policy.h raw

   1  // Copyright (c) 2009-2010 Satoshi Nakamoto
   2  // Copyright (c) 2009-present The Bitcoin Core developers
   3  // Distributed under the MIT software license, see the accompanying
   4  // file COPYING or http://www.opensource.org/licenses/mit-license.php.
   5  
   6  #ifndef BITCOIN_POLICY_POLICY_H
   7  #define BITCOIN_POLICY_POLICY_H
   8  
   9  #include <consensus/amount.h>
  10  #include <consensus/consensus.h>
  11  #include <consensus/validation.h>
  12  #include <primitives/transaction.h>
  13  #include <script/interpreter.h>
  14  #include <script/solver.h>
  15  #include <util/feefrac.h>
  16  
  17  #include <cstdint>
  18  #include <string>
  19  
  20  class CCoinsViewCache;
  21  class CFeeRate;
  22  class CScript;
  23  
  24  /** Default for -blockmaxweight, which controls the range of block weights the mining code will create **/
  25  static constexpr unsigned int DEFAULT_BLOCK_MAX_WEIGHT{MAX_BLOCK_WEIGHT};
  26  /** Default for -blockreservedweight **/
  27  static constexpr unsigned int DEFAULT_BLOCK_RESERVED_WEIGHT{8000};
  28  /** Default sigops cost to reserve for coinbase transaction outputs when creating block templates. */
  29  static constexpr unsigned int DEFAULT_COINBASE_OUTPUT_MAX_ADDITIONAL_SIGOPS{400};
  30  /** This accounts for the block header, var_int encoding of the transaction count and a minimally viable
  31   * coinbase transaction. It adds an additional safety margin, because even with a thorough understanding
  32   * of block serialization, it's easy to make a costly mistake when trying to squeeze every last byte.
  33   * Setting a lower value is prevented at startup. */
  34  static constexpr unsigned int MINIMUM_BLOCK_RESERVED_WEIGHT{2000};
  35  /** Default for -blockmintxfee, which sets the minimum feerate for a transaction in blocks created by mining code **/
  36  static constexpr unsigned int DEFAULT_BLOCK_MIN_TX_FEE{1};
  37  /** The maximum weight for transactions we're willing to relay/mine */
  38  static constexpr int32_t MAX_STANDARD_TX_WEIGHT{400000};
  39  /** The minimum non-witness size for transactions we're willing to relay/mine: one larger than 64  */
  40  static constexpr unsigned int MIN_STANDARD_TX_NONWITNESS_SIZE{65};
  41  /** Maximum number of signature check operations in an IsStandard() P2SH script */
  42  static constexpr unsigned int MAX_P2SH_SIGOPS{15};
  43  /** The maximum number of sigops we're willing to relay/mine in a single tx */
  44  static constexpr unsigned int MAX_STANDARD_TX_SIGOPS_COST{MAX_BLOCK_SIGOPS_COST/5};
  45  /** The maximum number of potentially executed legacy signature operations in a single standard tx */
  46  static constexpr unsigned int MAX_TX_LEGACY_SIGOPS{2'500};
  47  /** Default for -incrementalrelayfee, which sets the minimum feerate increase for mempool limiting or replacement **/
  48  static constexpr unsigned int DEFAULT_INCREMENTAL_RELAY_FEE{100};
  49  /** Default for -bytespersigop */
  50  static constexpr unsigned int DEFAULT_BYTES_PER_SIGOP{20};
  51  /** Default for -permitbaremultisig */
  52  static constexpr bool DEFAULT_PERMIT_BAREMULTISIG{true};
  53  /** The maximum number of witness stack items in a standard P2WSH script */
  54  static constexpr unsigned int MAX_STANDARD_P2WSH_STACK_ITEMS{100};
  55  /** The maximum size in bytes of each witness stack item in a standard P2WSH script */
  56  static constexpr unsigned int MAX_STANDARD_P2WSH_STACK_ITEM_SIZE{80};
  57  /** The maximum size in bytes of each witness stack item in a standard BIP 342 script (Taproot, leaf version 0xc0) */
  58  static constexpr unsigned int MAX_STANDARD_TAPSCRIPT_STACK_ITEM_SIZE{80};
  59  /** The maximum size in bytes of a standard witnessScript */
  60  static constexpr unsigned int MAX_STANDARD_P2WSH_SCRIPT_SIZE{3600};
  61  /** The maximum size of a standard ScriptSig */
  62  static constexpr unsigned int MAX_STANDARD_SCRIPTSIG_SIZE{1650};
  63  /** Min feerate for defining dust.
  64   * Changing the dust limit changes which transactions are
  65   * standard and should be done with care and ideally rarely. It makes sense to
  66   * only increase the dust limit after prior releases were already not creating
  67   * outputs below the new threshold */
  68  static constexpr unsigned int DUST_RELAY_TX_FEE{3000};
  69  /** Default for -minrelaytxfee, minimum relay fee for transactions */
  70  static constexpr unsigned int DEFAULT_MIN_RELAY_TX_FEE{100};
  71  /** Maximum number of transactions per cluster (default) */
  72  static constexpr unsigned int DEFAULT_CLUSTER_LIMIT{64};
  73  /** Maximum size of cluster in virtual kilobytes */
  74  static constexpr unsigned int DEFAULT_CLUSTER_SIZE_LIMIT_KVB{101};
  75  /** Default for -limitancestorcount, max number of in-mempool ancestors */
  76  static constexpr unsigned int DEFAULT_ANCESTOR_LIMIT{25};
  77  /** Default for -limitdescendantcount, max number of in-mempool descendants */
  78  static constexpr unsigned int DEFAULT_DESCENDANT_LIMIT{25};
  79  /** Default for -datacarrier */
  80  static const bool DEFAULT_ACCEPT_DATACARRIER = true;
  81  /**
  82   * Default setting for -datacarriersize in vbytes.
  83   */
  84  static const unsigned int MAX_OP_RETURN_RELAY = MAX_STANDARD_TX_WEIGHT / WITNESS_SCALE_FACTOR;
  85  /**
  86   * An extra transaction can be added to a package, as long as it only has one
  87   * ancestor and is no larger than this. Not really any reason to make this
  88   * configurable as it doesn't materially change DoS parameters.
  89   */
  90  static constexpr unsigned int EXTRA_DESCENDANT_TX_SIZE_LIMIT{10000};
  91  
  92  /**
  93   * Maximum number of ephemeral dust outputs allowed.
  94   */
  95  static constexpr unsigned int MAX_DUST_OUTPUTS_PER_TX{1};
  96  
  97  /**
  98   * Mandatory script verification flags that all new transactions must comply with for
  99   * them to be valid.
 100   *
 101   * Note that this does not affect consensus validity; see GetBlockScriptFlags()
 102   * for that.
 103   */
 104  static constexpr script_verify_flags MANDATORY_SCRIPT_VERIFY_FLAGS{SCRIPT_VERIFY_P2SH |
 105                                                               SCRIPT_VERIFY_DERSIG |
 106                                                               SCRIPT_VERIFY_NULLDUMMY |
 107                                                               SCRIPT_VERIFY_CHECKLOCKTIMEVERIFY |
 108                                                               SCRIPT_VERIFY_CHECKSEQUENCEVERIFY |
 109                                                               SCRIPT_VERIFY_WITNESS |
 110                                                               SCRIPT_VERIFY_TAPROOT};
 111  
 112  /**
 113   * Standard script verification flags that standard transactions will comply
 114   * with. However we do not ban/disconnect nodes that forward txs violating
 115   * the additional (non-mandatory) rules here, to improve forwards and
 116   * backwards compatibility.
 117   */
 118  static constexpr script_verify_flags STANDARD_SCRIPT_VERIFY_FLAGS{MANDATORY_SCRIPT_VERIFY_FLAGS |
 119                                                               SCRIPT_VERIFY_STRICTENC |
 120                                                               SCRIPT_VERIFY_MINIMALDATA |
 121                                                               SCRIPT_VERIFY_DISCOURAGE_UPGRADABLE_NOPS |
 122                                                               SCRIPT_VERIFY_CLEANSTACK |
 123                                                               SCRIPT_VERIFY_MINIMALIF |
 124                                                               SCRIPT_VERIFY_NULLFAIL |
 125                                                               SCRIPT_VERIFY_LOW_S |
 126                                                               SCRIPT_VERIFY_DISCOURAGE_UPGRADABLE_WITNESS_PROGRAM |
 127                                                               SCRIPT_VERIFY_WITNESS_PUBKEYTYPE |
 128                                                               SCRIPT_VERIFY_CONST_SCRIPTCODE |
 129                                                               SCRIPT_VERIFY_DISCOURAGE_UPGRADABLE_TAPROOT_VERSION |
 130                                                               SCRIPT_VERIFY_DISCOURAGE_OP_SUCCESS |
 131                                                               SCRIPT_VERIFY_DISCOURAGE_UPGRADABLE_PUBKEYTYPE};
 132  
 133  /** For convenience, standard but not mandatory verify flags. */
 134  static constexpr script_verify_flags STANDARD_NOT_MANDATORY_VERIFY_FLAGS{STANDARD_SCRIPT_VERIFY_FLAGS & ~MANDATORY_SCRIPT_VERIFY_FLAGS};
 135  
 136  /** Used as the flags parameter to sequence and nLocktime checks in non-consensus code. */
 137  static constexpr unsigned int STANDARD_LOCKTIME_VERIFY_FLAGS{LOCKTIME_VERIFY_SEQUENCE};
 138  
 139  CAmount GetDustThreshold(const CTxOut& txout, const CFeeRate& dustRelayFee);
 140  
 141  bool IsDust(const CTxOut& txout, const CFeeRate& dustRelayFee);
 142  
 143  bool IsStandard(const CScript& scriptPubKey, TxoutType& whichType);
 144  
 145  /** Get the vout index numbers of all dust outputs */
 146  std::vector<uint32_t> GetDust(const CTransaction& tx, CFeeRate dust_relay_rate);
 147  
 148  // Changing the default transaction version requires a two step process: first
 149  // adapting relay policy by bumping TX_MAX_STANDARD_VERSION, and then later
 150  // allowing the new transaction version in the wallet/RPC.
 151  static constexpr decltype(CTransaction::version) TX_MIN_STANDARD_VERSION{1};
 152  static constexpr decltype(CTransaction::version) TX_MAX_STANDARD_VERSION{3};
 153  
 154  /**
 155  * Check for standard transaction types
 156  * @return True if all outputs (scriptPubKeys) use only standard transaction forms
 157  */
 158  bool IsStandardTx(const CTransaction& tx, const std::optional<unsigned>& max_datacarrier_bytes, bool permit_bare_multisig, const CFeeRate& dust_relay_fee, std::string& reason);
 159  /**
 160   * Check for standard transaction types
 161   * @param[in] mapInputs       Map of previous transactions that have outputs we're spending
 162   * @returns valid TxValidationState if all inputs (scriptSigs) use only standard transaction forms else returns
 163   * invalid TxValidationState which states why the first invalid input is not standard
 164   */
 165  TxValidationState ValidateInputsStandardness(const CTransaction& tx, const CCoinsViewCache& mapInputs);
 166  /**
 167  * Check if the transaction is over standard P2WSH resources limit:
 168  * 3600bytes witnessScript size, 80bytes per witness stack element, 100 witness stack elements
 169  * These limits are adequate for multisignatures up to n-of-100 using OP_CHECKSIG, OP_ADD, and OP_EQUAL.
 170  *
 171  * Also enforce a maximum stack item size limit and no annexes for tapscript spends.
 172  */
 173  bool IsWitnessStandard(const CTransaction& tx, const CCoinsViewCache& mapInputs);
 174  /**
 175   * Check whether this transaction spends any witness program but P2A, including not-yet-defined ones.
 176   * May return `false` early for consensus-invalid transactions.
 177   */
 178  bool SpendsNonAnchorWitnessProg(const CTransaction& tx, const CCoinsViewCache& prevouts);
 179  
 180  /** Compute the virtual transaction size (weight reinterpreted as bytes). */
 181  int64_t GetVirtualTransactionSize(int64_t nWeight, int64_t nSigOpCost, unsigned int bytes_per_sigop);
 182  int64_t GetVirtualTransactionSize(const CTransaction& tx, int64_t nSigOpCost, unsigned int bytes_per_sigop);
 183  int64_t GetVirtualTransactionInputSize(const CTxIn& tx, int64_t nSigOpCost, unsigned int bytes_per_sigop);
 184  
 185  static inline int64_t GetVirtualTransactionSize(const CTransaction& tx)
 186  {
 187      return GetVirtualTransactionSize(tx, 0, 0);
 188  }
 189  
 190  static inline int64_t GetVirtualTransactionInputSize(const CTxIn& tx)
 191  {
 192      return GetVirtualTransactionInputSize(tx, 0, 0);
 193  }
 194  
 195  int64_t GetSigOpsAdjustedWeight(int64_t weight, int64_t sigop_cost, unsigned int bytes_per_sigop);
 196  
 197  static inline FeePerVSize ToFeePerVSize(FeePerWeight feerate) { return {feerate.fee, (feerate.size + WITNESS_SCALE_FACTOR - 1) / WITNESS_SCALE_FACTOR}; }
 198  
 199  #endif // BITCOIN_POLICY_POLICY_H
 200