LCOV - code coverage report
Current view: top level - src/test/fuzz - package_eval.cpp (source / functions) Coverage Total Hit
Test: fuzz_coverage.info Lines: 100.0 % 281 281
Test Date: 2026-02-13 04:14:00 Functions: 100.0 % 23 23
Branches: 67.4 % 436 294

             Branch data     Line data    Source code
       1                 :             : // Copyright (c) 2023-present The Bitcoin Core developers
       2                 :             : // Distributed under the MIT software license, see the accompanying
       3                 :             : // file COPYING or http://www.opensource.org/licenses/mit-license.php.
       4                 :             : 
       5                 :             : #include <consensus/validation.h>
       6                 :             : #include <node/context.h>
       7                 :             : #include <node/mempool_args.h>
       8                 :             : #include <node/miner.h>
       9                 :             : #include <policy/truc_policy.h>
      10                 :             : #include <test/fuzz/FuzzedDataProvider.h>
      11                 :             : #include <test/fuzz/fuzz.h>
      12                 :             : #include <test/fuzz/util.h>
      13                 :             : #include <test/fuzz/util/mempool.h>
      14                 :             : #include <test/util/mining.h>
      15                 :             : #include <test/util/script.h>
      16                 :             : #include <test/util/setup_common.h>
      17                 :             : #include <test/util/txmempool.h>
      18                 :             : #include <util/check.h>
      19                 :             : #include <util/rbf.h>
      20                 :             : #include <util/translation.h>
      21                 :             : #include <validation.h>
      22                 :             : #include <validationinterface.h>
      23                 :             : 
      24                 :             : using node::BlockAssembler;
      25                 :             : using node::NodeContext;
      26                 :             : 
      27                 :             : namespace {
      28                 :             : 
      29                 :             : const TestingSetup* g_setup;
      30                 :             : std::vector<COutPoint> g_outpoints_coinbase_init_mature;
      31                 :             : 
      32                 :             : struct MockedTxPool : public CTxMemPool {
      33                 :       67750 :     void RollingFeeUpdate() EXCLUSIVE_LOCKS_REQUIRED(!cs)
      34                 :             :     {
      35                 :       67750 :         LOCK(cs);
      36         [ +  - ]:       67750 :         lastRollingFeeUpdate = GetTime();
      37         [ +  - ]:       67750 :         blockSinceLastRollingFeeBump = true;
      38                 :       67750 :     }
      39                 :             : };
      40                 :             : 
      41                 :           2 : void initialize_tx_pool()
      42                 :             : {
      43   [ +  -  +  -  :           2 :     static const auto testing_setup = MakeNoLogFileContext<const TestingSetup>();
                   +  - ]
      44                 :           2 :     g_setup = testing_setup.get();
      45   [ +  -  +  - ]:           6 :     SetMockTime(WITH_LOCK(g_setup->m_node.chainman->GetMutex(), return g_setup->m_node.chainman->ActiveTip()->Time()));
      46                 :             : 
      47                 :           2 :     BlockAssembler::Options options;
      48                 :           2 :     options.coinbase_output_script = P2WSH_EMPTY;
      49                 :           2 :     options.include_dummy_extranonce = true;
      50                 :             : 
      51         [ +  + ]:         402 :     for (int i = 0; i < 2 * COINBASE_MATURITY; ++i) {
      52         [ +  - ]:         400 :         COutPoint prevout{MineBlock(g_setup->m_node, options)};
      53         [ +  + ]:         400 :         if (i < COINBASE_MATURITY) {
      54                 :             :             // Remember the txids to avoid expensive disk access later on
      55         [ +  - ]:         200 :             g_outpoints_coinbase_init_mature.push_back(prevout);
      56                 :             :         }
      57                 :             :     }
      58         [ +  - ]:           2 :     g_setup->m_node.validation_signals->SyncWithValidationInterfaceQueue();
      59                 :           2 : }
      60                 :             : 
      61                 :             : struct OutpointsUpdater final : public CValidationInterface {
      62                 :             :     std::set<COutPoint>& m_mempool_outpoints;
      63                 :             : 
      64                 :        4725 :     explicit OutpointsUpdater(std::set<COutPoint>& r)
      65                 :        4725 :         : m_mempool_outpoints{r} {}
      66                 :             : 
      67                 :      167951 :     void TransactionAddedToMempool(const NewMempoolTransactionInfo& tx, uint64_t /* mempool_sequence */) override
      68                 :             :     {
      69                 :             :         // for coins spent we always want to be able to rbf so they're not removed
      70                 :             : 
      71                 :             :         // outputs from this tx can now be spent
      72   [ -  +  +  + ]:      618688 :         for (uint32_t index{0}; index < tx.info.m_tx->vout.size(); ++index) {
      73                 :      450737 :             m_mempool_outpoints.insert(COutPoint{tx.info.m_tx->GetHash(), index});
      74                 :             :         }
      75                 :      167951 :     }
      76                 :             : 
      77                 :       62167 :     void TransactionRemovedFromMempool(const CTransactionRef& tx, MemPoolRemovalReason reason, uint64_t /* mempool_sequence */) override
      78                 :             :     {
      79                 :             :         // outpoints spent by this tx are now available
      80         [ +  + ]:      169694 :         for (const auto& input : tx->vin) {
      81                 :             :             // Could already exist if this was a replacement
      82                 :      107527 :             m_mempool_outpoints.insert(input.prevout);
      83                 :             :         }
      84                 :             :         // outpoints created by this tx no longer exist
      85   [ -  +  +  + ]:      220420 :         for (uint32_t index{0}; index < tx->vout.size(); ++index) {
      86                 :      158253 :             m_mempool_outpoints.erase(COutPoint{tx->GetHash(), index});
      87                 :             :         }
      88                 :       62167 :     }
      89                 :             : };
      90                 :             : 
      91                 :             : struct TransactionsDelta final : public CValidationInterface {
      92                 :             :     std::set<CTransactionRef>& m_added;
      93                 :             : 
      94                 :      262703 :     explicit TransactionsDelta(std::set<CTransactionRef>& a)
      95                 :      262703 :         : m_added{a} {}
      96                 :             : 
      97                 :       40384 :     void TransactionAddedToMempool(const NewMempoolTransactionInfo& tx, uint64_t /* mempool_sequence */) override
      98                 :             :     {
      99                 :             :         // Transactions may be entered and booted any number of times
     100                 :       40384 :         m_added.insert(tx.info.m_tx);
     101                 :       40384 :     }
     102                 :             : 
     103                 :       33064 :     void TransactionRemovedFromMempool(const CTransactionRef& tx, MemPoolRemovalReason reason, uint64_t /* mempool_sequence */) override
     104                 :             :     {
     105                 :             :         // Transactions may be entered and booted any number of times
     106                 :       33064 :          m_added.erase(tx);
     107                 :       33064 :     }
     108                 :             : };
     109                 :             : 
     110                 :      110884 : void MockTime(FuzzedDataProvider& fuzzed_data_provider, const Chainstate& chainstate)
     111                 :             : {
     112                 :      110884 :     const auto time = ConsumeTime(fuzzed_data_provider,
     113                 :      110884 :                                   chainstate.m_chain.Tip()->GetMedianTimePast() + 1,
     114         [ -  + ]:      110884 :                                   std::numeric_limits<decltype(chainstate.m_chain.Tip()->nTime)>::max());
     115                 :      110884 :     SetMockTime(time);
     116                 :      110884 : }
     117                 :             : 
     118                 :        2321 : std::unique_ptr<CTxMemPool> MakeMempool(FuzzedDataProvider& fuzzed_data_provider, const NodeContext& node)
     119                 :             : {
     120                 :             :     // Take the default options for tests...
     121                 :        2321 :     CTxMemPool::Options mempool_opts{MemPoolOptionsForTest(node)};
     122                 :             : 
     123                 :             : 
     124                 :             :     // ...override specific options for this specific fuzz suite
     125                 :        2321 :     mempool_opts.limits.ancestor_count = fuzzed_data_provider.ConsumeIntegralInRange<unsigned>(0, 50);
     126                 :        2321 :     mempool_opts.limits.descendant_count = fuzzed_data_provider.ConsumeIntegralInRange<unsigned>(0, 50);
     127                 :        2321 :     mempool_opts.max_size_bytes = fuzzed_data_provider.ConsumeIntegralInRange<unsigned>(0, 200) * 1'000'000;
     128                 :        2321 :     mempool_opts.expiry = std::chrono::hours{fuzzed_data_provider.ConsumeIntegralInRange<unsigned>(0, 999)};
     129                 :             :     // Only interested in 2 cases: sigop cost 0 or when single legacy sigop cost is >> 1KvB
     130                 :        2321 :     nBytesPerSigOp = fuzzed_data_provider.ConsumeIntegralInRange<unsigned>(0, 1) * 10'000;
     131                 :             : 
     132                 :        2321 :     mempool_opts.check_ratio = 1;
     133                 :        2321 :     mempool_opts.require_standard = fuzzed_data_provider.ConsumeBool();
     134                 :             : 
     135         [ +  - ]:        2321 :     bilingual_str error;
     136                 :             :     // ...and construct a CTxMemPool from it
     137         [ +  - ]:        2321 :     auto mempool{std::make_unique<CTxMemPool>(std::move(mempool_opts), error)};
     138                 :             :     // ... ignore the error since it might be beneficial to fuzz even when the
     139                 :             :     // mempool size is unreasonably small
     140   [ +  +  +  -  :        2689 :     Assert(error.empty() || error.original.starts_with("-maxmempool must be at least "));
                   -  + ]
     141                 :        2321 :     return mempool;
     142                 :        2321 : }
     143                 :             : 
     144                 :        2404 : std::unique_ptr<CTxMemPool> MakeEphemeralMempool(const NodeContext& node)
     145                 :             : {
     146                 :             :     // Take the default options for tests...
     147                 :        2404 :     CTxMemPool::Options mempool_opts{MemPoolOptionsForTest(node)};
     148                 :             : 
     149                 :        2404 :     mempool_opts.check_ratio = 1;
     150                 :             : 
     151                 :             :     // Require standardness rules otherwise ephemeral dust is no-op
     152                 :        2404 :     mempool_opts.require_standard = true;
     153                 :             : 
     154                 :             :     // And set minrelay to 0 to allow ephemeral parent tx even with non-TRUC
     155         [ +  - ]:        2404 :     mempool_opts.min_relay_feerate = CFeeRate(0);
     156                 :             : 
     157         [ +  - ]:        2404 :     bilingual_str error;
     158                 :             :     // ...and construct a CTxMemPool from it
     159         [ +  - ]:        2404 :     auto mempool{std::make_unique<CTxMemPool>(std::move(mempool_opts), error)};
     160         [ -  + ]:        2404 :     Assert(error.empty());
     161                 :        2404 :     return mempool;
     162                 :        2404 : }
     163                 :             : 
     164                 :             : // Scan mempool for a tx that has spent dust and return a
     165                 :             : // prevout of the child that isn't the dusty parent itself.
     166                 :             : // This is used to double-spend the child out of the mempool,
     167                 :             : // leaving the parent childless.
     168                 :             : // This assumes CheckMempoolEphemeralInvariants has passed for tx_pool.
     169                 :      189979 : std::optional<COutPoint> GetChildEvictingPrevout(const CTxMemPool& tx_pool)
     170                 :             : {
     171                 :      189979 :     LOCK(tx_pool.cs);
     172   [ +  -  +  + ]:     6740783 :     for (const auto& tx_info : tx_pool.infoAll()) {
     173   [ +  -  -  + ]:     6564404 :         const auto& entry = *Assert(tx_pool.GetEntry(tx_info.tx->GetHash()));
     174         [ +  - ]:     6564404 :         std::vector<uint32_t> dust_indexes{GetDust(*tx_info.tx, tx_pool.m_opts.dust_relay_feerate)};
     175         [ +  + ]:     6564404 :         if (!dust_indexes.empty()) {
     176         [ +  - ]:       30928 :             const auto& children = tx_pool.GetChildren(entry);
     177         [ +  + ]:       30928 :             if (!children.empty()) {
     178   [ -  +  -  + ]:       19956 :                 Assert(children.size() == 1);
     179                 :             :                 // Find an input that doesn't spend from parent's txid
     180                 :       19956 :                 const auto& only_child = children.begin()->get().GetTx();
     181         [ +  + ]:       38561 :                 for (const auto& tx_input : only_child.vin) {
     182         [ +  + ]:       32205 :                     if (tx_input.prevout.hash != tx_info.tx->GetHash()) {
     183                 :       13600 :                         return tx_input.prevout;
     184                 :             :                     }
     185                 :             :                 }
     186                 :             :             }
     187                 :       30928 :         }
     188                 :     6740783 :     }
     189                 :             : 
     190                 :      176379 :     return std::nullopt;
     191                 :      189979 : }
     192                 :             : 
     193         [ +  - ]:        2858 : FUZZ_TARGET(ephemeral_package_eval, .init = initialize_tx_pool)
     194                 :             : {
     195                 :        2404 :     SeedRandomStateForTest(SeedRand::ZEROS);
     196                 :        2404 :     FuzzedDataProvider fuzzed_data_provider(buffer.data(), buffer.size());
     197                 :        2404 :     const auto& node = g_setup->m_node;
     198                 :        2404 :     auto& chainstate{static_cast<DummyChainState&>(node.chainman->ActiveChainstate())};
     199                 :             : 
     200                 :        2404 :     MockTime(fuzzed_data_provider, chainstate);
     201                 :             : 
     202                 :             :     // All RBF-spendable outpoints outside of the unsubmitted package
     203         [ +  - ]:        2404 :     std::set<COutPoint> mempool_outpoints;
     204         [ +  - ]:        2404 :     std::unordered_map<COutPoint, CAmount, SaltedOutpointHasher> outpoints_value;
     205         [ +  + ]:      242804 :     for (const auto& outpoint : g_outpoints_coinbase_init_mature) {
     206         [ +  - ]:      240400 :         Assert(mempool_outpoints.insert(outpoint).second);
     207         [ +  - ]:      240400 :         outpoints_value[outpoint] = 50 * COIN;
     208                 :             :     }
     209                 :             : 
     210         [ +  - ]:        2404 :     auto outpoints_updater = std::make_shared<OutpointsUpdater>(mempool_outpoints);
     211   [ +  -  +  - ]:        4808 :     node.validation_signals->RegisterSharedValidationInterface(outpoints_updater);
     212                 :             : 
     213         [ +  - ]:        2404 :     auto tx_pool_{MakeEphemeralMempool(node)};
     214                 :        2404 :     MockedTxPool& tx_pool = *static_cast<MockedTxPool*>(tx_pool_.get());
     215                 :             : 
     216                 :        2404 :     chainstate.SetMempool(&tx_pool);
     217                 :             : 
     218   [ +  +  +  + ]:      428830 :     LIMITED_WHILE(fuzzed_data_provider.remaining_bytes() > 0, 300)
     219                 :             :     {
     220         [ -  + ]:      426426 :         Assert(!mempool_outpoints.empty());
     221                 :             : 
     222                 :      426426 :         std::vector<CTransactionRef> txs;
     223                 :             : 
     224                 :             :         // Find something we may want to double-spend with two input single tx
     225   [ +  +  +  - ]:      426426 :         std::optional<COutPoint> outpoint_to_rbf{fuzzed_data_provider.ConsumeBool() ? GetChildEvictingPrevout(tx_pool) : std::nullopt};
     226                 :             : 
     227                 :             :         // Make small packages
     228         [ +  + ]:      426426 :         const auto num_txs = outpoint_to_rbf ? 1 : fuzzed_data_provider.ConsumeIntegralInRange<size_t>(1, 4);
     229                 :             : 
     230                 :      426426 :         std::set<COutPoint> package_outpoints;
     231   [ -  +  +  + ]:     1367852 :         while (txs.size() < num_txs) {
     232                 :             :             // Create transaction to add to the mempool
     233         [ +  - ]:     1882852 :             txs.emplace_back([&] {
     234                 :      941426 :                 CMutableTransaction tx_mut;
     235                 :      941426 :                 tx_mut.version = CTransaction::CURRENT_VERSION;
     236                 :      941426 :                 tx_mut.nLockTime = 0;
     237                 :             :                 // Last transaction in a package needs to be a child of parents to get further in validation
     238                 :             :                 // so the last transaction to be generated(in a >1 package) must spend all package-made outputs
     239                 :             :                 // Note that this test currently only spends package outputs in last transaction.
     240   [ +  +  -  +  :      941426 :                 bool last_tx = num_txs > 1 && txs.size() == num_txs - 1;
                   +  + ]
     241         [ +  + ]:      941426 :                 const auto num_in = outpoint_to_rbf ? 2 :
     242         [ +  + ]:      927826 :                     last_tx ? fuzzed_data_provider.ConsumeIntegralInRange<int>(package_outpoints.size()/2 + 1, package_outpoints.size()) :
     243                 :      656332 :                     fuzzed_data_provider.ConsumeIntegralInRange<int>(1, 4);
     244         [ +  + ]:      941426 :                 const auto num_out = outpoint_to_rbf ? 1 : fuzzed_data_provider.ConsumeIntegralInRange<int>(1, 4);
     245                 :             : 
     246         [ +  + ]:      941426 :                 auto& outpoints = last_tx ? package_outpoints : mempool_outpoints;
     247                 :             : 
     248   [ +  -  -  +  :      941426 :                 Assert((int)outpoints.size() >= num_in && num_in > 0);
                   -  + ]
     249                 :             : 
     250                 :             :                 CAmount amount_in{0};
     251         [ +  + ]:     3535045 :                 for (int i = 0; i < num_in; ++i) {
     252                 :             :                     // Pop random outpoint. We erase them to avoid double-spending
     253                 :             :                     // while in this loop, but later add them back (unless last_tx).
     254                 :     2593619 :                     auto pop = outpoints.begin();
     255                 :     2593619 :                     std::advance(pop, fuzzed_data_provider.ConsumeIntegralInRange<size_t>(0, outpoints.size() - 1));
     256         [ +  + ]:     2593619 :                     auto outpoint = *pop;
     257                 :             : 
     258   [ +  +  +  + ]:     2593619 :                     if (i == 0 && outpoint_to_rbf) {
     259                 :       13600 :                         outpoint = *outpoint_to_rbf;
     260                 :       13600 :                         outpoints.erase(outpoint);
     261                 :             :                     } else {
     262                 :     2580019 :                         outpoints.erase(pop);
     263                 :             :                     }
     264                 :             :                     // no need to update or erase from outpoints_value
     265         [ +  - ]:     2593619 :                     amount_in += outpoints_value.at(outpoint);
     266                 :             : 
     267                 :             :                     // Create input
     268                 :     2593619 :                     CTxIn in;
     269                 :     2593619 :                     in.prevout = outpoint;
     270         [ +  - ]:     2593619 :                     in.scriptWitness.stack = P2WSH_EMPTY_TRUE_STACK;
     271                 :             : 
     272         [ +  - ]:     2593619 :                     tx_mut.vin.push_back(in);
     273                 :     2593619 :                 }
     274                 :             : 
     275                 :      941426 :                 const auto amount_fee = fuzzed_data_provider.ConsumeIntegralInRange<CAmount>(0, amount_in);
     276                 :      941426 :                 const auto amount_out = (amount_in - amount_fee) / num_out;
     277         [ +  + ]:     3085234 :                 for (int i = 0; i < num_out; ++i) {
     278         [ +  - ]:     2143808 :                     tx_mut.vout.emplace_back(amount_out, P2WSH_EMPTY);
     279                 :             :                 }
     280                 :             : 
     281                 :             :                 // Note output amounts can naturally drop to dust on their own.
     282   [ +  +  +  + ]:      941426 :                 if (!outpoint_to_rbf && fuzzed_data_provider.ConsumeBool()) {
     283                 :      331615 :                     uint32_t dust_index = fuzzed_data_provider.ConsumeIntegralInRange<uint32_t>(0, num_out);
     284   [ +  -  +  - ]:      331615 :                     tx_mut.vout.insert(tx_mut.vout.begin() + dust_index, CTxOut(0, P2WSH_EMPTY));
     285                 :             :                 }
     286                 :             : 
     287         [ +  - ]:      941426 :                 auto tx = MakeTransactionRef(tx_mut);
     288                 :             :                 // Restore previously removed outpoints, except in-package outpoints (to allow RBF)
     289         [ +  + ]:      941426 :                 if (!last_tx) {
     290         [ +  + ]:     2184147 :                     for (const auto& in : tx->vin) {
     291         [ +  - ]:     3028430 :                         Assert(outpoints.insert(in.prevout).second);
     292                 :             :                     }
     293                 :             :                     // Cache the in-package outpoints being made
     294   [ -  +  +  + ]:     2371159 :                     for (size_t i = 0; i < tx->vout.size(); ++i) {
     295         [ +  - ]:     1701227 :                         package_outpoints.emplace(tx->GetHash(), i);
     296                 :             :                     }
     297                 :             :                 }
     298                 :             :                 // We need newly-created values for the duration of this run
     299   [ -  +  +  + ]:     3416849 :                 for (size_t i = 0; i < tx->vout.size(); ++i) {
     300         [ +  - ]:     2475423 :                     outpoints_value[COutPoint(tx->GetHash(), i)] = tx->vout[i].nValue;
     301                 :             :                 }
     302                 :      941426 :                 return tx;
     303         [ +  - ]:     2824278 :             }());
     304                 :             :         }
     305                 :             : 
     306         [ +  + ]:      426426 :         if (fuzzed_data_provider.ConsumeBool()) {
     307         [ +  + ]:      180529 :             const auto& txid = fuzzed_data_provider.ConsumeBool() ?
     308                 :       70911 :                                    txs.back()->GetHash() :
     309                 :      109618 :                                    PickValue(fuzzed_data_provider, mempool_outpoints).hash;
     310                 :      180529 :             const auto delta = fuzzed_data_provider.ConsumeIntegralInRange<CAmount>(-50 * COIN, +50 * COIN);
     311                 :             :             // We only prioritise out of mempool transactions since PrioritiseTransaction doesn't
     312                 :             :             // filter for ephemeral dust
     313   [ +  -  +  + ]:      180529 :             if (tx_pool.exists(txid)) {
     314         [ +  - ]:       61360 :                 const auto tx_info{tx_pool.info(txid)};
     315   [ +  -  +  + ]:       61360 :                 if (GetDust(*tx_info.tx, tx_pool.m_opts.dust_relay_feerate).empty()) {
     316         [ +  - ]:       58941 :                     tx_pool.PrioritiseTransaction(txid, delta);
     317                 :             :                 }
     318                 :       61360 :             }
     319                 :             :         }
     320                 :             : 
     321         [ -  + ]:      426426 :         auto single_submit = txs.size() == 1;
     322                 :             : 
     323         [ +  - ]:     1279278 :         const auto result_package = WITH_LOCK(::cs_main,
     324                 :             :                                     return ProcessNewPackage(chainstate, tx_pool, txs, /*test_accept=*/single_submit, /*client_maxfeerate=*/{}));
     325                 :             : 
     326   [ +  -  +  - ]:     1279278 :         const auto res = WITH_LOCK(::cs_main, return AcceptToMemoryPool(chainstate, txs.back(), GetTime(),
     327                 :             :                                    /*bypass_limits=*/false, /*test_accept=*/!single_submit));
     328                 :             : 
     329   [ +  +  +  + ]:      426426 :         if (!single_submit && result_package.m_state.GetResult() != PackageValidationResult::PCKG_POLICY) {
     330                 :             :             // We don't know anything about the validity since transactions were randomly generated, so
     331                 :             :             // just use result_package.m_state here. This makes the expect_valid check meaningless, but
     332                 :             :             // we can still verify that the contents of m_tx_results are consistent with m_state.
     333         [ +  - ]:      163836 :             const bool expect_valid{result_package.m_state.IsValid()};
     334   [ +  -  -  + ]:      163836 :             Assert(!CheckPackageMempoolAcceptResult(txs, result_package, expect_valid, &tx_pool));
     335                 :             :         }
     336                 :             : 
     337         [ +  - ]:      426426 :         node.validation_signals->SyncWithValidationInterfaceQueue();
     338                 :             : 
     339         [ +  - ]:      426426 :         CheckMempoolEphemeralInvariants(tx_pool);
     340                 :      426426 :     }
     341                 :             : 
     342   [ +  -  +  - ]:        4808 :     node.validation_signals->UnregisterSharedValidationInterface(outpoints_updater);
     343                 :             : 
     344   [ +  +  +  -  :        7212 :     WITH_LOCK(::cs_main, tx_pool.check(chainstate.CoinsTip(), chainstate.m_chain.Height() + 1));
                   +  - ]
     345         [ +  - ]:        4808 : }
     346                 :             : 
     347                 :             : 
     348         [ +  - ]:        2775 : FUZZ_TARGET(tx_package_eval, .init = initialize_tx_pool)
     349                 :             : {
     350                 :        2321 :     SeedRandomStateForTest(SeedRand::ZEROS);
     351                 :        2321 :     FuzzedDataProvider fuzzed_data_provider(buffer.data(), buffer.size());
     352                 :        2321 :     const auto& node = g_setup->m_node;
     353                 :        2321 :     auto& chainstate{static_cast<DummyChainState&>(node.chainman->ActiveChainstate())};
     354                 :             : 
     355                 :        2321 :     MockTime(fuzzed_data_provider, chainstate);
     356                 :             : 
     357                 :             :     // All RBF-spendable outpoints outside of the unsubmitted package
     358         [ +  - ]:        2321 :     std::set<COutPoint> mempool_outpoints;
     359         [ +  - ]:        2321 :     std::unordered_map<COutPoint, CAmount, SaltedOutpointHasher> outpoints_value;
     360         [ +  + ]:      234421 :     for (const auto& outpoint : g_outpoints_coinbase_init_mature) {
     361         [ +  - ]:      232100 :         Assert(mempool_outpoints.insert(outpoint).second);
     362         [ +  - ]:      232100 :         outpoints_value[outpoint] = 50 * COIN;
     363                 :             :     }
     364                 :             : 
     365         [ +  - ]:        2321 :     auto outpoints_updater = std::make_shared<OutpointsUpdater>(mempool_outpoints);
     366   [ +  -  +  - ]:        4642 :     node.validation_signals->RegisterSharedValidationInterface(outpoints_updater);
     367                 :             : 
     368         [ +  - ]:        2321 :     auto tx_pool_{MakeMempool(fuzzed_data_provider, node)};
     369                 :        2321 :     MockedTxPool& tx_pool = *static_cast<MockedTxPool*>(tx_pool_.get());
     370                 :             : 
     371                 :        2321 :     chainstate.SetMempool(&tx_pool);
     372                 :             : 
     373   [ +  +  +  + ]:      265024 :     LIMITED_WHILE(fuzzed_data_provider.remaining_bytes() > 0, 300)
     374                 :             :     {
     375         [ -  + ]:      262703 :         Assert(!mempool_outpoints.empty());
     376                 :             : 
     377                 :      262703 :         std::vector<CTransactionRef> txs;
     378                 :             : 
     379                 :             :         // Make packages of 1-to-26 transactions
     380                 :      262703 :         const auto num_txs = fuzzed_data_provider.ConsumeIntegralInRange<size_t>(1, 26);
     381                 :      262703 :         std::set<COutPoint> package_outpoints;
     382   [ -  +  +  + ]:     1085392 :         while (txs.size() < num_txs) {
     383                 :             :             // Create transaction to add to the mempool
     384         [ +  - ]:     1645378 :             txs.emplace_back([&] {
     385                 :      822689 :                 CMutableTransaction tx_mut;
     386         [ +  + ]:      822689 :                 tx_mut.version = fuzzed_data_provider.ConsumeBool() ? TRUC_VERSION : CTransaction::CURRENT_VERSION;
     387         [ +  + ]:      822689 :                 tx_mut.nLockTime = fuzzed_data_provider.ConsumeBool() ? 0 : fuzzed_data_provider.ConsumeIntegral<uint32_t>();
     388                 :             :                 // Last transaction in a package needs to be a child of parents to get further in validation
     389                 :             :                 // so the last transaction to be generated(in a >1 package) must spend all package-made outputs
     390                 :             :                 // Note that this test currently only spends package outputs in last transaction.
     391   [ +  +  -  +  :      822689 :                 bool last_tx = num_txs > 1 && txs.size() == num_txs - 1;
                   +  + ]
     392                 :      822689 :                 const auto num_in = last_tx ? package_outpoints.size()  : fuzzed_data_provider.ConsumeIntegralInRange<int>(1, mempool_outpoints.size());
     393                 :      822689 :                 auto num_out = fuzzed_data_provider.ConsumeIntegralInRange<int>(1, mempool_outpoints.size() * 2);
     394                 :             : 
     395         [ +  + ]:      822689 :                 auto& outpoints = last_tx ? package_outpoints : mempool_outpoints;
     396                 :             : 
     397         [ -  + ]:      822689 :                 Assert(!outpoints.empty());
     398                 :             : 
     399                 :             :                 CAmount amount_in{0};
     400         [ +  + ]:    16069670 :                 for (size_t i = 0; i < num_in; ++i) {
     401                 :             :                     // Pop random outpoint. We erase them to avoid double-spending
     402                 :             :                     // while in this loop, but later add them back (unless last_tx).
     403                 :    15246981 :                     auto pop = outpoints.begin();
     404                 :    15246981 :                     std::advance(pop, fuzzed_data_provider.ConsumeIntegralInRange<size_t>(0, outpoints.size() - 1));
     405                 :    15246981 :                     const auto outpoint = *pop;
     406                 :    15246981 :                     outpoints.erase(pop);
     407                 :             :                     // no need to update or erase from outpoints_value
     408         [ +  - ]:    15246981 :                     amount_in += outpoints_value.at(outpoint);
     409                 :             : 
     410                 :             :                     // Create input
     411                 :    15246981 :                     const auto sequence = ConsumeSequence(fuzzed_data_provider);
     412                 :    15246981 :                     const auto script_sig = CScript{};
     413   [ +  +  +  - ]:    24058797 :                     const auto script_wit_stack = fuzzed_data_provider.ConsumeBool() ? P2WSH_EMPTY_TRUE_STACK : P2WSH_EMPTY_TWO_STACK;
     414                 :             : 
     415                 :    15246981 :                     CTxIn in;
     416                 :    15246981 :                     in.prevout = outpoint;
     417                 :    15246981 :                     in.nSequence = sequence;
     418                 :    15246981 :                     in.scriptSig = script_sig;
     419         [ +  - ]:    15246981 :                     in.scriptWitness.stack = script_wit_stack;
     420                 :             : 
     421         [ +  - ]:    15246981 :                     tx_mut.vin.push_back(in);
     422                 :    15246981 :                 }
     423                 :             : 
     424                 :             :                 // Duplicate an input
     425                 :      822689 :                 bool dup_input = fuzzed_data_provider.ConsumeBool();
     426         [ +  + ]:      822689 :                 if (dup_input) {
     427         [ +  - ]:      304929 :                     tx_mut.vin.push_back(tx_mut.vin.back());
     428                 :             :                 }
     429                 :             : 
     430                 :             :                 // Refer to a non-existent input
     431         [ +  + ]:      822689 :                 if (fuzzed_data_provider.ConsumeBool()) {
     432         [ +  - ]:      258669 :                     tx_mut.vin.emplace_back();
     433                 :             :                 }
     434                 :             : 
     435                 :             :                 // Make a p2pk output to make sigops adjusted vsize to violate TRUC rules, potentially, which is never spent
     436   [ +  +  +  + ]:      822689 :                 if (last_tx && amount_in > 1000 && fuzzed_data_provider.ConsumeBool()) {
     437   [ +  -  +  -  :      126834 :                     tx_mut.vout.emplace_back(1000, CScript() << std::vector<unsigned char>(33, 0x02) << OP_CHECKSIG);
                   +  - ]
     438                 :             :                     // Don't add any other outputs.
     439                 :       42278 :                     num_out = 1;
     440                 :       42278 :                     amount_in -= 1000;
     441                 :             :                 }
     442                 :             : 
     443                 :      822689 :                 const auto amount_fee = fuzzed_data_provider.ConsumeIntegralInRange<CAmount>(0, amount_in);
     444                 :      822689 :                 const auto amount_out = (amount_in - amount_fee) / num_out;
     445         [ +  + ]:    15190133 :                 for (int i = 0; i < num_out; ++i) {
     446         [ +  - ]:    14367444 :                     tx_mut.vout.emplace_back(amount_out, P2WSH_EMPTY);
     447                 :             :                 }
     448         [ +  - ]:      822689 :                 auto tx = MakeTransactionRef(tx_mut);
     449                 :             :                 // Restore previously removed outpoints, except in-package outpoints
     450         [ +  + ]:      822689 :                 if (!last_tx) {
     451         [ +  + ]:     8647659 :                     for (const auto& in : tx->vin) {
     452                 :             :                         // It's a fake input, or a new input, or a duplicate
     453   [ +  +  +  -  :    16124854 :                         Assert(in == CTxIn() || outpoints.insert(in.prevout).second || dup_input);
          +  +  +  -  -  
                      + ]
     454                 :             :                     }
     455                 :             :                     // Cache the in-package outpoints being made
     456   [ -  +  +  + ]:    13978197 :                     for (size_t i = 0; i < tx->vout.size(); ++i) {
     457         [ +  - ]:    13256581 :                         package_outpoints.emplace(tx->GetHash(), i);
     458                 :             :                     }
     459                 :             :                 }
     460                 :             :                 // We need newly-created values for the duration of this run
     461   [ -  +  +  + ]:    15232411 :                 for (size_t i = 0; i < tx->vout.size(); ++i) {
     462         [ +  - ]:    14409722 :                     outpoints_value[COutPoint(tx->GetHash(), i)] = tx->vout[i].nValue;
     463                 :             :                 }
     464                 :      822689 :                 return tx;
     465         [ +  - ]:     2468067 :             }());
     466                 :             :         }
     467                 :             : 
     468         [ +  + ]:      262703 :         if (fuzzed_data_provider.ConsumeBool()) {
     469         [ +  - ]:      106159 :             MockTime(fuzzed_data_provider, chainstate);
     470                 :             :         }
     471         [ +  + ]:      262703 :         if (fuzzed_data_provider.ConsumeBool()) {
     472         [ +  - ]:       67750 :             tx_pool.RollingFeeUpdate();
     473                 :             :         }
     474         [ +  + ]:      262703 :         if (fuzzed_data_provider.ConsumeBool()) {
     475         [ +  + ]:       93724 :             const auto& txid = fuzzed_data_provider.ConsumeBool() ?
     476                 :       43949 :                                    txs.back()->GetHash() :
     477                 :       49775 :                                    PickValue(fuzzed_data_provider, mempool_outpoints).hash;
     478                 :       93724 :             const auto delta = fuzzed_data_provider.ConsumeIntegralInRange<CAmount>(-50 * COIN, +50 * COIN);
     479         [ +  - ]:       93724 :             tx_pool.PrioritiseTransaction(txid, delta);
     480                 :             :         }
     481                 :             : 
     482                 :             :         // Remember all added transactions
     483         [ +  - ]:      262703 :         std::set<CTransactionRef> added;
     484         [ +  - ]:      262703 :         auto txr = std::make_shared<TransactionsDelta>(added);
     485   [ +  -  +  - ]:      525406 :         node.validation_signals->RegisterSharedValidationInterface(txr);
     486                 :             : 
     487                 :             :         // When there are multiple transactions in the package, we call ProcessNewPackage(txs, test_accept=false)
     488                 :             :         // and AcceptToMemoryPool(txs.back(), test_accept=true). When there is only 1 transaction, we might flip it
     489                 :             :         // (the package is a test accept and ATMP is a submission).
     490   [ -  +  +  +  :      424333 :         auto single_submit = txs.size() == 1 && fuzzed_data_provider.ConsumeBool();
                   +  + ]
     491                 :             : 
     492                 :             :         // Exercise client_maxfeerate logic
     493                 :      262703 :         std::optional<CFeeRate> client_maxfeerate{};
     494         [ +  + ]:      262703 :         if (fuzzed_data_provider.ConsumeBool()) {
     495         [ +  - ]:       62361 :             client_maxfeerate = CFeeRate(fuzzed_data_provider.ConsumeIntegralInRange<CAmount>(-1, 50 * COIN), 100);
     496                 :             :         }
     497                 :             : 
     498         [ +  - ]:      788109 :         const auto result_package = WITH_LOCK(::cs_main,
     499                 :             :                                     return ProcessNewPackage(chainstate, tx_pool, txs, /*test_accept=*/single_submit, client_maxfeerate));
     500                 :             : 
     501                 :             :         // Always set bypass_limits to false because it is not supported in ProcessNewPackage and
     502                 :             :         // can be a source of divergence.
     503   [ +  -  +  - ]:      788109 :         const auto res = WITH_LOCK(::cs_main, return AcceptToMemoryPool(chainstate, txs.back(), GetTime(),
     504                 :             :                                    /*bypass_limits=*/false, /*test_accept=*/!single_submit));
     505                 :      262703 :         const bool passed = res.m_result_type == MempoolAcceptResult::ResultType::VALID;
     506                 :             : 
     507         [ +  - ]:      262703 :         node.validation_signals->SyncWithValidationInterfaceQueue();
     508   [ +  -  +  - ]:      525406 :         node.validation_signals->UnregisterSharedValidationInterface(txr);
     509                 :             : 
     510                 :             :         // There is only 1 transaction in the package. We did a test-package-accept and a ATMP
     511         [ +  + ]:      262703 :         if (single_submit) {
     512         [ -  + ]:       28423 :             Assert(passed != added.empty());
     513         [ -  + ]:       28423 :             Assert(passed == res.m_state.IsValid());
     514         [ +  + ]:       28423 :             if (passed) {
     515         [ -  + ]:        3310 :                 Assert(added.size() == 1);
     516         [ -  + ]:        3310 :                 Assert(txs.back() == *added.begin());
     517                 :             :             }
     518         [ +  + ]:      234280 :         } else if (result_package.m_state.GetResult() != PackageValidationResult::PCKG_POLICY) {
     519                 :             :             // We don't know anything about the validity since transactions were randomly generated, so
     520                 :             :             // just use result_package.m_state here. This makes the expect_valid check meaningless, but
     521                 :             :             // we can still verify that the contents of m_tx_results are consistent with m_state.
     522         [ +  - ]:      180601 :             const bool expect_valid{result_package.m_state.IsValid()};
     523   [ +  -  -  + ]:      180601 :             Assert(!CheckPackageMempoolAcceptResult(txs, result_package, expect_valid, &tx_pool));
     524                 :             :         } else {
     525                 :             :             // This is empty if it fails early checks, or "full" if transactions are looked at deeper
     526   [ -  +  +  +  :      102445 :             Assert(result_package.m_tx_results.size() == txs.size() || result_package.m_tx_results.empty());
             +  -  -  + ]
     527                 :             :         }
     528                 :             : 
     529         [ +  - ]:      262703 :         CheckMempoolTRUCInvariants(tx_pool);
     530                 :             : 
     531                 :             :         // Dust checks only make sense when dust is enforced
     532         [ +  + ]:      262703 :         if (tx_pool.m_opts.require_standard) {
     533         [ +  - ]:      137545 :             CheckMempoolEphemeralInvariants(tx_pool);
     534                 :             :         }
     535         [ +  - ]:      525406 :     }
     536                 :             : 
     537   [ +  -  +  - ]:        4642 :     node.validation_signals->UnregisterSharedValidationInterface(outpoints_updater);
     538                 :             : 
     539   [ +  +  +  -  :        6963 :     WITH_LOCK(::cs_main, tx_pool.check(chainstate.CoinsTip(), chainstate.m_chain.Height() + 1));
                   +  - ]
     540         [ +  - ]:        4642 : }
     541                 :             : } // namespace
        

Generated by: LCOV version 2.0-1