Skip to content

Commit dc2fdb9

Browse files
tests: Add fuzzing harness for various CScript related functions
1 parent fce7c75 commit dc2fdb9

File tree

2 files changed

+71
-0
lines changed

2 files changed

+71
-0
lines changed

src/Makefile.test.include

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,7 @@ FUZZ_TARGETS = \
2222
test/fuzz/inv_deserialize \
2323
test/fuzz/messageheader_deserialize \
2424
test/fuzz/netaddr_deserialize \
25+
test/fuzz/script \
2526
test/fuzz/script_flags \
2627
test/fuzz/service_deserialize \
2728
test/fuzz/spanparsing \
@@ -268,6 +269,12 @@ test_fuzz_netaddr_deserialize_CXXFLAGS = $(AM_CXXFLAGS) $(PIE_FLAGS)
268269
test_fuzz_netaddr_deserialize_LDFLAGS = $(RELDFLAGS) $(AM_LDFLAGS) $(LIBTOOL_APP_LDFLAGS)
269270
test_fuzz_netaddr_deserialize_LDADD = $(FUZZ_SUITE_LD_COMMON)
270271

272+
test_fuzz_script_SOURCES = $(FUZZ_SUITE) test/fuzz/script.cpp
273+
test_fuzz_script_CPPFLAGS = $(AM_CPPFLAGS) $(BITCOIN_INCLUDES)
274+
test_fuzz_script_CXXFLAGS = $(AM_CXXFLAGS) $(PIE_FLAGS)
275+
test_fuzz_script_LDFLAGS = $(RELDFLAGS) $(AM_LDFLAGS) $(LIBTOOL_APP_LDFLAGS)
276+
test_fuzz_script_LDADD = $(FUZZ_SUITE_LD_COMMON)
277+
271278
test_fuzz_script_flags_SOURCES = $(FUZZ_SUITE) test/fuzz/script_flags.cpp
272279
test_fuzz_script_flags_CPPFLAGS = $(AM_CPPFLAGS) $(BITCOIN_INCLUDES)
273280
test_fuzz_script_flags_CXXFLAGS = $(AM_CXXFLAGS) $(PIE_FLAGS)

src/test/fuzz/script.cpp

Lines changed: 64 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,64 @@
1+
// Copyright (c) 2019 The Bitcoin Core developers
2+
// Distributed under the MIT software license, see the accompanying
3+
// file COPYING or http://www.opensource.org/licenses/mit-license.php.
4+
5+
#include <chainparams.h>
6+
#include <compressor.h>
7+
#include <core_io.h>
8+
#include <core_memusage.h>
9+
#include <policy/policy.h>
10+
#include <pubkey.h>
11+
#include <script/descriptor.h>
12+
#include <script/script.h>
13+
#include <script/sign.h>
14+
#include <script/signingprovider.h>
15+
#include <script/standard.h>
16+
#include <streams.h>
17+
#include <test/fuzz/fuzz.h>
18+
#include <util/memory.h>
19+
20+
void initialize()
21+
{
22+
// Fuzzers using pubkey must hold an ECCVerifyHandle.
23+
static const auto verify_handle = MakeUnique<ECCVerifyHandle>();
24+
}
25+
26+
void test_one_input(const std::vector<uint8_t>& buffer)
27+
{
28+
const CScript script(buffer.begin(), buffer.end());
29+
30+
std::vector<unsigned char> compressed;
31+
(void)CompressScript(script, compressed);
32+
33+
CTxDestination address;
34+
(void)ExtractDestination(script, address);
35+
36+
txnouttype type_ret;
37+
std::vector<CTxDestination> addresses;
38+
int required_ret;
39+
(void)ExtractDestinations(script, type_ret, addresses, required_ret);
40+
41+
(void)GetScriptForWitness(script);
42+
43+
const FlatSigningProvider signing_provider;
44+
(void)InferDescriptor(script, signing_provider);
45+
46+
(void)IsSegWitOutput(signing_provider, script);
47+
48+
(void)IsSolvable(signing_provider, script);
49+
50+
txnouttype which_type;
51+
(void)IsStandard(script, which_type);
52+
53+
(void)RecursiveDynamicUsage(script);
54+
55+
std::vector<std::vector<unsigned char>> solutions;
56+
(void)Solver(script, solutions);
57+
58+
(void)script.HasValidOps();
59+
(void)script.IsPayToScriptHash();
60+
(void)script.IsPayToWitnessScriptHash();
61+
(void)script.IsPushOnly();
62+
(void)script.IsUnspendable();
63+
(void)script.GetSigOpCount(/* fAccurate= */ false);
64+
}

0 commit comments

Comments
 (0)