Bitcoin Core 32.99.0
P2P Digital Currency
bech32.cpp
Go to the documentation of this file.
1// Copyright (c) 2017, 2021 Pieter Wuille
2// Copyright (c) 2021-present The Bitcoin Core developers
3// Distributed under the MIT software license, see the accompanying
4// file COPYING or http://www.opensource.org/licenses/mit-license.php.
5
6#include <bech32.h>
7#include <util/vector.h>
8
9#include <array>
10#include <cassert>
11#include <optional>
12
13namespace bech32
14{
15
16namespace
17{
18
19typedef std::vector<uint8_t> data;
20
22const char* CHARSET = "qpzry9x8gf2tvdw0s3jn54khce6mua7l";
23
25const int8_t CHARSET_REV[128] = {
26 -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
27 -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
28 -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
29 15, -1, 10, 17, 21, 20, 26, 30, 7, 5, -1, -1, -1, -1, -1, -1,
30 -1, 29, -1, 24, 13, 25, 9, 8, 23, -1, 18, 22, 31, 27, 19, -1,
31 1, 0, 3, 16, 11, 28, 12, 14, 6, 4, 2, -1, -1, -1, -1, -1,
32 -1, 29, -1, 24, 13, 25, 9, 8, 23, -1, 18, 22, 31, 27, 19, -1,
33 1, 0, 3, 16, 11, 28, 12, 14, 6, 4, 2, -1, -1, -1, -1, -1
34};
35
45constexpr std::pair<std::array<int16_t, 1023>, std::array<int16_t, 1024>> GenerateGFTables()
46{
47 // Build table for GF(32).
48 // We use these tables to perform arithmetic in GF(32) below, when constructing the
49 // tables for GF(1024).
50 std::array<int8_t, 31> GF32_EXP{};
51 std::array<int8_t, 32> GF32_LOG{};
52
53 // fmod encodes the defining polynomial of GF(32) over GF(2), x^5 + x^3 + 1.
54 // Because coefficients in GF(2) are binary digits, the coefficients are packed as 101001.
55 const int fmod = 41;
56
57 // Elements of GF(32) are encoded as vectors of length 5 over GF(2), that is,
58 // 5 binary digits. Each element (b_4, b_3, b_2, b_1, b_0) encodes a polynomial
59 // b_4*x^4 + b_3*x^3 + b_2*x^2 + b_1*x^1 + b_0 (modulo fmod).
60 // For example, 00001 = 1 is the multiplicative identity.
61 GF32_EXP[0] = 1;
62 GF32_LOG[0] = -1;
63 GF32_LOG[1] = 0;
64 int v = 1;
65 for (int i = 1; i < 31; ++i) {
66 // Multiplication by x is the same as shifting left by 1, as
67 // every coefficient of the polynomial is moved up one place.
68 v = v << 1;
69 // If the polynomial now has an x^5 term, we subtract fmod from it
70 // to remain working modulo fmod. Subtraction is the same as XOR in characteristic
71 // 2 fields.
72 if (v & 32) v ^= fmod;
73 GF32_EXP[i] = v;
74 GF32_LOG[v] = i;
75 }
76
77 // Build table for GF(1024)
78 std::array<int16_t, 1023> GF1024_EXP{};
79 std::array<int16_t, 1024> GF1024_LOG{};
80
81 GF1024_EXP[0] = 1;
82 GF1024_LOG[0] = -1;
83 GF1024_LOG[1] = 0;
84
85 // Each element v of GF(1024) is encoded as a 10 bit integer in the following way:
86 // v = v1 || v0 where v0, v1 are 5-bit integers (elements of GF(32)).
87 // The element (e) is encoded as 1 || 0, to represent 1*(e) + 0. Every other element
88 // a*(e) + b is represented as a || b (a and b are both GF(32) elements). Given (v),
89 // we compute (e)*(v) by multiplying in the following way:
90 //
91 // v0' = 23*v1
92 // v1' = 9*v1 + v0
93 // e*v = v1' || v0'
94 //
95 // Where 23, 9 are GF(32) elements encoded as described above. Multiplication in GF(32)
96 // is done using the log/exp tables:
97 // e^x * e^y = e^(x + y) so a * b = EXP[ LOG[a] + LOG [b] ]
98 // for non-zero a and b.
99
100 v = 1;
101 for (int i = 1; i < 1023; ++i) {
102 int v0 = v & 31;
103 int v1 = v >> 5;
104
105 int v0n = v1 ? GF32_EXP.at((GF32_LOG.at(v1) + GF32_LOG.at(23)) % 31) : 0;
106 int v1n = (v1 ? GF32_EXP.at((GF32_LOG.at(v1) + GF32_LOG.at(9)) % 31) : 0) ^ v0;
107
108 v = v1n << 5 | v0n;
109 GF1024_EXP[i] = v;
110 GF1024_LOG[v] = i;
111 }
112
113 return std::make_pair(GF1024_EXP, GF1024_LOG);
114}
115
116constexpr auto tables = GenerateGFTables();
117constexpr const std::array<int16_t, 1023>& GF1024_EXP = tables.first;
118constexpr const std::array<int16_t, 1024>& GF1024_LOG = tables.second;
119
120/* Determine the final constant to use for the specified encoding. */
121uint32_t EncodingConstant(Encoding encoding) {
122 assert(encoding == Encoding::BECH32 || encoding == Encoding::BECH32M);
123 return encoding == Encoding::BECH32 ? 1 : 0x2bc830a3;
124}
125
129uint32_t PolyMod(const data& v)
130{
131 // The input is interpreted as a list of coefficients of a polynomial over F = GF(32), with an
132 // implicit 1 in front. If the input is [v0,v1,v2,v3,v4], that polynomial is v(x) =
133 // 1*x^5 + v0*x^4 + v1*x^3 + v2*x^2 + v3*x + v4. The implicit 1 guarantees that
134 // [v0,v1,v2,...] has a distinct checksum from [0,v0,v1,v2,...].
135
136 // The output is a 30-bit integer whose 5-bit groups are the coefficients of the remainder of
137 // v(x) mod g(x), where g(x) is the Bech32 generator,
138 // x^6 + {29}x^5 + {22}x^4 + {20}x^3 + {21}x^2 + {29}x + {18}. g(x) is chosen in such a way
139 // that the resulting code is a BCH code, guaranteeing detection of up to 3 errors within a
140 // window of 1023 characters. Among the various possible BCH codes, one was selected to in
141 // fact guarantee detection of up to 4 errors within a window of 89 characters.
142
143 // Note that the coefficients are elements of GF(32), here represented as decimal numbers
144 // between {}. In this finite field, addition is just XOR of the corresponding numbers. For
145 // example, {27} + {13} = {27 ^ 13} = {22}. Multiplication is more complicated, and requires
146 // treating the bits of values themselves as coefficients of a polynomial over a smaller field,
147 // GF(2), and multiplying those polynomials mod a^5 + a^3 + 1. For example, {5} * {26} =
148 // (a^2 + 1) * (a^4 + a^3 + a) = (a^4 + a^3 + a) * a^2 + (a^4 + a^3 + a) = a^6 + a^5 + a^4 + a
149 // = a^3 + 1 (mod a^5 + a^3 + 1) = {9}.
150
151 // During the course of the loop below, `c` contains the bitpacked coefficients of the
152 // polynomial constructed from just the values of v that were processed so far, mod g(x). In
153 // the above example, `c` initially corresponds to 1 mod g(x), and after processing 2 inputs of
154 // v, it corresponds to x^2 + v0*x + v1 mod g(x). As 1 mod g(x) = 1, that is the starting value
155 // for `c`.
156
157 // The following Sage code constructs the generator used:
158 //
159 // B = GF(2) # Binary field
160 // BP.<b> = B[] # Polynomials over the binary field
161 // F_mod = b**5 + b**3 + 1
162 // F.<f> = GF(32, modulus=F_mod, repr='int') # GF(32) definition
163 // FP.<x> = F[] # Polynomials over GF(32)
164 // E_mod = x**2 + F.fetch_int(9)*x + F.fetch_int(23)
165 // E.<e> = F.extension(E_mod) # GF(1024) extension field definition
166 // for p in divisors(E.order() - 1): # Verify e has order 1023.
167 // assert((e**p == 1) == (p % 1023 == 0))
168 // G = lcm([(e**i).minpoly() for i in range(997,1000)])
169 // print(G) # Print out the generator
170 //
171 // It demonstrates that g(x) is the least common multiple of the minimal polynomials
172 // of 3 consecutive powers (997,998,999) of a primitive element (e) of GF(1024).
173 // That guarantees it is, in fact, the generator of a primitive BCH code with cycle
174 // length 1023 and distance 4. See https://en.wikipedia.org/wiki/BCH_code for more details.
175
176 uint32_t c = 1;
177 for (const auto v_i : v) {
178 // We want to update `c` to correspond to a polynomial with one extra term. If the initial
179 // value of `c` consists of the coefficients of c(x) = f(x) mod g(x), we modify it to
180 // correspond to c'(x) = (f(x) * x + v_i) mod g(x), where v_i is the next input to
181 // process. Simplifying:
182 // c'(x) = (f(x) * x + v_i) mod g(x)
183 // ((f(x) mod g(x)) * x + v_i) mod g(x)
184 // (c(x) * x + v_i) mod g(x)
185 // If c(x) = c0*x^5 + c1*x^4 + c2*x^3 + c3*x^2 + c4*x + c5, we want to compute
186 // c'(x) = (c0*x^5 + c1*x^4 + c2*x^3 + c3*x^2 + c4*x + c5) * x + v_i mod g(x)
187 // = c0*x^6 + c1*x^5 + c2*x^4 + c3*x^3 + c4*x^2 + c5*x + v_i mod g(x)
188 // = c0*(x^6 mod g(x)) + c1*x^5 + c2*x^4 + c3*x^3 + c4*x^2 + c5*x + v_i
189 // If we call (x^6 mod g(x)) = k(x), this can be written as
190 // c'(x) = (c1*x^5 + c2*x^4 + c3*x^3 + c4*x^2 + c5*x + v_i) + c0*k(x)
191
192 // First, determine the value of c0:
193 uint8_t c0 = c >> 25;
194
195 // Then compute c1*x^5 + c2*x^4 + c3*x^3 + c4*x^2 + c5*x + v_i:
196 c = ((c & 0x1ffffff) << 5) ^ v_i;
197
198 // Finally, for each set bit n in c0, conditionally add {2^n}k(x). These constants can be
199 // computed using the following Sage code (continuing the code above):
200 //
201 // for i in [1,2,4,8,16]: # Print out {1,2,4,8,16}*(g(x) mod x^6), packed in hex integers.
202 // v = 0
203 // for coef in reversed((F.fetch_int(i)*(G % x**6)).coefficients(sparse=True)):
204 // v = v*32 + coef.integer_representation()
205 // print("0x%x" % v)
206 //
207 if (c0 & 1) c ^= 0x3b6a57b2; // k(x) = {29}x^5 + {22}x^4 + {20}x^3 + {21}x^2 + {29}x + {18}
208 if (c0 & 2) c ^= 0x26508e6d; // {2}k(x) = {19}x^5 + {5}x^4 + x^3 + {3}x^2 + {19}x + {13}
209 if (c0 & 4) c ^= 0x1ea119fa; // {4}k(x) = {15}x^5 + {10}x^4 + {2}x^3 + {6}x^2 + {15}x + {26}
210 if (c0 & 8) c ^= 0x3d4233dd; // {8}k(x) = {30}x^5 + {20}x^4 + {4}x^3 + {12}x^2 + {30}x + {29}
211 if (c0 & 16) c ^= 0x2a1462b3; // {16}k(x) = {21}x^5 + x^4 + {8}x^3 + {24}x^2 + {21}x + {19}
212
213 }
214 return c;
215}
216
239constexpr std::array<uint32_t, 25> GenerateSyndromeConstants() {
240 std::array<uint32_t, 25> SYNDROME_CONSTS{};
241 for (int k = 1; k < 6; ++k) {
242 for (int shift = 0; shift < 5; ++shift) {
243 int16_t b = GF1024_LOG.at(size_t{1} << shift);
244 int16_t c0 = GF1024_EXP.at((997*k + b) % 1023);
245 int16_t c1 = GF1024_EXP.at((998*k + b) % 1023);
246 int16_t c2 = GF1024_EXP.at((999*k + b) % 1023);
247 uint32_t c = c2 << 20 | c1 << 10 | c0;
248 int ind = 5*(k-1) + shift;
249 SYNDROME_CONSTS[ind] = c;
250 }
251 }
252 return SYNDROME_CONSTS;
253}
254constexpr std::array<uint32_t, 25> SYNDROME_CONSTS = GenerateSyndromeConstants();
255
260uint32_t Syndrome(const uint32_t residue) {
261 // low is the first 5 bits, corresponding to the r6 in the residue
262 // (the constant term of the polynomial).
263 uint32_t low = residue & 0x1f;
264
265 // We begin by setting s_j = low = r6 for all three values of j, because these are unconditional.
266 uint32_t result = low ^ (low << 10) ^ (low << 20);
267
268 // Then for each following bit, we add the corresponding precomputed constant if the bit is 1.
269 // For example, 0x31edd3c4 is 1100011110 1101110100 1111000100 when unpacked in groups of 10
270 // bits, corresponding exactly to a^999 || a^998 || a^997 (matching the corresponding values in
271 // GF1024_EXP above). In this way, we compute all three values of s_j for j in (997, 998, 999)
272 // simultaneously. Recall that XOR corresponds to addition in a characteristic 2 field.
273 for (int i = 0; i < 25; ++i) {
274 result ^= ((residue >> (5+i)) & 1 ? SYNDROME_CONSTS.at(i) : 0);
275 }
276 return result;
277}
278
280inline unsigned char LowerCase(unsigned char c)
281{
282 return (c >= 'A' && c <= 'Z') ? (c - 'A') + 'a' : c;
283}
284
286bool CheckCharacters(const std::string& str, std::vector<int>& errors)
287{
288 bool lower = false, upper = false;
289 for (size_t i = 0; i < str.size(); ++i) {
290 unsigned char c{(unsigned char)(str[i])};
291 if (c >= 'a' && c <= 'z') {
292 if (upper) {
293 errors.push_back(i);
294 } else {
295 lower = true;
296 }
297 } else if (c >= 'A' && c <= 'Z') {
298 if (lower) {
299 errors.push_back(i);
300 } else {
301 upper = true;
302 }
303 } else if (c < 33 || c > 126) {
304 errors.push_back(i);
305 }
306 }
307 return errors.empty();
308}
309
310std::vector<unsigned char> PreparePolynomialCoefficients(const std::string& hrp, const data& values)
311{
312 data ret;
313 ret.reserve(hrp.size() + 1 + hrp.size() + values.size() + CHECKSUM_SIZE);
314
316 for (size_t i = 0; i < hrp.size(); ++i) ret.push_back(hrp[i] >> 5);
317 ret.push_back(0);
318 for (size_t i = 0; i < hrp.size(); ++i) ret.push_back(hrp[i] & 0x1f);
319
320 ret.insert(ret.end(), values.begin(), values.end());
321
322 return ret;
323}
324
326Encoding VerifyChecksum(const std::string& hrp, const data& values)
327{
328 // PolyMod computes what value to xor into the final values to make the checksum 0. However,
329 // if we required that the checksum was 0, it would be the case that appending a 0 to a valid
330 // list of values would result in a new valid list. For that reason, Bech32 requires the
331 // resulting checksum to be 1 instead. In Bech32m, this constant was amended. See
332 // https://gist.github.com/sipa/14c248c288c3880a3b191f978a34508e for details.
333 auto enc = PreparePolynomialCoefficients(hrp, values);
334 const uint32_t check = PolyMod(enc);
335 if (check == EncodingConstant(Encoding::BECH32)) return Encoding::BECH32;
336 if (check == EncodingConstant(Encoding::BECH32M)) return Encoding::BECH32M;
337 return Encoding::INVALID;
338}
339
341data CreateChecksum(Encoding encoding, const std::string& hrp, const data& values)
342{
343 auto enc = PreparePolynomialCoefficients(hrp, values);
344 enc.insert(enc.end(), CHECKSUM_SIZE, 0x00);
345 uint32_t mod = PolyMod(enc) ^ EncodingConstant(encoding); // Determine what to XOR into those 6 zeroes.
347 for (size_t i = 0; i < CHECKSUM_SIZE; ++i) {
348 // Convert the 5-bit groups in mod to checksum values.
349 ret[i] = (mod >> (5 * (5 - i))) & 31;
350 }
351 return ret;
352}
353
354} // namespace
355
357std::string Encode(Encoding encoding, const std::string& hrp, const data& values) {
358 // First ensure that the HRP is all lowercase. BIP-173 and BIP350 require an encoder
359 // to return a lowercase Bech32/Bech32m string, but if given an uppercase HRP, the
360 // result will always be invalid.
361 for (const char& c : hrp) assert(c < 'A' || c > 'Z');
362
363 std::string ret;
364 ret.reserve(hrp.size() + 1 + values.size() + CHECKSUM_SIZE);
365 ret += hrp;
366 ret += SEPARATOR;
367 for (const uint8_t& i : values) ret += CHARSET[i];
368 for (const uint8_t& i : CreateChecksum(encoding, hrp, values)) ret += CHARSET[i];
369 return ret;
370}
371
373DecodeResult Decode(const std::string& str, CharLimit limit) {
374 std::vector<int> errors;
375 if (!CheckCharacters(str, errors)) return {};
376 size_t pos = str.rfind(SEPARATOR);
377 if (str.size() > limit) return {};
378 if (pos == str.npos || pos == 0 || pos + CHECKSUM_SIZE >= str.size()) {
379 return {};
380 }
381 data values(str.size() - 1 - pos);
382 for (size_t i = 0; i < str.size() - 1 - pos; ++i) {
383 unsigned char c = str[i + pos + 1];
384 int8_t rev = CHARSET_REV[c];
385
386 if (rev == -1) {
387 return {};
388 }
389 values[i] = rev;
390 }
391 std::string hrp;
392 hrp.reserve(pos);
393 for (size_t i = 0; i < pos; ++i) {
394 hrp += LowerCase(str[i]);
395 }
396 Encoding result = VerifyChecksum(hrp, values);
397 if (result == Encoding::INVALID) return {};
398 return {result, std::move(hrp), data(values.begin(), values.end() - CHECKSUM_SIZE)};
399}
400
402std::pair<std::string, std::vector<int>> LocateErrors(const std::string& str, CharLimit limit) {
403 std::vector<int> error_locations{};
404
405 if (str.size() > limit) {
406 error_locations.push_back(static_cast<int>(limit));
407 return std::make_pair("Bech32 string too long", std::move(error_locations));
408 }
409
410 if (!CheckCharacters(str, error_locations)){
411 return std::make_pair("Invalid character or mixed case", std::move(error_locations));
412 }
413
414 size_t pos = str.rfind(SEPARATOR);
415 if (pos == str.npos) {
416 return std::make_pair("Missing separator", std::vector<int>{});
417 }
418 if (pos == 0 || pos + CHECKSUM_SIZE >= str.size()) {
419 error_locations.push_back(pos);
420 return std::make_pair("Invalid separator position", std::move(error_locations));
421 }
422
423 std::string hrp;
424 hrp.reserve(pos);
425 for (size_t i = 0; i < pos; ++i) {
426 hrp += LowerCase(str[i]);
427 }
428
429 size_t length = str.size() - 1 - pos; // length of data part
430 data values(length);
431 for (size_t i = pos + 1; i < str.size(); ++i) {
432 unsigned char c = str[i];
433 int8_t rev = CHARSET_REV[c];
434 if (rev == -1) {
435 error_locations.push_back(i);
436 return std::make_pair("Invalid Base 32 character", std::move(error_locations));
437 }
438 values[i - pos - 1] = rev;
439 }
440
441 // We attempt error detection with both bech32 and bech32m, and choose the one with the fewest errors
442 // We can't simply use the segwit version, because that may be one of the errors
443 std::optional<Encoding> error_encoding;
444 for (Encoding encoding : {Encoding::BECH32, Encoding::BECH32M}) {
445 std::vector<int> possible_errors;
446 // Recall that (expanded hrp + values) is interpreted as a list of coefficients of a polynomial
447 // over GF(32). PolyMod computes the "remainder" of this polynomial modulo the generator G(x).
448 auto enc = PreparePolynomialCoefficients(hrp, values);
449 uint32_t residue = PolyMod(enc) ^ EncodingConstant(encoding);
450
451 // All valid codewords should be multiples of G(x), so this remainder (after XORing with the encoding
452 // constant) should be 0 - hence 0 indicates there are no errors present.
453 if (residue != 0) {
454 // If errors are present, our polynomial must be of the form C(x) + E(x) where C is the valid
455 // codeword (a multiple of G(x)), and E encodes the errors.
456 uint32_t syn = Syndrome(residue);
457
458 // Unpack the three 10-bit syndrome values
459 int s0 = syn & 0x3FF;
460 int s1 = (syn >> 10) & 0x3FF;
461 int s2 = syn >> 20;
462
463 // Get the discrete logs of these values in GF1024 for more efficient computation
464 int l_s0 = GF1024_LOG.at(s0);
465 int l_s1 = GF1024_LOG.at(s1);
466 int l_s2 = GF1024_LOG.at(s2);
467
468 // First, suppose there is only a single error. Then E(x) = e1*x^p1 for some position p1
469 // Then s0 = E((e)^997) = e1*(e)^(997*p1) and s1 = E((e)^998) = e1*(e)^(998*p1)
470 // Therefore s1/s0 = (e)^p1, and by the same logic, s2/s1 = (e)^p1 too.
471 // Hence, s1^2 == s0*s2, which is exactly the condition we check first:
472 if (l_s0 != -1 && l_s1 != -1 && l_s2 != -1 && (2 * l_s1 - l_s2 - l_s0 + 2046) % 1023 == 0) {
473 // Compute the error position p1 as l_s1 - l_s0 = p1 (mod 1023)
474 size_t p1 = (l_s1 - l_s0 + 1023) % 1023; // the +1023 ensures it is positive
475 // Now because s0 = e1*(e)^(997*p1), we get e1 = s0/((e)^(997*p1)). Remember that (e)^1023 = 1,
476 // so 1/((e)^997) = (e)^(1023-997).
477 int l_e1 = l_s0 + (1023 - 997) * p1;
478 // Finally, some sanity checks on the result:
479 // - The error position should be within the length of the data
480 // - e1 should be in GF(32), which implies that e1 = (e)^(33k) for some k (the 31 non-zero elements
481 // of GF(32) form an index 33 subgroup of the 1023 non-zero elements of GF(1024)).
482 if (p1 < length && !(l_e1 % 33)) {
483 // Polynomials run from highest power to lowest, so the index p1 is from the right.
484 // We don't return e1 because it is dangerous to suggest corrections to the user,
485 // the user should check the address themselves.
486 possible_errors.push_back(str.size() - p1 - 1);
487 }
488 // Otherwise, suppose there are two errors. Then E(x) = e1*x^p1 + e2*x^p2.
489 } else {
490 // For all possible first error positions p1
491 for (size_t p1 = 0; p1 < length; ++p1) {
492 // We have guessed p1, and want to solve for p2. Recall that E(x) = e1*x^p1 + e2*x^p2, so
493 // s0 = E((e)^997) = e1*(e)^(997^p1) + e2*(e)^(997*p2), and similar for s1 and s2.
494 //
495 // Consider s2 + s1*(e)^p1
496 // = 2e1*(e)^(999^p1) + e2*(e)^(999*p2) + e2*(e)^(998*p2)*(e)^p1
497 // = e2*(e)^(999*p2) + e2*(e)^(998*p2)*(e)^p1
498 // (Because we are working in characteristic 2.)
499 // = e2*(e)^(998*p2) ((e)^p2 + (e)^p1)
500 //
501 int s2_s1p1 = s2 ^ (s1 == 0 ? 0 : GF1024_EXP.at((l_s1 + p1) % 1023));
502 if (s2_s1p1 == 0) continue;
503 int l_s2_s1p1 = GF1024_LOG.at(s2_s1p1);
504
505 // Similarly, s1 + s0*(e)^p1
506 // = e2*(e)^(997*p2) ((e)^p2 + (e)^p1)
507 int s1_s0p1 = s1 ^ (s0 == 0 ? 0 : GF1024_EXP.at((l_s0 + p1) % 1023));
508 if (s1_s0p1 == 0) continue;
509 int l_s1_s0p1 = GF1024_LOG.at(s1_s0p1);
510
511 // So, putting these together, we can compute the second error position as
512 // (e)^p2 = (s2 + s1^p1)/(s1 + s0^p1)
513 // p2 = log((e)^p2)
514 size_t p2 = (l_s2_s1p1 - l_s1_s0p1 + 1023) % 1023;
515
516 // Sanity checks that p2 is a valid position and not the same as p1
517 if (p2 >= length || p1 == p2) continue;
518
519 // Now we want to compute the error values e1 and e2.
520 // Similar to above, we compute s1 + s0*(e)^p2
521 // = e1*(e)^(997*p1) ((e)^p1 + (e)^p2)
522 int s1_s0p2 = s1 ^ (s0 == 0 ? 0 : GF1024_EXP.at((l_s0 + p2) % 1023));
523 if (s1_s0p2 == 0) continue;
524 int l_s1_s0p2 = GF1024_LOG.at(s1_s0p2);
525
526 // And compute (the log of) 1/((e)^p1 + (e)^p2))
527 int inv_p1_p2 = 1023 - GF1024_LOG.at(GF1024_EXP.at(p1) ^ GF1024_EXP.at(p2));
528
529 // Then (s1 + s0*(e)^p1) * (1/((e)^p1 + (e)^p2)))
530 // = e2*(e)^(997*p2)
531 // Then recover e2 by dividing by (e)^(997*p2)
532 int l_e2 = l_s1_s0p1 + inv_p1_p2 + (1023 - 997) * p2;
533 // Check that e2 is in GF(32)
534 if (l_e2 % 33) continue;
535
536 // In the same way, (s1 + s0*(e)^p2) * (1/((e)^p1 + (e)^p2)))
537 // = e1*(e)^(997*p1)
538 // So recover e1 by dividing by (e)^(997*p1)
539 int l_e1 = l_s1_s0p2 + inv_p1_p2 + (1023 - 997) * p1;
540 // Check that e1 is in GF(32)
541 if (l_e1 % 33) continue;
542
543 // Again, we do not return e1 or e2 for safety.
544 // Order the error positions from the left of the string and return them
545 if (p1 > p2) {
546 possible_errors.push_back(str.size() - p1 - 1);
547 possible_errors.push_back(str.size() - p2 - 1);
548 } else {
549 possible_errors.push_back(str.size() - p2 - 1);
550 possible_errors.push_back(str.size() - p1 - 1);
551 }
552 break;
553 }
554 }
555 } else {
556 // No errors
557 return std::make_pair("", std::vector<int>{});
558 }
559
560 if (error_locations.empty() || (!possible_errors.empty() && possible_errors.size() < error_locations.size())) {
561 error_locations = std::move(possible_errors);
562 if (!error_locations.empty()) error_encoding = encoding;
563 }
564 }
565 std::string error_message = error_encoding == Encoding::BECH32M ? "Invalid Bech32m checksum"
566 : error_encoding == Encoding::BECH32 ? "Invalid Bech32 checksum"
567 : "Invalid checksum";
568
569 return std::make_pair(error_message, std::move(error_locations));
570}
571
572} // namespace bech32
int ret
static const PrecomputedData data
Precomputed COutPoint and CCoins values.
std::pair< std::string, std::vector< int > > LocateErrors(const std::string &str, CharLimit limit)
Find index of an incorrect character in a Bech32 string.
Definition: bech32.cpp:402
Encoding
Definition: bech32.h:29
@ INVALID
Failed decoding.
@ BECH32
Bech32 encoding as defined in BIP173.
@ BECH32M
Bech32m encoding as defined in BIP350.
CharLimit
Character limits for Bech32(m) encoded strings.
Definition: bech32.h:40
DecodeResult Decode(const std::string &str, CharLimit limit)
Decode a Bech32 or Bech32m string.
Definition: bech32.cpp:373
std::string Encode(Encoding encoding, const std::string &hrp, const data &values)
Encode a Bech32 or Bech32m string.
Definition: bech32.cpp:357
constexpr size_t CHECKSUM_SIZE
Definition: bech32.h:26
constexpr char SEPARATOR
Definition: bech32.h:27
T check(T ptr)
static const int64_t values[]
A selection of numbers that do not trigger int64_t overflow when added/subtracted.
void PolyMod(const std::vector< typename F::Elem > &mod, std::vector< typename F::Elem > &val, const F &field)
Compute the remainder of a polynomial division of val by mod, putting the result in mod.
Definition: sketch_impl.h:18
assert(!tx.IsCoinBase())