AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Informational 20 Bitcoin

Merge bitcoin/bitcoin#36151: makeseeds: fix off-by-one in field count check

Public commit record

What the developer wrote

Authored by merge-script

81/100 · Strong
Merge bitcoin/bitcoin#36151: makeseeds: fix off-by-one in field count check

c786052865fd173fd8bc7396e1303f7840c5b0da makeseeds: fix off-by-one in field count check (aman21-droid)

Pull request description:

Fixes #36146.

`parseline()` checks that a line has at least 11 whitespace-separated fields:

```python
if len(sline) < 11:
# line too short to be valid, skip it.
return None
```

but it later reads `sline[11]` (the user agent), which needs 12. A line with exactly 11 fields got past the check and then raised `IndexError`, aborting the whole run instead of skipping that line. 11 is the highest index the function uses, so the check now requires 12 fields.

This isn't only theoretical: README.md builds seeds_main.txt by appending one crawler's output onto another's, so the file mixes two independently maintained formats, and a truncated download leaves a short last line too. Skipping the line is what the check was already trying to do.

ACKs for top commit:
maflcko:
lgtm ACK c786052865fd173fd8bc7396e1303f7840c5b0da
l0rinc:
ACK c786052865fd173fd8bc7396e1303f7840c5b0da

Tree-SHA512: 3c3aeb8876b7e0eccf8f03faafe0e0bb71d1b11924feaf22b2bb6bf1a36e25bedd622de257060de873c42f12fba8df42d96b2a831a2e8d395220fed70f4bba34
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This is a one-line fix in a Python helper script used to build the list of network seed nodes for Bitcoin Core. The script reads lines of data about internet nodes and was supposed to skip any line that didn't have enough fields. Due to an off-by-one error, a line with exactly 11 fields passed the 'too short' check but then crashed the program when it tried to read the 12th field. The fix simply changes the minimum required field count from 11 to 12. This only affects an offline developer/operations tool and cannot be used to attack the Bitcoin network or wallets directly.

Recommended action

No urgent action required. The fix is correct and should be merged as part of normal maintenance. Operators generating seed lists should use the patched version to avoid build-tool failures on truncated crawler output.

Security signals we found

01

Off-by-one in input validation guard

02

IndexError aborts tool run on malformed/truncated input

03

Fix located in non-runtime, offline seed-generation helper

04

No memory corruption, privilege escalation, or network exposure

Risk score

Why this scored 20/100

Our methodology →
Potential impact 2/30
Exploitability 1/25
Stealth signal 1/15
Affected reach 2/15
Confidence 9/10
Evidence quality 5/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.