BC
← All projectsBitcoin Core

Bitcoin Core

The Bitcoin network's reference node and wallet implementation.

BitcoinSupply chainNormal
Repository coverage

3185 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

324security candidates671second-pass queue3015AI analyses
151commits · 30 days
334commits · 60 days
1279commits · 180 days
2840commits · 365 days
Backfill bands
Aug 5 → Feb 61351 seen45 candidatesComplete
Feb 6 → Jun 61033 seen63 candidatesComplete
Jun 6 → Jul 6281 seen11 candidatesComplete
Jul 6 → Aug 5207 seen5 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

71/100 average clarity
1190Strong · 80–100
1206Adequate · 60–79
701Thin · 40–59
88Opaque · 0–39
6security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
merge-script2084993389
Antoine Poinsot22422170
Ava Chow20369194069
MarcoFalke41421408074
fanquake23121228058
Lőrinc18121177081
Hennadii Stepanov22616211065
rkrux57957074
Sjors Provoost89889074
Sebastian Falbesoner33733073
David Gumberg55655072
Pieter Wuille95595066
Analysis record

Published AI watches

Last scanned 35 minutes ago

Moderate 60 AI analysisMessage 100 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35833: log: prevent user input from injecting fake log lines

This update fixes a way that people with limited access to a Bitcoin node could make fake log entries appear real. Normally, the node cleans up special characters in log messages but was leaving newlines alone. A clever user could slip a n…

Log injection / log forgery via embedded newlines in untrusted inputInput from restricted RPC users reaching log output without newline escapingControl-character escaping bypass due to explicit newline exception
d4b0e1e4by Ava Chow+48−114 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36391: test: fix typo in rpc_psbt

This commit fixes a one-word typo in a comment inside a test file. The comment incorrectly referred to 'walletcreatepsbt' when the surrounding test code actually calls 'walletcreatefundedpsbt'. No code behavior changes, and there is no sec…

4b612c6bby merge-script+1−11 file
No security note in commit
Informational 15 AI analysisMessage 82 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

test: fix typo in rpc_psbt

This commit fixes a typo in a comment within a test file. The comment incorrectly referred to 'walletcreatepsbt' when the surrounding test code actually exercises 'walletcreatefundedpsbt'. No code behavior changes, and there is no security…

0a8ffe90by Bruno Garcia+1−11 file
No security note in commit
Informational 15 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36377: doc: add 461 (Deterministic ECDSA signatures with low-R grinding) to bips.md

This commit is a documentation-only update. It adds a single line to Bitcoin Core's list of implemented BIPs, noting that BIP 461 (a technique for making ECDSA signatures smaller and deterministic) has been implemented since version 0.17.0…

e0f16ef9by merge-script+1−01 file
No security note in commit
Low 27 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36375: wallet: accept uppercase addresses without amount in sendall

This patch fixes a bug in Bitcoin Core's `sendall` wallet command. If a user typed a bech32 address in uppercase letters, the command would fail with a confusing 'below dust threshold' error instead of sending the funds. The fix compares d…

Functional bug in RPC command causing unexpected transaction failureCase-sensitivity mismatch between user input and canonical address encodingNo memory safety, cryptographic, or authorization issue evident
e7aef7e8by Ava Chow+22−52 files
No security note in commit
Informational 15 AI analysisMessage 100 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36381: test: avoid testing at the exact `-maxfeerate` boundary

This commit fixes a flaky automated test in Bitcoin Core. The test was checking the maximum transaction fee rate by creating a transaction at the exact boundary, which sometimes failed because the real transaction size could be slightly sm…

No production code changedTest-only changeNo memory safety, cryptography, consensus, or authorization changes
ba8fdb97by Ava Chow+1−11 file
No security note in commit
Informational 20 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36233: guix: Update time-machine to `60f6956aeffa7f30285745bd0ea615e9acfc74f8`

This is a build-system maintenance update for Bitcoin Core's reproducible build environment (Guix). It updates the Guix time-machine commit and several dependency versions, and temporarily disables some test suites that fail when building …

No direct security-relevant code change in Bitcoin Core consensus, wallet, or P2P layers.Dependency version bumps (git-minimal, linux-headers, python-lief, python-minimal) are routine build-environment updates.Disabling third-party package test suites reduces build-time test coverage but does not alter Bitcoin Core's own test or release binaries.
619185d5by merge-script+32−73 files
No security note in commit
Informational 15 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36364: tools: Call SHA256AutoDetect in bitcoin-util, bitcoin-tx and bitcoin-wallet

This change makes three Bitcoin command-line tools (bitcoin-tx, bitcoin-util, and bitcoin-wallet) automatically pick the fastest SHA-256 hashing implementation available on the computer, such as hardware-accelerated versions on modern CPUs…

dc2a9987by merge-script+6−03 files
No security note in commit
Informational 23 AI analysisMessage 98 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36321: net: cast vector size to avoid overflow, truncation, sign change

This is a one-line fix in Bitcoin Core's network code. It changes how the size of a list of block headers is converted to a signed integer inside a loop. Previously, if the list was empty, the conversion could trigger undefined-behavior wa…

UndefinedBehaviorSanitizer integer sanitizer warning addressedImplicit signed/unsigned conversion in loop counterUnsigned integer wraparound on empty vector size
ced4c6e6by merge-script+1−11 file
No security note in commit
Low 32 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#34371: wallet: allow importprunedfunds for spending transactions

This change fixes a Bitcoin Core wallet bug where the `importprunedfunds` RPC command could only re-import transactions that sent money to the wallet, not transactions that spent money from it. After this fix, both incoming and outgoing tr…

Logic bug in wallet transaction import scopeIncorrect balance possible after removing and re-importing spending transactionFix routes import through existing involvement check (IsMine + IsFromMe)
ed7dd7cfby Ava Chow+36−203 files
No security note in commit
Low 28 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#29278: Wallet: Add `maxfeerate` wallet startup option

This commit adds a new Bitcoin Core wallet startup option called -maxfeerate. It lets users set a maximum fee rate (fee per unit of transaction size) that the wallet will allow when creating or broadcasting transactions. Previously, the wa…

New wallet startup option -maxfeerate to cap transaction fee rateNew transaction error type MAX_FEE_RATE_EXCEEDEDBroadcastTransaction now checks both max absolute fee and max fee rate
f80aaf4bby Ava Chow+303−7930 files
No security note in commit
Moderate 64 AI analysisMessage 86 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35984: sign: skip signing SIGHASH_SINGLE inputs with no corresponding output

This Bitcoin Core update fixes a wallet-signing quirk. When a user chose the SIGHASH_SINGLE signature mode, an input that had no matching output index would sign essentially nothing meaningful. That signature could then stay valid even if …

Funds-redirection footgun from SIGHASH_SINGLE signatures with no committed outputInconsistent guard between SignTransaction and SignPSBTInput pathsFix centralizes the guard in the low-level signature creator to cover future signing paths
e19f83e9by Ava Chow+37−82 files
Vendor flagged security relevance
Low 35 AI analysisMessage 86 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35696: i2p: update leaseset encryption types

This change updates Bitcoin Core's I2P (Invisible Internet Project) privacy network settings to use newer, stronger encryption for the published 'leaseset' that describes how other peers can contact a node. The old setting included ElGamal…

Cryptographic algorithm update (ElGamal to MLKEM-768)Use of I2P 'legacy' encryption type removedConfiguration-only change in network privacy layer
65e075f8by Ava Chow+2−21 file
No security note in commit
Informational 15 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35948: init: correct first-run disk space estimate

This change fixes a labeling bug in Bitcoin Core's first-run disk-space warning. The estimate was stored in GiB (binary gigabytes, 1024-based) but displayed as GB (decimal gigabytes, 1000-based), and for pruned nodes it showed the full-cha…

d26f19c7by Ava Chow+5−42 files
No security note in commit
Low 44 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36284: wallet: don't double discard output groups with avoidpartialspends

This is a wallet bug, not a theft or remote-code bug. When a Bitcoin Core user turns on the optional 'avoidpartialspends' or 'avoid_reuse' setting, an output group rejected during coin selection could be counted twice as 'discarded.' That …

Logic error causing double-counting of discarded UTXO groupsCan trigger false 'insufficient funds' failure in coin selectionAffects avoidpartialspends / avoid_reuse wallets only
e8e7e91aby Ava Chow+43−14 files
No security note in commit
Informational 18 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35890: doc: use overwrite (>) instead of append (>>) for one-shot PSBT files in offline-signing-tutorial.md

This is a documentation-only fix in a tutorial file. It changes two shell examples from using '>>' (append to file) to '>' (overwrite file). If a user followed the old instructions and ran the same command twice, the file would contain two…

No security signal: change is limited to documentationNo code changes to Bitcoin Core binaries, RPC, wallet, or consensus logicNo cryptographic, network, or privilege-boundary implications
bfdcd979by merge-script+2−21 file
No security note in commit
Informational 19 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35675: mining: add block template manager

This is a large internal code reorganization (refactor) in Bitcoin Core. It creates a new BlockTemplateManager class that takes over block-template creation, block submission, and tip-waiting helpers that were previously spread across seve…

Large refactor touching mining, RPC, interfaces, and test shutdown pathsNew object lifetime dependency: BlockTemplateManager holds references to mempool, chainman, and notifications; explicit reset ordering added in Shutdown/InitAndLoadChainstate/test setupsRemoval of early-init node.mining interface; BlockTemplateManager is now created after chainstate load, with a comment that it must exist before setChainstateLoaded(true) unblocks IPC waiters
5c726f20by Ryan Ofsky+561−44926 files
No security note in commit
Informational 12 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35301: Silent Payments: Implement bip352 (take 2)

This commit adds the first implementation of BIP352 (Silent Payments) to Bitcoin Core. Silent Payments are a new type of privacy-preserving Bitcoin address that lets someone receive payments without publicly revealing a fixed address. The …

New cryptographic feature implementation (BIP352 Silent Payments)Extensive use of secp256k1 silentpayments moduleInput public key extraction from P2PKH, P2WPKH, P2SH-P2WPKH, and P2TR inputs
be5d0b55by Ava Chow+6951−010 files
No security note in commit
Low 45 AI analysisMessage 96 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35440: wallet: check descriptor cache xpub length before decoding

This update fixes a wallet database loading bug where a damaged or tampered Bitcoin wallet file could cause the program to read past the end of a stored extended public key (xpub). The patch makes the loader check the stored xpub length be…

Out-of-bounds read in wallet descriptor cache deserializationASan container-overflow triggered by malformed on-disk recordMissing length validation between record size prefix and fixed-size decoder
b3f846ecby Ava Chow+225−8511 files
Vendor flagged security relevance
Informational 20 AI analysisMessage 100 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35813: wallet, rpc: Add listrawtransactions RPC

This commit adds a new wallet RPC called listrawtransactions to Bitcoin Core. It is a feature addition that lets users list every transaction their wallet knows about, including internal transfers and consolidations that the existing listt…

No security-relevant bug fix or vulnerability patch is present in the diff.New RPC exposes additional wallet transaction metadata, but only to callers already authorized for wallet RPCs.Code is a refactor of existing gettransaction logic into shared helpers; no new cryptographic, network, or consensus code.
2b95b45aby Ava Chow+334−276 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Lower-prioritypolicy: remove incorrect MANDATORY_SCRIPT_VERIFY_FLAGS commentby ismaelsadeeq · 5fa68988 · Mar 30, 2026 · 1 fileMessage 73 · AdequateInformational 15Details
Commit message · ismaelsadeeq

policy: remove incorrect MANDATORY_SCRIPT_VERIFY_FLAGS comment

The claim that failing mandatory script checks may trigger a DoS ban
is incorrect; Bitcoin Core does not automatically ban peers for
violating any of these flag checks.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 15/100

This commit only removes a misleading comment in the source code. It does not change any actual code behavior. The old comment incorrectly stated that failing certain script checks could cause a peer to be banned from the network. The commit corrects that documentation-only mistake. There is no security vulnerability being fixed here.

Lower-prioritydepends, qt: Fix build on aarch64 macOS 26.4by Hennadii Stepanov · 3aeccb7d · Mar 30, 2026 · 3 filesMessage 45 · ThinInformational 15Details
Commit message · Hennadii Stepanov

depends, qt: Fix build on aarch64 macOS 26.4

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100

This commit fixes a build problem when compiling Bitcoin Core's bundled Qt library on Apple Silicon Macs using a future macOS 26.4 software development kit. It changes the order in which the compiler checks for a low-level CPU 'yield' instruction so that the correct built-in function is chosen, avoiding an 'implicit function declaration' compiler error. There is no runtime security issue here; it is purely a compilation fix.

Lower-priorityguix: Clean up module list in manifestby Hennadii Stepanov · 325f743e · Mar 30, 2026 · 1 fileMessage 76 · AdequateInformational 15Details
Commit message · Hennadii Stepanov

guix: Clean up module list in manifest

These modules are no longer in use:
1. `cmake-build-system` since bitcoin/bitcoin#34550.
2. `gnu-build-system` since bitcoin/bitcoin#34627.
3. `download` since bitcoin/bitcoin#34550.
4. `cc-for-target` from `utils` since bitcoin/bitcoin#34627.

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
AI analysis · Informational 15/100

This commit removes unused software-building helper imports from a Guix packaging manifest. It is a routine cleanup with no security relevance.

Lower-priorityrefactor: Return std::optional from ParseDoubleby MarcoFalke · fabab69e · Mar 30, 2026 · 1 fileMessage 57 · ThinInformational 15Details
Commit message · MarcoFalke

refactor: Return std::optional from ParseDouble

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
AI analysis · Informational 15/100

This commit is a straightforward internal code cleanup: it changes the ParseDouble helper function to return a C++ std::optional<double> instead of writing a result through a pointer and returning a boolean success flag. The behavior of parsing JSON numbers remains the same, and no security issue is present.

AI review queuedrefactor: Return std::optional from GetWalletNameFromJSONRPCRequestby MarcoFalke · fa0a0944 · Mar 30, 2026 · 2 filesMessage 62 · AdequateInformational 15Details
Commit message · MarcoFalke

refactor: Return std::optional from GetWalletNameFromJSONRPCRequest

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a straightforward internal code cleanup. It changes one helper function so that it returns a wallet name directly (using std::optional) instead of writing it into a caller-provided variable and returning true/false. There is no change to user-visible behavior, no bug fix, and no security relevance.

Lower-priorityrefactor: Return std::optional from GetLogCategoryby MarcoFalke · fafb0c4c · Mar 30, 2026 · 3 filesMessage 62 · AdequateInformational 15Details
Commit message · MarcoFalke

refactor: Return std::optional from GetLogCategory

62/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
AI analysis · Informational 15/100

This is a clean internal code refactor: a helper function that looks up a log category by name now returns an optional value instead of writing to an output parameter. No behavior changes, no security implications.

Security candidatefuzz: Use CAmount for storing best_wasteby Ava Chow · 890a09b1 · Mar 28, 2026 · 1 fileMessage 75 · AdequateInformational 17Details
Commit message · Ava Chow

fuzz: Use CAmount for storing best_waste

Waste is a CAmount, which is an int64_t. This will overflow an int, so
`best_waste` should also be a `CAmount`.

75/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Mentions testing or verification✓ Names security-relevant behavior explicitly
Why it was queued
memory safetyfuzzing or regression evidencesigning or wallet path
AI analysis · Informational 17/100

This is a one-line fix in a fuzz test (automated randomized test) for Bitcoin Core's coin selection logic. It changes a variable that tracks the 'best waste' amount from a 32-bit signed integer to a 64-bit signed integer type, matching the actual CAmount type. The change prevents a possible integer overflow inside the fuzz test itself, not in the production wallet code that handles real Bitcoin transactions. It does not appear to be a security vulnerability in live Bitcoin Core software.

Lower-prioritytest: Remove unused, confusing and brittle connect_nodes.wait_for_connectby MarcoFalke · fae807ed · Mar 27, 2026 · 1 fileMessage 100 · StrongInformational 15Details
Commit message · MarcoFalke

test: Remove unused, confusing and brittle connect_nodes.wait_for_connect

The option is unused since the last removals in:
* 4c40a923f003420193aa574745f70788bcf35265, and
* 81bf3ebff7e7108bbfbf6fe4e122f4e52f278701

It was brittle and lead to intermittent test issues. Generally, it is
also confusing, because if a test wanted to connect nodes without
checking their connection, it can use `addnode`, like the rpc_setban.py
test.

So fix all issues by removing it.

100/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification
AI analysis · Informational 15/100

This commit removes an unused optional flag from a test helper function in Bitcoin Core's internal testing framework. It only affects test code, not the live Bitcoin network or wallet software, and has no security relevance.

Lower-prioritytest: Fix all races after a socket is closed gracefullyby MarcoFalke · fab27726 · Mar 27, 2026 · 1 fileMessage 95 · StrongInformational 15Details
Commit message · MarcoFalke

test: Fix all races after a socket is closed gracefully

This waits for any disconnect (e.g. from a restart of one of the nodes)
to fully happen before the next connect.

Can be reviewed with the git option:

--color-moved=dimmed-zebra

95/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
AI analysis · Informational 15/100

This change only touches Bitcoin Core's internal Python test framework. It makes a test helper wait for an old peer connection to fully disappear before creating a new one, reducing flaky test failures. It does not change the actual Bitcoin node software that users run, so it has no direct security impact on the network or on users.

Lower-prioritytest: Stricter checks in rpc_setban.pyby MarcoFalke · fa21eddd · Mar 27, 2026 · 1 fileMessage 100 · StrongInformational 14Details
Commit message · MarcoFalke

test: Stricter checks in rpc_setban.py

Make the checks stricter and easier to follow:
* Fix a typo.
* After the first ban from node 1 wait until node 0 "sees" the ban.
* Move the restart_node out of the debug log context, to avoid bloat.
* Removed the timeout from the outer/lower exit stack to check "dropped
(banned)\n" on node 1, because the inner/top exit stack waits longer.
* The inner/top exit stack checks for the both disconnections peer=2 and
possibly peer=3 (for v2->v1 retry).
* And finally, add a redundant assert to confirm once more that node 0
is has "seen" the ban.

100/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification
AI analysis · Informational 14/100

This commit only changes a test file that exercises the setban RPC. It makes the existing test stricter and easier to read by fixing a typo, adding waits for disconnections, moving a node restart outside a debug-log context, and adding an extra assertion. There is no change to production code, so it does not introduce or fix a security vulnerability in Bitcoin Core itself.

Lower-prioritytest: Add is_connected_to helperby MarcoFalke · faa404e1 · Mar 27, 2026 · 1 fileMessage 72 · AdequateInformational 15Details
Commit message · MarcoFalke

test: Add is_connected_to helper

Needed in the next commit.

Co-Authored-By: David Gumberg <davidzgumberg@gmail.com>

72/100 · AdequateMessage clarity
✓ Descriptive subject✓ Uses a recognizable type or scope✓ Provides an explanatory body✓ Mentions testing or verification
AI analysis · Informational 15/100

This commit adds a small helper function to Bitcoin Core's internal test framework. It lets one test node check whether it is connected to another test node by comparing their network version strings. There is no change to the actual Bitcoin Core software that users run, and no security issue is visible in the code.

Security candidateSquashed 'src/ipc/libmultiprocess/' changes from 1868a84451f..70f632bda8fby Ryan Ofsky · 2478a15e · Mar 27, 2026 · 28 filesMessage 91 · StrongModerate 59Details
Commit message · Ryan Ofsky

Squashed 'src/ipc/libmultiprocess/' changes from 1868a84451f..70f632bda8f

70f632bda8f Merge bitcoin-core/libmultiprocess#265: ci: set LC_ALL in shell scripts
8e8e564259a Merge bitcoin-core/libmultiprocess#249: fixes for race conditions on disconnects
05d34cc2ec3 ci: set LC_ALL in shell scripts
e606fd84a8c Merge bitcoin-core/libmultiprocess#264: ci: reduce nproc multipliers
ff0eed1bf18 refactor: Use loop variable in type-context.h
ff1d8ba172a refactor: Move type-context.h getParams() call closer to use
1dbc59a4aa3 race fix: m_on_cancel called after request finishes
1643d05ba07 test: m_on_cancel called after request finishes
f5509a31fcc race fix: getParams() called after request cancel
4a60c39f24a test: getParams() called after request cancel
f11ec29ed20 race fix: worker thread destroyed before it is initialized
a1d643348f4 test: worker thread destroyed before it is initialized
336023382c4 ci: reduce nproc multipliers
b090beb9651 Merge bitcoin-core/libmultiprocess#256: ci: cache gnu32 nix store
be8622816da ci: cache gnu32 nix store
975270b619c Merge bitcoin-core/libmultiprocess#263: ci: bump timeout factor to 40
09f10e5a598 ci: bump timeout factor to 40
db8f76ad290 Merge bitcoin-core/libmultiprocess#253: ci: run some Bitcoin Core CI jobs
55a9b557b19 ci: set Bitcoin Core CI test repetition
fb0fc84d556 ci: add TSan job with instrumented libc++
0f29c38725b ci: add Bitcoin Core IPC tests (ASan + macOS)
3f64320315d Merge bitcoin-core/libmultiprocess#262: ci: enable clang-tidy in macOS job, use nullptr
cd9f8bdc9f0 Merge bitcoin-core/libmultiprocess#258: log: add socket connected info message and demote destroy logs to debug
b5d6258a42f Merge bitcoin-core/libmultiprocess#255: fix: use unsigned char cast and sizeof in LogEscape escape sequence
d94688e2c32 Merge bitcoin-core/libmultiprocess#251: Improved CustomBuildField for std::optional in IPC/libmultiprocess
a9499fad755 mp: use nullptr with pthread_threadid_np
f499e37850f ci: enable clang-tidy in macOS job
98f1352159d log: add socket connected info message and demote destroy logs to debug
554a481ea73 fix: use unsigned char cast and sizeof in LogEscape escape sequence
1977b9f3f65 Use std::forward in CustomBuildField for std::optional to allow move semantics, resolves FIXME
22bec918c97 Merge bitcoin-core/libmultiprocess#247: type-map: Work around LLVM 22 "out of bounds index" error
8a5e3ae6ed2 Merge bitcoin-core/libmultiprocess#242: proxy-types: add CustomHasField hook to map Cap'n Proto values to null C++ values
e8d35246918 Merge bitcoin-core/libmultiprocess#246: doc: Bump version 8 > 9
97d877053b6 proxy-types: add CustomHasField hook for nullable decode paths
8c2f10252c9 refactor: add missing includes to mp/type-data.h
b1638aceb40 doc: Bump version 8 > 9
f61af487217 type-map: Work around LLVM 22 "out of bounds index" error

git-subtree-dir: src/ipc/libmultiprocess
git-subtree-split: 70f632bda8f80449b6240f98da768206a535a04e

91/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
memory safety
AI analysis · Moderate 59/100

This commit updates the libmultiprocess library inside Bitcoin Core. The most important changes are fixes for three race-condition bugs that could crash or destabilize the inter-process communication (IPC) layer when a connection is disconnected while worker threads are starting, running, or finishing. The commit also adds a new way to represent null data values in IPC messages, improves build/CI scripts, and bumps the library version. The race fixes are defensive hardening rather than obviously exploitable vulnerabilities, but they remove real crash paths that could be triggered by an attacker able to disconnect an IPC session at the right moment.

Lower-priorityrefactor: Use NodeClock::duration for m_last_ping_time/m_min_ping_time/m_ping_waitby MarcoFalke · fa644e62 · Mar 27, 2026 · 6 filesMessage 97 · StrongInformational 15Details
Commit message · MarcoFalke

refactor: Use NodeClock::duration for m_last_ping_time/m_min_ping_time/m_ping_wait

This refactor does not change any behavior and is needed for a future
commit, to avoid having to add duration casts.

It also improves the docs to better document that this is not a time
point, but a duration.

Also, it uses decltype to explain where the _::max() is coming from.

97/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Explains rationale or failure mode
AI analysis · Informational 15/100

This is a pure code cleanup (refactor) that renames the type used for ping timing variables from std::chrono::microseconds to NodeClock::duration. The commit message explicitly states it does not change behavior, and the diff shows only type aliases and documentation updates. There is no security issue here.

Lower-prioritydoc: Fix typo "eviction criterium" -> "eviction criterion"by MarcoFalke · 333316f6 · Mar 27, 2026 · 1 fileMessage 65 · AdequateInformational 15Details
Commit message · MarcoFalke

doc: Fix typo "eviction criterium" -> "eviction criterion"

Also, clarify round-trip time to mean round-trip duration.

65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
AI analysis · Informational 15/100

This commit only fixes spelling and wording in code comments. It changes 'criterium' to 'criterion' and rephrases 'round-trip time' to 'round-trip duration' in documentation-style comments. No program logic, behavior, or security properties are changed.

Lower-priorityrefactor: gui: Accept up to nanoseconds in formatDurationStr, but clarify they are ignoredby MarcoFalke · fa54fb01 · Mar 27, 2026 · 2 filesMessage 97 · StrongInformational 15Details
Commit message · MarcoFalke

refactor: gui: Accept up to nanoseconds in formatDurationStr, but clarify they are ignored

This refactor does not change any behavior. However, it helps future
commits to avoid having to place manual
std::chrono::duration_cast<std::chrono::seconds> when calling this
function.

97/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Explains rationale or failure mode
AI analysis · Informational 15/100

This is a minor code cleanup in Bitcoin Core's graphical user interface. A helper function that turns a time duration into human-readable text now accepts a more precise input type (nanoseconds) but still behaves exactly the same way it did before—any fractional seconds are still ignored. There is no security issue here.

Lower-priorityrefactor: Avoid manual chrono casts with * or /by MarcoFalke · fab88884 · Mar 27, 2026 · 2 filesMessage 80 · StrongInformational 15Details
Commit message · MarcoFalke

refactor: Avoid manual chrono casts with * or /

Manual chrono casts, using multiplication or division is confusing and
brittle.

Also, when calling ShouldRunInactivityChecks remove a confusing and
useless std::chrono::duration_cast<std::chrono::seconds>.

80/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
AI analysis · Informational 15/100

This is a small code cleanup that replaces hand-written time-unit conversions with safer, purpose-built helper functions. It does not change program behavior or fix any security issue.

Lower-priorityutil: Add NodeClock::epoch aliasby MarcoFalke · facfce37 · Mar 27, 2026 · 2 filesMessage 68 · AdequateInformational 15Details
Commit message · MarcoFalke

util: Add NodeClock::epoch alias

A default constructed time_point is the epoch, by definition.

Existing code uses a default constructed (or explicitly constructed with
a zero duration) chrono type to mean epoch. New code can now use
NodeClock::epoch as an alias.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 15/100

This commit is a minor code cleanup with no security relevance. It adds a named alias 'NodeClock::epoch' for the zero time point and a compile-time check that it equals zero. No behavior changes, no bug fixes, and no security impact.

Lower-priorityrefactor: Use NodeClock alias over deprecated GetTimeby MarcoFalke · fa41e072 · Mar 27, 2026 · 1 fileMessage 85 · StrongInformational 15Details
Commit message · MarcoFalke

refactor: Use NodeClock alias over deprecated GetTime

GetTime returns a duration, but a time point is the correct type to use
here.

This refactor does not change any behavior.

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
AI analysis · Informational 15/100

This is a one-line code cleanup in Bitcoin Core. It replaces an older way of getting the current time with a newer, type-correct equivalent. The commit message explicitly says it does not change behavior, and the diff shows only that single replacement with no logic changes.

Lower-prioritytest: Check that RPCs do not time out, even under loadby MarcoFalke · fa7bc26d · Mar 26, 2026 · 2 filesMessage 99 · StrongTriage 0Details
Commit message · MarcoFalke

test: Check that RPCs do not time out, even under load

Also, modify send_cli, so that the test can be run under --usecli

99/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body✓ Explains rationale or failure mode✓ Mentions testing or verification
Lower-prioritytest: Replace DEBUG_LOG_OUT with -printtoconsole=1by Hodlinator · 261d2294 · Mar 26, 2026 · 7 filesMessage 72 · AdequateInformational 15Details
Commit message · Hodlinator

test: Replace DEBUG_LOG_OUT with -printtoconsole=1

72/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
AI analysis · Informational 15/100

This commit is a test-only cleanup. It removes a custom test logging hook called DEBUG_LOG_OUT and replaces it with Bitcoin Core's existing -printtoconsole=1 command-line option. There is no change to the production wallet, networking, consensus, or node code that ordinary users run.

AI review queuedtest: wallet: Warning for excessive fallback fee.by David Gumberg · 3dcdb2b9 · Mar 26, 2026 · 1 fileMessage 67 · AdequateInformational 15Details
Commit message · David Gumberg

test: wallet: Warning for excessive fallback fee.

67/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only adds a new test case to Bitcoin Core's functional test suite. It checks that when a user starts the software with an unusually high fallback transaction fee, the software still works but prints a warning message. There is no code change to the actual Bitcoin Core wallet or fee logic—only a test that verifies existing behavior.

AI review queuedtest: wallet: -fallbackfee default is 0by David Gumberg · 6664e41e · Mar 26, 2026 · 1 fileMessage 82 · StrongInformational 15Details
Commit message · David Gumberg

test: wallet: -fallbackfee default is 0

Also check more RPC's for success and check that we are using
`-fallbackfee`.

82/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body✓ Mentions testing or verification
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only changes a test file. It improves an existing functional test to verify that Bitcoin Core's wallet correctly fails to send transactions when the fallback fee is unset or set to zero, and succeeds when a fallback fee is configured. There is no change to production code, no security fix, and no vulnerability being patched.

AI review queuedtest: wallet: refactor: fallbackfee extract common send failure checks.by David Gumberg · d28c9892 · Mar 26, 2026 · 1 fileMessage 72 · AdequateInformational 15Details
Commit message · David Gumberg

test: wallet: refactor: fallbackfee extract common send failure checks.

72/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This is a minor test-code cleanup. It renames a test class to match the actual topic (fallback fee), shortens a comment, and pulls three repeated 'sending must fail' checks into a helper function. No production code or security behavior is changed.

Lower-priorityfuzz: Use time helpers in node_evictionby MarcoFalke · fa1ebde1 · Mar 25, 2026 · 4 filesMessage 55 · ThinInformational 15Details
Commit message · MarcoFalke

fuzz: Use time helpers in node_eviction

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
fuzzing or regression evidence
AI analysis · Informational 15/100

This commit only changes Bitcoin Core's internal fuzz testing code, which is used to automatically generate random inputs to find bugs during development. It does not change any production networking, consensus, or wallet code that runs on real Bitcoin nodes. There is no security issue here for end users.

Lower-prioritynet: delay stale evaluation and expose time_added in private broadcastby Mccalabrese · 325afe66 · Mar 25, 2026 · 5 filesMessage 50 · ThinLow 27Details
Commit message · Mccalabrese

net: delay stale evaluation and expose time_added in private broadcast

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Low 27/100

This Bitcoin Core commit tweaks how the node decides whether a privately broadcast transaction is 'stale' and should be re-broadcast. Previously, a transaction could be marked stale just one minute after it was added, even if it had never actually been sent to any peer. Now, transactions that have not yet been picked for sending use a longer five-minute window, while already-sent transactions keep the one-minute window. The commit also exposes the 'time_added' field in an RPC diagnostic so users can see when each transaction entered the private-broadcast queue. There is no claim in the commit that this fixes a security vulnerability; it reads as a robustness/usability improvement.