1 // Copyright (c) 2021-2022 The Limenka developers
2 // Distributed under the MIT software license, see the accompanying
3 // file COPYING or http://www.opensource.org/licenses/mit-license.php.
4 5 #include <algorithm>
6 #include <common/args.h>
7 #include <common/messages.h>
8 #include <common/system.h>
9 #include <consensus/amount.h>
10 #include <consensus/validation.h>
11 #include <interfaces/chain.h>
12 #include <node/types.h>
13 #include <numeric>
14 #include <policy/policy.h>
15 #include <primitives/transaction.h>
16 #include <script/script.h>
17 #include <script/signingprovider.h>
18 #include <script/solver.h>
19 #include <util/check.h>
20 #include <util/moneystr.h>
21 #include <util/rbf.h>
22 #include <util/trace.h>
23 #include <util/translation.h>
24 #include <wallet/coincontrol.h>
25 #include <wallet/fees.h>
26 #include <wallet/receive.h>
27 #include <wallet/spend.h>
28 #include <wallet/transaction.h>
29 #include <wallet/wallet.h>
30 31 #include <cmath>
32 33 using common::StringForFeeReason;
34 using common::TransactionErrorString;
35 using interfaces::FoundBlock;
36 using node::TransactionError;
37 38 TRACEPOINT_SEMAPHORE(coin_selection, selected_coins);
39 TRACEPOINT_SEMAPHORE(coin_selection, normal_create_tx_internal);
40 TRACEPOINT_SEMAPHORE(coin_selection, attempting_aps_create_tx);
41 TRACEPOINT_SEMAPHORE(coin_selection, aps_create_tx_internal);
42 43 namespace wallet {
44 static constexpr size_t OUTPUT_GROUP_MAX_ENTRIES{100};
45 46 /** Whether the descriptor represents, directly or not, a witness program. */
47 static bool IsSegwit(const Descriptor& desc) {
48 if (const auto typ = desc.GetOutputType()) return *typ != OutputType::LEGACY;
49 return false;
50 }
51 52 /** Whether to assume ECDSA signatures' will be high-r. */
53 static bool UseMaxSig(const std::optional<CTxIn>& txin, const CCoinControl* coin_control) {
54 // Use max sig if watch only inputs were used or if this particular input is an external input
55 // to ensure a sufficient fee is attained for the requested feerate.
56 return coin_control && (coin_control->fAllowWatchOnly || (txin && coin_control->IsExternalSelected(txin->prevout)));
57 }
58 59 /** Get the size of an input (in witness units) once it's signed.
60 *
61 * @param desc The output script descriptor of the coin spent by this input.
62 * @param txin Optionally the txin to estimate the size of. Used to determine the size of ECDSA signatures.
63 * @param coin_control Information about the context to determine the size of ECDSA signatures.
64 * @param tx_is_segwit Whether the transaction has at least a single input spending a segwit coin.
65 * @param can_grind_r Whether the signer will be able to grind the R of the signature.
66 */
67 static std::optional<int64_t> MaxInputWeight(const Descriptor& desc, const std::optional<CTxIn>& txin,
68 const CCoinControl* coin_control, const bool tx_is_segwit,
69 const bool can_grind_r) {
70 if (const auto sat_weight = desc.MaxSatisfactionWeight(!can_grind_r || UseMaxSig(txin, coin_control))) {
71 if (const auto elems_count = desc.MaxSatisfactionElems()) {
72 const bool is_segwit = IsSegwit(desc);
73 // Account for the size of the scriptsig and the number of elements on the witness stack. Note
74 // that if any input in the transaction is spending a witness program, we need to specify the
75 // witness stack size for every input regardless of whether it is segwit itself.
76 // NOTE: this also works in case of mixed scriptsig-and-witness such as in p2sh-wrapped segwit v0
77 // outputs. In this case the size of the scriptsig length will always be one (since the redeemScript
78 // is always a push of the witness program in this case, which is smaller than 253 bytes).
79 const int64_t scriptsig_len = is_segwit ? 1 : GetSizeOfCompactSize(*sat_weight / WITNESS_SCALE_FACTOR);
80 const int64_t witstack_len = is_segwit ? GetSizeOfCompactSize(*elems_count) : (tx_is_segwit ? 1 : 0);
81 // previous txid + previous vout + sequence + scriptsig len + witstack size + scriptsig or witness
82 // NOTE: sat_weight already accounts for the witness discount accordingly.
83 return (32 + 4 + 4 + scriptsig_len) * WITNESS_SCALE_FACTOR + witstack_len + *sat_weight;
84 }
85 }
86 87 return {};
88 }
89 90 int CalculateMaximumSignedInputSize(const CTxOut& txout, const COutPoint outpoint, const SigningProvider* provider, bool can_grind_r, const CCoinControl* coin_control)
91 {
92 if (!provider) return -1;
93 94 if (const auto desc = InferDescriptor(txout.scriptPubKey, *provider)) {
95 if (const auto weight = MaxInputWeight(*desc, {}, coin_control, true, can_grind_r)) {
96 return static_cast<int>(GetVirtualTransactionSize(*weight, 0, 0));
97 }
98 }
99 100 return -1;
101 }
102 103 int CalculateMaximumSignedInputSize(const CTxOut& txout, const CWallet* wallet, const CCoinControl* coin_control)
104 {
105 const std::unique_ptr<SigningProvider> provider = wallet->GetSolvingProvider(txout.scriptPubKey);
106 return CalculateMaximumSignedInputSize(txout, COutPoint(), provider.get(), wallet->CanGrindR(), coin_control);
107 }
108 109 /** Infer a descriptor for the given output script. */
110 static std::unique_ptr<Descriptor> GetDescriptor(const CWallet* wallet, const CCoinControl* coin_control,
111 const CScript script_pubkey)
112 {
113 MultiSigningProvider providers;
114 for (const auto spkman: wallet->GetScriptPubKeyMans(script_pubkey)) {
115 providers.AddProvider(spkman->GetSolvingProvider(script_pubkey));
116 }
117 if (coin_control) {
118 providers.AddProvider(std::make_unique<FlatSigningProvider>(coin_control->m_external_provider));
119 }
120 return InferDescriptor(script_pubkey, providers);
121 }
122 123 /** Infer the maximum size of this input after it will be signed. */
124 static std::optional<int64_t> GetSignedTxinWeight(const CWallet* wallet, const CCoinControl* coin_control,
125 const CTxIn& txin, const CTxOut& txo, const bool tx_is_segwit,
126 const bool can_grind_r)
127 {
128 // If weight was provided, use that.
129 std::optional<int64_t> weight;
130 if (coin_control && (weight = coin_control->GetInputWeight(txin.prevout))) {
131 return weight.value();
132 }
133 134 // Otherwise, use the maximum satisfaction size provided by the descriptor.
135 std::unique_ptr<Descriptor> desc{GetDescriptor(wallet, coin_control, txo.scriptPubKey)};
136 if (desc) return MaxInputWeight(*desc, {txin}, coin_control, tx_is_segwit, can_grind_r);
137 138 return {};
139 }
140 141 // txouts needs to be in the order of tx.vin
142 TxSize CalculateMaximumSignedTxSize(const CTransaction &tx, const CWallet *wallet, const std::vector<CTxOut>& txouts, const CCoinControl* coin_control)
143 {
144 // version + nLockTime + input count + output count
145 int64_t weight = (4 + 4 + GetSizeOfCompactSize(tx.vin.size()) + GetSizeOfCompactSize(tx.vout.size())) * WITNESS_SCALE_FACTOR;
146 // Whether any input spends a witness program. Necessary to run before the next loop over the
147 // inputs in order to accurately compute the compactSize length for the witness data per input.
148 bool is_segwit = std::any_of(txouts.begin(), txouts.end(), [&](const CTxOut& txo) {
149 std::unique_ptr<Descriptor> desc{GetDescriptor(wallet, coin_control, txo.scriptPubKey)};
150 if (desc) return IsSegwit(*desc);
151 return false;
152 });
153 // Segwit marker and flag
154 if (is_segwit) weight += 2;
155 156 // Add the size of the transaction outputs.
157 for (const auto& txo : tx.vout) weight += GetSerializeSize(txo) * WITNESS_SCALE_FACTOR;
158 159 // Add the size of the transaction inputs as if they were signed.
160 for (uint32_t i = 0; i < txouts.size(); i++) {
161 const auto txin_weight = GetSignedTxinWeight(wallet, coin_control, tx.vin[i], txouts[i], is_segwit, wallet->CanGrindR());
162 if (!txin_weight) return TxSize{-1, -1};
163 assert(*txin_weight > -1);
164 weight += *txin_weight;
165 }
166 167 // It's ok to use 0 as the number of sigops since we never create any pathological transaction.
168 return TxSize{GetVirtualTransactionSize(weight, 0, 0), weight};
169 }
170 171 TxSize CalculateMaximumSignedTxSize(const CTransaction &tx, const CWallet *wallet, const CCoinControl* coin_control)
172 {
173 std::vector<CTxOut> txouts;
174 // Look up the inputs. The inputs are either in the wallet, or in coin_control.
175 for (const CTxIn& input : tx.vin) {
176 const auto mi = wallet->mapWallet.find(input.prevout.hash);
177 // Can not estimate size without knowing the input details
178 if (mi != wallet->mapWallet.end()) {
179 assert(input.prevout.n < mi->second.tx->vout.size());
180 txouts.emplace_back(mi->second.tx->vout.at(input.prevout.n));
181 } else if (coin_control) {
182 const auto& txout{coin_control->GetExternalOutput(input.prevout)};
183 if (!txout) return TxSize{-1, -1};
184 txouts.emplace_back(*txout);
185 } else {
186 return TxSize{-1, -1};
187 }
188 }
189 return CalculateMaximumSignedTxSize(tx, wallet, txouts, coin_control);
190 }
191 192 size_t CoinsResult::Size() const
193 {
194 size_t size{0};
195 for (const auto& it : coins) {
196 size += it.second.size();
197 }
198 return size;
199 }
200 201 std::vector<COutput> CoinsResult::All() const
202 {
203 std::vector<COutput> all;
204 all.reserve(coins.size());
205 for (const auto& it : coins) {
206 all.insert(all.end(), it.second.begin(), it.second.end());
207 }
208 return all;
209 }
210 211 void CoinsResult::Clear() {
212 coins.clear();
213 }
214 215 void CoinsResult::Erase(const std::unordered_set<COutPoint, SaltedOutpointHasher>& coins_to_remove)
216 {
217 for (auto& [type, vec] : coins) {
218 auto remove_it = std::remove_if(vec.begin(), vec.end(), [&](const COutput& coin) {
219 // remove it if it's on the set
220 if (coins_to_remove.count(coin.outpoint) == 0) return false;
221 222 // update cached amounts
223 total_amount -= coin.txout.nValue;
224 if (coin.HasEffectiveValue()) total_effective_amount = *total_effective_amount - coin.GetEffectiveValue();
225 return true;
226 });
227 vec.erase(remove_it, vec.end());
228 }
229 }
230 231 void CoinsResult::Shuffle(FastRandomContext& rng_fast)
232 {
233 for (auto& it : coins) {
234 std::shuffle(it.second.begin(), it.second.end(), rng_fast);
235 }
236 }
237 238 void CoinsResult::Add(OutputType type, const COutput& out)
239 {
240 coins[type].emplace_back(out);
241 total_amount += out.txout.nValue;
242 if (out.HasEffectiveValue()) {
243 total_effective_amount = total_effective_amount.has_value() ?
244 *total_effective_amount + out.GetEffectiveValue() : out.GetEffectiveValue();
245 }
246 }
247 248 static OutputType GetOutputType(TxoutType type, bool is_from_p2sh)
249 {
250 switch (type) {
251 case TxoutType::WITNESS_V1_TAPROOT:
252 return OutputType::BECH32M;
253 case TxoutType::WITNESS_V3_SPKHASH:
254 return OutputType::P2SPKH;
255 case TxoutType::WITNESS_V0_KEYHASH:
256 case TxoutType::WITNESS_V0_SCRIPTHASH:
257 if (is_from_p2sh) return OutputType::P2SH_SEGWIT;
258 else return OutputType::BECH32;
259 case TxoutType::SCRIPTHASH:
260 case TxoutType::PUBKEYHASH:
261 return OutputType::LEGACY;
262 default:
263 return OutputType::UNKNOWN;
264 }
265 }
266 267 // Fetch and validate the coin control selected inputs.
268 // Coins could be internal (from the wallet) or external.
269 util::Result<PreSelectedInputs> FetchSelectedInputs(const CWallet& wallet, const CCoinControl& coin_control,
270 const CoinSelectionParams& coin_selection_params)
271 {
272 PreSelectedInputs result;
273 const bool can_grind_r = wallet.CanGrindR();
274 std::map<COutPoint, CAmount> map_of_bump_fees = wallet.chain().calculateIndividualBumpFees(coin_control.ListSelected(), coin_selection_params.m_effective_feerate);
275 for (const COutPoint& outpoint : coin_control.ListSelected()) {
276 int64_t input_bytes = coin_control.GetInputWeight(outpoint).value_or(-1);
277 if (input_bytes != -1) {
278 input_bytes = GetVirtualTransactionSize(input_bytes, 0, 0);
279 }
280 CTxOut txout;
281 if (auto ptr_wtx = wallet.GetWalletTx(outpoint.hash)) {
282 // Clearly invalid input, fail
283 if (ptr_wtx->tx->vout.size() <= outpoint.n) {
284 return util::Error{strprintf(_("Invalid pre-selected input %s"), outpoint.ToString())};
285 }
286 txout = ptr_wtx->tx->vout.at(outpoint.n);
287 if (input_bytes == -1) {
288 input_bytes = CalculateMaximumSignedInputSize(txout, &wallet, &coin_control);
289 }
290 } else {
291 // The input is external. We did not find the tx in mapWallet.
292 const auto out{coin_control.GetExternalOutput(outpoint)};
293 if (!out) {
294 return util::Error{strprintf(_("Not found pre-selected input %s"), outpoint.ToString())};
295 }
296 297 txout = *out;
298 }
299 300 if (input_bytes == -1) {
301 input_bytes = CalculateMaximumSignedInputSize(txout, outpoint, &coin_control.m_external_provider, can_grind_r, &coin_control);
302 }
303 304 if (input_bytes == -1) {
305 return util::Error{strprintf(_("Not solvable pre-selected input %s"), outpoint.ToString())}; // Not solvable, can't estimate size for fee
306 }
307 308 /* Set some defaults for depth, spendable, solvable, safe, time, and from_me as these don't matter for preset inputs since no selection is being done. */
309 COutput output(outpoint, txout, /*depth=*/ 0, input_bytes, /*spendable=*/ true, /*solvable=*/ true, /*safe=*/ true, /*time=*/ 0, /*from_me=*/ false, coin_selection_params.m_effective_feerate);
310 output.ApplyBumpFee(map_of_bump_fees.at(output.outpoint));
311 result.Insert(output, coin_selection_params.m_subtract_fee_outputs);
312 }
313 return result;
314 }
315 316 CoinsResult AvailableCoins(const CWallet& wallet,
317 const CCoinControl* coinControl,
318 std::optional<CFeeRate> feerate,
319 const CoinFilterParams& params)
320 {
321 AssertLockHeld(wallet.cs_wallet);
322 323 CoinsResult result;
324 // Either the WALLET_FLAG_AVOID_REUSE flag is not set (in which case we always allow), or we default to avoiding, and only in the case where
325 // a coin control object is provided, and has the avoid address reuse flag set to false, do we allow already used addresses
326 bool allow_used_addresses = !wallet.IsWalletFlagSet(WALLET_FLAG_AVOID_REUSE) || (coinControl && !coinControl->m_avoid_address_reuse);
327 const int min_depth = {coinControl ? coinControl->m_min_depth : DEFAULT_MIN_DEPTH};
328 const int max_depth = {coinControl ? coinControl->m_max_depth : DEFAULT_MAX_DEPTH};
329 const bool only_safe = {coinControl ? !coinControl->m_include_unsafe_inputs : true};
330 const bool segwit_inputs_only = {coinControl ? coinControl->m_segwit_inputs_only : false};
331 const bool can_grind_r = wallet.CanGrindR();
332 std::vector<COutPoint> outpoints;
333 334 std::set<uint256> trusted_parents;
335 for (const auto& entry : wallet.mapWallet)
336 {
337 const uint256& txid = entry.first;
338 const CWalletTx& wtx = entry.second;
339 340 if (wallet.IsTxImmatureCoinBase(wtx) && !params.include_immature_coinbase)
341 continue;
342 343 int nDepth = wallet.GetTxDepthInMainChain(wtx);
344 if (nDepth < 0)
345 continue;
346 347 // We should not consider coins which aren't at least in our mempool
348 // It's possible for these to be conflicted via ancestors which we may never be able to detect
349 if (nDepth == 0 && !wtx.InMempool())
350 continue;
351 352 bool safeTx = CachedTxIsTrusted(wallet, wtx, trusted_parents);
353 354 // We should not consider coins from transactions that are replacing
355 // other transactions.
356 //
357 // Example: There is a transaction A which is replaced by bumpfee
358 // transaction B. In this case, we want to prevent creation of
359 // a transaction B' which spends an output of B.
360 //
361 // Reason: If transaction A were initially confirmed, transactions B
362 // and B' would no longer be valid, so the user would have to create
363 // a new transaction C to replace B'. However, in the case of a
364 // one-block reorg, transactions B' and C might BOTH be accepted,
365 // when the user only wanted one of them. Specifically, there could
366 // be a 1-block reorg away from the chain where transactions A and C
367 // were accepted to another chain where B, B', and C were all
368 // accepted.
369 if (nDepth == 0 && wtx.mapValue.count("replaces_txid")) {
370 safeTx = false;
371 }
372 373 // Similarly, we should not consider coins from transactions that
374 // have been replaced. In the example above, we would want to prevent
375 // creation of a transaction A' spending an output of A, because if
376 // transaction B were initially confirmed, conflicting with A and
377 // A', we wouldn't want to the user to create a transaction D
378 // intending to replace A', but potentially resulting in a scenario
379 // where A, A', and D could all be accepted (instead of just B and
380 // D, or just A and A' like the user would want).
381 if (nDepth == 0 && wtx.mapValue.count("replaced_by_txid")) {
382 safeTx = false;
383 }
384 385 if (only_safe && !safeTx) {
386 continue;
387 }
388 389 if (nDepth < min_depth || nDepth > max_depth) {
390 continue;
391 }
392 393 bool tx_from_me = CachedTxIsFromMe(wallet, wtx, ISMINE_ALL);
394 395 for (unsigned int i = 0; i < wtx.tx->vout.size(); i++) {
396 const CTxOut& output = wtx.tx->vout[i];
397 const COutPoint outpoint(Txid::FromUint256(txid), i);
398 399 if (output.nValue < params.min_amount || output.nValue > params.max_amount)
400 continue;
401 402 // Skip manually selected coins (the caller can fetch them directly)
403 if (coinControl && coinControl->HasSelected() && coinControl->IsSelected(outpoint))
404 continue;
405 406 if (wallet.IsLockedCoin(outpoint) && params.skip_locked)
407 continue;
408 409 if (wallet.IsSpent(outpoint))
410 continue;
411 412 isminetype mine = wallet.IsMine(output);
413 414 if (mine == ISMINE_NO) {
415 continue;
416 }
417 418 if (!allow_used_addresses && wallet.IsSpentKey(output.scriptPubKey)) {
419 continue;
420 }
421 422 std::unique_ptr<SigningProvider> provider = wallet.GetSolvingProvider(output.scriptPubKey);
423 424 if (segwit_inputs_only) {
425 if (provider) {
426 if (!IsSegWitOutput(*provider, output.scriptPubKey)) continue;
427 } else {
428 int witness_ver;
429 std::vector<unsigned char> witness_prog;
430 if (!output.scriptPubKey.IsWitnessProgram(witness_ver, witness_prog)) continue;
431 }
432 }
433 434 int input_bytes = CalculateMaximumSignedInputSize(output, COutPoint(), provider.get(), can_grind_r, coinControl);
435 // Because CalculateMaximumSignedInputSize infers a solvable descriptor to get the satisfaction size,
436 // it is safe to assume that this input is solvable if input_bytes is greater than -1.
437 bool solvable = input_bytes > -1;
438 bool spendable = ((mine & ISMINE_SPENDABLE) != ISMINE_NO) || (((mine & ISMINE_WATCH_ONLY) != ISMINE_NO) && (coinControl && coinControl->fAllowWatchOnly && solvable));
439 440 // Filter by spendable outputs only
441 if (!spendable && params.only_spendable) continue;
442 443 // Obtain script type
444 std::vector<std::vector<uint8_t>> script_solutions;
445 TxoutType type = Solver(output.scriptPubKey, script_solutions);
446 447 // If the output is P2SH and solvable, we want to know if it is
448 // a P2SH (legacy) or one of P2SH-P2WPKH, P2SH-P2WSH (P2SH-Segwit). We can determine
449 // this from the redeemScript. If the output is not solvable, it will be classified
450 // as a P2SH (legacy), since we have no way of knowing otherwise without the redeemScript
451 bool is_from_p2sh{false};
452 if (type == TxoutType::SCRIPTHASH && solvable) {
453 CScript script;
454 if (!provider->GetCScript(CScriptID(uint160(script_solutions[0])), script)) continue;
455 type = Solver(script, script_solutions);
456 is_from_p2sh = true;
457 }
458 459 result.Add(GetOutputType(type, is_from_p2sh),
460 COutput(outpoint, output, nDepth, input_bytes, spendable, solvable, safeTx, wtx.GetTxTime(), tx_from_me, feerate));
461 462 outpoints.push_back(outpoint);
463 464 // Checks the sum amount of all UTXO's.
465 if (params.min_sum_amount != MAX_MONEY) {
466 if (result.GetTotalAmount() >= params.min_sum_amount) {
467 return result;
468 }
469 }
470 471 // Checks the maximum number of UTXO's.
472 if (params.max_count > 0 && result.Size() >= params.max_count) {
473 return result;
474 }
475 }
476 }
477 478 if (feerate.has_value()) {
479 std::map<COutPoint, CAmount> map_of_bump_fees = wallet.chain().calculateIndividualBumpFees(outpoints, feerate.value());
480 481 for (auto& [_, outputs] : result.coins) {
482 for (auto& output : outputs) {
483 output.ApplyBumpFee(map_of_bump_fees.at(output.outpoint));
484 }
485 }
486 }
487 488 return result;
489 }
490 491 CoinsResult AvailableCoinsListUnspent(const CWallet& wallet, const CCoinControl* coinControl, CoinFilterParams params)
492 {
493 params.only_spendable = false;
494 return AvailableCoins(wallet, coinControl, /*feerate=*/ std::nullopt, params);
495 }
496 497 const CTxOut& FindNonChangeParentOutput(const CWallet& wallet, const COutPoint& outpoint)
498 {
499 AssertLockHeld(wallet.cs_wallet);
500 const CWalletTx* wtx{Assert(wallet.GetWalletTx(outpoint.hash))};
501 502 const CTransaction* ptx = wtx->tx.get();
503 int n = outpoint.n;
504 while (OutputIsChange(wallet, ptx->vout[n]) && ptx->vin.size() > 0) {
505 const COutPoint& prevout = ptx->vin[0].prevout;
506 const CWalletTx* it = wallet.GetWalletTx(prevout.hash);
507 if (!it || it->tx->vout.size() <= prevout.n ||
508 !wallet.IsMine(it->tx->vout[prevout.n])) {
509 break;
510 }
511 ptx = it->tx.get();
512 n = prevout.n;
513 }
514 return ptx->vout[n];
515 }
516 517 std::map<CTxDestination, std::vector<COutput>> ListCoins(const CWallet& wallet)
518 {
519 AssertLockHeld(wallet.cs_wallet);
520 521 std::map<CTxDestination, std::vector<COutput>> result;
522 523 CCoinControl coin_control;
524 // Include watch-only for LegacyScriptPubKeyMan wallets without private keys
525 coin_control.fAllowWatchOnly = wallet.GetLegacyScriptPubKeyMan() && wallet.IsWalletFlagSet(WALLET_FLAG_DISABLE_PRIVATE_KEYS);
526 CoinFilterParams coins_params;
527 coins_params.only_spendable = false;
528 coins_params.skip_locked = false;
529 for (const COutput& coin : AvailableCoins(wallet, &coin_control, /*feerate=*/std::nullopt, coins_params).All()) {
530 CTxDestination address;
531 if ((coin.spendable || (wallet.IsWalletFlagSet(WALLET_FLAG_DISABLE_PRIVATE_KEYS) && coin.solvable))) {
532 if (!ExtractDestination(FindNonChangeParentOutput(wallet, coin.outpoint).scriptPubKey, address)) {
533 // For backwards compatibility, we convert P2PK output scripts into PKHash destinations
534 if (auto pk_dest = std::get_if<PubKeyDestination>(&address)) {
535 address = PKHash(pk_dest->GetPubKey());
536 } else {
537 continue;
538 }
539 }
540 result[address].emplace_back(coin);
541 }
542 }
543 return result;
544 }
545 546 FilteredOutputGroups GroupOutputs(const CWallet& wallet,
547 const CoinsResult& coins,
548 const CoinSelectionParams& coin_sel_params,
549 const std::vector<SelectionFilter>& filters,
550 std::vector<OutputGroup>& ret_discarded_groups)
551 {
552 FilteredOutputGroups filtered_groups;
553 554 if (!coin_sel_params.m_avoid_partial_spends) {
555 // Allowing partial spends means no grouping. Each COutput gets its own OutputGroup
556 for (const auto& [type, outputs] : coins.coins) {
557 for (const COutput& output : outputs) {
558 // Get mempool info
559 size_t ancestors, descendants;
560 wallet.chain().getTransactionAncestry(output.outpoint.hash, ancestors, descendants);
561 562 // Create a new group per output and add it to the all groups vector
563 OutputGroup group(coin_sel_params);
564 group.Insert(std::make_shared<COutput>(output), ancestors, descendants);
565 566 // Each filter maps to a different set of groups
567 bool accepted = false;
568 for (const auto& sel_filter : filters) {
569 const auto& filter = sel_filter.filter;
570 if (!group.EligibleForSpending(filter)) continue;
571 filtered_groups[filter].Push(group, type, /*insert_positive=*/true, /*insert_mixed=*/true);
572 accepted = true;
573 }
574 if (!accepted) ret_discarded_groups.emplace_back(group);
575 }
576 }
577 return filtered_groups;
578 }
579 580 // We want to combine COutputs that have the same scriptPubKey into single OutputGroups
581 // except when there are more than OUTPUT_GROUP_MAX_ENTRIES COutputs grouped in an OutputGroup.
582 // To do this, we maintain a map where the key is the scriptPubKey and the value is a vector of OutputGroups.
583 // For each COutput, we check if the scriptPubKey is in the map, and if it is, the COutput is added
584 // to the last OutputGroup in the vector for the scriptPubKey. When the last OutputGroup has
585 // OUTPUT_GROUP_MAX_ENTRIES COutputs, a new OutputGroup is added to the end of the vector.
586 typedef std::map<std::pair<CScript, OutputType>, std::vector<OutputGroup>> ScriptPubKeyToOutgroup;
587 const auto& insert_output = [&](
588 const std::shared_ptr<COutput>& output, OutputType type, size_t ancestors, size_t descendants,
589 ScriptPubKeyToOutgroup& groups_map) {
590 std::vector<OutputGroup>& groups = groups_map[std::make_pair(output->txout.scriptPubKey,type)];
591 592 if (groups.size() == 0) {
593 // No OutputGroups for this scriptPubKey yet, add one
594 groups.emplace_back(coin_sel_params);
595 }
596 597 // Get the last OutputGroup in the vector so that we can add the COutput to it
598 // A pointer is used here so that group can be reassigned later if it is full.
599 OutputGroup* group = &groups.back();
600 601 // Check if this OutputGroup is full. We limit to OUTPUT_GROUP_MAX_ENTRIES when using -avoidpartialspends
602 // to avoid surprising users with very high fees.
603 if (group->m_outputs.size() >= OUTPUT_GROUP_MAX_ENTRIES) {
604 // The last output group is full, add a new group to the vector and use that group for the insertion
605 groups.emplace_back(coin_sel_params);
606 group = &groups.back();
607 }
608 609 group->Insert(output, ancestors, descendants);
610 };
611 612 ScriptPubKeyToOutgroup spk_to_groups_map;
613 ScriptPubKeyToOutgroup spk_to_positive_groups_map;
614 for (const auto& [type, outs] : coins.coins) {
615 for (const COutput& output : outs) {
616 size_t ancestors, descendants;
617 wallet.chain().getTransactionAncestry(output.outpoint.hash, ancestors, descendants);
618 619 const auto& shared_output = std::make_shared<COutput>(output);
620 // Filter for positive only before adding the output
621 if (output.GetEffectiveValue() > 0) {
622 insert_output(shared_output, type, ancestors, descendants, spk_to_positive_groups_map);
623 }
624 625 // 'All' groups
626 insert_output(shared_output, type, ancestors, descendants, spk_to_groups_map);
627 }
628 }
629 630 // Now we go through the entire maps and pull out the OutputGroups
631 const auto& push_output_groups = [&](const ScriptPubKeyToOutgroup& groups_map, bool positive_only) {
632 for (const auto& [script, groups] : groups_map) {
633 // Go through the vector backwards. This allows for the first item we deal with being the partial group.
634 for (auto group_it = groups.rbegin(); group_it != groups.rend(); group_it++) {
635 const OutputGroup& group = *group_it;
636 637 // Each filter maps to a different set of groups
638 bool accepted = false;
639 for (const auto& sel_filter : filters) {
640 const auto& filter = sel_filter.filter;
641 if (!group.EligibleForSpending(filter)) continue;
642 643 // Don't include partial groups if there are full groups too and we don't want partial groups
644 if (group_it == groups.rbegin() && groups.size() > 1 && !filter.m_include_partial_groups) {
645 continue;
646 }
647 648 OutputType type = script.second;
649 // Either insert the group into the positive-only groups or the mixed ones.
650 filtered_groups[filter].Push(group, type, positive_only, /*insert_mixed=*/!positive_only);
651 accepted = true;
652 }
653 if (!accepted) ret_discarded_groups.emplace_back(group);
654 }
655 }
656 };
657 658 push_output_groups(spk_to_groups_map, /*positive_only=*/ false);
659 push_output_groups(spk_to_positive_groups_map, /*positive_only=*/ true);
660 661 return filtered_groups;
662 }
663 664 FilteredOutputGroups GroupOutputs(const CWallet& wallet,
665 const CoinsResult& coins,
666 const CoinSelectionParams& params,
667 const std::vector<SelectionFilter>& filters)
668 {
669 std::vector<OutputGroup> unused;
670 return GroupOutputs(wallet, coins, params, filters, unused);
671 }
672 673 // Returns true if the result contains an error and the message is not empty
674 static bool HasErrorMsg(const util::Result<SelectionResult>& res) { return !util::ErrorString(res).empty(); }
675 676 util::Result<SelectionResult> AttemptSelection(interfaces::Chain& chain, const CAmount& nTargetValue, OutputGroupTypeMap& groups,
677 const CoinSelectionParams& coin_selection_params, bool allow_mixed_output_types)
678 {
679 // Run coin selection on each OutputType and compute the Waste Metric
680 std::vector<SelectionResult> results;
681 for (auto& [type, group] : groups.groups_by_type) {
682 auto result{ChooseSelectionResult(chain, nTargetValue, group, coin_selection_params)};
683 // If any specific error message appears here, then something particularly wrong happened.
684 if (HasErrorMsg(result)) return result; // So let's return the specific error.
685 // Append the favorable result.
686 if (result) results.push_back(*result);
687 }
688 // If we have at least one solution for funding the transaction without mixing, choose the minimum one according to waste metric
689 // and return the result
690 if (results.size() > 0) return *std::min_element(results.begin(), results.end());
691 692 // If we can't fund the transaction from any individual OutputType, run coin selection one last time
693 // over all available coins, which would allow mixing.
694 // If TypesCount() <= 1, there is nothing to mix.
695 if (allow_mixed_output_types && groups.TypesCount() > 1) {
696 return ChooseSelectionResult(chain, nTargetValue, groups.all_groups, coin_selection_params);
697 }
698 // Either mixing is not allowed and we couldn't find a solution from any single OutputType, or mixing was allowed and we still couldn't
699 // find a solution using all available coins
700 return util::Error();
701 };
702 703 util::Result<SelectionResult> ChooseSelectionResult(interfaces::Chain& chain, const CAmount& nTargetValue, Groups& groups, const CoinSelectionParams& coin_selection_params)
704 {
705 // Vector of results. We will choose the best one based on waste.
706 std::vector<SelectionResult> results;
707 std::vector<util::Result<SelectionResult>> errors;
708 auto append_error = [&] (util::Result<SelectionResult>&& result) {
709 // If any specific error message appears here, then something different from a simple "no selection found" happened.
710 // Let's save it, so it can be retrieved to the user if no other selection algorithm succeeded.
711 if (HasErrorMsg(result)) {
712 errors.emplace_back(std::move(result));
713 }
714 };
715 716 // Maximum allowed weight for selected coins.
717 int max_transaction_weight = coin_selection_params.m_max_tx_weight.value_or(MAX_STANDARD_TX_WEIGHT);
718 int tx_weight_no_input = coin_selection_params.tx_noinputs_size * WITNESS_SCALE_FACTOR;
719 int max_selection_weight = max_transaction_weight - tx_weight_no_input;
720 if (max_selection_weight <= 0) {
721 return util::Error{_("Maximum transaction weight is less than transaction weight without inputs")};
722 }
723 724 // SFFO frequently causes issues in the context of changeless input sets: skip BnB when SFFO is active
725 if (!coin_selection_params.m_subtract_fee_outputs) {
726 if (auto bnb_result{SelectCoinsBnB(groups.positive_group, nTargetValue, coin_selection_params.m_cost_of_change, max_selection_weight)}) {
727 results.push_back(*bnb_result);
728 } else append_error(std::move(bnb_result));
729 }
730 731 // Deduct change weight because remaining Coin Selection algorithms can create change output
732 int change_outputs_weight = coin_selection_params.change_output_size * WITNESS_SCALE_FACTOR;
733 max_selection_weight -= change_outputs_weight;
734 if (max_selection_weight < 0 && results.empty()) {
735 return util::Error{_("Maximum transaction weight is too low, can not accommodate change output")};
736 }
737 738 // The knapsack solver has some legacy behavior where it will spend dust outputs. We retain this behavior, so don't filter for positive only here.
739 if (auto knapsack_result{KnapsackSolver(groups.mixed_group, nTargetValue, coin_selection_params.m_min_change_target, coin_selection_params.rng_fast, max_selection_weight)}) {
740 results.push_back(*knapsack_result);
741 } else append_error(std::move(knapsack_result));
742 743 if (coin_selection_params.m_effective_feerate > CFeeRate{3 * coin_selection_params.m_long_term_feerate}) { // Minimize input set for feerates of at least 3×LTFRE (default: 30 ṩ/vB+)
744 if (auto cg_result{CoinGrinder(groups.positive_group, nTargetValue, coin_selection_params.m_min_change_target, max_selection_weight)}) {
745 cg_result->RecalculateWaste(coin_selection_params.min_viable_change, coin_selection_params.m_cost_of_change, coin_selection_params.m_change_fee);
746 results.push_back(*cg_result);
747 } else {
748 append_error(std::move(cg_result));
749 }
750 }
751 752 if (auto srd_result{SelectCoinsSRD(groups.positive_group, nTargetValue, coin_selection_params.m_change_fee, coin_selection_params.rng_fast, max_selection_weight)}) {
753 results.push_back(*srd_result);
754 } else append_error(std::move(srd_result));
755 756 // Privacy-first: temporal clustering selection
757 if (coin_selection_params.m_privacy_first) {
758 if (auto temporal_result{SelectCoinsTemporal(groups.positive_group, nTargetValue, coin_selection_params.m_temporal_window, coin_selection_params.m_target_merge_outputs, max_selection_weight)}) {
759 results.push_back(*temporal_result);
760 } else append_error(std::move(temporal_result));
761 }
762 763 if (results.empty()) {
764 // No solution found, retrieve the first explicit error (if any).
765 // future: add 'severity level' to errors so the worst one can be retrieved instead of the first one.
766 return errors.empty() ? util::Error() : std::move(errors.front());
767 }
768 769 // If the chosen input set has unconfirmed inputs, check for synergies from overlapping ancestry
770 for (auto& result : results) {
771 std::vector<COutPoint> outpoints;
772 std::set<std::shared_ptr<COutput>> coins = result.GetInputSet();
773 CAmount summed_bump_fees = 0;
774 for (auto& coin : coins) {
775 if (coin->depth > 0) continue; // Bump fees only exist for unconfirmed inputs
776 outpoints.push_back(coin->outpoint);
777 summed_bump_fees += coin->ancestor_bump_fees;
778 }
779 std::optional<CAmount> combined_bump_fee = chain.calculateCombinedBumpFee(outpoints, coin_selection_params.m_effective_feerate);
780 if (!combined_bump_fee.has_value()) {
781 return util::Error{_("Failed to calculate bump fees, because unconfirmed UTXOs depend on an enormous cluster of unconfirmed transactions.")};
782 }
783 CAmount bump_fee_overestimate = summed_bump_fees - combined_bump_fee.value();
784 if (bump_fee_overestimate) {
785 result.SetBumpFeeDiscount(bump_fee_overestimate);
786 }
787 result.RecalculateWaste(coin_selection_params.min_viable_change, coin_selection_params.m_cost_of_change, coin_selection_params.m_change_fee);
788 }
789 790 // Choose the result with the least waste
791 // If the waste is the same, choose the one which spends more inputs.
792 return *std::min_element(results.begin(), results.end());
793 }
794 795 util::Result<SelectionResult> SelectCoins(const CWallet& wallet, CoinsResult& available_coins, const PreSelectedInputs& pre_set_inputs,
796 const CAmount& nTargetValue, const CCoinControl& coin_control,
797 const CoinSelectionParams& coin_selection_params)
798 {
799 // Deduct preset inputs amount from the search target
800 CAmount selection_target = nTargetValue - pre_set_inputs.total_amount;
801 802 // Return if automatic coin selection is disabled, and we don't cover the selection target
803 if (!coin_control.m_allow_other_inputs && selection_target > 0) {
804 return util::Error{_("The preselected coins total amount does not cover the transaction target. "
805 "Please allow other inputs to be automatically selected or include more coins manually")};
806 }
807 808 // Return if we can cover the target only with the preset inputs
809 if (selection_target <= 0) {
810 SelectionResult result(nTargetValue, SelectionAlgorithm::MANUAL);
811 result.AddInputs(pre_set_inputs.coins, coin_selection_params.m_subtract_fee_outputs);
812 result.RecalculateWaste(coin_selection_params.min_viable_change, coin_selection_params.m_cost_of_change, coin_selection_params.m_change_fee);
813 return result;
814 }
815 816 // Return early if we cannot cover the target with the wallet's UTXO.
817 // We use the total effective value if we are not subtracting fee from outputs and 'available_coins' contains the data.
818 CAmount available_coins_total_amount = coin_selection_params.m_subtract_fee_outputs ? available_coins.GetTotalAmount() :
819 (available_coins.GetEffectiveTotalAmount().has_value() ? *available_coins.GetEffectiveTotalAmount() : 0);
820 if (selection_target > available_coins_total_amount) {
821 return util::Error(); // Insufficient funds
822 }
823 824 // Start wallet Coin Selection procedure
825 auto op_selection_result = AutomaticCoinSelection(wallet, available_coins, selection_target, coin_selection_params);
826 if (!op_selection_result) return op_selection_result;
827 828 // If needed, add preset inputs to the automatic coin selection result
829 if (!pre_set_inputs.coins.empty()) {
830 SelectionResult preselected(pre_set_inputs.total_amount, SelectionAlgorithm::MANUAL);
831 preselected.AddInputs(pre_set_inputs.coins, coin_selection_params.m_subtract_fee_outputs);
832 op_selection_result->Merge(preselected);
833 op_selection_result->RecalculateWaste(coin_selection_params.min_viable_change,
834 coin_selection_params.m_cost_of_change,
835 coin_selection_params.m_change_fee);
836 837 // Verify we haven't exceeded the maximum allowed weight
838 int max_inputs_weight = coin_selection_params.m_max_tx_weight.value_or(MAX_STANDARD_TX_WEIGHT) - (coin_selection_params.tx_noinputs_size * WITNESS_SCALE_FACTOR);
839 if (op_selection_result->GetWeight() > max_inputs_weight) {
840 return util::Error{_("The combination of the pre-selected inputs and the wallet automatic inputs selection exceeds the transaction maximum weight. "
841 "Please try sending a smaller amount or manually consolidating your wallet's UTXOs")};
842 }
843 }
844 return op_selection_result;
845 }
846 847 util::Result<SelectionResult> AutomaticCoinSelection(const CWallet& wallet, CoinsResult& available_coins, const CAmount& value_to_select, const CoinSelectionParams& coin_selection_params)
848 {
849 unsigned int limit_ancestor_count = 0;
850 unsigned int limit_descendant_count = 0;
851 wallet.chain().getPackageLimits(limit_ancestor_count, limit_descendant_count);
852 const size_t max_ancestors = (size_t)std::max<int64_t>(1, limit_ancestor_count);
853 const size_t max_descendants = (size_t)std::max<int64_t>(1, limit_descendant_count);
854 const bool fRejectLongChains = gArgs.GetBoolArg("-walletrejectlongchains", DEFAULT_WALLET_REJECT_LONG_CHAINS);
855 856 // Cases where we have 101+ outputs all pointing to the same destination may result in
857 // privacy leaks as they will potentially be deterministically sorted. We solve that by
858 // explicitly shuffling the outputs before processing
859 if (coin_selection_params.m_avoid_partial_spends && available_coins.Size() > OUTPUT_GROUP_MAX_ENTRIES) {
860 available_coins.Shuffle(coin_selection_params.rng_fast);
861 }
862 863 // Coin Selection attempts to select inputs from a pool of eligible UTXOs to fund the
864 // transaction at a target feerate. If an attempt fails, more attempts may be made using a more
865 // permissive CoinEligibilityFilter.
866 {
867 // Place coins eligibility filters on a scope increasing order.
868 std::vector<SelectionFilter> ordered_filters{
869 // If possible, fund the transaction with confirmed UTXOs only. Prefer at least six
870 // confirmations on outputs received from other wallets and only spend confirmed change.
871 {CoinEligibilityFilter(1, 6, 0), /*allow_mixed_output_types=*/false},
872 {CoinEligibilityFilter(1, 1, 0)},
873 };
874 // Fall back to using zero confirmation change (but with as few ancestors in the mempool as
875 // possible) if we cannot fund the transaction otherwise.
876 if (wallet.m_spend_zero_conf_change) {
877 ordered_filters.push_back({CoinEligibilityFilter(0, 1, 2)});
878 ordered_filters.push_back({CoinEligibilityFilter(0, 1, std::min(size_t{4}, max_ancestors/3), std::min(size_t{4}, max_descendants/3))});
879 ordered_filters.push_back({CoinEligibilityFilter(0, 1, max_ancestors/2, max_descendants/2)});
880 // If partial groups are allowed, relax the requirement of spending OutputGroups (groups
881 // of UTXOs sent to the same address, which are obviously controlled by a single wallet)
882 // in their entirety.
883 ordered_filters.push_back({CoinEligibilityFilter(0, 1, max_ancestors-1, max_descendants-1, /*include_partial=*/true)});
884 // Try with unsafe inputs if they are allowed. This may spend unconfirmed outputs
885 // received from other wallets.
886 if (coin_selection_params.m_include_unsafe_inputs) {
887 ordered_filters.push_back({CoinEligibilityFilter(/*conf_mine=*/0, /*conf_theirs*/0, max_ancestors-1, max_descendants-1, /*include_partial=*/true)});
888 }
889 // Try with unlimited ancestors/descendants. The transaction will still need to meet
890 // mempool ancestor/descendant policy to be accepted to mempool and broadcasted, but
891 // OutputGroups use heuristics that may overestimate ancestor/descendant counts.
892 if (!fRejectLongChains) {
893 ordered_filters.push_back({CoinEligibilityFilter(0, 1, std::numeric_limits<uint64_t>::max(),
894 std::numeric_limits<uint64_t>::max(),
895 /*include_partial=*/true)});
896 }
897 }
898 899 // Group outputs and map them by coin eligibility filter
900 std::vector<OutputGroup> discarded_groups;
901 FilteredOutputGroups filtered_groups = GroupOutputs(wallet, available_coins, coin_selection_params, ordered_filters, discarded_groups);
902 903 // Check if we still have enough balance after applying filters (some coins might be discarded)
904 CAmount total_discarded = 0;
905 CAmount total_unconf_long_chain = 0;
906 for (const auto& group : discarded_groups) {
907 total_discarded += group.GetSelectionAmount();
908 if (group.m_ancestors >= max_ancestors || group.m_descendants >= max_descendants) total_unconf_long_chain += group.GetSelectionAmount();
909 }
910 911 if (CAmount total_amount = available_coins.GetTotalAmount() - total_discarded; total_amount < value_to_select) {
912 // Special case, too-long-mempool cluster.
913 if (total_amount + total_unconf_long_chain > value_to_select) {
914 return util::Error{_("Unconfirmed UTXOs are available, but spending them creates a chain of transactions that will be rejected by the mempool")};
915 }
916 return util::Error{}; // General "Insufficient Funds"
917 }
918 919 // Walk-through the filters until the solution gets found.
920 // If no solution is found, return the first detailed error (if any).
921 // future: add "error level" so the worst one can be picked instead.
922 std::vector<util::Result<SelectionResult>> res_detailed_errors;
923 for (const auto& select_filter : ordered_filters) {
924 auto it = filtered_groups.find(select_filter.filter);
925 if (it == filtered_groups.end()) continue;
926 if (auto res{AttemptSelection(wallet.chain(), value_to_select, it->second,
927 coin_selection_params, select_filter.allow_mixed_output_types)}) {
928 return res; // result found
929 } else {
930 // If any specific error message appears here, then something particularly wrong might have happened.
931 // Save the error and continue the selection process. So if no solutions gets found, we can return
932 // the detailed error to the upper layers.
933 if (HasErrorMsg(res)) res_detailed_errors.emplace_back(std::move(res));
934 }
935 }
936 937 // Return right away if we have a detailed error
938 if (!res_detailed_errors.empty()) return std::move(res_detailed_errors.front());
939 940 941 // General "Insufficient Funds"
942 return util::Error{};
943 }
944 }
945 946 static bool IsCurrentForAntiFeeSniping(interfaces::Chain& chain, const uint256& block_hash)
947 {
948 if (chain.isInitialBlockDownload()) {
949 return false;
950 }
951 constexpr int64_t MAX_ANTI_FEE_SNIPING_TIP_AGE = 8 * 60 * 60; // in seconds
952 int64_t block_time;
953 CHECK_NONFATAL(chain.findBlock(block_hash, FoundBlock().time(block_time)));
954 if (block_time < (GetTime() - MAX_ANTI_FEE_SNIPING_TIP_AGE)) {
955 return false;
956 }
957 return true;
958 }
959 960 /**
961 * Set a height-based locktime for new transactions (uses the height of the
962 * current chain tip unless we are not synced with the current chain
963 */
964 static void DiscourageFeeSniping(CMutableTransaction& tx, FastRandomContext& rng_fast,
965 interfaces::Chain& chain, const uint256& block_hash, int block_height)
966 {
967 // All inputs must be added by now
968 assert(!tx.vin.empty());
969 // Discourage fee sniping.
970 //
971 // For a large miner the value of the transactions in the best block and
972 // the mempool can exceed the cost of deliberately attempting to mine two
973 // blocks to orphan the current best block. By setting nLockTime such that
974 // only the next block can include the transaction, we discourage this
975 // practice as the height restricted and limited blocksize gives miners
976 // considering fee sniping fewer options for pulling off this attack.
977 //
978 // A simple way to think about this is from the wallet's point of view we
979 // always want the blockchain to move forward. By setting nLockTime this
980 // way we're basically making the statement that we only want this
981 // transaction to appear in the next block; we don't want to potentially
982 // encourage reorgs by allowing transactions to appear at lower heights
983 // than the next block in forks of the best chain.
984 //
985 // Of course, the subsidy is high enough, and transaction volume low
986 // enough, that fee sniping isn't a problem yet, but by implementing a fix
987 // now we ensure code won't be written that makes assumptions about
988 // nLockTime that preclude a fix later.
989 if (IsCurrentForAntiFeeSniping(chain, block_hash)) {
990 tx.nLockTime = block_height;
991 992 // Secondly occasionally randomly pick a nLockTime even further back, so
993 // that transactions that are delayed after signing for whatever reason,
994 // e.g. high-latency mix networks and some CoinJoin implementations, have
995 // better privacy.
996 if (rng_fast.randrange(10) == 0) {
997 tx.nLockTime = std::max(0, int(tx.nLockTime) - int(rng_fast.randrange(100)));
998 }
999 } else {
1000 // If our chain is lagging behind, we can't discourage fee sniping nor help
1001 // the privacy of high-latency transactions. To avoid leaking a potentially
1002 // unique "nLockTime fingerprint", set nLockTime to a constant.
1003 tx.nLockTime = 0;
1004 }
1005 // Sanity check all values
1006 assert(tx.nLockTime < LOCKTIME_THRESHOLD); // Type must be block height
1007 assert(tx.nLockTime <= uint64_t(block_height));
1008 for (const auto& in : tx.vin) {
1009 // Can not be FINAL for locktime to work
1010 assert(in.nSequence != CTxIn::SEQUENCE_FINAL);
1011 // May be MAX NONFINAL to disable both BIP68 and BIP125
1012 if (in.nSequence == CTxIn::MAX_SEQUENCE_NONFINAL) continue;
1013 // May be MAX BIP125 to disable BIP68 and enable BIP125
1014 if (in.nSequence == MAX_BIP125_RBF_SEQUENCE) continue;
1015 // The wallet does not support any other sequence-use right now.
1016 assert(false);
1017 }
1018 }
1019 1020 void MaybeDiscourageFeeSniping2(const CWallet &wallet,
1021 CMutableTransaction& tx)
1022 {
1023 for (const CTxIn& tx_in : tx.vin) {
1024 // Checks sequence values consistent with DiscourageFeeSniping
1025 if (tx_in.nSequence != CTxIn::MAX_SEQUENCE_NONFINAL && tx_in.nSequence != MAX_BIP125_RBF_SEQUENCE) {
1026 // If an input has an incompatible sequence, we can't do anti-fee-sniping
1027 return;
1028 }
1029 }
1030 1031 FastRandomContext rng_fast;
1032 LOCK(wallet.cs_wallet);
1033 DiscourageFeeSniping(tx, rng_fast, wallet.chain(), wallet.GetLastBlockHash(), wallet.GetLastBlockHeight());
1034 }
1035 1036 size_t GetSerializeSizeForRecipient(const CRecipient& recipient)
1037 {
1038 return ::GetSerializeSize(CTxOut(recipient.nAmount, GetScriptForDestination(recipient.dest)));
1039 }
1040 1041 bool IsDust(const CRecipient& recipient, const CFeeRate& dustRelayFee)
1042 {
1043 return ::IsDust(CTxOut(recipient.nAmount, GetScriptForDestination(recipient.dest)), dustRelayFee);
1044 }
1045 1046 static util::Result<CreatedTransactionResult> CreateTransactionInternal(
1047 CWallet& wallet,
1048 const std::vector<CRecipient>& vecSend,
1049 std::optional<unsigned int> change_pos,
1050 const CCoinControl& coin_control,
1051 bool sign) EXCLUSIVE_LOCKS_REQUIRED(wallet.cs_wallet)
1052 {
1053 AssertLockHeld(wallet.cs_wallet);
1054 1055 FastRandomContext rng_fast;
1056 CMutableTransaction txNew; // The resulting transaction that we make
1057 1058 if (coin_control.m_version) {
1059 txNew.version = coin_control.m_version.value();
1060 }
1061 1062 CoinSelectionParams coin_selection_params{rng_fast}; // Parameters for coin selection, init with dummy
1063 coin_selection_params.m_avoid_partial_spends = coin_control.m_avoid_partial_spends;
1064 coin_selection_params.m_include_unsafe_inputs = coin_control.m_include_unsafe_inputs;
1065 coin_selection_params.m_max_tx_weight = coin_control.m_max_tx_weight.value_or(MAX_STANDARD_TX_WEIGHT);
1066 coin_selection_params.m_privacy_first = coin_control.m_privacy_first;
1067 coin_selection_params.m_temporal_window = coin_control.m_temporal_window;
1068 coin_selection_params.m_target_merge_outputs = coin_control.m_target_merge_outputs;
1069 int minimum_tx_weight = MIN_STANDARD_TX_NONWITNESS_SIZE * WITNESS_SCALE_FACTOR;
1070 if (coin_selection_params.m_max_tx_weight.value() < minimum_tx_weight || coin_selection_params.m_max_tx_weight.value() > MAX_STANDARD_TX_WEIGHT) {
1071 return util::Error{strprintf(_("Maximum transaction weight must be between %d and %d"), minimum_tx_weight, MAX_STANDARD_TX_WEIGHT)};
1072 }
1073 // Set the long term feerate estimate to the wallet's consolidate feerate
1074 coin_selection_params.m_long_term_feerate = wallet.m_consolidate_feerate;
1075 // Static vsize overhead + outputs vsize. 4 nVersion, 4 nLocktime, 1 input count, 1 witness overhead (dummy, flag, stack size)
1076 coin_selection_params.tx_noinputs_size = 10 + GetSizeOfCompactSize(vecSend.size()); // bytes for output count
1077 1078 CAmount recipients_sum = 0;
1079 const OutputType change_type = wallet.TransactionChangeType(coin_control.m_change_type ? *coin_control.m_change_type : wallet.m_default_change_type, vecSend);
1080 ReserveDestination reservedest(&wallet, change_type);
1081 unsigned int outputs_to_subtract_fee_from = 0; // The number of outputs which we are subtracting the fee from
1082 for (const auto& recipient : vecSend) {
1083 if (IsDust(recipient, wallet.chain().relayDustFee())) {
1084 return util::Error{_("Transaction amount too small")};
1085 }
1086 1087 // Include the fee cost for outputs.
1088 coin_selection_params.tx_noinputs_size += GetSerializeSizeForRecipient(recipient);
1089 recipients_sum += recipient.nAmount;
1090 1091 if (recipient.fSubtractFeeFromAmount) {
1092 outputs_to_subtract_fee_from++;
1093 coin_selection_params.m_subtract_fee_outputs = true;
1094 }
1095 }
1096 1097 // Create change script that will be used if we need change
1098 CScript scriptChange;
1099 bilingual_str error; // possible error str
1100 1101 // coin control: send change to custom address
1102 if (!std::get_if<CNoDestination>(&coin_control.destChange)) {
1103 scriptChange = GetScriptForDestination(coin_control.destChange);
1104 } else { // no coin control: send change to newly generated address
1105 // Note: We use a new key here to keep it from being obvious which side is the change.
1106 // The drawback is that by not reusing a previous key, the change may be lost if a
1107 // backup is restored, if the backup doesn't have the new private key for the change.
1108 // If we reused the old key, it would be possible to add code to look for and
1109 // rediscover unknown transactions that were written with keys of ours to recover
1110 // post-backup change.
1111 1112 // Reserve a new key pair from key pool. If it fails, provide a dummy
1113 // destination in case we don't need change.
1114 CTxDestination dest;
1115 auto op_dest = reservedest.GetReservedDestination(true);
1116 if (!op_dest) {
1117 error = _("Transaction needs a change address, but we can't generate it.") + Untranslated(" ") + util::ErrorString(op_dest);
1118 } else {
1119 dest = *op_dest;
1120 scriptChange = GetScriptForDestination(dest);
1121 }
1122 // A valid destination implies a change script (and
1123 // vice-versa). An empty change script will abort later, if the
1124 // change keypool ran out, but change is required.
1125 CHECK_NONFATAL(IsValidDestination(dest) != scriptChange.empty());
1126 }
1127 CTxOut change_prototype_txout(0, scriptChange);
1128 coin_selection_params.change_output_size = GetSerializeSize(change_prototype_txout);
1129 1130 // Get size of spending the change output
1131 int change_spend_size = CalculateMaximumSignedInputSize(change_prototype_txout, &wallet, /*coin_control=*/nullptr);
1132 // If the wallet doesn't know how to sign change output, assume p2sh-p2wpkh
1133 // as lower-bound to allow BnB to do it's thing
1134 if (change_spend_size == -1) {
1135 coin_selection_params.change_spend_size = DUMMY_NESTED_P2WPKH_INPUT_SIZE;
1136 } else {
1137 coin_selection_params.change_spend_size = change_spend_size;
1138 }
1139 1140 // Set discard feerate
1141 coin_selection_params.m_discard_feerate = GetDiscardRate(wallet);
1142 1143 // Get the fee rate to use effective values in coin selection
1144 FeeCalculation feeCalc;
1145 coin_selection_params.m_effective_feerate = GetMinimumFeeRate(wallet, coin_control, &feeCalc);
1146 // Do not, ever, assume that it's fine to change the fee rate if the user has explicitly
1147 // provided one
1148 if (coin_control.m_feerate && coin_selection_params.m_effective_feerate > *coin_control.m_feerate) {
1149 return util::Error{strprintf(_("Fee rate (%s) is lower than the minimum fee rate setting (%s)"), coin_control.m_feerate->ToString(FeeEstimateMode::SAT_VB), coin_selection_params.m_effective_feerate.ToString(FeeEstimateMode::SAT_VB))};
1150 }
1151 if (feeCalc.reason == FeeReason::FALLBACK && !wallet.m_allow_fallback_fee) {
1152 // eventually allow a fallback fee
1153 return util::Error{strprintf(_("Fee estimation failed. Fallbackfee is disabled. Wait a few blocks or enable %s."), "-fallbackfee")};
1154 }
1155 1156 // Calculate the cost of change
1157 // Cost of change is the cost of creating the change output + cost of spending the change output in the future.
1158 // For creating the change output now, we use the effective feerate.
1159 // For spending the change output in the future, we use the discard feerate for now.
1160 // So cost of change = (change output size * effective feerate) + (size of spending change output * discard feerate)
1161 coin_selection_params.m_change_fee = coin_selection_params.m_effective_feerate.GetFee(coin_selection_params.change_output_size);
1162 coin_selection_params.m_cost_of_change = coin_selection_params.m_discard_feerate.GetFee(coin_selection_params.change_spend_size) + coin_selection_params.m_change_fee;
1163 1164 coin_selection_params.m_min_change_target = GenerateChangeTarget(std::floor(recipients_sum / vecSend.size()), coin_selection_params.m_change_fee, rng_fast);
1165 1166 // The smallest change amount should be:
1167 // 1. at least equal to dust threshold
1168 // 2. at least 1 sat greater than fees to spend it at m_discard_feerate
1169 const auto dust = GetDustThreshold(change_prototype_txout, coin_selection_params.m_discard_feerate);
1170 const auto change_spend_fee = coin_selection_params.m_discard_feerate.GetFee(coin_selection_params.change_spend_size);
1171 coin_selection_params.min_viable_change = std::max(change_spend_fee + 1, dust);
1172 1173 // Include the fees for things that aren't inputs, excluding the change output
1174 const CAmount not_input_fees = coin_selection_params.m_effective_feerate.GetFee(coin_selection_params.m_subtract_fee_outputs ? 0 : coin_selection_params.tx_noinputs_size);
1175 CAmount selection_target = recipients_sum + not_input_fees;
1176 1177 // This can only happen if feerate is 0, and requested destinations are value of 0 (e.g. OP_RETURN)
1178 // and no pre-selected inputs. This will result in 0-input transaction, which is consensus-invalid anyways
1179 if (selection_target == 0 && !coin_control.HasSelected()) {
1180 return util::Error{_("Transaction requires one destination of non-0 value, a non-0 feerate, or a pre-selected input")};
1181 }
1182 1183 // Fetch manually selected coins
1184 PreSelectedInputs preset_inputs;
1185 if (coin_control.HasSelected()) {
1186 auto res_fetch_inputs = FetchSelectedInputs(wallet, coin_control, coin_selection_params);
1187 if (!res_fetch_inputs) return util::Error{util::ErrorString(res_fetch_inputs)};
1188 preset_inputs = *res_fetch_inputs;
1189 }
1190 1191 // Fetch wallet available coins if "other inputs" are
1192 // allowed (coins automatically selected by the wallet)
1193 CoinsResult available_coins;
1194 if (coin_control.m_allow_other_inputs) {
1195 available_coins = AvailableCoins(wallet, &coin_control, coin_selection_params.m_effective_feerate);
1196 }
1197 1198 // Choose coins to use
1199 auto select_coins_res = SelectCoins(wallet, available_coins, preset_inputs, /*nTargetValue=*/selection_target, coin_control, coin_selection_params);
1200 if (!select_coins_res) {
1201 // 'SelectCoins' either returns a specific error message or, if empty, means a general "Insufficient funds".
1202 const bilingual_str& err = util::ErrorString(select_coins_res);
1203 return util::Error{err.empty() ?_("Insufficient funds") : err};
1204 }
1205 const SelectionResult& result = *select_coins_res;
1206 TRACEPOINT(coin_selection, selected_coins,
1207 wallet.GetName().c_str(),
1208 GetAlgorithmName(result.GetAlgo()).c_str(),
1209 result.GetTarget(),
1210 result.GetWaste(),
1211 result.GetSelectedValue());
1212 1213 // vouts to the payees
1214 txNew.vout.reserve(vecSend.size() + 1); // + 1 because of possible later insert
1215 for (const auto& recipient : vecSend)
1216 {
1217 txNew.vout.emplace_back(recipient.nAmount, GetScriptForDestination(recipient.dest));
1218 }
1219 const CAmount change_amount = result.GetChange(coin_selection_params.min_viable_change, coin_selection_params.m_change_fee);
1220 if (change_amount > 0) {
1221 // Privacy: generate multiple change outputs if configured
1222 int change_count = coin_control.m_change_output_count;
1223 if (change_count < 1) change_count = 1;
1224 if (change_count > 8) change_count = 8;
1225 1226 if (!change_pos) {
1227 // Insert change txn at random position:
1228 change_pos = rng_fast.randrange(txNew.vout.size() + 1);
1229 } else if ((unsigned int)*change_pos > txNew.vout.size()) {
1230 return util::Error{_("Transaction change output index out of range")};
1231 }
1232 1233 // Create multiple change outputs with RANDOM varying amounts
1234 // Wider variance makes temporal rejoining harder
1235 std::vector<CAmount> change_amounts;
1236 CAmount remaining = change_amount;
1237 1238 for (int i = 0; i < change_count - 1; ++i) {
1239 // Random split: between 10% and 90% of remaining
1240 CAmount min_split = remaining / 10;
1241 CAmount max_split = remaining - (change_count - i - 1) * (remaining / 10); // ensure minimum for rest
1242 if (max_split <= min_split) max_split = min_split + 1;
1243 CAmount split = min_split + rng_fast.randrange(static_cast<int64_t>(max_split - min_split));
1244 change_amounts.push_back(split);
1245 remaining -= split;
1246 }
1247 change_amounts.push_back(remaining); // Last output gets remainder
1248 1249 // Shuffle the amounts for additional privacy
1250 for (int i = change_amounts.size() - 1; i > 0; --i) {
1251 int j = rng_fast.randrange(i + 1);
1252 std::swap(change_amounts[i], change_amounts[j]);
1253 }
1254 1255 // Create the change outputs
1256 for (int i = 0; i < change_count; ++i) {
1257 if (change_amounts[i] > 0) {
1258 CTxOut newTxOut(change_amounts[i], scriptChange);
1259 txNew.vout.insert(txNew.vout.begin() + *change_pos + i, newTxOut);
1260 }
1261 }
1262 } else {
1263 change_pos = std::nullopt;
1264 }
1265 1266 // Shuffle selected coins and fill in final vin
1267 std::vector<std::shared_ptr<COutput>> selected_coins = result.GetShuffledInputVector();
1268 1269 if (coin_control.HasSelected() && coin_control.HasSelectedOrder()) {
1270 // When there are preselected inputs, we need to move them to be the first UTXOs
1271 // and have them be in the order selected. We can use stable_sort for this, where we
1272 // compare with the positions stored in coin_control. The COutputs that have positions
1273 // will be placed before those that don't, and those positions will be in order.
1274 std::stable_sort(selected_coins.begin(), selected_coins.end(),
1275 [&coin_control](const std::shared_ptr<COutput>& a, const std::shared_ptr<COutput>& b) {
1276 auto a_pos = coin_control.GetSelectionPos(a->outpoint);
1277 auto b_pos = coin_control.GetSelectionPos(b->outpoint);
1278 if (a_pos.has_value() && b_pos.has_value()) {
1279 return a_pos.value() < b_pos.value();
1280 } else if (a_pos.has_value() && !b_pos.has_value()) {
1281 return true;
1282 } else {
1283 return false;
1284 }
1285 });
1286 }
1287 1288 // The sequence number is set to non-maxint so that DiscourageFeeSniping
1289 // works.
1290 //
1291 // BIP125 defines opt-in RBF as any nSequence < maxint-1, so
1292 // we use the highest possible value in that range (maxint-2)
1293 // to avoid conflicting with other possible uses of nSequence,
1294 // and in the spirit of "smallest possible change from prior
1295 // behavior."
1296 bool use_anti_fee_sniping = true;
1297 const uint32_t default_sequence{coin_control.m_signal_bip125_rbf.value_or(wallet.m_signal_rbf) ? MAX_BIP125_RBF_SEQUENCE : CTxIn::MAX_SEQUENCE_NONFINAL};
1298 txNew.vin.reserve(selected_coins.size());
1299 for (const auto& coin : selected_coins) {
1300 std::optional<uint32_t> sequence = coin_control.GetSequence(coin->outpoint);
1301 if (sequence) {
1302 // If an input has a preset sequence, we can't do anti-fee-sniping
1303 use_anti_fee_sniping = false;
1304 }
1305 txNew.vin.emplace_back(coin->outpoint, CScript{}, sequence.value_or(default_sequence));
1306 1307 auto scripts = coin_control.GetScripts(coin->outpoint);
1308 if (scripts.first) {
1309 txNew.vin.back().scriptSig = *scripts.first;
1310 }
1311 if (scripts.second) {
1312 txNew.vin.back().scriptWitness = *scripts.second;
1313 }
1314 }
1315 if (coin_control.m_locktime) {
1316 txNew.nLockTime = coin_control.m_locktime.value();
1317 // If we have a locktime set, we can't use anti-fee-sniping
1318 use_anti_fee_sniping = false;
1319 }
1320 if (use_anti_fee_sniping) {
1321 DiscourageFeeSniping(txNew, rng_fast, wallet.chain(), wallet.GetLastBlockHash(), wallet.GetLastBlockHeight());
1322 }
1323 1324 // Calculate the transaction fee
1325 TxSize tx_sizes = CalculateMaximumSignedTxSize(CTransaction(txNew), &wallet, &coin_control);
1326 int nBytes = tx_sizes.vsize;
1327 if (nBytes == -1) {
1328 return util::Error{_("Missing solving data for estimating transaction size")};
1329 }
1330 CAmount fee_needed = coin_selection_params.m_effective_feerate.GetFee(nBytes) + result.GetTotalBumpFees();
1331 const CAmount output_value = CalculateOutputValue(txNew);
1332 Assume(recipients_sum + change_amount == output_value);
1333 CAmount current_fee = result.GetSelectedValue() - output_value;
1334 1335 // Sanity check that the fee cannot be negative as that means we have more output value than input value
1336 if (current_fee < 0) {
1337 return util::Error{Untranslated(STR_INTERNAL_BUG("Fee paid < 0"))};
1338 }
1339 1340 // If there is a change output and we overpay the fees then increase the change to match the fee needed
1341 if (change_pos && fee_needed < current_fee) {
1342 auto& change = txNew.vout.at(*change_pos);
1343 change.nValue += current_fee - fee_needed;
1344 current_fee = result.GetSelectedValue() - CalculateOutputValue(txNew);
1345 if (fee_needed != current_fee) {
1346 return util::Error{Untranslated(STR_INTERNAL_BUG("Change adjustment: Fee needed != fee paid"))};
1347 }
1348 }
1349 1350 // Reduce output values for subtractFeeFromAmount
1351 if (coin_selection_params.m_subtract_fee_outputs) {
1352 CAmount to_reduce = fee_needed - current_fee;
1353 unsigned int i = 0;
1354 bool fFirst = true;
1355 for (const auto& recipient : vecSend)
1356 {
1357 if (change_pos && i == *change_pos) {
1358 ++i;
1359 }
1360 CTxOut& txout = txNew.vout[i];
1361 1362 if (recipient.fSubtractFeeFromAmount)
1363 {
1364 txout.nValue -= to_reduce / outputs_to_subtract_fee_from; // Subtract fee equally from each selected recipient
1365 1366 if (fFirst) // first receiver pays the remainder not divisible by output count
1367 {
1368 fFirst = false;
1369 txout.nValue -= to_reduce % outputs_to_subtract_fee_from;
1370 }
1371 1372 // Error if this output is reduced to be below dust
1373 if (IsDust(txout, wallet.chain().relayDustFee())) {
1374 if (txout.nValue < 0) {
1375 return util::Error{_("The transaction amount is too small to pay the fee")};
1376 } else {
1377 return util::Error{_("The transaction amount is too small to send after the fee has been deducted")};
1378 }
1379 }
1380 }
1381 ++i;
1382 }
1383 current_fee = result.GetSelectedValue() - CalculateOutputValue(txNew);
1384 if (fee_needed != current_fee) {
1385 return util::Error{Untranslated(STR_INTERNAL_BUG("SFFO: Fee needed != fee paid"))};
1386 }
1387 }
1388 1389 // fee_needed should now always be less than or equal to the current fees that we pay.
1390 // If it is not, it is a bug.
1391 if (fee_needed > current_fee) {
1392 return util::Error{Untranslated(STR_INTERNAL_BUG("Fee needed > fee paid"))};
1393 }
1394 1395 // Give up if change keypool ran out and change is required
1396 if (scriptChange.empty() && change_pos) {
1397 return util::Error{error};
1398 }
1399 1400 if (sign && !wallet.SignTransaction(txNew)) {
1401 return util::Error{_("Signing transaction failed")};
1402 }
1403 1404 // Return the constructed transaction data.
1405 CTransactionRef tx = MakeTransactionRef(std::move(txNew));
1406 1407 // Limit size
1408 if ((sign && GetTransactionWeight(*tx) > MAX_STANDARD_TX_WEIGHT) ||
1409 (!sign && tx_sizes.weight > MAX_STANDARD_TX_WEIGHT))
1410 {
1411 return util::Error{_("Transaction too large")};
1412 }
1413 1414 if (current_fee > wallet.m_default_max_tx_fee) {
1415 return util::Error{TransactionErrorString(TransactionError::MAX_FEE_EXCEEDED)};
1416 }
1417 1418 if (gArgs.GetBoolArg("-walletrejectlongchains", DEFAULT_WALLET_REJECT_LONG_CHAINS)) {
1419 // Lastly, ensure this tx will pass the mempool's chain limits
1420 auto result = wallet.chain().checkChainLimits(tx);
1421 if (!result) {
1422 return util::Error{util::ErrorString(result)};
1423 }
1424 }
1425 1426 // Before we return success, we assume any change key will be used to prevent
1427 // accidental reuse.
1428 reservedest.KeepDestination();
1429 1430 wallet.WalletLogPrintf("Coin Selection: Algorithm:%s, Waste Metric Score:%d\n", GetAlgorithmName(result.GetAlgo()), result.GetWaste());
1431 wallet.WalletLogPrintf("Fee Calculation: Fee:%d Bytes:%u Tgt:%d (requested %d) Reason:\"%s\" Decay %.5f: Estimation: (%g - %g) %.2f%% %.1f/(%.1f %d mem %.1f out) Fail: (%g - %g) %.2f%% %.1f/(%.1f %d mem %.1f out)\n",
1432 current_fee, nBytes, feeCalc.returnedTarget, feeCalc.desiredTarget, StringForFeeReason(feeCalc.reason), feeCalc.est.decay,
1433 feeCalc.est.pass.start, feeCalc.est.pass.end,
1434 (feeCalc.est.pass.totalConfirmed + feeCalc.est.pass.inMempool + feeCalc.est.pass.leftMempool) > 0.0 ? 100 * feeCalc.est.pass.withinTarget / (feeCalc.est.pass.totalConfirmed + feeCalc.est.pass.inMempool + feeCalc.est.pass.leftMempool) : 0.0,
1435 feeCalc.est.pass.withinTarget, feeCalc.est.pass.totalConfirmed, feeCalc.est.pass.inMempool, feeCalc.est.pass.leftMempool,
1436 feeCalc.est.fail.start, feeCalc.est.fail.end,
1437 (feeCalc.est.fail.totalConfirmed + feeCalc.est.fail.inMempool + feeCalc.est.fail.leftMempool) > 0.0 ? 100 * feeCalc.est.fail.withinTarget / (feeCalc.est.fail.totalConfirmed + feeCalc.est.fail.inMempool + feeCalc.est.fail.leftMempool) : 0.0,
1438 feeCalc.est.fail.withinTarget, feeCalc.est.fail.totalConfirmed, feeCalc.est.fail.inMempool, feeCalc.est.fail.leftMempool);
1439 return CreatedTransactionResult(tx, current_fee, change_pos, feeCalc);
1440 }
1441 1442 util::Result<CreatedTransactionResult> CreateTransaction(
1443 CWallet& wallet,
1444 const std::vector<CRecipient>& vecSend,
1445 std::optional<unsigned int> change_pos,
1446 const CCoinControl& coin_control,
1447 bool sign)
1448 {
1449 if (vecSend.empty()) {
1450 return util::Error{_("Transaction must have at least one recipient")};
1451 }
1452 1453 if (std::any_of(vecSend.cbegin(), vecSend.cend(), [](const auto& recipient){ return recipient.nAmount < 0; })) {
1454 return util::Error{_("Transaction amounts must not be negative")};
1455 }
1456 1457 LOCK(wallet.cs_wallet);
1458 1459 auto res = CreateTransactionInternal(wallet, vecSend, change_pos, coin_control, sign);
1460 TRACEPOINT(coin_selection, normal_create_tx_internal,
1461 wallet.GetName().c_str(),
1462 bool(res),
1463 res ? res->fee : 0,
1464 res && res->change_pos.has_value() ? int32_t(*res->change_pos) : -1);
1465 if (!res) return res;
1466 const auto& txr_ungrouped = *res;
1467 // try with avoidpartialspends unless it's enabled already
1468 if (txr_ungrouped.fee > 0 /* 0 means non-functional fee rate estimation */ && wallet.m_max_aps_fee > -1 && !coin_control.m_avoid_partial_spends) {
1469 TRACEPOINT(coin_selection, attempting_aps_create_tx, wallet.GetName().c_str());
1470 CCoinControl tmp_cc = coin_control;
1471 tmp_cc.m_avoid_partial_spends = true;
1472 1473 // Reuse the change destination from the first creation attempt to avoid skipping BIP44 indexes
1474 if (txr_ungrouped.change_pos) {
1475 ExtractDestination(txr_ungrouped.tx->vout[*txr_ungrouped.change_pos].scriptPubKey, tmp_cc.destChange);
1476 }
1477 1478 auto txr_grouped = CreateTransactionInternal(wallet, vecSend, change_pos, tmp_cc, sign);
1479 // if fee of this alternative one is within the range of the max fee, we use this one
1480 const bool use_aps{txr_grouped.has_value() ? (txr_grouped->fee <= txr_ungrouped.fee + wallet.m_max_aps_fee) : false};
1481 TRACEPOINT(coin_selection, aps_create_tx_internal,
1482 wallet.GetName().c_str(),
1483 use_aps,
1484 txr_grouped.has_value(),
1485 txr_grouped.has_value() ? txr_grouped->fee : 0,
1486 txr_grouped.has_value() && txr_grouped->change_pos.has_value() ? int32_t(*txr_grouped->change_pos) : -1);
1487 if (txr_grouped) {
1488 wallet.WalletLogPrintf("Fee non-grouped = %lld, grouped = %lld, using %s\n",
1489 txr_ungrouped.fee, txr_grouped->fee, use_aps ? "grouped" : "non-grouped");
1490 if (use_aps) return txr_grouped;
1491 }
1492 }
1493 return res;
1494 }
1495 1496 util::Result<CreatedTransactionResult> FundTransaction(CWallet& wallet, const CMutableTransaction& tx, const std::vector<CRecipient>& vecSend, std::optional<unsigned int> change_pos, bool lockUnspents, CCoinControl coinControl)
1497 {
1498 // We want to make sure tx.vout is not used now that we are passing outputs as a vector of recipients.
1499 // This sets us up to remove tx completely in a future PR in favor of passing the inputs directly.
1500 assert(tx.vout.empty());
1501 1502 // Set the user desired locktime
1503 coinControl.m_locktime = tx.nLockTime;
1504 1505 // Set the user desired version
1506 coinControl.m_version = tx.version;
1507 1508 // Acquire the locks to prevent races to the new locked unspents between the
1509 // CreateTransaction call and LockCoin calls (when lockUnspents is true).
1510 LOCK(wallet.cs_wallet);
1511 1512 // Fetch specified UTXOs from the UTXO set to get the scriptPubKeys and values of the outputs being selected
1513 // and to match with the given solving_data. Only used for non-wallet outputs.
1514 std::map<COutPoint, Coin> coins;
1515 for (const CTxIn& txin : tx.vin) {
1516 coins[txin.prevout]; // Create empty map entry keyed by prevout.
1517 }
1518 wallet.chain().findCoins(coins);
1519 1520 for (const CTxIn& txin : tx.vin) {
1521 const auto& outPoint = txin.prevout;
1522 PreselectedInput& preset_txin = coinControl.Select(outPoint);
1523 if (!wallet.IsMine(outPoint)) {
1524 if (coins[outPoint].out.IsNull()) {
1525 return util::Error{_("Unable to find UTXO for external input")};
1526 }
1527 1528 // The input was not in the wallet, but is in the UTXO set, so select as external
1529 preset_txin.SetTxOut(coins[outPoint].out);
1530 }
1531 preset_txin.SetSequence(txin.nSequence);
1532 preset_txin.SetScriptSig(txin.scriptSig);
1533 preset_txin.SetScriptWitness(txin.scriptWitness);
1534 }
1535 1536 auto res = CreateTransaction(wallet, vecSend, change_pos, coinControl, false);
1537 if (!res) {
1538 return res;
1539 }
1540 1541 if (lockUnspents) {
1542 for (const CTxIn& txin : res->tx->vin) {
1543 wallet.LockCoin(txin.prevout);
1544 }
1545 }
1546 1547 return res;
1548 }
1549 } // namespace wallet
1550