mempool: keep prioritisetransaction deltas within MAX_MONEY #36367

pull Bruce039 wants to merge 1 commits into bitcoin:master from Bruce039:fix-prioritisetransaction-delta-range changing 3 files +40 −3
  1. Bruce039 commented at 2:44 PM on September 28, 2026: none

    prioritisetransaction takes fee_delta as any int64. CTxMemPool::PrioritiseTransaction stacks deltas with SaturatingAdd, so the accumulated delta and the modified fee can go up to INT64_MAX. The cluster mempool then adds modified fees of several transactions together in FeeFrac (util/feefrac.h:108) without overflow checks.

    For example, with a parent and child in the mempool:

    prioritisetransaction <parent> 0 4611686018427387904
    prioritisetransaction <child> 0 9223372036854775807
    
    • getmempoolcluster reports chunkfee: -46116860184.27356705
    • getblocktemplate contains neither transaction, and the next block mined has only the coinbase
    • UBSan: feefrac.h:108:13: runtime error: signed integer overflow, reached from linearization via getrawmempool

    There's no use for a delta larger than the total money supply, so this:

    • rejects fee_delta outside -MAX_MONEY..MAX_MONEY in the RPC with "fee_delta out of range"
    • clamps the accumulated delta to -MAX_MONEY..MAX_MONEY in PrioritiseTransaction, which also covers deltas loaded from mempool.dat, and updates the modified fee by the change in the clamped delta

    With each modified fee bounded by 2 * MAX_MONEY, cluster sums stay far away from int64 limits.

    The new test_fee_delta_limits in mining_prioritisetransaction.py checks the RPC range error, that stacked deltas stop at MAX_MONEY, that the chunk fees add up, and that both transactions are in the block template. It fails on master ("No exception raised"). mempool_persist.py, mempool_packages.py, rpc_packages.py and the miner/rbf/txpackage unit tests pass.

    AI tools were used to help find this issue and to prepare the patch and test.

  2. mempool: keep prioritisetransaction deltas within MAX_MONEY
    prioritisetransaction accepts any int64 fee_delta, and
    CTxMemPool::PrioritiseTransaction only saturates the accumulated delta
    at the int64 limits. With large deltas the modified fees of a cluster
    add up past int64 in the txgraph chunk calculations (UBSan reports a
    signed overflow in FeeFrac::operator+=). For example, prioritising a
    parent by 2^62 and its child by INT64_MAX gives a negative chunk fee
    in getmempoolcluster, and both transactions are left out of block
    templates.
    
    Reject fee_delta values outside +-MAX_MONEY in the RPC, and clamp the
    accumulated delta to +-MAX_MONEY in PrioritiseTransaction (which also
    covers deltas loaded from mempool.dat). The modified fee is updated by
    the change in the clamped delta.
    0d16834506
  3. DrahtBot added the label Mempool on Sep 28, 2026
  4. DrahtBot commented at 2:44 PM on September 28, 2026: contributor

    <!--e57a25ab6845829454e8d69fc972939a-->

    The following sections might be updated with supplementary metadata relevant to reviewers and maintainers.

    <!--006a51241073e994b41acfe9ec718e94-->

    Code Coverage & Benchmarks

    For details see: https://corecheck.dev/bitcoin/bitcoin/pulls/36367.

    <!--021abf342d371248e50ceaed478a90ca-->

    Reviews

    See the guideline and AI policy for information on the review process. A summary of reviews will appear here.

    <!--5faf32d7da4f0f540f40219e4f7537a3-->

Contributors
Labels

github-metadata-mirror

This is a metadata mirror of the GitHub repository bitcoin/bitcoin. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2026-10-11 08:51 UTC

This site is hosted by @0xB10C
More mirrored repositories can be found on mirror.b10c.me