2014-08-27 20:11:41 +02:00
|
|
|
// Copyright (c) 2009-2010 Satoshi Nakamoto
|
2016-10-02 01:19:33 +08:00
|
|
|
// Copyright (c) 2009-2016 The Bitcoin Core developers
|
2014-09-09 10:00:42 +02:00
|
|
|
// Distributed under the MIT software license, see the accompanying
|
2014-08-27 20:11:41 +02:00
|
|
|
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
|
|
|
|
|
2014-11-03 16:16:40 +01:00
|
|
|
#ifndef BITCOIN_SCRIPT_INTERPRETER_H
|
|
|
|
#define BITCOIN_SCRIPT_INTERPRETER_H
|
2014-08-27 20:11:41 +02:00
|
|
|
|
2014-10-31 23:29:12 -04:00
|
|
|
#include "script_error.h"
|
2015-01-27 09:28:45 -04:00
|
|
|
#include "primitives/transaction.h"
|
2014-10-31 23:29:12 -04:00
|
|
|
|
2014-08-27 20:11:41 +02:00
|
|
|
#include <vector>
|
|
|
|
#include <stdint.h>
|
|
|
|
#include <string>
|
|
|
|
|
2014-09-10 16:16:09 +02:00
|
|
|
class CPubKey;
|
2014-08-27 20:11:41 +02:00
|
|
|
class CScript;
|
|
|
|
class CTransaction;
|
2014-10-06 13:00:55 +02:00
|
|
|
class uint256;
|
2014-08-27 20:11:41 +02:00
|
|
|
|
|
|
|
/** Signature hash types/flags */
|
|
|
|
enum
|
|
|
|
{
|
|
|
|
SIGHASH_ALL = 1,
|
|
|
|
SIGHASH_NONE = 2,
|
|
|
|
SIGHASH_SINGLE = 3,
|
|
|
|
SIGHASH_ANYONECANPAY = 0x80,
|
|
|
|
};
|
|
|
|
|
|
|
|
/** Script verification flags */
|
|
|
|
enum
|
|
|
|
{
|
|
|
|
SCRIPT_VERIFY_NONE = 0,
|
|
|
|
|
2014-10-07 02:22:47 +02:00
|
|
|
// Evaluate P2SH subscripts (softfork safe, BIP16).
|
|
|
|
SCRIPT_VERIFY_P2SH = (1U << 0),
|
|
|
|
|
|
|
|
// Passing a non-strict-DER signature or one with undefined hashtype to a checksig operation causes script failure.
|
2014-11-08 09:32:29 -08:00
|
|
|
// Evaluating a pubkey that is not (0x04 + 64 bytes) or (0x02 or 0x03 + 32 bytes) by checksig causes script failure.
|
|
|
|
// (softfork safe, but not used or intended as a consensus rule).
|
2014-10-07 02:22:47 +02:00
|
|
|
SCRIPT_VERIFY_STRICTENC = (1U << 1),
|
|
|
|
|
|
|
|
// Passing a non-strict-DER signature to a checksig operation causes script failure (softfork safe, BIP62 rule 1)
|
|
|
|
SCRIPT_VERIFY_DERSIG = (1U << 2),
|
|
|
|
|
|
|
|
// Passing a non-strict-DER signature or one with S > order/2 to a checksig operation causes script failure
|
|
|
|
// (softfork safe, BIP62 rule 5).
|
|
|
|
SCRIPT_VERIFY_LOW_S = (1U << 3),
|
|
|
|
|
|
|
|
// verify dummy stack item consumed by CHECKMULTISIG is of zero-length (softfork safe, BIP62 rule 7).
|
|
|
|
SCRIPT_VERIFY_NULLDUMMY = (1U << 4),
|
2014-10-08 16:29:45 -07:00
|
|
|
|
|
|
|
// Using a non-push operator in the scriptSig causes script failure (softfork safe, BIP62 rule 2).
|
|
|
|
SCRIPT_VERIFY_SIGPUSHONLY = (1U << 5),
|
2014-10-08 18:48:59 -07:00
|
|
|
|
|
|
|
// Require minimal encodings for all push operations (OP_0... OP_16, OP_1NEGATE where possible, direct
|
|
|
|
// pushes up to 75 bytes, OP_PUSHDATA up to 255 bytes, OP_PUSHDATA2 for anything larger). Evaluating
|
|
|
|
// any other push causes the script to fail (BIP62 rule 3).
|
|
|
|
// In addition, whenever a stack element is interpreted as a number, it must be of minimal length (BIP62 rule 4).
|
|
|
|
// (softfork safe)
|
2014-09-28 21:17:36 -04:00
|
|
|
SCRIPT_VERIFY_MINIMALDATA = (1U << 6),
|
|
|
|
|
|
|
|
// Discourage use of NOPs reserved for upgrades (NOP1-10)
|
|
|
|
//
|
|
|
|
// Provided so that nodes can avoid accepting or mining transactions
|
|
|
|
// containing executed NOP's whose meaning may change after a soft-fork,
|
|
|
|
// thus rendering the script invalid; with this flag set executing
|
|
|
|
// discouraged NOPs fails the script. This verification flag will never be
|
|
|
|
// a mandatory flag applied to scripts in a block. NOPs that are not
|
|
|
|
// executed, e.g. within an unexecuted IF ENDIF block, are *not* rejected.
|
2014-10-12 18:39:47 -07:00
|
|
|
SCRIPT_VERIFY_DISCOURAGE_UPGRADABLE_NOPS = (1U << 7),
|
|
|
|
|
|
|
|
// Require that only a single stack element remains after evaluation. This changes the success criterion from
|
|
|
|
// "At least one stack element must remain, and when interpreted as a boolean, it must be true" to
|
|
|
|
// "Exactly one stack element must remain, and when interpreted as a boolean, it must be true".
|
|
|
|
// (softfork safe, BIP62 rule 6)
|
2015-11-08 01:16:45 +01:00
|
|
|
// Note: CLEANSTACK should never be used without P2SH or WITNESS.
|
2014-10-12 18:39:47 -07:00
|
|
|
SCRIPT_VERIFY_CLEANSTACK = (1U << 8),
|
2014-09-29 03:44:25 -04:00
|
|
|
|
|
|
|
// Verify CHECKLOCKTIMEVERIFY
|
|
|
|
//
|
|
|
|
// See BIP65 for details.
|
|
|
|
SCRIPT_VERIFY_CHECKLOCKTIMEVERIFY = (1U << 9),
|
2015-09-25 16:18:51 -07:00
|
|
|
|
|
|
|
// support CHECKSEQUENCEVERIFY opcode
|
|
|
|
//
|
|
|
|
// See BIP112 for details
|
|
|
|
SCRIPT_VERIFY_CHECKSEQUENCEVERIFY = (1U << 10),
|
2015-11-08 01:16:45 +01:00
|
|
|
|
|
|
|
// Support segregated witness
|
|
|
|
//
|
|
|
|
SCRIPT_VERIFY_WITNESS = (1U << 11),
|
|
|
|
|
|
|
|
// Making v1-v16 witness program non-standard
|
|
|
|
//
|
|
|
|
SCRIPT_VERIFY_DISCOURAGE_UPGRADABLE_WITNESS_PROGRAM = (1U << 12),
|
2016-09-23 13:06:45 +08:00
|
|
|
|
|
|
|
// Segwit script only: Require the argument of OP_IF/NOTIF to be exactly 0x01 or empty vector
|
|
|
|
//
|
|
|
|
SCRIPT_VERIFY_MINIMALIF = (1U << 13),
|
2016-09-22 15:06:54 +08:00
|
|
|
|
|
|
|
// Signature(s) must be empty vector if an CHECK(MULTI)SIG operation failed
|
|
|
|
//
|
|
|
|
SCRIPT_VERIFY_NULLFAIL = (1U << 14),
|
2016-10-02 01:19:33 +08:00
|
|
|
|
|
|
|
// Public keys in segregated witness scripts must be compressed
|
|
|
|
//
|
|
|
|
SCRIPT_VERIFY_WITNESS_PUBKEYTYPE = (1U << 15),
|
2014-10-07 02:22:47 +02:00
|
|
|
};
|
2014-08-27 20:11:41 +02:00
|
|
|
|
2015-07-30 19:56:00 -04:00
|
|
|
bool CheckSignatureEncoding(const std::vector<unsigned char> &vchSig, unsigned int flags, ScriptError* serror);
|
|
|
|
|
2016-08-26 18:38:20 +02:00
|
|
|
struct PrecomputedTransactionData
|
2016-08-16 15:35:45 +02:00
|
|
|
{
|
|
|
|
uint256 hashPrevouts, hashSequence, hashOutputs;
|
|
|
|
|
2017-08-01 12:22:41 +02:00
|
|
|
explicit PrecomputedTransactionData(const CTransaction& tx);
|
2016-08-16 15:35:45 +02:00
|
|
|
};
|
|
|
|
|
2015-12-27 19:49:08 +01:00
|
|
|
enum SigVersion
|
|
|
|
{
|
|
|
|
SIGVERSION_BASE = 0,
|
|
|
|
SIGVERSION_WITNESS_V0 = 1,
|
|
|
|
};
|
|
|
|
|
2017-08-07 07:36:37 +02:00
|
|
|
uint256 SignatureHash(const CScript &scriptCode, const CTransaction& txTo, unsigned int nIn, int nHashType, const CAmount& amount, SigVersion sigversion, const PrecomputedTransactionData* cache = nullptr);
|
2014-09-10 14:42:22 +02:00
|
|
|
|
2014-09-10 16:16:09 +02:00
|
|
|
class BaseSignatureChecker
|
|
|
|
{
|
|
|
|
public:
|
2015-12-27 19:49:08 +01:00
|
|
|
virtual bool CheckSig(const std::vector<unsigned char>& scriptSig, const std::vector<unsigned char>& vchPubKey, const CScript& scriptCode, SigVersion sigversion) const
|
2014-09-10 16:16:09 +02:00
|
|
|
{
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
2014-09-29 03:44:25 -04:00
|
|
|
virtual bool CheckLockTime(const CScriptNum& nLockTime) const
|
|
|
|
{
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
2015-09-25 16:18:51 -07:00
|
|
|
virtual bool CheckSequence(const CScriptNum& nSequence) const
|
|
|
|
{
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
2014-09-10 16:16:09 +02:00
|
|
|
virtual ~BaseSignatureChecker() {}
|
|
|
|
};
|
|
|
|
|
2015-01-27 09:28:45 -04:00
|
|
|
class TransactionSignatureChecker : public BaseSignatureChecker
|
2014-09-10 14:42:22 +02:00
|
|
|
{
|
|
|
|
private:
|
2015-01-27 10:01:31 -04:00
|
|
|
const CTransaction* txTo;
|
2014-09-10 14:42:22 +02:00
|
|
|
unsigned int nIn;
|
2015-12-27 19:49:08 +01:00
|
|
|
const CAmount amount;
|
2016-08-26 18:38:20 +02:00
|
|
|
const PrecomputedTransactionData* txdata;
|
2014-09-10 14:42:22 +02:00
|
|
|
|
2014-09-10 16:16:09 +02:00
|
|
|
protected:
|
2014-09-14 04:48:32 +02:00
|
|
|
virtual bool VerifySignature(const std::vector<unsigned char>& vchSig, const CPubKey& vchPubKey, const uint256& sighash) const;
|
2014-09-10 16:16:09 +02:00
|
|
|
|
2014-09-10 14:42:22 +02:00
|
|
|
public:
|
2017-08-07 07:36:37 +02:00
|
|
|
TransactionSignatureChecker(const CTransaction* txToIn, unsigned int nInIn, const CAmount& amountIn) : txTo(txToIn), nIn(nInIn), amount(amountIn), txdata(nullptr) {}
|
2016-08-26 18:38:20 +02:00
|
|
|
TransactionSignatureChecker(const CTransaction* txToIn, unsigned int nInIn, const CAmount& amountIn, const PrecomputedTransactionData& txdataIn) : txTo(txToIn), nIn(nInIn), amount(amountIn), txdata(&txdataIn) {}
|
2017-06-20 21:58:56 +02:00
|
|
|
bool CheckSig(const std::vector<unsigned char>& scriptSig, const std::vector<unsigned char>& vchPubKey, const CScript& scriptCode, SigVersion sigversion) const override;
|
|
|
|
bool CheckLockTime(const CScriptNum& nLockTime) const override;
|
|
|
|
bool CheckSequence(const CScriptNum& nSequence) const override;
|
2014-09-10 14:42:22 +02:00
|
|
|
};
|
|
|
|
|
2015-01-27 09:28:45 -04:00
|
|
|
class MutableTransactionSignatureChecker : public TransactionSignatureChecker
|
|
|
|
{
|
|
|
|
private:
|
|
|
|
const CTransaction txTo;
|
|
|
|
|
|
|
|
public:
|
2016-11-10 08:00:05 +01:00
|
|
|
MutableTransactionSignatureChecker(const CMutableTransaction* txToIn, unsigned int nInIn, const CAmount& amountIn) : TransactionSignatureChecker(&txTo, nInIn, amountIn), txTo(*txToIn) {}
|
2015-01-27 09:28:45 -04:00
|
|
|
};
|
|
|
|
|
2017-08-07 07:36:37 +02:00
|
|
|
bool EvalScript(std::vector<std::vector<unsigned char> >& stack, const CScript& script, unsigned int flags, const BaseSignatureChecker& checker, SigVersion sigversion, ScriptError* error = nullptr);
|
|
|
|
bool VerifyScript(const CScript& scriptSig, const CScript& scriptPubKey, const CScriptWitness* witness, unsigned int flags, const BaseSignatureChecker& checker, ScriptError* serror = nullptr);
|
2014-08-27 20:11:41 +02:00
|
|
|
|
2016-01-03 18:54:50 +01:00
|
|
|
size_t CountWitnessSigOps(const CScript& scriptSig, const CScript& scriptPubKey, const CScriptWitness* witness, unsigned int flags);
|
|
|
|
|
2014-11-03 16:16:40 +01:00
|
|
|
#endif // BITCOIN_SCRIPT_INTERPRETER_H
|