1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
// Copyright 2021-2023 Axiom-Team
//
// This file is part of Duniter-v2S.
//
// Duniter-v2S is free software: you can redistribute it and/or modify
// it under the terms of the GNU Affero General Public License as published by
// the Free Software Foundation, version 3 of the License.
//
// Duniter-v2S is distributed in the hope that it will be useful,
// but WITHOUT ANY WARRANTY; without even the implied warranty of
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
// GNU Affero General Public License for more details.
//
// You should have received a copy of the GNU Affero General Public License
// along with Duniter-v2S. If not, see <https://www.gnu.org/licenses/>.

//! # Duniter Offences Pallet
//!
//! This pallet is a fork of the Substrate `offences` pallet, customized to align with the offence rules specified by the `authority-member` pallet rather than the Substrate `staking` pallet.
//!
//! ## Offences Processing
//!
//! The Duniter Offences Pallet manages various types of offences as follows:
//!
//! - **`im-online` Pallet Offences**: Offences from the `im-online` pallet necessitate disconnection of the offender.
//!
//! - **Other Offences**: For all other offences, the pallet enforces:
//!   - Disconnection of the offender.
//!   - Addition of the offender to a blacklist.
//!   - Authorization from a designated origin to remove offenders from the blacklist.
//!
//! ## Offences Triage and Slashing Execution
//!
//! This pallet handles the triage of offences, categorizing them based on predefined rules. The actual execution of slashing and other punitive measures is delegated to the `authority-member` pallet.

#![cfg_attr(not(feature = "std"), no_std)]

#[cfg(test)]
mod mock;

#[cfg(test)]
mod tests;

use core::marker::PhantomData;

use codec::Encode;
use frame_support::weights::Weight;
use scale_info::prelude::vec::Vec;
use sp_runtime::traits::Hash;
use sp_staking::offence::{Kind, Offence, OffenceDetails, OffenceError, ReportOffence};

pub use pallet::*;

pub mod traits;
use self::traits::*;

/// A binary blob which represents a SCALE codec-encoded `O::TimeSlot`.
type OpaqueTimeSlot = Vec<u8>;

/// A type alias for a report identifier.
type ReportIdOf<T> = <T as frame_system::Config>::Hash;

pub enum SlashStrategy {
    Disconnect,
    Blacklist,
}

#[frame_support::pallet]
pub mod pallet {
    use super::*;
    use frame_support::pallet_prelude::*;

    const STORAGE_VERSION: StorageVersion = StorageVersion::new(1);

    #[pallet::pallet]
    #[pallet::storage_version(STORAGE_VERSION)]
    #[pallet::without_storage_info]
    pub struct Pallet<T>(_);

    /// The pallet's config trait.
    #[pallet::config]
    pub trait Config: frame_system::Config {
        /// The overarching event type.
        type RuntimeEvent: From<Event> + IsType<<Self as frame_system::Config>::RuntimeEvent>;

        /// Full identification of the validator.
        type IdentificationTuple: Parameter;

        /// A handler called for every offence report.
        type OnOffenceHandler: OnOffenceHandler<Self::AccountId, Self::IdentificationTuple, Weight>;
    }

    /// The primary structure that holds all offence records keyed by report identifiers.
    #[pallet::storage]
    #[pallet::getter(fn reports)]
    pub type Reports<T: Config> = StorageMap<
        _,
        Twox64Concat,
        ReportIdOf<T>,
        OffenceDetails<T::AccountId, T::IdentificationTuple>,
    >;

    /// A vector of reports of the same kind that happened at the same time slot.
    #[pallet::storage]
    pub type ConcurrentReportsIndex<T: Config> = StorageDoubleMap<
        _,
        Twox64Concat,
        Kind,
        Twox64Concat,
        OpaqueTimeSlot,
        Vec<ReportIdOf<T>>,
        ValueQuery,
    >;

    /// Events type.
    #[pallet::event]
    #[pallet::generate_deposit(pub(super) fn deposit_event)]
    pub enum Event {
        /// An offense was reported during the specified time slot. This event is not deposited for duplicate slashes.
        Offence {
            kind: Kind,
            timeslot: OpaqueTimeSlot,
        },
    }
}

impl<T, O> ReportOffence<T::AccountId, T::IdentificationTuple, O> for Pallet<T>
where
    T: Config,
    O: Offence<T::IdentificationTuple>,
{
    fn report_offence(reporters: Vec<T::AccountId>, offence: O) -> Result<(), OffenceError> {
        let offenders = offence.offenders();
        let time_slot = offence.time_slot();

        // Go through all offenders in the offence report and find all offenders that were spotted
        // in unique reports.
        let TriageOutcome {
            concurrent_offenders,
        } = match Self::triage_offence_report::<O>(reporters, &time_slot, offenders) {
            Some(triage) => triage,
            None => return Err(OffenceError::DuplicateReport),
        };

        // Define the slash strategy.
        let slash_strategy = if O::ID == *b"im-online:offlin" {
            SlashStrategy::Disconnect
        } else {
            SlashStrategy::Blacklist
        };

        T::OnOffenceHandler::on_offence(
            &concurrent_offenders,
            slash_strategy,
            offence.session_index(),
        );

        Self::deposit_event(Event::Offence {
            kind: O::ID,
            timeslot: time_slot.encode(),
        });

        Ok(())
    }

    fn is_known_offence(offenders: &[T::IdentificationTuple], time_slot: &O::TimeSlot) -> bool {
        let any_unknown = offenders.iter().any(|offender| {
            let report_id = Self::report_id::<O>(time_slot, offender);
            !<Reports<T>>::contains_key(report_id)
        });

        !any_unknown
    }
}

impl<T: Config> Pallet<T> {
    /// Compute the ID for the given report properties.
    ///
    /// The report id depends on the offence kind, time slot and the id of offender.
    fn report_id<O: Offence<T::IdentificationTuple>>(
        time_slot: &O::TimeSlot,
        offender: &T::IdentificationTuple,
    ) -> ReportIdOf<T> {
        (O::ID, time_slot.encode(), offender).using_encoded(T::Hashing::hash)
    }

    /// Triages the offence report and returns the set of offenders that was involved in unique
    /// reports along with the list of the concurrent offences.
    fn triage_offence_report<O: Offence<T::IdentificationTuple>>(
        reporters: Vec<T::AccountId>,
        time_slot: &O::TimeSlot,
        offenders: Vec<T::IdentificationTuple>,
    ) -> Option<TriageOutcome<T>> {
        let mut storage = ReportIndexStorage::<T, O>::load(time_slot);

        let mut any_new = false;
        for offender in offenders {
            let report_id = Self::report_id::<O>(time_slot, &offender);

            if !<Reports<T>>::contains_key(report_id) {
                any_new = true;
                <Reports<T>>::insert(
                    report_id,
                    OffenceDetails {
                        offender,
                        reporters: reporters.clone(),
                    },
                );

                storage.insert(report_id);
            }
        }

        if any_new {
            // Load report details for the all reports happened at the same time.
            let concurrent_offenders = storage
                .concurrent_reports
                .iter()
                .filter_map(<Reports<T>>::get)
                .collect::<Vec<_>>();

            storage.save();

            Some(TriageOutcome {
                concurrent_offenders,
            })
        } else {
            None
        }
    }
}

struct TriageOutcome<T: Config> {
    /// Other reports for the same report kinds.
    concurrent_offenders: Vec<OffenceDetails<T::AccountId, T::IdentificationTuple>>,
}

/// An auxiliary struct for working with storage of indexes localized for a specific offence
/// kind (specified by the `O` type parameter).
///
/// This struct is responsible for aggregating storage writes and the underlying storage should not
/// accessed directly meanwhile.
#[must_use = "The changes are not saved without called `save`"]
struct ReportIndexStorage<T: Config, O: Offence<T::IdentificationTuple>> {
    opaque_time_slot: OpaqueTimeSlot,
    concurrent_reports: Vec<ReportIdOf<T>>,
    _phantom: PhantomData<O>,
}

impl<T: Config, O: Offence<T::IdentificationTuple>> ReportIndexStorage<T, O> {
    /// Preload indexes from the storage for the specific `time_slot` and the kind of the offence.
    fn load(time_slot: &O::TimeSlot) -> Self {
        let opaque_time_slot = time_slot.encode();

        let concurrent_reports = <ConcurrentReportsIndex<T>>::get(O::ID, &opaque_time_slot);

        Self {
            opaque_time_slot,
            concurrent_reports,
            _phantom: Default::default(),
        }
    }

    /// Insert a new report to the index.
    fn insert(&mut self, report_id: ReportIdOf<T>) {
        // Update the list of concurrent reports.
        self.concurrent_reports.push(report_id);
    }

    /// Dump the indexes to the storage.
    fn save(self) {
        <ConcurrentReportsIndex<T>>::insert(
            O::ID,
            &self.opaque_time_slot,
            &self.concurrent_reports,
        );
    }
}