Correct the cap comment's memory figure

The cache costs roughly 650KB at the cap, not 600KB. Drop the claim
that the cap guards against malicious memory exhaustion: the device is
airgapped and stateless, so a psbt that bloats the cache costs the user
a power cycle, not funds.
This commit is contained in:
kdmukai
2026-08-14 17:57:34 -05:00
parent 5791d55e2f
commit ab44e97012
+3 -6
View File
@@ -34,12 +34,9 @@ class PSBTParser():
"""
# Upper bound on how many levels of derivation a single parse will cache. 1000 is
# just slightly under a 3-of-5 multisig consolidating 200 inputs and holds the cache
# to a max of about 600 kilobytes. A psbt that requires more levels will still parse
# correctly, but may have to derive some levels more than once. Capping the cache at
# a realistic upper bound protects against a maliciously crafted psbt that would
# otherwise consume unbounded memory while still providing cache wins for even
# atypically large real-world psbts.
# just slightly under a 3-of-5 multisig consolidating 200 inputs, which costs roughly
# 650 kilobytes. A psbt that needs more levels than that still parses correctly; it
# just stops getting cache hits once the cache is full.
MAX_CACHED_DERIVATIONS = 1000