Commit Graph

50204 Commits

Author SHA1 Message Date
MarcoFalke
fa0fe212f5 test: [refactor] Properly use BOOST_CHECK_EXCEPTION 2026-08-19 21:35:47 +02:00
merge-script
b88bffe550 Merge bitcoin/bitcoin#36010: test: Print os exit code on failure
fada80192b test: Print os exit code on failure (MarcoFalke)

Pull request description:

  Printing the exit code (like printing the stderr) seems independently useful, but should also help to debug the Windows CI failures, which have an empty stderr and truncated combined log:

  * https://github.com/bitcoin/bitcoin/issues/34925
  * https://github.com/bitcoin/bitcoin/issues/34367
  * ...

ACKs for top commit:
  sedited:
    tACK fada80192b

Tree-SHA512: 085201532ccce9da27cf996136d48436b7800b00a8c8011977d37fcfe152ca029e093428b06ba058759ae10f6dd8e94500b34df712f13d6064f6a7499539bcdc
2026-08-18 18:19:36 +02:00
merge-script
0fd515bbb7 Merge bitcoin/bitcoin#36009: miniscript: remove unused context argument from ParseHexStr
1fdd208c1c miniscript: remove unused context argument from ParseHexStr (fanquake)

Pull request description:

  Remove unused code.

ACKs for top commit:
  stickies-v:
    ACK 1fdd208c1c
  sedited:
    ACK 1fdd208c1c

Tree-SHA512: ae7c87209ec373bb0bebe243c2d31301572c62a4c18bd08580aa2b8eee87906c521b42096a59e6951a1eb3acb42179505dc063bc7b560b9d9c8963dc3e2e4954
2026-08-18 18:06:45 +02:00
merge-script
15a7a4ed7c Merge bitcoin/bitcoin#35952: kernel: prevent dangling iterators from temporary ranges
fc0dcf950f kernel: keep range iterators tied to their owner (Lőrinc)
0936c55f62 test: characterize kernel range iterators (Lőrinc)

Pull request description:

  **Problem:** Kernel wrapper methods return `Range` views by value, but their iterators point to the `Range` object.
  Saving an iterator from a temporary view, such as `block.Transactions().begin()`, leaves it pointing to the destroyed view, so later use has undefined behavior.

  **Fix:** Make range iterators point to the underlying Kernel wrapper object and use the range's compile-time getter for element access.
  Remove `operator->`, which returned elements by value and could not easily support arrow expressions.

ACKs for top commit:
  purpleKarrot:
    ACK fc0dcf950f
  yuvicc:
    ACK fc0dcf950f
  sedited:
    ACK fc0dcf950f

Tree-SHA512: 85ae1f8d4c62a762a10c546ebb312f126efc5ef349557dd235c81b585bef92cbb6c4a565734d85d315641a169f48b6032b859f5a9f070bc347b1424b05473e5d
2026-08-18 15:25:33 +02:00
merge-script
ac6b6c1f06 Merge bitcoin/bitcoin#35680: private broadcast: bound rebroadcast attempts to 1,000
fe7d475d45 private broadcast: bound broadcast attempts per tx to 1k (Gregory Sanders)

Pull request description:

  Since rebroacasts introduce additional state, bound the state growth by capping the number of rebroadcasts. With ~72 bytes per record, 10k transactions rebroadcasting for ~42 hours will result about 703 MiB allocated with overhead.

ACKs for top commit:
  andrewtoth:
    ACK fe7d475d45
  frankomosh:
    ReACK fe7d475d45
  sedited:
    ACK fe7d475d45

Tree-SHA512: e4ec5156b90ad24d68b561df03ad09bdf0ac7535886ff56891cb698cf64ff0e1e484075b76040bba6194baf874c9237028c82debf7405136447ba5b5faee589c
2026-08-18 14:57:12 +02:00
Hennadii Stepanov
d411bb02ff Merge bitcoin/bitcoin#35993: guix: build glibc with --enable-kernel=3.17.0
5548818115 guix: build glibc with --enable-kernel=3.17.0 (fanquake)

Pull request description:

  Our minimum required kernel version is documented as `3.17.0`. Pass `--enable-kernel=3.17.0` when building glibc, so that version is reflected in the binary, and the version checked in the symbol-check script, aligns with the expected minimum.

ACKs for top commit:
  hebasto:
    ACK 5548818115, tested on Ubuntu 24.04:
  willcl-ark:
    ACK 5548818115

Tree-SHA512: fc23561d77da80f53cf7564bdb87f5f3c0b23401de79e0801168190d7a99c96e6a60e9437779680b43173572aededf4242b0fba0fe255970f83e6529e3149870
2026-08-18 13:47:58 +01:00
MarcoFalke
fada80192b test: Print os exit code on failure 2026-08-18 14:13:59 +02:00
merge-script
381c331219 Merge bitcoin/bitcoin#36007: http: Make HTTPRequest::m_client a weak_ptr
979a42ec17 http: Make HTTPRequest::m_client a weak_ptr (Hodlinator)

Pull request description:

  Removes the need for `HTTPClient::ReleaseRequest()` as the client<->request cycle is broken. Not having to remember to call `ReleaseRequest()` reduces cognitive load.

  Follow-up to #35735.

ACKs for top commit:
  pinheadmz:
    untested ACK 979a42ec17

Tree-SHA512: b740a765ffe0592055819e71df8654614e9e140bb77e4a6d146045255f1db9b470ae4a1a77aa16a0d3f3519b7c0d1e9f8c9fbc4c29aab28a2d55ea828ca912c6
2026-08-18 13:12:57 +01:00
merge-script
82b3bfe38c Merge bitcoin/bitcoin#35797: psbt: support output metadata updates before inputs are added
c079288967 psbt: update output metadata without inputs (Lőrinc)
4f5712476a test: characterize P2WSH miniscript output (Lőrinc)
e24e8fa2a6 test: characterize PSBT output metadata (Lőrinc)

Pull request description:

  **Problem:** PSBTv2 permits outputs to be added before inputs.
  An authenticated `descriptorprocesspsbt` request can abort the node while updating metadata for one of those outputs because `UpdatePSBTOutput()` traverses the output script with a signature creator for input index 0.
  ECDSA signing or a miniscript timelock check can then access the missing input.

  **Fix:** Make `UpdatePSBTOutput()` traverse output scripts with a temporary one-input transaction while continuing to take the output from the PSBT's unsigned transaction.
  `MutableTransactionSignatureCreator` continues to require a valid input index.
  Output metadata traversal still records scripts and key origins, allowing outputs to be updated before inputs are added.

ACKs for top commit:
  jeanpablojp:
    tACK c079288967
  achow101:
    ACK c079288967
  w0xlt:
    ACK c079288967
  polespinasa:
    ACK c079288967

Tree-SHA512: 0d8cda74b8a56c0f4713b2669e5a3e5b0551ecda4fdfceb38a80e5b98a9d208d447f2045a1cc9fee74fe33b2fc8f7a60997cd60b2961de5cea871f53831895fe
2026-08-18 13:05:56 +01:00
merge-script
681b429393 Merge bitcoin/bitcoin#35986: p2p: reconsider orphans when missing inputs are mined
9cc7dc50bd p2p: reconsider orphans when missing inputs are mined (Greg Sanders)

Pull request description:

  We reconsider for mempool entry of missing inputs, we should reconsider for mining of them too.

ACKs for top commit:
  yuvicc:
    ACK 9cc7dc50bd
  l0rinc:
    Lightly tested code review ACK 9cc7dc50bd
  marcofleon:
    ACK 9cc7dc50bd

Tree-SHA512: 9acfb6898e3b286ce23bc2ca3369ae951fadee5f175baad634a6bd23039108d97283814e47972fb857ae459505535f621866f2514b705e94cf841979c37a3933
2026-08-18 11:48:20 +01:00
merge-script
16f4bd15bc Merge bitcoin/bitcoin#35954: qa: Disable Qt's glib event dispatcher for GUI tests on OpenBSD
de2adc308a qa: Disable Qt's glib event dispatcher for GUI tests on OpenBSD (Hennadii Stepanov)

Pull request description:

  When `bitcoin-gui` is built against OpenBSD's system Qt packages (which have GLib support), shutdown emits "GLib-CRITICAL **: g_main_context_pop_thread_default: assertion 'stack != NULL' failed" messages on `stderr`, which the test framework treats as a failure.

  Set `QT_NO_GLIB=1` so Qt falls back to its poll-based event dispatcher, which avoids the GLib thread-default context entirely.

  Fixes https://github.com/bitcoin/bitcoin/issues/35851.

  See the CI log here: https://github.com/hebasto/bitcoin-core-nightly/actions/runs/31510478034.

ACKs for top commit:
  maflcko:
    lgtm ACK de2adc308a

Tree-SHA512: edc991c7a174bc304a4da0ca29ec97bcaece463289de3da5350a046f1133ce6d830c37d5188536ca2ce238d462e56de8f2167fdeeb1d1e5ecca38d60c8495cce
2026-08-18 11:07:29 +01:00
fanquake
1fdd208c1c miniscript: remove unused context argument from ParseHexStr 2026-08-18 10:09:23 +01:00
merge-script
4ca07c2fb3 Merge bitcoin/bitcoin#35963: doc : update cjdns docs to discourage using onlynet option
beefda21be doc : update cjdns docs to discourage using onlynet option (naiyoma)

Pull request description:

  Currently, the number of CJDNS addresses is still very small and may not be sufficient to fill all outbound connection slots. When running with the `-cjdnsonly` and `-cjdnsreachable` options, `ThreadOpenConnections()` repeatedly calls `Select()`, which returns the same few addresses over and over. The connection attempts may fail, the addresses remain in `AddrMan`, and the loop continually restarts.

  The documentation does mention running CJDNS alongside other networks, but we should explicitly explain why using only CJDNS is discouraged, since running with these options alone is supported.

ACKs for top commit:
  achow101:
    ACK beefda21be
  jonatack:
    ACK beefda21be
  hodlinator:
    ACK beefda21be
  brunoerg:
    ACK beefda21be

Tree-SHA512: 46126291ceb1c36384f9b3deaccdcf20baf8cd4a68491d2ad9fc4a35ec71ad4194b38c4a22c9853bd3f329e2ecb9a0452813d1eea121eb3712876e73dfd4b3f0
2026-08-18 10:08:37 +01:00
merge-script
4b4ae6e37c Merge bitcoin/bitcoin#35995: doc: fix outdated URL in hash_tests.cpp
158efbc723 doc: fix outdated URL in hash_tests.cpp (cyb3ralbert)

Pull request description:

  The old URL still 301-redirects, but to the site root, not to the file — and the file itself is gone: the same path on the new domain returns 404. The author's page at https://www.aumasson.jp/siphash/ says that the SipHash page and documentation have moved to github.com/veorq/SipHash.

  The vectors now live in vectors.h in that repository. All 64 values match the array below.

ACKs for top commit:
  maflcko:
    lgtm ACK 158efbc723
  l0rinc:
    tested ACK 158efbc723

Tree-SHA512: e45d6872787474e50d51f408ae496e816adbaa8ff263f34df6af7070cfc94bc4f289c5d43cf79461055a0e9738340eb3088837e42991640a253853a5c9984ec6
2026-08-18 10:07:18 +01:00
merge-script
a23df4bfa8 Merge bitcoin/bitcoin#35946: rpc: Improve some type specs for openrpc
e07d826e0e rpc: Fix type in ApplyTypeStrOverride (Shuvam Pandey)
c94074fa1b rpc: Surface OBJ_USER_KEYS description for openrpc (sedited)
c020c21d54 rpc: Handle skip type args for openrpc (sedited)

Pull request description:

  This was initially motivated by testing the dump of the schema against open-rpc-generator, which crashed with:

  ```
  open-rpc-generator generate -t client -l rust -n bitcoin_client -d ./openrpc.gen.json -o ./generated
  There was error at generator runtime:
  TypeError: Cannot convert undefined or null to object
  ```

  The changes here fix this crash (albeit perfectly valid existing schema), but I think creating a more complete output is helpful on its own. The openrpc schema dumps can eventually be re-used for the rpc docs and to track rpc interface changes more accurately. Adding the CreateTxDoc outputs section seems useful for that.

  Also includes a type tightening from number to integer in `ApplyTypeStrOverride` to reflect the actual behaviour in the rpc calls, where only integers are accepted.

ACKs for top commit:
  achow101:
    ACK e07d826e0e
  willcl-ark:
    ACK e07d826e0e

Tree-SHA512: d0454a71b4f1dab1daf8a0d5b1e5bf1c1b8f1a16d26638d4a64a2652402ad74230366cabf0cf4135a16d0bdab584d3d4b2a47f2968a4eff605348ce85e8dbadb
2026-08-18 09:59:26 +01:00
merge-script
20ad7c9eab Merge bitcoin/bitcoin#35955: wallet: remove orphaned GetAffectedKeys and LegacyScriptPubKeyMan declarations
02de12b1e6 wallet: remove remaining LegacyScriptPubKeyMan references (Laxman Acharya)
d194be69d6 wallet: remove orphaned GetAffectedKeys declaration (Laxman Acharya)

Pull request description:

  Follow-up to #28710, which removed `GetAffectedKeys()` and `LegacyScriptPubKeyMan` but left their declarations behind.

  Remove both orphaned declarations, rename `SetupLegacyScriptPubKeyMan()` to `SetupLegacyDataSPKM()`, and update related comments and logging to reflect the minimal `LegacyDataSPKM` retained for legacy wallet loading and migration.

  ## Testing

  ```bash
  cmake --build build --target bitcoin_wallet -j 8
  cmake --build build --target test_bitcoin -j 8
  build/bin/test_bitcoin --run_test=scriptpubkeyman_tests,walletdb_tests,wallet_tests --catch_system_errors=no --log_level=error
  ```

ACKs for top commit:
  achow101:
    ACK 02de12b1e6
  polespinasa:
    ACK 02de12b1e6

Tree-SHA512: 0d340291c969f013fd6ec55158f6797d4a1478ff7a819c2d250d1b3f345131db99a8b7b4b3ff0da1fa0e06182701abed31dcd317f8ef12c81837c1aed57b21a5
2026-08-18 09:45:34 +01:00
Hodlinator
979a42ec17 http: Make HTTPRequest::m_client a weak_ptr
This removes the need for HTTPClient::ReleaseRequest() as the client<->request cycle is broken. Not having to remember to call ReleaseRequest() reduces cognitive load.
2026-08-18 09:59:39 +02:00
cyb3ralbert
158efbc723 doc: fix outdated URL in hash_tests.cpp 2026-08-17 17:22:38 +03:00
fanquake
5548818115 guix: build glibc with --enable-kernel=3.17.0 2026-08-17 12:29:15 +01:00
merge-script
f72537037d Merge bitcoin/bitcoin#35972: fuzz: Fix assertion in txorphan
01dde6b205 fuzz: Fix assertion in txorphan (marcofleon)

Pull request description:

  `EraseTx()` calls `LimitOrphans()`, which may evict announcements from a peer that didn't announce the erased transaction, causing that peer's usage to decrease. Relax the assertion in the `EraseTx()` branch that claimed usage of a non-announcer peer should be unchanged. Also, add assertions for the other cases.

ACKs for top commit:
  dergoegge:
    utACK 01dde6b205
  instagibbs:
    ACK 01dde6b205

Tree-SHA512: 2e597b85fd41058c2fa79fa55f0d37e12505065b5e27aba7b9680e0c249a5450e6fa97b45394d6ffe1318f42538134ffa9c423b126c455f6f8e6d8ca59eed4b6
2026-08-17 12:04:02 +01:00
merge-script
4800cb7aea Merge bitcoin/bitcoin#35735: Add state to HTTPRequest
9954aa7728 http: don't parse any new requests from a client if m_req_busy = true (Matthew Zipkin)
c7db3ae1f9 test: cover HTTPRequest state machine (Matthew Zipkin)
90676e24ad Add state to HTTPRequest to avoid duplicate work over I/O cycles (Matthew Zipkin)
507e528e84 http: reuse HTTPHeaders to parse chunked trailer (Matthew Zipkin)
902d8908c9 http: only read one HTTPRequest at a time per client (Matthew Zipkin)

Pull request description:

  This PR reduces the memory consumption of the HTTP Server when reading data from connected clients, and improves performance especially when requests are large (i.e. requiring multiple TCP packets).

  In https://github.com/bitcoin/bitcoin/pull/35182 the server copies as much data as it can from the socket into application memory, and then tries to parse as many complete HTTP requests as possible from that data. If a request is discovered to be incomplete, the in-progress request is abandoned. The server tries again on the next I/O cycle to read the same data from the buffer, duplicating work as many times as it takes before the client finishes sending the request (or times out).

  This PR implements two improvements to this:
  1. Only parse one request at a time from the receive buffer. The server processes requests from each client in series anyway.
  2. Add state to `HTTPRequest` so it can be filled with data from the receive buffer over multiple I/O loop iterations without losing progress.

  If a client sends large or multiple requests, that data will sit in the kernel's socket buffer instead of the application memory. Eventually the socket buffer will fill up and TCP backpressure will kick in, dropping the TCP window to 0 and blocking the client from sending any more.

  A state machine for `HTTPRemoteClient` was [discussed previously](https://github.com/bitcoin/bitcoin/pull/35182#pullrequestreview-4322490068) to control resource consumption. Another nice benefit of this model (for a follow-up PR) will be to insert the RPC authentication check after reading 8kB-limited headers but before the 32MB-limited request body.

ACKs for top commit:
  winterrdog:
    re-ACK 9954aa7728
  janb84:
    re ACK 9954aa7728
  frankomosh:
    ACK 9954aa7728.
  fjahr:
    ACK 9954aa7728

Tree-SHA512: b7c913114283fbf1f360b40f6c65a01390a26731bf3b166f460ec260f9206f25d738b3a06887bfa839911c1c6aaf634448181da47a752a9a881aebd907e44868
2026-08-17 10:19:34 +01:00
merge-script
e0992599a6 Merge bitcoin/bitcoin#35846: test: Use throwing config parser getters without fallback
fabe100c2b test: Use throwing config parser getters without fallback (MarcoFalke)
fa8acd57cd test: Write true/false values in config.ini (MarcoFalke)

Pull request description:

  Currently, the called `getboolean` member function is *not* the throwing https://docs.python.org/3/library/configparser.html#configparser.ConfigParser.getboolean, but a non-throwing member function on a dict-like proxy object.

  This is confusing and brittle, because tests shouldn't silently skip when a config key is missing. Instead, tests should loudly fail, e.g. when the config key is renamed in one place, but not the other.

ACKs for top commit:
  jeanpablojp:
    tACK fabe100c2b
  willcl-ark:
    ACK fabe100c2b

Tree-SHA512: a970d74ad285372b8adcce8e2a52b01f5a3b563899dfc5262e6ffbf3d8aba43e72f7b03111e8d5188924c7d3d789992407cddb5d182d9be5e42f07896d8ad4a3
2026-08-17 10:11:25 +01:00
merge-script
e5977f0b9e Merge bitcoin/bitcoin#35982: Update minisketch subtree to latest master
461e3be8d3 Squashed 'src/minisketch/' changes from d1bd01e189..4a179c61e3 (fanquake)

Pull request description:

  Includes:
  * https://github.com/bitcoin-core/minisketch/pull/102

ACKs for top commit:
  hebasto:
    ACK 2dcb2c6df2.

Tree-SHA512: 295e217cb6d32e8d0bb4ea84bd0d6682f98735029c659ad06a6c588fa2865176d80adfca32a1a3a339ffb601e5d1cc99c81266914225e27726a8a859fee3549e
2026-08-17 09:51:28 +01:00
merge-script
fe7dbde52c Merge bitcoin/bitcoin#35976: test: Speedup fee estimation functional test with batching
b3d77ea027 test: Speedup fee estimation functional test with batching (sedited)

Pull request description:

  The fee estimation functional test is currently the slowest one by a good margin. It is a bit annoying, because it also increases the total runtime of the functional tests.

  It seems like most of the slowness comes from the transactions propagating between the nodes. This patch helps them do that by submitting them directly to all the nodes. Also take this opportunity to batch the transaction submissions.

  On my machine this speeds up the fee estimation functional test from around 71 seconds to 25 seconds.

ACKs for top commit:
  151henry151:
    tACK b3d77ea027
  maflcko:
    review ACK b3d77ea027 🐇
  ismaelsadeeq:
    ACK  b3d77ea027

Tree-SHA512: f76415dca7997577ca39ac6b95dfdf32b930dd64b4311e3da34e34adb16107ff4ea2d9fa679f3ca50540e80c38af7f9390b44f21ad1b8107fbbc3586edb2ef19
2026-08-17 09:47:08 +01:00
Greg Sanders
9cc7dc50bd p2p: reconsider orphans when missing inputs are mined 2026-08-17 02:48:44 -04:00
merge-script
c90c23d388 Merge bitcoin/bitcoin#35531: txindex: hash keys and pack positions to reduce disk usage
25bed560be test: add forward-compat functional test for txindex (sedited)
703304ed8c doc: add release notes for txindex disk usage and downgrading (Andrew Toth)
8e5320a2d2 tests: cover txindex hash prefix collisions and legacy fallback (Andrew Toth)
b75efa19ba txindex: skip bloom filters and legacy lookups for new databases (Andrew Toth)
004d7c098c txindex: hash key prefixes and pack block positions (Andrew Toth)
5a255970fd refactor: move txindex db constants and legacy key to txindex_key.h (Andrew Toth)
327660134c txindex: pass the full block to DB::WriteTxs (Andrew Toth)
42771e7998 txindex: use a new block locator for downgrade safety (Andrew Toth)
4b08baed72 txindex: return optional tx and block hash from FindTx (Andrew Toth)

Pull request description:

  The current txindex uses the full 32-byte txid as keys, which takes up about 66 GB of disk space today on mainnet. Using a 5-byte key prefix instead drops the disk usage to 26 GB - cutting the size to less than half.

  Using the full 32-bytes is unnecessary since a 5-byte salted siphash will produce collisions in about 1 in 1.1 trillion. Some collisions will occur, but the penalty is just an extra disk read, deserialization and hash.
  The tx position can be appended to the key instead of used as a value, and a LevelDB iterator can seek to the prefix and then scan for the correct tx. This is an almost identical approach to `txospenderindex`.

  Also instead of storing the file position of the block, we can store only the sequence of the connected block and offset of the transaction in the block. This can be packed into a 6-byte key suffix using 3-byte representations of the sequence and offset in the block. The block file can be recovered by the CBlockIndex that is already in memory. The sequence is mapped to the block hash in the db, so we can lookup the block hash to find the CBlockIndex during reads.

  If a tx is not found with this method, we fallback to looking up the legacy entry. With this method a user with an existing db can opt to erase the `indexes/txindex` folder and reindex, or keep the current index and new entries will be appended with the smaller footprint.

  The time to index was faster on my machine with this method, 1h19m vs current 1h50m.
  Lookups are roughly the same, around 0.2ms per lookup with `getrawtransaction`.
  When testing on mainnet, I got 894,549 2-way collisions, 395 3-way collision, and 1 4-way collision that worst case could cause an extra 3 false positives when reading.

ACKs for top commit:
  l0rinc:
    diff reACK 25bed560be
  sedited:
    ACK 25bed560be
  ajtowns:
    ACK 25bed560be

Tree-SHA512: a25c79ca7e722e2f372b65f5fc11c8b194ad49f2240b4881c7e606306aabbd3604aede3f1c33606b467486affac3a3f503638f513c896935cebbc02709cb60d8
2026-08-15 15:20:47 +01:00
fanquake
2dcb2c6df2 Update minisketch subtree to latest master 2026-08-15 15:05:06 +01:00
fanquake
461e3be8d3 Squashed 'src/minisketch/' changes from d1bd01e189..4a179c61e3
4a179c61e3 Merge bitcoin-core/minisketch#102: Avoid Clang's `-Wunused-template` under restricted field selections
d14cd495ff Avoid Clang's `-Wunused-template` under restricted field selections

git-subtree-dir: src/minisketch
git-subtree-split: 4a179c61e3cbe3ac2b3c027764ce8eb5183155e1
2026-08-15 15:05:06 +01:00
Hennadii Stepanov
05c36d9fad Merge bitcoin-core/gui#957: fix: add .dat file extension automatically when exporting watchonly
75a4e6c678 gui: fix allow restore wallets without .dat file extension (Pol Espinasa)
6ed7e05e20 gui: fix add .dat file extension automatically when exporting watchonly (Pol Espinasa)

Pull request description:

  fixes https://github.com/bitcoin-core/gui/issues/956

  Unlike `backup wallet`, `export watch-only wallet` was not automatically adding the file extension to the exported file, making restoring difficult if the user doesn't manually add the file extension after exporting.

  Allows also to restore a wallet from a non specified `.dat` file extension. This is achieved by removing the filter in the select file screen, matching the RPC behavior.

ACKs for top commit:
  hebasto:
    ACK 75a4e6c678.

Tree-SHA512: 7c45d51205f9abf2b67233e8abd3297e49a4230eb32aa4118b37ab9da0a8d692aae4b67a8880881e5fab42256d1cf52ccf1b289b8f23f85930354130c192b33d
2026-08-15 11:39:53 +01:00
Pol Espinasa
75a4e6c678 gui: fix allow restore wallets without .dat file extension 2026-08-15 08:43:22 +02:00
Ava Chow
a8b582ec1d Merge bitcoin/bitcoin#32784: wallet: derivehdkey RPC to get xpub at arbitrary path
c3945bfd2b doc: use derivehdkey in multisig tutorial (Sjors Provoost)
3662e33669 test: use derivehdkey in M-of-N multisig demo (Sjors Provoost)
d9570f0838 rpc: add derivehdkey (Sjors Provoost)
62da9f9614 wallet: add GetExtKey helper (Sjors Provoost)
aaf1548475 wallet: generalize GetActiveHDPubKeys helper (Sjors Provoost)
3821452c4a refactor: add hardened derivation helper (Sjors Provoost)
0ab61caafd rpc: ParsePathBIP32 helper (Sjors Provoost)
e36c4b76e1 util: reject out-of-range BIP32 keypath indices (Sjors Provoost)
ba78c31a00 fuzz: check ParseHDKeypath/WriteHDKeypath round-trip (Sjors Provoost)
8cce969085 Have ParseHDKeypath handle h derivation marker (Sjors Provoost)
fc53077762 test: move parse_hd_keypath test to bip32_tests (Sjors Provoost)
dab525eb77 key: add DeriveExtKey() helper (Sjors Provoost)

Pull request description:

  Adds a `derivehdkey` RPC that returns an xpub, or optionally the xprv, at an arbitrary BIP32 path (with at least one hardened step), derived from a wallet HD key.

  The main use case is coordinating a multisig setup, where each participant shares an xpub derived at a hardened path (e.g. `m/87h/0h/0h`) distinct from their default single-signature descriptors. See the (updated) `doc/multisig-tutorial.md` and (updated) functional test to see how that workflow improves.

  The first commits are some helpful helpers:

  - _key: add DeriveExtKey() helper_ - performs the actual derivation
  - _test: move parse_hd_keypath test to bip32_tests_ - from `psbt_wallet_tests`
  - _Have ParseHDKeypath handle h derivation marker_
  - _util: reject out-of-range BIP32 keypath indices_ -  `ParseHDKeypath` would previously map overflowing values without `h` to hardened.
  - _fuzz: check ParseHDKeypath/WriteHDKeypath round-trip_
  - _rpc: ParsePathBIP32 helper_
  - _refactor: add hardened derivation helper_ - `HasHardenedDerivation()`, to enforce the "at least one hardened step" rule
  - _wallet: generalize GetActiveHDPubKeys helper_ - extracts code from `gethdkeys` which `derivehdkey` needs
  - _wallet: add GetExtKey helper_ - reconstruct an xprv from a wallet xpub (analog of `GetKey()`); behavior-preserving prep, also simplifies `gethdkeys`.

  Meat and potatoes:
  - _rpc: add derivehdkey_ - the RPC itself, plus the `UnusedKey` filter on `GetHDPubKeys` that drives key selection.
  - _test: use derivehdkey in M-of-N multisig demo_ - rewrites the functional multisig test to use the RPC and `<0;1>` syntax.
  - _doc: use derivehdkey in multisig tutorial_ - same for the prose tutorial.

ACKs for top commit:
  pseudoramdom:
    code review ACK c3945bfd2b
  achow101:
    ACK c3945bfd2b
  w0xlt:
    That being the case, ACK c3945bfd2b

Tree-SHA512: 661f17c9bfe26017eb14c27ba7af37093387100d3baa25f5d29bba9c1aedc40d19afe1bdfc126a18d018857bb02f1fc84386f10b8f4f4b8e9d6f4b0691d9e302
2026-08-14 18:11:26 -07:00
Gregory Sanders
fe7d475d45 private broadcast: bound broadcast attempts per tx to 1k
Rather than rebroadcasting forever, bound attempts at
private broadcast, report remaining attempts over RPC
results, and allow exhausted transactions to be
retried when submitted.
2026-08-14 17:09:29 -04:00
sedited
b3d77ea027 test: Speedup fee estimation functional test with batching 2026-08-14 22:50:01 +02:00
merge-script
683e05a265 Merge bitcoin/bitcoin#35889: rpc: avoid quadratic gettxspendingprevout work and preserve order
ae36e2ef79 rpc: avoid quadratic prevout resolution (Lőrinc)
da1eaeb350 rpc: preserve `gettxspendingprevout` order (Lőrinc)
f98753e762 refactor: identify prevouts by request index (Lőrinc)
221a3fe5cf test: cover mixed `gettxspendingprevout` order (Lőrinc)

Pull request description:

  **Problem:** `gettxspendingprevout` erases each mempool result from a vector while holding `mempool.cs`, shifting the remaining requests every time and making large calls quadratic in the critical section.
  For 10,000 mempool matches, an [operation-count model](https://godbolt.org/z/nzch7McPG) reaches nearly 50 million moves.
  For mixed requests, the RPC returns mempool results before `txospenderindex` results instead of following request order.
  #34749 introduced both regressions.

  **Fix:** `gettxspendingprevout` stores each result at its request position and collects unresolved requests in a reserved worklist for the `txospenderindex` lookup.
  The mempool pass is linear, the response follows request order, and Clang can verify the lock requirement on `GetConflictTx`.

  **Benchmark:** The [functional benchmark](https://gist.github.com/l0rinc/c3231e287cacfdefd100dbf95cd0c3ad) sends mempool-only requests ranging from 8,000 to 128,000 entries ten times per size.
  Using the same settings for the unfixed and fixed commits:

  ```text
  AMD Ryzen 7 3700X (8 cores)
  unfixed  ██████████████████████████████  90 s
  fixed    ███▒░░░░░░░░░░░░░░░░░░░░░░░░░░  10 s  (-80 s, 9.0x faster)

  Raspberry Pi 5 (4 cores)
  unfixed  ██████████████████████████████  685 s
  fixed    ▓░░░░░░░░░░░░░░░░░░░░░░░░░░░░░  22 s  (-663 s, 31.1x faster)
  ```

  The unfixed run timed out after ~9 minutes on a Raspberry Pi 4 with 1 GB RAM.

  <details><summary>Benchmark command</summary>

  ```bash
  for commit in 963b061358 46e7173550a93cbe9d4e8ea28cfe7216286d8197; do \
    git fetch origin "$commit" && git checkout --detach "$commit" && \
    rm -rfd build && cmake -B build -G Ninja -DCMAKE_BUILD_TYPE=Release -DBUILD_TESTS=OFF -DENABLE_WALLET=OFF >/dev/null 2>&1 && \
    ninja -C build -j1 bitcoind >/dev/null 2>&1 && \
    build/test/functional/test_runner.py rpc_gettxspendingprevout_quadratic.py --repeats=10 || break; \
  done
  ```
  </details>

ACKs for top commit:
  andrewtoth:
    ACK ae36e2ef79
  sedited:
    Re-ACK ae36e2ef79

Tree-SHA512: c7734cae481f6638228c8fd3cc6d4c3fbc26cec6981dae7902292af08eae37455d37ff196da2cca5c3694271c99154838431ff21c12855f81f5f10edf85a793a
2026-08-14 22:01:12 +02:00
merge-script
230185a5ee Merge bitcoin/bitcoin#35971: net_processing: remove unused code
0cff3cc518 net_processing: Remove redundant porphanTx in ProcessOrphanTx (fanquake)
c7eacbd45b net_processing: remove Peer& from UpdatePeerStateForReceivedHeaders (fanquake)

Pull request description:

  Remove unused `peer` param from `UpdatePeerStateForReceivedHeaders`.
  Remove redundant `porphanTx` declaration from `ProcessOrphanTx`.

ACKs for top commit:
  marcofleon:
    ACK 0cff3cc518
  sedited:
    ACK 0cff3cc518

Tree-SHA512: d71684052f9f6c788b4d551886e7f6022d76300e9288089eea5fd0c87f9466dbcff88c9004899a399c669477988437e935aad06960cec721c650b66508c7a16a
2026-08-14 21:49:44 +02:00
Lőrinc
ae36e2ef79 rpc: avoid quadratic prevout resolution
`gettxspendingprevout` erases each mempool result from its worklist while holding `mempool.cs`, shifting the remaining requests every time and making the pass quadratic when it resolves many requests.
Collect unresolved requests in a reserved worklist so the mempool pass is linear and the compiler can verify the lock requirement on `GetConflictTx`.

Co-authored-by: Andrew Toth <andrewstoth@gmail.com>
2026-08-14 11:29:28 -07:00
Lőrinc
da1eaeb350 rpc: preserve gettxspendingprevout order
Store each `gettxspendingprevout` result at its request position so mixed mempool and `txospenderindex` results preserve request order.
2026-08-14 11:26:32 -07:00
Lőrinc
f98753e762 refactor: identify prevouts by request index
Replace `Entry`'s pointer into `output_params` with the request index, which identifies both the input and its response slot.
2026-08-14 11:26:32 -07:00
Lőrinc
221a3fe5cf test: cover mixed gettxspendingprevout order
Record that `gettxspendingprevout` currently returns mempool results before `txospenderindex` results for mixed requests.
2026-08-14 11:26:28 -07:00
Laxman Acharya
02de12b1e6 wallet: remove remaining LegacyScriptPubKeyMan references
`LegacyScriptPubKeyMan` was removed in 83af1a3cca. Remove the orphaned
forward declaration in `wallet/rpc/util.h`, rename
`CWallet::SetupLegacyScriptPubKeyMan()` to `SetupLegacyDataSPKM()`, and
update the comments and inactive-HD-chain log message that still use
the deleted class name.

Co-authored-by: shuv-amp <i@shuvamp.com.np>
2026-08-14 23:44:16 +05:45
Laxman Acharya
d194be69d6 wallet: remove orphaned GetAffectedKeys declaration
The definition of GetAffectedKeys() and its only caller were removed in
83af1a3cca ("wallet: Delete LegacySPKM"), but the declaration in
scriptpubkeyman.h was left behind. The symbol has had no definition and
no callers since then, so drop the leftover declaration.
2026-08-14 23:43:57 +05:45
marcofleon
01dde6b205 fuzz: Fix assertion in txorphan
EraseTx calls LimitOrphans, which may evict announcements from a peer
that didn't announce the erased transaction, causing that peer's usage
to decrease. Relax the assertion in the EraseTx branch that claimed
usage of a non-announcer peer is unchanged. Also, add assertions for
the other cases.
2026-08-14 18:18:07 +01:00
merge-script
dec68f997e Merge bitcoin/bitcoin#35852: scripted-diff: Use inline const(expr) over static constexpr in headers
fab74a0e92 refactor: Use C++14 digit separator for large int literals (MarcoFalke)
fae759be79 scripted-diff: Use inline constexpr over plain constexpr (MarcoFalke)
fa74f58a26 scripted-diff: Use inline const over (static) const (MarcoFalke)
fab1a62c87 refactor: Use inline constexpr for string literals in headers (MarcoFalke)
fa08bbed8d contrib: Adjust generate-seeds.py to write inline constexpr (MarcoFalke)
fad753611b scripted-diff: Use inline constexpr over (static) const (MarcoFalke)
faedb52583 refactor: Make CFeeRate(integral) ctor constexpr (MarcoFalke)
5555d5dcb5 scripted-diff: Use inline constexpr over static constexpr (MarcoFalke)
fa6e1a1e85 refactor: Remove static from constexpr functions in headers (MarcoFalke)

Pull request description:

  Both are fine and this refactor doesn't change any behavior.

  However, `inline constexpr` from C++17 will ensure each symbol has a single address
  across all TU, making the release binary minimally smaller. (For me it is smaller by about 1kB)

ACKs for top commit:
  l0rinc:
    reACK fab74a0e92
  rustaceanrob:
    ACK fab74a0e92
  hebasto:
    ACK fab74a0e92, I have reviewed the code and it looks OK.

Tree-SHA512: 6ec94136c12bcbf696812d0661c9857318a69e367c79fc00b9ca0b4068f269d10e5548d95c9ba2070225308c12d7a54fe8cb8447de7e0979cba99f48892b35f9
2026-08-14 17:29:46 +01:00
merge-script
e95bab98f0 Merge bitcoin/bitcoin#35960: common: remove ::runtime_error from RunCommandParseJSON
8b5da677d7 common: remove ::runtime_error from RunCommandParseJSON (fanquake)

Pull request description:

  I don't think there's a code path that can reach `RunCommandParseJSON` if we compile with `ENABLE_EXTERNAL_SIGNER=OFF`. If there is a reason for having the code this way, it could  be good to document.

  This also requires more workarounds in #35911.

ACKs for top commit:
  stickies-v:
    re-ACK 8b5da677d7
  sedited:
    ACK 8b5da677d7
  willcl-ark:
    ACK 8b5da677d7

Tree-SHA512: b0c50372fed35afe47713310851f0b58cd1803fbe87a3a5a75877772172a3881283394a91663251de22a9972f56b46d84ddc868686dec8b970474cfaf5dc0d32
2026-08-14 16:20:34 +01:00
merge-script
aad830ac4a Merge bitcoin/bitcoin#35847: test: move more tests to baseindex_tests and run them for all indexes
34c03075a5 test: run generic baseindex tests against every index type (Martin Zumsande)
11b3e251c4 test: make baseindex flush test chain-length agnostic (Martin Zumsande)
8b959f4c6a test: move unclean_shutdown test to baseindex_tests (Martin Zumsande)
2232d6afbe test: move index_reorg_crash to baseindex_tests (Martin Zumsande)
a3597e2683 test: move BuildChain helper into test mining util (Martin Zumsande)
954985e6a3 test: simplify blockfilter test's BuildChain helper (Martin Zumsande)

Pull request description:

  In #34897, the `baseindex_tests` unit test was introduced, meant for tests that test basic index functionality (e.g. reorg or unclean shutdown behavior) that should work regardless of the particular index type.
  This PR moves two more of these tests (`index_reorg_crash`, `coinstatsindex_unclean_shutdown`) from test files of specific indexes into that folder.
  In the second part, tests are executed sequentially for all index types instead of just one particular one, where applicable.

  Before moving `index_reorg_crash`  I extracted the `BuildChain` helper to `util/mining` so that it can be used by multiple tests. While doing that, I simplified the helper a bit.

ACKs for top commit:
  jeanpablojp:
    tACK 34c03075a5
  sedited:
    ACK 34c03075a5

Tree-SHA512: 1d7a43160a9b7ec3c75a8c806967f2031da4855fe449c9c8aac8e44b1940e5ee28fde9473406666e74a682cf135b87f8c0eb9ddba50fce156dce9fc54a7763eb
2026-08-14 16:13:57 +01:00
Shuvam Pandey
e07d826e0e rpc: Fix type in ApplyTypeStrOverride
This should be an integer, not a numeric, as already enforced by the RPC
code and described in the mapping just above the changed line.
2026-08-14 16:30:24 +02:00
fanquake
0cff3cc518 net_processing: Remove redundant porphanTx in ProcessOrphanTx 2026-08-14 14:05:42 +01:00
fanquake
c7eacbd45b net_processing: remove Peer& from UpdatePeerStateForReceivedHeaders 2026-08-14 11:52:59 +01:00
fanquake
8b5da677d7 common: remove ::runtime_error from RunCommandParseJSON
I don't think there's a code path that can reach RunCommandParseJSON if
we compile with `-DENABLE_EXTERNAL_SIGNER=OFF`. This also requires more
workarounds in #35911.

Co-authored-by: stickies-v <stickies-v@protonmail.com>
2026-08-14 10:39:20 +01:00
sedited
25bed560be test: add forward-compat functional test for txindex 2026-08-13 23:31:36 -04:00