Roadmap
Stop compiling test-utils into production builds
This PR removes the `test-utils` feature from the default list in `amaru-consensus`, which meant the test logic was included in the compilation process of any production build of `amaru`. This mostly has no tangible benefit (the compiler would drop the unreferenced test logic), but it does remove 3 crates from the binary and may save a few seconds in compilation. It does mean that it is semantically correct to use and enable `test-utils`, and a future accidental reference will error during compilation.
Forge Header Effect
This PR introduces the effect and the trait used to forge headers, as well as new world tests by @rkuhn. It also includes the changes introduced in, and therefore supersedes, #1375.
consolidate reconnect and resolv timers
fixes #1428
add EDR on KES key handling
fixes #1414
add simulation mode for measuring effect timings
The effect timing infrastructure has been in place for a while, but only network transmissions are actually simulated with latency.
implement basic in-process CredentialsResource
This is for trying out block forging on preprod or preview only, just build the simplest thing possible.
add EDR on KES key handling
rough sketch:
Extend the CBOR conformance coverage
### Abstract
Report the coverage of the cbor dataset against the specification + edge cases
### Abstract
Check the conformance of flat decoding
### Abstract
Remove "Nightly Synchronization" job and simplify e2e test setup
### Abstract
fix: verify both slot and hash
`BlockFetch` only succeeds if both asked slot and hash match.
feat: allow 3rd party dev to have full PR run
Make sure external contributors PR can run fully so that anyone can get good DX.
TUI improvements: 1s/3s/5s percentiles, peer scores
The score is not yet used in peer selection, that part is still awaiting a proper overhaul.
remove generic_const_exprs feature
fixes #1406
chore: added missing peer staging
<!-- This is an auto-generated comment: release notes by coderabbit.ai -->
feat: add API for bootstrap and mithril progress report
This PR exposes bootstrap and Mithril synchronization as reusable library workflows, with cancellation, crash recovery, and canonical progress reporting shared by the CLI and embedding applications.
trace schema distinguishes spans from events
first step of #1422
proper linking of events and spans for header and block perf telemetry
including world loop test to assert proper OTel structure
parent span requirements can be formulated in trace schema
second step of #1422
panic when starting with 50 upstream peers
``` thread 'amaru-node' (5842001) panicked at crates/amaru-pure-stage/src/tokio.rs:646:21: stage `connector-12` exceeded priority mailbox size (10): too many outstanding scheduled messages ```
perf(amaru-uplc): defer builtin cost argument sizing
~15-20% performance improvements; but more importantly, avoids potential heavy resource usage for some types when evaluating costs.
decode each VersionData with its own version, keep bytes is unknown
fixes #1425
add staggered block fetching
fixes #1423
Generate .env from clap's definitions (for node run + node bootstrap & globals)
See also #1404.
Correct usage of NAME in tracing EDR
Names are only for tracing events, not for naming spans.
make blockperf logs selectable via AMARU_LOG and inculde peer
- **log blockperf at DEBUG** - **blockperf logging, live vs sync mode** - **clean up logs at transition from sync to live**
more rigorous implementation of trace span EDR
Currently, we have a trace schema governing the properties and their types which must be present when creating an event or span. What we lack is:
fix: make decoders conform to the cbor dataset
This PR fixes the decoding gaps exposed by the cbor dataset generated in the [`cardano-cbor-dataset` repository](https://github.com/r2rationality/cardano-cbor-dataset/pull/1).
Update packages metadata for v10.11.20260925
Updates packages metadata generated from the published release [`v10.11.20260925`](https://github.com/pragma-org/amaru/releases/tag/v10.11.20260925).
clean cli and align options with EDR-019 - guidelines for cli
This is a bit painful, but waiting longer for this is not going to help. With adoption growing and more and more docs being produced, we need to anchor the "final" api surface for users real soon. The best moment to do this was 6 months ago. The second best moment is now.
Compilation warning
When compiling locally
Forging Credentials Resource
### Abstract
ci: some fixes
<!-- This is an auto-generated comment: release notes by coderabbit.ai -->
fix: explicitely set network when starting oura
Expose typed mempool services for embedders
### Abstract
refactor(ledger): address post-merge review
Addresses KtorZ's post-merge comments on #1309 revert BackgroundTasks to `Arc<HS>`, eliminate the `stake_distributions deque`, and restore `Sync` on `HistoricalStores`.
add forge_block stage
fixes #1361 fixes #1362
fix: workaround github api rate limits
Make sure CI doesn't fail due to GH API rate limit (unauthenticated calls). Relies on git clone instead.
add session type verification of typestate protocol handlers
This is the last preparatory step before moving all mini-protocol handlers to the new typestate API. It gives us full binary session type verification of the wire protocol in mermaid syntax, including timeouts (*) and `WantNext` and with a generic (i.e. independently auditable) implementation of pipelining.
Amaru for epoch-end ledger audits
First, let me thank you for Amaru. I'm currently working on [Tessera](https://tessera-preview.matthieu-pizenberg.workers.dev/), a tool implementing [CIP-179 on-chain surveys](https://github.com/cardano-foundation/CIPs/blob/master/CIP-0179/README.md). We want survey results to be reproducible and independently verifiable, so Amaru is one of the options I've explored. This is an experience report about what I did, and where I struggled.
chore: improve PR safety
**Currently blocked due to API rate limits while accessing peer snapshots. We might need to reconsider current approach**
fix(amaru): add missing systemd units definitions to debian archive.
fix(amaru-ledger): prune descendants of expired proposals
Fix governance ratification so that:
Reorganize Leadership Logic
In an attempt to familiarize myself with the new `forge_block` stage, I pulled the code locally and decided to isolate the leadership calculation logic. My goal is to decouple the "business logic" (Cardano-specific logic) from the pure stage wiring as much as possible, while also using the type system to restrict illegal states as much as possible. This is my proposed organization, and we can replicate this design for other pieces of the business logic. This means the computation logic lives with the storage logic, and is easier to read, review, and understand since it's not tangled into pure …
fix(tui): restore terminal before reporting panics
Make sure panic message is properly shown when tui is enabled.
amaru.env config file filled with avalaible Variables
### Abstract
chore: proper node shutdown
This PR does 2 main thing:
world loop test for block forging
Add a new scenario where the network starts from a snapshot matching the nodes’ KES key setup so that 100% stake is available for block forging. The network shall then be judged by whether it produces the expected chain density at acceptable levels of (slot|height) battles.
Discrepancy with Haskell's node on pools fallback drep
### What revision are you using?
Optimize reward payouts using RocksDB merge operators
### Abstract
Monitor RocksDB metrics
### Abstract
check and improve inbound connection limit handling
Currently, the handshake concludes successfully and then the bearer is dropped if the inbound connection limit is exceeded. We should investigate how the Haskell implementation signals this to the peer and possibly improve the behaviour accordingly.
check quality of peers shared by peer_sharing
Markus found the following when looking at the peers shared by Amaru:
Persist findings of consensus behaviour in Cardano blueprints
As discussed in Porto last week, any gaps found in the Ouroboros network spec shall eventually be filled with information on https://github.com/cardano-scaling/cardano-blueprint. This ticket serves as a reminder to myself that I should start with the notes taken in Porto from very fruitful discussions with Marcin M.
get rid of “analyzing changelog ...” notifications
no-changelog
test: run decoding tests from a node-agnostic test suite
This PR adds a test suite that checks the decoding expectations of the conformance test suite created in the [`cbor-dataset` repository](https://github.com/r2rationality/cardano-cbor-dataset):
fix(progress): leave completed terminal progress bars visible
<!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit
fix: decode uplc with smaller stack
Playing on iOS, I got some issues with stack sizes and uplc decoding. Building on top of recent related changes, use similar technics to solve that.
feat: test full sync nightly
Make sure full sync is tested every day. This will help catch new issues that might arise from new blocks.
chore: reduce trace levels
Traces that can happen w/o breaking amaru should be `warn`ings.
Fix mithril sync after bootstrap
This is a proposed fix for #1390
fix: more resilient pipe
Skip-Changelog
baby steps towards more readable typestate errors
The main problem with typestate is that the compiler diagnostics in case of error are very verbose and hard to read. This PR makes the types easier to read and adds a `Session::remainder(&self) -> &str` method for pretty-printing the current typestate.
feat(amaru-tui): simplify keyboard controls and improve copy mode
Few changes:
Block Forging EDR
This PR introduces the first draft of our block forging EDR. Refining this document will help is iron out the details of the design of block forging.
Update packages metadata for v10.11.20260918
Updates packages metadata generated from the published release [`v10.11.20260918`](https://github.com/pragma-org/amaru/releases/tag/v10.11.20260918).
New "Compact" Data Structures
Fixes #1147
Stack safe recursive types and tests
A "counter-proposal" to #1378; though I did preserve some of the commits, refactors and tests written on that occasion.
Metadatum Multi-era Decoding
### Abstract
fix startup after block validation error
Previously (and this was a complaint from users), after a false block validation error manual intervention on the chainstore was needed to get the node syncing again. While this would be tolerable, the bigger issue was that subsequent restarts would NOT show the validation error again, instead they would connect to peers and reject all received headers, sitting their idly because all headers “build upon an invalid block”.
Load and Validate OpCert and Cold Verification Key
### Abstract
Address CBOR Decoding FIXMEs
This PR progresses #1174, but doesn't necessarily close it entirely. Some of the FIXMEs there are left for other PRs or future work because they are more significant overhauls, or they need to be considered more deeply.
chore: harden cargo update
<!-- codesmith:footer --> --- <a href="https://app.blacksmith.sh/pragma-org/codesmith/amaru/pr/1372"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-light-v2.svg"><img alt="View with [code]smith" src="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"></picture></a> <a href="https://backend.blacksmith.sh/track/enable-autofix?expires=179206734…
some test and trace output fixes
- **avoid spamming logs when tests succeed** - **fix bytestring serde serialization**
Cleanup Property Generators
Closes #1216
Fix Changelog Workflow
Fix/improve the changelog workflow to support PR description edits, report better information about misplaced headers/content, and start posting the PR comment again.
fix: better store error handling
<!-- codesmith:footer --> --- <a href="https://app.blacksmith.sh/pragma-org/codesmith/amaru/pr/1373"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-light-v2.svg"><img alt="View with [code]smith" src="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"></picture></a> <a href="https://backend.blacksmith.sh/track/enable-autofix?expires=179207049…
bench epoch transition at scale
This pr adds a divan benchmark that seeds a RocksDB with realistic pools, UTxOs, and accounts, drives a State to the epoch boundary, and measures the full transition including the background rewards thread, pool updates, and stable flush.
Add KES Signing and Key Evolution
### Abstract
Check the conformance of cbor encoding with the Haskell node
### Abstract
chore: fix actions by sha
Make sure all GH actions: * have their versions set as sha * are of the same version across usages * are using the latest version, when make sense
TUI: clarify when tui mode shall exit and how
Currently, `amaru node run` may open the TUI and immediately close it, leaving nothing on the console.
Automatic release process for crates
In preparation for a release of the `amaru` crate on crates.io we need to install the following mechanisms:
Bootstrap should fill db with blocks
### Abstract
Optimize startup time edge case
### Abstract
Purge Mempool Transactions on Block Adoption
### Abstract
Mempool: For Some Parent and Slot, Provide a Block Body
### Abstract
Trace Schemas for Forging
### Abstract
Audit the Locally Forged Block Consensus Logic
### Abstract
Amaru Watermark in Protocol Minor Version
### Abstract
Build a Header and Block Body for a Led Slot
### Abstract
Compute Leader Schedule for an Epoch
### Abstract
WARN on Local Clock Drift
### Abstract
Block Forging CLI Commands
### Abstract
TUI: Forging View
### Abstract
Block multi-era decoding
### Abstract
Witness Set v12 Decoding
### Abstract
fix(mithril): make synchronization resilient
Improve Mithril synchronization correctness and resilience.
Update packages metadata for v10.11.20260912
Updates packages metadata generated from the published release [`v10.11.20260912`](https://github.com/pragma-org/amaru/releases/tag/v10.11.20260912).
Fix off-by-one epoch check on CC member and action expiry + fix immediate cc resolution post ratification
- :round_pushpin: **feat(amaru-ledger): dump the state of the constitutional committee on startup.**
Blacksmith runner minor cost saving
<!-- codesmith:footer --> --- <a href="https://app.blacksmith.sh/pragma-org/codesmith/amaru/pr/1342"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-light-v2.svg"><img alt="View with [code]smith" src="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"></picture></a> <a href="https://backend.blacksmith.sh/track/enable-autofix?expires=179172266…
feat: add Amaru user-guide documentation
This PR contains the documents for **Milestone 2: Building the state of the art and the public sources of “how to operate a Cardano node” (August)** as part of the Amaru projetct : _Operations & Use Cases: Devops and SPO relationship_
chore: systemd and default environment tweaks for Debian and RPM archives
<!-- This is an auto-generated comment: release notes by coderabbit.ai -->
Fix workflow concurrency and introduce blacksmith.sh runners for some jobs.
<!-- codesmith:footer --> --- <a href="https://app.blacksmith.sh/pragma-org/codesmith/amaru/pr/1341"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-light-v2.svg"><img alt="View with [code]smith" src="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"></picture></a> <a href="https://backend.blacksmith.sh/track/enable-autofix?expires=179171140…
Update CONTRIBUTING.md - Committers
Added clarification that the Amaru committers group are people under contract
fix: fetch candidate CC members from volatile and stable proposals
@arwlf reported an invalid block on mainnet with the following logs:
refactor: move `any_` functions as `Arbitrary` proptest! instance
### Abstract
Flat-decoding optimizations
## Abstract
make inbound upstream quantity configurable in peer mix
fixes #1334
advertise protocol V15 in consensus handshake
fixes #1332
add a simulation test for the “peer behind NAT” situation
to check that we can receive headers and blocks from a node we cannot dial
improve observability of new peer management
<sub>Stack created with <a href="https://github.com/github/gh-stack">GitHub Stacks CLI</a> • <a href="https://gh.io/stacks-feedback">Give Feedback 💬</a></sub>
use full-duplex peer connections
actually promote inbound connections to upstream peers without opening a second connection; also demote them when uninteresting without tearing down the bearer
implement peer churn
gracefully remove upstreams as per the Cardano churn schedule (20% every hour with some timing jitter); the metrics this is based on are still not refined, just the mechanism is implemented properly
use inbound or outbound connection as desired
start / stop protocol handlers gracefully to switch between the different usage levels for a bearer
properly terminate protocol handlers
Bearer termination is only adequate in case of peer misbehaviour, protocols can be shut down in a graceful fashion.
correctly implement bearer lifecycle
- model local use for maintenance or diffusion - tear down based on error or selection decision
remove concurrency infrastructure from ledger state
Closes the follow-up agreed in #1290, ref #1094 removes all remaining concurrency infrastructure from the ledger state, so stable and stake_distributions lose their Arc<Mutex> and the rewards background task now receives snapshot handles by value and returns the rotated stake distribution through its join handle instead of writing into shared state, verified with the full workspace suite plus a live preprod sync to tip of about 9,300 blocks including an epoch transition and rewards computation with no errors the read only era_history and global_parameters Arcs are left in place and I am happy …
feat: allow to cancel bootstrap process
Allow the bootstrap process to be cancelled using a `tokio_util::sync::CancellationToken`. Especially useful for 3rd party apps doing a bootstrap, as bootstrap process can take some significant time.
improve TUI log component: search, filter, retention
found that I want to use the TUI a bit more and built in some less-ish behaviour
implement mux level timeouts
<sub>Stack created with <a href="https://github.com/github/gh-stack">GitHub Stacks CLI</a> • <a href="https://gh.io/stacks-feedback">Give Feedback 💬</a></sub>
fix handshake negotiation
fixes #884
pure-stage typestate API: first step
This PR is intended to allow the upcoming stack of connection handling PRs to be built on their designated foundation. The precise typestate API and its application to all mini-protocols will continue to evolve in parallel.
update to Rust 1.100
This introduces the !/never type that I’ll want to use later, but it also enables several new cargo lints that took some effort to adhere to.
Update packages metadata for v10.11.20260903
Updates packages metadata generated from the published release [`v10.11.20260903`](https://github.com/pragma-org/amaru/releases/tag/v10.11.20260903).
fix: release should sign commit
Make sure commits from the release PR are signed.
chore: no need for custom stack anymore
Now that bootstrap is streamed, no more need for custom increased stack.
chore: move tx submission test to dedicated workflow
Move tx submission test to dedicated workflow. This reduce stress and time required to merge a PR, and simplify running PR by external contributors (as this requires access to a preprod wallet private key).
feat: consolidation telemetry global options
<!-- This is an auto-generated comment: release notes by coderabbit.ai -->
feat: allow to selectively export OTLP signals
By default all OLTP signals are exported (metrics, logs and spans) while end users might be interested in only a subset of those. If some collector path is missing then errors will be printed amaru side (client here in this scenario).
feat: improve log progress for non-tty use cases
When user run amaru on non-tty env (like embedded, as part of systemd,..) ouput appears stuck as interactive progress bar is diabled. Improve this by detecting when tty is not enabled on printing periodic progress as regular logs.
add world simulation tests
- **add full network simulation tests** - **run many simulated test scenarios**
run ledger on a dedicated thread
Closes #1094. The ledger now runs on its own dedicated thread that fully owns the ledger state, as described in EDR-012 callers send it request messages over a channel and get results back through a reply channel in each message, which removes the shared lock, the traits and effect wiring are unchanged, and stake distribution already ran on a background thread so nothing was needed there. Verified with the full workspace test suite plus a live preprod run, the node validated and adopted 24,830 blocks in 17 minutes through the new thread with no errors.
Increase Ledger Coverage
Closes #885
more principled peer resoluation
fixes #1257
feat: test e2e tx submission
Allow to easily test e2e tx submission, up to the point it is properly included in a peer mempool. Both from CI and local scripts.
Ledger predicate: VRFKeyHashAlreadyRegistered
### Abstract
VRF Key Uniqueness Validation - Take 2
Local transaction is not being diffused, despite peers asking?
### What revision are you using?
Add rust docs to TraceContext
As a way to solidify my understanding and softening the learning curve of future devs, the interplay between `tracing`, `opentelemetry` and serialization/deserialization (esp. with the `TraceBuffer`) should be spelt out.
Disentangle ledger store
### Abstract
amaru snapshot create fails with "Permission denied (os error 13)" when no --dist-dir and --snapshot-dir is given
### What revision are you using?
Correct behavior around invalid phase two transactions
Currently, Amaru runs all validation rules when a transaction has `is_valid: false`. This is a divergence from the Haskell implementation, where only the `UTXOW` state transition rule runs (which includes the `UTXO and UTXOS` rules). The `UTXOS` rule branches on `isValid`. The state update is also different, only the UTxO state changes are persisted (and here, it is the collateral spend and return only).
Cardano Node Diversity platform
### Abstract
Optimize the download of transactions in the txsubmission protocol across several peers
### Abstract
Support chained transactions in the mempool
### Abstract
Do not revalidate transactions that are already in the Mempool
### Abstract
Consider memory + cpu execution units when computing the available mempool capacity
### Abstract
Perform integrity/sanity check of the ledger & chain db
### Abstract
Update the animations for the simulation
### Abstract
Add ledger checks to the simulation
### Abstract
Add the txsubmission protocol to the simulation
### Abstract
Epoch Transition Benchmark
### Abstract
Granular Ledger Benchmarks
### Abstract
Global Ledger Benchmarks
### Abstract
Enable the TraceBuffer in production
### Abstract
Use a separate column family for `BEST_CHAIN_PREFIX`
### Abstract
Promote downstream connections to initiator mode on incoming connections (warm -> hot peer transition)
### Abstract
fix amaru-sim test termination
### Abstract
Publish on brew
Add bench capacities
Add a new `bench` subcommands allowing to provide metrics about current hosts. Those should be relevant to `amaru` e.g.
Allow to browse static JSON
`amaru` can output JSON traces. Allow to open them and display details.
Allow to browse metrics
OpenTelemetry offers metrics primitives. Create a new screen allowing to see at a glimpse the most important ones exposed by amaru. It should leverage ratatui primitives to display metrics.
Visualise current network connections state
Showing the state of incoming/outgoing (or initiator/responder as mini protocols' terminology has it) would be useful to troubleshoot a node's state. In particular, we'll need to be able to trigger disconnections of "faulty" nodes so while we'll obviously trace that, visualising the links from/to a node would be nice.
Publish on crates.io
Will allow use of https://github.com/cargo-bins/cargo-binstall
Add static querying capacities
`amaru` should offer static querying capacities e.g. access db details
Allow to search DReps by ids
Add VIM keybindings for navigation
Make sure VIM like keybindings are added on top of regular keybindings for navigation between various panels.
Add a main screen showing off instances details
Could take inspiration from https://github.com/blinklabs-io/nview
Publish on crates
This is currently blocked by amaru not being published on crates
Introduce indexing
Searching entities by most key requires full scan. Introduce a local index mechanism to speed things up.
Allow to be used as a library
Make sure `amaru-doctor` can be used as a library in `amaru` directly.
Allow to browse resource deltas between two epochs
fix: pad contingency registry_script.hash to 28 bytes
One-character JSON fix in `journal/2026/metadata.json`.
Add CAG off-ramp address to journal metadata
The journal `metadata.json` currently lists only scope_owners and the five treasury script anchors. Designated off-ramp / vendor-coordination addresses (per CAG MSA §1.7) live only in off-chain email and in per-tx on-chain rationale references[].