Bitcoin Core  22.99.0
P2P Digital Currency
script.cpp
Go to the documentation of this file.
1 // Copyright (c) 2019-2021 The Bitcoin Core developers
2 // Distributed under the MIT software license, see the accompanying
3 // file COPYING or http://www.opensource.org/licenses/mit-license.php.
4 
5 #include <chainparams.h>
6 #include <compressor.h>
7 #include <core_io.h>
8 #include <core_memusage.h>
9 #include <key_io.h>
10 #include <policy/policy.h>
11 #include <pubkey.h>
12 #include <rpc/util.h>
13 #include <script/descriptor.h>
14 #include <script/interpreter.h>
15 #include <script/script.h>
16 #include <script/script_error.h>
17 #include <script/sign.h>
18 #include <script/signingprovider.h>
19 #include <script/standard.h>
20 #include <streams.h>
22 #include <test/fuzz/fuzz.h>
23 #include <test/fuzz/util.h>
24 #include <univalue.h>
25 
26 #include <algorithm>
27 #include <cassert>
28 #include <cstdint>
29 #include <optional>
30 #include <string>
31 #include <vector>
32 
34 {
35  // Fuzzers using pubkey must hold an ECCVerifyHandle.
36  static const ECCVerifyHandle verify_handle;
37 
39 }
40 
42 {
43  FuzzedDataProvider fuzzed_data_provider(buffer.data(), buffer.size());
44  const CScript script{ConsumeScript(fuzzed_data_provider)};
45 
46  CompressedScript compressed;
47  if (CompressScript(script, compressed)) {
48  const unsigned int size = compressed[0];
49  compressed.erase(compressed.begin());
50  assert(size <= 5);
51  CScript decompressed_script;
52  const bool ok = DecompressScript(decompressed_script, size, compressed);
53  assert(ok);
54  assert(script == decompressed_script);
55  }
56 
57  TxoutType which_type;
58  bool is_standard_ret = IsStandard(script, which_type);
59  if (!is_standard_ret) {
60  assert(which_type == TxoutType::NONSTANDARD ||
61  which_type == TxoutType::NULL_DATA ||
62  which_type == TxoutType::MULTISIG);
63  }
64  if (which_type == TxoutType::NONSTANDARD) {
65  assert(!is_standard_ret);
66  }
67  if (which_type == TxoutType::NULL_DATA) {
68  assert(script.IsUnspendable());
69  }
70  if (script.IsUnspendable()) {
71  assert(which_type == TxoutType::NULL_DATA ||
72  which_type == TxoutType::NONSTANDARD);
73  }
74 
75  CTxDestination address;
76  bool extract_destination_ret = ExtractDestination(script, address);
77  if (!extract_destination_ret) {
78  assert(which_type == TxoutType::PUBKEY ||
79  which_type == TxoutType::NONSTANDARD ||
80  which_type == TxoutType::NULL_DATA ||
81  which_type == TxoutType::MULTISIG);
82  }
83  if (which_type == TxoutType::NONSTANDARD ||
84  which_type == TxoutType::NULL_DATA ||
85  which_type == TxoutType::MULTISIG) {
86  assert(!extract_destination_ret);
87  }
88 
89  const FlatSigningProvider signing_provider;
90  (void)InferDescriptor(script, signing_provider);
91  (void)IsSegWitOutput(signing_provider, script);
92  (void)IsSolvable(signing_provider, script);
93 
94  (void)RecursiveDynamicUsage(script);
95 
96  std::vector<std::vector<unsigned char>> solutions;
97  (void)Solver(script, solutions);
98 
99  (void)script.HasValidOps();
100  (void)script.IsPayToScriptHash();
101  (void)script.IsPayToWitnessScriptHash();
102  (void)script.IsPushOnly();
103  (void)script.GetSigOpCount(/* fAccurate= */ false);
104 
105  (void)FormatScript(script);
106  (void)ScriptToAsmStr(script, false);
107  (void)ScriptToAsmStr(script, true);
108 
110  ScriptPubKeyToUniv(script, o1, true);
112  ScriptPubKeyToUniv(script, o2, false);
114  ScriptToUniv(script, o3);
115 
116  {
117  const std::vector<uint8_t> bytes = ConsumeRandomLengthByteVector(fuzzed_data_provider);
118  CompressedScript compressed_script;
119  compressed_script.assign(bytes.begin(), bytes.end());
120  // DecompressScript(..., ..., bytes) is not guaranteed to be defined if the bytes vector is too short
121  if (compressed_script.size() >= 32) {
122  CScript decompressed_script;
123  DecompressScript(decompressed_script, fuzzed_data_provider.ConsumeIntegral<unsigned int>(), compressed_script);
124  }
125  }
126 
127  const std::optional<CScript> other_script = ConsumeDeserializable<CScript>(fuzzed_data_provider);
128  if (other_script) {
129  {
130  CScript script_mut{script};
131  (void)FindAndDelete(script_mut, *other_script);
132  }
133  const std::vector<std::string> random_string_vector = ConsumeRandomLengthStringVector(fuzzed_data_provider);
134  const uint32_t u32{fuzzed_data_provider.ConsumeIntegral<uint32_t>()};
135  const uint32_t flags{u32 | SCRIPT_VERIFY_P2SH};
136  {
137  CScriptWitness wit;
138  for (const auto& s : random_string_vector) {
139  wit.stack.emplace_back(s.begin(), s.end());
140  }
141  (void)CountWitnessSigOps(script, *other_script, &wit, flags);
142  wit.SetNull();
143  }
144  }
145 
146  (void)GetOpName(ConsumeOpcodeType(fuzzed_data_provider));
147  (void)ScriptErrorString(static_cast<ScriptError>(fuzzed_data_provider.ConsumeIntegralInRange<int>(0, SCRIPT_ERR_ERROR_COUNT)));
148 
149  {
150  const std::vector<uint8_t> bytes = ConsumeRandomLengthByteVector(fuzzed_data_provider);
151  CScript append_script{bytes.begin(), bytes.end()};
152  append_script << fuzzed_data_provider.ConsumeIntegral<int64_t>();
153  append_script << ConsumeOpcodeType(fuzzed_data_provider);
154  append_script << CScriptNum{fuzzed_data_provider.ConsumeIntegral<int64_t>()};
155  append_script << ConsumeRandomLengthByteVector(fuzzed_data_provider);
156  }
157 
158  {
159  const CTxDestination tx_destination_1{
160  fuzzed_data_provider.ConsumeBool() ?
161  DecodeDestination(fuzzed_data_provider.ConsumeRandomLengthString()) :
162  ConsumeTxDestination(fuzzed_data_provider)};
163  const CTxDestination tx_destination_2{ConsumeTxDestination(fuzzed_data_provider)};
164  const std::string encoded_dest{EncodeDestination(tx_destination_1)};
165  const UniValue json_dest{DescribeAddress(tx_destination_1)};
166  Assert(tx_destination_1 == DecodeDestination(encoded_dest));
167  (void)GetKeyForDestination(/*store=*/{}, tx_destination_1);
168  const CScript dest{GetScriptForDestination(tx_destination_1)};
169  const bool valid{IsValidDestination(tx_destination_1)};
170  Assert(dest.empty() != valid);
171 
172  Assert(valid == IsValidDestinationString(encoded_dest));
173 
174  (void)(tx_destination_1 < tx_destination_2);
175  if (tx_destination_1 == tx_destination_2) {
176  Assert(encoded_dest == EncodeDestination(tx_destination_2));
177  Assert(json_dest.write() == DescribeAddress(tx_destination_2).write());
178  Assert(dest == GetScriptForDestination(tx_destination_2));
179  }
180  }
181 }
ScriptErrorString
std::string ScriptErrorString(const ScriptError serror)
Definition: script_error.cpp:10
ConsumeRandomLengthStringVector
std::vector< std::string > ConsumeRandomLengthStringVector(FuzzedDataProvider &fuzzed_data_provider, const size_t max_vector_size=16, const size_t max_string_length=16) noexcept
Definition: util.h:81
CountWitnessSigOps
size_t CountWitnessSigOps(const CScript &scriptSig, const CScript &scriptPubKey, const CScriptWitness *witness, unsigned int flags)
Definition: interpreter.cpp:2106
policy.h
FindAndDelete
int FindAndDelete(CScript &script, const CScript &b)
Definition: interpreter.cpp:253
UniValue::VOBJ
@ VOBJ
Definition: univalue.h:19
assert
assert(!tx.IsCoinBase())
Solver
TxoutType Solver(const CScript &scriptPubKey, std::vector< std::vector< unsigned char >> &vSolutionsRet)
Parse a scriptPubKey and identify script type for standard scripts.
Definition: standard.cpp:144
IsStandard
bool IsStandard(const CScript &scriptPubKey, TxoutType &whichType)
Definition: policy.cpp:58
TxoutType
TxoutType
Definition: standard.h:59
flags
int flags
Definition: bitcoin-tx.cpp:525
key_io.h
ScriptPubKeyToUniv
void ScriptPubKeyToUniv(const CScript &scriptPubKey, UniValue &out, bool include_hex, bool include_address=true)
Definition: core_write.cpp:150
streams.h
TxoutType::NONSTANDARD
@ NONSTANDARD
prevector::erase
iterator erase(iterator pos)
Definition: prevector.h:401
ScriptToUniv
void ScriptToUniv(const CScript &script, UniValue &out)
Definition: core_write.cpp:145
GetScriptForDestination
CScript GetScriptForDestination(const CTxDestination &dest)
Generate a Bitcoin scriptPubKey for the given CTxDestination.
Definition: standard.cpp:310
ConsumeScript
CScript ConsumeScript(FuzzedDataProvider &fuzzed_data_provider, const bool maybe_p2wsh) noexcept
Definition: util.cpp:340
GetOpName
std::string GetOpName(opcodetype opcode)
Definition: script.cpp:12
util.h
FuzzedDataProvider::ConsumeRandomLengthString
std::string ConsumeRandomLengthString(size_t max_length)
Definition: FuzzedDataProvider.h:152
interpreter.h
FormatScript
std::string FormatScript(const CScript &script)
Definition: core_write.cpp:34
pubkey.h
chainparams.h
core_io.h
ConsumeOpcodeType
opcodetype ConsumeOpcodeType(FuzzedDataProvider &fuzzed_data_provider) noexcept
Definition: util.h:124
Assert
#define Assert(val)
Identity function.
Definition: check.h:57
ConsumeTxDestination
CTxDestination ConsumeTxDestination(FuzzedDataProvider &fuzzed_data_provider) noexcept
Definition: util.cpp:417
UniValue
Definition: univalue.h:17
ScriptError
enum ScriptError_t ScriptError
compressor.h
CScriptWitness
Definition: script.h:557
CScriptNum
Definition: script.h:219
signingprovider.h
initialize_script
void initialize_script()
Definition: script.cpp:33
RecursiveDynamicUsage
static size_t RecursiveDynamicUsage(const CScript &script)
Definition: core_memusage.h:12
TxoutType::PUBKEY
@ PUBKEY
CTxDestination
std::variant< CNoDestination, PKHash, ScriptHash, WitnessV0ScriptHash, WitnessV0KeyHash, WitnessV1Taproot, WitnessUnknown > CTxDestination
A txout script template with a specific destination.
Definition: standard.h:157
IsValidDestination
bool IsValidDestination(const CTxDestination &dest)
Check whether a CTxDestination is a CNoDestination.
Definition: standard.cpp:332
CompressScript
bool CompressScript(const CScript &script, CompressedScript &out)
Definition: compressor.cpp:55
IsSegWitOutput
bool IsSegWitOutput(const SigningProvider &provider, const CScript &script)
Check whether a scriptPubKey is known to be segwit.
Definition: sign.cpp:602
univalue.h
CBaseChainParams::REGTEST
static const std::string REGTEST
Definition: chainparamsbase.h:25
FuzzedDataProvider.h
sign.h
DescribeAddress
UniValue DescribeAddress(const CTxDestination &dest)
Definition: util.cpp:325
ConsumeRandomLengthByteVector
std::vector< uint8_t > ConsumeRandomLengthByteVector(FuzzedDataProvider &fuzzed_data_provider, const std::optional< size_t > &max_length=std::nullopt) noexcept
Definition: util.h:63
standard.h
GetKeyForDestination
CKeyID GetKeyForDestination(const SigningProvider &store, const CTxDestination &dest)
Return the CKeyID of the key involved in a script (if there is a unique one).
Definition: signingprovider.cpp:191
SelectParams
void SelectParams(const std::string &network)
Sets the params returned by Params() to those for the given chain name.
Definition: chainparams.cpp:580
CScript
Serialized script, used inside transaction inputs and outputs.
Definition: script.h:405
script.h
ExtractDestination
bool ExtractDestination(const CScript &scriptPubKey, CTxDestination &addressRet)
Parse a standard scriptPubKey for the destination address.
Definition: standard.cpp:213
TxoutType::NULL_DATA
@ NULL_DATA
unspendable OP_RETURN script that carries data
prevector
Implements a drop-in replacement for std::vector<T> which stores up to N elements directly (without h...
Definition: prevector.h:37
prevector::assign
void assign(size_type n, const T &val)
Definition: prevector.h:218
core_memusage.h
ECCVerifyHandle
Users of this module must hold an ECCVerifyHandle.
Definition: pubkey.h:332
CScriptWitness::SetNull
void SetNull()
Definition: script.h:568
IsSolvable
bool IsSolvable(const SigningProvider &provider, const CScript &script)
Definition: sign.cpp:583
fuzz.h
script_error.h
FuzzedDataProvider
Definition: FuzzedDataProvider.h:31
FuzzedDataProvider::ConsumeIntegral
T ConsumeIntegral()
Definition: FuzzedDataProvider.h:194
SCRIPT_VERIFY_P2SH
@ SCRIPT_VERIFY_P2SH
Definition: interpreter.h:46
DecodeDestination
CTxDestination DecodeDestination(const std::string &str, std::string &error_msg, std::vector< int > *error_locations)
Definition: key_io.cpp:281
prevector::size
size_type size() const
Definition: prevector.h:282
prevector::begin
iterator begin()
Definition: prevector.h:290
TxoutType::MULTISIG
@ MULTISIG
IsValidDestinationString
bool IsValidDestinationString(const std::string &str, const CChainParams &params)
Definition: key_io.cpp:292
FUZZ_TARGET_INIT
FUZZ_TARGET_INIT(script, initialize_script)
Definition: script.cpp:41
FuzzedDataProvider::ConsumeBool
bool ConsumeBool()
Definition: FuzzedDataProvider.h:288
u32
unsigned int u32
Definition: crypto_diff_fuzz_chacha20.cpp:20
InferDescriptor
std::unique_ptr< Descriptor > InferDescriptor(const CScript &script, const SigningProvider &provider)
Find a descriptor for the specified script, using information from provider where possible.
Definition: descriptor.cpp:1413
DecompressScript
bool DecompressScript(CScript &script, unsigned int nSize, const CompressedScript &in)
Definition: compressor.cpp:95
FuzzedDataProvider::ConsumeIntegralInRange
T ConsumeIntegralInRange(T min, T max)
Definition: FuzzedDataProvider.h:204
EncodeDestination
std::string EncodeDestination(const CTxDestination &dest)
Definition: key_io.cpp:276
ScriptToAsmStr
std::string ScriptToAsmStr(const CScript &script, const bool fAttemptSighashDecode=false)
Create the assembly string representation of a CScript object.
Definition: core_write.cpp:93
CScriptWitness::stack
std::vector< std::vector< unsigned char > > stack
Definition: script.h:561
FlatSigningProvider
Definition: signingprovider.h:72
descriptor.h
SCRIPT_ERR_ERROR_COUNT
@ SCRIPT_ERR_ERROR_COUNT
Definition: script_error.h:85