workflows: speed up slow-hash in PR core_tests
What changed, and why it matters
This commit changes Monero's CI testing workflow to optionally reduce the number of slow-hash iterations during automated pull-request tests, so the tests run faster. It does not change the real Monero mining or transaction verification code used by ordinary nodes or wallets. The production default of about 1 million iterations stays the same unless someone explicitly compiles with a special override flag. The main risk is accidental: if a binary were built with the reduced iteration count and used in production, the proof-of-work would be much weaker. But the commit only applies the override inside GitHub's test runners for pull requests.
No immediate action required. Verify that release builds and package builds never set MONERO_CRYPTO_SLOW_HASH_ITER to a low value, and consider adding a build-time warning or static assertion when the macro is set below the production value. Reviewers should confirm the workflow rebuilds only test binaries and does not publish CI artifacts with reduced hashing.
Security signals we found
Compile-time reduction of proof-of-work iteration count
CI-only override gated on github.event_name == 'pull_request'
Default iteration count preserved for normal builds
No change to consensus validation logic or transaction handling
Evidence from the diff
The patch makes ITER in src/crypto/slow-hash.c configurable at compile time via MONERO_CRYPTO_SLOW_HASH_ITER, defaulting to the original 1<<20. The GitHub Actions workflow then rebuilds core_tests with -DMONERO_CRYPTO_SLOW_HASH_ITER=20 only on pull_request events. This is a test-optimization change; the production consensus path is unaffected unless a build is deliberately compiled with the override. There is no runtime configuration or consensus bypass.
Changed components
src/crypto/slow-hash.c.github/workflows/build.ymlGitHub Actions core_tests jobInspect captured patch +27 / −12
diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml
index e89f95a..909fbeb 100644
--- a/.github/workflows/build.yml
+++ b/.github/workflows/build.yml
@@ -186,9 +186,9 @@ jobs:
fail-fast: false
matrix:
include:
- # Most popular Ubuntu LTS version
- - name: Ubuntu 24.04
- container: ubuntu:24.04
+ # Oldest supported Ubuntu LTS version
+ - name: Ubuntu 22.04
+ container: ubuntu:22.04
container:
image: ${{ matrix.container }}
env:
@@ -234,9 +234,9 @@ jobs:
strategy:
matrix:
include:
- # Oldest supported Ubuntu LTS version
- - name: Ubuntu 22.04
- container: ubuntu:22.04
+ # Most popular Ubuntu LTS version
+ - name: Ubuntu 24.04
+ container: ubuntu:24.04
container:
image: ${{ matrix.container }}
env:
@@ -256,7 +256,7 @@ jobs:
- name: install pip
run: apt install -y python3-pip
- name: install Python dependencies
- run: pip install requests psutil monotonic zmq deepdiff
+ run: python3 -m pip install --break-system-packages requests psutil monotonic zmq deepdiff
- name: configure git
run: git config --global --add safe.directory '*'
- uses: actions/checkout@v5
@@ -272,15 +272,26 @@ jobs:
- name: create dummy disk drives for testing
run: tests/create_test_disks.sh >> $GITHUB_ENV
- uses: ./.github/actions/set-make-job-count
- - name: tests
+ - name: build
env:
- CTEST_OUTPUT_ON_FAILURE: ON
- DNS_PUBLIC: tcp://9.9.9.9
CMAKE_BUILD_PARALLEL_LEVEL: ${{env.MAKE_JOB_COUNT}}
run: |
${{env.CCACHE_SETTINGS}}
${{env.BUILD_DEFAULT}}
- cmake --build build --target test
+ - name: run tests except core_tests
+ env:
+ DNS_PUBLIC: tcp://9.9.9.9
+ run: ctest --test-dir build --output-on-failure -E core_tests
+ - name: use reduced slow-hash iterations for core_tests
+ if: github.event_name == 'pull_request'
+ env:
+ CFLAGS: -DMONERO_CRYPTO_SLOW_HASH_ITER=20
+ CMAKE_BUILD_PARALLEL_LEVEL: ${{env.MAKE_JOB_COUNT}}
+ run: |
+ cmake -S . -B build --fresh -D ARCH="default" -D BUILD_TESTS=ON
+ cmake --build build --target core_tests
+ - name: run core_tests
+ run: ctest --test-dir build --output-on-failure -R core_tests
- name: save ccache
uses: actions/cache/save@v5
if: github.event_name != 'pull_request' && steps.ccache-restore.outputs.cache-hit != 'true'
diff --git a/src/crypto/slow-hash.c b/src/crypto/slow-hash.c
index 47ae2da..be3ad24 100644
--- a/src/crypto/slow-hash.c
+++ b/src/crypto/slow-hash.c
@@ -44,8 +44,12 @@
#include <errno.h>
+#ifndef MONERO_CRYPTO_SLOW_HASH_ITER
+#define MONERO_CRYPTO_SLOW_HASH_ITER (1 << 20)
+#endif
+
#define MEMORY (1 << 21) // 2MB scratchpad
-#define ITER (1 << 20)
+#define ITER MONERO_CRYPTO_SLOW_HASH_ITER
#define AES_BLOCK_SIZE 16
#define AES_KEY_SIZE 32
#define INIT_SIZE_BLK 8
Why this scored 18/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.