Skip to content

Testnet - #1

Merged
AIQnetLab merged 0 commit into
masterfrom
testnet
Oct 7, 2025
Merged

Testnet#1
AIQnetLab merged 0 commit into
masterfrom
testnet

Conversation

@AIQnetLab

@AIQnetLab AIQnetLab commented Sep 11, 2025

Copy link
Copy Markdown
Owner

Add LICENSE


Note

Integrates Phase 1 1DEV burn activation (Solana devnet) with updated rewards/consensus and configs, plus new scripts, monitoring, and documentation for testnet.

  • Core/Node:
    • Raise consensus reputation threshold to 70% and set transfer gas_limit to 10000.
    • Overhaul NodeConfig defaults (dynamic listen_addr, ports, metrics, RPC).
  • Activation:
    • Implement SolanaVerifier for 1DEV burns (devnet mint 62PP...FHHJ, incinerator addr) and enhance QNetVerifier.
  • Rewards:
    • Correct base emission to 251,432.34 QNC/4h; per-node-type reputation gates (Light any; Full/Super >=70).
    • Make reward claims zero-gas/fee (direct pool withdrawal).
  • Infrastructure/Config:
    • Add real 1DEV token/bridge settings, genesis nodes, Prometheus prometheus.yml, and issuer key placeholders.
  • Scripts/Tooling:
    • Add Solana token/keypair scripts and scripts/package.json deps; simple test token creator.
  • Security/Wallet:
    • Add production BIP39 wordlist (src/crypto/ProductionBIP39.js).
  • Testing/Integration:
    • Testnet launch checklist; remove old RocksDB state; integration tweaks (monitoring, configs).
  • Docs:
    • Extensive technical documentation updates for activation, network, and transparency.

Written by Cursor Bugbot for commit 493d272. This will update automatically on new commits. Configure here.

@github-advanced-security

ghost commented Sep 23, 2025

Copy link
Copy Markdown

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.

fastapi==0.104.1
uvicorn[standard]==0.24.0
pydantic==2.5.0
python-multipart==0.0.6

Check failure

Code scanning / Trivy

`python-multipart` is a streaming multipart parser for Python. When us ...

Package: python-multipart Installed Version: 0.0.6 Vulnerability CVE-2024-24762 Severity: HIGH Fixed Version: 0.0.7 Link: [CVE-2024-24762](https://avd.aquasec.com/nvd/cve-2024-24762)
fastapi==0.104.1
uvicorn[standard]==0.24.0
pydantic==2.5.0
python-multipart==0.0.6

Check failure

Code scanning / Trivy

python-multipart: python-multipart has a DoS via deformation `multipart/form-data` boundary

Package: python-multipart Installed Version: 0.0.6 Vulnerability CVE-2024-53981 Severity: HIGH Fixed Version: 0.0.18 Link: [CVE-2024-53981](https://avd.aquasec.com/nvd/cve-2024-53981)
uvicorn[standard]==0.24.0
pydantic==2.5.0
python-multipart==0.0.6
python-jose[cryptography]==3.3.0

Check failure

Code scanning / Trivy

python-jose: algorithm confusion with OpenSSH ECDSA keys and other key formats

Package: python-jose Installed Version: 3.3.0 Vulnerability CVE-2024-33663 Severity: CRITICAL Fixed Version: 3.4.0 Link: [CVE-2024-33663](https://avd.aquasec.com/nvd/cve-2024-33663)
uvicorn[standard]==0.24.0
pydantic==2.5.0
python-multipart==0.0.6
python-jose[cryptography]==3.3.0

Check warning

Code scanning / Trivy

python-jose: allows attackers to cause a denial of service

Package: python-jose Installed Version: 3.3.0 Vulnerability CVE-2024-33664 Severity: MEDIUM Fixed Version: 3.4.0 Link: [CVE-2024-33664](https://avd.aquasec.com/nvd/cve-2024-33664)
python-jose[cryptography]==3.3.0
passlib[bcrypt]==1.7.4
aiofiles==23.2.1
aiohttp==3.9.1

Check warning

Code scanning / Trivy

aiohttp: follow_symlinks directory traversal vulnerability

Package: aiohttp Installed Version: 3.9.1 Vulnerability CVE-2024-23334 Severity: HIGH Fixed Version: 3.9.2 Link: [CVE-2024-23334](https://avd.aquasec.com/nvd/cve-2024-23334)
redis==5.0.1
asyncio-mqtt==0.16.1
cryptography==41.0.8
requests==2.31.0

Check warning

Code scanning / Trivy

requests: subsequent requests to the same host ignore cert verification

Package: requests Installed Version: 2.31.0 Vulnerability CVE-2024-35195 Severity: MEDIUM Fixed Version: 2.32.0 Link: [CVE-2024-35195](https://avd.aquasec.com/nvd/cve-2024-35195)
redis==5.0.1
asyncio-mqtt==0.16.1
cryptography==41.0.8
requests==2.31.0

Check warning

Code scanning / Trivy

requests: Requests vulnerable to .netrc credentials leak via malicious URLs

Package: requests Installed Version: 2.31.0 Vulnerability CVE-2024-47081 Severity: MEDIUM Fixed Version: 2.32.4 Link: [CVE-2024-47081](https://avd.aquasec.com/nvd/cve-2024-47081)

# Monitoring and logging
prometheus-client==0.19.0
sentry-sdk[fastapi]==1.38.0

Check notice

Code scanning / Trivy

sentry-sdk is the official Python SDK for Sentry.io. A bug in Sentry's ...

Package: sentry-sdk Installed Version: 1.38.0 Vulnerability CVE-2024-40647 Severity: LOW Fixed Version: 2.8.0, 1.45.1 Link: [CVE-2024-40647](https://avd.aquasec.com/nvd/cve-2024-40647)
# Development
pytest==7.4.3
pytest-asyncio==0.21.1
black==23.11.0

Check warning

Code scanning / Trivy

psf/black: ReDoS via the lines_with_leading_tabs_expanded() function in strings.py file

Package: black Installed Version: 23.11.0 Vulnerability CVE-2024-21503 Severity: MEDIUM Fixed Version: 24.3.0 Link: [CVE-2024-21503](https://avd.aquasec.com/nvd/cve-2024-21503)
Comment thread scripts/package-lock.json
Comment on lines +464 to +476
"node_modules/bigint-buffer": {
"version": "1.1.5",
"resolved": "https://registry.npmjs.org/bigint-buffer/-/bigint-buffer-1.1.5.tgz",
"integrity": "sha512-trfYco6AoZ+rKhKnxA0hgX0HAbVP/s808/EuDSe2JDzUnCp/xAsli35Orvk67UrTEcwuxZqYZDmfA2RXJgxVvA==",
"hasInstallScript": true,
"license": "Apache-2.0",
"dependencies": {
"bindings": "^1.3.0"
},
"engines": {
"node": ">= 10.0.0"
}
},

Check failure

Code scanning / Trivy

bigint-buffer Vulnerable to Buffer Overflow via toBigIntLE() Function

Package: bigint-buffer Installed Version: 1.1.5 Vulnerability CVE-2025-3194 Severity: HIGH Fixed Version: Link: [CVE-2025-3194](https://avd.aquasec.com/nvd/cve-2025-3194)
cursor[bot]

This comment was marked as outdated.

cursor[bot]

This comment was marked as outdated.

cursor[bot]

This comment was marked as outdated.

cursor[bot]

This comment was marked as outdated.

cursor[bot]

This comment was marked as outdated.

cursor[bot]

This comment was marked as outdated.

cursor[bot]

This comment was marked as outdated.

cursor[bot]

This comment was marked as outdated.

cursor[bot]

This comment was marked as outdated.

cursor[bot]

This comment was marked as outdated.

cursor[bot]

This comment was marked as outdated.

cursor[bot]

This comment was marked as outdated.

cursor[bot]

This comment was marked as outdated.

cursor[bot]

This comment was marked as outdated.

}

false // CRITICAL: Never add unreachable peers, even during bootstrap
}

ghost Oct 7, 2025

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: Genesis Peer Connectivity Logic Conflict

The P2P module has conflicting logic for Genesis peers. While some paths use "bootstrap trust" to add them even if unreachable, other critical sections enforce strict connectivity for Byzantine safety. This inconsistency can lead to phantom Genesis peers being considered for consensus, compromising network stability and Byzantine fault tolerance.

Additional Locations (1)

Fix in Cursor Fix in Web

var endpoint = networkEnv === 'mainnet'
? this.endpoints.qnet.mainnet
: this.endpoints.qnet.testnet;
}

ghost Oct 7, 2025

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: Variable Hoisting Causes Unexpected Behavior

The endpoint variable in initializeQNetConnection is declared with var in both if and else blocks. This redeclaration can lead to unexpected behavior due to var's hoisting rules.

Additional Locations (1)

Fix in Cursor Fix in Web

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants