Line data Source code
1 : #define _GNU_SOURCE
2 : #include "fd_circq.h"
3 : #include "fd_event_client.h"
4 : #include "fd_boot_report.h"
5 :
6 : #include "../fd_txn_m.h"
7 : #include "../fd_clock_tile.h"
8 : #include "../metrics/fd_metrics.h"
9 : #include "../net/fd_net_tile.h"
10 : #include "../../discof/genesis/fd_genesi_tile.h"
11 : #include "generated/fd_event_gen.h"
12 : #include "../keyguard/fd_keyload.h"
13 : #include "../keyguard/fd_keyswitch.h"
14 : #include "../topo/fd_topo.h"
15 : #include "../waker/fd_waker.h"
16 : #include "../../waltz/resolv/fd_netdb.h"
17 : #include "../../waltz/http/fd_url.h"
18 : #include "../../ballet/pb/fd_pb_encode.h"
19 :
20 : #include "../../ballet/x509/fd_x509_ca_store.h"
21 :
22 : #include <unistd.h>
23 : #include <fcntl.h>
24 : #include <errno.h>
25 : #include <unistd.h>
26 : #include <sys/socket.h>
27 : #include <sys/syscall.h>
28 : #include <netinet/in.h>
29 : #include <netinet/tcp.h>
30 :
31 : #include "generated/fd_event_tile_seccomp.h"
32 :
33 0 : #define GRPC_BUF_MAX (12UL<<20UL) /* 12 MiB */
34 :
35 : /* An encoded event larger than the send buffer is rejected at transmit
36 : and skipped for good, so the worst case of the largest event has to fit
37 : with room for the gRPC framing: the 5-byte gRPC length prefix plus a
38 : 9-byte HTTP/2 DATA frame header per 16 KiB frame. */
39 : FD_STATIC_ASSERT( FD_EVENT_BLOCK_COMPLETED_BUF_MAX+5UL+9UL*( (FD_EVENT_BLOCK_COMPLETED_BUF_MAX+5UL+16383UL)/16384UL )<=GRPC_BUF_MAX, event_fits_grpc_tx_buf );
40 : FD_STATIC_ASSERT( FD_EVENT_BOOT_BUF_MAX+5UL+9UL*( (FD_EVENT_BOOT_BUF_MAX+5UL+16383UL)/16384UL )<=GRPC_BUF_MAX, boot_event_fits_grpc_tx_buf );
41 :
42 : /* Sized so the event workspace (circq + ~144 MiB client/ctx) fits in one
43 : gigantic page. */
44 0 : #define EVENT_CIRCQ_SZ ((1UL<<30UL)-(160UL<<20UL))
45 :
46 : /* The worst-case size of a Txn event:
47 : - Fixed overhead:
48 : - nonce 15
49 : - event_id 15
50 : - link_seq 15
51 : - timestamp 15
52 : - Event protobuf submessage opener 10
53 : - Txn protobuf submessage opener 10
54 : - source_ip 14
55 : - source_port 10
56 : - protocol 10
57 : - bundle_id 15
58 : - bundle_txn_count 10
59 : - bundle_commission 10
60 : - bundle_commission_pubkey 42
61 : - payload tag 5
62 : - payload length prefix 5
63 : - PB_ENCODER_SLACK 32
64 : Total: 233
65 :
66 : So the worst-case size is 233 + FD_TPU_MTU.
67 :
68 : TODO: this needs to be auto-generated as this is fragile,
69 : have the schema generator spit out max sizes for messages. */
70 0 : #define EVENT_TXN_BUF_MAX (FD_TPU_MTU+233UL)
71 :
72 0 : #define IN_KIND_SHRED (0)
73 0 : #define IN_KIND_DEDUP (1)
74 : #define IN_KIND_SIGN (2)
75 0 : #define IN_KIND_GENESI (3)
76 0 : #define IN_KIND_IPECHO (4)
77 0 : #define IN_KIND_EVENT (5)
78 :
79 : union fd_event_tile_in {
80 : struct {
81 : fd_wksp_t * mem;
82 : ulong mtu;
83 : ulong chunk0;
84 : ulong wmark;
85 : };
86 : fd_net_rx_bounds_t net_rx;
87 : };
88 :
89 : typedef union fd_event_tile_in fd_event_tile_in_t;
90 :
91 : struct fd_event_tile {
92 : fd_circq_t * circq;
93 : fd_event_client_t * client;
94 :
95 : fd_topo_t const * topo;
96 :
97 : int tile_shutdown_rendered[ FD_TOPO_MAX_TILES ];
98 :
99 : fd_keyswitch_t * keyswitch;
100 :
101 : ulong idle_cnt;
102 :
103 : ulong waker_client_idx;
104 : ulong * waker_fseq;
105 : long next_poll_deadline;
106 :
107 : ulong boot_id;
108 : ulong machine_id;
109 : ulong instance_id;
110 : ulong seed;
111 :
112 : ulong chunk;
113 :
114 : ushort shred_source_port;
115 : ulong shred_buf_sz;
116 : uchar shred_buf[ FD_NET_MTU ];
117 :
118 : ulong event_type;
119 : ulong event_sz;
120 : uchar event_buf[ FD_EVENT_GEN_STRUCT_MAX ] __attribute__((aligned(FD_EVENT_GEN_STRUCT_ALIGN)));
121 :
122 : uchar identity_pubkey[ 32UL ];
123 :
124 : int use_tls;
125 :
126 : /* CA trust store, loaded in privileged_init and referenced by the
127 : event client for certificate chain verification. */
128 : fd_x509_ca_store_t ca_store[1];
129 :
130 : fd_keyguard_client_t keyguard_client[1];
131 : fd_rng_t rng[1];
132 :
133 : fd_netdb_fds_t netdb_fds[1];
134 :
135 : fd_clock_tile_t clock[1];
136 :
137 : fd_boot_report_t boot_report[1];
138 :
139 : ulong in_cnt;
140 : int in_kind[ 64UL ];
141 : fd_event_tile_in_t in[ 64UL ];
142 : };
143 :
144 : typedef struct fd_event_tile fd_event_tile_t;
145 :
146 : FD_FN_CONST static inline ulong
147 0 : scratch_align( void ) {
148 0 : ulong a = alignof( fd_event_tile_t );
149 0 : a = fd_ulong_max( a, fd_event_client_align() );
150 0 : a = fd_ulong_max( a, fd_circq_align() );
151 0 : return a;
152 0 : }
153 :
154 : FD_FN_PURE static inline ulong
155 0 : scratch_footprint( fd_topo_tile_t const * tile ) {
156 0 : (void)tile;
157 :
158 0 : ulong l = FD_LAYOUT_INIT;
159 0 : l = FD_LAYOUT_APPEND( l, alignof(fd_event_tile_t), sizeof(fd_event_tile_t) );
160 0 : l = FD_LAYOUT_APPEND( l, fd_event_client_align(), fd_event_client_footprint( GRPC_BUF_MAX ) );
161 0 : l = FD_LAYOUT_APPEND( l, fd_circq_align(), fd_circq_footprint( EVENT_CIRCQ_SZ ) );
162 0 : return FD_LAYOUT_FINI( l, scratch_align() );
163 0 : }
164 :
165 : static inline void
166 0 : metrics_write( fd_event_tile_t * ctx ) {
167 0 : FD_MGAUGE_SET( EVENT, QUEUE_DEPTH, ctx->circq->cnt );
168 0 : FD_MGAUGE_SET( EVENT, QUEUE_UNSENT, fd_circq_unsent_cnt( ctx->circq ) );
169 0 : FD_MCNT_SET( EVENT, QUEUE_DROPPED, ctx->circq->metrics.drop_cnt );
170 0 : FD_MGAUGE_SET( EVENT, QUEUE_BYTES_USED, fd_circq_bytes_used( ctx->circq ) );
171 0 : FD_MGAUGE_SET( EVENT, QUEUE_BYTES_CAPACITY, ctx->circq->size );
172 :
173 0 : fd_event_client_metrics_t const * metrics = fd_event_client_metrics( ctx->client );
174 0 : FD_MCNT_SET( EVENT, SENT, metrics->events_sent );
175 0 : FD_MCNT_SET( EVENT, ACKED, metrics->events_acked );
176 0 : FD_MGAUGE_SET( EVENT, LAST_ACKED_ID, metrics->last_acked_id );
177 0 : FD_MCNT_SET( EVENT, BYTES_WRITTEN, metrics->bytes_written );
178 0 : FD_MCNT_SET( EVENT, BYTES_READ, metrics->bytes_read );
179 0 : FD_MCNT_SET( EVENT, AUTH_FAILED, metrics->auth_fail_cnt );
180 0 : FD_MCNT_SET( EVENT, INVALID_MESSAGE, metrics->invalid_msg_cnt );
181 0 : FD_MCNT_SET( EVENT, CONN_ATTEMPT, metrics->connect_attempt_cnt );
182 0 : FD_MCNT_SET( EVENT, HANDSHAKE_TIMEOUT, metrics->handshake_timeout_cnt );
183 0 : FD_MCNT_SET( EVENT, CREDIT_STALL, metrics->credit_stall_cnt );
184 :
185 0 : FD_MGAUGE_SET( EVENT, CONN_STATE, fd_event_client_state( ctx->client ) );
186 0 : }
187 :
188 : static void
189 : before_credit( fd_event_tile_t * ctx,
190 : fd_stem_context_t * stem,
191 0 : int * charge_busy ) {
192 0 : (void)stem;
193 :
194 0 : ctx->idle_cnt++;
195 0 : if( FD_LIKELY( ctx->idle_cnt<2UL*ctx->in_cnt ) ) return;
196 0 : ctx->idle_cnt = 0UL;
197 :
198 0 : int fired = fd_fseq_query( ctx->waker_fseq )==1UL;
199 0 : long now = fd_clock_tile_now( ctx->clock );
200 0 : if( FD_UNLIKELY( fired | ( now>=ctx->next_poll_deadline ) ) ) {
201 0 : if( FD_LIKELY( fired ) ) fd_fseq_update( ctx->waker_fseq, 0UL );
202 0 : int busy = 0;
203 0 : fd_event_client_poll( ctx->client, now, &busy );
204 0 : if( FD_LIKELY( fired ) ) fd_waker_client_rearm( ctx->waker_client_idx );
205 0 : *charge_busy = busy;
206 0 : ctx->next_poll_deadline = busy ? 0L : fd_event_client_next_deadline( ctx->client, now );
207 0 : }
208 0 : }
209 :
210 : static void
211 : during_frag( fd_event_tile_t * ctx,
212 : ulong in_idx,
213 : ulong seq,
214 : ulong sig,
215 : ulong chunk,
216 : ulong sz,
217 0 : ulong ctl ) {
218 0 : (void)seq; (void)ctl;
219 :
220 0 : fd_event_tile_in_t const * in = &ctx->in[ in_idx ];
221 0 : switch( ctx->in_kind[ in_idx ] ) {
222 0 : case IN_KIND_SHRED: {
223 0 : uchar const * dcache_entry = fd_net_rx_translate_frag( &ctx->in[ in_idx ].net_rx, chunk, ctl, sz );
224 0 : ulong hdr_sz = fd_disco_netmux_sig_hdr_sz( sig );
225 0 : FD_TEST( hdr_sz <= sz ); /* Should be ensured by the net tile */
226 0 : fd_udp_hdr_t const * udp_hdr = (fd_udp_hdr_t const *)( dcache_entry + hdr_sz - sizeof(fd_udp_hdr_t) );
227 0 : ctx->shred_source_port = fd_ushort_bswap( udp_hdr->net_sport );
228 : // TODO: SHOULD BE RELIABLE. MAKE XDP TILE RELIABLE FIRST.
229 0 : fd_memcpy( ctx->shred_buf, dcache_entry+hdr_sz, sz-hdr_sz );
230 0 : ctx->shred_buf_sz = sz-hdr_sz;
231 0 : break;
232 0 : }
233 0 : case IN_KIND_DEDUP:
234 0 : case IN_KIND_GENESI:
235 0 : case IN_KIND_IPECHO:
236 0 : if( FD_UNLIKELY( chunk<in->chunk0 || chunk>in->wmark || sz>in->mtu ) )
237 0 : FD_LOG_CRIT(( "chunk %lu %lu corrupt, not in range [%lu,%lu]", chunk, sz, in->chunk0, in->wmark ));
238 0 : ctx->chunk = chunk;
239 0 : break;
240 0 : case IN_KIND_EVENT: {
241 0 : ulong event_sz = FD_EVENT_SIG_SZ( sig );
242 0 : if( FD_UNLIKELY( chunk<in->chunk0 || chunk>in->wmark || event_sz>in->mtu ) )
243 0 : FD_LOG_CRIT(( "chunk %lu %lu corrupt, not in range [%lu,%lu]", chunk, event_sz, in->chunk0, in->wmark ));
244 0 : fd_memcpy( ctx->event_buf, fd_chunk_to_laddr_const( in->mem, chunk ), event_sz );
245 0 : ctx->event_type = FD_EVENT_SIG_TYPE( sig );
246 0 : ctx->event_sz = event_sz;
247 0 : break;
248 0 : }
249 0 : default:
250 0 : FD_LOG_CRIT(( "unexpected in_kind %d %lu", ctx->in_kind[ in_idx ], in_idx ));
251 0 : }
252 0 : }
253 :
254 : static void
255 : after_frag( fd_event_tile_t * ctx,
256 : ulong in_idx,
257 : ulong seq,
258 : ulong sig,
259 : ulong sz,
260 : ulong tsorig,
261 : ulong tspub,
262 0 : fd_stem_context_t * stem ) {
263 0 : (void)sz; (void)tsorig; (void)stem;
264 :
265 0 : switch( ctx->in_kind[ in_idx ] ) {
266 0 : case IN_KIND_SHRED: {
267 0 : FD_TEST( ctx->shred_buf_sz<=FD_NET_MTU );
268 : /* TODO: Currently no way to find a tight bound for the buffer
269 : size here, but 4096 is guaranteed to fit since sz<=FD_NET_MTU.
270 : Need to have the schema generator spit out max sizes for
271 : messages. */
272 0 : uchar * buffer = fd_circq_push_back( ctx->circq, 1UL, 4096UL );
273 0 : FD_TEST( buffer );
274 :
275 0 : uint ip_addr = fd_disco_netmux_sig_ip( sig );
276 0 : uint source_port = ctx->shred_source_port;
277 0 : int protocol;
278 0 : switch( fd_disco_netmux_sig_proto( sig ) ) {
279 0 : case DST_PROTO_SHRED:
280 0 : protocol = 1;
281 0 : break;
282 0 : case DST_PROTO_REPAIR:
283 0 : protocol = 2;
284 0 : break;
285 0 : default:
286 : // TODO: Leader shreds?
287 0 : FD_LOG_ERR(( "unexpected proto %lu in sig %lu", fd_disco_netmux_sig_proto( sig ), sig ));
288 0 : }
289 :
290 0 : ulong event_id = fd_event_client_id_reserve( ctx->client );
291 0 : long timestamp_nanos = fd_clock_tile_tickcomp_to_wallclock( ctx->clock, tspub );
292 :
293 0 : fd_pb_encoder_t encoder[1];
294 0 : fd_pb_encoder_init( encoder, buffer, 4096UL );
295 :
296 0 : FD_TEST( ctx->circq->cursor_push_seq );
297 0 : fd_pb_push_uint64( encoder, 1U, ctx->circq->cursor_push_seq-1UL );
298 0 : fd_pb_push_uint64( encoder, 2U, event_id );
299 0 : fd_pb_push_uint64( encoder, 3U, seq ); /* link_seq */
300 0 : fd_pb_push_uint64( encoder, 4U, (ulong)timestamp_nanos );
301 :
302 0 : fd_pb_submsg_open( encoder, 5U ); /* Event */
303 0 : fd_pb_submsg_open( encoder, 2U ); /* Shred */
304 0 : fd_pb_push_bytes( encoder, 1U, &ip_addr, 4UL );
305 0 : fd_pb_push_uint32( encoder, 2U, source_port );
306 0 : fd_pb_push_int32( encoder, 3U, protocol );
307 0 : fd_pb_push_bytes( encoder, 4U, ctx->shred_buf, ctx->shred_buf_sz );
308 0 : fd_pb_submsg_close( encoder );
309 0 : fd_pb_submsg_close( encoder );
310 0 : fd_circq_resize_back( ctx->circq, fd_pb_encoder_out_sz( encoder ) );
311 0 : break;
312 0 : }
313 0 : case IN_KIND_DEDUP:
314 0 : FD_TEST( sz<=FD_TPU_PARSED_MTU );
315 0 : uchar * buffer = fd_circq_push_back( ctx->circq, 1UL, EVENT_TXN_BUF_MAX );
316 0 : FD_TEST( buffer );
317 :
318 0 : fd_txn_m_t * txnm = (fd_txn_m_t *)fd_chunk_to_laddr( ctx->in[ in_idx ].mem, ctx->chunk );
319 0 : FD_TEST( txnm->payload_sz<=FD_TPU_MTU );
320 :
321 0 : int protocol = 0;
322 0 : switch( txnm->source_tpu ) {
323 0 : case FD_TXN_M_TPU_SOURCE_QUIC: protocol = 1; break;
324 0 : case FD_TXN_M_TPU_SOURCE_UDP: protocol = 2; break;
325 0 : case FD_TXN_M_TPU_SOURCE_GOSSIP: protocol = 3; break;
326 0 : case FD_TXN_M_TPU_SOURCE_BUNDLE: protocol = 4; break;
327 0 : case FD_TXN_M_TPU_SOURCE_TXSEND: protocol = 5; break;
328 0 : default:
329 0 : FD_LOG_ERR(( "unexpected source_tpu %u", txnm->source_tpu ));
330 0 : }
331 :
332 0 : ulong event_id = fd_event_client_id_reserve( ctx->client );
333 0 : long timestamp_nanos = fd_clock_tile_tickcomp_to_wallclock( ctx->clock, tspub );
334 :
335 0 : fd_pb_encoder_t encoder[1];
336 0 : fd_pb_encoder_init( encoder, buffer, EVENT_TXN_BUF_MAX );
337 :
338 0 : FD_TEST( ctx->circq->cursor_push_seq );
339 0 : fd_pb_push_uint64( encoder, 1U, ctx->circq->cursor_push_seq-1UL );
340 0 : fd_pb_push_uint64( encoder, 2U, event_id );
341 0 : fd_pb_push_uint64( encoder, 3U, seq ); /* link_seq */
342 0 : fd_pb_push_uint64( encoder, 4U, (ulong)timestamp_nanos );
343 :
344 0 : fd_pb_submsg_open( encoder, 5U ); /* Event */
345 0 : fd_pb_submsg_open( encoder, 1U ); /* Txn */
346 0 : fd_pb_push_bytes( encoder, 1U, &txnm->source_ipv4, 4UL );
347 0 : fd_pb_push_uint32( encoder, 2U, 0U ); /* TODO: source port .. */
348 0 : fd_pb_push_int32( encoder, 3U, protocol );
349 0 : fd_pb_push_uint64( encoder, 4U, txnm->block_engine.bundle_id );
350 0 : if( FD_UNLIKELY( txnm->block_engine.bundle_id ) ) {
351 0 : fd_pb_push_uint32( encoder, 5U, (uint)txnm->block_engine.bundle_txn_cnt );
352 0 : fd_pb_push_uint32( encoder, 6U, txnm->block_engine.commission );
353 0 : fd_pb_push_bytes( encoder, 7U, txnm->block_engine.commission_pubkey, 32UL );
354 0 : } else {
355 0 : fd_pb_push_uint32( encoder, 5U, 0U );
356 0 : fd_pb_push_uint32( encoder, 6U, 0U );
357 0 : uchar zero_pubkey[32UL] = {0};
358 0 : fd_pb_push_bytes( encoder, 7U, zero_pubkey, 32UL );
359 0 : }
360 0 : fd_pb_push_bytes( encoder, 8U, fd_txn_m_payload( txnm ), txnm->payload_sz );
361 :
362 0 : fd_pb_submsg_close( encoder );
363 0 : fd_pb_submsg_close( encoder );
364 0 : fd_circq_resize_back( ctx->circq, fd_pb_encoder_out_sz( encoder ) );
365 :
366 0 : break;
367 0 : case IN_KIND_GENESI: {
368 0 : fd_genesis_meta_t const * genesis_meta = fd_chunk_to_laddr( ctx->in[ in_idx ].mem, ctx->chunk );
369 0 : fd_event_client_init_genesis( ctx->client, genesis_meta );
370 0 : break;
371 0 : }
372 0 : case IN_KIND_IPECHO:
373 0 : FD_TEST( sig && sig<=USHORT_MAX );
374 0 : fd_event_client_init_shred_version( ctx->client, (ushort)sig );
375 0 : break;
376 0 : case IN_KIND_EVENT: {
377 0 : long timestamp_nanos = fd_clock_tile_tickcomp_to_wallclock( ctx->clock, tspub );
378 0 : fd_event_serialize_by_type( ctx->event_type, ctx->circq, ctx->client, timestamp_nanos, seq, ctx->event_buf, ctx->event_sz );
379 0 : break;
380 0 : }
381 0 : default:
382 0 : FD_LOG_ERR(( "unexpected in_kind %d", ctx->in_kind[ in_idx ] ));
383 0 : }
384 :
385 0 : ctx->next_poll_deadline = 0L;
386 0 : }
387 :
388 : static void
389 : privileged_init( fd_topo_t const * topo,
390 0 : fd_topo_tile_t const * tile ) {
391 0 : void * scratch = fd_topo_obj_laddr( topo, tile->tile_obj_id );
392 :
393 0 : FD_SCRATCH_ALLOC_INIT( l, scratch );
394 0 : fd_event_tile_t * ctx = FD_SCRATCH_ALLOC_APPEND( l, alignof(fd_event_tile_t), sizeof(fd_event_tile_t) );
395 0 : FD_SCRATCH_ALLOC_APPEND( l, fd_event_client_align(), fd_event_client_footprint( GRPC_BUF_MAX ) );
396 0 : FD_SCRATCH_ALLOC_APPEND( l, fd_circq_align(), fd_circq_footprint( EVENT_CIRCQ_SZ ) );
397 :
398 0 : ulong scratch_top = FD_SCRATCH_ALLOC_FINI( l, scratch_align() );
399 0 : if( FD_UNLIKELY( scratch_top > (ulong)scratch + scratch_footprint( tile ) ) )
400 0 : FD_LOG_ERR(( "scratch overflow %lu %lu %lu", scratch_top - (ulong)scratch - scratch_footprint( tile ), scratch_top, (ulong)scratch + scratch_footprint( tile ) ));
401 :
402 0 : if( FD_UNLIKELY( !strcmp( tile->event.identity_key_path, "" ) ) ) FD_LOG_ERR(( "identity_key_path not set" ));
403 0 : const uchar * identity_key = fd_keyload_load( tile->event.identity_key_path, /* pubkey only: */ 1 );
404 0 : fd_memcpy( ctx->identity_pubkey, identity_key, 32UL );
405 :
406 0 : FD_TEST( fd_rng_secure( &ctx->seed, 8UL ) );
407 0 : FD_TEST( fd_rng_secure( &ctx->instance_id, 8UL ) );
408 :
409 0 : FD_LOG_INFO(( "event instance_id=%lu", ctx->instance_id ));
410 :
411 0 : #define FD_EVENT_ID_SEED 0x812CAFEBABEFEEE0UL
412 :
413 0 : char _boot_id[ 36 ];
414 0 : int boot_id_fd = open( "/proc/sys/kernel/random/boot_id", O_RDONLY );
415 0 : if( FD_UNLIKELY( -1==boot_id_fd ) ) FD_LOG_ERR(( "open(/proc/sys/kernel/random/boot_id) failed (%d-%s)", errno, fd_io_strerror( errno ) ));
416 0 : if( FD_UNLIKELY( 36UL!=read( boot_id_fd, _boot_id, 36UL ) ) ) FD_LOG_ERR(( "read(/proc/sys/kernel/random/boot_id) failed (%d-%s)", errno, fd_io_strerror( errno ) ));
417 0 : if( FD_UNLIKELY( -1==close( boot_id_fd ) ) ) FD_LOG_ERR(( "close(/proc/sys/kernel/random/boot_id) failed (%d-%s)", errno, fd_io_strerror( errno ) ));
418 :
419 0 : ctx->boot_id = fd_hash( FD_EVENT_ID_SEED, _boot_id, 36UL );
420 :
421 0 : char _machine_id[ 32 ];
422 0 : int machine_id_fd = open( "/etc/machine-id", O_RDONLY );
423 0 : if( FD_UNLIKELY( -1==machine_id_fd ) ) FD_LOG_ERR(( "open(/etc/machine-id) failed (%d-%s)", errno, fd_io_strerror( errno ) ));
424 0 : if( FD_UNLIKELY( 32UL!=read( machine_id_fd, _machine_id, 32UL ) ) ) FD_LOG_ERR(( "read(/etc/machine-id) failed (%d-%s)", errno, fd_io_strerror( errno ) ));
425 0 : if( FD_UNLIKELY( -1==close( machine_id_fd ) ) ) FD_LOG_ERR(( "close(/etc/machine-id) failed (%d-%s)", errno, fd_io_strerror( errno ) ));
426 :
427 0 : ctx->machine_id = fd_hash( FD_EVENT_ID_SEED, _machine_id, 32UL );
428 :
429 0 : if( FD_UNLIKELY( !fd_netdb_open_fds( ctx->netdb_fds ) ) ) {
430 0 : FD_LOG_ERR(( "fd_netdb_open_fds failed" ));
431 0 : }
432 :
433 0 : fd_boot_report_collect( ctx->boot_report, topo, tile );
434 :
435 : /* Detect TLS from the URL scheme */
436 0 : fd_url_t url[ 1UL ];
437 0 : ushort port;
438 0 : _Bool is_ssl = 0;
439 0 : if( FD_UNLIKELY( fd_url_parse_endpoint( url, tile->event.url, strlen( tile->event.url ), &port, &is_ssl, "[tiles.event.url]" ) ) ) {
440 0 : FD_LOG_ERR(( "Could not parse [tiles.event.url]" ));
441 0 : }
442 0 : ctx->use_tls = is_ssl;
443 :
444 0 : if( ctx->use_tls ) {
445 : /* Load system CA certificates. Must happen here, while the tile can
446 : still open files. The TLS config itself lives in the event
447 : client. */
448 0 : long ca_cnt = fd_x509_ca_store_load_system( ctx->ca_store );
449 0 : if( FD_UNLIKELY( ca_cnt<0L ) ) FD_LOG_ERR(( "No CA certificate bundle found, cannot verify the event server certificate" ));
450 0 : }
451 0 : }
452 :
453 : static int
454 : link_is_event_report( fd_topo_t const * topo,
455 0 : ulong link_id ) {
456 0 : for( ulong i=0UL; i<topo->tile_cnt; i++ ) {
457 0 : if( FD_UNLIKELY( topo->tiles[ i ].event_link_id==link_id ) ) return 1;
458 0 : }
459 0 : return 0;
460 0 : }
461 :
462 : static void
463 : unprivileged_init( fd_topo_t const * topo,
464 0 : fd_topo_tile_t const * tile ) {
465 0 : void * scratch = fd_topo_obj_laddr( topo, tile->tile_obj_id );
466 :
467 0 : FD_SCRATCH_ALLOC_INIT( l, scratch );
468 0 : fd_event_tile_t * ctx = FD_SCRATCH_ALLOC_APPEND( l, alignof(fd_event_tile_t), sizeof(fd_event_tile_t) );
469 0 : void * _event_client = FD_SCRATCH_ALLOC_APPEND( l, fd_event_client_align(), fd_event_client_footprint( GRPC_BUF_MAX ) );
470 0 : void * _circq = FD_SCRATCH_ALLOC_APPEND( l, fd_circq_align(), fd_circq_footprint( EVENT_CIRCQ_SZ ) );
471 :
472 0 : ulong sign_in_idx = fd_topo_find_tile_in_link ( topo, tile, "sign_event", tile->kind_id );
473 0 : ulong sign_out_idx = fd_topo_find_tile_out_link( topo, tile, "event_sign", tile->kind_id );
474 0 : FD_TEST( sign_in_idx!=ULONG_MAX );
475 0 : fd_topo_link_t const * sign_in = &topo->links[ tile->in_link_id[ sign_in_idx ] ];
476 0 : fd_topo_link_t const * sign_out = &topo->links[ tile->out_link_id[ sign_out_idx ] ];
477 0 : if( FD_UNLIKELY( !fd_keyguard_client_join( fd_keyguard_client_new( ctx->keyguard_client,
478 0 : sign_out->mcache,
479 0 : sign_out->dcache,
480 0 : sign_in->mcache,
481 0 : sign_in->dcache,
482 0 : sign_out->mtu,
483 0 : sign_in->mtu ) ) ) ) {
484 0 : FD_LOG_ERR(( "failed to construct keyguard" ));
485 0 : }
486 :
487 0 : FD_TEST( fd_rng_join( fd_rng_new( ctx->rng, 0U, ctx->seed ) ) );
488 :
489 0 : ctx->keyswitch = fd_keyswitch_join( fd_topo_obj_laddr( topo, tile->id_keyswitch_obj_id ) );
490 0 : FD_TEST( ctx->keyswitch );
491 :
492 0 : ctx->circq = fd_circq_join( fd_circq_new( _circq, EVENT_CIRCQ_SZ ) );
493 0 : FD_TEST( ctx->circq );
494 :
495 0 : ctx->waker_client_idx = tile->waker_client_idx;
496 0 : FD_TEST( ctx->waker_client_idx!=ULONG_MAX );
497 0 : ctx->waker_fseq = fd_fseq_join( fd_topo_obj_laddr( topo, tile->waker_fseq_obj_id ) );
498 0 : FD_TEST( ctx->waker_fseq );
499 :
500 0 : ctx->client = fd_event_client_join( fd_event_client_new( _event_client,
501 0 : ctx->keyguard_client,
502 0 : ctx->rng,
503 0 : ctx->circq,
504 0 : FD_WAKER_INNER_FD( ctx->waker_client_idx ),
505 0 : 2*(1UL<<20UL) /* 2 MiB */,
506 0 : tile->event.url,
507 0 : ctx->identity_pubkey,
508 0 : fd_version_cstr,
509 0 : fd_commit_ref_cstr,
510 0 : tile->event.action,
511 0 : ctx->instance_id,
512 0 : ctx->boot_id,
513 0 : ctx->machine_id,
514 0 : GRPC_BUF_MAX,
515 0 : ctx->use_tls,
516 0 : ctx->ca_store ) );
517 0 : FD_TEST( ctx->client );
518 0 : ctx->next_poll_deadline = 0L;
519 :
520 0 : ctx->topo = topo;
521 0 : fd_memset( ctx->tile_shutdown_rendered, 0, sizeof(ctx->tile_shutdown_rendered) );
522 :
523 0 : ctx->idle_cnt = 0UL;
524 :
525 0 : FD_TEST( tile->in_cnt<=sizeof(ctx->in_kind)/sizeof(ctx->in_kind[0]) );
526 0 : int have_genesi = 0;
527 0 : int have_ipecho = 0;
528 0 : ulong polled_in_idx = 0UL;
529 0 : for( ulong i=0UL; i<tile->in_cnt; i++ ) {
530 0 : if( FD_UNLIKELY( !tile->in_link_poll[ i ] ) ) continue;
531 :
532 0 : fd_topo_link_t const * link = &topo->links[ tile->in_link_id[ i ] ];
533 0 : fd_topo_wksp_t const * link_wksp = &topo->workspaces[ topo->objs[ link->dcache_obj_id ].wksp_id ];
534 :
535 0 : if( FD_LIKELY( !strcmp( link->name, "net_shred" ) ) ) {
536 0 : fd_net_rx_bounds_init( &ctx->in[ polled_in_idx ].net_rx, link->dcache );
537 0 : ctx->in_kind[ polled_in_idx ] = IN_KIND_SHRED;
538 0 : polled_in_idx++;
539 0 : continue; /* only net_rx needs to be set in this case. */
540 0 : }
541 0 : else if( FD_LIKELY( !strcmp( link->name, "dedup_resolv" ) ) ) ctx->in_kind[ polled_in_idx ] = IN_KIND_DEDUP;
542 0 : else if( FD_LIKELY( !strcmp( link->name, "genesi_out" ) ) ) { ctx->in_kind[ polled_in_idx ] = IN_KIND_GENESI; have_genesi = 1; }
543 0 : else if( FD_LIKELY( !strcmp( link->name, "ipecho_out" ) ) ) { ctx->in_kind[ polled_in_idx ] = IN_KIND_IPECHO; have_ipecho = 1; }
544 0 : else if( FD_LIKELY( link_is_event_report( topo, link->id ) ) ) {
545 0 : ctx->in_kind[ polled_in_idx ] = IN_KIND_EVENT;
546 0 : FD_TEST( link->mtu<=sizeof(ctx->event_buf) );
547 0 : }
548 0 : else FD_LOG_ERR(( "event tile has unexpected input link %lu %s", i, link->name ));
549 :
550 0 : ctx->in[ polled_in_idx ].mem = link_wksp->wksp;
551 0 : ctx->in[ polled_in_idx ].mtu = link->mtu;
552 0 : if( FD_UNLIKELY( ctx->in[ polled_in_idx ].mtu ) ) {
553 0 : ctx->in[ polled_in_idx ].chunk0 = fd_dcache_compact_chunk0( ctx->in[ polled_in_idx ].mem, link->dcache );
554 0 : ctx->in[ polled_in_idx ].wmark = fd_dcache_compact_wmark ( ctx->in[ polled_in_idx ].mem, link->dcache, link->mtu );
555 0 : } else {
556 0 : ctx->in[ polled_in_idx ].chunk0 = 0UL;
557 0 : ctx->in[ polled_in_idx ].wmark = 0UL;
558 0 : }
559 0 : polled_in_idx++;
560 0 : }
561 0 : ctx->in_cnt = polled_in_idx;
562 :
563 0 : fd_boot_report_publish( ctx->boot_report, topo, ctx->circq, ctx->client );
564 :
565 0 : if( FD_UNLIKELY( !have_genesi ) ) {
566 0 : fd_genesis_meta_t meta[1]; fd_memset( meta, 0, sizeof(meta) );
567 0 : fd_memcpy( meta->genesis_hash.uc, tile->event.genesis_hash, 32UL );
568 0 : fd_event_client_init_genesis( ctx->client, meta );
569 0 : }
570 0 : if( FD_UNLIKELY( !have_ipecho ) ) {
571 0 : fd_event_client_init_shred_version( ctx->client, tile->event.shred_version );
572 0 : }
573 :
574 0 : fd_clock_tile_init( ctx->clock );
575 :
576 0 : ulong scratch_top = FD_SCRATCH_ALLOC_FINI( l, scratch_align() );
577 0 : if( FD_UNLIKELY( scratch_top > (ulong)scratch + scratch_footprint( tile ) ) )
578 0 : FD_LOG_ERR(( "scratch overflow %lu %lu %lu", scratch_top - (ulong)scratch - scratch_footprint( tile ), scratch_top, (ulong)scratch + scratch_footprint( tile ) ));
579 0 : }
580 :
581 : static ulong
582 : populate_allowed_seccomp( fd_topo_t const * topo,
583 : fd_topo_tile_t const * tile,
584 : ulong out_cnt,
585 0 : struct sock_filter * out ) {
586 0 : fd_event_tile_t * ctx = fd_topo_obj_laddr( topo, tile->tile_obj_id );
587 :
588 0 : uint epoll_inner_fd = (uint)FD_WAKER_INNER_FD( tile->waker_client_idx );
589 0 : uint epoll_outer_fd = (uint)FD_WAKER_OUTER_FD;
590 :
591 0 : populate_sock_filter_policy_fd_event_tile(
592 0 : out_cnt, out,
593 0 : (uint)fd_log_private_logfile_fd(),
594 0 : (uint)ctx->netdb_fds->etc_hosts,
595 0 : (uint)ctx->netdb_fds->etc_resolv_conf,
596 0 : epoll_inner_fd,
597 0 : epoll_outer_fd );
598 0 : return sock_filter_policy_fd_event_tile_instr_cnt;
599 0 : }
600 :
601 : static ulong
602 : populate_allowed_fds( fd_topo_t const * topo,
603 : fd_topo_tile_t const * tile,
604 : ulong out_fds_cnt,
605 0 : int * out_fds ) {
606 0 : fd_event_tile_t * ctx = fd_topo_obj_laddr( topo, tile->tile_obj_id );
607 :
608 0 : if( FD_UNLIKELY( out_fds_cnt<6UL ) ) FD_LOG_ERR(( "out_fds_cnt %lu", out_fds_cnt ));
609 :
610 0 : ulong out_cnt = 0;
611 0 : out_fds[ out_cnt++ ] = 2; /* stderr */
612 0 : if( FD_LIKELY( -1!=fd_log_private_logfile_fd() ) )
613 0 : out_fds[ out_cnt++ ] = fd_log_private_logfile_fd(); /* logfile */
614 0 : if( FD_LIKELY( ctx->netdb_fds->etc_hosts >= 0 ) )
615 0 : out_fds[ out_cnt++ ] = ctx->netdb_fds->etc_hosts;
616 0 : out_fds[ out_cnt++ ] = ctx->netdb_fds->etc_resolv_conf;
617 0 : out_fds[ out_cnt++ ] = FD_WAKER_OUTER_FD; /* waker outer epoll fd (rearm) */
618 0 : out_fds[ out_cnt++ ] = FD_WAKER_INNER_FD( tile->waker_client_idx ); /* waker inner epoll fd */
619 0 : return out_cnt;
620 0 : }
621 :
622 : static void
623 0 : during_housekeeping( fd_event_tile_t * ctx ) {
624 0 : if( FD_UNLIKELY( fd_clock_tile_recal_due( ctx->clock ) ) ) {
625 0 : fd_clock_tile_recal( ctx->clock );
626 0 : }
627 :
628 0 : if( FD_UNLIKELY( fd_keyswitch_state_query( ctx->keyswitch )==FD_KEYSWITCH_STATE_SWITCH_PENDING ) ) {
629 0 : FD_LOG_DEBUG(( "keyswitch: switching identity" ));
630 0 : memcpy( ctx->identity_pubkey, ctx->keyswitch->bytes, 32UL );
631 0 : fd_event_client_set_identity( ctx->client, ctx->identity_pubkey );
632 0 : ctx->next_poll_deadline = 0L;
633 0 : fd_keyswitch_state( ctx->keyswitch, FD_KEYSWITCH_STATE_COMPLETED );
634 0 : }
635 0 : }
636 :
637 0 : #define STEM_BURST (1UL)
638 0 : #define STEM_LAZY ((long)10e6) /* 10ms */
639 :
640 0 : #define STEM_CALLBACK_CONTEXT_TYPE fd_event_tile_t
641 0 : #define STEM_CALLBACK_CONTEXT_ALIGN alignof(fd_event_tile_t)
642 :
643 0 : #define STEM_CALLBACK_METRICS_WRITE metrics_write
644 0 : #define STEM_CALLBACK_BEFORE_CREDIT before_credit
645 0 : #define STEM_CALLBACK_DURING_FRAG during_frag
646 0 : #define STEM_CALLBACK_AFTER_FRAG after_frag
647 0 : #define STEM_CALLBACK_DURING_HOUSEKEEPING during_housekeeping
648 :
649 : #include "../stem/fd_stem.c"
650 :
651 : fd_topo_run_tile_t fd_tile_event = {
652 : .name = "event",
653 : .rlimit_file_cnt = 5UL, /* stderr, logfile, /etc/hosts, /etc/resolv.conf, and socket to the server */
654 : .populate_allowed_seccomp = populate_allowed_seccomp,
655 : .populate_allowed_fds = populate_allowed_fds,
656 : .scratch_align = scratch_align,
657 : .scratch_footprint = scratch_footprint,
658 : .privileged_init = privileged_init,
659 : .unprivileged_init = unprivileged_init,
660 : .run = stem_run,
661 : .keep_host_networking = 1,
662 : .allow_connect = 1,
663 : };
|