BC
← All projectsBitcoin Core

Bitcoin Core

The Bitcoin network's reference node and wallet implementation.

BitcoinSupply chainNormal
Repository coverage

3194 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

325security candidates672second-pass queue3017AI analyses
152commits · 30 days
322commits · 60 days
1286commits · 180 days
2834commits · 365 days
Backfill bands
Aug 5 → Feb 61351 seen45 candidatesComplete
Feb 6 → Jun 61033 seen63 candidatesComplete
Jun 6 → Jul 6281 seen11 candidatesComplete
Jul 6 → Aug 5207 seen5 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

71/100 average clarity
1198Strong · 80–100
1206Adequate · 60–79
702Thin · 40–59
88Opaque · 0–39
6security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
merge-script2105094389
Antoine Poinsot22422170
Ava Chow20669195070
MarcoFalke41421408074
fanquake23321228058
Lőrinc18121177081
Hennadii Stepanov22816211065
rkrux57957074
Sjors Provoost89889074
Sebastian Falbesoner33733073
David Gumberg55655072
Pieter Wuille95595066
Analysis record

Published AI watches

Last scanned 25 minutes ago

Low 38 AI analysisMessage 100 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36299: cli: Improve empty-response and fix -rpcclienttimeout regression

This update fixes two bugs in bitcoin-cli, the command-line tool used to talk to a Bitcoin node. First, when a server replied with an empty body but said it was intentionally empty (Content-Length: 0), the client would keep waiting instead…

Client-side hang on empty HTTP body (denial-of-service against bitcoin-cli user)Timeout regression could abort legitimate slow RPC responsesFix distinguishes Content-Length: 0 from absent Content-Length
dd809d2cby Ava Chow+41−232 files
No security note in commit
Informational 15 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36052: ci: Doc: Move all config comments right next to the option they explain

This commit is a documentation and code-style cleanup for Bitcoin Core's continuous integration (CI) scripts. It changes how build configuration strings are formatted in shell scripts so comments can sit next to the options they describe, …

9f059527by merge-script+100−9826 files
No security note in commit
Moderate 60 AI analysisMessage 100 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35833: log: prevent user input from injecting fake log lines

This update fixes a way that people with limited access to a Bitcoin node could make fake log entries appear real. Normally, the node cleans up special characters in log messages but was leaving newlines alone. A clever user could slip a n…

Log injection / log forgery via embedded newlines in untrusted inputInput from restricted RPC users reaching log output without newline escapingControl-character escaping bypass due to explicit newline exception
d4b0e1e4by Ava Chow+48−114 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36391: test: fix typo in rpc_psbt

This commit fixes a one-word typo in a comment inside a test file. The comment incorrectly referred to 'walletcreatepsbt' when the surrounding test code actually calls 'walletcreatefundedpsbt'. No code behavior changes, and there is no sec…

4b612c6bby merge-script+1−11 file
No security note in commit
Informational 15 AI analysisMessage 82 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

test: fix typo in rpc_psbt

This commit fixes a typo in a comment within a test file. The comment incorrectly referred to 'walletcreatepsbt' when the surrounding test code actually exercises 'walletcreatefundedpsbt'. No code behavior changes, and there is no security…

0a8ffe90by Bruno Garcia+1−11 file
No security note in commit
Informational 15 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36377: doc: add 461 (Deterministic ECDSA signatures with low-R grinding) to bips.md

This commit is a documentation-only update. It adds a single line to Bitcoin Core's list of implemented BIPs, noting that BIP 461 (a technique for making ECDSA signatures smaller and deterministic) has been implemented since version 0.17.0…

e0f16ef9by merge-script+1−01 file
No security note in commit
Low 27 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36375: wallet: accept uppercase addresses without amount in sendall

This patch fixes a bug in Bitcoin Core's `sendall` wallet command. If a user typed a bech32 address in uppercase letters, the command would fail with a confusing 'below dust threshold' error instead of sending the funds. The fix compares d…

Functional bug in RPC command causing unexpected transaction failureCase-sensitivity mismatch between user input and canonical address encodingNo memory safety, cryptographic, or authorization issue evident
e7aef7e8by Ava Chow+22−52 files
No security note in commit
Informational 15 AI analysisMessage 100 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36381: test: avoid testing at the exact `-maxfeerate` boundary

This commit fixes a flaky automated test in Bitcoin Core. The test was checking the maximum transaction fee rate by creating a transaction at the exact boundary, which sometimes failed because the real transaction size could be slightly sm…

No production code changedTest-only changeNo memory safety, cryptography, consensus, or authorization changes
ba8fdb97by Ava Chow+1−11 file
No security note in commit
Informational 20 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36233: guix: Update time-machine to `60f6956aeffa7f30285745bd0ea615e9acfc74f8`

This is a build-system maintenance update for Bitcoin Core's reproducible build environment (Guix). It updates the Guix time-machine commit and several dependency versions, and temporarily disables some test suites that fail when building …

No direct security-relevant code change in Bitcoin Core consensus, wallet, or P2P layers.Dependency version bumps (git-minimal, linux-headers, python-lief, python-minimal) are routine build-environment updates.Disabling third-party package test suites reduces build-time test coverage but does not alter Bitcoin Core's own test or release binaries.
619185d5by merge-script+32−73 files
No security note in commit
Informational 15 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36364: tools: Call SHA256AutoDetect in bitcoin-util, bitcoin-tx and bitcoin-wallet

This change makes three Bitcoin command-line tools (bitcoin-tx, bitcoin-util, and bitcoin-wallet) automatically pick the fastest SHA-256 hashing implementation available on the computer, such as hardware-accelerated versions on modern CPUs…

dc2a9987by merge-script+6−03 files
No security note in commit
Informational 23 AI analysisMessage 98 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36321: net: cast vector size to avoid overflow, truncation, sign change

This is a one-line fix in Bitcoin Core's network code. It changes how the size of a list of block headers is converted to a signed integer inside a loop. Previously, if the list was empty, the conversion could trigger undefined-behavior wa…

UndefinedBehaviorSanitizer integer sanitizer warning addressedImplicit signed/unsigned conversion in loop counterUnsigned integer wraparound on empty vector size
ced4c6e6by merge-script+1−11 file
No security note in commit
Low 32 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#34371: wallet: allow importprunedfunds for spending transactions

This change fixes a Bitcoin Core wallet bug where the `importprunedfunds` RPC command could only re-import transactions that sent money to the wallet, not transactions that spent money from it. After this fix, both incoming and outgoing tr…

Logic bug in wallet transaction import scopeIncorrect balance possible after removing and re-importing spending transactionFix routes import through existing involvement check (IsMine + IsFromMe)
ed7dd7cfby Ava Chow+36−203 files
No security note in commit
Low 28 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#29278: Wallet: Add `maxfeerate` wallet startup option

This commit adds a new Bitcoin Core wallet startup option called -maxfeerate. It lets users set a maximum fee rate (fee per unit of transaction size) that the wallet will allow when creating or broadcasting transactions. Previously, the wa…

New wallet startup option -maxfeerate to cap transaction fee rateNew transaction error type MAX_FEE_RATE_EXCEEDEDBroadcastTransaction now checks both max absolute fee and max fee rate
f80aaf4bby Ava Chow+303−7930 files
No security note in commit
Moderate 64 AI analysisMessage 86 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35984: sign: skip signing SIGHASH_SINGLE inputs with no corresponding output

This Bitcoin Core update fixes a wallet-signing quirk. When a user chose the SIGHASH_SINGLE signature mode, an input that had no matching output index would sign essentially nothing meaningful. That signature could then stay valid even if …

Funds-redirection footgun from SIGHASH_SINGLE signatures with no committed outputInconsistent guard between SignTransaction and SignPSBTInput pathsFix centralizes the guard in the low-level signature creator to cover future signing paths
e19f83e9by Ava Chow+37−82 files
Vendor flagged security relevance
Low 35 AI analysisMessage 86 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35696: i2p: update leaseset encryption types

This change updates Bitcoin Core's I2P (Invisible Internet Project) privacy network settings to use newer, stronger encryption for the published 'leaseset' that describes how other peers can contact a node. The old setting included ElGamal…

Cryptographic algorithm update (ElGamal to MLKEM-768)Use of I2P 'legacy' encryption type removedConfiguration-only change in network privacy layer
65e075f8by Ava Chow+2−21 file
No security note in commit
Informational 15 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35948: init: correct first-run disk space estimate

This change fixes a labeling bug in Bitcoin Core's first-run disk-space warning. The estimate was stored in GiB (binary gigabytes, 1024-based) but displayed as GB (decimal gigabytes, 1000-based), and for pruned nodes it showed the full-cha…

d26f19c7by Ava Chow+5−42 files
No security note in commit
Low 44 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36284: wallet: don't double discard output groups with avoidpartialspends

This is a wallet bug, not a theft or remote-code bug. When a Bitcoin Core user turns on the optional 'avoidpartialspends' or 'avoid_reuse' setting, an output group rejected during coin selection could be counted twice as 'discarded.' That …

Logic error causing double-counting of discarded UTXO groupsCan trigger false 'insufficient funds' failure in coin selectionAffects avoidpartialspends / avoid_reuse wallets only
e8e7e91aby Ava Chow+43−14 files
No security note in commit
Informational 18 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35890: doc: use overwrite (>) instead of append (>>) for one-shot PSBT files in offline-signing-tutorial.md

This is a documentation-only fix in a tutorial file. It changes two shell examples from using '>>' (append to file) to '>' (overwrite file). If a user followed the old instructions and ran the same command twice, the file would contain two…

No security signal: change is limited to documentationNo code changes to Bitcoin Core binaries, RPC, wallet, or consensus logicNo cryptographic, network, or privilege-boundary implications
bfdcd979by merge-script+2−21 file
No security note in commit
Informational 19 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35675: mining: add block template manager

This is a large internal code reorganization (refactor) in Bitcoin Core. It creates a new BlockTemplateManager class that takes over block-template creation, block submission, and tip-waiting helpers that were previously spread across seve…

Large refactor touching mining, RPC, interfaces, and test shutdown pathsNew object lifetime dependency: BlockTemplateManager holds references to mempool, chainman, and notifications; explicit reset ordering added in Shutdown/InitAndLoadChainstate/test setupsRemoval of early-init node.mining interface; BlockTemplateManager is now created after chainstate load, with a comment that it must exist before setChainstateLoaded(true) unblocks IPC waiters
5c726f20by Ryan Ofsky+561−44926 files
No security note in commit
Informational 12 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35301: Silent Payments: Implement bip352 (take 2)

This commit adds the first implementation of BIP352 (Silent Payments) to Bitcoin Core. Silent Payments are a new type of privacy-preserving Bitcoin address that lets someone receive payments without publicly revealing a fixed address. The …

New cryptographic feature implementation (BIP352 Silent Payments)Extensive use of secp256k1 silentpayments moduleInput public key extraction from P2PKH, P2WPKH, P2SH-P2WPKH, and P2TR inputs
be5d0b55by Ava Chow+6951−010 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Lower-prioritythreadpool: active-wait during shutdownby furszy · bf2c607a · Feb 26, 2026 · 1 fileMessage 68 · AdequateInformational 18Details
Commit message · furszy

threadpool: active-wait during shutdown

Instead of waiting for the workers to finish processing tasks, help
them actively inside Stop().

This speeds up the JSON-RPC and REST server shutdown procedure,
and results in a faster node shutdown when many requests remain unhandled

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 18/100

This commit changes how Bitcoin Core's internal thread pool shuts down. Instead of the shutdown thread passively waiting for worker threads to finish leftover tasks, it now pitches in and processes tasks itself while workers finish up. The goal is a faster node shutdown when many RPC/REST requests are still queued. The change itself is a performance/cleanup improvement, not a security fix.

Lower-prioritytest: [doc] Remove outdated commentby MarcoFalke · fa0cc1c5 · Feb 26, 2026 · 1 fileMessage 90 · StrongInformational 15Details
Commit message · MarcoFalke

test: [doc] Remove outdated comment

The curl requirement has long been removed, when windows support was
added to the script. Also, the build support has long been dropped,
since the project switched from autotools to cmake.

90/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
AI analysis · Informational 15/100

This commit simply deletes an outdated explanatory comment from a test helper script. No code behavior changes, no security fix or vulnerability is introduced.

Lower-prioritykernel: Add recent assumeutxo snapshot infoby Ava Chow · 44538f8a · Feb 26, 2026 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · Ava Chow

kernel: Add recent assumeutxo snapshot info

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100

This commit simply adds new pre-calculated snapshot data for a Bitcoin Core feature called 'assumeutxo.' It does not change any security logic, fix a bug, or introduce a vulnerability. It is a routine data update.

AI review queuedkernel: Update headerssync paramsby Ava Chow · 58c2e23f · Feb 25, 2026 · 2 filesMessage 35 · OpaqueInformational 15Details
Commit message · Ava Chow

kernel: Update headerssync params

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit updates the internal tuning numbers used by Bitcoin Core when a new node downloads block headers from the network. It pushes the target date forward by six months and refreshes the generated parameters for mainnet, testnet, testnet4, and signet. There is no bug fix, behavior change, or security patch visible in the diff—it is routine parameter maintenance.

AI review queuedkernel: update chainTxDataby Ava Chow · cf261b07 · Feb 25, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · Ava Chow

kernel: update chainTxData

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit updates routine network statistics in Bitcoin Core's chain parameters. It refreshes the recorded number of transactions, timestamps, and transaction rates for mainnet, testnet, signet, and regtest networks based on recent blockchain data. There is no security issue here—this is normal maintenance data.

Lower-prioritykernel: update defaultAssumeValid and minimumChainWorkby Ava Chow · 8eaf1d26 · Feb 25, 2026 · 1 fileMessage 50 · ThinInformational 15Details
Commit message · Ava Chow

kernel: update defaultAssumeValid and minimumChainWork

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100

This commit updates two routine Bitcoin network parameters—minimumChainWork and defaultAssumeValid—to newer block heights for mainnet, testnet, signet, and regtest. These values are checkpoints that help nodes sync faster by skipping validation of very old blocks. The change is a standard, scheduled maintenance update with no security vulnerability.

Lower-prioritykernel: update assumed blockchain and chainstate sizesby Ava Chow · 5ca0c555 · Feb 25, 2026 · 1 fileMessage 50 · ThinInformational 15Details
Commit message · Ava Chow

kernel: update assumed blockchain and chainstate sizes

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100

This commit simply updates Bitcoin Core's built-in estimates of how large the blockchain and chainstate data are on disk. These numbers are used to warn users about required disk space before downloading the chain. The values are being increased to reflect real-world blockchain growth. There is no security bug or vulnerability here.

Security candidatecontrib: Update fixed feedsby Ava Chow · fec58229 · Feb 25, 2026 · 5 filesMessage 35 · OpaqueInformational 21Details
Commit message · Ava Chow

contrib: Update fixed feeds

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
seed or entropy pathsigning or wallet path
AI analysis · Informational 21/100

This commit updates Bitcoin Core's built-in list of network seed nodes—the addresses new wallets use to find peers for the first time. It replaces old, stale addresses with a fresh set of IPv4, IPv6, I2P, and Tor onion-service entries. There is no code change and no indication of a security vulnerability; it is routine network-maintenance data.

Security candidatemakeseeds: Choose node info with most recent success when deduplicatingby Ava Chow · 27fbdb00 · Feb 25, 2026 · 1 fileMessage 50 · ThinInformational 18Details
Commit message · Ava Chow

makeseeds: Choose node info with most recent success when deduplicating

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
seed or entropy path
AI analysis · Informational 18/100

This commit fixes a small bug in an internal Bitcoin Core seed-list generator script. When the script saw the same IP address and port more than once, it used to keep whichever entry it encountered last. Now it keeps the one with the most recent successful contact. This makes the generated list of network peers slightly more accurate and reliable, but it is not a security fix for the Bitcoin software itself.

Security candidatemakeseeds: Update known user agentsby Ava Chow · 982883a1 · Feb 25, 2026 · 1 fileMessage 45 · ThinInformational 16Details
Commit message · Ava Chow

makeseeds: Update known user agents

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
seed or entropy path
AI analysis · Informational 16/100

This commit simply updates the list of recognized Bitcoin Core version numbers in a helper script used to generate the network seed list. It is a routine maintenance change with no security relevance.

Lower-prioritydoc: Update Guix install for Debian/Ubuntuby MarcoFalke · faa70ca7 · Feb 25, 2026 · 1 fileMessage 76 · AdequateInformational 16Details
Commit message · MarcoFalke

doc: Update Guix install for Debian/Ubuntu

Fixes https://github.com/bitcoin/bitcoin/issues/33982

Co-authored-by: Purple Ninja <129023353+ToRyVand@users.noreply.github.com>

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
documentation-only discount
AI analysis · Informational 16/100

This is a documentation-only update. It changes the Guix installation instructions for Debian and Ubuntu users because the `guix` package is no longer available in recent distribution repositories. There is no code change and no security issue.

Lower-prioritytest: Updates needed after bitcoin-core/libmultiprocess#240by Ryan Ofsky · 8fe91f37 · Feb 25, 2026 · 2 filesMessage 100 · StrongLow 26Details
Commit message · Ryan Ofsky

test: Updates needed after bitcoin-core/libmultiprocess#240

Upstream PR bitcoin-core/libmultiprocess#240 fixed various issues which require
updates to python IPC tests. Those changes are made in this commit.

100/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
AI analysis · Low 26/100

This commit updates Bitcoin Core's automated multiprocess (IPC) tests to match fixes made in an upstream library. The test changes describe that two previously crash-causing IPC scenarios—disconnecting during a call and overloading a server thread—now behave gracefully. A third change documents a macOS-specific exception-handling quirk. The commit itself only changes test code, not the production Bitcoin Core code that handles IPC, so it does not introduce or fix a direct vulnerability in the shipped software. It is evidence that related crash bugs were fixed elsewhere.

AI review queuedSquashed 'src/ipc/libmultiprocess/' changes from 1fc65008f7d..1868a84451fby Ryan Ofsky · b7ca3bf0 · Feb 25, 2026 · 12 filesMessage 100 · StrongModerate 57Details
Commit message · Ryan Ofsky

Squashed 'src/ipc/libmultiprocess/' changes from 1fc65008f7d..1868a84451f

1868a84451f Merge bitcoin-core/libmultiprocess#245: type-context.h: Extent cancel_mutex lock to prevent theoretical race
fd4a90d3103 Merge bitcoin-core/libmultiprocess#244: ci: suppress two tidy lint issues
16dfc368640 ci: avoid bugprone-unused-return-value lint in test
dacd5eda464 ci: suppress nontrivial-threadlocal lint in proxy.cpp
ef96a5b2be2 doc: Comment cleanups after #240
e0f1cd76219 type-context.h: Extent cancel_mutex lock to prevent theoretical race
290702c74ce Merge bitcoin-core/libmultiprocess#240: Avoid errors from asynchronous (non-c++) clients
3a69d4755af Merge bitcoin-core/libmultiprocess#241: doc: Bump version number v7 -> v8
0174450ca2e Prevent crash on unclean disconnect if abandoned IPC call returns interface pointer
ddb5f74196f Allow simultaneous calls on same Context.thread
c4762c7b513 refactor: Add ProxyServer<Thread>::post() method
0ade1b40ac5 doc: Bump version number

git-subtree-dir: src/ipc/libmultiprocess
git-subtree-split: 1868a84451fe1b6a00116375a5f717230bb2533e

100/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
second-pass: broader security terminology
AI analysis · Moderate 57/100

This commit updates Bitcoin Core's internal IPC helper library (libmultiprocess) to fix crash and race-condition bugs that can happen when an IPC client disconnects while a server call is still running. It also removes an earlier 'thread busy' limitation so multiple calls can now be queued on the same worker thread. The changes are defensive hardening of inter-process communication, not a new user-facing feature.

Lower-prioritypolicy: don't CheckEphemeralSpends on reorgby Greg Sanders · 33fbaed3 · Feb 25, 2026 · 3 filesMessage 45 · ThinLow 37Details
Commit message · Greg Sanders

policy: don't CheckEphemeralSpends on reorg

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Low 37/100

This Bitcoin Core change adjusts how the network's memory pool (mempool) handles tiny-value 'dust' transactions when a blockchain reorganization occurs. Previously, during a reorg, transactions that had been mined in a block were re-checked under normal mempool rules, which could wrongly reject related transactions that spend dust outputs. The fix skips that specific dust-spending check during reorgs, allowing legitimate reorged transactions to re-enter the mempool. It is a policy/standardness fix, not a consensus bug, so it cannot change which blocks are valid or steal funds.

Lower-prioritynet: Don't log own ips during discoverby sedited · a49f97ff · Feb 25, 2026 · 1 fileMessage 68 · AdequateLow 29Details
Commit message · sedited

net: Don't log own ips during discover

The -logips option seems to imply that ip addresses are only logged when
it is set. This seems like an obvious case for not logging these by
default.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Low 29/100

This change stops Bitcoin Core from writing the computer's own internet addresses to log files unless the user has turned on the -logips option. Previously, the software logged these addresses even when -logips was off, which could leak private network information in shared logs or backups. The fix is a straightforward privacy improvement, not a fix for an active attack.

Lower-prioritytest: cleanup, block threads via semaphore instead of shared_futureby l0rinc · 9ff1e82e · Feb 24, 2026 · 1 fileMessage 72 · AdequateInformational 15Details
Commit message · l0rinc

test: cleanup, block threads via semaphore instead of shared_future

No-behavior change.

72/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
AI analysis · Informational 15/100

This is a test-only code cleanup. It swaps one internal synchronization mechanism for another inside Bitcoin Core's thread pool unit tests. There is no change to the actual Bitcoin node software that users run, and the commit message explicitly says 'No-behavior change.' It cannot affect live funds, network consensus, or security.

AI review queuedthreadpool: guard against Start-Stop raceby furszy · 8cd4a436 · Feb 24, 2026 · 1 fileMessage 68 · AdequateLow 42Details
Commit message · furszy

threadpool: guard against Start-Stop race

Stop() has two windows where Start() could cause troubles:

1) m_workers is temporarily empty while workers are being joined,
this creates a window where Start() could slip through and reset
m_interrupt to false, preventing the old workers from exiting and
causing a deadlock.

2) Start() could be called after workers are joined but before the
empty() sanity check on m_work_queue, causing a crash.

Fix both races by keeping m_interrupt set for the entire duration
of Stop(), so any concurrent Start() call is rejected until all
workers have exited.

Co-authored-by: Hodlinator <172445034+hodlinator@users.noreply.github.com>

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
second-pass: broader security terminology
AI analysis · Low 42/100

This patch fixes a timing bug in Bitcoin Core's internal worker-thread pool. If someone started the thread pool while it was still stopping, the program could freeze (deadlock) or crash. The fix keeps the pool marked as 'stopping' until every worker thread has fully exited, so a new start request is rejected during that window.

Lower-priorityclusterlin: adopt trained cost model (feature)by Pieter Wuille · 744d47fc · Feb 24, 2026 · 3 filesMessage 60 · AdequateInformational 15Details
Commit message · Pieter Wuille

clusterlin: adopt trained cost model (feature)

See the comments for the SFLDefaultCostModel class for details on how
the numbers were obtained.

60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
AI analysis · Informational 15/100

This commit updates Bitcoin Core's internal transaction-cluster linearization code with a new set of performance-cost estimates derived from benchmark data. It also tweaks a fuzz test to skip single-transaction cases. There is no change to network protocol, consensus rules, wallet behavior, or any externally observable security property. It is a routine algorithm-tuning change.

AI review queuedclusterlin: rescale costs (preparation)by Pieter Wuille · 4eefdfc5 · Feb 24, 2026 · 4 filesMessage 35 · OpaqueInformational 15Details
Commit message · Pieter Wuille

clusterlin: rescale costs (preparation)

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit is a non-security internal tuning change for Bitcoin Core's transaction mempool linearization logic. It multiplies several cost constants by 38 to prepare for future algorithm changes, and updates corresponding test/fuzz thresholds. There is no bug fix, no vulnerability, and no user-facing behavior change beyond slightly different internal cost budgets.

Lower-priorityinit refactor: Only initialize node.notifications one timeby Ryan Ofsky · a7cabf92 · Feb 24, 2026 · 3 filesMessage 73 · AdequateInformational 24Details
Commit message · Ryan Ofsky

init refactor: Only initialize node.notifications one time

Instead of having the InitAndLoadChainstate function delete and create the
KernelNotifications object each time it is called (it can be called twice when
reindexing) to clear cached state, create it just one time and add a
setChainstateLoaded() method to manage state as it is loaded and unloaded.

This refactoring should make sense by itself to be more explicit about how
KernelNotifications state is cleared, but it's also needed to make outside code
accessing KernelNotifications state (currently just mining code) safe during
node startup and shutdown so the KernelNofications mutex can be used for
synchronization and does not get recreated itself.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 24/100

This is a code cleanup in Bitcoin Core's startup sequence. It changes how an internal notification object is created so it is only created once instead of being deleted and recreated during startup. The commit message says this is needed so that other parts of the program (like mining code) can safely read this object's state while the node is starting up or shutting down, because the object's mutex would otherwise be destroyed and recreated, which could cause crashes or race conditions. There is no direct evidence in the diff of an exploitable security bug.

Lower-priorityipc mining: Prevent ``Assertion `m_node.chainman' failed`` errors on early startupby Ryan Ofsky · bbc8f1e0 · Feb 24, 2026 · 6 filesMessage 81 · StrongModerate 57Details
Commit message · Ryan Ofsky

ipc mining: Prevent ``Assertion `m_node.chainman' failed`` errors on early startup

This fixes ``Assertion `m_node.chainman' failed`` errors first reported
https://github.com/bitcoin/bitcoin/issues/33994#issuecomment-3602551596 when
IPC mining methods are called before ChainstateManager is loaded.

The fix works by making the `Init.makeMining` method block until chainstate
data is loaded.

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
AI analysis · Moderate 57/100

This commit fixes a crash in Bitcoin Core that could happen when external programs talk to the node over the IPC mining interface while the node is still starting up. Before the fix, calling mining methods too early could trigger an internal assertion failure and crash the node. The fix makes external mining clients wait until the node's chain data is fully loaded before they can proceed.

Lower-priorityclusterlin: introduce CostModel class (preparation)by Pieter Wuille · 9e7129df · Feb 24, 2026 · 1 fileMessage 73 · AdequateInformational 15Details
Commit message · Pieter Wuille

clusterlin: introduce CostModel class (preparation)

This parametrizes the cost model for the SFL algorithm with another
class. Right now, the behavior of that class matches the naive cost
model so far, but it will be replaced with a more advanced on in a
future commit.

The reason for abstracting this out is that it makes benchmarking for
creating such cost models easy, by instantiating the cost model class
with one that tracks time.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 15/100

This commit is a pure internal refactoring of Bitcoin Core's transaction linearization code. It replaces a simple numeric cost counter with a pluggable 'CostModel' class so future work can experiment with different ways of measuring algorithmic work. The default cost model behaves exactly like the old code. There is no user-facing change, no network change, and no security-relevant behavior change.

Lower-priorityclusterlin: use 'cost' terminology instead of 'iters' (refactor)by Pieter Wuille · ecc9a84f · Feb 24, 2026 · 12 filesMessage 50 · ThinInformational 15Details
Commit message · Pieter Wuille

clusterlin: use 'cost' terminology instead of 'iters' (refactor)

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100

This commit is a pure rename/refactor. It changes variable names, comments, and constant names from 'iterations'/'iters' to 'cost' throughout the cluster linearization and transaction graph code. No logic, behavior, or security properties are altered.

Lower-prioritytest: index, improve txospenderindex_initial_sync() test codeby furszy · e8f8b74a · Feb 24, 2026 · 1 fileMessage 95 · StrongInformational 15Details
Commit message · furszy

test: index, improve txospenderindex_initial_sync() test code

The index is now initialized after the setup phase (chain generation
and txs creation), since it doesn't participate on it at all.
This improves readability and splits setup from what we actually
want to check.

This also adds a check after Sync() to verify the index best block hash
matches the tip, so we know it fully synced before checking the
processed data. This will help catching errors as Sync() could have
aborted prematurely.

As a happy side effect, the SyncWithValidationInterfaceQueue() call at
the end of the test is no longer needed and has been removed.

95/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
AI analysis · Informational 15/100

This is a routine improvement to a Bitcoin Core unit test. It reorganizes when an index is started during the test and adds an extra check that the index fully catches up to the latest block. There is no change to production code, no security fix, and no vulnerability.

Lower-priorityinit refactor: Remove node.init accesss in AppInitInterfacesby Ryan Ofsky · c8e332cb · Feb 24, 2026 · 1 fileMessage 85 · StrongInformational 15Details
Commit message · Ryan Ofsky

init refactor: Remove node.init accesss in AppInitInterfaces

There's no change in behavior. This is just a refactoring to avoid a minor
layer violation in init code. The node.init object is intended to return
interface pointers for code outside the node (like wallet and gui code), not
used by node itself to initialize its internal state.

(Motivation for this change is to introduce a MakeMining wait_loaded option in
an upcoming commit that can only be used internally and not set by external
clients.)

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
AI analysis · Informational 15/100

This is a small internal code cleanup in Bitcoin Core's startup code. It changes how two internal interfaces (chain and mining) are created, using direct function calls instead of going through an intermediate 'init' object. The commit message explicitly states there is no change in behavior, and the diff shows only two lines changed in a straightforward way. There is no security issue visible here.