From 151956be3d32b60ed75594ac212cf2394879e066 Mon Sep 17 00:00:00 2001 From: alexander-sei Date: Fri, 25 Sep 2026 13:38:24 +0200 Subject: [PATCH 1/5] Update v6.7 changelog in prep to cut rc3 Adds the release/v6.7 entries merged since the rc2 changelog (#4293), in prep to cut v6.7.0-rc3: #4334, #4315, #4313, the rc2 version bump (#4295), and the rc2 changelog backport (#4294). Regenerated with ./scripts/generate-changelog.sh release/v6.6 release/v6.7. Co-authored-by: Cursor --- CHANGELOG.md | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index bf67234657..b5ecf8d587 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -68,6 +68,11 @@ Ref: https://keepachangelog.com/en/1.0.0/ * [#3927](https://github.com/sei-protocol/sei-chain/pull/3927) **Legacy Sei JSON-RPC and CLI removal.** Removes `sei_associate`, `sei_getBlockByHash`, `sei_getBlockByHashExcludeTraceFail`, `sei_getBlockTransactionCountByHash`, `sei_getBlockTransactionCountByNumber`, `sei_getEvmTx`, `sei_getFilterChanges`, `sei_getFilterLogs`, `sei_getLogs`, `sei_getTransactionByBlockHashAndIndex`, `sei_getTransactionByBlockNumberAndIndex`, `sei_getTransactionByHash`, `sei_getTransactionCount`, `sei_getTransactionErrorByHash`, `sei_getTransactionReceiptExcludeTraceFail`, `sei_getVMError`, `sei_newBlockFilter`, `sei_newFilter`, `sei_sign`, and `sei_uninstallFilter`. Use standard `eth_*` methods for EVM-originated data and `seid tx evm native-associate -y` for address association. There is no block- or filter-level replacement for discovering Cosmos-originated synthetic logs; clients that know the synthetic transaction hash can enable `sei_getTransactionReceipt`. sei-chain +* [#4334](https://github.com/sei-protocol/sei-chain/pull/4334) Backport `release/v6.7`: Fail dynamic-gas precompile out-of-gas as an EVM out-of-gas call +* [#4315](https://github.com/sei-protocol/sei-chain/pull/4315) Backport `release/v6.7`: Pin the Go builder image per architecture in build-static.sh +* [#4313](https://github.com/sei-protocol/sei-chain/pull/4313) Backport `release/v6.7`: fix(memiavl): hold a snapshot reference for an iterator's lifetime +* [#4295](https://github.com/sei-protocol/sei-chain/pull/4295) Bump version to v6.7.0-rc2 in prep for release +* [#4294](https://github.com/sei-protocol/sei-chain/pull/4294) Backport `release/v6.7`: Update v6.7 changelog in prep to cut rc2 * [#4292](https://github.com/sei-protocol/sei-chain/pull/4292) Backport `release/v6.7`: Flush MemIAVL changelog before exiting on an upgrade panic * [#4285](https://github.com/sei-protocol/sei-chain/pull/4285) Backport `release/v6.7`: fix(seidb): refuse a corrupted changelog in digest replay instead of repairing it * [#4255](https://github.com/sei-protocol/sei-chain/pull/4255) Backport `release/v6.7`: feat(seidb): Add JSON output to evm-logical-digest and inspect a FlatKV migration in flight From 9adabea3322c9c5c76665a7afebf256bff19f5a5 Mon Sep 17 00:00:00 2001 From: alexander-sei Date: Fri, 25 Sep 2026 13:49:06 +0200 Subject: [PATCH 2/5] Revert changelog to the generated PR-list format Removes the hand-written ## Unreleased section and the ### Improvements and ### Upgrade guide sections under ## v6.7, so each release is again its version heading, sei-chain, and the list printed by scripts/generate-changelog.sh. Co-authored-by: Cursor --- CHANGELOG.md | 38 -------------------------------------- 1 file changed, 38 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index b5ecf8d587..74b03c3f78 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -28,45 +28,7 @@ Ref: https://keepachangelog.com/en/1.0.0/ # Changelog -## Unreleased - -### Improvements -* [#4166](https://github.com/sei-protocol/sei-chain/pull/4166) feat(seidb): `evm-logical-digest` can emit both digest and inspect reports as one JSON object on stdout, while progress and warnings go to stderr. Inspect mode now supports the mid-migration composite EVM view and semantic memiavl replay, so operators can shard and locate mismatched EVM keys during a FlatKV drain. Digest replay opens memiavl read-only without changelog repair, so an observer cannot truncate a live node's changelog. `seidb` now reports a failing command on stderr rather than stdout, so a refused `--json` run leaves stdout empty instead of putting a bare error line where the report belongs. -* [#4009](https://github.com/sei-protocol/sei-chain/pull/4009) Bound `/store/*/subspace` ABCI queries with pair/byte caps, empty-prefix rejection, SS-path concurrency limits, and context-aware iteration to prevent memory-exhaustion DoS. -* [#4032](https://github.com/sei-protocol/sei-chain/pull/4032) fix(config): the default `telemetry.prometheus-retention-time` drops from `7200` to `0`, so neither app.toml-generation pipeline (`seid init`, or the file a node writes for itself on any other subcommand) starts the Prometheus metrics sink unless an operator sets a positive retention. Freshly generated nodes keep the bounded in-memory telemetry sink used by SIGUSR1 dumps. Existing `app.toml` files are unchanged. -* [#4021](https://github.com/sei-protocol/sei-chain/pull/4021) feat(grpc): per-IP rate-limit admission for the gRPC plane, off by default behind `[grpc] rate-limiting-enabled` (new `ip-rate-limit-rps` / `ip-rate-limit-burst` / `trusted-proxy-cidrs`, defaults 10 rps / 20 burst / trust no proxy). Native gRPC (:9090) is admitted by a tap handler and gRPC-Web (:9091) by HTTP middleware, both before the request is protobuf-decoded, so a throttled caller cannot spend the decoder; streams pay one token to establish and one per inbound message. Both planes draw from the same per-IP buckets. Over-budget callers get `ResourceExhausted` on :9090 and HTTP 429 on :9091, counted by `rpc_rate_limit_rejected_total{plane="grpc", method_namespace}`. -* [#4078](https://github.com/sei-protocol/sei-chain/pull/4078) feat(grpc): bound concurrent in-flight RPCs and open connections per IP on the gRPC query plane. New `[grpc] max-connections-per-ip` and `[grpc-web] max-connections-per-ip` (default 0, unlimited) optionally cap one address's share of the global connection budget on :9090 and :9091, regardless of `rate-limiting-enabled`. New `[grpc] max-in-flight-per-ip` (default 100) caps concurrent RPCs per address when `rate-limiting-enabled = true`: the slot is taken at the HTTP/2 HEADERS frame and returned when the RPC ends. Both planes draw from the same per-IP pool. Concurrency rejections return `ResourceExhausted` on :9090 and HTTP 429 on :9091, counted by `rpc_inflight_rejected_total{plane, method_namespace}`; refused connections are counted by `rpc_connection_rejected_total{plane}`. -* [#4117](https://github.com/sei-protocol/sei-chain/pull/4117) chore(giga): remove the unused evmone/evmc execution path from the Giga executor. The Giga executor's production path already ran on go-ethereum's native interpreter; evmone was only reachable through a best-effort VM init that nothing consumed. Release images no longer ship `libevmone.*.so`/`.dylib` under `/usr/lib`, and the `SEI_EVMONE_LIB_DIR` operator override is removed. -* [#4098](https://github.com/sei-protocol/sei-chain/pull/4098) chore: upgrade the Go toolchain to 1.27.1 and golangci-lint to v2.13.2. The multistore state-sync snapshot format is bumped from `1` to `2` because the new toolchain's `compress/flate` emits a different (still valid) zlib stream, so snapshots of the same height are no longer byte-identical to those produced by earlier binaries. Nodes on this release restore both format `1` and format `2` snapshots. -* [#4191](https://github.com/sei-protocol/sei-chain/pull/4191) chore(docs): remove the embedded swagger UI and the `docs/rfc` folder. The API server no longer serves `/swagger/`; the `api.swagger` key in `app.toml` is now a no-op kept for sei-cosmos config compatibility. - -### State Machine Breaking -* [#4098](https://github.com/sei-protocol/sei-chain/pull/4098) `CommitSig.FromProto` now rejects a `block_id_flag` outside `ABSENT`/`COMMIT`/`NIL` at decode time instead of truncating it to `uint8`; a flag such as `257` that previously wrapped to `ABSENT` is now a decode error. - -### Upgrade guide -* [#4098](https://github.com/sei-protocol/sei-chain/pull/4098) **State-sync snapshot format bump (`1` → `2`).** Nodes running this release produce format `2` snapshots. Nodes still on an earlier release respond `REJECT_FORMAT` to every snapshot offered by an upgraded peer, so during a rolling upgrade they can only state-sync from peers that have not yet upgraded. Upgraded nodes accept both formats, so they can still bootstrap from old peers. **Operators should upgrade state-sync RPC providers last, or keep at least one pre-upgrade snapshot provider available until the rest of the fleet has moved.** -* [#4032](https://github.com/sei-protocol/sei-chain/pull/4032) **The Prometheus telemetry sink is off by default.** A node whose `app.toml` is generated by this release gets `prometheus-retention-time = 0`, which leaves the sink uncreated even though `telemetry.enabled` stays `true`. `GET /metrics?format=prometheus` on the app API server (:1317) then returns `prometheus metrics are not enabled`, and the `seid` process exports no application Prometheus series. **Operators who scrape application metrics should set a positive `[telemetry] prometheus-retention-time` in `app.toml` (the previous default was `7200`) before generating a new configuration file.** Nodes that already have `prometheus-retention-time` written in `app.toml` are unaffected. -* [#4021](https://github.com/sei-protocol/sei-chain/pull/4021) **gRPC per-IP rate limiting defaults are deliberately conservative.** Admission stays off unless `[grpc] rate-limiting-enabled = true`, but the defaults it enables are 10 rps / 20 burst per IP. Streams pay one token to establish and one per inbound message, so at the default burst a client that sends more than ~20 messages in a burst is cut off mid-stream with `ResourceExhausted`. Operators enabling admission should size `ip-rate-limit-rps` / `ip-rate-limit-burst` against their heaviest streaming client, and set `trusted-proxy-cidrs` to their ingress CIDRs so callers are not all bucketed under the proxy's IP. -* [#4078](https://github.com/sei-protocol/sei-chain/pull/4078) **Optional per-IP connection and in-flight RPC caps on :9090 and :9091.** `max-connections-per-ip` defaults to 0 (unlimited) on both planes; set a positive value to cap one address's share of the global connection budget. The cap keys on the TCP peer that opened the socket and is unaffected by `trusted-proxy-cidrs`, which needs a request to read `X-Forwarded-For` from and so cannot apply at accept time: everything reaching the node over `127.0.0.1` shares one allowance, as does every client behind a proxy or load balancer, and IPv6 peers share per /64. **Operators exposing public gRPC query endpoints directly may want to set `[grpc] max-connections-per-ip` and `[grpc-web] max-connections-per-ip` (for example to 100, a tenth of the default global budget); on a node behind an ingress, size it against that ingress's total concurrent connections rather than one client's, or leave it at 0.** The companion `[grpc] max-in-flight-per-ip` (default 100 concurrent RPCs per address) only takes effect when `rate-limiting-enabled = true`; size it against your heaviest client's concurrency. -* [#4009](https://github.com/sei-protocol/sei-chain/pull/4009) **`/store/*/subspace` scans are now capped.** Wide prefix scans that previously returned unbounded KV pairs now fail with `subspace result exceeds limit` once they would exceed the default caps of 1,000 pairs or 4 MiB of accumulated key+value bytes. Empty prefixes are rejected. Indexers and tooling that issue wide `/subspace` queries must narrow their prefixes, shard by sub-prefix, or raise `[state-commit] sc-subspace-max-pairs` and `sc-subspace-max-bytes` before upgrading. Values `<= 0` resolve to these defaults; there is no unlimited setting. - ## v6.7 - -### Improvements -* [#3818](https://github.com/sei-protocol/sei-chain/pull/3818) feat(evmrpc): extend HTTP admission control (`max_request_body_bytes`, `max_concurrent_request_bytes`, `ws_admission_timeout`) to the WebSocket plane (:8546). WS oversize frames close with WebSocket close code 1009; budget-wait timeouts return JSON-RPC error `-32005` before the connection closes. `evmrpc_requests_rejected_total` gains a `protocol` label (`http` / `ws`). -* [#3984](https://github.com/sei-protocol/sei-chain/pull/3984) feat(query): origin-aware pagination limits for ABCI queries. Untrusted callers on the ABCI/gRPC query path get configurable `max-limit`, `max-offset`, and flat `max-iterations` (defaults: 1000 / 10000 / 11000); requests above the caps are rejected upfront, and an exhausted iteration budget returns a partial page with `next_key` instead of failing. Trusted origins (new `[query] trusted-cidrs`) and the `[query] disable-limits` kill switch bypass the caps; the consensus/EVM precompile path is unaffected. -* [#3990](https://github.com/sei-protocol/sei-chain/pull/3990) Freeze mode is limited to full nodes and disables transaction and evidence submission, mempool gossip, and state sync from startup while preserving query RPC and mempool-backed reads. Frozen and Autobahn nodes no longer advertise the unused mempool P2P channel. - -### Upgrade guide -* **IBC core removal.** Removes the retired IBC core source, protobufs, light clients, CLI, and simulation support. Retired IBC stores remain mounted but are omitted from `export-genesis`; preserve the state database or use v6.6 freeze nodes for historical IBC data. -* **IBC transfer removal.** Removes ICS-20 execution, module APIs, CLI commands, CosmWasm transfer messages, transfer codecs, and transfer keeper integration, including the IBC EVM precompile's keeper injection. The transfer store and module account remain materialized for state compatibility. Transfer queries, historical transfer transaction decoding, and pre-v6.7 IBC precompile tracing must be served by v6.6 freeze nodes; v6.7 nodes do not provide them. -* **IBC query removal.** Removes the IBC core gRPC, REST, Protobuf, raw ABCI store, and native CosmWasm query APIs, along with CLI query commands. Historical IBC queries must be served by v6.6 freeze nodes. -* **Capability removal.** Removes the capability module and its IBC, transfer, and CosmWasm integrations. The capability store remains mounted for historical state access in freeze mode. -* [#3958](https://github.com/sei-protocol/sei-chain/pull/3958) **Feegrant removal.** Removes feegrant execution, module APIs, and the unreleased feegrant EVM precompile. The feegrant store remains mounted for historical state access. Transactions with a fee granter different from the payer are rejected. -* **WebSocket frame size default drops from 10 MiB to 5 MiB.** Before this release, :8546 used a hardcoded 10 MiB frame cap. Both HTTP and WebSocket now share `[evm].max_request_body_bytes`, whose default is 5 MiB (`5242880`). WS clients that send frames in the 5-10 MiB range (large `eth_sendRawTransaction` batches, wide filter payloads, etc.) will be disconnected after upgrade unless the limit is raised. **Operators who relied on the old 10 MiB WS cap should set `max_request_body_bytes = 10485760` in `app.toml` before upgrading.** This also raises the HTTP body limit to 10 MiB. The exported `DefaultWebsocketMaxMessageSize` constant was removed; use the config knob instead. -* [#3984](https://github.com/sei-protocol/sei-chain/pull/3984) **ABCI/gRPC pagination is now capped by default.** Untrusted callers requesting `limit` above 1000, `offset` above 10000, or a scan that exceeds 11000 total iterations now get `InvalidArgument` (over-cap) or a partial page with `next_key` (budget exhausted) instead of the previously unbounded scan. Clients that page with large limits/offsets, or trusted internal indexers, should either follow `next_key` for resumption or be added to the new `[query] trusted-cidrs` allowlist (or set `[query] disable-limits = true`) before upgrading. -* [#3927](https://github.com/sei-protocol/sei-chain/pull/3927) **Legacy Sei JSON-RPC and CLI removal.** Removes `sei_associate`, `sei_getBlockByHash`, `sei_getBlockByHashExcludeTraceFail`, `sei_getBlockTransactionCountByHash`, `sei_getBlockTransactionCountByNumber`, `sei_getEvmTx`, `sei_getFilterChanges`, `sei_getFilterLogs`, `sei_getLogs`, `sei_getTransactionByBlockHashAndIndex`, `sei_getTransactionByBlockNumberAndIndex`, `sei_getTransactionByHash`, `sei_getTransactionCount`, `sei_getTransactionErrorByHash`, `sei_getTransactionReceiptExcludeTraceFail`, `sei_getVMError`, `sei_newBlockFilter`, `sei_newFilter`, `sei_sign`, and `sei_uninstallFilter`. Use standard `eth_*` methods for EVM-originated data and `seid tx evm native-associate -y` for address association. There is no block- or filter-level replacement for discovering Cosmos-originated synthetic logs; clients that know the synthetic transaction hash can enable `sei_getTransactionReceipt`. - sei-chain * [#4334](https://github.com/sei-protocol/sei-chain/pull/4334) Backport `release/v6.7`: Fail dynamic-gas precompile out-of-gas as an EVM out-of-gas call * [#4315](https://github.com/sei-protocol/sei-chain/pull/4315) Backport `release/v6.7`: Pin the Go builder image per architecture in build-static.sh From a2e08a4bc152be70235d894b0dabd259c5797ca9 Mon Sep 17 00:00:00 2001 From: alexander-sei Date: Fri, 25 Sep 2026 13:57:32 +0200 Subject: [PATCH 3/5] Keep the Unreleased changelog section out of the rc3 update release/v6.7 has no Unreleased section, so changing it here would make the backport conflict. The Unreleased list is regenerated in a separate main-only change instead. Co-authored-by: Cursor --- CHANGELOG.md | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 74b03c3f78..ceba38ed83 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -28,6 +28,28 @@ Ref: https://keepachangelog.com/en/1.0.0/ # Changelog +## Unreleased + +### Improvements +* [#4166](https://github.com/sei-protocol/sei-chain/pull/4166) feat(seidb): `evm-logical-digest` can emit both digest and inspect reports as one JSON object on stdout, while progress and warnings go to stderr. Inspect mode now supports the mid-migration composite EVM view and semantic memiavl replay, so operators can shard and locate mismatched EVM keys during a FlatKV drain. Digest replay opens memiavl read-only without changelog repair, so an observer cannot truncate a live node's changelog. `seidb` now reports a failing command on stderr rather than stdout, so a refused `--json` run leaves stdout empty instead of putting a bare error line where the report belongs. +* [#4009](https://github.com/sei-protocol/sei-chain/pull/4009) Bound `/store/*/subspace` ABCI queries with pair/byte caps, empty-prefix rejection, SS-path concurrency limits, and context-aware iteration to prevent memory-exhaustion DoS. +* [#4032](https://github.com/sei-protocol/sei-chain/pull/4032) fix(config): the default `telemetry.prometheus-retention-time` drops from `7200` to `0`, so neither app.toml-generation pipeline (`seid init`, or the file a node writes for itself on any other subcommand) starts the Prometheus metrics sink unless an operator sets a positive retention. Freshly generated nodes keep the bounded in-memory telemetry sink used by SIGUSR1 dumps. Existing `app.toml` files are unchanged. +* [#4021](https://github.com/sei-protocol/sei-chain/pull/4021) feat(grpc): per-IP rate-limit admission for the gRPC plane, off by default behind `[grpc] rate-limiting-enabled` (new `ip-rate-limit-rps` / `ip-rate-limit-burst` / `trusted-proxy-cidrs`, defaults 10 rps / 20 burst / trust no proxy). Native gRPC (:9090) is admitted by a tap handler and gRPC-Web (:9091) by HTTP middleware, both before the request is protobuf-decoded, so a throttled caller cannot spend the decoder; streams pay one token to establish and one per inbound message. Both planes draw from the same per-IP buckets. Over-budget callers get `ResourceExhausted` on :9090 and HTTP 429 on :9091, counted by `rpc_rate_limit_rejected_total{plane="grpc", method_namespace}`. +* [#4078](https://github.com/sei-protocol/sei-chain/pull/4078) feat(grpc): bound concurrent in-flight RPCs and open connections per IP on the gRPC query plane. New `[grpc] max-connections-per-ip` and `[grpc-web] max-connections-per-ip` (default 0, unlimited) optionally cap one address's share of the global connection budget on :9090 and :9091, regardless of `rate-limiting-enabled`. New `[grpc] max-in-flight-per-ip` (default 100) caps concurrent RPCs per address when `rate-limiting-enabled = true`: the slot is taken at the HTTP/2 HEADERS frame and returned when the RPC ends. Both planes draw from the same per-IP pool. Concurrency rejections return `ResourceExhausted` on :9090 and HTTP 429 on :9091, counted by `rpc_inflight_rejected_total{plane, method_namespace}`; refused connections are counted by `rpc_connection_rejected_total{plane}`. +* [#4117](https://github.com/sei-protocol/sei-chain/pull/4117) chore(giga): remove the unused evmone/evmc execution path from the Giga executor. The Giga executor's production path already ran on go-ethereum's native interpreter; evmone was only reachable through a best-effort VM init that nothing consumed. Release images no longer ship `libevmone.*.so`/`.dylib` under `/usr/lib`, and the `SEI_EVMONE_LIB_DIR` operator override is removed. +* [#4098](https://github.com/sei-protocol/sei-chain/pull/4098) chore: upgrade the Go toolchain to 1.27.1 and golangci-lint to v2.13.2. The multistore state-sync snapshot format is bumped from `1` to `2` because the new toolchain's `compress/flate` emits a different (still valid) zlib stream, so snapshots of the same height are no longer byte-identical to those produced by earlier binaries. Nodes on this release restore both format `1` and format `2` snapshots. +* [#4191](https://github.com/sei-protocol/sei-chain/pull/4191) chore(docs): remove the embedded swagger UI and the `docs/rfc` folder. The API server no longer serves `/swagger/`; the `api.swagger` key in `app.toml` is now a no-op kept for sei-cosmos config compatibility. + +### State Machine Breaking +* [#4098](https://github.com/sei-protocol/sei-chain/pull/4098) `CommitSig.FromProto` now rejects a `block_id_flag` outside `ABSENT`/`COMMIT`/`NIL` at decode time instead of truncating it to `uint8`; a flag such as `257` that previously wrapped to `ABSENT` is now a decode error. + +### Upgrade guide +* [#4098](https://github.com/sei-protocol/sei-chain/pull/4098) **State-sync snapshot format bump (`1` → `2`).** Nodes running this release produce format `2` snapshots. Nodes still on an earlier release respond `REJECT_FORMAT` to every snapshot offered by an upgraded peer, so during a rolling upgrade they can only state-sync from peers that have not yet upgraded. Upgraded nodes accept both formats, so they can still bootstrap from old peers. **Operators should upgrade state-sync RPC providers last, or keep at least one pre-upgrade snapshot provider available until the rest of the fleet has moved.** +* [#4032](https://github.com/sei-protocol/sei-chain/pull/4032) **The Prometheus telemetry sink is off by default.** A node whose `app.toml` is generated by this release gets `prometheus-retention-time = 0`, which leaves the sink uncreated even though `telemetry.enabled` stays `true`. `GET /metrics?format=prometheus` on the app API server (:1317) then returns `prometheus metrics are not enabled`, and the `seid` process exports no application Prometheus series. **Operators who scrape application metrics should set a positive `[telemetry] prometheus-retention-time` in `app.toml` (the previous default was `7200`) before generating a new configuration file.** Nodes that already have `prometheus-retention-time` written in `app.toml` are unaffected. +* [#4021](https://github.com/sei-protocol/sei-chain/pull/4021) **gRPC per-IP rate limiting defaults are deliberately conservative.** Admission stays off unless `[grpc] rate-limiting-enabled = true`, but the defaults it enables are 10 rps / 20 burst per IP. Streams pay one token to establish and one per inbound message, so at the default burst a client that sends more than ~20 messages in a burst is cut off mid-stream with `ResourceExhausted`. Operators enabling admission should size `ip-rate-limit-rps` / `ip-rate-limit-burst` against their heaviest streaming client, and set `trusted-proxy-cidrs` to their ingress CIDRs so callers are not all bucketed under the proxy's IP. +* [#4078](https://github.com/sei-protocol/sei-chain/pull/4078) **Optional per-IP connection and in-flight RPC caps on :9090 and :9091.** `max-connections-per-ip` defaults to 0 (unlimited) on both planes; set a positive value to cap one address's share of the global connection budget. The cap keys on the TCP peer that opened the socket and is unaffected by `trusted-proxy-cidrs`, which needs a request to read `X-Forwarded-For` from and so cannot apply at accept time: everything reaching the node over `127.0.0.1` shares one allowance, as does every client behind a proxy or load balancer, and IPv6 peers share per /64. **Operators exposing public gRPC query endpoints directly may want to set `[grpc] max-connections-per-ip` and `[grpc-web] max-connections-per-ip` (for example to 100, a tenth of the default global budget); on a node behind an ingress, size it against that ingress's total concurrent connections rather than one client's, or leave it at 0.** The companion `[grpc] max-in-flight-per-ip` (default 100 concurrent RPCs per address) only takes effect when `rate-limiting-enabled = true`; size it against your heaviest client's concurrency. +* [#4009](https://github.com/sei-protocol/sei-chain/pull/4009) **`/store/*/subspace` scans are now capped.** Wide prefix scans that previously returned unbounded KV pairs now fail with `subspace result exceeds limit` once they would exceed the default caps of 1,000 pairs or 4 MiB of accumulated key+value bytes. Empty prefixes are rejected. Indexers and tooling that issue wide `/subspace` queries must narrow their prefixes, shard by sub-prefix, or raise `[state-commit] sc-subspace-max-pairs` and `sc-subspace-max-bytes` before upgrading. Values `<= 0` resolve to these defaults; there is no unlimited setting. + ## v6.7 sei-chain * [#4334](https://github.com/sei-protocol/sei-chain/pull/4334) Backport `release/v6.7`: Fail dynamic-gas precompile out-of-gas as an EVM out-of-gas call From 08fbbef2acfc3d8b325feece7117bb1b3a0f85a9 Mon Sep 17 00:00:00 2001 From: alexander-sei Date: Fri, 25 Sep 2026 21:51:26 +0200 Subject: [PATCH 4/5] Add #4347 to the v6.7 changelog for rc3 Regenerated with ./scripts/generate-changelog.sh release/v6.6 release/v6.7. Co-authored-by: Cursor --- CHANGELOG.md | 1 + 1 file changed, 1 insertion(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index ceba38ed83..51b9b3248c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -52,6 +52,7 @@ Ref: https://keepachangelog.com/en/1.0.0/ ## v6.7 sei-chain +* [#4347](https://github.com/sei-protocol/sei-chain/pull/4347) Backport `release/v6.7`: fix(flatkv): keep 10 old checkpoints instead of mirroring memIAVL's count * [#4334](https://github.com/sei-protocol/sei-chain/pull/4334) Backport `release/v6.7`: Fail dynamic-gas precompile out-of-gas as an EVM out-of-gas call * [#4315](https://github.com/sei-protocol/sei-chain/pull/4315) Backport `release/v6.7`: Pin the Go builder image per architecture in build-static.sh * [#4313](https://github.com/sei-protocol/sei-chain/pull/4313) Backport `release/v6.7`: fix(memiavl): hold a snapshot reference for an iterator's lifetime From 8dcba4fa62d6f8108eef2afc4c028eacdcfa4b47 Mon Sep 17 00:00:00 2001 From: alexander-sei Date: Fri, 25 Sep 2026 22:22:19 +0200 Subject: [PATCH 5/5] Add #4348 to the v6.7 changelog for rc3 Regenerated with ./scripts/generate-changelog.sh release/v6.6 release/v6.7. Co-authored-by: Cursor --- CHANGELOG.md | 1 + 1 file changed, 1 insertion(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 51b9b3248c..acbbcde03c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -52,6 +52,7 @@ Ref: https://keepachangelog.com/en/1.0.0/ ## v6.7 sei-chain +* [#4348](https://github.com/sei-protocol/sei-chain/pull/4348) Backport `release/v6.7`: fix(seidb): report only the current migration boundary on the snapshot gauge * [#4347](https://github.com/sei-protocol/sei-chain/pull/4347) Backport `release/v6.7`: fix(flatkv): keep 10 old checkpoints instead of mirroring memIAVL's count * [#4334](https://github.com/sei-protocol/sei-chain/pull/4334) Backport `release/v6.7`: Fail dynamic-gas precompile out-of-gas as an EVM out-of-gas call * [#4315](https://github.com/sei-protocol/sei-chain/pull/4315) Backport `release/v6.7`: Pin the Go builder image per architecture in build-static.sh