script: add and default to SIGHASH_ALL_WITH_RANGEPROOF for pre-taproot signing - #1584
Merged
Merged
Conversation
… rangeproof bit for Taproot signing Add a named default constant SIGHASH_ALL_WITH_RANGEPROOF (SIGHASH_ALL | SIGHASH_RANGEPROOF) and a DefaultSighashType() helper that selects the default pre-Taproot sighash based on whether SIGHASH_RANGEPROOF is active for the target chain. Strip the 0x40 (SIGHASH_RANGEPROOF) bit when computing Schnorr signatures, since the BIP341-style sighash always commits to rangeproofs and rejects the bit. This keeps SIGHASH_ALL_WITH_RANGEPROOF a valid universal default for both pre-Taproot and Taproot signing.
…eck) Add a Chain interface method that reports whether SIGHASH_RANGEPROOF is active for signing at the current chain tip, mirroring the mempool standardness check (DeploymentActiveAfter for DEPLOYMENT_DYNA_FED). This is the live-tip gating source used by the wallet and wallet-backed RPC to decide the default pre-Taproot sighash.
apoelstra
approved these changes
Aug 19, 2026
tomt1664
approved these changes
Aug 20, 2026
tomt1664
reviewed
Aug 20, 2026
| @@ -364,4 +364,28 @@ BOOST_AUTO_TEST_CASE(block_malleation) | |||
| } | |||
| } | |||
|
|
|||
Member
There was a problem hiding this comment.
#include <bitcoin-build-config.h> // IWYU pragma: keep at top for linter
Member
|
signed_pegin comes back complete: True, but fin_psbt comes back complete: False |
Add a CChainParams helper that decides, from chain parameters alone (without a chain tip), whether SIGHASH_RANGEPROOF can be assumed active. This is true when dynafed is configured ALWAYS_ACTIVE, or on liquidv1 where dynafed is height-activated (not the ALWAYS_ACTIVE sentinel) but is long since active on the live chain. This is the chainstate-less gating source used by elements-tx. Add a unit test covering liquidv1 (active by chain type, nStartTime != ALWAYS_ACTIVE), liquidv1test (active via ALWAYS_ACTIVE override), and regtest (inactive).
Change the wallet's default pre-Taproot sighash to commit to output rangeproofs when dynafed is active at the current tip, closing the pre-Taproot rangeproof (witness) malleability gap. Route the default through DefaultSighashType(chain().isSighashRangeproofActive()) in CWallet::SignTransaction and in the signrawtransactionwithwallet / walletprocesspsbt RPCs when the caller does not supply a sighash. Explicit user-supplied sighash types are left untouched.
…d active Default the raw signing RPCs to commit to output rangeproofs when dynafed is active at the current tip. The SignTransaction util gains a sighash_rangeproof_active parameter and, when no sighash is supplied, resolves the default via DefaultSighashType. Wire this through signrawtransactionwithkey and descriptorprocesspsbt using DeploymentActiveAfter(DEPLOYMENT_DYNA_FED) for tip activation. Explicit user-supplied sighash types are left untouched.
elements-tx has no chainstate, so gate the default sighash on chain parameters via CChainParams::SighashRangeproofActiveByParams(): commit to rangeproofs by default on chains where dynafed is known active (including liquidv1), otherwise use the historical SIGHASH_ALL default so offline-built txs stay standard and valid. Normalize SIGHASH_DEFAULT to SIGHASH_ALL for the legacy tool path; explicit sighash=... still overrides.
Extend feature_sighash_rangeproof.py with a case asserting that the wallet's default sign path (no explicit sighash arg) produces signatures that commit to output rangeproofs once dynafed is active.
Document the new default pre-Taproot sighash (SIGHASH_ALL | SIGHASH_RANGEPROOF), its scope (wallet + raw RPC + bitcoin-tx), and the activation/chain-params gating.
delta1
force-pushed
the
2026-08-sighash-default
branch
from
August 26, 2026 11:57
bbb1f5a to
feb50a3
Compare
Member
Author
|
Thanks @tomt1664 , fixed the issue in psbt.cpp |
Member
|
ACK feb50a3 tested locally |
tomt1664
added a commit
to tomt1664/elements
that referenced
this pull request
Sep 3, 2026
…TH_RANGEPROOF for pre-taproot signing feb50a3 doc: release note for default rangeproof-committing sighash (Byron Hambly) a1aacfa test: assert wallet default commits rangeproofs post-dynafed (Byron Hambly) 5ed683c bitcoin-tx: default to rangeproof-committing sighash via chain params (Byron Hambly) f5e2b1f rpc: default raw signing to rangeproof-committing sighash when dynafed active (Byron Hambly) ce342f5 wallet: default to rangeproof-committing sighash when dynafed active (Byron Hambly) 3587d77 chainparams: add SighashRangeproofActiveByParams() for offline gating (Byron Hambly) be15b06 node: expose Chain::isSighashRangeproofActive() (tip-based dynafed check) (Byron Hambly) 6a531c2 script: add SIGHASH_ALL_WITH_RANGEPROOF and DefaultSighashType; strip rangeproof bit for Taproot signing (Byron Hambly) 529eaa1 test: ruff format for feature_sighash_rangeproof.py (Byron Hambly) Pull request description: Pre-Taproot signatures using the historical SIGHASH_ALL default do not commit to output rangeproofs, leaving a witness malleability gap: an attacker can alter a transaction's rangeproofs without invalidating its signatures. This branch closes that gap by making signing default to SIGHASH_ALL | SIGHASH_RANGEPROOF on chains where dynafed is active, while leaving explicit user-supplied sighash types untouched and preserving the legacy default. Scope: - script: adds SIGHASH_ALL_WITH_RANGEPROOF and a DefaultSighashType() helper; strips the 0x40 bit for Taproot/Schnorr signing so the constant is a valid universal default. - node: exposes Chain::isSighashRangeproofActive() for a live tip-based dynafed check. - chainparams: adds SighashRangeproofActiveByParams() for chainstate-less gating (used by bitcoin-tx). - wallet + raw RPCs (signrawtransactionwithkey, signrawtransactionwithwallet, walletprocesspsbt, descriptorprocesspsbt) + - bitcoin-tx: default to the rangeproof-committing sighash when dynafed is active. - Adds unit and functional test coverage plus a release note. ACKs for top commit: tomt1664: ACK feb50a3 tested locally Tree-SHA512: acef900cd368cbe9c8e0f5a2082b953ba55fd8dd78bf02c0b99b27c71500e93fdcd3abff39f85681f88b98a86cf6be59fbdbb5fd4b679a8c142500bb17f117f9
tomt1664
added a commit
that referenced
this pull request
Sep 3, 2026
f80fb30 Merge #1589: simplicity: update subtree to abede47e (merge-script) 5b388c2 Merge pull request #1577 from Abdullah1738/feat/effective-fee-asset (Tom Trevethan) 48456e3 Add test that sighash midstate cache treats the SIGHASH_RANGEPROOF bit as part of its key (Tom Trevethan) d47af63 Merge #1584: script: add and default to SIGHASH_ALL_WITH_RANGEPROOF for pre-taproot signing (merge-script) 7c23bd1 blind: reject empty surjection-target set in SurjectOutput (Byron Hambly) 3e11e03 blindpsbt: require genuine commitments in VerifyBlindValueProof (Byron Hambly) 99e9f25 blindpsbt: require both range bounds to match claim in VerifyBlindValueProof (Byron Hambly) 8a08453 validation: always validate and retain dynafed header block_height (Byron Hambly) 4309282 dynafed: require at least four-fifths approval for parameter transition (Byron Hambly) 6a49991 blindpsbt: refuse to blind a PSET output with no amount (Byron Hambly) 0ce3c24 blindpsbt: reject off-curve blinding pubkey before ECDH (Byron Hambly) 2391041 blindpsbt: return error instead of asserting on surjection proof failure (Byron Hambly) 6253d7e fix: range proof cache bind to asset and scriptpubkey (Byron Hambly) 3d7134f Merge #1593: Fix RPC return errors for psbt and invalid rangeproofs (merge-script) Pull request description: ACKs for top commit: delta1: ACK f80fb30; tested locally Tree-SHA512: 42995e5b4842ce9694d9d5d30764230b774db24cda40d825742a174d564761e725a8323362404ee9653495936ab850c9933075b7ad924caa73768d0980bcbf96
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pre-Taproot signatures using the historical SIGHASH_ALL default do not commit to output rangeproofs, leaving a witness malleability gap: an attacker can alter a transaction's rangeproofs without invalidating its signatures. This branch closes that gap by making signing default to SIGHASH_ALL | SIGHASH_RANGEPROOF on chains where dynafed is active, while leaving explicit user-supplied sighash types untouched and preserving the legacy default.
Scope: