From 17f4f169af805458e0b77b4044b08c9052da2e2e Mon Sep 17 00:00:00 2001 From: Paul Berg Date: Sat, 29 Sep 2018 01:35:27 +0300 Subject: [PATCH] Named functions and defined a basic EIP191 content type list --- cmd/clef/main.go | 2 - signer/core/api.go | 198 ++++++++++++++++++++++++++++++++++++++++ signer/core/api_test.go | 40 ++++++++ 3 files changed, 238 insertions(+), 2 deletions(-) diff --git a/cmd/clef/main.go b/cmd/clef/main.go index f3464b2ff6..1dac85af92 100644 --- a/cmd/clef/main.go +++ b/cmd/clef/main.go @@ -664,8 +664,6 @@ func testExternalUI(api *core.SignerAPI) { checkErr("SignTransaction", err) _, err = api.SignData(ctx, "text/plain", common.MixedcaseAddress{}, common.Hex2Bytes("01020304")) checkErr("SignData", err) - //_, err = api.SignTypedData(ctx, common.MixedcaseAddress{}, core.TypedData{}) - //checkErr("SignTypedData", err) _, err = api.List(ctx) checkErr("List", err) _, err = api.New(ctx) diff --git a/signer/core/api.go b/signer/core/api.go index 49532f6ac4..2fdd4d542c 100644 --- a/signer/core/api.go +++ b/signer/core/api.go @@ -21,8 +21,11 @@ import ( "encoding/json" "errors" "fmt" + "github.com/ethereum/go-ethereum/core/types" + "github.com/ethereum/go-ethereum/crypto/sha3" "io/ioutil" "math/big" + "mime" "reflect" "github.com/ethereum/go-ethereum/accounts" @@ -175,7 +178,11 @@ type ( SignDataRequest struct { ContentType string `json:"content_type"` Address common.MixedcaseAddress `json:"address"` +<<<<<<< HEAD Rawdata interface{} `json:"raw_data"` +======= + Rawdata hexutil.Bytes `json:"raw_data"` +>>>>>>> 834cf03b0... Named functions and defined a basic EIP191 content type list Message string `json:"message"` Hash hexutil.Bytes `json:"hash"` Meta Metadata `json:"meta"` @@ -514,6 +521,197 @@ func (api *SignerAPI) SignTransaction(ctx context.Context, args SendTxArgs, meth } +<<<<<<< HEAD +======= +// SignData signs the hash of the provided data, but does so differently +// depending on the content-type specified. +// +// Depending on the content-type, different types of validations will occur. +// +// Note, the produced signature conforms to the secp256k1 curve R, S and V values, +// where the V value will be 27 or 28 for legacy reasons. +func (api *SignerAPI) SignData(ctx context.Context, contentType string, addr common.MixedcaseAddress, data hexutil.Bytes) (hexutil.Bytes, error) { + + var req, err = api.determineSignatureFormat(contentType, data) + if err != nil { + return nil, err + } + req.Address = addr + req.Meta = MetadataFromContext(ctx) + + // We make the request prior to looking up if we actually have the account, to prevent + // account-enumeration via the API + res, err := api.UI.ApproveSignData(req) + if err != nil { + return nil, err + } + if !res.Approved { + return nil, ErrRequestDenied + } + // Look up the wallet containing the requested signer + account := accounts.Account{Address: addr.Address()} + wallet, err := api.am.Find(account) + if err != nil { + return nil, err + } + // Sign the data with the wallet + signature, err := wallet.SignHashWithPassphrase(account, res.Password, req.Hash) + if err != nil { + api.UI.ShowError(err.Error()) + return nil, err + } + signature[64] += 27 // Transform V from 0/1 to 27/28 according to the yellow paper + return signature, nil +} + +// EcRecover returns the address for the Account that was used to create the signature. +// Note, this function is compatible with eth_sign and personal_sign. As such it recovers +// the address of: +// hash = keccak256("\x19Ethereum Signed Message:\n"${message length}${message}) +// addr = ecrecover(hash, signature) +// +// Note, the signature must conform to the secp256k1 curve R, S and V values, where +// the V value must be be 27 or 28 for legacy reasons. +// +// https://github.com/ethereum/go-ethereum/wiki/Management-APIs#personal_ecRecover +func (api *SignerAPI) EcRecover(ctx context.Context, contentType string, data, sig hexutil.Bytes) (common.Address, error) { + if len(sig) != 65 { + return common.Address{}, fmt.Errorf("signature must be 65 bytes long") + } + if sig[64] != 27 && sig[64] != 28 { + return common.Address{}, fmt.Errorf("invalid Ethereum signature (V is not 27 or 28)") + } + sig[64] -= 27 // Transform yellow paper V from 27/28 to 0/1 + hash, _ := SignDataPlain(data) + rpk, err := crypto.SigToPub(hash, sig) + if err != nil { + return common.Address{}, err + } + return crypto.PubkeyToAddress(*rpk), nil +} + +// Determines which signature method should be used based upon the mime type +func (api *SignerAPI) determineSignatureFormat(contentType string, data hexutil.Bytes) (*SignDataRequest, error) { + var req *SignDataRequest + mediaType, _, err := mime.ParseMediaType(contentType) + if err != nil { + return nil, err + } + switch mediaType { + case "application/clique": + header := &types.Header{} + if err := rlp.DecodeBytes(data, header); err != nil { + return nil, err + } + sighash, err := SignCliqueHeader(header) + if err != nil { + return nil, err + } + msg := fmt.Sprintf("Clique block %d [0x%x]", header.Number, header.Hash()) + req = &SignDataRequest{Rawdata: data, Message: msg, Hash: sighash, ContentType: mediaType} + case "application/validator": + // Sign calculates an Ethereum ECDSA signature for: + // keccack256("\x19Ethereum Signed Message:\n" + len(message) + message)) + + // In the cases where it matter ensure that the charset is handled. The charset + // resides in the 'params' returned as the second returnvalue from mime.ParseMediaType + // charset, ok := params["charset"] + // As it is now, we accept any charset and just treat it as 'raw'. + + sighash, msg := DataWithValidatorHash(data) + req = &SignDataRequest{Rawdata: data, Message: msg, Hash: sighash, ContentType: mediaType} + case "data/structured": + // EIP712 typed data + + // Sign calculates an Ethereum ECDSA signature for: + // keccack256("\x19Ethereum Signed Message:\n" + len(message) + message)) + + // In the cases where it matter ensure that the charset is handled. The charset + // resides in the 'params' returned as the second returnvalue from mime.ParseMediaType + // charset, ok := params["charset"] + // As it is now, we accept any charset and just treat it as 'raw'. + + sighash, msg := DataStructuredHash(data) + req = &SignDataRequest{Rawdata: data, Message: msg, Hash: sighash, ContentType: mediaType} + case "data/plain": + // Sign calculates an Ethereum ECDSA signature for: + // keccack256("\x19Ethereum Signed Message:\n" + len(message) + message)) + + // In the cases where it matter ensure that the charset is handled. The charset + // resides in the 'params' returned as the second returnvalue from mime.ParseMediaType + // charset, ok := params["charset"] + // As it is now, we accept any charset and just treat it as 'raw'. + + sighash, msg := DataPlainHash(data) + req = &SignDataRequest{Rawdata: data, Message: msg, Hash: sighash, ContentType: mediaType} + default: + return nil, fmt.Errorf("content type '%s' not implemented for signing", contentType) + } + return req, nil + +} + +// SignCliqueHeader returns the hash which is used as input for the proof-of-authority +// signing. It is the hash of the entire header apart from the 65 byte signature +// contained at the end of the extra data. +// +// The method requires the extra data to be at least 65 bytes -- the original implementation +// in clique.go panics if this is the case, thus it's been reimplemented here to avoid the panic +// and simply return an error instead +func SignCliqueHeader(header *types.Header) (hexutil.Bytes, error) { + hash := common.Hash{} + if len(header.Extra) < 65 { + return hash.Bytes(), fmt.Errorf("clique header extradata too short, %d < 65", len(header.Extra)) + } + hasher := sha3.NewKeccak256() + rlp.Encode(hasher, []interface{}{ + header.ParentHash, + header.UncleHash, + header.Coinbase, + header.Root, + header.TxHash, + header.ReceiptHash, + header.Bloom, + header.Difficulty, + header.Number, + header.GasLimit, + header.GasUsed, + header.Time, + header.Extra[:len(header.Extra)-65], + header.MixDigest, + header.Nonce, + }) + hasher.Sum(hash[:0]) + return hash.Bytes(), nil +} + +// DataWithValidatorHash signs the given message according to EIP191. +// +// https://github.com/ethereum/EIPs/issues/712 +func DataWithValidatorHash(data []byte) ([]byte, string) { + return nil, "" +} + +// DataStructuredHash signs the given message according to EIP712. +// +// https://github.com/ethereum/EIPs/issues/712 +func DataStructuredHash(data []byte) ([]byte, string) { + return nil, "" +} + +// DataPlainHash is a helper function that calculates a hash for the given message that can be +// safely used to calculate a signature from. +// +// The hash is calculated as +// keccak256("\x19Ethereum Signed Message:\n"${message length}${message}). +// +// This gives context to the signed message and prevents signing of transactions. +func DataPlainHash(data []byte) ([]byte, string) { + msg := fmt.Sprintf("\x19Ethereum Signed Message:\n%d%s", len(data), data) + return crypto.Keccak256([]byte(msg)), msg +} + +>>>>>>> 834cf03b0... Named functions and defined a basic EIP191 content type list // Export returns encrypted private key associated with the given address in web3 keystore format. func (api *SignerAPI) Export(ctx context.Context, addr common.Address) (json.RawMessage, error) { res, err := api.UI.ApproveExport(&ExportRequest{Address: addr, Meta: MetadataFromContext(ctx)}) diff --git a/signer/core/api_test.go b/signer/core/api_test.go index ff68c0b4e1..3bab5d0e97 100644 --- a/signer/core/api_test.go +++ b/signer/core/api_test.go @@ -245,6 +245,46 @@ func TestNewAcc(t *testing.T) { } } +func TestSignData(t *testing.T) { + api, control := setup(t) + //Create two accounts + createAccount(control, api, t) + createAccount(control, api, t) + control <- "1" + list, err := api.List(context.Background()) + if err != nil { + t.Fatal(err) + } + a := common.NewMixedcaseAddress(list[0]) + + control <- "Y" + control <- "wrongpassword" + h, err := api.SignData(context.Background(), "text/plain", a, []byte("EHLO world")) + if h != nil { + t.Errorf("Expected nil-data, got %x", h) + } + if err != keystore.ErrDecrypt { + t.Errorf("Expected ErrLocked! %v", err) + } + control <- "No way" + h, err = api.SignData(context.Background(), "text/plain", a, []byte("EHLO world")) + if h != nil { + t.Errorf("Expected nil-data, got %x", h) + } + if err != ErrRequestDenied { + t.Errorf("Expected ErrRequestDenied! %v", err) + } + control <- "Y" + control <- "a_long_password" + h, err = api.SignData(context.Background(), "text/plain", a, []byte("EHLO world")) + if err != nil { + t.Fatal(err) + } + if h == nil || len(h) != 65 { + t.Errorf("Expected 65 byte signature (got %d bytes)", len(h)) + } +} + func mkTestTx(from common.MixedcaseAddress) SendTxArgs { to := common.NewMixedcaseAddress(common.HexToAddress("0x1337")) gas := hexutil.Uint64(21000)