Repository navigation
fix(security): bump evm to GHSA Aug-2026 patched commit (mainnet/v36) - #4637
Merged
Merged
Conversation
…et/v36) Points the evm dependency at the patched release/v35 tip (github.com/zeta-chain/evm @ 51190f04, zeta-chain/evm#36) carrying the statedb underflow/overflow/atomicity guards, the module-account guard gated on the chain's blocked-receive policy, and the x/ibc/callbacks packet-timeout context fix. Logic-only; no module-set/store change, no upgrade handler. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
morde08
approved these changes
Sep 3, 2026
skosito
enabled auto-merge (squash)
September 3, 2026 16:04
s2imonovic
approved these changes
Sep 3, 2026
kingpinXD
approved these changes
Sep 3, 2026
morde08
pushed a commit
that referenced
this pull request
Sep 3, 2026
…innet/v36) (#4639) #4637 pinned the squash-merged release/v35 tip (51190f04), which carries the module-account guard re-gated on the chain's blocked-receive policy: delta.Sign() != 0 && k.bankWrapper.BlockedAddr(cosmosAddr) Live v36.0.6 runs the earlier form, which rejects any module account: delta.Sign() != 0 && acct is sdk.ModuleAccountI ZetaChain's blocked-receive set is a strict subset of its module accounts (x/fungible, x/crosschain and emissions are deliberately not blocked), so for an unblocked module account with a non-zero delta the two forms take different branches -- reject vs. mint/burn. That is a consensus-breaking difference and must not ship as a v36.0.x patch. Repins to 3e5f8e53, the commit v36.0.6 was built from, restoring an exact behavioural match with the deployed binary. The blocked-receive guard is still a wanted improvement; it needs its own coordinated upgrade. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Mainnet (node
release/v36) node-side of the fix. One line: bumps thecosmos/evmreplace to the patched commit.51190f04is the current tip ofzeta-chain/evm'srelease/v35— the fork line mainnet's v36 pins — after zeta-chain/evm#36 merged. It carries:SubBalanceunderflow guard +ParseAmountextended-denom handlingAddBalanceoverflow guardStateDB.Commit()atomicity (cache-context staging)the module-account guard, gated on the chain's blocked-receive policy
snapshot locked balance on the statedb account
x/ibc/callbacksonPacketTimeout:cachedCtx, not the livectxLogic-only: no module-set change, no store migration, no upgrade handler → ships as an ordinary
v36.xpatch (handlers key on major version).Vesting-module drop is intentionally NOT here — it changes the module version map and needs a coordinated upgrade; separate, non-urgent.
Note on the pin
Pinned to the merged
release/v35tip rather than to a commit on the PR branch. #36 was squash-merged, so the pre-merge commits are unreachable from any branch and a pseudo-version naming one of them would break as soon as the PR branch is deleted.The
v0.0.0-prefix matches the existing convention in thisreplaceblock. Note thatgo mod tidywould canonicalise it tov1.0.0-rc2.0.20260903155132-51190f042d34(the repo has a reachablev1.0.0-rc2tag); both resolve to the same commit but hash differently ingo.sum, so don't mix the two forms.Verification
go build ./cmd/zetacoredis green and produces a working binary. NoGOPRIVATEneeded — the evm dependency is public.Note
High Risk
Changes consensus-critical EVM/state and IBC callback behavior via a dependency swap; incorrect pinning or missed rollout could leave nodes on vulnerable logic despite no local code diff.
Overview
Security patch for mainnet
release/v36: bumps only thereplacepin forgithub.com/cosmos/evmtogithub.com/zeta-chain/evmat commit51190f042d34(tip of the fork’srelease/v35line after zeta-chain/evm#36), with matchinggo.sumentries.No node application code, module set, store migrations, or upgrade handlers change—this ships as a normal v36.x patch binary that pulls in upstream EVM fixes (balance underflow/overflow guards,
StateDB.Commitatomicity, module-account receive policy, snapshot locked balance, IBC callback timeout context isolation, and related hardening).The pin uses the existing
v0.0.0-…pseudo-version convention rather thango mod tidy’sv1.0.0-rc2.0.…form sogo.sumstays consistent with prior pins.Reviewed by Cursor Bugbot for commit 5de9c71. Configure here.
Greptile Summary
The PR advances the
github.com/cosmos/evmreplacement to the patched ZetaChain EVM commit for the mainnet v36 release line.go.mod.go.modchecksums togo.sum.Confidence Score: 5/5
The PR appears safe to merge, with the dependency pin and checksums aligned and no changed-code defect identified.
The replacement advances only the EVM source revision, preserves the module dependency graph, and includes matching checksums; the stated node build verification further confirms that the pin resolves and compiles.
Important Files Changed
Reviews (1): Last reviewed commit: "fix(security): bump cosmos/evm to GHSA A..." | Re-trigger Greptile