Bitcoin Core Github
44 subscribers
121K links
Download Telegram
💬 optout21 commented on pull request "mempool: Avoid needless vtx iteration during IBD":
(https://github.com/bitcoin/bitcoin/pull/32827#issuecomment-3093209323)
ACK 249889bee6b88eb9814eb969e6fb108f86a4bf98
💬 Eunovo commented on pull request "Silent Payments: Receiving":
(https://github.com/bitcoin/bitcoin/pull/32966#discussion_r2217572750)
The derived spend private key must be saved to the DB by the wallet.

We can avoid this by doing what other descriptors do; the sp descriptor will then be in this form `sp(xpriv/352h/0h/0h/1h/0,xpub/352h/0h/0h/0h/0)` . The `Parse` function will then derive the scan key and save it in the descriptor. The spend key can be derived later when needed from the master key.

With this alternative method, the wallet only saves the master key to DB as it has always done.
💬 Eunovo commented on pull request "Silent Payments: Receiving":
(https://github.com/bitcoin/bitcoin/pull/32966#discussion_r2217573106)
We only use the reference once, so it's not needed. I'll take this out as I retouch.
💬 ajtowns commented on pull request "script: return verification flag responsible for error upon validation failure":
(https://github.com/bitcoin/bitcoin/pull/33012#issuecomment-3093224008)
> Note this is a slight behaviour change, as a consensus-related Script validation failure that happens after a standardness-related Script validation failure would not be treated as a consensus error anymore (and consequentially the peer not disconnected).

I'm skeptical whether this behaviour is really worth preserving in a limited fashion? With this change, an attacker can waste your resources without being discouraged or risking having to pay tx fees by making a consensus invalid tx that f
...
💬 Eunovo commented on pull request "Silent Payments: Receiving":
(https://github.com/bitcoin/bitcoin/pull/32966#discussion_r2217694773)
Updated
💬 Eunovo commented on pull request "Silent Payments: Receiving":
(https://github.com/bitcoin/bitcoin/pull/32966#discussion_r2217694788)
Updated
💬 Eunovo commented on pull request "Silent Payments: Receiving":
(https://github.com/bitcoin/bitcoin/pull/32966#discussion_r2217694846)
I broke this into 3 commits.
💬 Eunovo commented on pull request "Silent Payments: Receiving":
(https://github.com/bitcoin/bitcoin/pull/32966#discussion_r2217695331)
I ended up leaving the reference and used it in 2 other locations. The code looks slightly cleaner this way.
💬 Eunovo commented on pull request "Silent Payments: Receiving":
(https://github.com/bitcoin/bitcoin/pull/32966#issuecomment-3094352453)
Added @achow101 as co-author on commits with code/ideas taken from https://github.com/bitcoin/bitcoin/pull/28453
💬 hebasto commented on pull request "p2p: improve TxOrphanage denial of service bounds":
(https://github.com/bitcoin/bitcoin/pull/31829#discussion_r2217735632)
b113877545a1c83b470a380402b4409aa02c8282

On Alpine Linux v3.22, using GCC 14.2.0:
```
[ 74%] Building CXX object src/test/fuzz/CMakeFiles/fuzz.dir/txorphan.cpp.o
In file included from /bitcoin/src/script/script.h:10,
from /bitcoin/src/primitives/transaction.h:11,
from /bitcoin/src/consensus/validation.h:11,
from /bitcoin/src/test/fuzz/txorphan.cpp:6:
/bitcoin/src/crypto/common.h: In function 'void txorphanage_sim_fuzz_target(FuzzBuffer
...
🤔 OrangeDoro reviewed a pull request: "test: revive test verifying that `GetCoinsCacheSizeState` switches from OK→LARGE→CRITICAL"
(https://github.com/bitcoin/bitcoin/pull/33021#pullrequestreview-3035969517)
Hi! I'm a grad student working on a research project about using large language models to automate code review. Based on your commit 966bbabbd69039a2c7a03429c783f7d6e6a7c2a7 and the changes in src/test/validation_flush_tests.cpp, my tool generated this comment:
1. **Dynamic Memory Usage Check**: Ensure that the expected behavior of `DynamicMemoryUsage()` aligns with the assumptions made in this test.
2. **Dynamic Memory Usage Checks**: The checks for `view.DynamicMemoryUsage()` are essential t
...
🤔 OrangeDoro reviewed a pull request: "test: Do not pass tests on unhandled exceptions"
(https://github.com/bitcoin/bitcoin/pull/33001#pullrequestreview-3035969810)
Hi! I'm a grad student working on a research project about using large language models to automate code review. Based on your commit faa3e684118bffa7a98cf76eeeb59243219df900 and the changes in test/functional/test_framework/test_framework.py, my tool generated this comment:
1. Ensure that `e.stdout` and `e.stderr` are checked for existence before logging to prevent potential `AttributeError`. Consider using `getattr(e, 'stdout', 'N/A')` and `getattr(e, 'stderr', 'N/A')`.
2. Change `except Base
...
⚠️ starixapp opened an issue: "[SECURITY] Urgent Disclosure Coordination Request – High-Risk CI/CD Vulnerability"
(https://github.com/bitcoin/bitcoin/issues/33022)
Hello Bitcoin Core Maintainers,

I’ve discovered a high-impact, multi-stage vulnerability chain that affects the CI/CD pipeline and trust chain of Bitcoin Core. The potential financial and systemic risk, if exploited, is critical and affects build integrity, wallet safety, and release trust.

I have already sent a private disclosure request to `security@bitcoincore.org` but have not yet received acknowledgment.

Due to the severity of the issue, I am requesting urgent coordination via a secure c
...
💬 kanzure commented on issue "[SECURITY] Urgent Disclosure Coordination Request – High-Risk CI/CD Vulnerability":
(https://github.com/bitcoin/bitcoin/issues/33022#issuecomment-3094520900)
Stop spamming all the different channels. Message received. No details are provided, and therefore I cannot act upon it. Stop.
💬 starixapp commented on issue "[SECURITY] Urgent Disclosure Coordination Request – High-Risk CI/CD Vulnerability":
(https://github.com/bitcoin/bitcoin/issues/33022#issuecomment-3094524335)
It’s disappointing to see that a critical vulnerability disclosure, made with clear ethical intent and no technical details exposed, is being dismissed as “spam”.

You’ve just publicly mocked a security researcher for *not leaking sensitive data*, while ignoring the fact that your security email hasn’t responded in days.

That’s not just unprofessional — it’s reckless.

I followed responsible disclosure standards to the letter:
- No PoC shared publicly
- No exploit details revealed
- Requested o
...
💬 starixapp commented on issue "[SECURITY] Urgent Disclosure Coordination Request – High-Risk CI/CD Vulnerability":
(https://github.com/bitcoin/bitcoin/issues/33022#issuecomment-3094525768)
Bryan,

Respectfully, your tone suggests authority, but to be clear: you are not listed as a security contact nor do you appear to represent Bitcoin Core’s responsible disclosure process.

If you are not in charge of CI/CD infrastructure or part of the official security response team, dismissing a potential systemic vulnerability as “spam” is not only inappropriate — it’s dangerous.

If you’d like to discuss memes or mailing lists, that's fine. But if you're not the person handling billion-dolla
...
💬 kanzure commented on issue "[SECURITY] Urgent Disclosure Coordination Request – High-Risk CI/CD Vulnerability":
(https://github.com/bitcoin/bitcoin/issues/33022#issuecomment-3094531100)
Your message is literally spam. It was sent four times to the mailing list in minutes, with slight variations testing filters I assume. It carries no pertinent information, and no patch to fix any security issues. Yes, I speak with authority because I know that anyone is able to contribute patches to GitHub. Also, if I am to believe you are truthful, then I'm also to believe you are truthful when you say that you sent to the security mailing list as well. So why would I not believe that? I'm spe
...
💬 kanzure commented on issue "[SECURITY] Urgent Disclosure Coordination Request – High-Risk CI/CD Vulnerability":
(https://github.com/bitcoin/bitcoin/issues/33022#issuecomment-3094546396)
I suppose the other possibility is that you do not want to use the PGP keys from the website or repository? But you specifically say you are looking for PGP keys.
💬 starixapp commented on issue "[SECURITY] Urgent Disclosure Coordination Request – High-Risk CI/CD Vulnerability":
(https://github.com/bitcoin/bitcoin/issues/33022#issuecomment-3094551778)
At this point, it’s clear you're more interested in gatekeeping than in actual security.

You’re attacking a disclosure you haven’t seen, dismissing a threat you haven’t reviewed, and injecting yourself into a process you’re not responsible for — all while preaching about protocol you clearly don't understand.

Let me be clear:
- I used the correct PGP keys.
- I used the official security contact.
- I requested private coordination to avoid exactly this kind of circus.

And what did I get?

A se
...
💬 starixapp commented on issue "[SECURITY] Urgent Disclosure Coordination Request – High-Risk CI/CD Vulnerability":
(https://github.com/bitcoin/bitcoin/issues/33022#issuecomment-3094554516)
Bryan,

Let’s correct the record — again:

I sent the message twice. Not four times. Not a filter test. Just a researcher trying to do the right thing through responsible disclosure.
The rest of your assumptions are as inaccurate as they are unnecessary.

If you’re seeing every attempt to coordinate securely as spam, and every ethical move as suspicious, then perhaps you’re part of the problem — not the solution.

You’ve misrepresented facts. You’ve mocked someone avoiding public leaks. And no
...