Files
merge-script 09e22fbbb0 Merge bitcoin/bitcoin#35873: test: add a tx_valid vector for CVE-2024-38365
6cd2fa5fb4 test: add a tx_valid vector for CVE-2024-38365 (JP)

Pull request description:

  Suggested by darosior in #35835.

  `FindAndDelete` only matches whole pushes at opcode boundaries, so a push that carries the signature inside its data is left in the scriptCode. btcd (<0.24.2) removed any push containing the signature, computed a different sighash, and would have rejected a transaction Core accepts: the chain split in [CVE-2024-38365](https://delvingbitcoin.org/t/cve-2024-38365-public-disclosure-btcd-findanddelete-bug/1184).

  The rule is already covered from the failure side, in `script_FindAndDelete` and in the `tx_invalid.json` vectors where the signature sits under a non-standard pushdata prefix. What was missing is the positive direction: a transaction Core must accept because nothing is deleted.

  This adds one vector to `tx_valid.json`, with `OP_CHECKSIGVERIFY <0xaaaa||sig>` as the P2SH redeemScript and the minimal 8-byte DER signature (r = s = 1). The pubkey is recovered from that signature and the sighash Core computes, so it verifies only if the `<0xaaaa||sig>` push survives into the scriptCode. `CONST_SCRIPTCODE` doesn't fire — `FindAndDelete` finds nothing — and the vector runs with every flag.

  To check it actually discriminates, I patched `EvalChecksigPreTapscript` to drop any push whose data contains the signature, the way btcd did. The vector fails with that patch and passes without it.

  Tested with:

  ```
  build/bin/test_bitcoin --run_test=transaction_tests
  ```

ACKs for top commit:
  fametrano:
    ACK 6cd2fa5fb4
  sedited:
    ACK 6cd2fa5fb4

Tree-SHA512: a08412e00ed43570c3cf556da1d243a40b9684ce17eb6d3017267c3e5e82f9cde232e077944b0ec9476df70e767caf0fcd33be5473dfd53ed2241f7b24a33b1d
2026-10-05 14:46:34 +02:00
..
…
…
…
…
…
…
…
…
…
2026-09-08 20:41:48 -07:00
…
…
…
…
…
…
…
2026-09-22 09:24:52 +02:00
…
…
…
…
2026-09-16 14:03:41 +02:00
2026-09-16 14:03:41 +02:00
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…