Transaction
1883A30E274551…079D8FFDE99A
Block 25,910 · index 0 · indexed
Summary
- Hash
- 1883A30E27455109879B8296CC6E7DFCDE6329ACF7916BEBA40B079D8FFDE99A
- Block
- 25,910
- Size
- 4448 bytes
- Gas used
- 10,177,014 / 12,212,476
- Fee
- 1000000ugnot
- Memo
- gnopublish
- Status
- success
Messages
- Package
- gno.land/p/moul/nestedpkg/v0
Arguments · 9
- #1nestedpkg
- #2README.md
- #3# `gno.land/p/moul/nestedpkg/v0` _TODO: describe this package._ <!-- BEGIN GNOCONTRACTS FOOTER (generated by `make readmes`; do not edit below) --> --- Part of **[moul/gno-contracts](https://github.com/moul/gno-contracts)** — moul's versioned gno.land contracts. See the repository for the full catalog, build/test tooling, and usage. > ⚠️ **Disclaimer:** provided as-is, without warranty; not security-audited. Full disclaimer: [DISCLAIMER](https://github.com/moul/gno-contracts/blob/main/DISCLAIMER.md). <!-- END GNOCONTRACTS FOOTER -->
- #4gnomod.toml
- #5module = "gno.land/p/moul/nestedpkg/v0" gno = "0.9"
- #6nestedpkg.gno
- #7// Package nestedpkg provides helpers for package-path based access control. // It is useful for upgrade patterns relying on namespaces. // // SECURITY: every exported helper takes `rlm realm` and reads both // `rlm.PkgPath()` and `rlm.Previous().PkgPath()` to make an // authorization decision. To close Class-2 designation forgery (a // hostile realm stashes a captured realm value and passes it back to // spoof identity), every helper gates on `rlm.IsCurrent()` first. The // Is* predicates return false on stale rlm (fail-closed); the Assert* // helpers panic. See docs/resources/gno-security.md. package nestedpkg import "strings" // IsCallerSubPath checks if the caller realm is located in a subfolder of the current realm. func IsCallerSubPath(_ int, rlm realm) bool { if !rlm.IsCurrent() { return false } var ( curPath = rlm.PkgPath() + "/" prevPath = rlm.Previous().PkgPath() + "/" ) return strings.HasPrefix(prevPath, curPath) } // AssertCallerIsSubPath panics if IsCallerSubPath returns false. func AssertCallerIsSubPath(_ int, rlm realm) { if !rlm.IsCurrent() { panic("unauthorized: rlm is not the caller's live cur") } var ( curPath = rlm.PkgPath() + "/" prevPath = rlm.Previous().PkgPath() + "/" ) if !strings.HasPrefix(prevPath, curPath) { panic("call restricted to nested packages. current realm is " + curPath + ", previous realm is " + prevPath) } } // IsCallerParentPath checks if the caller realm is located in a parent location of the current realm. func IsCallerParentPath(_ int, rlm realm) bool { if !rlm.IsCurrent() { return false } var ( curPath = rlm.PkgPath() + "/" prevPath = rlm.Previous().PkgPath() + "/" ) return strings.HasPrefix(curPath, prevPath) } // AssertCallerIsParentPath panics if IsCallerParentPath returns false. func AssertCallerIsParentPath(_ int, rlm realm) { if !rlm.IsCurrent() { panic("unauthorized: rlm is not the caller's live cur") } var ( curPath = rlm.PkgPath() + "/" prevPath = rlm.Previous().PkgPath() + "/" ) if !strings.HasPrefix(curPath, prevPath) { panic("call restricted to parent packages. current realm is " + curPath + ", previous realm is " + prevPath) } } // IsSameNamespace checks if the caller realm and the current realm are in the same namespace. func IsSameNamespace(_ int, rlm realm) bool { if !rlm.IsCurrent() { return false } var ( curNs = nsFromPath(rlm.PkgPath()) + "/" prevNs = nsFromPath(rlm.Previous().PkgPath()) + "/" ) return curNs == prevNs } // AssertIsSameNamespace panics if IsSameNamespace returns false. func AssertIsSameNamespace(_ int, rlm realm) { if !rlm.IsCurrent() { panic("unauthorized: rlm is not the caller's live cur") } var ( curNs = nsFromPath(rlm.PkgPath()) + "/" prevNs = nsFromPath(rlm.Previous().PkgPath()) + "/" ) if curNs != prevNs { panic("call restricted to packages from the same namespace. current realm is " + curNs + ", previous realm is " + prevNs) } } // nsFromPath extracts the namespace from a package path. func nsFromPath(pkgpath string) string { parts := strings.Split(pkgpath, "/") // Specifically for gno.land, potential paths are in the form of DOMAIN/r/NAMESPACE/... // XXX: Consider extra checks. // XXX: Support non gno.land domains, where p/ and r/ won't be enforced. if len(parts) >= 3 { return parts[2] } return "" } // XXX: Consider adding IsCallerDirectlySubPath // XXX: Consider adding IsCallerDirectlyParentPath
- #8/gno.MemPackageType
- #9 MPUserProd
Result log
msg:0,success:true,log:,events:[]