2022-06-29 04:05:31 +00:00
|
|
|
// Written in 2014 by Andrew Poelstra <apoelstra@wpsoftware.net>
|
|
|
|
// SPDX-License-Identifier: CC0-1.0
|
2022-01-09 06:50:02 +00:00
|
|
|
|
|
|
|
//! ECDSA Bitcoin signatures.
|
|
|
|
//!
|
|
|
|
//! This module provides ECDSA signatures used Bitcoin that can be roundtrip (de)serialized.
|
|
|
|
|
|
|
|
use core::str::FromStr;
|
2022-01-13 04:27:20 +00:00
|
|
|
use core::{fmt, iter};
|
2022-06-29 04:54:54 +00:00
|
|
|
|
2022-09-05 02:19:28 +00:00
|
|
|
use bitcoin_internals::write_err;
|
2023-02-18 11:31:07 +00:00
|
|
|
use bitcoin_internals::hex::display::DisplayHex;
|
2022-06-29 04:54:54 +00:00
|
|
|
use secp256k1;
|
|
|
|
|
|
|
|
use crate::prelude::*;
|
2022-05-02 22:13:57 +00:00
|
|
|
use crate::hashes::hex::{self, FromHex};
|
2022-10-24 22:14:01 +00:00
|
|
|
use crate::sighash::{EcdsaSighashType, NonStandardSighashType};
|
2023-02-18 11:43:13 +00:00
|
|
|
use crate::script::PushBytes;
|
2022-01-09 06:50:02 +00:00
|
|
|
|
2023-02-18 11:31:07 +00:00
|
|
|
const MAX_SIG_LEN: usize = 73;
|
|
|
|
|
2022-01-09 06:50:02 +00:00
|
|
|
/// An ECDSA signature with the corresponding hash type.
|
2022-05-06 03:37:24 +00:00
|
|
|
#[derive(Debug, Copy, Clone, PartialEq, Eq, Hash)]
|
2022-01-09 06:50:02 +00:00
|
|
|
#[cfg_attr(feature = "serde", derive(Serialize, Deserialize))]
|
2022-05-25 06:41:59 +00:00
|
|
|
#[cfg_attr(feature = "serde", serde(crate = "actual_serde"))]
|
2022-11-08 00:36:52 +00:00
|
|
|
pub struct Signature {
|
2022-01-09 06:50:02 +00:00
|
|
|
/// The underlying ECDSA Signature
|
|
|
|
pub sig: secp256k1::ecdsa::Signature,
|
|
|
|
/// The corresponding hash type
|
2022-03-28 21:48:53 +00:00
|
|
|
pub hash_ty: EcdsaSighashType,
|
2022-01-09 06:50:02 +00:00
|
|
|
}
|
|
|
|
|
2022-11-08 00:36:52 +00:00
|
|
|
impl Signature {
|
2022-01-07 02:58:47 +00:00
|
|
|
/// Constructs an ECDSA bitcoin signature for [`EcdsaSighashType::All`].
|
2022-11-08 00:36:52 +00:00
|
|
|
pub fn sighash_all(sig: secp256k1::ecdsa::Signature) -> Signature {
|
|
|
|
Signature {
|
2022-01-09 06:50:02 +00:00
|
|
|
sig,
|
2022-03-28 21:48:53 +00:00
|
|
|
hash_ty: EcdsaSighashType::All
|
2022-01-09 06:50:02 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-01-07 02:58:47 +00:00
|
|
|
/// Deserializes from slice following the standardness rules for [`EcdsaSighashType`].
|
2022-11-08 00:36:52 +00:00
|
|
|
pub fn from_slice(sl: &[u8]) -> Result<Self, Error> {
|
2022-01-09 06:50:02 +00:00
|
|
|
let (hash_ty, sig) = sl.split_last()
|
2022-11-08 00:36:52 +00:00
|
|
|
.ok_or(Error::EmptySignature)?;
|
2022-03-28 21:48:53 +00:00
|
|
|
let hash_ty = EcdsaSighashType::from_standard(*hash_ty as u32)
|
2022-11-08 00:36:52 +00:00
|
|
|
.map_err(|_| Error::NonStandardSighashType(*hash_ty as u32))?;
|
2022-01-09 06:50:02 +00:00
|
|
|
let sig = secp256k1::ecdsa::Signature::from_der(sig)
|
2022-11-08 00:36:52 +00:00
|
|
|
.map_err(Error::Secp256k1)?;
|
|
|
|
Ok(Signature { sig, hash_ty })
|
2022-01-09 06:50:02 +00:00
|
|
|
}
|
|
|
|
|
2022-01-07 02:58:47 +00:00
|
|
|
/// Serializes an ECDSA signature (inner secp256k1 signature in DER format).
|
2023-02-18 11:31:07 +00:00
|
|
|
///
|
|
|
|
/// This does **not** perform extra heap allocation.
|
|
|
|
pub fn serialize(&self) -> SerializedSignature {
|
|
|
|
let mut buf = [0u8; MAX_SIG_LEN];
|
|
|
|
let signature = self.sig.serialize_der();
|
|
|
|
buf[..signature.len()].copy_from_slice(&signature);
|
|
|
|
buf[signature.len()] = self.hash_ty as u8;
|
|
|
|
SerializedSignature {
|
|
|
|
data: buf,
|
|
|
|
len: signature.len() + 1,
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/// Serializes an ECDSA signature (inner secp256k1 signature in DER format) into `Vec`.
|
|
|
|
///
|
|
|
|
/// Note: this performs an extra heap allocation, you might prefer the
|
|
|
|
/// [`serialize`](Self::serialize) method instead.
|
2022-08-01 22:33:22 +00:00
|
|
|
pub fn to_vec(self) -> Vec<u8> {
|
2022-01-09 06:50:02 +00:00
|
|
|
// TODO: add support to serialize to a writer to SerializedSig
|
2022-01-13 04:27:20 +00:00
|
|
|
self.sig.serialize_der()
|
2022-05-25 03:40:13 +00:00
|
|
|
.iter().copied()
|
2022-01-13 04:27:20 +00:00
|
|
|
.chain(iter::once(self.hash_ty as u8))
|
|
|
|
.collect()
|
2022-01-09 06:50:02 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-11-08 00:36:52 +00:00
|
|
|
impl fmt::Display for Signature {
|
2022-01-09 06:50:02 +00:00
|
|
|
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
|
2023-01-07 15:39:11 +00:00
|
|
|
fmt::LowerHex::fmt(&self.sig.serialize_der().as_hex(), f)?;
|
|
|
|
fmt::LowerHex::fmt(&[self.hash_ty as u8].as_hex(), f)
|
2022-01-09 06:50:02 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-11-08 00:36:52 +00:00
|
|
|
impl FromStr for Signature {
|
|
|
|
type Err = Error;
|
2022-01-09 06:50:02 +00:00
|
|
|
|
|
|
|
fn from_str(s: &str) -> Result<Self, Self::Err> {
|
|
|
|
let bytes = Vec::from_hex(s)?;
|
|
|
|
let (sighash_byte, signature) = bytes.split_last()
|
2022-11-08 00:36:52 +00:00
|
|
|
.ok_or(Error::EmptySignature)?;
|
|
|
|
Ok(Signature {
|
2022-01-09 06:50:02 +00:00
|
|
|
sig: secp256k1::ecdsa::Signature::from_der(signature)?,
|
2022-03-28 21:48:53 +00:00
|
|
|
hash_ty: EcdsaSighashType::from_standard(*sighash_byte as u32)?
|
2022-01-09 06:50:02 +00:00
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-02-18 11:31:07 +00:00
|
|
|
/// Holds signature serialized in-line (not in `Vec`).
|
|
|
|
///
|
|
|
|
/// This avoids allocation and allows proving maximum size of the signature (73 bytes).
|
|
|
|
/// The type can be used largely as a byte slice. It implements all standard traits one would
|
|
|
|
/// expect and has familiar methods.
|
2023-02-18 11:43:13 +00:00
|
|
|
/// However, the usual use case is to push it into a script. This can be done directly passing it
|
|
|
|
/// into [`push_slice`](crate::script::ScriptBuf::push_slice).
|
2023-02-18 11:31:07 +00:00
|
|
|
#[derive(Copy, Clone)]
|
|
|
|
pub struct SerializedSignature {
|
|
|
|
data: [u8; MAX_SIG_LEN],
|
|
|
|
len: usize,
|
|
|
|
}
|
|
|
|
|
|
|
|
impl SerializedSignature {
|
|
|
|
/// Returns an iterator over bytes of the signature.
|
|
|
|
#[inline]
|
|
|
|
pub fn iter(&self) -> core::slice::Iter<'_, u8> {
|
|
|
|
self.into_iter()
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
impl core::ops::Deref for SerializedSignature {
|
|
|
|
type Target = [u8];
|
|
|
|
|
|
|
|
#[inline]
|
|
|
|
fn deref(&self) -> &Self::Target {
|
|
|
|
&self.data[..self.len]
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
impl core::ops::DerefMut for SerializedSignature {
|
|
|
|
#[inline]
|
|
|
|
fn deref_mut(&mut self) -> &mut Self::Target {
|
|
|
|
&mut self.data[..self.len]
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
impl AsRef<[u8]> for SerializedSignature {
|
|
|
|
#[inline]
|
|
|
|
fn as_ref(&self) -> &[u8] {
|
|
|
|
self
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
impl AsMut<[u8]> for SerializedSignature {
|
|
|
|
#[inline]
|
|
|
|
fn as_mut(&mut self) -> &mut [u8] {
|
|
|
|
self
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-02-18 11:43:13 +00:00
|
|
|
impl AsRef<PushBytes> for SerializedSignature {
|
|
|
|
#[inline]
|
|
|
|
fn as_ref(&self) -> &PushBytes {
|
|
|
|
&<&PushBytes>::from(&self.data)[..self.len()]
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-02-18 11:31:07 +00:00
|
|
|
impl core::borrow::Borrow<[u8]> for SerializedSignature {
|
|
|
|
#[inline]
|
|
|
|
fn borrow(&self) -> &[u8] {
|
|
|
|
self
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
impl core::borrow::BorrowMut<[u8]> for SerializedSignature {
|
|
|
|
#[inline]
|
|
|
|
fn borrow_mut(&mut self) -> &mut [u8] {
|
|
|
|
self
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
impl fmt::Debug for SerializedSignature {
|
|
|
|
#[inline]
|
|
|
|
fn fmt(&self, f: &mut fmt::Formatter) -> fmt::Result { fmt::Display::fmt(self, f) }
|
|
|
|
}
|
|
|
|
|
|
|
|
impl fmt::Display for SerializedSignature {
|
|
|
|
#[inline]
|
|
|
|
fn fmt(&self, f: &mut fmt::Formatter) -> fmt::Result { fmt::LowerHex::fmt(self, f) }
|
|
|
|
}
|
|
|
|
|
|
|
|
impl fmt::LowerHex for SerializedSignature {
|
|
|
|
#[inline]
|
|
|
|
fn fmt(&self, f: &mut fmt::Formatter) -> fmt::Result {
|
|
|
|
fmt::LowerHex::fmt(&(**self).as_hex(), f)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
impl fmt::UpperHex for SerializedSignature {
|
|
|
|
#[inline]
|
|
|
|
fn fmt(&self, f: &mut fmt::Formatter) -> fmt::Result {
|
|
|
|
fmt::UpperHex::fmt(&(**self).as_hex(), f)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
impl PartialEq for SerializedSignature {
|
|
|
|
#[inline]
|
|
|
|
fn eq(&self, other: &SerializedSignature) -> bool { **self == **other }
|
|
|
|
}
|
|
|
|
|
|
|
|
impl Eq for SerializedSignature {}
|
|
|
|
|
|
|
|
impl core::hash::Hash for SerializedSignature {
|
|
|
|
fn hash<H: core::hash::Hasher>(&self, state: &mut H) {
|
|
|
|
core::hash::Hash::hash(&**self, state)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
impl<'a> IntoIterator for &'a SerializedSignature {
|
|
|
|
type IntoIter = core::slice::Iter<'a, u8>;
|
|
|
|
type Item = &'a u8;
|
|
|
|
|
|
|
|
#[inline]
|
|
|
|
fn into_iter(self) -> Self::IntoIter {
|
|
|
|
(*self).iter()
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-01-09 06:50:02 +00:00
|
|
|
/// A key-related error.
|
|
|
|
#[derive(Clone, PartialEq, Eq, PartialOrd, Ord, Hash, Debug)]
|
2022-05-31 04:29:50 +00:00
|
|
|
#[non_exhaustive]
|
2022-11-08 00:36:52 +00:00
|
|
|
pub enum Error {
|
2022-01-09 06:50:02 +00:00
|
|
|
/// Hex encoding error
|
|
|
|
HexEncoding(hex::Error),
|
|
|
|
/// Base58 encoding error
|
2022-03-28 21:56:36 +00:00
|
|
|
NonStandardSighashType(u32),
|
2022-01-09 06:50:02 +00:00
|
|
|
/// Empty Signature
|
|
|
|
EmptySignature,
|
|
|
|
/// secp256k1-related error
|
|
|
|
Secp256k1(secp256k1::Error),
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2022-11-08 00:36:52 +00:00
|
|
|
impl fmt::Display for Error {
|
2022-01-09 06:50:02 +00:00
|
|
|
fn fmt(&self, f: &mut fmt::Formatter) -> fmt::Result {
|
|
|
|
match *self {
|
2022-11-08 00:36:52 +00:00
|
|
|
Error::HexEncoding(ref e) =>
|
|
|
|
write_err!(f, "Signature hex encoding error"; e),
|
|
|
|
Error::NonStandardSighashType(hash_ty) =>
|
2022-01-09 06:50:02 +00:00
|
|
|
write!(f, "Non standard signature hash type {}", hash_ty),
|
2022-11-08 00:36:52 +00:00
|
|
|
Error::EmptySignature =>
|
2022-01-09 06:50:02 +00:00
|
|
|
write!(f, "Empty ECDSA signature"),
|
2022-11-08 00:36:52 +00:00
|
|
|
Error::Secp256k1(ref e) =>
|
2022-05-25 02:56:51 +00:00
|
|
|
write_err!(f, "invalid ECDSA signature"; e),
|
2022-01-09 06:50:02 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
#[cfg(feature = "std")]
|
|
|
|
#[cfg_attr(docsrs, doc(cfg(feature = "std")))]
|
2022-11-08 00:36:52 +00:00
|
|
|
impl std::error::Error for Error {
|
2022-05-04 05:56:24 +00:00
|
|
|
fn source(&self) -> Option<&(dyn std::error::Error + 'static)> {
|
2022-11-08 00:36:52 +00:00
|
|
|
use self::Error::*;
|
2022-05-04 05:56:24 +00:00
|
|
|
|
|
|
|
match self {
|
|
|
|
HexEncoding(e) => Some(e),
|
|
|
|
Secp256k1(e) => Some(e),
|
|
|
|
NonStandardSighashType(_) | EmptySignature => None,
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
2022-01-09 06:50:02 +00:00
|
|
|
|
2022-11-08 00:36:52 +00:00
|
|
|
impl From<secp256k1::Error> for Error {
|
|
|
|
fn from(e: secp256k1::Error) -> Error {
|
|
|
|
Error::Secp256k1(e)
|
2022-01-09 06:50:02 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-11-08 00:36:52 +00:00
|
|
|
impl From<NonStandardSighashType> for Error {
|
2022-03-28 21:56:36 +00:00
|
|
|
fn from(err: NonStandardSighashType) -> Self {
|
2022-11-08 00:36:52 +00:00
|
|
|
Error::NonStandardSighashType(err.0)
|
2022-01-09 06:50:02 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-11-08 00:36:52 +00:00
|
|
|
impl From<hex::Error> for Error {
|
2022-01-09 06:50:02 +00:00
|
|
|
fn from(err: hex::Error) -> Self {
|
2022-11-08 00:36:52 +00:00
|
|
|
Error::HexEncoding(err)
|
2022-01-09 06:50:02 +00:00
|
|
|
}
|
|
|
|
}
|