Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
This is a wallet bug, not a theft or remote-code bug. When a Bitcoin Core user turns on the optional 'avoidpartialspends' or 'avoid_reuse' setting, an output group rejected during coin selection could be counted twice as 'discarded.' That …
Logic error causing double-counting of discarded UTXO groupsCan trigger false 'insufficient funds' failure in coin selectionAffects avoidpartialspends / avoid_reuse wallets only
This is a documentation-only fix in a tutorial file. It changes two shell examples from using '>>' (append to file) to '>' (overwrite file). If a user followed the old instructions and ran the same command twice, the file would contain two…
No security signal: change is limited to documentationNo code changes to Bitcoin Core binaries, RPC, wallet, or consensus logicNo cryptographic, network, or privilege-boundary implications
This is a large internal code reorganization (refactor) in Bitcoin Core. It creates a new BlockTemplateManager class that takes over block-template creation, block submission, and tip-waiting helpers that were previously spread across seve…
Large refactor touching mining, RPC, interfaces, and test shutdown pathsNew object lifetime dependency: BlockTemplateManager holds references to mempool, chainman, and notifications; explicit reset ordering added in Shutdown/InitAndLoadChainstate/test setupsRemoval of early-init node.mining interface; BlockTemplateManager is now created after chainstate load, with a comment that it must exist before setChainstateLoaded(true) unblocks IPC waiters
This commit adds the first implementation of BIP352 (Silent Payments) to Bitcoin Core. Silent Payments are a new type of privacy-preserving Bitcoin address that lets someone receive payments without publicly revealing a fixed address. The …
New cryptographic feature implementation (BIP352 Silent Payments)Extensive use of secp256k1 silentpayments moduleInput public key extraction from P2PKH, P2WPKH, P2SH-P2WPKH, and P2TR inputs
This update fixes a wallet database loading bug where a damaged or tampered Bitcoin wallet file could cause the program to read past the end of a stored extended public key (xpub). The patch makes the loader check the stored xpub length be…
Out-of-bounds read in wallet descriptor cache deserializationASan container-overflow triggered by malformed on-disk recordMissing length validation between record size prefix and fixed-size decoder
This commit adds a new wallet RPC called listrawtransactions to Bitcoin Core. It is a feature addition that lets users list every transaction their wallet knows about, including internal transfers and consolidations that the existing listt…
No security-relevant bug fix or vulnerability patch is present in the diff.New RPC exposes additional wallet transaction metadata, but only to callers already authorized for wallet RPCs.Code is a refactor of existing gettransaction logic into shared helpers; no new cryptographic, network, or consensus code.
This Bitcoin Core update fixes several wallet bugs where a failed database write could leave a wallet in an inconsistent state. For example, encrypting a wallet or changing its passphrase could appear to succeed in memory while the change …
Atomicity fix for encryption state and descriptor key persistenceFailure to persist master key during encryption previously reported success in memoryPassphrase change could activate new passphrase only in memory
This commit only changes Bitcoin Core's internal functional test code. It replaces hard-coded test keys and addresses with ones generated from a new test helper class, and unifies how tests tell nodes not to create a default wallet. There …
This commit only adds a new automated test to Bitcoin Core. It checks that when two partially-signed Bitcoin transactions (PSBTs) are combined, any custom 'unknown' data fields attached to them are preserved correctly. There is no change t…
This is a Bitcoin Core wallet maintenance patch. It speeds up a wallet function that checks whether a descriptor already exists by caching a hash of the descriptor's canonical text, instead of rebuilding that text every time. It also tidie…
No security-relevant signal in commit message or diffChange is described as performance improvement and code cleanupBackwards-compatibility test notes a known miniscript wallet loading incompatibility between v31.0/v31.1 and other versions, but this is a documented compatibility quirk, not a vulnerability
This is a documentation-only fix for Bitcoin Core's machine-readable RPC help data. It changes several default values from literal strings to 'hint' labels (because the real default depends on context) and corrects one boolean default from…
OpenRPC schema/default mismatch correctionRPC help metadata type correction (string 'false' to boolean false)No executable code path changes
This commit fixes documentation metadata for six Bitcoin Core RPC arguments. It changes how default values are described so that automatically generated API docs and schemas are accurate. The actual behavior of the software when running is…
No runtime code changesOnly RPC help/schema metadata modifiedVendor explicitly states runtime behavior is unchanged
This commit fixes a bug in Bitcoin Core's MuHash3072 cryptographic code where dividing a MuHash object by itself (x /= x) produced the wrong mathematical result. The fix is straightforward: the code now saves the divisor's numerator before…
Cryptographic correctness bug in MuHash3072 division operatorSelf-aliasing in operator/= produces incorrect 1/D result instead of empty setNo production code path identified that triggers self-division
This is a build-compatibility fix, not a security patch. It changes how some constant data is stored internally so that Apple's macOS linker (ld64) can build Bitcoin Core correctly. The change avoids a linker bug that caused build failures…
No security-relevant code logic changedChange is a linker bug workaround, not a vulnerability fixConstants remain read-only; no new attack surface introduced
This commit refactors Bitcoin Core's wallet descriptor import feature so the same logic can be used by both the RPC command and a new GUI-facing interface. It also tightens one input rule: negative timestamps are now rejected, and the mini…
Refactor of security-sensitive wallet import code into shared CWallet pathNew input validation: negative timestamps rejected for importdescriptorsCentralization of descriptor range bound checks in CheckDescriptorRangeBounds
This change fixes a bug in how Bitcoin Core reconnects to the Tor control port. A previous update accidentally removed the wait time between reconnect attempts when an already-established Tor control connection was dropped. Without the wai…
Uncontrolled retry loop causing resource exhaustion and log floodingLocal-only Tor control port interaction; no remote attacker path by defaultRegression introduced by prior refactor (#34158) and restored here
This change updates the Windows code-signing tool used in Bitcoin Core's reproducible build process. It fixes a build-time failure where signature verification could not complete because a certificate package was missing and the old tool v…
Tooling update in release signing pipelineRestores CA certificate store for signature verificationDisables CRL/CDP network lookups during verification
This change lets Bitcoin Core store different custom signet blockchains in separate data folders, using a unique suffix derived from each signet's network identifier. It also adds a friendlier error hint in bitcoin-cli when an RPC authenti…
Data isolation between distinct custom signets reduces risk of cross-network state corruption or accidental mainnet/testnet confusionNo memory-safety, cryptographic, or consensus changes observedNo privilege escalation, remote code execution, or denial-of-service vectors introduced in the diff
This change adds two extra pieces of information—whether a spent output came from a coinbase transaction and the block height at which it was created—to a Bitcoin Core REST API endpoint. It is a feature/parity improvement to make the REST …
This change makes Bitcoin Core treat manually-added peers (from -addnode, -connect, or the addnode RPC) more gently during Initial Block Download (IBD). Previously, if such a peer was slow or stalled at sending blocks, the node would disco…
Behavior change in peer disconnection logic during IBDManual peers exempted from block-stalling disconnectionNew per-peer cooldown state m_block_download_paused_until introduced
Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.
Lower-prioritydoc: remove mention of wsystemby fanquake · 57246934 · Aug 10, 2026 · 1 fileMessage 53 · ThinTriage 0Details
Commit message · fanquake
doc: remove mention of wsystem
Followup to #35704.
53/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Links an issue, advisory, or supporting reference! No meaningful explanatory body
Security candidateMerge bitcoin/bitcoin#35937: test: Append print_suppressions=0 to LSAN_OPTIONS, and suppress bitcoin-qtby merge-script · 5973e075 · Aug 10, 2026 · 2 filesMessage 91 · StrongInformational 15Details
Commit message · merge-script
Merge bitcoin/bitcoin#35937: test: Append print_suppressions=0 to LSAN_OPTIONS, and suppress bitcoin-qt
fad9ab714b5512f204f75a94d8cc4fa164dd4061 test: Append print_suppressions=0 to LSAN_OPTIONS, and suppress bitcoin-qt (MarcoFalke)
Pull request description:
(see commit msg for rationale and background).
To test, one should be able to use the cmake options such as `-DCMAKE_C_COMPILER='clang' -DCMAKE_CXX_COMPILER='clang++' --preset=dev-mode -DBUILD_GUI=ON -DSANITIZERS=address` on e.g. Fedora. Then see that the current suppressions file is insufficient, and also confirm that `print_suppressions=0` is required.
ACKs for top commit: fanquake: ACK fad9ab714b5512f204f75a94d8cc4fa164dd4061
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
This commit only changes test configuration. It tells the LeakSanitizer tool used during automated testing to stop printing long lists of suppressed memory leaks, and it narrows the list of ignored leaks to the bitcoin-qt GUI test binary. There is no change to the actual Bitcoin Core software that users run, and no security vulnerability is being fixed or introduced.
This PR adds explicit Cache-Control headers to REST responses.
The policy is:
- Immutable data gets: `Cache-Control: public, immutable, max-age=86400` - Mutable, node-local, and error responses get: `Cache-Control: no-store`
Important details:
- `/block` and `/block/notxdetails` bin/hex, `/blockpart`, `/blockfilter`, `/spenttxouts`, and `/deploymentinfo/<blockhash>.json` are treated as immutable. - `/block` and `/block/notxdetails` JSON, all `/tx` formats, `/headers`, `/blockfilterheaders`, `/blockhashbyheight`, `/chaininfo`, `/mempool`, `/getutxos`, and `/deploymentinfo.json` are no-store. - REST errors and HTTP dispatcher-generated errors are no-store. - Unmatched `/rest` 404s also return no-store, including paths like `/rest/tx`, `/rest/does-not-exist`, and `/rest?x=1`.
Tests were added in `interface_rest.py` to cover successful responses, behavior across a newly mined block, REST errors, and unmatched REST 404s.
Docs were added to `REST-interface.md`, including guidance for overriding the defaults in a reverse proxy or CDN.
Closes #33809
ACKs for top commit: stickies-v: re-ACK 75f58519277630a398cbe3cdde33a23383b07bc3 pinheadmz: ACK 75f58519277630a398cbe3cdde33a23383b07bc3 sedited: ACK 75f58519277630a398cbe3cdde33a23383b07bc3
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Merge bitcoin/bitcoin#35260: doc: clarify test placement guidance
db74d3390a391a2a76d7b4d676342a9d1489059b doc: clarify test placement guidance (Lőrinc)
Pull request description:
**Problem:** `doc/developer-notes.md` does not explain where test coverage belongs in a commit stack, especially when existing behavior is uncovered or a refactor depends on uncovered behavior. This has led to review questions about whether tests should record current behavior before a change or be added with the final behavior, for example in [#35251](https://github.com/bitcoin/bitcoin/pull/35251#discussion_r3217842286) and [#31212](https://github.com/bitcoin/bitcoin/pull/31212#discussion_r1854105033).
**Fix:** Add a `General Testing` section under the development guidelines explaining when to use automated tests or a manual testing guide and when behavior-preserving work is easy to validate without new tests. Add a `Commit Structure for Tests` subsection distinguishing existing coverage, simple uncovered changes, non-trivial changes to uncovered behavior, and non-trivial refactors whose preserved behavior is not covered. Replace the blanket `CONTRIBUTING.md` rule with a link to the detailed guidance.
ACKs for top commit: maflcko: lgtm ACK db74d3390a391a2a76d7b4d676342a9d1489059b pablomartin4btc: ACK db74d3390a391a2a76d7b4d676342a9d1489059b LarryRuane: ACK db74d3390a391a2a76d7b4d676342a9d1489059b w0xlt: ACK db74d3390a391a2a76d7b4d676342a9d1489059b sedited: ACK db74d3390a391a2a76d7b4d676342a9d1489059b
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Merge bitcoin/bitcoin#35822: fuzz: reset SOCKS5 interrupt between inputs
77440814bf2c3eb7a649f25c585b3fd54929e5f3 fuzz: reset SOCKS5 interrupt between inputs (Hao Xu)
Pull request description:
Reset `g_socks5_interrupt` before each `socks5` fuzz input.
`CThreadInterrupt` remains interrupted until explicitly reset. Previously, inputs executed after the first input setting the interrupt flag inherited its state. As corpus inputs are shuffled between all-input coverage runs, the number of affected inputs and the resulting coverage counts could differ.
Tested with the complete 91-input `socks5` corpus. The all-input deterministic coverage check passes.
ACKs for top commit: nervana21: tACK 77440814bf2c3eb7a649f25c585b3fd54929e5f3 maflcko: lgtm ACK 77440814bf2c3eb7a649f25c585b3fd54929e5f3 sedited: ACK 77440814bf2c3eb7a649f25c585b3fd54929e5f3
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
fuzzing or regression evidencemerge-commit duplicate discount
Follow-up to [#32800](https://github.com/bitcoin/bitcoin/pull/32800#discussion_r3672286132).
This fixes the RPC help text for `MempoolEntryDescription()`. These docs are used by mempool-entry RPCs such as `getmempoolentry`, verbose `getrawmempool`, `getmempoolancestors`, and `getmempooldescendants`.
The vsize fields in those results describe transactions already in the mempool, so they are always returned and there is no `allowed` field. This removes the incorrect optional markers and the `testmempoolaccept`-specific “only present when allowed is true” wording.
No behavior change.
ACKs for top commit: sedited: ACK a3ebf8ab607f2529b634eb6fa990aef7def43d1d
f32685315c2e465a60cecd605d7446d92803c366 doc: Install `pkgconf` to find `capnproto` on NetBSD (Hennadii Stepanov) 5964c7229fc261ef9c52f3aea1bb11a68a50c803 doc: Switch `pkg-config` package to modern `pkgconf` on NetBSD (Hennadii Stepanov) 9b85c9814d1d5b1ef9caedc25dc336dacb887dcc doc: Drop GCC upgrade instructions for NetBSD (Hennadii Stepanov)
Pull request description:
This PR updates the "NetBSD Build Guide" following the latest release 11.0. See commit messages for more details.
ACKs for top commit: fanquake: ACK f32685315c2e465a60cecd605d7446d92803c366
AI review queuedMerge bitcoin/bitcoin#35928: doc: mention -DWITH_ZMQ=ON in macOS build guideby merge-script · 8397e09e · Aug 7, 2026 · 1 fileMessage 91 · StrongInformational 15Details
Commit message · merge-script
Merge bitcoin/bitcoin#35928: doc: mention -DWITH_ZMQ=ON in macOS build guide
222855ed1129669e67785c9800292f017a301816 doc: mention -DWITH_ZMQ=ON in macOS build guide (cyb3ralbert)
Pull request description:
`doc/build-osx.md` currently says:
> Support for ZMQ notifications requires the following dependency.
The `zeromq` dependency is covered, but the `-DWITH_ZMQ=ON` CMake option is not mentioned anywhere in that section. `WITH_ZMQ` defaults to `OFF`, so following the guide as written results in a build with ZMQ disabled, even though the user completed the ZMQ section. I verified this at the configure step on macOS: with `zeromq` installed and no flag, CMake reports `ZeroMQ ... OFF`; with `-DWITH_ZMQ=ON` it reports `ON`.
The same wording was added to the BSD build guides in #35283, but `doc/build-osx.md` was not included.
Docs-only change. No tests run.
ACKs for top commit: hebasto: ACK 222855ed1129669e67785c9800292f017a301816.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
This is a one-line documentation update to the macOS build guide. It adds a note telling users to pass a specific CMake option if they want ZeroMQ notification support. There is no code change and no security impact.
Merge bitcoin/bitcoin#35704: windows: remove deprecated codecvt via UTF-8 narrow APIs
6b6d77cc84e4b08641bc2f3fd3c4cf2a22ffdddf windows: remove deprecated codecvt via UTF-8 narrow APIs (kevkevinpal)
Pull request description:
Since #32380 the Windows process code page is UTF-8, so narrow APIs accept UTF-8 directly. Drop wstring_convert/codecvt and the related wide process calls (`_wsystem`, `_wexecvp`, `CreateProcessW`) in favor of `::system`, `_execvp`, and `CreateProcess`.
This should be fine to remove since Bitcoin Core is now on C++20
ACKs for top commit: hebasto: re-ACK 6b6d77cc84e4b08641bc2f3fd3c4cf2a22ffdddf, only rebased since my [recent](https://github.com/bitcoin/bitcoin/pull/35704#pullrequestreview-4845891494) review. hodlinator: ACK 6b6d77cc84e4b08641bc2f3fd3c4cf2a22ffdddf
Merge bitcoin/bitcoin#35830: fees: Return false for incompatible fee estimates
b9d573e4a9594e460e100042f195392f3a59480b fees: Return false for incompatible fee estimates (Hao Xu)
Pull request description:
policy_estimator_io deliberately reuses a CBlockPolicyEstimator because constructing one for every fuzz input severely reduces throughput. However, Read() returns true for an incompatible old fee estimates file without replacing the estimator state. The target then calls Write() with state loaded by a previous input, making coverage depend on corpus order.
Return false for incompatible files so the target skips Write() when no state was loaded. This keeps the estimator reuse optimization instead of resetting the expensive object before every fuzz input.
For the in-tree production caller, incompatible files remain non-fatal and the estimator still starts from its default state. Read() now reports failure, so startup emits one additional non-fatal warning. Node startup and estimator state are unchanged, as is RPC behavior.
ACKs for top commit: maflcko: review ACK b9d573e4a9594e460e100042f195392f3a59480b 📩 sedited: ACK b9d573e4a9594e460e100042f195392f3a59480b
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
fuzzing or regression evidencemerge-commit duplicate discount
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
merge-commit duplicate discount
Security candidateMerge bitcoin/bitcoin#35482: fuzz: exercise the transaction-handling path in process_message(s)by merge-script · f11dc617 · Aug 7, 2026 · 8 filesMessage 100 · StrongInformational 15Details
Commit message · merge-script
Merge bitcoin/bitcoin#35482: fuzz: exercise the transaction-handling path in process_message(s)
87b080fe2b66036184a54a0bfc320498dd416d74 fuzz: reset the reused mempool in process_message(s) (Hao Xu) d522fd3196368d4be337bff7bc2a5f33ce3ed1c4 fuzz: prepare deterministic mempool rebuilds (Hao Xu) b11456386b266b8c0a319b6fad3481b8eeb155cf fuzz: let the test input toggle IBD in the p2p fuzz targets (Hao Xu) 2a29cee68438e485b101e9a89c907f7a2ea38232 test: add helper to reset chainman and mempool (Hao Xu) 2a4ef42d34edf6499e4185c2fc7c6fed8b071ae7 fuzz: share a single FakeNodeClock in the chainman-resetting fuzz targets (Hao Xu)
Pull request description:
## Problem
`process_message` and `process_messages` keep the node in IBD (`ResetIbd()`) and mine their coinbases with the default bare-`OP_TRUE` output script. As a result `net_processing` returns early at the `IsInitialBlockDownload()` check and never reaches the transaction-handling path; and even if it did, a tx spending a bare-`OP_TRUE` coinbase is rejected as `NONSTANDARD` by `ValidateInputsStandardness`. The reused mempool therefore always stays empty and that path is never exercised.
## Changes
Both targets now get the same treatment:
1. **Toggle IBD from the test input** — a `bool` decides whether to also `JumpOutOfIbd()`, exercising both the IBD and non-IBD paths. In `process_message` it is consumed last, so existing corpus entries read `false` and are unchanged. In `process_messages` the messages run in a loop, so the bool must be consumed *first* (see the corpus note below). 2. **Use a spendable `P2WSH_OP_TRUE` coinbase** — both anyone-can-spend (an `OP_TRUE` witness, no signature) and a standard witness output, so a fuzz-built tx spending a mature coinbase can actually be accepted into the mempool. 3. **Reset the rng before rebuilding (preparation)** — rebuilding the chainman (and, in the next commit, the mempool) consumes the global PRNG. Reset it with `MakeRandDeterministicDANGEROUS()` first so the rebuild is deterministic across iterations. Mirrors the `cmpctblock` harness. 4. **Reset the reused mempool** — now that the mempool can become non-empty, rebuild it together with the chainman in `ResetChainmanAndMempool()` when the block index grew or the mempool changed. A dirty mempool is detected by its sequence number rather than its size, since a tx can be added and removed within one iteration (leaving the size unchanged).
## Corpus note
~~In `process_messages` the IBD bool is consumed before the message loop (first integral read), which shifts the `FuzzedDataProvider` layout. Existing `process_messages` corpus entries can be migrated by appending a single `0x00` byte at the end (read as `false`, keeping the IBD path); every other consumed value stays the same. This is a qa-assets change accompanying this PR.~~
This note no longer applies because the IBD toggle is now consumed inside the message loop. Appending a single `0x00` byte would not reliably target that bool or preserve the rest of the input layout.
The accompanying `qa-assets` update should migrate or regenerate the affected `process_messages` corpus entries for the current layout.
ACKs for top commit: Crypt-iQ: crACK 87b080fe2b66036184a54a0bfc320498dd416d74 maflcko: review ACK 87b080fe2b66036184a54a0bfc320498dd416d74 🏁 frankomosh: Review ACK 87b080fe2b66036184a54a0bfc320498dd416d74
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
entropy or randomnesssigning boundarydefensive validationfuzzing or regression evidencemerge-commit duplicate discount
AI analysis · Informational 15/100
This commit only changes Bitcoin Core's internal fuzz testing code. It makes the fuzz tests exercise more of the transaction-handling code path by toggling Initial Block Download mode and resetting the mempool between test runs. There is no change to production network, wallet, or consensus code, and no security vulnerability is being fixed or introduced.
In the ci system, `BASE_ROOT_DIR` has a default value that can be changed. This has problems:
* The docs do not mention that changing the value requires re-building the image, as the value is embedded. * Many places hard-code the default value, which is confusing and brittle.
Fix all issues by adding docs and replacing the hard-coded default values with `$BASE_ROOT_DIR`.
ACKs for top commit: willcl-ark: ACK fae7ba9abae8c5bec72b1c79bdd2480bade89399
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
fuzzing or regression evidencesigning or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit removes unused variables from Bitcoin Core's test and fuzzing code. It is a cleanup/refactoring change with no effect on the live network software or user funds. It does not fix or introduce any security vulnerability.
fa2e76d397a4be6d98d3a43f4df923fa592523ea bench: Add base_blob compare bench via uint256 (MarcoFalke) fa588e9e0f8019d855dbc41199814564c27d5256 refactor: Mark assertion_fail as [[noreturn]] (MarcoFalke) faec059dfe8bc5a90e273748ce5ced0e024dad81 refactor: Add uint256::operator<=>() (MarcoFalke) fa6df14c2360f2b55daac0744e8a675eaf3e5eb4 refactor: uint256::operator==() = default (MarcoFalke)
Pull request description:
Some refactors with rationale:
* Default the `uint256` base blob equals operator, because this is standard C++20 practise. * Add the `uint256` base blob `<=>` operator, because this is standard C++20 practise. Also, `transaction_identifier` already offers such an operator. This allows to remove the non-standard `Compare()` function. * Add a `[[noreturn]]` to the assertion failure helper that does not return. This is standard C++11 practise.
ACKs for top commit: optout21: ACK fa2e76d397a4be6d98d3a43f4df923fa592523ea Sjors: ACK fa2e76d397a4be6d98d3a43f4df923fa592523ea purpleKarrot: ACK fa2e76d397a4be6d98d3a43f4df923fa592523ea hebasto: re-ACK fa2e76d397a4be6d98d3a43f4df923fa592523ea. w0xlt: ACK fa2e76d397a4be6d98d3a43f4df923fa592523ea as a simplification/refactor, not as a performance optimization.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit is a routine code cleanup in Bitcoin Core. It switches the uint256 equality and comparison operators to use standard C++20 defaults, removes an old custom Compare() helper, and marks an internal assertion-failure function as never returning. There is no security bug being fixed and no behavior change that would affect users or attackers.
Security candidateMerge bitcoin/bitcoin#35872: rpc: avoid descriptor range counter overflowby Ava Chow · b388674a · Aug 6, 2026 · 2 filesMessage 96 · StrongModerate 62Details
Commit message · Ava Chow
Merge bitcoin/bitcoin#35872: rpc: avoid descriptor range counter overflow
264555af3cc2ab2919e49e7dea3f8066b9336020 rpc: avoid descriptor range counter overflow (Lőrinc) 143a13fb2bd190e50c26bb5582c6c0a2af17867a test: characterize descriptor range endpoint (Lőrinc)
Pull request description:
**Problem:** The authenticated `scantxoutset`, `scanblocks`, `getdescriptoractivity`, `utxoupdatepsbt`, and `descriptorprocesspsbt` RPCs share a descriptor expansion helper that iterates inclusive `int64_t` ranges with an `int` counter. A ranged descriptor with an explicit `[begin, end]` range ending at `2^31 - 1` expands that valid position, then overflows when advancing the counter to exit the loop. Trap-enabled builds terminate, while other builds invoke undefined behavior.
**Fix:** Use `int64_t` for loop control so the one-past-the-end value is representable and every position passed to `Descriptor::Expand()` remains within its existing `int` range.
Related: [#26275](https://github.com/bitcoin/bitcoin/pull/26275) fixed the same endpoint overflow in `deriveaddresses`.
ACKs for top commit: achow101: ACK 264555af3cc2ab2919e49e7dea3f8066b9336020 polespinasa: ACK 264555af3cc2ab2919e49e7dea3f8066b9336020 sedited: ACK 264555af3cc2ab2919e49e7dea3f8066b9336020
This update fixes a counting bug in several Bitcoin Core RPC commands that scan descriptors. When a user requested a descriptor range ending at the maximum allowed value (2,147,483,647), the internal counter used a smaller integer type and could wrap past its maximum, causing undefined behavior. In practice this could crash builds that catch such errors, or silently misbehave in others. The fix widens the loop counter to a 64-bit integer so it can safely reach and pass the endpoint. A test was added to confirm the edge case now works.
AI review queuedMerge bitcoin/bitcoin#35842: rpc: Properly make RPCResult::Type::ANY non-test-onlyby merge-script · c36ffd87 · Aug 6, 2026 · 4 filesMessage 91 · StrongInformational 19Details
Commit message · merge-script
Merge bitcoin/bitcoin#35842: rpc: Properly make RPCResult::Type::ANY non-test-only
fac4b06e997e197d6dca4c41bdec99c0ba84cfca refactor: Use CLIENT_NAME in buildOpenRPCDoc (MarcoFalke) fa3aadbc32e01386ddf54263d756b7a89b30addf refactor: Use self.Arg<bool> in getopenrpcinfo (MarcoFalke) fa1871a52816e7d79a29bd7cabe2901e67acf71e refactor: Remove stale NOLINTNEXTLINE above GetAddressInfoBaseFields (MarcoFalke) fa2264791490a16e55e404687140d47c58972387 rpc: Properly make RPCResult::Type::ANY non-test-only (MarcoFalke) fa1242dcc02212154913745bb41aad12dd42761e refactor: Use std::visit in ApplyArgFallback (MarcoFalke)
Pull request description:
Commit 6a1a66c180cba5f2d4189e89327de23505c7f4dd attempted to properly render RPC results of the type `ANY`.
However, the commit is incomplete.
Fix it, by properly rendering all `ANY` types.
Moreover, a few trivial refactors after https://github.com/bitcoin/bitcoin/pull/34683 are included here.
ACKs for top commit: sedited: ACK fac4b06e997e197d6dca4c41bdec99c0ba84cfca willcl-ark: ACK fac4b06e997e197d6dca4c41bdec99c0ba84cfca
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathmerge-commit duplicate discountsecond-pass: security-sensitive path
AI analysis · Informational 19/100
This is a small cleanup and documentation fix for Bitcoin Core's RPC help system. It removes a comment that incorrectly said a certain output type was 'for testing only' and makes the help text properly display those outputs. There is no direct security vulnerability here; the change is about making generated API documentation accurate and consistent.
Merge bitcoin/bitcoin#35759: fuzz: check http_request body matches framing
7502b9ddba740a2b2250764e340b17a23b15ece8 fuzz: check http_request body matches framing (ameen-alam)
Pull request description:
The http_request target asserted that ReadBody() returns an empty string. That held for the libevent-based http_libevent::HTTPRequest, where the harness only parsed the request line and headers and never populated a body. Commit 9c20859b5f (PR #35182) replaced libevent with http_bitcoin::HTTPRequest, and the target was switched over in e427c227fa; its LoadBody() now decodes Content-Length and chunked bodies per RFC 9112, so any fully-parsed request carrying a body trips the stale assertion (e.g. "POST / HTTP/1.1\r\nContent-Length: 3\r\n\r\nabc").
Replace the emptiness check with a framing-consistency check that mirrors LoadBody()'s own branch logic: a chunked body is bounded by MAX_BODY_SIZE, a Content-Length body is exactly that many bytes, and a request with neither framing header has no body. This strengthens the target instead of dropping the assertion.
**Steps to reproduce (old assertion):** Build the fuzz binary and pass this input as a file to the `http_request` target: `POST / HTTP/1.1\r\nContent-Length: 3\r\n\r\nabc` → `test/fuzz/http_request.cpp:49: Assertion 'body.empty()' failed`
**Testing the fix:** Ran the updated target ~16 min under libFuzzer with ASAN/UBSAN (14.2M execs, no crashes), plus targeted inputs for each branch: Content-Length body, chunked, `Transfer-Encoding: identity` + Content-Length, no framing headers, and `Content-Length: 0`. Happy to contribute the repro input to qa-assets as a follow-up.
ACKs for top commit: pinheadmz: ACK 7502b9ddba740a2b2250764e340b17a23b15ece8 marcofleon: tACK 7502b9ddba740a2b2250764e340b17a23b15ece8
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
fuzzing or regression evidencemerge-commit duplicate discount
Merge bitcoin/bitcoin#35912: doc: fix stale bitcoin_en.xlf reference
e98ffd4bd82d35ea316f977a9659c8080066b643 doc: fix stale bitcoin_en.xlf reference (cyb3ralbert)
Pull request description:
`doc/release-process.md` still instructs users to create the Transifex resource from `src/qt/locale/bitcoin_en.xlf`, even though that file no longer exists.
It was removed in #34808, which switched the Transifex source to the native Qt `.ts` file. That PR updated the other references to `.xlf` in this document, but this one was missed. The last step in the same list already refers to `bitcoin_en.ts`, as does `.tx/config`.
This patch updates the remaining outdated reference.
Docs-only change. No tests run.
ACKs for top commit: hebasto: ACK e98ffd4bd82d35ea316f977a9659c8080066b643. This was overlooked in https://github.com/bitcoin/bitcoin/pull/34808.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Lower-priorityMerge bitcoin/bitcoin#34927: test: Check that RPCs do not time out, even under loadby merge-script · 950b1c09 · Aug 6, 2026 · 4 filesMessage 91 · StrongTriage 0Details
Commit message · merge-script
Merge bitcoin/bitcoin#34927: test: Check that RPCs do not time out, even under load
fa7bc26d1276581aac795daf8ceaea903cdcd7b3 test: Check that RPCs do not time out, even under load (MarcoFalke) fa2bd96cc0d4887b94b3f2601649ef62c5513308 test: Map cli CalledProcessError on server error to JSONRPCException (MarcoFalke)
Pull request description:
It turns out there is no test currently to check that the RPC server does not time out under load. With "load" I mean a flood of trivial payloads. That is, the only work needed is JSON encoding and decoding of (let's say) a block of data of 2 MB or so. This may take a few milliseconds, but should never take more than a few seconds.
So add a test for this.
ACKs for top commit: enirox001: ACK https://github.com/bitcoin/bitcoin/pull/34927/changes/fa7bc26d1276581aac795daf8ceaea903cdcd7b3 sedited: ACK fa7bc26d1276581aac795daf8ceaea903cdcd7b3
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
merge-commit duplicate discount
Lower-priorityMerge bitcoin/bitcoin#35885: ci: switch to a sourceware mirror for riscvby merge-script · bd01e66f · Aug 6, 2026 · 2 filesMessage 81 · StrongTriage 0Details
Commit message · merge-script
Merge bitcoin/bitcoin#35885: ci: switch to a sourceware mirror for riscv
81fcecfe4525f2d57412f07390a139a2acf1c54e Revert "ci: Temporarily remove riscv32 config from GHA matrix" (will) b283e1751cc48b247d500cb5a642561d10651f16 ci: use mirror for riscv submodules (will)
Pull request description:
The https transport is rate-limited to block AI scrapers.
Switch to a live mirror on fish.foo to re-enable the riscv job.
ACKs for top commit: maflcko: lgtm ACK 81fcecfe4525f2d57412f07390a139a2acf1c54e sedited: ACK 81fcecfe4525f2d57412f07390a139a2acf1c54e
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Links an issue, advisory, or supporting reference
Why it was queued
merge-commit duplicate discount
AI analysis · Informational 15/100
This is a code cleanup change that turns on a static-analysis rule to prevent a specific C++ coding pattern (anonymous namespaces in header files) and updates two headers to comply. It does not change how Bitcoin Core behaves at runtime and does not fix an active security bug.