LCOV - code coverage report
Current view: top level - disco/bundle - fd_bundle_tile.c (source / functions) Hit Total Coverage
Test: cov.lcov Lines: 112 478 23.4 %
Date: 2026-09-17 04:28:31 Functions: 7 30 23.3 %

          Line data    Source code
       1             : #define _GNU_SOURCE
       2             : #include "fd_bundle_tile_private.h"
       3             : #include "fd_bundle_tile.h"
       4             : #include "../fd_txn_m.h"
       5             : #include "../metrics/fd_metrics.h"
       6             : #include "../topo/fd_topo.h"
       7             : #include "../keyguard/fd_keyload.h"
       8             : #include "../waker/fd_waker.h"
       9             : #include "../../waltz/http/fd_url.h"
      10             : #include "../../ballet/hex/fd_hex.h"
      11             : #include <errno.h>
      12             : 
      13             : #include <dirent.h> /* opendir */
      14             : #include <stdio.h> /* snprintf */
      15             : #include <fcntl.h> /* F_SETFL */
      16             : #include <unistd.h> /* close */
      17             : #include <sys/mman.h> /* PROT_READ (seccomp) */
      18             : #include <sys/uio.h> /* writev */
      19             : #include <netinet/in.h> /* AF_INET */
      20             : #include <netinet/tcp.h> /* TCP_FASTOPEN_CONNECT (seccomp) */
      21             : #include "../../waltz/resolv/fd_netdb.h"
      22             : #include "../../discof/replay/fd_replay_tile.h"
      23             : 
      24             : #include "generated/fd_bundle_tile_seccomp.h"
      25             : 
      26           6 : #define IN_KIND_REPLAY_OUT (1)
      27             : 
      28           0 : #define STEM_BURST (5UL)
      29             : FD_STATIC_ASSERT( FD_BUNDLE_CLIENT_MAX_TXN_PER_BUNDLE<=STEM_BURST, stem_burst );
      30             : 
      31             : /* hysteresis thresholds to avoid bouncing (e.g. during forks) */
      32          36 : #define FD_BUNDLE_SLEEP_THRESHOLD_SLOTS   (450UL)
      33          30 : #define FD_BUNDLE_WAKE_THRESHOLD_SLOTS    (400UL)
      34          69 : #define FD_BUNDLE_SLEEP_CHECK_INTERVAL_NS ((long)5e9)
      35             : 
      36             : FD_FN_CONST static ulong
      37           0 : scratch_align( void ) {
      38           0 :   return fd_ulong_max( fd_ulong_max( alignof(fd_bundle_tile_t), fd_grpc_client_align() ), pending_txn_align() );
      39           0 : }
      40             : 
      41             : FD_FN_CONST static ulong
      42           0 : scratch_footprint( fd_topo_tile_t const * tile ) {
      43           0 :   ulong pending_max = tile->bundle.out_depth;
      44           0 :   ulong l = FD_LAYOUT_INIT;
      45           0 :   l = FD_LAYOUT_APPEND( l, alignof(fd_bundle_tile_t), sizeof(fd_bundle_tile_t)                        );
      46           0 :   l = FD_LAYOUT_APPEND( l, fd_grpc_client_align(),    fd_grpc_client_footprint( tile->bundle.buf_sz ) );
      47           0 :   l = FD_LAYOUT_APPEND( l, pending_txn_align(),       pending_txn_footprint( pending_max )            );
      48           0 :   return FD_LAYOUT_FINI( l, scratch_align() );
      49           0 : }
      50             : 
      51             : static void
      52          81 : fd_bundle_tile_maybe_sleep( fd_bundle_tile_t * ctx, long now_ns ) {
      53          81 :   if( FD_UNLIKELY( !ctx->replay_in.mem ) ) return;
      54          69 :   if( FD_LIKELY( now_ns < ctx->sleep_check_ns ) ) return;
      55          66 :   ctx->sleep_check_ns = now_ns + FD_BUNDLE_SLEEP_CHECK_INTERVAL_NS;
      56             : 
      57          66 :   ulong next_leader_slot = ctx->next_leader_slot;
      58          66 :   ulong reset_slot       = ctx->reset_slot;
      59             : 
      60             :   /* Either don't know the leader schedule yet or have no upcoming
      61             :      leader slots.  Sleep. */
      62          66 :   if( FD_UNLIKELY( next_leader_slot==ULONG_MAX || reset_slot==ULONG_MAX ) ) {
      63          12 :     if( !ctx->sleep_mode ) {
      64           9 :       ctx->sleep_mode = 1;
      65           9 :       FD_LOG_INFO(( "Bundle tile entering sleep mode: no upcoming leader slots" ));
      66           9 :     }
      67          12 :     return;
      68          12 :   }
      69             : 
      70          54 :   ulong slots_until_leader = fd_ulong_sat_sub( next_leader_slot, reset_slot );
      71             : 
      72          54 :   if( ctx->sleep_mode ) {
      73          24 :     if( slots_until_leader <= FD_BUNDLE_WAKE_THRESHOLD_SLOTS ) {
      74          15 :       ctx->sleep_mode = 0;
      75          15 :       ctx->next_step_deadline = 0L;
      76          15 :       ctx->last_bundle_status_log_nanos = now_ns;
      77          15 :       FD_LOG_INFO(( "Bundle tile waking up: next leader slot %lu (~%lu slots away)", next_leader_slot, slots_until_leader ));
      78          15 :     }
      79          30 :   } else {
      80             :     /* reset_slot stays at/near next_leader_slot throughout a leader
      81             :        rotation and only jumps to the next rotation after leadership
      82             :        ends, so this cannot trigger mid-rotation. */
      83          30 :     if( slots_until_leader > FD_BUNDLE_SLEEP_THRESHOLD_SLOTS ) {
      84          18 :       ctx->sleep_mode = 1;
      85          18 :       FD_LOG_INFO(( "Bundle tile entering sleep mode: next leader slot %lu (~%lu slots away)", next_leader_slot, slots_until_leader ));
      86          18 :     }
      87          30 :   }
      88          54 : }
      89             : 
      90             : static inline void
      91           0 : metrics_write( fd_bundle_tile_t * ctx ) {
      92           0 :   FD_MCNT_SET( BUNDLE, TXN_RX,                 ctx->metrics.txn_received_cnt          );
      93           0 :   FD_MCNT_SET( BUNDLE, BUNDLE_RX,              ctx->metrics.bundle_received_cnt       );
      94           0 :   FD_MCNT_SET( BUNDLE, PKT_RX,                 ctx->metrics.packet_received_cnt       );
      95           0 :   FD_MCNT_SET( BUNDLE, PROTOBUF_RX_BYTES,         ctx->metrics.proto_received_bytes      );
      96           0 :   FD_MCNT_SET( BUNDLE, SHREDSTREAM_HEARTBEAT_SENT, ctx->metrics.shredstream_heartbeat_cnt );
      97           0 :   FD_MCNT_SET( BUNDLE, PING_ACKED,        ctx->metrics.ping_ack_cnt              );
      98           0 :   FD_MCNT_SET( BUNDLE, CONN_ERROR_PROTOBUF,         ctx->metrics.decode_fail_cnt           );
      99           0 :   FD_MCNT_SET( BUNDLE, CONN_ERROR_TRANSPORT,        ctx->metrics.transport_fail_cnt        );
     100           0 :   FD_MCNT_SET( BUNDLE, CONN_ERROR_NO_FEE_INFO,      ctx->metrics.missing_builder_info_fail_cnt );
     101           0 :   FD_MGAUGE_SET( BUNDLE, TXN_PENDING,          pending_txn_cnt( ctx->pending_txns )   );
     102           0 :   FD_MCNT_SET  ( BUNDLE, TXN_BUFFER_FULL,     ctx->metrics.backpressure_drop_cnt );
     103             : 
     104           0 :   FD_MGAUGE_SET( BUNDLE, RTT_SAMPLE_NANOS,   (ulong)ctx->rtt->latest_rtt   );
     105           0 :   FD_MGAUGE_SET( BUNDLE, RTT_SMOOTHED_NANOS, (ulong)ctx->rtt->smoothed_rtt );
     106           0 :   FD_MGAUGE_SET( BUNDLE, RTT_VARIANCE_NANOS, (ulong)ctx->rtt->var_rtt      );
     107             : 
     108           0 :   FD_MHIST_COPY( BUNDLE, MESSAGE_RX_DELAY_NANOS, ctx->metrics.msg_rx_delay );
     109             : 
     110           0 :   fd_wksp_t * wksp = fd_wksp_containing( ctx );
     111           0 :   fd_wksp_usage_t usage[1];
     112           0 :   ulong const free_tag = 0UL;
     113           0 :   if( FD_UNLIKELY( !fd_wksp_usage( wksp, &free_tag, 1UL, usage ) ) ) {
     114           0 :     FD_LOG_ERR(( "fd_wksp_usage failed" )); /* unreachable */
     115           0 :   }
     116           0 :   FD_MGAUGE_SET( BUNDLE, HEAP_SIZE_BYTES, usage->total_sz );
     117           0 :   FD_MGAUGE_SET( BUNDLE, HEAP_FREE_BYTES, usage->free_sz  );
     118             : 
     119           0 :   int status = fd_bundle_client_status( ctx );
     120           0 :   ulong state = (ulong)status;
     121           0 :   if( FD_UNLIKELY( ctx->sleep_mode ) ) state = FD_BUNDLE_STATE_SLEEPING;
     122             : 
     123           0 :   FD_MGAUGE_SET( BUNDLE, STATE, state );
     124           0 :   ctx->bundle_status_recent = (uchar)state;
     125           0 : }
     126             : 
     127             : void
     128           9 : fd_bundle_tile_housekeeping( fd_bundle_tile_t * ctx ) {
     129           9 :   long log_interval_ns = (long)30e9;
     130           9 :   int  status          = fd_bundle_client_status( ctx );
     131           9 :   long log_next_ns     = ctx->last_bundle_status_log_nanos + log_interval_ns;
     132           9 :   long now_ns          = fd_log_wallclock();
     133             : 
     134           9 :   if( FD_UNLIKELY( !ctx->sleep_mode && status!=FD_BUNDLE_STATE_CONNECTED && now_ns>log_next_ns ) ) {
     135           3 :     FD_LOG_WARNING(( "No bundle server connection in the last %ld seconds", log_interval_ns/(long)1e9 ) );
     136           3 :     ctx->last_bundle_status_log_nanos = now_ns;
     137           3 :   }
     138             : 
     139           9 :   if( FD_UNLIKELY( fd_keyswitch_state_query( ctx->keyswitch )==FD_KEYSWITCH_STATE_SWITCH_PENDING ) ) {
     140           3 :     if( ctx->tcp_sock>=0 ) fd_bundle_client_reset( ctx );
     141           3 :     ctx->halt_signing = 1;
     142           3 :     fd_memcpy( ctx->auther.pubkey, ctx->keyswitch->bytes, 32UL );
     143           3 :     fd_keyswitch_state( ctx->keyswitch, FD_KEYSWITCH_STATE_COMPLETED );
     144           3 :   }
     145             : 
     146           9 :   if( FD_UNLIKELY( fd_keyswitch_state_query( ctx->keyswitch )==FD_KEYSWITCH_STATE_UNHALT_PENDING ) ) {
     147           3 :     ctx->defer_reset        = 1;
     148           3 :     ctx->sleep_check_ns     = 0;
     149           3 :     ctx->halt_signing       = 0;
     150           3 :     ctx->next_step_deadline = 0L; /* the socket was closed outside a step: step now */
     151           3 :     fd_keyswitch_state( ctx->keyswitch, FD_KEYSWITCH_STATE_COMPLETED );
     152           3 :   }
     153             : 
     154           9 :   fd_bundle_tile_maybe_sleep( ctx, now_ns );
     155           9 : }
     156             : 
     157             : static void
     158             : fd_bundle_tile_publish_block_engine_update(
     159             :     fd_bundle_tile_t *  ctx,
     160             :     fd_stem_context_t * stem
     161           0 : ) {
     162           0 :   fd_bundle_block_engine_update_t * update =
     163           0 :       fd_chunk_to_laddr( ctx->plugin_out.mem, ctx->plugin_out.chunk );
     164           0 :   memset( update, 0, sizeof(fd_bundle_block_engine_update_t) );
     165             : 
     166           0 :   strncpy( update->name, "jito", sizeof(update->name) );
     167             : 
     168           0 :   FD_TEST( fd_cstr_printf_check( update->url, sizeof(update->url), NULL,
     169           0 :                                 "%s://%.*s:%u",
     170           0 :                                 ctx->is_ssl ? "https" : "http",
     171           0 :                                 (int)ctx->server_fqdn_len,
     172           0 :                                 ctx->server_fqdn,
     173           0 :                                 ctx->server_tcp_port ) );
     174             : 
     175             :   /* Format IPv4 string */
     176           0 :   snprintf( update->ip_cstr, sizeof(update->ip_cstr),
     177           0 :             FD_IP4_ADDR_FMT,
     178           0 :             FD_IP4_ADDR_FMT_ARGS( ctx->server_ip4_addr ) );
     179             : 
     180           0 :   ulong tspub = (ulong)fd_frag_meta_ts_comp( fd_bundle_now( ctx ) );
     181           0 :   fd_stem_publish(
     182           0 :       stem,
     183           0 :       ctx->plugin_out.idx,
     184           0 :       (ulong)ctx->bundle_status_recent,
     185           0 :       ctx->plugin_out.chunk,
     186           0 :       sizeof(fd_bundle_block_engine_update_t),
     187           0 :       0UL, /* ctl */
     188           0 :       0UL, /* seq */
     189           0 :       tspub
     190           0 :   );
     191           0 :   ctx->plugin_out.chunk = fd_dcache_compact_next( ctx->plugin_out.chunk, sizeof(fd_bundle_block_engine_update_t), ctx->plugin_out.chunk0, ctx->plugin_out.wmark );
     192           0 : }
     193             : 
     194             : static void
     195             : during_frag( fd_bundle_tile_t * ctx,
     196             :              ulong              in_idx,
     197             :              ulong              seq    FD_PARAM_UNUSED,
     198             :              ulong              sig,
     199             :              ulong              chunk,
     200             :              ulong              sz     FD_PARAM_UNUSED,
     201          21 :              ulong              ctl    FD_PARAM_UNUSED ) {
     202             : 
     203          21 :   if( FD_UNLIKELY( ctx->in_kind[ in_idx ]==IN_KIND_REPLAY_OUT ) ) {
     204          18 :     if( FD_LIKELY( sig!=REPLAY_SIG_RESET ) ) return;
     205          15 :     if( FD_UNLIKELY( chunk<ctx->replay_in.chunk0 || chunk>ctx->replay_in.wmark || sz!=sizeof(fd_poh_reset_t) ) )
     206           0 :       FD_LOG_ERR(( "chunk %lu %lu corrupt, not in range [%lu,%lu]", chunk, sz, ctx->replay_in.chunk0, ctx->replay_in.wmark ));
     207             : 
     208          15 :     fd_poh_reset_t const * reset = fd_chunk_to_laddr_const( ctx->replay_in.mem, chunk );
     209          15 :     ctx->next_leader_slot_staged = reset->next_leader_slot;
     210          15 :     ctx->reset_slot_staged       = reset->completed_slot;
     211          15 :   }
     212          21 : }
     213             : 
     214             : static void
     215             : after_frag( fd_bundle_tile_t *  ctx,
     216             :             ulong               in_idx,
     217             :             ulong               seq    FD_PARAM_UNUSED,
     218             :             ulong               sig,
     219             :             ulong               sz     FD_PARAM_UNUSED,
     220             :             ulong               tsorig FD_PARAM_UNUSED,
     221             :             ulong               tspub  FD_PARAM_UNUSED,
     222          21 :             fd_stem_context_t * stem   FD_PARAM_UNUSED ) {
     223             : 
     224          21 :   if( FD_UNLIKELY( ctx->in_kind[ in_idx ]==IN_KIND_REPLAY_OUT ) ) {
     225          18 :     if( FD_LIKELY( sig!=REPLAY_SIG_RESET ) ) return;
     226          15 :     ctx->next_leader_slot = ctx->next_leader_slot_staged;
     227          15 :     ctx->reset_slot       = ctx->reset_slot_staged;
     228          15 :   }
     229          21 : }
     230             : 
     231             : static void
     232             : before_credit( fd_bundle_tile_t *  ctx,
     233             :                fd_stem_context_t * stem,
     234           0 :                int *               charge_busy ) {
     235           0 :   if( FD_UNLIKELY( !ctx->stem ) ) {
     236           0 :     ctx->stem = stem;
     237           0 :   }
     238             : 
     239           0 :   if( FD_UNLIKELY( ctx->halt_signing ) ) return;
     240             : 
     241           0 :   if( FD_UNLIKELY( ctx->sleep_mode ) ) {
     242           0 :     if( ctx->tcp_sock>=0 ) {
     243           0 :       fd_bundle_client_reset( ctx );
     244             :       /* Override backoff so we don't treat this as an error */
     245           0 :       ctx->backoff_until = 0;
     246           0 :       ctx->backoff_iter  = 0;
     247           0 :     }
     248           0 :     return;
     249           0 :   }
     250             : 
     251           0 :   if( pending_txn_empty( ctx->pending_txns ) ) {
     252           0 :     int  fired = fd_fseq_query( ctx->waker_fseq )==1UL;
     253           0 :     long now   = fd_bundle_now( ctx );
     254           0 :     if( FD_UNLIKELY( fired || now>=ctx->next_step_deadline ) ) {
     255           0 :       if( FD_LIKELY( fired ) ) fd_fseq_update( ctx->waker_fseq, 0UL );
     256           0 :       int busy = 0;
     257           0 :       fd_bundle_client_step( ctx, &busy );
     258           0 :       if( FD_LIKELY( fired ) ) fd_waker_client_rearm( ctx->waker_client_idx );
     259           0 :       *charge_busy = busy;
     260             :       /* A step that made progress may have more buffered work: re-step
     261             :          immediately. */
     262           0 :       ctx->next_step_deadline = busy ? 0L : fd_bundle_client_next_deadline( ctx, fd_bundle_now( ctx ) );
     263           0 :     }
     264           0 :   }
     265           0 : }
     266             : 
     267             : static void
     268             : after_credit( fd_bundle_tile_t *  ctx,
     269             :               fd_stem_context_t * stem,
     270             :               int *               opt_poll_in,
     271           0 :               int *               charge_busy ) {
     272           0 :   if( FD_UNLIKELY( fd_clock_tile_recal_due( ctx->clock ) ) ) fd_clock_tile_recal( ctx->clock );
     273             : 
     274           0 :   if( !pending_txn_empty( ctx->pending_txns ) ) {
     275           0 :     fd_bundle_pending_txn_t * head = pending_txn_peek_head( ctx->pending_txns );
     276           0 :     ulong drain_seq = head->bundle_seq;
     277           0 :     ulong drain_sig = head->sig;
     278           0 :     ulong drain_cnt = 0UL;
     279             : 
     280           0 :     do {
     281           0 :       fd_bundle_pending_txn_t const * txn = pending_txn_peek_head( ctx->pending_txns );
     282             : 
     283           0 :       fd_txn_m_t * txnm = fd_chunk_to_laddr( ctx->verify_out.mem, ctx->verify_out.chunk );
     284           0 :       *txnm = (fd_txn_m_t) {
     285           0 :         .reference_slot = 0UL,
     286           0 :         .payload_sz     = txn->payload_sz,
     287           0 :         .txn_t_sz       = 0U,
     288           0 :         .source_ipv4    = txn->source_ipv4,
     289           0 :         .source_tpu     = FD_TXN_M_TPU_SOURCE_BUNDLE,
     290           0 :         .first_seen_nanos = txn->first_seen_nanos,
     291           0 :         .block_engine   = {
     292           0 :           .bundle_id      = txn->bundle_seq,
     293           0 :           .bundle_txn_cnt = txn->bundle_txn_cnt,
     294           0 :           .commission     = txn->commission,
     295           0 :         },
     296           0 :       };
     297           0 :       fd_memcpy( txnm->block_engine.commission_pubkey, txn->commission_pubkey, 32UL );
     298           0 :       fd_memcpy( fd_txn_m_payload( txnm ), txn->payload, txn->payload_sz );
     299             : 
     300           0 :       ulong sz    = fd_txn_m_realized_footprint( txnm, 0, 0 );
     301           0 :       ulong tspub = (ulong)fd_frag_meta_ts_comp( fd_bundle_now( ctx ) );
     302           0 :       fd_stem_publish( stem, ctx->verify_out.idx, txn->sig, ctx->verify_out.chunk, sz, 0UL, 0UL, tspub );
     303           0 :       ctx->verify_out.chunk = fd_dcache_compact_next( ctx->verify_out.chunk, sz, ctx->verify_out.chunk0, ctx->verify_out.wmark );
     304             : 
     305           0 :       pending_txn_remove_head( ctx->pending_txns );
     306           0 :       drain_cnt++;
     307           0 :     } while( fd_bundle_drain_continue( ctx->pending_txns, drain_sig, drain_seq, drain_cnt, STEM_BURST ) );
     308             : 
     309           0 :     *charge_busy = 1;
     310           0 :     *opt_poll_in = 0;
     311           0 :   }
     312             : 
     313           0 :   if( ctx->plugin_out.mem ) {
     314           0 :     if( FD_UNLIKELY( ctx->bundle_status_recent != ctx->bundle_status_plugin ) ) {
     315           0 :       fd_bundle_tile_publish_block_engine_update( ctx, stem );
     316           0 :       ctx->bundle_status_plugin = (uchar)ctx->bundle_status_recent;
     317           0 :       *charge_busy = 1;
     318           0 :     }
     319           0 :   }
     320           0 : }
     321             : 
     322             : static void
     323             : fd_bundle_tls_keylog_line( fd_bundle_tile_t * ctx,
     324             :                            char const *       label,
     325             :                            uchar const        client_random[ static 32 ],
     326             :                            uchar const *      secret,
     327          12 :                            ulong              secret_sz ) {
     328          12 :   char line[ 256 ];
     329          12 :   char * p = fd_cstr_init( line );
     330          12 :   p = fd_cstr_append_cstr( p, label );
     331          12 :   p = fd_hex_encode( p, client_random, 32UL );
     332          12 :   p = fd_cstr_append_char( p, ' ' );
     333          12 :   p = fd_hex_encode( p, secret, secret_sz );
     334          12 :   ulong line_sz = (ulong)(p-line);
     335          12 :   fd_cstr_fini( p );
     336             : 
     337          12 :   struct iovec iovs[2] = {
     338          12 :     { .iov_base=line,         .iov_len=line_sz },
     339          12 :     { .iov_base=(void *)"\n", .iov_len=1UL     },
     340          12 :   };
     341          12 :   if( FD_UNLIKELY( writev( ctx->keylog_fd, iovs, 2 )!=(long)(line_sz+1UL) ) ) {
     342           0 :     FD_LOG_WARNING(( "write(keylog) failed (%i-%s)", errno, fd_io_strerror( errno ) ));
     343           0 :   }
     344          12 : }
     345             : 
     346             : static void
     347             : fd_bundle_tls_keylog( void const * handshake,
     348             :                       void const * recv_secret,
     349             :                       void const * send_secret,
     350           6 :                       uint         encryption_level ) {
     351           6 :   fd_tlsrec_conn_t const * tls_conn = (fd_tlsrec_conn_t const *)(
     352           6 :       (ulong)handshake - offsetof(fd_tlsrec_conn_t, hs) );
     353           6 :   fd_bundle_tile_t * ctx = (fd_bundle_tile_t *)(
     354           6 :       (ulong)tls_conn - offsetof(fd_bundle_tile_t, tls_conn) );
     355           6 :   fd_tls_estate_t const * hs = handshake;
     356             : 
     357           6 :   char const * client_label;
     358           6 :   char const * server_label;
     359           6 :   switch( encryption_level ) {
     360           3 :   case FD_TLS_LEVEL_HANDSHAKE:
     361           3 :     client_label = "CLIENT_HANDSHAKE_TRAFFIC_SECRET ";
     362           3 :     server_label = "SERVER_HANDSHAKE_TRAFFIC_SECRET ";
     363           3 :     break;
     364           3 :   case FD_TLS_LEVEL_APPLICATION:
     365           3 :     client_label = "CLIENT_TRAFFIC_SECRET_0 ";
     366           3 :     server_label = "SERVER_TRAFFIC_SECRET_0 ";
     367           3 :     break;
     368           0 :   default:
     369           0 :     return;
     370           6 :   }
     371             : 
     372           6 :   uchar const * client_secret = hs->base.server ? recv_secret : send_secret;
     373           6 :   uchar const * server_secret = hs->base.server ? send_secret : recv_secret;
     374           6 :   fd_bundle_tls_keylog_line( ctx, client_label, hs->base.client_random,
     375           6 :                              client_secret, 32UL );
     376           6 :   fd_bundle_tls_keylog_line( ctx, server_label, hs->base.client_random,
     377           6 :                              server_secret, 32UL );
     378           6 : }
     379             : 
     380             : #ifndef FD_TILE_TEST
     381             : static void
     382             : fd_bundle_tile_parse_endpoint( fd_bundle_tile_t *     ctx,
     383           0 :                                fd_topo_tile_t const * tile ) {
     384           0 :   fd_url_t url[1];
     385           0 :   _Bool is_ssl = 0;
     386           0 :   if( FD_UNLIKELY( fd_url_parse_endpoint( url,
     387           0 :                                           tile->bundle.url,
     388           0 :                                           tile->bundle.url_len,
     389           0 :                                           &ctx->server_tcp_port,
     390           0 :                                           &is_ssl,
     391           0 :                                           "[tiles.bundle.url]" ) ) ) {
     392           0 :     FD_LOG_ERR(( "Could not parse [tiles.bundle.url]" ));
     393           0 :   }
     394           0 :   if( FD_UNLIKELY( url->host_len>=FD_FQDN_BUF_MAX ) ) {
     395           0 :     FD_LOG_CRIT(( "Invalid url->host_len" )); /* unreachable */
     396           0 :   }
     397           0 :   fd_cstr_fini( fd_cstr_append_text( fd_cstr_init( ctx->server_fqdn ), url->host, url->host_len ) );
     398           0 :   ctx->server_fqdn_len = url->host_len;
     399             : 
     400           0 :   if( FD_UNLIKELY( tile->bundle.sni_len ) ) {
     401           0 :     fd_cstr_fini( fd_cstr_append_text( fd_cstr_init( ctx->server_sni ), tile->bundle.sni, tile->bundle.sni_len ) );
     402           0 :     ctx->server_sni_len = tile->bundle.sni_len;
     403           0 :   } else {
     404           0 :     fd_cstr_fini( fd_cstr_append_text( fd_cstr_init( ctx->server_sni ), url->host, url->host_len ) );
     405           0 :     ctx->server_sni_len = url->host_len;
     406           0 :   }
     407             : 
     408           0 :   if( FD_UNLIKELY( ctx->server_sni_len>=sizeof(ctx->tls->server_name) ) ) {
     409           0 :     FD_LOG_ERR(( "Server name is %lu bytes, longer than the %lu byte maximum: "
     410           0 :                  "check [tiles.bundle.url] and [tiles.bundle.tls_domain_name]",
     411           0 :                  ctx->server_sni_len, sizeof(ctx->tls->server_name)-1UL ));
     412           0 :   }
     413             : 
     414           0 :   ctx->is_ssl = !!is_ssl;
     415           0 : }
     416             : 
     417             : 
     418             : static void
     419             : fd_bundle_tile_init_tls( fd_bundle_tile_t *     ctx,
     420           0 :                          fd_topo_tile_t const * tile ) {
     421             :   /* Initialize native TLS */
     422           0 :   fd_tls_t * tls = fd_tls_join( fd_tls_new( ctx->tls ) );
     423             : 
     424           0 :   uchar rng_key[ FD_CHACHA_KEY_SZ ];
     425           0 :   if( FD_UNLIKELY( !fd_rng_secure( rng_key, sizeof(rng_key) ) ) ) FD_LOG_CRIT(( "fd_rng_secure failed" ));
     426           0 :   fd_chacha_rng_init( ctx->tls_rng, rng_key, FD_CHACHA_RNG_ALGO_CHACHA8 );
     427           0 :   fd_memzero_explicit( rng_key, sizeof(rng_key) );
     428           0 :   tls->rng = ctx->tls_rng;
     429           0 :   if( FD_LIKELY( ctx->keylog_fd>=0 ) ) tls->secrets_fn = fd_bundle_tls_keylog;
     430             : 
     431             :   /* ALPN: h2 */
     432           0 :   static uchar const alpn[] = { 2, 'h', '2' };
     433           0 :   fd_memcpy( tls->alpn, alpn, sizeof(alpn) );
     434           0 :   tls->alpn_sz = sizeof(alpn);
     435             : 
     436           0 :   if( FD_UNLIKELY( !ctx->is_ssl ) ) return; /* plaintext, nothing to verify */
     437             : 
     438           0 :   if( FD_UNLIKELY( !tile->bundle.tls_cert_verify ) ) {
     439           0 :     FD_LOG_WARNING(( "[tiles.bundle.tls_cert_verify] is disabled.  The block engine "
     440           0 :                      "certificate will not be verified.  This is insecure." ));
     441           0 :     return;
     442           0 :   }
     443             : 
     444             :   /* Load system CA certificates */
     445           0 :   if( FD_UNLIKELY( fd_x509_ca_store_load_system( ctx->ca_store )<0L ) ) {
     446           0 :     FD_LOG_ERR(( "No CA certificate bundle found, cannot verify the block engine "
     447           0 :                  "certificate.  Install the system CA certificates, or set "
     448           0 :                  "`[tiles.bundle] tls_cert_verify = false` to disable verification "
     449           0 :                  "(insecure)." ));
     450           0 :   }
     451             : 
     452           0 :   tls->ca_store = ctx->ca_store;
     453           0 : }
     454             : 
     455             : static void
     456             : privileged_init( fd_topo_t const *      topo,
     457           0 :                  fd_topo_tile_t const * tile ) {
     458           0 :   void * scratch = fd_topo_obj_laddr( topo, tile->tile_obj_id );
     459             : 
     460           0 :   ulong const pending_max = tile->bundle.out_depth;
     461             : 
     462           0 :   FD_SCRATCH_ALLOC_INIT( l, scratch );
     463           0 :   fd_bundle_tile_t * ctx         = FD_SCRATCH_ALLOC_APPEND( l, alignof(fd_bundle_tile_t), sizeof(fd_bundle_tile_t)                        );
     464           0 :   void *             grpc_mem    = FD_SCRATCH_ALLOC_APPEND( l, fd_grpc_client_align(),    fd_grpc_client_footprint( tile->bundle.buf_sz ) );
     465           0 :   void *             deque_mem   = FD_SCRATCH_ALLOC_APPEND( l, pending_txn_align(),        pending_txn_footprint( pending_max )            );
     466             : 
     467           0 :   ulong scratch_top = FD_SCRATCH_ALLOC_FINI( l, scratch_align() );
     468           0 :   if( FD_UNLIKELY( scratch_top > (ulong)scratch + scratch_footprint( tile ) ) )
     469           0 :     FD_LOG_ERR(( "scratch overflow %lu %lu %lu", scratch_top - (ulong)scratch - scratch_footprint( tile ), scratch_top, (ulong)scratch + scratch_footprint( tile ) ));
     470             : 
     471           0 :   memset( ctx, 0, sizeof(fd_bundle_tile_t) );
     472           0 :   ctx->grpc_client_mem  = grpc_mem;
     473           0 :   ctx->grpc_buf_max     = tile->bundle.buf_sz;
     474           0 :   ctx->tcp_sock         = -1;
     475           0 :   ctx->waker_client_idx = tile->waker_client_idx;
     476           0 :   ctx->pending_txns     = pending_txn_join( pending_txn_new( deque_mem, pending_max ) );
     477             : 
     478           0 :   fd_bundle_auther_init( &ctx->auther );
     479           0 :   uchar const * public_key = fd_keyload_load( tile->bundle.identity_key_path, 1 /* public key only */ );
     480           0 :   fd_memcpy( ctx->auther.pubkey, public_key, 32UL );
     481             : 
     482           0 :   ctx->keylog_fd = -1;
     483             : 
     484           0 :   if( FD_UNLIKELY( tile->bundle.key_log_path[0] ) ) {
     485           0 :     ctx->keylog_fd = open( tile->bundle.key_log_path, O_WRONLY|O_APPEND|O_CREAT, 0644 );
     486           0 :     if( FD_UNLIKELY( ctx->keylog_fd < 0 ) ) {
     487           0 :       FD_LOG_ERR(( "open(%s) failed (%i-%s)", tile->bundle.key_log_path, errno, fd_io_strerror( errno ) ));
     488           0 :     }
     489           0 :   }
     490             : 
     491           0 :   fd_bundle_tile_parse_endpoint( ctx, tile );
     492             : 
     493             :   /* Initialize native TLS before seccomp (reads CA certs from disk) */
     494           0 :   fd_bundle_tile_init_tls( ctx, tile );
     495             : 
     496             :   /* Init resolver */
     497           0 :   if( FD_UNLIKELY( !fd_netdb_open_fds( ctx->netdb_fds ) ) ) {
     498           0 :     FD_LOG_ERR(( "fd_netdb_open_fds failed" ));
     499           0 :   }
     500             : 
     501             :   /* Random seed for header hashmap */
     502           0 :   if( FD_UNLIKELY( !fd_rng_secure( &ctx->map_seed, sizeof(ulong) ) ) ) {
     503           0 :     FD_LOG_CRIT(( "fd_rng_secure failed" ));
     504           0 :   }
     505             : 
     506             :   /* Random seed for timing RNG */
     507           0 :   uint rng_seed;
     508           0 :   if( FD_UNLIKELY( !fd_rng_secure( &rng_seed, sizeof(uint) ) ) ) {
     509           0 :     FD_LOG_CRIT(( "fd_rng_secure failed" ));
     510           0 :   }
     511           0 :   if( FD_UNLIKELY( !fd_rng_join( fd_rng_new( &ctx->rng, rng_seed, 0UL ) ) ) ) {
     512           0 :     FD_LOG_CRIT(( "fd_rng_join failed" )); /* unreachable */
     513           0 :   }
     514           0 : }
     515             : 
     516             : static fd_bundle_out_ctx_t
     517             : bundle_out_link( fd_topo_t const *      topo,
     518             :                  fd_topo_link_t const * link,
     519           0 :                  ulong                  out_link_idx ) {
     520           0 :   fd_bundle_out_ctx_t out = {0};
     521           0 :   out.idx    = out_link_idx;
     522           0 :   out.mem    = topo->workspaces[ topo->objs[ link->dcache_obj_id ].wksp_id ].wksp;
     523           0 :   out.chunk0 = fd_dcache_compact_chunk0( out.mem, link->dcache );
     524           0 :   out.wmark  = fd_dcache_compact_wmark ( out.mem, link->dcache, link->mtu );
     525           0 :   out.chunk  = out.chunk0;
     526           0 :   return out;
     527           0 : }
     528             : 
     529             : static void
     530             : unprivileged_init( fd_topo_t const *      topo,
     531           0 :                    fd_topo_tile_t const * tile ) {
     532           0 :   fd_bundle_tile_t * ctx = fd_topo_obj_laddr( topo, tile->tile_obj_id );
     533           0 :   if( FD_UNLIKELY( tile->kind_id!=0 ) ) {
     534           0 :     FD_LOG_ERR(( "There can only be one bundle tile" ));
     535           0 :   }
     536             : 
     537           0 :   fd_clock_tile_init( ctx->clock );
     538             : 
     539           0 :   ulong sign_in_idx = fd_topo_find_tile_in_link( topo, tile, "sign_bundle", tile->kind_id );
     540           0 :   if( FD_UNLIKELY( sign_in_idx==ULONG_MAX ) ) FD_LOG_ERR(( "Missing sign_bundle link" ));
     541           0 :   fd_topo_link_t const * sign_in  = &topo->links[ tile->in_link_id[ sign_in_idx ] ];
     542             : 
     543           0 :   ulong sign_out_idx = fd_topo_find_tile_out_link( topo, tile, "bundle_sign", tile->kind_id );
     544           0 :   if( FD_UNLIKELY( sign_out_idx==ULONG_MAX ) ) FD_LOG_ERR(( "Missing bundle_sign link" ));
     545           0 :   fd_topo_link_t const * sign_out = &topo->links[ tile->out_link_id[ sign_out_idx ] ];
     546             : 
     547           0 :   if( FD_UNLIKELY( !fd_keyguard_client_join( fd_keyguard_client_new(
     548           0 :       ctx->keyguard_client,
     549           0 :       sign_out->mcache,
     550           0 :       sign_out->dcache,
     551           0 :       sign_in->mcache,
     552           0 :       sign_in->dcache,
     553           0 :       sign_out->mtu,
     554           0 :       sign_in->mtu
     555           0 :   ) ) ) ) {
     556           0 :     FD_LOG_ERR(( "fd_keyguard_client_join failed" )); /* unreachable */
     557           0 :   }
     558             : 
     559           0 :   ctx->keyswitch = fd_keyswitch_join( fd_topo_obj_laddr( topo, tile->id_keyswitch_obj_id ) );
     560           0 :   FD_TEST( ctx->keyswitch );
     561             : 
     562           0 :   FD_TEST( ctx->waker_client_idx!=ULONG_MAX );
     563           0 :   ctx->waker_fseq = fd_fseq_join( fd_topo_obj_laddr( topo, tile->waker_fseq_obj_id ) );
     564           0 :   FD_TEST( ctx->waker_fseq );
     565             : 
     566           0 :   ulong verify_out_idx = fd_topo_find_tile_out_link( topo, tile, "bundle_verif", tile->kind_id );
     567           0 :   if( FD_UNLIKELY( verify_out_idx==ULONG_MAX ) ) FD_LOG_ERR(( "Missing bundle_verif link" ));
     568           0 :   ctx->verify_out = bundle_out_link( topo, &topo->links[ tile->out_link_id[ verify_out_idx ] ], verify_out_idx );
     569             : 
     570           0 :   ulong plugin_out_idx = fd_topo_find_tile_out_link( topo, tile, "bundle_status", tile->kind_id );
     571           0 :   if( plugin_out_idx!=ULONG_MAX ) {
     572           0 :     ctx->plugin_out = bundle_out_link( topo, &topo->links[ tile->out_link_id[ plugin_out_idx ] ], plugin_out_idx );
     573           0 :   } else {
     574           0 :     ctx->plugin_out = (fd_bundle_out_ctx_t){ .idx=ULONG_MAX };
     575           0 :   }
     576             : 
     577             :   /* Set socket receive buffer size */
     578           0 :   ulong so_rcvbuf = tile->bundle.buf_sz;
     579           0 :   if( FD_UNLIKELY( so_rcvbuf < 2048UL  ) ) FD_LOG_ERR(( "Invalid [development.bundle.buffer_size_kib]: too small" ));
     580           0 :   if( FD_UNLIKELY( so_rcvbuf > INT_MAX ) ) FD_LOG_ERR(( "Invalid [development.bundle.buffer_size_kib]: too large" ));
     581           0 :   ctx->so_rcvbuf = (int)so_rcvbuf;
     582             : 
     583             :   /* Set idle ping timer */
     584           0 :   ctx->keepalive_interval = (long)tile->bundle.keepalive_interval_nanos;
     585             : 
     586           0 :   ctx->bundle_status_plugin = 127;
     587           0 :   ctx->bundle_status_recent = (uchar)FD_BUNDLE_STATE_DISCONNECTED;
     588           0 :   ctx->last_bundle_status_log_nanos = fd_log_wallclock();
     589             : 
     590           0 :   FD_TEST( tile->in_cnt<=sizeof(ctx->in_kind)/sizeof(ctx->in_kind[0]) );
     591           0 :   int has_replay_in = 0;
     592           0 :   ulong polled_in_idx = 0UL;
     593           0 :   for( ulong i=0UL; i<tile->in_cnt; i++ ) {
     594           0 :     if( FD_UNLIKELY( !tile->in_link_poll[ i ] ) ) continue;
     595             : 
     596           0 :     fd_topo_link_t const * link = &topo->links[ tile->in_link_id[ i ] ];
     597           0 :     if( !strcmp( link->name, "replay_out" ) ) {
     598           0 :       ctx->in_kind[ polled_in_idx ] = IN_KIND_REPLAY_OUT;
     599           0 :       fd_topo_wksp_t const * link_wksp = &topo->workspaces[ topo->objs[ link->dcache_obj_id ].wksp_id ];
     600           0 :       ctx->replay_in.mem    = link_wksp->wksp;
     601           0 :       ctx->replay_in.chunk0 = fd_dcache_compact_chunk0( ctx->replay_in.mem, link->dcache );
     602           0 :       ctx->replay_in.wmark  = fd_dcache_compact_wmark ( ctx->replay_in.mem, link->dcache, link->mtu );
     603           0 :       has_replay_in = 1;
     604           0 :     }
     605           0 :     polled_in_idx++;
     606           0 :   }
     607             : 
     608           0 :   ctx->next_leader_slot = ULONG_MAX;
     609           0 :   ctx->reset_slot       = ULONG_MAX;
     610           0 :   ctx->sleep_mode       = has_replay_in; /* start asleep until we learn leader schedule */
     611           0 :   ctx->sleep_check_ns   = 0;
     612           0 :   ctx->halt_signing     = 0;
     613           0 :   if( !has_replay_in ) memset( &ctx->replay_in, 0, sizeof(ctx->replay_in) );
     614             : 
     615           0 :   ctx->grpc_client = fd_grpc_client_new( ctx->grpc_client_mem, &fd_bundle_client_grpc_callbacks, ctx->grpc_metrics, ctx, ctx->grpc_buf_max, ctx->map_seed );
     616           0 :   if( FD_UNLIKELY( !ctx->grpc_client ) ) {
     617           0 :     FD_LOG_CRIT(( "fd_grpc_client_new failed" )); /* unreachable */
     618           0 :   }
     619           0 :   fd_grpc_client_set_version( ctx->grpc_client, fd_version_cstr, strlen( fd_version_cstr ) );
     620           0 :   fd_grpc_client_set_authority( ctx->grpc_client, ctx->server_sni, ctx->server_sni_len, ctx->server_tcp_port );
     621             : 
     622           0 :   fd_histf_new( ctx->metrics.msg_rx_delay,
     623           0 :       FD_MHIST_MIN( BUNDLE, MESSAGE_RX_DELAY_NANOS ),
     624           0 :       FD_MHIST_MAX( BUNDLE, MESSAGE_RX_DELAY_NANOS ) );
     625           0 : }
     626             : 
     627             : static ulong
     628             : populate_allowed_seccomp( fd_topo_t const *      topo,
     629             :                           fd_topo_tile_t const * tile,
     630             :                           ulong                  out_cnt,
     631           0 :                           struct sock_filter *   out ) {
     632           0 :   fd_bundle_tile_t * ctx = fd_topo_obj_laddr( topo, tile->tile_obj_id );
     633             : 
     634           0 :   uint epoll_inner_fd = (uint)FD_WAKER_INNER_FD( tile->waker_client_idx );
     635           0 :   uint epoll_outer_fd = (uint)FD_WAKER_OUTER_FD;
     636             : 
     637           0 :   populate_sock_filter_policy_fd_bundle_tile(
     638           0 :       out_cnt, out,
     639           0 :       (uint)fd_log_private_logfile_fd(),
     640           0 :       (uint)ctx->keylog_fd,
     641           0 :       (uint)ctx->netdb_fds->etc_hosts,
     642           0 :       (uint)ctx->netdb_fds->etc_resolv_conf,
     643           0 :       epoll_inner_fd,
     644           0 :       epoll_outer_fd
     645           0 :   );
     646           0 :   return sock_filter_policy_fd_bundle_tile_instr_cnt;
     647           0 : }
     648             : 
     649             : static ulong
     650             : populate_allowed_fds( fd_topo_t const *      topo,
     651             :                       fd_topo_tile_t const * tile,
     652             :                       ulong                  out_fds_cnt,
     653           0 :                       int *                  out_fds ) {
     654           0 :   fd_bundle_tile_t * ctx = fd_topo_obj_laddr( topo, tile->tile_obj_id );
     655             : 
     656           0 :   if( FD_UNLIKELY( out_fds_cnt<7UL ) ) FD_LOG_ERR(( "out_fds_cnt %lu", out_fds_cnt ));
     657             : 
     658           0 :   ulong out_cnt = 0UL;
     659           0 :   out_fds[ out_cnt++ ] = 2; /* stderr */
     660           0 :   if( FD_LIKELY( -1!=fd_log_private_logfile_fd() ) )
     661           0 :     out_fds[ out_cnt++ ] = fd_log_private_logfile_fd(); /* logfile */
     662           0 :   if( FD_LIKELY( ctx->netdb_fds->etc_hosts >= 0 ) )
     663           0 :     out_fds[ out_cnt++ ] = ctx->netdb_fds->etc_hosts;
     664           0 :   out_fds[ out_cnt++ ] = ctx->netdb_fds->etc_resolv_conf;
     665           0 :   if( FD_UNLIKELY( ctx->keylog_fd>=0 ) )
     666           0 :     out_fds[ out_cnt++ ] = ctx->keylog_fd;
     667           0 :   out_fds[ out_cnt++ ] = FD_WAKER_OUTER_FD;
     668           0 :   out_fds[ out_cnt++ ] = FD_WAKER_INNER_FD( tile->waker_client_idx );
     669           0 :   return out_cnt;
     670           0 : }
     671             : 
     672           0 : #define STEM_LAZY ((long)10e6)
     673             : 
     674           0 : #define STEM_CALLBACK_CONTEXT_TYPE  fd_bundle_tile_t
     675           0 : #define STEM_CALLBACK_CONTEXT_ALIGN alignof(fd_bundle_tile_t)
     676             : 
     677           0 : #define STEM_CALLBACK_DURING_HOUSEKEEPING fd_bundle_tile_housekeeping
     678           0 : #define STEM_CALLBACK_METRICS_WRITE       metrics_write
     679           0 : #define STEM_CALLBACK_DURING_FRAG         during_frag
     680           0 : #define STEM_CALLBACK_AFTER_FRAG          after_frag
     681           0 : #define STEM_CALLBACK_BEFORE_CREDIT       before_credit
     682           0 : #define STEM_CALLBACK_AFTER_CREDIT        after_credit
     683             : 
     684             : #include "../stem/fd_stem.c"
     685             : 
     686             : fd_topo_run_tile_t fd_tile_bundle = {
     687             :   .name                     = "bundle",
     688             :   .populate_allowed_seccomp = populate_allowed_seccomp,
     689             :   .populate_allowed_fds     = populate_allowed_fds,
     690             :   .scratch_align            = scratch_align,
     691             :   .scratch_footprint        = scratch_footprint,
     692             :   .privileged_init          = privileged_init,
     693             :   .unprivileged_init        = unprivileged_init,
     694             :   .run                      = stem_run,
     695             :   .rlimit_file_cnt          = 64,
     696             :   .keep_host_networking     = 1,
     697             :   .allow_connect            = 1
     698             : };
     699             : #endif

Generated by: LCOV version 1.14