Repository navigation
Commit d1e64da
committed
Merge #7639: feat: version 2 asset unlocks with stable txids and InstantSend locks (DIP-0027 amendment, v24)
d62becf fix(mempool): apply the asset unlock eviction check to package test acceptance (pasta)
38e953b fix(llmq): preserve legacy signature truncation bookkeeping (pasta)
1ba8ba0 fix(mempool): widen pending withdrawal accounting (pasta)
23c5045 fix(mempool): preserve package dependencies during unlock replacement (pasta)
8d91c72 fix(llmq): retain Platform recovered signatures per message (pasta)
f906977 fix(mempool): reject duplicate withdrawal indexes before package admission (pasta)
ce36a13 fix: protect asset unlock package parents (pasta)
5391ac4 fix(net): do not put the shared txid of a rejected asset unlock into the rejects filter (UdjinM6)
6fff8db fix(net): keep the lock of a held asset unlock when another instance is rejected (UdjinM6)
43d81ed test: reproduce asset unlock v2 lock removal and shared-txid reject filtering (UdjinM6)
61be75a test: exercise quorumSig in the asset unlock txid and commitment tests (pasta)
430fb7a fix(net): keep DSTX validation for version 2 asset unlocks and dedup them by txid too (pasta)
480f6e8 fix(instantsend): bound asset unlock lock retries and refuse locks on credit pool failure (pasta)
6965e50 fix(mempool): guard the credit pool lookup and hold one claimant per withdrawal index (pasta)
0325195 fix(evo): persist the credit pool snapshot once a block connection hits a cached pool (pasta)
c93ee22 fix(primitives): compute the asset unlock instance hash on demand (pasta)
070f410 test: cover InstantSend locks on version 2 asset unlocks (pasta)
22af9d6 feat(instantsend): lock version 2 asset unlocks by their withdrawal index (pasta)
682a059 feat(mempool): track pending asset unlock amount and withdrawal indexes (pasta)
f54ef8b test: cover version 2 asset unlocks in feature_asset_locks.py (pasta)
4fe11ce feat(rpc): expose asset unlock instance hashes and align platform signing with withdrawal re-signs (pasta)
e22d5f4 feat(net): relay version 2 asset unlocks by instance hash (pasta)
ac2039a feat(mempool): refresh pending withdrawals in place and retain expired version 2 asset unlocks (pasta)
8503c5d fix(evo): only write credit pool disk snapshots inside a block-scoped EvoDB transaction (pasta)
62845d2 feat(consensus): commit to asset unlock instance hashes in the coinbase transaction (pasta)
ab1ceb3 feat(consensus): compute version 2 asset unlock txids with the quorum signing info zeroed (pasta)
Pull request description:
## Issue being fixed or feature implemented
Users want Platform→Core withdrawals to be rapidly respendable with InstantSend finality. Today that is impossible: an Asset Unlock can expire before it is mined, Platform then re-signs the withdrawal, and because the re-signed transaction has a different txid, any transaction spending the unmined unlock's outputs is invalidated — so spends of unmined unlocks can never be islocked.
This PR implements **version 2 Asset Unlock transactions** (spec: dashpay/dips#189), activating with `DEPLOYMENT_V24`: the **txid itself is computed with the quorum signing info (`requestedHeight`, `quorumHash`, `quorumSig`) zeroed** — exactly and provably the only fields Platform changes when it re-signs an expired withdrawal. Every re-signed instance of one withdrawal is therefore *the same transaction*: children reference one stable txid forever and survive expiry and re-signing. This is segwit's txid/wtxid split applied to the quorum-sig fields — no aliasing in the mempool, UTXO set, or wallet layers; the spending model stays completely standard.
On top of that, **the unlock itself is InstantSend-locked** as soon as it can be mined in the next block, using its withdrawal index as a synthetic input. An islock attests "this will be mined and nothing in consensus prevents it"; for an unlock that holds as long as Platform keeps re-signing, which it is obligated to do (there is no refund path), and signing only minable-now instances makes any failure a double fault. Once locked, the withdrawal is like any other locked transaction: children are ordinary islocked spends, the wallet trusts its outputs, and Platform→Core transfers become rapidly respendable.
## What was done?
**Consensus — hashing rule** (`primitives/transaction`, `evo/assetlocktx`)
- v2 payloads are serialized byte-identically to v1; the version byte (gated on v24, `bad-assetunlocktx-version-2`, mirroring Asset Lock v2) changes hashing: the txid zeroes the trailing 132 payload bytes. The full-serialization hash remains available as `GetInstanceHash()` (computed on demand for v2 unlocks, equal to the txid for every other transaction).
- The signed message hash is unchanged — it zeroes only `quorumSig` and still commits to `requestedHeight`/`quorumHash` — and is now computed explicitly from the full serialization (using `GetHash()` on the sig-zeroed copy would silently zero all three fields under the new rule). Signature validity rules (48-block window, active-quorum-set+1 recency) are identical to v1.
**Consensus — coinbase commitment** (`evo/cbtx`, `validation`, `node/miner`, `blockencodings`)
- v2 txids exclude the sig bytes, so the block merkle root no longer commits to them. CbTx **version 4** (required post-v24) adds `merkleRootAssetUnlocks`: the merkle root over the instance hashes of the block's v2 unlocks (null when none). Verified in `CheckMerkleRoot` as a **mutation** check (`bad-cbtx-assetunlockmerkleroot`, `BLOCK_MUTATED`), mirroring segwit's witness commitment: a middleman can flip sig bytes without breaking the merkle root, and treating that as invalidity would let it poison an honest block's hash.
- Compact block short IDs are computed from instance hashes (BIP152v2's wtxid move): a mempool entry holding a *different* re-signed instance of a mined withdrawal is requested via `getblocktxn` instead of being spliced into the reconstructed block; `FillBlock`'s existing `IsBlockMutated` check backstops short-ID collisions.
**Mempool** (`validation`, `txmempool`, `node/transaction`, `node/miner`)
- A re-signed instance shares the entry's txid; ATMP routes it through a refresh path that fully validates it and, when `requestedHeight` is higher, swaps the `CTransactionRef` **in place** — descendants, ancestry, and fee accounting untouched because everything the txid covers is identical. Stale/duplicate instances are rejected (`assetunlock-stale-instance`). `sendrawtransaction` submits refreshes instead of short-circuiting on the known txid.
- v2 unlocks are **not expiry-evicted**: an expired instance waits in the mempool for its replacement, so children never die with it; the miner instead skips instances that aren't currently minable. Since unlocks have no inputs, a new outputs-already-known check prevents an already-mined instance from re-entering (and, for v2, lingering).
- The mempool tracks the **pending withdrawal total** (outputs + fee of every unlock it holds, the quantity the credit pool charges) and a withdrawal-index map. The credit pool limit is enforced only at block connect, so this is what lets InstantSend tell an over-limit unlock from a minable one. Exposed as `getmempoolinfo.pendingassetunlocks`. Mining any instance of a withdrawal evicts every other instance claiming its index.
- At most **one claimant per withdrawal index** is held: a second unlock claiming an index under a different txid (a v1 instance signed pre-fork re-signed as v2 post-fork, or a Platform fault) is rejected as `assetunlock-stale-instance` unless its `requestedHeight` is higher, in which case it evicts the held claimant and its descendants, mirroring the in-place refresh. Checked before signature verification. The credit pool lookup in ATMP is wrapped: a local reconstruction failure is a `TX_BAD_SPECIAL` rejection (no peer punishment) and EvoDB corruption an error state, never an escaped exception.
**InstantSend** (`instantsend/*`, `validation`)
- **The v2 unlock itself is islocked**, not just its children. Unlocks have no inputs, so the lock pins one synthetic outpoint: `{DIP-27 request id = SHA256d("plwdtx" ‖ index), 0}` (`instantsend::GetLockInputs`). Every instance of one withdrawal, whatever its version or txid, maps to that outpoint, so a lock binds the index to one txid, any other claimant conflicts through the ordinary outpoint conflict path, and a re-sign (same txid) leaves the lock intact. Wire format unchanged.
- Masternodes sign the lock only when the unlock is **minable in the next block** (`CheckCanLockAssetUnlock`): stable-txid instance, passes the full special-tx check at the tip including its quorum signature, no other instance of its index in the mempool (a withdrawal signed as v1 pre-fork can be re-signed as v2 post-fork under a different txid), and the mempool's pending withdrawal total fits the credit pool's current limit. Platform pools withdrawals under the same limit, so a pending total above it indicates a fault and nothing is signed until the window clears. Both the height window and the limit move with the tip, so every tracked unmined unlock is re-evaluated on each connected block; a refresh re-triggers an attempt too.
- Consequences that fall out for free: children are ordinary islocked spends (the rev-3 `CheckCanLock` exception is gone), the wallet trusts a locked withdrawal's outputs via `IsTxLockedByInstantSend`, and the mempool's time-based expiry already spares locked transactions.
- Every `vin.empty()` early-out in InstantSend (including the IS-DB block hooks that mark locks mined and the block-connect conflict filter) goes through `HasLockInputs`. A peer islock on an unlock whose inputs are anything but the synthetic outpoint is dropped. Mined unlocks are tracked but not locked retroactively, since ChainLocks never wait for them.
- `getassetunlockstatuses` reports `instantlock` for mempooled indexes.
**P2P relay** (`net_processing`, `protocol`, `version`)
- txid-based announcement can never propagate a refresh (known-txid dedup; rejects-filter poisoning). New `MSG_ASSET_UNLOCK` inventory type (protocol **70242**) announces v2 unlocks **by instance hash**; getdata is answered with a plain `tx` message; requests and the rejects filter are tracked per instance. Older peers get a `MSG_TX` announcement of the current instance and never see refreshes.
**RPC & signing tooling** (`core_write`, `rpc/quorums`, `llmq/signing*`)
- `instanceHash` in v2 unlock JSON. `platformsign` allows re-signing a request id with a different message hash. Platform recovered signatures are retained per message and retrieved by the requested message hash, so out-of-order delivery preserves both signatures. Share processing stops only for a matching Platform message, including on members that learned the earlier signature without voting. Each retained signature expires independently. Production Platform signing (Tenderdash vote extensions) is unaffected; this aligns Core's local signing path used by tests/tooling.
**Tests**
- Unit: txid invariance across the signing fields (and only those), `CMutableTransaction` agreement, msgHash semantics, v1 hashing unchanged, DIP-0027 worked-example vectors, CbTx unlock-root calculation.
- Unit: lock inputs of an unlock (synthetic outpoint, same for every version/instance of an index, distinct per index; ordinary txs / commitments / coinbase unchanged); mempool pending amount and index map across add, refresh, cross-version duplicate, index-conflict eviction and removal.
- Unit: ATMP rejects a staler claimant of a held withdrawal index before signature verification; credit pool snapshot persisted at a snapshot height when block assembly constructed the pool first; InstantSend tracker drops an unlocked unlock removed from the mempool and hands a queued unlock out once per trigger.
- Functional (`feature_asset_locks.py`): pre-fork v2 rejection; spend of an unmined v2 unlock by its stable txid; refresh in place (same txid, child untouched, `instanceHash` rotates); `MSG_ASSET_UNLOCK` inv observed for both the initial instance and the refresh; stale-instance rejection; survival of the expired instance + child; window clearing; fresh re-sign mined together with the child; CbTx v4 commitment asserted against the mined instance hash. With InstantSend enabled: the unlock is **not** locked while the pending total exceeds the limit (an ordinary tx is), the wallet does not trust the child's output, the re-signed minable instance within the limit **is** locked with the withdrawal index as its single input, the child is then locked through the ordinary path and trusted by the wallet, and a second withdrawal refused on the limit is locked by the per-block retry once the window clears and it is refreshed. Cross-version claimants: a v2 instance signed at the same height as the held v1 instance is rejected, a v2 unlock wrapped in a `dstx` message goes through DSTX validation and is dropped, and a v2 instance signed one block later replaces the v1 claimant and gets locked.
## How Has This Been Tested?
- `feature_asset_locks.py` passes locally (macOS arm64) including the extended `test_asset_unlock_v2` scenario; also `feature_llmq_is_retroactive.py`, `feature_llmq_is_cl_conflicts.py`, `feature_llmq_chainlocks.py`, `feature_llmq_singlenode.py`, `feature_notifications.py`, `rpc_netinfo.py`, `p2p_dstx.py`, `feature_protx_version.py`, `mempool_unbroadcast.py`, `interface_rest.py`, `wallet_basic.py`.
- Full `test_dash` unit suite passes.
- Lints: circular dependencies (two new expected entries registered), whitespace, python, assertions.
- The DIP worked-example vectors produced by `dip-0027/dip-0027-txid-calc.py` match Core's hashing byte-for-byte (pinned in a unit test).
## Breaking Changes
- **Consensus (v24 EHF, inactive until params are set):** v2 Asset Unlock payloads become acceptable and CbTx v4 becomes required once v24 activates; before activation both are rejected. **This must be code-complete before the v24 EHF parameters (bit 12, currently `NEVER_ACTIVE`) are finalized.**
- **Hashing:** for v2 unlocks (which cannot exist pre-fork), `txid ≠ H(full serialization)`. Light clients verifying merkle proofs for these transactions and explorer libraries computing txids from raw bytes need the one scoped rule; SPV output tracking and spending are otherwise completely standard.
- P2P: protocol bumped to 70242 for the `MSG_ASSET_UNLOCK` inventory type.
Known follow-ups (deliberately out of scope):
- Platform-side emitter PR (payload version byte + deterministic v24 gate on `core_chain_locked_height`); Platform's Tenderdash signing already produces the unchanged message hash.
- Restart gap: `LoadMempool` re-runs acceptance, so an *expired* v2 instance (and its children) is dropped on restart until the refresh arrives; the islock itself is persisted in the IS DB and wallet rebroadcast heals it. Accepting an expired instance whose txid is islocked on reload is a possible refinement.
- Ecosystem: anything computing txids from raw bytes (rust-dashcore `Transaction::txid()`, dash-spv, DashSync, dashj, explorers) needs the scoped v2 rule before activation.
- p2p-level regression tests for the legacy-peer (<70242) `MSG_TX` announcement path and for the rejects-filter poisoning scenario a rejected instance is announced over p2p, then a fresh instance must still propagate. The current functional test exercises the mempool refresh and `MSG_ASSET_UNLOCK` inv end-to-end but drives the stale-instance rejection via `sendrawtransaction`.
- The wallet keeps whatever instance it first saw (`AddToWallet` is a no-op on a known txid), so `gettransaction` may show a stale instance's `requestedHeight`/`quorumSig`; ZMQ/index consumers do observe each refresh. No fund-safety impact (outputs are identical across instances).
- Multi-transaction `testmempoolaccept` still rejects held unlocks as duplicate txids; single-transaction submission and `submitpackage` support instance refresh. Package preflight rejects duplicate withdrawal indexes before any submission, including when all claimants are new, and both `submitpackage` and multi-transaction `testmempoolaccept` reject a package that spends a mempool claimant (or one of its descendants) that admitting a packaged unlock would evict.
## Checklist:
- [x] I have performed a self-review of my own code
- [x] I have commented my code, particularly in hard-to-understand areas
- [x] I have added or updated relevant unit/integration/functional/e2e tests
- [x] I have made corresponding changes to the documentation (dashpay/dips#189)
- [ ] I have assigned this pull request to a milestone
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Top commit has no ACKs.
Tree-SHA512: dc4439a2941f5b0f20676ff7deb47854b11503321d92b8c70ae7421eb9b74877803c2fbc0078764b5ba44dcf9747d532af9d9e94075d9c11db8853cde76170e150 files changed
Lines changed: 2001 additions & 233 deletions
File tree
- doc
- src
- evo
- instantsend
- kernel
- llmq
- node
- primitives
- rpc
- test
- util
- test
- functional
- test_framework
- lint
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1316 | 1316 | | |
1317 | 1317 | | |
1318 | 1318 | | |
| 1319 | + | |
1319 | 1320 | | |
1320 | 1321 | | |
1321 | 1322 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
29 | | - | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
30 | 34 | | |
31 | 35 | | |
32 | 36 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
324 | 324 | | |
325 | 325 | | |
326 | 326 | | |
| 327 | + | |
| 328 | + | |
| 329 | + | |
327 | 330 | | |
328 | 331 | | |
329 | 332 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
103 | 103 | | |
104 | 104 | | |
105 | 105 | | |
106 | | - | |
107 | | - | |
108 | 106 | | |
109 | 107 | | |
110 | 108 | | |
| |||
141 | 139 | | |
142 | 140 | | |
143 | 141 | | |
144 | | - | |
| 142 | + | |
145 | 143 | | |
146 | 144 | | |
147 | 145 | | |
| |||
175 | 173 | | |
176 | 174 | | |
177 | 175 | | |
178 | | - | |
| 176 | + | |
| 177 | + | |
179 | 178 | | |
180 | 179 | | |
181 | 180 | | |
| |||
205 | 204 | | |
206 | 205 | | |
207 | 206 | | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
208 | 210 | | |
209 | 211 | | |
210 | 212 | | |
| |||
219 | 221 | | |
220 | 222 | | |
221 | 223 | | |
222 | | - | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
223 | 227 | | |
224 | 228 | | |
225 | 229 | | |
226 | 230 | | |
227 | 231 | | |
228 | 232 | | |
229 | | - | |
| 233 | + | |
230 | 234 | | |
231 | 235 | | |
232 | 236 | | |
233 | 237 | | |
234 | | - | |
| 238 | + | |
235 | 239 | | |
236 | 240 | | |
237 | 241 | | |
238 | 242 | | |
239 | | - | |
| 243 | + | |
240 | 244 | | |
241 | 245 | | |
242 | 246 | | |
243 | 247 | | |
244 | 248 | | |
245 | | - | |
| 249 | + | |
246 | 250 | | |
247 | 251 | | |
248 | 252 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
75 | 75 | | |
76 | 76 | | |
77 | 77 | | |
78 | | - | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
79 | 83 | | |
| 84 | + | |
80 | 85 | | |
81 | 86 | | |
82 | 87 | | |
| |||
163 | 168 | | |
164 | 169 | | |
165 | 170 | | |
166 | | - | |
| 171 | + | |
167 | 172 | | |
168 | 173 | | |
169 | | - | |
| 174 | + | |
170 | 175 | | |
171 | 176 | | |
172 | 177 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
24 | | - | |
| 24 | + | |
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
| |||
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
44 | 52 | | |
45 | 53 | | |
46 | 54 | | |
| |||
147 | 155 | | |
148 | 156 | | |
149 | 157 | | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
150 | 174 | | |
151 | 175 | | |
152 | | - | |
| 176 | + | |
153 | 177 | | |
154 | | - | |
| 178 | + | |
155 | 179 | | |
156 | 180 | | |
157 | 181 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
34 | 34 | | |
35 | 35 | | |
36 | 36 | | |
| 37 | + | |
37 | 38 | | |
38 | 39 | | |
39 | 40 | | |
| |||
45 | 46 | | |
46 | 47 | | |
47 | 48 | | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
48 | 53 | | |
49 | 54 | | |
50 | 55 | | |
| |||
56 | 61 | | |
57 | 62 | | |
58 | 63 | | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
59 | 67 | | |
60 | 68 | | |
61 | 69 | | |
| |||
68 | 76 | | |
69 | 77 | | |
70 | 78 | | |
71 | | - | |
| 79 | + | |
72 | 80 | | |
73 | 81 | | |
74 | 82 | | |
75 | 83 | | |
| 84 | + | |
76 | 85 | | |
77 | 86 | | |
78 | 87 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
143 | 143 | | |
144 | 144 | | |
145 | 145 | | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
146 | 149 | | |
147 | 150 | | |
148 | 151 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
119 | 119 | | |
120 | 120 | | |
121 | 121 | | |
122 | | - | |
123 | | - | |
124 | | - | |
125 | | - | |
126 | | - | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
127 | 129 | | |
128 | 130 | | |
129 | 131 | | |
| |||
135 | 137 | | |
136 | 138 | | |
137 | 139 | | |
138 | | - | |
| 140 | + | |
139 | 141 | | |
140 | | - | |
141 | | - | |
142 | | - | |
143 | | - | |
144 | | - | |
145 | | - | |
146 | | - | |
147 | | - | |
148 | | - | |
149 | | - | |
150 | | - | |
151 | | - | |
152 | | - | |
153 | | - | |
154 | | - | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
155 | 157 | | |
156 | 158 | | |
157 | 159 | | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
158 | 167 | | |
159 | 168 | | |
160 | 169 | | |
| |||
0 commit comments