LCOV - code coverage report
Current view: top level - disco/keyguard - fd_keyguard_match.c (source / functions) Hit Total Coverage
Test: cov.lcov Lines: 130 161 80.7 %
Date: 2026-09-17 04:28:31 Functions: 12 12 100.0 %

          Line data    Source code
       1             : #include "fd_keyguard.h"
       2             : #include "../../ballet/shred/fd_shred.h"
       3             : #include "../../ballet/txn/fd_compact_u16.h"
       4             : #include "../../flamenco/gossip/fd_gossip_value.h"
       5             : #include "../../discof/repair/fd_repair.h"
       6             : 
       7             : /* fd_keyguard_match fingerprints signing requests and checks them for
       8             :    ambiguity.
       9             : 
      10             :    Supported message types are as follows:
      11             : 
      12             :    - Legacy transaction messages
      13             :    - Version 0 transaction messages
      14             :    - Version 1 transaction messages
      15             :    - Legacy shred signed payloads
      16             :    - Merkle shred roots
      17             :    - TLS CertificateVerify challenges
      18             :    - Gossip message signed payloads (CrdsData)
      19             : 
      20             :    ### Fake Signing Attacks
      21             : 
      22             :    The main goal of fd_keyguard_match is to defeat "fake signing"
      23             :    attacks.  These are attacks in which the keyguard signs a request for
      24             :    which the client is not authorized.  Such attacks use a combination
      25             :    of vulnerabilities:  Key reuse, and type confusion.
      26             : 
      27             :    Key reuse is particularly prevalent with the validator identity key,
      28             :    the hot Ed25519 key that a validator uses in almost all protocols
      29             :    that it actively participates in.
      30             : 
      31             :    Type confusion occurs when the message payload being signed can be
      32             :    interpreted as multiple different message types.  Usually, this is
      33             :    categorically prevented by using "signing domains".
      34             : 
      35             :    Such attacks are particularly dangerous to validators because their
      36             :    validator identity key holds an amount of native tokens to
      37             :    participate in Tower BFT voting.  In the worst case, an attacker
      38             :    could trick a validator into signing an innocuous message (e.g. a
      39             :    gossip message) that can also be interpreted as a transaction
      40             :    withdrawing these tokens.
      41             : 
      42             :    ### Code Verification
      43             : 
      44             :    The safety of this module can be verified using a number of CBMC
      45             :    proofs composed via deductive reasoning.
      46             : 
      47             :    - fd_txn_minsz_proof verifies the constant FD_TXN_MIN_SERIALIZED_SZ.
      48             :    - fd_txn_ambiguity_gossip_proof verifies that gossip messages cannot
      49             :      be parsed as transactions.
      50             :    - fd_keyguard_match_txn_harness verifies that the txn fingerprinting
      51             :      logic is free of false negatives.
      52             :    - fd_keyguard_ambiguity_proof verifies that any input up to 2048 byte
      53             :      size are unambiguous, i.e. either detected by one or none of the
      54             :      fingerprinting functions.
      55             : 
      56             :    Under the hood, CBMC executes the keyguard logic with all possible
      57             :    inputs (>=2^16384 unique inputs) via symbolic execution.  The CBMC
      58             :    machine model also verifies that the code is free of common
      59             :    vulnerability classes (memory unsoundness, undefined behavior, …).
      60             : 
      61             :    As a result, we know with a high degree of certainty that type
      62             :    detection logic is free of false negatives.  For example, when
      63             :    fd_keyguard_match sees a transaction, it will always reliably detect
      64             :    it as one.  (fd_keyguard_match might also wrongly fingerprint
      65             :    arbitrary other inputs as, e.g. transactions.  But this is not a
      66             :    problem, as strict checks follow later on in fd_keyguard_authorize.)
      67             : 
      68             :    ### Deployment Context
      69             : 
      70             :    fd_keyguard_match is exposed to untrusted "signing request" inputs
      71             :    and implements the first line of authorization checks in the
      72             :    keyguard.  It is thus a critical component for securing the identity
      73             :    key.
      74             : 
      75             :    ### Implementation Approach
      76             : 
      77             :    This code looks awful and scary, but is carefully crafted to meet the
      78             :    aforementioned high assurance and formal verification requirements.
      79             : 
      80             :    Although parsers for the supported message types are available
      81             :    elsewhere in the codebase, they were not used here due to their time
      82             :    complexity exceeding the capabilities of CBMC.  The time complexity
      83             :    of all parsers in this compile unit is O(1), which allowed for
      84             :    complete CBMC coverage.
      85             : 
      86             :    TLDR:  The following code implements the least possible logic
      87             :           required to reliably detect types of identity key signing
      88             :           payloads without false negatives. */
      89             : 
      90             : FD_FN_PURE static int
      91             : fd_keyguard_payload_matches_txn_msg( uchar const * data,
      92             :                                      ulong         sz,
      93        6369 :                                      int           sign_type ) {
      94             : 
      95        6369 :   uchar const * end = data + sz;
      96             : 
      97        6369 :   if( sign_type != FD_KEYGUARD_SIGN_TYPE_ED25519 ) return 0;
      98             : 
      99             :   /* txn_msg_min_sz is the smallest valid size of a transaction msg. A
     100             :      transaction is the concatenation of (signature count, signatures,
     101             :      msg).  The smallest size of a txn is FD_TXN_MIN_SERIALIZED_SZ
     102             :      (formally proven with CBMC in fd_txn_minsz_proof.c).  We know the
     103             :      smallest sizes of "signature count" and "signatures", thus we can
     104             :      derive the smallest size of "msg". */
     105             : 
     106        6339 :   ulong const txn_msg_min_sz =
     107        6339 :       FD_TXN_MIN_SERIALIZED_SZ
     108        6339 :     -  1UL   /* min sz of signature count (compact_u16 encoding) */
     109        6339 :     - 64UL;  /* min sz of signature list (array of Ed25519 sigs) */
     110        6339 :   if( sz<txn_msg_min_sz ) return 0;
     111             : 
     112             :   /* Message type check.
     113             : 
     114             :      Bit patterns of first bytes are as follows
     115             : 
     116             :      - 0aaaaaaa bbbbbbbb cccccccc           (Legacy txns)
     117             :      - 10000000 aaaaaaaa bbbbbbbb cccccccc  (v0     txns)
     118             :      - 10000001 aaaaaaaa bbbbbbbb cccccccc  (v1     txns)
     119             : 
     120             :      Where 'a' are the bits that make up the 'required signature count'
     121             :        ... 'b'         ....                  'readonly signed count'
     122             :        ... 'c'         ....                  'readonly unsigned count' */
     123             : 
     124        6333 :   uchar const * cursor    = data;
     125        6333 :   uint          header_b0 = *cursor;
     126        6333 :   cursor++;
     127        6333 :   uint          sig_cnt;  /* sig count (ignoring compact_u16 encoding) */
     128        6333 :   if( header_b0 & 0x80UL ) {
     129             :     /* Versioned message, v0 and v1 recognized so far */
     130        6330 :     uint version = header_b0 & 0x7F;
     131        6330 :     if( version!=FD_TXN_V0 && version!=FD_TXN_V1 ) return 0;
     132             : 
     133             :     /* Check transaction V1 separately because the layout is
     134             :        different. We do the same checks for V1 and V0/legacy, just in
     135             :        a different code branch. */
     136        6327 :     if( version==FD_TXN_V1 ) {
     137        6327 :       sig_cnt = *cursor;
     138        6327 :       cursor++;
     139             : 
     140             :       /* There must be at least one signature. */
     141        6327 :       if( sig_cnt==0U ) return 0;
     142             : 
     143             :       /* Check if the signatures exceed the V1 limit */
     144        6324 :       if( sig_cnt>FD_TXN_SIG_MAX ) return 0;
     145             : 
     146             :       /* Skip other fields */
     147             :       //uint ro_signed_cnt      = *cursor;
     148        6324 :       cursor++;
     149             :       //uint ro_unsigned_cnt    = *cursor;
     150        6324 :       cursor++;
     151             :       //uint config_mask        = fd_uint_load_4( cursor );
     152        6324 :       cursor += 4UL;
     153             :       //uchar const * blockhash = cursor;
     154        6324 :       cursor += FD_TXN_BLOCKHASH_SZ;
     155             : 
     156        6324 :       if( cursor + 2 > end ) return 0;
     157        6324 :       ulong instr_cnt = *cursor;
     158        6324 :       cursor++;
     159        6324 :       ulong addr_cnt  = *cursor;
     160        6324 :       cursor++;
     161             : 
     162             :       /* Check if the instructions exceed the V1 limit */
     163        6324 :       if( instr_cnt>FD_TXN_INSTR_MAX ) return 0;
     164             : 
     165             :       /* Check if the addresses exceed the V1 limit */
     166        6321 :       if( addr_cnt>FD_TXN_ACCT_ADDR_MAX ) return 0;
     167             : 
     168        6318 :       if( sig_cnt>addr_cnt ) return 0;
     169             : 
     170        6315 :       return 1;
     171        6318 :     }
     172             : 
     173           0 :     sig_cnt = *cursor;
     174           0 :     cursor++;
     175           3 :   } else {
     176             :     /* Legacy message */
     177           3 :     sig_cnt = header_b0;
     178           3 :   }
     179             : 
     180             :   /* There must be at least one signature. */
     181           3 :   if( sig_cnt==0U ) return 0;
     182             : 
     183             :   /* Check if signatures exceed txn size limit */
     184           3 :   ulong sig_sz;
     185           3 :   if( __builtin_umull_overflow( sig_cnt, 64UL, &sig_sz ) ) return 0;
     186           3 :   if( sig_sz > (FD_TXN_MTU_V0-txn_msg_min_sz) ) return 0;
     187             : 
     188             :   /* Skip other fields */
     189             :   //uint ro_signed_cnt   = *cursor;
     190           3 :   cursor++;
     191             :   //uint ro_unsigned_cnt = *cursor;
     192           3 :   cursor++;
     193             : 
     194           3 :   if( cursor + 3 > end ) return 0;
     195           3 :   ulong addr_cnt_sz = fd_cu16_dec_sz( cursor, 3UL );
     196           3 :   if( !addr_cnt_sz ) return 0;
     197           3 :   ulong addr_cnt    = fd_cu16_dec_fixed( cursor, addr_cnt_sz );
     198           3 :   cursor += addr_cnt_sz;
     199             : 
     200           3 :   if( sig_cnt>addr_cnt ) return 0;
     201             : 
     202           3 :   return 1;
     203           3 : }
     204             : 
     205             : FD_FN_PURE static int
     206             : fd_keyguard_payload_matches_ping_msg( uchar const * data,
     207             :                                       ulong         sz,
     208        6369 :                                       int           sign_type ) {
     209        6369 :   return sign_type==FD_KEYGUARD_SIGN_TYPE_ED25519 &&
     210        6369 :          sz==32UL &&
     211        6369 :          (memcmp( data, "SOLANA_PING_PONG", 16UL ) == 0);
     212        6369 : }
     213             : 
     214             : FD_FN_PURE static int
     215             : fd_keyguard_payload_matches_pong_msg( uchar const * data,
     216             :                                       ulong         sz,
     217        6369 :                                       int           sign_type ) {
     218        6369 :   return sign_type==FD_KEYGUARD_SIGN_TYPE_SHA256_ED25519 &&
     219        6369 :          sz==48UL &&
     220        6369 :          (memcmp( data, "SOLANA_PING_PONG", 16UL ) == 0);
     221        6369 : }
     222             : 
     223             : FD_FN_PURE static int
     224             : fd_keyguard_payload_matches_prune_data( uchar const * data,
     225             :                                         ulong         sz,
     226        6369 :                                         int           sign_type ) {
     227        6369 :   if( sign_type != FD_KEYGUARD_SIGN_TYPE_ED25519 ) return 0;
     228             : 
     229        6339 :   ulong const static_sz = 106UL;
     230        6339 :   if( sz < static_sz ) return 0;
     231             : 
     232        6312 :   if( FD_LOAD( ulong, data )!=18UL ) return 0;
     233           0 :   if(  memcmp( data+8UL, "\xffSOLANA_PRUNE_DATA", 18UL ) ) return 0;
     234             : 
     235           0 :   ulong prune_cnt = FD_LOAD( ulong, data+58UL );
     236           0 :   ulong expected_sz;
     237           0 :   if( __builtin_umull_overflow( prune_cnt,   32UL,      &expected_sz ) ) return 0;
     238           0 :   if( __builtin_uaddl_overflow( expected_sz, static_sz, &expected_sz ) ) return 0;
     239           0 :   if( sz != expected_sz ) return 0;
     240             : 
     241           0 :   return 1;
     242           0 : }
     243             : 
     244             : FD_FN_PURE static int
     245             : fd_keyguard_payload_matches_gossip( uchar const * data,
     246             :                                     ulong         sz,
     247        6369 :                                     int           sign_type ) {
     248             : 
     249             :   /* All gossip messages except pings use raw signing */
     250        6369 :   if( sign_type != FD_KEYGUARD_SIGN_TYPE_ED25519 ) return 0;
     251             : 
     252             :   /* Every gossip message contains a 4 byte enum variant tag (at the
     253             :      beginning of the message) and a 32 byte public key (at an arbitrary
     254             :      location). */
     255        6339 :   if( sz<36UL ) return 0;
     256             : 
     257        6336 :   uint tag = FD_LOAD( uint, data );
     258             : 
     259        6336 :   return tag<FD_GOSSIP_VALUE_CNT;
     260        6339 : }
     261             : 
     262             : FD_FN_PURE static int
     263             : fd_keyguard_payload_matches_repair( uchar const * data,
     264             :                                     ulong         sz,
     265        6369 :                                     int           sign_type ) {
     266             : 
     267             :   /* All repair messages except pings use raw signing */
     268        6369 :   if( sign_type != FD_KEYGUARD_SIGN_TYPE_ED25519 ) return 0;
     269             : 
     270             :   /* Every repair message contains a 4 byte enum variant tag (at the
     271             :      beginning of the message) and a 32 byte public key (at an arbitrary
     272             :      location). */
     273        6339 :   if( sz<36UL ) return 0;
     274             : 
     275             :   /* Ensure that the kind matches a possible repair request. */
     276        6336 :   uint kind = FD_LOAD( uint, data );
     277        6336 :   if( (kind==FD_REPAIR_KIND_SHRED)
     278        6336 :     | (kind==FD_REPAIR_KIND_HIGHEST_SHRED)
     279        6336 :     | (kind==FD_REPAIR_KIND_ORPHAN)
     280        6336 :     | (kind==AG_REPAIR_KIND_PARENT_FEC_COUNT)
     281        6336 :     | (kind==AG_REPAIR_KIND_FEC_ROOT)
     282        6336 :     | (kind==AG_REPAIR_KIND_SHRED_FOR_BLOCK_ID) )
     283           0 :     return 1;
     284             : 
     285        6336 :   return 0;
     286        6336 : }
     287             : 
     288             : FD_FN_PURE int
     289             : fd_keyguard_payload_matches_shred( uchar const * data,
     290             :                                    ulong         sz,
     291        6369 :                                    int           sign_type ) {
     292        6369 :   (void)data;
     293             : 
     294             :   /* Note: Legacy shreds no longer relevant (drop_legacy_shreds) */
     295             : 
     296             :   /* FIXME: Sign Merkle shreds using SIGN_TYPE_SHA256_ED25519 (!!!) */
     297        6369 :   if( sign_type != FD_KEYGUARD_SIGN_TYPE_ED25519 ) return 0;
     298        6339 :   if( sz != 32 ) return 0;
     299             : 
     300           0 :   return 1;
     301        6339 : }
     302             : 
     303             : FD_FN_PURE int
     304             : fd_keyguard_payload_matches_tls_cv( uchar const * data,
     305             :                                     ulong         sz,
     306        6369 :                                     int           sign_type ) {
     307             : 
     308        6369 :   if( sign_type != FD_KEYGUARD_SIGN_TYPE_ED25519 ) return 0;
     309             : 
     310             :   /* TLS CertificateVerify signing payload one of 3 sizes
     311             :      depending on hash function chosen */
     312        6339 :   switch( sz ) {
     313           0 :   case 130UL: break;  /* Prefix + 32 byte hash */
     314           0 :   case 146UL: break;  /* Prefix + 48 byte hash */
     315           0 :   case 162UL: break;  /* Prefix + 64 byte hash */
     316        6339 :   default:
     317        6339 :     return 0;
     318        6339 :   }
     319             : 
     320             :   /* Always prefixed with client or server pattern */
     321           0 :   static char const client_prefix[ 98 ] =
     322           0 :     "                                "  /* 32 spaces */
     323           0 :     "                                "  /* 32 spaces */
     324           0 :     "TLS 1.3, client CertificateVerify";
     325             : 
     326           0 :   static char const server_prefix[ 98 ] =
     327           0 :     "                                "  /* 32 spaces */
     328           0 :     "                                "  /* 32 spaces */
     329           0 :     "TLS 1.3, server CertificateVerify";
     330           0 :   int is_client = 0==memcmp( data, client_prefix, 98UL );
     331           0 :   int is_server = 0==memcmp( data, server_prefix, 98UL );
     332           0 :   return (is_client)|(is_server);
     333        6339 : }
     334             : 
     335             : FD_FN_PURE int
     336             : fd_keyguard_payload_matches_ag_vote( uchar const * data,
     337             :                                      ulong         sz,
     338        6369 :                                      int           sign_type ) {
     339             : 
     340             :   /* Alpenglow vote payload produced by ag_vote_signing_ser:
     341             : 
     342             :      u8  tag            (1..5, WireConsensusMessageKind vote tags)
     343             :      u64 slot
     344             :      [32 bytes block id] only for notar (1) and notar fallback (4)
     345             :      u16 shred_version */
     346             : 
     347        6369 :   if( sign_type != FD_KEYGUARD_SIGN_TYPE_BLS ) return 0;
     348          24 :   if( sz!=11UL && sz!=43UL ) return 0;
     349          24 :   uchar tag = data[ 0 ];
     350          24 :   if( tag<1 || tag>5 ) return 0;
     351          18 :   int has_hash = ( tag==1 ) | ( tag==4 );
     352          18 :   return has_hash ? ( sz==43UL ) : ( sz==11UL );
     353          24 : }
     354             : 
     355             : FD_FN_PURE int
     356             : fd_keyguard_payload_matches_bundle( uchar const * data,
     357             :                                     ulong         sz,
     358        6369 :                                     int           sign_type ) {
     359        6369 :   (void)data;
     360             : 
     361        6369 :   if( sign_type != FD_KEYGUARD_SIGN_TYPE_PUBKEY_CONCAT_ED25519 ) return 0;
     362           3 :   if( sz!=9UL ) return 0;
     363             : 
     364           0 :   return 1;
     365           3 : }
     366             : 
     367             : FD_FN_PURE int
     368             : fd_keyguard_payload_matches_event( uchar const * data,
     369             :                                    ulong         sz,
     370        6369 :                                    int           sign_type ) {
     371        6369 :   static char const sign_prefix[ 100 ] =
     372        6369 :     "                                "  /* 32 spaces */
     373        6369 :     "                                "  /* 32 spaces */
     374        6369 :     "Firedancer event challenge-response";
     375             : 
     376        6369 :   if( sz!=sizeof(sign_prefix)+217UL ) return 0;
     377           0 :   if( sign_type!=FD_KEYGUARD_SIGN_TYPE_ED25519 ) return 0;
     378           0 :   if( 0!=memcmp( data, sign_prefix, sizeof(sign_prefix) ) ) return 0;
     379           0 :   return 1;
     380           0 : }
     381             : 
     382             : FD_FN_PURE ulong
     383             : fd_keyguard_payload_match( uchar const * data,
     384             :                            ulong         sz,
     385        6369 :                            int           sign_type ) {
     386        6369 :   ulong res = 0UL;
     387        6369 :   res |= fd_ulong_if( fd_keyguard_payload_matches_txn_msg   ( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_TXN,     0 );
     388        6369 :   res |= fd_ulong_if( fd_keyguard_payload_matches_gossip    ( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_GOSSIP,  0 );
     389        6369 :   res |= fd_ulong_if( fd_keyguard_payload_matches_repair    ( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_REPAIR,  0 );
     390        6369 :   res |= fd_ulong_if( fd_keyguard_payload_matches_prune_data( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_PRUNE,   0 );
     391        6369 :   res |= fd_ulong_if( fd_keyguard_payload_matches_shred     ( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_SHRED,   0 );
     392        6369 :   res |= fd_ulong_if( fd_keyguard_payload_matches_tls_cv    ( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_TLS_CV,  0 );
     393        6369 :   res |= fd_ulong_if( fd_keyguard_payload_matches_ping_msg  ( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_PING,    0 );
     394        6369 :   res |= fd_ulong_if( fd_keyguard_payload_matches_pong_msg  ( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_PONG,    0 );
     395        6369 :   res |= fd_ulong_if( fd_keyguard_payload_matches_bundle    ( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_BUNDLE,  0 );
     396        6369 :   res |= fd_ulong_if( fd_keyguard_payload_matches_event     ( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_EVENT,   0 );
     397        6369 :   res |= fd_ulong_if( fd_keyguard_payload_matches_ag_vote   ( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_AG_VOTE, 0 );
     398        6369 :   return res;
     399        6369 : }

Generated by: LCOV version 1.14