diff --git a/CHANGELOG.md b/CHANGELOG.md index 6fdcdca38..9ba9c3bab 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,7 @@ +# 6.1.7 +__added__ +- skip ecc library verification via DANGER_DO_NOT_VERIFY_ECCLIB flag + # 6.1.6 __fixed__ - Fix sighash treatment when signing taproot script sign scripts using Psbt (#2104) diff --git a/package-lock.json b/package-lock.json index 057cebca1..c7e89bad2 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "bitcoinjs-lib", - "version": "6.1.6", + "version": "6.1.7", "lockfileVersion": 2, "requires": true, "packages": { "": { "name": "bitcoinjs-lib", - "version": "6.1.6", + "version": "6.1.7", "license": "MIT", "dependencies": { "@noble/hashes": "^1.2.0", diff --git a/package.json b/package.json index 77f8bce1a..70998cdf1 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "bitcoinjs-lib", - "version": "6.1.6", + "version": "6.1.7", "description": "Client-side Bitcoin JavaScript library", "main": "./src/index.js", "types": "./src/index.d.ts", diff --git a/src/ecc_lib.d.ts b/src/ecc_lib.d.ts index abb750a32..abe31ed95 100644 --- a/src/ecc_lib.d.ts +++ b/src/ecc_lib.d.ts @@ -5,8 +5,11 @@ import { TinySecp256k1Interface } from './types'; * If `eccLib` is a new instance, it will be verified before setting it as the active library. * * @param eccLib The instance of the ECC library to initialize. + * @param opts Extra initialization options. Use {DANGER_DO_NOT_VERIFY_ECCLIB:true} if ecc verification should not be executed. Not recommended! */ -export declare function initEccLib(eccLib: TinySecp256k1Interface | undefined): void; +export declare function initEccLib(eccLib: TinySecp256k1Interface | undefined, opts?: { + DANGER_DO_NOT_VERIFY_ECCLIB: boolean; +}): void; /** * Retrieves the ECC Library instance. * Throws an error if the ECC Library is not provided. diff --git a/src/ecc_lib.js b/src/ecc_lib.js index 22202da98..8431956cc 100644 --- a/src/ecc_lib.js +++ b/src/ecc_lib.js @@ -8,14 +8,16 @@ const _ECCLIB_CACHE = {}; * If `eccLib` is a new instance, it will be verified before setting it as the active library. * * @param eccLib The instance of the ECC library to initialize. + * @param opts Extra initialization options. Use {DANGER_DO_NOT_VERIFY_ECCLIB:true} if ecc verification should not be executed. Not recommended! */ -function initEccLib(eccLib) { +function initEccLib(eccLib, opts) { if (!eccLib) { // allow clearing the library _ECCLIB_CACHE.eccLib = eccLib; } else if (eccLib !== _ECCLIB_CACHE.eccLib) { - // new instance, verify it - verifyEcc(eccLib); + if (!opts?.DANGER_DO_NOT_VERIFY_ECCLIB) + // new instance, verify it + verifyEcc(eccLib); _ECCLIB_CACHE.eccLib = eccLib; } } diff --git a/test/ecc_lib.spec.ts b/test/ecc_lib.spec.ts new file mode 100644 index 000000000..e8bd2a41e --- /dev/null +++ b/test/ecc_lib.spec.ts @@ -0,0 +1,22 @@ +import { initEccLib } from '../src'; +import { describe, test } from 'mocha'; +import * as assert from 'assert'; + +describe(`initEccLib`, () => { + beforeEach(() => { + initEccLib(undefined); + }); + + test('initEccLib should fail when invalid', () => { + assert.throws(() => { + initEccLib({ isXOnlyPoint: () => false } as any); + }, 'Error: ecc library invalid'); + }); + + test('initEccLib should not fail when DANGER_DO_NOT_VERIFY_ECCLIB = true', () => { + initEccLib({ isXOnlyPoint: () => false } as any, { + DANGER_DO_NOT_VERIFY_ECCLIB: true, + }); + assert.ok('it does not fail, verification is excluded'); + }); +}); diff --git a/ts_src/ecc_lib.ts b/ts_src/ecc_lib.ts index fbd1fcdb8..07946dd7f 100644 --- a/ts_src/ecc_lib.ts +++ b/ts_src/ecc_lib.ts @@ -8,14 +8,19 @@ const _ECCLIB_CACHE: { eccLib?: TinySecp256k1Interface } = {}; * If `eccLib` is a new instance, it will be verified before setting it as the active library. * * @param eccLib The instance of the ECC library to initialize. + * @param opts Extra initialization options. Use {DANGER_DO_NOT_VERIFY_ECCLIB:true} if ecc verification should not be executed. Not recommended! */ -export function initEccLib(eccLib: TinySecp256k1Interface | undefined): void { +export function initEccLib( + eccLib: TinySecp256k1Interface | undefined, + opts?: { DANGER_DO_NOT_VERIFY_ECCLIB: boolean }, +): void { if (!eccLib) { // allow clearing the library _ECCLIB_CACHE.eccLib = eccLib; } else if (eccLib !== _ECCLIB_CACHE.eccLib) { - // new instance, verify it - verifyEcc(eccLib!); + if (!opts?.DANGER_DO_NOT_VERIFY_ECCLIB) + // new instance, verify it + verifyEcc(eccLib!); _ECCLIB_CACHE.eccLib = eccLib; } }