[Whitelisted Caller] Dispatch whitelisted `System.authorizeUpgrade` for Nexus runtime v8200

Execute the previously whitelisted System.authorizeUpgrade call via the Whitelisted Caller track to authorize runtime upgrade nexus-v8200 on Nexus.

Dispatch Call Details

  • Outer call: Whitelist.dispatchWhitelistedCall(callHash, callEncodedLen, callWeightWitness) (pallet index 83, call index 2)
  • callHash: 0xc842c4dd0714ff1c1dcde5c27216f8561ef47d1ec75b3e59ef93abdb5f8942f6
  • callEncodedLen: 34
  • callWeightWitness: { refTime: 110778120, proofSize: 0 }

Runtime Information

  • Release: nexus-v8200 (published August 1, 2026)
  • Commit: c28fc0eb42ccde3091830ac5b38c4a1a0f0c066b
  • Spec version: 8200 (nexus-8200 nexus-0.tx1.au1), upgrading from 8000
  • WASM file: nexus_runtime-v8200.compact.compressed.wasm (2,082,839 bytes / 1.99 MiB)
  • WASM Keccak-256: 0x1e45b50cdfb9b90eab07bf3c83125300cf2dd911a2a02e6f1eec4957e1ec5bd5
  • Toolchain: rustc 1.91.1 (ed61e7d7e 2025-11-07)

What's Changed

polkadot-sdk stable2606 upgrade

The largest part of this release by volume. It moves the runtime onto the stable2606 SDK line and changes several runtime API signatures:

  • SessionKeys_generate_session_keys now takes an owner argument and returns OpaqueGeneratedSessionKeys, carrying a proof of possession over the owner account
  • a new KeyToIncludeInRelayProof runtime API is implemented, returning empty because this runtime reads no extra relay chain storage
  • pallet_scheduler gains SchedulingSignatureVerifier, set to ()

Collator operators calling author_rotateKeys should check their tooling against the new session keys signature.

Dispatchable XCM execute turned off

XcmExecuteFilter moves from Everything to Nothing, so PolkadotXcm::execute no longer accepts locally dispatched XCM programs. XcmReserveTransferFilter was already Nothing; XcmTeleportFilter and SafeCallFilter are unchanged at Everything.

GRANDPA consensus proofs bound to the tracked state machine

ismp-grandpa now checks that the shape of an incoming consensus message matches the state machine the client is configured to track, before any verification arm runs. A relay chain proof submitted against a parachain tracker, or the reverse, is rejected up front with ConsensusMessageStateMachineMismatch rather than being routed into a verification path that was never meant to receive it.

Mandatory proofs

Mandatory consensus proofs that do not advance a parachain's height are now accepted rather than discarded, and mandatory proofs are stored under their own offchain namespace so they no longer share key space with ordinary proofs.

ByteVector length validation on SCALE decode

ByteVector now validates its declared length while decoding instead of trusting it.

Edited
Reply
Up
Share
Status
Decision1d
Confirmation
1hr
Attempts
1
Tally
100%Aye
50.0%Threshold
0%Nay
Aye
349.48MBRIDGE
Nay
0BRIDGE
  • 5.00%
  • 0.0%

    Threshold

  • 0.0%
Support
57.5%
349.48MBRIDGE
Issuance
607.67MBRIDGE
Votes
Nested
Flattened
Actions
Check how referenda works here.
Call
Metadata
Timeline6
Votes Bubble
Curves
Statistics
Comments

Status
Decision1d
Confirmation
1hr
Attempts
1
Tally
100%Aye
50.0%Threshold
0%Nay
Aye
349.48MBRIDGE
Nay
0BRIDGE
  • 5.00%
  • 0.0%

    Threshold

  • 0.0%
Support
57.5%
349.48MBRIDGE
Issuance
607.67MBRIDGE
Votes
Nested
Flattened
Actions
Check how referenda works here.