AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 60 Bitcoin

Merge rust-bitcoin/rust-bitcoin#6945: bitcoin: handle OP_CODESEPARATOR in legacy

Public commit record

What the developer wrote

Authored by Andrew Poelstra

91/100 · Strong
Merge rust-bitcoin/rust-bitcoin#6945: bitcoin: handle OP_CODESEPARATOR in legacy

47a176520010af123c9890c5a616a822d583b951 bitcoin: restore tests that include OP_CODESEPARATOR (jrakibi)
cc3b772a097b153a48a0ca4b5d61754294facc86 bitcoin: Test legacy script code separator handling (jrakibi)
ebaf3db323afa43e69b65502211bf6c50f886f62 bitcoin: remove OP_CODESEPARATOR from legacy script code (jrakibi)
b2136093daed24b3337ec3720e368d9618c0361a bitcoin: add TODO for using ScriptCode in legacy sighash (jrakibi)
7197ccd1c4f1d6687296ffd73967aa1c3fb1dd90 bitcoin: rename script_pubkey to script_code (jrakibi)

Pull request description:

Currently, we don't support `OP_CODESEPARATOR` when computing legacy sighashes. This PR fixes this by removing them from script code when serializing the sighash.

Commit 1: renames script_pubkey to script_code (see #4136 and commit log for the reasoning).

Commit 3: removes `OP_CODESEPARATOR` instructions in two passes. The first counts them to calculate the script length for the CompactSize prefix.
The second pass removes `OP_CODESEPARATOR` while keeping `0xab` bytes that are part of pushed data unchanged.

The final commit restores all test vectors previously omitted from `legacy_sighash.json`

Closes #4136
Addresses the legacy part of #6808


ACKs for top commit:
tcharding:
ACK 47a176520010af123c9890c5a616a822d583b951
apoelstra:
ACK 47a176520010af123c9890c5a616a822d583b951; successfully ran local tests


Tree-SHA512: fa95c2c22ccdbb7bbf97a260184f10af8fc84d321e559c37c184ba36cb2476ec31728c3fb229d8604ffec69af568f3dc37d2ac8c2de8b1596b6fab05437deba2
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit fixes how the Rust Bitcoin library calculates old-style (legacy) transaction signatures when the spending script contains a special opcode called OP_CODESEPARATOR. Previously the library did not handle this opcode at all, which could produce signature hashes that disagree with Bitcoin Core and the Bitcoin protocol. The change strips OP_CODESEPARATOR opcodes from the script before hashing, matching Bitcoin Core's behavior. It also restores previously disabled test vectors that include this opcode.

Recommended action

Review the new legacy_encode_script_code_to implementation against Bitcoin Core's interpreter.cpp behavior, verify restored test vectors pass, and consider whether callers are correctly stripping executed OP_CODESEPARATOR prefixes as documented. No immediate emergency response is indicated, but downstream users relying on legacy sighashes should upgrade to ensure consensus compatibility.

Security signals we found

01

Protocol correctness fix for legacy sighash serialization

02

OP_CODESEPARATOR handling added to match Bitcoin Core consensus behavior

03

Previously omitted test vectors restored, indicating prior non-compliance

04

Incomplete push handling mirrors Bitcoin Core interpreter.cpp reference

05

No explicit security advisory or CVE referenced in commit materials

Risk score

Why this scored 60/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.