mirror of
https://github.com/sonr-io/sonr.git
synced 2026-08-02 17:31:39 +00:00
* feat: Add Enclave Usage Examples * feat(es/ucan): Add comprehensive integration tests - Create integration.test.ts with full UCAN token lifecycle testing - Cover end-to-end token creation, parsing, and validation - Test capability attenuation and delegation chains - Validate multi-algorithm support and timestamp scenarios - Implement error recovery and performance test scenarios 🤖 Generated with Claude Code Co-Authored-By: Claude <noreply@anthropic.com> * No commit suggestions generated * No commit suggestions generated * chore: Remove migrated components and add migration documentation Removed all code and references for components that have been moved to separate repositories: **Moved to sonr-io/hway:** - bridge/ - HTTP service with OAuth2/OIDC/WebAuthn handlers - cmd/hway/ - Highway service binary - internal/migrations/ - PostgreSQL schema migrations **Moved to sonr-io/motr:** - cmd/motr/ - Motor worker service (WASM vault operations) - cmd/vault/ - Vault CLI tool - crypto/ - Comprehensive cryptographic library - packages/ - TypeScript SDK packages (es, sdk, ui, com, pkl) - web/auth/ - Authentication web application - web/dash/ - Dashboard web application **Updated Configuration:** - Makefile: Removed build/test/release targets for moved components - CLAUDE.md: Simplified to focus on core blockchain components - devbox.json: Removed scripts for moved services - docker-compose.yml: Removed hway, postgres, redis, auth, dash services - .github/scopes.yml: Removed CI scopes for migrated components - .goreleaser.yml: Updated release configuration **Added Migration Documentation:** - MIGRATE_HWAY.md: Comprehensive Highway service architecture and migration guide - MIGRATE_MOTR.md: Comprehensive Motor/Worker/Vault architecture and migration guide These migration documents provide complete context for setting up the new repositories including architecture diagrams, component breakdowns, API documentation, and migration checklists. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com> * No commit suggestions generated * chore: Remove contracts references and documentation Removed all references to the contracts directory that was migrated to a separate repository. **Changes:** - .gitignore: Removed contract-specific ignore patterns for DAO and wSNR contracts - .gitignore: Removed hway and motr binary references (already migrated) - .rgignore: Removed contracts, chains, and crypto directory references - docs/reference/contracts/: Removed DAO.mdx and wSNR.mdx documentation files This completes the cleanup of migrated components from the repository. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com> * docs: add crypto library migration documentation Added comprehensive migration documentation for the crypto library that was moved to sonr-io/crypto repository. This documentation provides complete context for understanding the cryptographic primitives and protocols used throughout the Sonr ecosystem. ## Key Documentation Added ### MIGRATE_CRYPTO.md Complete documentation of the crypto library covering: **Core Cryptographic Primitives** - Elliptic curve implementations (Ed25519, Secp256k1, P-256, BLS12-381, Pallas/Vesta) - Native curve arithmetic with optimized field operations - Pairing-friendly curves for BLS signatures **Multi-Party Computation (MPC)** - MPC enclave for vault key generation and management - Threshold cryptography (TECDSA, TED25519 with FROST protocol) - Distributed Key Generation (DKG) via Gennaro and FROST protocols - Secret sharing schemes (Shamir, Feldman VSS, Pedersen VSS) **Digital Signature Schemes** - BLS signatures with aggregation support - BBS+ signatures for selective disclosure - Schnorr signatures (standard and Mina/NEM variants) - ECDSA with deterministic nonce generation **Zero-Knowledge Proofs** - Bulletproofs for range proofs - Inner Product Arguments (IPA) - Batch verification support **Advanced Cryptographic Protocols** - Cryptographic accumulators for set membership proofs - Paillier homomorphic encryption - Oblivious Transfer (OT) protocols - Verifiable Random Functions (VRF) **Key Management & Identity** - DID key management with multi-chain support - Multi-algorithm public key handling - Wallet address derivation (Bitcoin, Ethereum, Cosmos, Solana, etc.) **UCAN Integration** - User-Controlled Authorization Networks - Capability delegation and attenuation - JWT-based capability tokens - MPC-enabled UCAN signing **Security Utilities** - AEAD encryption (AES-GCM, AES-SIV) - Argon2 key derivation - ECIES encryption - Secure memory handling ### MIGRATE_MOTR.md Updates Updated Motor migration documentation to clarify that the crypto library is now a separate external dependency at github.com/sonr-io/crypto v1.0.1 ## Repository Context The crypto library has been successfully migrated to its own repository and is published as a Go module. It serves as the foundational cryptographic layer for: - Sonr blockchain (snrd) - DID signatures, vault operations - Highway service (hway) - UCAN token signing, WebAuthn - Motor/Worker (motr) - MPC vault operations, threshold signatures ## Integration Impact All Sonr ecosystem components now depend on the external crypto library: ```go require github.com/sonr-io/crypto v1.0.1 ``` The migration enables independent versioning and maintenance of cryptographic primitives while maintaining security and compatibility across the ecosystem. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com> * No commit suggestions generated * No commit suggestions generated * No commit suggestions generated --------- Co-authored-by: Claude <noreply@anthropic.com>
296 lines
8.9 KiB
Go
296 lines
8.9 KiB
Go
package plugin
|
|
|
|
import (
|
|
"encoding/json"
|
|
"fmt"
|
|
"time"
|
|
|
|
extism "github.com/extism/go-sdk"
|
|
"github.com/sonr-io/crypto/mpc"
|
|
)
|
|
|
|
// EnclaveConfig represents the MPC enclave configuration for the Motor plugin.
|
|
// This configuration is passed to the plugin via PDK environment variables.
|
|
type EnclaveConfig struct {
|
|
// ChainID specifies the blockchain network identifier (e.g., "sonr-testnet-1")
|
|
ChainID string `json:"chain_id" yaml:"chain_id"`
|
|
|
|
// EnclaveData contains the MPC enclave data with private key material
|
|
EnclaveData *mpc.EnclaveData `json:"enclave_data" yaml:"enclave_data"`
|
|
|
|
// VaultConfig provides additional vault configuration parameters
|
|
VaultConfig VaultConfig `json:"vault_config" yaml:"vault_config"`
|
|
|
|
// Security settings for plugin operations
|
|
Security SecurityConfig `json:"security" yaml:"security"`
|
|
|
|
// Timeout configurations for various operations
|
|
Timeouts TimeoutConfig `json:"timeouts" yaml:"timeouts"`
|
|
}
|
|
|
|
// VaultConfig specifies vault-specific configuration parameters.
|
|
type VaultConfig struct {
|
|
// IPFSEndpoint specifies the IPFS endpoint for vault operations
|
|
IPFSEndpoint string `json:"ipfs_endpoint" yaml:"ipfs_endpoint"`
|
|
|
|
// MaxVaultSize limits the maximum size of vault data in bytes
|
|
MaxVaultSize int64 `json:"max_vault_size" yaml:"max_vault_size"`
|
|
|
|
// EnableCompression enables compression for vault data
|
|
EnableCompression bool `json:"enable_compression" yaml:"enable_compression"`
|
|
|
|
// BackupEnabled enables automatic backup of vault data
|
|
BackupEnabled bool `json:"backup_enabled" yaml:"backup_enabled"`
|
|
|
|
// Custom metadata for vault operations
|
|
Metadata map[string]string `json:"metadata,omitempty" yaml:"metadata,omitempty"`
|
|
}
|
|
|
|
// SecurityConfig defines security parameters for plugin operations.
|
|
type SecurityConfig struct {
|
|
// RequiredAttestations specifies required security attestations
|
|
RequiredAttestations []string `json:"required_attestations" yaml:"required_attestations"`
|
|
|
|
// MaxTokenLifetime limits the maximum lifetime of generated tokens
|
|
MaxTokenLifetime time.Duration `json:"max_token_lifetime" yaml:"max_token_lifetime"`
|
|
|
|
// RequireAudience enforces audience validation for all tokens
|
|
RequireAudience bool `json:"require_audience" yaml:"require_audience"`
|
|
|
|
// AllowedOrigins specifies allowed origins for token delegation
|
|
AllowedOrigins []string `json:"allowed_origins" yaml:"allowed_origins"`
|
|
}
|
|
|
|
// TimeoutConfig specifies timeout values for various plugin operations.
|
|
type TimeoutConfig struct {
|
|
// TokenCreation timeout for UCAN token creation operations
|
|
TokenCreation time.Duration `json:"token_creation" yaml:"token_creation"`
|
|
|
|
// Signature timeout for cryptographic signing operations
|
|
Signature time.Duration `json:"signature" yaml:"signature"`
|
|
|
|
// Verification timeout for signature verification operations
|
|
Verification time.Duration `json:"verification" yaml:"verification"`
|
|
|
|
// PluginInit timeout for plugin initialization
|
|
PluginInit time.Duration `json:"plugin_init" yaml:"plugin_init"`
|
|
}
|
|
|
|
// DefaultEnclaveConfig returns a default enclave configuration with sensible defaults.
|
|
func DefaultEnclaveConfig() *EnclaveConfig {
|
|
return &EnclaveConfig{
|
|
ChainID: "sonr-testnet-1",
|
|
VaultConfig: VaultConfig{
|
|
IPFSEndpoint: "127.0.0.1:5001",
|
|
MaxVaultSize: 10 * 1024 * 1024, // 10MB
|
|
EnableCompression: true,
|
|
BackupEnabled: false,
|
|
Metadata: make(map[string]string),
|
|
},
|
|
Security: SecurityConfig{
|
|
RequiredAttestations: []string{},
|
|
MaxTokenLifetime: 24 * time.Hour,
|
|
RequireAudience: true,
|
|
AllowedOrigins: []string{"*"},
|
|
},
|
|
Timeouts: TimeoutConfig{
|
|
TokenCreation: 30 * time.Second,
|
|
Signature: 10 * time.Second,
|
|
Verification: 5 * time.Second,
|
|
PluginInit: 15 * time.Second,
|
|
},
|
|
}
|
|
}
|
|
|
|
// Validate checks that the enclave configuration is valid and complete.
|
|
func (c *EnclaveConfig) Validate() error {
|
|
if c.ChainID == "" {
|
|
return fmt.Errorf("chain_id is required")
|
|
}
|
|
|
|
if c.EnclaveData == nil {
|
|
return fmt.Errorf("enclave_data is required")
|
|
}
|
|
|
|
if !c.EnclaveData.IsValid() {
|
|
return fmt.Errorf("enclave_data is invalid")
|
|
}
|
|
|
|
// Validate vault configuration
|
|
if err := c.VaultConfig.Validate(); err != nil {
|
|
return fmt.Errorf("vault_config validation failed: %w", err)
|
|
}
|
|
|
|
// Validate security configuration
|
|
if err := c.Security.Validate(); err != nil {
|
|
return fmt.Errorf("security configuration validation failed: %w", err)
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
// ToManifestConfig converts the enclave configuration to Extism manifest config.
|
|
// This is used to pass configuration to the WASM plugin via environment variables.
|
|
func (c *EnclaveConfig) ToManifestConfig() (map[string]string, error) {
|
|
config := make(map[string]string)
|
|
|
|
// Add chain ID
|
|
config["chain_id"] = c.ChainID
|
|
|
|
// Serialize and add enclave data
|
|
if c.EnclaveData != nil {
|
|
enclaveBytes, err := json.Marshal(c.EnclaveData)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to marshal enclave data: %w", err)
|
|
}
|
|
config["enclave"] = string(enclaveBytes)
|
|
}
|
|
|
|
// Serialize and add vault configuration
|
|
vaultBytes, err := json.Marshal(c.VaultConfig)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to marshal vault config: %w", err)
|
|
}
|
|
config["vault_config"] = string(vaultBytes)
|
|
|
|
// Serialize and add security configuration
|
|
securityBytes, err := json.Marshal(c.Security)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to marshal security config: %w", err)
|
|
}
|
|
config["security_config"] = string(securityBytes)
|
|
|
|
// Serialize and add timeout configuration
|
|
timeoutBytes, err := json.Marshal(c.Timeouts)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to marshal timeout config: %w", err)
|
|
}
|
|
config["timeout_config"] = string(timeoutBytes)
|
|
|
|
return config, nil
|
|
}
|
|
|
|
// Validate checks that the vault configuration is valid.
|
|
func (v *VaultConfig) Validate() error {
|
|
if v.MaxVaultSize <= 0 {
|
|
return fmt.Errorf("max_vault_size must be positive")
|
|
}
|
|
|
|
if v.MaxVaultSize > 100*1024*1024 { // 100MB limit
|
|
return fmt.Errorf("max_vault_size exceeds maximum allowed (100MB)")
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
// Validate checks that the security configuration is valid.
|
|
func (s *SecurityConfig) Validate() error {
|
|
if s.MaxTokenLifetime <= 0 {
|
|
return fmt.Errorf("max_token_lifetime must be positive")
|
|
}
|
|
|
|
if s.MaxTokenLifetime > 30*24*time.Hour { // 30 days limit
|
|
return fmt.Errorf("max_token_lifetime exceeds maximum allowed (30 days)")
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
// LoaderConfig represents configuration for the plugin loader itself.
|
|
type LoaderConfig struct {
|
|
// EnableWASI enables WebAssembly System Interface for the plugin
|
|
EnableWASI bool
|
|
|
|
// MemoryLimit sets the maximum memory limit for the plugin in bytes
|
|
MemoryLimit uint32
|
|
|
|
// AllowHttpRequests enables HTTP requests from the plugin
|
|
AllowHttpRequests bool
|
|
|
|
// LogLevel sets the logging level for plugin operations
|
|
LogLevel string
|
|
|
|
// MaxConcurrentPlugins limits the number of concurrent plugin instances
|
|
MaxConcurrentPlugins int
|
|
}
|
|
|
|
// DefaultLoaderConfig returns a default loader configuration.
|
|
func DefaultLoaderConfig() *LoaderConfig {
|
|
return &LoaderConfig{
|
|
EnableWASI: true,
|
|
MemoryLimit: 64 * 1024 * 1024, // 64MB
|
|
AllowHttpRequests: false,
|
|
LogLevel: "info",
|
|
MaxConcurrentPlugins: 10,
|
|
}
|
|
}
|
|
|
|
// ToPluginConfig converts the loader configuration to Extism plugin config.
|
|
func (l *LoaderConfig) ToPluginConfig() extism.PluginConfig {
|
|
return extism.PluginConfig{
|
|
EnableWasi: l.EnableWASI,
|
|
}
|
|
}
|
|
|
|
// PluginState represents the runtime state of a plugin instance.
|
|
type PluginState struct {
|
|
// ID is the unique identifier for this plugin instance
|
|
ID string
|
|
|
|
// Config is the configuration used to create this plugin
|
|
Config *EnclaveConfig
|
|
|
|
// Plugin is the underlying Extism plugin instance
|
|
Plugin *extism.Plugin
|
|
|
|
// CreatedAt is the timestamp when the plugin was created
|
|
CreatedAt time.Time
|
|
|
|
// LastUsed is the timestamp of the last plugin operation
|
|
LastUsed time.Time
|
|
|
|
// IsHealthy indicates whether the plugin is in a healthy state
|
|
IsHealthy bool
|
|
|
|
// ErrorCount tracks the number of errors encountered
|
|
ErrorCount int
|
|
|
|
// MaxErrors is the maximum number of errors before marking unhealthy
|
|
MaxErrors int
|
|
}
|
|
|
|
// UpdateHealth updates the plugin health status based on operation result.
|
|
func (s *PluginState) UpdateHealth(err error) {
|
|
s.LastUsed = time.Now()
|
|
|
|
if err != nil {
|
|
s.ErrorCount++
|
|
if s.ErrorCount >= s.MaxErrors {
|
|
s.IsHealthy = false
|
|
}
|
|
} else {
|
|
// Reset error count on successful operation
|
|
s.ErrorCount = 0
|
|
s.IsHealthy = true
|
|
}
|
|
}
|
|
|
|
// IsExpired checks if the plugin instance should be considered expired.
|
|
func (s *PluginState) IsExpired(maxIdleTime time.Duration) bool {
|
|
return time.Since(s.LastUsed) > maxIdleTime
|
|
}
|
|
|
|
// NewPluginState creates a new plugin state with default values.
|
|
func NewPluginState(id string, config *EnclaveConfig, plugin *extism.Plugin) *PluginState {
|
|
return &PluginState{
|
|
ID: id,
|
|
Config: config,
|
|
Plugin: plugin,
|
|
CreatedAt: time.Now(),
|
|
LastUsed: time.Now(),
|
|
IsHealthy: true,
|
|
ErrorCount: 0,
|
|
MaxErrors: 5, // Allow up to 5 errors before marking as unhealthy
|
|
}
|
|
}
|