From 5a619a936664de6d8e6c0f3fd9b8d085651f8603 Mon Sep 17 00:00:00 2001 From: Daniel Shiposha Date: Tue, 30 Aug 2022 08:57:52 +0000 Subject: [PATCH] fix(xcm): improve denythentry, deny transact xcm --- --- a/Cargo.lock +++ b/Cargo.lock @@ -4572,6 +4572,16 @@ ] [[package]] +name = "logtest" +version = "2.0.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "eb3e43a8657c1d64516dcc9db8ca03826a4aceaf89d5ce1b37b59f6ff0e43026" +dependencies = [ + "lazy_static", + "log", +] + +[[package]] name = "lru" version = "0.6.6" source = "registry+https://github.com/rust-lang/crates.io-index" @@ -5148,7 +5158,9 @@ "frame-system-rpc-runtime-api", "frame-try-runtime", "hex-literal", + "impl-trait-for-tuples", "log", + "logtest", "orml-tokens", "orml-traits", "orml-vesting", @@ -8466,7 +8478,9 @@ "frame-system-rpc-runtime-api", "frame-try-runtime", "hex-literal", + "impl-trait-for-tuples", "log", + "logtest", "orml-tokens", "orml-traits", "orml-vesting", @@ -12206,7 +12220,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "97fee6b57c6a41524a810daee9286c02d7752c4253064d0b05472833a438f675" dependencies = [ - "cfg-if 0.1.10", + "cfg-if 1.0.0", "digest 0.10.3", "rand 0.8.5", "static_assertions", @@ -12459,7 +12473,9 @@ "frame-system-rpc-runtime-api", "frame-try-runtime", "hex-literal", + "impl-trait-for-tuples", "log", + "logtest", "orml-tokens", "orml-traits", "orml-vesting", --- a/runtime/common/config/xcm.rs +++ b/runtime/common/config/xcm.rs @@ -172,13 +172,32 @@ }; } +pub trait TryPass { + fn try_pass( + origin: &MultiLocation, + message: &mut Xcm, + ) -> Result<(), ()>; +} + +#[impl_trait_for_tuples::impl_for_tuples(30)] +impl TryPass for Tuple { + fn try_pass( + origin: &MultiLocation, + message: &mut Xcm, + ) -> Result<(), ()> { + for_tuples!( #( + Tuple::try_pass(origin, message)?; + )* ); + + Ok(()) + } +} + pub struct DenyTransact; -impl ShouldExecute for DenyTransact { - fn should_execute( +impl TryPass for DenyTransact { + fn try_pass( _origin: &MultiLocation, message: &mut Xcm, - _max_weight: Weight, - _weight_credit: &mut Weight, ) -> Result<(), ()> { let transact_inst = message .0 @@ -203,12 +222,12 @@ /// If it passes the Deny, and matches one of the Allow cases then it is let through. pub struct DenyThenTry(PhantomData, PhantomData) where - Deny: ShouldExecute, + Deny: TryPass, Allow: ShouldExecute; impl ShouldExecute for DenyThenTry where - Deny: ShouldExecute, + Deny: TryPass, Allow: ShouldExecute, { fn should_execute( @@ -217,7 +236,7 @@ max_weight: Weight, weight_credit: &mut Weight, ) -> Result<(), ()> { - Deny::should_execute(origin, message, max_weight, weight_credit)?; + Deny::try_pass(origin, message)?; Allow::should_execute(origin, message, max_weight, weight_credit) } } --- a/runtime/common/tests/xcm.rs +++ b/runtime/common/tests/xcm.rs @@ -34,7 +34,7 @@ } #[test] -fn xcm_barrier_does_not_allow_transact() { +fn xcm_barrier_denies_transact() { // We have a `AllowTopLevelPaidExecutionFrom` barrier, // so an XCM program should start from one of the following commands: // * `WithdrawAsset` --- a/runtime/opal/Cargo.toml +++ b/runtime/opal/Cargo.toml @@ -463,6 +463,11 @@ pallet-foreing-assets = { default-features = false, path = "../../pallets/foreing-assets" } ################################################################################ +# Other Dependencies + +impl-trait-for-tuples = "0.2.2" + +################################################################################ # Dev Dependencies [dev-dependencies.logtest] --- a/runtime/quartz/Cargo.toml +++ b/runtime/quartz/Cargo.toml @@ -471,6 +471,11 @@ pallet-foreing-assets = { default-features = false, path = "../../pallets/foreing-assets" } ################################################################################ +# Other Dependencies + +impl-trait-for-tuples = "0.2.2" + +################################################################################ # Dev Dependencies [dev-dependencies.logtest] --- a/runtime/quartz/src/xcm_config.rs +++ b/runtime/quartz/src/xcm_config.rs @@ -41,7 +41,7 @@ }; use xcm_executor::{ {Config, XcmExecutor}, - traits::{Convert as ConvertXcm, FilterAssetLocation, JustTry, MatchesFungible, ShouldExecute}, + traits::{Convert as ConvertXcm, FilterAssetLocation, JustTry, MatchesFungible}, }; use up_common::{ @@ -93,12 +93,10 @@ // Allow xcm exchange only with locations in list pub struct DenyExchangeWithUnknownLocation; -impl ShouldExecute for DenyExchangeWithUnknownLocation { - fn should_execute( +impl TryPass for DenyExchangeWithUnknownLocation { + fn try_pass( origin: &MultiLocation, message: &mut Xcm, - _max_weight: Weight, - _weight_credit: &mut Weight, ) -> Result<(), ()> { // Check if deposit or transfer belongs to allowed parachains @@ -126,9 +124,11 @@ } pub type Barrier = DenyThenTry< - DenyExchangeWithUnknownLocation, ( DenyTransact, + DenyExchangeWithUnknownLocation, + ), + ( TakeWeightCredit, AllowTopLevelPaidExecutionFrom, // Parent and its exec plurality get free execution --- a/runtime/unique/Cargo.toml +++ b/runtime/unique/Cargo.toml @@ -463,6 +463,11 @@ pallet-foreing-assets = { default-features = false, path = "../../pallets/foreing-assets" } ################################################################################ +# Other Dependencies + +impl-trait-for-tuples = "0.2.2" + +################################################################################ # Dev Dependencies [dev-dependencies.logtest] --- a/runtime/unique/src/xcm_config.rs +++ b/runtime/unique/src/xcm_config.rs @@ -41,7 +41,7 @@ }; use xcm_executor::{ {Config, XcmExecutor}, - traits::{Convert as ConvertXcm, FilterAssetLocation, JustTry, MatchesFungible, ShouldExecute}, + traits::{Convert as ConvertXcm, FilterAssetLocation, JustTry, MatchesFungible}, }; use up_common::{ @@ -67,9 +67,11 @@ pub type Barrier = DenyThenTry< - DenyExchangeWithUnknownLocation, ( DenyTransact, + DenyExchangeWithUnknownLocation, + ), + ( TakeWeightCredit, AllowTopLevelPaidExecutionFrom, // Parent and its exec plurality get free execution @@ -98,12 +100,10 @@ // Allow xcm exchange only with locations in list pub struct DenyExchangeWithUnknownLocation; -impl ShouldExecute for DenyExchangeWithUnknownLocation { - fn should_execute( +impl TryPass for DenyExchangeWithUnknownLocation { + fn try_pass( origin: &MultiLocation, message: &mut Xcm, - _max_weight: Weight, - _weight_credit: &mut Weight, ) -> Result<(), ()> { // Check if deposit or transfer belongs to allowed parachains -- gitstuff