Bitcoin Core 32.99.0
P2P Digital Currency
psbt.cpp
Go to the documentation of this file.
1// Copyright (c) 2009-present The Bitcoin Core developers
2// Distributed under the MIT software license, see the accompanying
3// file COPYING or http://www.opensource.org/licenses/mit-license.php.
4
5#include <psbt.h>
6
7#include <common/types.h>
8#include <node/types.h>
9#include <policy/policy.h>
12#include <util/check.h>
13#include <util/result.h>
14#include <util/strencodings.h>
15
16#include <algorithm>
17#include <set>
18
20
21PartiallySignedTransaction::PartiallySignedTransaction(const CMutableTransaction& tx, uint32_t version) : m_version(version)
22{
23 assert(m_version == 0 || m_version == 2);
24
27 inputs.reserve(tx.vin.size());
28 for (const CTxIn& input : tx.vin) {
29 inputs.emplace_back(GetVersion(), input.prevout.hash, input.prevout.n, input.nSequence);
30 }
31 outputs.reserve(tx.vout.size());
32 for (const CTxOut& output : tx.vout) {
33 outputs.emplace_back(GetVersion(), output.nValue, output.scriptPubKey);
34 }
35}
36
38{
39 // Prohibited to merge two PSBTs over different transactions
40 std::optional<Txid> this_id = GetUniqueID();
41 std::optional<Txid> psbt_id = psbt.GetUniqueID();
42 if (!this_id || !psbt_id || this_id != psbt_id) {
43 return false;
44 }
45 if (GetVersion() != psbt.GetVersion()) {
46 return false;
47 }
48
49 for (unsigned int i = 0; i < inputs.size(); ++i) {
50 inputs[i].Merge(psbt.inputs[i]);
51 }
52 for (unsigned int i = 0; i < outputs.size(); ++i) {
53 outputs[i].Merge(psbt.outputs[i]);
54 }
55 MergeGlobalXPubs(psbt);
56 if (fallback_locktime == std::nullopt && psbt.fallback_locktime != std::nullopt) fallback_locktime = psbt.fallback_locktime;
57
58 // Set m_tx_modifiable only if either PSBT had it set
59 if (m_tx_modifiable.has_value() || psbt.m_tx_modifiable.has_value()) {
60 // In general, we AND the modifiable flags
61 std::bitset<8> this_modifiable = m_tx_modifiable.value_or(0);
62 std::bitset<8> psbt_modifiable = psbt.m_tx_modifiable.value_or(0);
63 std::bitset<8> final_modifiable = this_modifiable & psbt_modifiable;
64 // SIGHASH_SINGLE Modifiable (bit 2) needs to be bitwise OR'd
65 final_modifiable.set(2, this_modifiable[2] || psbt_modifiable[2]);
66
67 m_tx_modifiable = final_modifiable;
68 }
69
70 m_proprietary.insert(psbt.m_proprietary.begin(), psbt.m_proprietary.end());
71 unknown.insert(psbt.unknown.begin(), psbt.unknown.end());
72
73 return true;
74}
75
77{
78 for (const auto& [origin, xpubs] : psbt.m_xpubs) {
79 for (const CExtPubKey& xpub : xpubs) {
80 const bool known{std::ranges::any_of(m_xpubs, [&](const auto& entry) { return entry.second.contains(xpub); })};
81 if (!known) m_xpubs[origin].insert(xpub);
82 }
83 }
84}
85
86std::optional<uint32_t> PartiallySignedTransaction::ComputeTimeLock() const
87{
88 if (GetVersion() >= 2) {
89 std::optional<uint32_t> time_lock{0};
90 std::optional<uint32_t> height_lock{0};
91 for (const PSBTInput& input : inputs) {
92 if (input.time_locktime.has_value() && !input.height_locktime.has_value()) {
93 height_lock.reset(); // Transaction can no longer have a height locktime
94 if (!time_lock.has_value()) {
95 return std::nullopt;
96 }
97 } else if (!input.time_locktime.has_value() && input.height_locktime.has_value()) {
98 time_lock.reset(); // Transaction can no longer have a time locktime
99 if (!height_lock.has_value()) {
100 return std::nullopt;
101 }
102 }
103 if (input.time_locktime && time_lock.has_value()) {
104 time_lock = std::max(time_lock, input.time_locktime);
105 }
106 if (input.height_locktime && height_lock.has_value()) {
107 height_lock = std::max(height_lock, input.height_locktime);
108 }
109 }
110 if (height_lock.has_value() && *height_lock > 0) {
111 return *height_lock;
112 }
113 if (time_lock.has_value() && *time_lock > 0) {
114 return *time_lock;
115 }
116 }
117 return fallback_locktime.value_or(0);
118}
119
120std::optional<CMutableTransaction> PartiallySignedTransaction::GetUnsignedTx() const
121{
123 mtx.version = tx_version;
124 std::optional<uint32_t> locktime = ComputeTimeLock();
125 if (!locktime) {
126 return std::nullopt;
127 }
128 mtx.nLockTime = *locktime;
129 uint32_t max_sequence = CTxIn::SEQUENCE_FINAL;
130 for (const PSBTInput& input : inputs) {
131 CTxIn txin;
132 txin.prevout.hash = input.prev_txid;
133 txin.prevout.n = input.prev_out;
134 txin.nSequence = input.sequence.value_or(max_sequence);
135 mtx.vin.push_back(txin);
136 }
137 for (const PSBTOutput& output : outputs) {
138 CTxOut txout;
139 txout.nValue = output.amount;
140 txout.scriptPubKey = output.script;
141 mtx.vout.push_back(txout);
142 }
143 return mtx;
144}
145
147{
148 // Get the unsigned transaction
149 std::optional<CMutableTransaction> mtx = GetUnsignedTx();
150 if (!mtx) {
151 return std::nullopt;
152 }
153 if (GetVersion() >= 2) {
154 for (CTxIn& txin : mtx->vin) {
155 txin.nSequence = 0;
156 }
157 }
158 return mtx->GetHash();
159}
160
162{
163 // The input being added must be for this PSBT's version
164 if (psbtin.GetVersion() != GetVersion()) {
165 return false;
166 }
167
168 // Prevent duplicate inputs
169 if (std::find_if(inputs.begin(), inputs.end(),
170 [psbtin](const PSBTInput& psbt) {
171 return psbt.prev_txid == psbtin.prev_txid && psbt.prev_out == psbtin.prev_out;
172 }
173 ) != inputs.end()) {
174 return false;
175 }
176
177 if (GetVersion() < 2) {
178 // This is a v0 psbt, so do the v0 AddInput
179 inputs.push_back(psbtin);
180 inputs.back().partial_sigs.clear();
181 inputs.back().final_script_sig.clear();
182 inputs.back().final_script_witness.SetNull();
183 return true;
184 }
185
186 // Check inputs modifiable flag
187 if (!m_tx_modifiable.has_value() || !m_tx_modifiable->test(0)) {
188 return false;
189 }
190
191 // Determine if we need to iterate the inputs.
192 // For now, we only do this if the new input has a required time lock.
193 // BIP 370 states that we should also do this if m_tx_modifiable's bit 2 is set
194 // (Has SIGHASH_SINGLE flag) but since we are only adding inputs at the end of the vector,
195 // we don't care about that.
196 bool iterate_inputs = psbtin.time_locktime != std::nullopt || psbtin.height_locktime != std::nullopt;
197 if (iterate_inputs) {
198 std::optional<uint32_t> old_timelock = ComputeTimeLock();
199 if (!old_timelock) {
200 return false;
201 }
202
203 std::optional<uint32_t> time_lock = psbtin.time_locktime;
204 std::optional<uint32_t> height_lock = psbtin.height_locktime;
205 bool has_sigs = false;
206 for (const PSBTInput& input : inputs) {
207 if (input.time_locktime.has_value() && !input.height_locktime.has_value()) {
208 height_lock.reset(); // Transaction can no longer have a height locktime
209 if (time_lock == std::nullopt) {
210 return false;
211 }
212 } else if (!input.time_locktime.has_value() && input.height_locktime.has_value()) {
213 time_lock.reset(); // Transaction can no longer have a time locktime
214 if (height_lock == std::nullopt) {
215 return false;
216 }
217 }
218 if (input.time_locktime && time_lock.has_value()) {
219 time_lock = std::max(time_lock, input.time_locktime);
220 }
221 if (input.height_locktime && height_lock.has_value()) {
222 height_lock = std::max(height_lock, input.height_locktime);
223 }
224 if (input.HasSignatures()) {
225 has_sigs = true;
226 }
227 }
228 uint32_t new_timelock = fallback_locktime.value_or(0);
229 if (height_lock.has_value() && *height_lock > 0) {
230 new_timelock = *height_lock;
231 } else if (time_lock.has_value() && *time_lock > 0) {
232 new_timelock = *time_lock;
233 }
234 if (has_sigs && *old_timelock != new_timelock) {
235 return false;
236 }
237 }
238
239 // Add the input to the end
240 inputs.push_back(psbtin);
241 return true;
242}
243
245{
246 // The output being added must be for this PSBT's version
247 if (psbtout.GetVersion() != GetVersion()) {
248 return false;
249 }
250
251 if (GetVersion() < 2) {
252 // This is a v0 psbt, do the v0 AddOutput
253 outputs.push_back(psbtout);
254 return true;
255 }
256
257 // No global tx, must be PSBTv2
258 // Check outputs are modifiable
259 if (!m_tx_modifiable.has_value() || !m_tx_modifiable->test(1)) {
260 return false;
261 }
262 outputs.push_back(psbtout);
263
264 return true;
265}
266
267bool PSBTInput::GetUTXO(CTxOut& utxo) const
268{
269 if (non_witness_utxo) {
270 if (prev_out >= non_witness_utxo->vout.size()) {
271 return false;
272 }
273 if (non_witness_utxo->GetHash() != prev_txid) {
274 return false;
275 }
276 utxo = non_witness_utxo->vout[prev_out];
277 } else if (!witness_utxo.IsNull()) {
278 utxo = witness_utxo;
279 } else {
280 return false;
281 }
282 return true;
283}
284
286{
288}
289
291{
292 if (!final_script_sig.empty()) {
293 sigdata.scriptSig = final_script_sig;
294 sigdata.complete = true;
295 }
298 sigdata.complete = true;
299 }
300 if (sigdata.complete) {
301 return;
302 }
303
304 sigdata.signatures.insert(partial_sigs.begin(), partial_sigs.end());
305 if (!redeem_script.empty()) {
307 }
308 if (!witness_script.empty()) {
310 }
311 for (const auto& key_pair : hd_keypaths) {
312 sigdata.misc_pubkeys.emplace(key_pair.first.GetID(), key_pair);
313 }
314 if (!m_tap_key_sig.empty()) {
316 }
317 for (const auto& [pubkey_leaf, sig] : m_tap_script_sigs) {
318 sigdata.taproot_script_sigs.emplace(pubkey_leaf, sig);
319 }
320 if (!m_tap_internal_key.IsNull()) {
322 }
323 if (!m_tap_merkle_root.IsNull()) {
325 }
326 for (const auto& [leaf_script, control_block] : m_tap_scripts) {
327 sigdata.tr_spenddata.scripts.emplace(leaf_script, control_block);
328 }
329 for (const auto& [pubkey, leaf_origin] : m_tap_bip32_paths) {
330 sigdata.taproot_misc_pubkeys.emplace(pubkey, leaf_origin);
331 sigdata.tap_pubkeys.emplace(Hash160(pubkey), pubkey);
332 }
333 for (const auto& [hash, preimage] : ripemd160_preimages) {
334 sigdata.ripemd160_preimages.emplace(std::vector<unsigned char>(hash.begin(), hash.end()), preimage);
335 }
336 for (const auto& [hash, preimage] : sha256_preimages) {
337 sigdata.sha256_preimages.emplace(std::vector<unsigned char>(hash.begin(), hash.end()), preimage);
338 }
339 for (const auto& [hash, preimage] : hash160_preimages) {
340 sigdata.hash160_preimages.emplace(std::vector<unsigned char>(hash.begin(), hash.end()), preimage);
341 }
342 for (const auto& [hash, preimage] : hash256_preimages) {
343 sigdata.hash256_preimages.emplace(std::vector<unsigned char>(hash.begin(), hash.end()), preimage);
344 }
345 sigdata.musig2_pubkeys.insert(m_musig2_participants.begin(), m_musig2_participants.end());
346 for (const auto& [agg_key_lh, pubnonces] : m_musig2_pubnonces) {
347 sigdata.musig2_pubnonces[agg_key_lh].insert(pubnonces.begin(), pubnonces.end());
348 }
349 for (const auto& [agg_key_lh, psigs] : m_musig2_partial_sigs) {
350 sigdata.musig2_partial_sigs[agg_key_lh].insert(psigs.begin(), psigs.end());
351 }
352}
353
355{
356 if (sigdata.complete) {
357 partial_sigs.clear();
358 hd_keypaths.clear();
361
362 if (!sigdata.scriptSig.empty()) {
363 final_script_sig = sigdata.scriptSig;
364 }
365 if (!sigdata.scriptWitness.IsNull()) {
367 }
368 return;
369 }
370
371 partial_sigs.insert(sigdata.signatures.begin(), sigdata.signatures.end());
372 if (redeem_script.empty() && !sigdata.redeem_script.empty()) {
374 }
375 if (witness_script.empty() && !sigdata.witness_script.empty()) {
377 }
378 for (const auto& entry : sigdata.misc_pubkeys) {
379 hd_keypaths.emplace(entry.second);
380 }
381 if (!sigdata.taproot_key_path_sig.empty()) {
383 }
384 for (const auto& [pubkey_leaf, sig] : sigdata.taproot_script_sigs) {
385 m_tap_script_sigs.emplace(pubkey_leaf, sig);
386 }
387 if (!sigdata.tr_spenddata.internal_key.IsNull()) {
389 }
390 if (!sigdata.tr_spenddata.merkle_root.IsNull()) {
392 }
393 for (const auto& [leaf_script, control_block] : sigdata.tr_spenddata.scripts) {
394 m_tap_scripts.emplace(leaf_script, control_block);
395 }
396 for (const auto& [pubkey, leaf_origin] : sigdata.taproot_misc_pubkeys) {
397 m_tap_bip32_paths.emplace(pubkey, leaf_origin);
398 }
399 m_musig2_participants.insert(sigdata.musig2_pubkeys.begin(), sigdata.musig2_pubkeys.end());
400 for (const auto& [agg_key_lh, pubnonces] : sigdata.musig2_pubnonces) {
401 m_musig2_pubnonces[agg_key_lh].insert(pubnonces.begin(), pubnonces.end());
402 }
403 for (const auto& [agg_key_lh, psigs] : sigdata.musig2_partial_sigs) {
404 m_musig2_partial_sigs[agg_key_lh].insert(psigs.begin(), psigs.end());
405 }
406 for (const auto& [hash, preimage] : sigdata.ripemd160_preimages) {
407 ripemd160_preimages.emplace(std::vector<unsigned char>(hash.begin(), hash.end()), preimage);
408 }
409 for (const auto& [hash, preimage] : sigdata.sha256_preimages) {
410 sha256_preimages.emplace(std::vector<unsigned char>(hash.begin(), hash.end()), preimage);
411 }
412 for (const auto& [hash, preimage] : sigdata.hash160_preimages) {
413 hash160_preimages.emplace(std::vector<unsigned char>(hash.begin(), hash.end()), preimage);
414 }
415 for (const auto& [hash, preimage] : sigdata.hash256_preimages) {
416 hash256_preimages.emplace(std::vector<unsigned char>(hash.begin(), hash.end()), preimage);
417 }
418}
419
420void PSBTInput::Merge(const PSBTInput& input)
421{
423 if (witness_utxo.IsNull() && !input.witness_utxo.IsNull()) {
425 }
426
427 partial_sigs.insert(input.partial_sigs.begin(), input.partial_sigs.end());
428 ripemd160_preimages.insert(input.ripemd160_preimages.begin(), input.ripemd160_preimages.end());
429 sha256_preimages.insert(input.sha256_preimages.begin(), input.sha256_preimages.end());
430 hash160_preimages.insert(input.hash160_preimages.begin(), input.hash160_preimages.end());
431 hash256_preimages.insert(input.hash256_preimages.begin(), input.hash256_preimages.end());
432 hd_keypaths.insert(input.hd_keypaths.begin(), input.hd_keypaths.end());
433 m_proprietary.insert(input.m_proprietary.begin(), input.m_proprietary.end());
434 unknown.insert(input.unknown.begin(), input.unknown.end());
435 m_tap_script_sigs.insert(input.m_tap_script_sigs.begin(), input.m_tap_script_sigs.end());
436 // Merge by control block, the serialized key (BIP 371), to avoid duplicate keys. Keep the
437 // leaf script already present; BIP 174 lets the Combiner pick arbitrarily on conflict.
438 std::set<std::vector<unsigned char>> seen_control_blocks;
439 for (const auto& [_, control_blocks] : m_tap_scripts) {
440 seen_control_blocks.insert(control_blocks.begin(), control_blocks.end());
441 }
442 for (const auto& [leaf, control_blocks] : input.m_tap_scripts) {
443 for (const auto& control_block : control_blocks) {
444 if (seen_control_blocks.insert(control_block).second) m_tap_scripts[leaf].insert(control_block);
445 }
446 }
447 m_tap_bip32_paths.insert(input.m_tap_bip32_paths.begin(), input.m_tap_bip32_paths.end());
448
453 if (m_tap_key_sig.empty() && !input.m_tap_key_sig.empty()) m_tap_key_sig = input.m_tap_key_sig;
456 m_musig2_participants.insert(input.m_musig2_participants.begin(), input.m_musig2_participants.end());
457 for (const auto& [agg_key_lh, pubnonces] : input.m_musig2_pubnonces) {
458 m_musig2_pubnonces[agg_key_lh].insert(pubnonces.begin(), pubnonces.end());
459 }
460 for (const auto& [agg_key_lh, psigs] : input.m_musig2_partial_sigs) {
461 m_musig2_partial_sigs[agg_key_lh].insert(psigs.begin(), psigs.end());
462 }
463 if (sighash_type == std::nullopt && input.sighash_type != std::nullopt) sighash_type = input.sighash_type;
464 if (sequence == std::nullopt && input.sequence != std::nullopt) sequence = input.sequence;
465 if (time_locktime == std::nullopt && input.time_locktime != std::nullopt) time_locktime = input.time_locktime;
466 if (height_locktime == std::nullopt && input.height_locktime != std::nullopt) height_locktime = input.height_locktime;
467}
468
470{
471 return !final_script_sig.empty()
473 || !partial_sigs.empty()
474 || !m_tap_key_sig.empty()
475 || !m_tap_script_sigs.empty()
476 || !m_musig2_partial_sigs.empty();
477}
478
480{
481 if (!redeem_script.empty()) {
483 }
484 if (!witness_script.empty()) {
486 }
487 for (const auto& key_pair : hd_keypaths) {
488 sigdata.misc_pubkeys.emplace(key_pair.first.GetID(), key_pair);
489 }
490 if (!m_tap_tree.empty() && m_tap_internal_key.IsFullyValid()) {
491 TaprootBuilder builder;
492 for (const auto& [depth, leaf_ver, script] : m_tap_tree) {
493 builder.Add((int)depth, script, (int)leaf_ver, /*track=*/true);
494 }
495 assert(builder.IsComplete());
497 TaprootSpendData spenddata = builder.GetSpendData();
498
500 sigdata.tr_spenddata.Merge(spenddata);
501 sigdata.tr_builder = builder;
502 }
503 for (const auto& [pubkey, leaf_origin] : m_tap_bip32_paths) {
504 sigdata.taproot_misc_pubkeys.emplace(pubkey, leaf_origin);
505 sigdata.tap_pubkeys.emplace(Hash160(pubkey), pubkey);
506 }
507 sigdata.musig2_pubkeys.insert(m_musig2_participants.begin(), m_musig2_participants.end());
508}
509
511{
512 if (redeem_script.empty() && !sigdata.redeem_script.empty()) {
514 }
515 if (witness_script.empty() && !sigdata.witness_script.empty()) {
517 }
518 for (const auto& entry : sigdata.misc_pubkeys) {
519 hd_keypaths.emplace(entry.second);
520 }
521 if (!sigdata.tr_spenddata.internal_key.IsNull()) {
523 }
524 if (sigdata.tr_builder.has_value() && sigdata.tr_builder->HasScripts()) {
525 m_tap_tree = sigdata.tr_builder->GetTreeTuples();
526 }
527 for (const auto& [pubkey, leaf_origin] : sigdata.taproot_misc_pubkeys) {
528 m_tap_bip32_paths.emplace(pubkey, leaf_origin);
529 }
530 m_musig2_participants.insert(sigdata.musig2_pubkeys.begin(), sigdata.musig2_pubkeys.end());
531}
532
533void PSBTOutput::Merge(const PSBTOutput& output)
534{
535 hd_keypaths.insert(output.hd_keypaths.begin(), output.hd_keypaths.end());
536 m_proprietary.insert(output.m_proprietary.begin(), output.m_proprietary.end());
537 unknown.insert(output.unknown.begin(), output.unknown.end());
538 m_tap_bip32_paths.insert(output.m_tap_bip32_paths.begin(), output.m_tap_bip32_paths.end());
539
543 if (m_tap_tree.empty() && !output.m_tap_tree.empty()) m_tap_tree = output.m_tap_tree;
544 m_musig2_participants.insert(output.m_musig2_participants.begin(), output.m_musig2_participants.end());
545}
546
547bool PSBTInputSigned(const PSBTInput& input)
548{
549 return !input.final_script_sig.empty() || !input.final_script_witness.IsNull();
550}
551
552bool PSBTInputSignedAndVerified(const PartiallySignedTransaction& psbt, unsigned int input_index, const PrecomputedTransactionData* txdata)
553{
554 CTxOut utxo;
555 assert(input_index < psbt.inputs.size());
556 const PSBTInput& input = psbt.inputs[input_index];
557
558 if (input.non_witness_utxo) {
559 // If we're taking our information from a non-witness UTXO, verify that it matches the prevout.
560 COutPoint prevout = input.GetOutPoint();
561 if (prevout.n >= input.non_witness_utxo->vout.size()) {
562 return false;
563 }
564 if (input.non_witness_utxo->GetHash() != prevout.hash) {
565 return false;
566 }
567 utxo = input.non_witness_utxo->vout[prevout.n];
568 } else if (!input.witness_utxo.IsNull()) {
569 utxo = input.witness_utxo;
570 } else {
571 return false;
572 }
573
574 std::optional<CMutableTransaction> unsigned_tx = psbt.GetUnsignedTx();
575 if (!unsigned_tx) {
576 return false;
577 }
578 const CMutableTransaction& tx = *unsigned_tx;
579 if (txdata) {
580 return VerifyScript(input.final_script_sig, utxo.scriptPubKey, &input.final_script_witness, STANDARD_SCRIPT_VERIFY_FLAGS, MutableTransactionSignatureChecker{&tx, input_index, utxo.nValue, *txdata, MissingDataBehavior::FAIL});
581 } else {
582 return VerifyScript(input.final_script_sig, utxo.scriptPubKey, &input.final_script_witness, STANDARD_SCRIPT_VERIFY_FLAGS, MutableTransactionSignatureChecker{&tx, input_index, utxo.nValue, MissingDataBehavior::FAIL});
583 }
584}
585
587 size_t count = 0;
588 for (const auto& input : psbt.inputs) {
589 if (!PSBTInputSigned(input)) {
590 count++;
591 }
592 }
593
594 return count;
595}
596
598{
599 std::optional<CMutableTransaction> unsigned_tx = psbt.GetUnsignedTx();
600 if (!unsigned_tx) {
601 return;
602 }
603 const CTxOut& out = unsigned_tx->vout.at(index);
604 PSBTOutput& psbt_out = psbt.outputs.at(index);
605
606 // Fill a SignatureData with output info
607 SignatureData sigdata;
608 psbt_out.FillSignatureData(sigdata);
609
610 // Construct a would-be spend of this output, to update sigdata with.
611 // Note that ProduceSignature is used to fill in metadata (not actual signatures),
612 // so provider does not need to provide any private keys (it can be a HidingSigningProvider).
614 tx.vin.emplace_back();
615 MutableTransactionSignatureCreator creator(tx, /*input_idx=*/0, out.nValue, {.sighash_type = SIGHASH_ALL});
616 ProduceSignature(provider, creator, out.scriptPubKey, sigdata);
617
618 // Put redeem_script, witness_script, key paths, into PSBTOutput.
619 psbt_out.FromSignatureData(sigdata);
620}
621
622std::optional<PrecomputedTransactionData> PrecomputePSBTData(const PartiallySignedTransaction& psbt)
623{
624 std::optional<CMutableTransaction> unsigned_tx = psbt.GetUnsignedTx();
625 if (!unsigned_tx) {
626 return std::nullopt;
627 }
628 const CMutableTransaction& tx = *unsigned_tx;
629 bool have_all_spent_outputs = true;
630 std::vector<CTxOut> utxos;
631 for (const PSBTInput& input : psbt.inputs) {
632 if (!input.GetUTXO(utxos.emplace_back())) have_all_spent_outputs = false;
633 }
635 if (have_all_spent_outputs) {
636 txdata.Init(tx, std::move(utxos), true);
637 } else {
638 txdata.Init(tx, {}, true);
639 }
640 return txdata;
641}
642
644{
645 PSBTInput& input = psbt.inputs.at(index);
646 std::optional<CMutableTransaction> unsigned_tx = psbt.GetUnsignedTx();
647 if (!unsigned_tx) {
648 return util::Unexpected{PSBTError::INVALID_TX};
649 }
650 const CMutableTransaction& tx = *unsigned_tx;
651
652 if (PSBTInputSignedAndVerified(psbt, index, txdata)) {
653 return {};
654 }
655
656 // Fill SignatureData with input info
657 SignatureData sigdata;
658 input.FillSignatureData(sigdata);
659
660 // Get UTXO
661 bool require_witness_sig = false;
662 CTxOut utxo;
663
664 if (input.non_witness_utxo) {
665 // If we're taking our information from a non-witness UTXO, verify that it matches the prevout.
666 COutPoint prevout = input.GetOutPoint();
667 if (prevout.n >= input.non_witness_utxo->vout.size()) {
668 return util::Unexpected{PSBTError::MISSING_INPUTS};
669 }
670 if (input.non_witness_utxo->GetHash() != prevout.hash) {
671 return util::Unexpected{PSBTError::MISSING_INPUTS};
672 }
673 utxo = input.non_witness_utxo->vout[prevout.n];
674 } else if (!input.witness_utxo.IsNull()) {
675 utxo = input.witness_utxo;
676 // When we're taking our information from a witness UTXO, we can't verify it is actually data from
677 // the output being spent. This is safe in case a witness signature is produced (which includes this
678 // information directly in the hash), but not for non-witness signatures. Remember that we require
679 // a witness signature in this situation.
680 require_witness_sig = true;
681 } else {
682 return util::Unexpected{PSBTError::MISSING_INPUTS};
683 }
684
685 // Get the sighash type
686 // If both the field and the parameter are provided, they must match
687 // If only the parameter is provided, use it and add it to the PSBT if it is other than SIGHASH_DEFAULT
688 // for all input types, and not SIGHASH_ALL for non-taproot input types.
689 // If neither are provided, use SIGHASH_DEFAULT if it is taproot, and SIGHASH_ALL for everything else.
690 int sighash{options.sighash_type.value_or(utxo.scriptPubKey.IsPayToTaproot() ? SIGHASH_DEFAULT : SIGHASH_ALL)};
691
692 // For user safety, the desired sighash must be provided if the PSBT wants something other than the default set in the previous line.
693 if (input.sighash_type && input.sighash_type != sighash) {
694 return util::Unexpected{PSBTError::SIGHASH_MISMATCH};
695 }
696 // Set the PSBT sighash field when sighash is not DEFAULT or ALL
697 // DEFAULT is allowed for non-taproot inputs since DEFAULT may be passed for them (e.g. the psbt being signed also has taproot inputs)
698 // Note that signing already aliases DEFAULT to ALL for non-taproot inputs.
699 if (utxo.scriptPubKey.IsPayToTaproot() ? sighash != SIGHASH_DEFAULT :
700 (sighash != SIGHASH_DEFAULT && sighash != SIGHASH_ALL)) {
701 input.sighash_type = sighash;
702 }
703
704 // Check all existing signatures use the sighash type
705 if (sighash == SIGHASH_DEFAULT) {
706 if (!input.m_tap_key_sig.empty() && input.m_tap_key_sig.size() != 64) {
707 return util::Unexpected{PSBTError::SIGHASH_MISMATCH};
708 }
709 for (const auto& [_, sig] : input.m_tap_script_sigs) {
710 if (sig.size() != 64) return util::Unexpected{PSBTError::SIGHASH_MISMATCH};
711 }
712 } else {
713 if (!input.m_tap_key_sig.empty() && (input.m_tap_key_sig.size() != 65 || input.m_tap_key_sig.back() != sighash)) {
714 return util::Unexpected{PSBTError::SIGHASH_MISMATCH};
715 }
716 for (const auto& [_, sig] : input.m_tap_script_sigs) {
717 if (sig.size() != 65 || sig.back() != sighash) return util::Unexpected{PSBTError::SIGHASH_MISMATCH};
718 }
719 for (const auto& [_, sig] : input.partial_sigs) {
720 if (sig.second.back() != sighash) return util::Unexpected{PSBTError::SIGHASH_MISMATCH};
721 }
722 }
723
724 sigdata.witness = false;
725 bool sig_complete;
726 if (txdata == nullptr) {
727 sig_complete = ProduceSignature(provider, DUMMY_SIGNATURE_CREATOR, utxo.scriptPubKey, sigdata);
728 } else {
729 MutableTransactionSignatureCreator creator(tx, index, utxo.nValue, txdata, {.sighash_type = sighash});
730 sig_complete = ProduceSignature(provider, creator, utxo.scriptPubKey, sigdata);
731 }
732 // Verify that a witness signature was produced in case one was required.
733 if (require_witness_sig && !sigdata.witness) return util::Unexpected{PSBTError::INCOMPLETE};
734
735 // If we are not finalizing, set sigdata.complete to false to not set the scriptWitness
736 if (!options.finalize && sigdata.complete) sigdata.complete = false;
737
738 input.FromSignatureData(sigdata);
739
740 // If we have a witness signature, put a witness UTXO.
741 if (sigdata.witness) {
742 input.witness_utxo = utxo;
743 // We can remove the non_witness_utxo if and only if there are no non-segwit or segwit v0
744 // inputs in this transaction. Since this requires inspecting the entire transaction, this
745 // is something for the caller to deal with (i.e. FillPSBT).
746 }
747
748 // Fill in the missing info
749 if (out_sigdata) {
750 out_sigdata->missing_pubkeys = sigdata.missing_pubkeys;
751 out_sigdata->missing_sigs = sigdata.missing_sigs;
752 out_sigdata->missing_redeem_script = sigdata.missing_redeem_script;
753 out_sigdata->missing_witness_script = sigdata.missing_witness_script;
754 }
755
756 if (!sig_complete) return util::Unexpected{PSBTError::INCOMPLETE};
757 return {};
758}
759
761{
762 // Figure out if any non_witness_utxos should be dropped
763 std::vector<unsigned int> to_drop;
764 for (unsigned int i = 0; i < psbtx.inputs.size(); ++i) {
765 const auto& input = psbtx.inputs.at(i);
766 int wit_ver;
767 std::vector<unsigned char> wit_prog;
768 if (input.witness_utxo.IsNull() || !input.witness_utxo.scriptPubKey.IsWitnessProgram(wit_ver, wit_prog)) {
769 // There's a non-segwit input, so we cannot drop any non_witness_utxos
770 to_drop.clear();
771 break;
772 }
773 if (wit_ver == 0) {
774 // Segwit v0, so we cannot drop any non_witness_utxos
775 to_drop.clear();
776 break;
777 }
778 // non_witness_utxos cannot be dropped if the sighash type includes SIGHASH_ANYONECANPAY
779 // Since callers should have called SignPSBTInput which updates the sighash type in the PSBT, we only
780 // need to look at that field. If it is not present, then we can assume SIGHASH_DEFAULT or SIGHASH_ALL.
781 if (input.sighash_type != std::nullopt && (*input.sighash_type & 0x80) == SIGHASH_ANYONECANPAY) {
782 to_drop.clear();
783 break;
784 }
785
786 if (input.non_witness_utxo) {
787 to_drop.push_back(i);
788 }
789 }
790
791 // Drop the non_witness_utxos that we can drop
792 for (unsigned int i : to_drop) {
793 psbtx.inputs.at(i).non_witness_utxo = nullptr;
794 }
795}
796
798{
799 // Finalize input signatures -- in case we have partial signatures that add up to a complete
800 // signature, but have not combined them yet (e.g. because the combiner that created this
801 // PartiallySignedTransaction did not understand them), this will combine them into a final
802 // script.
803 bool complete = true;
804 std::optional<PrecomputedTransactionData> txdata_res = PrecomputePSBTData(psbtx);
805 if (!txdata_res) {
806 return false;
807 }
808 const PrecomputedTransactionData& txdata = *txdata_res;
809 for (unsigned int i = 0; i < psbtx.inputs.size(); ++i) {
810 PSBTInput& input = psbtx.inputs.at(i);
811 const auto sign_result = SignPSBTInput(DUMMY_SIGNING_PROVIDER, psbtx, i, &txdata, {.sighash_type = input.sighash_type, .finalize = true}, /*out_sigdata=*/nullptr);
812 complete &= sign_result.has_value();
813 }
814
815 return complete;
816}
817
819{
820 // It's not safe to extract a PSBT that isn't finalized, and there's no easy way to check
821 // whether a PSBT is finalized without finalizing it, so we just do this.
822 if (!FinalizePSBT(psbtx)) {
823 return false;
824 }
825
826 std::optional<CMutableTransaction> unsigned_tx = psbtx.GetUnsignedTx();
827 if (!unsigned_tx) {
828 return false;
829 }
830 result = *unsigned_tx;
831 for (unsigned int i = 0; i < result.vin.size(); ++i) {
832 result.vin[i].scriptSig = psbtx.inputs[i].final_script_sig;
833 result.vin[i].scriptWitness = psbtx.inputs[i].final_script_witness;
834 }
835 return true;
836}
837
838std::optional<PartiallySignedTransaction> CombinePSBTs(const std::vector<PartiallySignedTransaction>& psbtxs)
839{
840 PartiallySignedTransaction out = psbtxs[0]; // Copy the first one
841
842 // Merge
843 for (auto it = std::next(psbtxs.begin()); it != psbtxs.end(); ++it) {
844 if (!out.Merge(*it)) {
845 return std::nullopt;
846 }
847 }
848 return out;
849}
850
851std::string PSBTRoleName(PSBTRole role) {
852 switch (role) {
853 case PSBTRole::CREATOR: return "creator";
854 case PSBTRole::UPDATER: return "updater";
855 case PSBTRole::SIGNER: return "signer";
856 case PSBTRole::FINALIZER: return "finalizer";
857 case PSBTRole::EXTRACTOR: return "extractor";
858 } // no default case, so the compiler can warn about missing cases
859 assert(false);
860}
861
863{
864 auto tx_data = DecodeBase64(base64_tx);
865 if (!tx_data) {
866 return util::Error{Untranslated("invalid base64")};
867 }
868 return DecodeRawPSBT(MakeByteSpan(*tx_data));
869}
870
872{
873 SpanReader ss_data{tx_data};
874 try {
876 if (!ss_data.empty()) {
877 return util::Error{Untranslated("extra data after PSBT")};
878 }
879 return psbt;
880 } catch (const std::exception& e) {
881 return util::Error{Untranslated(e.what())};
882 }
883}
884
886{
887 if (m_version != std::nullopt) {
888 return *m_version;
889 }
890 return 0;
891}
An outpoint - a combination of a transaction hash and an index n into its vout.
Definition: transaction.h:30
uint32_t n
Definition: transaction.h:33
Txid hash
Definition: transaction.h:32
void clear()
Definition: script.h:569
bool IsPayToTaproot() const
Definition: script.cpp:241
An input of a transaction.
Definition: transaction.h:63
static constexpr uint32_t SEQUENCE_FINAL
Setting nSequence to this value for every input in a transaction disables nLockTime/IsFinalTx().
Definition: transaction.h:77
uint32_t nSequence
Definition: transaction.h:67
COutPoint prevout
Definition: transaction.h:65
An output of a transaction.
Definition: transaction.h:141
CScript scriptPubKey
Definition: transaction.h:144
CAmount nValue
Definition: transaction.h:143
bool IsNull() const
Definition: transaction.h:161
A signature creator for transactions.
Definition: sign.h:54
A structure for PSBTs which contain per-input information.
Definition: psbt.h:282
std::vector< unsigned char > m_tap_key_sig
Definition: psbt.h:307
std::map< CPubKey, KeyOriginInfo > hd_keypaths
Definition: psbt.h:293
std::map< uint256, std::vector< unsigned char > > hash256_preimages
Definition: psbt.h:298
CScriptWitness final_script_witness
Definition: psbt.h:292
std::optional< uint32_t > sequence
Definition: psbt.h:302
std::map< std::pair< CPubKey, uint256 >, std::map< CPubKey, std::vector< uint8_t > > > m_musig2_pubnonces
Definition: psbt.h:317
bool HasSignatures() const
Definition: psbt.cpp:469
bool GetUTXO(CTxOut &utxo) const
Retrieves the UTXO for this input.
Definition: psbt.cpp:267
std::map< std::pair< std::vector< unsigned char >, int >, std::set< std::vector< unsigned char >, ShortestVectorFirstComparator > > m_tap_scripts
Definition: psbt.h:309
CTransactionRef non_witness_utxo
Definition: psbt.h:287
Txid prev_txid
Definition: psbt.h:300
std::map< CKeyID, SigPair > partial_sigs
Definition: psbt.h:294
std::optional< int > sighash_type
Definition: psbt.h:323
std::map< std::pair< XOnlyPubKey, uint256 >, std::vector< unsigned char > > m_tap_script_sigs
Definition: psbt.h:308
std::optional< uint32_t > time_locktime
Definition: psbt.h:303
uint256 m_tap_merkle_root
Definition: psbt.h:312
std::map< uint256, std::vector< unsigned char > > sha256_preimages
Definition: psbt.h:296
void FillSignatureData(SignatureData &sigdata) const
Definition: psbt.cpp:290
std::map< std::pair< CPubKey, uint256 >, std::map< CPubKey, uint256 > > m_musig2_partial_sigs
Definition: psbt.h:319
COutPoint GetOutPoint() const
Definition: psbt.cpp:285
std::map< uint160, std::vector< unsigned char > > hash160_preimages
Definition: psbt.h:297
void Merge(const PSBTInput &input)
Definition: psbt.cpp:420
uint32_t prev_out
Definition: psbt.h:301
std::map< CPubKey, std::vector< CPubKey > > m_musig2_participants
Definition: psbt.h:315
std::set< PSBTProprietary > m_proprietary
Definition: psbt.h:322
CScript redeem_script
Definition: psbt.h:289
CScript final_script_sig
Definition: psbt.h:291
void FromSignatureData(const SignatureData &sigdata)
Definition: psbt.cpp:354
uint32_t GetVersion() const
Definition: psbt.h:328
XOnlyPubKey m_tap_internal_key
Definition: psbt.h:311
std::optional< uint32_t > height_locktime
Definition: psbt.h:304
std::map< XOnlyPubKey, std::pair< std::set< uint256 >, KeyOriginInfo > > m_tap_bip32_paths
Definition: psbt.h:310
std::map< std::vector< unsigned char >, std::vector< unsigned char > > unknown
Definition: psbt.h:321
std::map< uint160, std::vector< unsigned char > > ripemd160_preimages
Definition: psbt.h:295
CTxOut witness_utxo
Definition: psbt.h:288
CScript witness_script
Definition: psbt.h:290
A structure for PSBTs which contains per output information.
Definition: psbt.h:939
std::map< CPubKey, std::vector< CPubKey > > m_musig2_participants
Definition: psbt.h:951
XOnlyPubKey m_tap_internal_key
Definition: psbt.h:948
std::map< XOnlyPubKey, std::pair< std::set< uint256 >, KeyOriginInfo > > m_tap_bip32_paths
Definition: psbt.h:950
CScript witness_script
Definition: psbt.h:945
void Merge(const PSBTOutput &output)
Definition: psbt.cpp:533
std::set< PSBTProprietary > m_proprietary
Definition: psbt.h:954
CScript redeem_script
Definition: psbt.h:944
uint32_t GetVersion() const
Definition: psbt.h:962
std::map< CPubKey, KeyOriginInfo > hd_keypaths
Definition: psbt.h:946
std::vector< std::tuple< uint8_t, uint8_t, std::vector< unsigned char > > > m_tap_tree
Definition: psbt.h:949
std::map< std::vector< unsigned char >, std::vector< unsigned char > > unknown
Definition: psbt.h:953
void FillSignatureData(SignatureData &sigdata) const
Definition: psbt.cpp:479
void FromSignatureData(const SignatureData &sigdata)
Definition: psbt.cpp:510
A version of CTransaction with the PSBT format.
Definition: psbt.h:1239
std::optional< std::bitset< 8 > > m_tx_modifiable
Definition: psbt.h:1247
uint32_t GetVersion() const
Definition: psbt.cpp:885
bool Merge(const PartiallySignedTransaction &psbt)
Merge psbt into this.
Definition: psbt.cpp:37
std::map< KeyOriginInfo, std::set< CExtPubKey > > m_xpubs
Definition: psbt.h:1246
std::optional< uint32_t > m_version
Definition: psbt.h:1241
std::optional< Txid > GetUniqueID() const
Definition: psbt.cpp:146
std::map< std::vector< unsigned char >, std::vector< unsigned char > > unknown
Definition: psbt.h:1250
std::vector< PSBTInput > inputs
Definition: psbt.h:1248
void MergeGlobalXPubs(const PartiallySignedTransaction &psbt)
Merge the global xpubs of psbt into this, keeping the existing origin for an xpub seen again with a d...
Definition: psbt.cpp:76
std::optional< CMutableTransaction > GetUnsignedTx() const
Definition: psbt.cpp:120
std::optional< uint32_t > ComputeTimeLock() const
Definition: psbt.cpp:86
std::vector< PSBTOutput > outputs
Definition: psbt.h:1249
std::set< PSBTProprietary > m_proprietary
Definition: psbt.h:1251
bool AddOutput(const PSBTOutput &psbtout)
Definition: psbt.cpp:244
std::optional< uint32_t > fallback_locktime
Definition: psbt.h:1254
PartiallySignedTransaction(const CMutableTransaction &tx, uint32_t version=2)
Definition: psbt.cpp:21
bool AddInput(const PSBTInput &psbtin)
Definition: psbt.cpp:161
An interface to be implemented by keystores that support signing.
Minimal stream for reading from an existing byte array by std::span.
Definition: streams.h:83
Utility class to construct Taproot outputs from internal key and script tree.
TaprootSpendData GetSpendData() const
Compute spending data (after Finalize()).
bool IsComplete() const
Return whether there were either no leaves, or the leaves form a Huffman tree.
TaprootBuilder & Add(int depth, std::span< const unsigned char > script, int leaf_version, bool track=true)
Add a new script at a certain depth in the tree.
TaprootBuilder & Finalize(const XOnlyPubKey &internal_key)
Finalize the construction.
bool IsNull() const
Test whether this is the 0 key (the result of default construction).
Definition: pubkey.h:259
bool IsFullyValid() const
Determine if this pubkey is fully valid.
Definition: pubkey.cpp:230
constexpr bool IsNull() const
Definition: uint256.h:50
bool empty() const
Definition: prevector.h:251
The util::Expected class provides a standard way for low-level functions to return either error value...
Definition: expected.h:44
The util::Unexpected class represents an unexpected value stored in util::Expected.
Definition: expected.h:21
is a home for simple enum and struct type definitions that can be used internally by functions in the...
uint160 Hash160(const T1 &in1)
Compute the 160-bit hash an object.
Definition: hash.h:100
bool VerifyScript(const CScript &scriptSig, const CScript &scriptPubKey, const CScriptWitness *witness, script_verify_flags flags, const BaseSignatureChecker &checker, ScriptError *serror)
@ SIGHASH_ANYONECANPAY
Definition: interpreter.h:35
@ SIGHASH_DEFAULT
Taproot only; implied when sighash byte is missing, and equivalent to SIGHASH_ALL.
Definition: interpreter.h:37
@ SIGHASH_ALL
Definition: interpreter.h:32
PSBTError
Definition: types.h:19
is a home for public enum and struct type definitions that are used internally by node code,...
constexpr script_verify_flags STANDARD_SCRIPT_VERIFY_FLAGS
Standard script verification flags that standard transactions will comply with.
Definition: policy.h:118
util::Expected< void, PSBTError > SignPSBTInput(const SigningProvider &provider, PartiallySignedTransaction &psbt, int index, const PrecomputedTransactionData *txdata, const common::PSBTFillOptions &options, SignatureData *out_sigdata)
Signs a PSBTInput, verifying that all provided data matches what is being signed.
Definition: psbt.cpp:643
void UpdatePSBTOutput(const SigningProvider &provider, PartiallySignedTransaction &psbt, int index)
Updates a PSBTOutput with information from provider.
Definition: psbt.cpp:597
bool PSBTInputSignedAndVerified(const PartiallySignedTransaction &psbt, unsigned int input_index, const PrecomputedTransactionData *txdata)
Checks whether a PSBTInput is already signed by doing script verification using final fields.
Definition: psbt.cpp:552
std::string PSBTRoleName(PSBTRole role)
Definition: psbt.cpp:851
util::Result< PartiallySignedTransaction > DecodeBase64PSBT(const std::string &base64_tx)
Decode a base64ed PSBT into a PartiallySignedTransaction.
Definition: psbt.cpp:862
std::optional< PartiallySignedTransaction > CombinePSBTs(const std::vector< PartiallySignedTransaction > &psbtxs)
Combines PSBTs with the same underlying transaction, resulting in a single PSBT with all partial sign...
Definition: psbt.cpp:838
void RemoveUnnecessaryTransactions(PartiallySignedTransaction &psbtx)
Reduces the size of the PSBT by dropping unnecessary non_witness_utxos (i.e.
Definition: psbt.cpp:760
std::optional< PrecomputedTransactionData > PrecomputePSBTData(const PartiallySignedTransaction &psbt)
Compute a PrecomputedTransactionData object from a psbt.
Definition: psbt.cpp:622
size_t CountPSBTUnsignedInputs(const PartiallySignedTransaction &psbt)
Counts the unsigned inputs of a PSBT.
Definition: psbt.cpp:586
bool FinalizeAndExtractPSBT(PartiallySignedTransaction &psbtx, CMutableTransaction &result)
Finalizes a PSBT if possible, and extracts it to a CMutableTransaction if it could be finalized.
Definition: psbt.cpp:818
bool PSBTInputSigned(const PSBTInput &input)
Checks whether a PSBTInput is already signed by checking for non-null finalized fields.
Definition: psbt.cpp:547
bool FinalizePSBT(PartiallySignedTransaction &psbtx)
Finalizes a PSBT if possible, combining partial signatures.
Definition: psbt.cpp:797
util::Result< PartiallySignedTransaction > DecodeRawPSBT(std::span< const std::byte > tx_data)
Decode a raw (binary blob) PSBT into a PartiallySignedTransaction.
Definition: psbt.cpp:871
PSBTRole
Definition: psbt.h:1620
constexpr deserialize_type deserialize
Definition: serialize.h:52
bool ProduceSignature(const SigningProvider &provider, const BaseSignatureCreator &creator, const CScript &fromPubKey, SignatureData &sigdata)
Produce a script signature using a generic signature creator.
Definition: sign.cpp:750
const BaseSignatureCreator & DUMMY_SIGNATURE_CREATOR
A signature creator that just produces 71-byte empty signatures.
Definition: sign.cpp:1008
const SigningProvider & DUMMY_SIGNING_PROVIDER
auto MakeByteSpan(const V &v) noexcept
Definition: span.h:84
A mutable version of CTransaction.
Definition: transaction.h:372
std::vector< CTxOut > vout
Definition: transaction.h:374
std::vector< CTxIn > vin
Definition: transaction.h:373
bool IsNull() const
Definition: script.h:586
void Init(const T &tx, std::vector< CTxOut > &&spent_outputs, bool force=false)
Initialize this PrecomputedTransactionData with transaction data.
uint160 missing_redeem_script
ScriptID of the missing redeemScript (if any)
Definition: sign.h:104
std::vector< CKeyID > missing_sigs
KeyIDs of pubkeys for signatures which could not be found.
Definition: sign.h:103
std::map< std::vector< uint8_t >, std::vector< uint8_t > > ripemd160_preimages
Mapping from a RIPEMD160 hash to its preimage provided to solve a Script.
Definition: sign.h:108
std::map< CKeyID, XOnlyPubKey > tap_pubkeys
Misc Taproot pubkeys involved in this input, by hash. (Equivalent of misc_pubkeys but for Taproot....
Definition: sign.h:101
std::map< CKeyID, SigPair > signatures
BIP 174 style partial signatures for the input. May contain all signatures necessary for producing a ...
Definition: sign.h:96
TaprootSpendData tr_spenddata
Taproot spending data.
Definition: sign.h:94
bool witness
Stores whether the input this SigData corresponds to is a witness input.
Definition: sign.h:89
std::map< CKeyID, std::pair< CPubKey, KeyOriginInfo > > misc_pubkeys
Definition: sign.h:97
std::optional< TaprootBuilder > tr_builder
Taproot tree used to build tr_spenddata.
Definition: sign.h:95
CScript scriptSig
The scriptSig of an input. Contains complete signatures or the traditional partial signatures format.
Definition: sign.h:90
std::map< std::vector< uint8_t >, std::vector< uint8_t > > sha256_preimages
Mapping from a SHA256 hash to its preimage provided to solve a Script.
Definition: sign.h:106
std::vector< unsigned char > taproot_key_path_sig
Definition: sign.h:98
std::map< std::pair< CPubKey, uint256 >, std::map< CPubKey, std::vector< uint8_t > > > musig2_pubnonces
Mapping from pair of MuSig2 aggregate pubkey, and tapleaf hash to map of MuSig2 participant pubkeys t...
Definition: sign.h:113
std::map< std::pair< XOnlyPubKey, uint256 >, std::vector< unsigned char > > taproot_script_sigs
Schnorr signature for key path spending.
Definition: sign.h:99
std::map< XOnlyPubKey, std::pair< std::set< uint256 >, KeyOriginInfo > > taproot_misc_pubkeys
Miscellaneous Taproot pubkeys involved in this input along with their leaf script hashes and key orig...
Definition: sign.h:100
std::map< std::vector< uint8_t >, std::vector< uint8_t > > hash256_preimages
Mapping from a HASH256 hash to its preimage provided to solve a Script.
Definition: sign.h:107
CScript redeem_script
The redeemScript (if any) for the input.
Definition: sign.h:91
std::map< std::pair< CPubKey, uint256 >, std::map< CPubKey, uint256 > > musig2_partial_sigs
Mapping from pair of MuSig2 aggregate pubkey, and tapleaf hash to map of MuSig2 participant pubkeys t...
Definition: sign.h:115
uint256 missing_witness_script
SHA256 of the missing witnessScript (if any)
Definition: sign.h:105
std::vector< CKeyID > missing_pubkeys
KeyIDs of pubkeys which could not be found.
Definition: sign.h:102
CScript witness_script
The witnessScript (if any) for the input. witnessScripts are used in P2WSH outputs.
Definition: sign.h:92
std::map< CPubKey, std::vector< CPubKey > > musig2_pubkeys
Map MuSig2 aggregate pubkeys to its participants.
Definition: sign.h:111
CScriptWitness scriptWitness
The scriptWitness of an input. Contains complete signatures or the traditional partial signatures for...
Definition: sign.h:93
bool complete
Stores whether the scriptSig and scriptWitness are complete.
Definition: sign.h:88
std::map< std::vector< uint8_t >, std::vector< uint8_t > > hash160_preimages
Mapping from a HASH160 hash to its preimage provided to solve a Script.
Definition: sign.h:109
uint256 merkle_root
The Merkle root of the script tree (0 if no scripts).
std::map< std::pair< std::vector< unsigned char >, int >, std::set< std::vector< unsigned char >, ShortestVectorFirstComparator > > scripts
Map from (script, leaf_version) to (sets of) control blocks.
void Merge(TaprootSpendData other)
Merge other TaprootSpendData (for the same scriptPubKey) into this.
XOnlyPubKey internal_key
The BIP341 internal key.
Instructions for how a PSBT should be signed or filled with information.
Definition: types.h:31
std::optional< int > sighash_type
The sighash type to use when signing (if PSBT does not specify).
Definition: types.h:40
bool finalize
Whether to create the final scriptSig or scriptWitness if possible.
Definition: types.h:45
FuzzedDataProvider provider
Definition: dbwrapper.cpp:366
static int count
consteval auto _(util::TranslatedLiteral str)
Definition: translation.h:79
bilingual_str Untranslated(std::string original)
Mark a bilingual_str as untranslated.
Definition: translation.h:82
std::optional< std::vector< unsigned char > > DecodeBase64(std::string_view str)
assert(!tx.IsCoinBase())