AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 60 Bitcoin

Merge bitcoin/bitcoin#35833: log: prevent user input from injecting fake log lines

Public commit record

What the developer wrote

Authored by Ava Chow

100/100 · Strong
Merge bitcoin/bitcoin#35833: log: prevent user input from injecting fake log lines

d93d366e204e95e873ef0b89425f84a520f8fabd log: escape newlines in messages (Lőrinc)
960dcdb62529a6498d1397e1cf1077fe3cb19d9f test: characterize RPC and wallet input logs (Lőrinc)

Pull request description:

**Problem:** Restricted RPC users and callers of `createwallet` or `restorewallet` can inject newlines through rejected methods or wallet names, and [global log escaping preserves them](https://github.com/bitcoin/bitcoin/pull/17095), making forged lines look like node messages.

**Fix:** Escape embedded newlines in log messages.

<details>
<summary>Manual reproducer</summary>

```bash
DATADIR="$(mktemp -d /tmp/bitcoin-log-injection.XXXXXX)"
M="$(date -u +%Y-%m-%dT%H:%M:%SZ) ERROR: ConnectTip: ConnectBlock 0000000000000000deadbeefdeadbeefdeadbeefdeadbeefdeadbeefdeadbeef failed, bad-txns-inputs-missingorspent"
cmake -B build >/dev/null 2>&1 && cmake --build build -j >/dev/null 2>&1
build/bin/bitcoind -regtest -daemonwait -datadir="$DATADIR" -rpcwhitelist=__cookie__:getblock,stop >/dev/null 2>&1
build/bin/bitcoin-cli -regtest -datadir="$DATADIR" $'getblock\n'"$M" >/dev/null 2>&1; killall bitcoind >/dev/null
echo; grep -E 'ConnectTip|not allowed' "$DATADIR/regtest/debug.log"
```

> Before

```bash
2026-07-28T23:18:57Z [warning] RPC User __cookie__ not allowed to call method getblock
2026-07-28T23:18:55Z ERROR: ConnectTip: ConnectBlock 0000000000000000deadbeefdeadbeefdeadbeefdeadbeefdeadbeefdeadbeef failed, bad-txns-inputs-missingorspent
```

> After

```bash
2026-07-28T23:19:45Z [warning] RPC User __cookie__ not allowed to call method getblock\x0a2026-07-28T23:19:41Z ERROR: ConnectTip: ConnectBlock 0000000000000000deadbeefdeadbeefdeadbeefdeadbeefdeadbeefdeadbeef failed, bad-txns-inputs-missingorspent
```
</details>

ACKs for top commit:
achow101:
ACK d93d366e204e95e873ef0b89425f84a520f8fabd
ryanofsky:
Code review ACK d93d366e204e95e873ef0b89425f84a520f8fabd. Fix is minimal now and tests have been expanded to ensure that newlines can't sneak into log messages through `InitWarning` or `InitError` calls by testing the `load_on_startup` case w0xlt reported https://github.com/bitcoin/bitcoin/pull/35833#issuecomment-5849713749.
w0xlt:
ACK d93d366e204e95e873ef0b89425f84a520f8fabd

Tree-SHA512: 6a19f937a2d362fd4dd2960d1551d7e630dc61e4200bd1f61eb65fd02286b2500ac5eb4fee01c1f1aed5fb4899daa56c11e800ccb4572a3372b180f8ec44c6db
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This update fixes a way that people with limited access to a Bitcoin node could make fake log entries appear real. Normally, the node cleans up special characters in log messages but was leaving newlines alone. A clever user could slip a newline into a wallet name or a blocked RPC command, causing the log file to show a forged line that looks like an official node error or warning. The fix now escapes newlines too, so the whole injected text stays on one line and is clearly not a real log entry. This is mainly a log-integrity and anti-confusion issue, not a direct theft or remote-control bug.

Recommended action

Apply the patch. Review any log-parsing or monitoring tools that previously relied on multi-line log messages, because legitimate messages containing newlines will now appear as single escaped lines. No other operational changes are required.

Security signals we found

01

Log injection / log forgery via embedded newlines in untrusted input

02

Input from restricted RPC users reaching log output without newline escaping

03

Control-character escaping bypass due to explicit newline exception

04

Forged log lines can impersonate node errors/warnings and mislead operators or monitoring

05

Fix is minimal: single-character policy change in LogEscapeMessage plus trailing-newline handling

Risk score

Why this scored 60/100

Our methodology →
Potential impact 12/30
Exploitability 14/25
Stealth signal 10/15
Affected reach 10/15
Confidence 9/10
Evidence quality 5/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.