What changed, and why it matters
This commit simply updates the version of P2Pool that the Monero GUI wallet automatically downloads, from version 4.15.1 to version 4.16. It changes the download URLs, filenames, and the expected SHA-256 hash values for each supported operating system. There is no indication in the commit itself that this is a security fix or that the hashes are wrong.
No security action required. Treat as a routine dependency version bump. If desired, verify the new SHA-256 hashes against the official P2Pool v4.16 release artifacts published by SChernykh.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The diff in src/p2pool/P2PoolManager.cpp updates hardcoded P2Pool release references: URLs now point to github.com/SChernykh/p2pool/releases/download/v4.16, local filenames reflect the v4.16 naming, and validHash constants are updated to match the new release’s SHA-256 hashes for Windows, Linux, macOS aarch64, and macOS x64. The download/verification logic is otherwise unchanged. No vulnerability, bug fix, or security-relevant behavior is visible in the diff.
Changed components
src/p2pool/P2PoolManager.cppInspect captured patch +12 / −12
diff --git a/src/p2pool/P2PoolManager.cpp b/src/p2pool/P2PoolManager.cpp
index 83524c1..c1e580e 100644
--- a/src/p2pool/P2PoolManager.cpp
+++ b/src/p2pool/P2PoolManager.cpp
@@ -55,21 +55,21 @@ void P2PoolManager::download() {
QString fileName;
QString validHash;
#ifdef Q_OS_WIN
- url = "https://github.com/SChernykh/p2pool/releases/download/v4.15.1/p2pool-v4.15.1-windows-x64.zip";
- fileName = m_p2poolPath + "/p2pool-v4.15.1-windows-x64.zip";
- validHash = "97b4ba97e65d766ecf223694168b5739e65156390707fbf50f9979054cba52d3";
+ url = "https://github.com/SChernykh/p2pool/releases/download/v4.16/p2pool-v4.16-windows-x64.zip";
+ fileName = m_p2poolPath + "/p2pool-v4.16-windows-x64.zip";
+ validHash = "8f619bf215e986f8b96526a1a279b83c84b569a0916c1d19713bfb616e78160a";
#elif defined(Q_OS_LINUX)
- url = "https://github.com/SChernykh/p2pool/releases/download/v4.15.1/p2pool-v4.15.1-linux-x64.tar.gz";
- fileName = m_p2poolPath + "/p2pool-v4.15.1-linux-x64.tar.gz";
- validHash = "efd8b23579774711a5b86743da980e0936b7c220894063296719116d7f9ba254";
+ url = "https://github.com/SChernykh/p2pool/releases/download/v4.16/p2pool-v4.16-linux-x64.tar.gz";
+ fileName = m_p2poolPath + "/p2pool-v4.16-linux-x64.tar.gz";
+ validHash = "1b03b2e4d4adfe488b2867eb85b57366fbaf8594a7f84cdbf13a3c8519159280";
#elif defined(Q_OS_MACOS_AARCH64)
- url = "https://github.com/SChernykh/p2pool/releases/download/v4.15.1/p2pool-v4.15.1-macos-aarch64.tar.gz";
- fileName = m_p2poolPath + "/p2pool-v4.15.1-macos-aarch64.tar.gz";
- validHash = "391c55474c3f08994340df2824a0b452dac8e0d18ee43cf3b361ce80f00dcd5b";
+ url = "https://github.com/SChernykh/p2pool/releases/download/v4.16/p2pool-v4.16-macos-aarch64.tar.gz";
+ fileName = m_p2poolPath + "/p2pool-v4.16-macos-aarch64.tar.gz";
+ validHash = "8e1d8c10850015c50cc4955dc3b9681007f329d51325a3a55bde700298bcfaeb";
#elif defined(Q_OS_MACOS)
- url = "https://github.com/SChernykh/p2pool/releases/download/v4.15.1/p2pool-v4.15.1-macos-x64.tar.gz";
- fileName = m_p2poolPath + "/p2pool-v4.15.1-macos-x64.tar.gz";
- validHash = "0e113c9beff21001ded4a15a3ae2f5ce8a151d18457476923026b322113bc1de";
+ url = "https://github.com/SChernykh/p2pool/releases/download/v4.16/p2pool-v4.16-macos-x64.tar.gz";
+ fileName = m_p2poolPath + "/p2pool-v4.16-macos-x64.tar.gz";
+ validHash = "573b6aa9b953fb5594f7eb21b1321a8d719e181b6814f931ce54b603dc6f0663";
#endif
QFile file(fileName);
epee::net_utils::http::http_simple_client http_client;
Why this scored 15/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.