Skip to content

Bump litecoin-core 0.21.5.6 - #38

Merged
pedrobranco merged 1 commit into
masterfrom
bugfix/bump-litecoin-0.21.5.6
Aug 4, 2026
Merged

pedrobranco merged 1 commit into
masterfrom
bugfix/bump-litecoin-0.21.5.6

Conversation

@joaomatbarbosa

@joaomatbarbosa joaomatbarbosa commented Aug 3, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Bump pinned Litecoin Core version in 0.21/Dockerfile from 0.21.2.2 to 0.21.5.6.
  • Upstream release is an urgent security fix hardening MWEB validation (node-wide limits on light-client service requests, relay-policy limits for tx weight/input counts, malformed MWEB data handling). Strongly recommended for all users.
  • Our production node (uphold/litecoin-core:0.21) has been on MWEB-enabled versions since activation, so it validates MWEB blocks regardless of whether we use MWEB txs ourselves.

Release notes: https://github.com/litecoin-project/litecoin/releases/tag/v0.21.5.6

Test plan

  • CI build/push succeeds for 0.21 tag
  • Pull new image, boot litecoind, confirm sync + RPC respond
  • Roll out to production litecoin-0 instance, monitor logs/peers after restart

Copilot AI review requested due to automatic review settings August 3, 2026 13:18

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Bumps the pinned Litecoin Core patch version used by the 0.21 Docker image to pick up upstream security hardening around MWEB validation, while keeping the image’s overall build and runtime flow the same.

Changes:

  • Update LITECOIN_VERSION in 0.21/Dockerfile from 0.21.2.2 to 0.21.5.6.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread 0.21/Dockerfile
Urgent security release hardening MWEB validation (resource-exhaustion
protections, relay-policy tx weight/input limits). Strongly recommended
by upstream for all users.

https://github.com/litecoin-project/litecoin/releases/tag/v0.21.5.6
@joaomatbarbosa
joaomatbarbosa force-pushed the bugfix/bump-litecoin-0.21.5.6 branch from 72baa50 to 797e0d6 Compare August 3, 2026 13:22
@pedrobranco
pedrobranco merged commit 0b9e05e into master Aug 4, 2026
69 of 86 checks passed
@pedrobranco
pedrobranco deleted the bugfix/bump-litecoin-0.21.5.6 branch August 4, 2026 13:35
joaomatbarbosa added a commit that referenced this pull request Aug 6, 2026
pgp.mit.edu, keyserver.pgp.com and the sks-keyservers.net pool are
unreachable, so key import fails and every build (0.10 through 0.21)
dies at that step. This blocked publishing the 0.21.5.6 security bump
from #38 -- `build (0.21)` failed 5 consecutive attempts on master and
uphold/litecoin-core:0.21 still serves the image built in Feb 2024.

Switch to keys.openpgp.org with keyserver.ubuntu.com as fallback.

Also pin both Litecoin signing keys by full 40-hex fingerprint instead
of 64-bit long key ID, matching what docker-dash-core already does and
what the gosu key here already used. Fetching by long ID leaves the
import open to key-ID collision; with a full fingerprint gpg rejects
any key that does not match.

  3620E9D387E55666 -> D35621D53A1CC6A3456758D03620E9D387E55666
                      David Burkett <davidburkett38@gmail.com>
  FE3348877809386C -> 59CAF0E96F23F53747945FD4FE3348877809386C
                      Adrian Gallagher <thrasher@addictionsoftware.com>
pedrobranco pushed a commit that referenced this pull request Aug 6, 2026
pgp.mit.edu, keyserver.pgp.com and the sks-keyservers.net pool are
unreachable, so key import fails and every build (0.10 through 0.21)
dies at that step. This blocked publishing the 0.21.5.6 security bump
from #38 -- `build (0.21)` failed 5 consecutive attempts on master and
uphold/litecoin-core:0.21 still serves the image built in Feb 2024.

Switch to keys.openpgp.org with keyserver.ubuntu.com as fallback.

Also pin both Litecoin signing keys by full 40-hex fingerprint instead
of 64-bit long key ID, matching what docker-dash-core already does and
what the gosu key here already used. Fetching by long ID leaves the
import open to key-ID collision; with a full fingerprint gpg rejects
any key that does not match.

  3620E9D387E55666 -> D35621D53A1CC6A3456758D03620E9D387E55666
                      David Burkett <davidburkett38@gmail.com>
  FE3348877809386C -> 59CAF0E96F23F53747945FD4FE3348877809386C
                      Adrian Gallagher <thrasher@addictionsoftware.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants