BC
← All projectsBitcoin Core

Bitcoin Core

The Bitcoin network's reference node and wallet implementation.

BitcoinSupply chainNormal
Repository coverage

3194 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

325security candidates672second-pass queue3017AI analyses
152commits · 30 days
322commits · 60 days
1286commits · 180 days
2834commits · 365 days
Backfill bands
Aug 5 → Feb 61351 seen45 candidatesComplete
Feb 6 → Jun 61033 seen63 candidatesComplete
Jun 6 → Jul 6281 seen11 candidatesComplete
Jul 6 → Aug 5207 seen5 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

71/100 average clarity
1198Strong · 80–100
1206Adequate · 60–79
702Thin · 40–59
88Opaque · 0–39
6security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
merge-script2105094389
Antoine Poinsot22422170
Ava Chow20669195070
MarcoFalke41421408074
fanquake23321228058
Lőrinc18121177081
Hennadii Stepanov22816211065
rkrux57957074
Sjors Provoost89889074
Sebastian Falbesoner33733073
David Gumberg55655072
Pieter Wuille95595066
Analysis record

Published AI watches

Last scanned 21 minutes ago

Low 38 AI analysisMessage 100 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36299: cli: Improve empty-response and fix -rpcclienttimeout regression

This update fixes two bugs in bitcoin-cli, the command-line tool used to talk to a Bitcoin node. First, when a server replied with an empty body but said it was intentionally empty (Content-Length: 0), the client would keep waiting instead…

Client-side hang on empty HTTP body (denial-of-service against bitcoin-cli user)Timeout regression could abort legitimate slow RPC responsesFix distinguishes Content-Length: 0 from absent Content-Length
dd809d2cby Ava Chow+41−232 files
No security note in commit
Informational 15 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36052: ci: Doc: Move all config comments right next to the option they explain

This commit is a documentation and code-style cleanup for Bitcoin Core's continuous integration (CI) scripts. It changes how build configuration strings are formatted in shell scripts so comments can sit next to the options they describe, …

9f059527by merge-script+100−9826 files
No security note in commit
Moderate 60 AI analysisMessage 100 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35833: log: prevent user input from injecting fake log lines

This update fixes a way that people with limited access to a Bitcoin node could make fake log entries appear real. Normally, the node cleans up special characters in log messages but was leaving newlines alone. A clever user could slip a n…

Log injection / log forgery via embedded newlines in untrusted inputInput from restricted RPC users reaching log output without newline escapingControl-character escaping bypass due to explicit newline exception
d4b0e1e4by Ava Chow+48−114 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36391: test: fix typo in rpc_psbt

This commit fixes a one-word typo in a comment inside a test file. The comment incorrectly referred to 'walletcreatepsbt' when the surrounding test code actually calls 'walletcreatefundedpsbt'. No code behavior changes, and there is no sec…

4b612c6bby merge-script+1−11 file
No security note in commit
Informational 15 AI analysisMessage 82 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

test: fix typo in rpc_psbt

This commit fixes a typo in a comment within a test file. The comment incorrectly referred to 'walletcreatepsbt' when the surrounding test code actually exercises 'walletcreatefundedpsbt'. No code behavior changes, and there is no security…

0a8ffe90by Bruno Garcia+1−11 file
No security note in commit
Informational 15 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36377: doc: add 461 (Deterministic ECDSA signatures with low-R grinding) to bips.md

This commit is a documentation-only update. It adds a single line to Bitcoin Core's list of implemented BIPs, noting that BIP 461 (a technique for making ECDSA signatures smaller and deterministic) has been implemented since version 0.17.0…

e0f16ef9by merge-script+1−01 file
No security note in commit
Low 27 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36375: wallet: accept uppercase addresses without amount in sendall

This patch fixes a bug in Bitcoin Core's `sendall` wallet command. If a user typed a bech32 address in uppercase letters, the command would fail with a confusing 'below dust threshold' error instead of sending the funds. The fix compares d…

Functional bug in RPC command causing unexpected transaction failureCase-sensitivity mismatch between user input and canonical address encodingNo memory safety, cryptographic, or authorization issue evident
e7aef7e8by Ava Chow+22−52 files
No security note in commit
Informational 15 AI analysisMessage 100 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36381: test: avoid testing at the exact `-maxfeerate` boundary

This commit fixes a flaky automated test in Bitcoin Core. The test was checking the maximum transaction fee rate by creating a transaction at the exact boundary, which sometimes failed because the real transaction size could be slightly sm…

No production code changedTest-only changeNo memory safety, cryptography, consensus, or authorization changes
ba8fdb97by Ava Chow+1−11 file
No security note in commit
Informational 20 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36233: guix: Update time-machine to `60f6956aeffa7f30285745bd0ea615e9acfc74f8`

This is a build-system maintenance update for Bitcoin Core's reproducible build environment (Guix). It updates the Guix time-machine commit and several dependency versions, and temporarily disables some test suites that fail when building …

No direct security-relevant code change in Bitcoin Core consensus, wallet, or P2P layers.Dependency version bumps (git-minimal, linux-headers, python-lief, python-minimal) are routine build-environment updates.Disabling third-party package test suites reduces build-time test coverage but does not alter Bitcoin Core's own test or release binaries.
619185d5by merge-script+32−73 files
No security note in commit
Informational 15 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36364: tools: Call SHA256AutoDetect in bitcoin-util, bitcoin-tx and bitcoin-wallet

This change makes three Bitcoin command-line tools (bitcoin-tx, bitcoin-util, and bitcoin-wallet) automatically pick the fastest SHA-256 hashing implementation available on the computer, such as hardware-accelerated versions on modern CPUs…

dc2a9987by merge-script+6−03 files
No security note in commit
Informational 23 AI analysisMessage 98 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36321: net: cast vector size to avoid overflow, truncation, sign change

This is a one-line fix in Bitcoin Core's network code. It changes how the size of a list of block headers is converted to a signed integer inside a loop. Previously, if the list was empty, the conversion could trigger undefined-behavior wa…

UndefinedBehaviorSanitizer integer sanitizer warning addressedImplicit signed/unsigned conversion in loop counterUnsigned integer wraparound on empty vector size
ced4c6e6by merge-script+1−11 file
No security note in commit
Low 32 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#34371: wallet: allow importprunedfunds for spending transactions

This change fixes a Bitcoin Core wallet bug where the `importprunedfunds` RPC command could only re-import transactions that sent money to the wallet, not transactions that spent money from it. After this fix, both incoming and outgoing tr…

Logic bug in wallet transaction import scopeIncorrect balance possible after removing and re-importing spending transactionFix routes import through existing involvement check (IsMine + IsFromMe)
ed7dd7cfby Ava Chow+36−203 files
No security note in commit
Low 28 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#29278: Wallet: Add `maxfeerate` wallet startup option

This commit adds a new Bitcoin Core wallet startup option called -maxfeerate. It lets users set a maximum fee rate (fee per unit of transaction size) that the wallet will allow when creating or broadcasting transactions. Previously, the wa…

New wallet startup option -maxfeerate to cap transaction fee rateNew transaction error type MAX_FEE_RATE_EXCEEDEDBroadcastTransaction now checks both max absolute fee and max fee rate
f80aaf4bby Ava Chow+303−7930 files
No security note in commit
Moderate 64 AI analysisMessage 86 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35984: sign: skip signing SIGHASH_SINGLE inputs with no corresponding output

This Bitcoin Core update fixes a wallet-signing quirk. When a user chose the SIGHASH_SINGLE signature mode, an input that had no matching output index would sign essentially nothing meaningful. That signature could then stay valid even if …

Funds-redirection footgun from SIGHASH_SINGLE signatures with no committed outputInconsistent guard between SignTransaction and SignPSBTInput pathsFix centralizes the guard in the low-level signature creator to cover future signing paths
e19f83e9by Ava Chow+37−82 files
Vendor flagged security relevance
Low 35 AI analysisMessage 86 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35696: i2p: update leaseset encryption types

This change updates Bitcoin Core's I2P (Invisible Internet Project) privacy network settings to use newer, stronger encryption for the published 'leaseset' that describes how other peers can contact a node. The old setting included ElGamal…

Cryptographic algorithm update (ElGamal to MLKEM-768)Use of I2P 'legacy' encryption type removedConfiguration-only change in network privacy layer
65e075f8by Ava Chow+2−21 file
No security note in commit
Informational 15 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35948: init: correct first-run disk space estimate

This change fixes a labeling bug in Bitcoin Core's first-run disk-space warning. The estimate was stored in GiB (binary gigabytes, 1024-based) but displayed as GB (decimal gigabytes, 1000-based), and for pruned nodes it showed the full-cha…

d26f19c7by Ava Chow+5−42 files
No security note in commit
Low 44 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#36284: wallet: don't double discard output groups with avoidpartialspends

This is a wallet bug, not a theft or remote-code bug. When a Bitcoin Core user turns on the optional 'avoidpartialspends' or 'avoid_reuse' setting, an output group rejected during coin selection could be counted twice as 'discarded.' That …

Logic error causing double-counting of discarded UTXO groupsCan trigger false 'insufficient funds' failure in coin selectionAffects avoidpartialspends / avoid_reuse wallets only
e8e7e91aby Ava Chow+43−14 files
No security note in commit
Informational 18 AI analysisMessage 81 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35890: doc: use overwrite (>) instead of append (>>) for one-shot PSBT files in offline-signing-tutorial.md

This is a documentation-only fix in a tutorial file. It changes two shell examples from using '>>' (append to file) to '>' (overwrite file). If a user followed the old instructions and ran the same command twice, the file would contain two…

No security signal: change is limited to documentationNo code changes to Bitcoin Core binaries, RPC, wallet, or consensus logicNo cryptographic, network, or privilege-boundary implications
bfdcd979by merge-script+2−21 file
No security note in commit
Informational 19 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35675: mining: add block template manager

This is a large internal code reorganization (refactor) in Bitcoin Core. It creates a new BlockTemplateManager class that takes over block-template creation, block submission, and tip-waiting helpers that were previously spread across seve…

Large refactor touching mining, RPC, interfaces, and test shutdown pathsNew object lifetime dependency: BlockTemplateManager holds references to mempool, chainman, and notifications; explicit reset ordering added in Shutdown/InitAndLoadChainstate/test setupsRemoval of early-init node.mining interface; BlockTemplateManager is now created after chainstate load, with a comment that it must exist before setChainstateLoaded(true) unblocks IPC waiters
5c726f20by Ryan Ofsky+561−44926 files
No security note in commit
Informational 12 AI analysisMessage 91 · Strong
BC Bitcoin CoreBitcoin Core BitcoinSupply chain

Merge bitcoin/bitcoin#35301: Silent Payments: Implement bip352 (take 2)

This commit adds the first implementation of BIP352 (Silent Payments) to Bitcoin Core. Silent Payments are a new type of privacy-preserving Bitcoin address that lets someone receive payments without publicly revealing a fixed address. The …

New cryptographic feature implementation (BIP352 Silent Payments)Extensive use of secp256k1 silentpayments moduleInput public key extraction from P2PKH, P2WPKH, P2SH-P2WPKH, and P2TR inputs
be5d0b55by Ava Chow+6951−010 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidateRevert "ci: Treat SHA1 LLVM signing key as warning"by will · 3574905c · Feb 20, 2026 · 1 fileMessage 65 · AdequateInformational 18Details
Commit message · will

Revert "ci: Treat SHA1 LLVM signing key as warning"

This reverts commit 3c8f5e48f710313de78bcbfafd09fed71890d754.

65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Why it was queued
signing boundary
AI analysis · Informational 18/100

This commit removes a temporary workaround in Bitcoin Core's automated testing setup that relaxed a security policy for checking the cryptographic signature on LLVM's software repository. The workaround was added because LLVM's signing key still used the older SHA1 hash algorithm, which newer Linux systems began rejecting. Now that LLVM has fixed its key, the workaround is no longer needed and is being removed. This is a cleanup change that restores normal, stricter security checks in the continuous integration (CI) environment. It does not change the Bitcoin Core software that users run.

Lower-prioritytest: Fixup assert_debug_log timeouts in feature_config_args.pyby MarcoFalke · fa4424fd · Feb 20, 2026 · 1 fileMessage 100 · StrongInformational 15Details
Commit message · MarcoFalke

test: Fixup assert_debug_log timeouts in feature_config_args.py

* The bitcoin.conf related checks do not need any timeout, because the
logging happens in the main thread, before the node is fully started.
* The net thread related checks do need a timeout, because the threads
may be late to start after the node is fully started.

100/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification
AI analysis · Informational 15/100

This is a minor test-only change in Bitcoin Core's own test suite. It adjusts how long the tests wait for certain log messages to appear, removing unnecessary waits for some checks and adding short waits for others. It does not change the Bitcoin software that users run and has no security impact.

Lower-prioritytest: Add missing syncwithvalidationinterfacequeueby MarcoFalke · faed837f · Feb 20, 2026 · 1 fileMessage 85 · StrongInformational 13Details
Commit message · MarcoFalke

test: Add missing syncwithvalidationinterfacequeue

This is required to actually erase the orphan transaction when the
BlockConnected event is handled in the background validation interface
queue thread.

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
AI analysis · Informational 13/100

This commit fixes a timing issue in a Bitcoin Core functional test. The test checks that orphan transactions are removed when a block connects, but the check was running before a background queue had finished processing the block. Adding a synchronization call makes the test wait for that background work, so the test reliably sees the expected log message. It does not change production node behavior or fix a security bug in the Bitcoin protocol.

Lower-priorityMinimize mempool lock, sync txo spender index only when and if neededby sstone · 0b96b9c6 · Feb 19, 2026 · 2 filesMessage 73 · AdequateLow 25Details
Commit message · sstone

Minimize mempool lock, sync txo spender index only when and if needed

We sync txospenderindex after we've checked the mempool for spending transaction, and only if search is not limited to the mempool and no
spending transactions have been found for some of the provided outpoints.
This should minimize the chance of having a block containing a spending transaction that is no longer in the mempool but has not been indexed yet.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Low 25/100

This commit tightens the timing of when Bitcoin Core's RPC call 'gettxspendingprevout' consults the optional on-disk 'txo spender index'. Previously, the code would wait for that index to finish syncing before even looking at the mempool. Now it searches the mempool first, releases the mempool lock, and only then waits for the index if it actually needs to. The goal is to reduce a small window where a block has just arrived, the spending transaction left the mempool, but the index hasn't recorded it yet, so the RPC could incorrectly report no spender. It is a robustness improvement, not a fix for a clear exploit.

Lower-prioritytest: addrman: successive failures in the last week for IsTerribleby brunoerg · 6202acd2 · Feb 19, 2026 · 1 fileMessage 72 · AdequateInformational 12Details
Commit message · brunoerg

test: addrman: successive failures in the last week for IsTerrible

72/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
AI analysis · Informational 12/100

This commit only adds a new unit test for Bitcoin Core's address manager. It checks that an address with many recent connection failures is correctly marked as 'terrible' and filtered out when peers are returned, while still remaining in the unfiltered list. There is no change to production code.

Lower-priorityrpc: add coinbase_tx field to getblockby Sjors Provoost · e0463b4e · Feb 19, 2026 · 3 filesMessage 68 · AdequateInformational 18Details
Commit message · Sjors Provoost

rpc: add coinbase_tx field to getblock

This adds a "coinbase_tx" field to the getblock RPC result, starting
at verbosity level 1. It contains only fields guaranteed to be small,
i.e. not the outputs.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 18/100

This change adds a new convenience field called coinbase_tx to the getblock RPC response in Bitcoin Core. It exposes only small, already-public metadata about the first transaction in a block (the coinbase transaction), such as version, locktime, sequence, coinbase script, and witness data. It does not expose transaction outputs or any new sensitive data. This is a feature addition, not a security fix or vulnerability.

Lower-prioritydoc: add release notes for Tor PoW defensesby Vasil Dimov · c68e3d2c · Feb 19, 2026 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · Vasil Dimov

doc: add release notes for Tor PoW defenses

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit only adds a release note describing a previously implemented feature: automatic Tor hidden services created by Bitcoin Core will use Tor's proof-of-work (PoW) defenses when supported by the Tor daemon. The commit itself changes only documentation and contains no code.

Lower-prioritydoc: add a hint to enable PoW defenses to manual hidden servicesby Vasil Dimov · 4bae84c9 · Feb 19, 2026 · 1 fileMessage 50 · ThinInformational 15Details
Commit message · Vasil Dimov

doc: add a hint to enable PoW defenses to manual hidden services

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit only updates documentation. It adds a note in the Tor setup guide suggesting users enable a Tor hidden-service proof-of-work defense if their Tor version supports it. No code behavior changes.

Lower-prioritytor: enable PoW defenses for automatically created hidden servicesby Vasil Dimov · 4c6798a3 · Feb 19, 2026 · 3 filesMessage 86 · StrongInformational 23Details
Commit message · Vasil Dimov

tor: enable PoW defenses for automatically created hidden services

Enable PoW defenses [1] for hidden services that we create via
Tor Control using the `ADD_ONION` command [2].

The ability to do that has been added in tor-0.4.9.2-alpha [3]. Previous
versions return a syntax error to the `ADD_ONION` command with
`PoWDefensesEnabled=1`, so the approach here is to try with PoW and if
we get syntax error, then retry without PoW.

[1] https://tpo.pages.torproject.net/onion-services/ecosystem/technology/security/pow/
[2] https://spec.torproject.org/control-spec/commands.html#add_onion
[3] https://gitlab.torproject.org/tpo/core/tor/-/commit/02c18044464bfe45f168b55297a785244094cfd5

86/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
AI analysis · Informational 23/100

This change makes Bitcoin Core nodes that advertise themselves as hidden services on the Tor network ask Tor to enable a built-in anti-spam feature called 'Proof-of-Work defenses' when creating those hidden services. If the installed Tor version is too old to understand that option, the code falls back to creating the hidden service without it. It is a hardening improvement, not a fix for an active vulnerability in Bitcoin Core itself.

Lower-prioritytor, fuzz: reuse constants instead of duplicatingby Vasil Dimov · fb993f76 · Feb 19, 2026 · 3 filesMessage 90 · StrongInformational 15Details
Commit message · Vasil Dimov

tor, fuzz: reuse constants instead of duplicating

`src/torcontrol.cpp` used to define some constants that are used
explicitly in `src/torcontrol.cpp` and implicitly in
`src/test/fuzz/torcontrol.cpp` by duplicating their values.

Move the constants to `src/torcontrol.h` and reuse them in
`src/test/fuzz/torcontrol.cpp` to avoid duplication and magic
numbers.

90/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification
Why it was queued
fuzzing or regression evidence
AI analysis · Informational 15/100

This is a minor code cleanup change. It moves two Tor status code numbers (250 for OK, 510 for unrecognized command) from one file to a shared header so both the main program and a test fuzzer use the same named constants instead of hard-coding the numbers twice. There is no security fix here and no behavior change.

Lower-priorityAdd a "tx output spender" indexby sstone · 3d82ec5b · Feb 19, 2026 · 18 filesMessage 68 · AdequateInformational 23Details
Commit message · sstone

Add a "tx output spender" index

Adds an outpoint -> txid index, which can be used to find which transactions spent a given output.
We use a composite key with 2 parts (suggested by @romanz): hash(spent outpoint) and tx position, with an empty value.
To find the spending tx for a given outpoint, we do a prefix search (prefix being the hash of the provided outpoint), and for all keys that match this prefix
we load the tx at the position specified in the key and return it, along with the block hash, if does spend the provided outpoint.
To handle reorgs we just erase the keys computed from the removed block.

This index is extremely useful for Lightning and more generally for layer-2 protocols that rely on chains of unpublished transactions.
If enabled, this index will be used by `gettxspendingprevout` when it does not find a spending transaction in the mempool.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Informational 23/100

This commit adds a new optional Bitcoin Core index called the transaction output spender index. When enabled with -txospenderindex=1, it records which transaction spent a given output, allowing the gettxspendingprevout RPC to find confirmed spending transactions, not just mempool ones. It is a feature addition, not a security fix, and does not by itself create a vulnerability. The main security-relevant consideration is that it increases disk and memory use, requires disabling pruning, and exposes more historical chain data through RPC.

AI review queuedqa: Disable parts of the test when running under Windows or rootby Hodlinator · 850a80c1 · Feb 19, 2026 · 1 fileMessage 91 · StrongInformational 15Details
Commit message · Hodlinator

qa: Disable parts of the test when running under Windows or root

test_scanning_sub_dir():
- Remove try/finally - we don't need to clean up after a failed test (done in this commit to maintain indentation).

Regarding symlinks: https://github.com/bitcoin/bitcoin/pull/31410#issuecomment-3554721014

Kept some symlink creation which didn't disrupt Windows cross builds to make for a smaller diff and less cumbersome code. There is some hope of eventually getting better symlink support via #34603.

Co-authored-by: Ava Chow <github@achow101.com>

91/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only changes a Bitcoin Core test script. It disables certain file-permission and symlink checks when the test runs on Windows or as the root/admin user, because those checks rely on Unix-style behavior that doesn't apply in those environments. There is no change to the actual Bitcoin Core wallet software that users run, and no security vulnerability is being fixed or introduced.

Lower-priorityci: Enable `wallet_multiwallet.py` in "Windows, test cross-built" jobby Hodlinator · c2e28d45 · Feb 19, 2026 · 1 fileMessage 87 · StrongInformational 15Details
Commit message · Hodlinator

ci: Enable `wallet_multiwallet.py` in "Windows, test cross-built" job

Co-authored-by: Hennadii Stepanov <32963518+hebasto@users.noreply.github.com>

87/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body✓ Mentions testing or verification
Why it was queued
documentation-only discount
AI analysis · Informational 15/100

This commit simply re-enables an automated test (wallet_multiwallet.py) in the Windows cross-build continuous integration job. It removes the temporary exclusion that was put in place while a bug was being fixed. There is no change to Bitcoin Core's actual wallet code, network code, or consensus logic, so it does not affect users' funds, node security, or network behavior.

Lower-priorityqa: Avoid duplicating output in case the diff is the sameby Hodlinator · 111864ac · Feb 19, 2026 · 1 fileMessage 50 · ThinInformational 15Details
Commit message · Hodlinator

qa: Avoid duplicating output in case the diff is the same

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Informational 15/100

This is a tiny quality-of-life improvement to Bitcoin Core's internal Python test framework. It stops an error message from printing the same dictionary twice when a test assertion fails. It does not change any production Bitcoin code, network behavior, or security logic.

AI review queuedqa: Check for platform-independent part of error messageby Hodlinator · ed43ce57 · Feb 19, 2026 · 1 fileMessage 65 · AdequateInformational 15Details
Commit message · Hodlinator

qa: Check for platform-independent part of error message

On Windows one gets different exception messages depending on whether running a native build or cross build.

65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This is a minor test-only change. It updates a single automated test in Bitcoin Core so that it checks for a stable, platform-independent error message ('Wallet file verification failed.') instead of a Windows-specific filesystem error string. There is no change to the actual Bitcoin Core wallet code that users run, and no security issue is present.

AI review queuedqa: Test scanning errors individuallyby Hodlinator · fb803e3c · Feb 19, 2026 · 1 fileMessage 78 · AdequateInformational 12Details
Commit message · Hodlinator

qa: Test scanning errors individually

This change ensures that each condition potentially triggering the
"Error while scanning" log message is tested independently, avoiding
false positives.

Co-authored-by: Hennadii Stepanov <32963518+hebasto@users.noreply.github.com>

78/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 12/100

This commit only changes a test file. It reorganizes existing wallet-scanning tests so each error condition is checked separately, rather than lumping them together. There is no change to the actual Bitcoin Core wallet code, so it does not fix or introduce a security issue in the software users run.

AI review queuedrefactor(qa): Break apart ginormous run_test()by Hodlinator · 64a098a9 · Feb 19, 2026 · 1 fileMessage 57 · ThinInformational 15Details
Commit message · Hodlinator

refactor(qa): Break apart ginormous run_test()

57/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit is a simple cleanup of a test file. It takes one very long test function and splits it into smaller, named helper functions without changing what the test actually does. There is no change to Bitcoin Core's production code or to how wallets behave.

AI review queuedscripted-diff: self.nodes[0] => nodeby Hodlinator · c811e473 · Feb 19, 2026 · 1 fileMessage 78 · AdequateInformational 15Details
Commit message · Hodlinator

scripted-diff: self.nodes[0] => node

-BEGIN VERIFY SCRIPT-
sed --in-place 's/self\.nodes\[0\]/node/g; s/node \= node/node \= self\.nodes\[0\]/' ./test/functional/wallet_multiwallet.py
-END VERIFY SCRIPT-

78/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This is a purely cosmetic code cleanup in a Bitcoin Core test file. It replaces repeated references to `self.nodes[0]` with a local variable named `node`. No production code, no behavior changes, and no security implications.

AI review queuedrefactor(qa): Lift out functions to outer scopesby Hodlinator · d1a4ddb5 · Feb 19, 2026 · 1 fileMessage 92 · StrongInformational 15Details
Commit message · Hodlinator

refactor(qa): Lift out functions to outer scopes

This prepares for later breaking apart of run_test().

Note that the "wallet" lambda was renamed to "get_wallet" since otherwise the Python interpreter emitted:
"UnboundLocalError: cannot access local variable 'wallet' where it is not associated with a value"

92/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Explains rationale or failure mode
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This is a harmless code cleanup in a test file. It moves some helper functions from inside a test method to the top of the file and renames one variable to avoid a Python language quirk. There is no change to Bitcoin Core's actual wallet behavior or security.

AI review queuedmove-only(qa): Move wallet creation check down to othersby Hodlinator · bb1aff7e · Feb 19, 2026 · 1 fileMessage 65 · AdequateInformational 15Details
Commit message · Hodlinator

move-only(qa): Move wallet creation check down to others

Makes the functions broken out from run_test() in the next commit more cohesive.

65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This is a test-only change that moves a single error-checking test case from one place to another within the same functional test file. It does not change any production code, wallet behavior, or security logic. The commit message explicitly calls it 'move-only'.

AI review queuedrefactor(qa): Remove unused optionby Hodlinator · 73cf8589 · Feb 19, 2026 · 1 fileMessage 72 · AdequateInformational 15Details
Commit message · Hodlinator

refactor(qa): Remove unused option

Last use was removed in 0d32d661481f099af572e7a08a50e17bcc165c44.

72/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit simply removes an unused command-line option from a single test script. It is a cleanup change with no effect on Bitcoin Core's runtime behavior, network security, or user funds.

Lower-priorityhttp: properly respond to HTTP request during shutdownby furszy · 726b3663 · Feb 18, 2026 · 1 fileMessage 73 · AdequateLow 35Details
Commit message · furszy

http: properly respond to HTTP request during shutdown

Makes sure we respond to the client as the HTTP request attempts to submit a task to
the thread pool during server shutdown.

Roughly what happens:

1) The server receives an HTTP request and starts calling http_request_cb().
2) Meanwhile on another thread, shutdown is triggered which calls InterruptHTTPServer()
and unregisters libevent http_request_cb() callback and interrupts the thread pool.
3) The request (step 1) resumes and tries to submit a task to the now-interrupted server.

This fix detects failed submissions immediately, and the server responds with
HTTP_SERVICE_UNAVAILABLE.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
AI analysis · Low 35/100

This change fixes a bug in Bitcoin Core's built-in web server (used by RPC and REST interfaces). During server shutdown, incoming HTTP requests could be accepted but then silently dropped because the worker thread pool had already been interrupted. The server would not send any response back to the client, causing the connection to hang until it timed out. The patch detects when a request cannot be queued and immediately replies with a '503 Service Unavailable' status, telling the client the server is shutting down.

Lower-priorityrefactor: Use static_cast<decltype(...)> to suppress integer sanitizer warningby MarcoFalke · fa6af856 · Feb 18, 2026 · 2 filesMessage 95 · StrongInformational 15Details
Commit message · MarcoFalke

refactor: Use static_cast<decltype(...)> to suppress integer sanitizer warning

This refactor does not change any behavior, except for the integer
sanitizer warning.

Can be tested via:

UBSAN_OPTIONS="suppressions=$(pwd)/test/sanitizer_suppressions/ubsan:print_stacktrace=1:halt_on_error=1:report_error_type=1" ./bld-cmake/bin/bitcoin-cli -stdinrpcpass uptime

95/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
defensive validation
AI analysis · Informational 15/100

This is a code cleanup that silences a harmless automated sanitizer warning. It does not change how the program behaves, fix a bug, or close a security hole. The change removes a suppression entry for a warning that is no longer triggered.

Lower-priorityutil: Fix UB in SetStdinEcho when ENOTTYby MarcoFalke · fa692974 · Feb 18, 2026 · 2 filesMessage 45 · ThinLow 34Details
Commit message · MarcoFalke

util: Fix UB in SetStdinEcho when ENOTTY

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI analysis · Low 34/100

This commit fixes a bug in the code that controls whether your password is shown on screen when you type it into Bitcoin Core. Previously, if the program was not connected to a normal terminal (for example, when run from a script or a pipe), the code could read and write random or invalid terminal settings, which is undefined behavior. The fix checks whether stdin is actually a terminal before trying to change its echo setting, and it now handles errors from the underlying system calls instead of ignoring them. The practical security risk is low: it mainly prevents crashes or strange behavior in non-interactive environments, rather than being an exploitable vulnerability.

Lower-prioritytest: Enable `system_tests/run_command` "stdin" test on Windowsby Hennadii Stepanov · 97e7e794 · Feb 18, 2026 · 1 fileMessage 72 · AdequateInformational 15Details
Commit message · Hennadii Stepanov

test: Enable `system_tests/run_command` "stdin" test on Windows

72/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Mentions testing or verification! No meaningful explanatory body
AI analysis · Informational 15/100

This commit simply removes two lines that previously skipped a test on Windows. The test checks that a helper program can receive data through standard input and echo it back. There is no change to production code, no security fix, and no vulnerability.