Repository navigation
commands: createmultisig: validate arguments like bitcoind does - #11021
Open
devdavidejesus wants to merge 2 commits into
Open
devdavidejesus wants to merge 2 commits into
devdavidejesus wants to merge 2 commits into
Conversation
An invalid public key was silently accepted (e.g. createmultisig 1 '["0378"]'), yielding an address whose coins might not be spendable. A redeem script larger than 520 bytes (e.g. 8 uncompressed keys) also yielded an unspendable p2sh address. Bad parameters raised bare AssertionErrors. Now the same checks as bitcoind's createmultisig are done: num must be an integer, the public keys must be valid hex-encoded points (hybrid keys are accepted, as in bitcoind), and the redeem script must fit in 520 bytes. Public keys given as bytes are no longer accepted. The order of the public keys is unchanged (see spesmilo#5343).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
On master,
createmultisigdoes not validate its arguments:0378is not a public key, yet an address is returned; coins sent to a multisig address built with an invalid key might not be spendable. Likewise, 8 uncompressed keys give a 531-byte redeem script, which cannot be spent as p2sh (520-byte limit), and other bad arguments raise bareAssertionErrors.This adds the checks that bitcoind's
createmultisigdoes (HexToPubKeyandAddAndGetMultisigDestinationinsrc/rpc/util.cpp):nummust be an integer with 1 <= num <= number of keys, each key must be a valid hex-encoded public key (hybrid keys are accepted, as in bitcoind), and the redeem script must fit in 520 bytes. The limit of 15 keys frommultisig_scriptis kept.The order of the keys is unchanged (see #5343). Keys passed as bytes, which only worked from the Python console, are no longer accepted, as the argument is documented as a list of hex strings.