AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Informational 18 Cryptographic libraries

workflows: speed up slow-hash in PR core_tests

Public commit record

What the developer wrote

Authored by selsta

45/100 · Thin
workflows: speed up slow-hash in PR core_tests
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This commit changes Monero's CI testing workflow to optionally reduce the number of slow-hash iterations during automated pull-request tests, so the tests run faster. It does not change the real Monero mining or transaction verification code used by ordinary nodes or wallets. The production default of about 1 million iterations stays the same unless someone explicitly compiles with a special override flag. The main risk is accidental: if a binary were built with the reduced iteration count and used in production, the proof-of-work would be much weaker. But the commit only applies the override inside GitHub's test runners for pull requests.

Recommended action

No immediate action required. Verify that release builds and package builds never set MONERO_CRYPTO_SLOW_HASH_ITER to a low value, and consider adding a build-time warning or static assertion when the macro is set below the production value. Reviewers should confirm the workflow rebuilds only test binaries and does not publish CI artifacts with reduced hashing.

Security signals we found

01

Compile-time reduction of proof-of-work iteration count

02

CI-only override gated on github.event_name == 'pull_request'

03

Default iteration count preserved for normal builds

04

No change to consensus validation logic or transaction handling

Risk score

Why this scored 18/100

Our methodology →
Potential impact 2/30
Exploitability 1/25
Stealth signal 1/15
Affected reach 2/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.