Skip to content

bip93: reject HRPs longer than 83 characters - #35

Closed
BenWestgate wants to merge 2 commits into
reviewability-v1from
32-reject-overlong-hrp
Closed

BenWestgate wants to merge 2 commits into
reviewability-v1from
32-reject-overlong-hrp

Conversation

@BenWestgate

Copy link
Copy Markdown
Owner

Fixes #32.

BIP173 limits the human-readable part to 1-83 US-ASCII characters. Codex32 decoding accepted otherwise-valid strings with longer HRPs, and public correction contexts could admit the same invalid namespace.

Reject HRPs longer than 83 characters in _decode_codex32 and CorrectionContext validation. Keep the generic Bech32 checksum code independent so its checksum-period tests can still exercise longer synthetic HRPs.

Tests cover the 83/84-character decode boundary and invalid correction context. The identical patch passed the full CI matrix on #33; #33 was closed automatically when its head branch was renamed to match issue #32.

BIP-0173 limits the human-readable part to 1-83 US-ASCII characters.
bech32_decode enforces the character set and case rules but not this
length bound, and codex32's own checksum-period limits (93/1023
expanded symbols) don't cover it either, so an overlong HRP with a
short enough data part was accepted.

Add the check in _decode_codex32 rather than bech32_decode: the
latter is exercised directly by the generic BIP-0173 checksum-period
test vectors, which use HRPs far longer than 83 characters to test
the long checksum's own 1023-symbol period independent of any one
application's rules.

Ran the full test suite (861 passed), ruff check, ruff format --check,
and mypy on the changed files.

fixes #32
Reject correction contexts whose human-readable part exceeds the BIP173 83-character limit before correction preparation starts. Preserve 83-character opaque HRPs and cover the invalid context path.\n\nrefs #32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant