Branch data Line data Source code
# 1 : : // Copyright (c) 2009-2010 Satoshi Nakamoto
# 2 : : // Copyright (c) 2009-2020 The Bitcoin Core developers
# 3 : : // Distributed under the MIT software license, see the accompanying
# 4 : : // file COPYING or http://www.opensource.org/licenses/mit-license.php.
# 5 : :
# 6 : : #ifndef BITCOIN_SCRIPT_INTERPRETER_H
# 7 : : #define BITCOIN_SCRIPT_INTERPRETER_H
# 8 : :
# 9 : : #include <script/script_error.h>
# 10 : : #include <span.h>
# 11 : : #include <primitives/transaction.h>
# 12 : :
# 13 : : #include <vector>
# 14 : : #include <stdint.h>
# 15 : :
# 16 : : class CPubKey;
# 17 : : class XOnlyPubKey;
# 18 : : class CScript;
# 19 : : class CTransaction;
# 20 : : class CTxOut;
# 21 : : class uint256;
# 22 : :
# 23 : : /** Signature hash types/flags */
# 24 : : enum
# 25 : : {
# 26 : : SIGHASH_ALL = 1,
# 27 : : SIGHASH_NONE = 2,
# 28 : : SIGHASH_SINGLE = 3,
# 29 : : SIGHASH_ANYONECANPAY = 0x80,
# 30 : :
# 31 : : SIGHASH_DEFAULT = 0, //!< Taproot only; implied when sighash byte is missing, and equivalent to SIGHASH_ALL
# 32 : : SIGHASH_OUTPUT_MASK = 3,
# 33 : : SIGHASH_INPUT_MASK = 0x80,
# 34 : : };
# 35 : :
# 36 : : /** Script verification flags.
# 37 : : *
# 38 : : * All flags are intended to be soft forks: the set of acceptable scripts under
# 39 : : * flags (A | B) is a subset of the acceptable scripts under flag (A).
# 40 : : */
# 41 : : enum
# 42 : : {
# 43 : : SCRIPT_VERIFY_NONE = 0,
# 44 : :
# 45 : : // Evaluate P2SH subscripts (BIP16).
# 46 : : SCRIPT_VERIFY_P2SH = (1U << 0),
# 47 : :
# 48 : : // Passing a non-strict-DER signature or one with undefined hashtype to a checksig operation causes script failure.
# 49 : : // Evaluating a pubkey that is not (0x04 + 64 bytes) or (0x02 or 0x03 + 32 bytes) by checksig causes script failure.
# 50 : : // (not used or intended as a consensus rule).
# 51 : : SCRIPT_VERIFY_STRICTENC = (1U << 1),
# 52 : :
# 53 : : // Passing a non-strict-DER signature to a checksig operation causes script failure (BIP62 rule 1)
# 54 : : SCRIPT_VERIFY_DERSIG = (1U << 2),
# 55 : :
# 56 : : // Passing a non-strict-DER signature or one with S > order/2 to a checksig operation causes script failure
# 57 : : // (BIP62 rule 5).
# 58 : : SCRIPT_VERIFY_LOW_S = (1U << 3),
# 59 : :
# 60 : : // verify dummy stack item consumed by CHECKMULTISIG is of zero-length (BIP62 rule 7).
# 61 : : SCRIPT_VERIFY_NULLDUMMY = (1U << 4),
# 62 : :
# 63 : : // Using a non-push operator in the scriptSig causes script failure (BIP62 rule 2).
# 64 : : SCRIPT_VERIFY_SIGPUSHONLY = (1U << 5),
# 65 : :
# 66 : : // Require minimal encodings for all push operations (OP_0... OP_16, OP_1NEGATE where possible, direct
# 67 : : // pushes up to 75 bytes, OP_PUSHDATA up to 255 bytes, OP_PUSHDATA2 for anything larger). Evaluating
# 68 : : // any other push causes the script to fail (BIP62 rule 3).
# 69 : : // In addition, whenever a stack element is interpreted as a number, it must be of minimal length (BIP62 rule 4).
# 70 : : SCRIPT_VERIFY_MINIMALDATA = (1U << 6),
# 71 : :
# 72 : : // Discourage use of NOPs reserved for upgrades (NOP1-10)
# 73 : : //
# 74 : : // Provided so that nodes can avoid accepting or mining transactions
# 75 : : // containing executed NOP's whose meaning may change after a soft-fork,
# 76 : : // thus rendering the script invalid; with this flag set executing
# 77 : : // discouraged NOPs fails the script. This verification flag will never be
# 78 : : // a mandatory flag applied to scripts in a block. NOPs that are not
# 79 : : // executed, e.g. within an unexecuted IF ENDIF block, are *not* rejected.
# 80 : : // NOPs that have associated forks to give them new meaning (CLTV, CSV)
# 81 : : // are not subject to this rule.
# 82 : : SCRIPT_VERIFY_DISCOURAGE_UPGRADABLE_NOPS = (1U << 7),
# 83 : :
# 84 : : // Require that only a single stack element remains after evaluation. This changes the success criterion from
# 85 : : // "At least one stack element must remain, and when interpreted as a boolean, it must be true" to
# 86 : : // "Exactly one stack element must remain, and when interpreted as a boolean, it must be true".
# 87 : : // (BIP62 rule 6)
# 88 : : // Note: CLEANSTACK should never be used without P2SH or WITNESS.
# 89 : : // Note: WITNESS_V0 and TAPSCRIPT script execution have behavior similar to CLEANSTACK as part of their
# 90 : : // consensus rules. It is automatic there and does not need this flag.
# 91 : : SCRIPT_VERIFY_CLEANSTACK = (1U << 8),
# 92 : :
# 93 : : // Verify CHECKLOCKTIMEVERIFY
# 94 : : //
# 95 : : // See BIP65 for details.
# 96 : : SCRIPT_VERIFY_CHECKLOCKTIMEVERIFY = (1U << 9),
# 97 : :
# 98 : : // support CHECKSEQUENCEVERIFY opcode
# 99 : : //
# 100 : : // See BIP112 for details
# 101 : : SCRIPT_VERIFY_CHECKSEQUENCEVERIFY = (1U << 10),
# 102 : :
# 103 : : // Support segregated witness
# 104 : : //
# 105 : : SCRIPT_VERIFY_WITNESS = (1U << 11),
# 106 : :
# 107 : : // Making v1-v16 witness program non-standard
# 108 : : //
# 109 : : SCRIPT_VERIFY_DISCOURAGE_UPGRADABLE_WITNESS_PROGRAM = (1U << 12),
# 110 : :
# 111 : : // Segwit script only: Require the argument of OP_IF/NOTIF to be exactly 0x01 or empty vector
# 112 : : //
# 113 : : // Note: TAPSCRIPT script execution has behavior similar to MINIMALIF as part of its consensus
# 114 : : // rules. It is automatic there and does not depend on this flag.
# 115 : : SCRIPT_VERIFY_MINIMALIF = (1U << 13),
# 116 : :
# 117 : : // Signature(s) must be empty vector if a CHECK(MULTI)SIG operation failed
# 118 : : //
# 119 : : SCRIPT_VERIFY_NULLFAIL = (1U << 14),
# 120 : :
# 121 : : // Public keys in segregated witness scripts must be compressed
# 122 : : //
# 123 : : SCRIPT_VERIFY_WITNESS_PUBKEYTYPE = (1U << 15),
# 124 : :
# 125 : : // Making OP_CODESEPARATOR and FindAndDelete fail any non-segwit scripts
# 126 : : //
# 127 : : SCRIPT_VERIFY_CONST_SCRIPTCODE = (1U << 16),
# 128 : :
# 129 : : // Taproot/Tapscript validation (BIPs 341 & 342)
# 130 : : //
# 131 : : SCRIPT_VERIFY_TAPROOT = (1U << 17),
# 132 : :
# 133 : : // Making unknown Taproot leaf versions non-standard
# 134 : : //
# 135 : : SCRIPT_VERIFY_DISCOURAGE_UPGRADABLE_TAPROOT_VERSION = (1U << 18),
# 136 : :
# 137 : : // Making unknown OP_SUCCESS non-standard
# 138 : : SCRIPT_VERIFY_DISCOURAGE_OP_SUCCESS = (1U << 19),
# 139 : :
# 140 : : // Making unknown public key versions (in BIP 342 scripts) non-standard
# 141 : : SCRIPT_VERIFY_DISCOURAGE_UPGRADABLE_PUBKEYTYPE = (1U << 20),
# 142 : : };
# 143 : :
# 144 : : bool CheckSignatureEncoding(const std::vector<unsigned char> &vchSig, unsigned int flags, ScriptError* serror);
# 145 : :
# 146 : : struct PrecomputedTransactionData
# 147 : : {
# 148 : : // BIP341 precomputed data.
# 149 : : // These are single-SHA256, see https://github.com/bitcoin/bips/blob/master/bip-0341.mediawiki#cite_note-15.
# 150 : : uint256 m_prevouts_single_hash;
# 151 : : uint256 m_sequences_single_hash;
# 152 : : uint256 m_outputs_single_hash;
# 153 : : uint256 m_spent_amounts_single_hash;
# 154 : : uint256 m_spent_scripts_single_hash;
# 155 : : //! Whether the 5 fields above are initialized.
# 156 : : bool m_bip341_taproot_ready = false;
# 157 : :
# 158 : : // BIP143 precomputed data (double-SHA256).
# 159 : : uint256 hashPrevouts, hashSequence, hashOutputs;
# 160 : : //! Whether the 3 fields above are initialized.
# 161 : : bool m_bip143_segwit_ready = false;
# 162 : :
# 163 : : std::vector<CTxOut> m_spent_outputs;
# 164 : : //! Whether m_spent_outputs is initialized.
# 165 : : bool m_spent_outputs_ready = false;
# 166 : :
# 167 : 195933 : PrecomputedTransactionData() = default;
# 168 : :
# 169 : : template <class T>
# 170 : : void Init(const T& tx, std::vector<CTxOut>&& spent_outputs);
# 171 : :
# 172 : : template <class T>
# 173 : : explicit PrecomputedTransactionData(const T& tx);
# 174 : : };
# 175 : :
# 176 : : enum class SigVersion
# 177 : : {
# 178 : : BASE = 0, //!< Bare scripts and BIP16 P2SH-wrapped redeemscripts
# 179 : : WITNESS_V0 = 1, //!< Witness v0 (P2WPKH and P2WSH); see BIP 141
# 180 : : TAPROOT = 2, //!< Witness v1 with 32-byte program, not BIP16 P2SH-wrapped, key path spending; see BIP 341
# 181 : : TAPSCRIPT = 3, //!< Witness v1 with 32-byte program, not BIP16 P2SH-wrapped, script path spending, leaf version 0xc0; see BIP 342
# 182 : : };
# 183 : :
# 184 : : struct ScriptExecutionData
# 185 : : {
# 186 : : //! Whether m_tapleaf_hash is initialized.
# 187 : : bool m_tapleaf_hash_init = false;
# 188 : : //! The tapleaf hash.
# 189 : : uint256 m_tapleaf_hash;
# 190 : :
# 191 : : //! Whether m_codeseparator_pos is initialized.
# 192 : : bool m_codeseparator_pos_init = false;
# 193 : : //! Opcode position of the last executed OP_CODESEPARATOR (or 0xFFFFFFFF if none executed).
# 194 : : uint32_t m_codeseparator_pos;
# 195 : :
# 196 : : //! Whether m_annex_present and (when needed) m_annex_hash are initialized.
# 197 : : bool m_annex_init = false;
# 198 : : //! Whether an annex is present.
# 199 : : bool m_annex_present;
# 200 : : //! Hash of the annex data.
# 201 : : uint256 m_annex_hash;
# 202 : :
# 203 : : //! Whether m_validation_weight_left is initialized.
# 204 : : bool m_validation_weight_left_init = false;
# 205 : : //! How much validation weight is left (decremented for every successful non-empty signature check).
# 206 : : int64_t m_validation_weight_left;
# 207 : : };
# 208 : :
# 209 : : /** Signature hash sizes */
# 210 : : static constexpr size_t WITNESS_V0_SCRIPTHASH_SIZE = 32;
# 211 : : static constexpr size_t WITNESS_V0_KEYHASH_SIZE = 20;
# 212 : : static constexpr size_t WITNESS_V1_TAPROOT_SIZE = 32;
# 213 : :
# 214 : : static constexpr uint8_t TAPROOT_LEAF_MASK = 0xfe;
# 215 : : static constexpr uint8_t TAPROOT_LEAF_TAPSCRIPT = 0xc0;
# 216 : : static constexpr size_t TAPROOT_CONTROL_BASE_SIZE = 33;
# 217 : : static constexpr size_t TAPROOT_CONTROL_NODE_SIZE = 32;
# 218 : : static constexpr size_t TAPROOT_CONTROL_MAX_NODE_COUNT = 128;
# 219 : : static constexpr size_t TAPROOT_CONTROL_MAX_SIZE = TAPROOT_CONTROL_BASE_SIZE + TAPROOT_CONTROL_NODE_SIZE * TAPROOT_CONTROL_MAX_NODE_COUNT;
# 220 : :
# 221 : : template <class T>
# 222 : : uint256 SignatureHash(const CScript& scriptCode, const T& txTo, unsigned int nIn, int nHashType, const CAmount& amount, SigVersion sigversion, const PrecomputedTransactionData* cache = nullptr);
# 223 : :
# 224 : : class BaseSignatureChecker
# 225 : : {
# 226 : : public:
# 227 : : virtual bool CheckECDSASignature(const std::vector<unsigned char>& scriptSig, const std::vector<unsigned char>& vchPubKey, const CScript& scriptCode, SigVersion sigversion) const
# 228 : 0 : {
# 229 : 0 : return false;
# 230 : 0 : }
# 231 : :
# 232 : : virtual bool CheckSchnorrSignature(Span<const unsigned char> sig, Span<const unsigned char> pubkey, SigVersion sigversion, const ScriptExecutionData& execdata, ScriptError* serror = nullptr) const
# 233 : 0 : {
# 234 : 0 : return false;
# 235 : 0 : }
# 236 : :
# 237 : : virtual bool CheckLockTime(const CScriptNum& nLockTime) const
# 238 : 0 : {
# 239 : 0 : return false;
# 240 : 0 : }
# 241 : :
# 242 : : virtual bool CheckSequence(const CScriptNum& nSequence) const
# 243 : 0 : {
# 244 : 0 : return false;
# 245 : 0 : }
# 246 : :
# 247 : 1157760 : virtual ~BaseSignatureChecker() {}
# 248 : : };
# 249 : :
# 250 : : /** Enum to specify what *TransactionSignatureChecker's behavior should be
# 251 : : * when dealing with missing transaction data.
# 252 : : */
# 253 : : enum class MissingDataBehavior
# 254 : : {
# 255 : : ASSERT_FAIL, //!< Abort execution through assertion failure (for consensus code)
# 256 : : FAIL, //!< Just act as if the signature was invalid
# 257 : : };
# 258 : :
# 259 : : template <class T>
# 260 : : class GenericTransactionSignatureChecker : public BaseSignatureChecker
# 261 : : {
# 262 : : private:
# 263 : : const T* txTo;
# 264 : : const MissingDataBehavior m_mdb;
# 265 : : unsigned int nIn;
# 266 : : const CAmount amount;
# 267 : : const PrecomputedTransactionData* txdata;
# 268 : :
# 269 : : protected:
# 270 : : virtual bool VerifyECDSASignature(const std::vector<unsigned char>& vchSig, const CPubKey& vchPubKey, const uint256& sighash) const;
# 271 : : virtual bool VerifySchnorrSignature(Span<const unsigned char> sig, const XOnlyPubKey& pubkey, const uint256& sighash) const;
# 272 : :
# 273 : : public:
# 274 : 259896 : GenericTransactionSignatureChecker(const T* txToIn, unsigned int nInIn, const CAmount& amountIn, MissingDataBehavior mdb) : txTo(txToIn), m_mdb(mdb), nIn(nInIn), amount(amountIn), txdata(nullptr) {}
# 275 : 622617 : GenericTransactionSignatureChecker(const T* txToIn, unsigned int nInIn, const CAmount& amountIn, const PrecomputedTransactionData& txdataIn, MissingDataBehavior mdb) : txTo(txToIn), m_mdb(mdb), nIn(nInIn), amount(amountIn), txdata(&txdataIn) {}
# 276 : : bool CheckECDSASignature(const std::vector<unsigned char>& scriptSig, const std::vector<unsigned char>& vchPubKey, const CScript& scriptCode, SigVersion sigversion) const override;
# 277 : : bool CheckSchnorrSignature(Span<const unsigned char> sig, Span<const unsigned char> pubkey, SigVersion sigversion, const ScriptExecutionData& execdata, ScriptError* serror = nullptr) const override;
# 278 : : bool CheckLockTime(const CScriptNum& nLockTime) const override;
# 279 : : bool CheckSequence(const CScriptNum& nSequence) const override;
# 280 : : };
# 281 : :
# 282 : : using TransactionSignatureChecker = GenericTransactionSignatureChecker<CTransaction>;
# 283 : : using MutableTransactionSignatureChecker = GenericTransactionSignatureChecker<CMutableTransaction>;
# 284 : :
# 285 : : class DeferringSignatureChecker : public BaseSignatureChecker
# 286 : : {
# 287 : : protected:
# 288 : : BaseSignatureChecker& m_checker;
# 289 : :
# 290 : : public:
# 291 : 69463 : DeferringSignatureChecker(BaseSignatureChecker& checker) : m_checker(checker) {}
# 292 : :
# 293 : : bool CheckECDSASignature(const std::vector<unsigned char>& scriptSig, const std::vector<unsigned char>& vchPubKey, const CScript& scriptCode, SigVersion sigversion) const override
# 294 : 0 : {
# 295 : 0 : return m_checker.CheckECDSASignature(scriptSig, vchPubKey, scriptCode, sigversion);
# 296 : 0 : }
# 297 : :
# 298 : : bool CheckSchnorrSignature(Span<const unsigned char> sig, Span<const unsigned char> pubkey, SigVersion sigversion, const ScriptExecutionData& execdata, ScriptError* serror = nullptr) const override
# 299 : 0 : {
# 300 : 0 : return m_checker.CheckSchnorrSignature(sig, pubkey, sigversion, execdata, serror);
# 301 : 0 : }
# 302 : :
# 303 : : bool CheckLockTime(const CScriptNum& nLockTime) const override
# 304 : 8 : {
# 305 : 8 : return m_checker.CheckLockTime(nLockTime);
# 306 : 8 : }
# 307 : : bool CheckSequence(const CScriptNum& nSequence) const override
# 308 : 8 : {
# 309 : 8 : return m_checker.CheckSequence(nSequence);
# 310 : 8 : }
# 311 : : };
# 312 : :
# 313 : : bool EvalScript(std::vector<std::vector<unsigned char> >& stack, const CScript& script, unsigned int flags, const BaseSignatureChecker& checker, SigVersion sigversion, ScriptExecutionData& execdata, ScriptError* error = nullptr);
# 314 : : bool EvalScript(std::vector<std::vector<unsigned char> >& stack, const CScript& script, unsigned int flags, const BaseSignatureChecker& checker, SigVersion sigversion, ScriptError* error = nullptr);
# 315 : : bool VerifyScript(const CScript& scriptSig, const CScript& scriptPubKey, const CScriptWitness* witness, unsigned int flags, const BaseSignatureChecker& checker, ScriptError* serror = nullptr);
# 316 : :
# 317 : : size_t CountWitnessSigOps(const CScript& scriptSig, const CScript& scriptPubKey, const CScriptWitness* witness, unsigned int flags);
# 318 : :
# 319 : : bool CheckMinimalPush(const std::vector<unsigned char>& data, opcodetype opcode);
# 320 : :
# 321 : : int FindAndDelete(CScript& script, const CScript& b);
# 322 : :
# 323 : : #endif // BITCOIN_SCRIPT_INTERPRETER_H
|