wallet: reject duplicate inputs in sendall #36344

pull Bruce039 wants to merge 1 commits into bitcoin:master from Bruce039:fix-sendall-duplicate-inputs changing 2 files +18 −0
  1. Bruce039 commented at 9:57 AM on September 26, 2026: none

    sendall with the inputs option doesn't check for duplicates. Each listed input is added to total_input_value in the loop at spend.cpp:1472, so passing the same UTXO twice counts its value twice.

    On regtest, with a wallet that has a single 1 BTC UTXO:

    sendall '["<addr>"]' '{"inputs": [<utxo>, <utxo>]}'
    
    • the RPC returns complete: true
    • the committed tx has 2 inputs (the same outpoint twice) and one output of 1.99998230 BTC
    • it isn't in the mempool, and testmempoolaccept rejects it with bad-txns-inputs-duplicate
    • after that, listunspent is empty and getbalances shows nonmempool: -1.0 until the tx is abandoned

    send and walletcreatefundedpsbt aren't affected, because CCoinControl::Select removes duplicates.

    This rejects a duplicated input with Invalid parameter, duplicated input: <txid>:<vout> (RPC_INVALID_PARAMETER). The message matches what createrawtransaction says for duplicated addresses. The new sendall_fails_on_duplicate_input test fails on master ("No exception raised") and passes with the fix. wallet_send.py still passes.

  2. DrahtBot added the label Wallet on Sep 26, 2026
  3. DrahtBot commented at 9:57 AM on September 26, 2026: contributor

    <!--e57a25ab6845829454e8d69fc972939a-->

    The following sections might be updated with supplementary metadata relevant to reviewers and maintainers.

    <!--006a51241073e994b41acfe9ec718e94-->

    Code Coverage & Benchmarks

    For details see: https://corecheck.dev/bitcoin/bitcoin/pulls/36344.

    <!--021abf342d371248e50ceaed478a90ca-->

    Reviews

    See the guideline and AI policy for information on the review process. A summary of reviews will appear here.

    <!--5faf32d7da4f0f540f40219e4f7537a3-->

  4. wallet: reject duplicate inputs in sendall
    sendall with the inputs option adds up the value of each listed input
    without checking for duplicates. When the same UTXO is given twice, the
    input value is counted twice, and the wallet builds, signs and commits
    a transaction that spends one outpoint twice and pays out twice its
    value. The RPC reports success, but the transaction is consensus-invalid
    (bad-txns-inputs-duplicate), and the coin disappears from listunspent
    until the transaction is abandoned.
    
    Reject duplicated inputs with an error, like createrawtransaction does
    for duplicated addresses.
    c46a0b34fd
  5. Bruce039 force-pushed on Sep 26, 2026
  6. DrahtBot added the label CI failed on Sep 26, 2026
  7. DrahtBot removed the label CI failed on Sep 26, 2026
Contributors
Labels

github-metadata-mirror

This is a metadata mirror of the GitHub repository bitcoin/bitcoin. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2026-09-28 09:51 UTC

This site is hosted by @0xB10C
More mirrored repositories can be found on mirror.b10c.me