Skip to content

Commit 31d2b40

Browse files
author
MarcoFalke
committed
Merge #19508: Work around memory-aliasing in descriptor ParsePubkey
fa2ae0a span: Add Span::empty() and use it in script/descriptor (MarcoFalke) fa8a992 Work around memory-aliasing in descriptor ParsePubkey (MarcoFalke) Pull request description: While this is not undefined behaviour, the memory aliasing trick is confusing when reading the code. Having `a.size()==0` and then access `a[0]` works in this particular case, but should probably be avoided to harden the code for the future. ACKs for top commit: theStack: re-ACK bitcoin/bitcoin@fa2ae0a elichai: ACK fa2ae0a jonatack: ACK fa2ae0a Tree-SHA512: 0ec7b09eef45504973a195923cdf1aa8522117c8e2f69b453e5ce9aa8a7e327c71138518022c32d05133dc99cb861101ed0f60fa891814ee3e9dab3a6fa61a84
2 parents 40a0481 + fa2ae0a commit 31d2b40

File tree

2 files changed

+5
-3
lines changed

2 files changed

+5
-3
lines changed

src/script/descriptor.cpp

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -825,8 +825,9 @@ std::unique_ptr<PubkeyProvider> ParsePubkey(uint32_t key_exp_index, const Span<c
825825
return nullptr;
826826
}
827827
if (origin_split.size() == 1) return ParsePubkeyInner(key_exp_index, origin_split[0], permit_uncompressed, out, error);
828-
if (origin_split[0].size() < 1 || origin_split[0][0] != '[') {
829-
error = strprintf("Key origin start '[ character expected but not found, got '%c' instead", origin_split[0][0]);
828+
if (origin_split[0].empty() || origin_split[0][0] != '[') {
829+
error = strprintf("Key origin start '[ character expected but not found, got '%c' instead",
830+
origin_split[0].empty() ? /** empty, implies split char */ ']' : origin_split[0][0]);
830831
return nullptr;
831832
}
832833
auto slash_split = Split(origin_split[0].subspan(1), '/');
@@ -896,7 +897,7 @@ std::unique_ptr<DescriptorImpl> ParseScript(uint32_t key_exp_index, Span<const c
896897
providers.emplace_back(std::move(pk));
897898
key_exp_index++;
898899
}
899-
if (providers.size() < 1 || providers.size() > 16) {
900+
if (providers.empty() || providers.size() > 16) {
900901
error = strprintf("Cannot have %u keys in multisig; must have between 1 and 16 keys, inclusive", providers.size());
901902
return nullptr;
902903
} else if (thres < 1) {

src/span.h

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -151,6 +151,7 @@ class Span
151151
return m_data[m_size - 1];
152152
}
153153
constexpr std::size_t size() const noexcept { return m_size; }
154+
constexpr bool empty() const noexcept { return size() == 0; }
154155
CONSTEXPR_IF_NOT_DEBUG C& operator[](std::size_t pos) const noexcept
155156
{
156157
ASSERT_IF_DEBUG(size() > pos);

0 commit comments

Comments
 (0)