Skip to content

Commit 3537c7c

Browse files
committed
rpc, psbt: Require sighashes match for descriptorprocesspsbt
1 parent 27d1396 commit 3537c7c

File tree

2 files changed

+19
-2
lines changed

2 files changed

+19
-2
lines changed

src/rpc/rawtransaction.cpp

+4-2
Original file line numberDiff line numberDiff line change
@@ -235,8 +235,10 @@ PartiallySignedTransaction ProcessPSBT(const std::string& psbt_string, const std
235235
// Note that SignPSBTInput does a lot more than just constructing ECDSA signatures.
236236
// We only actually care about those if our signing provider doesn't hide private
237237
// information, as is the case with `descriptorprocesspsbt`
238-
// As such, we ignore the return value as any errors just mean that we do not have enough information.
239-
(void)SignPSBTInput(provider, psbtx, /*index=*/i, &txdata, sighash_type, /*out_sigdata=*/nullptr, finalize);
238+
// Only error for mismatching sighash types as it is critical that the sighash to sign with matches the PSBT's
239+
if (SignPSBTInput(provider, psbtx, /*index=*/i, &txdata, sighash_type, /*out_sigdata=*/nullptr, finalize) == common::PSBTError::SIGHASH_MISMATCH) {
240+
throw JSONRPCPSBTError(common::PSBTError::SIGHASH_MISMATCH);
241+
}
240242
}
241243

242244
// Update script/keypath information using descriptor data.

test/functional/rpc_psbt.py

+15
Original file line numberDiff line numberDiff line change
@@ -212,6 +212,12 @@ def test_sighash_mismatch(self):
212212
def_wallet.sendtoaddress(addr, 5)
213213
self.generate(self.nodes[0], 6)
214214

215+
# Retrieve the descriptors so we can do all of the tests with descriptorprocesspsbt as well
216+
if self.options.descriptors:
217+
descs = wallet.listdescriptors(True)["descriptors"]
218+
else:
219+
descs = [descsum_create(f"wpkh({wallet.dumpprivkey(addr)})")]
220+
215221
# Make a PSBT
216222
psbt = wallet.walletcreatefundedpsbt([], [{def_wallet.getnewaddress(): 1}])["psbt"]
217223

@@ -228,6 +234,15 @@ def test_sighash_mismatch(self):
228234
proc = wallet.walletprocesspsbt(psbt, True, "ALL|ANYONECANPAY")
229235
assert_equal(proc["complete"], True)
230236

237+
# Repeat with descriptorprocesspsbt
238+
# Mismatching sighash type fails, including when no type is specified
239+
for sighash in ["DEFAULT", "ALL", "NONE", "SINGLE", "NONE|ANYONECANPAY", "SINGLE|ANYONECANPAY", None]:
240+
assert_raises_rpc_error(-22, "Specified sighash value does not match value stored in PSBT", self.nodes[0].descriptorprocesspsbt, psbt, descs, sighash)
241+
242+
# Matching sighash type succeeds
243+
proc = self.nodes[0].descriptorprocesspsbt(psbt, descs, "ALL|ANYONECANPAY")
244+
assert_equal(proc["complete"], True)
245+
231246
wallet.unloadwallet()
232247

233248
def test_sighash_adding(self):

0 commit comments

Comments
 (0)