Bitcoin Core 31.99.0
P2P Digital Currency
validation.cpp
Go to the documentation of this file.
1// Copyright (c) 2009-2010 Satoshi Nakamoto
2// Copyright (c) 2009-present The Bitcoin Core developers
3// Distributed under the MIT software license, see the accompanying
4// file COPYING or http://www.opensource.org/licenses/mit-license.php.
5
6#include <bitcoin-build-config.h> // IWYU pragma: keep
7
8#include <validation.h>
9
10#include <arith_uint256.h>
11#include <chain.h>
12#include <checkqueue.h>
13#include <clientversion.h>
14#include <consensus/amount.h>
15#include <consensus/consensus.h>
16#include <consensus/merkle.h>
17#include <consensus/tx_check.h>
18#include <consensus/tx_verify.h>
20#include <cuckoocache.h>
21#include <flatfile.h>
22#include <hash.h>
23#include <kernel/chainparams.h>
24#include <kernel/coinstats.h>
29#include <kernel/types.h>
30#include <kernel/warning.h>
31#include <logging/timer.h>
32#include <node/blockstorage.h>
33#include <node/utxo_snapshot.h>
35#include <policy/policy.h>
36#include <policy/rbf.h>
37#include <policy/settings.h>
38#include <policy/truc_policy.h>
39#include <pow.h>
40#include <primitives/block.h>
42#include <random.h>
43#include <script/script.h>
44#include <script/sigcache.h>
45#include <signet.h>
46#include <tinyformat.h>
47#include <txdb.h>
48#include <txmempool.h>
49#include <uint256.h>
50#include <undo.h>
51#include <util/byte_units.h>
52#include <util/check.h>
53#include <util/fs.h>
54#include <util/fs_helpers.h>
55#include <util/hasher.h>
56#include <util/log.h>
57#include <util/moneystr.h>
58#include <util/rbf.h>
59#include <util/result.h>
61#include <util/strencodings.h>
62#include <util/string.h>
63#include <util/threadpool.h>
64#include <util/time.h>
65#include <util/trace.h>
66#include <util/translation.h>
67#include <validationinterface.h>
68
69#include <algorithm>
70#include <cassert>
71#include <chrono>
72#include <deque>
73#include <numeric>
74#include <optional>
75#include <ranges>
76#include <span>
77#include <string>
78#include <tuple>
79#include <utility>
80
86
89using node::BlockMap;
93
98static constexpr auto DATABASE_WRITE_INTERVAL_MIN{50min};
99static constexpr auto DATABASE_WRITE_INTERVAL_MAX{70min};
101static constexpr std::chrono::hours MAX_FEE_ESTIMATION_TIP_AGE{3};
102const std::vector<std::string> CHECKLEVEL_DOC {
103 "level 0 reads the blocks from disk",
104 "level 1 verifies block validity",
105 "level 2 verifies undo data",
106 "level 3 checks disconnection of tip blocks",
107 "level 4 tries to reconnect the blocks",
108 "each level includes the checks of the previous levels",
109};
115static constexpr int PRUNE_LOCK_BUFFER{10};
116
117// Return whether the completed full flush should compact chainstate
118static bool ShouldCompactChainstate(bool in_ibd)
119{
120 static constexpr uint32_t flush_ratio{320}; // Roughly every 2 weeks with hourly flushes
121 return !in_ibd && FastRandomContext().randrange(flush_ratio) == 0;
122}
123
124TRACEPOINT_SEMAPHORE(validation, block_connected);
126TRACEPOINT_SEMAPHORE(mempool, replaced);
127TRACEPOINT_SEMAPHORE(mempool, rejected);
128
130{
132
133 // Find the latest block common to locator and chain - we expect that
134 // locator.vHave is sorted descending by height.
135 for (const uint256& hash : locator.vHave) {
136 const CBlockIndex* pindex{m_blockman.LookupBlockIndex(hash)};
137 if (pindex) {
138 if (m_chain.Contains(*pindex)) {
139 return pindex;
140 }
141 if (pindex->GetAncestor(m_chain.Height()) == m_chain.Tip()) {
142 return m_chain.Tip();
143 }
144 }
145 }
146 return m_chain.Genesis();
147}
148
150 const CCoinsViewCache& inputs, script_verify_flags flags, bool cacheSigStore,
151 bool cacheFullScriptStore, PrecomputedTransactionData& txdata,
152 ValidationCache& validation_cache,
153 std::vector<CScriptCheck>* pvChecks = nullptr)
155
156bool CheckFinalTxAtTip(const CBlockIndex& active_chain_tip, const CTransaction& tx)
157{
159
160 // CheckFinalTxAtTip() uses active_chain_tip.Height()+1 to evaluate
161 // nLockTime because when IsFinalTx() is called within
162 // AcceptBlock(), the height of the block *being*
163 // evaluated is what is used. Thus if we want to know if a
164 // transaction can be part of the *next* block, we need to call
165 // IsFinalTx() with one more than active_chain_tip.Height().
166 const int nBlockHeight = active_chain_tip.nHeight + 1;
167
168 // BIP113 requires that time-locked transactions have nLockTime set to
169 // less than the median time of the previous block they're contained in.
170 // When the next block is created its previous block will be the current
171 // chain tip, so we use that to calculate the median time passed to
172 // IsFinalTx().
173 const int64_t nBlockTime{active_chain_tip.GetMedianTimePast()};
174
175 return IsFinalTx(tx, nBlockHeight, nBlockTime);
176}
177
178namespace {
189std::optional<std::vector<int>> CalculatePrevHeights(
190 const CBlockIndex& tip,
191 const CCoinsView& coins,
192 const CTransaction& tx)
193{
194 std::vector<int> prev_heights;
195 prev_heights.resize(tx.vin.size());
196 for (size_t i = 0; i < tx.vin.size(); ++i) {
197 if (auto coin{coins.GetCoin(tx.vin[i].prevout)}) {
198 prev_heights[i] = coin->nHeight == MEMPOOL_HEIGHT
199 ? tip.nHeight + 1 // Assume all mempool transaction confirm in the next block.
200 : coin->nHeight;
201 } else {
202 LogInfo("ERROR: %s: Missing input %d in transaction \'%s\'\n", __func__, i, tx.GetHash().GetHex());
203 return std::nullopt;
204 }
205 }
206 return prev_heights;
207}
208} // namespace
209
210std::optional<LockPoints> CalculateLockPointsAtTip(
211 CBlockIndex* tip,
212 const CCoinsView& coins_view,
213 const CTransaction& tx)
214{
215 assert(tip);
216
217 auto prev_heights{CalculatePrevHeights(*tip, coins_view, tx)};
218 if (!prev_heights.has_value()) return std::nullopt;
219
220 CBlockIndex next_tip;
221 next_tip.pprev = tip;
222 // When SequenceLocks() is called within ConnectBlock(), the height
223 // of the block *being* evaluated is what is used.
224 // Thus if we want to know if a transaction can be part of the
225 // *next* block, we need to use one more than active_chainstate.m_chain.Height()
226 next_tip.nHeight = tip->nHeight + 1;
227 const auto [min_height, min_time] = CalculateSequenceLocks(tx, STANDARD_LOCKTIME_VERIFY_FLAGS, prev_heights.value(), next_tip);
228
229 // Also store the hash of the block with the highest height of
230 // all the blocks which have sequence locked prevouts.
231 // This hash needs to still be on the chain
232 // for these LockPoint calculations to be valid
233 // Note: It is impossible to correctly calculate a maxInputBlock
234 // if any of the sequence locked inputs depend on unconfirmed txs,
235 // except in the special case where the relative lock time/height
236 // is 0, which is equivalent to no sequence lock. Since we assume
237 // input height of tip+1 for mempool txs and test the resulting
238 // min_height and min_time from CalculateSequenceLocks against tip+1.
239 int max_input_height{0};
240 for (const int height : prev_heights.value()) {
241 // Can ignore mempool inputs since we'll fail if they had non-zero locks
242 if (height != next_tip.nHeight) {
243 max_input_height = std::max(max_input_height, height);
244 }
245 }
246
247 // tip->GetAncestor(max_input_height) should never return a nullptr
248 // because max_input_height is always less than the tip height.
249 // It would, however, be a bad bug to continue execution, since a
250 // LockPoints object with the maxInputBlock member set to nullptr
251 // signifies no relative lock time.
252 return LockPoints{min_height, min_time, Assert(tip->GetAncestor(max_input_height))};
253}
254
256 const LockPoints& lock_points)
257{
258 assert(tip != nullptr);
259
260 CBlockIndex index;
261 index.pprev = tip;
262 // CheckSequenceLocksAtTip() uses active_chainstate.m_chain.Height()+1 to evaluate
263 // height based locks because when SequenceLocks() is called within
264 // ConnectBlock(), the height of the block *being*
265 // evaluated is what is used.
266 // Thus if we want to know if a transaction can be part of the
267 // *next* block, we need to use one more than active_chainstate.m_chain.Height()
268 index.nHeight = tip->nHeight + 1;
269
270 return EvaluateSequenceLocks(index, {lock_points.height, lock_points.time});
271}
272
273static void LimitMempoolSize(CTxMemPool& pool, CCoinsViewCache& coins_cache)
275{
277 AssertLockHeld(pool.cs);
278 int expired = pool.Expire(GetTime<std::chrono::seconds>() - pool.m_opts.expiry);
279 if (expired != 0) {
280 LogDebug(BCLog::MEMPOOL, "Expired %i transactions from the memory pool\n", expired);
281 }
282
283 std::vector<COutPoint> vNoSpendsRemaining;
284 pool.TrimToSize(pool.m_opts.max_size_bytes, &vNoSpendsRemaining);
285 for (const COutPoint& removed : vNoSpendsRemaining)
286 coins_cache.Uncache(removed);
287}
288
290{
292 if (active_chainstate.m_chainman.IsInitialBlockDownload()) {
293 return false;
294 }
295 if (active_chainstate.m_chain.Tip()->GetBlockTime() < count_seconds(GetTime<std::chrono::seconds>() - MAX_FEE_ESTIMATION_TIP_AGE))
296 return false;
297 if (active_chainstate.m_chain.Height() < active_chainstate.m_chainman.m_best_header->nHeight - 1) {
298 return false;
299 }
300 return true;
301}
302
304 DisconnectedBlockTransactions& disconnectpool,
305 bool fAddToMempool)
306{
307 if (!m_mempool) return;
308
311 std::vector<Txid> vHashUpdate;
312 {
313 // disconnectpool is ordered so that the front is the most recently-confirmed
314 // transaction (the last tx of the block at the tip) in the disconnected chain.
315 // Iterate disconnectpool in reverse, so that we add transactions
316 // back to the mempool starting with the earliest transaction that had
317 // been previously seen in a block.
318 const auto queuedTx = disconnectpool.take();
319 auto it = queuedTx.rbegin();
320 while (it != queuedTx.rend()) {
321 // ignore validation errors in resurrected transactions
322 if (!fAddToMempool || (*it)->IsCoinBase() ||
323 AcceptToMemoryPool(*this, *it, GetTime(),
324 /*bypass_limits=*/true, /*test_accept=*/false).m_result_type !=
326 // If the transaction doesn't make it in to the mempool, remove any
327 // transactions that depend on it (which would now be orphans).
329 } else if (m_mempool->exists((*it)->GetHash())) {
330 vHashUpdate.push_back((*it)->GetHash());
331 }
332 ++it;
333 }
334 }
335
336 // AcceptToMemoryPool/addNewTransaction all assume that new mempool entries have
337 // no in-mempool children, which is generally not true when adding
338 // previously-confirmed transactions back to the mempool.
339 // UpdateTransactionsFromBlock finds descendants of any transactions in
340 // the disconnectpool that were added back and cleans up the mempool state.
342
343 // Predicate to use for filtering transactions in removeForReorg.
344 // Checks whether the transaction is still final and, if it spends a coinbase output, mature.
345 // Also updates valid entries' cached LockPoints if needed.
346 // If false, the tx is still valid and its lockpoints are updated.
347 // If true, the tx would be invalid in the next block; remove this entry and all of its descendants.
348 // Note that TRUC rules are not applied here, so reorgs may cause violations of TRUC inheritance or
349 // topology restrictions.
350 const auto filter_final_and_mature = [&](CTxMemPool::txiter it)
354 const CTransaction& tx = it->GetTx();
355
356 // The transaction must be final.
357 if (!CheckFinalTxAtTip(*Assert(m_chain.Tip()), tx)) return true;
358
359 const LockPoints& lp = it->GetLockPoints();
360 // CheckSequenceLocksAtTip checks if the transaction will be final in the next block to be
361 // created on top of the new chain.
364 return true;
365 }
366 } else {
367 const CCoinsViewMemPool view_mempool{&CoinsTip(), *m_mempool};
368 const std::optional<LockPoints> new_lock_points{CalculateLockPointsAtTip(m_chain.Tip(), view_mempool, tx)};
369 if (new_lock_points.has_value() && CheckSequenceLocksAtTip(m_chain.Tip(), *new_lock_points)) {
370 // Now update the mempool entry lockpoints as well.
371 it->UpdateLockPoints(*new_lock_points);
372 } else {
373 return true;
374 }
375 }
376
377 // If the transaction spends any coinbase outputs, it must be mature.
378 if (it->GetSpendsCoinbase()) {
379 for (const CTxIn& txin : tx.vin) {
380 if (m_mempool->exists(txin.prevout.hash)) continue;
381 const Coin& coin{CoinsTip().AccessCoin(txin.prevout)};
382 assert(!coin.IsSpent());
383 const auto mempool_spend_height{m_chain.Tip()->nHeight + 1};
384 if (coin.IsCoinBase() && mempool_spend_height - coin.nHeight < COINBASE_MATURITY) {
385 return true;
386 }
387 }
388 }
389 // Transaction is still valid and cached LockPoints are updated.
390 return false;
391 };
392
393 // We also need to remove any now-immature transactions
394 m_mempool->removeForReorg(m_chain, filter_final_and_mature);
395 // Re-limit mempool size, in case we added any transactions
397}
398
405 const CCoinsViewCache& view, const CTxMemPool& pool,
407 ValidationCache& validation_cache)
409{
412
414 for (const CTxIn& txin : tx.vin) {
415 const Coin& coin = view.AccessCoin(txin.prevout);
416
417 // This coin was checked in PreChecks and MemPoolAccept
418 // has been holding cs_main since then.
419 Assume(!coin.IsSpent());
420 if (coin.IsSpent()) return false;
421
422 // If the Coin is available, there are 2 possibilities:
423 // it is available in our current ChainstateActive UTXO set,
424 // or it's a UTXO provided by a transaction in our mempool.
425 // Ensure the scriptPubKeys in Coins from CoinsView are correct.
426 const CTransactionRef& txFrom = pool.get(txin.prevout.hash);
427 if (txFrom) {
428 assert(txFrom->GetHash() == txin.prevout.hash);
429 assert(txFrom->vout.size() > txin.prevout.n);
430 assert(txFrom->vout[txin.prevout.n] == coin.out);
431 } else {
432 const Coin& coinFromUTXOSet = coins_tip.AccessCoin(txin.prevout);
433 assert(!coinFromUTXOSet.IsSpent());
434 assert(coinFromUTXOSet.out == coin.out);
435 }
436 }
437
438 // Call CheckInputScripts() to cache signature and script validity against current tip consensus rules.
439 return CheckInputScripts(tx, state, view, flags, /* cacheSigStore= */ true, /* cacheFullScriptStore= */ true, txdata, validation_cache);
440}
441
442namespace {
443
444class MemPoolAccept
445{
446public:
447 explicit MemPoolAccept(CTxMemPool& mempool, Chainstate& active_chainstate) :
448 m_pool(mempool),
449 m_view(&CoinsViewEmpty::Get()),
450 m_viewmempool(&active_chainstate.CoinsTip(), m_pool),
451 m_active_chainstate(active_chainstate)
452 {
453 }
454
455 // We put the arguments we're handed into a struct, so we can pass them
456 // around easier.
457 struct ATMPArgs {
458 const int64_t m_accept_time;
459 const bool m_bypass_limits;
460 /*
461 * Return any outpoints which were not previously present in the coins
462 * cache, but were added as a result of validating the tx for mempool
463 * acceptance. This allows the caller to optionally remove the cache
464 * additions if the associated transaction ends up being rejected by
465 * the mempool.
466 */
467 std::vector<COutPoint>& m_coins_to_uncache;
469 const bool m_test_accept;
473 const bool m_allow_replacement;
475 const bool m_allow_sibling_eviction;
478 const bool m_package_submission;
482 const bool m_package_feerates;
487 const std::optional<CFeeRate> m_client_maxfeerate;
488
490 static ATMPArgs SingleAccept(int64_t accept_time,
491 bool bypass_limits, std::vector<COutPoint>& coins_to_uncache,
492 bool test_accept) {
493 return ATMPArgs{/*accept_time=*/ accept_time,
494 /*bypass_limits=*/ bypass_limits,
495 /*coins_to_uncache=*/ coins_to_uncache,
496 /*test_accept=*/ test_accept,
497 /*allow_replacement=*/ true,
498 /*allow_sibling_eviction=*/ true,
499 /*package_submission=*/ false,
500 /*package_feerates=*/ false,
501 /*client_maxfeerate=*/ {}, // checked by caller
502 };
503 }
504
506 static ATMPArgs PackageTestAccept(int64_t accept_time,
507 std::vector<COutPoint>& coins_to_uncache) {
508 return ATMPArgs{/*accept_time=*/ accept_time,
509 /*bypass_limits=*/ false,
510 /*coins_to_uncache=*/ coins_to_uncache,
511 /*test_accept=*/ true,
512 /*allow_replacement=*/ false,
513 /*allow_sibling_eviction=*/ false,
514 /*package_submission=*/ false, // not submitting to mempool
515 /*package_feerates=*/ false,
516 /*client_maxfeerate=*/ {}, // checked by caller
517 };
518 }
519
521 static ATMPArgs PackageChildWithParents(int64_t accept_time,
522 std::vector<COutPoint>& coins_to_uncache, const std::optional<CFeeRate>& client_maxfeerate) {
523 return ATMPArgs{/*accept_time=*/ accept_time,
524 /*bypass_limits=*/ false,
525 /*coins_to_uncache=*/ coins_to_uncache,
526 /*test_accept=*/ false,
527 /*allow_replacement=*/ true,
528 /*allow_sibling_eviction=*/ false,
529 /*package_submission=*/ true,
530 /*package_feerates=*/ true,
531 /*client_maxfeerate=*/ client_maxfeerate,
532 };
533 }
534
536 static ATMPArgs SingleInPackageAccept(const ATMPArgs& package_args) {
537 return ATMPArgs{/*accept_time=*/ package_args.m_accept_time,
538 /*bypass_limits=*/ false,
539 /*coins_to_uncache=*/ package_args.m_coins_to_uncache,
540 /*test_accept=*/ package_args.m_test_accept,
541 /*allow_replacement=*/ true,
542 /*allow_sibling_eviction=*/ true,
543 /*package_submission=*/ true, // trim at the end of AcceptPackage()
544 /*package_feerates=*/ false, // only 1 transaction
545 /*client_maxfeerate=*/ package_args.m_client_maxfeerate,
546 };
547 }
548
549 private:
550 // Private ctor to avoid exposing details to clients and allowing the possibility of
551 // mixing up the order of the arguments. Use static functions above instead.
552 ATMPArgs(int64_t accept_time,
553 bool bypass_limits,
554 std::vector<COutPoint>& coins_to_uncache,
555 bool test_accept,
556 bool allow_replacement,
557 bool allow_sibling_eviction,
558 bool package_submission,
559 bool package_feerates,
560 std::optional<CFeeRate> client_maxfeerate)
561 : m_accept_time{accept_time},
562 m_bypass_limits{bypass_limits},
563 m_coins_to_uncache{coins_to_uncache},
564 m_test_accept{test_accept},
565 m_allow_replacement{allow_replacement},
566 m_allow_sibling_eviction{allow_sibling_eviction},
567 m_package_submission{package_submission},
568 m_package_feerates{package_feerates},
569 m_client_maxfeerate{client_maxfeerate}
570 {
571 // If we are using package feerates, we must be doing package submission.
572 // It also means sibling eviction is not permitted.
573 if (m_package_feerates) {
574 Assume(m_package_submission);
575 Assume(!m_allow_sibling_eviction);
576 }
577 if (m_allow_sibling_eviction) Assume(m_allow_replacement);
578 }
579 };
580
582 void CleanupTemporaryCoins() EXCLUSIVE_LOCKS_REQUIRED(cs_main, m_pool.cs);
583
584 // Single transaction acceptance
585 MempoolAcceptResult AcceptSingleTransactionAndCleanup(const CTransactionRef& ptx, ATMPArgs& args) EXCLUSIVE_LOCKS_REQUIRED(cs_main) {
586 LOCK(m_pool.cs);
587 MempoolAcceptResult result = AcceptSingleTransactionInternal(ptx, args);
588 ClearSubPackageState();
589 return result;
590 }
591 MempoolAcceptResult AcceptSingleTransactionInternal(const CTransactionRef& ptx, ATMPArgs& args) EXCLUSIVE_LOCKS_REQUIRED(cs_main, m_pool.cs);
592
598 PackageMempoolAcceptResult AcceptMultipleTransactionsAndCleanup(const std::vector<CTransactionRef>& txns, ATMPArgs& args) EXCLUSIVE_LOCKS_REQUIRED(cs_main) {
599 LOCK(m_pool.cs);
600 PackageMempoolAcceptResult result = AcceptMultipleTransactionsInternal(txns, args);
601 ClearSubPackageState();
602 return result;
603 }
604 PackageMempoolAcceptResult AcceptMultipleTransactionsInternal(const std::vector<CTransactionRef>& txns, ATMPArgs& args) EXCLUSIVE_LOCKS_REQUIRED(cs_main, m_pool.cs);
605
616 PackageMempoolAcceptResult AcceptSubPackage(const std::vector<CTransactionRef>& subpackage, ATMPArgs& args)
618
623 PackageMempoolAcceptResult AcceptPackage(const Package& package, ATMPArgs& args) EXCLUSIVE_LOCKS_REQUIRED(cs_main);
624
625private:
626 // All the intermediate state that gets passed between the various levels
627 // of checking a given transaction.
628 struct Workspace {
629 explicit Workspace(const CTransactionRef& ptx) : m_ptx(ptx), m_hash(ptx->GetHash()) {}
632 std::set<Txid> m_conflicts;
635 CTxMemPool::setEntries m_iters_conflicting;
637 std::vector<CTxMemPoolEntry::CTxMemPoolEntryRef> m_parents;
638 /* Handle to the tx in the changeset */
642 bool m_sibling_eviction{false};
643
646 int64_t m_vsize;
648 CAmount m_base_fees;
650 CAmount m_modified_fees;
651
655 CFeeRate m_package_feerate{0};
656
657 const CTransactionRef& m_ptx;
659 const Txid& m_hash;
663 PrecomputedTransactionData m_precomputed_txdata;
664 };
665
666 // Run the policy checks on a given transaction, excluding any script checks.
667 // Looks up inputs, calculates feerate, considers replacement, evaluates
668 // package limits, etc. As this function can be invoked for "free" by a peer,
669 // only tests that are fast should be done here (to avoid CPU DoS).
670 bool PreChecks(ATMPArgs& args, Workspace& ws) EXCLUSIVE_LOCKS_REQUIRED(cs_main, m_pool.cs);
671
672 // Run checks for mempool replace-by-fee, only used in AcceptSingleTransaction.
673 bool ReplacementChecks(Workspace& ws) EXCLUSIVE_LOCKS_REQUIRED(cs_main, m_pool.cs);
674
675 bool PackageRBFChecks(const std::vector<CTransactionRef>& txns,
676 std::vector<Workspace>& workspaces,
677 PackageValidationState& package_state) EXCLUSIVE_LOCKS_REQUIRED(cs_main, m_pool.cs);
678
679 // Run the script checks using our policy flags. As this can be slow, we should
680 // only invoke this on transactions that have otherwise passed policy checks.
681 bool PolicyScriptChecks(Workspace& ws) EXCLUSIVE_LOCKS_REQUIRED(cs_main, m_pool.cs);
682
683 // Re-run the script checks, using consensus flags, and try to cache the
684 // result in the scriptcache. This should be done after
685 // PolicyScriptChecks(). This requires that all inputs either be in our
686 // utxo set or in the mempool.
687 bool ConsensusScriptChecks(Workspace& ws) EXCLUSIVE_LOCKS_REQUIRED(cs_main, m_pool.cs);
688
689 // Try to add the transaction to the mempool, removing any conflicts first.
690 void FinalizeSubpackage(const ATMPArgs& args) EXCLUSIVE_LOCKS_REQUIRED(cs_main, m_pool.cs);
691
692 // Submit all transactions to the mempool and call ConsensusScriptChecks to add to the script
693 // cache - should only be called after successful validation of all transactions in the package.
694 // Does not call LimitMempoolSize(), so mempool max_size_bytes may be temporarily exceeded.
695 bool SubmitPackage(const ATMPArgs& args, std::vector<Workspace>& workspaces, PackageValidationState& package_state,
696 std::map<Wtxid, MempoolAcceptResult>& results)
698
699 // Compare a package's feerate against minimum allowed.
700 bool CheckFeeRate(size_t package_size, CAmount package_fee, TxValidationState& state) EXCLUSIVE_LOCKS_REQUIRED(::cs_main, m_pool.cs)
701 {
703 AssertLockHeld(m_pool.cs);
704 CAmount mempoolRejectFee = m_pool.GetMinFee().GetFee(package_size);
705 if (mempoolRejectFee > 0 && package_fee < mempoolRejectFee) {
706 return state.Invalid(TxValidationResult::TX_RECONSIDERABLE, "mempool min fee not met", strprintf("%d < %d", package_fee, mempoolRejectFee));
707 }
708
709 if (package_fee < m_pool.m_opts.min_relay_feerate.GetFee(package_size)) {
710 return state.Invalid(TxValidationResult::TX_RECONSIDERABLE, "min relay fee not met",
711 strprintf("%d < %d", package_fee, m_pool.m_opts.min_relay_feerate.GetFee(package_size)));
712 }
713 return true;
714 }
715
716 ValidationCache& GetValidationCache()
717 {
718 return m_active_chainstate.m_chainman.m_validation_cache;
719 }
720
721private:
722 CTxMemPool& m_pool;
723
735 CCoinsViewCache m_view;
736
737 // These are the two possible backends for m_view.
740 CCoinsViewMemPool m_viewmempool;
741
742 Chainstate& m_active_chainstate;
743
744 // Fields below are per *sub*package state and must be reset prior to subsequent
745 // AcceptSingleTransaction and AcceptMultipleTransactions invocations
746 struct SubPackageState {
748 CAmount m_total_modified_fees{0};
750 int64_t m_total_vsize{0};
751
752 // RBF-related members
755 bool m_rbf{false};
757 std::list<CTransactionRef> m_replaced_transactions;
758 /* Changeset representing adding transactions and removing their conflicts. */
759 std::unique_ptr<CTxMemPool::ChangeSet> m_changeset;
760
762 CAmount m_conflicting_fees{0};
764 size_t m_conflicting_size{0};
765 };
766
767 struct SubPackageState m_subpackage;
768
770 void ClearSubPackageState() EXCLUSIVE_LOCKS_REQUIRED(cs_main, m_pool.cs)
771 {
772 m_subpackage = SubPackageState{};
773
774 // And clean coins while at it
775 CleanupTemporaryCoins();
776 }
777};
778
779bool MemPoolAccept::PreChecks(ATMPArgs& args, Workspace& ws)
780{
782 AssertLockHeld(m_pool.cs);
783 const CTransactionRef& ptx = ws.m_ptx;
784 const CTransaction& tx = *ws.m_ptx;
785 const Txid& hash = ws.m_hash;
786
787 // Copy/alias what we need out of args
788 const int64_t nAcceptTime = args.m_accept_time;
789 const bool bypass_limits = args.m_bypass_limits;
790 std::vector<COutPoint>& coins_to_uncache = args.m_coins_to_uncache;
791
792 // Alias what we need out of ws
793 TxValidationState& state = ws.m_state;
794
795 if (!CheckTransaction(tx, state)) {
796 return false; // state filled in by CheckTransaction
797 }
798
799 // Coinbase is only valid in a block, not as a loose transaction
800 if (tx.IsCoinBase())
801 return state.Invalid(TxValidationResult::TX_CONSENSUS, "coinbase");
802
803 // Rather not work on nonstandard transactions (unless -testnet/-regtest)
804 std::string reason;
805 if (m_pool.m_opts.require_standard && !IsStandardTx(tx, m_pool.m_opts.max_datacarrier_bytes, m_pool.m_opts.permit_bare_multisig, m_pool.m_opts.dust_relay_feerate, reason)) {
806 return state.Invalid(TxValidationResult::TX_NOT_STANDARD, reason);
807 }
808
809 // Transactions smaller than 65 non-witness bytes are not relayed to mitigate CVE-2017-12842.
811 return state.Invalid(TxValidationResult::TX_NOT_STANDARD, "tx-size-small");
812
813 // Only accept nLockTime-using transactions that can be mined in the next
814 // block; we don't want our mempool filled up with transactions that can't
815 // be mined yet.
816 if (!CheckFinalTxAtTip(*Assert(m_active_chainstate.m_chain.Tip()), tx)) {
817 return state.Invalid(TxValidationResult::TX_PREMATURE_SPEND, "non-final");
818 }
819
820 if (m_pool.exists(tx.GetWitnessHash())) {
821 // Exact transaction already exists in the mempool.
822 return state.Invalid(TxValidationResult::TX_CONFLICT, "txn-already-in-mempool");
823 } else if (m_pool.exists(tx.GetHash())) {
824 // Transaction with the same non-witness data but different witness (same txid, different
825 // wtxid) already exists in the mempool.
826 return state.Invalid(TxValidationResult::TX_CONFLICT, "txn-same-nonwitness-data-in-mempool");
827 }
828
829 // Check for conflicts with in-memory transactions
830 for (const CTxIn &txin : tx.vin)
831 {
832 const CTransaction* ptxConflicting = m_pool.GetConflictTx(txin.prevout);
833 if (ptxConflicting) {
834 if (!args.m_allow_replacement) {
835 // Transaction conflicts with a mempool tx, but we're not allowing replacements in this context.
836 return state.Invalid(TxValidationResult::TX_MEMPOOL_POLICY, "bip125-replacement-disallowed");
837 }
838 ws.m_conflicts.insert(ptxConflicting->GetHash());
839 }
840 }
841
842 m_view.SetBackend(m_viewmempool);
843
844 const CCoinsViewCache& coins_cache = m_active_chainstate.CoinsTip();
845 // do all inputs exist?
846 for (const CTxIn& txin : tx.vin) {
847 if (!coins_cache.HaveCoinInCache(txin.prevout)) {
848 coins_to_uncache.push_back(txin.prevout);
849 }
850
851 // Note: this call may add txin.prevout to the coins cache
852 // (coins_cache.cacheCoins) by way of FetchCoin(). It should be removed
853 // later (via coins_to_uncache) if this tx turns out to be invalid.
854 if (!m_view.HaveCoin(txin.prevout)) {
855 // Are inputs missing because we already have the tx?
856 for (size_t out = 0; out < tx.vout.size(); out++) {
857 // Optimistically just do efficient check of cache for outputs
858 if (coins_cache.HaveCoinInCache(COutPoint(hash, out))) {
859 return state.Invalid(TxValidationResult::TX_CONFLICT, "txn-already-known");
860 }
861 }
862 // Otherwise assume this might be an orphan tx for which we just haven't seen parents yet
863 return state.Invalid(TxValidationResult::TX_MISSING_INPUTS, "bad-txns-inputs-missingorspent");
864 }
865 }
866
867 // This is const, but calls into `CCoinsViewCache::GetBestBlock()` to refresh
868 // the cached best block through `m_viewmempool` after caching inputs.
869 (void)m_view.GetBestBlock();
870
871 // All required inputs are cached now, so switch m_view to the empty backend.
872 // This keeps already-fetched cache entries for later checks and prevents new
873 // backend lookups (which would avoid coins_to_uncache tracking).
874 m_view.SetBackend(CoinsViewEmpty::Get());
875
876 assert(m_active_chainstate.m_blockman.LookupBlockIndex(m_view.GetBestBlock()) == m_active_chainstate.m_chain.Tip());
877
878 // Only accept BIP68 sequence locked transactions that can be mined in the next
879 // block; we don't want our mempool filled up with transactions that can't
880 // be mined yet.
881 // Pass in m_view which has all of the relevant inputs cached. Note that, since m_view's
882 // backend was removed, it no longer pulls coins from the mempool.
883 const std::optional<LockPoints> lock_points{CalculateLockPointsAtTip(m_active_chainstate.m_chain.Tip(), m_view, tx)};
884 if (!lock_points.has_value() || !CheckSequenceLocksAtTip(m_active_chainstate.m_chain.Tip(), *lock_points)) {
885 return state.Invalid(TxValidationResult::TX_PREMATURE_SPEND, "non-BIP68-final");
886 }
887
888 // The mempool holds txs for the next block, so pass height+1 to CheckTxInputs
889 if (!Consensus::CheckTxInputs(tx, state, m_view, m_active_chainstate.m_chain.Height() + 1, ws.m_base_fees)) {
890 return false; // state filled in by CheckTxInputs
891 }
892
893 if (m_pool.m_opts.require_standard) {
894 state = ValidateInputsStandardness(tx, m_view);
895 if (state.IsInvalid()) {
896 return false;
897 }
898 }
899
900 // Check for non-standard witnesses.
901 if (tx.HasWitness() && m_pool.m_opts.require_standard && !IsWitnessStandard(tx, m_view)) {
902 return state.Invalid(TxValidationResult::TX_WITNESS_MUTATED, "bad-witness-nonstandard");
903 }
904
905 int64_t nSigOpsCost = GetTransactionSigOpCost(tx, m_view, STANDARD_SCRIPT_VERIFY_FLAGS);
906
907 // Keep track of transactions that spend a coinbase, which we re-scan
908 // during reorgs to ensure COINBASE_MATURITY is still met.
909 bool fSpendsCoinbase = false;
910 for (const CTxIn &txin : tx.vin) {
911 const Coin &coin = m_view.AccessCoin(txin.prevout);
912 if (coin.IsCoinBase()) {
913 fSpendsCoinbase = true;
914 break;
915 }
916 }
917
918 // Set entry_sequence to 0 when bypass_limits is used; this allows txs from a block
919 // reorg to be marked earlier than any child txs that were already in the mempool.
920 const uint64_t entry_sequence = bypass_limits ? 0 : m_pool.GetSequence();
921 if (!m_subpackage.m_changeset) {
922 m_subpackage.m_changeset = m_pool.GetChangeSet();
923 }
924 ws.m_tx_handle = m_subpackage.m_changeset->StageAddition(ptx, ws.m_base_fees, nAcceptTime, m_active_chainstate.m_chain.Height(), entry_sequence, fSpendsCoinbase, nSigOpsCost, lock_points.value());
925
926 // ws.m_modified_fees includes any fee deltas from PrioritiseTransaction
927 ws.m_modified_fees = ws.m_tx_handle->GetModifiedFee();
928
929 ws.m_vsize = ws.m_tx_handle->GetTxSize();
930
931 // Enforces 0-fee for dust transactions, no incentive to be mined alone
932 if (m_pool.m_opts.require_standard) {
933 if (!PreCheckEphemeralTx(*ptx, m_pool.m_opts.dust_relay_feerate, ws.m_base_fees, ws.m_modified_fees, state)) {
934 return false; // state filled in by PreCheckEphemeralTx
935 }
936 }
937
938 if (nSigOpsCost > MAX_STANDARD_TX_SIGOPS_COST)
939 return state.Invalid(TxValidationResult::TX_NOT_STANDARD, "bad-txns-too-many-sigops",
940 strprintf("%d", nSigOpsCost));
941
942 // No individual transactions are allowed below the mempool min feerate except from disconnected
943 // blocks and transactions in a package. Package transactions will be checked using package
944 // feerate later.
945 if (!bypass_limits && !args.m_package_feerates && !CheckFeeRate(ws.m_vsize, ws.m_modified_fees, state)) return false;
946
947 ws.m_iters_conflicting = m_pool.GetIterSet(ws.m_conflicts);
948
949 ws.m_parents = m_pool.GetParents(*ws.m_tx_handle);
950
951 if (!args.m_bypass_limits) {
952 // Perform the TRUC checks, using the in-mempool parents.
953 if (const auto err{SingleTRUCChecks(m_pool, ws.m_ptx, ws.m_parents, ws.m_conflicts, ws.m_vsize)}) {
954 // Single transaction contexts only.
955 if (args.m_allow_sibling_eviction && err->second != nullptr) {
956 // We should only be considering where replacement is considered valid as well.
957 Assume(args.m_allow_replacement);
958 // Potential sibling eviction. Add the sibling to our list of mempool conflicts to be
959 // included in RBF checks.
960 ws.m_conflicts.insert(err->second->GetHash());
961 // Adding the sibling to m_iters_conflicting here means that it doesn't count towards
962 // RBF Carve Out above. This is correct, since removing to-be-replaced transactions from
963 // the descendant count is done separately in SingleTRUCChecks for TRUC transactions.
964 ws.m_iters_conflicting.insert(m_pool.GetIter(err->second->GetHash()).value());
965 ws.m_sibling_eviction = true;
966 // The sibling will be treated as part of the to-be-replaced set in ReplacementChecks.
967 // Note that we are not checking whether it opts in to replaceability via BIP125 or TRUC
968 // (which is normally done in PreChecks). However, the only way a TRUC transaction can
969 // have a non-TRUC and non-BIP125 descendant is due to a reorg.
970 } else {
971 return state.Invalid(TxValidationResult::TX_MEMPOOL_POLICY, "TRUC-violation", err->first);
972 }
973 }
974 }
975
976 // We want to detect conflicts in any tx in a package to trigger package RBF logic
977 m_subpackage.m_rbf |= !ws.m_conflicts.empty();
978 return true;
979}
980
981bool MemPoolAccept::ReplacementChecks(Workspace& ws)
982{
984 AssertLockHeld(m_pool.cs);
985
986 const CTransaction& tx = *ws.m_ptx;
987 const Txid& hash = ws.m_hash;
988 TxValidationState& state = ws.m_state;
989
990 CTxMemPool::setEntries all_conflicts;
991
992 // Calculate all conflicting entries and enforce Rule #5.
993 if (const auto err_string{GetEntriesForConflicts(tx, m_pool, ws.m_iters_conflicting, all_conflicts)}) {
995 strprintf("too many potential replacements%s", ws.m_sibling_eviction ? " (including sibling eviction)" : ""), *err_string);
996 }
997
998 // Check if it's economically rational to mine this transaction rather than the ones it
999 // replaces and pays for its own relay fees. Enforce Rules #3 and #4.
1000 for (CTxMemPool::txiter it : all_conflicts) {
1001 m_subpackage.m_conflicting_fees += it->GetModifiedFee();
1002 m_subpackage.m_conflicting_size += it->GetTxSize();
1003 }
1004
1005 if (const auto err_string{PaysForRBF(m_subpackage.m_conflicting_fees, ws.m_modified_fees, ws.m_vsize,
1006 m_pool.m_opts.incremental_relay_feerate, hash)}) {
1007 // Result may change in a package context
1009 strprintf("insufficient fee%s", ws.m_sibling_eviction ? " (including sibling eviction)" : ""), *err_string);
1010 }
1011
1012 // Add all the to-be-removed transactions to the changeset.
1013 for (auto it : all_conflicts) {
1014 m_subpackage.m_changeset->StageRemoval(it);
1015 }
1016
1017 // Run cluster size limit checks and fail if we exceed them.
1018 if (!m_subpackage.m_changeset->CheckMemPoolPolicyLimits()) {
1019 return state.Invalid(TxValidationResult::TX_MEMPOOL_POLICY, "too-large-cluster", "");
1020 }
1021
1022 if (const auto err_string{ImprovesFeerateDiagram(*m_subpackage.m_changeset)}) {
1023 // We checked above for the cluster size limits being respected, so a
1024 // failure here can only be due to an insufficient fee.
1025 Assume(err_string->first == DiagramCheckError::FAILURE);
1026 return state.Invalid(TxValidationResult::TX_RECONSIDERABLE, "replacement-failed", err_string->second);
1027 }
1028
1029 return true;
1030}
1031
1032bool MemPoolAccept::PackageRBFChecks(const std::vector<CTransactionRef>& txns,
1033 std::vector<Workspace>& workspaces,
1034 PackageValidationState& package_state)
1035{
1037 AssertLockHeld(m_pool.cs);
1038
1039 assert(std::all_of(txns.cbegin(), txns.cend(), [this](const auto& tx)
1040 { return !m_pool.exists(tx->GetHash());}));
1041
1042 assert(txns.size() == workspaces.size());
1043
1044 // We're in package RBF context; replacement proposal must be size 2
1045 if (workspaces.size() != 2 || !Assume(IsChildWithParents(txns))) {
1046 return package_state.Invalid(PackageValidationResult::PCKG_POLICY, "package RBF failed: package must be 1-parent-1-child");
1047 }
1048
1049 // If the package has in-mempool parents, we won't consider a package RBF
1050 // since it would result in a cluster larger than 2.
1051 // N.B. To relax this constraint we will need to revisit how CCoinsViewMemPool::PackageAddTransaction
1052 // is being used inside AcceptMultipleTransactions to track available inputs while processing a package.
1053 // Specifically we would need to check that the ancestors of the new
1054 // transactions don't intersect with the set of transactions to be removed
1055 // due to RBF, which is not checked at all in the package acceptance
1056 // context.
1057 for (const auto& ws : workspaces) {
1058 if (!ws.m_parents.empty()) {
1059 return package_state.Invalid(PackageValidationResult::PCKG_POLICY, "package RBF failed: new transaction cannot have mempool ancestors");
1060 }
1061 }
1062
1063 // Aggregate all conflicts into one set.
1064 CTxMemPool::setEntries direct_conflict_iters;
1065 for (Workspace& ws : workspaces) {
1066 // Aggregate all conflicts into one set.
1067 direct_conflict_iters.merge(ws.m_iters_conflicting);
1068 }
1069
1070 const auto& parent_ws = workspaces[0];
1071 const auto& child_ws = workspaces[1];
1072
1073 // Don't consider replacements that would cause us to remove a large number of mempool entries.
1074 // This limit is not increased in a package RBF. Use the aggregate number of transactions.
1075 CTxMemPool::setEntries all_conflicts;
1076 if (const auto err_string{GetEntriesForConflicts(*child_ws.m_ptx, m_pool, direct_conflict_iters,
1077 all_conflicts)}) {
1078 return package_state.Invalid(PackageValidationResult::PCKG_POLICY,
1079 "package RBF failed: too many potential replacements", *err_string);
1080 }
1081
1082 for (CTxMemPool::txiter it : all_conflicts) {
1083 m_subpackage.m_changeset->StageRemoval(it);
1084 m_subpackage.m_conflicting_fees += it->GetModifiedFee();
1085 m_subpackage.m_conflicting_size += it->GetTxSize();
1086 }
1087
1088 // Use the child as the transaction for attributing errors to.
1089 const Txid& child_hash = child_ws.m_ptx->GetHash();
1090 if (const auto err_string{PaysForRBF(/*original_fees=*/m_subpackage.m_conflicting_fees,
1091 /*replacement_fees=*/m_subpackage.m_total_modified_fees,
1092 /*replacement_vsize=*/m_subpackage.m_total_vsize,
1093 m_pool.m_opts.incremental_relay_feerate, child_hash)}) {
1094 return package_state.Invalid(PackageValidationResult::PCKG_POLICY,
1095 "package RBF failed: insufficient anti-DoS fees", *err_string);
1096 }
1097
1098 // Ensure this two transaction package is a "chunk" on its own; we don't want the child
1099 // to be only paying anti-DoS fees
1100 const CFeeRate parent_feerate(parent_ws.m_modified_fees, parent_ws.m_vsize);
1101 const CFeeRate package_feerate(m_subpackage.m_total_modified_fees, m_subpackage.m_total_vsize);
1102 if (package_feerate <= parent_feerate) {
1103 return package_state.Invalid(PackageValidationResult::PCKG_POLICY,
1104 "package RBF failed: package feerate is less than or equal to parent feerate",
1105 strprintf("package feerate %s <= parent feerate is %s", package_feerate.ToString(), parent_feerate.ToString()));
1106 }
1107
1108 // Run cluster size limit checks and fail if we exceed them.
1109 if (!m_subpackage.m_changeset->CheckMemPoolPolicyLimits()) {
1110 return package_state.Invalid(PackageValidationResult::PCKG_POLICY, "too-large-cluster", "");
1111 }
1112
1113 // Check if it's economically rational to mine this package rather than the ones it replaces.
1114 if (const auto err_tup{ImprovesFeerateDiagram(*m_subpackage.m_changeset)}) {
1115 Assume(err_tup->first == DiagramCheckError::FAILURE);
1116 return package_state.Invalid(PackageValidationResult::PCKG_POLICY,
1117 "package RBF failed: " + err_tup.value().second, "");
1118 }
1119
1120 LogDebug(BCLog::TXPACKAGES, "package RBF checks passed: parent %s (wtxid=%s), child %s (wtxid=%s), package hash (%s)\n",
1121 txns.front()->GetHash().ToString(), txns.front()->GetWitnessHash().ToString(),
1122 txns.back()->GetHash().ToString(), txns.back()->GetWitnessHash().ToString(),
1123 GetPackageHash(txns).ToString());
1124
1125
1126 return true;
1127}
1128
1129bool MemPoolAccept::PolicyScriptChecks(Workspace& ws)
1130{
1132 AssertLockHeld(m_pool.cs);
1133 const CTransaction& tx = *ws.m_ptx;
1134 TxValidationState& state = ws.m_state;
1135
1136 constexpr script_verify_flags scriptVerifyFlags = STANDARD_SCRIPT_VERIFY_FLAGS;
1137
1138 // Check input scripts and signatures.
1139 // This is done last to help prevent CPU exhaustion denial-of-service attacks.
1140 if (!CheckInputScripts(tx, state, m_view, scriptVerifyFlags, true, false, ws.m_precomputed_txdata, GetValidationCache())) {
1141 // Detect a failure due to a missing witness so that p2p code can handle rejection caching appropriately.
1142 if (!tx.HasWitness() && SpendsNonAnchorWitnessProg(tx, m_view)) {
1144 state.GetRejectReason(), state.GetDebugMessage());
1145 }
1146 return false; // state filled in by CheckInputScripts
1147 }
1148
1149 return true;
1150}
1151
1152bool MemPoolAccept::ConsensusScriptChecks(Workspace& ws)
1153{
1155 AssertLockHeld(m_pool.cs);
1156 const CTransaction& tx = *ws.m_ptx;
1157 const Txid& hash = ws.m_hash;
1158 TxValidationState& state = ws.m_state;
1159
1160 // Check again against the current block tip's script verification
1161 // flags to cache our script execution flags. This is, of course,
1162 // useless if the next block has different script flags from the
1163 // previous one, but because the cache tracks script flags for us it
1164 // will auto-invalidate and we'll just have a few blocks of extra
1165 // misses on soft-fork activation.
1166 //
1167 // This is also useful in case of bugs in the standard flags that cause
1168 // transactions to pass as valid when they're actually invalid. For
1169 // instance the STRICTENC flag was incorrectly allowing certain
1170 // CHECKSIG NOT scripts to pass, even though they were invalid.
1171 //
1172 // There is a similar check in CreateNewBlock() to prevent creating
1173 // invalid blocks (using TestBlockValidity), however allowing such
1174 // transactions into the mempool can be exploited as a DoS attack.
1175 script_verify_flags currentBlockScriptVerifyFlags{GetBlockScriptFlags(*m_active_chainstate.m_chain.Tip(), m_active_chainstate.m_chainman)};
1176 if (!CheckInputsFromMempoolAndCache(tx, state, m_view, m_pool, currentBlockScriptVerifyFlags,
1177 ws.m_precomputed_txdata, m_active_chainstate.CoinsTip(), GetValidationCache())) {
1178 LogError("BUG! PLEASE REPORT THIS! CheckInputScripts failed against latest-block but not STANDARD flags %s, %s", hash.ToString(), state.ToString());
1179 return Assume(false);
1180 }
1181
1182 return true;
1183}
1184
1185void MemPoolAccept::FinalizeSubpackage(const ATMPArgs& args)
1186{
1188 AssertLockHeld(m_pool.cs);
1189
1190 if (!m_subpackage.m_changeset->GetRemovals().empty()) Assume(args.m_allow_replacement);
1191 // Remove conflicting transactions from the mempool
1192 for (CTxMemPool::txiter it : m_subpackage.m_changeset->GetRemovals())
1193 {
1194 std::string log_string = strprintf("replacing mempool tx %s (wtxid=%s, fees=%s, vsize=%s). ",
1195 it->GetTx().GetHash().ToString(),
1196 it->GetTx().GetWitnessHash().ToString(),
1197 it->GetFee(),
1198 it->GetTxSize());
1199 FeeFrac feerate{m_subpackage.m_total_modified_fees, int32_t(m_subpackage.m_total_vsize)};
1200 uint256 tx_or_package_hash{};
1201 const bool replaced_with_tx{m_subpackage.m_changeset->GetTxCount() == 1};
1202 if (replaced_with_tx) {
1203 const CTransaction& tx = m_subpackage.m_changeset->GetAddedTxn(0);
1204 tx_or_package_hash = tx.GetHash().ToUint256();
1205 log_string += strprintf("New tx %s (wtxid=%s, fees=%s, vsize=%s)",
1206 tx.GetHash().ToString(),
1207 tx.GetWitnessHash().ToString(),
1208 feerate.fee,
1209 feerate.size);
1210 } else {
1211 tx_or_package_hash = GetPackageHash(m_subpackage.m_changeset->GetAddedTxns());
1212 log_string += strprintf("New package %s with %lu txs, fees=%s, vsize=%s",
1213 tx_or_package_hash.ToString(),
1214 m_subpackage.m_changeset->GetTxCount(),
1215 feerate.fee,
1216 feerate.size);
1217
1218 }
1219 LogDebug(BCLog::MEMPOOL, "%s\n", log_string);
1220 TRACEPOINT(mempool, replaced,
1221 it->GetTx().GetHash().data(),
1222 it->GetTxSize(),
1223 it->GetFee(),
1224 std::chrono::duration_cast<std::chrono::duration<std::uint64_t>>(it->GetTime()).count(),
1225 tx_or_package_hash.data(),
1226 feerate.size,
1227 feerate.fee,
1228 replaced_with_tx
1229 );
1230 m_subpackage.m_replaced_transactions.push_back(it->GetSharedTx());
1231 }
1232 m_subpackage.m_changeset->Apply();
1233 m_subpackage.m_changeset.reset();
1234}
1235
1236bool MemPoolAccept::SubmitPackage(const ATMPArgs& args, std::vector<Workspace>& workspaces,
1237 PackageValidationState& package_state,
1238 std::map<Wtxid, MempoolAcceptResult>& results)
1239{
1241 AssertLockHeld(m_pool.cs);
1242 // Sanity check: none of the transactions should be in the mempool, and none of the transactions
1243 // should have a same-txid-different-witness equivalent in the mempool.
1244 assert(std::all_of(workspaces.cbegin(), workspaces.cend(), [this](const auto& ws) { return !m_pool.exists(ws.m_ptx->GetHash()); }));
1245
1246 bool all_submitted = true;
1247 FinalizeSubpackage(args);
1248 // ConsensusScriptChecks adds to the script cache and is therefore consensus-critical;
1249 // CheckInputsFromMempoolAndCache asserts that transactions only spend coins available from the
1250 // mempool or UTXO set. Submit each transaction to the mempool immediately after calling
1251 // ConsensusScriptChecks to make the outputs available for subsequent transactions.
1252 for (Workspace& ws : workspaces) {
1253 if (!ConsensusScriptChecks(ws)) {
1254 results.emplace(ws.m_ptx->GetWitnessHash(), MempoolAcceptResult::Failure(ws.m_state));
1255 // Since PolicyScriptChecks() passed, this should never fail.
1256 Assume(false);
1257 all_submitted = false;
1259 strprintf("BUG! PolicyScriptChecks succeeded but ConsensusScriptChecks failed: %s",
1260 ws.m_ptx->GetHash().ToString()));
1261 }
1262 // Remove first failing tx and all subsequent in package
1263 if (!all_submitted) {
1264 if (!m_subpackage.m_changeset) m_subpackage.m_changeset = m_pool.GetChangeSet();
1265 m_subpackage.m_changeset->StageRemoval(m_pool.GetIter(ws.m_ptx->GetHash()).value());
1266 }
1267 }
1268 if (!all_submitted) {
1269 Assume(m_subpackage.m_changeset);
1270 // This code should be unreachable; it's here as belt-and-suspenders
1271 // to try to ensure we have no consensus-invalid transactions in the
1272 // mempool.
1273 m_subpackage.m_changeset->Apply();
1274 m_subpackage.m_changeset.reset();
1275 return false;
1276 }
1277
1278 std::vector<Wtxid> all_package_wtxids;
1279 all_package_wtxids.reserve(workspaces.size());
1280 std::transform(workspaces.cbegin(), workspaces.cend(), std::back_inserter(all_package_wtxids),
1281 [](const auto& ws) { return ws.m_ptx->GetWitnessHash(); });
1282
1283 if (!m_subpackage.m_replaced_transactions.empty()) {
1284 LogDebug(BCLog::MEMPOOL, "replaced %u mempool transactions with %u new one(s) for %s additional fees, %d delta bytes\n",
1285 m_subpackage.m_replaced_transactions.size(), workspaces.size(),
1286 m_subpackage.m_total_modified_fees - m_subpackage.m_conflicting_fees,
1287 m_subpackage.m_total_vsize - static_cast<int>(m_subpackage.m_conflicting_size));
1288 }
1289
1290 // Add successful results. The returned results may change later if LimitMempoolSize() evicts them.
1291 for (Workspace& ws : workspaces) {
1292 auto iter = m_pool.GetIter(ws.m_ptx->GetHash());
1293 Assume(iter.has_value());
1294 const auto effective_feerate = args.m_package_feerates ? ws.m_package_feerate :
1295 CFeeRate{ws.m_modified_fees, static_cast<int32_t>(ws.m_vsize)};
1296 const auto effective_feerate_wtxids = args.m_package_feerates ? all_package_wtxids :
1297 std::vector<Wtxid>{ws.m_ptx->GetWitnessHash()};
1298 results.emplace(ws.m_ptx->GetWitnessHash(),
1299 MempoolAcceptResult::Success(std::move(m_subpackage.m_replaced_transactions), ws.m_vsize,
1300 ws.m_base_fees, effective_feerate, effective_feerate_wtxids));
1301 if (!m_pool.m_opts.signals) continue;
1302 const CTransaction& tx = *ws.m_ptx;
1303 const auto tx_info = NewMempoolTransactionInfo(ws.m_ptx, ws.m_base_fees,
1304 ws.m_vsize, (*iter)->GetHeight(),
1305 args.m_bypass_limits, args.m_package_submission,
1306 IsCurrentForFeeEstimation(m_active_chainstate),
1307 m_pool.HasNoInputsOf(tx));
1308 m_pool.m_opts.signals->TransactionAddedToMempool(tx_info, m_pool.GetAndIncrementSequence());
1309 }
1310 return all_submitted;
1311}
1312
1313MempoolAcceptResult MemPoolAccept::AcceptSingleTransactionInternal(const CTransactionRef& ptx, ATMPArgs& args)
1314{
1316 AssertLockHeld(m_pool.cs);
1317
1318 Workspace ws(ptx);
1319 const std::vector<Wtxid> single_wtxid{ws.m_ptx->GetWitnessHash()};
1320
1321 if (!PreChecks(args, ws)) {
1322 if (ws.m_state.GetResult() == TxValidationResult::TX_RECONSIDERABLE) {
1323 // Failed for fee reasons. Provide the effective feerate and which tx was included.
1324 return MempoolAcceptResult::FeeFailure(ws.m_state, CFeeRate(ws.m_modified_fees, ws.m_vsize), single_wtxid);
1325 }
1326 return MempoolAcceptResult::Failure(ws.m_state);
1327 }
1328
1329 if (m_subpackage.m_rbf && !ReplacementChecks(ws)) {
1330 if (ws.m_state.GetResult() == TxValidationResult::TX_RECONSIDERABLE) {
1331 // Failed for incentives-based fee reasons. Provide the effective feerate and which tx was included.
1332 return MempoolAcceptResult::FeeFailure(ws.m_state, CFeeRate(ws.m_modified_fees, ws.m_vsize), single_wtxid);
1333 }
1334 return MempoolAcceptResult::Failure(ws.m_state);
1335 }
1336
1337 // Check if the transaction would exceed the cluster size limit.
1338 if (!m_subpackage.m_changeset->CheckMemPoolPolicyLimits()) {
1339 ws.m_state.Invalid(TxValidationResult::TX_MEMPOOL_POLICY, "too-large-cluster", "");
1340 return MempoolAcceptResult::Failure(ws.m_state);
1341 }
1342
1343 // Now that we've verified the cluster limit is respected, we can perform
1344 // calculations involving the full ancestors of the tx.
1345 if (ws.m_conflicts.size()) {
1346 auto ancestors = m_subpackage.m_changeset->CalculateMemPoolAncestors(ws.m_tx_handle);
1347
1348 // A transaction that spends outputs that would be replaced by it is invalid. Now
1349 // that we have the set of all ancestors we can detect this
1350 // pathological case by making sure ws.m_conflicts and this tx's ancestors don't
1351 // intersect.
1352 if (const auto err_string{EntriesAndTxidsDisjoint(ancestors, ws.m_conflicts, ptx->GetHash())}) {
1353 // We classify this as a consensus error because a transaction depending on something it
1354 // conflicts with would be inconsistent.
1355 ws.m_state.Invalid(TxValidationResult::TX_CONSENSUS, "bad-txns-spends-conflicting-tx", *err_string);
1356 return MempoolAcceptResult::Failure(ws.m_state);
1357 }
1358 }
1359
1360 m_subpackage.m_total_vsize = ws.m_vsize;
1361 m_subpackage.m_total_modified_fees = ws.m_modified_fees;
1362
1363 // Individual modified feerate exceeded caller-defined max; abort
1364 if (args.m_client_maxfeerate && CFeeRate(ws.m_modified_fees, ws.m_vsize) > args.m_client_maxfeerate.value()) {
1365 ws.m_state.Invalid(TxValidationResult::TX_MEMPOOL_POLICY, "max feerate exceeded", "");
1366 return MempoolAcceptResult::Failure(ws.m_state);
1367 }
1368
1369 if (!args.m_bypass_limits && m_pool.m_opts.require_standard) {
1370 Wtxid dummy_wtxid;
1371 if (!CheckEphemeralSpends(/*package=*/{ptx}, m_pool.m_opts.dust_relay_feerate, m_pool, ws.m_state, dummy_wtxid)) {
1372 return MempoolAcceptResult::Failure(ws.m_state);
1373 }
1374 }
1375
1376 // Perform the inexpensive checks first and avoid hashing and signature verification unless
1377 // those checks pass, to mitigate CPU exhaustion denial-of-service attacks.
1378 if (!PolicyScriptChecks(ws)) return MempoolAcceptResult::Failure(ws.m_state);
1379
1380 if (!ConsensusScriptChecks(ws)) return MempoolAcceptResult::Failure(ws.m_state);
1381
1382 const CFeeRate effective_feerate{ws.m_modified_fees, static_cast<int32_t>(ws.m_vsize)};
1383 // Tx was accepted, but not added
1384 if (args.m_test_accept) {
1385 return MempoolAcceptResult::Success(std::move(m_subpackage.m_replaced_transactions), ws.m_vsize,
1386 ws.m_base_fees, effective_feerate, single_wtxid);
1387 }
1388
1389 FinalizeSubpackage(args);
1390
1391 // Limit the mempool, if appropriate.
1392 if (!args.m_package_submission && !args.m_bypass_limits) {
1393 LimitMempoolSize(m_pool, m_active_chainstate.CoinsTip());
1394 // If mempool contents change, then the m_view cache is dirty. Given this isn't a package
1395 // submission, we won't be using the cache anymore, but clear it anyway for clarity.
1396 CleanupTemporaryCoins();
1397
1398 if (!m_pool.exists(ws.m_hash)) {
1399 // The tx no longer meets our (new) mempool minimum feerate but could be reconsidered in a package.
1400 ws.m_state.Invalid(TxValidationResult::TX_RECONSIDERABLE, "mempool full");
1401 return MempoolAcceptResult::FeeFailure(ws.m_state, CFeeRate(ws.m_modified_fees, ws.m_vsize), {ws.m_ptx->GetWitnessHash()});
1402 }
1403 }
1404
1405 if (m_pool.m_opts.signals) {
1406 const CTransaction& tx = *ws.m_ptx;
1407 auto iter = m_pool.GetIter(tx.GetHash());
1408 Assume(iter.has_value());
1409 const auto tx_info = NewMempoolTransactionInfo(ws.m_ptx, ws.m_base_fees,
1410 ws.m_vsize, (*iter)->GetHeight(),
1411 args.m_bypass_limits, args.m_package_submission,
1412 IsCurrentForFeeEstimation(m_active_chainstate),
1413 m_pool.HasNoInputsOf(tx));
1414 m_pool.m_opts.signals->TransactionAddedToMempool(tx_info, m_pool.GetAndIncrementSequence());
1415 }
1416
1417 if (!m_subpackage.m_replaced_transactions.empty()) {
1418 LogDebug(BCLog::MEMPOOL, "replaced %u mempool transactions with 1 new transaction for %s additional fees, %d delta bytes\n",
1419 m_subpackage.m_replaced_transactions.size(),
1420 ws.m_modified_fees - m_subpackage.m_conflicting_fees,
1421 ws.m_vsize - static_cast<int>(m_subpackage.m_conflicting_size));
1422 }
1423
1424 return MempoolAcceptResult::Success(std::move(m_subpackage.m_replaced_transactions), ws.m_vsize, ws.m_base_fees,
1425 effective_feerate, single_wtxid);
1426}
1427
1428PackageMempoolAcceptResult MemPoolAccept::AcceptMultipleTransactionsInternal(const std::vector<CTransactionRef>& txns, ATMPArgs& args)
1429{
1431 AssertLockHeld(m_pool.cs);
1432
1433 // These context-free package limits can be done before taking the mempool lock.
1434 PackageValidationState package_state;
1435 if (!IsWellFormedPackage(txns, package_state)) return PackageMempoolAcceptResult(package_state, {});
1436
1437 std::vector<Workspace> workspaces{};
1438 workspaces.reserve(txns.size());
1439 std::transform(txns.cbegin(), txns.cend(), std::back_inserter(workspaces),
1440 [](const auto& tx) { return Workspace(tx); });
1441 std::map<Wtxid, MempoolAcceptResult> results;
1442
1443 // Do all PreChecks first and fail fast to avoid running expensive script checks when unnecessary.
1444 for (Workspace& ws : workspaces) {
1445 if (!PreChecks(args, ws)) {
1446 package_state.Invalid(PackageValidationResult::PCKG_TX, "transaction failed");
1447 // Exit early to avoid doing pointless work. Update the failed tx result; the rest are unfinished.
1448 results.emplace(ws.m_ptx->GetWitnessHash(), MempoolAcceptResult::Failure(ws.m_state));
1449 return PackageMempoolAcceptResult(package_state, std::move(results));
1450 }
1451
1452 // Individual modified feerate exceeded caller-defined max; abort
1453 // N.B. this doesn't take into account CPFPs. Chunk-aware validation may be more robust.
1454 if (args.m_client_maxfeerate && CFeeRate(ws.m_modified_fees, ws.m_vsize) > args.m_client_maxfeerate.value()) {
1455 // Need to set failure here both individually and at package level
1456 ws.m_state.Invalid(TxValidationResult::TX_MEMPOOL_POLICY, "max feerate exceeded", "");
1457 package_state.Invalid(PackageValidationResult::PCKG_TX, "transaction failed");
1458 // Exit early to avoid doing pointless work. Update the failed tx result; the rest are unfinished.
1459 results.emplace(ws.m_ptx->GetWitnessHash(), MempoolAcceptResult::Failure(ws.m_state));
1460 return PackageMempoolAcceptResult(package_state, std::move(results));
1461 }
1462
1463 // Make the coins created by this transaction available for subsequent transactions in the
1464 // package to spend. If there are no conflicts within the package, no transaction can spend a coin
1465 // needed by another transaction in the package. We also need to make sure that no package
1466 // tx replaces (or replaces the ancestor of) the parent of another package tx. As long as we
1467 // check these two things, we don't need to track the coins spent.
1468 // If a package tx conflicts with a mempool tx, PackageRBFChecks() ensures later that any package RBF attempt
1469 // has *no* in-mempool ancestors, so we don't have to worry about subsequent transactions in
1470 // same package spending the same in-mempool outpoints. This needs to be revisited for general
1471 // package RBF.
1472 m_viewmempool.PackageAddTransaction(ws.m_ptx);
1473 }
1474
1475 // At this point we have all in-mempool parents, and we know every transaction's vsize.
1476 // Run the TRUC checks on the package.
1477 for (Workspace& ws : workspaces) {
1478 if (auto err{PackageTRUCChecks(m_pool, ws.m_ptx, ws.m_vsize, txns, ws.m_parents)}) {
1479 package_state.Invalid(PackageValidationResult::PCKG_POLICY, "TRUC-violation", err.value());
1480 return PackageMempoolAcceptResult(package_state, {});
1481 }
1482 }
1483
1484 // Transactions must meet two minimum feerates: the mempool minimum fee and min relay fee.
1485 // For transactions consisting of exactly one child and its parents, it suffices to use the
1486 // package feerate (total modified fees / total virtual size) to check this requirement.
1487 // Note that this is an aggregate feerate; this function has not checked that there are transactions
1488 // too low feerate to pay for themselves, or that the child transactions are higher feerate than
1489 // their parents. Using aggregate feerate may allow "parents pay for child" behavior and permit
1490 // a child that is below mempool minimum feerate. To avoid these behaviors, callers of
1491 // AcceptMultipleTransactions need to restrict txns topology (e.g. to ancestor sets) and check
1492 // the feerates of individuals and subsets.
1493 m_subpackage.m_total_vsize = std::accumulate(workspaces.cbegin(), workspaces.cend(), int64_t{0},
1494 [](int64_t sum, auto& ws) { return sum + ws.m_vsize; });
1495 m_subpackage.m_total_modified_fees = std::accumulate(workspaces.cbegin(), workspaces.cend(), CAmount{0},
1496 [](CAmount sum, auto& ws) { return sum + ws.m_modified_fees; });
1497 const CFeeRate package_feerate(m_subpackage.m_total_modified_fees, m_subpackage.m_total_vsize);
1498 std::vector<Wtxid> all_package_wtxids;
1499 all_package_wtxids.reserve(workspaces.size());
1500 std::transform(workspaces.cbegin(), workspaces.cend(), std::back_inserter(all_package_wtxids),
1501 [](const auto& ws) { return ws.m_ptx->GetWitnessHash(); });
1502 TxValidationState placeholder_state;
1503 if (args.m_package_feerates &&
1504 !CheckFeeRate(m_subpackage.m_total_vsize, m_subpackage.m_total_modified_fees, placeholder_state)) {
1505 package_state.Invalid(PackageValidationResult::PCKG_TX, "transaction failed");
1506 return PackageMempoolAcceptResult(package_state, {{workspaces.back().m_ptx->GetWitnessHash(),
1507 MempoolAcceptResult::FeeFailure(placeholder_state, CFeeRate(m_subpackage.m_total_modified_fees, m_subpackage.m_total_vsize), all_package_wtxids)}});
1508 }
1509
1510 // Apply package mempool RBF checks.
1511 if (m_subpackage.m_rbf && !PackageRBFChecks(txns, workspaces, package_state)) {
1512 return PackageMempoolAcceptResult(package_state, std::move(results));
1513 }
1514
1515 // Check if the transactions would exceed the cluster size limit.
1516 if (!m_subpackage.m_changeset->CheckMemPoolPolicyLimits()) {
1517 package_state.Invalid(PackageValidationResult::PCKG_POLICY, "too-large-cluster", "");
1518 return PackageMempoolAcceptResult(package_state, std::move(results));
1519 }
1520
1521 // Now that we've bounded the resulting possible ancestry count, check package for dust spends
1522 if (m_pool.m_opts.require_standard) {
1523 TxValidationState child_state;
1524 Wtxid child_wtxid;
1525 if (!CheckEphemeralSpends(txns, m_pool.m_opts.dust_relay_feerate, m_pool, child_state, child_wtxid)) {
1526 package_state.Invalid(PackageValidationResult::PCKG_TX, "unspent-dust");
1527 results.emplace(child_wtxid, MempoolAcceptResult::Failure(child_state));
1528 return PackageMempoolAcceptResult(package_state, std::move(results));
1529 }
1530 }
1531
1532 for (Workspace& ws : workspaces) {
1533 ws.m_package_feerate = package_feerate;
1534 if (!PolicyScriptChecks(ws)) {
1535 // Exit early to avoid doing pointless work. Update the failed tx result; the rest are unfinished.
1536 package_state.Invalid(PackageValidationResult::PCKG_TX, "transaction failed");
1537 results.emplace(ws.m_ptx->GetWitnessHash(), MempoolAcceptResult::Failure(ws.m_state));
1538 return PackageMempoolAcceptResult(package_state, std::move(results));
1539 }
1540 if (args.m_test_accept) {
1541 const auto effective_feerate = args.m_package_feerates ? ws.m_package_feerate :
1542 CFeeRate{ws.m_modified_fees, static_cast<int32_t>(ws.m_vsize)};
1543 const auto effective_feerate_wtxids = args.m_package_feerates ? all_package_wtxids :
1544 std::vector<Wtxid>{ws.m_ptx->GetWitnessHash()};
1545 results.emplace(ws.m_ptx->GetWitnessHash(),
1546 MempoolAcceptResult::Success(std::move(m_subpackage.m_replaced_transactions),
1547 ws.m_vsize, ws.m_base_fees, effective_feerate,
1548 effective_feerate_wtxids));
1549 }
1550 }
1551
1552 if (args.m_test_accept) return PackageMempoolAcceptResult(package_state, std::move(results));
1553
1554 if (!SubmitPackage(args, workspaces, package_state, results)) {
1555 // PackageValidationState filled in by SubmitPackage().
1556 return PackageMempoolAcceptResult(package_state, std::move(results));
1557 }
1558
1559 return PackageMempoolAcceptResult(package_state, std::move(results));
1560}
1561
1562void MemPoolAccept::CleanupTemporaryCoins()
1563{
1564 // There are 3 kinds of coins in m_view:
1565 // (1) Temporary coins from the transactions in subpackage, constructed by m_viewmempool.
1566 // (2) Mempool coins from transactions in the mempool, constructed by m_viewmempool.
1567 // (3) Confirmed coins fetched from our current UTXO set.
1568 //
1569 // (1) Temporary coins need to be removed, regardless of whether the transaction was submitted.
1570 // If the transaction was submitted to the mempool, m_viewmempool will be able to fetch them from
1571 // there. If it wasn't submitted to mempool, it is incorrect to keep them - future calls may try
1572 // to spend those coins that don't actually exist.
1573 // (2) Mempool coins also need to be removed. If the mempool contents have changed as a result
1574 // of submitting or replacing transactions, coins previously fetched from mempool may now be
1575 // spent or nonexistent. Those coins need to be deleted from m_view.
1576 // (3) Confirmed coins don't need to be removed. The chainstate has not changed (we are
1577 // holding cs_main and no blocks have been processed) so the confirmed tx cannot disappear like
1578 // a mempool tx can. The coin may now be spent after we submitted a tx to mempool, but
1579 // we have already checked that the package does not have 2 transactions spending the same coin
1580 // and we check whether a mempool transaction spends conflicting coins (CTxMemPool::GetConflictTx).
1581 // Keeping them in m_view is an optimization to not re-fetch confirmed coins if we later look up
1582 // inputs for this transaction again.
1583 for (const auto& outpoint : m_viewmempool.GetNonBaseCoins()) {
1584 // In addition to resetting m_viewmempool, we also need to manually delete these coins from
1585 // m_view because it caches copies of the coins it fetched from m_viewmempool previously.
1586 m_view.Uncache(outpoint);
1587 }
1588 // This deletes the temporary and mempool coins.
1589 m_viewmempool.Reset();
1590}
1591
1592PackageMempoolAcceptResult MemPoolAccept::AcceptSubPackage(const std::vector<CTransactionRef>& subpackage, ATMPArgs& args)
1593{
1595 AssertLockHeld(m_pool.cs);
1596 auto result = [&]() EXCLUSIVE_LOCKS_REQUIRED(::cs_main, m_pool.cs) {
1597 if (subpackage.size() > 1) {
1598 return AcceptMultipleTransactionsInternal(subpackage, args);
1599 }
1600 const auto& tx = subpackage.front();
1601 ATMPArgs single_args = ATMPArgs::SingleInPackageAccept(args);
1602 const auto single_res = AcceptSingleTransactionInternal(tx, single_args);
1603 PackageValidationState package_state_wrapped;
1604 if (single_res.m_result_type != MempoolAcceptResult::ResultType::VALID) {
1605 package_state_wrapped.Invalid(PackageValidationResult::PCKG_TX, "transaction failed");
1606 }
1607 return PackageMempoolAcceptResult(package_state_wrapped, {{tx->GetWitnessHash(), single_res}});
1608 }();
1609
1610 // Clean up m_view and m_viewmempool so that other subpackage evaluations don't have access to
1611 // coins they shouldn't. Keep some coins in order to minimize re-fetching coins from the UTXO set.
1612 // Clean up package feerate and rbf calculations
1613 ClearSubPackageState();
1614
1615 return result;
1616}
1617
1618PackageMempoolAcceptResult MemPoolAccept::AcceptPackage(const Package& package, ATMPArgs& args)
1619{
1620 Assert(!package.empty());
1622 // Used if returning a PackageMempoolAcceptResult directly from this function.
1623 PackageValidationState package_state_quit_early;
1624
1625 // There are two topologies we are able to handle through this function:
1626 // (1) A single transaction
1627 // (2) A child-with-parents package.
1628 // Check that the package is well-formed. If it isn't, we won't try to validate any of the
1629 // transactions and thus won't return any MempoolAcceptResults, just a package-wide error.
1630
1631 // Context-free package checks.
1632 if (!IsWellFormedPackage(package, package_state_quit_early)) {
1633 return PackageMempoolAcceptResult(package_state_quit_early, {});
1634 }
1635
1636 if (package.size() > 1 && !IsChildWithParents(package)) {
1637 // All transactions in the package must be a parent of the last transaction. This is just an
1638 // opportunity for us to fail fast on a context-free check without taking the mempool lock.
1639 package_state_quit_early.Invalid(PackageValidationResult::PCKG_POLICY, "package-not-child-with-parents");
1640 return PackageMempoolAcceptResult(package_state_quit_early, {});
1641 }
1642
1643 LOCK(m_pool.cs);
1644 // Stores results from which we will create the returned PackageMempoolAcceptResult.
1645 // A result may be changed if a mempool transaction is evicted later due to LimitMempoolSize().
1646 std::map<Wtxid, MempoolAcceptResult> results_final;
1647 // Results from individual validation which will be returned if no other result is available for
1648 // this transaction. "Nonfinal" because if a transaction fails by itself but succeeds later
1649 // (i.e. when evaluated with a fee-bumping child), the result in this map may be discarded.
1650 std::map<Wtxid, MempoolAcceptResult> individual_results_nonfinal;
1651 // Tracks whether we think package submission could result in successful entry to the mempool
1652 bool quit_early{false};
1653 std::vector<CTransactionRef> txns_package_eval;
1654 for (const auto& tx : package) {
1655 const auto& wtxid = tx->GetWitnessHash();
1656 const auto& txid = tx->GetHash();
1657 // There are 3 possibilities: already in mempool, same-txid-diff-wtxid already in mempool,
1658 // or not in mempool. An already confirmed tx is treated as one not in mempool, because all
1659 // we know is that the inputs aren't available.
1660 if (m_pool.exists(wtxid)) {
1661 // Exact transaction already exists in the mempool.
1662 // Node operators are free to set their mempool policies however they please, nodes may receive
1663 // transactions in different orders, and malicious counterparties may try to take advantage of
1664 // policy differences to pin or delay propagation of transactions. As such, it's possible for
1665 // some package transaction(s) to already be in the mempool, and we don't want to reject the
1666 // entire package in that case (as that could be a censorship vector). De-duplicate the
1667 // transactions that are already in the mempool, and only call AcceptMultipleTransactions() with
1668 // the new transactions. This ensures we don't double-count transaction counts and sizes when
1669 // checking ancestor/descendant limits, or double-count transaction fees for fee-related policy.
1670 const auto& entry{*Assert(m_pool.GetEntry(txid))};
1671 results_final.emplace(wtxid, MempoolAcceptResult::MempoolTx(entry.GetTxSize(), entry.GetFee()));
1672 } else if (m_pool.exists(txid)) {
1673 // Transaction with the same non-witness data but different witness (same txid,
1674 // different wtxid) already exists in the mempool.
1675 //
1676 // We don't allow replacement transactions right now, so just swap the package
1677 // transaction for the mempool one. Note that we are ignoring the validity of the
1678 // package transaction passed in.
1679 // TODO: allow witness replacement in packages.
1680 const auto& entry{*Assert(m_pool.GetEntry(txid))};
1681 // Provide the wtxid of the mempool tx so that the caller can look it up in the mempool.
1682 results_final.emplace(wtxid, MempoolAcceptResult::MempoolTxDifferentWitness(entry.GetTx().GetWitnessHash()));
1683 } else {
1684 // Transaction does not already exist in the mempool.
1685 // Try submitting the transaction on its own.
1686 const auto single_package_res = AcceptSubPackage({tx}, args);
1687 const auto& single_res = single_package_res.m_tx_results.at(wtxid);
1688 if (single_res.m_result_type == MempoolAcceptResult::ResultType::VALID) {
1689 // The transaction succeeded on its own and is now in the mempool. Don't include it
1690 // in package validation, because its fees should only be "used" once.
1691 assert(m_pool.exists(wtxid));
1692 results_final.emplace(wtxid, single_res);
1693 } else if (package.size() == 1 || // If there is only one transaction, no need to retry it "as a package"
1694 (single_res.m_state.GetResult() != TxValidationResult::TX_RECONSIDERABLE &&
1695 single_res.m_state.GetResult() != TxValidationResult::TX_MISSING_INPUTS)) {
1696 // Package validation policy only differs from individual policy in its evaluation
1697 // of feerate. For example, if a transaction fails here due to violation of a
1698 // consensus rule, the result will not change when it is submitted as part of a
1699 // package. To minimize the amount of repeated work, unless the transaction fails
1700 // due to feerate or missing inputs (its parent is a previous transaction in the
1701 // package that failed due to feerate), don't run package validation. Note that this
1702 // decision might not make sense if different types of packages are allowed in the
1703 // future. Continue individually validating the rest of the transactions, because
1704 // some of them may still be valid.
1705 quit_early = true;
1706 package_state_quit_early.Invalid(PackageValidationResult::PCKG_TX, "transaction failed");
1707 individual_results_nonfinal.emplace(wtxid, single_res);
1708 } else {
1709 individual_results_nonfinal.emplace(wtxid, single_res);
1710 txns_package_eval.push_back(tx);
1711 }
1712 }
1713 }
1714
1715 auto multi_submission_result = quit_early || txns_package_eval.empty() ? PackageMempoolAcceptResult(package_state_quit_early, {}) :
1716 AcceptSubPackage(txns_package_eval, args);
1717 PackageValidationState& package_state_final = multi_submission_result.m_state;
1718
1719 // This is invoked by AcceptSubPackage() already, so this is just here for
1720 // clarity (since it's not permitted to invoke LimitMempoolSize() while a
1721 // changeset is outstanding).
1722 ClearSubPackageState();
1723
1724 // Make sure we haven't exceeded max mempool size.
1725 // Package transactions that were submitted to mempool or already in mempool may be evicted.
1726 // If mempool contents change, then the m_view cache is dirty. It has already been cleared above.
1727 LimitMempoolSize(m_pool, m_active_chainstate.CoinsTip());
1728
1729 for (const auto& tx : package) {
1730 const auto& wtxid = tx->GetWitnessHash();
1731 if (multi_submission_result.m_tx_results.contains(wtxid)) {
1732 // We shouldn't have re-submitted if the tx result was already in results_final.
1733 Assume(!results_final.contains(wtxid));
1734 // If it was submitted, check to see if the tx is still in the mempool. It could have
1735 // been evicted due to LimitMempoolSize() above.
1736 const auto& txresult = multi_submission_result.m_tx_results.at(wtxid);
1737 if (txresult.m_result_type == MempoolAcceptResult::ResultType::VALID && !m_pool.exists(wtxid)) {
1738 package_state_final.Invalid(PackageValidationResult::PCKG_TX, "transaction failed");
1739 TxValidationState mempool_full_state;
1740 mempool_full_state.Invalid(TxValidationResult::TX_MEMPOOL_POLICY, "mempool full");
1741 results_final.emplace(wtxid, MempoolAcceptResult::Failure(mempool_full_state));
1742 } else {
1743 results_final.emplace(wtxid, txresult);
1744 }
1745 } else if (const auto it{results_final.find(wtxid)}; it != results_final.end()) {
1746 // Already-in-mempool transaction. Check to see if it's still there, as it could have
1747 // been evicted when LimitMempoolSize() was called.
1748 Assume(it->second.m_result_type != MempoolAcceptResult::ResultType::INVALID);
1749 Assume(!individual_results_nonfinal.contains(wtxid));
1750 // Query by txid to include the same-txid-different-witness ones.
1751 if (!m_pool.exists(tx->GetHash())) {
1752 package_state_final.Invalid(PackageValidationResult::PCKG_TX, "transaction failed");
1753 TxValidationState mempool_full_state;
1754 mempool_full_state.Invalid(TxValidationResult::TX_MEMPOOL_POLICY, "mempool full");
1755 // Replace the previous result.
1756 results_final.erase(wtxid);
1757 results_final.emplace(wtxid, MempoolAcceptResult::Failure(mempool_full_state));
1758 }
1759 } else if (const auto it{individual_results_nonfinal.find(wtxid)}; it != individual_results_nonfinal.end()) {
1760 Assume(it->second.m_result_type == MempoolAcceptResult::ResultType::INVALID);
1761 // Interesting result from previous processing.
1762 results_final.emplace(wtxid, it->second);
1763 }
1764 }
1765 Assume(results_final.size() == package.size());
1766 return PackageMempoolAcceptResult(package_state_final, std::move(results_final));
1767}
1768
1769} // anon namespace
1770
1772 int64_t accept_time, bool bypass_limits, bool test_accept)
1773{
1775 assert(active_chainstate.GetMempool() != nullptr);
1776 CTxMemPool& pool{*active_chainstate.GetMempool()};
1777
1778 std::vector<COutPoint> coins_to_uncache;
1779
1780 auto args = MemPoolAccept::ATMPArgs::SingleAccept(accept_time, bypass_limits, coins_to_uncache, test_accept);
1781 MempoolAcceptResult result = MemPoolAccept(pool, active_chainstate).AcceptSingleTransactionAndCleanup(tx, args);
1782
1784 // Remove coins that were not present in the coins cache before calling
1785 // AcceptSingleTransaction(); this is to prevent memory DoS in case we receive a large
1786 // number of invalid transactions that attempt to overrun the in-memory coins cache
1787 // (`CCoinsViewCache::cacheCoins`).
1788
1789 for (const COutPoint& hashTx : coins_to_uncache)
1790 active_chainstate.CoinsTip().Uncache(hashTx);
1791 TRACEPOINT(mempool, rejected,
1792 tx->GetHash().data(),
1793 result.m_state.GetRejectReason().c_str()
1794 );
1795 }
1796 // After we've (potentially) uncached entries, ensure our coins cache is still within its size limits
1797 BlockValidationState state_dummy;
1798 active_chainstate.FlushStateToDisk(state_dummy, FlushStateMode::PERIODIC);
1799 return result;
1800}
1801
1803 const Package& package, bool test_accept, const std::optional<CFeeRate>& client_maxfeerate)
1804{
1806 assert(!package.empty());
1807 assert(std::all_of(package.cbegin(), package.cend(), [](const auto& tx){return tx != nullptr;}));
1808
1809 std::vector<COutPoint> coins_to_uncache;
1810 auto result = [&]() EXCLUSIVE_LOCKS_REQUIRED(cs_main) {
1812 if (test_accept) {
1813 auto args = MemPoolAccept::ATMPArgs::PackageTestAccept(GetTime(), coins_to_uncache);
1814 return MemPoolAccept(pool, active_chainstate).AcceptMultipleTransactionsAndCleanup(package, args);
1815 } else {
1816 auto args = MemPoolAccept::ATMPArgs::PackageChildWithParents(GetTime(), coins_to_uncache, client_maxfeerate);
1817 return MemPoolAccept(pool, active_chainstate).AcceptPackage(package, args);
1818 }
1819 }();
1820
1821 // Uncache coins pertaining to transactions that were not submitted to the mempool.
1822 if (test_accept || result.m_state.IsInvalid()) {
1823 for (const COutPoint& hashTx : coins_to_uncache) {
1824 active_chainstate.CoinsTip().Uncache(hashTx);
1825 }
1826 }
1827 // Ensure the coins cache is still within limits.
1828 BlockValidationState state_dummy;
1829 active_chainstate.FlushStateToDisk(state_dummy, FlushStateMode::PERIODIC);
1830 return result;
1831}
1832
1834{
1835 int halvings = nHeight / consensusParams.nSubsidyHalvingInterval;
1836 // Force block reward to zero when right shift is undefined.
1837 if (halvings >= 64)
1838 return 0;
1839
1840 CAmount nSubsidy = 50 * COIN;
1841 // Subsidy is cut in half every 210,000 blocks which will occur approximately every 4 years.
1842 nSubsidy >>= halvings;
1843 return nSubsidy;
1844}
1845
1847 : m_dbview{std::move(db_params), std::move(options)},
1848 m_catcherview(&m_dbview) {}
1849
1850void CoinsViews::InitCache(int32_t prevoutfetch_threads)
1851{
1853 m_cacheview = std::make_unique<CCoinsViewCache>(&m_catcherview);
1854 auto thread_pool{std::make_shared<ThreadPool>("prevout")};
1855 if (prevoutfetch_threads > 0) {
1856 thread_pool->Start(prevoutfetch_threads);
1857 LogInfo("Block input prevout fetching uses %d additional threads", prevoutfetch_threads);
1858 }
1859 m_connect_block_view = std::make_unique<CoinsViewOverlay>(&*m_cacheview, std::move(thread_pool));
1860}
1861
1863 CTxMemPool* mempool,
1864 BlockManager& blockman,
1865 ChainstateManager& chainman,
1866 std::optional<uint256> from_snapshot_blockhash)
1867 : m_mempool(mempool),
1868 m_blockman(blockman),
1869 m_chainman(chainman),
1870 m_assumeutxo(from_snapshot_blockhash ? Assumeutxo::UNVALIDATED : Assumeutxo::VALIDATED),
1871 m_from_snapshot_blockhash(from_snapshot_blockhash) {}
1872
1874{
1875 fs::path path{m_chainman.m_options.datadir / "chainstate"};
1878 }
1879 return path;
1880}
1881
1882const CBlockIndex* Chainstate::SnapshotBase() const
1883{
1884 if (!m_from_snapshot_blockhash) return nullptr;
1885 if (!m_cached_snapshot_base) m_cached_snapshot_base = Assert(m_chainman.m_blockman.LookupBlockIndex(*m_from_snapshot_blockhash));
1886 return m_cached_snapshot_base;
1887}
1888
1889const CBlockIndex* Chainstate::TargetBlock() const
1890{
1891 if (!m_target_blockhash) return nullptr;
1892 if (!m_cached_target_block) m_cached_target_block = Assert(m_chainman.m_blockman.LookupBlockIndex(*m_target_blockhash));
1893 return m_cached_target_block;
1894}
1895
1896void Chainstate::SetTargetBlock(CBlockIndex* block)
1897{
1898 if (block) {
1899 m_target_blockhash = block->GetBlockHash();
1900 } else {
1901 m_target_blockhash.reset();
1902 }
1903 m_cached_target_block = block;
1904}
1905
1906void Chainstate::SetTargetBlockHash(uint256 block_hash)
1907{
1908 m_target_blockhash = block_hash;
1909 m_cached_target_block = nullptr;
1910}
1911
1913 size_t cache_size_bytes,
1914 bool in_memory,
1915 bool should_wipe)
1916{
1917 m_coins_views = std::make_unique<CoinsViews>(
1918 DBParams{
1919 .path = StoragePath(),
1920 .cache_bytes = cache_size_bytes,
1921 .memory_only = in_memory,
1922 .wipe_data = should_wipe,
1923 .obfuscate = true,
1924 .options = m_chainman.m_options.coins_db},
1926
1927 m_coinsdb_cache_size_bytes = cache_size_bytes;
1928}
1929
1930void Chainstate::InitCoinsCache(size_t cache_size_bytes)
1931{
1933 assert(m_coins_views != nullptr);
1934 m_coinstip_cache_size_bytes = cache_size_bytes;
1936}
1937
1938// Lock-free: depends on `m_cached_is_ibd`, which is latched by `UpdateIBDStatus()`.
1940{
1941 return m_cached_is_ibd.load(std::memory_order_relaxed);
1942}
1943
1945{
1947
1948 if (this->GetRole().historical) {
1949 return;
1950 }
1951
1952 if (m_chainman.m_best_invalid && m_chainman.m_best_invalid->nChainWork > m_chain.Tip()->nChainWork + (GetBlockProof(*m_chain.Tip()) * 6)) {
1953 LogWarning("Found invalid chain more than 6 blocks longer than our best chain. This could be due to database corruption or consensus incompatibility with peers.");
1956 _("Warning: Found invalid chain more than 6 blocks longer than our best chain. This could be due to database corruption or consensus incompatibility with peers."));
1957 } else {
1959 }
1960}
1961
1962// Called both upon regular invalid block discovery *and* InvalidateBlock
1964{
1966 if (!m_chainman.m_best_invalid || pindexNew->nChainWork > m_chainman.m_best_invalid->nChainWork) {
1967 m_chainman.m_best_invalid = pindexNew;
1968 }
1969 SetBlockFailureFlags(pindexNew);
1970 if (m_chainman.m_best_header != nullptr && m_chainman.m_best_header->GetAncestor(pindexNew->nHeight) == pindexNew) {
1971 m_chainman.RecalculateBestHeader();
1972 }
1973
1974 LogInfo("%s: invalid block=%s height=%d log2_work=%f date=%s", __func__,
1975 pindexNew->GetBlockHash().ToString(), pindexNew->nHeight,
1976 log(pindexNew->nChainWork.getdouble())/log(2.0), FormatISO8601DateTime(pindexNew->GetBlockTime()));
1977 CBlockIndex *tip = m_chain.Tip();
1978 assert (tip);
1979 LogInfo("%s: current best=%s height=%d log2_work=%f date=%s", __func__,
1980 tip->GetBlockHash().ToString(), m_chain.Height(), log(tip->nChainWork.getdouble())/log(2.0),
1983}
1984
1985// Same as InvalidChainFound, above, except not called directly from InvalidateBlock,
1986// which does its own setBlockIndexCandidates management.
1988{
1991 pindex->nStatus |= BLOCK_FAILED_VALID;
1992 m_blockman.m_dirty_blockindex.insert(pindex);
1993 setBlockIndexCandidates.erase(pindex);
1994 InvalidChainFound(pindex);
1995 }
1996}
1997
1998void UpdateCoins(const CTransaction& tx, CCoinsViewCache& inputs, CTxUndo &txundo, int nHeight)
1999{
2000 // mark inputs spent
2001 if (!tx.IsCoinBase()) {
2002 txundo.vprevout.reserve(tx.vin.size());
2003 for (const CTxIn &txin : tx.vin) {
2004 txundo.vprevout.emplace_back();
2005 bool is_spent = inputs.SpendCoin(txin.prevout, &txundo.vprevout.back());
2006 assert(is_spent);
2007 }
2008 }
2009 // add outputs
2010 AddCoins(inputs, tx, nHeight);
2011}
2012
2013std::optional<std::pair<ScriptError, std::string>> CScriptCheck::operator()() {
2014 const CScript &scriptSig = ptxTo->vin[nIn].scriptSig;
2015 const CScriptWitness *witness = &ptxTo->vin[nIn].scriptWitness;
2018 return std::nullopt;
2019 } else {
2020 auto debug_str = strprintf("input %i of %s (wtxid %s), spending %s:%i", nIn, ptxTo->GetHash().ToString(), ptxTo->GetWitnessHash().ToString(), ptxTo->vin[nIn].prevout.hash.ToString(), ptxTo->vin[nIn].prevout.n);
2021 return std::make_pair(error, std::move(debug_str));
2022 }
2023}
2024
2025ValidationCache::ValidationCache(const size_t script_execution_cache_bytes, const size_t signature_cache_bytes)
2026 : m_signature_cache{signature_cache_bytes}
2027{
2028 // Setup the salted hasher
2030 // We want the nonce to be 64 bytes long to force the hasher to process
2031 // this chunk, which makes later hash computations more efficient. We
2032 // just write our 32-byte entropy twice to fill the 64 bytes.
2035
2036 const auto [num_elems, approx_size_bytes] = m_script_execution_cache.setup_bytes(script_execution_cache_bytes);
2037 LogInfo("Using %zu MiB out of %zu MiB requested for script execution cache, able to store %zu elements",
2038 approx_size_bytes >> 20, script_execution_cache_bytes >> 20, num_elems);
2039}
2040
2061 const CCoinsViewCache& inputs, script_verify_flags flags, bool cacheSigStore,
2062 bool cacheFullScriptStore, PrecomputedTransactionData& txdata,
2063 ValidationCache& validation_cache,
2064 std::vector<CScriptCheck>* pvChecks)
2065{
2066 if (tx.IsCoinBase()) return true;
2067
2068 if (pvChecks) {
2069 pvChecks->reserve(tx.vin.size());
2070 }
2071
2072 // First check if script executions have been cached with the same
2073 // flags. Note that this assumes that the inputs provided are
2074 // correct (ie that the transaction hash which is in tx's prevouts
2075 // properly commits to the scriptPubKey in the inputs view of that
2076 // transaction).
2077 uint256 hashCacheEntry;
2078 CSHA256 hasher = validation_cache.ScriptExecutionCacheHasher();
2079 hasher.Write(UCharCast(tx.GetWitnessHash().begin()), 32).Write((unsigned char*)&flags, sizeof(flags)).Finalize(hashCacheEntry.begin());
2080 AssertLockHeld(cs_main); //TODO: Remove this requirement by making CuckooCache not require external locks
2081 if (validation_cache.m_script_execution_cache.contains(hashCacheEntry, !cacheFullScriptStore)) {
2082 return true;
2083 }
2084
2085 if (!txdata.m_spent_outputs_ready) {
2086 std::vector<CTxOut> spent_outputs;
2087 spent_outputs.reserve(tx.vin.size());
2088
2089 for (const auto& txin : tx.vin) {
2090 const COutPoint& prevout = txin.prevout;
2091 const Coin& coin = inputs.AccessCoin(prevout);
2092 assert(!coin.IsSpent());
2093 spent_outputs.emplace_back(coin.out);
2094 }
2095 txdata.Init(tx, std::move(spent_outputs));
2096 }
2097 assert(txdata.m_spent_outputs.size() == tx.vin.size());
2098
2099 for (unsigned int i = 0; i < tx.vin.size(); i++) {
2100
2101 // We very carefully only pass in things to CScriptCheck which
2102 // are clearly committed to by tx' witness hash. This provides
2103 // a sanity check that our caching is not introducing consensus
2104 // failures through additional data in, eg, the coins being
2105 // spent being checked as a part of CScriptCheck.
2106
2107 // Verify signature
2108 CScriptCheck check(txdata.m_spent_outputs[i], tx, validation_cache.m_signature_cache, i, flags, cacheSigStore, &txdata);
2109 if (pvChecks) {
2110 pvChecks->emplace_back(std::move(check));
2111 } else if (auto result = check(); result.has_value()) {
2112 // Tx failures never trigger disconnections/bans.
2113 // This is so that network splits aren't triggered
2114 // either due to non-consensus relay policies (such as
2115 // non-standard DER encodings or non-null dummy
2116 // arguments) or due to new consensus rules introduced in
2117 // soft forks.
2119 return state.Invalid(TxValidationResult::TX_NOT_STANDARD, strprintf("mempool-script-verify-flag-failed (%s)", ScriptErrorString(result->first)), result->second);
2120 } else {
2121 return state.Invalid(TxValidationResult::TX_CONSENSUS, strprintf("block-script-verify-flag-failed (%s)", ScriptErrorString(result->first)), result->second);
2122 }
2123 }
2124 }
2125
2126 if (cacheFullScriptStore && !pvChecks) {
2127 // We executed all of the provided scripts, and were told to
2128 // cache the result. Do so now.
2129 validation_cache.m_script_execution_cache.insert(hashCacheEntry);
2130 }
2131
2132 return true;
2133}
2134
2135bool FatalError(Notifications& notifications, BlockValidationState& state, const bilingual_str& message)
2136{
2137 notifications.fatalError(message);
2138 return state.Error(message.original);
2139}
2140
2149{
2150 bool fClean = true;
2151
2152 if (view.HaveCoin(out)) fClean = false; // overwriting transaction output
2153
2154 if (undo.nHeight == 0) {
2155 // Missing undo metadata (height and coinbase). Older versions included this
2156 // information only in undo records for the last spend of a transactions'
2157 // outputs. This implies that it must be present for some other output of the same tx.
2158 const Coin& alternate = AccessByTxid(view, out.hash);
2159 if (!alternate.IsSpent()) {
2160 undo.nHeight = alternate.nHeight;
2161 undo.fCoinBase = alternate.fCoinBase;
2162 } else {
2163 return DISCONNECT_FAILED; // adding output for transaction without known metadata
2164 }
2165 }
2166 // If the coin already exists as an unspent coin in the cache, then the
2167 // possible_overwrite parameter to AddCoin must be set to true. We have
2168 // already checked whether an unspent coin exists above using HaveCoin, so
2169 // we don't need to guess. When fClean is false, an unspent coin already
2170 // existed and it is an overwrite.
2171 view.AddCoin(out, std::move(undo), !fClean);
2172
2173 return fClean ? DISCONNECT_OK : DISCONNECT_UNCLEAN;
2174}
2175
2178DisconnectResult Chainstate::DisconnectBlock(const CBlock& block, const CBlockIndex* pindex, CCoinsViewCache& view)
2179{
2181 bool fClean = true;
2182
2183 CBlockUndo blockUndo;
2184 if (!m_blockman.ReadBlockUndo(blockUndo, *pindex)) {
2185 LogError("DisconnectBlock(): failure reading undo data\n");
2186 return DISCONNECT_FAILED;
2187 }
2188
2189 if (blockUndo.vtxundo.size() + 1 != block.vtx.size()) {
2190 LogError("DisconnectBlock(): block and undo data inconsistent\n");
2191 return DISCONNECT_FAILED;
2192 }
2193
2194 // Ignore blocks that contain transactions which are 'overwritten' by later transactions,
2195 // unless those are already completely spent.
2196 // See https://github.com/bitcoin/bitcoin/issues/22596 for additional information.
2197 // Note: the blocks specified here are different than the ones used in ConnectBlock because DisconnectBlock
2198 // unwinds the blocks in reverse. As a result, the inconsistency is not discovered until the earlier
2199 // blocks with the duplicate coinbase transactions are disconnected.
2200 bool fEnforceBIP30 = !((pindex->nHeight==91722 && pindex->GetBlockHash() == uint256{"00000000000271a2dc26e7667f8419f2e15416dc6955e5a6c6cdf3f2574dd08e"}) ||
2201 (pindex->nHeight==91812 && pindex->GetBlockHash() == uint256{"00000000000af0aed4792b1acee3d966af36cf5def14935db8de83d6f9306f2f"}));
2202
2203 // undo transactions in reverse order
2204 for (int i = block.vtx.size() - 1; i >= 0; i--) {
2205 const CTransaction &tx = *(block.vtx[i]);
2206 Txid hash = tx.GetHash();
2207 bool is_coinbase = tx.IsCoinBase();
2208 bool is_bip30_exception = (is_coinbase && !fEnforceBIP30);
2209
2210 // Check that all outputs are available and match the outputs in the block itself
2211 // exactly.
2212 for (size_t o = 0; o < tx.vout.size(); o++) {
2213 if (!tx.vout[o].scriptPubKey.IsUnspendable()) {
2214 COutPoint out(hash, o);
2215 Coin coin;
2216 bool is_spent = view.SpendCoin(out, &coin);
2217 if (!is_spent || tx.vout[o] != coin.out || pindex->nHeight != coin.nHeight || is_coinbase != coin.IsCoinBase()) {
2218 if (!is_bip30_exception) {
2219 fClean = false; // transaction output mismatch
2220 }
2221 }
2222 }
2223 }
2224
2225 // restore inputs
2226 if (i > 0) { // not coinbases
2227 CTxUndo &txundo = blockUndo.vtxundo[i-1];
2228 if (txundo.vprevout.size() != tx.vin.size()) {
2229 LogError("DisconnectBlock(): transaction and undo data inconsistent\n");
2230 return DISCONNECT_FAILED;
2231 }
2232 for (unsigned int j = tx.vin.size(); j > 0;) {
2233 --j;
2234 const COutPoint& out = tx.vin[j].prevout;
2235 int res = ApplyTxInUndo(std::move(txundo.vprevout[j]), view, out);
2236 if (res == DISCONNECT_FAILED) return DISCONNECT_FAILED;
2237 fClean = fClean && res != DISCONNECT_UNCLEAN;
2238 }
2239 // At this point, all of txundo.vprevout should have been moved out.
2240 }
2241 }
2242
2243 // move best block pointer to prevout block
2244 view.SetBestBlock(pindex->pprev->GetBlockHash());
2245
2246 return fClean ? DISCONNECT_OK : DISCONNECT_UNCLEAN;
2247}
2248
2250{
2251 const Consensus::Params& consensusparams = chainman.GetConsensus();
2252
2253 // BIP16 didn't become active until Apr 1 2012 (on mainnet, and
2254 // retroactively applied to testnet)
2255 // However, only one historical block violated the P2SH rules (on both
2256 // mainnet and testnet).
2257 // Similarly, only one historical block violated the TAPROOT rules on
2258 // mainnet.
2259 // For simplicity, always leave P2SH+WITNESS+TAPROOT on except for the two
2260 // violating blocks.
2262 const auto it{consensusparams.script_flag_exceptions.find(*Assert(block_index.phashBlock))};
2263 if (it != consensusparams.script_flag_exceptions.end()) {
2264 flags = it->second;
2265 }
2266
2267 // Enforce the DERSIG (BIP66) rule
2268 if (DeploymentActiveAt(block_index, chainman, Consensus::DEPLOYMENT_DERSIG)) {
2270 }
2271
2272 // Enforce CHECKLOCKTIMEVERIFY (BIP65)
2273 if (DeploymentActiveAt(block_index, chainman, Consensus::DEPLOYMENT_CLTV)) {
2275 }
2276
2277 // Enforce CHECKSEQUENCEVERIFY (BIP112)
2278 if (DeploymentActiveAt(block_index, chainman, Consensus::DEPLOYMENT_CSV)) {
2280 }
2281
2282 // Enforce BIP147 NULLDUMMY (activated simultaneously with segwit)
2283 if (DeploymentActiveAt(block_index, chainman, Consensus::DEPLOYMENT_SEGWIT)) {
2285 }
2286
2287 return flags;
2288}
2289
2290
2294bool Chainstate::ConnectBlock(const CBlock& block, BlockValidationState& state, CBlockIndex* pindex,
2295 CCoinsViewCache& view, bool fJustCheck)
2296{
2298 assert(pindex);
2299
2300 uint256 block_hash{block.GetHash()};
2301 assert(*pindex->phashBlock == block_hash);
2302
2303 const auto time_start{SteadyClock::now()};
2304 const CChainParams& params{m_chainman.GetParams()};
2305
2306 // Check it again in case a previous version let a bad block in
2307 // NOTE: We don't currently (re-)invoke ContextualCheckBlock() or
2308 // ContextualCheckBlockHeader() here. This means that if we add a new
2309 // consensus rule that is enforced in one of those two functions, then we
2310 // may have let in a block that violates the rule prior to updating the
2311 // software, and we would NOT be enforcing the rule here. Fully solving
2312 // upgrade from one software version to the next after a consensus rule
2313 // change is potentially tricky and issue-specific (see NeedsRedownload()
2314 // for one approach that was used for BIP 141 deployment).
2315 // Also, currently the rule against blocks more than 2 hours in the future
2316 // is enforced in ContextualCheckBlockHeader(); we wouldn't want to
2317 // re-enforce that rule here (at least until we make it impossible for
2318 // the clock to go backward).
2319 if (!CheckBlock(block, state, params.GetConsensus(), !fJustCheck, !fJustCheck)) {
2321 // We don't write down blocks to disk if they may have been
2322 // corrupted, so this should be impossible unless we're having hardware
2323 // problems.
2324 return FatalError(m_chainman.GetNotifications(), state, _("Corrupt block found indicating potential hardware failure."));
2325 }
2326 LogError("%s: Consensus::CheckBlock: %s\n", __func__, state.ToString());
2327 return false;
2328 }
2329
2330 // verify that the view's current state corresponds to the previous block
2331 uint256 hashPrevBlock = pindex->pprev == nullptr ? uint256() : pindex->pprev->GetBlockHash();
2332 assert(hashPrevBlock == view.GetBestBlock());
2333
2334 m_chainman.num_blocks_total++;
2335
2336 // Special case for the genesis block, skipping connection of its transactions
2337 // (its coinbase is unspendable)
2338 if (block_hash == params.GetConsensus().hashGenesisBlock) {
2339 if (!fJustCheck)
2340 view.SetBestBlock(pindex->GetBlockHash());
2341 return true;
2342 }
2343
2344 const char* script_check_reason;
2346 script_check_reason = "assumevalid=0 (always verify)";
2347 } else {
2348 constexpr int64_t TWO_WEEKS_IN_SECONDS{60 * 60 * 24 * 7 * 2};
2349 // We've been configured with the hash of a block which has been externally verified to have a valid history.
2350 // A suitable default value is included with the software and updated from time to time. Because validity
2351 // relative to a piece of software is an objective fact these defaults can be easily reviewed.
2352 // This setting doesn't force the selection of any particular chain but makes validating some faster by
2353 // effectively caching the result of part of the verification.
2354 BlockMap::const_iterator it{m_blockman.m_block_index.find(m_chainman.AssumedValidBlock())};
2355 if (it == m_blockman.m_block_index.end()) {
2356 script_check_reason = "assumevalid hash not in headers";
2357 } else if (it->second.GetAncestor(pindex->nHeight) != pindex) {
2358 script_check_reason = (pindex->nHeight > it->second.nHeight) ? "block height above assumevalid height" : "block not in assumevalid chain";
2359 } else if (m_chainman.m_best_header->GetAncestor(pindex->nHeight) != pindex) {
2360 script_check_reason = "block not in best header chain";
2361 } else if (m_chainman.m_best_header->nChainWork < m_chainman.MinimumChainWork()) {
2362 script_check_reason = "best header chainwork below minimumchainwork";
2363 } else if (GetBlockProofEquivalentTime(*m_chainman.m_best_header, *pindex, *m_chainman.m_best_header, params.GetConsensus()) <= TWO_WEEKS_IN_SECONDS) {
2364 script_check_reason = "block too recent relative to best header";
2365 } else {
2366 // This block is a member of the assumed verified chain and an ancestor of the best header.
2367 // Script verification is skipped when connecting blocks under the
2368 // assumevalid block. Assuming the assumevalid block is valid this
2369 // is safe because block merkle hashes are still computed and checked,
2370 // Of course, if an assumed valid block is invalid due to false scriptSigs
2371 // this optimization would allow an invalid chain to be accepted.
2372 // The equivalent time check discourages hash power from extorting the network via DOS attack
2373 // into accepting an invalid block through telling users they must manually set assumevalid.
2374 // Requiring a software change or burying the invalid block, regardless of the setting, makes
2375 // it hard to hide the implication of the demand. This also avoids having release candidates
2376 // that are hardly doing any signature verification at all in testing without having to
2377 // artificially set the default assumed verified block further back.
2378 // The test against the minimum chain work prevents the skipping when denied access to any chain at
2379 // least as good as the expected chain.
2380 script_check_reason = nullptr;
2381 }
2382 }
2383
2384 const auto time_1{SteadyClock::now()};
2385 m_chainman.time_check += time_1 - time_start;
2386 LogDebug(BCLog::BENCH, " - Sanity checks: %.2fms [%.2fs (%.2fms/blk)]\n",
2387 Ticks<MillisecondsDouble>(time_1 - time_start),
2388 Ticks<SecondsDouble>(m_chainman.time_check),
2389 Ticks<MillisecondsDouble>(m_chainman.time_check) / m_chainman.num_blocks_total);
2390
2391 // Do not allow blocks that contain transactions which 'overwrite' older transactions,
2392 // unless those are already completely spent.
2393 // If such overwrites are allowed, coinbases and transactions depending upon those
2394 // can be duplicated to remove the ability to spend the first instance -- even after
2395 // being sent to another address.
2396 // See BIP30, CVE-2012-1909, and https://r6.ca/blog/20120206T005236Z.html for more information.
2397 // This rule was originally applied to all blocks with a timestamp after March 15, 2012, 0:00 UTC.
2398 // Now that the whole chain is irreversibly beyond that time it is applied to all blocks except the
2399 // two in the chain that violate it. This prevents exploiting the issue against nodes during their
2400 // initial block download.
2401 bool fEnforceBIP30 = !IsBIP30Repeat(*pindex);
2402
2403 // Once BIP34 activated it was not possible to create new duplicate coinbases and thus other than starting
2404 // with the 2 existing duplicate coinbase pairs, not possible to create overwriting txs. But by the
2405 // time BIP34 activated, in each of the existing pairs the duplicate coinbase had overwritten the first
2406 // before the first had been spent. Since those coinbases are sufficiently buried it's no longer possible to create further
2407 // duplicate transactions descending from the known pairs either.
2408 // If we're on the known chain at height greater than where BIP34 activated, we can save the db accesses needed for the BIP30 check.
2409
2410 // BIP34 requires that a block at height X (block X) has its coinbase
2411 // scriptSig start with a CScriptNum of X (indicated height X). The above
2412 // logic of no longer requiring BIP30 once BIP34 activates is flawed in the
2413 // case that there is a block X before the BIP34 height of 227,931 which has
2414 // an indicated height Y where Y is greater than X. The coinbase for block
2415 // X would also be a valid coinbase for block Y, which could be a BIP30
2416 // violation. An exhaustive search of all mainnet coinbases before the
2417 // BIP34 height which have an indicated height greater than the block height
2418 // reveals many occurrences. The 3 lowest indicated heights found are
2419 // 209,921, 490,897, and 1,983,702 and thus coinbases for blocks at these 3
2420 // heights would be the first opportunity for BIP30 to be violated.
2421
2422 // The search reveals a great many blocks which have an indicated height
2423 // greater than 1,983,702, so we simply remove the optimization to skip
2424 // BIP30 checking for blocks at height 1,983,702 or higher. Before we reach
2425 // that block in another 25 years or so, we should take advantage of a
2426 // future consensus change to do a new and improved version of BIP34 that
2427 // will actually prevent ever creating any duplicate coinbases in the
2428 // future.
2429 static constexpr int BIP34_IMPLIES_BIP30_LIMIT = 1983702;
2430
2431 // There is no potential to create a duplicate coinbase at block 209,921
2432 // because this is still before the BIP34 height and so explicit BIP30
2433 // checking is still active.
2434
2435 // The final case is block 176,684 which has an indicated height of
2436 // 490,897. Unfortunately, this issue was not discovered until about 2 weeks
2437 // before block 490,897 so there was not much opportunity to address this
2438 // case other than to carefully analyze it and determine it would not be a
2439 // problem. Block 490,897 was, in fact, mined with a different coinbase than
2440 // block 176,684, but it is important to note that even if it hadn't been or
2441 // is remined on an alternate fork with a duplicate coinbase, we would still
2442 // not run into a BIP30 violation. This is because the coinbase for 176,684
2443 // is spent in block 185,956 in transaction
2444 // d4f7fbbf92f4a3014a230b2dc70b8058d02eb36ac06b4a0736d9d60eaa9e8781. This
2445 // spending transaction can't be duplicated because it also spends coinbase
2446 // 0328dd85c331237f18e781d692c92de57649529bd5edf1d01036daea32ffde29. This
2447 // coinbase has an indicated height of over 4.2 billion, and wouldn't be
2448 // duplicatable until that height, and it's currently impossible to create a
2449 // chain that long. Nevertheless we may wish to consider a future soft fork
2450 // which retroactively prevents block 490,897 from creating a duplicate
2451 // coinbase. The two historical BIP30 violations often provide a confusing
2452 // edge case when manipulating the UTXO and it would be simpler not to have
2453 // another edge case to deal with.
2454
2455 // testnet3 has no blocks before the BIP34 height with indicated heights
2456 // post BIP34 before approximately height 486,000,000. After block
2457 // 1,983,702 testnet3 starts doing unnecessary BIP30 checking again.
2458 assert(pindex->pprev);
2459 CBlockIndex* pindexBIP34height = pindex->pprev->GetAncestor(params.GetConsensus().BIP34Height);
2460 //Only continue to enforce if we're below BIP34 activation height or the block hash at that height doesn't correspond.
2461 fEnforceBIP30 = fEnforceBIP30 && (!pindexBIP34height || !(pindexBIP34height->GetBlockHash() == params.GetConsensus().BIP34Hash));
2462
2463 // TODO: Remove BIP30 checking from block height 1,983,702 on, once we have a
2464 // consensus change that ensures coinbases at those heights cannot
2465 // duplicate earlier coinbases.
2466 if (fEnforceBIP30 || pindex->nHeight >= BIP34_IMPLIES_BIP30_LIMIT) {
2467 for (const auto& tx : block.vtx) {
2468 for (size_t o = 0; o < tx->vout.size(); o++) {
2469 if (view.HaveCoin(COutPoint(tx->GetHash(), o))) {
2470 state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-txns-BIP30",
2471 "tried to overwrite transaction");
2472 }
2473 }
2474 }
2475 }
2476
2477 // Enforce BIP68 (sequence locks)
2478 int nLockTimeFlags = 0;
2480 nLockTimeFlags |= LOCKTIME_VERIFY_SEQUENCE;
2481 }
2482
2483 // Get the script flags for this block
2485
2486 const auto time_2{SteadyClock::now()};
2487 m_chainman.time_forks += time_2 - time_1;
2488 LogDebug(BCLog::BENCH, " - Fork checks: %.2fms [%.2fs (%.2fms/blk)]\n",
2489 Ticks<MillisecondsDouble>(time_2 - time_1),
2490 Ticks<SecondsDouble>(m_chainman.time_forks),
2491 Ticks<MillisecondsDouble>(m_chainman.time_forks) / m_chainman.num_blocks_total);
2492
2493 const bool fScriptChecks{!!script_check_reason};
2494 const kernel::ChainstateRole role{GetRole()};
2495 if (script_check_reason != m_last_script_check_reason_logged && role.validated && !role.historical) {
2496 if (fScriptChecks) {
2497 LogInfo("Enabling script verification at block #%d (%s): %s.",
2498 pindex->nHeight, block_hash.ToString(), script_check_reason);
2499 } else {
2500 LogInfo("Disabling script verification at block #%d (%s).",
2501 pindex->nHeight, block_hash.ToString());
2502 }
2503 m_last_script_check_reason_logged = script_check_reason;
2504 }
2505
2506 CBlockUndo blockundo;
2507
2508 // Precomputed transaction data pointers must not be invalidated
2509 // until after `control` has run the script checks (potentially
2510 // in multiple threads). Preallocate the vector size so a new allocation
2511 // doesn't invalidate pointers into the vector, and keep txsdata in scope
2512 // for as long as `control`.
2513 std::vector<PrecomputedTransactionData> txsdata(block.vtx.size());
2514 std::optional<CCheckQueueControl<CScriptCheck>> control;
2515 if (auto& queue = m_chainman.GetCheckQueue(); queue.HasThreads() && fScriptChecks) control.emplace(queue);
2516
2517 std::vector<int> prevheights;
2518 CAmount nFees = 0;
2519 int nInputs = 0;
2520 int64_t nSigOpsCost = 0;
2521 blockundo.vtxundo.reserve(block.vtx.size() - 1);
2522 for (unsigned int i = 0; i < block.vtx.size(); i++)
2523 {
2524 if (!state.IsValid()) break;
2525 const CTransaction &tx = *(block.vtx[i]);
2526
2527 nInputs += tx.vin.size();
2528
2529 if (!tx.IsCoinBase())
2530 {
2531 CAmount txfee = 0;
2532 TxValidationState tx_state;
2533 if (!Consensus::CheckTxInputs(tx, tx_state, view, pindex->nHeight, txfee)) {
2534 // Any transaction validation failure in ConnectBlock is a block consensus failure
2536 tx_state.GetRejectReason(),
2537 tx_state.GetDebugMessage() + " in transaction " + tx.GetHash().ToString());
2538 break;
2539 }
2540 nFees += txfee;
2541 if (!MoneyRange(nFees)) {
2542 state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-txns-accumulated-fee-outofrange",
2543 "accumulated fee in the block out of range");
2544 break;
2545 }
2546
2547 // Check that transaction is BIP68 final
2548 // BIP68 lock checks (as opposed to nLockTime checks) must
2549 // be in ConnectBlock because they require the UTXO set
2550 prevheights.resize(tx.vin.size());
2551 for (size_t j = 0; j < tx.vin.size(); j++) {
2552 prevheights[j] = view.AccessCoin(tx.vin[j].prevout).nHeight;
2553 }
2554
2555 if (!SequenceLocks(tx, nLockTimeFlags, prevheights, *pindex)) {
2556 state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-txns-nonfinal",
2557 "contains a non-BIP68-final transaction " + tx.GetHash().ToString());
2558 break;
2559 }
2560 }
2561
2562 // GetTransactionSigOpCost counts 3 types of sigops:
2563 // * legacy (always)
2564 // * p2sh (when P2SH enabled in flags and excludes coinbase)
2565 // * witness (when witness enabled in flags and excludes coinbase)
2566 nSigOpsCost += GetTransactionSigOpCost(tx, view, flags);
2567 if (nSigOpsCost > MAX_BLOCK_SIGOPS_COST) {
2568 state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-blk-sigops", "too many sigops");
2569 break;
2570 }
2571
2572 if (!tx.IsCoinBase() && fScriptChecks)
2573 {
2574 bool fCacheResults = fJustCheck; /* Don't cache results if we're actually connecting blocks (still consult the cache, though) */
2575 bool tx_ok;
2576 TxValidationState tx_state;
2577 // If CheckInputScripts is called with a pointer to a checks vector, the resulting checks are appended to it. In that case
2578 // they need to be added to control which runs them asynchronously. Otherwise, CheckInputScripts runs the checks before returning.
2579 if (control) {
2580 std::vector<CScriptCheck> vChecks;
2581 tx_ok = CheckInputScripts(tx, tx_state, view, flags, fCacheResults, fCacheResults, txsdata[i], m_chainman.m_validation_cache, &vChecks);
2582 if (tx_ok) control->Add(std::move(vChecks));
2583 } else {
2584 tx_ok = CheckInputScripts(tx, tx_state, view, flags, fCacheResults, fCacheResults, txsdata[i], m_chainman.m_validation_cache);
2585 }
2586 if (!tx_ok) {
2587 // Any transaction validation failure in ConnectBlock is a block consensus failure
2589 tx_state.GetRejectReason(), tx_state.GetDebugMessage());
2590 break;
2591 }
2592 }
2593
2594 CTxUndo undoDummy;
2595 if (i > 0) {
2596 blockundo.vtxundo.emplace_back();
2597 }
2598 UpdateCoins(tx, view, i == 0 ? undoDummy : blockundo.vtxundo.back(), pindex->nHeight);
2599 }
2600 const auto time_3{SteadyClock::now()};
2601 m_chainman.time_connect += time_3 - time_2;
2602 LogDebug(BCLog::BENCH, " - Connect %u transactions: %.2fms (%.3fms/tx, %.3fms/txin) [%.2fs (%.2fms/blk)]\n", (unsigned)block.vtx.size(),
2603 Ticks<MillisecondsDouble>(time_3 - time_2), Ticks<MillisecondsDouble>(time_3 - time_2) / block.vtx.size(),
2604 nInputs <= 1 ? 0 : Ticks<MillisecondsDouble>(time_3 - time_2) / (nInputs - 1),
2605 Ticks<SecondsDouble>(m_chainman.time_connect),
2606 Ticks<MillisecondsDouble>(m_chainman.time_connect) / m_chainman.num_blocks_total);
2607
2608 CAmount blockReward = nFees + GetBlockSubsidy(pindex->nHeight, params.GetConsensus());
2609 if (block.vtx[0]->GetValueOut() > blockReward && state.IsValid()) {
2610 state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-cb-amount",
2611 strprintf("coinbase pays too much (actual=%d vs limit=%d)", block.vtx[0]->GetValueOut(), blockReward));
2612 }
2613 if (control) {
2614 auto parallel_result = control->Complete();
2615 if (parallel_result.has_value() && state.IsValid()) {
2616 state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, strprintf("block-script-verify-flag-failed (%s)", ScriptErrorString(parallel_result->first)), parallel_result->second);
2617 }
2618 }
2619 if (!state.IsValid()) {
2620 LogInfo("Block validation error: %s", state.ToString());
2621 return false;
2622 }
2623 const auto time_4{SteadyClock::now()};
2624 m_chainman.time_verify += time_4 - time_2;
2625 LogDebug(BCLog::BENCH, " - Verify %u txins: %.2fms (%.3fms/txin) [%.2fs (%.2fms/blk)]\n", nInputs - 1,
2626 Ticks<MillisecondsDouble>(time_4 - time_2),
2627 nInputs <= 1 ? 0 : Ticks<MillisecondsDouble>(time_4 - time_2) / (nInputs - 1),
2628 Ticks<SecondsDouble>(m_chainman.time_verify),
2629 Ticks<MillisecondsDouble>(m_chainman.time_verify) / m_chainman.num_blocks_total);
2630
2631 if (fJustCheck) {
2632 return true;
2633 }
2634
2635 if (!m_blockman.WriteBlockUndo(blockundo, state, *pindex)) {
2636 return false;
2637 }
2638
2639 const auto time_5{SteadyClock::now()};
2640 m_chainman.time_undo += time_5 - time_4;
2641 LogDebug(BCLog::BENCH, " - Write undo data: %.2fms [%.2fs (%.2fms/blk)]\n",
2642 Ticks<MillisecondsDouble>(time_5 - time_4),
2643 Ticks<SecondsDouble>(m_chainman.time_undo),
2644 Ticks<MillisecondsDouble>(m_chainman.time_undo) / m_chainman.num_blocks_total);
2645
2646 if (!pindex->IsValid(BLOCK_VALID_SCRIPTS)) {
2648 m_blockman.m_dirty_blockindex.insert(pindex);
2649 }
2650
2651 // add this block to the view's block chain
2652 view.SetBestBlock(pindex->GetBlockHash());
2653
2654 const auto time_6{SteadyClock::now()};
2655 m_chainman.time_index += time_6 - time_5;
2656 LogDebug(BCLog::BENCH, " - Index writing: %.2fms [%.2fs (%.2fms/blk)]\n",
2657 Ticks<MillisecondsDouble>(time_6 - time_5),
2658 Ticks<SecondsDouble>(m_chainman.time_index),
2659 Ticks<MillisecondsDouble>(m_chainman.time_index) / m_chainman.num_blocks_total);
2660
2661 TRACEPOINT(validation, block_connected,
2662 block_hash.data(),
2663 pindex->nHeight,
2664 block.vtx.size(),
2665 nInputs,
2666 nSigOpsCost,
2667 Ticks<std::chrono::nanoseconds>(time_5 - time_start)
2668 );
2669
2670 return true;
2671}
2672
2673CoinsCacheSizeState Chainstate::GetCoinsCacheSizeState()
2674{
2676 return this->GetCoinsCacheSizeState(
2679}
2680
2681CoinsCacheSizeState Chainstate::GetCoinsCacheSizeState(
2682 size_t max_coins_cache_size_bytes,
2683 size_t max_mempool_size_bytes)
2684{
2686 const int64_t nMempoolUsage = m_mempool ? m_mempool->DynamicMemoryUsage() : 0;
2687 int64_t cacheSize = CoinsTip().DynamicMemoryUsage();
2688 int64_t nTotalSpace =
2689 max_coins_cache_size_bytes + std::max<int64_t>(int64_t(max_mempool_size_bytes) - nMempoolUsage, 0);
2690
2691 if (cacheSize > nTotalSpace) {
2692 LogInfo("Cache size (%s) exceeds total space (%s)\n", cacheSize, nTotalSpace);
2694 } else if (cacheSize > LargeCoinsCacheThreshold(nTotalSpace)) {
2696 }
2698}
2699
2701 BlockValidationState &state,
2702 FlushStateMode mode,
2703 int nManualPruneHeight)
2704{
2705 LOCK(cs_main);
2706 assert(this->CanFlushToDisk());
2707 std::set<int> setFilesToPrune;
2708 bool full_flush_completed = false;
2709
2710 [[maybe_unused]] const size_t coins_count{CoinsTip().GetCacheSize()};
2711 [[maybe_unused]] const size_t coins_mem_usage{CoinsTip().DynamicMemoryUsage()};
2712
2713 try {
2714 {
2715 bool fFlushForPrune = false;
2716
2717 CoinsCacheSizeState cache_state = GetCoinsCacheSizeState();
2719 // make sure we don't prune above any of the prune locks bestblocks
2720 // pruning is height-based
2721 int last_prune{m_chain.Height()}; // last height we can prune
2722 std::optional<std::string> limiting_lock; // prune lock that actually was the limiting factor, only used for logging
2723
2724 for (const auto& prune_lock : m_blockman.m_prune_locks) {
2725 if (prune_lock.second.height_first == std::numeric_limits<int>::max()) continue;
2726 // Remove the buffer and one additional block here to get actual height that is outside of the buffer
2727 const int lock_height{prune_lock.second.height_first - PRUNE_LOCK_BUFFER - 1};
2728 last_prune = std::max(1, std::min(last_prune, lock_height));
2729 if (last_prune == lock_height) {
2730 limiting_lock = prune_lock.first;
2731 }
2732 }
2733
2734 if (limiting_lock) {
2735 LogDebug(BCLog::PRUNE, "%s limited pruning to height %d\n", limiting_lock.value(), last_prune);
2736 }
2737
2738 if (nManualPruneHeight > 0) {
2739 LOG_TIME_MILLIS_WITH_CATEGORY("find files to prune (manual)", BCLog::BENCH);
2740
2742 setFilesToPrune,
2743 std::min(last_prune, nManualPruneHeight),
2744 *this);
2745 } else {
2746 LOG_TIME_MILLIS_WITH_CATEGORY("find files to prune", BCLog::BENCH);
2747
2748 m_blockman.FindFilesToPrune(setFilesToPrune, last_prune, *this, m_chainman);
2750 }
2751 if (!setFilesToPrune.empty()) {
2752 fFlushForPrune = true;
2754 m_blockman.m_block_tree_db->WriteFlag("prunedblockfiles", true);
2756 }
2757 }
2758 }
2759 const auto nNow{NodeClock::now()};
2760 // The cache is large and we're within 10% and 10 MiB of the limit, but we have time now (not in the middle of a block processing).
2761 bool fCacheLarge = mode == FlushStateMode::PERIODIC && cache_state >= CoinsCacheSizeState::LARGE;
2762 // The cache is over the limit, we have to write now.
2763 bool fCacheCritical = mode == FlushStateMode::IF_NEEDED && cache_state >= CoinsCacheSizeState::CRITICAL;
2764 // It's been a while since we wrote the block index and chain state to disk. Do this frequently, so we don't need to redownload or reindex after a crash.
2765 bool fPeriodicWrite = mode == FlushStateMode::PERIODIC && nNow >= m_next_write;
2766 const auto empty_cache{(mode == FlushStateMode::FORCE_FLUSH) || fCacheLarge || fCacheCritical};
2767 // Combine all conditions that result in a write to disk.
2768 bool should_write = (mode == FlushStateMode::FORCE_SYNC) || empty_cache || fPeriodicWrite || fFlushForPrune;
2769 // Write blocks, block index and best chain related state to disk.
2770 if (should_write) {
2771 LogDebug(BCLog::COINDB, "Writing chainstate to disk: flush mode=%s, prune=%d, large=%d, critical=%d, periodic=%d",
2772 FlushStateModeNames[size_t(mode)], fFlushForPrune, fCacheLarge, fCacheCritical, fPeriodicWrite);
2773
2774 // Ensure we can write block index
2776 return FatalError(m_chainman.GetNotifications(), state, _("Disk space is too low!"));
2777 }
2778 {
2779 LOG_TIME_MILLIS_WITH_CATEGORY("write block and undo data to disk", BCLog::BENCH);
2780
2781 // First make sure all block and undo data is flushed to disk.
2782 // TODO: Handle return error, or add detailed comment why it is
2783 // safe to not return an error upon failure.
2784 if (!m_blockman.FlushChainstateBlockFile(m_chain.Height())) {
2785 LogWarning("%s: Failed to flush block file.\n", __func__);
2786 }
2787 }
2788
2789 // Then update all block file information (which may refer to block and undo files).
2790 {
2791 LOG_TIME_MILLIS_WITH_CATEGORY("write block index to disk", BCLog::BENCH);
2792
2793 m_blockman.WriteBlockIndexDB();
2794 }
2795 // Finally remove any pruned files
2796 if (fFlushForPrune) {
2797 LOG_TIME_MILLIS_WITH_CATEGORY("unlink pruned files", BCLog::BENCH);
2798
2799 m_blockman.UnlinkPrunedFiles(setFilesToPrune);
2800 }
2801
2802 if (!CoinsTip().GetBestBlock().IsNull()) {
2803 // Typical Coin structures on disk are around 48 bytes in size.
2804 // Pushing a new one to the database can cause it to be written
2805 // twice (once in the log, and once in the tables). This is already
2806 // an overestimation, as most will delete an existing entry or
2807 // overwrite one. Still, use a conservative safety factor of 2.
2808 if (!CheckDiskSpace(m_chainman.m_options.datadir, 48 * 2 * 2 * CoinsTip().GetDirtyCount())) {
2809 return FatalError(m_chainman.GetNotifications(), state, _("Disk space is too low!"));
2810 }
2811 // Flush the chainstate (which may refer to block index entries).
2812 empty_cache ? CoinsTip().Flush() : CoinsTip().Sync();
2813 m_last_flushed_block = m_blockman.LookupBlockIndex(CoinsTip().GetBestBlock());
2814 full_flush_completed = true;
2815 TRACEPOINT(utxocache, flush,
2816 int64_t{Ticks<std::chrono::microseconds>(NodeClock::now() - nNow)},
2817 (uint32_t)mode,
2818 (uint64_t)coins_count,
2819 (uint64_t)coins_mem_usage,
2820 (bool)fFlushForPrune);
2821 }
2822 }
2823
2824 if (should_write || m_next_write == NodeClock::time_point::max()) {
2827 }
2828 }
2829 if (full_flush_completed) {
2831 m_chainman.m_options.signals->ChainStateFlushed(this->GetRole(), GetLocator(m_last_flushed_block));
2832 }
2833
2835 try {
2837 } catch (const std::exception& e) {
2838 LogWarning("Failed to start chainstate compaction (%s)", e.what());
2839 }
2840 }
2841 }
2842 } catch (const std::runtime_error& e) {
2843 return FatalError(m_chainman.GetNotifications(), state, strprintf(_("System error while flushing: %s"), e.what()));
2844 }
2845 return true;
2846}
2847
2849{
2852 LogWarning("Failed to force flush state (%s)", state.ToString());
2853 }
2854}
2855
2857{
2860 if (!this->FlushStateToDisk(state, FlushStateMode::NONE)) {
2861 LogWarning("Failed to flush state (%s)", state.ToString());
2862 }
2863}
2864
2865static void UpdateTipLog(
2866 const ChainstateManager& chainman,
2867 const CCoinsViewCache& coins_tip,
2868 const CBlockIndex* tip,
2869 const std::string& func_name,
2870 const std::string& prefix,
2871 const std::string& warning_messages,
2872 const bool background_validation) EXCLUSIVE_LOCKS_REQUIRED(::cs_main)
2873{
2874
2876
2877 // Disable rate limiting as this may log frequently during IBD.
2878 LogInfo(util::log::NO_RATE_LIMIT, "%s%s: new best=%s height=%d version=0x%08x log2_work=%f tx=%lu date='%s' progress=%f cache=%.1fMiB(%utxo)%s\n",
2879 prefix, func_name,
2880 tip->GetBlockHash().ToString(), tip->nHeight, tip->nVersion,
2881 log(tip->nChainWork.getdouble()) / log(2.0), tip->m_chain_tx_count,
2883 background_validation ? chainman.GetBackgroundVerificationProgress(*tip) : chainman.GuessVerificationProgress(tip),
2884 coins_tip.DynamicMemoryUsage() / double(1_MiB),
2885 coins_tip.GetCacheSize(),
2886 !warning_messages.empty() ? strprintf(" warning='%s'", warning_messages) : "");
2887}
2888
2889void Chainstate::UpdateTip(const CBlockIndex* pindexNew)
2890{
2892 const auto& coins_tip = this->CoinsTip();
2893
2894 // The remainder of the function isn't relevant if we are not acting on
2895 // the active chainstate, so return if need be.
2896 if (this != &m_chainman.ActiveChainstate()) {
2897 // Only log every so often so that we don't bury log messages at the tip.
2898 constexpr int BACKGROUND_LOG_INTERVAL = 2000;
2899 if (pindexNew->nHeight % BACKGROUND_LOG_INTERVAL == 0) {
2900 UpdateTipLog(m_chainman, coins_tip, pindexNew, __func__, "[background validation] ", "", /*background_validation=*/true);
2901 }
2902 return;
2903 }
2904
2905 // New best block
2906 if (m_mempool) {
2908 }
2909
2910 std::vector<bilingual_str> warning_messages;
2913 for (auto [bit, active] : bits) {
2914 const bilingual_str warning = strprintf(_("Unknown new rules activated (versionbit %i)"), bit);
2915 if (active) {
2917 } else {
2918 warning_messages.push_back(warning);
2919 }
2920 }
2921 }
2922 UpdateTipLog(m_chainman, coins_tip, pindexNew, __func__, "",
2923 util::Join(warning_messages, Untranslated(", ")).original, /*background_validation=*/false);
2924}
2925
2937{
2940
2941 CBlockIndex *pindexDelete = m_chain.Tip();
2942 assert(pindexDelete);
2943 assert(pindexDelete->pprev);
2944 // Read block from disk.
2945 std::shared_ptr<CBlock> pblock = std::make_shared<CBlock>();
2946 CBlock& block = *pblock;
2947 if (!m_blockman.ReadBlock(block, *pindexDelete)) {
2948 LogError("DisconnectTip(): Failed to read block\n");
2949 return false;
2950 }
2951 // Apply the block atomically to the chain state.
2952 const auto time_start{SteadyClock::now()};
2953 {
2954 CCoinsViewCache view(&CoinsTip());
2955 assert(view.GetBestBlock() == pindexDelete->GetBlockHash());
2956 if (DisconnectBlock(block, pindexDelete, view) != DISCONNECT_OK) {
2957 LogError("DisconnectTip(): DisconnectBlock %s failed\n", pindexDelete->GetBlockHash().ToString());
2958 return false;
2959 }
2960 view.Flush(/*reallocate_cache=*/false); // local CCoinsViewCache goes out of scope
2961 }
2962 LogDebug(BCLog::BENCH, "- Disconnect block: %.2fms\n",
2963 Ticks<MillisecondsDouble>(SteadyClock::now() - time_start));
2964
2965 {
2966 // Prune locks that began at or after the tip should be moved backward so they get a chance to reorg
2967 const int max_height_first{pindexDelete->nHeight - 1};
2968 for (auto& prune_lock : m_blockman.m_prune_locks) {
2969 if (prune_lock.second.height_first <= max_height_first) continue;
2970
2971 prune_lock.second.height_first = max_height_first;
2972 LogDebug(BCLog::PRUNE, "%s prune lock moved back to %d\n", prune_lock.first, max_height_first);
2973 }
2974 }
2975
2976 // Write the chain state to disk, if necessary.
2978 return false;
2979 }
2980
2981 if (disconnectpool && m_mempool) {
2982 // Save transactions to re-add to mempool at end of reorg. If any entries are evicted for
2983 // exceeding memory limits, remove them and their descendants from the mempool.
2984 for (auto&& evicted_tx : disconnectpool->AddTransactionsFromBlock(block.vtx)) {
2986 }
2987 }
2988
2989 m_chain.SetTip(*pindexDelete->pprev);
2991
2992 UpdateTip(pindexDelete->pprev);
2993 // Let wallets know transactions went from 1-confirmed to
2994 // 0-confirmed or conflicted:
2996 m_chainman.m_options.signals->BlockDisconnected(std::move(pblock), pindexDelete);
2997 }
2998 return true;
2999}
3000
3003 std::shared_ptr<const CBlock> pblock;
3004};
3005
3013 BlockValidationState& state,
3014 CBlockIndex* pindexNew,
3015 std::shared_ptr<const CBlock> block_to_connect,
3016 std::vector<ConnectedBlock>& connected_blocks,
3017 DisconnectedBlockTransactions& disconnectpool)
3018{
3021
3022 assert(pindexNew->pprev == m_chain.Tip());
3023 // Read block from disk.
3024 const auto time_1{SteadyClock::now()};
3025 if (!block_to_connect) {
3026 std::shared_ptr<CBlock> pblockNew = std::make_shared<CBlock>();
3027 if (!m_blockman.ReadBlock(*pblockNew, *pindexNew)) {
3028 return FatalError(m_chainman.GetNotifications(), state, _("Failed to read block."));
3029 }
3030 block_to_connect = std::move(pblockNew);
3031 } else {
3032 LogDebug(BCLog::BENCH, " - Using cached block\n");
3033 }
3034 // Apply the block atomically to the chain state.
3035 const auto time_2{SteadyClock::now()};
3036 SteadyClock::time_point time_3;
3037 // When adding aggregate statistics in the future, keep in mind that
3038 // num_blocks_total may be zero until the ConnectBlock() call below.
3039 LogDebug(BCLog::BENCH, " - Load block from disk: %.2fms\n",
3040 Ticks<MillisecondsDouble>(time_2 - time_1));
3041 {
3042 CoinsViewOverlay& view{*m_coins_views->m_connect_block_view};
3043 const auto reset_guard{view.StartFetching(*block_to_connect)};
3044 bool rv = ConnectBlock(*block_to_connect, state, pindexNew, view);
3046 m_chainman.m_options.signals->BlockChecked(block_to_connect, state);
3047 }
3048 if (!rv) {
3049 if (state.IsInvalid())
3050 InvalidBlockFound(pindexNew, state);
3051 LogError("%s: ConnectBlock %s failed, %s\n", __func__, pindexNew->GetBlockHash().ToString(), state.ToString());
3052 return false;
3053 }
3054 time_3 = SteadyClock::now();
3055 m_chainman.time_connect_total += time_3 - time_2;
3056 assert(m_chainman.num_blocks_total > 0);
3057 LogDebug(BCLog::BENCH, " - Connect total: %.2fms [%.2fs (%.2fms/blk)]\n",
3058 Ticks<MillisecondsDouble>(time_3 - time_2),
3059 Ticks<SecondsDouble>(m_chainman.time_connect_total),
3060 Ticks<MillisecondsDouble>(m_chainman.time_connect_total) / m_chainman.num_blocks_total);
3061 view.Flush(/*reallocate_cache=*/false); // No need to reallocate since it only has capacity for 1 block
3062 }
3063 const auto time_4{SteadyClock::now()};
3064 m_chainman.time_flush += time_4 - time_3;
3065 LogDebug(BCLog::BENCH, " - Flush: %.2fms [%.2fs (%.2fms/blk)]\n",
3066 Ticks<MillisecondsDouble>(time_4 - time_3),
3067 Ticks<SecondsDouble>(m_chainman.time_flush),
3068 Ticks<MillisecondsDouble>(m_chainman.time_flush) / m_chainman.num_blocks_total);
3069 // Write the chain state to disk, if necessary.
3071 return false;
3072 }
3073 const auto time_5{SteadyClock::now()};
3074 m_chainman.time_chainstate += time_5 - time_4;
3075 LogDebug(BCLog::BENCH, " - Writing chainstate: %.2fms [%.2fs (%.2fms/blk)]\n",
3076 Ticks<MillisecondsDouble>(time_5 - time_4),
3077 Ticks<SecondsDouble>(m_chainman.time_chainstate),
3078 Ticks<MillisecondsDouble>(m_chainman.time_chainstate) / m_chainman.num_blocks_total);
3079 // Remove conflicting transactions from the mempool.
3080 std::vector<RemovedMempoolTransactionInfo> txs_removed_for_block;
3081 if (m_mempool) {
3082 txs_removed_for_block = m_mempool->removeForBlock(block_to_connect->vtx);
3083 disconnectpool.removeForBlock(block_to_connect->vtx);
3084 }
3085 // Update m_chain & related variables.
3086 m_chain.SetTip(*pindexNew);
3088 // Not fired while IBD is active. removeForBlock() above still runs.
3090 m_chainman.m_options.signals->MempoolTransactionsRemovedForBlock(block_to_connect, std::move(txs_removed_for_block), pindexNew->nHeight);
3091 }
3092 UpdateTip(pindexNew);
3093
3094 const auto time_6{SteadyClock::now()};
3095 m_chainman.time_post_connect += time_6 - time_5;
3096 m_chainman.time_total += time_6 - time_1;
3097 LogDebug(BCLog::BENCH, " - Connect postprocess: %.2fms [%.2fs (%.2fms/blk)]\n",
3098 Ticks<MillisecondsDouble>(time_6 - time_5),
3099 Ticks<SecondsDouble>(m_chainman.time_post_connect),
3100 Ticks<MillisecondsDouble>(m_chainman.time_post_connect) / m_chainman.num_blocks_total);
3101 LogDebug(BCLog::BENCH, "- Connect block: %.2fms [%.2fs (%.2fms/blk)]\n",
3102 Ticks<MillisecondsDouble>(time_6 - time_1),
3103 Ticks<SecondsDouble>(m_chainman.time_total),
3104 Ticks<MillisecondsDouble>(m_chainman.time_total) / m_chainman.num_blocks_total);
3105
3106 // See if this chainstate has reached a target block and can be used to
3107 // validate an assumeutxo snapshot. If it can, hashing the UTXO database
3108 // will be slow, and cs_main could remain locked here for several minutes.
3109 // If the snapshot is validated, the UTXO hash will be saved to
3110 // this->m_target_utxohash, causing HistoricalChainstate() to return null
3111 // and this chainstate to no longer be used. ActivateBestChain() will also
3112 // stop connecting blocks to this chainstate because this->ReachedTarget()
3113 // will be true and this->setBlockIndexCandidates will not have additional
3114 // blocks.
3116 m_chainman.MaybeValidateSnapshot(*this, current_cs);
3117
3118 connected_blocks.emplace_back(pindexNew, std::move(block_to_connect));
3119 return true;
3120}
3121
3127{
3129 do {
3130 CBlockIndex *pindexNew = nullptr;
3131
3132 // Find the best candidate header.
3133 {
3134 std::set<CBlockIndex*, CBlockIndexWorkComparator>::reverse_iterator it = setBlockIndexCandidates.rbegin();
3135 if (it == setBlockIndexCandidates.rend())
3136 return nullptr;
3137 pindexNew = *it;
3138 }
3139
3140 // Check whether all blocks on the path between the currently active chain and the candidate are valid.
3141 // Just going until the active chain is an optimization, as we know all blocks in it are valid already.
3142 bool fInvalidAncestor = false;
3143 for (CBlockIndex *pindexTest = pindexNew; pindexTest && !m_chain.Contains(*pindexTest); pindexTest = pindexTest->pprev) {
3144 assert(pindexTest->HaveNumChainTxs() || pindexTest->nHeight == 0);
3145
3146 // Pruned nodes may have entries in setBlockIndexCandidates for
3147 // which block files have been deleted. Remove those as candidates
3148 // for the most work chain if we come across them; we can't switch
3149 // to a chain unless we have all the non-active-chain parent blocks.
3150 bool fFailedChain = pindexTest->nStatus & BLOCK_FAILED_VALID;
3151 bool fMissingData = !(pindexTest->nStatus & BLOCK_HAVE_DATA);
3152 if (fFailedChain || fMissingData) {
3153 // Candidate chain is not usable (either invalid or missing data)
3154 if (fFailedChain && (m_chainman.m_best_invalid == nullptr || pindexNew->nChainWork > m_chainman.m_best_invalid->nChainWork)) {
3155 m_chainman.m_best_invalid = pindexNew;
3156 }
3157 // Remove the entire chain from the set.
3158 for (CBlockIndex *pindexFailed = pindexNew; pindexFailed != pindexTest; pindexFailed = pindexFailed->pprev) {
3159 // If we're missing data and not a descendant of an invalid block,
3160 // then add back to m_blocks_unlinked, so that if the block arrives in the future
3161 // we can try adding to setBlockIndexCandidates again.
3162 if (fMissingData && !fFailedChain) {
3163 // Avoid duplicate entries in m_blocks_unlinked. If the same entry is
3164 // processed twice in ReceivedBlockTransactions(), it may be re-added to
3165 // setBlockIndexCandidates with a modified nSequenceId, breaking ordering
3166 // guarantees and leading to undefined behavior.
3167 m_blockman.AddUnlinkedBlock(pindexFailed);
3168 }
3169 setBlockIndexCandidates.erase(pindexFailed);
3170 }
3171 setBlockIndexCandidates.erase(pindexTest);
3172 fInvalidAncestor = true;
3173 break;
3174 }
3175 }
3176 if (!fInvalidAncestor)
3177 return pindexNew;
3178 } while(true);
3179}
3180
3183 // Note that we can't delete the current block itself, as we may need to return to it later in case a
3184 // reorganization to a better block fails.
3185 std::set<CBlockIndex*, CBlockIndexWorkComparator>::iterator it = setBlockIndexCandidates.begin();
3186 while (it != setBlockIndexCandidates.end() && setBlockIndexCandidates.value_comp()(*it, m_chain.Tip())) {
3187 setBlockIndexCandidates.erase(it++);
3188 }
3189 // Either the current tip or a successor of it we're working towards is left in setBlockIndexCandidates.
3191}
3192
3199bool Chainstate::ActivateBestChainStep(BlockValidationState& state, CBlockIndex& index_most_work, const std::shared_ptr<const CBlock>& pblock, bool& fInvalidFound, std::vector<ConnectedBlock>& connected_blocks)
3200{
3203
3204 const CBlockIndex* pindexOldTip = m_chain.Tip();
3205 const CBlockIndex* pindexFork = m_chain.FindFork(index_most_work);
3206
3207 // Disconnect active blocks which are no longer in the best chain.
3208 bool fBlocksDisconnected = false;
3210 while (m_chain.Tip() && m_chain.Tip() != pindexFork) {
3211 if (!DisconnectTip(state, &disconnectpool)) {
3212 // This is likely a fatal error, but keep the mempool consistent,
3213 // just in case. Only remove from the mempool in this case.
3214 MaybeUpdateMempoolForReorg(disconnectpool, false);
3215
3216 // If we're unable to disconnect a block during normal operation,
3217 // then that is a failure of our local system -- we should abort
3218 // rather than stay on a less work chain.
3219 FatalError(m_chainman.GetNotifications(), state, _("Failed to disconnect block."));
3220 return false;
3221 }
3222 fBlocksDisconnected = true;
3223 }
3224
3225 // Build list of new blocks to connect (in descending height order).
3226 std::vector<CBlockIndex*> vpindexToConnect;
3227 bool fContinue = true;
3228 int nHeight = pindexFork ? pindexFork->nHeight : -1;
3229 while (fContinue && nHeight != index_most_work.nHeight) {
3230 // Don't iterate the entire list of potential improvements toward the best tip, as we likely only need
3231 // a few blocks along the way.
3232 int nTargetHeight = std::min(nHeight + 32, index_most_work.nHeight);
3233 vpindexToConnect.clear();
3234 vpindexToConnect.reserve(nTargetHeight - nHeight);
3235 CBlockIndex* pindexIter = index_most_work.GetAncestor(nTargetHeight);
3236 while (pindexIter && pindexIter->nHeight != nHeight) {
3237 vpindexToConnect.push_back(pindexIter);
3238 pindexIter = pindexIter->pprev;
3239 }
3240 nHeight = nTargetHeight;
3241
3242 // Connect new blocks.
3243 for (CBlockIndex* pindexConnect : vpindexToConnect | std::views::reverse) {
3244 if (!ConnectTip(state, pindexConnect, pindexConnect == &index_most_work ? pblock : std::shared_ptr<const CBlock>(), connected_blocks, disconnectpool)) {
3245 if (state.IsInvalid()) {
3246 // The block violates a consensus rule.
3248 InvalidChainFound(vpindexToConnect.front());
3249 }
3250 state = BlockValidationState();
3251 fInvalidFound = true;
3252 fContinue = false;
3253 break;
3254 } else {
3255 // A system error occurred (disk space, database error, ...).
3256 // Make the mempool consistent with the current tip, just in case
3257 // any observers try to use it before shutdown.
3258 MaybeUpdateMempoolForReorg(disconnectpool, false);
3259 return false;
3260 }
3261 } else {
3263 if (!pindexOldTip || m_chain.Tip()->nChainWork > pindexOldTip->nChainWork) {
3264 // We're in a better position than we were. Return temporarily to release the lock.
3265 fContinue = false;
3266 break;
3267 }
3268 }
3269 }
3270 }
3271
3272 if (fBlocksDisconnected) {
3273 // If any blocks were disconnected, disconnectpool may be non empty. Add
3274 // any disconnected transactions back to the mempool.
3275 MaybeUpdateMempoolForReorg(disconnectpool, true);
3276 }
3277 if (m_mempool) m_mempool->check(this->CoinsTip(), this->m_chain.Height() + 1);
3278
3280
3281 return true;
3282}
3283
3284static SynchronizationState GetSynchronizationState(bool init, bool blockfiles_indexed)
3285{
3287 if (!blockfiles_indexed) return SynchronizationState::INIT_REINDEX;
3289}
3290
3292{
3294 if (!m_cached_is_ibd.load(std::memory_order_relaxed)) return;
3295 if (m_blockman.LoadingBlocks()) return;
3296 if (!CurrentChainstate().m_chain.IsTipRecent(MinimumChainWork(), m_options.max_tip_age)) return;
3297 LogInfo("Leaving InitialBlockDownload (latching to false)");
3298 m_cached_is_ibd.store(false, std::memory_order_relaxed);
3299}
3300
3302{
3303 bool fNotify = false;
3304 bool fInitialBlockDownload = false;
3305 CBlockIndex* pindexHeader = nullptr;
3306 {
3307 LOCK(GetMutex());
3308 pindexHeader = m_best_header;
3309
3310 if (pindexHeader != m_last_notified_header) {
3311 fNotify = true;
3312 fInitialBlockDownload = IsInitialBlockDownload();
3313 m_last_notified_header = pindexHeader;
3314 }
3315 }
3316 // Send block tip changed notifications without the lock held
3317 if (fNotify) {
3318 GetNotifications().headerTip(GetSynchronizationState(fInitialBlockDownload, m_blockman.m_blockfiles_indexed), pindexHeader->nHeight, pindexHeader->nTime, false);
3319 }
3320 return fNotify;
3321}
3322
3325
3326 if (signals.CallbacksPending() > 10) {
3327 signals.SyncWithValidationInterfaceQueue();
3328 }
3329}
3330
3331bool Chainstate::ActivateBestChain(BlockValidationState& state, std::shared_ptr<const CBlock> pblock)
3332{
3334
3335 // Note that while we're often called here from ProcessNewBlock, this is
3336 // far from a guarantee. Things in the P2P/RPC will often end up calling
3337 // us in the middle of ProcessNewBlock - do not assume pblock is set
3338 // sanely for performance or correctness!
3340
3341 // ABC maintains a fair degree of expensive-to-calculate internal state
3342 // because this function periodically releases cs_main so that it does not lock up other threads for too long
3343 // during large connects - and to allow for e.g. the callback queue to drain
3344 // we use m_chainstate_mutex to enforce mutual exclusion so that only one caller may execute this function at a time
3346
3347 // Belt-and-suspenders check that we aren't attempting to advance the
3348 // chainstate past the target block.
3349 if (WITH_LOCK(::cs_main, return m_target_utxohash)) {
3350 LogError("%s", STR_INTERNAL_BUG("m_target_utxohash is set - this chainstate should not be in operation."));
3351 return Assume(false);
3352 }
3353
3354 CBlockIndex *pindexMostWork = nullptr;
3355 CBlockIndex *pindexNewTip = nullptr;
3356 bool exited_ibd{false};
3357 do {
3358 // Block until the validation queue drains. This should largely
3359 // never happen in normal operation, however may happen during
3360 // reindex, causing memory blowup if we run too far ahead.
3361 // Note that if a validationinterface callback ends up calling
3362 // ActivateBestChain this may lead to a deadlock! We should
3363 // probably have a DEBUG_LOCKORDER test for this in the future.
3365
3366 {
3367 LOCK(cs_main);
3368 {
3369 // Lock transaction pool for at least as long as it takes for connected_blocks to be consumed
3370 LOCK(MempoolMutex());
3371 const bool was_in_ibd = m_chainman.IsInitialBlockDownload();
3372 CBlockIndex* starting_tip = m_chain.Tip();
3373 bool blocks_connected = false;
3374 do {
3375 // We absolutely may not unlock cs_main until we've made forward progress
3376 // (with the exception of shutdown due to hardware issues, low disk space, etc).
3377 std::vector<ConnectedBlock> connected_blocks; // Destructed before cs_main is unlocked
3378
3379 if (pindexMostWork == nullptr) {
3380 pindexMostWork = FindMostWorkChain();
3381 }
3382
3383 // Whether we have anything to do at all.
3384 if (pindexMostWork == nullptr || pindexMostWork == m_chain.Tip()) {
3385 break;
3386 }
3387
3388 bool fInvalidFound = false;
3389 std::shared_ptr<const CBlock> nullBlockPtr;
3390 // BlockConnected signals must be sent for the original role;
3391 // in case snapshot validation is completed during ActivateBestChainStep, the
3392 // result of GetRole() changes from BACKGROUND to NORMAL.
3393 const ChainstateRole chainstate_role{this->GetRole()};
3394 if (!ActivateBestChainStep(state, *pindexMostWork, pblock && pblock->GetHash() == pindexMostWork->GetBlockHash() ? pblock : nullBlockPtr, fInvalidFound, connected_blocks)) {
3395 // A system error occurred
3396 return false;
3397 }
3398 blocks_connected = true;
3399
3400 if (fInvalidFound) {
3401 // Wipe cache, we may need another branch now.
3402 pindexMostWork = nullptr;
3403 }
3404 pindexNewTip = m_chain.Tip();
3405
3406 for (auto& [index, block] : std::move(connected_blocks)) {
3408 m_chainman.m_options.signals->BlockConnected(chainstate_role, std::move(Assert(block)), Assert(index));
3409 }
3410 }
3411
3412 // Break this do-while to ensure we don't advance past the target block.
3413 if (ReachedTarget()) {
3414 break;
3415 }
3416 } while (!m_chain.Tip() || (starting_tip && CBlockIndexWorkComparator()(m_chain.Tip(), starting_tip)));
3417 if (!blocks_connected) return true;
3418
3419 const CBlockIndex* pindexFork = starting_tip ? m_chain.FindFork(*starting_tip) : nullptr;
3420 bool still_in_ibd = m_chainman.IsInitialBlockDownload();
3421
3422 if (was_in_ibd && !still_in_ibd) {
3423 // Active chainstate has exited IBD.
3424 exited_ibd = true;
3425 }
3426
3427 // Notify external listeners about the new tip.
3428 // Enqueue while holding cs_main to ensure that UpdatedBlockTip is called in the order in which blocks are connected
3429 if (this == &m_chainman.ActiveChainstate() && pindexFork != pindexNewTip) {
3430 // Notify ValidationInterface subscribers
3432 m_chainman.m_options.signals->UpdatedBlockTip(pindexNewTip, pindexFork, still_in_ibd);
3433 }
3434
3437 /*index=*/*pindexNewTip,
3438 /*verification_progress=*/m_chainman.GuessVerificationProgress(pindexNewTip))))
3439 {
3440 // Just breaking and returning success for now. This could
3441 // be changed to bubble up the kernel::Interrupted value to
3442 // the caller so the caller could distinguish between
3443 // completed and interrupted operations.
3444 break;
3445 }
3446 }
3447 } // release MempoolMutex
3448 // Notify external listeners about the new tip, even if pindexFork == pindexNewTip.
3451 }
3452 } // release cs_main
3453 // When we reach this point, we switched to a new tip (stored in pindexNewTip).
3454
3455 bool reached_target;
3456 {
3458 if (exited_ibd) {
3459 // If a background chainstate is in use, we may need to rebalance our
3460 // allocation of caches once a chainstate exits initial block download.
3461 m_chainman.MaybeRebalanceCaches();
3462 }
3463
3464 // Write changes periodically to disk, after relay.
3466 return false;
3467 }
3468
3469 reached_target = ReachedTarget();
3470 }
3471
3472 if (reached_target) {
3473 // Chainstate has reached the target block, so exit.
3474 //
3475 // Restart indexes so indexes can resync and index new blocks after
3476 // the target block.
3477 //
3478 // This cannot be done while holding cs_main (within
3479 // MaybeValidateSnapshot) or a cs_main deadlock will occur.
3482 }
3483 break;
3484 }
3485
3486 // We check interrupt only after giving ActivateBestChainStep a chance to run once so that we
3487 // never interrupt before connecting the genesis block during LoadChainTip(). Previously this
3488 // caused an assert() failure during interrupt in such cases as the UTXO DB flushing checks
3489 // that the best block hash is non-null.
3490 if (m_chainman.m_interrupt) break;
3491 } while (pindexNewTip != pindexMostWork);
3492
3494
3495 return true;
3496}
3497
3498bool Chainstate::PreciousBlock(BlockValidationState& state, CBlockIndex* pindex)
3499{
3502 {
3503 LOCK(cs_main);
3504 if (pindex->nChainWork < m_chain.Tip()->nChainWork) {
3505 // Nothing to do, this block is not at the tip.
3506 return true;
3507 }
3509 // The chain has been extended since the last call, reset the counter.
3511 }
3513 setBlockIndexCandidates.erase(pindex);
3515 if (m_chainman.nBlockReverseSequenceId > std::numeric_limits<int32_t>::min()) {
3516 // We can't keep reducing the counter if somebody really wants to
3517 // call preciousblock 2**31-1 times on the same set of tips...
3519 }
3520 if (pindex->IsValid(BLOCK_VALID_TRANSACTIONS) && pindex->HaveNumChainTxs()) {
3521 setBlockIndexCandidates.insert(pindex);
3523 }
3524 }
3525
3526 return ActivateBestChain(state, std::shared_ptr<const CBlock>());
3527}
3528
3530{
3533
3534 // Genesis block can't be invalidated
3535 assert(pindex);
3536 if (pindex->nHeight == 0) return false;
3537
3538 // We do not allow ActivateBestChain() to run while InvalidateBlock() is
3539 // running, as that could cause the tip to change while we disconnect
3540 // blocks.
3542
3543 // We'll be acquiring and releasing cs_main below, to allow the validation
3544 // callbacks to run. However, we should keep the block index in a
3545 // consistent state as we disconnect blocks -- in particular we need to
3546 // add equal-work blocks to setBlockIndexCandidates as we disconnect.
3547 // To avoid walking the block index repeatedly in search of candidates,
3548 // build a map once so that we can look up candidate blocks by chain
3549 // work as we go.
3550 std::multimap<const arith_uint256, CBlockIndex*> highpow_outofchain_headers;
3551
3552 {
3553 LOCK(cs_main);
3554 for (auto& entry : m_blockman.m_block_index) {
3555 CBlockIndex& candidate = entry.second;
3556 // We don't need to put anything in our active chain into the
3557 // multimap, because those candidates will be found and considered
3558 // as we disconnect.
3559 // Instead, consider only non-active-chain blocks that score
3560 // at least as good with CBlockIndexWorkComparator as the new tip.
3561 if (!m_chain.Contains(candidate) &&
3562 !CBlockIndexWorkComparator()(&candidate, pindex->pprev) &&
3563 !(candidate.nStatus & BLOCK_FAILED_VALID)) {
3564 highpow_outofchain_headers.insert({candidate.nChainWork, &candidate});
3565 }
3566 }
3567 }
3568
3569 CBlockIndex* to_mark_failed = pindex;
3570 bool pindex_was_in_chain = false;
3571 int disconnected = 0;
3572
3573 // Disconnect (descendants of) pindex, and mark them invalid.
3574 while (true) {
3575 if (m_chainman.m_interrupt) break;
3576
3577 // Make sure the queue of validation callbacks doesn't grow unboundedly.
3579
3580 LOCK(cs_main);
3581 // Lock for as long as disconnectpool is in scope to make sure MaybeUpdateMempoolForReorg is
3582 // called after DisconnectTip without unlocking in between
3583 LOCK(MempoolMutex());
3584 if (!m_chain.Contains(*pindex)) break;
3585 pindex_was_in_chain = true;
3586 CBlockIndex* const disconnected_tip{m_chain.Tip()};
3587
3588 // ActivateBestChain considers blocks already in m_chain
3589 // unconditionally valid already, so force disconnect away from it.
3591 bool ret = DisconnectTip(state, &disconnectpool);
3592 // DisconnectTip will add transactions to disconnectpool.
3593 // Adjust the mempool to be consistent with the new tip, adding
3594 // transactions back to the mempool if disconnecting was successful,
3595 // and we're not doing a very deep invalidation (in which case
3596 // keeping the mempool up to date is probably futile anyway).
3597 MaybeUpdateMempoolForReorg(disconnectpool, /* fAddToMempool = */ (++disconnected <= 10) && ret);
3598 if (!ret) return false;
3599 CBlockIndex* new_tip{m_chain.Tip()};
3600 assert(disconnected_tip->pprev == new_tip);
3601
3602 // We immediately mark the disconnected blocks as invalid.
3603 // This prevents a case where pruned nodes may fail to invalidateblock
3604 // and be left unable to start as they have no tip candidates (as there
3605 // are no blocks that meet the "have data and are not invalid per
3606 // nStatus" criteria for inclusion in setBlockIndexCandidates).
3607 disconnected_tip->nStatus |= BLOCK_FAILED_VALID;
3608 m_blockman.m_dirty_blockindex.insert(disconnected_tip);
3609 setBlockIndexCandidates.erase(disconnected_tip);
3610 setBlockIndexCandidates.insert(new_tip);
3611
3612 // Mark out-of-chain descendants of the invalidated block as invalid
3613 // Add any equal or more work headers that are not invalidated to setBlockIndexCandidates
3614 // Recalculate m_best_header if it became invalid.
3615 auto candidate_it = highpow_outofchain_headers.lower_bound(new_tip->nChainWork);
3616
3617 const bool best_header_needs_update{m_chainman.m_best_header->GetAncestor(disconnected_tip->nHeight) == disconnected_tip};
3618 if (best_header_needs_update) {
3619 // new_tip is definitely still valid at this point, but there may be better ones
3620 m_chainman.m_best_header = new_tip;
3621 }
3622
3623 while (candidate_it != highpow_outofchain_headers.end()) {
3624 CBlockIndex* candidate{candidate_it->second};
3625 if (candidate->GetAncestor(disconnected_tip->nHeight) == disconnected_tip) {
3626 // Children of failed blocks are marked as BLOCK_FAILED_VALID.
3627 candidate->nStatus |= BLOCK_FAILED_VALID;
3628 m_blockman.m_dirty_blockindex.insert(candidate);
3629 // If invalidated, the block is irrelevant for setBlockIndexCandidates
3630 // and for m_best_header and can be removed from the cache.
3631 candidate_it = highpow_outofchain_headers.erase(candidate_it);
3632 continue;
3633 }
3634 if (!CBlockIndexWorkComparator()(candidate, new_tip) &&
3635 candidate->IsValid(BLOCK_VALID_TRANSACTIONS) &&
3636 candidate->HaveNumChainTxs()) {
3637 setBlockIndexCandidates.insert(candidate);
3638 // Do not remove candidate from the highpow_outofchain_headers cache, because it might be a descendant of the block being invalidated
3639 // which needs to be marked failed later.
3640 }
3641 if (best_header_needs_update &&
3642 m_chainman.m_best_header->nChainWork < candidate->nChainWork) {
3643 m_chainman.m_best_header = candidate;
3644 }
3645 ++candidate_it;
3646 }
3647
3648 // Track the last disconnected block to call InvalidChainFound on it.
3649 to_mark_failed = disconnected_tip;
3650 }
3651
3653
3654 {
3655 LOCK(cs_main);
3656 if (m_chain.Contains(*to_mark_failed)) {
3657 // If the to-be-marked invalid block is in the active chain, something is interfering and we can't proceed.
3658 return false;
3659 }
3660
3661 // Mark pindex as invalid if it never was in the main chain
3662 if (!pindex_was_in_chain && !(pindex->nStatus & BLOCK_FAILED_VALID)) {
3663 pindex->nStatus |= BLOCK_FAILED_VALID;
3664 m_blockman.m_dirty_blockindex.insert(pindex);
3665 setBlockIndexCandidates.erase(pindex);
3666 }
3667
3668 // If any new blocks somehow arrived while we were disconnecting
3669 // (above), then the pre-calculation of what should go into
3670 // setBlockIndexCandidates may have missed entries. This would
3671 // technically be an inconsistency in the block index, but if we clean
3672 // it up here, this should be an essentially unobservable error.
3673 // Loop back over all block index entries and add any missing entries
3674 // to setBlockIndexCandidates.
3675 for (auto& [_, block_index] : m_blockman.m_block_index) {
3676 if (block_index.IsValid(BLOCK_VALID_TRANSACTIONS) && block_index.HaveNumChainTxs() && !setBlockIndexCandidates.value_comp()(&block_index, m_chain.Tip())) {
3677 setBlockIndexCandidates.insert(&block_index);
3678 }
3679 }
3680
3681 InvalidChainFound(to_mark_failed);
3682 }
3683
3684 // Only notify about a new block tip if the active chain was modified.
3685 if (pindex_was_in_chain) {
3686 // Ignoring return value for now, this could be changed to bubble up
3687 // kernel::Interrupted value to the caller so the caller could
3688 // distinguish between completed and interrupted operations. It might
3689 // also make sense for the blockTip notification to have an enum
3690 // parameter indicating the source of the tip change so hooks can
3691 // distinguish user-initiated invalidateblock changes from other
3692 // changes.
3695 /*index=*/*to_mark_failed->pprev,
3696 /*verification_progress=*/WITH_LOCK(m_chainman.GetMutex(), return m_chainman.GuessVerificationProgress(to_mark_failed->pprev)));
3697
3698 // Fire ActiveTipChange now for the current chain tip to make sure clients are notified.
3699 // ActivateBestChain may call this as well, but not necessarily.
3702 }
3703 }
3704 return true;
3705}
3706
3707void Chainstate::SetBlockFailureFlags(CBlockIndex* invalid_block)
3708{
3710
3711 for (auto& [_, block_index] : m_blockman.m_block_index) {
3712 if (invalid_block != &block_index && block_index.GetAncestor(invalid_block->nHeight) == invalid_block) {
3713 block_index.nStatus |= BLOCK_FAILED_VALID;
3714 m_blockman.m_dirty_blockindex.insert(&block_index);
3715 }
3716 }
3717}
3718
3721
3722 int nHeight = pindex->nHeight;
3723
3724 // Remove the invalidity flag from this block and all its descendants and ancestors.
3725 for (auto& [_, block_index] : m_blockman.m_block_index) {
3726 if ((block_index.nStatus & BLOCK_FAILED_VALID) && (block_index.GetAncestor(nHeight) == pindex || pindex->GetAncestor(block_index.nHeight) == &block_index)) {
3727 block_index.nStatus &= ~BLOCK_FAILED_VALID;
3728 m_blockman.m_dirty_blockindex.insert(&block_index);
3729 if (block_index.IsValid(BLOCK_VALID_TRANSACTIONS) && block_index.HaveNumChainTxs() && setBlockIndexCandidates.value_comp()(m_chain.Tip(), &block_index)) {
3730 setBlockIndexCandidates.insert(&block_index);
3731 }
3732 if (&block_index == m_chainman.m_best_invalid) {
3733 // Reset invalid block marker if it was pointing to one of those.
3734 m_chainman.m_best_invalid = nullptr;
3735 }
3736 }
3737 }
3738}
3739
3741{
3743
3744 // Do not continue building a chainstate that is based on an invalid
3745 // snapshot. This is a belt-and-suspenders type of check because if an
3746 // invalid snapshot is loaded, the node will shut down to force a manual
3747 // intervention. But it is good to handle this case correctly regardless.
3748 if (m_assumeutxo == Assumeutxo::INVALID) {
3749 return;
3750 }
3751
3752 // The block only is a candidate for the most-work-chain if it has the same
3753 // or more work than our current tip.
3754 if (m_chain.Tip() != nullptr && setBlockIndexCandidates.value_comp()(pindex, m_chain.Tip())) {
3755 return;
3756 }
3757
3758 const CBlockIndex* target_block{TargetBlock()};
3759 if (!target_block) {
3760 // If no specific target block, add all entries that have more
3761 // work than the tip.
3762 setBlockIndexCandidates.insert(pindex);
3763 } else {
3764 // If there is a target block, only consider connecting blocks
3765 // towards the target block.
3766 if (target_block->GetAncestor(pindex->nHeight) == pindex) {
3767 setBlockIndexCandidates.insert(pindex);
3768 }
3769 }
3770}
3771
3774{
3776 pindexNew->nTx = block.vtx.size();
3777 // Typically m_chain_tx_count will be 0 at this point, but it can be nonzero if this
3778 // is a pruned block which is being downloaded again, or if this is an
3779 // assumeutxo snapshot block which has a hardcoded m_chain_tx_count value from the
3780 // snapshot metadata. If the pindex is not the snapshot block and the
3781 // m_chain_tx_count value is not zero, assert that value is actually correct.
3782 auto prev_tx_sum = [](CBlockIndex& block) { return block.nTx + (block.pprev ? block.pprev->m_chain_tx_count : 0); };
3783 if (!Assume(pindexNew->m_chain_tx_count == 0 || pindexNew->m_chain_tx_count == prev_tx_sum(*pindexNew) ||
3784 std::ranges::any_of(m_chainstates, [&](const auto& cs) EXCLUSIVE_LOCKS_REQUIRED(cs_main) { return cs->SnapshotBase() == pindexNew; }))) {
3785 LogWarning("Internal bug detected: block %d has unexpected m_chain_tx_count %i that should be %i (%s %s). Please report this issue here: %s\n",
3786 pindexNew->nHeight, pindexNew->m_chain_tx_count, prev_tx_sum(*pindexNew), CLIENT_NAME, FormatFullVersion(), CLIENT_BUGREPORT);
3787 pindexNew->m_chain_tx_count = 0;
3788 }
3789 pindexNew->nFile = pos.nFile;
3790 pindexNew->nDataPos = pos.nPos;
3791 pindexNew->nUndoPos = 0;
3792 pindexNew->nStatus |= BLOCK_HAVE_DATA;
3793 if (DeploymentActiveAt(*pindexNew, *this, Consensus::DEPLOYMENT_SEGWIT)) {
3794 pindexNew->nStatus |= BLOCK_OPT_WITNESS;
3795 }
3797 m_blockman.m_dirty_blockindex.insert(pindexNew);
3798
3799 if (pindexNew->pprev == nullptr || pindexNew->pprev->HaveNumChainTxs()) {
3800 // If pindexNew is the genesis block or all parents are BLOCK_VALID_TRANSACTIONS.
3801 std::deque<CBlockIndex*> queue;
3802 queue.push_back(pindexNew);
3803
3804 // Recursively process any descendant blocks that now may be eligible to be connected.
3805 while (!queue.empty()) {
3806 CBlockIndex *pindex = queue.front();
3807 queue.pop_front();
3808 // Before setting m_chain_tx_count, assert that it is 0 or already set to
3809 // the correct value. This assert will fail after receiving the
3810 // assumeutxo snapshot block if assumeutxo snapshot metadata has an
3811 // incorrect hardcoded AssumeutxoData::m_chain_tx_count value.
3812 if (!Assume(pindex->m_chain_tx_count == 0 || pindex->m_chain_tx_count == prev_tx_sum(*pindex))) {
3813 LogWarning("Internal bug detected: block %d has unexpected m_chain_tx_count %i that should be %i (%s %s). Please report this issue here: %s\n",
3814 pindex->nHeight, pindex->m_chain_tx_count, prev_tx_sum(*pindex), CLIENT_NAME, FormatFullVersion(), CLIENT_BUGREPORT);
3815 }
3816 pindex->m_chain_tx_count = prev_tx_sum(*pindex);
3817 pindex->nSequenceId = nBlockSequenceId++;
3818 for (const auto& c : m_chainstates) {
3819 c->TryAddBlockIndexCandidate(pindex);
3820 }
3821 std::pair<std::multimap<CBlockIndex*, CBlockIndex*>::iterator, std::multimap<CBlockIndex*, CBlockIndex*>::iterator> range = m_blockman.m_blocks_unlinked.equal_range(pindex);
3822 while (range.first != range.second) {
3823 std::multimap<CBlockIndex*, CBlockIndex*>::iterator it = range.first;
3824 queue.push_back(it->second);
3825 range.first++;
3826 m_blockman.m_blocks_unlinked.erase(it);
3827 }
3828 }
3829 } else {
3830 if (pindexNew->pprev && pindexNew->pprev->IsValid(BLOCK_VALID_TREE)) {
3831 m_blockman.AddUnlinkedBlock(pindexNew);
3832 }
3833 }
3834}
3835
3836static bool CheckBlockHeader(const CBlockHeader& block, BlockValidationState& state, const Consensus::Params& consensusParams, bool fCheckPOW = true)
3837{
3838 // Check proof of work matches claimed amount
3839 if (fCheckPOW && !CheckProofOfWork(block.GetHash(), block.nBits, consensusParams))
3840 return state.Invalid(BlockValidationResult::BLOCK_INVALID_HEADER, "high-hash", "proof of work failed");
3841
3842 return true;
3843}
3844
3845static bool CheckMerkleRoot(const CBlock& block, BlockValidationState& state)
3846{
3847 if (block.m_checked_merkle_root) return true;
3848
3849 bool mutated;
3850 uint256 merkle_root = BlockMerkleRoot(block, &mutated);
3851 if (block.hashMerkleRoot != merkle_root) {
3852 return state.Invalid(
3854 /*reject_reason=*/"bad-txnmrklroot",
3855 /*debug_message=*/"hashMerkleRoot mismatch");
3856 }
3857
3858 // Check for merkle tree malleability (CVE-2012-2459): repeating sequences
3859 // of transactions in a block without affecting the merkle root of a block,
3860 // while still invalidating it.
3861 if (mutated) {
3862 return state.Invalid(
3864 /*reject_reason=*/"bad-txns-duplicate",
3865 /*debug_message=*/"duplicate transaction");
3866 }
3867
3868 block.m_checked_merkle_root = true;
3869 return true;
3870}
3871
3878static bool CheckWitnessMalleation(const CBlock& block, bool expect_witness_commitment, BlockValidationState& state)
3879{
3880 if (expect_witness_commitment) {
3881 if (block.m_checked_witness_commitment) return true;
3882
3883 int commitpos = GetWitnessCommitmentIndex(block);
3884 if (commitpos != NO_WITNESS_COMMITMENT) {
3885 assert(!block.vtx.empty() && !block.vtx[0]->vin.empty());
3886 const auto& witness_stack{block.vtx[0]->vin[0].scriptWitness.stack};
3887
3888 if (witness_stack.size() != 1 || witness_stack[0].size() != 32) {
3889 return state.Invalid(
3891 /*reject_reason=*/"bad-witness-nonce-size",
3892 /*debug_message=*/strprintf("%s : invalid witness reserved value size", __func__));
3893 }
3894
3895 // The malleation check is ignored; as the transaction tree itself
3896 // already does not permit it, it is impossible to trigger in the
3897 // witness tree.
3898 uint256 hash_witness = BlockWitnessMerkleRoot(block);
3899
3900 CHash256().Write(hash_witness).Write(witness_stack[0]).Finalize(hash_witness);
3901 if (memcmp(hash_witness.begin(), &block.vtx[0]->vout[commitpos].scriptPubKey[6], 32)) {
3902 return state.Invalid(
3904 /*reject_reason=*/"bad-witness-merkle-match",
3905 /*debug_message=*/strprintf("%s : witness merkle commitment mismatch", __func__));
3906 }
3907
3908 block.m_checked_witness_commitment = true;
3909 return true;
3910 }
3911 }
3912
3913 // No witness data is allowed in blocks that don't commit to witness data, as this would otherwise leave room for spam
3914 for (const auto& tx : block.vtx) {
3915 if (tx->HasWitness()) {
3916 return state.Invalid(
3918 /*reject_reason=*/"unexpected-witness",
3919 /*debug_message=*/strprintf("%s : unexpected witness data found", __func__));
3920 }
3921 }
3922
3923 return true;
3924}
3925
3926bool CheckBlock(const CBlock& block, BlockValidationState& state, const Consensus::Params& consensusParams, bool fCheckPOW, bool fCheckMerkleRoot)
3927{
3928 // These are checks that are independent of context.
3929
3930 if (block.fChecked)
3931 return true;
3932
3933 // Check that the header is valid (particularly PoW). This is mostly
3934 // redundant with the call in AcceptBlockHeader.
3935 if (!CheckBlockHeader(block, state, consensusParams, fCheckPOW))
3936 return false;
3937
3938 // Signet only: check block solution
3939 if (consensusParams.signet_blocks && fCheckPOW && !CheckSignetBlockSolution(block, consensusParams)) {
3940 return state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-signet-blksig", "signet block signature validation failure");
3941 }
3942
3943 // Check the merkle root.
3944 if (fCheckMerkleRoot && !CheckMerkleRoot(block, state)) {
3945 return false;
3946 }
3947
3948 // All potential-corruption validation must be done before we do any
3949 // transaction validation, as otherwise we may mark the header as invalid
3950 // because we receive the wrong transactions for it.
3951 // Note that witness malleability is checked in ContextualCheckBlock, so no
3952 // checks that use witness data may be performed here.
3953
3954 // Size limits
3956 return state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-blk-length", "size limits failed");
3957
3958 // First transaction must be coinbase, the rest must not be
3959 if (block.vtx.empty() || !block.vtx[0]->IsCoinBase())
3960 return state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-cb-missing", "first tx is not coinbase");
3961 for (unsigned int i = 1; i < block.vtx.size(); i++)
3962 if (block.vtx[i]->IsCoinBase())
3963 return state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-cb-multiple", "more than one coinbase");
3964
3965 // Check transactions
3966 // Must check for duplicate inputs (see CVE-2018-17144)
3967 for (const auto& tx : block.vtx) {
3968 TxValidationState tx_state;
3969 if (!CheckTransaction(*tx, tx_state)) {
3970 // CheckBlock() does context-free validation checks. The only
3971 // possible failures are consensus failures.
3974 strprintf("Transaction check failed (tx hash %s) %s", tx->GetHash().ToString(), tx_state.GetDebugMessage()));
3975 }
3976 }
3977 // This underestimates the number of sigops, because unlike ConnectBlock it
3978 // does not count witness and p2sh sigops.
3979 unsigned int nSigOps = 0;
3980 for (const auto& tx : block.vtx)
3981 {
3982 nSigOps += GetLegacySigOpCount(*tx);
3983 }
3985 return state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-blk-sigops", "out-of-bounds SigOpCount");
3986
3987 if (fCheckPOW && fCheckMerkleRoot)
3988 block.fChecked = true;
3989
3990 return true;
3991}
3992
3994{
3995 int commitpos = GetWitnessCommitmentIndex(block);
3996 static const std::vector<unsigned char> nonce(32, 0x00);
3997 if (commitpos != NO_WITNESS_COMMITMENT && DeploymentActiveAfter(pindexPrev, *this, Consensus::DEPLOYMENT_SEGWIT) && !block.vtx[0]->HasWitness()) {
3998 CMutableTransaction tx(*block.vtx[0]);
3999 tx.vin[0].scriptWitness.stack.resize(1);
4000 tx.vin[0].scriptWitness.stack[0] = nonce;
4001 block.vtx[0] = MakeTransactionRef(std::move(tx));
4002 }
4003}
4004
4006{
4007 int commitpos = GetWitnessCommitmentIndex(block);
4008 std::vector<unsigned char> ret(32, 0x00);
4009 if (commitpos == NO_WITNESS_COMMITMENT) {
4010 uint256 witnessroot = BlockWitnessMerkleRoot(block);
4011 CHash256().Write(witnessroot).Write(ret).Finalize(witnessroot);
4012 CTxOut out;
4013 out.nValue = 0;
4014 out.scriptPubKey.resize(MINIMUM_WITNESS_COMMITMENT);
4015 out.scriptPubKey[0] = OP_RETURN;
4016 out.scriptPubKey[1] = 0x24;
4017 out.scriptPubKey[2] = 0xaa;
4018 out.scriptPubKey[3] = 0x21;
4019 out.scriptPubKey[4] = 0xa9;
4020 out.scriptPubKey[5] = 0xed;
4021 memcpy(&out.scriptPubKey[6], witnessroot.begin(), 32);
4022 CMutableTransaction tx(*block.vtx[0]);
4023 tx.vout.push_back(out);
4024 block.vtx[0] = MakeTransactionRef(std::move(tx));
4025 }
4026 UpdateUncommittedBlockStructures(block, pindexPrev);
4027}
4028
4029bool HasValidProofOfWork(std::span<const CBlockHeader> headers, const Consensus::Params& consensusParams)
4030{
4031 return std::ranges::all_of(headers,
4032 [&](const auto& header) { return CheckProofOfWork(header.GetHash(), header.nBits, consensusParams); });
4033}
4034
4035bool IsBlockMutated(const CBlock& block, bool check_witness_root)
4036{
4038 if (!CheckMerkleRoot(block, state)) {
4039 LogDebug(BCLog::VALIDATION, "Block mutated: %s\n", state.ToString());
4040 return true;
4041 }
4042
4043 if (block.vtx.empty() || !block.vtx[0]->IsCoinBase()) {
4044 // Consider the block mutated if any transaction is 64 bytes in size (see 3.1
4045 // in "Weaknesses in Bitcoin’s Merkle Root Construction":
4046 // https://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20190225/a27d8837/attachment-0001.pdf).
4047 //
4048 // Note: This is not a consensus change as this only applies to blocks that
4049 // don't have a coinbase transaction and would therefore already be invalid.
4050 return std::any_of(block.vtx.begin(), block.vtx.end(),
4051 [](auto& tx) { return GetSerializeSize(TX_NO_WITNESS(tx)) == 64; });
4052 } else {
4053 // Theoretically it is still possible for a block with a 64 byte
4054 // coinbase transaction to be mutated but we neglect that possibility
4055 // here as it requires at least 224 bits of work.
4056 }
4057
4058 if (!CheckWitnessMalleation(block, check_witness_root, state)) {
4059 LogDebug(BCLog::VALIDATION, "Block mutated: %s\n", state.ToString());
4060 return true;
4061 }
4062
4063 return false;
4064}
4065
4067{
4068 arith_uint256 total_work{0};
4069 for (const CBlockHeader& header : headers) {
4070 total_work += GetBlockProof(header);
4071 }
4072 return total_work;
4073}
4074
4089{
4091 assert(pindexPrev != nullptr);
4092 const int nHeight = pindexPrev->nHeight + 1;
4093
4094 // Check proof of work
4095 const Consensus::Params& consensusParams = chainman.GetConsensus();
4096 if (block.nBits != GetNextWorkRequired(pindexPrev, &block, consensusParams))
4097 return state.Invalid(BlockValidationResult::BLOCK_INVALID_HEADER, "bad-diffbits", "incorrect proof of work");
4098
4099 // Check timestamp against prev
4100 if (block.GetBlockTime() <= pindexPrev->GetMedianTimePast())
4101 return state.Invalid(BlockValidationResult::BLOCK_INVALID_HEADER, "time-too-old", "block's timestamp is too early");
4102
4103 // Testnet4 and regtest only: Check timestamp against prev for difficulty-adjustment
4104 // blocks to prevent timewarp attacks (see https://github.com/bitcoin/bitcoin/pull/15482).
4105 if (consensusParams.enforce_BIP94) {
4106 // Check timestamp for the first block of each difficulty adjustment
4107 // interval, except the genesis block.
4108 if (nHeight % consensusParams.DifficultyAdjustmentInterval() == 0) {
4109 if (block.GetBlockTime() < pindexPrev->GetBlockTime() - MAX_TIMEWARP) {
4110 return state.Invalid(BlockValidationResult::BLOCK_INVALID_HEADER, "time-timewarp-attack", "block's timestamp is too early on diff adjustment block");
4111 }
4112 }
4113 }
4114
4115 // Check timestamp
4116 if (block.Time() > NodeClock::now() + std::chrono::seconds{MAX_FUTURE_BLOCK_TIME}) {
4117 return state.Invalid(BlockValidationResult::BLOCK_TIME_FUTURE, "time-too-new", "block timestamp too far in the future");
4118 }
4119
4120 // Reject blocks with outdated version
4121 if ((block.nVersion < 2 && DeploymentActiveAfter(pindexPrev, chainman, Consensus::DEPLOYMENT_HEIGHTINCB)) ||
4122 (block.nVersion < 3 && DeploymentActiveAfter(pindexPrev, chainman, Consensus::DEPLOYMENT_DERSIG)) ||
4123 (block.nVersion < 4 && DeploymentActiveAfter(pindexPrev, chainman, Consensus::DEPLOYMENT_CLTV))) {
4124 return state.Invalid(BlockValidationResult::BLOCK_INVALID_HEADER, strprintf("bad-version(0x%08x)", block.nVersion),
4125 strprintf("rejected nVersion=0x%08x block", block.nVersion));
4126 }
4127
4128 return true;
4129}
4130
4137static bool ContextualCheckBlock(const CBlock& block, BlockValidationState& state, const ChainstateManager& chainman, const CBlockIndex* pindexPrev)
4138{
4139 const int nHeight = pindexPrev == nullptr ? 0 : pindexPrev->nHeight + 1;
4140
4141 // Enforce BIP113 (Median Time Past).
4142 bool enforce_locktime_median_time_past{false};
4143 if (DeploymentActiveAfter(pindexPrev, chainman, Consensus::DEPLOYMENT_CSV)) {
4144 assert(pindexPrev != nullptr);
4145 enforce_locktime_median_time_past = true;
4146 }
4147
4148 const int64_t nLockTimeCutoff{enforce_locktime_median_time_past ?
4149 pindexPrev->GetMedianTimePast() :
4150 block.GetBlockTime()};
4151
4152 // Check that all transactions are finalized
4153 for (const auto& tx : block.vtx) {
4154 if (!IsFinalTx(*tx, nHeight, nLockTimeCutoff)) {
4155 return state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-txns-nonfinal", "non-final transaction");
4156 }
4157 }
4158
4159 // Enforce rule that the coinbase starts with serialized block height
4161 {
4163 if (block.vtx[0]->vin[0].scriptSig.size() < expect.size() ||
4164 !std::equal(expect.begin(), expect.end(), block.vtx[0]->vin[0].scriptSig.begin())) {
4165 return state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-cb-height", "block height mismatch in coinbase");
4166 }
4167 }
4168
4169 // Validation for witness commitments.
4170 // * We compute the witness hash (which is the hash including witnesses) of all the block's transactions, except the
4171 // coinbase (where 0x0000....0000 is used instead).
4172 // * The coinbase scriptWitness is a stack of a single 32-byte vector, containing a witness reserved value (unconstrained).
4173 // * We build a merkle tree with all those witness hashes as leaves (similar to the hashMerkleRoot in the block header).
4174 // * There must be at least one output whose scriptPubKey is a single 36-byte push, the first 4 bytes of which are
4175 // {0xaa, 0x21, 0xa9, 0xed}, and the following 32 bytes are SHA256^2(witness root, witness reserved value). In case there are
4176 // multiple, the last one is used.
4177 if (!CheckWitnessMalleation(block, DeploymentActiveAfter(pindexPrev, chainman, Consensus::DEPLOYMENT_SEGWIT), state)) {
4178 return false;
4179 }
4180
4181 // After the coinbase witness reserved value and commitment are verified,
4182 // we can check if the block weight passes (before we've checked the
4183 // coinbase witness, it would be possible for the weight to be too
4184 // large by filling up the coinbase witness, which doesn't change
4185 // the block hash, so we couldn't mark the block as permanently
4186 // failed).
4187 if (GetBlockWeight(block) > MAX_BLOCK_WEIGHT) {
4188 return state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-blk-weight", strprintf("%s : weight limit failed", __func__));
4189 }
4190
4191 return true;
4192}
4193
4194bool ChainstateManager::AcceptBlockHeader(const CBlockHeader& block, BlockValidationState& state, CBlockIndex** ppindex, bool min_pow_checked)
4195{
4197
4198 // Check for duplicate
4199 uint256 hash = block.GetHash();
4200 BlockMap::iterator miSelf{m_blockman.m_block_index.find(hash)};
4201 if (hash != GetConsensus().hashGenesisBlock) {
4202 if (miSelf != m_blockman.m_block_index.end()) {
4203 // Block header is already known.
4204 CBlockIndex* pindex = &(miSelf->second);
4205 if (ppindex)
4206 *ppindex = pindex;
4207 if (pindex->nStatus & BLOCK_FAILED_VALID) {
4208 LogDebug(BCLog::VALIDATION, "%s: block %s is marked invalid\n", __func__, hash.ToString());
4209 return state.Invalid(BlockValidationResult::BLOCK_CACHED_INVALID, "duplicate-invalid",
4210 strprintf("block %s was previously marked invalid", hash.ToString()));
4211 }
4212 return true;
4213 }
4214
4215 if (!CheckBlockHeader(block, state, GetConsensus())) {
4216 LogDebug(BCLog::VALIDATION, "%s: Consensus::CheckBlockHeader: %s, %s\n", __func__, hash.ToString(), state.ToString());
4217 return false;
4218 }
4219
4220 // Get prev block index
4221 CBlockIndex* pindexPrev = nullptr;
4222 BlockMap::iterator mi{m_blockman.m_block_index.find(block.hashPrevBlock)};
4223 if (mi == m_blockman.m_block_index.end()) {
4224 LogDebug(BCLog::VALIDATION, "header %s has prev block not found: %s\n", hash.ToString(), block.hashPrevBlock.ToString());
4225 return state.Invalid(BlockValidationResult::BLOCK_MISSING_PREV, "prev-blk-not-found");
4226 }
4227 pindexPrev = &((*mi).second);
4228 if (pindexPrev->nStatus & BLOCK_FAILED_VALID) {
4229 LogDebug(BCLog::VALIDATION, "header %s has prev block invalid: %s\n", hash.ToString(), block.hashPrevBlock.ToString());
4230 return state.Invalid(BlockValidationResult::BLOCK_INVALID_PREV, "bad-prevblk");
4231 }
4232 if (!ContextualCheckBlockHeader(block, state, *this, pindexPrev)) {
4233 LogDebug(BCLog::VALIDATION, "%s: Consensus::ContextualCheckBlockHeader: %s, %s\n", __func__, hash.ToString(), state.ToString());
4234 return false;
4235 }
4236 }
4237 if (!min_pow_checked) {
4238 LogDebug(BCLog::VALIDATION, "%s: not adding new block header %s, missing anti-dos proof-of-work validation\n", __func__, hash.ToString());
4239 return state.Invalid(BlockValidationResult::BLOCK_HEADER_LOW_WORK, "too-little-chainwork");
4240 }
4241 CBlockIndex* pindex{m_blockman.AddToBlockIndex(block, m_best_header)};
4242
4243 if (ppindex)
4244 *ppindex = pindex;
4245
4246 return true;
4247}
4248
4249// Exposed wrapper for AcceptBlockHeader
4250bool ChainstateManager::ProcessNewBlockHeaders(std::span<const CBlockHeader> headers, bool min_pow_checked, BlockValidationState& state, const CBlockIndex** ppindex)
4251{
4253 {
4254 LOCK(cs_main);
4255 for (const CBlockHeader& header : headers) {
4256 CBlockIndex *pindex = nullptr; // Use a temp pindex instead of ppindex to avoid a const_cast
4257 bool accepted{AcceptBlockHeader(header, state, &pindex, min_pow_checked)};
4259
4260 if (!accepted) {
4261 return false;
4262 }
4263 if (ppindex) {
4264 *ppindex = pindex;
4265 }
4266 }
4267 }
4268 if (NotifyHeaderTip()) {
4269 if (IsInitialBlockDownload() && ppindex && *ppindex) {
4270 const CBlockIndex& last_accepted{**ppindex};
4271 int64_t blocks_left{(NodeClock::now() - last_accepted.Time()) / GetConsensus().PowTargetSpacing()};
4272 blocks_left = std::max<int64_t>(0, blocks_left);
4273 const double progress{100.0 * last_accepted.nHeight / (last_accepted.nHeight + blocks_left)};
4274 LogInfo("Synchronizing blockheaders, height: %d (~%.2f%%)\n", last_accepted.nHeight, progress);
4275 }
4276 }
4277 return true;
4278}
4279
4280void ChainstateManager::ReportHeadersPresync(int64_t height, int64_t timestamp)
4281{
4283 {
4284 LOCK(GetMutex());
4285 // Don't report headers presync progress if we already have a post-minchainwork header chain.
4286 // This means we lose reporting for potentially legitimate, but unlikely, deep reorgs, but
4287 // prevent attackers that spam low-work headers from filling our logs.
4288 if (m_best_header->nChainWork >= UintToArith256(GetConsensus().nMinimumChainWork)) return;
4289 // Rate limit headers presync updates to 4 per second, as these are not subject to DoS
4290 // protection.
4291 auto now = MockableSteadyClock::now();
4292 if (now < m_last_presync_update + std::chrono::milliseconds{250}) return;
4293 m_last_presync_update = now;
4294 }
4295 bool initial_download = IsInitialBlockDownload();
4296 GetNotifications().headerTip(GetSynchronizationState(initial_download, m_blockman.m_blockfiles_indexed), height, timestamp, /*presync=*/true);
4297 if (initial_download) {
4298 int64_t blocks_left{(NodeClock::now() - NodeSeconds{std::chrono::seconds{timestamp}}) / GetConsensus().PowTargetSpacing()};
4299 blocks_left = std::max<int64_t>(0, blocks_left);
4300 const double progress{100.0 * height / (height + blocks_left)};
4301 LogInfo("Pre-synchronizing blockheaders, height: %d (~%.2f%%)\n", height, progress);
4302 }
4303}
4304
4306bool ChainstateManager::AcceptBlock(const std::shared_ptr<const CBlock>& pblock, BlockValidationState& state, CBlockIndex** ppindex, bool fRequested, const FlatFilePos* dbp, bool* fNewBlock, bool min_pow_checked)
4307{
4308 const CBlock& block = *pblock;
4309
4310 if (fNewBlock) *fNewBlock = false;
4312
4313 CBlockIndex *pindexDummy = nullptr;
4314 CBlockIndex *&pindex = ppindex ? *ppindex : pindexDummy;
4315
4316 bool accepted_header{AcceptBlockHeader(block, state, &pindex, min_pow_checked)};
4318
4319 if (!accepted_header)
4320 return false;
4321
4322 // Check all requested blocks that we do not already have for validity and
4323 // save them to disk. Skip processing of unrequested blocks as an anti-DoS
4324 // measure, unless the blocks have more work than the active chain tip, and
4325 // aren't too far ahead of it, so are likely to be attached soon.
4326 bool fAlreadyHave = pindex->nStatus & BLOCK_HAVE_DATA;
4327 bool fHasMoreOrSameWork = (ActiveTip() ? pindex->nChainWork >= ActiveTip()->nChainWork : true);
4328 // Blocks that are too out-of-order needlessly limit the effectiveness of
4329 // pruning, because pruning will not delete block files that contain any
4330 // blocks which are too close in height to the tip. Apply this test
4331 // regardless of whether pruning is enabled; it should generally be safe to
4332 // not process unrequested blocks.
4333 bool fTooFarAhead{pindex->nHeight > ActiveHeight() + int(MIN_BLOCKS_TO_KEEP)};
4334
4335 // TODO: Decouple this function from the block download logic by removing fRequested
4336 // This requires some new chain data structure to efficiently look up if a
4337 // block is in a chain leading to a candidate for best tip, despite not
4338 // being such a candidate itself.
4339 // Note that this would break the getblockfrompeer RPC
4340
4341 // TODO: deal better with return value and error conditions for duplicate
4342 // and unrequested blocks.
4343 if (fAlreadyHave) return true;
4344 if (!fRequested) { // If we didn't ask for it:
4345 if (pindex->nTx != 0) return true; // This is a previously-processed block that was pruned
4346 if (!fHasMoreOrSameWork) return true; // Don't process less-work chains
4347 if (fTooFarAhead) return true; // Block height is too high
4348
4349 // Protect against DoS attacks from low-work chains.
4350 // If our tip is behind, a peer could try to send us
4351 // low-work blocks on a fake chain that we would never
4352 // request; don't process these.
4353 if (pindex->nChainWork < MinimumChainWork()) return true;
4354 }
4355
4356 const CChainParams& params{GetParams()};
4357
4358 if (!CheckBlock(block, state, params.GetConsensus()) ||
4359 !ContextualCheckBlock(block, state, *this, pindex->pprev)) {
4360 if (Assume(state.IsInvalid())) {
4361 ActiveChainstate().InvalidBlockFound(pindex, state);
4362 }
4363 LogError("%s: %s\n", __func__, state.ToString());
4364 return false;
4365 }
4366
4367 // Header is valid/has work, merkle tree and segwit merkle tree are good...RELAY NOW
4368 // (but if it does not build on our best tip, let the SendMessages loop relay it)
4369 if (!IsInitialBlockDownload() && ActiveTip() == pindex->pprev && m_options.signals) {
4370 m_options.signals->NewPoWValidBlock(pindex, pblock);
4371 }
4372
4373 // Write block to history file
4374 if (fNewBlock) *fNewBlock = true;
4375 try {
4376 FlatFilePos blockPos{};
4377 if (dbp) {
4378 blockPos = *dbp;
4379 m_blockman.UpdateBlockInfo(block, pindex->nHeight, blockPos);
4380 } else {
4381 blockPos = m_blockman.WriteBlock(block, pindex->nHeight);
4382 if (blockPos.IsNull()) {
4383 state.Error(strprintf("%s: Failed to find position to write new block to disk", __func__));
4384 return false;
4385 }
4386 }
4387 ReceivedBlockTransactions(block, pindex, blockPos);
4388 } catch (const std::runtime_error& e) {
4389 return FatalError(GetNotifications(), state, strprintf(_("System error while saving block to disk: %s"), e.what()));
4390 }
4391
4392 // TODO: FlushStateToDisk() handles flushing of both block and chainstate
4393 // data, so we should move this to ChainstateManager so that we can be more
4394 // intelligent about how we flush.
4395 // For now, since FlushStateMode::NONE is used, all that can happen is that
4396 // the block files may be pruned, so we can just call this on one
4397 // chainstate (particularly if we haven't implemented pruning with
4398 // background validation yet).
4399 //
4400 // Flush errors (e.g. low disk space during pruning) are ignored, so that
4401 // callers can't mistreat a flush failure as a block validation failure.
4402 // The fatal error notification inside FlushStateToDisk still fires,
4403 // so the node will shut down on unrecoverable flush errors regardless.
4404 // For state a dummy value is used, and the return value is ignored.
4405 BlockValidationState flush_state_ignore;
4406 (void)ActiveChainstate().FlushStateToDisk(flush_state_ignore, FlushStateMode::NONE);
4407
4409
4410 return true;
4411}
4412
4413bool ChainstateManager::ProcessNewBlock(const std::shared_ptr<const CBlock>& block, bool force_processing, bool min_pow_checked, bool* new_block)
4414{
4416
4417 {
4418 CBlockIndex *pindex = nullptr;
4419 if (new_block) *new_block = false;
4421
4422 // CheckBlock() does not support multi-threaded block validation because CBlock::fChecked can cause data race.
4423 // Therefore, the following critical section must include the CheckBlock() call as well.
4424 LOCK(cs_main);
4425
4426 // Skipping AcceptBlock() for CheckBlock() failures means that we will never mark a block as invalid if
4427 // CheckBlock() fails. This is protective against consensus failure if there are any unknown forms of block
4428 // malleability that cause CheckBlock() to fail; see e.g. CVE-2012-2459 and
4429 // https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2019-February/016697.html. Because CheckBlock() is
4430 // not very expensive, the anti-DoS benefits of caching failure (of a definitely-invalid block) are not substantial.
4431 bool ret = CheckBlock(*block, state, GetConsensus());
4432 if (ret) {
4433 // Store to disk
4434 ret = AcceptBlock(block, state, &pindex, force_processing, nullptr, new_block, min_pow_checked);
4435 }
4436 if (!ret) {
4437 if (m_options.signals) {
4438 m_options.signals->BlockChecked(block, state);
4439 }
4440 LogError("%s: AcceptBlock FAILED (%s)\n", __func__, state.ToString());
4441 return false;
4442 }
4443 }
4444
4446
4447 BlockValidationState state; // Only used to report errors, not invalidity - ignore it
4448 if (!ActiveChainstate().ActivateBestChain(state, block)) {
4449 LogError("%s: ActivateBestChain failed (%s)\n", __func__, state.ToString());
4450 return false;
4451 }
4452
4453 Chainstate* bg_chain{WITH_LOCK(cs_main, return HistoricalChainstate())};
4454 BlockValidationState bg_state;
4455 if (bg_chain && !bg_chain->ActivateBestChain(bg_state, block)) {
4456 LogError("%s: [background] ActivateBestChain failed (%s)\n", __func__, bg_state.ToString());
4457 return false;
4458 }
4459
4460 return true;
4461}
4462
4464{
4466 Chainstate& active_chainstate = ActiveChainstate();
4467 if (!active_chainstate.GetMempool()) {
4468 TxValidationState state;
4469 state.Invalid(TxValidationResult::TX_NO_MEMPOOL, "no-mempool");
4470 return MempoolAcceptResult::Failure(state);
4471 }
4472 auto result = AcceptToMemoryPool(active_chainstate, tx, GetTime(), /*bypass_limits=*/ false, test_accept);
4473 active_chainstate.GetMempool()->check(active_chainstate.CoinsTip(), active_chainstate.m_chain.Height() + 1);
4474 return result;
4475}
4476
4477
4479 Chainstate& chainstate,
4480 const CBlock& block,
4481 const bool check_pow,
4482 const bool check_merkle_root)
4483{
4484 // Lock must be held throughout this function for two reasons:
4485 // 1. We don't want the tip to change during several of the validation steps
4486 // 2. To prevent a CheckBlock() race condition for fChecked, see ProcessNewBlock()
4487 AssertLockHeld(chainstate.m_chainman.GetMutex());
4488
4490 CBlockIndex* tip{Assert(chainstate.m_chain.Tip())};
4491
4492 if (block.hashPrevBlock != *Assert(tip->phashBlock)) {
4493 state.Invalid({}, "inconclusive-not-best-prevblk");
4494 return state;
4495 }
4496
4497 // For signets CheckBlock() verifies the challenge iff fCheckPow is set.
4498 if (!CheckBlock(block, state, chainstate.m_chainman.GetConsensus(), /*fCheckPow=*/check_pow, /*fCheckMerkleRoot=*/check_merkle_root)) {
4499 // This should never happen, but belt-and-suspenders don't approve the
4500 // block if it does.
4501 if (state.IsValid()) NONFATAL_UNREACHABLE();
4502 return state;
4503 }
4504
4520 if (!ContextualCheckBlockHeader(block, state, chainstate.m_chainman, tip)) {
4521 if (state.IsValid()) NONFATAL_UNREACHABLE();
4522 return state;
4523 }
4524
4525 if (!ContextualCheckBlock(block, state, chainstate.m_chainman, tip)) {
4526 if (state.IsValid()) NONFATAL_UNREACHABLE();
4527 return state;
4528 }
4529
4530 // We don't want ConnectBlock to update the actual chainstate, so create
4531 // a cache on top of it, along with a dummy block index.
4532 CBlockIndex index_dummy{block};
4533 uint256 block_hash(block.GetHash());
4534 index_dummy.pprev = tip;
4535 index_dummy.nHeight = tip->nHeight + 1;
4536 index_dummy.phashBlock = &block_hash;
4537 CCoinsViewCache view_dummy(&chainstate.CoinsTip());
4538
4539 // Set fJustCheck to true in order to update, and not clear, validation caches.
4540 if(!chainstate.ConnectBlock(block, state, &index_dummy, view_dummy, /*fJustCheck=*/true)) {
4541 if (state.IsValid()) NONFATAL_UNREACHABLE();
4542 return state;
4543 }
4544
4545 // Ensure no check returned successfully while also setting an invalid state.
4546 if (!state.IsValid()) NONFATAL_UNREACHABLE();
4547
4548 return state;
4549}
4550
4551/* This function is called from the RPC code for pruneblockchain */
4552void PruneBlockFilesManual(Chainstate& active_chainstate, int nManualPruneHeight)
4553{
4555 if (!active_chainstate.FlushStateToDisk(
4556 state, FlushStateMode::NONE, nManualPruneHeight)) {
4557 LogWarning("Failed to flush state after manual prune (%s)", state.ToString());
4558 }
4559}
4560
4562{
4564 const CCoinsViewCache& coins_cache = CoinsTip();
4565 assert(!coins_cache.GetBestBlock().IsNull()); // Never called when the coins view is empty
4566 CBlockIndex* tip = m_chain.Tip();
4567
4568 if (tip && tip->GetBlockHash() == coins_cache.GetBestBlock()) {
4569 return true;
4570 }
4571
4572 // Load pointer to end of best chain
4573 CBlockIndex* pindex = m_blockman.LookupBlockIndex(coins_cache.GetBestBlock());
4574 if (!pindex) {
4575 return false;
4576 }
4577 m_chain.SetTip(*pindex);
4579 m_last_flushed_block = pindex;
4580 tip = m_chain.Tip();
4581
4582 // nSequenceId is one of the keys used to sort setBlockIndexCandidates. Ensure all
4583 // candidate sets are empty to avoid UB, as nSequenceId is about to be modified.
4584 for (const auto& cs : m_chainman.m_chainstates) {
4585 assert(cs->setBlockIndexCandidates.empty());
4586 }
4587
4588 // Make sure our chain tip before shutting down scores better than any other candidate
4589 // to maintain a consistent best tip over reboots in case of a tie.
4590 auto target = tip;
4591 while (target) {
4593 target = target->pprev;
4594 }
4595
4596 LogInfo("Loaded best chain: hashBestChain=%s height=%d date=%s progress=%f",
4597 tip->GetBlockHash().ToString(),
4598 m_chain.Height(),
4601
4602 // Ensure KernelNotifications m_tip_block is set even if no new block arrives.
4603 if (!this->GetRole().historical) {
4604 // Ignoring return value for now.
4607 /*index=*/*pindex,
4608 /*verification_progress=*/m_chainman.GuessVerificationProgress(tip));
4609 }
4610
4612
4613 return true;
4614}
4615
4617 : m_notifications{notifications}
4618{
4619 m_notifications.progress(_("Verifying blocks…"), 0, false);
4620}
4621
4623{
4624 m_notifications.progress(bilingual_str{}, 100, false);
4625}
4626
4628 Chainstate& chainstate,
4629 const Consensus::Params& consensus_params,
4630 CCoinsView& coinsview,
4631 int nCheckLevel, int nCheckDepth)
4632{
4634
4635 if (chainstate.m_chain.Tip() == nullptr || chainstate.m_chain.Tip()->pprev == nullptr) {
4637 }
4638
4639 // Verify blocks in the best chain
4640 if (nCheckDepth <= 0 || nCheckDepth > chainstate.m_chain.Height()) {
4641 nCheckDepth = chainstate.m_chain.Height();
4642 }
4643 nCheckLevel = std::max(0, std::min(4, nCheckLevel));
4644 LogInfo("Verifying last %i blocks at level %i", nCheckDepth, nCheckLevel);
4645 CCoinsViewCache coins(&coinsview);
4646 CBlockIndex* pindex;
4647 CBlockIndex* pindexFailure = nullptr;
4648 int nGoodTransactions = 0;
4650 int reportDone = 0;
4651 bool skipped_no_block_data{false};
4652 bool skipped_l3_checks{false};
4653 LogInfo("Verification progress: 0%%");
4654
4655 const bool is_snapshot_cs{chainstate.m_from_snapshot_blockhash};
4656
4657 for (pindex = chainstate.m_chain.Tip(); pindex && pindex->pprev; pindex = pindex->pprev) {
4658 const int percentageDone = std::max(1, std::min(99, (int)(((double)(chainstate.m_chain.Height() - pindex->nHeight)) / (double)nCheckDepth * (nCheckLevel >= 4 ? 50 : 100))));
4659 if (reportDone < percentageDone / 10) {
4660 // report every 10% step
4661 LogInfo("Verification progress: %d%%", percentageDone);
4662 reportDone = percentageDone / 10;
4663 }
4664 m_notifications.progress(_("Verifying blocks…"), percentageDone, false);
4665 if (pindex->nHeight <= chainstate.m_chain.Height() - nCheckDepth) {
4666 break;
4667 }
4668 if ((chainstate.m_blockman.IsPruneMode() || is_snapshot_cs) && !(pindex->nStatus & BLOCK_HAVE_DATA)) {
4669 // If pruning or running under an assumeutxo snapshot, only go
4670 // back as far as we have data.
4671 LogInfo("Block verification stopping at height %d (no data). This could be due to pruning or use of an assumeutxo snapshot.", pindex->nHeight);
4672 skipped_no_block_data = true;
4673 break;
4674 }
4675 CBlock block;
4676 // check level 0: read from disk
4677 if (!chainstate.m_blockman.ReadBlock(block, *pindex)) {
4678 LogError("Verification error: ReadBlock failed at %d, hash=%s", pindex->nHeight, pindex->GetBlockHash().ToString());
4680 }
4681 // check level 1: verify block validity
4682 if (nCheckLevel >= 1 && !CheckBlock(block, state, consensus_params)) {
4683 LogError("Verification error: found bad block at %d, hash=%s (%s)",
4684 pindex->nHeight, pindex->GetBlockHash().ToString(), state.ToString());
4686 }
4687 // check level 2: verify undo validity
4688 if (nCheckLevel >= 2 && pindex) {
4689 CBlockUndo undo;
4690 if (!pindex->GetUndoPos().IsNull()) {
4691 if (!chainstate.m_blockman.ReadBlockUndo(undo, *pindex)) {
4692 LogError("Verification error: found bad undo data at %d, hash=%s", pindex->nHeight, pindex->GetBlockHash().ToString());
4694 }
4695 }
4696 }
4697 // check level 3: check for inconsistencies during memory-only disconnect of tip blocks
4698 size_t curr_coins_usage = coins.DynamicMemoryUsage() + chainstate.CoinsTip().DynamicMemoryUsage();
4699
4700 if (nCheckLevel >= 3) {
4701 if (curr_coins_usage <= chainstate.m_coinstip_cache_size_bytes) {
4702 assert(coins.GetBestBlock() == pindex->GetBlockHash());
4703 DisconnectResult res = chainstate.DisconnectBlock(block, pindex, coins);
4704 if (res == DISCONNECT_FAILED) {
4705 LogError("Verification error: irrecoverable inconsistency in block data at %d, hash=%s", pindex->nHeight, pindex->GetBlockHash().ToString());
4707 }
4708 if (res == DISCONNECT_UNCLEAN) {
4709 nGoodTransactions = 0;
4710 pindexFailure = pindex;
4711 } else {
4712 nGoodTransactions += block.vtx.size();
4713 }
4714 } else {
4715 skipped_l3_checks = true;
4716 }
4717 }
4718 if (chainstate.m_chainman.m_interrupt) return VerifyDBResult::INTERRUPTED;
4719 }
4720 if (pindexFailure) {
4721 LogError("Verification error: coin database inconsistencies found (last %i blocks, %i good transactions before that)", chainstate.m_chain.Height() - pindexFailure->nHeight + 1, nGoodTransactions);
4723 }
4724 if (skipped_l3_checks) {
4725 LogWarning("Skipped verification of level >=3 (insufficient database cache size). Consider increasing -dbcache.");
4726 }
4727
4728 // store block count as we move pindex at check level >= 4
4729 int block_count = chainstate.m_chain.Height() - pindex->nHeight;
4730
4731 // check level 4: try reconnecting blocks
4732 if (nCheckLevel >= 4 && !skipped_l3_checks) {
4733 while (pindex != chainstate.m_chain.Tip()) {
4734 const int percentageDone = std::max(1, std::min(99, 100 - (int)(((double)(chainstate.m_chain.Height() - pindex->nHeight)) / (double)nCheckDepth * 50)));
4735 if (reportDone < percentageDone / 10) {
4736 // report every 10% step
4737 LogInfo("Verification progress: %d%%", percentageDone);
4738 reportDone = percentageDone / 10;
4739 }
4740 m_notifications.progress(_("Verifying blocks…"), percentageDone, false);
4741 pindex = chainstate.m_chain.Next(*pindex);
4742 CBlock block;
4743 if (!chainstate.m_blockman.ReadBlock(block, *pindex)) {
4744 LogError("Verification error: ReadBlock failed at %d, hash=%s", pindex->nHeight, pindex->GetBlockHash().ToString());
4746 }
4747 if (!chainstate.ConnectBlock(block, state, pindex, coins)) {
4748 LogError("Verification error: found unconnectable block at %d, hash=%s (%s)", pindex->nHeight, pindex->GetBlockHash().ToString(), state.ToString());
4750 }
4751 if (chainstate.m_chainman.m_interrupt) return VerifyDBResult::INTERRUPTED;
4752 }
4753 }
4754
4755 LogInfo("Verification: checked last %i blocks at level %i", block_count, nCheckLevel);
4756 if (nCheckLevel >= 3 && !skipped_l3_checks) {
4757 LogInfo("Verification: no coin database inconsistencies (%i transactions)", nGoodTransactions);
4758 }
4759
4760 if (skipped_l3_checks) {
4762 }
4763 if (skipped_no_block_data) {
4765 }
4767}
4768
4771{
4773 // TODO: merge with ConnectBlock
4774 CBlock block;
4775 if (!m_blockman.ReadBlock(block, *pindex)) {
4776 LogError("ReplayBlock(): ReadBlock failed at %d, hash=%s\n", pindex->nHeight, pindex->GetBlockHash().ToString());
4777 return false;
4778 }
4779
4780 for (const CTransactionRef& tx : block.vtx) {
4781 if (!tx->IsCoinBase()) {
4782 for (const CTxIn &txin : tx->vin) {
4783 inputs.SpendCoin(txin.prevout);
4784 }
4785 }
4786 // Pass check = true as every addition may be an overwrite.
4787 AddCoins(inputs, *tx, pindex->nHeight, true);
4788 }
4789 return true;
4790}
4791
4793{
4794 LOCK(cs_main);
4795
4796 CCoinsView& db = this->CoinsDB();
4797 CCoinsViewCache cache(&db);
4798
4799 std::vector<uint256> hashHeads = db.GetHeadBlocks();
4800 if (hashHeads.empty()) return true; // We're already in a consistent state.
4801 if (hashHeads.size() != 2) {
4802 LogError("ReplayBlocks(): unknown inconsistent state\n");
4803 return false;
4804 }
4805
4806 m_chainman.GetNotifications().progress(_("Replaying blocks…"), 0, false);
4807 LogInfo("Replaying blocks");
4808
4809 const CBlockIndex* pindexOld = nullptr; // Old tip during the interrupted flush.
4810 const CBlockIndex* pindexNew; // New tip during the interrupted flush.
4811 const CBlockIndex* pindexFork = nullptr; // Latest block common to both the old and the new tip.
4812
4813 if (!m_blockman.m_block_index.contains(hashHeads[0])) {
4814 LogError("ReplayBlocks(): reorganization to unknown block requested\n");
4815 return false;
4816 }
4817 pindexNew = &(m_blockman.m_block_index[hashHeads[0]]);
4818
4819 if (!hashHeads[1].IsNull()) { // The old tip is allowed to be 0, indicating it's the first flush.
4820 if (!m_blockman.m_block_index.contains(hashHeads[1])) {
4821 LogError("ReplayBlocks(): reorganization from unknown block requested\n");
4822 return false;
4823 }
4824 pindexOld = &(m_blockman.m_block_index[hashHeads[1]]);
4825 pindexFork = LastCommonAncestor(pindexOld, pindexNew);
4826 assert(pindexFork != nullptr);
4827 }
4828
4829 // Rollback along the old branch.
4830 const int nForkHeight{pindexFork ? pindexFork->nHeight : 0};
4831 if (pindexOld != pindexFork) {
4832 LogInfo("Rolling back from %s (%i to %i)", pindexOld->GetBlockHash().ToString(), pindexOld->nHeight, nForkHeight);
4833 while (pindexOld != pindexFork) {
4834 if (pindexOld->nHeight > 0) { // Never disconnect the genesis block.
4835 CBlock block;
4836 if (!m_blockman.ReadBlock(block, *pindexOld)) {
4837 LogError("RollbackBlock(): ReadBlock() failed at %d, hash=%s\n", pindexOld->nHeight, pindexOld->GetBlockHash().ToString());
4838 return false;
4839 }
4840 if (pindexOld->nHeight % 10'000 == 0) {
4841 LogInfo("Rolling back %s (%i)", pindexOld->GetBlockHash().ToString(), pindexOld->nHeight);
4842 }
4843 DisconnectResult res = DisconnectBlock(block, pindexOld, cache);
4844 if (res == DISCONNECT_FAILED) {
4845 LogError("RollbackBlock(): DisconnectBlock failed at %d, hash=%s\n", pindexOld->nHeight, pindexOld->GetBlockHash().ToString());
4846 return false;
4847 }
4848 // If DISCONNECT_UNCLEAN is returned, it means a non-existing UTXO was deleted, or an existing UTXO was
4849 // overwritten. It corresponds to cases where the block-to-be-disconnect never had all its operations
4850 // applied to the UTXO set. However, as both writing a UTXO and deleting a UTXO are idempotent operations,
4851 // the result is still a version of the UTXO set with the effects of that block undone.
4852 }
4853 pindexOld = pindexOld->pprev;
4854 }
4855 LogInfo("Rolled back to %s", pindexFork->GetBlockHash().ToString());
4856 }
4857
4858 // Roll forward from the forking point to the new tip.
4859 if (nForkHeight < pindexNew->nHeight) {
4860 LogInfo("Rolling forward to %s (%i to %i)", pindexNew->GetBlockHash().ToString(), nForkHeight, pindexNew->nHeight);
4861 for (int nHeight = nForkHeight + 1; nHeight <= pindexNew->nHeight; ++nHeight) {
4862 const CBlockIndex& pindex{*Assert(pindexNew->GetAncestor(nHeight))};
4863
4864 if (nHeight % 10'000 == 0) {
4865 LogInfo("Rolling forward %s (%i)", pindex.GetBlockHash().ToString(), nHeight);
4866 }
4867 m_chainman.GetNotifications().progress(_("Replaying blocks…"), (int)((nHeight - nForkHeight) * 100.0 / (pindexNew->nHeight - nForkHeight)), false);
4868 if (!RollforwardBlock(&pindex, cache)) return false;
4869 }
4870 LogInfo("Rolled forward to %s", pindexNew->GetBlockHash().ToString());
4871 }
4872
4873 cache.SetBestBlock(pindexNew->GetBlockHash());
4874 cache.Flush(/*reallocate_cache=*/false); // local CCoinsViewCache goes out of scope
4876 return true;
4877}
4878
4880{
4882
4883 // At and above m_params.SegwitHeight, segwit consensus rules must be validated
4884 CBlockIndex* block{m_chain.Tip()};
4885
4886 while (block != nullptr && DeploymentActiveAt(*block, m_chainman, Consensus::DEPLOYMENT_SEGWIT)) {
4887 if (!(block->nStatus & BLOCK_OPT_WITNESS)) {
4888 // block is insufficiently validated for a segwit client
4889 return true;
4890 }
4891 block = block->pprev;
4892 }
4893
4894 return false;
4895}
4896
4897void Chainstate::ClearBlockIndexCandidates()
4898{
4901}
4902
4903void Chainstate::PopulateBlockIndexCandidates()
4904{
4906
4907 for (CBlockIndex* pindex : m_blockman.GetAllBlockIndices()) {
4908 // With assumeutxo, the snapshot block is a candidate for the tip, but it
4909 // may not have BLOCK_VALID_TRANSACTIONS (e.g. if we haven't yet downloaded
4910 // the block), so we special-case it here.
4911 if (pindex == SnapshotBase() ||
4913 (pindex->HaveNumChainTxs() || pindex->pprev == nullptr))) {
4915 }
4916 }
4917}
4918
4920{
4922 // Load block index from databases
4924 bool ret{m_blockman.LoadBlockIndexDB(CurrentChainstate().m_from_snapshot_blockhash)};
4925 if (!ret) return false;
4926
4927 m_blockman.ScanAndUnlinkAlreadyPrunedFiles();
4928
4929 std::vector<CBlockIndex*> vSortedByHeight{m_blockman.GetAllBlockIndices()};
4930 std::sort(vSortedByHeight.begin(), vSortedByHeight.end(),
4932
4933 for (CBlockIndex* pindex : vSortedByHeight) {
4934 if (m_interrupt) return false;
4935 if (pindex->nStatus & BLOCK_FAILED_VALID && (!m_best_invalid || pindex->nChainWork > m_best_invalid->nChainWork)) {
4936 m_best_invalid = pindex;
4937 }
4938 if (pindex->IsValid(BLOCK_VALID_TREE) && (m_best_header == nullptr || CBlockIndexWorkComparator()(m_best_header, pindex)))
4939 m_best_header = pindex;
4940 }
4941 }
4942 return true;
4943}
4944
4946{
4947 LOCK(cs_main);
4948
4949 const CBlock& genesis_block{GetParams().GenesisBlock()};
4950
4951 // Check whether we're already initialized by checking for genesis in
4952 // m_blockman.m_block_index. Note that we can't use a chainstate's m_chain here, since it is
4953 // set based on the coins db, not the block index db, which is the only
4954 // thing loaded at this point.
4955 if (m_blockman.m_block_index.contains(genesis_block.GetHash())) {
4956 return true;
4957 }
4958
4959 try {
4960 FlatFilePos blockPos{m_blockman.WriteBlock(genesis_block, 0)};
4961 if (blockPos.IsNull()) {
4962 LogError("Writing genesis block to disk failed");
4963 return false;
4964 }
4965 CBlockIndex* pindex{m_blockman.AddToBlockIndex(genesis_block, m_best_header)};
4966 ReceivedBlockTransactions(genesis_block, pindex, blockPos);
4967 } catch (const std::runtime_error& e) {
4968 LogError("Failed to write genesis block: %s", e.what());
4969 return false;
4970 }
4971
4972 return true;
4973}
4974
4976 AutoFile& file_in,
4977 FlatFilePos* dbp,
4978 std::multimap<uint256, FlatFilePos>* blocks_with_unknown_parent)
4979{
4980 // Either both should be specified (-reindex), or neither (-loadblock).
4981 assert(!dbp == !blocks_with_unknown_parent);
4982
4983 const auto start{SteadyClock::now()};
4984 const CChainParams& params{GetParams()};
4985
4986 int nLoaded = 0;
4987 try {
4989 // nRewind indicates where to resume scanning in case something goes wrong,
4990 // such as a block fails to deserialize.
4991 uint64_t nRewind = blkdat.GetPos();
4992 while (!blkdat.eof()) {
4993 if (m_interrupt) return;
4994
4995 blkdat.SetPos(nRewind);
4996 nRewind++; // start one byte further next time, in case of failure
4997 blkdat.SetLimit(); // remove former limit
4998 unsigned int nSize = 0;
4999 try {
5000 // locate a header
5002 blkdat.FindByte(std::byte(params.MessageStart()[0]));
5003 nRewind = blkdat.GetPos() + 1;
5004 blkdat >> buf;
5005 if (buf != params.MessageStart()) {
5006 continue;
5007 }
5008 // read size
5009 blkdat >> nSize;
5010 if (nSize < 80 || nSize > MAX_BLOCK_SERIALIZED_SIZE)
5011 continue;
5012 } catch (const std::exception&) {
5013 // no valid block header found; don't complain
5014 // (this happens at the end of every blk.dat file)
5015 break;
5016 }
5017 try {
5018 // read block header
5019 const uint64_t nBlockPos{blkdat.GetPos()};
5020 if (dbp)
5021 dbp->nPos = nBlockPos;
5022 blkdat.SetLimit(nBlockPos + nSize);
5023 CBlockHeader header;
5024 blkdat >> header;
5025 const uint256 hash{header.GetHash()};
5026 // Skip the rest of this block (this may read from disk into memory); position to the marker before the
5027 // next block, but it's still possible to rewind to the start of the current block (without a disk read).
5028 nRewind = nBlockPos + nSize;
5029 blkdat.SkipTo(nRewind);
5030
5031 std::shared_ptr<CBlock> pblock{}; // needs to remain available after the cs_main lock is released to avoid duplicate reads from disk
5032
5033 {
5034 LOCK(cs_main);
5035 // detect out of order blocks, and store them for later
5036 if (hash != params.GetConsensus().hashGenesisBlock && !m_blockman.LookupBlockIndex(header.hashPrevBlock)) {
5037 LogDebug(BCLog::REINDEX, "%s: Out of order block %s, parent %s not known\n", __func__, hash.ToString(),
5038 header.hashPrevBlock.ToString());
5039 if (dbp && blocks_with_unknown_parent) {
5040 blocks_with_unknown_parent->emplace(header.hashPrevBlock, *dbp);
5041 }
5042 continue;
5043 }
5044
5045 // process in case the block isn't known yet
5046 const CBlockIndex* pindex = m_blockman.LookupBlockIndex(hash);
5047 if (!pindex || (pindex->nStatus & BLOCK_HAVE_DATA) == 0) {
5048 // This block can be processed immediately; rewind to its start, read and deserialize it.
5049 blkdat.SetPos(nBlockPos);
5050 pblock = std::make_shared<CBlock>();
5051 blkdat >> TX_WITH_WITNESS(*pblock);
5052 nRewind = blkdat.GetPos();
5053
5055 if (AcceptBlock(pblock, state, nullptr, true, dbp, nullptr, true)) {
5056 nLoaded++;
5057 }
5058 if (state.IsError()) {
5059 break;
5060 }
5061 } else if (hash != params.GetConsensus().hashGenesisBlock && pindex->nHeight % 1000 == 0) {
5062 LogDebug(BCLog::REINDEX, "Block Import: already had block %s at height %d\n", hash.ToString(), pindex->nHeight);
5063 }
5064 }
5065
5066 // Activate the genesis block so normal node progress can continue
5067 // During first -reindex, this will only connect Genesis since
5068 // ActivateBestChain only connects blocks which are in the block tree db,
5069 // which only contains blocks whose parents are in it.
5070 // But do this only if genesis isn't activated yet, to avoid connecting many blocks
5071 // without assumevalid in the case of a continuation of a reindex that
5072 // was interrupted by the user.
5073 if (hash == params.GetConsensus().hashGenesisBlock && WITH_LOCK(::cs_main, return ActiveHeight()) == -1) {
5075 if (!ActiveChainstate().ActivateBestChain(state, nullptr)) {
5076 break;
5077 }
5078 }
5079
5081 // must update the tip for pruning to work while importing with -loadblock.
5082 // this is a tradeoff to conserve disk space at the expense of time
5083 // spent updating the tip to be able to prune.
5084 // otherwise, ActivateBestChain won't be called by the import process
5085 // until after all of the block files are loaded. ActivateBestChain can be
5086 // called by concurrent network message processing. but, that is not
5087 // reliable for the purpose of pruning while importing.
5088 if (auto result{ActivateBestChains()}; !result) {
5089 LogDebug(BCLog::REINDEX, "%s\n", util::ErrorString(result).original);
5090 break;
5091 }
5092 }
5093
5095
5096 if (!blocks_with_unknown_parent) continue;
5097
5098 // Recursively process earlier encountered successors of this block
5099 std::deque<uint256> queue;
5100 queue.push_back(hash);
5101 while (!queue.empty()) {
5102 uint256 head = queue.front();
5103 queue.pop_front();
5104 auto range = blocks_with_unknown_parent->equal_range(head);
5105 while (range.first != range.second) {
5106 std::multimap<uint256, FlatFilePos>::iterator it = range.first;
5107 std::shared_ptr<CBlock> pblockrecursive = std::make_shared<CBlock>();
5108 if (m_blockman.ReadBlock(*pblockrecursive, it->second, {})) {
5109 const auto& block_hash{pblockrecursive->GetHash()};
5110 LogDebug(BCLog::REINDEX, "%s: Processing out of order child %s of %s", __func__, block_hash.ToString(), head.ToString());
5111 LOCK(cs_main);
5113 if (AcceptBlock(pblockrecursive, dummy, nullptr, true, &it->second, nullptr, true)) {
5114 nLoaded++;
5115 queue.push_back(block_hash);
5116 }
5117 }
5118 range.first++;
5119 blocks_with_unknown_parent->erase(it);
5121 }
5122 }
5123 } catch (const std::exception& e) {
5124 // historical bugs added extra data to the block files that does not deserialize cleanly.
5125 // commonly this data is between readable blocks, but it does not really matter. such data is not fatal to the import process.
5126 // the code that reads the block files deals with invalid data by simply ignoring it.
5127 // it continues to search for the next {4 byte magic message start bytes + 4 byte length + block} that does deserialize cleanly
5128 // and passes all of the other block validation checks dealing with POW and the merkle root, etc...
5129 // we merely note with this informational log message when unexpected data is encountered.
5130 // we could also be experiencing a storage system read error, or a read of a previous bad write. these are possible, but
5131 // less likely scenarios. we don't have enough information to tell a difference here.
5132 // the reindex process is not the place to attempt to clean and/or compact the block files. if so desired, a studious node operator
5133 // may use knowledge of the fact that the block files are not entirely pristine in order to prepare a set of pristine, and
5134 // perhaps ordered, block files for later reindexing.
5135 LogDebug(BCLog::REINDEX, "%s: unexpected data at file offset 0x%x - %s. continuing\n", __func__, (nRewind - 1), e.what());
5136 }
5137 }
5138 } catch (const std::runtime_error& e) {
5139 GetNotifications().fatalError(strprintf(_("System error while loading external block file: %s"), e.what()));
5140 }
5141 LogInfo("Loaded %i blocks from external file in %dms", nLoaded, Ticks<std::chrono::milliseconds>(SteadyClock::now() - start));
5142}
5143
5145{
5146 // Assert to verify Flatten() has been called.
5147 if (!*Assert(m_options.check_block_index)) return false;
5148 if (FastRandomContext().randrange(*m_options.check_block_index) >= 1) return false;
5149 return true;
5150}
5151
5153{
5154 if (!ShouldCheckBlockIndex()) {
5155 return;
5156 }
5157
5158 LOCK(cs_main);
5159
5160 // During a reindex, we read the genesis block and call CheckBlockIndex before ActivateBestChain,
5161 // so we have the genesis block in m_blockman.m_block_index but no active chain. (A few of the
5162 // tests when iterating the block tree require that m_chain has been initialized.)
5163 if (ActiveChain().Height() < 0) {
5164 assert(m_blockman.m_block_index.size() <= 1);
5165 return;
5166 }
5167
5168 // Build forward-pointing data structure for the entire block tree.
5169 // For performance reasons, indexes of the best header chain are stored in a vector (within CChain).
5170 // All remaining blocks are stored in a multimap.
5171 // The best header chain can differ from the active chain: E.g. its entries may belong to blocks that
5172 // are not yet validated.
5173 CChain best_hdr_chain;
5174 assert(m_best_header);
5175 assert(!(m_best_header->nStatus & BLOCK_FAILED_VALID));
5176 best_hdr_chain.SetTip(*m_best_header);
5177
5178 std::multimap<const CBlockIndex*, const CBlockIndex*> forward;
5179 for (auto& [_, block_index] : m_blockman.m_block_index) {
5180 // Only save indexes in forward that are not part of the best header chain.
5181 if (!best_hdr_chain.Contains(block_index)) {
5182 // Only genesis, which must be part of the best header chain, can have a nullptr parent.
5183 assert(block_index.pprev);
5184 forward.emplace(block_index.pprev, &block_index);
5185 }
5186 }
5187 assert(forward.size() + best_hdr_chain.Height() + 1 == m_blockman.m_block_index.size());
5188
5189 const CBlockIndex* pindex = best_hdr_chain[0];
5190 assert(pindex);
5191 // Iterate over the entire block tree, using depth-first search.
5192 // Along the way, remember whether there are blocks on the path from genesis
5193 // block being explored which are the first to have certain properties.
5194 size_t nNodes = 0;
5195 int nHeight = 0;
5196 const CBlockIndex* pindexFirstInvalid = nullptr; // Oldest ancestor of pindex which is invalid.
5197 const CBlockIndex* pindexFirstMissing = nullptr; // Oldest ancestor of pindex which does not have BLOCK_HAVE_DATA, since assumeutxo snapshot if used.
5198 const CBlockIndex* pindexFirstNeverProcessed = nullptr; // Oldest ancestor of pindex for which nTx == 0, since assumeutxo snapshot if used.
5199 const CBlockIndex* pindexFirstNotTreeValid = nullptr; // Oldest ancestor of pindex which does not have BLOCK_VALID_TREE (regardless of being valid or not).
5200 const CBlockIndex* pindexFirstNotTransactionsValid = nullptr; // Oldest ancestor of pindex which does not have BLOCK_VALID_TRANSACTIONS (regardless of being valid or not), since assumeutxo snapshot if used.
5201 const CBlockIndex* pindexFirstNotChainValid = nullptr; // Oldest ancestor of pindex which does not have BLOCK_VALID_CHAIN (regardless of being valid or not), since assumeutxo snapshot if used.
5202 const CBlockIndex* pindexFirstNotScriptsValid = nullptr; // Oldest ancestor of pindex which does not have BLOCK_VALID_SCRIPTS (regardless of being valid or not), since assumeutxo snapshot if used.
5203
5204 // After checking an assumeutxo snapshot block, reset pindexFirst pointers
5205 // to earlier blocks that have not been downloaded or validated yet, so
5206 // checks for later blocks can assume the earlier blocks were validated and
5207 // be stricter, testing for more requirements.
5208 const CBlockIndex* snap_base{CurrentChainstate().SnapshotBase()};
5209 const CBlockIndex *snap_first_missing{}, *snap_first_notx{}, *snap_first_notv{}, *snap_first_nocv{}, *snap_first_nosv{};
5210 auto snap_update_firsts = [&] {
5211 if (pindex == snap_base) {
5212 std::swap(snap_first_missing, pindexFirstMissing);
5213 std::swap(snap_first_notx, pindexFirstNeverProcessed);
5214 std::swap(snap_first_notv, pindexFirstNotTransactionsValid);
5215 std::swap(snap_first_nocv, pindexFirstNotChainValid);
5216 std::swap(snap_first_nosv, pindexFirstNotScriptsValid);
5217 }
5218 };
5219
5220 while (pindex != nullptr) {
5221 nNodes++;
5222 if (pindexFirstInvalid == nullptr && pindex->nStatus & BLOCK_FAILED_VALID) pindexFirstInvalid = pindex;
5223 if (pindexFirstMissing == nullptr && !(pindex->nStatus & BLOCK_HAVE_DATA)) {
5224 pindexFirstMissing = pindex;
5225 }
5226 if (pindexFirstNeverProcessed == nullptr && pindex->nTx == 0) pindexFirstNeverProcessed = pindex;
5227 if (pindex->pprev != nullptr && pindexFirstNotTreeValid == nullptr && (pindex->nStatus & BLOCK_VALID_MASK) < BLOCK_VALID_TREE) pindexFirstNotTreeValid = pindex;
5228
5229 if (pindex->pprev != nullptr) {
5230 if (pindexFirstNotTransactionsValid == nullptr &&
5231 (pindex->nStatus & BLOCK_VALID_MASK) < BLOCK_VALID_TRANSACTIONS) {
5232 pindexFirstNotTransactionsValid = pindex;
5233 }
5234
5235 if (pindexFirstNotChainValid == nullptr &&
5236 (pindex->nStatus & BLOCK_VALID_MASK) < BLOCK_VALID_CHAIN) {
5237 pindexFirstNotChainValid = pindex;
5238 }
5239
5240 if (pindexFirstNotScriptsValid == nullptr &&
5241 (pindex->nStatus & BLOCK_VALID_MASK) < BLOCK_VALID_SCRIPTS) {
5242 pindexFirstNotScriptsValid = pindex;
5243 }
5244 }
5245
5246 // Begin: actual consistency checks.
5247 if (pindex->pprev == nullptr) {
5248 // Genesis block checks.
5249 assert(pindex->GetBlockHash() == GetConsensus().hashGenesisBlock); // Genesis block's hash must match.
5250 for (const auto& c : m_chainstates) {
5251 if (c->m_chain.Genesis() != nullptr) {
5252 assert(pindex == c->m_chain.Genesis()); // The chain's genesis block must be this block.
5253 }
5254 }
5255 }
5256 // nSequenceId can't be set higher than SEQ_ID_INIT_FROM_DISK{1} for blocks that aren't linked
5257 // (negative is used for preciousblock, SEQ_ID_BEST_CHAIN_FROM_DISK{0} for active chain when loaded from disk)
5258 if (!pindex->HaveNumChainTxs()) assert(pindex->nSequenceId <= SEQ_ID_INIT_FROM_DISK);
5259 // VALID_TRANSACTIONS is equivalent to nTx > 0 for all nodes (whether or not pruning has occurred).
5260 // HAVE_DATA is only equivalent to nTx > 0 (or VALID_TRANSACTIONS) if no pruning has occurred.
5262 // If we've never pruned, then HAVE_DATA should be equivalent to nTx > 0
5263 assert(!(pindex->nStatus & BLOCK_HAVE_DATA) == (pindex->nTx == 0));
5264 assert(pindexFirstMissing == pindexFirstNeverProcessed);
5265 } else {
5266 // If we have pruned, then we can only say that HAVE_DATA implies nTx > 0
5267 if (pindex->nStatus & BLOCK_HAVE_DATA) assert(pindex->nTx > 0);
5268 }
5269 if (pindex->nStatus & BLOCK_HAVE_UNDO) assert(pindex->nStatus & BLOCK_HAVE_DATA);
5270 if (snap_base && snap_base->GetAncestor(pindex->nHeight) == pindex) {
5271 // Assumed-valid blocks should connect to the main chain.
5272 assert((pindex->nStatus & BLOCK_VALID_MASK) >= BLOCK_VALID_TREE);
5273 }
5274 // There should only be an nTx value if we have
5275 // actually seen a block's transactions.
5276 assert(((pindex->nStatus & BLOCK_VALID_MASK) >= BLOCK_VALID_TRANSACTIONS) == (pindex->nTx > 0)); // This is pruning-independent.
5277 // All parents having had data (at some point) is equivalent to all parents being VALID_TRANSACTIONS, which is equivalent to HaveNumChainTxs().
5278 // HaveNumChainTxs will also be set in the assumeutxo snapshot block from snapshot metadata.
5279 assert((pindexFirstNeverProcessed == nullptr || pindex == snap_base) == pindex->HaveNumChainTxs());
5280 assert((pindexFirstNotTransactionsValid == nullptr || pindex == snap_base) == pindex->HaveNumChainTxs());
5281 assert(pindex->nHeight == nHeight); // nHeight must be consistent.
5282 assert(pindex->pprev == nullptr || pindex->nChainWork >= pindex->pprev->nChainWork); // For every block except the genesis block, the chainwork must be larger than the parent's.
5283 assert(nHeight < 2 || (pindex->pskip && (pindex->pskip->nHeight < nHeight))); // The pskip pointer must point back for all but the first 2 blocks.
5284 assert(pindexFirstNotTreeValid == nullptr); // All m_blockman.m_block_index entries must at least be TREE valid
5285 if ((pindex->nStatus & BLOCK_VALID_MASK) >= BLOCK_VALID_TREE) assert(pindexFirstNotTreeValid == nullptr); // TREE valid implies all parents are TREE valid
5286 if ((pindex->nStatus & BLOCK_VALID_MASK) >= BLOCK_VALID_CHAIN) assert(pindexFirstNotChainValid == nullptr); // CHAIN valid implies all parents are CHAIN valid
5287 if ((pindex->nStatus & BLOCK_VALID_MASK) >= BLOCK_VALID_SCRIPTS) assert(pindexFirstNotScriptsValid == nullptr); // SCRIPTS valid implies all parents are SCRIPTS valid
5288 if (pindexFirstInvalid == nullptr) {
5289 // Checks for not-invalid blocks.
5290 assert((pindex->nStatus & BLOCK_FAILED_VALID) == 0); // The failed flag cannot be set for blocks without invalid parents.
5291 } else {
5292 assert(pindex->nStatus & BLOCK_FAILED_VALID); // Invalid blocks and their descendants must be marked as invalid
5293 }
5294 // Make sure m_chain_tx_count sum is correctly computed.
5295 if (!pindex->pprev) {
5296 // If no previous block, nTx and m_chain_tx_count must be the same.
5297 assert(pindex->m_chain_tx_count == pindex->nTx);
5298 } else if (pindex->pprev->m_chain_tx_count > 0 && pindex->nTx > 0) {
5299 // If previous m_chain_tx_count is set and number of transactions in block is known, sum must be set.
5300 assert(pindex->m_chain_tx_count == pindex->nTx + pindex->pprev->m_chain_tx_count);
5301 } else {
5302 // Otherwise m_chain_tx_count should only be set if this is a snapshot
5303 // block, and must be set if it is.
5304 assert((pindex->m_chain_tx_count != 0) == (pindex == snap_base));
5305 }
5306 // There should be no block with more work than m_best_header, unless it's known to be invalid
5307 assert((pindex->nStatus & BLOCK_FAILED_VALID) || pindex->nChainWork <= m_best_header->nChainWork);
5308
5309 // Chainstate-specific checks on setBlockIndexCandidates
5310 for (const auto& c : m_chainstates) {
5311 if (c->m_chain.Tip() == nullptr) continue;
5312 // Two main factors determine whether pindex is a candidate in
5313 // setBlockIndexCandidates:
5314 //
5315 // - If pindex has less work than the chain tip, it should not be a
5316 // candidate, and this will be asserted below. Otherwise it is a
5317 // potential candidate.
5318 //
5319 // - If pindex or one of its parent blocks back to the genesis block
5320 // or an assumeutxo snapshot never downloaded transactions
5321 // (pindexFirstNeverProcessed is non-null), it should not be a
5322 // candidate, and this will be asserted below. The only exception
5323 // is if pindex itself is an assumeutxo snapshot block. Then it is
5324 // also a potential candidate.
5325 if (!CBlockIndexWorkComparator()(pindex, c->m_chain.Tip()) && (pindexFirstNeverProcessed == nullptr || pindex == snap_base)) {
5326 // If pindex was detected as invalid (pindexFirstInvalid is
5327 // non-null), it is not required to be in
5328 // setBlockIndexCandidates.
5329 if (pindexFirstInvalid == nullptr) {
5330 // If pindex and all its parents back to the genesis block
5331 // or an assumeutxo snapshot block downloaded transactions,
5332 // and the transactions were not pruned (pindexFirstMissing
5333 // is null), it is a potential candidate. The check
5334 // excludes pruned blocks, because if any blocks were
5335 // pruned between pindex and the current chain tip, pindex will
5336 // only temporarily be added to setBlockIndexCandidates,
5337 // before being moved to m_blocks_unlinked. This check
5338 // could be improved to verify that if all blocks between
5339 // the chain tip and pindex have data, pindex must be a
5340 // candidate.
5341 //
5342 // If pindex is the chain tip, it also is a potential
5343 // candidate.
5344 //
5345 // If the chainstate was loaded from a snapshot and pindex
5346 // is the base of the snapshot, pindex is also a potential
5347 // candidate.
5348 if (pindexFirstMissing == nullptr || pindex == c->m_chain.Tip() || pindex == c->SnapshotBase()) {
5349 // If this chainstate is not a historical chainstate
5350 // targeting a specific block, pindex must be in
5351 // setBlockIndexCandidates. Otherwise, pindex only
5352 // needs to be added if it is an ancestor of the target
5353 // block.
5354 if (!c->TargetBlock() || c->TargetBlock()->GetAncestor(pindex->nHeight) == pindex) {
5355 assert(c->setBlockIndexCandidates.contains(pindex));
5356 }
5357 }
5358 // If some parent is missing, then it could be that this block was in
5359 // setBlockIndexCandidates but had to be removed because of the missing data.
5360 // In this case it must be in m_blocks_unlinked -- see test below.
5361 }
5362 } else { // If this block sorts worse than the current tip or some ancestor's block has never been seen, it cannot be in setBlockIndexCandidates.
5363 assert(!c->setBlockIndexCandidates.contains(pindex));
5364 }
5365 }
5366 // Check whether this block is in m_blocks_unlinked.
5367 auto rangeUnlinked{m_blockman.m_blocks_unlinked.equal_range(pindex->pprev)};
5368 bool foundInUnlinked = false;
5369 for (auto it = rangeUnlinked.first; it != rangeUnlinked.second; ++it) {
5370 assert(it->first == pindex->pprev);
5371 if (it->second == pindex) {
5372 assert(!foundInUnlinked); // No duplicates in m_blocks_unlinked
5373 foundInUnlinked = true;
5374 }
5375 }
5376 if (pindex->pprev && (pindex->nStatus & BLOCK_HAVE_DATA) && pindexFirstNeverProcessed != nullptr && pindexFirstInvalid == nullptr) {
5377 // If this block has block data available, some parent was never received, and has no invalid parents, it must be in m_blocks_unlinked.
5378 assert(foundInUnlinked);
5379 }
5380 if (!(pindex->nStatus & BLOCK_HAVE_DATA)) assert(!foundInUnlinked); // Can't be in m_blocks_unlinked if we don't HAVE_DATA
5381 if (pindexFirstMissing == nullptr) assert(!foundInUnlinked); // We aren't missing data for any parent -- cannot be in m_blocks_unlinked.
5382 if (pindex->pprev && (pindex->nStatus & BLOCK_HAVE_DATA) && pindexFirstNeverProcessed == nullptr && pindexFirstMissing != nullptr) {
5383 // We HAVE_DATA for this block, have received data for all parents at some point, but we're currently missing data for some parent.
5385 // This block may have entered m_blocks_unlinked if:
5386 // - it has a descendant that at some point had more work than the
5387 // tip, and
5388 // - we tried switching to that descendant but were missing
5389 // data for some intermediate block between m_chain and the
5390 // tip.
5391 // So if this block is itself better than any m_chain.Tip() and it wasn't in
5392 // setBlockIndexCandidates, then it must be in m_blocks_unlinked.
5393 for (const auto& c : m_chainstates) {
5394 if (!CBlockIndexWorkComparator()(pindex, c->m_chain.Tip()) && !c->setBlockIndexCandidates.contains(pindex)) {
5395 if (pindexFirstInvalid == nullptr) {
5396 if (!c->TargetBlock() || c->TargetBlock()->GetAncestor(pindex->nHeight) == pindex) {
5397 assert(foundInUnlinked);
5398 }
5399 }
5400 }
5401 }
5402 }
5403 // assert(pindex->GetBlockHash() == pindex->GetBlockHeader().GetHash()); // Perhaps too slow
5404 // End: actual consistency checks.
5405
5406
5407 // Try descending into the first subnode. Always process forks first and the best header chain after.
5408 snap_update_firsts();
5409 auto range{forward.equal_range(pindex)};
5410 if (range.first != range.second) {
5411 // A subnode not part of the best header chain was found.
5412 pindex = range.first->second;
5413 nHeight++;
5414 continue;
5415 } else if (best_hdr_chain.Contains(*pindex)) {
5416 // Descend further into best header chain.
5417 nHeight++;
5418 pindex = best_hdr_chain[nHeight];
5419 if (!pindex) break; // we are finished, since the best header chain is always processed last
5420 continue;
5421 }
5422 // This is a leaf node.
5423 // Move upwards until we reach a node of which we have not yet visited the last child.
5424 while (pindex) {
5425 // We are going to either move to a parent or a sibling of pindex.
5426 snap_update_firsts();
5427 // If pindex was the first with a certain property, unset the corresponding variable.
5428 if (pindex == pindexFirstInvalid) pindexFirstInvalid = nullptr;
5429 if (pindex == pindexFirstMissing) pindexFirstMissing = nullptr;
5430 if (pindex == pindexFirstNeverProcessed) pindexFirstNeverProcessed = nullptr;
5431 if (pindex == pindexFirstNotTreeValid) pindexFirstNotTreeValid = nullptr;
5432 if (pindex == pindexFirstNotTransactionsValid) pindexFirstNotTransactionsValid = nullptr;
5433 if (pindex == pindexFirstNotChainValid) pindexFirstNotChainValid = nullptr;
5434 if (pindex == pindexFirstNotScriptsValid) pindexFirstNotScriptsValid = nullptr;
5435 // Find our parent.
5436 CBlockIndex* pindexPar = pindex->pprev;
5437 // Find which child we just visited.
5438 auto rangePar{forward.equal_range(pindexPar)};
5439 while (rangePar.first->second != pindex) {
5440 assert(rangePar.first != rangePar.second); // Our parent must have at least the node we're coming from as child.
5441 rangePar.first++;
5442 }
5443 // Proceed to the next one.
5444 rangePar.first++;
5445 if (rangePar.first != rangePar.second) {
5446 // Move to a sibling not part of the best header chain.
5447 pindex = rangePar.first->second;
5448 break;
5449 } else if (pindexPar == best_hdr_chain[nHeight - 1]) {
5450 // Move to pindex's sibling on the best-chain, if it has one.
5451 pindex = best_hdr_chain[nHeight];
5452 // There will not be a next block if (and only if) parent block is the best header.
5453 assert((pindex == nullptr) == (pindexPar == best_hdr_chain.Tip()));
5454 break;
5455 } else {
5456 // Move up further.
5457 pindex = pindexPar;
5458 nHeight--;
5459 continue;
5460 }
5461 }
5462 }
5463
5464 // Check that we actually traversed the entire block index.
5465 assert(nNodes == forward.size() + best_hdr_chain.Height() + 1);
5466}
5467
5468std::string Chainstate::ToString()
5469{
5471 CBlockIndex* tip = m_chain.Tip();
5472 return strprintf("Chainstate [%s] @ height %d (%s)",
5473 m_from_snapshot_blockhash ? "snapshot" : "ibd",
5474 tip ? tip->nHeight : -1, tip ? tip->GetBlockHash().ToString() : "null");
5475}
5476
5477bool Chainstate::ResizeCoinsCaches(size_t coinstip_size, size_t coinsdb_size)
5478{
5480 if (coinstip_size == m_coinstip_cache_size_bytes &&
5481 coinsdb_size == m_coinsdb_cache_size_bytes) {
5482 // Cache sizes are unchanged, no need to continue.
5483 return true;
5484 }
5485 size_t old_coinstip_size = m_coinstip_cache_size_bytes;
5486 m_coinstip_cache_size_bytes = coinstip_size;
5487 m_coinsdb_cache_size_bytes = coinsdb_size;
5488 CoinsDB().ResizeCache(coinsdb_size);
5489
5490 LogInfo("[%s] resized coinsdb cache to %.1f MiB",
5491 this->ToString(), coinsdb_size / double(1_MiB));
5492 LogInfo("[%s] resized coinstip cache to %.1f MiB",
5493 this->ToString(), coinstip_size / double(1_MiB));
5494
5496 bool ret;
5497
5498 if (coinstip_size > old_coinstip_size) {
5499 // Likely no need to flush if cache sizes have grown.
5501 } else {
5502 // Otherwise, flush state to disk and deallocate the in-memory coins map.
5504 }
5505 return ret;
5506}
5507
5509{
5511 const ChainTxData& data{GetParams().TxData()};
5512 if (pindex == nullptr) {
5513 return 0.0;
5514 }
5515
5516 if (pindex->m_chain_tx_count == 0) {
5517 LogDebug(BCLog::VALIDATION, "Block %d has unset m_chain_tx_count. Unable to estimate verification progress.\n", pindex->nHeight);
5518 return 0.0;
5519 }
5520
5521 const int64_t nNow{TicksSinceEpoch<std::chrono::seconds>(NodeClock::now())};
5522 const auto block_time{
5523 (Assume(m_best_header) && std::abs(nNow - pindex->GetBlockTime()) <= Ticks<std::chrono::seconds>(2h) &&
5524 Assume(m_best_header->nHeight >= pindex->nHeight)) ?
5525 // When the header is known to be recent, switch to a height-based
5526 // approach. This ensures the returned value is quantized when
5527 // close to "1.0", because some users expect it to be. This also
5528 // avoids relying too much on the exact miner-set timestamp, which
5529 // may be off.
5530 nNow - (m_best_header->nHeight - pindex->nHeight) * GetConsensus().nPowTargetSpacing :
5531 pindex->GetBlockTime(),
5532 };
5533
5534 double fTxTotal;
5535
5536 if (pindex->m_chain_tx_count <= data.tx_count) {
5537 fTxTotal = data.tx_count + (nNow - data.nTime) * data.dTxRate;
5538 } else {
5539 fTxTotal = pindex->m_chain_tx_count + (nNow - block_time) * data.dTxRate;
5540 }
5541
5542 return std::min<double>(pindex->m_chain_tx_count / fTxTotal, 1.0);
5543}
5544
5546{
5549 auto target_block = HistoricalChainstate()->TargetBlock();
5550
5551 if (pindex.m_chain_tx_count == 0 || target_block->m_chain_tx_count == 0) {
5552 LogDebug(BCLog::VALIDATION, "[background validation] Block %d has unset m_chain_tx_count. Unable to estimate verification progress.", pindex.nHeight);
5553 return 0.0;
5554 }
5555 return static_cast<double>(pindex.m_chain_tx_count) / static_cast<double>(target_block->m_chain_tx_count);
5556}
5557
5558Chainstate& ChainstateManager::InitializeChainstate(CTxMemPool* mempool)
5559{
5561 assert(m_chainstates.empty());
5562 m_chainstates.emplace_back(std::make_unique<Chainstate>(mempool, m_blockman, *this));
5563 return *m_chainstates.back();
5564}
5565
5566[[nodiscard]] static bool DeleteCoinsDBFromDisk(const fs::path db_path, bool is_snapshot)
5568{
5570
5571 if (is_snapshot) {
5572 fs::path base_blockhash_path = db_path / node::SNAPSHOT_BLOCKHASH_FILENAME;
5573
5574 try {
5575 bool existed = fs::remove(base_blockhash_path);
5576 if (!existed) {
5577 LogWarning("[snapshot] snapshot chainstate dir being removed lacks %s file",
5579 }
5580 } catch (const fs::filesystem_error& e) {
5581 LogWarning("[snapshot] failed to remove file %s: %s\n",
5582 fs::PathToString(base_blockhash_path), e.code().message());
5583 }
5584 }
5585
5586 std::string path_str = fs::PathToString(db_path);
5587 LogInfo("Removing leveldb dir at %s\n", path_str);
5588
5589 // We have to destruct before this call leveldb::DB in order to release the db
5590 // lock, otherwise `DestroyDB` will fail. See `leveldb::~DBImpl()`.
5591 const bool destroyed = DestroyDB(path_str);
5592
5593 if (!destroyed) {
5594 LogError("leveldb DestroyDB call failed on %s", path_str);
5595 }
5596
5597 // Datadir should be removed from filesystem; otherwise initialization may detect
5598 // it on subsequent statups and get confused.
5599 //
5600 // If the base_blockhash_path removal above fails in the case of snapshot
5601 // chainstates, this will return false since leveldb won't remove a non-empty
5602 // directory.
5603 return destroyed && !fs::exists(db_path);
5604}
5605
5607 AutoFile& coins_file,
5608 const SnapshotMetadata& metadata,
5609 bool in_memory)
5610{
5611 uint256 base_blockhash = metadata.m_base_blockhash;
5612
5613 CBlockIndex* snapshot_start_block{};
5614
5615 {
5616 LOCK(::cs_main);
5617
5618 if (this->CurrentChainstate().m_from_snapshot_blockhash) {
5619 return util::Error{Untranslated("Can't activate a snapshot-based chainstate more than once")};
5620 }
5621 if (!GetParams().AssumeutxoForBlockhash(base_blockhash).has_value()) {
5622 auto available_heights = GetParams().GetAvailableSnapshotHeights();
5623 std::string heights_formatted = util::Join(available_heights, ", ", [&](const auto& i) { return util::ToString(i); });
5624 return util::Error{Untranslated(strprintf("assumeutxo block hash in snapshot metadata not recognized (hash: %s). The following snapshot heights are available: %s",
5625 base_blockhash.ToString(),
5626 heights_formatted))};
5627 }
5628
5629 snapshot_start_block = m_blockman.LookupBlockIndex(base_blockhash);
5630 if (!snapshot_start_block) {
5631 return util::Error{Untranslated(strprintf("The base block header (%s) must appear in the headers chain. Make sure all headers are syncing, and call loadtxoutset again",
5632 base_blockhash.ToString()))};
5633 }
5634
5635 bool start_block_invalid = snapshot_start_block->nStatus & BLOCK_FAILED_VALID;
5636 if (start_block_invalid) {
5637 return util::Error{Untranslated(strprintf("The base block header (%s) is part of an invalid chain", base_blockhash.ToString()))};
5638 }
5639
5640 if (!m_best_header || m_best_header->GetAncestor(snapshot_start_block->nHeight) != snapshot_start_block) {
5641 return util::Error{Untranslated("A forked headers-chain with more work than the chain with the snapshot base block header exists. Please proceed to sync without AssumeUtxo.")};
5642 }
5643
5644 auto mempool{CurrentChainstate().GetMempool()};
5645 if (mempool && mempool->size() > 0) {
5646 return util::Error{Untranslated("Can't activate a snapshot when mempool not empty")};
5647 }
5648 }
5649
5650 int64_t current_coinsdb_cache_size{0};
5651 int64_t current_coinstip_cache_size{0};
5652
5653 // Cache percentages to allocate to each chainstate.
5654 //
5655 // These particular percentages don't matter so much since they will only be
5656 // relevant during snapshot activation; caches are rebalanced at the conclusion of
5657 // this function. We want to give (essentially) all available cache capacity to the
5658 // snapshot to aid the bulk load later in this function.
5659 static constexpr double IBD_CACHE_PERC = 0.01;
5660 static constexpr double SNAPSHOT_CACHE_PERC = 0.99;
5661
5662 {
5663 LOCK(::cs_main);
5664 // Resize the coins caches to ensure we're not exceeding memory limits.
5665 //
5666 // Allocate the majority of the cache to the incoming snapshot chainstate, since
5667 // (optimistically) getting to its tip will be the top priority. We'll need to call
5668 // `MaybeRebalanceCaches()` once we're done with this function to ensure
5669 // the right allocation (including the possibility that no snapshot was activated
5670 // and that we should restore the active chainstate caches to their original size).
5671 //
5672 current_coinsdb_cache_size = this->ActiveChainstate().m_coinsdb_cache_size_bytes;
5673 current_coinstip_cache_size = this->ActiveChainstate().m_coinstip_cache_size_bytes;
5674
5675 // Temporarily resize the active coins cache to make room for the newly-created
5676 // snapshot chain.
5677 this->ActiveChainstate().ResizeCoinsCaches(
5678 static_cast<size_t>(current_coinstip_cache_size * IBD_CACHE_PERC),
5679 static_cast<size_t>(current_coinsdb_cache_size * IBD_CACHE_PERC));
5680 }
5681
5682 auto snapshot_chainstate = WITH_LOCK(::cs_main,
5683 return std::make_unique<Chainstate>(
5684 /*mempool=*/nullptr, m_blockman, *this, base_blockhash));
5685
5686 {
5687 LOCK(::cs_main);
5688 snapshot_chainstate->InitCoinsDB(
5689 static_cast<size_t>(current_coinsdb_cache_size * SNAPSHOT_CACHE_PERC),
5690 in_memory, /*should_wipe=*/false);
5691 snapshot_chainstate->InitCoinsCache(
5692 static_cast<size_t>(current_coinstip_cache_size * SNAPSHOT_CACHE_PERC));
5693 }
5694
5695 auto cleanup_bad_snapshot = [&](bilingual_str reason) EXCLUSIVE_LOCKS_REQUIRED(::cs_main) {
5696 this->MaybeRebalanceCaches();
5697
5698 // PopulateAndValidateSnapshot can return (in error) before the leveldb datadir
5699 // has been created, so only attempt removal if we got that far.
5700 if (auto snapshot_datadir = node::FindAssumeutxoChainstateDir(m_options.datadir)) {
5701 // We have to destruct leveldb::DB in order to release the db lock, otherwise
5702 // DestroyDB() (in DeleteCoinsDBFromDisk()) will fail. See `leveldb::~DBImpl()`.
5703 // Destructing the chainstate (and so resetting the coinsviews object) does this.
5704 snapshot_chainstate.reset();
5705 bool removed = DeleteCoinsDBFromDisk(*snapshot_datadir, /*is_snapshot=*/true);
5706 if (!removed) {
5707 GetNotifications().fatalError(strprintf(_("Failed to remove snapshot chainstate dir (%s). "
5708 "Manually remove it before restarting.\n"), fs::PathToString(*snapshot_datadir)));
5709 }
5710 }
5711 return util::Error{std::move(reason)};
5712 };
5713
5714 if (auto res{this->PopulateAndValidateSnapshot(*snapshot_chainstate, coins_file, metadata)}; !res) {
5715 LOCK(::cs_main);
5716 return cleanup_bad_snapshot(Untranslated(strprintf("Population failed: %s", util::ErrorString(res).original)));
5717 }
5718
5719 LOCK(::cs_main); // cs_main required for rest of snapshot activation.
5720
5721 // Do a final check to ensure that the snapshot chainstate is actually a more
5722 // work chain than the active chainstate; a user could have loaded a snapshot
5723 // very late in the IBD process, and we wouldn't want to load a useless chainstate.
5724 if (!CBlockIndexWorkComparator()(ActiveTip(), snapshot_chainstate->m_chain.Tip())) {
5725 return cleanup_bad_snapshot(Untranslated("work does not exceed active chainstate"));
5726 }
5727 // If not in-memory, persist the base blockhash for use during subsequent
5728 // initialization.
5729 if (!in_memory) {
5730 if (!node::WriteSnapshotBaseBlockhash(*snapshot_chainstate)) {
5731 return cleanup_bad_snapshot(Untranslated("could not write base blockhash"));
5732 }
5733 }
5734
5735 Chainstate& chainstate{AddChainstate(std::move(snapshot_chainstate))};
5736 m_blockman.m_snapshot_height = Assert(chainstate.SnapshotBase())->nHeight;
5737
5738 chainstate.PopulateBlockIndexCandidates();
5739
5740 LogInfo("[snapshot] successfully activated snapshot %s", base_blockhash.ToString());
5741 LogInfo("[snapshot] (%.2f MB)",
5742 chainstate.CoinsTip().DynamicMemoryUsage() / (1000 * 1000));
5743
5744 this->MaybeRebalanceCaches();
5745 return snapshot_start_block;
5746}
5747
5748static void FlushSnapshotToDisk(CCoinsViewCache& coins_cache, bool snapshot_loaded)
5749{
5751 strprintf("%s (%.2f MB)",
5752 snapshot_loaded ? "saving snapshot chainstate" : "flushing coins cache",
5753 coins_cache.DynamicMemoryUsage() / (1000 * 1000)),
5755
5756 coins_cache.Flush();
5757}
5758
5759struct StopHashingException : public std::exception
5760{
5761 const char* what() const noexcept override
5762 {
5763 return "ComputeUTXOStats interrupted.";
5764 }
5765};
5766
5768{
5769 if (interrupt) throw StopHashingException();
5770}
5771
5773 Chainstate& snapshot_chainstate,
5774 AutoFile& coins_file,
5775 const SnapshotMetadata& metadata)
5776{
5777 // It's okay to release cs_main before we're done using `coins_cache` because we know
5778 // that nothing else will be referencing the newly created snapshot_chainstate yet.
5779 CCoinsViewCache& coins_cache = *WITH_LOCK(::cs_main, return &snapshot_chainstate.CoinsTip());
5780
5781 uint256 base_blockhash = metadata.m_base_blockhash;
5782
5783 CBlockIndex* snapshot_start_block = WITH_LOCK(::cs_main, return m_blockman.LookupBlockIndex(base_blockhash));
5784
5785 if (!snapshot_start_block) {
5786 // Needed for ComputeUTXOStats to determine the
5787 // height and to avoid a crash when base_blockhash.IsNull()
5788 return util::Error{Untranslated(strprintf("Did not find snapshot start blockheader %s",
5789 base_blockhash.ToString()))};
5790 }
5791
5792 int base_height = snapshot_start_block->nHeight;
5793 const auto& maybe_au_data = GetParams().AssumeutxoForHeight(base_height);
5794
5795 if (!maybe_au_data) {
5796 return util::Error{Untranslated(strprintf("Assumeutxo height in snapshot metadata not recognized "
5797 "(%d) - refusing to load snapshot", base_height))};
5798 }
5799
5800 const AssumeutxoData& au_data = *maybe_au_data;
5801
5802 // This work comparison is a duplicate check with the one performed later in
5803 // ActivateSnapshot(), but is done so that we avoid doing the long work of staging
5804 // a snapshot that isn't actually usable.
5805 if (WITH_LOCK(::cs_main, return !CBlockIndexWorkComparator()(ActiveTip(), snapshot_start_block))) {
5806 return util::Error{Untranslated("Work does not exceed active chainstate")};
5807 }
5808
5809 const uint64_t coins_count = metadata.m_coins_count;
5810 uint64_t coins_left = metadata.m_coins_count;
5811
5812 LogInfo("[snapshot] loading %d coins from snapshot %s", coins_left, base_blockhash.ToString());
5813 int64_t coins_processed{0};
5814
5815 while (coins_left > 0) {
5816 try {
5817 Txid txid;
5818 coins_file >> txid;
5819 size_t coins_per_txid{0};
5820 coins_per_txid = ReadCompactSize(coins_file);
5821
5822 if (coins_per_txid > coins_left) {
5823 return util::Error{Untranslated("Mismatch in coins count in snapshot metadata and actual snapshot data")};
5824 }
5825
5826 for (size_t i = 0; i < coins_per_txid; i++) {
5827 COutPoint outpoint;
5828 Coin coin;
5829 outpoint.n = static_cast<uint32_t>(ReadCompactSize(coins_file));
5830 outpoint.hash = txid;
5831 coins_file >> coin;
5832 if (coin.nHeight > base_height ||
5833 outpoint.n >= std::numeric_limits<decltype(outpoint.n)>::max() // Avoid integer wrap-around in coinstats.cpp:ApplyHash
5834 ) {
5835 return util::Error{Untranslated(strprintf("Bad snapshot data after deserializing %d coins",
5836 coins_count - coins_left))};
5837 }
5838 if (!MoneyRange(coin.out.nValue)) {
5839 return util::Error{Untranslated(strprintf("Bad snapshot data after deserializing %d coins - bad tx out value",
5840 coins_count - coins_left))};
5841 }
5842 coins_cache.EmplaceCoinInternalDANGER(outpoint, std::move(coin));
5843
5844 --coins_left;
5845 ++coins_processed;
5846
5847 if (coins_processed % 1000000 == 0) {
5848 LogInfo("[snapshot] %d coins loaded (%.2f%%, %.2f MB)",
5849 coins_processed,
5850 static_cast<float>(coins_processed) * 100 / static_cast<float>(coins_count),
5851 coins_cache.DynamicMemoryUsage() / (1000 * 1000));
5852 }
5853
5854 // Batch write and flush (if we need to) every so often.
5855 //
5856 // If our average Coin size is roughly 41 bytes, checking every 120,000 coins
5857 // means <5MB of memory imprecision.
5858 if (coins_processed % 120000 == 0) {
5859 if (m_interrupt) {
5860 return util::Error{Untranslated("Aborting after an interrupt was requested")};
5861 }
5862
5863 const auto snapshot_cache_state = WITH_LOCK(::cs_main,
5864 return snapshot_chainstate.GetCoinsCacheSizeState());
5865
5866 if (snapshot_cache_state >= CoinsCacheSizeState::CRITICAL) {
5867 // This is a hack - we don't know what the actual best block is, but that
5868 // doesn't matter for the purposes of flushing the cache here. We'll set this
5869 // to its correct value (`base_blockhash`) below after the coins are loaded.
5870 coins_cache.SetBestBlock(GetRandHash());
5871
5872 // No need to acquire cs_main since this chainstate isn't being used yet.
5873 FlushSnapshotToDisk(coins_cache, /*snapshot_loaded=*/false);
5874 }
5875 }
5876 }
5877 } catch (const std::ios_base::failure&) {
5878 return util::Error{Untranslated(strprintf("Bad snapshot format or truncated snapshot after deserializing %d coins",
5879 coins_processed))};
5880 }
5881 }
5882
5883 // Important that we set this. This and the coins_cache accesses above are
5884 // sort of a layer violation, but either we reach into the innards of
5885 // CCoinsViewCache here or we have to invert some of the Chainstate to
5886 // embed them in a snapshot-activation-specific CCoinsViewCache bulk load
5887 // method.
5888 coins_cache.SetBestBlock(base_blockhash);
5889
5890 bool out_of_coins{false};
5891 try {
5892 std::byte left_over_byte;
5893 coins_file >> left_over_byte;
5894 } catch (const std::ios_base::failure&) {
5895 // We expect an exception since we should be out of coins.
5896 out_of_coins = true;
5897 }
5898 if (!out_of_coins) {
5899 return util::Error{Untranslated(strprintf("Bad snapshot - coins left over after deserializing %d coins",
5900 coins_count))};
5901 }
5902
5903 LogInfo("[snapshot] loaded %d (%.2f MB) coins from snapshot %s",
5904 coins_count,
5905 coins_cache.DynamicMemoryUsage() / (1000 * 1000),
5906 base_blockhash.ToString());
5907
5908 // No need to acquire cs_main since this chainstate isn't being used yet.
5909 FlushSnapshotToDisk(coins_cache, /*snapshot_loaded=*/true);
5910
5911 assert(coins_cache.GetBestBlock() == base_blockhash);
5912
5913 // As above, okay to immediately release cs_main here since no other context knows
5914 // about the snapshot_chainstate.
5915 const CCoinsViewDB& snapshot_coinsdb = WITH_LOCK(::cs_main, return snapshot_chainstate.CoinsDB());
5916
5917 std::optional<CCoinsStats> maybe_stats;
5918
5919 try {
5920 maybe_stats = ComputeUTXOStats(
5921 CoinStatsHashType::HASH_SERIALIZED, snapshot_coinsdb, m_blockman, [&interrupt = m_interrupt] { SnapshotUTXOHashBreakpoint(interrupt); });
5922 } catch (StopHashingException const&) {
5923 return util::Error{Untranslated("Aborting after an interrupt was requested")};
5924 }
5925 if (!maybe_stats.has_value()) {
5926 return util::Error{Untranslated("Failed to generate coins stats")};
5927 }
5928
5929 // Assert that the deserialized chainstate contents match the expected assumeutxo value.
5930 if (AssumeutxoHash{maybe_stats->hashSerialized} != au_data.hash_serialized) {
5931 return util::Error{Untranslated(strprintf("Bad snapshot content hash: expected %s, got %s",
5932 au_data.hash_serialized.ToString(), maybe_stats->hashSerialized.ToString()))};
5933 }
5934
5935 snapshot_chainstate.m_chain.SetTip(*snapshot_start_block);
5936
5937 // The remainder of this function requires modifying data protected by cs_main.
5938 LOCK(::cs_main);
5939
5940 // Fake various pieces of CBlockIndex state:
5941 CBlockIndex* index = nullptr;
5942
5943 // Don't make any modifications to the genesis block since it shouldn't be
5944 // necessary, and since the genesis block doesn't have normal flags like
5945 // BLOCK_VALID_SCRIPTS set.
5946 constexpr int AFTER_GENESIS_START{1};
5947
5948 for (int i = AFTER_GENESIS_START; i <= snapshot_chainstate.m_chain.Height(); ++i) {
5949 index = snapshot_chainstate.m_chain[i];
5950
5951 // Fake BLOCK_OPT_WITNESS so that Chainstate::NeedsRedownload()
5952 // won't ask for -reindex on startup.
5954 index->nStatus |= BLOCK_OPT_WITNESS;
5955 }
5956
5957 m_blockman.m_dirty_blockindex.insert(index);
5958 // Changes to the block index will be flushed to disk after this call
5959 // returns in `ActivateSnapshot()`, when `MaybeRebalanceCaches()` is
5960 // called, since we've added a snapshot chainstate and therefore will
5961 // have to downsize the IBD chainstate, which will result in a call to
5962 // `FlushStateToDisk(FORCE_FLUSH)`.
5963 }
5964
5965 assert(index);
5966 assert(index == snapshot_start_block);
5967 index->m_chain_tx_count = au_data.m_chain_tx_count;
5968
5969 LogInfo("[snapshot] validated snapshot (%.2f MB)",
5970 coins_cache.DynamicMemoryUsage() / (1000 * 1000));
5971 return {};
5972}
5973
5974// Currently, this function holds cs_main for its duration, which could be for
5975// multiple minutes due to the ComputeUTXOStats call. Holding cs_main used to be
5976// necessary (before d43a1f1a2fa3) to avoid advancing validated_cs farther than
5977// its target block. Now it should be possible to avoid this, but simply
5978// releasing cs_main here would not be possible because this function is invoked
5979// by ConnectTip within ActivateBestChain.
5980//
5981// Eventually (TODO) it would be better to call this function outside of
5982// ActivateBestChain, on a separate thread that should not require cs_main to
5983// hash, because the UTXO set is only hashed after the historical chainstate
5984// reaches its target block and is no longer changing.
5985SnapshotCompletionResult ChainstateManager::MaybeValidateSnapshot(Chainstate& validated_cs, Chainstate& unvalidated_cs)
5986{
5988
5989 // If the snapshot does not need to be validated...
5990 if (unvalidated_cs.m_assumeutxo != Assumeutxo::UNVALIDATED ||
5991 // Or if either chainstate is unusable...
5992 !unvalidated_cs.m_from_snapshot_blockhash ||
5993 validated_cs.m_assumeutxo != Assumeutxo::VALIDATED ||
5994 !validated_cs.m_chain.Tip() ||
5995 // Or the validated chainstate is not targeting the snapshot block...
5996 !validated_cs.m_target_blockhash ||
5997 *validated_cs.m_target_blockhash != *unvalidated_cs.m_from_snapshot_blockhash ||
5998 // Or the validated chainstate has not reached the snapshot block yet...
5999 !validated_cs.ReachedTarget()) {
6000 // Then the snapshot cannot be validated and there is nothing to do.
6002 }
6003 assert(validated_cs.TargetBlock() == validated_cs.m_chain.Tip());
6004
6005 auto handle_invalid_snapshot = [&]() EXCLUSIVE_LOCKS_REQUIRED(::cs_main) {
6006 bilingual_str user_error = strprintf(_(
6007 "%s failed to validate the -assumeutxo snapshot state. "
6008 "This indicates a hardware problem, or a bug in the software, or a "
6009 "bad software modification that allowed an invalid snapshot to be "
6010 "loaded. As a result of this, the node will shut down and stop using any "
6011 "state that was built on the snapshot, resetting the chain height "
6012 "from %d to %d. On the next "
6013 "restart, the node will resume syncing from %d "
6014 "without using any snapshot data. "
6015 "Please report this incident to %s, including how you obtained the snapshot. "
6016 "The invalid snapshot chainstate will be left on disk in case it is "
6017 "helpful in diagnosing the issue that caused this error."),
6018 CLIENT_NAME, unvalidated_cs.m_chain.Height(),
6019 validated_cs.m_chain.Height(),
6020 validated_cs.m_chain.Height(), CLIENT_BUGREPORT);
6021
6022 LogError("[snapshot] !!! %s\n", user_error.original);
6023 LogError("[snapshot] deleting snapshot, reverting to validated chain, and stopping node\n");
6024
6025 // Reset chainstate target to network tip instead of snapshot block.
6026 validated_cs.SetTargetBlock(nullptr);
6027
6028 unvalidated_cs.m_assumeutxo = Assumeutxo::INVALID;
6029
6030 auto rename_result = unvalidated_cs.InvalidateCoinsDBOnDisk();
6031 if (!rename_result) {
6032 user_error += Untranslated("\n") + util::ErrorString(rename_result);
6033 }
6034
6035 GetNotifications().fatalError(user_error);
6036 };
6037
6038 CCoinsViewDB& validated_coins_db = validated_cs.CoinsDB();
6039 validated_cs.ForceFlushStateToDisk();
6040
6041 const auto& maybe_au_data = m_options.chainparams.AssumeutxoForHeight(validated_cs.m_chain.Height());
6042 if (!maybe_au_data) {
6043 LogWarning("[snapshot] assumeutxo data not found for height "
6044 "(%d) - refusing to validate snapshot", validated_cs.m_chain.Height());
6045 handle_invalid_snapshot();
6047 }
6048
6049 const AssumeutxoData& au_data = *maybe_au_data;
6050 std::optional<CCoinsStats> validated_cs_stats;
6051 LogInfo("[snapshot] computing UTXO stats for background chainstate to validate "
6052 "snapshot - this could take a few minutes");
6053 try {
6054 validated_cs_stats = ComputeUTXOStats(
6055 CoinStatsHashType::HASH_SERIALIZED,
6056 validated_coins_db,
6057 m_blockman,
6058 [&interrupt = m_interrupt] { SnapshotUTXOHashBreakpoint(interrupt); });
6059 } catch (StopHashingException const&) {
6061 }
6062
6063 // XXX note that this function is slow and will hold cs_main for potentially minutes.
6064 if (!validated_cs_stats) {
6065 LogWarning("[snapshot] failed to generate stats for validation coins db");
6066 // While this isn't a problem with the snapshot per se, this condition
6067 // prevents us from validating the snapshot, so we should shut down and let the
6068 // user handle the issue manually.
6069 handle_invalid_snapshot();
6071 }
6072
6073 // Compare the validated chainstate's UTXO set hash against the hard-coded
6074 // assumeutxo hash we expect.
6075 //
6076 // TODO: For belt-and-suspenders, we could cache the UTXO set
6077 // hash for the snapshot when it's loaded in its chainstate's leveldb. We could then
6078 // reference that here for an additional check.
6079 if (AssumeutxoHash{validated_cs_stats->hashSerialized} != au_data.hash_serialized) {
6080 LogWarning("[snapshot] hash mismatch: actual=%s, expected=%s",
6081 validated_cs_stats->hashSerialized.ToString(),
6082 au_data.hash_serialized.ToString());
6083 handle_invalid_snapshot();
6085 }
6086
6087 LogInfo("[snapshot] snapshot beginning at %s has been fully validated",
6088 unvalidated_cs.m_from_snapshot_blockhash->ToString());
6089
6090 unvalidated_cs.m_assumeutxo = Assumeutxo::VALIDATED;
6091 validated_cs.m_target_utxohash = AssumeutxoHash{validated_cs_stats->hashSerialized};
6092 this->MaybeRebalanceCaches();
6093
6095}
6096
6098{
6099 LOCK(::cs_main);
6100 return CurrentChainstate();
6101}
6102
6103void ChainstateManager::MaybeRebalanceCaches()
6104{
6106 Chainstate& current_cs{CurrentChainstate()};
6107 Chainstate* historical_cs{HistoricalChainstate()};
6108 if (!historical_cs && !current_cs.m_from_snapshot_blockhash) {
6109 // Allocate everything to the IBD chainstate. This will always happen
6110 // when we are not using a snapshot.
6111 current_cs.ResizeCoinsCaches(m_total_coinstip_cache, m_total_coinsdb_cache);
6112 } else if (!historical_cs) {
6113 // If background validation has completed and snapshot is our active chain...
6114 LogInfo("[snapshot] allocating all cache to the snapshot chainstate");
6115 // Allocate everything to the snapshot chainstate.
6116 current_cs.ResizeCoinsCaches(m_total_coinstip_cache, m_total_coinsdb_cache);
6117 } else {
6118 // If both chainstates exist, determine who needs more cache based on IBD status.
6119 //
6120 // Note: shrink caches first so that we don't inadvertently overwhelm available memory.
6121 if (IsInitialBlockDownload()) {
6122 historical_cs->ResizeCoinsCaches(
6124 current_cs.ResizeCoinsCaches(
6126 } else {
6127 current_cs.ResizeCoinsCaches(
6129 historical_cs->ResizeCoinsCaches(
6131 }
6132 }
6133}
6134
6135void ChainstateManager::ResetChainstates()
6136{
6137 m_chainstates.clear();
6138}
6139
6146{
6147 if (!opts.check_block_index.has_value()) opts.check_block_index = opts.chainparams.DefaultConsistencyChecks();
6148 if (!opts.minimum_chain_work.has_value()) opts.minimum_chain_work = UintToArith256(opts.chainparams.GetConsensus().nMinimumChainWork);
6149 if (!opts.assumed_valid_block.has_value()) opts.assumed_valid_block = opts.chainparams.GetConsensus().defaultAssumeValid;
6150 return std::move(opts);
6151}
6152
6154 : m_script_check_queue{/*batch_size=*/128, std::clamp(options.worker_threads_num, 0, MAX_SCRIPTCHECK_THREADS)},
6155 m_interrupt{interrupt},
6156 m_options{Flatten(std::move(options))},
6157 m_blockman{interrupt, std::move(blockman_options)},
6158 m_validation_cache{m_options.script_execution_cache_bytes, m_options.signature_cache_bytes}
6159{
6160}
6161
6163{
6164 LOCK(::cs_main);
6165
6167}
6168
6169Chainstate* ChainstateManager::LoadAssumeutxoChainstate()
6170{
6171 assert(!CurrentChainstate().m_from_snapshot_blockhash);
6172 std::optional<fs::path> path = node::FindAssumeutxoChainstateDir(m_options.datadir);
6173 if (!path) {
6174 return nullptr;
6175 }
6176 std::optional<uint256> base_blockhash = node::ReadSnapshotBaseBlockhash(*path);
6177 if (!base_blockhash) {
6178 return nullptr;
6179 }
6180 LogInfo("[snapshot] detected active snapshot chainstate (%s) - loading",
6181 fs::PathToString(*path));
6182
6183 auto snapshot_chainstate{std::make_unique<Chainstate>(nullptr, m_blockman, *this, base_blockhash)};
6184 LogInfo("[snapshot] switching active chainstate to %s", snapshot_chainstate->ToString());
6185 return &this->AddChainstate(std::move(snapshot_chainstate));
6186}
6187
6188Chainstate& ChainstateManager::AddChainstate(std::unique_ptr<Chainstate> chainstate)
6189{
6190 Chainstate& prev_chainstate{CurrentChainstate()};
6191 assert(prev_chainstate.m_assumeutxo == Assumeutxo::VALIDATED);
6192 // Set target block for historical chainstate to snapshot block.
6193 assert(!prev_chainstate.m_target_blockhash);
6194 prev_chainstate.SetTargetBlockHash(*Assert(chainstate->m_from_snapshot_blockhash));
6195 m_chainstates.push_back(std::move(chainstate));
6196 Chainstate& curr_chainstate{CurrentChainstate()};
6197 assert(&curr_chainstate == m_chainstates.back().get());
6198
6199 // Transfer possession of the mempool to the chainstate.
6200 // Mempool is empty at this point because we're still in IBD.
6201 assert(!prev_chainstate.m_mempool || prev_chainstate.m_mempool->size() == 0);
6202 assert(!curr_chainstate.m_mempool);
6203 std::swap(curr_chainstate.m_mempool, prev_chainstate.m_mempool);
6204 return curr_chainstate;
6205}
6206
6207bool IsBIP30Repeat(const CBlockIndex& block_index)
6208{
6209 return (block_index.nHeight==91842 && block_index.GetBlockHash() == uint256{"00000000000a4d0a398161ffc163c503763b1f4360639393e0e4c8e300e0caec"}) ||
6210 (block_index.nHeight==91880 && block_index.GetBlockHash() == uint256{"00000000000743f190a18c5577a3c2d2a1f610ae9601ac046a38084ccb7cd721"});
6211}
6212
6213bool IsBIP30Unspendable(const uint256& block_hash, int block_height)
6214{
6215 return (block_height==91722 && block_hash == uint256{"00000000000271a2dc26e7667f8419f2e15416dc6955e5a6c6cdf3f2574dd08e"}) ||
6216 (block_height==91812 && block_hash == uint256{"00000000000af0aed4792b1acee3d966af36cf5def14935db8de83d6f9306f2f"});
6217}
6218
6219util::Result<void> Chainstate::InvalidateCoinsDBOnDisk()
6220{
6221 // Should never be called on a non-snapshot chainstate.
6223
6224 // Coins views no longer usable.
6225 m_coins_views.reset();
6226
6227 const fs::path db_path{StoragePath()};
6228 const fs::path invalid_path{db_path + "_INVALID"};
6229 const std::string db_path_str{fs::PathToString(db_path)};
6230 const std::string invalid_path_str{fs::PathToString(invalid_path)};
6231 LogInfo("[snapshot] renaming snapshot datadir %s to %s", db_path_str, invalid_path_str);
6232
6233 // The invalid storage directory is simply moved and not deleted because we may
6234 // want to do forensics later during issue investigation. The user is instructed
6235 // accordingly in MaybeValidateSnapshot().
6236 try {
6237 fs::rename(db_path, invalid_path);
6238 } catch (const fs::filesystem_error& e) {
6239 LogError("While invalidating the coins db: Error renaming file '%s' -> '%s': %s",
6240 db_path_str, invalid_path_str, e.what());
6241 return util::Error{strprintf(_(
6242 "Rename of '%s' -> '%s' failed. "
6243 "You should resolve this by manually moving or deleting the invalid "
6244 "snapshot directory %s, otherwise you will encounter the same error again "
6245 "on the next startup."),
6246 db_path_str, invalid_path_str, db_path_str)};
6247 }
6248 return {};
6249}
6250
6251bool ChainstateManager::DeleteChainstate(Chainstate& chainstate)
6252{
6254 assert(!chainstate.m_coins_views);
6255 const fs::path db_path{chainstate.StoragePath()};
6256 if (!DeleteCoinsDBFromDisk(db_path, /*is_snapshot=*/bool{chainstate.m_from_snapshot_blockhash})) {
6257 LogError("Deletion of %s failed. Please remove it manually to continue reindexing.",
6258 fs::PathToString(db_path));
6259 return false;
6260 }
6261 std::unique_ptr<Chainstate> prev_chainstate{Assert(RemoveChainstate(chainstate))};
6262 Chainstate& curr_chainstate{CurrentChainstate()};
6263 assert(!prev_chainstate->m_mempool || prev_chainstate->m_mempool->size() == 0);
6264 assert(!curr_chainstate.m_mempool);
6265 std::swap(curr_chainstate.m_mempool, prev_chainstate->m_mempool);
6266 return true;
6267}
6268
6269ChainstateRole Chainstate::GetRole() const
6270{
6271 return ChainstateRole{.validated = m_assumeutxo == Assumeutxo::VALIDATED, .historical = bool{m_target_blockhash}};
6272}
6273
6274void ChainstateManager::RecalculateBestHeader()
6275{
6277 m_best_header = ActiveChain().Tip();
6278 for (auto& entry : m_blockman.m_block_index) {
6279 if (!(entry.second.nStatus & BLOCK_FAILED_VALID) && m_best_header->nChainWork < entry.second.nChainWork) {
6280 m_best_header = &entry.second;
6281 }
6282 }
6283}
6284
6285std::optional<int> ChainstateManager::BlocksAheadOfTip() const
6286{
6287 LOCK(::cs_main);
6288 const CBlockIndex* best_header{m_best_header};
6289 const CBlockIndex* tip{ActiveChain().Tip()};
6290 // Only consider headers that extend the active tip; ignore competing branches.
6291 if (best_header && tip && best_header->nChainWork > tip->nChainWork &&
6292 best_header->GetAncestor(tip->nHeight) == tip) {
6293 return best_header->nHeight - tip->nHeight;
6294 }
6295 return std::nullopt;
6296}
6297
6298bool ChainstateManager::ValidatedSnapshotCleanup(Chainstate& validated_cs, Chainstate& unvalidated_cs)
6299{
6301 if (unvalidated_cs.m_assumeutxo != Assumeutxo::VALIDATED) {
6302 // No need to clean up.
6303 return false;
6304 }
6305
6306 const fs::path validated_path{validated_cs.StoragePath()};
6307 const fs::path assumed_valid_path{unvalidated_cs.StoragePath()};
6308 const fs::path delete_path{validated_path + "_todelete"};
6309
6310 // Since we're going to be moving around the underlying leveldb filesystem content
6311 // for each chainstate, make sure that the chainstates (and their constituent
6312 // CoinsViews members) have been destructed first.
6313 //
6314 // The caller of this method will be responsible for reinitializing chainstates
6315 // if they want to continue operation.
6316 this->ResetChainstates();
6317 assert(this->m_chainstates.size() == 0);
6318
6319 LogInfo("[snapshot] deleting background chainstate directory (now unnecessary) (%s)",
6320 fs::PathToString(validated_path));
6321
6322 auto rename_failed_abort = [this](
6323 fs::path p_old,
6324 fs::path p_new,
6325 const fs::filesystem_error& err) {
6326 LogError("[snapshot] Error renaming path (%s) -> (%s): %s\n",
6327 fs::PathToString(p_old), fs::PathToString(p_new), err.what());
6329 "Rename of '%s' -> '%s' failed. "
6330 "Cannot clean up the background chainstate leveldb directory."),
6331 fs::PathToString(p_old), fs::PathToString(p_new)));
6332 };
6333
6334 try {
6335 fs::rename(validated_path, delete_path);
6336 } catch (const fs::filesystem_error& e) {
6337 rename_failed_abort(validated_path, delete_path, e);
6338 throw;
6339 }
6340
6341 LogInfo("[snapshot] moving snapshot chainstate (%s) to "
6342 "default chainstate directory (%s)",
6343 fs::PathToString(assumed_valid_path), fs::PathToString(validated_path));
6344
6345 try {
6346 fs::rename(assumed_valid_path, validated_path);
6347 } catch (const fs::filesystem_error& e) {
6348 rename_failed_abort(assumed_valid_path, validated_path, e);
6349 throw;
6350 }
6351
6352 if (!DeleteCoinsDBFromDisk(delete_path, /*is_snapshot=*/false)) {
6353 // No need to FatalError because once the unneeded bg chainstate data is
6354 // moved, it will not interfere with subsequent initialization.
6355 LogWarning("Deletion of %s failed. Please remove it manually, as the "
6356 "directory is now unnecessary.",
6357 fs::PathToString(delete_path));
6358 } else {
6359 LogInfo("[snapshot] deleted background chainstate directory (%s)",
6360 fs::PathToString(validated_path));
6361 }
6362 return true;
6363}
6364
6365std::pair<int, int> Chainstate::GetPruneRange(int last_height_can_prune) const
6366{
6367 if (m_chain.Height() <= 0) {
6368 return {0, 0};
6369 }
6370 int prune_start{0};
6371
6372 if (m_from_snapshot_blockhash && m_assumeutxo != Assumeutxo::VALIDATED) {
6373 // Only prune blocks _after_ the snapshot if this is a snapshot chain
6374 // that has not been fully validated yet. The earlier blocks need to be
6375 // kept to validate the snapshot
6376 prune_start = Assert(SnapshotBase())->nHeight + 1;
6377 }
6378
6379 int max_prune = std::max<int>(
6380 0, m_chain.Height() - static_cast<int>(MIN_BLOCKS_TO_KEEP));
6381
6382 // last block to prune is the lesser of (caller-specified height, MIN_BLOCKS_TO_KEEP from the tip)
6383 //
6384 // While you might be tempted to prune the background chainstate more
6385 // aggressively (i.e. fewer MIN_BLOCKS_TO_KEEP), this won't work with index
6386 // building - specifically blockfilterindex requires undo data, and if
6387 // we don't maintain this trailing window, we hit indexing failures.
6388 int prune_end = std::min(last_height_can_prune, max_prune);
6389
6390 return {prune_start, prune_end};
6391}
6392
6393std::optional<std::pair<const CBlockIndex*, const CBlockIndex*>> ChainstateManager::GetHistoricalBlockRange() const
6394{
6395 const Chainstate* chainstate{HistoricalChainstate()};
6396 if (!chainstate) return {};
6397 return std::make_pair(chainstate->m_chain.Tip(), chainstate->TargetBlock());
6398}
6399
6400util::Result<void> ChainstateManager::ActivateBestChains()
6401{
6402 // We can't hold cs_main during ActivateBestChain even though we're accessing
6403 // the chainman unique_ptrs since ABC requires us not to be holding cs_main, so retrieve
6404 // the relevant pointers before the ABC call.
6406 std::vector<Chainstate*> chainstates;
6407 {
6408 LOCK(GetMutex());
6409 chainstates.reserve(m_chainstates.size());
6410 for (const auto& chainstate : m_chainstates) {
6411 if (chainstate && chainstate->m_assumeutxo != Assumeutxo::INVALID && !chainstate->m_target_utxohash) {
6412 chainstates.push_back(chainstate.get());
6413 }
6414 }
6415 }
6416 for (Chainstate* chainstate : chainstates) {
6418 if (!chainstate->ActivateBestChain(state, nullptr)) {
6419 LOCK(GetMutex());
6420 return util::Error{Untranslated(strprintf("%s Failed to connect best block (%s)", chainstate->ToString(), state.ToString()))};
6421 }
6422 }
6423 return {};
6424}
bool MoneyRange(const CAmount &nValue)
Definition: amount.h:27
int64_t CAmount
Amount in satoshis (Can be negative)
Definition: amount.h:12
constexpr CAmount COIN
The amount of satoshis in one BTC.
Definition: amount.h:15
arith_uint256 UintToArith256(const uint256 &a)
int ret
int flags
Definition: bitcoin-tx.cpp:530
ArgsManager & args
Definition: bitcoind.cpp:280
void InvalidateBlock(ChainstateManager &chainman, const uint256 block_hash)
CBlockLocator GetLocator(const CBlockIndex *index)
Get a locator for a block index entry.
Definition: chain.cpp:45
int64_t GetBlockProofEquivalentTime(const CBlockIndex &to, const CBlockIndex &from, const CBlockIndex &tip, const Consensus::Params &params)
Return the time it would take to redo the work difference between from and to, assuming the current h...
Definition: chain.cpp:135
const CBlockIndex * LastCommonAncestor(const CBlockIndex *pa, const CBlockIndex *pb)
Find the last common ancestor two blocks have.
Definition: chain.cpp:154
@ BLOCK_VALID_CHAIN
Outputs do not overspend inputs, no double spends, coinbase output ok, no immature coinbase spends,...
Definition: chain.h:65
@ BLOCK_VALID_MASK
All validity bits.
Definition: chain.h:72
@ BLOCK_VALID_TRANSACTIONS
Only first tx is coinbase, 2 <= coinbase input script length <= 100, transactions valid,...
Definition: chain.h:61
@ BLOCK_VALID_SCRIPTS
Scripts & signatures ok.
Definition: chain.h:69
@ BLOCK_VALID_TREE
All parent headers found, difficulty matches, timestamp >= median previous.
Definition: chain.h:51
@ BLOCK_HAVE_UNDO
undo data available in rev*.dat
Definition: chain.h:76
@ BLOCK_HAVE_DATA
full block available in blk*.dat
Definition: chain.h:75
@ BLOCK_FAILED_VALID
stage after last reached validness failed
Definition: chain.h:79
@ BLOCK_OPT_WITNESS
block data in blk*.dat was received with a witness-enforcing client
Definition: chain.h:82
constexpr int32_t SEQ_ID_BEST_CHAIN_FROM_DISK
Init values for CBlockIndex nSequenceId when loaded from disk.
Definition: chain.h:39
arith_uint256 GetBlockProof(const CBlockIndex &block)
Compute how much work a block index entry corresponds to.
Definition: chain.h:305
constexpr int32_t SEQ_ID_INIT_FROM_DISK
Definition: chain.h:40
#define NONFATAL_UNREACHABLE()
NONFATAL_UNREACHABLE() is a macro that is used to mark unreachable code.
Definition: check.h:133
#define Assert(val)
Identity function.
Definition: check.h:116
#define STR_INTERNAL_BUG(msg)
Definition: check.h:99
#define Assume(val)
Assume is the identity function.
Definition: check.h:128
Non-refcounted RAII wrapper for FILE*.
Definition: streams.h:395
std::string ToString() const
Definition: hash_type.h:43
Wrapper around an AutoFile& that implements a ring buffer to deserialize from.
Definition: streams.h:505
Nodes collect new transactions into a block, hash them into a hash tree, and scan through nonce value...
Definition: block.h:27
NodeSeconds Time() const
Definition: block.h:61
uint32_t nBits
Definition: block.h:34
int64_t GetBlockTime() const
Definition: block.h:66
int32_t nVersion
Definition: block.h:30
uint256 hashPrevBlock
Definition: block.h:31
uint256 hashMerkleRoot
Definition: block.h:32
uint256 GetHash() const
Definition: block.cpp:14
Definition: block.h:74
bool m_checked_merkle_root
Definition: block.h:82
std::vector< CTransactionRef > vtx
Definition: block.h:77
bool m_checked_witness_commitment
Definition: block.h:81
bool fChecked
Definition: block.h:80
The block chain is a tree shaped structure starting with the genesis block at the root,...
Definition: chain.h:94
bool IsValid(enum BlockStatus nUpTo) const EXCLUSIVE_LOCKS_REQUIRED(
Check whether this block index entry is valid up to the passed validity level.
Definition: chain.h:250
CBlockIndex * pprev
pointer to the index of the predecessor of this block
Definition: chain.h:100
uint64_t m_chain_tx_count
(memory only) Number of transactions in the chain up to and including this block.
Definition: chain.h:129
arith_uint256 nChainWork
(memory only) Total amount of work (expected number of hashes) in the chain up to and including this ...
Definition: chain.h:118
bool HaveNumChainTxs() const
Check whether this block and all previous blocks back to the genesis block or an assumeutxo snapshot ...
Definition: chain.h:214
uint32_t nTime
Definition: chain.h:142
int32_t nSequenceId
(memory only) Sequential id assigned to distinguish order in which blocks are received.
Definition: chain.h:149
uint256 GetBlockHash() const
Definition: chain.h:198
int64_t GetBlockTime() const
Definition: chain.h:221
int64_t GetMedianTimePast() const
Definition: chain.h:233
FlatFilePos GetUndoPos() const EXCLUSIVE_LOCKS_REQUIRED(
Definition: chain.h:174
bool RaiseValidity(enum BlockStatus nUpTo) EXCLUSIVE_LOCKS_REQUIRED(
Raise the validity level of this block index entry.
Definition: chain.h:262
CBlockIndex * pskip
pointer to the index of some further predecessor of this block
Definition: chain.h:103
unsigned int nTx
Number of transactions in this block.
Definition: chain.h:123
int32_t nVersion
block header
Definition: chain.h:140
CBlockIndex * GetAncestor(int height)
Efficiently find an ancestor of this block.
Definition: chain.cpp:109
int nHeight
height of the entry in the chain. The genesis block has height 0
Definition: chain.h:106
const uint256 * phashBlock
pointer to the hash of the block, if any. Memory is owned by this CBlockIndex
Definition: chain.h:97
Undo information for a CBlock.
Definition: undo.h:64
std::vector< CTxUndo > vtxundo
Definition: undo.h:66
An in-memory indexed chain of blocks.
Definition: chain.h:380
bool Contains(const CBlockIndex &index) const
Efficiently check whether a block is present in this chain.
Definition: chain.h:410
CBlockIndex * Tip() const
Returns the index entry for the tip of this chain, or nullptr if none.
Definition: chain.h:396
const CBlockIndex * FindFork(const CBlockIndex &index) const
Find the last common block between this chain and a block index entry.
Definition: chain.cpp:50
void SetTip(CBlockIndex &block)
Set/initialize a chain with a given tip.
Definition: chain.cpp:16
CBlockIndex * Next(const CBlockIndex &index) const
Find the successor of a block in this chain, or nullptr if the given index is not found or is the tip...
Definition: chain.h:416
CBlockIndex * Genesis() const
Returns the index entry for the genesis block of this chain, or nullptr if none.
Definition: chain.h:390
int Height() const
Return the maximal height in the chain.
Definition: chain.h:425
CChainParams defines various tweakable parameters of a given instance of the Bitcoin system.
Definition: chainparams.h:77
const CBlock & GenesisBlock() const
Definition: chainparams.h:94
std::vector< int > GetAvailableSnapshotHeights() const
const ChainTxData & TxData() const
Definition: chainparams.h:128
std::optional< AssumeutxoData > AssumeutxoForHeight(int height) const
Definition: chainparams.h:119
CCoinsView that adds a memory cache for transactions to another CCoinsView.
Definition: coins.h:437
void Sync()
Push the modifications applied to this cache to its base while retaining the contents of this cache (...
Definition: coins.cpp:284
bool SpendCoin(const COutPoint &outpoint, Coin *moveto=nullptr)
Spend a coin.
Definition: coins.cpp:144
void Uncache(const COutPoint &outpoint)
Removes the UTXO with the given outpoint from the cache, if it is not modified.
Definition: coins.cpp:303
void EmplaceCoinInternalDANGER(const COutPoint &outpoint, Coin &&coin)
Emplace a coin into cacheCoins without performing any checks, marking the emplaced coin as dirty.
Definition: coins.cpp:123
void AddCoin(const COutPoint &outpoint, Coin &&coin, bool possible_overwrite)
Add a coin.
Definition: coins.cpp:80
virtual void Flush(bool reallocate_cache=true)
Push the modifications applied to this cache to its base and wipe local state.
Definition: coins.cpp:272
void SetBestBlock(const uint256 &block_hash)
Definition: coins.cpp:196
unsigned int GetCacheSize() const
Size of the cache (in number of transaction outputs)
Definition: coins.cpp:318
uint256 GetBestBlock() const override
Retrieve the block hash whose state this CCoinsView currently represents.
Definition: coins.cpp:190
bool HaveCoinInCache(const COutPoint &outpoint) const
Check if we have the given utxo already loaded in this cache.
Definition: coins.cpp:185
size_t DynamicMemoryUsage() const
Calculate the size of the cache (in bytes)
Definition: coins.cpp:50
bool HaveCoin(const COutPoint &outpoint) const override
Just check whether a given outpoint is unspent.
Definition: coins.cpp:179
const Coin & AccessCoin(const COutPoint &output) const
Return a reference to Coin in the cache, or coinEmpty if not found.
Definition: coins.cpp:170
CCoinsView backed by the coin database (chainstate/)
Definition: txdb.h:37
std::shared_future< void > CompactFullAsync() EXCLUSIVE_LOCKS_REQUIRED(cs_main
Perform a full compaction of the underlying LevelDB on a one-shot background thread.
Definition: txdb.cpp:198
void ResizeCache(size_t new_cache_size) EXCLUSIVE_LOCKS_REQUIRED(cs_main
Dynamically alter the underlying leveldb cache size.
Definition: txdb.cpp:73
Pure abstract view on the open txout dataset.
Definition: coins.h:356
virtual std::optional< Coin > GetCoin(const COutPoint &outpoint) const =0
Retrieve the Coin (unspent transaction output) for a given outpoint.
CCoinsView that brings transactions from a mempool into view.
Definition: txmempool.h:777
Fee rate in satoshis per virtualbyte: CAmount / vB the feerate is represented internally as FeeFrac.
Definition: feerate.h:32
A hasher class for Bitcoin's 256-bit hash (double SHA-256).
Definition: hash.h:32
void Finalize(std::span< unsigned char > output)
Definition: hash.h:38
CHash256 & Write(std::span< const unsigned char > input)
Definition: hash.h:45
An outpoint - a combination of a transaction hash and an index n into its vout.
Definition: transaction.h:29
uint32_t n
Definition: transaction.h:32
Txid hash
Definition: transaction.h:31
A hasher class for SHA-256.
Definition: sha256.h:14
void Finalize(unsigned char hash[OUTPUT_SIZE])
Definition: sha256.cpp:725
CSHA256 & Write(const unsigned char *data, size_t len)
Definition: sha256.cpp:699
Closure representing one script verification Note that this stores references to the spending transac...
Definition: validation.h:338
SignatureCache * m_signature_cache
Definition: validation.h:346
PrecomputedTransactionData * txdata
Definition: validation.h:345
CTxOut m_tx_out
Definition: validation.h:340
script_verify_flags m_flags
Definition: validation.h:343
bool cacheStore
Definition: validation.h:344
std::optional< std::pair< ScriptError, std::string > > operator()()
const CTransaction * ptxTo
Definition: validation.h:341
unsigned int nIn
Definition: validation.h:342
Serialized script, used inside transaction inputs and outputs.
Definition: script.h:406
The basic transaction that is broadcasted on the network and contained in blocks.
Definition: transaction.h:281
bool HasWitness() const
Definition: transaction.h:353
const std::vector< CTxOut > vout
Definition: transaction.h:292
const Wtxid & GetWitnessHash() const LIFETIMEBOUND
Definition: transaction.h:329
bool IsCoinBase() const
Definition: transaction.h:341
const Txid & GetHash() const LIFETIMEBOUND
Definition: transaction.h:328
const std::vector< CTxIn > vin
Definition: transaction.h:291
An input of a transaction.
Definition: transaction.h:62
COutPoint prevout
Definition: transaction.h:64
CTxMemPool::txiter TxHandle
Definition: txmempool.h:658
CTxMemPool stores valid-according-to-the-current-best-chain transactions that may be included in the ...
Definition: txmempool.h:187
void check(const CCoinsViewCache &active_coins_tip, int64_t spendheight) const EXCLUSIVE_LOCKS_REQUIRED(void removeRecursive(const CTransaction &tx, MemPoolRemovalReason reason) EXCLUSIVE_LOCKS_REQUIRED(cs)
If sanity-checking is turned on, check makes sure the pool is consistent (does not contain two transa...
Definition: txmempool.h:323
void UpdateTransactionsFromBlock(const std::vector< Txid > &vHashesToUpdate) EXCLUSIVE_LOCKS_REQUIRED(cs
UpdateTransactionsFromBlock is called when adding transactions from a disconnected block back to the ...
Definition: txmempool.cpp:91
void AddTransactionsUpdated(unsigned int n)
Definition: txmempool.cpp:201
CTransactionRef get(const Txid &hash) const
Return a mempool transaction with a given hash.
Definition: txmempool.cpp:660
size_t DynamicMemoryUsage() const
Definition: txmempool.cpp:826
const Options m_opts
Definition: txmempool.h:301
void removeForReorg(CChain &chain, std::function< bool(txiter)> filter_final_and_mature) EXCLUSIVE_LOCKS_REQUIRED(cs
After reorg, filter the entries that would no longer be valid in the next block, and update the entri...
Definition: txmempool.cpp:360
bool exists(const Txid &txid) const
Definition: txmempool.h:513
std::set< txiter, CompareIteratorByHash > setEntries
Definition: txmempool.h:266
indexed_transaction_set::nth_index< 0 >::type::const_iterator txiter
Definition: txmempool.h:263
std::vector< RemovedMempoolTransactionInfo > removeForBlock(const std::vector< CTransactionRef > &vtx) EXCLUSIVE_LOCKS_REQUIRED(cs)
Definition: txmempool.cpp:405
unsigned long size() const
Definition: txmempool.h:495
An output of a transaction.
Definition: transaction.h:140
CScript scriptPubKey
Definition: transaction.h:143
CAmount nValue
Definition: transaction.h:142
Undo information for a CTransaction.
Definition: undo.h:54
std::vector< Coin > vprevout
Definition: undo.h:57
VerifyDBResult VerifyDB(Chainstate &chainstate, const Consensus::Params &consensus_params, CCoinsView &coinsview, int nCheckLevel, int nCheckDepth) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
kernel::Notifications & m_notifications
Definition: validation.h:437
CVerifyDB(kernel::Notifications &notifications)
Chainstate stores and provides an API to update our local knowledge of the current best chain.
Definition: validation.h:550
void InitCoinsCache(size_t cache_size_bytes) EXCLUSIVE_LOCKS_REQUIRED(bool CanFlushToDisk() const EXCLUSIVE_LOCKS_REQUIRED(
Initialize the in-memory coins cache (to be done after the health of the on-disk database is verified...
Definition: validation.h:616
Mutex m_chainstate_mutex
The ChainState Mutex A lock that must be held when modifying this ChainState - held in ActivateBestCh...
Definition: validation.h:557
CChain m_chain
The current chain of blockheaders we consult and build on.
Definition: validation.h:624
CTxMemPool * GetMempool()
Definition: validation.h:700
bool RollforwardBlock(const CBlockIndex *pindex, CCoinsViewCache &inputs) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Apply the effects of a block on the utxo cache, ignoring that it may already have been applied.
size_t m_coinstip_cache_size_bytes
The cache size of the in-memory coins view.
Definition: validation.h:720
void UpdateTip(const CBlockIndex *pindexNew) EXCLUSIVE_LOCKS_REQUIRED(NodeClock::time_poin m_next_write)
Check warning conditions and do some notifications on new chain tip set.
Definition: validation.h:891
CCoinsViewCache & CoinsTip() EXCLUSIVE_LOCKS_REQUIRED(
Definition: validation.h:685
bool LoadChainTip() EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Update the chain tip based on database information, i.e.
size_t m_coinsdb_cache_size_bytes
The cache size of the on-disk coins view.
Definition: validation.h:717
bool PreciousBlock(BlockValidationState &state, CBlockIndex *pindex) LOCKS_EXCLUDED(bool InvalidateBlock(BlockValidationState &state, CBlockIndex *pindex) LOCKS_EXCLUDED(void SetBlockFailureFlags(CBlockIndex *pindex) EXCLUSIVE_LOCKS_REQUIRED(voi ResetBlockFailureFlags)(CBlockIndex *pindex) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Mark a block as precious and reorganize.
Definition: validation.h:804
void InvalidBlockFound(CBlockIndex *pindex, const BlockValidationState &state) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
bool ConnectTip(BlockValidationState &state, CBlockIndex *pindexNew, std::shared_ptr< const CBlock > block_to_connect, std::vector< ConnectedBlock > &connected_blocks, DisconnectedBlockTransactions &disconnectpool) EXCLUSIVE_LOCKS_REQUIRED(cs_main
Connect a new block to m_chain.
void CheckForkWarningConditions() EXCLUSIVE_LOCKS_REQUIRED(cs_main)
const CBlockIndex *SnapshotBase() const EXCLUSIVE_LOCKS_REQUIRED(const CBlockIndex *TargetBlock() const EXCLUSIVE_LOCKS_REQUIRED(void SetTargetBlock(CBlockIndex *block) EXCLUSIVE_LOCKS_REQUIRED(void SetTargetBlockHash(uint256 block_hash) EXCLUSIVE_LOCKS_REQUIRED(boo ReachedTarget)() const EXCLUSIVE_LOCKS_REQUIRED(
The base of the snapshot this chainstate was created from.
Definition: validation.h:668
kernel::ChainstateRole GetRole() const EXCLUSIVE_LOCKS_REQUIRED(void InitCoinsDB(size_t cache_size_bytes, bool in_memory, bool should_wipe)
Return the current role of the chainstate.
const std::optional< uint256 > m_from_snapshot_blockhash
The blockhash which is the base of the snapshot this chainstate was created from.
Definition: validation.h:636
bool ActivateBestChain(BlockValidationState &state, std::shared_ptr< const CBlock > pblock=nullptr) LOCKS_EXCLUDED(DisconnectResult DisconnectBlock(const CBlock &block, const CBlockIndex *pindex, CCoinsViewCache &view) EXCLUSIVE_LOCKS_REQUIRED(boo ConnectBlock)(const CBlock &block, BlockValidationState &state, CBlockIndex *pindex, CCoinsViewCache &view, bool fJustCheck=false) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Find the best known block, and make it the tip of the block chain.
Definition: validation.h:780
bool ActivateBestChainStep(BlockValidationState &state, CBlockIndex &index_most_work, const std::shared_ptr< const CBlock > &pblock, bool &fInvalidFound, std::vector< ConnectedBlock > &connected_blocks) EXCLUSIVE_LOCKS_REQUIRED(cs_main
Return the [start, end] (inclusive) of block heights we can prune.
CTxMemPool * m_mempool
Optional mempool that is kept in sync with the chain.
Definition: validation.h:561
CCoinsViewDB & CoinsDB() EXCLUSIVE_LOCKS_REQUIRED(
Definition: validation.h:693
bool DisconnectTip(BlockValidationState &state, DisconnectedBlockTransactions *disconnectpool) EXCLUSIVE_LOCKS_REQUIRED(cs_main
Disconnect m_chain's tip.
CBlockIndex * FindMostWorkChain() EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Return the tip of the chain with the most work in it, that isn't known to be invalid (it's however fa...
std::set< CBlockIndex *, node::CBlockIndexWorkComparator > setBlockIndexCandidates
The set of all CBlockIndex entries that have as much work as our current tip or more,...
Definition: validation.h:682
ChainstateManager & m_chainman
The chainstate manager that owns this chainstate.
Definition: validation.h:582
std::unique_ptr< CoinsViews > m_coins_views
Manages the UTXO set, which is a reflection of the contents of m_chain.
Definition: validation.h:564
bool m_mempool cs
Definition: validation.h:784
bool ReplayBlocks()
Replay blocks that aren't fully applied to the database.
void PruneBlockIndexCandidates()
Delete all entries in setBlockIndexCandidates that are worse than the current tip.
void TryAddBlockIndexCandidate(CBlockIndex *pindex) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Add a block to the candidate set if it has as much work as the current tip.
void PruneAndFlush()
Prune blockfiles from the disk if necessary and then flush chainstate changes if we pruned.
bool ResizeCoinsCaches(size_t coinstip_size, size_t coinsdb_size) EXCLUSIVE_LOCKS_REQUIRED(bool FlushStateToDisk(BlockValidationState &state, FlushStateMode mode, int nManualPruneHeight=0)
Resize the CoinsViews caches dynamically and flush state to disk.
node::BlockManager & m_blockman
Reference to a BlockManager instance which itself is shared across all Chainstate instances.
Definition: validation.h:577
void ForceFlushStateToDisk(bool wipe_cache=true)
Flush all changes to disk.
void MaybeUpdateMempoolForReorg(DisconnectedBlockTransactions &disconnectpool, bool fAddToMempool) EXCLUSIVE_LOCKS_REQUIRED(cs_main
Make mempool consistent after a reorg, by re-adding or recursively erasing disconnected block transac...
Definition: validation.cpp:303
void ClearBlockIndexCandidates() EXCLUSIVE_LOCKS_REQUIRED(void PopulateBlockIndexCandidates() EXCLUSIVE_LOCKS_REQUIRED(const CBlockIndex * FindForkInGlobalIndex(const CBlockLocator &locator) const EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Populate the candidate set by calling TryAddBlockIndexCandidate on all valid block indices.
Definition: validation.cpp:129
void InvalidChainFound(CBlockIndex *pindexNew) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Chainstate(CTxMemPool *mempool, node::BlockManager &blockman, ChainstateManager &chainman, std::optional< uint256 > from_snapshot_blockhash=std::nullopt)
RecursiveMutex * MempoolMutex() const LOCK_RETURNED(m_mempool -> cs)
Indirection necessary to make lock annotations work with an optional mempool.
Definition: validation.h:843
fs::path StoragePath() const
Return path to chainstate leveldb directory.
bool NeedsRedownload() const EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Whether the chain state needs to be redownloaded due to lack of witness data.
Interface for managing multiple Chainstate objects, where each chainstate is associated with chainsta...
Definition: validation.h:941
util::Result< void > PopulateAndValidateSnapshot(Chainstate &snapshot_chainstate, AutoFile &coins_file, const node::SnapshotMetadata &metadata)
Internal helper for ActivateSnapshot().
Chainstate * HistoricalChainstate() const EXCLUSIVE_LOCKS_REQUIRED(GetMutex())
Return historical chainstate targeting a specific block, if any.
Definition: validation.h:1132
const uint256 & AssumedValidBlock() const
Definition: validation.h:1012
ValidationCache m_validation_cache
Definition: validation.h:1041
double GetBackgroundVerificationProgress(const CBlockIndex &pindex) const EXCLUSIVE_LOCKS_REQUIRED(GetMutex())
Guess background verification progress in case assume-utxo was used (as a fraction between 0....
double GuessVerificationProgress(const CBlockIndex *pindex) const EXCLUSIVE_LOCKS_REQUIRED(GetMutex())
Guess verification progress (as a fraction between 0.0=genesis and 1.0=current tip).
bool IsInitialBlockDownload() const noexcept
Check whether we are doing an initial block download (synchronizing from disk or network)
size_t m_total_coinstip_cache
The total number of bytes available for us to use across all in-memory coins caches.
Definition: validation.h:1083
MempoolAcceptResult ProcessTransaction(const CTransactionRef &tx, bool test_accept=false) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Try to add a transaction to the memory pool.
std::unique_ptr< Chainstate > RemoveChainstate(Chainstate &chainstate) EXCLUSIVE_LOCKS_REQUIRED(GetMutex())
Remove a chainstate.
Definition: validation.h:1152
kernel::Notifications & GetNotifications() const
Definition: validation.h:1013
void ReceivedBlockTransactions(const CBlock &block, CBlockIndex *pindexNew, const FlatFilePos &pos) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Mark a block as having its data received and checked (up to BLOCK_VALID_TRANSACTIONS).
bool ShouldCheckBlockIndex() const
RecursiveMutex & GetMutex() const LOCK_RETURNED(
Alias for cs_main.
Definition: validation.h:1033
CBlockIndex * ActiveTip() const EXCLUSIVE_LOCKS_REQUIRED(GetMutex())
Definition: validation.h:1171
Chainstate & ActiveChainstate() const
Alternatives to CurrentChainstate() used by older code to query latest chainstate information without...
SnapshotCompletionResult MaybeValidateSnapshot(Chainstate &validated_cs, Chainstate &unvalidated_cs) EXCLUSIVE_LOCKS_REQUIRED(Chainstate & CurrentChainstate() const EXCLUSIVE_LOCKS_REQUIRED(GetMutex())
Try to validate an assumeutxo snapshot by using a validated historical chainstate targeted at the sna...
Definition: validation.h:1123
bool ProcessNewBlock(const std::shared_ptr< const CBlock > &block, bool force_processing, bool min_pow_checked, bool *new_block) LOCKS_EXCLUDED(cs_main)
Process an incoming block.
size_t m_total_coinsdb_cache
The total number of bytes available for us to use across all leveldb coins databases.
Definition: validation.h:1087
void CheckBlockIndex() const
Make various assertions about the state of the block index.
const util::SignalInterrupt & m_interrupt
Definition: validation.h:1035
void LoadExternalBlockFile(AutoFile &file_in, FlatFilePos *dbp=nullptr, std::multimap< uint256, FlatFilePos > *blocks_with_unknown_parent=nullptr)
Import blocks from an external file.
int ActiveHeight() const EXCLUSIVE_LOCKS_REQUIRED(GetMutex())
Definition: validation.h:1170
VersionBitsCache m_versionbitscache
Track versionbit status.
Definition: validation.h:1196
std::function< void()> snapshot_download_completed
Function to restart active indexes; set dynamically to avoid a circular dependency on base/index....
Definition: validation.h:1006
const CChainParams & GetParams() const
Definition: validation.h:1008
void GenerateCoinbaseCommitment(CBlock &block, const CBlockIndex *pindexPrev) const
Produce the necessary coinbase commitment for a block (modifies the hash, don't call for mined blocks...
bool ProcessNewBlockHeaders(std::span< const CBlockHeader > headers, bool min_pow_checked, BlockValidationState &state, const CBlockIndex **ppindex=nullptr) LOCKS_EXCLUDED(cs_main)
Process incoming block headers.
const Consensus::Params & GetConsensus() const
Definition: validation.h:1009
ChainstateManager(const util::SignalInterrupt &interrupt, Options options, node::BlockManager::Options blockman_options)
const arith_uint256 & MinimumChainWork() const
Definition: validation.h:1011
void UpdateIBDStatus() EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Update and possibly latch the IBD status.
bool LoadGenesisBlock()
Ensures a genesis block is in the block tree, possibly writing one to disk.
const Options m_options
Definition: validation.h:1036
bool LoadBlockIndex() EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Load the block tree and coins database from disk, initializing state if we're running with -reindex.
Chainstate &InitializeChainstate(CTxMemPool *mempool) EXCLUSIVE_LOCKS_REQUIRED(util::Result< CBlockIndex * ActivateSnapshot)(AutoFile &coins_file, const node::SnapshotMetadata &metadata, bool in_memory)
Instantiate a new chainstate.
Definition: validation.h:1109
CChain & ActiveChain() const EXCLUSIVE_LOCKS_REQUIRED(GetMutex())
Definition: validation.h:1169
bool AcceptBlockHeader(const CBlockHeader &block, BlockValidationState &state, CBlockIndex **ppindex, bool min_pow_checked) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
If a block header hasn't already been seen, call CheckBlockHeader on it, ensure that it doesn't desce...
arith_uint256 nLastPreciousChainwork
chainwork for the last block that preciousblock has been applied to.
Definition: validation.h:1063
void ReportHeadersPresync(int64_t height, int64_t timestamp)
This is used by net_processing to report pre-synchronization progress of headers, as headers are not ...
std::atomic_bool m_cached_is_ibd
Whether initial block download (IBD) is ongoing.
Definition: validation.h:1050
bool NotifyHeaderTip() LOCKS_EXCLUDED(GetMutex())
void MaybeRebalanceCaches() EXCLUSIVE_LOCKS_REQUIRED(void UpdateUncommittedBlockStructures(CBlock &block, const CBlockIndex *pindexPrev) const
Check to see if caches are out of balance and if so, call ResizeCoinsCaches() as needed.
Chainstate *LoadAssumeutxoChainstate() EXCLUSIVE_LOCKS_REQUIRED(Chainstate &AddChainstate(std::unique_ptr< Chainstate > chainstate) EXCLUSIVE_LOCKS_REQUIRED(void ResetChainstates() EXCLUSIVE_LOCKS_REQUIRED(bool DeleteChainstate(Chainstate &chainstate) EXCLUSIVE_LOCKS_REQUIRED(bool ValidatedSnapshotCleanup(Chainstate &validated_cs, Chainstate &unvalidated_cs) EXCLUSIVE_LOCKS_REQUIRED(std::optional< std::pair< const CBlockIndex *, const CBlockIndex * > > GetHistoricalBlockRange() const EXCLUSIVE_LOCKS_REQUIRED(util::Result< void > ActivateBestChains() LOCKS_EXCLUDED(void RecalculateBestHeader() EXCLUSIVE_LOCKS_REQUIRED(std::optional< int > BlocksAheadOfTip() const LOCKS_EXCLUDED(CCheckQueue< CScriptCheck > & GetCheckQueue()
When starting up, search the datadir for a chainstate based on a UTXO snapshot that is in the process...
Definition: validation.h:1376
int32_t nBlockReverseSequenceId
Decreasing counter (used by subsequent preciousblock calls).
Definition: validation.h:1061
node::BlockManager m_blockman
A single BlockManager instance is shared across each constructed chainstate to avoid duplicating bloc...
Definition: validation.h:1039
bool AcceptBlock(const std::shared_ptr< const CBlock > &pblock, BlockValidationState &state, CBlockIndex **ppindex, bool fRequested, const FlatFilePos *dbp, bool *fNewBlock, bool min_pow_checked) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Sufficiently validate a block for disk storage (and store on disk).
A UTXO entry.
Definition: coins.h:46
bool IsCoinBase() const
Definition: coins.h:70
CTxOut out
unspent transaction output
Definition: coins.h:49
bool IsSpent() const
Either this coin never existed (see e.g.
Definition: coins.h:94
bool fCoinBase
whether containing transaction was a coinbase
Definition: coins.h:52
uint32_t nHeight
at which height this containing transaction was included in the active block chain
Definition: coins.h:55
Noop coins view.
Definition: coins.h:392
static CoinsViewEmpty & Get()
Definition: coins.cpp:29
CCoinsViewCache subclass that asynchronously fetches most block input prevouts in parallel during Con...
Definition: coins.h:653
CoinsViews(DBParams db_params, CoinsViewOptions options)
This constructor initializes CCoinsViewDB and CCoinsViewErrorCatcher instances, but it does not creat...
std::pair< uint32_t, size_t > setup_bytes(size_t bytes)
setup_bytes is a convenience function which accounts for internal memory usage when deciding how many...
Definition: cuckoocache.h:365
void insert(Element e)
insert loops at most depth_limit times trying to insert a hash at various locations in the table via ...
Definition: cuckoocache.h:398
bool contains(const Element &e, const bool erase) const
contains iterates through the hash locations for a given element and checks to see if it is present.
Definition: cuckoocache.h:475
DisconnectedBlockTransactions.
std::list< CTransactionRef > take()
Clear all data structures and return the list of transactions.
void removeForBlock(const std::vector< CTransactionRef > &vtx)
Remove any entries that are in this block.
std::vector< CTransactionRef > AddTransactionsFromBlock(const std::vector< CTransactionRef > &vtx)
Add transactions from the block, iterating through vtx in reverse order.
Fast randomness source.
Definition: random.h:386
Tp rand_uniform_delay(const Tp &time, typename Tp::duration range) noexcept
Return the time point advanced by a uniform random duration.
Definition: random.h:329
I randrange(I range) noexcept
Generate a random integer in the range [0..range), with range > 0.
Definition: random.h:254
Convenience class for initializing and passing the script execution cache and signature cache.
Definition: validation.h:370
ValidationCache(size_t script_execution_cache_bytes, size_t signature_cache_bytes)
CuckooCache::cache< uint256, SignatureCacheHasher > m_script_execution_cache
Definition: validation.h:376
CSHA256 ScriptExecutionCacheHasher() const
Return a copy of the pre-initialized hasher.
Definition: validation.h:385
CSHA256 m_script_execution_cache_hasher
Pre-initialized hasher to avoid having to recreate it for every hash calculation.
Definition: validation.h:373
SignatureCache m_signature_cache
Definition: validation.h:377
void BlockConnected(const kernel::ChainstateRole &, std::shared_ptr< const CBlock >, const CBlockIndex *pindex)
void BlockChecked(const std::shared_ptr< const CBlock > &, const BlockValidationState &)
void ChainStateFlushed(const kernel::ChainstateRole &, const CBlockLocator &)
void NewPoWValidBlock(const CBlockIndex *, const std::shared_ptr< const CBlock > &)
void UpdatedBlockTip(const CBlockIndex *, const CBlockIndex *, bool fInitialDownload)
void ActiveTipChange(const CBlockIndex &, bool)
void MempoolTransactionsRemovedForBlock(std::shared_ptr< const CBlock >, std::vector< RemovedMempoolTransactionInfo >, unsigned int block_height)
void BlockDisconnected(std::shared_ptr< const CBlock >, const CBlockIndex *pindex)
bool IsValid() const
Definition: validation.h:113
std::string GetRejectReason() const
Definition: validation.h:117
std::string GetDebugMessage() const
Definition: validation.h:118
bool Error(const std::string &reject_reason)
Definition: validation.h:106
bool Invalid(Result result, const std::string &reject_reason="", const std::string &debug_message="")
Definition: validation.h:96
bool IsError() const
Definition: validation.h:115
Result GetResult() const
Definition: validation.h:116
std::string ToString() const
Definition: validation.h:119
bool IsInvalid() const
Definition: validation.h:114
std::vector< std::pair< int, bool > > CheckUnknownActivations(const CBlockIndex *pindex, const CChainParams &chainparams) EXCLUSIVE_LOCKS_REQUIRED(!m_mutex)
Check for unknown activations Returns a vector containing the bit number used for signalling and a bo...
void Clear() EXCLUSIVE_LOCKS_REQUIRED(!m_mutex)
256-bit unsigned big integer.
constexpr bool IsNull() const
Definition: uint256.h:50
std::string ToString() const
Definition: uint256.cpp:21
constexpr unsigned char * begin()
Definition: uint256.h:101
double getdouble() const
A base class defining functions for notifying about certain kernel events.
virtual void headerTip(SynchronizationState state, int64_t height, int64_t timestamp, bool presync)
virtual void fatalError(const bilingual_str &message)
The fatal error notification is sent to notify the user when an error occurs in kernel code that can'...
virtual void warningSet(Warning id, const bilingual_str &message)
virtual void progress(const bilingual_str &title, int progress_percent, bool resume_possible)
virtual InterruptResult blockTip(SynchronizationState state, const CBlockIndex &index, double verification_progress)
virtual void warningUnset(Warning id)
Maintains a tree of blocks (stored in m_block_index) which is consulted to determine where the most-w...
Definition: blockstorage.h:196
const kernel::BlockManagerOpts m_opts
Definition: blockstorage.h:304
void FindFilesToPrune(std::set< int > &setFilesToPrune, int last_prune, const Chainstate &chain, ChainstateManager &chainman)
Prune block and undo files (blk???.dat and rev???.dat) so that the disk space used is less than a use...
CBlockIndex * LookupBlockIndex(const uint256 &hash) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
bool ReadBlockUndo(CBlockUndo &blockundo, const CBlockIndex &index) const
CBlockFileInfo *GetBlockFileInfo(size_t n) EXCLUSIVE_LOCKS_REQUIRED(bool WriteBlockUndo(const CBlockUndo &blockundo, BlockValidationState &state, CBlockIndex &block) EXCLUSIVE_LOCKS_REQUIRED(FlatFilePos WriteBlock(const CBlock &block, int nHeight) EXCLUSIVE_LOCKS_REQUIRED(void UpdateBlockInfo(const CBlock &block, unsigned int nHeight, const FlatFilePos &pos) EXCLUSIVE_LOCKS_REQUIRED(bool IsPruneMode() const
Get block file info entry for one block file.
Definition: blockstorage.h:407
std::atomic_bool m_blockfiles_indexed
Whether all blockfiles have been added to the block tree database.
Definition: blockstorage.h:333
std::vector< CBlockIndex * > GetAllBlockIndices() EXCLUSIVE_LOCKS_REQUIRED(std::multimap< CBlockIndex *, CBlockIndex * > m_blocks_unlinked
All pairs A->B, where A (or one of its ancestors) misses transactions, but B has transactions.
Definition: blockstorage.h:351
std::set< CBlockIndex * > m_dirty_blockindex
Dirty block index entries.
Definition: blockstorage.h:313
bool LoadingBlocks() const
Definition: blockstorage.h:413
void UnlinkPrunedFiles(const std::set< int > &setFilesToPrune) const
Actually unlink the specified files.
void WriteBlockIndexDB() EXCLUSIVE_LOCKS_REQUIRED(bool LoadBlockIndexDB(const std::optional< uint256 > &snapshot_blockhash) EXCLUSIVE_LOCKS_REQUIRED(void ScanAndUnlinkAlreadyPrunedFiles() EXCLUSIVE_LOCKS_REQUIRED(CBlockIndex * AddToBlockIndex(const CBlockHeader &block, CBlockIndex *&best_header) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Remove any pruned block & undo files that are still on disk.
Definition: blockstorage.h:372
void AddUnlinkedBlock(CBlockIndex *block) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
bool ReadBlock(CBlock &block, const FlatFilePos &pos, const std::optional< uint256 > &expected_hash) const
Functions for disk access for blocks.
bool m_check_for_pruning
Global flag to indicate we should check to see if there are block/undo files that should be deleted.
Definition: blockstorage.h:288
void FindFilesToPruneManual(std::set< int > &setFilesToPrune, int nManualPruneHeight, const Chainstate &chain)
std::optional< int > m_snapshot_height
The height of the base block of an assumeutxo snapshot, if one is in use.
Definition: blockstorage.h:349
uint64_t CalculateCurrentUsage() EXCLUSIVE_LOCKS_REQUIRED(bool CheckBlockDataAvailability(const CBlockIndex &upper_block, const CBlockIndex &lower_block, BlockStatus block_status=BLOCK_HAVE_DATA) EXCLUSIVE_LOCKS_REQUIRED(const CBlockIndex &GetFirstBlock(const CBlockIndex &upper_block LIFETIMEBOUND, uint32_t status_mask, const CBlockIndex *lower_block LIFETIMEBOUND=nullptr) const EXCLUSIVE_LOCKS_REQUIRED(boo m_have_pruned)
Calculate the amount of disk space the block & undo files currently use.
Definition: blockstorage.h:453
Metadata describing a serialized version of a UTXO set from which an assumeutxo Chainstate can be con...
Definition: utxo_snapshot.h:38
uint256 m_base_blockhash
The hash of the block that reflects the tip of the chain for the UTXO set contained in this snapshot.
Definition: utxo_snapshot.h:45
uint64_t m_coins_count
The number of coins in the UTXO set contained in this snapshot.
Definition: utxo_snapshot.h:50
std::string ToString() const
constexpr const std::byte * begin() const
const uint256 & ToUint256() const LIFETIMEBOUND
std::string GetHex() const
256-bit opaque blob.
Definition: uint256.h:196
Helper class that manages an interrupt flag, and allows a thread or signal to interrupt another threa...
std::string FormatFullVersion()
const Coin & AccessByTxid(const CCoinsViewCache &view, const Txid &txid)
Utility function to find any unspent output with a given txid.
Definition: coins.cpp:417
void AddCoins(CCoinsViewCache &cache, const CTransaction &tx, int nHeight, bool check_for_overwrite)
Utility function to add all of a transaction's outputs to a cache.
Definition: coins.cpp:133
static const PrecomputedData data
Precomputed COutPoint and CCoins values.
auto flush
Flush changes in top cache to the one below.
uint256 BlockMerkleRoot(const CBlock &block, bool *mutated)
Definition: merkle.cpp:77
uint256 BlockWitnessMerkleRoot(const CBlock &block)
Definition: merkle.cpp:87
constexpr int NO_WITNESS_COMMITMENT
Index marker for when no witness commitment is present in a coinbase transaction.
Definition: validation.h:23
constexpr size_t MINIMUM_WITNESS_COMMITMENT
Minimum size of a witness commitment structure.
Definition: validation.h:26
static int64_t GetBlockWeight(const CBlock &block)
Definition: validation.h:144
@ BLOCK_HEADER_LOW_WORK
the block header may be on a too-little-work chain
@ BLOCK_INVALID_HEADER
invalid proof of work or time too old
@ BLOCK_CACHED_INVALID
this block was cached as being invalid and we didn't store the reason why
@ BLOCK_CONSENSUS
invalid by consensus rules (excluding any below reasons)
@ BLOCK_MISSING_PREV
We don't have the previous block the checked one is built on.
@ BLOCK_INVALID_PREV
A block this one builds on is invalid.
@ BLOCK_MUTATED
the block's data didn't match the data committed to by the PoW
@ BLOCK_TIME_FUTURE
block timestamp was > 2 hours in the future (or our clock is bad)
int GetWitnessCommitmentIndex(const CBlock &block)
Compute at which vout of the block's coinbase transaction the witness commitment occurs,...
Definition: validation.h:155
@ TX_MISSING_INPUTS
transaction was missing some of its inputs
@ TX_MEMPOOL_POLICY
violated mempool's fee/size/descendant/RBF/etc limits
@ TX_PREMATURE_SPEND
transaction spends a coinbase too early, or violates locktime/sequence locks
@ TX_WITNESS_STRIPPED
Transaction is missing a witness.
@ TX_CONFLICT
Tx already in mempool or conflicts with a tx in the chain (if it conflicts with another tx in mempool...
@ TX_NOT_STANDARD
otherwise didn't meet our local policy rules
@ TX_WITNESS_MUTATED
Transaction might have a witness prior to SegWit activation, or witness may have been malleated (whic...
@ TX_NO_MEMPOOL
this node does not have a mempool so can't validate the transaction
@ TX_CONSENSUS
invalid by consensus rules
@ TX_RECONSIDERABLE
fails some policy, but might be acceptable if submitted in a (different) package
constexpr unsigned int LOCKTIME_VERIFY_SEQUENCE
Flags for nSequence and nLockTime locks.
Definition: consensus.h:28
constexpr int64_t MAX_BLOCK_SIGOPS_COST
The maximum allowed number of signature check operations in a block (network rule)
Definition: consensus.h:17
constexpr int64_t MAX_TIMEWARP
Maximum number of seconds that the timestamp of the first block of a difficulty adjustment period is ...
Definition: consensus.h:35
constexpr unsigned int MAX_BLOCK_SERIALIZED_SIZE
The maximum allowed size for a serialized block, in bytes (only for buffer size limits)
Definition: consensus.h:13
constexpr int COINBASE_MATURITY
Coinbase transaction outputs can only be spent after this number of new blocks (network rule)
Definition: consensus.h:19
constexpr unsigned int MAX_BLOCK_WEIGHT
The maximum allowed weight for a block, see BIP 141 (network rule)
Definition: consensus.h:15
constexpr int WITNESS_SCALE_FACTOR
Definition: consensus.h:21
RecursiveMutex cs_main
Mutex to guard access to validation specific variables, such as reading or changing the chainstate.
Definition: cs_main.cpp:8
bool DestroyDB(const std::string &path_str)
Definition: dbwrapper.cpp:39
bool DeploymentActiveAfter(const CBlockIndex *pindexPrev, const Consensus::Params &params, Consensus::BuriedDeployment dep, VersionBitsCache &versionbitscache)
Determine if a deployment is active for the next block.
bool DeploymentActiveAt(const CBlockIndex &index, const Consensus::Params &params, Consensus::BuriedDeployment dep, VersionBitsCache &versionbitscache)
Determine if a deployment is active for this block.
constexpr unsigned int MAX_DISCONNECTED_TX_POOL_BYTES
Maximum bytes for transactions to store for processing during reorg.
bool CheckEphemeralSpends(const Package &package, CFeeRate dust_relay_rate, const CTxMemPool &tx_pool, TxValidationState &out_child_state, Wtxid &out_child_wtxid)
Called for each transaction(package) if any dust is in the package.
bool PreCheckEphemeralTx(const CTransaction &tx, CFeeRate dust_relay_rate, CAmount base_fee, CAmount mod_fee, TxValidationState &state)
These utility functions ensure that ephemeral dust is safely created and spent without unduly risking...
volatile double sum
Definition: examples.cpp:10
static bool exists(const path &p)
Definition: fs.h:96
static std::string PathToString(const path &path)
Convert path object to a byte string.
Definition: fs.h:162
bool CheckDiskSpace(const fs::path &dir, uint64_t additional_bytes)
Definition: fs_helpers.cpp:93
HTTPHeaders headers
bool VerifyScript(const CScript &scriptSig, const CScript &scriptPubKey, const CScriptWitness *witness, script_verify_flags flags, const BaseSignatureChecker &checker, ScriptError *serror)
is a home for simple enum and struct type definitions that can be used internally by functions in the...
#define LogWarning(...)
Definition: log.h:126
#define LogInfo(...)
Definition: log.h:125
#define LogError(...)
Definition: log.h:127
#define LogDebug(category,...)
Definition: log.h:143
unsigned int nHeight
LockPoints lp
@ REORG
Removed for reorganization.
std::array< uint8_t, 4 > MessageStartChars
BlockValidationState m_state
Definition: miner.cpp:373
uint256 m_hash
Definition: miner.cpp:371
unsigned int nonce
@ COINDB
Definition: categories.h:33
@ REINDEX
Definition: categories.h:27
@ TXPACKAGES
Definition: categories.h:45
@ ALL
Definition: categories.h:48
@ VALIDATION
Definition: categories.h:36
@ PRUNE
Definition: categories.h:30
@ MEMPOOL
Definition: categories.h:18
@ BENCH
Definition: categories.h:20
bool CheckTxInputs(const CTransaction &tx, TxValidationState &state, const CCoinsViewCache &inputs, int nSpendHeight, CAmount &txfee)
Check whether all inputs of this transaction are valid (no double spends and amounts) This does not m...
Definition: tx_verify.cpp:170
@ DEPLOYMENT_DERSIG
Definition: params.h:30
@ DEPLOYMENT_CSV
Definition: params.h:31
@ DEPLOYMENT_SEGWIT
Definition: params.h:34
@ DEPLOYMENT_HEIGHTINCB
Definition: params.h:28
@ DEPLOYMENT_CLTV
Definition: params.h:29
T check(T ptr)
std::function< FILE *(const fs::path &, const char *)> FopenFn
Definition: fs.h:197
Definition: basic.cpp:11
static std::optional< CCoinsStats > ComputeUTXOStats(T hash_obj, const CCoinsViewDB &view, node::BlockManager &blockman, const std::function< void()> &interruption_point)
Calculate statistics about the unspent transaction output set.
Definition: coinstats.cpp:112
bool IsInterrupted(const T &result)
CoinStatsHashType
Definition: coinstats.h:26
const fs::path SNAPSHOT_BLOCKHASH_FILENAME
The file in the snapshot chainstate dir which stores the base blockhash.
bool WriteSnapshotBaseBlockhash(Chainstate &snapshot_chainstate)
std::optional< fs::path > FindAssumeutxoChainstateDir(const fs::path &data_dir)
Return a path to the snapshot-based chainstate dir, if one exists.
bool WriteSnapshotBaseBlockhash(Chainstate &snapshot_chainstate) EXCLUSIVE_LOCKS_REQUIRED(std::optional< uint256 > ReadSnapshotBaseBlockhash(fs::path chaindir) EXCLUSIVE_LOCKS_REQUIRED(constexpr std::string_view SNAPSHOT_CHAINSTATE_SUFFIX
Write out the blockhash of the snapshot base block that was used to construct this chainstate.
std::unordered_map< uint256, CBlockIndex, BlockHasher > BlockMap
Definition: blockstorage.h:138
std::optional< uint256 > ReadSnapshotBaseBlockhash(fs::path chaindir)
constexpr NoRateLimitTag NO_RATE_LIMIT
Definition: log.h:50
bilingual_str ErrorString(const Result< T > &result)
Definition: result.h:93
std::string ToString(const T &t)
Locale-independent version of std::to_string.
Definition: string.h:250
auto Join(const C &container, const S &separator, UnaryOp unary_op)
Join all container items.
Definition: string.h:209
static feebumper::Result CheckFeeRate(const CWallet &wallet, const CMutableTransaction &mtx, const CFeeRate &newFeerate, const int64_t maxTxSize, CAmount old_fee, std::vector< bilingual_str > &errors)
Check if the user provided a valid feeRate.
Definition: feebumper.cpp:61
std::shared_ptr< Chain::Notifications > m_notifications
Definition: interfaces.cpp:498
bool IsChildWithParents(const Package &package)
Context-free check that a package is exactly one child and its parents; not all parents need to be pr...
Definition: packages.cpp:119
bool IsWellFormedPackage(const Package &txns, PackageValidationState &state)
Context-free package policy checks:
Definition: packages.cpp:79
uint256 GetPackageHash(const std::vector< CTransactionRef > &transactions)
Get the hash of the concatenated wtxids of transactions, with wtxids treated as a little-endian numbe...
Definition: packages.cpp:151
std::vector< CTransactionRef > Package
A package is an ordered list of transactions.
Definition: packages.h:45
@ PCKG_POLICY
The package itself is invalid (e.g. too many transactions).
@ PCKG_MEMPOOL_ERROR
Mempool logic error.
@ PCKG_TX
At least one tx is invalid.
std::optional< std::pair< DiagramCheckError, std::string > > ImprovesFeerateDiagram(CTxMemPool::ChangeSet &changeset)
The replacement transaction must improve the feerate diagram of the mempool.
Definition: rbf.cpp:127
std::optional< std::string > PaysForRBF(CAmount original_fees, CAmount replacement_fees, size_t replacement_vsize, CFeeRate relay_fee, const Txid &txid)
The replacement transaction must pay more fees than the original transactions.
Definition: rbf.cpp:100
std::optional< std::string > EntriesAndTxidsDisjoint(const CTxMemPool::setEntries &ancestors, const std::set< Txid > &direct_conflicts, const Txid &txid)
Check the intersection between two sets of transactions (a set of mempool entries and a set of txids)...
Definition: rbf.cpp:85
std::optional< std::string > GetEntriesForConflicts(const CTransaction &tx, CTxMemPool &pool, const CTxMemPool::setEntries &iters_conflicting, CTxMemPool::setEntries &all_conflicts)
Get all descendants of iters_conflicting.
Definition: rbf.cpp:58
@ FAILURE
New diagram wasn't strictly superior
TxValidationState ValidateInputsStandardness(const CTransaction &tx, const CCoinsViewCache &mapInputs)
Check transaction inputs.
Definition: policy.cpp:214
bool SpendsNonAnchorWitnessProg(const CTransaction &tx, const CCoinsViewCache &prevouts)
Check whether this transaction spends any witness program but P2A, including not-yet-defined ones.
Definition: policy.cpp:354
bool IsWitnessStandard(const CTransaction &tx, const CCoinsViewCache &mapInputs)
Check if the transaction is over standard P2WSH resources limit: 3600bytes witnessScript size,...
Definition: policy.cpp:265
bool IsStandardTx(const CTransaction &tx, const std::optional< unsigned > &max_datacarrier_bytes, bool permit_bare_multisig, const CFeeRate &dust_relay_fee, std::string &reason)
Check for standard transaction types.
Definition: policy.cpp:100
constexpr script_verify_flags STANDARD_SCRIPT_VERIFY_FLAGS
Standard script verification flags that standard transactions will comply with.
Definition: policy.h:118
constexpr unsigned int STANDARD_LOCKTIME_VERIFY_FLAGS
Used as the flags parameter to sequence and nLocktime checks in non-consensus code.
Definition: policy.h:137
constexpr unsigned int MAX_STANDARD_TX_SIGOPS_COST
The maximum number of sigops we're willing to relay/mine in a single tx.
Definition: policy.h:44
constexpr unsigned int MIN_STANDARD_TX_NONWITNESS_SIZE
The minimum non-witness size for transactions we're willing to relay/mine: one larger than 64
Definition: policy.h:40
constexpr script_verify_flags STANDARD_NOT_MANDATORY_VERIFY_FLAGS
For convenience, standard but not mandatory verify flags.
Definition: policy.h:134
unsigned int GetNextWorkRequired(const CBlockIndex *pindexLast, const CBlockHeader *pblock, const Consensus::Params &params)
Definition: pow.cpp:14
bool CheckProofOfWork(uint256 hash, unsigned int nBits, const Consensus::Params &params)
Check whether a block hash satisfies the proof-of-work requirement specified by nBits.
Definition: pow.cpp:140
constexpr TransactionSerParams TX_NO_WITNESS
Definition: transaction.h:181
constexpr TransactionSerParams TX_WITH_WITNESS
Definition: transaction.h:180
static CTransactionRef MakeTransactionRef(Tx &&txIn)
Definition: transaction.h:404
std::shared_ptr< const CTransaction > CTransactionRef
Definition: transaction.h:403
uint256 GetRandHash() noexcept
Generate a random uint256.
Definition: random.h:463
const char * prefix
Definition: rest.cpp:1179
@ OP_RETURN
Definition: script.h:112
std::string ScriptErrorString(const ScriptError serror)
enum ScriptError_t ScriptError
@ SCRIPT_ERR_UNKNOWN_ERROR
Definition: script_error.h:14
uint64_t ReadCompactSize(Stream &is, bool range_check=true)
Decode a CompactSize-encoded variable-length integer.
Definition: serialize.h:333
uint64_t GetSerializeSize(const T &t)
Definition: serialize.h:1157
bool CheckSignetBlockSolution(const CBlock &block, const Consensus::Params &consensusParams)
Extract signature and check whether a block has a valid solution.
Definition: signet.cpp:126
unsigned char * UCharCast(char *c)
Definition: span.h:95
Holds configuration for use during UTXO snapshot load and validation.
Definition: chainparams.h:34
AssumeutxoHash hash_serialized
The expected hash of the deserialized UTXO set.
Definition: chainparams.h:38
uint64_t m_chain_tx_count
Used to populate the m_chain_tx_count value, which is used during BlockManager::LoadBlockIndex().
Definition: chainparams.h:44
Describes a place in the block chain to another node such that if the other node doesn't have the sam...
Definition: block.h:117
std::vector< uint256 > vHave
Definition: block.h:127
A mutable version of CTransaction.
Definition: transaction.h:358
std::vector< CTxOut > vout
Definition: transaction.h:360
std::vector< CTxIn > vin
Definition: transaction.h:359
Holds various statistics on transactions within a chain.
Definition: chainparams.h:57
User-controlled performance and debug options.
Definition: txdb.h:28
std::shared_ptr< const CBlock > pblock
const CBlockIndex * pindex
Parameters that influence chain consensus.
Definition: params.h:88
bool enforce_BIP94
Enforce BIP94 timewarp attack mitigation.
Definition: params.h:122
int64_t DifficultyAdjustmentInterval() const
Definition: params.h:130
bool signet_blocks
If true, witness commitments contain a payload equal to a Bitcoin Script solution to the signet chall...
Definition: params.h:140
int nSubsidyHalvingInterval
Definition: params.h:90
std::map< uint256, script_verify_flags > script_flag_exceptions
Hashes of blocks that.
Definition: params.h:97
int64_t nPowTargetSpacing
Definition: params.h:124
std::chrono::seconds PowTargetSpacing() const
Definition: params.h:126
Application-specific storage settings.
Definition: dbwrapper.h:41
fs::path path
Location in the filesystem where leveldb data will be stored.
Definition: dbwrapper.h:43
Data structure storing a fee and size.
Definition: feefrac.h:22
uint32_t nPos
Definition: flatfile.h:17
bool IsNull() const
Definition: flatfile.h:32
int32_t nFile
Definition: flatfile.h:16
int64_t time
Definition: mempool_entry.h:31
Validation result for a transaction evaluated by MemPoolAccept (single or package).
Definition: validation.h:134
const ResultType m_result_type
Result type.
Definition: validation.h:143
const TxValidationState m_state
Contains information about why the transaction failed.
Definition: validation.h:146
@ INVALID
‍Fully validated, valid.
static MempoolAcceptResult Failure(TxValidationState state)
Definition: validation.h:170
static MempoolAcceptResult FeeFailure(TxValidationState state, CFeeRate effective_feerate, const std::vector< Wtxid > &wtxids_fee_calculations)
Definition: validation.h:174
static MempoolAcceptResult MempoolTxDifferentWitness(const Wtxid &other_wtxid)
Definition: validation.h:193
static MempoolAcceptResult MempoolTx(int64_t vsize, CAmount fees)
Definition: validation.h:189
static MempoolAcceptResult Success(std::list< CTransactionRef > &&replaced_txns, int64_t vsize, CAmount fees, CFeeRate effective_feerate, const std::vector< Wtxid > &wtxids_fee_calculations)
Definition: validation.h:180
static time_point now() noexcept
Return current system time or mocked time, if set.
Definition: time.cpp:64
static time_point now() noexcept
Return current system time or mocked time, if set.
Definition: time.cpp:38
Validation result for package mempool acceptance.
Definition: validation.h:240
void Init(const T &tx, std::vector< CTxOut > &&spent_outputs, bool force=false)
Initialize this PrecomputedTransactionData with transaction data.
bool m_spent_outputs_ready
Whether m_spent_outputs is initialized.
Definition: interpreter.h:183
std::vector< CTxOut > m_spent_outputs
Definition: interpreter.h:181
const char * what() const noexcept override
Bilingual messages:
Definition: translation.h:24
std::string original
Definition: translation.h:25
An options struct for BlockManager, more ergonomically referred to as BlockManager::Options due to th...
An options struct for ChainstateManager, more ergonomically referred to as ChainstateManager::Options...
std::optional< int32_t > check_block_index
std::chrono::seconds max_tip_age
If the tip is older than this, the node is considered to be in initial block download.
int32_t prevoutfetch_threads_num
Number of worker threads used for prefetching block input prevouts. Zero means no parallel fetching.
Information about chainstate that notifications are sent from.
Definition: types.h:18
bool validated
Whether this is a notification from a chainstate that's been fully validated starting from the genesi...
Definition: types.h:22
#define AssertLockNotHeld(cs)
Definition: sync.h:149
#define LOCK(cs)
Definition: sync.h:268
#define WITH_LOCK(cs, code)
Run code while locking a mutex.
Definition: sync.h:299
CDBWrapper db
Definition: dbwrapper.cpp:371
#define EXCLUSIVE_LOCKS_REQUIRED(...)
Definition: threadsafety.h:49
#define LOCKS_EXCLUDED(...)
Definition: threadsafety.h:48
#define LOG_TIME_MILLIS_WITH_CATEGORY(end_msg, log_category)
Definition: timer.h:103
#define LOG_TIME_MILLIS_WITH_CATEGORY_MSG_ONCE(end_msg, log_category)
Definition: timer.h:105
#define strprintf
Format arguments and return the string or write to given std::ostream (see tinyformat::format doc for...
Definition: tinyformat.h:1172
#define TRACEPOINT(context,...)
Definition: trace.h:56
consteval auto _(util::TranslatedLiteral str)
Definition: translation.h:79
bilingual_str Untranslated(std::string original)
Mark a bilingual_str as untranslated.
Definition: translation.h:82
std::optional< std::pair< std::string, CTransactionRef > > SingleTRUCChecks(const CTxMemPool &pool, const CTransactionRef &ptx, const std::vector< CTxMemPoolEntry::CTxMemPoolEntryRef > &mempool_parents, const std::set< Txid > &direct_conflicts, int64_t vsize)
Must be called for every transaction, even if not TRUC.
std::optional< std::string > PackageTRUCChecks(const CTxMemPool &pool, const CTransactionRef &ptx, int64_t vsize, const Package &package, const std::vector< CTxMemPoolEntry::CTxMemPoolEntryRef > &mempool_parents)
Must be called for every transaction that is submitted within a package, even if not TRUC.
Definition: truc_policy.cpp:57
bool CheckTransaction(const CTransaction &tx, TxValidationState &state)
Definition: tx_check.cpp:19
bool EvaluateSequenceLocks(const CBlockIndex &block, std::pair< int, int64_t > lockPair)
Definition: tx_verify.cpp:103
std::pair< int, int64_t > CalculateSequenceLocks(const CTransaction &tx, int flags, std::vector< int > &prevHeights, const CBlockIndex &block)
Calculates the block height and previous block's median time past at which the transaction will be co...
Definition: tx_verify.cpp:45
int64_t GetTransactionSigOpCost(const CTransaction &tx, const CCoinsViewCache &inputs, script_verify_flags flags)
Compute total signature operation cost of a transaction.
Definition: tx_verify.cpp:149
unsigned int GetLegacySigOpCount(const CTransaction &tx)
Auxiliary functions for transaction validation (ideally should not be exposed)
Definition: tx_verify.cpp:118
bool SequenceLocks(const CTransaction &tx, int flags, std::vector< int > &prevHeights, const CBlockIndex &block)
Check if transaction is final per BIP 68 sequence numbers and can be included in a block.
Definition: tx_verify.cpp:113
bool IsFinalTx(const CTransaction &tx, int nBlockHeight, int64_t nBlockTime)
Check if transaction is final and can be included in a block with the specified height and time.
Definition: tx_verify.cpp:23
bool TestLockPointValidity(CChain &active_chain, const LockPoints &lp)
Test whether the LockPoints height and time are still valid on the current chain.
Definition: txmempool.cpp:40
constexpr uint32_t MEMPOOL_HEIGHT
Fake height value used in Coin to signify they are only in the memory pool (since 0....
Definition: txmempool.h:50
#define expect(bit)
int64_t GetTime()
DEPRECATED Use either ClockType::now() or Now<TimePointType>() if a cast is needed.
Definition: time.cpp:88
std::string FormatISO8601DateTime(int64_t nTime)
ISO 8601 formatting is preferred.
Definition: time.cpp:90
constexpr int64_t count_seconds(std::chrono::seconds t)
Definition: time.h:97
std::chrono::time_point< NodeClock, std::chrono::seconds > NodeSeconds
Definition: time.h:35
PackageMempoolAcceptResult ProcessNewPackage(Chainstate &active_chainstate, CTxMemPool &pool, const Package &package, bool test_accept, const std::optional< CFeeRate > &client_maxfeerate)
Validate (and maybe submit) a package to the mempool.
static void LimitMempoolSize(CTxMemPool &pool, CCoinsViewCache &coins_cache) EXCLUSIVE_LOCKS_REQUIRED(
Definition: validation.cpp:273
bool IsBlockMutated(const CBlock &block, bool check_witness_root)
Check if a block has been mutated (with respect to its merkle root and witness commitments).
script_verify_flags GetBlockScriptFlags(const CBlockIndex &block_index, const ChainstateManager &chainman)
std::optional< LockPoints > CalculateLockPointsAtTip(CBlockIndex *tip, const CCoinsView &coins_view, const CTransaction &tx)
Definition: validation.cpp:210
static bool pool cs
Definition: validation.cpp:409
bool CheckInputScripts(const CTransaction &tx, TxValidationState &state, const CCoinsViewCache &inputs, script_verify_flags flags, bool cacheSigStore, bool cacheFullScriptStore, PrecomputedTransactionData &txdata, ValidationCache &validation_cache, std::vector< CScriptCheck > *pvChecks=nullptr) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Check whether all of this transaction's input scripts succeed.
bool CheckFinalTxAtTip(const CBlockIndex &active_chain_tip, const CTransaction &tx)
Definition: validation.cpp:156
CAmount GetBlockSubsidy(int nHeight, const Consensus::Params &consensusParams)
MempoolAcceptResult AcceptToMemoryPool(Chainstate &active_chainstate, const CTransactionRef &tx, int64_t accept_time, bool bypass_limits, bool test_accept)
Try to add a transaction to the mempool.
bool HasValidProofOfWork(std::span< const CBlockHeader > headers, const Consensus::Params &consensusParams)
Check that the proof of work on each blockheader matches the value in nBits.
int ApplyTxInUndo(Coin &&undo, CCoinsViewCache &view, const COutPoint &out)
Restore the UTXO in a Coin at a given COutPoint.
static bool ContextualCheckBlock(const CBlock &block, BlockValidationState &state, const ChainstateManager &chainman, const CBlockIndex *pindexPrev)
NOTE: This function is not currently invoked by ConnectBlock(), so we should consider upgrade issues ...
bool FatalError(Notifications &notifications, BlockValidationState &state, const bilingual_str &message)
bool CheckSequenceLocksAtTip(CBlockIndex *tip, const LockPoints &lock_points)
Check if transaction will be BIP68 final in the next block to be created on top of tip.
Definition: validation.cpp:255
static bool ContextualCheckBlockHeader(const CBlockHeader &block, BlockValidationState &state, const ChainstateManager &chainman, const CBlockIndex *pindexPrev) EXCLUSIVE_LOCKS_REQUIRED(
Context-dependent validity checks.
static ChainstateManager::Options && Flatten(ChainstateManager::Options &&opts)
Apply default chain params to nullopt members.
static void UpdateTipLog(const ChainstateManager &chainman, const CCoinsViewCache &coins_tip, const CBlockIndex *tip, const std::string &func_name, const std::string &prefix, const std::string &warning_messages, const bool background_validation) EXCLUSIVE_LOCKS_REQUIRED(
static bool CheckInputsFromMempoolAndCache(const CTransaction &tx, TxValidationState &state, const CCoinsViewCache &view, const CTxMemPool &pool, script_verify_flags flags, PrecomputedTransactionData &txdata, CCoinsViewCache &coins_tip, ValidationCache &validation_cache) EXCLUSIVE_LOCKS_REQUIRED(cs_main
Checks to avoid mempool polluting consensus critical paths since cached signature and script validity...
static constexpr auto DATABASE_WRITE_INTERVAL_MAX
Definition: validation.cpp:99
static bool CheckWitnessMalleation(const CBlock &block, bool expect_witness_commitment, BlockValidationState &state)
CheckWitnessMalleation performs checks for block malleation with regard to its witnesses.
void UpdateCoins(const CTransaction &tx, CCoinsViewCache &inputs, CTxUndo &txundo, int nHeight)
static bool DeleteCoinsDBFromDisk(const fs::path db_path, bool is_snapshot) EXCLUSIVE_LOCKS_REQUIRED(
static bool CheckMerkleRoot(const CBlock &block, BlockValidationState &state)
static constexpr int PRUNE_LOCK_BUFFER
The number of blocks to keep below the deepest prune lock.
Definition: validation.cpp:115
arith_uint256 CalculateClaimedHeadersWork(std::span< const CBlockHeader > headers)
Return the sum of the claimed work on a given set of headers.
const std::vector< std::string > CHECKLEVEL_DOC
Documentation for argument 'checklevel'.
Definition: validation.cpp:102
bool CheckBlock(const CBlock &block, BlockValidationState &state, const Consensus::Params &consensusParams, bool fCheckPOW, bool fCheckMerkleRoot)
Functions for validating blocks and updating the block tree.
static constexpr std::chrono::hours MAX_FEE_ESTIMATION_TIP_AGE
Maximum age of our tip for us to be considered current for fee estimation.
Definition: validation.cpp:101
void PruneBlockFilesManual(Chainstate &active_chainstate, int nManualPruneHeight)
Prune block files up to a given height.
static void FlushSnapshotToDisk(CCoinsViewCache &coins_cache, bool snapshot_loaded)
static bool IsCurrentForFeeEstimation(Chainstate &active_chainstate) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Definition: validation.cpp:289
static constexpr auto DATABASE_WRITE_INTERVAL_MIN
Time window to wait between writing blocks/block index and chainstate to disk.
Definition: validation.cpp:98
AssertLockHeld(pool.cs)
BlockValidationState TestBlockValidity(Chainstate &chainstate, const CBlock &block, const bool check_pow, const bool check_merkle_root)
Verify a block, including transactions.
static bool CheckBlockHeader(const CBlockHeader &block, BlockValidationState &state, const Consensus::Params &consensusParams, bool fCheckPOW=true)
bool IsBIP30Repeat(const CBlockIndex &block_index)
Identifies blocks that overwrote an existing coinbase output in the UTXO set (see BIP30)
static void SnapshotUTXOHashBreakpoint(const util::SignalInterrupt &interrupt)
static bool ShouldCompactChainstate(bool in_ibd)
Definition: validation.cpp:118
static SynchronizationState GetSynchronizationState(bool init, bool blockfiles_indexed)
bool IsBIP30Unspendable(const uint256 &block_hash, int block_height)
Identifies blocks which coinbase output was subsequently overwritten in the UTXO set (see BIP30)
TRACEPOINT_SEMAPHORE(validation, block_connected)
static void LimitValidationInterfaceQueue(ValidationSignals &signals) LOCKS_EXCLUDED(cs_main)
assert(!tx.IsCoinBase())
constexpr int MAX_SCRIPTCHECK_THREADS
Maximum number of dedicated script-checking threads allowed.
Definition: validation.h:90
SnapshotCompletionResult
Definition: validation.h:903
Assumeutxo
Chainstate assumeutxo validity.
Definition: validation.h:526
@ VALIDATED
Every block in the chain has been validated.
@ UNVALIDATED
Blocks after an assumeutxo snapshot have been validated but the snapshot itself has not been validate...
@ INVALID
The assumeutxo snapshot failed validation.
SynchronizationState
Current sync state passed to tip changed callbacks.
Definition: validation.h:96
constexpr std::array FlushStateModeNames
Definition: validation.h:460
constexpr int64_t LargeCoinsCacheThreshold(int64_t total_space) noexcept
Definition: validation.h:517
VerifyDBResult
Definition: validation.h:425
FlushStateMode
Definition: validation.h:461
CoinsCacheSizeState
Definition: validation.h:509
@ LARGE
The cache is at >= 90% capacity.
@ CRITICAL
The coins cache is in immediate need of a flush.
constexpr unsigned int MIN_BLOCKS_TO_KEEP
Block files containing a block-height within MIN_BLOCKS_TO_KEEP of ActiveChain().Tip() will not be pr...
Definition: validation.h:76
DisconnectResult
Definition: validation.h:451
@ DISCONNECT_FAILED
Definition: validation.h:454
@ DISCONNECT_UNCLEAN
Definition: validation.h:453
@ DISCONNECT_OK
Definition: validation.h:452