aboutsummaryrefslogtreecommitdiffstats
path: root/core
diff options
context:
space:
mode:
authorWei-Ning Huang <w@dexon.org>2019-01-25 12:52:26 +0800
committerWei-Ning Huang <w@dexon.org>2019-04-09 21:32:56 +0800
commit0fa30af8a7aaab5e110e3430f2cb8f69cb17af70 (patch)
tree09649a34f10ee3f7340f7c767050b9f7ef609acb /core
parent72224d6ebc1763ee3787164fca00fe6d3ae501d6 (diff)
downloaddexon-0fa30af8a7aaab5e110e3430f2cb8f69cb17af70.tar
dexon-0fa30af8a7aaab5e110e3430f2cb8f69cb17af70.tar.gz
dexon-0fa30af8a7aaab5e110e3430f2cb8f69cb17af70.tar.bz2
dexon-0fa30af8a7aaab5e110e3430f2cb8f69cb17af70.tar.lz
dexon-0fa30af8a7aaab5e110e3430f2cb8f69cb17af70.tar.xz
dexon-0fa30af8a7aaab5e110e3430f2cb8f69cb17af70.tar.zst
dexon-0fa30af8a7aaab5e110e3430f2cb8f69cb17af70.zip
core: vm: more change to the randomness calculation (#175)
To prevent attacker from sending TX through a intermediate contract. Always use the original tx sender's adddress and nonce.
Diffstat (limited to 'core')
-rw-r--r--core/vm/instructions.go10
1 files changed, 5 insertions, 5 deletions
diff --git a/core/vm/instructions.go b/core/vm/instructions.go
index 3d17287ed..cb1f1bbaa 100644
--- a/core/vm/instructions.go
+++ b/core/vm/instructions.go
@@ -413,9 +413,9 @@ func opSha3(pc *uint64, interpreter *EVMInterpreter, contract *Contract, memory
func opRand(pc *uint64, interpreter *EVMInterpreter, contract *Contract, memory *Memory, stack *Stack) ([]byte, error) {
evm := interpreter.evm
- nonce := evm.StateDB.GetNonce(contract.Caller())
- binaryNonce := make([]byte, binary.MaxVarintLen64)
- binary.PutUvarint(binaryNonce, nonce)
+ nonce := evm.StateDB.GetNonce(evm.Origin)
+ binaryOriginNonce := make([]byte, binary.MaxVarintLen64)
+ binary.PutUvarint(binaryOriginNonce, nonce)
binaryUsedIndex := make([]byte, binary.MaxVarintLen64)
binary.PutUvarint(binaryUsedIndex, evm.RandCallIndex)
@@ -424,8 +424,8 @@ func opRand(pc *uint64, interpreter *EVMInterpreter, contract *Contract, memory
hash := crypto.Keccak256(
evm.Randomness,
- contract.Caller().Bytes(),
- binaryNonce,
+ evm.Origin.Bytes(),
+ binaryOriginNonce,
binaryUsedIndex)
stack.push(interpreter.intPool.get().SetBytes(hash))