bip-0375: check test vector signatures in the test runner #2317

pull fametrano wants to merge 2 commits into bitcoin:master from fametrano:bip375-check-signatures-v2 changing 6 files +606 −127
  1. fametrano commented at 8:36 PM on September 29, 2026: contributor

    Depends on #2316 and contains its commit, so only the last commit is new.

    What is wrong

    The BIP-375 validator does not read PSBT_IN_PARTIAL_SIG. Nothing checks that a P2PKH, P2WPKH or P2SH-P2WPKH program commits to its signing key. So master's vectors pass the test runner, although none of their P2WPKH programs matches its key and none of their signatures verifies. #2316 fixes those vectors.

    What this changes

    The test runner runs bip-0375/signatures.py on every vector. It checks that:

    • a single-key program commits to the keys in PSBT_IN_PARTIAL_SIG and PSBT_IN_BIP32_DERIVATION;
    • a P2SH program commits to PSBT_IN_REDEEM_SCRIPT;
    • a signature's sighash byte equals PSBT_IN_SIGHASH_TYPE, if set;
    • each signature verifies: BIP 143 for P2WPKH and P2SH-P2WPKH, legacy for P2PKH and bare scripts.

    A signature the check cannot verify, such as one with no defined sighash, is a failure, not a skip. #2316 removed the two such signatures from the vectors.

    The validator is unchanged. hash160 uses the pure Python RIPEMD-160 from bip-0352/, because hashlib lacks it on some OpenSSL builds.

    How it was tested

    • The runner reports 43 passed. Its -vv output is identical to #2316's.
    • On master's vectors, 39 of 43 fail.
    • One flipped byte in a P2PKH, P2WPKH, P2SH-P2WPKH or bare-script signature fails the vector. So does one flipped byte in a P2SH redeem script.
    • An empty signature fails the vector.

    #2256 and #2207 are built on master's vectors, so this check fails them until they are rebased onto #2316 and their P2WPKH inputs repaired.

  2. bip-0375: fix P2WPKH scriptPubKeys and signatures in test vectors
    The P2WPKH inputs of the test vectors spend a witness program equal to
    SHA256(pubkey)[:20] instead of HASH160(pubkey), so the key each input
    carries cannot spend it. None of the stored ECDSA signatures verifies
    against the transaction its PSBT describes, whatever the input type. The
    reference validator does not check signatures, so no test fails.
    
    Set every P2WPKH witness program to HASH160 of the input's public key,
    in PSBT_IN_WITNESS_UTXO and in the supplementary witness_utxo and
    prevout_scriptpubkey. Re-sign the PSBT_IN_PARTIAL_SIG signatures
    deterministically (RFC 6979, low S): BIP 143 for P2WPKH and P2SH-P2WPKH,
    the legacy signature hash for P2PKH and for the bare OP_2 input. Where
    an input sets PSBT_IN_SIGHASH_TYPE, its signature uses that type, as BIP
    174 requires.
    
    Two vectors carried a signature with no defined signature hash: one on
    a segwit v2 input, one in the vector whose output lacks PSBT_OUT_SCRIPT.
    Remove both signatures, and mark the segwit v2 input as not signed in
    the supplementary material. Both vectors still fail for their stated
    reason.
    
    Inside the PSBTs only PSBT_IN_WITNESS_UTXO and PSBT_IN_PARTIAL_SIG
    change, and the test runner's result for every vector is unchanged.
    d4d3e08e38
  3. bip-0375: check test vector signatures in the test runner
    The validator does not read PSBT_IN_PARTIAL_SIG. Nothing checks that a
    P2PKH, P2WPKH or P2SH-P2WPKH program commits to its signing key. So the
    wrong programs and signatures that the parent commit corrects pass the
    test runner.
    
    Add signatures.py. The test runner applies it to every vector. It
    checks that:
    - a single-key program commits to the keys in PSBT_IN_PARTIAL_SIG and
      PSBT_IN_BIP32_DERIVATION;
    - a P2SH program commits to PSBT_IN_REDEEM_SCRIPT;
    - a signature's sighash byte equals PSBT_IN_SIGHASH_TYPE, if set;
    - each signature verifies: BIP 143 for P2WPKH and P2SH-P2WPKH, the
      legacy sighash for P2PKH and bare scripts.
    
    A signature the check cannot verify is a failure. The validator is
    unchanged.
    
    hash160 uses the pure Python RIPEMD-160 from bip-0352. hashlib lacks
    RIPEMD-160 on some OpenSSL builds.
    5143bdba1d

github-metadata-mirror

This is a metadata mirror of the GitHub repository bitcoin/bips. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2026-10-03 06:10 UTC

This site is hosted by @0xB10C
More mirrored repositories can be found on mirror.b10c.me