test: add tests in script test suites covering script.cpp live mutants #36360

pull Yudis-bit wants to merge 4 commits into bitcoin:master from Yudis-bit:test-script-coverage-mutants changing 4 files +161 −0
  1. Yudis-bit commented at 6:12 PM on September 27, 2026: none

    Kills several live mutants in src/script/script.cpp found on https://bitcoincore.space/public/mutation_data.json. They are:

    <details> <summary><a href="https://bitcoincore.space/src/script/script.cpp#2346">script.cpp#2346, 2347, 2348</a>: <code>CScript::IsPayToTaproot</code>: size and opcode check operators</summary>

    diff --git a/src/script/script.cpp b/src/script/script.cpp
    --- a/src/script/script.cpp
    +++ b/src/script/script.cpp
    @@ -242,3 +242,3 @@ bool CScript::IsPayToTaproot() const
    -    return this->size() == 34 &&
    -           (*this)[0] == OP_1 &&
    -           (*this)[1] == 0x20;
    +    return this->size() == 34 ||
    +           (*this)[0] == OP_1 &&
    +           (*this)[1] != 0x20;
    

    Covered in src/test/script_segwit_tests.cpp (commit accf04f6e).

    </details>

    <details> <summary><a href="https://bitcoincore.space/src/script/script.cpp#2326">script.cpp#2326</a>: <code>GetSigOpCount</code>: evaluate scriptSig accurately</summary>

    diff --git a/src/script/script.cpp b/src/script/script.cpp
    --- a/src/script/script.cpp
    +++ b/src/script/script.cpp
    @@ -194,3 +194,3 @@ unsigned int CScript::GetSigOpCount(const CScript& scriptSig) const
         if (!IsPayToScriptHash())
    -        return GetSigOpCount(true);
    +        return GetSigOpCount(false);
         if (scriptSig.IsPushOnly()) {
    

    Covered in src/test/sigopcount_tests.cpp (commit b9ad09fe3).

    </details>

    <details> <summary><a href="https://bitcoincore.space/src/script/script.cpp#2325">script.cpp#2325, 2328</a>: <code>GetSigOpCount</code>: multisig boundary checks (OP_1 and OP_16)</summary>

    diff --git a/src/script/script.cpp b/src/script/script.cpp
    --- a/src/script/script.cpp
    +++ b/src/script/script.cpp
    @@ -179,3 +179,3 @@ unsigned int CScript::GetSigOpCount(bool fAccurate) const
    -            if (lastOpcode >= OP_1 && lastOpcode <= OP_16)
    +            if (lastOpcode > OP_1 && lastOpcode <= OP_16)
                     n += CScript::DecodeOP_N(lastOpcode);
    
    diff --git a/src/script/script.cpp b/src/script/script.cpp
    --- a/src/script/script.cpp
    +++ b/src/script/script.cpp
    @@ -204,3 +204,3 @@ unsigned int CScript::GetSigOpCount(const CScript& scriptSig) const
    -                if (opcode > OP_16)
    +                if (opcode >= OP_16)
                         return n;
    

    Covered in src/test/sigopcount_tests.cpp (commit b9ad09fe3).

    </details>

    <details> <summary><a href="https://bitcoincore.space/src/script/script.cpp#2337">script.cpp#2337</a>: <code>IsPayToAnchor</code>: payload byte matching conjunction</summary>

    diff --git a/src/script/script.cpp b/src/script/script.cpp
    --- a/src/script/script.cpp
    +++ b/src/script/script.cpp
    @@ -231,4 +231,4 @@ bool CScript::IsPayToAnchor(int version, Span<const unsigned char> program)
         return version == 1 &&
                program.size() == 2 &&
    -           program[0] == 0x4e &&
    +           (program[0] == 0x4e ||
                program[1] == 0x73);
    

    Covered in src/test/script_standard_tests.cpp (commit 559809edd).

    </details>

    <details> <summary><a href="https://bitcoincore.space/src/script/script.cpp#2365">script.cpp#2365</a>: <code>CScript::HasValidOps</code>: MAX_OPCODE boundary check</summary>

    diff --git a/src/script/script.cpp b/src/script/script.cpp
    --- a/src/script/script.cpp
    +++ b/src/script/script.cpp
    @@ -311,3 +311,3 @@ bool CScript::HasValidOps() const
         while (GetOp(it, opcode)) {
    -        if (opcode > MAX_OPCODE)
    +        if (opcode >= MAX_OPCODE)
                 return false;
    

    Covered in src/test/script_tests.cpp (commit ec4d7b3bd).

    </details>

    <details> <summary><a href="https://bitcoincore.space/src/script/script.cpp#2372">script.cpp#2372, 2377, 2380, 2383</a>: <code>CScript::GetOp</code>: truncated pushdata lengths</summary>

    diff --git a/src/script/script.cpp b/src/script/script.cpp
    --- a/src/script/script.cpp
    +++ b/src/script/script.cpp
    @@ -49,3 +49,3 @@ bool CScript::GetOp(const_iterator& pc, opcodetype& opcodeRet, std::vector<unsi
             if (opcode >= 0 && opcode <= OP_PUSHDATA4) {
    -            if (pc + nSize > pend)
    +            if (false)
                     return false;
    

    Covered in src/test/script_tests.cpp (commit ec4d7b3bd).

    </details>

    <details> <summary><a href="https://bitcoincore.space/src/script/script.cpp#2362">script.cpp#2362</a>: <code>CScriptWitness::ToString</code>: stack element delimiter condition</summary>

    diff --git a/src/script/script.cpp b/src/script/script.cpp
    --- a/src/script/script.cpp
    +++ b/src/script/script.cpp
    @@ -342,3 +342,3 @@ std::string CScriptWitness::ToString() const
         for (unsigned i = 0; i < stack.size(); i++) {
    -        if (i)
    +        if (1 == 1)
                 ret += ", ";
    

    Covered in src/test/script_tests.cpp (commit ec4d7b3bd).

    </details>

    Recommend reviewing per commit.

  2. test: cover CScript::IsPayToTaproot edge cases and malformed encodings
    Add unit test coverage for CScript::IsPayToTaproot() in script_segwit_tests:
    - Valid 34-byte SegWit v1 witness program (OP_1 0x20 <32-byte-key>).
    - Rejection of non-v1 witness programs (OP_0, OP_2, OP_16).
    - Rejection of mismatched program sizes (31, 33, and 34 bytes without OP_1 0x20).
    - Rejection of superfluous opcodes (OP_NOP) and empty scripts.
    - Rejection of pushdata-encoded 32-byte payloads (OP_PUSHDATA1/2/4).
    
    Kills live mutants 2346, 2347, and 2348 in src/script/script.cpp.
    accf04f6ee
  3. test: cover GetSigOpCount non-P2SH scriptSig and boundary multisig
    Add unit tests in sigopcount_tests:
    - Verify that non-P2SH scriptSig evaluation accurately accounts for sigops
      via GetSigOpCount(scriptSig), covering accurate counting logic.
    - Verify 1-of-1 multisig accurate counting where lastOpcode is OP_1.
    - Verify 16-of-16 multisig in P2SH scriptSig where opcode equals OP_16.
    
    Kills live mutants 2325, 2326, and 2328 in src/script/script.cpp.
    b9ad09fe3d
  4. test: cover IsPayToAnchor byte mismatches, versions, and lengths
    Add unit tests in script_standard_tests:
    - Verify Solver() and IsPayToAnchor() rejection of single-byte payload
      mismatches {0x4e, 0x00} and {0x00, 0x73} against ANCHOR_BYTES {0x4e, 0x73}.
    - Verify static CScript::IsPayToAnchor() rejection across invalid witness
      versions (0, 2) and invalid payload lengths (1, 3).
    
    Kills live mutant 2337 in src/script/script.cpp.
    559809edd2
  5. test: cover MAX_OPCODE boundary, truncated pushdata, and witness ToString
    Add unit tests in script_tests:
    - Verify MAX_OPCODE boundary in CScript::HasValidOps(): OP_NOP10 (0xb9)
      is valid while 0xba is rejected.
    - Verify CScript::GetOp() returns false on truncated OP_PUSHDATA1,
      OP_PUSHDATA2, and OP_PUSHDATA4 sequences missing length/payload bytes.
    - Verify CScriptWitness::ToString() formatting for empty, single, and
      multi-element witness stacks.
    
    Kills live mutants 2362, 2365, 2372, 2377, 2380, and 2383 in src/script/script.cpp.
    ec4d7b3bda
  6. Yudis-bit requested review from Copilot on Sep 27, 2026
  7. DrahtBot added the label Tests on Sep 27, 2026
  8. Copilot commented at 6:12 PM on September 27, 2026: none

    Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

  9. DrahtBot commented at 6:12 PM on September 27, 2026: contributor

    <!--e57a25ab6845829454e8d69fc972939a-->

    The following sections might be updated with supplementary metadata relevant to reviewers and maintainers.

    <!--006a51241073e994b41acfe9ec718e94-->

    Code Coverage & Benchmarks

    For details see: https://corecheck.dev/bitcoin/bitcoin/pulls/36360.

    <!--021abf342d371248e50ceaed478a90ca-->

    Reviews

    See the guideline and AI policy for information on the review process. A summary of reviews will appear here.

    <!--5faf32d7da4f0f540f40219e4f7537a3-->

  10. fanquake commented at 7:02 PM on September 27, 2026: member

github-metadata-mirror

This is a metadata mirror of the GitHub repository bitcoin/bitcoin. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2026-09-28 10:51 UTC

This site is hosted by @0xB10C
More mirrored repositories can be found on mirror.b10c.me