fuzz coverage

Coverage Report

Created: 2025-06-01 19:34

/Users/eugenesiegel/btc/bitcoin/src/coins.cpp
Line
Count
Source (jump to first uncovered line)
1
// Copyright (c) 2012-2022 The Bitcoin Core developers
2
// Distributed under the MIT software license, see the accompanying
3
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
4
5
#include <coins.h>
6
7
#include <consensus/consensus.h>
8
#include <logging.h>
9
#include <random.h>
10
#include <util/trace.h>
11
12
TRACEPOINT_SEMAPHORE(utxocache, add);
13
TRACEPOINT_SEMAPHORE(utxocache, spent);
14
TRACEPOINT_SEMAPHORE(utxocache, uncache);
15
16
0
std::optional<Coin> CCoinsView::GetCoin(const COutPoint& outpoint) const { return std::nullopt; }
17
0
uint256 CCoinsView::GetBestBlock() const { return uint256(); }
18
0
std::vector<uint256> CCoinsView::GetHeadBlocks() const { return std::vector<uint256>(); }
19
0
bool CCoinsView::BatchWrite(CoinsViewCacheCursor& cursor, const uint256 &hashBlock) { return false; }
20
0
std::unique_ptr<CCoinsViewCursor> CCoinsView::Cursor() const { return nullptr; }
21
22
bool CCoinsView::HaveCoin(const COutPoint &outpoint) const
23
0
{
24
0
    return GetCoin(outpoint).has_value();
25
0
}
26
27
30.2M
CCoinsViewBacked::CCoinsViewBacked(CCoinsView *viewIn) : base(viewIn) { }
28
39.9M
std::optional<Coin> CCoinsViewBacked::GetCoin(const COutPoint& outpoint) const { return base->GetCoin(outpoint); }
29
0
bool CCoinsViewBacked::HaveCoin(const COutPoint &outpoint) const { return base->HaveCoin(outpoint); }
30
149k
uint256 CCoinsViewBacked::GetBestBlock() const { return base->GetBestBlock(); }
31
0
std::vector<uint256> CCoinsViewBacked::GetHeadBlocks() const { return base->GetHeadBlocks(); }
32
0
void CCoinsViewBacked::SetBackend(CCoinsView &viewIn) { base = &viewIn; }
33
517
bool CCoinsViewBacked::BatchWrite(CoinsViewCacheCursor& cursor, const uint256 &hashBlock) { return base->BatchWrite(cursor, hashBlock); }
34
0
std::unique_ptr<CCoinsViewCursor> CCoinsViewBacked::Cursor() const { return base->Cursor(); }
35
0
size_t CCoinsViewBacked::EstimateSize() const { return base->EstimateSize(); }
36
37
CCoinsViewCache::CCoinsViewCache(CCoinsView* baseIn, bool deterministic) :
38
30.1M
    CCoinsViewBacked(baseIn), m_deterministic(deterministic),
39
30.1M
    cacheCoins(0, SaltedOutpointHasher(/*deterministic=*/deterministic), CCoinsMap::key_equal{}, &m_cache_coins_memory_resource)
40
30.1M
{
41
30.1M
    m_sentinel.second.SelfRef(m_sentinel);
42
30.1M
}
43
44
70.2M
size_t CCoinsViewCache::DynamicMemoryUsage() const {
45
70.2M
    return memusage::DynamicUsage(cacheCoins) + cachedCoinsUsage;
46
70.2M
}
47
48
79.9M
CCoinsMap::iterator CCoinsViewCache::FetchCoin(const COutPoint &outpoint) const {
49
79.9M
    const auto [ret, inserted] = cacheCoins.try_emplace(outpoint);
50
79.9M
    if (inserted) {
51
79.9M
        if (auto coin{base->GetCoin(outpoint)}) {
52
55
            ret->second.coin = std::move(*coin);
53
55
            cachedCoinsUsage += ret->second.coin.DynamicMemoryUsage();
54
55
            if (ret->second.coin.IsSpent()) { // TODO GetCoin cannot return spent coins
55
                // The parent only has an empty entry for this outpoint; we can consider our version as fresh.
56
0
                CCoinsCacheEntry::SetFresh(*ret, m_sentinel);
57
0
            }
58
79.9M
        } else {
59
79.9M
            cacheCoins.erase(ret);
60
79.9M
            return cacheCoins.end();
61
79.9M
        }
62
79.9M
    }
63
165
    return ret;
64
79.9M
}
65
66
std::optional<Coin> CCoinsViewCache::GetCoin(const COutPoint& outpoint) const
67
39.9M
{
68
39.9M
    if (auto it{FetchCoin(outpoint)}; it != cacheCoins.end() && 
!it->second.coin.IsSpent()110
)
return it->second.coin55
;
69
39.9M
    return std::nullopt;
70
39.9M
}
71
72
39.9M
void CCoinsViewCache::AddCoin(const COutPoint &outpoint, Coin&& coin, bool possible_overwrite) {
73
39.9M
    assert(!coin.IsSpent());
74
39.9M
    if (coin.out.scriptPubKey.IsUnspendable()) 
return19.9M
;
75
19.9M
    CCoinsMap::iterator it;
76
19.9M
    bool inserted;
77
19.9M
    std::tie(it, inserted) = cacheCoins.emplace(std::piecewise_construct, std::forward_as_tuple(outpoint), std::tuple<>());
78
19.9M
    bool fresh = false;
79
19.9M
    if (!inserted) {
80
0
        cachedCoinsUsage -= it->second.coin.DynamicMemoryUsage();
81
0
    }
82
19.9M
    if (!possible_overwrite) {
83
0
        if (!it->second.coin.IsSpent()) {
84
0
            throw std::logic_error("Attempted to overwrite an unspent coin (when possible_overwrite is false)");
85
0
        }
86
        // If the coin exists in this cache as a spent coin and is DIRTY, then
87
        // its spentness hasn't been flushed to the parent cache. We're
88
        // re-adding the coin to this cache now but we can't mark it as FRESH.
89
        // If we mark it FRESH and then spend it before the cache is flushed
90
        // we would remove it from this cache and would never flush spentness
91
        // to the parent cache.
92
        //
93
        // Re-adding a spent coin can happen in the case of a re-org (the coin
94
        // is 'spent' when the block adding it is disconnected and then
95
        // re-added when it is also added in a newly connected block).
96
        //
97
        // If the coin doesn't exist in the current cache, or is spent but not
98
        // DIRTY, then it can be marked FRESH.
99
0
        fresh = !it->second.IsDirty();
100
0
    }
101
19.9M
    it->second.coin = std::move(coin);
102
19.9M
    CCoinsCacheEntry::SetDirty(*it, m_sentinel);
103
19.9M
    if (fresh) 
CCoinsCacheEntry::SetFresh(*it, m_sentinel)0
;
104
19.9M
    cachedCoinsUsage += it->second.coin.DynamicMemoryUsage();
105
19.9M
    TRACEPOINT(utxocache, add,
106
19.9M
           outpoint.hash.data(),
107
19.9M
           (uint32_t)outpoint.n,
108
19.9M
           (uint32_t)it->second.coin.nHeight,
109
19.9M
           (int64_t)it->second.coin.out.nValue,
110
19.9M
           (bool)it->second.coin.IsCoinBase());
111
19.9M
}
112
113
0
void CCoinsViewCache::EmplaceCoinInternalDANGER(COutPoint&& outpoint, Coin&& coin) {
114
0
    cachedCoinsUsage += coin.DynamicMemoryUsage();
115
0
    auto [it, inserted] = cacheCoins.try_emplace(std::move(outpoint), std::move(coin));
116
0
    if (inserted) CCoinsCacheEntry::SetDirty(*it, m_sentinel);
117
0
}
118
119
19.9M
void AddCoins(CCoinsViewCache& cache, const CTransaction &tx, int nHeight, bool check_for_overwrite) {
120
19.9M
    bool fCoinbase = tx.IsCoinBase();
121
19.9M
    const Txid& txid = tx.GetHash();
122
59.9M
    for (size_t i = 0; i < tx.vout.size(); 
++i39.9M
) {
123
39.9M
        bool overwrite = check_for_overwrite ? 
cache.HaveCoin(COutPoint(txid, i))0
: fCoinbase;
124
        // Coinbase transactions can always be overwritten, in order to correctly
125
        // deal with the pre-BIP30 occurrences of duplicate coinbase transactions.
126
39.9M
        cache.AddCoin(COutPoint(txid, i), Coin(tx.vout[i], nHeight, fCoinbase), overwrite);
127
39.9M
    }
128
19.9M
}
129
130
55
bool CCoinsViewCache::SpendCoin(const COutPoint &outpoint, Coin* moveout) {
131
55
    CCoinsMap::iterator it = FetchCoin(outpoint);
132
55
    if (it == cacheCoins.end()) 
return false0
;
133
55
    cachedCoinsUsage -= it->second.coin.DynamicMemoryUsage();
134
55
    TRACEPOINT(utxocache, spent,
135
55
           outpoint.hash.data(),
136
55
           (uint32_t)outpoint.n,
137
55
           (uint32_t)it->second.coin.nHeight,
138
55
           (int64_t)it->second.coin.out.nValue,
139
55
           (bool)it->second.coin.IsCoinBase());
140
55
    if (moveout) {
141
55
        *moveout = std::move(it->second.coin);
142
55
    }
143
55
    if (it->second.IsFresh()) {
144
0
        cacheCoins.erase(it);
145
55
    } else {
146
55
        CCoinsCacheEntry::SetDirty(*it, m_sentinel);
147
55
        it->second.coin.Clear();
148
55
    }
149
55
    return true;
150
55
}
151
152
static const Coin coinEmpty;
153
154
0
const Coin& CCoinsViewCache::AccessCoin(const COutPoint &outpoint) const {
155
0
    CCoinsMap::const_iterator it = FetchCoin(outpoint);
156
0
    if (it == cacheCoins.end()) {
157
0
        return coinEmpty;
158
0
    } else {
159
0
        return it->second.coin;
160
0
    }
161
0
}
162
163
39.9M
bool CCoinsViewCache::HaveCoin(const COutPoint &outpoint) const {
164
39.9M
    CCoinsMap::const_iterator it = FetchCoin(outpoint);
165
39.9M
    return (it != cacheCoins.end() && 
!it->second.coin.IsSpent()0
);
166
39.9M
}
167
168
0
bool CCoinsViewCache::HaveCoinInCache(const COutPoint &outpoint) const {
169
0
    CCoinsMap::const_iterator it = cacheCoins.find(outpoint);
170
0
    return (it != cacheCoins.end() && !it->second.coin.IsSpent());
171
0
}
172
173
40.1M
uint256 CCoinsViewCache::GetBestBlock() const {
174
40.1M
    if (hashBlock.IsNull())
175
20.1M
        hashBlock = base->GetBestBlock();
176
40.1M
    return hashBlock;
177
40.1M
}
178
179
10.0M
void CCoinsViewCache::SetBestBlock(const uint256 &hashBlockIn) {
180
10.0M
    hashBlock = hashBlockIn;
181
10.0M
}
182
183
10.0M
bool CCoinsViewCache::BatchWrite(CoinsViewCacheCursor& cursor, const uint256 &hashBlockIn) {
184
20.0M
    for (auto it{cursor.Begin()}; it != cursor.End(); 
it = cursor.NextAndMaybeErase(*it)9.99M
) {
185
        // Ignore non-dirty entries (optimization).
186
9.99M
        if (!it->second.IsDirty()) {
187
0
            continue;
188
0
        }
189
9.99M
        CCoinsMap::iterator itUs = cacheCoins.find(it->first);
190
9.99M
        if (itUs == cacheCoins.end()) {
191
            // The parent cache does not have an entry, while the child cache does.
192
            // We can ignore it if it's both spent and FRESH in the child
193
9.99M
            if (!(it->second.IsFresh() && 
it->second.coin.IsSpent()0
)) {
194
                // Create the coin in the parent cache, move the data up
195
                // and mark it as dirty.
196
9.99M
                itUs = cacheCoins.try_emplace(it->first).first;
197
9.99M
                CCoinsCacheEntry& entry{itUs->second};
198
9.99M
                if (cursor.WillErase(*it)) {
199
                    // Since this entry will be erased,
200
                    // we can move the coin into us instead of copying it
201
9.99M
                    entry.coin = std::move(it->second.coin);
202
9.99M
                } else {
203
0
                    entry.coin = it->second.coin;
204
0
                }
205
9.99M
                cachedCoinsUsage += entry.coin.DynamicMemoryUsage();
206
9.99M
                CCoinsCacheEntry::SetDirty(*itUs, m_sentinel);
207
                // We can mark it FRESH in the parent if it was FRESH in the child
208
                // Otherwise it might have just been flushed from the parent's cache
209
                // and already exist in the grandparent
210
9.99M
                if (it->second.IsFresh()) 
CCoinsCacheEntry::SetFresh(*itUs, m_sentinel)0
;
211
9.99M
            }
212
9.99M
        } else {
213
            // Found the entry in the parent cache
214
110
            if (it->second.IsFresh() && 
!itUs->second.coin.IsSpent()0
) {
215
                // The coin was marked FRESH in the child cache, but the coin
216
                // exists in the parent cache. If this ever happens, it means
217
                // the FRESH flag was misapplied and there is a logic error in
218
                // the calling code.
219
0
                throw std::logic_error("FRESH flag misapplied to coin that exists in parent cache");
220
0
            }
221
222
110
            if (itUs->second.IsFresh() && 
it->second.coin.IsSpent()0
) {
223
                // The grandparent cache does not have an entry, and the coin
224
                // has been spent. We can just delete it from the parent cache.
225
0
                cachedCoinsUsage -= itUs->second.coin.DynamicMemoryUsage();
226
0
                cacheCoins.erase(itUs);
227
110
            } else {
228
                // A normal modification.
229
110
                cachedCoinsUsage -= itUs->second.coin.DynamicMemoryUsage();
230
110
                if (cursor.WillErase(*it)) {
231
                    // Since this entry will be erased,
232
                    // we can move the coin into us instead of copying it
233
110
                    itUs->second.coin = std::move(it->second.coin);
234
110
                } else {
235
0
                    itUs->second.coin = it->second.coin;
236
0
                }
237
110
                cachedCoinsUsage += itUs->second.coin.DynamicMemoryUsage();
238
110
                CCoinsCacheEntry::SetDirty(*itUs, m_sentinel);
239
                // NOTE: It isn't safe to mark the coin as FRESH in the parent
240
                // cache. If it already existed and was spent in the parent
241
                // cache then marking it FRESH would prevent that spentness
242
                // from being flushed to the grandparent.
243
110
            }
244
110
        }
245
9.99M
    }
246
10.0M
    hashBlock = hashBlockIn;
247
10.0M
    return true;
248
10.0M
}
249
250
10.0M
bool CCoinsViewCache::Flush() {
251
10.0M
    auto cursor{CoinsViewCacheCursor(cachedCoinsUsage, m_sentinel, cacheCoins, /*will_erase=*/true)};
252
10.0M
    bool fOk = base->BatchWrite(cursor, hashBlock);
253
10.0M
    if (fOk) {
254
10.0M
        cacheCoins.clear();
255
10.0M
        ReallocateCache();
256
10.0M
    }
257
10.0M
    cachedCoinsUsage = 0;
258
10.0M
    return fOk;
259
10.0M
}
260
261
bool CCoinsViewCache::Sync()
262
517
{
263
517
    auto cursor{CoinsViewCacheCursor(cachedCoinsUsage, m_sentinel, cacheCoins, /*will_erase=*/false)};
264
517
    bool fOk = base->BatchWrite(cursor, hashBlock);
265
517
    if (fOk) {
266
517
        if (m_sentinel.second.Next() != &m_sentinel) {
267
            /* BatchWrite must clear flags of all entries */
268
0
            throw std::logic_error("Not all unspent flagged entries were cleared");
269
0
        }
270
517
    }
271
517
    return fOk;
272
517
}
273
274
void CCoinsViewCache::Uncache(const COutPoint& hash)
275
0
{
276
0
    CCoinsMap::iterator it = cacheCoins.find(hash);
277
0
    if (it != cacheCoins.end() && !it->second.IsDirty() && !it->second.IsFresh()) {
278
0
        cachedCoinsUsage -= it->second.coin.DynamicMemoryUsage();
279
0
        TRACEPOINT(utxocache, uncache,
280
0
               hash.hash.data(),
281
0
               (uint32_t)hash.n,
282
0
               (uint32_t)it->second.coin.nHeight,
283
0
               (int64_t)it->second.coin.out.nValue,
284
0
               (bool)it->second.coin.IsCoinBase());
285
0
        cacheCoins.erase(it);
286
0
    }
287
0
}
288
289
40.1M
unsigned int CCoinsViewCache::GetCacheSize() const {
290
40.1M
    return cacheCoins.size();
291
40.1M
}
292
293
bool CCoinsViewCache::HaveInputs(const CTransaction& tx) const
294
0
{
295
0
    if (!tx.IsCoinBase()) {
296
0
        for (unsigned int i = 0; i < tx.vin.size(); i++) {
297
0
            if (!HaveCoin(tx.vin[i].prevout)) {
298
0
                return false;
299
0
            }
300
0
        }
301
0
    }
302
0
    return true;
303
0
}
304
305
void CCoinsViewCache::ReallocateCache()
306
10.0M
{
307
    // Cache should be empty when we're calling this.
308
10.0M
    assert(cacheCoins.size() == 0);
309
10.0M
    cacheCoins.~CCoinsMap();
310
10.0M
    m_cache_coins_memory_resource.~CCoinsMapMemoryResource();
311
10.0M
    ::new (&m_cache_coins_memory_resource) CCoinsMapMemoryResource{};
312
10.0M
    ::new (&cacheCoins) CCoinsMap{0, SaltedOutpointHasher{/*deterministic=*/m_deterministic}, CCoinsMap::key_equal{}, &m_cache_coins_memory_resource};
313
10.0M
}
314
315
void CCoinsViewCache::SanityCheck() const
316
0
{
317
0
    size_t recomputed_usage = 0;
318
0
    size_t count_flagged = 0;
319
0
    for (const auto& [_, entry] : cacheCoins) {
320
0
        unsigned attr = 0;
321
0
        if (entry.IsDirty()) attr |= 1;
322
0
        if (entry.IsFresh()) attr |= 2;
323
0
        if (entry.coin.IsSpent()) attr |= 4;
324
        // Only 5 combinations are possible.
325
0
        assert(attr != 2 && attr != 4 && attr != 7);
326
327
        // Recompute cachedCoinsUsage.
328
0
        recomputed_usage += entry.coin.DynamicMemoryUsage();
329
330
        // Count the number of entries we expect in the linked list.
331
0
        if (entry.IsDirty() || entry.IsFresh()) ++count_flagged;
332
0
    }
333
    // Iterate over the linked list of flagged entries.
334
0
    size_t count_linked = 0;
335
0
    for (auto it = m_sentinel.second.Next(); it != &m_sentinel; it = it->second.Next()) {
336
        // Verify linked list integrity.
337
0
        assert(it->second.Next()->second.Prev() == it);
338
0
        assert(it->second.Prev()->second.Next() == it);
339
        // Verify they are actually flagged.
340
0
        assert(it->second.IsDirty() || it->second.IsFresh());
341
        // Count the number of entries actually in the list.
342
0
        ++count_linked;
343
0
    }
344
0
    assert(count_linked == count_flagged);
345
0
    assert(recomputed_usage == cachedCoinsUsage);
346
0
}
347
348
static const size_t MIN_TRANSACTION_OUTPUT_WEIGHT = WITNESS_SCALE_FACTOR * ::GetSerializeSize(CTxOut());
349
static const size_t MAX_OUTPUTS_PER_BLOCK = MAX_BLOCK_WEIGHT / MIN_TRANSACTION_OUTPUT_WEIGHT;
350
351
const Coin& AccessByTxid(const CCoinsViewCache& view, const Txid& txid)
352
0
{
353
0
    COutPoint iter(txid, 0);
354
0
    while (iter.n < MAX_OUTPUTS_PER_BLOCK) {
355
0
        const Coin& alternate = view.AccessCoin(iter);
356
0
        if (!alternate.IsSpent()) return alternate;
357
0
        ++iter.n;
358
0
    }
359
0
    return coinEmpty;
360
0
}
361
362
template <typename ReturnType, typename Func>
363
static ReturnType ExecuteBackedWrapper(Func func, const std::vector<std::function<void()>>& err_callbacks)
364
39.9M
{
365
39.9M
    try {
366
39.9M
        return func();
367
39.9M
    } catch(const std::runtime_error& e) {
368
0
        for (const auto& f : err_callbacks) {
369
0
            f();
370
0
        }
371
0
        LogError("Error reading from database: %s\n", e.what());
Line
Count
Source
263
0
#define LogError(...) LogPrintLevel_(BCLog::LogFlags::ALL, BCLog::Level::Error, __VA_ARGS__)
Line
Count
Source
255
0
#define LogPrintLevel_(category, level, ...) LogPrintFormatInternal(__func__, __FILE__, __LINE__, category, level, __VA_ARGS__)
        LogError("Error reading from database: %s\n", e.what());
Line
Count
Source
263
0
#define LogError(...) LogPrintLevel_(BCLog::LogFlags::ALL, BCLog::Level::Error, __VA_ARGS__)
Line
Count
Source
255
0
#define LogPrintLevel_(category, level, ...) LogPrintFormatInternal(__func__, __FILE__, __LINE__, category, level, __VA_ARGS__)
372
        // Starting the shutdown sequence and returning false to the caller would be
373
        // interpreted as 'entry not found' (as opposed to unable to read data), and
374
        // could lead to invalid interpretation. Just exit immediately, as we can't
375
        // continue anyway, and all writes should be atomic.
376
0
        std::abort();
377
0
    }
378
39.9M
}
coins.cpp:_ZL20ExecuteBackedWrapperINSt3__18optionalI4CoinEEZNK22CCoinsViewErrorCatcher7GetCoinERK9COutPointE3$_0ET_T0_RKNS0_6vectorINS0_8functionIFvvEEENS0_9allocatorISE_EEEE
Line
Count
Source
364
39.9M
{
365
39.9M
    try {
366
39.9M
        return func();
367
39.9M
    } catch(const std::runtime_error& e) {
368
0
        for (const auto& f : err_callbacks) {
369
0
            f();
370
0
        }
371
0
        LogError("Error reading from database: %s\n", e.what());
Line
Count
Source
263
0
#define LogError(...) LogPrintLevel_(BCLog::LogFlags::ALL, BCLog::Level::Error, __VA_ARGS__)
Line
Count
Source
255
0
#define LogPrintLevel_(category, level, ...) LogPrintFormatInternal(__func__, __FILE__, __LINE__, category, level, __VA_ARGS__)
372
        // Starting the shutdown sequence and returning false to the caller would be
373
        // interpreted as 'entry not found' (as opposed to unable to read data), and
374
        // could lead to invalid interpretation. Just exit immediately, as we can't
375
        // continue anyway, and all writes should be atomic.
376
0
        std::abort();
377
0
    }
378
39.9M
}
Unexecuted instantiation: coins.cpp:_ZL20ExecuteBackedWrapperIbZNK22CCoinsViewErrorCatcher8HaveCoinERK9COutPointE3$_0ET_T0_RKNSt3__16vectorINS7_8functionIFvvEEENS7_9allocatorISB_EEEE
379
380
std::optional<Coin> CCoinsViewErrorCatcher::GetCoin(const COutPoint& outpoint) const
381
39.9M
{
382
39.9M
    return ExecuteBackedWrapper<std::optional<Coin>>([&]() { return CCoinsViewBacked::GetCoin(outpoint); }, m_err_callbacks);
383
39.9M
}
384
385
bool CCoinsViewErrorCatcher::HaveCoin(const COutPoint& outpoint) const
386
0
{
387
0
    return ExecuteBackedWrapper<bool>([&]() { return CCoinsViewBacked::HaveCoin(outpoint); }, m_err_callbacks);
388
0
}