Transaction

1883A30E274551…079D8FFDE99A

Block 25,910 · index 0 · indexed

Summary

Hash
1883A30E27455109879B8296CC6E7DFCDE6329ACF7916BEBA40B079D8FFDE99A
Block
25,910
Size
4448 bytes
Gas used
10,177,014 / 12,212,476
Fee
1000000ugnot
Memo
gnopublish
Status
success

Messages

#1AddPackagegno.land/p/moul/nestedpkg/v09 arguments

Arguments · 9

  1. #1nestedpkg
  2. #2README.md
  3. #3# `gno.land/p/moul/nestedpkg/v0` _TODO: describe this package._ <!-- BEGIN GNOCONTRACTS FOOTER (generated by `make readmes`; do not edit below) --> --- Part of **[moul/gno-contracts](https://github.com/moul/gno-contracts)** — moul's versioned gno.land contracts. See the repository for the full catalog, build/test tooling, and usage. > ⚠️ **Disclaimer:** provided as-is, without warranty; not security-audited. Full disclaimer: [DISCLAIMER](https://github.com/moul/gno-contracts/blob/main/DISCLAIMER.md). <!-- END GNOCONTRACTS FOOTER -->
  4. #4gnomod.toml
  5. #5module = "gno.land/p/moul/nestedpkg/v0" gno = "0.9"
  6. #6nestedpkg.gno
  7. #7// Package nestedpkg provides helpers for package-path based access control. // It is useful for upgrade patterns relying on namespaces. // // SECURITY: every exported helper takes `rlm realm` and reads both // `rlm.PkgPath()` and `rlm.Previous().PkgPath()` to make an // authorization decision. To close Class-2 designation forgery (a // hostile realm stashes a captured realm value and passes it back to // spoof identity), every helper gates on `rlm.IsCurrent()` first. The // Is* predicates return false on stale rlm (fail-closed); the Assert* // helpers panic. See docs/resources/gno-security.md. package nestedpkg import "strings" // IsCallerSubPath checks if the caller realm is located in a subfolder of the current realm. func IsCallerSubPath(_ int, rlm realm) bool { if !rlm.IsCurrent() { return false } var ( curPath = rlm.PkgPath() + "/" prevPath = rlm.Previous().PkgPath() + "/" ) return strings.HasPrefix(prevPath, curPath) } // AssertCallerIsSubPath panics if IsCallerSubPath returns false. func AssertCallerIsSubPath(_ int, rlm realm) { if !rlm.IsCurrent() { panic("unauthorized: rlm is not the caller's live cur") } var ( curPath = rlm.PkgPath() + "/" prevPath = rlm.Previous().PkgPath() + "/" ) if !strings.HasPrefix(prevPath, curPath) { panic("call restricted to nested packages. current realm is " + curPath + ", previous realm is " + prevPath) } } // IsCallerParentPath checks if the caller realm is located in a parent location of the current realm. func IsCallerParentPath(_ int, rlm realm) bool { if !rlm.IsCurrent() { return false } var ( curPath = rlm.PkgPath() + "/" prevPath = rlm.Previous().PkgPath() + "/" ) return strings.HasPrefix(curPath, prevPath) } // AssertCallerIsParentPath panics if IsCallerParentPath returns false. func AssertCallerIsParentPath(_ int, rlm realm) { if !rlm.IsCurrent() { panic("unauthorized: rlm is not the caller's live cur") } var ( curPath = rlm.PkgPath() + "/" prevPath = rlm.Previous().PkgPath() + "/" ) if !strings.HasPrefix(curPath, prevPath) { panic("call restricted to parent packages. current realm is " + curPath + ", previous realm is " + prevPath) } } // IsSameNamespace checks if the caller realm and the current realm are in the same namespace. func IsSameNamespace(_ int, rlm realm) bool { if !rlm.IsCurrent() { return false } var ( curNs = nsFromPath(rlm.PkgPath()) + "/" prevNs = nsFromPath(rlm.Previous().PkgPath()) + "/" ) return curNs == prevNs } // AssertIsSameNamespace panics if IsSameNamespace returns false. func AssertIsSameNamespace(_ int, rlm realm) { if !rlm.IsCurrent() { panic("unauthorized: rlm is not the caller's live cur") } var ( curNs = nsFromPath(rlm.PkgPath()) + "/" prevNs = nsFromPath(rlm.Previous().PkgPath()) + "/" ) if curNs != prevNs { panic("call restricted to packages from the same namespace. current realm is " + curNs + ", previous realm is " + prevNs) } } // nsFromPath extracts the namespace from a package path. func nsFromPath(pkgpath string) string { parts := strings.Split(pkgpath, "/") // Specifically for gno.land, potential paths are in the form of DOMAIN/r/NAMESPACE/... // XXX: Consider extra checks. // XXX: Support non gno.land domains, where p/ and r/ won't be enforced. if len(parts) >= 3 { return parts[2] } return "" } // XXX: Consider adding IsCallerDirectlySubPath // XXX: Consider adding IsCallerDirectlyParentPath
  8. #8/gno.MemPackageType
  9. #9 MPUserProd

Result log

msg:0,success:true,log:,events:[]

← Back to block 25,910