Follow up to #9485, which fixed truncated Bitcoin blocks. The same kind of bad block still crashed the Elements/Liquid header parser:
The challenge and dynafed fields were hashed before pull() checked the length. A truncated header caused a heap over-read, then a NULL dereference (sha256_update(shactx, NULL, 4))
A zero-length pull() after an earlier failure hit assert(p)
The extension-space and signblock witness counts come straight from the block, so a bad varint could loop up to 2^64 times
Separately, for all chains, a huge tx count made tal_arr() overflow and abort
As in #9485, this needs the chain backend to serve a bad block. A peer cannot trigger it
Fix
Add pull_and_hash(), which hashes only the bytes that pull() returns, and use it for all hashed header fields
Make pull() fail cleanly when the cursor is already NULL
Stop the two count-driven loops once the data runs out
Reject a tx count larger than the remaining bytes
Testing
run-bitcoin_block_from_hex now builds small liquid-regtest blocks (with and without dynafed) and checks that each one parses and that every truncation of it is rejected. It also checks huge extension space, signblock-witness and tx counts. Disabling any single part of the fix makes the test abort, segfault or hang
Important
26.09 FREEZE August 5th: Non-bugfix PRs not ready by this date will wait for 26.12.
RC1 is scheduled on August 17th
The final release is scheduled for September 7th.
Checklist
Before submitting the PR, ensure the following tasks are completed. If an item is not applicable to your PR, please mark it as checked:
The changelog has been updated in the relevant commit(s) according to the guidelines.
Tests have been added or modified to reflect the changes.
Documentation has been reviewed and updated as needed.
Related issues have been listed and linked, including any that this PR closes.
Important All PRs must consider how to reverse any persistent changes for tools/lightning-downgrade
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Follow up to #9485, which fixed truncated Bitcoin blocks. The same kind of bad block still crashed the Elements/Liquid header parser:
Separately, for all chains, a huge tx count made tal_arr() overflow and abort
As in #9485, this needs the chain backend to serve a bad block. A peer cannot trigger it
Fix
Testing
run-bitcoin_block_from_hex now builds small liquid-regtest blocks (with and without dynafed) and checks that each one parses and that every truncation of it is rejected. It also checks huge extension space, signblock-witness and tx counts. Disabling any single part of the fix makes the test abort, segfault or hang
Important
26.09 FREEZE August 5th: Non-bugfix PRs not ready by this date will wait for 26.12.
RC1 is scheduled on August 17th
The final release is scheduled for September 7th.
Checklist
Before submitting the PR, ensure the following tasks are completed. If an item is not applicable to your PR, please mark it as checked: