Skip to content

Reject non-minimal Bitcoin CompactSize encodings - #19

Open
SashaMIT wants to merge 1 commit into
bitcoinjs:masterfrom
SashaMIT:codered-compactsize-minimal
Open

SashaMIT wants to merge 1 commit into
bitcoinjs:masterfrom
SashaMIT:codered-compactsize-minimal

Conversation

@SashaMIT

Copy link
Copy Markdown

Summary

decode() accepted a longer tag for a value that fits in a shorter one. fd0100, fe01000000, and ff0100000000000000 all decoded as 1. Bitcoin CompactSize rejects that. A 0xfd value must be at least 0xfd, a 0xfe value must be greater than 0xffff, and a 0xff value must be greater than 0xffffffff.

Test plan

  • Before the change those three buffers decoded as { numberValue: 1, bytes: 3|5|9 }
  • They now throw non-minimal encoding
  • npx tape test/*.js (92 tests OK), including the existing minimal vectors such as fdfd00

Made with Cursor

decode() accepted 0xfd 0x01 0x00 as 1. A longer tag must not encode a value that fits in a shorter tag.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant