mirror of
https://github.com/SeedSigner/seedsigner.git
synced 2026-10-05 15:08:25 +00:00
Correct the cap comment's memory figure
The cache costs roughly 650KB at the cap, not 600KB. Drop the claim that the cap guards against malicious memory exhaustion: the device is airgapped and stateless, so a psbt that bloats the cache costs the user a power cycle, not funds.
This commit is contained in:
@@ -34,12 +34,9 @@ class PSBTParser():
|
|||||||
"""
|
"""
|
||||||
|
|
||||||
# Upper bound on how many levels of derivation a single parse will cache. 1000 is
|
# Upper bound on how many levels of derivation a single parse will cache. 1000 is
|
||||||
# just slightly under a 3-of-5 multisig consolidating 200 inputs and holds the cache
|
# just slightly under a 3-of-5 multisig consolidating 200 inputs, which costs roughly
|
||||||
# to a max of about 600 kilobytes. A psbt that requires more levels will still parse
|
# 650 kilobytes. A psbt that needs more levels than that still parses correctly; it
|
||||||
# correctly, but may have to derive some levels more than once. Capping the cache at
|
# just stops getting cache hits once the cache is full.
|
||||||
# a realistic upper bound protects against a maliciously crafted psbt that would
|
|
||||||
# otherwise consume unbounded memory while still providing cache wins for even
|
|
||||||
# atypically large real-world psbts.
|
|
||||||
MAX_CACHED_DERIVATIONS = 1000
|
MAX_CACHED_DERIVATIONS = 1000
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user