diff options
author | Ethan Buchman <ethan@coinculture.info> | 2015-03-19 11:56:06 +0800 |
---|---|---|
committer | Ethan Buchman <ethan@coinculture.info> | 2015-03-23 05:54:40 +0800 |
commit | d2fa6e7753deb0f7fe5e1d802460c88c2885b954 (patch) | |
tree | 26bdff963b0dc8e26da5d880a42b84b153b09a1c | |
parent | 8ed4f226d1dbecc9625a2f142e22926569198b73 (diff) | |
download | go-tangerine-d2fa6e7753deb0f7fe5e1d802460c88c2885b954.tar go-tangerine-d2fa6e7753deb0f7fe5e1d802460c88c2885b954.tar.gz go-tangerine-d2fa6e7753deb0f7fe5e1d802460c88c2885b954.tar.bz2 go-tangerine-d2fa6e7753deb0f7fe5e1d802460c88c2885b954.tar.lz go-tangerine-d2fa6e7753deb0f7fe5e1d802460c88c2885b954.tar.xz go-tangerine-d2fa6e7753deb0f7fe5e1d802460c88c2885b954.tar.zst go-tangerine-d2fa6e7753deb0f7fe5e1d802460c88c2885b954.zip |
vm: explicit error checks in ecrecover. closes #505
-rw-r--r-- | vm/address.go | 28 |
1 files changed, 21 insertions, 7 deletions
diff --git a/vm/address.go b/vm/address.go index 215f4bc8f..e4c33ec80 100644 --- a/vm/address.go +++ b/vm/address.go @@ -3,8 +3,8 @@ package vm import ( "math/big" - "github.com/ethereum/go-ethereum/crypto" "github.com/ethereum/go-ethereum/common" + "github.com/ethereum/go-ethereum/crypto" ) type Address interface { @@ -61,15 +61,29 @@ func ripemd160Func(in []byte) []byte { return common.LeftPadBytes(crypto.Ripemd160(in), 32) } -func ecrecoverFunc(in []byte) []byte { - // In case of an invalid sig. Defaults to return nil - defer func() { recover() }() +const EcRecoverInputLength = 128 +func ecrecoverFunc(in []byte) []byte { + // "in" is (hash, v, r, s), each 32 bytes + // but for ecrecover we want (r, s, v) + if len(in) < EcRecoverInputLength { + return nil + } hash := in[:32] - v := common.BigD(in[32:64]).Bytes()[0] - 27 + // v is only a bit, but comes as 32 bytes from vm. We only need least significant byte + encodedV := in[32:64] + v := encodedV[31] - 27 + if !(v == 0 || v == 1) { + return nil + } sig := append(in[64:], v) - - return common.LeftPadBytes(crypto.Sha3(crypto.Ecrecover(append(hash, sig...))[1:])[12:], 32) + pubKey := crypto.Ecrecover(append(hash, sig...)) + // secp256.go returns either nil or 65 bytes + if pubKey == nil || len(pubKey) != 65 { + return nil + } + // the first byte of pubkey is bitcoin heritage + return common.LeftPadBytes(crypto.Sha3(pubKey[1:])[12:], 32) } func memCpy(in []byte) []byte { |