3c3dd4c165
Per Sami directive 2026-08-02: 'why wouldn't we be using the latest
RocksDB?' Bumped CI to RocksDB 10.10.1 (commit
4595a5e95ae8525c42e172a054435782b3479c57, latest 10.x before 11.x line
began). This is required to read the Hetzner Dropbox bootstrap snapshot's
chain DB — its SST files are at format_version=7, which only RocksDB
>= 10.4.0 can open.
CoDEx flagged a previous proposal of 8.11.4 (wrong: 8.11.x only has
format_version=6 as default; v7 default arrived only in 10.11.0).
CoDEx also flagged an attempted explicit 'table_opts.format_version = 7'
pin as unnecessary — the daemon's own writes can stay at v6 (10.10.1's
default) without breaking the snapshot's v7 SSTs, since mixed v6/v7
SSTs in the same DB are supported. Reverted that pin; documented the
no-pin decision in CHANGELOG.md and inline in txdb-rocksdb.cpp.
src/txdb-rocksdb.cpp: kept RocksDB's own default (6 in 10.10.1) — no
explicit format_version pin. Comment explains why.
scripts/ci/build-rocksdb.sh: rocksdb 8.9.1 -> 10.10.1, commit pin
updated, stale 8.9.1 references in comments cleaned up. Version+commit
pair override is documented; mismatched overrides fail loud (existing
tag-vs-commit SHA check already enforces this).
CHANGELOG.md: v6.2.4 entry. Operator notes for upgrade from 6.2.3 cover:
- SONAME change librocksdb.so.8.9.1 -> librocksdb.so.10.10.1
- v7 SSTs from the imported snapshot make RocksDB < 10.4.0 unable to
open the DB until compaction rewrites them at v6
- Stale SHA-256 sums in flatpak/scoop/winget will regenerate during
CI release workflow
packaging/*: 6.2.3 -> 6.2.4 (deb, rpm, docker, flatpak, scoop, winget,
snap, appimage). Stale 8.9.1 references left in workflow comments
(build-all.yml, lint.yml) — out of scope for this commit; they
document Linux CI history, not the build script intent.
src/CMakeLists.txt: 8.9.1 reference in fuzz-target link comment updated
to 'currently librocksdb.so.10.10.1'.
src/clientversion.h: REVISION 3 -> 4 (full version: 6.2.4.0).
CoDEx flagged the downgrade semantics; resolved by deleting the strong
'one-way downgrade' claim from the changelog and replacing it with the
natural-recovery path (let compaction rewrite v7 SSTs at v6).
[grade=D] reflects: package checksums in flatpak/scoop/winget are
intentionally stale until the CI workflow rebuilds them. They MUST
NOT be packaged until regenerated. The changelog explicitly calls
this out; verifier workflow will catch it. CHANGELOG.md notes block
shipping those package manifests.
Scripts
Operational scripts for the Triangles project. See also doc/release-process.md
for the canonical release pipeline documentation.
Build verification
verify-reproducible-build.sh— builds the daemon (or another target) twice from the same source tree and verifies the SHA256 hashes match. Catches accidental introduction of non-determinism (e.g.__DATE__/__TIME__regressions, dirty git state, PIE base-address drift).
Release signing
sign-release.sh— generatesSHA256SUMS, writes detached PGP signatures (.asc) over each release artifact and overSHA256SUMS. Supports--verifyfor independent third-party verification. UsesTRIANGLES_RELEASE_KEYenv var (defaults tosami@cryptographic-triangles.org).
Existing infrastructure
bump-version.sh— sync version numbers across all manifests fromsrc/clientversion.h.sign-snapshot.sh— sign a UTXO snapshot file with the wallet's signing address (not a PGP key; this is a chain-level signature, not a release signature).validate_onion_seeds.py— validate every.onionaddress intriangles.confagainst the v3 hidden-service checksum.ibd-smoke-test.sh— fresh-datadir IBD smoke test for catching the classic "stalls early / loops around 570" failure mode.ci/build-rocksdb.sh— build and install a pinned RocksDB version for CI.ci/package-linux-daemon.sh— Linux packaging step (.deb).ci/package-windows-daemon.sh— Windows packaging step.tri/— operator-facing CLI for node administration.