QRL Weekly, 2026-October-02
2nd October 2026
Weekly Development Snapshot
Status
- September 18th: QRL Release Verifier audit complete
- September 11th: Ledger app audit and remediation complete
- August 4th: Audit results published for go-qrllib
- April 3rd: Audit complete of 2 cryptographic libraries
- March 31st: QRL 2.0 Testnet V2 released
- Audits & Remediation: 60%
QRL 2.0 Testnet V3 checklist from that update:
- Config parameters
- [done] Upstream bug fixes
- Testnet V2 scoped audits
QRL 2.0
qrysm
- Improved fork-choice and block-import recovery, preserving votes, finalization and execution validation across partial failures, cancellations and reorganizations
- Fixed handling of skipped-slot checkpoints, duplicate blocks and state recovery when blocks disappear during reads
- Improved state snapshot isolation and cache consistency, and released detached validator references to avoid retaining unused memory
- Hardened deposit processing and execution RPC handling against malformed responses, failed batches and timeouts
- Corrected SSZ encoding bounds and Merkle proof construction, and preserved signatures, deposit commitments and proposer slashings during copying and conversion
- Fixed voluntary exits to load custom chain configuration, so exits use the correct network’s signing parameters
- Added regression coverage for the fixes
qrl-tests
- Added automated consensus and staking test suite, covering deposits, validator activation, attestations, voluntary exits and withdrawals on a live test network
- Added the suite to nightly testing, with deposit waits derived from the live chain configuration and exits signed through the validator keymanager API
go-qrllib
- Added an additional Falcon-1024 tests, covering randomized encoding and FFT operations, sampling, key derivation and signing
- Included checks for architecture-sensitive key derivation; the upstream Falcon-1024 integration remains in review
- Updated the upstream Codecov CI action to v7.1.1
rust-qrllib
- Added ML-DSA tests confirming that signing fails after secret-key zeroization, repeated zeroization is safe, and the public key can still verify earlier signatures
- Refreshed Rust crates, demo dependencies and CI action pins
qrypto.js
- Updated development dependencies and CI action pins, including Mocha 12 and refreshed linting, formatting, build and browser-test tooling
QRL 1.x
QRL
- Corrected multisig test seed descriptors on the same branch
qryptonight / qrandomx
- Switched Linux builds to portable CPU targets, improving compatibility across x86-64 and ARM64 hardware
- Preserved optimized Argon2 runtime selection in qrandomx while using the portable build baseline
- Fixed source-distribution builds and version metadata; published pyqryptonight 0.99.13 and pyqrandomx 0.3.4
qrl-docker / qrl-docker-ci
- Documented the portable CPU baseline and how operators can verify their images
- Removed temporary compiler-wrapper workarounds from the Bionic and Focal images after the mining-library fixes became available
- Added Clang 18 to the Noble CI image for ThreadSanitizer testing
qrl-v1-docker-cluster
- Added a tool for running disposable QRL 1.x test networks across multiple Docker images
- Checks node health, mining, agreement on block hashes, wallet persistence and CPU instruction compatibility, then saves a report and logs
2nd October 2026