Line data Source code
1 : #ifndef HEADER_fd_src_disco_keyguard_fd_keyguard_h 2 : #define HEADER_fd_src_disco_keyguard_fd_keyguard_h 3 : 4 : /* fd_keyguard creates digital signatures on behalf of validator 5 : components. */ 6 : 7 : #include "../fd_disco_base.h" 8 : 9 : FD_PROTOTYPES_BEGIN 10 : 11 : /* FD_KEYGUARD_SIGN_REQ_MTU is the maximum size (inclusive) of a signing 12 : request payload. The payload in this case is the message byte array 13 : passed to fd_ed25519_sign. */ 14 : 15 30 : #define FD_KEYGUARD_SIGN_REQ_MTU (2048UL) 16 : 17 : /* Role definitions ***************************************************/ 18 : 19 9 : #define FD_KEYGUARD_ROLE_TXSEND (0) /* vote transaction sender */ 20 3 : #define FD_KEYGUARD_ROLE_GOSSIP (1) /* gossip participant */ 21 0 : #define FD_KEYGUARD_ROLE_LEADER (2) /* block producer (shreds) */ 22 0 : #define FD_KEYGUARD_ROLE_REPAIR (4) /* Repair tile */ 23 0 : #define FD_KEYGUARD_ROLE_BUNDLE (5) /* Bundle tile */ 24 0 : #define FD_KEYGUARD_ROLE_EVENT (6) /* Event tile */ 25 0 : #define FD_KEYGUARD_ROLE_BUNDLE_CRANK (7) /* Sign cranking transactions for bundle tips */ 26 0 : #define FD_KEYGUARD_ROLE_RSERVE (8) /* Repair server tile */ 27 21 : #define FD_KEYGUARD_ROLE_VOTOR (9) /* Alpenglow votor tile (QUIC TLS) */ 28 : #define FD_KEYGUARD_ROLE_CNT (10) /* number of known roles */ 29 : 30 : /* Payload types ******************************************************/ 31 : 32 6375 : #define FD_KEYGUARD_PAYLOAD_LG_TXN ( 0) /* Solana transaction message (e.g. vote) */ 33 6402 : #define FD_KEYGUARD_PAYLOAD_LG_GOSSIP ( 1) /* Gossip CrdsData */ 34 6372 : #define FD_KEYGUARD_PAYLOAD_LG_PRUNE ( 2) /* Gossip PruneData */ 35 6399 : #define FD_KEYGUARD_PAYLOAD_LG_SHRED ( 3) /* Solana legacy or merkle shred */ 36 6396 : #define FD_KEYGUARD_PAYLOAD_LG_TLS_CV ( 4) /* TLS 1.3 certificate verify payload */ 37 6399 : #define FD_KEYGUARD_PAYLOAD_LG_REPAIR ( 6) /* RepairProtocol */ 38 6402 : #define FD_KEYGUARD_PAYLOAD_LG_PING ( 7) /* Gossip ping protocol */ 39 6369 : #define FD_KEYGUARD_PAYLOAD_LG_BUNDLE ( 8) /* Bundle block producer authentication */ 40 6369 : #define FD_KEYGUARD_PAYLOAD_LG_EVENT ( 9) /* Event reporter authentication */ 41 6372 : #define FD_KEYGUARD_PAYLOAD_LG_PONG (10) /* Gossip/Repair ping/pong protocol */ 42 6390 : #define FD_KEYGUARD_PAYLOAD_LG_AG_VOTE (11) /* Alpenglow BLS vote */ 43 : 44 6375 : #define FD_KEYGUARD_PAYLOAD_TXN (1UL<<FD_KEYGUARD_PAYLOAD_LG_TXN ) 45 6402 : #define FD_KEYGUARD_PAYLOAD_GOSSIP (1UL<<FD_KEYGUARD_PAYLOAD_LG_GOSSIP ) 46 6372 : #define FD_KEYGUARD_PAYLOAD_PRUNE (1UL<<FD_KEYGUARD_PAYLOAD_LG_PRUNE ) 47 6399 : #define FD_KEYGUARD_PAYLOAD_SHRED (1UL<<FD_KEYGUARD_PAYLOAD_LG_SHRED ) 48 6396 : #define FD_KEYGUARD_PAYLOAD_TLS_CV (1UL<<FD_KEYGUARD_PAYLOAD_LG_TLS_CV ) 49 6399 : #define FD_KEYGUARD_PAYLOAD_REPAIR (1UL<<FD_KEYGUARD_PAYLOAD_LG_REPAIR ) 50 6402 : #define FD_KEYGUARD_PAYLOAD_PING (1UL<<FD_KEYGUARD_PAYLOAD_LG_PING ) 51 6369 : #define FD_KEYGUARD_PAYLOAD_BUNDLE (1UL<<FD_KEYGUARD_PAYLOAD_LG_BUNDLE ) 52 6369 : #define FD_KEYGUARD_PAYLOAD_EVENT (1UL<<FD_KEYGUARD_PAYLOAD_LG_EVENT ) 53 6372 : #define FD_KEYGUARD_PAYLOAD_PONG (1UL<<FD_KEYGUARD_PAYLOAD_LG_PONG ) 54 6390 : #define FD_KEYGUARD_PAYLOAD_AG_VOTE (1UL<<FD_KEYGUARD_PAYLOAD_LG_AG_VOTE) 55 : 56 : /* Sign types *********************************************************/ 57 : 58 53109 : #define FD_KEYGUARD_SIGN_TYPE_ED25519 (0) /* ed25519_sign(input) */ 59 12738 : #define FD_KEYGUARD_SIGN_TYPE_SHA256_ED25519 (1) /* ed25519_sign(sha256(data)) */ 60 6369 : #define FD_KEYGUARD_SIGN_TYPE_PUBKEY_CONCAT_ED25519 (2) /* ed25519_sign(pubkey-data) */ 61 6375 : #define FD_KEYGUARD_SIGN_TYPE_BLS (3) /* bls_sign(vote) */ 62 : #define FD_KEYGUARD_SIGN_TYPE_CNT (4) /* number of sign types */ 63 : 64 : 65 0 : #define FD_KEYGUARD_BLS_SIG_SZ (192UL) /* matches FD_BLS_SIG_SZ */ 66 : 67 : /* Type confusion/ambiguity checks ************************************/ 68 : 69 : /* fd_keyguard_payload_match returns a bitwise OR of 70 : FD_KEYGUARD_PAYLOAD_{...}. 71 : 72 : [data,data+sz) is the payload that is requested to be signed. 73 : 74 : sign_type is in FD_KEYGUARD_SIGN_TYPE_{...}. 75 : 76 : Returns 0 if none matched. fd_ulong_popcnt(return value) is 1 if the 77 : payload is unambiguously of a single type. */ 78 : 79 : FD_FN_PURE ulong 80 : fd_keyguard_payload_match( uchar const * data, 81 : ulong sz, 82 : int sign_type ); 83 : 84 : /* Authorization ******************************************************/ 85 : 86 : struct fd_keyguard_authority { 87 : uchar identity_pubkey[32]; 88 : /* Pack tile is allowed to sign a transaction that invokes these two 89 : programs that come from the config.toml. We need to check these 90 : programs, because otherwise an attacker with RCE on pack can make 91 : the validator sign a transaction that invokes their malicious 92 : program which drains the identity key. */ 93 : uchar tip_payment_program[32]; 94 : uchar tip_distribution_program[32]; 95 : }; 96 : 97 : typedef struct fd_keyguard_authority fd_keyguard_authority_t; 98 : 99 : /* fd_keyguard_payload_authorize decides whether the keyguard accepts 100 : a signing request. 101 : 102 : [data,data+sz) is the payload that is requested to be signed. 103 : 104 : role is one of FD_KEYGUARD_ROLE_{...}. It is assumed that the origin 105 : of the request was previously authorized for the given role. 106 : 107 : Returns 1 if authorized, otherwise 0. 108 : 109 : This function is more restrictive than the respective 110 : fd_keyguard_payload_matches functions. */ 111 : 112 : int 113 : fd_keyguard_payload_authorize( fd_keyguard_authority_t const * authority, 114 : uchar const * data, 115 : ulong sz, 116 : int role, 117 : int sign_type ); 118 : 119 : FD_PROTOTYPES_END 120 : 121 : #endif /* HEADER_fd_src_disco_keyguard_fd_keyguard_h */