Compare commits
33 Commits
feat-shami
...
cleverwild
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
62fb83469f | ||
|
|
d49c39130a | ||
|
|
c722712166 | ||
| 0677695b16 | |||
|
|
558910621b | ||
|
|
d7fe3a6377 | ||
|
|
27925a67ad | ||
| a0ac63f05c | |||
|
|
8dabec893e | ||
|
|
3d4bba3584 | ||
| 3ff0875c48 | |||
|
|
7cc745182f | ||
|
|
7de235f144 | ||
|
|
2b8acad415 | ||
|
|
95799e5da8 | ||
|
|
49e5f2c7f6 | ||
|
|
00426e597d | ||
|
|
10486e6a32 | ||
|
|
55b5b9361f | ||
|
|
5824df16b1 | ||
|
|
39d5dfd2e8 | ||
|
|
add058f1d5 | ||
|
|
5ecf3508d6 | ||
|
|
2b53023234 | ||
|
|
850e2b8669 | ||
|
|
4e11c27129 | ||
|
|
84e1ef7c85 | ||
|
|
7e23b3b2ec | ||
|
|
bb28d311a1 | ||
|
|
3302bb8995 | ||
|
|
772936937b | ||
|
|
7a64bcd1bf | ||
|
|
943d0ee72f |
109
AGENTS.md
109
AGENTS.md
@@ -1,13 +1,16 @@
|
|||||||
# AGENTS.md
|
# AGENTS.md
|
||||||
|
|
||||||
This file provides guidance to Codex (Codex.ai/code) when working with code in this repository.
|
Guidance for coding agents (Claude Code, Codex, …) working in this repository.
|
||||||
|
|
||||||
## Project Overview
|
## Project Overview
|
||||||
|
|
||||||
Arbiter is a **permissioned signing service** for cryptocurrency wallets. It consists of:
|
Arbiter is a **permissioned signing service** for cryptocurrency wallets:
|
||||||
|
|
||||||
- **`server/`** — Rust gRPC daemon that holds encrypted keys and enforces policies
|
- **`server/`** — Rust gRPC daemon that holds encrypted keys and enforces policies
|
||||||
- **`operator/`** — Flutter desktop app (macOS/Windows) with a Rust backend via Rinf
|
- **`useragent/`** — Flutter app (desktop + mobile + web targets) with a Rust core via `flutter_rust_bridge`
|
||||||
- **`protobufs/`** — Protocol Buffer definitions shared between server and client
|
- **`protobufs/`** — Protocol Buffer definitions shared between server and clients
|
||||||
|
- **`docs/`** — `ARCHITECTURE.md` (peer types, flows, threat model) and `IMPLEMENTATION.md`; treat them as the design source of truth and update them when behaviour changes
|
||||||
|
- **`scripts/`** — helper scripts, e.g. `gen_erc20_registry.py`
|
||||||
|
|
||||||
The vault never exposes key material; it only produces signatures when requests satisfy configured policies.
|
The vault never exposes key material; it only produces signatures when requests satisfy configured policies.
|
||||||
|
|
||||||
@@ -18,7 +21,7 @@ Tools are managed via [mise](https://mise.jdx.dev/). Install all required tools:
|
|||||||
mise install
|
mise install
|
||||||
```
|
```
|
||||||
|
|
||||||
Key versions: Rust 1.93.0 (with clippy), Flutter 3.38.9-stable, protoc 29.6, diesel_cli 2.3.6 (sqlite).
|
Key versions live in `mise.toml` (currently Rust 1.95.0 with clippy, Flutter 3.41.7-stable, protoc 29.6, diesel_cli 2.3.7 with `sqlite-bundled`, Python 3.14). Also provided there: `cargo-nextest`, `cargo-audit`, `cargo-vet`, `cargo-shear`, `cargo-mutants`, `cargo-features-manager`, `cargo-edit`, `ast-grep`, `flutter_rust_bridge_codegen`.
|
||||||
|
|
||||||
## Server (Rust workspace at `server/`)
|
## Server (Rust workspace at `server/`)
|
||||||
|
|
||||||
@@ -26,10 +29,14 @@ Key versions: Rust 1.93.0 (with clippy), Flutter 3.38.9-stable, protoc 29.6, die
|
|||||||
|
|
||||||
| Crate | Purpose |
|
| Crate | Purpose |
|
||||||
|---|---|
|
|---|---|
|
||||||
| `arbiter-proto` | Generated gRPC stubs + protobuf types; compiled from `protobufs/*.proto` via `tonic-prost-build` |
|
| `arbiter-proto` | Generated gRPC stubs + protobuf types (`tonic-prost-build`); also `ArbiterUrl`, `home_path()`, `BOOTSTRAP_PATH` |
|
||||||
| `arbiter-server` | Main daemon — actors, DB, EVM policy engine, gRPC service implementation |
|
| `arbiter-crypto` | Shared crypto primitives: `authn` (ML-DSA), `safecell` (hardened memory), `hashing::Hashable`, re-exported `x-wing` |
|
||||||
| `arbiter-operator` | Rust client library for the operator side of the gRPC protocol |
|
| `arbiter-macros` | `#[derive(Hashable)]` — canonical hashing of structs for the DB integrity layer |
|
||||||
| `arbiter-client` | Rust client library for SDK clients |
|
| `arbiter-server` | Main daemon — actors, peers, DB, EVM policy engine, gRPC service implementation |
|
||||||
|
| `arbiter-client` | Rust client library for SDK clients (`ArbiterClient`, EVM wallet, key storage) |
|
||||||
|
| `arbiter-tokens-registry` | Generated ERC-20 token registry used by token-transfer policies |
|
||||||
|
|
||||||
|
Workspace lints (`server/Cargo.toml`) are strict: most of clippy `pedantic`/`nursery` plus a large restriction set. `as` casts, indexing/slicing, `dbg!`, float arithmetic and undocumented `unsafe` are denied or warned — expect to add an `#[expect(..., reason = "...")]` rather than to silence a lint globally.
|
||||||
|
|
||||||
### Common Commands
|
### Common Commands
|
||||||
|
|
||||||
@@ -42,54 +49,78 @@ cargo build
|
|||||||
# Run the server daemon
|
# Run the server daemon
|
||||||
cargo run -p arbiter-server
|
cargo run -p arbiter-server
|
||||||
|
|
||||||
# Run all tests (preferred over cargo test)
|
# Run all tests (preferred over cargo test; CI uses --all-features)
|
||||||
cargo nextest run
|
cargo nextest run
|
||||||
|
|
||||||
# Run a single test
|
# Run a single test
|
||||||
cargo nextest run <test_name>
|
cargo nextest run <test_name>
|
||||||
|
|
||||||
# Lint
|
# Lint (CI runs it with -D warnings)
|
||||||
cargo clippy
|
cargo clippy --all -- -D warnings
|
||||||
|
|
||||||
# Security audit
|
# Security audit
|
||||||
cargo audit
|
cargo audit
|
||||||
|
|
||||||
|
# Supply-chain review (config in server/supply-chain/)
|
||||||
|
cargo vet
|
||||||
|
|
||||||
# Check unused dependencies
|
# Check unused dependencies
|
||||||
cargo shear
|
cargo shear
|
||||||
|
|
||||||
# Run snapshot tests and update snapshots
|
# Mutation testing
|
||||||
cargo insta review
|
cargo mutants
|
||||||
```
|
```
|
||||||
|
|
||||||
|
### CI
|
||||||
|
|
||||||
|
Woodpecker pipelines in `.woodpecker/` run on `server/**` changes: `server-lint` (clippy), `server-test` (nextest, `--all-features`), `server-audit`, `server-vet`, plus `useragent-analyze` for the Flutter app.
|
||||||
|
|
||||||
### Architecture
|
### Architecture
|
||||||
|
|
||||||
The server is actor-based using the **kameo** crate. All long-lived state lives in `GlobalActors`:
|
The server is actor-based using the **kameo** crate. Long-lived state lives in `GlobalActors` (`src/actors/mod.rs`):
|
||||||
|
|
||||||
- **`Bootstrapper`** — Manages the one-time bootstrap token written to `~/.arbiter/bootstrap_token` on first run.
|
- **`Bootstrapper`** — one-time bootstrap token, written to `~/.arbiter/bootstrap_token` on first run
|
||||||
- **`Vault`** — Holds the encrypted root key and manages the Sealed/Unsealed vault state machine. On unseal, decrypts the root key into a `memsafe` hardened memory cell.
|
- **`Vault`** — encrypted root key and the Sealed/Unsealed state machine; on unseal decrypts the root key into a `memsafe`-backed `SafeCell`
|
||||||
- **`FlowCoordinator`** — Coordinates cross-connection flow between operators and SDK clients.
|
- **`FlowCoordinator`** — cross-connection flow between operators and SDK clients
|
||||||
- **`EvmActor`** — Handles EVM transaction policy enforcement and signing.
|
- **`OperatorRegistry`** — tracks currently connected operators
|
||||||
|
- **`EvmActor`** — EVM transaction policy enforcement and signing
|
||||||
|
- **`events`** — a `kameo_actors::MessageBus` (`DeliveryStrategy::Guaranteed`) for cross-actor notifications
|
||||||
|
|
||||||
Per-connection actors live under `actors/operator/` and `actors/client/`, each with `auth` (challenge-response authentication) and `session` (post-auth operations) sub-modules.
|
Per-connection state lives under **`src/peers/`**, not `actors/`: `peers/client/` and `peers/operator/`, each with `auth` (challenge-response) and `session` (post-auth) sub-modules; the operator side additionally has `vault_gate/` for the unseal handshake.
|
||||||
|
|
||||||
**Database:** SQLite via `diesel-async` + `bb8` connection pool. Schema managed by embedded Diesel migrations in `crates/arbiter-server/migrations/`. DB file lives at `~/.arbiter/arbiter.sqlite`. Tests use a temp-file DB via `db::create_test_pool()`.
|
The gRPC surface lives in **`src/grpc/`**, split per peer (`client/`, `operator/`, `common/`) and per direction (`inbound.rs` — requests to the daemon, `outbound.rs` — server-initiated streams), with `request_tracker.rs` correlating the two.
|
||||||
|
|
||||||
|
EVM logic is in `src/evm/`: `policies/ether_transfer/`, `policies/token_transfers/`, `abi.rs`, `safe_signer.rs`.
|
||||||
|
|
||||||
|
**Database:** SQLite via `diesel-async` + `bb8`. Schema in `src/db/schema.rs`, models in `src/db/models.rs`, embedded migrations in `crates/arbiter-server/migrations/`. DB file lives at `~/.arbiter/arbiter.sqlite`; tests use a temp-file DB via `db::create_test_pool()`.
|
||||||
|
|
||||||
|
Entity ids are newtypes generated by the `declare_id!` macro in `db::models` (`OperatorId`, `ChainId`, …), each a `#[repr(transparent)]` wrapper over `i32` with `to_raw`/`from_raw`. Pass these around instead of bare `i32`.
|
||||||
|
|
||||||
|
**Row integrity:** sensitive rows are covered by an HMAC-SHA256 envelope (`src/crypto/integrity/`, table `integrity_envelope`), keyed from the vault root key. A struct becomes coverable by deriving `arbiter_macros::Hashable` and implementing `Integrable` (`KIND` + `VERSION`). When adding or changing a covered entity, keep the derive and the payload version in sync — a mismatch surfaces as `PayloadVersionMismatch` or `MacMismatch` at runtime.
|
||||||
|
|
||||||
**Cryptography:**
|
**Cryptography:**
|
||||||
- Authentication: ed25519 (challenge-response, nonce-tracked per peer)
|
- Authentication: **ML-DSA-87** (post-quantum, `arbiter-crypto::authn::v1`), challenge-response with per-peer nonce tracking
|
||||||
- Encryption at rest: XChaCha20-Poly1305 (versioned via `scheme` field for transparent migration on unseal)
|
- Encryption at rest: XChaCha20-Poly1305, versioned modules (`crypto/encryption/v1.rs`) with a `schema_version` column for transparent migration on unseal
|
||||||
- Password KDF: Argon2
|
- Password KDF: Argon2
|
||||||
- Unseal transport: X25519 ephemeral key exchange
|
- Unseal transport: X25519 ephemeral key exchange (`peers/operator/vault_gate/`); `x-wing` (hybrid PQ KEM) is available via `arbiter-crypto`
|
||||||
- TLS: self-signed certificate (aws-lc-rs backend), fingerprint distributed via `ArbiterUrl`
|
- TLS: self-signed certificate (rustls + aws-lc-rs, `prefer-post-quantum`), fingerprint distributed via `ArbiterUrl`
|
||||||
|
|
||||||
**Protocol:** gRPC with Protocol Buffers. The `ArbiterUrl` type encodes host, port, CA cert, and bootstrap token into a single shareable string (printed to console on first run).
|
Crypto modules are versioned by convention: `mod.rs` re-exports the current `vN`. Add a `v(N+1)` rather than editing an existing version in place.
|
||||||
|
|
||||||
|
**Protocol:** gRPC with Protocol Buffers. `ArbiterUrl` encodes host, port, CA cert and bootstrap token into a single shareable string (printed to console on first run).
|
||||||
|
|
||||||
### Proto Regeneration
|
### Proto Regeneration
|
||||||
|
|
||||||
When `.proto` files in `protobufs/` change, rebuild to regenerate:
|
`arbiter-proto/build.rs` compiles `arbiter.proto`, `operator.proto`, `client.proto` and `evm.proto` (with their `shared/`, `operator/`, `client/` includes) on build:
|
||||||
```sh
|
```sh
|
||||||
cd server && cargo build -p arbiter-proto
|
cd server && cargo build -p arbiter-proto
|
||||||
```
|
```
|
||||||
|
|
||||||
|
Dart protobuf stubs are generated separately, from the repo root:
|
||||||
|
```sh
|
||||||
|
mise run codegen # protoc --dart_out=grpc:useragent/lib/proto
|
||||||
|
```
|
||||||
|
|
||||||
### Database Migrations
|
### Database Migrations
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
@@ -100,6 +131,8 @@ diesel migration generate <name> --migration-dir crates/arbiter-server/migration
|
|||||||
diesel migration run --migration-dir crates/arbiter-server/migrations
|
diesel migration run --migration-dir crates/arbiter-server/migrations
|
||||||
```
|
```
|
||||||
|
|
||||||
|
Pre-release policy: there is a single `init` migration and no deployed databases yet, so schema changes are made by editing that migration directly instead of stacking new ones. Regenerate `src/db/schema.rs` after changing it.
|
||||||
|
|
||||||
### Code Conventions
|
### Code Conventions
|
||||||
|
|
||||||
**`#[must_use]` Attribute:**
|
**`#[must_use]` Attribute:**
|
||||||
@@ -121,29 +154,23 @@ pub fn verify(&self, nonce: i32, context: &[u8], signature: &Signature) -> bool
|
|||||||
|
|
||||||
This forces callers to either use the return value or explicitly ignore it with `let _ = ...;`, preventing silent failures.
|
This forces callers to either use the return value or explicitly ignore it with `let _ = ...;`, preventing silent failures.
|
||||||
|
|
||||||
## Operator (Flutter + Rinf at `operator/`)
|
## User Agent (Flutter + flutter_rust_bridge at `useragent/`)
|
||||||
|
|
||||||
The Flutter app uses [Rinf](https://rinf.cunarist.org) to call Rust code. The Rust logic lives in `operator/native/hub/` as a separate crate that uses `arbiter-operator` for the gRPC client.
|
The Flutter app calls Rust through [flutter_rust_bridge](https://cjycode.com/flutter_rust_bridge/) 2.12.0. The Rust side is the `rust_lib_arbiter` crate at `useragent/rust/`; everything exposed to Dart is declared in `useragent/rust/src/api/` and lands in `useragent/lib/src/rust/` (see `useragent/flutter_rust_bridge.yaml`). Dart UI code is organised as `lib/features/`, `lib/screens/`, `lib/widgets/`, `lib/providers/`, `lib/theme/`, with routing in `lib/router.dart` (`router.gr.dart` is generated).
|
||||||
|
|
||||||
Communication between Dart and Rust uses typed **signals** defined in `operator/native/hub/src/signals/`. After modifying signal structs, regenerate Dart bindings:
|
|
||||||
|
|
||||||
```sh
|
|
||||||
cd operator && rinf gen
|
|
||||||
```
|
|
||||||
|
|
||||||
### Common Commands
|
### Common Commands
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
cd operator
|
cd useragent
|
||||||
|
|
||||||
# Run the app (macOS or Windows)
|
# Run the app
|
||||||
flutter run
|
flutter run
|
||||||
|
|
||||||
# Regenerate Rust↔Dart signal bindings
|
# Regenerate Rust↔Dart bindings after editing rust/src/api/
|
||||||
rinf gen
|
mise run codegen # flutter_rust_bridge_codegen generate
|
||||||
|
|
||||||
# Analyze Dart code
|
# Analyze Dart code (also run in CI)
|
||||||
flutter analyze
|
flutter analyze
|
||||||
```
|
```
|
||||||
|
|
||||||
The Rinf Rust entry point is `operator/native/hub/src/lib.rs`. It spawns actors defined in `operator/native/hub/src/actors/` which handle Dart↔server communication via signals.
|
Note: `app/` contains only stale generated Flutter artifacts and is not the application source.
|
||||||
|
|||||||
@@ -152,5 +152,8 @@ url = "https://github.com/astral-sh/python-build-standalone/releases/download/20
|
|||||||
provenance = "github-attestations"
|
provenance = "github-attestations"
|
||||||
|
|
||||||
[[tools.rust]]
|
[[tools.rust]]
|
||||||
version = "1.95.0"
|
version = "1.98.1"
|
||||||
backend = "core:rust"
|
backend = "core:rust"
|
||||||
|
|
||||||
|
[tools.rust.options]
|
||||||
|
components = "clippy,rust-analyzer"
|
||||||
|
|||||||
@@ -4,7 +4,7 @@
|
|||||||
"cargo:cargo-vet" = "0.10.2"
|
"cargo:cargo-vet" = "0.10.2"
|
||||||
flutter = "3.41.7-stable"
|
flutter = "3.41.7-stable"
|
||||||
protoc = "29.6"
|
protoc = "29.6"
|
||||||
rust = { version = "1.95.0", components = "clippy,rust-analyzer" }
|
rust = { version = "latest", components = "clippy,rust-analyzer" }
|
||||||
"cargo:cargo-features-manager" = "0.12.0"
|
"cargo:cargo-features-manager" = "0.12.0"
|
||||||
"cargo:cargo-nextest" = "0.9.133"
|
"cargo:cargo-nextest" = "0.9.133"
|
||||||
"cargo:cargo-shear" = "latest"
|
"cargo:cargo-shear" = "latest"
|
||||||
|
|||||||
307
server/Cargo.lock
generated
307
server/Cargo.lock
generated
@@ -24,7 +24,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
|
|||||||
checksum = "d122413f284cf2d62fb1b7db97e02edb8cda96d769b16e443a4f6195e35662b0"
|
checksum = "d122413f284cf2d62fb1b7db97e02edb8cda96d769b16e443a4f6195e35662b0"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"crypto-common 0.1.7",
|
"crypto-common 0.1.7",
|
||||||
"generic-array",
|
"generic-array 0.14.7",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
@@ -504,7 +504,7 @@ dependencies = [
|
|||||||
"async-trait",
|
"async-trait",
|
||||||
"auto_impl",
|
"auto_impl",
|
||||||
"either",
|
"either",
|
||||||
"elliptic-curve",
|
"elliptic-curve 0.13.8",
|
||||||
"k256",
|
"k256",
|
||||||
"thiserror",
|
"thiserror",
|
||||||
]
|
]
|
||||||
@@ -771,6 +771,7 @@ dependencies = [
|
|||||||
"proptest",
|
"proptest",
|
||||||
"prost-types",
|
"prost-types",
|
||||||
"rand 0.10.1",
|
"rand 0.10.1",
|
||||||
|
"rand_core 0.10.1",
|
||||||
"rcgen",
|
"rcgen",
|
||||||
"restructed",
|
"restructed",
|
||||||
"rstest",
|
"rstest",
|
||||||
@@ -786,6 +787,7 @@ dependencies = [
|
|||||||
"tonic",
|
"tonic",
|
||||||
"tracing",
|
"tracing",
|
||||||
"tracing-subscriber",
|
"tracing-subscriber",
|
||||||
|
"vsss-rs",
|
||||||
"x25519-dalek 2.0.1",
|
"x25519-dalek 2.0.1",
|
||||||
]
|
]
|
||||||
|
|
||||||
@@ -820,7 +822,7 @@ dependencies = [
|
|||||||
"ark-serialize 0.3.0",
|
"ark-serialize 0.3.0",
|
||||||
"ark-std 0.3.0",
|
"ark-std 0.3.0",
|
||||||
"derivative",
|
"derivative",
|
||||||
"num-bigint",
|
"num-bigint 0.4.6",
|
||||||
"num-traits",
|
"num-traits",
|
||||||
"paste",
|
"paste",
|
||||||
"rustc_version 0.3.3",
|
"rustc_version 0.3.3",
|
||||||
@@ -840,7 +842,7 @@ dependencies = [
|
|||||||
"derivative",
|
"derivative",
|
||||||
"digest 0.10.7",
|
"digest 0.10.7",
|
||||||
"itertools 0.10.5",
|
"itertools 0.10.5",
|
||||||
"num-bigint",
|
"num-bigint 0.4.6",
|
||||||
"num-traits",
|
"num-traits",
|
||||||
"paste",
|
"paste",
|
||||||
"rustc_version 0.4.1",
|
"rustc_version 0.4.1",
|
||||||
@@ -861,7 +863,7 @@ dependencies = [
|
|||||||
"digest 0.10.7",
|
"digest 0.10.7",
|
||||||
"educe",
|
"educe",
|
||||||
"itertools 0.13.0",
|
"itertools 0.13.0",
|
||||||
"num-bigint",
|
"num-bigint 0.4.6",
|
||||||
"num-traits",
|
"num-traits",
|
||||||
"paste",
|
"paste",
|
||||||
"zeroize",
|
"zeroize",
|
||||||
@@ -903,7 +905,7 @@ version = "0.3.0"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "db2fd794a08ccb318058009eefdf15bcaaaaf6f8161eb3345f907222bac38b20"
|
checksum = "db2fd794a08ccb318058009eefdf15bcaaaaf6f8161eb3345f907222bac38b20"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"num-bigint",
|
"num-bigint 0.4.6",
|
||||||
"num-traits",
|
"num-traits",
|
||||||
"quote",
|
"quote",
|
||||||
"syn 1.0.109",
|
"syn 1.0.109",
|
||||||
@@ -915,7 +917,7 @@ version = "0.4.2"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "7abe79b0e4288889c4574159ab790824d0033b9fdcb2a112a3182fac2e514565"
|
checksum = "7abe79b0e4288889c4574159ab790824d0033b9fdcb2a112a3182fac2e514565"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"num-bigint",
|
"num-bigint 0.4.6",
|
||||||
"num-traits",
|
"num-traits",
|
||||||
"proc-macro2",
|
"proc-macro2",
|
||||||
"quote",
|
"quote",
|
||||||
@@ -928,7 +930,7 @@ version = "0.5.0"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "09be120733ee33f7693ceaa202ca41accd5653b779563608f1234f78ae07c4b3"
|
checksum = "09be120733ee33f7693ceaa202ca41accd5653b779563608f1234f78ae07c4b3"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"num-bigint",
|
"num-bigint 0.4.6",
|
||||||
"num-traits",
|
"num-traits",
|
||||||
"proc-macro2",
|
"proc-macro2",
|
||||||
"quote",
|
"quote",
|
||||||
@@ -953,7 +955,7 @@ checksum = "adb7b85a02b83d2f22f89bd5cac66c9c89474240cb6207cb1efc16d098e822a5"
|
|||||||
dependencies = [
|
dependencies = [
|
||||||
"ark-std 0.4.0",
|
"ark-std 0.4.0",
|
||||||
"digest 0.10.7",
|
"digest 0.10.7",
|
||||||
"num-bigint",
|
"num-bigint 0.4.6",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
@@ -965,7 +967,7 @@ dependencies = [
|
|||||||
"ark-std 0.5.0",
|
"ark-std 0.5.0",
|
||||||
"arrayvec",
|
"arrayvec",
|
||||||
"digest 0.10.7",
|
"digest 0.10.7",
|
||||||
"num-bigint",
|
"num-bigint 0.4.6",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
@@ -1195,6 +1197,12 @@ version = "0.2.0"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "4c7f02d4ea65f2c1853089ffd8d2787bdbc63de2f0d29dedbcf8ccdfa0ccd4cf"
|
checksum = "4c7f02d4ea65f2c1853089ffd8d2787bdbc63de2f0d29dedbcf8ccdfa0ccd4cf"
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "base16ct"
|
||||||
|
version = "1.0.0"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "fd307490d624467aa6f74b0eabb77633d1f758a7b25f12bceb0b22e08d9726f6"
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "base64"
|
name = "base64"
|
||||||
version = "0.22.1"
|
version = "0.22.1"
|
||||||
@@ -1283,7 +1291,7 @@ version = "0.10.4"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "3078c7629b62d3f0439517fa394996acacc5cbc91c5a20d8c658e77abd503a71"
|
checksum = "3078c7629b62d3f0439517fa394996acacc5cbc91c5a20d8c658e77abd503a71"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"generic-array",
|
"generic-array 0.14.7",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
@@ -1552,6 +1560,12 @@ version = "0.8.7"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "773648b94d0e5d620f64f280777445740e61fe701025087ec8b57f45c791888b"
|
checksum = "773648b94d0e5d620f64f280777445740e61fe701025087ec8b57f45c791888b"
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "cpubits"
|
||||||
|
version = "0.1.1"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "15b85f9c39137c3a891689859392b1bd49812121d0d61c9caf00d46ed5ce06ae"
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "cpufeatures"
|
name = "cpufeatures"
|
||||||
version = "0.2.17"
|
version = "0.2.17"
|
||||||
@@ -1612,19 +1626,35 @@ version = "0.5.5"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "0dc92fb57ca44df6db8059111ab3af99a63d5d0f8375d9972e319a379c6bab76"
|
checksum = "0dc92fb57ca44df6db8059111ab3af99a63d5d0f8375d9972e319a379c6bab76"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"generic-array",
|
"generic-array 0.14.7",
|
||||||
"rand_core 0.6.4",
|
"rand_core 0.6.4",
|
||||||
"subtle",
|
"subtle",
|
||||||
"zeroize",
|
"zeroize",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "crypto-bigint"
|
||||||
|
version = "0.7.5"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "1a52aa3fcda4e6302a9f48734f234d35d4721b96f8fe07d073f07ce9df4f0271"
|
||||||
|
dependencies = [
|
||||||
|
"cpubits",
|
||||||
|
"ctutils",
|
||||||
|
"hybrid-array",
|
||||||
|
"num-traits",
|
||||||
|
"rand_core 0.10.1",
|
||||||
|
"serdect 0.4.3",
|
||||||
|
"subtle",
|
||||||
|
"zeroize",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "crypto-common"
|
name = "crypto-common"
|
||||||
version = "0.1.7"
|
version = "0.1.7"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "78c8292055d1c1df0cce5d180393dc8cce0abec0a7102adb6c7b1eef6016d60a"
|
checksum = "78c8292055d1c1df0cce5d180393dc8cce0abec0a7102adb6c7b1eef6016d60a"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"generic-array",
|
"generic-array 0.14.7",
|
||||||
"rand_core 0.6.4",
|
"rand_core 0.6.4",
|
||||||
"typenum",
|
"typenum",
|
||||||
]
|
]
|
||||||
@@ -1646,6 +1676,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
|
|||||||
checksum = "7d5515a3834141de9eafb9717ad39eea8247b5674e6066c404e8c4b365d2a29e"
|
checksum = "7d5515a3834141de9eafb9717ad39eea8247b5674e6066c404e8c4b365d2a29e"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"cmov",
|
"cmov",
|
||||||
|
"subtle",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
@@ -1808,7 +1839,7 @@ dependencies = [
|
|||||||
"asn1-rs",
|
"asn1-rs",
|
||||||
"displaydoc",
|
"displaydoc",
|
||||||
"nom",
|
"nom",
|
||||||
"num-bigint",
|
"num-bigint 0.4.6",
|
||||||
"num-traits",
|
"num-traits",
|
||||||
"rusticata-macros",
|
"rusticata-macros",
|
||||||
]
|
]
|
||||||
@@ -1927,7 +1958,7 @@ version = "0.9.0"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "d3dd60d1080a57a05ab032377049e0591415d2b31afd7028356dbf3cc6dcb066"
|
checksum = "d3dd60d1080a57a05ab032377049e0591415d2b31afd7028356dbf3cc6dcb066"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"generic-array",
|
"generic-array 0.14.7",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
@@ -2005,9 +2036,9 @@ checksum = "ee27f32b5c5292967d2d4a9d7f1e0b0aed2c15daded5a60300e4abb9d8020bca"
|
|||||||
dependencies = [
|
dependencies = [
|
||||||
"der 0.7.10",
|
"der 0.7.10",
|
||||||
"digest 0.10.7",
|
"digest 0.10.7",
|
||||||
"elliptic-curve",
|
"elliptic-curve 0.13.8",
|
||||||
"rfc6979",
|
"rfc6979",
|
||||||
"serdect",
|
"serdect 0.2.0",
|
||||||
"signature 2.2.0",
|
"signature 2.2.0",
|
||||||
"spki 0.7.3",
|
"spki 0.7.3",
|
||||||
]
|
]
|
||||||
@@ -2039,20 +2070,52 @@ version = "0.13.8"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "b5e6043086bf7973472e0c7dff2142ea0b680d30e18d9cc40f267efbf222bd47"
|
checksum = "b5e6043086bf7973472e0c7dff2142ea0b680d30e18d9cc40f267efbf222bd47"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"base16ct",
|
"base16ct 0.2.0",
|
||||||
"crypto-bigint",
|
"crypto-bigint 0.5.5",
|
||||||
"digest 0.10.7",
|
"digest 0.10.7",
|
||||||
"ff",
|
"ff 0.13.1",
|
||||||
"generic-array",
|
"generic-array 0.14.7",
|
||||||
"group",
|
"group 0.13.0",
|
||||||
"pkcs8 0.10.2",
|
"pkcs8 0.10.2",
|
||||||
"rand_core 0.6.4",
|
"rand_core 0.6.4",
|
||||||
"sec1",
|
"sec1 0.7.3",
|
||||||
"serdect",
|
"serdect 0.2.0",
|
||||||
"subtle",
|
"subtle",
|
||||||
"zeroize",
|
"zeroize",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "elliptic-curve"
|
||||||
|
version = "0.14.1"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "9d65aa39b3a5c1c9c1b745c9a019234bb7a21b77abcb4f4d266d706e2d577d65"
|
||||||
|
dependencies = [
|
||||||
|
"base16ct 1.0.0",
|
||||||
|
"crypto-bigint 0.7.5",
|
||||||
|
"crypto-common 0.2.1",
|
||||||
|
"ff 0.14.0",
|
||||||
|
"group 0.14.0",
|
||||||
|
"hybrid-array",
|
||||||
|
"pkcs8 0.11.0",
|
||||||
|
"rand_core 0.10.1",
|
||||||
|
"sec1 0.8.1",
|
||||||
|
"serdect 0.4.3",
|
||||||
|
"subtle",
|
||||||
|
"zeroize",
|
||||||
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "elliptic-curve-tools"
|
||||||
|
version = "0.3.0"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "7a0d5e534f103b079a71ef1d66c6e62c89413f1b62709ca11f744429b4afe5b4"
|
||||||
|
dependencies = [
|
||||||
|
"elliptic-curve 0.14.1",
|
||||||
|
"heapless",
|
||||||
|
"serde",
|
||||||
|
"serdect 0.4.3",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "enum-ordinalize"
|
name = "enum-ordinalize"
|
||||||
version = "4.3.2"
|
version = "4.3.2"
|
||||||
@@ -2127,6 +2190,16 @@ dependencies = [
|
|||||||
"subtle",
|
"subtle",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "ff"
|
||||||
|
version = "0.14.0"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "a1f686ab92a9fb0eaf188f6c6c87b89490baa6fdb0db4544ba4dc47f7942489f"
|
||||||
|
dependencies = [
|
||||||
|
"rand_core 0.10.1",
|
||||||
|
"subtle",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "fiat-crypto"
|
name = "fiat-crypto"
|
||||||
version = "0.2.9"
|
version = "0.2.9"
|
||||||
@@ -2323,6 +2396,17 @@ dependencies = [
|
|||||||
"zeroize",
|
"zeroize",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "generic-array"
|
||||||
|
version = "1.4.2"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "fb130435a959a8d525e6bca66ff6c40981a300ee96d70e3ef56f046556d614a3"
|
||||||
|
dependencies = [
|
||||||
|
"rustversion",
|
||||||
|
"serde_core",
|
||||||
|
"typenum",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "getrandom"
|
name = "getrandom"
|
||||||
version = "0.2.17"
|
version = "0.2.17"
|
||||||
@@ -2382,11 +2466,22 @@ version = "0.13.0"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "f0f9ef7462f7c099f518d754361858f86d8a07af53ba9af0fe635bbccb151a63"
|
checksum = "f0f9ef7462f7c099f518d754361858f86d8a07af53ba9af0fe635bbccb151a63"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"ff",
|
"ff 0.13.1",
|
||||||
"rand_core 0.6.4",
|
"rand_core 0.6.4",
|
||||||
"subtle",
|
"subtle",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "group"
|
||||||
|
version = "0.14.0"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "7fd1a1c7a5206c5b7a3f5a0d7ccd3ff85d0c8f5133d62a02680255b0004af5f4"
|
||||||
|
dependencies = [
|
||||||
|
"ff 0.14.0",
|
||||||
|
"rand_core 0.10.1",
|
||||||
|
"subtle",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "h2"
|
name = "h2"
|
||||||
version = "0.4.13"
|
version = "0.4.13"
|
||||||
@@ -2406,6 +2501,15 @@ dependencies = [
|
|||||||
"tracing",
|
"tracing",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "hash32"
|
||||||
|
version = "0.3.1"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "47d60b12902ba28e2730cd37e95b8c9223af2808df9e902d4df49588d1470606"
|
||||||
|
dependencies = [
|
||||||
|
"byteorder",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "hashbrown"
|
name = "hashbrown"
|
||||||
version = "0.12.3"
|
version = "0.12.3"
|
||||||
@@ -2446,6 +2550,16 @@ version = "0.17.0"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "4f467dd6dccf739c208452f8014c75c18bb8301b050ad1cfb27153803edb0f51"
|
checksum = "4f467dd6dccf739c208452f8014c75c18bb8301b050ad1cfb27153803edb0f51"
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "heapless"
|
||||||
|
version = "0.9.3"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "25ba4bd83f9415b58b4ed8dc5714c76e626a105be4646c02630ad730ad3b5aa4"
|
||||||
|
dependencies = [
|
||||||
|
"hash32",
|
||||||
|
"stable_deref_trait",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "heck"
|
name = "heck"
|
||||||
version = "0.5.0"
|
version = "0.5.0"
|
||||||
@@ -2538,11 +2652,13 @@ checksum = "df3b46402a9d5adb4c86a0cf463f42e19994e3ee891101b1841f30a545cb49a9"
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "hybrid-array"
|
name = "hybrid-array"
|
||||||
version = "0.4.11"
|
version = "0.4.15"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "08d46837a0ed51fe95bd3b05de33cd64a1ee88fc797477ca48446872504507c5"
|
checksum = "27f864f10dfb56725ce5ce5472bc52252c8f93a4ab86327122cebf62c5f59a17"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"ctutils",
|
"ctutils",
|
||||||
|
"serde",
|
||||||
|
"subtle",
|
||||||
"typenum",
|
"typenum",
|
||||||
"zeroize",
|
"zeroize",
|
||||||
]
|
]
|
||||||
@@ -2808,7 +2924,7 @@ version = "0.1.4"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "879f10e63c20629ecabbb64a8010319738c66a5cd0c29b02d63d272b03751d01"
|
checksum = "879f10e63c20629ecabbb64a8010319738c66a5cd0c29b02d63d272b03751d01"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"generic-array",
|
"generic-array 0.14.7",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
@@ -2945,17 +3061,17 @@ checksum = "f6e3919bbaa2945715f0bb6d3934a173d1e9a59ac23767fbaaef277265a7411b"
|
|||||||
dependencies = [
|
dependencies = [
|
||||||
"cfg-if",
|
"cfg-if",
|
||||||
"ecdsa",
|
"ecdsa",
|
||||||
"elliptic-curve",
|
"elliptic-curve 0.13.8",
|
||||||
"once_cell",
|
"once_cell",
|
||||||
"serdect",
|
"serdect 0.2.0",
|
||||||
"sha2 0.10.9",
|
"sha2 0.10.9",
|
||||||
"signature 2.2.0",
|
"signature 2.2.0",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "kameo"
|
name = "kameo"
|
||||||
version = "0.20.0"
|
version = "0.22.2"
|
||||||
source = "git+https://github.com/hdbg/kameo.git?rev=805b417#805b41783fe90b54827ecad142b422c7a9b69b9a"
|
source = "git+https://github.com/hdbg/kameo.git?rev=3bbebac#3bbebac9f2a943be75588d80826e6bea45079d5f"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"downcast-rs",
|
"downcast-rs",
|
||||||
"dyn-clone",
|
"dyn-clone",
|
||||||
@@ -2968,8 +3084,8 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "kameo_actors"
|
name = "kameo_actors"
|
||||||
version = "0.5.0"
|
version = "0.8.1"
|
||||||
source = "git+https://github.com/hdbg/kameo.git?rev=805b417#805b41783fe90b54827ecad142b422c7a9b69b9a"
|
source = "git+https://github.com/hdbg/kameo.git?rev=3bbebac#3bbebac9f2a943be75588d80826e6bea45079d5f"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"futures",
|
"futures",
|
||||||
"glob",
|
"glob",
|
||||||
@@ -2980,14 +3096,13 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "kameo_macros"
|
name = "kameo_macros"
|
||||||
version = "0.20.0"
|
version = "0.21.1"
|
||||||
source = "git+https://github.com/hdbg/kameo.git?rev=805b417#805b41783fe90b54827ecad142b422c7a9b69b9a"
|
source = "git+https://github.com/hdbg/kameo.git?rev=3bbebac#3bbebac9f2a943be75588d80826e6bea45079d5f"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"darling 0.23.0",
|
|
||||||
"heck",
|
"heck",
|
||||||
"proc-macro2",
|
"proc-macro2",
|
||||||
"quote",
|
"quote",
|
||||||
"syn 2.0.117",
|
"syn 3.0.5",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
@@ -3331,6 +3446,17 @@ dependencies = [
|
|||||||
"num-traits",
|
"num-traits",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "num-bigint"
|
||||||
|
version = "0.5.1"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "93e7820bc0a80a0238e650327316f929ba18d5be054b647490a3a6a339f3e7c0"
|
||||||
|
dependencies = [
|
||||||
|
"num-integer",
|
||||||
|
"num-traits",
|
||||||
|
"serde",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "num-conv"
|
name = "num-conv"
|
||||||
version = "0.2.1"
|
version = "0.2.1"
|
||||||
@@ -4225,7 +4351,7 @@ dependencies = [
|
|||||||
"bytes",
|
"bytes",
|
||||||
"fastrlp 0.3.1",
|
"fastrlp 0.3.1",
|
||||||
"fastrlp 0.4.0",
|
"fastrlp 0.4.0",
|
||||||
"num-bigint",
|
"num-bigint 0.4.6",
|
||||||
"num-integer",
|
"num-integer",
|
||||||
"num-traits",
|
"num-traits",
|
||||||
"parity-scale-codec",
|
"parity-scale-codec",
|
||||||
@@ -4452,11 +4578,26 @@ version = "0.7.3"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "d3e97a565f76233a6003f9f5c54be1d9c5bdfa3eccfb189469f11ec4901c47dc"
|
checksum = "d3e97a565f76233a6003f9f5c54be1d9c5bdfa3eccfb189469f11ec4901c47dc"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"base16ct",
|
"base16ct 0.2.0",
|
||||||
"der 0.7.10",
|
"der 0.7.10",
|
||||||
"generic-array",
|
"generic-array 0.14.7",
|
||||||
"pkcs8 0.10.2",
|
"pkcs8 0.10.2",
|
||||||
"serdect",
|
"serdect 0.2.0",
|
||||||
|
"subtle",
|
||||||
|
"zeroize",
|
||||||
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "sec1"
|
||||||
|
version = "0.8.1"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "d56d437c2f19203ce5f7122e507831de96f3d2d4d3be5af44a0b0a09d8a80e4d"
|
||||||
|
dependencies = [
|
||||||
|
"base16ct 1.0.0",
|
||||||
|
"ctutils",
|
||||||
|
"der 0.8.0",
|
||||||
|
"hybrid-array",
|
||||||
|
"serdect 0.4.3",
|
||||||
"subtle",
|
"subtle",
|
||||||
"zeroize",
|
"zeroize",
|
||||||
]
|
]
|
||||||
@@ -4618,7 +4759,17 @@ version = "0.2.0"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "a84f14a19e9a014bb9f4512488d9829a68e04ecabffb0f9904cd1ace94598177"
|
checksum = "a84f14a19e9a014bb9f4512488d9829a68e04ecabffb0f9904cd1ace94598177"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"base16ct",
|
"base16ct 0.2.0",
|
||||||
|
"serde",
|
||||||
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "serdect"
|
||||||
|
version = "0.4.3"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "66cf8fedced2fcf12406bcb34223dffb92eaf34908ede12fed414c82b7f00b3e"
|
||||||
|
dependencies = [
|
||||||
|
"base16ct 1.0.0",
|
||||||
"serde",
|
"serde",
|
||||||
]
|
]
|
||||||
|
|
||||||
@@ -4664,6 +4815,17 @@ dependencies = [
|
|||||||
"keccak 0.2.0",
|
"keccak 0.2.0",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "sha3"
|
||||||
|
version = "0.12.0"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "bc9bad02c26382724b2d2692c6f179285e4b54eeecd7968f52a50059c3c11759"
|
||||||
|
dependencies = [
|
||||||
|
"digest 0.11.2",
|
||||||
|
"keccak 0.2.0",
|
||||||
|
"sponge-cursor",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "sha3-asm"
|
name = "sha3-asm"
|
||||||
version = "0.1.6"
|
version = "0.1.6"
|
||||||
@@ -4674,6 +4836,17 @@ dependencies = [
|
|||||||
"cfg-if",
|
"cfg-if",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "shake"
|
||||||
|
version = "0.1.0"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "09057cb2149ad4cbd2da1e26b351f9a4c354219421229c69c3063e6f61947c4a"
|
||||||
|
dependencies = [
|
||||||
|
"digest 0.11.2",
|
||||||
|
"keccak 0.2.0",
|
||||||
|
"sponge-cursor",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "sharded-slab"
|
name = "sharded-slab"
|
||||||
version = "0.1.7"
|
version = "0.1.7"
|
||||||
@@ -4807,6 +4980,12 @@ dependencies = [
|
|||||||
"der 0.8.0",
|
"der 0.8.0",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "sponge-cursor"
|
||||||
|
version = "0.1.0"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "3a0219bd7d979d58245a4f41f695e1ac9f8befdffadd7f61f1bae9e39abc6620"
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "sqlite-wasm-rs"
|
name = "sqlite-wasm-rs"
|
||||||
version = "0.5.3"
|
version = "0.5.3"
|
||||||
@@ -4934,6 +5113,17 @@ dependencies = [
|
|||||||
"unicode-ident",
|
"unicode-ident",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "syn"
|
||||||
|
version = "3.0.5"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "12df2e0110f65b775f769bb17ef989067a1d931b2eb822bd4346631eeada89f9"
|
||||||
|
dependencies = [
|
||||||
|
"proc-macro2",
|
||||||
|
"quote",
|
||||||
|
"unicode-ident",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "syn-solidity"
|
name = "syn-solidity"
|
||||||
version = "1.5.7"
|
version = "1.5.7"
|
||||||
@@ -5574,6 +5764,29 @@ version = "0.9.5"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "0b928f33d975fc6ad9f86c8f283853ad26bdd5b10b7f1542aa2fa15e2289105a"
|
checksum = "0b928f33d975fc6ad9f86c8f283853ad26bdd5b10b7f1542aa2fa15e2289105a"
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "vsss-rs"
|
||||||
|
version = "6.0.1"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "d6bfc736cfd88115aedb95ba84bc2d428fe351e92a56f69fce090af301402d91"
|
||||||
|
dependencies = [
|
||||||
|
"crypto-bigint 0.7.5",
|
||||||
|
"elliptic-curve 0.14.1",
|
||||||
|
"elliptic-curve-tools",
|
||||||
|
"ff 0.14.0",
|
||||||
|
"generic-array 1.4.2",
|
||||||
|
"hex",
|
||||||
|
"hybrid-array",
|
||||||
|
"num-bigint 0.5.1",
|
||||||
|
"num-traits",
|
||||||
|
"rand_core 0.10.1",
|
||||||
|
"serde",
|
||||||
|
"sha3 0.12.0",
|
||||||
|
"shake",
|
||||||
|
"subtle",
|
||||||
|
"zeroize",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "wait-timeout"
|
name = "wait-timeout"
|
||||||
version = "0.2.1"
|
version = "0.2.1"
|
||||||
@@ -6261,18 +6474,18 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "zeroize"
|
name = "zeroize"
|
||||||
version = "1.8.2"
|
version = "1.9.0"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "b97154e67e32c85465826e8bcc1c59429aaaf107c1e4a9e53c8d8ccd5eff88d0"
|
checksum = "e13c156562582aa81c60cb29407084cdb54c4164760106ab78e6c5b0858cf64e"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"zeroize_derive",
|
"zeroize_derive",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "zeroize_derive"
|
name = "zeroize_derive"
|
||||||
version = "1.4.3"
|
version = "1.5.0"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "85a5b4158499876c763cb03bc4e49185d3cccbabb15b33c627f7884f43db852e"
|
checksum = "3c50655cbb0fe3fc43170059e702f1ce5e19b84cec58dc87b037a09935c2f328"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"proc-macro2",
|
"proc-macro2",
|
||||||
"quote",
|
"quote",
|
||||||
|
|||||||
@@ -12,8 +12,8 @@ base64 = "0.22.1"
|
|||||||
chrono = { version = "0.4.44", features = ["serde"] }
|
chrono = { version = "0.4.44", features = ["serde"] }
|
||||||
futures = "0.3.32"
|
futures = "0.3.32"
|
||||||
k256 = { version = "0.13.4", features = ["ecdsa", "pkcs8"] }
|
k256 = { version = "0.13.4", features = ["ecdsa", "pkcs8"] }
|
||||||
kameo = {git = "https://github.com/hdbg/kameo.git", rev = "805b417"}
|
kameo = {git = "https://github.com/hdbg/kameo.git", rev = "3bbebac"}
|
||||||
kameo_actors = {git = "https://github.com/hdbg/kameo.git", rev = "805b417"}
|
kameo_actors = {git = "https://github.com/hdbg/kameo.git", rev = "3bbebac"}
|
||||||
hmac = "0.13.0"
|
hmac = "0.13.0"
|
||||||
miette = { version = "7.6.0", features = ["fancy", "serde"] }
|
miette = { version = "7.6.0", features = ["fancy", "serde"] }
|
||||||
ml-dsa = { version = "0.1.0-rc.9", features = ["zeroize"] }
|
ml-dsa = { version = "0.1.0-rc.9", features = ["zeroize"] }
|
||||||
@@ -21,6 +21,7 @@ mutants = "0.0.4"
|
|||||||
prost = "0.14.3"
|
prost = "0.14.3"
|
||||||
prost-types = { version = "0.14.3", features = ["chrono"] }
|
prost-types = { version = "0.14.3", features = ["chrono"] }
|
||||||
rand = "0.10.1"
|
rand = "0.10.1"
|
||||||
|
rand_core = "0.10.1"
|
||||||
rcgen = { version = "0.14.7", features = [ "aws_lc_rs", "pem", "x509-parser", "zeroize" ], default-features = false }
|
rcgen = { version = "0.14.7", features = [ "aws_lc_rs", "pem", "x509-parser", "zeroize" ], default-features = false }
|
||||||
rstest = "0.26.1"
|
rstest = "0.26.1"
|
||||||
rustls = { version = "0.23.40", features = ["aws-lc-rs", "logging", "prefer-post-quantum", "std"], default-features = false }
|
rustls = { version = "0.23.40", features = ["aws-lc-rs", "logging", "prefer-post-quantum", "std"], default-features = false }
|
||||||
@@ -76,6 +77,8 @@ needless_pass_by_ref_mut = "allow"
|
|||||||
pub_underscore_fields = "allow"
|
pub_underscore_fields = "allow"
|
||||||
redundant_pub_crate = "allow"
|
redundant_pub_crate = "allow"
|
||||||
uninhabited_references = "allow" # safe with unsafe_code = "forbid" and standard uninhabited pattern (match *self {})
|
uninhabited_references = "allow" # safe with unsafe_code = "forbid" and standard uninhabited pattern (match *self {})
|
||||||
|
too-many-lines = "allow" # this is a very common pattern in server code, and it's not always possible to break it down into smaller modules without hurting readability
|
||||||
|
unused_async_trait_impl = "allow" # too pedantic
|
||||||
|
|
||||||
# restriction lints
|
# restriction lints
|
||||||
alloc_instead_of_core = "warn"
|
alloc_instead_of_core = "warn"
|
||||||
|
|||||||
@@ -100,7 +100,7 @@ async fn send_auth_challenge_solution(
|
|||||||
key: &SigningKey,
|
key: &SigningKey,
|
||||||
challenge: AuthChallenge,
|
challenge: AuthChallenge,
|
||||||
) -> Result<(), AuthError> {
|
) -> Result<(), AuthError> {
|
||||||
let timestamp = DateTime::from_timestamp_nanos(challenge.timestamp_nanos as i64);
|
let timestamp = DateTime::from_timestamp_nanos(challenge.timestamp_nanos.cast_signed());
|
||||||
let challenge = authn::AuthChallenge {
|
let challenge = authn::AuthChallenge {
|
||||||
nonce: *challenge
|
nonce: *challenge
|
||||||
.random
|
.random
|
||||||
|
|||||||
@@ -94,7 +94,6 @@ impl ArbiterClient {
|
|||||||
}
|
}
|
||||||
|
|
||||||
#[cfg(feature = "evm")]
|
#[cfg(feature = "evm")]
|
||||||
#[expect(clippy::unused_async, reason = "false positive")]
|
|
||||||
pub async fn evm_wallets(&self) -> Result<Vec<ArbiterEvmWallet>, ArbiterClientError> {
|
pub async fn evm_wallets(&self) -> Result<Vec<ArbiterEvmWallet>, ArbiterClientError> {
|
||||||
todo!("fetch EVM wallet list from server")
|
todo!("fetch EVM wallet list from server")
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -23,6 +23,10 @@ pub mod proto {
|
|||||||
tonic::include_proto!("arbiter.operator.evm");
|
tonic::include_proto!("arbiter.operator.evm");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
pub mod governance {
|
||||||
|
tonic::include_proto!("arbiter.operator.governance");
|
||||||
|
}
|
||||||
|
|
||||||
pub mod sdk_client {
|
pub mod sdk_client {
|
||||||
tonic::include_proto!("arbiter.operator.sdk_client");
|
tonic::include_proto!("arbiter.operator.sdk_client");
|
||||||
}
|
}
|
||||||
@@ -34,6 +38,10 @@ pub mod proto {
|
|||||||
tonic::include_proto!("arbiter.operator.vault.bootstrap");
|
tonic::include_proto!("arbiter.operator.vault.bootstrap");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
pub mod rekey {
|
||||||
|
tonic::include_proto!("arbiter.operator.vault.rekey");
|
||||||
|
}
|
||||||
|
|
||||||
pub mod unseal {
|
pub mod unseal {
|
||||||
tonic::include_proto!("arbiter.operator.vault.unseal");
|
tonic::include_proto!("arbiter.operator.vault.unseal");
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -31,6 +31,7 @@ diesel_migrations = { version = "2.3.2", features = ["sqlite"] }
|
|||||||
async-trait.workspace = true
|
async-trait.workspace = true
|
||||||
tokio-stream.workspace = true
|
tokio-stream.workspace = true
|
||||||
rand.workspace = true
|
rand.workspace = true
|
||||||
|
rand_core.workspace = true
|
||||||
rcgen.workspace = true
|
rcgen.workspace = true
|
||||||
chrono.workspace = true
|
chrono.workspace = true
|
||||||
kameo.workspace = true
|
kameo.workspace = true
|
||||||
@@ -50,6 +51,7 @@ subtle = "2.6.1"
|
|||||||
x25519-dalek.workspace = true
|
x25519-dalek.workspace = true
|
||||||
k256.workspace = true
|
k256.workspace = true
|
||||||
kameo_actors.workspace = true
|
kameo_actors.workspace = true
|
||||||
|
vsss-rs = "6.0.1"
|
||||||
|
|
||||||
[dev-dependencies]
|
[dev-dependencies]
|
||||||
proptest = "1.11.0"
|
proptest = "1.11.0"
|
||||||
|
|||||||
@@ -37,7 +37,8 @@ create table if not exists tls_history (
|
|||||||
create table if not exists arbiter_settings (
|
create table if not exists arbiter_settings (
|
||||||
id INTEGER not null PRIMARY KEY CHECK (id = 1), -- singleton row, id must be 1
|
id INTEGER not null PRIMARY KEY CHECK (id = 1), -- singleton row, id must be 1
|
||||||
root_key_id integer references root_key_history (id) on delete RESTRICT, -- if null, means wasn't bootstrapped yet
|
root_key_id integer references root_key_history (id) on delete RESTRICT, -- if null, means wasn't bootstrapped yet
|
||||||
tls_id integer references tls_history (id) on delete RESTRICT
|
tls_id integer references tls_history (id) on delete RESTRICT,
|
||||||
|
shamir_threshold integer
|
||||||
) STRICT;
|
) STRICT;
|
||||||
|
|
||||||
insert into arbiter_settings (id) values (1) on conflict do nothing;
|
insert into arbiter_settings (id) values (1) on conflict do nothing;
|
||||||
@@ -56,6 +57,7 @@ create table if not exists operator (
|
|||||||
|
|
||||||
share blob not null,
|
share blob not null,
|
||||||
share_nonce blob not null,
|
share_nonce blob not null,
|
||||||
|
share_salt blob not null,
|
||||||
|
|
||||||
created_at integer not null default(unixepoch ('now')),
|
created_at integer not null default(unixepoch ('now')),
|
||||||
updated_at integer not null default(unixepoch ('now'))
|
updated_at integer not null default(unixepoch ('now'))
|
||||||
|
|||||||
@@ -1,98 +1,164 @@
|
|||||||
use crate::db::{self, DatabasePool, schema};
|
use crate::{
|
||||||
|
actors::vault::events,
|
||||||
|
db::{self, schema},
|
||||||
|
};
|
||||||
|
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
||||||
use arbiter_proto::{BOOTSTRAP_PATH, home_path};
|
use arbiter_proto::{BOOTSTRAP_PATH, home_path};
|
||||||
|
|
||||||
use diesel::QueryDsl;
|
use diesel::QueryDsl;
|
||||||
use diesel_async::RunQueryDsl;
|
use diesel_async::RunQueryDsl;
|
||||||
use kameo::{Actor, messages};
|
use kameo::{
|
||||||
use rand::{RngExt, distr::Alphanumeric, make_rng, rngs::StdRng};
|
Actor,
|
||||||
|
actor::ActorRef,
|
||||||
|
messages,
|
||||||
|
prelude::{Context, Message},
|
||||||
|
};
|
||||||
|
use kameo_actors::message_bus::{MessageBus, Register};
|
||||||
|
use rand::{RngExt, distr::Alphanumeric, rngs::SysRng};
|
||||||
|
use rand_core::UnwrapErr;
|
||||||
|
use std::path::{Path, PathBuf};
|
||||||
use subtle::ConstantTimeEq as _;
|
use subtle::ConstantTimeEq as _;
|
||||||
use thiserror::Error;
|
use tracing::warn;
|
||||||
|
|
||||||
const TOKEN_LENGTH: usize = 64;
|
const TOKEN_LENGTH: usize = 64;
|
||||||
|
|
||||||
pub async fn generate_token() -> Result<String, std::io::Error> {
|
async fn write_token_file(path: &Path, content: &str) -> Result<(), std::io::Error> {
|
||||||
let rng: StdRng = make_rng();
|
if let Some(parent) = path.parent() {
|
||||||
|
tokio::fs::create_dir_all(parent).await?;
|
||||||
let token = rng.sample_iter(Alphanumeric).take(TOKEN_LENGTH).fold(
|
}
|
||||||
String::default(),
|
tokio::fs::write(path, content.as_bytes()).await?;
|
||||||
|mut accum, char| {
|
#[cfg(unix)]
|
||||||
accum += char.to_string().as_str();
|
{
|
||||||
accum
|
use std::os::unix::fs::PermissionsExt as _;
|
||||||
},
|
tokio::fs::set_permissions(path, std::fs::Permissions::from_mode(0o600)).await?;
|
||||||
);
|
}
|
||||||
|
Ok(())
|
||||||
tokio::fs::write(home_path()?.join(BOOTSTRAP_PATH), token.as_str()).await?;
|
|
||||||
|
|
||||||
Ok(token)
|
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Error, Debug)]
|
async fn remove_token_file(path: &Path) {
|
||||||
|
match tokio::fs::remove_file(path).await {
|
||||||
|
Ok(()) => {}
|
||||||
|
Err(error) if error.kind() == std::io::ErrorKind::NotFound => {}
|
||||||
|
Err(error) => warn!(?error, ?path, "Failed to remove bootstrap token file"),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn generate_token(path: &Path) -> Result<SafeCell<[u8; TOKEN_LENGTH]>, std::io::Error> {
|
||||||
|
let mut cell = SafeCell::new([0u8; TOKEN_LENGTH]);
|
||||||
|
{
|
||||||
|
let mut buf = cell.write();
|
||||||
|
for (slot, byte) in buf
|
||||||
|
.iter_mut()
|
||||||
|
.zip(UnwrapErr(SysRng).sample_iter(Alphanumeric))
|
||||||
|
{
|
||||||
|
*slot = byte;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
let token = cell.read_inline(|buf| String::from_utf8_lossy(buf.as_ref()).into_owned());
|
||||||
|
write_token_file(path, &token).await?;
|
||||||
|
Ok(cell)
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, thiserror::Error)]
|
||||||
pub enum Error {
|
pub enum Error {
|
||||||
#[error("Database error: {0}")]
|
#[error("Database error: {0}")]
|
||||||
Database(#[from] db::PoolError),
|
Database(#[from] db::PoolError),
|
||||||
|
|
||||||
#[error("I/O error: {0}")]
|
#[error("I/O error: {0}")]
|
||||||
Io(#[from] std::io::Error),
|
Io(#[from] std::io::Error),
|
||||||
|
|
||||||
#[error("Database query error: {0}")]
|
#[error("Database query error: {0}")]
|
||||||
Query(#[from] diesel::result::Error),
|
Query(#[from] diesel::result::Error),
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Actor)]
|
/// Custodian of the one-time bootstrap token.
|
||||||
|
///
|
||||||
|
/// The token authorises registering operator identities before the vault
|
||||||
|
/// exists. A Shamir committee needs every member registered before it can be
|
||||||
|
/// declared, so the token stays valid across several registrations and is
|
||||||
|
/// retired by the `Bootstrapped` event rather than by first use, whichever
|
||||||
|
/// bootstrap path fired it.
|
||||||
|
///
|
||||||
|
/// Every daemon start mints a fresh token and overwrites the file: a token
|
||||||
|
/// handed out by an earlier run is dead.
|
||||||
pub struct Bootstrapper {
|
pub struct Bootstrapper {
|
||||||
token: Option<String>,
|
token: Option<SafeCell<[u8; TOKEN_LENGTH]>>,
|
||||||
|
token_path: Option<PathBuf>,
|
||||||
|
events: ActorRef<MessageBus>,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Actor for Bootstrapper {
|
||||||
|
type Args = Self;
|
||||||
|
type Error = std::convert::Infallible;
|
||||||
|
|
||||||
|
async fn on_start(args: Self::Args, actor_ref: ActorRef<Self>) -> Result<Self, Self::Error> {
|
||||||
|
let _ = args
|
||||||
|
.events
|
||||||
|
.tell(Register(actor_ref.recipient::<events::Bootstrapped>()))
|
||||||
|
.await;
|
||||||
|
Ok(args)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
impl Bootstrapper {
|
impl Bootstrapper {
|
||||||
pub async fn new(db: &DatabasePool) -> Result<Self, Error> {
|
pub async fn new(db: &db::DatabasePool, events: ActorRef<MessageBus>) -> Result<Self, Error> {
|
||||||
let row_count: i64 = {
|
let path = home_path()?.join(BOOTSTRAP_PATH);
|
||||||
let mut conn = db.get().await?;
|
let mut conn = db.get().await?;
|
||||||
|
|
||||||
schema::operator::table
|
let bootstrapped = schema::arbiter_settings::table
|
||||||
.count()
|
.select(schema::arbiter_settings::root_key_id)
|
||||||
.get_result(&mut conn)
|
.first::<Option<i32>>(&mut conn)
|
||||||
.await?
|
.await?
|
||||||
};
|
.is_some();
|
||||||
|
if bootstrapped {
|
||||||
|
// A token file can outlive the bootstrap that made it obsolete:
|
||||||
|
// the daemon may have been killed before the event was handled.
|
||||||
|
remove_token_file(&path).await;
|
||||||
|
return Ok(Self {
|
||||||
|
token: None,
|
||||||
|
token_path: None,
|
||||||
|
events,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
let token = if row_count == 0 {
|
Ok(Self {
|
||||||
let token = generate_token().await?;
|
token: Some(generate_token(&path).await?),
|
||||||
Some(token)
|
token_path: Some(path),
|
||||||
} else {
|
events,
|
||||||
None
|
})
|
||||||
};
|
}
|
||||||
|
|
||||||
Ok(Self { token })
|
async fn forget(&mut self) {
|
||||||
|
self.token = None;
|
||||||
|
if let Some(path) = self.token_path.take() {
|
||||||
|
remove_token_file(&path).await;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Message<events::Bootstrapped> for Bootstrapper {
|
||||||
|
type Reply = ();
|
||||||
|
|
||||||
|
async fn handle(
|
||||||
|
&mut self,
|
||||||
|
_: events::Bootstrapped,
|
||||||
|
_ctx: &mut Context<Self, Self::Reply>,
|
||||||
|
) -> Self::Reply {
|
||||||
|
self.forget().await;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#[messages]
|
#[messages]
|
||||||
impl Bootstrapper {
|
impl Bootstrapper {
|
||||||
#[message]
|
#[message]
|
||||||
pub fn is_correct_token(&self, token: String) -> bool {
|
pub fn verify_token(&mut self, token: Vec<u8>) -> bool {
|
||||||
self.token.as_ref().is_some_and(|expected| {
|
self.token.as_mut().is_some_and(|expected| {
|
||||||
let expected_bytes = expected.as_bytes();
|
expected.read_inline(|bytes| bool::from(bytes.as_ref().ct_eq(token.as_slice())))
|
||||||
let token_bytes = token.as_bytes();
|
|
||||||
|
|
||||||
let choice = expected_bytes.ct_eq(token_bytes);
|
|
||||||
bool::from(choice)
|
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
#[message]
|
#[message]
|
||||||
pub fn consume_token(&mut self, token: String) -> bool {
|
pub fn get_token(&mut self) -> Option<String> {
|
||||||
if self.is_correct_token(token) {
|
self.token
|
||||||
self.token = None;
|
.as_mut()
|
||||||
true
|
.map(|cell| cell.read_inline(|buf| String::from_utf8_lossy(buf.as_ref()).into_owned()))
|
||||||
} else {
|
|
||||||
false
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[messages]
|
|
||||||
impl Bootstrapper {
|
|
||||||
#[message]
|
|
||||||
pub fn get_token(&self) -> Option<String> {
|
|
||||||
self.token.clone()
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
use crate::{
|
use crate::{
|
||||||
actors::vault::{CreateNew, Decrypt, Vault},
|
actors::vault::{CreateNew, Decrypt, Vault},
|
||||||
crypto::integrity,
|
crypto::integrity::{self, Integrable},
|
||||||
db::{
|
db::{
|
||||||
DatabaseError, DatabasePool,
|
DatabaseError, DatabasePool,
|
||||||
models::{self, EvmWalletId},
|
models::{self, EvmWalletId},
|
||||||
@@ -25,14 +25,35 @@ use diesel::{
|
|||||||
use diesel_async::RunQueryDsl;
|
use diesel_async::RunQueryDsl;
|
||||||
use kameo::{Actor, actor::ActorRef, messages};
|
use kameo::{Actor, actor::ActorRef, messages};
|
||||||
use rand::{SeedableRng, rng, rngs::StdRng};
|
use rand::{SeedableRng, rng, rngs::StdRng};
|
||||||
|
use tracing::error;
|
||||||
|
|
||||||
pub use crate::evm::safe_signer;
|
pub use crate::evm::safe_signer;
|
||||||
|
|
||||||
|
/// Integrity guard that binds a wallet's encrypted key ID to its Ethereum address.
|
||||||
|
/// Both fields are included in the HMAC — swapping `aead_encrypted_id` in the DB
|
||||||
|
/// invalidates the envelope MAC, and the AEAD ciphertext is also bound to `address`
|
||||||
|
/// as AAD, so decryption fails too.
|
||||||
|
#[derive(arbiter_macros::Hashable)]
|
||||||
|
struct EvmWalletIntegrity {
|
||||||
|
aead_encrypted_id: i32,
|
||||||
|
address: Address,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Integrable for EvmWalletIntegrity {
|
||||||
|
const KIND: &'static str = "evm_wallet";
|
||||||
|
}
|
||||||
|
|
||||||
#[derive(Debug, thiserror::Error)]
|
#[derive(Debug, thiserror::Error)]
|
||||||
pub enum SignTransactionError {
|
pub enum SignTransactionError {
|
||||||
#[error("Wallet not found")]
|
#[error("Wallet not found")]
|
||||||
WalletNotFound,
|
WalletNotFound,
|
||||||
|
|
||||||
|
#[error("Decrypted key does not match requested wallet address")]
|
||||||
|
KeyAddressMismatch,
|
||||||
|
|
||||||
|
#[error("Internal signing error")]
|
||||||
|
Internal,
|
||||||
|
|
||||||
#[error("Database error: {0}")]
|
#[error("Database error: {0}")]
|
||||||
Database(#[from] DatabaseError),
|
Database(#[from] DatabaseError),
|
||||||
|
|
||||||
@@ -64,6 +85,12 @@ pub enum Error {
|
|||||||
Integrity(#[from] integrity::Error),
|
Integrity(#[from] integrity::Error),
|
||||||
}
|
}
|
||||||
|
|
||||||
|
impl From<diesel::result::Error> for Error {
|
||||||
|
fn from(e: diesel::result::Error) -> Self {
|
||||||
|
Self::Database(DatabaseError::from(e))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
#[derive(Actor)]
|
#[derive(Actor)]
|
||||||
pub struct EvmActor {
|
pub struct EvmActor {
|
||||||
pub vault: ActorRef<Vault>,
|
pub vault: ActorRef<Vault>,
|
||||||
@@ -97,20 +124,39 @@ impl EvmActor {
|
|||||||
|
|
||||||
let aead_id: i32 = self
|
let aead_id: i32 = self
|
||||||
.vault
|
.vault
|
||||||
.ask(CreateNew { plaintext })
|
.ask(CreateNew {
|
||||||
|
plaintext,
|
||||||
|
aad: address.as_slice().to_vec(),
|
||||||
|
})
|
||||||
.await
|
.await
|
||||||
.map_err(|_| Error::VaultSend)?;
|
.map_err(|_| Error::VaultSend)?;
|
||||||
|
|
||||||
let mut conn = self.db.get().await.map_err(DatabaseError::from)?;
|
let mut conn = self.db.get().await.map_err(DatabaseError::from)?;
|
||||||
let wallet_id = insert_into(schema::evm_wallet::table)
|
let wallet_id = conn
|
||||||
|
.exclusive_transaction(async |conn| {
|
||||||
|
let wallet_id: i32 = insert_into(schema::evm_wallet::table)
|
||||||
.values(&models::NewEvmWallet {
|
.values(&models::NewEvmWallet {
|
||||||
address: address.as_slice().to_vec(),
|
address: address.as_slice().to_vec(),
|
||||||
aead_encrypted_id: aead_id,
|
aead_encrypted_id: aead_id,
|
||||||
})
|
})
|
||||||
.returning(schema::evm_wallet::id)
|
.returning(schema::evm_wallet::id)
|
||||||
.get_result(&mut conn)
|
.get_result(conn)
|
||||||
.await
|
.await
|
||||||
.map_err(DatabaseError::from)?;
|
.map_err(DatabaseError::from)
|
||||||
|
.map_err(Error::Database)?;
|
||||||
|
|
||||||
|
integrity::sign_entity(
|
||||||
|
conn,
|
||||||
|
&self.vault,
|
||||||
|
&EvmWalletIntegrity { address, aead_encrypted_id: aead_id },
|
||||||
|
wallet_id,
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.map_err(Error::Integrity)?;
|
||||||
|
|
||||||
|
Ok::<i32, Error>(wallet_id)
|
||||||
|
})
|
||||||
|
.await?;
|
||||||
|
|
||||||
Ok((wallet_id, address))
|
Ok((wallet_id, address))
|
||||||
}
|
}
|
||||||
@@ -160,29 +206,14 @@ impl EvmActor {
|
|||||||
}
|
}
|
||||||
|
|
||||||
#[message]
|
#[message]
|
||||||
#[expect(clippy::unused_async, reason = "reserved for impl")]
|
pub async fn useragent_delete_grant(
|
||||||
pub async fn operator_delete_grant(&mut self, _grant_id: i32) -> Result<(), Error> {
|
&mut self,
|
||||||
// let mut conn = self.db.get().await.map_err(DatabaseError::from)?;
|
grant_id: i32,
|
||||||
// let vault = self.vault.clone();
|
) -> Result<(), Error> {
|
||||||
|
self.engine
|
||||||
// diesel_async::AsyncConnection::transaction(&mut conn, |conn| {
|
.revoke_grant(grant_id)
|
||||||
// Box::pin(async move {
|
.await
|
||||||
// diesel::update(schema::evm_basic_grant::table)
|
.map_err(Error::from)
|
||||||
// .filter(schema::evm_basic_grant::id.eq(grant_id))
|
|
||||||
// .set(schema::evm_basic_grant::revoked_at.eq(SqliteTimestamp::now()))
|
|
||||||
// .execute(conn)
|
|
||||||
// .await?;
|
|
||||||
|
|
||||||
// let signed = integrity::evm::load_signed_grant_by_basic_id(conn, grant_id).await?;
|
|
||||||
|
|
||||||
// diesel::result::QueryResult::Ok(())
|
|
||||||
// })
|
|
||||||
// })
|
|
||||||
// .await
|
|
||||||
// .map_err(DatabaseError::from)?;
|
|
||||||
|
|
||||||
// Ok(())
|
|
||||||
todo!()
|
|
||||||
}
|
}
|
||||||
|
|
||||||
#[message]
|
#[message]
|
||||||
@@ -256,16 +287,51 @@ impl EvmActor {
|
|||||||
.ok_or(SignTransactionError::WalletNotFound)?;
|
.ok_or(SignTransactionError::WalletNotFound)?;
|
||||||
drop(conn);
|
drop(conn);
|
||||||
|
|
||||||
|
let mut conn = self.db.get().await.map_err(DatabaseError::from)?;
|
||||||
|
let attestation = integrity::verify_entity(
|
||||||
|
&mut conn,
|
||||||
|
&self.vault,
|
||||||
|
&EvmWalletIntegrity {
|
||||||
|
address: wallet_address,
|
||||||
|
aead_encrypted_id: wallet.aead_encrypted_id,
|
||||||
|
},
|
||||||
|
wallet.id.to_raw(),
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.map_err(|e| {
|
||||||
|
error!(?e, ?wallet.id, "EVM wallet integrity check failed");
|
||||||
|
SignTransactionError::Internal
|
||||||
|
})?;
|
||||||
|
drop(conn);
|
||||||
|
|
||||||
|
if attestation != integrity::AttestationStatus::Attested {
|
||||||
|
error!(
|
||||||
|
?wallet.id,
|
||||||
|
"EVM wallet integrity unavailable; refusing to sign"
|
||||||
|
);
|
||||||
|
return Err(SignTransactionError::Internal);
|
||||||
|
}
|
||||||
|
|
||||||
let raw_key: SafeCell<Vec<u8>> = self
|
let raw_key: SafeCell<Vec<u8>> = self
|
||||||
.vault
|
.vault
|
||||||
.ask(Decrypt {
|
.ask(Decrypt {
|
||||||
aead_id: wallet.aead_encrypted_id,
|
aead_id: wallet.aead_encrypted_id,
|
||||||
|
aad: wallet.address.clone(),
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
.map_err(|_| SignTransactionError::VaultSend)?;
|
.map_err(|_| SignTransactionError::VaultSend)?;
|
||||||
|
|
||||||
let signer = safe_signer::SafeSigner::from_cell(raw_key)?;
|
let signer = safe_signer::SafeSigner::from_cell(raw_key)?;
|
||||||
|
|
||||||
|
if signer.address() != wallet_address {
|
||||||
|
error!(
|
||||||
|
expected = %wallet_address,
|
||||||
|
actual = %signer.address(),
|
||||||
|
"Decrypted private key address does not match requested wallet"
|
||||||
|
);
|
||||||
|
return Err(SignTransactionError::KeyAddressMismatch);
|
||||||
|
}
|
||||||
|
|
||||||
self.engine
|
self.engine
|
||||||
.evaluate_transaction(wallet_access, transaction.clone(), RunKind::Execution)
|
.evaluate_transaction(wallet_access, transaction.clone(), RunKind::Execution)
|
||||||
.await?;
|
.await?;
|
||||||
|
|||||||
@@ -11,7 +11,9 @@ use kameo::{
|
|||||||
prelude::{ActorId, ActorRef, ActorStopReason, Context, WeakActorRef},
|
prelude::{ActorId, ActorRef, ActorStopReason, Context, WeakActorRef},
|
||||||
reply::ReplySender,
|
reply::ReplySender,
|
||||||
};
|
};
|
||||||
use std::ops::ControlFlow;
|
use std::{ops::ControlFlow, time::Duration};
|
||||||
|
|
||||||
|
const APPROVAL_TIMEOUT: Duration = Duration::from_secs(30);
|
||||||
|
|
||||||
pub struct Args {
|
pub struct Args {
|
||||||
pub client: ClientProfile,
|
pub client: ClientProfile,
|
||||||
@@ -64,6 +66,14 @@ impl Actor for ClientApprovalController {
|
|||||||
.await;
|
.await;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
let weak = actor_ref.downgrade();
|
||||||
|
tokio::spawn(async move {
|
||||||
|
tokio::time::sleep(APPROVAL_TIMEOUT).await;
|
||||||
|
if let Some(r) = weak.upgrade() {
|
||||||
|
let _ = r.tell(OnApprovalTimeout {}).await;
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
Ok(this)
|
Ok(this)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -104,4 +114,14 @@ impl ClientApprovalController {
|
|||||||
ctx.stop();
|
ctx.stop();
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Fired after `APPROVAL_TIMEOUT` elapses. Any operator that hasn't responded
|
||||||
|
/// by then is treated as a denial to prevent zombie sessions from blocking the flow.
|
||||||
|
#[message(ctx)]
|
||||||
|
pub fn on_approval_timeout(&mut self, ctx: &mut Context<Self, ()>) {
|
||||||
|
if self.pending > 0 {
|
||||||
|
self.send_reply(Ok(false));
|
||||||
|
ctx.stop();
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -20,6 +20,8 @@ pub mod client_connect_approval;
|
|||||||
|
|
||||||
pub struct FlowCoordinator {
|
pub struct FlowCoordinator {
|
||||||
pub clients: HashMap<ActorId, ActorRef<ClientSession>>,
|
pub clients: HashMap<ActorId, ActorRef<ClientSession>>,
|
||||||
|
/// Maps DB `client_id` → `ActorId` for fast connected-client lookup.
|
||||||
|
client_ids: HashMap<i32, ActorId>,
|
||||||
operator_registry: ActorRef<OperatorRegistry>,
|
operator_registry: ActorRef<OperatorRegistry>,
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -27,6 +29,7 @@ impl FlowCoordinator {
|
|||||||
pub fn new(operator_registry: ActorRef<OperatorRegistry>) -> Self {
|
pub fn new(operator_registry: ActorRef<OperatorRegistry>) -> Self {
|
||||||
Self {
|
Self {
|
||||||
clients: HashMap::default(),
|
clients: HashMap::default(),
|
||||||
|
client_ids: HashMap::default(),
|
||||||
operator_registry,
|
operator_registry,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -48,6 +51,7 @@ impl Actor for FlowCoordinator {
|
|||||||
_: ActorStopReason,
|
_: ActorStopReason,
|
||||||
) -> Result<ControlFlow<ActorStopReason>, Self::Error> {
|
) -> Result<ControlFlow<ActorStopReason>, Self::Error> {
|
||||||
if self.clients.remove(&id).is_some() {
|
if self.clients.remove(&id).is_some() {
|
||||||
|
self.client_ids.retain(|_, actor_id| *actor_id != id);
|
||||||
info!(
|
info!(
|
||||||
?id,
|
?id,
|
||||||
actor = "FlowCoordinator",
|
actor = "FlowCoordinator",
|
||||||
@@ -75,14 +79,28 @@ impl FlowCoordinator {
|
|||||||
#[message(ctx)]
|
#[message(ctx)]
|
||||||
pub async fn register_client(
|
pub async fn register_client(
|
||||||
&mut self,
|
&mut self,
|
||||||
|
client_id: i32,
|
||||||
actor: ActorRef<ClientSession>,
|
actor: ActorRef<ClientSession>,
|
||||||
ctx: &mut Context<Self, ()>,
|
ctx: &mut Context<Self, ()>,
|
||||||
) {
|
) {
|
||||||
info!(id = %actor.id(), actor = "FlowCoordinator", event = "client.connected");
|
info!(id = %actor.id(), client_id, actor = "FlowCoordinator", event = "client.connected");
|
||||||
ctx.actor_ref().link(&actor).await;
|
ctx.actor_ref().link(&actor).await;
|
||||||
|
self.client_ids.insert(client_id, actor.id());
|
||||||
self.clients.insert(actor.id(), actor);
|
self.clients.insert(actor.id(), actor);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[message]
|
||||||
|
pub fn is_client_connected(&self, client_id: i32) -> bool {
|
||||||
|
self.client_ids.contains_key(&client_id)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Returns the DB `client_ids` of all currently connected SDK clients.
|
||||||
|
/// Used by operator sessions on startup to seed their approved-client set.
|
||||||
|
#[message]
|
||||||
|
pub fn get_connected_client_ids(&self) -> Vec<i32> {
|
||||||
|
self.client_ids.keys().copied().collect()
|
||||||
|
}
|
||||||
|
|
||||||
#[message(ctx)]
|
#[message(ctx)]
|
||||||
pub async fn request_client_approval(
|
pub async fn request_client_approval(
|
||||||
&mut self,
|
&mut self,
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
use crate::{
|
use crate::{
|
||||||
actors::{
|
actors::{
|
||||||
bootstrap::Bootstrapper, evm::EvmActor, flow_coordinator::FlowCoordinator,
|
bootstrap::Bootstrapper, evm::EvmActor, flow_coordinator::FlowCoordinator,
|
||||||
operator_registry::OperatorRegistry, vault::Vault,
|
operator_registry::OperatorRegistry, vault::Vault, vault_coordinator::VaultCoordinator,
|
||||||
},
|
},
|
||||||
db,
|
db,
|
||||||
};
|
};
|
||||||
@@ -15,20 +15,22 @@ pub mod evm;
|
|||||||
pub mod flow_coordinator;
|
pub mod flow_coordinator;
|
||||||
pub mod operator_registry;
|
pub mod operator_registry;
|
||||||
pub mod vault;
|
pub mod vault;
|
||||||
|
pub mod vault_coordinator;
|
||||||
|
|
||||||
#[derive(Error, Debug)]
|
#[derive(Error, Debug)]
|
||||||
pub enum SpawnError {
|
pub enum SpawnError {
|
||||||
#[error("Failed to spawn Bootstrapper actor")]
|
#[error("Failed to spawn Bootstrapper actor")]
|
||||||
Bootstrapper(#[from] bootstrap::Error),
|
Bootstrapper(#[from] bootstrap::Error),
|
||||||
|
|
||||||
#[error("Failed to spawn Vault actor")]
|
#[error("Failed to spawn Vault actor")]
|
||||||
Vault(#[from] vault::Error),
|
Vault(#[from] vault::Error),
|
||||||
|
#[error("Failed to spawn VaultCoordinator actor")]
|
||||||
|
VaultCoordinator(#[from] vault_coordinator::Error),
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Long-lived actors that are shared across all connections and handle global state and operations
|
|
||||||
#[derive(Clone)]
|
#[derive(Clone)]
|
||||||
pub struct GlobalActors {
|
pub struct GlobalActors {
|
||||||
pub vault: ActorRef<Vault>,
|
pub vault: ActorRef<Vault>,
|
||||||
|
pub vault_coordinator: ActorRef<VaultCoordinator>,
|
||||||
pub bootstrapper: ActorRef<Bootstrapper>,
|
pub bootstrapper: ActorRef<Bootstrapper>,
|
||||||
pub flow_coordinator: ActorRef<FlowCoordinator>,
|
pub flow_coordinator: ActorRef<FlowCoordinator>,
|
||||||
pub operator_registry: ActorRef<OperatorRegistry>,
|
pub operator_registry: ActorRef<OperatorRegistry>,
|
||||||
@@ -42,18 +44,22 @@ impl GlobalActors {
|
|||||||
}
|
}
|
||||||
|
|
||||||
pub async fn spawn(db: db::DatabasePool) -> Result<Self, SpawnError> {
|
pub async fn spawn(db: db::DatabasePool) -> Result<Self, SpawnError> {
|
||||||
let message_bus = Self::spawn_message_bus();
|
let events = Self::spawn_message_bus();
|
||||||
let key_holder = Vault::spawn(Vault::new(db.clone(), message_bus.clone()).await?);
|
let vault = Vault::spawn(Vault::new(db.clone(), events.clone()).await?);
|
||||||
|
let bootstrapper = Bootstrapper::spawn(Bootstrapper::new(&db, events.clone()).await?);
|
||||||
|
let vault_coordinator =
|
||||||
|
VaultCoordinator::spawn(VaultCoordinator::new(db.clone(), vault.clone()));
|
||||||
let operator_registry = OperatorRegistry::spawn(OperatorRegistry::default());
|
let operator_registry = OperatorRegistry::spawn(OperatorRegistry::default());
|
||||||
Ok(Self {
|
Ok(Self {
|
||||||
bootstrapper: Bootstrapper::spawn(Bootstrapper::new(&db).await?),
|
bootstrapper,
|
||||||
evm: EvmActor::spawn(EvmActor::new(key_holder.clone(), db)),
|
evm: EvmActor::spawn(EvmActor::new(vault.clone(), db.clone())),
|
||||||
vault: key_holder,
|
vault,
|
||||||
|
vault_coordinator,
|
||||||
flow_coordinator: FlowCoordinator::spawn(FlowCoordinator::new(
|
flow_coordinator: FlowCoordinator::spawn(FlowCoordinator::new(
|
||||||
operator_registry.clone(),
|
operator_registry.clone(),
|
||||||
)),
|
)),
|
||||||
operator_registry,
|
operator_registry,
|
||||||
events: message_bus,
|
events,
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -20,8 +20,8 @@ impl Actor for OperatorRegistry {
|
|||||||
|
|
||||||
type Error = Infallible;
|
type Error = Infallible;
|
||||||
|
|
||||||
async fn on_start(args: Self::Args, _: ActorRef<Self>) -> Result<Self, Self::Error> {
|
fn on_start(args: Self::Args, _: ActorRef<Self>) -> impl Future<Output = Result<Self, Self::Error>> {
|
||||||
Ok(args)
|
std::future::ready(Ok(args))
|
||||||
}
|
}
|
||||||
|
|
||||||
async fn on_link_died(
|
async fn on_link_died(
|
||||||
|
|||||||
@@ -1,15 +1,17 @@
|
|||||||
use crate::{
|
use crate::{
|
||||||
crypto::{
|
crypto::{
|
||||||
KeyCell, derive_key,
|
KeyCell,
|
||||||
encryption::v1::{self, Nonce},
|
encryption::v1::{self, Nonce},
|
||||||
integrity::v1::HmacSha256,
|
integrity::v1::HmacSha256,
|
||||||
},
|
},
|
||||||
db::{
|
db::{
|
||||||
self,
|
self,
|
||||||
|
custody::{self, CustodyRecord},
|
||||||
models::{self, RootKeyHistory, RootKeyHistoryId},
|
models::{self, RootKeyHistory, RootKeyHistoryId},
|
||||||
schema::{self},
|
schema::{self},
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
|
|
||||||
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
||||||
|
|
||||||
use chrono::Utc;
|
use chrono::Utc;
|
||||||
@@ -22,7 +24,7 @@ use hmac::{KeyInit as _, Mac as _};
|
|||||||
use kameo::{Actor, Reply, actor::ActorRef, messages};
|
use kameo::{Actor, Reply, actor::ActorRef, messages};
|
||||||
use kameo_actors::message_bus::{MessageBus, Publish};
|
use kameo_actors::message_bus::{MessageBus, Publish};
|
||||||
use strum::{EnumDiscriminants, IntoDiscriminant};
|
use strum::{EnumDiscriminants, IntoDiscriminant};
|
||||||
use tracing::{error, info};
|
use tracing::{error, info, warn};
|
||||||
|
|
||||||
pub mod events {
|
pub mod events {
|
||||||
#[derive(Clone, Copy)]
|
#[derive(Clone, Copy)]
|
||||||
@@ -45,6 +47,8 @@ pub enum Error {
|
|||||||
Sealed,
|
Sealed,
|
||||||
#[error("Invalid key provided")]
|
#[error("Invalid key provided")]
|
||||||
InvalidKey,
|
InvalidKey,
|
||||||
|
#[error("Vault locked: too many failed unseal attempts")]
|
||||||
|
LockedOut,
|
||||||
|
|
||||||
#[error("Requested aead entry not found")]
|
#[error("Requested aead entry not found")]
|
||||||
NotFound,
|
NotFound,
|
||||||
@@ -58,8 +62,14 @@ pub enum Error {
|
|||||||
#[error("Database transaction error: {0}")]
|
#[error("Database transaction error: {0}")]
|
||||||
DatabaseTransaction(#[from] diesel::result::Error),
|
DatabaseTransaction(#[from] diesel::result::Error),
|
||||||
|
|
||||||
|
#[error("Custody storage error: {0}")]
|
||||||
|
Custody(#[from] custody::Error),
|
||||||
|
|
||||||
#[error("Broken database")]
|
#[error("Broken database")]
|
||||||
BrokenDatabase,
|
BrokenDatabase,
|
||||||
|
|
||||||
|
#[error("Integrity key version mismatch: envelope uses key {envelope:?}, current key is {current:?}")]
|
||||||
|
KeyVersionMismatch { envelope: RootKeyHistoryId, current: RootKeyHistoryId },
|
||||||
}
|
}
|
||||||
|
|
||||||
struct Unsealed {
|
struct Unsealed {
|
||||||
@@ -79,6 +89,8 @@ enum State {
|
|||||||
Unsealed(Unsealed),
|
Unsealed(Unsealed),
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const MAX_UNSEAL_ATTEMPTS: u32 = 5;
|
||||||
|
|
||||||
/// Manages vault root key and tracks current state of the vault (bootstrapped/unbootstrapped, sealed/unsealed).
|
/// Manages vault root key and tracks current state of the vault (bootstrapped/unbootstrapped, sealed/unsealed).
|
||||||
///
|
///
|
||||||
/// Provides API for encrypting and decrypting data using the vault root key.
|
/// Provides API for encrypting and decrypting data using the vault root key.
|
||||||
@@ -88,6 +100,7 @@ pub struct Vault {
|
|||||||
db: db::DatabasePool,
|
db: db::DatabasePool,
|
||||||
state: State,
|
state: State,
|
||||||
events: ActorRef<MessageBus>,
|
events: ActorRef<MessageBus>,
|
||||||
|
unseal_failures: u32,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[messages]
|
#[messages]
|
||||||
@@ -110,7 +123,12 @@ impl Vault {
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
Ok(Self { db, state, events })
|
Ok(Self {
|
||||||
|
db,
|
||||||
|
state,
|
||||||
|
events,
|
||||||
|
unseal_failures: 0,
|
||||||
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
// Exclusive transaction to avoid race condtions if multiple vaults write
|
// Exclusive transaction to avoid race condtions if multiple vaults write
|
||||||
@@ -159,13 +177,16 @@ impl Vault {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Create the root key and take the vault into the unsealed state.
|
||||||
#[message]
|
#[message]
|
||||||
pub async fn bootstrap(&mut self, seal_key_raw: SafeCell<Vec<u8>>) -> Result<(), Error> {
|
pub async fn bootstrap(
|
||||||
|
&mut self,
|
||||||
|
mut seal_key: KeyCell,
|
||||||
|
custody: Option<CustodyRecord>,
|
||||||
|
) -> Result<(), Error> {
|
||||||
if !matches!(self.state, State::Unbootstrapped) {
|
if !matches!(self.state, State::Unbootstrapped) {
|
||||||
return Err(Error::AlreadyBootstrapped);
|
return Err(Error::AlreadyBootstrapped);
|
||||||
}
|
}
|
||||||
let salt = v1::generate_salt();
|
|
||||||
let mut seal_key = derive_key(seal_key_raw, &salt);
|
|
||||||
let mut root_key = KeyCell::new_secure_random();
|
let mut root_key = KeyCell::new_secure_random();
|
||||||
|
|
||||||
// Zero nonces are fine because they are one-time
|
// Zero nonces are fine because they are one-time
|
||||||
@@ -194,7 +215,7 @@ impl Vault {
|
|||||||
root_key_encryption_nonce: root_key_nonce.to_vec(),
|
root_key_encryption_nonce: root_key_nonce.to_vec(),
|
||||||
data_encryption_nonce: data_encryption_nonce_bytes.clone(),
|
data_encryption_nonce: data_encryption_nonce_bytes.clone(),
|
||||||
schema_version: 1,
|
schema_version: 1,
|
||||||
salt: salt.to_vec(),
|
salt: v1::generate_salt().to_vec(),
|
||||||
})
|
})
|
||||||
.returning(schema::root_key_history::id)
|
.returning(schema::root_key_history::id)
|
||||||
.get_result(&mut *conn)
|
.get_result(&mut *conn)
|
||||||
@@ -205,9 +226,11 @@ impl Vault {
|
|||||||
.execute(&mut *conn)
|
.execute(&mut *conn)
|
||||||
.await?;
|
.await?;
|
||||||
|
|
||||||
Result::<_, diesel::result::Error>::Ok(RootKeyHistoryId::from_raw(
|
if let Some(record) = custody.as_ref() {
|
||||||
root_key_history_id,
|
custody::write_record(&mut *conn, record).await?;
|
||||||
))
|
}
|
||||||
|
|
||||||
|
Result::<_, Error>::Ok(RootKeyHistoryId::from_raw(root_key_history_id))
|
||||||
})
|
})
|
||||||
.await?;
|
.await?;
|
||||||
|
|
||||||
@@ -223,7 +246,11 @@ impl Vault {
|
|||||||
}
|
}
|
||||||
|
|
||||||
#[message]
|
#[message]
|
||||||
pub async fn try_unseal(&mut self, seal_key_raw: SafeCell<Vec<u8>>) -> Result<(), Error> {
|
pub async fn try_unseal(&mut self, mut seal_key: KeyCell) -> Result<(), Error> {
|
||||||
|
if self.unseal_failures >= MAX_UNSEAL_ATTEMPTS {
|
||||||
|
return Err(Error::LockedOut);
|
||||||
|
}
|
||||||
|
|
||||||
let State::Sealed {
|
let State::Sealed {
|
||||||
root_key_history_id,
|
root_key_history_id,
|
||||||
} = &self.state
|
} = &self.state
|
||||||
@@ -241,13 +268,6 @@ impl Vault {
|
|||||||
.await?
|
.await?
|
||||||
};
|
};
|
||||||
|
|
||||||
let salt = ¤t_key.salt;
|
|
||||||
let salt = v1::Salt::try_from(salt.as_slice()).map_err(|_| {
|
|
||||||
error!("Broken database: invalid salt for root key");
|
|
||||||
Error::BrokenDatabase
|
|
||||||
})?;
|
|
||||||
let mut seal_key = derive_key(seal_key_raw, &salt);
|
|
||||||
|
|
||||||
let mut root_key = SafeCell::new(current_key.ciphertext.clone());
|
let mut root_key = SafeCell::new(current_key.ciphertext.clone());
|
||||||
|
|
||||||
let nonce =
|
let nonce =
|
||||||
@@ -256,13 +276,27 @@ impl Vault {
|
|||||||
Error::BrokenDatabase
|
Error::BrokenDatabase
|
||||||
})?;
|
})?;
|
||||||
|
|
||||||
seal_key
|
if seal_key
|
||||||
.decrypt_in_place(&nonce, v1::ROOT_KEY_TAG, &mut root_key)
|
.decrypt_in_place(&nonce, v1::ROOT_KEY_TAG, &mut root_key)
|
||||||
.map_err(|err| {
|
.is_err()
|
||||||
error!(?err, "Failed to unseal root key: invalid seal key");
|
{
|
||||||
Error::InvalidKey
|
self.unseal_failures += 1;
|
||||||
})?;
|
if self.unseal_failures >= MAX_UNSEAL_ATTEMPTS {
|
||||||
|
error!(
|
||||||
|
attempts = self.unseal_failures,
|
||||||
|
"Vault locked: maximum failed unseal attempts reached"
|
||||||
|
);
|
||||||
|
} else {
|
||||||
|
warn!(
|
||||||
|
attempts = self.unseal_failures,
|
||||||
|
remaining = MAX_UNSEAL_ATTEMPTS - self.unseal_failures,
|
||||||
|
"Failed unseal attempt"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
return Err(Error::InvalidKey);
|
||||||
|
}
|
||||||
|
|
||||||
|
self.unseal_failures = 0;
|
||||||
self.state = State::Unsealed(Unsealed {
|
self.state = State::Unsealed(Unsealed {
|
||||||
root_key_history_id: current_key.id,
|
root_key_history_id: current_key.id,
|
||||||
root_key: KeyCell::try_from(root_key).map_err(|err| {
|
root_key: KeyCell::try_from(root_key).map_err(|err| {
|
||||||
@@ -277,8 +311,10 @@ impl Vault {
|
|||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Decrypts an AEAD entry. The `aad` must match the value used at encryption time;
|
||||||
|
/// a mismatch causes authentication failure, preventing cross-wallet key swaps.
|
||||||
#[message]
|
#[message]
|
||||||
pub async fn decrypt(&mut self, aead_id: i32) -> Result<SafeCell<Vec<u8>>, Error> {
|
pub async fn decrypt(&mut self, aead_id: i32, aad: Vec<u8>) -> Result<SafeCell<Vec<u8>>, Error> {
|
||||||
let Unsealed { root_key, .. } = Self::expect_unsealed(&mut self.state)?;
|
let Unsealed { root_key, .. } = Self::expect_unsealed(&mut self.state)?;
|
||||||
|
|
||||||
let row: models::AeadEncrypted = {
|
let row: models::AeadEncrypted = {
|
||||||
@@ -300,13 +336,15 @@ impl Vault {
|
|||||||
Error::BrokenDatabase
|
Error::BrokenDatabase
|
||||||
})?;
|
})?;
|
||||||
let mut output = SafeCell::new(row.ciphertext);
|
let mut output = SafeCell::new(row.ciphertext);
|
||||||
root_key.decrypt_in_place(&nonce, v1::TAG, &mut output)?;
|
root_key.decrypt_in_place(&nonce, &aad, &mut output)?;
|
||||||
Ok(output)
|
Ok(output)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Creates a new `aead_encrypted` entry and returns its ID.
|
||||||
|
/// The `aad` is bound into the ciphertext and must be reproduced exactly at decryption time.
|
||||||
// Creates new `aead_encrypted` entry in the database and returns it's ID
|
// Creates new `aead_encrypted` entry in the database and returns it's ID
|
||||||
#[message]
|
#[message]
|
||||||
pub async fn create_new(&mut self, mut plaintext: SafeCell<Vec<u8>>) -> Result<i32, Error> {
|
pub async fn create_new(&mut self, mut plaintext: SafeCell<Vec<u8>>, aad: Vec<u8>) -> Result<i32, Error> {
|
||||||
let Unsealed {
|
let Unsealed {
|
||||||
root_key,
|
root_key,
|
||||||
root_key_history_id,
|
root_key_history_id,
|
||||||
@@ -318,7 +356,7 @@ impl Vault {
|
|||||||
|
|
||||||
let mut ciphertext_buffer = plaintext.write();
|
let mut ciphertext_buffer = plaintext.write();
|
||||||
let ciphertext_buffer: &mut Vec<u8> = ciphertext_buffer.as_mut();
|
let ciphertext_buffer: &mut Vec<u8> = ciphertext_buffer.as_mut();
|
||||||
root_key.encrypt_in_place(&nonce, v1::TAG, &mut *ciphertext_buffer)?;
|
root_key.encrypt_in_place(&nonce, &aad, &mut *ciphertext_buffer)?;
|
||||||
|
|
||||||
let ciphertext = std::mem::take(ciphertext_buffer);
|
let ciphertext = std::mem::take(ciphertext_buffer);
|
||||||
|
|
||||||
@@ -354,11 +392,9 @@ impl Vault {
|
|||||||
root_key_history_id,
|
root_key_history_id,
|
||||||
} = Self::expect_unsealed(&mut self.state)?;
|
} = Self::expect_unsealed(&mut self.state)?;
|
||||||
|
|
||||||
let mut hmac = root_key
|
let mut hmac = root_key.0.read_inline(|k| {
|
||||||
.0
|
HmacSha256::new_from_slice(k)
|
||||||
.read_inline(|k| match HmacSha256::new_from_slice(k) {
|
.unwrap_or_else(|_| unreachable!("HMAC accepts keys of any size"))
|
||||||
Ok(v) => v,
|
|
||||||
Err(_) => unreachable!("HMAC accepts keys of any size"),
|
|
||||||
});
|
});
|
||||||
hmac.update(&root_key_history_id.to_raw().to_be_bytes());
|
hmac.update(&root_key_history_id.to_raw().to_be_bytes());
|
||||||
hmac.update(&mac_input);
|
hmac.update(&mac_input);
|
||||||
@@ -380,14 +416,15 @@ impl Vault {
|
|||||||
} = Self::expect_unsealed(&mut self.state)?;
|
} = Self::expect_unsealed(&mut self.state)?;
|
||||||
|
|
||||||
if *root_key_history_id != key_version {
|
if *root_key_history_id != key_version {
|
||||||
return Ok(false);
|
return Err(Error::KeyVersionMismatch {
|
||||||
|
envelope: key_version,
|
||||||
|
current: *root_key_history_id,
|
||||||
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
let mut hmac = root_key
|
let mut hmac = root_key.0.read_inline(|k| {
|
||||||
.0
|
HmacSha256::new_from_slice(k)
|
||||||
.read_inline(|k| match HmacSha256::new_from_slice(k) {
|
.unwrap_or_else(|_| unreachable!("HMAC accepts keys of any size"))
|
||||||
Ok(v) => v,
|
|
||||||
Err(_) => unreachable!("HMAC accepts keys of any size"),
|
|
||||||
});
|
});
|
||||||
hmac.update(&key_version.to_raw().to_be_bytes());
|
hmac.update(&key_version.to_raw().to_be_bytes());
|
||||||
hmac.update(&mac_input);
|
hmac.update(&mac_input);
|
||||||
@@ -413,8 +450,6 @@ impl Vault {
|
|||||||
#[cfg(test)]
|
#[cfg(test)]
|
||||||
mod tests {
|
mod tests {
|
||||||
use crate::actors::GlobalActors;
|
use crate::actors::GlobalActors;
|
||||||
use crate::db::models::RootKeyHistory;
|
|
||||||
use arbiter_crypto::safecell::SafeCellHandle as _;
|
|
||||||
|
|
||||||
use super::*;
|
use super::*;
|
||||||
|
|
||||||
@@ -422,8 +457,8 @@ mod tests {
|
|||||||
let mut actor = Vault::new(db.clone(), GlobalActors::spawn_message_bus())
|
let mut actor = Vault::new(db.clone(), GlobalActors::spawn_message_bus())
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
let seal_key = SafeCell::new(b"test-seal-key".to_vec());
|
let seal_key = KeyCell::from([0u8; 32]);
|
||||||
actor.bootstrap(seal_key).await.unwrap();
|
actor.bootstrap(seal_key, None).await.unwrap();
|
||||||
actor
|
actor
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -432,12 +467,13 @@ mod tests {
|
|||||||
async fn nonce_monotonic_even_when_nonce_allocation_interleaves() {
|
async fn nonce_monotonic_even_when_nonce_allocation_interleaves() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
let mut actor = bootstrapped_actor(&db).await;
|
let mut actor = bootstrapped_actor(&db).await;
|
||||||
let root_key_history_id = match actor.state {
|
|
||||||
State::Unsealed(Unsealed {
|
let State::Unsealed(Unsealed {
|
||||||
root_key_history_id,
|
root_key_history_id,
|
||||||
..
|
..
|
||||||
}) => root_key_history_id,
|
}) = actor.state
|
||||||
_ => panic!("expected unsealed state"),
|
else {
|
||||||
|
panic!("expected unsealed state")
|
||||||
};
|
};
|
||||||
|
|
||||||
let n1 = Vault::get_new_nonce(&db, root_key_history_id)
|
let n1 = Vault::get_new_nonce(&db, root_key_history_id)
|
||||||
@@ -457,7 +493,7 @@ mod tests {
|
|||||||
assert_eq!(root_row.data_encryption_nonce, n2.to_vec());
|
assert_eq!(root_row.data_encryption_nonce, n2.to_vec());
|
||||||
|
|
||||||
let id = actor
|
let id = actor
|
||||||
.create_new(SafeCell::new(b"post-interleave".to_vec()))
|
.create_new(SafeCell::new(b"post-interleave".to_vec()), b"test-aad".to_vec())
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
let row: models::AeadEncrypted = schema::aead_encrypted::table
|
let row: models::AeadEncrypted = schema::aead_encrypted::table
|
||||||
|
|||||||
378
server/crates/arbiter-server/src/actors/vault_coordinator/mod.rs
Normal file
378
server/crates/arbiter-server/src/actors/vault_coordinator/mod.rs
Normal file
@@ -0,0 +1,378 @@
|
|||||||
|
//! Coordinates the multi-operator ceremonies that create and open the vault.
|
||||||
|
//!
|
||||||
|
//! The coordinator collects one passphrase per committee member, then hands the
|
||||||
|
//! assembled material to [`Vault`] in a single message. It owns no Diesel code:
|
||||||
|
//! everything it reads or writes goes through [`db::custody`].
|
||||||
|
|
||||||
|
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
||||||
|
use argon2::RECOMMENDED_SALT_LEN;
|
||||||
|
use kameo::{Actor, actor::ActorRef, error::SendError, messages};
|
||||||
|
use rand::rngs::SysRng;
|
||||||
|
use rand_core::{Rng as _, UnwrapErr};
|
||||||
|
|
||||||
|
use crate::{
|
||||||
|
actors::vault::{self, Bootstrap, TryUnseal, Vault},
|
||||||
|
crypto::{KeyCell, derive_key, encryption::v1::Nonce, shamir},
|
||||||
|
db::{
|
||||||
|
self,
|
||||||
|
custody::{self, CustodyRecord, EncryptedShare},
|
||||||
|
models::OperatorId,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
|
||||||
|
const SHARE_AAD: &[u8] = b"arbiter/shamir-share/v1";
|
||||||
|
|
||||||
|
#[derive(Debug, thiserror::Error)]
|
||||||
|
pub enum Error {
|
||||||
|
#[error("An ordinary committee is already being coordinated")]
|
||||||
|
AlreadyBootstrapping,
|
||||||
|
#[error("An unseal is already being coordinated")]
|
||||||
|
AlreadyUnsealing,
|
||||||
|
#[error("Bootstrap is not in progress")]
|
||||||
|
NotBootstrapping,
|
||||||
|
#[error("The operator already contributed")]
|
||||||
|
DuplicateContribution,
|
||||||
|
#[error("The ordinary committee cannot be empty")]
|
||||||
|
EmptyCommittee,
|
||||||
|
#[error("Two-operator committees are unsupported")]
|
||||||
|
UnsupportedCommittee,
|
||||||
|
#[error(
|
||||||
|
"The ordinary committee cannot exceed {} members",
|
||||||
|
shamir::MAX_COMMITTEE_SIZE
|
||||||
|
)]
|
||||||
|
CommitteeTooLarge,
|
||||||
|
#[error("Invalid passphrase")]
|
||||||
|
InvalidPassphrase,
|
||||||
|
#[error("Broken database")]
|
||||||
|
BrokenDatabase,
|
||||||
|
#[error("Shamir error: {0}")]
|
||||||
|
Shamir(String),
|
||||||
|
#[error("Database connection error: {0}")]
|
||||||
|
DatabaseConnection(#[from] db::PoolError),
|
||||||
|
#[error("Custody storage error: {0}")]
|
||||||
|
Custody(#[from] custody::Error),
|
||||||
|
#[error("Encryption error")]
|
||||||
|
Encryption,
|
||||||
|
#[error("The vault is already bootstrapped")]
|
||||||
|
AlreadyBootstrapped,
|
||||||
|
#[error("Vault error")]
|
||||||
|
Vault,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Passphrases gathered so far, in contribution order.
|
||||||
|
///
|
||||||
|
/// A `Vec` rather than a map because [`SafeCell`] values are neither cloneable
|
||||||
|
/// nor hashable, and a committee holds at most
|
||||||
|
/// [`shamir::MAX_COMMITTEE_SIZE`] of them.
|
||||||
|
#[derive(Default)]
|
||||||
|
struct Contributions(Vec<(OperatorId, SafeCell<Vec<u8>>)>);
|
||||||
|
|
||||||
|
impl Contributions {
|
||||||
|
fn contains(&self, operator_id: OperatorId) -> bool {
|
||||||
|
self.0.iter().any(|(id, _)| *id == operator_id)
|
||||||
|
}
|
||||||
|
|
||||||
|
fn put(&mut self, operator_id: OperatorId, passphrase: SafeCell<Vec<u8>>) {
|
||||||
|
match self.0.iter_mut().find(|(id, _)| *id == operator_id) {
|
||||||
|
Some(slot) => slot.1 = passphrase,
|
||||||
|
None => self.0.push((operator_id, passphrase)),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const fn len(&self) -> usize {
|
||||||
|
self.0.len()
|
||||||
|
}
|
||||||
|
|
||||||
|
fn operators(&self) -> Vec<OperatorId> {
|
||||||
|
self.0.iter().map(|(id, _)| *id).collect()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
enum CoordinatorState {
|
||||||
|
Idle,
|
||||||
|
Bootstrapping {
|
||||||
|
/// The operator that declared the committee. Only they may re-declare
|
||||||
|
/// it, which is the way out of a ceremony the others never finish.
|
||||||
|
declarer: OperatorId,
|
||||||
|
declared_count: usize,
|
||||||
|
contributions: Contributions,
|
||||||
|
retryable: bool,
|
||||||
|
},
|
||||||
|
Unsealing {
|
||||||
|
threshold: usize,
|
||||||
|
contributions: Contributions,
|
||||||
|
retryable: bool,
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Actor)]
|
||||||
|
pub struct VaultCoordinator {
|
||||||
|
db: db::DatabasePool,
|
||||||
|
vault: ActorRef<Vault>,
|
||||||
|
state: CoordinatorState,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl VaultCoordinator {
|
||||||
|
pub const fn new(db: db::DatabasePool, vault: ActorRef<Vault>) -> Self {
|
||||||
|
Self {
|
||||||
|
db,
|
||||||
|
vault,
|
||||||
|
state: CoordinatorState::Idle,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Explain why a committee size was rejected.
|
||||||
|
const fn committee_error(declared_count: usize) -> Error {
|
||||||
|
match declared_count {
|
||||||
|
0 => Error::EmptyCommittee,
|
||||||
|
2 => Error::UnsupportedCommittee,
|
||||||
|
_ => Error::CommitteeTooLarge,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn encrypt_share(
|
||||||
|
passphrase: &mut SafeCell<Vec<u8>>,
|
||||||
|
share: &[u8],
|
||||||
|
) -> Result<EncryptedShare, Error> {
|
||||||
|
let mut salt = [0u8; RECOMMENDED_SALT_LEN];
|
||||||
|
UnwrapErr(SysRng).fill_bytes(&mut salt);
|
||||||
|
|
||||||
|
let nonce = Nonce::default();
|
||||||
|
let ciphertext = derive_key(passphrase, &salt)
|
||||||
|
.encrypt(&nonce, SHARE_AAD, share)
|
||||||
|
.map_err(|_| Error::Encryption)?;
|
||||||
|
|
||||||
|
Ok(EncryptedShare {
|
||||||
|
ciphertext,
|
||||||
|
nonce: nonce.to_vec(),
|
||||||
|
salt: salt.to_vec(),
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
fn decrypt_share(
|
||||||
|
passphrase: &mut SafeCell<Vec<u8>>,
|
||||||
|
share: EncryptedShare,
|
||||||
|
) -> Result<SafeCell<Vec<u8>>, Error> {
|
||||||
|
let nonce = Nonce::try_from(share.nonce.as_slice()).map_err(|()| Error::BrokenDatabase)?;
|
||||||
|
|
||||||
|
let mut buffer = SafeCell::new(share.ciphertext);
|
||||||
|
derive_key(passphrase, &share.salt)
|
||||||
|
.decrypt_in_place(&nonce, SHARE_AAD, &mut buffer)
|
||||||
|
.map_err(|_| Error::InvalidPassphrase)?;
|
||||||
|
|
||||||
|
Ok(buffer)
|
||||||
|
}
|
||||||
|
|
||||||
|
const fn bootstrap_error(error: &SendError<Bootstrap, vault::Error>) -> Error {
|
||||||
|
match error {
|
||||||
|
SendError::HandlerError(vault::Error::AlreadyBootstrapped) => Error::AlreadyBootstrapped,
|
||||||
|
_ => Error::Vault,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Build the custody record and hand it to the vault, which stores it in the
|
||||||
|
/// same transaction as the root key.
|
||||||
|
async fn finalize_bootstrap(
|
||||||
|
vault: &ActorRef<Vault>,
|
||||||
|
contributions: &mut Contributions,
|
||||||
|
) -> Result<(), Error> {
|
||||||
|
let total = contributions.len();
|
||||||
|
let threshold = shamir::shamir_threshold(total).ok_or_else(|| committee_error(total))?;
|
||||||
|
|
||||||
|
let mut seal_key = KeyCell::new_secure_random();
|
||||||
|
let mut shares = shamir::split_key(threshold, total, &mut seal_key, UnwrapErr(SysRng))
|
||||||
|
.map_err(|error| Error::Shamir(error.to_string()))?;
|
||||||
|
|
||||||
|
if shares.len() < total {
|
||||||
|
return Err(Error::Shamir("missing share for operator".to_owned()));
|
||||||
|
}
|
||||||
|
|
||||||
|
let mut encrypted = Vec::with_capacity(total);
|
||||||
|
for ((operator_id, passphrase), share) in contributions.0.iter_mut().zip(shares.iter_mut()) {
|
||||||
|
let share = share.read_inline(|share| encrypt_share(passphrase, share))?;
|
||||||
|
encrypted.push((*operator_id, share));
|
||||||
|
}
|
||||||
|
|
||||||
|
vault
|
||||||
|
.ask(Bootstrap {
|
||||||
|
seal_key,
|
||||||
|
custody: Some(CustodyRecord {
|
||||||
|
threshold,
|
||||||
|
shares: encrypted,
|
||||||
|
}),
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.map_err(|error| bootstrap_error(&error))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Reconstruct the seal key from the contributed passphrases and unseal.
|
||||||
|
async fn finalize_unseal(
|
||||||
|
db: &db::DatabasePool,
|
||||||
|
vault: &ActorRef<Vault>,
|
||||||
|
threshold: usize,
|
||||||
|
contributions: &mut Contributions,
|
||||||
|
) -> Result<(), Error> {
|
||||||
|
let stored = {
|
||||||
|
let mut conn = db.get().await?;
|
||||||
|
custody::shares(&mut conn, &contributions.operators()).await?
|
||||||
|
};
|
||||||
|
|
||||||
|
let mut plaintext = Vec::with_capacity(stored.len());
|
||||||
|
for ((_, passphrase), share) in contributions.0.iter_mut().zip(stored) {
|
||||||
|
plaintext.push(decrypt_share(passphrase, share)?);
|
||||||
|
}
|
||||||
|
|
||||||
|
let seal_key = shamir::combine_shares(threshold, &mut plaintext)
|
||||||
|
.map_err(|error| Error::Shamir(error.to_string()))?;
|
||||||
|
|
||||||
|
vault
|
||||||
|
.ask(TryUnseal { seal_key })
|
||||||
|
.await
|
||||||
|
.map_err(|_| Error::Vault)
|
||||||
|
}
|
||||||
|
|
||||||
|
#[messages]
|
||||||
|
impl VaultCoordinator {
|
||||||
|
/// Announce how many operators will contribute to the bootstrap.
|
||||||
|
///
|
||||||
|
/// The declaring operator may re-declare to restart the ceremony; that is
|
||||||
|
/// the only way to release a committee whose members never all show up.
|
||||||
|
#[message]
|
||||||
|
pub fn start_bootstrap(
|
||||||
|
&mut self,
|
||||||
|
operator_id: OperatorId,
|
||||||
|
declared_count: usize,
|
||||||
|
) -> Result<(), Error> {
|
||||||
|
if shamir::shamir_threshold(declared_count).is_none() {
|
||||||
|
return Err(committee_error(declared_count));
|
||||||
|
}
|
||||||
|
|
||||||
|
match &self.state {
|
||||||
|
CoordinatorState::Unsealing { .. } => return Err(Error::AlreadyUnsealing),
|
||||||
|
CoordinatorState::Bootstrapping { declarer, .. } if *declarer != operator_id => {
|
||||||
|
return Err(Error::AlreadyBootstrapping);
|
||||||
|
}
|
||||||
|
CoordinatorState::Bootstrapping { .. } | CoordinatorState::Idle => {}
|
||||||
|
}
|
||||||
|
|
||||||
|
self.state = CoordinatorState::Bootstrapping {
|
||||||
|
declarer: operator_id,
|
||||||
|
declared_count,
|
||||||
|
contributions: Contributions::default(),
|
||||||
|
retryable: false,
|
||||||
|
};
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
#[message]
|
||||||
|
pub async fn contribute_bootstrap(
|
||||||
|
&mut self,
|
||||||
|
operator_id: OperatorId,
|
||||||
|
passphrase: SafeCell<Vec<u8>>,
|
||||||
|
) -> Result<bool, Error> {
|
||||||
|
let CoordinatorState::Bootstrapping {
|
||||||
|
declared_count,
|
||||||
|
contributions,
|
||||||
|
retryable,
|
||||||
|
..
|
||||||
|
} = &mut self.state
|
||||||
|
else {
|
||||||
|
return Err(Error::NotBootstrapping);
|
||||||
|
};
|
||||||
|
|
||||||
|
if contributions.contains(operator_id) && !*retryable {
|
||||||
|
return Err(Error::DuplicateContribution);
|
||||||
|
}
|
||||||
|
contributions.put(operator_id, passphrase);
|
||||||
|
*retryable = false;
|
||||||
|
|
||||||
|
if contributions.len() < *declared_count {
|
||||||
|
return Ok(false);
|
||||||
|
}
|
||||||
|
|
||||||
|
let state = std::mem::replace(&mut self.state, CoordinatorState::Idle);
|
||||||
|
let CoordinatorState::Bootstrapping {
|
||||||
|
declarer,
|
||||||
|
declared_count,
|
||||||
|
mut contributions,
|
||||||
|
..
|
||||||
|
} = state
|
||||||
|
else {
|
||||||
|
unreachable!("state was matched as Bootstrapping above")
|
||||||
|
};
|
||||||
|
|
||||||
|
match finalize_bootstrap(&self.vault, &mut contributions).await {
|
||||||
|
Ok(()) => Ok(true),
|
||||||
|
Err(error) => {
|
||||||
|
self.state = CoordinatorState::Bootstrapping {
|
||||||
|
declarer,
|
||||||
|
declared_count,
|
||||||
|
contributions,
|
||||||
|
retryable: true,
|
||||||
|
};
|
||||||
|
Err(error)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[message]
|
||||||
|
pub async fn contribute_unseal(
|
||||||
|
&mut self,
|
||||||
|
operator_id: OperatorId,
|
||||||
|
passphrase: SafeCell<Vec<u8>>,
|
||||||
|
) -> Result<bool, Error> {
|
||||||
|
if matches!(self.state, CoordinatorState::Idle) {
|
||||||
|
let threshold = {
|
||||||
|
let mut conn = self.db.get().await?;
|
||||||
|
custody::threshold(&mut conn).await?
|
||||||
|
};
|
||||||
|
self.state = CoordinatorState::Unsealing {
|
||||||
|
threshold,
|
||||||
|
contributions: Contributions::default(),
|
||||||
|
retryable: false,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
let CoordinatorState::Unsealing {
|
||||||
|
threshold,
|
||||||
|
contributions,
|
||||||
|
retryable,
|
||||||
|
} = &mut self.state
|
||||||
|
else {
|
||||||
|
return Err(Error::AlreadyBootstrapping);
|
||||||
|
};
|
||||||
|
|
||||||
|
if contributions.contains(operator_id) && !*retryable {
|
||||||
|
return Err(Error::DuplicateContribution);
|
||||||
|
}
|
||||||
|
contributions.put(operator_id, passphrase);
|
||||||
|
*retryable = false;
|
||||||
|
|
||||||
|
if contributions.len() < *threshold {
|
||||||
|
return Ok(false);
|
||||||
|
}
|
||||||
|
|
||||||
|
let state = std::mem::replace(&mut self.state, CoordinatorState::Idle);
|
||||||
|
let CoordinatorState::Unsealing {
|
||||||
|
threshold,
|
||||||
|
mut contributions,
|
||||||
|
..
|
||||||
|
} = state
|
||||||
|
else {
|
||||||
|
unreachable!("state was matched as Unsealing above")
|
||||||
|
};
|
||||||
|
|
||||||
|
match finalize_unseal(&self.db, &self.vault, threshold, &mut contributions).await {
|
||||||
|
Ok(()) => Ok(true),
|
||||||
|
Err(error) => {
|
||||||
|
self.state = CoordinatorState::Unsealing {
|
||||||
|
threshold,
|
||||||
|
contributions,
|
||||||
|
retryable: true,
|
||||||
|
};
|
||||||
|
Err(error)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -61,12 +61,11 @@ mod tests {
|
|||||||
#[test]
|
#[test]
|
||||||
fn derive_seal_key_deterministic() {
|
fn derive_seal_key_deterministic() {
|
||||||
static PASSWORD: &[u8] = b"password";
|
static PASSWORD: &[u8] = b"password";
|
||||||
let password = SafeCell::new(PASSWORD.to_vec());
|
let mut password = SafeCell::new(PASSWORD.to_vec());
|
||||||
let password2 = SafeCell::new(PASSWORD.to_vec());
|
|
||||||
let salt = generate_salt();
|
let salt = generate_salt();
|
||||||
|
|
||||||
let mut key1 = derive_key(password, &salt);
|
let mut key1 = derive_key(&mut password, &salt);
|
||||||
let mut key2 = derive_key(password2, &salt);
|
let mut key2 = derive_key(&mut password, &salt);
|
||||||
|
|
||||||
let key1_reader = key1.0.read();
|
let key1_reader = key1.0.read();
|
||||||
let key2_reader = key2.0.read();
|
let key2_reader = key2.0.read();
|
||||||
@@ -77,10 +76,10 @@ mod tests {
|
|||||||
#[test]
|
#[test]
|
||||||
fn successful_derive() {
|
fn successful_derive() {
|
||||||
static PASSWORD: &[u8] = b"password";
|
static PASSWORD: &[u8] = b"password";
|
||||||
let password = SafeCell::new(PASSWORD.to_vec());
|
let mut password = SafeCell::new(PASSWORD.to_vec());
|
||||||
let salt = generate_salt();
|
let salt = generate_salt();
|
||||||
|
|
||||||
let mut key = derive_key(password, &salt);
|
let mut key = derive_key(&mut password, &salt);
|
||||||
let key_reader = key.0.read();
|
let key_reader = key.0.read();
|
||||||
|
|
||||||
assert_ne!(key_reader.as_slice(), &[0u8; 32][..]);
|
assert_ne!(key_reader.as_slice(), &[0u8; 32][..]);
|
||||||
|
|||||||
@@ -192,7 +192,9 @@ pub async fn verify_entity<E: Integrable>(
|
|||||||
Ok(false) => Err(Error::MacMismatch {
|
Ok(false) => Err(Error::MacMismatch {
|
||||||
entity_kind: E::KIND,
|
entity_kind: E::KIND,
|
||||||
}),
|
}),
|
||||||
Err(SendError::HandlerError(vault::Error::Sealed)) => Ok(AttestationStatus::Unavailable),
|
Err(SendError::HandlerError(
|
||||||
|
vault::Error::Sealed | vault::Error::KeyVersionMismatch { .. },
|
||||||
|
)) => Ok(AttestationStatus::Unavailable),
|
||||||
Err(_) => Err(Error::VaultSend),
|
Err(_) => Err(Error::VaultSend),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -213,9 +215,9 @@ mod tests {
|
|||||||
GlobalActors,
|
GlobalActors,
|
||||||
vault::{Bootstrap, Vault},
|
vault::{Bootstrap, Vault},
|
||||||
},
|
},
|
||||||
|
crypto::KeyCell,
|
||||||
db::{self, schema},
|
db::{self, schema},
|
||||||
};
|
};
|
||||||
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
|
||||||
|
|
||||||
use super::{Error, Integrable, sign_entity, verify_entity};
|
use super::{Error, Integrable, sign_entity, verify_entity};
|
||||||
#[derive(Clone, arbiter_macros::Hashable)]
|
#[derive(Clone, arbiter_macros::Hashable)]
|
||||||
@@ -235,7 +237,8 @@ mod tests {
|
|||||||
);
|
);
|
||||||
actor
|
actor
|
||||||
.ask(Bootstrap {
|
.ask(Bootstrap {
|
||||||
seal_key_raw: SafeCell::new(b"integrity-test-seal-key".to_vec()),
|
seal_key: KeyCell::from([0u8; 32]),
|
||||||
|
custody: None,
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
@@ -331,4 +334,47 @@ mod tests {
|
|||||||
.unwrap_err();
|
.unwrap_err();
|
||||||
assert!(matches!(err, Error::MacMismatch { .. }));
|
assert!(matches!(err, Error::MacMismatch { .. }));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn key_version_mismatch_returns_unavailable_not_mac_mismatch() {
|
||||||
|
use crate::db::schema::integrity_envelope;
|
||||||
|
use super::AttestationStatus;
|
||||||
|
|
||||||
|
const ENTITY_ID: &[u8] = b"entity-id-rotation-test";
|
||||||
|
|
||||||
|
let db = db::create_test_pool().await;
|
||||||
|
let vault = bootstrapped_vault(&db).await;
|
||||||
|
let mut conn = db.get().await.unwrap();
|
||||||
|
|
||||||
|
let entity = DummyEntity {
|
||||||
|
payload_version: 1,
|
||||||
|
payload: b"payload-v1".to_vec(),
|
||||||
|
};
|
||||||
|
|
||||||
|
sign_entity(&mut conn, &vault, &entity, ENTITY_ID)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
// Simulate key rotation: update the stored key_version to a stale value.
|
||||||
|
// After real rotation the vault's root_key_history_id would advance, but
|
||||||
|
// here we achieve the same mismatch by back-dating the envelope's key_version.
|
||||||
|
diesel::update(integrity_envelope::table)
|
||||||
|
.filter(integrity_envelope::entity_kind.eq("dummy_entity"))
|
||||||
|
.filter(integrity_envelope::entity_id.eq(ENTITY_ID))
|
||||||
|
.set(integrity_envelope::key_version.eq(0))
|
||||||
|
.execute(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
// Must NOT error — version mismatch is Unavailable, not tampered.
|
||||||
|
let status = verify_entity(&mut conn, &vault, &entity, ENTITY_ID)
|
||||||
|
.await
|
||||||
|
.expect("key version mismatch must not be treated as an error");
|
||||||
|
|
||||||
|
assert_eq!(
|
||||||
|
status,
|
||||||
|
AttestationStatus::Unavailable,
|
||||||
|
"stale key_version must yield Unavailable, not MacMismatch"
|
||||||
|
);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
||||||
use encryption::v1::{Nonce, Salt};
|
use encryption::v1::Nonce;
|
||||||
|
|
||||||
use argon2::{Algorithm, Argon2};
|
use argon2::{Algorithm, Argon2};
|
||||||
use chacha20poly1305::{
|
use chacha20poly1305::{
|
||||||
@@ -13,6 +13,7 @@ use rand::{
|
|||||||
|
|
||||||
pub mod encryption;
|
pub mod encryption;
|
||||||
pub mod integrity;
|
pub mod integrity;
|
||||||
|
pub mod shamir;
|
||||||
|
|
||||||
pub struct KeyCell(pub SafeCell<Key>);
|
pub struct KeyCell(pub SafeCell<Key>);
|
||||||
impl From<SafeCell<Key>> for KeyCell {
|
impl From<SafeCell<Key>> for KeyCell {
|
||||||
@@ -20,6 +21,16 @@ impl From<SafeCell<Key>> for KeyCell {
|
|||||||
Self(value)
|
Self(value)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
impl From<[u8; 32]> for KeyCell {
|
||||||
|
fn from(bytes: [u8; 32]) -> Self {
|
||||||
|
let cell = SafeCell::new_inline(|key: &mut Key| {
|
||||||
|
key.copy_from_slice(&bytes);
|
||||||
|
});
|
||||||
|
Self(cell)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
impl TryFrom<SafeCell<Vec<u8>>> for KeyCell {
|
impl TryFrom<SafeCell<Vec<u8>>> for KeyCell {
|
||||||
type Error = ();
|
type Error = ();
|
||||||
|
|
||||||
@@ -58,6 +69,7 @@ impl KeyCell {
|
|||||||
let buffer = buffer.as_mut();
|
let buffer = buffer.as_mut();
|
||||||
cipher.encrypt_in_place(nonce, associated_data, buffer)
|
cipher.encrypt_in_place(nonce, associated_data, buffer)
|
||||||
}
|
}
|
||||||
|
|
||||||
pub fn decrypt_in_place(
|
pub fn decrypt_in_place(
|
||||||
&mut self,
|
&mut self,
|
||||||
nonce: &Nonce,
|
nonce: &Nonce,
|
||||||
@@ -93,8 +105,11 @@ impl KeyCell {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Derive a fixed-length key from the password using Argon2id, which is designed for password hashing and key derivation.
|
/// Derive a fixed-length key from a passphrase using Argon2id.
|
||||||
pub fn derive_key(mut password: SafeCell<Vec<u8>>, salt: &Salt) -> KeyCell {
|
///
|
||||||
|
/// The passphrase is borrowed so that callers can keep it in protected memory
|
||||||
|
/// and reuse it across retries instead of handing over a copy.
|
||||||
|
pub fn derive_key(password: &mut SafeCell<Vec<u8>>, salt: &[u8]) -> KeyCell {
|
||||||
let params = {
|
let params = {
|
||||||
#[cfg(debug_assertions)]
|
#[cfg(debug_assertions)]
|
||||||
{
|
{
|
||||||
@@ -132,11 +147,11 @@ mod tests {
|
|||||||
#[test]
|
#[test]
|
||||||
fn encrypt_decrypt() {
|
fn encrypt_decrypt() {
|
||||||
static PASSWORD: &[u8] = b"password";
|
static PASSWORD: &[u8] = b"password";
|
||||||
let password = SafeCell::new(PASSWORD.to_vec());
|
let mut password = SafeCell::new(PASSWORD.to_vec());
|
||||||
let salt = generate_salt();
|
let salt = generate_salt();
|
||||||
|
|
||||||
let mut key = derive_key(password, &salt);
|
let mut key = derive_key(&mut password, &salt);
|
||||||
let nonce = Nonce(*b"unique nonce 123 1231233"); // 24 bytes for XChaCha20Poly1305
|
let nonce = Nonce(*b"unique nonce 123 1231233");
|
||||||
let associated_data = b"associated data";
|
let associated_data = b"associated data";
|
||||||
let mut buffer = b"secret data".to_vec();
|
let mut buffer = b"secret data".to_vec();
|
||||||
|
|
||||||
|
|||||||
221
server/crates/arbiter-server/src/crypto/shamir.rs
Normal file
221
server/crates/arbiter-server/src/crypto/shamir.rs
Normal file
@@ -0,0 +1,221 @@
|
|||||||
|
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
||||||
|
use rand_core::CryptoRng;
|
||||||
|
use vsss_rs::Gf256;
|
||||||
|
|
||||||
|
use crate::crypto::KeyCell;
|
||||||
|
|
||||||
|
/// GF(256) addresses shares by a non-zero byte, so no committee can exceed 255.
|
||||||
|
pub const MAX_COMMITTEE_SIZE: usize = 255;
|
||||||
|
|
||||||
|
/// Errors returned by Shamir split/combine operations.
|
||||||
|
#[derive(Debug, thiserror::Error)]
|
||||||
|
pub enum ShamirError {
|
||||||
|
#[error("failed to split key: {0}")]
|
||||||
|
Split(String),
|
||||||
|
#[error("failed to combine shares: {0}")]
|
||||||
|
Combine(String),
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Return the required threshold for a Shamir share pool of `committee_size`.
|
||||||
|
///
|
||||||
|
/// A pool of two is rejected: a majority of two is two, which gives each holder
|
||||||
|
/// a veto over every unseal without giving either one recovery. That rejects no
|
||||||
|
/// supported committee, because a two-operator vault must carry at least one
|
||||||
|
/// recovery share and so never splits into a pool of two -- see
|
||||||
|
/// `docs/ARCHITECTURE.md` 3.9.
|
||||||
|
#[expect(
|
||||||
|
clippy::integer_division,
|
||||||
|
reason = "majority thresholds use integer arithmetic"
|
||||||
|
)]
|
||||||
|
#[must_use]
|
||||||
|
pub const fn shamir_threshold(committee_size: usize) -> Option<usize> {
|
||||||
|
match committee_size {
|
||||||
|
0 | 2 => None,
|
||||||
|
size if size > MAX_COMMITTEE_SIZE => None,
|
||||||
|
1 => Some(1),
|
||||||
|
size => Some(size / 2 + 1),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Split a seal key into `total` shares, `threshold` of which reconstruct it.
|
||||||
|
pub fn split_key(
|
||||||
|
threshold: usize,
|
||||||
|
total: usize,
|
||||||
|
key: &mut KeyCell,
|
||||||
|
rng: impl CryptoRng,
|
||||||
|
) -> Result<Vec<SafeCell<Vec<u8>>>, ShamirError> {
|
||||||
|
if total == 0 || threshold == 0 || threshold > total || total == 2 || total > MAX_COMMITTEE_SIZE
|
||||||
|
{
|
||||||
|
return Err(ShamirError::Split(
|
||||||
|
"unsupported committee parameters".to_owned(),
|
||||||
|
));
|
||||||
|
}
|
||||||
|
|
||||||
|
// Nothing to interpolate when one share suffices.
|
||||||
|
if threshold == 1 {
|
||||||
|
return Ok(key.0.read_inline(|key| {
|
||||||
|
std::iter::repeat_with(|| SafeCell::new(key.as_slice().to_vec()))
|
||||||
|
.take(total)
|
||||||
|
.collect()
|
||||||
|
}));
|
||||||
|
}
|
||||||
|
|
||||||
|
key.0.read_inline(|key| {
|
||||||
|
let key: &[u8; 32] = key
|
||||||
|
.as_slice()
|
||||||
|
.try_into()
|
||||||
|
.map_err(|_| ShamirError::Split("unexpected seal key length".to_owned()))?;
|
||||||
|
|
||||||
|
Gf256::split_array(threshold, total, key, rng)
|
||||||
|
.map(|shares| shares.into_iter().map(SafeCell::new).collect())
|
||||||
|
.map_err(|error| ShamirError::Split(format!("{error:?}")))
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Combine shares back into the seal key.
|
||||||
|
///
|
||||||
|
/// `threshold` comes from storage rather than from the shapes of the shares:
|
||||||
|
/// a one-of-one committee stores the key verbatim, and telling that apart by
|
||||||
|
/// share length alone would misread any Shamir share that happened to be key
|
||||||
|
/// sized.
|
||||||
|
pub fn combine_shares(
|
||||||
|
threshold: usize,
|
||||||
|
shares: &mut [SafeCell<Vec<u8>>],
|
||||||
|
) -> Result<KeyCell, ShamirError> {
|
||||||
|
if threshold == 0 {
|
||||||
|
return Err(ShamirError::Combine("threshold is zero".to_owned()));
|
||||||
|
}
|
||||||
|
if shares.len() < threshold {
|
||||||
|
return Err(ShamirError::Combine(
|
||||||
|
"not enough shares supplied".to_owned(),
|
||||||
|
));
|
||||||
|
}
|
||||||
|
|
||||||
|
// Mirror of the one-of-one case in [`split_key`]: the share is the key.
|
||||||
|
if threshold == 1 {
|
||||||
|
let share = shares
|
||||||
|
.first_mut()
|
||||||
|
.ok_or_else(|| ShamirError::Combine("no shares supplied".to_owned()))?;
|
||||||
|
return reconstructed_key(share.read_inline(|share| SafeCell::new(share.clone())));
|
||||||
|
}
|
||||||
|
|
||||||
|
let mut gathered = SafeCell::new(Vec::with_capacity(shares.len()));
|
||||||
|
for share in shares.iter_mut() {
|
||||||
|
share.read_inline(|share| {
|
||||||
|
gathered.write_inline(|gathered| gathered.push(share.clone()));
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
let combined = gathered.read_inline(|gathered| {
|
||||||
|
Gf256::combine_array(gathered.as_slice())
|
||||||
|
.map(SafeCell::new)
|
||||||
|
.map_err(|error| ShamirError::Combine(format!("{error:?}")))
|
||||||
|
})?;
|
||||||
|
|
||||||
|
reconstructed_key(combined)
|
||||||
|
}
|
||||||
|
|
||||||
|
fn reconstructed_key(bytes: SafeCell<Vec<u8>>) -> Result<KeyCell, ShamirError> {
|
||||||
|
KeyCell::try_from(bytes)
|
||||||
|
.map_err(|()| ShamirError::Combine("unexpected reconstructed key length".to_owned()))
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::{MAX_COMMITTEE_SIZE, combine_shares, shamir_threshold, split_key};
|
||||||
|
use crate::crypto::KeyCell;
|
||||||
|
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
||||||
|
use rand::rngs::SysRng;
|
||||||
|
use rand_core::UnwrapErr;
|
||||||
|
use rstest::rstest;
|
||||||
|
|
||||||
|
fn key_bytes(mut key: KeyCell) -> [u8; 32] {
|
||||||
|
key.0.read_inline(|key| {
|
||||||
|
let mut bytes = [0u8; 32];
|
||||||
|
bytes.copy_from_slice(key.as_slice());
|
||||||
|
bytes
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
fn select(shares: &mut [SafeCell<Vec<u8>>], indexes: &[usize]) -> Vec<SafeCell<Vec<u8>>> {
|
||||||
|
indexes
|
||||||
|
.iter()
|
||||||
|
.filter_map(|index| {
|
||||||
|
shares
|
||||||
|
.get_mut(*index)
|
||||||
|
.map(|share| share.read_inline(|share| SafeCell::new(share.clone())))
|
||||||
|
})
|
||||||
|
.collect()
|
||||||
|
}
|
||||||
|
|
||||||
|
#[rstest]
|
||||||
|
#[case(&[0, 1])]
|
||||||
|
#[case(&[0, 2])]
|
||||||
|
#[case(&[1, 2])]
|
||||||
|
fn threshold_shares_reconstruct_fixed_key(#[case] indexes: &[usize]) {
|
||||||
|
let expected = [9_u8; 32];
|
||||||
|
let mut key = KeyCell::from(expected);
|
||||||
|
let rng = UnwrapErr(SysRng);
|
||||||
|
let mut shares = split_key(2, 3, &mut key, rng).expect("split should succeed");
|
||||||
|
let mut selected = select(&mut shares, indexes);
|
||||||
|
let combined = combine_shares(2, &mut selected).expect("combine should succeed");
|
||||||
|
assert_eq!(key_bytes(combined), expected);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn one_of_one_round_trips_a_fixed_size_key() {
|
||||||
|
let expected = [7_u8; 32];
|
||||||
|
let mut key = KeyCell::from(expected);
|
||||||
|
let rng = UnwrapErr(SysRng);
|
||||||
|
let mut shares = split_key(1, 1, &mut key, rng).expect("split should succeed");
|
||||||
|
let combined = combine_shares(1, &mut shares).expect("combine should succeed");
|
||||||
|
assert_eq!(key_bytes(combined), expected);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn fewer_shares_than_threshold_is_rejected() {
|
||||||
|
let mut key = KeyCell::from([3_u8; 32]);
|
||||||
|
let rng = UnwrapErr(SysRng);
|
||||||
|
let mut shares = split_key(3, 5, &mut key, rng).expect("split should succeed");
|
||||||
|
let mut selected = select(&mut shares, &[0, 1]);
|
||||||
|
assert!(
|
||||||
|
combine_shares(3, &mut selected).is_err(),
|
||||||
|
"two of three shares must not reconstruct the key"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[rstest]
|
||||||
|
#[case(0, None)]
|
||||||
|
#[case(1, Some(1))]
|
||||||
|
#[case(2, None)]
|
||||||
|
#[case(3, Some(2))]
|
||||||
|
#[case(4, Some(3))]
|
||||||
|
#[case(MAX_COMMITTEE_SIZE, Some(128))]
|
||||||
|
#[case(MAX_COMMITTEE_SIZE + 1, None)]
|
||||||
|
fn committee_threshold_is_a_majority(
|
||||||
|
#[case] committee_size: usize,
|
||||||
|
#[case] expected: Option<usize>,
|
||||||
|
) {
|
||||||
|
assert_eq!(shamir_threshold(committee_size), expected);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn oversized_committee_is_rejected_by_split() {
|
||||||
|
let mut key = KeyCell::from([1_u8; 32]);
|
||||||
|
let rng = UnwrapErr(SysRng);
|
||||||
|
assert!(
|
||||||
|
split_key(129, MAX_COMMITTEE_SIZE + 1, &mut key, rng).is_err(),
|
||||||
|
"committees above the GF(256) share limit must be rejected"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn two_operator_committee_is_explicitly_unsupported() {
|
||||||
|
let mut key = KeyCell::from([7_u8; 32]);
|
||||||
|
let rng = UnwrapErr(SysRng);
|
||||||
|
assert!(
|
||||||
|
split_key(2, 2, &mut key, rng).is_err(),
|
||||||
|
"two-operator committees must be rejected"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
137
server/crates/arbiter-server/src/db/custody.rs
Normal file
137
server/crates/arbiter-server/src/db/custody.rs
Normal file
@@ -0,0 +1,137 @@
|
|||||||
|
//! Storage for Shamir custody material: the reconstruction threshold and the
|
||||||
|
//! per-operator encrypted shares of the vault seal key.
|
||||||
|
//!
|
||||||
|
//! The queries live here so that the actors above hold no Diesel code of their
|
||||||
|
//! own. Every one of them borrows the caller's connection instead of taking one
|
||||||
|
//! from the pool, which is what lets the vault write custody material inside
|
||||||
|
//! the same transaction that stores the root key.
|
||||||
|
|
||||||
|
use std::collections::HashMap;
|
||||||
|
|
||||||
|
use diesel::{ExpressionMethods as _, QueryDsl};
|
||||||
|
use diesel_async::RunQueryDsl;
|
||||||
|
|
||||||
|
use crate::db::{
|
||||||
|
self,
|
||||||
|
models::{OperatorId, SqliteTimestamp},
|
||||||
|
schema,
|
||||||
|
};
|
||||||
|
|
||||||
|
/// One Shamir share, encrypted under a key derived from its operator's passphrase.
|
||||||
|
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||||
|
pub struct EncryptedShare {
|
||||||
|
pub ciphertext: Vec<u8>,
|
||||||
|
pub nonce: Vec<u8>,
|
||||||
|
pub salt: Vec<u8>,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Everything a bootstrap persists about custody, written as a single unit.
|
||||||
|
#[derive(Debug)]
|
||||||
|
pub struct CustodyRecord {
|
||||||
|
pub threshold: usize,
|
||||||
|
pub shares: Vec<(OperatorId, EncryptedShare)>,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, thiserror::Error)]
|
||||||
|
pub enum Error {
|
||||||
|
#[error("Database query error: {0}")]
|
||||||
|
Query(#[from] diesel::result::Error),
|
||||||
|
#[error("Stored committee threshold is missing or out of range")]
|
||||||
|
BrokenThreshold,
|
||||||
|
#[error("Custody settings row is missing")]
|
||||||
|
MissingSettings,
|
||||||
|
#[error("No share stored for operator {0:?}")]
|
||||||
|
MissingShare(OperatorId),
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Persist threshold and shares on the caller's connection, joining any
|
||||||
|
/// transaction the caller has already opened.
|
||||||
|
pub async fn write_record(
|
||||||
|
conn: &mut db::DatabaseConnection,
|
||||||
|
record: &CustodyRecord,
|
||||||
|
) -> Result<(), Error> {
|
||||||
|
let threshold = i32::try_from(record.threshold).map_err(|_| Error::BrokenThreshold)?;
|
||||||
|
|
||||||
|
// SQLite has no batch form for REPLACE INTO in diesel, so the rows go
|
||||||
|
// in one at a time. The caller's transaction still makes them atomic.
|
||||||
|
let now = SqliteTimestamp::now();
|
||||||
|
for (operator_id, share) in &record.shares {
|
||||||
|
diesel::replace_into(schema::operator::table)
|
||||||
|
.values((
|
||||||
|
schema::operator::id.eq(Some(*operator_id)),
|
||||||
|
schema::operator::share.eq(&share.ciphertext),
|
||||||
|
schema::operator::share_nonce.eq(&share.nonce),
|
||||||
|
schema::operator::share_salt.eq(&share.salt),
|
||||||
|
schema::operator::created_at.eq(now.clone()),
|
||||||
|
schema::operator::updated_at.eq(now.clone()),
|
||||||
|
))
|
||||||
|
.execute(&mut *conn)
|
||||||
|
.await?;
|
||||||
|
}
|
||||||
|
|
||||||
|
let updated = diesel::update(schema::arbiter_settings::table)
|
||||||
|
.set(schema::arbiter_settings::shamir_threshold.eq(Some(threshold)))
|
||||||
|
.execute(&mut *conn)
|
||||||
|
.await?;
|
||||||
|
if updated != 1 {
|
||||||
|
return Err(Error::MissingSettings);
|
||||||
|
}
|
||||||
|
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Number of shares required to reconstruct the seal key.
|
||||||
|
pub async fn threshold(conn: &mut db::DatabaseConnection) -> Result<usize, Error> {
|
||||||
|
let stored: Option<i32> = schema::arbiter_settings::table
|
||||||
|
.select(schema::arbiter_settings::shamir_threshold)
|
||||||
|
.first(conn)
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
stored
|
||||||
|
.and_then(|value| usize::try_from(value).ok())
|
||||||
|
.filter(|threshold| *threshold > 0)
|
||||||
|
.ok_or(Error::BrokenThreshold)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Load the shares of `operators` in one query, in the order requested.
|
||||||
|
pub async fn shares(
|
||||||
|
conn: &mut db::DatabaseConnection,
|
||||||
|
operators: &[OperatorId],
|
||||||
|
) -> Result<Vec<EncryptedShare>, Error> {
|
||||||
|
/// (id, then the three columns that make up [`EncryptedShare`])
|
||||||
|
type ShareRow = (Option<OperatorId>, Vec<u8>, Vec<u8>, Vec<u8>);
|
||||||
|
|
||||||
|
let wanted: Vec<Option<OperatorId>> = operators.iter().copied().map(Some).collect();
|
||||||
|
|
||||||
|
let rows: Vec<ShareRow> = schema::operator::table
|
||||||
|
.filter(schema::operator::id.eq_any(wanted))
|
||||||
|
.select((
|
||||||
|
schema::operator::id,
|
||||||
|
schema::operator::share,
|
||||||
|
schema::operator::share_nonce,
|
||||||
|
schema::operator::share_salt,
|
||||||
|
))
|
||||||
|
.load(conn)
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
let mut found: HashMap<OperatorId, EncryptedShare> = rows
|
||||||
|
.into_iter()
|
||||||
|
.filter_map(|(id, ciphertext, nonce, salt)| {
|
||||||
|
id.map(|id| {
|
||||||
|
(
|
||||||
|
id,
|
||||||
|
EncryptedShare {
|
||||||
|
ciphertext,
|
||||||
|
nonce,
|
||||||
|
salt,
|
||||||
|
},
|
||||||
|
)
|
||||||
|
})
|
||||||
|
})
|
||||||
|
.collect();
|
||||||
|
|
||||||
|
operators
|
||||||
|
.iter()
|
||||||
|
.map(|id| found.remove(id).ok_or(Error::MissingShare(*id)))
|
||||||
|
.collect()
|
||||||
|
}
|
||||||
@@ -8,6 +8,7 @@ use diesel_migrations::{EmbeddedMigrations, MigrationHarness, embed_migrations};
|
|||||||
use thiserror::Error;
|
use thiserror::Error;
|
||||||
use tracing::info;
|
use tracing::info;
|
||||||
|
|
||||||
|
pub mod custody;
|
||||||
pub mod models;
|
pub mod models;
|
||||||
pub mod schema;
|
pub mod schema;
|
||||||
|
|
||||||
@@ -154,3 +155,39 @@ pub async fn create_test_pool() -> DatabasePool {
|
|||||||
.await
|
.await
|
||||||
.expect("Failed to create test database pool")
|
.expect("Failed to create test database pool")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use diesel::{ExpressionMethods as _, result::DatabaseErrorKind};
|
||||||
|
use diesel_async::RunQueryDsl as _;
|
||||||
|
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn operator_share_salt_must_be_supplied_by_application() {
|
||||||
|
let pool = create_test_pool().await;
|
||||||
|
let mut conn = pool.get().await.expect("pool connection");
|
||||||
|
|
||||||
|
let operator_id = diesel::insert_into(schema::operator_identity::table)
|
||||||
|
.values(schema::operator_identity::public_key.eq(vec![1]))
|
||||||
|
.returning(schema::operator_identity::id)
|
||||||
|
.get_result::<i32>(&mut conn)
|
||||||
|
.await
|
||||||
|
.expect("insert operator identity");
|
||||||
|
|
||||||
|
let error = diesel::insert_into(schema::operator::table)
|
||||||
|
.values((
|
||||||
|
schema::operator::id.eq(operator_id),
|
||||||
|
schema::operator::share.eq(vec![2]),
|
||||||
|
schema::operator::share_nonce.eq(vec![3]),
|
||||||
|
))
|
||||||
|
.execute(&mut conn)
|
||||||
|
.await
|
||||||
|
.expect_err("operator insert without an application-generated salt must fail");
|
||||||
|
|
||||||
|
assert!(matches!(
|
||||||
|
error,
|
||||||
|
diesel::result::Error::DatabaseError(DatabaseErrorKind::NotNullViolation, _)
|
||||||
|
));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -110,6 +110,18 @@ pub mod types {
|
|||||||
ToSql::<Integer, Sqlite>::to_sql(&self.0, out)
|
ToSql::<Integer, Sqlite>::to_sql(&self.0, out)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
impl arbiter_crypto::hashing::Hashable for $name {
|
||||||
|
fn hash<H: arbiter_crypto::hashing::Digest>(&self, hasher: &mut H) {
|
||||||
|
arbiter_crypto::hashing::Hashable::hash(&self.0, hasher);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
impl crate::crypto::integrity::v1::IntoId for $name {
|
||||||
|
fn into_id(self) -> Vec<u8> {
|
||||||
|
crate::crypto::integrity::v1::IntoId::into_id(self.0)
|
||||||
|
}
|
||||||
|
}
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -203,6 +215,7 @@ pub struct ArbiterSettings {
|
|||||||
pub id: i32,
|
pub id: i32,
|
||||||
pub root_key_id: Option<i32>, // references root_key_history.id
|
pub root_key_id: Option<i32>, // references root_key_history.id
|
||||||
pub tls_id: Option<i32>, // references tls_history.id
|
pub tls_id: Option<i32>, // references tls_history.id
|
||||||
|
pub shamir_threshold: Option<i32>,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Models, Queryable, Debug, Insertable, Selectable)]
|
#[derive(Models, Queryable, Debug, Insertable, Selectable)]
|
||||||
@@ -285,6 +298,7 @@ pub struct Operator {
|
|||||||
pub id: OperatorId,
|
pub id: OperatorId,
|
||||||
pub share: Vec<u8>,
|
pub share: Vec<u8>,
|
||||||
pub share_nonce: Vec<u8>,
|
pub share_nonce: Vec<u8>,
|
||||||
|
pub share_salt: Vec<u8>,
|
||||||
pub created_at: SqliteTimestamp,
|
pub created_at: SqliteTimestamp,
|
||||||
pub updated_at: SqliteTimestamp,
|
pub updated_at: SqliteTimestamp,
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -17,6 +17,7 @@ diesel::table! {
|
|||||||
id -> Integer,
|
id -> Integer,
|
||||||
root_key_id -> Nullable<Integer>,
|
root_key_id -> Nullable<Integer>,
|
||||||
tls_id -> Nullable<Integer>,
|
tls_id -> Nullable<Integer>,
|
||||||
|
shamir_threshold -> Nullable<Integer>,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -157,6 +158,7 @@ diesel::table! {
|
|||||||
id -> Nullable<Integer>,
|
id -> Nullable<Integer>,
|
||||||
share -> Binary,
|
share -> Binary,
|
||||||
share_nonce -> Binary,
|
share_nonce -> Binary,
|
||||||
|
share_salt -> Binary,
|
||||||
created_at -> Integer,
|
created_at -> Integer,
|
||||||
updated_at -> Integer,
|
updated_at -> Integer,
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,28 +1,34 @@
|
|||||||
|
use diesel_async::{AsyncConnection, RunQueryDsl};
|
||||||
|
use kameo::actor::ActorRef;
|
||||||
|
|
||||||
use crate::{
|
use crate::{
|
||||||
actors::vault::Vault,
|
actors::vault::Vault,
|
||||||
crypto::integrity,
|
crypto::integrity,
|
||||||
db::{
|
db::{
|
||||||
self, DatabaseError,
|
self, DatabaseError,
|
||||||
models::{
|
models::{
|
||||||
EvmBasicGrant, EvmWalletAccess, NewEvmBasicGrant, NewEvmTransactionLog, SqliteTimestamp,
|
EvmBasicGrant, EvmEtherTransferGrant, EvmEtherTransferGrantTarget,
|
||||||
|
EvmEtherTransferLimit, EvmTokenTransferGrant, EvmTokenTransferVolumeLimit,
|
||||||
|
EvmWalletAccess, NewEvmBasicGrant, NewEvmTransactionLog, SqliteTimestamp,
|
||||||
},
|
},
|
||||||
schema::{self, evm_transaction_log},
|
schema::{self, evm_transaction_log},
|
||||||
},
|
},
|
||||||
evm::policies::{
|
evm::policies::{
|
||||||
CombinedSettings, DatabaseID, EvalContext, EvalViolation, Grant, Policy,
|
CombinedSettings, DatabaseID, EvalContext, EvalViolation, Grant, Policy,
|
||||||
SharedGrantSettings, SpecificGrant, SpecificMeaning, ether_transfer::EtherTransfer,
|
SharedGrantSettings, SpecificGrant, SpecificMeaning, VolumeRateLimit,
|
||||||
token_transfers::TokenTransfer,
|
ether_transfer::EtherTransfer, token_transfers::TokenTransfer,
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
|
|
||||||
use alloy::{
|
use alloy::{
|
||||||
consensus::TxEip1559,
|
consensus::TxEip1559,
|
||||||
primitives::{TxKind, U256},
|
primitives::{Address, TxKind, U256},
|
||||||
};
|
};
|
||||||
use chrono::Utc;
|
use chrono::Utc;
|
||||||
use diesel::{ExpressionMethods as _, QueryDsl as _, QueryResult, insert_into, sqlite::Sqlite};
|
use diesel::{
|
||||||
use diesel_async::{AsyncConnection, RunQueryDsl};
|
ExpressionMethods as _, OptionalExtension, QueryDsl as _, QueryResult, SelectableHelper,
|
||||||
use kameo::actor::ActorRef;
|
insert_into, sqlite::Sqlite, update,
|
||||||
|
};
|
||||||
|
|
||||||
pub mod abi;
|
pub mod abi;
|
||||||
pub mod safe_signer;
|
pub mod safe_signer;
|
||||||
@@ -272,6 +278,151 @@ impl Engine {
|
|||||||
Ok(id)
|
Ok(id)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
pub async fn revoke_grant(
|
||||||
|
&self,
|
||||||
|
basic_grant_id: i32,
|
||||||
|
) -> Result<(), DatabaseError> {
|
||||||
|
let mut conn = self.db.get().await.map_err(DatabaseError::from)?;
|
||||||
|
let vault = self.vault.clone();
|
||||||
|
|
||||||
|
conn.transaction(async move |conn| {
|
||||||
|
use crate::db::schema::{
|
||||||
|
evm_basic_grant, evm_ether_transfer_grant, evm_ether_transfer_grant_target,
|
||||||
|
evm_ether_transfer_limit, evm_token_transfer_grant,
|
||||||
|
evm_token_transfer_volume_limit,
|
||||||
|
};
|
||||||
|
|
||||||
|
update(evm_basic_grant::table)
|
||||||
|
.filter(evm_basic_grant::id.eq(basic_grant_id))
|
||||||
|
.set(evm_basic_grant::revoked_at.eq(SqliteTimestamp(Utc::now())))
|
||||||
|
.execute(&mut *conn)
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
let basic_grant: EvmBasicGrant = evm_basic_grant::table
|
||||||
|
.filter(evm_basic_grant::id.eq(basic_grant_id))
|
||||||
|
.select(EvmBasicGrant::as_select())
|
||||||
|
.first(&mut *conn)
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
let shared = SharedGrantSettings::try_from_model(basic_grant)?;
|
||||||
|
|
||||||
|
if let Some(ether_grant) = evm_ether_transfer_grant::table
|
||||||
|
.filter(evm_ether_transfer_grant::basic_grant_id.eq(basic_grant_id))
|
||||||
|
.select(EvmEtherTransferGrant::as_select())
|
||||||
|
.first(&mut *conn)
|
||||||
|
.await
|
||||||
|
.optional()?
|
||||||
|
{
|
||||||
|
let target_rows: Vec<EvmEtherTransferGrantTarget> =
|
||||||
|
evm_ether_transfer_grant_target::table
|
||||||
|
.filter(evm_ether_transfer_grant_target::grant_id.eq(ether_grant.id))
|
||||||
|
.select(EvmEtherTransferGrantTarget::as_select())
|
||||||
|
.load(&mut *conn)
|
||||||
|
.await?;
|
||||||
|
let targets: Vec<Address> = target_rows
|
||||||
|
.into_iter()
|
||||||
|
.filter_map(|target| {
|
||||||
|
let arr: [u8; 20] = target.address.try_into().ok()?;
|
||||||
|
Some(Address::from(arr))
|
||||||
|
})
|
||||||
|
.collect();
|
||||||
|
|
||||||
|
let limit: EvmEtherTransferLimit = evm_ether_transfer_limit::table
|
||||||
|
.filter(evm_ether_transfer_limit::id.eq(ether_grant.limit_id))
|
||||||
|
.select(EvmEtherTransferLimit::as_select())
|
||||||
|
.first(&mut *conn)
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
let settings = CombinedSettings {
|
||||||
|
shared: shared.clone(),
|
||||||
|
specific: policies::ether_transfer::Settings {
|
||||||
|
target: targets,
|
||||||
|
limit: VolumeRateLimit {
|
||||||
|
max_volume: utils::try_bytes_to_u256(&limit.max_volume).map_err(
|
||||||
|
|err| {
|
||||||
|
diesel::result::Error::DeserializationError(Box::new(err))
|
||||||
|
},
|
||||||
|
)?,
|
||||||
|
window: chrono::Duration::seconds(limit.window_secs.into()),
|
||||||
|
},
|
||||||
|
},
|
||||||
|
};
|
||||||
|
|
||||||
|
integrity::sign_entity(&mut *conn, &vault, &settings, basic_grant_id)
|
||||||
|
.await
|
||||||
|
.map_err(|_| diesel::result::Error::RollbackTransaction)?;
|
||||||
|
|
||||||
|
return QueryResult::Ok(());
|
||||||
|
}
|
||||||
|
|
||||||
|
if let Some(token_grant) = evm_token_transfer_grant::table
|
||||||
|
.filter(evm_token_transfer_grant::basic_grant_id.eq(basic_grant_id))
|
||||||
|
.select(EvmTokenTransferGrant::as_select())
|
||||||
|
.first(&mut *conn)
|
||||||
|
.await
|
||||||
|
.optional()?
|
||||||
|
{
|
||||||
|
let volume_limit_rows: Vec<EvmTokenTransferVolumeLimit> =
|
||||||
|
evm_token_transfer_volume_limit::table
|
||||||
|
.filter(evm_token_transfer_volume_limit::grant_id.eq(token_grant.id))
|
||||||
|
.select(EvmTokenTransferVolumeLimit::as_select())
|
||||||
|
.load(&mut *conn)
|
||||||
|
.await?;
|
||||||
|
let volume_limits: Vec<VolumeRateLimit> = volume_limit_rows
|
||||||
|
.into_iter()
|
||||||
|
.map(|row| {
|
||||||
|
Ok(VolumeRateLimit {
|
||||||
|
max_volume: utils::try_bytes_to_u256(&row.max_volume).map_err(
|
||||||
|
|err| {
|
||||||
|
diesel::result::Error::DeserializationError(Box::new(err))
|
||||||
|
},
|
||||||
|
)?,
|
||||||
|
window: chrono::Duration::seconds(row.window_secs.into()),
|
||||||
|
})
|
||||||
|
})
|
||||||
|
.collect::<QueryResult<Vec<_>>>()?;
|
||||||
|
|
||||||
|
let target: Option<Address> = match token_grant.receiver {
|
||||||
|
None => None,
|
||||||
|
Some(bytes) => {
|
||||||
|
let arr: [u8; 20] = bytes.try_into().map_err(|_| {
|
||||||
|
diesel::result::Error::DeserializationError(
|
||||||
|
"Invalid receiver address length".into(),
|
||||||
|
)
|
||||||
|
})?;
|
||||||
|
Some(Address::from(arr))
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
let token_contract: [u8; 20] =
|
||||||
|
token_grant.token_contract.clone().try_into().map_err(|_| {
|
||||||
|
diesel::result::Error::DeserializationError(
|
||||||
|
"Invalid token contract address length".into(),
|
||||||
|
)
|
||||||
|
})?;
|
||||||
|
|
||||||
|
let settings = CombinedSettings {
|
||||||
|
shared,
|
||||||
|
specific: policies::token_transfers::Settings {
|
||||||
|
token_contract: Address::from(token_contract),
|
||||||
|
target,
|
||||||
|
volume_limits,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
|
||||||
|
integrity::sign_entity(&mut *conn, &vault, &settings, basic_grant_id)
|
||||||
|
.await
|
||||||
|
.map_err(|_| diesel::result::Error::RollbackTransaction)?;
|
||||||
|
|
||||||
|
return QueryResult::Ok(());
|
||||||
|
}
|
||||||
|
|
||||||
|
Err(diesel::result::Error::NotFound)
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.map_err(DatabaseError::from)
|
||||||
|
}
|
||||||
|
|
||||||
async fn list_one_kind<Kind: Policy, Y>(
|
async fn list_one_kind<Kind: Policy, Y>(
|
||||||
&self,
|
&self,
|
||||||
conn: &mut impl AsyncConnection<Backend = Sqlite>,
|
conn: &mut impl AsyncConnection<Backend = Sqlite>,
|
||||||
@@ -354,8 +505,12 @@ mod tests {
|
|||||||
use chrono::{Duration, Utc};
|
use chrono::{Duration, Utc};
|
||||||
use diesel::{SelectableHelper, insert_into};
|
use diesel::{SelectableHelper, insert_into};
|
||||||
use diesel_async::RunQueryDsl;
|
use diesel_async::RunQueryDsl;
|
||||||
|
use kameo::{actor::ActorRef, prelude::Spawn};
|
||||||
use rstest::rstest;
|
use rstest::rstest;
|
||||||
|
|
||||||
|
use crate::actors::{GlobalActors, vault::{Bootstrap, Vault}};
|
||||||
|
use crate::crypto::KeyCell;
|
||||||
|
use crate::crypto::integrity;
|
||||||
use crate::db::{
|
use crate::db::{
|
||||||
self, DatabaseConnection,
|
self, DatabaseConnection,
|
||||||
models::{
|
models::{
|
||||||
@@ -364,8 +519,10 @@ mod tests {
|
|||||||
},
|
},
|
||||||
schema::{evm_basic_grant, evm_transaction_log},
|
schema::{evm_basic_grant, evm_transaction_log},
|
||||||
};
|
};
|
||||||
|
use crate::evm::policies::ether_transfer::EtherTransfer;
|
||||||
use crate::evm::policies::{
|
use crate::evm::policies::{
|
||||||
EvalContext, EvalViolation, SharedGrantSettings, TransactionRateLimit,
|
CombinedSettings, EvalContext, EvalViolation, Policy, SharedGrantSettings,
|
||||||
|
TransactionRateLimit, VolumeRateLimit,
|
||||||
};
|
};
|
||||||
|
|
||||||
use super::check_shared_constraints;
|
use super::check_shared_constraints;
|
||||||
@@ -397,6 +554,7 @@ mod tests {
|
|||||||
chain: CHAIN_ID,
|
chain: CHAIN_ID,
|
||||||
valid_from: None,
|
valid_from: None,
|
||||||
valid_until: None,
|
valid_until: None,
|
||||||
|
revoked_at: None,
|
||||||
max_gas_fee_per_gas: None,
|
max_gas_fee_per_gas: None,
|
||||||
max_priority_fee_per_gas: None,
|
max_priority_fee_per_gas: None,
|
||||||
rate_limit: None,
|
rate_limit: None,
|
||||||
@@ -605,4 +763,116 @@ mod tests {
|
|||||||
assert!(violations.is_empty());
|
assert!(violations.is_empty());
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
async fn bootstrapped_vault(db: &db::DatabasePool) -> ActorRef<Vault> {
|
||||||
|
let actor = Vault::spawn(
|
||||||
|
Vault::new(db.clone(), GlobalActors::spawn_message_bus())
|
||||||
|
.await
|
||||||
|
.unwrap(),
|
||||||
|
);
|
||||||
|
actor
|
||||||
|
.ask(Bootstrap {
|
||||||
|
seal_key: KeyCell::from([0u8; 32]),
|
||||||
|
custody: None,
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
actor
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn revoke_grant_preserves_revoked_integrity() {
|
||||||
|
use crate::db::schema::evm_basic_grant;
|
||||||
|
use diesel::ExpressionMethods as _;
|
||||||
|
|
||||||
|
let db = db::create_test_pool().await;
|
||||||
|
let vault = bootstrapped_vault(&db).await;
|
||||||
|
let engine = super::Engine::new(db.clone(), vault.clone());
|
||||||
|
|
||||||
|
let full_grant = CombinedSettings {
|
||||||
|
shared: SharedGrantSettings {
|
||||||
|
wallet_access_id: WALLET_ACCESS_ID,
|
||||||
|
chain: CHAIN_ID,
|
||||||
|
valid_from: None,
|
||||||
|
valid_until: None,
|
||||||
|
revoked_at: None,
|
||||||
|
max_gas_fee_per_gas: None,
|
||||||
|
max_priority_fee_per_gas: None,
|
||||||
|
rate_limit: None,
|
||||||
|
},
|
||||||
|
specific: super::policies::ether_transfer::Settings {
|
||||||
|
target: vec![RECIPIENT],
|
||||||
|
limit: VolumeRateLimit {
|
||||||
|
max_volume: U256::from(100u64),
|
||||||
|
window: Duration::hours(1),
|
||||||
|
},
|
||||||
|
},
|
||||||
|
};
|
||||||
|
|
||||||
|
let grant_id = engine
|
||||||
|
.create_grant::<EtherTransfer>(full_grant)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
engine.revoke_grant(grant_id).await.unwrap();
|
||||||
|
|
||||||
|
let mut conn = db.get().await.unwrap();
|
||||||
|
diesel::update(evm_basic_grant::table)
|
||||||
|
.filter(evm_basic_grant::id.eq(grant_id))
|
||||||
|
.set(evm_basic_grant::revoked_at.eq::<Option<SqliteTimestamp>>(None))
|
||||||
|
.execute(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
let wallet_access = EvmWalletAccess {
|
||||||
|
id: WALLET_ACCESS_ID,
|
||||||
|
wallet_id: EvmWalletId::from_raw(10),
|
||||||
|
client_id: 20,
|
||||||
|
created_at: SqliteTimestamp(Utc::now()),
|
||||||
|
};
|
||||||
|
let context = EvalContext {
|
||||||
|
target: wallet_access,
|
||||||
|
chain: CHAIN_ID,
|
||||||
|
to: RECIPIENT,
|
||||||
|
value: U256::ONE,
|
||||||
|
calldata: Bytes::new(),
|
||||||
|
max_fee_per_gas: 1,
|
||||||
|
max_priority_fee_per_gas: 1,
|
||||||
|
};
|
||||||
|
|
||||||
|
let grant = EtherTransfer::try_find_grant(
|
||||||
|
&context, &mut conn,
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.unwrap()
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
let result =
|
||||||
|
integrity::verify_entity(&mut conn, &vault, &grant.settings, grant.id).await;
|
||||||
|
|
||||||
|
assert!(matches!(
|
||||||
|
result,
|
||||||
|
Err(integrity::Error::MacMismatch { .. })
|
||||||
|
));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn shared_settings_hash_changes_when_revoked_at_changes() {
|
||||||
|
use arbiter_crypto::hashing::Hashable;
|
||||||
|
use sha2::Digest;
|
||||||
|
|
||||||
|
let active = shared_settings();
|
||||||
|
let revoked = SharedGrantSettings {
|
||||||
|
revoked_at: Some(Utc::now()),
|
||||||
|
..shared_settings()
|
||||||
|
};
|
||||||
|
|
||||||
|
let mut active_hash = sha2::Sha256::new();
|
||||||
|
active.hash(&mut active_hash);
|
||||||
|
|
||||||
|
let mut revoked_hash = sha2::Sha256::new();
|
||||||
|
revoked.hash(&mut revoked_hash);
|
||||||
|
|
||||||
|
assert_ne!(active_hash.finalize(), revoked_hash.finalize());
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -144,6 +144,7 @@ pub struct SharedGrantSettings {
|
|||||||
|
|
||||||
pub valid_from: Option<DateTime<Utc>>,
|
pub valid_from: Option<DateTime<Utc>>,
|
||||||
pub valid_until: Option<DateTime<Utc>>,
|
pub valid_until: Option<DateTime<Utc>>,
|
||||||
|
pub revoked_at: Option<DateTime<Utc>>,
|
||||||
|
|
||||||
pub max_gas_fee_per_gas: Option<U256>,
|
pub max_gas_fee_per_gas: Option<U256>,
|
||||||
pub max_priority_fee_per_gas: Option<U256>,
|
pub max_priority_fee_per_gas: Option<U256>,
|
||||||
@@ -158,6 +159,7 @@ impl SharedGrantSettings {
|
|||||||
chain: model.chain_id.into(),
|
chain: model.chain_id.into(),
|
||||||
valid_from: model.valid_from.map(Into::into),
|
valid_from: model.valid_from.map(Into::into),
|
||||||
valid_until: model.valid_until.map(Into::into),
|
valid_until: model.valid_until.map(Into::into),
|
||||||
|
revoked_at: model.revoked_at.map(Into::into),
|
||||||
max_gas_fee_per_gas: model
|
max_gas_fee_per_gas: model
|
||||||
.max_gas_fee_per_gas
|
.max_gas_fee_per_gas
|
||||||
.map(|b| utils::try_bytes_to_u256(&b))
|
.map(|b| utils::try_bytes_to_u256(&b))
|
||||||
|
|||||||
@@ -80,6 +80,7 @@ fn shared() -> SharedGrantSettings {
|
|||||||
chain: CHAIN_ID,
|
chain: CHAIN_ID,
|
||||||
valid_from: None,
|
valid_from: None,
|
||||||
valid_until: None,
|
valid_until: None,
|
||||||
|
revoked_at: None,
|
||||||
max_gas_fee_per_gas: None,
|
max_gas_fee_per_gas: None,
|
||||||
max_priority_fee_per_gas: None,
|
max_priority_fee_per_gas: None,
|
||||||
rate_limit: None,
|
rate_limit: None,
|
||||||
|
|||||||
@@ -98,6 +98,7 @@ fn shared() -> SharedGrantSettings {
|
|||||||
chain: CHAIN_ID,
|
chain: CHAIN_ID,
|
||||||
valid_from: None,
|
valid_from: None,
|
||||||
valid_until: None,
|
valid_until: None,
|
||||||
|
revoked_at: None,
|
||||||
max_gas_fee_per_gas: None,
|
max_gas_fee_per_gas: None,
|
||||||
max_priority_fee_per_gas: None,
|
max_priority_fee_per_gas: None,
|
||||||
rate_limit: None,
|
rate_limit: None,
|
||||||
|
|||||||
@@ -200,7 +200,7 @@ impl Convert for auth::Outbound {
|
|||||||
.timestamp
|
.timestamp
|
||||||
.timestamp_nanos_opt()
|
.timestamp_nanos_opt()
|
||||||
.expect("timestamp within range")
|
.expect("timestamp within range")
|
||||||
as u64,
|
.cast_unsigned(),
|
||||||
random: challenge.nonce.to_vec(),
|
random: challenge.nonce.to_vec(),
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,11 +1,10 @@
|
|||||||
use crate::{
|
use crate::{
|
||||||
grpc::request_tracker::RequestTracker,
|
grpc::request_tracker::RequestTracker,
|
||||||
peers::operator::{OutOfBand, OperatorConnection, OperatorSession},
|
peers::operator::{OperatorConnection, OperatorSession, OutOfBand},
|
||||||
};
|
};
|
||||||
use arbiter_proto::{
|
use arbiter_proto::{
|
||||||
proto::operator::{
|
proto::operator::{
|
||||||
OperatorRequest, OperatorResponse,
|
OperatorRequest, OperatorResponse, operator_request::Payload as OperatorRequestPayload,
|
||||||
operator_request::Payload as OperatorRequestPayload,
|
|
||||||
operator_response::Payload as OperatorResponsePayload,
|
operator_response::Payload as OperatorResponsePayload,
|
||||||
},
|
},
|
||||||
transport::{Error as TransportError, Receiver, Sender, grpc::GrpcBi},
|
transport::{Error as TransportError, Receiver, Sender, grpc::GrpcBi},
|
||||||
@@ -111,6 +110,9 @@ async fn dispatch_inner(
|
|||||||
OperatorRequestPayload::Vault(req) => vault::dispatch(actor, req).await,
|
OperatorRequestPayload::Vault(req) => vault::dispatch(actor, req).await,
|
||||||
OperatorRequestPayload::Evm(req) => evm::dispatch(actor, req).await,
|
OperatorRequestPayload::Evm(req) => evm::dispatch(actor, req).await,
|
||||||
OperatorRequestPayload::SdkClient(req) => sdk_client::dispatch(actor, req).await,
|
OperatorRequestPayload::SdkClient(req) => sdk_client::dispatch(actor, req).await,
|
||||||
|
OperatorRequestPayload::Governance(_) => {
|
||||||
|
Err(Status::permission_denied(stringify!(Governance)))
|
||||||
|
}
|
||||||
OperatorRequestPayload::Auth(..) => {
|
OperatorRequestPayload::Auth(..) => {
|
||||||
warn!("Unsupported post-auth operator auth request");
|
warn!("Unsupported post-auth operator auth request");
|
||||||
Err(Status::invalid_argument("Unsupported operator request"))
|
Err(Status::invalid_argument("Unsupported operator request"))
|
||||||
|
|||||||
@@ -80,7 +80,7 @@ impl Sender<Result<auth::Outbound, auth::Error>> for AuthTransportAdapter<'_> {
|
|||||||
.timestamp
|
.timestamp
|
||||||
.timestamp_nanos_opt()
|
.timestamp_nanos_opt()
|
||||||
.expect("timestamp within range")
|
.expect("timestamp within range")
|
||||||
as u64,
|
.cast_unsigned(),
|
||||||
random: challenge.nonce.to_vec(),
|
random: challenge.nonce.to_vec(),
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
@@ -171,7 +171,7 @@ impl Receiver<auth::Inbound> for AuthTransportAdapter<'_> {
|
|||||||
|
|
||||||
Some(auth::Inbound::AuthChallengeRequest {
|
Some(auth::Inbound::AuthChallengeRequest {
|
||||||
pubkey,
|
pubkey,
|
||||||
bootstrap_token,
|
bootstrap_token: bootstrap_token.map(String::into_bytes),
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
AuthRequestPayload::ChallengeSolution(ProtoAuthChallengeSolution { signature }) => {
|
AuthRequestPayload::ChallengeSolution(ProtoAuthChallengeSolution { signature }) => {
|
||||||
|
|||||||
@@ -217,6 +217,11 @@ async fn handle_sign_transaction(
|
|||||||
result: Some(vet_error.convert()),
|
result: Some(vet_error.convert()),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
Err(kameo::error::SendError::HandlerError(
|
||||||
|
SessionSignTransactionError::ClientNotConnected,
|
||||||
|
)) => {
|
||||||
|
return Err(Status::permission_denied("client not connected"));
|
||||||
|
}
|
||||||
Err(kameo::error::SendError::HandlerError(SessionSignTransactionError::Internal)) => {
|
Err(kameo::error::SendError::HandlerError(SessionSignTransactionError::Internal)) => {
|
||||||
EvmSignTransactionResponse {
|
EvmSignTransactionResponse {
|
||||||
result: Some(EvmSignTransactionResult::Error(
|
result: Some(EvmSignTransactionResult::Error(
|
||||||
|
|||||||
@@ -86,6 +86,7 @@ impl TryConvert for ProtoSharedSettings {
|
|||||||
.valid_until
|
.valid_until
|
||||||
.map(ProtoTimestamp::try_convert)
|
.map(ProtoTimestamp::try_convert)
|
||||||
.transpose()?,
|
.transpose()?,
|
||||||
|
revoked_at: None,
|
||||||
max_gas_fee_per_gas: self
|
max_gas_fee_per_gas: self
|
||||||
.max_gas_fee_per_gas
|
.max_gas_fee_per_gas
|
||||||
.as_deref()
|
.as_deref()
|
||||||
|
|||||||
@@ -3,7 +3,6 @@ use crate::{
|
|||||||
peers::operator::{OperatorSession, session::handlers::HandleQueryVaultState},
|
peers::operator::{OperatorSession, session::handlers::HandleQueryVaultState},
|
||||||
};
|
};
|
||||||
use arbiter_proto::{
|
use arbiter_proto::{
|
||||||
proto::shared::VaultState as ProtoVaultState,
|
|
||||||
proto::operator::{
|
proto::operator::{
|
||||||
operator_response::Payload as OperatorResponsePayload,
|
operator_response::Payload as OperatorResponsePayload,
|
||||||
vault::{
|
vault::{
|
||||||
@@ -11,6 +10,7 @@ use arbiter_proto::{
|
|||||||
response::Payload as VaultResponsePayload,
|
response::Payload as VaultResponsePayload,
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
proto::shared::VaultState as ProtoVaultState,
|
||||||
};
|
};
|
||||||
|
|
||||||
use kameo::actor::ActorRef;
|
use kameo::actor::ActorRef;
|
||||||
@@ -33,11 +33,11 @@ pub(super) async fn dispatch(
|
|||||||
|
|
||||||
match payload {
|
match payload {
|
||||||
VaultRequestPayload::QueryState(()) => handle_query_vault_state(actor).await,
|
VaultRequestPayload::QueryState(()) => handle_query_vault_state(actor).await,
|
||||||
VaultRequestPayload::Unseal(_) | VaultRequestPayload::Bootstrap(_) => {
|
VaultRequestPayload::Unseal(_)
|
||||||
Err(Status::permission_denied(
|
| VaultRequestPayload::Bootstrap(_)
|
||||||
|
| VaultRequestPayload::Rekey(_) => Err(Status::permission_denied(
|
||||||
"Vault is already unsealed; unseal/bootstrap not permitted in session",
|
"Vault is already unsealed; unseal/bootstrap not permitted in session",
|
||||||
))
|
)),
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1,14 +1,17 @@
|
|||||||
use crate::{
|
use crate::{
|
||||||
|
crypto::shamir,
|
||||||
grpc::{Convert, TryConvert},
|
grpc::{Convert, TryConvert},
|
||||||
peers::operator::vault_gate::{
|
peers::operator::vault_gate::{
|
||||||
self as vault_gate, HandleBootstrapEncryptedKey, HandleHandshake, HandleUnsealEncryptedKey,
|
self as vault_gate, HandleBootstrapEncryptedKey, HandleContributeBootstrapPassphrase,
|
||||||
|
HandleContributeUnsealPassphrase, HandleDeclareCommittee, HandleHandshake,
|
||||||
|
HandleUnsealEncryptedKey,
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
use arbiter_proto::proto::operator::{
|
use arbiter_proto::proto::operator::{
|
||||||
operator_request::Payload as OperatorRequestPayload,
|
operator_request::Payload as OperatorRequestPayload,
|
||||||
vault::{
|
vault::{
|
||||||
self as proto_vault,
|
self as proto_vault,
|
||||||
bootstrap::{self as proto_bootstrap},
|
bootstrap::{self as proto_bootstrap, request::Payload as BootstrapRequestPayload},
|
||||||
request::Payload as VaultRequestPayload,
|
request::Payload as VaultRequestPayload,
|
||||||
unseal::{self as proto_unseal, request::Payload as UnsealRequestPayload},
|
unseal::{self as proto_unseal, request::Payload as UnsealRequestPayload},
|
||||||
},
|
},
|
||||||
@@ -50,6 +53,7 @@ impl TryConvert for VaultRequestPayload {
|
|||||||
Self::QueryState(()) => Ok(vault_gate::Inbound::HandleVaultState),
|
Self::QueryState(()) => Ok(vault_gate::Inbound::HandleVaultState),
|
||||||
Self::Unseal(req) => req.try_convert(),
|
Self::Unseal(req) => req.try_convert(),
|
||||||
Self::Bootstrap(req) => req.try_convert(),
|
Self::Bootstrap(req) => req.try_convert(),
|
||||||
|
Self::Rekey(_) => Err(Status::unimplemented("Vault re-key is not available")),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -73,6 +77,16 @@ impl TryConvert for UnsealRequestPayload {
|
|||||||
match self {
|
match self {
|
||||||
Self::Start(start) => start.try_convert(),
|
Self::Start(start) => start.try_convert(),
|
||||||
Self::EncryptedKey(key) => Ok(key.convert()),
|
Self::EncryptedKey(key) => Ok(key.convert()),
|
||||||
|
Self::ContributePassphrase(passphrase) => {
|
||||||
|
Ok(vault_gate::Inbound::HandleContributeUnsealPassphrase(
|
||||||
|
HandleContributeUnsealPassphrase {
|
||||||
|
passphrase: passphrase.passphrase,
|
||||||
|
},
|
||||||
|
))
|
||||||
|
}
|
||||||
|
Self::ContributeRecoveryPassphrase(_) => Err(Status::unimplemented(
|
||||||
|
"Recovery operator contributions are not available",
|
||||||
|
)),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -107,12 +121,52 @@ impl TryConvert for proto_bootstrap::Request {
|
|||||||
type Error = Status;
|
type Error = Status;
|
||||||
|
|
||||||
fn try_convert(self) -> Result<vault_gate::Inbound, Status> {
|
fn try_convert(self) -> Result<vault_gate::Inbound, Status> {
|
||||||
self.encrypted_key
|
self.payload
|
||||||
.ok_or_else(|| Status::invalid_argument("Missing bootstrap encrypted key"))?
|
.ok_or_else(|| Status::invalid_argument("Missing bootstrap payload"))?
|
||||||
.try_convert()
|
.try_convert()
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
impl TryConvert for BootstrapRequestPayload {
|
||||||
|
type Output = vault_gate::Inbound;
|
||||||
|
type Error = Status;
|
||||||
|
|
||||||
|
fn try_convert(self) -> Result<vault_gate::Inbound, Status> {
|
||||||
|
match self {
|
||||||
|
Self::EncryptedKey(key) => key.try_convert(),
|
||||||
|
Self::DeclareCommittee(dc) => {
|
||||||
|
if dc.recovery_count != 0 {
|
||||||
|
return Err(Status::unimplemented(
|
||||||
|
"Recovery operator contributions are not available",
|
||||||
|
));
|
||||||
|
}
|
||||||
|
let count = usize::try_from(dc.count)
|
||||||
|
.ok()
|
||||||
|
.filter(|count| *count <= shamir::MAX_COMMITTEE_SIZE)
|
||||||
|
.ok_or_else(|| {
|
||||||
|
Status::invalid_argument(format!(
|
||||||
|
"Committee count must not exceed {}",
|
||||||
|
shamir::MAX_COMMITTEE_SIZE
|
||||||
|
))
|
||||||
|
})?;
|
||||||
|
Ok(vault_gate::Inbound::HandleDeclareCommittee(
|
||||||
|
HandleDeclareCommittee { count },
|
||||||
|
))
|
||||||
|
}
|
||||||
|
Self::ContributePassphrase(cp) => {
|
||||||
|
Ok(vault_gate::Inbound::HandleContributeBootstrapPassphrase(
|
||||||
|
HandleContributeBootstrapPassphrase {
|
||||||
|
passphrase: cp.passphrase,
|
||||||
|
},
|
||||||
|
))
|
||||||
|
}
|
||||||
|
Self::ContributeRecoveryPassphrase(_) => Err(Status::unimplemented(
|
||||||
|
"Recovery operator contributions are not available",
|
||||||
|
)),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
impl TryConvert for proto_bootstrap::BootstrapEncryptedKey {
|
impl TryConvert for proto_bootstrap::BootstrapEncryptedKey {
|
||||||
type Output = vault_gate::Inbound;
|
type Output = vault_gate::Inbound;
|
||||||
type Error = Status;
|
type Error = Status;
|
||||||
|
|||||||
@@ -1,10 +1,9 @@
|
|||||||
use crate::{
|
use crate::{
|
||||||
actors::vault::VaultState,
|
actors::{vault::VaultState, vault_coordinator},
|
||||||
grpc::{Convert, TryConvert},
|
grpc::{Convert, TryConvert},
|
||||||
peers::operator::vault_gate::{self as vault_gate},
|
peers::operator::vault_gate::{self as vault_gate},
|
||||||
};
|
};
|
||||||
use arbiter_proto::proto::{
|
use arbiter_proto::proto::{
|
||||||
shared::VaultState as ProtoVaultState,
|
|
||||||
operator::{
|
operator::{
|
||||||
operator_response::Payload as OperatorResponsePayload,
|
operator_response::Payload as OperatorResponsePayload,
|
||||||
vault::{
|
vault::{
|
||||||
@@ -17,6 +16,7 @@ use arbiter_proto::proto::{
|
|||||||
},
|
},
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
shared::VaultState as ProtoVaultState,
|
||||||
};
|
};
|
||||||
|
|
||||||
use tonic::Status;
|
use tonic::Status;
|
||||||
@@ -34,6 +34,26 @@ const fn wrap_unseal_response(payload: UnsealResponsePayload) -> OperatorRespons
|
|||||||
}))
|
}))
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Ceremony errors are the operator's own doing far more often than ours, so
|
||||||
|
/// they travel back as a specific status instead of a blanket internal error.
|
||||||
|
fn ceremony_status(error: &vault_coordinator::Error) -> Status {
|
||||||
|
match error {
|
||||||
|
vault_coordinator::Error::AlreadyBootstrapping
|
||||||
|
| vault_coordinator::Error::AlreadyUnsealing
|
||||||
|
| vault_coordinator::Error::NotBootstrapping
|
||||||
|
| vault_coordinator::Error::DuplicateContribution => {
|
||||||
|
Status::failed_precondition(error.to_string())
|
||||||
|
}
|
||||||
|
vault_coordinator::Error::EmptyCommittee
|
||||||
|
| vault_coordinator::Error::UnsupportedCommittee
|
||||||
|
| vault_coordinator::Error::CommitteeTooLarge => {
|
||||||
|
Status::invalid_argument(error.to_string())
|
||||||
|
}
|
||||||
|
vault_coordinator::Error::InvalidPassphrase => Status::unauthenticated(error.to_string()),
|
||||||
|
_ => Status::internal("Vault ceremony failed"),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
fn wrap_bootstrap_response(result: ProtoBootstrapResult) -> OperatorResponsePayload {
|
fn wrap_bootstrap_response(result: ProtoBootstrapResult) -> OperatorResponsePayload {
|
||||||
wrap_vault_response(VaultResponsePayload::Bootstrap(proto_bootstrap::Response {
|
wrap_vault_response(VaultResponsePayload::Bootstrap(proto_bootstrap::Response {
|
||||||
result: result.into(),
|
result: result.into(),
|
||||||
@@ -110,6 +130,56 @@ impl TryConvert for vault_gate::Outbound {
|
|||||||
};
|
};
|
||||||
Ok(wrap_bootstrap_response(proto_result))
|
Ok(wrap_bootstrap_response(proto_result))
|
||||||
}
|
}
|
||||||
|
Self::HandleDeclareCommittee(result) => {
|
||||||
|
let proto_result = match result {
|
||||||
|
Ok(()) => ProtoBootstrapResult::AwaitingContributions,
|
||||||
|
Err(vault_gate::Error::Ceremony(
|
||||||
|
vault_coordinator::Error::AlreadyBootstrapped,
|
||||||
|
)) => ProtoBootstrapResult::AlreadyBootstrapped,
|
||||||
|
Err(vault_gate::Error::Ceremony(err)) => {
|
||||||
|
warn!(?err, "declare committee failed");
|
||||||
|
return Err(ceremony_status(&err));
|
||||||
|
}
|
||||||
|
Err(err) => {
|
||||||
|
warn!(?err, "declare committee failed");
|
||||||
|
return Err(Status::internal("Failed to declare committee"));
|
||||||
|
}
|
||||||
|
};
|
||||||
|
Ok(wrap_bootstrap_response(proto_result))
|
||||||
|
}
|
||||||
|
Self::HandleContributeBootstrapPassphrase(result) => {
|
||||||
|
let proto_result = match result {
|
||||||
|
Ok(true) => ProtoBootstrapResult::Success,
|
||||||
|
Ok(false) => ProtoBootstrapResult::AwaitingContributions,
|
||||||
|
Err(vault_gate::Error::Ceremony(
|
||||||
|
vault_coordinator::Error::AlreadyBootstrapped,
|
||||||
|
)) => ProtoBootstrapResult::AlreadyBootstrapped,
|
||||||
|
Err(vault_gate::Error::Ceremony(err)) => {
|
||||||
|
warn!(?err, "contribute bootstrap passphrase failed");
|
||||||
|
return Err(ceremony_status(&err));
|
||||||
|
}
|
||||||
|
Err(err) => {
|
||||||
|
warn!(?err, "contribute bootstrap passphrase failed");
|
||||||
|
return Err(Status::internal(
|
||||||
|
"Failed to contribute bootstrap passphrase",
|
||||||
|
));
|
||||||
|
}
|
||||||
|
};
|
||||||
|
Ok(wrap_bootstrap_response(proto_result))
|
||||||
|
}
|
||||||
|
Self::HandleContributeUnsealPassphrase(result) => {
|
||||||
|
let proto_result = match result {
|
||||||
|
Ok(true) => ProtoUnsealResult::Success,
|
||||||
|
Ok(false) => ProtoUnsealResult::AwaitingContributions,
|
||||||
|
Err(err) => {
|
||||||
|
warn!(?err, "contribute unseal passphrase failed");
|
||||||
|
return Err(Status::internal("Failed to contribute unseal passphrase"));
|
||||||
|
}
|
||||||
|
};
|
||||||
|
Ok(wrap_unseal_response(UnsealResponsePayload::Result(
|
||||||
|
proto_result.into(),
|
||||||
|
)))
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ use crate::{
|
|||||||
crypto::integrity::{self, AttestationStatus},
|
crypto::integrity::{self, AttestationStatus},
|
||||||
db::{
|
db::{
|
||||||
self,
|
self,
|
||||||
models::{ProgramClientMetadata, SqliteTimestamp},
|
models::ProgramClientMetadata,
|
||||||
schema::program_client,
|
schema::program_client,
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
@@ -18,14 +18,13 @@ use arbiter_proto::{
|
|||||||
transport::{Bi, expect_message},
|
transport::{Bi, expect_message},
|
||||||
};
|
};
|
||||||
|
|
||||||
use chrono::Utc;
|
|
||||||
use diesel::{
|
use diesel::{
|
||||||
ExpressionMethods as _, OptionalExtension as _, QueryDsl as _, SelectableHelper as _,
|
ExpressionMethods as _, OptionalExtension as _, QueryDsl as _, SelectableHelper as _,
|
||||||
dsl::insert_into, update,
|
dsl::insert_into,
|
||||||
};
|
};
|
||||||
use diesel_async::RunQueryDsl as _;
|
use diesel_async::RunQueryDsl as _;
|
||||||
use kameo::{actor::ActorRef, error::SendError};
|
use kameo::{actor::ActorRef, error::SendError};
|
||||||
use tracing::error;
|
use tracing::{error, warn};
|
||||||
|
|
||||||
#[derive(thiserror::Error, Debug, Clone, PartialEq, Eq)]
|
#[derive(thiserror::Error, Debug, Clone, PartialEq, Eq)]
|
||||||
pub enum Error {
|
pub enum Error {
|
||||||
@@ -211,71 +210,47 @@ async fn insert_client(
|
|||||||
.await
|
.await
|
||||||
}
|
}
|
||||||
|
|
||||||
async fn sync_client_metadata(
|
/// Compares stored metadata against what a reconnecting client presents.
|
||||||
|
/// Metadata is frozen after initial operator approval and must not be silently
|
||||||
|
/// overwritten. Doing so would let an approved client forge its displayed
|
||||||
|
/// identity in later approval prompts. Drift is logged and ignored.
|
||||||
|
async fn check_metadata_drift(
|
||||||
db: &db::DatabasePool,
|
db: &db::DatabasePool,
|
||||||
client_id: i32,
|
client_id: i32,
|
||||||
metadata: &ClientMetadata,
|
presented: &ClientMetadata,
|
||||||
) -> Result<(), Error> {
|
) -> Result<(), Error> {
|
||||||
use crate::db::schema::{client_metadata, client_metadata_history};
|
use crate::db::schema::client_metadata;
|
||||||
|
|
||||||
let now = SqliteTimestamp(Utc::now());
|
|
||||||
|
|
||||||
let mut conn = db.get().await.map_err(|e| {
|
let mut conn = db.get().await.map_err(|e| {
|
||||||
error!(error = ?e, "Database pool error");
|
error!(error = ?e, "Database pool error");
|
||||||
Error::DatabasePoolUnavailable
|
Error::DatabasePoolUnavailable
|
||||||
})?;
|
})?;
|
||||||
|
|
||||||
conn.exclusive_transaction(async |conn| {
|
let current: ProgramClientMetadata = program_client::table
|
||||||
let (current_metadata_id, current): (i32, ProgramClientMetadata) = program_client::table
|
|
||||||
.find(client_id)
|
.find(client_id)
|
||||||
.inner_join(client_metadata::table)
|
.inner_join(client_metadata::table)
|
||||||
.select((
|
.select(ProgramClientMetadata::as_select())
|
||||||
program_client::metadata_id,
|
.first(&mut conn)
|
||||||
ProgramClientMetadata::as_select(),
|
|
||||||
))
|
|
||||||
.first(&mut *conn)
|
|
||||||
.await?;
|
|
||||||
|
|
||||||
let unchanged = current.name == metadata.name
|
|
||||||
&& current.description == metadata.description
|
|
||||||
&& current.version == metadata.version;
|
|
||||||
if unchanged {
|
|
||||||
return Ok(());
|
|
||||||
}
|
|
||||||
|
|
||||||
insert_into(client_metadata_history::table)
|
|
||||||
.values((
|
|
||||||
client_metadata_history::metadata_id.eq(current_metadata_id),
|
|
||||||
client_metadata_history::client_id.eq(client_id),
|
|
||||||
))
|
|
||||||
.execute(&mut *conn)
|
|
||||||
.await?;
|
|
||||||
|
|
||||||
let metadata_id = insert_into(client_metadata::table)
|
|
||||||
.values((
|
|
||||||
client_metadata::name.eq(&metadata.name),
|
|
||||||
client_metadata::description.eq(&metadata.description),
|
|
||||||
client_metadata::version.eq(&metadata.version),
|
|
||||||
))
|
|
||||||
.returning(client_metadata::id)
|
|
||||||
.get_result::<i32>(&mut *conn)
|
|
||||||
.await?;
|
|
||||||
|
|
||||||
update(program_client::table.find(client_id))
|
|
||||||
.set((
|
|
||||||
program_client::metadata_id.eq(metadata_id),
|
|
||||||
program_client::updated_at.eq(now),
|
|
||||||
))
|
|
||||||
.execute(&mut *conn)
|
|
||||||
.await?;
|
|
||||||
|
|
||||||
Ok::<(), diesel::result::Error>(())
|
|
||||||
})
|
|
||||||
.await
|
.await
|
||||||
.map_err(|e| {
|
.map_err(|e| {
|
||||||
error!(error = ?e, "Database error");
|
error!(error = ?e, "Database error");
|
||||||
Error::DatabaseOperationFailed
|
Error::DatabaseOperationFailed
|
||||||
})
|
})?;
|
||||||
|
|
||||||
|
let changed = current.name != presented.name
|
||||||
|
|| current.description != presented.description
|
||||||
|
|| current.version != presented.version;
|
||||||
|
|
||||||
|
if changed {
|
||||||
|
warn!(
|
||||||
|
client_id,
|
||||||
|
stored_name = %current.name,
|
||||||
|
presented_name = %presented.name,
|
||||||
|
"reconnecting client presented different metadata; ignoring - metadata is frozen after operator approval"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
async fn challenge_client<T>(
|
async fn challenge_client<T>(
|
||||||
@@ -298,7 +273,7 @@ where
|
|||||||
|
|
||||||
let signature = expect_message(transport, |req: Inbound| match req {
|
let signature = expect_message(transport, |req: Inbound| match req {
|
||||||
Inbound::AuthChallengeSolution { signature } => Some(signature),
|
Inbound::AuthChallengeSolution { signature } => Some(signature),
|
||||||
_ => None,
|
Inbound::AuthChallengeRequest { .. } => None,
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
.map_err(|e| {
|
.map_err(|e| {
|
||||||
@@ -324,6 +299,7 @@ where
|
|||||||
|
|
||||||
let client_id = if let Some(id) = get_client_id(&props.db, &pubkey).await? {
|
let client_id = if let Some(id) = get_client_id(&props.db, &pubkey).await? {
|
||||||
verify_integrity(&props.db, &props.actors.vault, &pubkey).await?;
|
verify_integrity(&props.db, &props.actors.vault, &pubkey).await?;
|
||||||
|
check_metadata_drift(&props.db, id, &metadata).await?;
|
||||||
id
|
id
|
||||||
} else {
|
} else {
|
||||||
approve_new_client(
|
approve_new_client(
|
||||||
@@ -337,8 +313,6 @@ where
|
|||||||
insert_client(&props.db, &props.actors.vault, &pubkey, &metadata).await?
|
insert_client(&props.db, &props.actors.vault, &pubkey, &metadata).await?
|
||||||
};
|
};
|
||||||
|
|
||||||
sync_client_metadata(&props.db, client_id, &metadata).await?;
|
|
||||||
|
|
||||||
let challenge = AuthChallenge::generate(&mut rand::rng());
|
let challenge = AuthChallenge::generate(&mut rand::rng());
|
||||||
challenge_client(transport, pubkey, challenge).await?;
|
challenge_client(transport, pubkey, challenge).await?;
|
||||||
|
|
||||||
|
|||||||
@@ -83,7 +83,7 @@ impl Actor for ClientSession {
|
|||||||
args.props
|
args.props
|
||||||
.actors
|
.actors
|
||||||
.flow_coordinator
|
.flow_coordinator
|
||||||
.ask(RegisterClient { actor: this })
|
.ask(RegisterClient { client_id: args.client_id, actor: this })
|
||||||
.await
|
.await
|
||||||
.map_err(|_| Error::ConnectionRegistrationFailed)?;
|
.map_err(|_| Error::ConnectionRegistrationFailed)?;
|
||||||
Ok(args)
|
Ok(args)
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ mod state;
|
|||||||
pub enum Inbound {
|
pub enum Inbound {
|
||||||
AuthChallengeRequest {
|
AuthChallengeRequest {
|
||||||
pubkey: authn::PublicKey,
|
pubkey: authn::PublicKey,
|
||||||
bootstrap_token: Option<String>,
|
bootstrap_token: Option<Vec<u8>>,
|
||||||
},
|
},
|
||||||
AuthChallengeSolution {
|
AuthChallengeSolution {
|
||||||
signature: Vec<u8>,
|
signature: Vec<u8>,
|
||||||
|
|||||||
@@ -3,8 +3,8 @@ use super::{
|
|||||||
Error,
|
Error,
|
||||||
};
|
};
|
||||||
use crate::{
|
use crate::{
|
||||||
actors::bootstrap::ConsumeToken,
|
actors::bootstrap::VerifyToken,
|
||||||
db::{DatabasePool, schema::operator_identity},
|
db::{DatabasePool, models::OperatorId, schema::operator_identity},
|
||||||
peers::operator::auth::Outbound,
|
peers::operator::auth::Outbound,
|
||||||
};
|
};
|
||||||
use arbiter_crypto::authn::{self, AuthChallenge, OPERATOR_CONTEXT};
|
use arbiter_crypto::authn::{self, AuthChallenge, OPERATOR_CONTEXT};
|
||||||
@@ -16,13 +16,12 @@ use tracing::error;
|
|||||||
|
|
||||||
pub(super) struct ChallengeRequest {
|
pub(super) struct ChallengeRequest {
|
||||||
pub(super) pubkey: authn::PublicKey,
|
pub(super) pubkey: authn::PublicKey,
|
||||||
pub(super) bootstrap_token: Option<String>,
|
pub(super) bootstrap_token: Option<Vec<u8>>,
|
||||||
}
|
}
|
||||||
|
|
||||||
pub(super) struct ChallengeContext {
|
pub struct ChallengeContext {
|
||||||
pub(super) challenge: AuthChallenge,
|
pub(super) challenge: AuthChallenge,
|
||||||
pub(super) pubkey: authn::PublicKey,
|
pub(super) pubkey: authn::PublicKey,
|
||||||
pub(super) bootstrap_token: Option<String>,
|
|
||||||
}
|
}
|
||||||
|
|
||||||
pub(super) struct ChallengeSolution {
|
pub(super) struct ChallengeSolution {
|
||||||
@@ -38,7 +37,10 @@ smlang::statemachine!(
|
|||||||
}
|
}
|
||||||
);
|
);
|
||||||
|
|
||||||
async fn get_client_id(db: &DatabasePool, pubkey: &authn::PublicKey) -> Result<Option<i32>, Error> {
|
async fn get_client_id(
|
||||||
|
db: &DatabasePool,
|
||||||
|
pubkey: &authn::PublicKey,
|
||||||
|
) -> Result<Option<OperatorId>, Error> {
|
||||||
let mut conn = db.get().await.map_err(|e| {
|
let mut conn = db.get().await.map_err(|e| {
|
||||||
error!(error = ?e, "Database pool error");
|
error!(error = ?e, "Database pool error");
|
||||||
Error::internal("Database unavailable")
|
Error::internal("Database unavailable")
|
||||||
@@ -47,7 +49,7 @@ async fn get_client_id(db: &DatabasePool, pubkey: &authn::PublicKey) -> Result<O
|
|||||||
operator_identity::table
|
operator_identity::table
|
||||||
.filter(operator_identity::public_key.eq(pubkey.to_bytes()))
|
.filter(operator_identity::public_key.eq(pubkey.to_bytes()))
|
||||||
.select(operator_identity::id)
|
.select(operator_identity::id)
|
||||||
.first::<i32>(&mut conn)
|
.first::<OperatorId>(&mut conn)
|
||||||
.await
|
.await
|
||||||
.optional()
|
.optional()
|
||||||
.map_err(|e| {
|
.map_err(|e| {
|
||||||
@@ -56,14 +58,14 @@ async fn get_client_id(db: &DatabasePool, pubkey: &authn::PublicKey) -> Result<O
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
async fn register_key(db: &DatabasePool, pubkey: &authn::PublicKey) -> Result<i32, Error> {
|
async fn register_key(db: &DatabasePool, pubkey: &authn::PublicKey) -> Result<OperatorId, Error> {
|
||||||
let pubkey_bytes = pubkey.to_bytes();
|
let pubkey_bytes = pubkey.to_bytes();
|
||||||
let mut conn = db.get().await.map_err(|e| {
|
let mut conn = db.get().await.map_err(|e| {
|
||||||
error!(error = ?e, "Database pool error");
|
error!(error = ?e, "Database pool error");
|
||||||
Error::internal("Database unavailable")
|
Error::internal("Database unavailable")
|
||||||
})?;
|
})?;
|
||||||
|
|
||||||
let id: i32 = diesel::insert_into(operator_identity::table)
|
let id: OperatorId = diesel::insert_into(operator_identity::table)
|
||||||
.values((operator_identity::public_key.eq(pubkey_bytes),))
|
.values((operator_identity::public_key.eq(pubkey_bytes),))
|
||||||
.returning(operator_identity::id)
|
.returning(operator_identity::id)
|
||||||
.get_result(&mut conn)
|
.get_result(&mut conn)
|
||||||
@@ -79,11 +81,16 @@ async fn register_key(db: &DatabasePool, pubkey: &authn::PublicKey) -> Result<i3
|
|||||||
pub(super) struct AuthContext<'a, T: ?Sized> {
|
pub(super) struct AuthContext<'a, T: ?Sized> {
|
||||||
pub(super) conn: &'a mut OperatorConnection,
|
pub(super) conn: &'a mut OperatorConnection,
|
||||||
pub(super) transport: &'a mut T,
|
pub(super) transport: &'a mut T,
|
||||||
|
bootstrap_token: Option<Vec<u8>>,
|
||||||
}
|
}
|
||||||
|
|
||||||
impl<'a, T: ?Sized> AuthContext<'a, T> {
|
impl<'a, T: ?Sized> AuthContext<'a, T> {
|
||||||
pub(super) const fn new(conn: &'a mut OperatorConnection, transport: &'a mut T) -> Self {
|
pub(super) const fn new(conn: &'a mut OperatorConnection, transport: &'a mut T) -> Self {
|
||||||
Self { conn, transport }
|
Self {
|
||||||
|
conn,
|
||||||
|
transport,
|
||||||
|
bootstrap_token: None,
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -108,6 +115,8 @@ where
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
self.bootstrap_token = bootstrap_token;
|
||||||
|
|
||||||
let challenge = AuthChallenge::generate(&mut rand::rng());
|
let challenge = AuthChallenge::generate(&mut rand::rng());
|
||||||
|
|
||||||
self.transport
|
self.transport
|
||||||
@@ -120,22 +129,12 @@ where
|
|||||||
Error::Transport
|
Error::Transport
|
||||||
})?;
|
})?;
|
||||||
|
|
||||||
Ok(ChallengeContext {
|
Ok(ChallengeContext { challenge, pubkey })
|
||||||
challenge,
|
|
||||||
pubkey,
|
|
||||||
bootstrap_token,
|
|
||||||
})
|
|
||||||
}
|
}
|
||||||
|
|
||||||
#[allow(missing_docs)]
|
|
||||||
#[allow(clippy::unused_unit)]
|
|
||||||
async fn verify_solution(
|
async fn verify_solution(
|
||||||
&mut self,
|
&mut self,
|
||||||
ChallengeContext {
|
ChallengeContext { challenge, pubkey }: &ChallengeContext,
|
||||||
challenge,
|
|
||||||
pubkey,
|
|
||||||
bootstrap_token,
|
|
||||||
}: &ChallengeContext,
|
|
||||||
ChallengeSolution { solution }: ChallengeSolution,
|
ChallengeSolution { solution }: ChallengeSolution,
|
||||||
) -> Result<Credentials, Self::Error> {
|
) -> Result<Credentials, Self::Error> {
|
||||||
let signature = authn::Signature::try_from(solution.as_slice()).map_err(|()| {
|
let signature = authn::Signature::try_from(solution.as_slice()).map_err(|()| {
|
||||||
@@ -154,15 +153,13 @@ where
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Resolve client id: bootstrap (consume token + register) or lookup
|
// Resolve client id: bootstrap (consume token + register) or lookup
|
||||||
let id = match bootstrap_token {
|
let id = match self.bootstrap_token.take() {
|
||||||
Some(token) => {
|
Some(token) => {
|
||||||
let token_ok: bool = self
|
let token_ok: bool = self
|
||||||
.conn
|
.conn
|
||||||
.actors
|
.actors
|
||||||
.bootstrapper
|
.bootstrapper
|
||||||
.ask(ConsumeToken {
|
.ask(VerifyToken { token })
|
||||||
token: token.clone(),
|
|
||||||
})
|
|
||||||
.await
|
.await
|
||||||
.map_err(|e| {
|
.map_err(|e| {
|
||||||
error!(?e, "Failed to consume bootstrap token");
|
error!(?e, "Failed to consume bootstrap token");
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ use crate::{
|
|||||||
vault::{GetState, Vault},
|
vault::{GetState, Vault},
|
||||||
},
|
},
|
||||||
crypto::integrity::{self, AttestationStatus, Integrable},
|
crypto::integrity::{self, AttestationStatus, Integrable},
|
||||||
db::{DatabaseError, DatabasePool},
|
db::{DatabaseError, DatabasePool, models::OperatorId},
|
||||||
peers::client::ClientProfile,
|
peers::client::ClientProfile,
|
||||||
};
|
};
|
||||||
use arbiter_crypto::authn;
|
use arbiter_crypto::authn;
|
||||||
@@ -25,7 +25,7 @@ pub mod vault_gate;
|
|||||||
|
|
||||||
#[derive(Debug, Clone, Hashable)]
|
#[derive(Debug, Clone, Hashable)]
|
||||||
pub struct Credentials {
|
pub struct Credentials {
|
||||||
pub id: i32,
|
pub id: OperatorId,
|
||||||
pub pubkey: authn::PublicKey,
|
pub pubkey: authn::PublicKey,
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -5,12 +5,15 @@ use crate::{
|
|||||||
ClientSignTransaction, Generate, ListWallets, OperatorCreateGrant, OperatorListGrants,
|
ClientSignTransaction, Generate, ListWallets, OperatorCreateGrant, OperatorListGrants,
|
||||||
SignTransactionError as EvmSignError,
|
SignTransactionError as EvmSignError,
|
||||||
},
|
},
|
||||||
flow_coordinator::client_connect_approval::ClientApprovalAnswer,
|
flow_coordinator::{IsClientConnected, client_connect_approval::ClientApprovalAnswer},
|
||||||
vault::VaultState,
|
vault::VaultState,
|
||||||
},
|
},
|
||||||
db::models::{
|
db::{
|
||||||
|
models::{
|
||||||
EvmWalletAccess, EvmWalletId, NewEvmWalletAccess, ProgramClient, ProgramClientMetadata,
|
EvmWalletAccess, EvmWalletId, NewEvmWalletAccess, ProgramClient, ProgramClientMetadata,
|
||||||
},
|
},
|
||||||
|
schema::program_client,
|
||||||
|
},
|
||||||
evm::policies::{Grant, SpecificGrant},
|
evm::policies::{Grant, SpecificGrant},
|
||||||
};
|
};
|
||||||
use arbiter_crypto::authn;
|
use arbiter_crypto::authn;
|
||||||
@@ -19,13 +22,16 @@ use alloy::{consensus::TxEip1559, primitives::Address, signers::Signature};
|
|||||||
use diesel::{ExpressionMethods as _, QueryDsl as _, SelectableHelper};
|
use diesel::{ExpressionMethods as _, QueryDsl as _, SelectableHelper};
|
||||||
use diesel_async::{AsyncConnection, RunQueryDsl};
|
use diesel_async::{AsyncConnection, RunQueryDsl};
|
||||||
use kameo::{error::SendError, messages, prelude::Context};
|
use kameo::{error::SendError, messages, prelude::Context};
|
||||||
use tracing::error;
|
use tracing::{error, info, warn};
|
||||||
|
|
||||||
#[derive(Debug, Error)]
|
#[derive(Debug, Error)]
|
||||||
pub enum SignTransactionError {
|
pub enum SignTransactionError {
|
||||||
#[error("Policy evaluation failed")]
|
#[error("Policy evaluation failed")]
|
||||||
Vet(#[from] crate::evm::VetError),
|
Vet(#[from] crate::evm::VetError),
|
||||||
|
|
||||||
|
#[error("Client not connected")]
|
||||||
|
ClientNotConnected,
|
||||||
|
|
||||||
#[error("Internal signing error")]
|
#[error("Internal signing error")]
|
||||||
Internal,
|
Internal,
|
||||||
}
|
}
|
||||||
@@ -147,6 +153,30 @@ impl OperatorSession {
|
|||||||
wallet_address: Address,
|
wallet_address: Address,
|
||||||
transaction: TxEip1559,
|
transaction: TxEip1559,
|
||||||
) -> Result<Signature, SignTransactionError> {
|
) -> Result<Signature, SignTransactionError> {
|
||||||
|
if !self.approved_client_ids.contains(&client_id) {
|
||||||
|
warn!(
|
||||||
|
client_id,
|
||||||
|
"operator attempted to sign for client not in its approved set"
|
||||||
|
);
|
||||||
|
return Err(SignTransactionError::ClientNotConnected);
|
||||||
|
}
|
||||||
|
|
||||||
|
let connected = self
|
||||||
|
.props
|
||||||
|
.actors
|
||||||
|
.flow_coordinator
|
||||||
|
.ask(IsClientConnected { client_id })
|
||||||
|
.await
|
||||||
|
.unwrap_or(false);
|
||||||
|
|
||||||
|
if !connected {
|
||||||
|
self.approved_client_ids.remove(&client_id);
|
||||||
|
warn!(client_id, "operator attempted to sign for disconnected client");
|
||||||
|
return Err(SignTransactionError::ClientNotConnected);
|
||||||
|
}
|
||||||
|
|
||||||
|
info!(client_id, event = "sign_transaction", "operator.sign_transaction");
|
||||||
|
|
||||||
match self
|
match self
|
||||||
.props
|
.props
|
||||||
.actors
|
.actors
|
||||||
@@ -202,7 +232,7 @@ impl OperatorSession {
|
|||||||
use crate::db::schema::evm_wallet_access;
|
use crate::db::schema::evm_wallet_access;
|
||||||
for entry in entries {
|
for entry in entries {
|
||||||
diesel::delete(evm_wallet_access::table)
|
diesel::delete(evm_wallet_access::table)
|
||||||
.filter(evm_wallet_access::wallet_id.eq(entry))
|
.filter(evm_wallet_access::id.eq(entry))
|
||||||
.execute(&mut *conn)
|
.execute(&mut *conn)
|
||||||
.await?;
|
.await?;
|
||||||
}
|
}
|
||||||
@@ -218,8 +248,7 @@ impl OperatorSession {
|
|||||||
&mut self,
|
&mut self,
|
||||||
) -> Result<Vec<EvmWalletAccess>, Error> {
|
) -> Result<Vec<EvmWalletAccess>, Error> {
|
||||||
let mut conn = self.props.db.get().await?;
|
let mut conn = self.props.db.get().await?;
|
||||||
use crate::db::schema::evm_wallet_access;
|
let access_entries = crate::db::schema::evm_wallet_access::table
|
||||||
let access_entries = evm_wallet_access::table
|
|
||||||
.select(EvmWalletAccess::as_select())
|
.select(EvmWalletAccess::as_select())
|
||||||
.load::<_>(&mut conn)
|
.load::<_>(&mut conn)
|
||||||
.await?;
|
.await?;
|
||||||
@@ -256,6 +285,30 @@ impl OperatorSession {
|
|||||||
|
|
||||||
ctx.actor_ref().unlink(&pending_approval.controller).await;
|
ctx.actor_ref().unlink(&pending_approval.controller).await;
|
||||||
|
|
||||||
|
if approved {
|
||||||
|
let pubkey_bytes = pending_approval.pubkey.to_bytes();
|
||||||
|
match self.props.db.get().await {
|
||||||
|
Ok(mut conn) => {
|
||||||
|
match program_client::table
|
||||||
|
.filter(program_client::public_key.eq(pubkey_bytes.as_slice()))
|
||||||
|
.select(program_client::id)
|
||||||
|
.first::<i32>(&mut conn)
|
||||||
|
.await
|
||||||
|
{
|
||||||
|
Ok(client_id) => {
|
||||||
|
self.approved_client_ids.insert(client_id);
|
||||||
|
}
|
||||||
|
Err(err) => {
|
||||||
|
error!(?err, "Failed to look up client_id for approved pubkey");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Err(err) => {
|
||||||
|
error!(?err, "DB pool error after client approval");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -278,3 +331,142 @@ impl OperatorSession {
|
|||||||
Ok(clients)
|
Ok(clients)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use crate::db::{self, models::{EvmWalletId, NewEvmWalletAccess}, schema::evm_wallet_access};
|
||||||
|
use diesel::{ExpressionMethods as _, QueryDsl as _, SelectableHelper};
|
||||||
|
use diesel_async::{AsyncConnection, RunQueryDsl};
|
||||||
|
|
||||||
|
/// Regression test: revocation must delete by access-entry `id`, not by `wallet_id`.
|
||||||
|
///
|
||||||
|
/// Before the fix, revoking `entry_id=1` would delete all rows where `wallet_id=1`,
|
||||||
|
/// wiping out every client's access to wallet #1.
|
||||||
|
#[tokio::test]
|
||||||
|
async fn revoke_deletes_by_entry_id_not_wallet_id() {
|
||||||
|
use crate::db::models::EvmWalletAccess;
|
||||||
|
|
||||||
|
let pool = db::create_test_pool().await;
|
||||||
|
let mut conn = pool.get().await.expect("pool connection");
|
||||||
|
|
||||||
|
// Insert two access entries for the same wallet but different clients.
|
||||||
|
// entry A: id will be 1, wallet_id=1, client_id=10
|
||||||
|
// entry B: id will be 2, wallet_id=1, client_id=20
|
||||||
|
let entry_a = diesel::insert_into(evm_wallet_access::table)
|
||||||
|
.values(NewEvmWalletAccess {
|
||||||
|
wallet_id: EvmWalletId::from_raw(1),
|
||||||
|
client_id: 10,
|
||||||
|
})
|
||||||
|
.returning(EvmWalletAccess::as_select())
|
||||||
|
.get_result(&mut *conn)
|
||||||
|
.await
|
||||||
|
.expect("insert entry A");
|
||||||
|
|
||||||
|
let entry_b = diesel::insert_into(evm_wallet_access::table)
|
||||||
|
.values(NewEvmWalletAccess {
|
||||||
|
wallet_id: EvmWalletId::from_raw(1),
|
||||||
|
client_id: 20,
|
||||||
|
})
|
||||||
|
.returning(EvmWalletAccess::as_select())
|
||||||
|
.get_result(&mut *conn)
|
||||||
|
.await
|
||||||
|
.expect("insert entry B");
|
||||||
|
|
||||||
|
// Revoke only entry A by its primary key id.
|
||||||
|
conn.transaction(async |conn| {
|
||||||
|
diesel::delete(evm_wallet_access::table)
|
||||||
|
.filter(evm_wallet_access::id.eq(entry_a.id))
|
||||||
|
.execute(&mut *conn)
|
||||||
|
.await
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.expect("revoke entry A");
|
||||||
|
|
||||||
|
// Entry A must be gone.
|
||||||
|
let gone = evm_wallet_access::table
|
||||||
|
.filter(evm_wallet_access::id.eq(entry_a.id))
|
||||||
|
.count()
|
||||||
|
.get_result::<i64>(&mut *conn)
|
||||||
|
.await
|
||||||
|
.expect("count entry A");
|
||||||
|
assert_eq!(gone, 0, "revoked entry must be deleted");
|
||||||
|
|
||||||
|
// Entry B (same wallet, different client) must still exist.
|
||||||
|
let still_there = evm_wallet_access::table
|
||||||
|
.filter(evm_wallet_access::id.eq(entry_b.id))
|
||||||
|
.count()
|
||||||
|
.get_result::<i64>(&mut *conn)
|
||||||
|
.await
|
||||||
|
.expect("count entry B");
|
||||||
|
assert_eq!(still_there, 1, "unrelated entry must not be deleted");
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Regression test: when `entry_id` and `wallet_id` differ, only the correct row is removed.
|
||||||
|
///
|
||||||
|
/// This specifically catches the case where `entry.id=5` and `wallet_id=1` are different values;
|
||||||
|
/// the old bug would delete by `wallet_id`, potentially matching a completely different entry.
|
||||||
|
#[tokio::test]
|
||||||
|
async fn revoke_with_mismatched_wallet_and_entry_ids() {
|
||||||
|
use crate::db::models::EvmWalletAccess;
|
||||||
|
|
||||||
|
let pool = db::create_test_pool().await;
|
||||||
|
let mut conn = pool.get().await.expect("pool connection");
|
||||||
|
|
||||||
|
// Insert entries to force auto-increment IDs to diverge from wallet_ids.
|
||||||
|
// We'll insert 5 placeholder entries first so that the real entry gets id=6.
|
||||||
|
for i in 1_i32..=5 {
|
||||||
|
diesel::insert_into(evm_wallet_access::table)
|
||||||
|
.values(NewEvmWalletAccess {
|
||||||
|
wallet_id: EvmWalletId::from_raw(99),
|
||||||
|
client_id: i,
|
||||||
|
})
|
||||||
|
.execute(&mut *conn)
|
||||||
|
.await
|
||||||
|
.expect("insert placeholder");
|
||||||
|
}
|
||||||
|
|
||||||
|
// Real target: wallet_id=1, will get id=6.
|
||||||
|
let target = diesel::insert_into(evm_wallet_access::table)
|
||||||
|
.values(NewEvmWalletAccess {
|
||||||
|
wallet_id: EvmWalletId::from_raw(1),
|
||||||
|
client_id: 1,
|
||||||
|
})
|
||||||
|
.returning(EvmWalletAccess::as_select())
|
||||||
|
.get_result(&mut *conn)
|
||||||
|
.await
|
||||||
|
.expect("insert target");
|
||||||
|
|
||||||
|
// Sanity: target.id != target.wallet_id
|
||||||
|
assert_ne!(
|
||||||
|
target.id, target.wallet_id.to_raw(),
|
||||||
|
"test prerequisite: id and wallet_id must differ"
|
||||||
|
);
|
||||||
|
|
||||||
|
// Revoke by entry id.
|
||||||
|
conn.transaction(async |conn| {
|
||||||
|
diesel::delete(evm_wallet_access::table)
|
||||||
|
.filter(evm_wallet_access::id.eq(target.id))
|
||||||
|
.execute(&mut *conn)
|
||||||
|
.await
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.expect("revoke target");
|
||||||
|
|
||||||
|
let remaining = evm_wallet_access::table
|
||||||
|
.filter(evm_wallet_access::id.eq(target.id))
|
||||||
|
.count()
|
||||||
|
.get_result::<i64>(&mut *conn)
|
||||||
|
.await
|
||||||
|
.expect("count target");
|
||||||
|
assert_eq!(remaining, 0, "target must be deleted by its entry id");
|
||||||
|
|
||||||
|
// Placeholders for wallet_id=99 must be untouched.
|
||||||
|
let placeholders = evm_wallet_access::table
|
||||||
|
.filter(evm_wallet_access::wallet_id.eq(99))
|
||||||
|
.count()
|
||||||
|
.get_result::<i64>(&mut *conn)
|
||||||
|
.await
|
||||||
|
.expect("count placeholders");
|
||||||
|
assert_eq!(placeholders, 5, "unrelated entries must survive");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -1,16 +1,14 @@
|
|||||||
use super::{OutOfBand, OperatorConnection};
|
use super::{OutOfBand, OperatorConnection};
|
||||||
use crate::{
|
use crate::{
|
||||||
actors::{
|
actors::{
|
||||||
flow_coordinator::client_connect_approval::ClientApprovalController,
|
flow_coordinator::{GetConnectedClientIds, client_connect_approval::{ClientApprovalAnswer, ClientApprovalController}}, operator_registry::ConnectOperator,
|
||||||
operator_registry::ConnectOperator,
|
}, peers::client::ClientProfile,
|
||||||
},
|
|
||||||
peers::client::ClientProfile,
|
|
||||||
};
|
};
|
||||||
use arbiter_crypto::authn;
|
use arbiter_crypto::authn;
|
||||||
use arbiter_proto::transport::Sender;
|
use arbiter_proto::transport::Sender;
|
||||||
|
|
||||||
use kameo::{Actor, actor::ActorRef, messages};
|
use kameo::{Actor, actor::ActorRef, messages};
|
||||||
use std::{borrow::Cow, collections::HashMap};
|
use std::{borrow::Cow, collections::{HashMap, HashSet}};
|
||||||
use thiserror::Error;
|
use thiserror::Error;
|
||||||
use tracing::error;
|
use tracing::error;
|
||||||
|
|
||||||
@@ -54,6 +52,10 @@ pub struct OperatorSession {
|
|||||||
sender: Box<dyn Sender<OutOfBand>>,
|
sender: Box<dyn Sender<OutOfBand>>,
|
||||||
|
|
||||||
pending_client_approvals: HashMap<Vec<u8>, PendingClientApproval>,
|
pending_client_approvals: HashMap<Vec<u8>, PendingClientApproval>,
|
||||||
|
/// DB `client_ids` this operator session is allowed to sign for.
|
||||||
|
/// Seeded from currently-connected clients on start, then updated as
|
||||||
|
/// approvals are granted or denied during the session lifetime.
|
||||||
|
approved_client_ids: HashSet<i32>,
|
||||||
}
|
}
|
||||||
|
|
||||||
pub mod handlers;
|
pub mod handlers;
|
||||||
@@ -63,7 +65,8 @@ impl OperatorSession {
|
|||||||
Self {
|
Self {
|
||||||
props,
|
props,
|
||||||
sender,
|
sender,
|
||||||
pending_client_approvals: Default::default(),
|
pending_client_approvals: HashMap::default(),
|
||||||
|
approved_client_ids: HashSet::default(),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -88,6 +91,7 @@ impl OperatorSession {
|
|||||||
actor = "operator",
|
actor = "operator",
|
||||||
event = "failed to announce new client connection"
|
event = "failed to announce new client connection"
|
||||||
);
|
);
|
||||||
|
let _ = controller.tell(ClientApprovalAnswer { approved: false }).await;
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -106,7 +110,7 @@ impl Actor for OperatorSession {
|
|||||||
|
|
||||||
type Error = Error;
|
type Error = Error;
|
||||||
|
|
||||||
async fn on_start(args: Self::Args, this: ActorRef<Self>) -> Result<Self, Self::Error> {
|
async fn on_start(mut args: Self::Args, this: ActorRef<Self>) -> Result<Self, Self::Error> {
|
||||||
args.props
|
args.props
|
||||||
.actors
|
.actors
|
||||||
.operator_registry
|
.operator_registry
|
||||||
@@ -121,6 +125,16 @@ impl Actor for OperatorSession {
|
|||||||
);
|
);
|
||||||
Error::internal("Failed to register operator connection with operator registry")
|
Error::internal("Failed to register operator connection with operator registry")
|
||||||
})?;
|
})?;
|
||||||
|
|
||||||
|
// Seed approved set with clients already connected when this session starts.
|
||||||
|
// New clients will be added via handle_new_client_approve as they are approved.
|
||||||
|
match args.props.actors.flow_coordinator.ask(GetConnectedClientIds {}).await {
|
||||||
|
Ok(ids) => args.approved_client_ids.extend(ids),
|
||||||
|
Err(err) => {
|
||||||
|
error!(?err, "Failed to fetch connected client IDs on operator session start");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
Ok(args)
|
Ok(args)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -3,8 +3,9 @@ use crate::{
|
|||||||
actors::{
|
actors::{
|
||||||
GlobalActors,
|
GlobalActors,
|
||||||
vault::{self, Bootstrap, GetState, TryUnseal, VaultState, events},
|
vault::{self, Bootstrap, GetState, TryUnseal, VaultState, events},
|
||||||
|
vault_coordinator::{self, ContributeBootstrap, ContributeUnseal, StartBootstrap},
|
||||||
},
|
},
|
||||||
crypto::integrity::{self},
|
crypto::{KeyCell, integrity},
|
||||||
db::DatabasePool,
|
db::DatabasePool,
|
||||||
};
|
};
|
||||||
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
||||||
@@ -25,17 +26,29 @@ pub enum Error {
|
|||||||
AlreadyBootstrapped,
|
AlreadyBootstrapped,
|
||||||
#[error("Invalid key provided")]
|
#[error("Invalid key provided")]
|
||||||
InvalidKey,
|
InvalidKey,
|
||||||
|
#[error("Vault locked: too many failed unseal attempts")]
|
||||||
|
LockedOut,
|
||||||
#[error("State transition failed")]
|
#[error("State transition failed")]
|
||||||
State,
|
State,
|
||||||
|
#[error("Vault ceremony failed: {0}")]
|
||||||
|
Ceremony(#[from] vault_coordinator::Error),
|
||||||
#[error("Internal error: {0}")]
|
#[error("Internal error: {0}")]
|
||||||
Internal(String),
|
Internal(String),
|
||||||
}
|
}
|
||||||
|
|
||||||
impl Error {
|
impl Error {
|
||||||
fn internal(message: impl Into<String>) -> Self {
|
fn internal(message: impl Into<String>) -> Self {
|
||||||
Self::Internal(message.into())
|
Self::Internal(message.into())
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Preserve the coordinator's own error so the operator learns why a
|
||||||
|
/// ceremony was refused instead of reading "internal error".
|
||||||
|
fn ceremony<M>(error: SendError<M, vault_coordinator::Error>) -> Self {
|
||||||
|
match error {
|
||||||
|
SendError::HandlerError(inner) => Self::Ceremony(inner),
|
||||||
|
_ => Self::internal("VaultCoordinator unavailable"),
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
pub struct HandshakeResponse {
|
pub struct HandshakeResponse {
|
||||||
@@ -69,7 +82,6 @@ impl VaultGate {
|
|||||||
|
|
||||||
impl Actor for VaultGate {
|
impl Actor for VaultGate {
|
||||||
type Args = Self;
|
type Args = Self;
|
||||||
|
|
||||||
type Error = ();
|
type Error = ();
|
||||||
|
|
||||||
async fn on_start(
|
async fn on_start(
|
||||||
@@ -100,11 +112,8 @@ impl VaultGate {
|
|||||||
associated_data: &[u8],
|
associated_data: &[u8],
|
||||||
) -> Result<SafeCell<Vec<u8>>, ()> {
|
) -> Result<SafeCell<Vec<u8>>, ()> {
|
||||||
let nonce = XNonce::from_slice(nonce);
|
let nonce = XNonce::from_slice(nonce);
|
||||||
|
|
||||||
let cipher = XChaCha20Poly1305::new(secret.as_bytes().into());
|
let cipher = XChaCha20Poly1305::new(secret.as_bytes().into());
|
||||||
|
|
||||||
let mut key_buffer = SafeCell::new(ciphertext.to_vec());
|
let mut key_buffer = SafeCell::new(ciphertext.to_vec());
|
||||||
|
|
||||||
let decryption_result = key_buffer.write_inline(|write_handle| {
|
let decryption_result = key_buffer.write_inline(|write_handle| {
|
||||||
cipher.decrypt_in_place(nonce, associated_data, write_handle)
|
cipher.decrypt_in_place(nonce, associated_data, write_handle)
|
||||||
});
|
});
|
||||||
@@ -117,9 +126,13 @@ impl VaultGate {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
fn key_cell(buffer: SafeCell<Vec<u8>>) -> Result<KeyCell, Error> {
|
||||||
|
KeyCell::try_from(buffer).map_err(|()| Error::InvalidKey)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#[messages(messages = Inbound, replies = Outbound)]
|
#[messages]
|
||||||
impl VaultGate {
|
impl VaultGate {
|
||||||
#[message]
|
#[message]
|
||||||
pub fn handle_handshake(
|
pub fn handle_handshake(
|
||||||
@@ -128,14 +141,11 @@ impl VaultGate {
|
|||||||
) -> Result<HandshakeResponse, Error> {
|
) -> Result<HandshakeResponse, Error> {
|
||||||
let ephemeral_secret = EphemeralSecret::random();
|
let ephemeral_secret = EphemeralSecret::random();
|
||||||
let public_key = PublicKey::from(&ephemeral_secret);
|
let public_key = PublicKey::from(&ephemeral_secret);
|
||||||
|
|
||||||
let secret = ephemeral_secret.diffie_hellman(&client_pubkey);
|
let secret = ephemeral_secret.diffie_hellman(&client_pubkey);
|
||||||
|
|
||||||
self.state = State::ReadyForExchange {
|
self.state = State::ReadyForExchange {
|
||||||
server_key: public_key,
|
server_key: public_key,
|
||||||
secret,
|
secret,
|
||||||
};
|
};
|
||||||
|
|
||||||
Ok(HandshakeResponse {
|
Ok(HandshakeResponse {
|
||||||
server_pubkey: public_key,
|
server_pubkey: public_key,
|
||||||
})
|
})
|
||||||
@@ -151,25 +161,17 @@ impl VaultGate {
|
|||||||
let State::ReadyForExchange { secret, .. } = &self.state else {
|
let State::ReadyForExchange { secret, .. } = &self.state else {
|
||||||
return Err(Error::State);
|
return Err(Error::State);
|
||||||
};
|
};
|
||||||
|
let seal_key = Self::decrypt_key(secret, &nonce, &ciphertext, &associated_data)
|
||||||
|
.map_err(|()| Error::InvalidKey)
|
||||||
|
.and_then(Self::key_cell)?;
|
||||||
|
|
||||||
let Ok(seal_key_buffer) = Self::decrypt_key(secret, &nonce, &ciphertext, &associated_data)
|
match self.actors.vault.ask(TryUnseal { seal_key }).await {
|
||||||
else {
|
|
||||||
return Err(Error::InvalidKey);
|
|
||||||
};
|
|
||||||
|
|
||||||
match self
|
|
||||||
.actors
|
|
||||||
.vault
|
|
||||||
.ask(TryUnseal {
|
|
||||||
seal_key_raw: seal_key_buffer,
|
|
||||||
})
|
|
||||||
.await
|
|
||||||
{
|
|
||||||
Ok(()) => {
|
Ok(()) => {
|
||||||
info!("Successfully unsealed key with client-provided key");
|
info!("Successfully unsealed key with client-provided key");
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
Err(SendError::HandlerError(vault::Error::InvalidKey)) => Err(Error::InvalidKey),
|
Err(SendError::HandlerError(vault::Error::InvalidKey)) => Err(Error::InvalidKey),
|
||||||
|
Err(SendError::HandlerError(vault::Error::LockedOut)) => Err(Error::LockedOut),
|
||||||
Err(SendError::HandlerError(err)) => {
|
Err(SendError::HandlerError(err)) => {
|
||||||
error!(?err, "Vault failed to unseal key");
|
error!(?err, "Vault failed to unseal key");
|
||||||
Err(Error::InvalidKey)
|
Err(Error::InvalidKey)
|
||||||
@@ -191,17 +193,16 @@ impl VaultGate {
|
|||||||
let State::ReadyForExchange { secret, .. } = &self.state else {
|
let State::ReadyForExchange { secret, .. } = &self.state else {
|
||||||
return Err(Error::State);
|
return Err(Error::State);
|
||||||
};
|
};
|
||||||
|
let seal_key = Self::decrypt_key(secret, &nonce, &ciphertext, &associated_data)
|
||||||
let Ok(seal_key_buffer) = Self::decrypt_key(secret, &nonce, &ciphertext, &associated_data)
|
.map_err(|()| Error::InvalidKey)
|
||||||
else {
|
.and_then(Self::key_cell)?;
|
||||||
return Err(Error::InvalidKey);
|
|
||||||
};
|
|
||||||
|
|
||||||
match self
|
match self
|
||||||
.actors
|
.actors
|
||||||
.vault
|
.vault
|
||||||
.ask(Bootstrap {
|
.ask(Bootstrap {
|
||||||
seal_key_raw: seal_key_buffer,
|
seal_key,
|
||||||
|
custody: None,
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
{
|
{
|
||||||
@@ -225,14 +226,53 @@ impl VaultGate {
|
|||||||
|
|
||||||
#[message]
|
#[message]
|
||||||
pub async fn handle_vault_state(&mut self) -> Result<VaultState, Error> {
|
pub async fn handle_vault_state(&mut self) -> Result<VaultState, Error> {
|
||||||
let answer = self
|
self.actors
|
||||||
.actors
|
|
||||||
.vault
|
.vault
|
||||||
.ask(GetState {})
|
.ask(GetState {})
|
||||||
.await
|
.await
|
||||||
.map_err(|_| Error::internal("failed to query vault"))?;
|
.map_err(|_| Error::internal("failed to query vault"))
|
||||||
|
}
|
||||||
|
|
||||||
Ok(answer)
|
#[message]
|
||||||
|
pub async fn handle_declare_committee(&mut self, count: usize) -> Result<(), Error> {
|
||||||
|
self.actors
|
||||||
|
.vault_coordinator
|
||||||
|
.ask(StartBootstrap {
|
||||||
|
operator_id: self.auth_creds.id,
|
||||||
|
declared_count: count,
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.map_err(Error::ceremony)
|
||||||
|
}
|
||||||
|
|
||||||
|
#[message]
|
||||||
|
pub async fn handle_contribute_bootstrap_passphrase(
|
||||||
|
&mut self,
|
||||||
|
passphrase: Vec<u8>,
|
||||||
|
) -> Result<bool, Error> {
|
||||||
|
self.actors
|
||||||
|
.vault_coordinator
|
||||||
|
.ask(ContributeBootstrap {
|
||||||
|
operator_id: self.auth_creds.id,
|
||||||
|
passphrase: SafeCell::new(passphrase),
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.map_err(Error::ceremony)
|
||||||
|
}
|
||||||
|
|
||||||
|
#[message]
|
||||||
|
pub async fn handle_contribute_unseal_passphrase(
|
||||||
|
&mut self,
|
||||||
|
passphrase: Vec<u8>,
|
||||||
|
) -> Result<bool, Error> {
|
||||||
|
self.actors
|
||||||
|
.vault_coordinator
|
||||||
|
.ask(ContributeUnseal {
|
||||||
|
operator_id: self.auth_creds.id,
|
||||||
|
passphrase: SafeCell::new(passphrase),
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.map_err(Error::ceremony)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -286,3 +326,75 @@ impl Message<events::Unsealed> for VaultGate {
|
|||||||
ctx.stop();
|
ctx.stop();
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
pub enum Inbound {
|
||||||
|
HandleHandshake(HandleHandshake),
|
||||||
|
HandleUnsealEncryptedKey(HandleUnsealEncryptedKey),
|
||||||
|
HandleBootstrapEncryptedKey(HandleBootstrapEncryptedKey),
|
||||||
|
HandleVaultState,
|
||||||
|
HandleDeclareCommittee(HandleDeclareCommittee),
|
||||||
|
HandleContributeBootstrapPassphrase(HandleContributeBootstrapPassphrase),
|
||||||
|
HandleContributeUnsealPassphrase(HandleContributeUnsealPassphrase),
|
||||||
|
}
|
||||||
|
|
||||||
|
pub enum Outbound {
|
||||||
|
HandleHandshake(Result<HandshakeResponse, Error>),
|
||||||
|
HandleUnsealEncryptedKey(Result<(), Error>),
|
||||||
|
HandleBootstrapEncryptedKey(Result<(), Error>),
|
||||||
|
HandleVaultState(Result<VaultState, Error>),
|
||||||
|
HandleDeclareCommittee(Result<(), Error>),
|
||||||
|
HandleContributeBootstrapPassphrase(Result<bool, Error>),
|
||||||
|
HandleContributeUnsealPassphrase(Result<bool, Error>),
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Message<Inbound> for VaultGate {
|
||||||
|
type Reply = Result<Outbound, Error>;
|
||||||
|
|
||||||
|
async fn handle(
|
||||||
|
&mut self,
|
||||||
|
msg: Inbound,
|
||||||
|
_ctx: &mut kameo::prelude::Context<Self, Self::Reply>,
|
||||||
|
) -> Self::Reply {
|
||||||
|
match msg {
|
||||||
|
Inbound::HandleHandshake(message) => Ok(Outbound::HandleHandshake(
|
||||||
|
self.handle_handshake(message.client_pubkey),
|
||||||
|
)),
|
||||||
|
Inbound::HandleUnsealEncryptedKey(message) => Ok(Outbound::HandleUnsealEncryptedKey(
|
||||||
|
self.handle_unseal_encrypted_key(
|
||||||
|
message.nonce,
|
||||||
|
message.ciphertext,
|
||||||
|
message.associated_data,
|
||||||
|
)
|
||||||
|
.await,
|
||||||
|
)),
|
||||||
|
Inbound::HandleBootstrapEncryptedKey(message) => {
|
||||||
|
Ok(Outbound::HandleBootstrapEncryptedKey(
|
||||||
|
self.handle_bootstrap_encrypted_key(
|
||||||
|
message.nonce,
|
||||||
|
message.ciphertext,
|
||||||
|
message.associated_data,
|
||||||
|
)
|
||||||
|
.await,
|
||||||
|
))
|
||||||
|
}
|
||||||
|
Inbound::HandleVaultState => {
|
||||||
|
Ok(Outbound::HandleVaultState(self.handle_vault_state().await))
|
||||||
|
}
|
||||||
|
Inbound::HandleDeclareCommittee(message) => Ok(Outbound::HandleDeclareCommittee(
|
||||||
|
self.handle_declare_committee(message.count).await,
|
||||||
|
)),
|
||||||
|
Inbound::HandleContributeBootstrapPassphrase(message) => {
|
||||||
|
Ok(Outbound::HandleContributeBootstrapPassphrase(
|
||||||
|
self.handle_contribute_bootstrap_passphrase(message.passphrase)
|
||||||
|
.await,
|
||||||
|
))
|
||||||
|
}
|
||||||
|
Inbound::HandleContributeUnsealPassphrase(message) => {
|
||||||
|
Ok(Outbound::HandleContributeUnsealPassphrase(
|
||||||
|
self.handle_contribute_unseal_passphrase(message.passphrase)
|
||||||
|
.await,
|
||||||
|
))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -1,15 +1,12 @@
|
|||||||
use super::common::ChannelTransport;
|
use super::common::ChannelTransport;
|
||||||
use arbiter_crypto::{
|
use arbiter_crypto::authn::{self, AuthChallenge, CLIENT_CONTEXT};
|
||||||
authn::{self, AuthChallenge, CLIENT_CONTEXT},
|
|
||||||
safecell::{SafeCell, SafeCellHandle as _},
|
|
||||||
};
|
|
||||||
use arbiter_proto::{
|
use arbiter_proto::{
|
||||||
ClientMetadata,
|
ClientMetadata,
|
||||||
transport::{Receiver, Sender},
|
transport::{Receiver, Sender},
|
||||||
};
|
};
|
||||||
use arbiter_server::{
|
use arbiter_server::{
|
||||||
actors::{GlobalActors, vault::Bootstrap},
|
actors::{GlobalActors, vault::Bootstrap},
|
||||||
crypto::integrity,
|
crypto::{KeyCell, integrity},
|
||||||
db::{self, schema},
|
db::{self, schema},
|
||||||
peers::client::{ClientConnection, ClientCredentials, auth, connect_client},
|
peers::client::{ClientConnection, ClientCredentials, auth, connect_client},
|
||||||
};
|
};
|
||||||
@@ -100,7 +97,8 @@ async fn spawn_test_actors(db: &db::DatabasePool) -> GlobalActors {
|
|||||||
actors
|
actors
|
||||||
.vault
|
.vault
|
||||||
.ask(Bootstrap {
|
.ask(Bootstrap {
|
||||||
seal_key_raw: SafeCell::new(b"test-seal-key".to_vec()),
|
seal_key: KeyCell::from([0u8; 32]),
|
||||||
|
custody: None,
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
@@ -266,7 +264,7 @@ pub async fn metadata_unchanged_does_not_append_history() {
|
|||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
pub async fn metadata_change_appends_history_and_repoints_binding() {
|
pub async fn metadata_frozen_after_approval_ignores_reconnect_changes() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
let actors = spawn_test_actors(&db).await;
|
let actors = spawn_test_actors(&db).await;
|
||||||
let new_key = MlDsa87::key_gen(&mut rand::rng());
|
let new_key = MlDsa87::key_gen(&mut rand::rng());
|
||||||
@@ -287,6 +285,7 @@ pub async fn metadata_change_appends_history_and_repoints_binding() {
|
|||||||
connect_client(props, &mut server_transport).await;
|
connect_client(props, &mut server_transport).await;
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// Reconnect presenting different metadata — must be silently ignored.
|
||||||
test_transport
|
test_transport
|
||||||
.send(auth::Inbound::AuthChallengeRequest {
|
.send(auth::Inbound::AuthChallengeRequest {
|
||||||
pubkey: verifying_key(&new_key).into(),
|
pubkey: verifying_key(&new_key).into(),
|
||||||
@@ -313,6 +312,7 @@ pub async fn metadata_change_appends_history_and_repoints_binding() {
|
|||||||
client_metadata, client_metadata_history, program_client,
|
client_metadata, client_metadata_history, program_client,
|
||||||
};
|
};
|
||||||
let mut conn = db.get().await.unwrap();
|
let mut conn = db.get().await.unwrap();
|
||||||
|
// Metadata is frozen: no new row, no history entry.
|
||||||
let metadata_count: i64 = client_metadata::table
|
let metadata_count: i64 = client_metadata::table
|
||||||
.count()
|
.count()
|
||||||
.get_result(&mut conn)
|
.get_result(&mut conn)
|
||||||
@@ -338,15 +338,19 @@ pub async fn metadata_change_appends_history_and_repoints_binding() {
|
|||||||
.first::<(String, Option<String>, Option<String>)>(&mut conn)
|
.first::<(String, Option<String>, Option<String>)>(&mut conn)
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
assert_eq!(metadata_count, 2);
|
assert_eq!(
|
||||||
assert_eq!(history_count, 1);
|
metadata_count, 1,
|
||||||
|
"frozen: no new metadata row on reconnect"
|
||||||
|
);
|
||||||
|
assert_eq!(history_count, 0, "frozen: no history entry on reconnect");
|
||||||
assert_eq!(
|
assert_eq!(
|
||||||
current,
|
current,
|
||||||
(
|
(
|
||||||
"client".to_owned(),
|
"client".to_owned(),
|
||||||
Some("new".to_owned()),
|
Some("old".to_owned()),
|
||||||
Some("2.0.0".to_owned())
|
Some("1.0.0".to_owned())
|
||||||
)
|
),
|
||||||
|
"frozen: original metadata must be preserved"
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,10 +2,11 @@
|
|||||||
dead_code,
|
dead_code,
|
||||||
reason = "Common test utilities that may not be used in every test"
|
reason = "Common test utilities that may not be used in every test"
|
||||||
)]
|
)]
|
||||||
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
|
||||||
use arbiter_proto::transport::{Bi, Error, Receiver, Sender};
|
use arbiter_proto::transport::{Bi, Error, Receiver, Sender};
|
||||||
use arbiter_server::{
|
use arbiter_server::{
|
||||||
actors::{GlobalActors, vault::Vault},
|
actors::{GlobalActors, vault::Vault},
|
||||||
|
crypto::KeyCell,
|
||||||
db::{self, schema},
|
db::{self, schema},
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -19,7 +20,7 @@ pub(crate) async fn bootstrapped_vault(db: &db::DatabasePool) -> Vault {
|
|||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
actor
|
actor
|
||||||
.bootstrap(SafeCell::new(b"test-seal-key".to_vec()))
|
.bootstrap(KeyCell::from([0u8; 32]), None)
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
actor
|
actor
|
||||||
|
|||||||
@@ -1,13 +1,10 @@
|
|||||||
use super::common::ChannelTransport;
|
use super::common::ChannelTransport;
|
||||||
use arbiter_crypto::{
|
use arbiter_crypto::authn::{self, AuthChallenge, OPERATOR_CONTEXT};
|
||||||
authn::{self, AuthChallenge, OPERATOR_CONTEXT},
|
|
||||||
safecell::{SafeCell, SafeCellHandle as _},
|
|
||||||
};
|
|
||||||
use arbiter_proto::transport::{Error as TransportError, Receiver, Sender};
|
use arbiter_proto::transport::{Error as TransportError, Receiver, Sender};
|
||||||
use arbiter_server::{
|
use arbiter_server::{
|
||||||
actors::{GlobalActors, bootstrap::GetToken, vault::Bootstrap},
|
actors::{GlobalActors, bootstrap::GetToken, vault::Bootstrap},
|
||||||
crypto::integrity,
|
crypto::{KeyCell, integrity},
|
||||||
db::{self, schema},
|
db::{self, models::OperatorId, schema},
|
||||||
peers::operator::{self, Credentials, OperatorConnection, auth, vault_gate},
|
peers::operator::{self, Credentials, OperatorConnection, auth, vault_gate},
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -154,13 +151,6 @@ impl Sender<auth::Inbound> for StartTestTransport {
|
|||||||
pub async fn bootstrap_token_auth() {
|
pub async fn bootstrap_token_auth() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
let actors = GlobalActors::spawn(db.clone()).await.unwrap();
|
let actors = GlobalActors::spawn(db.clone()).await.unwrap();
|
||||||
actors
|
|
||||||
.vault
|
|
||||||
.ask(Bootstrap {
|
|
||||||
seal_key_raw: SafeCell::new(b"test-seal-key".to_vec()),
|
|
||||||
})
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
let token = actors.bootstrapper.ask(GetToken).await.unwrap().unwrap();
|
let token = actors.bootstrapper.ask(GetToken).await.unwrap().unwrap();
|
||||||
|
|
||||||
let (mut server_transport, mut test_transport) = ChannelTransport::new();
|
let (mut server_transport, mut test_transport) = ChannelTransport::new();
|
||||||
@@ -174,7 +164,7 @@ pub async fn bootstrap_token_auth() {
|
|||||||
test_transport
|
test_transport
|
||||||
.send(auth::Inbound::AuthChallengeRequest {
|
.send(auth::Inbound::AuthChallengeRequest {
|
||||||
pubkey: verifying_key(&new_key).into(),
|
pubkey: verifying_key(&new_key).into(),
|
||||||
bootstrap_token: Some(token),
|
bootstrap_token: Some(token.into_bytes()),
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
@@ -231,7 +221,7 @@ pub async fn bootstrap_invalid_token_auth() {
|
|||||||
test_transport
|
test_transport
|
||||||
.send(auth::Inbound::AuthChallengeRequest {
|
.send(auth::Inbound::AuthChallengeRequest {
|
||||||
pubkey: verifying_key(&new_key).into(),
|
pubkey: verifying_key(&new_key).into(),
|
||||||
bootstrap_token: Some("invalid_token".to_owned()),
|
bootstrap_token: Some(b"invalid_token".to_vec()),
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
@@ -275,7 +265,8 @@ pub async fn challenge_auth() {
|
|||||||
actors
|
actors
|
||||||
.vault
|
.vault
|
||||||
.ask(Bootstrap {
|
.ask(Bootstrap {
|
||||||
seal_key_raw: SafeCell::new(b"test-seal-key".to_vec()),
|
seal_key: KeyCell::from([0u8; 32]),
|
||||||
|
custody: None,
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
@@ -285,10 +276,10 @@ pub async fn challenge_auth() {
|
|||||||
|
|
||||||
{
|
{
|
||||||
let mut conn = db.get().await.unwrap();
|
let mut conn = db.get().await.unwrap();
|
||||||
let id: i32 = insert_into(schema::operator_identity::table)
|
let id: OperatorId = insert_into(schema::operator_identity::table)
|
||||||
.values((schema::operator_identity::public_key.eq(pubkey_bytes.clone()),))
|
.values((schema::operator_identity::public_key.eq(pubkey_bytes.clone()),))
|
||||||
.returning(schema::operator_identity::id)
|
.returning(schema::operator_identity::id)
|
||||||
.get_result(&mut conn)
|
.get_result::<OperatorId>(&mut conn)
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
integrity::sign_entity(
|
integrity::sign_entity(
|
||||||
@@ -361,7 +352,8 @@ pub async fn challenge_auth_rejects_integrity_tag_mismatch_when_unsealed() {
|
|||||||
actors
|
actors
|
||||||
.vault
|
.vault
|
||||||
.ask(Bootstrap {
|
.ask(Bootstrap {
|
||||||
seal_key_raw: SafeCell::new(b"test-seal-key".to_vec()),
|
seal_key: KeyCell::from([0u8; 32]),
|
||||||
|
custody: None,
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
@@ -400,7 +392,7 @@ pub async fn challenge_auth_rejects_integrity_tag_mismatch_when_unsealed() {
|
|||||||
let challenge = match response {
|
let challenge = match response {
|
||||||
Ok(resp) => match resp {
|
Ok(resp) => match resp {
|
||||||
auth::Outbound::AuthChallenge { challenge } => challenge,
|
auth::Outbound::AuthChallenge { challenge } => challenge,
|
||||||
other => panic!("Expected AuthChallenge, got {other:?}"),
|
other @ auth::Outbound::AuthSuccess => panic!("Expected AuthChallenge, got {other:?}"),
|
||||||
},
|
},
|
||||||
Err(err) => panic!("Expected Ok response, got Err({err:?})"),
|
Err(err) => panic!("Expected Ok response, got Err({err:?})"),
|
||||||
};
|
};
|
||||||
@@ -434,7 +426,8 @@ pub async fn challenge_auth_rejects_invalid_signature() {
|
|||||||
actors
|
actors
|
||||||
.vault
|
.vault
|
||||||
.ask(Bootstrap {
|
.ask(Bootstrap {
|
||||||
seal_key_raw: SafeCell::new(b"test-seal-key".to_vec()),
|
seal_key: KeyCell::from([0u8; 32]),
|
||||||
|
custody: None,
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
@@ -444,10 +437,10 @@ pub async fn challenge_auth_rejects_invalid_signature() {
|
|||||||
|
|
||||||
{
|
{
|
||||||
let mut conn = db.get().await.unwrap();
|
let mut conn = db.get().await.unwrap();
|
||||||
let id: i32 = insert_into(schema::operator_identity::table)
|
let id: OperatorId = insert_into(schema::operator_identity::table)
|
||||||
.values((schema::operator_identity::public_key.eq(pubkey_bytes.clone()),))
|
.values((schema::operator_identity::public_key.eq(pubkey_bytes.clone()),))
|
||||||
.returning(schema::operator_identity::id)
|
.returning(schema::operator_identity::id)
|
||||||
.get_result(&mut conn)
|
.get_result::<OperatorId>(&mut conn)
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
integrity::sign_entity(
|
integrity::sign_entity(
|
||||||
@@ -506,3 +499,92 @@ pub async fn challenge_auth_rejects_invalid_signature() {
|
|||||||
Err(auth::Error::InvalidChallengeSolution)
|
Err(auth::Error::InvalidChallengeSolution)
|
||||||
));
|
));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// The bootstrap token authorises registering committee members *before* the
|
||||||
|
/// vault exists. Once any bootstrap path succeeds it must stop working, or its
|
||||||
|
/// holder could keep minting operator identities until the next restart.
|
||||||
|
#[tokio::test]
|
||||||
|
#[test_log::test]
|
||||||
|
pub async fn bootstrap_token_rejected_after_bootstrap() {
|
||||||
|
let db = db::create_test_pool().await;
|
||||||
|
let actors = GlobalActors::spawn(db.clone()).await.unwrap();
|
||||||
|
let token = actors.bootstrapper.ask(GetToken).await.unwrap().unwrap();
|
||||||
|
|
||||||
|
actors
|
||||||
|
.vault
|
||||||
|
.ask(Bootstrap {
|
||||||
|
seal_key: KeyCell::from([0u8; 32]),
|
||||||
|
custody: None,
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
// `Bootstrapped` travels through the message bus, so the token disappears
|
||||||
|
// a couple of actor turns after the bootstrap call returns.
|
||||||
|
let mut retired = false;
|
||||||
|
for _ in 0..100 {
|
||||||
|
if actors.bootstrapper.ask(GetToken).await.unwrap().is_none() {
|
||||||
|
retired = true;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
tokio::task::yield_now().await;
|
||||||
|
}
|
||||||
|
assert!(
|
||||||
|
retired,
|
||||||
|
"the bootstrap token must be retired once the vault is bootstrapped"
|
||||||
|
);
|
||||||
|
|
||||||
|
let (mut server_transport, mut test_transport) = ChannelTransport::new();
|
||||||
|
let db_for_task = db.clone();
|
||||||
|
let task = tokio::spawn(async move {
|
||||||
|
let mut props = OperatorConnection::new(db_for_task, actors);
|
||||||
|
auth::authenticate(&mut props, &mut server_transport).await
|
||||||
|
});
|
||||||
|
|
||||||
|
let new_key = MlDsa87::key_gen(&mut rand::rng());
|
||||||
|
test_transport
|
||||||
|
.send(auth::Inbound::AuthChallengeRequest {
|
||||||
|
pubkey: verifying_key(&new_key).into(),
|
||||||
|
bootstrap_token: Some(token.into_bytes()),
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
let response = test_transport
|
||||||
|
.recv()
|
||||||
|
.await
|
||||||
|
.expect("should receive challenge");
|
||||||
|
let challenge = match response {
|
||||||
|
Ok(auth::Outbound::AuthChallenge { challenge }) => challenge,
|
||||||
|
other => panic!("Expected AuthChallenge, got {other:?}"),
|
||||||
|
};
|
||||||
|
|
||||||
|
let signature = sign_operator_challenge(&new_key, &challenge);
|
||||||
|
test_transport
|
||||||
|
.send(auth::Inbound::AuthChallengeSolution {
|
||||||
|
signature: signature.to_bytes(),
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
let response = test_transport
|
||||||
|
.recv()
|
||||||
|
.await
|
||||||
|
.expect("should receive auth result");
|
||||||
|
assert!(
|
||||||
|
matches!(response, Err(auth::Error::InvalidBootstrapToken)),
|
||||||
|
"a spent bootstrap token must not authorise a new identity, got {response:?}"
|
||||||
|
);
|
||||||
|
assert!(task.await.unwrap().is_err(), "authentication must fail");
|
||||||
|
|
||||||
|
let mut conn = db.get().await.unwrap();
|
||||||
|
let registered: i64 = schema::operator_identity::table
|
||||||
|
.count()
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert_eq!(
|
||||||
|
registered, 0,
|
||||||
|
"no identity may be registered after the bootstrap"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|||||||
@@ -1,13 +1,11 @@
|
|||||||
use arbiter_crypto::{
|
use arbiter_crypto::authn;
|
||||||
authn,
|
|
||||||
safecell::{SafeCell, SafeCellHandle as _},
|
|
||||||
};
|
|
||||||
use arbiter_server::{
|
use arbiter_server::{
|
||||||
actors::{
|
actors::{
|
||||||
GlobalActors,
|
GlobalActors,
|
||||||
vault::{Bootstrap, Seal},
|
vault::{Bootstrap, Seal},
|
||||||
},
|
},
|
||||||
db,
|
crypto::KeyCell,
|
||||||
|
db::{self, models::OperatorId},
|
||||||
peers::operator::{
|
peers::operator::{
|
||||||
Credentials,
|
Credentials,
|
||||||
vault_gate::{
|
vault_gate::{
|
||||||
@@ -22,7 +20,7 @@ use tokio::sync::oneshot;
|
|||||||
use x25519_dalek::{EphemeralSecret, PublicKey};
|
use x25519_dalek::{EphemeralSecret, PublicKey};
|
||||||
|
|
||||||
async fn setup_sealed_gate(
|
async fn setup_sealed_gate(
|
||||||
seal_key: &[u8],
|
seal_key: [u8; 32],
|
||||||
) -> (
|
) -> (
|
||||||
db::DatabasePool,
|
db::DatabasePool,
|
||||||
kameo::actor::ActorRef<VaultGate>,
|
kameo::actor::ActorRef<VaultGate>,
|
||||||
@@ -34,7 +32,8 @@ async fn setup_sealed_gate(
|
|||||||
actors
|
actors
|
||||||
.vault
|
.vault
|
||||||
.ask(Bootstrap {
|
.ask(Bootstrap {
|
||||||
seal_key_raw: SafeCell::new(seal_key.to_vec()),
|
seal_key: KeyCell::from(seal_key),
|
||||||
|
custody: None,
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
@@ -42,7 +41,10 @@ async fn setup_sealed_gate(
|
|||||||
|
|
||||||
let (promotion_tx, promotion_rx) = oneshot::channel();
|
let (promotion_tx, promotion_rx) = oneshot::channel();
|
||||||
let pubkey = authn::SigningKey::generate().public_key();
|
let pubkey = authn::SigningKey::generate().public_key();
|
||||||
let auth_creds = Credentials { id: 1, pubkey };
|
let auth_creds = Credentials {
|
||||||
|
id: OperatorId::from_raw(1),
|
||||||
|
pubkey,
|
||||||
|
};
|
||||||
let gate = VaultGate::spawn(VaultGate::new(auth_creds, actors, db.clone(), promotion_tx));
|
let gate = VaultGate::spawn(VaultGate::new(auth_creds, actors, db.clone(), promotion_tx));
|
||||||
|
|
||||||
(db, gate, promotion_rx)
|
(db, gate, promotion_rx)
|
||||||
@@ -83,10 +85,10 @@ async fn client_dh_encrypt(
|
|||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
pub async fn unseal_success() {
|
pub async fn unseal_success() {
|
||||||
let seal_key = b"test-seal-key";
|
let seal_key = [7u8; 32];
|
||||||
let (_db, gate, _promotion_rx) = setup_sealed_gate(seal_key).await;
|
let (_db, gate, _promotion_rx) = setup_sealed_gate(seal_key).await;
|
||||||
|
|
||||||
let encrypted_key = client_dh_encrypt(&gate, seal_key).await;
|
let encrypted_key = client_dh_encrypt(&gate, &seal_key).await;
|
||||||
|
|
||||||
let response = gate.ask(encrypted_key).await;
|
let response = gate.ask(encrypted_key).await;
|
||||||
assert!(matches!(response, Ok(())));
|
assert!(matches!(response, Ok(())));
|
||||||
@@ -95,10 +97,10 @@ pub async fn unseal_success() {
|
|||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
pub async fn unseal_wrong_seal_key() {
|
pub async fn unseal_wrong_seal_key() {
|
||||||
let seal_key = b"test-seal-key";
|
let seal_key = [7u8; 32];
|
||||||
let (_db, gate, _promotion_rx) = setup_sealed_gate(seal_key).await;
|
let (_db, gate, _promotion_rx) = setup_sealed_gate(seal_key).await;
|
||||||
|
|
||||||
let encrypted_key = client_dh_encrypt(&gate, b"wrong-key").await;
|
let encrypted_key = client_dh_encrypt(&gate, &[8u8; 32]).await;
|
||||||
|
|
||||||
let response = gate.ask(encrypted_key).await;
|
let response = gate.ask(encrypted_key).await;
|
||||||
assert!(matches!(
|
assert!(matches!(
|
||||||
@@ -112,7 +114,7 @@ pub async fn unseal_wrong_seal_key() {
|
|||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
pub async fn unseal_corrupted_ciphertext() {
|
pub async fn unseal_corrupted_ciphertext() {
|
||||||
let seal_key = b"test-seal-key";
|
let seal_key = [7u8; 32];
|
||||||
let (_db, gate, _promotion_rx) = setup_sealed_gate(seal_key).await;
|
let (_db, gate, _promotion_rx) = setup_sealed_gate(seal_key).await;
|
||||||
|
|
||||||
let client_secret = EphemeralSecret::random();
|
let client_secret = EphemeralSecret::random();
|
||||||
@@ -143,11 +145,11 @@ pub async fn unseal_corrupted_ciphertext() {
|
|||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
pub async fn unseal_retry_after_invalid_key() {
|
pub async fn unseal_retry_after_invalid_key() {
|
||||||
let seal_key = b"real-seal-key";
|
let seal_key = [9u8; 32];
|
||||||
let (_db, gate, _promotion_rx) = setup_sealed_gate(seal_key).await;
|
let (_db, gate, _promotion_rx) = setup_sealed_gate(seal_key).await;
|
||||||
|
|
||||||
{
|
{
|
||||||
let encrypted_key = client_dh_encrypt(&gate, b"wrong-key").await;
|
let encrypted_key = client_dh_encrypt(&gate, &[8u8; 32]).await;
|
||||||
|
|
||||||
let response = gate.ask(encrypted_key).await;
|
let response = gate.ask(encrypted_key).await;
|
||||||
assert!(matches!(
|
assert!(matches!(
|
||||||
@@ -159,7 +161,7 @@ pub async fn unseal_retry_after_invalid_key() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
{
|
{
|
||||||
let encrypted_key = client_dh_encrypt(&gate, seal_key).await;
|
let encrypted_key = client_dh_encrypt(&gate, &seal_key).await;
|
||||||
|
|
||||||
let response = gate.ask(encrypted_key).await;
|
let response = gate.ask(encrypted_key).await;
|
||||||
assert!(matches!(response, Ok(())));
|
assert!(matches!(response, Ok(())));
|
||||||
|
|||||||
@@ -2,6 +2,8 @@ mod common;
|
|||||||
|
|
||||||
#[path = "vault/concurrency.rs"]
|
#[path = "vault/concurrency.rs"]
|
||||||
mod concurrency;
|
mod concurrency;
|
||||||
|
#[path = "vault/custody.rs"]
|
||||||
|
mod custody;
|
||||||
#[path = "vault/lifecycle.rs"]
|
#[path = "vault/lifecycle.rs"]
|
||||||
mod lifecycle;
|
mod lifecycle;
|
||||||
#[path = "vault/storage.rs"]
|
#[path = "vault/storage.rs"]
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ use arbiter_server::{
|
|||||||
GlobalActors,
|
GlobalActors,
|
||||||
vault::{CreateNew, Error, Vault},
|
vault::{CreateNew, Error, Vault},
|
||||||
},
|
},
|
||||||
|
crypto::KeyCell,
|
||||||
db::{self, models, schema},
|
db::{self, models, schema},
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -14,6 +15,8 @@ use kameo::actor::{ActorRef, Spawn as _};
|
|||||||
use std::collections::{HashMap, HashSet};
|
use std::collections::{HashMap, HashSet};
|
||||||
use tokio::task::JoinSet;
|
use tokio::task::JoinSet;
|
||||||
|
|
||||||
|
const TEST_AAD: &[u8] = b"test-aad";
|
||||||
|
|
||||||
async fn write_concurrently(
|
async fn write_concurrently(
|
||||||
actor: ActorRef<Vault>,
|
actor: ActorRef<Vault>,
|
||||||
prefix: &'static str,
|
prefix: &'static str,
|
||||||
@@ -27,6 +30,7 @@ async fn write_concurrently(
|
|||||||
let id = actor
|
let id = actor
|
||||||
.ask(CreateNew {
|
.ask(CreateNew {
|
||||||
plaintext: SafeCell::new(plaintext.clone()),
|
plaintext: SafeCell::new(plaintext.clone()),
|
||||||
|
aad: TEST_AAD.to_vec(),
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
@@ -120,7 +124,7 @@ async fn insert_failure_does_not_create_partial_row() {
|
|||||||
drop(conn);
|
drop(conn);
|
||||||
|
|
||||||
let err = actor
|
let err = actor
|
||||||
.create_new(SafeCell::new(b"should fail".to_vec()))
|
.create_new(SafeCell::new(b"should fail".to_vec()), TEST_AAD.to_vec())
|
||||||
.await
|
.await
|
||||||
.unwrap_err();
|
.unwrap_err();
|
||||||
assert!(matches!(err, Error::DatabaseTransaction(_)));
|
assert!(matches!(err, Error::DatabaseTransaction(_)));
|
||||||
@@ -166,12 +170,12 @@ async fn decrypt_roundtrip_after_high_concurrency() {
|
|||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
decryptor
|
decryptor
|
||||||
.try_unseal(SafeCell::new(b"test-seal-key".to_vec()))
|
.try_unseal(KeyCell::from([0u8; 32]))
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
|
|
||||||
for (id, plaintext) in expected {
|
for (id, plaintext) in expected {
|
||||||
let mut decrypted = decryptor.decrypt(id).await.unwrap();
|
let mut decrypted = decryptor.decrypt(id, TEST_AAD.to_vec()).await.unwrap();
|
||||||
assert_eq!(*decrypted.read(), plaintext);
|
assert_eq!(*decrypted.read(), plaintext);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
317
server/crates/arbiter-server/tests/vault/custody.rs
Normal file
317
server/crates/arbiter-server/tests/vault/custody.rs
Normal file
@@ -0,0 +1,317 @@
|
|||||||
|
//! End-to-end coverage for the Shamir custody ceremonies.
|
||||||
|
|
||||||
|
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
||||||
|
use arbiter_server::{
|
||||||
|
actors::{
|
||||||
|
GlobalActors,
|
||||||
|
vault::{Bootstrap, GetState, Seal, VaultState},
|
||||||
|
vault_coordinator::{ContributeBootstrap, ContributeUnseal, StartBootstrap},
|
||||||
|
},
|
||||||
|
crypto::{KeyCell, shamir},
|
||||||
|
db::{self, models::OperatorId, schema},
|
||||||
|
};
|
||||||
|
|
||||||
|
use diesel::{ExpressionMethods as _, QueryDsl};
|
||||||
|
use diesel_async::RunQueryDsl;
|
||||||
|
|
||||||
|
/// Register `count` operator identities so committee members satisfy the
|
||||||
|
/// foreign key from `operator` to `operator_identity`.
|
||||||
|
async fn register_operators(db: &db::DatabasePool, count: usize) -> Vec<OperatorId> {
|
||||||
|
let mut conn = db.get().await.unwrap();
|
||||||
|
let mut ids = Vec::with_capacity(count);
|
||||||
|
for index in 0..count {
|
||||||
|
let pubkey = vec![u8::try_from(index).unwrap(); 32];
|
||||||
|
let id: OperatorId = diesel::insert_into(schema::operator_identity::table)
|
||||||
|
.values((schema::operator_identity::public_key.eq(pubkey),))
|
||||||
|
.returning(schema::operator_identity::id)
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
ids.push(id);
|
||||||
|
}
|
||||||
|
ids
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn stored_share_count(db: &db::DatabasePool) -> i64 {
|
||||||
|
let mut conn = db.get().await.unwrap();
|
||||||
|
schema::operator::table
|
||||||
|
.count()
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap()
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn stored_threshold(db: &db::DatabasePool) -> Option<i32> {
|
||||||
|
let mut conn = db.get().await.unwrap();
|
||||||
|
schema::arbiter_settings::table
|
||||||
|
.select(schema::arbiter_settings::shamir_threshold)
|
||||||
|
.first(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap()
|
||||||
|
}
|
||||||
|
|
||||||
|
fn passphrase(seed: u8) -> SafeCell<Vec<u8>> {
|
||||||
|
SafeCell::new(vec![seed; 16])
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The happy path: three operators bootstrap, and any two of them reopen the
|
||||||
|
/// vault after it is sealed.
|
||||||
|
#[tokio::test]
|
||||||
|
#[test_log::test]
|
||||||
|
async fn committee_of_three_unseals_with_two_passphrases() {
|
||||||
|
let db = db::create_test_pool().await;
|
||||||
|
let actors = GlobalActors::spawn(db.clone()).await.unwrap();
|
||||||
|
let operators = register_operators(&db, 3).await;
|
||||||
|
|
||||||
|
actors
|
||||||
|
.vault_coordinator
|
||||||
|
.ask(StartBootstrap {
|
||||||
|
operator_id: operators[0],
|
||||||
|
declared_count: 3,
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
for (index, operator_id) in operators.iter().enumerate() {
|
||||||
|
let finished = actors
|
||||||
|
.vault_coordinator
|
||||||
|
.ask(ContributeBootstrap {
|
||||||
|
operator_id: *operator_id,
|
||||||
|
passphrase: passphrase(u8::try_from(index).unwrap()),
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert_eq!(
|
||||||
|
finished,
|
||||||
|
index == 2,
|
||||||
|
"the ceremony finishes only on the last contribution"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
assert_eq!(
|
||||||
|
actors.vault.ask(GetState {}).await.unwrap(),
|
||||||
|
VaultState::Unsealed
|
||||||
|
);
|
||||||
|
assert_eq!(stored_share_count(&db).await, 3);
|
||||||
|
assert_eq!(stored_threshold(&db).await, Some(2));
|
||||||
|
|
||||||
|
actors.vault.ask(Seal {}).await.unwrap();
|
||||||
|
|
||||||
|
let first = actors
|
||||||
|
.vault_coordinator
|
||||||
|
.ask(ContributeUnseal {
|
||||||
|
operator_id: operators[0],
|
||||||
|
passphrase: passphrase(0),
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert!(!first, "one of two shares must not unseal");
|
||||||
|
|
||||||
|
let second = actors
|
||||||
|
.vault_coordinator
|
||||||
|
.ask(ContributeUnseal {
|
||||||
|
operator_id: operators[2],
|
||||||
|
passphrase: passphrase(2),
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert!(second, "the threshold contribution should unseal the vault");
|
||||||
|
assert_eq!(
|
||||||
|
actors.vault.ask(GetState {}).await.unwrap(),
|
||||||
|
VaultState::Unsealed
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Shares that describe a seal key the vault never adopted would make the vault
|
||||||
|
/// permanently un-unsealable, so a refused bootstrap must leave the table empty.
|
||||||
|
#[tokio::test]
|
||||||
|
#[test_log::test]
|
||||||
|
async fn refused_bootstrap_stores_no_shares() {
|
||||||
|
let db = db::create_test_pool().await;
|
||||||
|
let actors = GlobalActors::spawn(db.clone()).await.unwrap();
|
||||||
|
let operators = register_operators(&db, 1).await;
|
||||||
|
|
||||||
|
// Another path bootstraps the vault first; the ceremony now has nowhere to go.
|
||||||
|
actors
|
||||||
|
.vault
|
||||||
|
.ask(Bootstrap {
|
||||||
|
seal_key: KeyCell::from([4u8; 32]),
|
||||||
|
custody: None,
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
actors
|
||||||
|
.vault_coordinator
|
||||||
|
.ask(StartBootstrap {
|
||||||
|
operator_id: operators[0],
|
||||||
|
declared_count: 1,
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
let error = actors
|
||||||
|
.vault_coordinator
|
||||||
|
.ask(ContributeBootstrap {
|
||||||
|
operator_id: operators[0],
|
||||||
|
passphrase: passphrase(1),
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.expect_err("bootstrapping an already bootstrapped vault must fail");
|
||||||
|
assert!(
|
||||||
|
format!("{error:?}").contains("AlreadyBootstrapped"),
|
||||||
|
"expected AlreadyBootstrapped, got {error:?}"
|
||||||
|
);
|
||||||
|
|
||||||
|
assert_eq!(
|
||||||
|
stored_share_count(&db).await,
|
||||||
|
0,
|
||||||
|
"a refused bootstrap must not leave shares behind"
|
||||||
|
);
|
||||||
|
assert_eq!(
|
||||||
|
stored_threshold(&db).await,
|
||||||
|
None,
|
||||||
|
"a refused bootstrap must not leave a threshold behind"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
#[test_log::test]
|
||||||
|
async fn oversized_and_degenerate_committees_are_rejected() {
|
||||||
|
let db = db::create_test_pool().await;
|
||||||
|
let actors = GlobalActors::spawn(db.clone()).await.unwrap();
|
||||||
|
let operators = register_operators(&db, 1).await;
|
||||||
|
|
||||||
|
for (count, expected) in [
|
||||||
|
(0_usize, "EmptyCommittee"),
|
||||||
|
(2, "UnsupportedCommittee"),
|
||||||
|
(shamir::MAX_COMMITTEE_SIZE + 1, "CommitteeTooLarge"),
|
||||||
|
(usize::MAX, "CommitteeTooLarge"),
|
||||||
|
] {
|
||||||
|
let error = actors
|
||||||
|
.vault_coordinator
|
||||||
|
.ask(StartBootstrap {
|
||||||
|
operator_id: operators[0],
|
||||||
|
declared_count: count,
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.expect_err("committee size must be rejected");
|
||||||
|
assert!(
|
||||||
|
format!("{error:?}").contains(expected),
|
||||||
|
"expected {expected} for count {count}, got {error:?}"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// A committee whose members never all show up would otherwise wedge the
|
||||||
|
/// coordinator until restart. Only the operator that declared it may reset it.
|
||||||
|
#[tokio::test]
|
||||||
|
#[test_log::test]
|
||||||
|
async fn only_the_declarer_may_restart_a_stalled_committee() {
|
||||||
|
let db = db::create_test_pool().await;
|
||||||
|
let actors = GlobalActors::spawn(db.clone()).await.unwrap();
|
||||||
|
let operators = register_operators(&db, 3).await;
|
||||||
|
|
||||||
|
actors
|
||||||
|
.vault_coordinator
|
||||||
|
.ask(StartBootstrap {
|
||||||
|
operator_id: operators[0],
|
||||||
|
declared_count: 3,
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
actors
|
||||||
|
.vault_coordinator
|
||||||
|
.ask(ContributeBootstrap {
|
||||||
|
operator_id: operators[0],
|
||||||
|
passphrase: passphrase(0),
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
let error = actors
|
||||||
|
.vault_coordinator
|
||||||
|
.ask(StartBootstrap {
|
||||||
|
operator_id: operators[1],
|
||||||
|
declared_count: 3,
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.expect_err("a bystander must not reset someone else's ceremony");
|
||||||
|
assert!(
|
||||||
|
format!("{error:?}").contains("AlreadyBootstrapping"),
|
||||||
|
"expected AlreadyBootstrapping, got {error:?}"
|
||||||
|
);
|
||||||
|
|
||||||
|
actors
|
||||||
|
.vault_coordinator
|
||||||
|
.ask(StartBootstrap {
|
||||||
|
operator_id: operators[0],
|
||||||
|
declared_count: 1,
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.expect("the declarer may restart the ceremony");
|
||||||
|
|
||||||
|
let finished = actors
|
||||||
|
.vault_coordinator
|
||||||
|
.ask(ContributeBootstrap {
|
||||||
|
operator_id: operators[0],
|
||||||
|
passphrase: passphrase(0),
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert!(
|
||||||
|
finished,
|
||||||
|
"the restarted one-operator ceremony should complete"
|
||||||
|
);
|
||||||
|
assert_eq!(stored_share_count(&db).await, 1);
|
||||||
|
}
|
||||||
|
|
||||||
|
/// A wrong passphrase must not unseal, and the operator must be able to retry.
|
||||||
|
#[tokio::test]
|
||||||
|
#[test_log::test]
|
||||||
|
async fn wrong_passphrase_is_rejected_and_retryable() {
|
||||||
|
let db = db::create_test_pool().await;
|
||||||
|
let actors = GlobalActors::spawn(db.clone()).await.unwrap();
|
||||||
|
let operators = register_operators(&db, 1).await;
|
||||||
|
|
||||||
|
actors
|
||||||
|
.vault_coordinator
|
||||||
|
.ask(StartBootstrap {
|
||||||
|
operator_id: operators[0],
|
||||||
|
declared_count: 1,
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
actors
|
||||||
|
.vault_coordinator
|
||||||
|
.ask(ContributeBootstrap {
|
||||||
|
operator_id: operators[0],
|
||||||
|
passphrase: passphrase(7),
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
actors.vault.ask(Seal {}).await.unwrap();
|
||||||
|
|
||||||
|
let error = actors
|
||||||
|
.vault_coordinator
|
||||||
|
.ask(ContributeUnseal {
|
||||||
|
operator_id: operators[0],
|
||||||
|
passphrase: passphrase(8),
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.expect_err("a wrong passphrase must not unseal");
|
||||||
|
assert!(
|
||||||
|
format!("{error:?}").contains("InvalidPassphrase"),
|
||||||
|
"expected InvalidPassphrase, got {error:?}"
|
||||||
|
);
|
||||||
|
|
||||||
|
let unsealed = actors
|
||||||
|
.vault_coordinator
|
||||||
|
.ask(ContributeUnseal {
|
||||||
|
operator_id: operators[0],
|
||||||
|
passphrase: passphrase(7),
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.expect("the operator may retry with the correct passphrase");
|
||||||
|
assert!(unsealed, "the retry should unseal the vault");
|
||||||
|
}
|
||||||
@@ -5,23 +5,28 @@ use arbiter_server::{
|
|||||||
GlobalActors,
|
GlobalActors,
|
||||||
vault::{Error, Vault},
|
vault::{Error, Vault},
|
||||||
},
|
},
|
||||||
crypto::encryption::v1::{Nonce, ROOT_KEY_TAG},
|
crypto::{
|
||||||
|
KeyCell,
|
||||||
|
encryption::v1::{Nonce, ROOT_KEY_TAG},
|
||||||
|
},
|
||||||
db::{self, models, schema},
|
db::{self, models, schema},
|
||||||
};
|
};
|
||||||
|
|
||||||
use diesel::{QueryDsl, SelectableHelper};
|
use diesel::{QueryDsl, SelectableHelper};
|
||||||
use diesel_async::RunQueryDsl;
|
use diesel_async::RunQueryDsl;
|
||||||
|
|
||||||
|
const TEST_AAD: &[u8] = b"test-aad";
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
async fn test_bootstrap() {
|
async fn bootstrap() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
let mut actor = Vault::new(db.clone(), GlobalActors::spawn_message_bus())
|
let mut actor = Vault::new(db.clone(), GlobalActors::spawn_message_bus())
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
|
|
||||||
let seal_key = SafeCell::new(b"test-seal-key".to_vec());
|
let seal_key = KeyCell::from([0u8; 32]);
|
||||||
actor.bootstrap(seal_key).await.unwrap();
|
actor.bootstrap(seal_key, None).await.unwrap();
|
||||||
|
|
||||||
let mut conn = db.get().await.unwrap();
|
let mut conn = db.get().await.unwrap();
|
||||||
let row: models::RootKeyHistory = schema::root_key_history::table
|
let row: models::RootKeyHistory = schema::root_key_history::table
|
||||||
@@ -39,25 +44,25 @@ async fn test_bootstrap() {
|
|||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
async fn test_bootstrap_rejects_double() {
|
async fn bootstrap_rejects_double() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
let mut actor = common::bootstrapped_vault(&db).await;
|
let mut actor = common::bootstrapped_vault(&db).await;
|
||||||
|
|
||||||
let seal_key2 = SafeCell::new(b"test-seal-key".to_vec());
|
let seal_key2 = KeyCell::from([0u8; 32]);
|
||||||
let err = actor.bootstrap(seal_key2).await.unwrap_err();
|
let err = actor.bootstrap(seal_key2, None).await.unwrap_err();
|
||||||
assert!(matches!(err, Error::AlreadyBootstrapped));
|
assert!(matches!(err, Error::AlreadyBootstrapped));
|
||||||
}
|
}
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
async fn test_create_new_before_bootstrap_fails() {
|
async fn create_new_before_bootstrap_fails() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
let mut actor = Vault::new(db, GlobalActors::spawn_message_bus())
|
let mut actor = Vault::new(db, GlobalActors::spawn_message_bus())
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
|
|
||||||
let err = actor
|
let err = actor
|
||||||
.create_new(SafeCell::new(b"data".to_vec()))
|
.create_new(SafeCell::new(b"data".to_vec()), TEST_AAD.to_vec())
|
||||||
.await
|
.await
|
||||||
.unwrap_err();
|
.unwrap_err();
|
||||||
assert!(matches!(err, Error::NotBootstrapped));
|
assert!(matches!(err, Error::NotBootstrapped));
|
||||||
@@ -65,19 +70,19 @@ async fn test_create_new_before_bootstrap_fails() {
|
|||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
async fn test_decrypt_before_bootstrap_fails() {
|
async fn decrypt_before_bootstrap_fails() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
let mut actor = Vault::new(db, GlobalActors::spawn_message_bus())
|
let mut actor = Vault::new(db, GlobalActors::spawn_message_bus())
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
|
|
||||||
let err = actor.decrypt(1).await.unwrap_err();
|
let err = actor.decrypt(1, TEST_AAD.to_vec()).await.unwrap_err();
|
||||||
assert!(matches!(err, Error::NotBootstrapped));
|
assert!(matches!(err, Error::NotBootstrapped));
|
||||||
}
|
}
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
async fn test_new_restores_sealed_state() {
|
async fn new_restores_sealed_state() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
let actor = common::bootstrapped_vault(&db).await;
|
let actor = common::bootstrapped_vault(&db).await;
|
||||||
drop(actor);
|
drop(actor);
|
||||||
@@ -85,19 +90,19 @@ async fn test_new_restores_sealed_state() {
|
|||||||
let mut actor2 = Vault::new(db, GlobalActors::spawn_message_bus())
|
let mut actor2 = Vault::new(db, GlobalActors::spawn_message_bus())
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
let err = actor2.decrypt(1).await.unwrap_err();
|
let err = actor2.decrypt(1, TEST_AAD.to_vec()).await.unwrap_err();
|
||||||
assert!(matches!(err, Error::Sealed));
|
assert!(matches!(err, Error::Sealed));
|
||||||
}
|
}
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
async fn test_unseal_correct_password() {
|
async fn unseal_correct_password() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
let mut actor = common::bootstrapped_vault(&db).await;
|
let mut actor = common::bootstrapped_vault(&db).await;
|
||||||
|
|
||||||
let plaintext = b"survive a restart";
|
let plaintext = b"survive a restart";
|
||||||
let aead_id = actor
|
let aead_id = actor
|
||||||
.create_new(SafeCell::new(plaintext.to_vec()))
|
.create_new(SafeCell::new(plaintext.to_vec()), TEST_AAD.to_vec())
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
drop(actor);
|
drop(actor);
|
||||||
@@ -105,22 +110,22 @@ async fn test_unseal_correct_password() {
|
|||||||
let mut actor = Vault::new(db.clone(), GlobalActors::spawn_message_bus())
|
let mut actor = Vault::new(db.clone(), GlobalActors::spawn_message_bus())
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
let seal_key = SafeCell::new(b"test-seal-key".to_vec());
|
let seal_key = KeyCell::from([0u8; 32]);
|
||||||
actor.try_unseal(seal_key).await.unwrap();
|
actor.try_unseal(seal_key).await.unwrap();
|
||||||
|
|
||||||
let mut decrypted = actor.decrypt(aead_id).await.unwrap();
|
let mut decrypted = actor.decrypt(aead_id, TEST_AAD.to_vec()).await.unwrap();
|
||||||
assert_eq!(*decrypted.read(), plaintext);
|
assert_eq!(*decrypted.read(), plaintext);
|
||||||
}
|
}
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
async fn test_unseal_wrong_then_correct_password() {
|
async fn unseal_wrong_then_correct_password() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
let mut actor = common::bootstrapped_vault(&db).await;
|
let mut actor = common::bootstrapped_vault(&db).await;
|
||||||
|
|
||||||
let plaintext = b"important data";
|
let plaintext = b"important data";
|
||||||
let aead_id = actor
|
let aead_id = actor
|
||||||
.create_new(SafeCell::new(plaintext.to_vec()))
|
.create_new(SafeCell::new(plaintext.to_vec()), TEST_AAD.to_vec())
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
drop(actor);
|
drop(actor);
|
||||||
@@ -129,13 +134,13 @@ async fn test_unseal_wrong_then_correct_password() {
|
|||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
|
|
||||||
let bad_key = SafeCell::new(b"wrong-password".to_vec());
|
let bad_key = KeyCell::from([1u8; 32]);
|
||||||
let err = actor.try_unseal(bad_key).await.unwrap_err();
|
let err = actor.try_unseal(bad_key).await.unwrap_err();
|
||||||
assert!(matches!(err, Error::InvalidKey));
|
assert!(matches!(err, Error::InvalidKey));
|
||||||
|
|
||||||
let good_key = SafeCell::new(b"test-seal-key".to_vec());
|
let good_key = KeyCell::from([0u8; 32]);
|
||||||
actor.try_unseal(good_key).await.unwrap();
|
actor.try_unseal(good_key).await.unwrap();
|
||||||
|
|
||||||
let mut decrypted = actor.decrypt(aead_id).await.unwrap();
|
let mut decrypted = actor.decrypt(aead_id, TEST_AAD.to_vec()).await.unwrap();
|
||||||
assert_eq!(*decrypted.read(), plaintext);
|
assert_eq!(*decrypted.read(), plaintext);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -10,45 +10,47 @@ use diesel::{ExpressionMethods as _, QueryDsl, SelectableHelper, dsl::update};
|
|||||||
use diesel_async::RunQueryDsl;
|
use diesel_async::RunQueryDsl;
|
||||||
use std::collections::HashSet;
|
use std::collections::HashSet;
|
||||||
|
|
||||||
|
const TEST_AAD: &[u8] = b"test-aad";
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
async fn test_create_decrypt_roundtrip() {
|
async fn create_decrypt_roundtrip() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
let mut actor = common::bootstrapped_vault(&db).await;
|
let mut actor = common::bootstrapped_vault(&db).await;
|
||||||
|
|
||||||
let plaintext = b"hello arbiter";
|
let plaintext = b"hello arbiter";
|
||||||
let aead_id = actor
|
let aead_id = actor
|
||||||
.create_new(SafeCell::new(plaintext.to_vec()))
|
.create_new(SafeCell::new(plaintext.to_vec()), TEST_AAD.to_vec())
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
|
|
||||||
let mut decrypted = actor.decrypt(aead_id).await.unwrap();
|
let mut decrypted = actor.decrypt(aead_id, TEST_AAD.to_vec()).await.unwrap();
|
||||||
assert_eq!(*decrypted.read(), plaintext);
|
assert_eq!(*decrypted.read(), plaintext);
|
||||||
}
|
}
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
async fn test_decrypt_nonexistent_returns_not_found() {
|
async fn decrypt_nonexistent_returns_not_found() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
let mut actor = common::bootstrapped_vault(&db).await;
|
let mut actor = common::bootstrapped_vault(&db).await;
|
||||||
|
|
||||||
let err = actor.decrypt(9999).await.unwrap_err();
|
let err = actor.decrypt(9999, TEST_AAD.to_vec()).await.unwrap_err();
|
||||||
assert!(matches!(err, Error::NotFound));
|
assert!(matches!(err, Error::NotFound));
|
||||||
}
|
}
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
async fn test_ciphertext_differs_across_entries() {
|
async fn ciphertext_differs_across_entries() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
let mut actor = common::bootstrapped_vault(&db).await;
|
let mut actor = common::bootstrapped_vault(&db).await;
|
||||||
|
|
||||||
let plaintext = b"same content";
|
let plaintext = b"same content";
|
||||||
let id1 = actor
|
let id1 = actor
|
||||||
.create_new(SafeCell::new(plaintext.to_vec()))
|
.create_new(SafeCell::new(plaintext.to_vec()), TEST_AAD.to_vec())
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
let id2 = actor
|
let id2 = actor
|
||||||
.create_new(SafeCell::new(plaintext.to_vec()))
|
.create_new(SafeCell::new(plaintext.to_vec()), TEST_AAD.to_vec())
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
|
|
||||||
@@ -68,22 +70,22 @@ async fn test_ciphertext_differs_across_entries() {
|
|||||||
|
|
||||||
assert_ne!(row1.ciphertext, row2.ciphertext);
|
assert_ne!(row1.ciphertext, row2.ciphertext);
|
||||||
|
|
||||||
let mut d1 = actor.decrypt(id1).await.unwrap();
|
let mut d1 = actor.decrypt(id1, TEST_AAD.to_vec()).await.unwrap();
|
||||||
let mut d2 = actor.decrypt(id2).await.unwrap();
|
let mut d2 = actor.decrypt(id2, TEST_AAD.to_vec()).await.unwrap();
|
||||||
assert_eq!(*d1.read(), plaintext);
|
assert_eq!(*d1.read(), plaintext);
|
||||||
assert_eq!(*d2.read(), plaintext);
|
assert_eq!(*d2.read(), plaintext);
|
||||||
}
|
}
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
async fn test_nonce_never_reused() {
|
async fn nonce_never_reused() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
let mut actor = common::bootstrapped_vault(&db).await;
|
let mut actor = common::bootstrapped_vault(&db).await;
|
||||||
|
|
||||||
let n = 5;
|
let n = 5;
|
||||||
for i in 0..n {
|
for i in 0..n {
|
||||||
actor
|
actor
|
||||||
.create_new(SafeCell::new(format!("secret {i}").into_bytes()))
|
.create_new(SafeCell::new(format!("secret {i}").into_bytes()), TEST_AAD.to_vec())
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
}
|
}
|
||||||
@@ -137,7 +139,7 @@ async fn broken_db_nonce_format_fails_closed() {
|
|||||||
drop(conn);
|
drop(conn);
|
||||||
|
|
||||||
let err = actor
|
let err = actor
|
||||||
.create_new(SafeCell::new(b"must fail".to_vec()))
|
.create_new(SafeCell::new(b"must fail".to_vec()), TEST_AAD.to_vec())
|
||||||
.await
|
.await
|
||||||
.unwrap_err();
|
.unwrap_err();
|
||||||
assert!(matches!(err, Error::BrokenDatabase));
|
assert!(matches!(err, Error::BrokenDatabase));
|
||||||
@@ -145,7 +147,7 @@ async fn broken_db_nonce_format_fails_closed() {
|
|||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
let mut actor = common::bootstrapped_vault(&db).await;
|
let mut actor = common::bootstrapped_vault(&db).await;
|
||||||
let id = actor
|
let id = actor
|
||||||
.create_new(SafeCell::new(b"decrypt target".to_vec()))
|
.create_new(SafeCell::new(b"decrypt target".to_vec()), TEST_AAD.to_vec())
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
let mut conn = db.get().await.unwrap();
|
let mut conn = db.get().await.unwrap();
|
||||||
@@ -156,6 +158,6 @@ async fn broken_db_nonce_format_fails_closed() {
|
|||||||
.unwrap();
|
.unwrap();
|
||||||
drop(conn);
|
drop(conn);
|
||||||
|
|
||||||
let err = actor.decrypt(id).await.unwrap_err();
|
let err = actor.decrypt(id, TEST_AAD.to_vec()).await.unwrap_err();
|
||||||
assert!(matches!(err, Error::BrokenDatabase));
|
assert!(matches!(err, Error::BrokenDatabase));
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user