Bitcoin Core Fuzz Coverage Report

Coverage Report

Created: 2026-03-24 13:57

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/root/bitcoin/src/script/script.cpp
Line
Count
Source
1
// Copyright (c) 2009-2010 Satoshi Nakamoto
2
// Copyright (c) 2009-present The Bitcoin Core developers
3
// Distributed under the MIT software license, see the accompanying
4
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
5
6
#include <script/script.h>
7
8
#include <crypto/common.h>
9
#include <crypto/hex_base.h>
10
#include <hash.h>
11
#include <uint256.h>
12
#include <util/hash_type.h>
13
14
#include <string>
15
16
0
CScriptID::CScriptID(const CScript& in) : BaseHash(Hash160(in)) {}
17
18
std::string GetOpName(opcodetype opcode)
19
0
{
20
0
    switch (opcode)
21
0
    {
22
    // push value
23
0
    case OP_0                      : return "0";
24
0
    case OP_PUSHDATA1              : return "OP_PUSHDATA1";
25
0
    case OP_PUSHDATA2              : return "OP_PUSHDATA2";
26
0
    case OP_PUSHDATA4              : return "OP_PUSHDATA4";
27
0
    case OP_1NEGATE                : return "-1";
28
0
    case OP_RESERVED               : return "OP_RESERVED";
29
0
    case OP_1                      : return "1";
30
0
    case OP_2                      : return "2";
31
0
    case OP_3                      : return "3";
32
0
    case OP_4                      : return "4";
33
0
    case OP_5                      : return "5";
34
0
    case OP_6                      : return "6";
35
0
    case OP_7                      : return "7";
36
0
    case OP_8                      : return "8";
37
0
    case OP_9                      : return "9";
38
0
    case OP_10                     : return "10";
39
0
    case OP_11                     : return "11";
40
0
    case OP_12                     : return "12";
41
0
    case OP_13                     : return "13";
42
0
    case OP_14                     : return "14";
43
0
    case OP_15                     : return "15";
44
0
    case OP_16                     : return "16";
45
46
    // control
47
0
    case OP_NOP                    : return "OP_NOP";
48
0
    case OP_VER                    : return "OP_VER";
49
0
    case OP_IF                     : return "OP_IF";
50
0
    case OP_NOTIF                  : return "OP_NOTIF";
51
0
    case OP_VERIF                  : return "OP_VERIF";
52
0
    case OP_VERNOTIF               : return "OP_VERNOTIF";
53
0
    case OP_ELSE                   : return "OP_ELSE";
54
0
    case OP_ENDIF                  : return "OP_ENDIF";
55
0
    case OP_VERIFY                 : return "OP_VERIFY";
56
0
    case OP_RETURN                 : return "OP_RETURN";
57
58
    // stack ops
59
0
    case OP_TOALTSTACK             : return "OP_TOALTSTACK";
60
0
    case OP_FROMALTSTACK           : return "OP_FROMALTSTACK";
61
0
    case OP_2DROP                  : return "OP_2DROP";
62
0
    case OP_2DUP                   : return "OP_2DUP";
63
0
    case OP_3DUP                   : return "OP_3DUP";
64
0
    case OP_2OVER                  : return "OP_2OVER";
65
0
    case OP_2ROT                   : return "OP_2ROT";
66
0
    case OP_2SWAP                  : return "OP_2SWAP";
67
0
    case OP_IFDUP                  : return "OP_IFDUP";
68
0
    case OP_DEPTH                  : return "OP_DEPTH";
69
0
    case OP_DROP                   : return "OP_DROP";
70
0
    case OP_DUP                    : return "OP_DUP";
71
0
    case OP_NIP                    : return "OP_NIP";
72
0
    case OP_OVER                   : return "OP_OVER";
73
0
    case OP_PICK                   : return "OP_PICK";
74
0
    case OP_ROLL                   : return "OP_ROLL";
75
0
    case OP_ROT                    : return "OP_ROT";
76
0
    case OP_SWAP                   : return "OP_SWAP";
77
0
    case OP_TUCK                   : return "OP_TUCK";
78
79
    // splice ops
80
0
    case OP_CAT                    : return "OP_CAT";
81
0
    case OP_SUBSTR                 : return "OP_SUBSTR";
82
0
    case OP_LEFT                   : return "OP_LEFT";
83
0
    case OP_RIGHT                  : return "OP_RIGHT";
84
0
    case OP_SIZE                   : return "OP_SIZE";
85
86
    // bit logic
87
0
    case OP_INVERT                 : return "OP_INVERT";
88
0
    case OP_AND                    : return "OP_AND";
89
0
    case OP_OR                     : return "OP_OR";
90
0
    case OP_XOR                    : return "OP_XOR";
91
0
    case OP_EQUAL                  : return "OP_EQUAL";
92
0
    case OP_EQUALVERIFY            : return "OP_EQUALVERIFY";
93
0
    case OP_RESERVED1              : return "OP_RESERVED1";
94
0
    case OP_RESERVED2              : return "OP_RESERVED2";
95
96
    // numeric
97
0
    case OP_1ADD                   : return "OP_1ADD";
98
0
    case OP_1SUB                   : return "OP_1SUB";
99
0
    case OP_2MUL                   : return "OP_2MUL";
100
0
    case OP_2DIV                   : return "OP_2DIV";
101
0
    case OP_NEGATE                 : return "OP_NEGATE";
102
0
    case OP_ABS                    : return "OP_ABS";
103
0
    case OP_NOT                    : return "OP_NOT";
104
0
    case OP_0NOTEQUAL              : return "OP_0NOTEQUAL";
105
0
    case OP_ADD                    : return "OP_ADD";
106
0
    case OP_SUB                    : return "OP_SUB";
107
0
    case OP_MUL                    : return "OP_MUL";
108
0
    case OP_DIV                    : return "OP_DIV";
109
0
    case OP_MOD                    : return "OP_MOD";
110
0
    case OP_LSHIFT                 : return "OP_LSHIFT";
111
0
    case OP_RSHIFT                 : return "OP_RSHIFT";
112
0
    case OP_BOOLAND                : return "OP_BOOLAND";
113
0
    case OP_BOOLOR                 : return "OP_BOOLOR";
114
0
    case OP_NUMEQUAL               : return "OP_NUMEQUAL";
115
0
    case OP_NUMEQUALVERIFY         : return "OP_NUMEQUALVERIFY";
116
0
    case OP_NUMNOTEQUAL            : return "OP_NUMNOTEQUAL";
117
0
    case OP_LESSTHAN               : return "OP_LESSTHAN";
118
0
    case OP_GREATERTHAN            : return "OP_GREATERTHAN";
119
0
    case OP_LESSTHANOREQUAL        : return "OP_LESSTHANOREQUAL";
120
0
    case OP_GREATERTHANOREQUAL     : return "OP_GREATERTHANOREQUAL";
121
0
    case OP_MIN                    : return "OP_MIN";
122
0
    case OP_MAX                    : return "OP_MAX";
123
0
    case OP_WITHIN                 : return "OP_WITHIN";
124
125
    // crypto
126
0
    case OP_RIPEMD160              : return "OP_RIPEMD160";
127
0
    case OP_SHA1                   : return "OP_SHA1";
128
0
    case OP_SHA256                 : return "OP_SHA256";
129
0
    case OP_HASH160                : return "OP_HASH160";
130
0
    case OP_HASH256                : return "OP_HASH256";
131
0
    case OP_CODESEPARATOR          : return "OP_CODESEPARATOR";
132
0
    case OP_CHECKSIG               : return "OP_CHECKSIG";
133
0
    case OP_CHECKSIGVERIFY         : return "OP_CHECKSIGVERIFY";
134
0
    case OP_CHECKMULTISIG          : return "OP_CHECKMULTISIG";
135
0
    case OP_CHECKMULTISIGVERIFY    : return "OP_CHECKMULTISIGVERIFY";
136
137
    // expansion
138
0
    case OP_NOP1                   : return "OP_NOP1";
139
0
    case OP_CHECKLOCKTIMEVERIFY    : return "OP_CHECKLOCKTIMEVERIFY";
140
0
    case OP_CHECKSEQUENCEVERIFY    : return "OP_CHECKSEQUENCEVERIFY";
141
0
    case OP_NOP4                   : return "OP_NOP4";
142
0
    case OP_NOP5                   : return "OP_NOP5";
143
0
    case OP_NOP6                   : return "OP_NOP6";
144
0
    case OP_NOP7                   : return "OP_NOP7";
145
0
    case OP_NOP8                   : return "OP_NOP8";
146
0
    case OP_NOP9                   : return "OP_NOP9";
147
0
    case OP_NOP10                  : return "OP_NOP10";
148
149
    // Opcode added by BIP 342 (Tapscript)
150
0
    case OP_CHECKSIGADD            : return "OP_CHECKSIGADD";
151
152
0
    case OP_INVALIDOPCODE          : return "OP_INVALIDOPCODE";
153
154
0
    } // no default case, so the compiler can warn about missing cases
155
0
    return "OP_UNKNOWN";
156
0
}
157
158
unsigned int CScript::GetSigOpCount(bool fAccurate) const
159
0
{
160
0
    unsigned int n = 0;
161
0
    const_iterator pc = begin();
162
0
    opcodetype lastOpcode = OP_INVALIDOPCODE;
163
0
    while (pc < end())
164
0
    {
165
0
        opcodetype opcode;
166
0
        if (!GetOp(pc, opcode))
167
0
            break;
168
0
        if (opcode == OP_CHECKSIG || opcode == OP_CHECKSIGVERIFY)
169
0
            n++;
170
0
        else if (opcode == OP_CHECKMULTISIG || opcode == OP_CHECKMULTISIGVERIFY)
171
0
        {
172
0
            if (fAccurate && lastOpcode >= OP_1 && lastOpcode <= OP_16)
173
0
                n += DecodeOP_N(lastOpcode);
174
0
            else
175
0
                n += MAX_PUBKEYS_PER_MULTISIG;
176
0
        }
177
0
        lastOpcode = opcode;
178
0
    }
179
0
    return n;
180
0
}
181
182
unsigned int CScript::GetSigOpCount(const CScript& scriptSig) const
183
0
{
184
0
    if (!IsPayToScriptHash())
185
0
        return GetSigOpCount(true);
186
187
    // This is a pay-to-script-hash scriptPubKey;
188
    // get the last item that the scriptSig
189
    // pushes onto the stack:
190
0
    const_iterator pc = scriptSig.begin();
191
0
    std::vector<unsigned char> vData;
192
0
    while (pc < scriptSig.end())
193
0
    {
194
0
        opcodetype opcode;
195
0
        if (!scriptSig.GetOp(pc, opcode, vData))
196
0
            return 0;
197
0
        if (opcode > OP_16)
198
0
            return 0;
199
0
    }
200
201
    /// ... and return its opcount:
202
0
    CScript subscript(vData.begin(), vData.end());
203
0
    return subscript.GetSigOpCount(true);
204
0
}
205
206
bool CScript::IsPayToAnchor() const
207
0
{
208
0
    return (this->size() == 4 &&
209
0
        (*this)[0] == OP_1 &&
210
0
        (*this)[1] == 0x02 &&
211
0
        (*this)[2] == 0x4e &&
212
0
        (*this)[3] == 0x73);
213
0
}
214
215
bool CScript::IsPayToAnchor(int version, const std::vector<unsigned char>& program)
216
0
{
217
0
    return version == 1 &&
218
0
        program.size() == 2 &&
219
0
        program[0] == 0x4e &&
220
0
        program[1] == 0x73;
221
0
}
222
223
bool CScript::IsPayToScriptHash() const
224
0
{
225
    // Extra-fast test for pay-to-script-hash CScripts:
226
0
    return (this->size() == 23 &&
227
0
            (*this)[0] == OP_HASH160 &&
228
0
            (*this)[1] == 0x14 &&
229
0
            (*this)[22] == OP_EQUAL);
230
0
}
231
232
bool CScript::IsPayToWitnessScriptHash() const
233
0
{
234
    // Extra-fast test for pay-to-witness-script-hash CScripts:
235
0
    return (this->size() == 34 &&
236
0
            (*this)[0] == OP_0 &&
237
0
            (*this)[1] == 0x20);
238
0
}
239
240
bool CScript::IsPayToTaproot() const
241
0
{
242
0
    return (this->size() == 34 &&
243
0
            (*this)[0] == OP_1 &&
244
0
            (*this)[1] == 0x20);
245
0
}
246
247
// A witness program is any valid CScript that consists of a 1-byte push opcode
248
// followed by a data push between 2 and 40 bytes.
249
bool CScript::IsWitnessProgram(int& version, std::vector<unsigned char>& program) const
250
0
{
251
0
    if (this->size() < 4 || this->size() > 42) {
252
0
        return false;
253
0
    }
254
0
    if ((*this)[0] != OP_0 && ((*this)[0] < OP_1 || (*this)[0] > OP_16)) {
255
0
        return false;
256
0
    }
257
0
    if ((size_t)((*this)[1] + 2) == this->size()) {
258
0
        version = DecodeOP_N((opcodetype)(*this)[0]);
259
0
        program = std::vector<unsigned char>(this->begin() + 2, this->end());
260
0
        return true;
261
0
    }
262
0
    return false;
263
0
}
264
265
bool CScript::IsPushOnly(const_iterator pc) const
266
0
{
267
0
    while (pc < end())
268
0
    {
269
0
        opcodetype opcode;
270
0
        if (!GetOp(pc, opcode))
271
0
            return false;
272
        // Note that IsPushOnly() *does* consider OP_RESERVED to be a
273
        // push-type opcode, however execution of OP_RESERVED fails, so
274
        // it's not relevant to P2SH/BIP62 as the scriptSig would fail prior to
275
        // the P2SH special validation code being executed.
276
0
        if (opcode > OP_16)
277
0
            return false;
278
0
    }
279
0
    return true;
280
0
}
281
282
bool CScript::IsPushOnly() const
283
0
{
284
0
    return this->IsPushOnly(begin());
285
0
}
286
287
std::string CScriptWitness::ToString() const
288
0
{
289
0
    std::string ret = "CScriptWitness(";
290
0
    for (unsigned int i = 0; i < stack.size(); i++) {
291
0
        if (i) {
292
0
            ret += ", ";
293
0
        }
294
0
        ret += HexStr(stack[i]);
295
0
    }
296
0
    return ret + ")";
297
0
}
298
299
bool CScript::HasValidOps() const
300
0
{
301
0
    CScript::const_iterator it = begin();
302
0
    while (it < end()) {
303
0
        opcodetype opcode;
304
0
        std::vector<unsigned char> item;
305
0
        if (!GetOp(it, opcode, item) || opcode > MAX_OPCODE || item.size() > MAX_SCRIPT_ELEMENT_SIZE) {
306
0
            return false;
307
0
        }
308
0
    }
309
0
    return true;
310
0
}
311
312
bool GetScriptOp(CScriptBase::const_iterator& pc, CScriptBase::const_iterator end, opcodetype& opcodeRet, std::vector<unsigned char>* pvchRet)
313
0
{
314
0
    opcodeRet = OP_INVALIDOPCODE;
315
0
    if (pvchRet)
316
0
        pvchRet->clear();
317
0
    if (pc >= end)
318
0
        return false;
319
320
    // Read instruction
321
0
    if (end - pc < 1)
322
0
        return false;
323
0
    unsigned int opcode = *pc++;
324
325
    // Immediate operand
326
0
    if (opcode <= OP_PUSHDATA4)
327
0
    {
328
0
        unsigned int nSize = 0;
329
0
        if (opcode < OP_PUSHDATA1)
330
0
        {
331
0
            nSize = opcode;
332
0
        }
333
0
        else if (opcode == OP_PUSHDATA1)
334
0
        {
335
0
            if (end - pc < 1)
336
0
                return false;
337
0
            nSize = *pc++;
338
0
        }
339
0
        else if (opcode == OP_PUSHDATA2)
340
0
        {
341
0
            if (end - pc < 2)
342
0
                return false;
343
0
            nSize = ReadLE16(&pc[0]);
344
0
            pc += 2;
345
0
        }
346
0
        else if (opcode == OP_PUSHDATA4)
347
0
        {
348
0
            if (end - pc < 4)
349
0
                return false;
350
0
            nSize = ReadLE32(&pc[0]);
351
0
            pc += 4;
352
0
        }
353
0
        if (end - pc < 0 || (unsigned int)(end - pc) < nSize)
354
0
            return false;
355
0
        if (pvchRet)
356
0
            pvchRet->assign(pc, pc + nSize);
357
0
        pc += nSize;
358
0
    }
359
360
0
    opcodeRet = static_cast<opcodetype>(opcode);
361
0
    return true;
362
0
}
363
364
bool IsOpSuccess(const opcodetype& opcode)
365
0
{
366
0
    return opcode == 80 || opcode == 98 || (opcode >= 126 && opcode <= 129) ||
367
0
           (opcode >= 131 && opcode <= 134) || (opcode >= 137 && opcode <= 138) ||
368
0
           (opcode >= 141 && opcode <= 142) || (opcode >= 149 && opcode <= 153) ||
369
0
           (opcode >= 187 && opcode <= 254);
370
0
}
371
372
0
bool CheckMinimalPush(const std::vector<unsigned char>& data, opcodetype opcode) {
373
    // Excludes OP_1NEGATE, OP_1-16 since they are by definition minimal
374
0
    assert(0 <= opcode && opcode <= OP_PUSHDATA4);
375
0
    if (data.size() == 0) {
376
        // Should have used OP_0.
377
0
        return opcode == OP_0;
378
0
    } else if (data.size() == 1 && data[0] >= 1 && data[0] <= 16) {
379
        // Should have used OP_1 .. OP_16.
380
0
        return false;
381
0
    } else if (data.size() == 1 && data[0] == 0x81) {
382
        // Should have used OP_1NEGATE.
383
0
        return false;
384
0
    } else if (data.size() <= 75) {
385
        // Must have used a direct push (opcode indicating number of bytes pushed + those bytes).
386
0
        return opcode == data.size();
387
0
    } else if (data.size() <= 255) {
388
        // Must have used OP_PUSHDATA.
389
0
        return opcode == OP_PUSHDATA1;
390
0
    } else if (data.size() <= 65535) {
391
        // Must have used OP_PUSHDATA2.
392
0
        return opcode == OP_PUSHDATA2;
393
0
    }
394
0
    return true;
395
0
}