Elect new IC/GuestOS revision (commit 2cdff28)
#144194 · Open · 4 d left · proposed Oct 2, 2026
Summary
Discussion linkRelease Notes for release-2026-10-02_03-31-base (2cdff28573522b2c9c5e96a4407b50281eb82b5c) This release is based on changes since release-2026-09-25_03-28-base (d26cd031176beec51b39fbb9e39e80a3a46a748e).
Please note that some commits may be excluded from this release if they're not relevant, or not modifying the GuestOS image. Additionally, descriptions of some changes might have been slightly modified to fit the release notes format.
To see a full list of commits added since last release, compare the revisions on GitHub.
Features:
647a36502Core Protocol: More timeouts for the XNet endpoint (#11707)3588f1203Core Protocol: Advert trigger, conditions and targets (#11698)514854dd1Core Protocol:AdvertTask::advertise_to()(#11663)4f3d0d8d5Core Protocol:XNetClient::post_advert()(#11613)f5b887d83Core Protocol: XNet advert endpoint (#11603)6a6957489Core Protocol: Fast upgrades: upgrade payload section in blocks (#11655)9ccebc7dbCore Protocol(p2p): retry after some delay when connection is short-lived (#11671)
Bugfixes:
2a310be3eCore Protocol(replay): keep querying registry for new changes until reaching latest version (#11699)79114b9c0Core Protocol: Read advert bodies before taking an XNet endpoint permit (#11702)14ca7cc0bCore Protocol(ci): compile the universal canister module without host CPU features (#11673)
Performance improvements:
19d16c0bbCore Protocol: Do not count asynchronous HTTP outcall receipts towards the per-block response limit (#11713)fb9a8cc13Core Protocol: Drop delivered HTTP outcall contexts once all replicas are accounted for (#11709)6f8c82bdbCore Protocol: Wrap someCanisterHttpRequestContextfields inArc<_>(#11568)443585ebcCore Protocol(https_outcalls): Avoid cloning responses when building payloads (#11676)
Chores:
687e6a42eCore Protocol(protobuf): add the canister HTTP hashes-in-blocks messages (#11716)7b8819b0aCore Protocol: simplify dependency graph (#11669)ecfed2b76Core Protocol: Reject some more principals with better errors (#11705)be35a3ecfCore Protocol(recovery): log downloaded checkpoint name and height (#11680)f570aa657Node: Improve manageboot.sh clean-up (#11664)bf30d3348Node: Update Base Image Refs [2026-09-24-0808] (#11666)
Refactoring:
e60630ddbCore Protocol(delegations): introduce trait to verify delegations against the replicated state (#11706)d63108a99Core Protocol: Track node health inProximityMap(#11697)4446fe452Core Protocol: ExtractXNetAdvertHandlerImplfromXNetPayloadBuilderImpl(#11696)b56357952Core Protocol: extract SOCKS proxy resolution into a cache (#11619)209c10ffaCore Protocol: share subnet memory accounting between install_code and management operations (#11682)e8616d7a0Core Protocol: share the up-front management instruction charge (#11679)a6239f7acCore Protocol: account for cycles and memory usage after management operations (#11571)
Tests:
Documentation:
Full list of changes (including the ones that are not relevant to GuestOS) can be found on GitHub.
IC-OS Verification
To build and verify the IC-OS GuestOS disk image, after installing curl if necessary (sudo apt install curl), run:
# From https://github.com/dfinity/ic#verifying-releases
curl -fsSL https://raw.githubusercontent.com/dfinity/ic/2cdff28573522b2c9c5e96a4407b50281eb82b5c/ci/scripts/repro-check | python3 - -c 2cdff28573522b2c9c5e96a4407b50281eb82b5c --guestos
The two SHA256 sums printed above from a) the downloaded CDN image and b) the locally built image, must be identical, and must match the SHA256 from the payload of the NNS proposal.
While not required for this NNS proposal, as we are only electing a new GuestOS version here, you have the option to verify the build reproducibility of the HostOS by passing --hostos to the script above instead of --guestos, or the SetupOS by passing --setupos.
Official view: dashboard.internetcomputer.org/proposal/144194