Skip to content

backport: bitcoin#35984 - #7827

Open
PastaPastaPasta wants to merge 1 commit into
dashpay:developfrom
PastaPastaPasta:codex/security-psbt-single-guard
Open

PastaPastaPasta wants to merge 1 commit into
dashpay:developfrom
PastaPastaPasta:codex/security-psbt-single-guard

Conversation

@PastaPastaPasta

@PastaPastaPasta PastaPastaPasta commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Issue being fixed or feature implemented

When a signer explicitly requests SINGLE or SINGLE|ANYONECANPAY for a PSBT input that has no output at the same index, the legacy signature hash is the constant one, so the signature does not bind the transaction as the signer expects. SignTransaction() already skipped such inputs but SignPSBTInput() did not. Default ALL signing and the wallet's requested-sighash agreement checks limit exposure to explicit nondefault signing.

What was done?

Backport of bitcoin#35984.

The missing-output check moves into MutableTransactionSignatureCreator::CreateSig, so PSBT and raw transaction signing share the same refusal, and the redundant raw-signing check is removed.

Dash adaptations:

  • Uses nHashType & 0x1f with the legacy SignatureHash, since Dash lacks SIGHASH_OUTPUT_MASK and the upstream signing-options interface.
  • The regression test is ported for P2PKH only (Dash has no segwit or taproot) and extended with SINGLE|ANYONECANPAY, ALL and raw-signing controls.
  • Upstream's test_psbt_roundtrip/test_psbt_version UTXO-selection hunks are omitted, because those tests arrive with PSBTv2 (Implement BIP 370 PSBTv2 bitcoin/bitcoin#21283), which Dash does not have.

How Has This Been Tested?

On macOS arm64 with the existing depends prefix and --enable-werror:

  • Full make -j1 passed before and after the change.
  • The new signing scenario failed on the baseline in both legacy and descriptor modes (input 1 finalized under SINGLE) and passes after the fix.
  • rpc_psbt.py passed in both descriptor and legacy variants, including the SINGLE|ANYONECANPAY, ALL and raw-signing controls.
  • src/test/test_dash --run_test=sighash_tests,script_tests,psbt_wallet_tests passed.
  • Targeted Python lint, whitespace lint and git diff --check passed.

Breaking Changes

The shared signer refuses to create SINGLE signatures when the matching output is missing. No consensus or RPC schema changes.

Checklist:

  • I have performed a self-review of my own code
  • I have made corresponding changes to the documentation
  • I have assigned this pull request to a milestone (for repository code-owners and collaborators only)

🤖 Generated with Claude Code

@thepastaclaw

thepastaclaw commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

✅ Final review complete — no blockers (commit 59391d5) · triage: low

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: eeea32fb-7dd4-482e-a313-ecf0e2b2c1ba
📥 Commits

Reviewing files that changed from the base of the PR and between b88580c and 59391d5.

📒 Files selected for processing (1)
  • test/functional/rpc_psbt.py

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 0 remain after this review.


Walkthrough

CreateSig now rejects new SIGHASH_SINGLE signatures when the input has no corresponding output. SignTransaction attempts signature production for each input. A functional test checks PSBT and raw-transaction signing with SIGHASH_SINGLE, SIGHASH_SINGLE|ANYONECANPAY, and ALL.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: ⚪ Minimal · up to 59391

This backport makes PSBT and raw transaction signing consistently refuse SIGHASH_SINGLE signatures when the input has no matching output. No merge-blocking risk was found.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check Passed The title clearly identifies this change as a backport of Bitcoin PR #35984, which matches the primary purpose of the changeset.
Description check Passed The description directly explains the missing-output check, the shared signing change, Dash-specific adaptations, regression tests, and validation results.
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@thepastaclaw thepastaclaw left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Final validation — Phase 1 + Phase 2

Verified the complete two-file change at e5823ec against Bitcoin bitcoin#35984 and Dash's signing callers; no actionable defects were found. The omitted upstream UTXO-selection edits are explicitly excluded in the PR description and commit message, so they do not warrant a completeness finding. Validation was static only: the supplied CI snapshot shows successful container builds and formatting/title/merge checks, two queued manifest jobs, and no completed unit or functional test results.

Review provenance

Source: reviewer 1: glm-5.3-flash (agent: phase1-reviewer, role: general); reviewer 2: gpt-6.1-sol (agent: phase2-reviewer, role: general); reviewer 3: gpt-6.1-sol (agent: phase2-reviewer, role: backport-reviewer); reviewer 4: gpt-6.1-sol (agent: phase2-reviewer, role: dash-core-commit-history); final verifier: gpt-6.1-sol (agent: sol-verifier, role: final-verifier)

  • Triage: low by gpt-6.1-sol (effort low) — The diff moves a small missing-output guard into MutableTransactionSignatureCreator::CreateSig and adds focused regression coverage, making it contained and straightforward despite touching signing.
  • Phase 1 reviewers: glm-5.3-flash — general (completed, effort high); agent phase1-reviewer
  • Phase 1 model: glm-5.3-flash — zai quota: 5h 95% left, weekly 95% left; passed over gemini-3.8-flash-high (antigravity below 15% reserve: weekly 15% left, 5h 100% left)
  • Fresh verifier: gpt-6.1-sol — final-verifier; agent sol-verifier
  • Phase 2 reviewers: gpt-6.1-sol — general (completed, effort medium); agent phase2-reviewer, gpt-6.1-sol — backport-reviewer (completed, effort medium); agent phase2-reviewer, gpt-6.1-sol — dash-core-commit-history (completed, effort medium); agent phase2-reviewer

@thepastaclaw thepastaclaw added the pastaclaw:approved thepastaclaw's latest review approved this PR label Oct 7, 2026
@PastaPastaPasta
PastaPastaPasta force-pushed the codex/security-psbt-single-guard branch from e5823ec to 4e6d495 Compare October 8, 2026 23:49
@PastaPastaPasta PastaPastaPasta changed the title backport: guard SIGHASH_SINGLE signing (bitcoin#35984) backport: bitcoin#35984 Oct 8, 2026
@PastaPastaPasta PastaPastaPasta added this to the 24 milestone Oct 9, 2026

@thepastaclaw thepastaclaw left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-review — Final validation — Phase 1 + Phase 2

At head 4e6d495, the complete two-file diff correctly centralizes the missing-output SIGHASH_SINGLE refusal without changing consensus verification or ALL-based wallet and CoinJoin signing. The retained regression covers PSBT and raw signing, including SINGLE|ANYONECANPAY and ALL controls; the omitted upstream test-maintenance hunks are explicitly excluded in the PR description and do not warrant findings. Verification was static: the supplied CI snapshot reports successful completed builds, lint, and no-wallet tests, with wallet-enabled Linux tests, sanitizer tests, and the multiprocess build still pending.

🔴 0 blocking | 🟡 0 suggestion(s) | 💬 0 nitpick(s)

Review provenance

Source: reviewer 1: gemini-3.8-flash-high (agent: phase1-reviewer, role: general); reviewer 2: gpt-6.1-sol (agent: phase2-reviewer, role: general); reviewer 3: gpt-6.1-sol (agent: phase2-reviewer, role: backport-reviewer); reviewer 4: gpt-6.1-sol (agent: phase2-reviewer, role: dash-core-commit-history); reviewer 5: gpt-6.1-sol (agent: phase2-reviewer, role: general); reviewer 6: gpt-6.1-sol (agent: phase2-reviewer, role: backport-reviewer); reviewer 7: gpt-6.1-sol (agent: phase2-reviewer, role: dash-core-commit-history); final verifier: gpt-6.1-sol (agent: sol-verifier, role: final-verifier)

  • Triage: low by gpt-6.1-sol (effort low) — The change is a small, well-contained relocation of an existing SIGHASH_SINGLE guard into the shared signature creator, with focused regression coverage, rather than a large or intricate signature change.
  • Phase 1 reviewers: gemini-3.8-flash-high — general (completed, effort high); agent phase1-reviewer
  • Phase 1 model: gemini-3.8-flash-high — antigravity quota: weekly 74% left, 5h 36% left
  • Fresh final gate: an independent Phase-2 review ran after iterative findings were reconciled
  • Fresh verifier: gpt-6.1-sol — final-verifier; agent sol-verifier
  • Phase 2 reviewers: gpt-6.1-sol — general (completed, effort medium); agent phase2-reviewer, gpt-6.1-sol — backport-reviewer (completed, effort medium); agent phase2-reviewer, gpt-6.1-sol — dash-core-commit-history (completed, effort medium); agent phase2-reviewer, gpt-6.1-sol — general (completed, effort medium); agent phase2-reviewer, gpt-6.1-sol — backport-reviewer (completed, effort medium); agent phase2-reviewer, gpt-6.1-sol — dash-core-commit-history (completed, effort medium); agent phase2-reviewer
🤖 Prompt for all review comments with AI agents
These findings are from an automated code review. Verify the current code and confirm that no unresolved issues remain.

No unresolved findings remain from the prior review on this head.

@PastaPastaPasta
PastaPastaPasta force-pushed the codex/security-psbt-single-guard branch from 4e6d495 to b88580c Compare October 9, 2026 01:48
… corresponding output

8df006f wallet: skip signing SIGHASH_SINGLE inputs with no corresponding output (furszy)

Pull request description:

  `SIGHASH_SINGLE` only commits to the output at the input's index. If the output at such
  position doesn't exist, it commits to no output at all (legacy uses a fixed sighash of 1, segwit
  v0 zeroes `hashOutputs`), which means the signature stays valid even when outputs are
  swapped, which is a footgun that lets funds be redirected without the owner's consent.

  `SignTransaction()` already skipped these inputs, but `SignPSBTInput()` did not, so
  `walletprocesspsbt` signed them. This moves the check into the `CreateSig` so both
  paths, and any future one, skip producing the detached signature.

  Note: if there is a valid use for the segwit v0 case, I would rather re-allow it through
  an explicit opt-in arg than by default, so it is always a deliberate choice.

  Fixes bitcoin#35977

ACKs for top commit:
  thomasbuilds:
    ACK 8df006f
  achow101:
    ACK 8df006f

Tree-SHA512: ac1c9659910eae889475c65b8dde68e711c4d85d0d520af06411728591e573bf027b41a9ac6dd0f6e93de425841ac6c7d9e6c9f07936b9d8ae390941fbe6f1f1

BACKPORT NOTE:
- src/script/sign.cpp: Dash has no SignOptions or SIGHASH_DEFAULT, so the
  check uses nHashType. Dash also has no SIGHASH_OUTPUT_MASK (added with
  Taproot), so it tests (nHashType & 0x1f), the same test Dash's legacy
  SignatureHash uses for SIGHASH_SINGLE. For every sighash the wallet can
  sign with (ALL/NONE/SINGLE, optionally |ANYONECANPAY) this matches
  upstream's (hashtype & SIGHASH_OUTPUT_MASK).
- test/functional/rpc_psbt.py, test_sighash_single():
  - No loop over legacy/bech32/bech32m address types; Dash only has P2PKH.
    Instead the test covers SINGLE, SINGLE|ANYONECANPAY and ALL (control),
    and also checks signrawtransactionwithwallet, because this change
    removes SignTransaction's own SIGHASH_SINGLE check and Dash had no test
    for that path.
  - It runs after test_input_confs_control; Dash has none of the sighash
    tests upstream places it next to.
  - Omitted: the test_psbt_roundtrip and test_psbt_version UTXO selection
    changes; those tests (PSBTv2) do not exist in Dash.

Co-authored-by: Ava Chow <github@achow101.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@PastaPastaPasta
PastaPastaPasta force-pushed the codex/security-psbt-single-guard branch from b88580c to 59391d5 Compare October 9, 2026 02:09

@thepastaclaw thepastaclaw left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-review — Final validation — Phase 1 + Phase 2

Verified the complete diff at 59391d5 against the upstream merge and surrounding signing paths; no actionable defects were found. The shared refusal matches Dash's legacy signature-hash semantics, and the omitted PSBTv2 test-fixture changes are explicitly documented intentional exclusions. This was a static review: the supplied CI snapshot shows successful lint and several platform builds, with three test jobs and additional builds still pending.

🔴 0 blocking | 🟡 0 suggestion(s) | 💬 0 nitpick(s)

Review provenance

Source: reviewer 1: gemini-3.8-flash-high (agent: phase1-reviewer, role: general); reviewer 2: gpt-6.1-sol (agent: phase2-reviewer, role: general); reviewer 3: gpt-6.1-sol (agent: phase2-reviewer, role: backport-reviewer); reviewer 4: gpt-6.1-sol (agent: phase2-reviewer, role: dash-core-commit-history); reviewer 5: gpt-6.1-sol (agent: phase2-reviewer, role: general); reviewer 6: gpt-6.1-sol (agent: phase2-reviewer, role: backport-reviewer); reviewer 7: gpt-6.1-sol (agent: phase2-reviewer, role: dash-core-commit-history); final verifier: gpt-6.1-sol (agent: sol-verifier, role: final-verifier)

  • Triage: low by gpt-6.1-sol (effort low) — The change moves a small, straightforward missing-output guard into the shared signature creator and adds focused regression tests, without the size or intricacy required for critical.
  • Phase 1 reviewers: gemini-3.8-flash-high — general (completed, effort high); agent phase1-reviewer
  • Phase 1 model: gemini-3.8-flash-high — antigravity quota: weekly 69% left, 5h 90% left
  • Fresh final gate: an independent Phase-2 review ran after iterative findings were reconciled
  • Fresh verifier: gpt-6.1-sol — final-verifier; agent sol-verifier
  • Phase 2 reviewers: gpt-6.1-sol — general (completed, effort medium); agent phase2-reviewer, gpt-6.1-sol — backport-reviewer (completed, effort medium); agent phase2-reviewer, gpt-6.1-sol — dash-core-commit-history (completed, effort medium); agent phase2-reviewer, gpt-6.1-sol — general (completed, effort medium); agent phase2-reviewer, gpt-6.1-sol — backport-reviewer (completed, effort medium); agent phase2-reviewer, gpt-6.1-sol — dash-core-commit-history (completed, effort medium); agent phase2-reviewer
🤖 Prompt for all review comments with AI agents
These findings are from an automated code review. Verify the current code and confirm that no unresolved issues remain.

No unresolved findings remain from the prior review on this head.
Out-of-scope follow-up suggestions (1)

These are valid observations, but they are outside this PR's scope and should be handled in separate issues or author/maintainer-requested PRs rather than blocking this review.

  • Declared omission: PSBTv2-dependent upstream test transformations — INTENTIONAL_EXCLUSION: The supplied PR description explicitly states that upstream's test_psbt_roundtrip/test_psbt_version UTXO-selection hunks are omitted because their PSBTv2 tests are absent; HEAD's BACKPORT NOTE repeats this exclusion. Comparing upstream merge e19f83e with its first parent confirms that these two hunks replace listunspent()[0] with selection by amount == Decimal(50). The tests were introduced by 8838418 and bcc1dca, both verified ancestors of the bitcoin#21283 merge d7ed284. Neither test exists in Dash's base f35a24c or exact head, and base-history git log -S searches show no introduction. Their omission is therefore an expressly bounded backport exception, not an undisclosed prerequisite gap; requesting future PSBTv2 work is outside this fix's scope.
    • Follow-up: Consider creating a separate issue or author/maintainer-requested PR for this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport-candidate-24.0.x pastaclaw:approved thepastaclaw's latest review approved this PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants