AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Informational 19 Cryptographic libraries

txpool: fix time_in_pool age calculation

Public commit record

What the developer wrote

Authored by selsta

45/100 · Thin
txpool: fix time_in_pool age calculation
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This commit fixes a simple arithmetic bug in how long a transaction has been waiting in the memory pool ("time in pool") was calculated. The old code subtracted the current time from the receive time in the wrong order, which could produce a very large, nonsensical age value instead of a small positive number. The fix ensures the age is always the current time minus the receive time, or zero if the clock somehow runs backward. This is a correctness fix for statistics/ranking of pending transactions, not a direct funds-theft or code-execution vulnerability.

Recommended action

Merge the patch; it is a low-risk correctness fix. Review any downstream logic that uses the returned age (e.g., fee estimation, relay decisions) to confirm it was not relying on the bogus underflowed value. No emergency response is warranted.

Security signals we found

01

Integer underflow in age field due to reversed subtraction order

02

Incorrect metadata reported for mempool transactions

03

Potential skew of transaction backlog statistics / prioritization heuristics

Risk score

Why this scored 19/100

Our methodology →
Potential impact 2/30
Exploitability 1/25
Stealth signal 1/15
Affected reach 3/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.