465bca734econtrib: reject divergent verify-commits history (Lőrinc)b3d1dca338contrib: fail on verify-commits ancestry errors (Lőrinc) Pull request description: **Problem:** `verify-commits.py` checks a Git commit's history for trusted signatures and tree hashes back to configured roots. The documented workflow runs this check after fetching a commit and before checkout, proceeding only when the script succeeds. A commit that is an ancestor of a configured root is intentionally accepted without checking earlier history. The script also takes this success path after Git errors or for divergent commits, even though neither establishes that relationship. **Fix:** Require Git to prove the ancestor relationship before taking this success path. **Reproducers:** Each commit can be validated manually. <details><summary>Manual reproducer: Git error</summary> Run this on `master` and at this PR's head: ```bash contrib/verify-commits/verify-commits.py 0000000000000000000000000000000000000000 && echo ❌ || echo ✅ ``` `master` exits successfully without verifying the missing commit, while the PR head rejects the Git error. </details> <details><summary>Manual reproducer: divergent history</summary> On `master` and at this PR's head, create an unreferenced sibling of the trusted root and run the verifier: ```bash root=$(head -n1 contrib/verify-commits/trusted-git-root) divergent_commit=$(git commit-tree "$root^{tree}" -p "$root^" -m 'divergent commit') contrib/verify-commits/verify-commits.py "$divergent_commit" && echo ❌ || echo ✅ ``` `master` exits successfully without verifying the sibling commit, while the PR head rejects divergent history. </details> This issue was also found and disclosed responsibly by the Red Team 🟥. ACKs for top commit: 151henry151: tACK465bca734ejeanpablojp: tACK465bca734eachow101: ACK465bca734esedited: ACK465bca734emaflcko: review ACK465bca734e🥜 Tree-SHA512: 72b8cd9902d881e59a1d99fda8e5d511806826fa27c05a2c21a7d2eb62b2a5a0b1b6bdc67e8d19d57f9171278f4858fd019eb7890b960df0475ba4713683f0ac
Repository Tools
Developer tools
Specific tools for developers working on this repository.
Additional tools, including the github-merge.py script, are available in the maintainer-tools repository.
Verify-Commits
Tool to verify that every merge commit was signed by a developer using the github-merge.py script.
Linearize
Construct a linear, no-fork, best version of the blockchain.
Qos
A Linux bash script that will set up traffic control (tc) to limit the outgoing bandwidth for connections to the Bitcoin network. This means one can have an always-on bitcoind instance running, and another local bitcoind/bitcoin-qt instance which connects to this node and receives blocks from it.
Seeds
Utility to generate the pnSeed[] array that is compiled into the client.
ASMap
Utilities to analyze and process asmap files.
Build Tools and Keys
Packaging
The Debian subfolder contains the copyright file.
All other packaging related files can be found in the bitcoin-core/packaging repository.
MacDeploy
Scripts and notes for Mac builds.
Test and Verify Tools
TestGen
Utilities to generate test vectors for the data-driven Bitcoin tests.
Verify-Binaries
This script attempts to download and verify the signature file SHA256SUMS.asc from bitcoin.org.
Command Line Tools
Completions
Shell completions for bash and fish.
UTXO Set Tools
UTXO-to-SQLite
This script converts a compact-serialized UTXO set (as generated by Bitcoin Core with dumptxoutset)
to a SQLite3 database. For more details like e.g. the created table name and schema, refer to the
module docstring on top of the script, which is also contained in the command's --help output.