2021-07-27 12:28:05 +01:00
|
|
|
# Nimbus
|
|
|
|
# Copyright (c) 2018 Status Research & Development GmbH
|
|
|
|
# Licensed under either of
|
|
|
|
# * Apache License, version 2.0, ([LICENSE-APACHE](LICENSE-APACHE) or
|
|
|
|
# http://www.apache.org/licenses/LICENSE-2.0)
|
|
|
|
# * MIT license ([LICENSE-MIT](LICENSE-MIT) or
|
|
|
|
# http://opensource.org/licenses/MIT)
|
|
|
|
# at your option. This file may not be copied, modified, or distributed except
|
|
|
|
# according to those terms.
|
|
|
|
|
|
|
|
##
|
|
|
|
## Recover Address From Signature
|
|
|
|
## ==============================
|
|
|
|
##
|
|
|
|
## This module provides caching and direct versions for recovering the
|
|
|
|
## `EthAddress` from an extended signature. The caching version reduces
|
|
|
|
## calculation time for the price of maintaing it in a LRU cache.
|
|
|
|
|
|
|
|
import
|
|
|
|
../constants,
|
2022-01-18 13:05:00 +00:00
|
|
|
./keyed_queue/kq_rlp,
|
|
|
|
./utils_defs,
|
|
|
|
eth/[common, common/transaction, keys, rlp],
|
2021-07-27 12:28:05 +01:00
|
|
|
nimcrypto,
|
2022-01-18 13:05:00 +00:00
|
|
|
stew/[keyed_queue, results],
|
2021-07-27 12:28:05 +01:00
|
|
|
stint
|
|
|
|
|
2021-08-24 14:34:58 +07:00
|
|
|
export
|
|
|
|
utils_defs
|
|
|
|
|
2022-01-18 13:05:00 +00:00
|
|
|
{.push raises: [Defect].}
|
|
|
|
|
2021-07-27 12:28:05 +01:00
|
|
|
const
|
|
|
|
INMEMORY_SIGNATURES* = ##\
|
2022-01-18 13:05:00 +00:00
|
|
|
## Default number of recent block signatures to keep in memory
|
2021-07-27 12:28:05 +01:00
|
|
|
4096
|
|
|
|
|
|
|
|
type
|
2022-01-18 13:05:00 +00:00
|
|
|
EcKey* = ##\
|
|
|
|
## Internal key used for the LRU cache (derived from Hash256).
|
|
|
|
array[32,byte]
|
2021-07-27 12:28:05 +01:00
|
|
|
|
2022-01-18 13:05:00 +00:00
|
|
|
EcAddrResult* = ##\
|
|
|
|
## Typical `EthAddress` result as returned by `ecRecover()` functions.
|
|
|
|
Result[EthAddress,UtilsError]
|
2021-07-27 12:28:05 +01:00
|
|
|
|
2022-01-18 13:05:00 +00:00
|
|
|
EcRecover* = object
|
|
|
|
size: uint
|
|
|
|
q: KeyedQueue[EcKey,EthAddress]
|
2021-07-27 12:28:05 +01:00
|
|
|
|
|
|
|
# ------------------------------------------------------------------------------
|
|
|
|
# Private helpers
|
|
|
|
# ------------------------------------------------------------------------------
|
|
|
|
|
2022-01-18 13:05:00 +00:00
|
|
|
proc vrsSerialised(tx: Transaction): Result[array[65,byte],UtilsError] =
|
|
|
|
## Parts copied from `transaction.getSignature`.
|
|
|
|
var data: array[65,byte]
|
|
|
|
data[0..31] = tx.R.toByteArrayBE
|
|
|
|
data[32..63] = tx.S.toByteArrayBE
|
|
|
|
|
|
|
|
if tx.txType != TxLegacy:
|
|
|
|
data[64] = tx.V.byte
|
|
|
|
elif tx.V >= EIP155_CHAIN_ID_OFFSET:
|
|
|
|
data[64] = byte(1 - (tx.V and 1))
|
|
|
|
elif tx.V == 27 or tx.V == 28:
|
|
|
|
data[64] = byte(tx.V - 27)
|
|
|
|
else:
|
|
|
|
return err((errSigPrefixError,"")) # legacy error
|
|
|
|
|
|
|
|
ok(data)
|
|
|
|
|
|
|
|
proc encodePreSealed(header: BlockHeader): seq[byte] =
|
|
|
|
## Cut sigature off `extraData` header field.
|
|
|
|
if header.extraData.len < EXTRA_SEAL:
|
|
|
|
return rlp.encode(header)
|
2021-07-27 12:28:05 +01:00
|
|
|
|
|
|
|
var rlpHeader = header
|
|
|
|
rlpHeader.extraData.setLen(header.extraData.len - EXTRA_SEAL)
|
|
|
|
rlp.encode(rlpHeader)
|
|
|
|
|
2022-01-18 13:05:00 +00:00
|
|
|
proc hashPreSealed(header: BlockHeader): Hash256 =
|
2021-07-27 12:28:05 +01:00
|
|
|
## Returns the hash of a block prior to it being sealed.
|
|
|
|
keccak256.digest header.encodePreSealed
|
|
|
|
|
|
|
|
|
2022-01-18 13:05:00 +00:00
|
|
|
proc recoverImpl(rawSig: openArray[byte]; msg: Hash256): EcAddrResult =
|
2021-07-27 12:28:05 +01:00
|
|
|
## Extract account address from the last 65 bytes of the `extraData` argument
|
|
|
|
## (which is typically the bock header field with the same name.) The second
|
|
|
|
## argument `hash` is used to extract the intermediate public key. Typically,
|
|
|
|
## this would be the hash of the block header without the last 65 bytes of
|
|
|
|
## the `extraData` field reserved for the signature.
|
2022-01-18 13:05:00 +00:00
|
|
|
if rawSig.len < EXTRA_SEAL:
|
2021-07-27 12:28:05 +01:00
|
|
|
return err((errMissingSignature,""))
|
|
|
|
|
|
|
|
let sig = Signature.fromRaw(
|
2022-01-18 13:05:00 +00:00
|
|
|
rawSig.toOpenArray(rawSig.len - EXTRA_SEAL, rawSig.high))
|
2021-07-27 12:28:05 +01:00
|
|
|
if sig.isErr:
|
|
|
|
return err((errSkSigResult,$sig.error))
|
|
|
|
|
|
|
|
# Recover the public key from signature and seal hash
|
2022-01-18 13:05:00 +00:00
|
|
|
let pubKey = recover(sig.value, SKMessage(msg.data))
|
2021-07-27 12:28:05 +01:00
|
|
|
if pubKey.isErr:
|
|
|
|
return err((errSkPubKeyResult,$pubKey.error))
|
|
|
|
|
|
|
|
# Convert public key to address.
|
2022-01-18 13:05:00 +00:00
|
|
|
ok(pubKey.value.toCanonicalAddress)
|
2021-07-27 12:28:05 +01:00
|
|
|
|
|
|
|
# ------------------------------------------------------------------------------
|
2022-01-18 13:05:00 +00:00
|
|
|
# Public function: straight ecRecover versions
|
2021-07-27 12:28:05 +01:00
|
|
|
# ------------------------------------------------------------------------------
|
|
|
|
|
2022-01-18 13:05:00 +00:00
|
|
|
proc ecRecover*(header: BlockHeader): EcAddrResult =
|
|
|
|
## Extracts account address from the `extraData` field (last 65 bytes) of
|
|
|
|
## the argument header.
|
|
|
|
header.extraData.recoverImpl(header.hashPreSealed)
|
|
|
|
|
|
|
|
proc ecRecover*(tx: var Transaction): EcAddrResult =
|
|
|
|
## Extracts sender address from transaction. This function has similar
|
|
|
|
## functionality as `transaction.getSender()`.
|
|
|
|
let txSig = tx.vrsSerialised
|
|
|
|
if txSig.isErr:
|
|
|
|
return err(txSig.error)
|
|
|
|
txSig.value.recoverImpl(tx.txHashNoSignature)
|
|
|
|
|
|
|
|
proc ecRecover*(tx: Transaction): EcAddrResult =
|
|
|
|
## Variant of `ecRecover()` for call-by-value header.
|
|
|
|
var ty = tx
|
|
|
|
ty.ecRecover
|
2021-07-27 12:28:05 +01:00
|
|
|
|
|
|
|
# ------------------------------------------------------------------------------
|
|
|
|
# Public constructor for caching ecRecover version
|
|
|
|
# ------------------------------------------------------------------------------
|
|
|
|
|
2022-01-18 13:05:00 +00:00
|
|
|
proc init*(er: var EcRecover; cacheSize = INMEMORY_SIGNATURES; initSize = 10) =
|
|
|
|
## Inialise recover cache
|
|
|
|
er.size = cacheSize.uint
|
|
|
|
er.q.init(initSize)
|
2021-07-27 12:28:05 +01:00
|
|
|
|
2022-01-18 13:05:00 +00:00
|
|
|
proc init*(T: type EcRecover;
|
|
|
|
cacheSize = INMEMORY_SIGNATURES; initSize = 10): T =
|
|
|
|
## Inialise recover cache
|
|
|
|
result.init(cacheSize, initSize)
|
2021-07-27 12:28:05 +01:00
|
|
|
|
2022-01-18 13:05:00 +00:00
|
|
|
# ------------------------------------------------------------------------------
|
|
|
|
# Public functions: miscellaneous
|
|
|
|
# ------------------------------------------------------------------------------
|
2021-07-27 12:28:05 +01:00
|
|
|
|
2022-01-18 13:05:00 +00:00
|
|
|
proc len*(er: var EcRecover): int =
|
|
|
|
## Returns the current number of entries in the LRU cache.
|
|
|
|
er.q.len
|
2021-07-27 12:28:05 +01:00
|
|
|
|
|
|
|
# ------------------------------------------------------------------------------
|
2022-01-18 13:05:00 +00:00
|
|
|
# Public functions: caching ecRecover version
|
2021-07-27 12:28:05 +01:00
|
|
|
# ------------------------------------------------------------------------------
|
|
|
|
|
2022-01-18 13:05:00 +00:00
|
|
|
proc ecRecover*(er: var EcRecover; header: var BlockHeader): EcAddrResult
|
|
|
|
{.gcsafe, raises: [Defect,CatchableError].} =
|
2021-07-27 12:28:05 +01:00
|
|
|
## Extract account address from `extraData` field (last 65 bytes) of the
|
|
|
|
## argument header. The result is kept in a LRU cache to re-purposed for
|
|
|
|
## improved result delivery avoiding calculations.
|
2022-01-18 13:05:00 +00:00
|
|
|
let key = header.blockHash.data
|
|
|
|
block:
|
|
|
|
let rc = er.q.lruFetch(key)
|
|
|
|
if rc.isOK:
|
|
|
|
return ok(rc.value)
|
|
|
|
block:
|
|
|
|
let rc = header.extraData.recoverImpl(header.hashPreSealed)
|
|
|
|
if rc.isOK:
|
|
|
|
return ok(er.q.lruAppend(key, rc.value, er.size.int))
|
|
|
|
err(rc.error)
|
|
|
|
|
|
|
|
proc ecRecover*(er: var EcRecover; header: BlockHeader): EcAddrResult
|
|
|
|
{.gcsafe, raises: [Defect,CatchableError].} =
|
|
|
|
## Variant of `ecRecover()` for call-by-value header
|
|
|
|
var hdr = header
|
|
|
|
er.ecRecover(hdr)
|
|
|
|
|
|
|
|
proc ecRecover*(er: var EcRecover; hash: Hash256): EcAddrResult
|
|
|
|
{.gcsafe, raises: [Defect,CatchableError].} =
|
|
|
|
## Variant of `ecRecover()` for hash only. Will only succeed it the
|
|
|
|
## argument hash is uk the LRU queue.
|
|
|
|
let rc = er.q.lruFetch(hash.data)
|
|
|
|
if rc.isOK:
|
|
|
|
return ok(rc.value)
|
|
|
|
err((errItemNotFound,""))
|
2021-07-27 12:28:05 +01:00
|
|
|
|
|
|
|
# ------------------------------------------------------------------------------
|
2022-01-18 13:05:00 +00:00
|
|
|
# Public RLP mixin functions for caching version
|
2021-07-27 12:28:05 +01:00
|
|
|
# ------------------------------------------------------------------------------
|
|
|
|
|
2022-01-18 13:05:00 +00:00
|
|
|
proc append*(rw: var RlpWriter; data: EcRecover)
|
|
|
|
{.raises: [Defect,KeyError].} =
|
|
|
|
## Generic support for `rlp.encode()`
|
|
|
|
rw.append((data.size,data.q))
|
2021-07-27 12:28:05 +01:00
|
|
|
|
2022-01-18 13:05:00 +00:00
|
|
|
proc read*(rlp: var Rlp; Q: type EcRecover): Q
|
|
|
|
{.raises: [Defect,KeyError].} =
|
|
|
|
## Generic support for `rlp.decode()` for loading the cache from a
|
2021-07-27 12:28:05 +01:00
|
|
|
## serialised data stream.
|
2022-01-18 13:05:00 +00:00
|
|
|
(result.size, result.q) = rlp.read((type result.size, type result.q))
|
|
|
|
|
|
|
|
# ------------------------------------------------------------------------------
|
|
|
|
# Debugging
|
|
|
|
# ------------------------------------------------------------------------------
|
|
|
|
|
|
|
|
iterator keyItemPairs*(er: var EcRecover): (EcKey,EthAddress)
|
|
|
|
{.gcsafe, raises: [Defect,CatchableError].} =
|
|
|
|
var rc = er.q.first
|
|
|
|
while rc.isOK:
|
|
|
|
yield (rc.value.key, rc.value.data)
|
|
|
|
rc = er.q.next(rc.value.key)
|
2021-07-27 12:28:05 +01:00
|
|
|
|
|
|
|
# ------------------------------------------------------------------------------
|
|
|
|
# End
|
|
|
|
# ------------------------------------------------------------------------------
|