From ab44e970125066ef2ba1a5e74c9fda6beb5071e2 Mon Sep 17 00:00:00 2001 From: kdmukai <934746+kdmukai@users.noreply.github.com> Date: Fri, 14 Aug 2026 17:57:34 -0500 Subject: [PATCH] Correct the cap comment's memory figure The cache costs roughly 650KB at the cap, not 600KB. Drop the claim that the cap guards against malicious memory exhaustion: the device is airgapped and stateless, so a psbt that bloats the cache costs the user a power cycle, not funds. --- src/seedsigner/models/psbt_parser.py | 9 +++------ 1 file changed, 3 insertions(+), 6 deletions(-) diff --git a/src/seedsigner/models/psbt_parser.py b/src/seedsigner/models/psbt_parser.py index a67fb2a6..ef746c97 100644 --- a/src/seedsigner/models/psbt_parser.py +++ b/src/seedsigner/models/psbt_parser.py @@ -34,12 +34,9 @@ class PSBTParser(): """ # Upper bound on how many levels of derivation a single parse will cache. 1000 is - # just slightly under a 3-of-5 multisig consolidating 200 inputs and holds the cache - # to a max of about 600 kilobytes. A psbt that requires more levels will still parse - # correctly, but may have to derive some levels more than once. Capping the cache at - # a realistic upper bound protects against a maliciously crafted psbt that would - # otherwise consume unbounded memory while still providing cache wins for even - # atypically large real-world psbts. + # just slightly under a 3-of-5 multisig consolidating 200 inputs, which costs roughly + # 650 kilobytes. A psbt that needs more levels than that still parses correctly; it + # just stops getting cache hits once the cache is full. MAX_CACHED_DERIVATIONS = 1000