From 6eab6c7c285be21e8069863688a7daf878b7bb6b Mon Sep 17 00:00:00 2001 From: TimothyBanks Date: Mon, 10 Aug 2026 21:35:33 -0400 Subject: [PATCH] feat: Hook up permissioned_domain_id host function --- crates/xrpl-host-functions/src/lib.rs | 12 +++++++ .../tests/generated_abi.rs | 23 +++++++++++++ crates/xrpl-wasm-vm-ffi/src/lib.rs | 18 +++++++++++ crates/xrpl-wasm-vm/src/abi.rs | 8 +++++ crates/xrpl-wasm-vm/src/register.rs | 23 +++++++++++++ crates/xrpl-wasm-vm/tests/budgets.rs | 5 +++ crates/xrpl-wasm-vm/tests/host_calls.rs | 19 +++++++++++ crates/xrpl-wasm-vm/tests/preflight.rs | 3 +- crates/xrpl-wasm-vm/tests/support/mod.rs | 32 +++++++++++++++++++ include/xrpl/tx/wasm/HostContext.h | 8 +++++ src/libxrpl/tx/wasm/HostContext.cpp | 20 ++++++++++++ 11 files changed, 170 insertions(+), 1 deletion(-) diff --git a/crates/xrpl-host-functions/src/lib.rs b/crates/xrpl-host-functions/src/lib.rs index 4dcc509937..151a4ffbfe 100644 --- a/crates/xrpl-host-functions/src/lib.rs +++ b/crates/xrpl-host-functions/src/lib.rs @@ -374,6 +374,18 @@ host_functions! { out: &mut [u8], ) -> HostResult; + /// The 32-byte keylet of a `PermissionedDomain`, computed from the 20-byte owner + /// account and its sequence number. `seq` is the guest's `u32` carried as its `i32` + /// bit pattern. Reads the account region and writes the keylet. + #[gas = 350] + #[wasm_name = "permissioned_domain_id"] + fn permissioned_domain_keylet( + &self, + account: &[u8], + seq: i32, + out: &mut [u8], + ) -> HostResult; + /// The XRPL `sha512Half` of `data`: the first [`HASH_LEN`] bytes of its SHA-512. #[gas = 2000] #[wasm_name = "sha512_half"] diff --git a/crates/xrpl-host-functions/tests/generated_abi.rs b/crates/xrpl-host-functions/tests/generated_abi.rs index d8ef7520a4..3ba4d96e2d 100644 --- a/crates/xrpl-host-functions/tests/generated_abi.rs +++ b/crates/xrpl-host-functions/tests/generated_abi.rs @@ -347,6 +347,19 @@ impl HostFunctions for FakeHost { put(out, &[account[0]; HASH_LEN]) } + /// The same account-and-sequence shape, for a `PermissionedDomain`. + fn permissioned_domain_keylet( + &self, + account: &[u8], + _seq: i32, + out: &mut [u8], + ) -> HostResult { + if account.is_empty() { + return Err(HostError::InvalidAccount); + } + put(out, &[account[0]; HASH_LEN]) + } + fn sha512_half(&self, data: &[u8], out: &mut [u8]) -> HostResult { let mut digest = [0; HASH_LEN]; digest[0] = data.len() as u8; @@ -547,6 +560,15 @@ fn the_trait_is_implementable() { host.paychannel_keylet(&[7; 20], &[], 5, &mut out), Err(HostError::InvalidAccount) ); + assert_eq!( + host.permissioned_domain_keylet(&[7; 20], 5, &mut out), + Ok(HASH_LEN) + ); + assert_eq!(out[0], 7); + assert_eq!( + host.permissioned_domain_keylet(&[], 5, &mut out), + Err(HostError::InvalidAccount) + ); assert_eq!(host.sha512_half(b"abc", &mut out), Ok(HASH_LEN)); assert_eq!(out[0], 3); assert_eq!(host.trace("hello", b"xy", true), Ok(())); @@ -648,6 +670,7 @@ fn the_spec_table_matches_the_declarations() { ("offer_id", 350), ("oracle_id", 350), ("paychan_id", 350), + ("permissioned_domain_id", 350), ("sha512_half", 2000), ("trace", 500), ("trace_num", 500), diff --git a/crates/xrpl-wasm-vm-ffi/src/lib.rs b/crates/xrpl-wasm-vm-ffi/src/lib.rs index 69ca769ad8..02776c4b1e 100644 --- a/crates/xrpl-wasm-vm-ffi/src/lib.rs +++ b/crates/xrpl-wasm-vm-ffi/src/lib.rs @@ -358,6 +358,15 @@ mod ffi { out: &mut [u8], ) -> i32; + #[namespace = "xrpl"] + #[cxx_name = "permissionedDomainKeylet"] + fn permissioned_domain_keylet( + self: &HostContext, + account: &[u8], + seq: i32, + out: &mut [u8], + ) -> i32; + #[namespace = "xrpl"] #[cxx_name = "sha512Half"] fn sha512_half(self: &HostContext, data: &[u8], out: &mut [u8]) -> i32; @@ -604,6 +613,15 @@ impl HostFunctions for CxxHost<'_> { bytes_written(self.ctx.paychannel_keylet(account, destination, seq, out)) } + fn permissioned_domain_keylet( + &self, + account: &[u8], + seq: i32, + out: &mut [u8], + ) -> HostResult { + bytes_written(self.ctx.permissioned_domain_keylet(account, seq, out)) + } + fn sha512_half(&self, data: &[u8], out: &mut [u8]) -> HostResult { bytes_written(self.ctx.sha512_half(data, out)) } diff --git a/crates/xrpl-wasm-vm/src/abi.rs b/crates/xrpl-wasm-vm/src/abi.rs index bdbd9fc674..a5bd7ce8c5 100644 --- a/crates/xrpl-wasm-vm/src/abi.rs +++ b/crates/xrpl-wasm-vm/src/abi.rs @@ -358,6 +358,14 @@ mod tests { ) -> HostResult { unreachable!("no unit test in this module calls the host") } + fn permissioned_domain_keylet( + &self, + _account: &[u8], + _seq: i32, + _out: &mut [u8], + ) -> HostResult { + unreachable!("no unit test in this module calls the host") + } fn sha512_half(&self, _data: &[u8], _out: &mut [u8]) -> HostResult { unreachable!("no unit test in this module calls the host") } diff --git a/crates/xrpl-wasm-vm/src/register.rs b/crates/xrpl-wasm-vm/src/register.rs index 469b72066a..22c4407d54 100644 --- a/crates/xrpl-wasm-vm/src/register.rs +++ b/crates/xrpl-wasm-vm/src/register.rs @@ -647,6 +647,29 @@ pub(crate) fn register_host_functions( }) }, ), + HostFunctionSpec::PermissionedDomainKeylet => linker.func_wrap( + HOST_MODULE, + op.wasm_name(), + |mut caller: Caller<'_, VmState<'_>>, + acc_ptr: i32, + acc_len: i32, + seq: i32, + out_ptr: i32, + out_len: i32| + -> Result { + charged( + &mut caller, + HostFunctionSpec::PermissionedDomainKeylet, + |c| { + let out = Region::new(out_ptr, out_len); + let account = Region::new(acc_ptr, acc_len); + write_buffered(c, out, |host, data, buf| { + host.permissioned_domain_keylet(account.read(data)?, seq, buf) + }) + }, + ) + }, + ), HostFunctionSpec::Sha512Half => linker.func_wrap( HOST_MODULE, op.wasm_name(), diff --git a/crates/xrpl-wasm-vm/tests/budgets.rs b/crates/xrpl-wasm-vm/tests/budgets.rs index c8597eb295..e062f1c06c 100644 --- a/crates/xrpl-wasm-vm/tests/budgets.rs +++ b/crates/xrpl-wasm-vm/tests/budgets.rs @@ -219,6 +219,11 @@ fn call_for(op: HostFunctionSpec) -> Call { "(call $paychan_id (i32.const 0) (i32.const 20) (i32.const 20) (i32.const 20) (i32.const 5) (i32.const 40) (i32.const 20))", 7, ), + HostFunctionSpec::PermissionedDomainKeylet => ( + import::PERMISSIONED_DOMAIN_ID, + "(call $permissioned_domain_id (i32.const 0) (i32.const 20) (i32.const 5) (i32.const 32) (i32.const 32))", + 5, + ), HostFunctionSpec::Sha512Half => ( import::SHA512_HALF, "(call $sha512_half (i32.const 0) (i32.const 4) (i32.const 0) (i32.const 32))", diff --git a/crates/xrpl-wasm-vm/tests/host_calls.rs b/crates/xrpl-wasm-vm/tests/host_calls.rs index 941b7798ec..09dfdd807e 100644 --- a/crates/xrpl-wasm-vm/tests/host_calls.rs +++ b/crates/xrpl-wasm-vm/tests/host_calls.rs @@ -683,6 +683,25 @@ fn paychan_id_reads_both_accounts_and_the_seq() { ); } +/// Another account-and-sequence keylet, with its own answer set, for a permissioned +/// domain. +#[test] +fn permissioned_domain_id_reads_the_account_and_seq() { + let account = vec![0u8; 20]; + let host = FakeHost::new().answering_permissioned_domain_keylet( + account.clone(), + 5, + support::Answer::filler(32), + ); + + let wat = module( + &[import::PERMISSIONED_DOMAIN_ID, ONE_PAGE], + "(call $permissioned_domain_id (i32.const 0) (i32.const 20) (i32.const 5) (i32.const 64) (i32.const 64))", + ); + assert_eq!(status(&wat, &host), 32, "the 32-byte keylet length"); + assert_eq!(*host.domain_keylets_asked.borrow(), vec![(account, 5)]); +} + /// A leading scalar parameter reaches the host as declared. #[test] fn home_le_field_passes_the_field_selector_through() { diff --git a/crates/xrpl-wasm-vm/tests/preflight.rs b/crates/xrpl-wasm-vm/tests/preflight.rs index 67b181b113..1542caf3c1 100644 --- a/crates/xrpl-wasm-vm/tests/preflight.rs +++ b/crates/xrpl-wasm-vm/tests/preflight.rs @@ -98,7 +98,7 @@ fn a_disabled_feature_does_not_pass() { /// Every host function the ABI declares, spelled as a guest imports it. The count /// is asserted against the ABI so a function added to it cannot be left out here. -const ALL_IMPORTS: [&str; 37] = [ +const ALL_IMPORTS: [&str; 38] = [ import::LDGR_INDEX, import::PARENT_LDGR_TIME, import::PARENT_LDGR_HASH, @@ -133,6 +133,7 @@ const ALL_IMPORTS: [&str; 37] = [ import::OFFER_ID, import::ORACLE_ID, import::PAYCHAN_ID, + import::PERMISSIONED_DOMAIN_ID, import::SHA512_HALF, import::TRACE, import::TRACE_NUM, diff --git a/crates/xrpl-wasm-vm/tests/support/mod.rs b/crates/xrpl-wasm-vm/tests/support/mod.rs index e9feedde13..9f7c632b7e 100644 --- a/crates/xrpl-wasm-vm/tests/support/mod.rs +++ b/crates/xrpl-wasm-vm/tests/support/mod.rs @@ -254,6 +254,11 @@ pub struct FakeHost { pub paychannel_keylets: HashMap<(Vec, Vec, i32), Answer>, /// Every (account, destination, seq) `paychannel_keylet` was asked for. pub paychannel_keylets_asked: RefCell, Vec, i32)>>, + /// What `permissioned_domain_keylet` answers, by (account bytes, seq). An unlisted + /// key answers `InvalidAccount`. + pub domain_keylets: HashMap<(Vec, i32), Answer>, + /// Every (account, seq) `permissioned_domain_keylet` was asked for. + pub domain_keylets_asked: RefCell, i32)>>, /// What `sha512_half` answers, whatever it is given. pub digest: Answer, /// Every field selector `get_current_ledger_obj_field` was asked for. @@ -338,6 +343,8 @@ impl Default for FakeHost { oracle_keylets_asked: RefCell::new(Vec::new()), paychannel_keylets: HashMap::new(), paychannel_keylets_asked: RefCell::new(Vec::new()), + domain_keylets: HashMap::new(), + domain_keylets_asked: RefCell::new(Vec::new()), digest: Answer::filler(32), fields_asked: RefCell::new(Vec::new()), digested: RefCell::new(Vec::new()), @@ -603,6 +610,16 @@ impl FakeHost { self } + pub fn answering_permissioned_domain_keylet( + mut self, + account: Vec, + seq: i32, + answer: Answer, + ) -> FakeHost { + self.domain_keylets.insert((account, seq), answer); + self + } + pub fn answering_digest(mut self, answer: Answer) -> FakeHost { self.digest = answer; self @@ -943,6 +960,20 @@ impl HostFunctions for FakeHost { } } + fn permissioned_domain_keylet( + &self, + account: &[u8], + seq: i32, + out: &mut [u8], + ) -> HostResult { + let key = (account.to_vec(), seq); + self.domain_keylets_asked.borrow_mut().push(key.clone()); + match self.domain_keylets.get(&key) { + Some(answer) => answer.fill(out), + None => Err(HostError::InvalidAccount), + } + } + fn sha512_half(&self, data: &[u8], out: &mut [u8]) -> HostResult { self.digested.borrow_mut().push(data.to_vec()); self.digest.fill(out) @@ -1018,6 +1049,7 @@ pub mod import { pub const OFFER_ID: &str = r#"(import "host_lib" "offer_id" (func $offer_id (param i32 i32 i32 i32 i32) (result i32)))"#; pub const ORACLE_ID: &str = r#"(import "host_lib" "oracle_id" (func $oracle_id (param i32 i32 i32 i32 i32) (result i32)))"#; pub const PAYCHAN_ID: &str = r#"(import "host_lib" "paychan_id" (func $paychan_id (param i32 i32 i32 i32 i32 i32 i32) (result i32)))"#; + pub const PERMISSIONED_DOMAIN_ID: &str = r#"(import "host_lib" "permissioned_domain_id" (func $permissioned_domain_id (param i32 i32 i32 i32 i32) (result i32)))"#; pub const SHA512_HALF: &str = r#"(import "host_lib" "sha512_half" (func $sha512_half (param i32 i32 i32 i32) (result i32)))"#; pub const TRACE: &str = r#"(import "host_lib" "trace" (func $trace (param i32 i32 i32 i32 i32) (result i32)))"#; diff --git a/include/xrpl/tx/wasm/HostContext.h b/include/xrpl/tx/wasm/HostContext.h index 19e6d5fdfe..ef8028ea17 100644 --- a/include/xrpl/tx/wasm/HostContext.h +++ b/include/xrpl/tx/wasm/HostContext.h @@ -235,6 +235,14 @@ public: std::int32_t seq, rust::Slice out) const noexcept; + // The account id must be 20 bytes, else `InvalidParams`. `seq` carries the guest's + // u32 as its i32 bit pattern. Writes the 32-byte keylet. + [[nodiscard]] std::int32_t + permissionedDomainKeylet( + rust::Slice account, + std::int32_t seq, + rust::Slice out) const noexcept; + [[nodiscard]] std::int32_t sha512Half(rust::Slice data, rust::Slice out) const noexcept; diff --git a/src/libxrpl/tx/wasm/HostContext.cpp b/src/libxrpl/tx/wasm/HostContext.cpp index 739334d84e..b4f90c839b 100644 --- a/src/libxrpl/tx/wasm/HostContext.cpp +++ b/src/libxrpl/tx/wasm/HostContext.cpp @@ -746,6 +746,26 @@ HostContext::paychannelKeylet( }); } +std::int32_t +HostContext::permissionedDomainKeylet( + rust::Slice account, + std::int32_t seq, + rust::Slice out) const noexcept +{ + return guarded(hostFunctions_.getJournal(), kHostInternal, [&] { + if (account.size() != AccountID::size()) + return hfErrorToInt(HostFunctionError::InvalidParams); + + // The guest's u32 seq arrives as its i32 bit pattern; recover it. + auto const value = hostFunctions_.permissionedDomainKeylet( + AccountID::fromVoid(account.data()), static_cast(seq)); + if (!value) + return hfErrorToInt(value.error()); + + return answer(out, value->data(), value->size()); + }); +} + std::int32_t HostContext::sha512Half(rust::Slice data, rust::Slice out) const noexcept