AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Informational 15 Bitcoin

Merge bitcoin/bitcoin#36262: test: cover orphan reconsideration interruptibility

Public commit record

What the developer wrote

Authored by merge-script

91/100 · Strong
Merge bitcoin/bitcoin#36262: test: cover orphan reconsideration interruptibility

16bff77a5aaf7a9740b859f74b8898cee6de5588 test: cover orphan reconsideration interruptibility (ViniciusCestarii)

Pull request description:

Add test checking that ProcessOrphanTx reconsiders at most one orphan per ProcessMessages(). This test prevents regression of [CVE-2024-52914](https://bitcoincore.org/en/2024/07/03/disclose-orphan-dos/) which currently no existing test checks.

The test kills 2 mutants found with https://github.com/ViniciusCestarii/mutant-harness:

1. Remove `return true` after an orphan is accepted

```diff
--- a/src/net_processing.cpp
+++ b/src/net_processing.cpp
@@ -3494,7 +3494,6 @@ bool PeerManagerImpl::ProcessOrphanTx(Peer& peer)
if (result.m_result_type == MempoolAcceptResult::ResultType::VALID) {
LogDebug(BCLog::TXPACKAGES, " accepted orphan tx %s (wtxid=%s)\n", orphanHash.ToString(), orphan_wtxid.ToString());
ProcessValidTx(peer.m_id, porphanTx, result.m_replaced_transactions);
- return true;
} else if (state.GetResult() != TxValidationResult::TX_MISSING_INPUTS) {
```

2. Remove `return true` after an orphan is rejected for a reason other than `TX_MISSING_INPUTS`

```diff
--- a/src/net_processing.cpp
+++ b/src/net_processing.cpp
@@ -3508,7 +3508,6 @@ bool PeerManagerImpl::ProcessOrphanTx(Peer& peer)
state.GetResult() != TxValidationResult::TX_RESULT_UNSET)) {
ProcessInvalidTx(peer.m_id, porphanTx, state, /*first_time_failure=*/false);
}
- return true;
}
}
```

ACKs for top commit:
instagibbs:
reACK https://github.com/bitcoin/bitcoin/pull/36262/commits/16bff77a5aaf7a9740b859f74b8898cee6de5588
fametrano:
tACK 16bff77a5aaf7a9740b859f74b8898cee6de5588

Tree-SHA512: 3d00bf7aa023c47d335b0f4c9d720c914611962272b895d91c8a542739f3b9c0d35c1dba5becdfd7167122c3f3f2be87b366d296732fa2765538467e6c0af6d7
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit only adds a new automated test to Bitcoin Core. It does not change any production code. The test verifies that a previously fixed denial-of-service bug (CVE-2024-52914) stays fixed by checking that orphan transactions are reconsidered one at a time per network message. It is a regression test, not a security patch.

Recommended action

No security action needed. Treat as normal test-only maintenance. Reviewers may optionally confirm the test correctly exercises the CVE-2024-52914 fix and passes in CI.

Security signals we found

01

Adds regression test for previously disclosed CVE-2024-52914

02

No changes to src/net_processing.cpp or other production code

03

Test targets interruptibility of orphan transaction reconsideration

04

Commit message explicitly describes test purpose and mutant killing

Risk score

Why this scored 15/100

Our methodology →
Potential impact 0/30
Exploitability 0/25
Stealth signal 0/15
Affected reach 0/15
Confidence 10/10
Evidence quality 5/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.