diff --git a/.gitignore b/.gitignore index 4d7fe2b3dd..dbd166ae7d 100644 --- a/.gitignore +++ b/.gitignore @@ -73,7 +73,6 @@ scripts/tn_init.sh tests/plugin_test unittests/unit_test -tutorials/sig-em-tutorial/contracts doxygen wire.doxygen diff --git a/contracts/sysio.roa/sysio.roa.cpp b/contracts/sysio.roa/sysio.roa.cpp index 18f33656a4..2c5ae9266b 100644 --- a/contracts/sysio.roa/sysio.roa.cpp +++ b/contracts/sysio.roa/sysio.roa.cpp @@ -6,6 +6,8 @@ #include // add_sat_u64 / add_sat_i64 -- never-throw saturating accumulators #include // get_permission -- read an account's active authority in nodeownreg +#include + namespace sysio { namespace { @@ -14,6 +16,10 @@ namespace sysio { constexpr name AUTHEX_ACCOUNT = "sysio.authex"_n; constexpr name AUTHEX_RECORDLINK = "recordlink"_n; + /// Names under this prefix belong to system accounts. The chain refuses them only to non-privileged + /// creators, and sysio.roa is privileged, so node-owner claims must refuse them here. + constexpr std::string_view RESERVED_SYSTEM_NAME_PREFIX = "sysio."; + /// Maximum number of generated account names checked before newuser gives up. constexpr uint32_t MAX_ACCOUNT_NAME_ATTEMPTS{100}; @@ -817,6 +823,7 @@ namespace sysio { } bool roa::valid_name_for_tier(const name& account, uint8_t tier) { + if (account.to_string().rfind(RESERVED_SYSTEM_NAME_PREFIX, 0) == 0) return false; const size_t len = account.length(); // Tier-1 owners take a short 2-6 char prefix (sub-accounts become .); // tier 2/3 take a 1-12 char vanity name. diff --git a/contracts/sysio.roa/sysio.roa.hpp b/contracts/sysio.roa/sysio.roa.hpp index 93b0f14118..c060ad34b7 100644 --- a/contracts/sysio.roa/sysio.roa.hpp +++ b/contracts/sysio.roa/sysio.roa.hpp @@ -373,7 +373,7 @@ namespace sysio { // to migrate.) enum reject_reason : uint8_t { NONE = 0, // not rejected - NAME_INVALID = 1, // chosen account name violates the tier's length rule + NAME_INVALID = 1, // chosen name violates the tier's length rule or is a reserved sysio. name OWNER_NOT_ACCOUNT = 2, // account does not exist (creation did not occur) ACCOUNT_KEY_MISMATCH = 3, // existing account's active authority != the single claimed wire key DUPLICATE = 4, // owner is already a registered node owner @@ -488,14 +488,15 @@ namespace sysio { uint8_t network_gen); /** - * @brief Whether `account`'s name satisfies the node-owner name-length rule for `tier`. + * @brief Whether `account`'s name satisfies the node-owner naming rules for `tier`. * Tier-1 owners take a short 2-6 char prefix (sub-accounts become .); - * tier 2/3 take a 1-12 char vanity name. Shared by newnameduser (gates creation) and - * nodeownreg (records NAME_INVALID) so the rule lives in one place. + * tier 2/3 take a 1-12 char vanity name, and no tier may take a name under the reserved + * `sysio.` prefix. Shared by newnameduser (gates creation) and nodeownreg (records + * NAME_INVALID) so the rule lives in one place. * * @param account The chosen account name. * @param tier Node-owner tier (must already be validated to 1-3). - * @return true if the name length is valid for the tier. + * @return true if the name is valid for the tier. */ static bool valid_name_for_tier(const name& account, uint8_t tier); diff --git a/contracts/sysio.roa/sysio.roa.wasm b/contracts/sysio.roa/sysio.roa.wasm index 9dd9979dd0..cc20763d1c 100755 Binary files a/contracts/sysio.roa/sysio.roa.wasm and b/contracts/sysio.roa/sysio.roa.wasm differ diff --git a/contracts/sysio.system/include/sysio.system/sysio.system.hpp b/contracts/sysio.system/include/sysio.system/sysio.system.hpp index 16fd17f5fb..ce18ec5dad 100644 --- a/contracts/sysio.system/include/sysio.system/sysio.system.hpp +++ b/contracts/sysio.system/include/sysio.system/sysio.system.hpp @@ -624,12 +624,6 @@ namespace sysiosystem { [[sysio::action]] void limitauthchg( const name& account, const std::vector& allow_perms, const std::vector& disallow_perms ); - /** - * On Link Auth notify to catch auth.ext stuff for sig-em - */ - [[sysio::on_notify("auth.msg::onlinkauth")]] - void onlinkauth(const name &user, const name &permission, const sysio::public_key &pub_key); - /** * Rescore a producer whose collateral standing just changed on sysio.opreg. * diff --git a/contracts/sysio.system/src/sysio.system.cpp b/contracts/sysio.system/src/sysio.system.cpp index aa50223792..440219ba29 100644 --- a/contracts/sysio.system/src/sysio.system.cpp +++ b/contracts/sysio.system/src/sysio.system.cpp @@ -268,17 +268,4 @@ namespace sysiosystem { check(core == symbol("SYS", 4), "core symbol must be SYS."); } - - // ** ON NOTIFY OF AUTH.MSG MODIFICATION ** - void system_contract::onlinkauth(const name& account_name, const name& permission, const sysio::public_key& pub_key) { - // Convert pub_key to authority object - authority auth; - auth.threshold = 1; - - auth.keys.push_back({pub_key, 1}); - - // Update auth with special permission. - updateauth_action update_auth{ get_self(), { {get_self(), active_permission} } }; - update_auth.send(account_name, permission, name("owner"), auth, name("")); - } } /// sysio.system diff --git a/contracts/sysio.system/sysio.system.wasm b/contracts/sysio.system/sysio.system.wasm index 42ff23131a..c2799df03c 100755 Binary files a/contracts/sysio.system/sysio.system.wasm and b/contracts/sysio.system/sysio.system.wasm differ diff --git a/contracts/tests/contract_test_support.hpp b/contracts/tests/contract_test_support.hpp index 05637c0cda..7f89f085cb 100644 --- a/contracts/tests/contract_test_support.hpp +++ b/contracts/tests/contract_test_support.hpp @@ -117,4 +117,15 @@ inline fc::mutable_variant_object svm_outpost_mvo(std::string_view program_id) { ("source_deposit_addr", std::string{}); } +/// Mirrors of sysio.roa's `nodeownerreg` audit values (`reg_status` / `reject_reason` in sysio.roa.hpp). +namespace nodeownerreg { +inline constexpr uint64_t status_confirmed = 0; +inline constexpr uint64_t status_rejected = 1; +inline constexpr uint64_t reason_name_invalid = 1; +inline constexpr uint64_t reason_owner_not_account = 2; +inline constexpr uint64_t reason_account_key_mismatch = 3; +inline constexpr uint64_t reason_duplicate = 4; +inline constexpr uint64_t reason_link_key_mismatch = 5; +} // namespace nodeownerreg + } // namespace sysio_system::test_support diff --git a/contracts/tests/sysio.dispatch_tests.cpp b/contracts/tests/sysio.dispatch_tests.cpp index 1b6d72e458..b4ecb5b45b 100644 --- a/contracts/tests/sysio.dispatch_tests.cpp +++ b/contracts/tests/sysio.dispatch_tests.cpp @@ -14,6 +14,7 @@ #include #include #include +#include #include // kv_index / by_code_key for reading sysio.roa kv tables #include #include @@ -38,9 +39,12 @@ #include #include #include +#include +#include #include "contracts.hpp" #include "contract_test_support.hpp" +#include "test_symbol.hpp" // Canonical-encoding + header-derivation oracle: inbound envelopes must carry // spec-derived semantic headers or apply_consensus drops them before dispatch. #include "opp_envelope_oracle.hpp" @@ -330,6 +334,14 @@ std::string encode_swap_request( } // anonymous namespace +/// Wire layout of an `auth.msg::onlinkauth` action, the payload sysio.system once acted on. +struct onlinkauth_notification { + name user; + name permission; + public_key_type pub_key; +}; +FC_REFLECT(onlinkauth_notification, (user)(permission)(pub_key)) + class sysio_dispatch_tester : public tester { public: static constexpr auto MSGCH_ACCOUNT = "sysio.msgch"_n; @@ -1951,7 +1963,7 @@ BOOST_FIXTURE_TEST_CASE(dispatch_routes_node_owner_reg_to_roa, sysio_dispatch_te BOOST_REQUIRE_EQUAL(reg["tier"].as(), 2u); auto audit = get_nodeownerreg(CLAIM_ACCOUNT); BOOST_REQUIRE(!audit.is_null()); - BOOST_REQUIRE_EQUAL(audit["status"].as(), 0u); // CONFIRMED + BOOST_REQUIRE_EQUAL(audit["status"].as(), sysio_system::test_support::nodeownerreg::status_confirmed); } FC_LOG_AND_RETHROW() } // WSA-005: node-owner registration is bound to the EXACT Ethereum source outpost (NODE_OWNER_SRC_CHAIN @@ -2015,6 +2027,161 @@ BOOST_FIXTURE_TEST_CASE(node_owner_reg_from_non_evm_outpost_is_dropped, sysio_di BOOST_REQUIRE(get_nodeownerreg(CLAIM_ACCOUNT).is_null()); } FC_LOG_AND_RETHROW() } +/// Node-owner claims on a chain running sysio.system. A tier-2/3 claim lets the NFT holder pick any valid 1-12 char +/// name and control the account created for it; these cases pin what that control must not reach. +class node_owner_claim_tester : public sysio_dispatch_tester { +public: + static constexpr auto NODE_OWNER_SOURCE_CHAIN = "ETHEREUM"; + static constexpr uint32_t CLAIM_TIER = 2; + static constexpr auto AUTH_MSG_ACCOUNT = "auth.msg"_n; + static constexpr auto ONLINKAUTH_ACTION = "onlinkauth"_n; + static constexpr auto AUTH_EXT_PERMISSION = "auth.ext"_n; + static constexpr auto OTHER_PERMISSION = "session"_n; + static constexpr auto RESERVED_SYSTEM_NAME = "sysio.pwn"_n; + static constexpr auto PAYER_ACCOUNT = "payer"_n; + /// Never created; only names the key a notification offers. + static constexpr auto REPLACEMENT_KEY_NAME = "replacement"_n; + static constexpr auto SYSTEM_INIT_ACTION = "init"_n; + static constexpr auto ADDPOLICY_ACTION = "addpolicy"_n; + static constexpr auto SELF_POLICY_WEIGHT = "0.1000 SYS"; + + /// Parent and authority of each of an account's permissions, keyed by permission name. + using permission_set = std::map>; + + /// Deploy and initialize sysio.system; the base dispatch fixture runs without it. + void deploy_system_contract() { + set_code(config::system_account_name, contracts::system_wasm()); + set_abi(config::system_account_name, contracts::system_abi().data()); + produce_block(); + base_tester::push_action(config::system_account_name, SYSTEM_INIT_ACTION, config::system_account_name, + mvo()("version", 0)("core", CORE_SYM_STR)); + produce_block(); + } + + /// Deliver a NodeOwnerRegistration for `account` through the Ethereum outpost, as BAR.commitNode emits it. + void claim_node_owner(name account, const public_key_type& wire_key) { + const auto eth_key = fc::crypto::private_key::generate(fc::crypto::private_key::key_type::em).get_public_key(); + const auto payload = encode_node_owner_registration(account.to_string(), CLAIM_TIER, + sysio::opp::types::WIRE_KEY_TYPE_K1, + k1_pubkey_bytes(wire_key), em_pubkey_bytes(eth_key)); + const auto envelope = encode_envelope_with_one_attestation( + current_epoch(), sysio::opp::types::ATTESTATION_TYPE_NODE_OWNER_REG, payload); + BOOST_REQUIRE_EQUAL(success(), deliver(fc::slug_name{NODE_OWNER_SOURCE_CHAIN}.value, envelope)); + produce_blocks(2); + } + + /// The claimant issues a policy to itself from its tier budget; PAYER_ACCOUNT pays for the transaction. + void issue_own_policy(name owner) { + signed_transaction trx; + trx.actions.emplace_back(get_action(config::roa_account_name, ADDPOLICY_ACTION, + vector{{PAYER_ACCOUNT, config::sysio_payer_name}, {PAYER_ACCOUNT, config::active_name}, + {owner, config::active_name}}, + mvo()("owner", owner)("issuer", owner)("net_weight", SELF_POLICY_WEIGHT)("cpu_weight", SELF_POLICY_WEIGHT) + ("ram_weight", SELF_POLICY_WEIGHT)("time_block", 0)("network_gen", ROA_NETWORK_GEN))); + set_transaction_headers(trx); + trx.sign(get_private_key(PAYER_ACCOUNT, "active"), control->get_chain_id()); + trx.sign(get_private_key(owner, "active"), control->get_chain_id()); + push_transaction(trx); + produce_block(); + } + + /// Code a claimant can deploy on its account: it forwards every action it receives to sysio as a notification. + static std::vector notify_system_account_wasm() { + std::ostringstream wast; + wast << R"((module + (import "env" "require_recipient" (func $require_recipient (param i64))) + (func (export "apply") (param i64 i64 i64) + (call $require_recipient (i64.const 0x)" + << std::hex << config::system_account_name.to_uint64_t() << R"()) + ) + ))"; + return wast_to_wasm(wast.str()); + } + + /// Push auth.msg::onlinkauth as auth.msg; true when the transaction committed and the notification reached sysio. + bool notify_onlinkauth(name user, name permission, const public_key_type& key) { + signed_transaction trx; + trx.actions.emplace_back(vector{{AUTH_MSG_ACCOUNT, config::active_name}}, AUTH_MSG_ACCOUNT, + ONLINKAUTH_ACTION, fc::raw::pack(onlinkauth_notification{user, permission, key})); + set_transaction_headers(trx); + trx.sign(get_private_key(AUTH_MSG_ACCOUNT, "active"), control->get_chain_id()); + bool delivered = false; + try { + const auto trace = push_transaction(trx); + delivered = std::ranges::any_of(trace->action_traces, [](const action_trace& at) { + return at.receiver == config::system_account_name && at.act.name == ONLINKAUTH_ACTION; + }); + } catch (const fc::exception&) { + delivered = false; + } + produce_block(); + return delivered; + } + + /// Native newaccount creates only the account_object; metadata appears once code, abi or privilege is set. + bool account_exists(name account) const { + return control->db().find(account) != nullptr; + } + + /// Every permission of `account`, for before/after comparison. + permission_set permissions_of(name account) const { + permission_set out; + const auto& db = control->db(); + const auto& idx = db.get_index(); + for (auto it = idx.lower_bound(boost::make_tuple(account)); it != idx.end() && it->owner == account; ++it) { + const name parent = it->parent._id == 0 ? name{} : db.get(it->parent).name; + out.emplace(it->name, std::make_pair(parent, it->auth.to_authority())); + } + return out; + } +}; + +// A tier-2/3 claim can take the name auth.msg and deploy code there, so an auth.msg::onlinkauth notification is +// attacker-controlled. It must reach sysio as an ordinary notification and change nothing: not sysio's owner, active, +// auth.ext or any other permission, and not a user's. +BOOST_FIXTURE_TEST_CASE(claimed_auth_msg_notification_changes_no_permission, node_owner_claim_tester) { try { + bootstrap_for_dispatch(NODE_OWNER_SOURCE_CHAIN); + create_account(PAYER_ACCOUNT); + deploy_system_contract(); + + claim_node_owner(AUTH_MSG_ACCOUNT, get_public_key(AUTH_MSG_ACCOUNT, "active")); + const auto audit = get_nodeownerreg(AUTH_MSG_ACCOUNT); + BOOST_REQUIRE(!audit.is_null()); + BOOST_REQUIRE_EQUAL(audit["status"].as(), sysio_system::test_support::nodeownerreg::status_confirmed); + issue_own_policy(AUTH_MSG_ACCOUNT); + set_code(AUTH_MSG_ACCOUNT, notify_system_account_wasm()); + produce_block(); + + const auto replacement_key = get_public_key(REPLACEMENT_KEY_NAME, "active"); + const auto sysio_before = permissions_of(config::system_account_name); + const auto user_before = permissions_of(CLAIM_ACCOUNT); + for (const auto target : {config::system_account_name, CLAIM_ACCOUNT}) { + for (const auto permission : {config::owner_name, config::active_name, AUTH_EXT_PERMISSION, OTHER_PERMISSION}) { + BOOST_CHECK_MESSAGE(notify_onlinkauth(target, permission, replacement_key), + "onlinkauth for " << target.to_string() << "@" << permission.to_string() + << " did not commit as a plain notification"); + } + } + BOOST_CHECK_MESSAGE(permissions_of(config::system_account_name) == sysio_before, "sysio permissions changed"); + BOOST_CHECK_MESSAGE(permissions_of(CLAIM_ACCOUNT) == user_before, "claimacct permissions changed"); +} FC_LOG_AND_RETHROW() } + +// No node owner may claim a name under the reserved sysio. prefix: the depot's claim is rejected as NAME_INVALID and +// no account is created. +BOOST_FIXTURE_TEST_CASE(node_owner_claim_rejects_reserved_system_name, node_owner_claim_tester) { try { + bootstrap_for_dispatch(NODE_OWNER_SOURCE_CHAIN); + deploy_system_contract(); + + claim_node_owner(RESERVED_SYSTEM_NAME, get_public_key(RESERVED_SYSTEM_NAME, "active")); + + const auto audit = get_nodeownerreg(RESERVED_SYSTEM_NAME); + BOOST_REQUIRE(!audit.is_null()); + BOOST_CHECK_EQUAL(audit["status"].as(), sysio_system::test_support::nodeownerreg::status_rejected); + BOOST_CHECK_EQUAL(audit["reason"].as(), sysio_system::test_support::nodeownerreg::reason_name_invalid); + BOOST_CHECK(get_nodeowner(RESERVED_SYSTEM_NAME).is_null()); + BOOST_CHECK(!account_exists(RESERVED_SYSTEM_NAME)); +} FC_LOG_AND_RETHROW() } + /// Regression: a non-advancing advance() must not permanently strand the epoch. /// /// When every active outpost has reached consensus and the wall clock has passed, chkcons triggers diff --git a/contracts/tests/sysio.roa_tests.cpp b/contracts/tests/sysio.roa_tests.cpp index fa127aadc5..790a108d06 100644 --- a/contracts/tests/sysio.roa_tests.cpp +++ b/contracts/tests/sysio.roa_tests.cpp @@ -6,6 +6,7 @@ #include #include #include "sysio.system_tester.hpp" +#include "contract_test_support.hpp" #include #include #include @@ -2119,6 +2120,9 @@ BOOST_FIXTURE_TEST_CASE( newnameduser_tier_name_rules, sysio_roa_tester ) try { // sysio.authex.active <- sysio.roa@sysio.code delegation that authorizes the inline recordlink. // --------------------------------------------------------------------------- +/// Shared mirrors of sysio.roa's node-owner registration audit values. +namespace nodeownerreg_audit = sysio_system::test_support::nodeownerreg; + class sysio_roa_nodeownreg_tester : public sysio_roa_tester { public: static constexpr auto AUTHEX = "sysio.authex"_n; @@ -2183,10 +2187,14 @@ class sysio_roa_nodeownreg_tester : public sysio_roa_tester { return fc::crypto::private_key::generate(fc::crypto::private_key::key_type::k1).get_public_key(); } - // nodeownerreg reg_status + reject_reason values (mirror sysio.roa.hpp). - static constexpr uint64_t CONFIRMED = 0, REJECTED = 1; - static constexpr uint64_t R_NAME_INVALID = 1, R_OWNER_NOT_ACCOUNT = 2, - R_ACCOUNT_KEY_MISMATCH = 3, R_DUPLICATE = 4, R_LINK_KEY_MISMATCH = 5; + // nodeownerreg reg_status + reject_reason values, shared with the depot dispatch tests. + static constexpr uint64_t CONFIRMED = nodeownerreg_audit::status_confirmed; + static constexpr uint64_t REJECTED = nodeownerreg_audit::status_rejected; + static constexpr uint64_t R_NAME_INVALID = nodeownerreg_audit::reason_name_invalid; + static constexpr uint64_t R_OWNER_NOT_ACCOUNT = nodeownerreg_audit::reason_owner_not_account; + static constexpr uint64_t R_ACCOUNT_KEY_MISMATCH = nodeownerreg_audit::reason_account_key_mismatch; + static constexpr uint64_t R_DUPLICATE = nodeownerreg_audit::reason_duplicate; + static constexpr uint64_t R_LINK_KEY_MISMATCH = nodeownerreg_audit::reason_link_key_mismatch; abi_serializer authex_abi_ser; }; @@ -2488,6 +2496,33 @@ BOOST_FIXTURE_TEST_CASE( nodeownreg_name_invalid, sysio_roa_nodeownreg_tester ) BOOST_REQUIRE_EQUAL(audit["reason"].as(), R_NAME_INVALID); } FC_LOG_AND_RETHROW() +// No tier may claim a name under the reserved sysio. prefix, however deep: newnameduser creates nothing (sysio's RAM +// pool is untouched) and nodeownreg records REJECTED/NAME_INVALID. +BOOST_FIXTURE_TEST_CASE( nodeownreg_rejects_reserved_system_names, sysio_roa_nodeownreg_tester ) try { + constexpr auto tier2_name = "sysio.pwn"_n; + constexpr auto nested_name = "sysio.a.b"_n; // prefix() is "sysio.a": the rule must match the leading segment + constexpr uint8_t tier2 = 2, tier3 = 3; + auto& rlm = control->get_resource_limits_manager(); + const auto wire_pub = gen_k1_key(); + + for (const auto& [owner, tier] : {std::pair{tier2_name, tier2}, std::pair{nested_name, tier3}}) { + int64_t net = 0, cpu = 0, pool_before = 0, pool_after = 0; + rlm.get_account_limits(config::system_account_name, pool_before, net, cpu); + BOOST_REQUIRE_EQUAL(success(), newnameduser(owner, wire_pub, tier)); + produce_blocks(); + rlm.get_account_limits(config::system_account_name, pool_after, net, cpu); + BOOST_CHECK_EQUAL(pool_before, pool_after); + + BOOST_REQUIRE_EQUAL(success(), nodeownreg(owner, tier, gen_em_key(), wire_pub)); + produce_blocks(); + BOOST_CHECK(get_nodeowner(owner).is_null()); + const auto audit = get_nodeownerreg(owner); + BOOST_REQUIRE(!audit.is_null()); + BOOST_CHECK_EQUAL(audit["status"].as(), REJECTED); + BOOST_CHECK_EQUAL(audit["reason"].as(), R_NAME_INVALID); + } +} FC_LOG_AND_RETHROW() + // Valid-for-tier name that is not an account -> REJECTED/OWNER_NOT_ACCOUNT. BOOST_FIXTURE_TEST_CASE( nodeownreg_owner_not_account, sysio_roa_nodeownreg_tester ) try { const auto owner = "ghost"_n; // 5 chars: valid for tier 1, but no account was created diff --git a/tutorials/sig-em-tutorial/clone-repos.sh b/tutorials/sig-em-tutorial/clone-repos.sh deleted file mode 100755 index 4ef2381f24..0000000000 --- a/tutorials/sig-em-tutorial/clone-repos.sh +++ /dev/null @@ -1,8 +0,0 @@ -#!/bin/bash - -mkdir contracts && cd contracts - -git clone https://gitea.gitgo.app/Wire/auth.msg -git clone https://gitea.gitgo.app/Wire/settle.wns - -cd .. \ No newline at end of file diff --git a/tutorials/sig-em-tutorial/prepare-sig-em.sh b/tutorials/sig-em-tutorial/prepare-sig-em.sh deleted file mode 100755 index bd70e9005e..0000000000 --- a/tutorials/sig-em-tutorial/prepare-sig-em.sh +++ /dev/null @@ -1,45 +0,0 @@ -#!/bin/bash - -# Issue tokens -clio -u http://0.0.0.0:8000 push action sysio.token issue '[ "sysio", "1000000000.0000 SYS", "Issue" ]' -p sysio@active - -# Create accounts -clio wallet import --private-key 5JJPh8dLzbz1XYnGoUaCr3LQDj9aWeA52sqGQgqgarYKYpYzsbY -clio -u http://0.0.0.0:8000 system newaccount sysio settle.wns SYS5bVXRvVGsAfDWCQ1v5m5JRx42AAy6HtskiBpYXxedW8wxGeShb SYS5bVXRvVGsAfDWCQ1v5m5JRx42AAy6HtskiBpYXxedW8wxGeShb --stake-net '1000.0000 SYS' --stake-cpu '1000.0000 SYS' --buy-ram-kbytes 2048 -clio -u http://0.0.0.0:8000 system newaccount sysio auth.msg SYS5bVXRvVGsAfDWCQ1v5m5JRx42AAy6HtskiBpYXxedW8wxGeShb SYS5bVXRvVGsAfDWCQ1v5m5JRx42AAy6HtskiBpYXxedW8wxGeShb --stake-net '1000.0000 SYS' --stake-cpu '1000.0000 SYS' --buy-ram-kbytes 2048 - -# Compile and deploy auth.msg contract -cd contracts/auth.msg -# source ./build.sh -source ./deploy.sh - -# Compile and deploy settle.wns contract -cd ../settle.wns -# source ./build.sh -source ./deploy.sh - -# Allow auth.msg to add auth.ext permissions on accounts -clio -u http://0.0.0.0:8000 push action sysio updateauth '{ "account": "auth.msg", "permission": "owner", "parent": "", "auth": { "threshold": 1, - "keys": [{ - "key": "PUB_K1_5bVXRvVGsAfDWCQ1v5m5JRx42AAy6HtskiBpYXxedW8wwJWhhS", - "weight": 1 - }], "accounts": [{ "permission": { "actor": "auth.msg", "permission": "sysio.code" }, "weight": 1 }], "waits": []}}' -p auth.msg@owner - -# Init settle contract -clio -u http://0.0.0.0:8000 push action settle.wns initcontract '[]' -p settle.wns@active - -# HELPERS - -# clio -u http://0.0.0.0:8000 system newaccount sysio ikdfsdhpun.x PUB_EM_8exffEtJ8SsyG5kiwAPwACqLf29ygzbtxoqBFdWTrWB6qxCYGE PUB_EM_8exffEtJ8SsyG5kiwAPwACqLf29ygzbtxoqBFdWTrWB6qxCYGE --stake-net '100.0000 SYS' --stake-cpu '100.0000 SYS' --buy-ram-kbytes 1024 -# clio -u http://0.0.0.0:8000 system newaccount sysio qhzesdrkcdls PUB_EM_6hx8XEjettHeTg2W2vaw66577g1mwDg2oz4mtkpfx54UqEM99C PUB_EM_6hx8XEjettHeTg2W2vaw66577g1mwDg2oz4mtkpfx54UqEM99C --stake-net '100.0000 SYS' --stake-cpu '100.0000 SYS' --buy-ram-kbytes 1024 -# clio -u http://0.0.0.0:8000 system newaccount sysio .pbqcja3oeej PUB_EM_6iPWEcH1tgQTjPNCRYfrVBx2MhGv4onomyfybupcUmW5LBHQqt PUB_EM_6iPWEcH1tgQTjPNCRYfrVBx2MhGv4onomyfybupcUmW5LBHQqt --stake-net '100.0000 SYS' --stake-cpu '100.0000 SYS' --buy-ram-kbytes 1024 - - -# clio -u http://0.0.0.0:8000 system delegatebw sysio settle.wns "100.0000 SYS" "100.0000 SYS" -p sysio@active -# clio -u http://0.0.0.0:8000 system delegatebw sysio auth.msg "40.0000 SYS" "40.0000 SYS" -p sysio@active -# clio -u http://0.0.0.0:8000 system delegatebw sysio ikdfsdhpun.x "100.0000 SYS" "100.0000 SYS" -p sysio@active - -# clio -u http://0.0.0.0:8000 system buyram sysio settle.wns "100.0000 SYS" -p sysio@active -# clio -u http://0.0.0.0:8000 system buyram sysio auth.msg "100.0000 SYS" -p sysio@active - -# clio -u http://0.0.0.0:8000 system buyram sysio ikdfsdhpun.x "10.0000 SYS" -p sysio@active \ No newline at end of file diff --git a/tutorials/sig-em-tutorial/unlock.sh b/tutorials/sig-em-tutorial/unlock.sh deleted file mode 100755 index 86135837f4..0000000000 --- a/tutorials/sig-em-tutorial/unlock.sh +++ /dev/null @@ -1,7 +0,0 @@ -#!/bin/bash - -# Read the password from the wallet.pass file -PASSWORD=$(cat ../bios-boot-tutorial/wallet.pwd) - -# Use the password to unlock the wallet -clio wallet unlock --password "$PASSWORD" \ No newline at end of file