No description
Find a file
Andrew Poelstra 0bff9b06f7
psbt: guard against empty PSBT transaction
There is a crashing bug in psbt.h which works as follows. This occurs in
the psbt_deserialize_input fuzz test, which deserializes an input and
then tries to reserialize it. Here a PSET input may contain a mainchain
transaction, which is where our trouble is.

The process is as follows:

1. On line 901, we create a CTransactionRef, which is a newtype around
   std::shared_ptr<CTransaction> which defaults to being null.
2. On line 903 we then call `UnserializeFromVector` to populate this,
   where this is a helper function which attempts to read some number of
   objects from a byte vector, i.e. a length-prefixed blob.
3. HOWEVER, `UnserializeFromVector` when given an empty vector, decides
   that it has successfully deserialized zero elements, and returns.
4. Then, on line 904 we assign the CTransactionRef, which is a valid
   std::shared_ptr whose internal pointer is NULL, to `m_peg_in_tx`,
   which is a variant of monostate, Bitcoin::CTransactionRef, and
   CTransactionRef. Its variant changes from the default monostate
   to CTransactionRef.
5. Then, on line 419, we call `std::get_if<CTransactionRef>` on this
   object, which returns a std::optional<CTransactionRef>. Because
   `m_peg_in_tx` is in the `CTransactionRef` variant, this succeeds,
   returning a true std::optional containing a valid std::shared_ptr
   which contains a NULL pointer.
6. Then, on line 420, we call `if (peg_in_tx)`, which is true, because
   we have a true std::optional. We then dereference it on line 423,
   which is perfectly legal, to get our std::shared_ptr, and pass this
   shared pointer to SerializeToVector.
7. SerializeToVector passes through like 6 layers of serialize.h
   obfuscation and eventually dereferences the shared pointer, but
   because it's NULL, this is a NULL pointer dereference, and we get a
   crash.

There are two lessons here:

1. Don't use C++. As I say in acf709b3ab,
   where I introduced some of the offending code here (but only by
   replacing boost stuff with their STL equivalents; the bug existed
   before I did this), "what a trainwreck of a language".
2. Don't use `UnserializeFromVector` and expect it to throw if the data
   you're deserializing is malformed. If it's malformed in the sense of
   being empty, it will "succeed" and silently do nothing.

I glanced at every other instance of UnserializeFromVector to check what
will happen when it's passed an empty string. I believe there are no
other cases where it will fail to initialize a NULL pointer, so I
believe that this will not cause other crashes. But I also believe that
the behavior in this case is almost always wrong and that we parse
malformed PSETs in crazy and incorrect ways all over the place.

If anybody has a problem with this, I encourage you to go review the
Bitcoin PSBT2 PRs, which this stuff is based on, which have been
languishing in rebase hell for the better part of a decade. Don't blame
the author for not writing perfect code in a hostile language with no
support.

After this PR I ran the fuzzer for 16 hours on a 192-thread machine (so
3072 CPU-hours) and didn't see any more crashes.
2025-02-14 18:08:45 +00:00
.github doc: Remove label from good first issue template 2020-08-24 09:31:24 +02:00
.tx qt: Update transifex resource blob to 23.0 2022-02-03 13:18:28 +01:00
build-aux/m4 build: use header-only Boost unit test 2022-02-13 20:59:02 +00:00
build_msvc Win64: set the right TargetName in native builds 2025-02-12 11:16:14 -08:00
ci Apply acc06bc91f fix also to pip upgrade 2025-02-13 05:46:30 -08:00
contrib lint: fix shellcheck, spelling, and locale 2025-02-13 16:08:39 +02:00
depends Update xcb_proto to 1.15.2, manually picked from 7cb88c8b46 2025-02-07 13:34:50 -08:00
doc lint: fix codespell warnings 2023-09-27 15:56:20 +02:00
share Merge b6b7815ddc into merged_master (Bitcoin PR bitcoin/bitcoin#24277) 2023-06-30 13:12:30 +00:00
src psbt: guard against empty PSBT transaction 2025-02-14 18:08:45 +00:00
test lint: fix shellcheck, spelling, and locale 2025-02-13 16:08:39 +02:00
.cirrus.yml ci: Use macos-ventura-xcode:14.1 image for "macOS native" task 2025-02-13 05:46:30 -08:00
.editorconfig ci: Drop AppVeyor CI integration 2021-09-07 06:12:53 +03:00
.gitattributes Separate protocol versioning from clientversion 2014-10-29 00:24:40 -04:00
.gitignore Merge 619f8a27ad into merged_master (Bitcoin PR bitcoin/bitcoin#24304) 2023-07-03 11:19:58 +00:00
.python-version Bump minimum python version to 3.6 2020-11-09 17:53:47 +10:00
.style.yapf test: .style.yapf: Set column_limit=160 2019-03-04 18:28:13 -05:00
autogen.sh scripted-diff: Bump copyright of files changed in 2019 2019-12-30 10:42:20 +13:00
configure.ac build: Fix Boost.Process test for Boost 1.78 2025-02-11 06:14:51 -08:00
CONTRIBUTING.md Merge 0dc1002c30 into merged_master (Bitcoin PR bitcoin/bitcoin#24433) 2023-07-02 16:08:36 +00:00
COPYING doc: Update license year range to 2022 2022-01-03 04:48:41 +08:00
INSTALL.md doc: Added hyperlink for doc/build 2021-09-09 19:53:12 +05:30
libbitcoinconsensus.pc.in build: remove libcrypto as internal dependency in libbitcoinconsensus.pc 2019-11-19 15:03:44 +01:00
Makefile.am Enable coverage for simplicity/secp256k1 2025-02-04 12:14:28 -05:00
README.md Merge 9b28bd73a3 into merged_master (Bitcoin PR #20691) 2021-06-15 13:07:58 +00:00
REVIEWERS doc: update maintainer list in REVIEWERS 2022-02-25 11:46:26 +00:00
SECURITY.md Merge c702d1fefd into merged_master (Bitcoin PR bitcoin/bitcoin#23466) 2023-05-17 12:25:58 +00:00

Elements Project blockchain platform

Build Status

https://elementsproject.org

This is the integration and staging tree for the Elements blockchain platform, a collection of feature experiments and extensions to the Bitcoin protocol. This platform enables anyone to build their own businesses or networks pegged to Bitcoin as a sidechain or run as a standalone blockchain with arbitrary asset tokens.

Modes

Elements supports a few different pre-set chains for syncing. Note though some are intended for QA and debugging only:

  • Liquid mode: elementsd -chain=liquidv1 (syncs with Liquid network)
  • Bitcoin mainnet mode: elementsd -chain=main (not intended to be run for commerce)
  • Bitcoin testnet mode: elementsd -chain=testnet3
  • Bitcoin regtest mode: elementsd -chain=regtest
  • Elements custom chains: Any other -chain= argument. It has regtest-like default parameters that can be over-ridden by the user by a rich set of start-up options.

Confidential Assets

The latest feature in the Elements blockchain platform is Confidential Assets, the ability to issue multiple assets on a blockchain where asset identifiers and amounts are blinded yet auditable through the use of applied cryptography.

Features of the Elements blockchain platform

Compared to Bitcoin itself, it adds the following features:

Previous elements that have been integrated into Bitcoin:

  • Segregated Witness
  • Relative Lock Time

Elements deferred for additional research and standardization:

Additional RPC commands and parameters:

The CI (Continuous Integration) systems make sure that every pull request is built for Windows, Linux, and macOS, and that unit/sanity tests are run automatically.

License

Elements is released under the terms of the MIT license. See COPYING for more information or see http://opensource.org/licenses/MIT.

What is the Elements Project?

Elements is an open source, sidechain-capable blockchain platform. It also allows experiments to more rapidly bring technical innovation to the Bitcoin ecosystem.

Learn more on the Elements Project website

https://github.com/ElementsProject/elementsproject.github.io

Secure Reporting

See our vulnerability reporting guide