xrpld
Loading...
Searching...
No Matches
ConfidentialMPTClawback.cpp
1#include <xrpl/tx/transactors/token/ConfidentialMPTClawback.h>
2
3#include <xrpl/beast/utility/Journal.h>
4#include <xrpl/beast/utility/instrumentation.h>
5#include <xrpl/core/ServiceRegistry.h>
6#include <xrpl/ledger/ReadView.h>
7#include <xrpl/protocol/ConfidentialTransfer.h>
8#include <xrpl/protocol/Feature.h>
9#include <xrpl/protocol/Indexes.h>
10#include <xrpl/protocol/LedgerFormats.h>
11#include <xrpl/protocol/Protocol.h>
12#include <xrpl/protocol/SField.h>
13#include <xrpl/protocol/STTx.h>
14#include <xrpl/protocol/TER.h>
15#include <xrpl/protocol/XRPAmount.h>
16#include <xrpl/tx/Transactor.h>
17
18#include <memory>
19#include <utility>
20
21namespace xrpl {
22
25{
26 auto const account = ctx.tx[sfAccount];
27
28 // Only issuer can clawback
29 if (account != MPTIssue(ctx.tx[sfMPTokenIssuanceID]).getIssuer())
30 return temMALFORMED;
31
32 // Cannot clawback from self
33 if (account == ctx.tx[sfHolder])
34 return temMALFORMED;
35
36 // Check invalid claw amount
37 auto const clawAmount = ctx.tx[sfMPTAmount];
38 if (clawAmount == 0 || clawAmount > kMaxMpTokenAmount)
39 return temBAD_AMOUNT;
40
41 // Verify proof length
42 if (ctx.tx[sfZKProof].length() != kEcClawbackProofLength)
43 return temMALFORMED;
44
45 return tesSUCCESS;
46}
47
53
54TER
56{
57 // Check if sender account exists
58 auto const account = ctx.tx[sfAccount];
59 if (!ctx.view.exists(keylet::account(account)))
60 return terNO_ACCOUNT;
61
62 // Check if holder account exists
63 auto const holder = ctx.tx[sfHolder];
64 if (!ctx.view.exists(keylet::account(holder)))
65 return tecNO_TARGET;
66
67 // Check if MPT issuance exists
68 auto const mptIssuanceID = ctx.tx[sfMPTokenIssuanceID];
69 auto const sleIssuance = ctx.view.read(keylet::mptokenIssuance(mptIssuanceID));
70 if (!sleIssuance)
72
73 // Sanity check: account must be the same as issuer
74 if (sleIssuance->getAccountID(sfIssuer) != account)
75 {
76 // LCOV_EXCL_START
77 UNREACHABLE(
78 "xrpl::ConfidentialMPTClawback::preclaim : preflight already validated the "
79 "submitter is the issuer");
80 return tefINTERNAL;
81 // LCOV_EXCL_STOP
82 }
83
84 // Check if issuance has issuer ElGamal public key
85 if (!sleIssuance->isFieldPresent(sfIssuerEncryptionKey))
86 return tecNO_PERMISSION;
87
88 // Check if clawback is allowed
89 if (!sleIssuance->isFlag(lsfMPTCanClawback))
90 return tecNO_PERMISSION;
91
92 // Check if issuance allows confidential transfer
93 if (!sleIssuance->isFlag(lsfMPTCanHoldConfidentialBalance))
94 return tecNO_PERMISSION;
95
96 // Check holder's MPToken
97 auto const sleHolderMPToken = ctx.view.read(keylet::mptoken(mptIssuanceID, holder));
98 if (!sleHolderMPToken)
100
101 // Check if holder has confidential balances to claw back
102 if (!sleHolderMPToken->isFieldPresent(sfIssuerEncryptedBalance))
103 return tecNO_PERMISSION;
104
105 // Check if Holder has ElGamal public Key
106 if (!sleHolderMPToken->isFieldPresent(sfHolderEncryptionKey))
107 return tecNO_PERMISSION;
108
109 // Sanity check: claw amount can not exceed confidential outstanding amount
110 // or total outstanding amount (prevents underflow in doApply)
111 auto const amount = ctx.tx[sfMPTAmount];
112 if (amount > (*sleIssuance)[~sfConfidentialOutstandingAmount].value_or(0) ||
113 amount > (*sleIssuance)[sfOutstandingAmount])
115
116 auto const contextHash =
117 getClawbackContextHash(account, mptIssuanceID, ctx.tx.getSeqProxy().value(), holder);
118
119 // Verify the revealed confidential amount by the issuer matches the exact
120 // confidential balance of the holder.
121 return verifyClawbackProof(
122 amount,
123 ctx.tx[sfZKProof],
124 (*sleIssuance)[sfIssuerEncryptionKey],
125 (*sleHolderMPToken)[sfIssuerEncryptedBalance],
126 contextHash);
127}
128
129TER
131{
132 auto const mptIssuanceID = ctx_.tx[sfMPTokenIssuanceID];
133 auto const holder = ctx_.tx[sfHolder];
134
135 auto sleIssuance = view().peek(keylet::mptokenIssuance(mptIssuanceID));
136 auto sleHolderMPToken = view().peek(keylet::mptoken(mptIssuanceID, holder));
137
138 if (!sleIssuance || !sleHolderMPToken)
139 {
140 // LCOV_EXCL_START
141 UNREACHABLE(
142 "xrpl::ConfidentialMPTClawback::doApply : preclaim already validated these "
143 "objects exist");
144 return tecINTERNAL;
145 // LCOV_EXCL_STOP
146 }
147
148 auto const clawAmount = ctx_.tx[sfMPTAmount];
149
150 auto const holderPubKey = (*sleHolderMPToken)[sfHolderEncryptionKey];
151 auto const issuerPubKey = (*sleIssuance)[sfIssuerEncryptionKey];
152
153 // After clawback, the balance should be encrypted zero.
154 auto const encZeroForHolder = encryptCanonicalZeroAmount(holderPubKey, holder, mptIssuanceID);
155 if (!encZeroForHolder)
156 {
157 // LCOV_EXCL_START
158 UNREACHABLE(
159 "xrpl::ConfidentialMPTClawback::doApply : canonical zero encryption cannot fail "
160 "for an already-valid holder public key");
161 return tecINTERNAL;
162 // LCOV_EXCL_STOP
163 }
164
165 auto encZeroForIssuer = encryptCanonicalZeroAmount(issuerPubKey, holder, mptIssuanceID);
166 if (!encZeroForIssuer)
167 {
168 // LCOV_EXCL_START
169 UNREACHABLE(
170 "xrpl::ConfidentialMPTClawback::doApply : canonical zero encryption cannot fail "
171 "for an already-valid issuer public key");
172 return tecINTERNAL;
173 // LCOV_EXCL_STOP
174 }
175
176 // Set holder's confidential balances to encrypted zero
177 (*sleHolderMPToken)[sfConfidentialBalanceInbox] = *encZeroForHolder;
178 (*sleHolderMPToken)[sfConfidentialBalanceSpending] = *encZeroForHolder;
179 (*sleHolderMPToken)[sfIssuerEncryptedBalance] = std::move(*encZeroForIssuer);
180 incrementConfidentialVersion(*sleHolderMPToken);
181
182 if (sleHolderMPToken->isFieldPresent(sfAuditorEncryptedBalance))
183 {
184 // Sanity check: the issuance must have an auditor public key if
185 // auditing is enabled.
186 if (!sleIssuance->isFieldPresent(sfAuditorEncryptionKey))
187 {
188 // LCOV_EXCL_START
189 UNREACHABLE(
190 "xrpl::ConfidentialMPTClawback::doApply : the holder's auditor balance implies "
191 "the issuance has an auditor public key");
192 return tecINTERNAL;
193 // LCOV_EXCL_STOP
194 }
195
196 auto const auditorPubKey = (*sleIssuance)[sfAuditorEncryptionKey];
197
198 auto encZeroForAuditor = encryptCanonicalZeroAmount(auditorPubKey, holder, mptIssuanceID);
199
200 if (!encZeroForAuditor)
201 {
202 // LCOV_EXCL_START
203 UNREACHABLE(
204 "xrpl::ConfidentialMPTClawback::doApply : canonical zero encryption cannot "
205 "fail for an already-valid auditor public key");
206 return tecINTERNAL;
207 // LCOV_EXCL_STOP
208 }
209
210 (*sleHolderMPToken)[sfAuditorEncryptedBalance] = std::move(*encZeroForAuditor);
211 }
212
213 // Allow clawback on stale mirrors since the issuer can still generate the
214 // proof using the corresponding stale private key. The mirrors are updated
215 // to the current epoch during execution.
216 if (view().rules().enabled(featureConfidentialMPTKeyRotation))
217 setMirrorEpochs(*sleIssuance, *sleHolderMPToken);
218
219 // Decrease Global Confidential Outstanding Amount
220 auto const oldCOA = (*sleIssuance)[sfConfidentialOutstandingAmount];
221 if (clawAmount > oldCOA)
222 return tecINTERNAL; // LCOV_EXCL_LINE
223 (*sleIssuance)[sfConfidentialOutstandingAmount] = oldCOA - clawAmount;
224
225 // Decrease Global Total Outstanding Amount
226 auto const oldOA = (*sleIssuance)[sfOutstandingAmount];
227 if (clawAmount > oldOA)
228 return tecINTERNAL; // LCOV_EXCL_LINE
229 (*sleIssuance)[sfOutstandingAmount] = oldOA - clawAmount;
230
231 view().update(sleHolderMPToken);
232 view().update(sleIssuance);
233
234 return tesSUCCESS;
235}
236
237void
244
245bool
247 STTx const&,
248 TER,
249 XRPAmount,
250 ReadView const&,
251 beast::Journal const&)
252{
253 return true;
254}
255
256} // namespace xrpl
A generic endpoint for log messages.
Definition Journal.h:44
virtual SLE::pointer peek(Keylet const &k)=0
Prepare to modify the SLE associated with key.
virtual void update(SLE::Ref sle)=0
Indicate changes to a peeked SLE.
static TER preclaim(PreclaimContext const &ctx)
static NotTEC preflight(PreflightContext const &ctx)
static XRPAmount calculateBaseFee(ReadView const &view, STTx const &tx)
void visitInvariantEntry(bool isDelete, std::shared_ptr< SLE const > const &before, std::shared_ptr< SLE const > const &after) override
bool finalizeInvariants(STTx const &tx, TER result, XRPAmount fee, ReadView const &view, beast::Journal const &j) override
Check transaction-specific post-conditions after all entries have been visited.
AccountID const & getIssuer() const
Definition MPTIssue.cpp:29
A view into a ledger.
Definition ReadView.h:41
virtual bool exists(Keylet const &k) const =0
Determine if a state item exists.
virtual SLE::const_pointer read(Keylet const &k) const =0
Return the state item associated with a key.
SeqProxy getSeqProxy() const
Definition STTx.cpp:198
constexpr std::uint32_t value() const
Definition SeqProxy.h:80
ApplyView & view()
Definition Transactor.h:184
static XRPAmount calculateBaseFee(ReadView const &view, STTx const &tx)
ApplyContext & ctx_
Definition Transactor.h:162
Keylet mptoken(MPTID const &issuanceID, AccountID const &holder) noexcept
Definition Indexes.cpp:573
Keylet account(AccountID const &id) noexcept
AccountID root.
Definition Indexes.cpp:220
Keylet mptokenIssuance(MPTID const &issuanceID) noexcept
Definition Indexes.cpp:567
Use hash_* containers for keys that do not need a cryptographically secure hashing algorithm.
Definition algorithm.h:5
@ terNO_ACCOUNT
Definition TER.h:218
void setMirrorEpochs(SLE const &issuance, SLE &mptoken)
Set the holder's MPToken mirror epochs to match the issuance's current key epochs.
std::optional< Buffer > encryptCanonicalZeroAmount(Slice const &pubKeySlice, AccountID const &account, MPTID const &mptId)
Generates the canonical zero encryption for a specific MPToken.
constexpr std::uint32_t kConfidentialFeeMultiplier
Extra base fee multiplier charged to confidential MPT transactions.
Definition Protocol.h:551
@ tefINTERNAL
Definition TER.h:168
constexpr std::size_t kEcClawbackProofLength
Length of the ZKProof for ConfidentialMPTClawback.
Definition Protocol.h:541
TER verifyClawbackProof(uint64_t const amount, Slice const &proof, Slice const &pubKeySlice, Slice const &ciphertext, UInt256 const &contextHash)
Verifies a compact sigma clawback proof.
TERSubset< CanCvtToNotTEC > NotTEC
Definition TER.h:614
UInt256 getClawbackContextHash(AccountID const &account, UInt192 const &issuanceID, std::uint32_t sequence, AccountID const &holder)
Generates the context hash for ConfidentialMPTClawback transactions.
@ temMALFORMED
Definition TER.h:75
@ temBAD_AMOUNT
Definition TER.h:77
TERSubset< CanCvtToTER > TER
Definition TER.h:654
@ tecNO_TARGET
Definition TER.h:312
@ tecOBJECT_NOT_FOUND
Definition TER.h:334
@ tecINTERNAL
Definition TER.h:318
@ tecINSUFFICIENT_FUNDS
Definition TER.h:333
@ tecNO_PERMISSION
Definition TER.h:313
void incrementConfidentialVersion(STObject &mptoken)
Increments the confidential balance version counter on an MPToken.
constexpr std::uint64_t kMaxMpTokenAmount
The maximum amount of MPTokenIssuance.
Definition Protocol.h:297
@ tesSUCCESS
Definition TER.h:250
State information when determining if a tx is likely to claim a fee.
Definition Transactor.h:92
ReadView const & view
Definition Transactor.h:95
State information when preflighting a tx.
Definition Transactor.h:39