The wallet sizes a transaction assuming a 71-byte low-R ECDSA signature. A signature whose r or s has leading zero bytes is shorter, so the fee can cover a few bytes more than the signed transaction needs. In #36394 the wallet estimated 219 bytes and paid 438 sat at 2 sat/vB, but the signed transaction was 216 bytes: the signature was 3 bytes short. That happens about once in 4 million signatures. assert_fee_amount allows only 2 bytes of overestimate, so the test failed.
I raise the allowance to 3 bytes, which makes the failure about 200 times rarer. The check that the fee is not too low is unchanged. @maflcko suggested 3 bytes in #24151 and #25164.
Fixes #36394.
Made with my usual tools: a computer, the Internet and an LLM. The mistakes, as usual, are all mine.