git.delta.rocks / unique-network / refs/commits / bebe624eff63

difftreelog

feat prevent ouroboros creation during nest

Yaroslav Bolyukin2022-04-19parent: #07a6969.patch.diff
in: master

11 files changed

modifiedclient/rpc/src/lib.rsdiffbeforeafterboth
--- a/client/rpc/src/lib.rs
+++ b/client/rpc/src/lib.rs
@@ -77,11 +77,7 @@
 	) -> Result<Vec<u8>>;
 
 	#[rpc(name = "unique_totalSupply")]
-	fn total_supply(
-		&self,
-		collection: CollectionId,
-		at: Option<BlockHash>,
-	) -> Result<u32>;
+	fn total_supply(&self, collection: CollectionId, at: Option<BlockHash>) -> Result<u32>;
 	#[rpc(name = "unique_accountBalance")]
 	fn account_balance(
 		&self,
modifiedpallets/common/src/lib.rsdiffbeforeafterboth
--- a/pallets/common/src/lib.rs
+++ b/pallets/common/src/lib.rs
@@ -918,7 +918,7 @@
 	fn check_nesting(
 		&self,
 		sender: T::CrossAccountId,
-		from: CollectionId,
+		from: (CollectionId, TokenId),
 		under: TokenId,
 		budget: &dyn Budget,
 	) -> DispatchResult;
modifiedpallets/fungible/src/common.rsdiffbeforeafterboth
--- a/pallets/fungible/src/common.rs
+++ b/pallets/fungible/src/common.rs
@@ -237,7 +237,7 @@
 	fn check_nesting(
 		&self,
 		_sender: <T>::CrossAccountId,
-		_from: CollectionId,
+		_from: (CollectionId, TokenId),
 		_under: TokenId,
 		_budget: &dyn Budget,
 	) -> sp_runtime::DispatchResult {
modifiedpallets/fungible/src/lib.rsdiffbeforeafterboth
before · pallets/fungible/src/lib.rs
1// Copyright 2019-2022 Unique Network (Gibraltar) Ltd.2// This file is part of Unique Network.34// Unique Network is free software: you can redistribute it and/or modify5// it under the terms of the GNU General Public License as published by6// the Free Software Foundation, either version 3 of the License, or7// (at your option) any later version.89// Unique Network is distributed in the hope that it will be useful,10// but WITHOUT ANY WARRANTY; without even the implied warranty of11// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the12// GNU General Public License for more details.1314// You should have received a copy of the GNU General Public License15// along with Unique Network. If not, see <http://www.gnu.org/licenses/>.1617#![cfg_attr(not(feature = "std"), no_std)]1819use core::ops::Deref;20use frame_support::{ensure};21use pallet_evm::account::CrossAccountId;22use up_data_structs::{23	AccessMode, CollectionId, TokenId, CreateCollectionData, mapping::TokenAddressMapping,24	budget::Budget,25};26use pallet_common::{27	Error as CommonError, Event as CommonEvent, Pallet as PalletCommon, CollectionHandle,28	dispatch::CollectionDispatch,29};30use pallet_structure::Pallet as PalletStructure;31use pallet_evm_coder_substrate::WithRecorder;32use sp_core::H160;33use sp_runtime::{ArithmeticError, DispatchError, DispatchResult};34use sp_std::collections::btree_map::BTreeMap;3536pub use pallet::*;3738use crate::erc::ERC20Events;39#[cfg(feature = "runtime-benchmarks")]40pub mod benchmarking;41pub mod common;42pub mod erc;43pub mod weights;4445pub type CreateItemData<T> = (<T as pallet_evm::account::Config>::CrossAccountId, u128);46pub(crate) type SelfWeightOf<T> = <T as Config>::WeightInfo;4748#[frame_support::pallet]49pub mod pallet {50	use frame_support::{Blake2_128, Blake2_128Concat, Twox64Concat, pallet_prelude::*, storage::Key};51	use up_data_structs::CollectionId;52	use super::weights::WeightInfo;5354	#[pallet::error]55	pub enum Error<T> {56		/// Not Fungible item data used to mint in Fungible collection.57		NotFungibleDataUsedToMintFungibleCollectionToken,58		/// Not default id passed as TokenId argument59		FungibleItemsHaveNoId,60		/// Tried to set data for fungible item61		FungibleItemsDontHaveData,62		/// Fungible token does not support nested63		FungibleDisallowsNesting,64	}6566	#[pallet::config]67	pub trait Config:68		frame_system::Config + pallet_common::Config + pallet_structure::Config69	{70		type WeightInfo: WeightInfo;71	}7273	#[pallet::pallet]74	#[pallet::generate_store(pub(super) trait Store)]75	pub struct Pallet<T>(_);7677	#[pallet::storage]78	pub type TotalSupply<T: Config> =79		StorageMap<Hasher = Twox64Concat, Key = CollectionId, Value = u128, QueryKind = ValueQuery>;8081	#[pallet::storage]82	pub type Balance<T: Config> = StorageNMap<83		Key = (84			Key<Twox64Concat, CollectionId>,85			Key<Blake2_128Concat, T::CrossAccountId>,86		),87		Value = u128,88		QueryKind = ValueQuery,89	>;9091	#[pallet::storage]92	pub type Allowance<T: Config> = StorageNMap<93		Key = (94			Key<Twox64Concat, CollectionId>,95			Key<Blake2_128, T::CrossAccountId>,96			Key<Blake2_128Concat, T::CrossAccountId>,97		),98		Value = u128,99		QueryKind = ValueQuery,100	>;101}102103pub struct FungibleHandle<T: Config>(pallet_common::CollectionHandle<T>);104impl<T: Config> FungibleHandle<T> {105	pub fn cast(inner: pallet_common::CollectionHandle<T>) -> Self {106		Self(inner)107	}108	pub fn into_inner(self) -> pallet_common::CollectionHandle<T> {109		self.0110	}111}112impl<T: Config> WithRecorder<T> for FungibleHandle<T> {113	fn recorder(&self) -> &pallet_evm_coder_substrate::SubstrateRecorder<T> {114		self.0.recorder()115	}116	fn into_recorder(self) -> pallet_evm_coder_substrate::SubstrateRecorder<T> {117		self.0.into_recorder()118	}119}120impl<T: Config> Deref for FungibleHandle<T> {121	type Target = pallet_common::CollectionHandle<T>;122123	fn deref(&self) -> &Self::Target {124		&self.0125	}126}127128impl<T: Config> Pallet<T> {129	pub fn init_collection(130		owner: T::AccountId,131		data: CreateCollectionData<T::AccountId>,132	) -> Result<CollectionId, DispatchError> {133		<PalletCommon<T>>::init_collection(owner, data)134	}135	pub fn destroy_collection(136		collection: FungibleHandle<T>,137		sender: &T::CrossAccountId,138	) -> DispatchResult {139		let id = collection.id;140141		// =========142143		PalletCommon::destroy_collection(collection.0, sender)?;144145		<TotalSupply<T>>::remove(id);146		<Balance<T>>::remove_prefix((id,), None);147		<Allowance<T>>::remove_prefix((id,), None);148		Ok(())149	}150151	pub fn burn(152		collection: &FungibleHandle<T>,153		owner: &T::CrossAccountId,154		amount: u128,155	) -> DispatchResult {156		let total_supply = <TotalSupply<T>>::get(collection.id)157			.checked_sub(amount)158			.ok_or(<CommonError<T>>::TokenValueTooLow)?;159160		let balance = <Balance<T>>::get((collection.id, owner))161			.checked_sub(amount)162			.ok_or(<CommonError<T>>::TokenValueTooLow)?;163164		if collection.access == AccessMode::AllowList {165			collection.check_allowlist(owner)?;166		}167168		// =========169170		if balance == 0 {171			<Balance<T>>::remove((collection.id, owner));172		} else {173			<Balance<T>>::insert((collection.id, owner), balance);174		}175		<TotalSupply<T>>::insert(collection.id, total_supply);176177		collection.log_mirrored(ERC20Events::Transfer {178			from: *owner.as_eth(),179			to: H160::default(),180			value: amount.into(),181		});182		<PalletCommon<T>>::deposit_event(CommonEvent::ItemDestroyed(183			collection.id,184			TokenId::default(),185			owner.clone(),186			amount,187		));188		Ok(())189	}190191	pub fn transfer(192		collection: &FungibleHandle<T>,193		from: &T::CrossAccountId,194		to: &T::CrossAccountId,195		amount: u128,196		nesting_budget: &dyn Budget,197	) -> DispatchResult {198		ensure!(199			collection.limits.transfers_enabled(),200			<CommonError<T>>::TransferNotAllowed,201		);202203		if collection.access == AccessMode::AllowList {204			collection.check_allowlist(from)?;205			collection.check_allowlist(to)?;206		}207		<PalletCommon<T>>::ensure_correct_receiver(to)?;208209		let balance_from = <Balance<T>>::get((collection.id, from))210			.checked_sub(amount)211			.ok_or(<CommonError<T>>::TokenValueTooLow)?;212		let balance_to = if from != to {213			Some(214				<Balance<T>>::get((collection.id, to))215					.checked_add(amount)216					.ok_or(ArithmeticError::Overflow)?,217			)218		} else {219			None220		};221222		if let Some(target) = T::CrossTokenAddressMapping::address_to_token(to) {223			let handle = <CollectionHandle<T>>::try_get(target.0)?;224			let dispatch = T::CollectionDispatch::dispatch(handle);225			let dispatch = dispatch.as_dyn();226227			dispatch.check_nesting(from.clone(), collection.id, target.1, nesting_budget)?;228		}229230		// =========231232		if let Some(balance_to) = balance_to {233			// from != to234			if balance_from == 0 {235				<Balance<T>>::remove((collection.id, from));236			} else {237				<Balance<T>>::insert((collection.id, from), balance_from);238			}239			<Balance<T>>::insert((collection.id, to), balance_to);240		}241242		collection.log_mirrored(ERC20Events::Transfer {243			from: *from.as_eth(),244			to: *to.as_eth(),245			value: amount.into(),246		});247		<PalletCommon<T>>::deposit_event(CommonEvent::Transfer(248			collection.id,249			TokenId::default(),250			from.clone(),251			to.clone(),252			amount,253		));254		Ok(())255	}256257	pub fn create_multiple_items(258		collection: &FungibleHandle<T>,259		sender: &T::CrossAccountId,260		data: BTreeMap<T::CrossAccountId, u128>,261		nesting_budget: &dyn Budget,262	) -> DispatchResult {263		if !collection.is_owner_or_admin(sender) {264			ensure!(265				collection.mint_mode,266				<CommonError<T>>::PublicMintingNotAllowed267			);268			collection.check_allowlist(sender)?;269270			for (owner, _) in data.iter() {271				collection.check_allowlist(owner)?;272			}273		}274275		let total_supply = data276			.iter()277			.map(|(_, v)| *v)278			.try_fold(<TotalSupply<T>>::get(collection.id), |acc, v| {279				acc.checked_add(v)280			})281			.ok_or(ArithmeticError::Overflow)?;282283		let mut balances = data;284		for (k, v) in balances.iter_mut() {285			*v = <Balance<T>>::get((collection.id, &k))286				.checked_add(*v)287				.ok_or(ArithmeticError::Overflow)?;288		}289290		for (to, _) in balances.iter() {291			if let Some(target) = T::CrossTokenAddressMapping::address_to_token(to) {292				let handle = <CollectionHandle<T>>::try_get(target.0)?;293				let dispatch = T::CollectionDispatch::dispatch(handle);294				let dispatch = dispatch.as_dyn();295296				dispatch.check_nesting(sender.clone(), collection.id, target.1, nesting_budget)?;297			}298		}299300		// =========301302		<TotalSupply<T>>::insert(collection.id, total_supply);303		for (user, amount) in balances {304			<Balance<T>>::insert((collection.id, &user), amount);305306			collection.log_mirrored(ERC20Events::Transfer {307				from: H160::default(),308				to: *user.as_eth(),309				value: amount.into(),310			});311			<PalletCommon<T>>::deposit_event(CommonEvent::ItemCreated(312				collection.id,313				TokenId::default(),314				user.clone(),315				amount,316			));317		}318319		Ok(())320	}321322	fn set_allowance_unchecked(323		collection: &FungibleHandle<T>,324		owner: &T::CrossAccountId,325		spender: &T::CrossAccountId,326		amount: u128,327	) {328		if amount == 0 {329			<Allowance<T>>::remove((collection.id, owner, spender));330		} else {331			<Allowance<T>>::insert((collection.id, owner, spender), amount);332		}333334		collection.log_mirrored(ERC20Events::Approval {335			owner: *owner.as_eth(),336			spender: *spender.as_eth(),337			value: amount.into(),338		});339		<PalletCommon<T>>::deposit_event(CommonEvent::Approved(340			collection.id,341			TokenId(0),342			owner.clone(),343			spender.clone(),344			amount,345		));346	}347348	pub fn set_allowance(349		collection: &FungibleHandle<T>,350		owner: &T::CrossAccountId,351		spender: &T::CrossAccountId,352		amount: u128,353	) -> DispatchResult {354		if collection.access == AccessMode::AllowList {355			collection.check_allowlist(owner)?;356			collection.check_allowlist(spender)?;357		}358359		if <Balance<T>>::get((collection.id, owner)) < amount {360			ensure!(361				collection.ignores_owned_amount(owner),362				<CommonError<T>>::CantApproveMoreThanOwned363			);364		}365366		// =========367368		Self::set_allowance_unchecked(collection, owner, spender, amount);369		Ok(())370	}371372	fn check_allowed(373		collection: &FungibleHandle<T>,374		spender: &T::CrossAccountId,375		from: &T::CrossAccountId,376		amount: u128,377		nesting_budget: &dyn Budget,378	) -> Result<Option<u128>, DispatchError> {379		if spender.conv_eq(from) {380			return Ok(None);381		}382		if collection.access == AccessMode::AllowList {383			// `from`, `to` checked in [`transfer`]384			collection.check_allowlist(spender)?;385		}386		if let Some(source) = T::CrossTokenAddressMapping::address_to_token(from) {387			// TODO: should collection owner be allowed to perform this transfer?388			ensure!(389				<PalletStructure<T>>::indirectly_owned(390					spender.clone(),391					source.0,392					source.1,393					nesting_budget394				)?,395				<CommonError<T>>::ApprovedValueTooLow,396			);397			return Ok(None);398		}399		let allowance = <Allowance<T>>::get((collection.id, from, spender)).checked_sub(amount);400		if allowance.is_none() {401			ensure!(402				collection.ignores_allowance(spender),403				<CommonError<T>>::ApprovedValueTooLow404			);405		}406407		Ok(allowance)408	}409410	pub fn transfer_from(411		collection: &FungibleHandle<T>,412		spender: &T::CrossAccountId,413		from: &T::CrossAccountId,414		to: &T::CrossAccountId,415		amount: u128,416		nesting_budget: &dyn Budget,417	) -> DispatchResult {418		let allowance = Self::check_allowed(collection, spender, from, amount, nesting_budget)?;419420		// =========421422		Self::transfer(collection, from, to, amount, nesting_budget)?;423		if let Some(allowance) = allowance {424			Self::set_allowance_unchecked(collection, from, spender, allowance);425		}426		Ok(())427	}428429	pub fn burn_from(430		collection: &FungibleHandle<T>,431		spender: &T::CrossAccountId,432		from: &T::CrossAccountId,433		amount: u128,434		nesting_budget: &dyn Budget,435	) -> DispatchResult {436		let allowance = Self::check_allowed(collection, spender, from, amount, nesting_budget)?;437438		// =========439440		Self::burn(collection, from, amount)?;441		if let Some(allowance) = allowance {442			Self::set_allowance_unchecked(collection, from, spender, allowance);443		}444		Ok(())445	}446447	/// Delegated to `create_multiple_items`448	pub fn create_item(449		collection: &FungibleHandle<T>,450		sender: &T::CrossAccountId,451		data: CreateItemData<T>,452		nesting_budget: &dyn Budget,453	) -> DispatchResult {454		Self::create_multiple_items(455			collection,456			sender,457			[(data.0, data.1)].into_iter().collect(),458			nesting_budget,459		)460	}461}
after · pallets/fungible/src/lib.rs
1// Copyright 2019-2022 Unique Network (Gibraltar) Ltd.2// This file is part of Unique Network.34// Unique Network is free software: you can redistribute it and/or modify5// it under the terms of the GNU General Public License as published by6// the Free Software Foundation, either version 3 of the License, or7// (at your option) any later version.89// Unique Network is distributed in the hope that it will be useful,10// but WITHOUT ANY WARRANTY; without even the implied warranty of11// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the12// GNU General Public License for more details.1314// You should have received a copy of the GNU General Public License15// along with Unique Network. If not, see <http://www.gnu.org/licenses/>.1617#![cfg_attr(not(feature = "std"), no_std)]1819use core::ops::Deref;20use frame_support::{ensure};21use pallet_evm::account::CrossAccountId;22use up_data_structs::{23	AccessMode, CollectionId, TokenId, CreateCollectionData, mapping::TokenAddressMapping,24	budget::Budget,25};26use pallet_common::{27	Error as CommonError, Event as CommonEvent, Pallet as PalletCommon, CollectionHandle,28	dispatch::CollectionDispatch,29};30use pallet_structure::Pallet as PalletStructure;31use pallet_evm_coder_substrate::WithRecorder;32use sp_core::H160;33use sp_runtime::{ArithmeticError, DispatchError, DispatchResult};34use sp_std::collections::btree_map::BTreeMap;3536pub use pallet::*;3738use crate::erc::ERC20Events;39#[cfg(feature = "runtime-benchmarks")]40pub mod benchmarking;41pub mod common;42pub mod erc;43pub mod weights;4445pub type CreateItemData<T> = (<T as pallet_evm::account::Config>::CrossAccountId, u128);46pub(crate) type SelfWeightOf<T> = <T as Config>::WeightInfo;4748#[frame_support::pallet]49pub mod pallet {50	use frame_support::{Blake2_128, Blake2_128Concat, Twox64Concat, pallet_prelude::*, storage::Key};51	use up_data_structs::CollectionId;52	use super::weights::WeightInfo;5354	#[pallet::error]55	pub enum Error<T> {56		/// Not Fungible item data used to mint in Fungible collection.57		NotFungibleDataUsedToMintFungibleCollectionToken,58		/// Not default id passed as TokenId argument59		FungibleItemsHaveNoId,60		/// Tried to set data for fungible item61		FungibleItemsDontHaveData,62		/// Fungible token does not support nested63		FungibleDisallowsNesting,64	}6566	#[pallet::config]67	pub trait Config:68		frame_system::Config + pallet_common::Config + pallet_structure::Config69	{70		type WeightInfo: WeightInfo;71	}7273	#[pallet::pallet]74	#[pallet::generate_store(pub(super) trait Store)]75	pub struct Pallet<T>(_);7677	#[pallet::storage]78	pub type TotalSupply<T: Config> =79		StorageMap<Hasher = Twox64Concat, Key = CollectionId, Value = u128, QueryKind = ValueQuery>;8081	#[pallet::storage]82	pub type Balance<T: Config> = StorageNMap<83		Key = (84			Key<Twox64Concat, CollectionId>,85			Key<Blake2_128Concat, T::CrossAccountId>,86		),87		Value = u128,88		QueryKind = ValueQuery,89	>;9091	#[pallet::storage]92	pub type Allowance<T: Config> = StorageNMap<93		Key = (94			Key<Twox64Concat, CollectionId>,95			Key<Blake2_128, T::CrossAccountId>,96			Key<Blake2_128Concat, T::CrossAccountId>,97		),98		Value = u128,99		QueryKind = ValueQuery,100	>;101}102103pub struct FungibleHandle<T: Config>(pallet_common::CollectionHandle<T>);104impl<T: Config> FungibleHandle<T> {105	pub fn cast(inner: pallet_common::CollectionHandle<T>) -> Self {106		Self(inner)107	}108	pub fn into_inner(self) -> pallet_common::CollectionHandle<T> {109		self.0110	}111}112impl<T: Config> WithRecorder<T> for FungibleHandle<T> {113	fn recorder(&self) -> &pallet_evm_coder_substrate::SubstrateRecorder<T> {114		self.0.recorder()115	}116	fn into_recorder(self) -> pallet_evm_coder_substrate::SubstrateRecorder<T> {117		self.0.into_recorder()118	}119}120impl<T: Config> Deref for FungibleHandle<T> {121	type Target = pallet_common::CollectionHandle<T>;122123	fn deref(&self) -> &Self::Target {124		&self.0125	}126}127128impl<T: Config> Pallet<T> {129	pub fn init_collection(130		owner: T::AccountId,131		data: CreateCollectionData<T::AccountId>,132	) -> Result<CollectionId, DispatchError> {133		<PalletCommon<T>>::init_collection(owner, data)134	}135	pub fn destroy_collection(136		collection: FungibleHandle<T>,137		sender: &T::CrossAccountId,138	) -> DispatchResult {139		let id = collection.id;140141		// =========142143		PalletCommon::destroy_collection(collection.0, sender)?;144145		<TotalSupply<T>>::remove(id);146		<Balance<T>>::remove_prefix((id,), None);147		<Allowance<T>>::remove_prefix((id,), None);148		Ok(())149	}150151	pub fn burn(152		collection: &FungibleHandle<T>,153		owner: &T::CrossAccountId,154		amount: u128,155	) -> DispatchResult {156		let total_supply = <TotalSupply<T>>::get(collection.id)157			.checked_sub(amount)158			.ok_or(<CommonError<T>>::TokenValueTooLow)?;159160		let balance = <Balance<T>>::get((collection.id, owner))161			.checked_sub(amount)162			.ok_or(<CommonError<T>>::TokenValueTooLow)?;163164		if collection.access == AccessMode::AllowList {165			collection.check_allowlist(owner)?;166		}167168		// =========169170		if balance == 0 {171			<Balance<T>>::remove((collection.id, owner));172		} else {173			<Balance<T>>::insert((collection.id, owner), balance);174		}175		<TotalSupply<T>>::insert(collection.id, total_supply);176177		collection.log_mirrored(ERC20Events::Transfer {178			from: *owner.as_eth(),179			to: H160::default(),180			value: amount.into(),181		});182		<PalletCommon<T>>::deposit_event(CommonEvent::ItemDestroyed(183			collection.id,184			TokenId::default(),185			owner.clone(),186			amount,187		));188		Ok(())189	}190191	pub fn transfer(192		collection: &FungibleHandle<T>,193		from: &T::CrossAccountId,194		to: &T::CrossAccountId,195		amount: u128,196		nesting_budget: &dyn Budget,197	) -> DispatchResult {198		ensure!(199			collection.limits.transfers_enabled(),200			<CommonError<T>>::TransferNotAllowed,201		);202203		if collection.access == AccessMode::AllowList {204			collection.check_allowlist(from)?;205			collection.check_allowlist(to)?;206		}207		<PalletCommon<T>>::ensure_correct_receiver(to)?;208209		let balance_from = <Balance<T>>::get((collection.id, from))210			.checked_sub(amount)211			.ok_or(<CommonError<T>>::TokenValueTooLow)?;212		let balance_to = if from != to {213			Some(214				<Balance<T>>::get((collection.id, to))215					.checked_add(amount)216					.ok_or(ArithmeticError::Overflow)?,217			)218		} else {219			None220		};221222		if let Some(target) = T::CrossTokenAddressMapping::address_to_token(to) {223			let handle = <CollectionHandle<T>>::try_get(target.0)?;224			let dispatch = T::CollectionDispatch::dispatch(handle);225			let dispatch = dispatch.as_dyn();226227			dispatch.check_nesting(228				from.clone(),229				(collection.id, TokenId::default()),230				target.1,231				nesting_budget,232			)?;233		}234235		// =========236237		if let Some(balance_to) = balance_to {238			// from != to239			if balance_from == 0 {240				<Balance<T>>::remove((collection.id, from));241			} else {242				<Balance<T>>::insert((collection.id, from), balance_from);243			}244			<Balance<T>>::insert((collection.id, to), balance_to);245		}246247		collection.log_mirrored(ERC20Events::Transfer {248			from: *from.as_eth(),249			to: *to.as_eth(),250			value: amount.into(),251		});252		<PalletCommon<T>>::deposit_event(CommonEvent::Transfer(253			collection.id,254			TokenId::default(),255			from.clone(),256			to.clone(),257			amount,258		));259		Ok(())260	}261262	pub fn create_multiple_items(263		collection: &FungibleHandle<T>,264		sender: &T::CrossAccountId,265		data: BTreeMap<T::CrossAccountId, u128>,266		nesting_budget: &dyn Budget,267	) -> DispatchResult {268		if !collection.is_owner_or_admin(sender) {269			ensure!(270				collection.mint_mode,271				<CommonError<T>>::PublicMintingNotAllowed272			);273			collection.check_allowlist(sender)?;274275			for (owner, _) in data.iter() {276				collection.check_allowlist(owner)?;277			}278		}279280		let total_supply = data281			.iter()282			.map(|(_, v)| *v)283			.try_fold(<TotalSupply<T>>::get(collection.id), |acc, v| {284				acc.checked_add(v)285			})286			.ok_or(ArithmeticError::Overflow)?;287288		let mut balances = data;289		for (k, v) in balances.iter_mut() {290			*v = <Balance<T>>::get((collection.id, &k))291				.checked_add(*v)292				.ok_or(ArithmeticError::Overflow)?;293		}294295		for (to, _) in balances.iter() {296			if let Some(target) = T::CrossTokenAddressMapping::address_to_token(to) {297				let handle = <CollectionHandle<T>>::try_get(target.0)?;298				let dispatch = T::CollectionDispatch::dispatch(handle);299				let dispatch = dispatch.as_dyn();300301				dispatch.check_nesting(302					sender.clone(),303					(collection.id, TokenId::default()),304					target.1,305					nesting_budget,306				)?;307			}308		}309310		// =========311312		<TotalSupply<T>>::insert(collection.id, total_supply);313		for (user, amount) in balances {314			<Balance<T>>::insert((collection.id, &user), amount);315316			collection.log_mirrored(ERC20Events::Transfer {317				from: H160::default(),318				to: *user.as_eth(),319				value: amount.into(),320			});321			<PalletCommon<T>>::deposit_event(CommonEvent::ItemCreated(322				collection.id,323				TokenId::default(),324				user.clone(),325				amount,326			));327		}328329		Ok(())330	}331332	fn set_allowance_unchecked(333		collection: &FungibleHandle<T>,334		owner: &T::CrossAccountId,335		spender: &T::CrossAccountId,336		amount: u128,337	) {338		if amount == 0 {339			<Allowance<T>>::remove((collection.id, owner, spender));340		} else {341			<Allowance<T>>::insert((collection.id, owner, spender), amount);342		}343344		collection.log_mirrored(ERC20Events::Approval {345			owner: *owner.as_eth(),346			spender: *spender.as_eth(),347			value: amount.into(),348		});349		<PalletCommon<T>>::deposit_event(CommonEvent::Approved(350			collection.id,351			TokenId(0),352			owner.clone(),353			spender.clone(),354			amount,355		));356	}357358	pub fn set_allowance(359		collection: &FungibleHandle<T>,360		owner: &T::CrossAccountId,361		spender: &T::CrossAccountId,362		amount: u128,363	) -> DispatchResult {364		if collection.access == AccessMode::AllowList {365			collection.check_allowlist(owner)?;366			collection.check_allowlist(spender)?;367		}368369		if <Balance<T>>::get((collection.id, owner)) < amount {370			ensure!(371				collection.ignores_owned_amount(owner),372				<CommonError<T>>::CantApproveMoreThanOwned373			);374		}375376		// =========377378		Self::set_allowance_unchecked(collection, owner, spender, amount);379		Ok(())380	}381382	fn check_allowed(383		collection: &FungibleHandle<T>,384		spender: &T::CrossAccountId,385		from: &T::CrossAccountId,386		amount: u128,387		nesting_budget: &dyn Budget,388	) -> Result<Option<u128>, DispatchError> {389		if spender.conv_eq(from) {390			return Ok(None);391		}392		if collection.access == AccessMode::AllowList {393			// `from`, `to` checked in [`transfer`]394			collection.check_allowlist(spender)?;395		}396		if let Some(source) = T::CrossTokenAddressMapping::address_to_token(from) {397			// TODO: should collection owner be allowed to perform this transfer?398			ensure!(399				<PalletStructure<T>>::check_indirectly_owned(400					spender.clone(),401					source.0,402					source.1,403					None,404					nesting_budget405				)?,406				<CommonError<T>>::ApprovedValueTooLow,407			);408			return Ok(None);409		}410		let allowance = <Allowance<T>>::get((collection.id, from, spender)).checked_sub(amount);411		if allowance.is_none() {412			ensure!(413				collection.ignores_allowance(spender),414				<CommonError<T>>::ApprovedValueTooLow415			);416		}417418		Ok(allowance)419	}420421	pub fn transfer_from(422		collection: &FungibleHandle<T>,423		spender: &T::CrossAccountId,424		from: &T::CrossAccountId,425		to: &T::CrossAccountId,426		amount: u128,427		nesting_budget: &dyn Budget,428	) -> DispatchResult {429		let allowance = Self::check_allowed(collection, spender, from, amount, nesting_budget)?;430431		// =========432433		Self::transfer(collection, from, to, amount, nesting_budget)?;434		if let Some(allowance) = allowance {435			Self::set_allowance_unchecked(collection, from, spender, allowance);436		}437		Ok(())438	}439440	pub fn burn_from(441		collection: &FungibleHandle<T>,442		spender: &T::CrossAccountId,443		from: &T::CrossAccountId,444		amount: u128,445		nesting_budget: &dyn Budget,446	) -> DispatchResult {447		let allowance = Self::check_allowed(collection, spender, from, amount, nesting_budget)?;448449		// =========450451		Self::burn(collection, from, amount)?;452		if let Some(allowance) = allowance {453			Self::set_allowance_unchecked(collection, from, spender, allowance);454		}455		Ok(())456	}457458	/// Delegated to `create_multiple_items`459	pub fn create_item(460		collection: &FungibleHandle<T>,461		sender: &T::CrossAccountId,462		data: CreateItemData<T>,463		nesting_budget: &dyn Budget,464	) -> DispatchResult {465		Self::create_multiple_items(466			collection,467			sender,468			[(data.0, data.1)].into_iter().collect(),469			nesting_budget,470		)471	}472}
modifiedpallets/nonfungible/src/common.rsdiffbeforeafterboth
--- a/pallets/nonfungible/src/common.rs
+++ b/pallets/nonfungible/src/common.rs
@@ -251,7 +251,7 @@
 	fn check_nesting(
 		&self,
 		sender: T::CrossAccountId,
-		from: CollectionId,
+		from: (CollectionId, TokenId),
 		under: TokenId,
 		budget: &dyn Budget,
 	) -> sp_runtime::DispatchResult {
modifiedpallets/nonfungible/src/lib.rsdiffbeforeafterboth
--- a/pallets/nonfungible/src/lib.rs
+++ b/pallets/nonfungible/src/lib.rs
@@ -296,7 +296,12 @@
 			let dispatch = T::CollectionDispatch::dispatch(handle);
 			let dispatch = dispatch.as_dyn();
 
-			dispatch.check_nesting(from.clone(), collection.id, target.1, nesting_budget)?;
+			dispatch.check_nesting(
+				from.clone(),
+				(collection.id, token),
+				target.1,
+				nesting_budget,
+			)?;
 		}
 
 		// =========
@@ -381,13 +386,18 @@
 			);
 		}
 
-		for (to, _) in balances.iter() {
-			if let Some(target) = T::CrossTokenAddressMapping::address_to_token(to) {
+		for (i, data) in data.iter().enumerate() {
+			let token = TokenId(first_token + i as u32 + 1);
+			if let Some(target) = T::CrossTokenAddressMapping::address_to_token(&data.owner) {
 				let handle = <CollectionHandle<T>>::try_get(target.0)?;
 				let dispatch = T::CollectionDispatch::dispatch(handle);
 				let dispatch = dispatch.as_dyn();
-
-				dispatch.check_nesting(sender.clone(), collection.id, target.1, nesting_budget)?;
+				dispatch.check_nesting(
+					sender.clone(),
+					(collection.id, token),
+					target.1,
+					nesting_budget,
+				)?;
 			}
 		}
 
@@ -535,10 +545,11 @@
 		if let Some(source) = T::CrossTokenAddressMapping::address_to_token(from) {
 			// TODO: should collection owner be allowed to perform this transfer?
 			ensure!(
-				<PalletStructure<T>>::indirectly_owned(
+				<PalletStructure<T>>::check_indirectly_owned(
 					spender.clone(),
 					source.0,
 					source.1,
+					None,
 					nesting_budget
 				)?,
 				<CommonError<T>>::ApprovedValueTooLow,
@@ -610,31 +621,40 @@
 	pub fn check_nesting(
 		handle: &NonfungibleHandle<T>,
 		sender: T::CrossAccountId,
-		from: CollectionId,
+		from: (CollectionId, TokenId),
 		under: TokenId,
 		nesting_budget: &dyn Budget,
 	) -> DispatchResult {
 		fn ensure_sender_allowed<T: Config>(
 			collection: CollectionId,
 			token: TokenId,
+			for_nest: (CollectionId, TokenId),
 			sender: T::CrossAccountId,
 			budget: &dyn Budget,
 		) -> DispatchResult {
 			ensure!(
-				<PalletStructure<T>>::indirectly_owned(sender, collection, token, budget)?,
+				<PalletStructure<T>>::check_indirectly_owned(
+					sender,
+					collection,
+					token,
+					Some(for_nest),
+					budget
+				)?,
 				<CommonError<T>>::OnlyOwnerAllowedToNest,
 			);
 			Ok(())
 		}
 		match handle.limits.nesting_rule() {
 			NestingRule::Disabled => fail!(<CommonError<T>>::NestingIsDisabled),
-			NestingRule::Owner => ensure_sender_allowed::<T>(handle.id, under, sender, nesting_budget)?,
+			NestingRule::Owner => {
+				ensure_sender_allowed::<T>(handle.id, under, from, sender, nesting_budget)?
+			}
 			NestingRule::OwnerRestricted(whitelist) => {
 				ensure!(
-					whitelist.contains(&from),
+					whitelist.contains(&from.0),
 					<CommonError<T>>::SourceCollectionIsNotAllowedToNest
 				);
-				ensure_sender_allowed::<T>(handle.id, under, sender, nesting_budget)?
+				ensure_sender_allowed::<T>(handle.id, under, from, sender, nesting_budget)?
 			}
 		}
 		Ok(())
modifiedpallets/refungible/src/common.rsdiffbeforeafterboth
--- a/pallets/refungible/src/common.rs
+++ b/pallets/refungible/src/common.rs
@@ -260,7 +260,7 @@
 	fn check_nesting(
 		&self,
 		_sender: <T>::CrossAccountId,
-		_from: CollectionId,
+		_from: (CollectionId, TokenId),
 		_under: TokenId,
 		_budget: &dyn Budget,
 	) -> sp_runtime::DispatchResult {
modifiedpallets/refungible/src/lib.rsdiffbeforeafterboth
--- a/pallets/refungible/src/lib.rs
+++ b/pallets/refungible/src/lib.rs
@@ -352,7 +352,12 @@
 			let dispatch = T::CollectionDispatch::dispatch(handle);
 			let dispatch = dispatch.as_dyn();
 
-			dispatch.check_nesting(from.clone(), collection.id, target.1, nesting_budget)?;
+			dispatch.check_nesting(
+				from.clone(),
+				(collection.id, token),
+				target.1,
+				nesting_budget,
+			)?;
 		}
 
 		// =========
@@ -455,7 +460,8 @@
 			}
 		}
 
-		for token in data.iter() {
+		for (i, token) in data.iter().enumerate() {
+			let token_id = TokenId(first_token_id + i as u32 + 1);
 			for (to, _) in token.users.iter() {
 				if let Some(target) = T::CrossTokenAddressMapping::address_to_token(to) {
 					let handle = <CollectionHandle<T>>::try_get(target.0)?;
@@ -464,7 +470,7 @@
 
 					dispatch.check_nesting(
 						sender.clone(),
-						collection.id,
+						(collection.id, token_id),
 						target.1,
 						nesting_budget,
 					)?;
@@ -575,10 +581,11 @@
 		if let Some(source) = T::CrossTokenAddressMapping::address_to_token(from) {
 			// TODO: should collection owner be allowed to perform this transfer?
 			ensure!(
-				<PalletStructure<T>>::indirectly_owned(
+				<PalletStructure<T>>::check_indirectly_owned(
 					spender.clone(),
 					source.0,
 					source.1,
+					None,
 					nesting_budget
 				)?,
 				<CommonError<T>>::ApprovedValueTooLow,
modifiedpallets/structure/src/lib.rsdiffbeforeafterboth
--- a/pallets/structure/src/lib.rs
+++ b/pallets/structure/src/lib.rs
@@ -71,7 +71,7 @@
 #[derive(PartialEq)]
 pub enum Parent<CrossAccountId> {
 	/// Token owned by normal account
-	Normal(CrossAccountId),
+	User(CrossAccountId),
 	/// Passed token not found
 	TokenNotFound,
 	/// Token owner is another token (target token still may not exist)
@@ -94,7 +94,7 @@
 		Ok(match handle.token_owner(token) {
 			Some(owner) => match T::CrossTokenAddressMapping::address_to_token(&owner) {
 				Some((collection, token)) => Parent::Token(collection, token),
-				None => Parent::Normal(owner),
+				None => Parent::User(owner),
 			},
 			None => Parent::TokenNotFound,
 		})
@@ -137,29 +137,46 @@
 	) -> Result<T::CrossAccountId, DispatchError> {
 		let owner = Self::parent_chain(collection, token)
 			.take_while(|_| budget.consume())
-			.find(|p| matches!(p, Ok(Parent::Normal(_) | Parent::TokenNotFound)))
+			.find(|p| matches!(p, Ok(Parent::User(_) | Parent::TokenNotFound)))
 			.ok_or(<Error<T>>::DepthLimit)??;
 
 		Ok(match owner {
-			Parent::Normal(v) => v,
+			Parent::User(v) => v,
 			_ => fail!(<Error<T>>::TokenNotFound),
 		})
 	}
 
 	/// Check if token indirectly owned by specified user
-	pub fn indirectly_owned(
+	pub fn check_indirectly_owned(
 		user: T::CrossAccountId,
 		collection: CollectionId,
 		token: TokenId,
+		for_nest: Option<(CollectionId, TokenId)>,
 		budget: &dyn Budget,
 	) -> Result<bool, DispatchError> {
 		let target_parent = match T::CrossTokenAddressMapping::address_to_token(&user) {
 			Some((collection, token)) => Parent::Token(collection, token),
-			None => Parent::Normal(user),
+			None => Parent::User(user),
 		};
 
-		Ok(Self::parent_chain(collection, token)
-			.take_while(|_| budget.consume())
-			.any(|parent| Ok(&target_parent) == parent.as_ref()))
+		// Tried to nest token in itself
+		if Some((collection, token)) == for_nest {
+			return Err(<Error<T>>::OuroborosDetected.into());
+		}
+
+		for parent in Self::parent_chain(collection, token).take_while(|_| budget.consume()) {
+			match parent? {
+				// Tried to nest token in chain, which has this token as one of parents
+				Parent::Token(collection, token) if Some((collection, token)) == for_nest => {
+					return Err(<Error<T>>::OuroborosDetected.into())
+				}
+				// Found needed parent, token is indirecty owned
+				v if v == target_parent => return Ok(true),
+				Parent::TokenNotFound => return Ok(false),
+				_ => {}
+			}
+		}
+
+		Err(<Error<T>>::DepthLimit.into())
 	}
 }
modifiedtests/src/eth/util/helpers.tsdiffbeforeafterboth
--- a/tests/src/eth/util/helpers.ts
+++ b/tests/src/eth/util/helpers.ts
@@ -23,7 +23,7 @@
 import usingApi, {submitTransactionAsync} from '../../substrate/substrate-api';
 import {IKeyringPair} from '@polkadot/types/types';
 import {expect} from 'chai';
-import {getGenericResult, UNIQUE} from '../../util/helpers';
+import {CrossAccountId, getGenericResult, UNIQUE} from '../../util/helpers';
 import * as solc from 'solc';
 import config from '../../config';
 import privateKey from '../../substrate/privateKey';
@@ -80,6 +80,11 @@
   ]);
   return Web3.utils.toChecksumAddress('0x' + buf.toString('hex'));
 }
+export function tokenIdToCross(collection: number, token: number): CrossAccountId {
+  return {
+    Ethereum: tokenIdToAddress(collection, token),
+  };
+}
 
 export function createEthAccount(web3: Web3) {
   const account = web3.eth.accounts.create();
addedtests/src/nesting/graphs.test.tsdiffbeforeafterboth
--- /dev/null
+++ b/tests/src/nesting/graphs.test.ts
@@ -0,0 +1,51 @@
+import {ApiPromise} from '@polkadot/api';
+import {IKeyringPair} from '@polkadot/types/types';
+import {expect} from 'chai';
+import {tokenIdToCross} from '../eth/util/helpers';
+import privateKey from '../substrate/privateKey';
+import usingApi, {executeTransaction} from '../substrate/substrate-api';
+import {getCreateCollectionResult, transferExpectSuccess} from '../util/helpers';
+
+/**
+ * ```dot
+ * 4 -> 3 -> 2 -> 1
+ * 7 -> 6 -> 5 -> 2
+ * 8 -> 5
+ * ```
+ */
+async function buildComplexObjectGraph(api: ApiPromise, sender: IKeyringPair): Promise<number> {
+  const events = await executeTransaction(api, sender, api.tx.unique.createCollectionEx({mode: 'NFT'}));
+  const {collectionId} = getCreateCollectionResult(events);
+
+  await executeTransaction(api, sender, api.tx.unique.createMultipleItemsEx(collectionId, {NFT: Array(8).fill({owner: {Substrate: sender.address}})}));
+
+  await transferExpectSuccess(collectionId, 8, sender, tokenIdToCross(collectionId, 5));
+
+  await transferExpectSuccess(collectionId, 7, sender, tokenIdToCross(collectionId, 6));
+  await transferExpectSuccess(collectionId, 6, sender, tokenIdToCross(collectionId, 5));
+  await transferExpectSuccess(collectionId, 5, sender, tokenIdToCross(collectionId, 2));
+
+  await transferExpectSuccess(collectionId, 4, sender, tokenIdToCross(collectionId, 3));
+  await transferExpectSuccess(collectionId, 3, sender, tokenIdToCross(collectionId, 2));
+  await transferExpectSuccess(collectionId, 2, sender, tokenIdToCross(collectionId, 1));
+
+  return collectionId;
+}
+
+describe('graphs', () => {
+  it('ouroboros can\'t be created in graph', async () => {
+    await usingApi(async api => {
+      const alice = privateKey('//Alice');
+      const collection = await buildComplexObjectGraph(api, alice);
+
+      // to self
+      await expect(executeTransaction(api, alice, api.tx.unique.transfer(tokenIdToCross(collection, 1), collection, 1, 1)))
+        .to.be.rejectedWith(/structure\.OuroborosDetected/);
+      // to nested part of graph
+      await expect(executeTransaction(api, alice, api.tx.unique.transfer(tokenIdToCross(collection, 5), collection, 1, 1)))
+        .to.be.rejectedWith(/structure\.OuroborosDetected/);
+      await expect(executeTransaction(api, alice, api.tx.unique.transfer(tokenIdToCross(collection, 8), collection, 2, 1)))
+        .to.be.rejectedWith(/structure\.OuroborosDetected/);
+    });
+  });
+});