decodepsbt shows each PSBT_IN_TAP_LEAF_SCRIPT record as-is. It does
not say whether its control block could be a genuine leaf of the input's
taproot tree. InferTaprootTree() already checks this, but silently
skips whatever fails. That is correct there: one bad candidate among
several script paths is not an error. But it means a PSBT with an
unusable leaf shows no sign of it.
This PR adds a diagnostic only; signing does not change. A new optional
control_block_warnings array, next to control_blocks, gives the first
check a control block fails. There are four checks:
- leaf version (must be even);
- control block size;
- leaf-version byte (must match
leaf_ver); - Merkle root (must match
PSBT_IN_TAP_MERKLE_ROOT).
The Merkle-root check needs PSBT_IN_TAP_MERKLE_ROOT, which is optional
per BIP371. When it is absent, only the other three checks run, and the
help text says so.
Similar in spirit to #25513, which added the same kind of check for
PSBT_OUT_TAP_TREE.
Commits
- Unit test for the four checks in
InferTaprootTree()(none existed). - Extract the checks into
CheckTapLeafCandidate(), shared byInferTaprootTree()anddecodepsbt. decodepsbt's newcontrol_block_warningsfield, with its functional test.
Written with LLM, a computer and the Internet; the mistakes, as usual, are all mine.