Compare commits
1 Commits
security-h
...
impl-usera
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3aae3e1d83 |
@@ -67,14 +67,18 @@ The `program_client.nonce` column stores the **next usable nonce** — i.e. it i
|
|||||||
## Cryptography
|
## Cryptography
|
||||||
|
|
||||||
### Authentication
|
### Authentication
|
||||||
- **Client protocol:** ML-DSA
|
- **Client protocol:** ed25519
|
||||||
|
|
||||||
### User-Agent Authentication
|
### User-Agent Authentication
|
||||||
|
|
||||||
User-agent authentication supports multiple signature schemes because platform-provided "hardware-bound" keys do not expose a uniform algorithm across operating systems and hardware.
|
User-agent authentication supports multiple signature schemes because platform-provided "hardware-bound" keys do not expose a uniform algorithm across operating systems and hardware.
|
||||||
|
|
||||||
- **Supported schemes:** ML-DSA
|
- **Supported schemes:** RSA, Ed25519, ECDSA (secp256k1)
|
||||||
- **Why:** Secure Enclave (MacOS) support them natively, on other platforms we could emulate while they roll-out
|
- **Why:** the user agent authenticates with keys backed by platform facilities, and those facilities differ by platform
|
||||||
|
- **Apple Silicon Secure Enclave / Secure Element:** ECDSA-only in practice
|
||||||
|
- **Windows Hello / TPM 2.0:** currently RSA-backed in our integration
|
||||||
|
|
||||||
|
This is why the user-agent auth protocol carries an explicit `KeyType`, while the SDK client protocol remains fixed to ed25519.
|
||||||
|
|
||||||
### Encryption at Rest
|
### Encryption at Rest
|
||||||
- **Scheme:** Symmetric AEAD — currently **XChaCha20-Poly1305**
|
- **Scheme:** Symmetric AEAD — currently **XChaCha20-Poly1305**
|
||||||
|
|||||||
11
mise.lock
11
mise.lock
@@ -48,10 +48,6 @@ backend = "cargo:cargo-features-manager"
|
|||||||
version = "1.46.3"
|
version = "1.46.3"
|
||||||
backend = "cargo:cargo-insta"
|
backend = "cargo:cargo-insta"
|
||||||
|
|
||||||
[[tools."cargo:cargo-mutants"]]
|
|
||||||
version = "27.0.0"
|
|
||||||
backend = "cargo:cargo-mutants"
|
|
||||||
|
|
||||||
[[tools."cargo:cargo-nextest"]]
|
[[tools."cargo:cargo-nextest"]]
|
||||||
version = "0.9.126"
|
version = "0.9.126"
|
||||||
backend = "cargo:cargo-nextest"
|
backend = "cargo:cargo-nextest"
|
||||||
@@ -115,37 +111,30 @@ backend = "core:python"
|
|||||||
[tools.python."platforms.linux-arm64"]
|
[tools.python."platforms.linux-arm64"]
|
||||||
checksum = "sha256:53700338695e402a1a1fe22be4a41fbdacc70e22bb308a48eca8ed67cb7992be"
|
checksum = "sha256:53700338695e402a1a1fe22be4a41fbdacc70e22bb308a48eca8ed67cb7992be"
|
||||||
url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260324/cpython-3.14.3+20260324-aarch64-unknown-linux-gnu-install_only_stripped.tar.gz"
|
url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260324/cpython-3.14.3+20260324-aarch64-unknown-linux-gnu-install_only_stripped.tar.gz"
|
||||||
provenance = "github-attestations"
|
|
||||||
|
|
||||||
[tools.python."platforms.linux-arm64-musl"]
|
[tools.python."platforms.linux-arm64-musl"]
|
||||||
checksum = "sha256:53700338695e402a1a1fe22be4a41fbdacc70e22bb308a48eca8ed67cb7992be"
|
checksum = "sha256:53700338695e402a1a1fe22be4a41fbdacc70e22bb308a48eca8ed67cb7992be"
|
||||||
url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260324/cpython-3.14.3+20260324-aarch64-unknown-linux-gnu-install_only_stripped.tar.gz"
|
url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260324/cpython-3.14.3+20260324-aarch64-unknown-linux-gnu-install_only_stripped.tar.gz"
|
||||||
provenance = "github-attestations"
|
|
||||||
|
|
||||||
[tools.python."platforms.linux-x64"]
|
[tools.python."platforms.linux-x64"]
|
||||||
checksum = "sha256:d7a9f970914bb4c88756fe3bdcc186d4feb90e9500e54f1db47dae4dc9687e39"
|
checksum = "sha256:d7a9f970914bb4c88756fe3bdcc186d4feb90e9500e54f1db47dae4dc9687e39"
|
||||||
url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260324/cpython-3.14.3+20260324-x86_64-unknown-linux-gnu-install_only_stripped.tar.gz"
|
url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260324/cpython-3.14.3+20260324-x86_64-unknown-linux-gnu-install_only_stripped.tar.gz"
|
||||||
provenance = "github-attestations"
|
|
||||||
|
|
||||||
[tools.python."platforms.linux-x64-musl"]
|
[tools.python."platforms.linux-x64-musl"]
|
||||||
checksum = "sha256:d7a9f970914bb4c88756fe3bdcc186d4feb90e9500e54f1db47dae4dc9687e39"
|
checksum = "sha256:d7a9f970914bb4c88756fe3bdcc186d4feb90e9500e54f1db47dae4dc9687e39"
|
||||||
url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260324/cpython-3.14.3+20260324-x86_64-unknown-linux-gnu-install_only_stripped.tar.gz"
|
url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260324/cpython-3.14.3+20260324-x86_64-unknown-linux-gnu-install_only_stripped.tar.gz"
|
||||||
provenance = "github-attestations"
|
|
||||||
|
|
||||||
[tools.python."platforms.macos-arm64"]
|
[tools.python."platforms.macos-arm64"]
|
||||||
checksum = "sha256:c43aecde4a663aebff99b9b83da0efec506479f1c3f98331442f33d2c43501f9"
|
checksum = "sha256:c43aecde4a663aebff99b9b83da0efec506479f1c3f98331442f33d2c43501f9"
|
||||||
url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260324/cpython-3.14.3+20260324-aarch64-apple-darwin-install_only_stripped.tar.gz"
|
url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260324/cpython-3.14.3+20260324-aarch64-apple-darwin-install_only_stripped.tar.gz"
|
||||||
provenance = "github-attestations"
|
|
||||||
|
|
||||||
[tools.python."platforms.macos-x64"]
|
[tools.python."platforms.macos-x64"]
|
||||||
checksum = "sha256:9ab41dbc2f100a2a45d1833b9c11165f51051c558b5213eda9a9731d5948a0c0"
|
checksum = "sha256:9ab41dbc2f100a2a45d1833b9c11165f51051c558b5213eda9a9731d5948a0c0"
|
||||||
url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260324/cpython-3.14.3+20260324-x86_64-apple-darwin-install_only_stripped.tar.gz"
|
url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260324/cpython-3.14.3+20260324-x86_64-apple-darwin-install_only_stripped.tar.gz"
|
||||||
provenance = "github-attestations"
|
|
||||||
|
|
||||||
[tools.python."platforms.windows-x64"]
|
[tools.python."platforms.windows-x64"]
|
||||||
checksum = "sha256:bbe19034b35b0267176a7442575ae7dc6343480fd4d35598cb7700173d431e09"
|
checksum = "sha256:bbe19034b35b0267176a7442575ae7dc6343480fd4d35598cb7700173d431e09"
|
||||||
url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260324/cpython-3.14.3+20260324-x86_64-pc-windows-msvc-install_only_stripped.tar.gz"
|
url = "https://github.com/astral-sh/python-build-standalone/releases/download/20260324/cpython-3.14.3+20260324-x86_64-pc-windows-msvc-install_only_stripped.tar.gz"
|
||||||
provenance = "github-attestations"
|
|
||||||
|
|
||||||
[[tools.rust]]
|
[[tools.rust]]
|
||||||
version = "1.93.0"
|
version = "1.93.0"
|
||||||
|
|||||||
@@ -12,7 +12,6 @@ protoc = "29.6"
|
|||||||
python = "3.14.3"
|
python = "3.14.3"
|
||||||
ast-grep = "0.42.0"
|
ast-grep = "0.42.0"
|
||||||
"cargo:cargo-edit" = "0.13.9"
|
"cargo:cargo-edit" = "0.13.9"
|
||||||
"cargo:cargo-mutants" = "27.0.0"
|
|
||||||
|
|
||||||
[tasks.codegen]
|
[tasks.codegen]
|
||||||
sources = ['protobufs/*.proto', 'protobufs/**/*.proto']
|
sources = ['protobufs/*.proto', 'protobufs/**/*.proto']
|
||||||
|
|||||||
@@ -36,10 +36,6 @@ message GasLimitExceededViolation {
|
|||||||
}
|
}
|
||||||
|
|
||||||
message EvalViolation {
|
message EvalViolation {
|
||||||
message ChainIdMismatch {
|
|
||||||
uint64 expected = 1;
|
|
||||||
uint64 actual = 2;
|
|
||||||
}
|
|
||||||
oneof kind {
|
oneof kind {
|
||||||
bytes invalid_target = 1; // 20-byte Ethereum address
|
bytes invalid_target = 1; // 20-byte Ethereum address
|
||||||
GasLimitExceededViolation gas_limit_exceeded = 2;
|
GasLimitExceededViolation gas_limit_exceeded = 2;
|
||||||
@@ -47,8 +43,6 @@ message EvalViolation {
|
|||||||
google.protobuf.Empty volumetric_limit_exceeded = 4;
|
google.protobuf.Empty volumetric_limit_exceeded = 4;
|
||||||
google.protobuf.Empty invalid_time = 5;
|
google.protobuf.Empty invalid_time = 5;
|
||||||
google.protobuf.Empty invalid_transaction_type = 6;
|
google.protobuf.Empty invalid_transaction_type = 6;
|
||||||
|
|
||||||
ChainIdMismatch chain_id_mismatch = 7;
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1 +0,0 @@
|
|||||||
test_tool = "nextest"
|
|
||||||
2
server/.gitignore
vendored
2
server/.gitignore
vendored
@@ -1,2 +0,0 @@
|
|||||||
mutants.out/
|
|
||||||
mutants.out.old/
|
|
||||||
329
server/Cargo.lock
generated
329
server/Cargo.lock
generated
@@ -347,7 +347,7 @@ dependencies = [
|
|||||||
"ruint",
|
"ruint",
|
||||||
"rustc-hash",
|
"rustc-hash",
|
||||||
"serde",
|
"serde",
|
||||||
"sha3 0.10.8",
|
"sha3",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
@@ -548,7 +548,7 @@ dependencies = [
|
|||||||
"proc-macro-error2",
|
"proc-macro-error2",
|
||||||
"proc-macro2",
|
"proc-macro2",
|
||||||
"quote",
|
"quote",
|
||||||
"sha3 0.10.8",
|
"sha3",
|
||||||
"syn 2.0.117",
|
"syn 2.0.117",
|
||||||
"syn-solidity",
|
"syn-solidity",
|
||||||
]
|
]
|
||||||
@@ -680,9 +680,9 @@ name = "arbiter-client"
|
|||||||
version = "0.1.0"
|
version = "0.1.0"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"alloy",
|
"alloy",
|
||||||
"arbiter-crypto",
|
|
||||||
"arbiter-proto",
|
"arbiter-proto",
|
||||||
"async-trait",
|
"async-trait",
|
||||||
|
"ed25519-dalek",
|
||||||
"http",
|
"http",
|
||||||
"rand 0.10.0",
|
"rand 0.10.0",
|
||||||
"rustls-webpki",
|
"rustls-webpki",
|
||||||
@@ -692,29 +692,6 @@ dependencies = [
|
|||||||
"tonic",
|
"tonic",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "arbiter-crypto"
|
|
||||||
version = "0.1.0"
|
|
||||||
dependencies = [
|
|
||||||
"alloy",
|
|
||||||
"base64",
|
|
||||||
"chrono",
|
|
||||||
"hmac",
|
|
||||||
"memsafe",
|
|
||||||
"ml-dsa",
|
|
||||||
"rand 0.10.0",
|
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "arbiter-macros"
|
|
||||||
version = "0.1.0"
|
|
||||||
dependencies = [
|
|
||||||
"arbiter-crypto",
|
|
||||||
"proc-macro2",
|
|
||||||
"quote",
|
|
||||||
"syn 2.0.117",
|
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "arbiter-proto"
|
name = "arbiter-proto"
|
||||||
version = "0.1.0"
|
version = "0.1.0"
|
||||||
@@ -748,8 +725,6 @@ version = "0.1.0"
|
|||||||
dependencies = [
|
dependencies = [
|
||||||
"alloy",
|
"alloy",
|
||||||
"anyhow",
|
"anyhow",
|
||||||
"arbiter-crypto",
|
|
||||||
"arbiter-macros",
|
|
||||||
"arbiter-proto",
|
"arbiter-proto",
|
||||||
"arbiter-tokens-registry",
|
"arbiter-tokens-registry",
|
||||||
"argon2",
|
"argon2",
|
||||||
@@ -767,24 +742,23 @@ dependencies = [
|
|||||||
"insta",
|
"insta",
|
||||||
"k256",
|
"k256",
|
||||||
"kameo",
|
"kameo",
|
||||||
"ml-dsa",
|
"memsafe",
|
||||||
"mutants",
|
|
||||||
"pem",
|
"pem",
|
||||||
"proptest",
|
"postcard",
|
||||||
"prost",
|
"prost",
|
||||||
"prost-types",
|
"prost-types",
|
||||||
"rand 0.10.0",
|
"rand 0.10.0",
|
||||||
"rcgen",
|
"rcgen",
|
||||||
"restructed",
|
"restructed",
|
||||||
"rstest",
|
"rsa",
|
||||||
"rustls",
|
"rustls",
|
||||||
"secrecy",
|
"secrecy",
|
||||||
|
"serde",
|
||||||
"serde_with",
|
"serde_with",
|
||||||
"sha2 0.10.9",
|
"sha2 0.10.9",
|
||||||
"smlang",
|
"smlang",
|
||||||
"spki 0.7.3",
|
"spki",
|
||||||
"strum 0.28.0",
|
"strum 0.28.0",
|
||||||
"subtle",
|
|
||||||
"test-log",
|
"test-log",
|
||||||
"thiserror 2.0.18",
|
"thiserror 2.0.18",
|
||||||
"tokio",
|
"tokio",
|
||||||
@@ -1083,6 +1057,15 @@ dependencies = [
|
|||||||
"syn 2.0.117",
|
"syn 2.0.117",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "atomic-polyfill"
|
||||||
|
version = "1.0.3"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "8cf2bce30dfe09ef0bfaef228b9d414faaf7e563035494d7fe092dba54b300f4"
|
||||||
|
dependencies = [
|
||||||
|
"critical-section",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "atomic-waker"
|
name = "atomic-waker"
|
||||||
version = "1.1.2"
|
version = "1.1.2"
|
||||||
@@ -1474,10 +1457,13 @@ dependencies = [
|
|||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "cmov"
|
name = "cobs"
|
||||||
version = "0.5.3"
|
version = "0.3.0"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "3f88a43d011fc4a6876cb7344703e297c71dda42494fee094d5f7c76bf13f746"
|
checksum = "0fa961b519f0b462e3a3b4a34b64d119eeaca1d59af726fe450bbba07a9fc0a1"
|
||||||
|
dependencies = [
|
||||||
|
"thiserror 2.0.18",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "console"
|
name = "console"
|
||||||
@@ -1509,12 +1495,6 @@ version = "0.9.6"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "c2459377285ad874054d797f3ccebf984978aa39129f6eafde5cdc8315b612f8"
|
checksum = "c2459377285ad874054d797f3ccebf984978aa39129f6eafde5cdc8315b612f8"
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "const-oid"
|
|
||||||
version = "0.10.2"
|
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
|
||||||
checksum = "a6ef517f0926dd24a1582492c791b6a4818a4d94e789a334894aa15b0d12f55c"
|
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "const_format"
|
name = "const_format"
|
||||||
version = "0.2.35"
|
version = "0.2.35"
|
||||||
@@ -1592,6 +1572,12 @@ dependencies = [
|
|||||||
"cfg-if",
|
"cfg-if",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "critical-section"
|
||||||
|
version = "1.2.0"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "790eea4361631c5e7d22598ecd5723ff611904e3344ce8720784c93e3d83d40b"
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "crossbeam-utils"
|
name = "crossbeam-utils"
|
||||||
version = "0.8.21"
|
version = "0.8.21"
|
||||||
@@ -1636,15 +1622,6 @@ dependencies = [
|
|||||||
"hybrid-array",
|
"hybrid-array",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "ctutils"
|
|
||||||
version = "0.4.2"
|
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
|
||||||
checksum = "7d5515a3834141de9eafb9717ad39eea8247b5674e6066c404e8c4b365d2a29e"
|
|
||||||
dependencies = [
|
|
||||||
"cmov",
|
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "curve25519-dalek"
|
name = "curve25519-dalek"
|
||||||
version = "4.1.3"
|
version = "4.1.3"
|
||||||
@@ -1783,17 +1760,8 @@ version = "0.7.10"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "e7c1832837b905bbfb5101e07cc24c8deddf52f93225eee6ead5f4d63d53ddcb"
|
checksum = "e7c1832837b905bbfb5101e07cc24c8deddf52f93225eee6ead5f4d63d53ddcb"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"const-oid 0.9.6",
|
"const-oid",
|
||||||
"zeroize",
|
"pem-rfc7468",
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "der"
|
|
||||||
version = "0.8.0"
|
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
|
||||||
checksum = "71fd89660b2dc699704064e59e9dba0147b903e85319429e131620d022be411b"
|
|
||||||
dependencies = [
|
|
||||||
"const-oid 0.10.2",
|
|
||||||
"zeroize",
|
"zeroize",
|
||||||
]
|
]
|
||||||
|
|
||||||
@@ -1936,7 +1904,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
|
|||||||
checksum = "9ed9a281f7bc9b7576e61468ba615a66a5c8cfdff42420a70aa82701a3b1e292"
|
checksum = "9ed9a281f7bc9b7576e61468ba615a66a5c8cfdff42420a70aa82701a3b1e292"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"block-buffer 0.10.4",
|
"block-buffer 0.10.4",
|
||||||
"const-oid 0.9.6",
|
"const-oid",
|
||||||
"crypto-common 0.1.7",
|
"crypto-common 0.1.7",
|
||||||
"subtle",
|
"subtle",
|
||||||
]
|
]
|
||||||
@@ -2000,13 +1968,13 @@ version = "0.16.9"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "ee27f32b5c5292967d2d4a9d7f1e0b0aed2c15daded5a60300e4abb9d8020bca"
|
checksum = "ee27f32b5c5292967d2d4a9d7f1e0b0aed2c15daded5a60300e4abb9d8020bca"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"der 0.7.10",
|
"der",
|
||||||
"digest 0.10.7",
|
"digest 0.10.7",
|
||||||
"elliptic-curve",
|
"elliptic-curve",
|
||||||
"rfc6979",
|
"rfc6979",
|
||||||
"serdect",
|
"serdect",
|
||||||
"signature 2.2.0",
|
"signature 2.2.0",
|
||||||
"spki 0.7.3",
|
"spki",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
@@ -2015,6 +1983,7 @@ version = "3.0.0-rc.4"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "c6e914c7c52decb085cea910552e24c63ac019e3ab8bf001ff736da9a9d9d890"
|
checksum = "c6e914c7c52decb085cea910552e24c63ac019e3ab8bf001ff736da9a9d9d890"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
|
"serde",
|
||||||
"signature 3.0.0-rc.10",
|
"signature 3.0.0-rc.10",
|
||||||
]
|
]
|
||||||
|
|
||||||
@@ -2027,6 +1996,7 @@ dependencies = [
|
|||||||
"curve25519-dalek 5.0.0-pre.6",
|
"curve25519-dalek 5.0.0-pre.6",
|
||||||
"ed25519",
|
"ed25519",
|
||||||
"rand_core 0.10.0",
|
"rand_core 0.10.0",
|
||||||
|
"serde",
|
||||||
"sha2 0.11.0-rc.5",
|
"sha2 0.11.0-rc.5",
|
||||||
"subtle",
|
"subtle",
|
||||||
"zeroize",
|
"zeroize",
|
||||||
@@ -2065,7 +2035,7 @@ dependencies = [
|
|||||||
"ff",
|
"ff",
|
||||||
"generic-array",
|
"generic-array",
|
||||||
"group",
|
"group",
|
||||||
"pkcs8 0.10.2",
|
"pkcs8",
|
||||||
"rand_core 0.6.4",
|
"rand_core 0.6.4",
|
||||||
"sec1",
|
"sec1",
|
||||||
"serdect",
|
"serdect",
|
||||||
@@ -2073,6 +2043,18 @@ dependencies = [
|
|||||||
"zeroize",
|
"zeroize",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "embedded-io"
|
||||||
|
version = "0.4.0"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "ef1a6892d9eef45c8fa6b9e0086428a2cca8491aca8f787c534a3d6d0bcb3ced"
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "embedded-io"
|
||||||
|
version = "0.6.1"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "edd0f118536f44f5ccd48bcb8b111bdc3de888b58c74639dfb034a357d0f206d"
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "encode_unicode"
|
name = "encode_unicode"
|
||||||
version = "1.0.0"
|
version = "1.0.0"
|
||||||
@@ -2490,6 +2472,15 @@ dependencies = [
|
|||||||
"tracing",
|
"tracing",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "hash32"
|
||||||
|
version = "0.2.1"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "b0c35f58762feb77d74ebe43bdbc3210f09be9fe6742234d573bacc26ed92b67"
|
||||||
|
dependencies = [
|
||||||
|
"byteorder",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "hashbrown"
|
name = "hashbrown"
|
||||||
version = "0.12.3"
|
version = "0.12.3"
|
||||||
@@ -2524,6 +2515,20 @@ dependencies = [
|
|||||||
"serde_core",
|
"serde_core",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "heapless"
|
||||||
|
version = "0.7.17"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "cdc6457c0eb62c71aac4bc17216026d8410337c4126773b9c5daba343f17964f"
|
||||||
|
dependencies = [
|
||||||
|
"atomic-polyfill",
|
||||||
|
"hash32",
|
||||||
|
"rustc_version 0.4.1",
|
||||||
|
"serde",
|
||||||
|
"spin",
|
||||||
|
"stable_deref_trait",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "heck"
|
name = "heck"
|
||||||
version = "0.5.0"
|
version = "0.5.0"
|
||||||
@@ -2612,7 +2617,6 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
|
|||||||
checksum = "8655f91cd07f2b9d0c24137bd650fe69617773435ee5ec83022377777ce65ef1"
|
checksum = "8655f91cd07f2b9d0c24137bd650fe69617773435ee5ec83022377777ce65ef1"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"typenum",
|
"typenum",
|
||||||
"zeroize",
|
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
@@ -3010,16 +3014,6 @@ dependencies = [
|
|||||||
"cpufeatures 0.2.17",
|
"cpufeatures 0.2.17",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "keccak"
|
|
||||||
version = "0.2.0"
|
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
|
||||||
checksum = "9e24a010dd405bd7ed803e5253182815b41bf2e6a80cc3bfc066658e03a198aa"
|
|
||||||
dependencies = [
|
|
||||||
"cfg-if",
|
|
||||||
"cpufeatures 0.3.0",
|
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "keccak-asm"
|
name = "keccak-asm"
|
||||||
version = "0.1.5"
|
version = "0.1.5"
|
||||||
@@ -3035,6 +3029,9 @@ name = "lazy_static"
|
|||||||
version = "1.5.0"
|
version = "1.5.0"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "bbd2bcb4c963f2ddae06a2efc7e9f3591312473c50c6685e1f298068316e66fe"
|
checksum = "bbd2bcb4c963f2ddae06a2efc7e9f3591312473c50c6685e1f298068316e66fe"
|
||||||
|
dependencies = [
|
||||||
|
"spin",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "leb128fmt"
|
name = "leb128fmt"
|
||||||
@@ -3233,46 +3230,12 @@ dependencies = [
|
|||||||
"windows-sys 0.61.2",
|
"windows-sys 0.61.2",
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "ml-dsa"
|
|
||||||
version = "0.1.0-rc.8"
|
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
|
||||||
checksum = "f5b2bb0ad6fa2b40396775bd56f51345171490fef993f46f91a876ecdbdaea55"
|
|
||||||
dependencies = [
|
|
||||||
"const-oid 0.10.2",
|
|
||||||
"ctutils",
|
|
||||||
"hybrid-array",
|
|
||||||
"module-lattice",
|
|
||||||
"pkcs8 0.11.0-rc.11",
|
|
||||||
"rand_core 0.10.0",
|
|
||||||
"sha3 0.11.0",
|
|
||||||
"signature 3.0.0-rc.10",
|
|
||||||
"zeroize",
|
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "module-lattice"
|
|
||||||
version = "0.2.1"
|
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
|
||||||
checksum = "164eb3faeaecbd14b0b2a917c1b4d0c035097a9c559b0bed85c2cdd032bc8faa"
|
|
||||||
dependencies = [
|
|
||||||
"hybrid-array",
|
|
||||||
"num-traits",
|
|
||||||
"zeroize",
|
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "multimap"
|
name = "multimap"
|
||||||
version = "0.10.1"
|
version = "0.10.1"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "1d87ecb2933e8aeadb3e3a02b828fed80a7528047e68b4f424523a0981a3a084"
|
checksum = "1d87ecb2933e8aeadb3e3a02b828fed80a7528047e68b4f424523a0981a3a084"
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "mutants"
|
|
||||||
version = "0.0.4"
|
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
|
||||||
checksum = "add0ac067452ff1aca8c5002111bd6b1c895baee6e45fcbc44e0193aea17be56"
|
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "nom"
|
name = "nom"
|
||||||
version = "7.1.3"
|
version = "7.1.3"
|
||||||
@@ -3302,6 +3265,23 @@ dependencies = [
|
|||||||
"num-traits",
|
"num-traits",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "num-bigint-dig"
|
||||||
|
version = "0.8.6"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "e661dda6640fad38e827a6d4a310ff4763082116fe217f279885c97f511bb0b7"
|
||||||
|
dependencies = [
|
||||||
|
"lazy_static",
|
||||||
|
"libm",
|
||||||
|
"num-integer",
|
||||||
|
"num-iter",
|
||||||
|
"num-traits",
|
||||||
|
"rand 0.8.5",
|
||||||
|
"serde",
|
||||||
|
"smallvec",
|
||||||
|
"zeroize",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "num-conv"
|
name = "num-conv"
|
||||||
version = "0.2.0"
|
version = "0.2.0"
|
||||||
@@ -3317,6 +3297,17 @@ dependencies = [
|
|||||||
"num-traits",
|
"num-traits",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "num-iter"
|
||||||
|
version = "0.1.45"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "1429034a0490724d0075ebb2bc9e875d6503c3cf69e235a8941aa757d83ef5bf"
|
||||||
|
dependencies = [
|
||||||
|
"autocfg",
|
||||||
|
"num-integer",
|
||||||
|
"num-traits",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "num-traits"
|
name = "num-traits"
|
||||||
version = "0.2.19"
|
version = "0.2.19"
|
||||||
@@ -3486,6 +3477,15 @@ dependencies = [
|
|||||||
"serde_core",
|
"serde_core",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "pem-rfc7468"
|
||||||
|
version = "0.7.0"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "88b39c9bfcfc231068454382784bb460aae594343fb030d46e9f50a645418412"
|
||||||
|
dependencies = [
|
||||||
|
"base64ct",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "percent-encoding"
|
name = "percent-encoding"
|
||||||
version = "2.3.2"
|
version = "2.3.2"
|
||||||
@@ -3545,24 +3545,25 @@ version = "0.1.0"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "8b870d8c151b6f2fb93e84a13146138f05d02ed11c7e7c54f8826aaaf7c9f184"
|
checksum = "8b870d8c151b6f2fb93e84a13146138f05d02ed11c7e7c54f8826aaaf7c9f184"
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "pkcs1"
|
||||||
|
version = "0.7.5"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "c8ffb9f10fa047879315e6625af03c164b16962a5368d724ed16323b68ace47f"
|
||||||
|
dependencies = [
|
||||||
|
"der",
|
||||||
|
"pkcs8",
|
||||||
|
"spki",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "pkcs8"
|
name = "pkcs8"
|
||||||
version = "0.10.2"
|
version = "0.10.2"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "f950b2377845cebe5cf8b5165cb3cc1a5e0fa5cfa3e1f7f55707d8fd82e0a7b7"
|
checksum = "f950b2377845cebe5cf8b5165cb3cc1a5e0fa5cfa3e1f7f55707d8fd82e0a7b7"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"der 0.7.10",
|
"der",
|
||||||
"spki 0.7.3",
|
"spki",
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "pkcs8"
|
|
||||||
version = "0.11.0-rc.11"
|
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
|
||||||
checksum = "12922b6296c06eb741b02d7b5161e3aaa22864af38dfa025a1a3ba3f68c84577"
|
|
||||||
dependencies = [
|
|
||||||
"der 0.8.0",
|
|
||||||
"spki 0.8.0",
|
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
@@ -3588,6 +3589,19 @@ version = "1.13.1"
|
|||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "c33a9471896f1c69cecef8d20cbe2f7accd12527ce60845ff44c153bb2a21b49"
|
checksum = "c33a9471896f1c69cecef8d20cbe2f7accd12527ce60845ff44c153bb2a21b49"
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "postcard"
|
||||||
|
version = "1.1.3"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "6764c3b5dd454e283a30e6dfe78e9b31096d9e32036b5d1eaac7a6119ccb9a24"
|
||||||
|
dependencies = [
|
||||||
|
"cobs",
|
||||||
|
"embedded-io 0.4.0",
|
||||||
|
"embedded-io 0.6.1",
|
||||||
|
"heapless",
|
||||||
|
"serde",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "potential_utf"
|
name = "potential_utf"
|
||||||
version = "0.1.4"
|
version = "0.1.4"
|
||||||
@@ -3699,9 +3713,9 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "proptest"
|
name = "proptest"
|
||||||
version = "1.11.0"
|
version = "1.10.0"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "4b45fcc2344c680f5025fe57779faef368840d0bd1f42f216291f0dc4ace4744"
|
checksum = "37566cb3fdacef14c0737f9546df7cfeadbfbc9fef10991038bf5015d0c80532"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"bit-set",
|
"bit-set",
|
||||||
"bit-vec",
|
"bit-vec",
|
||||||
@@ -4202,6 +4216,28 @@ dependencies = [
|
|||||||
"rustc-hex",
|
"rustc-hex",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "rsa"
|
||||||
|
version = "0.9.10"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "b8573f03f5883dcaebdfcf4725caa1ecb9c15b2ef50c43a07b816e06799bb12d"
|
||||||
|
dependencies = [
|
||||||
|
"const-oid",
|
||||||
|
"digest 0.10.7",
|
||||||
|
"num-bigint-dig",
|
||||||
|
"num-integer",
|
||||||
|
"num-traits",
|
||||||
|
"pkcs1",
|
||||||
|
"pkcs8",
|
||||||
|
"rand_core 0.6.4",
|
||||||
|
"serde",
|
||||||
|
"sha2 0.10.9",
|
||||||
|
"signature 2.2.0",
|
||||||
|
"spki",
|
||||||
|
"subtle",
|
||||||
|
"zeroize",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "rsqlite-vfs"
|
name = "rsqlite-vfs"
|
||||||
version = "0.1.0"
|
version = "0.1.0"
|
||||||
@@ -4441,9 +4477,9 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
|
|||||||
checksum = "d3e97a565f76233a6003f9f5c54be1d9c5bdfa3eccfb189469f11ec4901c47dc"
|
checksum = "d3e97a565f76233a6003f9f5c54be1d9c5bdfa3eccfb189469f11ec4901c47dc"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"base16ct",
|
"base16ct",
|
||||||
"der 0.7.10",
|
"der",
|
||||||
"generic-array",
|
"generic-array",
|
||||||
"pkcs8 0.10.2",
|
"pkcs8",
|
||||||
"serdect",
|
"serdect",
|
||||||
"subtle",
|
"subtle",
|
||||||
"zeroize",
|
"zeroize",
|
||||||
@@ -4637,17 +4673,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
|
|||||||
checksum = "75872d278a8f37ef87fa0ddbda7802605cb18344497949862c0d4dcb291eba60"
|
checksum = "75872d278a8f37ef87fa0ddbda7802605cb18344497949862c0d4dcb291eba60"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"digest 0.10.7",
|
"digest 0.10.7",
|
||||||
"keccak 0.1.6",
|
"keccak",
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "sha3"
|
|
||||||
version = "0.11.0"
|
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
|
||||||
checksum = "be176f1a57ce4e3d31c1a166222d9768de5954f811601fb7ca06fc8203905ce1"
|
|
||||||
dependencies = [
|
|
||||||
"digest 0.11.2",
|
|
||||||
"keccak 0.2.0",
|
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
@@ -4700,10 +4726,6 @@ name = "signature"
|
|||||||
version = "3.0.0-rc.10"
|
version = "3.0.0-rc.10"
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
checksum = "7f1880df446116126965eeec169136b2e0251dba37c6223bcc819569550edea3"
|
checksum = "7f1880df446116126965eeec169136b2e0251dba37c6223bcc819569550edea3"
|
||||||
dependencies = [
|
|
||||||
"digest 0.11.2",
|
|
||||||
"rand_core 0.10.0",
|
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "simd-adler32"
|
name = "simd-adler32"
|
||||||
@@ -4763,6 +4785,15 @@ dependencies = [
|
|||||||
"windows-sys 0.61.2",
|
"windows-sys 0.61.2",
|
||||||
]
|
]
|
||||||
|
|
||||||
|
[[package]]
|
||||||
|
name = "spin"
|
||||||
|
version = "0.9.8"
|
||||||
|
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||||
|
checksum = "6980e8d7511241f8acf4aebddbb1ff938df5eebe98691418c4468d0b72a96a67"
|
||||||
|
dependencies = [
|
||||||
|
"lock_api",
|
||||||
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "spki"
|
name = "spki"
|
||||||
version = "0.7.3"
|
version = "0.7.3"
|
||||||
@@ -4770,17 +4801,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
|
|||||||
checksum = "d91ed6c858b01f942cd56b37a94b3e0a1798290327d1236e4d9cf4eaca44d29d"
|
checksum = "d91ed6c858b01f942cd56b37a94b3e0a1798290327d1236e4d9cf4eaca44d29d"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"base64ct",
|
"base64ct",
|
||||||
"der 0.7.10",
|
"der",
|
||||||
]
|
|
||||||
|
|
||||||
[[package]]
|
|
||||||
name = "spki"
|
|
||||||
version = "0.8.0"
|
|
||||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
|
||||||
checksum = "1d9efca8738c78ee9484207732f728b1ef517bbb1833d6fc0879ca898a522f6f"
|
|
||||||
dependencies = [
|
|
||||||
"base64ct",
|
|
||||||
"der 0.8.0",
|
|
||||||
]
|
]
|
||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
|
|||||||
@@ -20,7 +20,7 @@ tokio = { version = "1.50.0", features = ["full"] }
|
|||||||
ed25519-dalek = { version = "3.0.0-pre.6", features = ["rand_core"] }
|
ed25519-dalek = { version = "3.0.0-pre.6", features = ["rand_core"] }
|
||||||
chrono = { version = "0.4.44", features = ["serde"] }
|
chrono = { version = "0.4.44", features = ["serde"] }
|
||||||
rand = "0.10.0"
|
rand = "0.10.0"
|
||||||
rustls = { version = "0.23.37", features = ["aws-lc-rs", "logging", "prefer-post-quantum", "std"], default-features = false }
|
rustls = { version = "0.23.37", features = ["aws-lc-rs"] }
|
||||||
smlang = "0.8.0"
|
smlang = "0.8.0"
|
||||||
thiserror = "2.0.18"
|
thiserror = "2.0.18"
|
||||||
async-trait = "0.1.89"
|
async-trait = "0.1.89"
|
||||||
@@ -44,7 +44,3 @@ sha2 = "0.10"
|
|||||||
spki = "0.7"
|
spki = "0.7"
|
||||||
prost = "0.14.3"
|
prost = "0.14.3"
|
||||||
miette = { version = "7.6.0", features = ["fancy", "serde"] }
|
miette = { version = "7.6.0", features = ["fancy", "serde"] }
|
||||||
mutants = "0.0.4"
|
|
||||||
ml-dsa = { version = "0.1.0-rc.8", features = ["zeroize"] }
|
|
||||||
base64 = "0.22.1"
|
|
||||||
hmac = "0.12.1"
|
|
||||||
|
|||||||
@@ -13,12 +13,12 @@ evm = ["dep:alloy"]
|
|||||||
|
|
||||||
[dependencies]
|
[dependencies]
|
||||||
arbiter-proto.path = "../arbiter-proto"
|
arbiter-proto.path = "../arbiter-proto"
|
||||||
arbiter-crypto.path = "../arbiter-crypto"
|
|
||||||
alloy = { workspace = true, optional = true }
|
alloy = { workspace = true, optional = true }
|
||||||
tonic.workspace = true
|
tonic.workspace = true
|
||||||
tonic.features = ["tls-aws-lc"]
|
tonic.features = ["tls-aws-lc"]
|
||||||
tokio.workspace = true
|
tokio.workspace = true
|
||||||
tokio-stream.workspace = true
|
tokio-stream.workspace = true
|
||||||
|
ed25519-dalek.workspace = true
|
||||||
thiserror.workspace = true
|
thiserror.workspace = true
|
||||||
http = "1.4.0"
|
http = "1.4.0"
|
||||||
rustls-webpki = { version = "0.103.10", features = ["aws-lc-rs"] }
|
rustls-webpki = { version = "0.103.10", features = ["aws-lc-rs"] }
|
||||||
|
|||||||
@@ -1,6 +1,5 @@
|
|||||||
use arbiter_crypto::authn::{CLIENT_CONTEXT, SigningKey, format_challenge};
|
|
||||||
use arbiter_proto::{
|
use arbiter_proto::{
|
||||||
ClientMetadata,
|
ClientMetadata, format_challenge,
|
||||||
proto::{
|
proto::{
|
||||||
client::{
|
client::{
|
||||||
ClientRequest,
|
ClientRequest,
|
||||||
@@ -15,6 +14,7 @@ use arbiter_proto::{
|
|||||||
shared::ClientInfo as ProtoClientInfo,
|
shared::ClientInfo as ProtoClientInfo,
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
|
use ed25519_dalek::Signer as _;
|
||||||
|
|
||||||
use crate::{
|
use crate::{
|
||||||
storage::StorageError,
|
storage::StorageError,
|
||||||
@@ -54,14 +54,14 @@ fn map_auth_result(code: i32) -> AuthError {
|
|||||||
async fn send_auth_challenge_request(
|
async fn send_auth_challenge_request(
|
||||||
transport: &mut ClientTransport,
|
transport: &mut ClientTransport,
|
||||||
metadata: ClientMetadata,
|
metadata: ClientMetadata,
|
||||||
key: &SigningKey,
|
key: &ed25519_dalek::SigningKey,
|
||||||
) -> std::result::Result<(), AuthError> {
|
) -> std::result::Result<(), AuthError> {
|
||||||
transport
|
transport
|
||||||
.send(ClientRequest {
|
.send(ClientRequest {
|
||||||
request_id: next_request_id(),
|
request_id: next_request_id(),
|
||||||
payload: Some(ClientRequestPayload::Auth(proto_auth::Request {
|
payload: Some(ClientRequestPayload::Auth(proto_auth::Request {
|
||||||
payload: Some(AuthRequestPayload::ChallengeRequest(AuthChallengeRequest {
|
payload: Some(AuthRequestPayload::ChallengeRequest(AuthChallengeRequest {
|
||||||
pubkey: key.public_key().to_bytes(),
|
pubkey: key.verifying_key().to_bytes().to_vec(),
|
||||||
client_info: Some(ProtoClientInfo {
|
client_info: Some(ProtoClientInfo {
|
||||||
name: metadata.name,
|
name: metadata.name,
|
||||||
description: metadata.description,
|
description: metadata.description,
|
||||||
@@ -95,14 +95,11 @@ async fn receive_auth_challenge(
|
|||||||
|
|
||||||
async fn send_auth_challenge_solution(
|
async fn send_auth_challenge_solution(
|
||||||
transport: &mut ClientTransport,
|
transport: &mut ClientTransport,
|
||||||
key: &SigningKey,
|
key: &ed25519_dalek::SigningKey,
|
||||||
challenge: AuthChallenge,
|
challenge: AuthChallenge,
|
||||||
) -> std::result::Result<(), AuthError> {
|
) -> std::result::Result<(), AuthError> {
|
||||||
let challenge_payload = format_challenge(challenge.nonce, &challenge.pubkey);
|
let challenge_payload = format_challenge(challenge.nonce, &challenge.pubkey);
|
||||||
let signature = key
|
let signature = key.sign(&challenge_payload).to_bytes().to_vec();
|
||||||
.sign_message(&challenge_payload, CLIENT_CONTEXT)
|
|
||||||
.map_err(|_| AuthError::UnexpectedAuthResponse)?
|
|
||||||
.to_bytes();
|
|
||||||
|
|
||||||
transport
|
transport
|
||||||
.send(ClientRequest {
|
.send(ClientRequest {
|
||||||
@@ -143,7 +140,7 @@ async fn receive_auth_confirmation(
|
|||||||
pub(crate) async fn authenticate(
|
pub(crate) async fn authenticate(
|
||||||
transport: &mut ClientTransport,
|
transport: &mut ClientTransport,
|
||||||
metadata: ClientMetadata,
|
metadata: ClientMetadata,
|
||||||
key: &SigningKey,
|
key: &ed25519_dalek::SigningKey,
|
||||||
) -> std::result::Result<(), AuthError> {
|
) -> std::result::Result<(), AuthError> {
|
||||||
send_auth_challenge_request(transport, metadata, key).await?;
|
send_auth_challenge_request(transport, metadata, key).await?;
|
||||||
let challenge = receive_auth_challenge(transport).await?;
|
let challenge = receive_auth_challenge(transport).await?;
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
use arbiter_crypto::authn::SigningKey;
|
|
||||||
use arbiter_proto::{
|
use arbiter_proto::{
|
||||||
ClientMetadata, proto::arbiter_service_client::ArbiterServiceClient, url::ArbiterUrl,
|
ClientMetadata, proto::arbiter_service_client::ArbiterServiceClient, url::ArbiterUrl,
|
||||||
};
|
};
|
||||||
@@ -61,7 +60,7 @@ impl ArbiterClient {
|
|||||||
pub async fn connect_with_key(
|
pub async fn connect_with_key(
|
||||||
url: ArbiterUrl,
|
url: ArbiterUrl,
|
||||||
metadata: ClientMetadata,
|
metadata: ClientMetadata,
|
||||||
key: SigningKey,
|
key: ed25519_dalek::SigningKey,
|
||||||
) -> Result<Self, Error> {
|
) -> Result<Self, Error> {
|
||||||
let anchor = webpki::anchor_from_trusted_cert(&url.ca_cert)?.to_owned();
|
let anchor = webpki::anchor_from_trusted_cert(&url.ca_cert)?.to_owned();
|
||||||
let tls = ClientTlsConfig::new().trust_anchor(anchor);
|
let tls = ClientTlsConfig::new().trust_anchor(anchor);
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
use arbiter_crypto::authn::SigningKey;
|
|
||||||
use arbiter_proto::home_path;
|
use arbiter_proto::home_path;
|
||||||
use std::path::{Path, PathBuf};
|
use std::path::{Path, PathBuf};
|
||||||
|
|
||||||
@@ -12,7 +11,7 @@ pub enum StorageError {
|
|||||||
}
|
}
|
||||||
|
|
||||||
pub trait SigningKeyStorage {
|
pub trait SigningKeyStorage {
|
||||||
fn load_or_create(&self) -> std::result::Result<SigningKey, StorageError>;
|
fn load_or_create(&self) -> std::result::Result<ed25519_dalek::SigningKey, StorageError>;
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Debug, Clone)]
|
#[derive(Debug, Clone)]
|
||||||
@@ -21,7 +20,7 @@ pub struct FileSigningKeyStorage {
|
|||||||
}
|
}
|
||||||
|
|
||||||
impl FileSigningKeyStorage {
|
impl FileSigningKeyStorage {
|
||||||
pub const DEFAULT_FILE_NAME: &str = "sdk_client_ml_dsa.key";
|
pub const DEFAULT_FILE_NAME: &str = "sdk_client_ed25519.key";
|
||||||
|
|
||||||
pub fn new(path: impl Into<PathBuf>) -> Self {
|
pub fn new(path: impl Into<PathBuf>) -> Self {
|
||||||
Self { path: path.into() }
|
Self { path: path.into() }
|
||||||
@@ -31,7 +30,7 @@ impl FileSigningKeyStorage {
|
|||||||
Ok(Self::new(home_path()?.join(Self::DEFAULT_FILE_NAME)))
|
Ok(Self::new(home_path()?.join(Self::DEFAULT_FILE_NAME)))
|
||||||
}
|
}
|
||||||
|
|
||||||
fn read_key(path: &Path) -> std::result::Result<SigningKey, StorageError> {
|
fn read_key(path: &Path) -> std::result::Result<ed25519_dalek::SigningKey, StorageError> {
|
||||||
let bytes = std::fs::read(path)?;
|
let bytes = std::fs::read(path)?;
|
||||||
let raw: [u8; 32] =
|
let raw: [u8; 32] =
|
||||||
bytes
|
bytes
|
||||||
@@ -40,12 +39,12 @@ impl FileSigningKeyStorage {
|
|||||||
expected: 32,
|
expected: 32,
|
||||||
actual: v.len(),
|
actual: v.len(),
|
||||||
})?;
|
})?;
|
||||||
Ok(SigningKey::from_seed(raw))
|
Ok(ed25519_dalek::SigningKey::from_bytes(&raw))
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
impl SigningKeyStorage for FileSigningKeyStorage {
|
impl SigningKeyStorage for FileSigningKeyStorage {
|
||||||
fn load_or_create(&self) -> std::result::Result<SigningKey, StorageError> {
|
fn load_or_create(&self) -> std::result::Result<ed25519_dalek::SigningKey, StorageError> {
|
||||||
if let Some(parent) = self.path.parent() {
|
if let Some(parent) = self.path.parent() {
|
||||||
std::fs::create_dir_all(parent)?;
|
std::fs::create_dir_all(parent)?;
|
||||||
}
|
}
|
||||||
@@ -54,8 +53,8 @@ impl SigningKeyStorage for FileSigningKeyStorage {
|
|||||||
return Self::read_key(&self.path);
|
return Self::read_key(&self.path);
|
||||||
}
|
}
|
||||||
|
|
||||||
let key = SigningKey::generate();
|
let key = ed25519_dalek::SigningKey::generate(&mut rand::rng());
|
||||||
let raw_key = key.to_seed();
|
let raw_key = key.to_bytes();
|
||||||
|
|
||||||
// Use create_new to prevent accidental overwrite if another process creates the key first.
|
// Use create_new to prevent accidental overwrite if another process creates the key first.
|
||||||
match std::fs::OpenOptions::new()
|
match std::fs::OpenOptions::new()
|
||||||
@@ -104,7 +103,7 @@ mod tests {
|
|||||||
.load_or_create()
|
.load_or_create()
|
||||||
.expect("second load_or_create should read same key");
|
.expect("second load_or_create should read same key");
|
||||||
|
|
||||||
assert_eq!(key_a.to_seed(), key_b.to_seed());
|
assert_eq!(key_a.to_bytes(), key_b.to_bytes());
|
||||||
assert!(path.exists());
|
assert!(path.exists());
|
||||||
|
|
||||||
std::fs::remove_file(path).expect("temp key file should be removable");
|
std::fs::remove_file(path).expect("temp key file should be removable");
|
||||||
|
|||||||
1
server/crates/arbiter-crypto/.gitignore
vendored
1
server/crates/arbiter-crypto/.gitignore
vendored
@@ -1 +0,0 @@
|
|||||||
/target
|
|
||||||
@@ -1,21 +0,0 @@
|
|||||||
[package]
|
|
||||||
name = "arbiter-crypto"
|
|
||||||
version = "0.1.0"
|
|
||||||
edition = "2024"
|
|
||||||
|
|
||||||
[dependencies]
|
|
||||||
ml-dsa = {workspace = true, optional = true }
|
|
||||||
rand = {workspace = true, optional = true}
|
|
||||||
base64 = {workspace = true, optional = true }
|
|
||||||
memsafe = {version = "0.4.0", optional = true}
|
|
||||||
hmac.workspace = true
|
|
||||||
alloy.workspace = true
|
|
||||||
chrono.workspace = true
|
|
||||||
|
|
||||||
[lints]
|
|
||||||
workspace = true
|
|
||||||
|
|
||||||
[features]
|
|
||||||
default = ["authn", "safecell"]
|
|
||||||
authn = ["dep:ml-dsa", "dep:rand", "dep:base64"]
|
|
||||||
safecell = ["dep:memsafe"]
|
|
||||||
@@ -1,2 +0,0 @@
|
|||||||
pub mod v1;
|
|
||||||
pub use v1::*;
|
|
||||||
@@ -1,193 +0,0 @@
|
|||||||
use base64::{Engine as _, prelude::BASE64_STANDARD};
|
|
||||||
use hmac::digest::Digest;
|
|
||||||
use ml_dsa::{
|
|
||||||
EncodedVerifyingKey, Error, KeyGen, MlDsa87, Seed, Signature as MlDsaSignature,
|
|
||||||
SigningKey as MlDsaSigningKey, VerifyingKey as MlDsaVerifyingKey, signature::Keypair as _,
|
|
||||||
};
|
|
||||||
|
|
||||||
pub static CLIENT_CONTEXT: &[u8] = b"arbiter_client";
|
|
||||||
pub static USERAGENT_CONTEXT: &[u8] = b"arbiter_user_agent";
|
|
||||||
|
|
||||||
pub fn format_challenge(nonce: i32, pubkey: &[u8]) -> Vec<u8> {
|
|
||||||
let concat_form = format!("{}:{}", nonce, BASE64_STANDARD.encode(pubkey));
|
|
||||||
concat_form.into_bytes()
|
|
||||||
}
|
|
||||||
|
|
||||||
pub type KeyParams = MlDsa87;
|
|
||||||
|
|
||||||
#[derive(Clone, Debug, PartialEq)]
|
|
||||||
pub struct PublicKey(Box<MlDsaVerifyingKey<KeyParams>>);
|
|
||||||
|
|
||||||
impl crate::hashing::Hashable for PublicKey {
|
|
||||||
fn hash<H: Digest>(&self, hasher: &mut H) {
|
|
||||||
hasher.update(self.to_bytes());
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[derive(Clone, Debug, PartialEq)]
|
|
||||||
pub struct Signature(Box<MlDsaSignature<KeyParams>>);
|
|
||||||
|
|
||||||
#[derive(Debug)]
|
|
||||||
pub struct SigningKey(Box<MlDsaSigningKey<KeyParams>>);
|
|
||||||
|
|
||||||
impl PublicKey {
|
|
||||||
pub fn to_bytes(&self) -> Vec<u8> {
|
|
||||||
self.0.encode().0.to_vec()
|
|
||||||
}
|
|
||||||
|
|
||||||
pub fn verify(&self, nonce: i32, context: &[u8], signature: &Signature) -> bool {
|
|
||||||
self.0.verify_with_context(
|
|
||||||
&format_challenge(nonce, &self.to_bytes()),
|
|
||||||
context,
|
|
||||||
&signature.0,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl Signature {
|
|
||||||
pub fn to_bytes(&self) -> Vec<u8> {
|
|
||||||
self.0.encode().0.to_vec()
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl SigningKey {
|
|
||||||
pub fn generate() -> Self {
|
|
||||||
Self(Box::new(KeyParams::key_gen(&mut rand::rng())))
|
|
||||||
}
|
|
||||||
|
|
||||||
pub fn from_seed(seed: [u8; 32]) -> Self {
|
|
||||||
Self(Box::new(KeyParams::from_seed(&Seed::from(seed))))
|
|
||||||
}
|
|
||||||
|
|
||||||
pub fn to_seed(&self) -> [u8; 32] {
|
|
||||||
self.0.to_seed().into()
|
|
||||||
}
|
|
||||||
|
|
||||||
pub fn public_key(&self) -> PublicKey {
|
|
||||||
self.0.verifying_key().into()
|
|
||||||
}
|
|
||||||
|
|
||||||
pub fn sign_message(&self, message: &[u8], context: &[u8]) -> Result<Signature, Error> {
|
|
||||||
self.0
|
|
||||||
.signing_key()
|
|
||||||
.sign_deterministic(message, context)
|
|
||||||
.map(Into::into)
|
|
||||||
}
|
|
||||||
|
|
||||||
pub fn sign_challenge(&self, nonce: i32, context: &[u8]) -> Result<Signature, Error> {
|
|
||||||
self.sign_message(
|
|
||||||
&format_challenge(nonce, &self.public_key().to_bytes()),
|
|
||||||
context,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl From<MlDsaVerifyingKey<KeyParams>> for PublicKey {
|
|
||||||
fn from(value: MlDsaVerifyingKey<KeyParams>) -> Self {
|
|
||||||
Self(Box::new(value))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl From<MlDsaSignature<KeyParams>> for Signature {
|
|
||||||
fn from(value: MlDsaSignature<KeyParams>) -> Self {
|
|
||||||
Self(Box::new(value))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl From<MlDsaSigningKey<KeyParams>> for SigningKey {
|
|
||||||
fn from(value: MlDsaSigningKey<KeyParams>) -> Self {
|
|
||||||
Self(Box::new(value))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl TryFrom<Vec<u8>> for PublicKey {
|
|
||||||
type Error = ();
|
|
||||||
|
|
||||||
fn try_from(value: Vec<u8>) -> Result<Self, Self::Error> {
|
|
||||||
Self::try_from(value.as_slice())
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl TryFrom<&'_ [u8]> for PublicKey {
|
|
||||||
type Error = ();
|
|
||||||
|
|
||||||
fn try_from(value: &[u8]) -> Result<Self, Self::Error> {
|
|
||||||
let encoded = EncodedVerifyingKey::<KeyParams>::try_from(value).map_err(|_| ())?;
|
|
||||||
Ok(Self(Box::new(MlDsaVerifyingKey::decode(&encoded))))
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl TryFrom<Vec<u8>> for Signature {
|
|
||||||
type Error = ();
|
|
||||||
|
|
||||||
fn try_from(value: Vec<u8>) -> Result<Self, Self::Error> {
|
|
||||||
Self::try_from(value.as_slice())
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl TryFrom<&'_ [u8]> for Signature {
|
|
||||||
type Error = ();
|
|
||||||
|
|
||||||
fn try_from(value: &[u8]) -> Result<Self, Self::Error> {
|
|
||||||
MlDsaSignature::try_from(value)
|
|
||||||
.map(|sig| Self(Box::new(sig)))
|
|
||||||
.map_err(|_| ())
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[cfg(test)]
|
|
||||||
mod tests {
|
|
||||||
use ml_dsa::{KeyGen, MlDsa87, signature::Keypair as _};
|
|
||||||
|
|
||||||
use super::{CLIENT_CONTEXT, PublicKey, Signature, SigningKey, USERAGENT_CONTEXT};
|
|
||||||
|
|
||||||
#[test]
|
|
||||||
fn public_key_round_trip_decodes() {
|
|
||||||
let key = MlDsa87::key_gen(&mut rand::rng());
|
|
||||||
let encoded = PublicKey::from(key.verifying_key()).to_bytes();
|
|
||||||
|
|
||||||
let decoded = PublicKey::try_from(encoded.as_slice()).expect("public key should decode");
|
|
||||||
|
|
||||||
assert_eq!(decoded, PublicKey::from(key.verifying_key()));
|
|
||||||
}
|
|
||||||
|
|
||||||
#[test]
|
|
||||||
fn signature_round_trip_decodes() {
|
|
||||||
let key = SigningKey::generate();
|
|
||||||
let signature = key
|
|
||||||
.sign_message(b"challenge", CLIENT_CONTEXT)
|
|
||||||
.expect("signature should be created");
|
|
||||||
|
|
||||||
let decoded =
|
|
||||||
Signature::try_from(signature.to_bytes().as_slice()).expect("signature should decode");
|
|
||||||
|
|
||||||
assert_eq!(decoded, signature);
|
|
||||||
}
|
|
||||||
|
|
||||||
#[test]
|
|
||||||
fn challenge_verification_uses_context_and_canonical_key_bytes() {
|
|
||||||
let key = SigningKey::generate();
|
|
||||||
let public_key = key.public_key();
|
|
||||||
let nonce = 17;
|
|
||||||
let signature = key
|
|
||||||
.sign_challenge(nonce, CLIENT_CONTEXT)
|
|
||||||
.expect("signature should be created");
|
|
||||||
|
|
||||||
assert!(public_key.verify(nonce, CLIENT_CONTEXT, &signature));
|
|
||||||
assert!(!public_key.verify(nonce, USERAGENT_CONTEXT, &signature));
|
|
||||||
}
|
|
||||||
|
|
||||||
#[test]
|
|
||||||
fn signing_key_round_trip_seed_preserves_public_key_and_signing() {
|
|
||||||
let original = SigningKey::generate();
|
|
||||||
let restored = SigningKey::from_seed(original.to_seed());
|
|
||||||
|
|
||||||
assert_eq!(restored.public_key(), original.public_key());
|
|
||||||
|
|
||||||
let signature = restored
|
|
||||||
.sign_challenge(9, CLIENT_CONTEXT)
|
|
||||||
.expect("signature should be created");
|
|
||||||
|
|
||||||
assert!(restored.public_key().verify(9, CLIENT_CONTEXT, &signature));
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,111 +0,0 @@
|
|||||||
pub use hmac::digest::Digest;
|
|
||||||
use std::collections::HashSet;
|
|
||||||
|
|
||||||
/// Deterministically hash a value by feeding its fields into the hasher in a consistent order.
|
|
||||||
#[diagnostic::on_unimplemented(
|
|
||||||
note = "for local types consider adding `#[derive(arbiter_macros::Hashable)]` to your `{Self}` type",
|
|
||||||
note = "for types from other crates check whether the crate offers a `Hashable` implementation"
|
|
||||||
)]
|
|
||||||
pub trait Hashable {
|
|
||||||
fn hash<H: Digest>(&self, hasher: &mut H);
|
|
||||||
}
|
|
||||||
|
|
||||||
macro_rules! impl_numeric {
|
|
||||||
($($t:ty),*) => {
|
|
||||||
$(
|
|
||||||
impl Hashable for $t {
|
|
||||||
fn hash<H: Digest>(&self, hasher: &mut H) {
|
|
||||||
hasher.update(&self.to_be_bytes());
|
|
||||||
}
|
|
||||||
}
|
|
||||||
)*
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
impl_numeric!(u8, u16, u32, u64, i8, i16, i32, i64);
|
|
||||||
|
|
||||||
impl Hashable for &[u8] {
|
|
||||||
fn hash<H: Digest>(&self, hasher: &mut H) {
|
|
||||||
hasher.update(self);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl Hashable for String {
|
|
||||||
fn hash<H: Digest>(&self, hasher: &mut H) {
|
|
||||||
hasher.update(self.as_bytes());
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl<T: Hashable + PartialOrd> Hashable for Vec<T> {
|
|
||||||
fn hash<H: Digest>(&self, hasher: &mut H) {
|
|
||||||
let ref_sorted = {
|
|
||||||
let mut sorted = self.iter().collect::<Vec<_>>();
|
|
||||||
sorted.sort_by(|a, b| a.partial_cmp(b).unwrap());
|
|
||||||
sorted
|
|
||||||
};
|
|
||||||
for item in ref_sorted {
|
|
||||||
item.hash(hasher);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl<T: Hashable + PartialOrd> Hashable for HashSet<T> {
|
|
||||||
fn hash<H: Digest>(&self, hasher: &mut H) {
|
|
||||||
let ref_sorted = {
|
|
||||||
let mut sorted = self.iter().collect::<Vec<_>>();
|
|
||||||
sorted.sort_by(|a, b| a.partial_cmp(b).unwrap());
|
|
||||||
sorted
|
|
||||||
};
|
|
||||||
for item in ref_sorted {
|
|
||||||
item.hash(hasher);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl<T: Hashable> Hashable for Option<T> {
|
|
||||||
fn hash<H: Digest>(&self, hasher: &mut H) {
|
|
||||||
match self {
|
|
||||||
Some(value) => {
|
|
||||||
hasher.update([1]);
|
|
||||||
value.hash(hasher);
|
|
||||||
}
|
|
||||||
None => hasher.update([0]),
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl<T: Hashable> Hashable for Box<T> {
|
|
||||||
fn hash<H: Digest>(&self, hasher: &mut H) {
|
|
||||||
self.as_ref().hash(hasher);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl<T: Hashable> Hashable for &T {
|
|
||||||
fn hash<H: Digest>(&self, hasher: &mut H) {
|
|
||||||
(*self).hash(hasher);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl Hashable for alloy::primitives::Address {
|
|
||||||
fn hash<H: Digest>(&self, hasher: &mut H) {
|
|
||||||
hasher.update(self.as_slice());
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl Hashable for alloy::primitives::U256 {
|
|
||||||
fn hash<H: Digest>(&self, hasher: &mut H) {
|
|
||||||
hasher.update(self.to_be_bytes::<32>());
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl Hashable for chrono::Duration {
|
|
||||||
fn hash<H: Digest>(&self, hasher: &mut H) {
|
|
||||||
hasher.update(self.num_seconds().to_be_bytes());
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
impl Hashable for chrono::DateTime<chrono::Utc> {
|
|
||||||
fn hash<H: Digest>(&self, hasher: &mut H) {
|
|
||||||
hasher.update(self.timestamp_millis().to_be_bytes());
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
#[cfg(feature = "authn")]
|
|
||||||
pub mod authn;
|
|
||||||
pub mod hashing;
|
|
||||||
#[cfg(feature = "safecell")]
|
|
||||||
pub mod safecell;
|
|
||||||
@@ -1,18 +0,0 @@
|
|||||||
[package]
|
|
||||||
name = "arbiter-macros"
|
|
||||||
version = "0.1.0"
|
|
||||||
edition = "2024"
|
|
||||||
|
|
||||||
[lib]
|
|
||||||
proc-macro = true
|
|
||||||
|
|
||||||
[dependencies]
|
|
||||||
proc-macro2 = "1.0"
|
|
||||||
quote = "1.0"
|
|
||||||
syn = { version = "2.0", features = ["derive", "fold", "full", "visit-mut"] }
|
|
||||||
|
|
||||||
[dev-dependencies]
|
|
||||||
arbiter-crypto = { path = "../arbiter-crypto" }
|
|
||||||
|
|
||||||
[lints]
|
|
||||||
workspace = true
|
|
||||||
@@ -1,133 +0,0 @@
|
|||||||
use proc_macro2::{Span, TokenStream, TokenTree};
|
|
||||||
use quote::quote;
|
|
||||||
use syn::parse_quote;
|
|
||||||
use syn::spanned::Spanned;
|
|
||||||
use syn::{DataStruct, DeriveInput, Fields, Generics, Index};
|
|
||||||
|
|
||||||
use crate::utils::{HASHABLE_TRAIT_PATH, HMAC_DIGEST_PATH};
|
|
||||||
|
|
||||||
pub(crate) fn derive(input: &DeriveInput) -> TokenStream {
|
|
||||||
match &input.data {
|
|
||||||
syn::Data::Struct(struct_data) => hashable_struct(input, struct_data),
|
|
||||||
syn::Data::Enum(_) => {
|
|
||||||
syn::Error::new_spanned(input, "Hashable can currently be derived only for structs")
|
|
||||||
.to_compile_error()
|
|
||||||
}
|
|
||||||
syn::Data::Union(_) => {
|
|
||||||
syn::Error::new_spanned(input, "Hashable cannot be derived for unions")
|
|
||||||
.to_compile_error()
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
fn hashable_struct(input: &DeriveInput, struct_data: &syn::DataStruct) -> TokenStream {
|
|
||||||
let ident = &input.ident;
|
|
||||||
let hashable_trait = HASHABLE_TRAIT_PATH.to_path();
|
|
||||||
let hmac_digest = HMAC_DIGEST_PATH.to_path();
|
|
||||||
let generics = add_hashable_bounds(input.generics.clone(), &hashable_trait);
|
|
||||||
let field_accesses = collect_field_accesses(struct_data);
|
|
||||||
let hash_calls = build_hash_calls(&field_accesses, &hashable_trait);
|
|
||||||
|
|
||||||
let (impl_generics, ty_generics, where_clause) = generics.split_for_impl();
|
|
||||||
|
|
||||||
quote! {
|
|
||||||
#[automatically_derived]
|
|
||||||
impl #impl_generics #hashable_trait for #ident #ty_generics #where_clause {
|
|
||||||
fn hash<H: #hmac_digest>(&self, hasher: &mut H) {
|
|
||||||
#(#hash_calls)*
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
fn add_hashable_bounds(mut generics: Generics, hashable_trait: &syn::Path) -> Generics {
|
|
||||||
for type_param in generics.type_params_mut() {
|
|
||||||
type_param.bounds.push(parse_quote!(#hashable_trait));
|
|
||||||
}
|
|
||||||
|
|
||||||
generics
|
|
||||||
}
|
|
||||||
|
|
||||||
struct FieldAccess {
|
|
||||||
access: TokenStream,
|
|
||||||
span: Span,
|
|
||||||
}
|
|
||||||
|
|
||||||
fn collect_field_accesses(struct_data: &DataStruct) -> Vec<FieldAccess> {
|
|
||||||
match &struct_data.fields {
|
|
||||||
Fields::Named(fields) => {
|
|
||||||
// Keep deterministic alphabetical order for named fields.
|
|
||||||
// Do not remove this sort, because it keeps hash output stable regardless of source order.
|
|
||||||
let mut named_fields = fields
|
|
||||||
.named
|
|
||||||
.iter()
|
|
||||||
.map(|field| {
|
|
||||||
let name = field
|
|
||||||
.ident
|
|
||||||
.as_ref()
|
|
||||||
.expect("Fields::Named(fields) must have names")
|
|
||||||
.clone();
|
|
||||||
(name.to_string(), name)
|
|
||||||
})
|
|
||||||
.collect::<Vec<_>>();
|
|
||||||
|
|
||||||
named_fields.sort_by(|a, b| a.0.cmp(&b.0));
|
|
||||||
|
|
||||||
named_fields
|
|
||||||
.into_iter()
|
|
||||||
.map(|(_, name)| FieldAccess {
|
|
||||||
access: quote! { #name },
|
|
||||||
span: name.span(),
|
|
||||||
})
|
|
||||||
.collect()
|
|
||||||
}
|
|
||||||
Fields::Unnamed(fields) => fields
|
|
||||||
.unnamed
|
|
||||||
.iter()
|
|
||||||
.enumerate()
|
|
||||||
.map(|(i, field)| FieldAccess {
|
|
||||||
access: {
|
|
||||||
let index = Index::from(i);
|
|
||||||
quote! { #index }
|
|
||||||
},
|
|
||||||
span: field.ty.span(),
|
|
||||||
})
|
|
||||||
.collect(),
|
|
||||||
Fields::Unit => Vec::new(),
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
fn build_hash_calls(
|
|
||||||
field_accesses: &[FieldAccess],
|
|
||||||
hashable_trait: &syn::Path,
|
|
||||||
) -> Vec<TokenStream> {
|
|
||||||
field_accesses
|
|
||||||
.iter()
|
|
||||||
.map(|field| {
|
|
||||||
let access = &field.access;
|
|
||||||
let call = quote! {
|
|
||||||
#hashable_trait::hash(&self.#access, hasher);
|
|
||||||
};
|
|
||||||
|
|
||||||
respan(call, field.span)
|
|
||||||
})
|
|
||||||
.collect()
|
|
||||||
}
|
|
||||||
|
|
||||||
/// Recursively set span on all tokens, including interpolated ones.
|
|
||||||
fn respan(tokens: TokenStream, span: Span) -> TokenStream {
|
|
||||||
tokens
|
|
||||||
.into_iter()
|
|
||||||
.map(|tt| match tt {
|
|
||||||
TokenTree::Group(g) => {
|
|
||||||
let mut new = proc_macro2::Group::new(g.delimiter(), respan(g.stream(), span));
|
|
||||||
new.set_span(span);
|
|
||||||
TokenTree::Group(new)
|
|
||||||
}
|
|
||||||
mut other => {
|
|
||||||
other.set_span(span);
|
|
||||||
other
|
|
||||||
}
|
|
||||||
})
|
|
||||||
.collect()
|
|
||||||
}
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
use syn::{DeriveInput, parse_macro_input};
|
|
||||||
|
|
||||||
mod hashable;
|
|
||||||
mod utils;
|
|
||||||
|
|
||||||
#[proc_macro_derive(Hashable)]
|
|
||||||
pub fn derive_hashable(input: proc_macro::TokenStream) -> proc_macro::TokenStream {
|
|
||||||
let input = parse_macro_input!(input as DeriveInput);
|
|
||||||
hashable::derive(&input).into()
|
|
||||||
}
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
pub struct ToPath(pub &'static str);
|
|
||||||
|
|
||||||
impl ToPath {
|
|
||||||
pub fn to_path(&self) -> syn::Path {
|
|
||||||
syn::parse_str(self.0).expect("Invalid path")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
macro_rules! ensure_path {
|
|
||||||
($path:path) => {{
|
|
||||||
#[cfg(test)]
|
|
||||||
#[expect(unused_imports)]
|
|
||||||
use $path as _;
|
|
||||||
ToPath(stringify!($path))
|
|
||||||
}};
|
|
||||||
}
|
|
||||||
|
|
||||||
pub const HASHABLE_TRAIT_PATH: ToPath = ensure_path!(::arbiter_crypto::hashing::Hashable);
|
|
||||||
pub const HMAC_DIGEST_PATH: ToPath = ensure_path!(::arbiter_crypto::hashing::Digest);
|
|
||||||
@@ -17,7 +17,7 @@ url = "2.5.8"
|
|||||||
miette.workspace = true
|
miette.workspace = true
|
||||||
thiserror.workspace = true
|
thiserror.workspace = true
|
||||||
rustls-pki-types.workspace = true
|
rustls-pki-types.workspace = true
|
||||||
base64.workspace = true
|
base64 = "0.22.1"
|
||||||
prost-types.workspace = true
|
prost-types.workspace = true
|
||||||
tracing.workspace = true
|
tracing.workspace = true
|
||||||
async-trait.workspace = true
|
async-trait.workspace = true
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
pub mod transport;
|
pub mod transport;
|
||||||
pub mod url;
|
pub mod url;
|
||||||
|
|
||||||
|
use base64::{Engine, prelude::BASE64_STANDARD};
|
||||||
|
|
||||||
pub mod proto {
|
pub mod proto {
|
||||||
tonic::include_proto!("arbiter");
|
tonic::include_proto!("arbiter");
|
||||||
|
|
||||||
@@ -82,3 +84,8 @@ pub fn home_path() -> Result<std::path::PathBuf, std::io::Error> {
|
|||||||
|
|
||||||
Ok(arbiter_home)
|
Ok(arbiter_home)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
pub fn format_challenge(nonce: i32, pubkey: &[u8]) -> Vec<u8> {
|
||||||
|
let concat_form = format!("{}:{}", nonce, BASE64_STANDARD.encode(pubkey));
|
||||||
|
concat_form.into_bytes()
|
||||||
|
}
|
||||||
|
|||||||
@@ -16,9 +16,9 @@ diesel-async = { version = "0.8.0", features = [
|
|||||||
"sqlite",
|
"sqlite",
|
||||||
"tokio",
|
"tokio",
|
||||||
] }
|
] }
|
||||||
|
ed25519-dalek.workspace = true
|
||||||
|
ed25519-dalek.features = ["serde"]
|
||||||
arbiter-proto.path = "../arbiter-proto"
|
arbiter-proto.path = "../arbiter-proto"
|
||||||
arbiter-crypto.path = "../arbiter-crypto"
|
|
||||||
arbiter-macros.path = "../arbiter-macros"
|
|
||||||
tracing.workspace = true
|
tracing.workspace = true
|
||||||
tracing-subscriber = { version = "0.3", features = ["env-filter"] }
|
tracing-subscriber = { version = "0.3", features = ["env-filter"] }
|
||||||
tonic.workspace = true
|
tonic.workspace = true
|
||||||
@@ -37,31 +37,31 @@ dashmap = "6.1.0"
|
|||||||
rand.workspace = true
|
rand.workspace = true
|
||||||
rcgen.workspace = true
|
rcgen.workspace = true
|
||||||
chrono.workspace = true
|
chrono.workspace = true
|
||||||
|
memsafe = "0.4.0"
|
||||||
zeroize = { version = "1.8.2", features = ["std", "simd"] }
|
zeroize = { version = "1.8.2", features = ["std", "simd"] }
|
||||||
kameo.workspace = true
|
kameo.workspace = true
|
||||||
|
x25519-dalek.workspace = true
|
||||||
chacha20poly1305 = { version = "0.10.1", features = ["std"] }
|
chacha20poly1305 = { version = "0.10.1", features = ["std"] }
|
||||||
argon2 = { version = "0.5.3", features = ["zeroize"] }
|
argon2 = { version = "0.5.3", features = ["zeroize"] }
|
||||||
restructed = "0.2.2"
|
restructed = "0.2.2"
|
||||||
strum = { version = "0.28.0", features = ["derive"] }
|
strum = { version = "0.28.0", features = ["derive"] }
|
||||||
pem = "3.0.6"
|
pem = "3.0.6"
|
||||||
|
k256.workspace = true
|
||||||
|
k256.features = ["serde"]
|
||||||
|
rsa.workspace = true
|
||||||
|
rsa.features = ["serde"]
|
||||||
sha2.workspace = true
|
sha2.workspace = true
|
||||||
hmac.workspace = true
|
hmac = "0.12"
|
||||||
spki.workspace = true
|
spki.workspace = true
|
||||||
alloy.workspace = true
|
alloy.workspace = true
|
||||||
prost-types.workspace = true
|
prost-types.workspace = true
|
||||||
prost.workspace = true
|
prost.workspace = true
|
||||||
arbiter-tokens-registry.path = "../arbiter-tokens-registry"
|
arbiter-tokens-registry.path = "../arbiter-tokens-registry"
|
||||||
anyhow = "1.0.102"
|
anyhow = "1.0.102"
|
||||||
|
postcard = { version = "1.1.3", features = ["use-std"] }
|
||||||
|
serde = { version = "1.0.228", features = ["derive"] }
|
||||||
serde_with = "3.18.0"
|
serde_with = "3.18.0"
|
||||||
mutants.workspace = true
|
|
||||||
subtle = "2.6.1"
|
|
||||||
ml-dsa.workspace = true
|
|
||||||
ed25519-dalek.workspace = true
|
|
||||||
x25519-dalek.workspace = true
|
|
||||||
k256.workspace = true
|
|
||||||
|
|
||||||
[dev-dependencies]
|
[dev-dependencies]
|
||||||
insta = "1.46.3"
|
insta = "1.46.3"
|
||||||
proptest = "1.11.0"
|
|
||||||
rstest.workspace = true
|
|
||||||
test-log = { version = "0.2", default-features = false, features = ["trace"] }
|
test-log = { version = "0.2", default-features = false, features = ["trace"] }
|
||||||
|
|||||||
@@ -47,7 +47,7 @@ create table if not exists useragent_client (
|
|||||||
id integer not null primary key,
|
id integer not null primary key,
|
||||||
nonce integer not null default(1), -- used for auth challenge
|
nonce integer not null default(1), -- used for auth challenge
|
||||||
public_key blob not null,
|
public_key blob not null,
|
||||||
key_type integer not null default(1),
|
key_type integer not null default(1), -- 1=Ed25519, 2=ECDSA(secp256k1)
|
||||||
created_at integer not null default(unixepoch ('now')),
|
created_at integer not null default(unixepoch ('now')),
|
||||||
updated_at integer not null default(unixepoch ('now'))
|
updated_at integer not null default(unixepoch ('now'))
|
||||||
) STRICT;
|
) STRICT;
|
||||||
|
|||||||
@@ -4,7 +4,6 @@ use diesel_async::RunQueryDsl;
|
|||||||
use kameo::{Actor, messages};
|
use kameo::{Actor, messages};
|
||||||
|
|
||||||
use rand::{RngExt, distr::Alphanumeric, make_rng, rngs::StdRng};
|
use rand::{RngExt, distr::Alphanumeric, make_rng, rngs::StdRng};
|
||||||
use subtle::ConstantTimeEq as _;
|
|
||||||
use thiserror::Error;
|
use thiserror::Error;
|
||||||
|
|
||||||
use crate::db::{self, DatabasePool, schema};
|
use crate::db::{self, DatabasePool, schema};
|
||||||
@@ -45,14 +44,14 @@ pub struct Bootstrapper {
|
|||||||
|
|
||||||
impl Bootstrapper {
|
impl Bootstrapper {
|
||||||
pub async fn new(db: &DatabasePool) -> Result<Self, Error> {
|
pub async fn new(db: &DatabasePool) -> Result<Self, Error> {
|
||||||
let row_count: i64 = {
|
let mut conn = db.get().await?;
|
||||||
let mut conn = db.get().await?;
|
|
||||||
|
|
||||||
schema::useragent_client::table
|
let row_count: i64 = schema::useragent_client::table
|
||||||
.count()
|
.count()
|
||||||
.get_result(&mut conn)
|
.get_result(&mut conn)
|
||||||
.await?
|
.await?;
|
||||||
};
|
|
||||||
|
drop(conn);
|
||||||
|
|
||||||
let token = if row_count == 0 {
|
let token = if row_count == 0 {
|
||||||
let token = generate_token().await?;
|
let token = generate_token().await?;
|
||||||
@@ -70,13 +69,7 @@ impl Bootstrapper {
|
|||||||
#[message]
|
#[message]
|
||||||
pub fn is_correct_token(&self, token: String) -> bool {
|
pub fn is_correct_token(&self, token: String) -> bool {
|
||||||
match &self.token {
|
match &self.token {
|
||||||
Some(expected) => {
|
Some(expected) => *expected == token,
|
||||||
let expected_bytes = expected.as_bytes();
|
|
||||||
let token_bytes = token.as_bytes();
|
|
||||||
|
|
||||||
let choice = expected_bytes.ct_eq(token_bytes);
|
|
||||||
bool::from(choice)
|
|
||||||
}
|
|
||||||
None => false,
|
None => false,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,6 +1,5 @@
|
|||||||
use arbiter_crypto::authn::{self, CLIENT_CONTEXT};
|
|
||||||
use arbiter_proto::{
|
use arbiter_proto::{
|
||||||
ClientMetadata,
|
ClientMetadata, format_challenge,
|
||||||
transport::{Bi, expect_message},
|
transport::{Bi, expect_message},
|
||||||
};
|
};
|
||||||
use chrono::Utc;
|
use chrono::Utc;
|
||||||
@@ -9,16 +8,15 @@ use diesel::{
|
|||||||
dsl::insert_into, update,
|
dsl::insert_into, update,
|
||||||
};
|
};
|
||||||
use diesel_async::RunQueryDsl as _;
|
use diesel_async::RunQueryDsl as _;
|
||||||
use kameo::{actor::ActorRef, error::SendError};
|
use ed25519_dalek::{Signature, VerifyingKey};
|
||||||
|
use kameo::error::SendError;
|
||||||
use tracing::error;
|
use tracing::error;
|
||||||
|
|
||||||
use crate::{
|
use crate::{
|
||||||
actors::{
|
actors::{
|
||||||
client::{ClientConnection, ClientCredentials, ClientProfile},
|
client::{ClientConnection, ClientProfile},
|
||||||
flow_coordinator::{self, RequestClientApproval},
|
flow_coordinator::{self, RequestClientApproval},
|
||||||
keyholder::KeyHolder,
|
|
||||||
},
|
},
|
||||||
crypto::integrity::{self, AttestationStatus},
|
|
||||||
db::{
|
db::{
|
||||||
self,
|
self,
|
||||||
models::{ProgramClientMetadata, SqliteTimestamp},
|
models::{ProgramClientMetadata, SqliteTimestamp},
|
||||||
@@ -32,8 +30,6 @@ pub enum Error {
|
|||||||
DatabasePoolUnavailable,
|
DatabasePoolUnavailable,
|
||||||
#[error("Database operation failed")]
|
#[error("Database operation failed")]
|
||||||
DatabaseOperationFailed,
|
DatabaseOperationFailed,
|
||||||
#[error("Integrity check failed")]
|
|
||||||
IntegrityCheckFailed,
|
|
||||||
#[error("Invalid challenge solution")]
|
#[error("Invalid challenge solution")]
|
||||||
InvalidChallengeSolution,
|
InvalidChallengeSolution,
|
||||||
#[error("Client approval request failed")]
|
#[error("Client approval request failed")]
|
||||||
@@ -42,13 +38,6 @@ pub enum Error {
|
|||||||
Transport,
|
Transport,
|
||||||
}
|
}
|
||||||
|
|
||||||
impl From<diesel::result::Error> for Error {
|
|
||||||
fn from(e: diesel::result::Error) -> Self {
|
|
||||||
error!(?e, "Database error");
|
|
||||||
Self::DatabaseOperationFailed
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[derive(thiserror::Error, Debug, Clone, PartialEq, Eq)]
|
#[derive(thiserror::Error, Debug, Clone, PartialEq, Eq)]
|
||||||
pub enum ApproveError {
|
pub enum ApproveError {
|
||||||
#[error("Internal error")]
|
#[error("Internal error")]
|
||||||
@@ -62,93 +51,32 @@ pub enum ApproveError {
|
|||||||
#[derive(Debug, Clone)]
|
#[derive(Debug, Clone)]
|
||||||
pub enum Inbound {
|
pub enum Inbound {
|
||||||
AuthChallengeRequest {
|
AuthChallengeRequest {
|
||||||
pubkey: authn::PublicKey,
|
pubkey: VerifyingKey,
|
||||||
metadata: ClientMetadata,
|
metadata: ClientMetadata,
|
||||||
},
|
},
|
||||||
AuthChallengeSolution {
|
AuthChallengeSolution {
|
||||||
signature: authn::Signature,
|
signature: Signature,
|
||||||
},
|
},
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Debug, Clone)]
|
#[derive(Debug, Clone)]
|
||||||
pub enum Outbound {
|
pub enum Outbound {
|
||||||
AuthChallenge {
|
AuthChallenge { pubkey: VerifyingKey, nonce: i32 },
|
||||||
pubkey: authn::PublicKey,
|
|
||||||
nonce: i32,
|
|
||||||
},
|
|
||||||
AuthSuccess,
|
AuthSuccess,
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Returns the current nonce and client ID for a registered client.
|
pub struct ClientInfo {
|
||||||
|
pub id: i32,
|
||||||
|
pub current_nonce: i32,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Atomically reads and increments the nonce for a known client.
|
||||||
/// Returns `None` if the pubkey is not registered.
|
/// Returns `None` if the pubkey is not registered.
|
||||||
async fn get_current_nonce_and_id(
|
async fn get_client_and_nonce(
|
||||||
db: &db::DatabasePool,
|
db: &db::DatabasePool,
|
||||||
pubkey: &authn::PublicKey,
|
pubkey: &VerifyingKey,
|
||||||
) -> Result<Option<(i32, i32)>, Error> {
|
) -> Result<Option<ClientInfo>, Error> {
|
||||||
let pubkey_bytes = pubkey.to_bytes();
|
let pubkey_bytes = pubkey.as_bytes().to_vec();
|
||||||
let mut conn = db.get().await.map_err(|e| {
|
|
||||||
error!(error = ?e, "Database pool error");
|
|
||||||
Error::DatabasePoolUnavailable
|
|
||||||
})?;
|
|
||||||
program_client::table
|
|
||||||
.filter(program_client::public_key.eq(&pubkey_bytes))
|
|
||||||
.select((program_client::id, program_client::nonce))
|
|
||||||
.first::<(i32, i32)>(&mut conn)
|
|
||||||
.await
|
|
||||||
.optional()
|
|
||||||
.map_err(|e| {
|
|
||||||
error!(error = ?e, "Database error");
|
|
||||||
Error::DatabaseOperationFailed
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
async fn verify_integrity(
|
|
||||||
db: &db::DatabasePool,
|
|
||||||
keyholder: &ActorRef<KeyHolder>,
|
|
||||||
pubkey: &authn::PublicKey,
|
|
||||||
) -> Result<(), Error> {
|
|
||||||
let mut db_conn = db.get().await.map_err(|e| {
|
|
||||||
error!(error = ?e, "Database pool error");
|
|
||||||
Error::DatabasePoolUnavailable
|
|
||||||
})?;
|
|
||||||
|
|
||||||
let (id, nonce) = get_current_nonce_and_id(db, pubkey).await?.ok_or_else(|| {
|
|
||||||
error!("Client not found during integrity verification");
|
|
||||||
Error::DatabaseOperationFailed
|
|
||||||
})?;
|
|
||||||
|
|
||||||
let attestation = integrity::verify_entity(
|
|
||||||
&mut db_conn,
|
|
||||||
keyholder,
|
|
||||||
&ClientCredentials {
|
|
||||||
pubkey: pubkey.clone(),
|
|
||||||
nonce,
|
|
||||||
},
|
|
||||||
id,
|
|
||||||
)
|
|
||||||
.await
|
|
||||||
.map_err(|e| {
|
|
||||||
error!(?e, "Integrity verification failed");
|
|
||||||
Error::IntegrityCheckFailed
|
|
||||||
})?;
|
|
||||||
|
|
||||||
if attestation != AttestationStatus::Attested {
|
|
||||||
error!("Integrity attestation unavailable for client {id}");
|
|
||||||
return Err(Error::IntegrityCheckFailed);
|
|
||||||
}
|
|
||||||
|
|
||||||
Ok(())
|
|
||||||
}
|
|
||||||
|
|
||||||
/// Atomically increments the nonce and re-signs the integrity envelope.
|
|
||||||
/// Returns the new nonce, which is used as the challenge nonce.
|
|
||||||
async fn create_nonce(
|
|
||||||
db: &db::DatabasePool,
|
|
||||||
keyholder: &ActorRef<KeyHolder>,
|
|
||||||
pubkey: &authn::PublicKey,
|
|
||||||
) -> Result<i32, Error> {
|
|
||||||
let pubkey_bytes = pubkey.to_bytes();
|
|
||||||
let pubkey = pubkey.clone();
|
|
||||||
|
|
||||||
let mut conn = db.get().await.map_err(|e| {
|
let mut conn = db.get().await.map_err(|e| {
|
||||||
error!(error = ?e, "Database pool error");
|
error!(error = ?e, "Database pool error");
|
||||||
@@ -156,35 +84,34 @@ async fn create_nonce(
|
|||||||
})?;
|
})?;
|
||||||
|
|
||||||
conn.exclusive_transaction(|conn| {
|
conn.exclusive_transaction(|conn| {
|
||||||
let keyholder = keyholder.clone();
|
|
||||||
let pubkey = pubkey.clone();
|
|
||||||
Box::pin(async move {
|
Box::pin(async move {
|
||||||
let (id, new_nonce): (i32, i32) = update(program_client::table)
|
let Some((client_id, current_nonce)) = program_client::table
|
||||||
.filter(program_client::public_key.eq(&pubkey_bytes))
|
.filter(program_client::public_key.eq(&pubkey_bytes))
|
||||||
.set(program_client::nonce.eq(program_client::nonce + 1))
|
.select((program_client::id, program_client::nonce))
|
||||||
.returning((program_client::id, program_client::nonce))
|
.first::<(i32, i32)>(conn)
|
||||||
.get_result(conn)
|
.await
|
||||||
|
.optional()?
|
||||||
|
else {
|
||||||
|
return Result::<_, diesel::result::Error>::Ok(None);
|
||||||
|
};
|
||||||
|
|
||||||
|
update(program_client::table)
|
||||||
|
.filter(program_client::public_key.eq(&pubkey_bytes))
|
||||||
|
.set(program_client::nonce.eq(current_nonce + 1))
|
||||||
|
.execute(conn)
|
||||||
.await?;
|
.await?;
|
||||||
|
|
||||||
integrity::sign_entity(
|
Ok(Some(ClientInfo {
|
||||||
conn,
|
id: client_id,
|
||||||
&keyholder,
|
current_nonce,
|
||||||
&ClientCredentials {
|
}))
|
||||||
pubkey: pubkey.clone(),
|
|
||||||
nonce: new_nonce,
|
|
||||||
},
|
|
||||||
id,
|
|
||||||
)
|
|
||||||
.await
|
|
||||||
.map_err(|e| {
|
|
||||||
error!(?e, "Integrity sign failed after nonce update");
|
|
||||||
Error::DatabaseOperationFailed
|
|
||||||
})?;
|
|
||||||
|
|
||||||
Ok(new_nonce)
|
|
||||||
})
|
})
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
|
.map_err(|e| {
|
||||||
|
error!(error = ?e, "Database error");
|
||||||
|
Error::DatabaseOperationFailed
|
||||||
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
async fn approve_new_client(
|
async fn approve_new_client(
|
||||||
@@ -212,65 +139,45 @@ async fn approve_new_client(
|
|||||||
|
|
||||||
async fn insert_client(
|
async fn insert_client(
|
||||||
db: &db::DatabasePool,
|
db: &db::DatabasePool,
|
||||||
keyholder: &ActorRef<KeyHolder>,
|
pubkey: &VerifyingKey,
|
||||||
pubkey: &authn::PublicKey,
|
|
||||||
metadata: &ClientMetadata,
|
metadata: &ClientMetadata,
|
||||||
) -> Result<i32, Error> {
|
) -> Result<i32, Error> {
|
||||||
use crate::db::schema::{client_metadata, program_client};
|
use crate::db::schema::{client_metadata, program_client};
|
||||||
let pubkey = pubkey.clone();
|
|
||||||
let metadata = metadata.clone();
|
|
||||||
|
|
||||||
let mut conn = db.get().await.map_err(|e| {
|
let mut conn = db.get().await.map_err(|e| {
|
||||||
error!(error = ?e, "Database pool error");
|
error!(error = ?e, "Database pool error");
|
||||||
Error::DatabasePoolUnavailable
|
Error::DatabasePoolUnavailable
|
||||||
})?;
|
})?;
|
||||||
|
|
||||||
conn.exclusive_transaction(|conn| {
|
let metadata_id = insert_into(client_metadata::table)
|
||||||
let keyholder = keyholder.clone();
|
.values((
|
||||||
let pubkey = pubkey.clone();
|
client_metadata::name.eq(&metadata.name),
|
||||||
Box::pin(async move {
|
client_metadata::description.eq(&metadata.description),
|
||||||
const NONCE_START: i32 = 1;
|
client_metadata::version.eq(&metadata.version),
|
||||||
|
))
|
||||||
|
.returning(client_metadata::id)
|
||||||
|
.get_result::<i32>(&mut conn)
|
||||||
|
.await
|
||||||
|
.map_err(|e| {
|
||||||
|
error!(error = ?e, "Failed to insert client metadata");
|
||||||
|
Error::DatabaseOperationFailed
|
||||||
|
})?;
|
||||||
|
|
||||||
let metadata_id = insert_into(client_metadata::table)
|
let client_id = insert_into(program_client::table)
|
||||||
.values((
|
.values((
|
||||||
client_metadata::name.eq(&metadata.name),
|
program_client::public_key.eq(pubkey.as_bytes().to_vec()),
|
||||||
client_metadata::description.eq(&metadata.description),
|
program_client::metadata_id.eq(metadata_id),
|
||||||
client_metadata::version.eq(&metadata.version),
|
program_client::nonce.eq(1), // pre-incremented; challenge uses 0
|
||||||
))
|
))
|
||||||
.returning(client_metadata::id)
|
.on_conflict_do_nothing()
|
||||||
.get_result::<i32>(conn)
|
.returning(program_client::id)
|
||||||
.await?;
|
.get_result::<i32>(&mut conn)
|
||||||
|
.await
|
||||||
|
.map_err(|e| {
|
||||||
|
error!(error = ?e, "Failed to insert client metadata");
|
||||||
|
Error::DatabaseOperationFailed
|
||||||
|
})?;
|
||||||
|
|
||||||
let client_id = insert_into(program_client::table)
|
Ok(client_id)
|
||||||
.values((
|
|
||||||
program_client::public_key.eq(pubkey.to_bytes()),
|
|
||||||
program_client::metadata_id.eq(metadata_id),
|
|
||||||
program_client::nonce.eq(NONCE_START),
|
|
||||||
))
|
|
||||||
.on_conflict_do_nothing()
|
|
||||||
.returning(program_client::id)
|
|
||||||
.get_result::<i32>(conn)
|
|
||||||
.await?;
|
|
||||||
|
|
||||||
integrity::sign_entity(
|
|
||||||
conn,
|
|
||||||
&keyholder,
|
|
||||||
&ClientCredentials {
|
|
||||||
pubkey: pubkey.clone(),
|
|
||||||
nonce: NONCE_START,
|
|
||||||
},
|
|
||||||
client_id,
|
|
||||||
)
|
|
||||||
.await
|
|
||||||
.map_err(|e| {
|
|
||||||
error!(error = ?e, "Failed to sign integrity tag for new client key");
|
|
||||||
Error::DatabaseOperationFailed
|
|
||||||
})?;
|
|
||||||
|
|
||||||
Ok(client_id)
|
|
||||||
})
|
|
||||||
})
|
|
||||||
.await
|
|
||||||
}
|
}
|
||||||
|
|
||||||
async fn sync_client_metadata(
|
async fn sync_client_metadata(
|
||||||
@@ -346,17 +253,14 @@ async fn sync_client_metadata(
|
|||||||
|
|
||||||
async fn challenge_client<T>(
|
async fn challenge_client<T>(
|
||||||
transport: &mut T,
|
transport: &mut T,
|
||||||
pubkey: authn::PublicKey,
|
pubkey: VerifyingKey,
|
||||||
nonce: i32,
|
nonce: i32,
|
||||||
) -> Result<(), Error>
|
) -> Result<(), Error>
|
||||||
where
|
where
|
||||||
T: Bi<Inbound, Result<Outbound, Error>> + ?Sized,
|
T: Bi<Inbound, Result<Outbound, Error>> + ?Sized,
|
||||||
{
|
{
|
||||||
transport
|
transport
|
||||||
.send(Ok(Outbound::AuthChallenge {
|
.send(Ok(Outbound::AuthChallenge { pubkey, nonce }))
|
||||||
pubkey: pubkey.clone(),
|
|
||||||
nonce,
|
|
||||||
}))
|
|
||||||
.await
|
.await
|
||||||
.map_err(|e| {
|
.map_err(|e| {
|
||||||
error!(error = ?e, "Failed to send auth challenge");
|
error!(error = ?e, "Failed to send auth challenge");
|
||||||
@@ -373,10 +277,12 @@ where
|
|||||||
Error::Transport
|
Error::Transport
|
||||||
})?;
|
})?;
|
||||||
|
|
||||||
if !pubkey.verify(nonce, CLIENT_CONTEXT, &signature) {
|
let formatted = format_challenge(nonce, pubkey.as_bytes());
|
||||||
|
|
||||||
|
pubkey.verify_strict(&formatted, &signature).map_err(|_| {
|
||||||
error!("Challenge solution verification failed");
|
error!("Challenge solution verification failed");
|
||||||
return Err(Error::InvalidChallengeSolution);
|
Error::InvalidChallengeSolution
|
||||||
}
|
})?;
|
||||||
|
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
@@ -389,27 +295,27 @@ where
|
|||||||
return Err(Error::Transport);
|
return Err(Error::Transport);
|
||||||
};
|
};
|
||||||
|
|
||||||
let client_id = match get_current_nonce_and_id(&props.db, &pubkey).await? {
|
let info = match get_client_and_nonce(&props.db, &pubkey).await? {
|
||||||
Some((id, _)) => {
|
Some(nonce) => nonce,
|
||||||
verify_integrity(&props.db, &props.actors.key_holder, &pubkey).await?;
|
|
||||||
id
|
|
||||||
}
|
|
||||||
None => {
|
None => {
|
||||||
approve_new_client(
|
approve_new_client(
|
||||||
&props.actors,
|
&props.actors,
|
||||||
ClientProfile {
|
ClientProfile {
|
||||||
pubkey: pubkey.clone(),
|
pubkey,
|
||||||
metadata: metadata.clone(),
|
metadata: metadata.clone(),
|
||||||
},
|
},
|
||||||
)
|
)
|
||||||
.await?;
|
.await?;
|
||||||
insert_client(&props.db, &props.actors.key_holder, &pubkey, &metadata).await?
|
let client_id = insert_client(&props.db, &pubkey, &metadata).await?;
|
||||||
|
ClientInfo {
|
||||||
|
id: client_id,
|
||||||
|
current_nonce: 0,
|
||||||
|
}
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
sync_client_metadata(&props.db, client_id, &metadata).await?;
|
sync_client_metadata(&props.db, info.id, &metadata).await?;
|
||||||
let challenge_nonce = create_nonce(&props.db, &props.actors.key_holder, &pubkey).await?;
|
challenge_client(transport, pubkey, info.current_nonce).await?;
|
||||||
challenge_client(transport, pubkey, challenge_nonce).await?;
|
|
||||||
|
|
||||||
transport
|
transport
|
||||||
.send(Ok(Outbound::AuthSuccess))
|
.send(Ok(Outbound::AuthSuccess))
|
||||||
@@ -419,5 +325,5 @@ where
|
|||||||
Error::Transport
|
Error::Transport
|
||||||
})?;
|
})?;
|
||||||
|
|
||||||
Ok(client_id)
|
Ok(info.id)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,30 +1,18 @@
|
|||||||
use arbiter_crypto::authn;
|
|
||||||
use arbiter_proto::{ClientMetadata, transport::Bi};
|
use arbiter_proto::{ClientMetadata, transport::Bi};
|
||||||
use kameo::actor::Spawn;
|
use kameo::actor::Spawn;
|
||||||
use tracing::{error, info};
|
use tracing::{error, info};
|
||||||
|
|
||||||
use crate::{
|
use crate::{
|
||||||
actors::{GlobalActors, client::session::ClientSession},
|
actors::{GlobalActors, client::session::ClientSession},
|
||||||
crypto::integrity::Integrable,
|
|
||||||
db,
|
db,
|
||||||
};
|
};
|
||||||
|
|
||||||
#[derive(Debug, Clone)]
|
#[derive(Debug, Clone)]
|
||||||
pub struct ClientProfile {
|
pub struct ClientProfile {
|
||||||
pub pubkey: authn::PublicKey,
|
pub pubkey: ed25519_dalek::VerifyingKey,
|
||||||
pub metadata: ClientMetadata,
|
pub metadata: ClientMetadata,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(arbiter_macros::Hashable)]
|
|
||||||
pub struct ClientCredentials {
|
|
||||||
pub pubkey: authn::PublicKey,
|
|
||||||
pub nonce: i32,
|
|
||||||
}
|
|
||||||
|
|
||||||
impl Integrable for ClientCredentials {
|
|
||||||
const KIND: &'static str = "client_credentials";
|
|
||||||
}
|
|
||||||
|
|
||||||
pub struct ClientConnection {
|
pub struct ClientConnection {
|
||||||
pub(crate) db: db::DatabasePool,
|
pub(crate) db: db::DatabasePool,
|
||||||
pub(crate) actors: GlobalActors,
|
pub(crate) actors: GlobalActors,
|
||||||
@@ -43,9 +31,7 @@ pub async fn connect_client<T>(mut props: ClientConnection, transport: &mut T)
|
|||||||
where
|
where
|
||||||
T: Bi<auth::Inbound, Result<auth::Outbound, auth::Error>> + Send + ?Sized,
|
T: Bi<auth::Inbound, Result<auth::Outbound, auth::Error>> + Send + ?Sized,
|
||||||
{
|
{
|
||||||
let fut = auth::authenticate(&mut props, transport);
|
match auth::authenticate(&mut props, transport).await {
|
||||||
println!("authenticate future size: {}", std::mem::size_of_val(&fut));
|
|
||||||
match fut.await {
|
|
||||||
Ok(client_id) => {
|
Ok(client_id) => {
|
||||||
ClientSession::spawn(ClientSession::new(props, client_id));
|
ClientSession::spawn(ClientSession::new(props, client_id));
|
||||||
info!("Client authenticated, session started");
|
info!("Client authenticated, session started");
|
||||||
|
|||||||
@@ -1,8 +1,9 @@
|
|||||||
use alloy::{consensus::TxEip1559, primitives::Address, signers::Signature};
|
use alloy::{consensus::TxEip1559, primitives::Address, signers::Signature};
|
||||||
use diesel::{
|
use diesel::{
|
||||||
ExpressionMethods, OptionalExtension as _, QueryDsl, SelectableHelper as _, dsl::insert_into,
|
BoolExpressionMethods as _, ExpressionMethods, OptionalExtension as _, QueryDsl,
|
||||||
|
SelectableHelper as _, dsl::insert_into,
|
||||||
};
|
};
|
||||||
use diesel_async::RunQueryDsl;
|
use diesel_async::{AsyncConnection as _, RunQueryDsl};
|
||||||
use kameo::{Actor, actor::ActorRef, messages};
|
use kameo::{Actor, actor::ActorRef, messages};
|
||||||
use rand::{SeedableRng, rng, rngs::StdRng};
|
use rand::{SeedableRng, rng, rngs::StdRng};
|
||||||
|
|
||||||
@@ -21,8 +22,8 @@ use crate::{
|
|||||||
ether_transfer::EtherTransfer, token_transfers::TokenTransfer,
|
ether_transfer::EtherTransfer, token_transfers::TokenTransfer,
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
safe_cell::{SafeCell, SafeCellHandle as _},
|
||||||
};
|
};
|
||||||
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
|
||||||
|
|
||||||
pub use crate::evm::safe_signer;
|
pub use crate::evm::safe_signer;
|
||||||
|
|
||||||
@@ -158,28 +159,115 @@ impl EvmActor {
|
|||||||
}
|
}
|
||||||
|
|
||||||
#[message]
|
#[message]
|
||||||
pub async fn useragent_delete_grant(&mut self, _grant_id: i32) -> Result<(), Error> {
|
pub async fn useragent_delete_grant(&mut self, grant_id: i32) -> Result<(), Error> {
|
||||||
// let mut conn = self.db.get().await.map_err(DatabaseError::from)?;
|
let mut conn = self.db.get().await.map_err(DatabaseError::from)?;
|
||||||
// let keyholder = self.keyholder.clone();
|
|
||||||
|
|
||||||
// diesel_async::AsyncConnection::transaction(&mut conn, |conn| {
|
// We intentionally perform a hard delete here to avoid leaving revoked grants and their
|
||||||
// Box::pin(async move {
|
// related rows as long-lived DB garbage. We also don't rely on SQLite FK cascades because
|
||||||
// diesel::update(schema::evm_basic_grant::table)
|
// they can be disabled per-connection.
|
||||||
// .filter(schema::evm_basic_grant::id.eq(grant_id))
|
conn.transaction(|conn| {
|
||||||
// .set(schema::evm_basic_grant::revoked_at.eq(SqliteTimestamp::now()))
|
Box::pin(async move {
|
||||||
// .execute(conn)
|
// First, resolve policy-specific rows by basic grant id.
|
||||||
// .await?;
|
let token_grant_id: Option<i32> = schema::evm_token_transfer_grant::table
|
||||||
|
.select(schema::evm_token_transfer_grant::id)
|
||||||
|
.filter(schema::evm_token_transfer_grant::basic_grant_id.eq(grant_id))
|
||||||
|
.first::<i32>(conn)
|
||||||
|
.await
|
||||||
|
.optional()?;
|
||||||
|
|
||||||
// let signed = integrity::evm::load_signed_grant_by_basic_id(conn, grant_id).await?;
|
let ether_grant: Option<(i32, i32)> = schema::evm_ether_transfer_grant::table
|
||||||
|
.select((
|
||||||
|
schema::evm_ether_transfer_grant::id,
|
||||||
|
schema::evm_ether_transfer_grant::limit_id,
|
||||||
|
))
|
||||||
|
.filter(schema::evm_ether_transfer_grant::basic_grant_id.eq(grant_id))
|
||||||
|
.first::<(i32, i32)>(conn)
|
||||||
|
.await
|
||||||
|
.optional()?;
|
||||||
|
|
||||||
// diesel::result::QueryResult::Ok(())
|
// Token-transfer: logs must be deleted before transaction logs (FK restrict).
|
||||||
// })
|
if let Some(token_grant_id) = token_grant_id {
|
||||||
// })
|
diesel::delete(
|
||||||
// .await
|
schema::evm_token_transfer_log::table
|
||||||
// .map_err(DatabaseError::from)?;
|
.filter(schema::evm_token_transfer_log::grant_id.eq(token_grant_id)),
|
||||||
|
)
|
||||||
|
.execute(conn)
|
||||||
|
.await?;
|
||||||
|
|
||||||
// Ok(())
|
diesel::delete(schema::evm_token_transfer_volume_limit::table.filter(
|
||||||
todo!()
|
schema::evm_token_transfer_volume_limit::grant_id.eq(token_grant_id),
|
||||||
|
))
|
||||||
|
.execute(conn)
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
diesel::delete(
|
||||||
|
schema::evm_token_transfer_grant::table
|
||||||
|
.filter(schema::evm_token_transfer_grant::id.eq(token_grant_id)),
|
||||||
|
)
|
||||||
|
.execute(conn)
|
||||||
|
.await?;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Shared transaction logs for any grant kind.
|
||||||
|
diesel::delete(
|
||||||
|
schema::evm_transaction_log::table
|
||||||
|
.filter(schema::evm_transaction_log::grant_id.eq(grant_id)),
|
||||||
|
)
|
||||||
|
.execute(conn)
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
// Ether-transfer: delete targets, grant row, then its limit row.
|
||||||
|
if let Some((ether_grant_id, limit_id)) = ether_grant {
|
||||||
|
diesel::delete(schema::evm_ether_transfer_grant_target::table.filter(
|
||||||
|
schema::evm_ether_transfer_grant_target::grant_id.eq(ether_grant_id),
|
||||||
|
))
|
||||||
|
.execute(conn)
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
diesel::delete(
|
||||||
|
schema::evm_ether_transfer_grant::table
|
||||||
|
.filter(schema::evm_ether_transfer_grant::id.eq(ether_grant_id)),
|
||||||
|
)
|
||||||
|
.execute(conn)
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
diesel::delete(
|
||||||
|
schema::evm_ether_transfer_limit::table
|
||||||
|
.filter(schema::evm_ether_transfer_limit::id.eq(limit_id)),
|
||||||
|
)
|
||||||
|
.execute(conn)
|
||||||
|
.await?;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Integrity envelopes are not FK-constrained; delete only grant-related kinds to
|
||||||
|
// avoid accidentally deleting other entities that share the same integer ID.
|
||||||
|
let entity_id = grant_id.to_be_bytes().to_vec();
|
||||||
|
diesel::delete(
|
||||||
|
schema::integrity_envelope::table
|
||||||
|
.filter(schema::integrity_envelope::entity_id.eq(entity_id))
|
||||||
|
.filter(
|
||||||
|
schema::integrity_envelope::entity_kind
|
||||||
|
.eq("EtherTransfer")
|
||||||
|
.or(schema::integrity_envelope::entity_kind.eq("TokenTransfer")),
|
||||||
|
),
|
||||||
|
)
|
||||||
|
.execute(conn)
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
// Finally remove the basic grant row itself (idempotent if it doesn't exist).
|
||||||
|
diesel::delete(
|
||||||
|
schema::evm_basic_grant::table.filter(schema::evm_basic_grant::id.eq(grant_id)),
|
||||||
|
)
|
||||||
|
.execute(conn)
|
||||||
|
.await?;
|
||||||
|
|
||||||
|
diesel::result::QueryResult::Ok(())
|
||||||
|
})
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.map_err(DatabaseError::from)?;
|
||||||
|
|
||||||
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
#[message]
|
#[message]
|
||||||
@@ -271,3 +359,6 @@ impl EvmActor {
|
|||||||
Ok(signer.sign_transaction_sync(&mut transaction)?)
|
Ok(signer.sign_transaction_sync(&mut transaction)?)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests;
|
||||||
|
|||||||
283
server/crates/arbiter-server/src/actors/evm/tests.rs
Normal file
283
server/crates/arbiter-server/src/actors/evm/tests.rs
Normal file
@@ -0,0 +1,283 @@
|
|||||||
|
use diesel::{ExpressionMethods as _, QueryDsl as _, dsl::insert_into};
|
||||||
|
use diesel_async::RunQueryDsl;
|
||||||
|
use kameo::actor::Spawn as _;
|
||||||
|
|
||||||
|
use crate::{
|
||||||
|
actors::{evm::EvmActor, keyholder::KeyHolder},
|
||||||
|
db::{self, models, schema},
|
||||||
|
};
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn delete_ether_grant_cleans_related_tables() {
|
||||||
|
let db = db::create_test_pool().await;
|
||||||
|
let keyholder = KeyHolder::spawn(KeyHolder::new(db.clone()).await.unwrap());
|
||||||
|
let mut actor = EvmActor::new(keyholder, db.clone());
|
||||||
|
|
||||||
|
let mut conn = db.get().await.unwrap();
|
||||||
|
|
||||||
|
let basic_id: i32 = insert_into(schema::evm_basic_grant::table)
|
||||||
|
.values(&models::NewEvmBasicGrant {
|
||||||
|
wallet_access_id: 1,
|
||||||
|
chain_id: 1,
|
||||||
|
valid_from: None,
|
||||||
|
valid_until: None,
|
||||||
|
max_gas_fee_per_gas: None,
|
||||||
|
max_priority_fee_per_gas: None,
|
||||||
|
rate_limit_count: None,
|
||||||
|
rate_limit_window_secs: None,
|
||||||
|
revoked_at: None,
|
||||||
|
})
|
||||||
|
.returning(schema::evm_basic_grant::id)
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
let limit_id: i32 = insert_into(schema::evm_ether_transfer_limit::table)
|
||||||
|
.values(&models::NewEvmEtherTransferLimit {
|
||||||
|
window_secs: 60,
|
||||||
|
max_volume: vec![1],
|
||||||
|
})
|
||||||
|
.returning(schema::evm_ether_transfer_limit::id)
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
let ether_grant_id: i32 = insert_into(schema::evm_ether_transfer_grant::table)
|
||||||
|
.values(&models::NewEvmEtherTransferGrant {
|
||||||
|
basic_grant_id: basic_id,
|
||||||
|
limit_id,
|
||||||
|
})
|
||||||
|
.returning(schema::evm_ether_transfer_grant::id)
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
insert_into(schema::evm_ether_transfer_grant_target::table)
|
||||||
|
.values(&models::NewEvmEtherTransferGrantTarget {
|
||||||
|
grant_id: ether_grant_id,
|
||||||
|
address: vec![0u8; 20],
|
||||||
|
})
|
||||||
|
.execute(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
insert_into(schema::evm_transaction_log::table)
|
||||||
|
.values(&models::NewEvmTransactionLog {
|
||||||
|
grant_id: basic_id,
|
||||||
|
wallet_access_id: 1,
|
||||||
|
chain_id: 1,
|
||||||
|
eth_value: vec![0],
|
||||||
|
signed_at: models::SqliteTimestamp::now(),
|
||||||
|
})
|
||||||
|
.execute(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
insert_into(schema::integrity_envelope::table)
|
||||||
|
.values(&models::NewIntegrityEnvelope {
|
||||||
|
entity_kind: "EtherTransfer".to_owned(),
|
||||||
|
entity_id: basic_id.to_be_bytes().to_vec(),
|
||||||
|
payload_version: 1,
|
||||||
|
key_version: 1,
|
||||||
|
mac: vec![0u8; 32],
|
||||||
|
})
|
||||||
|
.execute(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
drop(conn);
|
||||||
|
|
||||||
|
actor.useragent_delete_grant(basic_id).await.unwrap();
|
||||||
|
|
||||||
|
// Idempotency: second delete should be a no-op.
|
||||||
|
actor.useragent_delete_grant(basic_id).await.unwrap();
|
||||||
|
|
||||||
|
let mut conn = db.get().await.unwrap();
|
||||||
|
|
||||||
|
let basic_count: i64 = schema::evm_basic_grant::table
|
||||||
|
.count()
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert_eq!(basic_count, 0);
|
||||||
|
|
||||||
|
let ether_grant_count: i64 = schema::evm_ether_transfer_grant::table
|
||||||
|
.count()
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert_eq!(ether_grant_count, 0);
|
||||||
|
|
||||||
|
let target_count: i64 = schema::evm_ether_transfer_grant_target::table
|
||||||
|
.count()
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert_eq!(target_count, 0);
|
||||||
|
|
||||||
|
let limit_count: i64 = schema::evm_ether_transfer_limit::table
|
||||||
|
.count()
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert_eq!(limit_count, 0);
|
||||||
|
|
||||||
|
let log_count: i64 = schema::evm_transaction_log::table
|
||||||
|
.count()
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert_eq!(log_count, 0);
|
||||||
|
|
||||||
|
let envelope_count: i64 = schema::integrity_envelope::table
|
||||||
|
.filter(schema::integrity_envelope::entity_kind.eq("EtherTransfer"))
|
||||||
|
.count()
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert_eq!(envelope_count, 0);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn delete_token_grant_cleans_related_tables() {
|
||||||
|
let db = db::create_test_pool().await;
|
||||||
|
let keyholder = KeyHolder::spawn(KeyHolder::new(db.clone()).await.unwrap());
|
||||||
|
let mut actor = EvmActor::new(keyholder, db.clone());
|
||||||
|
|
||||||
|
let mut conn = db.get().await.unwrap();
|
||||||
|
|
||||||
|
let basic_id: i32 = insert_into(schema::evm_basic_grant::table)
|
||||||
|
.values(&models::NewEvmBasicGrant {
|
||||||
|
wallet_access_id: 1,
|
||||||
|
chain_id: 1,
|
||||||
|
valid_from: None,
|
||||||
|
valid_until: None,
|
||||||
|
max_gas_fee_per_gas: None,
|
||||||
|
max_priority_fee_per_gas: None,
|
||||||
|
rate_limit_count: None,
|
||||||
|
rate_limit_window_secs: None,
|
||||||
|
revoked_at: None,
|
||||||
|
})
|
||||||
|
.returning(schema::evm_basic_grant::id)
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
let token_grant_id: i32 = insert_into(schema::evm_token_transfer_grant::table)
|
||||||
|
.values(&models::NewEvmTokenTransferGrant {
|
||||||
|
basic_grant_id: basic_id,
|
||||||
|
token_contract: vec![1u8; 20],
|
||||||
|
receiver: None,
|
||||||
|
})
|
||||||
|
.returning(schema::evm_token_transfer_grant::id)
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
insert_into(schema::evm_token_transfer_volume_limit::table)
|
||||||
|
.values(&models::NewEvmTokenTransferVolumeLimit {
|
||||||
|
grant_id: token_grant_id,
|
||||||
|
window_secs: 60,
|
||||||
|
max_volume: vec![1],
|
||||||
|
})
|
||||||
|
.execute(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
insert_into(schema::evm_token_transfer_volume_limit::table)
|
||||||
|
.values(&models::NewEvmTokenTransferVolumeLimit {
|
||||||
|
grant_id: token_grant_id,
|
||||||
|
window_secs: 3600,
|
||||||
|
max_volume: vec![2],
|
||||||
|
})
|
||||||
|
.execute(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
let tx_log_id: i32 = insert_into(schema::evm_transaction_log::table)
|
||||||
|
.values(&models::NewEvmTransactionLog {
|
||||||
|
grant_id: basic_id,
|
||||||
|
wallet_access_id: 1,
|
||||||
|
chain_id: 1,
|
||||||
|
eth_value: vec![0],
|
||||||
|
signed_at: models::SqliteTimestamp::now(),
|
||||||
|
})
|
||||||
|
.returning(schema::evm_transaction_log::id)
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
insert_into(schema::evm_token_transfer_log::table)
|
||||||
|
.values(&models::NewEvmTokenTransferLog {
|
||||||
|
grant_id: token_grant_id,
|
||||||
|
log_id: tx_log_id,
|
||||||
|
chain_id: 1,
|
||||||
|
token_contract: vec![1u8; 20],
|
||||||
|
recipient_address: vec![2u8; 20],
|
||||||
|
value: vec![3],
|
||||||
|
})
|
||||||
|
.execute(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
insert_into(schema::integrity_envelope::table)
|
||||||
|
.values(&models::NewIntegrityEnvelope {
|
||||||
|
entity_kind: "TokenTransfer".to_owned(),
|
||||||
|
entity_id: basic_id.to_be_bytes().to_vec(),
|
||||||
|
payload_version: 1,
|
||||||
|
key_version: 1,
|
||||||
|
mac: vec![0u8; 32],
|
||||||
|
})
|
||||||
|
.execute(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
drop(conn);
|
||||||
|
|
||||||
|
actor.useragent_delete_grant(basic_id).await.unwrap();
|
||||||
|
|
||||||
|
let mut conn = db.get().await.unwrap();
|
||||||
|
|
||||||
|
let basic_count: i64 = schema::evm_basic_grant::table
|
||||||
|
.count()
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert_eq!(basic_count, 0);
|
||||||
|
|
||||||
|
let token_grant_count: i64 = schema::evm_token_transfer_grant::table
|
||||||
|
.count()
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert_eq!(token_grant_count, 0);
|
||||||
|
|
||||||
|
let token_limits_count: i64 = schema::evm_token_transfer_volume_limit::table
|
||||||
|
.count()
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert_eq!(token_limits_count, 0);
|
||||||
|
|
||||||
|
let token_logs_count: i64 = schema::evm_token_transfer_log::table
|
||||||
|
.count()
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert_eq!(token_logs_count, 0);
|
||||||
|
|
||||||
|
let tx_logs_count: i64 = schema::evm_transaction_log::table
|
||||||
|
.count()
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert_eq!(tx_logs_count, 0);
|
||||||
|
|
||||||
|
let envelope_count: i64 = schema::integrity_envelope::table
|
||||||
|
.filter(schema::integrity_envelope::entity_kind.eq("TokenTransfer"))
|
||||||
|
.count()
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert_eq!(envelope_count, 0);
|
||||||
|
}
|
||||||
@@ -9,17 +9,22 @@ use kameo::{Actor, Reply, messages};
|
|||||||
use strum::{EnumDiscriminants, IntoDiscriminant};
|
use strum::{EnumDiscriminants, IntoDiscriminant};
|
||||||
use tracing::{error, info};
|
use tracing::{error, info};
|
||||||
|
|
||||||
use crate::crypto::{
|
use crate::{
|
||||||
KeyCell, derive_key,
|
crypto::{
|
||||||
encryption::v1::{self, Nonce},
|
KeyCell, derive_key,
|
||||||
integrity::v1::HmacSha256,
|
encryption::v1::{self, Nonce},
|
||||||
|
integrity::v1::HmacSha256,
|
||||||
|
},
|
||||||
|
safe_cell::SafeCell,
|
||||||
};
|
};
|
||||||
use crate::db::{
|
use crate::{
|
||||||
self,
|
db::{
|
||||||
models::{self, RootKeyHistory},
|
self,
|
||||||
schema::{self},
|
models::{self, RootKeyHistory},
|
||||||
|
schema::{self},
|
||||||
|
},
|
||||||
|
safe_cell::SafeCellHandle as _,
|
||||||
};
|
};
|
||||||
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
|
||||||
|
|
||||||
#[derive(Default, EnumDiscriminants)]
|
#[derive(Default, EnumDiscriminants)]
|
||||||
#[strum_discriminants(derive(Reply), vis(pub), name(KeyHolderState))]
|
#[strum_discriminants(derive(Reply), vis(pub), name(KeyHolderState))]
|
||||||
@@ -395,8 +400,10 @@ mod tests {
|
|||||||
|
|
||||||
use diesel_async::RunQueryDsl;
|
use diesel_async::RunQueryDsl;
|
||||||
|
|
||||||
use crate::db::{self};
|
use crate::{
|
||||||
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
db::{self},
|
||||||
|
safe_cell::SafeCell,
|
||||||
|
};
|
||||||
|
|
||||||
use super::*;
|
use super::*;
|
||||||
|
|
||||||
|
|||||||
@@ -1,18 +1,18 @@
|
|||||||
use arbiter_crypto::authn;
|
|
||||||
use arbiter_proto::transport::Bi;
|
use arbiter_proto::transport::Bi;
|
||||||
use tracing::error;
|
use tracing::error;
|
||||||
|
|
||||||
use crate::actors::user_agent::{
|
use crate::actors::user_agent::{
|
||||||
UserAgentConnection,
|
AuthPublicKey, UserAgentConnection,
|
||||||
auth::state::{AuthContext, AuthStateMachine},
|
auth::state::{AuthContext, AuthStateMachine},
|
||||||
};
|
};
|
||||||
|
|
||||||
mod state;
|
mod state;
|
||||||
use state::*;
|
use state::*;
|
||||||
|
|
||||||
#[derive(Debug, Clone)]
|
#[derive(Debug, Clone)]
|
||||||
pub enum Inbound {
|
pub enum Inbound {
|
||||||
AuthChallengeRequest {
|
AuthChallengeRequest {
|
||||||
pubkey: authn::PublicKey,
|
pubkey: AuthPublicKey,
|
||||||
bootstrap_token: Option<String>,
|
bootstrap_token: Option<String>,
|
||||||
},
|
},
|
||||||
AuthChallengeSolution {
|
AuthChallengeSolution {
|
||||||
@@ -71,7 +71,7 @@ fn parse_auth_event(payload: Inbound) -> AuthEvents {
|
|||||||
pub async fn authenticate<T>(
|
pub async fn authenticate<T>(
|
||||||
props: &mut UserAgentConnection,
|
props: &mut UserAgentConnection,
|
||||||
transport: T,
|
transport: T,
|
||||||
) -> Result<authn::PublicKey, Error>
|
) -> Result<AuthPublicKey, Error>
|
||||||
where
|
where
|
||||||
T: Bi<Inbound, Result<Outbound, Error>> + Send,
|
T: Bi<Inbound, Result<Outbound, Error>> + Send,
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -1,8 +1,7 @@
|
|||||||
use arbiter_crypto::authn::{self, USERAGENT_CONTEXT};
|
|
||||||
use arbiter_proto::transport::Bi;
|
use arbiter_proto::transport::Bi;
|
||||||
use diesel::{ExpressionMethods as _, OptionalExtension as _, QueryDsl, update};
|
use diesel::{ExpressionMethods as _, OptionalExtension as _, QueryDsl, update};
|
||||||
use diesel_async::{AsyncConnection, RunQueryDsl};
|
use diesel_async::{AsyncConnection, RunQueryDsl};
|
||||||
use kameo::actor::ActorRef;
|
use kameo::{actor::ActorRef, error::SendError};
|
||||||
use tracing::error;
|
use tracing::error;
|
||||||
|
|
||||||
use super::Error;
|
use super::Error;
|
||||||
@@ -10,24 +9,24 @@ use crate::{
|
|||||||
actors::{
|
actors::{
|
||||||
bootstrap::ConsumeToken,
|
bootstrap::ConsumeToken,
|
||||||
keyholder::KeyHolder,
|
keyholder::KeyHolder,
|
||||||
user_agent::{UserAgentConnection, UserAgentCredentials, auth::Outbound},
|
user_agent::{AuthPublicKey, UserAgentConnection, UserAgentCredentials, auth::Outbound},
|
||||||
},
|
},
|
||||||
crypto::integrity,
|
crypto::integrity::{self, AttestationStatus},
|
||||||
db::{DatabasePool, schema::useragent_client},
|
db::{DatabasePool, schema::useragent_client},
|
||||||
};
|
};
|
||||||
|
|
||||||
pub struct ChallengeRequest {
|
pub struct ChallengeRequest {
|
||||||
pub pubkey: authn::PublicKey,
|
pub pubkey: AuthPublicKey,
|
||||||
}
|
}
|
||||||
|
|
||||||
pub struct BootstrapAuthRequest {
|
pub struct BootstrapAuthRequest {
|
||||||
pub pubkey: authn::PublicKey,
|
pub pubkey: AuthPublicKey,
|
||||||
pub token: String,
|
pub token: String,
|
||||||
}
|
}
|
||||||
|
|
||||||
pub struct ChallengeContext {
|
pub struct ChallengeContext {
|
||||||
pub challenge_nonce: i32,
|
pub challenge_nonce: i32,
|
||||||
pub key: authn::PublicKey,
|
pub key: AuthPublicKey,
|
||||||
}
|
}
|
||||||
|
|
||||||
pub struct ChallengeSolution {
|
pub struct ChallengeSolution {
|
||||||
@@ -39,15 +38,15 @@ smlang::statemachine!(
|
|||||||
custom_error: true,
|
custom_error: true,
|
||||||
transitions: {
|
transitions: {
|
||||||
*Init + AuthRequest(ChallengeRequest) / async prepare_challenge = SentChallenge(ChallengeContext),
|
*Init + AuthRequest(ChallengeRequest) / async prepare_challenge = SentChallenge(ChallengeContext),
|
||||||
Init + BootstrapAuthRequest(BootstrapAuthRequest) / async verify_bootstrap_token = AuthOk(authn::PublicKey),
|
Init + BootstrapAuthRequest(BootstrapAuthRequest) / async verify_bootstrap_token = AuthOk(AuthPublicKey),
|
||||||
SentChallenge(ChallengeContext) + ReceivedSolution(ChallengeSolution) / async verify_solution = AuthOk(authn::PublicKey),
|
SentChallenge(ChallengeContext) + ReceivedSolution(ChallengeSolution) / async verify_solution = AuthOk(AuthPublicKey),
|
||||||
}
|
}
|
||||||
);
|
);
|
||||||
|
|
||||||
/// Returns the current nonce, ready to use for the challenge nonce.
|
/// Returns the current nonce, ready to use for the challenge nonce.
|
||||||
async fn get_current_nonce_and_id(
|
async fn get_current_nonce_and_id(
|
||||||
db: &DatabasePool,
|
db: &DatabasePool,
|
||||||
key: &authn::PublicKey,
|
key: &AuthPublicKey,
|
||||||
) -> Result<(i32, i32), Error> {
|
) -> Result<(i32, i32), Error> {
|
||||||
let mut db_conn = db.get().await.map_err(|e| {
|
let mut db_conn = db.get().await.map_err(|e| {
|
||||||
error!(error = ?e, "Database pool error");
|
error!(error = ?e, "Database pool error");
|
||||||
@@ -57,7 +56,8 @@ async fn get_current_nonce_and_id(
|
|||||||
.exclusive_transaction(|conn| {
|
.exclusive_transaction(|conn| {
|
||||||
Box::pin(async move {
|
Box::pin(async move {
|
||||||
useragent_client::table
|
useragent_client::table
|
||||||
.filter(useragent_client::public_key.eq(key.to_bytes()))
|
.filter(useragent_client::public_key.eq(key.to_stored_bytes()))
|
||||||
|
.filter(useragent_client::key_type.eq(key.key_type()))
|
||||||
.select((useragent_client::id, useragent_client::nonce))
|
.select((useragent_client::id, useragent_client::nonce))
|
||||||
.first::<(i32, i32)>(conn)
|
.first::<(i32, i32)>(conn)
|
||||||
.await
|
.await
|
||||||
@@ -78,7 +78,7 @@ async fn get_current_nonce_and_id(
|
|||||||
async fn verify_integrity(
|
async fn verify_integrity(
|
||||||
db: &DatabasePool,
|
db: &DatabasePool,
|
||||||
keyholder: &ActorRef<KeyHolder>,
|
keyholder: &ActorRef<KeyHolder>,
|
||||||
pubkey: &authn::PublicKey,
|
pubkey: &AuthPublicKey,
|
||||||
) -> Result<(), Error> {
|
) -> Result<(), Error> {
|
||||||
let mut db_conn = db.get().await.map_err(|e| {
|
let mut db_conn = db.get().await.map_err(|e| {
|
||||||
error!(error = ?e, "Database pool error");
|
error!(error = ?e, "Database pool error");
|
||||||
@@ -87,7 +87,7 @@ async fn verify_integrity(
|
|||||||
|
|
||||||
let (id, nonce) = get_current_nonce_and_id(db, pubkey).await?;
|
let (id, nonce) = get_current_nonce_and_id(db, pubkey).await?;
|
||||||
|
|
||||||
let _result = integrity::verify_entity(
|
let result = integrity::verify_entity(
|
||||||
&mut db_conn,
|
&mut db_conn,
|
||||||
keyholder,
|
keyholder,
|
||||||
&UserAgentCredentials {
|
&UserAgentCredentials {
|
||||||
@@ -103,12 +103,13 @@ async fn verify_integrity(
|
|||||||
})?;
|
})?;
|
||||||
|
|
||||||
Ok(())
|
Ok(())
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
async fn create_nonce(
|
async fn create_nonce(
|
||||||
db: &DatabasePool,
|
db: &DatabasePool,
|
||||||
keyholder: &ActorRef<KeyHolder>,
|
keyholder: &ActorRef<KeyHolder>,
|
||||||
pubkey: &authn::PublicKey,
|
pubkey: &AuthPublicKey,
|
||||||
) -> Result<i32, Error> {
|
) -> Result<i32, Error> {
|
||||||
let mut db_conn = db.get().await.map_err(|e| {
|
let mut db_conn = db.get().await.map_err(|e| {
|
||||||
error!(error = ?e, "Database pool error");
|
error!(error = ?e, "Database pool error");
|
||||||
@@ -118,7 +119,8 @@ async fn create_nonce(
|
|||||||
.exclusive_transaction(|conn| {
|
.exclusive_transaction(|conn| {
|
||||||
Box::pin(async move {
|
Box::pin(async move {
|
||||||
let (id, new_nonce): (i32, i32) = update(useragent_client::table)
|
let (id, new_nonce): (i32, i32) = update(useragent_client::table)
|
||||||
.filter(useragent_client::public_key.eq(pubkey.to_bytes()))
|
.filter(useragent_client::public_key.eq(pubkey.to_stored_bytes()))
|
||||||
|
.filter(useragent_client::key_type.eq(pubkey.key_type()))
|
||||||
.set(useragent_client::nonce.eq(useragent_client::nonce + 1))
|
.set(useragent_client::nonce.eq(useragent_client::nonce + 1))
|
||||||
.returning((useragent_client::id, useragent_client::nonce))
|
.returning((useragent_client::id, useragent_client::nonce))
|
||||||
.get_result(conn)
|
.get_result(conn)
|
||||||
@@ -153,9 +155,10 @@ async fn create_nonce(
|
|||||||
async fn register_key(
|
async fn register_key(
|
||||||
db: &DatabasePool,
|
db: &DatabasePool,
|
||||||
keyholder: &ActorRef<KeyHolder>,
|
keyholder: &ActorRef<KeyHolder>,
|
||||||
pubkey: &authn::PublicKey,
|
pubkey: &AuthPublicKey,
|
||||||
) -> Result<(), Error> {
|
) -> Result<(), Error> {
|
||||||
let pubkey_bytes = pubkey.to_bytes();
|
let pubkey_bytes = pubkey.to_stored_bytes();
|
||||||
|
let key_type = pubkey.key_type();
|
||||||
let mut conn = db.get().await.map_err(|e| {
|
let mut conn = db.get().await.map_err(|e| {
|
||||||
error!(error = ?e, "Database pool error");
|
error!(error = ?e, "Database pool error");
|
||||||
Error::internal("Database unavailable")
|
Error::internal("Database unavailable")
|
||||||
@@ -169,6 +172,7 @@ async fn register_key(
|
|||||||
.values((
|
.values((
|
||||||
useragent_client::public_key.eq(pubkey_bytes),
|
useragent_client::public_key.eq(pubkey_bytes),
|
||||||
useragent_client::nonce.eq(NONCE_START),
|
useragent_client::nonce.eq(NONCE_START),
|
||||||
|
useragent_client::key_type.eq(key_type),
|
||||||
))
|
))
|
||||||
.returning(useragent_client::id)
|
.returning(useragent_client::id)
|
||||||
.get_result(conn)
|
.get_result(conn)
|
||||||
@@ -183,7 +187,7 @@ async fn register_key(
|
|||||||
nonce: NONCE_START,
|
nonce: NONCE_START,
|
||||||
};
|
};
|
||||||
|
|
||||||
integrity::sign_entity(conn, keyholder, &entity, id)
|
integrity::sign_entity(conn, &keyholder, &entity, id)
|
||||||
.await
|
.await
|
||||||
.map_err(|e| {
|
.map_err(|e| {
|
||||||
error!(error = ?e, "Failed to sign integrity tag for new user-agent key");
|
error!(error = ?e, "Failed to sign integrity tag for new user-agent key");
|
||||||
@@ -242,7 +246,7 @@ where
|
|||||||
async fn verify_bootstrap_token(
|
async fn verify_bootstrap_token(
|
||||||
&mut self,
|
&mut self,
|
||||||
BootstrapAuthRequest { pubkey, token }: BootstrapAuthRequest,
|
BootstrapAuthRequest { pubkey, token }: BootstrapAuthRequest,
|
||||||
) -> Result<authn::PublicKey, Self::Error> {
|
) -> Result<AuthPublicKey, Self::Error> {
|
||||||
let token_ok: bool = self
|
let token_ok: bool = self
|
||||||
.conn
|
.conn
|
||||||
.actors
|
.actors
|
||||||
@@ -290,13 +294,35 @@ where
|
|||||||
key,
|
key,
|
||||||
}: &ChallengeContext,
|
}: &ChallengeContext,
|
||||||
ChallengeSolution { solution }: ChallengeSolution,
|
ChallengeSolution { solution }: ChallengeSolution,
|
||||||
) -> Result<authn::PublicKey, Self::Error> {
|
) -> Result<AuthPublicKey, Self::Error> {
|
||||||
let signature = authn::Signature::try_from(solution.as_slice()).map_err(|_| {
|
let formatted = arbiter_proto::format_challenge(*challenge_nonce, &key.to_stored_bytes());
|
||||||
error!("Failed to decode signature in challenge solution");
|
|
||||||
Error::InvalidChallengeSolution
|
|
||||||
})?;
|
|
||||||
|
|
||||||
let valid = key.verify(*challenge_nonce, USERAGENT_CONTEXT, &signature);
|
let valid = match key {
|
||||||
|
AuthPublicKey::Ed25519(vk) => {
|
||||||
|
let sig = solution.as_slice().try_into().map_err(|_| {
|
||||||
|
error!(?solution, "Invalid Ed25519 signature length");
|
||||||
|
Error::InvalidChallengeSolution
|
||||||
|
})?;
|
||||||
|
vk.verify_strict(&formatted, &sig).is_ok()
|
||||||
|
}
|
||||||
|
AuthPublicKey::EcdsaSecp256k1(vk) => {
|
||||||
|
use k256::ecdsa::signature::Verifier as _;
|
||||||
|
let sig = k256::ecdsa::Signature::try_from(solution.as_slice()).map_err(|_| {
|
||||||
|
error!(?solution, "Invalid ECDSA signature bytes");
|
||||||
|
Error::InvalidChallengeSolution
|
||||||
|
})?;
|
||||||
|
vk.verify(&formatted, &sig).is_ok()
|
||||||
|
}
|
||||||
|
AuthPublicKey::Rsa(pk) => {
|
||||||
|
use rsa::signature::Verifier as _;
|
||||||
|
let verifying_key = rsa::pss::VerifyingKey::<sha2::Sha256>::new(pk.clone());
|
||||||
|
let sig = rsa::pss::Signature::try_from(solution.as_slice()).map_err(|_| {
|
||||||
|
error!(?solution, "Invalid RSA signature bytes");
|
||||||
|
Error::InvalidChallengeSolution
|
||||||
|
})?;
|
||||||
|
verifying_key.verify(&formatted, &sig).is_ok()
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
match valid {
|
match valid {
|
||||||
true => {
|
true => {
|
||||||
|
|||||||
@@ -1,25 +1,126 @@
|
|||||||
use crate::{
|
use crate::{
|
||||||
actors::{GlobalActors, client::ClientProfile},
|
actors::{GlobalActors, client::ClientProfile}, crypto::integrity::Integrable, db::{self, models::KeyType}
|
||||||
crypto::integrity::Integrable,
|
|
||||||
db,
|
|
||||||
};
|
};
|
||||||
use arbiter_crypto::authn;
|
|
||||||
|
|
||||||
#[derive(Debug, arbiter_macros::Hashable)]
|
fn serialize_ecdsa<S>(key: &k256::ecdsa::VerifyingKey, serializer: S) -> Result<S::Ok, S::Error>
|
||||||
|
where
|
||||||
|
S: serde::Serializer,
|
||||||
|
{
|
||||||
|
// Serialize as hex string for easier debugging (33 bytes compressed SEC1 format)
|
||||||
|
let key = key.to_encoded_point(true);
|
||||||
|
let bytes = key.as_bytes();
|
||||||
|
serializer.serialize_bytes(bytes)
|
||||||
|
}
|
||||||
|
|
||||||
|
fn deserialize_ecdsa<'de, D>(deserializer: D) -> Result<k256::ecdsa::VerifyingKey, D::Error>
|
||||||
|
where
|
||||||
|
D: serde::Deserializer<'de>,
|
||||||
|
{
|
||||||
|
struct EcdsaVisitor;
|
||||||
|
|
||||||
|
impl<'de> serde::de::Visitor<'de> for EcdsaVisitor {
|
||||||
|
type Value = k256::ecdsa::VerifyingKey;
|
||||||
|
|
||||||
|
fn expecting(&self, formatter: &mut std::fmt::Formatter) -> std::fmt::Result {
|
||||||
|
formatter.write_str("a compressed SEC1-encoded ECDSA public key")
|
||||||
|
}
|
||||||
|
|
||||||
|
fn visit_bytes<E>(self, v: &[u8]) -> Result<Self::Value, E>
|
||||||
|
where
|
||||||
|
E: serde::de::Error,
|
||||||
|
{
|
||||||
|
let point = k256::EncodedPoint::from_bytes(v)
|
||||||
|
.map_err(|_| E::custom("invalid compressed SEC1 format"))?;
|
||||||
|
k256::ecdsa::VerifyingKey::from_encoded_point(&point)
|
||||||
|
.map_err(|_| E::custom("invalid ECDSA public key"))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
deserializer.deserialize_bytes(EcdsaVisitor)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Abstraction over Ed25519 / ECDSA-secp256k1 / RSA public keys used during the auth handshake.
|
||||||
|
#[derive(Clone, Debug, Serialize)]
|
||||||
|
pub enum AuthPublicKey {
|
||||||
|
Ed25519(ed25519_dalek::VerifyingKey),
|
||||||
|
/// Compressed SEC1 public key; signature bytes are raw 64-byte (r||s).
|
||||||
|
#[serde(serialize_with = "serialize_ecdsa", deserialize_with = "deserialize_ecdsa")]
|
||||||
|
EcdsaSecp256k1(k256::ecdsa::VerifyingKey),
|
||||||
|
/// RSA-2048+ public key (Windows Hello / KeyCredentialManager); signature bytes are PSS+SHA-256.
|
||||||
|
Rsa(rsa::RsaPublicKey),
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Serialize)]
|
||||||
pub struct UserAgentCredentials {
|
pub struct UserAgentCredentials {
|
||||||
pub pubkey: authn::PublicKey,
|
pub pubkey: AuthPublicKey,
|
||||||
pub nonce: i32,
|
pub nonce: i32
|
||||||
}
|
}
|
||||||
|
|
||||||
impl Integrable for UserAgentCredentials {
|
impl Integrable for UserAgentCredentials {
|
||||||
const KIND: &'static str = "useragent_credentials";
|
const KIND: &'static str = "useragent_credentials";
|
||||||
}
|
}
|
||||||
|
|
||||||
|
impl AuthPublicKey {
|
||||||
|
/// Canonical bytes stored in DB and echoed back in the challenge.
|
||||||
|
/// Ed25519: raw 32 bytes. ECDSA: SEC1 compressed 33 bytes. RSA: DER-encoded SPKI.
|
||||||
|
pub fn to_stored_bytes(&self) -> Vec<u8> {
|
||||||
|
match self {
|
||||||
|
AuthPublicKey::Ed25519(k) => k.to_bytes().to_vec(),
|
||||||
|
// SEC1 compressed (33 bytes) is the natural compact format for secp256k1
|
||||||
|
AuthPublicKey::EcdsaSecp256k1(k) => k.to_encoded_point(true).as_bytes().to_vec(),
|
||||||
|
AuthPublicKey::Rsa(k) => {
|
||||||
|
use rsa::pkcs8::EncodePublicKey as _;
|
||||||
|
#[allow(clippy::expect_used)]
|
||||||
|
k.to_public_key_der()
|
||||||
|
.expect("rsa SPKI encoding is infallible")
|
||||||
|
.to_vec()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pub fn key_type(&self) -> KeyType {
|
||||||
|
match self {
|
||||||
|
AuthPublicKey::Ed25519(_) => KeyType::Ed25519,
|
||||||
|
AuthPublicKey::EcdsaSecp256k1(_) => KeyType::EcdsaSecp256k1,
|
||||||
|
AuthPublicKey::Rsa(_) => KeyType::Rsa,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
impl TryFrom<(KeyType, Vec<u8>)> for AuthPublicKey {
|
||||||
|
type Error = &'static str;
|
||||||
|
|
||||||
|
fn try_from(value: (KeyType, Vec<u8>)) -> Result<Self, Self::Error> {
|
||||||
|
let (key_type, bytes) = value;
|
||||||
|
match key_type {
|
||||||
|
KeyType::Ed25519 => {
|
||||||
|
let bytes: [u8; 32] = bytes.try_into().map_err(|_| "invalid Ed25519 key length")?;
|
||||||
|
let key = ed25519_dalek::VerifyingKey::from_bytes(&bytes)
|
||||||
|
.map_err(|_e| "invalid Ed25519 key")?;
|
||||||
|
Ok(AuthPublicKey::Ed25519(key))
|
||||||
|
}
|
||||||
|
KeyType::EcdsaSecp256k1 => {
|
||||||
|
let point =
|
||||||
|
k256::EncodedPoint::from_bytes(&bytes).map_err(|_e| "invalid ECDSA key")?;
|
||||||
|
let key = k256::ecdsa::VerifyingKey::from_encoded_point(&point)
|
||||||
|
.map_err(|_e| "invalid ECDSA key")?;
|
||||||
|
Ok(AuthPublicKey::EcdsaSecp256k1(key))
|
||||||
|
}
|
||||||
|
KeyType::Rsa => {
|
||||||
|
use rsa::pkcs8::DecodePublicKey as _;
|
||||||
|
let key = rsa::RsaPublicKey::from_public_key_der(&bytes)
|
||||||
|
.map_err(|_e| "invalid RSA key")?;
|
||||||
|
Ok(AuthPublicKey::Rsa(key))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// Messages, sent by user agent to connection client without having a request
|
// Messages, sent by user agent to connection client without having a request
|
||||||
#[derive(Debug)]
|
#[derive(Debug)]
|
||||||
pub enum OutOfBand {
|
pub enum OutOfBand {
|
||||||
ClientConnectionRequest { profile: ClientProfile },
|
ClientConnectionRequest { profile: ClientProfile },
|
||||||
ClientConnectionCancel { pubkey: authn::PublicKey },
|
ClientConnectionCancel { pubkey: ed25519_dalek::VerifyingKey },
|
||||||
}
|
}
|
||||||
|
|
||||||
pub struct UserAgentConnection {
|
pub struct UserAgentConnection {
|
||||||
@@ -37,4 +138,5 @@ pub mod auth;
|
|||||||
pub mod session;
|
pub mod session;
|
||||||
|
|
||||||
pub use auth::authenticate;
|
pub use auth::authenticate;
|
||||||
|
use serde::Serialize;
|
||||||
pub use session::UserAgentSession;
|
pub use session::UserAgentSession;
|
||||||
|
|||||||
@@ -1,9 +1,8 @@
|
|||||||
use arbiter_crypto::authn;
|
|
||||||
|
|
||||||
use std::{borrow::Cow, collections::HashMap};
|
use std::{borrow::Cow, collections::HashMap};
|
||||||
|
|
||||||
use arbiter_proto::transport::Sender;
|
use arbiter_proto::transport::Sender;
|
||||||
use async_trait::async_trait;
|
use async_trait::async_trait;
|
||||||
|
use ed25519_dalek::VerifyingKey;
|
||||||
use kameo::{Actor, actor::ActorRef, messages};
|
use kameo::{Actor, actor::ActorRef, messages};
|
||||||
use thiserror::Error;
|
use thiserror::Error;
|
||||||
use tracing::error;
|
use tracing::error;
|
||||||
@@ -13,6 +12,7 @@ use crate::actors::{
|
|||||||
flow_coordinator::{RegisterUserAgent, client_connect_approval::ClientApprovalController},
|
flow_coordinator::{RegisterUserAgent, client_connect_approval::ClientApprovalController},
|
||||||
user_agent::{OutOfBand, UserAgentConnection},
|
user_agent::{OutOfBand, UserAgentConnection},
|
||||||
};
|
};
|
||||||
|
|
||||||
mod state;
|
mod state;
|
||||||
use state::{DummyContext, UserAgentEvents, UserAgentStateMachine};
|
use state::{DummyContext, UserAgentEvents, UserAgentStateMachine};
|
||||||
|
|
||||||
@@ -47,7 +47,6 @@ impl Error {
|
|||||||
}
|
}
|
||||||
|
|
||||||
pub struct PendingClientApproval {
|
pub struct PendingClientApproval {
|
||||||
pubkey: authn::PublicKey,
|
|
||||||
controller: ActorRef<ClientApprovalController>,
|
controller: ActorRef<ClientApprovalController>,
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -56,7 +55,7 @@ pub struct UserAgentSession {
|
|||||||
state: UserAgentStateMachine<DummyContext>,
|
state: UserAgentStateMachine<DummyContext>,
|
||||||
sender: Box<dyn Sender<OutOfBand>>,
|
sender: Box<dyn Sender<OutOfBand>>,
|
||||||
|
|
||||||
pending_client_approvals: HashMap<Vec<u8>, PendingClientApproval>,
|
pending_client_approvals: HashMap<VerifyingKey, PendingClientApproval>,
|
||||||
}
|
}
|
||||||
|
|
||||||
pub mod connection;
|
pub mod connection;
|
||||||
@@ -119,13 +118,8 @@ impl UserAgentSession {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
self.pending_client_approvals.insert(
|
self.pending_client_approvals
|
||||||
client.pubkey.to_bytes(),
|
.insert(client.pubkey, PendingClientApproval { controller });
|
||||||
PendingClientApproval {
|
|
||||||
pubkey: client.pubkey,
|
|
||||||
controller,
|
|
||||||
},
|
|
||||||
);
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -164,18 +158,14 @@ impl Actor for UserAgentSession {
|
|||||||
let cancelled_pubkey = self
|
let cancelled_pubkey = self
|
||||||
.pending_client_approvals
|
.pending_client_approvals
|
||||||
.iter()
|
.iter()
|
||||||
.find_map(|(k, v)| (v.controller.id() == id).then_some(k.clone()));
|
.find_map(|(k, v)| (v.controller.id() == id).then_some(*k));
|
||||||
|
|
||||||
if let Some(pubkey_bytes) = cancelled_pubkey {
|
if let Some(pubkey) = cancelled_pubkey {
|
||||||
let Some(approval) = self.pending_client_approvals.remove(&pubkey_bytes) else {
|
self.pending_client_approvals.remove(&pubkey);
|
||||||
return Ok(std::ops::ControlFlow::Continue(()));
|
|
||||||
};
|
|
||||||
|
|
||||||
if let Err(e) = self
|
if let Err(e) = self
|
||||||
.sender
|
.sender
|
||||||
.send(OutOfBand::ClientConnectionCancel {
|
.send(OutOfBand::ClientConnectionCancel { pubkey })
|
||||||
pubkey: approval.pubkey,
|
|
||||||
})
|
|
||||||
.await
|
.await
|
||||||
{
|
{
|
||||||
error!(
|
error!(
|
||||||
|
|||||||
@@ -1,10 +1,6 @@
|
|||||||
use std::sync::Mutex;
|
use std::sync::Mutex;
|
||||||
|
|
||||||
use alloy::{consensus::TxEip1559, primitives::Address, signers::Signature};
|
use alloy::{consensus::TxEip1559, primitives::Address, signers::Signature};
|
||||||
use arbiter_crypto::{
|
|
||||||
authn,
|
|
||||||
safecell::{SafeCell, SafeCellHandle as _},
|
|
||||||
};
|
|
||||||
use chacha20poly1305::{AeadInPlace, XChaCha20Poly1305, XNonce, aead::KeyInit};
|
use chacha20poly1305::{AeadInPlace, XChaCha20Poly1305, XNonce, aead::KeyInit};
|
||||||
use diesel::{ExpressionMethods as _, QueryDsl as _, SelectableHelper};
|
use diesel::{ExpressionMethods as _, QueryDsl as _, SelectableHelper};
|
||||||
use diesel_async::{AsyncConnection, RunQueryDsl};
|
use diesel_async::{AsyncConnection, RunQueryDsl};
|
||||||
@@ -17,21 +13,25 @@ use x25519_dalek::{EphemeralSecret, PublicKey};
|
|||||||
use crate::actors::flow_coordinator::client_connect_approval::ClientApprovalAnswer;
|
use crate::actors::flow_coordinator::client_connect_approval::ClientApprovalAnswer;
|
||||||
use crate::actors::keyholder::KeyHolderState;
|
use crate::actors::keyholder::KeyHolderState;
|
||||||
use crate::actors::user_agent::session::Error;
|
use crate::actors::user_agent::session::Error;
|
||||||
use crate::actors::{
|
|
||||||
evm::{
|
|
||||||
ClientSignTransaction, Generate, ListWallets, SignTransactionError as EvmSignError,
|
|
||||||
UseragentCreateGrant, UseragentListGrants,
|
|
||||||
},
|
|
||||||
keyholder::{self, Bootstrap, TryUnseal},
|
|
||||||
user_agent::session::{
|
|
||||||
UserAgentSession,
|
|
||||||
state::{UnsealContext, UserAgentEvents, UserAgentStates},
|
|
||||||
},
|
|
||||||
};
|
|
||||||
use crate::db::models::{
|
use crate::db::models::{
|
||||||
EvmWalletAccess, NewEvmWalletAccess, ProgramClient, ProgramClientMetadata,
|
EvmWalletAccess, NewEvmWalletAccess, ProgramClient, ProgramClientMetadata,
|
||||||
};
|
};
|
||||||
use crate::evm::policies::{Grant, SpecificGrant};
|
use crate::evm::policies::{Grant, SpecificGrant};
|
||||||
|
use crate::safe_cell::SafeCell;
|
||||||
|
use crate::{
|
||||||
|
actors::{
|
||||||
|
evm::{
|
||||||
|
ClientSignTransaction, Generate, ListWallets, SignTransactionError as EvmSignError,
|
||||||
|
UseragentCreateGrant, UseragentDeleteGrant, UseragentListGrants,
|
||||||
|
},
|
||||||
|
keyholder::{self, Bootstrap, TryUnseal},
|
||||||
|
user_agent::session::{
|
||||||
|
UserAgentSession,
|
||||||
|
state::{UnsealContext, UserAgentEvents, UserAgentStates},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
safe_cell::SafeCellHandle as _,
|
||||||
|
};
|
||||||
|
|
||||||
impl UserAgentSession {
|
impl UserAgentSession {
|
||||||
fn take_unseal_secret(&mut self) -> Result<(EphemeralSecret, PublicKey), Error> {
|
fn take_unseal_secret(&mut self) -> Result<(EphemeralSecret, PublicKey), Error> {
|
||||||
@@ -361,21 +361,19 @@ impl UserAgentSession {
|
|||||||
&mut self,
|
&mut self,
|
||||||
grant_id: i32,
|
grant_id: i32,
|
||||||
) -> Result<(), GrantMutationError> {
|
) -> Result<(), GrantMutationError> {
|
||||||
// match self
|
match self
|
||||||
// .props
|
.props
|
||||||
// .actors
|
.actors
|
||||||
// .evm
|
.evm
|
||||||
// .ask(UseragentDeleteGrant { grant_id })
|
.ask(UseragentDeleteGrant { grant_id })
|
||||||
// .await
|
.await
|
||||||
// {
|
{
|
||||||
// Ok(()) => Ok(()),
|
Ok(()) => Ok(()),
|
||||||
// Err(err) => {
|
Err(err) => {
|
||||||
// error!(?err, "EVM grant delete failed");
|
error!(?err, "EVM grant delete failed");
|
||||||
// Err(GrantMutationError::Internal)
|
Err(GrantMutationError::Internal)
|
||||||
// }
|
}
|
||||||
// }
|
}
|
||||||
let _ = grant_id;
|
|
||||||
todo!()
|
|
||||||
}
|
}
|
||||||
|
|
||||||
#[message]
|
#[message]
|
||||||
@@ -475,10 +473,10 @@ impl UserAgentSession {
|
|||||||
pub(crate) async fn handle_new_client_approve(
|
pub(crate) async fn handle_new_client_approve(
|
||||||
&mut self,
|
&mut self,
|
||||||
approved: bool,
|
approved: bool,
|
||||||
pubkey: authn::PublicKey,
|
pubkey: ed25519_dalek::VerifyingKey,
|
||||||
ctx: &mut Context<Self, Result<(), Error>>,
|
ctx: &mut Context<Self, Result<(), Error>>,
|
||||||
) -> Result<(), Error> {
|
) -> Result<(), Error> {
|
||||||
let pending_approval = match self.pending_client_approvals.remove(&pubkey.to_bytes()) {
|
let pending_approval = match self.pending_client_approvals.remove(&pubkey) {
|
||||||
Some(approval) => approval,
|
Some(approval) => approval,
|
||||||
None => {
|
None => {
|
||||||
error!("Received client connection response for unknown client");
|
error!("Received client connection response for unknown client");
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
pub mod v1;
|
pub mod v1;
|
||||||
|
|
||||||
pub use v1::*;
|
pub use v1::*;
|
||||||
@@ -59,8 +59,10 @@ mod tests {
|
|||||||
use std::ops::Deref as _;
|
use std::ops::Deref as _;
|
||||||
|
|
||||||
use super::*;
|
use super::*;
|
||||||
use crate::crypto::derive_key;
|
use crate::{
|
||||||
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
crypto::derive_key,
|
||||||
|
safe_cell::{SafeCell, SafeCellHandle as _},
|
||||||
|
};
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
pub fn derive_seal_key_deterministic() {
|
pub fn derive_seal_key_deterministic() {
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
pub mod v1;
|
pub mod v1;
|
||||||
|
|
||||||
pub use v1::*;
|
pub use v1::*;
|
||||||
@@ -1,6 +1,7 @@
|
|||||||
use crate::actors::keyholder;
|
use crate::{actors::keyholder, crypto::KeyCell,safe_cell::SafeCellHandle as _};
|
||||||
use arbiter_crypto::hashing::Hashable;
|
use chacha20poly1305::Key;
|
||||||
use hmac::Hmac;
|
use hmac::{Hmac, Mac as _};
|
||||||
|
use serde::Serialize;
|
||||||
use sha2::Sha256;
|
use sha2::Sha256;
|
||||||
|
|
||||||
use diesel::{ExpressionMethods as _, QueryDsl, dsl::insert_into, sqlite::Sqlite};
|
use diesel::{ExpressionMethods as _, QueryDsl, dsl::insert_into, sqlite::Sqlite};
|
||||||
@@ -42,6 +43,9 @@ pub enum Error {
|
|||||||
|
|
||||||
#[error("Integrity MAC mismatch for entity {entity_kind}")]
|
#[error("Integrity MAC mismatch for entity {entity_kind}")]
|
||||||
MacMismatch { entity_kind: &'static str },
|
MacMismatch { entity_kind: &'static str },
|
||||||
|
|
||||||
|
#[error("Payload serialization error: {0}")]
|
||||||
|
PayloadSerialization(#[from] postcard::Error),
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||||
@@ -55,15 +59,13 @@ pub const INTEGRITY_SUBKEY_TAG: &[u8] = b"arbiter/db-integrity-key/v1";
|
|||||||
|
|
||||||
pub type HmacSha256 = Hmac<Sha256>;
|
pub type HmacSha256 = Hmac<Sha256>;
|
||||||
|
|
||||||
pub trait Integrable: Hashable {
|
pub trait Integrable: Serialize {
|
||||||
const KIND: &'static str;
|
const KIND: &'static str;
|
||||||
const VERSION: i32 = 1;
|
const VERSION: i32 = 1;
|
||||||
}
|
}
|
||||||
|
|
||||||
fn payload_hash(payload: &impl Hashable) -> [u8; 32] {
|
fn payload_hash(payload: &[u8]) -> [u8; 32] {
|
||||||
let mut hasher = Sha256::new();
|
Sha256::digest(payload).into()
|
||||||
payload.hash(&mut hasher);
|
|
||||||
hasher.finalize().into()
|
|
||||||
}
|
}
|
||||||
|
|
||||||
fn push_len_prefixed(out: &mut Vec<u8>, bytes: &[u8]) {
|
fn push_len_prefixed(out: &mut Vec<u8>, bytes: &[u8]) {
|
||||||
@@ -107,7 +109,8 @@ pub async fn sign_entity<E: Integrable>(
|
|||||||
entity: &E,
|
entity: &E,
|
||||||
entity_id: impl IntoId,
|
entity_id: impl IntoId,
|
||||||
) -> Result<(), Error> {
|
) -> Result<(), Error> {
|
||||||
let payload_hash = payload_hash(&entity);
|
let payload = postcard::to_stdvec(entity)?;
|
||||||
|
let payload_hash = payload_hash(&payload);
|
||||||
|
|
||||||
let entity_id = entity_id.into_id();
|
let entity_id = entity_id.into_id();
|
||||||
|
|
||||||
@@ -124,8 +127,8 @@ pub async fn sign_entity<E: Integrable>(
|
|||||||
insert_into(integrity_envelope::table)
|
insert_into(integrity_envelope::table)
|
||||||
.values(NewIntegrityEnvelope {
|
.values(NewIntegrityEnvelope {
|
||||||
entity_kind: E::KIND.to_owned(),
|
entity_kind: E::KIND.to_owned(),
|
||||||
entity_id,
|
entity_id: entity_id,
|
||||||
payload_version: E::VERSION,
|
payload_version: E::VERSION ,
|
||||||
key_version,
|
key_version,
|
||||||
mac: mac.to_vec(),
|
mac: mac.to_vec(),
|
||||||
})
|
})
|
||||||
@@ -159,9 +162,7 @@ pub async fn verify_entity<E: Integrable>(
|
|||||||
.first(conn)
|
.first(conn)
|
||||||
.await
|
.await
|
||||||
.map_err(|err| match err {
|
.map_err(|err| match err {
|
||||||
diesel::result::Error::NotFound => Error::MissingEnvelope {
|
diesel::result::Error::NotFound => Error::MissingEnvelope { entity_kind: E::KIND },
|
||||||
entity_kind: E::KIND,
|
|
||||||
},
|
|
||||||
other => Error::Database(db::DatabaseError::from(other)),
|
other => Error::Database(db::DatabaseError::from(other)),
|
||||||
})?;
|
})?;
|
||||||
|
|
||||||
@@ -173,8 +174,14 @@ pub async fn verify_entity<E: Integrable>(
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
let payload_hash = payload_hash(&entity);
|
let payload = postcard::to_stdvec(entity)?;
|
||||||
let mac_input = build_mac_input(E::KIND, &entity_id, envelope.payload_version, &payload_hash);
|
let payload_hash = payload_hash(&payload);
|
||||||
|
let mac_input = build_mac_input(
|
||||||
|
E::KIND,
|
||||||
|
&entity_id,
|
||||||
|
envelope.payload_version,
|
||||||
|
&payload_hash,
|
||||||
|
);
|
||||||
|
|
||||||
let result = keyholder
|
let result = keyholder
|
||||||
.ask(VerifyIntegrity {
|
.ask(VerifyIntegrity {
|
||||||
@@ -182,16 +189,13 @@ pub async fn verify_entity<E: Integrable>(
|
|||||||
expected_mac: envelope.mac,
|
expected_mac: envelope.mac,
|
||||||
key_version: envelope.key_version,
|
key_version: envelope.key_version,
|
||||||
})
|
})
|
||||||
.await;
|
.await
|
||||||
|
;
|
||||||
|
|
||||||
match result {
|
match result {
|
||||||
Ok(true) => Ok(AttestationStatus::Attested),
|
Ok(true) => Ok(AttestationStatus::Attested),
|
||||||
Ok(false) => Err(Error::MacMismatch {
|
Ok(false) => Err(Error::MacMismatch { entity_kind: E::KIND }),
|
||||||
entity_kind: E::KIND,
|
Err(SendError::HandlerError(keyholder::Error::NotBootstrapped)) => Ok(AttestationStatus::Unavailable),
|
||||||
}),
|
|
||||||
Err(SendError::HandlerError(keyholder::Error::NotBootstrapped)) => {
|
|
||||||
Ok(AttestationStatus::Unavailable)
|
|
||||||
}
|
|
||||||
Err(_) => Err(Error::KeyholderSend),
|
Err(_) => Err(Error::KeyholderSend),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -205,15 +209,17 @@ mod tests {
|
|||||||
use crate::{
|
use crate::{
|
||||||
actors::keyholder::{Bootstrap, KeyHolder},
|
actors::keyholder::{Bootstrap, KeyHolder},
|
||||||
db::{self, schema},
|
db::{self, schema},
|
||||||
|
safe_cell::{SafeCell, SafeCellHandle as _},
|
||||||
};
|
};
|
||||||
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
|
||||||
|
|
||||||
use super::{Error, Integrable, sign_entity, verify_entity};
|
use super::{Error, Integrable, sign_entity, verify_entity};
|
||||||
#[derive(Clone, arbiter_macros::Hashable)]
|
|
||||||
|
#[derive(Clone, serde::Serialize)]
|
||||||
struct DummyEntity {
|
struct DummyEntity {
|
||||||
payload_version: i32,
|
payload_version: i32,
|
||||||
payload: Vec<u8>,
|
payload: Vec<u8>,
|
||||||
}
|
}
|
||||||
|
|
||||||
impl Integrable for DummyEntity {
|
impl Integrable for DummyEntity {
|
||||||
const KIND: &'static str = "dummy_entity";
|
const KIND: &'static str = "dummy_entity";
|
||||||
}
|
}
|
||||||
@@ -242,9 +248,7 @@ mod tests {
|
|||||||
payload: b"payload-v1".to_vec(),
|
payload: b"payload-v1".to_vec(),
|
||||||
};
|
};
|
||||||
|
|
||||||
sign_entity(&mut conn, &keyholder, &entity, ENTITY_ID)
|
sign_entity(&mut conn, &keyholder, &entity, ENTITY_ID).await.unwrap();
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
|
|
||||||
let count: i64 = schema::integrity_envelope::table
|
let count: i64 = schema::integrity_envelope::table
|
||||||
.filter(schema::integrity_envelope::entity_kind.eq("dummy_entity"))
|
.filter(schema::integrity_envelope::entity_kind.eq("dummy_entity"))
|
||||||
@@ -255,9 +259,7 @@ mod tests {
|
|||||||
.unwrap();
|
.unwrap();
|
||||||
|
|
||||||
assert_eq!(count, 1, "envelope row must be created exactly once");
|
assert_eq!(count, 1, "envelope row must be created exactly once");
|
||||||
verify_entity(&mut conn, &keyholder, &entity, ENTITY_ID)
|
verify_entity(&mut conn, &keyholder, &entity, ENTITY_ID).await.unwrap();
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
}
|
}
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
@@ -273,9 +275,7 @@ mod tests {
|
|||||||
payload: b"payload-v1".to_vec(),
|
payload: b"payload-v1".to_vec(),
|
||||||
};
|
};
|
||||||
|
|
||||||
sign_entity(&mut conn, &keyholder, &entity, ENTITY_ID)
|
sign_entity(&mut conn, &keyholder, &entity, ENTITY_ID).await.unwrap();
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
|
|
||||||
diesel::update(schema::integrity_envelope::table)
|
diesel::update(schema::integrity_envelope::table)
|
||||||
.filter(schema::integrity_envelope::entity_kind.eq("dummy_entity"))
|
.filter(schema::integrity_envelope::entity_kind.eq("dummy_entity"))
|
||||||
@@ -304,9 +304,7 @@ mod tests {
|
|||||||
payload: b"payload-v1".to_vec(),
|
payload: b"payload-v1".to_vec(),
|
||||||
};
|
};
|
||||||
|
|
||||||
sign_entity(&mut conn, &keyholder, &entity, ENTITY_ID)
|
sign_entity(&mut conn, &keyholder, &entity, ENTITY_ID).await.unwrap();
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
|
|
||||||
let tampered = DummyEntity {
|
let tampered = DummyEntity {
|
||||||
payload: b"payload-v1-but-tampered".to_vec(),
|
payload: b"payload-v1-but-tampered".to_vec(),
|
||||||
|
|||||||
@@ -10,7 +10,7 @@ use rand::{
|
|||||||
rngs::{StdRng, SysRng},
|
rngs::{StdRng, SysRng},
|
||||||
};
|
};
|
||||||
|
|
||||||
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
use crate::safe_cell::{SafeCell, SafeCellHandle as _};
|
||||||
|
|
||||||
pub mod encryption;
|
pub mod encryption;
|
||||||
pub mod integrity;
|
pub mod integrity;
|
||||||
@@ -102,21 +102,11 @@ impl KeyCell {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// User password might be of different length, have not enough entropy, etc...
|
||||||
/// Derive a fixed-length key from the password using Argon2id, which is designed for password hashing and key derivation.
|
/// Derive a fixed-length key from the password using Argon2id, which is designed for password hashing and key derivation.
|
||||||
pub fn derive_key(mut password: SafeCell<Vec<u8>>, salt: &Salt) -> KeyCell {
|
pub fn derive_key(mut password: SafeCell<Vec<u8>>, salt: &Salt) -> KeyCell {
|
||||||
let params = {
|
|
||||||
#[cfg(debug_assertions)]
|
|
||||||
{
|
|
||||||
argon2::Params::new(8, 1, 1, None).unwrap()
|
|
||||||
}
|
|
||||||
|
|
||||||
#[cfg(not(debug_assertions))]
|
|
||||||
{
|
|
||||||
argon2::Params::new(262_144, 3, 4, None).unwrap()
|
|
||||||
}
|
|
||||||
};
|
|
||||||
|
|
||||||
#[allow(clippy::unwrap_used)]
|
#[allow(clippy::unwrap_used)]
|
||||||
|
let params = argon2::Params::new(262_144, 3, 4, None).unwrap();
|
||||||
let hasher = Argon2::new(Algorithm::Argon2id, argon2::Version::V0x13, params);
|
let hasher = Argon2::new(Algorithm::Argon2id, argon2::Version::V0x13, params);
|
||||||
let mut key = SafeCell::new(Key::default());
|
let mut key = SafeCell::new(Key::default());
|
||||||
password.read_inline(|password_source| {
|
password.read_inline(|password_source| {
|
||||||
@@ -141,7 +131,7 @@ mod tests {
|
|||||||
derive_key,
|
derive_key,
|
||||||
encryption::v1::{Nonce, generate_salt},
|
encryption::v1::{Nonce, generate_salt},
|
||||||
};
|
};
|
||||||
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
use crate::safe_cell::{SafeCell, SafeCellHandle as _};
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
pub fn encrypt_decrypt() {
|
pub fn encrypt_decrypt() {
|
||||||
|
|||||||
@@ -133,7 +133,6 @@ pub async fn create_pool(url: Option<&str>) -> Result<DatabasePool, DatabaseSetu
|
|||||||
Ok(pool)
|
Ok(pool)
|
||||||
}
|
}
|
||||||
|
|
||||||
#[mutants::skip]
|
|
||||||
pub async fn create_test_pool() -> DatabasePool {
|
pub async fn create_test_pool() -> DatabasePool {
|
||||||
use rand::distr::{Alphanumeric, SampleString as _};
|
use rand::distr::{Alphanumeric, SampleString as _};
|
||||||
|
|
||||||
|
|||||||
@@ -72,6 +72,40 @@ pub mod types {
|
|||||||
Ok(SqliteTimestamp(datetime))
|
Ok(SqliteTimestamp(datetime))
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Key algorithm stored in the `useragent_client.key_type` column.
|
||||||
|
/// Values must stay stable — they are persisted in the database.
|
||||||
|
#[derive(Debug, Clone, Copy, PartialEq, Eq, FromSqlRow, AsExpression, strum::FromRepr)]
|
||||||
|
#[diesel(sql_type = Integer)]
|
||||||
|
#[repr(i32)]
|
||||||
|
pub enum KeyType {
|
||||||
|
Ed25519 = 1,
|
||||||
|
EcdsaSecp256k1 = 2,
|
||||||
|
Rsa = 3,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl ToSql<Integer, Sqlite> for KeyType {
|
||||||
|
fn to_sql<'b>(
|
||||||
|
&'b self,
|
||||||
|
out: &mut diesel::serialize::Output<'b, '_, Sqlite>,
|
||||||
|
) -> diesel::serialize::Result {
|
||||||
|
out.set_value(*self as i32);
|
||||||
|
Ok(IsNull::No)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
impl FromSql<Integer, Sqlite> for KeyType {
|
||||||
|
fn from_sql(
|
||||||
|
mut bytes: <Sqlite as diesel::backend::Backend>::RawValue<'_>,
|
||||||
|
) -> diesel::deserialize::Result<Self> {
|
||||||
|
let Some(SqliteType::Long) = bytes.value_type() else {
|
||||||
|
return Err("Expected Integer for KeyType".into());
|
||||||
|
};
|
||||||
|
let discriminant = bytes.read_long();
|
||||||
|
KeyType::from_repr(discriminant as i32)
|
||||||
|
.ok_or_else(|| format!("Unknown KeyType discriminant: {discriminant}").into())
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
pub use types::*;
|
pub use types::*;
|
||||||
|
|
||||||
@@ -210,6 +244,7 @@ pub struct UseragentClient {
|
|||||||
pub public_key: Vec<u8>,
|
pub public_key: Vec<u8>,
|
||||||
pub created_at: SqliteTimestamp,
|
pub created_at: SqliteTimestamp,
|
||||||
pub updated_at: SqliteTimestamp,
|
pub updated_at: SqliteTimestamp,
|
||||||
|
pub key_type: KeyType,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Models, Queryable, Debug, Insertable, Selectable)]
|
#[derive(Models, Queryable, Debug, Insertable, Selectable)]
|
||||||
|
|||||||
@@ -21,8 +21,8 @@ use crate::{
|
|||||||
schema::{self, evm_transaction_log},
|
schema::{self, evm_transaction_log},
|
||||||
},
|
},
|
||||||
evm::policies::{
|
evm::policies::{
|
||||||
CombinedSettings, DatabaseID, EvalContext, EvalViolation, Grant, Policy,
|
DatabaseID, EvalContext, EvalViolation, Grant, Policy, CombinedSettings, SharedGrantSettings,
|
||||||
SharedGrantSettings, SpecificGrant, SpecificMeaning, ether_transfer::EtherTransfer,
|
SpecificGrant, SpecificMeaning, ether_transfer::EtherTransfer,
|
||||||
token_transfers::TokenTransfer,
|
token_transfers::TokenTransfer,
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
@@ -90,14 +90,6 @@ async fn check_shared_constraints(
|
|||||||
let mut violations = Vec::new();
|
let mut violations = Vec::new();
|
||||||
let now = Utc::now();
|
let now = Utc::now();
|
||||||
|
|
||||||
if shared.chain != context.chain {
|
|
||||||
violations.push(EvalViolation::MismatchingChainId {
|
|
||||||
expected: shared.chain,
|
|
||||||
actual: context.chain,
|
|
||||||
});
|
|
||||||
return Ok(violations);
|
|
||||||
}
|
|
||||||
|
|
||||||
// Validity window
|
// Validity window
|
||||||
if shared.valid_from.is_some_and(|t| now < t) || shared.valid_until.is_some_and(|t| now > t) {
|
if shared.valid_from.is_some_and(|t| now < t) || shared.valid_until.is_some_and(|t| now > t) {
|
||||||
violations.push(EvalViolation::InvalidTime);
|
violations.push(EvalViolation::InvalidTime);
|
||||||
@@ -258,9 +250,14 @@ impl Engine {
|
|||||||
|
|
||||||
P::create_grant(&basic_grant, &full_grant.specific, conn).await?;
|
P::create_grant(&basic_grant, &full_grant.specific, conn).await?;
|
||||||
|
|
||||||
integrity::sign_entity(conn, &keyholder, &full_grant, basic_grant.id)
|
integrity::sign_entity(
|
||||||
.await
|
conn,
|
||||||
.map_err(|_| diesel::result::Error::RollbackTransaction)?;
|
&keyholder,
|
||||||
|
&full_grant,
|
||||||
|
basic_grant.id,
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.map_err(|_| diesel::result::Error::RollbackTransaction)?;
|
||||||
|
|
||||||
QueryResult::Ok(basic_grant.id)
|
QueryResult::Ok(basic_grant.id)
|
||||||
})
|
})
|
||||||
@@ -345,276 +342,3 @@ impl Engine {
|
|||||||
Err(VetError::UnsupportedTransactionType)
|
Err(VetError::UnsupportedTransactionType)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#[cfg(test)]
|
|
||||||
mod tests {
|
|
||||||
use alloy::primitives::{Address, Bytes, U256, address};
|
|
||||||
use chrono::{Duration, Utc};
|
|
||||||
use diesel::{SelectableHelper, insert_into};
|
|
||||||
use diesel_async::RunQueryDsl;
|
|
||||||
use rstest::rstest;
|
|
||||||
|
|
||||||
use crate::db::{
|
|
||||||
self, DatabaseConnection,
|
|
||||||
models::{
|
|
||||||
EvmBasicGrant, EvmWalletAccess, NewEvmBasicGrant, NewEvmTransactionLog, SqliteTimestamp,
|
|
||||||
},
|
|
||||||
schema::{evm_basic_grant, evm_transaction_log},
|
|
||||||
};
|
|
||||||
use crate::evm::policies::{
|
|
||||||
EvalContext, EvalViolation, SharedGrantSettings, TransactionRateLimit,
|
|
||||||
};
|
|
||||||
|
|
||||||
use super::check_shared_constraints;
|
|
||||||
|
|
||||||
const WALLET_ACCESS_ID: i32 = 1;
|
|
||||||
const CHAIN_ID: u64 = 1;
|
|
||||||
const RECIPIENT: Address = address!("1111111111111111111111111111111111111111");
|
|
||||||
|
|
||||||
fn context() -> EvalContext {
|
|
||||||
EvalContext {
|
|
||||||
target: EvmWalletAccess {
|
|
||||||
id: WALLET_ACCESS_ID,
|
|
||||||
wallet_id: 10,
|
|
||||||
client_id: 20,
|
|
||||||
created_at: SqliteTimestamp(Utc::now()),
|
|
||||||
},
|
|
||||||
chain: CHAIN_ID,
|
|
||||||
to: RECIPIENT,
|
|
||||||
value: U256::ZERO,
|
|
||||||
calldata: Bytes::new(),
|
|
||||||
max_fee_per_gas: 100,
|
|
||||||
max_priority_fee_per_gas: 10,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
fn shared_settings() -> SharedGrantSettings {
|
|
||||||
SharedGrantSettings {
|
|
||||||
wallet_access_id: WALLET_ACCESS_ID,
|
|
||||||
chain: CHAIN_ID,
|
|
||||||
valid_from: None,
|
|
||||||
valid_until: None,
|
|
||||||
revoked_at: None,
|
|
||||||
max_gas_fee_per_gas: None,
|
|
||||||
max_priority_fee_per_gas: None,
|
|
||||||
rate_limit: None,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
async fn insert_basic_grant(
|
|
||||||
conn: &mut DatabaseConnection,
|
|
||||||
shared: &SharedGrantSettings,
|
|
||||||
) -> EvmBasicGrant {
|
|
||||||
insert_into(evm_basic_grant::table)
|
|
||||||
.values(NewEvmBasicGrant {
|
|
||||||
wallet_access_id: shared.wallet_access_id,
|
|
||||||
chain_id: shared.chain as i32,
|
|
||||||
valid_from: shared.valid_from.map(SqliteTimestamp),
|
|
||||||
valid_until: shared.valid_until.map(SqliteTimestamp),
|
|
||||||
max_gas_fee_per_gas: shared
|
|
||||||
.max_gas_fee_per_gas
|
|
||||||
.map(|fee| super::utils::u256_to_bytes(fee).to_vec()),
|
|
||||||
max_priority_fee_per_gas: shared
|
|
||||||
.max_priority_fee_per_gas
|
|
||||||
.map(|fee| super::utils::u256_to_bytes(fee).to_vec()),
|
|
||||||
rate_limit_count: shared.rate_limit.as_ref().map(|limit| limit.count as i32),
|
|
||||||
rate_limit_window_secs: shared
|
|
||||||
.rate_limit
|
|
||||||
.as_ref()
|
|
||||||
.map(|limit| limit.window.num_seconds() as i32),
|
|
||||||
revoked_at: None,
|
|
||||||
})
|
|
||||||
.returning(EvmBasicGrant::as_select())
|
|
||||||
.get_result(conn)
|
|
||||||
.await
|
|
||||||
.unwrap()
|
|
||||||
}
|
|
||||||
|
|
||||||
#[rstest]
|
|
||||||
#[case::matching_chain(CHAIN_ID, false)]
|
|
||||||
#[case::mismatching_chain(CHAIN_ID + 1, true)]
|
|
||||||
#[tokio::test]
|
|
||||||
async fn check_shared_constraints_enforces_chain_id(
|
|
||||||
#[case] context_chain: u64,
|
|
||||||
#[case] expect_mismatch: bool,
|
|
||||||
) {
|
|
||||||
let db = db::create_test_pool().await;
|
|
||||||
let mut conn = db.get().await.unwrap();
|
|
||||||
|
|
||||||
let context = EvalContext {
|
|
||||||
chain: context_chain,
|
|
||||||
..context()
|
|
||||||
};
|
|
||||||
|
|
||||||
let violations = check_shared_constraints(&context, &shared_settings(), 999, &mut *conn)
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
|
|
||||||
assert_eq!(
|
|
||||||
violations
|
|
||||||
.iter()
|
|
||||||
.any(|violation| matches!(violation, EvalViolation::MismatchingChainId { .. })),
|
|
||||||
expect_mismatch
|
|
||||||
);
|
|
||||||
|
|
||||||
if expect_mismatch {
|
|
||||||
assert_eq!(violations.len(), 1);
|
|
||||||
} else {
|
|
||||||
assert!(violations.is_empty());
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[rstest]
|
|
||||||
#[case::valid_from_in_bounds(Some(Utc::now() - Duration::hours(1)), None, false)]
|
|
||||||
#[case::valid_from_out_of_bounds(Some(Utc::now() + Duration::hours(1)), None, true)]
|
|
||||||
#[case::valid_until_in_bounds(None, Some(Utc::now() + Duration::hours(1)), false)]
|
|
||||||
#[case::valid_until_out_of_bounds(None, Some(Utc::now() - Duration::hours(1)), true)]
|
|
||||||
#[tokio::test]
|
|
||||||
async fn check_shared_constraints_enforces_validity_window(
|
|
||||||
#[case] valid_from: Option<chrono::DateTime<Utc>>,
|
|
||||||
#[case] valid_until: Option<chrono::DateTime<Utc>>,
|
|
||||||
#[case] expect_invalid_time: bool,
|
|
||||||
) {
|
|
||||||
let db = db::create_test_pool().await;
|
|
||||||
let mut conn = db.get().await.unwrap();
|
|
||||||
|
|
||||||
let shared = SharedGrantSettings {
|
|
||||||
valid_from,
|
|
||||||
valid_until,
|
|
||||||
..shared_settings()
|
|
||||||
};
|
|
||||||
|
|
||||||
let violations = check_shared_constraints(&context(), &shared, 999, &mut *conn)
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
|
|
||||||
assert_eq!(
|
|
||||||
violations
|
|
||||||
.iter()
|
|
||||||
.any(|violation| matches!(violation, EvalViolation::InvalidTime)),
|
|
||||||
expect_invalid_time
|
|
||||||
);
|
|
||||||
|
|
||||||
if expect_invalid_time {
|
|
||||||
assert_eq!(violations.len(), 1);
|
|
||||||
} else {
|
|
||||||
assert!(violations.is_empty());
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[rstest]
|
|
||||||
#[case::max_fee_within_limit(Some(U256::from(100u64)), None, 100, 10, false)]
|
|
||||||
#[case::max_fee_exceeded(Some(U256::from(99u64)), None, 100, 10, true)]
|
|
||||||
#[case::priority_fee_within_limit(None, Some(U256::from(10u64)), 100, 10, false)]
|
|
||||||
#[case::priority_fee_exceeded(None, Some(U256::from(9u64)), 100, 10, true)]
|
|
||||||
#[tokio::test]
|
|
||||||
async fn check_shared_constraints_enforces_gas_fee_caps(
|
|
||||||
#[case] max_gas_fee_per_gas: Option<U256>,
|
|
||||||
#[case] max_priority_fee_per_gas: Option<U256>,
|
|
||||||
#[case] actual_max_fee_per_gas: u128,
|
|
||||||
#[case] actual_max_priority_fee_per_gas: u128,
|
|
||||||
#[case] expect_gas_limit_violation: bool,
|
|
||||||
) {
|
|
||||||
let db = db::create_test_pool().await;
|
|
||||||
let mut conn = db.get().await.unwrap();
|
|
||||||
|
|
||||||
let context = EvalContext {
|
|
||||||
max_fee_per_gas: actual_max_fee_per_gas,
|
|
||||||
max_priority_fee_per_gas: actual_max_priority_fee_per_gas,
|
|
||||||
..context()
|
|
||||||
};
|
|
||||||
|
|
||||||
let shared = SharedGrantSettings {
|
|
||||||
max_gas_fee_per_gas,
|
|
||||||
max_priority_fee_per_gas,
|
|
||||||
..shared_settings()
|
|
||||||
};
|
|
||||||
let violations = check_shared_constraints(&context, &shared, 999, &mut *conn)
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
|
|
||||||
assert_eq!(
|
|
||||||
violations
|
|
||||||
.iter()
|
|
||||||
.any(|violation| matches!(violation, EvalViolation::GasLimitExceeded { .. })),
|
|
||||||
expect_gas_limit_violation
|
|
||||||
);
|
|
||||||
|
|
||||||
if expect_gas_limit_violation {
|
|
||||||
assert_eq!(violations.len(), 1);
|
|
||||||
} else {
|
|
||||||
assert!(violations.is_empty());
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[rstest]
|
|
||||||
#[case::under_rate_limit(2, false)]
|
|
||||||
#[case::at_rate_limit(1, true)]
|
|
||||||
#[tokio::test]
|
|
||||||
async fn check_shared_constraints_enforces_rate_limit(
|
|
||||||
#[case] rate_limit_count: u32,
|
|
||||||
#[case] expect_rate_limit_violation: bool,
|
|
||||||
) {
|
|
||||||
let db = db::create_test_pool().await;
|
|
||||||
let mut conn = db.get().await.unwrap();
|
|
||||||
|
|
||||||
let shared = SharedGrantSettings {
|
|
||||||
rate_limit: Some(TransactionRateLimit {
|
|
||||||
count: rate_limit_count,
|
|
||||||
window: Duration::hours(1),
|
|
||||||
}),
|
|
||||||
..shared_settings()
|
|
||||||
};
|
|
||||||
|
|
||||||
let basic_grant = insert_basic_grant(&mut conn, &shared).await;
|
|
||||||
|
|
||||||
insert_into(evm_transaction_log::table)
|
|
||||||
.values(NewEvmTransactionLog {
|
|
||||||
grant_id: basic_grant.id,
|
|
||||||
wallet_access_id: WALLET_ACCESS_ID,
|
|
||||||
chain_id: CHAIN_ID as i32,
|
|
||||||
eth_value: super::utils::u256_to_bytes(U256::ZERO).to_vec(),
|
|
||||||
signed_at: SqliteTimestamp(Utc::now()),
|
|
||||||
})
|
|
||||||
.execute(&mut *conn)
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
|
|
||||||
let violations = check_shared_constraints(&context(), &shared, basic_grant.id, &mut *conn)
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
|
|
||||||
assert_eq!(
|
|
||||||
violations
|
|
||||||
.iter()
|
|
||||||
.any(|violation| matches!(violation, EvalViolation::RateLimitExceeded)),
|
|
||||||
expect_rate_limit_violation
|
|
||||||
);
|
|
||||||
|
|
||||||
if expect_rate_limit_violation {
|
|
||||||
assert_eq!(violations.len(), 1);
|
|
||||||
} else {
|
|
||||||
assert!(violations.is_empty());
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[test]
|
|
||||||
fn shared_settings_hash_changes_when_revoked_at_changes() {
|
|
||||||
use arbiter_crypto::hashing::Hashable;
|
|
||||||
use sha2::Digest;
|
|
||||||
|
|
||||||
let active = shared_settings();
|
|
||||||
let revoked = SharedGrantSettings {
|
|
||||||
revoked_at: Some(Utc::now()),
|
|
||||||
..shared_settings()
|
|
||||||
};
|
|
||||||
|
|
||||||
let mut active_hash = sha2::Sha256::new();
|
|
||||||
active.hash(&mut active_hash);
|
|
||||||
|
|
||||||
let mut revoked_hash = sha2::Sha256::new();
|
|
||||||
revoked.hash(&mut revoked_hash);
|
|
||||||
|
|
||||||
assert_ne!(active_hash.finalize(), revoked_hash.finalize());
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -7,12 +7,11 @@ use diesel::{
|
|||||||
};
|
};
|
||||||
use diesel_async::{AsyncConnection, RunQueryDsl};
|
use diesel_async::{AsyncConnection, RunQueryDsl};
|
||||||
|
|
||||||
|
use serde::Serialize;
|
||||||
use thiserror::Error;
|
use thiserror::Error;
|
||||||
|
|
||||||
use crate::{
|
use crate::{
|
||||||
crypto::integrity::v1::Integrable,
|
crypto::integrity::v1::Integrable, db::models::{self, EvmBasicGrant, EvmWalletAccess}, evm::utils
|
||||||
db::models::{self, EvmBasicGrant, EvmWalletAccess},
|
|
||||||
evm::utils,
|
|
||||||
};
|
};
|
||||||
|
|
||||||
pub mod ether_transfer;
|
pub mod ether_transfer;
|
||||||
@@ -56,14 +55,11 @@ pub enum EvalViolation {
|
|||||||
|
|
||||||
#[error("Transaction type is not allowed by this grant")]
|
#[error("Transaction type is not allowed by this grant")]
|
||||||
InvalidTransactionType,
|
InvalidTransactionType,
|
||||||
|
|
||||||
#[error("Mismatching chain ID")]
|
|
||||||
MismatchingChainId { expected: ChainId, actual: ChainId },
|
|
||||||
}
|
}
|
||||||
|
|
||||||
pub type DatabaseID = i32;
|
pub type DatabaseID = i32;
|
||||||
|
|
||||||
#[derive(Debug)]
|
#[derive(Debug, Serialize)]
|
||||||
pub struct Grant<PolicySettings> {
|
pub struct Grant<PolicySettings> {
|
||||||
pub id: DatabaseID,
|
pub id: DatabaseID,
|
||||||
pub common_settings_id: DatabaseID, // ID of the basic grant for shared-logic checks like rate limits and validity periods
|
pub common_settings_id: DatabaseID, // ID of the basic grant for shared-logic checks like rate limits and validity periods
|
||||||
@@ -127,26 +123,25 @@ pub enum SpecificMeaning {
|
|||||||
TokenTransfer(token_transfers::Meaning),
|
TokenTransfer(token_transfers::Meaning),
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Clone, Debug, PartialEq, Eq, Hash, PartialOrd, Ord, arbiter_macros::Hashable)]
|
#[derive(Clone, Debug, PartialEq, Eq, Hash, Serialize)]
|
||||||
pub struct TransactionRateLimit {
|
pub struct TransactionRateLimit {
|
||||||
pub count: u32,
|
pub count: u32,
|
||||||
pub window: Duration,
|
pub window: Duration,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Clone, Debug, PartialEq, Eq, Hash, PartialOrd, Ord, arbiter_macros::Hashable)]
|
#[derive(Clone, Debug, PartialEq, Eq, Hash, Serialize)]
|
||||||
pub struct VolumeRateLimit {
|
pub struct VolumeRateLimit {
|
||||||
pub max_volume: U256,
|
pub max_volume: U256,
|
||||||
pub window: Duration,
|
pub window: Duration,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Clone, Debug, PartialEq, Eq, Hash, arbiter_macros::Hashable)]
|
#[derive(Clone, Debug, PartialEq, Eq, Hash, Serialize)]
|
||||||
pub struct SharedGrantSettings {
|
pub struct SharedGrantSettings {
|
||||||
pub wallet_access_id: i32,
|
pub wallet_access_id: i32,
|
||||||
pub chain: ChainId,
|
pub chain: ChainId,
|
||||||
|
|
||||||
pub valid_from: Option<DateTime<Utc>>,
|
pub valid_from: Option<DateTime<Utc>>,
|
||||||
pub valid_until: Option<DateTime<Utc>>,
|
pub valid_until: Option<DateTime<Utc>>,
|
||||||
pub revoked_at: Option<DateTime<Utc>>,
|
|
||||||
|
|
||||||
pub max_gas_fee_per_gas: Option<U256>,
|
pub max_gas_fee_per_gas: Option<U256>,
|
||||||
pub max_priority_fee_per_gas: Option<U256>,
|
pub max_priority_fee_per_gas: Option<U256>,
|
||||||
@@ -161,7 +156,6 @@ impl SharedGrantSettings {
|
|||||||
chain: model.chain_id as u64, // safe because chain_id is stored as i32 but is guaranteed to be a valid ChainId by the API when creating grants
|
chain: model.chain_id as u64, // safe because chain_id is stored as i32 but is guaranteed to be a valid ChainId by the API when creating grants
|
||||||
valid_from: model.valid_from.map(Into::into),
|
valid_from: model.valid_from.map(Into::into),
|
||||||
valid_until: model.valid_until.map(Into::into),
|
valid_until: model.valid_until.map(Into::into),
|
||||||
revoked_at: model.revoked_at.map(Into::into),
|
|
||||||
max_gas_fee_per_gas: model
|
max_gas_fee_per_gas: model
|
||||||
.max_gas_fee_per_gas
|
.max_gas_fee_per_gas
|
||||||
.map(|b| utils::try_bytes_to_u256(&b))
|
.map(|b| utils::try_bytes_to_u256(&b))
|
||||||
@@ -202,7 +196,7 @@ pub enum SpecificGrant {
|
|||||||
TokenTransfer(token_transfers::Settings),
|
TokenTransfer(token_transfers::Settings),
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Debug, arbiter_macros::Hashable)]
|
#[derive(Debug, Serialize)]
|
||||||
pub struct CombinedSettings<PolicyGrant> {
|
pub struct CombinedSettings<PolicyGrant> {
|
||||||
pub shared: SharedGrantSettings,
|
pub shared: SharedGrantSettings,
|
||||||
pub specific: PolicyGrant,
|
pub specific: PolicyGrant,
|
||||||
@@ -221,3 +215,4 @@ impl<P: Integrable> Integrable for CombinedSettings<P> {
|
|||||||
const KIND: &'static str = P::KIND;
|
const KIND: &'static str = P::KIND;
|
||||||
const VERSION: i32 = P::VERSION;
|
const VERSION: i32 = P::VERSION;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -52,7 +52,7 @@ impl From<Meaning> for SpecificMeaning {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// A grant for ether transfers, which can be scoped to specific target addresses and volume limits
|
// A grant for ether transfers, which can be scoped to specific target addresses and volume limits
|
||||||
#[derive(Debug, Clone, arbiter_macros::Hashable)]
|
#[derive(Debug, Clone, serde::Serialize)]
|
||||||
pub struct Settings {
|
pub struct Settings {
|
||||||
pub target: Vec<Address>,
|
pub target: Vec<Address>,
|
||||||
pub limit: VolumeRateLimit,
|
pub limit: VolumeRateLimit,
|
||||||
|
|||||||
@@ -78,13 +78,14 @@ fn shared() -> SharedGrantSettings {
|
|||||||
chain: CHAIN_ID,
|
chain: CHAIN_ID,
|
||||||
valid_from: None,
|
valid_from: None,
|
||||||
valid_until: None,
|
valid_until: None,
|
||||||
revoked_at: None,
|
|
||||||
max_gas_fee_per_gas: None,
|
max_gas_fee_per_gas: None,
|
||||||
max_priority_fee_per_gas: None,
|
max_priority_fee_per_gas: None,
|
||||||
rate_limit: None,
|
rate_limit: None,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ── analyze ─────────────────────────────────────────────────────────────
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn analyze_matches_empty_calldata() {
|
fn analyze_matches_empty_calldata() {
|
||||||
let m = EtherTransfer::analyze(&ctx(ALLOWED, U256::from(1_000u64))).unwrap();
|
let m = EtherTransfer::analyze(&ctx(ALLOWED, U256::from(1_000u64))).unwrap();
|
||||||
@@ -101,6 +102,8 @@ fn analyze_rejects_nonempty_calldata() {
|
|||||||
assert!(EtherTransfer::analyze(&context).is_none());
|
assert!(EtherTransfer::analyze(&context).is_none());
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ── evaluate ────────────────────────────────────────────────────────────
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
async fn evaluate_passes_for_allowed_target() {
|
async fn evaluate_passes_for_allowed_target() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
@@ -273,6 +276,8 @@ async fn evaluate_passes_at_exactly_volume_limit() {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ── try_find_grant ───────────────────────────────────────────────────────
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
async fn try_find_grant_roundtrip() {
|
async fn try_find_grant_roundtrip() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
@@ -331,36 +336,7 @@ async fn try_find_grant_wrong_target_returns_none() {
|
|||||||
assert!(found.is_none());
|
assert!(found.is_none());
|
||||||
}
|
}
|
||||||
|
|
||||||
proptest::proptest! {
|
// ── find_all_grants ──────────────────────────────────────────────────────
|
||||||
#[test]
|
|
||||||
fn target_order_does_not_affect_hash(
|
|
||||||
raw_addrs in proptest::collection::vec(proptest::prelude::any::<[u8; 20]>(), 0..8),
|
|
||||||
seed in proptest::prelude::any::<u64>(),
|
|
||||||
max_volume in proptest::prelude::any::<u64>(),
|
|
||||||
window_secs in 1i64..=86400,
|
|
||||||
) {
|
|
||||||
use rand::{SeedableRng, seq::SliceRandom};
|
|
||||||
use sha2::Digest;
|
|
||||||
use arbiter_crypto::hashing::Hashable;
|
|
||||||
|
|
||||||
let addrs: Vec<Address> = raw_addrs.iter().map(|b| Address::from(*b)).collect();
|
|
||||||
let mut shuffled = addrs.clone();
|
|
||||||
shuffled.shuffle(&mut rand::rngs::StdRng::seed_from_u64(seed));
|
|
||||||
|
|
||||||
let limit = VolumeRateLimit {
|
|
||||||
max_volume: U256::from(max_volume),
|
|
||||||
window: Duration::seconds(window_secs),
|
|
||||||
};
|
|
||||||
|
|
||||||
let mut h1 = sha2::Sha256::new();
|
|
||||||
Settings { target: addrs, limit: limit.clone() }.hash(&mut h1);
|
|
||||||
|
|
||||||
let mut h2 = sha2::Sha256::new();
|
|
||||||
Settings { target: shuffled, limit }.hash(&mut h2);
|
|
||||||
|
|
||||||
proptest::prop_assert_eq!(h1.finalize(), h2.finalize());
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
async fn find_all_grants_empty_db() {
|
async fn find_all_grants_empty_db() {
|
||||||
|
|||||||
@@ -1,5 +1,17 @@
|
|||||||
use std::collections::HashMap;
|
use std::collections::HashMap;
|
||||||
|
|
||||||
|
use alloy::{
|
||||||
|
primitives::{Address, U256},
|
||||||
|
sol_types::SolCall,
|
||||||
|
};
|
||||||
|
use arbiter_tokens_registry::evm::nonfungible::{self, TokenInfo};
|
||||||
|
use chrono::{DateTime, Duration, Utc};
|
||||||
|
use diesel::dsl::{auto_type, insert_into};
|
||||||
|
use diesel::sqlite::Sqlite;
|
||||||
|
use diesel::{ExpressionMethods, prelude::*};
|
||||||
|
use diesel_async::{AsyncConnection, RunQueryDsl};
|
||||||
|
use serde::Serialize;
|
||||||
|
|
||||||
use crate::db::schema::{
|
use crate::db::schema::{
|
||||||
evm_basic_grant, evm_token_transfer_grant, evm_token_transfer_log,
|
evm_basic_grant, evm_token_transfer_grant, evm_token_transfer_log,
|
||||||
evm_token_transfer_volume_limit,
|
evm_token_transfer_volume_limit,
|
||||||
@@ -20,16 +32,6 @@ use crate::{
|
|||||||
},
|
},
|
||||||
evm::policies::CombinedSettings,
|
evm::policies::CombinedSettings,
|
||||||
};
|
};
|
||||||
use alloy::{
|
|
||||||
primitives::{Address, U256},
|
|
||||||
sol_types::SolCall,
|
|
||||||
};
|
|
||||||
use arbiter_tokens_registry::evm::nonfungible::{self, TokenInfo};
|
|
||||||
use chrono::{DateTime, Duration, Utc};
|
|
||||||
use diesel::dsl::{auto_type, insert_into};
|
|
||||||
use diesel::sqlite::Sqlite;
|
|
||||||
use diesel::{ExpressionMethods, prelude::*};
|
|
||||||
use diesel_async::{AsyncConnection, RunQueryDsl};
|
|
||||||
|
|
||||||
use super::{DatabaseID, EvalContext, EvalViolation};
|
use super::{DatabaseID, EvalContext, EvalViolation};
|
||||||
|
|
||||||
@@ -62,7 +64,7 @@ impl From<Meaning> for SpecificMeaning {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// A grant for token transfers, which can be scoped to specific target addresses and volume limits
|
// A grant for token transfers, which can be scoped to specific target addresses and volume limits
|
||||||
#[derive(Debug, Clone, arbiter_macros::Hashable)]
|
#[derive(Debug, Clone, Serialize)]
|
||||||
pub struct Settings {
|
pub struct Settings {
|
||||||
pub token_contract: Address,
|
pub token_contract: Address,
|
||||||
pub target: Option<Address>,
|
pub target: Option<Address>,
|
||||||
@@ -71,7 +73,6 @@ pub struct Settings {
|
|||||||
impl Integrable for Settings {
|
impl Integrable for Settings {
|
||||||
const KIND: &'static str = "TokenTransfer";
|
const KIND: &'static str = "TokenTransfer";
|
||||||
}
|
}
|
||||||
|
|
||||||
impl From<Settings> for SpecificGrant {
|
impl From<Settings> for SpecificGrant {
|
||||||
fn from(val: Settings) -> SpecificGrant {
|
fn from(val: Settings) -> SpecificGrant {
|
||||||
SpecificGrant::TokenTransfer(val)
|
SpecificGrant::TokenTransfer(val)
|
||||||
|
|||||||
@@ -95,13 +95,14 @@ fn shared() -> SharedGrantSettings {
|
|||||||
chain: CHAIN_ID,
|
chain: CHAIN_ID,
|
||||||
valid_from: None,
|
valid_from: None,
|
||||||
valid_until: None,
|
valid_until: None,
|
||||||
revoked_at: None,
|
|
||||||
max_gas_fee_per_gas: None,
|
max_gas_fee_per_gas: None,
|
||||||
max_priority_fee_per_gas: None,
|
max_priority_fee_per_gas: None,
|
||||||
rate_limit: None,
|
rate_limit: None,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ── analyze ─────────────────────────────────────────────────────────────
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn analyze_known_token_valid_calldata() {
|
fn analyze_known_token_valid_calldata() {
|
||||||
let calldata = transfer_calldata(RECIPIENT, U256::from(100u64));
|
let calldata = transfer_calldata(RECIPIENT, U256::from(100u64));
|
||||||
@@ -127,6 +128,8 @@ fn analyze_empty_calldata_returns_none() {
|
|||||||
assert!(TokenTransfer::analyze(&ctx(DAI, Bytes::new())).is_none());
|
assert!(TokenTransfer::analyze(&ctx(DAI, Bytes::new())).is_none());
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ── evaluate ────────────────────────────────────────────────────────────
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
async fn evaluate_rejects_nonzero_eth_value() {
|
async fn evaluate_rejects_nonzero_eth_value() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
@@ -409,39 +412,7 @@ async fn try_find_grant_unknown_token_returns_none() {
|
|||||||
assert!(found.is_none());
|
assert!(found.is_none());
|
||||||
}
|
}
|
||||||
|
|
||||||
proptest::proptest! {
|
// ── find_all_grants ──────────────────────────────────────────────────────
|
||||||
#[test]
|
|
||||||
fn volume_limits_order_does_not_affect_hash(
|
|
||||||
raw_limits in proptest::collection::vec(
|
|
||||||
(proptest::prelude::any::<u64>(), 1i64..=86400),
|
|
||||||
0..8,
|
|
||||||
),
|
|
||||||
seed in proptest::prelude::any::<u64>(),
|
|
||||||
) {
|
|
||||||
use rand::{SeedableRng, seq::SliceRandom};
|
|
||||||
use sha2::Digest;
|
|
||||||
use arbiter_crypto::hashing::Hashable;
|
|
||||||
|
|
||||||
let limits: Vec<VolumeRateLimit> = raw_limits
|
|
||||||
.iter()
|
|
||||||
.map(|(max_vol, window_secs)| VolumeRateLimit {
|
|
||||||
max_volume: U256::from(*max_vol),
|
|
||||||
window: Duration::seconds(*window_secs),
|
|
||||||
})
|
|
||||||
.collect();
|
|
||||||
|
|
||||||
let mut shuffled = limits.clone();
|
|
||||||
shuffled.shuffle(&mut rand::rngs::StdRng::seed_from_u64(seed));
|
|
||||||
|
|
||||||
let mut h1 = sha2::Sha256::new();
|
|
||||||
Settings { token_contract: DAI, target: None, volume_limits: limits }.hash(&mut h1);
|
|
||||||
|
|
||||||
let mut h2 = sha2::Sha256::new();
|
|
||||||
Settings { token_contract: DAI, target: None, volume_limits: shuffled }.hash(&mut h2);
|
|
||||||
|
|
||||||
proptest::prop_assert_eq!(h1.finalize(), h2.finalize());
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
async fn find_all_grants_empty_db() {
|
async fn find_all_grants_empty_db() {
|
||||||
|
|||||||
@@ -1,12 +1,12 @@
|
|||||||
use std::sync::Mutex;
|
use std::sync::Mutex;
|
||||||
|
|
||||||
|
use crate::safe_cell::{SafeCell, SafeCellHandle as _};
|
||||||
use alloy::{
|
use alloy::{
|
||||||
consensus::SignableTransaction,
|
consensus::SignableTransaction,
|
||||||
network::{TxSigner, TxSignerSync},
|
network::{TxSigner, TxSignerSync},
|
||||||
primitives::{Address, B256, ChainId, Signature},
|
primitives::{Address, B256, ChainId, Signature},
|
||||||
signers::{Error, Result, Signer, SignerSync, utils::secret_key_to_address},
|
signers::{Error, Result, Signer, SignerSync, utils::secret_key_to_address},
|
||||||
};
|
};
|
||||||
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
|
||||||
use async_trait::async_trait;
|
use async_trait::async_trait;
|
||||||
use k256::ecdsa::{self, RecoveryId, SigningKey, signature::hazmat::PrehashSigner};
|
use k256::ecdsa::{self, RecoveryId, SigningKey, signature::hazmat::PrehashSigner};
|
||||||
|
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
use arbiter_crypto::authn;
|
|
||||||
use arbiter_proto::{
|
use arbiter_proto::{
|
||||||
ClientMetadata,
|
ClientMetadata,
|
||||||
proto::{
|
proto::{
|
||||||
@@ -46,7 +45,7 @@ impl<'a> AuthTransportAdapter<'a> {
|
|||||||
match response {
|
match response {
|
||||||
auth::Outbound::AuthChallenge { pubkey, nonce } => {
|
auth::Outbound::AuthChallenge { pubkey, nonce } => {
|
||||||
AuthResponsePayload::Challenge(ProtoAuthChallenge {
|
AuthResponsePayload::Challenge(ProtoAuthChallenge {
|
||||||
pubkey: pubkey.to_bytes(),
|
pubkey: pubkey.to_bytes().to_vec(),
|
||||||
nonce,
|
nonce,
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
@@ -69,7 +68,6 @@ impl<'a> AuthTransportAdapter<'a> {
|
|||||||
auth::Error::ApproveError(auth::ApproveError::Internal)
|
auth::Error::ApproveError(auth::ApproveError::Internal)
|
||||||
| auth::Error::DatabasePoolUnavailable
|
| auth::Error::DatabasePoolUnavailable
|
||||||
| auth::Error::DatabaseOperationFailed
|
| auth::Error::DatabaseOperationFailed
|
||||||
| auth::Error::IntegrityCheckFailed
|
|
||||||
| auth::Error::Transport => ProtoAuthResult::Internal,
|
| auth::Error::Transport => ProtoAuthResult::Internal,
|
||||||
}
|
}
|
||||||
.into(),
|
.into(),
|
||||||
@@ -161,7 +159,11 @@ impl Receiver<auth::Inbound> for AuthTransportAdapter<'_> {
|
|||||||
.await;
|
.await;
|
||||||
return None;
|
return None;
|
||||||
};
|
};
|
||||||
let Ok(pubkey) = authn::PublicKey::try_from(pubkey.as_slice()) else {
|
let Ok(pubkey) = <[u8; 32]>::try_from(pubkey) else {
|
||||||
|
let _ = self.send_auth_result(ProtoAuthResult::InvalidKey).await;
|
||||||
|
return None;
|
||||||
|
};
|
||||||
|
let Ok(pubkey) = ed25519_dalek::VerifyingKey::from_bytes(&pubkey) else {
|
||||||
let _ = self.send_auth_result(ProtoAuthResult::InvalidKey).await;
|
let _ = self.send_auth_result(ProtoAuthResult::InvalidKey).await;
|
||||||
return None;
|
return None;
|
||||||
};
|
};
|
||||||
@@ -171,7 +173,7 @@ impl Receiver<auth::Inbound> for AuthTransportAdapter<'_> {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
AuthRequestPayload::ChallengeSolution(ProtoAuthChallengeSolution { signature }) => {
|
AuthRequestPayload::ChallengeSolution(ProtoAuthChallengeSolution { signature }) => {
|
||||||
let Ok(signature) = authn::Signature::try_from(signature.as_slice()) else {
|
let Ok(signature) = ed25519_dalek::Signature::try_from(signature.as_slice()) else {
|
||||||
let _ = self
|
let _ = self
|
||||||
.send_auth_result(ProtoAuthResult::InvalidSignature)
|
.send_auth_result(ProtoAuthResult::InvalidSignature)
|
||||||
.await;
|
.await;
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ use arbiter_proto::proto::{
|
|||||||
EvalViolation as ProtoEvalViolation, GasLimitExceededViolation, NoMatchingGrantError,
|
EvalViolation as ProtoEvalViolation, GasLimitExceededViolation, NoMatchingGrantError,
|
||||||
PolicyViolationsError, SpecificMeaning as ProtoSpecificMeaning,
|
PolicyViolationsError, SpecificMeaning as ProtoSpecificMeaning,
|
||||||
TokenInfo as ProtoTokenInfo, TransactionEvalError as ProtoTransactionEvalError,
|
TokenInfo as ProtoTokenInfo, TransactionEvalError as ProtoTransactionEvalError,
|
||||||
eval_violation as proto_eval_violation, eval_violation::Kind as ProtoEvalViolationKind,
|
eval_violation::Kind as ProtoEvalViolationKind,
|
||||||
specific_meaning::Meaning as ProtoSpecificMeaningKind,
|
specific_meaning::Meaning as ProtoSpecificMeaningKind,
|
||||||
transaction_eval_error::Kind as ProtoTransactionEvalErrorKind,
|
transaction_eval_error::Kind as ProtoTransactionEvalErrorKind,
|
||||||
},
|
},
|
||||||
@@ -79,12 +79,6 @@ impl Convert for EvalViolation {
|
|||||||
EvalViolation::InvalidTransactionType => {
|
EvalViolation::InvalidTransactionType => {
|
||||||
ProtoEvalViolationKind::InvalidTransactionType(())
|
ProtoEvalViolationKind::InvalidTransactionType(())
|
||||||
}
|
}
|
||||||
EvalViolation::MismatchingChainId { expected, actual } => {
|
|
||||||
ProtoEvalViolationKind::ChainIdMismatch(proto_eval_violation::ChainIdMismatch {
|
|
||||||
expected,
|
|
||||||
actual,
|
|
||||||
})
|
|
||||||
}
|
|
||||||
};
|
};
|
||||||
|
|
||||||
ProtoEvalViolation { kind: Some(kind) }
|
ProtoEvalViolation { kind: Some(kind) }
|
||||||
@@ -114,7 +108,7 @@ impl Convert for VetError {
|
|||||||
violations: violations.into_iter().map(Convert::convert).collect(),
|
violations: violations.into_iter().map(Convert::convert).collect(),
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
PolicyError::Database(_) | PolicyError::Integrity(_) => {
|
PolicyError::Database(_)| PolicyError::Integrity(_) => {
|
||||||
return EvmSignTransactionResult::Error(ProtoEvmError::Internal.into());
|
return EvmSignTransactionResult::Error(ProtoEvmError::Internal.into());
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
use arbiter_crypto::authn;
|
|
||||||
use arbiter_proto::{
|
use arbiter_proto::{
|
||||||
proto::user_agent::{
|
proto::user_agent::{
|
||||||
UserAgentRequest, UserAgentResponse,
|
UserAgentRequest, UserAgentResponse,
|
||||||
@@ -6,7 +5,8 @@ use arbiter_proto::{
|
|||||||
self as proto_auth, AuthChallenge as ProtoAuthChallenge,
|
self as proto_auth, AuthChallenge as ProtoAuthChallenge,
|
||||||
AuthChallengeRequest as ProtoAuthChallengeRequest,
|
AuthChallengeRequest as ProtoAuthChallengeRequest,
|
||||||
AuthChallengeSolution as ProtoAuthChallengeSolution, AuthResult as ProtoAuthResult,
|
AuthChallengeSolution as ProtoAuthChallengeSolution, AuthResult as ProtoAuthResult,
|
||||||
request::Payload as AuthRequestPayload, response::Payload as AuthResponsePayload,
|
KeyType as ProtoKeyType, request::Payload as AuthRequestPayload,
|
||||||
|
response::Payload as AuthResponsePayload,
|
||||||
},
|
},
|
||||||
user_agent_request::Payload as UserAgentRequestPayload,
|
user_agent_request::Payload as UserAgentRequestPayload,
|
||||||
user_agent_response::Payload as UserAgentResponsePayload,
|
user_agent_response::Payload as UserAgentResponsePayload,
|
||||||
@@ -18,7 +18,8 @@ use tonic::Status;
|
|||||||
use tracing::warn;
|
use tracing::warn;
|
||||||
|
|
||||||
use crate::{
|
use crate::{
|
||||||
actors::user_agent::{UserAgentConnection, auth},
|
actors::user_agent::{AuthPublicKey, UserAgentConnection, auth},
|
||||||
|
db::models::KeyType,
|
||||||
grpc::request_tracker::RequestTracker,
|
grpc::request_tracker::RequestTracker,
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -140,9 +141,28 @@ impl Receiver<auth::Inbound> for AuthTransportAdapter<'_> {
|
|||||||
AuthRequestPayload::ChallengeRequest(ProtoAuthChallengeRequest {
|
AuthRequestPayload::ChallengeRequest(ProtoAuthChallengeRequest {
|
||||||
pubkey,
|
pubkey,
|
||||||
bootstrap_token,
|
bootstrap_token,
|
||||||
key_type: _,
|
key_type,
|
||||||
}) => {
|
}) => {
|
||||||
let Ok(pubkey) = authn::PublicKey::try_from(pubkey.as_slice()) else {
|
let Ok(key_type) = ProtoKeyType::try_from(key_type) else {
|
||||||
|
warn!(
|
||||||
|
event = "received request with invalid key type",
|
||||||
|
"grpc.useragent.auth_adapter"
|
||||||
|
);
|
||||||
|
return None;
|
||||||
|
};
|
||||||
|
let key_type = match key_type {
|
||||||
|
ProtoKeyType::Ed25519 => KeyType::Ed25519,
|
||||||
|
ProtoKeyType::EcdsaSecp256k1 => KeyType::EcdsaSecp256k1,
|
||||||
|
ProtoKeyType::Rsa => KeyType::Rsa,
|
||||||
|
ProtoKeyType::Unspecified => {
|
||||||
|
warn!(
|
||||||
|
event = "received request with unspecified key type",
|
||||||
|
"grpc.useragent.auth_adapter"
|
||||||
|
);
|
||||||
|
return None;
|
||||||
|
}
|
||||||
|
};
|
||||||
|
let Ok(pubkey) = AuthPublicKey::try_from((key_type, pubkey)) else {
|
||||||
warn!(
|
warn!(
|
||||||
event = "received request with invalid public key",
|
event = "received request with invalid public key",
|
||||||
"grpc.useragent.auth_adapter"
|
"grpc.useragent.auth_adapter"
|
||||||
@@ -168,7 +188,7 @@ pub async fn start(
|
|||||||
conn: &mut UserAgentConnection,
|
conn: &mut UserAgentConnection,
|
||||||
bi: &mut GrpcBi<UserAgentRequest, UserAgentResponse>,
|
bi: &mut GrpcBi<UserAgentRequest, UserAgentResponse>,
|
||||||
request_tracker: &mut RequestTracker,
|
request_tracker: &mut RequestTracker,
|
||||||
) -> Result<authn::PublicKey, auth::Error> {
|
) -> Result<AuthPublicKey, auth::Error> {
|
||||||
let transport = AuthTransportAdapter::new(bi, request_tracker);
|
let transport = AuthTransportAdapter::new(bi, request_tracker);
|
||||||
auth::authenticate(conn, transport).await
|
auth::authenticate(conn, transport).await
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -87,7 +87,6 @@ impl TryConvert for ProtoSharedSettings {
|
|||||||
.valid_until
|
.valid_until
|
||||||
.map(ProtoTimestamp::try_convert)
|
.map(ProtoTimestamp::try_convert)
|
||||||
.transpose()?,
|
.transpose()?,
|
||||||
revoked_at: None,
|
|
||||||
max_gas_fee_per_gas: self
|
max_gas_fee_per_gas: self
|
||||||
.max_gas_fee_per_gas
|
.max_gas_fee_per_gas
|
||||||
.as_deref()
|
.as_deref()
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
use arbiter_crypto::authn;
|
|
||||||
use arbiter_proto::proto::{
|
use arbiter_proto::proto::{
|
||||||
shared::ClientInfo as ProtoClientMetadata,
|
shared::ClientInfo as ProtoClientMetadata,
|
||||||
user_agent::{
|
user_agent::{
|
||||||
@@ -42,7 +41,7 @@ pub(super) fn out_of_band_payload(oob: OutOfBand) -> UserAgentResponsePayload {
|
|||||||
match oob {
|
match oob {
|
||||||
OutOfBand::ClientConnectionRequest { profile } => wrap_sdk_client_response(
|
OutOfBand::ClientConnectionRequest { profile } => wrap_sdk_client_response(
|
||||||
SdkClientResponsePayload::ConnectionRequest(ProtoSdkClientConnectionRequest {
|
SdkClientResponsePayload::ConnectionRequest(ProtoSdkClientConnectionRequest {
|
||||||
pubkey: profile.pubkey.to_bytes(),
|
pubkey: profile.pubkey.to_bytes().to_vec(),
|
||||||
info: Some(ProtoClientMetadata {
|
info: Some(ProtoClientMetadata {
|
||||||
name: profile.metadata.name,
|
name: profile.metadata.name,
|
||||||
description: profile.metadata.description,
|
description: profile.metadata.description,
|
||||||
@@ -52,7 +51,7 @@ pub(super) fn out_of_band_payload(oob: OutOfBand) -> UserAgentResponsePayload {
|
|||||||
),
|
),
|
||||||
OutOfBand::ClientConnectionCancel { pubkey } => wrap_sdk_client_response(
|
OutOfBand::ClientConnectionCancel { pubkey } => wrap_sdk_client_response(
|
||||||
SdkClientResponsePayload::ConnectionCancel(ProtoSdkClientConnectionCancel {
|
SdkClientResponsePayload::ConnectionCancel(ProtoSdkClientConnectionCancel {
|
||||||
pubkey: pubkey.to_bytes(),
|
pubkey: pubkey.to_bytes().to_vec(),
|
||||||
}),
|
}),
|
||||||
),
|
),
|
||||||
}
|
}
|
||||||
@@ -90,8 +89,10 @@ async fn handle_connection_response(
|
|||||||
actor: &ActorRef<UserAgentSession>,
|
actor: &ActorRef<UserAgentSession>,
|
||||||
resp: ProtoSdkClientConnectionResponse,
|
resp: ProtoSdkClientConnectionResponse,
|
||||||
) -> Result<Option<UserAgentResponsePayload>, Status> {
|
) -> Result<Option<UserAgentResponsePayload>, Status> {
|
||||||
let pubkey = authn::PublicKey::try_from(resp.pubkey.as_slice())
|
let pubkey_bytes = <[u8; 32]>::try_from(resp.pubkey)
|
||||||
.map_err(|_| Status::invalid_argument("Invalid ML-DSA public key"))?;
|
.map_err(|_| Status::invalid_argument("Invalid Ed25519 public key length"))?;
|
||||||
|
let pubkey = ed25519_dalek::VerifyingKey::from_bytes(&pubkey_bytes)
|
||||||
|
.map_err(|_| Status::invalid_argument("Invalid Ed25519 public key"))?;
|
||||||
|
|
||||||
actor
|
actor
|
||||||
.ask(HandleNewClientApprove {
|
.ask(HandleNewClientApprove {
|
||||||
@@ -116,7 +117,7 @@ async fn handle_list(
|
|||||||
.into_iter()
|
.into_iter()
|
||||||
.map(|(client, metadata)| ProtoSdkClientEntry {
|
.map(|(client, metadata)| ProtoSdkClientEntry {
|
||||||
id: client.id,
|
id: client.id,
|
||||||
pubkey: client.public_key.to_vec(),
|
pubkey: client.public_key,
|
||||||
info: Some(ProtoClientMetadata {
|
info: Some(ProtoClientMetadata {
|
||||||
name: metadata.name,
|
name: metadata.name,
|
||||||
description: metadata.description,
|
description: metadata.description,
|
||||||
|
|||||||
@@ -7,6 +7,7 @@ pub mod crypto;
|
|||||||
pub mod db;
|
pub mod db;
|
||||||
pub mod evm;
|
pub mod evm;
|
||||||
pub mod grpc;
|
pub mod grpc;
|
||||||
|
pub mod safe_cell;
|
||||||
pub mod utils;
|
pub mod utils;
|
||||||
|
|
||||||
pub struct Server {
|
pub struct Server {
|
||||||
|
|||||||
@@ -10,7 +10,6 @@ use tracing::info;
|
|||||||
const PORT: u16 = 50051;
|
const PORT: u16 = 50051;
|
||||||
|
|
||||||
#[tokio::main]
|
#[tokio::main]
|
||||||
#[mutants::skip]
|
|
||||||
async fn main() -> anyhow::Result<()> {
|
async fn main() -> anyhow::Result<()> {
|
||||||
aws_lc_rs::default_provider().install_default().unwrap();
|
aws_lc_rs::default_provider().install_default().unwrap();
|
||||||
|
|
||||||
|
|||||||
@@ -105,11 +105,6 @@ impl<T> SafeCellHandle<T> for MemSafeCell<T> {
|
|||||||
|
|
||||||
fn abort_memory_breach(action: &str, err: &memsafe::error::MemoryError) -> ! {
|
fn abort_memory_breach(action: &str, err: &memsafe::error::MemoryError) -> ! {
|
||||||
eprintln!("fatal {action}: {err}");
|
eprintln!("fatal {action}: {err}");
|
||||||
// SAFETY: Intentionally cause a segmentation fault to prevent further execution in a compromised state.
|
|
||||||
unsafe {
|
|
||||||
let unsafe_pointer = std::ptr::null_mut::<u8>();
|
|
||||||
std::ptr::write_volatile(unsafe_pointer, 0);
|
|
||||||
}
|
|
||||||
std::process::abort();
|
std::process::abort();
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1,21 +1,13 @@
|
|||||||
use arbiter_crypto::{
|
|
||||||
authn::{self, CLIENT_CONTEXT, format_challenge},
|
|
||||||
safecell::{SafeCell, SafeCellHandle as _},
|
|
||||||
};
|
|
||||||
use arbiter_proto::ClientMetadata;
|
use arbiter_proto::ClientMetadata;
|
||||||
use arbiter_proto::transport::{Receiver, Sender};
|
use arbiter_proto::transport::{Receiver, Sender};
|
||||||
|
use arbiter_server::actors::GlobalActors;
|
||||||
use arbiter_server::{
|
use arbiter_server::{
|
||||||
actors::{
|
actors::client::{ClientConnection, auth, connect_client},
|
||||||
GlobalActors,
|
db,
|
||||||
client::{ClientConnection, ClientCredentials, auth, connect_client},
|
|
||||||
keyholder::Bootstrap,
|
|
||||||
},
|
|
||||||
crypto::integrity,
|
|
||||||
db::{self, schema},
|
|
||||||
};
|
};
|
||||||
use diesel::{ExpressionMethods as _, NullableExpressionMethods as _, QueryDsl as _, insert_into};
|
use diesel::{ExpressionMethods as _, NullableExpressionMethods as _, QueryDsl as _, insert_into};
|
||||||
use diesel_async::RunQueryDsl;
|
use diesel_async::RunQueryDsl;
|
||||||
use ml_dsa::{KeyGen, MlDsa87, SigningKey, VerifyingKey, signature::Keypair as _};
|
use ed25519_dalek::Signer as _;
|
||||||
|
|
||||||
use super::common::ChannelTransport;
|
use super::common::ChannelTransport;
|
||||||
|
|
||||||
@@ -29,8 +21,7 @@ fn metadata(name: &str, description: Option<&str>, version: Option<&str>) -> Cli
|
|||||||
|
|
||||||
async fn insert_registered_client(
|
async fn insert_registered_client(
|
||||||
db: &db::DatabasePool,
|
db: &db::DatabasePool,
|
||||||
actors: &GlobalActors,
|
pubkey: Vec<u8>,
|
||||||
pubkey: VerifyingKey<MlDsa87>,
|
|
||||||
metadata: &ClientMetadata,
|
metadata: &ClientMetadata,
|
||||||
) {
|
) {
|
||||||
use arbiter_server::db::schema::{client_metadata, program_client};
|
use arbiter_server::db::schema::{client_metadata, program_client};
|
||||||
@@ -46,90 +37,34 @@ async fn insert_registered_client(
|
|||||||
.get_result(&mut conn)
|
.get_result(&mut conn)
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
let client_id: i32 = insert_into(program_client::table)
|
insert_into(program_client::table)
|
||||||
.values((
|
.values((
|
||||||
program_client::public_key.eq(pubkey.encode().to_vec()),
|
program_client::public_key.eq(pubkey),
|
||||||
program_client::metadata_id.eq(metadata_id),
|
program_client::metadata_id.eq(metadata_id),
|
||||||
))
|
))
|
||||||
.returning(program_client::id)
|
|
||||||
.get_result(&mut conn)
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
|
|
||||||
integrity::sign_entity(
|
|
||||||
&mut conn,
|
|
||||||
&actors.key_holder,
|
|
||||||
&ClientCredentials {
|
|
||||||
pubkey: pubkey.into(),
|
|
||||||
nonce: 1,
|
|
||||||
},
|
|
||||||
client_id,
|
|
||||||
)
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
}
|
|
||||||
|
|
||||||
fn sign_client_challenge(
|
|
||||||
key: &SigningKey<MlDsa87>,
|
|
||||||
nonce: i32,
|
|
||||||
pubkey: &authn::PublicKey,
|
|
||||||
) -> authn::Signature {
|
|
||||||
let challenge = format_challenge(nonce, &pubkey.to_bytes());
|
|
||||||
key.signing_key()
|
|
||||||
.sign_deterministic(&challenge, CLIENT_CONTEXT)
|
|
||||||
.unwrap()
|
|
||||||
.into()
|
|
||||||
}
|
|
||||||
|
|
||||||
async fn insert_bootstrap_sentinel_useragent(db: &db::DatabasePool) {
|
|
||||||
let mut conn = db.get().await.unwrap();
|
|
||||||
let sentinel_key = MlDsa87::key_gen(&mut rand::rng())
|
|
||||||
.verifying_key()
|
|
||||||
.encode()
|
|
||||||
.to_vec();
|
|
||||||
|
|
||||||
insert_into(schema::useragent_client::table)
|
|
||||||
.values((
|
|
||||||
schema::useragent_client::public_key.eq(sentinel_key),
|
|
||||||
schema::useragent_client::key_type.eq(1i32),
|
|
||||||
))
|
|
||||||
.execute(&mut conn)
|
.execute(&mut conn)
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
}
|
}
|
||||||
|
|
||||||
async fn spawn_test_actors(db: &db::DatabasePool) -> GlobalActors {
|
|
||||||
insert_bootstrap_sentinel_useragent(db).await;
|
|
||||||
|
|
||||||
let actors = GlobalActors::spawn(db.clone()).await.unwrap();
|
|
||||||
actors
|
|
||||||
.key_holder
|
|
||||||
.ask(Bootstrap {
|
|
||||||
seal_key_raw: SafeCell::new(b"test-seal-key".to_vec()),
|
|
||||||
})
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
actors
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
pub async fn test_unregistered_pubkey_rejected() {
|
pub async fn test_unregistered_pubkey_rejected() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
|
|
||||||
let (server_transport, mut test_transport) = ChannelTransport::new();
|
let (server_transport, mut test_transport) = ChannelTransport::new();
|
||||||
let actors = spawn_test_actors(&db).await;
|
let actors = GlobalActors::spawn(db.clone()).await.unwrap();
|
||||||
let props = ClientConnection::new(db.clone(), actors);
|
let props = ClientConnection::new(db.clone(), actors);
|
||||||
let task = tokio::spawn(async move {
|
let task = tokio::spawn(async move {
|
||||||
let mut server_transport = server_transport;
|
let mut server_transport = server_transport;
|
||||||
connect_client(props, &mut server_transport).await;
|
connect_client(props, &mut server_transport).await;
|
||||||
});
|
});
|
||||||
|
|
||||||
let new_key = MlDsa87::key_gen(&mut rand::rng());
|
let new_key = ed25519_dalek::SigningKey::generate(&mut rand::rng());
|
||||||
|
|
||||||
test_transport
|
test_transport
|
||||||
.send(auth::Inbound::AuthChallengeRequest {
|
.send(auth::Inbound::AuthChallengeRequest {
|
||||||
pubkey: new_key.verifying_key().into(),
|
pubkey: new_key.verifying_key(),
|
||||||
metadata: metadata("client", Some("desc"), Some("1.0.0")),
|
metadata: metadata("client", Some("desc"), Some("1.0.0")),
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
@@ -143,19 +78,20 @@ pub async fn test_unregistered_pubkey_rejected() {
|
|||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
pub async fn test_challenge_auth() {
|
pub async fn test_challenge_auth() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
let actors = spawn_test_actors(&db).await;
|
|
||||||
|
|
||||||
let new_key = MlDsa87::key_gen(&mut rand::rng());
|
let new_key = ed25519_dalek::SigningKey::generate(&mut rand::rng());
|
||||||
|
let pubkey_bytes = new_key.verifying_key().to_bytes().to_vec();
|
||||||
|
|
||||||
insert_registered_client(
|
insert_registered_client(
|
||||||
&db,
|
&db,
|
||||||
&actors,
|
pubkey_bytes.clone(),
|
||||||
new_key.verifying_key(),
|
|
||||||
&metadata("client", Some("desc"), Some("1.0.0")),
|
&metadata("client", Some("desc"), Some("1.0.0")),
|
||||||
)
|
)
|
||||||
.await;
|
.await;
|
||||||
|
|
||||||
let (server_transport, mut test_transport) = ChannelTransport::new();
|
let (server_transport, mut test_transport) = ChannelTransport::new();
|
||||||
|
let actors = GlobalActors::spawn(db.clone()).await.unwrap();
|
||||||
|
|
||||||
let props = ClientConnection::new(db.clone(), actors);
|
let props = ClientConnection::new(db.clone(), actors);
|
||||||
let task = tokio::spawn(async move {
|
let task = tokio::spawn(async move {
|
||||||
let mut server_transport = server_transport;
|
let mut server_transport = server_transport;
|
||||||
@@ -165,7 +101,7 @@ pub async fn test_challenge_auth() {
|
|||||||
// Send challenge request
|
// Send challenge request
|
||||||
test_transport
|
test_transport
|
||||||
.send(auth::Inbound::AuthChallengeRequest {
|
.send(auth::Inbound::AuthChallengeRequest {
|
||||||
pubkey: new_key.verifying_key().into(),
|
pubkey: new_key.verifying_key(),
|
||||||
metadata: metadata("client", Some("desc"), Some("1.0.0")),
|
metadata: metadata("client", Some("desc"), Some("1.0.0")),
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
@@ -185,7 +121,8 @@ pub async fn test_challenge_auth() {
|
|||||||
};
|
};
|
||||||
|
|
||||||
// Sign the challenge and send solution
|
// Sign the challenge and send solution
|
||||||
let signature = sign_client_challenge(&new_key, challenge.1, &challenge.0);
|
let formatted_challenge = arbiter_proto::format_challenge(challenge.1, challenge.0.as_bytes());
|
||||||
|
let signature = new_key.sign(&formatted_challenge);
|
||||||
|
|
||||||
test_transport
|
test_transport
|
||||||
.send(auth::Inbound::AuthChallengeSolution { signature })
|
.send(auth::Inbound::AuthChallengeSolution { signature })
|
||||||
@@ -210,13 +147,34 @@ pub async fn test_challenge_auth() {
|
|||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
pub async fn test_metadata_unchanged_does_not_append_history() {
|
pub async fn test_metadata_unchanged_does_not_append_history() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
let actors = spawn_test_actors(&db).await;
|
let actors = GlobalActors::spawn(db.clone()).await.unwrap();
|
||||||
let new_key = MlDsa87::key_gen(&mut rand::rng());
|
let props = ClientConnection::new(db.clone(), actors);
|
||||||
|
|
||||||
|
let new_key = ed25519_dalek::SigningKey::generate(&mut rand::rng());
|
||||||
let requested = metadata("client", Some("desc"), Some("1.0.0"));
|
let requested = metadata("client", Some("desc"), Some("1.0.0"));
|
||||||
|
|
||||||
insert_registered_client(&db, &actors, new_key.verifying_key(), &requested).await;
|
{
|
||||||
|
use arbiter_server::db::schema::{client_metadata, program_client};
|
||||||
let props = ClientConnection::new(db.clone(), actors);
|
let mut conn = db.get().await.unwrap();
|
||||||
|
let metadata_id: i32 = insert_into(client_metadata::table)
|
||||||
|
.values((
|
||||||
|
client_metadata::name.eq(&requested.name),
|
||||||
|
client_metadata::description.eq(&requested.description),
|
||||||
|
client_metadata::version.eq(&requested.version),
|
||||||
|
))
|
||||||
|
.returning(client_metadata::id)
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
insert_into(program_client::table)
|
||||||
|
.values((
|
||||||
|
program_client::public_key.eq(new_key.verifying_key().to_bytes().to_vec()),
|
||||||
|
program_client::metadata_id.eq(metadata_id),
|
||||||
|
))
|
||||||
|
.execute(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
}
|
||||||
|
|
||||||
let (server_transport, mut test_transport) = ChannelTransport::new();
|
let (server_transport, mut test_transport) = ChannelTransport::new();
|
||||||
let task = tokio::spawn(async move {
|
let task = tokio::spawn(async move {
|
||||||
@@ -226,7 +184,7 @@ pub async fn test_metadata_unchanged_does_not_append_history() {
|
|||||||
|
|
||||||
test_transport
|
test_transport
|
||||||
.send(auth::Inbound::AuthChallengeRequest {
|
.send(auth::Inbound::AuthChallengeRequest {
|
||||||
pubkey: new_key.verifying_key().into(),
|
pubkey: new_key.verifying_key(),
|
||||||
metadata: requested,
|
metadata: requested,
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
@@ -237,7 +195,7 @@ pub async fn test_metadata_unchanged_does_not_append_history() {
|
|||||||
auth::Outbound::AuthChallenge { pubkey, nonce } => (pubkey, nonce),
|
auth::Outbound::AuthChallenge { pubkey, nonce } => (pubkey, nonce),
|
||||||
other => panic!("Expected AuthChallenge, got {other:?}"),
|
other => panic!("Expected AuthChallenge, got {other:?}"),
|
||||||
};
|
};
|
||||||
let signature = sign_client_challenge(&new_key, nonce, &pubkey);
|
let signature = new_key.sign(&arbiter_proto::format_challenge(nonce, pubkey.as_bytes()));
|
||||||
test_transport
|
test_transport
|
||||||
.send(auth::Inbound::AuthChallengeSolution { signature })
|
.send(auth::Inbound::AuthChallengeSolution { signature })
|
||||||
.await
|
.await
|
||||||
@@ -267,19 +225,34 @@ pub async fn test_metadata_unchanged_does_not_append_history() {
|
|||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
pub async fn test_metadata_change_appends_history_and_repoints_binding() {
|
pub async fn test_metadata_change_appends_history_and_repoints_binding() {
|
||||||
let db = db::create_test_pool().await;
|
let db = db::create_test_pool().await;
|
||||||
let actors = spawn_test_actors(&db).await;
|
let actors = GlobalActors::spawn(db.clone()).await.unwrap();
|
||||||
let new_key = MlDsa87::key_gen(&mut rand::rng());
|
|
||||||
|
|
||||||
insert_registered_client(
|
|
||||||
&db,
|
|
||||||
&actors,
|
|
||||||
new_key.verifying_key(),
|
|
||||||
&metadata("client", Some("old"), Some("1.0.0")),
|
|
||||||
)
|
|
||||||
.await;
|
|
||||||
|
|
||||||
let props = ClientConnection::new(db.clone(), actors);
|
let props = ClientConnection::new(db.clone(), actors);
|
||||||
|
|
||||||
|
let new_key = ed25519_dalek::SigningKey::generate(&mut rand::rng());
|
||||||
|
|
||||||
|
{
|
||||||
|
use arbiter_server::db::schema::{client_metadata, program_client};
|
||||||
|
let mut conn = db.get().await.unwrap();
|
||||||
|
let metadata_id: i32 = insert_into(client_metadata::table)
|
||||||
|
.values((
|
||||||
|
client_metadata::name.eq("client"),
|
||||||
|
client_metadata::description.eq(Some("old")),
|
||||||
|
client_metadata::version.eq(Some("1.0.0")),
|
||||||
|
))
|
||||||
|
.returning(client_metadata::id)
|
||||||
|
.get_result(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
insert_into(program_client::table)
|
||||||
|
.values((
|
||||||
|
program_client::public_key.eq(new_key.verifying_key().to_bytes().to_vec()),
|
||||||
|
program_client::metadata_id.eq(metadata_id),
|
||||||
|
))
|
||||||
|
.execute(&mut conn)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
}
|
||||||
|
|
||||||
let (server_transport, mut test_transport) = ChannelTransport::new();
|
let (server_transport, mut test_transport) = ChannelTransport::new();
|
||||||
let task = tokio::spawn(async move {
|
let task = tokio::spawn(async move {
|
||||||
let mut server_transport = server_transport;
|
let mut server_transport = server_transport;
|
||||||
@@ -288,7 +261,7 @@ pub async fn test_metadata_change_appends_history_and_repoints_binding() {
|
|||||||
|
|
||||||
test_transport
|
test_transport
|
||||||
.send(auth::Inbound::AuthChallengeRequest {
|
.send(auth::Inbound::AuthChallengeRequest {
|
||||||
pubkey: new_key.verifying_key().into(),
|
pubkey: new_key.verifying_key(),
|
||||||
metadata: metadata("client", Some("new"), Some("2.0.0")),
|
metadata: metadata("client", Some("new"), Some("2.0.0")),
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
@@ -299,7 +272,7 @@ pub async fn test_metadata_change_appends_history_and_repoints_binding() {
|
|||||||
auth::Outbound::AuthChallenge { pubkey, nonce } => (pubkey, nonce),
|
auth::Outbound::AuthChallenge { pubkey, nonce } => (pubkey, nonce),
|
||||||
other => panic!("Expected AuthChallenge, got {other:?}"),
|
other => panic!("Expected AuthChallenge, got {other:?}"),
|
||||||
};
|
};
|
||||||
let signature = sign_client_challenge(&new_key, nonce, &pubkey);
|
let signature = new_key.sign(&arbiter_proto::format_challenge(nonce, pubkey.as_bytes()));
|
||||||
test_transport
|
test_transport
|
||||||
.send(auth::Inbound::AuthChallengeSolution { signature })
|
.send(auth::Inbound::AuthChallengeSolution { signature })
|
||||||
.await
|
.await
|
||||||
@@ -349,59 +322,3 @@ pub async fn test_metadata_change_appends_history_and_repoints_binding() {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#[tokio::test]
|
|
||||||
#[test_log::test]
|
|
||||||
pub async fn test_challenge_auth_rejects_integrity_tag_mismatch() {
|
|
||||||
let db = db::create_test_pool().await;
|
|
||||||
let actors = spawn_test_actors(&db).await;
|
|
||||||
|
|
||||||
let new_key = MlDsa87::key_gen(&mut rand::rng());
|
|
||||||
let requested = metadata("client", Some("desc"), Some("1.0.0"));
|
|
||||||
|
|
||||||
{
|
|
||||||
use arbiter_server::db::schema::{client_metadata, program_client};
|
|
||||||
let mut conn = db.get().await.unwrap();
|
|
||||||
let metadata_id: i32 = insert_into(client_metadata::table)
|
|
||||||
.values((
|
|
||||||
client_metadata::name.eq(&requested.name),
|
|
||||||
client_metadata::description.eq(&requested.description),
|
|
||||||
client_metadata::version.eq(&requested.version),
|
|
||||||
))
|
|
||||||
.returning(client_metadata::id)
|
|
||||||
.get_result(&mut conn)
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
insert_into(program_client::table)
|
|
||||||
.values((
|
|
||||||
program_client::public_key.eq(new_key.verifying_key().encode().to_vec()),
|
|
||||||
program_client::metadata_id.eq(metadata_id),
|
|
||||||
))
|
|
||||||
.execute(&mut conn)
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
}
|
|
||||||
|
|
||||||
let (server_transport, mut test_transport) = ChannelTransport::new();
|
|
||||||
let props = ClientConnection::new(db.clone(), actors);
|
|
||||||
let task = tokio::spawn(async move {
|
|
||||||
let mut server_transport = server_transport;
|
|
||||||
connect_client(props, &mut server_transport).await;
|
|
||||||
});
|
|
||||||
|
|
||||||
test_transport
|
|
||||||
.send(auth::Inbound::AuthChallengeRequest {
|
|
||||||
pubkey: new_key.verifying_key().into(),
|
|
||||||
metadata: requested,
|
|
||||||
})
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
|
|
||||||
let response = test_transport
|
|
||||||
.recv()
|
|
||||||
.await
|
|
||||||
.expect("should receive auth rejection");
|
|
||||||
assert!(matches!(response, Err(auth::Error::IntegrityCheckFailed)));
|
|
||||||
|
|
||||||
task.await.unwrap();
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -1,10 +1,9 @@
|
|||||||
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
|
||||||
use arbiter_proto::transport::{Bi, Error, Receiver, Sender};
|
use arbiter_proto::transport::{Bi, Error, Receiver, Sender};
|
||||||
use arbiter_server::{
|
use arbiter_server::{
|
||||||
actors::keyholder::KeyHolder,
|
actors::keyholder::KeyHolder,
|
||||||
db::{self, schema},
|
db::{self, schema},
|
||||||
|
safe_cell::{SafeCell, SafeCellHandle as _},
|
||||||
};
|
};
|
||||||
|
|
||||||
use async_trait::async_trait;
|
use async_trait::async_trait;
|
||||||
use diesel::QueryDsl;
|
use diesel::QueryDsl;
|
||||||
use diesel_async::RunQueryDsl;
|
use diesel_async::RunQueryDsl;
|
||||||
|
|||||||
@@ -1,11 +1,10 @@
|
|||||||
use std::collections::{HashMap, HashSet};
|
use std::collections::{HashMap, HashSet};
|
||||||
|
|
||||||
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
|
||||||
use arbiter_server::{
|
use arbiter_server::{
|
||||||
actors::keyholder::{CreateNew, Error, KeyHolder},
|
actors::keyholder::{CreateNew, Error, KeyHolder},
|
||||||
db::{self, models, schema},
|
db::{self, models, schema},
|
||||||
|
safe_cell::{SafeCell, SafeCellHandle as _},
|
||||||
};
|
};
|
||||||
|
|
||||||
use diesel::{ExpressionMethods as _, QueryDsl, SelectableHelper, dsl::sql_query};
|
use diesel::{ExpressionMethods as _, QueryDsl, SelectableHelper, dsl::sql_query};
|
||||||
use diesel_async::RunQueryDsl;
|
use diesel_async::RunQueryDsl;
|
||||||
use kameo::actor::{ActorRef, Spawn as _};
|
use kameo::actor::{ActorRef, Spawn as _};
|
||||||
|
|||||||
@@ -1,10 +1,9 @@
|
|||||||
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
|
||||||
use arbiter_server::{
|
use arbiter_server::{
|
||||||
actors::keyholder::{Error, KeyHolder},
|
actors::keyholder::{Error, KeyHolder},
|
||||||
crypto::encryption::v1::{Nonce, ROOT_KEY_TAG},
|
crypto::encryption::v1::{Nonce, ROOT_KEY_TAG},
|
||||||
db::{self, models, schema},
|
db::{self, models, schema},
|
||||||
|
safe_cell::{SafeCell, SafeCellHandle as _},
|
||||||
};
|
};
|
||||||
|
|
||||||
use diesel::{QueryDsl, SelectableHelper};
|
use diesel::{QueryDsl, SelectableHelper};
|
||||||
use diesel_async::RunQueryDsl;
|
use diesel_async::RunQueryDsl;
|
||||||
|
|
||||||
|
|||||||
@@ -1,12 +1,11 @@
|
|||||||
use std::collections::HashSet;
|
use std::collections::HashSet;
|
||||||
|
|
||||||
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
|
||||||
use arbiter_server::{
|
use arbiter_server::{
|
||||||
actors::keyholder::Error,
|
actors::keyholder::Error,
|
||||||
crypto::encryption::v1::Nonce,
|
crypto::encryption::v1::Nonce,
|
||||||
db::{self, models, schema},
|
db::{self, models, schema},
|
||||||
|
safe_cell::{SafeCell, SafeCellHandle as _},
|
||||||
};
|
};
|
||||||
|
|
||||||
use diesel::{ExpressionMethods as _, QueryDsl, SelectableHelper, dsl::update};
|
use diesel::{ExpressionMethods as _, QueryDsl, SelectableHelper, dsl::update};
|
||||||
use diesel_async::RunQueryDsl;
|
use diesel_async::RunQueryDsl;
|
||||||
|
|
||||||
|
|||||||
@@ -1,37 +1,21 @@
|
|||||||
use arbiter_crypto::{
|
|
||||||
authn::{self, USERAGENT_CONTEXT, format_challenge},
|
|
||||||
safecell::{SafeCell, SafeCellHandle as _},
|
|
||||||
};
|
|
||||||
|
|
||||||
use arbiter_proto::transport::{Receiver, Sender};
|
use arbiter_proto::transport::{Receiver, Sender};
|
||||||
use arbiter_server::{
|
use arbiter_server::{
|
||||||
actors::{
|
actors::{
|
||||||
GlobalActors,
|
GlobalActors,
|
||||||
bootstrap::GetToken,
|
bootstrap::GetToken,
|
||||||
keyholder::Bootstrap,
|
keyholder::Bootstrap,
|
||||||
user_agent::{UserAgentConnection, UserAgentCredentials, auth},
|
user_agent::{AuthPublicKey, UserAgentConnection, UserAgentCredentials, auth},
|
||||||
},
|
},
|
||||||
crypto::integrity,
|
crypto::integrity,
|
||||||
db::{self, schema},
|
db::{self, schema},
|
||||||
|
safe_cell::{SafeCell, SafeCellHandle as _},
|
||||||
};
|
};
|
||||||
use diesel::{ExpressionMethods as _, QueryDsl, insert_into};
|
use diesel::{ExpressionMethods as _, QueryDsl, insert_into};
|
||||||
use diesel_async::RunQueryDsl;
|
use diesel_async::RunQueryDsl;
|
||||||
use ml_dsa::{KeyGen, MlDsa87, SigningKey, signature::Keypair as _};
|
use ed25519_dalek::Signer as _;
|
||||||
|
|
||||||
use super::common::ChannelTransport;
|
use super::common::ChannelTransport;
|
||||||
|
|
||||||
fn sign_useragent_challenge(
|
|
||||||
key: &SigningKey<MlDsa87>,
|
|
||||||
nonce: i32,
|
|
||||||
pubkey_bytes: &[u8],
|
|
||||||
) -> authn::Signature {
|
|
||||||
let challenge = format_challenge(nonce, pubkey_bytes);
|
|
||||||
key.signing_key()
|
|
||||||
.sign_deterministic(&challenge, USERAGENT_CONTEXT)
|
|
||||||
.unwrap()
|
|
||||||
.into()
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
#[test_log::test]
|
#[test_log::test]
|
||||||
pub async fn test_bootstrap_token_auth() {
|
pub async fn test_bootstrap_token_auth() {
|
||||||
@@ -53,10 +37,10 @@ pub async fn test_bootstrap_token_auth() {
|
|||||||
auth::authenticate(&mut props, server_transport).await
|
auth::authenticate(&mut props, server_transport).await
|
||||||
});
|
});
|
||||||
|
|
||||||
let new_key = MlDsa87::key_gen(&mut rand::rng());
|
let new_key = ed25519_dalek::SigningKey::generate(&mut rand::rng());
|
||||||
test_transport
|
test_transport
|
||||||
.send(auth::Inbound::AuthChallengeRequest {
|
.send(auth::Inbound::AuthChallengeRequest {
|
||||||
pubkey: new_key.verifying_key().into(),
|
pubkey: AuthPublicKey::Ed25519(new_key.verifying_key()),
|
||||||
bootstrap_token: Some(token),
|
bootstrap_token: Some(token),
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
@@ -79,7 +63,7 @@ pub async fn test_bootstrap_token_auth() {
|
|||||||
.first::<Vec<u8>>(&mut conn)
|
.first::<Vec<u8>>(&mut conn)
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
assert_eq!(stored_pubkey, new_key.verifying_key().encode().to_vec());
|
assert_eq!(stored_pubkey, new_key.verifying_key().to_bytes().to_vec());
|
||||||
}
|
}
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
@@ -95,10 +79,10 @@ pub async fn test_bootstrap_invalid_token_auth() {
|
|||||||
auth::authenticate(&mut props, server_transport).await
|
auth::authenticate(&mut props, server_transport).await
|
||||||
});
|
});
|
||||||
|
|
||||||
let new_key = MlDsa87::key_gen(&mut rand::rng());
|
let new_key = ed25519_dalek::SigningKey::generate(&mut rand::rng());
|
||||||
test_transport
|
test_transport
|
||||||
.send(auth::Inbound::AuthChallengeRequest {
|
.send(auth::Inbound::AuthChallengeRequest {
|
||||||
pubkey: new_key.verifying_key().into(),
|
pubkey: AuthPublicKey::Ed25519(new_key.verifying_key()),
|
||||||
bootstrap_token: Some("invalid_token".to_string()),
|
bootstrap_token: Some("invalid_token".to_string()),
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
@@ -131,8 +115,8 @@ pub async fn test_challenge_auth() {
|
|||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
|
|
||||||
let new_key = MlDsa87::key_gen(&mut rand::rng());
|
let new_key = ed25519_dalek::SigningKey::generate(&mut rand::rng());
|
||||||
let pubkey_bytes = new_key.verifying_key().encode().to_vec();
|
let pubkey_bytes = new_key.verifying_key().to_bytes().to_vec();
|
||||||
|
|
||||||
{
|
{
|
||||||
let mut conn = db.get().await.unwrap();
|
let mut conn = db.get().await.unwrap();
|
||||||
@@ -149,7 +133,7 @@ pub async fn test_challenge_auth() {
|
|||||||
&mut conn,
|
&mut conn,
|
||||||
&actors.key_holder,
|
&actors.key_holder,
|
||||||
&UserAgentCredentials {
|
&UserAgentCredentials {
|
||||||
pubkey: new_key.verifying_key().into(),
|
pubkey: AuthPublicKey::Ed25519(new_key.verifying_key()),
|
||||||
nonce: 1,
|
nonce: 1,
|
||||||
},
|
},
|
||||||
id,
|
id,
|
||||||
@@ -167,7 +151,7 @@ pub async fn test_challenge_auth() {
|
|||||||
|
|
||||||
test_transport
|
test_transport
|
||||||
.send(auth::Inbound::AuthChallengeRequest {
|
.send(auth::Inbound::AuthChallengeRequest {
|
||||||
pubkey: new_key.verifying_key().into(),
|
pubkey: AuthPublicKey::Ed25519(new_key.verifying_key()),
|
||||||
bootstrap_token: None,
|
bootstrap_token: None,
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
@@ -185,11 +169,12 @@ pub async fn test_challenge_auth() {
|
|||||||
Err(err) => panic!("Expected Ok response, got Err({err:?})"),
|
Err(err) => panic!("Expected Ok response, got Err({err:?})"),
|
||||||
};
|
};
|
||||||
|
|
||||||
let signature = sign_useragent_challenge(&new_key, challenge, &pubkey_bytes);
|
let formatted_challenge = arbiter_proto::format_challenge(challenge, &pubkey_bytes);
|
||||||
|
let signature = new_key.sign(&formatted_challenge);
|
||||||
|
|
||||||
test_transport
|
test_transport
|
||||||
.send(auth::Inbound::AuthChallengeSolution {
|
.send(auth::Inbound::AuthChallengeSolution {
|
||||||
signature: signature.to_bytes(),
|
signature: signature.to_bytes().to_vec(),
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
@@ -220,8 +205,8 @@ pub async fn test_challenge_auth_rejects_integrity_tag_mismatch_when_unsealed()
|
|||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
|
|
||||||
let new_key = MlDsa87::key_gen(&mut rand::rng());
|
let new_key = ed25519_dalek::SigningKey::generate(&mut rand::rng());
|
||||||
let pubkey_bytes = new_key.verifying_key().encode().to_vec();
|
let pubkey_bytes = new_key.verifying_key().to_bytes().to_vec();
|
||||||
|
|
||||||
{
|
{
|
||||||
let mut conn = db.get().await.unwrap();
|
let mut conn = db.get().await.unwrap();
|
||||||
@@ -244,7 +229,7 @@ pub async fn test_challenge_auth_rejects_integrity_tag_mismatch_when_unsealed()
|
|||||||
|
|
||||||
test_transport
|
test_transport
|
||||||
.send(auth::Inbound::AuthChallengeRequest {
|
.send(auth::Inbound::AuthChallengeRequest {
|
||||||
pubkey: new_key.verifying_key().into(),
|
pubkey: AuthPublicKey::Ed25519(new_key.verifying_key()),
|
||||||
bootstrap_token: None,
|
bootstrap_token: None,
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
@@ -269,8 +254,8 @@ pub async fn test_challenge_auth_rejects_invalid_signature() {
|
|||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
|
|
||||||
let new_key = MlDsa87::key_gen(&mut rand::rng());
|
let new_key = ed25519_dalek::SigningKey::generate(&mut rand::rng());
|
||||||
let pubkey_bytes = new_key.verifying_key().encode().to_vec();
|
let pubkey_bytes = new_key.verifying_key().to_bytes().to_vec();
|
||||||
|
|
||||||
{
|
{
|
||||||
let mut conn = db.get().await.unwrap();
|
let mut conn = db.get().await.unwrap();
|
||||||
@@ -287,7 +272,7 @@ pub async fn test_challenge_auth_rejects_invalid_signature() {
|
|||||||
&mut conn,
|
&mut conn,
|
||||||
&actors.key_holder,
|
&actors.key_holder,
|
||||||
&UserAgentCredentials {
|
&UserAgentCredentials {
|
||||||
pubkey: new_key.verifying_key().into(),
|
pubkey: AuthPublicKey::Ed25519(new_key.verifying_key()),
|
||||||
nonce: 1,
|
nonce: 1,
|
||||||
},
|
},
|
||||||
id,
|
id,
|
||||||
@@ -305,7 +290,7 @@ pub async fn test_challenge_auth_rejects_invalid_signature() {
|
|||||||
|
|
||||||
test_transport
|
test_transport
|
||||||
.send(auth::Inbound::AuthChallengeRequest {
|
.send(auth::Inbound::AuthChallengeRequest {
|
||||||
pubkey: new_key.verifying_key().into(),
|
pubkey: AuthPublicKey::Ed25519(new_key.verifying_key()),
|
||||||
bootstrap_token: None,
|
bootstrap_token: None,
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
@@ -323,11 +308,12 @@ pub async fn test_challenge_auth_rejects_invalid_signature() {
|
|||||||
Err(err) => panic!("Expected Ok response, got Err({err:?})"),
|
Err(err) => panic!("Expected Ok response, got Err({err:?})"),
|
||||||
};
|
};
|
||||||
|
|
||||||
let signature = sign_useragent_challenge(&new_key, challenge + 1, &pubkey_bytes);
|
let wrong_challenge = arbiter_proto::format_challenge(challenge + 1, &pubkey_bytes);
|
||||||
|
let signature = new_key.sign(&wrong_challenge);
|
||||||
|
|
||||||
test_transport
|
test_transport
|
||||||
.send(auth::Inbound::AuthChallengeSolution {
|
.send(auth::Inbound::AuthChallengeSolution {
|
||||||
signature: signature.to_bytes(),
|
signature: signature.to_bytes().to_vec(),
|
||||||
})
|
})
|
||||||
.await
|
.await
|
||||||
.unwrap();
|
.unwrap();
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
use arbiter_crypto::safecell::{SafeCell, SafeCellHandle as _};
|
|
||||||
use arbiter_server::{
|
use arbiter_server::{
|
||||||
actors::{
|
actors::{
|
||||||
GlobalActors,
|
GlobalActors,
|
||||||
@@ -9,9 +8,11 @@ use arbiter_server::{
|
|||||||
},
|
},
|
||||||
},
|
},
|
||||||
db,
|
db,
|
||||||
|
safe_cell::{SafeCell, SafeCellHandle as _},
|
||||||
};
|
};
|
||||||
|
|
||||||
use chacha20poly1305::{AeadInPlace, XChaCha20Poly1305, XNonce, aead::KeyInit};
|
use chacha20poly1305::{AeadInPlace, XChaCha20Poly1305, XNonce, aead::KeyInit};
|
||||||
|
use diesel::{ExpressionMethods as _, QueryDsl as _, insert_into};
|
||||||
|
use diesel_async::RunQueryDsl;
|
||||||
use kameo::actor::Spawn as _;
|
use kameo::actor::Spawn as _;
|
||||||
use x25519_dalek::{EphemeralSecret, PublicKey};
|
use x25519_dalek::{EphemeralSecret, PublicKey};
|
||||||
|
|
||||||
@@ -150,4 +151,4 @@ pub async fn test_unseal_retry_after_invalid_key() {
|
|||||||
let response = user_agent.ask(encrypted_key).await;
|
let response = user_agent.ask(encrypted_key).await;
|
||||||
assert!(matches!(response, Ok(())));
|
assert!(matches!(response, Ok(())));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
Reference in New Issue
Block a user