83950275eddacac56c58a7a3648ed435a5593328 qa: unit test sighash caching (Antoine Poinsot)
b221aa80a081579b8d3b460e3403f7ac0daa7139 qa: simple differential fuzzing for sighash with/without caching (Antoine Poinsot)
92af9f74d74e76681f7d98f293eab226972137b4 script: (optimization) introduce sighash midstate caching (Pieter Wuille)
8f3ddb0bccebc930836b4a6745a7cf29b41eb302 script: (refactor) prepare for introducing sighash midstate cache (Pieter Wuille)
9014d4016ad9351cb59b587541895e55f5d589cc tests: add sighash caching tests to feature_taproot (Pieter Wuille)
Pull request description:
This introduces a per-txin cache for sighash midstate computation to the script interpreter for legacy (bare), P2SH, P2WSH, and (as collateral effect, but not actually useful) P2WPKH. This reduces the impact of certain types of quadratic hashing attacks that use standard transactions. It is not known to improve the situation for attacks involving non-standard transaction attacks.
The cache works by remembering for each of the 6 sighash modes a `(scriptCode, midstate)` tuple, which gives a midstate `CSHA256` object right before the appending of the sighash type itself (to permit all 256, rather than just the 6 ones that match the modes). The midstate is only reused if the `scriptCode` matches. This works because - within a single input - only the sighash type and the `scriptCode` affect the actual sighash used.
The PR implements two different approaches:
* The initial commits introduce the caching effect always, for both consensus and relay relation validation. Despite being primarily intended for improving the situation for standard transactions only, I chose this approach as the code paths are already largely common between the two, and this approach I believe involves fewer code changes than a more targetted approach, and furthermore, it should not hurt (it may even help common multisig cases slightly).
* The final commit changes the behavior to only using the cache for non-consensus script validation. I'm open to feedback about whether adding this commit is worth it.
Functional tests are included that construct contrived cases with many sighash types (standard and non-standard ones) and `OP_CODESEPARATOR`s in all script types (including P2TR, which isn't modified by this PR).
ACKs for top commit:
achow101:
ACK 83950275eddacac56c58a7a3648ed435a5593328
dergoegge:
Code review ACK 83950275eddacac56c58a7a3648ed435a5593328
darosior:
re-ACK 83950275eddacac56c58a7a3648ed435a5593328
Tree-SHA512: 65ae8635429a4d563b19969bac8128038ac2cbe01d9c9946abd4cac3c0780974d1e8b9aae9bb83f414e5d247a59f4a18fef5b37d93ad59ed41b6f11c3fe05af4
|
||
|---|---|---|
| .. | ||
| data | ||
| fuzz | ||
| util | ||
| addrman_tests.cpp | ||
| allocator_tests.cpp | ||
| amount_tests.cpp | ||
| arith_uint256_tests.cpp | ||
| banman_tests.cpp | ||
| base32_tests.cpp | ||
| base58_tests.cpp | ||
| base64_tests.cpp | ||
| bech32_tests.cpp | ||
| bip32_tests.cpp | ||
| blech32_tests.cpp | ||
| blind_tests.cpp | ||
| blockchain_tests.cpp | ||
| blockencodings_tests.cpp | ||
| blockfilter_index_tests.cpp | ||
| blockfilter_tests.cpp | ||
| bloom_tests.cpp | ||
| bswap_tests.cpp | ||
| checkqueue_tests.cpp | ||
| coins_tests.cpp | ||
| coinstatsindex_tests.cpp | ||
| compilerbug_tests.cpp | ||
| compress_tests.cpp | ||
| crypto_tests.cpp | ||
| cuckoocache_tests.cpp | ||
| dbwrapper_tests.cpp | ||
| denialofservice_tests.cpp | ||
| descriptor_tests.cpp | ||
| dynafed_tests.cpp | ||
| flatfile_tests.cpp | ||
| fs_tests.cpp | ||
| getarg_tests.cpp | ||
| hash_tests.cpp | ||
| i2p_tests.cpp | ||
| interfaces_tests.cpp | ||
| key_io_tests.cpp | ||
| key_tests.cpp | ||
| logging_tests.cpp | ||
| main.cpp | ||
| Makefile | ||
| mempool_tests.cpp | ||
| merkle_tests.cpp | ||
| merkleblock_tests.cpp | ||
| miner_tests.cpp | ||
| minisketch_tests.cpp | ||
| multisig_tests.cpp | ||
| net_peer_eviction_tests.cpp | ||
| net_tests.cpp | ||
| netbase_tests.cpp | ||
| pegin_spent_tests.cpp | ||
| pegin_witness_tests.cpp | ||
| pmt_tests.cpp | ||
| policy_fee_tests.cpp | ||
| policyestimator_tests.cpp | ||
| pow_tests.cpp | ||
| prevector_tests.cpp | ||
| raii_event_tests.cpp | ||
| random_tests.cpp | ||
| README.md | ||
| reverselock_tests.cpp | ||
| rpc_tests.cpp | ||
| sanity_tests.cpp | ||
| scheduler_tests.cpp | ||
| script_p2sh_tests.cpp | ||
| script_parse_tests.cpp | ||
| script_standard_tests.cpp | ||
| script_tests.cpp | ||
| scriptnum10.h | ||
| scriptnum_tests.cpp | ||
| serfloat_tests.cpp | ||
| serialize_tests.cpp | ||
| settings_tests.cpp | ||
| sighash_tests.cpp | ||
| sigopcount_tests.cpp | ||
| skiplist_tests.cpp | ||
| sock_tests.cpp | ||
| streams_tests.cpp | ||
| sync_tests.cpp | ||
| system_tests.cpp | ||
| timedata_tests.cpp | ||
| torcontrol_tests.cpp | ||
| transaction_tests.cpp | ||
| txindex_tests.cpp | ||
| txpackage_tests.cpp | ||
| txrequest_tests.cpp | ||
| txvalidation_tests.cpp | ||
| txvalidationcache_tests.cpp | ||
| uint256_tests.cpp | ||
| util_tests.cpp | ||
| util_threadnames_tests.cpp | ||
| validation_block_tests.cpp | ||
| validation_chainstate_tests.cpp | ||
| validation_chainstatemanager_tests.cpp | ||
| validation_flush_tests.cpp | ||
| validation_tests.cpp | ||
| validationinterface_tests.cpp | ||
| versionbits_tests.cpp | ||
Unit tests
The sources in this directory are unit test cases. Boost includes a unit testing framework, and since Bitcoin Core already uses Boost, it makes sense to simply use this framework rather than require developers to configure some other framework (we want as few impediments to creating unit tests as possible).
The build system is set up to compile an executable called test_bitcoin
that runs all of the unit tests. The main source file for the test library is found in
util/setup_common.cpp.
Compiling/running unit tests
Unit tests will be automatically compiled if dependencies were met in ./configure
and tests weren't explicitly disabled.
After configuring, they can be run with make check.
To run the unit tests manually, launch src/test/test_bitcoin. To recompile
after a test file was modified, run make and then run the test again. If you
modify a non-test file, use make -C src/test to recompile only what's needed
to run the unit tests.
To add more unit tests, add BOOST_AUTO_TEST_CASE functions to the existing
.cpp files in the test/ directory or add new .cpp files that
implement new BOOST_AUTO_TEST_SUITE sections.
To run the GUI unit tests manually, launch src/qt/test/test_bitcoin-qt
To add more GUI unit tests, add them to the src/qt/test/ directory and
the src/qt/test/test_main.cpp file.
Running individual tests
test_bitcoin accepts the command line arguments from the boost framework.
For example, to run just the getarg_tests suite of tests:
test_bitcoin --log_level=all --run_test=getarg_tests
log_level controls the verbosity of the test framework, which logs when a
test case is entered, for example. test_bitcoin also accepts the command
line arguments accepted by bitcoind. Use -- to separate both types of
arguments:
test_bitcoin --log_level=all --run_test=getarg_tests -- -printtoconsole=1
The -printtoconsole=1 after the two dashes redirects the debug log, which
would normally go to a file in the test datadir
(BasicTestingSetup::m_path_root), to the standard terminal output.
... or to run just the doubledash test:
test_bitcoin --run_test=getarg_tests/doubledash
Run test_bitcoin --help for the full list.
Adding test cases
To add a new unit test file to our test suite you need
to add the file to src/Makefile.test.include. The pattern is to create
one test file for each class or source file for which you want to create
unit tests. The file naming convention is <source_filename>_tests.cpp
and such files should wrap their tests in a test suite
called <source_filename>_tests. For an example of this pattern,
see uint256_tests.cpp.
Logging and debugging in unit tests
make check will write to a log file foo_tests.cpp.log and display this file
on failure. For running individual tests verbosely, refer to the section
above.
To write to logs from unit tests you need to use specific message methods
provided by Boost. The simplest is BOOST_TEST_MESSAGE.
For debugging you can launch the test_bitcoin executable with gdb or lldb and
start debugging, just like you would with any other program:
gdb src/test/test_bitcoin
Segmentation faults
If you hit a segmentation fault during a test run, you can diagnose where the fault
is happening by running gdb ./src/test/test_bitcoin and then using the bt command
within gdb.
Another tool that can be used to resolve segmentation faults is valgrind.
If for whatever reason you want to produce a core dump file for this fault, you can do
that as well. By default, the boost test runner will intercept system errors and not
produce a core file. To bypass this, add --catch_system_errors=no to the
test_bitcoin arguments and ensure that your ulimits are set properly (e.g. ulimit -c unlimited).
Running the tests and hitting a segmentation fault should now produce a file called core
(on Linux platforms, the file name will likely depend on the contents of
/proc/sys/kernel/core_pattern).
You can then explore the core dump using
gdb src/test/test_bitcoin core
(gbd) bt # produce a backtrace for where a segfault occurred