Line data Source code
1 : #include "fd_system_program.h"
2 : #include "../fd_borrowed_account.h"
3 : #include "../fd_system_ids.h"
4 : #include "../sysvar/fd_sysvar_rent.h"
5 : #include "../sysvar/fd_sysvar_recent_hashes.h"
6 : #include "../../log_collector/fd_log_collector.h"
7 : #include "../../../ballet/sha256/fd_sha256.h"
8 :
9 : static int
10 : require_acct( fd_exec_instr_ctx_t * ctx,
11 : ushort idx,
12 12 : fd_pubkey_t const * pubkey ) {
13 :
14 : /* https://github.com/anza-xyz/agave/blob/v2.1.14/program-runtime/src/sysvar_cache.rs#L290-L294 */
15 12 : fd_pubkey_t const * acc_key = NULL;
16 12 : int err = fd_exec_instr_ctx_get_key_of_account_at_index( ctx, idx, &acc_key );
17 12 : if( FD_UNLIKELY( err ) ) return err;
18 :
19 12 : if( FD_UNLIKELY( 0!=memcmp( acc_key, pubkey->uc, sizeof(fd_pubkey_t) ) ) )
20 0 : return FD_EXECUTOR_INSTR_ERR_INVALID_ARG;
21 :
22 12 : return FD_EXECUTOR_INSTR_SUCCESS;
23 12 : }
24 :
25 : static int
26 : require_acct_rent( fd_exec_instr_ctx_t * ctx,
27 : ushort idx,
28 3 : fd_rent_t * rent ) {
29 :
30 3 : do {
31 3 : int err = require_acct( ctx, idx, &fd_sysvar_rent_id );
32 3 : if( FD_UNLIKELY( err ) ) return err;
33 3 : } while(0);
34 :
35 3 : if( FD_UNLIKELY( !fd_sysvar_cache_rent_read( ctx->sysvar_cache, rent ) ) )
36 0 : return FD_EXECUTOR_INSTR_ERR_UNSUPPORTED_SYSVAR;
37 :
38 3 : return FD_EXECUTOR_INSTR_SUCCESS;
39 3 : }
40 :
41 : static int
42 : require_acct_recent_blockhashes( fd_exec_instr_ctx_t * ctx,
43 9 : ushort idx ) {
44 9 : int err = require_acct( ctx, idx, &fd_sysvar_recent_block_hashes_id );
45 9 : if( FD_UNLIKELY( err ) ) return err;
46 :
47 9 : if( FD_UNLIKELY( !fd_sysvar_cache_recent_hashes_is_valid( ctx->sysvar_cache ) ) ) {
48 0 : return FD_EXECUTOR_INSTR_ERR_UNSUPPORTED_SYSVAR;
49 0 : }
50 :
51 9 : return FD_EXECUTOR_INSTR_SUCCESS;
52 9 : }
53 :
54 : /* most_recent_block_hash mirrors
55 : solana_runtime::bank::Bank::last_blockhash_and_lamports_per_signature
56 :
57 : https://github.com/solana-labs/solana/blob/v1.17.23/runtime/src/bank.rs#L4033-L4040 */
58 :
59 : static int
60 : most_recent_block_hash( fd_exec_instr_ctx_t * ctx,
61 9 : fd_blockhash_info_t * out ) {
62 : /* The environment config blockhash comes from `bank.last_blockhash_and_lamports_per_signature()`,
63 : which takes the top element from the blockhash queue.
64 : https://github.com/anza-xyz/agave/blob/v2.1.6/programs/system/src/system_instruction.rs#L47 */
65 9 : fd_blockhashes_t const * blockhashes = &ctx->bank->f.block_hash_queue;
66 9 : fd_blockhash_info_t const * last_bhash_info = fd_blockhashes_peek_last( blockhashes );
67 9 : if( FD_UNLIKELY( last_bhash_info==NULL ) ) {
68 : // Agave panics if this blockhash was never set at the start of the txn batch
69 0 : ctx->txn_out->err.custom_err = FD_SYSTEM_PROGRAM_ERR_NONCE_NO_RECENT_BLOCKHASHES;
70 0 : return FD_EXECUTOR_INSTR_ERR_CUSTOM_ERR;
71 0 : }
72 :
73 9 : *out = *last_bhash_info;
74 9 : return FD_EXECUTOR_INSTR_SUCCESS;
75 9 : }
76 :
77 : static void
78 : fd_durable_nonce_from_blockhash( fd_hash_t * out,
79 411 : fd_hash_t const * blockhash ) {
80 411 : uchar buf[45];
81 411 : memcpy( buf, "DURABLE_NONCE", 13UL );
82 411 : memcpy( buf+13, blockhash, sizeof(fd_hash_t) );
83 411 : fd_sha256_hash( buf, sizeof(buf), out );
84 411 : }
85 :
86 : /* fd_system_program_set_nonce_state is a helper for updating the
87 : contents of a nonce account.
88 :
89 : Matches solana_sdk::transaction_context::BorrowedAccount::set_state
90 : https://github.com/solana-labs/solana/blob/v1.17.23/sdk/src/transaction_context.rs#L1020-L1029 */
91 :
92 : static int
93 : fd_system_program_set_nonce_state( fd_borrowed_account_t * account,
94 9 : fd_nonce_state_versions_t const * new_state ) {
95 :
96 : /* https://github.com/solana-labs/solana/blob/v1.17.23/sdk/src/transaction_context.rs#L1021
97 : => https://github.com/solana-labs/solana/blob/v1.17.23/sdk/src/transaction_context.rs#L868 */
98 :
99 9 : uchar * data = NULL;
100 9 : ulong dlen = 0UL;
101 9 : int err = fd_borrowed_account_get_data_mut( account, &data, &dlen );
102 9 : if( FD_UNLIKELY( err ) ) return err;
103 :
104 : /* https://github.com/solana-labs/solana/blob/v1.17.23/sdk/src/transaction_context.rs#L1024-L1026 */
105 :
106 9 : if( FD_UNLIKELY( fd_nonce_state_versions_size( new_state ) > fd_borrowed_account_get_data_len( account ) ) )
107 0 : return FD_EXECUTOR_INSTR_ERR_ACC_DATA_TOO_SMALL;
108 :
109 : /* https://github.com/solana-labs/solana/blob/v1.17.23/sdk/src/transaction_context.rs#L1027 */
110 :
111 9 : ulong written = 0UL;
112 9 : if( FD_UNLIKELY( fd_nonce_state_versions_encode( new_state, data, dlen, &written ) ) ) {
113 0 : return FD_EXECUTOR_INSTR_ERR_GENERIC_ERR;
114 0 : }
115 :
116 9 : return FD_EXECUTOR_INSTR_SUCCESS;
117 9 : }
118 :
119 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L20-L70
120 :
121 : Matches Solana Labs system_instruction::advance_nonce_account */
122 :
123 : static int
124 : fd_system_program_advance_nonce_account( fd_exec_instr_ctx_t * ctx,
125 : fd_borrowed_account_t * account,
126 6 : ushort instr_acc_idx ) {
127 :
128 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L25-L32 */
129 :
130 6 : if( FD_UNLIKELY( !fd_instr_acc_is_writable_idx( ctx->instr, instr_acc_idx ) ) ) {
131 : /* Max msg_sz: 50 - 2 + 45 = 93 < 127 => we can use printf */
132 0 : FD_BASE58_ENCODE_32_BYTES( account->acc->pubkey, pubkey_b58 );
133 0 : fd_log_collector_printf_dangerous_max_127( ctx,
134 0 : "Advance nonce account: Account %s must be writeable", pubkey_b58 );
135 0 : return FD_EXECUTOR_INSTR_ERR_INVALID_ARG;
136 0 : }
137 :
138 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L34 */
139 :
140 6 : fd_nonce_state_versions_t state[1];
141 6 : if( FD_UNLIKELY( fd_nonce_state_versions_decode(
142 6 : state,
143 6 : fd_borrowed_account_get_data( account ),
144 6 : fd_borrowed_account_get_data_len( account ) ) ) ) {
145 0 : return FD_EXECUTOR_INSTR_ERR_INVALID_ACC_DATA;
146 0 : }
147 :
148 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L35 */
149 :
150 6 : if( state->kind==FD_NONCE_STATE_UNINITIALIZED ) {
151 : /* Max msg_sz: 50 - 2 + 45 = 93 < 127 => we can use printf */
152 0 : FD_BASE58_ENCODE_32_BYTES( account->acc->pubkey, pubkey_b58 );
153 0 : fd_log_collector_printf_dangerous_max_127( ctx,
154 0 : "Advance nonce account: Account %s state is invalid", pubkey_b58 );
155 0 : return FD_EXECUTOR_INSTR_ERR_INVALID_ACC_DATA;
156 0 : }
157 :
158 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L37-L44 */
159 :
160 6 : if( FD_UNLIKELY( !fd_exec_instr_ctx_any_signed( ctx, &state->authority ) ) ) {
161 : /* Max msg_sz: 50 - 2 + 45 = 93 < 127 => we can use printf */
162 0 : FD_BASE58_ENCODE_32_BYTES( state->authority.key, authority_b58 );
163 0 : fd_log_collector_printf_dangerous_max_127( ctx,
164 0 : "Advance nonce account: Account %s must be a signer", authority_b58 );
165 0 : return FD_EXECUTOR_INSTR_ERR_MISSING_REQUIRED_SIGNATURE;
166 0 : }
167 :
168 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L45 */
169 :
170 6 : fd_blockhash_info_t blockhash[1];
171 6 : do {
172 6 : int err = most_recent_block_hash( ctx, blockhash );
173 6 : if( FD_UNLIKELY( err ) ) return err;
174 6 : } while(0);
175 :
176 6 : fd_hash_t next_durable_nonce;
177 6 : fd_durable_nonce_from_blockhash( &next_durable_nonce, &blockhash->hash );
178 :
179 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L46-L52 */
180 :
181 6 : if( FD_UNLIKELY( 0==memcmp( state->durable_nonce.hash, next_durable_nonce.hash, sizeof(fd_hash_t) ) ) ) {
182 0 : fd_log_collector_msg_literal( ctx, "Advance nonce account: nonce can only advance once per slot" );
183 0 : ctx->txn_out->err.custom_err = FD_SYSTEM_PROGRAM_ERR_NONCE_BLOCKHASH_NOT_EXPIRED;
184 0 : return FD_EXECUTOR_INSTR_ERR_CUSTOM_ERR;
185 0 : }
186 :
187 : /* https://github.com/anza-xyz/agave/blob/v3.0.3/programs/system/src/system_instruction.rs#L57-L63 */
188 :
189 6 : fd_nonce_state_versions_t new_state = {
190 6 : .version = FD_NONCE_VERSION_CURRENT,
191 6 : .kind = FD_NONCE_STATE_INITIALIZED,
192 6 : .authority = state->authority,
193 6 : .durable_nonce = next_durable_nonce,
194 6 : .lamports_per_signature = blockhash->lamports_per_signature
195 6 : };
196 :
197 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L59 */
198 :
199 6 : do {
200 6 : int err = fd_system_program_set_nonce_state( account, &new_state );
201 6 : if( FD_UNLIKELY( err ) ) return err;
202 6 : } while(0);
203 :
204 6 : return FD_EXECUTOR_INSTR_SUCCESS;
205 6 : }
206 :
207 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L423-L441
208 :
209 : Matches Solana Labs system_processor SystemInstruction::AdvanceNonceAccount => { ... } */
210 :
211 : int
212 6 : fd_system_program_exec_advance_nonce_account( fd_exec_instr_ctx_t * ctx ) {
213 6 : int err;
214 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L423-L441 */
215 :
216 6 : if( FD_UNLIKELY( ctx->instr->acct_cnt < 1 ) )
217 0 : return FD_EXECUTOR_INSTR_ERR_MISSING_ACC;
218 :
219 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L425-L426 */
220 :
221 6 : uchar const instr_acc_idx = 0;
222 :
223 : /* https://github.com/anza-xyz/agave/blob/v2.1.14/programs/system/src/system_processor.rs#L409-L410 */
224 :
225 6 : fd_guarded_borrowed_account_t account = {0};
226 6 : FD_TRY_BORROW_INSTR_ACCOUNT_DEFAULT_ERR_CHECK( ctx, instr_acc_idx, &account );
227 :
228 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L427-L432 */
229 :
230 6 : err = require_acct_recent_blockhashes( ctx, 1UL );
231 6 : if( FD_UNLIKELY( err ) ) return err;
232 :
233 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L433-L439 */
234 :
235 6 : if( FD_UNLIKELY( fd_sysvar_cache_recent_hashes_is_empty( ctx->sysvar_cache ) ) ) {
236 0 : fd_log_collector_msg_literal( ctx, "Advance nonce account: recent blockhash list is empty" );
237 0 : ctx->txn_out->err.custom_err = FD_SYSTEM_PROGRAM_ERR_NONCE_NO_RECENT_BLOCKHASHES;
238 0 : return FD_EXECUTOR_INSTR_ERR_CUSTOM_ERR;
239 0 : }
240 :
241 6 : err = fd_system_program_advance_nonce_account( ctx, &account, instr_acc_idx );
242 :
243 : /* Implicit drop */
244 :
245 6 : return err;
246 6 : }
247 :
248 : /* https://github.com/anza-xyz/agave/blob/7585b70d5ea5fcbb1710636ad429580a18f42c2a/programs/system/src/system_instruction.rs#L99-L109 */
249 :
250 : static int
251 : withdraw_nonce_check_signer( fd_exec_instr_ctx_t * ctx,
252 0 : fd_pubkey_t const * signer ) {
253 0 : if( FD_UNLIKELY( !fd_exec_instr_ctx_any_signed( ctx, signer ) ) ) {
254 : /* Max msg_sz: 44 - 2 + 45 = 87 < 127 => we can use printf */
255 0 : FD_BASE58_ENCODE_32_BYTES( signer->key, signer_b58 );
256 0 : fd_log_collector_printf_dangerous_max_127( ctx,
257 0 : "Withdraw nonce account: Account %s must sign", signer_b58 );
258 0 : return FD_EXECUTOR_INSTR_ERR_MISSING_REQUIRED_SIGNATURE;
259 0 : }
260 0 : return FD_EXECUTOR_INSTR_SUCCESS;
261 0 : }
262 :
263 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L72-L151
264 :
265 : Matches Solana Labs system_instruction::withdraw_nonce_account */
266 :
267 : static int
268 : fd_system_program_withdraw_nonce_account( fd_exec_instr_ctx_t * ctx,
269 : ulong requested_lamports,
270 0 : fd_rent_t const * rent ) {
271 0 : int err;
272 0 : ushort const from_acct_idx = 0UL;
273 0 : ushort const to_acct_idx = 1UL;
274 :
275 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L82-L83 */
276 :
277 0 : fd_guarded_borrowed_account_t from = {0};
278 0 : FD_TRY_BORROW_INSTR_ACCOUNT_DEFAULT_ERR_CHECK( ctx, from_acct_idx, &from );
279 :
280 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L84-L91 */
281 :
282 0 : if( FD_UNLIKELY( !fd_instr_acc_is_writable_idx( ctx->instr, from_acct_idx ) ) ) {
283 : /* Max msg_sz: 51 - 2 + 45 = 94 < 127 => we can use printf */
284 0 : FD_BASE58_ENCODE_32_BYTES( from.acc->pubkey, pubkey_b58 );
285 0 : fd_log_collector_printf_dangerous_max_127( ctx,
286 0 : "Withdraw nonce account: Account %s must be writeable", pubkey_b58 );
287 0 : return FD_EXECUTOR_INSTR_ERR_INVALID_ARG;
288 0 : }
289 :
290 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L93 */
291 :
292 0 : fd_nonce_state_versions_t state[1];
293 0 : if( FD_UNLIKELY( fd_nonce_state_versions_decode(
294 0 : state,
295 0 : fd_borrowed_account_get_data( &from ),
296 0 : fd_borrowed_account_get_data_len( &from ) ) ) ) {
297 0 : return FD_EXECUTOR_INSTR_ERR_INVALID_ACC_DATA;
298 0 : }
299 :
300 : /* TODO: update permalinks once Agave 4.1 tag has been created */
301 : /* https://github.com/anza-xyz/agave/blob/7585b70d5ea5fcbb1710636ad429580a18f42c2a/programs/system/src/system_instruction.rs#L112-L153 */
302 :
303 0 : if( state->kind==FD_NONCE_STATE_UNINITIALIZED ) {
304 : /* https://github.com/anza-xyz/agave/blob/7585b70d5ea5fcbb1710636ad429580a18f42c2a/programs/system/src/system_instruction.rs#L113-L124 */
305 :
306 0 : if( FD_UNLIKELY( requested_lamports > fd_borrowed_account_get_lamports( &from ) ) ) {
307 : /* Max msg_sz: 59 - 6 + 20 + 20 = 93 < 127 => we can use printf */
308 0 : fd_log_collector_printf_dangerous_max_127( ctx,
309 0 : "Withdraw nonce account: insufficient lamports %lu, need %lu", fd_borrowed_account_get_lamports( &from ), requested_lamports );
310 0 : return FD_EXECUTOR_INSTR_ERR_INSUFFICIENT_FUNDS;
311 0 : }
312 :
313 : /* https://github.com/anza-xyz/agave/blob/7585b70d5ea5fcbb1710636ad429580a18f42c2a/programs/system/src/system_instruction.rs#L123 */
314 :
315 0 : do {
316 0 : int err = withdraw_nonce_check_signer( ctx, (fd_pubkey_t const*)from.acc->pubkey );
317 0 : if( FD_UNLIKELY( err ) ) return err;
318 0 : } while(0);
319 :
320 0 : } else { /* FD_NONCE_STATE_INITIALIZED */
321 : /* https://github.com/anza-xyz/agave/blob/7585b70d5ea5fcbb1710636ad429580a18f42c2a/programs/system/src/system_instruction.rs#L125-L152 */
322 :
323 0 : if( requested_lamports == fd_borrowed_account_get_lamports( &from ) ) {
324 : /* https://github.com/anza-xyz/agave/blob/7585b70d5ea5fcbb1710636ad429580a18f42c2a/programs/system/src/system_instruction.rs#L126-L138 */
325 :
326 : /* https://github.com/anza-xyz/agave/blob/7585b70d5ea5fcbb1710636ad429580a18f42c2a/programs/system/src/system_instruction.rs#L127-L128 */
327 :
328 0 : fd_blockhash_info_t blockhash[1];
329 0 : do {
330 0 : int err = most_recent_block_hash( ctx, blockhash );
331 0 : if( FD_UNLIKELY( err ) ) return err;
332 0 : } while(0);
333 :
334 0 : fd_hash_t next_durable_nonce;
335 0 : fd_durable_nonce_from_blockhash( &next_durable_nonce, &blockhash->hash );
336 :
337 : /* https://github.com/anza-xyz/agave/blob/7585b70d5ea5fcbb1710636ad429580a18f42c2a/programs/system/src/system_instruction.rs#L129-L135 */
338 :
339 0 : if( FD_UNLIKELY( 0==memcmp( state->durable_nonce.hash, next_durable_nonce.hash, sizeof(fd_hash_t) ) ) ) {
340 0 : fd_log_collector_msg_literal( ctx, "Withdraw nonce account: nonce can only advance once per slot" );
341 0 : ctx->txn_out->err.custom_err = FD_SYSTEM_PROGRAM_ERR_NONCE_BLOCKHASH_NOT_EXPIRED;
342 0 : return FD_EXECUTOR_INSTR_ERR_CUSTOM_ERR;
343 0 : }
344 :
345 : /* https://github.com/anza-xyz/agave/blob/7585b70d5ea5fcbb1710636ad429580a18f42c2a/programs/system/src/system_instruction.rs#L136 */
346 :
347 0 : do {
348 0 : int err = withdraw_nonce_check_signer( ctx, &state->authority );
349 0 : if( FD_UNLIKELY( err ) ) return err;
350 0 : } while(0);
351 :
352 : /* https://github.com/anza-xyz/agave/blob/7585b70d5ea5fcbb1710636ad429580a18f42c2a/programs/system/src/system_instruction.rs#L137 */
353 :
354 0 : fd_nonce_state_versions_t new_state[1] = {{
355 0 : .version = FD_NONCE_VERSION_CURRENT,
356 0 : .kind = FD_NONCE_STATE_UNINITIALIZED
357 0 : }};
358 :
359 0 : do {
360 0 : int err = fd_system_program_set_nonce_state( &from, new_state );
361 0 : if( FD_UNLIKELY( err ) ) return err;
362 0 : } while(0);
363 :
364 0 : } else {
365 : /* https://github.com/anza-xyz/agave/blob/7585b70d5ea5fcbb1710636ad429580a18f42c2a/programs/system/src/system_instruction.rs#L138-L151 */
366 :
367 : /* https://github.com/anza-xyz/agave/blob/7585b70d5ea5fcbb1710636ad429580a18f42c2a/programs/system/src/system_instruction.rs#L139-L140 */
368 :
369 0 : ulong min_balance = fd_rent_exempt_minimum_balance( rent, fd_borrowed_account_get_data_len( &from ) );
370 :
371 0 : ulong amount;
372 0 : if( FD_UNLIKELY( __builtin_uaddl_overflow( requested_lamports, min_balance, &amount ) ) )
373 0 : return FD_EXECUTOR_INSTR_ERR_INSUFFICIENT_FUNDS;
374 :
375 : /* https://github.com/anza-xyz/agave/blob/7585b70d5ea5fcbb1710636ad429580a18f42c2a/programs/system/src/system_instruction.rs#L141-L149 */
376 :
377 0 : if( FD_UNLIKELY( amount > fd_borrowed_account_get_lamports( &from ) ) ) {
378 : /* Max msg_sz: 59 - 6 + 20 + 20 = 93 < 127 => we can use printf */
379 0 : fd_log_collector_printf_dangerous_max_127( ctx,
380 0 : "Withdraw nonce account: insufficient lamports %lu, need %lu", fd_borrowed_account_get_lamports( &from ), amount );
381 0 : return FD_EXECUTOR_INSTR_ERR_INSUFFICIENT_FUNDS;
382 0 : }
383 :
384 : /* https://github.com/anza-xyz/agave/blob/7585b70d5ea5fcbb1710636ad429580a18f42c2a/programs/system/src/system_instruction.rs#L150 */
385 :
386 0 : do {
387 0 : int err = withdraw_nonce_check_signer( ctx, &state->authority );
388 0 : if( FD_UNLIKELY( err ) ) return err;
389 0 : } while(0);
390 :
391 0 : }
392 0 : }
393 :
394 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L144 */
395 :
396 0 : err = fd_borrowed_account_checked_sub_lamports( &from, requested_lamports );
397 0 : if( FD_UNLIKELY( err ) ) return err;
398 :
399 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L145 */
400 :
401 0 : fd_borrowed_account_drop( &from );
402 :
403 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L146-L147 */
404 :
405 0 : fd_guarded_borrowed_account_t to = {0};
406 0 : FD_TRY_BORROW_INSTR_ACCOUNT_DEFAULT_ERR_CHECK( ctx, to_acct_idx, &to );
407 :
408 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L148 */
409 :
410 0 : err = fd_borrowed_account_checked_add_lamports( &to, requested_lamports );
411 0 : if( FD_UNLIKELY( err ) ) return err;
412 :
413 : /* Implicit drop */
414 :
415 0 : return FD_EXECUTOR_INSTR_SUCCESS;
416 0 : }
417 :
418 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L442-L461
419 :
420 : Matches Solana Labs system_processor SystemInstruction::WithdrawNonceAccount { ... } => { ... } */
421 :
422 : int
423 : fd_system_program_exec_withdraw_nonce_account( fd_exec_instr_ctx_t * ctx,
424 0 : ulong requested_lamports ) {
425 :
426 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L443 */
427 :
428 0 : if( FD_UNLIKELY( ctx->instr->acct_cnt < 2 ) )
429 0 : return FD_EXECUTOR_INSTR_ERR_MISSING_ACC;
430 :
431 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L445-L449 */
432 :
433 0 : do {
434 0 : int err = require_acct_recent_blockhashes( ctx, 2UL );
435 0 : if( FD_UNLIKELY( err ) ) return err;
436 0 : } while(0);
437 :
438 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L450 */
439 :
440 0 : fd_rent_t rent[1];
441 0 : do {
442 0 : int err = require_acct_rent( ctx, 3UL, rent );
443 0 : if( FD_UNLIKELY( err ) ) return err;
444 0 : } while(0);
445 :
446 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L451-L460 */
447 :
448 0 : return fd_system_program_withdraw_nonce_account( ctx, requested_lamports, rent );
449 0 : }
450 :
451 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L153-L198
452 :
453 : Matches Solana Labs system_instruction::initialize_nonce_account */
454 :
455 : static int
456 : fd_system_program_initialize_nonce_account( fd_exec_instr_ctx_t * ctx,
457 : fd_borrowed_account_t * account,
458 : fd_pubkey_t const * authorized,
459 3 : fd_rent_t const * rent ) {
460 :
461 : /* https://github.com/anza-xyz/agave/blob/v2.2.0/programs/system/src/system_instruction.rs#L167-L174 */
462 :
463 3 : if( FD_UNLIKELY( !fd_borrowed_account_is_writable( account ) ) ) {
464 : /* Max msg_sz: 53 - 2 + 45 = 96 < 127 => we can use printf */
465 0 : FD_BASE58_ENCODE_32_BYTES( account->acc->pubkey, pubkey_b58 );
466 0 : fd_log_collector_printf_dangerous_max_127( ctx,
467 0 : "Initialize nonce account: Account %s must be writeable", pubkey_b58 );
468 0 : return FD_EXECUTOR_INSTR_ERR_INVALID_ARG;
469 0 : }
470 :
471 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L168 */
472 :
473 3 : fd_nonce_state_versions_t state[1];
474 3 : if( FD_UNLIKELY( fd_nonce_state_versions_decode(
475 3 : state,
476 3 : fd_borrowed_account_get_data( account ),
477 3 : fd_borrowed_account_get_data_len( account ) ) ) ) {
478 0 : return FD_EXECUTOR_INSTR_ERR_INVALID_ACC_DATA;
479 0 : }
480 :
481 3 : if( state->kind==FD_NONCE_STATE_INITIALIZED ) {
482 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L189-L196 */
483 :
484 : /* Max msg_sz: 53 - 2 + 45 = 96 < 127 => we can use printf */
485 0 : FD_BASE58_ENCODE_32_BYTES( account->acc->pubkey, pubkey_b58 );
486 0 : fd_log_collector_printf_dangerous_max_127( ctx,
487 0 : "Initialize nonce account: Account %s state is invalid", pubkey_b58 );
488 :
489 0 : return FD_EXECUTOR_INSTR_ERR_INVALID_ACC_DATA;
490 0 : }
491 :
492 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L169-L188 */
493 :
494 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L170 */
495 :
496 3 : ulong min_balance = fd_rent_exempt_minimum_balance( rent, fd_borrowed_account_get_data_len( account ) );
497 :
498 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L171-L179 */
499 :
500 3 : if( FD_UNLIKELY( fd_borrowed_account_get_lamports( account ) < min_balance ) ) {
501 : /* Max msg_sz: 61 - 6 + 20 + 20 = 95 < 127 => we can use printf */
502 0 : fd_log_collector_printf_dangerous_max_127( ctx,
503 0 : "Initialize nonce account: insufficient lamports %lu, need %lu", fd_borrowed_account_get_lamports( account ), min_balance );
504 0 : return FD_EXECUTOR_INSTR_ERR_INSUFFICIENT_FUNDS;
505 0 : }
506 :
507 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L180 */
508 :
509 3 : fd_blockhash_info_t blockhash[1];
510 3 : do {
511 3 : int err = most_recent_block_hash( ctx, blockhash );
512 3 : if( FD_UNLIKELY( err ) ) return err;
513 3 : } while(0);
514 :
515 3 : fd_hash_t durable_nonce;
516 3 : fd_durable_nonce_from_blockhash( &durable_nonce, &blockhash->hash );
517 :
518 : /* https://github.com/anza-xyz/agave/blob/v3.0.3/programs/system/src/system_instruction.rs#L185-L191 */
519 :
520 3 : fd_nonce_state_versions_t new_state = {
521 3 : .version = FD_NONCE_VERSION_CURRENT,
522 3 : .kind = FD_NONCE_STATE_INITIALIZED,
523 3 : .authority = *authorized,
524 3 : .durable_nonce = durable_nonce,
525 3 : .lamports_per_signature = blockhash->lamports_per_signature
526 3 : };
527 :
528 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L187 */
529 :
530 3 : do {
531 3 : int err = fd_system_program_set_nonce_state( account, &new_state );
532 3 : if( FD_UNLIKELY( err ) ) return err;
533 3 : } while(0);
534 :
535 3 : return FD_EXECUTOR_INSTR_SUCCESS;
536 3 : }
537 :
538 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L462-L481
539 :
540 : Matches Solana Labs system_processor SystemInstruction::InitializeNonceAccount { ... } => { ... } */
541 :
542 : int
543 : fd_system_program_exec_initialize_nonce_account( fd_exec_instr_ctx_t * ctx,
544 3 : fd_pubkey_t const * authorized ) {
545 3 : int err;
546 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L463 */
547 :
548 3 : if( FD_UNLIKELY( ctx->instr->acct_cnt < 1 ) )
549 0 : return FD_EXECUTOR_INSTR_ERR_MISSING_ACC;
550 :
551 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L464-L465 */
552 :
553 3 : uchar const instr_acc_idx = 0;
554 : /* https://github.com/anza-xyz/agave/blob/v2.1.14/programs/system/src/system_processor.rs#L448-L449 */
555 3 : fd_guarded_borrowed_account_t account = {0};
556 3 : FD_TRY_BORROW_INSTR_ACCOUNT_DEFAULT_ERR_CHECK( ctx, instr_acc_idx, &account );
557 :
558 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L466-L471 */
559 :
560 3 : do {
561 3 : err = require_acct_recent_blockhashes( ctx, 1UL );
562 3 : if( FD_UNLIKELY( err ) ) return err;
563 3 : } while(0);
564 :
565 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L472-L478 */
566 :
567 3 : if( FD_UNLIKELY( fd_sysvar_cache_recent_hashes_is_empty( ctx->sysvar_cache ) ) ) {
568 0 : fd_log_collector_msg_literal( ctx, "Initialize nonce account: recent blockhash list is empty" );
569 0 : ctx->txn_out->err.custom_err = FD_SYSTEM_PROGRAM_ERR_NONCE_NO_RECENT_BLOCKHASHES;
570 0 : return FD_EXECUTOR_INSTR_ERR_CUSTOM_ERR;
571 0 : }
572 :
573 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L479 */
574 :
575 3 : fd_rent_t rent[1];
576 3 : do {
577 3 : err = require_acct_rent( ctx, 2UL, rent );
578 3 : if( FD_UNLIKELY( err ) ) return err;
579 3 : } while(0);
580 :
581 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L480 */
582 :
583 3 : err = fd_system_program_initialize_nonce_account( ctx, &account, authorized, rent );
584 :
585 : /* Implicit drop */
586 :
587 3 : return err;
588 3 : }
589 :
590 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L200-L236
591 :
592 : Matches Solana Labs system_instruction::authorize_nonce_account */
593 :
594 : static int
595 : fd_system_program_authorize_nonce_account( fd_exec_instr_ctx_t * ctx,
596 : fd_borrowed_account_t * account,
597 : ushort instr_acc_idx,
598 0 : fd_pubkey_t const * nonce_authority ) {
599 :
600 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L206-L213 */
601 :
602 0 : if( FD_UNLIKELY( !fd_instr_acc_is_writable_idx( ctx->instr, instr_acc_idx ) ) ) {
603 : /* Max msg_sz: 52 - 2 + 45 = 95 < 127 => we can use printf */
604 0 : FD_BASE58_ENCODE_32_BYTES( account->acc->pubkey, pubkey_b58 );
605 0 : fd_log_collector_printf_dangerous_max_127( ctx,
606 0 : "Authorize nonce account: Account %s must be writeable", pubkey_b58 );
607 0 : return FD_EXECUTOR_INSTR_ERR_INVALID_ARG;
608 0 : }
609 :
610 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L214-L215 */
611 :
612 0 : fd_nonce_state_versions_t state[1];
613 0 : if( FD_UNLIKELY( fd_nonce_state_versions_decode(
614 0 : state,
615 0 : fd_borrowed_account_get_data( account ),
616 0 : fd_borrowed_account_get_data_len( account ) ) ) ) {
617 0 : return FD_EXECUTOR_INSTR_ERR_INVALID_ACC_DATA;
618 0 : }
619 :
620 : /* Inlining solana_program::nonce::state::Versions::authorize
621 : https://github.com/solana-labs/solana/blob/v1.17.23/sdk/program/src/nonce/state/mod.rs#L76-L102 */
622 :
623 : /* https://github.com/solana-labs/solana/blob/v1.17.23/sdk/program/src/nonce/state/mod.rs#L81-L84 */
624 :
625 0 : if( FD_UNLIKELY( state->kind != FD_NONCE_STATE_INITIALIZED ) ) {
626 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L219-L226 */
627 :
628 : /* Max msg_sz: 52 - 2 + 45 = 95 < 127 => we can use printf */
629 0 : FD_BASE58_ENCODE_32_BYTES( account->acc->pubkey, pubkey_b58 );
630 0 : fd_log_collector_printf_dangerous_max_127( ctx,
631 0 : "Authorize nonce account: Account %s state is invalid", pubkey_b58 );
632 :
633 0 : return FD_EXECUTOR_INSTR_ERR_INVALID_ACC_DATA;
634 0 : }
635 :
636 : /* https://github.com/solana-labs/solana/blob/v1.17.23/sdk/program/src/nonce/state/mod.rs#L85-L89 */
637 :
638 0 : if( FD_UNLIKELY( !fd_exec_instr_ctx_any_signed( ctx, &state->authority ) ) ) {
639 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L227-L234 */
640 : /* Max msg_sz: 45 - 2 + 45 = 88 < 127 => we can use printf */
641 0 : FD_BASE58_ENCODE_32_BYTES( state->authority.key, authority_b58 );
642 0 : fd_log_collector_printf_dangerous_max_127( ctx,
643 0 : "Authorize nonce account: Account %s must sign", authority_b58 );
644 0 : return FD_EXECUTOR_INSTR_ERR_MISSING_REQUIRED_SIGNATURE;
645 0 : }
646 :
647 : /* https://github.com/solana-labs/solana/blob/v1.17.23/sdk/program/src/nonce/state/mod.rs#L90-L101
648 :
649 : Versions::authorize preserves the outer version tag (Legacy stays
650 : Legacy, Current stays Current) and replaces only the inner
651 : authority. */
652 :
653 0 : fd_nonce_state_versions_t new_state[1] = {{
654 0 : .version = state->version,
655 0 : .kind = FD_NONCE_STATE_INITIALIZED,
656 0 : .authority = *nonce_authority,
657 0 : .durable_nonce = state->durable_nonce,
658 0 : .lamports_per_signature = state->lamports_per_signature
659 0 : }};
660 :
661 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_instruction.rs#L218 */
662 :
663 0 : do {
664 0 : int err = fd_system_program_set_nonce_state( account, new_state );
665 0 : if( FD_UNLIKELY( err ) ) return err;
666 0 : } while(0);
667 :
668 0 : return FD_EXECUTOR_INSTR_SUCCESS;
669 0 : }
670 :
671 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L482-L487
672 :
673 : Matches Solana Labs system_processor SystemInstruction::AuthorizeNonceAccount { ... } => { ... } */
674 :
675 : int
676 : fd_system_program_exec_authorize_nonce_account( fd_exec_instr_ctx_t * ctx,
677 0 : fd_pubkey_t const * nonce_authority ) {
678 0 : int err;
679 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L483 */
680 :
681 0 : if( FD_UNLIKELY( ctx->instr->acct_cnt < 1 ) )
682 0 : return FD_EXECUTOR_INSTR_ERR_MISSING_ACC;
683 :
684 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L484-L485 */
685 :
686 0 : fd_guarded_borrowed_account_t account = {0};
687 0 : err = fd_exec_instr_ctx_try_borrow_instr_account( ctx, 0, &account );
688 0 : if( FD_UNLIKELY( err ) ) {
689 0 : return err;
690 0 : }
691 :
692 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L486 */
693 :
694 0 : err = fd_system_program_authorize_nonce_account( ctx, &account, 0UL, nonce_authority );
695 :
696 : /* Implicit drop */
697 :
698 0 : return err;
699 0 : }
700 :
701 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L488-L503
702 :
703 : Matches Solana Labs system_processor SystemInstruction::UpgradeNonceAccount { ... } => { ... } */
704 :
705 : int
706 0 : fd_system_program_exec_upgrade_nonce_account( fd_exec_instr_ctx_t * ctx ) {
707 0 : int err;
708 0 : ushort const nonce_acct_idx = 0UL;
709 :
710 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L489 */
711 :
712 0 : if( FD_UNLIKELY( ctx->instr->acct_cnt < 1 ) )
713 0 : return FD_EXECUTOR_INSTR_ERR_MISSING_ACC;
714 :
715 : /* https://github.com/anza-xyz/agave/blob/v2.1.14/programs/system/src/system_processor.rs#L474-475 */
716 :
717 0 : fd_guarded_borrowed_account_t account = {0};
718 0 : FD_TRY_BORROW_INSTR_ACCOUNT_DEFAULT_ERR_CHECK( ctx, nonce_acct_idx, &account );
719 :
720 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L492-L494 */
721 :
722 0 : if( FD_UNLIKELY( 0!=memcmp( fd_borrowed_account_get_owner( &account ), fd_solana_system_program_id.key, sizeof(fd_pubkey_t) ) ) )
723 0 : return FD_EXECUTOR_INSTR_ERR_INVALID_ACC_OWNER;
724 :
725 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L495-L497 */
726 :
727 0 : if( FD_UNLIKELY( !fd_instr_acc_is_writable_idx( ctx->instr, 0 ) ) )
728 0 : return FD_EXECUTOR_INSTR_ERR_INVALID_ARG;
729 :
730 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L498 */
731 :
732 0 : fd_nonce_state_versions_t state[1];
733 0 : if( FD_UNLIKELY( fd_nonce_state_versions_decode(
734 0 : state,
735 0 : fd_borrowed_account_get_data( &account ),
736 0 : fd_borrowed_account_get_data_len( &account ) ) ) ) {
737 0 : return FD_EXECUTOR_INSTR_ERR_INVALID_ACC_DATA;
738 0 : }
739 :
740 : /* Inlining solana_program::nonce::state::Versions::upgrade
741 : https://github.com/solana-labs/solana/blob/v1.17.23/sdk/program/src/nonce/state/mod.rs#L55-L73 */
742 :
743 0 : if( FD_UNLIKELY( state->version != FD_NONCE_VERSION_LEGACY ) )
744 0 : return FD_EXECUTOR_INSTR_ERR_INVALID_ARG;
745 :
746 0 : if( FD_UNLIKELY( state->kind != FD_NONCE_STATE_INITIALIZED ) )
747 0 : return FD_EXECUTOR_INSTR_ERR_INVALID_ARG;
748 :
749 0 : fd_durable_nonce_from_blockhash( &state->durable_nonce, &state->durable_nonce );
750 :
751 : /* https://github.com/solana-labs/solana/blob/v1.17.23/programs/system/src/system_processor.rs#L501 */
752 :
753 0 : fd_nonce_state_versions_t new_state[1] = {{
754 0 : .version = FD_NONCE_VERSION_CURRENT,
755 0 : .kind = FD_NONCE_STATE_INITIALIZED,
756 0 : .authority = state->authority,
757 0 : .durable_nonce = state->durable_nonce,
758 0 : .lamports_per_signature = state->lamports_per_signature
759 0 : }};
760 :
761 0 : err = fd_system_program_set_nonce_state( &account, new_state );
762 0 : if( FD_UNLIKELY( err ) ) return err;
763 :
764 : /* Implicit drop */
765 :
766 0 : return FD_EXECUTOR_INSTR_SUCCESS;
767 0 : }
768 :
769 : /* https://github.com/anza-xyz/agave/blob/v3.0.3/runtime/src/bank/check_transactions.rs#L166-L200 */
770 : /* The age of a transaction is valid under two conditions. The first is that
771 : the transactions blockhash is a recent blockhash (within 151) in the block
772 : hash queue. The other condition is that the transaction contains a valid
773 : nonce account. This is the case under several conditions. If neither
774 : condition is met then the transaction is invalid.
775 : Note: We check 151 and not 150 due to a known bug in agave. */
776 : int
777 : fd_check_transaction_age( fd_bank_t * bank,
778 : fd_txn_in_t const * txn_in,
779 402 : fd_txn_out_t * txn_out ) {
780 :
781 402 : fd_blockhashes_t const * block_hash_queue = &bank->f.block_hash_queue;
782 402 : fd_hash_t const * last_blockhash = fd_blockhashes_peek_last_hash( block_hash_queue );
783 402 : if( FD_UNLIKELY( !last_blockhash ) ) {
784 0 : FD_LOG_CRIT(( "blockhash queue is empty" ));
785 0 : }
786 :
787 : /* check_transaction_age */
788 402 : fd_hash_t next_durable_nonce = {0};
789 402 : fd_durable_nonce_from_blockhash( &next_durable_nonce, last_blockhash );
790 402 : ushort recent_blockhash_off = TXN( txn_in->txn )->recent_blockhash_off;
791 402 : fd_hash_t * recent_blockhash = (fd_hash_t *)((uchar *)txn_in->txn->payload + recent_blockhash_off);
792 :
793 : /* https://github.com/anza-xyz/agave/blob/16de8b75ebcd57022409b422de557dd37b1de8db/runtime/src/bank.rs#L3538-L3542 */
794 : /* get_hash_info_if_valid. Check 151 hashes from the block hash queue and its
795 : age to see if it is valid. */
796 :
797 402 : if( fd_blockhashes_check_age( block_hash_queue, recent_blockhash, FD_SYSVAR_RECENT_HASHES_CAP ) ) {
798 384 : return FD_RUNTIME_EXECUTE_SUCCESS;
799 384 : }
800 :
801 : /* https://github.com/anza-xyz/agave/blob/16de8b75ebcd57022409b422de557dd37b1de8db/runtime/src/bank.rs#L3622-L3633 */
802 : /* check_and_load_message_nonce_account */
803 18 : if( FD_UNLIKELY( !memcmp( &next_durable_nonce, recent_blockhash, sizeof(fd_hash_t) ) ) ) { /* nonce_is_advanceable == false */
804 3 : return FD_RUNTIME_TXN_ERR_BLOCKHASH_NONCE_ALREADY_ADVANCED;
805 3 : }
806 :
807 : /* https://github.com/anza-xyz/agave/blob/16de8b75ebcd57022409b422de557dd37b1de8db/runtime/src/bank.rs#L3603-L3620*/
808 : /* load_message_nonce_account */
809 :
810 : /* https://github.com/anza-xyz/agave/blob/v2.3.1/svm-transaction/src/svm_message.rs#L87-L119 */
811 : /* get_durable_nonce */
812 15 : if( FD_UNLIKELY( !TXN( txn_in->txn )->instr_cnt ) ) {
813 0 : return FD_RUNTIME_TXN_ERR_BLOCKHASH_NOT_FOUND;
814 0 : }
815 : /* Check the first instruction (nonce instruction) to see if the
816 : program id is the system program. Also make sure that it is an
817 : advance nonce account instruction. Finally make sure that the
818 : first instruction account is writable; if it is, then that account
819 : is a durable nonce account. */
820 15 : fd_txn_instr_t const * txn_instr = &TXN( txn_in->txn )->instr[0];
821 15 : if( FD_UNLIKELY( txn_instr->acct_cnt==0 ) ) {
822 0 : return FD_RUNTIME_TXN_ERR_BLOCKHASH_NOT_FOUND;
823 0 : }
824 :
825 15 : fd_acct_addr_t const * tx_accs = fd_txn_get_acct_addrs( TXN( txn_in->txn ), txn_in->txn->payload );
826 15 : fd_acct_addr_t const * prog_id = tx_accs + txn_instr->program_id;
827 15 : if( FD_UNLIKELY( memcmp( prog_id->b, fd_solana_system_program_id.key, sizeof( fd_pubkey_t ) ) ) ) {
828 0 : return FD_RUNTIME_TXN_ERR_BLOCKHASH_NOT_FOUND;
829 0 : }
830 15 : uchar const * instr_data = fd_txn_get_instr_data( txn_instr, txn_in->txn->payload );
831 15 : uchar const * instr_accts = fd_txn_get_instr_accts( txn_instr, txn_in->txn->payload );
832 15 : uchar nonce_idx = instr_accts[0];
833 :
834 : /* https://github.com/anza-xyz/agave/blob/v2.3.1/svm-transaction/src/svm_message.rs#L99-L105 */
835 15 : if( FD_UNLIKELY( txn_instr->data_sz<4UL || FD_LOAD( uint, instr_data ) !=
836 15 : (uint)FD_SYSTEM_PROGRAM_INSTR_ADVANCE_NONCE_ACCOUNT ) ) {
837 0 : return FD_RUNTIME_TXN_ERR_BLOCKHASH_NOT_FOUND;
838 0 : }
839 :
840 : /* Nonce account must be...
841 : - writable
842 : - statically included in the transaction account keys (if SIMD-242
843 : is active)
844 : https://github.com/anza-xyz/agave/blob/v2.3.1/svm-transaction/src/svm_message.rs#L110-L111 */
845 15 : if( FD_UNLIKELY( !fd_runtime_account_is_writable_idx( txn_in, txn_out, nonce_idx ) ) ) {
846 0 : return FD_RUNTIME_TXN_ERR_BLOCKHASH_FAIL_ADVANCE_NONCE_INSTR;
847 0 : }
848 15 : if( FD_UNLIKELY( FD_FEATURE_ACTIVE_BANK( bank, require_static_nonce_account ) &&
849 15 : nonce_idx>=TXN( txn_in->txn )->acct_addr_cnt ) ) {
850 0 : return FD_RUNTIME_TXN_ERR_BLOCKHASH_FAIL_ADVANCE_NONCE_INSTR;
851 0 : }
852 :
853 :
854 : /* The transaction accounts were set up before this check, including
855 : forwarding writable bundle accounts into the current txn_out. */
856 15 : fd_acc_t * nonce_entry = txn_out->accounts.account[ nonce_idx ];
857 15 : if( FD_UNLIKELY( !nonce_entry->lamports ) ) {
858 0 : return FD_RUNTIME_TXN_ERR_BLOCKHASH_FAIL_ADVANCE_NONCE_INSTR;
859 0 : }
860 :
861 : /* https://github.com/anza-xyz/agave/blob/16de8b75ebcd57022409b422de557dd37b1de8db/sdk/src/nonce_account.rs#L28-L42 */
862 : /* verify_nonce_account */
863 15 : fd_pubkey_t const * owner_pubkey = fd_type_pun_const( nonce_entry->owner );
864 15 : if( FD_UNLIKELY( !fd_pubkey_eq( owner_pubkey, &fd_solana_system_program_id ) ) ) {
865 0 : return FD_RUNTIME_TXN_ERR_BLOCKHASH_FAIL_ADVANCE_NONCE_INSTR;
866 0 : }
867 :
868 15 : fd_nonce_state_versions_t state[1];
869 15 : if( FD_UNLIKELY( fd_nonce_state_versions_decode( state, nonce_entry->data, nonce_entry->data_len ) ) ) {
870 0 : return FD_RUNTIME_TXN_ERR_BLOCKHASH_FAIL_ADVANCE_NONCE_INSTR;
871 0 : }
872 :
873 : /* https://github.com/anza-xyz/agave/blob/16de8b75ebcd57022409b422de557dd37b1de8db/sdk/program/src/nonce/state/mod.rs#L36-L53 */
874 : /* verify_recent_blockhash. This checks that the decoded nonce record is
875 : not a legacy nonce nor uninitialized. If this is the case, then we can
876 : verify by comparing the decoded durable nonce to the recent blockhash */
877 15 : if( FD_UNLIKELY( state->version != FD_NONCE_VERSION_CURRENT ) ) {
878 0 : return FD_RUNTIME_TXN_ERR_BLOCKHASH_FAIL_ADVANCE_NONCE_INSTR;
879 0 : }
880 :
881 15 : if( FD_UNLIKELY( state->kind != FD_NONCE_STATE_INITIALIZED ) ) {
882 0 : return FD_RUNTIME_TXN_ERR_BLOCKHASH_FAIL_ADVANCE_NONCE_INSTR;
883 0 : }
884 :
885 15 : if( FD_UNLIKELY( memcmp( &state->durable_nonce, recent_blockhash, sizeof(fd_hash_t) ) ) ) {
886 0 : return FD_RUNTIME_TXN_ERR_BLOCKHASH_FAIL_WRONG_NONCE;
887 0 : }
888 :
889 : /* Finally check that the nonce is authorized by seeing if any
890 : accounts in the nonce instruction are signers. This is a
891 : successful exit case. */
892 39 : for( ushort i=0; i<txn_instr->acct_cnt; ++i ) {
893 39 : if( fd_txn_is_signer( TXN( txn_in->txn ), (int)instr_accts[i] ) ) {
894 15 : if( fd_pubkey_eq( &txn_out->accounts.keys[ instr_accts[i] ], &state->authority ) ) {
895 : /* Mark nonce account to make sure that we modify and hash the
896 : account even if the transaction failed to execute
897 : successfully. */
898 :
899 15 : txn_out->accounts.nonce_idx_in_txn = instr_accts[ 0 ];
900 :
901 15 : fd_blockhashes_t const * blockhashes = &bank->f.block_hash_queue;
902 15 : fd_blockhash_info_t const * last_bhash_info = fd_blockhashes_peek_last( blockhashes );
903 15 : FD_TEST( last_bhash_info ); /* Agave panics here if the blockhash queue is empty */
904 :
905 : /* https://github.com/anza-xyz/agave/blob/v3.0.3/runtime/src/bank/check_transactions.rs#L217-L221*/
906 15 : fd_nonce_state_versions_t new_state = {
907 15 : .version = FD_NONCE_VERSION_CURRENT,
908 15 : .kind = FD_NONCE_STATE_INITIALIZED,
909 15 : .authority = state->authority,
910 15 : .durable_nonce = next_durable_nonce,
911 : /* https://github.com/anza-xyz/agave/blob/v3.0.3/runtime/src/bank/check_transactions.rs#L88-L90 */
912 15 : .lamports_per_signature = last_bhash_info->lamports_per_signature
913 15 : };
914 :
915 15 : FD_TEST( fd_nonce_state_versions_size( &new_state )<=FD_SYSTEM_PROGRAM_NONCE_DLEN );
916 15 : fd_memcpy( txn_out->accounts.nonce_rollback_data, nonce_entry->data, nonce_entry->data_len );
917 15 : txn_out->accounts.nonce_rollback_data_len = nonce_entry->data_len;
918 :
919 15 : ulong written = 0UL;
920 15 : int err = fd_nonce_state_versions_encode( &new_state, txn_out->accounts.nonce_rollback_data, txn_out->accounts.nonce_rollback_data_len, &written );
921 15 : if( FD_UNLIKELY( err ) ) {
922 0 : return FD_RUNTIME_TXN_ERR_BLOCKHASH_FAIL_ADVANCE_NONCE_INSTR;
923 0 : }
924 :
925 15 : return FD_RUNTIME_EXECUTE_SUCCESS;
926 15 : }
927 15 : }
928 39 : }
929 : /* This means that the blockhash was not found */
930 0 : return FD_RUNTIME_TXN_ERR_BLOCKHASH_FAIL_ADVANCE_NONCE_INSTR;
931 :
932 15 : }
|