scriptpubkeyman.cpp raw

   1  // Copyright (c) 2023-present The Limenka developers
   2  // Distributed under the MIT software license, see the accompanying
   3  // file COPYING or http://www.opensource.org/licenses/mit-license.php.
   4  
   5  #include <addresstype.h>
   6  #include <chainparams.h>
   7  #include <coins.h>
   8  #include <key.h>
   9  #include <primitives/transaction.h>
  10  #include <psbt.h>
  11  #include <script/descriptor.h>
  12  #include <script/interpreter.h>
  13  #include <script/script.h>
  14  #include <script/signingprovider.h>
  15  #include <sync.h>
  16  #include <test/fuzz/FuzzedDataProvider.h>
  17  #include <test/fuzz/fuzz.h>
  18  #include <test/fuzz/util.h>
  19  #include <test/fuzz/util/descriptor.h>
  20  #include <test/util/setup_common.h>
  21  #include <util/check.h>
  22  #include <util/time.h>
  23  #include <util/translation.h>
  24  #include <validation.h>
  25  #include <wallet/scriptpubkeyman.h>
  26  #include <wallet/test/util.h>
  27  #include <wallet/types.h>
  28  #include <wallet/wallet.h>
  29  #include <wallet/walletutil.h>
  30  
  31  #include <map>
  32  #include <memory>
  33  #include <optional>
  34  #include <string>
  35  #include <utility>
  36  #include <variant>
  37  
  38  namespace wallet {
  39  namespace {
  40  const TestingSetup* g_setup;
  41  
  42  //! The converter of mocked descriptors, needs to be initialized when the target is.
  43  MockedDescriptorConverter MOCKED_DESC_CONVERTER;
  44  
  45  void initialize_spkm()
  46  {
  47      static const auto testing_setup{MakeNoLogFileContext<const TestingSetup>()};
  48      g_setup = testing_setup.get();
  49      SelectParams(ChainType::MAIN);
  50      MOCKED_DESC_CONVERTER.Init();
  51  }
  52  
  53  /**
  54   * Key derivation is expensive. Deriving deep derivation paths take a lot of compute and we'd rather spend time
  55   * elsewhere in this target, like on actually fuzzing the DescriptorScriptPubKeyMan. So rule out strings which could
  56   * correspond to a descriptor containing a too large derivation path.
  57   */
  58  static bool TooDeepDerivPath(std::string_view desc)
  59  {
  60      const FuzzBufferType desc_buf{reinterpret_cast<const unsigned char *>(desc.data()), desc.size()};
  61      return HasDeepDerivPath(desc_buf);
  62  }
  63  
  64  static std::optional<std::pair<WalletDescriptor, FlatSigningProvider>> CreateWalletDescriptor(FuzzedDataProvider& fuzzed_data_provider)
  65  {
  66      const std::string mocked_descriptor{fuzzed_data_provider.ConsumeRandomLengthString()};
  67      if (TooDeepDerivPath(mocked_descriptor)) return {};
  68      const auto desc_str{MOCKED_DESC_CONVERTER.GetDescriptor(mocked_descriptor)};
  69      if (!desc_str.has_value()) return std::nullopt;
  70  
  71      FlatSigningProvider keys;
  72      std::string error;
  73      std::vector<std::unique_ptr<Descriptor>> parsed_descs = Parse(desc_str.value(), keys, error, false);
  74      if (parsed_descs.empty()) return std::nullopt;
  75  
  76      WalletDescriptor w_desc{std::move(parsed_descs.at(0)), /*creation_time=*/0, /*range_start=*/0, /*range_end=*/1, /*next_index=*/1};
  77      return std::make_pair(w_desc, keys);
  78  }
  79  
  80  static DescriptorScriptPubKeyMan* CreateDescriptor(WalletDescriptor& wallet_desc, FlatSigningProvider& keys, CWallet& keystore)
  81  {
  82      LOCK(keystore.cs_wallet);
  83      keystore.AddWalletDescriptor(wallet_desc, keys, /*label=*/"", /*internal=*/false);
  84      return keystore.GetDescriptorScriptPubKeyMan(wallet_desc);
  85  };
  86  
  87  FUZZ_TARGET(scriptpubkeyman, .init = initialize_spkm)
  88  {
  89      SeedRandomStateForTest(SeedRand::ZEROS);
  90      FuzzedDataProvider fuzzed_data_provider{buffer.data(), buffer.size()};
  91      SetMockTime(ConsumeTime(fuzzed_data_provider));
  92      const auto& node{g_setup->m_node};
  93      Chainstate& chainstate{node.chainman->ActiveChainstate()};
  94      std::unique_ptr<CWallet> wallet_ptr{std::make_unique<CWallet>(node.chain.get(), "", CreateMockableWalletDatabase())};
  95      CWallet& wallet{*wallet_ptr};
  96      {
  97          LOCK(wallet.cs_wallet);
  98          wallet.SetWalletFlag(WALLET_FLAG_DESCRIPTORS);
  99          wallet.SetLastBlockProcessed(chainstate.m_chain.Height(), chainstate.m_chain.Tip()->GetBlockHash());
 100          wallet.m_keypool_size = 1;
 101      }
 102  
 103      auto wallet_desc{CreateWalletDescriptor(fuzzed_data_provider)};
 104      if (!wallet_desc.has_value()) return;
 105      auto spk_manager{CreateDescriptor(wallet_desc->first, wallet_desc->second, wallet)};
 106      if (spk_manager == nullptr) return;
 107  
 108      if (fuzzed_data_provider.ConsumeBool()) {
 109          auto wallet_desc{CreateWalletDescriptor(fuzzed_data_provider)};
 110          if (!wallet_desc.has_value()) {
 111              return;
 112          }
 113          std::string error;
 114          if (spk_manager->CanUpdateToWalletDescriptor(wallet_desc->first, error)) {
 115              auto new_spk_manager{CreateDescriptor(wallet_desc->first, wallet_desc->second, wallet)};
 116              if (new_spk_manager != nullptr) spk_manager = new_spk_manager;
 117          }
 118      }
 119  
 120      bool good_data{true};
 121      LIMITED_WHILE(good_data && fuzzed_data_provider.ConsumeBool(), 20) {
 122          CallOneOf(
 123              fuzzed_data_provider,
 124              [&] {
 125                  const CScript script{ConsumeScript(fuzzed_data_provider)};
 126                  auto is_mine{spk_manager->IsMine(script)};
 127                  if (is_mine == isminetype::ISMINE_SPENDABLE) {
 128                      assert(spk_manager->GetScriptPubKeys().count(script));
 129                  }
 130              },
 131              [&] {
 132                  auto spks{spk_manager->GetScriptPubKeys()};
 133                  for (const CScript& spk : spks) {
 134                      assert(spk_manager->IsMine(spk) == ISMINE_SPENDABLE);
 135                      CTxDestination dest;
 136                      bool extract_dest{ExtractDestination(spk, dest)};
 137                      if (extract_dest) {
 138                          const std::string msg{fuzzed_data_provider.ConsumeRandomLengthString()};
 139                          PKHash pk_hash{std::get_if<PKHash>(&dest) && fuzzed_data_provider.ConsumeBool() ?
 140                                             *std::get_if<PKHash>(&dest) :
 141                                             PKHash{ConsumeUInt160(fuzzed_data_provider)}};
 142                          std::string str_sig;
 143                          (void)spk_manager->SignMessage(MessageSignatureFormat::LEGACY, msg, pk_hash, str_sig);
 144                          (void)spk_manager->GetMetadata(dest);
 145                      }
 146                  }
 147              },
 148              [&] {
 149                  auto spks{spk_manager->GetScriptPubKeys()};
 150                  if (!spks.empty()) {
 151                      auto& spk{PickValue(fuzzed_data_provider, spks)};
 152                      (void)spk_manager->MarkUnusedAddresses(spk);
 153                  }
 154              },
 155              [&] {
 156                  LOCK(spk_manager->cs_desc_man);
 157                  auto wallet_desc{spk_manager->GetWalletDescriptor()};
 158                  if (wallet_desc.descriptor->IsSingleType()) {
 159                      auto output_type{wallet_desc.descriptor->GetOutputType()};
 160                      if (output_type.has_value()) {
 161                          auto dest{spk_manager->GetNewDestination(*output_type)};
 162                          if (dest) {
 163                              assert(IsValidDestination(*dest));
 164                              assert(spk_manager->IsHDEnabled());
 165                          }
 166                      }
 167                  }
 168              },
 169              [&] {
 170                  CMutableTransaction tx_to;
 171                  const std::optional<CMutableTransaction> opt_tx_to{ConsumeDeserializable<CMutableTransaction>(fuzzed_data_provider, TX_WITH_WITNESS)};
 172                  if (!opt_tx_to) {
 173                      good_data = false;
 174                      return;
 175                  }
 176                  tx_to = *opt_tx_to;
 177  
 178                  std::map<COutPoint, Coin> coins{ConsumeCoins(fuzzed_data_provider)};
 179                  const int sighash{fuzzed_data_provider.ConsumeIntegral<int>()};
 180                  std::map<int, bilingual_str> input_errors;
 181                  (void)spk_manager->SignTransaction(tx_to, coins, sighash, input_errors);
 182              },
 183              [&] {
 184                  std::optional<PartiallySignedTransaction> opt_psbt{ConsumeDeserializable<PartiallySignedTransaction>(fuzzed_data_provider)};
 185                  if (!opt_psbt) {
 186                      good_data = false;
 187                      return;
 188                  }
 189                  auto psbt{*opt_psbt};
 190                  const PrecomputedTransactionData txdata{PrecomputePSBTData(psbt)};
 191                  const int sighash_type{fuzzed_data_provider.ConsumeIntegralInRange<int>(0, 150)};
 192                  auto sign  = fuzzed_data_provider.ConsumeBool();
 193                  auto bip32derivs = fuzzed_data_provider.ConsumeBool();
 194                  auto finalize = fuzzed_data_provider.ConsumeBool();
 195                  (void)spk_manager->FillPSBT(psbt, txdata, sighash_type, sign, bip32derivs, nullptr, finalize);
 196              }
 197          );
 198      }
 199  
 200      std::string descriptor;
 201      (void)spk_manager->GetDescriptorString(descriptor, /*priv=*/fuzzed_data_provider.ConsumeBool());
 202      (void)spk_manager->GetEndRange();
 203      (void)spk_manager->GetKeyPoolSize();
 204  }
 205  
 206  } // namespace
 207  } // namespace wallet
 208