Repository navigation
Conversation
When an input carries a non_witness_utxo but no witness_utxo, the signature type was chosen from the presence of witness_utxo alone, so a p2wpkh, p2sh-p2wpkh, p2wsh or p2sh-p2wsh output backed only by the full previous transaction was signed with the legacy digest. Finalize and extract then succeed, so the caller gets a complete transaction whose signature is invalid. Choose the signature type from the referenced output's script, including a matching P2SH redeem script, and check the previous transaction's txid before using it. Add a test that signs the same input with and without witness_utxo for all four script types, verifies each signature against the BIP143 digest and requires the two signatures to be identical.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
When an input carries a non_witness_utxo but no witness_utxo, the signature type is chosen
from the presence of witness_utxo alone, so a p2wpkh, p2sh-p2wpkh, p2wsh or p2sh-p2wsh output
backed only by the full previous transaction is signed with the legacy digest. Finalize and
extract then succeed, so the caller gets a complete transaction whose signature is invalid.
This change chooses the signature type from the referenced output's script, including a
matching P2SH redeem script, and checks the previous transaction's txid before using it.
The new test signs the same input with and without witness_utxo for all four script types,
verifies each signature against the BIP143 digest, requires the two signatures to be
identical, checks the serialized result and finalizes, and checks that a previous
transaction whose txid does not match the input is not signed from. It fails on master at
the BIP143 verification and passes with this change.
Validation, on master 374df23 plus this change alone (macOS, Apple clang 21, autoconf 2.73,
python 3.14.7):
make check: all 8 C test programs pass (test_bech32, test_psbt, test_psbt_limits,
test_clear, test_coinselection, test_tx, test_descriptor, test_elements_tx).
this change under ASAN and UBSAN: 263,613 PSBTs give a different result, and every one of
them contains an input backed only by a previous transaction whose referenced output is
segwit v0; no PSBT without such an input changed; no sanitizer reports. This bounds where
behaviour changed. Correctness of the changed signatures is established by the digest
checks in the new test for its fixtures, not for every differing mutant.
Not run here: valgrind, gcc ASAN/UBSAN, scan-build, cmake and mingw lanes. The no Elements
ABI lane fails on this toolchain before and after the change, on unused static functions in
libsecp256k1 headers under -Werror (for example src/util.h:34:13 print_buf_plain); with
-Wno-unused-function added it builds and passes make check. That is an adapted local build,
not the upstream lane.