mirror of
https://github.com/SeedSigner/seedsigner.git
synced 2026-10-05 15:08:25 +00:00
Correct the cap comment's memory figure
The cache costs roughly 650KB at the cap, not 600KB. Drop the claim that the cap guards against malicious memory exhaustion: the device is airgapped and stateless, so a psbt that bloats the cache costs the user a power cycle, not funds.
This commit is contained in:
@@ -34,12 +34,9 @@ class PSBTParser():
|
||||
"""
|
||||
|
||||
# Upper bound on how many levels of derivation a single parse will cache. 1000 is
|
||||
# just slightly under a 3-of-5 multisig consolidating 200 inputs and holds the cache
|
||||
# to a max of about 600 kilobytes. A psbt that requires more levels will still parse
|
||||
# correctly, but may have to derive some levels more than once. Capping the cache at
|
||||
# a realistic upper bound protects against a maliciously crafted psbt that would
|
||||
# otherwise consume unbounded memory while still providing cache wins for even
|
||||
# atypically large real-world psbts.
|
||||
# just slightly under a 3-of-5 multisig consolidating 200 inputs, which costs roughly
|
||||
# 650 kilobytes. A psbt that needs more levels than that still parses correctly; it
|
||||
# just stops getting cache hits once the cache is full.
|
||||
MAX_CACHED_DERIVATIONS = 1000
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user