package node
import (
"math/big"
common2 "github.com/ethereum/go-ethereum/common"
"github.com/ethereum/go-ethereum/rlp"
ffi_bls "github.com/harmony-one/bls/ffi/go/bls"
"github.com/harmony-one/harmony/core/types"
"github.com/harmony-one/harmony/internal/utils"
"github.com/harmony-one/harmony/shard"
"github.com/pkg/errors"
"github.com/prometheus/client_golang/prometheus"
)
const (
maxPendingCrossLinkSize = 1000
crossLinkBatchSize = 3
)
var (
errAlreadyExist = errors . New ( "crosslink already exist" )
)
// VerifyBlockCrossLinks verifies the crosslinks of the block.
// This method should be called from beacon chain.
func ( node * Node ) VerifyBlockCrossLinks ( block * types . Block ) error {
cxLinksData := block . Header ( ) . CrossLinks ( )
if len ( cxLinksData ) == 0 {
utils . Logger ( ) . Debug ( ) . Msgf ( "[CrossLinkVerification] Zero CrossLinks in the header" )
return nil
}
crossLinks := types . CrossLinks { }
err := rlp . DecodeBytes ( cxLinksData , & crossLinks )
if err != nil {
return errors . Wrapf (
err , "[CrossLinkVerification] failed to decode cross links" ,
)
}
if ! crossLinks . IsSorted ( ) {
return errors . New ( "[CrossLinkVerification] cross links are not sorted" )
}
for _ , crossLink := range crossLinks {
// ReadCrossLink beacon chain usage.
cl , err := node . Blockchain ( ) . ReadCrossLink ( crossLink . ShardID ( ) , crossLink . BlockNum ( ) )
if err == nil && cl != nil {
// Add slash for exist same blocknum but different crosslink
return errAlreadyExist
}
if err := node . VerifyCrossLink ( crossLink ) ; err != nil {
return errors . Wrapf ( err , "cannot VerifyBlockCrossLinks" )
}
}
return nil
}
// ProcessCrossLinkHeartbeatMessage process crosslink heart beat signal.
// This function is only called on shards 1,2,3 when network message `CrosslinkHeartbeat` receiving.
func ( node * Node ) ProcessCrossLinkHeartbeatMessage ( msgPayload [ ] byte ) {
if err := node . processCrossLinkHeartbeatMessage ( msgPayload ) ; err != nil {
utils . Logger ( ) . Err ( err ) .
Msg ( "[ProcessCrossLinkHeartbeatMessage] failed process crosslink heartbeat signal" )
}
}
func ( node * Node ) processCrossLinkHeartbeatMessage ( msgPayload [ ] byte ) error {
hb := types . CrosslinkHeartbeat { }
err := rlp . DecodeBytes ( msgPayload , & hb )
if err != nil {
return err
}
shardID := node . Blockchain ( ) . CurrentBlock ( ) . ShardID ( )
if hb . ShardID != shardID {
return errors . Errorf ( "invalid shard id: expected %d, got %d" , shardID , hb . ShardID )
}
// Outdated signal.
if s := node . crosslinks . LastKnownCrosslinkHeartbeatSignal ( ) ; s != nil && s . LatestContinuousBlockNum > hb . LatestContinuousBlockNum {
return nil
}
sig := & ffi_bls . Sign { }
err = sig . Deserialize ( hb . Signature )
if err != nil {
return err
}
hb . Signature = nil
serialized , err := rlp . EncodeToBytes ( hb )
if err != nil {
return err
}
pub := ffi_bls . PublicKey { }
err = pub . Deserialize ( hb . PublicKey )
if err != nil {
return err
}
ok := sig . VerifyHash ( & pub , serialized )
if ! ok {
return errors . New ( "invalid signature" )
}
state , err := node . EpochChain ( ) . ReadShardState ( big . NewInt ( int64 ( hb . Epoch ) ) )
if err != nil {
return err
}
committee , err := state . FindCommitteeByID ( shard . BeaconChainShardID )
if err != nil {
return err
}
pubs , err := committee . BLSPublicKeys ( )
if err != nil {
return err
}
keyExists := false
for _ , row := range pubs {
if pub . IsEqual ( row . Object ) {
keyExists = true
break
}
}
if ! keyExists {
return errors . New ( "pub key doesn't exist" )
}
utils . Logger ( ) . Info ( ) .
Msgf ( "[ProcessCrossLinkHeartbeatMessage] storing hb signal with block num %d" , hb . LatestContinuousBlockNum )
node . crosslinks . SetLastKnownCrosslinkHeartbeatSignal ( & hb )
return nil
}
// ProcessCrossLinkMessage verify and process Node/CrossLink message into crosslink when it's valid
func ( node * Node ) ProcessCrossLinkMessage ( msgPayload [ ] byte ) {
if node . IsRunningBeaconChain ( ) {
pendingCLs , err := node . Blockchain ( ) . ReadPendingCrossLinks ( )
if err == nil && len ( pendingCLs ) >= maxPendingCrossLinkSize {
utils . Logger ( ) . Debug ( ) .
Msgf ( "[ProcessingCrossLink] Pending Crosslink reach maximum size: %d" , len ( pendingCLs ) )
return
}
existingCLs := map [ common2 . Hash ] struct { } { }
for _ , pending := range pendingCLs {
existingCLs [ pending . Hash ( ) ] = struct { } { }
}
var crosslinks [ ] types . CrossLink
if err := rlp . DecodeBytes ( msgPayload , & crosslinks ) ; err != nil {
utils . Logger ( ) . Error ( ) .
Err ( err ) .
Msg ( "[ProcessingCrossLink] Crosslink Message Broadcast Unable to Decode" )
return
}
var candidates [ ] types . CrossLink
utils . Logger ( ) . Debug ( ) .
Msgf ( "[ProcessingCrossLink] Received crosslinks: %d" , len ( crosslinks ) )
for i , cl := range crosslinks {
if i > crossLinkBatchSize * 2 { // A sanity check to prevent spamming
break
}
if _ , ok := existingCLs [ cl . Hash ( ) ] ; ok {
nodeCrossLinkMessageCounterVec . With ( prometheus . Labels { "type" : "duplicate_crosslink" } ) . Inc ( )
utils . Logger ( ) . Debug ( ) . Err ( err ) .
Msgf ( "[ProcessingCrossLink] Cross Link already exists in pending queue, pass. Beacon Epoch: %d, Block num: %d, Epoch: %d, shardID %d" ,
node . Blockchain ( ) . CurrentHeader ( ) . Epoch ( ) , cl . Number ( ) , cl . Epoch ( ) , cl . ShardID ( ) )
continue
}
// ReadCrossLink beacon chain usage.
exist , err := node . Blockchain ( ) . ReadCrossLink ( cl . ShardID ( ) , cl . Number ( ) . Uint64 ( ) )
if err == nil && exist != nil {
nodeCrossLinkMessageCounterVec . With ( prometheus . Labels { "type" : "duplicate_crosslink" } ) . Inc ( )
utils . Logger ( ) . Debug ( ) . Err ( err ) .
Msgf ( "[ProcessingCrossLink] Cross Link already exists, pass. Beacon Epoch: %d, Block num: %d, Epoch: %d, shardID %d" , node . Blockchain ( ) . CurrentHeader ( ) . Epoch ( ) , cl . Number ( ) , cl . Epoch ( ) , cl . ShardID ( ) )
continue
}
if err = node . VerifyCrossLink ( cl ) ; err != nil {
nodeCrossLinkMessageCounterVec . With ( prometheus . Labels { "type" : "invalid_crosslink" } ) . Inc ( )
[double-sign] Provide proof of double sign in slash record sent to beaconchain (#2253)
* [double-sign] Commit changes in consensus needed for double-sign
* [double-sign] Leader captures when valdator double signs, broadcasts to beaconchain
* [slash] Add quick iteration tool for testing double-signing
* [slash] Add webhook example
* [slash] Add http server for hook to trigger double sign behavior
* [double-sign] Use bin/trigger-double-sign to cause a double-sign
* [double-sign] Full feedback loop working
* [slash] Thread through the slash records in the block proposal step
* [slash] Compute the slashing rate
* [double-sign] Generalize yaml malicious for many keys
* [double-sign][slash] Modify data structures, verify via webhook handler
* [slash][double-sign] Find one address of bls public key signer, seemingly settle on data structures
* [slash] Apply to state slashing for double signing
* [slash][double-sign] Checkpoint for working code that slashes on beaconchain
* [slash] Keep track of the total slash and total reporters reward
* [slash] Dump account state before and after the slash
* [slash] Satisfy Travis
* [slash][state] Apply slash to the snapshot at beginning of epoch, now need to capture also the new delegates
* [slash] Capture the unique new delegations since snapshot as well
* [slash] Filter undelegation by epoch of double sign
* [slash] Add TODO of correctness needed in slash needs on off-chain data
* [rpc] Fix closure issue on shardID
* [slash] Add delegator to double-sign testing script
* [slash] Expand crt-validator.sh with commenting printfs and make delegation
* [slash] Finish track payment of leftover slash debt after undelegation runs out
* [slash] Now be explicit about error wrt delegatorSlashApply
* [slash] Capture specific sanity check on slash paidoff
* [slash] Track slash from undelegation piecemeal
* [slash][delegation] Named slice types, .String()
* [slash] Do no RLP encode twice, once is enough
* [slash] Remove special case of validators own delegation
* [slash] Refactor approach to slash state application
* [slash] Begin expanding out Verify
* [slash] Slash on snapshot delegations, not current
* [slash] Fix Epoch Cmp
* [slash] Third iteration on slash logic
* [slash] Use full slash amount
* [slash] More log, whitespace
* [slash] Remove Println, add log
* [slash] Remove debug Println
* [slash] Add record in unit test
* [slash] Build Validator snapshot, current. Fill out slash record
* [slash] Need to get RLP dump of a header to use in test
* [slash] Factor out double sign test constants
* [slash] Factor out common for validator, stub out slash application, finish out deserialization setup
* [slash] Factor out data structure creation because of var lexical scoping
* [slash] Seem to have pipeline of unit test e2e executing
* [slash] Add expected snitch, slash amounts
* [slash] Checkpoint
* [slash] Unit test correctly checks case of validator own stake which could drop below 1 ONE in slashing
* [config] add double-sign testnet config (#1)
Signed-off-by: Leo Chen <leo@harmony.one>
* [slash] Commit for as is code & data of current dump.json
* [slash] Order of state operation not correct in test, hence bad results, thank you dlv
* [slash] Add snapshot state dump
* [slash] Pay off slash of validator own delegation correctly
* [slash] Pay off slash debt with special case for min-self
* [slash] Pass first scenario conclusively
* [slash] 2% slash passes unit test for own delegation and external
* [slash] Parameterize unit test to easily test .02 vs .80 slash
* [slash] Handle own delegation correctly at 80% slash
* [slash] Have 80% slash working with external delegator
* [slash] Remove debug code from slash
* [slash] Adjust Apply signature, test again for 2% slash
* [slash] Factor out scenario in testing so can test 2% and 80% at same time
* [slash] Correct balance deduction on plan delegation
* [slash] Mock out ChainReader for TestVerify
* [slash] Small surface area interface, now feedback loop for verify
* [slash] Remove development json
* [slash] trigger-double-sign consumes yaml
* [slash] Remove dead code
* [slash][test] Factor ValidatorWrapper into scenario
* [slash][test] Add example from local-testing dump - caution might be off
* [slash] Factor out mutation of slashDebt
* [slash][test] Factor out tests so can easily load test-case from bytes
* [slash] Fix payment mistake in validator own delegation wrt min-self-delgation respected
* [slash] Satisfy Travis
* [slash] Begin cleanup of PR
* [slash] Apply slash from header to Finalize via state processor
* [slash] Productionize code, Println => logs; adjust slash picked in newblock
* [slash] Need pointer for rlp.Decode
* [slash] ValidatorInformation use full wrapper
* Fix median stake
* [staking] Adjust MarshalJSON for Validator, Wrapper
* Refactor offchain data commit; Make block onchain/offchain commit atomic (#2279)
* Refactor offchain data; Add epoch to ValidatorSnapshot
* Make block onchain/offchain data commit atomically
* [slash][committee] Set .Active to false on double sign, do not consider banned or inactive for committee assignment
* [effective] VC eligible.go
* [consensus] Redundant field in printf
* [docker] import-ks for a dev account
* [slash] Create BLS key for dockerfile and crt-validator.sh
* [slash][docker] Easy deployment of double-sign testing
* [docker] Have slash work as single docker command
* [rpc] Fix median-stake RPC
* [slash] Update webhook with default docker BLS key
* [docker][slash] Fresh yaml copy for docker build, remove dev code in main.go
* [slash] Remove helper binary, commented out code, change to local config
* [params] Factor out test genesis value
* Add shard checking to Tx-Pool & correct blacklist (#2301)
* [core] Fix blacklist & add shardID check
* [staking + node + cmd] Fix blacklist & add shardID check
* [slash] Adjust to PR comments part 1
* [docker] Use different throw away funded account
* [docker] Create easier testing for delegation with private keys
* [docker] Update yaml
* [slash] Remove special case for slashing validator own delegation wrt min-self-delegate
* [docker] Install nano as well
* [slash] Early error if banned
* [quorum] Expose earning account in decider marshal json
* Revert "Refactor offchain data commit; Make block onchain/offchain commit atomic (#2279)"
This reverts commit 9ffbf682c075b49188923c65a0bbf39ac188be00.
* [slash] Add non-sanity check way to update validator
* [reward] Increase percision on percentage in schedule
* [slash] Adjust logs
* [committee] Check eligibility of validator before doing sanity check
* [slash] Update docker
* [slash] Move create validator script to test
* [slash] More log
* [param] Make things faster
* [slash][off-chain] Clear out slashes from pending in writeblockwithstate
* [cross-link] Log is not error, just info
* [blockchain] Not necessary to guard DeletePendingSlashingCandidates
* [slash][consensus] Use plain []byte for signature b/c bls.Sign has private impl fields, rlp does not encode that
* [slash][test] Use faucet as sender, assume user imported
* [slash] Test setup
* [slash] reserve error for real error in logs
* [slash][availability] Apply availability correct, bump signing count each block
* [slash][staking] Consider banned field in sanity check, pay snitch only half of what was actually slashed
* [slash] Pay as much as can
* [slash] use right nowAmt
* [slash] Take away from rewards as well
* [slash] iterate faster
* [slash] Remove dev based timing
* [slash] Add more log, sanity check incoming slash records, only count external for slash rate
* [availability][state] Adjust signature of ValidatorWrapper wrt state, filter out for staked validators, correct availaibility measure on running counters
* [availability] More log
* [slash] Simply pre slash erra slashing
* [slash] Remove development code
* [slash] Use height from recvMsg, todo on epoch
* [staking] Not necessary to touch LastEpochInCommittee in staking_verifier
* [slash] Undo ds in endpoint pattern config
* [slash] Add TODO and log when delegation becomes 0 b/c slash debt payment
* [slash] Abstract staked validators from shard.State into type, set slash rate based BLSKey count
Co-authored-by: Leo Chen <leo@harmony.one>
Co-authored-by: flicker-harmony <52401354+flicker-harmony@users.noreply.github.com>
Co-authored-by: Rongjian Lan <rongjian@harmony.one>
Co-authored-by: Daniel Van Der Maden <daniel@harmony.one>
5 years ago
utils . Logger ( ) . Info ( ) .
Str ( "cross-link-issue" , err . Error ( ) ) .
Msgf ( "[ProcessingCrossLink] Failed to verify new cross link for blockNum %d epochNum %d shard %d skipped: %v" , cl . BlockNum ( ) , cl . Epoch ( ) . Uint64 ( ) , cl . ShardID ( ) , cl )
continue
}
candidates = append ( candidates , cl )
nodeCrossLinkMessageCounterVec . With ( prometheus . Labels { "type" : "new_crosslink" } ) . Inc ( )
utils . Logger ( ) . Debug ( ) .
[double-sign] Provide proof of double sign in slash record sent to beaconchain (#2253)
* [double-sign] Commit changes in consensus needed for double-sign
* [double-sign] Leader captures when valdator double signs, broadcasts to beaconchain
* [slash] Add quick iteration tool for testing double-signing
* [slash] Add webhook example
* [slash] Add http server for hook to trigger double sign behavior
* [double-sign] Use bin/trigger-double-sign to cause a double-sign
* [double-sign] Full feedback loop working
* [slash] Thread through the slash records in the block proposal step
* [slash] Compute the slashing rate
* [double-sign] Generalize yaml malicious for many keys
* [double-sign][slash] Modify data structures, verify via webhook handler
* [slash][double-sign] Find one address of bls public key signer, seemingly settle on data structures
* [slash] Apply to state slashing for double signing
* [slash][double-sign] Checkpoint for working code that slashes on beaconchain
* [slash] Keep track of the total slash and total reporters reward
* [slash] Dump account state before and after the slash
* [slash] Satisfy Travis
* [slash][state] Apply slash to the snapshot at beginning of epoch, now need to capture also the new delegates
* [slash] Capture the unique new delegations since snapshot as well
* [slash] Filter undelegation by epoch of double sign
* [slash] Add TODO of correctness needed in slash needs on off-chain data
* [rpc] Fix closure issue on shardID
* [slash] Add delegator to double-sign testing script
* [slash] Expand crt-validator.sh with commenting printfs and make delegation
* [slash] Finish track payment of leftover slash debt after undelegation runs out
* [slash] Now be explicit about error wrt delegatorSlashApply
* [slash] Capture specific sanity check on slash paidoff
* [slash] Track slash from undelegation piecemeal
* [slash][delegation] Named slice types, .String()
* [slash] Do no RLP encode twice, once is enough
* [slash] Remove special case of validators own delegation
* [slash] Refactor approach to slash state application
* [slash] Begin expanding out Verify
* [slash] Slash on snapshot delegations, not current
* [slash] Fix Epoch Cmp
* [slash] Third iteration on slash logic
* [slash] Use full slash amount
* [slash] More log, whitespace
* [slash] Remove Println, add log
* [slash] Remove debug Println
* [slash] Add record in unit test
* [slash] Build Validator snapshot, current. Fill out slash record
* [slash] Need to get RLP dump of a header to use in test
* [slash] Factor out double sign test constants
* [slash] Factor out common for validator, stub out slash application, finish out deserialization setup
* [slash] Factor out data structure creation because of var lexical scoping
* [slash] Seem to have pipeline of unit test e2e executing
* [slash] Add expected snitch, slash amounts
* [slash] Checkpoint
* [slash] Unit test correctly checks case of validator own stake which could drop below 1 ONE in slashing
* [config] add double-sign testnet config (#1)
Signed-off-by: Leo Chen <leo@harmony.one>
* [slash] Commit for as is code & data of current dump.json
* [slash] Order of state operation not correct in test, hence bad results, thank you dlv
* [slash] Add snapshot state dump
* [slash] Pay off slash of validator own delegation correctly
* [slash] Pay off slash debt with special case for min-self
* [slash] Pass first scenario conclusively
* [slash] 2% slash passes unit test for own delegation and external
* [slash] Parameterize unit test to easily test .02 vs .80 slash
* [slash] Handle own delegation correctly at 80% slash
* [slash] Have 80% slash working with external delegator
* [slash] Remove debug code from slash
* [slash] Adjust Apply signature, test again for 2% slash
* [slash] Factor out scenario in testing so can test 2% and 80% at same time
* [slash] Correct balance deduction on plan delegation
* [slash] Mock out ChainReader for TestVerify
* [slash] Small surface area interface, now feedback loop for verify
* [slash] Remove development json
* [slash] trigger-double-sign consumes yaml
* [slash] Remove dead code
* [slash][test] Factor ValidatorWrapper into scenario
* [slash][test] Add example from local-testing dump - caution might be off
* [slash] Factor out mutation of slashDebt
* [slash][test] Factor out tests so can easily load test-case from bytes
* [slash] Fix payment mistake in validator own delegation wrt min-self-delgation respected
* [slash] Satisfy Travis
* [slash] Begin cleanup of PR
* [slash] Apply slash from header to Finalize via state processor
* [slash] Productionize code, Println => logs; adjust slash picked in newblock
* [slash] Need pointer for rlp.Decode
* [slash] ValidatorInformation use full wrapper
* Fix median stake
* [staking] Adjust MarshalJSON for Validator, Wrapper
* Refactor offchain data commit; Make block onchain/offchain commit atomic (#2279)
* Refactor offchain data; Add epoch to ValidatorSnapshot
* Make block onchain/offchain data commit atomically
* [slash][committee] Set .Active to false on double sign, do not consider banned or inactive for committee assignment
* [effective] VC eligible.go
* [consensus] Redundant field in printf
* [docker] import-ks for a dev account
* [slash] Create BLS key for dockerfile and crt-validator.sh
* [slash][docker] Easy deployment of double-sign testing
* [docker] Have slash work as single docker command
* [rpc] Fix median-stake RPC
* [slash] Update webhook with default docker BLS key
* [docker][slash] Fresh yaml copy for docker build, remove dev code in main.go
* [slash] Remove helper binary, commented out code, change to local config
* [params] Factor out test genesis value
* Add shard checking to Tx-Pool & correct blacklist (#2301)
* [core] Fix blacklist & add shardID check
* [staking + node + cmd] Fix blacklist & add shardID check
* [slash] Adjust to PR comments part 1
* [docker] Use different throw away funded account
* [docker] Create easier testing for delegation with private keys
* [docker] Update yaml
* [slash] Remove special case for slashing validator own delegation wrt min-self-delegate
* [docker] Install nano as well
* [slash] Early error if banned
* [quorum] Expose earning account in decider marshal json
* Revert "Refactor offchain data commit; Make block onchain/offchain commit atomic (#2279)"
This reverts commit 9ffbf682c075b49188923c65a0bbf39ac188be00.
* [slash] Add non-sanity check way to update validator
* [reward] Increase percision on percentage in schedule
* [slash] Adjust logs
* [committee] Check eligibility of validator before doing sanity check
* [slash] Update docker
* [slash] Move create validator script to test
* [slash] More log
* [param] Make things faster
* [slash][off-chain] Clear out slashes from pending in writeblockwithstate
* [cross-link] Log is not error, just info
* [blockchain] Not necessary to guard DeletePendingSlashingCandidates
* [slash][consensus] Use plain []byte for signature b/c bls.Sign has private impl fields, rlp does not encode that
* [slash][test] Use faucet as sender, assume user imported
* [slash] Test setup
* [slash] reserve error for real error in logs
* [slash][availability] Apply availability correct, bump signing count each block
* [slash][staking] Consider banned field in sanity check, pay snitch only half of what was actually slashed
* [slash] Pay as much as can
* [slash] use right nowAmt
* [slash] Take away from rewards as well
* [slash] iterate faster
* [slash] Remove dev based timing
* [slash] Add more log, sanity check incoming slash records, only count external for slash rate
* [availability][state] Adjust signature of ValidatorWrapper wrt state, filter out for staked validators, correct availaibility measure on running counters
* [availability] More log
* [slash] Simply pre slash erra slashing
* [slash] Remove development code
* [slash] Use height from recvMsg, todo on epoch
* [staking] Not necessary to touch LastEpochInCommittee in staking_verifier
* [slash] Undo ds in endpoint pattern config
* [slash] Add TODO and log when delegation becomes 0 b/c slash debt payment
* [slash] Abstract staked validators from shard.State into type, set slash rate based BLSKey count
Co-authored-by: Leo Chen <leo@harmony.one>
Co-authored-by: flicker-harmony <52401354+flicker-harmony@users.noreply.github.com>
Co-authored-by: Rongjian Lan <rongjian@harmony.one>
Co-authored-by: Daniel Van Der Maden <daniel@harmony.one>
5 years ago
Msgf ( "[ProcessingCrossLink] Committing for shardID %d, blockNum %d" ,
cl . ShardID ( ) , cl . Number ( ) . Uint64 ( ) ,
)
}
Len , _ := node . Blockchain ( ) . AddPendingCrossLinks ( candidates )
utils . Logger ( ) . Debug ( ) .
Msgf ( "[ProcessingCrossLink] Add pending crosslinks, total pending: %d" , Len )
}
}
// VerifyCrossLink verifies the header is valid
func ( node * Node ) VerifyCrossLink ( cl types . CrossLink ) error {
if node . Blockchain ( ) . ShardID ( ) != shard . BeaconChainShardID {
return errors . New ( "[VerifyCrossLink] Shard chains should not verify cross links" )
}
engine := node . Blockchain ( ) . Engine ( )
if err := engine . VerifyCrossLink ( node . Blockchain ( ) , cl ) ; err != nil {
return errors . Wrap ( err , "[VerifyCrossLink]" )
}
return nil
}