validation: fix false corruption errors after refetching pruned blocks #36452

pull l0rinc wants to merge 3 commits into bitcoin:master from l0rinc:l0rinc/verify-pruned-undo changing 3 files +31 −5
  1. l0rinc commented at 12:37 PM on October 7, 2026: contributor

    Problem: getblockfrompeer restores a pruned block's body without recreating its undo record. If startup verification reaches that block at level >2, it attempts to disconnect it and reports database corruption, preventing the node from restarting.

    Fix: Stop deep verification when a pruned node reaches missing undo data, using the existing result for unavailable history. The same allowance covers missing undo on AssumeUTXO snapshot chainstates, matching the existing treatment of unavailable snapshot history. Level 4 still reconnects the newer blocks that were disconnected. verifychain returns false to indicate incomplete verification. Lower verification levels and corruption checks for undo records marked as present retain their existing behavior.

    This came up during pruned txindex review. The pending pruneassumevalid change also needs verification to handle missing undo correctly, so this fix is being split out to land first.

  2. DrahtBot added the label Validation on Oct 7, 2026
  3. DrahtBot commented at 12:37 PM on October 7, 2026: contributor

    <!--e57a25ab6845829454e8d69fc972939a-->

    The following sections might be updated with supplementary metadata relevant to reviewers and maintainers.

    <!--006a51241073e994b41acfe9ec718e94-->

    External sites

    <!--021abf342d371248e50ceaed478a90ca-->

    Reviews

    See the guideline and AI policy for information on the review process. A summary of reviews will appear here.

    <!--174a7506f384e20aa4161008e828411d-->

    Conflicts

    Reviewers, this pull request conflicts with the following ones:

    • #35307 <sub><img src="https://drahtbot.space/ack_count/bitcoin/bitcoin/35307.svg"></sub> (blockstorage: keep snapshot base in normal blockfile range by shuv-amp)

    If you consider this pull request important, please also help to review the conflicting pull requests. Ideally, start with the one that should be merged first.

    <!--5faf32d7da4f0f540f40219e4f7537a3-->

  4. andrewtoth commented at 6:12 PM on October 7, 2026: contributor

    IIUC this bug can't realistically be triggered with default checkblocks=6 config. This would require a checkblocks value of > 288 (or 0 to go all the way back) and the user would have to call getblockfrompeer for the block at the exact prune boundary. If a single fully-pruned block sits between the last non-pruned block and the fetched block with no undo, then this bug will not trigger.

  5. test: characterize verification without undo
    Restore the highest pruned block so verification reaches its missing undo before an older missing block body.
    Record the corruption error from deep verifychain checks and confirm that level 2 can still verify the available bodies.
    Record the failed deep startup check and confirm that restarting with shallow checks preserves the chain tip and restored block.
    
    Record the same corruption error from default `verifychain` checks on an AssumeUTXO snapshot tip before background validation reaches it.
    8bb9329674
  6. refactor: extract verification data allowance
    Name the existing pruning-or-snapshot allowance so the following undo-data check can reuse it.
    Rename the skipped-data flag to cover unavailable undo as well as block bodies.
    9353002199
  7. validation: stop verification at pruned undo
    Refetching a pruned block with `getblockfrompeer` restores its body but not its undo record.
    Stop startup verification and `verifychain` when their disconnect checks need missing pruned undo, rather than reporting database corruption.
    The existing allowance for unavailable snapshot history also covers missing undo on AssumeUTXO snapshot chainstates.
    Check available block bodies before stopping for missing undo, preserving the checks at lower verification levels.
    1639200575
  8. l0rinc force-pushed on Oct 8, 2026
  9. l0rinc commented at 6:41 AM on October 8, 2026: contributor

    @andrewtoth, that’s right for ordinary pruning, but this can also happen with default checks under AssumeUTXO before background validation reaches the requested block, so I’ve added a small test for that and expanded the verifychain test coverage following Ralph AI’s suggestions - hope it's clearer now.

    This change is also a prerequisite for the pruneassumevalid change I’m currently working on, which won’t retain the 288-block reorg buffer in the assumevalid region during IBD since we don’t expect reorgs there after headers-first sync.


github-metadata-mirror

This is a metadata mirror of the GitHub repository bitcoin/bitcoin. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2026-10-11 08:51 UTC

This site is hosted by @0xB10C
More mirrored repositories can be found on mirror.b10c.me