segwit_addr.c 7.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209
  1. /* Copyright (c) 2017, 2021 Pieter Wuille
  2. *
  3. * Permission is hereby granted, free of charge, to any person obtaining a copy
  4. * of this software and associated documentation files (the "Software"), to deal
  5. * in the Software without restriction, including without limitation the rights
  6. * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
  7. * copies of the Software, and to permit persons to whom the Software is
  8. * furnished to do so, subject to the following conditions:
  9. *
  10. * The above copyright notice and this permission notice shall be included in
  11. * all copies or substantial portions of the Software.
  12. *
  13. * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
  14. * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
  15. * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
  16. * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
  17. * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
  18. * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
  19. * THE SOFTWARE.
  20. */
  21. #include <stdlib.h>
  22. #include <stdint.h>
  23. #include <string.h>
  24. #include "segwit_addr.h"
  25. static uint32_t bech32_polymod_step(uint32_t pre) {
  26. uint8_t b = pre >> 25;
  27. return ((pre & 0x1FFFFFF) << 5) ^
  28. (-((b >> 0) & 1) & 0x3b6a57b2UL) ^
  29. (-((b >> 1) & 1) & 0x26508e6dUL) ^
  30. (-((b >> 2) & 1) & 0x1ea119faUL) ^
  31. (-((b >> 3) & 1) & 0x3d4233ddUL) ^
  32. (-((b >> 4) & 1) & 0x2a1462b3UL);
  33. }
  34. static uint32_t bech32_final_constant(bech32_encoding enc) {
  35. if (enc == BECH32_ENCODING_BECH32) return 1;
  36. if (enc == BECH32_ENCODING_BECH32M) return 0x2bc830a3;
  37. return 0;
  38. }
  39. static const char* charset = "qpzry9x8gf2tvdw0s3jn54khce6mua7l";
  40. static const int8_t charset_rev[128] = {
  41. -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
  42. -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
  43. -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
  44. 15, -1, 10, 17, 21, 20, 26, 30, 7, 5, -1, -1, -1, -1, -1, -1,
  45. -1, 29, -1, 24, 13, 25, 9, 8, 23, -1, 18, 22, 31, 27, 19, -1,
  46. 1, 0, 3, 16, 11, 28, 12, 14, 6, 4, 2, -1, -1, -1, -1, -1,
  47. -1, 29, -1, 24, 13, 25, 9, 8, 23, -1, 18, 22, 31, 27, 19, -1,
  48. 1, 0, 3, 16, 11, 28, 12, 14, 6, 4, 2, -1, -1, -1, -1, -1
  49. };
  50. int bech32_encode(char *output, const char *hrp, const uint8_t *data, size_t data_len, bech32_encoding enc) {
  51. uint32_t chk = 1;
  52. size_t i = 0;
  53. while (hrp[i] != 0) {
  54. int ch = hrp[i];
  55. if (ch < 33 || ch > 126) {
  56. return 0;
  57. }
  58. if (ch >= 'A' && ch <= 'Z') return 0;
  59. chk = bech32_polymod_step(chk) ^ (ch >> 5);
  60. ++i;
  61. }
  62. if (i + 7 + data_len > 90) return 0;
  63. chk = bech32_polymod_step(chk);
  64. while (*hrp != 0) {
  65. chk = bech32_polymod_step(chk) ^ (*hrp & 0x1f);
  66. *(output++) = *(hrp++);
  67. }
  68. *(output++) = '1';
  69. for (i = 0; i < data_len; ++i) {
  70. if (*data >> 5) return 0;
  71. chk = bech32_polymod_step(chk) ^ (*data);
  72. *(output++) = charset[*(data++)];
  73. }
  74. for (i = 0; i < 6; ++i) {
  75. chk = bech32_polymod_step(chk);
  76. }
  77. chk ^= bech32_final_constant(enc);
  78. for (i = 0; i < 6; ++i) {
  79. *(output++) = charset[(chk >> ((5 - i) * 5)) & 0x1f];
  80. }
  81. *output = 0;
  82. return 1;
  83. }
  84. bech32_encoding bech32_decode(char* hrp, uint8_t *data, size_t *data_len, const char *input) {
  85. uint32_t chk = 1;
  86. size_t i = 0;
  87. size_t input_len = strlen(input);
  88. size_t hrp_len = 0;
  89. int have_lower = 0, have_upper = 0;
  90. if (input_len < 8) {
  91. return BECH32_ENCODING_NONE;
  92. }
  93. *data_len = 0;
  94. while (*data_len < input_len && input[(input_len - 1) - *data_len] != '1') {
  95. ++(*data_len);
  96. }
  97. hrp_len = input_len - (1 + *data_len);
  98. if (1 + *data_len >= input_len || *data_len < 6 || hrp_len > BECH32_MAX_HRP_LEN) {
  99. return BECH32_ENCODING_NONE;
  100. }
  101. *(data_len) -= 6;
  102. for (i = 0; i < hrp_len; ++i) {
  103. int ch = input[i];
  104. if (ch < 33 || ch > 126) {
  105. return BECH32_ENCODING_NONE;
  106. }
  107. if (ch >= 'a' && ch <= 'z') {
  108. have_lower = 1;
  109. } else if (ch >= 'A' && ch <= 'Z') {
  110. have_upper = 1;
  111. ch = (ch - 'A') + 'a';
  112. }
  113. hrp[i] = ch;
  114. chk = bech32_polymod_step(chk) ^ (ch >> 5);
  115. }
  116. hrp[i] = 0;
  117. chk = bech32_polymod_step(chk);
  118. for (i = 0; i < hrp_len; ++i) {
  119. chk = bech32_polymod_step(chk) ^ (input[i] & 0x1f);
  120. }
  121. ++i;
  122. while (i < input_len) {
  123. int v = (input[i] & 0x80) ? -1 : charset_rev[(int)input[i]];
  124. if (input[i] >= 'a' && input[i] <= 'z') have_lower = 1;
  125. if (input[i] >= 'A' && input[i] <= 'Z') have_upper = 1;
  126. if (v == -1) {
  127. return BECH32_ENCODING_NONE;
  128. }
  129. chk = bech32_polymod_step(chk) ^ v;
  130. if (i + 6 < input_len) {
  131. data[i - (1 + hrp_len)] = v;
  132. }
  133. ++i;
  134. }
  135. if (have_lower && have_upper) {
  136. return BECH32_ENCODING_NONE;
  137. }
  138. if (chk == bech32_final_constant(BECH32_ENCODING_BECH32)) {
  139. return BECH32_ENCODING_BECH32;
  140. } else if (chk == bech32_final_constant(BECH32_ENCODING_BECH32M)) {
  141. return BECH32_ENCODING_BECH32M;
  142. } else {
  143. return BECH32_ENCODING_NONE;
  144. }
  145. }
  146. static int convert_bits(uint8_t* out, size_t* outlen, int outbits, const uint8_t* in, size_t inlen, int inbits, int pad) {
  147. uint32_t val = 0;
  148. int bits = 0;
  149. uint32_t maxv = (((uint32_t)1) << outbits) - 1;
  150. while (inlen--) {
  151. val = (val << inbits) | *(in++);
  152. bits += inbits;
  153. while (bits >= outbits) {
  154. bits -= outbits;
  155. out[(*outlen)++] = (val >> bits) & maxv;
  156. }
  157. }
  158. if (pad) {
  159. if (bits) {
  160. out[(*outlen)++] = (val << (outbits - bits)) & maxv;
  161. }
  162. } else if (((val << (outbits - bits)) & maxv) || bits >= inbits) {
  163. return 0;
  164. }
  165. return 1;
  166. }
  167. int segwit_addr_encode(char *output, const char *hrp, int witver, const uint8_t *witprog, size_t witprog_len) {
  168. uint8_t data[65] = {0};
  169. size_t datalen = 0;
  170. bech32_encoding enc = BECH32_ENCODING_BECH32;
  171. if (witver > 16) return 0;
  172. if (witver == 0 && witprog_len != 20 && witprog_len != 32) return 0;
  173. if (witprog_len < 2 || witprog_len > 40) return 0;
  174. if (witver > 0) enc = BECH32_ENCODING_BECH32M;
  175. data[0] = witver;
  176. convert_bits(data + 1, &datalen, 5, witprog, witprog_len, 8, 1);
  177. ++datalen;
  178. return bech32_encode(output, hrp, data, datalen, enc);
  179. }
  180. int segwit_addr_decode(int* witver, uint8_t* witdata, size_t* witdata_len, const char* hrp, const char* addr) {
  181. uint8_t data[84] = {0};
  182. char hrp_actual[84] = {0};
  183. size_t data_len = 0;
  184. if (strlen(addr) > 90) return 0;
  185. bech32_encoding enc = bech32_decode(hrp_actual, data, &data_len, addr);
  186. if (enc == BECH32_ENCODING_NONE) return 0;
  187. if (data_len == 0 || data_len > 65) return 0;
  188. if (strncmp(hrp, hrp_actual, 84) != 0) return 0;
  189. if (data[0] > 16) return 0;
  190. if (data[0] == 0 && enc != BECH32_ENCODING_BECH32) return 0;
  191. if (data[0] > 0 && enc != BECH32_ENCODING_BECH32M) return 0;
  192. *witdata_len = 0;
  193. if (!convert_bits(witdata, witdata_len, 8, data + 1, data_len - 1, 5, 0)) return 0;
  194. if (*witdata_len < 2 || *witdata_len > 40) return 0;
  195. if (data[0] == 0 && *witdata_len != 20 && *witdata_len != 32) return 0;
  196. *witver = data[0];
  197. return 1;
  198. }