Skip to content

Releases: ipfs/kubo

v0.24.0

08 Nov 11:44
v0.24.0
e70db65
Compare
Choose a tag to compare

Overview

πŸ”¦ Highlights

Support for content blocking

This Kubo release ships with built-in content-blocking subsystem announced earlier this year.
Content blocking is an opt-in decision made by the operator of ipfs daemon.
The official build does not ship with any denylists.

Learn more at /docs/content-blocking.md

Gateway: the root of the CARs are no longer meaningful

When requesting a CAR from the gateway, the root of the CAR might no longer be
meaningful. By default, the CAR root will be the last resolvable segment of the
path. However, in situations where the path cannot be resolved, such as when
the path does not exist, a CAR will be sent with a root of bafkqaaa (empty CID).
This CAR will contain all blocks necessary to validate that the path does not exist.

IPNS: improved publishing defaults

This release changes the default values used when publishing IPNS record
via ipfs name publish command:

  • Default --lifetime increased from 24h to 48h to take full advantage of
    the increased expiration window of Amino DHT
    (go-libp2p-kad-dht#793)
  • Default --ttl increased from 1m to 1h to improve website caching and follow
    saner defaults present in similar systems like DNS
    (specs#371)

This change only impacts the implicit defaults, when mentioned parameters are omitted
during publishing. Users are free to override the default if different value
makes more sense for their use case.

IPNS: record TTL is used for caching

In this release, we've made significant improvements to IPNS caching.

Previously, the TTL value in IPNS records was not utilized, and the
boxo/namesys library maintained a static one-minute resolution cache.

With this update, IPNS publishers gain more control over how long a valid IPNS
record remains cached before checking an upstream routing system, such as Amino
DHT, for updates. The TTL value in the IPNS record now serves as a hint for:

  • boxo/namesys: the internal cache, determining how long the IPNS resolution
    result is cached before asking upsteam routing systems for updates.
  • boxo/gateway: the Cache-Control HTTP header in responses to requests made
    for /ipns/name content paths.

These changes make it easier for rarely updated IPNS-hosted websites to be
cached more efficiently and load faster in browser contexts.

Experimental Transport: WebRTC Direct

This Kubo release includes the initial work towards WebRTC Direct
introduced in go-libp2p v0.32:

WebRTC Direct
allows browser nodes to connect to go-libp2p nodes directly,
without any configuration (e.g. TLS certificates) needed on the go-libp2p
side. This is useful for browser nodes that aren’t able to use
WebTransport.

The /webrtc-direct transport is disabled by default in Kubo 0.24,
and not ready for production use yet, but we plan to enable it in a future release.

See Swarm.Transports.Network.WebRTCDirect
to learn how to enable it manually, and what current limitations are.

πŸ“ Changelog

Full Changelog
Read more

v0.24.0-rc2

03 Nov 15:35
v0.24.0-rc2
Compare
Choose a tag to compare
v0.24.0-rc2 Pre-release
Pre-release

v0.24.0-rc1

01 Nov 12:17
v0.24.0-rc1
Compare
Choose a tag to compare
v0.24.0-rc1 Pre-release
Pre-release

v0.23.0

05 Oct 17:36
v0.23.0
3a1a041
Compare
Choose a tag to compare

Overview

πŸ”¦ Highlights

Mplex deprecation

Mplex is being deprecated, this is because it is unreliable and
randomly drop streams when sending data too fast.

New pieces of code rely on backpressure, that means the stream will dynamicaly
slow down the sending rate if data is getting backed up.
Backpressure is provided by Yamux and QUIC.

In case you need compatibility with older implementations that do not ship with
Yamux (like default's JS-IPFS) you can turned it back ON in the config with:

$ ipfs config --json Swarm.Transports.Multiplexers.Mplex 200

We will completely remove Mplex in v0.24 as it makes protocols very bad to implement,
if you are in this situation you need to add yamux support to your other implementation.

Gateway: meaningful CAR responses on Not Found errors

When requesting a CAR from the gateway, the root of the CAR might no longer be
meaningful. By default, the CAR root will be the last resolvable segment of the
path. However, in situations where the path cannot be resolved, such as when
the path does not exist, a CAR will be sent with a root of bafkqaaa (empty CID).

This CAR will contain all blocks necessary to validate that the path does not
exist without having to trust the gateway.

Gateway: added Gateway.DisableHTMLErrors configuration option

The Gateway.DisableHTMLErrors configuration option forces errors to be
displayed in browsers as plain text (text/plain) rather than HTML error
pages. It's especially beneficial for whitelabel or middleware deployments that
wish to avoid IPFS branding and links on error pages in browsers.

Binary characters in file names: no longer works with old clients and new Kubo servers

In this version, we updated Kubo to support Go 1.20+. In Go 1.20, a regression
regarding multipart headers was introduced.
This only affects ipfs add when a file name has binary characters in its name.
As a consequence, we had to update the encoding of the file name headers. This is
the compatibility table:

New Client Old Client
New Server βœ… 🟑*
Old Server βœ… βœ…

*Old clients can only send Unicode file paths to the server.

Self-hosting /routing/v1 endpoint for delegated routing needs

The Routing system configured in Kubo can be now exposed on the gateway port as a standard
HTTP Routing V1 API endpoint. This allows
self-hosting and experimentation with custom delegated routers. This is disabled by default,
but can be enabled by setting Gateway.ExposeRoutingAPI to true .

Trustless Gateway Over Libp2p Experiment

In this update, we've introduced an experimental opt-in feature allowing users to
serve a subset of Trustless Gateway responses,
such as blocks and CARs, over libp2p. This enhancement leverages the ongoing
/http/1.1 specification work in libp2p
to make it easier to support HTTP semantics over libp2p streams.

This development means that if users wish to utilize the Trustless Gateway API
for data transport, they can now do so even in scenarios where standard HTTP
might be problematic, such as when the endpoint is behind a firewall or when
attempting to serve data to a browser without a CA certificate.

See HTTP Gateway over Libp2p for details about this experiment.

Removal of /quic (Draft 29) support

Kubo no longer supports QUIC Draft 29. This means that older nodes aren't able to connect
to newer nodes using QUIC Draft 29. However, they are still able to connect through any other
transport that both nodes talk (such as QUIC RFC 9000, or TCP). QUIC Draft 29 was a preliminary implementation of QUIC before
the official RFC 9000 was published, and it has now been dropped by go-libp2p
and therefore Kubo.

In Kubo 0.18, we shipped a migration
to have listeners for both /quic (Draft 29) and /quic-v1 (RFC 9000). Similarly, in this
version we are shipping a migration to remove the current /quic addresses, maintaining
the /quic-v1 addresses only. For more background information, check issue #9496.

Better Caching of multiaddresses for providers in DHT servers

Thanks to probelab.io's RFM17.1 DHT servers will now cache the addresses of content hosts for the lifetime of the provider record.

This means clients who resolve content from theses servers get a responses which include both peer id and multiaddresses.
In most cases this enables skipping a second query which resolves the peer id to multiaddresses for stable enough peers.

This will improve content fetching lantency in the network overtime as servers updates.

Fixed FUSE multiblock structures

lsing directories and reading dag-pb files on a fuse volume have been fixed. #9044
Thx a lot @bmwiedemann for debugging this issue.

πŸ“ Changelog

Full Changelog
  • github.com/ipfs/kubo:
    • fix: align systemd unit file with default IPFS installation path (#10163) (ipfs/kubo#10163)
    • docs: capitalize headers for consistency
    • Merge commit '695bf66674931a138862b6fa2cb0b16dc2f6ddd8' into release-v0.23.0
    • chore: update version
    • changelog: generalize fuse 9044's entry
    • changelog: update fuse 9044's entry
    • Update go-unixfsnode to 1.8.0 to fix FUSE
    • docs(readme): header improvements (#10144) (ipfs/kubo#10144)
    • fix(docker): allow nofuse builds for MacOS (#10135) (ipfs/kubo#10135)
    • docs: fix typos
    • docs: s/ipfs dht/amino dht/
    • changelog: mention probelab RFM17.1 dht improvement
    • tests: remove sharness ping tests
    • perf: make bootstrap saves O(N)
    • chore: update go-libp2p-kad-dht
    • chore: webui v4.1.1 (#10120) (ipfs/kubo#10120)
    • core/bootstrap: fix panic without backup bootstrap peer functions (#10029) (ipfs/kubo#10029)
    • feat: add Gateway.DisableHTMLErrors option (#10137) (ipfs/kubo#10137)
    • fix(migrations): use dweb.link (#10133) (ipfs/kubo#10133)
    • docs: add changelog info for QUIC Draft 29 (#10132) (ipfs/kubo#10132)
    • feat: add gateway to http over libp2p (ipfs/kubo#10108)
    • migration: update 14-to-15 to v1.0.1
    • chore: update to build with Go 1.21
    • refactor: stop using go-libp2p deprecated peer.ID.Pretty
    • docs(readonly): fix typo
    • docs(changelog): link to relevant IPIP
    • fix: hamt traversal in ipld-explorer (webui@4.1.0) (#10025) (ipfs/kubo#10025)
    • refactor: if statement (#10105) (ipfs/kubo#10105)
    • chore: bump repo version to 15
    • docs: remove link to deleted #accelerated-dht-client
    • feat(gateway): expose /routing/v1 server (opt-in) (#9877) (ipfs/kubo#9877)
    • improve error in fuse node failures
    • chore: update boxo, go-libp2p, and internalize mplex (#10095) (ipfs/kubo#10095)
    • dockerfile: reorder copy order for better layer caching
    • refactor: using error is instead of == (#10093) (ipfs/kubo#10093)
    • fix: use %-encoded headers in most compatible way
    • fix: open /dev/null with read write permissions
    • chore: bump to go 1.20
    • docs(readme): new logo and header
    • docker: change to releases that follow debian's updates
    • docker: bump debian version to bookworm
    • chore: restore exec perms for t0116-gateway-cache.sh and fixtures (#10085) (ipfs/kubo#10085)
    • fix(gw): useful IPIP-402 CAR...
Read more

v0.23.0-rc1

26 Sep 13:30
v0.23.0-rc1
Compare
Choose a tag to compare
v0.23.0-rc1 Pre-release
Pre-release

v0.22.0

09 Aug 14:42
v0.22.0
3f884d3
Compare
Choose a tag to compare

Release issue #9911

v0.22.0

Overview

πŸ”¦ Highlights

Gateway: support for order= and dups= parameters (IPIP-412)

The updated boxo/gateway library introduces support for ordered CAR responses through the inclusion of optional CAR content type parameters: order=dfs and dups=y|n from IPIP-412.

Previously, Kubo already provided CARs in DFS order without duplicate blocks. With the implementation of IPIP-412, this behavior is now explicitly defined rather than implied.

In the absence of dups or order in Accept request reader, the default CAR response will have the Content-Type: application/vnd.ipld.car; version=1; order=dfs; dups=n and the same blocks as Kubo 0.21.

Kubo 0.22 still only supports DFS block ordering (order=dfs). However, it is now possible to request a DFS CAR stream with duplicate blocks by opting in via Accept: application/vnd.ipld.car; order=dfs; dups=y. This opt-in feature can be beneficial for memory-constrained clients and IoT devices, as it allows for streaming large DAGs without the need to store all previously encountered blocks in memory.

ipfs name publish now supports V2 only IPNS records

When publishing an IPNS record, you are now able to create v2 only records by passing --v1compat=false. By default, we still create V1+V2 records, such that there is the highest chance of backwards compatibility. The goal is to move to V2 only in the future.

For more details, see IPIP-428 and the updated IPNS Record Verification logic.

IPNS name resolution has been fixed

IPNS name resolution had a regression where if IPNS over PubSub was enabled, but the name was not also available via IPNS over PubSub it would take 1 minute to for the lookup to complete (if the record was not yet cached).

This has been fixed and as before will give the best record from either the DHT subsystem or IPNS over PubSub, whichever comes back first.

For details see #9927 and #10020.

go-libp2p v0.29.0 update with smart dialing

We updated from go-libp2p v0.27.7 to v0.29.0. This release includes smart dialing, which is a prioritization algorithm that will try to rank addresses and protocols rather than attempting all options in parallel. Anecdotally, we have observed Kubo nodes make 30% less dials with no to low latency impact.

This includes a breaking change to ipfs id and some of the ipfs swarm commands. We no longer report ProtocolVersion. This used to be hardcoded as ipfs/0.1.0 and sent to other peers but was not providing any distinguishing value. See libp2p/go-libp2p#2294 for more information.

πŸ“ Changelog

Full Changelog
Read more

v0.21.1

15 Aug 07:18
v0.21.1
Compare
Choose a tag to compare

v0.21.1

Dependencies updates for bug fixes.

v0.22.0-rc1

27 Jul 12:48
v0.22.0-rc1
Compare
Choose a tag to compare
v0.22.0-rc1 Pre-release
Pre-release

See the related issue: #9911

Changelog: docs/changelogs/v0.22.md

v0.21.0

03 Jul 10:56
v0.21.0
294db3e
Compare
Choose a tag to compare

Overview

πŸ”¦ Highlights

Saving previously seen nodes for later bootstrapping

Kubo now stores a subset of connected peers as backup bootstrap nodes (kubo#8856).
These nodes are used in addition to the explicitly defined bootstrappers in the
Bootstrap configuration.

This enhancement improves the resiliency of the system, as it eliminates the
necessity of relying solely on the default bootstrappers operated by Protocol
Labs for joining the public IPFS swarm. Previously, this level of robustness
was only available in LAN contexts with mDNS peer discovery
enabled.

With this update, the same level of robustness is applied to peers that lack
mDNS peers and solely rely on the public DHT.

Gateway: DeserializedResponses config flag

This release introduces the
Gateway.DeserializedResponses
configuration flag.

With this flag, one can explicitly configure whether the gateway responds to
deserialized requests or not. By default, this flag is enabled.

Disabling deserialized responses allows the
gateway to operate
as a Trustless Gateway
limited to three verifiable
response types:
application/vnd.ipld.raw,
application/vnd.ipld.car,
and application/vnd.ipfs.ipns-record.

With deserialized responses disabled, the Kubo gateway can serve as a block
backend for other software (like
bifrost-gateway,
IPFS in Chromium
etc) without the usual risks associated with hosting deserialized data behind
third-party CIDs.

client/rpc migration of go-ipfs-http-client

The go-ipfs-http-client RPC has
been migrated into kubo/client/rpc.

With this change the two will be kept in sync, in some previous releases we
updated the CoreAPI with new Kubo features but forgot to port thoses to the
http-client, making it impossible to use them together with the same coreapi
version.

For smooth transition v0.7.0 of go-ipfs-http-client provides updated stubs
for Kubo v0.21.

Gateway: DAG-CBOR/-JSON previews and improved error pages

In this release, we improved the HTML templates of our HTTP gateway:

  1. You can now preview the contents of a DAG-CBOR and DAG-JSON document from your browser, as well as follow any IPLD Links (CBOR Tag 42) contained within them.
  2. The HTML directory listings now contain updated, higher-definition icons.
  3. On gateway error, instead of a plain text error message, web browsers will now get a friendly HTML response with more details regarding the problem.

HTML responses are returned when request's Accept header includes text/html.

DAG-CBOR Preview Error Page
DAG-CBOR Preview Error Page

Gateway: subdomain redirects are now text/html

HTTP 301 redirects from path to subdomain
no longer include the target data in the body.
The data is returned only once, with the final HTTP 200 returned from the
target subdomain.

The HTTP 301 body now includes human-readable text/html message
for clients that do not follow redirects by default:

$ curl "https://subdomain-gw.example.net/ipfs/${cid}/"
<a href="https://${cid}.ipfs.subdomain-gw.example.net/">Moved Permanently</a>.

Rationale can be found in kubo#9913.

Gateway: support for partial CAR export parameters (IPIP-402)

The gateway now supports optional CAR export parameters
dag-scope=block|entity|all and entity-bytes=from:to as specified in
IPIP-402.

Batch block retrieval minimizes round trips, catering to the requirements of
light HTTP clients for directory enumeration, range requests, and content path
resolution.

ipfs dag stat deduping statistics

ipfs dat stat now accept multiple CIDs and will dump advanced statistics
on the number of shared blocks and size of each CID.

$ ipfs dag stat --progress=false QmfXuRxzyVy5H2LssLgtXrKCrNvDY8UBvMp2aoW8LS8AYA QmfZDyu2UFfUhL4VdHaw7Hofivmn5D4DdQj38Lwo86RsnB

CID                                           	Blocks         	Size
QmfXuRxzyVy5H2LssLgtXrKCrNvDY8UBvMp2aoW8LS8AYA	3              	2151
QmfZDyu2UFfUhL4VdHaw7Hofivmn5D4DdQj38Lwo86RsnB	4              	3223

Summary
Total Size: 3326
Unique Blocks: 5
Shared Size: 2048
Ratio: 1.615755

ipfs --enc=json dag stat's keys are a non breaking change, new keys have been added but old keys with previous sementics are still here.

Accelerated DHT Client is no longer experimental

The accelerated DHT client is now
the main recommended solution for users who are hosting lots of data.
By trading some upfront DHT caching and increased memory usage,
one gets provider throughput improvements up to 6 millions times bigger dataset.
See the docs for more info.

The Experimental.AcceleratedDHTClient flag moved to [Routing.AcceleratedDHTClient](docs/config.md#routingaccelerateddhtclient).
A config migration has been added to handle this automatically.

A new tracker estimates the providing speed and warns users if they
should be using AcceleratedDHTClient because they are falling behind.

πŸ“ Changelog

Full Changelog
  • github.com/ipfs/kubo:
  • github.com/ipfs/boxo (v0.8.1 -> v0.10.2-0.20230629143123-2d3edc552442):
    • chore: version 0.10.2
    • fix(gateway): include CORS on subdomain redirects (#395) (ipfs/boxo#395)
    • fix(gateway): ensure 'X-Ipfs-Root' header is valid (#337) (ipfs/boxo#337)
    • docs: prepare changelog for next release [ci skip]
    • chore: version 0.10.1 (#359) (ipfs/boxo#359)
    • fix(gateway): allow CAR trustless requests with path
    • blockstore: replace go.uber.org/atomic with sync/atomic
    • fix(gateway): remove handleUnsupportedHeaders after go-ipfs 0.13 (#350) (ipfs/boxo#350)
    • docs: update RELEASE.md based on 0.9 release (#343) (ipfs/boxo#343)
    • chore: v0.10.0 (#345) (ipfs/boxo#345)
    • docs(changelog): car params from ipip-402
    • docs(changelog): add gateway deserialized responses (#341) (ipfs/boxo#341)
    • feat(gateway): implement IPIP-402 extensions for gateway CAR requests (#303) (ipfs/boxo#303)
    • chore: release v0.9.0
    • changelog: update for 0.8.1 and 0.9.0
    • provider: second round of reprovider refactor
    • feat(unixfs): change protobuf package name to unixfs.v1.pb to prevent collisions with go-unixfs. Also regenerate protobufs with latest gogo
    • feat(ipld/merkledag): remove use of go-ipld-format global registry
    • feat(ipld/merkledag): updated to use its own global go-ipld-legacy registry instead of a shared global registry
    • chore: do not rely on deprecated logger
    • changelog: add changelog for async pin listing (#336) (ipfs/boxo#336)
    • pinner: change the interface to have async pin listing
    • provider: revert through...
Read more

v0.21.0-rc3

20 Jun 13:09
v0.21.0-rc3
9f21cf5
Compare
Choose a tag to compare
v0.21.0-rc3 Pre-release
Pre-release