Line data Source code
1 : #include "fd_keyguard.h"
2 : #include "../../ballet/shred/fd_shred.h"
3 : #include "../../ballet/txn/fd_compact_u16.h"
4 : #include "../../flamenco/gossip/fd_gossip_value.h"
5 : #include "../../discof/repair/fd_repair.h"
6 :
7 : /* fd_keyguard_match fingerprints signing requests and checks them for
8 : ambiguity.
9 :
10 : Supported message types are as follows:
11 :
12 : - Legacy transaction messages
13 : - Version 0 transaction messages
14 : - Version 1 transaction messages
15 : - Legacy shred signed payloads
16 : - Merkle shred roots
17 : - TLS CertificateVerify challenges
18 : - Gossip message signed payloads (CrdsData)
19 :
20 : ### Fake Signing Attacks
21 :
22 : The main goal of fd_keyguard_match is to defeat "fake signing"
23 : attacks. These are attacks in which the keyguard signs a request for
24 : which the client is not authorized. Such attacks use a combination
25 : of vulnerabilities: Key reuse, and type confusion.
26 :
27 : Key reuse is particularly prevalent with the validator identity key,
28 : the hot Ed25519 key that a validator uses in almost all protocols
29 : that it actively participates in.
30 :
31 : Type confusion occurs when the message payload being signed can be
32 : interpreted as multiple different message types. Usually, this is
33 : categorically prevented by using "signing domains".
34 :
35 : Such attacks are particularly dangerous to validators because their
36 : validator identity key holds an amount of native tokens to
37 : participate in Tower BFT voting. In the worst case, an attacker
38 : could trick a validator into signing an innocuous message (e.g. a
39 : gossip message) that can also be interpreted as a transaction
40 : withdrawing these tokens.
41 :
42 : ### Code Verification
43 :
44 : The safety of this module can be verified using a number of CBMC
45 : proofs composed via deductive reasoning.
46 :
47 : - fd_txn_minsz_proof verifies the constant FD_TXN_MIN_SERIALIZED_SZ.
48 : - fd_txn_ambiguity_gossip_proof verifies that gossip messages cannot
49 : be parsed as transactions.
50 : - fd_keyguard_match_txn_harness verifies that the txn fingerprinting
51 : logic is free of false negatives.
52 : - fd_keyguard_ambiguity_proof verifies that any input up to 2048 byte
53 : size are unambiguous, i.e. either detected by one or none of the
54 : fingerprinting functions.
55 :
56 : Under the hood, CBMC executes the keyguard logic with all possible
57 : inputs (>=2^16384 unique inputs) via symbolic execution. The CBMC
58 : machine model also verifies that the code is free of common
59 : vulnerability classes (memory unsoundness, undefined behavior, …).
60 :
61 : As a result, we know with a high degree of certainty that type
62 : detection logic is free of false negatives. For example, when
63 : fd_keyguard_match sees a transaction, it will always reliably detect
64 : it as one. (fd_keyguard_match might also wrongly fingerprint
65 : arbitrary other inputs as, e.g. transactions. But this is not a
66 : problem, as strict checks follow later on in fd_keyguard_authorize.)
67 :
68 : ### Deployment Context
69 :
70 : fd_keyguard_match is exposed to untrusted "signing request" inputs
71 : and implements the first line of authorization checks in the
72 : keyguard. It is thus a critical component for securing the identity
73 : key.
74 :
75 : ### Implementation Approach
76 :
77 : This code looks awful and scary, but is carefully crafted to meet the
78 : aforementioned high assurance and formal verification requirements.
79 :
80 : Although parsers for the supported message types are available
81 : elsewhere in the codebase, they were not used here due to their time
82 : complexity exceeding the capabilities of CBMC. The time complexity
83 : of all parsers in this compile unit is O(1), which allowed for
84 : complete CBMC coverage.
85 :
86 : TLDR: The following code implements the least possible logic
87 : required to reliably detect types of identity key signing
88 : payloads without false negatives. */
89 :
90 : FD_FN_PURE static int
91 : fd_keyguard_payload_matches_txn_msg( uchar const * data,
92 : ulong sz,
93 6369 : int sign_type ) {
94 :
95 6369 : uchar const * end = data + sz;
96 :
97 6369 : if( sign_type != FD_KEYGUARD_SIGN_TYPE_ED25519 ) return 0;
98 :
99 : /* txn_msg_min_sz is the smallest valid size of a transaction msg. A
100 : transaction is the concatenation of (signature count, signatures,
101 : msg). The smallest size of a txn is FD_TXN_MIN_SERIALIZED_SZ
102 : (formally proven with CBMC in fd_txn_minsz_proof.c). We know the
103 : smallest sizes of "signature count" and "signatures", thus we can
104 : derive the smallest size of "msg". */
105 :
106 6339 : ulong const txn_msg_min_sz =
107 6339 : FD_TXN_MIN_SERIALIZED_SZ
108 6339 : - 1UL /* min sz of signature count (compact_u16 encoding) */
109 6339 : - 64UL; /* min sz of signature list (array of Ed25519 sigs) */
110 6339 : if( sz<txn_msg_min_sz ) return 0;
111 :
112 : /* Message type check.
113 :
114 : Bit patterns of first bytes are as follows
115 :
116 : - 0aaaaaaa bbbbbbbb cccccccc (Legacy txns)
117 : - 10000000 aaaaaaaa bbbbbbbb cccccccc (v0 txns)
118 : - 10000001 aaaaaaaa bbbbbbbb cccccccc (v1 txns)
119 :
120 : Where 'a' are the bits that make up the 'required signature count'
121 : ... 'b' .... 'readonly signed count'
122 : ... 'c' .... 'readonly unsigned count' */
123 :
124 6333 : uchar const * cursor = data;
125 6333 : uint header_b0 = *cursor;
126 6333 : cursor++;
127 6333 : uint sig_cnt; /* sig count (ignoring compact_u16 encoding) */
128 6333 : if( header_b0 & 0x80UL ) {
129 : /* Versioned message, v0 and v1 recognized so far */
130 6330 : uint version = header_b0 & 0x7F;
131 6330 : if( version!=FD_TXN_V0 && version!=FD_TXN_V1 ) return 0;
132 :
133 : /* Check transaction V1 separately because the layout is
134 : different. We do the same checks for V1 and V0/legacy, just in
135 : a different code branch. */
136 6327 : if( version==FD_TXN_V1 ) {
137 6327 : sig_cnt = *cursor;
138 6327 : cursor++;
139 :
140 : /* There must be at least one signature. */
141 6327 : if( sig_cnt==0U ) return 0;
142 :
143 : /* Check if the signatures exceed the V1 limit */
144 6324 : if( sig_cnt>FD_TXN_SIG_MAX ) return 0;
145 :
146 : /* Skip other fields */
147 : //uint ro_signed_cnt = *cursor;
148 6324 : cursor++;
149 : //uint ro_unsigned_cnt = *cursor;
150 6324 : cursor++;
151 : //uint config_mask = fd_uint_load_4( cursor );
152 6324 : cursor += 4UL;
153 : //uchar const * blockhash = cursor;
154 6324 : cursor += FD_TXN_BLOCKHASH_SZ;
155 :
156 6324 : if( cursor + 2 > end ) return 0;
157 6324 : ulong instr_cnt = *cursor;
158 6324 : cursor++;
159 6324 : ulong addr_cnt = *cursor;
160 6324 : cursor++;
161 :
162 : /* Check if the instructions exceed the V1 limit */
163 6324 : if( instr_cnt>FD_TXN_INSTR_MAX ) return 0;
164 :
165 : /* Check if the addresses exceed the V1 limit */
166 6321 : if( addr_cnt>FD_TXN_ACCT_ADDR_MAX ) return 0;
167 :
168 6318 : if( sig_cnt>addr_cnt ) return 0;
169 :
170 6315 : return 1;
171 6318 : }
172 :
173 0 : sig_cnt = *cursor;
174 0 : cursor++;
175 3 : } else {
176 : /* Legacy message */
177 3 : sig_cnt = header_b0;
178 3 : }
179 :
180 : /* There must be at least one signature. */
181 3 : if( sig_cnt==0U ) return 0;
182 :
183 : /* Check if signatures exceed txn size limit */
184 3 : ulong sig_sz;
185 3 : if( __builtin_umull_overflow( sig_cnt, 64UL, &sig_sz ) ) return 0;
186 3 : if( sig_sz > (FD_TXN_MTU_V0-txn_msg_min_sz) ) return 0;
187 :
188 : /* Skip other fields */
189 : //uint ro_signed_cnt = *cursor;
190 3 : cursor++;
191 : //uint ro_unsigned_cnt = *cursor;
192 3 : cursor++;
193 :
194 3 : if( cursor + 3 > end ) return 0;
195 3 : ulong addr_cnt_sz = fd_cu16_dec_sz( cursor, 3UL );
196 3 : if( !addr_cnt_sz ) return 0;
197 3 : ulong addr_cnt = fd_cu16_dec_fixed( cursor, addr_cnt_sz );
198 3 : cursor += addr_cnt_sz;
199 :
200 3 : if( sig_cnt>addr_cnt ) return 0;
201 :
202 3 : return 1;
203 3 : }
204 :
205 : FD_FN_PURE static int
206 : fd_keyguard_payload_matches_ping_msg( uchar const * data,
207 : ulong sz,
208 6369 : int sign_type ) {
209 6369 : return sign_type==FD_KEYGUARD_SIGN_TYPE_ED25519 &&
210 6369 : sz==32UL &&
211 6369 : (memcmp( data, "SOLANA_PING_PONG", 16UL ) == 0);
212 6369 : }
213 :
214 : FD_FN_PURE static int
215 : fd_keyguard_payload_matches_pong_msg( uchar const * data,
216 : ulong sz,
217 6369 : int sign_type ) {
218 6369 : return sign_type==FD_KEYGUARD_SIGN_TYPE_SHA256_ED25519 &&
219 6369 : sz==48UL &&
220 6369 : (memcmp( data, "SOLANA_PING_PONG", 16UL ) == 0);
221 6369 : }
222 :
223 : FD_FN_PURE static int
224 : fd_keyguard_payload_matches_prune_data( uchar const * data,
225 : ulong sz,
226 6369 : int sign_type ) {
227 6369 : if( sign_type != FD_KEYGUARD_SIGN_TYPE_ED25519 ) return 0;
228 :
229 6339 : ulong const static_sz = 106UL;
230 6339 : if( sz < static_sz ) return 0;
231 :
232 6312 : if( FD_LOAD( ulong, data )!=18UL ) return 0;
233 0 : if( memcmp( data+8UL, "\xffSOLANA_PRUNE_DATA", 18UL ) ) return 0;
234 :
235 0 : ulong prune_cnt = FD_LOAD( ulong, data+58UL );
236 0 : ulong expected_sz;
237 0 : if( __builtin_umull_overflow( prune_cnt, 32UL, &expected_sz ) ) return 0;
238 0 : if( __builtin_uaddl_overflow( expected_sz, static_sz, &expected_sz ) ) return 0;
239 0 : if( sz != expected_sz ) return 0;
240 :
241 0 : return 1;
242 0 : }
243 :
244 : FD_FN_PURE static int
245 : fd_keyguard_payload_matches_gossip( uchar const * data,
246 : ulong sz,
247 6369 : int sign_type ) {
248 :
249 : /* All gossip messages except pings use raw signing */
250 6369 : if( sign_type != FD_KEYGUARD_SIGN_TYPE_ED25519 ) return 0;
251 :
252 : /* Every gossip message contains a 4 byte enum variant tag (at the
253 : beginning of the message) and a 32 byte public key (at an arbitrary
254 : location). */
255 6339 : if( sz<36UL ) return 0;
256 :
257 6336 : uint tag = FD_LOAD( uint, data );
258 :
259 6336 : return tag<FD_GOSSIP_VALUE_CNT;
260 6339 : }
261 :
262 : FD_FN_PURE static int
263 : fd_keyguard_payload_matches_repair( uchar const * data,
264 : ulong sz,
265 6369 : int sign_type ) {
266 :
267 : /* All repair messages except pings use raw signing */
268 6369 : if( sign_type != FD_KEYGUARD_SIGN_TYPE_ED25519 ) return 0;
269 :
270 : /* Every repair message contains a 4 byte enum variant tag (at the
271 : beginning of the message) and a 32 byte public key (at an arbitrary
272 : location). */
273 6339 : if( sz<36UL ) return 0;
274 :
275 : /* Ensure that the kind matches a possible repair request. */
276 6336 : uint kind = FD_LOAD( uint, data );
277 6336 : if( (kind==FD_REPAIR_KIND_SHRED)
278 6336 : | (kind==FD_REPAIR_KIND_HIGHEST_SHRED)
279 6336 : | (kind==FD_REPAIR_KIND_ORPHAN)
280 6336 : | (kind==AG_REPAIR_KIND_PARENT_FEC_COUNT)
281 6336 : | (kind==AG_REPAIR_KIND_FEC_ROOT)
282 6336 : | (kind==AG_REPAIR_KIND_SHRED_FOR_BLOCK_ID) )
283 0 : return 1;
284 :
285 6336 : return 0;
286 6336 : }
287 :
288 : FD_FN_PURE int
289 : fd_keyguard_payload_matches_shred( uchar const * data,
290 : ulong sz,
291 6369 : int sign_type ) {
292 6369 : (void)data;
293 :
294 : /* Note: Legacy shreds no longer relevant (drop_legacy_shreds) */
295 :
296 : /* FIXME: Sign Merkle shreds using SIGN_TYPE_SHA256_ED25519 (!!!) */
297 6369 : if( sign_type != FD_KEYGUARD_SIGN_TYPE_ED25519 ) return 0;
298 6339 : if( sz != 32 ) return 0;
299 :
300 0 : return 1;
301 6339 : }
302 :
303 : FD_FN_PURE int
304 : fd_keyguard_payload_matches_tls_cv( uchar const * data,
305 : ulong sz,
306 6369 : int sign_type ) {
307 :
308 6369 : if( sign_type != FD_KEYGUARD_SIGN_TYPE_ED25519 ) return 0;
309 :
310 : /* TLS CertificateVerify signing payload one of 3 sizes
311 : depending on hash function chosen */
312 6339 : switch( sz ) {
313 0 : case 130UL: break; /* Prefix + 32 byte hash */
314 0 : case 146UL: break; /* Prefix + 48 byte hash */
315 0 : case 162UL: break; /* Prefix + 64 byte hash */
316 6339 : default:
317 6339 : return 0;
318 6339 : }
319 :
320 : /* Always prefixed with client or server pattern */
321 0 : static char const client_prefix[ 98 ] =
322 0 : " " /* 32 spaces */
323 0 : " " /* 32 spaces */
324 0 : "TLS 1.3, client CertificateVerify";
325 :
326 0 : static char const server_prefix[ 98 ] =
327 0 : " " /* 32 spaces */
328 0 : " " /* 32 spaces */
329 0 : "TLS 1.3, server CertificateVerify";
330 0 : int is_client = 0==memcmp( data, client_prefix, 98UL );
331 0 : int is_server = 0==memcmp( data, server_prefix, 98UL );
332 0 : return (is_client)|(is_server);
333 6339 : }
334 :
335 : FD_FN_PURE int
336 : fd_keyguard_payload_matches_ag_vote( uchar const * data,
337 : ulong sz,
338 6369 : int sign_type ) {
339 :
340 : /* Alpenglow vote payload produced by ag_vote_signing_ser:
341 :
342 : u8 tag (1..5, WireConsensusMessageKind vote tags)
343 : u64 slot
344 : [32 bytes block id] only for notar (1) and notar fallback (4)
345 : u16 shred_version */
346 :
347 6369 : if( sign_type != FD_KEYGUARD_SIGN_TYPE_BLS ) return 0;
348 24 : if( sz!=11UL && sz!=43UL ) return 0;
349 24 : uchar tag = data[ 0 ];
350 24 : if( tag<1 || tag>5 ) return 0;
351 18 : int has_hash = ( tag==1 ) | ( tag==4 );
352 18 : return has_hash ? ( sz==43UL ) : ( sz==11UL );
353 24 : }
354 :
355 : FD_FN_PURE int
356 : fd_keyguard_payload_matches_bundle( uchar const * data,
357 : ulong sz,
358 6369 : int sign_type ) {
359 6369 : (void)data;
360 :
361 6369 : if( sign_type != FD_KEYGUARD_SIGN_TYPE_PUBKEY_CONCAT_ED25519 ) return 0;
362 3 : if( sz!=9UL ) return 0;
363 :
364 0 : return 1;
365 3 : }
366 :
367 : FD_FN_PURE int
368 : fd_keyguard_payload_matches_event( uchar const * data,
369 : ulong sz,
370 6369 : int sign_type ) {
371 6369 : static char const sign_prefix[ 100 ] =
372 6369 : " " /* 32 spaces */
373 6369 : " " /* 32 spaces */
374 6369 : "Firedancer event challenge-response";
375 :
376 6369 : if( sz!=sizeof(sign_prefix)+217UL ) return 0;
377 0 : if( sign_type!=FD_KEYGUARD_SIGN_TYPE_ED25519 ) return 0;
378 0 : if( 0!=memcmp( data, sign_prefix, sizeof(sign_prefix) ) ) return 0;
379 0 : return 1;
380 0 : }
381 :
382 : FD_FN_PURE ulong
383 : fd_keyguard_payload_match( uchar const * data,
384 : ulong sz,
385 6369 : int sign_type ) {
386 6369 : ulong res = 0UL;
387 6369 : res |= fd_ulong_if( fd_keyguard_payload_matches_txn_msg ( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_TXN, 0 );
388 6369 : res |= fd_ulong_if( fd_keyguard_payload_matches_gossip ( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_GOSSIP, 0 );
389 6369 : res |= fd_ulong_if( fd_keyguard_payload_matches_repair ( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_REPAIR, 0 );
390 6369 : res |= fd_ulong_if( fd_keyguard_payload_matches_prune_data( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_PRUNE, 0 );
391 6369 : res |= fd_ulong_if( fd_keyguard_payload_matches_shred ( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_SHRED, 0 );
392 6369 : res |= fd_ulong_if( fd_keyguard_payload_matches_tls_cv ( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_TLS_CV, 0 );
393 6369 : res |= fd_ulong_if( fd_keyguard_payload_matches_ping_msg ( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_PING, 0 );
394 6369 : res |= fd_ulong_if( fd_keyguard_payload_matches_pong_msg ( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_PONG, 0 );
395 6369 : res |= fd_ulong_if( fd_keyguard_payload_matches_bundle ( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_BUNDLE, 0 );
396 6369 : res |= fd_ulong_if( fd_keyguard_payload_matches_event ( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_EVENT, 0 );
397 6369 : res |= fd_ulong_if( fd_keyguard_payload_matches_ag_vote ( data, sz, sign_type ), FD_KEYGUARD_PAYLOAD_AG_VOTE, 0 );
398 6369 : return res;
399 6369 : }
|