Repository navigation
fix: release InstantSend tracking after mempool eviction - #7839
PastaPastaPasta wants to merge 1 commit into
Conversation
An ordinary transaction that left the mempool by expiry or size trimming before it was locked or mined stayed in the InstantSend non-locked tracker for good: TransactionIsRemoved only released Platform transfers, and the confirmation cleanup skips unmined entries. Each evicted transaction kept its full object, parent links, spent-outpoint index and timing record, outside any mempool accounting. Release the tracking for every unlocked transaction that is removed, and drop its timing record. TransactionIsRemoved is also called when a peer's transaction is rejected, which can happen for a transaction that is already mined but not yet locked or fully confirmed. Its tracking must survive so that a later conflicting lock still finds the block, so the mined check and the erase happen together under cs_nonLocked. Platform transfers keep their existing unconditional removal. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 10 minutes. View limit detailsLimit details: You’ve used all 4 included reviews currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (3)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
✅ Final review complete — no blockers (commit 312fb0d) · triage: low |
thepastaclaw
left a comment
There was a problem hiding this comment.
Final validation — Phase 1 + Phase 2
Verified the exact-head diff and surrounding removal, peer-rejection, mined-conflict, and validation-notification paths; no actionable in-scope defects were found. The cleanup preserves ordinary mined tracking under the removal mutex, retains existing Platform-transfer behavior, and adds regression coverage for expiry, trimming, and mined-conflict retention. Verification was static: no builds or tests were run; the supplied CI snapshot shows a successful amd64 container job with arm64 and slim-container jobs still queued, while local test and mutation results remain author-reported evidence.
Review provenance
Source: reviewer 1: glm-5.3-flash (agent: phase1-reviewer, role: general); reviewer 2: gpt-6.1-sol (agent: phase2-reviewer, role: general); reviewer 3: gpt-6.1-sol (agent: phase2-reviewer, role: dash-core-commit-history); final verifier: gpt-6.1-sol (agent: sol-verifier, role: final-verifier)
- Triage:
lowbygpt-6.1-sol(effort low) — This is a small, contained tracking-cleanup fix with focused regression coverage and a mined-entry guard, rather than a large or intricate change to a critical surface. - Phase 1 reviewers:
glm-5.3-flash— general (completed, effort high); agentphase1-reviewer - Phase 1 model:
glm-5.3-flash— zai quota: 5h 90% left, weekly 94% left; passed overgemini-3.8-flash-high(antigravity below 15% reserve: weekly 15% left, 5h 100% left) - Fresh verifier:
gpt-6.1-sol— final-verifier; agentsol-verifier - Phase 2 reviewers:
gpt-6.1-sol— general (completed, effort medium); agentphase2-reviewer,gpt-6.1-sol— dash-core-commit-history (completed, effort medium); agentphase2-reviewer
Potential PR merge conflictsThis is advisory only. It does not block CI, but it marks PRs that will likely need a rebase depending on merge order. If these PRs merge firstThis PR will likely need a rebase:
|
Issue being fixed or feature implemented
InstantSend tracks every unlocked transaction that enters the mempool. When an ordinary unlocked transaction left the mempool through expiry or size trimming,
TransactionIsRemovedreturned early: only Platform transfers were released. The confirmation cleanup only handles mined entries, so the evicted transaction stayed tracked for good. Its full object, parent links, spent-outpoint index and timing record were all kept outside the mempool size limit. Sustained churn of transactions that are never locked or mined grows this memory without bound. Normal lock delivery limits the exposure in practice. The achievable growth rate has not been measured.What was done?
TransactionIsRemovednow releases the tracking of any unlocked transaction through the existingRemoveNonLockedTxcleanup, which handles parent links, outpoint index and retry entries. It also drops the timing record.TransactionIsRemovedis also called when a peer's transaction is rejected. On a node without txindex, a mined transaction that is not yet locked can be replayed and rejected after a reorg clears the recent-confirmed filter. That transaction's tracking must survive so that a later conflicting lock still finds its block.RemoveNonLockedTxtherefore takes akeepMinedflag, and the mined check and the erase happen together undercs_nonLocked.This is a Dash-specific fix. Bitcoin Core has nothing to backport.
How Has This Been Tested?
macOS arm64, existing depends build:
make -j1passed../src/test/test_dash --run_test=evo_islock_testspassed all 14 cases.test/functional/p2p_instantsend.pyandtest/functional/feature_llmq_is_retroactive.pypassed.lint-includes.py,lint-include-guards.py,lint-circular-dependencies.pyandgit diff --checkpassed.New test
nonlocked_ordinary_tx_released_on_mempool_removal:NetInstantSendvalidation listener and adds standard valid transactions to the mempool. It then expires the mempool and, in a second pass, trims it. A weak pointer confirms that the last owner of each transaction is released.TransactionIsRemovedentry point. It checks that the transaction is still owned and thatRetrieveISConflictsstill reports it at that block. An earlier version of this fix removed mined entries unconditionally, and this case fails against it (exit 201).An independent review approved the change. No sustained churn or memory-exhaustion run was done. The mined negative case uses the manager's public tracking calls, not a mined block or an end-to-end replay.
Breaking Changes
None. Tracking for mined transactions is kept, and locked-transaction and Platform-transfer handling are unchanged.
Checklist:
🤖 Generated with Claude Code