bc584ddaa0e193134f6753310ad59e4ddd502012
[electrum-nvc.git] / lib / wallet.py
1 #!/usr/bin/env python
2 #
3 # Electrum - lightweight Bitcoin client
4 # Copyright (C) 2011 thomasv@gitorious
5 #
6 # This program is free software: you can redistribute it and/or modify
7 # it under the terms of the GNU General Public License as published by
8 # the Free Software Foundation, either version 3 of the License, or
9 # (at your option) any later version.
10 #
11 # This program is distributed in the hope that it will be useful,
12 # but WITHOUT ANY WARRANTY; without even the implied warranty of
13 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 # GNU General Public License for more details.
15 #
16 # You should have received a copy of the GNU General Public License
17 # along with this program. If not, see <http://www.gnu.org/licenses/>.
18
19
20 import sys, base64, os, re, hashlib, copy, operator, ast, threading, random
21 import aes, ecdsa
22 from ecdsa.util import string_to_number, number_to_string
23
24 ############ functions from pywallet ##################### 
25
26 addrtype = 0
27
28 def hash_160(public_key):
29     try:
30         md = hashlib.new('ripemd160')
31         md.update(hashlib.sha256(public_key).digest())
32         return md.digest()
33     except:
34         import ripemd
35         md = ripemd.new(hashlib.sha256(public_key).digest())
36         return md.digest()
37
38
39 def public_key_to_bc_address(public_key):
40     h160 = hash_160(public_key)
41     return hash_160_to_bc_address(h160)
42
43 def hash_160_to_bc_address(h160):
44     vh160 = chr(addrtype) + h160
45     h = Hash(vh160)
46     addr = vh160 + h[0:4]
47     return b58encode(addr)
48
49 def bc_address_to_hash_160(addr):
50     bytes = b58decode(addr, 25)
51     return bytes[1:21]
52
53 def encode_point(pubkey, compressed=False):
54     order = generator_secp256k1.order()
55     p = pubkey.pubkey.point
56     x_str = ecdsa.util.number_to_string(p.x(), order)
57     y_str = ecdsa.util.number_to_string(p.y(), order)
58     if compressed:
59         return chr(2 + (p.y() & 1)) + x_str
60     else:
61         return chr(4) + pubkey.to_string() #x_str + y_str
62
63 __b58chars = '123456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz'
64 __b58base = len(__b58chars)
65
66 def b58encode(v):
67     """ encode v, which is a string of bytes, to base58.                
68     """
69
70     long_value = 0L
71     for (i, c) in enumerate(v[::-1]):
72         long_value += (256**i) * ord(c)
73
74     result = ''
75     while long_value >= __b58base:
76         div, mod = divmod(long_value, __b58base)
77         result = __b58chars[mod] + result
78         long_value = div
79     result = __b58chars[long_value] + result
80
81     # Bitcoin does a little leading-zero-compression:
82     # leading 0-bytes in the input become leading-1s
83     nPad = 0
84     for c in v:
85         if c == '\0': nPad += 1
86         else: break
87
88     return (__b58chars[0]*nPad) + result
89
90 def b58decode(v, length):
91     """ decode v into a string of len bytes
92     """
93     long_value = 0L
94     for (i, c) in enumerate(v[::-1]):
95         long_value += __b58chars.find(c) * (__b58base**i)
96
97     result = ''
98     while long_value >= 256:
99         div, mod = divmod(long_value, 256)
100         result = chr(mod) + result
101         long_value = div
102     result = chr(long_value) + result
103
104     nPad = 0
105     for c in v:
106         if c == __b58chars[0]: nPad += 1
107         else: break
108
109     result = chr(0)*nPad + result
110     if length is not None and len(result) != length:
111         return None
112
113     return result
114
115
116 def Hash(data):
117     return hashlib.sha256(hashlib.sha256(data).digest()).digest()
118
119 def EncodeBase58Check(vchIn):
120     hash = Hash(vchIn)
121     return b58encode(vchIn + hash[0:4])
122
123 def DecodeBase58Check(psz):
124     vchRet = b58decode(psz, None)
125     key = vchRet[0:-4]
126     csum = vchRet[-4:]
127     hash = Hash(key)
128     cs32 = hash[0:4]
129     if cs32 != csum:
130         return None
131     else:
132         return key
133
134 def PrivKeyToSecret(privkey):
135     return privkey[9:9+32]
136
137 def SecretToASecret(secret):
138     vchIn = chr(addrtype+128) + secret
139     return EncodeBase58Check(vchIn)
140
141 def ASecretToSecret(key):
142     vch = DecodeBase58Check(key)
143     if vch and vch[0] == chr(addrtype+128):
144         return vch[1:]
145     else:
146         return False
147
148 ########### end pywallet functions #######################
149
150 # URL decode
151 _ud = re.compile('%([0-9a-hA-H]{2})', re.MULTILINE)
152 urldecode = lambda x: _ud.sub(lambda m: chr(int(m.group(1), 16)), x)
153
154
155 def int_to_hex(i, length=1):
156     s = hex(i)[2:].rstrip('L')
157     s = "0"*(2*length - len(s)) + s
158     return s.decode('hex')[::-1].encode('hex')
159
160
161 # AES
162 EncodeAES = lambda secret, s: base64.b64encode(aes.encryptData(secret,s))
163 DecodeAES = lambda secret, e: aes.decryptData(secret, base64.b64decode(e))
164
165
166
167 # secp256k1, http://www.oid-info.com/get/1.3.132.0.10
168 _p = 0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFC2FL
169 _r = 0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEBAAEDCE6AF48A03BBFD25E8CD0364141L
170 _b = 0x0000000000000000000000000000000000000000000000000000000000000007L
171 _a = 0x0000000000000000000000000000000000000000000000000000000000000000L
172 _Gx = 0x79BE667EF9DCBBAC55A06295CE870B07029BFCDB2DCE28D959F2815B16F81798L
173 _Gy = 0x483ada7726a3c4655da4fbfc0e1108a8fd17b448a68554199c47d08ffb10d4b8L
174 curve_secp256k1 = ecdsa.ellipticcurve.CurveFp( _p, _a, _b )
175 generator_secp256k1 = ecdsa.ellipticcurve.Point( curve_secp256k1, _Gx, _Gy, _r )
176 oid_secp256k1 = (1,3,132,0,10)
177 SECP256k1 = ecdsa.curves.Curve("SECP256k1", curve_secp256k1, generator_secp256k1, oid_secp256k1 ) 
178
179
180 def filter(s): 
181     out = re.sub('( [^\n]*|)\n','',s)
182     out = out.replace(' ','')
183     out = out.replace('\n','')
184     return out
185
186 def raw_tx( inputs, outputs, for_sig = None ):
187     s  = int_to_hex(1,4)                                     +   '     version\n' 
188     s += int_to_hex( len(inputs) )                           +   '     number of inputs\n'
189     for i in range(len(inputs)):
190         _, _, p_hash, p_index, p_script, pubkey, sig = inputs[i]
191         s += p_hash.decode('hex')[::-1].encode('hex')        +  '     prev hash\n'
192         s += int_to_hex(p_index,4)                           +  '     prev index\n'
193         if for_sig is None:
194             sig = sig + chr(1)                               # hashtype
195             script  = int_to_hex( len(sig))                  +  '     push %d bytes\n'%len(sig)
196             script += sig.encode('hex')                      +  '     sig\n'
197             pubkey = chr(4) + pubkey
198             script += int_to_hex( len(pubkey))               +  '     push %d bytes\n'%len(pubkey)
199             script += pubkey.encode('hex')                   +  '     pubkey\n'
200         elif for_sig==i:
201             script = p_script                                +  '     scriptsig \n'
202         else:
203             script=''
204         s += int_to_hex( len(filter(script))/2 )             +  '     script length \n'
205         s += script
206         s += "ffffffff"                                      +  '     sequence\n'
207     s += int_to_hex( len(outputs) )                          +  '     number of outputs\n'
208     for output in outputs:
209         addr, amount = output
210         s += int_to_hex( amount, 8)                          +  '     amount: %d\n'%amount 
211         script = '76a9'                                      # op_dup, op_hash_160
212         script += '14'                                       # push 0x14 bytes
213         script += bc_address_to_hash_160(addr).encode('hex')
214         script += '88ac'                                     # op_equalverify, op_checksig
215         s += int_to_hex( len(filter(script))/2 )             +  '     script length \n'
216         s += script                                          +  '     script \n'
217     s += int_to_hex(0,4)                                     # lock time
218     if for_sig is not None: s += int_to_hex(1, 4)            # hash type
219     return s
220
221
222
223
224 def format_satoshis(x, is_diff=False, num_zeros = 0):
225     from decimal import Decimal
226     s = Decimal(x)
227     sign, digits, exp = s.as_tuple()
228     digits = map(str, digits)
229     while len(digits) < 9:
230         digits.insert(0,'0')
231     digits.insert(-8,'.')
232     s = ''.join(digits).rstrip('0')
233     if sign: 
234         s = '-' + s
235     elif is_diff:
236         s = "+" + s
237
238     p = s.find('.')
239     s += "0"*( 1 + num_zeros - ( len(s) - p ))
240     s += " "*( 9 - ( len(s) - p ))
241     s = " "*( 5 - ( p )) + s
242     return s
243
244
245 from version import ELECTRUM_VERSION, SEED_VERSION
246 from interface import DEFAULT_SERVERS
247
248
249
250
251 class Wallet:
252     def __init__(self):
253
254         self.electrum_version = ELECTRUM_VERSION
255         self.seed_version = SEED_VERSION
256         self.update_callbacks = []
257
258         self.gap_limit = 5           # configuration
259         self.use_change = True
260         self.fee = 100000
261         self.num_zeros = 0
262         self.master_public_key = ''
263
264         # saved fields
265         self.use_encryption = False
266         self.addresses = []          # receiving addresses visible for user
267         self.change_addresses = []   # addresses used as change
268         self.seed = ''               # encrypted
269         self.history = {}
270         self.labels = {}             # labels for addresses and transactions
271         self.aliases = {}            # aliases for addresses
272         self.authorities = {}        # trusted addresses
273         self.frozen_addresses = []
274         self.prioritized_addresses = []
275         self.expert_mode = False
276         
277         self.receipts = {}           # signed URIs
278         self.receipt = None          # next receipt
279         self.addressbook = []        # outgoing addresses, for payments
280         self.debug_server = False    # write server communication debug info to stdout
281
282         # not saved
283         self.tx_history = {}
284
285         self.imported_keys = {}
286         self.remote_url = None
287
288         self.was_updated = True
289         self.blocks = -1
290         self.banner = ''
291
292         # there is a difference between self.up_to_date and self.is_up_to_date()
293         # self.is_up_to_date() returns true when all requests have been answered and processed
294         # self.up_to_date is true when the wallet is synchronized (stronger requirement)
295         self.up_to_date_event = threading.Event()
296         self.up_to_date_event.clear()
297         self.up_to_date = False
298         self.lock = threading.Lock()
299         self.tx_event = threading.Event()
300
301         self.pick_random_server()
302
303     def register_callback(self, update_callback):
304         with self.lock:
305             self.update_callbacks.append(update_callback)
306
307     def trigger_callbacks(self):
308         with self.lock:
309             callbacks = self.update_callbacks[:]
310         [update() for update in callbacks]
311
312     def pick_random_server(self):
313         self.server = random.choice( DEFAULT_SERVERS )         # random choice when the wallet is created
314
315     def is_up_to_date(self):
316         return self.interface.responses.empty() and not self.interface.unanswered_requests
317
318     def set_server(self, server):
319         # raise an error if the format isnt correct
320         a,b,c = server.split(':')
321         b = int(b)
322         assert c in ['t','h','n']
323         # set the server
324         if server != self.server:
325             self.server = server
326             self.save()
327             self.interface.is_connected = False  # this exits the polling loop
328             self.interface.poke()
329
330     def set_path(self, wallet_path):
331
332         if wallet_path is not None:
333             self.path = wallet_path
334         else:
335             # backward compatibility: look for wallet file in the default data directory
336             if "HOME" in os.environ:
337                 wallet_dir = os.path.join( os.environ["HOME"], '.electrum')
338             elif "LOCALAPPDATA" in os.environ:
339                 wallet_dir = os.path.join( os.environ["LOCALAPPDATA"], 'Electrum' )
340             elif "APPDATA" in os.environ:
341                 wallet_dir = os.path.join( os.environ["APPDATA"], 'Electrum' )
342             else:
343                 raise BaseException("No home directory found in environment variables.")
344
345             if not os.path.exists( wallet_dir ): os.mkdir( wallet_dir )
346             self.path = os.path.join( wallet_dir, 'electrum.dat' )
347
348     def import_key(self, keypair, password):
349         address, key = keypair.split(':')
350         if not self.is_valid(address):
351             raise BaseException('Invalid Bitcoin address')
352         if address in self.all_addresses():
353             raise BaseException('Address already in wallet')
354         b = ASecretToSecret( key )
355         if not b: 
356             raise BaseException('Unsupported key format')
357         secexp = int( b.encode('hex'), 16)
358         private_key = ecdsa.SigningKey.from_secret_exponent( secexp, curve=SECP256k1 )
359         # sanity check
360         public_key = private_key.get_verifying_key()
361         if not address == public_key_to_bc_address( '04'.decode('hex') + public_key.to_string() ):
362             raise BaseException('Address does not match private key')
363         self.imported_keys[address] = self.pw_encode( key, password )
364
365     def new_seed(self, password):
366         seed = "%032x"%ecdsa.util.randrange( pow(2,128) )
367         #self.init_mpk(seed)
368         # encrypt
369         self.seed = self.pw_encode( seed, password )
370
371
372     def init_mpk(self,seed):
373         # public key
374         curve = SECP256k1
375         secexp = self.stretch_key(seed)
376         master_private_key = ecdsa.SigningKey.from_secret_exponent( secexp, curve = SECP256k1 )
377         self.master_public_key = master_private_key.get_verifying_key().to_string()
378
379     def all_addresses(self):
380         return self.addresses + self.change_addresses + self.imported_keys.keys()
381
382     def is_mine(self, address):
383         return address in self.all_addresses()
384
385     def is_change(self, address):
386         return address in self.change_addresses
387
388     def is_valid(self,addr):
389         ADDRESS_RE = re.compile('[1-9A-HJ-NP-Za-km-z]{26,}\\Z')
390         if not ADDRESS_RE.match(addr): return False
391         try:
392             h = bc_address_to_hash_160(addr)
393         except:
394             return False
395         return addr == hash_160_to_bc_address(h)
396
397     def stretch_key(self,seed):
398         oldseed = seed
399         for i in range(100000):
400             seed = hashlib.sha256(seed + oldseed).digest()
401         return string_to_number( seed )
402
403     def get_sequence(self,n,for_change):
404         return string_to_number( Hash( "%d:%d:"%(n,for_change) + self.master_public_key ) )
405
406     def get_private_key_base58(self, address, password):
407         pk = self.get_private_key(address, password)
408         if pk is None: return None
409         return SecretToASecret( pk )
410
411     def get_private_key(self, address, password):
412         """  Privatekey(type,n) = Master_private_key + H(n|S|type)  """
413         order = generator_secp256k1.order()
414         
415         if address in self.imported_keys.keys():
416             b = self.pw_decode( self.imported_keys[address], password )
417             if not b: return None
418             b = ASecretToSecret( b )
419             secexp = int( b.encode('hex'), 16)
420         else:
421             if address in self.addresses:
422                 n = self.addresses.index(address)
423                 for_change = False
424             elif address in self.change_addresses:
425                 n = self.change_addresses.index(address)
426                 for_change = True
427             else:
428                 raise BaseException("unknown address")
429             try:
430                 seed = self.pw_decode( self.seed, password)
431             except:
432                 raise BaseException("Invalid password")
433             if not seed: return None
434             secexp = self.stretch_key(seed)
435             secexp = ( secexp + self.get_sequence(n,for_change) ) % order
436
437         pk = number_to_string(secexp,order)
438         return pk
439
440     def msg_magic(self, message):
441         return "\x18Bitcoin Signed Message:\n" + chr( len(message) ) + message
442
443     def sign_message(self, address, message, password):
444         private_key = ecdsa.SigningKey.from_string( self.get_private_key(address, password), curve = SECP256k1 )
445         public_key = private_key.get_verifying_key()
446         signature = private_key.sign_digest( Hash( self.msg_magic( message ) ), sigencode = ecdsa.util.sigencode_string )
447         assert public_key.verify_digest( signature, Hash( self.msg_magic( message ) ), sigdecode = ecdsa.util.sigdecode_string)
448         for i in range(4):
449             sig = base64.b64encode( chr(27+i) + signature )
450             try:
451                 self.verify_message( address, sig, message)
452                 return sig
453             except:
454                 continue
455         else:
456             raise BaseException("error: cannot sign message")
457
458
459     def verify_message(self, address, signature, message):
460         """ See http://www.secg.org/download/aid-780/sec1-v2.pdf for the math """
461         from ecdsa import numbertheory, ellipticcurve, util
462         import msqr
463         curve = curve_secp256k1
464         G = generator_secp256k1
465         order = G.order()
466         # extract r,s from signature
467         sig = base64.b64decode(signature)
468         if len(sig) != 65: raise BaseException("Wrong encoding")
469         r,s = util.sigdecode_string(sig[1:], order)
470         nV = ord(sig[0])
471         if nV < 27 or nV >= 35:
472             raise BaseException("Bad encoding")
473         if nV >= 31:
474             compressed = True
475             nV -= 4
476         else:
477             compressed = False
478
479         recid = nV - 27
480         # 1.1
481         x = r + (recid/2) * order
482         # 1.3
483         alpha = ( x * x * x  + curve.a() * x + curve.b() ) % curve.p()
484         beta = msqr.modular_sqrt(alpha, curve.p())
485         y = beta if (beta - recid) % 2 == 0 else curve.p() - beta
486         # 1.4 the constructor checks that nR is at infinity
487         R = ellipticcurve.Point(curve, x, y, order)
488         # 1.5 compute e from message:
489         h = Hash( self.msg_magic( message ) )
490         e = string_to_number(h)
491         minus_e = -e % order
492         # 1.6 compute Q = r^-1 (sR - eG)
493         inv_r = numbertheory.inverse_mod(r,order)
494         Q = inv_r * ( s * R + minus_e * G )
495         public_key = ecdsa.VerifyingKey.from_public_point( Q, curve = SECP256k1 )
496         # check that Q is the public key
497         public_key.verify_digest( sig[1:], h, sigdecode = ecdsa.util.sigdecode_string)
498         # check that we get the original signing address
499         addr = public_key_to_bc_address( encode_point(public_key, compressed) )
500         if address != addr:
501             raise BaseException("Bad signature")
502     
503
504     def create_new_address(self, for_change):
505         """   Publickey(type,n) = Master_public_key + H(n|S|type)*point  """
506         curve = SECP256k1
507         n = len(self.change_addresses) if for_change else len(self.addresses)
508         z = self.get_sequence(n,for_change)
509         master_public_key = ecdsa.VerifyingKey.from_string( self.master_public_key, curve = SECP256k1 )
510         pubkey_point = master_public_key.pubkey.point + z*curve.generator
511         public_key2 = ecdsa.VerifyingKey.from_public_point( pubkey_point, curve = SECP256k1 )
512         address = public_key_to_bc_address( '04'.decode('hex') + public_key2.to_string() )
513         if for_change:
514             self.change_addresses.append(address)
515         else:
516             self.addresses.append(address)
517
518         self.history[address] = []
519         print address
520         return address
521
522
523     def change_gap_limit(self, value):
524         if value >= self.gap_limit:
525             self.gap_limit = value
526             self.save()
527             self.interface.poke()
528             return True
529
530         elif value >= self.min_acceptable_gap():
531             k = self.num_unused_trailing_addresses()
532             n = len(self.addresses) - k + value
533             self.addresses = self.addresses[0:n]
534             self.gap_limit = value
535             self.save()
536             return True
537         else:
538             return False
539
540     def num_unused_trailing_addresses(self):
541         k = 0
542         for a in self.addresses[::-1]:
543             if self.history.get(a):break
544             k = k + 1
545         return k
546
547     def min_acceptable_gap(self):
548         # fixme: this assumes wallet is synchronized
549         n = 0
550         nmax = 0
551         k = self.num_unused_trailing_addresses()
552         for a in self.addresses[0:-k]:
553             if self.history.get(a):
554                 n = 0
555             else:
556                 n += 1
557                 if n > nmax: nmax = n
558         return nmax + 1
559
560
561     def synchronize(self):
562         if not self.master_public_key:
563             return []
564
565         new_addresses = []
566         while True:
567             if self.change_addresses == []:
568                 new_addresses.append( self.create_new_address(True) )
569                 continue
570             a = self.change_addresses[-1]
571             if self.history.get(a):
572                 new_addresses.append( self.create_new_address(True) )
573             else:
574                 break
575
576         n = self.gap_limit
577         while True:
578             if len(self.addresses) < n:
579                 new_addresses.append( self.create_new_address(False) )
580                 continue
581             if map( lambda a: self.history.get(a), self.addresses[-n:] ) == n*[[]]:
582                 break
583             else:
584                 new_addresses.append( self.create_new_address(False) )
585
586         if self.remote_url:
587             num = self.get_remote_number()
588             while len(self.addresses)<num:
589                 new_addresses.append( self.create_new_address(False) )
590
591         return new_addresses
592
593
594     def get_remote_number(self):
595         import jsonrpclib
596         server = jsonrpclib.Server(self.remote_url)
597         out = server.getnum()
598         return out
599
600     def get_remote_mpk(self):
601         import jsonrpclib
602         server = jsonrpclib.Server(self.remote_url)
603         out = server.getkey()
604         return out
605
606     def is_found(self):
607         return (len(self.change_addresses) > 1 ) or ( len(self.addresses) > self.gap_limit )
608
609     def fill_addressbook(self):
610         for tx in self.tx_history.values():
611             if tx['value']<0:
612                 for i in tx['outputs']:
613                     if not self.is_mine(i) and i not in self.addressbook:
614                         self.addressbook.append(i)
615         # redo labels
616         self.update_tx_labels()
617
618
619     def save(self):
620         s = {
621             'seed_version':self.seed_version,
622             'use_encryption':self.use_encryption,
623             'use_change':self.use_change,
624             'master_public_key': self.master_public_key.encode('hex'),
625             'fee':self.fee,
626             'server':self.server,
627             'seed':self.seed,
628             'addresses':self.addresses,
629             'change_addresses':self.change_addresses,
630             'history':self.history, 
631             'labels':self.labels,
632             'contacts':self.addressbook,
633             'imported_keys':self.imported_keys,
634             'aliases':self.aliases,
635             'authorities':self.authorities,
636             'receipts':self.receipts,
637             'num_zeros':self.num_zeros,
638             'frozen_addresses':self.frozen_addresses,
639             'prioritized_addresses':self.prioritized_addresses,
640             'expert_mode':self.expert_mode,
641             'gap_limit':self.gap_limit,
642             'debug_server':self.debug_server,
643             }
644         f = open(self.path,"w")
645         f.write( repr(s) )
646         f.close()
647         import stat
648         os.chmod(self.path,stat.S_IREAD | stat.S_IWRITE)
649
650     def read(self):
651         import interface
652
653         upgrade_msg = """This wallet seed is deprecated. Please run upgrade.py for a diagnostic."""
654         self.file_exists = False
655         try:
656             f = open(self.path,"r")
657             data = f.read()
658             f.close()
659         except:
660             return
661         try:
662             d = ast.literal_eval( data )
663             interface.old_to_new(d)
664             self.seed_version = d.get('seed_version')
665             self.master_public_key = d.get('master_public_key').decode('hex')
666             self.use_encryption = d.get('use_encryption')
667             self.use_change = bool(d.get('use_change',True))
668             self.fee = int( d.get('fee') )
669             self.seed = d.get('seed')
670             self.server = d.get('server')
671             #blocks = d.get('blocks')
672             self.addresses = d.get('addresses')
673             self.change_addresses = d.get('change_addresses')
674             self.history = d.get('history')
675             self.labels = d.get('labels')
676             self.addressbook = d.get('contacts')
677             self.imported_keys = d.get('imported_keys',{})
678             self.aliases = d.get('aliases',{})
679             self.authorities = d.get('authorities',{})
680             self.receipts = d.get('receipts',{})
681             self.num_zeros = d.get('num_zeros',0)
682             self.frozen_addresses = d.get('frozen_addresses',[])
683             self.prioritized_addresses = d.get('prioritized_addresses',[])
684             self.expert_mode = d.get('expert_mode',False)
685             self.gap_limit = d.get('gap_limit',5)
686             self.debug_server = d.get('debug_server',False)
687         except:
688             raise BaseException("cannot read wallet file")
689
690         self.update_tx_history()
691
692         if self.seed_version != SEED_VERSION:
693             raise BaseException(upgrade_msg)
694
695         if self.remote_url: assert self.master_public_key.encode('hex') == self.get_remote_mpk()
696
697         self.file_exists = True
698
699
700     def get_address_flags(self, addr):
701         flags = "C" if self.is_change(addr) else "I" if addr in self.imported_keys.keys() else "-" 
702         flags += "F" if addr in self.frozen_addresses else "P" if addr in self.prioritized_addresses else "-"
703         return flags
704         
705
706     def get_addr_balance(self, addr):
707         assert self.is_mine(addr)
708         h = self.history.get(addr,[])
709         c = u = 0
710         for item in h:
711             v = item['value']
712             if item['height']:
713                 c += v
714             else:
715                 u += v
716         return c, u
717
718     def get_balance(self):
719         conf = unconf = 0
720         for addr in self.all_addresses(): 
721             c, u = self.get_addr_balance(addr)
722             conf += c
723             unconf += u
724         return conf, unconf
725
726
727     def choose_tx_inputs( self, amount, fixed_fee, from_addr = None ):
728         """ todo: minimize tx size """
729         total = 0
730         fee = self.fee if fixed_fee is None else fixed_fee
731
732         coins = []
733         prioritized_coins = []
734         domain = [from_addr] if from_addr else self.all_addresses()
735         for i in self.frozen_addresses:
736             if i in domain: domain.remove(i)
737
738         for i in self.prioritized_addresses:
739             if i in domain: domain.remove(i)
740
741         for addr in domain:
742             h = self.history.get(addr)
743             if h is None: continue
744             for item in h:
745                 if item.get('raw_output_script'):
746                     coins.append( (addr,item))
747
748         coins = sorted( coins, key = lambda x: x[1]['timestamp'] )
749
750         for addr in self.prioritized_addresses:
751             h = self.history.get(addr)
752             if h is None: continue
753             for item in h:
754                 if item.get('raw_output_script'):
755                     prioritized_coins.append( (addr,item))
756
757         prioritized_coins = sorted( prioritized_coins, key = lambda x: x[1]['timestamp'] )
758
759         inputs = []
760         coins = prioritized_coins + coins
761
762         for c in coins: 
763             addr, item = c
764             v = item.get('value')
765             total += v
766             inputs.append((addr, v, item['tx_hash'], item['index'], item['raw_output_script'], None, None) )
767             fee = self.fee*len(inputs) if fixed_fee is None else fixed_fee
768             if total >= amount + fee: break
769         else:
770             #print "not enough funds: %s %s"%(format_satoshis(total), format_satoshis(fee))
771             inputs = []
772         return inputs, total, fee
773
774     def choose_tx_outputs( self, to_addr, amount, fee, total, change_addr=None ):
775         outputs = [ (to_addr, amount) ]
776         change_amount = total - ( amount + fee )
777         if change_amount != 0:
778             # normally, the update thread should ensure that the last change address is unused
779             if not change_addr:
780                 change_addr = self.change_addresses[-1]
781             outputs.append( ( change_addr,  change_amount) )
782         return outputs
783
784     def sign_inputs( self, inputs, outputs, password ):
785         s_inputs = []
786         for i in range(len(inputs)):
787             addr, v, p_hash, p_pos, p_scriptPubKey, _, _ = inputs[i]
788             private_key = ecdsa.SigningKey.from_string( self.get_private_key(addr, password), curve = SECP256k1 )
789             public_key = private_key.get_verifying_key()
790             pubkey = public_key.to_string()
791             tx = filter( raw_tx( inputs, outputs, for_sig = i ) )
792             sig = private_key.sign_digest( Hash( tx.decode('hex') ), sigencode = ecdsa.util.sigencode_der )
793             assert public_key.verify_digest( sig, Hash( tx.decode('hex') ), sigdecode = ecdsa.util.sigdecode_der)
794             s_inputs.append( (addr, v, p_hash, p_pos, p_scriptPubKey, pubkey, sig) )
795         return s_inputs
796
797     def pw_encode(self, s, password):
798         if password:
799             secret = Hash(password)
800             return EncodeAES(secret, s)
801         else:
802             return s
803
804     def pw_decode(self, s, password):
805         if password is not None:
806             secret = Hash(password)
807             d = DecodeAES(secret, s)
808             if s == self.seed:
809                 try:
810                     d.decode('hex')
811                 except:
812                     raise BaseException("Invalid password")
813             return d
814         else:
815             return s
816
817     def get_status(self, address):
818         h = self.history.get(address)
819         if not h:
820             status = None
821         else:
822             lastpoint = h[-1]
823             status = lastpoint['block_hash']
824             if status == 'mempool': 
825                 status = status + ':%d'% len(h)
826         return status
827
828     def receive_status_callback(self, addr, status):
829         with self.lock:
830             if self.get_status(addr) != status:
831                 #print "updating status for", addr, status
832                 self.interface.get_history(addr)
833
834     def receive_history_callback(self, addr, data): 
835         #print "updating history for", addr
836         with self.lock:
837             self.history[addr] = data
838             self.update_tx_history()
839             self.save()
840
841     def get_tx_history(self):
842         lines = self.tx_history.values()
843         lines = sorted(lines, key=operator.itemgetter("timestamp"))
844         return lines
845
846     def update_tx_history(self):
847         self.tx_history= {}
848         for addr in self.all_addresses():
849             h = self.history.get(addr)
850             if h is None: continue
851             for tx in h:
852                 tx_hash = tx['tx_hash']
853                 line = self.tx_history.get(tx_hash)
854                 if not line:
855                     self.tx_history[tx_hash] = copy.copy(tx)
856                     line = self.tx_history.get(tx_hash)
857                 else:
858                     line['value'] += tx['value']
859                 if line['height'] == 0:
860                     line['timestamp'] = 1e12
861         self.update_tx_labels()
862
863     def update_tx_labels(self):
864         for tx in self.tx_history.values():
865             default_label = ''
866             if tx['value']<0:
867                 for o_addr in tx['outputs']:
868                     if not self.is_mine(o_addr):
869                         dest_label = self.labels.get(o_addr)
870                         if dest_label:
871                             default_label = 'to: ' + dest_label
872                         else:
873                             default_label = 'to: ' + o_addr
874             else:
875                 for o_addr in tx['outputs']:
876                     if self.is_mine(o_addr) and not self.is_change(o_addr):
877                         break
878                 else:
879                     for o_addr in tx['outputs']:
880                         if self.is_mine(o_addr):
881                             break
882                     else:
883                         o_addr = None
884
885                 if o_addr:
886                     dest_label = self.labels.get(o_addr)
887                     if dest_label:
888                         default_label = 'at: ' + dest_label
889                     else:
890                         default_label = 'at: ' + o_addr
891
892             tx['default_label'] = default_label
893
894     def mktx(self, to_address, amount, label, password, fee=None, change_addr=None, from_addr= None):
895         if not self.is_valid(to_address):
896             raise BaseException("Invalid address")
897         inputs, total, fee = self.choose_tx_inputs( amount, fee, from_addr )
898         if not inputs:
899             raise BaseException("Not enough funds")
900
901         if not self.use_change and not change_addr:
902             change_addr = inputs[0][0]
903             print "sending change to", change_addr
904
905         outputs = self.choose_tx_outputs( to_address, amount, fee, total, change_addr )
906         s_inputs = self.sign_inputs( inputs, outputs, password )
907
908         tx = filter( raw_tx( s_inputs, outputs ) )
909         if to_address not in self.addressbook:
910             self.addressbook.append(to_address)
911         if label: 
912             tx_hash = Hash(tx.decode('hex') )[::-1].encode('hex')
913             self.labels[tx_hash] = label
914
915         return tx
916
917     def sendtx(self, tx):
918         tx_hash = Hash(tx.decode('hex') )[::-1].encode('hex')
919         self.tx_event.clear()
920         self.interface.send([('blockchain.transaction.broadcast', [tx])])
921         self.tx_event.wait()
922         out = self.tx_result 
923         if out != tx_hash:
924             return False, "error: " + out
925         if self.receipt:
926             self.receipts[tx_hash] = self.receipt
927             self.receipt = None
928         return True, out
929
930
931     def read_alias(self, alias):
932         # this might not be the right place for this function.
933         import urllib
934
935         m1 = re.match('([\w\-\.]+)@((\w[\w\-]+\.)+[\w\-]+)', alias)
936         m2 = re.match('((\w[\w\-]+\.)+[\w\-]+)', alias)
937         if m1:
938             url = 'http://' + m1.group(2) + '/bitcoin.id/' + m1.group(1) 
939         elif m2:
940             url = 'http://' + alias + '/bitcoin.id'
941         else:
942             return ''
943         try:
944             lines = urllib.urlopen(url).readlines()
945         except:
946             return ''
947
948         # line 0
949         line = lines[0].strip().split(':')
950         if len(line) == 1:
951             auth_name = None
952             target = signing_addr = line[0]
953         else:
954             target, auth_name, signing_addr, signature = line
955             msg = "alias:%s:%s:%s"%(alias,target,auth_name)
956             print msg, signature
957             self.verify_message(signing_addr, signature, msg)
958         
959         # other lines are signed updates
960         for line in lines[1:]:
961             line = line.strip()
962             if not line: continue
963             line = line.split(':')
964             previous = target
965             print repr(line)
966             target, signature = line
967             self.verify_message(previous, signature, "alias:%s:%s"%(alias,target))
968
969         if not self.is_valid(target):
970             raise BaseException("Invalid bitcoin address")
971
972         return target, signing_addr, auth_name
973
974     def update_password(self, seed, old_password, new_password):
975         if new_password == '': new_password = None
976         self.use_encryption = (new_password != None)
977         self.seed = self.pw_encode( seed, new_password)
978         for k in self.imported_keys.keys():
979             a = self.imported_keys[k]
980             b = self.pw_decode(a, old_password)
981             c = self.pw_encode(b, new_password)
982             self.imported_keys[k] = c
983         self.save()
984
985     def get_alias(self, alias, interactive = False, show_message=None, question = None):
986         try:
987             target, signing_address, auth_name = self.read_alias(alias)
988         except BaseException, e:
989             # raise exception if verify fails (verify the chain)
990             if interactive:
991                 show_message("Alias error: " + str(e))
992             return
993
994         print target, signing_address, auth_name
995
996         if auth_name is None:
997             a = self.aliases.get(alias)
998             if not a:
999                 msg = "Warning: the alias '%s' is self-signed.\nThe signing address is %s.\n\nDo you want to add this alias to your list of contacts?"%(alias,signing_address)
1000                 if interactive and question( msg ):
1001                     self.aliases[alias] = (signing_address, target)
1002                 else:
1003                     target = None
1004             else:
1005                 if signing_address != a[0]:
1006                     msg = "Warning: the key of alias '%s' has changed since your last visit! It is possible that someone is trying to do something nasty!!!\nDo you accept to change your trusted key?"%alias
1007                     if interactive and question( msg ):
1008                         self.aliases[alias] = (signing_address, target)
1009                     else:
1010                         target = None
1011         else:
1012             if signing_address not in self.authorities.keys():
1013                 msg = "The alias: '%s' links to %s\n\nWarning: this alias was signed by an unknown key.\nSigning authority: %s\nSigning address: %s\n\nDo you want to add this key to your list of trusted keys?"%(alias,target,auth_name,signing_address)
1014                 if interactive and question( msg ):
1015                     self.authorities[signing_address] = auth_name
1016                 else:
1017                     target = None
1018
1019         if target:
1020             self.aliases[alias] = (signing_address, target)
1021             
1022         return target
1023
1024
1025     def parse_url(self, url, show_message, question):
1026         o = url[8:].split('?')
1027         address = o[0]
1028         if len(o)>1:
1029             params = o[1].split('&')
1030         else:
1031             params = []
1032
1033         amount = label = message = signature = identity = ''
1034         for p in params:
1035             k,v = p.split('=')
1036             uv = urldecode(v)
1037             if k == 'amount': amount = uv
1038             elif k == 'message': message = uv
1039             elif k == 'label': label = uv
1040             elif k == 'signature':
1041                 identity, signature = uv.split(':')
1042                 url = url.replace('&%s=%s'%(k,v),'')
1043             else: 
1044                 print k,v
1045
1046         if label and self.labels.get(address) != label:
1047             if question('Give label "%s" to address %s ?'%(label,address)):
1048                 if address not in self.addressbook and address not in self.all_addresses(): 
1049                     self.addressbook.append(address)
1050                 self.labels[address] = label
1051
1052         if signature:
1053             if re.match('^(|([\w\-\.]+)@)((\w[\w\-]+\.)+[\w\-]+)$', identity):
1054                 signing_address = self.get_alias(identity, True, show_message, question)
1055             elif self.is_valid(identity):
1056                 signing_address = identity
1057             else:
1058                 signing_address = None
1059             if not signing_address:
1060                 return
1061             try:
1062                 self.verify_message(signing_address, signature, url )
1063                 self.receipt = (signing_address, signature, url)
1064             except:
1065                 show_message('Warning: the URI contains a bad signature.\nThe identity of the recipient cannot be verified.')
1066                 address = amount = label = identity = message = ''
1067
1068         if re.match('^(|([\w\-\.]+)@)((\w[\w\-]+\.)+[\w\-]+)$', address):
1069             payto_address = self.get_alias(address, True, show_message, question)
1070             if payto_address:
1071                 address = address + ' <' + payto_address + '>'
1072
1073         return address, amount, label, message, signature, identity, url
1074
1075
1076     def update(self):
1077         self.interface.poke()
1078         self.up_to_date_event.wait(10000000000)
1079
1080
1081     def start_session(self, interface):
1082         self.interface = interface
1083         self.interface.send([('server.banner',[]), ('blockchain.numblocks.subscribe',[]), ('server.peers.subscribe',[])])
1084         self.interface.subscribe(self.all_addresses())
1085
1086
1087     def freeze(self,addr):
1088         if addr in self.all_addresses() and addr not in self.frozen_addresses:
1089             self.unprioritize(addr)
1090             self.frozen_addresses.append(addr)
1091             self.save()
1092             return True
1093         else:
1094             return False
1095
1096     def unfreeze(self,addr):
1097         if addr in self.all_addresses() and addr in self.frozen_addresses:
1098             self.frozen_addresses.remove(addr)
1099             self.save()
1100             return True
1101         else:
1102             return False
1103
1104     def prioritize(self,addr):
1105         if addr in self.all_addresses() and addr not in self.prioritized_addresses:
1106             self.unfreeze(addr)
1107             self.prioritized_addresses.append(addr)
1108             self.save()
1109             return True
1110         else:
1111             return False
1112
1113     def unprioritize(self,addr):
1114         if addr in self.all_addresses() and addr in self.prioritized_addresses:
1115             self.prioritized_addresses.remove(addr)
1116             self.save()
1117             return True
1118         else:
1119             return False