AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 29 Cryptographic libraries

p2p: fix race causing dropped connections during sync

Public commit record

What the developer wrote

Authored by j-berman

85/100 · Strong
p2p: fix race causing dropped connections during sync

Without this commit:
1) read height from DB
2) add block to chain in separate thread
3) read chain for block id's and request them from peer
4) ERR in handle_response_chain_entry, peer's first block is the
one that was added to the chain, which has block idx=height from
step 1.

This commit reads the chain for height and highest block id's
in one go while holding the m_blockchain_lock to avoid the race.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
The short version

What changed, and why it matters

This patch fixes a timing bug in Monero's peer-to-peer syncing. Previously, a node could read its own blockchain height, then a new block could be added in another thread, and then the node would ask a peer for older blocks using an out-of-date height. This mismatch could cause the node to think the peer's first returned block was wrong and drop the connection, making sync slower or less reliable. The fix reads the height and the list of block hashes together under the same lock so they cannot get out of step.

Recommended action

Treat as a reliability/DoS-hardening fix. Nodes should upgrade to avoid unnecessary sync failures and dropped peer connections. No immediate emergency response is warranted, but the fix should be included in the next release.

Security signals we found

01

Race condition between blockchain height read and short-chain history read

02

P2P connection drop during synchronization

03

Missing atomic snapshot across height and chain history

04

Potential denial-of-service via sync disruption

Risk score

Why this scored 29/100

Our methodology →
Potential impact 5/30
Exploitability 2/25
Stealth signal 3/15
Affected reach 8/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.