Skip to content

docs(esplora): explain prevout trust assumptions - #2350

Open
h55n wants to merge 1 commit into
bitcoindevkit:masterfrom
h55n:docs/2343-esplora-prevout-trust
Open

h55n wants to merge 1 commit into
bitcoindevkit:masterfrom
h55n:docs/2343-esplora-prevout-trust

Conversation

@h55n

@h55n h55n commented Oct 8, 2026

Copy link
Copy Markdown

Description

Refs #2343

Documents that Esplora sync and full_scan add server-reported previous outputs as floating txouts without checking them against the full parent transaction. Explains how fee and sent/received numbers can depend on those values, or on scripts a server reports, when the parent transaction is absent, including inputs that belong to other parties. Adds a trust-assumptions section to the Esplora README and links the sync and full_scan docs on both the blocking and async extension traits to it.

This changes documentation only. It does not add parent-transaction verification.

Notes to the reviewers

Doc-only, 33 added lines in 3 files. I used "Refs" because I am not sure whether you also want the behaviour changed (verifying parents) rather than documented. Happy to adjust the wording or scope to whatever you prefer on #2343.
Behaviour described in the docs is checked by a separate local harness: a forged floating txout value changes the computed fee, and fetching the full actual parent transaction restores the correct fee.

Changelog notice

Documented the trust assumptions of server-reported previous outputs in bdk_esplora.

Checklists

All Submissions:

  • I followed the contribution guidelines

Bugfixes:

Copilot AI balanced review requested due to automatic review settings October 8, 2026 07:32

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Triage

Development

Successfully merging this pull request may close these issues.

2 participants