node.go 28 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819
  1. package guardiand
  2. import (
  3. "context"
  4. "encoding/base64"
  5. "encoding/hex"
  6. "fmt"
  7. "github.com/certusone/wormhole/node/pkg/db"
  8. "github.com/certusone/wormhole/node/pkg/notify/discord"
  9. "github.com/certusone/wormhole/node/pkg/telemetry"
  10. "github.com/certusone/wormhole/node/pkg/version"
  11. "github.com/gagliardetto/solana-go/rpc"
  12. "go.uber.org/zap/zapcore"
  13. "log"
  14. "net/http"
  15. _ "net/http/pprof"
  16. "os"
  17. "path"
  18. "strings"
  19. solana_types "github.com/gagliardetto/solana-go"
  20. "github.com/gorilla/mux"
  21. "github.com/prometheus/client_golang/prometheus/promhttp"
  22. "github.com/certusone/wormhole/node/pkg/common"
  23. "github.com/certusone/wormhole/node/pkg/devnet"
  24. "github.com/certusone/wormhole/node/pkg/ethereum"
  25. "github.com/certusone/wormhole/node/pkg/p2p"
  26. "github.com/certusone/wormhole/node/pkg/processor"
  27. gossipv1 "github.com/certusone/wormhole/node/pkg/proto/gossip/v1"
  28. "github.com/certusone/wormhole/node/pkg/readiness"
  29. "github.com/certusone/wormhole/node/pkg/reporter"
  30. solana "github.com/certusone/wormhole/node/pkg/solana"
  31. "github.com/certusone/wormhole/node/pkg/supervisor"
  32. "github.com/certusone/wormhole/node/pkg/vaa"
  33. eth_common "github.com/ethereum/go-ethereum/common"
  34. ethcrypto "github.com/ethereum/go-ethereum/crypto"
  35. "github.com/libp2p/go-libp2p-core/crypto"
  36. "github.com/libp2p/go-libp2p-core/peer"
  37. "github.com/spf13/cobra"
  38. "go.uber.org/zap"
  39. "github.com/certusone/wormhole/node/pkg/terra"
  40. "github.com/certusone/wormhole/node/pkg/algorand"
  41. ipfslog "github.com/ipfs/go-log/v2"
  42. )
  43. var (
  44. p2pNetworkID *string
  45. p2pPort *uint
  46. p2pBootstrap *string
  47. nodeKeyPath *string
  48. adminSocketPath *string
  49. dataDir *string
  50. statusAddr *string
  51. guardianKeyPath *string
  52. solanaContract *string
  53. ethRPC *string
  54. ethContract *string
  55. bscRPC *string
  56. bscContract *string
  57. polygonRPC *string
  58. polygonContract *string
  59. ethRopstenRPC *string
  60. ethRopstenContract *string
  61. fantomRPC *string
  62. fantomContract *string
  63. avalancheRPC *string
  64. avalancheContract *string
  65. oasisRPC *string
  66. oasisContract *string
  67. terraWS *string
  68. terraLCD *string
  69. terraContract *string
  70. algorandRPC *string
  71. algorandToken *string
  72. algorandContract *string
  73. solanaWsRPC *string
  74. solanaRPC *string
  75. logLevel *string
  76. unsafeDevMode *bool
  77. testnetMode *bool
  78. devNumGuardians *uint
  79. nodeName *string
  80. publicRPC *string
  81. publicWeb *string
  82. tlsHostname *string
  83. tlsProdEnv *bool
  84. disableHeartbeatVerify *bool
  85. disableTelemetry *bool
  86. telemetryKey *string
  87. discordToken *string
  88. discordChannel *string
  89. bigTablePersistenceEnabled *bool
  90. bigTableGCPProject *string
  91. bigTableInstanceName *string
  92. bigTableTableName *string
  93. bigTableTopicName *string
  94. bigTableKeyPath *string
  95. )
  96. func init() {
  97. p2pNetworkID = NodeCmd.Flags().String("network", "/wormhole/dev", "P2P network identifier")
  98. p2pPort = NodeCmd.Flags().Uint("port", 8999, "P2P UDP listener port")
  99. p2pBootstrap = NodeCmd.Flags().String("bootstrap", "", "P2P bootstrap peers (comma-separated)")
  100. statusAddr = NodeCmd.Flags().String("statusAddr", "[::]:6060", "Listen address for status server (disabled if blank)")
  101. nodeKeyPath = NodeCmd.Flags().String("nodeKey", "", "Path to node key (will be generated if it doesn't exist)")
  102. adminSocketPath = NodeCmd.Flags().String("adminSocket", "", "Admin gRPC service UNIX domain socket path")
  103. dataDir = NodeCmd.Flags().String("dataDir", "", "Data directory")
  104. guardianKeyPath = NodeCmd.Flags().String("guardianKey", "", "Path to guardian key (required)")
  105. solanaContract = NodeCmd.Flags().String("solanaContract", "", "Address of the Solana program (required)")
  106. ethRPC = NodeCmd.Flags().String("ethRPC", "", "Ethereum RPC URL")
  107. ethContract = NodeCmd.Flags().String("ethContract", "", "Ethereum contract address")
  108. bscRPC = NodeCmd.Flags().String("bscRPC", "", "Binance Smart Chain RPC URL")
  109. bscContract = NodeCmd.Flags().String("bscContract", "", "Binance Smart Chain contract address")
  110. polygonRPC = NodeCmd.Flags().String("polygonRPC", "", "Polygon RPC URL")
  111. polygonContract = NodeCmd.Flags().String("polygonContract", "", "Polygon contract address")
  112. ethRopstenRPC = NodeCmd.Flags().String("ethRopstenRPC", "", "Ethereum Ropsten RPC URL")
  113. ethRopstenContract = NodeCmd.Flags().String("ethRopstenContract", "", "Ethereum Ropsten contract address")
  114. avalancheRPC = NodeCmd.Flags().String("avalancheRPC", "", "Avalanche RPC URL")
  115. avalancheContract = NodeCmd.Flags().String("avalancheContract", "", "Avalanche contract address")
  116. oasisRPC = NodeCmd.Flags().String("oasisRPC", "", "Oasis RPC URL")
  117. oasisContract = NodeCmd.Flags().String("oasisContract", "", "Oasis contract address")
  118. fantomRPC = NodeCmd.Flags().String("fantomRPC", "", "Fantom Websocket RPC URL")
  119. fantomContract = NodeCmd.Flags().String("fantomContract", "", "Fantom contract address")
  120. terraWS = NodeCmd.Flags().String("terraWS", "", "Path to terrad root for websocket connection")
  121. terraLCD = NodeCmd.Flags().String("terraLCD", "", "Path to LCD service root for http calls")
  122. terraContract = NodeCmd.Flags().String("terraContract", "", "Wormhole contract address on Terra blockchain")
  123. algorandRPC = NodeCmd.Flags().String("algorandRPC", "", "Algorand RPC URL")
  124. algorandToken = NodeCmd.Flags().String("algorandToken", "", "Algorand access token")
  125. algorandContract = NodeCmd.Flags().String("algorandContract", "", "Algorand contract")
  126. solanaWsRPC = NodeCmd.Flags().String("solanaWS", "", "Solana Websocket URL (required")
  127. solanaRPC = NodeCmd.Flags().String("solanaRPC", "", "Solana RPC URL (required")
  128. logLevel = NodeCmd.Flags().String("logLevel", "info", "Logging level (debug, info, warn, error, dpanic, panic, fatal)")
  129. unsafeDevMode = NodeCmd.Flags().Bool("unsafeDevMode", false, "Launch node in unsafe, deterministic devnet mode")
  130. testnetMode = NodeCmd.Flags().Bool("testnetMode", false, "Launch node in testnet mode (enables testnet-only features like Ropsten)")
  131. devNumGuardians = NodeCmd.Flags().Uint("devNumGuardians", 5, "Number of devnet guardians to include in guardian set")
  132. nodeName = NodeCmd.Flags().String("nodeName", "", "Node name to announce in gossip heartbeats")
  133. publicRPC = NodeCmd.Flags().String("publicRPC", "", "Listen address for public gRPC interface")
  134. publicWeb = NodeCmd.Flags().String("publicWeb", "", "Listen address for public REST and gRPC Web interface")
  135. tlsHostname = NodeCmd.Flags().String("tlsHostname", "", "If set, serve publicWeb as TLS with this hostname using Let's Encrypt")
  136. tlsProdEnv = NodeCmd.Flags().Bool("tlsProdEnv", false,
  137. "Use the production Let's Encrypt environment instead of staging")
  138. disableHeartbeatVerify = NodeCmd.Flags().Bool("disableHeartbeatVerify", false,
  139. "Disable heartbeat signature verification (useful during network startup)")
  140. disableTelemetry = NodeCmd.Flags().Bool("disableTelemetry", false,
  141. "Disable telemetry")
  142. telemetryKey = NodeCmd.Flags().String("telemetryKey", "",
  143. "Telemetry write key")
  144. discordToken = NodeCmd.Flags().String("discordToken", "", "Discord bot token (optional)")
  145. discordChannel = NodeCmd.Flags().String("discordChannel", "", "Discord channel name (optional)")
  146. bigTablePersistenceEnabled = NodeCmd.Flags().Bool("bigTablePersistenceEnabled", false, "Turn on forwarding events to BigTable")
  147. bigTableGCPProject = NodeCmd.Flags().String("bigTableGCPProject", "", "Google Cloud project ID for storing events")
  148. bigTableInstanceName = NodeCmd.Flags().String("bigTableInstanceName", "", "BigTable instance name for storing events")
  149. bigTableTableName = NodeCmd.Flags().String("bigTableTableName", "", "BigTable table name to store events in")
  150. bigTableTopicName = NodeCmd.Flags().String("bigTableTopicName", "", "GCP topic name to publish to")
  151. bigTableKeyPath = NodeCmd.Flags().String("bigTableKeyPath", "", "Path to json Service Account key")
  152. }
  153. var (
  154. rootCtx context.Context
  155. rootCtxCancel context.CancelFunc
  156. )
  157. // "Why would anyone do this?" are famous last words.
  158. //
  159. // We already forcibly override RPC URLs and keys in dev mode to prevent security
  160. // risks from operator error, but an extra warning won't hurt.
  161. const devwarning = `
  162. +++++++++++++++++++++++++++++++++++++++++++++++++++
  163. | NODE IS RUNNING IN INSECURE DEVELOPMENT MODE |
  164. | |
  165. | Do not use -unsafeDevMode in prod. |
  166. +++++++++++++++++++++++++++++++++++++++++++++++++++
  167. `
  168. // NodeCmd represents the node command
  169. var NodeCmd = &cobra.Command{
  170. Use: "node",
  171. Short: "Run the guardiand node",
  172. Run: runNode,
  173. }
  174. func runNode(cmd *cobra.Command, args []string) {
  175. if *unsafeDevMode {
  176. fmt.Print(devwarning)
  177. }
  178. common.LockMemory()
  179. common.SetRestrictiveUmask()
  180. // Refuse to run as root in production mode.
  181. if !*unsafeDevMode && os.Geteuid() == 0 {
  182. fmt.Println("can't run as uid 0")
  183. os.Exit(1)
  184. }
  185. // Set up logging. The go-log zap wrapper that libp2p uses is compatible with our
  186. // usage of zap in supervisor, which is nice.
  187. lvl, err := ipfslog.LevelFromString(*logLevel)
  188. if err != nil {
  189. fmt.Println("Invalid log level")
  190. os.Exit(1)
  191. }
  192. logger := zap.New(zapcore.NewCore(
  193. consoleEncoder{zapcore.NewConsoleEncoder(
  194. zap.NewDevelopmentEncoderConfig())},
  195. zapcore.AddSync(zapcore.Lock(os.Stderr)),
  196. zap.NewAtomicLevelAt(zapcore.Level(lvl))))
  197. if *unsafeDevMode {
  198. // Use the hostname as nodeName. For production, we don't want to do this to
  199. // prevent accidentally leaking sensitive hostnames.
  200. hostname, err := os.Hostname()
  201. if err != nil {
  202. panic(err)
  203. }
  204. *nodeName = hostname
  205. // Put node name into the log for development.
  206. logger = logger.Named(*nodeName)
  207. }
  208. // Override the default go-log config, which uses a magic environment variable.
  209. ipfslog.SetAllLoggers(lvl)
  210. // Register components for readiness checks.
  211. readiness.RegisterComponent(common.ReadinessEthSyncing)
  212. readiness.RegisterComponent(common.ReadinessSolanaSyncing)
  213. readiness.RegisterComponent(common.ReadinessTerraSyncing)
  214. if *unsafeDevMode {
  215. readiness.RegisterComponent(common.ReadinessAlgorandSyncing)
  216. }
  217. readiness.RegisterComponent(common.ReadinessBSCSyncing)
  218. readiness.RegisterComponent(common.ReadinessPolygonSyncing)
  219. readiness.RegisterComponent(common.ReadinessAvalancheSyncing)
  220. readiness.RegisterComponent(common.ReadinessOasisSyncing)
  221. if *testnetMode {
  222. readiness.RegisterComponent(common.ReadinessEthRopstenSyncing)
  223. readiness.RegisterComponent(common.ReadinessFantomSyncing)
  224. }
  225. if *statusAddr != "" {
  226. // Use a custom routing instead of using http.DefaultServeMux directly to avoid accidentally exposing packages
  227. // that register themselves with it by default (like pprof).
  228. router := mux.NewRouter()
  229. // pprof server. NOT necessarily safe to expose publicly - only enable it in dev mode to avoid exposing it by
  230. // accident. There's benefit to having pprof enabled on production nodes, but we would likely want to expose it
  231. // via a dedicated port listening on localhost, or via the admin UNIX socket.
  232. if *unsafeDevMode {
  233. // Pass requests to http.DefaultServeMux, which pprof automatically registers with as an import side-effect.
  234. router.PathPrefix("/debug/pprof/").Handler(http.DefaultServeMux)
  235. }
  236. // Simple endpoint exposing node readiness (safe to expose to untrusted clients)
  237. router.HandleFunc("/readyz", readiness.Handler)
  238. // Prometheus metrics (safe to expose to untrusted clients)
  239. router.Handle("/metrics", promhttp.Handler())
  240. go func() {
  241. logger.Info("status server listening on [::]:6060")
  242. logger.Error("status server crashed", zap.Error(http.ListenAndServe(*statusAddr, router)))
  243. }()
  244. }
  245. // In devnet mode, we automatically set a number of flags that rely on deterministic keys.
  246. if *unsafeDevMode {
  247. g0key, err := peer.IDFromPrivateKey(devnet.DeterministicP2PPrivKeyByIndex(0))
  248. if err != nil {
  249. panic(err)
  250. }
  251. // Use the first guardian node as bootstrap
  252. *p2pBootstrap = fmt.Sprintf("/dns4/guardian-0.guardian/udp/%d/quic/p2p/%s", *p2pPort, g0key.String())
  253. // Deterministic ganache ETH devnet address.
  254. *ethContract = devnet.GanacheWormholeContractAddress.Hex()
  255. *bscContract = devnet.GanacheWormholeContractAddress.Hex()
  256. *polygonContract = devnet.GanacheWormholeContractAddress.Hex()
  257. *avalancheContract = devnet.GanacheWormholeContractAddress.Hex()
  258. *oasisContract = devnet.GanacheWormholeContractAddress.Hex()
  259. *fantomContract = devnet.GanacheWormholeContractAddress.Hex()
  260. }
  261. // Verify flags
  262. if *nodeKeyPath == "" && !*unsafeDevMode { // In devnet mode, keys are deterministically generated.
  263. logger.Fatal("Please specify --nodeKey")
  264. }
  265. if *guardianKeyPath == "" {
  266. logger.Fatal("Please specify --guardianKey")
  267. }
  268. if *adminSocketPath == "" {
  269. logger.Fatal("Please specify --adminSocket")
  270. }
  271. if *dataDir == "" {
  272. logger.Fatal("Please specify --dataDir")
  273. }
  274. if *ethRPC == "" {
  275. logger.Fatal("Please specify --ethRPC")
  276. }
  277. if *ethContract == "" {
  278. logger.Fatal("Please specify --ethContract")
  279. }
  280. if *bscRPC == "" {
  281. logger.Fatal("Please specify --bscRPC")
  282. }
  283. if *bscContract == "" {
  284. logger.Fatal("Please specify --bscContract")
  285. }
  286. if *polygonRPC == "" {
  287. logger.Fatal("Please specify --polygonRPC")
  288. }
  289. if *polygonContract == "" {
  290. logger.Fatal("Please specify --polygonContract")
  291. }
  292. if *avalancheRPC == "" {
  293. logger.Fatal("Please specify --avalancheRPC")
  294. }
  295. if *oasisRPC == "" {
  296. logger.Fatal("Please specify --oasisRPC")
  297. }
  298. if *fantomRPC == "" {
  299. logger.Fatal("Please specify --fantomRPC")
  300. }
  301. if *fantomContract == "" && !*unsafeDevMode {
  302. logger.Fatal("Please specify --fantomContract")
  303. }
  304. if *testnetMode {
  305. if *ethRopstenRPC == "" {
  306. logger.Fatal("Please specify --ethRopstenRPC")
  307. }
  308. if *ethRopstenContract == "" {
  309. logger.Fatal("Please specify --ethRopstenContract")
  310. }
  311. } else {
  312. if *ethRopstenRPC != "" {
  313. logger.Fatal("Please do not specify --ethRopstenRPC in non-testnet mode")
  314. }
  315. if *ethRopstenContract != "" {
  316. logger.Fatal("Please do not specify --ethRopstenContract in non-testnet mode")
  317. }
  318. }
  319. if *nodeName == "" {
  320. logger.Fatal("Please specify --nodeName")
  321. }
  322. if *solanaContract == "" {
  323. logger.Fatal("Please specify --solanaContract")
  324. }
  325. if *solanaWsRPC == "" {
  326. logger.Fatal("Please specify --solanaWsUrl")
  327. }
  328. if *solanaRPC == "" {
  329. logger.Fatal("Please specify --solanaUrl")
  330. }
  331. if *terraWS == "" {
  332. logger.Fatal("Please specify --terraWS")
  333. }
  334. if *terraLCD == "" {
  335. logger.Fatal("Please specify --terraLCD")
  336. }
  337. if *terraContract == "" {
  338. logger.Fatal("Please specify --terraContract")
  339. }
  340. if *unsafeDevMode {
  341. if *algorandRPC == "" {
  342. logger.Fatal("Please specify --algorandRPC")
  343. }
  344. if *algorandToken == "" {
  345. logger.Fatal("Please specify --algorandToken")
  346. }
  347. if *algorandContract == "" {
  348. logger.Fatal("Please specify --algorandContract")
  349. }
  350. }
  351. if *bigTablePersistenceEnabled {
  352. if *bigTableGCPProject == "" {
  353. logger.Fatal("Please specify --bigTableGCPProject")
  354. }
  355. if *bigTableInstanceName == "" {
  356. logger.Fatal("Please specify --bigTableInstanceName")
  357. }
  358. if *bigTableTableName == "" {
  359. logger.Fatal("Please specify --bigTableTableName")
  360. }
  361. if *bigTableTopicName == "" {
  362. logger.Fatal("Please specify --bigTableTopicName")
  363. }
  364. if *bigTableKeyPath == "" {
  365. logger.Fatal("Please specify --bigTableKeyPath")
  366. }
  367. }
  368. // Complain about Infura on mainnet.
  369. //
  370. // As it turns out, Infura has a bug where it would sometimes incorrectly round
  371. // block timestamps, which causes consensus issues - the timestamp is part of
  372. // the VAA and nodes using Infura would sometimes derive an incorrect VAA,
  373. // accidentally attacking the network by signing a conflicting VAA.
  374. //
  375. // Node operators do not usually rely on Infura in the first place - doing
  376. // so is insecure, since nodes blindly trust the connected nodes to verify
  377. // on-chain message proofs. However, node operators sometimes used
  378. // Infura during migrations where their primary node was offline, causing
  379. // the aforementioned consensus oddities which were eventually found to
  380. // be Infura-related. This is generally to the detriment of network security
  381. // and a judgement call made by individual operators. In the case of Infura,
  382. // we know it's actively dangerous so let's make an opinionated argument.
  383. //
  384. // Insert "I'm a sign, not a cop" meme.
  385. //
  386. if strings.Contains(*ethRPC, "mainnet.infura.io") ||
  387. strings.Contains(*polygonRPC, "polygon-mainnet.infura.io") {
  388. logger.Fatal("Infura is known to send incorrect blocks - please use your own nodes")
  389. }
  390. ethContractAddr := eth_common.HexToAddress(*ethContract)
  391. bscContractAddr := eth_common.HexToAddress(*bscContract)
  392. polygonContractAddr := eth_common.HexToAddress(*polygonContract)
  393. ethRopstenContractAddr := eth_common.HexToAddress(*ethRopstenContract)
  394. avalancheContractAddr := eth_common.HexToAddress(*avalancheContract)
  395. oasisContractAddr := eth_common.HexToAddress(*oasisContract)
  396. fantomContractAddr := eth_common.HexToAddress(*fantomContract)
  397. solAddress, err := solana_types.PublicKeyFromBase58(*solanaContract)
  398. if err != nil {
  399. logger.Fatal("invalid Solana contract address", zap.Error(err))
  400. }
  401. // In devnet mode, we generate a deterministic guardian key and write it to disk.
  402. if *unsafeDevMode {
  403. gk, err := generateDevnetGuardianKey()
  404. if err != nil {
  405. logger.Fatal("failed to generate devnet guardian key", zap.Error(err))
  406. }
  407. err = writeGuardianKey(gk, "auto-generated deterministic devnet key", *guardianKeyPath, true)
  408. if err != nil {
  409. logger.Fatal("failed to write devnet guardian key", zap.Error(err))
  410. }
  411. }
  412. // Database
  413. dbPath := path.Join(*dataDir, "db")
  414. if err := os.MkdirAll(dbPath, 0700); err != nil {
  415. logger.Fatal("failed to create database directory", zap.Error(err))
  416. }
  417. db, err := db.Open(dbPath)
  418. if err != nil {
  419. logger.Fatal("failed to open database", zap.Error(err))
  420. }
  421. defer db.Close()
  422. // Guardian key
  423. gk, err := loadGuardianKey(*guardianKeyPath)
  424. if err != nil {
  425. logger.Fatal("failed to load guardian key", zap.Error(err))
  426. }
  427. guardianAddr := ethcrypto.PubkeyToAddress(gk.PublicKey).String()
  428. logger.Info("Loaded guardian key", zap.String(
  429. "address", guardianAddr))
  430. p2p.DefaultRegistry.SetGuardianAddress(guardianAddr)
  431. // Node's main lifecycle context.
  432. rootCtx, rootCtxCancel = context.WithCancel(context.Background())
  433. defer rootCtxCancel()
  434. // Ethereum lock event channel
  435. lockC := make(chan *common.MessagePublication)
  436. // Ethereum incoming guardian set updates
  437. setC := make(chan *common.GuardianSet)
  438. // Outbound gossip message queue
  439. sendC := make(chan []byte)
  440. // Inbound observations
  441. obsvC := make(chan *gossipv1.SignedObservation, 50)
  442. // Inbound signed VAAs
  443. signedInC := make(chan *gossipv1.SignedVAAWithQuorum, 50)
  444. // Inbound observation requests from the p2p service (for all chains)
  445. obsvReqC := make(chan *gossipv1.ObservationRequest, 50)
  446. // Outbound observation requests
  447. obsvReqSendC := make(chan *gossipv1.ObservationRequest)
  448. // Injected VAAs (manually generated rather than created via observation)
  449. injectC := make(chan *vaa.VAA)
  450. // Guardian set state managed by processor
  451. gst := common.NewGuardianSetState()
  452. // Per-chain observation requests
  453. chainObsvReqC := make(map[vaa.ChainID]chan *gossipv1.ObservationRequest)
  454. // Observation request channel for each chain supporting observation requests.
  455. chainObsvReqC[vaa.ChainIDSolana] = make(chan *gossipv1.ObservationRequest)
  456. chainObsvReqC[vaa.ChainIDEthereum] = make(chan *gossipv1.ObservationRequest)
  457. chainObsvReqC[vaa.ChainIDTerra] = make(chan *gossipv1.ObservationRequest)
  458. chainObsvReqC[vaa.ChainIDBSC] = make(chan *gossipv1.ObservationRequest)
  459. chainObsvReqC[vaa.ChainIDPolygon] = make(chan *gossipv1.ObservationRequest)
  460. chainObsvReqC[vaa.ChainIDAvalanche] = make(chan *gossipv1.ObservationRequest)
  461. chainObsvReqC[vaa.ChainIDOasis] = make(chan *gossipv1.ObservationRequest)
  462. if *testnetMode {
  463. chainObsvReqC[vaa.ChainIDFantom] = make(chan *gossipv1.ObservationRequest)
  464. chainObsvReqC[vaa.ChainIDEthereumRopsten] = make(chan *gossipv1.ObservationRequest)
  465. }
  466. // Multiplex observation requests to the appropriate chain
  467. go func() {
  468. for {
  469. select {
  470. case <-rootCtx.Done():
  471. return
  472. case req := <-obsvReqC:
  473. if channel, ok := chainObsvReqC[vaa.ChainID(req.ChainId)]; ok {
  474. channel <- req
  475. } else {
  476. logger.Error("unknown chain ID for reobservation request",
  477. zap.Uint32("chain_id", req.ChainId),
  478. zap.String("tx_hash", hex.EncodeToString(req.TxHash)))
  479. }
  480. }
  481. }
  482. }()
  483. var notifier *discord.DiscordNotifier
  484. if *discordToken != "" {
  485. notifier, err = discord.NewDiscordNotifier(*discordToken, *discordChannel, logger)
  486. if err != nil {
  487. logger.Error("failed to initialize Discord bot", zap.Error(err))
  488. }
  489. }
  490. // Load p2p private key
  491. var priv crypto.PrivKey
  492. if *unsafeDevMode {
  493. idx, err := devnet.GetDevnetIndex()
  494. if err != nil {
  495. logger.Fatal("Failed to parse hostname - are we running in devnet?")
  496. }
  497. priv = devnet.DeterministicP2PPrivKeyByIndex(int64(idx))
  498. } else {
  499. priv, err = common.GetOrCreateNodeKey(logger, *nodeKeyPath)
  500. if err != nil {
  501. logger.Fatal("Failed to load node key", zap.Error(err))
  502. }
  503. }
  504. // Enable unless it is disabled. For devnet, only when --telemetryKey is set.
  505. if !*disableTelemetry && (!*unsafeDevMode || *unsafeDevMode && *telemetryKey != "") {
  506. logger.Info("Telemetry enabled")
  507. if *telemetryKey == "" {
  508. logger.Fatal("Please specify --telemetryKey")
  509. }
  510. creds, err := decryptTelemetryServiceAccount()
  511. if err != nil {
  512. logger.Fatal("Failed to decrypt telemetry service account", zap.Error(err))
  513. }
  514. // Get libp2p peer ID from private key
  515. pk := priv.GetPublic()
  516. peerID, err := peer.IDFromPublicKey(pk)
  517. if err != nil {
  518. logger.Fatal("Failed to get peer ID from private key", zap.Error(err))
  519. }
  520. tm, err := telemetry.New(context.Background(), telemetryProject, creds, map[string]string{
  521. "node_name": *nodeName,
  522. "node_key": peerID.Pretty(),
  523. "guardian_addr": guardianAddr,
  524. "network": *p2pNetworkID,
  525. "version": version.Version(),
  526. })
  527. if err != nil {
  528. logger.Fatal("Failed to initialize telemetry", zap.Error(err))
  529. }
  530. defer tm.Close()
  531. logger = tm.WrapLogger(logger)
  532. } else {
  533. logger.Info("Telemetry disabled")
  534. }
  535. // Redirect ipfs logs to plain zap
  536. ipfslog.SetPrimaryCore(logger.Core())
  537. // provides methods for reporting progress toward message attestation, and channels for receiving attestation lifecyclye events.
  538. attestationEvents := reporter.EventListener(logger)
  539. publicrpcService, publicrpcServer, err := publicrpcServiceRunnable(logger, *publicRPC, db, gst)
  540. if err != nil {
  541. log.Fatal("failed to create publicrpc service socket", zap.Error(err))
  542. }
  543. // local admin service socket
  544. adminService, err := adminServiceRunnable(logger, *adminSocketPath, injectC, signedInC, obsvReqSendC, db, gst)
  545. if err != nil {
  546. logger.Fatal("failed to create admin service socket", zap.Error(err))
  547. }
  548. publicwebService, err := publicwebServiceRunnable(logger, *publicWeb, *adminSocketPath, publicrpcServer,
  549. *tlsHostname, *tlsProdEnv, path.Join(*dataDir, "autocert"))
  550. if err != nil {
  551. log.Fatal("failed to create publicrpc service socket", zap.Error(err))
  552. }
  553. // Run supervisor.
  554. supervisor.New(rootCtx, logger, func(ctx context.Context) error {
  555. if err := supervisor.Run(ctx, "p2p", p2p.Run(
  556. obsvC, obsvReqC, obsvReqSendC, sendC, signedInC, priv, gk, gst, *p2pPort, *p2pNetworkID, *p2pBootstrap, *nodeName, *disableHeartbeatVerify, rootCtxCancel)); err != nil {
  557. return err
  558. }
  559. if err := supervisor.Run(ctx, "ethwatch",
  560. ethereum.NewEthWatcher(*ethRPC, ethContractAddr, "eth", common.ReadinessEthSyncing, vaa.ChainIDEthereum, lockC, setC, 1, chainObsvReqC[vaa.ChainIDEthereum]).Run); err != nil {
  561. return err
  562. }
  563. if err := supervisor.Run(ctx, "bscwatch",
  564. ethereum.NewEthWatcher(*bscRPC, bscContractAddr, "bsc", common.ReadinessBSCSyncing, vaa.ChainIDBSC, lockC, nil, 1, chainObsvReqC[vaa.ChainIDBSC]).Run); err != nil {
  565. return err
  566. }
  567. if err := supervisor.Run(ctx, "polygonwatch",
  568. ethereum.NewEthWatcher(*polygonRPC, polygonContractAddr, "polygon", common.ReadinessPolygonSyncing, vaa.ChainIDPolygon, lockC, nil, 512, chainObsvReqC[vaa.ChainIDPolygon]).Run); err != nil {
  569. // Special case: Polygon can fork like PoW Ethereum, and it's not clear what the safe number of blocks is
  570. //
  571. // Hardcode the minimum number of confirmations to 512 regardless of what the smart contract specifies to protect
  572. // developers from accidentally specifying an unsafe number of confirmations. We can remove this restriction as soon
  573. // as specific public guidance exists for Polygon developers.
  574. return err
  575. }
  576. if err := supervisor.Run(ctx, "avalanchewatch",
  577. ethereum.NewEthWatcher(*avalancheRPC, avalancheContractAddr, "avalanche", common.ReadinessAvalancheSyncing, vaa.ChainIDAvalanche, lockC, nil, 1, chainObsvReqC[vaa.ChainIDAvalanche]).Run); err != nil {
  578. return err
  579. }
  580. if err := supervisor.Run(ctx, "oasiswatch",
  581. ethereum.NewEthWatcher(*oasisRPC, oasisContractAddr, "oasis", common.ReadinessOasisSyncing, vaa.ChainIDOasis, lockC, nil, 1, chainObsvReqC[vaa.ChainIDOasis]).Run); err != nil {
  582. return err
  583. }
  584. if err := supervisor.Run(ctx, "fantomwatch",
  585. ethereum.NewEthWatcher(*fantomRPC, fantomContractAddr, "fantom", common.ReadinessFantomSyncing, vaa.ChainIDFantom, lockC, nil, 1, chainObsvReqC[vaa.ChainIDFantom]).Run); err != nil {
  586. return err
  587. }
  588. if *testnetMode {
  589. if err := supervisor.Run(ctx, "ethropstenwatch",
  590. ethereum.NewEthWatcher(*ethRopstenRPC, ethRopstenContractAddr, "ethropsten", common.ReadinessEthRopstenSyncing, vaa.ChainIDEthereumRopsten, lockC, setC, 1, chainObsvReqC[vaa.ChainIDEthereumRopsten]).Run); err != nil {
  591. return err
  592. }
  593. }
  594. // Start Terra watcher only if configured
  595. logger.Info("Starting Terra watcher")
  596. if err := supervisor.Run(ctx, "terrawatch",
  597. terra.NewWatcher(*terraWS, *terraLCD, *terraContract, lockC, setC, chainObsvReqC[vaa.ChainIDTerra]).Run); err != nil {
  598. return err
  599. }
  600. if *unsafeDevMode {
  601. if err := supervisor.Run(ctx, "algorandwatch",
  602. algorand.NewWatcher(*algorandRPC, *algorandToken, *algorandContract, lockC, setC).Run); err != nil {
  603. return err
  604. }
  605. }
  606. if err := supervisor.Run(ctx, "solwatch-confirmed",
  607. solana.NewSolanaWatcher(*solanaWsRPC, *solanaRPC, solAddress, lockC, nil, rpc.CommitmentConfirmed).Run); err != nil {
  608. return err
  609. }
  610. if err := supervisor.Run(ctx, "solwatch-finalized",
  611. solana.NewSolanaWatcher(*solanaWsRPC, *solanaRPC, solAddress, lockC, chainObsvReqC[vaa.ChainIDSolana], rpc.CommitmentFinalized).Run); err != nil {
  612. return err
  613. }
  614. p := processor.NewProcessor(ctx,
  615. db,
  616. lockC,
  617. setC,
  618. sendC,
  619. obsvC,
  620. injectC,
  621. signedInC,
  622. gk,
  623. gst,
  624. *unsafeDevMode,
  625. *devNumGuardians,
  626. *ethRPC,
  627. *terraLCD,
  628. *terraContract,
  629. attestationEvents,
  630. notifier,
  631. )
  632. if err := supervisor.Run(ctx, "processor", p.Run); err != nil {
  633. return err
  634. }
  635. if err := supervisor.Run(ctx, "admin", adminService); err != nil {
  636. return err
  637. }
  638. if *publicRPC != "" {
  639. if err := supervisor.Run(ctx, "publicrpc", publicrpcService); err != nil {
  640. return err
  641. }
  642. }
  643. if *publicWeb != "" {
  644. if err := supervisor.Run(ctx, "publicweb", publicwebService); err != nil {
  645. return err
  646. }
  647. }
  648. if *bigTablePersistenceEnabled {
  649. bigTableConnection := &reporter.BigTableConnectionConfig{
  650. GcpProjectID: *bigTableGCPProject,
  651. GcpInstanceName: *bigTableInstanceName,
  652. TableName: *bigTableTableName,
  653. TopicName: *bigTableTopicName,
  654. GcpKeyFilePath: *bigTableKeyPath,
  655. }
  656. if err := supervisor.Run(ctx, "bigtable", reporter.BigTableWriter(attestationEvents, bigTableConnection)); err != nil {
  657. return err
  658. }
  659. }
  660. logger.Info("Started internal services")
  661. <-ctx.Done()
  662. return nil
  663. },
  664. // It's safer to crash and restart the process in case we encounter a panic,
  665. // rather than attempting to reschedule the runnable.
  666. supervisor.WithPropagatePanic)
  667. <-rootCtx.Done()
  668. logger.Info("root context cancelled, exiting...")
  669. // TODO: wait for things to shut down gracefully
  670. }
  671. func decryptTelemetryServiceAccount() ([]byte, error) {
  672. // Decrypt service account credentials
  673. key, err := base64.StdEncoding.DecodeString(*telemetryKey)
  674. if err != nil {
  675. return nil, fmt.Errorf("failed to decode: %w", err)
  676. }
  677. ciphertext, err := base64.StdEncoding.DecodeString(telemetryServiceAccount)
  678. if err != nil {
  679. panic(err)
  680. }
  681. creds, err := common.DecryptAESGCM(ciphertext, key)
  682. if err != nil {
  683. return nil, fmt.Errorf("failed to decrypt: %w", err)
  684. }
  685. return creds, err
  686. }