common/json_parse: json_to_bitcoin_amount fails to detect overflow and accepts negative/empty inputs
Los mantenedores suelen responder en 2 días
@bhuvan-somisetty ya está trabajando en esto.
Desde el 10/10/2026.
- #9618 de @bhuvan-somisetty — abierto
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 62/100
Línea de trabajo
El error está en json_to_bitcoin_amount() en common/json_parse.c, donde la comprobación de desbordamiento compara la misma expresión envuelta consigo misma, y el análisis de números acepta un '-' inicial y tokens vacíos. Empieza leyendo esa función y la llamada a strtoul, luego busca las pruebas existentes de json_parse y añade las tres entradas reportadas como casos. Está terminado cuando las tres devuelven false y los importes válidos siguen analizándose correctamente.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Issue and Steps to Reproduce
json_to_bitcoin_amount() in common/json_parse.c has multiple parsing and overflow validation flaws:
-
Tautological overflow check:
*satoshi = btc * (uint64_t)100000000 + sat; if (*satoshi != btc * (uint64_t)100000000 + sat) return false;Both sides of
*satoshi != btc * (uint64_t)100000000 + satevaluate the exact sameuint64_twrapped value after an overflow. Whenbtcis large (e.g.184467440738),btc * 100000000overflowsuint64_tand wraps around, but the check evaluateswrapped_val != wrapped_val(which isfalse), returningtruewith a corrupted satoshi value. -
Negative numbers & signs accepted:
strtoulaccepts leading'-'and converts negative values (such as"-1.00000000"or"-0.00000001") into large unsigned values (e.g.ULONG_MAX), wrapping around during multiplication and returningtrue. -
Empty tokens:
An empty token (tok->start == tok->end) is parsed as0satoshis and returnstrueinstead of returningfalse.
Steps to reproduce
Call json_to_bitcoin_amount() with:
"184467440738.00000000": returnstruewith wrapped amount90448385instead offalse."-1.00000000": returnstruewith corrupted amount instead offalse."": returnstruewith0satoshis instead offalse.
getinfo output
N/A (C unit parsing logic in common/json_parse.c)
- Lenguaje dominante
- C
- Estrellas
- 3.1k
- Forks
- 1k
- Merge medio
- 3 d 7 h
- PR fusionados (30 d)
- 42
Preparar el entorno
- Incluye un Dockerfile o un archivo de Docker Compose
- Tiene una plantilla de pull request
- Sin guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de ElementsProject/lightning
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 66/100
ElementsProject/lightning#9616 ·
Los mantenedores suelen responder en 2 días
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
ElementsProject/lightning#9593 ·
Los mantenedores suelen responder en 2 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
ElementsProject/lightning#9322 ·
Los mantenedores suelen responder en 2 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
ElementsProject/lightning#9206 ·
Los mantenedores suelen responder en 2 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
ElementsProject/lightning#9187 · 1 comentario · 1 reacción ·
Los mantenedores suelen responder en 2 días
Todos los issues de ElementsProject/lightning
Issues similares
-
good first issue help wanted
Dificultad 2/5 1-3 horas Aptitud para principiantes 77/100
Los mantenedores suelen responder en 1 día
-
Add `pdfcpu` to the pantryAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 1 día
-
bug good first issue
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
tmewett/BrogueCE#929 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
bug : find_key() compares kty against "ocy" instead of "oct", breaking kid-less HS256 verificationAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 77/100
OpenPrinting/cups#1756 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 1/5 1-3 horas Aptitud para principiantes 76/100
SteamGridDB/SGDBoop#147 ·