• v0.14.0 ee534b0f55

    btcbob released this 2026-09-26 13:51:52 +00:00 | 4 commits to main since this release

    The big change in this release is the wallet file. Read the first section before you upgrade.

    Your wallet is converted to a new format on first start

    Until now wallet.dat was a Berkeley DB file. From v0.14.0 it is an SQLite file. The records inside (keys, labels, watch-only addresses, transactions) are the same; only the file format around them changes.

    What happens the first time v0.14.0 starts with an old wallet:

    1. It reads your old wallet.dat without changing it.
    2. It writes every record into a new SQLite file, reads the new file back, and checks it against the original, byte for byte.
    3. It keeps your original file, unchanged, as wallet.dat.bdb-<number> in the same folder (the number is the time of the conversion).
    4. Only then does the new file take the name wallet.dat.

    The log says so in one line:

    Migrated wallet.dat to SQLite: 25 records written and verified byte for byte in 10ms; the Berkeley DB original is kept as wallet.dat.bdb-1790342535
    

    If any step fails, the node stops with an error and your original wallet.dat is left exactly as it was. Nothing is ever deleted. An encrypted wallet converts without asking for your passphrase, and the same passphrase unlocks it afterwards.

    Older versions cannot open a converted wallet. If you start v0.13.8 or earlier on it, it stops with wallet.dat corrupt, salvage failed. The file is not damaged and is not changed by that; the old version simply cannot read the new format.

    If you need to go back to an older version, you have two ways:

    • The kept original. Stop the node, move the new wallet.dat aside, and rename wallet.dat.bdb-<number> back to wallet.dat. Anything that happened in the wallet after the upgrade (new addresses, labels) is not in that file, although transactions to old addresses show up again after a rescan.
    • Export and import. On v0.14.0, dobbscoin-cli dumpwallet <file> writes every key and label to a text file. On the older version, start with a fresh wallet and run dobbscoin-cli importwallet <file>. That file holds your private keys in plain text: keep it somewhere safe and delete it when you are done.

    Back up before you upgrade anyway. The conversion keeps your original, but a backup on another disk is still the only thing that survives a lost disk. Wallets you back up with backupwallet from now on are SQLite files too.

    Other wallet changes

    • A damaged wallet stops the node instead of being quietly rewritten. The old version, on finding a damaged wallet file, salvaged whatever it could read and carried on. v0.14.0 stops and says so, and -salvagewallet is there when you choose to use it. -salvagewallet now keeps redeem scripts, watch-only addresses, labels and key metadata, not only keys, and a single bad record no longer costs every record stored beside it.
    • A write-protected wallet.dat is refused at startup with a message that says it cannot be written, instead of starting and failing at the first new address.
    • A symlinked wallet.dat stays where it is. If your wallet.dat is a link to another disk, the conversion and encryptwallet now work on the real file there, instead of replacing the link with a plain file in the data folder.
    • Every write is safe against a power cut. Each change is flushed to disk, including the folder entry, before it counts as done.
    • Refilling the keypool is fast. 1000 new keys went from about 6 seconds to a third of a second.
    • The wallet file code was checked with fuzzing (random and damaged files fed to it for hours) and a code review. Those found and fixed several problems before release, the worst being a damaged wallet that could load with an encrypted key missing and no error. None of these problems ever existed in a released version; they were all in the new code.

    Mining

    The built-in miner is much faster, solo and pool. It now hashes several nonces at once using the SIMD instructions of your processor: about 5 to 6 times faster on processors with AVX2, and 2 to 3 times faster on older ones that have only SSE2. It picks the fastest method your processor supports by itself, and the log says which one (Scrypt miner: using AVX2 (6-way)). To force one, start with -minerscrypt=generic, sse2, avx or avx2. Only the miner changed: block validation still uses the original scrypt code, and the miner checks every block it finds with that code before sending it.

    Network

    DNS seeds on a second domain. v0.13.8 added ten spare seed names, all on dobbscoin.info, so they shared one registrar and one renewal date. Five more now ship on 23skidoo.info, behind the same nodes:

    jhvh1.23skidoo.info
    dobbs.23skidoo.info
    eris.23skidoo.info
    connie.23skidoo.info
    nheeghee.23skidoo.info
    

    A new node has two independent ways to find the network by name. Seeds are not consensus.

    Fallback addresses that work. When no DNS seed answers, a node falls back to a built-in list of addresses. That list was still Bitcoin's from 2015 and reached no (BOB) node at all. It now holds the six public (BOB) nodes behind the DNS seeds.

    Downloads and installing

    The Linux builds no longer need libnatpmp or libminiupnpc (#45). Every Linux build since v0.13.5 failed on a system without those two packages, with error while loading shared libraries: libnatpmp.so.1. Both libraries are now built into the binaries. Port mapping (-mapport) works as before.

    Both Linux tarballs include dobbscoin-cli. The v0.13.8 daemon tarball shipped dobbscoind alone.

    A Windows installer. This release ships a setup.exe alongside the zip. It installs to Program Files\Dobbscoin: the wallet, a short readme and a plain-words license summary in that folder, the daemon and dobbscoin-cli in daemon, and two documents (files.md, tor.md) in doc. Its uninstaller removes everything it added to the registry. The installer shows "Bob" and the Dobbscoin coin; its images and icons had been Bitcoin's since an old code import. The zip is still there for people who would rather not install anything.

    The installer waits for a running wallet. If Dobbscoin is still running, the installer now says so before it copies anything and offers Retry and Cancel, instead of failing halfway with "Error opening file for writing". A silent install (/S) stops with an error code instead.

    License notices. COPYING now ends with a Third-party notices section for the code bundled into the programs. Every download carries it, the AppImage included.

    Updated Windows libraries: OpenSSL 3.5.8, Boost 1.83, Qt 5.15.19. The Windows programs need nothing but Windows itself. Every Windows program now reports its real version in its file properties (it used to say 0.13.0.0).

    For people who build from source

    • Berkeley DB is gone as a build dependency. The wallet needs SQLite (libsqlite3-dev) instead. Nobody has to build Berkeley DB 4.8 by hand anymore.
    • CMake builds the whole tree (#43), beside Autotools for this one release. Both produce the same code; Autotools is removed in the next release. BUILDING.md has copy-and-paste steps for Linux and for the Windows installer, and doc/build-cmake.md has every option.
    • qa/run-all.sh runs every test suite in one command: 26 suites, 0 failures.
    • The wallet file readers have libFuzzer harnesses; see doc/fuzzing.md.

    No consensus rules change in this release.


    Should you upgrade?

    Everyone, eventually. Future releases build on the new wallet format. Read the first section, make a backup, and upgrade when it suits you.

    Miners and pool operators: be on v0.13.8 or later before block 2,000,000 (roughly 2027-01-24), when CHECKLOCKTIMEVERIFY activates by height. There is no version signaling to warn anyone first. v0.14.0 satisfies that; so does v0.13.8. If you run a pool, test the wallet conversion on a copy of your pool wallet first, and don't leave the upgrade to the last week.

    What the Linux builds need

    The daemon tarball (dobbscoind, dobbscoin-cli) is dynamically linked against these, which most Debian and Ubuntu systems already have:

    sudo apt install libsqlite3-0 libssl3 \
                     libboost-chrono1.74.0 libboost-filesystem1.74.0 \
                     libboost-program-options1.74.0 libboost-thread1.74.0
    

    libsqlite3-0 is new in this release. libnatpmp1 and libminiupnpc17 are no longer needed. The binaries are built on Ubuntu 22.04 and need glibc 2.34 or newer.

    The Qt tarball also needs the system Qt 5 libraries (libqt5core5a libqt5gui5 libqt5widgets5 libqt5network5 libqt5dbus5), libqrencode4 and libprotobuf23. libprotobuf23 is not packaged on some newer systems (Debian 12 ships libprotobuf32). If the Qt tarball will not start, use the AppImage.

    The AppImage bundles its libraries and needs none of this.

    Verification

    All of this was run on the release files themselves, the Linux ones on a machine that did not build them:

    • Version: every program reports v0.14.0.0-ee534b0f; getinfo reports "version" : 140000.
    • Linux, with libnatpmp and libminiupnpc hidden from the loader: the daemon starts, mines on regtest, sends and confirms a payment, and backupwallet writes a valid SQLite copy. The v0.13.8 daemon, under the same conditions, fails in the loader.
    • Wallet conversion, Linux and Windows: wallets written by an unmodified v0.13.8, one plain and one encrypted, convert on first start. The kept .bdb- file is byte-identical to the original. Labels and the watch-only address are present. The encrypted wallet refuses a wrong passphrase, unlocks with the right one, signs a message and spends.
    • The way back: v0.13.8 refuses a converted wallet and leaves it unchanged; a dumpwallet file from v0.14.0 imports into v0.13.8 with its labels.
    • Mining: 60 seconds of solo mining on testnet, 8 threads on an AVX2 processor: about 97,000 hashes per second on Linux and 94,000 on Windows. 4 threads on an SSE2-only processor: about 38,000. Each time the log named the method it chose. The new code matches the original scrypt on 3,072 random inputs and 128 real mainnet block headers for every method the processor supports.
    • Windows: the unit tests pass (177 cases); the installer installs silently, the installed programs are identical to the ones in the zip and carry version 0.14.0.0, and the uninstaller leaves no registry key and no folder behind.
    • Test suites: consensus and scrypt suites 37 cases, no errors; qa/run-all.sh: passed 26 failed 0 known failures 0.

    Checksums

    c5e5caed803991825f87d776feb411a90a5a7bb07bd40982b2f0967591b58588  dobbscoin-v0.14.0-linux-daemon.tar.gz
    d2a1245a34cfcc947c3f1fb22ed4c2daf8957e327aea4402c9b19df456f2b64c  dobbscoin-v0.14.0-linux-qt.tar.gz
    f111d52ce5e13b825a6e38613b88b24af522b235c481fd5b66d71c70b1b8e5c2  dobbscoin-v0.14.0-win64-setup.exe
    56d271d65ef67d058b1e2a71182441b1ba77f95a517cebac77e7609ea20937d7  dobbscoin-v0.14.0-win64.zip
    df3b57a23b747742b2edaf17ff9f825204fe094b3591c728a96ef67c640df79e  dobbscoin-v0.14.0-x86_64.AppImage
    

    The zip also carries SHA256SUMS-windows.txt for the three programs inside it. To check a download on Linux: sha256sum -c SHA256SUMS.txt. On Windows: certutil -hashfile <file> SHA256.

    Downloads
  • v0.13.8 7c315584da

    btcbob released this 2026-09-18 14:33:59 +00:00 | 88 commits to main since this release

    Consensus

    CHECKLOCKTIMEVERIFY (BIP65). OP_NOP2 becomes OP_CHECKLOCKTIMEVERIFY, enforced from
    block 2,000,000 on mainnet, the same height as the AuxPoW merge-mining fork, so the network
    takes one upgrade instead of two. Below that height the opcode behaves exactly as it always did,
    which is what keeps this a soft fork. This is what atomic swaps need; nothing else in the release
    depends on it.

    Signature verification moved from OpenSSL to libsecp256k1 v0.5.1. Validation no longer depends
    on which OpenSSL version a binary happened to link against. Unlike CLTV this is live the moment
    the node runs
    , not at a future height. Signing already used libsecp256k1; only verification was
    on the OpenSSL path.

    Block-version comparisons read the base version. Past block 2,000,000 the AuxPoW chain ID
    occupies the high bits of nVersion, so every block reads as version 11,534,339 and a plain
    nVersion >= N comparison is true for every N. Six comparisons, including the soft-fork majority
    checks, now call GetBaseVersion(). A no-op below 2,000,000 and the reason soft-fork logic still
    means something above it.

    Network

    A peer running an older protocol version is no longer refused. MIN_PEER_PROTO_VERSION was
    defined as PROTOCOL_VERSION itself, so the next bump of the protocol version, for any reason at
    all, would have made the new release refuse every node already on the network while those nodes
    happily accepted it. Nothing changes today; the floor is the literal 70005, where the network has
    been since the v10.2.0 hardfork.

    Ten spare DNS seeds. seed1.dobbscoin.info through seed10.dobbscoin.info ship alongside
    seed.dobbscoin.info. They have resolved since 2026-08-16; until now the client asked for one of
    them. One seed name is one thing to break.

    A peer-selection loop no longer burns a CPU core. CAddrMan::Select_() retried an unbounded
    random walk over a sparse address table, and on a node with few known addresses it could spin at
    essentially 100% of a core indefinitely. It is bounded now, and it stops using the slow RNG to do
    it. Measured on a real node: 99.2% of a core before, 0.1% after.

    Wallet

    The pool field defaults to pool.dobbscoin.info:3033. A blank field sent miners to 3032 at
    difficulty 15,000, where a small rig finds nothing and sees no error. 3033 starts at difficulty 4.

    Node operators

    -assumevalid=<blockhash>. Skips signature verification for the named block and everything
    before it, which until now only the last checkpoint could do. It defaults to block 1,890,000 and
    -assumevalid=0 turns it off and verifies everything. This is a local sync-speed setting: it
    relaxes no consensus rule, every other check still runs on every block, and a block that fails one
    is still rejected. The named block has to be on the header chain the node is actually following, so
    a low-work chain cannot talk a node out of verifying.

    getblockheader, and getblock accepts an integer verbosity. Standard RPC shapes that tooling
    expects.

    Developer

    qa/run-all.sh runs every suite in the tree in one command: the unit tests, the CLTV and AuxPoW and
    assumevalid chain harnesses, and all twenty functional tests. 25 suites, 0 failures, about five
    and a half minutes.

    The twenty functional tests in qa/rpc-tests had not run in years; they were written for Python 2.
    They run again. Regtest also stopped retargeting its difficulty, which it had been doing from block
    20 on a chain whose block times are all zero, hardening the target by three orders of magnitude and
    taking mining from 30 milliseconds a block to 33 seconds.


    Should you upgrade?

    Miners and pool operators: yes, before block 2,000,000 (roughly 2027-01-24 at 120-second
    spacing). CLTV is a soft fork, which means it makes previously-valid things invalid. A miner running
    older software past that height can mine a block that violates a CLTV lock; upgraded nodes will
    reject it and that block is lost. There is no version signaling to warn anyone first: the AuxPoW
    chain ID makes version bits unreadable past 2,000,000, so activation is by height, flag-day style.

    Everyone else: yes, whenever convenient. The addrman fix is the one change with an effect you
    can see today. A node older than this release still follows the chain until 2,000,000, and v0.12.0
    remains the floor for the AuxPoW fork itself.

    Evidence behind the consensus changes

    • 68,863 real mainnet transactions revalidated with the new verification path: verifychain 4 50000, heights 1,855,101 to 1,905,101, all above checkpoint 1,848,000 so signatures are genuinely
      checked. No inconsistencies.
    • That harness was proved by sabotage, not trusted: patching Verify to fail after its first
      200 calls makes the same check return false.
    • High-S signatures proved by mutation. Low-S is not a consensus rule on this chain, so a
      libsecp256k1 port that normalises wrong would reject blocks an OpenSSL node accepts. Deleting the
      normalisation line makes a real high-S spend get rejected on a real chain while the entire unit
      test suite still passes
      .
    • A/B against production. A node running this build followed mainnet alongside a node running
      v0.13.7, compared every five minutes on tip hash rather than height. Zero divergences.
    • -assumevalid proved by sabotage too. With an abort wired into the signature-checking branch,
      a node with -assumevalid set syncs the whole chain and the control node stops dead at the first
      block carrying a spend.
    • CLTV activation suite 3/3, signature normalisation suite 2/2, on freshly built binaries.
    • AuxPoW regtest suites: RPC contract 6/6 and the consensus path 9/9, the latter accepting a real
      merge-mined block and refusing eight malformed proofs, each for its own distinct reason.
    • Full unit suite 163 cases, no errors, and the encrypt-wallet round trip passes.

    The test suite passes, for the first time

    test_dobbscoin had reported failures for years: 62 of them, then 42 after signature verification
    moved to libsecp256k1. It is now 163 test cases with no errors. The last 42 were fixtures, not
    code — script_tests.cpp builds its cases at run time and asserts each appears in
    script_valid.json / script_invalid.json, and 42 did not, each differing from a same-named entry
    only in the signature bytes. The missing vectors were merged in rather than overwriting the files,
    which would have deleted about a thousand hand-written ones.

    That matters more than it sounds: while 42 tests were red, a new regression was indistinguishable
    from the standing noise.

    What the Linux builds need

    The .tar.gz builds are dynamically linked. On Debian or Ubuntu:

    sudo apt install libnatpmp1 libminiupnpc17 libssl3 \
                     libboost-chrono1.74.0 libboost-filesystem1.74.0 \
                     libboost-program-options1.74.0 libboost-thread1.74.0
    

    Most systems have all of these except libnatpmp1. Without it the daemon fails in the loader
    before it can say anything itself:

    error while loading shared libraries: libnatpmp.so.1
    

    That is a missing package, not a bad download. This has been true of every Linux build since
    v0.13.5, when NAT-PMP was added; it went unnoticed because our own nodes were older than the
    feature. The AppImage bundles all of them and needs none of this.

    Downloads
  • v0.13.7 f95f2f2695

    btcbob released this 2026-09-10 22:59:55 +00:00 | 119 commits to main since this release

    Pool mining works. v0.13.6 could not submit a share.

    v0.13.6 was tagged at d89a9c3e — one commit before the stratum shareMultiplier fix — and its published binaries were built from that commit. A v0.13.6 wallet pointed at a pool hashes at a normal rate, reports a healthy hashrate in the Mining tab, and submits nothing.

    Confirmed in the field 2026-09-10: three authorizations on pool.dobbscoin.info:3033 produced zero shares in twenty minutes, while other miners on the same pool logged 296 accepted over the same window. The same machine on a fixed build had its first accepted share 3m21s after connecting.

    What changed

    • 45446a8c — stratum: apply the pool coin template shareMultiplier to the share bound. The client screened shares against Bitcoin's diff-1 target and omitted the coin's shareMultiplier (65536), so it was too strict by exactly that factor. At stratum difficulty 2 it demanded ~8.6e9 hashes for a share it should have found in ~131k.
    • 2bcffa21 — stratum: count rejected shares, reset session state on reconnect, fix the backoff ladder. Adds the accepted/rejected counter to the Mining tab.

    How to tell which build you have

    This build's title bar reads v0.13.7 with no commit suffix. v0.13.6 reads v0.13.6.0-d89a9c3. If your Mining tab shows a hashrate while the pool shows nothing, you are on v0.13.6 or earlier — replace it.

    The accepted/rejected counter only exists from v0.13.7 on. If your Mining tab has no such counter, that is itself the tell.

    Artifacts

    Windows x86-64, Linux (Qt and daemon-only tarballs), and an x86-64 AppImage. Verify with sha256sum -c SHA256SUMS.txt.

    The Linux binaries were built natively on our own hardware from this tag; 33 consensus test cases pass. All four artifacts were re-downloaded from the public URLs on a separate host and checked against the manifest before this release was announced.

    Downloads
  • v0.13.6 a78df4f6c7

    btcbob released this 2026-09-09 00:36:56 +00:00 | 121 commits to main since this release

    ⚠️ SUPERSEDED BY v0.13.7 — DO NOT USE FOR POOL MINING

    These binaries were built from d89a9c3, one commit before the stratum shareMultiplier fix. A v0.13.6 wallet pointed at a pool hashes normally, reports a healthy hashrate in the Mining tab, and submits nothing — no accepted shares, no rejected shares, no error. Verified in the field 2026-09-10.

    Solo mining and ordinary wallet use are unaffected. If you pool mine, get v0.13.7.

    Official release build. Artifacts and SHA256SUMS.txt as published; verify with sha256sum -c SHA256SUMS.txt

    Downloads
  • wallet-v0.13.6-20260908 a78df4f6c7

    btcbob released this 2026-09-08 23:06:48 +00:00 | 121 commits to main since this release

    Windows x64 wallet built from main. Supersedes wallet-stratumfix2-20260908, which was built from the older d77cca98 and was missing everything below except the stratum fixes.

    The Overview page now shows chain vitals

    Block height, difficulty and network hash rate, in the left column between the Balances frame and the logo — so the wallet says what the chain is doing without opening the debug window. (754f406d, ported from (OFF)'s "The Deep".)

    Pool mining works

    The pool client had been screening its own candidate shares against a bar 65,536x stricter than the pool's, because it omitted the coin template's shareMultiplier. At stratum difficulty 2 it demanded 8.59e9 hashes per share — about 6.1 days at a typical desktop rate — so it hashed at full speed and submitted nothing, on any port. A source comment asserted the multiplier was 1; it is 65536. (45446a8c)

    Also fixed (2bcffa21): rejected shares were counted nowhere, so the UI read accepted 0 / rejected 0 regardless — and one rejected share overwrote the connection-status string, making the wallet report the pool as down. Reconnect did not clear the previous session's extranonce, difficulty or job. The reconnect backoff ladder never reset, because it tested a flag its own error path had already cleared.

    Verified against the live pool

    Two independent ways: the unpatched client behind a proxy dividing announced difficulty by 65536 (Share accepted: D=2), and the patched client with no proxy (Share accepted: D=28.442, 0 rejected). Both also exercise the header assembly, merkle folding and submit path, none of which had ever produced an accepted share before.

    Use

    Pool pool.dobbscoin.info:3033, user YOUR_BOB_ADDRESS.WORKER_NAME. Expect two to three minutes of nothing after connecting while the pool walks your difficulty down, then shares. Port 3033 starts low; 3032 starts high for ASICs. Both settle in the same place.

    Build

    Cross-built from a78df4f6 on our own hardware — no GitHub Actions involved. Reports v0.13.6.0-a78df4f6.

    sha256 e31caaba59268b70c5226c2596c19cada311da2d876142504ffdf8a46979193a

    Downloads
  • wallet-stratumfix2-20260908 d77cca983a

    btcbob released this 2026-09-08 14:26:29 +00:00 | 131 commits to main since this release

    Windows x64 wallet with the in-wallet Mining tab. Pool mining works in this build; it did not in any previous one.

    What was wrong

    The pool client screened its own candidate shares against a bar 65,536x stricter than the pool's, because it omitted the coin template's shareMultiplier. At stratum difficulty 2 it demanded 8.59e9 hashes per share -- about 6.1 days at a typical desktop rate -- so it hashed at full speed and submitted nothing, on any port. A comment in the source asserted the multiplier was 1; it is 65536.

    Also fixed

    • Rejected shares were counted nowhere, so the UI read accepted 0 / rejected 0 whether or not anything was wrong -- and a single rejected share overwrote the connection-status string, making the wallet report the pool as down.
    • Reconnect did not clear the previous session's extranonce, difficulty or job, so workers resumed dead work the moment authorize succeeded.
    • The reconnect backoff ladder never reset, because it tested a flag its own error path had already cleared.

    Verified

    Against the live pool, two independent ways: the unpatched client behind a proxy dividing announced difficulty by 65536 (Share accepted: D=2), and this build with no proxy (Share accepted: D=28.442, 0 rejected). Both also exercise the header assembly, merkle folding and submit path, none of which had ever produced an accepted share before.

    Use

    Pool: pool.dobbscoin.info:3033, user YOUR_BOB_ADDRESS.WORKER_NAME. Expect roughly two to three minutes of nothing after connecting while the pool walks your difficulty down, then shares.

    Build provenance

    Cross-built from d77cca98 with the stratum fixes applied; those fixes are commits 45446a8c and 2bcffa21 on main. The reported version string is unchanged at v0.13.4-d77cca9.

    sha256 fbeb8da563043dc7eb54b5fb269f6d68a9a0a5716a28e490805b0d1ba52dea86

    Downloads