2021-07-04 11:00:56 +00:00
|
|
|
package audit
|
2020-10-27 12:14:06 +00:00
|
|
|
|
|
|
|
import (
|
2022-12-12 20:01:38 +00:00
|
|
|
"github.com/TrueCloudLab/frostfs-contract/common"
|
2020-12-17 15:58:12 +00:00
|
|
|
"github.com/nspcc-dev/neo-go/pkg/interop"
|
2021-06-30 10:59:32 +00:00
|
|
|
"github.com/nspcc-dev/neo-go/pkg/interop/contract"
|
2020-12-17 15:58:12 +00:00
|
|
|
"github.com/nspcc-dev/neo-go/pkg/interop/iterator"
|
2021-03-12 12:16:36 +00:00
|
|
|
"github.com/nspcc-dev/neo-go/pkg/interop/native/crypto"
|
2021-02-11 15:55:32 +00:00
|
|
|
"github.com/nspcc-dev/neo-go/pkg/interop/native/management"
|
2020-10-27 12:14:06 +00:00
|
|
|
"github.com/nspcc-dev/neo-go/pkg/interop/runtime"
|
|
|
|
"github.com/nspcc-dev/neo-go/pkg/interop/storage"
|
|
|
|
)
|
|
|
|
|
|
|
|
type (
|
2020-12-17 15:58:12 +00:00
|
|
|
auditHeader struct {
|
|
|
|
epoch int
|
|
|
|
cid []byte
|
|
|
|
from interop.PublicKey
|
2020-10-27 12:14:06 +00:00
|
|
|
}
|
|
|
|
)
|
|
|
|
|
2022-04-14 11:56:51 +00:00
|
|
|
// Audit key is a combination of the epoch, the container ID and the public key of the node that
|
|
|
|
// has executed the audit. Together, it shouldn't be more than 64 bytes. We can't shrink
|
2020-12-17 15:58:12 +00:00
|
|
|
// epoch and container ID since we iterate over these values. But we can shrink
|
|
|
|
// public key by using first bytes of the hashed value.
|
2020-10-27 12:14:06 +00:00
|
|
|
|
2021-11-29 17:58:27 +00:00
|
|
|
// V2 format
|
2020-12-17 15:58:12 +00:00
|
|
|
const maxKeySize = 24 // 24 + 32 (container ID length) + 8 (epoch length) = 64
|
2020-10-27 12:14:06 +00:00
|
|
|
|
2020-12-17 15:58:12 +00:00
|
|
|
func (a auditHeader) ID() []byte {
|
|
|
|
var buf interface{} = a.epoch
|
2020-10-27 12:14:06 +00:00
|
|
|
|
2021-03-12 12:16:36 +00:00
|
|
|
hashedKey := crypto.Sha256(a.from)
|
2020-12-17 15:58:12 +00:00
|
|
|
shortedKey := hashedKey[:maxKeySize]
|
2020-10-27 12:14:06 +00:00
|
|
|
|
2020-12-17 15:58:12 +00:00
|
|
|
return append(buf.([]byte), append(a.cid, shortedKey...)...)
|
|
|
|
}
|
2020-10-27 12:14:06 +00:00
|
|
|
|
2020-12-17 15:58:12 +00:00
|
|
|
const (
|
2021-02-11 15:55:32 +00:00
|
|
|
netmapContractKey = "netmapScriptHash"
|
2021-04-27 10:48:40 +00:00
|
|
|
|
|
|
|
notaryDisabledKey = "notary"
|
2020-10-27 12:14:06 +00:00
|
|
|
)
|
|
|
|
|
2021-05-12 08:31:07 +00:00
|
|
|
func _deploy(data interface{}, isUpdate bool) {
|
2021-12-27 07:15:36 +00:00
|
|
|
ctx := storage.GetContext()
|
2023-02-16 11:38:45 +00:00
|
|
|
|
|
|
|
//TODO(@acid-ant): #9 remove notaryDisabled from args in future version
|
|
|
|
if data.([]interface{})[0].(bool) {
|
|
|
|
panic(common.PanicMsgForNotaryDisabledEnv)
|
|
|
|
}
|
|
|
|
storage.Delete(ctx, notaryDisabledKey)
|
|
|
|
|
2021-06-03 07:49:07 +00:00
|
|
|
if isUpdate {
|
2021-12-27 08:49:30 +00:00
|
|
|
args := data.([]interface{})
|
|
|
|
common.CheckVersion(args[len(args)-1].(int))
|
2021-06-03 07:49:07 +00:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2021-11-29 16:34:11 +00:00
|
|
|
args := data.(struct {
|
2023-02-16 11:38:45 +00:00
|
|
|
//TODO(@acid-ant): #9 remove notaryDisabled in future version
|
2021-11-29 16:34:11 +00:00
|
|
|
notaryDisabled bool
|
|
|
|
addrNetmap interop.Hash160
|
|
|
|
})
|
2021-05-12 08:31:07 +00:00
|
|
|
|
2021-11-29 16:43:01 +00:00
|
|
|
if len(args.addrNetmap) != interop.Hash160Len {
|
2021-11-29 10:51:57 +00:00
|
|
|
panic("incorrect length of contract script hash")
|
2020-10-27 12:14:06 +00:00
|
|
|
}
|
|
|
|
|
2021-11-29 16:34:11 +00:00
|
|
|
storage.Put(ctx, netmapContractKey, args.addrNetmap)
|
2020-10-27 12:14:06 +00:00
|
|
|
|
|
|
|
runtime.Log("audit contract initialized")
|
|
|
|
}
|
|
|
|
|
2022-04-14 11:56:51 +00:00
|
|
|
// Update method updates contract source code and manifest. It can be invoked
|
2021-09-20 15:41:46 +00:00
|
|
|
// only by committee.
|
2021-09-21 12:58:37 +00:00
|
|
|
func Update(script []byte, manifest []byte, data interface{}) {
|
2021-09-20 15:41:46 +00:00
|
|
|
if !common.HasUpdateAccess() {
|
|
|
|
panic("only committee can update contract")
|
2021-02-11 15:55:32 +00:00
|
|
|
}
|
|
|
|
|
2021-11-09 10:55:21 +00:00
|
|
|
contract.Call(interop.Hash160(management.Hash), "update",
|
|
|
|
contract.All, script, manifest, common.AppendVersion(data))
|
2021-02-11 15:55:32 +00:00
|
|
|
runtime.Log("audit contract updated")
|
|
|
|
}
|
|
|
|
|
2022-04-14 11:56:51 +00:00
|
|
|
// Put method stores a stable marshalled `DataAuditResult` structure. It can be
|
2021-07-05 16:25:29 +00:00
|
|
|
// invoked only by Inner Ring nodes.
|
|
|
|
//
|
2022-04-14 11:56:51 +00:00
|
|
|
// Inner Ring nodes perform audit of containers and produce `DataAuditResult`
|
|
|
|
// structures. They are stored in audit contract and used for settlements
|
2021-07-05 16:25:29 +00:00
|
|
|
// in later epochs.
|
2021-05-21 11:37:31 +00:00
|
|
|
func Put(rawAuditResult []byte) {
|
2021-03-09 19:15:58 +00:00
|
|
|
ctx := storage.GetContext()
|
2021-04-29 13:07:08 +00:00
|
|
|
|
2023-02-16 11:38:45 +00:00
|
|
|
innerRing := common.InnerRingNodes()
|
2020-10-27 12:14:06 +00:00
|
|
|
|
2020-12-17 15:58:12 +00:00
|
|
|
hdr := newAuditHeader(rawAuditResult)
|
|
|
|
presented := false
|
2020-10-27 12:14:06 +00:00
|
|
|
|
|
|
|
for i := range innerRing {
|
|
|
|
ir := innerRing[i]
|
2022-03-21 11:01:45 +00:00
|
|
|
if common.BytesEqual(ir, hdr.from) {
|
2020-10-27 12:14:06 +00:00
|
|
|
presented = true
|
2020-12-17 15:58:12 +00:00
|
|
|
|
2020-10-27 12:14:06 +00:00
|
|
|
break
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-12-17 15:58:12 +00:00
|
|
|
if !runtime.CheckWitness(hdr.from) || !presented {
|
2021-11-29 10:51:57 +00:00
|
|
|
panic("put access denied")
|
2020-10-27 12:14:06 +00:00
|
|
|
}
|
|
|
|
|
2020-12-17 15:58:12 +00:00
|
|
|
storage.Put(ctx, hdr.ID(), rawAuditResult)
|
2020-10-27 12:14:06 +00:00
|
|
|
|
2020-12-17 15:58:12 +00:00
|
|
|
runtime.Log("audit: result has been saved")
|
2020-10-27 12:14:06 +00:00
|
|
|
}
|
|
|
|
|
2022-04-14 11:56:51 +00:00
|
|
|
// Get method returns a stable marshaled DataAuditResult structure.
|
2021-07-05 16:25:29 +00:00
|
|
|
//
|
2022-04-14 11:56:51 +00:00
|
|
|
// The ID of the DataAuditResult can be obtained from listing methods.
|
2020-12-17 15:58:12 +00:00
|
|
|
func Get(id []byte) []byte {
|
2021-03-09 19:15:58 +00:00
|
|
|
ctx := storage.GetReadOnlyContext()
|
2020-12-17 15:58:12 +00:00
|
|
|
return storage.Get(ctx, id).([]byte)
|
2020-10-27 12:14:06 +00:00
|
|
|
}
|
|
|
|
|
2022-04-14 11:56:51 +00:00
|
|
|
// List method returns a list of all available DataAuditResult IDs from
|
|
|
|
// the contract storage.
|
2020-12-17 15:58:12 +00:00
|
|
|
func List() [][]byte {
|
2021-03-09 19:15:58 +00:00
|
|
|
ctx := storage.GetReadOnlyContext()
|
2021-02-08 15:23:08 +00:00
|
|
|
it := storage.Find(ctx, []byte{}, storage.KeysOnly)
|
2020-10-27 12:14:06 +00:00
|
|
|
|
2020-12-17 15:58:12 +00:00
|
|
|
return list(it)
|
|
|
|
}
|
2020-10-27 12:14:06 +00:00
|
|
|
|
2022-04-14 11:56:51 +00:00
|
|
|
// ListByEpoch method returns a list of DataAuditResult IDs generated during
|
|
|
|
// the specified epoch.
|
2020-12-17 15:58:12 +00:00
|
|
|
func ListByEpoch(epoch int) [][]byte {
|
2021-03-09 19:15:58 +00:00
|
|
|
ctx := storage.GetReadOnlyContext()
|
2021-04-01 06:36:29 +00:00
|
|
|
var buf interface{} = epoch
|
|
|
|
it := storage.Find(ctx, buf.([]byte), storage.KeysOnly)
|
2020-10-27 12:14:06 +00:00
|
|
|
|
2020-12-17 15:58:12 +00:00
|
|
|
return list(it)
|
|
|
|
}
|
2020-10-27 12:14:06 +00:00
|
|
|
|
2022-04-14 11:56:51 +00:00
|
|
|
// ListByCID method returns a list of DataAuditResult IDs generated during
|
|
|
|
// the specified epoch for the specified container.
|
2020-12-17 15:58:12 +00:00
|
|
|
func ListByCID(epoch int, cid []byte) [][]byte {
|
2021-03-09 19:15:58 +00:00
|
|
|
ctx := storage.GetReadOnlyContext()
|
|
|
|
|
2020-12-17 15:58:12 +00:00
|
|
|
var buf interface{} = epoch
|
2020-10-27 12:14:06 +00:00
|
|
|
|
2020-12-17 15:58:12 +00:00
|
|
|
prefix := append(buf.([]byte), cid...)
|
2021-02-08 15:23:08 +00:00
|
|
|
it := storage.Find(ctx, prefix, storage.KeysOnly)
|
2020-10-27 12:14:06 +00:00
|
|
|
|
2020-12-17 15:58:12 +00:00
|
|
|
return list(it)
|
|
|
|
}
|
2020-10-27 12:14:06 +00:00
|
|
|
|
2022-04-14 11:56:51 +00:00
|
|
|
// ListByNode method returns a list of DataAuditResult IDs generated in
|
|
|
|
// the specified epoch for the specified container by the specified Inner Ring node.
|
2020-12-17 15:58:12 +00:00
|
|
|
func ListByNode(epoch int, cid []byte, key interop.PublicKey) [][]byte {
|
2021-03-09 19:15:58 +00:00
|
|
|
ctx := storage.GetReadOnlyContext()
|
2020-12-17 15:58:12 +00:00
|
|
|
hdr := auditHeader{
|
|
|
|
epoch: epoch,
|
|
|
|
cid: cid,
|
|
|
|
from: key,
|
|
|
|
}
|
2020-10-27 12:14:06 +00:00
|
|
|
|
2021-02-08 15:23:08 +00:00
|
|
|
it := storage.Find(ctx, hdr.ID(), storage.KeysOnly)
|
2020-10-27 12:14:06 +00:00
|
|
|
|
2020-12-17 15:58:12 +00:00
|
|
|
return list(it)
|
|
|
|
}
|
2020-10-27 12:14:06 +00:00
|
|
|
|
2020-12-17 15:58:12 +00:00
|
|
|
func list(it iterator.Iterator) [][]byte {
|
|
|
|
var result [][]byte
|
2020-10-27 12:14:06 +00:00
|
|
|
|
2021-02-11 15:55:32 +00:00
|
|
|
ignore := [][]byte{
|
|
|
|
[]byte(netmapContractKey),
|
|
|
|
}
|
|
|
|
|
|
|
|
loop:
|
2020-12-17 15:58:12 +00:00
|
|
|
for iterator.Next(it) {
|
2021-02-08 15:23:08 +00:00
|
|
|
key := iterator.Value(it).([]byte) // iterator MUST BE `storage.KeysOnly`
|
2021-02-11 15:55:32 +00:00
|
|
|
for _, ignoreKey := range ignore {
|
|
|
|
if common.BytesEqual(key, ignoreKey) {
|
|
|
|
continue loop
|
|
|
|
}
|
2020-10-27 12:14:06 +00:00
|
|
|
}
|
2020-12-17 15:58:12 +00:00
|
|
|
|
|
|
|
result = append(result, key)
|
2020-10-27 12:14:06 +00:00
|
|
|
}
|
|
|
|
|
2020-12-17 15:58:12 +00:00
|
|
|
return result
|
2020-10-27 12:14:06 +00:00
|
|
|
}
|
|
|
|
|
2022-04-14 11:56:51 +00:00
|
|
|
// Version returns the version of the contract.
|
2020-12-17 15:58:12 +00:00
|
|
|
func Version() int {
|
2021-07-29 11:44:53 +00:00
|
|
|
return common.Version
|
2020-10-27 12:14:06 +00:00
|
|
|
}
|
|
|
|
|
2022-04-14 11:56:51 +00:00
|
|
|
// readNext reads the length from the first byte, and then reads data (max 127 bytes).
|
2020-12-17 15:58:12 +00:00
|
|
|
func readNext(input []byte) ([]byte, int) {
|
|
|
|
var buf interface{} = input[0]
|
|
|
|
ln := buf.(int)
|
|
|
|
|
|
|
|
return input[1 : 1+ln], 1 + ln
|
2020-10-27 12:14:06 +00:00
|
|
|
}
|
|
|
|
|
2020-12-17 15:58:12 +00:00
|
|
|
func newAuditHeader(input []byte) auditHeader {
|
2021-11-29 17:58:27 +00:00
|
|
|
// V2 format
|
2020-12-21 14:17:17 +00:00
|
|
|
offset := int(input[1])
|
|
|
|
offset = 2 + offset + 1 // version prefix + version len + epoch prefix
|
|
|
|
|
|
|
|
var buf interface{} = input[offset : offset+8] // [ 8 integer bytes ]
|
2020-12-17 15:58:12 +00:00
|
|
|
epoch := buf.(int)
|
|
|
|
|
2020-12-21 14:17:17 +00:00
|
|
|
offset = offset + 8
|
|
|
|
|
2020-12-17 15:58:12 +00:00
|
|
|
// cid is a nested structure with raw bytes
|
|
|
|
// [ cid struct prefix (wireType + len = 2 bytes), cid value wireType (1 byte), ... ]
|
2020-12-21 14:17:17 +00:00
|
|
|
cid, cidOffset := readNext(input[offset+2+1:])
|
2020-12-17 15:58:12 +00:00
|
|
|
|
|
|
|
// key is a raw byte
|
|
|
|
// [ public key wireType (1 byte), ... ]
|
2020-12-21 14:17:17 +00:00
|
|
|
key, _ := readNext(input[offset+2+1+cidOffset+1:])
|
2020-12-17 15:58:12 +00:00
|
|
|
|
|
|
|
return auditHeader{
|
|
|
|
epoch,
|
|
|
|
cid,
|
|
|
|
key,
|
|
|
|
}
|
2020-10-27 12:14:06 +00:00
|
|
|
}
|