Files
sonr/x/dwn/client/plugin/config.go
T
40eadc995e Feat/1285 es ucan formatting (#1302)
* feat: Add Enclave Usage Examples

* feat(es/ucan): Add comprehensive integration tests

- Create integration.test.ts with full UCAN token lifecycle testing
- Cover end-to-end token creation, parsing, and validation
- Test capability attenuation and delegation chains
- Validate multi-algorithm support and timestamp scenarios
- Implement error recovery and performance test scenarios

🤖 Generated with Claude Code

Co-Authored-By: Claude <noreply@anthropic.com>

* No commit suggestions generated

* No commit suggestions generated

* chore: Remove migrated components and add migration documentation

Removed all code and references for components that have been moved to separate repositories:

**Moved to sonr-io/hway:**
- bridge/ - HTTP service with OAuth2/OIDC/WebAuthn handlers
- cmd/hway/ - Highway service binary
- internal/migrations/ - PostgreSQL schema migrations

**Moved to sonr-io/motr:**
- cmd/motr/ - Motor worker service (WASM vault operations)
- cmd/vault/ - Vault CLI tool
- crypto/ - Comprehensive cryptographic library
- packages/ - TypeScript SDK packages (es, sdk, ui, com, pkl)
- web/auth/ - Authentication web application
- web/dash/ - Dashboard web application

**Updated Configuration:**
- Makefile: Removed build/test/release targets for moved components
- CLAUDE.md: Simplified to focus on core blockchain components
- devbox.json: Removed scripts for moved services
- docker-compose.yml: Removed hway, postgres, redis, auth, dash services
- .github/scopes.yml: Removed CI scopes for migrated components
- .goreleaser.yml: Updated release configuration

**Added Migration Documentation:**
- MIGRATE_HWAY.md: Comprehensive Highway service architecture and migration guide
- MIGRATE_MOTR.md: Comprehensive Motor/Worker/Vault architecture and migration guide

These migration documents provide complete context for setting up the new repositories including architecture diagrams, component breakdowns, API documentation, and migration checklists.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* No commit suggestions generated

* chore: Remove contracts references and documentation

Removed all references to the contracts directory that was migrated to a separate repository.

**Changes:**
- .gitignore: Removed contract-specific ignore patterns for DAO and wSNR contracts
- .gitignore: Removed hway and motr binary references (already migrated)
- .rgignore: Removed contracts, chains, and crypto directory references
- docs/reference/contracts/: Removed DAO.mdx and wSNR.mdx documentation files

This completes the cleanup of migrated components from the repository.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* docs: add crypto library migration documentation

Added comprehensive migration documentation for the crypto library that was
moved to sonr-io/crypto repository. This documentation provides complete context
for understanding the cryptographic primitives and protocols used throughout
the Sonr ecosystem.

## Key Documentation Added

### MIGRATE_CRYPTO.md
Complete documentation of the crypto library covering:

**Core Cryptographic Primitives**
- Elliptic curve implementations (Ed25519, Secp256k1, P-256, BLS12-381, Pallas/Vesta)
- Native curve arithmetic with optimized field operations
- Pairing-friendly curves for BLS signatures

**Multi-Party Computation (MPC)**
- MPC enclave for vault key generation and management
- Threshold cryptography (TECDSA, TED25519 with FROST protocol)
- Distributed Key Generation (DKG) via Gennaro and FROST protocols
- Secret sharing schemes (Shamir, Feldman VSS, Pedersen VSS)

**Digital Signature Schemes**
- BLS signatures with aggregation support
- BBS+ signatures for selective disclosure
- Schnorr signatures (standard and Mina/NEM variants)
- ECDSA with deterministic nonce generation

**Zero-Knowledge Proofs**
- Bulletproofs for range proofs
- Inner Product Arguments (IPA)
- Batch verification support

**Advanced Cryptographic Protocols**
- Cryptographic accumulators for set membership proofs
- Paillier homomorphic encryption
- Oblivious Transfer (OT) protocols
- Verifiable Random Functions (VRF)

**Key Management & Identity**
- DID key management with multi-chain support
- Multi-algorithm public key handling
- Wallet address derivation (Bitcoin, Ethereum, Cosmos, Solana, etc.)

**UCAN Integration**
- User-Controlled Authorization Networks
- Capability delegation and attenuation
- JWT-based capability tokens
- MPC-enabled UCAN signing

**Security Utilities**
- AEAD encryption (AES-GCM, AES-SIV)
- Argon2 key derivation
- ECIES encryption
- Secure memory handling

### MIGRATE_MOTR.md Updates
Updated Motor migration documentation to clarify that the crypto library
is now a separate external dependency at github.com/sonr-io/crypto v1.0.1

## Repository Context

The crypto library has been successfully migrated to its own repository
and is published as a Go module. It serves as the foundational cryptographic
layer for:
- Sonr blockchain (snrd) - DID signatures, vault operations
- Highway service (hway) - UCAN token signing, WebAuthn
- Motor/Worker (motr) - MPC vault operations, threshold signatures

## Integration Impact

All Sonr ecosystem components now depend on the external crypto library:
```go
require github.com/sonr-io/crypto v1.0.1
```

The migration enables independent versioning and maintenance of cryptographic
primitives while maintaining security and compatibility across the ecosystem.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* No commit suggestions generated

* No commit suggestions generated

* No commit suggestions generated

---------

Co-authored-by: Claude <noreply@anthropic.com>
2025-10-10 11:47:18 -04:00

296 lines
8.9 KiB
Go

package plugin
import (
"encoding/json"
"fmt"
"time"
extism "github.com/extism/go-sdk"
"github.com/sonr-io/crypto/mpc"
)
// EnclaveConfig represents the MPC enclave configuration for the Motor plugin.
// This configuration is passed to the plugin via PDK environment variables.
type EnclaveConfig struct {
// ChainID specifies the blockchain network identifier (e.g., "sonr-testnet-1")
ChainID string `json:"chain_id" yaml:"chain_id"`
// EnclaveData contains the MPC enclave data with private key material
EnclaveData *mpc.EnclaveData `json:"enclave_data" yaml:"enclave_data"`
// VaultConfig provides additional vault configuration parameters
VaultConfig VaultConfig `json:"vault_config" yaml:"vault_config"`
// Security settings for plugin operations
Security SecurityConfig `json:"security" yaml:"security"`
// Timeout configurations for various operations
Timeouts TimeoutConfig `json:"timeouts" yaml:"timeouts"`
}
// VaultConfig specifies vault-specific configuration parameters.
type VaultConfig struct {
// IPFSEndpoint specifies the IPFS endpoint for vault operations
IPFSEndpoint string `json:"ipfs_endpoint" yaml:"ipfs_endpoint"`
// MaxVaultSize limits the maximum size of vault data in bytes
MaxVaultSize int64 `json:"max_vault_size" yaml:"max_vault_size"`
// EnableCompression enables compression for vault data
EnableCompression bool `json:"enable_compression" yaml:"enable_compression"`
// BackupEnabled enables automatic backup of vault data
BackupEnabled bool `json:"backup_enabled" yaml:"backup_enabled"`
// Custom metadata for vault operations
Metadata map[string]string `json:"metadata,omitempty" yaml:"metadata,omitempty"`
}
// SecurityConfig defines security parameters for plugin operations.
type SecurityConfig struct {
// RequiredAttestations specifies required security attestations
RequiredAttestations []string `json:"required_attestations" yaml:"required_attestations"`
// MaxTokenLifetime limits the maximum lifetime of generated tokens
MaxTokenLifetime time.Duration `json:"max_token_lifetime" yaml:"max_token_lifetime"`
// RequireAudience enforces audience validation for all tokens
RequireAudience bool `json:"require_audience" yaml:"require_audience"`
// AllowedOrigins specifies allowed origins for token delegation
AllowedOrigins []string `json:"allowed_origins" yaml:"allowed_origins"`
}
// TimeoutConfig specifies timeout values for various plugin operations.
type TimeoutConfig struct {
// TokenCreation timeout for UCAN token creation operations
TokenCreation time.Duration `json:"token_creation" yaml:"token_creation"`
// Signature timeout for cryptographic signing operations
Signature time.Duration `json:"signature" yaml:"signature"`
// Verification timeout for signature verification operations
Verification time.Duration `json:"verification" yaml:"verification"`
// PluginInit timeout for plugin initialization
PluginInit time.Duration `json:"plugin_init" yaml:"plugin_init"`
}
// DefaultEnclaveConfig returns a default enclave configuration with sensible defaults.
func DefaultEnclaveConfig() *EnclaveConfig {
return &EnclaveConfig{
ChainID: "sonr-testnet-1",
VaultConfig: VaultConfig{
IPFSEndpoint: "127.0.0.1:5001",
MaxVaultSize: 10 * 1024 * 1024, // 10MB
EnableCompression: true,
BackupEnabled: false,
Metadata: make(map[string]string),
},
Security: SecurityConfig{
RequiredAttestations: []string{},
MaxTokenLifetime: 24 * time.Hour,
RequireAudience: true,
AllowedOrigins: []string{"*"},
},
Timeouts: TimeoutConfig{
TokenCreation: 30 * time.Second,
Signature: 10 * time.Second,
Verification: 5 * time.Second,
PluginInit: 15 * time.Second,
},
}
}
// Validate checks that the enclave configuration is valid and complete.
func (c *EnclaveConfig) Validate() error {
if c.ChainID == "" {
return fmt.Errorf("chain_id is required")
}
if c.EnclaveData == nil {
return fmt.Errorf("enclave_data is required")
}
if !c.EnclaveData.IsValid() {
return fmt.Errorf("enclave_data is invalid")
}
// Validate vault configuration
if err := c.VaultConfig.Validate(); err != nil {
return fmt.Errorf("vault_config validation failed: %w", err)
}
// Validate security configuration
if err := c.Security.Validate(); err != nil {
return fmt.Errorf("security configuration validation failed: %w", err)
}
return nil
}
// ToManifestConfig converts the enclave configuration to Extism manifest config.
// This is used to pass configuration to the WASM plugin via environment variables.
func (c *EnclaveConfig) ToManifestConfig() (map[string]string, error) {
config := make(map[string]string)
// Add chain ID
config["chain_id"] = c.ChainID
// Serialize and add enclave data
if c.EnclaveData != nil {
enclaveBytes, err := json.Marshal(c.EnclaveData)
if err != nil {
return nil, fmt.Errorf("failed to marshal enclave data: %w", err)
}
config["enclave"] = string(enclaveBytes)
}
// Serialize and add vault configuration
vaultBytes, err := json.Marshal(c.VaultConfig)
if err != nil {
return nil, fmt.Errorf("failed to marshal vault config: %w", err)
}
config["vault_config"] = string(vaultBytes)
// Serialize and add security configuration
securityBytes, err := json.Marshal(c.Security)
if err != nil {
return nil, fmt.Errorf("failed to marshal security config: %w", err)
}
config["security_config"] = string(securityBytes)
// Serialize and add timeout configuration
timeoutBytes, err := json.Marshal(c.Timeouts)
if err != nil {
return nil, fmt.Errorf("failed to marshal timeout config: %w", err)
}
config["timeout_config"] = string(timeoutBytes)
return config, nil
}
// Validate checks that the vault configuration is valid.
func (v *VaultConfig) Validate() error {
if v.MaxVaultSize <= 0 {
return fmt.Errorf("max_vault_size must be positive")
}
if v.MaxVaultSize > 100*1024*1024 { // 100MB limit
return fmt.Errorf("max_vault_size exceeds maximum allowed (100MB)")
}
return nil
}
// Validate checks that the security configuration is valid.
func (s *SecurityConfig) Validate() error {
if s.MaxTokenLifetime <= 0 {
return fmt.Errorf("max_token_lifetime must be positive")
}
if s.MaxTokenLifetime > 30*24*time.Hour { // 30 days limit
return fmt.Errorf("max_token_lifetime exceeds maximum allowed (30 days)")
}
return nil
}
// LoaderConfig represents configuration for the plugin loader itself.
type LoaderConfig struct {
// EnableWASI enables WebAssembly System Interface for the plugin
EnableWASI bool
// MemoryLimit sets the maximum memory limit for the plugin in bytes
MemoryLimit uint32
// AllowHttpRequests enables HTTP requests from the plugin
AllowHttpRequests bool
// LogLevel sets the logging level for plugin operations
LogLevel string
// MaxConcurrentPlugins limits the number of concurrent plugin instances
MaxConcurrentPlugins int
}
// DefaultLoaderConfig returns a default loader configuration.
func DefaultLoaderConfig() *LoaderConfig {
return &LoaderConfig{
EnableWASI: true,
MemoryLimit: 64 * 1024 * 1024, // 64MB
AllowHttpRequests: false,
LogLevel: "info",
MaxConcurrentPlugins: 10,
}
}
// ToPluginConfig converts the loader configuration to Extism plugin config.
func (l *LoaderConfig) ToPluginConfig() extism.PluginConfig {
return extism.PluginConfig{
EnableWasi: l.EnableWASI,
}
}
// PluginState represents the runtime state of a plugin instance.
type PluginState struct {
// ID is the unique identifier for this plugin instance
ID string
// Config is the configuration used to create this plugin
Config *EnclaveConfig
// Plugin is the underlying Extism plugin instance
Plugin *extism.Plugin
// CreatedAt is the timestamp when the plugin was created
CreatedAt time.Time
// LastUsed is the timestamp of the last plugin operation
LastUsed time.Time
// IsHealthy indicates whether the plugin is in a healthy state
IsHealthy bool
// ErrorCount tracks the number of errors encountered
ErrorCount int
// MaxErrors is the maximum number of errors before marking unhealthy
MaxErrors int
}
// UpdateHealth updates the plugin health status based on operation result.
func (s *PluginState) UpdateHealth(err error) {
s.LastUsed = time.Now()
if err != nil {
s.ErrorCount++
if s.ErrorCount >= s.MaxErrors {
s.IsHealthy = false
}
} else {
// Reset error count on successful operation
s.ErrorCount = 0
s.IsHealthy = true
}
}
// IsExpired checks if the plugin instance should be considered expired.
func (s *PluginState) IsExpired(maxIdleTime time.Duration) bool {
return time.Since(s.LastUsed) > maxIdleTime
}
// NewPluginState creates a new plugin state with default values.
func NewPluginState(id string, config *EnclaveConfig, plugin *extism.Plugin) *PluginState {
return &PluginState{
ID: id,
Config: config,
Plugin: plugin,
CreatedAt: time.Now(),
LastUsed: time.Now(),
IsHealthy: true,
ErrorCount: 0,
MaxErrors: 5, // Allow up to 5 errors before marking as unhealthy
}
}