Merge bitcoin/bitcoin#36151: makeseeds: fix off-by-one in field count check
What changed, and why it matters
This is a one-line fix in a Python helper script used to build the list of network seed nodes for Bitcoin Core. The script reads lines of data about internet nodes and was supposed to skip any line that didn't have enough fields. Due to an off-by-one error, a line with exactly 11 fields passed the 'too short' check but then crashed the program when it tried to read the 12th field. The fix simply changes the minimum required field count from 11 to 12. This only affects an offline developer/operations tool and cannot be used to attack the Bitcoin network or wallets directly.
No urgent action required. The fix is correct and should be merged as part of normal maintenance. Operators generating seed lists should use the patched version to avoid build-tool failures on truncated crawler output.
Security signals we found
Off-by-one in input validation guard
IndexError aborts tool run on malformed/truncated input
Fix located in non-runtime, offline seed-generation helper
No memory corruption, privilege escalation, or network exposure
Evidence from the diff
In contrib/seeds/makeseeds.py, parseline() validates input lines by splitting on whitespace and checking len(sline) < 11, but later indexes sline[11] (the user agent field). A line with exactly 11 fields therefore bypasses the guard and raises IndexError, aborting the entire makeseeds run. The patch changes the guard to len(sline) < 12, matching the actual minimum access pattern. The tool is non-privileged, run offline by maintainers to generate src/chainparamsseeds.h, and consumes public crawler data. The crash is a denial-of-service-to-the-build-tool condition, not a network or node vulnerability.
Changed components
contrib/seeds/makeseeds.pyparseline() functionInspect captured patch +1 / −1
### contrib/seeds/makeseeds.py
@@ -62,7 +62,7 @@ def parseline(line: str) -> Union[dict, None]:
# Ignore line that starts with comment
return None
sline = line.split()
- if len(sline) < 11:
+ if len(sline) < 12:
# line too short to be valid, skip it.
return None
# Skip bad results.Why this scored 20/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.