lbcd/wire
Dave Collins 79aac01b02 wire: Reject non-canonically encoded varints.
The Bitcoin wire protocol includes several fields with their lengths
encoded according to a variable length integer encoding scheme that does
not enforce a unique encoding for all numbers.

This can lead to a situation where deserializing and re-serializing the
same data can result in different bytes.  There are no currently known
issues due to this, but it is safer to reject such subtle differences as
they could potentially lead to exploits.

Consequently, this commit modifies the varint decoding function to error
when the value is not canonically encoded which effectively means that
all messages with varints that are not canonically encoded will now be
rejected.  This will not cause issues with old client versions in
regards to blocks and transactions since the data is deserialized into
memory and then reserialized before being relayed thereby effectively
erasing any non-canonical encodings.

Also, new tests have been added to ensure non-canonical encodings are
properly rejected and exercise the new code, and the default user agent
version for wire has been bumped to version 0.2.1 to differentiate the
new behavior.

The equivalent logic was implemented in Bitcoin Core by PR 2884.
2015-09-26 16:22:31 -05:00
..
bench_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
blockheader.go Implmement BlockHeader BtcEncode/BtcDecode. 2015-07-22 11:34:18 -04:00
blockheader_test.go Implmement BlockHeader BtcEncode/BtcDecode. 2015-07-22 11:34:18 -04:00
common.go wire: Reject non-canonically encoded varints. 2015-09-26 16:22:31 -05:00
common_test.go wire: Reject non-canonically encoded varints. 2015-09-26 16:22:31 -05:00
doc.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
error.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
fakeconn_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
fakemessage_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
fixedIO_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
internal_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
invvect.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
invvect_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
message.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
message_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgaddr.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgaddr_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgalert.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgalert_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgblock.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgblock_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgfilteradd.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgfilteradd_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgfilterclear.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgfilterclear_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgfilterload.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgfilterload_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msggetaddr.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msggetaddr_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msggetblocks.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msggetblocks_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msggetdata.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msggetdata_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msggetheaders.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msggetheaders_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgheaders.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgheaders_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msginv.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msginv_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgmempool.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgmempool_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgmerkleblock.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgmerkleblock_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgnotfound.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgnotfound_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgping.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgping_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgpong.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgpong_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgreject.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgreject_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgtx.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgtx_test.go wire: Remove duplicate tx error path tests. 2015-07-26 13:05:09 -05:00
msgverack.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgverack_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
msgversion.go wire: Reject non-canonically encoded varints. 2015-09-26 16:22:31 -05:00
msgversion_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
netaddress.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
netaddress_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
protocol.go Recognize the BIP0064 service bit. 2015-08-22 09:11:05 -04:00
protocol_test.go Recognize the BIP0064 service bit. 2015-08-22 09:11:05 -04:00
README.md Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
shahash.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00
shahash_test.go Relicense to the btcsuite developers. 2015-05-01 12:00:56 -05:00

wire

[Build Status] (https://travis-ci.org/btcsuite/btcd) ![ISC License] (http://img.shields.io/badge/license-ISC-blue.svg)

Package wire implements the bitcoin wire protocol. A comprehensive suite of tests with 100% test coverage is provided to ensure proper functionality.

There is an associated blog post about the release of this package here.

This package has intentionally been designed so it can be used as a standalone package for any projects needing to interface with bitcoin peers at the wire protocol level.

Documentation

[GoDoc] (http://godoc.org/github.com/btcsuite/btcd/wire)

Full go doc style documentation for the project can be viewed online without installing this package by using the GoDoc site here: http://godoc.org/github.com/btcsuite/btcd/wire

You can also view the documentation locally once the package is installed with the godoc tool by running godoc -http=":6060" and pointing your browser to http://localhost:6060/pkg/github.com/btcsuite/btcd/wire

Installation

$ go get github.com/btcsuite/btcd/wire

Bitcoin Message Overview

The bitcoin protocol consists of exchanging messages between peers. Each message is preceded by a header which identifies information about it such as which bitcoin network it is a part of, its type, how big it is, and a checksum to verify validity. All encoding and decoding of message headers is handled by this package.

To accomplish this, there is a generic interface for bitcoin messages named Message which allows messages of any type to be read, written, or passed around through channels, functions, etc. In addition, concrete implementations of most of the currently supported bitcoin messages are provided. For these supported messages, all of the details of marshalling and unmarshalling to and from the wire using bitcoin encoding are handled so the caller doesn't have to concern themselves with the specifics.

Reading Messages Example

In order to unmarshal bitcoin messages from the wire, use the ReadMessage function. It accepts any io.Reader, but typically this will be a net.Conn to a remote node running a bitcoin peer. Example syntax is:

	// Use the most recent protocol version supported by the package and the
	// main bitcoin network.
	pver := wire.ProtocolVersion
	btcnet := wire.MainNet

	// Reads and validates the next bitcoin message from conn using the
	// protocol version pver and the bitcoin network btcnet.  The returns
	// are a wire.Message, a []byte which contains the unmarshalled
	// raw payload, and a possible error.
	msg, rawPayload, err := wire.ReadMessage(conn, pver, btcnet)
	if err != nil {
		// Log and handle the error
	}

See the package documentation for details on determining the message type.

Writing Messages Example

In order to marshal bitcoin messages to the wire, use the WriteMessage function. It accepts any io.Writer, but typically this will be a net.Conn to a remote node running a bitcoin peer. Example syntax to request addresses from a remote peer is:

	// Use the most recent protocol version supported by the package and the
	// main bitcoin network.
	pver := wire.ProtocolVersion
	btcnet := wire.MainNet

	// Create a new getaddr bitcoin message.
	msg := wire.NewMsgGetAddr()

	// Writes a bitcoin message msg to conn using the protocol version
	// pver, and the bitcoin network btcnet.  The return is a possible
	// error.
	err := wire.WriteMessage(conn, msg, pver, btcnet)
	if err != nil {
		// Log and handle the error
	}

GPG Verification Key

All official release tags are signed by Conformal so users can ensure the code has not been tampered with and is coming from the btcsuite developers. To verify the signature perform the following:

  • Download the public key from the Conformal website at https://opensource.conformal.com/GIT-GPG-KEY-conformal.txt

  • Import the public key into your GPG keyring:

    gpg --import GIT-GPG-KEY-conformal.txt
    
  • Verify the release tag with the following command where TAG_NAME is a placeholder for the specific tag:

    git tag -v TAG_NAME
    

License

Package wire is licensed under the copyfree ISC License.