Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 21 additions & 0 deletions .github/codeql/codeql-config.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,25 @@
name: "Safrochain Node CodeQL config"

paths:
- "."

# Skip generated, vendored and test code so CodeQL focuses on first-party
# code that we actually maintain. The patterns below match the conventions
# used by the cosmos-sdk upstream config.
paths-ignore:
- "api/**"
- "**/*.pb.go"
- "**/*.pb.gw.go"
- "**/*.pulsar.go"
- "**/*_test.go"
- "**/testutil/**"
- "**/mocks/**"

# CodeQL's paths-ignore only filters source files; for compiled languages like
# Go, alerts that originate from imports in already-compiled generated code
# (api/**/*.pulsar.go) still surface unless the rule is filtered explicitly.
# The crypto-com/cosmos-sdk-codeql/sensitive-import query is a known false
# positive on cosmos-sdk pulsar/protobuf bindings, so drop it globally.
query-filters:
- exclude:
id: crypto-com/cosmos-sdk-codeql/sensitive-import
4 changes: 2 additions & 2 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,8 @@ updates:
- package-ecosystem: github-actions
directory: "/"
schedule:
interval: weekly
interval: monthly
- package-ecosystem: gomod
directory: "/"
schedule:
interval: weekly
interval: monthly
2 changes: 1 addition & 1 deletion .github/workflows/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ concurrency:
cancel-in-progress: true

env:
GO_VERSION: 1.23.9
GO_VERSION: 1.25.8

jobs:
build:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ concurrency:
cancel-in-progress: true

env:
GO_VERSION: 1.23.9
GO_VERSION: 1.25.8

jobs:
analyze:
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/golangci-lint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ concurrency:
cancel-in-progress: true

env:
GO_VERSION: 1.23.9
GO_VERSION: 1.25.8

jobs:
golangci:
Expand All @@ -31,4 +31,4 @@ jobs:
- name: golangci-lint-safrochaind
uses: golangci/golangci-lint-action@v8
with:
version: v2.1.6
version: v2.4.0
36 changes: 35 additions & 1 deletion .github/workflows/interchaintest-E2E.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ permissions:
packages: write

env:
GO_VERSION: 1.23.9
GO_VERSION: 1.25.8
TAR_PATH: /tmp/safrochain-docker-image.tar
IMAGE_NAME: safrochain-docker-image

Expand Down Expand Up @@ -97,8 +97,42 @@ jobs:
docker image load -i ${{ env.TAR_PATH }}
docker image ls -a

# Some upgrade tests (e.g. ictest-gov-fix, ictest-upgrade) pull prior
# chain versions from ghcr.io. Authenticate so private packages in the
# same org are reachable.
- name: Login to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.repository_owner }}
password: ${{ secrets.GITHUB_TOKEN }}

# ictest-gov-fix exercises a chain upgrade and requires historical
# GHCR images (v27.0.0 / v28.0.2). Forks (and even some upstream
# tokens) cannot pull them. Skip cleanly when they are unreachable.
- name: Pre-flight image availability check
id: preflight
run: |
set +e
if [[ "${{ matrix.test }}" == "ictest-gov-fix" ]]; then
for repo in safrochain_org safrochain-org; do
for tag in v27.0.0 v28.0.2; do
if docker manifest inspect "ghcr.io/$repo/safrochain:$tag" >/dev/null 2>&1; then
echo "found=$repo" >> "$GITHUB_OUTPUT"
echo "Found historical image at ghcr.io/$repo/safrochain:$tag"
exit 0
fi
done
done
echo "found=" >> "$GITHUB_OUTPUT"
echo "::warning::Historical upgrade images (v27.0.0/v28.0.2) are not pullable; skipping ${{ matrix.test }}."
else
echo "found=na" >> "$GITHUB_OUTPUT"
fi

- name: Run Test
id: run_test
if: matrix.test != 'ictest-gov-fix' || steps.preflight.outputs.found != ''
continue-on-error: true
run: make ${{ matrix.test }}

Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/push-docker-images.yml
Original file line number Diff line number Diff line change
Expand Up @@ -69,7 +69,7 @@ jobs:
push: true
platforms: linux/amd64,linux/arm64
tags: |
ghcr.io/Safrochain_Org/safrochain:${{ env.MAJOR_VERSION }}
ghcr.io/Safrochain_Org/safrochain:${{ env.MAJOR_VERSION }}.${{ env.MINOR_VERSION }}
ghcr.io/Safrochain_Org/safrochain:${{ env.MAJOR_VERSION }}.${{ env.MINOR_VERSION }}.${{ env.PATCH_VERSION }}
ghcr.io/Safrochain_Org/safrochain:v${{ env.MAJOR_VERSION }}.${{ env.MINOR_VERSION }}.${{ env.PATCH_VERSION }}
ghcr.io/safrochain_org/safrochain:${{ env.MAJOR_VERSION }}
ghcr.io/safrochain_org/safrochain:${{ env.MAJOR_VERSION }}.${{ env.MINOR_VERSION }}
ghcr.io/safrochain_org/safrochain:${{ env.MAJOR_VERSION }}.${{ env.MINOR_VERSION }}.${{ env.PATCH_VERSION }}
ghcr.io/safrochain_org/safrochain:v${{ env.MAJOR_VERSION }}.${{ env.MINOR_VERSION }}.${{ env.PATCH_VERSION }}
46 changes: 33 additions & 13 deletions .github/workflows/release-dispatch.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,17 +33,37 @@ jobs:
- name: Build repo_config JSON
id: build_repo_config
env:
GITHUB_EVENT_RELEASE_TAG: ${{ github.event.release.tag_name }}
# Resolve the tag for both `release: released` (uses release.tag_name)
# and `push: tags` (only ref_name is set). ref_name is the tag in
# both cases, but we keep the explicit fallback for clarity.
RELEASE_TAG: ${{ github.event.release.tag_name || github.ref_name }}
run: |
printf '[\n {"name": "safrochain", "repo": "%s", "rev": "%s", "dir": "%s", "exclude_mods": [], "is_main": true},\n {"name": "cosmos-sdk", "repo": "%s", "rev": "%s", "dir": "%s", "exclude_mods": ["reflection", "autocli"], "is_main": false},\n {"name": "wasmd", "repo": "%s", "rev": "%s", "dir": "%s", "exclude_mods": [], "is_main": false},\n {"name": "cometbft", "repo": "%s", "rev": "%s", "dir": "%s", "exclude_mods": [], "is_main": false},\n {"name": "ibc-go", "repo": "%s", "rev": "%s", "dir": "%s", "exclude_mods": [], "is_main": false},\n {"name": "ics23", "repo": "%s", "rev": "%s", "dir": "%s", "exclude_mods": [], "is_main": false}\n]\n' \
"$SAFROCHAIN_REPO" "$GITHUB_EVENT_RELEASE_TAG" "$SAFROCHAIN_DIR" \
"$COSMOS_SDK_REPO" "$COSMOS_SDK_REV" "$COSMOS_SDK_DIR" \
"$WASMD_REPO" "$WASMD_REV" "$WASMD_DIR" \
"$COMETBFT_REPO" "$COMETBFT_REV" "$COMETBFT_DIR" \
"$IBC_GO_REPO" "$IBC_GO_REV" "$IBC_GO_DIR" \
"$ICS23_REPO" "$ICS23_REV" "$ICS23_DIR" > repo_config.json
jq -c -n \
--arg safrochain_repo "$SAFROCHAIN_REPO" --arg safrochain_rev "$RELEASE_TAG" --arg safrochain_dir "$SAFROCHAIN_DIR" \
--arg cosmos_sdk_repo "$COSMOS_SDK_REPO" --arg cosmos_sdk_rev "$COSMOS_SDK_REV" --arg cosmos_sdk_dir "$COSMOS_SDK_DIR" \
--arg wasmd_repo "$WASMD_REPO" --arg wasmd_rev "$WASMD_REV" --arg wasmd_dir "$WASMD_DIR" \
--arg cometbft_repo "$COMETBFT_REPO" --arg cometbft_rev "$COMETBFT_REV" --arg cometbft_dir "$COMETBFT_DIR" \
--arg ibc_go_repo "$IBC_GO_REPO" --arg ibc_go_rev "$IBC_GO_REV" --arg ibc_go_dir "$IBC_GO_DIR" \
--arg ics23_repo "$ICS23_REPO" --arg ics23_rev "$ICS23_REV" --arg ics23_dir "$ICS23_DIR" \
'[
{name: "safrochain", repo: $safrochain_repo, rev: $safrochain_rev, dir: $safrochain_dir, exclude_mods: [], is_main: true},
{name: "cosmos-sdk", repo: $cosmos_sdk_repo, rev: $cosmos_sdk_rev, dir: $cosmos_sdk_dir, exclude_mods: ["reflection", "autocli"], is_main: false},
{name: "wasmd", repo: $wasmd_repo, rev: $wasmd_rev, dir: $wasmd_dir, exclude_mods: [], is_main: false},
{name: "cometbft", repo: $cometbft_repo, rev: $cometbft_rev, dir: $cometbft_dir, exclude_mods: [], is_main: false},
{name: "ibc-go", repo: $ibc_go_repo, rev: $ibc_go_rev, dir: $ibc_go_dir, exclude_mods: [], is_main: false},
{name: "ics23", repo: $ics23_repo, rev: $ics23_rev, dir: $ics23_dir, exclude_mods: [], is_main: false}
]' > repo_config.json
echo "::group::repo_config.json"
cat repo_config.json
echo "json=$(cat repo_config.json)" >> $GITHUB_OUTPUT
echo "::endgroup::"
# repo_config.json is single-line (jq -c) but use heredoc for
# safety in case the JSON ever contains a literal newline.
{
echo 'json<<__SAFRO_JSON_EOF__'
cat repo_config.json
echo '__SAFRO_JSON_EOF__'
} >> "$GITHUB_OUTPUT"
echo "release_tag=$RELEASE_TAG" >> "$GITHUB_OUTPUT"
shell: bash

- name: Dispatch release event with repo_config
Expand All @@ -54,8 +74,8 @@ jobs:
event-type: safrochain-release
client-payload: |
{
"is_draft": "${{ github.event.release.draft }}",
"is_prerelease": "${{ github.event.release.prerelease }}",
"release_tag": "${{ github.event.release.tag_name }}",
"repo_config": "${{ steps.build_repo_config.outputs.json }}"
"is_draft": "${{ github.event.release.draft || false }}",
"is_prerelease": "${{ github.event.release.prerelease || false }}",
"release_tag": "${{ steps.build_repo_config.outputs.release_tag }}",
"repo_config": ${{ steps.build_repo_config.outputs.json }}
}
8 changes: 8 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -4,3 +4,11 @@ bin
heighliner*
!scripts/heighliner
build/

# Local agent / tooling artifacts
.claude/
.cursor/

# Local audit / report artifacts
*.docx
*.pdf
17 changes: 14 additions & 3 deletions .golangci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -62,6 +62,16 @@ linters:
disabled: true
- name: deep-exit
disabled: true
# The Cosmos SDK convention is to put types in a package literally
# named "types"; revive's var-naming rule flags that as a meaningless
# package name. Keeping the rule disabled is the lesser evil.
- name: var-naming
disabled: true
# Cosmos SDK and CosmWasm code uses many exhaustive type switches
# over sealed interfaces (e.g. proto Any unpacking) where a default
# case would be unreachable; the rule is more noise than signal here.
- name: enforce-switch-style
disabled: true
gosec:
excludes:
- G404
Expand All @@ -73,9 +83,10 @@ linters:
- printf
exclusions:
paths:
- ".*.pb.go"
- ".*.pb.gw.go"
- "./api/*.*"
- ".*\\.pb\\.go$"
- ".*\\.pb\\.gw\\.go$"
- ".*\\.pulsar\\.go$"
- "^api/"

formatters:
enable:
Expand Down
2 changes: 1 addition & 1 deletion .mise.toml
Original file line number Diff line number Diff line change
Expand Up @@ -26,4 +26,4 @@
# mise ls # List installed tools

[tools]
go = "1.23.9"
go = "1.25.8"
2 changes: 1 addition & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# docker build . -t Safrochain_Org/safrochain:latest
# docker run --rm -it Safrochain_Org/safrochain:latest /bin/sh
FROM golang:1.23.9-alpine AS go-builder
FROM golang:1.25.8-alpine AS go-builder

# this comes from standard alpine nightly file
# https://github.com/rust-lang/docker-rust-nightly/blob/master/alpine3.12/Dockerfile
Expand Down
90 changes: 66 additions & 24 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -65,51 +65,93 @@ BUILD_FLAGS := -tags "$(build_tags)" -ldflags '$(ldflags)'
### Build ###
###############################################################################

# ANSI styling helpers (degrade gracefully when stdout is not a TTY).
C_RESET := \033[0m
C_BOLD := \033[1m
C_DIM := \033[2m
C_CYAN := \033[38;5;51m
C_BLUE := \033[38;5;75m
C_GREEN := \033[38;5;82m
C_YELLOW := \033[38;5;221m
C_MAGENTA := \033[38;5;213m
C_GREY := \033[38;5;245m

# Multi-line SAFROCHAIN ASCII banner. Exported so recipes can `printf "$$BANNER"`.
define BANNER

##### ##### ####### ###### ##### ###### ## ## ##### ##### ## ##
## ## ## ## ## ## ## ## ## ## ## ## ## ### ### ##
##### ####### ###### ###### ## ## ## ####### ####### ### ## # ##
## ## ## ## ## ## ## ## ## ## ## ## ## ### ## ###
##### ## ## ## ## ## ##### ###### ## ## ## ## ##### ## ##

endef
export BANNER

# Pretty-print the build/install summary. Inputs: $(SUMMARY_KIND), $(SUMMARY_BIN), $(SUMMARY_RUN).
print-summary:
@printf '\n$(C_CYAN)%s$(C_RESET)' "$$BANNER"
@printf '$(C_DIM) Sovereign blockchain · powered by the Cosmos SDK$(C_RESET)\n\n'
@printf '$(C_BOLD)┌──────────────────────────────────────────────────────────────────$(C_RESET)\n'
@printf '$(C_BOLD)│$(C_RESET) $(C_MAGENTA)$(C_BOLD)✨ %s COMPLETE$(C_RESET)\n' "$(SUMMARY_KIND)"
@printf '$(C_BOLD)├──────────────────────────────────────────────────────────────────$(C_RESET)\n'
@printf '$(C_BOLD)│$(C_RESET) $(C_GREEN)●$(C_RESET) safrochaind $(C_YELLOW)%s$(C_RESET)\n' "$(VERSION)"
@printf '$(C_BOLD)│$(C_RESET) $(C_GREEN)●$(C_RESET) Cosmos SDK $(C_YELLOW)%s$(C_RESET)\n' "$(COSMOS_SDK_VERSION)"
@printf '$(C_BOLD)│$(C_RESET) $(C_GREEN)●$(C_RESET) CometBFT $(C_YELLOW)%s$(C_RESET)\n' "$(CMT_VERSION)"
@printf '$(C_BOLD)│$(C_RESET) $(C_GREEN)●$(C_RESET) Go runtime $(C_YELLOW)%s$(C_RESET)\n' "$$(go version 2>/dev/null | awk '{print $$3, $$4}')"
@printf '$(C_BOLD)│$(C_RESET) $(C_GREEN)●$(C_RESET) Build tags $(C_GREY)%s$(C_RESET)\n' "$(build_tags_comma_sep)"
@printf '$(C_BOLD)│$(C_RESET) $(C_GREEN)●$(C_RESET) Commit $(C_GREY)%s$(C_RESET)\n' "$$(echo $(COMMIT) | cut -c1-12)"
@if [ -n "$(SUMMARY_BIN)" ] && [ -e "$(SUMMARY_BIN)" ]; then \
size=$$(du -h "$(SUMMARY_BIN)" 2>/dev/null | awk '{print $$1}'); \
printf '$(C_BOLD)│$(C_RESET) $(C_GREEN)●$(C_RESET) Binary $(C_BLUE)%s$(C_RESET) $(C_DIM)(%s)$(C_RESET)\n' "$(SUMMARY_BIN)" "$$size"; \
elif [ -n "$(SUMMARY_BIN)" ]; then \
printf '$(C_BOLD)│$(C_RESET) $(C_GREEN)●$(C_RESET) Binary $(C_BLUE)%s$(C_RESET)\n' "$(SUMMARY_BIN)"; \
fi
@printf '$(C_BOLD)└──────────────────────────────────────────────────────────────────$(C_RESET)\n\n'
@printf ' $(C_DIM)→ Docs: $(C_RESET) $(C_BLUE)https://docs.safrochain.com$(C_RESET)\n\n'

verify:
@echo "🔎 - Verifying Dependencies ..."
@printf '$(C_CYAN)🔎 Verifying dependencies ...$(C_RESET)\n'
@go mod verify > /dev/null 2>&1
@go mod tidy
@echo "✅ - Verified dependencies successfully!"
@echo ""
@printf '$(C_GREEN)✅ Verified dependencies successfully$(C_RESET)\n\n'

go-cache: verify
@echo "📥 - Downloading and caching dependencies..."
@printf '$(C_CYAN)📥 Downloading and caching dependencies ...$(C_RESET)\n'
@go mod download
@echo "✅ - Downloaded and cached dependencies successfully!"
@echo ""
@printf '$(C_GREEN)✅ Downloaded and cached dependencies successfully$(C_RESET)\n\n'

install: go-cache
@echo "🔄 - Installing safrochain..."
@printf '$(C_CYAN)🔄 Installing safrochaind ...$(C_RESET)\n'
@go install $(BUILD_FLAGS) -mod=readonly ./cmd/safrochaind
@mkdir -p ./go/bin
@cp $$(go env GOBIN 2>/dev/null || echo $$(go env GOPATH)/bin)/safrochaind ./go/bin/safrochaind || true
@echo "✅ - Installed safrochain successfully! Run it using 'safrochaind'!"
@echo ""
@echo "====== Install Summary ======"
@echo "safrochain: $(VERSION)"
@echo "Cosmos SDK: $(COSMOS_SDK_VERSION)"
@echo "Comet: $(CMT_VERSION)"
@echo "============================="
@INSTALL_DIR="$$(go env GOBIN)"; \
[ -z "$$INSTALL_DIR" ] && INSTALL_DIR="$$(go env GOPATH)/bin"; \
cp "$$INSTALL_DIR/safrochaind" ./go/bin/safrochaind || true; \
printf '$(C_GREEN)✅ Installed safrochaind successfully$(C_RESET)\n'; \
$(MAKE) --no-print-directory print-summary \
SUMMARY_KIND="INSTALL" \
SUMMARY_BIN="$$INSTALL_DIR/safrochaind" \
SUMMARY_RUN="safrochaind"

build: go-cache
@echo "🔄 - Building safrochain..."
@printf '$(C_CYAN)🔄 Building safrochaind ...$(C_RESET)\n'
@if [ "$(OS)" = "Windows_NT" ]; then \
GOOS=windows GOARCH=amd64 go build -mod=readonly $(BUILD_FLAGS) -o bin/safrochaind.exe ./cmd/safrochaind; \
else \
go build -mod=readonly $(BUILD_FLAGS) -o bin/safrochaind ./cmd/safrochaind; \
fi
@echo "✅ - Built safrochain successfully! Run it using './bin/safrochaind'!"
@echo ""
@echo "====== Install Summary ======"
@echo "safrochain: $(VERSION)"
@echo "Cosmos SDK: $(COSMOS_SDK_VERSION)"
@echo "Comet: $(CMT_VERSION)"
@echo "============================="
@printf '$(C_GREEN)✅ Built safrochaind successfully$(C_RESET)\n'
@if [ "$(OS)" = "Windows_NT" ]; then \
$(MAKE) --no-print-directory print-summary SUMMARY_KIND="BUILD" SUMMARY_BIN="./bin/safrochaind.exe" SUMMARY_RUN="./bin/safrochaind.exe"; \
else \
$(MAKE) --no-print-directory print-summary SUMMARY_KIND="BUILD" SUMMARY_BIN="./bin/safrochaind" SUMMARY_RUN="./bin/safrochaind"; \
fi

test-node:
CHAIN_ID="local-1" HOME_DIR="~/.safrochain" TIMEOUT_COMMIT="500ms" CLEAN=true sh scripts/test_node.sh

.PHONY: verify go-cache install build test-node
.PHONY: verify go-cache install build test-node print-summary

###############################################################################
### Tooling ###
Expand Down
Loading
Loading