scriptpubkeyman.cpp raw
1 // Copyright (c) 2023-present The Limenka developers
2 // Distributed under the MIT software license, see the accompanying
3 // file COPYING or http://www.opensource.org/licenses/mit-license.php.
4
5 #include <addresstype.h>
6 #include <chainparams.h>
7 #include <coins.h>
8 #include <key.h>
9 #include <primitives/transaction.h>
10 #include <psbt.h>
11 #include <script/descriptor.h>
12 #include <script/interpreter.h>
13 #include <script/script.h>
14 #include <script/signingprovider.h>
15 #include <sync.h>
16 #include <test/fuzz/FuzzedDataProvider.h>
17 #include <test/fuzz/fuzz.h>
18 #include <test/fuzz/util.h>
19 #include <test/fuzz/util/descriptor.h>
20 #include <test/util/setup_common.h>
21 #include <util/check.h>
22 #include <util/time.h>
23 #include <util/translation.h>
24 #include <validation.h>
25 #include <wallet/scriptpubkeyman.h>
26 #include <wallet/test/util.h>
27 #include <wallet/types.h>
28 #include <wallet/wallet.h>
29 #include <wallet/walletutil.h>
30
31 #include <map>
32 #include <memory>
33 #include <optional>
34 #include <string>
35 #include <utility>
36 #include <variant>
37
38 namespace wallet {
39 namespace {
40 const TestingSetup* g_setup;
41
42 //! The converter of mocked descriptors, needs to be initialized when the target is.
43 MockedDescriptorConverter MOCKED_DESC_CONVERTER;
44
45 void initialize_spkm()
46 {
47 static const auto testing_setup{MakeNoLogFileContext<const TestingSetup>()};
48 g_setup = testing_setup.get();
49 SelectParams(ChainType::MAIN);
50 MOCKED_DESC_CONVERTER.Init();
51 }
52
53 /**
54 * Key derivation is expensive. Deriving deep derivation paths take a lot of compute and we'd rather spend time
55 * elsewhere in this target, like on actually fuzzing the DescriptorScriptPubKeyMan. So rule out strings which could
56 * correspond to a descriptor containing a too large derivation path.
57 */
58 static bool TooDeepDerivPath(std::string_view desc)
59 {
60 const FuzzBufferType desc_buf{reinterpret_cast<const unsigned char *>(desc.data()), desc.size()};
61 return HasDeepDerivPath(desc_buf);
62 }
63
64 static std::optional<std::pair<WalletDescriptor, FlatSigningProvider>> CreateWalletDescriptor(FuzzedDataProvider& fuzzed_data_provider)
65 {
66 const std::string mocked_descriptor{fuzzed_data_provider.ConsumeRandomLengthString()};
67 if (TooDeepDerivPath(mocked_descriptor)) return {};
68 const auto desc_str{MOCKED_DESC_CONVERTER.GetDescriptor(mocked_descriptor)};
69 if (!desc_str.has_value()) return std::nullopt;
70
71 FlatSigningProvider keys;
72 std::string error;
73 std::vector<std::unique_ptr<Descriptor>> parsed_descs = Parse(desc_str.value(), keys, error, false);
74 if (parsed_descs.empty()) return std::nullopt;
75
76 WalletDescriptor w_desc{std::move(parsed_descs.at(0)), /*creation_time=*/0, /*range_start=*/0, /*range_end=*/1, /*next_index=*/1};
77 return std::make_pair(w_desc, keys);
78 }
79
80 static DescriptorScriptPubKeyMan* CreateDescriptor(WalletDescriptor& wallet_desc, FlatSigningProvider& keys, CWallet& keystore)
81 {
82 LOCK(keystore.cs_wallet);
83 keystore.AddWalletDescriptor(wallet_desc, keys, /*label=*/"", /*internal=*/false);
84 return keystore.GetDescriptorScriptPubKeyMan(wallet_desc);
85 };
86
87 FUZZ_TARGET(scriptpubkeyman, .init = initialize_spkm)
88 {
89 SeedRandomStateForTest(SeedRand::ZEROS);
90 FuzzedDataProvider fuzzed_data_provider{buffer.data(), buffer.size()};
91 SetMockTime(ConsumeTime(fuzzed_data_provider));
92 const auto& node{g_setup->m_node};
93 Chainstate& chainstate{node.chainman->ActiveChainstate()};
94 std::unique_ptr<CWallet> wallet_ptr{std::make_unique<CWallet>(node.chain.get(), "", CreateMockableWalletDatabase())};
95 CWallet& wallet{*wallet_ptr};
96 {
97 LOCK(wallet.cs_wallet);
98 wallet.SetWalletFlag(WALLET_FLAG_DESCRIPTORS);
99 wallet.SetLastBlockProcessed(chainstate.m_chain.Height(), chainstate.m_chain.Tip()->GetBlockHash());
100 wallet.m_keypool_size = 1;
101 }
102
103 auto wallet_desc{CreateWalletDescriptor(fuzzed_data_provider)};
104 if (!wallet_desc.has_value()) return;
105 auto spk_manager{CreateDescriptor(wallet_desc->first, wallet_desc->second, wallet)};
106 if (spk_manager == nullptr) return;
107
108 if (fuzzed_data_provider.ConsumeBool()) {
109 auto wallet_desc{CreateWalletDescriptor(fuzzed_data_provider)};
110 if (!wallet_desc.has_value()) {
111 return;
112 }
113 std::string error;
114 if (spk_manager->CanUpdateToWalletDescriptor(wallet_desc->first, error)) {
115 auto new_spk_manager{CreateDescriptor(wallet_desc->first, wallet_desc->second, wallet)};
116 if (new_spk_manager != nullptr) spk_manager = new_spk_manager;
117 }
118 }
119
120 bool good_data{true};
121 LIMITED_WHILE(good_data && fuzzed_data_provider.ConsumeBool(), 20) {
122 CallOneOf(
123 fuzzed_data_provider,
124 [&] {
125 const CScript script{ConsumeScript(fuzzed_data_provider)};
126 auto is_mine{spk_manager->IsMine(script)};
127 if (is_mine == isminetype::ISMINE_SPENDABLE) {
128 assert(spk_manager->GetScriptPubKeys().count(script));
129 }
130 },
131 [&] {
132 auto spks{spk_manager->GetScriptPubKeys()};
133 for (const CScript& spk : spks) {
134 assert(spk_manager->IsMine(spk) == ISMINE_SPENDABLE);
135 CTxDestination dest;
136 bool extract_dest{ExtractDestination(spk, dest)};
137 if (extract_dest) {
138 const std::string msg{fuzzed_data_provider.ConsumeRandomLengthString()};
139 PKHash pk_hash{std::get_if<PKHash>(&dest) && fuzzed_data_provider.ConsumeBool() ?
140 *std::get_if<PKHash>(&dest) :
141 PKHash{ConsumeUInt160(fuzzed_data_provider)}};
142 std::string str_sig;
143 (void)spk_manager->SignMessage(MessageSignatureFormat::LEGACY, msg, pk_hash, str_sig);
144 (void)spk_manager->GetMetadata(dest);
145 }
146 }
147 },
148 [&] {
149 auto spks{spk_manager->GetScriptPubKeys()};
150 if (!spks.empty()) {
151 auto& spk{PickValue(fuzzed_data_provider, spks)};
152 (void)spk_manager->MarkUnusedAddresses(spk);
153 }
154 },
155 [&] {
156 LOCK(spk_manager->cs_desc_man);
157 auto wallet_desc{spk_manager->GetWalletDescriptor()};
158 if (wallet_desc.descriptor->IsSingleType()) {
159 auto output_type{wallet_desc.descriptor->GetOutputType()};
160 if (output_type.has_value()) {
161 auto dest{spk_manager->GetNewDestination(*output_type)};
162 if (dest) {
163 assert(IsValidDestination(*dest));
164 assert(spk_manager->IsHDEnabled());
165 }
166 }
167 }
168 },
169 [&] {
170 CMutableTransaction tx_to;
171 const std::optional<CMutableTransaction> opt_tx_to{ConsumeDeserializable<CMutableTransaction>(fuzzed_data_provider, TX_WITH_WITNESS)};
172 if (!opt_tx_to) {
173 good_data = false;
174 return;
175 }
176 tx_to = *opt_tx_to;
177
178 std::map<COutPoint, Coin> coins{ConsumeCoins(fuzzed_data_provider)};
179 const int sighash{fuzzed_data_provider.ConsumeIntegral<int>()};
180 std::map<int, bilingual_str> input_errors;
181 (void)spk_manager->SignTransaction(tx_to, coins, sighash, input_errors);
182 },
183 [&] {
184 std::optional<PartiallySignedTransaction> opt_psbt{ConsumeDeserializable<PartiallySignedTransaction>(fuzzed_data_provider)};
185 if (!opt_psbt) {
186 good_data = false;
187 return;
188 }
189 auto psbt{*opt_psbt};
190 const PrecomputedTransactionData txdata{PrecomputePSBTData(psbt)};
191 const int sighash_type{fuzzed_data_provider.ConsumeIntegralInRange<int>(0, 150)};
192 auto sign = fuzzed_data_provider.ConsumeBool();
193 auto bip32derivs = fuzzed_data_provider.ConsumeBool();
194 auto finalize = fuzzed_data_provider.ConsumeBool();
195 (void)spk_manager->FillPSBT(psbt, txdata, sighash_type, sign, bip32derivs, nullptr, finalize);
196 }
197 );
198 }
199
200 std::string descriptor;
201 (void)spk_manager->GetDescriptorString(descriptor, /*priv=*/fuzzed_data_provider.ConsumeBool());
202 (void)spk_manager->GetEndRange();
203 (void)spk_manager->GetKeyPoolSize();
204 }
205
206 } // namespace
207 } // namespace wallet
208