2014-08-27 17:22:33 +02:00
|
|
|
// Copyright (c) 2009-2010 Satoshi Nakamoto
|
2014-12-17 02:47:57 +01:00
|
|
|
// Copyright (c) 2009-2014 The Bitcoin Core developers
|
2014-09-09 10:00:42 +02:00
|
|
|
// Distributed under the MIT software license, see the accompanying
|
2014-08-27 17:22:33 +02:00
|
|
|
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
|
|
|
|
|
|
|
|
#include "script/sign.h"
|
|
|
|
|
2014-11-18 21:03:02 +00:00
|
|
|
#include "primitives/transaction.h"
|
2014-08-27 17:22:33 +02:00
|
|
|
#include "key.h"
|
|
|
|
#include "keystore.h"
|
|
|
|
#include "script/standard.h"
|
|
|
|
#include "uint256.h"
|
|
|
|
|
|
|
|
#include <boost/foreach.hpp>
|
|
|
|
|
|
|
|
using namespace std;
|
|
|
|
|
|
|
|
typedef vector<unsigned char> valtype;
|
|
|
|
|
2014-11-04 10:06:20 -08:00
|
|
|
TransactionSignatureCreator::TransactionSignatureCreator(const CKeyStore* keystoreIn, const CTransaction* txToIn, unsigned int nInIn, int nHashTypeIn) : BaseSignatureCreator(keystoreIn), txTo(txToIn), nIn(nInIn), nHashType(nHashTypeIn), checker(txTo, nIn) {}
|
|
|
|
|
|
|
|
bool TransactionSignatureCreator::CreateSig(std::vector<unsigned char>& vchSig, const CKeyID& address, const CScript& scriptCode) const
|
2014-08-27 17:22:33 +02:00
|
|
|
{
|
|
|
|
CKey key;
|
2014-11-04 10:06:20 -08:00
|
|
|
if (!keystore->GetKey(address, key))
|
2014-08-27 17:22:33 +02:00
|
|
|
return false;
|
|
|
|
|
2014-11-04 10:06:20 -08:00
|
|
|
uint256 hash = SignatureHash(scriptCode, *txTo, nIn, nHashType);
|
2014-08-27 17:22:33 +02:00
|
|
|
if (!key.Sign(hash, vchSig))
|
|
|
|
return false;
|
|
|
|
vchSig.push_back((unsigned char)nHashType);
|
2014-11-04 10:06:20 -08:00
|
|
|
return true;
|
|
|
|
}
|
2014-08-27 17:22:33 +02:00
|
|
|
|
2014-11-04 10:06:20 -08:00
|
|
|
static bool Sign1(const CKeyID& address, const BaseSignatureCreator& creator, const CScript& scriptCode, CScript& scriptSigRet)
|
|
|
|
{
|
|
|
|
vector<unsigned char> vchSig;
|
|
|
|
if (!creator.CreateSig(vchSig, address, scriptCode))
|
|
|
|
return false;
|
|
|
|
scriptSigRet << vchSig;
|
2014-08-27 17:22:33 +02:00
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2014-11-04 10:06:20 -08:00
|
|
|
static bool SignN(const vector<valtype>& multisigdata, const BaseSignatureCreator& creator, const CScript& scriptCode, CScript& scriptSigRet)
|
2014-08-27 17:22:33 +02:00
|
|
|
{
|
|
|
|
int nSigned = 0;
|
|
|
|
int nRequired = multisigdata.front()[0];
|
|
|
|
for (unsigned int i = 1; i < multisigdata.size()-1 && nSigned < nRequired; i++)
|
|
|
|
{
|
|
|
|
const valtype& pubkey = multisigdata[i];
|
|
|
|
CKeyID keyID = CPubKey(pubkey).GetID();
|
2014-11-04 10:06:20 -08:00
|
|
|
if (Sign1(keyID, creator, scriptCode, scriptSigRet))
|
2014-08-27 17:22:33 +02:00
|
|
|
++nSigned;
|
|
|
|
}
|
|
|
|
return nSigned==nRequired;
|
|
|
|
}
|
|
|
|
|
2014-11-10 14:40:01 +08:00
|
|
|
/**
|
2014-11-04 10:06:20 -08:00
|
|
|
* Sign scriptPubKey using signature made with creator.
|
2014-11-10 14:40:01 +08:00
|
|
|
* Signatures are returned in scriptSigRet (or returns false if scriptPubKey can't be signed),
|
|
|
|
* unless whichTypeRet is TX_SCRIPTHASH, in which case scriptSigRet is the redemption script.
|
|
|
|
* Returns false if scriptPubKey could not be completely satisfied.
|
|
|
|
*/
|
2014-11-04 10:06:20 -08:00
|
|
|
static bool SignStep(const BaseSignatureCreator& creator, const CScript& scriptPubKey,
|
|
|
|
CScript& scriptSigRet, txnouttype& whichTypeRet)
|
2014-08-27 17:22:33 +02:00
|
|
|
{
|
|
|
|
scriptSigRet.clear();
|
|
|
|
|
|
|
|
vector<valtype> vSolutions;
|
|
|
|
if (!Solver(scriptPubKey, whichTypeRet, vSolutions))
|
|
|
|
return false;
|
|
|
|
|
|
|
|
CKeyID keyID;
|
|
|
|
switch (whichTypeRet)
|
|
|
|
{
|
|
|
|
case TX_NONSTANDARD:
|
|
|
|
case TX_NULL_DATA:
|
|
|
|
return false;
|
|
|
|
case TX_PUBKEY:
|
|
|
|
keyID = CPubKey(vSolutions[0]).GetID();
|
2014-11-04 10:06:20 -08:00
|
|
|
return Sign1(keyID, creator, scriptPubKey, scriptSigRet);
|
2014-08-27 17:22:33 +02:00
|
|
|
case TX_PUBKEYHASH:
|
|
|
|
keyID = CKeyID(uint160(vSolutions[0]));
|
2014-11-04 10:06:20 -08:00
|
|
|
if (!Sign1(keyID, creator, scriptPubKey, scriptSigRet))
|
2014-08-27 17:22:33 +02:00
|
|
|
return false;
|
|
|
|
else
|
|
|
|
{
|
|
|
|
CPubKey vch;
|
2014-11-04 10:06:20 -08:00
|
|
|
creator.KeyStore().GetPubKey(keyID, vch);
|
2014-09-24 22:54:08 -04:00
|
|
|
scriptSigRet << ToByteVector(vch);
|
2014-08-27 17:22:33 +02:00
|
|
|
}
|
|
|
|
return true;
|
|
|
|
case TX_SCRIPTHASH:
|
2014-11-04 10:06:20 -08:00
|
|
|
return creator.KeyStore().GetCScript(uint160(vSolutions[0]), scriptSigRet);
|
2014-08-27 17:22:33 +02:00
|
|
|
|
|
|
|
case TX_MULTISIG:
|
|
|
|
scriptSigRet << OP_0; // workaround CHECKMULTISIG bug
|
2014-11-04 10:06:20 -08:00
|
|
|
return (SignN(vSolutions, creator, scriptPubKey, scriptSigRet));
|
2014-08-27 17:22:33 +02:00
|
|
|
}
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
2014-11-04 10:06:20 -08:00
|
|
|
bool ProduceSignature(const BaseSignatureCreator& creator, const CScript& fromPubKey, CScript& scriptSig)
|
2014-08-27 17:22:33 +02:00
|
|
|
{
|
|
|
|
txnouttype whichType;
|
2014-11-04 10:06:20 -08:00
|
|
|
if (!SignStep(creator, fromPubKey, scriptSig, whichType))
|
2014-08-27 17:22:33 +02:00
|
|
|
return false;
|
|
|
|
|
|
|
|
if (whichType == TX_SCRIPTHASH)
|
|
|
|
{
|
|
|
|
// Solver returns the subscript that need to be evaluated;
|
|
|
|
// the final scriptSig is the signatures from that
|
|
|
|
// and then the serialized subscript:
|
2014-11-04 10:06:20 -08:00
|
|
|
CScript subscript = scriptSig;
|
2014-08-27 17:22:33 +02:00
|
|
|
|
|
|
|
txnouttype subType;
|
|
|
|
bool fSolved =
|
2014-11-04 10:06:20 -08:00
|
|
|
SignStep(creator, subscript, scriptSig, subType) && subType != TX_SCRIPTHASH;
|
2014-08-27 17:22:33 +02:00
|
|
|
// Append serialized subscript whether or not it is completely signed:
|
2014-11-04 10:06:20 -08:00
|
|
|
scriptSig << static_cast<valtype>(subscript);
|
2014-08-27 17:22:33 +02:00
|
|
|
if (!fSolved) return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
// Test solution
|
2014-11-04 10:06:20 -08:00
|
|
|
return VerifyScript(scriptSig, fromPubKey, STANDARD_SCRIPT_VERIFY_FLAGS, creator.Checker());
|
|
|
|
}
|
|
|
|
|
|
|
|
bool SignSignature(const CKeyStore &keystore, const CScript& fromPubKey, CMutableTransaction& txTo, unsigned int nIn, int nHashType)
|
|
|
|
{
|
|
|
|
assert(nIn < txTo.vin.size());
|
|
|
|
CTxIn& txin = txTo.vin[nIn];
|
|
|
|
|
|
|
|
CTransaction txToConst(txTo);
|
|
|
|
TransactionSignatureCreator creator(&keystore, &txToConst, nIn, nHashType);
|
|
|
|
|
|
|
|
return ProduceSignature(creator, fromPubKey, txin.scriptSig);
|
2014-08-27 17:22:33 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
bool SignSignature(const CKeyStore &keystore, const CTransaction& txFrom, CMutableTransaction& txTo, unsigned int nIn, int nHashType)
|
|
|
|
{
|
|
|
|
assert(nIn < txTo.vin.size());
|
|
|
|
CTxIn& txin = txTo.vin[nIn];
|
|
|
|
assert(txin.prevout.n < txFrom.vout.size());
|
|
|
|
const CTxOut& txout = txFrom.vout[txin.prevout.n];
|
|
|
|
|
|
|
|
return SignSignature(keystore, txout.scriptPubKey, txTo, nIn, nHashType);
|
|
|
|
}
|
|
|
|
|
|
|
|
static CScript PushAll(const vector<valtype>& values)
|
|
|
|
{
|
|
|
|
CScript result;
|
|
|
|
BOOST_FOREACH(const valtype& v, values)
|
|
|
|
result << v;
|
|
|
|
return result;
|
|
|
|
}
|
|
|
|
|
2014-11-04 10:06:20 -08:00
|
|
|
static CScript CombineMultisig(const CScript& scriptPubKey, const BaseSignatureChecker& checker,
|
2014-08-27 17:22:33 +02:00
|
|
|
const vector<valtype>& vSolutions,
|
2014-11-04 13:59:41 -08:00
|
|
|
const vector<valtype>& sigs1, const vector<valtype>& sigs2)
|
2014-08-27 17:22:33 +02:00
|
|
|
{
|
|
|
|
// Combine all the signatures we've got:
|
|
|
|
set<valtype> allsigs;
|
|
|
|
BOOST_FOREACH(const valtype& v, sigs1)
|
|
|
|
{
|
|
|
|
if (!v.empty())
|
|
|
|
allsigs.insert(v);
|
|
|
|
}
|
|
|
|
BOOST_FOREACH(const valtype& v, sigs2)
|
|
|
|
{
|
|
|
|
if (!v.empty())
|
|
|
|
allsigs.insert(v);
|
|
|
|
}
|
|
|
|
|
|
|
|
// Build a map of pubkey -> signature by matching sigs to pubkeys:
|
|
|
|
assert(vSolutions.size() > 1);
|
|
|
|
unsigned int nSigsRequired = vSolutions.front()[0];
|
|
|
|
unsigned int nPubKeys = vSolutions.size()-2;
|
|
|
|
map<valtype, valtype> sigs;
|
|
|
|
BOOST_FOREACH(const valtype& sig, allsigs)
|
|
|
|
{
|
|
|
|
for (unsigned int i = 0; i < nPubKeys; i++)
|
|
|
|
{
|
|
|
|
const valtype& pubkey = vSolutions[i+1];
|
|
|
|
if (sigs.count(pubkey))
|
|
|
|
continue; // Already got a sig for this pubkey
|
|
|
|
|
2014-11-04 10:06:20 -08:00
|
|
|
if (checker.CheckSig(sig, pubkey, scriptPubKey))
|
2014-08-27 17:22:33 +02:00
|
|
|
{
|
|
|
|
sigs[pubkey] = sig;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
// Now build a merged CScript:
|
|
|
|
unsigned int nSigsHave = 0;
|
|
|
|
CScript result; result << OP_0; // pop-one-too-many workaround
|
|
|
|
for (unsigned int i = 0; i < nPubKeys && nSigsHave < nSigsRequired; i++)
|
|
|
|
{
|
|
|
|
if (sigs.count(vSolutions[i+1]))
|
|
|
|
{
|
|
|
|
result << sigs[vSolutions[i+1]];
|
|
|
|
++nSigsHave;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
// Fill any missing with OP_0:
|
|
|
|
for (unsigned int i = nSigsHave; i < nSigsRequired; i++)
|
|
|
|
result << OP_0;
|
|
|
|
|
|
|
|
return result;
|
|
|
|
}
|
|
|
|
|
2014-11-04 10:06:20 -08:00
|
|
|
static CScript CombineSignatures(const CScript& scriptPubKey, const BaseSignatureChecker& checker,
|
2014-08-27 17:22:33 +02:00
|
|
|
const txnouttype txType, const vector<valtype>& vSolutions,
|
|
|
|
vector<valtype>& sigs1, vector<valtype>& sigs2)
|
|
|
|
{
|
|
|
|
switch (txType)
|
|
|
|
{
|
|
|
|
case TX_NONSTANDARD:
|
|
|
|
case TX_NULL_DATA:
|
|
|
|
// Don't know anything about this, assume bigger one is correct:
|
|
|
|
if (sigs1.size() >= sigs2.size())
|
|
|
|
return PushAll(sigs1);
|
|
|
|
return PushAll(sigs2);
|
|
|
|
case TX_PUBKEY:
|
|
|
|
case TX_PUBKEYHASH:
|
|
|
|
// Signatures are bigger than placeholders or empty scripts:
|
|
|
|
if (sigs1.empty() || sigs1[0].empty())
|
|
|
|
return PushAll(sigs2);
|
|
|
|
return PushAll(sigs1);
|
|
|
|
case TX_SCRIPTHASH:
|
|
|
|
if (sigs1.empty() || sigs1.back().empty())
|
|
|
|
return PushAll(sigs2);
|
|
|
|
else if (sigs2.empty() || sigs2.back().empty())
|
|
|
|
return PushAll(sigs1);
|
|
|
|
else
|
|
|
|
{
|
|
|
|
// Recur to combine:
|
|
|
|
valtype spk = sigs1.back();
|
|
|
|
CScript pubKey2(spk.begin(), spk.end());
|
|
|
|
|
|
|
|
txnouttype txType2;
|
|
|
|
vector<vector<unsigned char> > vSolutions2;
|
|
|
|
Solver(pubKey2, txType2, vSolutions2);
|
|
|
|
sigs1.pop_back();
|
|
|
|
sigs2.pop_back();
|
2014-11-04 10:06:20 -08:00
|
|
|
CScript result = CombineSignatures(pubKey2, checker, txType2, vSolutions2, sigs1, sigs2);
|
2014-08-27 17:22:33 +02:00
|
|
|
result << spk;
|
|
|
|
return result;
|
|
|
|
}
|
|
|
|
case TX_MULTISIG:
|
2014-11-04 10:06:20 -08:00
|
|
|
return CombineMultisig(scriptPubKey, checker, vSolutions, sigs1, sigs2);
|
2014-08-27 17:22:33 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
return CScript();
|
|
|
|
}
|
|
|
|
|
2014-11-04 13:59:41 -08:00
|
|
|
CScript CombineSignatures(const CScript& scriptPubKey, const CTransaction& txTo, unsigned int nIn,
|
2014-08-27 17:22:33 +02:00
|
|
|
const CScript& scriptSig1, const CScript& scriptSig2)
|
2014-11-04 10:06:20 -08:00
|
|
|
{
|
|
|
|
TransactionSignatureChecker checker(&txTo, nIn);
|
|
|
|
return CombineSignatures(scriptPubKey, checker, scriptSig1, scriptSig2);
|
|
|
|
}
|
|
|
|
|
|
|
|
CScript CombineSignatures(const CScript& scriptPubKey, const BaseSignatureChecker& checker,
|
|
|
|
const CScript& scriptSig1, const CScript& scriptSig2)
|
2014-08-27 17:22:33 +02:00
|
|
|
{
|
|
|
|
txnouttype txType;
|
|
|
|
vector<vector<unsigned char> > vSolutions;
|
|
|
|
Solver(scriptPubKey, txType, vSolutions);
|
|
|
|
|
|
|
|
vector<valtype> stack1;
|
2014-09-10 16:16:09 +02:00
|
|
|
EvalScript(stack1, scriptSig1, SCRIPT_VERIFY_STRICTENC, BaseSignatureChecker());
|
2014-08-27 17:22:33 +02:00
|
|
|
vector<valtype> stack2;
|
2014-09-10 16:16:09 +02:00
|
|
|
EvalScript(stack2, scriptSig2, SCRIPT_VERIFY_STRICTENC, BaseSignatureChecker());
|
2014-08-27 17:22:33 +02:00
|
|
|
|
2014-11-04 10:06:20 -08:00
|
|
|
return CombineSignatures(scriptPubKey, checker, txType, vSolutions, stack1, stack2);
|
2014-08-27 17:22:33 +02:00
|
|
|
}
|