Blockchain: fix data race in get_dynamic_base_fee_estimate
What changed, and why it matters
This commit adds a missing lock around a function that estimates transaction fees. Without the lock, multiple threads could read blockchain data while it is being changed, leading to inconsistent or incorrect fee estimates. The fix prevents this 'data race' by ensuring only one thread accesses the relevant data at a time.
Apply the patch. Review other fee-estimation and blockchain-query paths for similar missing locks, and consider running thread-safety static analysis or stress tests on concurrent fee queries.
Security signals we found
data race fix
missing synchronization primitive added
concurrency safety improvement in fee estimation
Evidence from the diff
The patch adds CRITICAL_REGION_LOCAL(m_blockchain_lock) at the start of Blockchain::get_dynamic_base_fee_estimate_2021_scaling. This function reads the current hard fork version and database height, then computes dynamic base fees. The omission of the lock allowed concurrent access to mutable blockchain state, creating a data race. The fix aligns this function with the locking discipline used elsewhere in the class, but the commit provides no proof of exploitability beyond the race condition itself.
Changed components
src/cryptonote_core/blockchain.cppBlockchain::get_dynamic_base_fee_estimate_2021_scalingdynamic fee estimationInspect captured patch +1 / −0
diff --git a/src/cryptonote_core/blockchain.cpp b/src/cryptonote_core/blockchain.cpp
index b8babf5..23bcc65 100644
--- a/src/cryptonote_core/blockchain.cpp
+++ b/src/cryptonote_core/blockchain.cpp
@@ -3654,6 +3654,7 @@ void Blockchain::get_dynamic_base_fee_estimate_2021_scaling(uint64_t base_reward
void Blockchain::get_dynamic_base_fee_estimate_2021_scaling(uint64_t grace_blocks, std::vector<uint64_t> &fees) const
{
+ CRITICAL_REGION_LOCAL(m_blockchain_lock);
const uint8_t version = get_current_hard_fork_version();
const uint64_t db_height = m_db->height();
Why this scored 46/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.