@@ -6,15 +6,39 @@ type: newsletter
66layout : newsletter
77lang : en
88---
9- This week's newsletter includes action items related to the
10- newly-proposed BIP322, Bitcoin Core 0.17, and Optech's upcoming Paris
11- workshop; a link to the C-Lightning 0.6.1 release, more information
12- about BIP322, and some details about the Bustapay proposal; plus brief
13- descriptions of notable merges in popular Bitcoin infrastructure
14- projects.
9+ This week's newsletter includes action items related to the security
10+ release of Bitcoin Core 0.16.3 and Bitcoin Core 0.17RC4, the
11+ newly-proposed BIP322, and Optech's upcoming Paris workshop; a link to
12+ the C-Lightning 0.6.1 release, more information about BIP322, and some
13+ details about the Bustapay proposal; plus brief descriptions of notable
14+ merges in popular Bitcoin infrastructure projects.
1515
1616## Action items
1717
18+ - ** Upgrade to Bitcoin Core 0.16.3 to fix denial-of-service
19+ vulnerability:** a bug introduced in Bitcoin Core 0.14.0 and affecting
20+ all subsequent versions through to 0.16.2 will cause Bitcoin Core to
21+ crash when attempting to validate a block containing a transaction
22+ that attempts to spend the same input twice. Such blocks would be
23+ invalid and so can only be created by miners willing to lose the
24+ allowed income from having created a block (at least 12.5 XBT or
25+ $80,000 USD).
26+
27+ Patches for [ master] [ dup txin master ] and [ 0.16] [ dup txin 0.16 ]
28+ branches were submitted for public review yesterday, the 0.16.3
29+ release has been tagged containing the patch, and binaries will
30+ be available for [ download] [ core download ] as soon as a sufficient
31+ number of well-known contributors have reproduced the deterministic
32+ build---probably later today (Tuesday). Immediate upgrade is
33+ highly recommended.
34+
35+ - ** Allocate time to test Bitcoin Core 0.17RC4:** Bitcoin Core will soon
36+ be uploading [ binaries] [ bcc 0.17 ] for 0.17 Release Candidate (RC) 4
37+ containing the same patch for the DoS vulnerability described above.
38+ All testers of previous release candidates should upgrade. Testing is
39+ greatly appreciated and can help ensure the quality of the final
40+ release.
41+
1842- ** Review proposed BIP322 for generic message signing:** this
1943 [ recently-proposed] [ BIP322 proposal ] BIP will allow users to create
2044 signed messages for all currently-used types of Bitcoin addresses,
@@ -26,11 +50,6 @@ projects.
2650 compatible with your organization's needs. See the News section below
2751 for additional details.
2852
29- - ** Allocate time to test Bitcoin Core 0.17RC3:** Bitcoin Core has
30- uploaded [ binaries] [ bcc 0.17 ] for 0.17 Release Candidate (RC) 3.
31- Testing is greatly appreciated and can help ensure the quality of the
32- final release.
33-
3453- ** [ Optech Paris workshop] [ workshop ] November 12-13:** member
3554 companies should [ send us an email] [ optech email ] to reserve spots for
3655 your engineers. Planned topics include a comparison of two methods
@@ -142,7 +161,7 @@ wait until version 0.18 in about six months from now.*
142161 [ Bitcoin Core #14168 ] [ ] . This issue, along with a number of other issues such
143162 as [ Bitcoin Core #10973 ] [ ] (Refactor: separate wallet from node) and [ Bitcoin
144163 Core #14180 ] [ ] (Run all tests even if wallet is not compiled) are part of a
145- long-term effort to disentagle the wallet code from the server code. Doing so
164+ long-term effort to disentangle the wallet code from the server code. Doing so
146165 provides a number of benefits including easier code maintenance, better
147166 opportunities for testing individual components, and potentially more secure
148167 software if the wallet component is moved to its own process.
@@ -177,3 +196,6 @@ wait until version 0.18 in about six months from now.*
177196[ bustapay proposal ] : https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2018-August/016340.html
178197[ bustapay sjors ] : https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2018-September/016383.html
179198[ p2p reject ] : https://btcinformation.org/en/developer-reference#reject
199+ [ dup txin master ] : https://github.com/bitcoin/bitcoin/pull/14247
200+ [ dup txin 0.16 ] : https://github.com/bitcoin/bitcoin/pull/14249
201+ [ core download ] : https://bitcoincore.org/en/download
0 commit comments