5.22 KiB
Newer Older
// Copyright 2015-2018 Parity Technologies (UK) Ltd.
// This file is part of Parity.

// Parity is free software: you can redistribute it and/or modify
// it under the terms of the GNU General Public License as published by
// the Free Software Foundation, either version 3 of the License, or
// (at your option) any later version.

// Parity is distributed in the hope that it will be useful,
// but WITHOUT ANY WARRANTY; without even the implied warranty of
// GNU General Public License for more details.

// You should have received a copy of the GNU General Public License
// along with Parity.  If not, see <>.

//! Smart contract based node filter.

Marek Kotewicz's avatar
Marek Kotewicz committed
extern crate ethabi;
extern crate ethcore;
extern crate ethcore_network as network;
extern crate ethcore_network_devp2p as devp2p;
Marek Kotewicz's avatar
Marek Kotewicz committed
extern crate ethereum_types;
Marek Kotewicz's avatar
Marek Kotewicz committed
extern crate lru_cache;
extern crate parking_lot;
Marek Kotewicz's avatar
Marek Kotewicz committed
extern crate ethabi_derive;
extern crate ethabi_contract;
extern crate ethcore_io as io;
Marek Kotewicz's avatar
Marek Kotewicz committed
extern crate kvdb_memorydb;
extern crate tempdir;
Marek Kotewicz's avatar
Marek Kotewicz committed
extern crate log;

use std::sync::Weak;
Marek Kotewicz's avatar
Marek Kotewicz committed

use lru_cache::LruCache;
use parking_lot::Mutex;

use ethcore::client::{BlockChainClient, BlockId};
Marek Kotewicz's avatar
Marek Kotewicz committed
use ethereum_types::{H256, Address};
use network::{ConnectionFilter, ConnectionDirection};
use devp2p::NodeId;
Marek Kotewicz's avatar
Marek Kotewicz committed

use_contract!(peer_set, "PeerSet", "res/peer_set.json");

const MAX_CACHE_SIZE: usize = 4096;

/// Connection filter that uses a contract to manage permissions.
pub struct NodeFilter {
Marek Kotewicz's avatar
Marek Kotewicz committed
	contract: peer_set::PeerSet,
	client: Weak<BlockChainClient>,
	contract_address: Address,
	permission_cache: Mutex<LruCache<(H256, NodeId), bool>>,

impl NodeFilter {
	/// Create a new instance. Accepts a contract address.
	pub fn new(client: Weak<BlockChainClient>, contract_address: Address) -> NodeFilter {
		NodeFilter {
Marek Kotewicz's avatar
Marek Kotewicz committed
			contract: peer_set::PeerSet::default(),
Marek Kotewicz's avatar
Marek Kotewicz committed
			permission_cache: Mutex::new(LruCache::new(MAX_CACHE_SIZE)),

impl ConnectionFilter for NodeFilter {
	fn connection_allowed(&self, own_id: &NodeId, connecting_id: &NodeId, _direction: ConnectionDirection) -> bool {
		let client = match self.client.upgrade() {
			Some(client) => client,
			None => return false,

		let block_hash = match client.block_hash(BlockId::Latest) {
			Some(block_hash) => block_hash,
			None => return false,

		let key = (block_hash, *connecting_id);

		let mut cache = self.permission_cache.lock();
		if let Some(res) = cache.get_mut(&key) {
			return *res;

Marek Kotewicz's avatar
Marek Kotewicz committed
		let address = self.contract_address;
		let own_low = H256::from_slice(&own_id[0..32]);
		let own_high = H256::from_slice(&own_id[32..64]);
		let id_low = H256::from_slice(&connecting_id[0..32]);
		let id_high = H256::from_slice(&connecting_id[32..64]);

		let allowed = self.contract.functions()
			.call(own_low, own_high, id_low, id_high, &|data| client.call_contract(BlockId::Latest, address, data))
			.unwrap_or_else(|e| {
				debug!("Error callling peer set contract: {:?}", e);

		cache.insert(key, allowed);

mod test {
	use std::sync::{Arc, Weak};
	use ethcore::spec::Spec;
	use ethcore::client::{BlockChainClient, Client, ClientConfig};
	use ethcore::miner::Miner;
	use ethcore::test_helpers;
	use network::{ConnectionDirection, ConnectionFilter, NodeId};
	use io::IoChannel;
	use super::NodeFilter;

	/// Contract code:
	fn node_filter() {
		let contract_addr = "0000000000000000000000000000000000000005".into();
		let data = include_bytes!("../res/node_filter.json");
		let tempdir = TempDir::new("").unwrap();
		let spec = Spec::load(&tempdir.path(), &data[..]).unwrap();
		let client_db = test_helpers::new_db();

		let client = Client::new(
			Arc::new(Miner::new_for_tests(&spec, None)),
		let filter = NodeFilter::new(Arc::downgrade(&client) as Weak<BlockChainClient>, contract_addr);
		let self1: NodeId = "00000000000000000000000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000002".into();
		let self2: NodeId = "00000000000000000000000000000000000000000000000000000000000000020000000000000000000000000000000000000000000000000000000000000003".into();
		let node1: NodeId = "00000000000000000000000000000000000000000000000000000000000000110000000000000000000000000000000000000000000000000000000000000012".into();
		let node2: NodeId = "00000000000000000000000000000000000000000000000000000000000000210000000000000000000000000000000000000000000000000000000000000022".into();
		let nodex: NodeId = "77000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000".into();

		assert!(filter.connection_allowed(&self1, &node1, ConnectionDirection::Inbound));
		assert!(filter.connection_allowed(&self1, &nodex, ConnectionDirection::Inbound));
		assert!(filter.connection_allowed(&self2, &node1, ConnectionDirection::Inbound));
		assert!(filter.connection_allowed(&self2, &node2, ConnectionDirection::Inbound));