Skip to content

Fix DERSignature serialization length and integer tag - #329

Open
kumar-miskin wants to merge 2 commits into
petertodd:masterfrom
kumar-miskin:fix-der-signature-serialization
Open

kumar-miskin wants to merge 2 commits into
petertodd:masterfrom
kumar-miskin:fix-der-signature-serialization

Conversation

@kumar-miskin

@kumar-miskin kumar-miskin commented Oct 10, 2026 •

Copy link
Copy Markdown

Fixes #295.

DERSignature.stream_serialize omits the SEQUENCE body length and writes a SEQUENCE tag (0x30) before s where an INTEGER tag (0x02) is required. A valid signature such as 3006020101020101 currently serializes back as 30020101300101, which cannot be deserialized.

The change builds the two encoded INTEGER fields in a temporary stream, then writes the length-prefixed body after the SEQUENCE tag. It leaves deserialization and key signing/verification unchanged.

Prior art: #190 already identified the omitted sequence length, but was closed without merging. This patch addresses that omission and the second INTEGER tag reported in #295, with regression coverage. It is not a claim of a new discovery.

Tests:

  • Unmodified master: 149 tests pass.
  • Added exact-byte and stream tests fail before the fix, including four short/32-byte/leading-zero integer vectors.
  • Patched branch: python3 -m unittest discover passes all 152 tests on Linux/Python 3.10.12/OpenSSL 3.0.2.
  • Locally generated ECDSA signatures round-trip byte-for-byte and still verify.

The helper is not used internally for signature serialization, as noted in #190. This is a focused fix to its public serialization behavior, not a change to consensus validation or live wallet signing. No Windows/multi-version test matrix run locally.

AI-assisted patch preparation and testing.

Related: petertodd#295. Prior art: petertodd#190 identified the missing sequence length.
AI-assisted patch preparation and testing.
Cover exact encodings, leading-zero integer payloads, stream serialization and locally generated signatures that still verify after round-trip.
AI-assisted patch preparation and testing.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug in signature serialize/deserialize

1 participant