 29 and advanced generated Logos Storage bindings.
  • QA: Expanded Logos Basecamp MCP tests for workspace, sidebar, app manager, and inspector behavior.
  • QA: Advanced Logos Execution Zone sequencer-registration scenarios and test prerequisites.
  • QA: Merged AutoTLS integration coverage and ACME request fixes.
  • QA: Expanded Status Desktop Keycard coverage and fixed signing compatibility with applet 3.2.
  • QA: Ran Status Mobile backend peers in containers on CI and resolved long-press test failures.
  • QA: Traced a 160 MB status-go memory increase to a vendor bump.
  • SEC: Closed the DPRK supply-chain incident and contained a macOS CI mining compromise.
  • SEC: Surfaced 16 new audit findings, including nine rated high severity; triage remains outstanding.
  • SEC: Approved the merged status-go protobuf update and downstream Status app changes.
  • SEC: Reported five high-severity and six medium-severity Logos Execution Zone audit findings.
  • SEC: Scoped the external Logos Blockchain audit and finalized the internal audit guideline.

ift-ts:bi:

ift-ts:dst:

ift-ts:infra:

  • develp
    • Fixed Dune query for validator exits by adjusting engine
    • Submitted new compounding validator key for Develp staking
    • Rocketpool oDAO node upgrade to 1.22.1 release
  • lido
    • Migrated another 4 hosts from tyo1 to tyo2 data center
    • Deployed new Lido CMv2 keys to new tyo2 master hosts
    • Converted master hosts to cheaper Teraswitch servers
    • Prepared Lido services migration to master nodes
    • Improvements to bonded network interfaces on tyo2 hosts
  • staking
    • Timing games Commit-boost configuration testing prepared
    • Nimbus beacon node patched to allow for timing games
  • nimbus
    • Setup of data import necessary for Nimbus-eth1 ERE files generation
    • Deployed nimbus-eth1 EL to Sepolia testnet for ERE files generation
    • Multiple build issues resolved for nimbus-eth1 client
  • logos
    • Processed organization validation for DigiCert Logos signing cert
    • Research into Logos storage setup for Logos package manager
    • Research into logos.dev fleet automatic deployments
  • waku
    • Removed more Elastic IPs from Waku fleets to reduce costs
  • status
    • Status Nix PR for Linux builds finally ready to merge
    • Deployed NBS Nim to CI hosts to reduce Status build times
    • Deployed new protobuf needed by status-go builds
    • Debugging Keycard build issues with Linux Docker image
    • Work on Status Bot engagement feature requested by Volo
    • Work on Status Bot and Discourse post bridging
    • Migrated DO Status prod store DB to smaller host
    • Addition of LiFi API keys for swaps in Jenkins CI
  • proxy
    • Cleanup of Status Network configuration from proxy service
  • other notes
    • Decommissioned two unused wakudev hosts after consulting devs
  • sites
    • Permission role adjustments for Logos stewards website
    • Acid Info admin panel environment adjustments
  • office
    • Research into expiring Matrix MAS auth sessions based on Keycloak status
  • ci
    • Addressing CVE-2026-65400 hack on Jenkins CI slave hosts, postmortem
    • Reinstallation of compromised Jenkins MacOS CI slave hosts
    • Development of Wazuh monitoring Ansible role for MacOS hosts
    • Deployed Github Actions metrics exporter for new Logos enterprise
    • Off-boarding for multiple former contributors and access audit
    • Debugged CI GitHub pull timeouts caused by new GH rate limiting
    • Added missing keycard-tech organization to Gitea mirroring
    • Re-bootstrapping Windows hosts to provide more E2E runners
    • Fixed broken Gitea API health check broken by upgrade and auth change
    • Fixed Nix installation by locking nixos-26.05 channel
  • hq
    • Completed enabling of security and TLS transport for ElasticSearch
    • Fixed broken Logstash aggregation due to missing Nimbus logs cleanup

ift-ts:nim:

ift-ts:p2p:

ift-ts:qa:

ift-ts:sec:

  • ift-ts:sec:ift:2026q3-ir-vulma:security-incidents
    • DPRK supply-chain IR (declared 2026-08-10) closed — final radiken orphan-commit sweep, endpoint scan, and visitor risk assessment done; no longer tracked
    • New IR 2026-09-04: macOS CI host macm2-01.ih-eu-mda1.ci.release compromised via VNC 5900 left open publicly — commodity mining campaign (auto.c3pool.org:443, com.apple.airportd / .config/sysmond masquerade; IOCs confirmed with 0xM3R)
    • Forensics with jakubgs found matching Nix, Brew, and Qt 6.11.0 checksums against a clean host; reported no compromised CI components.
    • Root cause fixed: VNC 5900 VPN-only (92e9129), MTR Exporter 8002 closed (bca5921)
    • HackenProof triage — two valid Status reports: Status-476 (vote-weight unit mismatch: whole-token SNT vs raw base units), Status-479 (finalizeVotingRoom snapshots at executing block — flash-loan reuse across voters)
  • ift-ts:sec:ift:2026q3-ir-vulma:vulnerability-management
  • ift-ts:sec:ift:2026q3-ssdlc-security-keycard-vulnerability-reviews
    • Keycard workstream dropped — no longer tracked; open items (keycard-shell#220, audit findings #95 / #93) handed back to the Keycard team
  • ift-ts:sec:ift:2026q3-tr-wallet-security:audit-treasury-multisig
  • ift-ts:sec:ift:2026q3-cicd-security-review:code-review-activities
  • ift-ts:sec:ift:2026q3-threat-intelligence:supply-chain-attack-research
    • Continued npm / OAuth / CI-tool supply-chain watch; folded macOS CI incident IOCs (auto.c3pool.org:443, com.apple.airportd / .config/sysmond masquerade) into detection notes — commodity campaign, not targeted
  • other notes
    • Offboarding: access review and revocation for new leavers (PATs, SSH keys, OAuth, Notion workspace)
    • Reviewed pending PAT requests; iterated on security checklist and Copilot policy
  • ift-ts:sec:ift:2026q3-internal-audit:logos-execution-zone-security-review
  • ift-ts:sec:ift:2026q3-internal-audit:logos-blockchain-security-review
    • Scoped external audit
    • Finalized the internal audit guideline
    • Reported one finding: #155