AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Informational 15 Bitcoin

Merge bitcoin/bitcoin#35835: test: add CONST_SCRIPTCODE failure-path vectors to script_tests.json

Public commit record

What the developer wrote

Authored by merge-script

96/100 · Strong
Merge bitcoin/bitcoin#35835: test: add CONST_SCRIPTCODE failure-path vectors to script_tests.json

829e44a1151fa432f293554f25832f19bde209ec test: add CONST_SCRIPTCODE failure-path vectors to script_tests.json (JP)

Pull request description:

Follow-up to #35664.

Going through which script error codes `script_tests.json` covers, I found that neither error gated behind `SCRIPT_VERIFY_CONST_SCRIPTCODE` is asserted anywhere. `SCRIPT_ERR_SIG_FINDANDDELETE` is not asserted by any test; `SCRIPT_ERR_OP_CODESEPARATOR` appears only as a mempool reject string in `invalid_txs.py`, never at the script level. `tx_invalid.json` does have a `CONST_SCRIPTCODE` section, but those vectors can only say a transaction is invalid, not which error made it fail; `script_tests.json` is the harness that pins error codes, and it has no vector using the flag.

This adds six vectors. Four fail with the flag set:

- `OP_CODESEPARATOR` in an executed pre-segwit script.
- `OP_CODESEPARATOR` in an unexecuted `IF` branch. The check in `EvalScript` runs ahead of the `fExec` guard, so the opcode is rejected even though it never executes — the rule with no error-level coverage before.
- A signature push that also appears in the scriptPubKey, against `CHECKSIG`.
- The same against `CHECKMULTISIG`, which calls `FindAndDelete` in a separate loop.

The other two are controls with the flag off, one per error. Both checks run before signature verification, so the vectors can use a dummy signature.

To confirm the expected errors are the ones that fire, I added the vectors expecting `OK` first and let the harness report the actual error for each.

Tested with:

```
build/bin/test_bitcoin --run_test=script_tests/script_json_test
```

ACKs for top commit:
fametrano:
ACK 829e44a1151fa432f293554f25832f19bde209ec
sedited:
ACK 829e44a1151fa432f293554f25832f19bde209ec

Tree-SHA512: b8d52028b5c7e0ec555b4df3749740337b6921b0357b5c9b156daf2a74203a5b95e3bcfa225ebd5a26e0b4cd90290732e4440c0d2b2bfe6f629f51cd319c4415
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
The short version

What changed, and why it matters

This commit only adds new test cases to a Bitcoin Core test data file. It does not change any production code, consensus rules, or network behavior. The tests verify that two specific script error conditions are correctly detected when a particular validation flag is enabled. There is no security vulnerability being fixed here—this is purely additional test coverage.

Recommended action

No action required. This is a benign test-only addition. Reviewers may optionally verify the test vectors match the documented behavior of SCRIPT_VERIFY_CONST_SCRIPTCODE.

Security signals we found

01

Test-only change

02

Adds regression/edge-case coverage for existing script validation flags

03

No production code modified

Risk score

Why this scored 15/100

Our methodology →
Potential impact 0/30
Exploitability 0/25
Stealth signal 0/15
Affected reach 0/15
Confidence 10/10
Evidence quality 5/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.