Skip to content

fix: penalize oversized notfound messages - #7348

Merged
PastaPastaPasta merged 3 commits into
dashpay:developfrom
thepastaclaw:fix/notfound-oversized-penalty
Jun 25, 2026
Merged

fix: penalize oversized notfound messages#7348
PastaPastaPasta merged 3 commits into
dashpay:developfrom
thepastaclaw:fix/notfound-oversized-penalty

Conversation

@thepastaclaw

Copy link
Copy Markdown

fix: penalize oversized notfound messages

Issue being fixed or feature implemented

Oversized notfound inventory vectors were ignored after deserialization. This
change gives them a small misbehavior score, matching the defensive treatment
used for other inventory-vector messages, and avoids holding cs_main while
deserializing the vector.

What was done?

  • Deserialize notfound inventory vectors before taking cs_main.
  • Return early with a small misbehavior score when a notfound vector exceeds
    the maximum outstanding object/block request count.
  • Add functional coverage for the oversized notfound path.

How Has This Been Tested?

Environment: macOS 15.6 arm64, local Dash Core autotools build from this branch.

  • git diff --check

  • Local build configured with:

    ./configure --without-gui --disable-bench --disable-fuzz-binary \
      --disable-tests --disable-wallet
  • make -j8 src/dashd src/dash-cli

    • Initial parallel build hit a generated dependency-file race while building
      dash-cli; dashd linked successfully.
  • make -j1 src/dash-cli

  • test/functional/p2p_tx_download.py --cachedir=/tmp/dash_func_cache_notfound

Breaking Changes

None.

Checklist

  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added or updated relevant unit/integration/functional/e2e tests
  • I have made corresponding changes to the documentation
  • I have assigned this pull request to a milestone
    (for repository code-owners and collaborators only)

@thepastaclaw

Copy link
Copy Markdown
Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jun 9, 2026

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@github-actions

github-actions Bot commented Jun 9, 2026

Copy link
Copy Markdown

✅ No Merge Conflicts Detected

This PR currently has no conflicts with other open PRs.

@coderabbitai

coderabbitai Bot commented Jun 9, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 2c0e2dcd-64c8-4a09-acbc-e388e5fdcc05

📥 Commits

Reviewing files that changed from the base of the PR and between c4a51eecab3fa50c202ffe5376f520d424d96a4a and a97b7b4.

📒 Files selected for processing (2)
  • src/net_processing.cpp
  • test/functional/p2p_tx_download.py
🚧 Files skipped from review as they are similar to previous changes (2)
  • src/net_processing.cpp
  • test/functional/p2p_tx_download.py

Walkthrough

This PR adds a defensive validation layer to NOTFOUND message processing. PeerManagerImpl now reads the incoming NOTFOUND vInv and rejects it immediately (Misbehaving score 20) if its size exceeds MAX_PEER_OBJECT_IN_FLIGHT + MAX_BLOCKS_IN_TRANSIT_PER_PEER; otherwise it proceeds with the existing per-inventory cleanup for known types. A functional test sends an oversized NOTFOUND and asserts the misbehavior log entry.

Sequence Diagram(s)

sequenceDiagram
  participant RemotePeer
  participant PeerManager
  participant Node
  RemotePeer->>PeerManager: SEND msg_notfound (vInv)
  PeerManager->>PeerManager: read vInv and compute size
  alt size > MAX_PEER_OBJECT_IN_FLIGHT + MAX_BLOCKS_IN_TRANSIT_PER_PEER
    PeerManager->>Node: Misbehaving(peer, score=20)
    Note right of PeerManager: return early
  else size within limits
    PeerManager->>PeerManager: iterate vInv, erase m_object_in_flight/announced entries
    PeerManager->>RemotePeer: continue normal processing
  end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Suggested reviewers

  • UdjinM6
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely identifies the main change: penalizing oversized notfound messages, which is the primary objective of the PR.
Description check ✅ Passed The description comprehensively explains the issue, the three key changes made, testing approach, and checklist status, all directly related to the changeset.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
test/functional/p2p_tx_download.py (1)

147-149: ⚡ Quick win

Avoid hardcoded oversized-count literals in this test.

+ 17 and "notfound message size = 117" bake in current protocol limits. Derive both from named constants so this stays valid if limits change.

Suggested refactor
     def test_oversized_notfound(self):
         self.log.info('Check that oversized notfound increases misbehavior score')
-        invs = [CInv(t=1, h=i) for i in range(MAX_GETDATA_IN_FLIGHT + 17)]
-        with self.nodes[0].assert_debug_log(["Misbehaving", "notfound message size = 117"]):
+        oversized_count = MAX_GETDATA_IN_FLIGHT + 17  # 1 above current C++ notfound limit path
+        invs = [CInv(t=1, h=i) for i in range(oversized_count)]
+        with self.nodes[0].assert_debug_log(["Misbehaving", f"notfound message size = {oversized_count}"]):
             self.nodes[0].p2ps[0].send_message(msg_notfound(vec=invs))
             self.nodes[0].p2ps[0].sync_with_ping()
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@test/functional/p2p_tx_download.py` around lines 147 - 149, Replace the
hardcoded "+ 17" and "117" by deriving both values from named constants and the
actual serialized message size: introduce a small named constant (e.g.
EXTRA_NOTFOUND_INV_COUNT) and build invs as CInv(t=1, h=i) for i in
range(MAX_GETDATA_IN_FLIGHT + EXTRA_NOTFOUND_INV_COUNT); then compute the
expected debug string dynamically from the serialized notfound message (e.g.
expected = f"notfound message size = {len(msg_notfound(vec=invs).serialize())}"
or equivalent) and use that in self.nodes[0].assert_debug_log instead of the
literal "notfound message size = 117", keeping references to CInv,
MAX_GETDATA_IN_FLIGHT, msg_notfound and assert_debug_log to locate the changes.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@test/functional/p2p_tx_download.py`:
- Around line 147-149: Replace the hardcoded "+ 17" and "117" by deriving both
values from named constants and the actual serialized message size: introduce a
small named constant (e.g. EXTRA_NOTFOUND_INV_COUNT) and build invs as CInv(t=1,
h=i) for i in range(MAX_GETDATA_IN_FLIGHT + EXTRA_NOTFOUND_INV_COUNT); then
compute the expected debug string dynamically from the serialized notfound
message (e.g. expected = f"notfound message size =
{len(msg_notfound(vec=invs).serialize())}" or equivalent) and use that in
self.nodes[0].assert_debug_log instead of the literal "notfound message size =
117", keeping references to CInv, MAX_GETDATA_IN_FLIGHT, msg_notfound and
assert_debug_log to locate the changes.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 2220f6ad-bdbd-40da-920c-3278cc73bb3b

📥 Commits

Reviewing files that changed from the base of the PR and between 317917a and 641f39b04d13e708666ee89080c2b875493d1d61.

📒 Files selected for processing (2)
  • src/net_processing.cpp
  • test/functional/p2p_tx_download.py

@thepastaclaw

Copy link
Copy Markdown
Author

Addressed CodeRabbit nitpick in follow-up commit: introduced named NOTFOUND-size constants and derived the oversized test count/assertion from those constants instead of hardcoded literals. Validation: test/functional/p2p_tx_download.py --timeout-factor=2.

@thepastaclaw

Copy link
Copy Markdown
Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jun 9, 2026

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@thepastaclaw

Copy link
Copy Markdown
Author

CI follow-up: the only red check is linux64_multiprocess-test / Test source, and its GitHub check annotation says the hosted runner lost communication with the server. I could not fetch test failure logs, and gh run rerun --failed is blocked for my account because rerun requires repo admin rights. This looks like runner infrastructure rather than a code/test failure; maintainer rerun needed.

@thepastaclaw

Copy link
Copy Markdown
Author

CI is green after the CI-only empty rerun commit 3d6d17ea62. There is no code diff from the previously reviewed head, so the existing CodeRabbit/automation review remains applicable. Marking ready for review.

@thepastaclaw
thepastaclaw marked this pull request as ready for review June 10, 2026 02:30
@thepastaclaw

thepastaclaw commented Jun 10, 2026

Copy link
Copy Markdown
Author

✅ Review complete (commit a97b7b4)

@thepastaclaw thepastaclaw left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

Small, focused fix that moves NOTFOUND deserialization out of cs_main and applies a misbehavior penalty when vInv exceeds the per-peer in-flight budget. Logic and lock ordering are correct, and the functional test exercises the new path. One minor consistency observation: the chosen penalty (10) is half of what sibling inventory-vector oversize checks use (20).

💬 1 nitpick(s)

Comment thread src/net_processing.cpp
@thepastaclaw

thepastaclaw commented Jun 15, 2026

Copy link
Copy Markdown
Author

CI follow-up correction: the red job was linux64_ubsan-test / Test source, failing in feature_governance.py with a vote-propagation race (gobject count reported 24 vs 25). I checked the logs and this happens in governance vote propagation, not in this PR’s oversized-notfound path; another parallel feature_governance instance passed in the same run. Since I do not have permission to rerun the failed job directly, I pushed empty commit af5d8c0e00 to rerun CI.

@thepastaclaw thepastaclaw left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

Both agents independently report no findings on the cumulative head at af5d8c0e. The PR moves NOTFOUND vector deserialization out from under cs_main, adds a 20-point misbehavior penalty for oversized notfound vectors (matching the established pattern for inv/getdata/addr/headers), and includes focused functional test coverage. The latest delta from c4a51eecab is a CI-only rerun commit, so there are no carried-forward prior findings and no resolved findings.

@thepastaclaw thepastaclaw left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

Both agents independently found no in-scope issues in this PR, which adds a misbehavior penalty (score 20) for oversized notfound inventory vectors and reorders deserialization before cs_main. CodeRabbit reported zero inline findings. The change is consistent with existing conventions for other inv-vector messages and includes functional test coverage. No carried-forward prior findings exist.

@UdjinM6 UdjinM6 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good but you should drop empty "ci retrigger" commits

@thepastaclaw
thepastaclaw force-pushed the fix/notfound-oversized-penalty branch from b9e5b53 to a97b7b4 Compare June 16, 2026 22:02

@thepastaclaw thepastaclaw left a comment

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

Both agents found no in-scope issues in this PR, which adds a misbehavior penalty for oversized notfound messages and a functional test covering it. The change mirrors handling for other inventory-vector messages and matches upstream Bitcoin Core. No carried-forward prior findings exist (prior review at b9e5b531 was clean), and CodeRabbit reported 0 inline findings.

@thepastaclaw

thepastaclaw commented Jun 16, 2026

Copy link
Copy Markdown
Author

CI follow-up on the current red checks:

  • aarch64-linux-build / Build source failed before a code/build error with the GitHub runner annotation System.IO.IOException: No space left on device while writing the runner diagnostic log (/home/runner/actions-runner/.../_diag/Worker_*.log). That is runner disk exhaustion.
  • linux64_ubsan-test / Test source failed in feature_asset_locks.py at the existing asset-unlock mempool-size assertion (AssertionError: not(1 == 0) after asset_unlock_tx_too_big_fee). This is in the asset-lock functional test path, not in this PR’s notfound handling changes (net_processing.cpp and p2p_tx_download.py).

I’m leaving the branch unchanged; both failures look unrelated to this PR and need a maintainer rerun if CI needs to be refreshed.

@thepastaclaw

Copy link
Copy Markdown
Author

Done — the empty CI-retrigger commits are no longer on the branch. Current head is a97b7b45, with only the oversized-notfound fix and follow-up code/test adjustment commits.

@thepastaclaw

Copy link
Copy Markdown
Author

CI follow-up on the current red check:

  • linux64_ubsan-test / Test source failed in feature_asset_locks.py, not in this PR's notfound handling path.
  • The failure is a quorum-mining wait timeout: quorum_hash in self.nodes[0].quorum('list')[llmq_type_name] did not become true within 60s while running mine_quorum_2_nodes() / llmq_test_platform.
  • This PR only changes oversized notfound message handling and its targeted P2P coverage, so this looks unrelated to the diff.

Leaving the branch unchanged; maintainers can rerun CI if they want a clean runner result.

@UdjinM6 UdjinM6 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

utACK a97b7b4

@PastaPastaPasta
PastaPastaPasta merged commit 6a051f5 into dashpay:develop Jun 25, 2026
80 of 83 checks passed
@github-actions

Copy link
Copy Markdown

This pull request has conflicts, please rebase.

@UdjinM6 UdjinM6 added this to the 24 milestone Jun 30, 2026
PastaPastaPasta added a commit to PastaPastaPasta/dash that referenced this pull request Jul 29, 2026
a97b7b4 fix: align oversized notfound penalty (PastaClaw)
a43a27f test: avoid hardcoded oversized notfound count (PastaClaw)
f84962b fix: penalize oversized notfound messages (PastaClaw)

Pull request description:

  # fix: penalize oversized notfound messages

  ## Issue being fixed or feature implemented

  Oversized `notfound` inventory vectors were ignored after deserialization. This
  change gives them a small misbehavior score, matching the defensive treatment
  used for other inventory-vector messages, and avoids holding `cs_main` while
  deserializing the vector.

  ## What was done?

  - Deserialize `notfound` inventory vectors before taking `cs_main`.
  - Return early with a small misbehavior score when a `notfound` vector exceeds
    the maximum outstanding object/block request count.
  - Add functional coverage for the oversized `notfound` path.

  ## How Has This Been Tested?

  Environment: macOS 15.6 arm64, local Dash Core autotools build from this branch.

  - `git diff --check`
  - Local build configured with:

    ```bash
    ./configure --without-gui --disable-bench --disable-fuzz-binary \
      --disable-tests --disable-wallet
    ```

  - `make -j8 src/dashd src/dash-cli`
    - Initial parallel build hit a generated dependency-file race while building
      `dash-cli`; `dashd` linked successfully.
  - `make -j1 src/dash-cli`
  - `test/functional/p2p_tx_download.py --cachedir=/tmp/dash_func_cache_notfound`

  ## Breaking Changes

  None.

  ## Checklist

  - [x] I have performed a self-review of my own code
  - [ ] I have commented my code, particularly in hard-to-understand areas
  - [x] I have added or updated relevant unit/integration/functional/e2e tests
  - [ ] I have made corresponding changes to the documentation
  - [ ] I have assigned this pull request to a milestone
    *(for repository code-owners and collaborators only)*

ACKs for top commit:
  UdjinM6:
    utACK a97b7b4

Tree-SHA512: 35ff6b0b9e12e377e5600f4b0b2caee9582d0b4022dad04727fab54599807a5659c1837e43d30205386be34ce4dda33d4d9f687101ce67e8a694fb1a614d3914
(cherry picked from commit 6a051f5)
PastaPastaPasta added a commit to PastaPastaPasta/dash that referenced this pull request Jul 29, 2026
a97b7b4 fix: align oversized notfound penalty (PastaClaw)
a43a27f test: avoid hardcoded oversized notfound count (PastaClaw)
f84962b fix: penalize oversized notfound messages (PastaClaw)

Pull request description:

  # fix: penalize oversized notfound messages

  ## Issue being fixed or feature implemented

  Oversized `notfound` inventory vectors were ignored after deserialization. This
  change gives them a small misbehavior score, matching the defensive treatment
  used for other inventory-vector messages, and avoids holding `cs_main` while
  deserializing the vector.

  ## What was done?

  - Deserialize `notfound` inventory vectors before taking `cs_main`.
  - Return early with a small misbehavior score when a `notfound` vector exceeds
    the maximum outstanding object/block request count.
  - Add functional coverage for the oversized `notfound` path.

  ## How Has This Been Tested?

  Environment: macOS 15.6 arm64, local Dash Core autotools build from this branch.

  - `git diff --check`
  - Local build configured with:

    ```bash
    ./configure --without-gui --disable-bench --disable-fuzz-binary \
      --disable-tests --disable-wallet
    ```

  - `make -j8 src/dashd src/dash-cli`
    - Initial parallel build hit a generated dependency-file race while building
      `dash-cli`; `dashd` linked successfully.
  - `make -j1 src/dash-cli`
  - `test/functional/p2p_tx_download.py --cachedir=/tmp/dash_func_cache_notfound`

  ## Breaking Changes

  None.

  ## Checklist

  - [x] I have performed a self-review of my own code
  - [ ] I have commented my code, particularly in hard-to-understand areas
  - [x] I have added or updated relevant unit/integration/functional/e2e tests
  - [ ] I have made corresponding changes to the documentation
  - [ ] I have assigned this pull request to a milestone
    *(for repository code-owners and collaborators only)*

ACKs for top commit:
  UdjinM6:
    utACK a97b7b4

Tree-SHA512: 35ff6b0b9e12e377e5600f4b0b2caee9582d0b4022dad04727fab54599807a5659c1837e43d30205386be34ce4dda33d4d9f687101ce67e8a694fb1a614d3914
(cherry picked from commit 6a051f5)
PastaPastaPasta added a commit that referenced this pull request Jul 30, 2026
24920a0 chore: prepare v23.1.8 release (pasta)
2194248 Merge #7348: fix: penalize oversized notfound messages (pasta)
f5c72c3 Merge #7347: fix: punish invalid dstx messages (pasta)
550caf7 Merge #7465: fix(qt): handle pixel-sized fonts when scaling widgets (pasta)
e203710 Merge #7419: fix(net): bound CoinJoin message vector intake (pasta)
5f5b960 Merge #7418: fix(net): bound signing message vector intake (Pasta)
7cc2cca Merge #7450: test: make governance vote fixtures wire-valid (Pasta)
f011c80 Merge #7440: fix(net): bound governance vote signature deserialization (Pasta)
4b4d96a Merge #7442: fix(net): authorize governance inv responses via the net-layer per-peer request tracker (Pasta)
f855b13 Merge #7444: fix(net): bound bloom message vectors before allocation (Pasta)
5b5c6fb Merge #7415: fix: bound pending sig share queue (Pasta)
9bbe808 Merge #7416: fix(net): bound quorum data response vectors (Pasta)
da42f50 Merge #7424: fix: bound ChainLock seen cache (Pasta)
5b310df Merge #7438: fix: bound SPORK signature deserialization (Pasta)
e118d0c Merge #7259: fix: dangling point to cj client (Pasta)
9921621 Merge #7439: refactor: add bounded vector deserialization (Pasta)
89bdf7c Merge #7414: fix(net): throttle per-object governance vote sync requests (Pasta)
44c396d Merge #7402: fix: bound pending recovered sig queue to prevent remote OOM (Pasta)
05cfe27 Merge #7351: fix: limit signing share sessions per peer (pasta)
3ef3a5b Merge #7408: fix: bound DKG contribution blob intake (pasta)
0ea6532 Merge #7387: test: migrate governance inv cache coverage to unit tests (Pasta)
8ffdf7f Merge #7398: backport: compact block relay hardening (bitcoin#26898, bitcoin#27626, bitcoin#27743, bitcoin#26969, bitcoin#29412, bitcoin#32646, bitcoin#33296) (Pasta)
2915142 backport: bitcoin#27608 - p2p: Avoid prematurely clearing download state for other peers (PastaClaw)
90b5473 Merge #7396: fix: run of circular-dependencies with python3.15 (Pasta)
b003cdc Merge #7395: ci: update GitHub Actions pins for Node 24 (pasta)
97c3dd1 Merge #7394: fix: stabilize par help text in manpages (pasta)
8f8616b Merge #7372: backport: bitcoin#32693: depends: fix cmake compatibility error for freetype (pasta)
48f72be Merge #7360: fix: empty platformP2PPort deprecated field in protx listdiff results (pasta)
a8cccff Merge #7298: fix(qt): keep PoSe score visible when hiding banned masternodes (pasta)

Pull request description:

  Release PR for Dash Core v23.1.8, a patch release on top of v23.1.7.

  Fast-forwards from `v23.1.x` (currently at `chore: prepare v23.1.7 release`), 29 commits, no merge commits, no conflicts.

  ## Contents

  Backports of PRs already reviewed and merged on `develop`:

  `#7259` `#7347` `#7348` `#7351` `#7298` `#7360` `#7372` `#7387` `#7394` `#7395` `#7396` `#7398` `#7402` `#7408` `#7414` `#7415` `#7416` `#7418` `#7419` `#7424` `#7438` `#7439` `#7440` `#7442` `#7444` `#7450` `#7465`

  Plus `backport: bitcoin#27608`, a single commit taken from Dash #7237 because #7398's compact-block hardening depends on it. The rest of that v0.26 batch is intentionally not included on v23.1.x. The commit is byte-identical to its reviewed counterpart inside #7237.

  And release preparation: version bump, regenerated man pages, release notes, archived 23.1.7 notes.

  ## Note for reviewers: this branch was rebuilt

  An earlier revision of this PR was discarded and the branch rebuilt from scratch. Review comments on the previous revision point at commits that no longer exist, though the feedback itself was carried over (see below).

  The reason: several commits titled `Merge #NNNN` in the earlier revision contained substantial code that exists nowhere upstream — apparently written from a description of each PR rather than ported from its diff. For example, `feature_llmq_simplepose.py` is byte-identical between v23.1.7 and `develop`, yet the earlier `Merge #7408` rewrote 66 lines of it; `test/functional/p2p_governance_invs.py` does not exist on `develop` at all, yet had grown from 62 to 148 lines.

  That mislabeling matters because a commit titled `Merge #NNNN` invites less scrutiny, not more. It also had consequences: the earlier revision was **missing #7440 entirely**, and contained eleven consecutive commits that did not compile (code written against newer upstream APIs this branch does not have — `Misbehaving(Peer&)`, and `PeerIsBanned` used five commits before it was declared).

  Every commit on this branch has now been diffed against its upstream merge commit. Where a backport differs, it is because v23.1.x predates an upstream refactor and the change had to be applied to the pre-refactor file — for example #7418 and #7438 patch `signing_shares.cpp` / `spork.cpp` where upstream patches `net_signing.cpp` / `net_processing.cpp`.

  ## Dropped from this branch

  - **#7350** (`net: don't lock cs_main while reading blocks`) — dropped on review feedback. It is a 110-line lock-structure refactor of `ProcessGetBlockData` with no measured benefit, and it would add avoidable churn to the eventual master→develop merge-back. Nothing on this branch depends on it: #7398's compact-block work precedes it, and the remaining 14 commits replay with zero conflicts once it is removed. Thanks @knst.

  ## Added after the initial review pass

  - **#7351** (`fix: limit signing share sessions per peer`) — cherry-picked as a single
    commit and placed before #7402, matching upstream's merge order. The include block
    additionally carries `<ranges>`: upstream's diff adds only `<algorithm>` because develop
    already had it, whereas v23.1.x did not and the backported `GetSessionCount()` /
    `GetAnnouncementSessionCount()` use `std::ranges::count_if`.
  - **#7465** (`fix(qt): handle pixel-sized fonts when scaling widgets`) — cherry-picked from
    the five upstream commits. `optiontests.cpp` additionally includes `qt/guiutil_font.h`,
    because `fontsLoaded()` and `updateFonts()` are declared there on v23.1.x while develop
    declares them in `qt/guiutil.h`, which is all the upstream test includes.

  Two further backports were added later and applied without any adaptation --
  their diffs are byte-for-byte identical to upstream:

  - **#7347** (`fix: punish invalid dstx messages`)
  - **#7348** (`fix: penalize oversized notfound messages`)

  ## Adaptations worth flagging

  - **#7360** — upstream gates `platformP2PPort` / `platformHTTPPort` in `protx listdiff` behind `IsServiceDeprecatedRPCEnabled()`. On 23.x those deprecated fields are deliberately not enforced through gating (see `bbcd9d543e6`), so shipping the gate as-is would silently drop two fields that v23.1.7 always returned. Changed to `if (true)` with a comment, per review feedback, keeping the block aligned with `develop`. The substantive fix from #7360 — reading the live port from `netInfo` instead of the always-zero scalar — is retained.

  - **#7415** — the pending-map caps (`MAX_PENDING_SIG_SHARES_PER_NODE`, `MAX_PENDING_SIG_SHARES_TOTAL`) are backported. The additional bound upstream places on batches awaiting verification is not, because it guards a condition that does not exist here: upstream's dispatcher pushes one task per batch inside an inner loop, whereas v23.1.x pushes a single looping worker per 10 ms tick. There is no unbounded task queue to bound.

  - **Man pages** — regenerated without the `lock` debug category, which only exists under `DEBUG_LOCKCONTENTION` and so is absent from release binaries. Thanks @UdjinM6 for catching this.

  ## Known CI failure

  macOS jobs are expected to fail. `actions/upload-artifact@v6` rejects filenames containing `:`, and the Xcode SDK ships Perl man pages with `::` in the name. A release-branch-only workaround existed on the earlier revision but was dropped as it corresponds to no upstream PR. This is accepted for this release.

  ## Testing

  - Every commit through #7465 compiles individually (verified for 27 of the 29; the three additions below were verified at the tip) — verified individually, not just at the tip.
  - Full build clean; no new warnings.
  - Unit tests pass.
  - Functional tests pass: `feature_llmq_signing` (both variants), `feature_llmq_chainlocks`, `feature_llmq_dkgerrors`, `feature_llmq_is_cl_conflicts`, `p2p_instantsend`, `feature_dip3_deterministicmns` (both wallet types), `rpc_coinjoin`.
  - Qt unit tests pass (32 cases, run under the `cocoa` platform plugin so the pixel-sized
    font regression from #7465 actually executes rather than self-skipping).
  - Lint: one pre-existing `lint-cppcheck-dash` failure, identical on v23.1.7, in files this branch does not touch.

Top commit has no ACKs.

Tree-SHA512: 0fa469c9a33820aa85fbb8b90c5877409d09490f746f1300b05ceda470a600765f900bec42e5aad5d90a2d46b44e28c20e44dc4a8fe719553a072298069eaec4
thepastaclaw added a commit to thepastaclaw/dash that referenced this pull request Jul 30, 2026
Upstream landed its own "release: prepare v23.1.8" (dashpay#7493) plus parallel
merges of several PRs this branch had already backported, so most conflicts
are two adaptations of the same change rather than divergent intent.

Resolutions:
- Release artifacts (manpages, flatpak metainfo, release notes, configure.ac):
  took upstream's published v23.1.8 text as the base, then re-added the
  CoinJoin/wallet, GUI, and credits content that upstream's copy lacked.
- LLMQ/net/test files where upstream carried a refined superset (dashpay#7351,
  dashpay#7347, dashpay#7348, dashpay#7465): took upstream.
- CoinJoin client lifetime, overviewpage mixing-state, dmnstate platform
  ports, and coinjoin_tests: kept this branch's versions.
- test/functional/p2p_governance_invs.py: accepted upstream's removal in
  favor of the src/test/governance_inv_tests.cpp migration (dashpay#7387).

Auto-merge produced two duplicate definitions that would not compile
(IsSyncableObject in governance.cpp, UnserializeBatchedSigShares in
signing_shares.cpp); both were reduced to a single definition.

Co-Authored-By: Claude <noreply@anthropic.com>
@UdjinM6 UdjinM6 modified the milestones: 24, 23.1.8 Jul 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants