fuzz coverage

Coverage Report

Created: 2025-09-17 22:41

/Users/eugenesiegel/btc/bitcoin/src/script/script.cpp
Line
Count
Source (jump to first uncovered line)
1
// Copyright (c) 2009-2010 Satoshi Nakamoto
2
// Copyright (c) 2009-present The Bitcoin Core developers
3
// Distributed under the MIT software license, see the accompanying
4
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
5
6
#include <script/script.h>
7
8
#include <crypto/common.h>
9
#include <crypto/hex_base.h>
10
#include <hash.h>
11
#include <uint256.h>
12
#include <util/hash_type.h>
13
14
#include <string>
15
16
0
CScriptID::CScriptID(const CScript& in) : BaseHash(Hash160(in)) {}
17
18
std::string GetOpName(opcodetype opcode)
19
0
{
20
0
    switch (opcode)
21
0
    {
22
    // push value
23
0
    case OP_0                      : return "0";
24
0
    case OP_PUSHDATA1              : return "OP_PUSHDATA1";
25
0
    case OP_PUSHDATA2              : return "OP_PUSHDATA2";
26
0
    case OP_PUSHDATA4              : return "OP_PUSHDATA4";
27
0
    case OP_1NEGATE                : return "-1";
28
0
    case OP_RESERVED               : return "OP_RESERVED";
29
0
    case OP_1                      : return "1";
30
0
    case OP_2                      : return "2";
31
0
    case OP_3                      : return "3";
32
0
    case OP_4                      : return "4";
33
0
    case OP_5                      : return "5";
34
0
    case OP_6                      : return "6";
35
0
    case OP_7                      : return "7";
36
0
    case OP_8                      : return "8";
37
0
    case OP_9                      : return "9";
38
0
    case OP_10                     : return "10";
39
0
    case OP_11                     : return "11";
40
0
    case OP_12                     : return "12";
41
0
    case OP_13                     : return "13";
42
0
    case OP_14                     : return "14";
43
0
    case OP_15                     : return "15";
44
0
    case OP_16                     : return "16";
45
46
    // control
47
0
    case OP_NOP                    : return "OP_NOP";
48
0
    case OP_VER                    : return "OP_VER";
49
0
    case OP_IF                     : return "OP_IF";
50
0
    case OP_NOTIF                  : return "OP_NOTIF";
51
0
    case OP_VERIF                  : return "OP_VERIF";
52
0
    case OP_VERNOTIF               : return "OP_VERNOTIF";
53
0
    case OP_ELSE                   : return "OP_ELSE";
54
0
    case OP_ENDIF                  : return "OP_ENDIF";
55
0
    case OP_VERIFY                 : return "OP_VERIFY";
56
0
    case OP_RETURN                 : return "OP_RETURN";
57
58
    // stack ops
59
0
    case OP_TOALTSTACK             : return "OP_TOALTSTACK";
60
0
    case OP_FROMALTSTACK           : return "OP_FROMALTSTACK";
61
0
    case OP_2DROP                  : return "OP_2DROP";
62
0
    case OP_2DUP                   : return "OP_2DUP";
63
0
    case OP_3DUP                   : return "OP_3DUP";
64
0
    case OP_2OVER                  : return "OP_2OVER";
65
0
    case OP_2ROT                   : return "OP_2ROT";
66
0
    case OP_2SWAP                  : return "OP_2SWAP";
67
0
    case OP_IFDUP                  : return "OP_IFDUP";
68
0
    case OP_DEPTH                  : return "OP_DEPTH";
69
0
    case OP_DROP                   : return "OP_DROP";
70
0
    case OP_DUP                    : return "OP_DUP";
71
0
    case OP_NIP                    : return "OP_NIP";
72
0
    case OP_OVER                   : return "OP_OVER";
73
0
    case OP_PICK                   : return "OP_PICK";
74
0
    case OP_ROLL                   : return "OP_ROLL";
75
0
    case OP_ROT                    : return "OP_ROT";
76
0
    case OP_SWAP                   : return "OP_SWAP";
77
0
    case OP_TUCK                   : return "OP_TUCK";
78
79
    // splice ops
80
0
    case OP_CAT                    : return "OP_CAT";
81
0
    case OP_SUBSTR                 : return "OP_SUBSTR";
82
0
    case OP_LEFT                   : return "OP_LEFT";
83
0
    case OP_RIGHT                  : return "OP_RIGHT";
84
0
    case OP_SIZE                   : return "OP_SIZE";
85
86
    // bit logic
87
0
    case OP_INVERT                 : return "OP_INVERT";
88
0
    case OP_AND                    : return "OP_AND";
89
0
    case OP_OR                     : return "OP_OR";
90
0
    case OP_XOR                    : return "OP_XOR";
91
0
    case OP_EQUAL                  : return "OP_EQUAL";
92
0
    case OP_EQUALVERIFY            : return "OP_EQUALVERIFY";
93
0
    case OP_RESERVED1              : return "OP_RESERVED1";
94
0
    case OP_RESERVED2              : return "OP_RESERVED2";
95
96
    // numeric
97
0
    case OP_1ADD                   : return "OP_1ADD";
98
0
    case OP_1SUB                   : return "OP_1SUB";
99
0
    case OP_2MUL                   : return "OP_2MUL";
100
0
    case OP_2DIV                   : return "OP_2DIV";
101
0
    case OP_NEGATE                 : return "OP_NEGATE";
102
0
    case OP_ABS                    : return "OP_ABS";
103
0
    case OP_NOT                    : return "OP_NOT";
104
0
    case OP_0NOTEQUAL              : return "OP_0NOTEQUAL";
105
0
    case OP_ADD                    : return "OP_ADD";
106
0
    case OP_SUB                    : return "OP_SUB";
107
0
    case OP_MUL                    : return "OP_MUL";
108
0
    case OP_DIV                    : return "OP_DIV";
109
0
    case OP_MOD                    : return "OP_MOD";
110
0
    case OP_LSHIFT                 : return "OP_LSHIFT";
111
0
    case OP_RSHIFT                 : return "OP_RSHIFT";
112
0
    case OP_BOOLAND                : return "OP_BOOLAND";
113
0
    case OP_BOOLOR                 : return "OP_BOOLOR";
114
0
    case OP_NUMEQUAL               : return "OP_NUMEQUAL";
115
0
    case OP_NUMEQUALVERIFY         : return "OP_NUMEQUALVERIFY";
116
0
    case OP_NUMNOTEQUAL            : return "OP_NUMNOTEQUAL";
117
0
    case OP_LESSTHAN               : return "OP_LESSTHAN";
118
0
    case OP_GREATERTHAN            : return "OP_GREATERTHAN";
119
0
    case OP_LESSTHANOREQUAL        : return "OP_LESSTHANOREQUAL";
120
0
    case OP_GREATERTHANOREQUAL     : return "OP_GREATERTHANOREQUAL";
121
0
    case OP_MIN                    : return "OP_MIN";
122
0
    case OP_MAX                    : return "OP_MAX";
123
0
    case OP_WITHIN                 : return "OP_WITHIN";
124
125
    // crypto
126
0
    case OP_RIPEMD160              : return "OP_RIPEMD160";
127
0
    case OP_SHA1                   : return "OP_SHA1";
128
0
    case OP_SHA256                 : return "OP_SHA256";
129
0
    case OP_HASH160                : return "OP_HASH160";
130
0
    case OP_HASH256                : return "OP_HASH256";
131
0
    case OP_CODESEPARATOR          : return "OP_CODESEPARATOR";
132
0
    case OP_CHECKSIG               : return "OP_CHECKSIG";
133
0
    case OP_CHECKSIGVERIFY         : return "OP_CHECKSIGVERIFY";
134
0
    case OP_CHECKMULTISIG          : return "OP_CHECKMULTISIG";
135
0
    case OP_CHECKMULTISIGVERIFY    : return "OP_CHECKMULTISIGVERIFY";
136
137
    // expansion
138
0
    case OP_NOP1                   : return "OP_NOP1";
139
0
    case OP_CHECKLOCKTIMEVERIFY    : return "OP_CHECKLOCKTIMEVERIFY";
140
0
    case OP_CHECKSEQUENCEVERIFY    : return "OP_CHECKSEQUENCEVERIFY";
141
0
    case OP_NOP4                   : return "OP_NOP4";
142
0
    case OP_NOP5                   : return "OP_NOP5";
143
0
    case OP_NOP6                   : return "OP_NOP6";
144
0
    case OP_NOP7                   : return "OP_NOP7";
145
0
    case OP_NOP8                   : return "OP_NOP8";
146
0
    case OP_NOP9                   : return "OP_NOP9";
147
0
    case OP_NOP10                  : return "OP_NOP10";
148
149
    // Opcode added by BIP 342 (Tapscript)
150
0
    case OP_CHECKSIGADD            : return "OP_CHECKSIGADD";
151
152
0
    case OP_INVALIDOPCODE          : return "OP_INVALIDOPCODE";
153
154
0
    default:
155
0
        return "OP_UNKNOWN";
156
0
    }
157
0
}
158
159
unsigned int CScript::GetSigOpCount(bool fAccurate) const
160
4.66M
{
161
4.66M
    unsigned int n = 0;
162
4.66M
    const_iterator pc = begin();
163
4.66M
    opcodetype lastOpcode = OP_INVALIDOPCODE;
164
10.8M
    while (pc < end())
165
6.17M
    {
166
6.17M
        opcodetype opcode;
167
6.17M
        if (!GetOp(pc, opcode))
168
0
            break;
169
6.17M
        if (opcode == OP_CHECKSIG || opcode == OP_CHECKSIGVERIFY)
170
0
            n++;
171
6.17M
        else if (opcode == OP_CHECKMULTISIG || opcode == OP_CHECKMULTISIGVERIFY)
172
0
        {
173
0
            if (fAccurate && lastOpcode >= OP_1 && lastOpcode <= OP_16)
174
0
                n += DecodeOP_N(lastOpcode);
175
0
            else
176
0
                n += MAX_PUBKEYS_PER_MULTISIG;
177
0
        }
178
6.17M
        lastOpcode = opcode;
179
6.17M
    }
180
4.66M
    return n;
181
4.66M
}
182
183
unsigned int CScript::GetSigOpCount(const CScript& scriptSig) const
184
389k
{
185
389k
    if (!IsPayToScriptHash())
186
389k
        return GetSigOpCount(true);
187
188
    // This is a pay-to-script-hash scriptPubKey;
189
    // get the last item that the scriptSig
190
    // pushes onto the stack:
191
0
    const_iterator pc = scriptSig.begin();
192
0
    std::vector<unsigned char> vData;
193
0
    while (pc < scriptSig.end())
194
0
    {
195
0
        opcodetype opcode;
196
0
        if (!scriptSig.GetOp(pc, opcode, vData))
197
0
            return 0;
198
0
        if (opcode > OP_16)
199
0
            return 0;
200
0
    }
201
202
    /// ... and return its opcount:
203
0
    CScript subscript(vData.begin(), vData.end());
204
0
    return subscript.GetSigOpCount(true);
205
0
}
206
207
bool CScript::IsPayToAnchor() const
208
389k
{
209
389k
    return (this->size() == 4 &&
210
389k
        
(*this)[0] == OP_10
&&
211
389k
        
(*this)[1] == 0x020
&&
212
389k
        
(*this)[2] == 0x4e0
&&
213
389k
        
(*this)[3] == 0x730
);
214
389k
}
215
216
bool CScript::IsPayToAnchor(int version, const std::vector<unsigned char>& program)
217
0
{
218
0
    return version == 1 &&
219
0
        program.size() == 2 &&
220
0
        program[0] == 0x4e &&
221
0
        program[1] == 0x73;
222
0
}
223
224
bool CScript::IsPayToScriptHash() const
225
2.63M
{
226
    // Extra-fast test for pay-to-script-hash CScripts:
227
2.63M
    return (this->size() == 23 &&
228
2.63M
            
(*this)[0] == OP_HASH1600
&&
229
2.63M
            
(*this)[1] == 0x140
&&
230
2.63M
            
(*this)[22] == OP_EQUAL0
);
231
2.63M
}
232
233
bool CScript::IsPayToWitnessScriptHash() const
234
0
{
235
    // Extra-fast test for pay-to-witness-script-hash CScripts:
236
0
    return (this->size() == 34 &&
237
0
            (*this)[0] == OP_0 &&
238
0
            (*this)[1] == 0x20);
239
0
}
240
241
bool CScript::IsPayToTaproot() const
242
0
{
243
0
    return (this->size() == 34 &&
244
0
            (*this)[0] == OP_1 &&
245
0
            (*this)[1] == 0x20);
246
0
}
247
248
// A witness program is any valid CScript that consists of a 1-byte push opcode
249
// followed by a data push between 2 and 40 bytes.
250
bool CScript::IsWitnessProgram(int& version, std::vector<unsigned char>& program) const
251
3.43M
{
252
3.43M
    if (this->size() < 4 || this->size() > 42) {
253
0
        return false;
254
0
    }
255
3.43M
    if ((*this)[0] != OP_0 && 
(0
(*this)[0] < OP_10
||
(*this)[0] > OP_160
)) {
256
0
        return false;
257
0
    }
258
3.43M
    if ((size_t)((*this)[1] + 2) == this->size()) {
259
3.43M
        version = DecodeOP_N((opcodetype)(*this)[0]);
260
3.43M
        program = std::vector<unsigned char>(this->begin() + 2, this->end());
261
3.43M
        return true;
262
3.43M
    }
263
0
    return false;
264
3.43M
}
265
266
bool CScript::IsPushOnly(const_iterator pc) const
267
459k
{
268
459k
    while (pc < end())
269
0
    {
270
0
        opcodetype opcode;
271
0
        if (!GetOp(pc, opcode))
272
0
            return false;
273
        // Note that IsPushOnly() *does* consider OP_RESERVED to be a
274
        // push-type opcode, however execution of OP_RESERVED fails, so
275
        // it's not relevant to P2SH/BIP62 as the scriptSig would fail prior to
276
        // the P2SH special validation code being executed.
277
0
        if (opcode > OP_16)
278
0
            return false;
279
0
    }
280
459k
    return true;
281
459k
}
282
283
bool CScript::IsPushOnly() const
284
459k
{
285
459k
    return this->IsPushOnly(begin());
286
459k
}
287
288
std::string CScriptWitness::ToString() const
289
0
{
290
0
    std::string ret = "CScriptWitness(";
291
0
    for (unsigned int i = 0; i < stack.size(); i++) {
292
0
        if (i) {
293
0
            ret += ", ";
294
0
        }
295
0
        ret += HexStr(stack[i]);
296
0
    }
297
0
    return ret + ")";
298
0
}
299
300
bool CScript::HasValidOps() const
301
0
{
302
0
    CScript::const_iterator it = begin();
303
0
    while (it < end()) {
304
0
        opcodetype opcode;
305
0
        std::vector<unsigned char> item;
306
0
        if (!GetOp(it, opcode, item) || opcode > MAX_OPCODE || item.size() > MAX_SCRIPT_ELEMENT_SIZE) {
307
0
            return false;
308
0
        }
309
0
    }
310
0
    return true;
311
0
}
312
313
bool GetScriptOp(CScriptBase::const_iterator& pc, CScriptBase::const_iterator end, opcodetype& opcodeRet, std::vector<unsigned char>* pvchRet)
314
7.96M
{
315
7.96M
    opcodeRet = OP_INVALIDOPCODE;
316
7.96M
    if (pvchRet)
317
1.79M
        pvchRet->clear();
318
7.96M
    if (pc >= end)
319
0
        return false;
320
321
    // Read instruction
322
7.96M
    if (end - pc < 1)
323
0
        return false;
324
7.96M
    unsigned int opcode = *pc++;
325
326
    // Immediate operand
327
7.96M
    if (opcode <= OP_PUSHDATA4)
328
5.91M
    {
329
5.91M
        unsigned int nSize = 0;
330
5.91M
        if (opcode < OP_PUSHDATA1)
331
5.91M
        {
332
5.91M
            nSize = opcode;
333
5.91M
        }
334
0
        else if (opcode == OP_PUSHDATA1)
335
0
        {
336
0
            if (end - pc < 1)
337
0
                return false;
338
0
            nSize = *pc++;
339
0
        }
340
0
        else if (opcode == OP_PUSHDATA2)
341
0
        {
342
0
            if (end - pc < 2)
343
0
                return false;
344
0
            nSize = ReadLE16(&pc[0]);
345
0
            pc += 2;
346
0
        }
347
0
        else if (opcode == OP_PUSHDATA4)
348
0
        {
349
0
            if (end - pc < 4)
350
0
                return false;
351
0
            nSize = ReadLE32(&pc[0]);
352
0
            pc += 4;
353
0
        }
354
5.91M
        if (end - pc < 0 || (unsigned int)(end - pc) < nSize)
355
0
            return false;
356
5.91M
        if (pvchRet)
357
1.19M
            pvchRet->assign(pc, pc + nSize);
358
5.91M
        pc += nSize;
359
5.91M
    }
360
361
7.96M
    opcodeRet = static_cast<opcodetype>(opcode);
362
7.96M
    return true;
363
7.96M
}
364
365
bool IsOpSuccess(const opcodetype& opcode)
366
0
{
367
0
    return opcode == 80 || opcode == 98 || (opcode >= 126 && opcode <= 129) ||
368
0
           (opcode >= 131 && opcode <= 134) || (opcode >= 137 && opcode <= 138) ||
369
0
           (opcode >= 141 && opcode <= 142) || (opcode >= 149 && opcode <= 153) ||
370
0
           (opcode >= 187 && opcode <= 254);
371
0
}
372
373
602k
bool CheckMinimalPush(const std::vector<unsigned char>& data, opcodetype opcode) {
374
    // Excludes OP_1NEGATE, OP_1-16 since they are by definition minimal
375
602k
    assert(0 <= opcode && opcode <= OP_PUSHDATA4);
376
602k
    if (data.size() == 0) {
377
        // Should have used OP_0.
378
301k
        return opcode == OP_0;
379
301k
    } else if (data.size() == 1 && 
data[0] >= 10
&&
data[0] <= 160
) {
380
        // Should have used OP_1 .. OP_16.
381
0
        return false;
382
301k
    } else if (data.size() == 1 && 
data[0] == 0x810
) {
383
        // Should have used OP_1NEGATE.
384
0
        return false;
385
301k
    } else if (data.size() <= 75) {
386
        // Must have used a direct push (opcode indicating number of bytes pushed + those bytes).
387
301k
        return opcode == data.size();
388
301k
    } else 
if (0
data.size() <= 2550
) {
389
        // Must have used OP_PUSHDATA.
390
0
        return opcode == OP_PUSHDATA1;
391
0
    } else if (data.size() <= 65535) {
392
        // Must have used OP_PUSHDATA2.
393
0
        return opcode == OP_PUSHDATA2;
394
0
    }
395
0
    return true;
396
602k
}