implement SignedPod (non-mock) using proof-based signatures (#160)
This commit is contained in:
parent
30f26a94ef
commit
d6033b7090
9 changed files with 259 additions and 60 deletions
|
|
@ -382,7 +382,7 @@ pub fn hash_statements(statements: &[Statement], _params: &Params) -> middleware
|
|||
}
|
||||
|
||||
impl Pod for MockMainPod {
|
||||
fn verify(&self) -> bool {
|
||||
fn verify(&self) -> Result<()> {
|
||||
// 1. TODO: Verify input pods
|
||||
|
||||
let input_statement_offset = self.offset_input_statements();
|
||||
|
|
@ -451,18 +451,20 @@ impl Pod for MockMainPod {
|
|||
.collect::<Result<Vec<_>>>()
|
||||
.unwrap();
|
||||
if !ids_match {
|
||||
error!("Verification failed: POD ID is incorrect.");
|
||||
return Err(anyhow!("Verification failed: POD ID is incorrect."));
|
||||
}
|
||||
if !has_type_statement {
|
||||
error!("Verification failed: POD does not have type statement.");
|
||||
return Err(anyhow!(
|
||||
"Verification failed: POD does not have type statement."
|
||||
));
|
||||
}
|
||||
if !value_ofs_unique {
|
||||
error!("Verification failed: Repeated ValueOf");
|
||||
return Err(anyhow!("Verification failed: Repeated ValueOf"));
|
||||
}
|
||||
if !statement_check.iter().all(|b| *b) {
|
||||
error!("Verification failed: Statement did not check.")
|
||||
return Err(anyhow!("Verification failed: Statement did not check."));
|
||||
}
|
||||
ids_match && has_type_statement && value_ofs_unique & statement_check.into_iter().all(|b| b)
|
||||
Ok(())
|
||||
}
|
||||
fn id(&self) -> PodId {
|
||||
self.id
|
||||
|
|
@ -539,9 +541,9 @@ pub mod tests {
|
|||
|
||||
println!("{:#}", pod);
|
||||
|
||||
assert!(pod.verify()); // TODO
|
||||
// println!("id: {}", pod.id());
|
||||
// println!("pub_statements: {:?}", pod.pub_statements());
|
||||
pod.verify()?; // TODO
|
||||
// println!("id: {}", pod.id());
|
||||
// println!("pub_statements: {:?}", pod.pub_statements());
|
||||
Ok(())
|
||||
}
|
||||
|
||||
|
|
@ -560,7 +562,7 @@ pub mod tests {
|
|||
|
||||
println!("{}", pod);
|
||||
|
||||
assert!(pod.verify());
|
||||
pod.verify()?;
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
|
@ -574,7 +576,7 @@ pub mod tests {
|
|||
let pod = proof_pod.pod.into_any().downcast::<MockMainPod>().unwrap();
|
||||
|
||||
println!("{}", pod);
|
||||
assert!(pod.verify());
|
||||
pod.verify()?;
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
|
|
|||
|
|
@ -1,4 +1,4 @@
|
|||
use anyhow::Result;
|
||||
use anyhow::{anyhow, Result};
|
||||
use std::any::Any;
|
||||
use std::collections::HashMap;
|
||||
|
||||
|
|
@ -55,44 +55,47 @@ impl MockSignedPod {
|
|||
}
|
||||
|
||||
impl Pod for MockSignedPod {
|
||||
fn verify(&self) -> bool {
|
||||
fn verify(&self) -> Result<()> {
|
||||
// 1. Verify type
|
||||
let value_at_type = match self.dict.get(&hash_str(KEY_TYPE).into()) {
|
||||
Ok(v) => v,
|
||||
Err(_) => return false,
|
||||
};
|
||||
let value_at_type = self.dict.get(&hash_str(KEY_TYPE).into())?;
|
||||
if Value::from(PodType::MockSigned) != value_at_type {
|
||||
return false;
|
||||
return Err(anyhow!(
|
||||
"type does not match, expected MockSigned ({}), found {}",
|
||||
PodType::MockSigned,
|
||||
value_at_type
|
||||
));
|
||||
}
|
||||
|
||||
// 2. Verify id
|
||||
let mt = match MerkleTree::new(
|
||||
let mt = MerkleTree::new(
|
||||
MAX_DEPTH,
|
||||
&self
|
||||
.dict
|
||||
.iter()
|
||||
.map(|(&k, &v)| (k, v))
|
||||
.collect::<HashMap<Value, Value>>(),
|
||||
) {
|
||||
Ok(mt) => mt,
|
||||
Err(_) => return false,
|
||||
};
|
||||
)?;
|
||||
let id = PodId(mt.root());
|
||||
if id != self.id {
|
||||
return false;
|
||||
return Err(anyhow!(
|
||||
"id does not match, expected {}, computed {}",
|
||||
self.id,
|
||||
id
|
||||
));
|
||||
}
|
||||
|
||||
// 3. Verify signature
|
||||
let pk_hash = match self.dict.get(&hash_str(KEY_SIGNER).into()) {
|
||||
Ok(v) => v,
|
||||
Err(_) => return false,
|
||||
};
|
||||
let pk_hash = self.dict.get(&hash_str(KEY_SIGNER).into())?;
|
||||
let signature = format!("{}_signed_by_{}", id, pk_hash);
|
||||
if signature != self.signature {
|
||||
return false;
|
||||
return Err(anyhow!(
|
||||
"signature does not match, expected {}, computed {}",
|
||||
self.id,
|
||||
id
|
||||
));
|
||||
}
|
||||
|
||||
true
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn id(&self) -> PodId {
|
||||
|
|
@ -138,17 +141,17 @@ pub mod tests {
|
|||
let pod = pod.sign(&mut signer).unwrap();
|
||||
let pod = pod.pod.into_any().downcast::<MockSignedPod>().unwrap();
|
||||
|
||||
assert!(pod.verify());
|
||||
pod.verify()?;
|
||||
println!("id: {}", pod.id());
|
||||
println!("kvs: {:?}", pod.kvs());
|
||||
|
||||
let mut bad_pod = pod.clone();
|
||||
bad_pod.signature = "".into();
|
||||
assert!(!bad_pod.verify());
|
||||
assert!(bad_pod.verify().is_err());
|
||||
|
||||
let mut bad_pod = pod.clone();
|
||||
bad_pod.id.0 .0[0] = F::ZERO;
|
||||
assert!(!bad_pod.verify());
|
||||
assert!(bad_pod.verify().is_err());
|
||||
|
||||
let mut bad_pod = pod.clone();
|
||||
let bad_kv = (hash_str(KEY_SIGNER).into(), Value(PodId(EMPTY_HASH).0 .0));
|
||||
|
|
@ -160,7 +163,7 @@ pub mod tests {
|
|||
.collect::<HashMap<Value, Value>>();
|
||||
let bad_mt = MerkleTree::new(MAX_DEPTH, bad_kvs_mt)?;
|
||||
bad_pod.dict.mt = bad_mt;
|
||||
assert!(!bad_pod.verify());
|
||||
assert!(bad_pod.verify().is_err());
|
||||
|
||||
let mut bad_pod = pod.clone();
|
||||
let bad_kv = (hash_str(KEY_TYPE).into(), Value::from(0));
|
||||
|
|
@ -172,7 +175,7 @@ pub mod tests {
|
|||
.collect::<HashMap<Value, Value>>();
|
||||
let bad_mt = MerkleTree::new(MAX_DEPTH, bad_kvs_mt)?;
|
||||
bad_pod.dict.mt = bad_mt;
|
||||
assert!(!bad_pod.verify());
|
||||
assert!(bad_pod.verify().is_err());
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue