# Aeva v1.0.1-beta.1

A security release for Aeva Mainnet Beta (`aeva-1`, EVM chain id 2383):
`v1.0.0-beta.1` plus one fix. It replaces `v1.0.0-beta.1`, which must not
start `aeva-1`.

* Built from `36d47722a6fdccd70d1d2e1a2b8e4621a58ff219` (`v1.0.0-beta.1` and the fix below).
* **One transaction could stop the chain.** A transaction whose message fails
  its own stateless validation — a settlement leg with a zero, negative or
  oversized amount, a duplicate leg, an accept of settlement 0 — or has no
  handler (the unwired `x/auth/vesting` messages) was admitted by
  `broadcast_tx_sync`, gossiped and proposed, and every validator rejected
  every proposal carrying it, round after round. aeva-testnet-1 stopped this
  way at height 317 444. `broadcast_tx_sync` now refuses such a transaction at
  once with the message's own error, and a proposer drops one that reached its
  mempool anyway, with its sender's later transactions in the same block.
* Settlements: at most 16 legs, checked before anything else
  (`settlement/3`); governance cannot raise `max_legs` above 16. A zero,
  negative or oversized leg amount is `settlement/23`, `24` or `25` (it was
  `settlement/16`).
* Not a rolling patch: a network must not run `v1.0.0-beta.1` and
  `v1.0.1-beta.1` side by side (ADR-019, addendum). `aeva-1` starts on
  `v1.0.1-beta.1`.

Otherwise as `v1.0.0-beta.1`:

* Mainnet Beta starts from the project's own pre-genesis locks on Robinhood
  Chain. The bridge for $AEVA holders is closed at launch and opens by a
  governance vote after the external audit.
* 60 % of every fee is burned, 40 % goes to the stakers.
* No faucet on mainnet: this release carries no faucet binary.
