What changed, and why it matters
This change adds a safety check when a Monero node packages a block for relay to other nodes. Before this patch, if a block somehow contained the same transaction hash twice, the node would not notice and could produce an invalid or malformed block package. The fix detects duplicate transaction hashes and throws an error instead of silently continuing. The commit message does not describe this as a security fix, so its security relevance is uncertain, but duplicate-hash bugs in consensus-related code can sometimes be exploited to cause network disruption or inconsistent state.
Treat as a hardening fix with possible denial-of-service or consensus-integrity implications. Review whether duplicate `tx_hashes` can reach `get_block_complete_entry()` from untrusted input (e.g., a miner-submitted block or a relayed block) and confirm the throw is handled safely by callers. No immediate emergency response is indicated, but include in routine security release notes if a new version is prepared.
Security signals we found
Consensus-adjacent validation added to block serialization path
Duplicate identifier check prevents potential inconsistent block packaging
No explicit security framing in commit or vendor references
Evidence from the diff
In get_block_complete_entry(), which serializes a block plus its transactions into a block_complete_entry for P2P relay, the patch now constructs an unordered_set from b.tx_hashes and checks that the set size equals the vector size. If duplicates exist, it throws via CHECK_AND_ASSERT_THROW_MES. This prevents construction of a block complete entry containing duplicate transaction references. The downstream effect before the patch is not fully clear from the diff alone: depending on how the resulting block_complete_entry is consumed, duplicates could lead to missing transactions, mismatched tx_hashes/tx_blobs lengths, or relay of an invalid block.
Changed components
src/cryptonote_core/cryptonote_core.cppget_block_complete_entry()P2P block/transaction relayInspect captured patch +3 / −0
### src/cryptonote_core/cryptonote_core.cpp
@@ -1270,6 +1270,9 @@ namespace cryptonote
//-----------------------------------------------------------------------------------------------
block_complete_entry get_block_complete_entry(block& b, tx_memory_pool &pool)
{
+ const std::unordered_set<crypto::hash> tx_hashes(b.tx_hashes.cbegin(), b.tx_hashes.cend());
+ CHECK_AND_ASSERT_THROW_MES(tx_hashes.size() == b.tx_hashes.size(), "Duplicate transaction hashes in block");
+
block_complete_entry bce;
bce.block = cryptonote::block_to_blob(b);
bce.block_weight = 0; // we can leave it to 0, those txes aren't prunedWhy this scored 57/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.