1 // Copyright (c) 2009-2010 Satoshi Nakamoto
2 // Copyright (c) 2009-2016 The Bitcoin Core developers
3 // Distributed under the MIT software license, see the accompanying
4 // file COPYING or http://www.opensource.org/licenses/mit-license.php.
6 #ifndef BITCOIN_SCRIPT_INTERPRETER_H
7 #define BITCOIN_SCRIPT_INTERPRETER_H
9 #include "script_error.h"
10 #include "primitives/transaction.h"
21 /** Signature hash types/flags */
27 SIGHASH_ANYONECANPAY
= 0x80,
30 /** Script verification flags */
33 SCRIPT_VERIFY_NONE
= 0,
35 // Evaluate P2SH subscripts (softfork safe, BIP16).
36 SCRIPT_VERIFY_P2SH
= (1U << 0),
38 // Passing a non-strict-DER signature or one with undefined hashtype to a checksig operation causes script failure.
39 // Evaluating a pubkey that is not (0x04 + 64 bytes) or (0x02 or 0x03 + 32 bytes) by checksig causes script failure.
40 // (softfork safe, but not used or intended as a consensus rule).
41 SCRIPT_VERIFY_STRICTENC
= (1U << 1),
43 // Passing a non-strict-DER signature to a checksig operation causes script failure (softfork safe, BIP62 rule 1)
44 SCRIPT_VERIFY_DERSIG
= (1U << 2),
46 // Passing a non-strict-DER signature or one with S > order/2 to a checksig operation causes script failure
47 // (softfork safe, BIP62 rule 5).
48 SCRIPT_VERIFY_LOW_S
= (1U << 3),
50 // verify dummy stack item consumed by CHECKMULTISIG is of zero-length (softfork safe, BIP62 rule 7).
51 SCRIPT_VERIFY_NULLDUMMY
= (1U << 4),
53 // Using a non-push operator in the scriptSig causes script failure (softfork safe, BIP62 rule 2).
54 SCRIPT_VERIFY_SIGPUSHONLY
= (1U << 5),
56 // Require minimal encodings for all push operations (OP_0... OP_16, OP_1NEGATE where possible, direct
57 // pushes up to 75 bytes, OP_PUSHDATA up to 255 bytes, OP_PUSHDATA2 for anything larger). Evaluating
58 // any other push causes the script to fail (BIP62 rule 3).
59 // In addition, whenever a stack element is interpreted as a number, it must be of minimal length (BIP62 rule 4).
61 SCRIPT_VERIFY_MINIMALDATA
= (1U << 6),
63 // Discourage use of NOPs reserved for upgrades (NOP1-10)
65 // Provided so that nodes can avoid accepting or mining transactions
66 // containing executed NOP's whose meaning may change after a soft-fork,
67 // thus rendering the script invalid; with this flag set executing
68 // discouraged NOPs fails the script. This verification flag will never be
69 // a mandatory flag applied to scripts in a block. NOPs that are not
70 // executed, e.g. within an unexecuted IF ENDIF block, are *not* rejected.
71 SCRIPT_VERIFY_DISCOURAGE_UPGRADABLE_NOPS
= (1U << 7),
73 // Require that only a single stack element remains after evaluation. This changes the success criterion from
74 // "At least one stack element must remain, and when interpreted as a boolean, it must be true" to
75 // "Exactly one stack element must remain, and when interpreted as a boolean, it must be true".
76 // (softfork safe, BIP62 rule 6)
77 // Note: CLEANSTACK should never be used without P2SH or WITNESS.
78 SCRIPT_VERIFY_CLEANSTACK
= (1U << 8),
80 // Verify CHECKLOCKTIMEVERIFY
82 // See BIP65 for details.
83 SCRIPT_VERIFY_CHECKLOCKTIMEVERIFY
= (1U << 9),
85 // support CHECKSEQUENCEVERIFY opcode
87 // See BIP112 for details
88 SCRIPT_VERIFY_CHECKSEQUENCEVERIFY
= (1U << 10),
90 // Support segregated witness
92 SCRIPT_VERIFY_WITNESS
= (1U << 11),
94 // Making v1-v16 witness program non-standard
96 SCRIPT_VERIFY_DISCOURAGE_UPGRADABLE_WITNESS_PROGRAM
= (1U << 12),
98 // Segwit script only: Require the argument of OP_IF/NOTIF to be exactly 0x01 or empty vector
100 SCRIPT_VERIFY_MINIMALIF
= (1U << 13),
102 // Signature(s) must be empty vector if an CHECK(MULTI)SIG operation failed
104 SCRIPT_VERIFY_NULLFAIL
= (1U << 14),
106 // Public keys in segregated witness scripts must be compressed
108 SCRIPT_VERIFY_WITNESS_PUBKEYTYPE
= (1U << 15),
111 bool CheckSignatureEncoding(const std::vector
<unsigned char> &vchSig
, unsigned int flags
, ScriptError
* serror
);
113 struct PrecomputedTransactionData
115 uint256 hashPrevouts
, hashSequence
, hashOutputs
;
117 explicit PrecomputedTransactionData(const CTransaction
& tx
);
123 SIGVERSION_WITNESS_V0
= 1,
126 uint256
SignatureHash(const CScript
&scriptCode
, const CTransaction
& txTo
, unsigned int nIn
, int nHashType
, const CAmount
& amount
, SigVersion sigversion
, const PrecomputedTransactionData
* cache
= nullptr);
128 class BaseSignatureChecker
131 virtual bool CheckSig(const std::vector
<unsigned char>& scriptSig
, const std::vector
<unsigned char>& vchPubKey
, const CScript
& scriptCode
, SigVersion sigversion
) const
136 virtual bool CheckLockTime(const CScriptNum
& nLockTime
) const
141 virtual bool CheckSequence(const CScriptNum
& nSequence
) const
146 virtual ~BaseSignatureChecker() {}
149 class TransactionSignatureChecker
: public BaseSignatureChecker
152 const CTransaction
* txTo
;
154 const CAmount amount
;
155 const PrecomputedTransactionData
* txdata
;
158 virtual bool VerifySignature(const std::vector
<unsigned char>& vchSig
, const CPubKey
& vchPubKey
, const uint256
& sighash
) const;
161 TransactionSignatureChecker(const CTransaction
* txToIn
, unsigned int nInIn
, const CAmount
& amountIn
) : txTo(txToIn
), nIn(nInIn
), amount(amountIn
), txdata(nullptr) {}
162 TransactionSignatureChecker(const CTransaction
* txToIn
, unsigned int nInIn
, const CAmount
& amountIn
, const PrecomputedTransactionData
& txdataIn
) : txTo(txToIn
), nIn(nInIn
), amount(amountIn
), txdata(&txdataIn
) {}
163 bool CheckSig(const std::vector
<unsigned char>& scriptSig
, const std::vector
<unsigned char>& vchPubKey
, const CScript
& scriptCode
, SigVersion sigversion
) const override
;
164 bool CheckLockTime(const CScriptNum
& nLockTime
) const override
;
165 bool CheckSequence(const CScriptNum
& nSequence
) const override
;
168 class MutableTransactionSignatureChecker
: public TransactionSignatureChecker
171 const CTransaction txTo
;
174 MutableTransactionSignatureChecker(const CMutableTransaction
* txToIn
, unsigned int nInIn
, const CAmount
& amountIn
) : TransactionSignatureChecker(&txTo
, nInIn
, amountIn
), txTo(*txToIn
) {}
177 bool EvalScript(std::vector
<std::vector
<unsigned char> >& stack
, const CScript
& script
, unsigned int flags
, const BaseSignatureChecker
& checker
, SigVersion sigversion
, ScriptError
* error
= nullptr);
178 bool VerifyScript(const CScript
& scriptSig
, const CScript
& scriptPubKey
, const CScriptWitness
* witness
, unsigned int flags
, const BaseSignatureChecker
& checker
, ScriptError
* serror
= nullptr);
180 size_t CountWitnessSigOps(const CScript
& scriptSig
, const CScript
& scriptPubKey
, const CScriptWitness
* witness
, unsigned int flags
);
182 #endif // BITCOIN_SCRIPT_INTERPRETER_H