# Kiwistand v0.7.0 released Source: https://github.com/attestate/kiwistand/blob/main/changelog.md#070 Methodology We are versioning according to semver.org We are currently in the "Initial development phase" Unreleased 0.15.0 BREAKING CHANGE: Chunk trie sync so one frame no longer grows with the tree Sync used to put every node of a level, and then every missing leaf, into a single length-prefixed message. That payload grew with the trie, which is why maxDataLength went 4MB → 8MB → 16MB → 32MB. A level and its missing leaves are now sent as several frames of at most 1 MiB. Each frame is the same CBOR array as before, so the receiver stores it the same way. maxDataLength is 2 MiB: a ceiling for one frame, not for the trie. It does not need to move again as the tree grows. Breaking Changes Protocol versions bumped: Pubsub topics (roots/messages): 11.0.0 → 12.0.0 Protocols (leaves/levels): 14.0.0 → 15.0.0 Migration All nodes must upgrade together. A 15.0.0 node will not sync with a 14.0.0 node. 0.14.0 BREAKING CHANGE: Add text post support with inline content This release adds support for submitting text-only posts using data:text/plain, URLs, allowing users to share thoughts and discussions directly without requiring external links. Breaking Changes Protocol versions bumped: Pubsub topics (roots/messages): 10.0.0 → 11.0.0 Protocols (leaves/levels): 13.0.0 → 14.0.0 Validation schema updated: href field now accepts data:text/plain, URLs (up to 2048 chars) Pattern: ^(https?://|data:text/plain,|kiwi:0x) New Features Text Post Submission: New textarea in submit form with 2048 character limit Inline Storage: Text content stored as data:text/plain, URLs with encodeURIComponent encoding Story Display: Text content renders on story pages between subtitle and action buttons Feed Behavior: Text posts appear in feeds without preview (consistent with comment links) No Domain Badge: Text posts don't show domain badges (data: and kiwi: URLs) Preview Generation: OG images generated with empty domain for social sharing Security DOMPurify sanitization at all rendering points Frontend validation: maxLength constraint (2048 characters) Safe encoding: encodeURIComponent for storage Title sanitization: getSlug() uses DOMPurify Bug Fixes Fixed frame image path generation (was incorrectly stripping extra characters from index) Migration All nodes must upgrade to maintain P2P connectivity. Nodes on different protocol versions will not sync with each other. Text posts will only be recognized by nodes running 0.14.0+. 0.13.0 BREAKING CHANGE: Increase P2P sync message size limit to 32MB Increased maxDataLength from 16MB to 32MB in sync protocol (src/sync.mjs) Fixes "message length too long" errors during trie reconciliation Required as trie grows larger and deeper levels contain more nodes to sync Protocol versions bumped: Pubsub topics (roots/messages): 9.0.0 → 10.0.0 Protocols (leaves/levels): 12.0.0 → 13.0.0 Migration: All nodes must upgrade to maintain P2P connectivity. Nodes on different protocol versions will not sync with each other. 0.12.0 BREAKING CHANGE: Complete removal of Kiwi Pass NFT-based access control system This release removes the entire NFT/allowlist concept from Kiwistand and simplifies to delegation-only access control. Breaking Changes Protocol versions bumped: Pubsub topics: 8.0.0 → 9.0.0 Protocols (leaves/levels): 11.0.0 → 12.0.0 API Changes: Removed /allowlist endpoint Removed fetchAllowList() from frontend API Delegator2 SDK (@attestate/delegator2): eligible(allowlist, delegations, address) → resolveIdentity(delegations, address) Removed all NFT-related functions: eligibleAt(), extractLegacyObject(), legacyEligibleAt(), _eligibleAt() Removed Components Backend: src/chainstate/mainnet-mints.mjs - Mainnet NFT tracking src/chainstate/mint.config.crawler.mjs - NFT mint crawler src/chainstate/transfer-loader.mjs - NFT transfer loader Registry functions: allowlist(), refreshAccounts(), augmentWithMainnet() Frontend: src/web/src/BuyButton.jsx - NFT purchase component src/web/src/TelegramLink.jsx - Telegram integration src/web/src/LeaderboardStats.jsx - Community stats src/views/kiwipass-mint.mjs - NFT minting page src/views/indexing.mjs - NFT indexing wait page src/views/invite.mjs - Invite page src/views/leaderboard.mjs - Community leaderboard Routes: /community, /invite, /indexing, /kiwipass-mint How It Works Now Any address can act on its own behalf If an address has delegated to another address, resolveIdentity() resolves it to the delegator No more NFT/allowlist checks anywhere in the codebase All identity resolution is done purely through the delegation system Migration Guide If you're running a node: Update to the latest version The system will automatically work with the new delegation-only model No manual migration needed - existing delegations continue to work If you're using the API: Replace calls to /api/v1/allowlist with /api/v1/delegations Update any code using eligible() to use resolveIdentity() 0.11.0 (breaking) Fixed critical bug in allowlist crawler that halted allowlist progression since the Delegator3/smart account switch in August 2025. Background: When commit 14baab66 updated the system to use Delegator3 contract (0x418910fef46896eb0bfe38f656e2f7df3eca7198), the ABI for the setup function was correctly updated to match Delegator3's on-chain interface, which only accepts bytes32[3] data as a parameter (removing the beneficiaries and amounts arrays that existed in Delegator2). However, the transfer-loader.mjs code was not updated accordingly - it still attempted to extract and use input.beneficiaries and input.amounts after decoding. Since these fields no longer exist in Delegator3's return value, this caused the decoder to throw errors on every Delegator3 transaction, completely halting the allowlist crawler. Impact: The allowlist stopped updating after the Delegator3 switch. Users who minted Kiwi Passes during this period (several weeks) were not added to the allowlist and could not interact with the site. All production nodes were affected. Fix (commit c8a92a7c): Removed the code that tried to access non-existent beneficiaries and amounts fields (src/chainstate/transfer-loader.mjs:67-76, 113-122) Added try-catch blocks around decodeFunctionData to handle any decoding errors gracefully Now correctly processes Delegator3 transactions with the updated ABI How to upgrade your existing node? CRITICAL: All nodes running the broken version have corrupted/incomplete op-call-block-logs-load data and MUST re-sync: Navigate to your DATA_DIR Delete the op-call-block-logs-load directory Run: DATA_DIR=/path/to/your/data npm run sync Wait until the logs show: "op-call-block-logs loader strategy has finished" Your node is now fully synchronized with the correct allowlist 0.10.1 Fix npm run reconcile 0.10.0 (breaking) To make Kiwi News compatible with smart wallets and EIP-4337, we've made some breaking changes to the delegator2 contract. Instead of relying on transaction.from, it now emits msg.sender from within the contract, hence allowing paymasters etc. to call etch in the name of the Kiwi Pass controlling address. This however means that we have, for the time being, added all other signers as a plain text file to the code base, meaning that the old delegator2 contract at 0x08b7ECFac2c5754ABafb789c84F8fa37c9f088B0 will not count anymore when delegating upvoting/commenting power to a new address. Instead all apps will have to start using the new contract: 0x418910fef46896eb0bfe38f656e2f7df3eca7198. For a proper upgrade path where signers can both be revoked and used from both delegator2 contracts we'll have to combine their logs. It's not clear to me whether all of this work would be worth it or whether it would be simpler to just call the delegator2@0.5.1 period its own epoch, add all its messages to a merkle tree and then just consider them valid if they appear as a member. For this release, I did the simplest possible thing because I felt as if this work wouldn't pay off to do properly as we're still not really making money with Kiwi. Anyways, as the above change will interact with what messages nodes are considering valid, we've bumped the version to 0.10.0 and we've also upgraded our version identifiers in libp2p. We highly recommend all node operators to upgrade. How to upgrade your existing node? Run npm i then run cd src/web && npm i -f In your DATA_DIR, rename list-delegations-load-2 (to back it up) Run npm run sync. It will run very briefly (this is fine) That's it, you should be good to go 0.9.0 (breaking) Add token tracking to allow to precisely determine during reconciliation if someone was eligible to post during a period. For more details of what this feature consists of, read the changelogs of the dependencies: @attestate/crawler-call-block-logs@0.5.0 @attestate/delegator2@0.5.0 and 0.5.1 Essentially with this release we're laying the groundwork for our later 1 pass = 1 upvote change. For more details, see this document. If you're running a node in version 0.9.0 it is required to re-sync the node using npm run sync. For this, in your DATA_DIR, delete the op-call-block-logs folder, then run npm run sync until you catch up again with the OP mainnet chain tip. This is necessary as we have to load each chain interactions respective tokenId into the mints database. (breaking) For those who are running a kiwistand node in npm run reconcile mode, we've fixed a bug that could have allowed an upvote to be stored twice. If you've done this, please delete the data.mdb and lock.mdb file from your DATA_DIR and re-reconcile with the network from scratch. We're including many other changes in this release, none of which are supposed to be breaking. Most changes are related to the product and the front end. This release doesn't include any breaking changes to the protocol itself, which is why we've also not bumped the protocol version identifiers. It, however, contains the above breaking changes for anyone currently running a node, which is why this release is a minor patch version increase. 0.8.0 (breaking) Double it-length-prefixed length Fixes in reconciliation algorithm Caution: If you're running a node and you must preserve its reconciliation data, it is best get in touch with us directly via Telegram. If you can afford to just delete the reconciliation data and start over, we suggest you do this. 0.7.0 (breaking) Fixed a bug in the constraints metadata db. Details: https://github.com/attestate/kiwistand/commit/37ba938a811b39ec6e88887eaa278d393b72ff6b Caution: If you're running a node, read this carefully and potentially get in touch! Hardcode mainnet mints to preserve mainnet timestamps of minting Optimism mint crawler records timestamps of mints Mints can now be tracked separately Many frontend updates 0.6.0 Upgrade all libp2p version identifiers Move all eligible-defining NFTs to oeth:0x66747bdc903d17c586fa09ee5d6b54cc85bbea45 Deprecate RPC_HTTP_HOST Fix bugs with indexing logs. attestate/crawler order function was ordering logs based on blockIndex and transactionIndex, but logIndex was necessary too. We've essentially created two new indexing strategies ("list-delegations-2", and "op-call-block-logs"). store.posts now tolerates finding "in-eligible" messages Added docs that explain how Kiwi News Protocol's set reconciliation works Use a DFS to traverse the tree for posts (thank you to @freeatnet!) 0.5.0 Deactivate revocations temporarily until we're properly implementing them in the set reconciliation algorithm. Details. Upgrade all protocol major versions. 0.4.0 Require new environment variable OPTIMISM_RPC_HTTP_HOST Website: Minor stylistic changes Protocol: All semantic version identifiers have been upgraded as a major version to avoid name collisions with nodes running older versions of this software. API POST /api/v1/list endpoint now adds two new properties to a message identity and signer. POST /api/v1/messages now accepts messages signed from a delegate address. Docs Document difference in ports between API and frontend 0.3.0 Environment Variables Rename TIMESTAMP_TOLERANCE_SECS to MAX_TIMESTAMP_DELTA_SECS Separate HTTP_PORT (for website) and API_PORT (for node API) Remove all TODAYS_EDITOR_... variables Add Sphinx docs Many changes to the frontend (won't list details) Separated website frontend from node API frontend. They now run on differnet ports. The allowlist registry now guarantees returning a set of unique Ethereum addresses. The level's remote comparisons are now validated at the receiving node with a JSON schema. For the frontend (mainly), ecrecover can now cache recovering signatures. Logging of errors in the reconciliation algorithm has been improved. The "leaves" function can now be called with a "startDatetime" parameter to speed up database queries. Database migration This release contains an incompatible database migration from earlier releases! If you actually need to migrate from 0.2.0 to 0.3.0, contact @timdaub! LMDB now uses "ordered-binary" key encoding to enable range based key queries. Our message hashing and identity generation was broken and so messages weren't canonically hashed. This had to be addressed in a database migration and by fixing the canonicalization. Again, if you really must migrate your data, make sure to contact us beforehand! We enabled "useNodePruning" in ethereumjs/trie (this gets rid of deleted nodes). Protocols Upgrade "leaves" protocol to v3.0.0 Improve PMT traversal algorithm that had a bug when branching factor was too big (vendored in WalkController from ethereumjs/trie). Improved atomic committments of data entry within set reconciliation. Made both metadb and trie transactional. 0.2.0 We discovered a critical issue in the v0.1.0 code base that lead to digests of messages in the ordering algorithm to be non-canonical [1] (thanks @freeatnet). We're fixing this using npm:canonicalize that implements RFC8785 for canonical JSON. Since we already had nodes in the network with existing data we shipped our first migration too. It checks for the digest algorithm, and applies a migration accordingly. We strongly recommend doing a backup of the DATA_DIR before applying the v0.2.0 update. To avoid synchronizations between v0.1.0 nodes and v0.2.0 nodes, we upgraded all protocol and pubsub identifiers and versions too to avoid corrupting data bases. 1: https://github.com/attestate/kiwistand/commit/debb66ab676053a82b9aab789f68049a5c9a4528 0.1.0 Initial release of Kiwi News run until 2023-05-06