wallet: reject recipient amounts above MAX_MONEY #36342

pull Bruce039 wants to merge 1 commits into bitcoin:master from Bruce039:fix-recipients-sum-overflow changing 2 files +28 −0
  1. Bruce039 commented at 9:53 AM on September 26, 2026: none

    CreateTransaction checks that recipient amounts aren't negative, but not that they're within MAX_MONEY. CreateTransactionInternal then sums them into recipients_sum (spend.cpp:1100) with no range check, and that sum can overflow.

    Easiest way to hit it is fundrawtransaction with a raw tx that has two outputs of 2^62 sat. It can also be reached with only valid amounts through walletcreatefundedpsbt/send/sendmany and a few thousand 21M BTC outputs. The "Transaction too large" check only runs after coin selection, so it doesn't stop this. On master the node aborts:

    Assertion failed: (!m_selected_inputs.empty()), function RecalculateWaste, file coinselection.cpp, line 904.
    

    UBSan reports the overflow at spend.cpp:1100 first. With other values the sum wraps to a small positive number instead, and fundrawtransaction returns success for a tx with outputs of 46116860184 BTC each.

    This checks every amount and the running sum against MoneyRange in CreateTransaction, next to the existing negative check, and returns an error before coin selection starts. The new test_outputs_above_max_money in wallet_fundrawtransaction.py covers a single output above MAX_MONEY, two outputs whose sum is above it, and a sum that overflows int64. On master the first case returns "Insufficient funds" and the overflow case crashes the node. With the fix all three get the new error. I ran it on a normal and an ASan/UBSan build, and wallet_basic.py and rpc_psbt.py still pass.

  2. DrahtBot added the label Wallet on Sep 26, 2026
  3. DrahtBot commented at 9:53 AM on September 26, 2026: contributor

    <!--e57a25ab6845829454e8d69fc972939a-->

    The following sections might be updated with supplementary metadata relevant to reviewers and maintainers.

    <!--006a51241073e994b41acfe9ec718e94-->

    Code Coverage & Benchmarks

    For details see: https://corecheck.dev/bitcoin/bitcoin/pulls/36342.

    <!--021abf342d371248e50ceaed478a90ca-->

    Reviews

    See the guideline and AI policy for information on the review process. A summary of reviews will appear here.

    <!--174a7506f384e20aa4161008e828411d-->

    Conflicts

    Reviewers, this pull request conflicts with the following ones:

    • #35317 (wallet: fix ignored subtract_fee_from_outputs option by stutxo)

    If you consider this pull request important, please also help to review the conflicting pull requests. Ideally, start with the one that should be merged first.

    <!--5faf32d7da4f0f540f40219e4f7537a3-->

  4. wallet: reject recipient amounts above MAX_MONEY
    CreateTransaction only checks that recipient amounts are not negative.
    CreateTransactionInternal then adds them up in recipients_sum, which can
    overflow int64. For example, fundrawtransaction on a raw tx with two
    outputs of 2^62 sat, or sendmany/walletcreatefundedpsbt with enough
    MAX_MONEY outputs. The negative sum then reaches coin selection and the
    node aborts on assert(!m_selected_inputs.empty()) in RecalculateWaste.
    With other values the sum wraps to a small positive number and funding
    succeeds with outputs far above MAX_MONEY.
    
    Check that every amount and the running sum stay within MoneyRange
    before starting coin selection.
    f2915243d6
  5. Bruce039 force-pushed on Sep 26, 2026
  6. pinheadmz commented at 11:40 AM on September 26, 2026: member

    You just opened three PRs in ten minutes. Do all three of these conform to our AI Policy? Before we spend any precious human resources reading through your submissions can you please assure us that you understand all the choices you've made and that you are motivated by solving real problems real users have with the software?

  7. Bruce039 commented at 12:05 PM on September 26, 2026: none

    Yes, I've read the AI policy and I accept it. And yes, I used AI, but only for the PR description and the tests. Finding the bug and the rest of the underlying work was done by me. About the 3 PRs: I've been preparing for PRs for the last few days, and it made more sense to me to collect all the bugs I found and send them at the same time.

  8. DrahtBot added the label CI failed on Sep 26, 2026
  9. DrahtBot removed the label CI failed on Sep 26, 2026
Labels

github-metadata-mirror

This is a metadata mirror of the GitHub repository bitcoin/bitcoin. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2026-09-28 09:51 UTC

This site is hosted by @0xB10C
More mirrored repositories can be found on mirror.b10c.me