quorum/controls/permission/permission.go

466 lines
14 KiB
Go
Raw Normal View History

package permission
2018-07-12 03:00:19 -07:00
import (
2018-10-30 23:42:29 -07:00
"crypto/ecdsa"
"fmt"
"encoding/json"
2018-07-12 03:00:19 -07:00
"io/ioutil"
"path/filepath"
"math/big"
"os"
"sync"
2018-07-12 03:00:19 -07:00
2018-08-05 22:26:29 -07:00
"github.com/ethereum/go-ethereum/core/types"
2018-07-12 03:00:19 -07:00
"github.com/ethereum/go-ethereum/accounts/abi/bind"
2018-07-13 18:22:43 -07:00
"github.com/ethereum/go-ethereum/params"
"github.com/ethereum/go-ethereum/eth"
2018-07-12 03:00:19 -07:00
"github.com/ethereum/go-ethereum/ethclient"
"github.com/ethereum/go-ethereum/log"
"github.com/ethereum/go-ethereum/node"
"github.com/ethereum/go-ethereum/p2p"
2018-09-19 18:51:36 -07:00
"github.com/ethereum/go-ethereum/p2p/discover"
2018-09-28 01:15:59 -07:00
"github.com/ethereum/go-ethereum/controls"
"github.com/ethereum/go-ethereum/cmd/utils"
"github.com/ethereum/go-ethereum/raft"
2018-10-30 00:59:08 -07:00
pbind "github.com/ethereum/go-ethereum/controls/bind"
2018-07-12 03:00:19 -07:00
)
const (
PERMISSIONED_CONFIG = "permissioned-nodes.json"
BLACKLIST_CONFIG = "disallowed-nodes.json"
)
2018-07-13 18:22:43 -07:00
type NodeOperation uint8
const (
NodeAdd NodeOperation = iota
NodeDelete
)
type PermissionCtrl struct {
node *node.Node
ethClnt *ethclient.Client
eth *eth.Ethereum
isRaft bool
2018-10-30 23:42:29 -07:00
key *ecdsa.PrivateKey
2018-10-25 21:33:23 -07:00
}
2018-10-30 23:42:29 -07:00
func NewQuorumPermissionCtrl(stack *node.Node, isRaft bool) (*PermissionCtrl, error) {
2018-08-05 22:26:29 -07:00
// Create a new ethclient to for interfacing with the contract
stateReader, e, err := controls.CreateEthClient(stack)
2018-08-05 22:26:29 -07:00
if err != nil {
log.Error("Unable to create ethereum client for permissions check : ", "err", err)
return nil, err
}
2018-10-30 23:42:29 -07:00
prvKey := stack.GetNodeKey()
log.Info("mykey value is : ", "prvKey", prvKey)
return &PermissionCtrl{stack, stateReader, e, isRaft, prvKey}, nil
}
// This function first adds the node list from permissioned-nodes.json to
// the permissiones contract deployed as a precompile via genesis.json
func (p *PermissionCtrl) Start() error {
// check if permissioning contract is there at address. If not return from here
2018-10-30 00:59:08 -07:00
if _, err := pbind.NewPermissionsFilterer(params.QuorumPermissionsContract, p.ethClnt); err != nil {
log.Error("Permissions not enabled for the network : ", "err", err)
return nil
}
// Permissions initialization
p.init()
// Monitors node addition and decativation from network
p.manageNodePermissions()
// Monitors account level persmissions update from smart contarct
p.manageAccountPermissions()
return nil
}
2018-07-13 18:22:43 -07:00
// This functions updates the initial values for the network
func (p *PermissionCtrl) init() error {
// populate the initial list of nodes into the smart contract
// from permissioned-nodes.json
p.populateStaticNodesToContract()
// populate the account access for the genesis.json accounts. these
// accounts will have full access
// populateInitAccountAccess()
// call populates the node details from contract to KnownNodes
if err := p.populatePermissionedNodes(); err != nil {
return err
}
// call populates the account permissions based on past history
if err := p.populateAcctPermissions(); err != nil {
return err
}
return nil
}
// Manages node addition and decavtivation from network
func (p *PermissionCtrl) manageNodePermissions() {
2018-07-13 18:22:43 -07:00
//monitor for new nodes addition via smart contract
go p.monitorNewNodeAdd()
//monitor for nodes deletiin via smart contract
go p.monitorNodeDeactivation()
2018-08-31 04:35:35 -07:00
//monitor for nodes blacklisting via smart contract
go p.monitorNodeBlacklisting()
2018-07-13 18:22:43 -07:00
}
// This functions listens on the channel for new node approval via smart contract and
2018-07-13 18:22:43 -07:00
// adds the same into permissioned-nodes.json
func (p *PermissionCtrl) monitorNewNodeAdd() {
2018-10-30 00:59:08 -07:00
permissions, err := pbind.NewPermissionsFilterer(params.QuorumPermissionsContract, p.ethClnt)
2018-07-13 18:22:43 -07:00
if err != nil {
log.Error("failed to monitor new node add : ", "err", err)
2018-07-13 18:22:43 -07:00
}
2018-10-30 00:59:08 -07:00
ch := make(chan *pbind.PermissionsNodeApproved, 1)
2018-07-13 18:22:43 -07:00
opts := &bind.WatchOpts{}
var blockNumber uint64 = 1
opts.Start = &blockNumber
2018-10-30 00:59:08 -07:00
var nodeAddEvent *pbind.PermissionsNodeApproved
2018-07-13 18:22:43 -07:00
2018-08-16 20:20:33 -07:00
_, err = permissions.WatchNodeApproved(opts, ch)
if err != nil {
log.Info("Failed WatchNodeApproved: %v", err)
}
2018-08-16 20:20:33 -07:00
for {
select {
case nodeAddEvent = <-ch:
p.updatePermissionedNodes(nodeAddEvent.EnodeId, nodeAddEvent.IpAddrPort, nodeAddEvent.DiscPort, nodeAddEvent.RaftPort, NodeAdd)
}
}
2018-07-13 18:22:43 -07:00
}
// This functions listens on the channel for new node approval via smart contract and
// adds the same into permissioned-nodes.json
func (p *PermissionCtrl) monitorNodeDeactivation() {
2018-10-30 00:59:08 -07:00
permissions, err := pbind.NewPermissionsFilterer(params.QuorumPermissionsContract, p.ethClnt)
if err != nil {
log.Error("Failed to monitor node delete: ", "err", err)
}
2018-10-30 00:59:08 -07:00
ch := make(chan *pbind.PermissionsNodeDeactivated)
opts := &bind.WatchOpts{}
var blockNumber uint64 = 1
opts.Start = &blockNumber
2018-10-30 00:59:08 -07:00
var newNodeDeleteEvent *pbind.PermissionsNodeDeactivated
2018-08-16 20:20:33 -07:00
_, err = permissions.WatchNodeDeactivated(opts, ch)
if err != nil {
log.Info("Failed NodeDeactivated: %v", err)
}
2018-08-16 20:20:33 -07:00
for {
select {
case newNodeDeleteEvent = <-ch:
p.updatePermissionedNodes(newNodeDeleteEvent.EnodeId, newNodeDeleteEvent.IpAddrPort, newNodeDeleteEvent.DiscPort, newNodeDeleteEvent.RaftPort, NodeDelete)
}
2018-08-16 20:20:33 -07:00
}
}
2018-08-05 22:26:29 -07:00
2018-08-31 04:35:35 -07:00
// This function listnes on the channel for any node blacklisting event via smart contract
// and adds the same disallowed-nodes.json
func (p *PermissionCtrl) monitorNodeBlacklisting() {
2018-10-30 00:59:08 -07:00
permissions, err := pbind.NewPermissionsFilterer(params.QuorumPermissionsContract, p.ethClnt)
2018-08-31 04:35:35 -07:00
if err != nil {
log.Error("failed to monitor new node add : ", "err", err)
2018-08-31 04:35:35 -07:00
}
2018-10-30 00:59:08 -07:00
ch := make(chan *pbind.PermissionsNodeBlacklisted, 1)
2018-08-31 04:35:35 -07:00
opts := &bind.WatchOpts{}
var blockNumber uint64 = 1
opts.Start = &blockNumber
2018-10-30 00:59:08 -07:00
var nodeBlacklistEvent *pbind.PermissionsNodeBlacklisted
2018-08-31 04:35:35 -07:00
_, err = permissions.WatchNodeBlacklisted(opts, ch)
if err != nil {
log.Info("Failed WatchNodeBlacklisted: %v", err)
}
for {
select {
case nodeBlacklistEvent = <-ch:
p.updateDisallowedNodes(nodeBlacklistEvent)
2018-08-31 04:35:35 -07:00
}
}
2018-08-31 04:35:35 -07:00
}
//this function populates the new node information into the permissioned-nodes.json file
func (p *PermissionCtrl) updatePermissionedNodes(enodeId, ipAddrPort, discPort, raftPort string, operation NodeOperation) {
newEnodeId := formatEnodeId(enodeId, ipAddrPort, discPort, raftPort, p.isRaft)
//new logic to update the server KnownNodes variable for permissioning
server := p.node.Server();
newNode, err := discover.ParseNode(newEnodeId)
if err != nil {
log.Error("updatePermissionedNodes: Node URL", "url", newEnodeId, "err", err)
}
if (operation == NodeAdd) {
// Add the new enode id to server.KnownNodes
server.KnownNodes = append(server.KnownNodes, newNode)
} else {
// delete the new enode id from server.KnownNodes
2018-08-16 20:20:33 -07:00
index := 0
for i, node := range server.KnownNodes {
if (node.ID == newNode.ID) {
2018-08-16 20:20:33 -07:00
index = i
}
}
server.KnownNodes = append(server.KnownNodes[:index], server.KnownNodes[index+1:]...)
}
}
2018-08-31 04:35:35 -07:00
//this function populates the new node information into the permissioned-nodes.json file
2018-10-30 00:59:08 -07:00
func (p *PermissionCtrl) updateDisallowedNodes(nodeBlacklistEvent *pbind.PermissionsNodeBlacklisted) {
dataDir := p.node.InstanceDir()
2018-08-31 04:35:35 -07:00
log.Debug("updateDisallowedNodes", "DataDir", dataDir, "file", BLACKLIST_CONFIG)
2018-09-02 23:59:45 -07:00
fileExisted := true
2018-08-31 04:35:35 -07:00
path := filepath.Join(dataDir, BLACKLIST_CONFIG)
2018-09-02 23:59:45 -07:00
// Check if the file is existing. If the file is not existing create the file
2018-08-31 04:35:35 -07:00
if _, err := os.Stat(path); err != nil {
log.Error("Read Error for disallowed-nodes.json file.", "err", err)
2018-08-31 04:35:35 -07:00
if _, err := os.OpenFile(path, os.O_CREATE|os.O_RDWR, 0644); err != nil {
log.Error("Failed to create disallowed-nodes.json file ", "err", err)
return
2018-08-31 04:35:35 -07:00
}
2018-09-02 23:59:45 -07:00
fileExisted = false
2018-08-31 04:35:35 -07:00
}
nodelist := []string{}
2018-09-02 23:59:45 -07:00
// Load the nodes from the config file
if fileExisted == true {
blob, err := ioutil.ReadFile(path)
if err != nil {
log.Error("updateDisallowedNodes Failed to access disallowed-nodes.json", "err", err)
return
}
if (blob != nil) {
if err := json.Unmarshal(blob, &nodelist); err != nil {
log.Error("updateDisallowedNodes: Failed to load nodes list", "err", err)
return
2018-09-02 23:59:45 -07:00
}
2018-08-31 04:35:35 -07:00
}
}
newEnodeId := formatEnodeId(nodeBlacklistEvent.EnodeId, nodeBlacklistEvent.IpAddrPort, nodeBlacklistEvent.DiscPort, nodeBlacklistEvent.RaftPort, p.isRaft)
2018-08-31 04:35:35 -07:00
nodelist = append(nodelist, newEnodeId)
mu := sync.RWMutex{}
2018-09-02 23:59:45 -07:00
blob, _ := json.Marshal(nodelist)
2018-08-31 04:35:35 -07:00
mu.Lock()
if err := ioutil.WriteFile(path, blob, 0644); err != nil {
2018-08-31 04:35:35 -07:00
log.Error("updateDisallowedNodes: Error writing new node info to file", "err", err)
}
mu.Unlock()
// Disconnect the peer if it is already connected
p.disconnectNode(newEnodeId)
2018-08-31 04:35:35 -07:00
}
// Manages account level permissions update
func (p *PermissionCtrl) manageAccountPermissions() error {
//monitor for nodes deletiin via smart contract
go p.monitorAccountPermissions()
return nil
}
// populates the nodes list from permissioned-nodes.json into the permissions
// smart contract
func (p *PermissionCtrl) populatePermissionedNodes() error {
2018-10-30 00:59:08 -07:00
permissions, err := pbind.NewPermissionsFilterer(params.QuorumPermissionsContract, p.ethClnt)
if err != nil {
log.Error("Failed to monitor node delete: ", "err", err)
return err
}
opts := &bind.FilterOpts{}
pastAddEvent, err := permissions.FilterNodeApproved(opts)
recExists := true
for recExists {
recExists = pastAddEvent.Next()
if recExists {
p.updatePermissionedNodes(pastAddEvent.Event.EnodeId, pastAddEvent.Event.IpAddrPort, pastAddEvent.Event.DiscPort, pastAddEvent.Event.RaftPort, NodeAdd)
}
}
opts = &bind.FilterOpts{}
pastDelEvent, err := permissions.FilterNodeDeactivated(opts)
recExists = true
for recExists {
recExists = pastDelEvent.Next()
if recExists {
p.updatePermissionedNodes(pastDelEvent.Event.EnodeId, pastDelEvent.Event.IpAddrPort, pastDelEvent.Event.DiscPort, pastDelEvent.Event.RaftPort, NodeDelete)
}
}
return nil
}
// populates the nodes list from permissioned-nodes.json into the permissions
// smart contract
func (p *PermissionCtrl) populateAcctPermissions() error {
2018-10-30 00:59:08 -07:00
permissions, err := pbind.NewPermissionsFilterer(params.QuorumPermissionsContract, p.ethClnt)
if err != nil {
log.Error("Failed to monitor node delete: ", "err", err)
return err
}
opts := &bind.FilterOpts{}
2018-09-05 19:40:21 -07:00
pastEvents, err := permissions.FilterAccountAccessModified(opts)
recExists := true
for recExists {
recExists = pastEvents.Next()
if recExists {
2018-09-05 19:40:21 -07:00
types.AddAccountAccess(pastEvents.Event.Address, pastEvents.Event.Access)
}
}
return nil
}
// Monitors permissions changes at acount level and uodate the global permissions
// map with the same
func (p *PermissionCtrl) monitorAccountPermissions() {
2018-10-30 00:59:08 -07:00
permissions, err := pbind.NewPermissionsFilterer(params.QuorumPermissionsContract, p.ethClnt)
if err != nil {
log.Error("Failed to monitor Account permissions : ", "err", err)
}
2018-10-30 00:59:08 -07:00
ch := make(chan *pbind.PermissionsAccountAccessModified)
opts := &bind.WatchOpts{}
var blockNumber uint64 = 1
opts.Start = &blockNumber
2018-10-30 00:59:08 -07:00
var newEvent *pbind.PermissionsAccountAccessModified
2018-09-05 19:40:21 -07:00
_, err = permissions.WatchAccountAccessModified(opts, ch)
2018-08-16 20:20:33 -07:00
if err != nil {
log.Info("Failed NewNodeProposed: %v", err)
}
for {
2018-08-16 20:20:33 -07:00
select {
case newEvent = <-ch:
2018-09-05 19:40:21 -07:00
types.AddAccountAccess(newEvent.Address, newEvent.Access)
}
}
}
2018-09-19 18:51:36 -07:00
// Disconnect the node from the network
func (p *PermissionCtrl) disconnectNode(enodeId string) {
if p.isRaft {
2018-09-19 18:51:36 -07:00
var raftService *raft.RaftService
if err := p.node.Service(&raftService); err == nil {
2018-09-19 18:51:36 -07:00
raftApi := raft.NewPublicRaftAPI(raftService)
//get the raftId for the given enodeId
raftId, err := raftApi.GetRaftId(enodeId)
if err == nil {
raftApi.RemovePeer(raftId)
}
}
} else {
// Istanbul - disconnect the peer
server := p.node.Server()
2018-09-19 18:51:36 -07:00
if server != nil {
node, err := discover.ParseNode(enodeId)
if err == nil {
server.RemovePeer(node)
}
}
}
}
2018-09-19 22:55:57 -07:00
// helper function to format EnodeId
2018-10-23 08:00:57 -07:00
// This will format the EnodeId and return
func formatEnodeId(enodeId, ipAddrPort, discPort, raftPort string, isRaft bool) string {
2018-09-19 22:55:57 -07:00
newEnodeId := "enode://" + enodeId + "@" + ipAddrPort + "?discPort=" + discPort
if isRaft {
newEnodeId += "&raftport=" + raftPort
2018-09-19 22:55:57 -07:00
}
return newEnodeId
}
//populates the nodes list from permissioned-nodes.json into the permissions
//smart contract
func (p *PermissionCtrl) populateStaticNodesToContract() {
2018-10-30 00:59:08 -07:00
permissionsContract, err := pbind.NewPermissions(params.QuorumPermissionsContract, p.ethClnt)
if err != nil {
utils.Fatalf("Failed to instantiate a Permissions contract: %v", err)
}
2018-10-30 23:42:29 -07:00
auth := bind.NewKeyedTransactor(p.key)
if err != nil {
utils.Fatalf("Failed to create authorized transactor: %v", err)
}
2018-10-30 00:59:08 -07:00
permissionsSession := &pbind.PermissionsSession{
Contract: permissionsContract,
CallOpts: bind.CallOpts{
Pending: true,
},
TransactOpts: bind.TransactOpts{
From: auth.From,
Signer: auth.Signer,
GasLimit: 4700000,
GasPrice: big.NewInt(0),
},
}
tx, err := permissionsSession.GetNetworkBootStatus()
if err != nil {
log.Warn("Failed to udpate network boot status ", "err", err)
}
if tx != true {
datadir := p.node.InstanceDir()
nodes := p2p.ParsePermissionedNodes(datadir)
for _, node := range nodes {
enodeID := node.ID.String()
ipAddr := node.IP.String()
port := fmt.Sprintf("%v", node.TCP)
discPort := fmt.Sprintf("%v", node.UDP)
raftPort := fmt.Sprintf("%v", node.RaftPort)
ipAddrPort := ipAddr + ":" + port
log.Trace("Adding node to permissions contract", "enodeID", enodeID)
nonce := p.eth.TxPool().Nonce(permissionsSession.TransactOpts.From)
permissionsSession.TransactOpts.Nonce = new(big.Int).SetUint64(nonce)
tx, err := permissionsSession.ProposeNode(enodeID, ipAddrPort, discPort, raftPort)
if err != nil {
log.Warn("Failed to propose node", "err", err)
}
log.Debug("Transaction pending", "tx hash", tx.Hash())
}
// update the network boot status to true
nonce := p.eth.TxPool().Nonce(permissionsSession.TransactOpts.From)
permissionsSession.TransactOpts.Nonce = new(big.Int).SetUint64(nonce)
_, err := permissionsSession.UpdateNetworkBootStatus()
if err != nil {
log.Warn("Failed to udpate network boot status ", "err", err)
}
}
}