mirror of
https://github.com/tendermint/tendermint.git
synced 2026-01-08 06:15:33 +00:00
* Add protos for ExtendedCommit Cherry-pick from e73f0178b72a16ee81f8e856aadf651f2c62ec6e just the changes to the .proto files, since we have deleted the .intermediate files. Signed-off-by: Thane Thomson <connect@thanethomson.com> * make proto-gen Signed-off-by: Thane Thomson <connect@thanethomson.com> * BlockStore holds extended commit Cherry-pick 8d504d4b50ec6afbdffe2df7ababbef30e15053d and fix conflicts. Signed-off-by: Thane Thomson <connect@thanethomson.com> * Reshuffle ExtendedCommit and ExtendedCommitSig Separate the data structures and functions from their Commit-oriented counterparts to adhere to the current coding style. Signed-off-by: Thane Thomson <connect@thanethomson.com> * Fix exit condition in blocksync * Add note to remove TxResult proto As Sergio pointed out in 3e31aa6f583cdc71e208ed03a82f1d804ec0de49, this proto message can probably be removed. We should do this in a separate PR. Signed-off-by: Thane Thomson <connect@thanethomson.com> * Lift termination condition into for loop Signed-off-by: Thane Thomson <connect@thanethomson.com> * Enforce vote extension signature requirement Signed-off-by: Thane Thomson <connect@thanethomson.com> * Expand on comment for PeekTwoBlocks for posterity Signed-off-by: Thane Thomson <connect@thanethomson.com> * Isolate TODO more clearly Signed-off-by: Thane Thomson <connect@thanethomson.com> * make mockery Signed-off-by: Thane Thomson <connect@thanethomson.com> * Fix comment Signed-off-by: Thane Thomson <connect@thanethomson.com> * Make panic output from BlockStore.SaveBlock more readable Signed-off-by: Thane Thomson <connect@thanethomson.com> * Add helper methods to ExtendedCommitSig and ExtendedCommit Signed-off-by: Thane Thomson <connect@thanethomson.com> * Fix most tests except TestHandshake* Signed-off-by: Thane Thomson <connect@thanethomson.com> * Fix store prefix collision Signed-off-by: Thane Thomson <connect@thanethomson.com> * Fix TestBlockFetchAtHeight Signed-off-by: Thane Thomson <connect@thanethomson.com> * Remove global state from store tests Signed-off-by: Thane Thomson <connect@thanethomson.com> * Apply suggestions from code review Co-authored-by: M. J. Fromberger <fromberger@interchain.io> Co-authored-by: Sergio Mena <sergio@informal.systems> * blocksync: Just return error Signed-off-by: Thane Thomson <connect@thanethomson.com> * make format Signed-off-by: Thane Thomson <connect@thanethomson.com> * types: Remove unused/commented-out code Signed-off-by: Thane Thomson <connect@thanethomson.com> * blocksync: Change pool AddBlock function signature to return errors Signed-off-by: Thane Thomson <connect@thanethomson.com> * types: Improve legibility of switch statements Signed-off-by: Thane Thomson <connect@thanethomson.com> * blocksync: Expand on extended commit requirement in AddBlock description Signed-off-by: Thane Thomson <connect@thanethomson.com> * blocksync: Return error without also logging it Signed-off-by: Thane Thomson <connect@thanethomson.com> * consensus: Rename short-lived local variable Signed-off-by: Thane Thomson <connect@thanethomson.com> * consensus: Allocate TODO to Sergio Signed-off-by: Thane Thomson <connect@thanethomson.com> * evidence/pool_test: Inline slice construction Signed-off-by: Thane Thomson <connect@thanethomson.com> * state: Rename LoadBlockExtCommit to LoadBlockExtendedCommit Signed-off-by: Thane Thomson <connect@thanethomson.com> * proto: Remove TODO on TxResult Signed-off-by: Thane Thomson <connect@thanethomson.com> * types: Minor format Signed-off-by: Thane Thomson <connect@thanethomson.com> * types: Reformat ExtendedCommitSig.BlockID Signed-off-by: Thane Thomson <connect@thanethomson.com> * types: Remove NewExtendedCommit constructor Signed-off-by: Thane Thomson <connect@thanethomson.com> * types: Remove NewCommit constructor Signed-off-by: Thane Thomson <connect@thanethomson.com> * types: Shorten receiver names for ExtendedCommit Signed-off-by: Thane Thomson <connect@thanethomson.com> * types: Convert ExtendedCommit.Copy to a deep clone Signed-off-by: Thane Thomson <connect@thanethomson.com> * types: Assign TODO to Sergio Signed-off-by: Thane Thomson <connect@thanethomson.com> * types: Fix legibility nits Signed-off-by: Thane Thomson <connect@thanethomson.com> * types: Improve legibility Signed-off-by: Thane Thomson <connect@thanethomson.com> * store/state: Add TODO to move prefixes to common package Signed-off-by: Thane Thomson <connect@thanethomson.com> * Propagate validator info to PrepareProposal In order to propagate validator voting power through to PrepareProposal, we need to load the validator set info from the height corresponding to the extended commit that we're passing through to PrepareProposal as the "LocalLastCommit". Signed-off-by: Thane Thomson <connect@thanethomson.com> * Rename local var for clarity Signed-off-by: Thane Thomson <connect@thanethomson.com> * Fix TestMaxProposalBlockSize Signed-off-by: Thane Thomson <connect@thanethomson.com> * Rename local var for clarity Signed-off-by: Thane Thomson <connect@thanethomson.com> * Remove debug log Signed-off-by: Thane Thomson <connect@thanethomson.com> * Remove CommigSig.ForBlock helper Signed-off-by: Thane Thomson <connect@thanethomson.com> * Remove CommigSig.Absent helper Signed-off-by: Thane Thomson <connect@thanethomson.com> * Remove ExtendedCommitSig.ForBlock helper Signed-off-by: Thane Thomson <connect@thanethomson.com> * Remove ExtendedCommitSig.Absent helper Signed-off-by: Thane Thomson <connect@thanethomson.com> * There are no extended commits below the initial height Signed-off-by: Thane Thomson <connect@thanethomson.com> * Fix comment grammar Signed-off-by: Thane Thomson <connect@thanethomson.com> * Remove JSON encoding from ExtendedCommit Signed-off-by: Thane Thomson <connect@thanethomson.com> * Embed CommitSig into ExtendedCommitSig instead of duplicating fields Signed-off-by: Thane Thomson <connect@thanethomson.com> * Rename ExtendedCommit vote_extension field to extension for consistency with domain types Signed-off-by: Thane Thomson <connect@thanethomson.com> * blocksync: Panic if we peek a block without an extended commit Signed-off-by: Thane Thomson <connect@thanethomson.com> * Apply suggestions from code review Co-authored-by: M. J. Fromberger <fromberger@interchain.io> * Remove Sergio from TODO Signed-off-by: Thane Thomson <connect@thanethomson.com> * Increase hard-coded vote extension max size to 1MB Signed-off-by: Thane Thomson <connect@thanethomson.com> * state: Remove unnecessary comment Signed-off-by: Thane Thomson <connect@thanethomson.com> * state: Ensure no of commit sigs equals validator set length Signed-off-by: Thane Thomson <connect@thanethomson.com> * make format Signed-off-by: Thane Thomson <connect@thanethomson.com> * types: Minor legibility improvements Signed-off-by: Thane Thomson <connect@thanethomson.com> * Improve legibility Signed-off-by: Thane Thomson <connect@thanethomson.com> * types: Remove unused GetVotes function on VoteSet Signed-off-by: Thane Thomson <connect@thanethomson.com> * Refactor TestMaxProposalBlockSize to construct more realistic extended commit Signed-off-by: Thane Thomson <connect@thanethomson.com> * Refactor buildExtendedCommitInfo to resemble buildLastCommitInfo Signed-off-by: Thane Thomson <connect@thanethomson.com> * Apply suggestions from code review Co-authored-by: M. J. Fromberger <fromberger@interchain.io> * abci++: Disable VerifyVoteExtension call on nil precommits (#8491) Signed-off-by: Thane Thomson <connect@thanethomson.com> * types: Require vote extensions on non-nil precommits and not otherwise Signed-off-by: Thane Thomson <connect@thanethomson.com> * Disable lint Signed-off-by: Thane Thomson <connect@thanethomson.com> * Increase timeout for TestReactorVotingPowerChange to counter flakiness Signed-off-by: Thane Thomson <connect@thanethomson.com> * Only sign and verify vote extensions in non-nil precommits Signed-off-by: Thane Thomson <connect@thanethomson.com> * Revert "Disable lint" This reverts commit6fffbf9402. Signed-off-by: Thane Thomson <connect@thanethomson.com> * Add missing non-nil check uncovered non-deterministically in TestHandshakeReplayAll Signed-off-by: Thane Thomson <connect@thanethomson.com> * Expand error message for accuracy Signed-off-by: Thane Thomson <connect@thanethomson.com> * Only call ExtendVote when we make non-nil precommits Signed-off-by: Thane Thomson <connect@thanethomson.com> * Revert "Increase timeout for TestReactorVotingPowerChange to counter flakiness" This reverts commitaf514939db. Signed-off-by: Thane Thomson <connect@thanethomson.com> * Refactor ValidateBasic for ExtendedCommitSig for legibility Signed-off-by: Thane Thomson <connect@thanethomson.com> Co-authored-by: Sergio Mena <sergio@informal.systems> Co-authored-by: M. J. Fromberger <fromberger@interchain.io>
360 lines
12 KiB
Go
360 lines
12 KiB
Go
package types
|
|
|
|
import (
|
|
"errors"
|
|
"fmt"
|
|
|
|
"github.com/tendermint/tendermint/crypto"
|
|
"github.com/tendermint/tendermint/crypto/batch"
|
|
tmmath "github.com/tendermint/tendermint/libs/math"
|
|
)
|
|
|
|
const batchVerifyThreshold = 2
|
|
|
|
func shouldBatchVerify(vals *ValidatorSet, commit *Commit) bool {
|
|
return len(commit.Signatures) >= batchVerifyThreshold && batch.SupportsBatchVerifier(vals.GetProposer().PubKey)
|
|
}
|
|
|
|
// TODO(wbanfield): determine if the following comment is still true regarding Gaia.
|
|
|
|
// VerifyCommit verifies +2/3 of the set had signed the given commit.
|
|
//
|
|
// It checks all the signatures! While it's safe to exit as soon as we have
|
|
// 2/3+ signatures, doing so would impact incentivization logic in the ABCI
|
|
// application that depends on the LastCommitInfo sent in FinalizeBlock, which
|
|
// includes which validators signed. For instance, Gaia incentivizes proposers
|
|
// with a bonus for including more than +2/3 of the signatures.
|
|
func VerifyCommit(chainID string, vals *ValidatorSet, blockID BlockID,
|
|
height int64, commit *Commit) error {
|
|
// run a basic validation of the arguments
|
|
if err := verifyBasicValsAndCommit(vals, commit, height, blockID); err != nil {
|
|
return err
|
|
}
|
|
|
|
// calculate voting power needed. Note that total voting power is capped to
|
|
// 1/8th of max int64 so this operation should never overflow
|
|
votingPowerNeeded := vals.TotalVotingPower() * 2 / 3
|
|
|
|
// ignore all absent signatures
|
|
ignore := func(c CommitSig) bool { return c.BlockIDFlag == BlockIDFlagAbsent }
|
|
|
|
// only count the signatures that are for the block
|
|
count := func(c CommitSig) bool { return c.BlockIDFlag == BlockIDFlagCommit }
|
|
|
|
// attempt to batch verify
|
|
if shouldBatchVerify(vals, commit) {
|
|
return verifyCommitBatch(chainID, vals, commit,
|
|
votingPowerNeeded, ignore, count, true, true)
|
|
}
|
|
|
|
// if verification failed or is not supported then fallback to single verification
|
|
return verifyCommitSingle(chainID, vals, commit, votingPowerNeeded,
|
|
ignore, count, true, true)
|
|
}
|
|
|
|
// LIGHT CLIENT VERIFICATION METHODS
|
|
|
|
// VerifyCommitLight verifies +2/3 of the set had signed the given commit.
|
|
//
|
|
// This method is primarily used by the light client and does not check all the
|
|
// signatures.
|
|
func VerifyCommitLight(chainID string, vals *ValidatorSet, blockID BlockID,
|
|
height int64, commit *Commit) error {
|
|
// run a basic validation of the arguments
|
|
if err := verifyBasicValsAndCommit(vals, commit, height, blockID); err != nil {
|
|
return err
|
|
}
|
|
|
|
// calculate voting power needed
|
|
votingPowerNeeded := vals.TotalVotingPower() * 2 / 3
|
|
|
|
// ignore all commit signatures that are not for the block
|
|
ignore := func(c CommitSig) bool { return c.BlockIDFlag != BlockIDFlagCommit }
|
|
|
|
// count all the remaining signatures
|
|
count := func(c CommitSig) bool { return true }
|
|
|
|
// attempt to batch verify
|
|
if shouldBatchVerify(vals, commit) {
|
|
return verifyCommitBatch(chainID, vals, commit,
|
|
votingPowerNeeded, ignore, count, false, true)
|
|
}
|
|
|
|
// if verification failed or is not supported then fallback to single verification
|
|
return verifyCommitSingle(chainID, vals, commit, votingPowerNeeded,
|
|
ignore, count, false, true)
|
|
}
|
|
|
|
// VerifyCommitLightTrusting verifies that trustLevel of the validator set signed
|
|
// this commit.
|
|
//
|
|
// NOTE the given validators do not necessarily correspond to the validator set
|
|
// for this commit, but there may be some intersection.
|
|
//
|
|
// This method is primarily used by the light client and does not check all the
|
|
// signatures.
|
|
func VerifyCommitLightTrusting(chainID string, vals *ValidatorSet, commit *Commit, trustLevel tmmath.Fraction) error {
|
|
// sanity checks
|
|
if vals == nil {
|
|
return errors.New("nil validator set")
|
|
}
|
|
if trustLevel.Denominator == 0 {
|
|
return errors.New("trustLevel has zero Denominator")
|
|
}
|
|
if commit == nil {
|
|
return errors.New("nil commit")
|
|
}
|
|
|
|
// safely calculate voting power needed.
|
|
totalVotingPowerMulByNumerator, overflow := safeMul(vals.TotalVotingPower(), int64(trustLevel.Numerator))
|
|
if overflow {
|
|
return errors.New("int64 overflow while calculating voting power needed. please provide smaller trustLevel numerator")
|
|
}
|
|
votingPowerNeeded := totalVotingPowerMulByNumerator / int64(trustLevel.Denominator)
|
|
|
|
// ignore all commit signatures that are not for the block
|
|
ignore := func(c CommitSig) bool { return c.BlockIDFlag != BlockIDFlagCommit }
|
|
|
|
// count all the remaining signatures
|
|
count := func(c CommitSig) bool { return true }
|
|
|
|
// attempt to batch verify commit. As the validator set doesn't necessarily
|
|
// correspond with the validator set that signed the block we need to look
|
|
// up by address rather than index.
|
|
if shouldBatchVerify(vals, commit) {
|
|
return verifyCommitBatch(chainID, vals, commit,
|
|
votingPowerNeeded, ignore, count, false, false)
|
|
}
|
|
|
|
// attempt with single verification
|
|
return verifyCommitSingle(chainID, vals, commit, votingPowerNeeded,
|
|
ignore, count, false, false)
|
|
}
|
|
|
|
// ValidateHash returns an error if the hash is not empty, but its
|
|
// size != crypto.HashSize.
|
|
func ValidateHash(h []byte) error {
|
|
if len(h) > 0 && len(h) != crypto.HashSize {
|
|
return fmt.Errorf("expected size to be %d bytes, got %d bytes",
|
|
crypto.HashSize,
|
|
len(h),
|
|
)
|
|
}
|
|
return nil
|
|
}
|
|
|
|
// Batch verification
|
|
|
|
// verifyCommitBatch batch verifies commits. This routine is equivalent
|
|
// to verifyCommitSingle in behavior, just faster iff every signature in the
|
|
// batch is valid.
|
|
//
|
|
// Note: The caller is responsible for checking to see if this routine is
|
|
// usable via `shouldVerifyBatch(vals, commit)`.
|
|
func verifyCommitBatch(
|
|
chainID string,
|
|
vals *ValidatorSet,
|
|
commit *Commit,
|
|
votingPowerNeeded int64,
|
|
ignoreSig func(CommitSig) bool,
|
|
countSig func(CommitSig) bool,
|
|
countAllSignatures bool,
|
|
lookUpByIndex bool,
|
|
) error {
|
|
var (
|
|
val *Validator
|
|
valIdx int32
|
|
talliedVotingPower int64
|
|
seenVals = make(map[int32]int, len(commit.Signatures))
|
|
batchSigIdxs = make([]int, 0, len(commit.Signatures))
|
|
)
|
|
// attempt to create a batch verifier
|
|
bv, ok := batch.CreateBatchVerifier(vals.GetProposer().PubKey)
|
|
// re-check if batch verification is supported
|
|
if !ok || len(commit.Signatures) < batchVerifyThreshold {
|
|
// This should *NEVER* happen.
|
|
return fmt.Errorf("unsupported signature algorithm or insufficient signatures for batch verification")
|
|
}
|
|
|
|
for idx, commitSig := range commit.Signatures {
|
|
// skip over signatures that should be ignored
|
|
if ignoreSig(commitSig) {
|
|
continue
|
|
}
|
|
|
|
// If the vals and commit have a 1-to-1 correspondance we can retrieve
|
|
// them by index else we need to retrieve them by address
|
|
if lookUpByIndex {
|
|
val = vals.Validators[idx]
|
|
} else {
|
|
valIdx, val = vals.GetByAddress(commitSig.ValidatorAddress)
|
|
|
|
// if the signature doesn't belong to anyone in the validator set
|
|
// then we just skip over it
|
|
if val == nil {
|
|
continue
|
|
}
|
|
|
|
// because we are getting validators by address we need to make sure
|
|
// that the same validator doesn't commit twice
|
|
if firstIndex, ok := seenVals[valIdx]; ok {
|
|
secondIndex := idx
|
|
return fmt.Errorf("double vote from %v (%d and %d)", val, firstIndex, secondIndex)
|
|
}
|
|
seenVals[valIdx] = idx
|
|
}
|
|
|
|
// Validate signature.
|
|
voteSignBytes := commit.VoteSignBytes(chainID, int32(idx))
|
|
|
|
// add the key, sig and message to the verifier
|
|
if err := bv.Add(val.PubKey, voteSignBytes, commitSig.Signature); err != nil {
|
|
return err
|
|
}
|
|
batchSigIdxs = append(batchSigIdxs, idx)
|
|
|
|
// If this signature counts then add the voting power of the validator
|
|
// to the tally
|
|
if countSig(commitSig) {
|
|
talliedVotingPower += val.VotingPower
|
|
}
|
|
|
|
// if we don't need to verify all signatures and already have sufficient
|
|
// voting power we can break from batching and verify all the signatures
|
|
if !countAllSignatures && talliedVotingPower > votingPowerNeeded {
|
|
break
|
|
}
|
|
}
|
|
|
|
// ensure that we have batched together enough signatures to exceed the
|
|
// voting power needed else there is no need to even verify
|
|
if got, needed := talliedVotingPower, votingPowerNeeded; got <= needed {
|
|
return ErrNotEnoughVotingPowerSigned{Got: got, Needed: needed}
|
|
}
|
|
|
|
// attempt to verify the batch.
|
|
ok, validSigs := bv.Verify()
|
|
if ok {
|
|
// success
|
|
return nil
|
|
}
|
|
|
|
// one or more of the signatures is invalid, find and return the first
|
|
// invalid signature.
|
|
for i, ok := range validSigs {
|
|
if !ok {
|
|
// go back from the batch index to the commit.Signatures index
|
|
idx := batchSigIdxs[i]
|
|
sig := commit.Signatures[idx]
|
|
return fmt.Errorf("wrong signature (#%d): %X", idx, sig)
|
|
}
|
|
}
|
|
|
|
// execution reaching here is a bug, and one of the following has
|
|
// happened:
|
|
// * non-zero tallied voting power, empty batch (impossible?)
|
|
// * bv.Verify() returned `false, []bool{true, ..., true}` (BUG)
|
|
return fmt.Errorf("BUG: batch verification failed with no invalid signatures")
|
|
}
|
|
|
|
// Single Verification
|
|
|
|
// verifyCommitSingle single verifies commits.
|
|
// If a key does not support batch verification, or batch verification fails this will be used
|
|
// This method is used to check all the signatures included in a commit.
|
|
// It is used in consensus for validating a block LastCommit.
|
|
// CONTRACT: both commit and validator set should have passed validate basic
|
|
func verifyCommitSingle(
|
|
chainID string,
|
|
vals *ValidatorSet,
|
|
commit *Commit,
|
|
votingPowerNeeded int64,
|
|
ignoreSig func(CommitSig) bool,
|
|
countSig func(CommitSig) bool,
|
|
countAllSignatures bool,
|
|
lookUpByIndex bool,
|
|
) error {
|
|
var (
|
|
val *Validator
|
|
valIdx int32
|
|
talliedVotingPower int64
|
|
voteSignBytes []byte
|
|
seenVals = make(map[int32]int, len(commit.Signatures))
|
|
)
|
|
for idx, commitSig := range commit.Signatures {
|
|
if ignoreSig(commitSig) {
|
|
continue
|
|
}
|
|
|
|
// If the vals and commit have a 1-to-1 correspondance we can retrieve
|
|
// them by index else we need to retrieve them by address
|
|
if lookUpByIndex {
|
|
val = vals.Validators[idx]
|
|
} else {
|
|
valIdx, val = vals.GetByAddress(commitSig.ValidatorAddress)
|
|
|
|
// if the signature doesn't belong to anyone in the validator set
|
|
// then we just skip over it
|
|
if val == nil {
|
|
continue
|
|
}
|
|
|
|
// because we are getting validators by address we need to make sure
|
|
// that the same validator doesn't commit twice
|
|
if firstIndex, ok := seenVals[valIdx]; ok {
|
|
secondIndex := idx
|
|
return fmt.Errorf("double vote from %v (%d and %d)", val, firstIndex, secondIndex)
|
|
}
|
|
seenVals[valIdx] = idx
|
|
}
|
|
|
|
voteSignBytes = commit.VoteSignBytes(chainID, int32(idx))
|
|
|
|
if !val.PubKey.VerifySignature(voteSignBytes, commitSig.Signature) {
|
|
return fmt.Errorf("wrong signature (#%d): %X", idx, commitSig.Signature)
|
|
}
|
|
|
|
// If this signature counts then add the voting power of the validator
|
|
// to the tally
|
|
if countSig(commitSig) {
|
|
talliedVotingPower += val.VotingPower
|
|
}
|
|
|
|
// check if we have enough signatures and can thus exit early
|
|
if !countAllSignatures && talliedVotingPower > votingPowerNeeded {
|
|
return nil
|
|
}
|
|
}
|
|
|
|
if got, needed := talliedVotingPower, votingPowerNeeded; got <= needed {
|
|
return ErrNotEnoughVotingPowerSigned{Got: got, Needed: needed}
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
func verifyBasicValsAndCommit(vals *ValidatorSet, commit *Commit, height int64, blockID BlockID) error {
|
|
if vals == nil {
|
|
return errors.New("nil validator set")
|
|
}
|
|
|
|
if commit == nil {
|
|
return errors.New("nil commit")
|
|
}
|
|
|
|
if vals.Size() != len(commit.Signatures) {
|
|
return NewErrInvalidCommitSignatures(vals.Size(), len(commit.Signatures))
|
|
}
|
|
|
|
// Validate Height and BlockID.
|
|
if height != commit.Height {
|
|
return NewErrInvalidCommitHeight(height, commit.Height)
|
|
}
|
|
if !blockID.Equals(commit.BlockID) {
|
|
return fmt.Errorf("invalid commit -- wrong block ID: want %v, got %v",
|
|
blockID, commit.BlockID)
|
|
}
|
|
|
|
return nil
|
|
}
|