Bitcoin Core 31.99.0
P2P Digital Currency
validation.cpp
Go to the documentation of this file.
1// Copyright (c) 2009-2010 Satoshi Nakamoto
2// Copyright (c) 2009-present The Bitcoin Core developers
3// Distributed under the MIT software license, see the accompanying
4// file COPYING or http://www.opensource.org/licenses/mit-license.php.
5
6#include <bitcoin-build-config.h> // IWYU pragma: keep
7
8#include <validation.h>
9
10#include <arith_uint256.h>
11#include <chain.h>
12#include <checkqueue.h>
13#include <clientversion.h>
14#include <consensus/amount.h>
15#include <consensus/consensus.h>
16#include <consensus/merkle.h>
17#include <consensus/tx_check.h>
18#include <consensus/tx_verify.h>
20#include <cuckoocache.h>
21#include <flatfile.h>
22#include <hash.h>
23#include <kernel/chainparams.h>
24#include <kernel/coinstats.h>
29#include <kernel/types.h>
30#include <kernel/warning.h>
31#include <logging/timer.h>
32#include <node/blockstorage.h>
33#include <node/utxo_snapshot.h>
35#include <policy/policy.h>
36#include <policy/rbf.h>
37#include <policy/settings.h>
38#include <policy/truc_policy.h>
39#include <pow.h>
40#include <primitives/block.h>
42#include <random.h>
43#include <script/script.h>
44#include <script/sigcache.h>
45#include <signet.h>
46#include <tinyformat.h>
47#include <txdb.h>
48#include <txmempool.h>
49#include <uint256.h>
50#include <undo.h>
51#include <util/byte_units.h>
52#include <util/check.h>
53#include <util/fs.h>
54#include <util/fs_helpers.h>
55#include <util/hasher.h>
56#include <util/log.h>
57#include <util/moneystr.h>
58#include <util/rbf.h>
59#include <util/result.h>
61#include <util/strencodings.h>
62#include <util/string.h>
63#include <util/threadpool.h>
64#include <util/time.h>
65#include <util/trace.h>
66#include <util/translation.h>
67#include <validationinterface.h>
68
69#include <algorithm>
70#include <cassert>
71#include <chrono>
72#include <deque>
73#include <numeric>
74#include <optional>
75#include <ranges>
76#include <span>
77#include <string>
78#include <tuple>
79#include <utility>
80
86
89using node::BlockMap;
93
98static constexpr auto DATABASE_WRITE_INTERVAL_MIN{50min};
99static constexpr auto DATABASE_WRITE_INTERVAL_MAX{70min};
101static constexpr std::chrono::hours MAX_FEE_ESTIMATION_TIP_AGE{3};
102const std::vector<std::string> CHECKLEVEL_DOC {
103 "level 0 reads the blocks from disk",
104 "level 1 verifies block validity",
105 "level 2 verifies undo data",
106 "level 3 checks disconnection of tip blocks",
107 "level 4 tries to reconnect the blocks",
108 "each level includes the checks of the previous levels",
109};
115static constexpr int PRUNE_LOCK_BUFFER{10};
116
117// Return whether the completed full flush should compact chainstate
118static bool ShouldCompactChainstate(bool in_ibd)
119{
120 static constexpr uint32_t flush_ratio{320}; // Roughly every 2 weeks with hourly flushes
121 return !in_ibd && FastRandomContext().randrange(flush_ratio) == 0;
122}
123
124TRACEPOINT_SEMAPHORE(validation, block_connected);
126TRACEPOINT_SEMAPHORE(mempool, replaced);
127TRACEPOINT_SEMAPHORE(mempool, rejected);
128
130{
132
133 // Find the latest block common to locator and chain - we expect that
134 // locator.vHave is sorted descending by height.
135 for (const uint256& hash : locator.vHave) {
136 const CBlockIndex* pindex{m_blockman.LookupBlockIndex(hash)};
137 if (pindex) {
138 if (m_chain.Contains(*pindex)) {
139 return pindex;
140 }
141 if (pindex->GetAncestor(m_chain.Height()) == m_chain.Tip()) {
142 return m_chain.Tip();
143 }
144 }
145 }
146 return m_chain.Genesis();
147}
148
150 const CCoinsViewCache& inputs, script_verify_flags flags, bool cacheSigStore,
151 bool cacheFullScriptStore, PrecomputedTransactionData& txdata,
152 ValidationCache& validation_cache,
153 std::vector<CScriptCheck>* pvChecks = nullptr)
155
156bool CheckFinalTxAtTip(const CBlockIndex& active_chain_tip, const CTransaction& tx)
157{
159
160 // CheckFinalTxAtTip() uses active_chain_tip.Height()+1 to evaluate
161 // nLockTime because when IsFinalTx() is called within
162 // AcceptBlock(), the height of the block *being*
163 // evaluated is what is used. Thus if we want to know if a
164 // transaction can be part of the *next* block, we need to call
165 // IsFinalTx() with one more than active_chain_tip.Height().
166 const int nBlockHeight = active_chain_tip.nHeight + 1;
167
168 // BIP113 requires that time-locked transactions have nLockTime set to
169 // less than the median time of the previous block they're contained in.
170 // When the next block is created its previous block will be the current
171 // chain tip, so we use that to calculate the median time passed to
172 // IsFinalTx().
173 const int64_t nBlockTime{active_chain_tip.GetMedianTimePast()};
174
175 return IsFinalTx(tx, nBlockHeight, nBlockTime);
176}
177
178namespace {
189std::optional<std::vector<int>> CalculatePrevHeights(
190 const CBlockIndex& tip,
191 const CCoinsView& coins,
192 const CTransaction& tx)
193{
194 std::vector<int> prev_heights;
195 prev_heights.resize(tx.vin.size());
196 for (size_t i = 0; i < tx.vin.size(); ++i) {
197 if (auto coin{coins.GetCoin(tx.vin[i].prevout)}) {
198 prev_heights[i] = coin->nHeight == MEMPOOL_HEIGHT
199 ? tip.nHeight + 1 // Assume all mempool transaction confirm in the next block.
200 : coin->nHeight;
201 } else {
202 LogInfo("ERROR: %s: Missing input %d in transaction \'%s\'\n", __func__, i, tx.GetHash().GetHex());
203 return std::nullopt;
204 }
205 }
206 return prev_heights;
207}
208} // namespace
209
210std::optional<LockPoints> CalculateLockPointsAtTip(
211 CBlockIndex* tip,
212 const CCoinsView& coins_view,
213 const CTransaction& tx)
214{
215 assert(tip);
216
217 auto prev_heights{CalculatePrevHeights(*tip, coins_view, tx)};
218 if (!prev_heights.has_value()) return std::nullopt;
219
220 CBlockIndex next_tip;
221 next_tip.pprev = tip;
222 // When SequenceLocks() is called within ConnectBlock(), the height
223 // of the block *being* evaluated is what is used.
224 // Thus if we want to know if a transaction can be part of the
225 // *next* block, we need to use one more than active_chainstate.m_chain.Height()
226 next_tip.nHeight = tip->nHeight + 1;
227 const auto [min_height, min_time] = CalculateSequenceLocks(tx, STANDARD_LOCKTIME_VERIFY_FLAGS, prev_heights.value(), next_tip);
228
229 // Also store the hash of the block with the highest height of
230 // all the blocks which have sequence locked prevouts.
231 // This hash needs to still be on the chain
232 // for these LockPoint calculations to be valid
233 // Note: It is impossible to correctly calculate a maxInputBlock
234 // if any of the sequence locked inputs depend on unconfirmed txs,
235 // except in the special case where the relative lock time/height
236 // is 0, which is equivalent to no sequence lock. Since we assume
237 // input height of tip+1 for mempool txs and test the resulting
238 // min_height and min_time from CalculateSequenceLocks against tip+1.
239 int max_input_height{0};
240 for (const int height : prev_heights.value()) {
241 // Can ignore mempool inputs since we'll fail if they had non-zero locks
242 if (height != next_tip.nHeight) {
243 max_input_height = std::max(max_input_height, height);
244 }
245 }
246
247 // tip->GetAncestor(max_input_height) should never return a nullptr
248 // because max_input_height is always less than the tip height.
249 // It would, however, be a bad bug to continue execution, since a
250 // LockPoints object with the maxInputBlock member set to nullptr
251 // signifies no relative lock time.
252 return LockPoints{min_height, min_time, Assert(tip->GetAncestor(max_input_height))};
253}
254
256 const LockPoints& lock_points)
257{
258 assert(tip != nullptr);
259
260 CBlockIndex index;
261 index.pprev = tip;
262 // CheckSequenceLocksAtTip() uses active_chainstate.m_chain.Height()+1 to evaluate
263 // height based locks because when SequenceLocks() is called within
264 // ConnectBlock(), the height of the block *being*
265 // evaluated is what is used.
266 // Thus if we want to know if a transaction can be part of the
267 // *next* block, we need to use one more than active_chainstate.m_chain.Height()
268 index.nHeight = tip->nHeight + 1;
269
270 return EvaluateSequenceLocks(index, {lock_points.height, lock_points.time});
271}
272
273static void LimitMempoolSize(CTxMemPool& pool, CCoinsViewCache& coins_cache)
275{
277 AssertLockHeld(pool.cs);
278 int expired = pool.Expire(GetTime<std::chrono::seconds>() - pool.m_opts.expiry);
279 if (expired != 0) {
280 LogDebug(BCLog::MEMPOOL, "Expired %i transactions from the memory pool\n", expired);
281 }
282
283 std::vector<COutPoint> vNoSpendsRemaining;
284 pool.TrimToSize(pool.m_opts.max_size_bytes, &vNoSpendsRemaining);
285 for (const COutPoint& removed : vNoSpendsRemaining)
286 coins_cache.Uncache(removed);
287}
288
290{
292 if (active_chainstate.m_chainman.IsInitialBlockDownload()) {
293 return false;
294 }
295 if (active_chainstate.m_chain.Tip()->GetBlockTime() < count_seconds(GetTime<std::chrono::seconds>() - MAX_FEE_ESTIMATION_TIP_AGE))
296 return false;
297 if (active_chainstate.m_chain.Height() < active_chainstate.m_chainman.m_best_header->nHeight - 1) {
298 return false;
299 }
300 return true;
301}
302
304 DisconnectedBlockTransactions& disconnectpool,
305 bool fAddToMempool)
306{
307 if (!m_mempool) return;
308
311 std::vector<Txid> vHashUpdate;
312 {
313 // disconnectpool is ordered so that the front is the most recently-confirmed
314 // transaction (the last tx of the block at the tip) in the disconnected chain.
315 // Iterate disconnectpool in reverse, so that we add transactions
316 // back to the mempool starting with the earliest transaction that had
317 // been previously seen in a block.
318 const auto queuedTx = disconnectpool.take();
319 auto it = queuedTx.rbegin();
320 while (it != queuedTx.rend()) {
321 // ignore validation errors in resurrected transactions
322 if (!fAddToMempool || (*it)->IsCoinBase() ||
323 AcceptToMemoryPool(*this, *it, GetTime(),
324 /*bypass_limits=*/true, /*test_accept=*/false).m_result_type !=
326 // If the transaction doesn't make it in to the mempool, remove any
327 // transactions that depend on it (which would now be orphans).
329 } else if (m_mempool->exists((*it)->GetHash())) {
330 vHashUpdate.push_back((*it)->GetHash());
331 }
332 ++it;
333 }
334 }
335
336 // AcceptToMemoryPool/addNewTransaction all assume that new mempool entries have
337 // no in-mempool children, which is generally not true when adding
338 // previously-confirmed transactions back to the mempool.
339 // UpdateTransactionsFromBlock finds descendants of any transactions in
340 // the disconnectpool that were added back and cleans up the mempool state.
342
343 // Predicate to use for filtering transactions in removeForReorg.
344 // Checks whether the transaction is still final and, if it spends a coinbase output, mature.
345 // Also updates valid entries' cached LockPoints if needed.
346 // If false, the tx is still valid and its lockpoints are updated.
347 // If true, the tx would be invalid in the next block; remove this entry and all of its descendants.
348 // Note that TRUC rules are not applied here, so reorgs may cause violations of TRUC inheritance or
349 // topology restrictions.
350 const auto filter_final_and_mature = [&](CTxMemPool::txiter it)
354 const CTransaction& tx = it->GetTx();
355
356 // The transaction must be final.
357 if (!CheckFinalTxAtTip(*Assert(m_chain.Tip()), tx)) return true;
358
359 const LockPoints& lp = it->GetLockPoints();
360 // CheckSequenceLocksAtTip checks if the transaction will be final in the next block to be
361 // created on top of the new chain.
364 return true;
365 }
366 } else {
367 const CCoinsViewMemPool view_mempool{&CoinsTip(), *m_mempool};
368 const std::optional<LockPoints> new_lock_points{CalculateLockPointsAtTip(m_chain.Tip(), view_mempool, tx)};
369 if (new_lock_points.has_value() && CheckSequenceLocksAtTip(m_chain.Tip(), *new_lock_points)) {
370 // Now update the mempool entry lockpoints as well.
371 it->UpdateLockPoints(*new_lock_points);
372 } else {
373 return true;
374 }
375 }
376
377 // If the transaction spends any coinbase outputs, it must be mature.
378 if (it->GetSpendsCoinbase()) {
379 for (const CTxIn& txin : tx.vin) {
380 if (m_mempool->exists(txin.prevout.hash)) continue;
381 const Coin& coin{CoinsTip().AccessCoin(txin.prevout)};
382 assert(!coin.IsSpent());
383 const auto mempool_spend_height{m_chain.Tip()->nHeight + 1};
384 if (coin.IsCoinBase() && mempool_spend_height - coin.nHeight < COINBASE_MATURITY) {
385 return true;
386 }
387 }
388 }
389 // Transaction is still valid and cached LockPoints are updated.
390 return false;
391 };
392
393 // We also need to remove any now-immature transactions
394 m_mempool->removeForReorg(m_chain, filter_final_and_mature);
395 // Re-limit mempool size, in case we added any transactions
397}
398
405 const CCoinsViewCache& view, const CTxMemPool& pool,
407 ValidationCache& validation_cache)
409{
412
414 for (const CTxIn& txin : tx.vin) {
415 const Coin& coin = view.AccessCoin(txin.prevout);
416
417 // This coin was checked in PreChecks and MemPoolAccept
418 // has been holding cs_main since then.
419 Assume(!coin.IsSpent());
420 if (coin.IsSpent()) return false;
421
422 // If the Coin is available, there are 2 possibilities:
423 // it is available in our current ChainstateActive UTXO set,
424 // or it's a UTXO provided by a transaction in our mempool.
425 // Ensure the scriptPubKeys in Coins from CoinsView are correct.
426 const CTransactionRef& txFrom = pool.get(txin.prevout.hash);
427 if (txFrom) {
428 assert(txFrom->GetHash() == txin.prevout.hash);
429 assert(txFrom->vout.size() > txin.prevout.n);
430 assert(txFrom->vout[txin.prevout.n] == coin.out);
431 } else {
432 const Coin& coinFromUTXOSet = coins_tip.AccessCoin(txin.prevout);
433 assert(!coinFromUTXOSet.IsSpent());
434 assert(coinFromUTXOSet.out == coin.out);
435 }
436 }
437
438 // Call CheckInputScripts() to cache signature and script validity against current tip consensus rules.
439 return CheckInputScripts(tx, state, view, flags, /* cacheSigStore= */ true, /* cacheFullScriptStore= */ true, txdata, validation_cache);
440}
441
442namespace {
443
444class MemPoolAccept
445{
446public:
447 explicit MemPoolAccept(CTxMemPool& mempool, Chainstate& active_chainstate) :
448 m_pool(mempool),
449 m_view(&CoinsViewEmpty::Get()),
450 m_viewmempool(&active_chainstate.CoinsTip(), m_pool),
451 m_active_chainstate(active_chainstate)
452 {
453 }
454
455 // We put the arguments we're handed into a struct, so we can pass them
456 // around easier.
457 struct ATMPArgs {
458 const CChainParams& m_chainparams;
459 const int64_t m_accept_time;
460 const bool m_bypass_limits;
461 /*
462 * Return any outpoints which were not previously present in the coins
463 * cache, but were added as a result of validating the tx for mempool
464 * acceptance. This allows the caller to optionally remove the cache
465 * additions if the associated transaction ends up being rejected by
466 * the mempool.
467 */
468 std::vector<COutPoint>& m_coins_to_uncache;
470 const bool m_test_accept;
474 const bool m_allow_replacement;
476 const bool m_allow_sibling_eviction;
479 const bool m_package_submission;
483 const bool m_package_feerates;
488 const std::optional<CFeeRate> m_client_maxfeerate;
489
491 static ATMPArgs SingleAccept(const CChainParams& chainparams, int64_t accept_time,
492 bool bypass_limits, std::vector<COutPoint>& coins_to_uncache,
493 bool test_accept) {
494 return ATMPArgs{/*chainparams=*/ chainparams,
495 /*accept_time=*/ accept_time,
496 /*bypass_limits=*/ bypass_limits,
497 /*coins_to_uncache=*/ coins_to_uncache,
498 /*test_accept=*/ test_accept,
499 /*allow_replacement=*/ true,
500 /*allow_sibling_eviction=*/ true,
501 /*package_submission=*/ false,
502 /*package_feerates=*/ false,
503 /*client_maxfeerate=*/ {}, // checked by caller
504 };
505 }
506
508 static ATMPArgs PackageTestAccept(const CChainParams& chainparams, int64_t accept_time,
509 std::vector<COutPoint>& coins_to_uncache) {
510 return ATMPArgs{/*chainparams=*/ chainparams,
511 /*accept_time=*/ accept_time,
512 /*bypass_limits=*/ false,
513 /*coins_to_uncache=*/ coins_to_uncache,
514 /*test_accept=*/ true,
515 /*allow_replacement=*/ false,
516 /*allow_sibling_eviction=*/ false,
517 /*package_submission=*/ false, // not submitting to mempool
518 /*package_feerates=*/ false,
519 /*client_maxfeerate=*/ {}, // checked by caller
520 };
521 }
522
524 static ATMPArgs PackageChildWithParents(const CChainParams& chainparams, int64_t accept_time,
525 std::vector<COutPoint>& coins_to_uncache, const std::optional<CFeeRate>& client_maxfeerate) {
526 return ATMPArgs{/*chainparams=*/ chainparams,
527 /*accept_time=*/ accept_time,
528 /*bypass_limits=*/ false,
529 /*coins_to_uncache=*/ coins_to_uncache,
530 /*test_accept=*/ false,
531 /*allow_replacement=*/ true,
532 /*allow_sibling_eviction=*/ false,
533 /*package_submission=*/ true,
534 /*package_feerates=*/ true,
535 /*client_maxfeerate=*/ client_maxfeerate,
536 };
537 }
538
540 static ATMPArgs SingleInPackageAccept(const ATMPArgs& package_args) {
541 return ATMPArgs{/*chainparams=*/ package_args.m_chainparams,
542 /*accept_time=*/ package_args.m_accept_time,
543 /*bypass_limits=*/ false,
544 /*coins_to_uncache=*/ package_args.m_coins_to_uncache,
545 /*test_accept=*/ package_args.m_test_accept,
546 /*allow_replacement=*/ true,
547 /*allow_sibling_eviction=*/ true,
548 /*package_submission=*/ true, // trim at the end of AcceptPackage()
549 /*package_feerates=*/ false, // only 1 transaction
550 /*client_maxfeerate=*/ package_args.m_client_maxfeerate,
551 };
552 }
553
554 private:
555 // Private ctor to avoid exposing details to clients and allowing the possibility of
556 // mixing up the order of the arguments. Use static functions above instead.
557 ATMPArgs(const CChainParams& chainparams,
558 int64_t accept_time,
559 bool bypass_limits,
560 std::vector<COutPoint>& coins_to_uncache,
561 bool test_accept,
562 bool allow_replacement,
563 bool allow_sibling_eviction,
564 bool package_submission,
565 bool package_feerates,
566 std::optional<CFeeRate> client_maxfeerate)
567 : m_chainparams{chainparams},
568 m_accept_time{accept_time},
569 m_bypass_limits{bypass_limits},
570 m_coins_to_uncache{coins_to_uncache},
571 m_test_accept{test_accept},
572 m_allow_replacement{allow_replacement},
573 m_allow_sibling_eviction{allow_sibling_eviction},
574 m_package_submission{package_submission},
575 m_package_feerates{package_feerates},
576 m_client_maxfeerate{client_maxfeerate}
577 {
578 // If we are using package feerates, we must be doing package submission.
579 // It also means sibling eviction is not permitted.
580 if (m_package_feerates) {
581 Assume(m_package_submission);
582 Assume(!m_allow_sibling_eviction);
583 }
584 if (m_allow_sibling_eviction) Assume(m_allow_replacement);
585 }
586 };
587
589 void CleanupTemporaryCoins() EXCLUSIVE_LOCKS_REQUIRED(cs_main, m_pool.cs);
590
591 // Single transaction acceptance
592 MempoolAcceptResult AcceptSingleTransactionAndCleanup(const CTransactionRef& ptx, ATMPArgs& args) EXCLUSIVE_LOCKS_REQUIRED(cs_main) {
593 LOCK(m_pool.cs);
594 MempoolAcceptResult result = AcceptSingleTransactionInternal(ptx, args);
595 ClearSubPackageState();
596 return result;
597 }
598 MempoolAcceptResult AcceptSingleTransactionInternal(const CTransactionRef& ptx, ATMPArgs& args) EXCLUSIVE_LOCKS_REQUIRED(cs_main, m_pool.cs);
599
605 PackageMempoolAcceptResult AcceptMultipleTransactionsAndCleanup(const std::vector<CTransactionRef>& txns, ATMPArgs& args) EXCLUSIVE_LOCKS_REQUIRED(cs_main) {
606 LOCK(m_pool.cs);
607 PackageMempoolAcceptResult result = AcceptMultipleTransactionsInternal(txns, args);
608 ClearSubPackageState();
609 return result;
610 }
611 PackageMempoolAcceptResult AcceptMultipleTransactionsInternal(const std::vector<CTransactionRef>& txns, ATMPArgs& args) EXCLUSIVE_LOCKS_REQUIRED(cs_main, m_pool.cs);
612
623 PackageMempoolAcceptResult AcceptSubPackage(const std::vector<CTransactionRef>& subpackage, ATMPArgs& args)
625
630 PackageMempoolAcceptResult AcceptPackage(const Package& package, ATMPArgs& args) EXCLUSIVE_LOCKS_REQUIRED(cs_main);
631
632private:
633 // All the intermediate state that gets passed between the various levels
634 // of checking a given transaction.
635 struct Workspace {
636 explicit Workspace(const CTransactionRef& ptx) : m_ptx(ptx), m_hash(ptx->GetHash()) {}
639 std::set<Txid> m_conflicts;
642 CTxMemPool::setEntries m_iters_conflicting;
644 std::vector<CTxMemPoolEntry::CTxMemPoolEntryRef> m_parents;
645 /* Handle to the tx in the changeset */
649 bool m_sibling_eviction{false};
650
653 int64_t m_vsize;
655 CAmount m_base_fees;
657 CAmount m_modified_fees;
658
662 CFeeRate m_package_feerate{0};
663
664 const CTransactionRef& m_ptx;
666 const Txid& m_hash;
670 PrecomputedTransactionData m_precomputed_txdata;
671 };
672
673 // Run the policy checks on a given transaction, excluding any script checks.
674 // Looks up inputs, calculates feerate, considers replacement, evaluates
675 // package limits, etc. As this function can be invoked for "free" by a peer,
676 // only tests that are fast should be done here (to avoid CPU DoS).
677 bool PreChecks(ATMPArgs& args, Workspace& ws) EXCLUSIVE_LOCKS_REQUIRED(cs_main, m_pool.cs);
678
679 // Run checks for mempool replace-by-fee, only used in AcceptSingleTransaction.
680 bool ReplacementChecks(Workspace& ws) EXCLUSIVE_LOCKS_REQUIRED(cs_main, m_pool.cs);
681
682 bool PackageRBFChecks(const std::vector<CTransactionRef>& txns,
683 std::vector<Workspace>& workspaces,
684 int64_t total_vsize,
685 PackageValidationState& package_state) EXCLUSIVE_LOCKS_REQUIRED(cs_main, m_pool.cs);
686
687 // Run the script checks using our policy flags. As this can be slow, we should
688 // only invoke this on transactions that have otherwise passed policy checks.
689 bool PolicyScriptChecks(const ATMPArgs& args, Workspace& ws) EXCLUSIVE_LOCKS_REQUIRED(cs_main, m_pool.cs);
690
691 // Re-run the script checks, using consensus flags, and try to cache the
692 // result in the scriptcache. This should be done after
693 // PolicyScriptChecks(). This requires that all inputs either be in our
694 // utxo set or in the mempool.
695 bool ConsensusScriptChecks(const ATMPArgs& args, Workspace& ws) EXCLUSIVE_LOCKS_REQUIRED(cs_main, m_pool.cs);
696
697 // Try to add the transaction to the mempool, removing any conflicts first.
698 void FinalizeSubpackage(const ATMPArgs& args) EXCLUSIVE_LOCKS_REQUIRED(cs_main, m_pool.cs);
699
700 // Submit all transactions to the mempool and call ConsensusScriptChecks to add to the script
701 // cache - should only be called after successful validation of all transactions in the package.
702 // Does not call LimitMempoolSize(), so mempool max_size_bytes may be temporarily exceeded.
703 bool SubmitPackage(const ATMPArgs& args, std::vector<Workspace>& workspaces, PackageValidationState& package_state,
704 std::map<Wtxid, MempoolAcceptResult>& results)
706
707 // Compare a package's feerate against minimum allowed.
708 bool CheckFeeRate(size_t package_size, CAmount package_fee, TxValidationState& state) EXCLUSIVE_LOCKS_REQUIRED(::cs_main, m_pool.cs)
709 {
711 AssertLockHeld(m_pool.cs);
712 CAmount mempoolRejectFee = m_pool.GetMinFee().GetFee(package_size);
713 if (mempoolRejectFee > 0 && package_fee < mempoolRejectFee) {
714 return state.Invalid(TxValidationResult::TX_RECONSIDERABLE, "mempool min fee not met", strprintf("%d < %d", package_fee, mempoolRejectFee));
715 }
716
717 if (package_fee < m_pool.m_opts.min_relay_feerate.GetFee(package_size)) {
718 return state.Invalid(TxValidationResult::TX_RECONSIDERABLE, "min relay fee not met",
719 strprintf("%d < %d", package_fee, m_pool.m_opts.min_relay_feerate.GetFee(package_size)));
720 }
721 return true;
722 }
723
724 ValidationCache& GetValidationCache()
725 {
726 return m_active_chainstate.m_chainman.m_validation_cache;
727 }
728
729private:
730 CTxMemPool& m_pool;
731
743 CCoinsViewCache m_view;
744
745 // These are the two possible backends for m_view.
748 CCoinsViewMemPool m_viewmempool;
749
750 Chainstate& m_active_chainstate;
751
752 // Fields below are per *sub*package state and must be reset prior to subsequent
753 // AcceptSingleTransaction and AcceptMultipleTransactions invocations
754 struct SubPackageState {
756 CAmount m_total_modified_fees{0};
758 int64_t m_total_vsize{0};
759
760 // RBF-related members
763 bool m_rbf{false};
765 std::list<CTransactionRef> m_replaced_transactions;
766 /* Changeset representing adding transactions and removing their conflicts. */
767 std::unique_ptr<CTxMemPool::ChangeSet> m_changeset;
768
770 CAmount m_conflicting_fees{0};
772 size_t m_conflicting_size{0};
773 };
774
775 struct SubPackageState m_subpackage;
776
778 void ClearSubPackageState() EXCLUSIVE_LOCKS_REQUIRED(cs_main, m_pool.cs)
779 {
780 m_subpackage = SubPackageState{};
781
782 // And clean coins while at it
783 CleanupTemporaryCoins();
784 }
785};
786
787bool MemPoolAccept::PreChecks(ATMPArgs& args, Workspace& ws)
788{
790 AssertLockHeld(m_pool.cs);
791 const CTransactionRef& ptx = ws.m_ptx;
792 const CTransaction& tx = *ws.m_ptx;
793 const Txid& hash = ws.m_hash;
794
795 // Copy/alias what we need out of args
796 const int64_t nAcceptTime = args.m_accept_time;
797 const bool bypass_limits = args.m_bypass_limits;
798 std::vector<COutPoint>& coins_to_uncache = args.m_coins_to_uncache;
799
800 // Alias what we need out of ws
801 TxValidationState& state = ws.m_state;
802
803 if (!CheckTransaction(tx, state)) {
804 return false; // state filled in by CheckTransaction
805 }
806
807 // Coinbase is only valid in a block, not as a loose transaction
808 if (tx.IsCoinBase())
809 return state.Invalid(TxValidationResult::TX_CONSENSUS, "coinbase");
810
811 // Rather not work on nonstandard transactions (unless -testnet/-regtest)
812 std::string reason;
813 if (m_pool.m_opts.require_standard && !IsStandardTx(tx, m_pool.m_opts.max_datacarrier_bytes, m_pool.m_opts.permit_bare_multisig, m_pool.m_opts.dust_relay_feerate, reason)) {
814 return state.Invalid(TxValidationResult::TX_NOT_STANDARD, reason);
815 }
816
817 // Transactions smaller than 65 non-witness bytes are not relayed to mitigate CVE-2017-12842.
819 return state.Invalid(TxValidationResult::TX_NOT_STANDARD, "tx-size-small");
820
821 // Only accept nLockTime-using transactions that can be mined in the next
822 // block; we don't want our mempool filled up with transactions that can't
823 // be mined yet.
824 if (!CheckFinalTxAtTip(*Assert(m_active_chainstate.m_chain.Tip()), tx)) {
825 return state.Invalid(TxValidationResult::TX_PREMATURE_SPEND, "non-final");
826 }
827
828 if (m_pool.exists(tx.GetWitnessHash())) {
829 // Exact transaction already exists in the mempool.
830 return state.Invalid(TxValidationResult::TX_CONFLICT, "txn-already-in-mempool");
831 } else if (m_pool.exists(tx.GetHash())) {
832 // Transaction with the same non-witness data but different witness (same txid, different
833 // wtxid) already exists in the mempool.
834 return state.Invalid(TxValidationResult::TX_CONFLICT, "txn-same-nonwitness-data-in-mempool");
835 }
836
837 // Check for conflicts with in-memory transactions
838 for (const CTxIn &txin : tx.vin)
839 {
840 const CTransaction* ptxConflicting = m_pool.GetConflictTx(txin.prevout);
841 if (ptxConflicting) {
842 if (!args.m_allow_replacement) {
843 // Transaction conflicts with a mempool tx, but we're not allowing replacements in this context.
844 return state.Invalid(TxValidationResult::TX_MEMPOOL_POLICY, "bip125-replacement-disallowed");
845 }
846 ws.m_conflicts.insert(ptxConflicting->GetHash());
847 }
848 }
849
850 m_view.SetBackend(m_viewmempool);
851
852 const CCoinsViewCache& coins_cache = m_active_chainstate.CoinsTip();
853 // do all inputs exist?
854 for (const CTxIn& txin : tx.vin) {
855 if (!coins_cache.HaveCoinInCache(txin.prevout)) {
856 coins_to_uncache.push_back(txin.prevout);
857 }
858
859 // Note: this call may add txin.prevout to the coins cache
860 // (coins_cache.cacheCoins) by way of FetchCoin(). It should be removed
861 // later (via coins_to_uncache) if this tx turns out to be invalid.
862 if (!m_view.HaveCoin(txin.prevout)) {
863 // Are inputs missing because we already have the tx?
864 for (size_t out = 0; out < tx.vout.size(); out++) {
865 // Optimistically just do efficient check of cache for outputs
866 if (coins_cache.HaveCoinInCache(COutPoint(hash, out))) {
867 return state.Invalid(TxValidationResult::TX_CONFLICT, "txn-already-known");
868 }
869 }
870 // Otherwise assume this might be an orphan tx for which we just haven't seen parents yet
871 return state.Invalid(TxValidationResult::TX_MISSING_INPUTS, "bad-txns-inputs-missingorspent");
872 }
873 }
874
875 // This is const, but calls into `CCoinsViewCache::GetBestBlock()` to refresh
876 // the cached best block through `m_viewmempool` after caching inputs.
877 (void)m_view.GetBestBlock();
878
879 // All required inputs are cached now, so switch m_view to the empty backend.
880 // This keeps already-fetched cache entries for later checks and prevents new
881 // backend lookups (which would avoid coins_to_uncache tracking).
882 m_view.SetBackend(CoinsViewEmpty::Get());
883
884 assert(m_active_chainstate.m_blockman.LookupBlockIndex(m_view.GetBestBlock()) == m_active_chainstate.m_chain.Tip());
885
886 // Only accept BIP68 sequence locked transactions that can be mined in the next
887 // block; we don't want our mempool filled up with transactions that can't
888 // be mined yet.
889 // Pass in m_view which has all of the relevant inputs cached. Note that, since m_view's
890 // backend was removed, it no longer pulls coins from the mempool.
891 const std::optional<LockPoints> lock_points{CalculateLockPointsAtTip(m_active_chainstate.m_chain.Tip(), m_view, tx)};
892 if (!lock_points.has_value() || !CheckSequenceLocksAtTip(m_active_chainstate.m_chain.Tip(), *lock_points)) {
893 return state.Invalid(TxValidationResult::TX_PREMATURE_SPEND, "non-BIP68-final");
894 }
895
896 // The mempool holds txs for the next block, so pass height+1 to CheckTxInputs
897 if (!Consensus::CheckTxInputs(tx, state, m_view, m_active_chainstate.m_chain.Height() + 1, ws.m_base_fees)) {
898 return false; // state filled in by CheckTxInputs
899 }
900
901 if (m_pool.m_opts.require_standard) {
902 state = ValidateInputsStandardness(tx, m_view);
903 if (state.IsInvalid()) {
904 return false;
905 }
906 }
907
908 // Check for non-standard witnesses.
909 if (tx.HasWitness() && m_pool.m_opts.require_standard && !IsWitnessStandard(tx, m_view)) {
910 return state.Invalid(TxValidationResult::TX_WITNESS_MUTATED, "bad-witness-nonstandard");
911 }
912
913 int64_t nSigOpsCost = GetTransactionSigOpCost(tx, m_view, STANDARD_SCRIPT_VERIFY_FLAGS);
914
915 // Keep track of transactions that spend a coinbase, which we re-scan
916 // during reorgs to ensure COINBASE_MATURITY is still met.
917 bool fSpendsCoinbase = false;
918 for (const CTxIn &txin : tx.vin) {
919 const Coin &coin = m_view.AccessCoin(txin.prevout);
920 if (coin.IsCoinBase()) {
921 fSpendsCoinbase = true;
922 break;
923 }
924 }
925
926 // Set entry_sequence to 0 when bypass_limits is used; this allows txs from a block
927 // reorg to be marked earlier than any child txs that were already in the mempool.
928 const uint64_t entry_sequence = bypass_limits ? 0 : m_pool.GetSequence();
929 if (!m_subpackage.m_changeset) {
930 m_subpackage.m_changeset = m_pool.GetChangeSet();
931 }
932 ws.m_tx_handle = m_subpackage.m_changeset->StageAddition(ptx, ws.m_base_fees, nAcceptTime, m_active_chainstate.m_chain.Height(), entry_sequence, fSpendsCoinbase, nSigOpsCost, lock_points.value());
933
934 // ws.m_modified_fees includes any fee deltas from PrioritiseTransaction
935 ws.m_modified_fees = ws.m_tx_handle->GetModifiedFee();
936
937 ws.m_vsize = ws.m_tx_handle->GetTxSize();
938
939 // Enforces 0-fee for dust transactions, no incentive to be mined alone
940 if (m_pool.m_opts.require_standard) {
941 if (!PreCheckEphemeralTx(*ptx, m_pool.m_opts.dust_relay_feerate, ws.m_base_fees, ws.m_modified_fees, state)) {
942 return false; // state filled in by PreCheckEphemeralTx
943 }
944 }
945
946 if (nSigOpsCost > MAX_STANDARD_TX_SIGOPS_COST)
947 return state.Invalid(TxValidationResult::TX_NOT_STANDARD, "bad-txns-too-many-sigops",
948 strprintf("%d", nSigOpsCost));
949
950 // No individual transactions are allowed below the mempool min feerate except from disconnected
951 // blocks and transactions in a package. Package transactions will be checked using package
952 // feerate later.
953 if (!bypass_limits && !args.m_package_feerates && !CheckFeeRate(ws.m_vsize, ws.m_modified_fees, state)) return false;
954
955 ws.m_iters_conflicting = m_pool.GetIterSet(ws.m_conflicts);
956
957 ws.m_parents = m_pool.GetParents(*ws.m_tx_handle);
958
959 if (!args.m_bypass_limits) {
960 // Perform the TRUC checks, using the in-mempool parents.
961 if (const auto err{SingleTRUCChecks(m_pool, ws.m_ptx, ws.m_parents, ws.m_conflicts, ws.m_vsize)}) {
962 // Single transaction contexts only.
963 if (args.m_allow_sibling_eviction && err->second != nullptr) {
964 // We should only be considering where replacement is considered valid as well.
965 Assume(args.m_allow_replacement);
966 // Potential sibling eviction. Add the sibling to our list of mempool conflicts to be
967 // included in RBF checks.
968 ws.m_conflicts.insert(err->second->GetHash());
969 // Adding the sibling to m_iters_conflicting here means that it doesn't count towards
970 // RBF Carve Out above. This is correct, since removing to-be-replaced transactions from
971 // the descendant count is done separately in SingleTRUCChecks for TRUC transactions.
972 ws.m_iters_conflicting.insert(m_pool.GetIter(err->second->GetHash()).value());
973 ws.m_sibling_eviction = true;
974 // The sibling will be treated as part of the to-be-replaced set in ReplacementChecks.
975 // Note that we are not checking whether it opts in to replaceability via BIP125 or TRUC
976 // (which is normally done in PreChecks). However, the only way a TRUC transaction can
977 // have a non-TRUC and non-BIP125 descendant is due to a reorg.
978 } else {
979 return state.Invalid(TxValidationResult::TX_MEMPOOL_POLICY, "TRUC-violation", err->first);
980 }
981 }
982 }
983
984 // We want to detect conflicts in any tx in a package to trigger package RBF logic
985 m_subpackage.m_rbf |= !ws.m_conflicts.empty();
986 return true;
987}
988
989bool MemPoolAccept::ReplacementChecks(Workspace& ws)
990{
992 AssertLockHeld(m_pool.cs);
993
994 const CTransaction& tx = *ws.m_ptx;
995 const Txid& hash = ws.m_hash;
996 TxValidationState& state = ws.m_state;
997
998 CTxMemPool::setEntries all_conflicts;
999
1000 // Calculate all conflicting entries and enforce Rule #5.
1001 if (const auto err_string{GetEntriesForConflicts(tx, m_pool, ws.m_iters_conflicting, all_conflicts)}) {
1003 strprintf("too many potential replacements%s", ws.m_sibling_eviction ? " (including sibling eviction)" : ""), *err_string);
1004 }
1005
1006 // Check if it's economically rational to mine this transaction rather than the ones it
1007 // replaces and pays for its own relay fees. Enforce Rules #3 and #4.
1008 for (CTxMemPool::txiter it : all_conflicts) {
1009 m_subpackage.m_conflicting_fees += it->GetModifiedFee();
1010 m_subpackage.m_conflicting_size += it->GetTxSize();
1011 }
1012
1013 if (const auto err_string{PaysForRBF(m_subpackage.m_conflicting_fees, ws.m_modified_fees, ws.m_vsize,
1014 m_pool.m_opts.incremental_relay_feerate, hash)}) {
1015 // Result may change in a package context
1017 strprintf("insufficient fee%s", ws.m_sibling_eviction ? " (including sibling eviction)" : ""), *err_string);
1018 }
1019
1020 // Add all the to-be-removed transactions to the changeset.
1021 for (auto it : all_conflicts) {
1022 m_subpackage.m_changeset->StageRemoval(it);
1023 }
1024
1025 // Run cluster size limit checks and fail if we exceed them.
1026 if (!m_subpackage.m_changeset->CheckMemPoolPolicyLimits()) {
1027 return state.Invalid(TxValidationResult::TX_MEMPOOL_POLICY, "too-large-cluster", "");
1028 }
1029
1030 if (const auto err_string{ImprovesFeerateDiagram(*m_subpackage.m_changeset)}) {
1031 // We checked above for the cluster size limits being respected, so a
1032 // failure here can only be due to an insufficient fee.
1033 Assume(err_string->first == DiagramCheckError::FAILURE);
1034 return state.Invalid(TxValidationResult::TX_RECONSIDERABLE, "replacement-failed", err_string->second);
1035 }
1036
1037 return true;
1038}
1039
1040bool MemPoolAccept::PackageRBFChecks(const std::vector<CTransactionRef>& txns,
1041 std::vector<Workspace>& workspaces,
1042 const int64_t total_vsize,
1043 PackageValidationState& package_state)
1044{
1046 AssertLockHeld(m_pool.cs);
1047
1048 assert(std::all_of(txns.cbegin(), txns.cend(), [this](const auto& tx)
1049 { return !m_pool.exists(tx->GetHash());}));
1050
1051 assert(txns.size() == workspaces.size());
1052
1053 // We're in package RBF context; replacement proposal must be size 2
1054 if (workspaces.size() != 2 || !Assume(IsChildWithParents(txns))) {
1055 return package_state.Invalid(PackageValidationResult::PCKG_POLICY, "package RBF failed: package must be 1-parent-1-child");
1056 }
1057
1058 // If the package has in-mempool parents, we won't consider a package RBF
1059 // since it would result in a cluster larger than 2.
1060 // N.B. To relax this constraint we will need to revisit how CCoinsViewMemPool::PackageAddTransaction
1061 // is being used inside AcceptMultipleTransactions to track available inputs while processing a package.
1062 // Specifically we would need to check that the ancestors of the new
1063 // transactions don't intersect with the set of transactions to be removed
1064 // due to RBF, which is not checked at all in the package acceptance
1065 // context.
1066 for (const auto& ws : workspaces) {
1067 if (!ws.m_parents.empty()) {
1068 return package_state.Invalid(PackageValidationResult::PCKG_POLICY, "package RBF failed: new transaction cannot have mempool ancestors");
1069 }
1070 }
1071
1072 // Aggregate all conflicts into one set.
1073 CTxMemPool::setEntries direct_conflict_iters;
1074 for (Workspace& ws : workspaces) {
1075 // Aggregate all conflicts into one set.
1076 direct_conflict_iters.merge(ws.m_iters_conflicting);
1077 }
1078
1079 const auto& parent_ws = workspaces[0];
1080 const auto& child_ws = workspaces[1];
1081
1082 // Don't consider replacements that would cause us to remove a large number of mempool entries.
1083 // This limit is not increased in a package RBF. Use the aggregate number of transactions.
1084 CTxMemPool::setEntries all_conflicts;
1085 if (const auto err_string{GetEntriesForConflicts(*child_ws.m_ptx, m_pool, direct_conflict_iters,
1086 all_conflicts)}) {
1087 return package_state.Invalid(PackageValidationResult::PCKG_POLICY,
1088 "package RBF failed: too many potential replacements", *err_string);
1089 }
1090
1091 for (CTxMemPool::txiter it : all_conflicts) {
1092 m_subpackage.m_changeset->StageRemoval(it);
1093 m_subpackage.m_conflicting_fees += it->GetModifiedFee();
1094 m_subpackage.m_conflicting_size += it->GetTxSize();
1095 }
1096
1097 // Use the child as the transaction for attributing errors to.
1098 const Txid& child_hash = child_ws.m_ptx->GetHash();
1099 if (const auto err_string{PaysForRBF(/*original_fees=*/m_subpackage.m_conflicting_fees,
1100 /*replacement_fees=*/m_subpackage.m_total_modified_fees,
1101 /*replacement_vsize=*/m_subpackage.m_total_vsize,
1102 m_pool.m_opts.incremental_relay_feerate, child_hash)}) {
1103 return package_state.Invalid(PackageValidationResult::PCKG_POLICY,
1104 "package RBF failed: insufficient anti-DoS fees", *err_string);
1105 }
1106
1107 // Ensure this two transaction package is a "chunk" on its own; we don't want the child
1108 // to be only paying anti-DoS fees
1109 const CFeeRate parent_feerate(parent_ws.m_modified_fees, parent_ws.m_vsize);
1110 const CFeeRate package_feerate(m_subpackage.m_total_modified_fees, m_subpackage.m_total_vsize);
1111 if (package_feerate <= parent_feerate) {
1112 return package_state.Invalid(PackageValidationResult::PCKG_POLICY,
1113 "package RBF failed: package feerate is less than or equal to parent feerate",
1114 strprintf("package feerate %s <= parent feerate is %s", package_feerate.ToString(), parent_feerate.ToString()));
1115 }
1116
1117 // Run cluster size limit checks and fail if we exceed them.
1118 if (!m_subpackage.m_changeset->CheckMemPoolPolicyLimits()) {
1119 return package_state.Invalid(PackageValidationResult::PCKG_POLICY, "too-large-cluster", "");
1120 }
1121
1122 // Check if it's economically rational to mine this package rather than the ones it replaces.
1123 if (const auto err_tup{ImprovesFeerateDiagram(*m_subpackage.m_changeset)}) {
1124 Assume(err_tup->first == DiagramCheckError::FAILURE);
1125 return package_state.Invalid(PackageValidationResult::PCKG_POLICY,
1126 "package RBF failed: " + err_tup.value().second, "");
1127 }
1128
1129 LogDebug(BCLog::TXPACKAGES, "package RBF checks passed: parent %s (wtxid=%s), child %s (wtxid=%s), package hash (%s)\n",
1130 txns.front()->GetHash().ToString(), txns.front()->GetWitnessHash().ToString(),
1131 txns.back()->GetHash().ToString(), txns.back()->GetWitnessHash().ToString(),
1132 GetPackageHash(txns).ToString());
1133
1134
1135 return true;
1136}
1137
1138bool MemPoolAccept::PolicyScriptChecks(const ATMPArgs& args, Workspace& ws)
1139{
1141 AssertLockHeld(m_pool.cs);
1142 const CTransaction& tx = *ws.m_ptx;
1143 TxValidationState& state = ws.m_state;
1144
1145 constexpr script_verify_flags scriptVerifyFlags = STANDARD_SCRIPT_VERIFY_FLAGS;
1146
1147 // Check input scripts and signatures.
1148 // This is done last to help prevent CPU exhaustion denial-of-service attacks.
1149 if (!CheckInputScripts(tx, state, m_view, scriptVerifyFlags, true, false, ws.m_precomputed_txdata, GetValidationCache())) {
1150 // Detect a failure due to a missing witness so that p2p code can handle rejection caching appropriately.
1151 if (!tx.HasWitness() && SpendsNonAnchorWitnessProg(tx, m_view)) {
1153 state.GetRejectReason(), state.GetDebugMessage());
1154 }
1155 return false; // state filled in by CheckInputScripts
1156 }
1157
1158 return true;
1159}
1160
1161bool MemPoolAccept::ConsensusScriptChecks(const ATMPArgs& args, Workspace& ws)
1162{
1164 AssertLockHeld(m_pool.cs);
1165 const CTransaction& tx = *ws.m_ptx;
1166 const Txid& hash = ws.m_hash;
1167 TxValidationState& state = ws.m_state;
1168
1169 // Check again against the current block tip's script verification
1170 // flags to cache our script execution flags. This is, of course,
1171 // useless if the next block has different script flags from the
1172 // previous one, but because the cache tracks script flags for us it
1173 // will auto-invalidate and we'll just have a few blocks of extra
1174 // misses on soft-fork activation.
1175 //
1176 // This is also useful in case of bugs in the standard flags that cause
1177 // transactions to pass as valid when they're actually invalid. For
1178 // instance the STRICTENC flag was incorrectly allowing certain
1179 // CHECKSIG NOT scripts to pass, even though they were invalid.
1180 //
1181 // There is a similar check in CreateNewBlock() to prevent creating
1182 // invalid blocks (using TestBlockValidity), however allowing such
1183 // transactions into the mempool can be exploited as a DoS attack.
1184 script_verify_flags currentBlockScriptVerifyFlags{GetBlockScriptFlags(*m_active_chainstate.m_chain.Tip(), m_active_chainstate.m_chainman)};
1185 if (!CheckInputsFromMempoolAndCache(tx, state, m_view, m_pool, currentBlockScriptVerifyFlags,
1186 ws.m_precomputed_txdata, m_active_chainstate.CoinsTip(), GetValidationCache())) {
1187 LogError("BUG! PLEASE REPORT THIS! CheckInputScripts failed against latest-block but not STANDARD flags %s, %s", hash.ToString(), state.ToString());
1188 return Assume(false);
1189 }
1190
1191 return true;
1192}
1193
1194void MemPoolAccept::FinalizeSubpackage(const ATMPArgs& args)
1195{
1197 AssertLockHeld(m_pool.cs);
1198
1199 if (!m_subpackage.m_changeset->GetRemovals().empty()) Assume(args.m_allow_replacement);
1200 // Remove conflicting transactions from the mempool
1201 for (CTxMemPool::txiter it : m_subpackage.m_changeset->GetRemovals())
1202 {
1203 std::string log_string = strprintf("replacing mempool tx %s (wtxid=%s, fees=%s, vsize=%s). ",
1204 it->GetTx().GetHash().ToString(),
1205 it->GetTx().GetWitnessHash().ToString(),
1206 it->GetFee(),
1207 it->GetTxSize());
1208 FeeFrac feerate{m_subpackage.m_total_modified_fees, int32_t(m_subpackage.m_total_vsize)};
1209 uint256 tx_or_package_hash{};
1210 const bool replaced_with_tx{m_subpackage.m_changeset->GetTxCount() == 1};
1211 if (replaced_with_tx) {
1212 const CTransaction& tx = m_subpackage.m_changeset->GetAddedTxn(0);
1213 tx_or_package_hash = tx.GetHash().ToUint256();
1214 log_string += strprintf("New tx %s (wtxid=%s, fees=%s, vsize=%s)",
1215 tx.GetHash().ToString(),
1216 tx.GetWitnessHash().ToString(),
1217 feerate.fee,
1218 feerate.size);
1219 } else {
1220 tx_or_package_hash = GetPackageHash(m_subpackage.m_changeset->GetAddedTxns());
1221 log_string += strprintf("New package %s with %lu txs, fees=%s, vsize=%s",
1222 tx_or_package_hash.ToString(),
1223 m_subpackage.m_changeset->GetTxCount(),
1224 feerate.fee,
1225 feerate.size);
1226
1227 }
1228 LogDebug(BCLog::MEMPOOL, "%s\n", log_string);
1229 TRACEPOINT(mempool, replaced,
1230 it->GetTx().GetHash().data(),
1231 it->GetTxSize(),
1232 it->GetFee(),
1233 std::chrono::duration_cast<std::chrono::duration<std::uint64_t>>(it->GetTime()).count(),
1234 tx_or_package_hash.data(),
1235 feerate.size,
1236 feerate.fee,
1237 replaced_with_tx
1238 );
1239 m_subpackage.m_replaced_transactions.push_back(it->GetSharedTx());
1240 }
1241 m_subpackage.m_changeset->Apply();
1242 m_subpackage.m_changeset.reset();
1243}
1244
1245bool MemPoolAccept::SubmitPackage(const ATMPArgs& args, std::vector<Workspace>& workspaces,
1246 PackageValidationState& package_state,
1247 std::map<Wtxid, MempoolAcceptResult>& results)
1248{
1250 AssertLockHeld(m_pool.cs);
1251 // Sanity check: none of the transactions should be in the mempool, and none of the transactions
1252 // should have a same-txid-different-witness equivalent in the mempool.
1253 assert(std::all_of(workspaces.cbegin(), workspaces.cend(), [this](const auto& ws) { return !m_pool.exists(ws.m_ptx->GetHash()); }));
1254
1255 bool all_submitted = true;
1256 FinalizeSubpackage(args);
1257 // ConsensusScriptChecks adds to the script cache and is therefore consensus-critical;
1258 // CheckInputsFromMempoolAndCache asserts that transactions only spend coins available from the
1259 // mempool or UTXO set. Submit each transaction to the mempool immediately after calling
1260 // ConsensusScriptChecks to make the outputs available for subsequent transactions.
1261 for (Workspace& ws : workspaces) {
1262 if (!ConsensusScriptChecks(args, ws)) {
1263 results.emplace(ws.m_ptx->GetWitnessHash(), MempoolAcceptResult::Failure(ws.m_state));
1264 // Since PolicyScriptChecks() passed, this should never fail.
1265 Assume(false);
1266 all_submitted = false;
1268 strprintf("BUG! PolicyScriptChecks succeeded but ConsensusScriptChecks failed: %s",
1269 ws.m_ptx->GetHash().ToString()));
1270 }
1271 // Remove first failing tx and all subsequent in package
1272 if (!all_submitted) {
1273 if (!m_subpackage.m_changeset) m_subpackage.m_changeset = m_pool.GetChangeSet();
1274 m_subpackage.m_changeset->StageRemoval(m_pool.GetIter(ws.m_ptx->GetHash()).value());
1275 }
1276 }
1277 if (!all_submitted) {
1278 Assume(m_subpackage.m_changeset);
1279 // This code should be unreachable; it's here as belt-and-suspenders
1280 // to try to ensure we have no consensus-invalid transactions in the
1281 // mempool.
1282 m_subpackage.m_changeset->Apply();
1283 m_subpackage.m_changeset.reset();
1284 return false;
1285 }
1286
1287 std::vector<Wtxid> all_package_wtxids;
1288 all_package_wtxids.reserve(workspaces.size());
1289 std::transform(workspaces.cbegin(), workspaces.cend(), std::back_inserter(all_package_wtxids),
1290 [](const auto& ws) { return ws.m_ptx->GetWitnessHash(); });
1291
1292 if (!m_subpackage.m_replaced_transactions.empty()) {
1293 LogDebug(BCLog::MEMPOOL, "replaced %u mempool transactions with %u new one(s) for %s additional fees, %d delta bytes\n",
1294 m_subpackage.m_replaced_transactions.size(), workspaces.size(),
1295 m_subpackage.m_total_modified_fees - m_subpackage.m_conflicting_fees,
1296 m_subpackage.m_total_vsize - static_cast<int>(m_subpackage.m_conflicting_size));
1297 }
1298
1299 // Add successful results. The returned results may change later if LimitMempoolSize() evicts them.
1300 for (Workspace& ws : workspaces) {
1301 auto iter = m_pool.GetIter(ws.m_ptx->GetHash());
1302 Assume(iter.has_value());
1303 const auto effective_feerate = args.m_package_feerates ? ws.m_package_feerate :
1304 CFeeRate{ws.m_modified_fees, static_cast<int32_t>(ws.m_vsize)};
1305 const auto effective_feerate_wtxids = args.m_package_feerates ? all_package_wtxids :
1306 std::vector<Wtxid>{ws.m_ptx->GetWitnessHash()};
1307 results.emplace(ws.m_ptx->GetWitnessHash(),
1308 MempoolAcceptResult::Success(std::move(m_subpackage.m_replaced_transactions), ws.m_vsize,
1309 ws.m_base_fees, effective_feerate, effective_feerate_wtxids));
1310 if (!m_pool.m_opts.signals) continue;
1311 const CTransaction& tx = *ws.m_ptx;
1312 const auto tx_info = NewMempoolTransactionInfo(ws.m_ptx, ws.m_base_fees,
1313 ws.m_vsize, (*iter)->GetHeight(),
1314 args.m_bypass_limits, args.m_package_submission,
1315 IsCurrentForFeeEstimation(m_active_chainstate),
1316 m_pool.HasNoInputsOf(tx));
1317 m_pool.m_opts.signals->TransactionAddedToMempool(tx_info, m_pool.GetAndIncrementSequence());
1318 }
1319 return all_submitted;
1320}
1321
1322MempoolAcceptResult MemPoolAccept::AcceptSingleTransactionInternal(const CTransactionRef& ptx, ATMPArgs& args)
1323{
1325 AssertLockHeld(m_pool.cs);
1326
1327 Workspace ws(ptx);
1328 const std::vector<Wtxid> single_wtxid{ws.m_ptx->GetWitnessHash()};
1329
1330 if (!PreChecks(args, ws)) {
1331 if (ws.m_state.GetResult() == TxValidationResult::TX_RECONSIDERABLE) {
1332 // Failed for fee reasons. Provide the effective feerate and which tx was included.
1333 return MempoolAcceptResult::FeeFailure(ws.m_state, CFeeRate(ws.m_modified_fees, ws.m_vsize), single_wtxid);
1334 }
1335 return MempoolAcceptResult::Failure(ws.m_state);
1336 }
1337
1338 if (m_subpackage.m_rbf && !ReplacementChecks(ws)) {
1339 if (ws.m_state.GetResult() == TxValidationResult::TX_RECONSIDERABLE) {
1340 // Failed for incentives-based fee reasons. Provide the effective feerate and which tx was included.
1341 return MempoolAcceptResult::FeeFailure(ws.m_state, CFeeRate(ws.m_modified_fees, ws.m_vsize), single_wtxid);
1342 }
1343 return MempoolAcceptResult::Failure(ws.m_state);
1344 }
1345
1346 // Check if the transaction would exceed the cluster size limit.
1347 if (!m_subpackage.m_changeset->CheckMemPoolPolicyLimits()) {
1348 ws.m_state.Invalid(TxValidationResult::TX_MEMPOOL_POLICY, "too-large-cluster", "");
1349 return MempoolAcceptResult::Failure(ws.m_state);
1350 }
1351
1352 // Now that we've verified the cluster limit is respected, we can perform
1353 // calculations involving the full ancestors of the tx.
1354 if (ws.m_conflicts.size()) {
1355 auto ancestors = m_subpackage.m_changeset->CalculateMemPoolAncestors(ws.m_tx_handle);
1356
1357 // A transaction that spends outputs that would be replaced by it is invalid. Now
1358 // that we have the set of all ancestors we can detect this
1359 // pathological case by making sure ws.m_conflicts and this tx's ancestors don't
1360 // intersect.
1361 if (const auto err_string{EntriesAndTxidsDisjoint(ancestors, ws.m_conflicts, ptx->GetHash())}) {
1362 // We classify this as a consensus error because a transaction depending on something it
1363 // conflicts with would be inconsistent.
1364 ws.m_state.Invalid(TxValidationResult::TX_CONSENSUS, "bad-txns-spends-conflicting-tx", *err_string);
1365 return MempoolAcceptResult::Failure(ws.m_state);
1366 }
1367 }
1368
1369 m_subpackage.m_total_vsize = ws.m_vsize;
1370 m_subpackage.m_total_modified_fees = ws.m_modified_fees;
1371
1372 // Individual modified feerate exceeded caller-defined max; abort
1373 if (args.m_client_maxfeerate && CFeeRate(ws.m_modified_fees, ws.m_vsize) > args.m_client_maxfeerate.value()) {
1374 ws.m_state.Invalid(TxValidationResult::TX_MEMPOOL_POLICY, "max feerate exceeded", "");
1375 return MempoolAcceptResult::Failure(ws.m_state);
1376 }
1377
1378 if (!args.m_bypass_limits && m_pool.m_opts.require_standard) {
1379 Wtxid dummy_wtxid;
1380 if (!CheckEphemeralSpends(/*package=*/{ptx}, m_pool.m_opts.dust_relay_feerate, m_pool, ws.m_state, dummy_wtxid)) {
1381 return MempoolAcceptResult::Failure(ws.m_state);
1382 }
1383 }
1384
1385 // Perform the inexpensive checks first and avoid hashing and signature verification unless
1386 // those checks pass, to mitigate CPU exhaustion denial-of-service attacks.
1387 if (!PolicyScriptChecks(args, ws)) return MempoolAcceptResult::Failure(ws.m_state);
1388
1389 if (!ConsensusScriptChecks(args, ws)) return MempoolAcceptResult::Failure(ws.m_state);
1390
1391 const CFeeRate effective_feerate{ws.m_modified_fees, static_cast<int32_t>(ws.m_vsize)};
1392 // Tx was accepted, but not added
1393 if (args.m_test_accept) {
1394 return MempoolAcceptResult::Success(std::move(m_subpackage.m_replaced_transactions), ws.m_vsize,
1395 ws.m_base_fees, effective_feerate, single_wtxid);
1396 }
1397
1398 FinalizeSubpackage(args);
1399
1400 // Limit the mempool, if appropriate.
1401 if (!args.m_package_submission && !args.m_bypass_limits) {
1402 LimitMempoolSize(m_pool, m_active_chainstate.CoinsTip());
1403 // If mempool contents change, then the m_view cache is dirty. Given this isn't a package
1404 // submission, we won't be using the cache anymore, but clear it anyway for clarity.
1405 CleanupTemporaryCoins();
1406
1407 if (!m_pool.exists(ws.m_hash)) {
1408 // The tx no longer meets our (new) mempool minimum feerate but could be reconsidered in a package.
1409 ws.m_state.Invalid(TxValidationResult::TX_RECONSIDERABLE, "mempool full");
1410 return MempoolAcceptResult::FeeFailure(ws.m_state, CFeeRate(ws.m_modified_fees, ws.m_vsize), {ws.m_ptx->GetWitnessHash()});
1411 }
1412 }
1413
1414 if (m_pool.m_opts.signals) {
1415 const CTransaction& tx = *ws.m_ptx;
1416 auto iter = m_pool.GetIter(tx.GetHash());
1417 Assume(iter.has_value());
1418 const auto tx_info = NewMempoolTransactionInfo(ws.m_ptx, ws.m_base_fees,
1419 ws.m_vsize, (*iter)->GetHeight(),
1420 args.m_bypass_limits, args.m_package_submission,
1421 IsCurrentForFeeEstimation(m_active_chainstate),
1422 m_pool.HasNoInputsOf(tx));
1423 m_pool.m_opts.signals->TransactionAddedToMempool(tx_info, m_pool.GetAndIncrementSequence());
1424 }
1425
1426 if (!m_subpackage.m_replaced_transactions.empty()) {
1427 LogDebug(BCLog::MEMPOOL, "replaced %u mempool transactions with 1 new transaction for %s additional fees, %d delta bytes\n",
1428 m_subpackage.m_replaced_transactions.size(),
1429 ws.m_modified_fees - m_subpackage.m_conflicting_fees,
1430 ws.m_vsize - static_cast<int>(m_subpackage.m_conflicting_size));
1431 }
1432
1433 return MempoolAcceptResult::Success(std::move(m_subpackage.m_replaced_transactions), ws.m_vsize, ws.m_base_fees,
1434 effective_feerate, single_wtxid);
1435}
1436
1437PackageMempoolAcceptResult MemPoolAccept::AcceptMultipleTransactionsInternal(const std::vector<CTransactionRef>& txns, ATMPArgs& args)
1438{
1440 AssertLockHeld(m_pool.cs);
1441
1442 // These context-free package limits can be done before taking the mempool lock.
1443 PackageValidationState package_state;
1444 if (!IsWellFormedPackage(txns, package_state)) return PackageMempoolAcceptResult(package_state, {});
1445
1446 std::vector<Workspace> workspaces{};
1447 workspaces.reserve(txns.size());
1448 std::transform(txns.cbegin(), txns.cend(), std::back_inserter(workspaces),
1449 [](const auto& tx) { return Workspace(tx); });
1450 std::map<Wtxid, MempoolAcceptResult> results;
1451
1452 // Do all PreChecks first and fail fast to avoid running expensive script checks when unnecessary.
1453 for (Workspace& ws : workspaces) {
1454 if (!PreChecks(args, ws)) {
1455 package_state.Invalid(PackageValidationResult::PCKG_TX, "transaction failed");
1456 // Exit early to avoid doing pointless work. Update the failed tx result; the rest are unfinished.
1457 results.emplace(ws.m_ptx->GetWitnessHash(), MempoolAcceptResult::Failure(ws.m_state));
1458 return PackageMempoolAcceptResult(package_state, std::move(results));
1459 }
1460
1461 // Individual modified feerate exceeded caller-defined max; abort
1462 // N.B. this doesn't take into account CPFPs. Chunk-aware validation may be more robust.
1463 if (args.m_client_maxfeerate && CFeeRate(ws.m_modified_fees, ws.m_vsize) > args.m_client_maxfeerate.value()) {
1464 // Need to set failure here both individually and at package level
1465 ws.m_state.Invalid(TxValidationResult::TX_MEMPOOL_POLICY, "max feerate exceeded", "");
1466 package_state.Invalid(PackageValidationResult::PCKG_TX, "transaction failed");
1467 // Exit early to avoid doing pointless work. Update the failed tx result; the rest are unfinished.
1468 results.emplace(ws.m_ptx->GetWitnessHash(), MempoolAcceptResult::Failure(ws.m_state));
1469 return PackageMempoolAcceptResult(package_state, std::move(results));
1470 }
1471
1472 // Make the coins created by this transaction available for subsequent transactions in the
1473 // package to spend. If there are no conflicts within the package, no transaction can spend a coin
1474 // needed by another transaction in the package. We also need to make sure that no package
1475 // tx replaces (or replaces the ancestor of) the parent of another package tx. As long as we
1476 // check these two things, we don't need to track the coins spent.
1477 // If a package tx conflicts with a mempool tx, PackageRBFChecks() ensures later that any package RBF attempt
1478 // has *no* in-mempool ancestors, so we don't have to worry about subsequent transactions in
1479 // same package spending the same in-mempool outpoints. This needs to be revisited for general
1480 // package RBF.
1481 m_viewmempool.PackageAddTransaction(ws.m_ptx);
1482 }
1483
1484 // At this point we have all in-mempool parents, and we know every transaction's vsize.
1485 // Run the TRUC checks on the package.
1486 for (Workspace& ws : workspaces) {
1487 if (auto err{PackageTRUCChecks(m_pool, ws.m_ptx, ws.m_vsize, txns, ws.m_parents)}) {
1488 package_state.Invalid(PackageValidationResult::PCKG_POLICY, "TRUC-violation", err.value());
1489 return PackageMempoolAcceptResult(package_state, {});
1490 }
1491 }
1492
1493 // Transactions must meet two minimum feerates: the mempool minimum fee and min relay fee.
1494 // For transactions consisting of exactly one child and its parents, it suffices to use the
1495 // package feerate (total modified fees / total virtual size) to check this requirement.
1496 // Note that this is an aggregate feerate; this function has not checked that there are transactions
1497 // too low feerate to pay for themselves, or that the child transactions are higher feerate than
1498 // their parents. Using aggregate feerate may allow "parents pay for child" behavior and permit
1499 // a child that is below mempool minimum feerate. To avoid these behaviors, callers of
1500 // AcceptMultipleTransactions need to restrict txns topology (e.g. to ancestor sets) and check
1501 // the feerates of individuals and subsets.
1502 m_subpackage.m_total_vsize = std::accumulate(workspaces.cbegin(), workspaces.cend(), int64_t{0},
1503 [](int64_t sum, auto& ws) { return sum + ws.m_vsize; });
1504 m_subpackage.m_total_modified_fees = std::accumulate(workspaces.cbegin(), workspaces.cend(), CAmount{0},
1505 [](CAmount sum, auto& ws) { return sum + ws.m_modified_fees; });
1506 const CFeeRate package_feerate(m_subpackage.m_total_modified_fees, m_subpackage.m_total_vsize);
1507 std::vector<Wtxid> all_package_wtxids;
1508 all_package_wtxids.reserve(workspaces.size());
1509 std::transform(workspaces.cbegin(), workspaces.cend(), std::back_inserter(all_package_wtxids),
1510 [](const auto& ws) { return ws.m_ptx->GetWitnessHash(); });
1511 TxValidationState placeholder_state;
1512 if (args.m_package_feerates &&
1513 !CheckFeeRate(m_subpackage.m_total_vsize, m_subpackage.m_total_modified_fees, placeholder_state)) {
1514 package_state.Invalid(PackageValidationResult::PCKG_TX, "transaction failed");
1515 return PackageMempoolAcceptResult(package_state, {{workspaces.back().m_ptx->GetWitnessHash(),
1516 MempoolAcceptResult::FeeFailure(placeholder_state, CFeeRate(m_subpackage.m_total_modified_fees, m_subpackage.m_total_vsize), all_package_wtxids)}});
1517 }
1518
1519 // Apply package mempool RBF checks.
1520 if (m_subpackage.m_rbf && !PackageRBFChecks(txns, workspaces, m_subpackage.m_total_vsize, package_state)) {
1521 return PackageMempoolAcceptResult(package_state, std::move(results));
1522 }
1523
1524 // Check if the transactions would exceed the cluster size limit.
1525 if (!m_subpackage.m_changeset->CheckMemPoolPolicyLimits()) {
1526 package_state.Invalid(PackageValidationResult::PCKG_POLICY, "too-large-cluster", "");
1527 return PackageMempoolAcceptResult(package_state, std::move(results));
1528 }
1529
1530 // Now that we've bounded the resulting possible ancestry count, check package for dust spends
1531 if (m_pool.m_opts.require_standard) {
1532 TxValidationState child_state;
1533 Wtxid child_wtxid;
1534 if (!CheckEphemeralSpends(txns, m_pool.m_opts.dust_relay_feerate, m_pool, child_state, child_wtxid)) {
1535 package_state.Invalid(PackageValidationResult::PCKG_TX, "unspent-dust");
1536 results.emplace(child_wtxid, MempoolAcceptResult::Failure(child_state));
1537 return PackageMempoolAcceptResult(package_state, std::move(results));
1538 }
1539 }
1540
1541 for (Workspace& ws : workspaces) {
1542 ws.m_package_feerate = package_feerate;
1543 if (!PolicyScriptChecks(args, ws)) {
1544 // Exit early to avoid doing pointless work. Update the failed tx result; the rest are unfinished.
1545 package_state.Invalid(PackageValidationResult::PCKG_TX, "transaction failed");
1546 results.emplace(ws.m_ptx->GetWitnessHash(), MempoolAcceptResult::Failure(ws.m_state));
1547 return PackageMempoolAcceptResult(package_state, std::move(results));
1548 }
1549 if (args.m_test_accept) {
1550 const auto effective_feerate = args.m_package_feerates ? ws.m_package_feerate :
1551 CFeeRate{ws.m_modified_fees, static_cast<int32_t>(ws.m_vsize)};
1552 const auto effective_feerate_wtxids = args.m_package_feerates ? all_package_wtxids :
1553 std::vector<Wtxid>{ws.m_ptx->GetWitnessHash()};
1554 results.emplace(ws.m_ptx->GetWitnessHash(),
1555 MempoolAcceptResult::Success(std::move(m_subpackage.m_replaced_transactions),
1556 ws.m_vsize, ws.m_base_fees, effective_feerate,
1557 effective_feerate_wtxids));
1558 }
1559 }
1560
1561 if (args.m_test_accept) return PackageMempoolAcceptResult(package_state, std::move(results));
1562
1563 if (!SubmitPackage(args, workspaces, package_state, results)) {
1564 // PackageValidationState filled in by SubmitPackage().
1565 return PackageMempoolAcceptResult(package_state, std::move(results));
1566 }
1567
1568 return PackageMempoolAcceptResult(package_state, std::move(results));
1569}
1570
1571void MemPoolAccept::CleanupTemporaryCoins()
1572{
1573 // There are 3 kinds of coins in m_view:
1574 // (1) Temporary coins from the transactions in subpackage, constructed by m_viewmempool.
1575 // (2) Mempool coins from transactions in the mempool, constructed by m_viewmempool.
1576 // (3) Confirmed coins fetched from our current UTXO set.
1577 //
1578 // (1) Temporary coins need to be removed, regardless of whether the transaction was submitted.
1579 // If the transaction was submitted to the mempool, m_viewmempool will be able to fetch them from
1580 // there. If it wasn't submitted to mempool, it is incorrect to keep them - future calls may try
1581 // to spend those coins that don't actually exist.
1582 // (2) Mempool coins also need to be removed. If the mempool contents have changed as a result
1583 // of submitting or replacing transactions, coins previously fetched from mempool may now be
1584 // spent or nonexistent. Those coins need to be deleted from m_view.
1585 // (3) Confirmed coins don't need to be removed. The chainstate has not changed (we are
1586 // holding cs_main and no blocks have been processed) so the confirmed tx cannot disappear like
1587 // a mempool tx can. The coin may now be spent after we submitted a tx to mempool, but
1588 // we have already checked that the package does not have 2 transactions spending the same coin
1589 // and we check whether a mempool transaction spends conflicting coins (CTxMemPool::GetConflictTx).
1590 // Keeping them in m_view is an optimization to not re-fetch confirmed coins if we later look up
1591 // inputs for this transaction again.
1592 for (const auto& outpoint : m_viewmempool.GetNonBaseCoins()) {
1593 // In addition to resetting m_viewmempool, we also need to manually delete these coins from
1594 // m_view because it caches copies of the coins it fetched from m_viewmempool previously.
1595 m_view.Uncache(outpoint);
1596 }
1597 // This deletes the temporary and mempool coins.
1598 m_viewmempool.Reset();
1599}
1600
1601PackageMempoolAcceptResult MemPoolAccept::AcceptSubPackage(const std::vector<CTransactionRef>& subpackage, ATMPArgs& args)
1602{
1604 AssertLockHeld(m_pool.cs);
1605 auto result = [&]() EXCLUSIVE_LOCKS_REQUIRED(::cs_main, m_pool.cs) {
1606 if (subpackage.size() > 1) {
1607 return AcceptMultipleTransactionsInternal(subpackage, args);
1608 }
1609 const auto& tx = subpackage.front();
1610 ATMPArgs single_args = ATMPArgs::SingleInPackageAccept(args);
1611 const auto single_res = AcceptSingleTransactionInternal(tx, single_args);
1612 PackageValidationState package_state_wrapped;
1613 if (single_res.m_result_type != MempoolAcceptResult::ResultType::VALID) {
1614 package_state_wrapped.Invalid(PackageValidationResult::PCKG_TX, "transaction failed");
1615 }
1616 return PackageMempoolAcceptResult(package_state_wrapped, {{tx->GetWitnessHash(), single_res}});
1617 }();
1618
1619 // Clean up m_view and m_viewmempool so that other subpackage evaluations don't have access to
1620 // coins they shouldn't. Keep some coins in order to minimize re-fetching coins from the UTXO set.
1621 // Clean up package feerate and rbf calculations
1622 ClearSubPackageState();
1623
1624 return result;
1625}
1626
1627PackageMempoolAcceptResult MemPoolAccept::AcceptPackage(const Package& package, ATMPArgs& args)
1628{
1629 Assert(!package.empty());
1631 // Used if returning a PackageMempoolAcceptResult directly from this function.
1632 PackageValidationState package_state_quit_early;
1633
1634 // There are two topologies we are able to handle through this function:
1635 // (1) A single transaction
1636 // (2) A child-with-parents package.
1637 // Check that the package is well-formed. If it isn't, we won't try to validate any of the
1638 // transactions and thus won't return any MempoolAcceptResults, just a package-wide error.
1639
1640 // Context-free package checks.
1641 if (!IsWellFormedPackage(package, package_state_quit_early)) {
1642 return PackageMempoolAcceptResult(package_state_quit_early, {});
1643 }
1644
1645 if (package.size() > 1 && !IsChildWithParents(package)) {
1646 // All transactions in the package must be a parent of the last transaction. This is just an
1647 // opportunity for us to fail fast on a context-free check without taking the mempool lock.
1648 package_state_quit_early.Invalid(PackageValidationResult::PCKG_POLICY, "package-not-child-with-parents");
1649 return PackageMempoolAcceptResult(package_state_quit_early, {});
1650 }
1651
1652 LOCK(m_pool.cs);
1653 // Stores results from which we will create the returned PackageMempoolAcceptResult.
1654 // A result may be changed if a mempool transaction is evicted later due to LimitMempoolSize().
1655 std::map<Wtxid, MempoolAcceptResult> results_final;
1656 // Results from individual validation which will be returned if no other result is available for
1657 // this transaction. "Nonfinal" because if a transaction fails by itself but succeeds later
1658 // (i.e. when evaluated with a fee-bumping child), the result in this map may be discarded.
1659 std::map<Wtxid, MempoolAcceptResult> individual_results_nonfinal;
1660 // Tracks whether we think package submission could result in successful entry to the mempool
1661 bool quit_early{false};
1662 std::vector<CTransactionRef> txns_package_eval;
1663 for (const auto& tx : package) {
1664 const auto& wtxid = tx->GetWitnessHash();
1665 const auto& txid = tx->GetHash();
1666 // There are 3 possibilities: already in mempool, same-txid-diff-wtxid already in mempool,
1667 // or not in mempool. An already confirmed tx is treated as one not in mempool, because all
1668 // we know is that the inputs aren't available.
1669 if (m_pool.exists(wtxid)) {
1670 // Exact transaction already exists in the mempool.
1671 // Node operators are free to set their mempool policies however they please, nodes may receive
1672 // transactions in different orders, and malicious counterparties may try to take advantage of
1673 // policy differences to pin or delay propagation of transactions. As such, it's possible for
1674 // some package transaction(s) to already be in the mempool, and we don't want to reject the
1675 // entire package in that case (as that could be a censorship vector). De-duplicate the
1676 // transactions that are already in the mempool, and only call AcceptMultipleTransactions() with
1677 // the new transactions. This ensures we don't double-count transaction counts and sizes when
1678 // checking ancestor/descendant limits, or double-count transaction fees for fee-related policy.
1679 const auto& entry{*Assert(m_pool.GetEntry(txid))};
1680 results_final.emplace(wtxid, MempoolAcceptResult::MempoolTx(entry.GetTxSize(), entry.GetFee()));
1681 } else if (m_pool.exists(txid)) {
1682 // Transaction with the same non-witness data but different witness (same txid,
1683 // different wtxid) already exists in the mempool.
1684 //
1685 // We don't allow replacement transactions right now, so just swap the package
1686 // transaction for the mempool one. Note that we are ignoring the validity of the
1687 // package transaction passed in.
1688 // TODO: allow witness replacement in packages.
1689 const auto& entry{*Assert(m_pool.GetEntry(txid))};
1690 // Provide the wtxid of the mempool tx so that the caller can look it up in the mempool.
1691 results_final.emplace(wtxid, MempoolAcceptResult::MempoolTxDifferentWitness(entry.GetTx().GetWitnessHash()));
1692 } else {
1693 // Transaction does not already exist in the mempool.
1694 // Try submitting the transaction on its own.
1695 const auto single_package_res = AcceptSubPackage({tx}, args);
1696 const auto& single_res = single_package_res.m_tx_results.at(wtxid);
1697 if (single_res.m_result_type == MempoolAcceptResult::ResultType::VALID) {
1698 // The transaction succeeded on its own and is now in the mempool. Don't include it
1699 // in package validation, because its fees should only be "used" once.
1700 assert(m_pool.exists(wtxid));
1701 results_final.emplace(wtxid, single_res);
1702 } else if (package.size() == 1 || // If there is only one transaction, no need to retry it "as a package"
1703 (single_res.m_state.GetResult() != TxValidationResult::TX_RECONSIDERABLE &&
1704 single_res.m_state.GetResult() != TxValidationResult::TX_MISSING_INPUTS)) {
1705 // Package validation policy only differs from individual policy in its evaluation
1706 // of feerate. For example, if a transaction fails here due to violation of a
1707 // consensus rule, the result will not change when it is submitted as part of a
1708 // package. To minimize the amount of repeated work, unless the transaction fails
1709 // due to feerate or missing inputs (its parent is a previous transaction in the
1710 // package that failed due to feerate), don't run package validation. Note that this
1711 // decision might not make sense if different types of packages are allowed in the
1712 // future. Continue individually validating the rest of the transactions, because
1713 // some of them may still be valid.
1714 quit_early = true;
1715 package_state_quit_early.Invalid(PackageValidationResult::PCKG_TX, "transaction failed");
1716 individual_results_nonfinal.emplace(wtxid, single_res);
1717 } else {
1718 individual_results_nonfinal.emplace(wtxid, single_res);
1719 txns_package_eval.push_back(tx);
1720 }
1721 }
1722 }
1723
1724 auto multi_submission_result = quit_early || txns_package_eval.empty() ? PackageMempoolAcceptResult(package_state_quit_early, {}) :
1725 AcceptSubPackage(txns_package_eval, args);
1726 PackageValidationState& package_state_final = multi_submission_result.m_state;
1727
1728 // This is invoked by AcceptSubPackage() already, so this is just here for
1729 // clarity (since it's not permitted to invoke LimitMempoolSize() while a
1730 // changeset is outstanding).
1731 ClearSubPackageState();
1732
1733 // Make sure we haven't exceeded max mempool size.
1734 // Package transactions that were submitted to mempool or already in mempool may be evicted.
1735 // If mempool contents change, then the m_view cache is dirty. It has already been cleared above.
1736 LimitMempoolSize(m_pool, m_active_chainstate.CoinsTip());
1737
1738 for (const auto& tx : package) {
1739 const auto& wtxid = tx->GetWitnessHash();
1740 if (multi_submission_result.m_tx_results.contains(wtxid)) {
1741 // We shouldn't have re-submitted if the tx result was already in results_final.
1742 Assume(!results_final.contains(wtxid));
1743 // If it was submitted, check to see if the tx is still in the mempool. It could have
1744 // been evicted due to LimitMempoolSize() above.
1745 const auto& txresult = multi_submission_result.m_tx_results.at(wtxid);
1746 if (txresult.m_result_type == MempoolAcceptResult::ResultType::VALID && !m_pool.exists(wtxid)) {
1747 package_state_final.Invalid(PackageValidationResult::PCKG_TX, "transaction failed");
1748 TxValidationState mempool_full_state;
1749 mempool_full_state.Invalid(TxValidationResult::TX_MEMPOOL_POLICY, "mempool full");
1750 results_final.emplace(wtxid, MempoolAcceptResult::Failure(mempool_full_state));
1751 } else {
1752 results_final.emplace(wtxid, txresult);
1753 }
1754 } else if (const auto it{results_final.find(wtxid)}; it != results_final.end()) {
1755 // Already-in-mempool transaction. Check to see if it's still there, as it could have
1756 // been evicted when LimitMempoolSize() was called.
1757 Assume(it->second.m_result_type != MempoolAcceptResult::ResultType::INVALID);
1758 Assume(!individual_results_nonfinal.contains(wtxid));
1759 // Query by txid to include the same-txid-different-witness ones.
1760 if (!m_pool.exists(tx->GetHash())) {
1761 package_state_final.Invalid(PackageValidationResult::PCKG_TX, "transaction failed");
1762 TxValidationState mempool_full_state;
1763 mempool_full_state.Invalid(TxValidationResult::TX_MEMPOOL_POLICY, "mempool full");
1764 // Replace the previous result.
1765 results_final.erase(wtxid);
1766 results_final.emplace(wtxid, MempoolAcceptResult::Failure(mempool_full_state));
1767 }
1768 } else if (const auto it{individual_results_nonfinal.find(wtxid)}; it != individual_results_nonfinal.end()) {
1769 Assume(it->second.m_result_type == MempoolAcceptResult::ResultType::INVALID);
1770 // Interesting result from previous processing.
1771 results_final.emplace(wtxid, it->second);
1772 }
1773 }
1774 Assume(results_final.size() == package.size());
1775 return PackageMempoolAcceptResult(package_state_final, std::move(results_final));
1776}
1777
1778} // anon namespace
1779
1781 int64_t accept_time, bool bypass_limits, bool test_accept)
1782{
1784 const CChainParams& chainparams{active_chainstate.m_chainman.GetParams()};
1785 assert(active_chainstate.GetMempool() != nullptr);
1786 CTxMemPool& pool{*active_chainstate.GetMempool()};
1787
1788 std::vector<COutPoint> coins_to_uncache;
1789
1790 auto args = MemPoolAccept::ATMPArgs::SingleAccept(chainparams, accept_time, bypass_limits, coins_to_uncache, test_accept);
1791 MempoolAcceptResult result = MemPoolAccept(pool, active_chainstate).AcceptSingleTransactionAndCleanup(tx, args);
1792
1794 // Remove coins that were not present in the coins cache before calling
1795 // AcceptSingleTransaction(); this is to prevent memory DoS in case we receive a large
1796 // number of invalid transactions that attempt to overrun the in-memory coins cache
1797 // (`CCoinsViewCache::cacheCoins`).
1798
1799 for (const COutPoint& hashTx : coins_to_uncache)
1800 active_chainstate.CoinsTip().Uncache(hashTx);
1801 TRACEPOINT(mempool, rejected,
1802 tx->GetHash().data(),
1803 result.m_state.GetRejectReason().c_str()
1804 );
1805 }
1806 // After we've (potentially) uncached entries, ensure our coins cache is still within its size limits
1807 BlockValidationState state_dummy;
1808 active_chainstate.FlushStateToDisk(state_dummy, FlushStateMode::PERIODIC);
1809 return result;
1810}
1811
1813 const Package& package, bool test_accept, const std::optional<CFeeRate>& client_maxfeerate)
1814{
1816 assert(!package.empty());
1817 assert(std::all_of(package.cbegin(), package.cend(), [](const auto& tx){return tx != nullptr;}));
1818
1819 std::vector<COutPoint> coins_to_uncache;
1820 const CChainParams& chainparams = active_chainstate.m_chainman.GetParams();
1821 auto result = [&]() EXCLUSIVE_LOCKS_REQUIRED(cs_main) {
1823 if (test_accept) {
1824 auto args = MemPoolAccept::ATMPArgs::PackageTestAccept(chainparams, GetTime(), coins_to_uncache);
1825 return MemPoolAccept(pool, active_chainstate).AcceptMultipleTransactionsAndCleanup(package, args);
1826 } else {
1827 auto args = MemPoolAccept::ATMPArgs::PackageChildWithParents(chainparams, GetTime(), coins_to_uncache, client_maxfeerate);
1828 return MemPoolAccept(pool, active_chainstate).AcceptPackage(package, args);
1829 }
1830 }();
1831
1832 // Uncache coins pertaining to transactions that were not submitted to the mempool.
1833 if (test_accept || result.m_state.IsInvalid()) {
1834 for (const COutPoint& hashTx : coins_to_uncache) {
1835 active_chainstate.CoinsTip().Uncache(hashTx);
1836 }
1837 }
1838 // Ensure the coins cache is still within limits.
1839 BlockValidationState state_dummy;
1840 active_chainstate.FlushStateToDisk(state_dummy, FlushStateMode::PERIODIC);
1841 return result;
1842}
1843
1845{
1846 int halvings = nHeight / consensusParams.nSubsidyHalvingInterval;
1847 // Force block reward to zero when right shift is undefined.
1848 if (halvings >= 64)
1849 return 0;
1850
1851 CAmount nSubsidy = 50 * COIN;
1852 // Subsidy is cut in half every 210,000 blocks which will occur approximately every 4 years.
1853 nSubsidy >>= halvings;
1854 return nSubsidy;
1855}
1856
1858 : m_dbview{std::move(db_params), std::move(options)},
1859 m_catcherview(&m_dbview) {}
1860
1861void CoinsViews::InitCache(int32_t prevoutfetch_threads)
1862{
1864 m_cacheview = std::make_unique<CCoinsViewCache>(&m_catcherview);
1865 auto thread_pool{std::make_shared<ThreadPool>("prevout")};
1866 if (prevoutfetch_threads > 0) {
1867 thread_pool->Start(prevoutfetch_threads);
1868 LogInfo("Block input prevout fetching uses %d additional threads", prevoutfetch_threads);
1869 }
1870 m_connect_block_view = std::make_unique<CoinsViewOverlay>(&*m_cacheview, std::move(thread_pool));
1871}
1872
1874 CTxMemPool* mempool,
1875 BlockManager& blockman,
1876 ChainstateManager& chainman,
1877 std::optional<uint256> from_snapshot_blockhash)
1878 : m_mempool(mempool),
1879 m_blockman(blockman),
1880 m_chainman(chainman),
1881 m_assumeutxo(from_snapshot_blockhash ? Assumeutxo::UNVALIDATED : Assumeutxo::VALIDATED),
1882 m_from_snapshot_blockhash(from_snapshot_blockhash) {}
1883
1885{
1886 fs::path path{m_chainman.m_options.datadir / "chainstate"};
1889 }
1890 return path;
1891}
1892
1893const CBlockIndex* Chainstate::SnapshotBase() const
1894{
1895 if (!m_from_snapshot_blockhash) return nullptr;
1896 if (!m_cached_snapshot_base) m_cached_snapshot_base = Assert(m_chainman.m_blockman.LookupBlockIndex(*m_from_snapshot_blockhash));
1897 return m_cached_snapshot_base;
1898}
1899
1900const CBlockIndex* Chainstate::TargetBlock() const
1901{
1902 if (!m_target_blockhash) return nullptr;
1903 if (!m_cached_target_block) m_cached_target_block = Assert(m_chainman.m_blockman.LookupBlockIndex(*m_target_blockhash));
1904 return m_cached_target_block;
1905}
1906
1907void Chainstate::SetTargetBlock(CBlockIndex* block)
1908{
1909 if (block) {
1910 m_target_blockhash = block->GetBlockHash();
1911 } else {
1912 m_target_blockhash.reset();
1913 }
1914 m_cached_target_block = block;
1915}
1916
1917void Chainstate::SetTargetBlockHash(uint256 block_hash)
1918{
1919 m_target_blockhash = block_hash;
1920 m_cached_target_block = nullptr;
1921}
1922
1924 size_t cache_size_bytes,
1925 bool in_memory,
1926 bool should_wipe)
1927{
1928 m_coins_views = std::make_unique<CoinsViews>(
1929 DBParams{
1930 .path = StoragePath(),
1931 .cache_bytes = cache_size_bytes,
1932 .memory_only = in_memory,
1933 .wipe_data = should_wipe,
1934 .obfuscate = true,
1935 .options = m_chainman.m_options.coins_db},
1937
1938 m_coinsdb_cache_size_bytes = cache_size_bytes;
1939}
1940
1941void Chainstate::InitCoinsCache(size_t cache_size_bytes)
1942{
1944 assert(m_coins_views != nullptr);
1945 m_coinstip_cache_size_bytes = cache_size_bytes;
1947}
1948
1949// Lock-free: depends on `m_cached_is_ibd`, which is latched by `UpdateIBDStatus()`.
1951{
1952 return m_cached_is_ibd.load(std::memory_order_relaxed);
1953}
1954
1956{
1958
1959 if (this->GetRole().historical) {
1960 return;
1961 }
1962
1963 if (m_chainman.m_best_invalid && m_chainman.m_best_invalid->nChainWork > m_chain.Tip()->nChainWork + (GetBlockProof(*m_chain.Tip()) * 6)) {
1964 LogWarning("Found invalid chain more than 6 blocks longer than our best chain. This could be due to database corruption or consensus incompatibility with peers.");
1967 _("Warning: Found invalid chain more than 6 blocks longer than our best chain. This could be due to database corruption or consensus incompatibility with peers."));
1968 } else {
1970 }
1971}
1972
1973// Called both upon regular invalid block discovery *and* InvalidateBlock
1975{
1977 if (!m_chainman.m_best_invalid || pindexNew->nChainWork > m_chainman.m_best_invalid->nChainWork) {
1978 m_chainman.m_best_invalid = pindexNew;
1979 }
1980 SetBlockFailureFlags(pindexNew);
1981 if (m_chainman.m_best_header != nullptr && m_chainman.m_best_header->GetAncestor(pindexNew->nHeight) == pindexNew) {
1982 m_chainman.RecalculateBestHeader();
1983 }
1984
1985 LogInfo("%s: invalid block=%s height=%d log2_work=%f date=%s", __func__,
1986 pindexNew->GetBlockHash().ToString(), pindexNew->nHeight,
1987 log(pindexNew->nChainWork.getdouble())/log(2.0), FormatISO8601DateTime(pindexNew->GetBlockTime()));
1988 CBlockIndex *tip = m_chain.Tip();
1989 assert (tip);
1990 LogInfo("%s: current best=%s height=%d log2_work=%f date=%s", __func__,
1991 tip->GetBlockHash().ToString(), m_chain.Height(), log(tip->nChainWork.getdouble())/log(2.0),
1994}
1995
1996// Same as InvalidChainFound, above, except not called directly from InvalidateBlock,
1997// which does its own setBlockIndexCandidates management.
1999{
2002 pindex->nStatus |= BLOCK_FAILED_VALID;
2003 m_blockman.m_dirty_blockindex.insert(pindex);
2004 setBlockIndexCandidates.erase(pindex);
2005 InvalidChainFound(pindex);
2006 }
2007}
2008
2009void UpdateCoins(const CTransaction& tx, CCoinsViewCache& inputs, CTxUndo &txundo, int nHeight)
2010{
2011 // mark inputs spent
2012 if (!tx.IsCoinBase()) {
2013 txundo.vprevout.reserve(tx.vin.size());
2014 for (const CTxIn &txin : tx.vin) {
2015 txundo.vprevout.emplace_back();
2016 bool is_spent = inputs.SpendCoin(txin.prevout, &txundo.vprevout.back());
2017 assert(is_spent);
2018 }
2019 }
2020 // add outputs
2021 AddCoins(inputs, tx, nHeight);
2022}
2023
2024std::optional<std::pair<ScriptError, std::string>> CScriptCheck::operator()() {
2025 const CScript &scriptSig = ptxTo->vin[nIn].scriptSig;
2026 const CScriptWitness *witness = &ptxTo->vin[nIn].scriptWitness;
2029 return std::nullopt;
2030 } else {
2031 auto debug_str = strprintf("input %i of %s (wtxid %s), spending %s:%i", nIn, ptxTo->GetHash().ToString(), ptxTo->GetWitnessHash().ToString(), ptxTo->vin[nIn].prevout.hash.ToString(), ptxTo->vin[nIn].prevout.n);
2032 return std::make_pair(error, std::move(debug_str));
2033 }
2034}
2035
2036ValidationCache::ValidationCache(const size_t script_execution_cache_bytes, const size_t signature_cache_bytes)
2037 : m_signature_cache{signature_cache_bytes}
2038{
2039 // Setup the salted hasher
2041 // We want the nonce to be 64 bytes long to force the hasher to process
2042 // this chunk, which makes later hash computations more efficient. We
2043 // just write our 32-byte entropy twice to fill the 64 bytes.
2046
2047 const auto [num_elems, approx_size_bytes] = m_script_execution_cache.setup_bytes(script_execution_cache_bytes);
2048 LogInfo("Using %zu MiB out of %zu MiB requested for script execution cache, able to store %zu elements",
2049 approx_size_bytes >> 20, script_execution_cache_bytes >> 20, num_elems);
2050}
2051
2072 const CCoinsViewCache& inputs, script_verify_flags flags, bool cacheSigStore,
2073 bool cacheFullScriptStore, PrecomputedTransactionData& txdata,
2074 ValidationCache& validation_cache,
2075 std::vector<CScriptCheck>* pvChecks)
2076{
2077 if (tx.IsCoinBase()) return true;
2078
2079 if (pvChecks) {
2080 pvChecks->reserve(tx.vin.size());
2081 }
2082
2083 // First check if script executions have been cached with the same
2084 // flags. Note that this assumes that the inputs provided are
2085 // correct (ie that the transaction hash which is in tx's prevouts
2086 // properly commits to the scriptPubKey in the inputs view of that
2087 // transaction).
2088 uint256 hashCacheEntry;
2089 CSHA256 hasher = validation_cache.ScriptExecutionCacheHasher();
2090 hasher.Write(UCharCast(tx.GetWitnessHash().begin()), 32).Write((unsigned char*)&flags, sizeof(flags)).Finalize(hashCacheEntry.begin());
2091 AssertLockHeld(cs_main); //TODO: Remove this requirement by making CuckooCache not require external locks
2092 if (validation_cache.m_script_execution_cache.contains(hashCacheEntry, !cacheFullScriptStore)) {
2093 return true;
2094 }
2095
2096 if (!txdata.m_spent_outputs_ready) {
2097 std::vector<CTxOut> spent_outputs;
2098 spent_outputs.reserve(tx.vin.size());
2099
2100 for (const auto& txin : tx.vin) {
2101 const COutPoint& prevout = txin.prevout;
2102 const Coin& coin = inputs.AccessCoin(prevout);
2103 assert(!coin.IsSpent());
2104 spent_outputs.emplace_back(coin.out);
2105 }
2106 txdata.Init(tx, std::move(spent_outputs));
2107 }
2108 assert(txdata.m_spent_outputs.size() == tx.vin.size());
2109
2110 for (unsigned int i = 0; i < tx.vin.size(); i++) {
2111
2112 // We very carefully only pass in things to CScriptCheck which
2113 // are clearly committed to by tx' witness hash. This provides
2114 // a sanity check that our caching is not introducing consensus
2115 // failures through additional data in, eg, the coins being
2116 // spent being checked as a part of CScriptCheck.
2117
2118 // Verify signature
2119 CScriptCheck check(txdata.m_spent_outputs[i], tx, validation_cache.m_signature_cache, i, flags, cacheSigStore, &txdata);
2120 if (pvChecks) {
2121 pvChecks->emplace_back(std::move(check));
2122 } else if (auto result = check(); result.has_value()) {
2123 // Tx failures never trigger disconnections/bans.
2124 // This is so that network splits aren't triggered
2125 // either due to non-consensus relay policies (such as
2126 // non-standard DER encodings or non-null dummy
2127 // arguments) or due to new consensus rules introduced in
2128 // soft forks.
2130 return state.Invalid(TxValidationResult::TX_NOT_STANDARD, strprintf("mempool-script-verify-flag-failed (%s)", ScriptErrorString(result->first)), result->second);
2131 } else {
2132 return state.Invalid(TxValidationResult::TX_CONSENSUS, strprintf("block-script-verify-flag-failed (%s)", ScriptErrorString(result->first)), result->second);
2133 }
2134 }
2135 }
2136
2137 if (cacheFullScriptStore && !pvChecks) {
2138 // We executed all of the provided scripts, and were told to
2139 // cache the result. Do so now.
2140 validation_cache.m_script_execution_cache.insert(hashCacheEntry);
2141 }
2142
2143 return true;
2144}
2145
2146bool FatalError(Notifications& notifications, BlockValidationState& state, const bilingual_str& message)
2147{
2148 notifications.fatalError(message);
2149 return state.Error(message.original);
2150}
2151
2160{
2161 bool fClean = true;
2162
2163 if (view.HaveCoin(out)) fClean = false; // overwriting transaction output
2164
2165 if (undo.nHeight == 0) {
2166 // Missing undo metadata (height and coinbase). Older versions included this
2167 // information only in undo records for the last spend of a transactions'
2168 // outputs. This implies that it must be present for some other output of the same tx.
2169 const Coin& alternate = AccessByTxid(view, out.hash);
2170 if (!alternate.IsSpent()) {
2171 undo.nHeight = alternate.nHeight;
2172 undo.fCoinBase = alternate.fCoinBase;
2173 } else {
2174 return DISCONNECT_FAILED; // adding output for transaction without known metadata
2175 }
2176 }
2177 // If the coin already exists as an unspent coin in the cache, then the
2178 // possible_overwrite parameter to AddCoin must be set to true. We have
2179 // already checked whether an unspent coin exists above using HaveCoin, so
2180 // we don't need to guess. When fClean is false, an unspent coin already
2181 // existed and it is an overwrite.
2182 view.AddCoin(out, std::move(undo), !fClean);
2183
2184 return fClean ? DISCONNECT_OK : DISCONNECT_UNCLEAN;
2185}
2186
2189DisconnectResult Chainstate::DisconnectBlock(const CBlock& block, const CBlockIndex* pindex, CCoinsViewCache& view)
2190{
2192 bool fClean = true;
2193
2194 CBlockUndo blockUndo;
2195 if (!m_blockman.ReadBlockUndo(blockUndo, *pindex)) {
2196 LogError("DisconnectBlock(): failure reading undo data\n");
2197 return DISCONNECT_FAILED;
2198 }
2199
2200 if (blockUndo.vtxundo.size() + 1 != block.vtx.size()) {
2201 LogError("DisconnectBlock(): block and undo data inconsistent\n");
2202 return DISCONNECT_FAILED;
2203 }
2204
2205 // Ignore blocks that contain transactions which are 'overwritten' by later transactions,
2206 // unless those are already completely spent.
2207 // See https://github.com/bitcoin/bitcoin/issues/22596 for additional information.
2208 // Note: the blocks specified here are different than the ones used in ConnectBlock because DisconnectBlock
2209 // unwinds the blocks in reverse. As a result, the inconsistency is not discovered until the earlier
2210 // blocks with the duplicate coinbase transactions are disconnected.
2211 bool fEnforceBIP30 = !((pindex->nHeight==91722 && pindex->GetBlockHash() == uint256{"00000000000271a2dc26e7667f8419f2e15416dc6955e5a6c6cdf3f2574dd08e"}) ||
2212 (pindex->nHeight==91812 && pindex->GetBlockHash() == uint256{"00000000000af0aed4792b1acee3d966af36cf5def14935db8de83d6f9306f2f"}));
2213
2214 // undo transactions in reverse order
2215 for (int i = block.vtx.size() - 1; i >= 0; i--) {
2216 const CTransaction &tx = *(block.vtx[i]);
2217 Txid hash = tx.GetHash();
2218 bool is_coinbase = tx.IsCoinBase();
2219 bool is_bip30_exception = (is_coinbase && !fEnforceBIP30);
2220
2221 // Check that all outputs are available and match the outputs in the block itself
2222 // exactly.
2223 for (size_t o = 0; o < tx.vout.size(); o++) {
2224 if (!tx.vout[o].scriptPubKey.IsUnspendable()) {
2225 COutPoint out(hash, o);
2226 Coin coin;
2227 bool is_spent = view.SpendCoin(out, &coin);
2228 if (!is_spent || tx.vout[o] != coin.out || pindex->nHeight != coin.nHeight || is_coinbase != coin.IsCoinBase()) {
2229 if (!is_bip30_exception) {
2230 fClean = false; // transaction output mismatch
2231 }
2232 }
2233 }
2234 }
2235
2236 // restore inputs
2237 if (i > 0) { // not coinbases
2238 CTxUndo &txundo = blockUndo.vtxundo[i-1];
2239 if (txundo.vprevout.size() != tx.vin.size()) {
2240 LogError("DisconnectBlock(): transaction and undo data inconsistent\n");
2241 return DISCONNECT_FAILED;
2242 }
2243 for (unsigned int j = tx.vin.size(); j > 0;) {
2244 --j;
2245 const COutPoint& out = tx.vin[j].prevout;
2246 int res = ApplyTxInUndo(std::move(txundo.vprevout[j]), view, out);
2247 if (res == DISCONNECT_FAILED) return DISCONNECT_FAILED;
2248 fClean = fClean && res != DISCONNECT_UNCLEAN;
2249 }
2250 // At this point, all of txundo.vprevout should have been moved out.
2251 }
2252 }
2253
2254 // move best block pointer to prevout block
2255 view.SetBestBlock(pindex->pprev->GetBlockHash());
2256
2257 return fClean ? DISCONNECT_OK : DISCONNECT_UNCLEAN;
2258}
2259
2261{
2262 const Consensus::Params& consensusparams = chainman.GetConsensus();
2263
2264 // BIP16 didn't become active until Apr 1 2012 (on mainnet, and
2265 // retroactively applied to testnet)
2266 // However, only one historical block violated the P2SH rules (on both
2267 // mainnet and testnet).
2268 // Similarly, only one historical block violated the TAPROOT rules on
2269 // mainnet.
2270 // For simplicity, always leave P2SH+WITNESS+TAPROOT on except for the two
2271 // violating blocks.
2273 const auto it{consensusparams.script_flag_exceptions.find(*Assert(block_index.phashBlock))};
2274 if (it != consensusparams.script_flag_exceptions.end()) {
2275 flags = it->second;
2276 }
2277
2278 // Enforce the DERSIG (BIP66) rule
2279 if (DeploymentActiveAt(block_index, chainman, Consensus::DEPLOYMENT_DERSIG)) {
2281 }
2282
2283 // Enforce CHECKLOCKTIMEVERIFY (BIP65)
2284 if (DeploymentActiveAt(block_index, chainman, Consensus::DEPLOYMENT_CLTV)) {
2286 }
2287
2288 // Enforce CHECKSEQUENCEVERIFY (BIP112)
2289 if (DeploymentActiveAt(block_index, chainman, Consensus::DEPLOYMENT_CSV)) {
2291 }
2292
2293 // Enforce BIP147 NULLDUMMY (activated simultaneously with segwit)
2294 if (DeploymentActiveAt(block_index, chainman, Consensus::DEPLOYMENT_SEGWIT)) {
2296 }
2297
2298 return flags;
2299}
2300
2301
2305bool Chainstate::ConnectBlock(const CBlock& block, BlockValidationState& state, CBlockIndex* pindex,
2306 CCoinsViewCache& view, bool fJustCheck)
2307{
2309 assert(pindex);
2310
2311 uint256 block_hash{block.GetHash()};
2312 assert(*pindex->phashBlock == block_hash);
2313
2314 const auto time_start{SteadyClock::now()};
2315 const CChainParams& params{m_chainman.GetParams()};
2316
2317 // Check it again in case a previous version let a bad block in
2318 // NOTE: We don't currently (re-)invoke ContextualCheckBlock() or
2319 // ContextualCheckBlockHeader() here. This means that if we add a new
2320 // consensus rule that is enforced in one of those two functions, then we
2321 // may have let in a block that violates the rule prior to updating the
2322 // software, and we would NOT be enforcing the rule here. Fully solving
2323 // upgrade from one software version to the next after a consensus rule
2324 // change is potentially tricky and issue-specific (see NeedsRedownload()
2325 // for one approach that was used for BIP 141 deployment).
2326 // Also, currently the rule against blocks more than 2 hours in the future
2327 // is enforced in ContextualCheckBlockHeader(); we wouldn't want to
2328 // re-enforce that rule here (at least until we make it impossible for
2329 // the clock to go backward).
2330 if (!CheckBlock(block, state, params.GetConsensus(), !fJustCheck, !fJustCheck)) {
2332 // We don't write down blocks to disk if they may have been
2333 // corrupted, so this should be impossible unless we're having hardware
2334 // problems.
2335 return FatalError(m_chainman.GetNotifications(), state, _("Corrupt block found indicating potential hardware failure."));
2336 }
2337 LogError("%s: Consensus::CheckBlock: %s\n", __func__, state.ToString());
2338 return false;
2339 }
2340
2341 // verify that the view's current state corresponds to the previous block
2342 uint256 hashPrevBlock = pindex->pprev == nullptr ? uint256() : pindex->pprev->GetBlockHash();
2343 assert(hashPrevBlock == view.GetBestBlock());
2344
2345 m_chainman.num_blocks_total++;
2346
2347 // Special case for the genesis block, skipping connection of its transactions
2348 // (its coinbase is unspendable)
2349 if (block_hash == params.GetConsensus().hashGenesisBlock) {
2350 if (!fJustCheck)
2351 view.SetBestBlock(pindex->GetBlockHash());
2352 return true;
2353 }
2354
2355 const char* script_check_reason;
2357 script_check_reason = "assumevalid=0 (always verify)";
2358 } else {
2359 constexpr int64_t TWO_WEEKS_IN_SECONDS{60 * 60 * 24 * 7 * 2};
2360 // We've been configured with the hash of a block which has been externally verified to have a valid history.
2361 // A suitable default value is included with the software and updated from time to time. Because validity
2362 // relative to a piece of software is an objective fact these defaults can be easily reviewed.
2363 // This setting doesn't force the selection of any particular chain but makes validating some faster by
2364 // effectively caching the result of part of the verification.
2365 BlockMap::const_iterator it{m_blockman.m_block_index.find(m_chainman.AssumedValidBlock())};
2366 if (it == m_blockman.m_block_index.end()) {
2367 script_check_reason = "assumevalid hash not in headers";
2368 } else if (it->second.GetAncestor(pindex->nHeight) != pindex) {
2369 script_check_reason = (pindex->nHeight > it->second.nHeight) ? "block height above assumevalid height" : "block not in assumevalid chain";
2370 } else if (m_chainman.m_best_header->GetAncestor(pindex->nHeight) != pindex) {
2371 script_check_reason = "block not in best header chain";
2372 } else if (m_chainman.m_best_header->nChainWork < m_chainman.MinimumChainWork()) {
2373 script_check_reason = "best header chainwork below minimumchainwork";
2374 } else if (GetBlockProofEquivalentTime(*m_chainman.m_best_header, *pindex, *m_chainman.m_best_header, params.GetConsensus()) <= TWO_WEEKS_IN_SECONDS) {
2375 script_check_reason = "block too recent relative to best header";
2376 } else {
2377 // This block is a member of the assumed verified chain and an ancestor of the best header.
2378 // Script verification is skipped when connecting blocks under the
2379 // assumevalid block. Assuming the assumevalid block is valid this
2380 // is safe because block merkle hashes are still computed and checked,
2381 // Of course, if an assumed valid block is invalid due to false scriptSigs
2382 // this optimization would allow an invalid chain to be accepted.
2383 // The equivalent time check discourages hash power from extorting the network via DOS attack
2384 // into accepting an invalid block through telling users they must manually set assumevalid.
2385 // Requiring a software change or burying the invalid block, regardless of the setting, makes
2386 // it hard to hide the implication of the demand. This also avoids having release candidates
2387 // that are hardly doing any signature verification at all in testing without having to
2388 // artificially set the default assumed verified block further back.
2389 // The test against the minimum chain work prevents the skipping when denied access to any chain at
2390 // least as good as the expected chain.
2391 script_check_reason = nullptr;
2392 }
2393 }
2394
2395 const auto time_1{SteadyClock::now()};
2396 m_chainman.time_check += time_1 - time_start;
2397 LogDebug(BCLog::BENCH, " - Sanity checks: %.2fms [%.2fs (%.2fms/blk)]\n",
2398 Ticks<MillisecondsDouble>(time_1 - time_start),
2399 Ticks<SecondsDouble>(m_chainman.time_check),
2400 Ticks<MillisecondsDouble>(m_chainman.time_check) / m_chainman.num_blocks_total);
2401
2402 // Do not allow blocks that contain transactions which 'overwrite' older transactions,
2403 // unless those are already completely spent.
2404 // If such overwrites are allowed, coinbases and transactions depending upon those
2405 // can be duplicated to remove the ability to spend the first instance -- even after
2406 // being sent to another address.
2407 // See BIP30, CVE-2012-1909, and https://r6.ca/blog/20120206T005236Z.html for more information.
2408 // This rule was originally applied to all blocks with a timestamp after March 15, 2012, 0:00 UTC.
2409 // Now that the whole chain is irreversibly beyond that time it is applied to all blocks except the
2410 // two in the chain that violate it. This prevents exploiting the issue against nodes during their
2411 // initial block download.
2412 bool fEnforceBIP30 = !IsBIP30Repeat(*pindex);
2413
2414 // Once BIP34 activated it was not possible to create new duplicate coinbases and thus other than starting
2415 // with the 2 existing duplicate coinbase pairs, not possible to create overwriting txs. But by the
2416 // time BIP34 activated, in each of the existing pairs the duplicate coinbase had overwritten the first
2417 // before the first had been spent. Since those coinbases are sufficiently buried it's no longer possible to create further
2418 // duplicate transactions descending from the known pairs either.
2419 // If we're on the known chain at height greater than where BIP34 activated, we can save the db accesses needed for the BIP30 check.
2420
2421 // BIP34 requires that a block at height X (block X) has its coinbase
2422 // scriptSig start with a CScriptNum of X (indicated height X). The above
2423 // logic of no longer requiring BIP30 once BIP34 activates is flawed in the
2424 // case that there is a block X before the BIP34 height of 227,931 which has
2425 // an indicated height Y where Y is greater than X. The coinbase for block
2426 // X would also be a valid coinbase for block Y, which could be a BIP30
2427 // violation. An exhaustive search of all mainnet coinbases before the
2428 // BIP34 height which have an indicated height greater than the block height
2429 // reveals many occurrences. The 3 lowest indicated heights found are
2430 // 209,921, 490,897, and 1,983,702 and thus coinbases for blocks at these 3
2431 // heights would be the first opportunity for BIP30 to be violated.
2432
2433 // The search reveals a great many blocks which have an indicated height
2434 // greater than 1,983,702, so we simply remove the optimization to skip
2435 // BIP30 checking for blocks at height 1,983,702 or higher. Before we reach
2436 // that block in another 25 years or so, we should take advantage of a
2437 // future consensus change to do a new and improved version of BIP34 that
2438 // will actually prevent ever creating any duplicate coinbases in the
2439 // future.
2440 static constexpr int BIP34_IMPLIES_BIP30_LIMIT = 1983702;
2441
2442 // There is no potential to create a duplicate coinbase at block 209,921
2443 // because this is still before the BIP34 height and so explicit BIP30
2444 // checking is still active.
2445
2446 // The final case is block 176,684 which has an indicated height of
2447 // 490,897. Unfortunately, this issue was not discovered until about 2 weeks
2448 // before block 490,897 so there was not much opportunity to address this
2449 // case other than to carefully analyze it and determine it would not be a
2450 // problem. Block 490,897 was, in fact, mined with a different coinbase than
2451 // block 176,684, but it is important to note that even if it hadn't been or
2452 // is remined on an alternate fork with a duplicate coinbase, we would still
2453 // not run into a BIP30 violation. This is because the coinbase for 176,684
2454 // is spent in block 185,956 in transaction
2455 // d4f7fbbf92f4a3014a230b2dc70b8058d02eb36ac06b4a0736d9d60eaa9e8781. This
2456 // spending transaction can't be duplicated because it also spends coinbase
2457 // 0328dd85c331237f18e781d692c92de57649529bd5edf1d01036daea32ffde29. This
2458 // coinbase has an indicated height of over 4.2 billion, and wouldn't be
2459 // duplicatable until that height, and it's currently impossible to create a
2460 // chain that long. Nevertheless we may wish to consider a future soft fork
2461 // which retroactively prevents block 490,897 from creating a duplicate
2462 // coinbase. The two historical BIP30 violations often provide a confusing
2463 // edge case when manipulating the UTXO and it would be simpler not to have
2464 // another edge case to deal with.
2465
2466 // testnet3 has no blocks before the BIP34 height with indicated heights
2467 // post BIP34 before approximately height 486,000,000. After block
2468 // 1,983,702 testnet3 starts doing unnecessary BIP30 checking again.
2469 assert(pindex->pprev);
2470 CBlockIndex* pindexBIP34height = pindex->pprev->GetAncestor(params.GetConsensus().BIP34Height);
2471 //Only continue to enforce if we're below BIP34 activation height or the block hash at that height doesn't correspond.
2472 fEnforceBIP30 = fEnforceBIP30 && (!pindexBIP34height || !(pindexBIP34height->GetBlockHash() == params.GetConsensus().BIP34Hash));
2473
2474 // TODO: Remove BIP30 checking from block height 1,983,702 on, once we have a
2475 // consensus change that ensures coinbases at those heights cannot
2476 // duplicate earlier coinbases.
2477 if (fEnforceBIP30 || pindex->nHeight >= BIP34_IMPLIES_BIP30_LIMIT) {
2478 for (const auto& tx : block.vtx) {
2479 for (size_t o = 0; o < tx->vout.size(); o++) {
2480 if (view.HaveCoin(COutPoint(tx->GetHash(), o))) {
2481 state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-txns-BIP30",
2482 "tried to overwrite transaction");
2483 }
2484 }
2485 }
2486 }
2487
2488 // Enforce BIP68 (sequence locks)
2489 int nLockTimeFlags = 0;
2491 nLockTimeFlags |= LOCKTIME_VERIFY_SEQUENCE;
2492 }
2493
2494 // Get the script flags for this block
2496
2497 const auto time_2{SteadyClock::now()};
2498 m_chainman.time_forks += time_2 - time_1;
2499 LogDebug(BCLog::BENCH, " - Fork checks: %.2fms [%.2fs (%.2fms/blk)]\n",
2500 Ticks<MillisecondsDouble>(time_2 - time_1),
2501 Ticks<SecondsDouble>(m_chainman.time_forks),
2502 Ticks<MillisecondsDouble>(m_chainman.time_forks) / m_chainman.num_blocks_total);
2503
2504 const bool fScriptChecks{!!script_check_reason};
2505 const kernel::ChainstateRole role{GetRole()};
2506 if (script_check_reason != m_last_script_check_reason_logged && role.validated && !role.historical) {
2507 if (fScriptChecks) {
2508 LogInfo("Enabling script verification at block #%d (%s): %s.",
2509 pindex->nHeight, block_hash.ToString(), script_check_reason);
2510 } else {
2511 LogInfo("Disabling script verification at block #%d (%s).",
2512 pindex->nHeight, block_hash.ToString());
2513 }
2514 m_last_script_check_reason_logged = script_check_reason;
2515 }
2516
2517 CBlockUndo blockundo;
2518
2519 // Precomputed transaction data pointers must not be invalidated
2520 // until after `control` has run the script checks (potentially
2521 // in multiple threads). Preallocate the vector size so a new allocation
2522 // doesn't invalidate pointers into the vector, and keep txsdata in scope
2523 // for as long as `control`.
2524 std::vector<PrecomputedTransactionData> txsdata(block.vtx.size());
2525 std::optional<CCheckQueueControl<CScriptCheck>> control;
2526 if (auto& queue = m_chainman.GetCheckQueue(); queue.HasThreads() && fScriptChecks) control.emplace(queue);
2527
2528 std::vector<int> prevheights;
2529 CAmount nFees = 0;
2530 int nInputs = 0;
2531 int64_t nSigOpsCost = 0;
2532 blockundo.vtxundo.reserve(block.vtx.size() - 1);
2533 for (unsigned int i = 0; i < block.vtx.size(); i++)
2534 {
2535 if (!state.IsValid()) break;
2536 const CTransaction &tx = *(block.vtx[i]);
2537
2538 nInputs += tx.vin.size();
2539
2540 if (!tx.IsCoinBase())
2541 {
2542 CAmount txfee = 0;
2543 TxValidationState tx_state;
2544 if (!Consensus::CheckTxInputs(tx, tx_state, view, pindex->nHeight, txfee)) {
2545 // Any transaction validation failure in ConnectBlock is a block consensus failure
2547 tx_state.GetRejectReason(),
2548 tx_state.GetDebugMessage() + " in transaction " + tx.GetHash().ToString());
2549 break;
2550 }
2551 nFees += txfee;
2552 if (!MoneyRange(nFees)) {
2553 state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-txns-accumulated-fee-outofrange",
2554 "accumulated fee in the block out of range");
2555 break;
2556 }
2557
2558 // Check that transaction is BIP68 final
2559 // BIP68 lock checks (as opposed to nLockTime checks) must
2560 // be in ConnectBlock because they require the UTXO set
2561 prevheights.resize(tx.vin.size());
2562 for (size_t j = 0; j < tx.vin.size(); j++) {
2563 prevheights[j] = view.AccessCoin(tx.vin[j].prevout).nHeight;
2564 }
2565
2566 if (!SequenceLocks(tx, nLockTimeFlags, prevheights, *pindex)) {
2567 state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-txns-nonfinal",
2568 "contains a non-BIP68-final transaction " + tx.GetHash().ToString());
2569 break;
2570 }
2571 }
2572
2573 // GetTransactionSigOpCost counts 3 types of sigops:
2574 // * legacy (always)
2575 // * p2sh (when P2SH enabled in flags and excludes coinbase)
2576 // * witness (when witness enabled in flags and excludes coinbase)
2577 nSigOpsCost += GetTransactionSigOpCost(tx, view, flags);
2578 if (nSigOpsCost > MAX_BLOCK_SIGOPS_COST) {
2579 state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-blk-sigops", "too many sigops");
2580 break;
2581 }
2582
2583 if (!tx.IsCoinBase() && fScriptChecks)
2584 {
2585 bool fCacheResults = fJustCheck; /* Don't cache results if we're actually connecting blocks (still consult the cache, though) */
2586 bool tx_ok;
2587 TxValidationState tx_state;
2588 // If CheckInputScripts is called with a pointer to a checks vector, the resulting checks are appended to it. In that case
2589 // they need to be added to control which runs them asynchronously. Otherwise, CheckInputScripts runs the checks before returning.
2590 if (control) {
2591 std::vector<CScriptCheck> vChecks;
2592 tx_ok = CheckInputScripts(tx, tx_state, view, flags, fCacheResults, fCacheResults, txsdata[i], m_chainman.m_validation_cache, &vChecks);
2593 if (tx_ok) control->Add(std::move(vChecks));
2594 } else {
2595 tx_ok = CheckInputScripts(tx, tx_state, view, flags, fCacheResults, fCacheResults, txsdata[i], m_chainman.m_validation_cache);
2596 }
2597 if (!tx_ok) {
2598 // Any transaction validation failure in ConnectBlock is a block consensus failure
2600 tx_state.GetRejectReason(), tx_state.GetDebugMessage());
2601 break;
2602 }
2603 }
2604
2605 CTxUndo undoDummy;
2606 if (i > 0) {
2607 blockundo.vtxundo.emplace_back();
2608 }
2609 UpdateCoins(tx, view, i == 0 ? undoDummy : blockundo.vtxundo.back(), pindex->nHeight);
2610 }
2611 const auto time_3{SteadyClock::now()};
2612 m_chainman.time_connect += time_3 - time_2;
2613 LogDebug(BCLog::BENCH, " - Connect %u transactions: %.2fms (%.3fms/tx, %.3fms/txin) [%.2fs (%.2fms/blk)]\n", (unsigned)block.vtx.size(),
2614 Ticks<MillisecondsDouble>(time_3 - time_2), Ticks<MillisecondsDouble>(time_3 - time_2) / block.vtx.size(),
2615 nInputs <= 1 ? 0 : Ticks<MillisecondsDouble>(time_3 - time_2) / (nInputs - 1),
2616 Ticks<SecondsDouble>(m_chainman.time_connect),
2617 Ticks<MillisecondsDouble>(m_chainman.time_connect) / m_chainman.num_blocks_total);
2618
2619 CAmount blockReward = nFees + GetBlockSubsidy(pindex->nHeight, params.GetConsensus());
2620 if (block.vtx[0]->GetValueOut() > blockReward && state.IsValid()) {
2621 state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-cb-amount",
2622 strprintf("coinbase pays too much (actual=%d vs limit=%d)", block.vtx[0]->GetValueOut(), blockReward));
2623 }
2624 if (control) {
2625 auto parallel_result = control->Complete();
2626 if (parallel_result.has_value() && state.IsValid()) {
2627 state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, strprintf("block-script-verify-flag-failed (%s)", ScriptErrorString(parallel_result->first)), parallel_result->second);
2628 }
2629 }
2630 if (!state.IsValid()) {
2631 LogInfo("Block validation error: %s", state.ToString());
2632 return false;
2633 }
2634 const auto time_4{SteadyClock::now()};
2635 m_chainman.time_verify += time_4 - time_2;
2636 LogDebug(BCLog::BENCH, " - Verify %u txins: %.2fms (%.3fms/txin) [%.2fs (%.2fms/blk)]\n", nInputs - 1,
2637 Ticks<MillisecondsDouble>(time_4 - time_2),
2638 nInputs <= 1 ? 0 : Ticks<MillisecondsDouble>(time_4 - time_2) / (nInputs - 1),
2639 Ticks<SecondsDouble>(m_chainman.time_verify),
2640 Ticks<MillisecondsDouble>(m_chainman.time_verify) / m_chainman.num_blocks_total);
2641
2642 if (fJustCheck) {
2643 return true;
2644 }
2645
2646 if (!m_blockman.WriteBlockUndo(blockundo, state, *pindex)) {
2647 return false;
2648 }
2649
2650 const auto time_5{SteadyClock::now()};
2651 m_chainman.time_undo += time_5 - time_4;
2652 LogDebug(BCLog::BENCH, " - Write undo data: %.2fms [%.2fs (%.2fms/blk)]\n",
2653 Ticks<MillisecondsDouble>(time_5 - time_4),
2654 Ticks<SecondsDouble>(m_chainman.time_undo),
2655 Ticks<MillisecondsDouble>(m_chainman.time_undo) / m_chainman.num_blocks_total);
2656
2657 if (!pindex->IsValid(BLOCK_VALID_SCRIPTS)) {
2659 m_blockman.m_dirty_blockindex.insert(pindex);
2660 }
2661
2662 // add this block to the view's block chain
2663 view.SetBestBlock(pindex->GetBlockHash());
2664
2665 const auto time_6{SteadyClock::now()};
2666 m_chainman.time_index += time_6 - time_5;
2667 LogDebug(BCLog::BENCH, " - Index writing: %.2fms [%.2fs (%.2fms/blk)]\n",
2668 Ticks<MillisecondsDouble>(time_6 - time_5),
2669 Ticks<SecondsDouble>(m_chainman.time_index),
2670 Ticks<MillisecondsDouble>(m_chainman.time_index) / m_chainman.num_blocks_total);
2671
2672 TRACEPOINT(validation, block_connected,
2673 block_hash.data(),
2674 pindex->nHeight,
2675 block.vtx.size(),
2676 nInputs,
2677 nSigOpsCost,
2678 Ticks<std::chrono::nanoseconds>(time_5 - time_start)
2679 );
2680
2681 return true;
2682}
2683
2684CoinsCacheSizeState Chainstate::GetCoinsCacheSizeState()
2685{
2687 return this->GetCoinsCacheSizeState(
2690}
2691
2692CoinsCacheSizeState Chainstate::GetCoinsCacheSizeState(
2693 size_t max_coins_cache_size_bytes,
2694 size_t max_mempool_size_bytes)
2695{
2697 const int64_t nMempoolUsage = m_mempool ? m_mempool->DynamicMemoryUsage() : 0;
2698 int64_t cacheSize = CoinsTip().DynamicMemoryUsage();
2699 int64_t nTotalSpace =
2700 max_coins_cache_size_bytes + std::max<int64_t>(int64_t(max_mempool_size_bytes) - nMempoolUsage, 0);
2701
2702 if (cacheSize > nTotalSpace) {
2703 LogInfo("Cache size (%s) exceeds total space (%s)\n", cacheSize, nTotalSpace);
2705 } else if (cacheSize > LargeCoinsCacheThreshold(nTotalSpace)) {
2707 }
2709}
2710
2712 BlockValidationState &state,
2713 FlushStateMode mode,
2714 int nManualPruneHeight)
2715{
2716 LOCK(cs_main);
2717 assert(this->CanFlushToDisk());
2718 std::set<int> setFilesToPrune;
2719 bool full_flush_completed = false;
2720
2721 [[maybe_unused]] const size_t coins_count{CoinsTip().GetCacheSize()};
2722 [[maybe_unused]] const size_t coins_mem_usage{CoinsTip().DynamicMemoryUsage()};
2723
2724 try {
2725 {
2726 bool fFlushForPrune = false;
2727
2728 CoinsCacheSizeState cache_state = GetCoinsCacheSizeState();
2730 // make sure we don't prune above any of the prune locks bestblocks
2731 // pruning is height-based
2732 int last_prune{m_chain.Height()}; // last height we can prune
2733 std::optional<std::string> limiting_lock; // prune lock that actually was the limiting factor, only used for logging
2734
2735 for (const auto& prune_lock : m_blockman.m_prune_locks) {
2736 if (prune_lock.second.height_first == std::numeric_limits<int>::max()) continue;
2737 // Remove the buffer and one additional block here to get actual height that is outside of the buffer
2738 const int lock_height{prune_lock.second.height_first - PRUNE_LOCK_BUFFER - 1};
2739 last_prune = std::max(1, std::min(last_prune, lock_height));
2740 if (last_prune == lock_height) {
2741 limiting_lock = prune_lock.first;
2742 }
2743 }
2744
2745 if (limiting_lock) {
2746 LogDebug(BCLog::PRUNE, "%s limited pruning to height %d\n", limiting_lock.value(), last_prune);
2747 }
2748
2749 if (nManualPruneHeight > 0) {
2750 LOG_TIME_MILLIS_WITH_CATEGORY("find files to prune (manual)", BCLog::BENCH);
2751
2753 setFilesToPrune,
2754 std::min(last_prune, nManualPruneHeight),
2755 *this);
2756 } else {
2757 LOG_TIME_MILLIS_WITH_CATEGORY("find files to prune", BCLog::BENCH);
2758
2759 m_blockman.FindFilesToPrune(setFilesToPrune, last_prune, *this, m_chainman);
2761 }
2762 if (!setFilesToPrune.empty()) {
2763 fFlushForPrune = true;
2765 m_blockman.m_block_tree_db->WriteFlag("prunedblockfiles", true);
2767 }
2768 }
2769 }
2770 const auto nNow{NodeClock::now()};
2771 // The cache is large and we're within 10% and 10 MiB of the limit, but we have time now (not in the middle of a block processing).
2772 bool fCacheLarge = mode == FlushStateMode::PERIODIC && cache_state >= CoinsCacheSizeState::LARGE;
2773 // The cache is over the limit, we have to write now.
2774 bool fCacheCritical = mode == FlushStateMode::IF_NEEDED && cache_state >= CoinsCacheSizeState::CRITICAL;
2775 // It's been a while since we wrote the block index and chain state to disk. Do this frequently, so we don't need to redownload or reindex after a crash.
2776 bool fPeriodicWrite = mode == FlushStateMode::PERIODIC && nNow >= m_next_write;
2777 const auto empty_cache{(mode == FlushStateMode::FORCE_FLUSH) || fCacheLarge || fCacheCritical};
2778 // Combine all conditions that result in a write to disk.
2779 bool should_write = (mode == FlushStateMode::FORCE_SYNC) || empty_cache || fPeriodicWrite || fFlushForPrune;
2780 // Write blocks, block index and best chain related state to disk.
2781 if (should_write) {
2782 LogDebug(BCLog::COINDB, "Writing chainstate to disk: flush mode=%s, prune=%d, large=%d, critical=%d, periodic=%d",
2783 FlushStateModeNames[size_t(mode)], fFlushForPrune, fCacheLarge, fCacheCritical, fPeriodicWrite);
2784
2785 // Ensure we can write block index
2787 return FatalError(m_chainman.GetNotifications(), state, _("Disk space is too low!"));
2788 }
2789 {
2790 LOG_TIME_MILLIS_WITH_CATEGORY("write block and undo data to disk", BCLog::BENCH);
2791
2792 // First make sure all block and undo data is flushed to disk.
2793 // TODO: Handle return error, or add detailed comment why it is
2794 // safe to not return an error upon failure.
2795 if (!m_blockman.FlushChainstateBlockFile(m_chain.Height())) {
2796 LogWarning("%s: Failed to flush block file.\n", __func__);
2797 }
2798 }
2799
2800 // Then update all block file information (which may refer to block and undo files).
2801 {
2802 LOG_TIME_MILLIS_WITH_CATEGORY("write block index to disk", BCLog::BENCH);
2803
2804 m_blockman.WriteBlockIndexDB();
2805 }
2806 // Finally remove any pruned files
2807 if (fFlushForPrune) {
2808 LOG_TIME_MILLIS_WITH_CATEGORY("unlink pruned files", BCLog::BENCH);
2809
2810 m_blockman.UnlinkPrunedFiles(setFilesToPrune);
2811 }
2812
2813 if (!CoinsTip().GetBestBlock().IsNull()) {
2814 // Typical Coin structures on disk are around 48 bytes in size.
2815 // Pushing a new one to the database can cause it to be written
2816 // twice (once in the log, and once in the tables). This is already
2817 // an overestimation, as most will delete an existing entry or
2818 // overwrite one. Still, use a conservative safety factor of 2.
2819 if (!CheckDiskSpace(m_chainman.m_options.datadir, 48 * 2 * 2 * CoinsTip().GetDirtyCount())) {
2820 return FatalError(m_chainman.GetNotifications(), state, _("Disk space is too low!"));
2821 }
2822 // Flush the chainstate (which may refer to block index entries).
2823 empty_cache ? CoinsTip().Flush() : CoinsTip().Sync();
2824 m_last_flushed_block = m_blockman.LookupBlockIndex(CoinsTip().GetBestBlock());
2825 full_flush_completed = true;
2826 TRACEPOINT(utxocache, flush,
2827 int64_t{Ticks<std::chrono::microseconds>(NodeClock::now() - nNow)},
2828 (uint32_t)mode,
2829 (uint64_t)coins_count,
2830 (uint64_t)coins_mem_usage,
2831 (bool)fFlushForPrune);
2832 }
2833 }
2834
2835 if (should_write || m_next_write == NodeClock::time_point::max()) {
2838 }
2839 }
2840 if (full_flush_completed) {
2842 m_chainman.m_options.signals->ChainStateFlushed(this->GetRole(), GetLocator(m_last_flushed_block));
2843 }
2844
2846 try {
2848 } catch (const std::exception& e) {
2849 LogWarning("Failed to start chainstate compaction (%s)", e.what());
2850 }
2851 }
2852 }
2853 } catch (const std::runtime_error& e) {
2854 return FatalError(m_chainman.GetNotifications(), state, strprintf(_("System error while flushing: %s"), e.what()));
2855 }
2856 return true;
2857}
2858
2860{
2863 LogWarning("Failed to force flush state (%s)", state.ToString());
2864 }
2865}
2866
2868{
2871 if (!this->FlushStateToDisk(state, FlushStateMode::NONE)) {
2872 LogWarning("Failed to flush state (%s)", state.ToString());
2873 }
2874}
2875
2876static void UpdateTipLog(
2877 const ChainstateManager& chainman,
2878 const CCoinsViewCache& coins_tip,
2879 const CBlockIndex* tip,
2880 const std::string& func_name,
2881 const std::string& prefix,
2882 const std::string& warning_messages,
2883 const bool background_validation) EXCLUSIVE_LOCKS_REQUIRED(::cs_main)
2884{
2885
2887
2888 // Disable rate limiting as this may log frequently during IBD.
2889 LogInfo(util::log::NO_RATE_LIMIT, "%s%s: new best=%s height=%d version=0x%08x log2_work=%f tx=%lu date='%s' progress=%f cache=%.1fMiB(%utxo)%s\n",
2890 prefix, func_name,
2891 tip->GetBlockHash().ToString(), tip->nHeight, tip->nVersion,
2892 log(tip->nChainWork.getdouble()) / log(2.0), tip->m_chain_tx_count,
2894 background_validation ? chainman.GetBackgroundVerificationProgress(*tip) : chainman.GuessVerificationProgress(tip),
2895 coins_tip.DynamicMemoryUsage() / double(1_MiB),
2896 coins_tip.GetCacheSize(),
2897 !warning_messages.empty() ? strprintf(" warning='%s'", warning_messages) : "");
2898}
2899
2900void Chainstate::UpdateTip(const CBlockIndex* pindexNew)
2901{
2903 const auto& coins_tip = this->CoinsTip();
2904
2905 // The remainder of the function isn't relevant if we are not acting on
2906 // the active chainstate, so return if need be.
2907 if (this != &m_chainman.ActiveChainstate()) {
2908 // Only log every so often so that we don't bury log messages at the tip.
2909 constexpr int BACKGROUND_LOG_INTERVAL = 2000;
2910 if (pindexNew->nHeight % BACKGROUND_LOG_INTERVAL == 0) {
2911 UpdateTipLog(m_chainman, coins_tip, pindexNew, __func__, "[background validation] ", "", /*background_validation=*/true);
2912 }
2913 return;
2914 }
2915
2916 // New best block
2917 if (m_mempool) {
2919 }
2920
2921 std::vector<bilingual_str> warning_messages;
2924 for (auto [bit, active] : bits) {
2925 const bilingual_str warning = strprintf(_("Unknown new rules activated (versionbit %i)"), bit);
2926 if (active) {
2928 } else {
2929 warning_messages.push_back(warning);
2930 }
2931 }
2932 }
2933 UpdateTipLog(m_chainman, coins_tip, pindexNew, __func__, "",
2934 util::Join(warning_messages, Untranslated(", ")).original, /*background_validation=*/false);
2935}
2936
2948{
2951
2952 CBlockIndex *pindexDelete = m_chain.Tip();
2953 assert(pindexDelete);
2954 assert(pindexDelete->pprev);
2955 // Read block from disk.
2956 std::shared_ptr<CBlock> pblock = std::make_shared<CBlock>();
2957 CBlock& block = *pblock;
2958 if (!m_blockman.ReadBlock(block, *pindexDelete)) {
2959 LogError("DisconnectTip(): Failed to read block\n");
2960 return false;
2961 }
2962 // Apply the block atomically to the chain state.
2963 const auto time_start{SteadyClock::now()};
2964 {
2965 CCoinsViewCache view(&CoinsTip());
2966 assert(view.GetBestBlock() == pindexDelete->GetBlockHash());
2967 if (DisconnectBlock(block, pindexDelete, view) != DISCONNECT_OK) {
2968 LogError("DisconnectTip(): DisconnectBlock %s failed\n", pindexDelete->GetBlockHash().ToString());
2969 return false;
2970 }
2971 view.Flush(/*reallocate_cache=*/false); // local CCoinsViewCache goes out of scope
2972 }
2973 LogDebug(BCLog::BENCH, "- Disconnect block: %.2fms\n",
2974 Ticks<MillisecondsDouble>(SteadyClock::now() - time_start));
2975
2976 {
2977 // Prune locks that began at or after the tip should be moved backward so they get a chance to reorg
2978 const int max_height_first{pindexDelete->nHeight - 1};
2979 for (auto& prune_lock : m_blockman.m_prune_locks) {
2980 if (prune_lock.second.height_first <= max_height_first) continue;
2981
2982 prune_lock.second.height_first = max_height_first;
2983 LogDebug(BCLog::PRUNE, "%s prune lock moved back to %d\n", prune_lock.first, max_height_first);
2984 }
2985 }
2986
2987 // Write the chain state to disk, if necessary.
2989 return false;
2990 }
2991
2992 if (disconnectpool && m_mempool) {
2993 // Save transactions to re-add to mempool at end of reorg. If any entries are evicted for
2994 // exceeding memory limits, remove them and their descendants from the mempool.
2995 for (auto&& evicted_tx : disconnectpool->AddTransactionsFromBlock(block.vtx)) {
2997 }
2998 }
2999
3000 m_chain.SetTip(*pindexDelete->pprev);
3002
3003 UpdateTip(pindexDelete->pprev);
3004 // Let wallets know transactions went from 1-confirmed to
3005 // 0-confirmed or conflicted:
3007 m_chainman.m_options.signals->BlockDisconnected(std::move(pblock), pindexDelete);
3008 }
3009 return true;
3010}
3011
3014 std::shared_ptr<const CBlock> pblock;
3015};
3016
3024 BlockValidationState& state,
3025 CBlockIndex* pindexNew,
3026 std::shared_ptr<const CBlock> block_to_connect,
3027 std::vector<ConnectedBlock>& connected_blocks,
3028 DisconnectedBlockTransactions& disconnectpool)
3029{
3032
3033 assert(pindexNew->pprev == m_chain.Tip());
3034 // Read block from disk.
3035 const auto time_1{SteadyClock::now()};
3036 if (!block_to_connect) {
3037 std::shared_ptr<CBlock> pblockNew = std::make_shared<CBlock>();
3038 if (!m_blockman.ReadBlock(*pblockNew, *pindexNew)) {
3039 return FatalError(m_chainman.GetNotifications(), state, _("Failed to read block."));
3040 }
3041 block_to_connect = std::move(pblockNew);
3042 } else {
3043 LogDebug(BCLog::BENCH, " - Using cached block\n");
3044 }
3045 // Apply the block atomically to the chain state.
3046 const auto time_2{SteadyClock::now()};
3047 SteadyClock::time_point time_3;
3048 // When adding aggregate statistics in the future, keep in mind that
3049 // num_blocks_total may be zero until the ConnectBlock() call below.
3050 LogDebug(BCLog::BENCH, " - Load block from disk: %.2fms\n",
3051 Ticks<MillisecondsDouble>(time_2 - time_1));
3052 {
3053 CoinsViewOverlay& view{*m_coins_views->m_connect_block_view};
3054 const auto reset_guard{view.StartFetching(*block_to_connect)};
3055 bool rv = ConnectBlock(*block_to_connect, state, pindexNew, view);
3057 m_chainman.m_options.signals->BlockChecked(block_to_connect, state);
3058 }
3059 if (!rv) {
3060 if (state.IsInvalid())
3061 InvalidBlockFound(pindexNew, state);
3062 LogError("%s: ConnectBlock %s failed, %s\n", __func__, pindexNew->GetBlockHash().ToString(), state.ToString());
3063 return false;
3064 }
3065 time_3 = SteadyClock::now();
3066 m_chainman.time_connect_total += time_3 - time_2;
3067 assert(m_chainman.num_blocks_total > 0);
3068 LogDebug(BCLog::BENCH, " - Connect total: %.2fms [%.2fs (%.2fms/blk)]\n",
3069 Ticks<MillisecondsDouble>(time_3 - time_2),
3070 Ticks<SecondsDouble>(m_chainman.time_connect_total),
3071 Ticks<MillisecondsDouble>(m_chainman.time_connect_total) / m_chainman.num_blocks_total);
3072 view.Flush(/*reallocate_cache=*/false); // No need to reallocate since it only has capacity for 1 block
3073 }
3074 const auto time_4{SteadyClock::now()};
3075 m_chainman.time_flush += time_4 - time_3;
3076 LogDebug(BCLog::BENCH, " - Flush: %.2fms [%.2fs (%.2fms/blk)]\n",
3077 Ticks<MillisecondsDouble>(time_4 - time_3),
3078 Ticks<SecondsDouble>(m_chainman.time_flush),
3079 Ticks<MillisecondsDouble>(m_chainman.time_flush) / m_chainman.num_blocks_total);
3080 // Write the chain state to disk, if necessary.
3082 return false;
3083 }
3084 const auto time_5{SteadyClock::now()};
3085 m_chainman.time_chainstate += time_5 - time_4;
3086 LogDebug(BCLog::BENCH, " - Writing chainstate: %.2fms [%.2fs (%.2fms/blk)]\n",
3087 Ticks<MillisecondsDouble>(time_5 - time_4),
3088 Ticks<SecondsDouble>(m_chainman.time_chainstate),
3089 Ticks<MillisecondsDouble>(m_chainman.time_chainstate) / m_chainman.num_blocks_total);
3090 // Remove conflicting transactions from the mempool.
3091 std::vector<RemovedMempoolTransactionInfo> txs_removed_for_block;
3092 if (m_mempool) {
3093 txs_removed_for_block = m_mempool->removeForBlock(block_to_connect->vtx);
3094 disconnectpool.removeForBlock(block_to_connect->vtx);
3095 }
3096 // Update m_chain & related variables.
3097 m_chain.SetTip(*pindexNew);
3099 // Not fired while IBD is active. removeForBlock() above still runs.
3101 m_chainman.m_options.signals->MempoolTransactionsRemovedForBlock(block_to_connect, std::move(txs_removed_for_block), pindexNew->nHeight);
3102 }
3103 UpdateTip(pindexNew);
3104
3105 const auto time_6{SteadyClock::now()};
3106 m_chainman.time_post_connect += time_6 - time_5;
3107 m_chainman.time_total += time_6 - time_1;
3108 LogDebug(BCLog::BENCH, " - Connect postprocess: %.2fms [%.2fs (%.2fms/blk)]\n",
3109 Ticks<MillisecondsDouble>(time_6 - time_5),
3110 Ticks<SecondsDouble>(m_chainman.time_post_connect),
3111 Ticks<MillisecondsDouble>(m_chainman.time_post_connect) / m_chainman.num_blocks_total);
3112 LogDebug(BCLog::BENCH, "- Connect block: %.2fms [%.2fs (%.2fms/blk)]\n",
3113 Ticks<MillisecondsDouble>(time_6 - time_1),
3114 Ticks<SecondsDouble>(m_chainman.time_total),
3115 Ticks<MillisecondsDouble>(m_chainman.time_total) / m_chainman.num_blocks_total);
3116
3117 // See if this chainstate has reached a target block and can be used to
3118 // validate an assumeutxo snapshot. If it can, hashing the UTXO database
3119 // will be slow, and cs_main could remain locked here for several minutes.
3120 // If the snapshot is validated, the UTXO hash will be saved to
3121 // this->m_target_utxohash, causing HistoricalChainstate() to return null
3122 // and this chainstate to no longer be used. ActivateBestChain() will also
3123 // stop connecting blocks to this chainstate because this->ReachedTarget()
3124 // will be true and this->setBlockIndexCandidates will not have additional
3125 // blocks.
3127 m_chainman.MaybeValidateSnapshot(*this, current_cs);
3128
3129 connected_blocks.emplace_back(pindexNew, std::move(block_to_connect));
3130 return true;
3131}
3132
3138{
3140 do {
3141 CBlockIndex *pindexNew = nullptr;
3142
3143 // Find the best candidate header.
3144 {
3145 std::set<CBlockIndex*, CBlockIndexWorkComparator>::reverse_iterator it = setBlockIndexCandidates.rbegin();
3146 if (it == setBlockIndexCandidates.rend())
3147 return nullptr;
3148 pindexNew = *it;
3149 }
3150
3151 // Check whether all blocks on the path between the currently active chain and the candidate are valid.
3152 // Just going until the active chain is an optimization, as we know all blocks in it are valid already.
3153 bool fInvalidAncestor = false;
3154 for (CBlockIndex *pindexTest = pindexNew; pindexTest && !m_chain.Contains(*pindexTest); pindexTest = pindexTest->pprev) {
3155 assert(pindexTest->HaveNumChainTxs() || pindexTest->nHeight == 0);
3156
3157 // Pruned nodes may have entries in setBlockIndexCandidates for
3158 // which block files have been deleted. Remove those as candidates
3159 // for the most work chain if we come across them; we can't switch
3160 // to a chain unless we have all the non-active-chain parent blocks.
3161 bool fFailedChain = pindexTest->nStatus & BLOCK_FAILED_VALID;
3162 bool fMissingData = !(pindexTest->nStatus & BLOCK_HAVE_DATA);
3163 if (fFailedChain || fMissingData) {
3164 // Candidate chain is not usable (either invalid or missing data)
3165 if (fFailedChain && (m_chainman.m_best_invalid == nullptr || pindexNew->nChainWork > m_chainman.m_best_invalid->nChainWork)) {
3166 m_chainman.m_best_invalid = pindexNew;
3167 }
3168 // Remove the entire chain from the set.
3169 for (CBlockIndex *pindexFailed = pindexNew; pindexFailed != pindexTest; pindexFailed = pindexFailed->pprev) {
3170 // If we're missing data and not a descendant of an invalid block,
3171 // then add back to m_blocks_unlinked, so that if the block arrives in the future
3172 // we can try adding to setBlockIndexCandidates again.
3173 if (fMissingData && !fFailedChain) {
3174 // Avoid duplicate entries in m_blocks_unlinked. If the same entry is
3175 // processed twice in ReceivedBlockTransactions(), it may be re-added to
3176 // setBlockIndexCandidates with a modified nSequenceId, breaking ordering
3177 // guarantees and leading to undefined behavior.
3178 m_blockman.AddUnlinkedBlock(pindexFailed);
3179 }
3180 setBlockIndexCandidates.erase(pindexFailed);
3181 }
3182 setBlockIndexCandidates.erase(pindexTest);
3183 fInvalidAncestor = true;
3184 break;
3185 }
3186 }
3187 if (!fInvalidAncestor)
3188 return pindexNew;
3189 } while(true);
3190}
3191
3194 // Note that we can't delete the current block itself, as we may need to return to it later in case a
3195 // reorganization to a better block fails.
3196 std::set<CBlockIndex*, CBlockIndexWorkComparator>::iterator it = setBlockIndexCandidates.begin();
3197 while (it != setBlockIndexCandidates.end() && setBlockIndexCandidates.value_comp()(*it, m_chain.Tip())) {
3198 setBlockIndexCandidates.erase(it++);
3199 }
3200 // Either the current tip or a successor of it we're working towards is left in setBlockIndexCandidates.
3202}
3203
3210bool Chainstate::ActivateBestChainStep(BlockValidationState& state, CBlockIndex& index_most_work, const std::shared_ptr<const CBlock>& pblock, bool& fInvalidFound, std::vector<ConnectedBlock>& connected_blocks)
3211{
3214
3215 const CBlockIndex* pindexOldTip = m_chain.Tip();
3216 const CBlockIndex* pindexFork = m_chain.FindFork(index_most_work);
3217
3218 // Disconnect active blocks which are no longer in the best chain.
3219 bool fBlocksDisconnected = false;
3221 while (m_chain.Tip() && m_chain.Tip() != pindexFork) {
3222 if (!DisconnectTip(state, &disconnectpool)) {
3223 // This is likely a fatal error, but keep the mempool consistent,
3224 // just in case. Only remove from the mempool in this case.
3225 MaybeUpdateMempoolForReorg(disconnectpool, false);
3226
3227 // If we're unable to disconnect a block during normal operation,
3228 // then that is a failure of our local system -- we should abort
3229 // rather than stay on a less work chain.
3230 FatalError(m_chainman.GetNotifications(), state, _("Failed to disconnect block."));
3231 return false;
3232 }
3233 fBlocksDisconnected = true;
3234 }
3235
3236 // Build list of new blocks to connect (in descending height order).
3237 std::vector<CBlockIndex*> vpindexToConnect;
3238 bool fContinue = true;
3239 int nHeight = pindexFork ? pindexFork->nHeight : -1;
3240 while (fContinue && nHeight != index_most_work.nHeight) {
3241 // Don't iterate the entire list of potential improvements toward the best tip, as we likely only need
3242 // a few blocks along the way.
3243 int nTargetHeight = std::min(nHeight + 32, index_most_work.nHeight);
3244 vpindexToConnect.clear();
3245 vpindexToConnect.reserve(nTargetHeight - nHeight);
3246 CBlockIndex* pindexIter = index_most_work.GetAncestor(nTargetHeight);
3247 while (pindexIter && pindexIter->nHeight != nHeight) {
3248 vpindexToConnect.push_back(pindexIter);
3249 pindexIter = pindexIter->pprev;
3250 }
3251 nHeight = nTargetHeight;
3252
3253 // Connect new blocks.
3254 for (CBlockIndex* pindexConnect : vpindexToConnect | std::views::reverse) {
3255 if (!ConnectTip(state, pindexConnect, pindexConnect == &index_most_work ? pblock : std::shared_ptr<const CBlock>(), connected_blocks, disconnectpool)) {
3256 if (state.IsInvalid()) {
3257 // The block violates a consensus rule.
3259 InvalidChainFound(vpindexToConnect.front());
3260 }
3261 state = BlockValidationState();
3262 fInvalidFound = true;
3263 fContinue = false;
3264 break;
3265 } else {
3266 // A system error occurred (disk space, database error, ...).
3267 // Make the mempool consistent with the current tip, just in case
3268 // any observers try to use it before shutdown.
3269 MaybeUpdateMempoolForReorg(disconnectpool, false);
3270 return false;
3271 }
3272 } else {
3274 if (!pindexOldTip || m_chain.Tip()->nChainWork > pindexOldTip->nChainWork) {
3275 // We're in a better position than we were. Return temporarily to release the lock.
3276 fContinue = false;
3277 break;
3278 }
3279 }
3280 }
3281 }
3282
3283 if (fBlocksDisconnected) {
3284 // If any blocks were disconnected, disconnectpool may be non empty. Add
3285 // any disconnected transactions back to the mempool.
3286 MaybeUpdateMempoolForReorg(disconnectpool, true);
3287 }
3288 if (m_mempool) m_mempool->check(this->CoinsTip(), this->m_chain.Height() + 1);
3289
3291
3292 return true;
3293}
3294
3295static SynchronizationState GetSynchronizationState(bool init, bool blockfiles_indexed)
3296{
3298 if (!blockfiles_indexed) return SynchronizationState::INIT_REINDEX;
3300}
3301
3303{
3305 if (!m_cached_is_ibd.load(std::memory_order_relaxed)) return;
3306 if (m_blockman.LoadingBlocks()) return;
3307 if (!CurrentChainstate().m_chain.IsTipRecent(MinimumChainWork(), m_options.max_tip_age)) return;
3308 LogInfo("Leaving InitialBlockDownload (latching to false)");
3309 m_cached_is_ibd.store(false, std::memory_order_relaxed);
3310}
3311
3313{
3314 bool fNotify = false;
3315 bool fInitialBlockDownload = false;
3316 CBlockIndex* pindexHeader = nullptr;
3317 {
3318 LOCK(GetMutex());
3319 pindexHeader = m_best_header;
3320
3321 if (pindexHeader != m_last_notified_header) {
3322 fNotify = true;
3323 fInitialBlockDownload = IsInitialBlockDownload();
3324 m_last_notified_header = pindexHeader;
3325 }
3326 }
3327 // Send block tip changed notifications without the lock held
3328 if (fNotify) {
3329 GetNotifications().headerTip(GetSynchronizationState(fInitialBlockDownload, m_blockman.m_blockfiles_indexed), pindexHeader->nHeight, pindexHeader->nTime, false);
3330 }
3331 return fNotify;
3332}
3333
3336
3337 if (signals.CallbacksPending() > 10) {
3338 signals.SyncWithValidationInterfaceQueue();
3339 }
3340}
3341
3342bool Chainstate::ActivateBestChain(BlockValidationState& state, std::shared_ptr<const CBlock> pblock)
3343{
3345
3346 // Note that while we're often called here from ProcessNewBlock, this is
3347 // far from a guarantee. Things in the P2P/RPC will often end up calling
3348 // us in the middle of ProcessNewBlock - do not assume pblock is set
3349 // sanely for performance or correctness!
3351
3352 // ABC maintains a fair degree of expensive-to-calculate internal state
3353 // because this function periodically releases cs_main so that it does not lock up other threads for too long
3354 // during large connects - and to allow for e.g. the callback queue to drain
3355 // we use m_chainstate_mutex to enforce mutual exclusion so that only one caller may execute this function at a time
3357
3358 // Belt-and-suspenders check that we aren't attempting to advance the
3359 // chainstate past the target block.
3360 if (WITH_LOCK(::cs_main, return m_target_utxohash)) {
3361 LogError("%s", STR_INTERNAL_BUG("m_target_utxohash is set - this chainstate should not be in operation."));
3362 return Assume(false);
3363 }
3364
3365 CBlockIndex *pindexMostWork = nullptr;
3366 CBlockIndex *pindexNewTip = nullptr;
3367 bool exited_ibd{false};
3368 do {
3369 // Block until the validation queue drains. This should largely
3370 // never happen in normal operation, however may happen during
3371 // reindex, causing memory blowup if we run too far ahead.
3372 // Note that if a validationinterface callback ends up calling
3373 // ActivateBestChain this may lead to a deadlock! We should
3374 // probably have a DEBUG_LOCKORDER test for this in the future.
3376
3377 {
3378 LOCK(cs_main);
3379 {
3380 // Lock transaction pool for at least as long as it takes for connected_blocks to be consumed
3381 LOCK(MempoolMutex());
3382 const bool was_in_ibd = m_chainman.IsInitialBlockDownload();
3383 CBlockIndex* starting_tip = m_chain.Tip();
3384 bool blocks_connected = false;
3385 do {
3386 // We absolutely may not unlock cs_main until we've made forward progress
3387 // (with the exception of shutdown due to hardware issues, low disk space, etc).
3388 std::vector<ConnectedBlock> connected_blocks; // Destructed before cs_main is unlocked
3389
3390 if (pindexMostWork == nullptr) {
3391 pindexMostWork = FindMostWorkChain();
3392 }
3393
3394 // Whether we have anything to do at all.
3395 if (pindexMostWork == nullptr || pindexMostWork == m_chain.Tip()) {
3396 break;
3397 }
3398
3399 bool fInvalidFound = false;
3400 std::shared_ptr<const CBlock> nullBlockPtr;
3401 // BlockConnected signals must be sent for the original role;
3402 // in case snapshot validation is completed during ActivateBestChainStep, the
3403 // result of GetRole() changes from BACKGROUND to NORMAL.
3404 const ChainstateRole chainstate_role{this->GetRole()};
3405 if (!ActivateBestChainStep(state, *pindexMostWork, pblock && pblock->GetHash() == pindexMostWork->GetBlockHash() ? pblock : nullBlockPtr, fInvalidFound, connected_blocks)) {
3406 // A system error occurred
3407 return false;
3408 }
3409 blocks_connected = true;
3410
3411 if (fInvalidFound) {
3412 // Wipe cache, we may need another branch now.
3413 pindexMostWork = nullptr;
3414 }
3415 pindexNewTip = m_chain.Tip();
3416
3417 for (auto& [index, block] : std::move(connected_blocks)) {
3419 m_chainman.m_options.signals->BlockConnected(chainstate_role, std::move(Assert(block)), Assert(index));
3420 }
3421 }
3422
3423 // Break this do-while to ensure we don't advance past the target block.
3424 if (ReachedTarget()) {
3425 break;
3426 }
3427 } while (!m_chain.Tip() || (starting_tip && CBlockIndexWorkComparator()(m_chain.Tip(), starting_tip)));
3428 if (!blocks_connected) return true;
3429
3430 const CBlockIndex* pindexFork = starting_tip ? m_chain.FindFork(*starting_tip) : nullptr;
3431 bool still_in_ibd = m_chainman.IsInitialBlockDownload();
3432
3433 if (was_in_ibd && !still_in_ibd) {
3434 // Active chainstate has exited IBD.
3435 exited_ibd = true;
3436 }
3437
3438 // Notify external listeners about the new tip.
3439 // Enqueue while holding cs_main to ensure that UpdatedBlockTip is called in the order in which blocks are connected
3440 if (this == &m_chainman.ActiveChainstate() && pindexFork != pindexNewTip) {
3441 // Notify ValidationInterface subscribers
3443 m_chainman.m_options.signals->UpdatedBlockTip(pindexNewTip, pindexFork, still_in_ibd);
3444 }
3445
3448 /*index=*/*pindexNewTip,
3449 /*verification_progress=*/m_chainman.GuessVerificationProgress(pindexNewTip))))
3450 {
3451 // Just breaking and returning success for now. This could
3452 // be changed to bubble up the kernel::Interrupted value to
3453 // the caller so the caller could distinguish between
3454 // completed and interrupted operations.
3455 break;
3456 }
3457 }
3458 } // release MempoolMutex
3459 // Notify external listeners about the new tip, even if pindexFork == pindexNewTip.
3462 }
3463 } // release cs_main
3464 // When we reach this point, we switched to a new tip (stored in pindexNewTip).
3465
3466 bool reached_target;
3467 {
3469 if (exited_ibd) {
3470 // If a background chainstate is in use, we may need to rebalance our
3471 // allocation of caches once a chainstate exits initial block download.
3472 m_chainman.MaybeRebalanceCaches();
3473 }
3474
3475 // Write changes periodically to disk, after relay.
3477 return false;
3478 }
3479
3480 reached_target = ReachedTarget();
3481 }
3482
3483 if (reached_target) {
3484 // Chainstate has reached the target block, so exit.
3485 //
3486 // Restart indexes so indexes can resync and index new blocks after
3487 // the target block.
3488 //
3489 // This cannot be done while holding cs_main (within
3490 // MaybeValidateSnapshot) or a cs_main deadlock will occur.
3493 }
3494 break;
3495 }
3496
3497 // We check interrupt only after giving ActivateBestChainStep a chance to run once so that we
3498 // never interrupt before connecting the genesis block during LoadChainTip(). Previously this
3499 // caused an assert() failure during interrupt in such cases as the UTXO DB flushing checks
3500 // that the best block hash is non-null.
3501 if (m_chainman.m_interrupt) break;
3502 } while (pindexNewTip != pindexMostWork);
3503
3505
3506 return true;
3507}
3508
3509bool Chainstate::PreciousBlock(BlockValidationState& state, CBlockIndex* pindex)
3510{
3513 {
3514 LOCK(cs_main);
3515 if (pindex->nChainWork < m_chain.Tip()->nChainWork) {
3516 // Nothing to do, this block is not at the tip.
3517 return true;
3518 }
3520 // The chain has been extended since the last call, reset the counter.
3522 }
3524 setBlockIndexCandidates.erase(pindex);
3526 if (m_chainman.nBlockReverseSequenceId > std::numeric_limits<int32_t>::min()) {
3527 // We can't keep reducing the counter if somebody really wants to
3528 // call preciousblock 2**31-1 times on the same set of tips...
3530 }
3531 if (pindex->IsValid(BLOCK_VALID_TRANSACTIONS) && pindex->HaveNumChainTxs()) {
3532 setBlockIndexCandidates.insert(pindex);
3534 }
3535 }
3536
3537 return ActivateBestChain(state, std::shared_ptr<const CBlock>());
3538}
3539
3541{
3544
3545 // Genesis block can't be invalidated
3546 assert(pindex);
3547 if (pindex->nHeight == 0) return false;
3548
3549 // We do not allow ActivateBestChain() to run while InvalidateBlock() is
3550 // running, as that could cause the tip to change while we disconnect
3551 // blocks.
3553
3554 // We'll be acquiring and releasing cs_main below, to allow the validation
3555 // callbacks to run. However, we should keep the block index in a
3556 // consistent state as we disconnect blocks -- in particular we need to
3557 // add equal-work blocks to setBlockIndexCandidates as we disconnect.
3558 // To avoid walking the block index repeatedly in search of candidates,
3559 // build a map once so that we can look up candidate blocks by chain
3560 // work as we go.
3561 std::multimap<const arith_uint256, CBlockIndex*> highpow_outofchain_headers;
3562
3563 {
3564 LOCK(cs_main);
3565 for (auto& entry : m_blockman.m_block_index) {
3566 CBlockIndex& candidate = entry.second;
3567 // We don't need to put anything in our active chain into the
3568 // multimap, because those candidates will be found and considered
3569 // as we disconnect.
3570 // Instead, consider only non-active-chain blocks that score
3571 // at least as good with CBlockIndexWorkComparator as the new tip.
3572 if (!m_chain.Contains(candidate) &&
3573 !CBlockIndexWorkComparator()(&candidate, pindex->pprev) &&
3574 !(candidate.nStatus & BLOCK_FAILED_VALID)) {
3575 highpow_outofchain_headers.insert({candidate.nChainWork, &candidate});
3576 }
3577 }
3578 }
3579
3580 CBlockIndex* to_mark_failed = pindex;
3581 bool pindex_was_in_chain = false;
3582 int disconnected = 0;
3583
3584 // Disconnect (descendants of) pindex, and mark them invalid.
3585 while (true) {
3586 if (m_chainman.m_interrupt) break;
3587
3588 // Make sure the queue of validation callbacks doesn't grow unboundedly.
3590
3591 LOCK(cs_main);
3592 // Lock for as long as disconnectpool is in scope to make sure MaybeUpdateMempoolForReorg is
3593 // called after DisconnectTip without unlocking in between
3594 LOCK(MempoolMutex());
3595 if (!m_chain.Contains(*pindex)) break;
3596 pindex_was_in_chain = true;
3597 CBlockIndex* const disconnected_tip{m_chain.Tip()};
3598
3599 // ActivateBestChain considers blocks already in m_chain
3600 // unconditionally valid already, so force disconnect away from it.
3602 bool ret = DisconnectTip(state, &disconnectpool);
3603 // DisconnectTip will add transactions to disconnectpool.
3604 // Adjust the mempool to be consistent with the new tip, adding
3605 // transactions back to the mempool if disconnecting was successful,
3606 // and we're not doing a very deep invalidation (in which case
3607 // keeping the mempool up to date is probably futile anyway).
3608 MaybeUpdateMempoolForReorg(disconnectpool, /* fAddToMempool = */ (++disconnected <= 10) && ret);
3609 if (!ret) return false;
3610 CBlockIndex* new_tip{m_chain.Tip()};
3611 assert(disconnected_tip->pprev == new_tip);
3612
3613 // We immediately mark the disconnected blocks as invalid.
3614 // This prevents a case where pruned nodes may fail to invalidateblock
3615 // and be left unable to start as they have no tip candidates (as there
3616 // are no blocks that meet the "have data and are not invalid per
3617 // nStatus" criteria for inclusion in setBlockIndexCandidates).
3618 disconnected_tip->nStatus |= BLOCK_FAILED_VALID;
3619 m_blockman.m_dirty_blockindex.insert(disconnected_tip);
3620 setBlockIndexCandidates.erase(disconnected_tip);
3621 setBlockIndexCandidates.insert(new_tip);
3622
3623 // Mark out-of-chain descendants of the invalidated block as invalid
3624 // Add any equal or more work headers that are not invalidated to setBlockIndexCandidates
3625 // Recalculate m_best_header if it became invalid.
3626 auto candidate_it = highpow_outofchain_headers.lower_bound(new_tip->nChainWork);
3627
3628 const bool best_header_needs_update{m_chainman.m_best_header->GetAncestor(disconnected_tip->nHeight) == disconnected_tip};
3629 if (best_header_needs_update) {
3630 // new_tip is definitely still valid at this point, but there may be better ones
3631 m_chainman.m_best_header = new_tip;
3632 }
3633
3634 while (candidate_it != highpow_outofchain_headers.end()) {
3635 CBlockIndex* candidate{candidate_it->second};
3636 if (candidate->GetAncestor(disconnected_tip->nHeight) == disconnected_tip) {
3637 // Children of failed blocks are marked as BLOCK_FAILED_VALID.
3638 candidate->nStatus |= BLOCK_FAILED_VALID;
3639 m_blockman.m_dirty_blockindex.insert(candidate);
3640 // If invalidated, the block is irrelevant for setBlockIndexCandidates
3641 // and for m_best_header and can be removed from the cache.
3642 candidate_it = highpow_outofchain_headers.erase(candidate_it);
3643 continue;
3644 }
3645 if (!CBlockIndexWorkComparator()(candidate, new_tip) &&
3646 candidate->IsValid(BLOCK_VALID_TRANSACTIONS) &&
3647 candidate->HaveNumChainTxs()) {
3648 setBlockIndexCandidates.insert(candidate);
3649 // Do not remove candidate from the highpow_outofchain_headers cache, because it might be a descendant of the block being invalidated
3650 // which needs to be marked failed later.
3651 }
3652 if (best_header_needs_update &&
3653 m_chainman.m_best_header->nChainWork < candidate->nChainWork) {
3654 m_chainman.m_best_header = candidate;
3655 }
3656 ++candidate_it;
3657 }
3658
3659 // Track the last disconnected block to call InvalidChainFound on it.
3660 to_mark_failed = disconnected_tip;
3661 }
3662
3664
3665 {
3666 LOCK(cs_main);
3667 if (m_chain.Contains(*to_mark_failed)) {
3668 // If the to-be-marked invalid block is in the active chain, something is interfering and we can't proceed.
3669 return false;
3670 }
3671
3672 // Mark pindex as invalid if it never was in the main chain
3673 if (!pindex_was_in_chain && !(pindex->nStatus & BLOCK_FAILED_VALID)) {
3674 pindex->nStatus |= BLOCK_FAILED_VALID;
3675 m_blockman.m_dirty_blockindex.insert(pindex);
3676 setBlockIndexCandidates.erase(pindex);
3677 }
3678
3679 // If any new blocks somehow arrived while we were disconnecting
3680 // (above), then the pre-calculation of what should go into
3681 // setBlockIndexCandidates may have missed entries. This would
3682 // technically be an inconsistency in the block index, but if we clean
3683 // it up here, this should be an essentially unobservable error.
3684 // Loop back over all block index entries and add any missing entries
3685 // to setBlockIndexCandidates.
3686 for (auto& [_, block_index] : m_blockman.m_block_index) {
3687 if (block_index.IsValid(BLOCK_VALID_TRANSACTIONS) && block_index.HaveNumChainTxs() && !setBlockIndexCandidates.value_comp()(&block_index, m_chain.Tip())) {
3688 setBlockIndexCandidates.insert(&block_index);
3689 }
3690 }
3691
3692 InvalidChainFound(to_mark_failed);
3693 }
3694
3695 // Only notify about a new block tip if the active chain was modified.
3696 if (pindex_was_in_chain) {
3697 // Ignoring return value for now, this could be changed to bubble up
3698 // kernel::Interrupted value to the caller so the caller could
3699 // distinguish between completed and interrupted operations. It might
3700 // also make sense for the blockTip notification to have an enum
3701 // parameter indicating the source of the tip change so hooks can
3702 // distinguish user-initiated invalidateblock changes from other
3703 // changes.
3706 /*index=*/*to_mark_failed->pprev,
3707 /*verification_progress=*/WITH_LOCK(m_chainman.GetMutex(), return m_chainman.GuessVerificationProgress(to_mark_failed->pprev)));
3708
3709 // Fire ActiveTipChange now for the current chain tip to make sure clients are notified.
3710 // ActivateBestChain may call this as well, but not necessarily.
3713 }
3714 }
3715 return true;
3716}
3717
3718void Chainstate::SetBlockFailureFlags(CBlockIndex* invalid_block)
3719{
3721
3722 for (auto& [_, block_index] : m_blockman.m_block_index) {
3723 if (invalid_block != &block_index && block_index.GetAncestor(invalid_block->nHeight) == invalid_block) {
3724 block_index.nStatus |= BLOCK_FAILED_VALID;
3725 m_blockman.m_dirty_blockindex.insert(&block_index);
3726 }
3727 }
3728}
3729
3732
3733 int nHeight = pindex->nHeight;
3734
3735 // Remove the invalidity flag from this block and all its descendants and ancestors.
3736 for (auto& [_, block_index] : m_blockman.m_block_index) {
3737 if ((block_index.nStatus & BLOCK_FAILED_VALID) && (block_index.GetAncestor(nHeight) == pindex || pindex->GetAncestor(block_index.nHeight) == &block_index)) {
3738 block_index.nStatus &= ~BLOCK_FAILED_VALID;
3739 m_blockman.m_dirty_blockindex.insert(&block_index);
3740 if (block_index.IsValid(BLOCK_VALID_TRANSACTIONS) && block_index.HaveNumChainTxs() && setBlockIndexCandidates.value_comp()(m_chain.Tip(), &block_index)) {
3741 setBlockIndexCandidates.insert(&block_index);
3742 }
3743 if (&block_index == m_chainman.m_best_invalid) {
3744 // Reset invalid block marker if it was pointing to one of those.
3745 m_chainman.m_best_invalid = nullptr;
3746 }
3747 }
3748 }
3749}
3750
3752{
3754
3755 // Do not continue building a chainstate that is based on an invalid
3756 // snapshot. This is a belt-and-suspenders type of check because if an
3757 // invalid snapshot is loaded, the node will shut down to force a manual
3758 // intervention. But it is good to handle this case correctly regardless.
3759 if (m_assumeutxo == Assumeutxo::INVALID) {
3760 return;
3761 }
3762
3763 // The block only is a candidate for the most-work-chain if it has the same
3764 // or more work than our current tip.
3765 if (m_chain.Tip() != nullptr && setBlockIndexCandidates.value_comp()(pindex, m_chain.Tip())) {
3766 return;
3767 }
3768
3769 const CBlockIndex* target_block{TargetBlock()};
3770 if (!target_block) {
3771 // If no specific target block, add all entries that have more
3772 // work than the tip.
3773 setBlockIndexCandidates.insert(pindex);
3774 } else {
3775 // If there is a target block, only consider connecting blocks
3776 // towards the target block.
3777 if (target_block->GetAncestor(pindex->nHeight) == pindex) {
3778 setBlockIndexCandidates.insert(pindex);
3779 }
3780 }
3781}
3782
3785{
3787 pindexNew->nTx = block.vtx.size();
3788 // Typically m_chain_tx_count will be 0 at this point, but it can be nonzero if this
3789 // is a pruned block which is being downloaded again, or if this is an
3790 // assumeutxo snapshot block which has a hardcoded m_chain_tx_count value from the
3791 // snapshot metadata. If the pindex is not the snapshot block and the
3792 // m_chain_tx_count value is not zero, assert that value is actually correct.
3793 auto prev_tx_sum = [](CBlockIndex& block) { return block.nTx + (block.pprev ? block.pprev->m_chain_tx_count : 0); };
3794 if (!Assume(pindexNew->m_chain_tx_count == 0 || pindexNew->m_chain_tx_count == prev_tx_sum(*pindexNew) ||
3795 std::ranges::any_of(m_chainstates, [&](const auto& cs) EXCLUSIVE_LOCKS_REQUIRED(cs_main) { return cs->SnapshotBase() == pindexNew; }))) {
3796 LogWarning("Internal bug detected: block %d has unexpected m_chain_tx_count %i that should be %i (%s %s). Please report this issue here: %s\n",
3797 pindexNew->nHeight, pindexNew->m_chain_tx_count, prev_tx_sum(*pindexNew), CLIENT_NAME, FormatFullVersion(), CLIENT_BUGREPORT);
3798 pindexNew->m_chain_tx_count = 0;
3799 }
3800 pindexNew->nFile = pos.nFile;
3801 pindexNew->nDataPos = pos.nPos;
3802 pindexNew->nUndoPos = 0;
3803 pindexNew->nStatus |= BLOCK_HAVE_DATA;
3804 if (DeploymentActiveAt(*pindexNew, *this, Consensus::DEPLOYMENT_SEGWIT)) {
3805 pindexNew->nStatus |= BLOCK_OPT_WITNESS;
3806 }
3808 m_blockman.m_dirty_blockindex.insert(pindexNew);
3809
3810 if (pindexNew->pprev == nullptr || pindexNew->pprev->HaveNumChainTxs()) {
3811 // If pindexNew is the genesis block or all parents are BLOCK_VALID_TRANSACTIONS.
3812 std::deque<CBlockIndex*> queue;
3813 queue.push_back(pindexNew);
3814
3815 // Recursively process any descendant blocks that now may be eligible to be connected.
3816 while (!queue.empty()) {
3817 CBlockIndex *pindex = queue.front();
3818 queue.pop_front();
3819 // Before setting m_chain_tx_count, assert that it is 0 or already set to
3820 // the correct value. This assert will fail after receiving the
3821 // assumeutxo snapshot block if assumeutxo snapshot metadata has an
3822 // incorrect hardcoded AssumeutxoData::m_chain_tx_count value.
3823 if (!Assume(pindex->m_chain_tx_count == 0 || pindex->m_chain_tx_count == prev_tx_sum(*pindex))) {
3824 LogWarning("Internal bug detected: block %d has unexpected m_chain_tx_count %i that should be %i (%s %s). Please report this issue here: %s\n",
3825 pindex->nHeight, pindex->m_chain_tx_count, prev_tx_sum(*pindex), CLIENT_NAME, FormatFullVersion(), CLIENT_BUGREPORT);
3826 }
3827 pindex->m_chain_tx_count = prev_tx_sum(*pindex);
3828 pindex->nSequenceId = nBlockSequenceId++;
3829 for (const auto& c : m_chainstates) {
3830 c->TryAddBlockIndexCandidate(pindex);
3831 }
3832 std::pair<std::multimap<CBlockIndex*, CBlockIndex*>::iterator, std::multimap<CBlockIndex*, CBlockIndex*>::iterator> range = m_blockman.m_blocks_unlinked.equal_range(pindex);
3833 while (range.first != range.second) {
3834 std::multimap<CBlockIndex*, CBlockIndex*>::iterator it = range.first;
3835 queue.push_back(it->second);
3836 range.first++;
3837 m_blockman.m_blocks_unlinked.erase(it);
3838 }
3839 }
3840 } else {
3841 if (pindexNew->pprev && pindexNew->pprev->IsValid(BLOCK_VALID_TREE)) {
3842 m_blockman.AddUnlinkedBlock(pindexNew);
3843 }
3844 }
3845}
3846
3847static bool CheckBlockHeader(const CBlockHeader& block, BlockValidationState& state, const Consensus::Params& consensusParams, bool fCheckPOW = true)
3848{
3849 // Check proof of work matches claimed amount
3850 if (fCheckPOW && !CheckProofOfWork(block.GetHash(), block.nBits, consensusParams))
3851 return state.Invalid(BlockValidationResult::BLOCK_INVALID_HEADER, "high-hash", "proof of work failed");
3852
3853 return true;
3854}
3855
3856static bool CheckMerkleRoot(const CBlock& block, BlockValidationState& state)
3857{
3858 if (block.m_checked_merkle_root) return true;
3859
3860 bool mutated;
3861 uint256 merkle_root = BlockMerkleRoot(block, &mutated);
3862 if (block.hashMerkleRoot != merkle_root) {
3863 return state.Invalid(
3865 /*reject_reason=*/"bad-txnmrklroot",
3866 /*debug_message=*/"hashMerkleRoot mismatch");
3867 }
3868
3869 // Check for merkle tree malleability (CVE-2012-2459): repeating sequences
3870 // of transactions in a block without affecting the merkle root of a block,
3871 // while still invalidating it.
3872 if (mutated) {
3873 return state.Invalid(
3875 /*reject_reason=*/"bad-txns-duplicate",
3876 /*debug_message=*/"duplicate transaction");
3877 }
3878
3879 block.m_checked_merkle_root = true;
3880 return true;
3881}
3882
3889static bool CheckWitnessMalleation(const CBlock& block, bool expect_witness_commitment, BlockValidationState& state)
3890{
3891 if (expect_witness_commitment) {
3892 if (block.m_checked_witness_commitment) return true;
3893
3894 int commitpos = GetWitnessCommitmentIndex(block);
3895 if (commitpos != NO_WITNESS_COMMITMENT) {
3896 assert(!block.vtx.empty() && !block.vtx[0]->vin.empty());
3897 const auto& witness_stack{block.vtx[0]->vin[0].scriptWitness.stack};
3898
3899 if (witness_stack.size() != 1 || witness_stack[0].size() != 32) {
3900 return state.Invalid(
3902 /*reject_reason=*/"bad-witness-nonce-size",
3903 /*debug_message=*/strprintf("%s : invalid witness reserved value size", __func__));
3904 }
3905
3906 // The malleation check is ignored; as the transaction tree itself
3907 // already does not permit it, it is impossible to trigger in the
3908 // witness tree.
3909 uint256 hash_witness = BlockWitnessMerkleRoot(block);
3910
3911 CHash256().Write(hash_witness).Write(witness_stack[0]).Finalize(hash_witness);
3912 if (memcmp(hash_witness.begin(), &block.vtx[0]->vout[commitpos].scriptPubKey[6], 32)) {
3913 return state.Invalid(
3915 /*reject_reason=*/"bad-witness-merkle-match",
3916 /*debug_message=*/strprintf("%s : witness merkle commitment mismatch", __func__));
3917 }
3918
3919 block.m_checked_witness_commitment = true;
3920 return true;
3921 }
3922 }
3923
3924 // No witness data is allowed in blocks that don't commit to witness data, as this would otherwise leave room for spam
3925 for (const auto& tx : block.vtx) {
3926 if (tx->HasWitness()) {
3927 return state.Invalid(
3929 /*reject_reason=*/"unexpected-witness",
3930 /*debug_message=*/strprintf("%s : unexpected witness data found", __func__));
3931 }
3932 }
3933
3934 return true;
3935}
3936
3937bool CheckBlock(const CBlock& block, BlockValidationState& state, const Consensus::Params& consensusParams, bool fCheckPOW, bool fCheckMerkleRoot)
3938{
3939 // These are checks that are independent of context.
3940
3941 if (block.fChecked)
3942 return true;
3943
3944 // Check that the header is valid (particularly PoW). This is mostly
3945 // redundant with the call in AcceptBlockHeader.
3946 if (!CheckBlockHeader(block, state, consensusParams, fCheckPOW))
3947 return false;
3948
3949 // Signet only: check block solution
3950 if (consensusParams.signet_blocks && fCheckPOW && !CheckSignetBlockSolution(block, consensusParams)) {
3951 return state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-signet-blksig", "signet block signature validation failure");
3952 }
3953
3954 // Check the merkle root.
3955 if (fCheckMerkleRoot && !CheckMerkleRoot(block, state)) {
3956 return false;
3957 }
3958
3959 // All potential-corruption validation must be done before we do any
3960 // transaction validation, as otherwise we may mark the header as invalid
3961 // because we receive the wrong transactions for it.
3962 // Note that witness malleability is checked in ContextualCheckBlock, so no
3963 // checks that use witness data may be performed here.
3964
3965 // Size limits
3967 return state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-blk-length", "size limits failed");
3968
3969 // First transaction must be coinbase, the rest must not be
3970 if (block.vtx.empty() || !block.vtx[0]->IsCoinBase())
3971 return state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-cb-missing", "first tx is not coinbase");
3972 for (unsigned int i = 1; i < block.vtx.size(); i++)
3973 if (block.vtx[i]->IsCoinBase())
3974 return state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-cb-multiple", "more than one coinbase");
3975
3976 // Check transactions
3977 // Must check for duplicate inputs (see CVE-2018-17144)
3978 for (const auto& tx : block.vtx) {
3979 TxValidationState tx_state;
3980 if (!CheckTransaction(*tx, tx_state)) {
3981 // CheckBlock() does context-free validation checks. The only
3982 // possible failures are consensus failures.
3985 strprintf("Transaction check failed (tx hash %s) %s", tx->GetHash().ToString(), tx_state.GetDebugMessage()));
3986 }
3987 }
3988 // This underestimates the number of sigops, because unlike ConnectBlock it
3989 // does not count witness and p2sh sigops.
3990 unsigned int nSigOps = 0;
3991 for (const auto& tx : block.vtx)
3992 {
3993 nSigOps += GetLegacySigOpCount(*tx);
3994 }
3996 return state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-blk-sigops", "out-of-bounds SigOpCount");
3997
3998 if (fCheckPOW && fCheckMerkleRoot)
3999 block.fChecked = true;
4000
4001 return true;
4002}
4003
4005{
4006 int commitpos = GetWitnessCommitmentIndex(block);
4007 static const std::vector<unsigned char> nonce(32, 0x00);
4008 if (commitpos != NO_WITNESS_COMMITMENT && DeploymentActiveAfter(pindexPrev, *this, Consensus::DEPLOYMENT_SEGWIT) && !block.vtx[0]->HasWitness()) {
4009 CMutableTransaction tx(*block.vtx[0]);
4010 tx.vin[0].scriptWitness.stack.resize(1);
4011 tx.vin[0].scriptWitness.stack[0] = nonce;
4012 block.vtx[0] = MakeTransactionRef(std::move(tx));
4013 }
4014}
4015
4017{
4018 int commitpos = GetWitnessCommitmentIndex(block);
4019 std::vector<unsigned char> ret(32, 0x00);
4020 if (commitpos == NO_WITNESS_COMMITMENT) {
4021 uint256 witnessroot = BlockWitnessMerkleRoot(block);
4022 CHash256().Write(witnessroot).Write(ret).Finalize(witnessroot);
4023 CTxOut out;
4024 out.nValue = 0;
4025 out.scriptPubKey.resize(MINIMUM_WITNESS_COMMITMENT);
4026 out.scriptPubKey[0] = OP_RETURN;
4027 out.scriptPubKey[1] = 0x24;
4028 out.scriptPubKey[2] = 0xaa;
4029 out.scriptPubKey[3] = 0x21;
4030 out.scriptPubKey[4] = 0xa9;
4031 out.scriptPubKey[5] = 0xed;
4032 memcpy(&out.scriptPubKey[6], witnessroot.begin(), 32);
4033 CMutableTransaction tx(*block.vtx[0]);
4034 tx.vout.push_back(out);
4035 block.vtx[0] = MakeTransactionRef(std::move(tx));
4036 }
4037 UpdateUncommittedBlockStructures(block, pindexPrev);
4038}
4039
4040bool HasValidProofOfWork(std::span<const CBlockHeader> headers, const Consensus::Params& consensusParams)
4041{
4042 return std::ranges::all_of(headers,
4043 [&](const auto& header) { return CheckProofOfWork(header.GetHash(), header.nBits, consensusParams); });
4044}
4045
4046bool IsBlockMutated(const CBlock& block, bool check_witness_root)
4047{
4049 if (!CheckMerkleRoot(block, state)) {
4050 LogDebug(BCLog::VALIDATION, "Block mutated: %s\n", state.ToString());
4051 return true;
4052 }
4053
4054 if (block.vtx.empty() || !block.vtx[0]->IsCoinBase()) {
4055 // Consider the block mutated if any transaction is 64 bytes in size (see 3.1
4056 // in "Weaknesses in Bitcoin’s Merkle Root Construction":
4057 // https://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20190225/a27d8837/attachment-0001.pdf).
4058 //
4059 // Note: This is not a consensus change as this only applies to blocks that
4060 // don't have a coinbase transaction and would therefore already be invalid.
4061 return std::any_of(block.vtx.begin(), block.vtx.end(),
4062 [](auto& tx) { return GetSerializeSize(TX_NO_WITNESS(tx)) == 64; });
4063 } else {
4064 // Theoretically it is still possible for a block with a 64 byte
4065 // coinbase transaction to be mutated but we neglect that possibility
4066 // here as it requires at least 224 bits of work.
4067 }
4068
4069 if (!CheckWitnessMalleation(block, check_witness_root, state)) {
4070 LogDebug(BCLog::VALIDATION, "Block mutated: %s\n", state.ToString());
4071 return true;
4072 }
4073
4074 return false;
4075}
4076
4078{
4079 arith_uint256 total_work{0};
4080 for (const CBlockHeader& header : headers) {
4081 total_work += GetBlockProof(header);
4082 }
4083 return total_work;
4084}
4085
4100{
4102 assert(pindexPrev != nullptr);
4103 const int nHeight = pindexPrev->nHeight + 1;
4104
4105 // Check proof of work
4106 const Consensus::Params& consensusParams = chainman.GetConsensus();
4107 if (block.nBits != GetNextWorkRequired(pindexPrev, &block, consensusParams))
4108 return state.Invalid(BlockValidationResult::BLOCK_INVALID_HEADER, "bad-diffbits", "incorrect proof of work");
4109
4110 // Check timestamp against prev
4111 if (block.GetBlockTime() <= pindexPrev->GetMedianTimePast())
4112 return state.Invalid(BlockValidationResult::BLOCK_INVALID_HEADER, "time-too-old", "block's timestamp is too early");
4113
4114 // Testnet4 and regtest only: Check timestamp against prev for difficulty-adjustment
4115 // blocks to prevent timewarp attacks (see https://github.com/bitcoin/bitcoin/pull/15482).
4116 if (consensusParams.enforce_BIP94) {
4117 // Check timestamp for the first block of each difficulty adjustment
4118 // interval, except the genesis block.
4119 if (nHeight % consensusParams.DifficultyAdjustmentInterval() == 0) {
4120 if (block.GetBlockTime() < pindexPrev->GetBlockTime() - MAX_TIMEWARP) {
4121 return state.Invalid(BlockValidationResult::BLOCK_INVALID_HEADER, "time-timewarp-attack", "block's timestamp is too early on diff adjustment block");
4122 }
4123 }
4124 }
4125
4126 // Check timestamp
4127 if (block.Time() > NodeClock::now() + std::chrono::seconds{MAX_FUTURE_BLOCK_TIME}) {
4128 return state.Invalid(BlockValidationResult::BLOCK_TIME_FUTURE, "time-too-new", "block timestamp too far in the future");
4129 }
4130
4131 // Reject blocks with outdated version
4132 if ((block.nVersion < 2 && DeploymentActiveAfter(pindexPrev, chainman, Consensus::DEPLOYMENT_HEIGHTINCB)) ||
4133 (block.nVersion < 3 && DeploymentActiveAfter(pindexPrev, chainman, Consensus::DEPLOYMENT_DERSIG)) ||
4134 (block.nVersion < 4 && DeploymentActiveAfter(pindexPrev, chainman, Consensus::DEPLOYMENT_CLTV))) {
4135 return state.Invalid(BlockValidationResult::BLOCK_INVALID_HEADER, strprintf("bad-version(0x%08x)", block.nVersion),
4136 strprintf("rejected nVersion=0x%08x block", block.nVersion));
4137 }
4138
4139 return true;
4140}
4141
4148static bool ContextualCheckBlock(const CBlock& block, BlockValidationState& state, const ChainstateManager& chainman, const CBlockIndex* pindexPrev)
4149{
4150 const int nHeight = pindexPrev == nullptr ? 0 : pindexPrev->nHeight + 1;
4151
4152 // Enforce BIP113 (Median Time Past).
4153 bool enforce_locktime_median_time_past{false};
4154 if (DeploymentActiveAfter(pindexPrev, chainman, Consensus::DEPLOYMENT_CSV)) {
4155 assert(pindexPrev != nullptr);
4156 enforce_locktime_median_time_past = true;
4157 }
4158
4159 const int64_t nLockTimeCutoff{enforce_locktime_median_time_past ?
4160 pindexPrev->GetMedianTimePast() :
4161 block.GetBlockTime()};
4162
4163 // Check that all transactions are finalized
4164 for (const auto& tx : block.vtx) {
4165 if (!IsFinalTx(*tx, nHeight, nLockTimeCutoff)) {
4166 return state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-txns-nonfinal", "non-final transaction");
4167 }
4168 }
4169
4170 // Enforce rule that the coinbase starts with serialized block height
4172 {
4174 if (block.vtx[0]->vin[0].scriptSig.size() < expect.size() ||
4175 !std::equal(expect.begin(), expect.end(), block.vtx[0]->vin[0].scriptSig.begin())) {
4176 return state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-cb-height", "block height mismatch in coinbase");
4177 }
4178 }
4179
4180 // Validation for witness commitments.
4181 // * We compute the witness hash (which is the hash including witnesses) of all the block's transactions, except the
4182 // coinbase (where 0x0000....0000 is used instead).
4183 // * The coinbase scriptWitness is a stack of a single 32-byte vector, containing a witness reserved value (unconstrained).
4184 // * We build a merkle tree with all those witness hashes as leaves (similar to the hashMerkleRoot in the block header).
4185 // * There must be at least one output whose scriptPubKey is a single 36-byte push, the first 4 bytes of which are
4186 // {0xaa, 0x21, 0xa9, 0xed}, and the following 32 bytes are SHA256^2(witness root, witness reserved value). In case there are
4187 // multiple, the last one is used.
4188 if (!CheckWitnessMalleation(block, DeploymentActiveAfter(pindexPrev, chainman, Consensus::DEPLOYMENT_SEGWIT), state)) {
4189 return false;
4190 }
4191
4192 // After the coinbase witness reserved value and commitment are verified,
4193 // we can check if the block weight passes (before we've checked the
4194 // coinbase witness, it would be possible for the weight to be too
4195 // large by filling up the coinbase witness, which doesn't change
4196 // the block hash, so we couldn't mark the block as permanently
4197 // failed).
4198 if (GetBlockWeight(block) > MAX_BLOCK_WEIGHT) {
4199 return state.Invalid(BlockValidationResult::BLOCK_CONSENSUS, "bad-blk-weight", strprintf("%s : weight limit failed", __func__));
4200 }
4201
4202 return true;
4203}
4204
4205bool ChainstateManager::AcceptBlockHeader(const CBlockHeader& block, BlockValidationState& state, CBlockIndex** ppindex, bool min_pow_checked)
4206{
4208
4209 // Check for duplicate
4210 uint256 hash = block.GetHash();
4211 BlockMap::iterator miSelf{m_blockman.m_block_index.find(hash)};
4212 if (hash != GetConsensus().hashGenesisBlock) {
4213 if (miSelf != m_blockman.m_block_index.end()) {
4214 // Block header is already known.
4215 CBlockIndex* pindex = &(miSelf->second);
4216 if (ppindex)
4217 *ppindex = pindex;
4218 if (pindex->nStatus & BLOCK_FAILED_VALID) {
4219 LogDebug(BCLog::VALIDATION, "%s: block %s is marked invalid\n", __func__, hash.ToString());
4220 return state.Invalid(BlockValidationResult::BLOCK_CACHED_INVALID, "duplicate-invalid",
4221 strprintf("block %s was previously marked invalid", hash.ToString()));
4222 }
4223 return true;
4224 }
4225
4226 if (!CheckBlockHeader(block, state, GetConsensus())) {
4227 LogDebug(BCLog::VALIDATION, "%s: Consensus::CheckBlockHeader: %s, %s\n", __func__, hash.ToString(), state.ToString());
4228 return false;
4229 }
4230
4231 // Get prev block index
4232 CBlockIndex* pindexPrev = nullptr;
4233 BlockMap::iterator mi{m_blockman.m_block_index.find(block.hashPrevBlock)};
4234 if (mi == m_blockman.m_block_index.end()) {
4235 LogDebug(BCLog::VALIDATION, "header %s has prev block not found: %s\n", hash.ToString(), block.hashPrevBlock.ToString());
4236 return state.Invalid(BlockValidationResult::BLOCK_MISSING_PREV, "prev-blk-not-found");
4237 }
4238 pindexPrev = &((*mi).second);
4239 if (pindexPrev->nStatus & BLOCK_FAILED_VALID) {
4240 LogDebug(BCLog::VALIDATION, "header %s has prev block invalid: %s\n", hash.ToString(), block.hashPrevBlock.ToString());
4241 return state.Invalid(BlockValidationResult::BLOCK_INVALID_PREV, "bad-prevblk");
4242 }
4243 if (!ContextualCheckBlockHeader(block, state, *this, pindexPrev)) {
4244 LogDebug(BCLog::VALIDATION, "%s: Consensus::ContextualCheckBlockHeader: %s, %s\n", __func__, hash.ToString(), state.ToString());
4245 return false;
4246 }
4247 }
4248 if (!min_pow_checked) {
4249 LogDebug(BCLog::VALIDATION, "%s: not adding new block header %s, missing anti-dos proof-of-work validation\n", __func__, hash.ToString());
4250 return state.Invalid(BlockValidationResult::BLOCK_HEADER_LOW_WORK, "too-little-chainwork");
4251 }
4252 CBlockIndex* pindex{m_blockman.AddToBlockIndex(block, m_best_header)};
4253
4254 if (ppindex)
4255 *ppindex = pindex;
4256
4257 return true;
4258}
4259
4260// Exposed wrapper for AcceptBlockHeader
4261bool ChainstateManager::ProcessNewBlockHeaders(std::span<const CBlockHeader> headers, bool min_pow_checked, BlockValidationState& state, const CBlockIndex** ppindex)
4262{
4264 {
4265 LOCK(cs_main);
4266 for (const CBlockHeader& header : headers) {
4267 CBlockIndex *pindex = nullptr; // Use a temp pindex instead of ppindex to avoid a const_cast
4268 bool accepted{AcceptBlockHeader(header, state, &pindex, min_pow_checked)};
4270
4271 if (!accepted) {
4272 return false;
4273 }
4274 if (ppindex) {
4275 *ppindex = pindex;
4276 }
4277 }
4278 }
4279 if (NotifyHeaderTip()) {
4280 if (IsInitialBlockDownload() && ppindex && *ppindex) {
4281 const CBlockIndex& last_accepted{**ppindex};
4282 int64_t blocks_left{(NodeClock::now() - last_accepted.Time()) / GetConsensus().PowTargetSpacing()};
4283 blocks_left = std::max<int64_t>(0, blocks_left);
4284 const double progress{100.0 * last_accepted.nHeight / (last_accepted.nHeight + blocks_left)};
4285 LogInfo("Synchronizing blockheaders, height: %d (~%.2f%%)\n", last_accepted.nHeight, progress);
4286 }
4287 }
4288 return true;
4289}
4290
4291void ChainstateManager::ReportHeadersPresync(int64_t height, int64_t timestamp)
4292{
4294 {
4295 LOCK(GetMutex());
4296 // Don't report headers presync progress if we already have a post-minchainwork header chain.
4297 // This means we lose reporting for potentially legitimate, but unlikely, deep reorgs, but
4298 // prevent attackers that spam low-work headers from filling our logs.
4299 if (m_best_header->nChainWork >= UintToArith256(GetConsensus().nMinimumChainWork)) return;
4300 // Rate limit headers presync updates to 4 per second, as these are not subject to DoS
4301 // protection.
4302 auto now = MockableSteadyClock::now();
4303 if (now < m_last_presync_update + std::chrono::milliseconds{250}) return;
4304 m_last_presync_update = now;
4305 }
4306 bool initial_download = IsInitialBlockDownload();
4307 GetNotifications().headerTip(GetSynchronizationState(initial_download, m_blockman.m_blockfiles_indexed), height, timestamp, /*presync=*/true);
4308 if (initial_download) {
4309 int64_t blocks_left{(NodeClock::now() - NodeSeconds{std::chrono::seconds{timestamp}}) / GetConsensus().PowTargetSpacing()};
4310 blocks_left = std::max<int64_t>(0, blocks_left);
4311 const double progress{100.0 * height / (height + blocks_left)};
4312 LogInfo("Pre-synchronizing blockheaders, height: %d (~%.2f%%)\n", height, progress);
4313 }
4314}
4315
4317bool ChainstateManager::AcceptBlock(const std::shared_ptr<const CBlock>& pblock, BlockValidationState& state, CBlockIndex** ppindex, bool fRequested, const FlatFilePos* dbp, bool* fNewBlock, bool min_pow_checked)
4318{
4319 const CBlock& block = *pblock;
4320
4321 if (fNewBlock) *fNewBlock = false;
4323
4324 CBlockIndex *pindexDummy = nullptr;
4325 CBlockIndex *&pindex = ppindex ? *ppindex : pindexDummy;
4326
4327 bool accepted_header{AcceptBlockHeader(block, state, &pindex, min_pow_checked)};
4329
4330 if (!accepted_header)
4331 return false;
4332
4333 // Check all requested blocks that we do not already have for validity and
4334 // save them to disk. Skip processing of unrequested blocks as an anti-DoS
4335 // measure, unless the blocks have more work than the active chain tip, and
4336 // aren't too far ahead of it, so are likely to be attached soon.
4337 bool fAlreadyHave = pindex->nStatus & BLOCK_HAVE_DATA;
4338 bool fHasMoreOrSameWork = (ActiveTip() ? pindex->nChainWork >= ActiveTip()->nChainWork : true);
4339 // Blocks that are too out-of-order needlessly limit the effectiveness of
4340 // pruning, because pruning will not delete block files that contain any
4341 // blocks which are too close in height to the tip. Apply this test
4342 // regardless of whether pruning is enabled; it should generally be safe to
4343 // not process unrequested blocks.
4344 bool fTooFarAhead{pindex->nHeight > ActiveHeight() + int(MIN_BLOCKS_TO_KEEP)};
4345
4346 // TODO: Decouple this function from the block download logic by removing fRequested
4347 // This requires some new chain data structure to efficiently look up if a
4348 // block is in a chain leading to a candidate for best tip, despite not
4349 // being such a candidate itself.
4350 // Note that this would break the getblockfrompeer RPC
4351
4352 // TODO: deal better with return value and error conditions for duplicate
4353 // and unrequested blocks.
4354 if (fAlreadyHave) return true;
4355 if (!fRequested) { // If we didn't ask for it:
4356 if (pindex->nTx != 0) return true; // This is a previously-processed block that was pruned
4357 if (!fHasMoreOrSameWork) return true; // Don't process less-work chains
4358 if (fTooFarAhead) return true; // Block height is too high
4359
4360 // Protect against DoS attacks from low-work chains.
4361 // If our tip is behind, a peer could try to send us
4362 // low-work blocks on a fake chain that we would never
4363 // request; don't process these.
4364 if (pindex->nChainWork < MinimumChainWork()) return true;
4365 }
4366
4367 const CChainParams& params{GetParams()};
4368
4369 if (!CheckBlock(block, state, params.GetConsensus()) ||
4370 !ContextualCheckBlock(block, state, *this, pindex->pprev)) {
4371 if (Assume(state.IsInvalid())) {
4372 ActiveChainstate().InvalidBlockFound(pindex, state);
4373 }
4374 LogError("%s: %s\n", __func__, state.ToString());
4375 return false;
4376 }
4377
4378 // Header is valid/has work, merkle tree and segwit merkle tree are good...RELAY NOW
4379 // (but if it does not build on our best tip, let the SendMessages loop relay it)
4380 if (!IsInitialBlockDownload() && ActiveTip() == pindex->pprev && m_options.signals) {
4381 m_options.signals->NewPoWValidBlock(pindex, pblock);
4382 }
4383
4384 // Write block to history file
4385 if (fNewBlock) *fNewBlock = true;
4386 try {
4387 FlatFilePos blockPos{};
4388 if (dbp) {
4389 blockPos = *dbp;
4390 m_blockman.UpdateBlockInfo(block, pindex->nHeight, blockPos);
4391 } else {
4392 blockPos = m_blockman.WriteBlock(block, pindex->nHeight);
4393 if (blockPos.IsNull()) {
4394 state.Error(strprintf("%s: Failed to find position to write new block to disk", __func__));
4395 return false;
4396 }
4397 }
4398 ReceivedBlockTransactions(block, pindex, blockPos);
4399 } catch (const std::runtime_error& e) {
4400 return FatalError(GetNotifications(), state, strprintf(_("System error while saving block to disk: %s"), e.what()));
4401 }
4402
4403 // TODO: FlushStateToDisk() handles flushing of both block and chainstate
4404 // data, so we should move this to ChainstateManager so that we can be more
4405 // intelligent about how we flush.
4406 // For now, since FlushStateMode::NONE is used, all that can happen is that
4407 // the block files may be pruned, so we can just call this on one
4408 // chainstate (particularly if we haven't implemented pruning with
4409 // background validation yet).
4410 //
4411 // Flush errors (e.g. low disk space during pruning) are ignored, so that
4412 // callers can't mistreat a flush failure as a block validation failure.
4413 // The fatal error notification inside FlushStateToDisk still fires,
4414 // so the node will shut down on unrecoverable flush errors regardless.
4415 // For state a dummy value is used, and the return value is ignored.
4416 BlockValidationState flush_state_ignore;
4417 (void)ActiveChainstate().FlushStateToDisk(flush_state_ignore, FlushStateMode::NONE);
4418
4420
4421 return true;
4422}
4423
4424bool ChainstateManager::ProcessNewBlock(const std::shared_ptr<const CBlock>& block, bool force_processing, bool min_pow_checked, bool* new_block)
4425{
4427
4428 {
4429 CBlockIndex *pindex = nullptr;
4430 if (new_block) *new_block = false;
4432
4433 // CheckBlock() does not support multi-threaded block validation because CBlock::fChecked can cause data race.
4434 // Therefore, the following critical section must include the CheckBlock() call as well.
4435 LOCK(cs_main);
4436
4437 // Skipping AcceptBlock() for CheckBlock() failures means that we will never mark a block as invalid if
4438 // CheckBlock() fails. This is protective against consensus failure if there are any unknown forms of block
4439 // malleability that cause CheckBlock() to fail; see e.g. CVE-2012-2459 and
4440 // https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2019-February/016697.html. Because CheckBlock() is
4441 // not very expensive, the anti-DoS benefits of caching failure (of a definitely-invalid block) are not substantial.
4442 bool ret = CheckBlock(*block, state, GetConsensus());
4443 if (ret) {
4444 // Store to disk
4445 ret = AcceptBlock(block, state, &pindex, force_processing, nullptr, new_block, min_pow_checked);
4446 }
4447 if (!ret) {
4448 if (m_options.signals) {
4449 m_options.signals->BlockChecked(block, state);
4450 }
4451 LogError("%s: AcceptBlock FAILED (%s)\n", __func__, state.ToString());
4452 return false;
4453 }
4454 }
4455
4457
4458 BlockValidationState state; // Only used to report errors, not invalidity - ignore it
4459 if (!ActiveChainstate().ActivateBestChain(state, block)) {
4460 LogError("%s: ActivateBestChain failed (%s)\n", __func__, state.ToString());
4461 return false;
4462 }
4463
4464 Chainstate* bg_chain{WITH_LOCK(cs_main, return HistoricalChainstate())};
4465 BlockValidationState bg_state;
4466 if (bg_chain && !bg_chain->ActivateBestChain(bg_state, block)) {
4467 LogError("%s: [background] ActivateBestChain failed (%s)\n", __func__, bg_state.ToString());
4468 return false;
4469 }
4470
4471 return true;
4472}
4473
4475{
4477 Chainstate& active_chainstate = ActiveChainstate();
4478 if (!active_chainstate.GetMempool()) {
4479 TxValidationState state;
4480 state.Invalid(TxValidationResult::TX_NO_MEMPOOL, "no-mempool");
4481 return MempoolAcceptResult::Failure(state);
4482 }
4483 auto result = AcceptToMemoryPool(active_chainstate, tx, GetTime(), /*bypass_limits=*/ false, test_accept);
4484 active_chainstate.GetMempool()->check(active_chainstate.CoinsTip(), active_chainstate.m_chain.Height() + 1);
4485 return result;
4486}
4487
4488
4490 Chainstate& chainstate,
4491 const CBlock& block,
4492 const bool check_pow,
4493 const bool check_merkle_root)
4494{
4495 // Lock must be held throughout this function for two reasons:
4496 // 1. We don't want the tip to change during several of the validation steps
4497 // 2. To prevent a CheckBlock() race condition for fChecked, see ProcessNewBlock()
4498 AssertLockHeld(chainstate.m_chainman.GetMutex());
4499
4501 CBlockIndex* tip{Assert(chainstate.m_chain.Tip())};
4502
4503 if (block.hashPrevBlock != *Assert(tip->phashBlock)) {
4504 state.Invalid({}, "inconclusive-not-best-prevblk");
4505 return state;
4506 }
4507
4508 // For signets CheckBlock() verifies the challenge iff fCheckPow is set.
4509 if (!CheckBlock(block, state, chainstate.m_chainman.GetConsensus(), /*fCheckPow=*/check_pow, /*fCheckMerkleRoot=*/check_merkle_root)) {
4510 // This should never happen, but belt-and-suspenders don't approve the
4511 // block if it does.
4512 if (state.IsValid()) NONFATAL_UNREACHABLE();
4513 return state;
4514 }
4515
4531 if (!ContextualCheckBlockHeader(block, state, chainstate.m_chainman, tip)) {
4532 if (state.IsValid()) NONFATAL_UNREACHABLE();
4533 return state;
4534 }
4535
4536 if (!ContextualCheckBlock(block, state, chainstate.m_chainman, tip)) {
4537 if (state.IsValid()) NONFATAL_UNREACHABLE();
4538 return state;
4539 }
4540
4541 // We don't want ConnectBlock to update the actual chainstate, so create
4542 // a cache on top of it, along with a dummy block index.
4543 CBlockIndex index_dummy{block};
4544 uint256 block_hash(block.GetHash());
4545 index_dummy.pprev = tip;
4546 index_dummy.nHeight = tip->nHeight + 1;
4547 index_dummy.phashBlock = &block_hash;
4548 CCoinsViewCache view_dummy(&chainstate.CoinsTip());
4549
4550 // Set fJustCheck to true in order to update, and not clear, validation caches.
4551 if(!chainstate.ConnectBlock(block, state, &index_dummy, view_dummy, /*fJustCheck=*/true)) {
4552 if (state.IsValid()) NONFATAL_UNREACHABLE();
4553 return state;
4554 }
4555
4556 // Ensure no check returned successfully while also setting an invalid state.
4557 if (!state.IsValid()) NONFATAL_UNREACHABLE();
4558
4559 return state;
4560}
4561
4562/* This function is called from the RPC code for pruneblockchain */
4563void PruneBlockFilesManual(Chainstate& active_chainstate, int nManualPruneHeight)
4564{
4566 if (!active_chainstate.FlushStateToDisk(
4567 state, FlushStateMode::NONE, nManualPruneHeight)) {
4568 LogWarning("Failed to flush state after manual prune (%s)", state.ToString());
4569 }
4570}
4571
4573{
4575 const CCoinsViewCache& coins_cache = CoinsTip();
4576 assert(!coins_cache.GetBestBlock().IsNull()); // Never called when the coins view is empty
4577 CBlockIndex* tip = m_chain.Tip();
4578
4579 if (tip && tip->GetBlockHash() == coins_cache.GetBestBlock()) {
4580 return true;
4581 }
4582
4583 // Load pointer to end of best chain
4584 CBlockIndex* pindex = m_blockman.LookupBlockIndex(coins_cache.GetBestBlock());
4585 if (!pindex) {
4586 return false;
4587 }
4588 m_chain.SetTip(*pindex);
4590 m_last_flushed_block = pindex;
4591 tip = m_chain.Tip();
4592
4593 // nSequenceId is one of the keys used to sort setBlockIndexCandidates. Ensure all
4594 // candidate sets are empty to avoid UB, as nSequenceId is about to be modified.
4595 for (const auto& cs : m_chainman.m_chainstates) {
4596 assert(cs->setBlockIndexCandidates.empty());
4597 }
4598
4599 // Make sure our chain tip before shutting down scores better than any other candidate
4600 // to maintain a consistent best tip over reboots in case of a tie.
4601 auto target = tip;
4602 while (target) {
4604 target = target->pprev;
4605 }
4606
4607 LogInfo("Loaded best chain: hashBestChain=%s height=%d date=%s progress=%f",
4608 tip->GetBlockHash().ToString(),
4609 m_chain.Height(),
4612
4613 // Ensure KernelNotifications m_tip_block is set even if no new block arrives.
4614 if (!this->GetRole().historical) {
4615 // Ignoring return value for now.
4618 /*index=*/*pindex,
4619 /*verification_progress=*/m_chainman.GuessVerificationProgress(tip));
4620 }
4621
4623
4624 return true;
4625}
4626
4628 : m_notifications{notifications}
4629{
4630 m_notifications.progress(_("Verifying blocks…"), 0, false);
4631}
4632
4634{
4635 m_notifications.progress(bilingual_str{}, 100, false);
4636}
4637
4639 Chainstate& chainstate,
4640 const Consensus::Params& consensus_params,
4641 CCoinsView& coinsview,
4642 int nCheckLevel, int nCheckDepth)
4643{
4645
4646 if (chainstate.m_chain.Tip() == nullptr || chainstate.m_chain.Tip()->pprev == nullptr) {
4648 }
4649
4650 // Verify blocks in the best chain
4651 if (nCheckDepth <= 0 || nCheckDepth > chainstate.m_chain.Height()) {
4652 nCheckDepth = chainstate.m_chain.Height();
4653 }
4654 nCheckLevel = std::max(0, std::min(4, nCheckLevel));
4655 LogInfo("Verifying last %i blocks at level %i", nCheckDepth, nCheckLevel);
4656 CCoinsViewCache coins(&coinsview);
4657 CBlockIndex* pindex;
4658 CBlockIndex* pindexFailure = nullptr;
4659 int nGoodTransactions = 0;
4661 int reportDone = 0;
4662 bool skipped_no_block_data{false};
4663 bool skipped_l3_checks{false};
4664 LogInfo("Verification progress: 0%%");
4665
4666 const bool is_snapshot_cs{chainstate.m_from_snapshot_blockhash};
4667
4668 for (pindex = chainstate.m_chain.Tip(); pindex && pindex->pprev; pindex = pindex->pprev) {
4669 const int percentageDone = std::max(1, std::min(99, (int)(((double)(chainstate.m_chain.Height() - pindex->nHeight)) / (double)nCheckDepth * (nCheckLevel >= 4 ? 50 : 100))));
4670 if (reportDone < percentageDone / 10) {
4671 // report every 10% step
4672 LogInfo("Verification progress: %d%%", percentageDone);
4673 reportDone = percentageDone / 10;
4674 }
4675 m_notifications.progress(_("Verifying blocks…"), percentageDone, false);
4676 if (pindex->nHeight <= chainstate.m_chain.Height() - nCheckDepth) {
4677 break;
4678 }
4679 if ((chainstate.m_blockman.IsPruneMode() || is_snapshot_cs) && !(pindex->nStatus & BLOCK_HAVE_DATA)) {
4680 // If pruning or running under an assumeutxo snapshot, only go
4681 // back as far as we have data.
4682 LogInfo("Block verification stopping at height %d (no data). This could be due to pruning or use of an assumeutxo snapshot.", pindex->nHeight);
4683 skipped_no_block_data = true;
4684 break;
4685 }
4686 CBlock block;
4687 // check level 0: read from disk
4688 if (!chainstate.m_blockman.ReadBlock(block, *pindex)) {
4689 LogError("Verification error: ReadBlock failed at %d, hash=%s", pindex->nHeight, pindex->GetBlockHash().ToString());
4691 }
4692 // check level 1: verify block validity
4693 if (nCheckLevel >= 1 && !CheckBlock(block, state, consensus_params)) {
4694 LogError("Verification error: found bad block at %d, hash=%s (%s)",
4695 pindex->nHeight, pindex->GetBlockHash().ToString(), state.ToString());
4697 }
4698 // check level 2: verify undo validity
4699 if (nCheckLevel >= 2 && pindex) {
4700 CBlockUndo undo;
4701 if (!pindex->GetUndoPos().IsNull()) {
4702 if (!chainstate.m_blockman.ReadBlockUndo(undo, *pindex)) {
4703 LogError("Verification error: found bad undo data at %d, hash=%s", pindex->nHeight, pindex->GetBlockHash().ToString());
4705 }
4706 }
4707 }
4708 // check level 3: check for inconsistencies during memory-only disconnect of tip blocks
4709 size_t curr_coins_usage = coins.DynamicMemoryUsage() + chainstate.CoinsTip().DynamicMemoryUsage();
4710
4711 if (nCheckLevel >= 3) {
4712 if (curr_coins_usage <= chainstate.m_coinstip_cache_size_bytes) {
4713 assert(coins.GetBestBlock() == pindex->GetBlockHash());
4714 DisconnectResult res = chainstate.DisconnectBlock(block, pindex, coins);
4715 if (res == DISCONNECT_FAILED) {
4716 LogError("Verification error: irrecoverable inconsistency in block data at %d, hash=%s", pindex->nHeight, pindex->GetBlockHash().ToString());
4718 }
4719 if (res == DISCONNECT_UNCLEAN) {
4720 nGoodTransactions = 0;
4721 pindexFailure = pindex;
4722 } else {
4723 nGoodTransactions += block.vtx.size();
4724 }
4725 } else {
4726 skipped_l3_checks = true;
4727 }
4728 }
4729 if (chainstate.m_chainman.m_interrupt) return VerifyDBResult::INTERRUPTED;
4730 }
4731 if (pindexFailure) {
4732 LogError("Verification error: coin database inconsistencies found (last %i blocks, %i good transactions before that)", chainstate.m_chain.Height() - pindexFailure->nHeight + 1, nGoodTransactions);
4734 }
4735 if (skipped_l3_checks) {
4736 LogWarning("Skipped verification of level >=3 (insufficient database cache size). Consider increasing -dbcache.");
4737 }
4738
4739 // store block count as we move pindex at check level >= 4
4740 int block_count = chainstate.m_chain.Height() - pindex->nHeight;
4741
4742 // check level 4: try reconnecting blocks
4743 if (nCheckLevel >= 4 && !skipped_l3_checks) {
4744 while (pindex != chainstate.m_chain.Tip()) {
4745 const int percentageDone = std::max(1, std::min(99, 100 - (int)(((double)(chainstate.m_chain.Height() - pindex->nHeight)) / (double)nCheckDepth * 50)));
4746 if (reportDone < percentageDone / 10) {
4747 // report every 10% step
4748 LogInfo("Verification progress: %d%%", percentageDone);
4749 reportDone = percentageDone / 10;
4750 }
4751 m_notifications.progress(_("Verifying blocks…"), percentageDone, false);
4752 pindex = chainstate.m_chain.Next(*pindex);
4753 CBlock block;
4754 if (!chainstate.m_blockman.ReadBlock(block, *pindex)) {
4755 LogError("Verification error: ReadBlock failed at %d, hash=%s", pindex->nHeight, pindex->GetBlockHash().ToString());
4757 }
4758 if (!chainstate.ConnectBlock(block, state, pindex, coins)) {
4759 LogError("Verification error: found unconnectable block at %d, hash=%s (%s)", pindex->nHeight, pindex->GetBlockHash().ToString(), state.ToString());
4761 }
4762 if (chainstate.m_chainman.m_interrupt) return VerifyDBResult::INTERRUPTED;
4763 }
4764 }
4765
4766 LogInfo("Verification: checked last %i blocks at level %i", block_count, nCheckLevel);
4767 if (nCheckLevel >= 3 && !skipped_l3_checks) {
4768 LogInfo("Verification: no coin database inconsistencies (%i transactions)", nGoodTransactions);
4769 }
4770
4771 if (skipped_l3_checks) {
4773 }
4774 if (skipped_no_block_data) {
4776 }
4778}
4779
4782{
4784 // TODO: merge with ConnectBlock
4785 CBlock block;
4786 if (!m_blockman.ReadBlock(block, *pindex)) {
4787 LogError("ReplayBlock(): ReadBlock failed at %d, hash=%s\n", pindex->nHeight, pindex->GetBlockHash().ToString());
4788 return false;
4789 }
4790
4791 for (const CTransactionRef& tx : block.vtx) {
4792 if (!tx->IsCoinBase()) {
4793 for (const CTxIn &txin : tx->vin) {
4794 inputs.SpendCoin(txin.prevout);
4795 }
4796 }
4797 // Pass check = true as every addition may be an overwrite.
4798 AddCoins(inputs, *tx, pindex->nHeight, true);
4799 }
4800 return true;
4801}
4802
4804{
4805 LOCK(cs_main);
4806
4807 CCoinsView& db = this->CoinsDB();
4808 CCoinsViewCache cache(&db);
4809
4810 std::vector<uint256> hashHeads = db.GetHeadBlocks();
4811 if (hashHeads.empty()) return true; // We're already in a consistent state.
4812 if (hashHeads.size() != 2) {
4813 LogError("ReplayBlocks(): unknown inconsistent state\n");
4814 return false;
4815 }
4816
4817 m_chainman.GetNotifications().progress(_("Replaying blocks…"), 0, false);
4818 LogInfo("Replaying blocks");
4819
4820 const CBlockIndex* pindexOld = nullptr; // Old tip during the interrupted flush.
4821 const CBlockIndex* pindexNew; // New tip during the interrupted flush.
4822 const CBlockIndex* pindexFork = nullptr; // Latest block common to both the old and the new tip.
4823
4824 if (!m_blockman.m_block_index.contains(hashHeads[0])) {
4825 LogError("ReplayBlocks(): reorganization to unknown block requested\n");
4826 return false;
4827 }
4828 pindexNew = &(m_blockman.m_block_index[hashHeads[0]]);
4829
4830 if (!hashHeads[1].IsNull()) { // The old tip is allowed to be 0, indicating it's the first flush.
4831 if (!m_blockman.m_block_index.contains(hashHeads[1])) {
4832 LogError("ReplayBlocks(): reorganization from unknown block requested\n");
4833 return false;
4834 }
4835 pindexOld = &(m_blockman.m_block_index[hashHeads[1]]);
4836 pindexFork = LastCommonAncestor(pindexOld, pindexNew);
4837 assert(pindexFork != nullptr);
4838 }
4839
4840 // Rollback along the old branch.
4841 const int nForkHeight{pindexFork ? pindexFork->nHeight : 0};
4842 if (pindexOld != pindexFork) {
4843 LogInfo("Rolling back from %s (%i to %i)", pindexOld->GetBlockHash().ToString(), pindexOld->nHeight, nForkHeight);
4844 while (pindexOld != pindexFork) {
4845 if (pindexOld->nHeight > 0) { // Never disconnect the genesis block.
4846 CBlock block;
4847 if (!m_blockman.ReadBlock(block, *pindexOld)) {
4848 LogError("RollbackBlock(): ReadBlock() failed at %d, hash=%s\n", pindexOld->nHeight, pindexOld->GetBlockHash().ToString());
4849 return false;
4850 }
4851 if (pindexOld->nHeight % 10'000 == 0) {
4852 LogInfo("Rolling back %s (%i)", pindexOld->GetBlockHash().ToString(), pindexOld->nHeight);
4853 }
4854 DisconnectResult res = DisconnectBlock(block, pindexOld, cache);
4855 if (res == DISCONNECT_FAILED) {
4856 LogError("RollbackBlock(): DisconnectBlock failed at %d, hash=%s\n", pindexOld->nHeight, pindexOld->GetBlockHash().ToString());
4857 return false;
4858 }
4859 // If DISCONNECT_UNCLEAN is returned, it means a non-existing UTXO was deleted, or an existing UTXO was
4860 // overwritten. It corresponds to cases where the block-to-be-disconnect never had all its operations
4861 // applied to the UTXO set. However, as both writing a UTXO and deleting a UTXO are idempotent operations,
4862 // the result is still a version of the UTXO set with the effects of that block undone.
4863 }
4864 pindexOld = pindexOld->pprev;
4865 }
4866 LogInfo("Rolled back to %s", pindexFork->GetBlockHash().ToString());
4867 }
4868
4869 // Roll forward from the forking point to the new tip.
4870 if (nForkHeight < pindexNew->nHeight) {
4871 LogInfo("Rolling forward to %s (%i to %i)", pindexNew->GetBlockHash().ToString(), nForkHeight, pindexNew->nHeight);
4872 for (int nHeight = nForkHeight + 1; nHeight <= pindexNew->nHeight; ++nHeight) {
4873 const CBlockIndex& pindex{*Assert(pindexNew->GetAncestor(nHeight))};
4874
4875 if (nHeight % 10'000 == 0) {
4876 LogInfo("Rolling forward %s (%i)", pindex.GetBlockHash().ToString(), nHeight);
4877 }
4878 m_chainman.GetNotifications().progress(_("Replaying blocks…"), (int)((nHeight - nForkHeight) * 100.0 / (pindexNew->nHeight - nForkHeight)), false);
4879 if (!RollforwardBlock(&pindex, cache)) return false;
4880 }
4881 LogInfo("Rolled forward to %s", pindexNew->GetBlockHash().ToString());
4882 }
4883
4884 cache.SetBestBlock(pindexNew->GetBlockHash());
4885 cache.Flush(/*reallocate_cache=*/false); // local CCoinsViewCache goes out of scope
4887 return true;
4888}
4889
4891{
4893
4894 // At and above m_params.SegwitHeight, segwit consensus rules must be validated
4895 CBlockIndex* block{m_chain.Tip()};
4896
4897 while (block != nullptr && DeploymentActiveAt(*block, m_chainman, Consensus::DEPLOYMENT_SEGWIT)) {
4898 if (!(block->nStatus & BLOCK_OPT_WITNESS)) {
4899 // block is insufficiently validated for a segwit client
4900 return true;
4901 }
4902 block = block->pprev;
4903 }
4904
4905 return false;
4906}
4907
4908void Chainstate::ClearBlockIndexCandidates()
4909{
4912}
4913
4914void Chainstate::PopulateBlockIndexCandidates()
4915{
4917
4918 for (CBlockIndex* pindex : m_blockman.GetAllBlockIndices()) {
4919 // With assumeutxo, the snapshot block is a candidate for the tip, but it
4920 // may not have BLOCK_VALID_TRANSACTIONS (e.g. if we haven't yet downloaded
4921 // the block), so we special-case it here.
4922 if (pindex == SnapshotBase() ||
4924 (pindex->HaveNumChainTxs() || pindex->pprev == nullptr))) {
4926 }
4927 }
4928}
4929
4931{
4933 // Load block index from databases
4935 bool ret{m_blockman.LoadBlockIndexDB(CurrentChainstate().m_from_snapshot_blockhash)};
4936 if (!ret) return false;
4937
4938 m_blockman.ScanAndUnlinkAlreadyPrunedFiles();
4939
4940 std::vector<CBlockIndex*> vSortedByHeight{m_blockman.GetAllBlockIndices()};
4941 std::sort(vSortedByHeight.begin(), vSortedByHeight.end(),
4943
4944 for (CBlockIndex* pindex : vSortedByHeight) {
4945 if (m_interrupt) return false;
4946 if (pindex->nStatus & BLOCK_FAILED_VALID && (!m_best_invalid || pindex->nChainWork > m_best_invalid->nChainWork)) {
4947 m_best_invalid = pindex;
4948 }
4949 if (pindex->IsValid(BLOCK_VALID_TREE) && (m_best_header == nullptr || CBlockIndexWorkComparator()(m_best_header, pindex)))
4950 m_best_header = pindex;
4951 }
4952 }
4953 return true;
4954}
4955
4957{
4958 LOCK(cs_main);
4959
4960 const CBlock& genesis_block{GetParams().GenesisBlock()};
4961
4962 // Check whether we're already initialized by checking for genesis in
4963 // m_blockman.m_block_index. Note that we can't use a chainstate's m_chain here, since it is
4964 // set based on the coins db, not the block index db, which is the only
4965 // thing loaded at this point.
4966 if (m_blockman.m_block_index.contains(genesis_block.GetHash())) {
4967 return true;
4968 }
4969
4970 try {
4971 FlatFilePos blockPos{m_blockman.WriteBlock(genesis_block, 0)};
4972 if (blockPos.IsNull()) {
4973 LogError("Writing genesis block to disk failed");
4974 return false;
4975 }
4976 CBlockIndex* pindex{m_blockman.AddToBlockIndex(genesis_block, m_best_header)};
4977 ReceivedBlockTransactions(genesis_block, pindex, blockPos);
4978 } catch (const std::runtime_error& e) {
4979 LogError("Failed to write genesis block: %s", e.what());
4980 return false;
4981 }
4982
4983 return true;
4984}
4985
4987 AutoFile& file_in,
4988 FlatFilePos* dbp,
4989 std::multimap<uint256, FlatFilePos>* blocks_with_unknown_parent)
4990{
4991 // Either both should be specified (-reindex), or neither (-loadblock).
4992 assert(!dbp == !blocks_with_unknown_parent);
4993
4994 const auto start{SteadyClock::now()};
4995 const CChainParams& params{GetParams()};
4996
4997 int nLoaded = 0;
4998 try {
5000 // nRewind indicates where to resume scanning in case something goes wrong,
5001 // such as a block fails to deserialize.
5002 uint64_t nRewind = blkdat.GetPos();
5003 while (!blkdat.eof()) {
5004 if (m_interrupt) return;
5005
5006 blkdat.SetPos(nRewind);
5007 nRewind++; // start one byte further next time, in case of failure
5008 blkdat.SetLimit(); // remove former limit
5009 unsigned int nSize = 0;
5010 try {
5011 // locate a header
5013 blkdat.FindByte(std::byte(params.MessageStart()[0]));
5014 nRewind = blkdat.GetPos() + 1;
5015 blkdat >> buf;
5016 if (buf != params.MessageStart()) {
5017 continue;
5018 }
5019 // read size
5020 blkdat >> nSize;
5021 if (nSize < 80 || nSize > MAX_BLOCK_SERIALIZED_SIZE)
5022 continue;
5023 } catch (const std::exception&) {
5024 // no valid block header found; don't complain
5025 // (this happens at the end of every blk.dat file)
5026 break;
5027 }
5028 try {
5029 // read block header
5030 const uint64_t nBlockPos{blkdat.GetPos()};
5031 if (dbp)
5032 dbp->nPos = nBlockPos;
5033 blkdat.SetLimit(nBlockPos + nSize);
5034 CBlockHeader header;
5035 blkdat >> header;
5036 const uint256 hash{header.GetHash()};
5037 // Skip the rest of this block (this may read from disk into memory); position to the marker before the
5038 // next block, but it's still possible to rewind to the start of the current block (without a disk read).
5039 nRewind = nBlockPos + nSize;
5040 blkdat.SkipTo(nRewind);
5041
5042 std::shared_ptr<CBlock> pblock{}; // needs to remain available after the cs_main lock is released to avoid duplicate reads from disk
5043
5044 {
5045 LOCK(cs_main);
5046 // detect out of order blocks, and store them for later
5047 if (hash != params.GetConsensus().hashGenesisBlock && !m_blockman.LookupBlockIndex(header.hashPrevBlock)) {
5048 LogDebug(BCLog::REINDEX, "%s: Out of order block %s, parent %s not known\n", __func__, hash.ToString(),
5049 header.hashPrevBlock.ToString());
5050 if (dbp && blocks_with_unknown_parent) {
5051 blocks_with_unknown_parent->emplace(header.hashPrevBlock, *dbp);
5052 }
5053 continue;
5054 }
5055
5056 // process in case the block isn't known yet
5057 const CBlockIndex* pindex = m_blockman.LookupBlockIndex(hash);
5058 if (!pindex || (pindex->nStatus & BLOCK_HAVE_DATA) == 0) {
5059 // This block can be processed immediately; rewind to its start, read and deserialize it.
5060 blkdat.SetPos(nBlockPos);
5061 pblock = std::make_shared<CBlock>();
5062 blkdat >> TX_WITH_WITNESS(*pblock);
5063 nRewind = blkdat.GetPos();
5064
5066 if (AcceptBlock(pblock, state, nullptr, true, dbp, nullptr, true)) {
5067 nLoaded++;
5068 }
5069 if (state.IsError()) {
5070 break;
5071 }
5072 } else if (hash != params.GetConsensus().hashGenesisBlock && pindex->nHeight % 1000 == 0) {
5073 LogDebug(BCLog::REINDEX, "Block Import: already had block %s at height %d\n", hash.ToString(), pindex->nHeight);
5074 }
5075 }
5076
5077 // Activate the genesis block so normal node progress can continue
5078 // During first -reindex, this will only connect Genesis since
5079 // ActivateBestChain only connects blocks which are in the block tree db,
5080 // which only contains blocks whose parents are in it.
5081 // But do this only if genesis isn't activated yet, to avoid connecting many blocks
5082 // without assumevalid in the case of a continuation of a reindex that
5083 // was interrupted by the user.
5084 if (hash == params.GetConsensus().hashGenesisBlock && WITH_LOCK(::cs_main, return ActiveHeight()) == -1) {
5086 if (!ActiveChainstate().ActivateBestChain(state, nullptr)) {
5087 break;
5088 }
5089 }
5090
5092 // must update the tip for pruning to work while importing with -loadblock.
5093 // this is a tradeoff to conserve disk space at the expense of time
5094 // spent updating the tip to be able to prune.
5095 // otherwise, ActivateBestChain won't be called by the import process
5096 // until after all of the block files are loaded. ActivateBestChain can be
5097 // called by concurrent network message processing. but, that is not
5098 // reliable for the purpose of pruning while importing.
5099 if (auto result{ActivateBestChains()}; !result) {
5100 LogDebug(BCLog::REINDEX, "%s\n", util::ErrorString(result).original);
5101 break;
5102 }
5103 }
5104
5106
5107 if (!blocks_with_unknown_parent) continue;
5108
5109 // Recursively process earlier encountered successors of this block
5110 std::deque<uint256> queue;
5111 queue.push_back(hash);
5112 while (!queue.empty()) {
5113 uint256 head = queue.front();
5114 queue.pop_front();
5115 auto range = blocks_with_unknown_parent->equal_range(head);
5116 while (range.first != range.second) {
5117 std::multimap<uint256, FlatFilePos>::iterator it = range.first;
5118 std::shared_ptr<CBlock> pblockrecursive = std::make_shared<CBlock>();
5119 if (m_blockman.ReadBlock(*pblockrecursive, it->second, {})) {
5120 const auto& block_hash{pblockrecursive->GetHash()};
5121 LogDebug(BCLog::REINDEX, "%s: Processing out of order child %s of %s", __func__, block_hash.ToString(), head.ToString());
5122 LOCK(cs_main);
5124 if (AcceptBlock(pblockrecursive, dummy, nullptr, true, &it->second, nullptr, true)) {
5125 nLoaded++;
5126 queue.push_back(block_hash);
5127 }
5128 }
5129 range.first++;
5130 blocks_with_unknown_parent->erase(it);
5132 }
5133 }
5134 } catch (const std::exception& e) {
5135 // historical bugs added extra data to the block files that does not deserialize cleanly.
5136 // commonly this data is between readable blocks, but it does not really matter. such data is not fatal to the import process.
5137 // the code that reads the block files deals with invalid data by simply ignoring it.
5138 // it continues to search for the next {4 byte magic message start bytes + 4 byte length + block} that does deserialize cleanly
5139 // and passes all of the other block validation checks dealing with POW and the merkle root, etc...
5140 // we merely note with this informational log message when unexpected data is encountered.
5141 // we could also be experiencing a storage system read error, or a read of a previous bad write. these are possible, but
5142 // less likely scenarios. we don't have enough information to tell a difference here.
5143 // the reindex process is not the place to attempt to clean and/or compact the block files. if so desired, a studious node operator
5144 // may use knowledge of the fact that the block files are not entirely pristine in order to prepare a set of pristine, and
5145 // perhaps ordered, block files for later reindexing.
5146 LogDebug(BCLog::REINDEX, "%s: unexpected data at file offset 0x%x - %s. continuing\n", __func__, (nRewind - 1), e.what());
5147 }
5148 }
5149 } catch (const std::runtime_error& e) {
5150 GetNotifications().fatalError(strprintf(_("System error while loading external block file: %s"), e.what()));
5151 }
5152 LogInfo("Loaded %i blocks from external file in %dms", nLoaded, Ticks<std::chrono::milliseconds>(SteadyClock::now() - start));
5153}
5154
5156{
5157 // Assert to verify Flatten() has been called.
5158 if (!*Assert(m_options.check_block_index)) return false;
5159 if (FastRandomContext().randrange(*m_options.check_block_index) >= 1) return false;
5160 return true;
5161}
5162
5164{
5165 if (!ShouldCheckBlockIndex()) {
5166 return;
5167 }
5168
5169 LOCK(cs_main);
5170
5171 // During a reindex, we read the genesis block and call CheckBlockIndex before ActivateBestChain,
5172 // so we have the genesis block in m_blockman.m_block_index but no active chain. (A few of the
5173 // tests when iterating the block tree require that m_chain has been initialized.)
5174 if (ActiveChain().Height() < 0) {
5175 assert(m_blockman.m_block_index.size() <= 1);
5176 return;
5177 }
5178
5179 // Build forward-pointing data structure for the entire block tree.
5180 // For performance reasons, indexes of the best header chain are stored in a vector (within CChain).
5181 // All remaining blocks are stored in a multimap.
5182 // The best header chain can differ from the active chain: E.g. its entries may belong to blocks that
5183 // are not yet validated.
5184 CChain best_hdr_chain;
5185 assert(m_best_header);
5186 assert(!(m_best_header->nStatus & BLOCK_FAILED_VALID));
5187 best_hdr_chain.SetTip(*m_best_header);
5188
5189 std::multimap<const CBlockIndex*, const CBlockIndex*> forward;
5190 for (auto& [_, block_index] : m_blockman.m_block_index) {
5191 // Only save indexes in forward that are not part of the best header chain.
5192 if (!best_hdr_chain.Contains(block_index)) {
5193 // Only genesis, which must be part of the best header chain, can have a nullptr parent.
5194 assert(block_index.pprev);
5195 forward.emplace(block_index.pprev, &block_index);
5196 }
5197 }
5198 assert(forward.size() + best_hdr_chain.Height() + 1 == m_blockman.m_block_index.size());
5199
5200 const CBlockIndex* pindex = best_hdr_chain[0];
5201 assert(pindex);
5202 // Iterate over the entire block tree, using depth-first search.
5203 // Along the way, remember whether there are blocks on the path from genesis
5204 // block being explored which are the first to have certain properties.
5205 size_t nNodes = 0;
5206 int nHeight = 0;
5207 const CBlockIndex* pindexFirstInvalid = nullptr; // Oldest ancestor of pindex which is invalid.
5208 const CBlockIndex* pindexFirstMissing = nullptr; // Oldest ancestor of pindex which does not have BLOCK_HAVE_DATA, since assumeutxo snapshot if used.
5209 const CBlockIndex* pindexFirstNeverProcessed = nullptr; // Oldest ancestor of pindex for which nTx == 0, since assumeutxo snapshot if used.
5210 const CBlockIndex* pindexFirstNotTreeValid = nullptr; // Oldest ancestor of pindex which does not have BLOCK_VALID_TREE (regardless of being valid or not).
5211 const CBlockIndex* pindexFirstNotTransactionsValid = nullptr; // Oldest ancestor of pindex which does not have BLOCK_VALID_TRANSACTIONS (regardless of being valid or not), since assumeutxo snapshot if used.
5212 const CBlockIndex* pindexFirstNotChainValid = nullptr; // Oldest ancestor of pindex which does not have BLOCK_VALID_CHAIN (regardless of being valid or not), since assumeutxo snapshot if used.
5213 const CBlockIndex* pindexFirstNotScriptsValid = nullptr; // Oldest ancestor of pindex which does not have BLOCK_VALID_SCRIPTS (regardless of being valid or not), since assumeutxo snapshot if used.
5214
5215 // After checking an assumeutxo snapshot block, reset pindexFirst pointers
5216 // to earlier blocks that have not been downloaded or validated yet, so
5217 // checks for later blocks can assume the earlier blocks were validated and
5218 // be stricter, testing for more requirements.
5219 const CBlockIndex* snap_base{CurrentChainstate().SnapshotBase()};
5220 const CBlockIndex *snap_first_missing{}, *snap_first_notx{}, *snap_first_notv{}, *snap_first_nocv{}, *snap_first_nosv{};
5221 auto snap_update_firsts = [&] {
5222 if (pindex == snap_base) {
5223 std::swap(snap_first_missing, pindexFirstMissing);
5224 std::swap(snap_first_notx, pindexFirstNeverProcessed);
5225 std::swap(snap_first_notv, pindexFirstNotTransactionsValid);
5226 std::swap(snap_first_nocv, pindexFirstNotChainValid);
5227 std::swap(snap_first_nosv, pindexFirstNotScriptsValid);
5228 }
5229 };
5230
5231 while (pindex != nullptr) {
5232 nNodes++;
5233 if (pindexFirstInvalid == nullptr && pindex->nStatus & BLOCK_FAILED_VALID) pindexFirstInvalid = pindex;
5234 if (pindexFirstMissing == nullptr && !(pindex->nStatus & BLOCK_HAVE_DATA)) {
5235 pindexFirstMissing = pindex;
5236 }
5237 if (pindexFirstNeverProcessed == nullptr && pindex->nTx == 0) pindexFirstNeverProcessed = pindex;
5238 if (pindex->pprev != nullptr && pindexFirstNotTreeValid == nullptr && (pindex->nStatus & BLOCK_VALID_MASK) < BLOCK_VALID_TREE) pindexFirstNotTreeValid = pindex;
5239
5240 if (pindex->pprev != nullptr) {
5241 if (pindexFirstNotTransactionsValid == nullptr &&
5242 (pindex->nStatus & BLOCK_VALID_MASK) < BLOCK_VALID_TRANSACTIONS) {
5243 pindexFirstNotTransactionsValid = pindex;
5244 }
5245
5246 if (pindexFirstNotChainValid == nullptr &&
5247 (pindex->nStatus & BLOCK_VALID_MASK) < BLOCK_VALID_CHAIN) {
5248 pindexFirstNotChainValid = pindex;
5249 }
5250
5251 if (pindexFirstNotScriptsValid == nullptr &&
5252 (pindex->nStatus & BLOCK_VALID_MASK) < BLOCK_VALID_SCRIPTS) {
5253 pindexFirstNotScriptsValid = pindex;
5254 }
5255 }
5256
5257 // Begin: actual consistency checks.
5258 if (pindex->pprev == nullptr) {
5259 // Genesis block checks.
5260 assert(pindex->GetBlockHash() == GetConsensus().hashGenesisBlock); // Genesis block's hash must match.
5261 for (const auto& c : m_chainstates) {
5262 if (c->m_chain.Genesis() != nullptr) {
5263 assert(pindex == c->m_chain.Genesis()); // The chain's genesis block must be this block.
5264 }
5265 }
5266 }
5267 // nSequenceId can't be set higher than SEQ_ID_INIT_FROM_DISK{1} for blocks that aren't linked
5268 // (negative is used for preciousblock, SEQ_ID_BEST_CHAIN_FROM_DISK{0} for active chain when loaded from disk)
5269 if (!pindex->HaveNumChainTxs()) assert(pindex->nSequenceId <= SEQ_ID_INIT_FROM_DISK);
5270 // VALID_TRANSACTIONS is equivalent to nTx > 0 for all nodes (whether or not pruning has occurred).
5271 // HAVE_DATA is only equivalent to nTx > 0 (or VALID_TRANSACTIONS) if no pruning has occurred.
5273 // If we've never pruned, then HAVE_DATA should be equivalent to nTx > 0
5274 assert(!(pindex->nStatus & BLOCK_HAVE_DATA) == (pindex->nTx == 0));
5275 assert(pindexFirstMissing == pindexFirstNeverProcessed);
5276 } else {
5277 // If we have pruned, then we can only say that HAVE_DATA implies nTx > 0
5278 if (pindex->nStatus & BLOCK_HAVE_DATA) assert(pindex->nTx > 0);
5279 }
5280 if (pindex->nStatus & BLOCK_HAVE_UNDO) assert(pindex->nStatus & BLOCK_HAVE_DATA);
5281 if (snap_base && snap_base->GetAncestor(pindex->nHeight) == pindex) {
5282 // Assumed-valid blocks should connect to the main chain.
5283 assert((pindex->nStatus & BLOCK_VALID_MASK) >= BLOCK_VALID_TREE);
5284 }
5285 // There should only be an nTx value if we have
5286 // actually seen a block's transactions.
5287 assert(((pindex->nStatus & BLOCK_VALID_MASK) >= BLOCK_VALID_TRANSACTIONS) == (pindex->nTx > 0)); // This is pruning-independent.
5288 // All parents having had data (at some point) is equivalent to all parents being VALID_TRANSACTIONS, which is equivalent to HaveNumChainTxs().
5289 // HaveNumChainTxs will also be set in the assumeutxo snapshot block from snapshot metadata.
5290 assert((pindexFirstNeverProcessed == nullptr || pindex == snap_base) == pindex->HaveNumChainTxs());
5291 assert((pindexFirstNotTransactionsValid == nullptr || pindex == snap_base) == pindex->HaveNumChainTxs());
5292 assert(pindex->nHeight == nHeight); // nHeight must be consistent.
5293 assert(pindex->pprev == nullptr || pindex->nChainWork >= pindex->pprev->nChainWork); // For every block except the genesis block, the chainwork must be larger than the parent's.
5294 assert(nHeight < 2 || (pindex->pskip && (pindex->pskip->nHeight < nHeight))); // The pskip pointer must point back for all but the first 2 blocks.
5295 assert(pindexFirstNotTreeValid == nullptr); // All m_blockman.m_block_index entries must at least be TREE valid
5296 if ((pindex->nStatus & BLOCK_VALID_MASK) >= BLOCK_VALID_TREE) assert(pindexFirstNotTreeValid == nullptr); // TREE valid implies all parents are TREE valid
5297 if ((pindex->nStatus & BLOCK_VALID_MASK) >= BLOCK_VALID_CHAIN) assert(pindexFirstNotChainValid == nullptr); // CHAIN valid implies all parents are CHAIN valid
5298 if ((pindex->nStatus & BLOCK_VALID_MASK) >= BLOCK_VALID_SCRIPTS) assert(pindexFirstNotScriptsValid == nullptr); // SCRIPTS valid implies all parents are SCRIPTS valid
5299 if (pindexFirstInvalid == nullptr) {
5300 // Checks for not-invalid blocks.
5301 assert((pindex->nStatus & BLOCK_FAILED_VALID) == 0); // The failed flag cannot be set for blocks without invalid parents.
5302 } else {
5303 assert(pindex->nStatus & BLOCK_FAILED_VALID); // Invalid blocks and their descendants must be marked as invalid
5304 }
5305 // Make sure m_chain_tx_count sum is correctly computed.
5306 if (!pindex->pprev) {
5307 // If no previous block, nTx and m_chain_tx_count must be the same.
5308 assert(pindex->m_chain_tx_count == pindex->nTx);
5309 } else if (pindex->pprev->m_chain_tx_count > 0 && pindex->nTx > 0) {
5310 // If previous m_chain_tx_count is set and number of transactions in block is known, sum must be set.
5311 assert(pindex->m_chain_tx_count == pindex->nTx + pindex->pprev->m_chain_tx_count);
5312 } else {
5313 // Otherwise m_chain_tx_count should only be set if this is a snapshot
5314 // block, and must be set if it is.
5315 assert((pindex->m_chain_tx_count != 0) == (pindex == snap_base));
5316 }
5317 // There should be no block with more work than m_best_header, unless it's known to be invalid
5318 assert((pindex->nStatus & BLOCK_FAILED_VALID) || pindex->nChainWork <= m_best_header->nChainWork);
5319
5320 // Chainstate-specific checks on setBlockIndexCandidates
5321 for (const auto& c : m_chainstates) {
5322 if (c->m_chain.Tip() == nullptr) continue;
5323 // Two main factors determine whether pindex is a candidate in
5324 // setBlockIndexCandidates:
5325 //
5326 // - If pindex has less work than the chain tip, it should not be a
5327 // candidate, and this will be asserted below. Otherwise it is a
5328 // potential candidate.
5329 //
5330 // - If pindex or one of its parent blocks back to the genesis block
5331 // or an assumeutxo snapshot never downloaded transactions
5332 // (pindexFirstNeverProcessed is non-null), it should not be a
5333 // candidate, and this will be asserted below. The only exception
5334 // is if pindex itself is an assumeutxo snapshot block. Then it is
5335 // also a potential candidate.
5336 if (!CBlockIndexWorkComparator()(pindex, c->m_chain.Tip()) && (pindexFirstNeverProcessed == nullptr || pindex == snap_base)) {
5337 // If pindex was detected as invalid (pindexFirstInvalid is
5338 // non-null), it is not required to be in
5339 // setBlockIndexCandidates.
5340 if (pindexFirstInvalid == nullptr) {
5341 // If pindex and all its parents back to the genesis block
5342 // or an assumeutxo snapshot block downloaded transactions,
5343 // and the transactions were not pruned (pindexFirstMissing
5344 // is null), it is a potential candidate. The check
5345 // excludes pruned blocks, because if any blocks were
5346 // pruned between pindex and the current chain tip, pindex will
5347 // only temporarily be added to setBlockIndexCandidates,
5348 // before being moved to m_blocks_unlinked. This check
5349 // could be improved to verify that if all blocks between
5350 // the chain tip and pindex have data, pindex must be a
5351 // candidate.
5352 //
5353 // If pindex is the chain tip, it also is a potential
5354 // candidate.
5355 //
5356 // If the chainstate was loaded from a snapshot and pindex
5357 // is the base of the snapshot, pindex is also a potential
5358 // candidate.
5359 if (pindexFirstMissing == nullptr || pindex == c->m_chain.Tip() || pindex == c->SnapshotBase()) {
5360 // If this chainstate is not a historical chainstate
5361 // targeting a specific block, pindex must be in
5362 // setBlockIndexCandidates. Otherwise, pindex only
5363 // needs to be added if it is an ancestor of the target
5364 // block.
5365 if (!c->TargetBlock() || c->TargetBlock()->GetAncestor(pindex->nHeight) == pindex) {
5366 assert(c->setBlockIndexCandidates.contains(pindex));
5367 }
5368 }
5369 // If some parent is missing, then it could be that this block was in
5370 // setBlockIndexCandidates but had to be removed because of the missing data.
5371 // In this case it must be in m_blocks_unlinked -- see test below.
5372 }
5373 } else { // If this block sorts worse than the current tip or some ancestor's block has never been seen, it cannot be in setBlockIndexCandidates.
5374 assert(!c->setBlockIndexCandidates.contains(pindex));
5375 }
5376 }
5377 // Check whether this block is in m_blocks_unlinked.
5378 auto rangeUnlinked{m_blockman.m_blocks_unlinked.equal_range(pindex->pprev)};
5379 bool foundInUnlinked = false;
5380 for (auto it = rangeUnlinked.first; it != rangeUnlinked.second; ++it) {
5381 assert(it->first == pindex->pprev);
5382 if (it->second == pindex) {
5383 assert(!foundInUnlinked); // No duplicates in m_blocks_unlinked
5384 foundInUnlinked = true;
5385 }
5386 }
5387 if (pindex->pprev && (pindex->nStatus & BLOCK_HAVE_DATA) && pindexFirstNeverProcessed != nullptr && pindexFirstInvalid == nullptr) {
5388 // If this block has block data available, some parent was never received, and has no invalid parents, it must be in m_blocks_unlinked.
5389 assert(foundInUnlinked);
5390 }
5391 if (!(pindex->nStatus & BLOCK_HAVE_DATA)) assert(!foundInUnlinked); // Can't be in m_blocks_unlinked if we don't HAVE_DATA
5392 if (pindexFirstMissing == nullptr) assert(!foundInUnlinked); // We aren't missing data for any parent -- cannot be in m_blocks_unlinked.
5393 if (pindex->pprev && (pindex->nStatus & BLOCK_HAVE_DATA) && pindexFirstNeverProcessed == nullptr && pindexFirstMissing != nullptr) {
5394 // We HAVE_DATA for this block, have received data for all parents at some point, but we're currently missing data for some parent.
5396 // This block may have entered m_blocks_unlinked if:
5397 // - it has a descendant that at some point had more work than the
5398 // tip, and
5399 // - we tried switching to that descendant but were missing
5400 // data for some intermediate block between m_chain and the
5401 // tip.
5402 // So if this block is itself better than any m_chain.Tip() and it wasn't in
5403 // setBlockIndexCandidates, then it must be in m_blocks_unlinked.
5404 for (const auto& c : m_chainstates) {
5405 if (!CBlockIndexWorkComparator()(pindex, c->m_chain.Tip()) && !c->setBlockIndexCandidates.contains(pindex)) {
5406 if (pindexFirstInvalid == nullptr) {
5407 if (!c->TargetBlock() || c->TargetBlock()->GetAncestor(pindex->nHeight) == pindex) {
5408 assert(foundInUnlinked);
5409 }
5410 }
5411 }
5412 }
5413 }
5414 // assert(pindex->GetBlockHash() == pindex->GetBlockHeader().GetHash()); // Perhaps too slow
5415 // End: actual consistency checks.
5416
5417
5418 // Try descending into the first subnode. Always process forks first and the best header chain after.
5419 snap_update_firsts();
5420 auto range{forward.equal_range(pindex)};
5421 if (range.first != range.second) {
5422 // A subnode not part of the best header chain was found.
5423 pindex = range.first->second;
5424 nHeight++;
5425 continue;
5426 } else if (best_hdr_chain.Contains(*pindex)) {
5427 // Descend further into best header chain.
5428 nHeight++;
5429 pindex = best_hdr_chain[nHeight];
5430 if (!pindex) break; // we are finished, since the best header chain is always processed last
5431 continue;
5432 }
5433 // This is a leaf node.
5434 // Move upwards until we reach a node of which we have not yet visited the last child.
5435 while (pindex) {
5436 // We are going to either move to a parent or a sibling of pindex.
5437 snap_update_firsts();
5438 // If pindex was the first with a certain property, unset the corresponding variable.
5439 if (pindex == pindexFirstInvalid) pindexFirstInvalid = nullptr;
5440 if (pindex == pindexFirstMissing) pindexFirstMissing = nullptr;
5441 if (pindex == pindexFirstNeverProcessed) pindexFirstNeverProcessed = nullptr;
5442 if (pindex == pindexFirstNotTreeValid) pindexFirstNotTreeValid = nullptr;
5443 if (pindex == pindexFirstNotTransactionsValid) pindexFirstNotTransactionsValid = nullptr;
5444 if (pindex == pindexFirstNotChainValid) pindexFirstNotChainValid = nullptr;
5445 if (pindex == pindexFirstNotScriptsValid) pindexFirstNotScriptsValid = nullptr;
5446 // Find our parent.
5447 CBlockIndex* pindexPar = pindex->pprev;
5448 // Find which child we just visited.
5449 auto rangePar{forward.equal_range(pindexPar)};
5450 while (rangePar.first->second != pindex) {
5451 assert(rangePar.first != rangePar.second); // Our parent must have at least the node we're coming from as child.
5452 rangePar.first++;
5453 }
5454 // Proceed to the next one.
5455 rangePar.first++;
5456 if (rangePar.first != rangePar.second) {
5457 // Move to a sibling not part of the best header chain.
5458 pindex = rangePar.first->second;
5459 break;
5460 } else if (pindexPar == best_hdr_chain[nHeight - 1]) {
5461 // Move to pindex's sibling on the best-chain, if it has one.
5462 pindex = best_hdr_chain[nHeight];
5463 // There will not be a next block if (and only if) parent block is the best header.
5464 assert((pindex == nullptr) == (pindexPar == best_hdr_chain.Tip()));
5465 break;
5466 } else {
5467 // Move up further.
5468 pindex = pindexPar;
5469 nHeight--;
5470 continue;
5471 }
5472 }
5473 }
5474
5475 // Check that we actually traversed the entire block index.
5476 assert(nNodes == forward.size() + best_hdr_chain.Height() + 1);
5477}
5478
5479std::string Chainstate::ToString()
5480{
5482 CBlockIndex* tip = m_chain.Tip();
5483 return strprintf("Chainstate [%s] @ height %d (%s)",
5484 m_from_snapshot_blockhash ? "snapshot" : "ibd",
5485 tip ? tip->nHeight : -1, tip ? tip->GetBlockHash().ToString() : "null");
5486}
5487
5488bool Chainstate::ResizeCoinsCaches(size_t coinstip_size, size_t coinsdb_size)
5489{
5491 if (coinstip_size == m_coinstip_cache_size_bytes &&
5492 coinsdb_size == m_coinsdb_cache_size_bytes) {
5493 // Cache sizes are unchanged, no need to continue.
5494 return true;
5495 }
5496 size_t old_coinstip_size = m_coinstip_cache_size_bytes;
5497 m_coinstip_cache_size_bytes = coinstip_size;
5498 m_coinsdb_cache_size_bytes = coinsdb_size;
5499 CoinsDB().ResizeCache(coinsdb_size);
5500
5501 LogInfo("[%s] resized coinsdb cache to %.1f MiB",
5502 this->ToString(), coinsdb_size / double(1_MiB));
5503 LogInfo("[%s] resized coinstip cache to %.1f MiB",
5504 this->ToString(), coinstip_size / double(1_MiB));
5505
5507 bool ret;
5508
5509 if (coinstip_size > old_coinstip_size) {
5510 // Likely no need to flush if cache sizes have grown.
5512 } else {
5513 // Otherwise, flush state to disk and deallocate the in-memory coins map.
5515 }
5516 return ret;
5517}
5518
5520{
5522 const ChainTxData& data{GetParams().TxData()};
5523 if (pindex == nullptr) {
5524 return 0.0;
5525 }
5526
5527 if (pindex->m_chain_tx_count == 0) {
5528 LogDebug(BCLog::VALIDATION, "Block %d has unset m_chain_tx_count. Unable to estimate verification progress.\n", pindex->nHeight);
5529 return 0.0;
5530 }
5531
5532 const int64_t nNow{TicksSinceEpoch<std::chrono::seconds>(NodeClock::now())};
5533 const auto block_time{
5534 (Assume(m_best_header) && std::abs(nNow - pindex->GetBlockTime()) <= Ticks<std::chrono::seconds>(2h) &&
5535 Assume(m_best_header->nHeight >= pindex->nHeight)) ?
5536 // When the header is known to be recent, switch to a height-based
5537 // approach. This ensures the returned value is quantized when
5538 // close to "1.0", because some users expect it to be. This also
5539 // avoids relying too much on the exact miner-set timestamp, which
5540 // may be off.
5541 nNow - (m_best_header->nHeight - pindex->nHeight) * GetConsensus().nPowTargetSpacing :
5542 pindex->GetBlockTime(),
5543 };
5544
5545 double fTxTotal;
5546
5547 if (pindex->m_chain_tx_count <= data.tx_count) {
5548 fTxTotal = data.tx_count + (nNow - data.nTime) * data.dTxRate;
5549 } else {
5550 fTxTotal = pindex->m_chain_tx_count + (nNow - block_time) * data.dTxRate;
5551 }
5552
5553 return std::min<double>(pindex->m_chain_tx_count / fTxTotal, 1.0);
5554}
5555
5557{
5560 auto target_block = HistoricalChainstate()->TargetBlock();
5561
5562 if (pindex.m_chain_tx_count == 0 || target_block->m_chain_tx_count == 0) {
5563 LogDebug(BCLog::VALIDATION, "[background validation] Block %d has unset m_chain_tx_count. Unable to estimate verification progress.", pindex.nHeight);
5564 return 0.0;
5565 }
5566 return static_cast<double>(pindex.m_chain_tx_count) / static_cast<double>(target_block->m_chain_tx_count);
5567}
5568
5569Chainstate& ChainstateManager::InitializeChainstate(CTxMemPool* mempool)
5570{
5572 assert(m_chainstates.empty());
5573 m_chainstates.emplace_back(std::make_unique<Chainstate>(mempool, m_blockman, *this));
5574 return *m_chainstates.back();
5575}
5576
5577[[nodiscard]] static bool DeleteCoinsDBFromDisk(const fs::path db_path, bool is_snapshot)
5579{
5581
5582 if (is_snapshot) {
5583 fs::path base_blockhash_path = db_path / node::SNAPSHOT_BLOCKHASH_FILENAME;
5584
5585 try {
5586 bool existed = fs::remove(base_blockhash_path);
5587 if (!existed) {
5588 LogWarning("[snapshot] snapshot chainstate dir being removed lacks %s file",
5590 }
5591 } catch (const fs::filesystem_error& e) {
5592 LogWarning("[snapshot] failed to remove file %s: %s\n",
5593 fs::PathToString(base_blockhash_path), e.code().message());
5594 }
5595 }
5596
5597 std::string path_str = fs::PathToString(db_path);
5598 LogInfo("Removing leveldb dir at %s\n", path_str);
5599
5600 // We have to destruct before this call leveldb::DB in order to release the db
5601 // lock, otherwise `DestroyDB` will fail. See `leveldb::~DBImpl()`.
5602 const bool destroyed = DestroyDB(path_str);
5603
5604 if (!destroyed) {
5605 LogError("leveldb DestroyDB call failed on %s", path_str);
5606 }
5607
5608 // Datadir should be removed from filesystem; otherwise initialization may detect
5609 // it on subsequent statups and get confused.
5610 //
5611 // If the base_blockhash_path removal above fails in the case of snapshot
5612 // chainstates, this will return false since leveldb won't remove a non-empty
5613 // directory.
5614 return destroyed && !fs::exists(db_path);
5615}
5616
5618 AutoFile& coins_file,
5619 const SnapshotMetadata& metadata,
5620 bool in_memory)
5621{
5622 uint256 base_blockhash = metadata.m_base_blockhash;
5623
5624 CBlockIndex* snapshot_start_block{};
5625
5626 {
5627 LOCK(::cs_main);
5628
5629 if (this->CurrentChainstate().m_from_snapshot_blockhash) {
5630 return util::Error{Untranslated("Can't activate a snapshot-based chainstate more than once")};
5631 }
5632 if (!GetParams().AssumeutxoForBlockhash(base_blockhash).has_value()) {
5633 auto available_heights = GetParams().GetAvailableSnapshotHeights();
5634 std::string heights_formatted = util::Join(available_heights, ", ", [&](const auto& i) { return util::ToString(i); });
5635 return util::Error{Untranslated(strprintf("assumeutxo block hash in snapshot metadata not recognized (hash: %s). The following snapshot heights are available: %s",
5636 base_blockhash.ToString(),
5637 heights_formatted))};
5638 }
5639
5640 snapshot_start_block = m_blockman.LookupBlockIndex(base_blockhash);
5641 if (!snapshot_start_block) {
5642 return util::Error{Untranslated(strprintf("The base block header (%s) must appear in the headers chain. Make sure all headers are syncing, and call loadtxoutset again",
5643 base_blockhash.ToString()))};
5644 }
5645
5646 bool start_block_invalid = snapshot_start_block->nStatus & BLOCK_FAILED_VALID;
5647 if (start_block_invalid) {
5648 return util::Error{Untranslated(strprintf("The base block header (%s) is part of an invalid chain", base_blockhash.ToString()))};
5649 }
5650
5651 if (!m_best_header || m_best_header->GetAncestor(snapshot_start_block->nHeight) != snapshot_start_block) {
5652 return util::Error{Untranslated("A forked headers-chain with more work than the chain with the snapshot base block header exists. Please proceed to sync without AssumeUtxo.")};
5653 }
5654
5655 auto mempool{CurrentChainstate().GetMempool()};
5656 if (mempool && mempool->size() > 0) {
5657 return util::Error{Untranslated("Can't activate a snapshot when mempool not empty")};
5658 }
5659 }
5660
5661 int64_t current_coinsdb_cache_size{0};
5662 int64_t current_coinstip_cache_size{0};
5663
5664 // Cache percentages to allocate to each chainstate.
5665 //
5666 // These particular percentages don't matter so much since they will only be
5667 // relevant during snapshot activation; caches are rebalanced at the conclusion of
5668 // this function. We want to give (essentially) all available cache capacity to the
5669 // snapshot to aid the bulk load later in this function.
5670 static constexpr double IBD_CACHE_PERC = 0.01;
5671 static constexpr double SNAPSHOT_CACHE_PERC = 0.99;
5672
5673 {
5674 LOCK(::cs_main);
5675 // Resize the coins caches to ensure we're not exceeding memory limits.
5676 //
5677 // Allocate the majority of the cache to the incoming snapshot chainstate, since
5678 // (optimistically) getting to its tip will be the top priority. We'll need to call
5679 // `MaybeRebalanceCaches()` once we're done with this function to ensure
5680 // the right allocation (including the possibility that no snapshot was activated
5681 // and that we should restore the active chainstate caches to their original size).
5682 //
5683 current_coinsdb_cache_size = this->ActiveChainstate().m_coinsdb_cache_size_bytes;
5684 current_coinstip_cache_size = this->ActiveChainstate().m_coinstip_cache_size_bytes;
5685
5686 // Temporarily resize the active coins cache to make room for the newly-created
5687 // snapshot chain.
5688 this->ActiveChainstate().ResizeCoinsCaches(
5689 static_cast<size_t>(current_coinstip_cache_size * IBD_CACHE_PERC),
5690 static_cast<size_t>(current_coinsdb_cache_size * IBD_CACHE_PERC));
5691 }
5692
5693 auto snapshot_chainstate = WITH_LOCK(::cs_main,
5694 return std::make_unique<Chainstate>(
5695 /*mempool=*/nullptr, m_blockman, *this, base_blockhash));
5696
5697 {
5698 LOCK(::cs_main);
5699 snapshot_chainstate->InitCoinsDB(
5700 static_cast<size_t>(current_coinsdb_cache_size * SNAPSHOT_CACHE_PERC),
5701 in_memory, /*should_wipe=*/false);
5702 snapshot_chainstate->InitCoinsCache(
5703 static_cast<size_t>(current_coinstip_cache_size * SNAPSHOT_CACHE_PERC));
5704 }
5705
5706 auto cleanup_bad_snapshot = [&](bilingual_str reason) EXCLUSIVE_LOCKS_REQUIRED(::cs_main) {
5707 this->MaybeRebalanceCaches();
5708
5709 // PopulateAndValidateSnapshot can return (in error) before the leveldb datadir
5710 // has been created, so only attempt removal if we got that far.
5711 if (auto snapshot_datadir = node::FindAssumeutxoChainstateDir(m_options.datadir)) {
5712 // We have to destruct leveldb::DB in order to release the db lock, otherwise
5713 // DestroyDB() (in DeleteCoinsDBFromDisk()) will fail. See `leveldb::~DBImpl()`.
5714 // Destructing the chainstate (and so resetting the coinsviews object) does this.
5715 snapshot_chainstate.reset();
5716 bool removed = DeleteCoinsDBFromDisk(*snapshot_datadir, /*is_snapshot=*/true);
5717 if (!removed) {
5718 GetNotifications().fatalError(strprintf(_("Failed to remove snapshot chainstate dir (%s). "
5719 "Manually remove it before restarting.\n"), fs::PathToString(*snapshot_datadir)));
5720 }
5721 }
5722 return util::Error{std::move(reason)};
5723 };
5724
5725 if (auto res{this->PopulateAndValidateSnapshot(*snapshot_chainstate, coins_file, metadata)}; !res) {
5726 LOCK(::cs_main);
5727 return cleanup_bad_snapshot(Untranslated(strprintf("Population failed: %s", util::ErrorString(res).original)));
5728 }
5729
5730 LOCK(::cs_main); // cs_main required for rest of snapshot activation.
5731
5732 // Do a final check to ensure that the snapshot chainstate is actually a more
5733 // work chain than the active chainstate; a user could have loaded a snapshot
5734 // very late in the IBD process, and we wouldn't want to load a useless chainstate.
5735 if (!CBlockIndexWorkComparator()(ActiveTip(), snapshot_chainstate->m_chain.Tip())) {
5736 return cleanup_bad_snapshot(Untranslated("work does not exceed active chainstate"));
5737 }
5738 // If not in-memory, persist the base blockhash for use during subsequent
5739 // initialization.
5740 if (!in_memory) {
5741 if (!node::WriteSnapshotBaseBlockhash(*snapshot_chainstate)) {
5742 return cleanup_bad_snapshot(Untranslated("could not write base blockhash"));
5743 }
5744 }
5745
5746 Chainstate& chainstate{AddChainstate(std::move(snapshot_chainstate))};
5747 m_blockman.m_snapshot_height = Assert(chainstate.SnapshotBase())->nHeight;
5748
5749 chainstate.PopulateBlockIndexCandidates();
5750
5751 LogInfo("[snapshot] successfully activated snapshot %s", base_blockhash.ToString());
5752 LogInfo("[snapshot] (%.2f MB)",
5753 chainstate.CoinsTip().DynamicMemoryUsage() / (1000 * 1000));
5754
5755 this->MaybeRebalanceCaches();
5756 return snapshot_start_block;
5757}
5758
5759static void FlushSnapshotToDisk(CCoinsViewCache& coins_cache, bool snapshot_loaded)
5760{
5762 strprintf("%s (%.2f MB)",
5763 snapshot_loaded ? "saving snapshot chainstate" : "flushing coins cache",
5764 coins_cache.DynamicMemoryUsage() / (1000 * 1000)),
5766
5767 coins_cache.Flush();
5768}
5769
5770struct StopHashingException : public std::exception
5771{
5772 const char* what() const noexcept override
5773 {
5774 return "ComputeUTXOStats interrupted.";
5775 }
5776};
5777
5779{
5780 if (interrupt) throw StopHashingException();
5781}
5782
5784 Chainstate& snapshot_chainstate,
5785 AutoFile& coins_file,
5786 const SnapshotMetadata& metadata)
5787{
5788 // It's okay to release cs_main before we're done using `coins_cache` because we know
5789 // that nothing else will be referencing the newly created snapshot_chainstate yet.
5790 CCoinsViewCache& coins_cache = *WITH_LOCK(::cs_main, return &snapshot_chainstate.CoinsTip());
5791
5792 uint256 base_blockhash = metadata.m_base_blockhash;
5793
5794 CBlockIndex* snapshot_start_block = WITH_LOCK(::cs_main, return m_blockman.LookupBlockIndex(base_blockhash));
5795
5796 if (!snapshot_start_block) {
5797 // Needed for ComputeUTXOStats to determine the
5798 // height and to avoid a crash when base_blockhash.IsNull()
5799 return util::Error{Untranslated(strprintf("Did not find snapshot start blockheader %s",
5800 base_blockhash.ToString()))};
5801 }
5802
5803 int base_height = snapshot_start_block->nHeight;
5804 const auto& maybe_au_data = GetParams().AssumeutxoForHeight(base_height);
5805
5806 if (!maybe_au_data) {
5807 return util::Error{Untranslated(strprintf("Assumeutxo height in snapshot metadata not recognized "
5808 "(%d) - refusing to load snapshot", base_height))};
5809 }
5810
5811 const AssumeutxoData& au_data = *maybe_au_data;
5812
5813 // This work comparison is a duplicate check with the one performed later in
5814 // ActivateSnapshot(), but is done so that we avoid doing the long work of staging
5815 // a snapshot that isn't actually usable.
5816 if (WITH_LOCK(::cs_main, return !CBlockIndexWorkComparator()(ActiveTip(), snapshot_start_block))) {
5817 return util::Error{Untranslated("Work does not exceed active chainstate")};
5818 }
5819
5820 const uint64_t coins_count = metadata.m_coins_count;
5821 uint64_t coins_left = metadata.m_coins_count;
5822
5823 LogInfo("[snapshot] loading %d coins from snapshot %s", coins_left, base_blockhash.ToString());
5824 int64_t coins_processed{0};
5825
5826 while (coins_left > 0) {
5827 try {
5828 Txid txid;
5829 coins_file >> txid;
5830 size_t coins_per_txid{0};
5831 coins_per_txid = ReadCompactSize(coins_file);
5832
5833 if (coins_per_txid > coins_left) {
5834 return util::Error{Untranslated("Mismatch in coins count in snapshot metadata and actual snapshot data")};
5835 }
5836
5837 for (size_t i = 0; i < coins_per_txid; i++) {
5838 COutPoint outpoint;
5839 Coin coin;
5840 outpoint.n = static_cast<uint32_t>(ReadCompactSize(coins_file));
5841 outpoint.hash = txid;
5842 coins_file >> coin;
5843 if (coin.nHeight > base_height ||
5844 outpoint.n >= std::numeric_limits<decltype(outpoint.n)>::max() // Avoid integer wrap-around in coinstats.cpp:ApplyHash
5845 ) {
5846 return util::Error{Untranslated(strprintf("Bad snapshot data after deserializing %d coins",
5847 coins_count - coins_left))};
5848 }
5849 if (!MoneyRange(coin.out.nValue)) {
5850 return util::Error{Untranslated(strprintf("Bad snapshot data after deserializing %d coins - bad tx out value",
5851 coins_count - coins_left))};
5852 }
5853 coins_cache.EmplaceCoinInternalDANGER(outpoint, std::move(coin));
5854
5855 --coins_left;
5856 ++coins_processed;
5857
5858 if (coins_processed % 1000000 == 0) {
5859 LogInfo("[snapshot] %d coins loaded (%.2f%%, %.2f MB)",
5860 coins_processed,
5861 static_cast<float>(coins_processed) * 100 / static_cast<float>(coins_count),
5862 coins_cache.DynamicMemoryUsage() / (1000 * 1000));
5863 }
5864
5865 // Batch write and flush (if we need to) every so often.
5866 //
5867 // If our average Coin size is roughly 41 bytes, checking every 120,000 coins
5868 // means <5MB of memory imprecision.
5869 if (coins_processed % 120000 == 0) {
5870 if (m_interrupt) {
5871 return util::Error{Untranslated("Aborting after an interrupt was requested")};
5872 }
5873
5874 const auto snapshot_cache_state = WITH_LOCK(::cs_main,
5875 return snapshot_chainstate.GetCoinsCacheSizeState());
5876
5877 if (snapshot_cache_state >= CoinsCacheSizeState::CRITICAL) {
5878 // This is a hack - we don't know what the actual best block is, but that
5879 // doesn't matter for the purposes of flushing the cache here. We'll set this
5880 // to its correct value (`base_blockhash`) below after the coins are loaded.
5881 coins_cache.SetBestBlock(GetRandHash());
5882
5883 // No need to acquire cs_main since this chainstate isn't being used yet.
5884 FlushSnapshotToDisk(coins_cache, /*snapshot_loaded=*/false);
5885 }
5886 }
5887 }
5888 } catch (const std::ios_base::failure&) {
5889 return util::Error{Untranslated(strprintf("Bad snapshot format or truncated snapshot after deserializing %d coins",
5890 coins_processed))};
5891 }
5892 }
5893
5894 // Important that we set this. This and the coins_cache accesses above are
5895 // sort of a layer violation, but either we reach into the innards of
5896 // CCoinsViewCache here or we have to invert some of the Chainstate to
5897 // embed them in a snapshot-activation-specific CCoinsViewCache bulk load
5898 // method.
5899 coins_cache.SetBestBlock(base_blockhash);
5900
5901 bool out_of_coins{false};
5902 try {
5903 std::byte left_over_byte;
5904 coins_file >> left_over_byte;
5905 } catch (const std::ios_base::failure&) {
5906 // We expect an exception since we should be out of coins.
5907 out_of_coins = true;
5908 }
5909 if (!out_of_coins) {
5910 return util::Error{Untranslated(strprintf("Bad snapshot - coins left over after deserializing %d coins",
5911 coins_count))};
5912 }
5913
5914 LogInfo("[snapshot] loaded %d (%.2f MB) coins from snapshot %s",
5915 coins_count,
5916 coins_cache.DynamicMemoryUsage() / (1000 * 1000),
5917 base_blockhash.ToString());
5918
5919 // No need to acquire cs_main since this chainstate isn't being used yet.
5920 FlushSnapshotToDisk(coins_cache, /*snapshot_loaded=*/true);
5921
5922 assert(coins_cache.GetBestBlock() == base_blockhash);
5923
5924 // As above, okay to immediately release cs_main here since no other context knows
5925 // about the snapshot_chainstate.
5926 const CCoinsViewDB& snapshot_coinsdb = WITH_LOCK(::cs_main, return snapshot_chainstate.CoinsDB());
5927
5928 std::optional<CCoinsStats> maybe_stats;
5929
5930 try {
5931 maybe_stats = ComputeUTXOStats(
5932 CoinStatsHashType::HASH_SERIALIZED, snapshot_coinsdb, m_blockman, [&interrupt = m_interrupt] { SnapshotUTXOHashBreakpoint(interrupt); });
5933 } catch (StopHashingException const&) {
5934 return util::Error{Untranslated("Aborting after an interrupt was requested")};
5935 }
5936 if (!maybe_stats.has_value()) {
5937 return util::Error{Untranslated("Failed to generate coins stats")};
5938 }
5939
5940 // Assert that the deserialized chainstate contents match the expected assumeutxo value.
5941 if (AssumeutxoHash{maybe_stats->hashSerialized} != au_data.hash_serialized) {
5942 return util::Error{Untranslated(strprintf("Bad snapshot content hash: expected %s, got %s",
5943 au_data.hash_serialized.ToString(), maybe_stats->hashSerialized.ToString()))};
5944 }
5945
5946 snapshot_chainstate.m_chain.SetTip(*snapshot_start_block);
5947
5948 // The remainder of this function requires modifying data protected by cs_main.
5949 LOCK(::cs_main);
5950
5951 // Fake various pieces of CBlockIndex state:
5952 CBlockIndex* index = nullptr;
5953
5954 // Don't make any modifications to the genesis block since it shouldn't be
5955 // necessary, and since the genesis block doesn't have normal flags like
5956 // BLOCK_VALID_SCRIPTS set.
5957 constexpr int AFTER_GENESIS_START{1};
5958
5959 for (int i = AFTER_GENESIS_START; i <= snapshot_chainstate.m_chain.Height(); ++i) {
5960 index = snapshot_chainstate.m_chain[i];
5961
5962 // Fake BLOCK_OPT_WITNESS so that Chainstate::NeedsRedownload()
5963 // won't ask for -reindex on startup.
5965 index->nStatus |= BLOCK_OPT_WITNESS;
5966 }
5967
5968 m_blockman.m_dirty_blockindex.insert(index);
5969 // Changes to the block index will be flushed to disk after this call
5970 // returns in `ActivateSnapshot()`, when `MaybeRebalanceCaches()` is
5971 // called, since we've added a snapshot chainstate and therefore will
5972 // have to downsize the IBD chainstate, which will result in a call to
5973 // `FlushStateToDisk(FORCE_FLUSH)`.
5974 }
5975
5976 assert(index);
5977 assert(index == snapshot_start_block);
5978 index->m_chain_tx_count = au_data.m_chain_tx_count;
5979
5980 LogInfo("[snapshot] validated snapshot (%.2f MB)",
5981 coins_cache.DynamicMemoryUsage() / (1000 * 1000));
5982 return {};
5983}
5984
5985// Currently, this function holds cs_main for its duration, which could be for
5986// multiple minutes due to the ComputeUTXOStats call. Holding cs_main used to be
5987// necessary (before d43a1f1a2fa3) to avoid advancing validated_cs farther than
5988// its target block. Now it should be possible to avoid this, but simply
5989// releasing cs_main here would not be possible because this function is invoked
5990// by ConnectTip within ActivateBestChain.
5991//
5992// Eventually (TODO) it would be better to call this function outside of
5993// ActivateBestChain, on a separate thread that should not require cs_main to
5994// hash, because the UTXO set is only hashed after the historical chainstate
5995// reaches its target block and is no longer changing.
5996SnapshotCompletionResult ChainstateManager::MaybeValidateSnapshot(Chainstate& validated_cs, Chainstate& unvalidated_cs)
5997{
5999
6000 // If the snapshot does not need to be validated...
6001 if (unvalidated_cs.m_assumeutxo != Assumeutxo::UNVALIDATED ||
6002 // Or if either chainstate is unusable...
6003 !unvalidated_cs.m_from_snapshot_blockhash ||
6004 validated_cs.m_assumeutxo != Assumeutxo::VALIDATED ||
6005 !validated_cs.m_chain.Tip() ||
6006 // Or the validated chainstate is not targeting the snapshot block...
6007 !validated_cs.m_target_blockhash ||
6008 *validated_cs.m_target_blockhash != *unvalidated_cs.m_from_snapshot_blockhash ||
6009 // Or the validated chainstate has not reached the snapshot block yet...
6010 !validated_cs.ReachedTarget()) {
6011 // Then the snapshot cannot be validated and there is nothing to do.
6013 }
6014 assert(validated_cs.TargetBlock() == validated_cs.m_chain.Tip());
6015
6016 auto handle_invalid_snapshot = [&]() EXCLUSIVE_LOCKS_REQUIRED(::cs_main) {
6017 bilingual_str user_error = strprintf(_(
6018 "%s failed to validate the -assumeutxo snapshot state. "
6019 "This indicates a hardware problem, or a bug in the software, or a "
6020 "bad software modification that allowed an invalid snapshot to be "
6021 "loaded. As a result of this, the node will shut down and stop using any "
6022 "state that was built on the snapshot, resetting the chain height "
6023 "from %d to %d. On the next "
6024 "restart, the node will resume syncing from %d "
6025 "without using any snapshot data. "
6026 "Please report this incident to %s, including how you obtained the snapshot. "
6027 "The invalid snapshot chainstate will be left on disk in case it is "
6028 "helpful in diagnosing the issue that caused this error."),
6029 CLIENT_NAME, unvalidated_cs.m_chain.Height(),
6030 validated_cs.m_chain.Height(),
6031 validated_cs.m_chain.Height(), CLIENT_BUGREPORT);
6032
6033 LogError("[snapshot] !!! %s\n", user_error.original);
6034 LogError("[snapshot] deleting snapshot, reverting to validated chain, and stopping node\n");
6035
6036 // Reset chainstate target to network tip instead of snapshot block.
6037 validated_cs.SetTargetBlock(nullptr);
6038
6039 unvalidated_cs.m_assumeutxo = Assumeutxo::INVALID;
6040
6041 auto rename_result = unvalidated_cs.InvalidateCoinsDBOnDisk();
6042 if (!rename_result) {
6043 user_error += Untranslated("\n") + util::ErrorString(rename_result);
6044 }
6045
6046 GetNotifications().fatalError(user_error);
6047 };
6048
6049 CCoinsViewDB& validated_coins_db = validated_cs.CoinsDB();
6050 validated_cs.ForceFlushStateToDisk();
6051
6052 const auto& maybe_au_data = m_options.chainparams.AssumeutxoForHeight(validated_cs.m_chain.Height());
6053 if (!maybe_au_data) {
6054 LogWarning("[snapshot] assumeutxo data not found for height "
6055 "(%d) - refusing to validate snapshot", validated_cs.m_chain.Height());
6056 handle_invalid_snapshot();
6058 }
6059
6060 const AssumeutxoData& au_data = *maybe_au_data;
6061 std::optional<CCoinsStats> validated_cs_stats;
6062 LogInfo("[snapshot] computing UTXO stats for background chainstate to validate "
6063 "snapshot - this could take a few minutes");
6064 try {
6065 validated_cs_stats = ComputeUTXOStats(
6066 CoinStatsHashType::HASH_SERIALIZED,
6067 validated_coins_db,
6068 m_blockman,
6069 [&interrupt = m_interrupt] { SnapshotUTXOHashBreakpoint(interrupt); });
6070 } catch (StopHashingException const&) {
6072 }
6073
6074 // XXX note that this function is slow and will hold cs_main for potentially minutes.
6075 if (!validated_cs_stats) {
6076 LogWarning("[snapshot] failed to generate stats for validation coins db");
6077 // While this isn't a problem with the snapshot per se, this condition
6078 // prevents us from validating the snapshot, so we should shut down and let the
6079 // user handle the issue manually.
6080 handle_invalid_snapshot();
6082 }
6083
6084 // Compare the validated chainstate's UTXO set hash against the hard-coded
6085 // assumeutxo hash we expect.
6086 //
6087 // TODO: For belt-and-suspenders, we could cache the UTXO set
6088 // hash for the snapshot when it's loaded in its chainstate's leveldb. We could then
6089 // reference that here for an additional check.
6090 if (AssumeutxoHash{validated_cs_stats->hashSerialized} != au_data.hash_serialized) {
6091 LogWarning("[snapshot] hash mismatch: actual=%s, expected=%s",
6092 validated_cs_stats->hashSerialized.ToString(),
6093 au_data.hash_serialized.ToString());
6094 handle_invalid_snapshot();
6096 }
6097
6098 LogInfo("[snapshot] snapshot beginning at %s has been fully validated",
6099 unvalidated_cs.m_from_snapshot_blockhash->ToString());
6100
6101 unvalidated_cs.m_assumeutxo = Assumeutxo::VALIDATED;
6102 validated_cs.m_target_utxohash = AssumeutxoHash{validated_cs_stats->hashSerialized};
6103 this->MaybeRebalanceCaches();
6104
6106}
6107
6109{
6110 LOCK(::cs_main);
6111 return CurrentChainstate();
6112}
6113
6114void ChainstateManager::MaybeRebalanceCaches()
6115{
6117 Chainstate& current_cs{CurrentChainstate()};
6118 Chainstate* historical_cs{HistoricalChainstate()};
6119 if (!historical_cs && !current_cs.m_from_snapshot_blockhash) {
6120 // Allocate everything to the IBD chainstate. This will always happen
6121 // when we are not using a snapshot.
6122 current_cs.ResizeCoinsCaches(m_total_coinstip_cache, m_total_coinsdb_cache);
6123 } else if (!historical_cs) {
6124 // If background validation has completed and snapshot is our active chain...
6125 LogInfo("[snapshot] allocating all cache to the snapshot chainstate");
6126 // Allocate everything to the snapshot chainstate.
6127 current_cs.ResizeCoinsCaches(m_total_coinstip_cache, m_total_coinsdb_cache);
6128 } else {
6129 // If both chainstates exist, determine who needs more cache based on IBD status.
6130 //
6131 // Note: shrink caches first so that we don't inadvertently overwhelm available memory.
6132 if (IsInitialBlockDownload()) {
6133 historical_cs->ResizeCoinsCaches(
6135 current_cs.ResizeCoinsCaches(
6137 } else {
6138 current_cs.ResizeCoinsCaches(
6140 historical_cs->ResizeCoinsCaches(
6142 }
6143 }
6144}
6145
6146void ChainstateManager::ResetChainstates()
6147{
6148 m_chainstates.clear();
6149}
6150
6157{
6158 if (!opts.check_block_index.has_value()) opts.check_block_index = opts.chainparams.DefaultConsistencyChecks();
6159 if (!opts.minimum_chain_work.has_value()) opts.minimum_chain_work = UintToArith256(opts.chainparams.GetConsensus().nMinimumChainWork);
6160 if (!opts.assumed_valid_block.has_value()) opts.assumed_valid_block = opts.chainparams.GetConsensus().defaultAssumeValid;
6161 return std::move(opts);
6162}
6163
6165 : m_script_check_queue{/*batch_size=*/128, std::clamp(options.worker_threads_num, 0, MAX_SCRIPTCHECK_THREADS)},
6166 m_interrupt{interrupt},
6167 m_options{Flatten(std::move(options))},
6168 m_blockman{interrupt, std::move(blockman_options)},
6169 m_validation_cache{m_options.script_execution_cache_bytes, m_options.signature_cache_bytes}
6170{
6171}
6172
6174{
6175 LOCK(::cs_main);
6176
6178}
6179
6180Chainstate* ChainstateManager::LoadAssumeutxoChainstate()
6181{
6182 assert(!CurrentChainstate().m_from_snapshot_blockhash);
6183 std::optional<fs::path> path = node::FindAssumeutxoChainstateDir(m_options.datadir);
6184 if (!path) {
6185 return nullptr;
6186 }
6187 std::optional<uint256> base_blockhash = node::ReadSnapshotBaseBlockhash(*path);
6188 if (!base_blockhash) {
6189 return nullptr;
6190 }
6191 LogInfo("[snapshot] detected active snapshot chainstate (%s) - loading",
6192 fs::PathToString(*path));
6193
6194 auto snapshot_chainstate{std::make_unique<Chainstate>(nullptr, m_blockman, *this, base_blockhash)};
6195 LogInfo("[snapshot] switching active chainstate to %s", snapshot_chainstate->ToString());
6196 return &this->AddChainstate(std::move(snapshot_chainstate));
6197}
6198
6199Chainstate& ChainstateManager::AddChainstate(std::unique_ptr<Chainstate> chainstate)
6200{
6201 Chainstate& prev_chainstate{CurrentChainstate()};
6202 assert(prev_chainstate.m_assumeutxo == Assumeutxo::VALIDATED);
6203 // Set target block for historical chainstate to snapshot block.
6204 assert(!prev_chainstate.m_target_blockhash);
6205 prev_chainstate.m_target_blockhash = chainstate->m_from_snapshot_blockhash;
6206 m_chainstates.push_back(std::move(chainstate));
6207 Chainstate& curr_chainstate{CurrentChainstate()};
6208 assert(&curr_chainstate == m_chainstates.back().get());
6209
6210 // Transfer possession of the mempool to the chainstate.
6211 // Mempool is empty at this point because we're still in IBD.
6212 assert(!prev_chainstate.m_mempool || prev_chainstate.m_mempool->size() == 0);
6213 assert(!curr_chainstate.m_mempool);
6214 std::swap(curr_chainstate.m_mempool, prev_chainstate.m_mempool);
6215 return curr_chainstate;
6216}
6217
6218bool IsBIP30Repeat(const CBlockIndex& block_index)
6219{
6220 return (block_index.nHeight==91842 && block_index.GetBlockHash() == uint256{"00000000000a4d0a398161ffc163c503763b1f4360639393e0e4c8e300e0caec"}) ||
6221 (block_index.nHeight==91880 && block_index.GetBlockHash() == uint256{"00000000000743f190a18c5577a3c2d2a1f610ae9601ac046a38084ccb7cd721"});
6222}
6223
6224bool IsBIP30Unspendable(const uint256& block_hash, int block_height)
6225{
6226 return (block_height==91722 && block_hash == uint256{"00000000000271a2dc26e7667f8419f2e15416dc6955e5a6c6cdf3f2574dd08e"}) ||
6227 (block_height==91812 && block_hash == uint256{"00000000000af0aed4792b1acee3d966af36cf5def14935db8de83d6f9306f2f"});
6228}
6229
6230util::Result<void> Chainstate::InvalidateCoinsDBOnDisk()
6231{
6232 // Should never be called on a non-snapshot chainstate.
6234
6235 // Coins views no longer usable.
6236 m_coins_views.reset();
6237
6238 const fs::path db_path{StoragePath()};
6239 const fs::path invalid_path{db_path + "_INVALID"};
6240 const std::string db_path_str{fs::PathToString(db_path)};
6241 const std::string invalid_path_str{fs::PathToString(invalid_path)};
6242 LogInfo("[snapshot] renaming snapshot datadir %s to %s", db_path_str, invalid_path_str);
6243
6244 // The invalid storage directory is simply moved and not deleted because we may
6245 // want to do forensics later during issue investigation. The user is instructed
6246 // accordingly in MaybeValidateSnapshot().
6247 try {
6248 fs::rename(db_path, invalid_path);
6249 } catch (const fs::filesystem_error& e) {
6250 LogError("While invalidating the coins db: Error renaming file '%s' -> '%s': %s",
6251 db_path_str, invalid_path_str, e.what());
6252 return util::Error{strprintf(_(
6253 "Rename of '%s' -> '%s' failed. "
6254 "You should resolve this by manually moving or deleting the invalid "
6255 "snapshot directory %s, otherwise you will encounter the same error again "
6256 "on the next startup."),
6257 db_path_str, invalid_path_str, db_path_str)};
6258 }
6259 return {};
6260}
6261
6262bool ChainstateManager::DeleteChainstate(Chainstate& chainstate)
6263{
6265 assert(!chainstate.m_coins_views);
6266 const fs::path db_path{chainstate.StoragePath()};
6267 if (!DeleteCoinsDBFromDisk(db_path, /*is_snapshot=*/bool{chainstate.m_from_snapshot_blockhash})) {
6268 LogError("Deletion of %s failed. Please remove it manually to continue reindexing.",
6269 fs::PathToString(db_path));
6270 return false;
6271 }
6272 std::unique_ptr<Chainstate> prev_chainstate{Assert(RemoveChainstate(chainstate))};
6273 Chainstate& curr_chainstate{CurrentChainstate()};
6274 assert(!prev_chainstate->m_mempool || prev_chainstate->m_mempool->size() == 0);
6275 assert(!curr_chainstate.m_mempool);
6276 std::swap(curr_chainstate.m_mempool, prev_chainstate->m_mempool);
6277 return true;
6278}
6279
6280ChainstateRole Chainstate::GetRole() const
6281{
6282 return ChainstateRole{.validated = m_assumeutxo == Assumeutxo::VALIDATED, .historical = bool{m_target_blockhash}};
6283}
6284
6285void ChainstateManager::RecalculateBestHeader()
6286{
6288 m_best_header = ActiveChain().Tip();
6289 for (auto& entry : m_blockman.m_block_index) {
6290 if (!(entry.second.nStatus & BLOCK_FAILED_VALID) && m_best_header->nChainWork < entry.second.nChainWork) {
6291 m_best_header = &entry.second;
6292 }
6293 }
6294}
6295
6296std::optional<int> ChainstateManager::BlocksAheadOfTip() const
6297{
6298 LOCK(::cs_main);
6299 const CBlockIndex* best_header{m_best_header};
6300 const CBlockIndex* tip{ActiveChain().Tip()};
6301 // Only consider headers that extend the active tip; ignore competing branches.
6302 if (best_header && tip && best_header->nChainWork > tip->nChainWork &&
6303 best_header->GetAncestor(tip->nHeight) == tip) {
6304 return best_header->nHeight - tip->nHeight;
6305 }
6306 return std::nullopt;
6307}
6308
6309bool ChainstateManager::ValidatedSnapshotCleanup(Chainstate& validated_cs, Chainstate& unvalidated_cs)
6310{
6312 if (unvalidated_cs.m_assumeutxo != Assumeutxo::VALIDATED) {
6313 // No need to clean up.
6314 return false;
6315 }
6316
6317 const fs::path validated_path{validated_cs.StoragePath()};
6318 const fs::path assumed_valid_path{unvalidated_cs.StoragePath()};
6319 const fs::path delete_path{validated_path + "_todelete"};
6320
6321 // Since we're going to be moving around the underlying leveldb filesystem content
6322 // for each chainstate, make sure that the chainstates (and their constituent
6323 // CoinsViews members) have been destructed first.
6324 //
6325 // The caller of this method will be responsible for reinitializing chainstates
6326 // if they want to continue operation.
6327 this->ResetChainstates();
6328 assert(this->m_chainstates.size() == 0);
6329
6330 LogInfo("[snapshot] deleting background chainstate directory (now unnecessary) (%s)",
6331 fs::PathToString(validated_path));
6332
6333 auto rename_failed_abort = [this](
6334 fs::path p_old,
6335 fs::path p_new,
6336 const fs::filesystem_error& err) {
6337 LogError("[snapshot] Error renaming path (%s) -> (%s): %s\n",
6338 fs::PathToString(p_old), fs::PathToString(p_new), err.what());
6340 "Rename of '%s' -> '%s' failed. "
6341 "Cannot clean up the background chainstate leveldb directory."),
6342 fs::PathToString(p_old), fs::PathToString(p_new)));
6343 };
6344
6345 try {
6346 fs::rename(validated_path, delete_path);
6347 } catch (const fs::filesystem_error& e) {
6348 rename_failed_abort(validated_path, delete_path, e);
6349 throw;
6350 }
6351
6352 LogInfo("[snapshot] moving snapshot chainstate (%s) to "
6353 "default chainstate directory (%s)",
6354 fs::PathToString(assumed_valid_path), fs::PathToString(validated_path));
6355
6356 try {
6357 fs::rename(assumed_valid_path, validated_path);
6358 } catch (const fs::filesystem_error& e) {
6359 rename_failed_abort(assumed_valid_path, validated_path, e);
6360 throw;
6361 }
6362
6363 if (!DeleteCoinsDBFromDisk(delete_path, /*is_snapshot=*/false)) {
6364 // No need to FatalError because once the unneeded bg chainstate data is
6365 // moved, it will not interfere with subsequent initialization.
6366 LogWarning("Deletion of %s failed. Please remove it manually, as the "
6367 "directory is now unnecessary.",
6368 fs::PathToString(delete_path));
6369 } else {
6370 LogInfo("[snapshot] deleted background chainstate directory (%s)",
6371 fs::PathToString(validated_path));
6372 }
6373 return true;
6374}
6375
6376std::pair<int, int> Chainstate::GetPruneRange(int last_height_can_prune) const
6377{
6378 if (m_chain.Height() <= 0) {
6379 return {0, 0};
6380 }
6381 int prune_start{0};
6382
6383 if (m_from_snapshot_blockhash && m_assumeutxo != Assumeutxo::VALIDATED) {
6384 // Only prune blocks _after_ the snapshot if this is a snapshot chain
6385 // that has not been fully validated yet. The earlier blocks need to be
6386 // kept to validate the snapshot
6387 prune_start = Assert(SnapshotBase())->nHeight + 1;
6388 }
6389
6390 int max_prune = std::max<int>(
6391 0, m_chain.Height() - static_cast<int>(MIN_BLOCKS_TO_KEEP));
6392
6393 // last block to prune is the lesser of (caller-specified height, MIN_BLOCKS_TO_KEEP from the tip)
6394 //
6395 // While you might be tempted to prune the background chainstate more
6396 // aggressively (i.e. fewer MIN_BLOCKS_TO_KEEP), this won't work with index
6397 // building - specifically blockfilterindex requires undo data, and if
6398 // we don't maintain this trailing window, we hit indexing failures.
6399 int prune_end = std::min(last_height_can_prune, max_prune);
6400
6401 return {prune_start, prune_end};
6402}
6403
6404std::optional<std::pair<const CBlockIndex*, const CBlockIndex*>> ChainstateManager::GetHistoricalBlockRange() const
6405{
6406 const Chainstate* chainstate{HistoricalChainstate()};
6407 if (!chainstate) return {};
6408 return std::make_pair(chainstate->m_chain.Tip(), chainstate->TargetBlock());
6409}
6410
6411util::Result<void> ChainstateManager::ActivateBestChains()
6412{
6413 // We can't hold cs_main during ActivateBestChain even though we're accessing
6414 // the chainman unique_ptrs since ABC requires us not to be holding cs_main, so retrieve
6415 // the relevant pointers before the ABC call.
6417 std::vector<Chainstate*> chainstates;
6418 {
6419 LOCK(GetMutex());
6420 chainstates.reserve(m_chainstates.size());
6421 for (const auto& chainstate : m_chainstates) {
6422 if (chainstate && chainstate->m_assumeutxo != Assumeutxo::INVALID && !chainstate->m_target_utxohash) {
6423 chainstates.push_back(chainstate.get());
6424 }
6425 }
6426 }
6427 for (Chainstate* chainstate : chainstates) {
6429 if (!chainstate->ActivateBestChain(state, nullptr)) {
6430 LOCK(GetMutex());
6431 return util::Error{Untranslated(strprintf("%s Failed to connect best block (%s)", chainstate->ToString(), state.ToString()))};
6432 }
6433 }
6434 return {};
6435}
bool MoneyRange(const CAmount &nValue)
Definition: amount.h:27
int64_t CAmount
Amount in satoshis (Can be negative)
Definition: amount.h:12
constexpr CAmount COIN
The amount of satoshis in one BTC.
Definition: amount.h:15
arith_uint256 UintToArith256(const uint256 &a)
int ret
int flags
Definition: bitcoin-tx.cpp:530
ArgsManager & args
Definition: bitcoind.cpp:280
void InvalidateBlock(ChainstateManager &chainman, const uint256 block_hash)
CBlockLocator GetLocator(const CBlockIndex *index)
Get a locator for a block index entry.
Definition: chain.cpp:45
int64_t GetBlockProofEquivalentTime(const CBlockIndex &to, const CBlockIndex &from, const CBlockIndex &tip, const Consensus::Params &params)
Return the time it would take to redo the work difference between from and to, assuming the current h...
Definition: chain.cpp:135
const CBlockIndex * LastCommonAncestor(const CBlockIndex *pa, const CBlockIndex *pb)
Find the last common ancestor two blocks have.
Definition: chain.cpp:154
@ BLOCK_VALID_CHAIN
Outputs do not overspend inputs, no double spends, coinbase output ok, no immature coinbase spends,...
Definition: chain.h:65
@ BLOCK_VALID_MASK
All validity bits.
Definition: chain.h:72
@ BLOCK_VALID_TRANSACTIONS
Only first tx is coinbase, 2 <= coinbase input script length <= 100, transactions valid,...
Definition: chain.h:61
@ BLOCK_VALID_SCRIPTS
Scripts & signatures ok.
Definition: chain.h:69
@ BLOCK_VALID_TREE
All parent headers found, difficulty matches, timestamp >= median previous.
Definition: chain.h:51
@ BLOCK_HAVE_UNDO
undo data available in rev*.dat
Definition: chain.h:76
@ BLOCK_HAVE_DATA
full block available in blk*.dat
Definition: chain.h:75
@ BLOCK_FAILED_VALID
stage after last reached validness failed
Definition: chain.h:79
@ BLOCK_OPT_WITNESS
block data in blk*.dat was received with a witness-enforcing client
Definition: chain.h:82
constexpr int32_t SEQ_ID_BEST_CHAIN_FROM_DISK
Init values for CBlockIndex nSequenceId when loaded from disk.
Definition: chain.h:39
arith_uint256 GetBlockProof(const CBlockIndex &block)
Compute how much work a block index entry corresponds to.
Definition: chain.h:305
constexpr int32_t SEQ_ID_INIT_FROM_DISK
Definition: chain.h:40
#define NONFATAL_UNREACHABLE()
NONFATAL_UNREACHABLE() is a macro that is used to mark unreachable code.
Definition: check.h:133
#define Assert(val)
Identity function.
Definition: check.h:116
#define STR_INTERNAL_BUG(msg)
Definition: check.h:99
#define Assume(val)
Assume is the identity function.
Definition: check.h:128
Non-refcounted RAII wrapper for FILE*.
Definition: streams.h:395
std::string ToString() const
Definition: hash_type.h:43
Wrapper around an AutoFile& that implements a ring buffer to deserialize from.
Definition: streams.h:505
Nodes collect new transactions into a block, hash them into a hash tree, and scan through nonce value...
Definition: block.h:27
NodeSeconds Time() const
Definition: block.h:61
uint32_t nBits
Definition: block.h:34
int64_t GetBlockTime() const
Definition: block.h:66
int32_t nVersion
Definition: block.h:30
uint256 hashPrevBlock
Definition: block.h:31
uint256 hashMerkleRoot
Definition: block.h:32
uint256 GetHash() const
Definition: block.cpp:14
Definition: block.h:74
bool m_checked_merkle_root
Definition: block.h:82
std::vector< CTransactionRef > vtx
Definition: block.h:77
bool m_checked_witness_commitment
Definition: block.h:81
bool fChecked
Definition: block.h:80
The block chain is a tree shaped structure starting with the genesis block at the root,...
Definition: chain.h:94
bool IsValid(enum BlockStatus nUpTo) const EXCLUSIVE_LOCKS_REQUIRED(
Check whether this block index entry is valid up to the passed validity level.
Definition: chain.h:250
CBlockIndex * pprev
pointer to the index of the predecessor of this block
Definition: chain.h:100
uint64_t m_chain_tx_count
(memory only) Number of transactions in the chain up to and including this block.
Definition: chain.h:129
arith_uint256 nChainWork
(memory only) Total amount of work (expected number of hashes) in the chain up to and including this ...
Definition: chain.h:118
bool HaveNumChainTxs() const
Check whether this block and all previous blocks back to the genesis block or an assumeutxo snapshot ...
Definition: chain.h:214
uint32_t nTime
Definition: chain.h:142
int32_t nSequenceId
(memory only) Sequential id assigned to distinguish order in which blocks are received.
Definition: chain.h:149
uint256 GetBlockHash() const
Definition: chain.h:198
int64_t GetBlockTime() const
Definition: chain.h:221
int64_t GetMedianTimePast() const
Definition: chain.h:233
FlatFilePos GetUndoPos() const EXCLUSIVE_LOCKS_REQUIRED(
Definition: chain.h:174
bool RaiseValidity(enum BlockStatus nUpTo) EXCLUSIVE_LOCKS_REQUIRED(
Raise the validity level of this block index entry.
Definition: chain.h:262
CBlockIndex * pskip
pointer to the index of some further predecessor of this block
Definition: chain.h:103
unsigned int nTx
Number of transactions in this block.
Definition: chain.h:123
int32_t nVersion
block header
Definition: chain.h:140
CBlockIndex * GetAncestor(int height)
Efficiently find an ancestor of this block.
Definition: chain.cpp:109
int nHeight
height of the entry in the chain. The genesis block has height 0
Definition: chain.h:106
const uint256 * phashBlock
pointer to the hash of the block, if any. Memory is owned by this CBlockIndex
Definition: chain.h:97
Undo information for a CBlock.
Definition: undo.h:64
std::vector< CTxUndo > vtxundo
Definition: undo.h:66
An in-memory indexed chain of blocks.
Definition: chain.h:380
bool Contains(const CBlockIndex &index) const
Efficiently check whether a block is present in this chain.
Definition: chain.h:410
CBlockIndex * Tip() const
Returns the index entry for the tip of this chain, or nullptr if none.
Definition: chain.h:396
const CBlockIndex * FindFork(const CBlockIndex &index) const
Find the last common block between this chain and a block index entry.
Definition: chain.cpp:50
void SetTip(CBlockIndex &block)
Set/initialize a chain with a given tip.
Definition: chain.cpp:16
CBlockIndex * Next(const CBlockIndex &index) const
Find the successor of a block in this chain, or nullptr if the given index is not found or is the tip...
Definition: chain.h:416
CBlockIndex * Genesis() const
Returns the index entry for the genesis block of this chain, or nullptr if none.
Definition: chain.h:390
int Height() const
Return the maximal height in the chain.
Definition: chain.h:425
CChainParams defines various tweakable parameters of a given instance of the Bitcoin system.
Definition: chainparams.h:77
const CBlock & GenesisBlock() const
Definition: chainparams.h:94
std::vector< int > GetAvailableSnapshotHeights() const
const ChainTxData & TxData() const
Definition: chainparams.h:128
std::optional< AssumeutxoData > AssumeutxoForHeight(int height) const
Definition: chainparams.h:119
CCoinsView that adds a memory cache for transactions to another CCoinsView.
Definition: coins.h:437
void Sync()
Push the modifications applied to this cache to its base while retaining the contents of this cache (...
Definition: coins.cpp:284
bool SpendCoin(const COutPoint &outpoint, Coin *moveto=nullptr)
Spend a coin.
Definition: coins.cpp:144
void Uncache(const COutPoint &outpoint)
Removes the UTXO with the given outpoint from the cache, if it is not modified.
Definition: coins.cpp:303
void EmplaceCoinInternalDANGER(const COutPoint &outpoint, Coin &&coin)
Emplace a coin into cacheCoins without performing any checks, marking the emplaced coin as dirty.
Definition: coins.cpp:123
void AddCoin(const COutPoint &outpoint, Coin &&coin, bool possible_overwrite)
Add a coin.
Definition: coins.cpp:80
virtual void Flush(bool reallocate_cache=true)
Push the modifications applied to this cache to its base and wipe local state.
Definition: coins.cpp:272
void SetBestBlock(const uint256 &block_hash)
Definition: coins.cpp:196
unsigned int GetCacheSize() const
Size of the cache (in number of transaction outputs)
Definition: coins.cpp:318
uint256 GetBestBlock() const override
Retrieve the block hash whose state this CCoinsView currently represents.
Definition: coins.cpp:190
bool HaveCoinInCache(const COutPoint &outpoint) const
Check if we have the given utxo already loaded in this cache.
Definition: coins.cpp:185
size_t DynamicMemoryUsage() const
Calculate the size of the cache (in bytes)
Definition: coins.cpp:50
bool HaveCoin(const COutPoint &outpoint) const override
Just check whether a given outpoint is unspent.
Definition: coins.cpp:179
const Coin & AccessCoin(const COutPoint &output) const
Return a reference to Coin in the cache, or coinEmpty if not found.
Definition: coins.cpp:170
CCoinsView backed by the coin database (chainstate/)
Definition: txdb.h:37
std::shared_future< void > CompactFullAsync() EXCLUSIVE_LOCKS_REQUIRED(cs_main
Perform a full compaction of the underlying LevelDB on a one-shot background thread.
Definition: txdb.cpp:198
void ResizeCache(size_t new_cache_size) EXCLUSIVE_LOCKS_REQUIRED(cs_main
Dynamically alter the underlying leveldb cache size.
Definition: txdb.cpp:73
Pure abstract view on the open txout dataset.
Definition: coins.h:356
virtual std::optional< Coin > GetCoin(const COutPoint &outpoint) const =0
Retrieve the Coin (unspent transaction output) for a given outpoint.
CCoinsView that brings transactions from a mempool into view.
Definition: txmempool.h:777
Fee rate in satoshis per virtualbyte: CAmount / vB the feerate is represented internally as FeeFrac.
Definition: feerate.h:32
A hasher class for Bitcoin's 256-bit hash (double SHA-256).
Definition: hash.h:32
void Finalize(std::span< unsigned char > output)
Definition: hash.h:38
CHash256 & Write(std::span< const unsigned char > input)
Definition: hash.h:45
An outpoint - a combination of a transaction hash and an index n into its vout.
Definition: transaction.h:29
uint32_t n
Definition: transaction.h:32
Txid hash
Definition: transaction.h:31
A hasher class for SHA-256.
Definition: sha256.h:14
void Finalize(unsigned char hash[OUTPUT_SIZE])
Definition: sha256.cpp:725
CSHA256 & Write(const unsigned char *data, size_t len)
Definition: sha256.cpp:699
Closure representing one script verification Note that this stores references to the spending transac...
Definition: validation.h:342
SignatureCache * m_signature_cache
Definition: validation.h:350
PrecomputedTransactionData * txdata
Definition: validation.h:349
CTxOut m_tx_out
Definition: validation.h:344
script_verify_flags m_flags
Definition: validation.h:347
bool cacheStore
Definition: validation.h:348
std::optional< std::pair< ScriptError, std::string > > operator()()
const CTransaction * ptxTo
Definition: validation.h:345
unsigned int nIn
Definition: validation.h:346
Serialized script, used inside transaction inputs and outputs.
Definition: script.h:406
The basic transaction that is broadcasted on the network and contained in blocks.
Definition: transaction.h:281
bool HasWitness() const
Definition: transaction.h:353
const std::vector< CTxOut > vout
Definition: transaction.h:292
const Wtxid & GetWitnessHash() const LIFETIMEBOUND
Definition: transaction.h:329
bool IsCoinBase() const
Definition: transaction.h:341
const Txid & GetHash() const LIFETIMEBOUND
Definition: transaction.h:328
const std::vector< CTxIn > vin
Definition: transaction.h:291
An input of a transaction.
Definition: transaction.h:62
COutPoint prevout
Definition: transaction.h:64
CTxMemPool::txiter TxHandle
Definition: txmempool.h:658
CTxMemPool stores valid-according-to-the-current-best-chain transactions that may be included in the ...
Definition: txmempool.h:187
void check(const CCoinsViewCache &active_coins_tip, int64_t spendheight) const EXCLUSIVE_LOCKS_REQUIRED(void removeRecursive(const CTransaction &tx, MemPoolRemovalReason reason) EXCLUSIVE_LOCKS_REQUIRED(cs)
If sanity-checking is turned on, check makes sure the pool is consistent (does not contain two transa...
Definition: txmempool.h:323
void UpdateTransactionsFromBlock(const std::vector< Txid > &vHashesToUpdate) EXCLUSIVE_LOCKS_REQUIRED(cs
UpdateTransactionsFromBlock is called when adding transactions from a disconnected block back to the ...
Definition: txmempool.cpp:91
void AddTransactionsUpdated(unsigned int n)
Definition: txmempool.cpp:201
CTransactionRef get(const Txid &hash) const
Return a mempool transaction with a given hash.
Definition: txmempool.cpp:660
size_t DynamicMemoryUsage() const
Definition: txmempool.cpp:826
const Options m_opts
Definition: txmempool.h:301
void removeForReorg(CChain &chain, std::function< bool(txiter)> filter_final_and_mature) EXCLUSIVE_LOCKS_REQUIRED(cs
After reorg, filter the entries that would no longer be valid in the next block, and update the entri...
Definition: txmempool.cpp:360
bool exists(const Txid &txid) const
Definition: txmempool.h:513
std::set< txiter, CompareIteratorByHash > setEntries
Definition: txmempool.h:266
indexed_transaction_set::nth_index< 0 >::type::const_iterator txiter
Definition: txmempool.h:263
std::vector< RemovedMempoolTransactionInfo > removeForBlock(const std::vector< CTransactionRef > &vtx) EXCLUSIVE_LOCKS_REQUIRED(cs)
Definition: txmempool.cpp:405
unsigned long size() const
Definition: txmempool.h:495
An output of a transaction.
Definition: transaction.h:140
CScript scriptPubKey
Definition: transaction.h:143
CAmount nValue
Definition: transaction.h:142
Undo information for a CTransaction.
Definition: undo.h:54
std::vector< Coin > vprevout
Definition: undo.h:57
VerifyDBResult VerifyDB(Chainstate &chainstate, const Consensus::Params &consensus_params, CCoinsView &coinsview, int nCheckLevel, int nCheckDepth) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
kernel::Notifications & m_notifications
Definition: validation.h:441
CVerifyDB(kernel::Notifications &notifications)
Chainstate stores and provides an API to update our local knowledge of the current best chain.
Definition: validation.h:554
void InitCoinsCache(size_t cache_size_bytes) EXCLUSIVE_LOCKS_REQUIRED(bool CanFlushToDisk() const EXCLUSIVE_LOCKS_REQUIRED(
Initialize the in-memory coins cache (to be done after the health of the on-disk database is verified...
Definition: validation.h:620
Mutex m_chainstate_mutex
The ChainState Mutex A lock that must be held when modifying this ChainState - held in ActivateBestCh...
Definition: validation.h:561
CChain m_chain
The current chain of blockheaders we consult and build on.
Definition: validation.h:628
CTxMemPool * GetMempool()
Definition: validation.h:704
bool RollforwardBlock(const CBlockIndex *pindex, CCoinsViewCache &inputs) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Apply the effects of a block on the utxo cache, ignoring that it may already have been applied.
size_t m_coinstip_cache_size_bytes
The cache size of the in-memory coins view.
Definition: validation.h:724
void UpdateTip(const CBlockIndex *pindexNew) EXCLUSIVE_LOCKS_REQUIRED(NodeClock::time_poin m_next_write)
Check warning conditions and do some notifications on new chain tip set.
Definition: validation.h:895
CCoinsViewCache & CoinsTip() EXCLUSIVE_LOCKS_REQUIRED(
Definition: validation.h:689
bool LoadChainTip() EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Update the chain tip based on database information, i.e.
size_t m_coinsdb_cache_size_bytes
The cache size of the on-disk coins view.
Definition: validation.h:721
bool PreciousBlock(BlockValidationState &state, CBlockIndex *pindex) LOCKS_EXCLUDED(bool InvalidateBlock(BlockValidationState &state, CBlockIndex *pindex) LOCKS_EXCLUDED(void SetBlockFailureFlags(CBlockIndex *pindex) EXCLUSIVE_LOCKS_REQUIRED(voi ResetBlockFailureFlags)(CBlockIndex *pindex) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Mark a block as precious and reorganize.
Definition: validation.h:808
void InvalidBlockFound(CBlockIndex *pindex, const BlockValidationState &state) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
bool ConnectTip(BlockValidationState &state, CBlockIndex *pindexNew, std::shared_ptr< const CBlock > block_to_connect, std::vector< ConnectedBlock > &connected_blocks, DisconnectedBlockTransactions &disconnectpool) EXCLUSIVE_LOCKS_REQUIRED(cs_main
Connect a new block to m_chain.
void CheckForkWarningConditions() EXCLUSIVE_LOCKS_REQUIRED(cs_main)
const CBlockIndex *SnapshotBase() const EXCLUSIVE_LOCKS_REQUIRED(const CBlockIndex *TargetBlock() const EXCLUSIVE_LOCKS_REQUIRED(void SetTargetBlock(CBlockIndex *block) EXCLUSIVE_LOCKS_REQUIRED(void SetTargetBlockHash(uint256 block_hash) EXCLUSIVE_LOCKS_REQUIRED(boo ReachedTarget)() const EXCLUSIVE_LOCKS_REQUIRED(
The base of the snapshot this chainstate was created from.
Definition: validation.h:672
kernel::ChainstateRole GetRole() const EXCLUSIVE_LOCKS_REQUIRED(void InitCoinsDB(size_t cache_size_bytes, bool in_memory, bool should_wipe)
Return the current role of the chainstate.
const std::optional< uint256 > m_from_snapshot_blockhash
The blockhash which is the base of the snapshot this chainstate was created from.
Definition: validation.h:640
bool ActivateBestChain(BlockValidationState &state, std::shared_ptr< const CBlock > pblock=nullptr) LOCKS_EXCLUDED(DisconnectResult DisconnectBlock(const CBlock &block, const CBlockIndex *pindex, CCoinsViewCache &view) EXCLUSIVE_LOCKS_REQUIRED(boo ConnectBlock)(const CBlock &block, BlockValidationState &state, CBlockIndex *pindex, CCoinsViewCache &view, bool fJustCheck=false) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Find the best known block, and make it the tip of the block chain.
Definition: validation.h:784
bool ActivateBestChainStep(BlockValidationState &state, CBlockIndex &index_most_work, const std::shared_ptr< const CBlock > &pblock, bool &fInvalidFound, std::vector< ConnectedBlock > &connected_blocks) EXCLUSIVE_LOCKS_REQUIRED(cs_main
Return the [start, end] (inclusive) of block heights we can prune.
CTxMemPool * m_mempool
Optional mempool that is kept in sync with the chain.
Definition: validation.h:565
CCoinsViewDB & CoinsDB() EXCLUSIVE_LOCKS_REQUIRED(
Definition: validation.h:697
bool DisconnectTip(BlockValidationState &state, DisconnectedBlockTransactions *disconnectpool) EXCLUSIVE_LOCKS_REQUIRED(cs_main
Disconnect m_chain's tip.
CBlockIndex * FindMostWorkChain() EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Return the tip of the chain with the most work in it, that isn't known to be invalid (it's however fa...
std::set< CBlockIndex *, node::CBlockIndexWorkComparator > setBlockIndexCandidates
The set of all CBlockIndex entries that have as much work as our current tip or more,...
Definition: validation.h:686
ChainstateManager & m_chainman
The chainstate manager that owns this chainstate.
Definition: validation.h:586
std::unique_ptr< CoinsViews > m_coins_views
Manages the UTXO set, which is a reflection of the contents of m_chain.
Definition: validation.h:568
bool m_mempool cs
Definition: validation.h:788
bool ReplayBlocks()
Replay blocks that aren't fully applied to the database.
void PruneBlockIndexCandidates()
Delete all entries in setBlockIndexCandidates that are worse than the current tip.
void TryAddBlockIndexCandidate(CBlockIndex *pindex) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Add a block to the candidate set if it has as much work as the current tip.
void PruneAndFlush()
Prune blockfiles from the disk if necessary and then flush chainstate changes if we pruned.
bool ResizeCoinsCaches(size_t coinstip_size, size_t coinsdb_size) EXCLUSIVE_LOCKS_REQUIRED(bool FlushStateToDisk(BlockValidationState &state, FlushStateMode mode, int nManualPruneHeight=0)
Resize the CoinsViews caches dynamically and flush state to disk.
node::BlockManager & m_blockman
Reference to a BlockManager instance which itself is shared across all Chainstate instances.
Definition: validation.h:581
void ForceFlushStateToDisk(bool wipe_cache=true)
Flush all changes to disk.
void MaybeUpdateMempoolForReorg(DisconnectedBlockTransactions &disconnectpool, bool fAddToMempool) EXCLUSIVE_LOCKS_REQUIRED(cs_main
Make mempool consistent after a reorg, by re-adding or recursively erasing disconnected block transac...
Definition: validation.cpp:303
void ClearBlockIndexCandidates() EXCLUSIVE_LOCKS_REQUIRED(void PopulateBlockIndexCandidates() EXCLUSIVE_LOCKS_REQUIRED(const CBlockIndex * FindForkInGlobalIndex(const CBlockLocator &locator) const EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Populate the candidate set by calling TryAddBlockIndexCandidate on all valid block indices.
Definition: validation.cpp:129
void InvalidChainFound(CBlockIndex *pindexNew) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Chainstate(CTxMemPool *mempool, node::BlockManager &blockman, ChainstateManager &chainman, std::optional< uint256 > from_snapshot_blockhash=std::nullopt)
RecursiveMutex * MempoolMutex() const LOCK_RETURNED(m_mempool -> cs)
Indirection necessary to make lock annotations work with an optional mempool.
Definition: validation.h:847
fs::path StoragePath() const
Return path to chainstate leveldb directory.
bool NeedsRedownload() const EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Whether the chain state needs to be redownloaded due to lack of witness data.
Interface for managing multiple Chainstate objects, where each chainstate is associated with chainsta...
Definition: validation.h:945
util::Result< void > PopulateAndValidateSnapshot(Chainstate &snapshot_chainstate, AutoFile &coins_file, const node::SnapshotMetadata &metadata)
Internal helper for ActivateSnapshot().
Chainstate * HistoricalChainstate() const EXCLUSIVE_LOCKS_REQUIRED(GetMutex())
Return historical chainstate targeting a specific block, if any.
Definition: validation.h:1136
const uint256 & AssumedValidBlock() const
Definition: validation.h:1016
ValidationCache m_validation_cache
Definition: validation.h:1045
double GetBackgroundVerificationProgress(const CBlockIndex &pindex) const EXCLUSIVE_LOCKS_REQUIRED(GetMutex())
Guess background verification progress in case assume-utxo was used (as a fraction between 0....
double GuessVerificationProgress(const CBlockIndex *pindex) const EXCLUSIVE_LOCKS_REQUIRED(GetMutex())
Guess verification progress (as a fraction between 0.0=genesis and 1.0=current tip).
bool IsInitialBlockDownload() const noexcept
Check whether we are doing an initial block download (synchronizing from disk or network)
size_t m_total_coinstip_cache
The total number of bytes available for us to use across all in-memory coins caches.
Definition: validation.h:1087
MempoolAcceptResult ProcessTransaction(const CTransactionRef &tx, bool test_accept=false) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Try to add a transaction to the memory pool.
std::unique_ptr< Chainstate > RemoveChainstate(Chainstate &chainstate) EXCLUSIVE_LOCKS_REQUIRED(GetMutex())
Remove a chainstate.
Definition: validation.h:1156
kernel::Notifications & GetNotifications() const
Definition: validation.h:1017
void ReceivedBlockTransactions(const CBlock &block, CBlockIndex *pindexNew, const FlatFilePos &pos) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Mark a block as having its data received and checked (up to BLOCK_VALID_TRANSACTIONS).
bool ShouldCheckBlockIndex() const
RecursiveMutex & GetMutex() const LOCK_RETURNED(
Alias for cs_main.
Definition: validation.h:1037
CBlockIndex * ActiveTip() const EXCLUSIVE_LOCKS_REQUIRED(GetMutex())
Definition: validation.h:1175
Chainstate & ActiveChainstate() const
Alternatives to CurrentChainstate() used by older code to query latest chainstate information without...
SnapshotCompletionResult MaybeValidateSnapshot(Chainstate &validated_cs, Chainstate &unvalidated_cs) EXCLUSIVE_LOCKS_REQUIRED(Chainstate & CurrentChainstate() const EXCLUSIVE_LOCKS_REQUIRED(GetMutex())
Try to validate an assumeutxo snapshot by using a validated historical chainstate targeted at the sna...
Definition: validation.h:1127
bool ProcessNewBlock(const std::shared_ptr< const CBlock > &block, bool force_processing, bool min_pow_checked, bool *new_block) LOCKS_EXCLUDED(cs_main)
Process an incoming block.
size_t m_total_coinsdb_cache
The total number of bytes available for us to use across all leveldb coins databases.
Definition: validation.h:1091
void CheckBlockIndex() const
Make various assertions about the state of the block index.
const util::SignalInterrupt & m_interrupt
Definition: validation.h:1039
void LoadExternalBlockFile(AutoFile &file_in, FlatFilePos *dbp=nullptr, std::multimap< uint256, FlatFilePos > *blocks_with_unknown_parent=nullptr)
Import blocks from an external file.
int ActiveHeight() const EXCLUSIVE_LOCKS_REQUIRED(GetMutex())
Definition: validation.h:1174
VersionBitsCache m_versionbitscache
Track versionbit status.
Definition: validation.h:1200
std::function< void()> snapshot_download_completed
Function to restart active indexes; set dynamically to avoid a circular dependency on base/index....
Definition: validation.h:1010
const CChainParams & GetParams() const
Definition: validation.h:1012
void GenerateCoinbaseCommitment(CBlock &block, const CBlockIndex *pindexPrev) const
Produce the necessary coinbase commitment for a block (modifies the hash, don't call for mined blocks...
bool ProcessNewBlockHeaders(std::span< const CBlockHeader > headers, bool min_pow_checked, BlockValidationState &state, const CBlockIndex **ppindex=nullptr) LOCKS_EXCLUDED(cs_main)
Process incoming block headers.
const Consensus::Params & GetConsensus() const
Definition: validation.h:1013
ChainstateManager(const util::SignalInterrupt &interrupt, Options options, node::BlockManager::Options blockman_options)
const arith_uint256 & MinimumChainWork() const
Definition: validation.h:1015
void UpdateIBDStatus() EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Update and possibly latch the IBD status.
bool LoadGenesisBlock()
Ensures a genesis block is in the block tree, possibly writing one to disk.
const Options m_options
Definition: validation.h:1040
bool LoadBlockIndex() EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Load the block tree and coins database from disk, initializing state if we're running with -reindex.
Chainstate &InitializeChainstate(CTxMemPool *mempool) EXCLUSIVE_LOCKS_REQUIRED(util::Result< CBlockIndex * ActivateSnapshot)(AutoFile &coins_file, const node::SnapshotMetadata &metadata, bool in_memory)
Instantiate a new chainstate.
Definition: validation.h:1113
CChain & ActiveChain() const EXCLUSIVE_LOCKS_REQUIRED(GetMutex())
Definition: validation.h:1173
bool AcceptBlockHeader(const CBlockHeader &block, BlockValidationState &state, CBlockIndex **ppindex, bool min_pow_checked) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
If a block header hasn't already been seen, call CheckBlockHeader on it, ensure that it doesn't desce...
arith_uint256 nLastPreciousChainwork
chainwork for the last block that preciousblock has been applied to.
Definition: validation.h:1067
void ReportHeadersPresync(int64_t height, int64_t timestamp)
This is used by net_processing to report pre-synchronization progress of headers, as headers are not ...
std::atomic_bool m_cached_is_ibd
Whether initial block download (IBD) is ongoing.
Definition: validation.h:1054
bool NotifyHeaderTip() LOCKS_EXCLUDED(GetMutex())
void MaybeRebalanceCaches() EXCLUSIVE_LOCKS_REQUIRED(void UpdateUncommittedBlockStructures(CBlock &block, const CBlockIndex *pindexPrev) const
Check to see if caches are out of balance and if so, call ResizeCoinsCaches() as needed.
Chainstate *LoadAssumeutxoChainstate() EXCLUSIVE_LOCKS_REQUIRED(Chainstate &AddChainstate(std::unique_ptr< Chainstate > chainstate) EXCLUSIVE_LOCKS_REQUIRED(void ResetChainstates() EXCLUSIVE_LOCKS_REQUIRED(bool DeleteChainstate(Chainstate &chainstate) EXCLUSIVE_LOCKS_REQUIRED(bool ValidatedSnapshotCleanup(Chainstate &validated_cs, Chainstate &unvalidated_cs) EXCLUSIVE_LOCKS_REQUIRED(std::optional< std::pair< const CBlockIndex *, const CBlockIndex * > > GetHistoricalBlockRange() const EXCLUSIVE_LOCKS_REQUIRED(util::Result< void > ActivateBestChains() LOCKS_EXCLUDED(void RecalculateBestHeader() EXCLUSIVE_LOCKS_REQUIRED(std::optional< int > BlocksAheadOfTip() const LOCKS_EXCLUDED(CCheckQueue< CScriptCheck > & GetCheckQueue()
When starting up, search the datadir for a chainstate based on a UTXO snapshot that is in the process...
Definition: validation.h:1380
int32_t nBlockReverseSequenceId
Decreasing counter (used by subsequent preciousblock calls).
Definition: validation.h:1065
node::BlockManager m_blockman
A single BlockManager instance is shared across each constructed chainstate to avoid duplicating bloc...
Definition: validation.h:1043
bool AcceptBlock(const std::shared_ptr< const CBlock > &pblock, BlockValidationState &state, CBlockIndex **ppindex, bool fRequested, const FlatFilePos *dbp, bool *fNewBlock, bool min_pow_checked) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Sufficiently validate a block for disk storage (and store on disk).
A UTXO entry.
Definition: coins.h:46
bool IsCoinBase() const
Definition: coins.h:70
CTxOut out
unspent transaction output
Definition: coins.h:49
bool IsSpent() const
Either this coin never existed (see e.g.
Definition: coins.h:94
bool fCoinBase
whether containing transaction was a coinbase
Definition: coins.h:52
uint32_t nHeight
at which height this containing transaction was included in the active block chain
Definition: coins.h:55
Noop coins view.
Definition: coins.h:392
static CoinsViewEmpty & Get()
Definition: coins.cpp:29
CCoinsViewCache subclass that asynchronously fetches most block input prevouts in parallel during Con...
Definition: coins.h:653
CoinsViews(DBParams db_params, CoinsViewOptions options)
This constructor initializes CCoinsViewDB and CCoinsViewErrorCatcher instances, but it does not creat...
std::pair< uint32_t, size_t > setup_bytes(size_t bytes)
setup_bytes is a convenience function which accounts for internal memory usage when deciding how many...
Definition: cuckoocache.h:365
void insert(Element e)
insert loops at most depth_limit times trying to insert a hash at various locations in the table via ...
Definition: cuckoocache.h:398
bool contains(const Element &e, const bool erase) const
contains iterates through the hash locations for a given element and checks to see if it is present.
Definition: cuckoocache.h:475
DisconnectedBlockTransactions.
std::list< CTransactionRef > take()
Clear all data structures and return the list of transactions.
void removeForBlock(const std::vector< CTransactionRef > &vtx)
Remove any entries that are in this block.
std::vector< CTransactionRef > AddTransactionsFromBlock(const std::vector< CTransactionRef > &vtx)
Add transactions from the block, iterating through vtx in reverse order.
Fast randomness source.
Definition: random.h:386
Tp rand_uniform_delay(const Tp &time, typename Tp::duration range) noexcept
Return the time point advanced by a uniform random duration.
Definition: random.h:329
I randrange(I range) noexcept
Generate a random integer in the range [0..range), with range > 0.
Definition: random.h:254
Convenience class for initializing and passing the script execution cache and signature cache.
Definition: validation.h:374
ValidationCache(size_t script_execution_cache_bytes, size_t signature_cache_bytes)
CuckooCache::cache< uint256, SignatureCacheHasher > m_script_execution_cache
Definition: validation.h:380
CSHA256 ScriptExecutionCacheHasher() const
Return a copy of the pre-initialized hasher.
Definition: validation.h:389
CSHA256 m_script_execution_cache_hasher
Pre-initialized hasher to avoid having to recreate it for every hash calculation.
Definition: validation.h:377
SignatureCache m_signature_cache
Definition: validation.h:381
void BlockConnected(const kernel::ChainstateRole &, std::shared_ptr< const CBlock >, const CBlockIndex *pindex)
void BlockChecked(const std::shared_ptr< const CBlock > &, const BlockValidationState &)
void ChainStateFlushed(const kernel::ChainstateRole &, const CBlockLocator &)
void NewPoWValidBlock(const CBlockIndex *, const std::shared_ptr< const CBlock > &)
void UpdatedBlockTip(const CBlockIndex *, const CBlockIndex *, bool fInitialDownload)
void ActiveTipChange(const CBlockIndex &, bool)
void MempoolTransactionsRemovedForBlock(std::shared_ptr< const CBlock >, std::vector< RemovedMempoolTransactionInfo >, unsigned int block_height)
void BlockDisconnected(std::shared_ptr< const CBlock >, const CBlockIndex *pindex)
bool IsValid() const
Definition: validation.h:113
std::string GetRejectReason() const
Definition: validation.h:117
std::string GetDebugMessage() const
Definition: validation.h:118
bool Error(const std::string &reject_reason)
Definition: validation.h:106
bool Invalid(Result result, const std::string &reject_reason="", const std::string &debug_message="")
Definition: validation.h:96
bool IsError() const
Definition: validation.h:115
Result GetResult() const
Definition: validation.h:116
std::string ToString() const
Definition: validation.h:119
bool IsInvalid() const
Definition: validation.h:114
std::vector< std::pair< int, bool > > CheckUnknownActivations(const CBlockIndex *pindex, const CChainParams &chainparams) EXCLUSIVE_LOCKS_REQUIRED(!m_mutex)
Check for unknown activations Returns a vector containing the bit number used for signalling and a bo...
void Clear() EXCLUSIVE_LOCKS_REQUIRED(!m_mutex)
256-bit unsigned big integer.
constexpr bool IsNull() const
Definition: uint256.h:50
std::string ToString() const
Definition: uint256.cpp:21
constexpr unsigned char * begin()
Definition: uint256.h:101
double getdouble() const
A base class defining functions for notifying about certain kernel events.
virtual void headerTip(SynchronizationState state, int64_t height, int64_t timestamp, bool presync)
virtual void fatalError(const bilingual_str &message)
The fatal error notification is sent to notify the user when an error occurs in kernel code that can'...
virtual void warningSet(Warning id, const bilingual_str &message)
virtual void progress(const bilingual_str &title, int progress_percent, bool resume_possible)
virtual InterruptResult blockTip(SynchronizationState state, const CBlockIndex &index, double verification_progress)
virtual void warningUnset(Warning id)
Maintains a tree of blocks (stored in m_block_index) which is consulted to determine where the most-w...
Definition: blockstorage.h:196
const kernel::BlockManagerOpts m_opts
Definition: blockstorage.h:304
void FindFilesToPrune(std::set< int > &setFilesToPrune, int last_prune, const Chainstate &chain, ChainstateManager &chainman)
Prune block and undo files (blk???.dat and rev???.dat) so that the disk space used is less than a use...
CBlockIndex * LookupBlockIndex(const uint256 &hash) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
bool ReadBlockUndo(CBlockUndo &blockundo, const CBlockIndex &index) const
CBlockFileInfo *GetBlockFileInfo(size_t n) EXCLUSIVE_LOCKS_REQUIRED(bool WriteBlockUndo(const CBlockUndo &blockundo, BlockValidationState &state, CBlockIndex &block) EXCLUSIVE_LOCKS_REQUIRED(FlatFilePos WriteBlock(const CBlock &block, int nHeight) EXCLUSIVE_LOCKS_REQUIRED(void UpdateBlockInfo(const CBlock &block, unsigned int nHeight, const FlatFilePos &pos) EXCLUSIVE_LOCKS_REQUIRED(bool IsPruneMode() const
Get block file info entry for one block file.
Definition: blockstorage.h:407
std::atomic_bool m_blockfiles_indexed
Whether all blockfiles have been added to the block tree database.
Definition: blockstorage.h:333
std::vector< CBlockIndex * > GetAllBlockIndices() EXCLUSIVE_LOCKS_REQUIRED(std::multimap< CBlockIndex *, CBlockIndex * > m_blocks_unlinked
All pairs A->B, where A (or one of its ancestors) misses transactions, but B has transactions.
Definition: blockstorage.h:351
std::set< CBlockIndex * > m_dirty_blockindex
Dirty block index entries.
Definition: blockstorage.h:313
bool LoadingBlocks() const
Definition: blockstorage.h:413
void UnlinkPrunedFiles(const std::set< int > &setFilesToPrune) const
Actually unlink the specified files.
void WriteBlockIndexDB() EXCLUSIVE_LOCKS_REQUIRED(bool LoadBlockIndexDB(const std::optional< uint256 > &snapshot_blockhash) EXCLUSIVE_LOCKS_REQUIRED(void ScanAndUnlinkAlreadyPrunedFiles() EXCLUSIVE_LOCKS_REQUIRED(CBlockIndex * AddToBlockIndex(const CBlockHeader &block, CBlockIndex *&best_header) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Remove any pruned block & undo files that are still on disk.
Definition: blockstorage.h:372
void AddUnlinkedBlock(CBlockIndex *block) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
bool ReadBlock(CBlock &block, const FlatFilePos &pos, const std::optional< uint256 > &expected_hash) const
Functions for disk access for blocks.
bool m_check_for_pruning
Global flag to indicate we should check to see if there are block/undo files that should be deleted.
Definition: blockstorage.h:288
void FindFilesToPruneManual(std::set< int > &setFilesToPrune, int nManualPruneHeight, const Chainstate &chain)
std::optional< int > m_snapshot_height
The height of the base block of an assumeutxo snapshot, if one is in use.
Definition: blockstorage.h:349
uint64_t CalculateCurrentUsage() EXCLUSIVE_LOCKS_REQUIRED(bool CheckBlockDataAvailability(const CBlockIndex &upper_block, const CBlockIndex &lower_block, BlockStatus block_status=BLOCK_HAVE_DATA) EXCLUSIVE_LOCKS_REQUIRED(const CBlockIndex &GetFirstBlock(const CBlockIndex &upper_block LIFETIMEBOUND, uint32_t status_mask, const CBlockIndex *lower_block LIFETIMEBOUND=nullptr) const EXCLUSIVE_LOCKS_REQUIRED(boo m_have_pruned)
Calculate the amount of disk space the block & undo files currently use.
Definition: blockstorage.h:453
Metadata describing a serialized version of a UTXO set from which an assumeutxo Chainstate can be con...
Definition: utxo_snapshot.h:38
uint256 m_base_blockhash
The hash of the block that reflects the tip of the chain for the UTXO set contained in this snapshot.
Definition: utxo_snapshot.h:45
uint64_t m_coins_count
The number of coins in the UTXO set contained in this snapshot.
Definition: utxo_snapshot.h:50
std::string ToString() const
constexpr const std::byte * begin() const
const uint256 & ToUint256() const LIFETIMEBOUND
std::string GetHex() const
256-bit opaque blob.
Definition: uint256.h:196
Helper class that manages an interrupt flag, and allows a thread or signal to interrupt another threa...
std::string FormatFullVersion()
const Coin & AccessByTxid(const CCoinsViewCache &view, const Txid &txid)
Utility function to find any unspent output with a given txid.
Definition: coins.cpp:417
void AddCoins(CCoinsViewCache &cache, const CTransaction &tx, int nHeight, bool check_for_overwrite)
Utility function to add all of a transaction's outputs to a cache.
Definition: coins.cpp:133
static const PrecomputedData data
Precomputed COutPoint and CCoins values.
auto flush
Flush changes in top cache to the one below.
uint256 BlockMerkleRoot(const CBlock &block, bool *mutated)
Definition: merkle.cpp:77
uint256 BlockWitnessMerkleRoot(const CBlock &block)
Definition: merkle.cpp:87
constexpr int NO_WITNESS_COMMITMENT
Index marker for when no witness commitment is present in a coinbase transaction.
Definition: validation.h:23
constexpr size_t MINIMUM_WITNESS_COMMITMENT
Minimum size of a witness commitment structure.
Definition: validation.h:26
static int64_t GetBlockWeight(const CBlock &block)
Definition: validation.h:144
@ BLOCK_HEADER_LOW_WORK
the block header may be on a too-little-work chain
@ BLOCK_INVALID_HEADER
invalid proof of work or time too old
@ BLOCK_CACHED_INVALID
this block was cached as being invalid and we didn't store the reason why
@ BLOCK_CONSENSUS
invalid by consensus rules (excluding any below reasons)
@ BLOCK_MISSING_PREV
We don't have the previous block the checked one is built on.
@ BLOCK_INVALID_PREV
A block this one builds on is invalid.
@ BLOCK_MUTATED
the block's data didn't match the data committed to by the PoW
@ BLOCK_TIME_FUTURE
block timestamp was > 2 hours in the future (or our clock is bad)
int GetWitnessCommitmentIndex(const CBlock &block)
Compute at which vout of the block's coinbase transaction the witness commitment occurs,...
Definition: validation.h:155
@ TX_MISSING_INPUTS
transaction was missing some of its inputs
@ TX_MEMPOOL_POLICY
violated mempool's fee/size/descendant/RBF/etc limits
@ TX_PREMATURE_SPEND
transaction spends a coinbase too early, or violates locktime/sequence locks
@ TX_WITNESS_STRIPPED
Transaction is missing a witness.
@ TX_CONFLICT
Tx already in mempool or conflicts with a tx in the chain (if it conflicts with another tx in mempool...
@ TX_NOT_STANDARD
otherwise didn't meet our local policy rules
@ TX_WITNESS_MUTATED
Transaction might have a witness prior to SegWit activation, or witness may have been malleated (whic...
@ TX_NO_MEMPOOL
this node does not have a mempool so can't validate the transaction
@ TX_CONSENSUS
invalid by consensus rules
@ TX_RECONSIDERABLE
fails some policy, but might be acceptable if submitted in a (different) package
constexpr unsigned int LOCKTIME_VERIFY_SEQUENCE
Flags for nSequence and nLockTime locks.
Definition: consensus.h:28
constexpr int64_t MAX_BLOCK_SIGOPS_COST
The maximum allowed number of signature check operations in a block (network rule)
Definition: consensus.h:17
constexpr int64_t MAX_TIMEWARP
Maximum number of seconds that the timestamp of the first block of a difficulty adjustment period is ...
Definition: consensus.h:35
constexpr unsigned int MAX_BLOCK_SERIALIZED_SIZE
The maximum allowed size for a serialized block, in bytes (only for buffer size limits)
Definition: consensus.h:13
constexpr int COINBASE_MATURITY
Coinbase transaction outputs can only be spent after this number of new blocks (network rule)
Definition: consensus.h:19
constexpr unsigned int MAX_BLOCK_WEIGHT
The maximum allowed weight for a block, see BIP 141 (network rule)
Definition: consensus.h:15
constexpr int WITNESS_SCALE_FACTOR
Definition: consensus.h:21
RecursiveMutex cs_main
Mutex to guard access to validation specific variables, such as reading or changing the chainstate.
Definition: cs_main.cpp:8
bool DestroyDB(const std::string &path_str)
Definition: dbwrapper.cpp:39
bool DeploymentActiveAfter(const CBlockIndex *pindexPrev, const Consensus::Params &params, Consensus::BuriedDeployment dep, VersionBitsCache &versionbitscache)
Determine if a deployment is active for the next block.
bool DeploymentActiveAt(const CBlockIndex &index, const Consensus::Params &params, Consensus::BuriedDeployment dep, VersionBitsCache &versionbitscache)
Determine if a deployment is active for this block.
constexpr unsigned int MAX_DISCONNECTED_TX_POOL_BYTES
Maximum bytes for transactions to store for processing during reorg.
bool CheckEphemeralSpends(const Package &package, CFeeRate dust_relay_rate, const CTxMemPool &tx_pool, TxValidationState &out_child_state, Wtxid &out_child_wtxid)
Called for each transaction(package) if any dust is in the package.
bool PreCheckEphemeralTx(const CTransaction &tx, CFeeRate dust_relay_rate, CAmount base_fee, CAmount mod_fee, TxValidationState &state)
These utility functions ensure that ephemeral dust is safely created and spent without unduly risking...
volatile double sum
Definition: examples.cpp:10
static bool exists(const path &p)
Definition: fs.h:96
static std::string PathToString(const path &path)
Convert path object to a byte string.
Definition: fs.h:162
bool CheckDiskSpace(const fs::path &dir, uint64_t additional_bytes)
Definition: fs_helpers.cpp:93
HTTPHeaders headers
bool VerifyScript(const CScript &scriptSig, const CScript &scriptPubKey, const CScriptWitness *witness, script_verify_flags flags, const BaseSignatureChecker &checker, ScriptError *serror)
is a home for simple enum and struct type definitions that can be used internally by functions in the...
#define LogWarning(...)
Definition: log.h:126
#define LogInfo(...)
Definition: log.h:125
#define LogError(...)
Definition: log.h:127
#define LogDebug(category,...)
Definition: log.h:143
unsigned int nHeight
LockPoints lp
@ REORG
Removed for reorganization.
std::array< uint8_t, 4 > MessageStartChars
BlockValidationState m_state
Definition: miner.cpp:373
uint256 m_hash
Definition: miner.cpp:371
unsigned int nonce
@ COINDB
Definition: categories.h:33
@ REINDEX
Definition: categories.h:27
@ TXPACKAGES
Definition: categories.h:45
@ ALL
Definition: categories.h:48
@ VALIDATION
Definition: categories.h:36
@ PRUNE
Definition: categories.h:30
@ MEMPOOL
Definition: categories.h:18
@ BENCH
Definition: categories.h:20
bool CheckTxInputs(const CTransaction &tx, TxValidationState &state, const CCoinsViewCache &inputs, int nSpendHeight, CAmount &txfee)
Check whether all inputs of this transaction are valid (no double spends and amounts) This does not m...
Definition: tx_verify.cpp:170
@ DEPLOYMENT_DERSIG
Definition: params.h:30
@ DEPLOYMENT_CSV
Definition: params.h:31
@ DEPLOYMENT_SEGWIT
Definition: params.h:34
@ DEPLOYMENT_HEIGHTINCB
Definition: params.h:28
@ DEPLOYMENT_CLTV
Definition: params.h:29
T check(T ptr)
std::function< FILE *(const fs::path &, const char *)> FopenFn
Definition: fs.h:197
Definition: basic.cpp:8
static std::optional< CCoinsStats > ComputeUTXOStats(T hash_obj, const CCoinsViewDB &view, node::BlockManager &blockman, const std::function< void()> &interruption_point)
Calculate statistics about the unspent transaction output set.
Definition: coinstats.cpp:112
bool IsInterrupted(const T &result)
CoinStatsHashType
Definition: coinstats.h:26
const fs::path SNAPSHOT_BLOCKHASH_FILENAME
The file in the snapshot chainstate dir which stores the base blockhash.
bool WriteSnapshotBaseBlockhash(Chainstate &snapshot_chainstate)
std::optional< fs::path > FindAssumeutxoChainstateDir(const fs::path &data_dir)
Return a path to the snapshot-based chainstate dir, if one exists.
bool WriteSnapshotBaseBlockhash(Chainstate &snapshot_chainstate) EXCLUSIVE_LOCKS_REQUIRED(std::optional< uint256 > ReadSnapshotBaseBlockhash(fs::path chaindir) EXCLUSIVE_LOCKS_REQUIRED(constexpr std::string_view SNAPSHOT_CHAINSTATE_SUFFIX
Write out the blockhash of the snapshot base block that was used to construct this chainstate.
std::unordered_map< uint256, CBlockIndex, BlockHasher > BlockMap
Definition: blockstorage.h:138
std::optional< uint256 > ReadSnapshotBaseBlockhash(fs::path chaindir)
constexpr NoRateLimitTag NO_RATE_LIMIT
Definition: log.h:50
bilingual_str ErrorString(const Result< T > &result)
Definition: result.h:93
std::string ToString(const T &t)
Locale-independent version of std::to_string.
Definition: string.h:249
auto Join(const C &container, const S &separator, UnaryOp unary_op)
Join all container items.
Definition: string.h:208
static feebumper::Result CheckFeeRate(const CWallet &wallet, const CMutableTransaction &mtx, const CFeeRate &newFeerate, const int64_t maxTxSize, CAmount old_fee, std::vector< bilingual_str > &errors)
Check if the user provided a valid feeRate.
Definition: feebumper.cpp:61
std::shared_ptr< Chain::Notifications > m_notifications
Definition: interfaces.cpp:498
bool IsChildWithParents(const Package &package)
Context-free check that a package is exactly one child and its parents; not all parents need to be pr...
Definition: packages.cpp:119
bool IsWellFormedPackage(const Package &txns, PackageValidationState &state)
Context-free package policy checks:
Definition: packages.cpp:79
uint256 GetPackageHash(const std::vector< CTransactionRef > &transactions)
Get the hash of the concatenated wtxids of transactions, with wtxids treated as a little-endian numbe...
Definition: packages.cpp:151
std::vector< CTransactionRef > Package
A package is an ordered list of transactions.
Definition: packages.h:45
@ PCKG_POLICY
The package itself is invalid (e.g. too many transactions).
@ PCKG_MEMPOOL_ERROR
Mempool logic error.
@ PCKG_TX
At least one tx is invalid.
std::optional< std::pair< DiagramCheckError, std::string > > ImprovesFeerateDiagram(CTxMemPool::ChangeSet &changeset)
The replacement transaction must improve the feerate diagram of the mempool.
Definition: rbf.cpp:127
std::optional< std::string > PaysForRBF(CAmount original_fees, CAmount replacement_fees, size_t replacement_vsize, CFeeRate relay_fee, const Txid &txid)
The replacement transaction must pay more fees than the original transactions.
Definition: rbf.cpp:100
std::optional< std::string > EntriesAndTxidsDisjoint(const CTxMemPool::setEntries &ancestors, const std::set< Txid > &direct_conflicts, const Txid &txid)
Check the intersection between two sets of transactions (a set of mempool entries and a set of txids)...
Definition: rbf.cpp:85
std::optional< std::string > GetEntriesForConflicts(const CTransaction &tx, CTxMemPool &pool, const CTxMemPool::setEntries &iters_conflicting, CTxMemPool::setEntries &all_conflicts)
Get all descendants of iters_conflicting.
Definition: rbf.cpp:58
@ FAILURE
New diagram wasn't strictly superior
TxValidationState ValidateInputsStandardness(const CTransaction &tx, const CCoinsViewCache &mapInputs)
Check transaction inputs.
Definition: policy.cpp:214
bool SpendsNonAnchorWitnessProg(const CTransaction &tx, const CCoinsViewCache &prevouts)
Check whether this transaction spends any witness program but P2A, including not-yet-defined ones.
Definition: policy.cpp:354
bool IsWitnessStandard(const CTransaction &tx, const CCoinsViewCache &mapInputs)
Check if the transaction is over standard P2WSH resources limit: 3600bytes witnessScript size,...
Definition: policy.cpp:265
bool IsStandardTx(const CTransaction &tx, const std::optional< unsigned > &max_datacarrier_bytes, bool permit_bare_multisig, const CFeeRate &dust_relay_fee, std::string &reason)
Check for standard transaction types.
Definition: policy.cpp:100
constexpr script_verify_flags STANDARD_SCRIPT_VERIFY_FLAGS
Standard script verification flags that standard transactions will comply with.
Definition: policy.h:118
constexpr unsigned int STANDARD_LOCKTIME_VERIFY_FLAGS
Used as the flags parameter to sequence and nLocktime checks in non-consensus code.
Definition: policy.h:137
constexpr unsigned int MAX_STANDARD_TX_SIGOPS_COST
The maximum number of sigops we're willing to relay/mine in a single tx.
Definition: policy.h:44
constexpr unsigned int MIN_STANDARD_TX_NONWITNESS_SIZE
The minimum non-witness size for transactions we're willing to relay/mine: one larger than 64
Definition: policy.h:40
constexpr script_verify_flags STANDARD_NOT_MANDATORY_VERIFY_FLAGS
For convenience, standard but not mandatory verify flags.
Definition: policy.h:134
unsigned int GetNextWorkRequired(const CBlockIndex *pindexLast, const CBlockHeader *pblock, const Consensus::Params &params)
Definition: pow.cpp:14
bool CheckProofOfWork(uint256 hash, unsigned int nBits, const Consensus::Params &params)
Check whether a block hash satisfies the proof-of-work requirement specified by nBits.
Definition: pow.cpp:140
constexpr TransactionSerParams TX_NO_WITNESS
Definition: transaction.h:181
constexpr TransactionSerParams TX_WITH_WITNESS
Definition: transaction.h:180
static CTransactionRef MakeTransactionRef(Tx &&txIn)
Definition: transaction.h:404
std::shared_ptr< const CTransaction > CTransactionRef
Definition: transaction.h:403
uint256 GetRandHash() noexcept
Generate a random uint256.
Definition: random.h:463
const char * prefix
Definition: rest.cpp:1179
@ OP_RETURN
Definition: script.h:112
std::string ScriptErrorString(const ScriptError serror)
enum ScriptError_t ScriptError
@ SCRIPT_ERR_UNKNOWN_ERROR
Definition: script_error.h:14
uint64_t ReadCompactSize(Stream &is, bool range_check=true)
Decode a CompactSize-encoded variable-length integer.
Definition: serialize.h:333
uint64_t GetSerializeSize(const T &t)
Definition: serialize.h:1157
bool CheckSignetBlockSolution(const CBlock &block, const Consensus::Params &consensusParams)
Extract signature and check whether a block has a valid solution.
Definition: signet.cpp:126
unsigned char * UCharCast(char *c)
Definition: span.h:95
Holds configuration for use during UTXO snapshot load and validation.
Definition: chainparams.h:34
AssumeutxoHash hash_serialized
The expected hash of the deserialized UTXO set.
Definition: chainparams.h:38
uint64_t m_chain_tx_count
Used to populate the m_chain_tx_count value, which is used during BlockManager::LoadBlockIndex().
Definition: chainparams.h:44
Describes a place in the block chain to another node such that if the other node doesn't have the sam...
Definition: block.h:117
std::vector< uint256 > vHave
Definition: block.h:127
A mutable version of CTransaction.
Definition: transaction.h:358
std::vector< CTxOut > vout
Definition: transaction.h:360
std::vector< CTxIn > vin
Definition: transaction.h:359
Holds various statistics on transactions within a chain.
Definition: chainparams.h:57
User-controlled performance and debug options.
Definition: txdb.h:28
std::shared_ptr< const CBlock > pblock
const CBlockIndex * pindex
Parameters that influence chain consensus.
Definition: params.h:88
bool enforce_BIP94
Enforce BIP94 timewarp attack mitigation.
Definition: params.h:122
int64_t DifficultyAdjustmentInterval() const
Definition: params.h:130
bool signet_blocks
If true, witness commitments contain a payload equal to a Bitcoin Script solution to the signet chall...
Definition: params.h:140
int nSubsidyHalvingInterval
Definition: params.h:90
std::map< uint256, script_verify_flags > script_flag_exceptions
Hashes of blocks that.
Definition: params.h:97
int64_t nPowTargetSpacing
Definition: params.h:124
std::chrono::seconds PowTargetSpacing() const
Definition: params.h:126
Application-specific storage settings.
Definition: dbwrapper.h:41
fs::path path
Location in the filesystem where leveldb data will be stored.
Definition: dbwrapper.h:43
Data structure storing a fee and size.
Definition: feefrac.h:22
uint32_t nPos
Definition: flatfile.h:17
bool IsNull() const
Definition: flatfile.h:32
int32_t nFile
Definition: flatfile.h:16
int64_t time
Definition: mempool_entry.h:31
Validation result for a transaction evaluated by MemPoolAccept (single or package).
Definition: validation.h:134
const ResultType m_result_type
Result type.
Definition: validation.h:143
const TxValidationState m_state
Contains information about why the transaction failed.
Definition: validation.h:146
@ INVALID
‍Fully validated, valid.
static MempoolAcceptResult Failure(TxValidationState state)
Definition: validation.h:170
static MempoolAcceptResult FeeFailure(TxValidationState state, CFeeRate effective_feerate, const std::vector< Wtxid > &wtxids_fee_calculations)
Definition: validation.h:174
static MempoolAcceptResult MempoolTxDifferentWitness(const Wtxid &other_wtxid)
Definition: validation.h:193
static MempoolAcceptResult MempoolTx(int64_t vsize, CAmount fees)
Definition: validation.h:189
static MempoolAcceptResult Success(std::list< CTransactionRef > &&replaced_txns, int64_t vsize, CAmount fees, CFeeRate effective_feerate, const std::vector< Wtxid > &wtxids_fee_calculations)
Definition: validation.h:180
static time_point now() noexcept
Return current system time or mocked time, if set.
Definition: time.cpp:64
static time_point now() noexcept
Return current system time or mocked time, if set.
Definition: time.cpp:38
Validation result for package mempool acceptance.
Definition: validation.h:240
void Init(const T &tx, std::vector< CTxOut > &&spent_outputs, bool force=false)
Initialize this PrecomputedTransactionData with transaction data.
bool m_spent_outputs_ready
Whether m_spent_outputs is initialized.
Definition: interpreter.h:183
std::vector< CTxOut > m_spent_outputs
Definition: interpreter.h:181
const char * what() const noexcept override
Bilingual messages:
Definition: translation.h:24
std::string original
Definition: translation.h:25
An options struct for BlockManager, more ergonomically referred to as BlockManager::Options due to th...
An options struct for ChainstateManager, more ergonomically referred to as ChainstateManager::Options...
std::optional< int32_t > check_block_index
std::chrono::seconds max_tip_age
If the tip is older than this, the node is considered to be in initial block download.
int32_t prevoutfetch_threads_num
Number of worker threads used for prefetching block input prevouts. Zero means no parallel fetching.
Information about chainstate that notifications are sent from.
Definition: types.h:18
bool validated
Whether this is a notification from a chainstate that's been fully validated starting from the genesi...
Definition: types.h:22
#define AssertLockNotHeld(cs)
Definition: sync.h:149
#define LOCK(cs)
Definition: sync.h:268
#define WITH_LOCK(cs, code)
Run code while locking a mutex.
Definition: sync.h:299
CDBWrapper db
Definition: dbwrapper.cpp:371
#define EXCLUSIVE_LOCKS_REQUIRED(...)
Definition: threadsafety.h:49
#define LOCKS_EXCLUDED(...)
Definition: threadsafety.h:48
#define LOG_TIME_MILLIS_WITH_CATEGORY(end_msg, log_category)
Definition: timer.h:103
#define LOG_TIME_MILLIS_WITH_CATEGORY_MSG_ONCE(end_msg, log_category)
Definition: timer.h:105
#define strprintf
Format arguments and return the string or write to given std::ostream (see tinyformat::format doc for...
Definition: tinyformat.h:1172
#define TRACEPOINT(context,...)
Definition: trace.h:56
consteval auto _(util::TranslatedLiteral str)
Definition: translation.h:79
bilingual_str Untranslated(std::string original)
Mark a bilingual_str as untranslated.
Definition: translation.h:82
std::optional< std::pair< std::string, CTransactionRef > > SingleTRUCChecks(const CTxMemPool &pool, const CTransactionRef &ptx, const std::vector< CTxMemPoolEntry::CTxMemPoolEntryRef > &mempool_parents, const std::set< Txid > &direct_conflicts, int64_t vsize)
Must be called for every transaction, even if not TRUC.
std::optional< std::string > PackageTRUCChecks(const CTxMemPool &pool, const CTransactionRef &ptx, int64_t vsize, const Package &package, const std::vector< CTxMemPoolEntry::CTxMemPoolEntryRef > &mempool_parents)
Must be called for every transaction that is submitted within a package, even if not TRUC.
Definition: truc_policy.cpp:57
bool CheckTransaction(const CTransaction &tx, TxValidationState &state)
Definition: tx_check.cpp:19
bool EvaluateSequenceLocks(const CBlockIndex &block, std::pair< int, int64_t > lockPair)
Definition: tx_verify.cpp:103
std::pair< int, int64_t > CalculateSequenceLocks(const CTransaction &tx, int flags, std::vector< int > &prevHeights, const CBlockIndex &block)
Calculates the block height and previous block's median time past at which the transaction will be co...
Definition: tx_verify.cpp:45
int64_t GetTransactionSigOpCost(const CTransaction &tx, const CCoinsViewCache &inputs, script_verify_flags flags)
Compute total signature operation cost of a transaction.
Definition: tx_verify.cpp:149
unsigned int GetLegacySigOpCount(const CTransaction &tx)
Auxiliary functions for transaction validation (ideally should not be exposed)
Definition: tx_verify.cpp:118
bool SequenceLocks(const CTransaction &tx, int flags, std::vector< int > &prevHeights, const CBlockIndex &block)
Check if transaction is final per BIP 68 sequence numbers and can be included in a block.
Definition: tx_verify.cpp:113
bool IsFinalTx(const CTransaction &tx, int nBlockHeight, int64_t nBlockTime)
Check if transaction is final and can be included in a block with the specified height and time.
Definition: tx_verify.cpp:23
bool TestLockPointValidity(CChain &active_chain, const LockPoints &lp)
Test whether the LockPoints height and time are still valid on the current chain.
Definition: txmempool.cpp:40
constexpr uint32_t MEMPOOL_HEIGHT
Fake height value used in Coin to signify they are only in the memory pool (since 0....
Definition: txmempool.h:50
#define expect(bit)
int64_t GetTime()
DEPRECATED Use either ClockType::now() or Now<TimePointType>() if a cast is needed.
Definition: time.cpp:88
std::string FormatISO8601DateTime(int64_t nTime)
ISO 8601 formatting is preferred.
Definition: time.cpp:90
constexpr int64_t count_seconds(std::chrono::seconds t)
Definition: time.h:97
std::chrono::time_point< NodeClock, std::chrono::seconds > NodeSeconds
Definition: time.h:35
PackageMempoolAcceptResult ProcessNewPackage(Chainstate &active_chainstate, CTxMemPool &pool, const Package &package, bool test_accept, const std::optional< CFeeRate > &client_maxfeerate)
Validate (and maybe submit) a package to the mempool.
static void LimitMempoolSize(CTxMemPool &pool, CCoinsViewCache &coins_cache) EXCLUSIVE_LOCKS_REQUIRED(
Definition: validation.cpp:273
bool IsBlockMutated(const CBlock &block, bool check_witness_root)
Check if a block has been mutated (with respect to its merkle root and witness commitments).
script_verify_flags GetBlockScriptFlags(const CBlockIndex &block_index, const ChainstateManager &chainman)
std::optional< LockPoints > CalculateLockPointsAtTip(CBlockIndex *tip, const CCoinsView &coins_view, const CTransaction &tx)
Definition: validation.cpp:210
static bool pool cs
Definition: validation.cpp:409
bool CheckInputScripts(const CTransaction &tx, TxValidationState &state, const CCoinsViewCache &inputs, script_verify_flags flags, bool cacheSigStore, bool cacheFullScriptStore, PrecomputedTransactionData &txdata, ValidationCache &validation_cache, std::vector< CScriptCheck > *pvChecks=nullptr) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Check whether all of this transaction's input scripts succeed.
bool CheckFinalTxAtTip(const CBlockIndex &active_chain_tip, const CTransaction &tx)
Definition: validation.cpp:156
CAmount GetBlockSubsidy(int nHeight, const Consensus::Params &consensusParams)
MempoolAcceptResult AcceptToMemoryPool(Chainstate &active_chainstate, const CTransactionRef &tx, int64_t accept_time, bool bypass_limits, bool test_accept)
Try to add a transaction to the mempool.
bool HasValidProofOfWork(std::span< const CBlockHeader > headers, const Consensus::Params &consensusParams)
Check that the proof of work on each blockheader matches the value in nBits.
int ApplyTxInUndo(Coin &&undo, CCoinsViewCache &view, const COutPoint &out)
Restore the UTXO in a Coin at a given COutPoint.
static bool ContextualCheckBlock(const CBlock &block, BlockValidationState &state, const ChainstateManager &chainman, const CBlockIndex *pindexPrev)
NOTE: This function is not currently invoked by ConnectBlock(), so we should consider upgrade issues ...
bool FatalError(Notifications &notifications, BlockValidationState &state, const bilingual_str &message)
bool CheckSequenceLocksAtTip(CBlockIndex *tip, const LockPoints &lock_points)
Check if transaction will be BIP68 final in the next block to be created on top of tip.
Definition: validation.cpp:255
static bool ContextualCheckBlockHeader(const CBlockHeader &block, BlockValidationState &state, const ChainstateManager &chainman, const CBlockIndex *pindexPrev) EXCLUSIVE_LOCKS_REQUIRED(
Context-dependent validity checks.
static ChainstateManager::Options && Flatten(ChainstateManager::Options &&opts)
Apply default chain params to nullopt members.
static void UpdateTipLog(const ChainstateManager &chainman, const CCoinsViewCache &coins_tip, const CBlockIndex *tip, const std::string &func_name, const std::string &prefix, const std::string &warning_messages, const bool background_validation) EXCLUSIVE_LOCKS_REQUIRED(
static bool CheckInputsFromMempoolAndCache(const CTransaction &tx, TxValidationState &state, const CCoinsViewCache &view, const CTxMemPool &pool, script_verify_flags flags, PrecomputedTransactionData &txdata, CCoinsViewCache &coins_tip, ValidationCache &validation_cache) EXCLUSIVE_LOCKS_REQUIRED(cs_main
Checks to avoid mempool polluting consensus critical paths since cached signature and script validity...
static constexpr auto DATABASE_WRITE_INTERVAL_MAX
Definition: validation.cpp:99
static bool CheckWitnessMalleation(const CBlock &block, bool expect_witness_commitment, BlockValidationState &state)
CheckWitnessMalleation performs checks for block malleation with regard to its witnesses.
void UpdateCoins(const CTransaction &tx, CCoinsViewCache &inputs, CTxUndo &txundo, int nHeight)
static bool DeleteCoinsDBFromDisk(const fs::path db_path, bool is_snapshot) EXCLUSIVE_LOCKS_REQUIRED(
static bool CheckMerkleRoot(const CBlock &block, BlockValidationState &state)
static constexpr int PRUNE_LOCK_BUFFER
The number of blocks to keep below the deepest prune lock.
Definition: validation.cpp:115
arith_uint256 CalculateClaimedHeadersWork(std::span< const CBlockHeader > headers)
Return the sum of the claimed work on a given set of headers.
const std::vector< std::string > CHECKLEVEL_DOC
Documentation for argument 'checklevel'.
Definition: validation.cpp:102
bool CheckBlock(const CBlock &block, BlockValidationState &state, const Consensus::Params &consensusParams, bool fCheckPOW, bool fCheckMerkleRoot)
Functions for validating blocks and updating the block tree.
static constexpr std::chrono::hours MAX_FEE_ESTIMATION_TIP_AGE
Maximum age of our tip for us to be considered current for fee estimation.
Definition: validation.cpp:101
void PruneBlockFilesManual(Chainstate &active_chainstate, int nManualPruneHeight)
Prune block files up to a given height.
static void FlushSnapshotToDisk(CCoinsViewCache &coins_cache, bool snapshot_loaded)
static bool IsCurrentForFeeEstimation(Chainstate &active_chainstate) EXCLUSIVE_LOCKS_REQUIRED(cs_main)
Definition: validation.cpp:289
static constexpr auto DATABASE_WRITE_INTERVAL_MIN
Time window to wait between writing blocks/block index and chainstate to disk.
Definition: validation.cpp:98
AssertLockHeld(pool.cs)
BlockValidationState TestBlockValidity(Chainstate &chainstate, const CBlock &block, const bool check_pow, const bool check_merkle_root)
Verify a block, including transactions.
static bool CheckBlockHeader(const CBlockHeader &block, BlockValidationState &state, const Consensus::Params &consensusParams, bool fCheckPOW=true)
bool IsBIP30Repeat(const CBlockIndex &block_index)
Identifies blocks that overwrote an existing coinbase output in the UTXO set (see BIP30)
static void SnapshotUTXOHashBreakpoint(const util::SignalInterrupt &interrupt)
static bool ShouldCompactChainstate(bool in_ibd)
Definition: validation.cpp:118
static SynchronizationState GetSynchronizationState(bool init, bool blockfiles_indexed)
bool IsBIP30Unspendable(const uint256 &block_hash, int block_height)
Identifies blocks which coinbase output was subsequently overwritten in the UTXO set (see BIP30)
TRACEPOINT_SEMAPHORE(validation, block_connected)
static void LimitValidationInterfaceQueue(ValidationSignals &signals) LOCKS_EXCLUDED(cs_main)
assert(!tx.IsCoinBase())
constexpr int MAX_SCRIPTCHECK_THREADS
Maximum number of dedicated script-checking threads allowed.
Definition: validation.h:90
SnapshotCompletionResult
Definition: validation.h:907
Assumeutxo
Chainstate assumeutxo validity.
Definition: validation.h:530
@ VALIDATED
Every block in the chain has been validated.
@ UNVALIDATED
Blocks after an assumeutxo snapshot have been validated but the snapshot itself has not been validate...
@ INVALID
The assumeutxo snapshot failed validation.
SynchronizationState
Current sync state passed to tip changed callbacks.
Definition: validation.h:96
constexpr std::array FlushStateModeNames
Definition: validation.h:464
constexpr int64_t LargeCoinsCacheThreshold(int64_t total_space) noexcept
Definition: validation.h:521
VerifyDBResult
Definition: validation.h:429
FlushStateMode
Definition: validation.h:465
CoinsCacheSizeState
Definition: validation.h:513
@ LARGE
The cache is at >= 90% capacity.
@ CRITICAL
The coins cache is in immediate need of a flush.
constexpr unsigned int MIN_BLOCKS_TO_KEEP
Block files containing a block-height within MIN_BLOCKS_TO_KEEP of ActiveChain().Tip() will not be pr...
Definition: validation.h:76
DisconnectResult
Definition: validation.h:455
@ DISCONNECT_FAILED
Definition: validation.h:458
@ DISCONNECT_UNCLEAN
Definition: validation.h:457
@ DISCONNECT_OK
Definition: validation.h:456