Depends on #2316 and contains its commit, so only the last commit is new.
What is wrong
The BIP-375 validator does not read PSBT_IN_PARTIAL_SIG. Nothing checks that a P2PKH, P2WPKH or P2SH-P2WPKH program commits to its signing key. So master's vectors pass the test runner, although none of their P2WPKH programs matches its key and none of their signatures verifies. #2316 fixes those vectors.
What this changes
The test runner runs bip-0375/signatures.py on every vector. It checks that:
- a single-key program commits to the keys in
PSBT_IN_PARTIAL_SIGandPSBT_IN_BIP32_DERIVATION; - a P2SH program commits to
PSBT_IN_REDEEM_SCRIPT; - a signature's sighash byte equals
PSBT_IN_SIGHASH_TYPE, if set; - each signature verifies: BIP 143 for P2WPKH and P2SH-P2WPKH, legacy for P2PKH and bare scripts.
A signature the check cannot verify, such as one with no defined sighash, is a failure, not a skip. #2316 removed the two such signatures from the vectors.
The validator is unchanged. hash160 uses the pure Python RIPEMD-160 from bip-0352/, because hashlib lacks it on some OpenSSL builds.
How it was tested
- The runner reports 43 passed. Its
-vvoutput is identical to #2316's. - On master's vectors, 39 of 43 fail.
- One flipped byte in a P2PKH, P2WPKH, P2SH-P2WPKH or bare-script signature fails the vector. So does one flipped byte in a P2SH redeem script.
- An empty signature fails the vector.
#2256 and #2207 are built on master's vectors, so this check fails them until they are rebased onto #2316 and their P2WPKH inputs repaired.