xrpld
Loading...
Searching...
No Matches
src/test/jtx/ConfidentialTransfer.h
1#pragma once
2
3#include <test/jtx/Account.h>
4#include <test/jtx/Env.h>
5#include <test/jtx/mpt.h>
6
7#include <xrpl/basics/Buffer.h>
8#include <xrpl/basics/base_uint.h>
9#include <xrpl/basics/contract.h>
10#include <xrpl/beast/unit_test/suite.h>
11#include <xrpl/protocol/ConfidentialTransfer.h>
12#include <xrpl/protocol/Protocol.h>
13#include <xrpl/protocol/TER.h>
14#include <xrpl/protocol/TxFlags.h>
15
16#include <array>
17#include <cstddef>
18#include <cstdint>
19#include <functional>
20#include <optional>
21#include <stdexcept>
22#include <string>
23#include <utility>
24#include <vector>
25
26namespace xrpl {
27
29{
30protected:
31 template <class T>
32 static T
33 requireOptional(std::optional<T> value, char const* message)
34 {
35 if (!value)
37 return std::move(*value);
38 }
39
40 template <class T>
41 static T const&
42 requireOptionalRef(std::optional<T> const& value, char const* message)
43 {
44 if (!value)
46 return *value;
47 }
48
49 // Creates the MPT issuance on the given Env, authorizes and funds each
50 // holder, generates keys for the issuer, holders and optional auditor,
51 // registers the issuer/auditor keys, and converts part of each holder's
52 // balance to a confidential balance.
54 {
55 // Per-holder configuration: the account, how much MPT to fund it
56 // with, and how much of that to convert to a confidential balance.
63
65
67 test::jtx::Env& env,
68 test::jtx::Account const& issuer,
69 std::vector<HolderInit> const& holders,
70 std::uint32_t flags = tfMPTCanLock | tfMPTCanHoldConfidentialBalance | tfMPTCanTransfer,
71 std::optional<test::jtx::Account> auditor = std::nullopt);
72
73 private:
76 };
77
78 // Create an issuance that can hold confidential balances, with the listed
79 // holders funded and authorized, and a key pair generated for the issuer,
80 // every holder, and every extra key owner. The keys are
81 // generated but not registered.
82 static void
85 test::jtx::Account const& issuer,
87 std::vector<test::jtx::Account> const& keyOwners = {},
88 std::uint32_t flags = tfMPTCanTransfer | tfMPTCanHoldConfidentialBalance);
89
90 // Set up an MPT environment suitable for batch testing.
91 // alice is issuer; bob has 'bobAmt' in confidential spending; carol has
92 // 'carolAmt' in confidential spending; dave is initialised with pubkey but
93 // zero spending/inbox.
94 static void
97 test::jtx::Account const& alice,
98 test::jtx::Account const& bob,
99 test::jtx::Account const& carol,
100 test::jtx::Account const& dave,
101 std::uint64_t bobAmt,
102 std::uint64_t carolAmt);
103
104 // Helper struct to encapsulate common setup for integration tests.
106 {
107 // Constants
108 uint64_t sendAmount;
109 uint32_t version;
110
111 // Blinding factors
115
116 // Encrypted amounts
121
122 // Commitments
124
125 // Long-lived pub key buffers (to avoid dangling Slice)
130
131 // Balance data
132 uint64_t prevSpending;
134
135 // Balance commitment (declared after prevSpending for init order)
137
138 // Recipients vector
140
141 // Constructor that performs all common setup
144 test::jtx::Account const& sender,
145 test::jtx::Account const& dest,
146 test::jtx::Account const& issuer,
147 uint64_t amount,
149
150 // Generate proof with current account sequence
154 test::jtx::Env& env,
155 test::jtx::Account const& sender,
156 test::jtx::Account const& dest) const;
157
159 sendArgs(
160 test::jtx::Account const& sender,
161 test::jtx::Account const& dest,
162 Buffer const& proof,
163 std::optional<TER> err = std::nullopt) const;
164 };
165
166 // Get a bad ciphertext with valid structure but cryptographic invalid for
167 // testing purposes. For preflight test purposes.
168 static Buffer const&
170
171 // Get a trivial buffer that is structurally and mathematically valid, but
172 // contains invalid data that does not match the ledger state. For preclaim
173 // test purposes.
174 static Buffer const&
176
177 // Returns a valid compressed EC point (33 bytes) that can pass preflight
178 // validation but contains invalid data for preclaim test purposes.
179 static Buffer const&
181
182 // Returns a hex-encoded send proof of the correct length filled with
183 // placeholder data. It passes the proof length check in preflight but
184 // fails proof verification.
185 static std::string
187
188 // Offset where the bulletproof begins in a send proof blob.
189 // Proof layout: [compact_sigma | bulletproof]
191
192 // Decrypts holder's current spending/inbox balances under currentKey and
193 // re-encrypts them under newKey, returning {spendingCiphertext,
194 // inboxCiphertext}. Returns std::nullopt if either balance is missing or
195 // fails to decrypt.
199 test::jtx::Account const& holder,
200 test::jtx::Account const& currentKey,
201 test::jtx::Account const& newKey);
202
203 // Generate a forged aggregated bulletproof (double bulletproof) for
204 // the given values and blinding factors. Used to test that splicing
205 // a bulletproof claiming a different remaining balance is rejected.
206 static Buffer
208 std::array<uint64_t, 2> const& values,
209 std::array<Buffer, 2> const& blindingFactors,
210 UInt256 const& contextHash);
211
212 // Generate a forged single bulletproof for a single value and blinding factor.
213 // Used to test ConvertBack overdraft prevention via bulletproof verification.
214 static Buffer
216 uint64_t value,
217 Buffer const& blindingFactor,
218 UInt256 const& contextHash);
219
220 // Forges a ConvertBack proof (compact sigma + single bulletproof) whose
221 // sigma component claims claimedBalance (which may be wrong) while binding
222 // to the real pedersen commitment and to the encrypted spending balance
223 // already on the ledger. The bulletproof component is built from the real
224 // remaining balance (realBalance - amt) so it stays honest.
225 // mpt_get_convert_back_proof validates its inputs before proving, so it
226 // cannot be used to build such an inconsistent proof.
227 static Buffer
230 test::jtx::Account const& holder,
231 uint64_t claimedBalance,
232 uint64_t realBalance,
233 uint64_t amt,
234 Buffer const& pedersenCommitment,
235 Buffer const& encryptedSpendingBalance,
236 Buffer const& pcBlindingFactor,
237 UInt256 const& contextHash);
238
239 // Forges a ConfidentialMPTSend proof (compact sigma + double bulletproof)
240 // for setup.sendAmount against setup's real balance commitment/ciphertext.
241 // mpt_get_confidential_send_proof does not allow to build a proof whose amount
242 // exceeds the sender's claimed balance.
243 static Buffer
246 test::jtx::Env& env,
247 test::jtx::Account const& sender,
248 test::jtx::Account const& dest,
249 ConfidentialSendSetup const& setup);
250};
251
252} // namespace xrpl
A testsuite class.
Definition suite.h:52
Like std::vector<char> but better.
Definition Buffer.h:19
static Buffer getForgedSingleBulletproof(uint64_t value, Buffer const &blindingFactor, UInt256 const &contextHash)
static Buffer getForgedSendProof(test::jtx::MPTTester &mpt, test::jtx::Env &env, test::jtx::Account const &sender, test::jtx::Account const &dest, ConfidentialSendSetup const &setup)
static std::optional< std::pair< Buffer, Buffer > > reencryptHolderBalances(test::jtx::MPTTester &mpt, test::jtx::Account const &holder, test::jtx::Account const &currentKey, test::jtx::Account const &newKey)
static void setupConfidentialIssuance(test::jtx::MPTTester &mpt, test::jtx::Account const &issuer, std::vector< test::jtx::Account > const &holders, std::vector< test::jtx::Account > const &keyOwners={}, std::uint32_t flags=tfMPTCanTransfer|tfMPTCanHoldConfidentialBalance)
static T requireOptional(std::optional< T > value, char const *message)
static void setupBatchEnv(test::jtx::MPTTester &mpt, test::jtx::Account const &alice, test::jtx::Account const &bob, test::jtx::Account const &carol, test::jtx::Account const &dave, std::uint64_t bobAmt, std::uint64_t carolAmt)
static T const & requireOptionalRef(std::optional< T > const &value, char const *message)
static Buffer getForgedBulletproof(std::array< uint64_t, 2 > const &values, std::array< Buffer, 2 > const &blindingFactors, UInt256 const &contextHash)
static Buffer getForgedConvertBackProof(test::jtx::MPTTester &mpt, test::jtx::Account const &holder, uint64_t claimedBalance, uint64_t realBalance, uint64_t amt, Buffer const &pedersenCommitment, Buffer const &encryptedSpendingBalance, Buffer const &pcBlindingFactor, UInt256 const &contextHash)
Immutable cryptographic account descriptor.
Definition jtx/Account.h:21
A transaction testing environment.
Definition Env.h:161
Test helper for creating, mutating, and asserting MPT and confidential MPT ledger state.
Definition mpt.h:512
Use hash_* containers for keys that do not need a cryptographically secure hashing algorithm.
Definition algorithm.h:5
BaseUInt< 256 > UInt256
Definition base_uint.h:580
constexpr std::size_t kEcDoubleBulletproofLength
Length of double bulletproof (range proof for 2 commitments) in bytes.
Definition Protocol.h:515
constexpr std::size_t kEcSendProofLength
192 bytes compact sigma proof + 754 bytes double bulletproof.
Definition Protocol.h:525
XRPL_NO_SANITIZE_ADDRESS void Throw(Args &&... args)
Definition contract.h:52
static std::vector< test::jtx::Account > extractAccounts(std::vector< HolderInit > const &holders)
ConfidentialEnv(test::jtx::Env &env, test::jtx::Account const &issuer, std::vector< HolderInit > const &holders, std::uint32_t flags=tfMPTCanLock|tfMPTCanHoldConfidentialBalance|tfMPTCanTransfer, std::optional< test::jtx::Account > auditor=std::nullopt)
std::optional< Buffer > generateProof(test::jtx::MPTTester &mpt, test::jtx::Env &env, test::jtx::Account const &sender, test::jtx::Account const &dest) const
test::jtx::MPTConfidentialSend sendArgs(test::jtx::Account const &sender, test::jtx::Account const &dest, Buffer const &proof, std::optional< TER > err=std::nullopt) const
ConfidentialSendSetup(test::jtx::MPTTester &mpt, test::jtx::Account const &sender, test::jtx::Account const &dest, test::jtx::Account const &issuer, uint64_t amount, std::optional< std::reference_wrapper< test::jtx::Account const > > auditor=std::nullopt)
Arguments for building a ConfidentialMPTSend test transaction.
Definition mpt.h:322