feat: add fallback locktime support in PSBT deserialization (#3583)
What changed, and why it matters
This commit adds one line to make sure a fallback locktime value is copied from a Bitcoin transaction into a PSBT (Partially Signed Bitcoin Transaction) data structure during parsing. A locktime is a standard Bitcoin field that controls when a transaction can be mined. The change appears to be a missing-field fix rather than a security patch, and there is no direct evidence in the commit that it fixes an active vulnerability.
Review whether setGlobalFallbackLocktime handles unexpected locktime values safely, and confirm the change is covered by tests. Treat as a routine correctness fix unless additional context shows it prevents a specific transaction-relay or fee-sniping issue.
Security signals we found
Adds missing PSBT v2 global field mapping
No input validation or bounds checking added
No vendor security language in commit title or message
Single-line functional change in deserialization path
Evidence from the diff
In cw_bitcoin/lib/psbt/v0_deserialize.dart, the PSBT v0-to-v2 deserialization now calls setGlobalFallbackLocktime() with the unsigned transaction’s locktime. PSBT v2 requires a global fallback locktime when the transaction version is 1 or lower. Previously this field may have been left unset, which could cause PSBT v2 consumers to lack locktime context. This is a completeness/correctness fix; the diff does not show any validation, bounds checking, or logic change beyond copying the existing locktime bytes.
Changed components
cw_bitcoin/lib/psbt/v0_deserialize.dartBitcoin PSBT v0/v2 deserializationInspect captured patch +1 / −0
diff --git a/cw_bitcoin/lib/psbt/v0_deserialize.dart b/cw_bitcoin/lib/psbt/v0_deserialize.dart
index 541eb69..d458a1f 100644
--- a/cw_bitcoin/lib/psbt/v0_deserialize.dart
+++ b/cw_bitcoin/lib/psbt/v0_deserialize.dart
@@ -20,6 +20,7 @@ extension PsbtSigner on PsbtV2 {
setGlobalInputCount(tx.inputs.length);
setGlobalOutputCount(tx.outputs.length);
setGlobalTxVersion(Uint8List.fromList(tx.version).readUint32LE(0));
+ setGlobalFallbackLocktime(Uint8List.fromList(tx.locktime).readUint32LE(0));
for (var i = 0; i < getGlobalInputCount(); i++) {
inputMaps.insert(i, <String, Uint8List>{});
Why this scored 18/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.