psbt.cpp raw

   1  // Copyright (c) 2009-present The Bitcoin Core developers
   2  // Distributed under the MIT software license, see the accompanying
   3  // file COPYING or http://www.opensource.org/licenses/mit-license.php.
   4  
   5  #include <psbt.h>
   6  
   7  #include <common/types.h>
   8  #include <node/types.h>
   9  #include <policy/policy.h>
  10  #include <primitives/transaction.h>
  11  #include <script/signingprovider.h>
  12  #include <util/check.h>
  13  #include <util/result.h>
  14  #include <util/strencodings.h>
  15  
  16  using common::PSBTError;
  17  
  18  PartiallySignedTransaction::PartiallySignedTransaction(const CMutableTransaction& tx, uint32_t version) : m_version(version)
  19  {
  20      assert(m_version == 0 || m_version == 2);
  21  
  22      tx_version = tx.version;
  23      fallback_locktime = tx.nLockTime;
  24      inputs.reserve(tx.vin.size());
  25      for (const CTxIn& input : tx.vin) {
  26          inputs.emplace_back(GetVersion(), input.prevout.hash, input.prevout.n, input.nSequence);
  27      }
  28      outputs.reserve(tx.vout.size());
  29      for (const CTxOut& output : tx.vout) {
  30          outputs.emplace_back(GetVersion(), output.nValue, output.scriptPubKey);
  31      }
  32  }
  33  
  34  bool PartiallySignedTransaction::IsNull() const
  35  {
  36      return inputs.empty() && outputs.empty() && unknown.empty();
  37  }
  38  
  39  bool PartiallySignedTransaction::Merge(const PartiallySignedTransaction& psbt)
  40  {
  41      // Prohibited to merge two PSBTs over different transactions
  42      std::optional<Txid> this_id = GetUniqueID();
  43      std::optional<Txid> psbt_id = psbt.GetUniqueID();
  44      if (!this_id || !psbt_id || this_id != psbt_id) {
  45          return false;
  46      }
  47      if (GetVersion() != psbt.GetVersion()) {
  48          return false;
  49      }
  50  
  51      for (unsigned int i = 0; i < inputs.size(); ++i) {
  52          if (!inputs[i].Merge(psbt.inputs[i])) {
  53              return false;
  54          }
  55      }
  56      for (unsigned int i = 0; i < outputs.size(); ++i) {
  57          if (!outputs[i].Merge(psbt.outputs[i])) {
  58              return false;
  59          }
  60      }
  61      for (auto& xpub_pair : psbt.m_xpubs) {
  62          if (!m_xpubs.contains(xpub_pair.first)) {
  63              m_xpubs[xpub_pair.first] = xpub_pair.second;
  64          } else {
  65              m_xpubs[xpub_pair.first].insert(xpub_pair.second.begin(), xpub_pair.second.end());
  66          }
  67      }
  68      if (fallback_locktime == std::nullopt && psbt.fallback_locktime != std::nullopt) fallback_locktime = psbt.fallback_locktime;
  69  
  70      // Set m_tx_modifiable only if either PSBT had it set
  71      if (m_tx_modifiable.has_value() || psbt.m_tx_modifiable.has_value()) {
  72          // In general, we AND the modifiable flags
  73          std::bitset<8> this_modifiable = m_tx_modifiable.value_or(0);
  74          std::bitset<8> psbt_modifiable = psbt.m_tx_modifiable.value_or(0);
  75          std::bitset<8> final_modifiable = this_modifiable & psbt_modifiable;
  76          // SIGHASH_SINGLE Modifiable (bit 2) needs to be bitwise OR'd
  77          final_modifiable.set(2, this_modifiable[2] || psbt_modifiable[2]);
  78  
  79          m_tx_modifiable = final_modifiable;
  80      }
  81  
  82      m_proprietary.insert(psbt.m_proprietary.begin(), psbt.m_proprietary.end());
  83      unknown.insert(psbt.unknown.begin(), psbt.unknown.end());
  84  
  85      return true;
  86  }
  87  
  88  std::optional<uint32_t> PartiallySignedTransaction::ComputeTimeLock() const
  89  {
  90      if (GetVersion() >= 2) {
  91          std::optional<uint32_t> time_lock{0};
  92          std::optional<uint32_t> height_lock{0};
  93          for (const PSBTInput& input : inputs) {
  94              if (input.time_locktime.has_value() && !input.height_locktime.has_value()) {
  95                  height_lock.reset(); // Transaction can no longer have a height locktime
  96                  if (!time_lock.has_value()) {
  97                      return std::nullopt;
  98                  }
  99              } else if (!input.time_locktime.has_value() && input.height_locktime.has_value()) {
 100                  time_lock.reset(); // Transaction can no longer have a time locktime
 101                  if (!height_lock.has_value()) {
 102                      return std::nullopt;
 103                  }
 104              }
 105              if (input.time_locktime && time_lock.has_value()) {
 106                  time_lock = std::max(time_lock, input.time_locktime);
 107              }
 108              if (input.height_locktime && height_lock.has_value()) {
 109                  height_lock = std::max(height_lock, input.height_locktime);
 110              }
 111          }
 112          if (height_lock.has_value() && *height_lock > 0) {
 113              return *height_lock;
 114          }
 115          if (time_lock.has_value() && *time_lock > 0) {
 116              return *time_lock;
 117          }
 118      }
 119      return fallback_locktime.value_or(0);
 120  }
 121  
 122  std::optional<CMutableTransaction> PartiallySignedTransaction::GetUnsignedTx() const
 123  {
 124      CMutableTransaction mtx;
 125      mtx.version = tx_version;
 126      std::optional<uint32_t> locktime = ComputeTimeLock();
 127      if (!locktime) {
 128          return std::nullopt;
 129      }
 130      mtx.nLockTime = *locktime;
 131      uint32_t max_sequence = CTxIn::SEQUENCE_FINAL;
 132      for (const PSBTInput& input : inputs) {
 133          CTxIn txin;
 134          txin.prevout.hash = input.prev_txid;
 135          txin.prevout.n = input.prev_out;
 136          txin.nSequence = input.sequence.value_or(max_sequence);
 137          mtx.vin.push_back(txin);
 138      }
 139      for (const PSBTOutput& output : outputs) {
 140          CTxOut txout;
 141          txout.nValue = output.amount;
 142          txout.scriptPubKey = output.script;
 143          mtx.vout.push_back(txout);
 144      }
 145      return mtx;
 146  }
 147  
 148  std::optional<Txid> PartiallySignedTransaction::GetUniqueID() const
 149  {
 150      // Get the unsigned transaction
 151      std::optional<CMutableTransaction> mtx = GetUnsignedTx();
 152      if (!mtx) {
 153          return std::nullopt;
 154      }
 155      if (GetVersion() >= 2) {
 156          for (CTxIn& txin : mtx->vin) {
 157              txin.nSequence = 0;
 158          }
 159      }
 160      return mtx->GetHash();
 161  }
 162  
 163  bool PartiallySignedTransaction::AddInput(const PSBTInput& psbtin)
 164  {
 165      // The input being added must be for this PSBT's version
 166      if (psbtin.GetVersion() != GetVersion()) {
 167          return false;
 168      }
 169  
 170      // Prevent duplicate inputs
 171      if (std::find_if(inputs.begin(), inputs.end(),
 172          [psbtin](const PSBTInput& psbt) {
 173              return psbt.prev_txid == psbtin.prev_txid && psbt.prev_out == psbtin.prev_out;
 174          }
 175      ) != inputs.end()) {
 176          return false;
 177      }
 178  
 179      if (GetVersion() < 2) {
 180          // This is a v0 psbt, so do the v0 AddInput
 181          inputs.push_back(psbtin);
 182          inputs.back().partial_sigs.clear();
 183          inputs.back().final_script_sig.clear();
 184          inputs.back().final_script_witness.SetNull();
 185          return true;
 186      }
 187  
 188      // Check inputs modifiable flag
 189      if (!m_tx_modifiable.has_value() || !m_tx_modifiable->test(0)) {
 190          return false;
 191      }
 192  
 193      // Determine if we need to iterate the inputs.
 194      // For now, we only do this if the new input has a required time lock.
 195      // BIP 370 states that we should also do this if m_tx_modifiable's bit 2 is set
 196      // (Has SIGHASH_SINGLE flag) but since we are only adding inputs at the end of the vector,
 197      // we don't care about that.
 198      bool iterate_inputs = psbtin.time_locktime != std::nullopt || psbtin.height_locktime != std::nullopt;
 199      if (iterate_inputs) {
 200          std::optional<uint32_t> old_timelock = ComputeTimeLock();
 201          if (!old_timelock) {
 202              return false;
 203          }
 204  
 205          std::optional<uint32_t> time_lock = psbtin.time_locktime;
 206          std::optional<uint32_t> height_lock = psbtin.height_locktime;
 207          bool has_sigs = false;
 208          for (const PSBTInput& input : inputs) {
 209              if (input.time_locktime.has_value() && !input.height_locktime.has_value()) {
 210                  height_lock.reset(); // Transaction can no longer have a height locktime
 211                  if (time_lock == std::nullopt) {
 212                      return false;
 213                  }
 214              } else if (!input.time_locktime.has_value() && input.height_locktime.has_value()) {
 215                  time_lock.reset(); // Transaction can no longer have a time locktime
 216                  if (height_lock == std::nullopt) {
 217                      return false;
 218                  }
 219              }
 220              if (input.time_locktime && time_lock.has_value()) {
 221                  time_lock = std::max(time_lock, input.time_locktime);
 222              }
 223              if (input.height_locktime && height_lock.has_value()) {
 224                  height_lock = std::max(height_lock, input.height_locktime);
 225              }
 226              if (input.HasSignatures()) {
 227                  has_sigs = true;
 228              }
 229          }
 230          uint32_t new_timelock = fallback_locktime.value_or(0);
 231          if (height_lock.has_value() && *height_lock > 0) {
 232              new_timelock = *height_lock;
 233          } else if (time_lock.has_value() && *time_lock > 0) {
 234              new_timelock = *time_lock;
 235          }
 236          if (has_sigs && *old_timelock != new_timelock) {
 237              return false;
 238          }
 239      }
 240  
 241      // Add the input to the end
 242      inputs.push_back(psbtin);
 243      return true;
 244  }
 245  
 246  bool PartiallySignedTransaction::AddOutput(const PSBTOutput& psbtout)
 247  {
 248      // The output being added must be for this PSBT's version
 249      if (psbtout.GetVersion() != GetVersion()) {
 250          return false;
 251      }
 252  
 253      if (GetVersion() < 2) {
 254          // This is a v0 psbt, do the v0 AddOutput
 255          outputs.push_back(psbtout);
 256          return true;
 257      }
 258  
 259      // No global tx, must be PSBTv2
 260      // Check outputs are modifiable
 261      if (!m_tx_modifiable.has_value() || !m_tx_modifiable->test(1)) {
 262          return false;
 263      }
 264      outputs.push_back(psbtout);
 265  
 266      return true;
 267  }
 268  
 269  bool PSBTInput::GetUTXO(CTxOut& utxo) const
 270  {
 271      if (non_witness_utxo) {
 272          if (prev_out >= non_witness_utxo->vout.size()) {
 273              return false;
 274          }
 275          if (non_witness_utxo->GetHash() != prev_txid) {
 276              return false;
 277          }
 278          utxo = non_witness_utxo->vout[prev_out];
 279      } else if (!witness_utxo.IsNull()) {
 280          utxo = witness_utxo;
 281      } else {
 282          return false;
 283      }
 284      return true;
 285  }
 286  
 287  COutPoint PSBTInput::GetOutPoint() const
 288  {
 289      return COutPoint(prev_txid, prev_out);
 290  }
 291  
 292  bool PSBTInput::IsNull() const
 293  {
 294      return !non_witness_utxo && witness_utxo.IsNull() && partial_sigs.empty() && unknown.empty() && hd_keypaths.empty() && redeem_script.empty() && witness_script.empty();
 295  }
 296  
 297  void PSBTInput::FillSignatureData(SignatureData& sigdata) const
 298  {
 299      if (!final_script_sig.empty()) {
 300          sigdata.scriptSig = final_script_sig;
 301          sigdata.complete = true;
 302      }
 303      if (!final_script_witness.IsNull()) {
 304          sigdata.scriptWitness = final_script_witness;
 305          sigdata.complete = true;
 306      }
 307      if (sigdata.complete) {
 308          return;
 309      }
 310  
 311      sigdata.signatures.insert(partial_sigs.begin(), partial_sigs.end());
 312      if (!redeem_script.empty()) {
 313          sigdata.redeem_script = redeem_script;
 314      }
 315      if (!witness_script.empty()) {
 316          sigdata.witness_script = witness_script;
 317      }
 318      for (const auto& key_pair : hd_keypaths) {
 319          sigdata.misc_pubkeys.emplace(key_pair.first.GetID(), key_pair);
 320      }
 321      if (!m_tap_key_sig.empty()) {
 322          sigdata.taproot_key_path_sig = m_tap_key_sig;
 323      }
 324      for (const auto& [pubkey_leaf, sig] : m_tap_script_sigs) {
 325          sigdata.taproot_script_sigs.emplace(pubkey_leaf, sig);
 326      }
 327      if (!m_tap_internal_key.IsNull()) {
 328          sigdata.tr_spenddata.internal_key = m_tap_internal_key;
 329      }
 330      if (!m_tap_merkle_root.IsNull()) {
 331          sigdata.tr_spenddata.merkle_root = m_tap_merkle_root;
 332      }
 333      for (const auto& [leaf_script, control_block] : m_tap_scripts) {
 334          sigdata.tr_spenddata.scripts.emplace(leaf_script, control_block);
 335      }
 336      for (const auto& [pubkey, leaf_origin] : m_tap_bip32_paths) {
 337          sigdata.taproot_misc_pubkeys.emplace(pubkey, leaf_origin);
 338          sigdata.tap_pubkeys.emplace(Hash160(pubkey), pubkey);
 339      }
 340      for (const auto& [hash, preimage] : ripemd160_preimages) {
 341          sigdata.ripemd160_preimages.emplace(std::vector<unsigned char>(hash.begin(), hash.end()), preimage);
 342      }
 343      for (const auto& [hash, preimage] : sha256_preimages) {
 344          sigdata.sha256_preimages.emplace(std::vector<unsigned char>(hash.begin(), hash.end()), preimage);
 345      }
 346      for (const auto& [hash, preimage] : hash160_preimages) {
 347          sigdata.hash160_preimages.emplace(std::vector<unsigned char>(hash.begin(), hash.end()), preimage);
 348      }
 349      for (const auto& [hash, preimage] : hash256_preimages) {
 350          sigdata.hash256_preimages.emplace(std::vector<unsigned char>(hash.begin(), hash.end()), preimage);
 351      }
 352      sigdata.musig2_pubkeys.insert(m_musig2_participants.begin(), m_musig2_participants.end());
 353      for (const auto& [agg_key_lh, pubnonces] : m_musig2_pubnonces) {
 354          sigdata.musig2_pubnonces[agg_key_lh].insert(pubnonces.begin(), pubnonces.end());
 355      }
 356      for (const auto& [agg_key_lh, psigs] : m_musig2_partial_sigs) {
 357          sigdata.musig2_partial_sigs[agg_key_lh].insert(psigs.begin(), psigs.end());
 358      }
 359  }
 360  
 361  void PSBTInput::FromSignatureData(const SignatureData& sigdata)
 362  {
 363      if (sigdata.complete) {
 364          partial_sigs.clear();
 365          hd_keypaths.clear();
 366          redeem_script.clear();
 367          witness_script.clear();
 368  
 369          if (!sigdata.scriptSig.empty()) {
 370              final_script_sig = sigdata.scriptSig;
 371          }
 372          if (!sigdata.scriptWitness.IsNull()) {
 373              final_script_witness = sigdata.scriptWitness;
 374          }
 375          return;
 376      }
 377  
 378      partial_sigs.insert(sigdata.signatures.begin(), sigdata.signatures.end());
 379      if (redeem_script.empty() && !sigdata.redeem_script.empty()) {
 380          redeem_script = sigdata.redeem_script;
 381      }
 382      if (witness_script.empty() && !sigdata.witness_script.empty()) {
 383          witness_script = sigdata.witness_script;
 384      }
 385      for (const auto& entry : sigdata.misc_pubkeys) {
 386          hd_keypaths.emplace(entry.second);
 387      }
 388      if (!sigdata.taproot_key_path_sig.empty()) {
 389          m_tap_key_sig = sigdata.taproot_key_path_sig;
 390      }
 391      for (const auto& [pubkey_leaf, sig] : sigdata.taproot_script_sigs) {
 392          m_tap_script_sigs.emplace(pubkey_leaf, sig);
 393      }
 394      if (!sigdata.tr_spenddata.internal_key.IsNull()) {
 395          m_tap_internal_key = sigdata.tr_spenddata.internal_key;
 396      }
 397      if (!sigdata.tr_spenddata.merkle_root.IsNull()) {
 398          m_tap_merkle_root = sigdata.tr_spenddata.merkle_root;
 399      }
 400      for (const auto& [leaf_script, control_block] : sigdata.tr_spenddata.scripts) {
 401          m_tap_scripts.emplace(leaf_script, control_block);
 402      }
 403      for (const auto& [pubkey, leaf_origin] : sigdata.taproot_misc_pubkeys) {
 404          m_tap_bip32_paths.emplace(pubkey, leaf_origin);
 405      }
 406      m_musig2_participants.insert(sigdata.musig2_pubkeys.begin(), sigdata.musig2_pubkeys.end());
 407      for (const auto& [agg_key_lh, pubnonces] : sigdata.musig2_pubnonces) {
 408          m_musig2_pubnonces[agg_key_lh].insert(pubnonces.begin(), pubnonces.end());
 409      }
 410      for (const auto& [agg_key_lh, psigs] : sigdata.musig2_partial_sigs) {
 411          m_musig2_partial_sigs[agg_key_lh].insert(psigs.begin(), psigs.end());
 412      }
 413      for (const auto& [hash, preimage] : sigdata.ripemd160_preimages) {
 414          ripemd160_preimages.emplace(std::vector<unsigned char>(hash.begin(), hash.end()), preimage);
 415      }
 416      for (const auto& [hash, preimage] : sigdata.sha256_preimages) {
 417          sha256_preimages.emplace(std::vector<unsigned char>(hash.begin(), hash.end()), preimage);
 418      }
 419      for (const auto& [hash, preimage] : sigdata.hash160_preimages) {
 420          hash160_preimages.emplace(std::vector<unsigned char>(hash.begin(), hash.end()), preimage);
 421      }
 422      for (const auto& [hash, preimage] : sigdata.hash256_preimages) {
 423          hash256_preimages.emplace(std::vector<unsigned char>(hash.begin(), hash.end()), preimage);
 424      }
 425  }
 426  
 427  bool PSBTInput::Merge(const PSBTInput& input)
 428  {
 429      if (!non_witness_utxo && input.non_witness_utxo) non_witness_utxo = input.non_witness_utxo;
 430      if (witness_utxo.IsNull() && !input.witness_utxo.IsNull()) {
 431          witness_utxo = input.witness_utxo;
 432      }
 433  
 434      partial_sigs.insert(input.partial_sigs.begin(), input.partial_sigs.end());
 435      ripemd160_preimages.insert(input.ripemd160_preimages.begin(), input.ripemd160_preimages.end());
 436      sha256_preimages.insert(input.sha256_preimages.begin(), input.sha256_preimages.end());
 437      hash160_preimages.insert(input.hash160_preimages.begin(), input.hash160_preimages.end());
 438      hash256_preimages.insert(input.hash256_preimages.begin(), input.hash256_preimages.end());
 439      hd_keypaths.insert(input.hd_keypaths.begin(), input.hd_keypaths.end());
 440      m_proprietary.insert(input.m_proprietary.begin(), input.m_proprietary.end());
 441      unknown.insert(input.unknown.begin(), input.unknown.end());
 442      m_tap_script_sigs.insert(input.m_tap_script_sigs.begin(), input.m_tap_script_sigs.end());
 443      m_tap_scripts.insert(input.m_tap_scripts.begin(), input.m_tap_scripts.end());
 444      m_tap_bip32_paths.insert(input.m_tap_bip32_paths.begin(), input.m_tap_bip32_paths.end());
 445  
 446      if (redeem_script.empty() && !input.redeem_script.empty()) redeem_script = input.redeem_script;
 447      if (witness_script.empty() && !input.witness_script.empty()) witness_script = input.witness_script;
 448      if (final_script_sig.empty() && !input.final_script_sig.empty()) final_script_sig = input.final_script_sig;
 449      if (final_script_witness.IsNull() && !input.final_script_witness.IsNull()) final_script_witness = input.final_script_witness;
 450      if (m_tap_key_sig.empty() && !input.m_tap_key_sig.empty()) m_tap_key_sig = input.m_tap_key_sig;
 451      if (m_tap_internal_key.IsNull() && !input.m_tap_internal_key.IsNull()) m_tap_internal_key = input.m_tap_internal_key;
 452      if (m_tap_merkle_root.IsNull() && !input.m_tap_merkle_root.IsNull()) m_tap_merkle_root = input.m_tap_merkle_root;
 453      m_musig2_participants.insert(input.m_musig2_participants.begin(), input.m_musig2_participants.end());
 454      for (const auto& [agg_key_lh, pubnonces] : input.m_musig2_pubnonces) {
 455          m_musig2_pubnonces[agg_key_lh].insert(pubnonces.begin(), pubnonces.end());
 456      }
 457      for (const auto& [agg_key_lh, psigs] : input.m_musig2_partial_sigs) {
 458          m_musig2_partial_sigs[agg_key_lh].insert(psigs.begin(), psigs.end());
 459      }
 460      if (sequence == std::nullopt && input.sequence != std::nullopt) sequence = input.sequence;
 461      if (time_locktime == std::nullopt && input.time_locktime != std::nullopt) time_locktime = input.time_locktime;
 462      if (height_locktime == std::nullopt && input.height_locktime != std::nullopt) height_locktime = input.height_locktime;
 463  
 464      return true;
 465  }
 466  
 467  bool PSBTInput::HasSignatures() const
 468  {
 469      return !final_script_sig.empty()
 470             || !final_script_witness.IsNull()
 471             || !partial_sigs.empty()
 472             || !m_tap_key_sig.empty()
 473             || !m_tap_script_sigs.empty()
 474             || !m_musig2_partial_sigs.empty();
 475  }
 476  
 477  void PSBTOutput::FillSignatureData(SignatureData& sigdata) const
 478  {
 479      if (!redeem_script.empty()) {
 480          sigdata.redeem_script = redeem_script;
 481      }
 482      if (!witness_script.empty()) {
 483          sigdata.witness_script = witness_script;
 484      }
 485      for (const auto& key_pair : hd_keypaths) {
 486          sigdata.misc_pubkeys.emplace(key_pair.first.GetID(), key_pair);
 487      }
 488      if (!m_tap_tree.empty() && m_tap_internal_key.IsFullyValid()) {
 489          TaprootBuilder builder;
 490          for (const auto& [depth, leaf_ver, script] : m_tap_tree) {
 491              builder.Add((int)depth, script, (int)leaf_ver, /*track=*/true);
 492          }
 493          assert(builder.IsComplete());
 494          builder.Finalize(m_tap_internal_key);
 495          TaprootSpendData spenddata = builder.GetSpendData();
 496  
 497          sigdata.tr_spenddata.internal_key = m_tap_internal_key;
 498          sigdata.tr_spenddata.Merge(spenddata);
 499          sigdata.tr_builder = builder;
 500      }
 501      for (const auto& [pubkey, leaf_origin] : m_tap_bip32_paths) {
 502          sigdata.taproot_misc_pubkeys.emplace(pubkey, leaf_origin);
 503          sigdata.tap_pubkeys.emplace(Hash160(pubkey), pubkey);
 504      }
 505      sigdata.musig2_pubkeys.insert(m_musig2_participants.begin(), m_musig2_participants.end());
 506  }
 507  
 508  void PSBTOutput::FromSignatureData(const SignatureData& sigdata)
 509  {
 510      if (redeem_script.empty() && !sigdata.redeem_script.empty()) {
 511          redeem_script = sigdata.redeem_script;
 512      }
 513      if (witness_script.empty() && !sigdata.witness_script.empty()) {
 514          witness_script = sigdata.witness_script;
 515      }
 516      for (const auto& entry : sigdata.misc_pubkeys) {
 517          hd_keypaths.emplace(entry.second);
 518      }
 519      if (!sigdata.tr_spenddata.internal_key.IsNull()) {
 520          m_tap_internal_key = sigdata.tr_spenddata.internal_key;
 521      }
 522      if (sigdata.tr_builder.has_value() && sigdata.tr_builder->HasScripts()) {
 523          m_tap_tree = sigdata.tr_builder->GetTreeTuples();
 524      }
 525      for (const auto& [pubkey, leaf_origin] : sigdata.taproot_misc_pubkeys) {
 526          m_tap_bip32_paths.emplace(pubkey, leaf_origin);
 527      }
 528      m_musig2_participants.insert(sigdata.musig2_pubkeys.begin(), sigdata.musig2_pubkeys.end());
 529  }
 530  
 531  bool PSBTOutput::IsNull() const
 532  {
 533      return redeem_script.empty() && witness_script.empty() && hd_keypaths.empty() && unknown.empty();
 534  }
 535  
 536  bool PSBTOutput::Merge(const PSBTOutput& output)
 537  {
 538      hd_keypaths.insert(output.hd_keypaths.begin(), output.hd_keypaths.end());
 539      m_proprietary.insert(output.m_proprietary.begin(), output.m_proprietary.end());
 540      unknown.insert(output.unknown.begin(), output.unknown.end());
 541      m_tap_bip32_paths.insert(output.m_tap_bip32_paths.begin(), output.m_tap_bip32_paths.end());
 542  
 543      if (redeem_script.empty() && !output.redeem_script.empty()) redeem_script = output.redeem_script;
 544      if (witness_script.empty() && !output.witness_script.empty()) witness_script = output.witness_script;
 545      if (m_tap_internal_key.IsNull() && !output.m_tap_internal_key.IsNull()) m_tap_internal_key = output.m_tap_internal_key;
 546      if (m_tap_tree.empty() && !output.m_tap_tree.empty()) m_tap_tree = output.m_tap_tree;
 547      m_musig2_participants.insert(output.m_musig2_participants.begin(), output.m_musig2_participants.end());
 548  
 549      return true;
 550  }
 551  
 552  bool PSBTInputSigned(const PSBTInput& input)
 553  {
 554      return !input.final_script_sig.empty() || !input.final_script_witness.IsNull();
 555  }
 556  
 557  bool PSBTInputSignedAndVerified(const PartiallySignedTransaction& psbt, unsigned int input_index, const PrecomputedTransactionData* txdata)
 558  {
 559      CTxOut utxo;
 560      assert(input_index < psbt.inputs.size());
 561      const PSBTInput& input = psbt.inputs[input_index];
 562  
 563      if (input.non_witness_utxo) {
 564          // If we're taking our information from a non-witness UTXO, verify that it matches the prevout.
 565          COutPoint prevout = input.GetOutPoint();
 566          if (prevout.n >= input.non_witness_utxo->vout.size()) {
 567              return false;
 568          }
 569          if (input.non_witness_utxo->GetHash() != prevout.hash) {
 570              return false;
 571          }
 572          utxo = input.non_witness_utxo->vout[prevout.n];
 573      } else if (!input.witness_utxo.IsNull()) {
 574          utxo = input.witness_utxo;
 575      } else {
 576          return false;
 577      }
 578  
 579      std::optional<CMutableTransaction> unsigned_tx = psbt.GetUnsignedTx();
 580      if (!unsigned_tx) {
 581          return false;
 582      }
 583      const CMutableTransaction& tx = *unsigned_tx;
 584      if (txdata) {
 585          return VerifyScript(input.final_script_sig, utxo.scriptPubKey, &input.final_script_witness, STANDARD_SCRIPT_VERIFY_FLAGS, MutableTransactionSignatureChecker{&tx, input_index, utxo.nValue, *txdata, MissingDataBehavior::FAIL});
 586      } else {
 587          return VerifyScript(input.final_script_sig, utxo.scriptPubKey, &input.final_script_witness, STANDARD_SCRIPT_VERIFY_FLAGS, MutableTransactionSignatureChecker{&tx, input_index, utxo.nValue, MissingDataBehavior::FAIL});
 588      }
 589  }
 590  
 591  size_t CountPSBTUnsignedInputs(const PartiallySignedTransaction& psbt) {
 592      size_t count = 0;
 593      for (const auto& input : psbt.inputs) {
 594          if (!PSBTInputSigned(input)) {
 595              count++;
 596          }
 597      }
 598  
 599      return count;
 600  }
 601  
 602  void UpdatePSBTOutput(const SigningProvider& provider, PartiallySignedTransaction& psbt, int index)
 603  {
 604      std::optional<CMutableTransaction> unsigned_tx = psbt.GetUnsignedTx();
 605      if (!unsigned_tx) {
 606          return;
 607      }
 608      CMutableTransaction& tx = *unsigned_tx;
 609      const CTxOut& out = tx.vout.at(index);
 610      PSBTOutput& psbt_out = psbt.outputs.at(index);
 611  
 612      // Fill a SignatureData with output info
 613      SignatureData sigdata;
 614      psbt_out.FillSignatureData(sigdata);
 615  
 616      // Construct a would-be spend of this output, to update sigdata with.
 617      // Note that ProduceSignature is used to fill in metadata (not actual signatures),
 618      // so provider does not need to provide any private keys (it can be a HidingSigningProvider).
 619      MutableTransactionSignatureCreator creator(tx, /*input_idx=*/0, out.nValue, {.sighash_type = SIGHASH_ALL});
 620      ProduceSignature(provider, creator, out.scriptPubKey, sigdata);
 621  
 622      // Put redeem_script, witness_script, key paths, into PSBTOutput.
 623      psbt_out.FromSignatureData(sigdata);
 624  }
 625  
 626  std::optional<PrecomputedTransactionData> PrecomputePSBTData(const PartiallySignedTransaction& psbt)
 627  {
 628      std::optional<CMutableTransaction> unsigned_tx = psbt.GetUnsignedTx();
 629      if (!unsigned_tx) {
 630          return std::nullopt;
 631      }
 632      const CMutableTransaction& tx = *unsigned_tx;
 633      bool have_all_spent_outputs = true;
 634      std::vector<CTxOut> utxos;
 635      for (const PSBTInput& input : psbt.inputs) {
 636          if (!input.GetUTXO(utxos.emplace_back())) have_all_spent_outputs = false;
 637      }
 638      PrecomputedTransactionData txdata;
 639      if (have_all_spent_outputs) {
 640          txdata.Init(tx, std::move(utxos), true);
 641      } else {
 642          txdata.Init(tx, {}, true);
 643      }
 644      return txdata;
 645  }
 646  
 647  PSBTError SignPSBTInput(const SigningProvider& provider, PartiallySignedTransaction& psbt, int index, const PrecomputedTransactionData* txdata, const common::PSBTFillOptions& options,  SignatureData* out_sigdata)
 648  {
 649      PSBTInput& input = psbt.inputs.at(index);
 650      std::optional<CMutableTransaction> unsigned_tx = psbt.GetUnsignedTx();
 651      if (!unsigned_tx) {
 652          return PSBTError::INVALID_TX;
 653      }
 654      const CMutableTransaction& tx = *unsigned_tx;
 655  
 656      if (PSBTInputSignedAndVerified(psbt, index, txdata)) {
 657          return PSBTError::OK;
 658      }
 659  
 660      // Fill SignatureData with input info
 661      SignatureData sigdata;
 662      input.FillSignatureData(sigdata);
 663  
 664      // Get UTXO
 665      bool require_witness_sig = false;
 666      CTxOut utxo;
 667  
 668      if (input.non_witness_utxo) {
 669          // If we're taking our information from a non-witness UTXO, verify that it matches the prevout.
 670          COutPoint prevout = input.GetOutPoint();
 671          if (prevout.n >= input.non_witness_utxo->vout.size()) {
 672              return PSBTError::MISSING_INPUTS;
 673          }
 674          if (input.non_witness_utxo->GetHash() != prevout.hash) {
 675              return PSBTError::MISSING_INPUTS;
 676          }
 677          utxo = input.non_witness_utxo->vout[prevout.n];
 678      } else if (!input.witness_utxo.IsNull()) {
 679          utxo = input.witness_utxo;
 680          // When we're taking our information from a witness UTXO, we can't verify it is actually data from
 681          // the output being spent. This is safe in case a witness signature is produced (which includes this
 682          // information directly in the hash), but not for non-witness signatures. Remember that we require
 683          // a witness signature in this situation.
 684          require_witness_sig = true;
 685      } else {
 686          return PSBTError::MISSING_INPUTS;
 687      }
 688  
 689      // Get the sighash type
 690      // If both the field and the parameter are provided, they must match
 691      // If only the parameter is provided, use it and add it to the PSBT if it is other than SIGHASH_DEFAULT
 692      // for all input types, and not SIGHASH_ALL for non-taproot input types.
 693      // If neither are provided, use SIGHASH_DEFAULT if it is taproot, and SIGHASH_ALL for everything else.
 694      int sighash{options.sighash_type.value_or(utxo.scriptPubKey.IsPayToTaproot() ? SIGHASH_DEFAULT : SIGHASH_ALL)};
 695  
 696      // For user safety, the desired sighash must be provided if the PSBT wants something other than the default set in the previous line.
 697      if (input.sighash_type && input.sighash_type != sighash) {
 698          return PSBTError::SIGHASH_MISMATCH;
 699      }
 700      // Set the PSBT sighash field when sighash is not DEFAULT or ALL
 701      // DEFAULT is allowed for non-taproot inputs since DEFAULT may be passed for them (e.g. the psbt being signed also has taproot inputs)
 702      // Note that signing already aliases DEFAULT to ALL for non-taproot inputs.
 703      if (utxo.scriptPubKey.IsPayToTaproot() ? sighash != SIGHASH_DEFAULT :
 704                                              (sighash != SIGHASH_DEFAULT && sighash != SIGHASH_ALL)) {
 705          input.sighash_type = sighash;
 706      }
 707  
 708      // Check all existing signatures use the sighash type
 709      if (sighash == SIGHASH_DEFAULT) {
 710          if (!input.m_tap_key_sig.empty() && input.m_tap_key_sig.size() != 64) {
 711              return PSBTError::SIGHASH_MISMATCH;
 712          }
 713          for (const auto& [_, sig] : input.m_tap_script_sigs) {
 714              if (sig.size() != 64) return PSBTError::SIGHASH_MISMATCH;
 715          }
 716      } else {
 717          if (!input.m_tap_key_sig.empty() && (input.m_tap_key_sig.size() != 65 || input.m_tap_key_sig.back() != sighash)) {
 718              return PSBTError::SIGHASH_MISMATCH;
 719          }
 720          for (const auto& [_, sig] : input.m_tap_script_sigs) {
 721              if (sig.size() != 65 || sig.back() != sighash) return PSBTError::SIGHASH_MISMATCH;
 722          }
 723          for (const auto& [_, sig] : input.partial_sigs) {
 724              if (sig.second.back() != sighash) return PSBTError::SIGHASH_MISMATCH;
 725          }
 726      }
 727  
 728      sigdata.witness = false;
 729      bool sig_complete;
 730      if (txdata == nullptr) {
 731          sig_complete = ProduceSignature(provider, DUMMY_SIGNATURE_CREATOR, utxo.scriptPubKey, sigdata);
 732      } else {
 733          MutableTransactionSignatureCreator creator(tx, index, utxo.nValue, txdata, {.sighash_type = sighash});
 734          sig_complete = ProduceSignature(provider, creator, utxo.scriptPubKey, sigdata);
 735      }
 736      // Verify that a witness signature was produced in case one was required.
 737      if (require_witness_sig && !sigdata.witness) return PSBTError::INCOMPLETE;
 738  
 739      // If we are not finalizing, set sigdata.complete to false to not set the scriptWitness
 740      if (!options.finalize && sigdata.complete) sigdata.complete = false;
 741  
 742      input.FromSignatureData(sigdata);
 743  
 744      // If we have a witness signature, put a witness UTXO.
 745      if (sigdata.witness) {
 746          input.witness_utxo = utxo;
 747          // We can remove the non_witness_utxo if and only if there are no non-segwit or segwit v0
 748          // inputs in this transaction. Since this requires inspecting the entire transaction, this
 749          // is something for the caller to deal with (i.e. FillPSBT).
 750      }
 751  
 752      // Fill in the missing info
 753      if (out_sigdata) {
 754          out_sigdata->missing_pubkeys = sigdata.missing_pubkeys;
 755          out_sigdata->missing_sigs = sigdata.missing_sigs;
 756          out_sigdata->missing_redeem_script = sigdata.missing_redeem_script;
 757          out_sigdata->missing_witness_script = sigdata.missing_witness_script;
 758      }
 759  
 760      return sig_complete ? PSBTError::OK : PSBTError::INCOMPLETE;
 761  }
 762  
 763  void RemoveUnnecessaryTransactions(PartiallySignedTransaction& psbtx)
 764  {
 765      // Figure out if any non_witness_utxos should be dropped
 766      std::vector<unsigned int> to_drop;
 767      for (unsigned int i = 0; i < psbtx.inputs.size(); ++i) {
 768          const auto& input = psbtx.inputs.at(i);
 769          int wit_ver;
 770          std::vector<unsigned char> wit_prog;
 771          if (input.witness_utxo.IsNull() || !input.witness_utxo.scriptPubKey.IsWitnessProgram(wit_ver, wit_prog)) {
 772              // There's a non-segwit input, so we cannot drop any non_witness_utxos
 773              to_drop.clear();
 774              break;
 775          }
 776          if (wit_ver == 0) {
 777              // Segwit v0, so we cannot drop any non_witness_utxos
 778              to_drop.clear();
 779              break;
 780          }
 781          // non_witness_utxos cannot be dropped if the sighash type includes SIGHASH_ANYONECANPAY
 782          // Since callers should have called SignPSBTInput which updates the sighash type in the PSBT, we only
 783          // need to look at that field. If it is not present, then we can assume SIGHASH_DEFAULT or SIGHASH_ALL.
 784          if (input.sighash_type != std::nullopt && (*input.sighash_type & 0x80) == SIGHASH_ANYONECANPAY) {
 785              to_drop.clear();
 786              break;
 787          }
 788  
 789          if (input.non_witness_utxo) {
 790              to_drop.push_back(i);
 791          }
 792      }
 793  
 794      // Drop the non_witness_utxos that we can drop
 795      for (unsigned int i : to_drop) {
 796          psbtx.inputs.at(i).non_witness_utxo = nullptr;
 797      }
 798  }
 799  
 800  bool FinalizePSBT(PartiallySignedTransaction& psbtx)
 801  {
 802      // Finalize input signatures -- in case we have partial signatures that add up to a complete
 803      //   signature, but have not combined them yet (e.g. because the combiner that created this
 804      //   PartiallySignedTransaction did not understand them), this will combine them into a final
 805      //   script.
 806      bool complete = true;
 807      std::optional<PrecomputedTransactionData> txdata_res = PrecomputePSBTData(psbtx);
 808      if (!txdata_res) {
 809          return false;
 810      }
 811      const PrecomputedTransactionData& txdata = *txdata_res;
 812      for (unsigned int i = 0; i < psbtx.inputs.size(); ++i) {
 813          PSBTInput& input = psbtx.inputs.at(i);
 814          complete &= (SignPSBTInput(DUMMY_SIGNING_PROVIDER, psbtx, i, &txdata, {.sighash_type = input.sighash_type, .finalize = true}, /*out_sigdata=*/nullptr) == PSBTError::OK);
 815      }
 816  
 817      return complete;
 818  }
 819  
 820  bool FinalizeAndExtractPSBT(PartiallySignedTransaction& psbtx, CMutableTransaction& result)
 821  {
 822      // It's not safe to extract a PSBT that isn't finalized, and there's no easy way to check
 823      //   whether a PSBT is finalized without finalizing it, so we just do this.
 824      if (!FinalizePSBT(psbtx)) {
 825          return false;
 826      }
 827  
 828      std::optional<CMutableTransaction> unsigned_tx = psbtx.GetUnsignedTx();
 829      if (!unsigned_tx) {
 830          return false;
 831      }
 832      result = *unsigned_tx;
 833      for (unsigned int i = 0; i < result.vin.size(); ++i) {
 834          result.vin[i].scriptSig = psbtx.inputs[i].final_script_sig;
 835          result.vin[i].scriptWitness = psbtx.inputs[i].final_script_witness;
 836      }
 837      return true;
 838  }
 839  
 840  std::optional<PartiallySignedTransaction> CombinePSBTs(const std::vector<PartiallySignedTransaction>& psbtxs)
 841  {
 842      PartiallySignedTransaction out = psbtxs[0]; // Copy the first one
 843  
 844      // Merge
 845      for (auto it = std::next(psbtxs.begin()); it != psbtxs.end(); ++it) {
 846          if (!out.Merge(*it)) {
 847              return std::nullopt;
 848          }
 849      }
 850      return out;
 851  }
 852  
 853  std::string PSBTRoleName(PSBTRole role) {
 854      switch (role) {
 855      case PSBTRole::CREATOR: return "creator";
 856      case PSBTRole::UPDATER: return "updater";
 857      case PSBTRole::SIGNER: return "signer";
 858      case PSBTRole::FINALIZER: return "finalizer";
 859      case PSBTRole::EXTRACTOR: return "extractor";
 860      } // no default case, so the compiler can warn about missing cases
 861      assert(false);
 862  }
 863  
 864  util::Result<PartiallySignedTransaction> DecodeBase64PSBT(const std::string& base64_tx)
 865  {
 866      auto tx_data = DecodeBase64(base64_tx);
 867      if (!tx_data) {
 868          return util::Error{Untranslated("invalid base64")};
 869      }
 870      return DecodeRawPSBT(MakeByteSpan(*tx_data));
 871  }
 872  
 873  util::Result<PartiallySignedTransaction> DecodeRawPSBT(std::span<const std::byte> tx_data)
 874  {
 875      SpanReader ss_data{tx_data};
 876      try {
 877          PartiallySignedTransaction psbt(deserialize, ss_data);
 878          if (!ss_data.empty()) {
 879              return util::Error{Untranslated("extra data after PSBT")};
 880          }
 881          return psbt;
 882      } catch (const std::exception& e) {
 883          return util::Error{Untranslated(e.what())};
 884      }
 885  }
 886  
 887  uint32_t PartiallySignedTransaction::GetVersion() const
 888  {
 889      if (m_version != std::nullopt) {
 890          return *m_version;
 891      }
 892      return 0;
 893  }
 894