2015-07-07 00:54:22 +00:00
|
|
|
// Copyright 2014 The go-ethereum Authors
|
2015-07-22 16:48:40 +00:00
|
|
|
// This file is part of the go-ethereum library.
|
2015-07-07 00:54:22 +00:00
|
|
|
//
|
2015-07-23 16:35:11 +00:00
|
|
|
// The go-ethereum library is free software: you can redistribute it and/or modify
|
2015-07-07 00:54:22 +00:00
|
|
|
// it under the terms of the GNU Lesser General Public License as published by
|
|
|
|
// the Free Software Foundation, either version 3 of the License, or
|
|
|
|
// (at your option) any later version.
|
|
|
|
//
|
2015-07-22 16:48:40 +00:00
|
|
|
// The go-ethereum library is distributed in the hope that it will be useful,
|
2015-07-07 00:54:22 +00:00
|
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
2015-07-22 16:48:40 +00:00
|
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
2015-07-07 00:54:22 +00:00
|
|
|
// GNU Lesser General Public License for more details.
|
|
|
|
//
|
|
|
|
// You should have received a copy of the GNU Lesser General Public License
|
2015-07-22 16:48:40 +00:00
|
|
|
// along with the go-ethereum library. If not, see <http://www.gnu.org/licenses/>.
|
2015-07-07 00:54:22 +00:00
|
|
|
|
2014-10-18 11:31:20 +00:00
|
|
|
package vm
|
2014-10-08 10:01:36 +00:00
|
|
|
|
|
|
|
import (
|
2017-02-18 08:24:12 +00:00
|
|
|
"crypto/sha256"
|
2019-06-17 17:19:47 +00:00
|
|
|
"encoding/binary"
|
2017-02-01 21:36:51 +00:00
|
|
|
"errors"
|
common: move big integer math to common/math (#3699)
* common: remove CurrencyToString
Move denomination values to params instead.
* common: delete dead code
* common: move big integer operations to common/math
This commit consolidates all big integer operations into common/math and
adds tests and documentation.
There should be no change in semantics for BigPow, BigMin, BigMax, S256,
U256, Exp and their behaviour is now locked in by tests.
The BigD, BytesToBig and Bytes2Big functions don't provide additional
value, all uses are replaced by new(big.Int).SetBytes().
BigToBytes is now called PaddedBigBytes, its minimum output size
parameter is now specified as the number of bytes instead of bits. The
single use of this function is in the EVM's MSTORE instruction.
Big and String2Big are replaced by ParseBig, which is slightly stricter.
It previously accepted leading zeros for hexadecimal inputs but treated
decimal inputs as octal if a leading zero digit was present.
ParseUint64 is used in places where String2Big was used to decode a
uint64.
The new functions MustParseBig and MustParseUint64 are now used in many
places where parsing errors were previously ignored.
* common: delete unused big integer variables
* accounts/abi: replace uses of BytesToBig with use of encoding/binary
* common: remove BytesToBig
* common: remove Bytes2Big
* common: remove BigTrue
* cmd/utils: add BigFlag and use it for error-checked integer flags
While here, remove environment variable processing for DirectoryFlag
because we don't use it.
* core: add missing error checks in genesis block parser
* common: remove String2Big
* cmd/evm: use utils.BigFlag
* common/math: check for 256 bit overflow in ParseBig
This is supposed to prevent silent overflow/truncation of values in the
genesis block JSON. Without this check, a genesis block that set a
balance larger than 256 bits would lead to weird behaviour in the VM.
* cmd/utils: fixup import
2017-02-26 21:21:51 +00:00
|
|
|
"math/big"
|
2017-02-18 08:24:12 +00:00
|
|
|
|
2020-06-04 07:43:08 +00:00
|
|
|
"github.com/holiman/uint256"
|
|
|
|
|
2019-05-27 13:51:49 +00:00
|
|
|
"github.com/ledgerwatch/turbo-geth/common"
|
|
|
|
"github.com/ledgerwatch/turbo-geth/common/math"
|
|
|
|
"github.com/ledgerwatch/turbo-geth/crypto"
|
|
|
|
"github.com/ledgerwatch/turbo-geth/crypto/blake2b"
|
|
|
|
"github.com/ledgerwatch/turbo-geth/crypto/bn256"
|
|
|
|
"github.com/ledgerwatch/turbo-geth/params"
|
2019-11-27 08:50:30 +00:00
|
|
|
|
|
|
|
//lint:ignore SA1019 Needed for precompile
|
2017-02-18 08:24:12 +00:00
|
|
|
"golang.org/x/crypto/ripemd160"
|
2014-10-08 10:01:36 +00:00
|
|
|
)
|
|
|
|
|
2017-08-10 13:39:43 +00:00
|
|
|
// PrecompiledContract is the basic interface for native Go contracts. The implementation
|
2017-01-05 10:52:10 +00:00
|
|
|
// requires a deterministic gas count based on the input size of the Run method of the
|
|
|
|
// contract.
|
|
|
|
type PrecompiledContract interface {
|
2017-02-01 21:36:51 +00:00
|
|
|
RequiredGas(input []byte) uint64 // RequiredPrice calculates the contract gas use
|
|
|
|
Run(input []byte) ([]byte, error) // Run runs the precompiled contract
|
2014-10-08 10:01:36 +00:00
|
|
|
}
|
|
|
|
|
2017-08-10 13:39:43 +00:00
|
|
|
// PrecompiledContractsHomestead contains the default set of pre-compiled Ethereum
|
|
|
|
// contracts used in the Frontier and Homestead releases.
|
|
|
|
var PrecompiledContractsHomestead = map[common.Address]PrecompiledContract{
|
2017-01-05 10:52:10 +00:00
|
|
|
common.BytesToAddress([]byte{1}): &ecrecover{},
|
2017-02-18 08:24:12 +00:00
|
|
|
common.BytesToAddress([]byte{2}): &sha256hash{},
|
|
|
|
common.BytesToAddress([]byte{3}): &ripemd160hash{},
|
2017-01-05 10:52:10 +00:00
|
|
|
common.BytesToAddress([]byte{4}): &dataCopy{},
|
2014-10-08 10:01:36 +00:00
|
|
|
}
|
|
|
|
|
2017-09-14 07:07:31 +00:00
|
|
|
// PrecompiledContractsByzantium contains the default set of pre-compiled Ethereum
|
|
|
|
// contracts used in the Byzantium release.
|
|
|
|
var PrecompiledContractsByzantium = map[common.Address]PrecompiledContract{
|
2017-08-10 11:07:11 +00:00
|
|
|
common.BytesToAddress([]byte{1}): &ecrecover{},
|
|
|
|
common.BytesToAddress([]byte{2}): &sha256hash{},
|
|
|
|
common.BytesToAddress([]byte{3}): &ripemd160hash{},
|
|
|
|
common.BytesToAddress([]byte{4}): &dataCopy{},
|
2017-08-10 13:39:43 +00:00
|
|
|
common.BytesToAddress([]byte{5}): &bigModExp{},
|
2019-08-06 14:12:54 +00:00
|
|
|
common.BytesToAddress([]byte{6}): &bn256AddByzantium{},
|
|
|
|
common.BytesToAddress([]byte{7}): &bn256ScalarMulByzantium{},
|
|
|
|
common.BytesToAddress([]byte{8}): &bn256PairingByzantium{},
|
|
|
|
}
|
|
|
|
|
|
|
|
// PrecompiledContractsIstanbul contains the default set of pre-compiled Ethereum
|
|
|
|
// contracts used in the Istanbul release.
|
|
|
|
var PrecompiledContractsIstanbul = map[common.Address]PrecompiledContract{
|
|
|
|
common.BytesToAddress([]byte{1}): &ecrecover{},
|
|
|
|
common.BytesToAddress([]byte{2}): &sha256hash{},
|
|
|
|
common.BytesToAddress([]byte{3}): &ripemd160hash{},
|
|
|
|
common.BytesToAddress([]byte{4}): &dataCopy{},
|
|
|
|
common.BytesToAddress([]byte{5}): &bigModExp{},
|
|
|
|
common.BytesToAddress([]byte{6}): &bn256AddIstanbul{},
|
|
|
|
common.BytesToAddress([]byte{7}): &bn256ScalarMulIstanbul{},
|
|
|
|
common.BytesToAddress([]byte{8}): &bn256PairingIstanbul{},
|
2019-06-17 17:19:47 +00:00
|
|
|
common.BytesToAddress([]byte{9}): &blake2F{},
|
2017-08-10 11:07:11 +00:00
|
|
|
}
|
|
|
|
|
2017-08-10 13:39:43 +00:00
|
|
|
// RunPrecompiledContract runs and evaluates the output of a precompiled contract.
|
2017-01-05 10:52:10 +00:00
|
|
|
func RunPrecompiledContract(p PrecompiledContract, input []byte, contract *Contract) (ret []byte, err error) {
|
2017-02-01 21:36:51 +00:00
|
|
|
gas := p.RequiredGas(input)
|
2017-01-05 10:52:10 +00:00
|
|
|
if contract.UseGas(gas) {
|
2017-02-01 21:36:51 +00:00
|
|
|
return p.Run(input)
|
2015-01-13 09:30:52 +00:00
|
|
|
}
|
2017-08-10 13:39:43 +00:00
|
|
|
return nil, ErrOutOfGas
|
2014-10-08 10:01:36 +00:00
|
|
|
}
|
|
|
|
|
2017-08-10 13:39:43 +00:00
|
|
|
// ECRECOVER implemented as a native contract.
|
2017-01-05 10:52:10 +00:00
|
|
|
type ecrecover struct{}
|
2014-10-08 10:01:36 +00:00
|
|
|
|
2017-02-01 21:36:51 +00:00
|
|
|
func (c *ecrecover) RequiredGas(input []byte) uint64 {
|
2017-01-05 10:52:10 +00:00
|
|
|
return params.EcrecoverGas
|
2014-10-08 10:01:36 +00:00
|
|
|
}
|
|
|
|
|
2017-08-10 13:39:43 +00:00
|
|
|
func (c *ecrecover) Run(input []byte) ([]byte, error) {
|
2017-01-05 10:52:10 +00:00
|
|
|
const ecRecoverInputLength = 128
|
2014-10-08 10:01:36 +00:00
|
|
|
|
2017-08-10 13:39:43 +00:00
|
|
|
input = common.RightPadBytes(input, ecRecoverInputLength)
|
|
|
|
// "input" is (hash, v, r, s), each 32 bytes
|
2015-06-09 13:41:15 +00:00
|
|
|
// but for ecrecover we want (r, s, v)
|
2015-03-29 13:02:49 +00:00
|
|
|
|
2020-06-04 07:43:08 +00:00
|
|
|
r := new(uint256.Int).SetBytes(input[64:96])
|
|
|
|
s := new(uint256.Int).SetBytes(input[96:128])
|
2017-08-10 13:39:43 +00:00
|
|
|
v := input[63] - 27
|
2015-06-09 13:41:15 +00:00
|
|
|
|
2017-08-10 13:39:43 +00:00
|
|
|
// tighter sig s values input homestead only apply to tx sigs
|
|
|
|
if !allZero(input[32:63]) || !crypto.ValidateSignatureValues(v, r, s, false) {
|
2017-02-01 21:36:51 +00:00
|
|
|
return nil, nil
|
2015-03-19 03:56:06 +00:00
|
|
|
}
|
2019-11-04 09:31:10 +00:00
|
|
|
// We must make sure not to modify the 'input', so placing the 'v' along with
|
|
|
|
// the signature needs to be done on a new allocation
|
|
|
|
sig := make([]byte, 65)
|
|
|
|
copy(sig, input[64:128])
|
|
|
|
sig[64] = v
|
2017-01-05 10:35:23 +00:00
|
|
|
// v needs to be at the end for libsecp256k1
|
2019-11-04 09:31:10 +00:00
|
|
|
pubKey, err := crypto.Ecrecover(input[:32], sig)
|
2015-03-29 13:02:49 +00:00
|
|
|
// make sure the public key is a valid one
|
2015-04-05 17:31:18 +00:00
|
|
|
if err != nil {
|
2017-02-01 21:36:51 +00:00
|
|
|
return nil, nil
|
2015-03-19 03:56:06 +00:00
|
|
|
}
|
2015-03-29 13:02:49 +00:00
|
|
|
|
2015-03-19 03:56:06 +00:00
|
|
|
// the first byte of pubkey is bitcoin heritage
|
2017-02-01 21:36:51 +00:00
|
|
|
return common.LeftPadBytes(crypto.Keccak256(pubKey[1:])[12:], 32), nil
|
2014-10-08 10:01:36 +00:00
|
|
|
}
|
2015-01-05 16:37:30 +00:00
|
|
|
|
2017-08-10 13:39:43 +00:00
|
|
|
// SHA256 implemented as a native contract.
|
2017-02-18 08:24:12 +00:00
|
|
|
type sha256hash struct{}
|
2017-01-05 10:52:10 +00:00
|
|
|
|
2017-01-04 19:17:24 +00:00
|
|
|
// RequiredGas returns the gas required to execute the pre-compiled contract.
|
|
|
|
//
|
|
|
|
// This method does not require any overflow checking as the input size gas costs
|
|
|
|
// required for anything significant is so high it's impossible to pay for.
|
2017-02-01 21:36:51 +00:00
|
|
|
func (c *sha256hash) RequiredGas(input []byte) uint64 {
|
2017-08-10 13:39:43 +00:00
|
|
|
return uint64(len(input)+31)/32*params.Sha256PerWordGas + params.Sha256BaseGas
|
2017-01-05 10:52:10 +00:00
|
|
|
}
|
2017-08-10 13:39:43 +00:00
|
|
|
func (c *sha256hash) Run(input []byte) ([]byte, error) {
|
|
|
|
h := sha256.Sum256(input)
|
2017-02-01 21:36:51 +00:00
|
|
|
return h[:], nil
|
2017-01-05 10:52:10 +00:00
|
|
|
}
|
|
|
|
|
2018-07-31 10:27:51 +00:00
|
|
|
// RIPEMD160 implemented as a native contract.
|
2017-02-18 08:24:12 +00:00
|
|
|
type ripemd160hash struct{}
|
2017-01-05 10:52:10 +00:00
|
|
|
|
2017-01-04 19:17:24 +00:00
|
|
|
// RequiredGas returns the gas required to execute the pre-compiled contract.
|
|
|
|
//
|
|
|
|
// This method does not require any overflow checking as the input size gas costs
|
|
|
|
// required for anything significant is so high it's impossible to pay for.
|
2017-02-01 21:36:51 +00:00
|
|
|
func (c *ripemd160hash) RequiredGas(input []byte) uint64 {
|
2017-08-10 13:39:43 +00:00
|
|
|
return uint64(len(input)+31)/32*params.Ripemd160PerWordGas + params.Ripemd160BaseGas
|
2017-01-05 10:52:10 +00:00
|
|
|
}
|
2017-08-10 13:39:43 +00:00
|
|
|
func (c *ripemd160hash) Run(input []byte) ([]byte, error) {
|
2017-02-18 08:24:12 +00:00
|
|
|
ripemd := ripemd160.New()
|
2017-08-10 13:39:43 +00:00
|
|
|
ripemd.Write(input)
|
2017-02-01 21:36:51 +00:00
|
|
|
return common.LeftPadBytes(ripemd.Sum(nil), 32), nil
|
2017-01-05 10:52:10 +00:00
|
|
|
}
|
|
|
|
|
2017-08-10 13:39:43 +00:00
|
|
|
// data copy implemented as a native contract.
|
2017-01-05 10:52:10 +00:00
|
|
|
type dataCopy struct{}
|
|
|
|
|
2017-01-04 19:17:24 +00:00
|
|
|
// RequiredGas returns the gas required to execute the pre-compiled contract.
|
|
|
|
//
|
|
|
|
// This method does not require any overflow checking as the input size gas costs
|
|
|
|
// required for anything significant is so high it's impossible to pay for.
|
2017-02-01 21:36:51 +00:00
|
|
|
func (c *dataCopy) RequiredGas(input []byte) uint64 {
|
2017-08-10 13:39:43 +00:00
|
|
|
return uint64(len(input)+31)/32*params.IdentityPerWordGas + params.IdentityBaseGas
|
2017-01-05 10:52:10 +00:00
|
|
|
}
|
2017-02-01 21:36:51 +00:00
|
|
|
func (c *dataCopy) Run(in []byte) ([]byte, error) {
|
|
|
|
return in, nil
|
2015-01-05 16:37:30 +00:00
|
|
|
}
|
2017-08-10 11:07:11 +00:00
|
|
|
|
2017-08-10 13:39:43 +00:00
|
|
|
// bigModExp implements a native big integer exponential modular operation.
|
|
|
|
type bigModExp struct{}
|
2017-08-10 11:07:11 +00:00
|
|
|
|
2017-08-14 14:08:49 +00:00
|
|
|
var (
|
|
|
|
big1 = big.NewInt(1)
|
|
|
|
big4 = big.NewInt(4)
|
|
|
|
big8 = big.NewInt(8)
|
|
|
|
big16 = big.NewInt(16)
|
|
|
|
big32 = big.NewInt(32)
|
|
|
|
big64 = big.NewInt(64)
|
|
|
|
big96 = big.NewInt(96)
|
|
|
|
big480 = big.NewInt(480)
|
|
|
|
big1024 = big.NewInt(1024)
|
|
|
|
big3072 = big.NewInt(3072)
|
|
|
|
big199680 = big.NewInt(199680)
|
|
|
|
)
|
|
|
|
|
2017-08-10 11:07:11 +00:00
|
|
|
// RequiredGas returns the gas required to execute the pre-compiled contract.
|
2017-08-10 13:39:43 +00:00
|
|
|
func (c *bigModExp) RequiredGas(input []byte) uint64 {
|
2017-08-10 11:07:11 +00:00
|
|
|
var (
|
2017-08-14 14:08:49 +00:00
|
|
|
baseLen = new(big.Int).SetBytes(getData(input, 0, 32))
|
|
|
|
expLen = new(big.Int).SetBytes(getData(input, 32, 32))
|
|
|
|
modLen = new(big.Int).SetBytes(getData(input, 64, 32))
|
2017-08-10 11:07:11 +00:00
|
|
|
)
|
2017-08-14 14:08:49 +00:00
|
|
|
if len(input) > 96 {
|
|
|
|
input = input[96:]
|
|
|
|
} else {
|
|
|
|
input = input[:0]
|
|
|
|
}
|
2017-08-10 13:39:43 +00:00
|
|
|
// Retrieve the head 32 bytes of exp for the adjusted exponent length
|
|
|
|
var expHead *big.Int
|
|
|
|
if big.NewInt(int64(len(input))).Cmp(baseLen) <= 0 {
|
|
|
|
expHead = new(big.Int)
|
|
|
|
} else {
|
2017-08-14 14:08:49 +00:00
|
|
|
if expLen.Cmp(big32) > 0 {
|
|
|
|
expHead = new(big.Int).SetBytes(getData(input, baseLen.Uint64(), 32))
|
2017-08-10 13:39:43 +00:00
|
|
|
} else {
|
2017-08-14 14:08:49 +00:00
|
|
|
expHead = new(big.Int).SetBytes(getData(input, baseLen.Uint64(), expLen.Uint64()))
|
2017-08-10 13:39:43 +00:00
|
|
|
}
|
2017-08-10 11:07:11 +00:00
|
|
|
}
|
2017-08-10 13:39:43 +00:00
|
|
|
// Calculate the adjusted exponent length
|
|
|
|
var msb int
|
|
|
|
if bitlen := expHead.BitLen(); bitlen > 0 {
|
|
|
|
msb = bitlen - 1
|
|
|
|
}
|
|
|
|
adjExpLen := new(big.Int)
|
2017-08-14 14:08:49 +00:00
|
|
|
if expLen.Cmp(big32) > 0 {
|
|
|
|
adjExpLen.Sub(expLen, big32)
|
|
|
|
adjExpLen.Mul(big8, adjExpLen)
|
2017-08-10 13:39:43 +00:00
|
|
|
}
|
|
|
|
adjExpLen.Add(adjExpLen, big.NewInt(int64(msb)))
|
|
|
|
|
|
|
|
// Calculate the gas cost of the operation
|
|
|
|
gas := new(big.Int).Set(math.BigMax(modLen, baseLen))
|
|
|
|
switch {
|
2017-08-14 14:08:49 +00:00
|
|
|
case gas.Cmp(big64) <= 0:
|
2017-08-10 13:39:43 +00:00
|
|
|
gas.Mul(gas, gas)
|
2017-08-14 14:08:49 +00:00
|
|
|
case gas.Cmp(big1024) <= 0:
|
2017-08-10 13:39:43 +00:00
|
|
|
gas = new(big.Int).Add(
|
2017-08-14 14:08:49 +00:00
|
|
|
new(big.Int).Div(new(big.Int).Mul(gas, gas), big4),
|
|
|
|
new(big.Int).Sub(new(big.Int).Mul(big96, gas), big3072),
|
2017-08-10 13:39:43 +00:00
|
|
|
)
|
|
|
|
default:
|
|
|
|
gas = new(big.Int).Add(
|
2017-08-14 14:08:49 +00:00
|
|
|
new(big.Int).Div(new(big.Int).Mul(gas, gas), big16),
|
|
|
|
new(big.Int).Sub(new(big.Int).Mul(big480, gas), big199680),
|
2017-08-10 13:39:43 +00:00
|
|
|
)
|
|
|
|
}
|
2017-08-14 14:08:49 +00:00
|
|
|
gas.Mul(gas, math.BigMax(adjExpLen, big1))
|
2017-08-10 13:39:43 +00:00
|
|
|
gas.Div(gas, new(big.Int).SetUint64(params.ModExpQuadCoeffDiv))
|
|
|
|
|
|
|
|
if gas.BitLen() > 64 {
|
|
|
|
return math.MaxUint64
|
|
|
|
}
|
|
|
|
return gas.Uint64()
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c *bigModExp) Run(input []byte) ([]byte, error) {
|
2017-08-10 11:07:11 +00:00
|
|
|
var (
|
2017-08-14 14:08:49 +00:00
|
|
|
baseLen = new(big.Int).SetBytes(getData(input, 0, 32)).Uint64()
|
|
|
|
expLen = new(big.Int).SetBytes(getData(input, 32, 32)).Uint64()
|
|
|
|
modLen = new(big.Int).SetBytes(getData(input, 64, 32)).Uint64()
|
2017-08-10 11:07:11 +00:00
|
|
|
)
|
2017-08-14 14:08:49 +00:00
|
|
|
if len(input) > 96 {
|
|
|
|
input = input[96:]
|
|
|
|
} else {
|
|
|
|
input = input[:0]
|
|
|
|
}
|
|
|
|
// Handle a special case when both the base and mod length is zero
|
|
|
|
if baseLen == 0 && modLen == 0 {
|
|
|
|
return []byte{}, nil
|
|
|
|
}
|
|
|
|
// Retrieve the operands and execute the exponentiation
|
2017-08-10 13:39:43 +00:00
|
|
|
var (
|
2017-08-14 14:08:49 +00:00
|
|
|
base = new(big.Int).SetBytes(getData(input, 0, baseLen))
|
|
|
|
exp = new(big.Int).SetBytes(getData(input, baseLen, expLen))
|
|
|
|
mod = new(big.Int).SetBytes(getData(input, baseLen+expLen, modLen))
|
2017-08-10 13:39:43 +00:00
|
|
|
)
|
|
|
|
if mod.BitLen() == 0 {
|
|
|
|
// Modulo 0 is undefined, return zero
|
|
|
|
return common.LeftPadBytes([]byte{}, int(modLen)), nil
|
2017-08-10 11:07:11 +00:00
|
|
|
}
|
2017-08-10 13:39:43 +00:00
|
|
|
return common.LeftPadBytes(base.Exp(base, exp, mod).Bytes(), int(modLen)), nil
|
2017-08-10 11:07:11 +00:00
|
|
|
}
|
|
|
|
|
2017-08-10 13:39:43 +00:00
|
|
|
// newCurvePoint unmarshals a binary blob into a bn256 elliptic curve point,
|
|
|
|
// returning it, or an error if the point is invalid.
|
|
|
|
func newCurvePoint(blob []byte) (*bn256.G1, error) {
|
2018-03-05 12:33:45 +00:00
|
|
|
p := new(bn256.G1)
|
|
|
|
if _, err := p.Unmarshal(blob); err != nil {
|
|
|
|
return nil, err
|
2017-08-10 11:07:11 +00:00
|
|
|
}
|
2017-08-10 13:39:43 +00:00
|
|
|
return p, nil
|
|
|
|
}
|
2017-08-10 11:07:11 +00:00
|
|
|
|
2017-08-10 13:39:43 +00:00
|
|
|
// newTwistPoint unmarshals a binary blob into a bn256 elliptic curve point,
|
|
|
|
// returning it, or an error if the point is invalid.
|
|
|
|
func newTwistPoint(blob []byte) (*bn256.G2, error) {
|
2018-03-05 12:33:45 +00:00
|
|
|
p := new(bn256.G2)
|
|
|
|
if _, err := p.Unmarshal(blob); err != nil {
|
|
|
|
return nil, err
|
2017-08-10 11:07:11 +00:00
|
|
|
}
|
2017-08-10 13:39:43 +00:00
|
|
|
return p, nil
|
2017-08-10 11:07:11 +00:00
|
|
|
}
|
|
|
|
|
2019-08-06 14:12:54 +00:00
|
|
|
// runBn256Add implements the Bn256Add precompile, referenced by both
|
|
|
|
// Byzantium and Istanbul operations.
|
|
|
|
func runBn256Add(input []byte) ([]byte, error) {
|
2017-08-14 14:08:49 +00:00
|
|
|
x, err := newCurvePoint(getData(input, 0, 64))
|
2017-08-10 13:39:43 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
2017-08-10 11:07:11 +00:00
|
|
|
}
|
2017-08-14 14:08:49 +00:00
|
|
|
y, err := newCurvePoint(getData(input, 64, 64))
|
2017-08-10 13:39:43 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
2017-08-10 11:07:11 +00:00
|
|
|
}
|
2017-08-17 13:46:46 +00:00
|
|
|
res := new(bn256.G1)
|
|
|
|
res.Add(x, y)
|
|
|
|
return res.Marshal(), nil
|
2017-08-10 11:07:11 +00:00
|
|
|
}
|
|
|
|
|
2019-08-06 14:12:54 +00:00
|
|
|
// bn256Add implements a native elliptic curve point addition conforming to
|
|
|
|
// Istanbul consensus rules.
|
|
|
|
type bn256AddIstanbul struct{}
|
|
|
|
|
|
|
|
// RequiredGas returns the gas required to execute the pre-compiled contract.
|
|
|
|
func (c *bn256AddIstanbul) RequiredGas(input []byte) uint64 {
|
|
|
|
return params.Bn256AddGasIstanbul
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c *bn256AddIstanbul) Run(input []byte) ([]byte, error) {
|
|
|
|
return runBn256Add(input)
|
|
|
|
}
|
|
|
|
|
|
|
|
// bn256AddByzantium implements a native elliptic curve point addition
|
|
|
|
// conforming to Byzantium consensus rules.
|
|
|
|
type bn256AddByzantium struct{}
|
2017-08-10 11:07:11 +00:00
|
|
|
|
|
|
|
// RequiredGas returns the gas required to execute the pre-compiled contract.
|
2019-08-06 14:12:54 +00:00
|
|
|
func (c *bn256AddByzantium) RequiredGas(input []byte) uint64 {
|
|
|
|
return params.Bn256AddGasByzantium
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c *bn256AddByzantium) Run(input []byte) ([]byte, error) {
|
|
|
|
return runBn256Add(input)
|
2017-08-10 11:07:11 +00:00
|
|
|
}
|
|
|
|
|
2019-08-06 14:12:54 +00:00
|
|
|
// runBn256ScalarMul implements the Bn256ScalarMul precompile, referenced by
|
|
|
|
// both Byzantium and Istanbul operations.
|
|
|
|
func runBn256ScalarMul(input []byte) ([]byte, error) {
|
2017-08-14 14:08:49 +00:00
|
|
|
p, err := newCurvePoint(getData(input, 0, 64))
|
2017-08-10 13:39:43 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
2017-08-17 13:46:46 +00:00
|
|
|
res := new(bn256.G1)
|
|
|
|
res.ScalarMult(p, new(big.Int).SetBytes(getData(input, 64, 32)))
|
|
|
|
return res.Marshal(), nil
|
2017-08-10 13:39:43 +00:00
|
|
|
}
|
2017-08-10 11:07:11 +00:00
|
|
|
|
2019-08-06 14:12:54 +00:00
|
|
|
// bn256ScalarMulIstanbul implements a native elliptic curve scalar
|
|
|
|
// multiplication conforming to Istanbul consensus rules.
|
|
|
|
type bn256ScalarMulIstanbul struct{}
|
|
|
|
|
|
|
|
// RequiredGas returns the gas required to execute the pre-compiled contract.
|
|
|
|
func (c *bn256ScalarMulIstanbul) RequiredGas(input []byte) uint64 {
|
|
|
|
return params.Bn256ScalarMulGasIstanbul
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c *bn256ScalarMulIstanbul) Run(input []byte) ([]byte, error) {
|
|
|
|
return runBn256ScalarMul(input)
|
|
|
|
}
|
|
|
|
|
|
|
|
// bn256ScalarMulByzantium implements a native elliptic curve scalar
|
|
|
|
// multiplication conforming to Byzantium consensus rules.
|
|
|
|
type bn256ScalarMulByzantium struct{}
|
|
|
|
|
|
|
|
// RequiredGas returns the gas required to execute the pre-compiled contract.
|
|
|
|
func (c *bn256ScalarMulByzantium) RequiredGas(input []byte) uint64 {
|
|
|
|
return params.Bn256ScalarMulGasByzantium
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c *bn256ScalarMulByzantium) Run(input []byte) ([]byte, error) {
|
|
|
|
return runBn256ScalarMul(input)
|
|
|
|
}
|
|
|
|
|
2017-08-10 11:07:11 +00:00
|
|
|
var (
|
2017-08-10 13:39:43 +00:00
|
|
|
// true32Byte is returned if the bn256 pairing check succeeds.
|
|
|
|
true32Byte = []byte{0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 1}
|
|
|
|
|
|
|
|
// false32Byte is returned if the bn256 pairing check fails.
|
|
|
|
false32Byte = make([]byte, 32)
|
|
|
|
|
|
|
|
// errBadPairingInput is returned if the bn256 pairing input is invalid.
|
|
|
|
errBadPairingInput = errors.New("bad elliptic curve pairing size")
|
2017-08-10 11:07:11 +00:00
|
|
|
)
|
|
|
|
|
2019-08-06 14:12:54 +00:00
|
|
|
// runBn256Pairing implements the Bn256Pairing precompile, referenced by both
|
|
|
|
// Byzantium and Istanbul operations.
|
|
|
|
func runBn256Pairing(input []byte) ([]byte, error) {
|
2017-08-10 13:39:43 +00:00
|
|
|
// Handle some corner cases cheaply
|
|
|
|
if len(input)%192 > 0 {
|
|
|
|
return nil, errBadPairingInput
|
|
|
|
}
|
|
|
|
// Convert the input into a set of coordinates
|
2017-08-10 11:07:11 +00:00
|
|
|
var (
|
2017-08-10 13:39:43 +00:00
|
|
|
cs []*bn256.G1
|
|
|
|
ts []*bn256.G2
|
2017-08-10 11:07:11 +00:00
|
|
|
)
|
2017-08-10 13:39:43 +00:00
|
|
|
for i := 0; i < len(input); i += 192 {
|
|
|
|
c, err := newCurvePoint(input[i : i+64])
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
2017-08-10 11:07:11 +00:00
|
|
|
}
|
2017-08-10 13:39:43 +00:00
|
|
|
t, err := newTwistPoint(input[i+64 : i+192])
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
2017-08-10 11:07:11 +00:00
|
|
|
}
|
2017-08-10 13:39:43 +00:00
|
|
|
cs = append(cs, c)
|
|
|
|
ts = append(ts, t)
|
2017-08-10 11:07:11 +00:00
|
|
|
}
|
2017-08-10 13:39:43 +00:00
|
|
|
// Execute the pairing checks and return the results
|
2017-08-17 13:46:46 +00:00
|
|
|
if bn256.PairingCheck(cs, ts) {
|
2017-08-10 11:07:11 +00:00
|
|
|
return true32Byte, nil
|
|
|
|
}
|
2017-08-10 13:39:43 +00:00
|
|
|
return false32Byte, nil
|
2017-08-10 11:07:11 +00:00
|
|
|
}
|
2019-08-06 14:12:54 +00:00
|
|
|
|
|
|
|
// bn256PairingIstanbul implements a pairing pre-compile for the bn256 curve
|
|
|
|
// conforming to Istanbul consensus rules.
|
|
|
|
type bn256PairingIstanbul struct{}
|
|
|
|
|
|
|
|
// RequiredGas returns the gas required to execute the pre-compiled contract.
|
|
|
|
func (c *bn256PairingIstanbul) RequiredGas(input []byte) uint64 {
|
|
|
|
return params.Bn256PairingBaseGasIstanbul + uint64(len(input)/192)*params.Bn256PairingPerPointGasIstanbul
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c *bn256PairingIstanbul) Run(input []byte) ([]byte, error) {
|
|
|
|
return runBn256Pairing(input)
|
|
|
|
}
|
|
|
|
|
|
|
|
// bn256PairingByzantium implements a pairing pre-compile for the bn256 curve
|
|
|
|
// conforming to Byzantium consensus rules.
|
|
|
|
type bn256PairingByzantium struct{}
|
|
|
|
|
|
|
|
// RequiredGas returns the gas required to execute the pre-compiled contract.
|
|
|
|
func (c *bn256PairingByzantium) RequiredGas(input []byte) uint64 {
|
|
|
|
return params.Bn256PairingBaseGasByzantium + uint64(len(input)/192)*params.Bn256PairingPerPointGasByzantium
|
|
|
|
}
|
|
|
|
|
|
|
|
func (c *bn256PairingByzantium) Run(input []byte) ([]byte, error) {
|
|
|
|
return runBn256Pairing(input)
|
|
|
|
}
|
2019-06-17 17:19:47 +00:00
|
|
|
|
|
|
|
type blake2F struct{}
|
|
|
|
|
|
|
|
func (c *blake2F) RequiredGas(input []byte) uint64 {
|
2019-08-21 09:38:18 +00:00
|
|
|
// If the input is malformed, we can't calculate the gas, return 0 and let the
|
|
|
|
// actual call choke and fault.
|
2019-06-17 17:19:47 +00:00
|
|
|
if len(input) != blake2FInputLength {
|
|
|
|
return 0
|
|
|
|
}
|
2019-08-21 09:38:18 +00:00
|
|
|
return uint64(binary.BigEndian.Uint32(input[0:4]))
|
2019-06-17 17:19:47 +00:00
|
|
|
}
|
|
|
|
|
2019-08-21 09:38:18 +00:00
|
|
|
const (
|
|
|
|
blake2FInputLength = 213
|
|
|
|
blake2FFinalBlockBytes = byte(1)
|
|
|
|
blake2FNonFinalBlockBytes = byte(0)
|
2019-06-17 17:19:47 +00:00
|
|
|
)
|
|
|
|
|
2019-08-21 09:38:18 +00:00
|
|
|
var (
|
|
|
|
errBlake2FInvalidInputLength = errors.New("invalid input length")
|
|
|
|
errBlake2FInvalidFinalFlag = errors.New("invalid final flag")
|
2019-06-17 17:19:47 +00:00
|
|
|
)
|
|
|
|
|
|
|
|
func (c *blake2F) Run(input []byte) ([]byte, error) {
|
2019-08-21 09:38:18 +00:00
|
|
|
// Make sure the input is valid (correct lenth and final flag)
|
2019-06-17 17:19:47 +00:00
|
|
|
if len(input) != blake2FInputLength {
|
2019-08-21 09:38:18 +00:00
|
|
|
return nil, errBlake2FInvalidInputLength
|
2019-06-17 17:19:47 +00:00
|
|
|
}
|
|
|
|
if input[212] != blake2FNonFinalBlockBytes && input[212] != blake2FFinalBlockBytes {
|
2019-08-21 09:38:18 +00:00
|
|
|
return nil, errBlake2FInvalidFinalFlag
|
2019-06-17 17:19:47 +00:00
|
|
|
}
|
2019-08-21 09:38:18 +00:00
|
|
|
// Parse the input into the Blake2b call parameters
|
|
|
|
var (
|
|
|
|
rounds = binary.BigEndian.Uint32(input[0:4])
|
|
|
|
final = (input[212] == blake2FFinalBlockBytes)
|
2019-06-17 17:19:47 +00:00
|
|
|
|
2019-08-21 09:38:18 +00:00
|
|
|
h [8]uint64
|
|
|
|
m [16]uint64
|
|
|
|
t [2]uint64
|
|
|
|
)
|
2019-06-17 17:19:47 +00:00
|
|
|
for i := 0; i < 8; i++ {
|
|
|
|
offset := 4 + i*8
|
|
|
|
h[i] = binary.LittleEndian.Uint64(input[offset : offset+8])
|
|
|
|
}
|
|
|
|
for i := 0; i < 16; i++ {
|
|
|
|
offset := 68 + i*8
|
|
|
|
m[i] = binary.LittleEndian.Uint64(input[offset : offset+8])
|
|
|
|
}
|
|
|
|
t[0] = binary.LittleEndian.Uint64(input[196:204])
|
|
|
|
t[1] = binary.LittleEndian.Uint64(input[204:212])
|
|
|
|
|
2019-08-21 09:38:18 +00:00
|
|
|
// Execute the compression function, extract and return the result
|
|
|
|
blake2b.F(&h, m, t, final, rounds)
|
2019-06-17 17:19:47 +00:00
|
|
|
|
2019-08-21 09:38:18 +00:00
|
|
|
output := make([]byte, 64)
|
2019-06-17 17:19:47 +00:00
|
|
|
for i := 0; i < 8; i++ {
|
|
|
|
offset := i * 8
|
|
|
|
binary.LittleEndian.PutUint64(output[offset:offset+8], h[i])
|
|
|
|
}
|
2019-08-21 09:38:18 +00:00
|
|
|
return output, nil
|
2019-06-17 17:19:47 +00:00
|
|
|
}
|