Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

docs: [L-06] revokeOperator() does not protect against the double-spending allowance attack #834

Merged
merged 4 commits into from
Jan 9, 2024

Conversation

YamenMerhi
Copy link
Member

What does this PR introduce?

📄 Documentation

  • Advise use of increase/decrease allowance in LSP7
  • Generate docs

PR Checklist

  • Wrote Tests
  • Wrote & Generated Documentation (readme/natspec/dodoc)
  • Ran npm run lint && npm run lint:solidity (solhint)
  • Ran npm run format (prettier)
  • Ran npm run build
  • Ran npm run test

@Hugoo
Copy link
Contributor

Hugoo commented Jan 2, 2024

Copy link
Contributor

github-actions bot commented Jan 2, 2024

👋 Hello
⛽ I am the Gas Bot Reporter. I keep track of the gas costs of common interactions using Universal Profiles 🆙 !
📊 Here is a summary of the gas cost with the code introduced by this PR.

⛽📊 Gas Benchmark Report

Deployment Costs

Deployed contracts ⛽ Deployment cost
UniversalProfile 3168335 (0 )
KeyManager 3659003 (0 )
LSP1DelegateUP 1637510 (0 )
LSP7Mintable 2407811 (-12 📉✅)
LSP8Mintable 2809933 (0 )

Runtime Costs

UniversalProfile owned by an 🔑 EOA

🔀 execute scenarios

execute scenarios - UP owned by 🔑 EOA ⛽ Gas Usage
Transfer 1 LYX to an EOA without data 37572 (0 )
Transfer 1 LYX to a UP without data 46265 (0 )
Transfer 1 LYX to an EOA with 256 bytes of data 42233 (0 )
Transfer 1 LYX to a UP with 256 bytes of data 57198 (12 📈❌)
Transfer 0.1 LYX to 3x EOA without data 70898 (0 )
Transfer 0.1 LYX to 3x UP without data 104489 (0 )
Transfer 0.1 LYX to 3x EOA with 256 bytes of data 84910 (60 📈❌)
Transfer 0.1 LYX to 3x UPs with 256 bytes of data 137173 (-36 📉✅)

🗄️ setData scenarios

setData scenarios - UP owned by 🔑 EOA ⛽ Gas Usage
Set a 20 bytes long value 49909 (-12 📉✅)
Set a 60 bytes long value 95243 (0 )
Set a 160 bytes long value 164391 (-12 📉✅)
Set a 300 bytes long value 279284 (12 📈❌)
Set a 600 bytes long value 486668 (12 📈❌)
Change the value of a data key already set 32809 (0 )
Remove the value of a data key already set 27283 (0 )
Set 2 data keys of 20 bytes long value 78428 (-12 📉✅)
Set 2 data keys of 100 bytes long value 260580 (24 📈❌)
Set 3 data keys of 20 bytes long value 105128 (0 )
Change the value of three data keys already set of 20 bytes long value 45428 (12 📈❌)
Remove the value of three data keys already set 41325 (0 )

🗄️ Tokens scenarios

Tokens scenarios - UP owned by 🔑 EOA ⛽ Gas Usage
Minting a LSP7Token to a UP (No Delegate) from an EOA 93114 (0 )
Minting a LSP7Token to an EOA from an EOA 59390 (0 )
Transferring an LSP7Token from a UP to another UP (No Delegate) 102367 (0 )
Minting a LSP8Token to a UP (No Delegate) from an EOA 159961 (0 )
Minting a LSP8Token to an EOA from an EOA 126238 (0 )
Transferring an LSP8Token from a UP to another UP (No Delegate) 151083 (0 )
UniversalProfile owned by a 🔒📄 LSP6KeyManager

🔀 execute scenarios

execute scenarios 👑 main controller 🛃 restricted controller
LYX transfer --> to an EOA 64365 (0 ) 75316 (0 )
LYX transfer --> to a UP 78508 (0 ) 93410 (0 )
LSP7 token transfer --> to an EOA 116872 (0 ) 131622 (0 )
LSP7 token transfer --> to a UP 250518 (0 ) 265268 (0 )
LSP8 NFT transfer --> to an EOA 180981 (0 ) 195731 (0 )
LSP8 NFT transfer --> to a UP 297829 (0 ) 312579 (0 )

🗄️ setData scenarios

setData scenarios 👑 main controller 🛃 restricted controller
Update Profile details (LSP3Profile Metadata) 67264 (0 ) 77286 (0 )
Add a new controller with permission to SET_DATA + 3x allowed data keys:
AddressPermissions[]
+ AddressPermissions[index]
+ AddressPermissions:Permissions:<controller>
+ AddressPermissions:AllowedERC725YDataKeys:<controller)
209516 (0 ) 219673 (0 )
Update permissions of previous controller. Allow it now to SUPER_SETDATA 52292 (0 ) 55298 (0 )
Remove a controller:
1. decrease AddressPermissions[] Array length
2. remove the controller address at AddressPermissions[index]
3. set "0x" for the controller permissions under AddressPermissions:Permissions:
78765 (0 ) 90064 (0 )
Write 5x new LSP12 Issued Assets 66959 (0 ) 101586 (0 )
Update 3x data keys (first 3) 125411 (0 ) 159515 (0 )
Update 3x data keys (middle 3) 105499 (0 ) 143669 (0 )
Update 3x data keys (last 3) 125411 (0 ) 169002 (0 )
Set 2 x new data keys + add 3x new controllers 810121 (0 ) 871921 (0 )

Copy link
Contributor

github-actions bot commented Jan 9, 2024

Changes to gas cost

Generated at commit: 4abc34b2552c11bb89d03d8288559c0ddafb24a0, compared to commit: 0433a6b60f0cea17b78d24b063737cd4094c8f02

🧾 Summary (10% most significant diffs)

Contract Method Avg (+/-) %
LSP6ExecuteRestrictedController transferNFTToRandomEOA
transferTokensToRandomEOA
+35,831 ❌
+18,834 ❌
+25.00%
+25.00%
LSP6ExecuteUnrestrictedController transferTokensToRandomEOA +18,520 ❌ +25.00%

Full diff report 👇
Contract Deployment Cost (+/-) Method Min (+/-) % Avg (+/-) % Median (+/-) % Max (+/-) % # Calls (+/-)
LSP6ExecuteRestrictedController 3,047,114 (0) transferLYXToEOA
transferLYXToUP
transferNFTToRandomEOA
transferNFTToRandomUP
transferTokensToRandomEOA
transferTokensToRandomUP
77,723 (+15,544)
69,116 (+13,823)
179,157 (+35,831)
311,559 (+62,311)
94,170 (+18,834)
226,357 (+19,900)
+25.00%
+25.00%
+25.00%
+25.00%
+25.00%
+9.64%
77,723 (+15,544)
69,116 (+13,823)
179,157 (+35,831)
311,559 (+62,311)
94,170 (+18,834)
226,357 (+19,900)
+25.00%
+25.00%
+25.00%
+25.00%
+25.00%
+9.64%
77,723 (+15,544)
69,116 (+13,823)
179,157 (+35,831)
311,559 (+62,311)
94,170 (+18,834)
226,357 (+19,900)
+25.00%
+25.00%
+25.00%
+25.00%
+25.00%
+9.64%
77,723 (+15,544)
69,116 (+13,823)
179,157 (+35,831)
311,559 (+62,311)
94,170 (+18,834)
226,357 (+19,900)
+25.00%
+25.00%
+25.00%
+25.00%
+25.00%
+9.64%
1 (0)
1 (0)
1 (0)
1 (0)
1 (0)
1 (0)
LSP6ExecuteUnrestrictedController 3,047,114 (0) transferLYXToEOA
transferLYXToUP
transferNFTToRandomEOA
transferNFTToRandomUP
transferTokensToRandomEOA
transferTokensToRandomUP
78,207 (+15,641)
71,116 (+14,223)
177,587 (+35,517)
309,989 (+61,997)
92,600 (+18,520)
224,787 (+19,900)
+25.00%
+25.00%
+25.00%
+25.00%
+25.00%
+9.71%
78,207 (+15,641)
71,116 (+14,223)
177,587 (+35,517)
309,989 (+61,997)
92,600 (+18,520)
224,787 (+19,900)
+25.00%
+25.00%
+25.00%
+25.00%
+25.00%
+9.71%
78,207 (+15,641)
71,116 (+14,223)
177,587 (+35,517)
309,989 (+61,997)
92,600 (+18,520)
224,787 (+19,900)
+25.00%
+25.00%
+25.00%
+25.00%
+25.00%
+9.71%
78,207 (+15,641)
71,116 (+14,223)
177,587 (+35,517)
309,989 (+61,997)
92,600 (+18,520)
224,787 (+19,900)
+25.00%
+25.00%
+25.00%
+25.00%
+25.00%
+9.71%
1 (0)
1 (0)
1 (0)
1 (0)
1 (0)
1 (0)
LSP6SetDataRestrictedController 3,035,099 (0) execute 37,886 (+7,577) +25.00% 38,070 (+3,789) +11.05% 38,070 (+3,789) +11.05% 38,254 (0) 0.00% 2 (0)
LSP6SetDataUnrestrictedController 3,035,099 (0) execute 37,886 (+7,577) +25.00% 38,070 (+3,789) +11.05% 38,070 (+3,789) +11.05% 38,254 (0) 0.00% 2 (0)

@CJ42 CJ42 merged commit 62009fa into develop Jan 9, 2024
43 checks passed
@CJ42 CJ42 deleted the DEV-9442 branch January 9, 2024 12:52
richtera pushed a commit that referenced this pull request Mar 6, 2024
…nding allowance attack (#834)

* Advise use of increase/decrease allowance in LSP7

* docs: generate docs

* docs: fix minor natspec issue

---------

Co-authored-by: Jean Cvllr <31145285+CJ42@users.noreply.github.com>
@richtera richtera mentioned this pull request Mar 6, 2024
6 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

4 participants