git.delta.rocks / unique-network / refs/commits / bebe624eff63

difftreelog

feat prevent ouroboros creation during nest

Yaroslav Bolyukin2022-04-19parent: #07a6969.patch.diff
in: master

11 files changed

modifiedclient/rpc/src/lib.rsdiffbeforeafterboth
--- a/client/rpc/src/lib.rs
+++ b/client/rpc/src/lib.rs
@@ -77,11 +77,7 @@
 	) -> Result<Vec<u8>>;
 
 	#[rpc(name = "unique_totalSupply")]
-	fn total_supply(
-		&self,
-		collection: CollectionId,
-		at: Option<BlockHash>,
-	) -> Result<u32>;
+	fn total_supply(&self, collection: CollectionId, at: Option<BlockHash>) -> Result<u32>;
 	#[rpc(name = "unique_accountBalance")]
 	fn account_balance(
 		&self,
modifiedpallets/common/src/lib.rsdiffbeforeafterboth
--- a/pallets/common/src/lib.rs
+++ b/pallets/common/src/lib.rs
@@ -918,7 +918,7 @@
 	fn check_nesting(
 		&self,
 		sender: T::CrossAccountId,
-		from: CollectionId,
+		from: (CollectionId, TokenId),
 		under: TokenId,
 		budget: &dyn Budget,
 	) -> DispatchResult;
modifiedpallets/fungible/src/common.rsdiffbeforeafterboth
--- a/pallets/fungible/src/common.rs
+++ b/pallets/fungible/src/common.rs
@@ -237,7 +237,7 @@
 	fn check_nesting(
 		&self,
 		_sender: <T>::CrossAccountId,
-		_from: CollectionId,
+		_from: (CollectionId, TokenId),
 		_under: TokenId,
 		_budget: &dyn Budget,
 	) -> sp_runtime::DispatchResult {
modifiedpallets/fungible/src/lib.rsdiffbeforeafterboth
--- a/pallets/fungible/src/lib.rs
+++ b/pallets/fungible/src/lib.rs
@@ -224,7 +224,12 @@
 			let dispatch = T::CollectionDispatch::dispatch(handle);
 			let dispatch = dispatch.as_dyn();
 
-			dispatch.check_nesting(from.clone(), collection.id, target.1, nesting_budget)?;
+			dispatch.check_nesting(
+				from.clone(),
+				(collection.id, TokenId::default()),
+				target.1,
+				nesting_budget,
+			)?;
 		}
 
 		// =========
@@ -293,7 +298,12 @@
 				let dispatch = T::CollectionDispatch::dispatch(handle);
 				let dispatch = dispatch.as_dyn();
 
-				dispatch.check_nesting(sender.clone(), collection.id, target.1, nesting_budget)?;
+				dispatch.check_nesting(
+					sender.clone(),
+					(collection.id, TokenId::default()),
+					target.1,
+					nesting_budget,
+				)?;
 			}
 		}
 
@@ -386,10 +396,11 @@
 		if let Some(source) = T::CrossTokenAddressMapping::address_to_token(from) {
 			// TODO: should collection owner be allowed to perform this transfer?
 			ensure!(
-				<PalletStructure<T>>::indirectly_owned(
+				<PalletStructure<T>>::check_indirectly_owned(
 					spender.clone(),
 					source.0,
 					source.1,
+					None,
 					nesting_budget
 				)?,
 				<CommonError<T>>::ApprovedValueTooLow,
modifiedpallets/nonfungible/src/common.rsdiffbeforeafterboth
--- a/pallets/nonfungible/src/common.rs
+++ b/pallets/nonfungible/src/common.rs
@@ -251,7 +251,7 @@
 	fn check_nesting(
 		&self,
 		sender: T::CrossAccountId,
-		from: CollectionId,
+		from: (CollectionId, TokenId),
 		under: TokenId,
 		budget: &dyn Budget,
 	) -> sp_runtime::DispatchResult {
modifiedpallets/nonfungible/src/lib.rsdiffbeforeafterboth
before · pallets/nonfungible/src/lib.rs
1// Copyright 2019-2022 Unique Network (Gibraltar) Ltd.2// This file is part of Unique Network.34// Unique Network is free software: you can redistribute it and/or modify5// it under the terms of the GNU General Public License as published by6// the Free Software Foundation, either version 3 of the License, or7// (at your option) any later version.89// Unique Network is distributed in the hope that it will be useful,10// but WITHOUT ANY WARRANTY; without even the implied warranty of11// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the12// GNU General Public License for more details.1314// You should have received a copy of the GNU General Public License15// along with Unique Network. If not, see <http://www.gnu.org/licenses/>.1617#![cfg_attr(not(feature = "std"), no_std)]1819use erc::ERC721Events;20use frame_support::{BoundedVec, ensure, fail};21use up_data_structs::{22	AccessMode, CollectionId, CustomDataLimit, TokenId, CreateCollectionData, CreateNftExData,23	mapping::TokenAddressMapping, NestingRule, budget::Budget,24};25use pallet_evm::account::CrossAccountId;26use pallet_common::{27	Error as CommonError, Pallet as PalletCommon, Event as CommonEvent, CollectionHandle,28	dispatch::CollectionDispatch,29};30use pallet_structure::Pallet as PalletStructure;31use pallet_evm_coder_substrate::{SubstrateRecorder, WithRecorder};32use sp_core::H160;33use sp_runtime::{ArithmeticError, DispatchError, DispatchResult};34use sp_std::{vec::Vec, vec};35use core::ops::Deref;36use sp_std::collections::btree_map::BTreeMap;37use codec::{Encode, Decode, MaxEncodedLen};38use scale_info::TypeInfo;3940pub use pallet::*;41#[cfg(feature = "runtime-benchmarks")]42pub mod benchmarking;43pub mod common;44pub mod erc;45pub mod weights;4647pub type CreateItemData<T> = CreateNftExData<<T as pallet_evm::account::Config>::CrossAccountId>;48pub(crate) type SelfWeightOf<T> = <T as Config>::WeightInfo;4950#[derive(Encode, Decode, TypeInfo, MaxEncodedLen)]51pub struct ItemData<CrossAccountId> {52	pub const_data: BoundedVec<u8, CustomDataLimit>,53	pub variable_data: BoundedVec<u8, CustomDataLimit>,54	pub owner: CrossAccountId,55}5657#[frame_support::pallet]58pub mod pallet {59	use super::*;60	use frame_support::{Blake2_128Concat, Twox64Concat, pallet_prelude::*, storage::Key};61	use up_data_structs::{CollectionId, TokenId};62	use super::weights::WeightInfo;6364	#[pallet::error]65	pub enum Error<T> {66		/// Not Nonfungible item data used to mint in Nonfungible collection.67		NotNonfungibleDataUsedToMintFungibleCollectionToken,68		/// Used amount > 1 with NFT69		NonfungibleItemsHaveNoAmount,70	}7172	#[pallet::config]73	pub trait Config:74		frame_system::Config + pallet_common::Config + pallet_structure::Config75	{76		type WeightInfo: WeightInfo;77	}7879	#[pallet::pallet]80	#[pallet::generate_store(pub(super) trait Store)]81	pub struct Pallet<T>(_);8283	#[pallet::storage]84	pub type TokensMinted<T: Config> =85		StorageMap<Hasher = Twox64Concat, Key = CollectionId, Value = u32, QueryKind = ValueQuery>;86	#[pallet::storage]87	pub type TokensBurnt<T: Config> =88		StorageMap<Hasher = Twox64Concat, Key = CollectionId, Value = u32, QueryKind = ValueQuery>;8990	#[pallet::storage]91	pub type TokenData<T: Config> = StorageNMap<92		Key = (Key<Twox64Concat, CollectionId>, Key<Twox64Concat, TokenId>),93		Value = ItemData<T::CrossAccountId>,94		QueryKind = OptionQuery,95	>;9697	/// Used to enumerate tokens owned by account98	#[pallet::storage]99	pub type Owned<T: Config> = StorageNMap<100		Key = (101			Key<Twox64Concat, CollectionId>,102			Key<Blake2_128Concat, T::CrossAccountId>,103			Key<Twox64Concat, TokenId>,104		),105		Value = bool,106		QueryKind = ValueQuery,107	>;108109	#[pallet::storage]110	pub type AccountBalance<T: Config> = StorageNMap<111		Key = (112			Key<Twox64Concat, CollectionId>,113			Key<Blake2_128Concat, T::CrossAccountId>,114		),115		Value = u32,116		QueryKind = ValueQuery,117	>;118119	#[pallet::storage]120	pub type Allowance<T: Config> = StorageNMap<121		Key = (Key<Twox64Concat, CollectionId>, Key<Twox64Concat, TokenId>),122		Value = T::CrossAccountId,123		QueryKind = OptionQuery,124	>;125}126127pub struct NonfungibleHandle<T: Config>(pallet_common::CollectionHandle<T>);128impl<T: Config> NonfungibleHandle<T> {129	pub fn cast(inner: pallet_common::CollectionHandle<T>) -> Self {130		Self(inner)131	}132	pub fn into_inner(self) -> pallet_common::CollectionHandle<T> {133		self.0134	}135}136impl<T: Config> WithRecorder<T> for NonfungibleHandle<T> {137	fn recorder(&self) -> &SubstrateRecorder<T> {138		self.0.recorder()139	}140	fn into_recorder(self) -> SubstrateRecorder<T> {141		self.0.into_recorder()142	}143}144impl<T: Config> Deref for NonfungibleHandle<T> {145	type Target = pallet_common::CollectionHandle<T>;146147	fn deref(&self) -> &Self::Target {148		&self.0149	}150}151152impl<T: Config> Pallet<T> {153	pub fn total_supply(collection: &NonfungibleHandle<T>) -> u32 {154		<TokensMinted<T>>::get(collection.id) - <TokensBurnt<T>>::get(collection.id)155	}156	pub fn token_exists(collection: &NonfungibleHandle<T>, token: TokenId) -> bool {157		<TokenData<T>>::contains_key((collection.id, token))158	}159}160161// unchecked calls skips any permission checks162impl<T: Config> Pallet<T> {163	pub fn init_collection(164		owner: T::AccountId,165		data: CreateCollectionData<T::AccountId>,166	) -> Result<CollectionId, DispatchError> {167		<PalletCommon<T>>::init_collection(owner, data)168	}169	pub fn destroy_collection(170		collection: NonfungibleHandle<T>,171		sender: &T::CrossAccountId,172	) -> DispatchResult {173		let id = collection.id;174175		// =========176177		PalletCommon::destroy_collection(collection.0, sender)?;178179		<TokenData<T>>::remove_prefix((id,), None);180		<Owned<T>>::remove_prefix((id,), None);181		<TokensMinted<T>>::remove(id);182		<TokensBurnt<T>>::remove(id);183		<Allowance<T>>::remove_prefix((id,), None);184		<AccountBalance<T>>::remove_prefix((id,), None);185		Ok(())186	}187188	pub fn burn(189		collection: &NonfungibleHandle<T>,190		sender: &T::CrossAccountId,191		token: TokenId,192	) -> DispatchResult {193		let token_data =194			<TokenData<T>>::get((collection.id, token)).ok_or(<CommonError<T>>::TokenNotFound)?;195		ensure!(196			&token_data.owner == sender197				|| (collection.limits.owner_can_transfer() && collection.is_owner_or_admin(sender)),198			<CommonError<T>>::NoPermission199		);200201		if collection.access == AccessMode::AllowList {202			collection.check_allowlist(sender)?;203		}204205		let burnt = <TokensBurnt<T>>::get(collection.id)206			.checked_add(1)207			.ok_or(ArithmeticError::Overflow)?;208209		let balance = <AccountBalance<T>>::get((collection.id, token_data.owner.clone()))210			.checked_sub(1)211			.ok_or(ArithmeticError::Overflow)?;212213		if balance == 0 {214			<AccountBalance<T>>::remove((collection.id, token_data.owner.clone()));215		} else {216			<AccountBalance<T>>::insert((collection.id, token_data.owner.clone()), balance);217		}218		// =========219220		<Owned<T>>::remove((collection.id, &token_data.owner, token));221		<TokensBurnt<T>>::insert(collection.id, burnt);222		<TokenData<T>>::remove((collection.id, token));223		let old_spender = <Allowance<T>>::take((collection.id, token));224225		if let Some(old_spender) = old_spender {226			<PalletCommon<T>>::deposit_event(CommonEvent::Approved(227				collection.id,228				token,229				sender.clone(),230				old_spender,231				0,232			));233		}234235		collection.log_mirrored(ERC721Events::Transfer {236			from: *token_data.owner.as_eth(),237			to: H160::default(),238			token_id: token.into(),239		});240		<PalletCommon<T>>::deposit_event(CommonEvent::ItemDestroyed(241			collection.id,242			token,243			token_data.owner,244			1,245		));246		Ok(())247	}248249	pub fn transfer(250		collection: &NonfungibleHandle<T>,251		from: &T::CrossAccountId,252		to: &T::CrossAccountId,253		token: TokenId,254		nesting_budget: &dyn Budget,255	) -> DispatchResult {256		ensure!(257			collection.limits.transfers_enabled(),258			<CommonError<T>>::TransferNotAllowed259		);260261		let token_data =262			<TokenData<T>>::get((collection.id, token)).ok_or(<CommonError<T>>::TokenNotFound)?;263		// TODO: require sender to be token, owner, require admins to go through transfer_from264		ensure!(265			&token_data.owner == from266				|| (collection.limits.owner_can_transfer() && collection.is_owner_or_admin(from)),267			<CommonError<T>>::NoPermission268		);269270		if collection.access == AccessMode::AllowList {271			collection.check_allowlist(from)?;272			collection.check_allowlist(to)?;273		}274		<PalletCommon<T>>::ensure_correct_receiver(to)?;275276		let balance_from = <AccountBalance<T>>::get((collection.id, from))277			.checked_sub(1)278			.ok_or(<CommonError<T>>::TokenValueTooLow)?;279		let balance_to = if from != to {280			let balance_to = <AccountBalance<T>>::get((collection.id, to))281				.checked_add(1)282				.ok_or(ArithmeticError::Overflow)?;283284			ensure!(285				balance_to < collection.limits.account_token_ownership_limit(),286				<CommonError<T>>::AccountTokenLimitExceeded,287			);288289			Some(balance_to)290		} else {291			None292		};293294		if let Some(target) = T::CrossTokenAddressMapping::address_to_token(to) {295			let handle = <CollectionHandle<T>>::try_get(target.0)?;296			let dispatch = T::CollectionDispatch::dispatch(handle);297			let dispatch = dispatch.as_dyn();298299			dispatch.check_nesting(from.clone(), collection.id, target.1, nesting_budget)?;300		}301302		// =========303304		<TokenData<T>>::insert(305			(collection.id, token),306			ItemData {307				owner: to.clone(),308				..token_data309			},310		);311312		if let Some(balance_to) = balance_to {313			// from != to314			if balance_from == 0 {315				<AccountBalance<T>>::remove((collection.id, from));316			} else {317				<AccountBalance<T>>::insert((collection.id, from), balance_from);318			}319			<AccountBalance<T>>::insert((collection.id, to), balance_to);320			<Owned<T>>::remove((collection.id, from, token));321			<Owned<T>>::insert((collection.id, to, token), true);322		}323		Self::set_allowance_unchecked(collection, from, token, None, true);324325		collection.log_mirrored(ERC721Events::Transfer {326			from: *from.as_eth(),327			to: *to.as_eth(),328			token_id: token.into(),329		});330		<PalletCommon<T>>::deposit_event(CommonEvent::Transfer(331			collection.id,332			token,333			from.clone(),334			to.clone(),335			1,336		));337		Ok(())338	}339340	pub fn create_multiple_items(341		collection: &NonfungibleHandle<T>,342		sender: &T::CrossAccountId,343		data: Vec<CreateItemData<T>>,344		nesting_budget: &dyn Budget,345	) -> DispatchResult {346		if !collection.is_owner_or_admin(sender) {347			ensure!(348				collection.mint_mode,349				<CommonError<T>>::PublicMintingNotAllowed350			);351			collection.check_allowlist(sender)?;352353			for item in data.iter() {354				collection.check_allowlist(&item.owner)?;355			}356		}357358		for data in data.iter() {359			<PalletCommon<T>>::ensure_correct_receiver(&data.owner)?;360		}361362		let first_token = <TokensMinted<T>>::get(collection.id);363		let tokens_minted = first_token364			.checked_add(data.len() as u32)365			.ok_or(ArithmeticError::Overflow)?;366		ensure!(367			tokens_minted <= collection.limits.token_limit(),368			<CommonError<T>>::CollectionTokenLimitExceeded369		);370371		let mut balances = BTreeMap::new();372		for data in &data {373			let balance = balances374				.entry(&data.owner)375				.or_insert_with(|| <AccountBalance<T>>::get((collection.id, &data.owner)));376			*balance = balance.checked_add(1).ok_or(ArithmeticError::Overflow)?;377378			ensure!(379				*balance <= collection.limits.account_token_ownership_limit(),380				<CommonError<T>>::AccountTokenLimitExceeded,381			);382		}383384		for (to, _) in balances.iter() {385			if let Some(target) = T::CrossTokenAddressMapping::address_to_token(to) {386				let handle = <CollectionHandle<T>>::try_get(target.0)?;387				let dispatch = T::CollectionDispatch::dispatch(handle);388				let dispatch = dispatch.as_dyn();389390				dispatch.check_nesting(sender.clone(), collection.id, target.1, nesting_budget)?;391			}392		}393394		// =========395396		<TokensMinted<T>>::insert(collection.id, tokens_minted);397		for (account, balance) in balances {398			<AccountBalance<T>>::insert((collection.id, account), balance);399		}400		for (i, data) in data.into_iter().enumerate() {401			let token = first_token + i as u32 + 1;402403			<TokenData<T>>::insert(404				(collection.id, token),405				ItemData {406					const_data: data.const_data,407					variable_data: data.variable_data,408					owner: data.owner.clone(),409				},410			);411			<Owned<T>>::insert((collection.id, &data.owner, token), true);412413			collection.log_mirrored(ERC721Events::Transfer {414				from: H160::default(),415				to: *data.owner.as_eth(),416				token_id: token.into(),417			});418			<PalletCommon<T>>::deposit_event(CommonEvent::ItemCreated(419				collection.id,420				TokenId(token),421				data.owner.clone(),422				1,423			));424		}425		Ok(())426	}427428	pub fn set_allowance_unchecked(429		collection: &NonfungibleHandle<T>,430		sender: &T::CrossAccountId,431		token: TokenId,432		spender: Option<&T::CrossAccountId>,433		assume_implicit_eth: bool,434	) {435		if let Some(spender) = spender {436			let old_spender = <Allowance<T>>::get((collection.id, token));437			<Allowance<T>>::insert((collection.id, token), spender);438			// In ERC721 there is only one possible approved user of token, so we set439			// approved user to spender440			collection.log_mirrored(ERC721Events::Approval {441				owner: *sender.as_eth(),442				approved: *spender.as_eth(),443				token_id: token.into(),444			});445			// In Unique chain, any token can have any amount of approved users, so we need to446			// set allowance of old owner to 0, and allowance of new owner to 1447			if old_spender.as_ref() != Some(spender) {448				if let Some(old_owner) = old_spender {449					<PalletCommon<T>>::deposit_event(CommonEvent::Approved(450						collection.id,451						token,452						sender.clone(),453						old_owner,454						0,455					));456				}457				<PalletCommon<T>>::deposit_event(CommonEvent::Approved(458					collection.id,459					token,460					sender.clone(),461					spender.clone(),462					1,463				));464			}465		} else {466			let old_spender = <Allowance<T>>::take((collection.id, token));467			if !assume_implicit_eth {468				// In ERC721 there is only one possible approved user of token, so we set469				// approved user to zero address470				collection.log_mirrored(ERC721Events::Approval {471					owner: *sender.as_eth(),472					approved: H160::default(),473					token_id: token.into(),474				});475			}476			// In Unique chain, any token can have any amount of approved users, so we need to477			// set allowance of old owner to 0478			if let Some(old_spender) = old_spender {479				<PalletCommon<T>>::deposit_event(CommonEvent::Approved(480					collection.id,481					token,482					sender.clone(),483					old_spender,484					0,485				));486			}487		}488	}489490	pub fn set_allowance(491		collection: &NonfungibleHandle<T>,492		sender: &T::CrossAccountId,493		token: TokenId,494		spender: Option<&T::CrossAccountId>,495	) -> DispatchResult {496		if collection.access == AccessMode::AllowList {497			collection.check_allowlist(sender)?;498			if let Some(spender) = spender {499				collection.check_allowlist(spender)?;500			}501		}502503		if let Some(spender) = spender {504			<PalletCommon<T>>::ensure_correct_receiver(spender)?;505		}506		let token_data =507			<TokenData<T>>::get((collection.id, token)).ok_or(<CommonError<T>>::TokenNotFound)?;508		if &token_data.owner != sender {509			ensure!(510				collection.ignores_owned_amount(sender),511				<CommonError<T>>::CantApproveMoreThanOwned512			);513		}514515		// =========516517		Self::set_allowance_unchecked(collection, sender, token, spender, false);518		Ok(())519	}520521	fn check_allowed(522		collection: &NonfungibleHandle<T>,523		spender: &T::CrossAccountId,524		from: &T::CrossAccountId,525		token: TokenId,526		nesting_budget: &dyn Budget,527	) -> DispatchResult {528		if spender.conv_eq(from) {529			return Ok(());530		}531		if collection.access == AccessMode::AllowList {532			// `from`, `to` checked in [`transfer`]533			collection.check_allowlist(spender)?;534		}535		if let Some(source) = T::CrossTokenAddressMapping::address_to_token(from) {536			// TODO: should collection owner be allowed to perform this transfer?537			ensure!(538				<PalletStructure<T>>::indirectly_owned(539					spender.clone(),540					source.0,541					source.1,542					nesting_budget543				)?,544				<CommonError<T>>::ApprovedValueTooLow,545			);546			return Ok(());547		}548		if <Allowance<T>>::get((collection.id, token)).as_ref() == Some(spender) {549			return Ok(());550		}551		ensure!(552			collection.ignores_allowance(spender),553			<CommonError<T>>::ApprovedValueTooLow554		);555		Ok(())556	}557558	pub fn transfer_from(559		collection: &NonfungibleHandle<T>,560		spender: &T::CrossAccountId,561		from: &T::CrossAccountId,562		to: &T::CrossAccountId,563		token: TokenId,564		nesting_budget: &dyn Budget,565	) -> DispatchResult {566		Self::check_allowed(collection, spender, from, token, nesting_budget)?;567568		// =========569570		// Allowance is reset in [`transfer`]571		Self::transfer(collection, from, to, token, nesting_budget)572	}573574	pub fn burn_from(575		collection: &NonfungibleHandle<T>,576		spender: &T::CrossAccountId,577		from: &T::CrossAccountId,578		token: TokenId,579		nesting_budget: &dyn Budget,580	) -> DispatchResult {581		Self::check_allowed(collection, spender, from, token, nesting_budget)?;582583		// =========584585		Self::burn(collection, from, token)586	}587588	pub fn set_variable_metadata(589		collection: &NonfungibleHandle<T>,590		sender: &T::CrossAccountId,591		token: TokenId,592		data: BoundedVec<u8, CustomDataLimit>,593	) -> DispatchResult {594		let token_data =595			<TokenData<T>>::get((collection.id, token)).ok_or(<CommonError<T>>::TokenNotFound)?;596		collection.check_can_update_meta(sender, &token_data.owner)?;597598		// =========599600		<TokenData<T>>::insert(601			(collection.id, token),602			ItemData {603				variable_data: data,604				..token_data605			},606		);607		Ok(())608	}609610	pub fn check_nesting(611		handle: &NonfungibleHandle<T>,612		sender: T::CrossAccountId,613		from: CollectionId,614		under: TokenId,615		nesting_budget: &dyn Budget,616	) -> DispatchResult {617		fn ensure_sender_allowed<T: Config>(618			collection: CollectionId,619			token: TokenId,620			sender: T::CrossAccountId,621			budget: &dyn Budget,622		) -> DispatchResult {623			ensure!(624				<PalletStructure<T>>::indirectly_owned(sender, collection, token, budget)?,625				<CommonError<T>>::OnlyOwnerAllowedToNest,626			);627			Ok(())628		}629		match handle.limits.nesting_rule() {630			NestingRule::Disabled => fail!(<CommonError<T>>::NestingIsDisabled),631			NestingRule::Owner => ensure_sender_allowed::<T>(handle.id, under, sender, nesting_budget)?,632			NestingRule::OwnerRestricted(whitelist) => {633				ensure!(634					whitelist.contains(&from),635					<CommonError<T>>::SourceCollectionIsNotAllowedToNest636				);637				ensure_sender_allowed::<T>(handle.id, under, sender, nesting_budget)?638			}639		}640		Ok(())641	}642643	/// Delegated to `create_multiple_items`644	pub fn create_item(645		collection: &NonfungibleHandle<T>,646		sender: &T::CrossAccountId,647		data: CreateItemData<T>,648		nesting_budget: &dyn Budget,649	) -> DispatchResult {650		Self::create_multiple_items(collection, sender, vec![data], nesting_budget)651	}652}
modifiedpallets/refungible/src/common.rsdiffbeforeafterboth
--- a/pallets/refungible/src/common.rs
+++ b/pallets/refungible/src/common.rs
@@ -260,7 +260,7 @@
 	fn check_nesting(
 		&self,
 		_sender: <T>::CrossAccountId,
-		_from: CollectionId,
+		_from: (CollectionId, TokenId),
 		_under: TokenId,
 		_budget: &dyn Budget,
 	) -> sp_runtime::DispatchResult {
modifiedpallets/refungible/src/lib.rsdiffbeforeafterboth
--- a/pallets/refungible/src/lib.rs
+++ b/pallets/refungible/src/lib.rs
@@ -352,7 +352,12 @@
 			let dispatch = T::CollectionDispatch::dispatch(handle);
 			let dispatch = dispatch.as_dyn();
 
-			dispatch.check_nesting(from.clone(), collection.id, target.1, nesting_budget)?;
+			dispatch.check_nesting(
+				from.clone(),
+				(collection.id, token),
+				target.1,
+				nesting_budget,
+			)?;
 		}
 
 		// =========
@@ -455,7 +460,8 @@
 			}
 		}
 
-		for token in data.iter() {
+		for (i, token) in data.iter().enumerate() {
+			let token_id = TokenId(first_token_id + i as u32 + 1);
 			for (to, _) in token.users.iter() {
 				if let Some(target) = T::CrossTokenAddressMapping::address_to_token(to) {
 					let handle = <CollectionHandle<T>>::try_get(target.0)?;
@@ -464,7 +470,7 @@
 
 					dispatch.check_nesting(
 						sender.clone(),
-						collection.id,
+						(collection.id, token_id),
 						target.1,
 						nesting_budget,
 					)?;
@@ -575,10 +581,11 @@
 		if let Some(source) = T::CrossTokenAddressMapping::address_to_token(from) {
 			// TODO: should collection owner be allowed to perform this transfer?
 			ensure!(
-				<PalletStructure<T>>::indirectly_owned(
+				<PalletStructure<T>>::check_indirectly_owned(
 					spender.clone(),
 					source.0,
 					source.1,
+					None,
 					nesting_budget
 				)?,
 				<CommonError<T>>::ApprovedValueTooLow,
modifiedpallets/structure/src/lib.rsdiffbeforeafterboth
--- a/pallets/structure/src/lib.rs
+++ b/pallets/structure/src/lib.rs
@@ -71,7 +71,7 @@
 #[derive(PartialEq)]
 pub enum Parent<CrossAccountId> {
 	/// Token owned by normal account
-	Normal(CrossAccountId),
+	User(CrossAccountId),
 	/// Passed token not found
 	TokenNotFound,
 	/// Token owner is another token (target token still may not exist)
@@ -94,7 +94,7 @@
 		Ok(match handle.token_owner(token) {
 			Some(owner) => match T::CrossTokenAddressMapping::address_to_token(&owner) {
 				Some((collection, token)) => Parent::Token(collection, token),
-				None => Parent::Normal(owner),
+				None => Parent::User(owner),
 			},
 			None => Parent::TokenNotFound,
 		})
@@ -137,29 +137,46 @@
 	) -> Result<T::CrossAccountId, DispatchError> {
 		let owner = Self::parent_chain(collection, token)
 			.take_while(|_| budget.consume())
-			.find(|p| matches!(p, Ok(Parent::Normal(_) | Parent::TokenNotFound)))
+			.find(|p| matches!(p, Ok(Parent::User(_) | Parent::TokenNotFound)))
 			.ok_or(<Error<T>>::DepthLimit)??;
 
 		Ok(match owner {
-			Parent::Normal(v) => v,
+			Parent::User(v) => v,
 			_ => fail!(<Error<T>>::TokenNotFound),
 		})
 	}
 
 	/// Check if token indirectly owned by specified user
-	pub fn indirectly_owned(
+	pub fn check_indirectly_owned(
 		user: T::CrossAccountId,
 		collection: CollectionId,
 		token: TokenId,
+		for_nest: Option<(CollectionId, TokenId)>,
 		budget: &dyn Budget,
 	) -> Result<bool, DispatchError> {
 		let target_parent = match T::CrossTokenAddressMapping::address_to_token(&user) {
 			Some((collection, token)) => Parent::Token(collection, token),
-			None => Parent::Normal(user),
+			None => Parent::User(user),
 		};
 
-		Ok(Self::parent_chain(collection, token)
-			.take_while(|_| budget.consume())
-			.any(|parent| Ok(&target_parent) == parent.as_ref()))
+		// Tried to nest token in itself
+		if Some((collection, token)) == for_nest {
+			return Err(<Error<T>>::OuroborosDetected.into());
+		}
+
+		for parent in Self::parent_chain(collection, token).take_while(|_| budget.consume()) {
+			match parent? {
+				// Tried to nest token in chain, which has this token as one of parents
+				Parent::Token(collection, token) if Some((collection, token)) == for_nest => {
+					return Err(<Error<T>>::OuroborosDetected.into())
+				}
+				// Found needed parent, token is indirecty owned
+				v if v == target_parent => return Ok(true),
+				Parent::TokenNotFound => return Ok(false),
+				_ => {}
+			}
+		}
+
+		Err(<Error<T>>::DepthLimit.into())
 	}
 }
modifiedtests/src/eth/util/helpers.tsdiffbeforeafterboth
--- a/tests/src/eth/util/helpers.ts
+++ b/tests/src/eth/util/helpers.ts
@@ -23,7 +23,7 @@
 import usingApi, {submitTransactionAsync} from '../../substrate/substrate-api';
 import {IKeyringPair} from '@polkadot/types/types';
 import {expect} from 'chai';
-import {getGenericResult, UNIQUE} from '../../util/helpers';
+import {CrossAccountId, getGenericResult, UNIQUE} from '../../util/helpers';
 import * as solc from 'solc';
 import config from '../../config';
 import privateKey from '../../substrate/privateKey';
@@ -80,6 +80,11 @@
   ]);
   return Web3.utils.toChecksumAddress('0x' + buf.toString('hex'));
 }
+export function tokenIdToCross(collection: number, token: number): CrossAccountId {
+  return {
+    Ethereum: tokenIdToAddress(collection, token),
+  };
+}
 
 export function createEthAccount(web3: Web3) {
   const account = web3.eth.accounts.create();
addedtests/src/nesting/graphs.test.tsdiffbeforeafterboth
--- /dev/null
+++ b/tests/src/nesting/graphs.test.ts
@@ -0,0 +1,51 @@
+import {ApiPromise} from '@polkadot/api';
+import {IKeyringPair} from '@polkadot/types/types';
+import {expect} from 'chai';
+import {tokenIdToCross} from '../eth/util/helpers';
+import privateKey from '../substrate/privateKey';
+import usingApi, {executeTransaction} from '../substrate/substrate-api';
+import {getCreateCollectionResult, transferExpectSuccess} from '../util/helpers';
+
+/**
+ * ```dot
+ * 4 -> 3 -> 2 -> 1
+ * 7 -> 6 -> 5 -> 2
+ * 8 -> 5
+ * ```
+ */
+async function buildComplexObjectGraph(api: ApiPromise, sender: IKeyringPair): Promise<number> {
+  const events = await executeTransaction(api, sender, api.tx.unique.createCollectionEx({mode: 'NFT'}));
+  const {collectionId} = getCreateCollectionResult(events);
+
+  await executeTransaction(api, sender, api.tx.unique.createMultipleItemsEx(collectionId, {NFT: Array(8).fill({owner: {Substrate: sender.address}})}));
+
+  await transferExpectSuccess(collectionId, 8, sender, tokenIdToCross(collectionId, 5));
+
+  await transferExpectSuccess(collectionId, 7, sender, tokenIdToCross(collectionId, 6));
+  await transferExpectSuccess(collectionId, 6, sender, tokenIdToCross(collectionId, 5));
+  await transferExpectSuccess(collectionId, 5, sender, tokenIdToCross(collectionId, 2));
+
+  await transferExpectSuccess(collectionId, 4, sender, tokenIdToCross(collectionId, 3));
+  await transferExpectSuccess(collectionId, 3, sender, tokenIdToCross(collectionId, 2));
+  await transferExpectSuccess(collectionId, 2, sender, tokenIdToCross(collectionId, 1));
+
+  return collectionId;
+}
+
+describe('graphs', () => {
+  it('ouroboros can\'t be created in graph', async () => {
+    await usingApi(async api => {
+      const alice = privateKey('//Alice');
+      const collection = await buildComplexObjectGraph(api, alice);
+
+      // to self
+      await expect(executeTransaction(api, alice, api.tx.unique.transfer(tokenIdToCross(collection, 1), collection, 1, 1)))
+        .to.be.rejectedWith(/structure\.OuroborosDetected/);
+      // to nested part of graph
+      await expect(executeTransaction(api, alice, api.tx.unique.transfer(tokenIdToCross(collection, 5), collection, 1, 1)))
+        .to.be.rejectedWith(/structure\.OuroborosDetected/);
+      await expect(executeTransaction(api, alice, api.tx.unique.transfer(tokenIdToCross(collection, 8), collection, 2, 1)))
+        .to.be.rejectedWith(/structure\.OuroborosDetected/);
+    });
+  });
+});