Commit Graph

49180 Commits

Author SHA1 Message Date
Ava Chow
a5050ddb6b Merge bitcoin/bitcoin#32150: coinselection: Optimize BnB exploration
7249b376a0 opt: Skip UTXOs with worse waste, same eff_value (Murch)
5204291860 opt: Skip evaluation of equivalent input sets (Murch)
ba1807b981 coinselection: Track effective_value lookahead (Murch)
fa226ab902 coinselection: BnB skip exploring high waste (Murch)
7ecea1dc5d coinselection: Track whether BnB completed (Murch)
3ca0f36164 coinselection: rewrite BnB in CoinGrinder-style (Murch)
2e73739837 coinselection: Track BnB iteration count in result (Murch)

Pull request description:

  This PR rewrites the implementation of the BnB coinselection algorithm
  to skip the duplicate evaluation of previously visited input selections.

  In the original implementation of BnB, the state of the search is
  backtracked by explicitly walking back to the omission branch and then
  testing again. This retests an equivalent candidate set as before, e.g.,
  after backtracking from {ABC}, it would evaluate {AB_}, before trying
  {AB_D}, but {AB_} is equivalent to {AB} which was tested before.

  CoinGrinder tracks the state of the search instead by remembering which
  UTXO was last added and explicitly shifting from that UTXO directly to
  the next, so after {ABC}, it will immediately move on to {AB_D}. We
  replicate this approach here.

  As fewer nodes are visited, this approach will enumerate more possible
  combinations than the original implementation given the same limit for
  iterations.

ACKs for top commit:
  achow101:
    ACK 7249b376a0
  w0xlt:
    reACK 7249b376a0

Tree-SHA512: fd5851ceea3a3a4699fc062254fa5438daa4275b4d52325983e63670040cf0ba35112be9e63813d8f30b38993c031f3df343b2152eb8c068d272fbff72d1881a
2026-06-03 14:06:42 -07:00
Ava Chow
082bb1a104 Merge bitcoin/bitcoin#35335: Make deployment configuration available outside of regtest in unit tests
801e3bfe38 chainparams: add overloads for RegTest and SigNet with no options (Antoine Poinsot)
4995c00a9c chainparams: make deployment configuration available on all test networks (Antoine Poinsot)
df7ed5f355 chainparams: encapsulate deployment configuration logic (Antoine Poinsot)

Pull request description:

  It's sometimes useful to test a deployment on other networks than regtest. This may be e.g. because regtest lacks a property relevant for the test, or simply because the test aims to be portable while regtest is Bitcoin Core specific.

  This PR makes it possible to set the `-vbparams` and `-testactivationheight` options on any network in unit tests, and on any **test** network as a startup option.

  This is preparatory work for a BIP 54 implementation, but may be useful separately.

ACKs for top commit:
  edilmedeiros:
    utACK 801e3bfe38
  achow101:
    ACK 801e3bfe38
  sedited:
    ACK 801e3bfe38
  instagibbs:
    ACK 801e3bfe38

Tree-SHA512: 10649dc9bbc70a830bb0c4b1c965de5bf2e6be1a6c2832bdf11e9248dacb4a1f60421b410d0284213e88de6c54218252ae5de423b4c6e659d10bab1cbe7e7e87
2026-06-03 13:53:24 -07:00
Ava Chow
5bd990a3dd Merge bitcoin/bitcoin#34779: BIP 323: reserve version bits 5-28 as extra nonce space
107d4178d9 versionbits: update VersionBitsCache doc comment to match current behaviour (Antoine Poinsot)
94e3ac0b21 doc: release notes and bips doc update for #34779 (Antoine Poinsot)
1d5240574a qa: test we don't warn for ignored unknown version bits deployments (Antoine Poinsot)
f802edf57c versionbits: Limit live activation params and activation warnings per BIP323 (Anthony Towns)

Pull request description:

  This implements https://github.com/bitcoin/bips/pull/2116, which repurposes 24 version bits as extra nonce space for miners rather than soft fork deployment coordination. 24 bits allows a miner to perform up to 72 PH before needing a fresh job from its controller. The current 16 bits in use by miners only allow up to 280 TH, which [apparently led some ASIC designers to start rolling the timestamp field](https://github.com/bitaxeorg/ESP-Miner/pull/1553#issuecomment-3937736319) on their beefier machines.

  Mailing list discussion available [here](https://gnusha.org/pi/bitcoindev/6fa0cb45-37d6-4b41-9ff8-03730fd96d6e@mattcorallo.com/). A previous shot at this is https://github.com/bitcoin/bitcoin/pull/13972 (with a smaller extranonce space).

  This change only affects the warning logic.

ACKs for top commit:
  ajtowns:
    ACK 107d4178d9
  achow101:
    ACK 107d4178d9
  sedited:
    Re-ACK 107d4178d9
  optout21:
    ACK 107d4178d9

Tree-SHA512: cfaf5d7de1e8c020a4d7f4b1096b6c3e0e3b41ea840a4652ebcdabc345c5c557161c8304f1d7d6de541a2bf1df3c855ad7b64e49dd8c8af3937876d134bb5aba
2026-06-03 11:56:14 -07:00
Hennadii Stepanov
7c2718a4b8 Merge bitcoin/bitcoin#34767: Bugfix: GUI/Intro: Handle errors from SelectParams the same as if during InitConfig
55d37546fa Bugfix: GUI/Intro: Handle errors from SelectParams the same as if during InitConfig (Luke Dashjr)

Pull request description:

  Without this, invalid vbparams just silently exit with no message

ACKs for top commit:
  sedited:
    ACK 55d37546fa
  hebasto:
    ACK 55d37546fa, tested on Fedora 44.

Tree-SHA512: 0508ca64c86a651b9b21ae2a1e26dfb84c0dbb0b20d309da499545be2733d42c98012b84d81177ba0635d0d8bce87c888b256a014e2065bd4a80db88e73ec3d4
2026-06-03 11:23:37 +01:00
merge-script
b28cf409a1 Merge bitcoin/bitcoin#34866: fuzz: target concurrent leveldb reads
8cb8653a22 fuzz: target concurrent leveldb reads (Andrew Toth)
6609088fe6 fuzz: extract ConsumeDBParams helper (Andrew Toth)

Pull request description:

  Inspired by https://github.com/bitcoin/bitcoin/pull/31132#issuecomment-4054461591.

  We currently do concurrent leveldb reads when accessing our indexes.
  1. `txindex` - we call `FindTx()` from multiple RPC threads.
  2. `blockfilterindex` - we call `LookupFilter/Header()` concurrently from `msghand` thread for p2p requests as well as RPC threads.
  3. `coinstatsindex` - we call `LookUpStats()` from multiple RPC threads.
  4. `txospenderindex` - we call `FindSpender()` from multiple RPC threads.

  We also read from our chainstate and blocks index while background compactions are writing.

  While OSS-Fuzz does cover leveldb (https://github.com/google/oss-fuzz/blob/master/projects/leveldb/fuzz_db.cc), it doesn't cover multi threaded access. Without a deterministic hypervisor this fuzz harness won't be deterministic, but we can at least run it with TSan to get a higher confidence that the synchronization code in leveldb is correct. Hopefully other reviewers find this useful.

  This harness creates a threadpool with 16 threads, and then creates an in-memory levelDB which it seeds with deterministically random values. It chooses a random set of keys to query. It first performs all queries on the db on a single thread to get a baseline, then synchronizes all threads on a latch so they hit the db at the same time. Each thread performs the same queries, and afterwards are all checked against the baseline.

  It uses a `DeterministicEnv` to capture background compaction work when seeding the db, which is also run immediately after the latch is released. This causes a race between compaction and reading, ensuring we exercise many thread synchronization code paths in leveldb.

  I ran both TSan and ASan/UBSan overnight with no issues.

ACKs for top commit:
  fjahr:
    Code review ACK 8cb8653a22
  l0rinc:
    ACK 8cb8653a22

Tree-SHA512: 2ca31a824715b92e258c84ecf0c762f43ee2a528e3a3192f94d8aaeddf6e99f820a0297ce9efcc95bc32c7ec74489f240a25bab856d724d768117a7d95a33974
2026-06-03 10:02:30 +01:00
merge-script
2669019fe8 Merge bitcoin/bitcoin#35269: musig: Include pubnonce in session id
2ef6679c2c test: Check that MuSig2 signing does not reuse nonces (Ava Chow)
bb05986c0a musig: Include pubnonce in session id (Ava Chow)

Pull request description:

  It is safe to have multiple musig signing sessions over the same message so long as the nonces used are different. Including the pubnonce in the session id allows for multiple simultaneous signing sessions over the same message, rather than asserting when the user tries to do this.

  The second commit tests this behavior, both ensuring that there is no crash, and verifying that both sessions produce unique nonces and signatures to verify that no reuse is occurring.

  Lastly, the assertion in `SetMuSig2SecNonce` is retained as hitting it now would indicate that a nonce has been reused. We prefer to assert and crash rather than do something that is highly likely to leak a private key.

  Fixes #35250

ACKs for top commit:
  rkrux:
    lgtm ACK 2ef6679c2c
  junbyjun1238:
    utACK 2ef6679c2c
  theStack:
    ACK 2ef6679c2c

Tree-SHA512: 9fb60b68ebe0ea9656408afb65b9ec9f280632e1bb84a4821b074c8d8569847845f7c29da800c757b9ddf3aa31aa890dd9e3646cf119917a714e7daf20be2198
2026-06-02 21:33:01 +02:00
Andrew Toth
8cb8653a22 fuzz: target concurrent leveldb reads 2026-06-02 09:56:32 -04:00
Andrew Toth
6609088fe6 fuzz: extract ConsumeDBParams helper
Pull the inline DBParams construction out of TestDbWrapper into a shared
ConsumeDBParams() helper. This is a pure refactor with no behavior change,
preparing for an additional harness that needs to build the same params.
2026-06-02 09:48:57 -04:00
merge-script
61d1c78ed4 Merge bitcoin/bitcoin#35192: wallet: unfriend LegacyDataSPKM and DescriptorScriptPubKeyMan
6c525c2ec1 wallet: unfriend LegacyDataSPKM and DescriptorScriptPubKeyMan classes (rkrux)

Pull request description:

  After #28333, `LegacyDataSPKM` doesn't need to use the private or protected members
  of `DescriptorScriptPubKeyMan` class such as `AddDescriptorKeyWithDB` and
  `TopUpWithDB`. Moreover, these two SPKMs are siblings that inherit from the common
  `ScriptPubKeyMan` that have non intersecting use cases semantically. It seems reasonable
  to me that they are unfriended so that private members of one are not exposed to
  another unnecessarily.

ACKs for top commit:
  polespinasa:
    ACK 6c525c2ec1
  sedited:
    ACK 6c525c2ec1

Tree-SHA512: ebcd9b4e202b152b53c390f44cac46748b7fdebd4f854e84d322468a1f117e729d75210db5688dc7f38124280378f62fa469d2e5ee9adb4cb77acb2c73cc8480
2026-06-02 13:48:00 +02:00
merge-script
2e0a36c360 Merge bitcoin/bitcoin#35439: test: Improve loopback address check in rpc_bind.py
c8b8c275fa test: Improve loopback address check in `rcp_bind.py` (xyzconstant)

Pull request description:

  A [loopback address](https://www.geeksforgeeks.org/computer-networks/what-is-a-loopback-address/) can range from `127.0.0.0` to `127.255.255.255`. This commit relaxes the loopback check in `rpc_bind.py` by checking whether an IP address (from `all_interfaces()`) starts with `'127.'` instead of strictly matching `'127.0.0.1'`.

  Programs like VPNs might add an extra loopback address (e.g., 127.1.130.83), which failed under the previous state. These addresses will now pass with this update.

  ---
  **For context:** I found this while running tests with the Mullvad daemon active. Mullvad adds a custom lo0 interface like `inet 127.141.11.239 netmask 0xff000000` that failed with `--nonloopback`, which should not be the case since the address is a valid loopback IP.

ACKs for top commit:
  maflcko:
    lgtm ACK c8b8c275fa
  willcl-ark:
    ACK c8b8c275fa

Tree-SHA512: 3b82002d6bc90cfc4023dd0274a40970abb2dc6a9ced77dd97e275b31340bb657d5222bb55a768ebf71047ac1521dd4ba77fb427398f7cc9857738bcd16c5818
2026-06-02 12:36:28 +02:00
merge-script
53373d07c3 Merge bitcoin/bitcoin#35430: ci: use warp caching on warp runners
2ce4ae7d8f ci: Add dynamic cache switching to warp cache (will)

Pull request description:

  The GHA cache is very slow, taking on the order of minutes to save and
  restore from.

  Use WarpBuild's cache instead as this is in the same region and should
  be much faster.

  WarpBuild cache action does not auto-fallback to GHA if not being run on
  Warp. To allow fork runs to fallback to GHA caching, whilst minimising
  duplication in the action files, create new "interal" actions which
  perform the switching logic, and use these in the (renamed) cache|save
  actions.

  Without this we would need the `if` logic in our prvious actions, 4
  times in each of save and restore.

ACKs for top commit:
  m3dwards:
    ACK 2ce4ae7d8f

Tree-SHA512: 966ed85558e8ebeed20a6fdf065f0838c9bee95f7d0a2fd1c8a46de20b956f5eedb6bf5098d742da20ea80c56069b86ff46f3151936dc28d5e4afa70acc5d988
2026-06-02 11:11:26 +01:00
merge-script
255f7c720f Merge bitcoin/bitcoin#35404: wallet: allow anti-fee-sniping in sendall RPC while not relying on RBF default
9c1fcaca5c wallet, test: fix sendall anti-fee-sniping when locktime is not specified (rkrux)
8877eec726 wallet: allow anti-fee-sniping in sendall RPC while not relying on RBF default (rkrux)

Pull request description:

  Partially fixes https://github.com/bitcoin/bitcoin/issues/32661.
  Prerequisite to #35405.

  The test change in the second commit would fail without the presence
  of the first commit.

ACKs for top commit:
  maflcko:
    review ACK 9c1fcaca5c 🍅
  xyzconstant:
    Tested ACK 9c1fcaca5c
  polespinasa:
    code review ACK 9c1fcaca5c
  sedited:
    ACK 9c1fcaca5c

Tree-SHA512: 048c1a6c64c104f8c27053e4dea139fb8740f30096f4d85daf23aa53a9ad21f0120151a7d1d6ea19b12d174976999335b3f9ac863800629774d8030b7f34918f
2026-06-02 11:59:27 +02:00
xyzconstant
c8b8c275fa test: Improve loopback address check in rcp_bind.py
A loopback address can range from `127.0.0.0` to `127.255.255.255`.
This commit relaxes the loopback check in `rpc_bind.py` by checking whether
an IP address (from `all_interfaces()`) starts with `'127.'` instead of
strictly matching `'127.0.0.1'`.

Programs like VPNs might add an extra loopback address (e.g., 127.1.130.83),
which failed under the previous state. These addresses will now pass with this update.
2026-06-01 19:01:12 -03:00
merge-script
654a5223af Merge bitcoin/bitcoin#33661: test: Add test on skip heights in CBlockIndex
131fa570b9 test: Add test for BuildSkip() and skip heights (optout)

Pull request description:

  The skip height values computed by the (internal) function `GetSkipHeight()`, and the `CBlockIndex::BuildSkip()` method are not tested directly, and the skip logic is not well documented. To improve test coverage, a new test is added, to verify `CBlockIndex::BuildSkip()` and the skip height bit-manipulation logic.

  Note: the original version contained a test for the complexity of the `GetAncestor()` algorithm, whose performance is greatly determined by the skip height logic. This test was out-scoped. (see: https://github.com/bitcoin/bitcoin/pull/33661#issuecomment-4486353485)

  The motivation is to document the skip value computation through a test. (The issued was noticed while reviewing #33515.)

ACKs for top commit:
  l0rinc:
    ACK 131fa570b9
  sipa:
    ACK 131fa570b9

Tree-SHA512: 468070946419d9d2891e43ed014b040348fc9d3b35dc21522487ac28e06b6d5d556ac02ebc4fa7761e202fc80f9e9ab7a7ec47c6e05ae55e33950ff5f8f3596f
2026-06-01 21:53:58 +02:00
merge-script
19e45334bc Merge bitcoin/bitcoin#35312: kernel: assert invalid buffer preconditions in btck_*_create functions
570a627640 kernel: assert invalid buffer preconditions in `btck_*_create` functions (stringintech)

Pull request description:

  The kernel API appears to use `nullptr` returns to report failures that callers may reasonably want to recover from: malformed serialized input, object construction failures, chainstate/load failures, and similar runtime conditions.

  The raw create-function buffer checks seem to be a different case. A failure of `ptr == nullptr && len > 0` does not indicate malformed input data or a failure encountered while deserializing or constructing the requested object. Returning `nullptr` for these checks widens the recoverable error surface with cases that are better treated as programmer errors, similar to other asserted preconditions in this API such as invalid indices and impossible enum/flag states.

  This change switches those buffer argument checks from `nullptr` returns to assertions in `btck_transaction_create`, `btck_script_pubkey_create`, `btck_block_create`, `btck_block_header_create`, and `btck_chainstate_manager_options_create`. `btck_block_header_create` additionally asserts the pre-existing documented length contract (must be 80 bytes). These functions still return `nullptr` when the provided bytes cannot be parsed or when object creation fails during processing.

  I ended up looking at this while working on the `kernel-bindings-tests` spec/schema for `btck_script_pubkey_create`, where treating this path as a regular error did not seem like the right contract: https://github.com/stringintech/kernel-bindings-tests/pull/14#discussion_r3240859568.

ACKs for top commit:
  stickies-v:
    ACK 570a627640
  janb84:
    ACK 570a627640
  w0xlt:
    ACK 570a627640
  sedited:
    ACK 570a627640

Tree-SHA512: 064d834abe0c27245a144e5290bbeeb510daf9e4d50bb3a8e50bd8a0bf897b3dcf6ad5acfcabf1d8110da120e5e014ee3aea0241c0f181a21c6f3c14dc452ade
2026-06-01 21:47:38 +02:00
Antoine Poinsot
107d4178d9 versionbits: update VersionBitsCache doc comment to match current behaviour
Co-Authored-by: Anthony Towns <aj@erisian.com.au>
2026-06-01 09:53:29 -04:00
Antoine Poinsot
94e3ac0b21 doc: release notes and bips doc update for #34779 2026-06-01 09:53:29 -04:00
Antoine Poinsot
1d5240574a qa: test we don't warn for ignored unknown version bits deployments
Co-Authored-by: Anthony Towns <aj@erisian.com.au>
2026-06-01 09:53:27 -04:00
Anthony Towns
f802edf57c versionbits: Limit live activation params and activation warnings per BIP323
Test bits are conserved. This only has an effect on the warnings.

Co-Authored-By: Antoine Poinsot <mail@antoinep.com>
2026-06-01 09:50:48 -04:00
will
2ce4ae7d8f ci: Add dynamic cache switching to warp cache
The GHA cache is very slow, taking on the order of minutes to save and
restore from.

Use WarpBuild's cache instead as this is in the same region and much
faster.

WarpBuild cache action does not auto-fallback to GHA if not being run on
Warp. To allow fork runs to fallback to GHA caching, whilst minimising
duplication in the action files, create new "interal" actions which
perform the switching logic, and use these in the (renamed) cache|save
actions.

Without this we would need the `if` logic in our prvious actions, 4
times in each of save and restore.

Plumb the provider through into the action, as a composite action can't
read `env` (`GITHUB_OUTPUT`) from previous steps.
2026-06-01 12:08:27 +01:00
merge-script
fbe628756c Merge bitcoin/bitcoin#35131: guix, refactor: Minor script cleanups and improvements
53388773af guix: Remove redundant ShellCheck `source` directives (Hennadii Stepanov)
62cf7bc53f guix, refactor: Add `BASE` argument to `*_for_host` functions (Hennadii Stepanov)
5d46429e32 guix, refactor: Move `distsrc_for_host()` to `prelude.bash` (Hennadii Stepanov)
cab65ea9c6 guix, refactor: Move duplicated `profiledir_for_host()` to `prelude.bash` (Hennadii Stepanov)
faa9d4345f guix, refactor: Move duplicated `outdir_for_host()` to `prelude.bash` (Hennadii Stepanov)
6b59fd6b8c guix, refactor: Remove `contains()` function (Hennadii Stepanov)
d4c69a7224 guix, refactor: Remove unused `out_name()` function (Hennadii Stepanov)

Pull request description:

  While working on https://github.com/bitcoin/bitcoin/pull/35098, I reviewed my notes regarding a few minor Guix script flaws and decided to address them here.

  This PR:

  1. Removes unused code.

  2. Reduces code duplication.

  3. Improves consistency across function usage.

  4. Minimizes ShellCheck directive usage.

ACKs for top commit:
  fanquake:
    ACK 53388773af - the move-only deduplication, and dead code removal seem fine. The other (refactoring) changes seem less well motived

Tree-SHA512: d565e31ba49300f3001b04d3143721aced305f41bca6d04c33dc479d568efb2c06d91758619378199f174a40f1306c9418ae80d5478013a65ad96341bea122b1
2026-05-30 10:25:25 +01:00
Ava Chow
34ac53457f Merge bitcoin/bitcoin#35402: doc: Compress doc/build-unix.md dependency package names into table
fa787043f5 doc: Compress doc/build-unix.md dependency package names into table (MarcoFalke)

Pull request description:

  Currently, `doc/build-unix.md` is tediously verbose, because for several Linux distros, it has exact duplicate sections with only the package names adjusted.

  This is hard to maintain, and review. Also, it is hard to read, and hard to use, because a one-line copy-paste does not work to fetch the list of packages.

  Fix all issues by compressing the 150+ lines into a small table and a short description.

ACKs for top commit:
  achow101:
    ACK fa787043f5
  darosior:
    ACK fa787043f5
  sedited:
    ACK fa787043f5
  hebasto:
    re-ACK fa787043f5.

Tree-SHA512: a6d7f18392ab5a0d468387ffe4335f71ae9656a100ede3de4118e3ef28814e5a70202ffa55eb0218a07effcde220b680499ea9068fd54b91cac42fca8699febf
2026-05-29 15:25:53 -07:00
merge-script
10dfdd4b9f Merge bitcoin/bitcoin#35379: test: Fix feature_dbcrash.py --usecli error
fad585b6e5 test: Wait for node exit after crash in verify_utxo_hash (MarcoFalke)
faf1475514 ci: Exclude feature_dbcrash.py under --v2transport --usecli (MarcoFalke)
fac27d702f test: Fix feature_dbcrash.py --usecli intermittent error (MarcoFalke)
fa09de8b68 test: [refactor] Simplify submit_block_catch_error (MarcoFalke)

Pull request description:

  This fixes a small intermittent issue that snuck in via commit fa8d4d5c35.

  Generally, it seems tedious and brittle trying to enumerate all possible exception types on all platforms and all test configs, all possible errno values, etc.

  So just treat any `Exception` as crash, and confirm it in the test. The test would still fail, if a crash did not happen after an Exception, but the failure may be minimally more tedious to debug. I think this is fine, because failures should be rare and having simpler and more flexible test code is preferable.

  ----

  Also, disable the test for now in CI, because it is quite slow.

ACKs for top commit:
  willcl-ark:
    ACK fad585b6e5

Tree-SHA512: 6ff69a53908b22904780f29def473f8e26c5b608d89420ac76768d06ea3e3394b5d3f4d488100f9d47f943ff5778a555302ccdaebc11fda7c009205b6a6ca05c
2026-05-29 15:16:32 +01:00
merge-script
214ad1761b Merge bitcoin/bitcoin#35408: ci: 35378 followups
5700a61b73 ci: use ubuntu-latest instead of ubuntu-24.04 (fanquake)
265563bf75 doc: remove reference to cirrus (fanquake)

Pull request description:

  Two followups to #35378, mentioned here: https://github.com/bitcoin/bitcoin/pull/35397#discussion_r3319302684.

ACKs for top commit:
  maflcko:
    review ACK 5700a61b73 🥗
  willcl-ark:
    ACK 5700a61b73

Tree-SHA512: 015cc2efd5f9c421c09c1d953e48e46c860deaa81302d00929b893a6cdcf759a8baac6a521ff80f8618adaf9d64800a4c0d921ca1e92ea32a6b83f241bd33657
2026-05-29 15:00:29 +01:00
merge-script
a3dc44c085 Merge bitcoin/bitcoin#35385: test: restore JSONRPCException error format
ac09260982 test: restore JSONRPCException error format (rkrux)

Pull request description:

  This is a follow-up to PR #34575.

ACKs for top commit:
  maflcko:
    lgtm ACK ac09260982

Tree-SHA512: 15979f4e2c07993f283640ebfe570e9f8d3842a23a8118042f5b618273e0da8a01bcabe1ec90b6cc49ebf28e9819d1b4f077ac18f62f681a4d4f58ad8e11bdb1
2026-05-29 14:47:29 +01:00
rkrux
9c1fcaca5c wallet, test: fix sendall anti-fee-sniping when locktime is not specified
This particular test case only needs to ensure that locktime is not
specified in the RPC request, it doesn't need to rely on the wallet optin
RBF default that causes the test to pass coincidentally.

Co-authored-by: maflcko <6399679+maflcko@users.noreply.github.com>
2026-05-29 18:37:17 +05:30
stringintech
570a627640 kernel: assert invalid buffer preconditions in btck_*_create functions
Switch buffer `ptr == nullptr && len > 0` checks from `nullptr` returns to assertions. These checks represent invalid caller preconditions, not failures encountered while deserializing or constructing the requested object. `btck_block_header_create` additionally asserts the pre-existing documented length contract (must be 80 bytes).
2026-05-29 15:43:13 +03:30
rkrux
ac09260982 test: restore JSONRPCException error format
This is a follow-up to PR 34575.

Copy is done so that checking of error["code"] in test_node.py
while handling this exception doesn't fail.

Co-authored-by: maflcko <6399679+maflcko@users.noreply.github.com>
2026-05-29 17:03:15 +05:30
rkrux
6c525c2ec1 wallet: unfriend LegacyDataSPKM and DescriptorScriptPubKeyMan classes
After PR 28333, `LegacyDataSPKM` doesn't need to use the private or
protected members of `DescriptorScriptPubKeyMan` class such as
`AddDescriptorKeyWithDB` and `TopUpWithDB`. Moreover, these two SPKMs
are siblings that inherit from the common `ScriptPubKeyMan`.

It seems reasonable to me that they are unfriended so that private
members of one are not exposed to another unnecessarily.
2026-05-29 15:28:37 +05:30
rkrux
8877eec726 wallet: allow anti-fee-sniping in sendall RPC while not relying on RBF default
In case locktime (and replaceable) not being specified in this RPC request,
the wallet sets the transaction replaceable due to the default value of opt-in
RBF set in the wallet.

This allowed the anti-fee-sniping flow to be executed but in case of
replaceable being set false in the request, anti-fee-sniping flow would be
missed.

This patch fixes it.
2026-05-29 15:14:54 +05:30
merge-script
13b7fffc5e Merge bitcoin/bitcoin#35011: iwyu: Fix warnings in src/script and treat them as errors
6183942513 ci, iwyu: Fix warnings in src/scripts and treat them as error (Brandon Odiwuor)

Pull request description:

  This PR [continues](https://github.com/bitcoin/bitcoin/pull/33725#issuecomment-3466897433) the ongoing effort to enforce IWYU warnings.

  See [Developer Notes](https://github.com/bitcoin/bitcoin/blob/master/doc/developer-notes.md#using-iwyu).

ACKs for top commit:
  maflcko:
    review ACK 6183942513  🚖
  hebasto:
    ACK 6183942513.

Tree-SHA512: 75f36189953cae82e03a7a69c285969e3fbf896656f60c77ab44b80264f88a03cf78af5352b719567f80abc0d7c818b7e4ffff0c83cfbc6d08c2d5fcc2fb0c5b
2026-05-29 10:30:30 +01:00
Brandon Odiwuor
6183942513 ci, iwyu: Fix warnings in src/scripts and treat them as error 2026-05-29 11:36:08 +03:00
fanquake
5700a61b73 ci: use ubuntu-latest instead of ubuntu-24.04
To match the usage of -latest for the warp runners.
2026-05-29 09:03:12 +01:00
fanquake
265563bf75 doc: remove reference to cirrus 2026-05-29 08:59:43 +01:00
merge-script
1ea532e590 Merge bitcoin/bitcoin#34953: crypto: disable ASan instrumentation of SSE4 SHA256 for GCC (matching Clang)
fedeff7f20 crypto: disable ASan instrumentation of SSE4 SHA256 for GCC (deadmanoz)

Pull request description:

  Fix the runtime crash described in #34881.

  Upstream already disables ASan instrumentation for `sha256_sse4::Transform()` under Clang. This extends the same workaround to GCC by adding an `#elif` branch for `__GNUC__` / `__SANITIZE_ADDRESS__` that applies the same `no_sanitize("address")` attribute.

  Testing:

  - reproduced the crash before the fix with GCC 13, 14, and 15 on Haswell-class machines / guests without SHA-NI (including by forcing the SSE4 implementation on GitHub CI)
  - SEGV in debug builds regardless of optimization level (tested `-O0`, `-O1`, `-O2`, `-O3`)
  - verified that the GCC + ASan debug configurations that previously crashed pass with this change

  Issue #34881 has more details about the issue.

  Note: the original Clang code placed the `__attribute__` between the function declarator and the opening brace. GCC's [Attribute Syntax](https://gcc.gnu.org/onlinedocs/gcc/Attribute-Syntax.html) documentation notes that this position in a function definition "may, in future, be permitted," so it is not currently supported. Placing the attribute at the start of the function definition is valid form for both GCC and Clang.

ACKs for top commit:
  maflcko:
    lgtm ACK fedeff7f20 🏒
  sedited:
    tACK fedeff7f20

Tree-SHA512: d8adda0df140b6c93d18f5ecd096b12012332bb640e678075e668122e596baddcb2182cbaeafe7908ada90b4b5cc776a59dcdfb488229ab6640058ccbbd7ea93
2026-05-28 23:04:29 +02:00
Ava Chow
d0a54dd8e0 Merge bitcoin/bitcoin#35381: wallet, test: optinrbf deprecation followups
f701cd159a doc: fix typo in release notes of #34917 (rkrux)
7bc39e3d08 wallet, test: add wallet_deprecated_rbf.py for walletrbf deprecated keys & options (rkrux)
2cbbcb5659 wallet, test: remove -deprecatedrpc=bip125 from wallet_send.py (rkrux)
307134bd7e wallet, test: remove -deprecatedrpc=bip125 from wallet_migration.py (rkrux)
3ec550d168 wallet, test: remove -deprecatedrpc=bip125 from wallet_basic.py (rkrux)
a52ea9bff9 wallet, test: remove -walletrbf startup option from wallet_backwards_compatibility.py (rkrux)
42330922dd wallet, test: remove -walletrbf startup option from wallet_backwards_compatibility.py (rkrux)
8cb6e405d8 wallet, test: remove -walletrbf startup option from wallet_listtransactions.py (rkrux)
0ee94b2fef wallet, test: remove -deprecatedrpc=bip125 from wallet_listtransactions.py (rkrux)
5e833e068d wallet, test: -walletrbf startup option from wallet_bumpfee.py (rkrux)
a2a2b1745f wallet, test: remove -walletrbf startup option from rpc_psbt.py (rkrux)
a3fe455a95 wallet: refactor to read -walletrbf only once instead of twice (rkrux)

Pull request description:

  Prerequisite to #35404 and #35405.

  All these changes address the points raised in the review of PR #34917
  here: https://github.com/bitcoin/bitcoin/pull/34917#pullrequestreview-4362148900.

  Essentially updating the existing wallet functional tests without using
  the -deprecatedrpc=bip125 and -walletrbf startup options. Instead,
  these two are added and tested via a singular new
  wallet_deprecated_rbf.py test that can be removed easily later when
  these startup options are completely removed from the wallet post
  deprecation.

ACKs for top commit:
  maflcko:
    review ACK f701cd159a  🌄
  achow101:
    ACK f701cd159a

Tree-SHA512: 700785062b5de8ee3b6c4f50570b769d56c6c4960f2b6e2a2e71be8085c6b51eaeb34fb158fae76f812fe82791aaa0c0277f964f0472cb0784b86caabe6d4ec9
2026-05-28 13:44:17 -07:00
merge-script
c6f225c757 Merge bitcoin/bitcoin#28333: wallet: Construct ScriptPubKeyMans with all data rather than loaded progressively
451fdd26a4 test: wallet: Constructing a DSPKM that can't TopUp() throws. (David Gumberg)
32946e0291 wallet: Setup new autogenerated descriptors on construction (Ava Chow)
e20aaff70f wallet: Construct ExternalSignerSPKM with the new descriptor (Ava Chow)
aa4f7823aa wallet: include keys when constructing DescriptorSPKM during import (Ava Chow)
6538f69135 fuzz: Skip adding descriptor to wallet if it cannot be expanded (Ava Chow)
8be5ee554b test: wallet: Check that loading wallet with both unencrypted and encrypted keys fails. (David Gumberg)
80b0c25992 wallet: Load everything into DescSPKM on construction (Ava Chow)
f713fd1725 refactor: wallet: Don't reuse WALLET_BLANK flag for born-encrypted wallets. (David Gumberg)
cd912c4e10 wallet: Consolidate generation setup callers into one function (Ava Chow)
0301c758ea wallet migration, fuzz: Migrate hd seed once (Ava Chow)

Pull request description:

  Instead of constructing ScriptPubKeyMans with no data, and then loading data as we find it, we should gather everything first and then load it all on construction. If there actually is no data and we want to setup generation, then that should also occur in a constructor rather than afterwards.

  This change is only applied to DescriptorScriptPubKeyMan and ExternalSignerScriptPubKeyMan, and should be done for any ScriptPubKeyMans added in the future. I don't think it's really worth it to do this for LegacyScriptPubKeyMan since it would make loading performance worse (or cause layer violations) and it's (supposed to be) going away soon.

ACKs for top commit:
  polespinasa:
    ACK 451fdd26a4
  davidgumberg:
    re crACK 451fdd26a4
  w0xlt:
    ACK 451fdd26a4

Tree-SHA512: 58a889bf7c77d5da78041907a76a1958207f95a19bec8dc4d86d4e4108d256a729e0949c0973f7d447178f78a7fd4268cda71d358cae4dec5a76dc453b5283af
2026-05-28 21:49:59 +02:00
Ava Chow
5486ef8cc2 Merge bitcoin/bitcoin#34198: wallet: fix ancient wallets migration
b86c1c443d test: add coverage for migrating ancient wallets (furszy)
fd44d48b24 wallet: fix ancient wallets migration (furszy)

Pull request description:

  We currently fail migration if the wallet does not contain the best block locator.
  This is a problem for wallets created before https://github.com/bitcoin/bitcoin/pull/152, which are not storing such record.

  Missing this record is not an error. it simply means the wallet will scan the chain prior
  to finish migration.

ACKs for top commit:
  achow101:
    ACK b86c1c443d
  w0xlt:
    reACK b86c1c443d
  sedited:
    Re-ACK b86c1c443d

Tree-SHA512: 5226934e16d32f3337c432a84e1adce9985518e52c62abfa4a8d6b3d857d4b5c6aa99ac90e84ae6772983ceaf7a67e128ff7e0e174843fcb892728b9be4653cf
2026-05-28 11:57:39 -07:00
MarcoFalke
fa787043f5 doc: Compress doc/build-unix.md dependency package names into table 2026-05-28 20:45:09 +02:00
merge-script
f1344e6c7f Merge bitcoin/bitcoin#35378: ci: switch to warp runners
4bdd46ace3 ci: switch runners from cirrus to warpbuild (will)

Pull request description:

  As cirrus is closing down, switch to warpbuild runners.

  Switch runner and provider names over. We now use GHA cache, so we don't need to switch that over here.

ACKs for top commit:
  m3dwards:
    ACK 4bdd46ace3
  maflcko:
    review ACK 4bdd46ace3  🤾
  hebasto:
    ACK 4bdd46ace3.

Tree-SHA512: 47ed28a6cb7ab10a973af6aa24f4f7a632f59ed17e189ae4f658de37069d763c92cc0e32769693568db6d0e5d2543abcb77bb0977f0b3f296d80a254d6bb3833
2026-05-28 17:10:21 +01:00
merge-script
d12d8e52d2 Merge bitcoin/bitcoin#35400: doc: Remove good_first_issue.yml, Reword "Getting started" section
fa51f37f18 doc: Reword the Getting-Started section (MarcoFalke)
fab5733f5d doc: Remove good_first_issue.yml (MarcoFalke)

Pull request description:

  Fixes https://github.com/bitcoin/bitcoin/issues/35399

  IIUC, the good-first-issue label and template were meant to make it easier for completely new contributors to get started with something simple. However, I don't think the label and issue template are applicable anymore:

  * There are currently no issues with this label, and directing people toward an empty list seems pointless.
  * Historically the issue and label has been used rarely. 2026: once, 2025 twice, 2024 thrice. Source: https://github.com/bitcoin/bitcoin/issues?q=state%3Aclosed%20is%3Aissue%20label%3A%22good%20first%20issue%22
  * The template has been mis-used, according to https://github.com/bitcoin/bitcoin/issues/35399

  Fix all issues by removing it, since it is clear that it is no longer actively used, nor applicable and possibly a net-negative overall.

  Of course, regular devs are still free to open issues of this kind as a normal issue, if they wish. However, having the template for this in this repo and tracking it via a label doesn't seem useful.

  Since removing the template and label requires rewriting the "Getting Started" section in  `CONTRIBUTING.md`, I went ahead and also removed the mention of `Up for grabs` as good things for newcomers to work on. I don't recall the last new contributor that picked something up successfully. Also, `Up for grabs` is usually stuff that people lost interest in, or is no longer relevant.

  Instead I've added a sentence to encourage new contributors to help with critical and broad review, which will naturally guide them to good first follow-up issues to work on.

  Meta: I know this topic can be subjective and offer bike-shed potential, but I am happy to iterate a bit on this for a few days.

ACKs for top commit:
  stickies-v:
    ACK fa51f37f18
  danielabrozzoni:
    ACK fa51f37f18
  sedited:
    ACK fa51f37f18
  darosior:
    ACK fa51f37f18
  furszy:
    ACK fa51f37f18
  winterrdog:
    ACK fa51f37f18

Tree-SHA512: 9e6d7fe86262bee2df1e0af33ecfb5f77036da2d5d1832bb6afb08f4107d9313eec06d8b769966bf8ecaf8a4c574da5ff99509cc4b7fd9c53ea86788da29721c
2026-05-28 16:12:55 +01:00
furszy
b86c1c443d test: add coverage for migrating ancient wallets
Pre-#152 wallets have no best block stored. Test we
can migrate them.
2026-05-28 09:55:15 -04:00
furszy
fd44d48b24 wallet: fix ancient wallets migration
The best block locator was introduced in #152, previously created
wallets do not have these record.
2026-05-28 09:55:15 -04:00
merge-script
a34dbc836c Merge bitcoin/bitcoin#35313: Bump leveldb subtree
a9ac680af3 build: remove FALLTHROUGH_INTENDED from leveldb.cmake (fanquake)
4d58c3271c build: remove -Wno-conditional-uninitialized from leveldb build (fanquake)
58cdb5c2e8 Squashed 'src/leveldb/' changes from ab6c84e6f3..a7f9bdc611 (fanquake)

Pull request description:

  Includes:
  * https://github.com/bitcoin-core/leveldb-subtree/pull/52
  * https://github.com/bitcoin-core/leveldb-subtree/pull/53
  * https://github.com/bitcoin-core/leveldb-subtree/pull/55
  * https://github.com/bitcoin-core/leveldb-subtree/pull/59
  * https://github.com/bitcoin-core/leveldb-subtree/pull/60
  * https://github.com/bitcoin-core/leveldb-subtree/pull/61

ACKs for top commit:
  hebasto:
    ACK a9ac680af3.
  sedited:
    ACK a9ac680af3
  andrewtoth:
    ACK a9ac680af3

Tree-SHA512: dc80a0e5eabd63866b395681935ba47bd3f67292049f2cce77f6bcf9cdd6f3bb9bcf2d87ae836a7af5b3f07fe21a1885697cbae3eb930900e396c2588910e12a
2026-05-28 14:05:10 +01:00
Ryan Ofsky
896eaacd91 Merge bitcoin/bitcoin#34644: mining: add submitBlock to IPC Mining interface
3962138cc0 test: add IPC submitBlock functional test (woltx)
5b60f69e40 mining: add submitBlock IPC method to Mining interface (woltx)
813b4a80d7 refactor: introduce SubmitBlock helper (w0xlt)

Pull request description:

  This PR adds a `submitBlock` method to the IPC Mining interface, equivalent to the `submitblock` RPC. It accepts a serialized block over IPC, validates/processes it via the normal block-processing path.

  The method uses the same result shape as `checkBlock`: `bool` + `reason/debug out-params`. It reports duplicate, inconclusive, and invalid-block rejection details, and initializes reason/debug on every call.

  Closes #34626

ACKs for top commit:
  Sjors:
    ACK 3962138cc0
  optout21:
    reACK 3962138cc0
  ryanofsky:
    Code review ACK 3962138cc0. Just rebased since and made suggested changes since last review.

Tree-SHA512: 705cbb89972a80b6ff0ab75a78f686983d6077c97f1758795efe5b8968f01065ebef664ac850eae2bc86af8964efa2a68e8dfc677209c312856650f9387ed006
2026-05-28 08:02:24 -04:00
MarcoFalke
fa51f37f18 doc: Reword the Getting-Started section
Explain how to find good first issues to work on.

Also, remove the mention of up-for-grabs for new contributors, because
up-for-grabs is usually stuff that people lost interest in and is often
no longer relevant.
2026-05-28 13:32:05 +02:00
Hennadii Stepanov
53388773af guix: Remove redundant ShellCheck source directives 2026-05-28 12:26:48 +01:00
Hennadii Stepanov
62cf7bc53f guix, refactor: Add BASE argument to *_for_host functions 2026-05-28 12:21:37 +01:00
Hennadii Stepanov
5d46429e32 guix, refactor: Move distsrc_for_host() to prelude.bash
The `distsrc_for_host()` function now accepts a second optional
argument, `SUFFIX`, making it consistent with other similar functions.
2026-05-28 12:17:55 +01:00
Hennadii Stepanov
cab65ea9c6 guix, refactor: Move duplicated profiledir_for_host() to prelude.bash 2026-05-28 12:17:19 +01:00