Bitcoin Core Fuzz Coverage Report for wallet_tx_can_be_bumped

Coverage Report

Created: 2025-11-19 11:20

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/Users/brunogarcia/projects/bitcoin-core-dev/src/coins.cpp
Line
Count
Source
1
// Copyright (c) 2012-2022 The Bitcoin Core developers
2
// Distributed under the MIT software license, see the accompanying
3
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
4
5
#include <coins.h>
6
7
#include <consensus/consensus.h>
8
#include <logging.h>
9
#include <random.h>
10
#include <util/trace.h>
11
12
TRACEPOINT_SEMAPHORE(utxocache, add);
13
TRACEPOINT_SEMAPHORE(utxocache, spent);
14
TRACEPOINT_SEMAPHORE(utxocache, uncache);
15
16
0
std::optional<Coin> CCoinsView::GetCoin(const COutPoint& outpoint) const { return std::nullopt; }
17
0
uint256 CCoinsView::GetBestBlock() const { return uint256(); }
18
0
std::vector<uint256> CCoinsView::GetHeadBlocks() const { return std::vector<uint256>(); }
19
0
bool CCoinsView::BatchWrite(CoinsViewCacheCursor& cursor, const uint256 &hashBlock) { return false; }
20
0
std::unique_ptr<CCoinsViewCursor> CCoinsView::Cursor() const { return nullptr; }
21
22
bool CCoinsView::HaveCoin(const COutPoint &outpoint) const
23
0
{
24
0
    return GetCoin(outpoint).has_value();
25
0
}
26
27
0
CCoinsViewBacked::CCoinsViewBacked(CCoinsView *viewIn) : base(viewIn) { }
28
0
std::optional<Coin> CCoinsViewBacked::GetCoin(const COutPoint& outpoint) const { return base->GetCoin(outpoint); }
29
0
bool CCoinsViewBacked::HaveCoin(const COutPoint &outpoint) const { return base->HaveCoin(outpoint); }
30
0
uint256 CCoinsViewBacked::GetBestBlock() const { return base->GetBestBlock(); }
31
0
std::vector<uint256> CCoinsViewBacked::GetHeadBlocks() const { return base->GetHeadBlocks(); }
32
0
void CCoinsViewBacked::SetBackend(CCoinsView &viewIn) { base = &viewIn; }
33
0
bool CCoinsViewBacked::BatchWrite(CoinsViewCacheCursor& cursor, const uint256 &hashBlock) { return base->BatchWrite(cursor, hashBlock); }
34
0
std::unique_ptr<CCoinsViewCursor> CCoinsViewBacked::Cursor() const { return base->Cursor(); }
35
0
size_t CCoinsViewBacked::EstimateSize() const { return base->EstimateSize(); }
36
37
CCoinsViewCache::CCoinsViewCache(CCoinsView* baseIn, bool deterministic) :
38
0
    CCoinsViewBacked(baseIn), m_deterministic(deterministic),
39
0
    cacheCoins(0, SaltedOutpointHasher(/*deterministic=*/deterministic), CCoinsMap::key_equal{}, &m_cache_coins_memory_resource)
40
0
{
41
0
    m_sentinel.second.SelfRef(m_sentinel);
42
0
}
43
44
0
size_t CCoinsViewCache::DynamicMemoryUsage() const {
45
0
    return memusage::DynamicUsage(cacheCoins) + cachedCoinsUsage;
46
0
}
47
48
0
CCoinsMap::iterator CCoinsViewCache::FetchCoin(const COutPoint &outpoint) const {
49
0
    const auto [ret, inserted] = cacheCoins.try_emplace(outpoint);
50
0
    if (inserted) {
51
0
        if (auto coin{base->GetCoin(outpoint)}) {
52
0
            ret->second.coin = std::move(*coin);
53
0
            cachedCoinsUsage += ret->second.coin.DynamicMemoryUsage();
54
0
            if (ret->second.coin.IsSpent()) { // TODO GetCoin cannot return spent coins
55
                // The parent only has an empty entry for this outpoint; we can consider our version as fresh.
56
0
                CCoinsCacheEntry::SetFresh(*ret, m_sentinel);
57
0
            }
58
0
        } else {
59
0
            cacheCoins.erase(ret);
60
0
            return cacheCoins.end();
61
0
        }
62
0
    }
63
0
    return ret;
64
0
}
65
66
std::optional<Coin> CCoinsViewCache::GetCoin(const COutPoint& outpoint) const
67
0
{
68
0
    if (auto it{FetchCoin(outpoint)}; it != cacheCoins.end() && !it->second.coin.IsSpent()) return it->second.coin;
69
0
    return std::nullopt;
70
0
}
71
72
0
void CCoinsViewCache::AddCoin(const COutPoint &outpoint, Coin&& coin, bool possible_overwrite) {
73
0
    assert(!coin.IsSpent());
74
0
    if (coin.out.scriptPubKey.IsUnspendable()) return;
75
0
    CCoinsMap::iterator it;
76
0
    bool inserted;
77
0
    std::tie(it, inserted) = cacheCoins.emplace(std::piecewise_construct, std::forward_as_tuple(outpoint), std::tuple<>());
78
0
    bool fresh = false;
79
0
    if (!possible_overwrite) {
80
0
        if (!it->second.coin.IsSpent()) {
81
0
            throw std::logic_error("Attempted to overwrite an unspent coin (when possible_overwrite is false)");
82
0
        }
83
        // If the coin exists in this cache as a spent coin and is DIRTY, then
84
        // its spentness hasn't been flushed to the parent cache. We're
85
        // re-adding the coin to this cache now but we can't mark it as FRESH.
86
        // If we mark it FRESH and then spend it before the cache is flushed
87
        // we would remove it from this cache and would never flush spentness
88
        // to the parent cache.
89
        //
90
        // Re-adding a spent coin can happen in the case of a re-org (the coin
91
        // is 'spent' when the block adding it is disconnected and then
92
        // re-added when it is also added in a newly connected block).
93
        //
94
        // If the coin doesn't exist in the current cache, or is spent but not
95
        // DIRTY, then it can be marked FRESH.
96
0
        fresh = !it->second.IsDirty();
97
0
    }
98
0
    if (!inserted) {
99
0
        cachedCoinsUsage -= it->second.coin.DynamicMemoryUsage();
100
0
    }
101
0
    it->second.coin = std::move(coin);
102
0
    CCoinsCacheEntry::SetDirty(*it, m_sentinel);
103
0
    if (fresh) CCoinsCacheEntry::SetFresh(*it, m_sentinel);
104
0
    cachedCoinsUsage += it->second.coin.DynamicMemoryUsage();
105
0
    TRACEPOINT(utxocache, add,
106
0
           outpoint.hash.data(),
107
0
           (uint32_t)outpoint.n,
108
0
           (uint32_t)it->second.coin.nHeight,
109
0
           (int64_t)it->second.coin.out.nValue,
110
0
           (bool)it->second.coin.IsCoinBase());
111
0
}
112
113
0
void CCoinsViewCache::EmplaceCoinInternalDANGER(COutPoint&& outpoint, Coin&& coin) {
114
0
    const auto mem_usage{coin.DynamicMemoryUsage()};
115
0
    auto [it, inserted] = cacheCoins.try_emplace(std::move(outpoint), std::move(coin));
116
0
    if (inserted) {
117
0
        CCoinsCacheEntry::SetDirty(*it, m_sentinel);
118
0
        cachedCoinsUsage += mem_usage;
119
0
    }
120
0
}
121
122
0
void AddCoins(CCoinsViewCache& cache, const CTransaction &tx, int nHeight, bool check_for_overwrite) {
123
0
    bool fCoinbase = tx.IsCoinBase();
124
0
    const Txid& txid = tx.GetHash();
125
0
    for (size_t i = 0; i < tx.vout.size(); ++i) {
126
0
        bool overwrite = check_for_overwrite ? cache.HaveCoin(COutPoint(txid, i)) : fCoinbase;
127
        // Coinbase transactions can always be overwritten, in order to correctly
128
        // deal with the pre-BIP30 occurrences of duplicate coinbase transactions.
129
0
        cache.AddCoin(COutPoint(txid, i), Coin(tx.vout[i], nHeight, fCoinbase), overwrite);
130
0
    }
131
0
}
132
133
0
bool CCoinsViewCache::SpendCoin(const COutPoint &outpoint, Coin* moveout) {
134
0
    CCoinsMap::iterator it = FetchCoin(outpoint);
135
0
    if (it == cacheCoins.end()) return false;
136
0
    cachedCoinsUsage -= it->second.coin.DynamicMemoryUsage();
137
0
    TRACEPOINT(utxocache, spent,
138
0
           outpoint.hash.data(),
139
0
           (uint32_t)outpoint.n,
140
0
           (uint32_t)it->second.coin.nHeight,
141
0
           (int64_t)it->second.coin.out.nValue,
142
0
           (bool)it->second.coin.IsCoinBase());
143
0
    if (moveout) {
144
0
        *moveout = std::move(it->second.coin);
145
0
    }
146
0
    if (it->second.IsFresh()) {
147
0
        cacheCoins.erase(it);
148
0
    } else {
149
0
        CCoinsCacheEntry::SetDirty(*it, m_sentinel);
150
0
        it->second.coin.Clear();
151
0
    }
152
0
    return true;
153
0
}
154
155
static const Coin coinEmpty;
156
157
0
const Coin& CCoinsViewCache::AccessCoin(const COutPoint &outpoint) const {
158
0
    CCoinsMap::const_iterator it = FetchCoin(outpoint);
159
0
    if (it == cacheCoins.end()) {
160
0
        return coinEmpty;
161
0
    } else {
162
0
        return it->second.coin;
163
0
    }
164
0
}
165
166
0
bool CCoinsViewCache::HaveCoin(const COutPoint &outpoint) const {
167
0
    CCoinsMap::const_iterator it = FetchCoin(outpoint);
168
0
    return (it != cacheCoins.end() && !it->second.coin.IsSpent());
169
0
}
170
171
0
bool CCoinsViewCache::HaveCoinInCache(const COutPoint &outpoint) const {
172
0
    CCoinsMap::const_iterator it = cacheCoins.find(outpoint);
173
0
    return (it != cacheCoins.end() && !it->second.coin.IsSpent());
174
0
}
175
176
0
uint256 CCoinsViewCache::GetBestBlock() const {
177
0
    if (hashBlock.IsNull())
178
0
        hashBlock = base->GetBestBlock();
179
0
    return hashBlock;
180
0
}
181
182
0
void CCoinsViewCache::SetBestBlock(const uint256 &hashBlockIn) {
183
0
    hashBlock = hashBlockIn;
184
0
}
185
186
0
bool CCoinsViewCache::BatchWrite(CoinsViewCacheCursor& cursor, const uint256 &hashBlockIn) {
187
0
    for (auto it{cursor.Begin()}; it != cursor.End(); it = cursor.NextAndMaybeErase(*it)) {
188
        // Ignore non-dirty entries (optimization).
189
0
        if (!it->second.IsDirty()) {
190
0
            continue;
191
0
        }
192
0
        CCoinsMap::iterator itUs = cacheCoins.find(it->first);
193
0
        if (itUs == cacheCoins.end()) {
194
            // The parent cache does not have an entry, while the child cache does.
195
            // We can ignore it if it's both spent and FRESH in the child
196
0
            if (!(it->second.IsFresh() && it->second.coin.IsSpent())) {
197
                // Create the coin in the parent cache, move the data up
198
                // and mark it as dirty.
199
0
                itUs = cacheCoins.try_emplace(it->first).first;
200
0
                CCoinsCacheEntry& entry{itUs->second};
201
0
                assert(entry.coin.DynamicMemoryUsage() == 0);
202
0
                if (cursor.WillErase(*it)) {
203
                    // Since this entry will be erased,
204
                    // we can move the coin into us instead of copying it
205
0
                    entry.coin = std::move(it->second.coin);
206
0
                } else {
207
0
                    entry.coin = it->second.coin;
208
0
                }
209
0
                cachedCoinsUsage += entry.coin.DynamicMemoryUsage();
210
0
                CCoinsCacheEntry::SetDirty(*itUs, m_sentinel);
211
                // We can mark it FRESH in the parent if it was FRESH in the child
212
                // Otherwise it might have just been flushed from the parent's cache
213
                // and already exist in the grandparent
214
0
                if (it->second.IsFresh()) CCoinsCacheEntry::SetFresh(*itUs, m_sentinel);
215
0
            }
216
0
        } else {
217
            // Found the entry in the parent cache
218
0
            if (it->second.IsFresh() && !itUs->second.coin.IsSpent()) {
219
                // The coin was marked FRESH in the child cache, but the coin
220
                // exists in the parent cache. If this ever happens, it means
221
                // the FRESH flag was misapplied and there is a logic error in
222
                // the calling code.
223
0
                throw std::logic_error("FRESH flag misapplied to coin that exists in parent cache");
224
0
            }
225
226
0
            if (itUs->second.IsFresh() && it->second.coin.IsSpent()) {
227
                // The grandparent cache does not have an entry, and the coin
228
                // has been spent. We can just delete it from the parent cache.
229
0
                cachedCoinsUsage -= itUs->second.coin.DynamicMemoryUsage();
230
0
                cacheCoins.erase(itUs);
231
0
            } else {
232
                // A normal modification.
233
0
                cachedCoinsUsage -= itUs->second.coin.DynamicMemoryUsage();
234
0
                if (cursor.WillErase(*it)) {
235
                    // Since this entry will be erased,
236
                    // we can move the coin into us instead of copying it
237
0
                    itUs->second.coin = std::move(it->second.coin);
238
0
                } else {
239
0
                    itUs->second.coin = it->second.coin;
240
0
                }
241
0
                cachedCoinsUsage += itUs->second.coin.DynamicMemoryUsage();
242
0
                CCoinsCacheEntry::SetDirty(*itUs, m_sentinel);
243
                // NOTE: It isn't safe to mark the coin as FRESH in the parent
244
                // cache. If it already existed and was spent in the parent
245
                // cache then marking it FRESH would prevent that spentness
246
                // from being flushed to the grandparent.
247
0
            }
248
0
        }
249
0
    }
250
0
    hashBlock = hashBlockIn;
251
0
    return true;
252
0
}
253
254
0
bool CCoinsViewCache::Flush() {
255
0
    auto cursor{CoinsViewCacheCursor(m_sentinel, cacheCoins, /*will_erase=*/true)};
256
0
    bool fOk = base->BatchWrite(cursor, hashBlock);
257
0
    if (fOk) {
258
0
        cacheCoins.clear();
259
0
        ReallocateCache();
260
0
        cachedCoinsUsage = 0;
261
0
    }
262
0
    return fOk;
263
0
}
264
265
bool CCoinsViewCache::Sync()
266
0
{
267
0
    auto cursor{CoinsViewCacheCursor(m_sentinel, cacheCoins, /*will_erase=*/false)};
268
0
    bool fOk = base->BatchWrite(cursor, hashBlock);
269
0
    if (fOk) {
270
0
        if (m_sentinel.second.Next() != &m_sentinel) {
271
            /* BatchWrite must clear flags of all entries */
272
0
            throw std::logic_error("Not all unspent flagged entries were cleared");
273
0
        }
274
0
    }
275
0
    return fOk;
276
0
}
277
278
void CCoinsViewCache::Uncache(const COutPoint& hash)
279
0
{
280
0
    CCoinsMap::iterator it = cacheCoins.find(hash);
281
0
    if (it != cacheCoins.end() && !it->second.IsDirty() && !it->second.IsFresh()) {
282
0
        cachedCoinsUsage -= it->second.coin.DynamicMemoryUsage();
283
0
        TRACEPOINT(utxocache, uncache,
284
0
               hash.hash.data(),
285
0
               (uint32_t)hash.n,
286
0
               (uint32_t)it->second.coin.nHeight,
287
0
               (int64_t)it->second.coin.out.nValue,
288
0
               (bool)it->second.coin.IsCoinBase());
289
0
        cacheCoins.erase(it);
290
0
    }
291
0
}
292
293
0
unsigned int CCoinsViewCache::GetCacheSize() const {
294
0
    return cacheCoins.size();
295
0
}
296
297
bool CCoinsViewCache::HaveInputs(const CTransaction& tx) const
298
0
{
299
0
    if (!tx.IsCoinBase()) {
300
0
        for (unsigned int i = 0; i < tx.vin.size(); i++) {
301
0
            if (!HaveCoin(tx.vin[i].prevout)) {
302
0
                return false;
303
0
            }
304
0
        }
305
0
    }
306
0
    return true;
307
0
}
308
309
void CCoinsViewCache::ReallocateCache()
310
0
{
311
    // Cache should be empty when we're calling this.
312
0
    assert(cacheCoins.size() == 0);
313
0
    cacheCoins.~CCoinsMap();
314
0
    m_cache_coins_memory_resource.~CCoinsMapMemoryResource();
315
0
    ::new (&m_cache_coins_memory_resource) CCoinsMapMemoryResource{};
316
0
    ::new (&cacheCoins) CCoinsMap{0, SaltedOutpointHasher{/*deterministic=*/m_deterministic}, CCoinsMap::key_equal{}, &m_cache_coins_memory_resource};
317
0
}
318
319
void CCoinsViewCache::SanityCheck() const
320
0
{
321
0
    size_t recomputed_usage = 0;
322
0
    size_t count_flagged = 0;
323
0
    for (const auto& [_, entry] : cacheCoins) {
324
0
        unsigned attr = 0;
325
0
        if (entry.IsDirty()) attr |= 1;
326
0
        if (entry.IsFresh()) attr |= 2;
327
0
        if (entry.coin.IsSpent()) attr |= 4;
328
        // Only 5 combinations are possible.
329
0
        assert(attr != 2 && attr != 4 && attr != 7);
330
331
        // Recompute cachedCoinsUsage.
332
0
        recomputed_usage += entry.coin.DynamicMemoryUsage();
333
334
        // Count the number of entries we expect in the linked list.
335
0
        if (entry.IsDirty() || entry.IsFresh()) ++count_flagged;
336
0
    }
337
    // Iterate over the linked list of flagged entries.
338
0
    size_t count_linked = 0;
339
0
    for (auto it = m_sentinel.second.Next(); it != &m_sentinel; it = it->second.Next()) {
340
        // Verify linked list integrity.
341
0
        assert(it->second.Next()->second.Prev() == it);
342
0
        assert(it->second.Prev()->second.Next() == it);
343
        // Verify they are actually flagged.
344
0
        assert(it->second.IsDirty() || it->second.IsFresh());
345
        // Count the number of entries actually in the list.
346
0
        ++count_linked;
347
0
    }
348
0
    assert(count_linked == count_flagged);
349
0
    assert(recomputed_usage == cachedCoinsUsage);
350
0
}
351
352
static const uint64_t MIN_TRANSACTION_OUTPUT_WEIGHT{WITNESS_SCALE_FACTOR * ::GetSerializeSize(CTxOut())};
353
static const uint64_t MAX_OUTPUTS_PER_BLOCK{MAX_BLOCK_WEIGHT / MIN_TRANSACTION_OUTPUT_WEIGHT};
354
355
const Coin& AccessByTxid(const CCoinsViewCache& view, const Txid& txid)
356
0
{
357
0
    COutPoint iter(txid, 0);
358
0
    while (iter.n < MAX_OUTPUTS_PER_BLOCK) {
359
0
        const Coin& alternate = view.AccessCoin(iter);
360
0
        if (!alternate.IsSpent()) return alternate;
361
0
        ++iter.n;
362
0
    }
363
0
    return coinEmpty;
364
0
}
365
366
template <typename ReturnType, typename Func>
367
static ReturnType ExecuteBackedWrapper(Func func, const std::vector<std::function<void()>>& err_callbacks)
368
0
{
369
0
    try {
370
0
        return func();
371
0
    } catch(const std::runtime_error& e) {
372
0
        for (const auto& f : err_callbacks) {
373
0
            f();
374
0
        }
375
0
        LogError("Error reading from database: %s\n", e.what());
Line
Count
Source
370
0
#define LogError(...) LogPrintLevel_(BCLog::LogFlags::ALL, BCLog::Level::Error, /*should_ratelimit=*/true, __VA_ARGS__)
Line
Count
Source
362
0
#define LogPrintLevel_(category, level, should_ratelimit, ...) LogPrintFormatInternal(std::source_location::current(), category, level, should_ratelimit, __VA_ARGS__)
        LogError("Error reading from database: %s\n", e.what());
Line
Count
Source
370
0
#define LogError(...) LogPrintLevel_(BCLog::LogFlags::ALL, BCLog::Level::Error, /*should_ratelimit=*/true, __VA_ARGS__)
Line
Count
Source
362
0
#define LogPrintLevel_(category, level, should_ratelimit, ...) LogPrintFormatInternal(std::source_location::current(), category, level, should_ratelimit, __VA_ARGS__)
376
        // Starting the shutdown sequence and returning false to the caller would be
377
        // interpreted as 'entry not found' (as opposed to unable to read data), and
378
        // could lead to invalid interpretation. Just exit immediately, as we can't
379
        // continue anyway, and all writes should be atomic.
380
0
        std::abort();
381
0
    }
382
0
}
Unexecuted instantiation: coins.cpp:std::__1::optional<Coin> ExecuteBackedWrapper<std::__1::optional<Coin>, CCoinsViewErrorCatcher::GetCoin(COutPoint const&) const::$_0>(CCoinsViewErrorCatcher::GetCoin(COutPoint const&) const::$_0, std::__1::vector<std::__1::function<void ()>, std::__1::allocator<std::__1::function<void ()>>> const&)
Unexecuted instantiation: coins.cpp:bool ExecuteBackedWrapper<bool, CCoinsViewErrorCatcher::HaveCoin(COutPoint const&) const::$_0>(CCoinsViewErrorCatcher::HaveCoin(COutPoint const&) const::$_0, std::__1::vector<std::__1::function<void ()>, std::__1::allocator<std::__1::function<void ()>>> const&)
383
384
std::optional<Coin> CCoinsViewErrorCatcher::GetCoin(const COutPoint& outpoint) const
385
0
{
386
0
    return ExecuteBackedWrapper<std::optional<Coin>>([&]() { return CCoinsViewBacked::GetCoin(outpoint); }, m_err_callbacks);
387
0
}
388
389
bool CCoinsViewErrorCatcher::HaveCoin(const COutPoint& outpoint) const
390
0
{
391
0
    return ExecuteBackedWrapper<bool>([&]() { return CCoinsViewBacked::HaveCoin(outpoint); }, m_err_callbacks);
392
0
}