From 01b95ac6f496e24e525b2fc9d69ee8b543da65ff Mon Sep 17 00:00:00 2001 From: Martin Zumsande Date: Mon, 18 Aug 2025 21:36:01 +0200 Subject: [PATCH] index: don't commit state in BaseIndex::Rewind The committed state of an index should never be ahead of the flushed chainstate. Otherwise, in the case of an unclean shutdown, the blocks necessary to revert from the prematurely committed state would not be available, which would corrupt the coinstatsindex in particular. Instead, the index state will be committed with the next ChainStateFlushed notification. --- src/index/base.cpp | 9 ++------- 1 file changed, 2 insertions(+), 7 deletions(-) diff --git a/src/index/base.cpp b/src/index/base.cpp index fdd0e0d8af2..e984aaf5dd0 100644 --- a/src/index/base.cpp +++ b/src/index/base.cpp @@ -301,18 +301,13 @@ bool BaseIndex::Rewind(const CBlockIndex* current_tip, const CBlockIndex* new_ti } } - // In the case of a reorg, ensure persisted block locator is not stale. + // Don't commit here - the committed index state must never be ahead of the + // flushed chainstate, otherwise unclean restarts would lead to index corruption. // Pruning has a minimum of 288 blocks-to-keep and getting the index // out of sync may be possible but a users fault. // In case we reorg beyond the pruned depth, ReadBlock would // throw and lead to a graceful shutdown SetBestBlockIndex(new_tip); - if (!Commit()) { - // If commit fails, revert the best block index to avoid corruption. - SetBestBlockIndex(current_tip); - return false; - } - return true; }