spend.cpp raw

   1  // Copyright (c) 2021-2022 The Limenka developers
   2  // Distributed under the MIT software license, see the accompanying
   3  // file COPYING or http://www.opensource.org/licenses/mit-license.php.
   4  
   5  #include <algorithm>
   6  #include <common/args.h>
   7  #include <common/messages.h>
   8  #include <common/system.h>
   9  #include <consensus/amount.h>
  10  #include <consensus/validation.h>
  11  #include <interfaces/chain.h>
  12  #include <node/types.h>
  13  #include <numeric>
  14  #include <policy/policy.h>
  15  #include <primitives/transaction.h>
  16  #include <script/script.h>
  17  #include <script/signingprovider.h>
  18  #include <script/solver.h>
  19  #include <util/check.h>
  20  #include <util/moneystr.h>
  21  #include <util/rbf.h>
  22  #include <util/trace.h>
  23  #include <util/translation.h>
  24  #include <wallet/coincontrol.h>
  25  #include <wallet/fees.h>
  26  #include <wallet/receive.h>
  27  #include <wallet/spend.h>
  28  #include <wallet/transaction.h>
  29  #include <wallet/wallet.h>
  30  
  31  #include <cmath>
  32  
  33  using common::StringForFeeReason;
  34  using common::TransactionErrorString;
  35  using interfaces::FoundBlock;
  36  using node::TransactionError;
  37  
  38  TRACEPOINT_SEMAPHORE(coin_selection, selected_coins);
  39  TRACEPOINT_SEMAPHORE(coin_selection, normal_create_tx_internal);
  40  TRACEPOINT_SEMAPHORE(coin_selection, attempting_aps_create_tx);
  41  TRACEPOINT_SEMAPHORE(coin_selection, aps_create_tx_internal);
  42  
  43  namespace wallet {
  44  static constexpr size_t OUTPUT_GROUP_MAX_ENTRIES{100};
  45  
  46  /** Whether the descriptor represents, directly or not, a witness program. */
  47  static bool IsSegwit(const Descriptor& desc) {
  48      if (const auto typ = desc.GetOutputType()) return *typ != OutputType::LEGACY;
  49      return false;
  50  }
  51  
  52  /** Whether to assume ECDSA signatures' will be high-r. */
  53  static bool UseMaxSig(const std::optional<CTxIn>& txin, const CCoinControl* coin_control) {
  54      // Use max sig if watch only inputs were used or if this particular input is an external input
  55      // to ensure a sufficient fee is attained for the requested feerate.
  56      return coin_control && (coin_control->fAllowWatchOnly || (txin && coin_control->IsExternalSelected(txin->prevout)));
  57  }
  58  
  59  /** Get the size of an input (in witness units) once it's signed.
  60   *
  61   * @param desc The output script descriptor of the coin spent by this input.
  62   * @param txin Optionally the txin to estimate the size of. Used to determine the size of ECDSA signatures.
  63   * @param coin_control Information about the context to determine the size of ECDSA signatures.
  64   * @param tx_is_segwit Whether the transaction has at least a single input spending a segwit coin.
  65   * @param can_grind_r Whether the signer will be able to grind the R of the signature.
  66   */
  67  static std::optional<int64_t> MaxInputWeight(const Descriptor& desc, const std::optional<CTxIn>& txin,
  68                                               const CCoinControl* coin_control, const bool tx_is_segwit,
  69                                               const bool can_grind_r) {
  70      if (const auto sat_weight = desc.MaxSatisfactionWeight(!can_grind_r || UseMaxSig(txin, coin_control))) {
  71          if (const auto elems_count = desc.MaxSatisfactionElems()) {
  72              const bool is_segwit = IsSegwit(desc);
  73              // Account for the size of the scriptsig and the number of elements on the witness stack. Note
  74              // that if any input in the transaction is spending a witness program, we need to specify the
  75              // witness stack size for every input regardless of whether it is segwit itself.
  76              // NOTE: this also works in case of mixed scriptsig-and-witness such as in p2sh-wrapped segwit v0
  77              // outputs. In this case the size of the scriptsig length will always be one (since the redeemScript
  78              // is always a push of the witness program in this case, which is smaller than 253 bytes).
  79              const int64_t scriptsig_len = is_segwit ? 1 : GetSizeOfCompactSize(*sat_weight / WITNESS_SCALE_FACTOR);
  80              const int64_t witstack_len = is_segwit ? GetSizeOfCompactSize(*elems_count) : (tx_is_segwit ? 1 : 0);
  81              // previous txid + previous vout + sequence + scriptsig len + witstack size + scriptsig or witness
  82              // NOTE: sat_weight already accounts for the witness discount accordingly.
  83              return (32 + 4 + 4 + scriptsig_len) * WITNESS_SCALE_FACTOR + witstack_len + *sat_weight;
  84          }
  85      }
  86  
  87      return {};
  88  }
  89  
  90  int CalculateMaximumSignedInputSize(const CTxOut& txout, const COutPoint outpoint, const SigningProvider* provider, bool can_grind_r, const CCoinControl* coin_control)
  91  {
  92      if (!provider) return -1;
  93  
  94      if (const auto desc = InferDescriptor(txout.scriptPubKey, *provider)) {
  95          if (const auto weight = MaxInputWeight(*desc, {}, coin_control, true, can_grind_r)) {
  96              return static_cast<int>(GetVirtualTransactionSize(*weight, 0, 0));
  97          }
  98      }
  99  
 100      return -1;
 101  }
 102  
 103  int CalculateMaximumSignedInputSize(const CTxOut& txout, const CWallet* wallet, const CCoinControl* coin_control)
 104  {
 105      const std::unique_ptr<SigningProvider> provider = wallet->GetSolvingProvider(txout.scriptPubKey);
 106      return CalculateMaximumSignedInputSize(txout, COutPoint(), provider.get(), wallet->CanGrindR(), coin_control);
 107  }
 108  
 109  /** Infer a descriptor for the given output script. */
 110  static std::unique_ptr<Descriptor> GetDescriptor(const CWallet* wallet, const CCoinControl* coin_control,
 111                                                   const CScript script_pubkey)
 112  {
 113      MultiSigningProvider providers;
 114      for (const auto spkman: wallet->GetScriptPubKeyMans(script_pubkey)) {
 115          providers.AddProvider(spkman->GetSolvingProvider(script_pubkey));
 116      }
 117      if (coin_control) {
 118          providers.AddProvider(std::make_unique<FlatSigningProvider>(coin_control->m_external_provider));
 119      }
 120      return InferDescriptor(script_pubkey, providers);
 121  }
 122  
 123  /** Infer the maximum size of this input after it will be signed. */
 124  static std::optional<int64_t> GetSignedTxinWeight(const CWallet* wallet, const CCoinControl* coin_control,
 125                                                    const CTxIn& txin, const CTxOut& txo, const bool tx_is_segwit,
 126                                                    const bool can_grind_r)
 127  {
 128      // If weight was provided, use that.
 129      std::optional<int64_t> weight;
 130      if (coin_control && (weight = coin_control->GetInputWeight(txin.prevout))) {
 131          return weight.value();
 132      }
 133  
 134      // Otherwise, use the maximum satisfaction size provided by the descriptor.
 135      std::unique_ptr<Descriptor> desc{GetDescriptor(wallet, coin_control, txo.scriptPubKey)};
 136      if (desc) return MaxInputWeight(*desc, {txin}, coin_control, tx_is_segwit, can_grind_r);
 137  
 138      return {};
 139  }
 140  
 141  // txouts needs to be in the order of tx.vin
 142  TxSize CalculateMaximumSignedTxSize(const CTransaction &tx, const CWallet *wallet, const std::vector<CTxOut>& txouts, const CCoinControl* coin_control)
 143  {
 144      // version + nLockTime + input count + output count
 145      int64_t weight = (4 + 4 + GetSizeOfCompactSize(tx.vin.size()) + GetSizeOfCompactSize(tx.vout.size())) * WITNESS_SCALE_FACTOR;
 146      // Whether any input spends a witness program. Necessary to run before the next loop over the
 147      // inputs in order to accurately compute the compactSize length for the witness data per input.
 148      bool is_segwit = std::any_of(txouts.begin(), txouts.end(), [&](const CTxOut& txo) {
 149          std::unique_ptr<Descriptor> desc{GetDescriptor(wallet, coin_control, txo.scriptPubKey)};
 150          if (desc) return IsSegwit(*desc);
 151          return false;
 152      });
 153      // Segwit marker and flag
 154      if (is_segwit) weight += 2;
 155  
 156      // Add the size of the transaction outputs.
 157      for (const auto& txo : tx.vout) weight += GetSerializeSize(txo) * WITNESS_SCALE_FACTOR;
 158  
 159      // Add the size of the transaction inputs as if they were signed.
 160      for (uint32_t i = 0; i < txouts.size(); i++) {
 161          const auto txin_weight = GetSignedTxinWeight(wallet, coin_control, tx.vin[i], txouts[i], is_segwit, wallet->CanGrindR());
 162          if (!txin_weight) return TxSize{-1, -1};
 163          assert(*txin_weight > -1);
 164          weight += *txin_weight;
 165      }
 166  
 167      // It's ok to use 0 as the number of sigops since we never create any pathological transaction.
 168      return TxSize{GetVirtualTransactionSize(weight, 0, 0), weight};
 169  }
 170  
 171  TxSize CalculateMaximumSignedTxSize(const CTransaction &tx, const CWallet *wallet, const CCoinControl* coin_control)
 172  {
 173      std::vector<CTxOut> txouts;
 174      // Look up the inputs. The inputs are either in the wallet, or in coin_control.
 175      for (const CTxIn& input : tx.vin) {
 176          const auto mi = wallet->mapWallet.find(input.prevout.hash);
 177          // Can not estimate size without knowing the input details
 178          if (mi != wallet->mapWallet.end()) {
 179              assert(input.prevout.n < mi->second.tx->vout.size());
 180              txouts.emplace_back(mi->second.tx->vout.at(input.prevout.n));
 181          } else if (coin_control) {
 182              const auto& txout{coin_control->GetExternalOutput(input.prevout)};
 183              if (!txout) return TxSize{-1, -1};
 184              txouts.emplace_back(*txout);
 185          } else {
 186              return TxSize{-1, -1};
 187          }
 188      }
 189      return CalculateMaximumSignedTxSize(tx, wallet, txouts, coin_control);
 190  }
 191  
 192  size_t CoinsResult::Size() const
 193  {
 194      size_t size{0};
 195      for (const auto& it : coins) {
 196          size += it.second.size();
 197      }
 198      return size;
 199  }
 200  
 201  std::vector<COutput> CoinsResult::All() const
 202  {
 203      std::vector<COutput> all;
 204      all.reserve(coins.size());
 205      for (const auto& it : coins) {
 206          all.insert(all.end(), it.second.begin(), it.second.end());
 207      }
 208      return all;
 209  }
 210  
 211  void CoinsResult::Clear() {
 212      coins.clear();
 213  }
 214  
 215  void CoinsResult::Erase(const std::unordered_set<COutPoint, SaltedOutpointHasher>& coins_to_remove)
 216  {
 217      for (auto& [type, vec] : coins) {
 218          auto remove_it = std::remove_if(vec.begin(), vec.end(), [&](const COutput& coin) {
 219              // remove it if it's on the set
 220              if (coins_to_remove.count(coin.outpoint) == 0) return false;
 221  
 222              // update cached amounts
 223              total_amount -= coin.txout.nValue;
 224              if (coin.HasEffectiveValue()) total_effective_amount = *total_effective_amount - coin.GetEffectiveValue();
 225              return true;
 226          });
 227          vec.erase(remove_it, vec.end());
 228      }
 229  }
 230  
 231  void CoinsResult::Shuffle(FastRandomContext& rng_fast)
 232  {
 233      for (auto& it : coins) {
 234          std::shuffle(it.second.begin(), it.second.end(), rng_fast);
 235      }
 236  }
 237  
 238  void CoinsResult::Add(OutputType type, const COutput& out)
 239  {
 240      coins[type].emplace_back(out);
 241      total_amount += out.txout.nValue;
 242      if (out.HasEffectiveValue()) {
 243          total_effective_amount = total_effective_amount.has_value() ?
 244                  *total_effective_amount + out.GetEffectiveValue() : out.GetEffectiveValue();
 245      }
 246  }
 247  
 248  static OutputType GetOutputType(TxoutType type, bool is_from_p2sh)
 249  {
 250      switch (type) {
 251          case TxoutType::WITNESS_V1_TAPROOT:
 252              return OutputType::BECH32M;
 253          case TxoutType::WITNESS_V3_SPKHASH:
 254              return OutputType::P2SPKH;
 255          case TxoutType::WITNESS_V0_KEYHASH:
 256          case TxoutType::WITNESS_V0_SCRIPTHASH:
 257              if (is_from_p2sh) return OutputType::P2SH_SEGWIT;
 258              else return OutputType::BECH32;
 259          case TxoutType::SCRIPTHASH:
 260          case TxoutType::PUBKEYHASH:
 261              return OutputType::LEGACY;
 262          default:
 263              return OutputType::UNKNOWN;
 264      }
 265  }
 266  
 267  // Fetch and validate the coin control selected inputs.
 268  // Coins could be internal (from the wallet) or external.
 269  util::Result<PreSelectedInputs> FetchSelectedInputs(const CWallet& wallet, const CCoinControl& coin_control,
 270                                              const CoinSelectionParams& coin_selection_params)
 271  {
 272      PreSelectedInputs result;
 273      const bool can_grind_r = wallet.CanGrindR();
 274      std::map<COutPoint, CAmount> map_of_bump_fees = wallet.chain().calculateIndividualBumpFees(coin_control.ListSelected(), coin_selection_params.m_effective_feerate);
 275      for (const COutPoint& outpoint : coin_control.ListSelected()) {
 276          int64_t input_bytes = coin_control.GetInputWeight(outpoint).value_or(-1);
 277          if (input_bytes != -1) {
 278              input_bytes = GetVirtualTransactionSize(input_bytes, 0, 0);
 279          }
 280          CTxOut txout;
 281          if (auto ptr_wtx = wallet.GetWalletTx(outpoint.hash)) {
 282              // Clearly invalid input, fail
 283              if (ptr_wtx->tx->vout.size() <= outpoint.n) {
 284                  return util::Error{strprintf(_("Invalid pre-selected input %s"), outpoint.ToString())};
 285              }
 286              txout = ptr_wtx->tx->vout.at(outpoint.n);
 287              if (input_bytes == -1) {
 288                  input_bytes = CalculateMaximumSignedInputSize(txout, &wallet, &coin_control);
 289              }
 290          } else {
 291              // The input is external. We did not find the tx in mapWallet.
 292              const auto out{coin_control.GetExternalOutput(outpoint)};
 293              if (!out) {
 294                  return util::Error{strprintf(_("Not found pre-selected input %s"), outpoint.ToString())};
 295              }
 296  
 297              txout = *out;
 298          }
 299  
 300          if (input_bytes == -1) {
 301              input_bytes = CalculateMaximumSignedInputSize(txout, outpoint, &coin_control.m_external_provider, can_grind_r, &coin_control);
 302          }
 303  
 304          if (input_bytes == -1) {
 305              return util::Error{strprintf(_("Not solvable pre-selected input %s"), outpoint.ToString())}; // Not solvable, can't estimate size for fee
 306          }
 307  
 308          /* Set some defaults for depth, spendable, solvable, safe, time, and from_me as these don't matter for preset inputs since no selection is being done. */
 309          COutput output(outpoint, txout, /*depth=*/ 0, input_bytes, /*spendable=*/ true, /*solvable=*/ true, /*safe=*/ true, /*time=*/ 0, /*from_me=*/ false, coin_selection_params.m_effective_feerate);
 310          output.ApplyBumpFee(map_of_bump_fees.at(output.outpoint));
 311          result.Insert(output, coin_selection_params.m_subtract_fee_outputs);
 312      }
 313      return result;
 314  }
 315  
 316  CoinsResult AvailableCoins(const CWallet& wallet,
 317                             const CCoinControl* coinControl,
 318                             std::optional<CFeeRate> feerate,
 319                             const CoinFilterParams& params)
 320  {
 321      AssertLockHeld(wallet.cs_wallet);
 322  
 323      CoinsResult result;
 324      // Either the WALLET_FLAG_AVOID_REUSE flag is not set (in which case we always allow), or we default to avoiding, and only in the case where
 325      // a coin control object is provided, and has the avoid address reuse flag set to false, do we allow already used addresses
 326      bool allow_used_addresses = !wallet.IsWalletFlagSet(WALLET_FLAG_AVOID_REUSE) || (coinControl && !coinControl->m_avoid_address_reuse);
 327      const int min_depth = {coinControl ? coinControl->m_min_depth : DEFAULT_MIN_DEPTH};
 328      const int max_depth = {coinControl ? coinControl->m_max_depth : DEFAULT_MAX_DEPTH};
 329      const bool only_safe = {coinControl ? !coinControl->m_include_unsafe_inputs : true};
 330      const bool segwit_inputs_only = {coinControl ? coinControl->m_segwit_inputs_only : false};
 331      const bool can_grind_r = wallet.CanGrindR();
 332      std::vector<COutPoint> outpoints;
 333  
 334      std::set<uint256> trusted_parents;
 335      for (const auto& entry : wallet.mapWallet)
 336      {
 337          const uint256& txid = entry.first;
 338          const CWalletTx& wtx = entry.second;
 339  
 340          if (wallet.IsTxImmatureCoinBase(wtx) && !params.include_immature_coinbase)
 341              continue;
 342  
 343          int nDepth = wallet.GetTxDepthInMainChain(wtx);
 344          if (nDepth < 0)
 345              continue;
 346  
 347          // We should not consider coins which aren't at least in our mempool
 348          // It's possible for these to be conflicted via ancestors which we may never be able to detect
 349          if (nDepth == 0 && !wtx.InMempool())
 350              continue;
 351  
 352          bool safeTx = CachedTxIsTrusted(wallet, wtx, trusted_parents);
 353  
 354          // We should not consider coins from transactions that are replacing
 355          // other transactions.
 356          //
 357          // Example: There is a transaction A which is replaced by bumpfee
 358          // transaction B. In this case, we want to prevent creation of
 359          // a transaction B' which spends an output of B.
 360          //
 361          // Reason: If transaction A were initially confirmed, transactions B
 362          // and B' would no longer be valid, so the user would have to create
 363          // a new transaction C to replace B'. However, in the case of a
 364          // one-block reorg, transactions B' and C might BOTH be accepted,
 365          // when the user only wanted one of them. Specifically, there could
 366          // be a 1-block reorg away from the chain where transactions A and C
 367          // were accepted to another chain where B, B', and C were all
 368          // accepted.
 369          if (nDepth == 0 && wtx.mapValue.count("replaces_txid")) {
 370              safeTx = false;
 371          }
 372  
 373          // Similarly, we should not consider coins from transactions that
 374          // have been replaced. In the example above, we would want to prevent
 375          // creation of a transaction A' spending an output of A, because if
 376          // transaction B were initially confirmed, conflicting with A and
 377          // A', we wouldn't want to the user to create a transaction D
 378          // intending to replace A', but potentially resulting in a scenario
 379          // where A, A', and D could all be accepted (instead of just B and
 380          // D, or just A and A' like the user would want).
 381          if (nDepth == 0 && wtx.mapValue.count("replaced_by_txid")) {
 382              safeTx = false;
 383          }
 384  
 385          if (only_safe && !safeTx) {
 386              continue;
 387          }
 388  
 389          if (nDepth < min_depth || nDepth > max_depth) {
 390              continue;
 391          }
 392  
 393          bool tx_from_me = CachedTxIsFromMe(wallet, wtx, ISMINE_ALL);
 394  
 395          for (unsigned int i = 0; i < wtx.tx->vout.size(); i++) {
 396              const CTxOut& output = wtx.tx->vout[i];
 397              const COutPoint outpoint(Txid::FromUint256(txid), i);
 398  
 399              if (output.nValue < params.min_amount || output.nValue > params.max_amount)
 400                  continue;
 401  
 402              // Skip manually selected coins (the caller can fetch them directly)
 403              if (coinControl && coinControl->HasSelected() && coinControl->IsSelected(outpoint))
 404                  continue;
 405  
 406              if (wallet.IsLockedCoin(outpoint) && params.skip_locked)
 407                  continue;
 408  
 409              if (wallet.IsSpent(outpoint))
 410                  continue;
 411  
 412              isminetype mine = wallet.IsMine(output);
 413  
 414              if (mine == ISMINE_NO) {
 415                  continue;
 416              }
 417  
 418              if (!allow_used_addresses && wallet.IsSpentKey(output.scriptPubKey)) {
 419                  continue;
 420              }
 421  
 422              std::unique_ptr<SigningProvider> provider = wallet.GetSolvingProvider(output.scriptPubKey);
 423  
 424              if (segwit_inputs_only) {
 425                  if (provider) {
 426                      if (!IsSegWitOutput(*provider, output.scriptPubKey)) continue;
 427                  } else {
 428                      int witness_ver;
 429                      std::vector<unsigned char> witness_prog;
 430                      if (!output.scriptPubKey.IsWitnessProgram(witness_ver, witness_prog)) continue;
 431                  }
 432              }
 433  
 434              int input_bytes = CalculateMaximumSignedInputSize(output, COutPoint(), provider.get(), can_grind_r, coinControl);
 435              // Because CalculateMaximumSignedInputSize infers a solvable descriptor to get the satisfaction size,
 436              // it is safe to assume that this input is solvable if input_bytes is greater than -1.
 437              bool solvable = input_bytes > -1;
 438              bool spendable = ((mine & ISMINE_SPENDABLE) != ISMINE_NO) || (((mine & ISMINE_WATCH_ONLY) != ISMINE_NO) && (coinControl && coinControl->fAllowWatchOnly && solvable));
 439  
 440              // Filter by spendable outputs only
 441              if (!spendable && params.only_spendable) continue;
 442  
 443              // Obtain script type
 444              std::vector<std::vector<uint8_t>> script_solutions;
 445              TxoutType type = Solver(output.scriptPubKey, script_solutions);
 446  
 447              // If the output is P2SH and solvable, we want to know if it is
 448              // a P2SH (legacy) or one of P2SH-P2WPKH, P2SH-P2WSH (P2SH-Segwit). We can determine
 449              // this from the redeemScript. If the output is not solvable, it will be classified
 450              // as a P2SH (legacy), since we have no way of knowing otherwise without the redeemScript
 451              bool is_from_p2sh{false};
 452              if (type == TxoutType::SCRIPTHASH && solvable) {
 453                  CScript script;
 454                  if (!provider->GetCScript(CScriptID(uint160(script_solutions[0])), script)) continue;
 455                  type = Solver(script, script_solutions);
 456                  is_from_p2sh = true;
 457              }
 458  
 459              result.Add(GetOutputType(type, is_from_p2sh),
 460                         COutput(outpoint, output, nDepth, input_bytes, spendable, solvable, safeTx, wtx.GetTxTime(), tx_from_me, feerate));
 461  
 462              outpoints.push_back(outpoint);
 463  
 464              // Checks the sum amount of all UTXO's.
 465              if (params.min_sum_amount != MAX_MONEY) {
 466                  if (result.GetTotalAmount() >= params.min_sum_amount) {
 467                      return result;
 468                  }
 469              }
 470  
 471              // Checks the maximum number of UTXO's.
 472              if (params.max_count > 0 && result.Size() >= params.max_count) {
 473                  return result;
 474              }
 475          }
 476      }
 477  
 478      if (feerate.has_value()) {
 479          std::map<COutPoint, CAmount> map_of_bump_fees = wallet.chain().calculateIndividualBumpFees(outpoints, feerate.value());
 480  
 481          for (auto& [_, outputs] : result.coins) {
 482              for (auto& output : outputs) {
 483                  output.ApplyBumpFee(map_of_bump_fees.at(output.outpoint));
 484              }
 485          }
 486      }
 487  
 488      return result;
 489  }
 490  
 491  CoinsResult AvailableCoinsListUnspent(const CWallet& wallet, const CCoinControl* coinControl, CoinFilterParams params)
 492  {
 493      params.only_spendable = false;
 494      return AvailableCoins(wallet, coinControl, /*feerate=*/ std::nullopt, params);
 495  }
 496  
 497  const CTxOut& FindNonChangeParentOutput(const CWallet& wallet, const COutPoint& outpoint)
 498  {
 499      AssertLockHeld(wallet.cs_wallet);
 500      const CWalletTx* wtx{Assert(wallet.GetWalletTx(outpoint.hash))};
 501  
 502      const CTransaction* ptx = wtx->tx.get();
 503      int n = outpoint.n;
 504      while (OutputIsChange(wallet, ptx->vout[n]) && ptx->vin.size() > 0) {
 505          const COutPoint& prevout = ptx->vin[0].prevout;
 506          const CWalletTx* it = wallet.GetWalletTx(prevout.hash);
 507          if (!it || it->tx->vout.size() <= prevout.n ||
 508              !wallet.IsMine(it->tx->vout[prevout.n])) {
 509              break;
 510          }
 511          ptx = it->tx.get();
 512          n = prevout.n;
 513      }
 514      return ptx->vout[n];
 515  }
 516  
 517  std::map<CTxDestination, std::vector<COutput>> ListCoins(const CWallet& wallet)
 518  {
 519      AssertLockHeld(wallet.cs_wallet);
 520  
 521      std::map<CTxDestination, std::vector<COutput>> result;
 522  
 523      CCoinControl coin_control;
 524      // Include watch-only for LegacyScriptPubKeyMan wallets without private keys
 525      coin_control.fAllowWatchOnly = wallet.GetLegacyScriptPubKeyMan() && wallet.IsWalletFlagSet(WALLET_FLAG_DISABLE_PRIVATE_KEYS);
 526      CoinFilterParams coins_params;
 527      coins_params.only_spendable = false;
 528      coins_params.skip_locked = false;
 529      for (const COutput& coin : AvailableCoins(wallet, &coin_control, /*feerate=*/std::nullopt, coins_params).All()) {
 530          CTxDestination address;
 531          if ((coin.spendable || (wallet.IsWalletFlagSet(WALLET_FLAG_DISABLE_PRIVATE_KEYS) && coin.solvable))) {
 532              if (!ExtractDestination(FindNonChangeParentOutput(wallet, coin.outpoint).scriptPubKey, address)) {
 533                  // For backwards compatibility, we convert P2PK output scripts into PKHash destinations
 534                  if (auto pk_dest = std::get_if<PubKeyDestination>(&address)) {
 535                      address = PKHash(pk_dest->GetPubKey());
 536                  } else {
 537                      continue;
 538                  }
 539              }
 540              result[address].emplace_back(coin);
 541          }
 542      }
 543      return result;
 544  }
 545  
 546  FilteredOutputGroups GroupOutputs(const CWallet& wallet,
 547                            const CoinsResult& coins,
 548                            const CoinSelectionParams& coin_sel_params,
 549                            const std::vector<SelectionFilter>& filters,
 550                            std::vector<OutputGroup>& ret_discarded_groups)
 551  {
 552      FilteredOutputGroups filtered_groups;
 553  
 554      if (!coin_sel_params.m_avoid_partial_spends) {
 555          // Allowing partial spends means no grouping. Each COutput gets its own OutputGroup
 556          for (const auto& [type, outputs] : coins.coins) {
 557              for (const COutput& output : outputs) {
 558                  // Get mempool info
 559                  size_t ancestors, descendants;
 560                  wallet.chain().getTransactionAncestry(output.outpoint.hash, ancestors, descendants);
 561  
 562                  // Create a new group per output and add it to the all groups vector
 563                  OutputGroup group(coin_sel_params);
 564                  group.Insert(std::make_shared<COutput>(output), ancestors, descendants);
 565  
 566                  // Each filter maps to a different set of groups
 567                  bool accepted = false;
 568                  for (const auto& sel_filter : filters) {
 569                      const auto& filter = sel_filter.filter;
 570                      if (!group.EligibleForSpending(filter)) continue;
 571                      filtered_groups[filter].Push(group, type, /*insert_positive=*/true, /*insert_mixed=*/true);
 572                      accepted = true;
 573                  }
 574                  if (!accepted) ret_discarded_groups.emplace_back(group);
 575              }
 576          }
 577          return filtered_groups;
 578      }
 579  
 580      // We want to combine COutputs that have the same scriptPubKey into single OutputGroups
 581      // except when there are more than OUTPUT_GROUP_MAX_ENTRIES COutputs grouped in an OutputGroup.
 582      // To do this, we maintain a map where the key is the scriptPubKey and the value is a vector of OutputGroups.
 583      // For each COutput, we check if the scriptPubKey is in the map, and if it is, the COutput is added
 584      // to the last OutputGroup in the vector for the scriptPubKey. When the last OutputGroup has
 585      // OUTPUT_GROUP_MAX_ENTRIES COutputs, a new OutputGroup is added to the end of the vector.
 586      typedef std::map<std::pair<CScript, OutputType>, std::vector<OutputGroup>> ScriptPubKeyToOutgroup;
 587      const auto& insert_output = [&](
 588              const std::shared_ptr<COutput>& output, OutputType type, size_t ancestors, size_t descendants,
 589              ScriptPubKeyToOutgroup& groups_map) {
 590          std::vector<OutputGroup>& groups = groups_map[std::make_pair(output->txout.scriptPubKey,type)];
 591  
 592          if (groups.size() == 0) {
 593              // No OutputGroups for this scriptPubKey yet, add one
 594              groups.emplace_back(coin_sel_params);
 595          }
 596  
 597          // Get the last OutputGroup in the vector so that we can add the COutput to it
 598          // A pointer is used here so that group can be reassigned later if it is full.
 599          OutputGroup* group = &groups.back();
 600  
 601          // Check if this OutputGroup is full. We limit to OUTPUT_GROUP_MAX_ENTRIES when using -avoidpartialspends
 602          // to avoid surprising users with very high fees.
 603          if (group->m_outputs.size() >= OUTPUT_GROUP_MAX_ENTRIES) {
 604              // The last output group is full, add a new group to the vector and use that group for the insertion
 605              groups.emplace_back(coin_sel_params);
 606              group = &groups.back();
 607          }
 608  
 609          group->Insert(output, ancestors, descendants);
 610      };
 611  
 612      ScriptPubKeyToOutgroup spk_to_groups_map;
 613      ScriptPubKeyToOutgroup spk_to_positive_groups_map;
 614      for (const auto& [type, outs] : coins.coins) {
 615          for (const COutput& output : outs) {
 616              size_t ancestors, descendants;
 617              wallet.chain().getTransactionAncestry(output.outpoint.hash, ancestors, descendants);
 618  
 619              const auto& shared_output = std::make_shared<COutput>(output);
 620              // Filter for positive only before adding the output
 621              if (output.GetEffectiveValue() > 0) {
 622                  insert_output(shared_output, type, ancestors, descendants, spk_to_positive_groups_map);
 623              }
 624  
 625              // 'All' groups
 626              insert_output(shared_output, type, ancestors, descendants, spk_to_groups_map);
 627          }
 628      }
 629  
 630      // Now we go through the entire maps and pull out the OutputGroups
 631      const auto& push_output_groups = [&](const ScriptPubKeyToOutgroup& groups_map, bool positive_only) {
 632          for (const auto& [script, groups] : groups_map) {
 633              // Go through the vector backwards. This allows for the first item we deal with being the partial group.
 634              for (auto group_it = groups.rbegin(); group_it != groups.rend(); group_it++) {
 635                  const OutputGroup& group = *group_it;
 636  
 637                  // Each filter maps to a different set of groups
 638                  bool accepted = false;
 639                  for (const auto& sel_filter : filters) {
 640                      const auto& filter = sel_filter.filter;
 641                      if (!group.EligibleForSpending(filter)) continue;
 642  
 643                      // Don't include partial groups if there are full groups too and we don't want partial groups
 644                      if (group_it == groups.rbegin() && groups.size() > 1 && !filter.m_include_partial_groups) {
 645                          continue;
 646                      }
 647  
 648                      OutputType type = script.second;
 649                      // Either insert the group into the positive-only groups or the mixed ones.
 650                      filtered_groups[filter].Push(group, type, positive_only, /*insert_mixed=*/!positive_only);
 651                      accepted = true;
 652                  }
 653                  if (!accepted) ret_discarded_groups.emplace_back(group);
 654              }
 655          }
 656      };
 657  
 658      push_output_groups(spk_to_groups_map, /*positive_only=*/ false);
 659      push_output_groups(spk_to_positive_groups_map, /*positive_only=*/ true);
 660  
 661      return filtered_groups;
 662  }
 663  
 664  FilteredOutputGroups GroupOutputs(const CWallet& wallet,
 665                                    const CoinsResult& coins,
 666                                    const CoinSelectionParams& params,
 667                                    const std::vector<SelectionFilter>& filters)
 668  {
 669      std::vector<OutputGroup> unused;
 670      return GroupOutputs(wallet, coins, params, filters, unused);
 671  }
 672  
 673  // Returns true if the result contains an error and the message is not empty
 674  static bool HasErrorMsg(const util::Result<SelectionResult>& res) { return !util::ErrorString(res).empty(); }
 675  
 676  util::Result<SelectionResult> AttemptSelection(interfaces::Chain& chain, const CAmount& nTargetValue, OutputGroupTypeMap& groups,
 677                                 const CoinSelectionParams& coin_selection_params, bool allow_mixed_output_types)
 678  {
 679      // Run coin selection on each OutputType and compute the Waste Metric
 680      std::vector<SelectionResult> results;
 681      for (auto& [type, group] : groups.groups_by_type) {
 682          auto result{ChooseSelectionResult(chain, nTargetValue, group, coin_selection_params)};
 683          // If any specific error message appears here, then something particularly wrong happened.
 684          if (HasErrorMsg(result)) return result; // So let's return the specific error.
 685          // Append the favorable result.
 686          if (result) results.push_back(*result);
 687      }
 688      // If we have at least one solution for funding the transaction without mixing, choose the minimum one according to waste metric
 689      // and return the result
 690      if (results.size() > 0) return *std::min_element(results.begin(), results.end());
 691  
 692      // If we can't fund the transaction from any individual OutputType, run coin selection one last time
 693      // over all available coins, which would allow mixing.
 694      // If TypesCount() <= 1, there is nothing to mix.
 695      if (allow_mixed_output_types && groups.TypesCount() > 1) {
 696          return ChooseSelectionResult(chain, nTargetValue, groups.all_groups, coin_selection_params);
 697      }
 698      // Either mixing is not allowed and we couldn't find a solution from any single OutputType, or mixing was allowed and we still couldn't
 699      // find a solution using all available coins
 700      return util::Error();
 701  };
 702  
 703  util::Result<SelectionResult> ChooseSelectionResult(interfaces::Chain& chain, const CAmount& nTargetValue, Groups& groups, const CoinSelectionParams& coin_selection_params)
 704  {
 705      // Vector of results. We will choose the best one based on waste.
 706      std::vector<SelectionResult> results;
 707      std::vector<util::Result<SelectionResult>> errors;
 708      auto append_error = [&] (util::Result<SelectionResult>&& result) {
 709          // If any specific error message appears here, then something different from a simple "no selection found" happened.
 710          // Let's save it, so it can be retrieved to the user if no other selection algorithm succeeded.
 711          if (HasErrorMsg(result)) {
 712              errors.emplace_back(std::move(result));
 713          }
 714      };
 715  
 716      // Maximum allowed weight for selected coins.
 717      int max_transaction_weight = coin_selection_params.m_max_tx_weight.value_or(MAX_STANDARD_TX_WEIGHT);
 718      int tx_weight_no_input = coin_selection_params.tx_noinputs_size * WITNESS_SCALE_FACTOR;
 719      int max_selection_weight = max_transaction_weight - tx_weight_no_input;
 720      if (max_selection_weight <= 0) {
 721          return util::Error{_("Maximum transaction weight is less than transaction weight without inputs")};
 722      }
 723  
 724      // SFFO frequently causes issues in the context of changeless input sets: skip BnB when SFFO is active
 725      if (!coin_selection_params.m_subtract_fee_outputs) {
 726          if (auto bnb_result{SelectCoinsBnB(groups.positive_group, nTargetValue, coin_selection_params.m_cost_of_change, max_selection_weight)}) {
 727              results.push_back(*bnb_result);
 728          } else append_error(std::move(bnb_result));
 729      }
 730  
 731      // Deduct change weight because remaining Coin Selection algorithms can create change output
 732      int change_outputs_weight = coin_selection_params.change_output_size * WITNESS_SCALE_FACTOR;
 733      max_selection_weight -= change_outputs_weight;
 734      if (max_selection_weight < 0 && results.empty()) {
 735          return util::Error{_("Maximum transaction weight is too low, can not accommodate change output")};
 736      }
 737  
 738      // The knapsack solver has some legacy behavior where it will spend dust outputs. We retain this behavior, so don't filter for positive only here.
 739      if (auto knapsack_result{KnapsackSolver(groups.mixed_group, nTargetValue, coin_selection_params.m_min_change_target, coin_selection_params.rng_fast, max_selection_weight)}) {
 740          results.push_back(*knapsack_result);
 741      } else append_error(std::move(knapsack_result));
 742  
 743      if (coin_selection_params.m_effective_feerate > CFeeRate{3 * coin_selection_params.m_long_term_feerate}) { // Minimize input set for feerates of at least 3×LTFRE (default: 30 ṩ/vB+)
 744          if (auto cg_result{CoinGrinder(groups.positive_group, nTargetValue, coin_selection_params.m_min_change_target, max_selection_weight)}) {
 745              cg_result->RecalculateWaste(coin_selection_params.min_viable_change, coin_selection_params.m_cost_of_change, coin_selection_params.m_change_fee);
 746              results.push_back(*cg_result);
 747          } else {
 748              append_error(std::move(cg_result));
 749          }
 750      }
 751  
 752      if (auto srd_result{SelectCoinsSRD(groups.positive_group, nTargetValue, coin_selection_params.m_change_fee, coin_selection_params.rng_fast, max_selection_weight)}) {
 753          results.push_back(*srd_result);
 754      } else append_error(std::move(srd_result));
 755      
 756      // Privacy-first: temporal clustering selection
 757      if (coin_selection_params.m_privacy_first) {
 758          if (auto temporal_result{SelectCoinsTemporal(groups.positive_group, nTargetValue, coin_selection_params.m_temporal_window, coin_selection_params.m_target_merge_outputs, max_selection_weight)}) {
 759              results.push_back(*temporal_result);
 760          } else append_error(std::move(temporal_result));
 761      }
 762  
 763      if (results.empty()) {
 764          // No solution found, retrieve the first explicit error (if any).
 765          // future: add 'severity level' to errors so the worst one can be retrieved instead of the first one.
 766          return errors.empty() ? util::Error() : std::move(errors.front());
 767      }
 768  
 769      // If the chosen input set has unconfirmed inputs, check for synergies from overlapping ancestry
 770      for (auto& result : results) {
 771          std::vector<COutPoint> outpoints;
 772          std::set<std::shared_ptr<COutput>> coins = result.GetInputSet();
 773          CAmount summed_bump_fees = 0;
 774          for (auto& coin : coins) {
 775              if (coin->depth > 0) continue; // Bump fees only exist for unconfirmed inputs
 776              outpoints.push_back(coin->outpoint);
 777              summed_bump_fees += coin->ancestor_bump_fees;
 778          }
 779          std::optional<CAmount> combined_bump_fee = chain.calculateCombinedBumpFee(outpoints, coin_selection_params.m_effective_feerate);
 780          if (!combined_bump_fee.has_value()) {
 781              return util::Error{_("Failed to calculate bump fees, because unconfirmed UTXOs depend on an enormous cluster of unconfirmed transactions.")};
 782          }
 783          CAmount bump_fee_overestimate = summed_bump_fees - combined_bump_fee.value();
 784          if (bump_fee_overestimate) {
 785              result.SetBumpFeeDiscount(bump_fee_overestimate);
 786          }
 787          result.RecalculateWaste(coin_selection_params.min_viable_change, coin_selection_params.m_cost_of_change, coin_selection_params.m_change_fee);
 788      }
 789  
 790      // Choose the result with the least waste
 791      // If the waste is the same, choose the one which spends more inputs.
 792      return *std::min_element(results.begin(), results.end());
 793  }
 794  
 795  util::Result<SelectionResult> SelectCoins(const CWallet& wallet, CoinsResult& available_coins, const PreSelectedInputs& pre_set_inputs,
 796                                            const CAmount& nTargetValue, const CCoinControl& coin_control,
 797                                            const CoinSelectionParams& coin_selection_params)
 798  {
 799      // Deduct preset inputs amount from the search target
 800      CAmount selection_target = nTargetValue - pre_set_inputs.total_amount;
 801  
 802      // Return if automatic coin selection is disabled, and we don't cover the selection target
 803      if (!coin_control.m_allow_other_inputs && selection_target > 0) {
 804          return util::Error{_("The preselected coins total amount does not cover the transaction target. "
 805                               "Please allow other inputs to be automatically selected or include more coins manually")};
 806      }
 807  
 808      // Return if we can cover the target only with the preset inputs
 809      if (selection_target <= 0) {
 810          SelectionResult result(nTargetValue, SelectionAlgorithm::MANUAL);
 811          result.AddInputs(pre_set_inputs.coins, coin_selection_params.m_subtract_fee_outputs);
 812          result.RecalculateWaste(coin_selection_params.min_viable_change, coin_selection_params.m_cost_of_change, coin_selection_params.m_change_fee);
 813          return result;
 814      }
 815  
 816      // Return early if we cannot cover the target with the wallet's UTXO.
 817      // We use the total effective value if we are not subtracting fee from outputs and 'available_coins' contains the data.
 818      CAmount available_coins_total_amount = coin_selection_params.m_subtract_fee_outputs ? available_coins.GetTotalAmount() :
 819              (available_coins.GetEffectiveTotalAmount().has_value() ? *available_coins.GetEffectiveTotalAmount() : 0);
 820      if (selection_target > available_coins_total_amount) {
 821          return util::Error(); // Insufficient funds
 822      }
 823  
 824      // Start wallet Coin Selection procedure
 825      auto op_selection_result = AutomaticCoinSelection(wallet, available_coins, selection_target, coin_selection_params);
 826      if (!op_selection_result) return op_selection_result;
 827  
 828      // If needed, add preset inputs to the automatic coin selection result
 829      if (!pre_set_inputs.coins.empty()) {
 830          SelectionResult preselected(pre_set_inputs.total_amount, SelectionAlgorithm::MANUAL);
 831          preselected.AddInputs(pre_set_inputs.coins, coin_selection_params.m_subtract_fee_outputs);
 832          op_selection_result->Merge(preselected);
 833          op_selection_result->RecalculateWaste(coin_selection_params.min_viable_change,
 834                                                  coin_selection_params.m_cost_of_change,
 835                                                  coin_selection_params.m_change_fee);
 836  
 837          // Verify we haven't exceeded the maximum allowed weight
 838          int max_inputs_weight = coin_selection_params.m_max_tx_weight.value_or(MAX_STANDARD_TX_WEIGHT) - (coin_selection_params.tx_noinputs_size * WITNESS_SCALE_FACTOR);
 839          if (op_selection_result->GetWeight() > max_inputs_weight) {
 840              return util::Error{_("The combination of the pre-selected inputs and the wallet automatic inputs selection exceeds the transaction maximum weight. "
 841                                   "Please try sending a smaller amount or manually consolidating your wallet's UTXOs")};
 842          }
 843      }
 844      return op_selection_result;
 845  }
 846  
 847  util::Result<SelectionResult> AutomaticCoinSelection(const CWallet& wallet, CoinsResult& available_coins, const CAmount& value_to_select, const CoinSelectionParams& coin_selection_params)
 848  {
 849      unsigned int limit_ancestor_count = 0;
 850      unsigned int limit_descendant_count = 0;
 851      wallet.chain().getPackageLimits(limit_ancestor_count, limit_descendant_count);
 852      const size_t max_ancestors = (size_t)std::max<int64_t>(1, limit_ancestor_count);
 853      const size_t max_descendants = (size_t)std::max<int64_t>(1, limit_descendant_count);
 854      const bool fRejectLongChains = gArgs.GetBoolArg("-walletrejectlongchains", DEFAULT_WALLET_REJECT_LONG_CHAINS);
 855  
 856      // Cases where we have 101+ outputs all pointing to the same destination may result in
 857      // privacy leaks as they will potentially be deterministically sorted. We solve that by
 858      // explicitly shuffling the outputs before processing
 859      if (coin_selection_params.m_avoid_partial_spends && available_coins.Size() > OUTPUT_GROUP_MAX_ENTRIES) {
 860          available_coins.Shuffle(coin_selection_params.rng_fast);
 861      }
 862  
 863      // Coin Selection attempts to select inputs from a pool of eligible UTXOs to fund the
 864      // transaction at a target feerate. If an attempt fails, more attempts may be made using a more
 865      // permissive CoinEligibilityFilter.
 866      {
 867          // Place coins eligibility filters on a scope increasing order.
 868          std::vector<SelectionFilter> ordered_filters{
 869                  // If possible, fund the transaction with confirmed UTXOs only. Prefer at least six
 870                  // confirmations on outputs received from other wallets and only spend confirmed change.
 871                  {CoinEligibilityFilter(1, 6, 0), /*allow_mixed_output_types=*/false},
 872                  {CoinEligibilityFilter(1, 1, 0)},
 873          };
 874          // Fall back to using zero confirmation change (but with as few ancestors in the mempool as
 875          // possible) if we cannot fund the transaction otherwise.
 876          if (wallet.m_spend_zero_conf_change) {
 877              ordered_filters.push_back({CoinEligibilityFilter(0, 1, 2)});
 878              ordered_filters.push_back({CoinEligibilityFilter(0, 1, std::min(size_t{4}, max_ancestors/3), std::min(size_t{4}, max_descendants/3))});
 879              ordered_filters.push_back({CoinEligibilityFilter(0, 1, max_ancestors/2, max_descendants/2)});
 880              // If partial groups are allowed, relax the requirement of spending OutputGroups (groups
 881              // of UTXOs sent to the same address, which are obviously controlled by a single wallet)
 882              // in their entirety.
 883              ordered_filters.push_back({CoinEligibilityFilter(0, 1, max_ancestors-1, max_descendants-1, /*include_partial=*/true)});
 884              // Try with unsafe inputs if they are allowed. This may spend unconfirmed outputs
 885              // received from other wallets.
 886              if (coin_selection_params.m_include_unsafe_inputs) {
 887                  ordered_filters.push_back({CoinEligibilityFilter(/*conf_mine=*/0, /*conf_theirs*/0, max_ancestors-1, max_descendants-1, /*include_partial=*/true)});
 888              }
 889              // Try with unlimited ancestors/descendants. The transaction will still need to meet
 890              // mempool ancestor/descendant policy to be accepted to mempool and broadcasted, but
 891              // OutputGroups use heuristics that may overestimate ancestor/descendant counts.
 892              if (!fRejectLongChains) {
 893                  ordered_filters.push_back({CoinEligibilityFilter(0, 1, std::numeric_limits<uint64_t>::max(),
 894                                                                     std::numeric_limits<uint64_t>::max(),
 895                                                                     /*include_partial=*/true)});
 896              }
 897          }
 898  
 899          // Group outputs and map them by coin eligibility filter
 900          std::vector<OutputGroup> discarded_groups;
 901          FilteredOutputGroups filtered_groups = GroupOutputs(wallet, available_coins, coin_selection_params, ordered_filters, discarded_groups);
 902  
 903          // Check if we still have enough balance after applying filters (some coins might be discarded)
 904          CAmount total_discarded = 0;
 905          CAmount total_unconf_long_chain = 0;
 906          for (const auto& group : discarded_groups) {
 907              total_discarded += group.GetSelectionAmount();
 908              if (group.m_ancestors >= max_ancestors || group.m_descendants >= max_descendants) total_unconf_long_chain += group.GetSelectionAmount();
 909          }
 910  
 911          if (CAmount total_amount = available_coins.GetTotalAmount() - total_discarded; total_amount < value_to_select) {
 912              // Special case, too-long-mempool cluster.
 913              if (total_amount + total_unconf_long_chain > value_to_select) {
 914                  return util::Error{_("Unconfirmed UTXOs are available, but spending them creates a chain of transactions that will be rejected by the mempool")};
 915              }
 916              return util::Error{}; // General "Insufficient Funds"
 917          }
 918  
 919          // Walk-through the filters until the solution gets found.
 920          // If no solution is found, return the first detailed error (if any).
 921          // future: add "error level" so the worst one can be picked instead.
 922          std::vector<util::Result<SelectionResult>> res_detailed_errors;
 923          for (const auto& select_filter : ordered_filters) {
 924              auto it = filtered_groups.find(select_filter.filter);
 925              if (it == filtered_groups.end()) continue;
 926              if (auto res{AttemptSelection(wallet.chain(), value_to_select, it->second,
 927                                            coin_selection_params, select_filter.allow_mixed_output_types)}) {
 928                  return res; // result found
 929              } else {
 930                  // If any specific error message appears here, then something particularly wrong might have happened.
 931                  // Save the error and continue the selection process. So if no solutions gets found, we can return
 932                  // the detailed error to the upper layers.
 933                  if (HasErrorMsg(res)) res_detailed_errors.emplace_back(std::move(res));
 934              }
 935          }
 936  
 937          // Return right away if we have a detailed error
 938          if (!res_detailed_errors.empty()) return std::move(res_detailed_errors.front());
 939  
 940  
 941          // General "Insufficient Funds"
 942          return util::Error{};
 943      }
 944  }
 945  
 946  static bool IsCurrentForAntiFeeSniping(interfaces::Chain& chain, const uint256& block_hash)
 947  {
 948      if (chain.isInitialBlockDownload()) {
 949          return false;
 950      }
 951      constexpr int64_t MAX_ANTI_FEE_SNIPING_TIP_AGE = 8 * 60 * 60; // in seconds
 952      int64_t block_time;
 953      CHECK_NONFATAL(chain.findBlock(block_hash, FoundBlock().time(block_time)));
 954      if (block_time < (GetTime() - MAX_ANTI_FEE_SNIPING_TIP_AGE)) {
 955          return false;
 956      }
 957      return true;
 958  }
 959  
 960  /**
 961   * Set a height-based locktime for new transactions (uses the height of the
 962   * current chain tip unless we are not synced with the current chain
 963   */
 964  static void DiscourageFeeSniping(CMutableTransaction& tx, FastRandomContext& rng_fast,
 965                                   interfaces::Chain& chain, const uint256& block_hash, int block_height)
 966  {
 967      // All inputs must be added by now
 968      assert(!tx.vin.empty());
 969      // Discourage fee sniping.
 970      //
 971      // For a large miner the value of the transactions in the best block and
 972      // the mempool can exceed the cost of deliberately attempting to mine two
 973      // blocks to orphan the current best block. By setting nLockTime such that
 974      // only the next block can include the transaction, we discourage this
 975      // practice as the height restricted and limited blocksize gives miners
 976      // considering fee sniping fewer options for pulling off this attack.
 977      //
 978      // A simple way to think about this is from the wallet's point of view we
 979      // always want the blockchain to move forward. By setting nLockTime this
 980      // way we're basically making the statement that we only want this
 981      // transaction to appear in the next block; we don't want to potentially
 982      // encourage reorgs by allowing transactions to appear at lower heights
 983      // than the next block in forks of the best chain.
 984      //
 985      // Of course, the subsidy is high enough, and transaction volume low
 986      // enough, that fee sniping isn't a problem yet, but by implementing a fix
 987      // now we ensure code won't be written that makes assumptions about
 988      // nLockTime that preclude a fix later.
 989      if (IsCurrentForAntiFeeSniping(chain, block_hash)) {
 990          tx.nLockTime = block_height;
 991  
 992          // Secondly occasionally randomly pick a nLockTime even further back, so
 993          // that transactions that are delayed after signing for whatever reason,
 994          // e.g. high-latency mix networks and some CoinJoin implementations, have
 995          // better privacy.
 996          if (rng_fast.randrange(10) == 0) {
 997              tx.nLockTime = std::max(0, int(tx.nLockTime) - int(rng_fast.randrange(100)));
 998          }
 999      } else {
1000          // If our chain is lagging behind, we can't discourage fee sniping nor help
1001          // the privacy of high-latency transactions. To avoid leaking a potentially
1002          // unique "nLockTime fingerprint", set nLockTime to a constant.
1003          tx.nLockTime = 0;
1004      }
1005      // Sanity check all values
1006      assert(tx.nLockTime < LOCKTIME_THRESHOLD); // Type must be block height
1007      assert(tx.nLockTime <= uint64_t(block_height));
1008      for (const auto& in : tx.vin) {
1009          // Can not be FINAL for locktime to work
1010          assert(in.nSequence != CTxIn::SEQUENCE_FINAL);
1011          // May be MAX NONFINAL to disable both BIP68 and BIP125
1012          if (in.nSequence == CTxIn::MAX_SEQUENCE_NONFINAL) continue;
1013          // May be MAX BIP125 to disable BIP68 and enable BIP125
1014          if (in.nSequence == MAX_BIP125_RBF_SEQUENCE) continue;
1015          // The wallet does not support any other sequence-use right now.
1016          assert(false);
1017      }
1018  }
1019  
1020  void MaybeDiscourageFeeSniping2(const CWallet &wallet,
1021                                 CMutableTransaction& tx)
1022  {
1023      for (const CTxIn& tx_in : tx.vin) {
1024          // Checks sequence values consistent with DiscourageFeeSniping
1025          if (tx_in.nSequence != CTxIn::MAX_SEQUENCE_NONFINAL && tx_in.nSequence != MAX_BIP125_RBF_SEQUENCE) {
1026              // If an input has an incompatible sequence, we can't do anti-fee-sniping
1027              return;
1028          }
1029      }
1030  
1031      FastRandomContext rng_fast;
1032      LOCK(wallet.cs_wallet);
1033      DiscourageFeeSniping(tx, rng_fast, wallet.chain(), wallet.GetLastBlockHash(), wallet.GetLastBlockHeight());
1034  }
1035  
1036  size_t GetSerializeSizeForRecipient(const CRecipient& recipient)
1037  {
1038      return ::GetSerializeSize(CTxOut(recipient.nAmount, GetScriptForDestination(recipient.dest)));
1039  }
1040  
1041  bool IsDust(const CRecipient& recipient, const CFeeRate& dustRelayFee)
1042  {
1043      return ::IsDust(CTxOut(recipient.nAmount, GetScriptForDestination(recipient.dest)), dustRelayFee);
1044  }
1045  
1046  static util::Result<CreatedTransactionResult> CreateTransactionInternal(
1047          CWallet& wallet,
1048          const std::vector<CRecipient>& vecSend,
1049          std::optional<unsigned int> change_pos,
1050          const CCoinControl& coin_control,
1051          bool sign) EXCLUSIVE_LOCKS_REQUIRED(wallet.cs_wallet)
1052  {
1053      AssertLockHeld(wallet.cs_wallet);
1054  
1055      FastRandomContext rng_fast;
1056      CMutableTransaction txNew; // The resulting transaction that we make
1057  
1058      if (coin_control.m_version) {
1059          txNew.version = coin_control.m_version.value();
1060      }
1061  
1062      CoinSelectionParams coin_selection_params{rng_fast}; // Parameters for coin selection, init with dummy
1063      coin_selection_params.m_avoid_partial_spends = coin_control.m_avoid_partial_spends;
1064      coin_selection_params.m_include_unsafe_inputs = coin_control.m_include_unsafe_inputs;
1065      coin_selection_params.m_max_tx_weight = coin_control.m_max_tx_weight.value_or(MAX_STANDARD_TX_WEIGHT);
1066      coin_selection_params.m_privacy_first = coin_control.m_privacy_first;
1067      coin_selection_params.m_temporal_window = coin_control.m_temporal_window;
1068      coin_selection_params.m_target_merge_outputs = coin_control.m_target_merge_outputs;
1069      int minimum_tx_weight = MIN_STANDARD_TX_NONWITNESS_SIZE * WITNESS_SCALE_FACTOR;
1070      if (coin_selection_params.m_max_tx_weight.value() < minimum_tx_weight || coin_selection_params.m_max_tx_weight.value() > MAX_STANDARD_TX_WEIGHT) {
1071          return util::Error{strprintf(_("Maximum transaction weight must be between %d and %d"), minimum_tx_weight, MAX_STANDARD_TX_WEIGHT)};
1072      }
1073      // Set the long term feerate estimate to the wallet's consolidate feerate
1074      coin_selection_params.m_long_term_feerate = wallet.m_consolidate_feerate;
1075      // Static vsize overhead + outputs vsize. 4 nVersion, 4 nLocktime, 1 input count, 1 witness overhead (dummy, flag, stack size)
1076      coin_selection_params.tx_noinputs_size = 10 + GetSizeOfCompactSize(vecSend.size()); // bytes for output count
1077  
1078      CAmount recipients_sum = 0;
1079      const OutputType change_type = wallet.TransactionChangeType(coin_control.m_change_type ? *coin_control.m_change_type : wallet.m_default_change_type, vecSend);
1080      ReserveDestination reservedest(&wallet, change_type);
1081      unsigned int outputs_to_subtract_fee_from = 0; // The number of outputs which we are subtracting the fee from
1082      for (const auto& recipient : vecSend) {
1083          if (IsDust(recipient, wallet.chain().relayDustFee())) {
1084              return util::Error{_("Transaction amount too small")};
1085          }
1086  
1087          // Include the fee cost for outputs.
1088          coin_selection_params.tx_noinputs_size += GetSerializeSizeForRecipient(recipient);
1089          recipients_sum += recipient.nAmount;
1090  
1091          if (recipient.fSubtractFeeFromAmount) {
1092              outputs_to_subtract_fee_from++;
1093              coin_selection_params.m_subtract_fee_outputs = true;
1094          }
1095      }
1096  
1097      // Create change script that will be used if we need change
1098      CScript scriptChange;
1099      bilingual_str error; // possible error str
1100  
1101      // coin control: send change to custom address
1102      if (!std::get_if<CNoDestination>(&coin_control.destChange)) {
1103          scriptChange = GetScriptForDestination(coin_control.destChange);
1104      } else { // no coin control: send change to newly generated address
1105          // Note: We use a new key here to keep it from being obvious which side is the change.
1106          //  The drawback is that by not reusing a previous key, the change may be lost if a
1107          //  backup is restored, if the backup doesn't have the new private key for the change.
1108          //  If we reused the old key, it would be possible to add code to look for and
1109          //  rediscover unknown transactions that were written with keys of ours to recover
1110          //  post-backup change.
1111  
1112          // Reserve a new key pair from key pool. If it fails, provide a dummy
1113          // destination in case we don't need change.
1114          CTxDestination dest;
1115          auto op_dest = reservedest.GetReservedDestination(true);
1116          if (!op_dest) {
1117              error = _("Transaction needs a change address, but we can't generate it.") + Untranslated(" ") + util::ErrorString(op_dest);
1118          } else {
1119              dest = *op_dest;
1120              scriptChange = GetScriptForDestination(dest);
1121          }
1122          // A valid destination implies a change script (and
1123          // vice-versa). An empty change script will abort later, if the
1124          // change keypool ran out, but change is required.
1125          CHECK_NONFATAL(IsValidDestination(dest) != scriptChange.empty());
1126      }
1127      CTxOut change_prototype_txout(0, scriptChange);
1128      coin_selection_params.change_output_size = GetSerializeSize(change_prototype_txout);
1129  
1130      // Get size of spending the change output
1131      int change_spend_size = CalculateMaximumSignedInputSize(change_prototype_txout, &wallet, /*coin_control=*/nullptr);
1132      // If the wallet doesn't know how to sign change output, assume p2sh-p2wpkh
1133      // as lower-bound to allow BnB to do it's thing
1134      if (change_spend_size == -1) {
1135          coin_selection_params.change_spend_size = DUMMY_NESTED_P2WPKH_INPUT_SIZE;
1136      } else {
1137          coin_selection_params.change_spend_size = change_spend_size;
1138      }
1139  
1140      // Set discard feerate
1141      coin_selection_params.m_discard_feerate = GetDiscardRate(wallet);
1142  
1143      // Get the fee rate to use effective values in coin selection
1144      FeeCalculation feeCalc;
1145      coin_selection_params.m_effective_feerate = GetMinimumFeeRate(wallet, coin_control, &feeCalc);
1146      // Do not, ever, assume that it's fine to change the fee rate if the user has explicitly
1147      // provided one
1148      if (coin_control.m_feerate && coin_selection_params.m_effective_feerate > *coin_control.m_feerate) {
1149          return util::Error{strprintf(_("Fee rate (%s) is lower than the minimum fee rate setting (%s)"), coin_control.m_feerate->ToString(FeeEstimateMode::SAT_VB), coin_selection_params.m_effective_feerate.ToString(FeeEstimateMode::SAT_VB))};
1150      }
1151      if (feeCalc.reason == FeeReason::FALLBACK && !wallet.m_allow_fallback_fee) {
1152          // eventually allow a fallback fee
1153          return util::Error{strprintf(_("Fee estimation failed. Fallbackfee is disabled. Wait a few blocks or enable %s."), "-fallbackfee")};
1154      }
1155  
1156      // Calculate the cost of change
1157      // Cost of change is the cost of creating the change output + cost of spending the change output in the future.
1158      // For creating the change output now, we use the effective feerate.
1159      // For spending the change output in the future, we use the discard feerate for now.
1160      // So cost of change = (change output size * effective feerate) + (size of spending change output * discard feerate)
1161      coin_selection_params.m_change_fee = coin_selection_params.m_effective_feerate.GetFee(coin_selection_params.change_output_size);
1162      coin_selection_params.m_cost_of_change = coin_selection_params.m_discard_feerate.GetFee(coin_selection_params.change_spend_size) + coin_selection_params.m_change_fee;
1163  
1164      coin_selection_params.m_min_change_target = GenerateChangeTarget(std::floor(recipients_sum / vecSend.size()), coin_selection_params.m_change_fee, rng_fast);
1165  
1166      // The smallest change amount should be:
1167      // 1. at least equal to dust threshold
1168      // 2. at least 1 sat greater than fees to spend it at m_discard_feerate
1169      const auto dust = GetDustThreshold(change_prototype_txout, coin_selection_params.m_discard_feerate);
1170      const auto change_spend_fee = coin_selection_params.m_discard_feerate.GetFee(coin_selection_params.change_spend_size);
1171      coin_selection_params.min_viable_change = std::max(change_spend_fee + 1, dust);
1172  
1173      // Include the fees for things that aren't inputs, excluding the change output
1174      const CAmount not_input_fees = coin_selection_params.m_effective_feerate.GetFee(coin_selection_params.m_subtract_fee_outputs ? 0 : coin_selection_params.tx_noinputs_size);
1175      CAmount selection_target = recipients_sum + not_input_fees;
1176  
1177      // This can only happen if feerate is 0, and requested destinations are value of 0 (e.g. OP_RETURN)
1178      // and no pre-selected inputs. This will result in 0-input transaction, which is consensus-invalid anyways
1179      if (selection_target == 0 && !coin_control.HasSelected()) {
1180          return util::Error{_("Transaction requires one destination of non-0 value, a non-0 feerate, or a pre-selected input")};
1181      }
1182  
1183      // Fetch manually selected coins
1184      PreSelectedInputs preset_inputs;
1185      if (coin_control.HasSelected()) {
1186          auto res_fetch_inputs = FetchSelectedInputs(wallet, coin_control, coin_selection_params);
1187          if (!res_fetch_inputs) return util::Error{util::ErrorString(res_fetch_inputs)};
1188          preset_inputs = *res_fetch_inputs;
1189      }
1190  
1191      // Fetch wallet available coins if "other inputs" are
1192      // allowed (coins automatically selected by the wallet)
1193      CoinsResult available_coins;
1194      if (coin_control.m_allow_other_inputs) {
1195          available_coins = AvailableCoins(wallet, &coin_control, coin_selection_params.m_effective_feerate);
1196      }
1197  
1198      // Choose coins to use
1199      auto select_coins_res = SelectCoins(wallet, available_coins, preset_inputs, /*nTargetValue=*/selection_target, coin_control, coin_selection_params);
1200      if (!select_coins_res) {
1201          // 'SelectCoins' either returns a specific error message or, if empty, means a general "Insufficient funds".
1202          const bilingual_str& err = util::ErrorString(select_coins_res);
1203          return util::Error{err.empty() ?_("Insufficient funds") : err};
1204      }
1205      const SelectionResult& result = *select_coins_res;
1206      TRACEPOINT(coin_selection, selected_coins,
1207             wallet.GetName().c_str(),
1208             GetAlgorithmName(result.GetAlgo()).c_str(),
1209             result.GetTarget(),
1210             result.GetWaste(),
1211             result.GetSelectedValue());
1212  
1213      // vouts to the payees
1214      txNew.vout.reserve(vecSend.size() + 1); // + 1 because of possible later insert
1215      for (const auto& recipient : vecSend)
1216      {
1217          txNew.vout.emplace_back(recipient.nAmount, GetScriptForDestination(recipient.dest));
1218      }
1219      const CAmount change_amount = result.GetChange(coin_selection_params.min_viable_change, coin_selection_params.m_change_fee);
1220      if (change_amount > 0) {
1221          // Privacy: generate multiple change outputs if configured
1222          int change_count = coin_control.m_change_output_count;
1223          if (change_count < 1) change_count = 1;
1224          if (change_count > 8) change_count = 8;
1225          
1226          if (!change_pos) {
1227              // Insert change txn at random position:
1228              change_pos = rng_fast.randrange(txNew.vout.size() + 1);
1229          } else if ((unsigned int)*change_pos > txNew.vout.size()) {
1230              return util::Error{_("Transaction change output index out of range")};
1231          }
1232          
1233          // Create multiple change outputs with RANDOM varying amounts
1234          // Wider variance makes temporal rejoining harder
1235          std::vector<CAmount> change_amounts;
1236          CAmount remaining = change_amount;
1237          
1238          for (int i = 0; i < change_count - 1; ++i) {
1239              // Random split: between 10% and 90% of remaining
1240              CAmount min_split = remaining / 10;
1241              CAmount max_split = remaining - (change_count - i - 1) * (remaining / 10);  // ensure minimum for rest
1242              if (max_split <= min_split) max_split = min_split + 1;
1243              CAmount split = min_split + rng_fast.randrange(static_cast<int64_t>(max_split - min_split));
1244              change_amounts.push_back(split);
1245              remaining -= split;
1246          }
1247          change_amounts.push_back(remaining);  // Last output gets remainder
1248          
1249          // Shuffle the amounts for additional privacy
1250          for (int i = change_amounts.size() - 1; i > 0; --i) {
1251              int j = rng_fast.randrange(i + 1);
1252              std::swap(change_amounts[i], change_amounts[j]);
1253          }
1254          
1255          // Create the change outputs
1256          for (int i = 0; i < change_count; ++i) {
1257              if (change_amounts[i] > 0) {
1258                  CTxOut newTxOut(change_amounts[i], scriptChange);
1259                  txNew.vout.insert(txNew.vout.begin() + *change_pos + i, newTxOut);
1260              }
1261          }
1262      } else {
1263          change_pos = std::nullopt;
1264      }
1265  
1266      // Shuffle selected coins and fill in final vin
1267      std::vector<std::shared_ptr<COutput>> selected_coins = result.GetShuffledInputVector();
1268  
1269      if (coin_control.HasSelected() && coin_control.HasSelectedOrder()) {
1270          // When there are preselected inputs, we need to move them to be the first UTXOs
1271          // and have them be in the order selected. We can use stable_sort for this, where we
1272          // compare with the positions stored in coin_control. The COutputs that have positions
1273          // will be placed before those that don't, and those positions will be in order.
1274          std::stable_sort(selected_coins.begin(), selected_coins.end(),
1275              [&coin_control](const std::shared_ptr<COutput>& a, const std::shared_ptr<COutput>& b) {
1276                  auto a_pos = coin_control.GetSelectionPos(a->outpoint);
1277                  auto b_pos = coin_control.GetSelectionPos(b->outpoint);
1278                  if (a_pos.has_value() && b_pos.has_value()) {
1279                      return a_pos.value() < b_pos.value();
1280                  } else if (a_pos.has_value() && !b_pos.has_value()) {
1281                      return true;
1282                  } else {
1283                      return false;
1284                  }
1285              });
1286      }
1287  
1288      // The sequence number is set to non-maxint so that DiscourageFeeSniping
1289      // works.
1290      //
1291      // BIP125 defines opt-in RBF as any nSequence < maxint-1, so
1292      // we use the highest possible value in that range (maxint-2)
1293      // to avoid conflicting with other possible uses of nSequence,
1294      // and in the spirit of "smallest possible change from prior
1295      // behavior."
1296      bool use_anti_fee_sniping = true;
1297      const uint32_t default_sequence{coin_control.m_signal_bip125_rbf.value_or(wallet.m_signal_rbf) ? MAX_BIP125_RBF_SEQUENCE : CTxIn::MAX_SEQUENCE_NONFINAL};
1298      txNew.vin.reserve(selected_coins.size());
1299      for (const auto& coin : selected_coins) {
1300          std::optional<uint32_t> sequence = coin_control.GetSequence(coin->outpoint);
1301          if (sequence) {
1302              // If an input has a preset sequence, we can't do anti-fee-sniping
1303              use_anti_fee_sniping = false;
1304          }
1305          txNew.vin.emplace_back(coin->outpoint, CScript{}, sequence.value_or(default_sequence));
1306  
1307          auto scripts = coin_control.GetScripts(coin->outpoint);
1308          if (scripts.first) {
1309              txNew.vin.back().scriptSig = *scripts.first;
1310          }
1311          if (scripts.second) {
1312              txNew.vin.back().scriptWitness = *scripts.second;
1313          }
1314      }
1315      if (coin_control.m_locktime) {
1316          txNew.nLockTime = coin_control.m_locktime.value();
1317          // If we have a locktime set, we can't use anti-fee-sniping
1318          use_anti_fee_sniping = false;
1319      }
1320      if (use_anti_fee_sniping) {
1321          DiscourageFeeSniping(txNew, rng_fast, wallet.chain(), wallet.GetLastBlockHash(), wallet.GetLastBlockHeight());
1322      }
1323  
1324      // Calculate the transaction fee
1325      TxSize tx_sizes = CalculateMaximumSignedTxSize(CTransaction(txNew), &wallet, &coin_control);
1326      int nBytes = tx_sizes.vsize;
1327      if (nBytes == -1) {
1328          return util::Error{_("Missing solving data for estimating transaction size")};
1329      }
1330      CAmount fee_needed = coin_selection_params.m_effective_feerate.GetFee(nBytes) + result.GetTotalBumpFees();
1331      const CAmount output_value = CalculateOutputValue(txNew);
1332      Assume(recipients_sum + change_amount == output_value);
1333      CAmount current_fee = result.GetSelectedValue() - output_value;
1334  
1335      // Sanity check that the fee cannot be negative as that means we have more output value than input value
1336      if (current_fee < 0) {
1337          return util::Error{Untranslated(STR_INTERNAL_BUG("Fee paid < 0"))};
1338      }
1339  
1340      // If there is a change output and we overpay the fees then increase the change to match the fee needed
1341      if (change_pos && fee_needed < current_fee) {
1342          auto& change = txNew.vout.at(*change_pos);
1343          change.nValue += current_fee - fee_needed;
1344          current_fee = result.GetSelectedValue() - CalculateOutputValue(txNew);
1345          if (fee_needed != current_fee) {
1346              return util::Error{Untranslated(STR_INTERNAL_BUG("Change adjustment: Fee needed != fee paid"))};
1347          }
1348      }
1349  
1350      // Reduce output values for subtractFeeFromAmount
1351      if (coin_selection_params.m_subtract_fee_outputs) {
1352          CAmount to_reduce = fee_needed - current_fee;
1353          unsigned int i = 0;
1354          bool fFirst = true;
1355          for (const auto& recipient : vecSend)
1356          {
1357              if (change_pos && i == *change_pos) {
1358                  ++i;
1359              }
1360              CTxOut& txout = txNew.vout[i];
1361  
1362              if (recipient.fSubtractFeeFromAmount)
1363              {
1364                  txout.nValue -= to_reduce / outputs_to_subtract_fee_from; // Subtract fee equally from each selected recipient
1365  
1366                  if (fFirst) // first receiver pays the remainder not divisible by output count
1367                  {
1368                      fFirst = false;
1369                      txout.nValue -= to_reduce % outputs_to_subtract_fee_from;
1370                  }
1371  
1372                  // Error if this output is reduced to be below dust
1373                  if (IsDust(txout, wallet.chain().relayDustFee())) {
1374                      if (txout.nValue < 0) {
1375                          return util::Error{_("The transaction amount is too small to pay the fee")};
1376                      } else {
1377                          return util::Error{_("The transaction amount is too small to send after the fee has been deducted")};
1378                      }
1379                  }
1380              }
1381              ++i;
1382          }
1383          current_fee = result.GetSelectedValue() - CalculateOutputValue(txNew);
1384          if (fee_needed != current_fee) {
1385              return util::Error{Untranslated(STR_INTERNAL_BUG("SFFO: Fee needed != fee paid"))};
1386          }
1387      }
1388  
1389      // fee_needed should now always be less than or equal to the current fees that we pay.
1390      // If it is not, it is a bug.
1391      if (fee_needed > current_fee) {
1392          return util::Error{Untranslated(STR_INTERNAL_BUG("Fee needed > fee paid"))};
1393      }
1394  
1395      // Give up if change keypool ran out and change is required
1396      if (scriptChange.empty() && change_pos) {
1397          return util::Error{error};
1398      }
1399  
1400      if (sign && !wallet.SignTransaction(txNew)) {
1401          return util::Error{_("Signing transaction failed")};
1402      }
1403  
1404      // Return the constructed transaction data.
1405      CTransactionRef tx = MakeTransactionRef(std::move(txNew));
1406  
1407      // Limit size
1408      if ((sign && GetTransactionWeight(*tx) > MAX_STANDARD_TX_WEIGHT) ||
1409          (!sign && tx_sizes.weight > MAX_STANDARD_TX_WEIGHT))
1410      {
1411          return util::Error{_("Transaction too large")};
1412      }
1413  
1414      if (current_fee > wallet.m_default_max_tx_fee) {
1415          return util::Error{TransactionErrorString(TransactionError::MAX_FEE_EXCEEDED)};
1416      }
1417  
1418      if (gArgs.GetBoolArg("-walletrejectlongchains", DEFAULT_WALLET_REJECT_LONG_CHAINS)) {
1419          // Lastly, ensure this tx will pass the mempool's chain limits
1420          auto result = wallet.chain().checkChainLimits(tx);
1421          if (!result) {
1422              return util::Error{util::ErrorString(result)};
1423          }
1424      }
1425  
1426      // Before we return success, we assume any change key will be used to prevent
1427      // accidental reuse.
1428      reservedest.KeepDestination();
1429  
1430      wallet.WalletLogPrintf("Coin Selection: Algorithm:%s, Waste Metric Score:%d\n", GetAlgorithmName(result.GetAlgo()), result.GetWaste());
1431      wallet.WalletLogPrintf("Fee Calculation: Fee:%d Bytes:%u Tgt:%d (requested %d) Reason:\"%s\" Decay %.5f: Estimation: (%g - %g) %.2f%% %.1f/(%.1f %d mem %.1f out) Fail: (%g - %g) %.2f%% %.1f/(%.1f %d mem %.1f out)\n",
1432                current_fee, nBytes, feeCalc.returnedTarget, feeCalc.desiredTarget, StringForFeeReason(feeCalc.reason), feeCalc.est.decay,
1433                feeCalc.est.pass.start, feeCalc.est.pass.end,
1434                (feeCalc.est.pass.totalConfirmed + feeCalc.est.pass.inMempool + feeCalc.est.pass.leftMempool) > 0.0 ? 100 * feeCalc.est.pass.withinTarget / (feeCalc.est.pass.totalConfirmed + feeCalc.est.pass.inMempool + feeCalc.est.pass.leftMempool) : 0.0,
1435                feeCalc.est.pass.withinTarget, feeCalc.est.pass.totalConfirmed, feeCalc.est.pass.inMempool, feeCalc.est.pass.leftMempool,
1436                feeCalc.est.fail.start, feeCalc.est.fail.end,
1437                (feeCalc.est.fail.totalConfirmed + feeCalc.est.fail.inMempool + feeCalc.est.fail.leftMempool) > 0.0 ? 100 * feeCalc.est.fail.withinTarget / (feeCalc.est.fail.totalConfirmed + feeCalc.est.fail.inMempool + feeCalc.est.fail.leftMempool) : 0.0,
1438                feeCalc.est.fail.withinTarget, feeCalc.est.fail.totalConfirmed, feeCalc.est.fail.inMempool, feeCalc.est.fail.leftMempool);
1439      return CreatedTransactionResult(tx, current_fee, change_pos, feeCalc);
1440  }
1441  
1442  util::Result<CreatedTransactionResult> CreateTransaction(
1443          CWallet& wallet,
1444          const std::vector<CRecipient>& vecSend,
1445          std::optional<unsigned int> change_pos,
1446          const CCoinControl& coin_control,
1447          bool sign)
1448  {
1449      if (vecSend.empty()) {
1450          return util::Error{_("Transaction must have at least one recipient")};
1451      }
1452  
1453      if (std::any_of(vecSend.cbegin(), vecSend.cend(), [](const auto& recipient){ return recipient.nAmount < 0; })) {
1454          return util::Error{_("Transaction amounts must not be negative")};
1455      }
1456  
1457      LOCK(wallet.cs_wallet);
1458  
1459      auto res = CreateTransactionInternal(wallet, vecSend, change_pos, coin_control, sign);
1460      TRACEPOINT(coin_selection, normal_create_tx_internal,
1461             wallet.GetName().c_str(),
1462             bool(res),
1463             res ? res->fee : 0,
1464             res && res->change_pos.has_value() ? int32_t(*res->change_pos) : -1);
1465      if (!res) return res;
1466      const auto& txr_ungrouped = *res;
1467      // try with avoidpartialspends unless it's enabled already
1468      if (txr_ungrouped.fee > 0 /* 0 means non-functional fee rate estimation */ && wallet.m_max_aps_fee > -1 && !coin_control.m_avoid_partial_spends) {
1469          TRACEPOINT(coin_selection, attempting_aps_create_tx, wallet.GetName().c_str());
1470          CCoinControl tmp_cc = coin_control;
1471          tmp_cc.m_avoid_partial_spends = true;
1472  
1473          // Reuse the change destination from the first creation attempt to avoid skipping BIP44 indexes
1474          if (txr_ungrouped.change_pos) {
1475              ExtractDestination(txr_ungrouped.tx->vout[*txr_ungrouped.change_pos].scriptPubKey, tmp_cc.destChange);
1476          }
1477  
1478          auto txr_grouped = CreateTransactionInternal(wallet, vecSend, change_pos, tmp_cc, sign);
1479          // if fee of this alternative one is within the range of the max fee, we use this one
1480          const bool use_aps{txr_grouped.has_value() ? (txr_grouped->fee <= txr_ungrouped.fee + wallet.m_max_aps_fee) : false};
1481          TRACEPOINT(coin_selection, aps_create_tx_internal,
1482                 wallet.GetName().c_str(),
1483                 use_aps,
1484                 txr_grouped.has_value(),
1485                 txr_grouped.has_value() ? txr_grouped->fee : 0,
1486                 txr_grouped.has_value() && txr_grouped->change_pos.has_value() ? int32_t(*txr_grouped->change_pos) : -1);
1487          if (txr_grouped) {
1488              wallet.WalletLogPrintf("Fee non-grouped = %lld, grouped = %lld, using %s\n",
1489                  txr_ungrouped.fee, txr_grouped->fee, use_aps ? "grouped" : "non-grouped");
1490              if (use_aps) return txr_grouped;
1491          }
1492      }
1493      return res;
1494  }
1495  
1496  util::Result<CreatedTransactionResult> FundTransaction(CWallet& wallet, const CMutableTransaction& tx, const std::vector<CRecipient>& vecSend, std::optional<unsigned int> change_pos, bool lockUnspents, CCoinControl coinControl)
1497  {
1498      // We want to make sure tx.vout is not used now that we are passing outputs as a vector of recipients.
1499      // This sets us up to remove tx completely in a future PR in favor of passing the inputs directly.
1500      assert(tx.vout.empty());
1501  
1502      // Set the user desired locktime
1503      coinControl.m_locktime = tx.nLockTime;
1504  
1505      // Set the user desired version
1506      coinControl.m_version = tx.version;
1507  
1508      // Acquire the locks to prevent races to the new locked unspents between the
1509      // CreateTransaction call and LockCoin calls (when lockUnspents is true).
1510      LOCK(wallet.cs_wallet);
1511  
1512      // Fetch specified UTXOs from the UTXO set to get the scriptPubKeys and values of the outputs being selected
1513      // and to match with the given solving_data. Only used for non-wallet outputs.
1514      std::map<COutPoint, Coin> coins;
1515      for (const CTxIn& txin : tx.vin) {
1516          coins[txin.prevout]; // Create empty map entry keyed by prevout.
1517      }
1518      wallet.chain().findCoins(coins);
1519  
1520      for (const CTxIn& txin : tx.vin) {
1521          const auto& outPoint = txin.prevout;
1522          PreselectedInput& preset_txin = coinControl.Select(outPoint);
1523          if (!wallet.IsMine(outPoint)) {
1524              if (coins[outPoint].out.IsNull()) {
1525                  return util::Error{_("Unable to find UTXO for external input")};
1526              }
1527  
1528              // The input was not in the wallet, but is in the UTXO set, so select as external
1529              preset_txin.SetTxOut(coins[outPoint].out);
1530          }
1531          preset_txin.SetSequence(txin.nSequence);
1532          preset_txin.SetScriptSig(txin.scriptSig);
1533          preset_txin.SetScriptWitness(txin.scriptWitness);
1534      }
1535  
1536      auto res = CreateTransaction(wallet, vecSend, change_pos, coinControl, false);
1537      if (!res) {
1538          return res;
1539      }
1540  
1541      if (lockUnspents) {
1542          for (const CTxIn& txin : res->tx->vin) {
1543              wallet.LockCoin(txin.prevout);
1544          }
1545      }
1546  
1547      return res;
1548  }
1549  } // namespace wallet
1550