Commit graph

1573 commits

Author SHA1 Message Date
Byron Hambly
3e078a0566 Merge 638855af63 into merged_master (Bitcoin PR bitcoin/bitcoin#19101) 2023-04-10 10:37:34 +00:00
Byron Hambly
a20c67310c Merge b1a672d158 into merged_master (Bitcoin PR bitcoin/bitcoin#22337) 2023-04-07 11:57:51 +00:00
Byron Hambly
238953d3bf Merge a162edfdd1 into merged_master (Bitcoin PR bitcoin/bitcoin#22359) 2023-04-07 06:48:57 +00:00
Byron Hambly
1d89a2fdfa Merge 4f1a75b1aa into merged_master (Bitcoin PR bitcoin/bitcoin#22621) 2023-04-06 13:59:37 +00:00
Andrew Chow
a584133bd6 wallet: Add include_explicit to FillPSBT 2022-10-18 16:52:31 -04:00
Allen Piscitello
420de43c1c removing code to blind issuances. PSET should be modified to include an option to blind or unblind issuances, defaulting to unblind. 2022-08-24 09:42:29 -05:00
Allen Piscitello
5954b10a1a Fixing issuance cases and half blinded cases in PSET 2022-08-18 11:20:02 -05:00
sanket1729
53a75ebbae Check the value assetion only on valid amounts
This causes crash on elements wallet when dealing with transactions that
have explicit values and confidential assets. This creates a somewhat
serious DoS attack as the sender can cause the reciever's wallet to
crash by partially blinding the change output. To make matters worse,
the wallet initially accepts the transaction, but fails while spending
the output.

This is likely caused by a combination of two bugs:
1) The wallet's current behaviour stores the complete transaction of interest
in CWalletTx instead of just Outpoints. Only that the spend time do we
iterate over all outputs, try to unblind them and check which are
isMine. When calling wtx.GetOutputValueOut() or similar calls, we hit this assertion.

While the current behaviour is okay, I think the correct way is move
the IsMine == ISMINE_NO at the start of the loop. We should not do be
any checks on outputs that are not ours. This is used in multiple
places at different parts of the codebase for different RPCs.

2) When dealing with partially blinded trasactions, ComputeBlindingData
correctly sets value = -1, and the cache byte to 1. When getting the
data again with GetBlindingData for explicit value and confidential
asset, we load the precomputed data with value = -1 and assert the
loaded value be the explicit value in the transaction. This is only true
for explicit value and explicit asset.

The changed assertion checks that written value should be same as the
explicit value that was written only when the amounts are valid
2022-08-08 03:28:51 -07:00
Andrew Poelstra
b64ca7f411 Merge 6eed792d43 into merged_master (Elements PR ElementsProject/elements#1050)
Conflicts were mostly obvious, except for those in CreateTransactionInternal.
(This function was moved from wallet.cpp to spend.cpp, and substantially
rewritten, between 0.21 and 22.0.) For those I manually applied the changes
from the diff, which wound up taking a slightly different form.

Also had to update the new test because the `addresses` field of the RPC
output was removed.
2021-10-04 15:13:47 +00:00
Andrew Poelstra
533da12c2c wallet: make sure extra OP_RETURN output is blinded when called from fundraw
This is a followup to https://github.com/ElementsProject/elements/pull/588
2021-09-30 21:54:40 +00:00
Andrew Poelstra
9afcb83baf wallet: correctly handle blinding of manually-set change addresses
When the user specifies a change address manually, use the change address
to obtain blinding parameters (either extract the blinding key from the
address or don't blind the change).

The previous behavior would assume that the change address was owned by
the wallet and always generate a blinding key internally. If the user
were to pass a non-wallet-owned change address, the result would be an
output that could not be unblinded by its owner.
2021-09-30 21:54:40 +00:00
Andrew Poelstra
9813c3e74a wallet: fix "cannot unblind IsMine output" check in SignPSBT 2021-09-30 21:54:40 +00:00
Andrew Poelstra
daa471ddd2 Merge 4c7dc0620a into merged_master (Elements PR ElementsProject/elements#1046) 2021-09-22 02:26:13 +00:00
Andrew Poelstra
c6f801d4ce PSET: encapsulate blind proof checks into one method 2021-09-21 20:33:31 +00:00
Andrew Poelstra
c88eb96e74 pset: check that we can get the blinding factors from any IsMine outputs before signing
Arguably we should do this for signrawtransaction too but it'd be a
lot of duplicated code for a deprecated workflow.
2021-09-21 20:33:31 +00:00
Andrew Poelstra
9c55d0a175 pset: only check asset/amount proofs in case both explicit+blinded values are provided 2021-09-21 20:33:28 +00:00
Andrew Poelstra
c55db47277 Merge ade32378c1 into merged_master (Elements PR ElementsProject/elements#1041) 2021-09-18 16:37:33 +00:00
Andrew Poelstra
edac5081f4 Merge 1240172eaa into merged_master (Elements PR ElementsProject/elements#1038)
Surprisingly the only conflicts were converting nullopts
2021-09-18 02:10:36 +00:00
Andrew Poelstra
ade32378c1
Merge ElementsProject/elements#1041: re-enable fallbackfee by default
1204b91c2d re-enable fallbackfee by default (Andrew Poelstra)

Pull request description:

  Upstream disabled the default `fallbackfee` option in 0.17, which caused us some user error reports in 0.18. Re-enable the option in 0.21.

ACKs for top commit:
  stevenroose:
    utACK 1204b91c2d

Tree-SHA512: 62d053405c00f5ca31ae3fb24ab8def2c9e3bd52909dfac57e65224947295a56f0b8a322ffeb0dfcdcb3103fcaf310a9554f3ed3a8490859ca82aaeae26c7fb2
2021-09-16 23:51:19 +00:00
Andrew Poelstra
388d47f9a3
Merge ElementsProject/elements#1010: Support supplying contract hash to issueasset RPC
47d43f14ad Support supplying contract hash to issueasset RPC (Steven Roose)

Pull request description:

  forward port of https://github.com/ElementsProject/elements/pull/993.
  Closes https://github.com/ElementsProject/elements/issues/985.

ACKs for top commit:
  apoelstra:
    ACK 47d43f14ad

Tree-SHA512: e29cda86291c8fe4650595129af477c6dc8648465a5305002ae521bac21a114d6a1c44738786351ac4355eafdcb0da3e4e42c8f204137f9e31e03df20a91db64
2021-09-16 23:06:23 +00:00
Andrew Poelstra
1204b91c2d re-enable fallbackfee by default 2021-09-15 22:39:33 +00:00
Steven Roose
47d43f14ad
Support supplying contract hash to issueasset RPC 2021-09-15 16:23:32 -01:00
Andrew Chow
b2a7007961 pset: verify blind value and asset proofs when signing 2021-09-11 21:02:26 -04:00
Andrew Poelstra
2ec356a185 wallet: additional patch for https://github.com/bitcoin/bitcoin/issues/20347
How to review this PR:
  * Skim the description of https://github.com/bitcoin/bitcoin/issues/20347
    to see that it's roughly "when pick_new_inputs is unset but bnb_used is
    set, one the next iteration of the loop an assumption may be wrong"
  * See that in this case, we just add another iteration to the loop...
  * ...in exactly the same way as the other place that pick_new_inputs is
    turned off, I just missed this one before
  * Observe that the regression test fails before the patch but passes after.
2021-09-06 20:06:48 +00:00
Andrew Poelstra
36e5e2a7f1 Merge 9a154599fe into merged_master (Elements PR ElementsProject/elements#900)
Surprisingly easy to do. Almost all of the diff resolution was mechanically
  * replacing boost::variant with std::variant
  * replacing Optional with std::optional
     * then replacing `nullopt` with `std::nullopt`
  * updating the RPC functions for the new RPCArg::Default type
  * update the tests/ directory to make new (since 22) tests use arrays for
    createrawtransaction outputs
  * other ad-hoc changes to function parameters etc (not too many of these)

I had to "really" change the code in PrecomputePSBTData, which was introduced
in 22.0 and affected by PSET, but this function was like 8 lines long so it
was easy.

Reviewing the diff may be a bit difficult because of the mix of mechanical
changes and ad-hoc things. Probably the most straightforward thing to do
is to redo the merge, `sed -i` to fix the boost::variant and Optional stuff,
then diff the remaining conflicts against this commit.

TODO: grep for `blindpsbt` and you will see that this RPC is still referenced
in documentation and help text even though it was deleted. Need to fix this
in 0.21 in a separate PR.
2021-09-04 19:34:14 +00:00
Russell Yanofsky
62a09a3077 refactor: remove ::vpwallets and related global variables
Move global wallet variables to WalletContext struct
2021-08-17 04:05:15 -04:00
Samuel Dobson
b1a672d158
Merge bitcoin/bitcoin#22337: wallet: Use bilingual_str for errors
92993aa5cf Change SignTransaction's input_errors to use bilingual_str (Andrew Chow)
171366e89b Use bilingual_str for address fetching functions (Andrew Chow)
9571c69b51 Add bilingual_str::clear() (Andrew Chow)

Pull request description:

  In a couple of places in the wallet, errors are `std::string`. In order for these errors to be translated, change them to use `bilingual_str`.

ACKs for top commit:
  hebasto:
    re-ACK 92993aa5cf, only rebased since my [previous](https://github.com/bitcoin/bitcoin/pull/22337#pullrequestreview-694542729) review, verified with
  klementtan:
    Code review ACK 92993aa5cf
  meshcollider:
    Code review ACK 92993aa5cf

Tree-SHA512: 5400e419dd87db8c49b67ed0964de2d44b58010a566ca246f2f0760ed9ef6a9b6f6df7a6adcb211b315b74c727bfe8c7d07eb5690b5922fa5828ceef4c83461f
2021-08-09 14:45:12 +12:00
Samuel Dobson
a162edfdd1
Merge bitcoin/bitcoin#22359: wallet: Do not set fInMempool in transactionAddedToMempool when tx is not in the mempool
fa6fd3dd6a wallet: Properly set fInMempool in mempool notifications (MarcoFalke)

Pull request description:

  A wallet method (like bumping the fee) might have set `fInMempool` to false because the transaction was removed from the mempool (See commit fa4e088cba).

  Avoid setting it back to true (incorrectly) in the validation interface background thread.

  Fixes #22357

ACKs for top commit:
  ryanofsky:
    Code review ACK fa6fd3dd6a. Only change since last review is extending workaround to `transactionRemovedFromMempool`. Since we know this workaround is imperfect and the goal of this PR is mainly to fix CI errors, I would probably be inclined to limit the workaround to as few places as possible where we have seen actual failures, instead of adding the workaround to as many places as possible, where there is some chance it might trigger new failures. But since this workaround is so straightforward and almost looks like a real fix, probably it doesn't matter.
  meshcollider:
    utACK fa6fd3dd6a

Tree-SHA512: d690136a577f1f532aa1fee80d3f6600ff7fc61286fbf564a53d7938d5ae52d33f0dbb0fef8b8c041a4970fb424f0b9f1ee7ce791e0ff8354e0000ecc9e22b84
2021-08-09 14:21:22 +12:00
fanquake
32fa49a184
make ParseOutputType return a std::optional<OutputType> 2021-08-04 19:20:32 +08:00
Andrew Poelstra
71045e76ea Merge 539023ab41 into merged_master (Bitcoin PR bitcoin/bitcoin#22492) 2021-08-03 16:35:52 +00:00
Andrew Poelstra
31c675389f Merge 185acdb5e8 into merged_master (Bitcoin PR bitcoin/bitcoin#22334) 2021-07-30 03:47:55 +00:00
Andrew Poelstra
59bf2ee204 Merge 5a95c5179c into merged_master (Bitcoin PR bitcoin/bitcoin#20191)
This broke functional tests; had to forward-port #22379 (which will be
merged in a couple PRs) to fix it.
2021-07-30 00:37:08 +00:00
Andrew Poelstra
3c24e4c1b5 Merge 045bb06ebd into merged_master (Bitcoin PR bitcoin/bitcoin#19651) 2021-07-29 23:12:48 +00:00
Andrew Poelstra
8a158e3e93 Merge 722776c0fd into merged_master (Bitcoin PR bitcoin/bitcoin#21329) 2021-07-29 22:11:13 +00:00
Andrew Poelstra
4d0fe73399 Merge e0face9235 into merged_master (Bitcoin PR bitcoin/bitcoin#22358) 2021-07-29 14:25:02 +00:00
Andrew Poelstra
b3bba59059 Merge 0553d75268 into merged_master (Bitcoin PR bitcoin/bitcoin#22154) 2021-07-29 02:50:04 +00:00
Andrew Poelstra
0afcb6d978 Merge 5c2e2afe99 into merged_master (Bitcoin PR bitcoin/bitcoin#21365)
This introduces Taproot wallet support. I fixed all the merge conflicts
and ensured that the tests pass, but this is still using the old sighash
(before Russell/Sanket/I redid it) so is not actually production ready.
Will be fixed when we bring Elements #1002 in.
2021-08-03 20:43:53 +00:00
Andrew Poelstra
1a0a945459 Merge 7c561bea52 into merged_master (Bitcoin PR bitcoin/bitcoin#21935) 2021-07-25 23:50:09 +00:00
Andrew Poelstra
18986689be Merge 907d636e5e into merged_master (Bitcoin PR bitcoin/bitcoin#21353) 2021-07-21 20:30:59 +00:00
Andrew Chow
25d99e6511 Reorder dumpwallet so that cs_main functions go first
DEBUG_LOCKORDER expects cs_wallet, cs_main, and cs_KeyStore to be
acquired in that order. However dumpwallet would take these in the order
cs_wallet, cs_KeyStore, cs_main. So when configured with
`--enable-debug`, it is possible to hit the lock order assertion when
using dumpwallet.

To fix this, cs_wallet and cs_KeyStore are no longer locked at the same
time. Instead cs_wallet will be locked first. Then the functions which
lock cs_main will be run. Lastly cs_KeyStore will be locked afterwards.
This avoids the lock order issue.

Furthermore, since GetKeyBirthTimes (only used by dumpwallet) also uses
a function that locks cs_main, and itself also locks cs_KeyStore, the
same reordering is done here.
2021-07-19 12:25:11 -04:00
Andrew Poelstra
3d6a5a2182 Merge 55a156fca0 into merged_master (Bitcoin PR bitcoin/bitcoin#21207)
git diff --color-moved=zebra is your friend
2021-07-19 03:15:44 +00:00
Andrew Poelstra
013eaeaca2 Merge 7076bba841 into merged_master (Bitcoin PR bitcoin-core/gui#346) 2021-07-18 09:43:00 +00:00
Andrew Poelstra
5f8081db1a Merge ecddd12482 into merged_master (Bitcoin PR bitcoin/bitcoin#18418) 2021-07-18 03:10:21 +00:00
Andrew Poelstra
81eb03b40c Merge 7aa41fc581 into merged_master (Bitcoin PR bitcoin/bitcoin#22042) 2021-07-17 19:14:17 +00:00
Andrew Poelstra
8b34c974c3 Merge 6b254814c0 into merged_master (Bitcoin PR bitcoin/bitcoin#17331)
This removes a lot of the craziness that was added during the 0.21
rebase 240f03f586 (Bitcoin PR #17290)
as well as a lot of other upstream craziness. It's a very positive
change but will probably be a bear to review.

There are two places where I (purposely) nontrivially changed the
logic beyond what the upstream PR did:

    1. When setting the change output positions, I used a uniform
       distribution for all change outputs and also obeyed the user's
       `change_position` choice. The old code was non-uniform and
       had a bug where it would offset the change position.

       For non-policy assets, I do not create zero-sized change
       since we would just remove them later. For the policy asset,
       I do sometimes create zero-sized change since the upstream
       logic expects it to exist.

    2. Rather than "reblinding whenever something changes" we blind
       once for size/fee estimation purposes and then again at the
       end after all potential adjustments have been made. The
       resulting code should be closer to upstream.

       We should really redo this code though because our use of the
       `BlindDetails` structure is very confusing and stateful.

    3. We consider whether or not we're using CT/CA when estimating
       the size of change outpust. This is because we now use branch
       and bound far more often (yay!) which selects coins such that
       there will be no change output. This is implemented however
       by adding a change output then dumping it to fees ... meaning
       that if we dramatically overestimate the size of a change out
       then we'll end up dramatically dumping too many coins to fees.

There are another couple small things, which I apologize for .. this
PR took me 2 hours to get compiling and 11 hours to get working(!!)
and some things got away from me.

One fun thing is that I changed CWallet::SelectCoinsMinConf to gate
an addition on coin_selection_params.m_subtract_fee_outputs ... this
is actually an upstream bug that I'll file whenever I get around to
producing a test that triggers it. (A bit hard as I have to gin up
a scenario where branch-and-bound fails to hit this codepath.)

Also, in test/functional/wallet_bumpfee.py I had to change the feerate
required to force selection to add another input from 500 to 800. I
don't know why and I don't care to figure it out.
2021-07-17 02:42:16 +00:00
Andrew Poelstra
e552043a9a Merge d4c409cf09 into merged_master (Bitcoin PR bitcoin/bitcoin#20773) 2021-07-11 07:37:55 +00:00
Andrew Poelstra
9096687c0e Merge 386ba92e83 into merged_master (Bitcoin PR bitcoin/bitcoin#21910) 2021-07-10 02:10:19 +00:00
Andrew Poelstra
d56bdbd28f Merge 32692d2681 into merged_master (Bitcoin PR bitcoin/bitcoin#21359)
I hacked up rpc_fundrawtransaction.py a little bit because our `get_address`
method here depends on nobody having called `createwallet` on a particular
node ... the "correct" fix for this would be to redo the Elements changes
to this functional test for the 0.20+ createwallet changes, but because
there will be big future changes to this test (in Elements #900 (PSET))
I did the quick/hacky thing, and will defer cleanups to a separate
post-rebase PR.
2021-07-08 16:08:49 +00:00
Andrew Poelstra
400268064d Merge f8176b768a into merged_master (Bitcoin PR bitcoin/bitcoin#21836) 2021-07-08 08:34:10 +00:00
Andrew Poelstra
3850e85010 Merge 32f1f021bf into merged_master (Bitcoin PR bitcoin/bitcoin#21817) 2021-07-07 02:29:25 +00:00