walletdb.cpp raw

   1  // Copyright (c) 2009-2010 Satoshi Nakamoto
   2  // Copyright (c) 2009-present The Bitcoin Core developers
   3  // Distributed under the MIT software license, see the accompanying
   4  // file COPYING or http://www.opensource.org/licenses/mit-license.php.
   5  
   6  #include <bitcoin-build-config.h> // IWYU pragma: keep
   7  
   8  #include <wallet/walletdb.h>
   9  
  10  #include <common/system.h>
  11  #include <key_io.h>
  12  #include <primitives/transaction_identifier.h>
  13  #include <protocol.h>
  14  #include <script/script.h>
  15  #include <serialize.h>
  16  #include <sync.h>
  17  #include <util/bip32.h>
  18  #include <util/check.h>
  19  #include <util/fs.h>
  20  #include <util/time.h>
  21  #include <util/translation.h>
  22  #include <wallet/migrate.h>
  23  #include <wallet/sqlite.h>
  24  #include <wallet/wallet.h>
  25  
  26  #include <atomic>
  27  #include <optional>
  28  #include <string>
  29  
  30  namespace wallet {
  31  namespace DBKeys {
  32  const std::string ACENTRY{"acentry"};
  33  const std::string ACTIVEEXTERNALSPK{"activeexternalspk"};
  34  const std::string ACTIVEINTERNALSPK{"activeinternalspk"};
  35  const std::string BESTBLOCK_NOMERKLE{"bestblock_nomerkle"};
  36  const std::string BESTBLOCK{"bestblock"};
  37  const std::string CRYPTED_KEY{"ckey"};
  38  const std::string CSCRIPT{"cscript"};
  39  const std::string DEFAULTKEY{"defaultkey"};
  40  const std::string DESTDATA{"destdata"};
  41  const std::string FLAGS{"flags"};
  42  const std::string HDCHAIN{"hdchain"};
  43  const std::string KEYMETA{"keymeta"};
  44  const std::string KEY{"key"};
  45  const std::string LOCKED_UTXO{"lockedutxo"};
  46  const std::string MASTER_KEY{"mkey"};
  47  const std::string MINVERSION{"minversion"};
  48  const std::string NAME{"name"};
  49  const std::string OLD_KEY{"wkey"};
  50  const std::string ORDERPOSNEXT{"orderposnext"};
  51  const std::string POOL{"pool"};
  52  const std::string PURPOSE{"purpose"};
  53  const std::string SETTINGS{"settings"};
  54  const std::string TX{"tx"};
  55  const std::string VERSION{"version"};
  56  const std::string WALLETDESCRIPTOR{"walletdescriptor"};
  57  const std::string WALLETDESCRIPTORCACHE{"walletdescriptorcache"};
  58  const std::string WALLETDESCRIPTORLHCACHE{"walletdescriptorlhcache"};
  59  const std::string WALLETDESCRIPTORCKEY{"walletdescriptorckey"};
  60  const std::string WALLETDESCRIPTORKEY{"walletdescriptorkey"};
  61  const std::string WATCHMETA{"watchmeta"};
  62  const std::string WATCHS{"watchs"};
  63  const std::unordered_set<std::string> LEGACY_TYPES{CRYPTED_KEY, CSCRIPT, DEFAULTKEY, HDCHAIN, KEYMETA, KEY, OLD_KEY, POOL, WATCHMETA, WATCHS};
  64  } // namespace DBKeys
  65  
  66  void LogDBInfo()
  67  {
  68      // Add useful DB information here. This will be printed during startup.
  69      LogInfo("Using SQLite Version %s", SQLiteDatabaseVersion());
  70  }
  71  
  72  //
  73  // WalletBatch
  74  //
  75  
  76  bool WalletBatch::WriteName(const std::string& strAddress, const std::string& strName)
  77  {
  78      return WriteIC(std::make_pair(DBKeys::NAME, strAddress), strName);
  79  }
  80  
  81  bool WalletBatch::EraseName(const std::string& strAddress)
  82  {
  83      // This should only be used for sending addresses, never for receiving addresses,
  84      // receiving addresses must always have an address book entry if they're not change return.
  85      return EraseIC(std::make_pair(DBKeys::NAME, strAddress));
  86  }
  87  
  88  bool WalletBatch::WritePurpose(const std::string& strAddress, const std::string& strPurpose)
  89  {
  90      return WriteIC(std::make_pair(DBKeys::PURPOSE, strAddress), strPurpose);
  91  }
  92  
  93  bool WalletBatch::ErasePurpose(const std::string& strAddress)
  94  {
  95      return EraseIC(std::make_pair(DBKeys::PURPOSE, strAddress));
  96  }
  97  
  98  bool WalletBatch::WriteTx(const CWalletTx& wtx)
  99  {
 100      return WriteIC(std::make_pair(DBKeys::TX, wtx.GetHash()), wtx);
 101  }
 102  
 103  bool WalletBatch::EraseTx(Txid hash)
 104  {
 105      return EraseIC(std::make_pair(DBKeys::TX, hash.ToUint256()));
 106  }
 107  
 108  bool WalletBatch::WriteKeyMetadata(const CKeyMetadata& meta, const CPubKey& pubkey, const bool overwrite)
 109  {
 110      return WriteIC(std::make_pair(DBKeys::KEYMETA, pubkey), meta, overwrite);
 111  }
 112  
 113  bool WalletBatch::WriteKey(const CPubKey& vchPubKey, const CPrivKey& vchPrivKey, const CKeyMetadata& keyMeta)
 114  {
 115      if (!WriteKeyMetadata(keyMeta, vchPubKey, false)) {
 116          return false;
 117      }
 118  
 119      // hash pubkey/privkey to accelerate wallet load
 120      const auto keypair_hash = Hash(vchPubKey, vchPrivKey);
 121  
 122      return WriteIC(std::make_pair(DBKeys::KEY, vchPubKey), std::make_pair(vchPrivKey, keypair_hash), false);
 123  }
 124  
 125  bool WalletBatch::WriteCryptedKey(const CPubKey& vchPubKey,
 126                                  const std::vector<unsigned char>& vchCryptedSecret,
 127                                  const CKeyMetadata &keyMeta)
 128  {
 129      if (!WriteKeyMetadata(keyMeta, vchPubKey, true)) {
 130          return false;
 131      }
 132  
 133      // Compute a checksum of the encrypted key
 134      uint256 checksum = Hash(vchCryptedSecret);
 135  
 136      const auto key = std::make_pair(DBKeys::CRYPTED_KEY, vchPubKey);
 137      if (!WriteIC(key, std::make_pair(vchCryptedSecret, checksum), false)) {
 138          // It may already exist, so try writing just the checksum
 139          std::vector<unsigned char> val;
 140          if (!m_batch->Read(key, val)) {
 141              return false;
 142          }
 143          if (!WriteIC(key, std::make_pair(val, checksum), true)) {
 144              return false;
 145          }
 146      }
 147      EraseIC(std::make_pair(DBKeys::KEY, vchPubKey));
 148      return true;
 149  }
 150  
 151  bool WalletBatch::WriteMasterKey(unsigned int nID, const CMasterKey& kMasterKey)
 152  {
 153      return WriteIC(std::make_pair(DBKeys::MASTER_KEY, nID), kMasterKey, true);
 154  }
 155  
 156  bool WalletBatch::EraseMasterKey(unsigned int id)
 157  {
 158      return EraseIC(std::make_pair(DBKeys::MASTER_KEY, id));
 159  }
 160  
 161  bool WalletBatch::WriteWatchOnly(const CScript &dest, const CKeyMetadata& keyMeta)
 162  {
 163      if (!WriteIC(std::make_pair(DBKeys::WATCHMETA, dest), keyMeta)) {
 164          return false;
 165      }
 166      return WriteIC(std::make_pair(DBKeys::WATCHS, dest), uint8_t{'1'});
 167  }
 168  
 169  bool WalletBatch::EraseWatchOnly(const CScript &dest)
 170  {
 171      if (!EraseIC(std::make_pair(DBKeys::WATCHMETA, dest))) {
 172          return false;
 173      }
 174      return EraseIC(std::make_pair(DBKeys::WATCHS, dest));
 175  }
 176  
 177  bool WalletBatch::WriteBestBlock(const CBlockLocator& locator)
 178  {
 179      WriteIC(DBKeys::BESTBLOCK, CBlockLocator()); // Write empty block locator so versions that require a merkle branch automatically rescan
 180      return WriteIC(DBKeys::BESTBLOCK_NOMERKLE, locator);
 181  }
 182  
 183  bool WalletBatch::ReadBestBlock(CBlockLocator& locator)
 184  {
 185      if (m_batch->Read(DBKeys::BESTBLOCK, locator) && !locator.vHave.empty()) return true;
 186      return m_batch->Read(DBKeys::BESTBLOCK_NOMERKLE, locator);
 187  }
 188  
 189  bool WalletBatch::IsEncrypted()
 190  {
 191      DataStream prefix;
 192      prefix << DBKeys::MASTER_KEY;
 193      if (auto cursor = m_batch->GetNewPrefixCursor(prefix)) {
 194          DataStream k, v;
 195          if (cursor->Next(k, v) == DatabaseCursor::Status::MORE) return true;
 196      }
 197      return false;
 198  }
 199  
 200  bool WalletBatch::WriteOrderPosNext(int64_t nOrderPosNext)
 201  {
 202      return WriteIC(DBKeys::ORDERPOSNEXT, nOrderPosNext);
 203  }
 204  
 205  bool WalletBatch::WriteActiveScriptPubKeyMan(uint8_t type, const uint256& id, bool internal)
 206  {
 207      std::string key = internal ? DBKeys::ACTIVEINTERNALSPK : DBKeys::ACTIVEEXTERNALSPK;
 208      return WriteIC(make_pair(key, type), id);
 209  }
 210  
 211  bool WalletBatch::EraseActiveScriptPubKeyMan(uint8_t type, bool internal)
 212  {
 213      const std::string key{internal ? DBKeys::ACTIVEINTERNALSPK : DBKeys::ACTIVEEXTERNALSPK};
 214      return EraseIC(make_pair(key, type));
 215  }
 216  
 217  bool WalletBatch::WriteDescriptorKey(const uint256& desc_id, const CPubKey& pubkey, const CPrivKey& privkey)
 218  {
 219      // hash pubkey/privkey to accelerate wallet load
 220      const auto keypair_hash = Hash(pubkey, privkey);
 221  
 222      return WriteIC(std::make_pair(DBKeys::WALLETDESCRIPTORKEY, std::make_pair(desc_id, pubkey)), std::make_pair(privkey, keypair_hash), false);
 223  }
 224  
 225  bool WalletBatch::WriteCryptedDescriptorKey(const uint256& desc_id, const CPubKey& pubkey, const std::vector<unsigned char>& secret)
 226  {
 227      if (!WriteIC(std::make_pair(DBKeys::WALLETDESCRIPTORCKEY, std::make_pair(desc_id, pubkey)), secret, false)) {
 228          return false;
 229      }
 230      EraseIC(std::make_pair(DBKeys::WALLETDESCRIPTORKEY, std::make_pair(desc_id, pubkey)));
 231      return true;
 232  }
 233  
 234  bool WalletBatch::WriteDescriptor(const uint256& desc_id, const WalletDescriptor& descriptor)
 235  {
 236      return WriteIC(make_pair(DBKeys::WALLETDESCRIPTOR, desc_id), descriptor);
 237  }
 238  
 239  bool WalletBatch::WriteDescriptorDerivedCache(const CExtPubKey& xpub, const uint256& desc_id, uint32_t key_exp_index, uint32_t der_index)
 240  {
 241      std::vector<unsigned char> ser_xpub(BIP32_EXTKEY_SIZE);
 242      xpub.Encode(ser_xpub.data());
 243      return WriteIC(std::make_pair(std::make_pair(DBKeys::WALLETDESCRIPTORCACHE, desc_id), std::make_pair(key_exp_index, der_index)), ser_xpub);
 244  }
 245  
 246  bool WalletBatch::WriteDescriptorParentCache(const CExtPubKey& xpub, const uint256& desc_id, uint32_t key_exp_index)
 247  {
 248      std::vector<unsigned char> ser_xpub(BIP32_EXTKEY_SIZE);
 249      xpub.Encode(ser_xpub.data());
 250      return WriteIC(std::make_pair(std::make_pair(DBKeys::WALLETDESCRIPTORCACHE, desc_id), key_exp_index), ser_xpub);
 251  }
 252  
 253  bool WalletBatch::WriteDescriptorLastHardenedCache(const CExtPubKey& xpub, const uint256& desc_id, uint32_t key_exp_index)
 254  {
 255      std::vector<unsigned char> ser_xpub(BIP32_EXTKEY_SIZE);
 256      xpub.Encode(ser_xpub.data());
 257      return WriteIC(std::make_pair(std::make_pair(DBKeys::WALLETDESCRIPTORLHCACHE, desc_id), key_exp_index), ser_xpub);
 258  }
 259  
 260  bool WalletBatch::WriteDescriptorCacheItems(const uint256& desc_id, const DescriptorCache& cache)
 261  {
 262      for (const auto& parent_xpub_pair : cache.GetCachedParentExtPubKeys()) {
 263          if (!WriteDescriptorParentCache(parent_xpub_pair.second, desc_id, parent_xpub_pair.first)) {
 264              return false;
 265          }
 266      }
 267      for (const auto& derived_xpub_map_pair : cache.GetCachedDerivedExtPubKeys()) {
 268          for (const auto& derived_xpub_pair : derived_xpub_map_pair.second) {
 269              if (!WriteDescriptorDerivedCache(derived_xpub_pair.second, desc_id, derived_xpub_map_pair.first, derived_xpub_pair.first)) {
 270                  return false;
 271              }
 272          }
 273      }
 274      for (const auto& lh_xpub_pair : cache.GetCachedLastHardenedExtPubKeys()) {
 275          if (!WriteDescriptorLastHardenedCache(lh_xpub_pair.second, desc_id, lh_xpub_pair.first)) {
 276              return false;
 277          }
 278      }
 279      return true;
 280  }
 281  
 282  bool WalletBatch::WriteLockedUTXO(const COutPoint& output)
 283  {
 284      return WriteIC(std::make_pair(DBKeys::LOCKED_UTXO, std::make_pair(output.hash, output.n)), uint8_t{'1'});
 285  }
 286  
 287  bool WalletBatch::EraseLockedUTXO(const COutPoint& output)
 288  {
 289      return EraseIC(std::make_pair(DBKeys::LOCKED_UTXO, std::make_pair(output.hash, output.n)));
 290  }
 291  
 292  bool LoadKey(CWallet* pwallet, DataStream& ssKey, DataStream& ssValue, std::string& strErr)
 293  {
 294      LOCK(pwallet->cs_wallet);
 295      try {
 296          CPubKey vchPubKey;
 297          ssKey >> vchPubKey;
 298          if (!vchPubKey.IsValid())
 299          {
 300              strErr = "Error reading wallet database: CPubKey corrupt";
 301              return false;
 302          }
 303          CKey key;
 304          CPrivKey pkey;
 305          uint256 hash;
 306  
 307          ssValue >> pkey;
 308  
 309          // Old wallets store keys as DBKeys::KEY [pubkey] => [privkey]
 310          // ... which was slow for wallets with lots of keys, because the public key is re-derived from the private key
 311          // using EC operations as a checksum.
 312          // Newer wallets store keys as DBKeys::KEY [pubkey] => [privkey][hash(pubkey,privkey)], which is much faster while
 313          // remaining backwards-compatible.
 314          try
 315          {
 316              ssValue >> hash;
 317          }
 318          catch (const std::ios_base::failure&) {}
 319  
 320          bool fSkipCheck = false;
 321  
 322          if (!hash.IsNull())
 323          {
 324              // hash pubkey/privkey to accelerate wallet load
 325              const auto keypair_hash = Hash(vchPubKey, pkey);
 326  
 327              if (keypair_hash != hash)
 328              {
 329                  strErr = "Error reading wallet database: CPubKey/CPrivKey corrupt";
 330                  return false;
 331              }
 332  
 333              fSkipCheck = true;
 334          }
 335  
 336          if (!key.Load(pkey, vchPubKey, fSkipCheck))
 337          {
 338              strErr = "Error reading wallet database: CPrivKey corrupt";
 339              return false;
 340          }
 341          if (!pwallet->GetOrCreateLegacyDataSPKM()->LoadKey(key, vchPubKey))
 342          {
 343              strErr = "Error reading wallet database: LegacyDataSPKM::LoadKey failed";
 344              return false;
 345          }
 346      } catch (const std::exception& e) {
 347          if (strErr.empty()) {
 348              strErr = e.what();
 349          }
 350          return false;
 351      }
 352      return true;
 353  }
 354  
 355  bool LoadCryptedKey(CWallet* pwallet, DataStream& ssKey, DataStream& ssValue, std::string& strErr)
 356  {
 357      LOCK(pwallet->cs_wallet);
 358      try {
 359          CPubKey vchPubKey;
 360          ssKey >> vchPubKey;
 361          if (!vchPubKey.IsValid())
 362          {
 363              strErr = "Error reading wallet database: CPubKey corrupt";
 364              return false;
 365          }
 366          std::vector<unsigned char> vchPrivKey;
 367          ssValue >> vchPrivKey;
 368  
 369          // Get the checksum and check it
 370          bool checksum_valid = false;
 371          if (!ssValue.empty()) {
 372              uint256 checksum;
 373              ssValue >> checksum;
 374              if (!(checksum_valid = Hash(vchPrivKey) == checksum)) {
 375                  strErr = "Error reading wallet database: Encrypted key corrupt";
 376                  return false;
 377              }
 378          }
 379  
 380          if (!pwallet->GetOrCreateLegacyDataSPKM()->LoadCryptedKey(vchPubKey, vchPrivKey, checksum_valid))
 381          {
 382              strErr = "Error reading wallet database: LegacyDataSPKM::LoadCryptedKey failed";
 383              return false;
 384          }
 385      } catch (const std::exception& e) {
 386          if (strErr.empty()) {
 387              strErr = e.what();
 388          }
 389          return false;
 390      }
 391      return true;
 392  }
 393  
 394  bool LoadEncryptionKey(CWallet* pwallet, DataStream& ssKey, DataStream& ssValue, std::string& strErr)
 395  {
 396      LOCK(pwallet->cs_wallet);
 397      try {
 398          // Master encryption key is loaded into only the wallet and not any of the ScriptPubKeyMans.
 399          unsigned int nID;
 400          ssKey >> nID;
 401          CMasterKey kMasterKey;
 402          ssValue >> kMasterKey;
 403          if(pwallet->mapMasterKeys.contains(nID))
 404          {
 405              strErr = strprintf("Error reading wallet database: duplicate CMasterKey id %u", nID);
 406              return false;
 407          }
 408          pwallet->mapMasterKeys[nID] = kMasterKey;
 409          if (pwallet->nMasterKeyMaxID < nID)
 410              pwallet->nMasterKeyMaxID = nID;
 411  
 412      } catch (const std::exception& e) {
 413          if (strErr.empty()) {
 414              strErr = e.what();
 415          }
 416          return false;
 417      }
 418      return true;
 419  }
 420  
 421  bool LoadHDChain(CWallet* pwallet, DataStream& ssValue, std::string& strErr)
 422  {
 423      LOCK(pwallet->cs_wallet);
 424      try {
 425          CHDChain chain;
 426          ssValue >> chain;
 427          pwallet->GetOrCreateLegacyDataSPKM()->LoadHDChain(chain);
 428      } catch (const std::exception& e) {
 429          if (strErr.empty()) {
 430              strErr = e.what();
 431          }
 432          return false;
 433      }
 434      return true;
 435  }
 436  
 437  static DBErrors LoadWalletFlags(CWallet* pwallet, DatabaseBatch& batch) EXCLUSIVE_LOCKS_REQUIRED(pwallet->cs_wallet)
 438  {
 439      AssertLockHeld(pwallet->cs_wallet);
 440      uint64_t flags;
 441      if (batch.Read(DBKeys::FLAGS, flags)) {
 442          if (!pwallet->LoadWalletFlags(flags)) {
 443              pwallet->WalletLogPrintf("Error reading wallet database: Unknown non-tolerable wallet flags found\n");
 444              return DBErrors::TOO_NEW;
 445          }
 446          // All wallets must be descriptor wallets unless opened with a bdb_ro db
 447          // bdb_ro is only used for legacy to descriptor migration.
 448          if (pwallet->GetDatabase().Format() != "bdb_ro" && !pwallet->IsWalletFlagSet(WALLET_FLAG_DESCRIPTORS)) {
 449              return DBErrors::LEGACY_WALLET;
 450          }
 451      }
 452      return DBErrors::LOAD_OK;
 453  }
 454  
 455  struct LoadResult
 456  {
 457      DBErrors m_result{DBErrors::LOAD_OK};
 458      int m_records{0};
 459  };
 460  
 461  using LoadFunc = std::function<DBErrors(CWallet* pwallet, DataStream& key, DataStream& value, std::string& err)>;
 462  static LoadResult LoadRecords(CWallet* pwallet, DatabaseBatch& batch, const std::string& key, DataStream& prefix, LoadFunc load_func)
 463  {
 464      LoadResult result;
 465      DataStream ssKey;
 466      DataStream ssValue{};
 467  
 468      Assume(!prefix.empty());
 469      std::unique_ptr<DatabaseCursor> cursor = batch.GetNewPrefixCursor(prefix);
 470      if (!cursor) {
 471          pwallet->WalletLogPrintf("Error getting database cursor for '%s' records\n", key);
 472          result.m_result = DBErrors::CORRUPT;
 473          return result;
 474      }
 475  
 476      while (true) {
 477          DatabaseCursor::Status status = cursor->Next(ssKey, ssValue);
 478          if (status == DatabaseCursor::Status::DONE) {
 479              break;
 480          } else if (status == DatabaseCursor::Status::FAIL) {
 481              pwallet->WalletLogPrintf("Error reading next '%s' record for wallet database\n", key);
 482              result.m_result = DBErrors::CORRUPT;
 483              return result;
 484          }
 485          std::string type;
 486          ssKey >> type;
 487          assert(type == key);
 488          std::string error;
 489          DBErrors record_res = load_func(pwallet, ssKey, ssValue, error);
 490          if (record_res != DBErrors::LOAD_OK) {
 491              pwallet->WalletLogPrintf("%s\n", error);
 492          }
 493          result.m_result = std::max(result.m_result, record_res);
 494          ++result.m_records;
 495      }
 496      return result;
 497  }
 498  
 499  static LoadResult LoadRecords(CWallet* pwallet, DatabaseBatch& batch, const std::string& key, LoadFunc load_func)
 500  {
 501      DataStream prefix;
 502      prefix << key;
 503      return LoadRecords(pwallet, batch, key, prefix, load_func);
 504  }
 505  
 506  bool HasLegacyRecords(CWallet& wallet)
 507  {
 508      const auto& batch = wallet.GetDatabase().MakeBatch();
 509      return HasLegacyRecords(wallet, *batch);
 510  }
 511  
 512  bool HasLegacyRecords(CWallet& wallet, DatabaseBatch& batch)
 513  {
 514      for (const auto& type : DBKeys::LEGACY_TYPES) {
 515          DataStream key;
 516          DataStream value{};
 517          DataStream prefix;
 518  
 519          prefix << type;
 520          std::unique_ptr<DatabaseCursor> cursor = batch.GetNewPrefixCursor(prefix);
 521          if (!cursor) {
 522              // Could only happen on a closed db, which means there is an error in the code flow.
 523              throw std::runtime_error(strprintf("Error getting database cursor for '%s' records", type));
 524          }
 525  
 526          DatabaseCursor::Status status = cursor->Next(key, value);
 527          if (status != DatabaseCursor::Status::DONE) {
 528              return true;
 529          }
 530      }
 531      return false;
 532  }
 533  
 534  static DBErrors LoadLegacyWalletRecords(CWallet* pwallet, DatabaseBatch& batch, int last_client) EXCLUSIVE_LOCKS_REQUIRED(pwallet->cs_wallet)
 535  {
 536      AssertLockHeld(pwallet->cs_wallet);
 537      DBErrors result = DBErrors::LOAD_OK;
 538  
 539      // Make sure descriptor wallets don't have any legacy records
 540      if (pwallet->IsWalletFlagSet(WALLET_FLAG_DESCRIPTORS)) {
 541          if (HasLegacyRecords(*pwallet, batch)) {
 542              pwallet->WalletLogPrintf("Error: Unexpected legacy entry found in descriptor wallet %s. The wallet might have been tampered with or created with malicious intent.\n", pwallet->GetName());
 543              return DBErrors::UNEXPECTED_LEGACY_ENTRY;
 544          }
 545  
 546          return DBErrors::LOAD_OK;
 547      }
 548  
 549      // Load HD Chain
 550      // Note: There should only be one HDCHAIN record with no data following the type
 551      LoadResult hd_chain_res = LoadRecords(pwallet, batch, DBKeys::HDCHAIN,
 552          [] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& err) {
 553          return LoadHDChain(pwallet, value, err) ? DBErrors:: LOAD_OK : DBErrors::CORRUPT;
 554      });
 555      result = std::max(result, hd_chain_res.m_result);
 556  
 557      // Load unencrypted keys
 558      LoadResult key_res = LoadRecords(pwallet, batch, DBKeys::KEY,
 559          [] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& err) {
 560          return LoadKey(pwallet, key, value, err) ? DBErrors::LOAD_OK : DBErrors::CORRUPT;
 561      });
 562      result = std::max(result, key_res.m_result);
 563  
 564      // Load encrypted keys
 565      LoadResult ckey_res = LoadRecords(pwallet, batch, DBKeys::CRYPTED_KEY,
 566          [] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& err) {
 567          return LoadCryptedKey(pwallet, key, value, err) ? DBErrors::LOAD_OK : DBErrors::CORRUPT;
 568      });
 569      result = std::max(result, ckey_res.m_result);
 570  
 571      // Load scripts
 572      LoadResult script_res = LoadRecords(pwallet, batch, DBKeys::CSCRIPT,
 573          [] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& strErr) {
 574          uint160 hash;
 575          key >> hash;
 576          CScript script;
 577          value >> script;
 578          if (!pwallet->GetOrCreateLegacyDataSPKM()->LoadCScript(script))
 579          {
 580              strErr = "Error reading wallet database: LegacyDataSPKM::LoadCScript failed";
 581              return DBErrors::NONCRITICAL_ERROR;
 582          }
 583          return DBErrors::LOAD_OK;
 584      });
 585      result = std::max(result, script_res.m_result);
 586  
 587      // Load keymeta
 588      std::map<uint160, CHDChain> hd_chains;
 589      LoadResult keymeta_res = LoadRecords(pwallet, batch, DBKeys::KEYMETA,
 590          [&hd_chains] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& strErr) {
 591          CPubKey vchPubKey;
 592          key >> vchPubKey;
 593          CKeyMetadata keyMeta;
 594          value >> keyMeta;
 595          pwallet->GetOrCreateLegacyDataSPKM()->LoadKeyMetadata(vchPubKey.GetID(), keyMeta);
 596  
 597          // Extract some CHDChain info from this metadata if it has any
 598          if (keyMeta.nVersion >= CKeyMetadata::VERSION_WITH_HDDATA && !keyMeta.hd_seed_id.IsNull() && keyMeta.hdKeypath.size() > 0) {
 599              // Get the path from the key origin or from the path string
 600              // Not applicable when path is "s" or "m" as those indicate a seed
 601              // See https://github.com/bitcoin/bitcoin/pull/12924
 602              bool internal = false;
 603              uint32_t index = 0;
 604              if (keyMeta.hdKeypath != "s" && keyMeta.hdKeypath != "m") {
 605                  std::vector<uint32_t> path;
 606                  if (keyMeta.has_key_origin) {
 607                      // We have a key origin, so pull it from its path vector
 608                      path = keyMeta.key_origin.path;
 609                  } else {
 610                      // No key origin, have to parse the string
 611                      if (!ParseHDKeypath(keyMeta.hdKeypath, path)) {
 612                          strErr = "Error reading wallet database: keymeta with invalid HD keypath";
 613                          return DBErrors::NONCRITICAL_ERROR;
 614                      }
 615                  }
 616  
 617                  // Extract the index and internal from the path
 618                  // Path string is m/0'/k'/i'
 619                  // Path vector is [0', k', i'] (but as ints OR'd with the hardened bit
 620                  // k == 0 for external, 1 for internal. i is the index
 621                  if (path.size() != 3) {
 622                      strErr = "Error reading wallet database: keymeta found with unexpected path";
 623                      return DBErrors::NONCRITICAL_ERROR;
 624                  }
 625                  if (path[0] != 0x80000000) {
 626                      strErr = strprintf("Unexpected path index of 0x%08x (expected 0x80000000) for the element at index 0", path[0]);
 627                      return DBErrors::NONCRITICAL_ERROR;
 628                  }
 629                  if (path[1] != 0x80000000 && path[1] != (1 | 0x80000000)) {
 630                      strErr = strprintf("Unexpected path index of 0x%08x (expected 0x80000000 or 0x80000001) for the element at index 1", path[1]);
 631                      return DBErrors::NONCRITICAL_ERROR;
 632                  }
 633                  if ((path[2] & 0x80000000) == 0) {
 634                      strErr = strprintf("Unexpected path index of 0x%08x (expected to be greater than or equal to 0x80000000)", path[2]);
 635                      return DBErrors::NONCRITICAL_ERROR;
 636                  }
 637                  internal = path[1] == (1 | 0x80000000);
 638                  index = path[2] & ~0x80000000;
 639              }
 640  
 641              // Insert a new CHDChain, or get the one that already exists
 642              auto [ins, inserted] = hd_chains.emplace(keyMeta.hd_seed_id, CHDChain());
 643              CHDChain& chain = ins->second;
 644              if (inserted) {
 645                  // For new chains, we want to default to VERSION_HD_BASE until we see an internal
 646                  chain.nVersion = CHDChain::VERSION_HD_BASE;
 647                  chain.seed_id = keyMeta.hd_seed_id;
 648              }
 649              if (internal) {
 650                  chain.nVersion = CHDChain::VERSION_HD_CHAIN_SPLIT;
 651                  chain.nInternalChainCounter = std::max(chain.nInternalChainCounter, index + 1);
 652              } else {
 653                  chain.nExternalChainCounter = std::max(chain.nExternalChainCounter, index + 1);
 654              }
 655          }
 656          return DBErrors::LOAD_OK;
 657      });
 658      result = std::max(result, keymeta_res.m_result);
 659  
 660      // Set inactive chains
 661      if (!hd_chains.empty()) {
 662          LegacyDataSPKM* legacy_spkm = pwallet->GetLegacyDataSPKM();
 663          if (legacy_spkm) {
 664              for (const auto& [hd_seed_id, chain] : hd_chains) {
 665                  if (hd_seed_id != legacy_spkm->GetHDChain().seed_id) {
 666                      legacy_spkm->AddInactiveHDChain(chain);
 667                  }
 668              }
 669          } else {
 670              pwallet->WalletLogPrintf("Inactive HD Chains found but no Legacy ScriptPubKeyMan\n");
 671              result = DBErrors::CORRUPT;
 672          }
 673      }
 674  
 675      // Load watchonly scripts
 676      LoadResult watch_script_res = LoadRecords(pwallet, batch, DBKeys::WATCHS,
 677          [] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& err) {
 678          CScript script;
 679          key >> script;
 680          uint8_t fYes;
 681          value >> fYes;
 682          if (fYes == '1') {
 683              pwallet->GetOrCreateLegacyDataSPKM()->LoadWatchOnly(script);
 684          }
 685          return DBErrors::LOAD_OK;
 686      });
 687      result = std::max(result, watch_script_res.m_result);
 688  
 689      // Load watchonly meta
 690      LoadResult watch_meta_res = LoadRecords(pwallet, batch, DBKeys::WATCHMETA,
 691          [] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& err) {
 692          CScript script;
 693          key >> script;
 694          CKeyMetadata keyMeta;
 695          value >> keyMeta;
 696          pwallet->GetOrCreateLegacyDataSPKM()->LoadScriptMetadata(CScriptID(script), keyMeta);
 697          return DBErrors::LOAD_OK;
 698      });
 699      result = std::max(result, watch_meta_res.m_result);
 700  
 701      // Deal with old "wkey" and "defaultkey" records.
 702      // These are not actually loaded, but we need to check for them
 703  
 704      // We don't want or need the default key, but if there is one set,
 705      // we want to make sure that it is valid so that we can detect corruption
 706      // Note: There should only be one DEFAULTKEY with nothing trailing the type
 707      LoadResult default_key_res = LoadRecords(pwallet, batch, DBKeys::DEFAULTKEY,
 708          [] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& err) {
 709          CPubKey default_pubkey;
 710          try {
 711              value >> default_pubkey;
 712          } catch (const std::exception& e) {
 713              err = e.what();
 714              return DBErrors::CORRUPT;
 715          }
 716          if (!default_pubkey.IsValid()) {
 717              err = "Error reading wallet database: Default Key corrupt";
 718              return DBErrors::CORRUPT;
 719          }
 720          return DBErrors::LOAD_OK;
 721      });
 722      result = std::max(result, default_key_res.m_result);
 723  
 724      // "wkey" records are unsupported, if we see any, throw an error
 725      LoadResult wkey_res = LoadRecords(pwallet, batch, DBKeys::OLD_KEY,
 726          [] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& err) {
 727          err = "Found unsupported 'wkey' record, try loading with version 0.18";
 728          return DBErrors::LOAD_FAIL;
 729      });
 730      result = std::max(result, wkey_res.m_result);
 731  
 732      if (result <= DBErrors::NONCRITICAL_ERROR) {
 733          // Only do logging and time first key update if there were no critical errors
 734          pwallet->WalletLogPrintf("Legacy Wallet Keys: %u plaintext, %u encrypted, %u w/ metadata, %u total.\n",
 735                 key_res.m_records, ckey_res.m_records, keymeta_res.m_records, key_res.m_records + ckey_res.m_records);
 736      }
 737  
 738      return result;
 739  }
 740  
 741  template<typename... Args>
 742  static DataStream PrefixStream(const Args&... args)
 743  {
 744      DataStream prefix;
 745      SerializeMany(prefix, args...);
 746      return prefix;
 747  }
 748  
 749  static DBErrors LoadDescriptorWalletRecords(CWallet* pwallet, DatabaseBatch& batch, int last_client) EXCLUSIVE_LOCKS_REQUIRED(pwallet->cs_wallet)
 750  {
 751      AssertLockHeld(pwallet->cs_wallet);
 752  
 753      // Load descriptor record
 754      int num_keys = 0;
 755      int num_ckeys= 0;
 756      LoadResult desc_res = LoadRecords(pwallet, batch, DBKeys::WALLETDESCRIPTOR,
 757          [&batch, &num_keys, &num_ckeys, &last_client] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& strErr) {
 758          DBErrors result = DBErrors::LOAD_OK;
 759  
 760          uint256 id;
 761          key >> id;
 762          WalletDescriptor desc;
 763          try {
 764              value >> desc;
 765          } catch (const std::ios_base::failure& e) {
 766              strErr = strprintf("Error: Unrecognized descriptor found in wallet %s. ", pwallet->GetName());
 767              strErr += (last_client > CLIENT_VERSION) ? "The wallet might have been created on a newer version. " :
 768                      "The database might be corrupted or the software version is not compatible with one of your wallet descriptors. ";
 769              strErr += "Please try running the latest software version";
 770              // Also include error details
 771              strErr = strprintf("%s\nDetails: %s", strErr, e.what());
 772              return DBErrors::UNKNOWN_DESCRIPTOR;
 773          }
 774  
 775          if (id != desc.id) {
 776              strErr = "The descriptor ID calculated by the wallet differs from the one in DB";
 777              return DBErrors::CORRUPT;
 778          }
 779  
 780          DescriptorCache cache;
 781  
 782          // Get key cache for this descriptor
 783          DataStream prefix = PrefixStream(DBKeys::WALLETDESCRIPTORCACHE, id);
 784          LoadResult key_cache_res = LoadRecords(pwallet, batch, DBKeys::WALLETDESCRIPTORCACHE, prefix,
 785              [&id, &cache] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& err) {
 786              bool parent = true;
 787              uint256 desc_id;
 788              uint32_t key_exp_index;
 789              uint32_t der_index;
 790              key >> desc_id;
 791              assert(desc_id == id);
 792              key >> key_exp_index;
 793  
 794              // if the der_index exists, it's a derived xpub
 795              try
 796              {
 797                  key >> der_index;
 798                  parent = false;
 799              }
 800              catch (...) {}
 801  
 802              std::vector<unsigned char> ser_xpub(BIP32_EXTKEY_SIZE);
 803              value >> ser_xpub;
 804              CExtPubKey xpub;
 805              xpub.Decode(ser_xpub.data());
 806              if (parent) {
 807                  cache.CacheParentExtPubKey(key_exp_index, xpub);
 808              } else {
 809                  cache.CacheDerivedExtPubKey(key_exp_index, der_index, xpub);
 810              }
 811              return DBErrors::LOAD_OK;
 812          });
 813          result = std::max(result, key_cache_res.m_result);
 814  
 815          // Get last hardened cache for this descriptor
 816          prefix = PrefixStream(DBKeys::WALLETDESCRIPTORLHCACHE, id);
 817          LoadResult lh_cache_res = LoadRecords(pwallet, batch, DBKeys::WALLETDESCRIPTORLHCACHE, prefix,
 818              [&id, &cache] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& err) {
 819              uint256 desc_id;
 820              uint32_t key_exp_index;
 821              key >> desc_id;
 822              assert(desc_id == id);
 823              key >> key_exp_index;
 824  
 825              std::vector<unsigned char> ser_xpub(BIP32_EXTKEY_SIZE);
 826              value >> ser_xpub;
 827              CExtPubKey xpub;
 828              xpub.Decode(ser_xpub.data());
 829              cache.CacheLastHardenedExtPubKey(key_exp_index, xpub);
 830              return DBErrors::LOAD_OK;
 831          });
 832          result = std::max(result, lh_cache_res.m_result);
 833  
 834          // Set the cache to the WalletDescriptor
 835          desc.cache = cache;
 836  
 837          // Get unencrypted keys
 838          KeyMap keys;
 839          prefix = PrefixStream(DBKeys::WALLETDESCRIPTORKEY, id);
 840          LoadResult key_res = LoadRecords(pwallet, batch, DBKeys::WALLETDESCRIPTORKEY, prefix,
 841              [&id, &keys] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& strErr) {
 842              uint256 desc_id;
 843              CPubKey pubkey;
 844              key >> desc_id;
 845              assert(desc_id == id);
 846              key >> pubkey;
 847              if (!pubkey.IsValid())
 848              {
 849                  strErr = "Error reading wallet database: descriptor unencrypted key CPubKey corrupt";
 850                  return DBErrors::CORRUPT;
 851              }
 852              CKey privkey;
 853              CPrivKey pkey;
 854              uint256 hash;
 855  
 856              value >> pkey;
 857              value >> hash;
 858  
 859              // hash pubkey/privkey to accelerate wallet load
 860              const auto keypair_hash = Hash(pubkey, pkey);
 861  
 862              if (keypair_hash != hash)
 863              {
 864                  strErr = "Error reading wallet database: descriptor unencrypted key CPubKey/CPrivKey corrupt";
 865                  return DBErrors::CORRUPT;
 866              }
 867  
 868              if (!privkey.Load(pkey, pubkey, true))
 869              {
 870                  strErr = "Error reading wallet database: descriptor unencrypted key CPrivKey corrupt";
 871                  return DBErrors::CORRUPT;
 872              }
 873              keys[pubkey.GetID()] = privkey;
 874              return DBErrors::LOAD_OK;
 875          });
 876          result = std::max(result, key_res.m_result);
 877          num_keys = key_res.m_records;
 878  
 879          // Get encrypted keys
 880          CryptedKeyMap ckeys;
 881          prefix = PrefixStream(DBKeys::WALLETDESCRIPTORCKEY, id);
 882          LoadResult ckey_res = LoadRecords(pwallet, batch, DBKeys::WALLETDESCRIPTORCKEY, prefix,
 883              [&id, &ckeys] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& err) {
 884              uint256 desc_id;
 885              CPubKey pubkey;
 886              key >> desc_id;
 887              assert(desc_id == id);
 888              key >> pubkey;
 889              if (!pubkey.IsValid())
 890              {
 891                  err = "Error reading wallet database: descriptor encrypted key CPubKey corrupt";
 892                  return DBErrors::CORRUPT;
 893              }
 894              std::vector<unsigned char> privkey;
 895              value >> privkey;
 896  
 897              ckeys[pubkey.GetID()] = std::make_pair(pubkey, privkey);
 898              return DBErrors::LOAD_OK;
 899          });
 900          result = std::max(result, ckey_res.m_result);
 901          num_ckeys = ckey_res.m_records;
 902  
 903          try {
 904              pwallet->LoadDescriptorScriptPubKeyMan(id, desc, keys, ckeys);
 905          } catch (std::runtime_error& e) {
 906              strErr = e.what();
 907              return DBErrors::CORRUPT;
 908          }
 909  
 910          return result;
 911      });
 912  
 913      if (desc_res.m_result <= DBErrors::NONCRITICAL_ERROR) {
 914          // Only log if there are no critical errors
 915          pwallet->WalletLogPrintf("Descriptors: %u, Descriptor Keys: %u plaintext, %u encrypted, %u total.\n",
 916                 desc_res.m_records, num_keys, num_ckeys, num_keys + num_ckeys);
 917      }
 918  
 919      return desc_res.m_result;
 920  }
 921  
 922  static DBErrors LoadAddressBookRecords(CWallet* pwallet, DatabaseBatch& batch) EXCLUSIVE_LOCKS_REQUIRED(pwallet->cs_wallet)
 923  {
 924      AssertLockHeld(pwallet->cs_wallet);
 925      DBErrors result = DBErrors::LOAD_OK;
 926  
 927      // Load name record
 928      LoadResult name_res = LoadRecords(pwallet, batch, DBKeys::NAME,
 929          [] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& err) EXCLUSIVE_LOCKS_REQUIRED(pwallet->cs_wallet) {
 930          std::string strAddress;
 931          key >> strAddress;
 932          std::string label;
 933          value >> label;
 934          pwallet->m_address_book[DecodeDestination(strAddress)].SetLabel(label);
 935          return DBErrors::LOAD_OK;
 936      });
 937      result = std::max(result, name_res.m_result);
 938  
 939      // Load purpose record
 940      LoadResult purpose_res = LoadRecords(pwallet, batch, DBKeys::PURPOSE,
 941          [] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& err) EXCLUSIVE_LOCKS_REQUIRED(pwallet->cs_wallet) {
 942          std::string strAddress;
 943          key >> strAddress;
 944          std::string purpose_str;
 945          value >> purpose_str;
 946          std::optional<AddressPurpose> purpose{PurposeFromString(purpose_str)};
 947          if (!purpose) {
 948              pwallet->WalletLogPrintf("Warning: nonstandard purpose string '%s' for address '%s'\n", purpose_str, strAddress);
 949          }
 950          pwallet->m_address_book[DecodeDestination(strAddress)].purpose = purpose;
 951          return DBErrors::LOAD_OK;
 952      });
 953      result = std::max(result, purpose_res.m_result);
 954  
 955      // Load destination data record
 956      LoadResult dest_res = LoadRecords(pwallet, batch, DBKeys::DESTDATA,
 957          [] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& err) EXCLUSIVE_LOCKS_REQUIRED(pwallet->cs_wallet) {
 958          std::string strAddress, strKey, strValue;
 959          key >> strAddress;
 960          key >> strKey;
 961          value >> strValue;
 962          const CTxDestination& dest{DecodeDestination(strAddress)};
 963          if (strKey.compare("used") == 0) {
 964              // Load "used" key indicating if an IsMine address has
 965              // previously been spent from with avoid_reuse option enabled.
 966              // The strValue is not used for anything currently, but could
 967              // hold more information in the future. Current values are just
 968              // "1" or "p" for present (which was written prior to
 969              // f5ba424cd44619d9b9be88b8593d69a7ba96db26).
 970              pwallet->LoadAddressPreviouslySpent(dest);
 971          } else if (strKey.starts_with("rr")) {
 972              // Load "rr##" keys where ## is a decimal number, and strValue
 973              // is a serialized RecentRequestEntry object.
 974              pwallet->LoadAddressReceiveRequest(dest, strKey.substr(2), strValue);
 975          }
 976          return DBErrors::LOAD_OK;
 977      });
 978      result = std::max(result, dest_res.m_result);
 979  
 980      return result;
 981  }
 982  
 983  static DBErrors LoadTxRecords(CWallet* pwallet, DatabaseBatch& batch, bool& any_unordered) EXCLUSIVE_LOCKS_REQUIRED(pwallet->cs_wallet)
 984  {
 985      AssertLockHeld(pwallet->cs_wallet);
 986      DBErrors result = DBErrors::LOAD_OK;
 987  
 988      // Load tx record
 989      any_unordered = false;
 990      LoadResult tx_res = LoadRecords(pwallet, batch, DBKeys::TX,
 991          [&any_unordered] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& err) EXCLUSIVE_LOCKS_REQUIRED(pwallet->cs_wallet) {
 992          DBErrors result = DBErrors::LOAD_OK;
 993          Txid hash;
 994          key >> hash;
 995          // LoadToWallet call below creates a new CWalletTx that fill_wtx
 996          // callback fills with transaction metadata.
 997          auto fill_wtx = [&](CWalletTx& wtx, bool new_tx) {
 998              if(!new_tx) {
 999                  // There's some corruption here since the tx we just tried to load was already in the wallet.
1000                  err = "Error: Corrupt transaction found. This can be fixed by removing transactions from wallet and rescanning.";
1001                  result = DBErrors::CORRUPT;
1002                  return false;
1003              }
1004              value >> wtx;
1005              if (wtx.GetHash() != hash)
1006                  return false;
1007  
1008              if (wtx.nOrderPos == -1)
1009                  any_unordered = true;
1010  
1011              return true;
1012          };
1013          if (!pwallet->LoadToWallet(hash, fill_wtx)) {
1014              // Use std::max as fill_wtx may have already set result to CORRUPT
1015              result = std::max(result, DBErrors::NEED_RESCAN);
1016          }
1017          return result;
1018      });
1019      result = std::max(result, tx_res.m_result);
1020  
1021      // Load locked utxo record
1022      LoadResult locked_utxo_res = LoadRecords(pwallet, batch, DBKeys::LOCKED_UTXO,
1023          [] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& err) EXCLUSIVE_LOCKS_REQUIRED(pwallet->cs_wallet) {
1024          Txid hash;
1025          uint32_t n;
1026          key >> hash;
1027          key >> n;
1028          pwallet->LoadLockedCoin(COutPoint(hash, n), /*persistent=*/true);
1029          return DBErrors::LOAD_OK;
1030      });
1031      result = std::max(result, locked_utxo_res.m_result);
1032  
1033      // Load orderposnext record
1034      // Note: There should only be one ORDERPOSNEXT record with nothing trailing the type
1035      LoadResult order_pos_res = LoadRecords(pwallet, batch, DBKeys::ORDERPOSNEXT,
1036          [] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& err) EXCLUSIVE_LOCKS_REQUIRED(pwallet->cs_wallet) {
1037          try {
1038              value >> pwallet->nOrderPosNext;
1039          } catch (const std::exception& e) {
1040              err = e.what();
1041              return DBErrors::NONCRITICAL_ERROR;
1042          }
1043          return DBErrors::LOAD_OK;
1044      });
1045      result = std::max(result, order_pos_res.m_result);
1046  
1047      // After loading all tx records, abandon any coinbase that is no longer in the active chain.
1048      // This could happen during an external wallet load, or if the user replaced the chain data.
1049      for (auto& [id, wtx] : pwallet->mapWallet) {
1050          if (wtx.IsCoinBase() && wtx.isInactive()) {
1051              pwallet->AbandonTransaction(wtx);
1052          }
1053      }
1054  
1055      return result;
1056  }
1057  
1058  static DBErrors LoadActiveSPKMs(CWallet* pwallet, DatabaseBatch& batch) EXCLUSIVE_LOCKS_REQUIRED(pwallet->cs_wallet)
1059  {
1060      AssertLockHeld(pwallet->cs_wallet);
1061      DBErrors result = DBErrors::LOAD_OK;
1062  
1063      // Load spk records
1064      std::set<std::pair<OutputType, bool>> seen_spks;
1065      for (const auto& spk_key : {DBKeys::ACTIVEEXTERNALSPK, DBKeys::ACTIVEINTERNALSPK}) {
1066          LoadResult spkm_res = LoadRecords(pwallet, batch, spk_key,
1067              [&seen_spks, &spk_key] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& strErr) {
1068              uint8_t output_type;
1069              key >> output_type;
1070              uint256 id;
1071              value >> id;
1072  
1073              bool internal = spk_key == DBKeys::ACTIVEINTERNALSPK;
1074              auto [it, insert] = seen_spks.emplace(static_cast<OutputType>(output_type), internal);
1075              if (!insert) {
1076                  strErr = "Multiple ScriptpubKeyMans specified for a single type";
1077                  return DBErrors::CORRUPT;
1078              }
1079              pwallet->LoadActiveScriptPubKeyMan(id, static_cast<OutputType>(output_type), /*internal=*/internal);
1080              return DBErrors::LOAD_OK;
1081          });
1082          result = std::max(result, spkm_res.m_result);
1083      }
1084      return result;
1085  }
1086  
1087  static DBErrors LoadDecryptionKeys(CWallet* pwallet, DatabaseBatch& batch) EXCLUSIVE_LOCKS_REQUIRED(pwallet->cs_wallet)
1088  {
1089      AssertLockHeld(pwallet->cs_wallet);
1090  
1091      // Load decryption key (mkey) records
1092      LoadResult mkey_res = LoadRecords(pwallet, batch, DBKeys::MASTER_KEY,
1093          [] (CWallet* pwallet, DataStream& key, DataStream& value, std::string& err) {
1094          if (!LoadEncryptionKey(pwallet, key, value, err)) {
1095              return DBErrors::CORRUPT;
1096          }
1097          return DBErrors::LOAD_OK;
1098      });
1099      return mkey_res.m_result;
1100  }
1101  
1102  DBErrors WalletBatch::LoadWallet(CWallet* pwallet)
1103  {
1104      DBErrors result = DBErrors::LOAD_OK;
1105      bool any_unordered = false;
1106  
1107      LOCK(pwallet->cs_wallet);
1108  
1109      // Last client version to open this wallet
1110      int last_client = CLIENT_VERSION;
1111      bool has_last_client = m_batch->Read(DBKeys::VERSION, last_client);
1112      if (has_last_client) pwallet->WalletLogPrintf("Last client version = %d\n", last_client);
1113  
1114      try {
1115          // Load wallet flags, so they are known when processing other records.
1116          // The FLAGS key is absent during wallet creation.
1117          if ((result = LoadWalletFlags(pwallet, *m_batch)) != DBErrors::LOAD_OK) return result;
1118  
1119  #ifndef ENABLE_EXTERNAL_SIGNER
1120          if (pwallet->IsWalletFlagSet(WALLET_FLAG_EXTERNAL_SIGNER)) {
1121              pwallet->WalletLogPrintf("Error: External signer wallet being loaded without external signer support compiled\n");
1122              return DBErrors::EXTERNAL_SIGNER_SUPPORT_REQUIRED;
1123          }
1124  #endif
1125  
1126          // Load legacy wallet keys
1127          result = std::max(LoadLegacyWalletRecords(pwallet, *m_batch, last_client), result);
1128  
1129          // Load descriptors
1130          result = std::max(LoadDescriptorWalletRecords(pwallet, *m_batch, last_client), result);
1131          // Early return if there are unknown descriptors. Later loading of ACTIVEINTERNALSPK and ACTIVEEXTERNALEXPK
1132          // may reference the unknown descriptor's ID which can result in a misleading corruption error
1133          // when in reality the wallet is simply too new.
1134          if (result == DBErrors::UNKNOWN_DESCRIPTOR) return result;
1135  
1136          // Load address book
1137          result = std::max(LoadAddressBookRecords(pwallet, *m_batch), result);
1138  
1139          // Load SPKMs
1140          result = std::max(LoadActiveSPKMs(pwallet, *m_batch), result);
1141  
1142          // Load decryption keys
1143          result = std::max(LoadDecryptionKeys(pwallet, *m_batch), result);
1144  
1145          // Load tx records
1146          result = std::max(LoadTxRecords(pwallet, *m_batch, any_unordered), result);
1147      } catch (std::runtime_error& e) {
1148          // Exceptions that can be ignored or treated as non-critical are handled by the individual loading functions.
1149          // Any uncaught exceptions will be caught here and treated as critical.
1150          // Catch std::runtime_error specifically as many functions throw these and they at least have some message that
1151          // we can log
1152          pwallet->WalletLogPrintf("%s\n", e.what());
1153          result = DBErrors::CORRUPT;
1154      } catch (...) {
1155          // All other exceptions are still problematic, but we can't log them
1156          result = DBErrors::CORRUPT;
1157      }
1158  
1159      // Any wallet corruption at all: skip any rewriting or
1160      // upgrading, we don't want to make it worse.
1161      if (result != DBErrors::LOAD_OK)
1162          return result;
1163  
1164      if (!has_last_client || last_client != CLIENT_VERSION) // Update
1165          this->WriteVersion(CLIENT_VERSION);
1166  
1167      if (any_unordered)
1168          result = pwallet->ReorderTransactions();
1169  
1170      // Upgrade all of the descriptor caches to cache the last hardened xpub
1171      // This operation is not atomic, but if it fails, only new entries are added so it is backwards compatible
1172      try {
1173          pwallet->UpgradeDescriptorCache();
1174      } catch (...) {
1175          result = DBErrors::CORRUPT;
1176      }
1177  
1178      // Since it was accidentally possible to "encrypt" a wallet with private keys disabled, we should check if this is
1179      // such a wallet and remove the encryption key records to avoid any future issues.
1180      // Although wallets without private keys should not have *ckey records, we should double check that.
1181      // Removing the mkey records is only safe if there are no *ckey records.
1182      if (pwallet->IsWalletFlagSet(WALLET_FLAG_DISABLE_PRIVATE_KEYS) && pwallet->HasEncryptionKeys() && !pwallet->HaveCryptedKeys()) {
1183          pwallet->WalletLogPrintf("Detected extraneous encryption keys in this wallet without private keys. Removing extraneous encryption keys.\n");
1184          for (const auto& [id, _] : pwallet->mapMasterKeys) {
1185              if (!EraseMasterKey(id)) {
1186                  pwallet->WalletLogPrintf("Error: Unable to remove extraneous encryption key '%u'. Wallet corrupt.\n", id);
1187                  return DBErrors::CORRUPT;
1188              }
1189          }
1190          pwallet->mapMasterKeys.clear();
1191      }
1192  
1193      return result;
1194  }
1195  
1196  static bool RunWithinTxn(WalletBatch& batch, std::string_view process_desc, const std::function<bool(WalletBatch&)>& func)
1197  {
1198      if (!batch.TxnBegin()) {
1199          LogDebug(BCLog::WALLETDB, "Error: cannot create db txn for %s\n", process_desc);
1200          return false;
1201      }
1202  
1203      // Run procedure
1204      if (!func(batch)) {
1205          LogDebug(BCLog::WALLETDB, "Error: %s failed\n", process_desc);
1206          batch.TxnAbort();
1207          return false;
1208      }
1209  
1210      if (!batch.TxnCommit()) {
1211          LogDebug(BCLog::WALLETDB, "Error: cannot commit db txn for %s\n", process_desc);
1212          return false;
1213      }
1214  
1215      // All good
1216      return true;
1217  }
1218  
1219  bool RunWithinTxn(WalletDatabase& database, std::string_view process_desc, const std::function<bool(WalletBatch&)>& func)
1220  {
1221      WalletBatch batch(database);
1222      return RunWithinTxn(batch, process_desc, func);
1223  }
1224  
1225  bool WalletBatch::WriteAddressPreviouslySpent(const CTxDestination& dest, bool previously_spent)
1226  {
1227      auto key{std::make_pair(DBKeys::DESTDATA, std::make_pair(EncodeDestination(dest), std::string("used")))};
1228      return previously_spent ? WriteIC(key, std::string("1")) : EraseIC(key);
1229  }
1230  
1231  bool WalletBatch::WriteAddressReceiveRequest(const CTxDestination& dest, const std::string& id, const std::string& receive_request)
1232  {
1233      return WriteIC(std::make_pair(DBKeys::DESTDATA, std::make_pair(EncodeDestination(dest), "rr" + id)), receive_request);
1234  }
1235  
1236  bool WalletBatch::EraseAddressReceiveRequest(const CTxDestination& dest, const std::string& id)
1237  {
1238      return EraseIC(std::make_pair(DBKeys::DESTDATA, std::make_pair(EncodeDestination(dest), "rr" + id)));
1239  }
1240  
1241  bool WalletBatch::EraseAddressData(const CTxDestination& dest)
1242  {
1243      DataStream prefix;
1244      prefix << DBKeys::DESTDATA << EncodeDestination(dest);
1245      return m_batch->ErasePrefix(prefix);
1246  }
1247  
1248  bool WalletBatch::WriteWalletFlags(const uint64_t flags)
1249  {
1250      return WriteIC(DBKeys::FLAGS, flags);
1251  }
1252  
1253  bool WalletBatch::EraseRecords(const std::unordered_set<std::string>& types)
1254  {
1255      return std::all_of(types.begin(), types.end(), [&](const std::string& type) {
1256          return m_batch->ErasePrefix(DataStream() << type);
1257      });
1258  }
1259  
1260  bool WalletBatch::TxnBegin()
1261  {
1262      return m_batch->TxnBegin();
1263  }
1264  
1265  bool WalletBatch::TxnCommit()
1266  {
1267      bool res = m_batch->TxnCommit();
1268      if (res) {
1269          for (const auto& listener : m_txn_listeners) {
1270              listener.on_commit();
1271          }
1272          // txn finished, clear listeners
1273          m_txn_listeners.clear();
1274      }
1275      return res;
1276  }
1277  
1278  bool WalletBatch::TxnAbort()
1279  {
1280      bool res = m_batch->TxnAbort();
1281      if (res) {
1282          for (const auto& listener : m_txn_listeners) {
1283              listener.on_abort();
1284          }
1285          // txn finished, clear listeners
1286          m_txn_listeners.clear();
1287      }
1288      return res;
1289  }
1290  
1291  void WalletBatch::RegisterTxnListener(const DbTxnListener& l)
1292  {
1293      assert(m_batch->HasActiveTxn());
1294      m_txn_listeners.emplace_back(l);
1295  }
1296  
1297  std::unique_ptr<WalletDatabase> MakeDatabase(const fs::path& path, const DatabaseOptions& options, DatabaseStatus& status, bilingual_str& error)
1298  {
1299      bool exists;
1300      try {
1301          exists = fs::symlink_status(path).type() != fs::file_type::not_found;
1302      } catch (const fs::filesystem_error& e) {
1303          error = Untranslated(strprintf("Failed to access database path '%s': %s", fs::PathToString(path), e.code().message()));
1304          status = DatabaseStatus::FAILED_BAD_PATH;
1305          return nullptr;
1306      }
1307  
1308      std::optional<DatabaseFormat> format;
1309      if (exists) {
1310          if (IsBDBFile(BDBDataFile(path))) {
1311              format = DatabaseFormat::BERKELEY_RO;
1312          }
1313          if (IsSQLiteFile(SQLiteDataFile(path))) {
1314              if (format) {
1315                  error = Untranslated(strprintf("Failed to load database path '%s'. Data is in ambiguous format.", fs::PathToString(path)));
1316                  status = DatabaseStatus::FAILED_BAD_FORMAT;
1317                  return nullptr;
1318              }
1319              format = DatabaseFormat::SQLITE;
1320          }
1321      } else if (options.require_existing) {
1322          error = Untranslated(strprintf("Failed to load database path '%s'. Path does not exist.", fs::PathToString(path)));
1323          status = DatabaseStatus::FAILED_NOT_FOUND;
1324          return nullptr;
1325      }
1326  
1327      if (!format && options.require_existing) {
1328          error = Untranslated(strprintf("Failed to load database path '%s'. Data is not in recognized format.", fs::PathToString(path)));
1329          status = DatabaseStatus::FAILED_BAD_FORMAT;
1330          return nullptr;
1331      }
1332  
1333      if (format && options.require_create) {
1334          error = Untranslated(strprintf("Failed to create database path '%s'. Database already exists.", fs::PathToString(path)));
1335          status = DatabaseStatus::FAILED_ALREADY_EXISTS;
1336          return nullptr;
1337      }
1338  
1339      // BERKELEY_RO can only be opened if require_format was set, which only occurs in migration.
1340      if (format && format == DatabaseFormat::BERKELEY_RO && (!options.require_format || options.require_format != DatabaseFormat::BERKELEY_RO)) {
1341          error = Untranslated(strprintf("Failed to open database path '%s'. The wallet appears to be a Legacy wallet, please use the wallet migration tool (migratewallet RPC or the GUI option).", fs::PathToString(path)));
1342          status = DatabaseStatus::FAILED_LEGACY_DISABLED;
1343          return nullptr;
1344      }
1345  
1346      // A db already exists so format is set, but options also specifies the format, so make sure they agree
1347      if (format && options.require_format && format != options.require_format) {
1348          error = Untranslated(strprintf("Failed to load database path '%s'. Data is not in required format.", fs::PathToString(path)));
1349          status = DatabaseStatus::FAILED_BAD_FORMAT;
1350          return nullptr;
1351      }
1352  
1353      // Format is not set when a db doesn't already exist, so use the format specified by the options if it is set.
1354      if (!format && options.require_format) format = options.require_format;
1355  
1356      if (!format) {
1357          format = DatabaseFormat::SQLITE;
1358      }
1359  
1360      if (format == DatabaseFormat::SQLITE) {
1361          return MakeSQLiteDatabase(path, options, status, error);
1362      }
1363  
1364      if (format == DatabaseFormat::BERKELEY_RO) {
1365          return MakeBerkeleyRODatabase(path, options, status, error);
1366      }
1367  
1368      error = Untranslated(STR_INTERNAL_BUG("Could not determine wallet format"));
1369      status = DatabaseStatus::FAILED_BAD_FORMAT;
1370      return nullptr;
1371  }
1372  } // namespace wallet
1373