Branch data Line data Source code
1 : : // Copyright (c) 2009-present The Bitcoin Core developers
2 : : // Distributed under the MIT software license, see the accompanying
3 : : // file COPYING or http://www.opensource.org/licenses/mit-license.php.
4 : :
5 : : #ifndef BITCOIN_PSBT_H
6 : : #define BITCOIN_PSBT_H
7 : :
8 : : #include <common/types.h>
9 : : #include <musig.h>
10 : : #include <node/transaction.h>
11 : : #include <policy/feerate.h>
12 : : #include <primitives/transaction.h>
13 : : #include <pubkey.h>
14 : : #include <script/keyorigin.h>
15 : : #include <script/sign.h>
16 : : #include <script/signingprovider.h>
17 : : #include <span.h>
18 : : #include <streams.h>
19 : : #include <uint256.h>
20 : : #include <util/result.h>
21 : : #include <util/expected.h>
22 : :
23 : : #include <optional>
24 : : #include <bitset>
25 : :
26 : : namespace node {
27 : : enum class TransactionError;
28 : : } // namespace node
29 : :
30 : : using common::PSBTError;
31 : :
32 : : // Magic bytes
33 : : inline constexpr uint8_t PSBT_MAGIC_BYTES[5] = {'p', 's', 'b', 't', 0xff};
34 : :
35 : : // Global types
36 : : inline constexpr uint8_t PSBT_GLOBAL_UNSIGNED_TX = 0x00;
37 : : inline constexpr uint8_t PSBT_GLOBAL_XPUB = 0x01;
38 : : inline constexpr uint8_t PSBT_GLOBAL_TX_VERSION = 0x02;
39 : : inline constexpr uint8_t PSBT_GLOBAL_FALLBACK_LOCKTIME = 0x03;
40 : : inline constexpr uint8_t PSBT_GLOBAL_INPUT_COUNT = 0x04;
41 : : inline constexpr uint8_t PSBT_GLOBAL_OUTPUT_COUNT = 0x05;
42 : : inline constexpr uint8_t PSBT_GLOBAL_TX_MODIFIABLE = 0x06;
43 : : inline constexpr uint8_t PSBT_GLOBAL_VERSION = 0xFB;
44 : : inline constexpr uint8_t PSBT_GLOBAL_PROPRIETARY = 0xFC;
45 : :
46 : : // Input types
47 : : inline constexpr uint8_t PSBT_IN_NON_WITNESS_UTXO = 0x00;
48 : : inline constexpr uint8_t PSBT_IN_WITNESS_UTXO = 0x01;
49 : : inline constexpr uint8_t PSBT_IN_PARTIAL_SIG = 0x02;
50 : : inline constexpr uint8_t PSBT_IN_SIGHASH = 0x03;
51 : : inline constexpr uint8_t PSBT_IN_REDEEMSCRIPT = 0x04;
52 : : inline constexpr uint8_t PSBT_IN_WITNESSSCRIPT = 0x05;
53 : : inline constexpr uint8_t PSBT_IN_BIP32_DERIVATION = 0x06;
54 : : inline constexpr uint8_t PSBT_IN_SCRIPTSIG = 0x07;
55 : : inline constexpr uint8_t PSBT_IN_SCRIPTWITNESS = 0x08;
56 : : inline constexpr uint8_t PSBT_IN_RIPEMD160 = 0x0A;
57 : : inline constexpr uint8_t PSBT_IN_SHA256 = 0x0B;
58 : : inline constexpr uint8_t PSBT_IN_HASH160 = 0x0C;
59 : : inline constexpr uint8_t PSBT_IN_HASH256 = 0x0D;
60 : : inline constexpr uint8_t PSBT_IN_PREVIOUS_TXID = 0x0e;
61 : : inline constexpr uint8_t PSBT_IN_OUTPUT_INDEX = 0x0f;
62 : : inline constexpr uint8_t PSBT_IN_SEQUENCE = 0x10;
63 : : inline constexpr uint8_t PSBT_IN_REQUIRED_TIME_LOCKTIME = 0x11;
64 : : inline constexpr uint8_t PSBT_IN_REQUIRED_HEIGHT_LOCKTIME = 0x12;
65 : : inline constexpr uint8_t PSBT_IN_TAP_KEY_SIG = 0x13;
66 : : inline constexpr uint8_t PSBT_IN_TAP_SCRIPT_SIG = 0x14;
67 : : inline constexpr uint8_t PSBT_IN_TAP_LEAF_SCRIPT = 0x15;
68 : : inline constexpr uint8_t PSBT_IN_TAP_BIP32_DERIVATION = 0x16;
69 : : inline constexpr uint8_t PSBT_IN_TAP_INTERNAL_KEY = 0x17;
70 : : inline constexpr uint8_t PSBT_IN_TAP_MERKLE_ROOT = 0x18;
71 : : inline constexpr uint8_t PSBT_IN_MUSIG2_PARTICIPANT_PUBKEYS = 0x1a;
72 : : inline constexpr uint8_t PSBT_IN_MUSIG2_PUB_NONCE = 0x1b;
73 : : inline constexpr uint8_t PSBT_IN_MUSIG2_PARTIAL_SIG = 0x1c;
74 : : inline constexpr uint8_t PSBT_IN_PROPRIETARY = 0xFC;
75 : :
76 : : // Output types
77 : : inline constexpr uint8_t PSBT_OUT_REDEEMSCRIPT = 0x00;
78 : : inline constexpr uint8_t PSBT_OUT_WITNESSSCRIPT = 0x01;
79 : : inline constexpr uint8_t PSBT_OUT_BIP32_DERIVATION = 0x02;
80 : : inline constexpr uint8_t PSBT_OUT_AMOUNT = 0x03;
81 : : inline constexpr uint8_t PSBT_OUT_SCRIPT = 0x04;
82 : : inline constexpr uint8_t PSBT_OUT_TAP_INTERNAL_KEY = 0x05;
83 : : inline constexpr uint8_t PSBT_OUT_TAP_TREE = 0x06;
84 : : inline constexpr uint8_t PSBT_OUT_TAP_BIP32_DERIVATION = 0x07;
85 : : inline constexpr uint8_t PSBT_OUT_MUSIG2_PARTICIPANT_PUBKEYS = 0x08;
86 : : inline constexpr uint8_t PSBT_OUT_PROPRIETARY = 0xFC;
87 : :
88 : : // The separator is 0x00. Reading this in means that the unserializer can interpret it
89 : : // as a 0 length key which indicates that this is the separator. The separator has no value.
90 : : inline constexpr uint8_t PSBT_SEPARATOR = 0x00;
91 : :
92 : : // BIP 174 does not specify a maximum file size, but we set a limit anyway
93 : : // to prevent reading a stream indefinitely and running out of memory.
94 : : inline constexpr std::streamsize MAX_FILE_SIZE_PSBT{100'000'000}; // 100 MB
95 : :
96 : : // PSBT version number
97 : : inline constexpr uint32_t PSBT_HIGHEST_VERSION = 2;
98 : :
99 : : /** A structure for PSBT proprietary types */
100 : 47662 : struct PSBTProprietary
101 : : {
102 : : uint64_t subtype;
103 : : std::vector<unsigned char> identifier;
104 : : std::vector<unsigned char> key;
105 : : std::vector<unsigned char> value;
106 : :
107 : 284574 : bool operator<(const PSBTProprietary &b) const {
108 : 284574 : return key < b.key;
109 : : }
110 : 0 : bool operator==(const PSBTProprietary &b) const {
111 [ # # ]: 0 : return key == b.key;
112 : : }
113 : : };
114 : :
115 : : // Takes a stream and multiple arguments and serializes them as if first serialized into a vector and then into the stream
116 : : // The resulting output into the stream has the total serialized length of all of the objects followed by all objects concatenated with each other.
117 : : template<typename Stream, typename... X>
118 : 184543 : void SerializeToVector(Stream& s, const X&... args)
119 : : {
120 : 184543 : SizeComputer sizecomp;
121 : 184543 : SerializeMany(sizecomp, args...);
122 : 184543 : WriteCompactSize(s, sizecomp.size());
123 : 184543 : SerializeMany(s, args...);
124 : 184543 : }
125 : :
126 : : // Takes a stream and multiple arguments and unserializes them first as a vector then each object individually in the order provided in the arguments
127 : : template<typename Stream, typename... X>
128 : 62081 : void UnserializeFromVector(Stream& s, X&&... args)
129 : : {
130 : 62081 : size_t expected_size = ReadCompactSize(s);
131 : 62068 : size_t remaining_before = s.size();
132 [ + + ]: 61086 : UnserializeMany(s, args...);
133 : 61086 : size_t remaining_after = s.size();
134 [ + + ]: 61086 : if (remaining_after + expected_size != remaining_before) {
135 [ + - ]: 1618 : throw std::ios_base::failure("Size of value was not the stated size");
136 : : }
137 : 60277 : }
138 : :
139 : : // Deserialize bytes of given length from the stream as a KeyOriginInfo
140 : : template<typename Stream>
141 : 62407 : KeyOriginInfo DeserializeKeyOrigin(Stream& s, uint64_t length)
142 : : {
143 : : // Read in key path
144 [ + + + + ]: 62407 : if (length % 4 || length == 0) {
145 [ + - ]: 258 : throw std::ios_base::failure("Invalid length for HD key path");
146 : : }
147 : :
148 : 62278 : KeyOriginInfo hd_keypath;
149 [ + + ]: 62278 : s >> hd_keypath.fingerprint;
150 [ + + ]: 2276877 : for (unsigned int i = 4; i < length; i += sizeof(uint32_t)) {
151 : : uint32_t index;
152 : 2214646 : s >> index;
153 [ + - ]: 2214646 : hd_keypath.path.push_back(index);
154 : : }
155 : 62146 : return hd_keypath;
156 : 132 : }
157 : :
158 : : // Deserialize a length prefixed KeyOriginInfo from a stream
159 : : template<typename Stream>
160 : 44579 : void DeserializeHDKeypath(Stream& s, KeyOriginInfo& hd_keypath)
161 : : {
162 : 44579 : hd_keypath = DeserializeKeyOrigin(s, ReadCompactSize(s));
163 : 44293 : }
164 : :
165 : : // Deserialize HD keypaths into a map
166 : : template<typename Stream>
167 [ - + ]: 42804 : void DeserializeHDKeypaths(Stream& s, const std::vector<unsigned char>& key, std::map<CPubKey, KeyOriginInfo>& hd_keypaths)
168 : : {
169 : : // Make sure that the key is the size of pubkey + 1
170 [ + + + + ]: 42804 : if (key.size() != CPubKey::SIZE + 1 && key.size() != CPubKey::COMPRESSED_SIZE + 1) {
171 [ + - ]: 27438 : throw std::ios_base::failure("Size of key was not the expected size for the type BIP32 keypath");
172 : : }
173 : : // Read in the pubkey from key
174 : 29085 : CPubKey pubkey(key.begin() + 1, key.end());
175 [ + + ]: 29085 : if (!pubkey.IsFullyValid()) {
176 [ + - ]: 388 : throw std::ios_base::failure("Invalid pubkey");
177 : : }
178 : :
179 : 28891 : KeyOriginInfo keypath;
180 [ + + ]: 28891 : DeserializeHDKeypath(s, keypath);
181 : :
182 : : // Add to map
183 [ + - ]: 28686 : hd_keypaths.emplace(pubkey, std::move(keypath));
184 : 28686 : }
185 : :
186 : : // Serialize a KeyOriginInfo to a stream
187 : : template<typename Stream>
188 : 35224 : void SerializeKeyOrigin(Stream& s, KeyOriginInfo hd_keypath)
189 : : {
190 : 35224 : s << hd_keypath.fingerprint;
191 [ + + ]: 1828227 : for (const auto& path : hd_keypath.path) {
192 : 1793003 : s << path;
193 : : }
194 : 35224 : }
195 : :
196 : : // Serialize a length prefixed KeyOriginInfo to a stream
197 : : template<typename Stream>
198 : 25818 : void SerializeHDKeypath(Stream& s, KeyOriginInfo hd_keypath)
199 : : {
200 [ - + ]: 25818 : WriteCompactSize(s, (hd_keypath.path.size() + 1) * sizeof(uint32_t));
201 [ + - ]: 25818 : SerializeKeyOrigin(s, hd_keypath);
202 : 25818 : }
203 : :
204 : : // Serialize HD keypaths to a stream from a map
205 : : template<typename Stream>
206 : 66947 : void SerializeHDKeypaths(Stream& s, const std::map<CPubKey, KeyOriginInfo>& hd_keypaths, CompactSizeWriter type)
207 : : {
208 [ + + ]: 88192 : for (const auto& keypath_pair : hd_keypaths) {
209 [ + + ]: 21471 : if (!keypath_pair.first.IsValid()) {
210 [ + - ]: 452 : throw std::ios_base::failure("Invalid CPubKey being serialized");
211 : : }
212 : 21245 : SerializeToVector(s, type, std::span{keypath_pair.first});
213 [ + - ]: 42490 : SerializeHDKeypath(s, keypath_pair.second);
214 : : }
215 : 66721 : }
216 : :
217 : : // Deserialize a PSBT_{IN/OUT}_MUSIG2_PARTICIPANT_PUBKEYS field
218 : : template<typename Stream>
219 : 9646 : void DeserializeMuSig2ParticipantPubkeys(Stream& s, SpanReader& skey, std::map<CPubKey, std::vector<CPubKey>>& out, std::string context)
220 : : {
221 : : std::array<unsigned char, CPubKey::COMPRESSED_SIZE> agg_pubkey_bytes;
222 : 9646 : skey >> std::as_writable_bytes(std::span{agg_pubkey_bytes});
223 : 9646 : CPubKey agg_pubkey(agg_pubkey_bytes);
224 [ + + ]: 9646 : if (!agg_pubkey.IsFullyValid()) {
225 [ + - + - ]: 88 : throw std::ios_base::failure(context + " musig2 aggregate pubkey is invalid");
226 : : }
227 : :
228 : 9602 : std::vector<CPubKey> participants;
229 [ + + ]: 9602 : std::vector<unsigned char> val;
230 [ - + ]: 9547 : s >> val;
231 : 9547 : SpanReader s_val{val};
232 [ + + ]: 11285 : while (s_val.size() >= CPubKey::COMPRESSED_SIZE) {
233 : : std::array<unsigned char, CPubKey::COMPRESSED_SIZE> part_pubkey_bytes;
234 [ + - ]: 3600 : s_val >> std::as_writable_bytes(std::span{part_pubkey_bytes});
235 : 1800 : CPubKey participant(part_pubkey_bytes);
236 [ + - + + ]: 1800 : if (!participant.IsFullyValid()) {
237 [ + - + - ]: 124 : throw std::ios_base::failure(context + " musig2 participant pubkey is invalid");
238 : : }
239 [ + - ]: 1738 : participants.push_back(participant);
240 : : }
241 [ + + ]: 9485 : if (!s_val.empty()) {
242 [ + - + - ]: 88 : throw std::ios_base::failure(context + " musig2 participants pubkeys value size is not a multiple of 33");
243 : : }
244 : :
245 [ + - ]: 9441 : out.emplace(agg_pubkey, participants);
246 : 9602 : }
247 : :
248 : : // Deserialize the MuSig2 participant identifiers from PSBT_MUSIG2_{PUBNONCE/PARTIAL_SIG} fields
249 : : // Both fields contain the same data after the type byte - aggregate pubkey | participant pubkey | leaf script hash
250 : : template<typename Stream>
251 : 9192 : void DeserializeMuSig2ParticipantDataIdentifier(Stream& skey, CPubKey& agg_pub, CPubKey& part_pub, uint256& leaf_hash)
252 : : {
253 : 9192 : leaf_hash.SetNull();
254 : :
255 : : std::array<unsigned char, CPubKey::COMPRESSED_SIZE> part_pubkey_bytes;
256 : : std::array<unsigned char, CPubKey::COMPRESSED_SIZE> agg_pubkey_bytes;
257 : :
258 : 9192 : skey >> std::as_writable_bytes(std::span{part_pubkey_bytes}) >> std::as_writable_bytes(std::span{agg_pubkey_bytes});
259 : 9192 : agg_pub.Set(agg_pubkey_bytes.begin(), agg_pubkey_bytes.end());
260 [ + + ]: 9192 : if (!agg_pub.IsFullyValid()) {
261 [ + - ]: 74 : throw std::ios_base::failure("musig2 aggregate pubkey is invalid");
262 : : }
263 : :
264 : 9155 : part_pub.Set(part_pubkey_bytes.begin(), part_pubkey_bytes.end());
265 [ + + ]: 9155 : if (!part_pub.IsFullyValid()) {
266 [ + - ]: 56 : throw std::ios_base::failure("musig2 participant pubkey is invalid");
267 : : }
268 : :
269 [ + + ]: 9127 : if (!skey.empty()) {
270 : 1533 : skey >> leaf_hash;
271 : : }
272 : 9127 : }
273 : :
274 : 183541 : static inline void ExpectedKeySize(const std::string& key_name, const std::vector<unsigned char>& key, uint64_t expected_size) {
275 [ - + + + ]: 183541 : if (key.size() != expected_size) {
276 [ + - + - ]: 5350 : throw std::ios_base::failure(tfm::format("Size of key was not %d for the type %s", expected_size, key_name));
277 : : }
278 : 180866 : }
279 : :
280 : : /** A structure for PSBTs which contain per-input information */
281 : : class PSBTInput
282 : : {
283 : : private:
284 : 10354 : uint32_t m_psbt_version;
285 : :
286 : : public:
287 [ + - ]: 10354 : CTransactionRef non_witness_utxo;
288 : 10354 : CTxOut witness_utxo;
289 : : CScript redeem_script;
290 : : CScript witness_script;
291 : : CScript final_script_sig;
292 : : CScriptWitness final_script_witness;
293 : 10354 : std::map<CPubKey, KeyOriginInfo> hd_keypaths;
294 : 10354 : std::map<CKeyID, SigPair> partial_sigs;
295 : 10354 : std::map<uint160, std::vector<unsigned char>> ripemd160_preimages;
296 : 10354 : std::map<uint256, std::vector<unsigned char>> sha256_preimages;
297 : 10354 : std::map<uint160, std::vector<unsigned char>> hash160_preimages;
298 : 10354 : std::map<uint256, std::vector<unsigned char>> hash256_preimages;
299 : :
300 : : Txid prev_txid;
301 : 10354 : uint32_t prev_out;
302 [ + - ]: 10354 : std::optional<uint32_t> sequence;
303 : 10354 : std::optional<uint32_t> time_locktime;
304 : 10354 : std::optional<uint32_t> height_locktime;
305 : :
306 : : // Taproot fields
307 : 10354 : std::vector<unsigned char> m_tap_key_sig;
308 : 10354 : std::map<std::pair<XOnlyPubKey, uint256>, std::vector<unsigned char>> m_tap_script_sigs;
309 : 10354 : std::map<std::pair<std::vector<unsigned char>, int>, std::set<std::vector<unsigned char>, ShortestVectorFirstComparator>> m_tap_scripts;
310 : 10354 : std::map<XOnlyPubKey, std::pair<std::set<uint256>, KeyOriginInfo>> m_tap_bip32_paths;
311 : : XOnlyPubKey m_tap_internal_key;
312 : : uint256 m_tap_merkle_root;
313 : :
314 : : // MuSig2 fields
315 : 10354 : std::map<CPubKey, std::vector<CPubKey>> m_musig2_participants;
316 : : // Key is the aggregate pubkey and the script leaf hash, value is a map of participant pubkey to pubnonce
317 : 10354 : std::map<std::pair<CPubKey, uint256>, std::map<CPubKey, std::vector<uint8_t>>> m_musig2_pubnonces;
318 : : // Key is the aggregate pubkey and the script leaf hash, value is a map of participant pubkey to partial_sig
319 : 10354 : std::map<std::pair<CPubKey, uint256>, std::map<CPubKey, uint256>> m_musig2_partial_sigs;
320 : :
321 : 10354 : std::map<std::vector<unsigned char>, std::vector<unsigned char>> unknown;
322 : 10354 : std::set<PSBTProprietary> m_proprietary;
323 [ + - ]: 10354 : std::optional<int> sighash_type;
324 : :
325 : : void FillSignatureData(SignatureData& sigdata) const;
326 : : void FromSignatureData(const SignatureData& sigdata);
327 : : [[nodiscard]] bool Merge(const PSBTInput& input);
328 : 12830 : uint32_t GetVersion() const { return m_psbt_version; }
329 : : COutPoint GetOutPoint() const;
330 : : /**
331 : : * Retrieves the UTXO for this input
332 : : *
333 : : * @param[out] utxo The UTXO of this input
334 : : * @return Whether the UTXO could be retrieved
335 : : */
336 : : bool GetUTXO(CTxOut& utxo) const;
337 : : bool HasSignatures() const;
338 : :
339 : 58004 : explicit PSBTInput(uint32_t psbt_version, const Txid& prev_txid, uint32_t prev_out, std::optional<uint32_t> sequence = std::nullopt)
340 : 58004 : : m_psbt_version(psbt_version),
341 : 58004 : prev_txid(prev_txid),
342 [ - + ]: 58004 : prev_out(prev_out),
343 [ - + ]: 58004 : sequence(sequence)
344 : : {
345 [ - + ]: 58004 : assert(m_psbt_version == 0 || m_psbt_version == 2);
346 : 58004 : }
347 : :
348 : : // Construct a PSBTInput when the previous txid and output index are expected to be serialized
349 : : template <typename Stream>
350 : 0 : explicit PSBTInput(deserialize_type, Stream& s, uint32_t psbt_version)
351 [ # # ]: 0 : : m_psbt_version(psbt_version)
352 : : {
353 [ # # ]: 0 : assert(m_psbt_version == 2);
354 [ # # ]: 0 : Unserialize(s);
355 [ # # ]: 0 : }
356 : :
357 : 186372 : bool operator==(const PSBTInput&) const = default;
[ + - + -
+ - + - +
- + - + -
+ - + - +
- + - + -
+ - + - +
- + - + -
+ - + - +
- + - + -
+ - + - +
- + - +
- ]
358 : :
359 : : template <typename Stream>
360 : 28303 : inline void Serialize(Stream& s) const {
361 : : // Write the utxo
362 [ + + ]: 28303 : if (non_witness_utxo) {
363 : 670 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_NON_WITNESS_UTXO));
364 : 670 : SerializeToVector(s, TX_NO_WITNESS(non_witness_utxo));
365 : : }
366 [ + + ]: 28303 : if (!witness_utxo.IsNull()) {
367 : 15146 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_WITNESS_UTXO));
368 : 15146 : SerializeToVector(s, witness_utxo);
369 : : }
370 : :
371 [ + + + + : 31698 : if (final_script_sig.empty() && final_script_witness.IsNull()) {
+ + ]
372 : : // Write any partial signatures
373 [ + + ]: 26184 : for (const auto& sig_pair : partial_sigs) {
374 : 2791 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_PARTIAL_SIG), std::span{sig_pair.second.first});
375 : 2791 : s << sig_pair.second.second;
376 : : }
377 : :
378 : : // Write the sighash type
379 [ + + ]: 23393 : if (sighash_type != std::nullopt) {
380 : 85 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_SIGHASH));
381 : 85 : SerializeToVector(s, *sighash_type);
382 : : }
383 : :
384 : : // Write the redeem script
385 [ + + + + ]: 23665 : if (!redeem_script.empty()) {
386 : 886 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_REDEEMSCRIPT));
387 : 886 : s << redeem_script;
388 : : }
389 : :
390 : : // Write the witness script
391 [ + + + + ]: 23801 : if (!witness_script.empty()) {
392 : 677 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_WITNESSSCRIPT));
393 : 677 : s << witness_script;
394 : : }
395 : :
396 : : // Write any hd keypaths
397 : 23393 : SerializeHDKeypaths(s, hd_keypaths, CompactSizeWriter(PSBT_IN_BIP32_DERIVATION));
398 : :
399 : : // Write any ripemd160 preimage
400 [ + + ]: 27424 : for (const auto& [hash, preimage] : ripemd160_preimages) {
401 : 4031 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_RIPEMD160), std::span{hash});
402 : 4031 : s << preimage;
403 : : }
404 : :
405 : : // Write any sha256 preimage
406 [ + + ]: 33460 : for (const auto& [hash, preimage] : sha256_preimages) {
407 : 10067 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_SHA256), std::span{hash});
408 : 10067 : s << preimage;
409 : : }
410 : :
411 : : // Write any hash160 preimage
412 [ + + ]: 33999 : for (const auto& [hash, preimage] : hash160_preimages) {
413 : 10606 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_HASH160), std::span{hash});
414 : 10606 : s << preimage;
415 : : }
416 : :
417 : : // Write any hash256 preimage
418 [ + + ]: 28574 : for (const auto& [hash, preimage] : hash256_preimages) {
419 : 5181 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_HASH256), std::span{hash});
420 : 5181 : s << preimage;
421 : : }
422 : :
423 : : // Write taproot key sig
424 [ + + ]: 23393 : if (!m_tap_key_sig.empty()) {
425 : 619 : SerializeToVector(s, PSBT_IN_TAP_KEY_SIG);
426 : 619 : s << m_tap_key_sig;
427 : : }
428 : :
429 : : // Write taproot script sigs
430 [ + + ]: 27707 : for (const auto& [pubkey_leaf, sig] : m_tap_script_sigs) {
431 : 4314 : const auto& [xonly, leaf_hash] = pubkey_leaf;
432 : 4314 : SerializeToVector(s, PSBT_IN_TAP_SCRIPT_SIG, xonly, leaf_hash);
433 : 4314 : s << sig;
434 : : }
435 : :
436 : : // Write taproot leaf scripts
437 [ + + ]: 43009 : for (const auto& [leaf, control_blocks] : m_tap_scripts) {
438 : 19616 : const auto& [script, leaf_ver] = leaf;
439 [ - + + + ]: 41781 : for (const auto& control_block : control_blocks) {
440 : 22165 : SerializeToVector(s, PSBT_IN_TAP_LEAF_SCRIPT, std::span{control_block});
441 : 22165 : std::vector<unsigned char> value_v(script.begin(), script.end());
442 [ + - + - ]: 22165 : value_v.push_back((uint8_t)leaf_ver);
443 : 22165 : s << value_v;
444 : : }
445 : : }
446 : :
447 : : // Write taproot bip32 keypaths
448 [ + + ]: 28548 : for (const auto& [xonly, leaf_origin] : m_tap_bip32_paths) {
449 : 5155 : const auto& [leaf_hashes, origin] = leaf_origin;
450 : 5155 : SerializeToVector(s, PSBT_IN_TAP_BIP32_DERIVATION, xonly);
451 : 5155 : std::vector<unsigned char> value;
452 [ + - ]: 5155 : VectorWriter s_value{value, 0};
453 [ + - ]: 5155 : s_value << leaf_hashes;
454 [ + - + - ]: 10310 : SerializeKeyOrigin(s_value, origin);
455 : 5155 : s << value;
456 : : }
457 : :
458 : : // Write taproot internal key
459 [ + + ]: 46786 : if (!m_tap_internal_key.IsNull()) {
460 : 266 : SerializeToVector(s, PSBT_IN_TAP_INTERNAL_KEY);
461 [ + - ]: 532 : s << ToByteVector(m_tap_internal_key);
462 : : }
463 : :
464 : : // Write taproot merkle root
465 [ + + ]: 46786 : if (!m_tap_merkle_root.IsNull()) {
466 : 260 : SerializeToVector(s, PSBT_IN_TAP_MERKLE_ROOT);
467 : 260 : SerializeToVector(s, m_tap_merkle_root);
468 : : }
469 : :
470 : : // Write MuSig2 Participants
471 [ + + ]: 25248 : for (const auto& [agg_pubkey, part_pubs] : m_musig2_participants) {
472 : 1855 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_MUSIG2_PARTICIPANT_PUBKEYS), std::span{agg_pubkey});
473 : 1855 : std::vector<unsigned char> value;
474 [ + - ]: 1855 : VectorWriter s_value{value, 0};
475 [ + - + + ]: 2232 : for (auto& pk : part_pubs) {
476 [ + - ]: 754 : s_value << std::span{pk};
477 : : }
478 : 1855 : s << value;
479 : : }
480 : :
481 : : // Write MuSig2 pubnonces
482 [ + + ]: 25597 : for (const auto& [agg_pubkey_leaf_hash, pubnonces] : m_musig2_pubnonces) {
483 : 2204 : const auto& [agg_pubkey, leaf_hash] = agg_pubkey_leaf_hash;
484 [ + + ]: 4985 : for (const auto& [part_pubkey, pubnonce] : pubnonces) {
485 [ + + ]: 5562 : if (leaf_hash.IsNull()) {
486 : 2326 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_MUSIG2_PUB_NONCE), std::span{part_pubkey}, std::span{agg_pubkey});
487 : : } else {
488 : 455 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_MUSIG2_PUB_NONCE), std::span{part_pubkey}, std::span{agg_pubkey}, leaf_hash);
489 : : }
490 : 2781 : s << pubnonce;
491 : : }
492 : : }
493 : :
494 : : // Write MuSig2 partial signatures
495 [ + + ]: 25254 : for (const auto& [agg_pubkey_leaf_hash, psigs] : m_musig2_partial_sigs) {
496 : 1861 : const auto& [agg_pubkey, leaf_hash] = agg_pubkey_leaf_hash;
497 [ + + ]: 4285 : for (const auto& [pubkey, psig] : psigs) {
498 [ + + ]: 4848 : if (leaf_hash.IsNull()) {
499 : 1889 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_MUSIG2_PARTIAL_SIG), std::span{pubkey}, std::span{agg_pubkey});
500 : : } else {
501 : 535 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_MUSIG2_PARTIAL_SIG), std::span{pubkey}, std::span{agg_pubkey}, leaf_hash);
502 : : }
503 : 2424 : SerializeToVector(s, psig);
504 : : }
505 : : }
506 : : }
507 : :
508 : : // Write script sig
509 [ + + + + ]: 31698 : if (!final_script_sig.empty()) {
510 : 4168 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_SCRIPTSIG));
511 : 4168 : s << final_script_sig;
512 : : }
513 : : // write script witness
514 [ + + ]: 28303 : if (!final_script_witness.IsNull()) {
515 : 749 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_SCRIPTWITNESS));
516 : 749 : SerializeToVector(s, final_script_witness.stack);
517 : : }
518 : :
519 : : // Write PSBTv2 fields
520 [ - + ]: 28303 : if (m_psbt_version >= 2) {
521 : : // Write prev txid, vout, sequence, and lock times
522 : 0 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_PREVIOUS_TXID));
523 : 0 : SerializeToVector(s, prev_txid);
524 : :
525 : 0 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_OUTPUT_INDEX));
526 : 0 : SerializeToVector(s, prev_out);
527 : :
528 [ # # ]: 0 : if (sequence != std::nullopt) {
529 : 0 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_SEQUENCE));
530 : 0 : SerializeToVector(s, *sequence);
531 : : }
532 [ # # ]: 0 : if (time_locktime != std::nullopt) {
533 : 0 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_REQUIRED_TIME_LOCKTIME));
534 : 0 : SerializeToVector(s, *time_locktime);
535 : : }
536 [ # # ]: 0 : if (height_locktime != std::nullopt) {
537 : 0 : SerializeToVector(s, CompactSizeWriter(PSBT_IN_REQUIRED_HEIGHT_LOCKTIME));
538 : 0 : SerializeToVector(s, *height_locktime);
539 : : }
540 : : }
541 : :
542 : : // Write proprietary things
543 [ + + ]: 33977 : for (const auto& entry : m_proprietary) {
544 : 5674 : s << entry.key;
545 : 5674 : s << entry.value;
546 : : }
547 : :
548 : : // Write unknown things
549 [ + + ]: 71400 : for (auto& entry : unknown) {
550 : 43097 : s << entry.first;
551 : 43097 : s << entry.second;
552 : : }
553 : :
554 : 28303 : s << PSBT_SEPARATOR;
555 : 28303 : }
556 : :
557 : :
558 : : template <typename Stream>
559 : 44615 : inline void Unserialize(Stream& s) {
560 : : // Used for duplicate key detection
561 : 44615 : std::set<std::vector<unsigned char>> key_lookup;
562 : : // Cache whether PSBTv2 required fields were seen
563 : 44615 : bool found_prev_txid = false;
564 : 44615 : bool found_prev_out = false;
565 : :
566 : : // Read loop
567 : 44615 : bool found_sep = false;
568 [ + + ]: 304066 : while(!s.empty()) {
569 : : // Read the key of format "<keylen><keytype><keydata>" after which
570 : : // "key" will contain "<keytype><keydata>"
571 [ + + ]: 298977 : std::vector<unsigned char> key;
572 : 298483 : s >> key;
573 : :
574 : : // the key is empty if that was actually a separator byte
575 : : // This is a special case for key lengths 0 as those are not allowed (except for separator)
576 [ + + ]: 298483 : if (key.empty()) {
577 : 39526 : found_sep = true;
578 : : break;
579 : : }
580 : :
581 : : // Duplicate keys are not permitted
582 [ + - + + ]: 258957 : if (!key_lookup.emplace(key).second) {
583 [ - + + - : 456 : throw std::ios_base::failure(tfm::format("Duplicate Key, input key \"%s\" already provided", HexStr(key)));
+ - + - ]
584 : : }
585 : :
586 : : // "skey" is used so that "key" is unchanged after reading keytype below
587 : 258729 : SpanReader skey{key};
588 : : // keytype is of the format compact size uint at the beginning of "key"
589 [ + + ]: 258729 : uint64_t type = ReadCompactSize(skey);
590 : :
591 : : // Do stuff based on keytype "type", i.e., key checks, reading values of the
592 : : // format "<valuelen><valuedata>" from the stream "s", and value checks
593 : 258721 : switch(type) {
[ + + + +
+ + + + +
+ + + + +
+ + + + +
+ + + + +
+ + + +
+ ]
594 : 1780 : case PSBT_IN_NON_WITNESS_UTXO:
595 : : {
596 [ + - + + ]: 1810 : ExpectedKeySize("Input Non-witness UTXO", key, 1);
597 : : // Set the stream to unserialize with witness since this is always a valid network transaction
598 [ + + ]: 1750 : UnserializeFromVector(s, TX_WITH_WITNESS(non_witness_utxo));
599 : : break;
600 : : }
601 : 17837 : case PSBT_IN_WITNESS_UTXO:
602 [ + - + + ]: 17862 : ExpectedKeySize("Input Witness UTXO", key, 1);
603 [ + + ]: 17812 : UnserializeFromVector(s, witness_utxo);
604 : : break;
605 [ - + ]: 6885 : case PSBT_IN_PARTIAL_SIG:
606 : : {
607 : : // Make sure that the key is the size of pubkey + 1
608 [ + + + + ]: 6885 : if (key.size() != CPubKey::SIZE + 1 && key.size() != CPubKey::COMPRESSED_SIZE + 1) {
609 [ + - ]: 38 : throw std::ios_base::failure("Size of key was not the expected size for the type partial signature pubkey");
610 : : }
611 : : // Read in the pubkey from key
612 : 6866 : CPubKey pubkey(key.begin() + 1, key.end());
613 [ + - + + ]: 6866 : if (!pubkey.IsFullyValid()) {
614 [ + - ]: 130 : throw std::ios_base::failure("Invalid pubkey");
615 : : }
616 : :
617 : : // Read in the signature from value
618 [ + + ]: 6801 : std::vector<unsigned char> sig;
619 : 6504 : s >> sig;
620 : :
621 : : // Check that the signature is validly encoded
622 [ + + + - : 6504 : if (sig.empty() || !CheckSignatureEncoding(sig, SCRIPT_VERIFY_DERSIG | SCRIPT_VERIFY_STRICTENC, nullptr)) {
+ + ]
623 [ + - ]: 768 : throw std::ios_base::failure("Signature is not a valid encoding");
624 : : }
625 : :
626 : : // Add to list
627 [ + - + - ]: 12240 : partial_sigs.emplace(pubkey.GetID(), SigPair(pubkey, std::move(sig)));
628 : : break;
629 : 6801 : }
630 : 366 : case PSBT_IN_SIGHASH:
631 [ + - + + ]: 384 : ExpectedKeySize("Input Sighash Type", key, 1);
632 : : int sighash;
633 [ + + ]: 348 : UnserializeFromVector(s, sighash);
634 : 334 : sighash_type = sighash;
635 : 334 : break;
636 : 2120 : case PSBT_IN_REDEEMSCRIPT:
637 : : {
638 [ + - + + ]: 2143 : ExpectedKeySize("Input redeemScript", key, 1);
639 [ + + ]: 2097 : s >> redeem_script;
640 : : break;
641 : : }
642 : 1596 : case PSBT_IN_WITNESSSCRIPT:
643 : : {
644 [ + - + + ]: 1613 : ExpectedKeySize("Input witnessScript", key, 1);
645 [ + + ]: 1579 : s >> witness_script;
646 : : break;
647 : : }
648 : 8276 : case PSBT_IN_BIP32_DERIVATION:
649 : : {
650 [ + + ]: 8276 : DeserializeHDKeypaths(s, key, hd_keypaths);
651 : : break;
652 : : }
653 : 5126 : case PSBT_IN_SCRIPTSIG:
654 : : {
655 [ + - + + ]: 5142 : ExpectedKeySize("Input Final scriptSig", key, 1);
656 [ + + ]: 259660 : s >> final_script_sig;
657 : : break;
658 : : }
659 : 1343 : case PSBT_IN_SCRIPTWITNESS:
660 : : {
661 [ + - + + ]: 1363 : ExpectedKeySize("Input Final scriptWitness", key, 1);
662 [ + + ]: 1323 : UnserializeFromVector(s, final_script_witness.stack);
663 : : break;
664 : : }
665 : 8442 : case PSBT_IN_RIPEMD160:
666 : : {
667 [ + - + + : 16884 : ExpectedKeySize("Input RIPEMD160 Preimage", key, CRIPEMD160::OUTPUT_SIZE + 1);
+ - ]
668 : : // Read in the hash from key
669 [ + - ]: 8424 : std::vector<unsigned char> hash_vec(key.begin() + 1, key.end());
670 : 8424 : uint160 hash(hash_vec);
671 : :
672 : : // Read in the preimage from value
673 [ + + ]: 8424 : std::vector<unsigned char> preimage;
674 : 8383 : s >> preimage;
675 : :
676 : : // Add to preimages list
677 [ + - ]: 8383 : ripemd160_preimages.emplace(hash, std::move(preimage));
678 : : break;
679 : 8465 : }
680 : 15282 : case PSBT_IN_SHA256:
681 : : {
682 [ + - + + : 30564 : ExpectedKeySize("Input SHA256 Preimage", key, CSHA256::OUTPUT_SIZE + 1);
+ - ]
683 : : // Read in the hash from key
684 [ + - ]: 15264 : std::vector<unsigned char> hash_vec(key.begin() + 1, key.end());
685 : 15264 : uint256 hash(hash_vec);
686 : :
687 : : // Read in the preimage from value
688 [ + + ]: 15264 : std::vector<unsigned char> preimage;
689 : 15217 : s >> preimage;
690 : :
691 : : // Add to preimages list
692 [ + - ]: 15217 : sha256_preimages.emplace(hash, std::move(preimage));
693 : : break;
694 : 15311 : }
695 : 16531 : case PSBT_IN_HASH160:
696 : : {
697 [ + - + + : 33062 : ExpectedKeySize("Input Hash160 Preimage", key, CHash160::OUTPUT_SIZE + 1);
+ - ]
698 : : // Read in the hash from key
699 [ + - ]: 16514 : std::vector<unsigned char> hash_vec(key.begin() + 1, key.end());
700 : 16514 : uint160 hash(hash_vec);
701 : :
702 : : // Read in the preimage from value
703 [ + + ]: 16514 : std::vector<unsigned char> preimage;
704 : 16468 : s >> preimage;
705 : :
706 : : // Add to preimages list
707 [ + - ]: 16468 : hash160_preimages.emplace(hash, std::move(preimage));
708 : : break;
709 : 16560 : }
710 : 10391 : case PSBT_IN_HASH256:
711 : : {
712 [ + - + + : 20782 : ExpectedKeySize("Input Hash256 Preimage", key, CHash256::OUTPUT_SIZE + 1);
+ - ]
713 : : // Read in the hash from key
714 [ + - ]: 10374 : std::vector<unsigned char> hash_vec(key.begin() + 1, key.end());
715 : 10374 : uint256 hash(hash_vec);
716 : :
717 : : // Read in the preimage from value
718 [ + + ]: 10374 : std::vector<unsigned char> preimage;
719 : 10330 : s >> preimage;
720 : :
721 : : // Add to preimages list
722 [ + - ]: 10330 : hash256_preimages.emplace(hash, std::move(preimage));
723 : : break;
724 : 10418 : }
725 : 106 : case PSBT_IN_PREVIOUS_TXID:
726 : : {
727 [ + - + + ]: 179 : ExpectedKeySize("Input Previous TXID", key, 1);
728 [ + - ]: 33 : if (m_psbt_version < 2) {
729 [ + - ]: 66 : throw std::ios_base::failure("Previous txid is not allowed in PSBTv0");
730 : : }
731 [ # # ]: 0 : UnserializeFromVector(s, prev_txid);
732 : : found_prev_txid = true;
733 : : break;
734 : : }
735 : 54 : case PSBT_IN_OUTPUT_INDEX:
736 : : {
737 [ + - + + ]: 95 : ExpectedKeySize("Input Previous Output's Index", key, 1);
738 [ + - ]: 13 : if (m_psbt_version < 2) {
739 [ + - ]: 26 : throw std::ios_base::failure("Previous output's index is not allowed in PSBTv0");
740 : : }
741 [ # # ]: 0 : UnserializeFromVector(s, prev_out);
742 : : found_prev_out = true;
743 : : break;
744 : : }
745 : 258 : case PSBT_IN_SEQUENCE:
746 : : {
747 [ + - + + ]: 498 : ExpectedKeySize("Input Sequence", key, 1);
748 [ + - ]: 18 : if (m_psbt_version < 2) {
749 [ + - ]: 36 : throw std::ios_base::failure("Sequence is not allowed in PSBTv0");
750 : : }
751 [ # # ]: 0 : sequence.emplace();
752 [ # # ]: 0 : UnserializeFromVector(s, *sequence);
753 : : break;
754 : : }
755 : 405 : case PSBT_IN_REQUIRED_TIME_LOCKTIME:
756 : : {
757 [ + - + + ]: 793 : ExpectedKeySize("Input Required Time Based Locktime", key, 1);
758 [ + - ]: 17 : if (m_psbt_version < 2) {
759 [ + - ]: 34 : throw std::ios_base::failure("Required time based locktime is not allowed in PSBTv0");
760 : : }
761 [ # # ]: 0 : time_locktime.emplace();
762 [ # # ]: 0 : UnserializeFromVector(s, *time_locktime);
763 [ # # ]: 0 : if (*time_locktime < LOCKTIME_THRESHOLD) {
764 [ # # ]: 0 : throw std::ios_base::failure("Required time based locktime is invalid (less than 500000000)");
765 : : }
766 : : break;
767 : : }
768 : 58 : case PSBT_IN_REQUIRED_HEIGHT_LOCKTIME:
769 : : {
770 [ + - + + ]: 98 : ExpectedKeySize("Input Required Height Based Locktime", key, 1);
771 [ + - ]: 18 : if (m_psbt_version < 2) {
772 [ + - ]: 36 : throw std::ios_base::failure("Required height based locktime is not allowed in PSBTv0");
773 : : }
774 [ # # ]: 0 : height_locktime.emplace();
775 [ # # ]: 0 : UnserializeFromVector(s, *height_locktime);
776 [ # # ]: 0 : if (*height_locktime >= LOCKTIME_THRESHOLD) {
777 [ # # ]: 0 : throw std::ios_base::failure("Required height based locktime is invalid (greater than or equal to 500000000)");
778 [ # # ]: 0 : } else if (*height_locktime == 0) {
779 [ # # ]: 0 : throw std::ios_base::failure("Required height based locktime is invalid (0)");
780 : : }
781 : : break;
782 : : }
783 : 995 : case PSBT_IN_TAP_KEY_SIG:
784 : : {
785 [ + - + + ]: 1009 : ExpectedKeySize("Input Taproot Key Path Signature", key, 1);
786 [ + + ]: 981 : s >> m_tap_key_sig;
787 [ - + + + ]: 952 : if (m_tap_key_sig.size() < 64) {
788 [ + - ]: 24 : throw std::ios_base::failure("Input Taproot key path signature is shorter than 64 bytes");
789 [ + + ]: 940 : } else if (m_tap_key_sig.size() > 65) {
790 [ + - ]: 20 : throw std::ios_base::failure("Input Taproot key path signature is longer than 65 bytes");
791 : : }
792 : : break;
793 : : }
794 : 8607 : case PSBT_IN_TAP_SCRIPT_SIG:
795 : : {
796 [ + - + + : 17214 : ExpectedKeySize("Input Taproot Script Path Signature", key, 65);
- + ]
797 : 8590 : SpanReader s_key{std::span{key}.subspan(1)};
798 : 8590 : XOnlyPubKey xonly;
799 [ + - ]: 8590 : uint256 hash;
800 [ + - ]: 8590 : s_key >> xonly;
801 : 8590 : s_key >> hash;
802 [ + + ]: 8590 : std::vector<unsigned char> sig;
803 [ - + ]: 8556 : s >> sig;
804 [ + + ]: 8556 : if (sig.size() < 64) {
805 [ + - ]: 64 : throw std::ios_base::failure("Input Taproot script path signature is shorter than 64 bytes");
806 [ + + ]: 8524 : } else if (sig.size() > 65) {
807 [ + - ]: 30 : throw std::ios_base::failure("Input Taproot script path signature is longer than 65 bytes");
808 : : }
809 [ + - ]: 8509 : m_tap_script_sigs.emplace(std::make_pair(xonly, hash), sig);
810 : : break;
811 : 8590 : }
812 [ - + ]: 41669 : case PSBT_IN_TAP_LEAF_SCRIPT:
813 : : {
814 [ + + ]: 41669 : if (key.size() < 34) {
815 [ + - ]: 66 : throw std::ios_base::failure("Input Taproot leaf script key is not at least 34 bytes");
816 [ + + ]: 41636 : } else if ((key.size() - 2) % 32 != 0) {
817 [ + - ]: 32 : throw std::ios_base::failure("Input Taproot leaf script key's control block size is not valid");
818 : : }
819 [ + + ]: 41620 : std::vector<unsigned char> script_v;
820 : 41563 : s >> script_v;
821 [ + + ]: 41563 : if (script_v.empty()) {
822 [ + - ]: 44 : throw std::ios_base::failure("Input Taproot leaf script must be at least 1 byte");
823 : : }
824 [ + - ]: 41541 : uint8_t leaf_ver = script_v.back();
825 : 41541 : script_v.pop_back();
826 [ + - ]: 41541 : const auto leaf_script = std::make_pair(script_v, (int)leaf_ver);
827 [ + - + - : 83082 : m_tap_scripts[leaf_script].insert(std::vector<unsigned char>(key.begin() + 1, key.end()));
+ - ]
828 : : break;
829 : 41620 : }
830 : 9844 : case PSBT_IN_TAP_BIP32_DERIVATION:
831 : : {
832 [ + - + + : 19688 : ExpectedKeySize("Input Taproot BIP32 Keypath", key, 33);
- + ]
833 : 9828 : SpanReader s_key{std::span{key}.subspan(1)};
834 [ + - ]: 9828 : XOnlyPubKey xonly;
835 [ + + ]: 9828 : s_key >> xonly;
836 : 9828 : std::set<uint256> leaf_hashes;
837 [ + + + + ]: 9828 : uint64_t value_len = ReadCompactSize(s);
838 [ + + ]: 9816 : size_t before_hashes = s.size();
839 [ + + ]: 9679 : s >> leaf_hashes;
840 : 9679 : size_t after_hashes = s.size();
841 : 9679 : size_t hashes_len = before_hashes - after_hashes;
842 [ + + ]: 9679 : if (hashes_len > value_len) {
843 [ + - ]: 50 : throw std::ios_base::failure("Input Taproot BIP32 keypath has an invalid length");
844 : : }
845 : 9654 : size_t origin_len = value_len - hashes_len;
846 [ + + + - ]: 19286 : m_tap_bip32_paths.emplace(xonly, std::make_pair(leaf_hashes, DeserializeKeyOrigin(s, origin_len)));
847 : : break;
848 : 9828 : }
849 : 395 : case PSBT_IN_TAP_INTERNAL_KEY:
850 : : {
851 [ + - + + ]: 412 : ExpectedKeySize("Input Taproot Internal Key", key, 1);
852 [ + + ]: 378 : UnserializeFromVector(s, m_tap_internal_key);
853 : : break;
854 : : }
855 : 453 : case PSBT_IN_TAP_MERKLE_ROOT:
856 : : {
857 [ + - + + ]: 471 : ExpectedKeySize("Input Taproot Merkle Root", key, 1);
858 [ + + ]: 435 : UnserializeFromVector(s, m_tap_merkle_root);
859 : : break;
860 : : }
861 : 3118 : case PSBT_IN_MUSIG2_PARTICIPANT_PUBKEYS:
862 : : {
863 [ + - + + ]: 3134 : ExpectedKeySize("Input MuSig2 Participants Pubkeys", key, CPubKey::COMPRESSED_SIZE + 1);
864 [ + - + + ]: 6204 : DeserializeMuSig2ParticipantPubkeys(s, skey, m_musig2_participants, std::string{"Input"});
865 : : break;
866 : : }
867 [ - + ]: 5343 : case PSBT_IN_MUSIG2_PUB_NONCE:
868 : : {
869 [ + + + + ]: 5343 : if (key.size() != 2 * CPubKey::COMPRESSED_SIZE + 1 && key.size() != 2 * CPubKey::COMPRESSED_SIZE + CSHA256::OUTPUT_SIZE + 1) {
870 [ + - ]: 32 : throw std::ios_base::failure("Input musig2 pubnonce key is not expected size of 67 or 99 bytes");
871 : : }
872 : 5327 : CPubKey agg_pub, part_pub;
873 : 5327 : uint256 leaf_hash;
874 [ + + ]: 5327 : DeserializeMuSig2ParticipantDataIdentifier(skey, agg_pub, part_pub, leaf_hash);
875 : :
876 [ + + ]: 5291 : std::vector<uint8_t> pubnonce;
877 [ - + ]: 5259 : s >> pubnonce;
878 [ + + ]: 5259 : if (pubnonce.size() != MUSIG2_PUBNONCE_SIZE) {
879 [ + - ]: 46 : throw std::ios_base::failure("Input musig2 pubnonce value is not 66 bytes");
880 : : }
881 : :
882 [ + - + - ]: 5236 : m_musig2_pubnonces[std::make_pair(agg_pub, leaf_hash)].emplace(part_pub, pubnonce);
883 : : break;
884 : 5291 : }
885 [ - + ]: 3882 : case PSBT_IN_MUSIG2_PARTIAL_SIG:
886 : : {
887 [ + + + + ]: 3882 : if (key.size() != 2 * CPubKey::COMPRESSED_SIZE + 1 && key.size() != 2 * CPubKey::COMPRESSED_SIZE + CSHA256::OUTPUT_SIZE + 1) {
888 [ + - ]: 34 : throw std::ios_base::failure("Input musig2 partial sig key is not expected size of 67 or 99 bytes");
889 : : }
890 : 3865 : CPubKey agg_pub, part_pub;
891 : 3865 : uint256 leaf_hash;
892 [ + + ]: 3865 : DeserializeMuSig2ParticipantDataIdentifier(skey, agg_pub, part_pub, leaf_hash);
893 : :
894 : 3836 : uint256 partial_sig;
895 [ + + ]: 3836 : UnserializeFromVector(s, partial_sig);
896 : :
897 [ + - + - ]: 3822 : m_musig2_partial_sigs[std::make_pair(agg_pub, leaf_hash)].emplace(part_pub, partial_sig);
898 : : break;
899 : : }
900 [ + + ]: 12338 : case PSBT_IN_PROPRIETARY:
901 : : {
902 [ + + ]: 12338 : PSBTProprietary this_prop;
903 : 12306 : skey >> this_prop.identifier;
904 [ + + ]: 12306 : this_prop.subtype = ReadCompactSize(skey);
905 [ + - ]: 12305 : this_prop.key = key;
906 : :
907 : 12248 : s >> this_prop.value;
908 [ + - ]: 12248 : m_proprietary.insert(this_prop);
909 : : break;
910 : 12338 : }
911 : : // Unknown stuff
912 : 75221 : default:
913 : : // Read in the value
914 [ + + ]: 75221 : std::vector<unsigned char> val_bytes;
915 : 75140 : s >> val_bytes;
916 [ + - ]: 75140 : unknown.emplace(std::move(key), std::move(val_bytes));
917 : : break;
918 : 75221 : }
919 : : }
920 : :
921 : : if (!found_sep) {
922 [ + - ]: 376 : throw std::ios_base::failure("Separator is missing at the end of an input map");
923 : : }
924 : :
925 : : // Make sure required PSBTv2 fields are present
926 [ - + ]: 39526 : if (m_psbt_version >= 2) {
927 [ # # ]: 0 : if (!found_prev_txid) {
928 [ # # ]: 0 : throw std::ios_base::failure("Previous TXID is required in PSBTv2");
929 : : }
930 [ # # ]: 0 : if (!found_prev_out) {
931 [ # # ]: 0 : throw std::ios_base::failure("Previous output's index is required in PSBTv2");
932 : : }
933 : : }
934 : 39526 : }
935 : : };
936 : :
937 : : /** A structure for PSBTs which contains per output information */
938 : : class PSBTOutput
939 : : {
940 : : private:
941 : 12345 : uint32_t m_psbt_version;
942 : :
943 : : public:
944 : : CScript redeem_script;
945 : : CScript witness_script;
946 : 12345 : std::map<CPubKey, KeyOriginInfo> hd_keypaths;
947 : :
948 : : XOnlyPubKey m_tap_internal_key;
949 : 12345 : std::vector<std::tuple<uint8_t, uint8_t, std::vector<unsigned char>>> m_tap_tree;
950 : 12345 : std::map<XOnlyPubKey, std::pair<std::set<uint256>, KeyOriginInfo>> m_tap_bip32_paths;
951 : 12345 : std::map<CPubKey, std::vector<CPubKey>> m_musig2_participants;
952 : :
953 : 12345 : std::map<std::vector<unsigned char>, std::vector<unsigned char>> unknown;
954 : 12345 : std::set<PSBTProprietary> m_proprietary;
955 : :
956 : 12345 : CAmount amount;
957 : : CScript script;
958 : :
959 : : void FillSignatureData(SignatureData& sigdata) const;
960 : : void FromSignatureData(const SignatureData& sigdata);
961 : : [[nodiscard]] bool Merge(const PSBTOutput& output);
962 : 12861 : uint32_t GetVersion() const { return m_psbt_version; }
963 : :
964 : 62008 : explicit PSBTOutput(uint32_t psbt_version, CAmount amount, const CScript& script)
965 : 62008 : : m_psbt_version(psbt_version),
966 : 62008 : amount(amount),
967 : 62008 : script(script)
968 : : {
969 [ - + ]: 62008 : assert(m_psbt_version == 0 || m_psbt_version == 2);
970 : 62008 : }
971 : :
972 : : // Construct a PSBTOutput when the amount and script are expected to be serialized
973 : : template <typename Stream>
974 : 0 : explicit PSBTOutput(deserialize_type, Stream& s, uint32_t psbt_version)
975 [ # # ]: 0 : : m_psbt_version(psbt_version)
976 : : {
977 [ # # ]: 0 : assert(m_psbt_version == 2);
978 [ # # ]: 0 : Unserialize(s);
979 : 0 : }
980 : :
981 : 74070 : bool operator==(const PSBTOutput&) const = default;
[ + - + -
+ - + - +
- + - + -
+ - + - +
- + - -
+ ]
982 : :
983 : : template <typename Stream>
984 : 29524 : inline void Serialize(Stream& s) const {
985 : : // Write the redeem script
986 [ + + + + ]: 29892 : if (!redeem_script.empty()) {
987 : 1047 : SerializeToVector(s, CompactSizeWriter(PSBT_OUT_REDEEMSCRIPT));
988 : 1047 : s << redeem_script;
989 : : }
990 : :
991 : : // Write the witness script
992 [ + + + + ]: 30066 : if (!witness_script.empty()) {
993 : 1152 : SerializeToVector(s, CompactSizeWriter(PSBT_OUT_WITNESSSCRIPT));
994 : 1152 : s << witness_script;
995 : : }
996 : :
997 : : // Write any hd keypaths
998 : 29524 : SerializeHDKeypaths(s, hd_keypaths, CompactSizeWriter(PSBT_OUT_BIP32_DERIVATION));
999 : :
1000 [ - + ]: 29524 : if (m_psbt_version >= 2) {
1001 : : // Write amount and spk
1002 : 0 : SerializeToVector(s, CompactSizeWriter(PSBT_OUT_AMOUNT));
1003 : 0 : SerializeToVector(s, amount);
1004 : :
1005 : 0 : SerializeToVector(s, CompactSizeWriter(PSBT_OUT_SCRIPT));
1006 : 0 : s << script;
1007 : : }
1008 : :
1009 : : // Write proprietary things
1010 [ + + ]: 44301 : for (const auto& entry : m_proprietary) {
1011 : 14777 : s << entry.key;
1012 : 14777 : s << entry.value;
1013 : : }
1014 : :
1015 : : // Write taproot internal key
1016 [ + + ]: 59048 : if (!m_tap_internal_key.IsNull()) {
1017 : 1923 : SerializeToVector(s, PSBT_OUT_TAP_INTERNAL_KEY);
1018 [ + - ]: 3846 : s << ToByteVector(m_tap_internal_key);
1019 : : }
1020 : :
1021 : : // Write taproot tree
1022 [ + + ]: 29524 : if (!m_tap_tree.empty()) {
1023 : 1437 : SerializeToVector(s, PSBT_OUT_TAP_TREE);
1024 : 1437 : std::vector<unsigned char> value;
1025 [ + - ]: 1437 : VectorWriter s_value{value, 0};
1026 [ + - + + ]: 8552 : for (const auto& [depth, leaf_ver, script] : m_tap_tree) {
1027 [ + - ]: 7115 : s_value << depth;
1028 [ + - ]: 7115 : s_value << leaf_ver;
1029 : 7115 : s_value << script;
1030 : : }
1031 : 1437 : s << value;
1032 : 1437 : }
1033 : :
1034 : : // Write taproot bip32 keypaths
1035 [ + + ]: 33775 : for (const auto& [xonly, leaf] : m_tap_bip32_paths) {
1036 : 4251 : const auto& [leaf_hashes, origin] = leaf;
1037 : 4251 : SerializeToVector(s, PSBT_OUT_TAP_BIP32_DERIVATION, xonly);
1038 : 4251 : std::vector<unsigned char> value;
1039 [ + - ]: 4251 : VectorWriter s_value{value, 0};
1040 [ + - ]: 4251 : s_value << leaf_hashes;
1041 [ + - + - ]: 8502 : SerializeKeyOrigin(s_value, origin);
1042 : 4251 : s << value;
1043 : : }
1044 : :
1045 : : // Write MuSig2 Participants
1046 [ + + ]: 32169 : for (const auto& [agg_pubkey, part_pubs] : m_musig2_participants) {
1047 : 2645 : SerializeToVector(s, CompactSizeWriter(PSBT_OUT_MUSIG2_PARTICIPANT_PUBKEYS), std::span{agg_pubkey});
1048 : 2645 : std::vector<unsigned char> value;
1049 [ + - ]: 2645 : VectorWriter s_value{value, 0};
1050 [ + - + + ]: 3256 : for (auto& pk : part_pubs) {
1051 [ + - ]: 1222 : s_value << std::span{pk};
1052 : : }
1053 : 2645 : s << value;
1054 : : }
1055 : :
1056 : : // Write unknown things
1057 [ + + ]: 61729 : for (auto& entry : unknown) {
1058 : 32205 : s << entry.first;
1059 : 32205 : s << entry.second;
1060 : : }
1061 : :
1062 : 29524 : s << PSBT_SEPARATOR;
1063 : 29524 : }
1064 : :
1065 : :
1066 : : template <typename Stream>
1067 : 44052 : inline void Unserialize(Stream& s) {
1068 : : // Used for duplicate key detection
1069 : 44052 : std::set<std::vector<unsigned char>> key_lookup;
1070 : : // Cache whether PSBTv2 required fields are found
1071 : 44052 : bool found_amount = false;
1072 : 44052 : bool found_script = false;
1073 : :
1074 : : // Read loop
1075 : 44052 : bool found_sep = false;
1076 [ + + ]: 186972 : while(!s.empty()) {
1077 : : // Read the key of format "<keylen><keytype><keydata>" after which
1078 : : // "key" will contain "<keytype><keydata>"
1079 [ + + ]: 184314 : std::vector<unsigned char> key;
1080 : 183911 : s >> key;
1081 : :
1082 : : // the key is empty if that was actually a separator byte
1083 : : // This is a special case for key lengths 0 as those are not allowed (except for separator)
1084 [ + + ]: 183911 : if (key.empty()) {
1085 : 41394 : found_sep = true;
1086 : : break;
1087 : : }
1088 : :
1089 : : // Duplicate keys are not permitted
1090 [ + - + + ]: 142517 : if (!key_lookup.emplace(key).second) {
1091 [ - + + - : 230 : throw std::ios_base::failure(tfm::format("Duplicate Key, output key \"%s\" already provided", HexStr(key)));
+ - + - ]
1092 : : }
1093 : :
1094 : : // "skey" is used so that "key" is unchanged after reading keytype below
1095 : 142402 : SpanReader skey{key};
1096 : : // keytype is of the format compact size uint at the beginning of "key"
1097 [ + + ]: 142402 : uint64_t type = ReadCompactSize(skey);
1098 : :
1099 : : // Do stuff based on keytype "type", i.e., key checks, reading values of the
1100 : : // format "<valuelen><valuedata>" from the stream "s", and value checks
1101 : 142394 : switch(type) {
[ + + + +
+ + + + +
+ + ]
1102 : 3223 : case PSBT_OUT_REDEEMSCRIPT:
1103 : : {
1104 [ + - + + ]: 3266 : ExpectedKeySize("Output redeemScript", key, 1);
1105 [ + + ]: 3180 : s >> redeem_script;
1106 : : break;
1107 : : }
1108 : 3237 : case PSBT_OUT_WITNESSSCRIPT:
1109 : : {
1110 [ + - + + ]: 3255 : ExpectedKeySize("Output witnessScript", key, 1);
1111 [ + + ]: 3219 : s >> witness_script;
1112 : : break;
1113 : : }
1114 : 20498 : case PSBT_OUT_BIP32_DERIVATION:
1115 : : {
1116 [ + + ]: 20498 : DeserializeHDKeypaths(s, key, hd_keypaths);
1117 : : break;
1118 : : }
1119 : 269 : case PSBT_OUT_AMOUNT:
1120 : : {
1121 [ + - + + ]: 474 : ExpectedKeySize("Output Amount", key, 1);
1122 [ + - ]: 64 : if (m_psbt_version < 2) {
1123 [ + - ]: 128 : throw std::ios_base::failure("Output amount is not allowed in PSBTv0");
1124 : : }
1125 [ # # ]: 0 : UnserializeFromVector(s, amount);
1126 : : found_amount = true;
1127 : : break;
1128 : : }
1129 : 222 : case PSBT_OUT_SCRIPT:
1130 : : {
1131 [ + - + + ]: 410 : ExpectedKeySize("Output Script", key, 1);
1132 [ + - ]: 34 : if (m_psbt_version < 2) {
1133 [ + - ]: 68 : throw std::ios_base::failure("Output script is not allowed in PSBTv0");
1134 : : }
1135 [ - - ]: 140368 : s >> script;
1136 : : found_script = true;
1137 : : break;
1138 : : }
1139 : 2281 : case PSBT_OUT_TAP_INTERNAL_KEY:
1140 : : {
1141 [ + - + + ]: 2302 : ExpectedKeySize("Output Taproot Internal Key", key, 1);
1142 [ + + ]: 2260 : UnserializeFromVector(s, m_tap_internal_key);
1143 : : break;
1144 : : }
1145 : 3421 : case PSBT_OUT_TAP_TREE:
1146 : : {
1147 [ + - + + ]: 3440 : ExpectedKeySize("Output Taproot Tree Key", key, 1);
1148 [ + + ]: 3402 : std::vector<unsigned char> tree_v;
1149 [ - + ]: 3371 : s >> tree_v;
1150 [ + + ]: 3371 : SpanReader s_tree{tree_v};
1151 [ + + ]: 3371 : if (s_tree.empty()) {
1152 [ + - ]: 32 : throw std::ios_base::failure("Output Taproot tree must not be empty");
1153 : : }
1154 : 3355 : TaprootBuilder builder;
1155 [ + + ]: 240703 : while (!s_tree.empty()) {
1156 : : uint8_t depth;
1157 : : uint8_t leaf_ver;
1158 [ + - ]: 237348 : std::vector<unsigned char> script;
1159 [ + + ]: 237348 : s_tree >> depth;
1160 [ + + ]: 237279 : s_tree >> leaf_ver;
1161 : 237004 : s_tree >> script;
1162 [ + + ]: 237004 : if (depth > TAPROOT_CONTROL_MAX_NODE_COUNT) {
1163 [ + - ]: 96 : throw std::ios_base::failure("Output Taproot tree has as leaf greater than Taproot maximum depth");
1164 : : }
1165 [ + + ]: 236956 : if ((leaf_ver & ~TAPROOT_LEAF_MASK) != 0) {
1166 [ + - ]: 128 : throw std::ios_base::failure("Output Taproot tree has a leaf with an invalid leaf version");
1167 : : }
1168 [ + - ]: 236892 : m_tap_tree.emplace_back(depth, leaf_ver, script);
1169 [ - + + - ]: 236892 : builder.Add((int)depth, script, (int)leaf_ver, /*track=*/true);
1170 : : }
1171 [ + + ]: 2899 : if (!builder.IsComplete()) {
1172 [ + - ]: 228 : throw std::ios_base::failure("Output Taproot tree is malformed");
1173 : : }
1174 : : break;
1175 : 3972 : }
1176 : 8471 : case PSBT_OUT_TAP_BIP32_DERIVATION:
1177 : : {
1178 [ + - + + : 16942 : ExpectedKeySize("Output Taproot BIP32 Keypath", key, 33);
- + ]
1179 [ + + ]: 8445 : XOnlyPubKey xonly(uint256(std::span<uint8_t>(key).last(32)));
1180 : 8445 : std::set<uint256> leaf_hashes;
1181 [ + + + + ]: 8445 : uint64_t value_len = ReadCompactSize(s);
1182 [ + + ]: 8431 : size_t before_hashes = s.size();
1183 [ + + ]: 8267 : s >> leaf_hashes;
1184 : 8267 : size_t after_hashes = s.size();
1185 : 8267 : size_t hashes_len = before_hashes - after_hashes;
1186 [ + + ]: 8267 : if (hashes_len > value_len) {
1187 [ + - ]: 36 : throw std::ios_base::failure("Output Taproot BIP32 keypath has an invalid length");
1188 : : }
1189 : 8249 : size_t origin_len = value_len - hashes_len;
1190 [ + + + - ]: 16470 : m_tap_bip32_paths.emplace(xonly, std::make_pair(leaf_hashes, DeserializeKeyOrigin(s, origin_len)));
1191 : : break;
1192 : 8445 : }
1193 : 6568 : case PSBT_OUT_MUSIG2_PARTICIPANT_PUBKEYS:
1194 : : {
1195 [ + - + + ]: 6592 : ExpectedKeySize("Output MuSig2 Participants Pubkeys", key, CPubKey::COMPRESSED_SIZE + 1);
1196 [ + - + + ]: 13088 : DeserializeMuSig2ParticipantPubkeys(s, skey, m_musig2_participants, std::string{"Output"});
1197 : : break;
1198 : : }
1199 [ + + ]: 26844 : case PSBT_OUT_PROPRIETARY:
1200 : : {
1201 [ + + ]: 26844 : PSBTProprietary this_prop;
1202 : 26816 : skey >> this_prop.identifier;
1203 [ + + ]: 26816 : this_prop.subtype = ReadCompactSize(skey);
1204 [ + - ]: 26815 : this_prop.key = key;
1205 : :
1206 : 26755 : s >> this_prop.value;
1207 [ + - ]: 26755 : m_proprietary.insert(this_prop);
1208 : : break;
1209 : 26844 : }
1210 : : // Unknown stuff
1211 : 67360 : default: {
1212 : : // Read in the value
1213 [ + + ]: 67360 : std::vector<unsigned char> val_bytes;
1214 : 67246 : s >> val_bytes;
1215 [ + - ]: 67246 : unknown.emplace(std::move(key), std::move(val_bytes));
1216 : : break;
1217 : 67360 : }
1218 : : }
1219 : : }
1220 : :
1221 : : if (!found_sep) {
1222 [ + - ]: 212 : throw std::ios_base::failure("Separator is missing at the end of an output map");
1223 : : }
1224 : :
1225 : : // Make sure required PSBTv2 fields are present
1226 [ - + ]: 41394 : if (m_psbt_version >= 2) {
1227 [ # # ]: 0 : if (!found_amount) {
1228 [ # # ]: 0 : throw std::ios_base::failure("Output amount is required in PSBTv2");
1229 : : }
1230 [ # # ]: 0 : if (!found_script) {
1231 [ # # ]: 0 : throw std::ios_base::failure("Output script is required in PSBTv2");
1232 : : }
1233 : : }
1234 : 41394 : }
1235 : : };
1236 : :
1237 : : /** A version of CTransaction with the PSBT format*/
1238 : : class PartiallySignedTransaction
1239 : : {
1240 : : private:
1241 : : std::optional<uint32_t> m_version;
1242 : :
1243 : : public:
1244 : : // We use a vector of CExtPubKey in the event that there happens to be the same KeyOriginInfos for different CExtPubKeys
1245 : : // Note that this map swaps the key and values from the serialization
1246 : : std::map<KeyOriginInfo, std::set<CExtPubKey>> m_xpubs;
1247 : : std::optional<std::bitset<8>> m_tx_modifiable;
1248 : : std::vector<PSBTInput> inputs;
1249 : : std::vector<PSBTOutput> outputs;
1250 : : std::map<std::vector<unsigned char>, std::vector<unsigned char>> unknown;
1251 : : std::set<PSBTProprietary> m_proprietary;
1252 : :
1253 : : uint32_t tx_version;
1254 : : std::optional<uint32_t> fallback_locktime;
1255 : :
1256 : : uint32_t GetVersion() const;
1257 : :
1258 : : /** Merge psbt into this. The two psbts must have the same underlying CTransaction (i.e. the
1259 : : * same actual Bitcoin transaction.) Returns true if the merge succeeded, false otherwise. */
1260 : : [[nodiscard]] bool Merge(const PartiallySignedTransaction& psbt);
1261 : : /** Merge the global xpubs of psbt into this, keeping the existing origin for an xpub
1262 : : * seen again with a different one, as the serialized records are keyed by xpub. */
1263 : : void MergeGlobalXPubs(const PartiallySignedTransaction& psbt);
1264 : : bool AddInput(const PSBTInput& psbtin);
1265 : : bool AddOutput(const PSBTOutput& psbtout);
1266 : : std::optional<uint32_t> ComputeTimeLock() const;
1267 : : std::optional<CMutableTransaction> GetUnsignedTx() const;
1268 : : std::optional<Txid> GetUniqueID() const;
1269 : : explicit PartiallySignedTransaction(const CMutableTransaction& tx, uint32_t version = 2);
1270 : :
1271 : : template <typename Stream>
1272 : 16008 : inline void Serialize(Stream& s) const {
1273 : :
1274 : : // magic bytes
1275 : 16008 : s << PSBT_MAGIC_BYTES;
1276 : :
1277 [ + + ]: 16008 : if (GetVersion() < 2) {
1278 : : // unsigned tx flag
1279 : 16005 : SerializeToVector(s, CompactSizeWriter(PSBT_GLOBAL_UNSIGNED_TX));
1280 : :
1281 : : // Write serialized tx to a stream
1282 [ + - ]: 32010 : SerializeToVector(s, TX_NO_WITNESS(*GetUnsignedTx()));
1283 : : }
1284 : :
1285 : : // Write xpubs
1286 [ + + ]: 19675 : for (const auto& xpub_pair : m_xpubs) {
1287 [ + + ]: 8240 : for (const auto& xpub : xpub_pair.second) {
1288 : : unsigned char ser_xpub[BIP32_EXTKEY_WITH_VERSION_SIZE];
1289 : 4573 : xpub.EncodeWithVersion(ser_xpub);
1290 : : // Note that the serialization swaps the key and value
1291 : : // The xpub is the key (for uniqueness) while the path is the value
1292 : 4573 : SerializeToVector(s, PSBT_GLOBAL_XPUB, ser_xpub);
1293 [ + - ]: 9146 : SerializeHDKeypath(s, xpub_pair.first);
1294 : : }
1295 : : }
1296 : :
1297 [ + + ]: 16008 : if (GetVersion() >= 2) {
1298 : : // Write PSBTv2 tx version, locktime, counts, etc.
1299 : 3 : SerializeToVector(s, CompactSizeWriter(PSBT_GLOBAL_TX_VERSION));
1300 : 3 : SerializeToVector(s, tx_version);
1301 [ + - ]: 3 : if (fallback_locktime != std::nullopt) {
1302 : 3 : SerializeToVector(s, CompactSizeWriter(PSBT_GLOBAL_FALLBACK_LOCKTIME));
1303 : 3 : SerializeToVector(s, *fallback_locktime);
1304 : : }
1305 : :
1306 : 3 : SerializeToVector(s, CompactSizeWriter(PSBT_GLOBAL_INPUT_COUNT));
1307 [ - + ]: 3 : SerializeToVector(s, CompactSizeWriter(inputs.size()));
1308 : 3 : SerializeToVector(s, CompactSizeWriter(PSBT_GLOBAL_OUTPUT_COUNT));
1309 [ - + ]: 3 : SerializeToVector(s, CompactSizeWriter(outputs.size()));
1310 : :
1311 [ - + ]: 3 : if (m_tx_modifiable != std::nullopt) {
1312 : 0 : SerializeToVector(s, CompactSizeWriter(PSBT_GLOBAL_TX_MODIFIABLE));
1313 : 0 : SerializeToVector(s, static_cast<uint8_t>(m_tx_modifiable->to_ulong()));
1314 : : }
1315 : : }
1316 : :
1317 : : // PSBT version
1318 [ + + ]: 16008 : if (GetVersion() > 0) {
1319 : 3 : SerializeToVector(s, CompactSizeWriter(PSBT_GLOBAL_VERSION));
1320 : 3 : SerializeToVector(s, *m_version);
1321 : : }
1322 : :
1323 : : // Write proprietary things
1324 [ + + ]: 19558 : for (const auto& entry : m_proprietary) {
1325 : 3550 : s << entry.key;
1326 : 3550 : s << entry.value;
1327 : : }
1328 : :
1329 : : // Write the unknown things
1330 [ + + ]: 24836 : for (auto& entry : unknown) {
1331 : 8828 : s << entry.first;
1332 : 8828 : s << entry.second;
1333 : : }
1334 : :
1335 : : // Separator
1336 : 16008 : s << PSBT_SEPARATOR;
1337 : :
1338 : : // Write inputs
1339 [ + + ]: 43631 : for (const PSBTInput& input : inputs) {
1340 : 27623 : s << input;
1341 : : }
1342 : : // Write outputs
1343 [ + + ]: 45207 : for (const PSBTOutput& output : outputs) {
1344 : 29199 : s << output;
1345 : : }
1346 : 16008 : }
1347 : :
1348 : :
1349 : : template <typename Stream>
1350 : 41228 : inline void Unserialize(Stream& s) {
1351 : : // Read the magic bytes
1352 : : uint8_t magic[5];
1353 : 36715 : s >> magic;
1354 [ + + ]: 36715 : if (!std::equal(magic, magic + 5, PSBT_MAGIC_BYTES)) {
1355 [ + - ]: 3594 : throw std::ios_base::failure("Invalid PSBT magic bytes");
1356 : : }
1357 : :
1358 : : // Used for duplicate key detection
1359 : 34918 : std::set<std::vector<unsigned char>> key_lookup;
1360 : :
1361 : : // Read global data
1362 : 34918 : bool found_sep = false;
1363 : 34918 : std::optional<CMutableTransaction> tx;
1364 : 34918 : uint64_t input_count = 0;
1365 : 34918 : uint64_t output_count = 0;
1366 : 34918 : bool found_input_count = false;
1367 : 34918 : bool found_output_count = false;
1368 : 34918 : bool found_tx_version = false;
1369 : 34918 : bool found_fallback_locktime = false;
1370 [ + + ]: 115913 : while(!s.empty()) {
1371 : : // Read the key of format "<keylen><keytype><keydata>" after which
1372 : : // "key" will contain "<keytype><keydata>"
1373 [ + + ]: 113391 : std::vector<unsigned char> key;
1374 : 113157 : s >> key;
1375 : :
1376 : : // the key is empty if that was actually a separator byte
1377 : : // This is a special case for key lengths 0 as those are not allowed (except for separator)
1378 [ + + ]: 113157 : if (key.empty()) {
1379 : 32396 : found_sep = true;
1380 : : break;
1381 : : }
1382 : :
1383 : : // Duplicate keys are not permitted
1384 [ + - + + ]: 80761 : if (!key_lookup.emplace(key).second) {
1385 [ - + + - : 104 : throw std::ios_base::failure(tfm::format("Duplicate Key, global key \"%s\" already provided", HexStr(key)));
+ - + - ]
1386 : : }
1387 : :
1388 : : // "skey" is used so that "key" is unchanged after reading keytype below
1389 : 80709 : SpanReader skey{key};
1390 : : // keytype is of the format compact size uint at the beginning of "key"
1391 [ + + ]: 80709 : uint64_t type = ReadCompactSize(skey);
1392 : :
1393 : : // Do stuff based on keytype "type", i.e., key checks, reading values of the
1394 : : // format "<valuelen><valuedata>" from the stream "s", and value checks
1395 [ + + + + : 80694 : switch(type) {
+ + + + +
+ ]
1396 : 33667 : case PSBT_GLOBAL_UNSIGNED_TX:
1397 : : {
1398 [ + - + + ]: 33680 : ExpectedKeySize("Global Unsigned TX", key, 1);
1399 : : // Set the stream to serialize with non-witness since this should always be non-witness
1400 [ + - ]: 33654 : tx.emplace();
1401 [ + + ]: 33654 : UnserializeFromVector(s, TX_NO_WITNESS(*tx));
1402 : : // Make sure that all scriptSigs and scriptWitnesses are empty
1403 [ + + ]: 78442 : for (const CTxIn& txin : tx->vin) {
1404 [ + + + + : 45401 : if (!txin.scriptSig.empty() || !txin.scriptWitness.IsNull()) {
- + ]
1405 [ + - ]: 38 : throw std::ios_base::failure("Unsigned tx does not have empty scriptSigs and scriptWitnesses.");
1406 : : }
1407 : : }
1408 : 33052 : tx_version = tx->version;
1409 [ - + ]: 33052 : fallback_locktime = tx->nLockTime;
1410 : : // Set the input and output counts
1411 [ - + - + ]: 33052 : input_count = tx->vin.size();
1412 [ - + ]: 33052 : output_count = tx->vout.size();
1413 : 33052 : break;
1414 : : }
1415 : 455 : case PSBT_GLOBAL_TX_VERSION:
1416 : : {
1417 [ + - + + ]: 874 : ExpectedKeySize("Global Transaction Version", key, 1);
1418 [ + + ]: 36 : UnserializeFromVector(s, tx_version);
1419 : : found_tx_version = true;
1420 : : break;
1421 : : }
1422 : 395 : case PSBT_GLOBAL_FALLBACK_LOCKTIME:
1423 : : {
1424 [ + - + + ]: 725 : ExpectedKeySize("Global Fallback Locktime", key, 1);
1425 [ + + ]: 65 : fallback_locktime.emplace();
1426 [ + + ]: 65 : UnserializeFromVector(s, *fallback_locktime);
1427 : : found_fallback_locktime = true;
1428 : : break;
1429 : : }
1430 : 152 : case PSBT_GLOBAL_INPUT_COUNT:
1431 : : {
1432 [ + - + + : 304 : ExpectedKeySize("Global Input Count", key, 1);
+ + ]
1433 : 46 : CompactSizeReader reader(input_count);
1434 [ + + ]: 46 : UnserializeFromVector(s, reader);
1435 : : found_input_count = true;
1436 : : break;
1437 : : }
1438 : 64 : case PSBT_GLOBAL_OUTPUT_COUNT:
1439 : : {
1440 [ + - + + : 128 : ExpectedKeySize("Global Output Count", key, 1);
+ + ]
1441 : 30 : CompactSizeReader reader(output_count);
1442 [ + + ]: 30 : UnserializeFromVector(s, reader);
1443 : : found_output_count = true;
1444 : : break;
1445 : : }
1446 : 109 : case PSBT_GLOBAL_TX_MODIFIABLE:
1447 : : {
1448 [ + - + + ]: 184 : ExpectedKeySize("Global TX Modifiable Flags", key, 1);
1449 : : uint8_t tx_mod;
1450 [ + + ]: 34 : UnserializeFromVector(s, tx_mod);
1451 [ - + ]: 18 : m_tx_modifiable.emplace(tx_mod);
1452 : : break;
1453 : : }
1454 : 15814 : case PSBT_GLOBAL_XPUB:
1455 : : {
1456 [ + - + + : 31628 : ExpectedKeySize("Global XPUB", key, BIP32_EXTKEY_WITH_VERSION_SIZE + 1);
+ - ]
1457 : : // Read in the xpub from key
1458 [ + - ]: 15771 : CExtPubKey xpub;
1459 [ + - ]: 15771 : xpub.DecodeWithVersion(&key.data()[1]);
1460 [ + - + + ]: 15771 : if (!xpub.pubkey.IsFullyValid()) {
1461 [ + - ]: 166 : throw std::ios_base::failure("Invalid pubkey");
1462 : : }
1463 : : // Read in the keypath from stream
1464 : 15688 : KeyOriginInfo keypath;
1465 [ + + ]: 15688 : DeserializeHDKeypath(s, keypath);
1466 : :
1467 : : // Note that we store these swapped to make searches faster.
1468 : : // Serialization uses xpub -> keypath to enqure key uniqueness
1469 [ + + ]: 15607 : if (!m_xpubs.contains(keypath)) {
1470 : : // Make a new set to put the xpub in
1471 [ + - + + : 38451 : m_xpubs[keypath] = {xpub};
- - ]
1472 : : } else {
1473 : : // Insert xpub into existing set
1474 [ + - + - ]: 2790 : m_xpubs[keypath].insert(xpub);
1475 : : }
1476 : : break;
1477 : 15852 : }
1478 : 86 : case PSBT_GLOBAL_VERSION:
1479 : : {
1480 [ + - + + ]: 98 : ExpectedKeySize("Global PSBT Version", key, 1);
1481 : : uint32_t v;
1482 [ + + ]: 74 : UnserializeFromVector(s, v);
1483 : 63 : m_version = v;
1484 [ + + ]: 63 : if (*m_version > PSBT_HIGHEST_VERSION) {
1485 [ + - ]: 30 : throw std::ios_base::failure("Unsupported version number");
1486 : : }
1487 : : break;
1488 : : }
1489 [ + + ]: 8480 : case PSBT_GLOBAL_PROPRIETARY:
1490 : : {
1491 [ + + ]: 8480 : PSBTProprietary this_prop;
1492 : 8458 : skey >> this_prop.identifier;
1493 [ + + ]: 8458 : this_prop.subtype = ReadCompactSize(skey);
1494 [ + - ]: 8457 : this_prop.key = key;
1495 : :
1496 : 8403 : s >> this_prop.value;
1497 [ + - ]: 8403 : m_proprietary.insert(this_prop);
1498 : : break;
1499 : 8480 : }
1500 : : // Unknown stuff
1501 : 21472 : default: {
1502 : : // Read in the value
1503 [ + + ]: 21472 : std::vector<unsigned char> val_bytes;
1504 : 21388 : s >> val_bytes;
1505 [ + - ]: 21388 : unknown.emplace(std::move(key), std::move(val_bytes));
1506 : 21472 : }
1507 : : }
1508 : : }
1509 : :
1510 : : if (!found_sep) {
1511 [ + - ]: 192 : throw std::ios_base::failure("Separator is missing at the end of the global map");
1512 : : }
1513 : :
1514 [ + - ]: 32396 : const uint32_t psbt_ver = GetVersion();
1515 : :
1516 : : // Check PSBT version constraints
1517 [ + + ]: 32396 : if (psbt_ver == 0) {
1518 : : // Make sure that we got an unsigned tx for PSBTv0
1519 [ + + ]: 32381 : if (!tx) {
1520 [ + - ]: 136 : throw std::ios_base::failure("No unsigned transaction was provided");
1521 : : }
1522 : : // Make sure no PSBTv2 fields are present
1523 [ + + ]: 32313 : if (found_tx_version) {
1524 [ + - ]: 10 : throw std::ios_base::failure("PSBT_GLOBAL_TX_VERSION is not allowed in PSBTv0");
1525 : : }
1526 [ + + ]: 32308 : if (found_fallback_locktime) {
1527 [ + - ]: 12 : throw std::ios_base::failure("PSBT_GLOBAL_FALLBACK_LOCKTIME is not allowed in PSBTv0");
1528 : : }
1529 [ + + ]: 32302 : if (found_input_count) {
1530 [ + - ]: 20 : throw std::ios_base::failure("PSBT_GLOBAL_INPUT_COUNT is not allowed in PSBTv0");
1531 : : }
1532 [ + + ]: 32292 : if (found_output_count) {
1533 [ + - ]: 14 : throw std::ios_base::failure("PSBT_GLOBAL_OUTPUT_COUNT is not allowed in PSBTv0");
1534 : : }
1535 [ + + ]: 32285 : if (m_tx_modifiable != std::nullopt) {
1536 [ + - ]: 12 : throw std::ios_base::failure("PSBT_GLOBAL_TX_MODIFIABLE is not allowed in PSBTv0");
1537 : : }
1538 : : }
1539 : : // Disallow v1
1540 [ + + ]: 32294 : if (psbt_ver == 1) {
1541 [ + - ]: 10 : throw std::ios_base::failure("There is no PSBT version 1");
1542 : : }
1543 [ + + ]: 32289 : if (psbt_ver == 2) {
1544 : : // Tx version, input, and output counts are required
1545 [ + + ]: 10 : if (!found_tx_version) {
1546 [ + - ]: 10 : throw std::ios_base::failure("PSBT_GLOBAL_TX_VERSION is required in PSBTv2");
1547 : : }
1548 [ + + ]: 5 : if (!found_input_count) {
1549 [ + - ]: 8 : throw std::ios_base::failure("PSBT_GLOBAL_INPUT_COUNT is required in PSBTv2");
1550 : : }
1551 [ + - ]: 1 : if (!found_output_count) {
1552 [ + - ]: 2 : throw std::ios_base::failure("PSBT_GLOBAL_OUTPUT_COUNT is required in PSBTv2");
1553 : : }
1554 : : // Unsigned tx is disallowed
1555 [ # # ]: 0 : if (tx) {
1556 [ # # ]: 0 : throw std::ios_base::failure("PSBT_GLOBAL_UNSIGNED_TX is not allowed in PSBTv2");
1557 : : }
1558 : : }
1559 [ - + ]: 32279 : if (psbt_ver > 2) {
1560 [ # # ]: 0 : throw std::ios_base::failure("Unknown PSBT version");
1561 : : }
1562 : :
1563 : : // Read input data
1564 : : unsigned int i = 0;
1565 [ + + + + ]: 70980 : while (!s.empty() && i < input_count) {
1566 [ + - ]: 42770 : if (psbt_ver < 2) {
1567 [ + - ]: 42770 : inputs.emplace_back(psbt_ver, tx->vin[i].prevout.hash, tx->vin[i].prevout.n, tx->vin[i].nSequence);
1568 [ + + ]: 42770 : s >> inputs.back();
1569 : : } else {
1570 [ # # ]: 0 : inputs.emplace_back(deserialize, s, psbt_ver);
1571 : : }
1572 : :
1573 : : // Make sure the non-witness utxo matches the outpoint
1574 : 38846 : const PSBTInput& input = inputs.back();
1575 [ + + ]: 38846 : if (input.non_witness_utxo) {
1576 [ + - ]: 837 : if (psbt_ver < 2) {
1577 [ + + - + ]: 837 : if (input.non_witness_utxo->GetHash() != tx->vin[i].prevout.hash) {
1578 [ + - ]: 270 : throw std::ios_base::failure("Non-witness UTXO does not match outpoint hash");
1579 : : }
1580 [ - + + + ]: 702 : if (tx->vin[i].prevout.n >= input.non_witness_utxo->vout.size()) {
1581 [ + - ]: 20 : throw std::ios_base::failure("Input specifies output index that does not exist");
1582 : : }
1583 : : } else {
1584 [ # # ]: 0 : if (input.non_witness_utxo->GetHash() != input.prev_txid) {
1585 [ # # ]: 0 : throw std::ios_base::failure("Non-witness UTXO does not match outpoint hash");
1586 : : }
1587 [ # # # # ]: 0 : if (input.prev_out >= input.non_witness_utxo->vout.size()) {
1588 [ # # ]: 0 : throw std::ios_base::failure("Input specifies output index that does not exist");
1589 : : }
1590 : : }
1591 : : }
1592 : 38701 : ++i;
1593 : : }
1594 : : // Make sure that the number of inputs matches the number of inputs in the transaction
1595 [ - + + + ]: 28210 : if (inputs.size() != input_count) {
1596 [ + - ]: 126 : throw std::ios_base::failure("Inputs provided does not match the number of inputs in transaction.");
1597 : : }
1598 : :
1599 : : // Read output data
1600 : : i = 0;
1601 [ + + + + ]: 69216 : while (!s.empty() && i < output_count) {
1602 [ + - ]: 43151 : if (psbt_ver < 2) {
1603 [ + - ]: 43151 : outputs.emplace_back(psbt_ver, tx->vout[i].nValue, tx->vout[i].scriptPubKey);
1604 [ + + ]: 43151 : s >> outputs.back();
1605 : : } else {
1606 [ # # ]: 0 : outputs.emplace_back(deserialize, s, psbt_ver);
1607 : : }
1608 : 41069 : ++i;
1609 : : }
1610 : : // Make sure that the number of outputs matches the number of outputs in the transaction
1611 [ - + + + ]: 26065 : if (outputs.size() != output_count) {
1612 [ + - ]: 190 : throw std::ios_base::failure("Outputs provided does not match the number of outputs in transaction.");
1613 : : }
1614 [ + - ]: 47735 : }
1615 : :
1616 : : template <typename Stream>
1617 [ + + ]: 41228 : PartiallySignedTransaction(deserialize_type, Stream& s) {
1618 [ + + ]: 41228 : Unserialize(s);
1619 : 71744 : }
1620 : : };
1621 : :
1622 : : enum class PSBTRole {
1623 : : CREATOR,
1624 : : UPDATER,
1625 : : SIGNER,
1626 : : FINALIZER,
1627 : : EXTRACTOR
1628 : : };
1629 : :
1630 : : std::string PSBTRoleName(PSBTRole role);
1631 : :
1632 : : /** Compute a PrecomputedTransactionData object from a psbt. */
1633 : : std::optional<PrecomputedTransactionData> PrecomputePSBTData(const PartiallySignedTransaction& psbt);
1634 : :
1635 : : /** Checks whether a PSBTInput is already signed by checking for non-null finalized fields. */
1636 : : bool PSBTInputSigned(const PSBTInput& input);
1637 : :
1638 : : /** Checks whether a PSBTInput is already signed by doing script verification using final fields. */
1639 : : bool PSBTInputSignedAndVerified(const PartiallySignedTransaction& psbt, unsigned int input_index, const PrecomputedTransactionData* txdata);
1640 : :
1641 : : /** Signs a PSBTInput, verifying that all provided data matches what is being signed.
1642 : : *
1643 : : * txdata should be the output of PrecomputePSBTData (which can be shared across
1644 : : * multiple SignPSBTInput calls). If it is nullptr, a dummy signature will be created.
1645 : : **/
1646 : : [[nodiscard]] util::Expected<void, PSBTError> SignPSBTInput(const SigningProvider& provider, PartiallySignedTransaction& psbt, int index, const PrecomputedTransactionData* txdata, const common::PSBTFillOptions& options, SignatureData* out_sigdata = nullptr);
1647 : :
1648 : : /** Reduces the size of the PSBT by dropping unnecessary `non_witness_utxos` (i.e. complete previous transactions) from a psbt when all inputs are segwit v1. */
1649 : : void RemoveUnnecessaryTransactions(PartiallySignedTransaction& psbtx);
1650 : :
1651 : : /** Counts the unsigned inputs of a PSBT. */
1652 : : size_t CountPSBTUnsignedInputs(const PartiallySignedTransaction& psbt);
1653 : :
1654 : : /** Updates a PSBTOutput with information from provider.
1655 : : *
1656 : : * This fills in the redeem_script, witness_script, and hd_keypaths where possible.
1657 : : */
1658 : : void UpdatePSBTOutput(const SigningProvider& provider, PartiallySignedTransaction& psbt, int index);
1659 : :
1660 : : /**
1661 : : * Finalizes a PSBT if possible, combining partial signatures.
1662 : : *
1663 : : * @param[in,out] psbtx PartiallySignedTransaction to finalize
1664 : : * return True if the PSBT is now complete, false otherwise
1665 : : */
1666 : : bool FinalizePSBT(PartiallySignedTransaction& psbtx);
1667 : :
1668 : : /**
1669 : : * Finalizes a PSBT if possible, and extracts it to a CMutableTransaction if it could be finalized.
1670 : : *
1671 : : * @param[in] psbtx PartiallySignedTransaction
1672 : : * @param[out] result CMutableTransaction representing the complete transaction, if successful
1673 : : * @return True if we successfully extracted the transaction, false otherwise
1674 : : */
1675 : : bool FinalizeAndExtractPSBT(PartiallySignedTransaction& psbtx, CMutableTransaction& result);
1676 : :
1677 : : /**
1678 : : * Combines PSBTs with the same underlying transaction, resulting in a single PSBT with all partial signatures from each input.
1679 : : *
1680 : : * @param[in] psbtxs the PSBTs to combine
1681 : : * @return The combined PSBT or std::nullopt if the PSBTs cannot be combined
1682 : : */
1683 : : [[nodiscard]] std::optional<PartiallySignedTransaction> CombinePSBTs(const std::vector<PartiallySignedTransaction>& psbtxs);
1684 : :
1685 : : //! Decode a base64ed PSBT into a PartiallySignedTransaction
1686 : : [[nodiscard]] util::Result<PartiallySignedTransaction> DecodeBase64PSBT(const std::string& base64_tx);
1687 : : //! Decode a raw (binary blob) PSBT into a PartiallySignedTransaction
1688 : : [[nodiscard]] util::Result<PartiallySignedTransaction> DecodeRawPSBT(std::span<const std::byte> tx_data);
1689 : :
1690 : : #endif // BITCOIN_PSBT_H
|