difftreelog
feat(xcm) move DenyThenTry to common, add DenyTransact
in: master
4 files changed
runtime/common/config/xcm.rsdiffbeforeafterboth--- a/runtime/common/config/xcm.rs
+++ b/runtime/common/config/xcm.rs
@@ -34,6 +34,7 @@
AssetId::{Concrete},
Fungibility::Fungible as XcmFungible,
MultiAsset, Error as XcmError,
+ Instruction, Xcm,
};
use xcm_builder::{
AccountId32Aliases, AllowTopLevelPaidExecutionFrom, CurrencyAdapter, EnsureXcmOrigin,
@@ -45,6 +46,7 @@
use xcm_executor::{Config, XcmExecutor, Assets};
use xcm_executor::traits::{
Convert as ConvertXcm, JustTry, MatchesFungible, WeightTrader, FilterAssetLocation,
+ ShouldExecute,
};
use pallet_foreing_assets::{
AssetIds, AssetIdMapping, XcmForeignAssetIdMapping, CurrencyId, NativeCurrency, FreeForAll,
@@ -171,13 +173,53 @@
};
}
-/*
-pub type Barrier = (
- TakeWeightCredit,
- AllowTopLevelPaidExecutionFrom<Everything>,
- // ^^^ Parent & its unit plurality gets free execution
-);
- */
+pub struct DenyTransact;
+impl ShouldExecute for DenyTransact {
+ fn should_execute<Call>(
+ _origin: &MultiLocation,
+ message: &mut Xcm<Call>,
+ _max_weight: Weight,
+ _weight_credit: &mut Weight,
+ ) -> Result<(), ()> {
+ let transact_inst = message.0.iter()
+ .find(|inst| matches![inst, Instruction::Transact { .. }]);
+
+ match transact_inst {
+ Some(_) => {
+ log::warn!(
+ target: "xcm::barrier",
+ "transact XCM rejected"
+ );
+
+ Err(())
+ },
+ None => Ok(())
+ }
+ }
+}
+
+/// Deny executing the XCM if it matches any of the Deny filter regardless of anything else.
+/// If it passes the Deny, and matches one of the Allow cases then it is let through.
+pub struct DenyThenTry<Deny, Allow>(PhantomData<Deny>, PhantomData<Allow>)
+ where
+ Deny: ShouldExecute,
+ Allow: ShouldExecute;
+
+impl<Deny, Allow> ShouldExecute for DenyThenTry<Deny, Allow>
+ where
+ Deny: ShouldExecute,
+ Allow: ShouldExecute,
+{
+ fn should_execute<Call>(
+ origin: &MultiLocation,
+ message: &mut Xcm<Call>,
+ max_weight: Weight,
+ weight_credit: &mut Weight,
+ ) -> Result<(), ()> {
+ Deny::should_execute(origin, message, max_weight, weight_credit)?;
+ Allow::should_execute(origin, message, max_weight, weight_credit)
+ }
+}
pub struct UsingOnlySelfCurrencyComponents<
WeightToFee: WeightToFeePolynomial<Balance = Currency::Balance>,
runtime/opal/src/xcm_config.rsdiffbeforeafterboth--- a/runtime/opal/src/xcm_config.rs
+++ b/runtime/opal/src/xcm_config.rs
@@ -301,13 +301,16 @@
}
}
-pub type Barrier = (
- TakeWeightCredit,
- AllowTopLevelPaidExecutionFrom<Everything>,
- AllowUnpaidExecutionFrom<ParentOrParentsUnitPlurality>,
- // ^^^ Parent & its unit plurality gets free execution
- AllowAllDebug,
-);
+pub type Barrier = DenyThenTry<
+ DenyTransact,
+ (
+ TakeWeightCredit,
+ AllowTopLevelPaidExecutionFrom<Everything>,
+ AllowUnpaidExecutionFrom<ParentOrParentsUnitPlurality>,
+ // ^^^ Parent & its unit plurality gets free execution
+ AllowAllDebug,
+ )
+>;
pub struct AllAsset;
impl FilterAssetLocation for AllAsset {
runtime/quartz/src/xcm_config.rsdiffbeforeafterboth--- a/runtime/quartz/src/xcm_config.rs
+++ b/runtime/quartz/src/xcm_config.rs
@@ -76,29 +76,6 @@
};
}
-/// Deny executing the XCM if it matches any of the Deny filter regardless of anything else.
-/// If it passes the Deny, and matches one of the Allow cases then it is let through.
-pub struct DenyThenTry<Deny, Allow>(PhantomData<Deny>, PhantomData<Allow>)
- where
- Deny: ShouldExecute,
- Allow: ShouldExecute;
-
-impl<Deny, Allow> ShouldExecute for DenyThenTry<Deny, Allow>
- where
- Deny: ShouldExecute,
- Allow: ShouldExecute,
-{
- fn should_execute<Call>(
- origin: &MultiLocation,
- message: &mut Xcm<Call>,
- max_weight: Weight,
- weight_credit: &mut Weight,
- ) -> Result<(), ()> {
- Deny::should_execute(origin, message, max_weight, weight_credit)?;
- Allow::should_execute(origin, message, max_weight, weight_credit)
- }
-}
-
pub fn get_allowed_locations() -> Vec<MultiLocation> {
vec![
// Self location
@@ -151,6 +128,7 @@
pub type Barrier = DenyThenTry<
DenyExchangeWithUnknownLocation,
(
+ DenyTransact,
TakeWeightCredit,
AllowTopLevelPaidExecutionFrom<Everything>,
// Parent and its exec plurality get free execution
runtime/unique/src/xcm_config.rsdiffbeforeafterboth1// Copyright 2019-2022 Unique Network (Gibraltar) Ltd.2// This file is part of Unique Network.34// Unique Network is free software: you can redistribute it and/or modify5// it under the terms of the GNU General Public License as published by6// the Free Software Foundation, either version 3 of the License, or7// (at your option) any later version.89// Unique Network is distributed in the hope that it will be useful,10// but WITHOUT ANY WARRANTY; without even the implied warranty of11// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the12// GNU General Public License for more details.1314// You should have received a copy of the GNU General Public License15// along with Unique Network. If not, see <http://www.gnu.org/licenses/>.1617use cumulus_pallet_xcm;18use frame_support::{19 {match_types, parameter_types, weights::Weight},20 pallet_prelude::Get,21 traits::{Contains, Everything, fungibles},22};23use frame_system::EnsureRoot;24use orml_traits::{location::AbsoluteReserveProvider, parameter_type_with_key};25use pallet_xcm::XcmPassthrough;26use polkadot_parachain::primitives::Sibling;27use sp_runtime::traits::{AccountIdConversion, CheckedConversion, Convert, Zero};28use sp_std::{borrow::Borrow, marker::PhantomData, vec, vec::Vec};29use xcm::{30 latest::{MultiAsset, Xcm},31 prelude::{Concrete, Fungible as XcmFungible},32 v1::{BodyId, Junction::*, Junctions::*, MultiLocation, NetworkId},33};34use xcm_builder::{35 AllowKnownQueryResponses, AllowSubscriptionsFrom,36 AccountId32Aliases, AllowTopLevelPaidExecutionFrom, AllowUnpaidExecutionFrom,37 EnsureXcmOrigin, FixedWeightBounds, FungiblesAdapter, LocationInverter, ParentAsSuperuser,38 ParentIsPreset, RelayChainAsNative, SiblingParachainAsNative, SiblingParachainConvertsVia,39 SignedAccountId32AsNative, SignedToAccountId32, SovereignSignedViaLocation, TakeWeightCredit,40 ConvertedConcreteAssetId,41};42use xcm_executor::{43 {Config, XcmExecutor},44 traits::{Convert as ConvertXcm, FilterAssetLocation, JustTry, MatchesFungible, ShouldExecute},45};4647use up_common::{48 constants::{MAXIMUM_BLOCK_WEIGHT, UNIQUE},49 types::{AccountId, Balance},50};51use pallet_foreing_assets::{52 AssetIds, AssetIdMapping, XcmForeignAssetIdMapping, CurrencyId, NativeCurrency,53 FreeForAll, TryAsForeing, ForeignAssetId,54};55use crate::{56 Balances, Call, DmpQueue, Event, Origin, ParachainInfo,57 ParachainSystem, PolkadotXcm, Runtime, XcmpQueue,58};59use crate::runtime_common::config::substrate::{TreasuryModuleId, MaxLocks, MaxReserves};60use crate::runtime_common::config::pallets::TreasuryAccountId;61use crate::runtime_common::config::xcm::*;62use crate::*;63use xcm::opaque::latest::prelude::{ DepositReserveAsset, DepositAsset, TransferAsset, TransferReserveAsset };6465// Signed version of balance66pub type Amount = i128;676869pub type Barrier = DenyThenTry<70 DenyExchangeWithUnknownLocation,71 (72 TakeWeightCredit,73 AllowTopLevelPaidExecutionFrom<Everything>,74 // Parent and its exec plurality get free execution75 AllowUnpaidExecutionFrom<ParentOrParentsExecutivePlurality>,76 // Expected responses are OK.77 AllowKnownQueryResponses<PolkadotXcm>,78 // Subscriptions for version tracking are OK.79 AllowSubscriptionsFrom<ParentOrSiblings>,80 ),81>;8283pub fn get_allowed_locations() -> Vec<MultiLocation> {84 vec![85 // Self location86 MultiLocation { parents: 0, interior: Here },87 // Parent location88 MultiLocation { parents: 1, interior: Here },89 // Karura/Acala location90 MultiLocation { parents: 1, interior: X1(Parachain(2000)) },91 // Moonbeam location92 MultiLocation { parents: 1, interior: X1(Parachain(2004)) },93 // Self parachain address94 MultiLocation { parents: 1, interior: X1(Parachain(ParachainInfo::get().into())) },95 ]96}9798pub struct DenyThenTry<Deny, Allow>(PhantomData<Deny>, PhantomData<Allow>)99 where100 Deny: ShouldExecute,101 Allow: ShouldExecute;102103impl<Deny, Allow> ShouldExecute for DenyThenTry<Deny, Allow>104 where105 Deny: ShouldExecute,106 Allow: ShouldExecute,107{108 fn should_execute<Call>(109 origin: &MultiLocation,110 message: &mut Xcm<Call>,111 max_weight: Weight,112 weight_credit: &mut Weight,113 ) -> Result<(), ()> {114 Deny::should_execute(origin, message, max_weight, weight_credit)?;115 Allow::should_execute(origin, message, max_weight, weight_credit)116 }117}118119// Allow xcm exchange only with locations in list120pub struct DenyExchangeWithUnknownLocation;121impl ShouldExecute for DenyExchangeWithUnknownLocation {122 fn should_execute<Call>(123 origin: &MultiLocation,124 message: &mut Xcm<Call>,125 _max_weight: Weight,126 _weight_credit: &mut Weight,127 ) -> Result<(), ()> {128129 // Check if deposit or transfer belongs to allowed parachains130 let mut allowed = get_allowed_locations().contains(origin);131132 message.0.iter().for_each(|inst| {133 match inst {134 DepositReserveAsset { dest: dst, .. } => { allowed |= get_allowed_locations().contains(dst); }135 TransferReserveAsset { dest: dst, .. } => { allowed |= get_allowed_locations().contains(dst); }136 _ => {}137 }138 });139140 if allowed {141 return Ok(());142 }143144 log::warn!(145 target: "xcm::barrier",146 "Unexpected deposit or transfer location"147 );148 // Deny149 Err(())150 }151}152153154match_types! {155 pub type ParentOrParentsExecutivePlurality: impl Contains<MultiLocation> = {156 MultiLocation { parents: 1, interior: Here } |157 MultiLocation { parents: 1, interior: X1(Plurality { id: BodyId::Executive, .. }) }158 };159 pub type ParentOrSiblings: impl Contains<MultiLocation> = {160 MultiLocation { parents: 1, interior: Here } |161 MultiLocation { parents: 1, interior: X1(_) }162 };163}164165pub fn get_all_module_accounts() -> Vec<AccountId> {166 vec![TreasuryModuleId::get().into_account_truncating()]167}168169pub struct DustRemovalWhitelist;170impl Contains<AccountId> for DustRemovalWhitelist {171 fn contains(a: &AccountId) -> bool {172 get_all_module_accounts().contains(a)173 }174}175176parameter_type_with_key! {177 pub ExistentialDeposits: |currency_id: CurrencyId| -> Balance {178 match currency_id {179 CurrencyId::NativeAssetId(symbol) => match symbol {180 NativeCurrency::Here => 0,181 NativeCurrency::Parent=> 0,182 },183 _ => 100_000184 }185 };186}187188impl orml_tokens::Config for Runtime {189 type Event = Event;190 type Balance = Balance;191 type Amount = Amount;192 type CurrencyId = CurrencyId;193 type WeightInfo = ();194 type ExistentialDeposits = ExistentialDeposits;195 type OnDust = orml_tokens::TransferDust<Runtime, TreasuryAccountId>;196 type MaxLocks = MaxLocks;197 type MaxReserves = MaxReserves;198 // TODO: Add all module accounts199 type DustRemovalWhitelist = DustRemovalWhitelist;200 /// The id type for named reserves.201 type ReserveIdentifier = ();202 type OnNewTokenAccount = ();203 type OnKilledTokenAccount = ();204}205206impl orml_xtokens::Config for Runtime {207 type Event = Event;208 type Balance = Balance;209 type CurrencyId = CurrencyId;210 type CurrencyIdConvert = CurrencyIdConvert;211 type AccountIdToMultiLocation = AccountIdToMultiLocation;212 type SelfLocation = SelfLocation;213 type XcmExecutor = XcmExecutor<XcmConfig<Self>>;214 type Weigher = FixedWeightBounds<UnitWeightCost, Call, MaxInstructions>;215 type BaseXcmWeight = BaseXcmWeight;216 type LocationInverter = LocationInverter<Ancestry>;217 type MaxAssetsForTransfer = MaxAssetsForTransfer;218 type MinXcmFee = ParachainMinFee;219 type MultiLocationsFilter = Everything;220 type ReserveProvider = AbsoluteReserveProvider;221}222223pub struct CurrencyIdConvert;224impl Convert<AssetIds, Option<MultiLocation>> for CurrencyIdConvert {225 fn convert(id: AssetIds) -> Option<MultiLocation> {226 match id {227 AssetIds::NativeAssetId(NativeCurrency::Here) => Some(MultiLocation::new(228 1,229 X1(Parachain(ParachainInfo::get().into())),230 )),231 _ => None,232 }233 }234}235236parameter_types! {237 pub const BaseXcmWeight: Weight = 100_000_000; // TODO: recheck this238 pub const MaxAssetsForTransfer: usize = 2;239240 pub Ancestry: MultiLocation = Parachain(ParachainInfo::parachain_id().into()).into();241 pub SelfLocation: MultiLocation = MultiLocation::new(1, X1(Parachain(ParachainInfo::get().into())));242}243244parameter_type_with_key! {245 pub ParachainMinFee: |_location: MultiLocation| -> Option<u128> {246 Some(100_000_000)247 };248}249250251pub struct AccountIdToMultiLocation;252impl Convert<AccountId, MultiLocation> for AccountIdToMultiLocation {253 fn convert(account: AccountId) -> MultiLocation {254 X1(AccountId32 {255 network: NetworkId::Any,256 id: account.into(),257 })258 .into()259 }260}1// Copyright 2019-2022 Unique Network (Gibraltar) Ltd.2// This file is part of Unique Network.34// Unique Network is free software: you can redistribute it and/or modify5// it under the terms of the GNU General Public License as published by6// the Free Software Foundation, either version 3 of the License, or7// (at your option) any later version.89// Unique Network is distributed in the hope that it will be useful,10// but WITHOUT ANY WARRANTY; without even the implied warranty of11// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the12// GNU General Public License for more details.1314// You should have received a copy of the GNU General Public License15// along with Unique Network. If not, see <http://www.gnu.org/licenses/>.1617use cumulus_pallet_xcm;18use frame_support::{19 {match_types, parameter_types, weights::Weight},20 pallet_prelude::Get,21 traits::{Contains, Everything, fungibles},22};23use frame_system::EnsureRoot;24use orml_traits::{location::AbsoluteReserveProvider, parameter_type_with_key};25use pallet_xcm::XcmPassthrough;26use polkadot_parachain::primitives::Sibling;27use sp_runtime::traits::{AccountIdConversion, CheckedConversion, Convert, Zero};28use sp_std::{borrow::Borrow, marker::PhantomData, vec, vec::Vec};29use xcm::{30 latest::{MultiAsset, Xcm},31 prelude::{Concrete, Fungible as XcmFungible},32 v1::{BodyId, Junction::*, Junctions::*, MultiLocation, NetworkId},33};34use xcm_builder::{35 AllowKnownQueryResponses, AllowSubscriptionsFrom,36 AccountId32Aliases, AllowTopLevelPaidExecutionFrom, AllowUnpaidExecutionFrom,37 EnsureXcmOrigin, FixedWeightBounds, FungiblesAdapter, LocationInverter, ParentAsSuperuser,38 ParentIsPreset, RelayChainAsNative, SiblingParachainAsNative, SiblingParachainConvertsVia,39 SignedAccountId32AsNative, SignedToAccountId32, SovereignSignedViaLocation, TakeWeightCredit,40 ConvertedConcreteAssetId,41};42use xcm_executor::{43 {Config, XcmExecutor},44 traits::{Convert as ConvertXcm, FilterAssetLocation, JustTry, MatchesFungible, ShouldExecute},45};4647use up_common::{48 constants::{MAXIMUM_BLOCK_WEIGHT, UNIQUE},49 types::{AccountId, Balance},50};51use pallet_foreing_assets::{52 AssetIds, AssetIdMapping, XcmForeignAssetIdMapping, CurrencyId, NativeCurrency,53 FreeForAll, TryAsForeing, ForeignAssetId,54};55use crate::{56 Balances, Call, DmpQueue, Event, Origin, ParachainInfo,57 ParachainSystem, PolkadotXcm, Runtime, XcmpQueue,58};59use crate::runtime_common::config::substrate::{TreasuryModuleId, MaxLocks, MaxReserves};60use crate::runtime_common::config::pallets::TreasuryAccountId;61use crate::runtime_common::config::xcm::*;62use crate::*;63use xcm::opaque::latest::prelude::{ DepositReserveAsset, DepositAsset, TransferAsset, TransferReserveAsset };6465// Signed version of balance66pub type Amount = i128;676869pub type Barrier = DenyThenTry<70 DenyExchangeWithUnknownLocation,71 (72 DenyTransact,73 TakeWeightCredit,74 AllowTopLevelPaidExecutionFrom<Everything>,75 // Parent and its exec plurality get free execution76 AllowUnpaidExecutionFrom<ParentOrParentsExecutivePlurality>,77 // Expected responses are OK.78 AllowKnownQueryResponses<PolkadotXcm>,79 // Subscriptions for version tracking are OK.80 AllowSubscriptionsFrom<ParentOrSiblings>,81 ),82>;8384pub fn get_allowed_locations() -> Vec<MultiLocation> {85 vec![86 // Self location87 MultiLocation { parents: 0, interior: Here },88 // Parent location89 MultiLocation { parents: 1, interior: Here },90 // Karura/Acala location91 MultiLocation { parents: 1, interior: X1(Parachain(2000)) },92 // Moonbeam location93 MultiLocation { parents: 1, interior: X1(Parachain(2004)) },94 // Self parachain address95 MultiLocation { parents: 1, interior: X1(Parachain(ParachainInfo::get().into())) },96 ]97}9899// Allow xcm exchange only with locations in list100pub struct DenyExchangeWithUnknownLocation;101impl ShouldExecute for DenyExchangeWithUnknownLocation {102 fn should_execute<Call>(103 origin: &MultiLocation,104 message: &mut Xcm<Call>,105 _max_weight: Weight,106 _weight_credit: &mut Weight,107 ) -> Result<(), ()> {108109 // Check if deposit or transfer belongs to allowed parachains110 let mut allowed = get_allowed_locations().contains(origin);111112 message.0.iter().for_each(|inst| {113 match inst {114 DepositReserveAsset { dest: dst, .. } => { allowed |= get_allowed_locations().contains(dst); }115 TransferReserveAsset { dest: dst, .. } => { allowed |= get_allowed_locations().contains(dst); }116 _ => {}117 }118 });119120 if allowed {121 return Ok(());122 }123124 log::warn!(125 target: "xcm::barrier",126 "Unexpected deposit or transfer location"127 );128 // Deny129 Err(())130 }131}132133134match_types! {135 pub type ParentOrParentsExecutivePlurality: impl Contains<MultiLocation> = {136 MultiLocation { parents: 1, interior: Here } |137 MultiLocation { parents: 1, interior: X1(Plurality { id: BodyId::Executive, .. }) }138 };139 pub type ParentOrSiblings: impl Contains<MultiLocation> = {140 MultiLocation { parents: 1, interior: Here } |141 MultiLocation { parents: 1, interior: X1(_) }142 };143}144145pub fn get_all_module_accounts() -> Vec<AccountId> {146 vec![TreasuryModuleId::get().into_account_truncating()]147}148149pub struct DustRemovalWhitelist;150impl Contains<AccountId> for DustRemovalWhitelist {151 fn contains(a: &AccountId) -> bool {152 get_all_module_accounts().contains(a)153 }154}155156parameter_type_with_key! {157 pub ExistentialDeposits: |currency_id: CurrencyId| -> Balance {158 match currency_id {159 CurrencyId::NativeAssetId(symbol) => match symbol {160 NativeCurrency::Here => 0,161 NativeCurrency::Parent=> 0,162 },163 _ => 100_000164 }165 };166}167168impl orml_tokens::Config for Runtime {169 type Event = Event;170 type Balance = Balance;171 type Amount = Amount;172 type CurrencyId = CurrencyId;173 type WeightInfo = ();174 type ExistentialDeposits = ExistentialDeposits;175 type OnDust = orml_tokens::TransferDust<Runtime, TreasuryAccountId>;176 type MaxLocks = MaxLocks;177 type MaxReserves = MaxReserves;178 // TODO: Add all module accounts179 type DustRemovalWhitelist = DustRemovalWhitelist;180 /// The id type for named reserves.181 type ReserveIdentifier = ();182 type OnNewTokenAccount = ();183 type OnKilledTokenAccount = ();184}185186impl orml_xtokens::Config for Runtime {187 type Event = Event;188 type Balance = Balance;189 type CurrencyId = CurrencyId;190 type CurrencyIdConvert = CurrencyIdConvert;191 type AccountIdToMultiLocation = AccountIdToMultiLocation;192 type SelfLocation = SelfLocation;193 type XcmExecutor = XcmExecutor<XcmConfig<Self>>;194 type Weigher = FixedWeightBounds<UnitWeightCost, Call, MaxInstructions>;195 type BaseXcmWeight = BaseXcmWeight;196 type LocationInverter = LocationInverter<Ancestry>;197 type MaxAssetsForTransfer = MaxAssetsForTransfer;198 type MinXcmFee = ParachainMinFee;199 type MultiLocationsFilter = Everything;200 type ReserveProvider = AbsoluteReserveProvider;201}202203pub struct CurrencyIdConvert;204impl Convert<AssetIds, Option<MultiLocation>> for CurrencyIdConvert {205 fn convert(id: AssetIds) -> Option<MultiLocation> {206 match id {207 AssetIds::NativeAssetId(NativeCurrency::Here) => Some(MultiLocation::new(208 1,209 X1(Parachain(ParachainInfo::get().into())),210 )),211 _ => None,212 }213 }214}215216parameter_types! {217 pub const BaseXcmWeight: Weight = 100_000_000; // TODO: recheck this218 pub const MaxAssetsForTransfer: usize = 2;219220 pub Ancestry: MultiLocation = Parachain(ParachainInfo::parachain_id().into()).into();221 pub SelfLocation: MultiLocation = MultiLocation::new(1, X1(Parachain(ParachainInfo::get().into())));222}223224parameter_type_with_key! {225 pub ParachainMinFee: |_location: MultiLocation| -> Option<u128> {226 Some(100_000_000)227 };228}229230231pub struct AccountIdToMultiLocation;232impl Convert<AccountId, MultiLocation> for AccountIdToMultiLocation {233 fn convert(account: AccountId) -> MultiLocation {234 X1(AccountId32 {235 network: NetworkId::Any,236 id: account.into(),237 })238 .into()239 }240}