Example #1
0
def do_add_cmd(config, args):
    """subcommand to add an entry to the eservice database
    """
    parser = argparse.ArgumentParser()
    parser.add_argument('-u',
                        '--url',
                        help='enclave service url',
                        required=True)
    parser.add_argument('-n',
                        '--name',
                        help='name to give to this enclave service')

    options = parser.parse_args(args)

    _load_database_(config)

    try:
        ledger_config = config['Ledger']
        if not options.name:
            eservice_db.add_by_url(ledger_config, options.url)
        else:
            eservice_db.add_by_url(ledger_config,
                                   options.url,
                                   name=options.name)
    except Exception as e:
        logger.error('unable to add eservice data for %s; %s', options.url,
                     str(e))
        sys.exit(-1)

    _save_database_(config)
Example #2
0
def command_eservice_db(state, bindings, pargs):
    """controller command to manage the enclave service database
    """

    parser = argparse.ArgumentParser(prog='eservice')

    subparsers = parser.add_subparsers(dest='command')

    add_parser = subparsers.add_parser(
        'add', description='add an eservice to the database')
    add_parser.add_argument('--url',
                            help='URL for the enclave service to add',
                            type=str,
                            required=True)
    add_parser.add_argument('--name',
                            help='Short name for the enclave service',
                            type=str,
                            required=True)

    clear_parser = subparsers.add_parser(
        'clear', description='remove all eservices in the database')
    list_parser = subparsers.add_parser(
        'list', description='list eservices in the database')

    load_parser = subparsers.add_parser(
        'load', description='load an eservice database')
    load_parser.add_argument('--database',
                             help='Name of the eservice database to use',
                             type=str,
                             required=True)
    merge_group = load_parser.add_mutually_exclusive_group(required=False)
    merge_group.add_argument('--merge',
                             help='Merge new database with current db',
                             dest='merge',
                             action='store_true')
    merge_group.add_argument('--no-merge',
                             help='Overwrite current db with new database',
                             dest='merge',
                             action='store_false')
    load_parser.set_defaults(merge=False)

    remove_parser = subparsers.add_parser(
        'remove', description='remove eservice from the database')
    remove_group = remove_parser.add_mutually_exclusive_group(required=True)
    remove_group.add_argument('--name',
                              help='Short name for enclave service to remove',
                              type=str)

    save_parser = subparsers.add_parser(
        'save', description='save the current eservice database')
    save_parser.add_argument('--database',
                             help='Name of the eservice database to use',
                             type=str,
                             required=True)

    options = parser.parse_args(pargs)

    default_database = state.get(['Service', 'EnclaveServiceDatabaseFile'])
    ledger_config = state.get(['Sawtooth'])

    if options.command == 'add':
        if not eservice_db.add_by_url(
                ledger_config, options.url, name=options.name, update=True):
            raise Exception(
                'failed to add eservice {0} to the database'.format(
                    options.name))
        return

    if options.command == 'clear':
        eservice_db.clear_all_data()
        return

    if options.command == 'list':
        enclave_names = list(eservice_db.get_enclave_names())
        enclave_names.sort()

        for enclave_name in enclave_names:
            enclave_info = eservice_db.get_by_name(enclave_name)
            enclave_short_id = _hashed_identity_(enclave_info.enclave_id)
            print("{0:<18} {1:<18} {2}".format(enclave_name, enclave_short_id,
                                               enclave_info.url))

    if options.command == 'load':
        eservice_db.load_database(options.database, options.merge)
        return

    if options.command == 'remove':
        eservice_db.remove_by_name(name=options.name)
        return

    if options.command == 'save':
        eservice_db.save_database(options.database, True)
        return

    raise Exception('unknown subcommand')
Example #3
0
def CreateAndRegisterEnclave(config):
    """
    creates and registers an enclave
    IMPORTANT: if an eservice is available it will be used,
               otherwise, the code interfaces directly with the python/swig wrapper in the eservice code
    """

    global enclave
    global txn_dependencies
    ledger_config = config.get('Sawtooth')

    interpreter = config['Contract']['Interpreter']

    # if we are using the eservice then there is nothing to register since
    # the eservice has already registered the enclave
    if use_eservice:
        enclaveclients = []
        try:
            for url in config['Service']['EnclaveServiceURLs']:
                einfo = db.add_by_url(ledger_config, url)
                if einfo is None:
                    logger.error("unable to connect to enclave service; %s",
                                 url)
                    sys.exit(-1)

                if einfo.client.interpreter != interpreter:
                    logger.error(
                        'contract and enclave expect different interpreters; <%s> != <%s>',
                        einfo.client.interpreter, interpreter)
                    sys.exit(-1)

                enclaveclients.append(einfo.client)
        except Exception as e:
            logger.error('unable to setup enclave services; %s', str(e))
            sys.exit(-1)

        return enclaveclients

    # not using an eservice so build the local enclave
    try:
        global block_store
        block_store_file = config['StorageService']['BlockStore']
        block_store = BlockStoreManager(block_store_file,
                                        create_block_store=True)
    except Exception as e:
        block_store.close()
        logger.error('failed to initialize the block store; %s', str(e))
        sys.exit(-1)

    try:
        enclave_helper.initialize_enclave(config)
        enclave = enclave_helper.Enclave.create_new_enclave()
    except Exception as e:
        logger.exception('failed to initialize the enclave; %s', str(e))
        block_store.close()
        sys.exit(-1)

    if enclave.interpreter != interpreter:
        logger.error(
            'contract and enclave expect different interpreters; %s != %s',
            enclave.interpreter, interpreter)
        ErrorShutdown()

    try:
        enclave.attach_block_store(block_store)
    except Exception as e:
        logger.exception('failed to attach block store; %s', str(e))
        ErrorShutdown()

    try:
        ledger_config = config.get('Sawtooth')
        if use_ledger:
            txnid = enclave.register_enclave(ledger_config)
            logger.info('enclave registration successful')

            enclave.verify_registration(ledger_config)
            logger.info('verified enclave registration')
        else:
            logger.debug('no ledger config; skipping enclave registration')
    except Exception as e:
        logger.exception('failed to register the enclave; %s', str(e))
        ErrorShutdown()

    return [enclave]
def command_eservice_db(state, bindings, pargs):
    """controller command to manage the enclave service database
    """

    parser = argparse.ArgumentParser(prog='eservice_db')
    parser.add_argument('-q',
                        '--quiet',
                        help='Do not print the result',
                        action='store_true')

    subparsers = parser.add_subparsers(dest='command')

    add_parser = subparsers.add_parser(
        'add', description='add an eservice to the database')
    add_parser.add_argument('--url',
                            help='URL for the enclave service to add',
                            type=str,
                            required=True)
    add_parser.add_argument('--name',
                            help='Short name for the enclave service',
                            type=str,
                            required=True)

    clear_parser = subparsers.add_parser(
        'clear', description='remove all eservices in the database')
    list_parser = subparsers.add_parser(
        'list', description='list eservices in the database')

    info_parser = subparsers.add_parser(
        'info', description='get information about a specific eservice')
    info_parser.add_argument('--name',
                             help='Short name for enclave service',
                             type=str,
                             required=True)
    info_parser.add_argument('-s',
                             '--symbol',
                             help='binding symbol for the result',
                             type=str)
    info_parser.add_argument('-f',
                             '--field',
                             help='field to display',
                             type=str)

    load_parser = subparsers.add_parser(
        'load', description='load an eservice database')
    load_parser.add_argument('--database',
                             help='Name of the eservice database to use',
                             type=str,
                             required=True)
    merge_group = load_parser.add_mutually_exclusive_group(required=False)
    merge_group.add_argument('--merge',
                             help='Merge new database with current db',
                             dest='merge',
                             action='store_true')
    merge_group.add_argument('--no-merge',
                             help='Overwrite current db with new database',
                             dest='merge',
                             action='store_false')
    load_parser.set_defaults(merge=False)

    remove_parser = subparsers.add_parser(
        'remove', description='remove eservice from the database')
    remove_group = remove_parser.add_mutually_exclusive_group(required=True)
    remove_group.add_argument('--name',
                              help='Short name for enclave service to remove',
                              type=str)

    save_parser = subparsers.add_parser(
        'save', description='save the current eservice database')
    save_parser.add_argument('--database',
                             help='Name of the eservice database to use',
                             type=str,
                             required=True)

    options = parser.parse_args(pargs)

    default_database = state.get(['Service', 'EnclaveServiceDatabaseFile'])
    ledger_config = state.get(['Ledger'])

    if options.command == 'add':
        if not eservice_db.add_by_url(
                ledger_config, options.url, name=options.name, update=True):
            raise Exception(
                'failed to add eservice {0} to the database'.format(
                    options.name))
        return

    if options.command == 'clear':
        eservice_db.clear_all_data()
        return

    if options.command == 'list':
        enclave_names = list(eservice_db.get_enclave_names())
        enclave_names.sort()

        for enclave_name in enclave_names:
            enclave_info = eservice_db.get_by_name(enclave_name)
            enclave_short_id = _hashed_identity_(enclave_info.enclave_id)
            print("{0:<18} {1:<18} {2}".format(enclave_name, enclave_short_id,
                                               enclave_info.url))

        return

    if options.command == 'info':
        enclave_info = eservice_db.get_by_name(options.name)
        enclave_info.verify(state.get(['Ledger']))

        enclave = {}
        enclave['short_name'] = options.name
        enclave['short_id'] = _hashed_identity_(enclave_info.enclave_id)
        enclave['enclave_id'] = enclave_info.enclave_id
        enclave['url'] = enclave_info.url
        enclave['last_verified_time'] = enclave_info.last_verified_time
        enclave['interpreter'] = enclave_info.client.interpreter
        enclave[
            'storage_service_url'] = enclave_info.client.storage_service_url
        enclave['verifying_key'] = enclave_info.client.verifying_key
        enclave['encryption_key'] = enclave_info.client.encryption_key

        result = enclave
        if options.field:
            result = enclave[options.field]

        if not options.quiet:
            print(json.dumps(result, indent=4, sort_keys=True))

        if options.symbol:
            bindings.bind(options.symbol, result)

        return

    if options.command == 'load':
        eservice_db.load_database(options.database, options.merge)
        return

    if options.command == 'remove':
        eservice_db.remove_by_name(name=options.name)
        return

    if options.command == 'save':
        eservice_db.save_database(options.database, True)
        return

    raise Exception('unknown subcommand')
Example #5
0
    serialized_db = json.dumps(serialized_einfo_list)
    return hash(serialized_db)


# -----------------------------------------------------------------
# -----------------------------------------------------------------
ledger_config = {'LedgerURL': options.ledger}

# -----------------------------------------------------------------
# logger.info('create and load the database from the provided URLs')
# -----------------------------------------------------------------
names = []
enclave_count = 0
for url in options.url:
    names.append('enclave_{0}'.format(enclave_count))
    eservice_db.add_by_url(ledger_config, url, name=names[enclave_count])
    enclave_count += 1

# -----------------------------------------------------------------
# logger.info('verify that the information in the database is consistent')
# -----------------------------------------------------------------
for e in names:
    einfo_by_name = eservice_db.get_by_name(e)
    einfo_by_enclave_id = eservice_db.get_by_enclave_id(
        einfo_by_name.client.enclave_id)

    # this can probably be simplified to just a comparison of
    # the two objects
    assert einfo_by_name.name == e
    assert einfo_by_enclave_id.name == e
    assert einfo_by_name.name == einfo_by_enclave_id.name