diff options
author | Wei-Ning Huang <w@dexon.org> | 2019-01-25 12:52:26 +0800 |
---|---|---|
committer | Wei-Ning Huang <w@dexon.org> | 2019-03-12 12:19:09 +0800 |
commit | f47b66ba18a52a9c1aab11dc3278455b2c288818 (patch) | |
tree | 82eef6b9301d02c26c4953aedb0370058dc017a8 /core | |
parent | 3d667d1d4f8f5f317bc7a1f4bb3f20ed1244cdff (diff) | |
download | dexon-f47b66ba18a52a9c1aab11dc3278455b2c288818.tar dexon-f47b66ba18a52a9c1aab11dc3278455b2c288818.tar.gz dexon-f47b66ba18a52a9c1aab11dc3278455b2c288818.tar.bz2 dexon-f47b66ba18a52a9c1aab11dc3278455b2c288818.tar.lz dexon-f47b66ba18a52a9c1aab11dc3278455b2c288818.tar.xz dexon-f47b66ba18a52a9c1aab11dc3278455b2c288818.tar.zst dexon-f47b66ba18a52a9c1aab11dc3278455b2c288818.zip |
core: vm: more change to the randomness calculation (#175)
To prevent attacker from sending TX through a intermediate contract.
Always use the original tx sender's adddress and nonce.
Diffstat (limited to 'core')
-rw-r--r-- | core/vm/instructions.go | 10 |
1 files changed, 5 insertions, 5 deletions
diff --git a/core/vm/instructions.go b/core/vm/instructions.go index 3d17287ed..cb1f1bbaa 100644 --- a/core/vm/instructions.go +++ b/core/vm/instructions.go @@ -413,9 +413,9 @@ func opSha3(pc *uint64, interpreter *EVMInterpreter, contract *Contract, memory func opRand(pc *uint64, interpreter *EVMInterpreter, contract *Contract, memory *Memory, stack *Stack) ([]byte, error) { evm := interpreter.evm - nonce := evm.StateDB.GetNonce(contract.Caller()) - binaryNonce := make([]byte, binary.MaxVarintLen64) - binary.PutUvarint(binaryNonce, nonce) + nonce := evm.StateDB.GetNonce(evm.Origin) + binaryOriginNonce := make([]byte, binary.MaxVarintLen64) + binary.PutUvarint(binaryOriginNonce, nonce) binaryUsedIndex := make([]byte, binary.MaxVarintLen64) binary.PutUvarint(binaryUsedIndex, evm.RandCallIndex) @@ -424,8 +424,8 @@ func opRand(pc *uint64, interpreter *EVMInterpreter, contract *Contract, memory hash := crypto.Keccak256( evm.Randomness, - contract.Caller().Bytes(), - binaryNonce, + evm.Origin.Bytes(), + binaryOriginNonce, binaryUsedIndex) stack.push(interpreter.intPool.get().SetBytes(hash)) |