igneum/tools/exec-attacks/compile.mjs
igneum-labs 1037d06276 exec-attacks: execution-layer attack suite (tools + bench log)
Adversarial robustness and conformance tests of the execution layer against a
throwaway 3-node simnet on ports 27600+. Six scenarios, each a runnable command
with a design-derived pass criterion and a measured result: malformed/boundary
txs, nonce games across parallel blocks, RPC fuzz, pgas exhaustion, reorgs under
execution, and developer-registry abuse. 98 checks, 0 failures, 0 node panics.

Two findings filed in the bench-log entry: the mempool admits txs with gas_limit
above B_e (low), and an over-pgas-budget tx is executed natively in full before
being skipped for no fee (medium, griefing).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-03 22:57:19 +00:00

25 lines
1.4 KiB
JavaScript

// Compiles the attack contracts with solc-js and writes contracts/*.json (abi + creation bytecode).
import solc from 'solc';
import { readFileSync, writeFileSync } from 'node:fs';
import { fileURLToPath } from 'node:url';
import path from 'node:path';
const here = path.dirname(fileURLToPath(import.meta.url));
const input = {
language: 'Solidity',
sources: {
'PgasBomb.sol': { content: readFileSync(path.join(here, 'contracts/PgasBomb.sol'), 'utf8') },
'RegistryAbuse.sol': { content: readFileSync(path.join(here, 'contracts/RegistryAbuse.sol'), 'utf8') },
},
settings: { optimizer: { enabled: true, runs: 200 }, evmVersion: 'cancun', outputSelection: { '*': { '*': ['abi', 'evm.bytecode.object'] } } },
};
const out = JSON.parse(solc.compile(JSON.stringify(input)));
for (const e of out.errors ?? []) { if (e.severity === 'error') { console.error(e.formattedMessage); process.exit(1); } }
const write = (file, srcFile, name) => {
const c = out.contracts[srcFile][name];
writeFileSync(path.join(here, 'contracts', file), JSON.stringify({ abi: c.abi, bytecode: '0x' + c.evm.bytecode.object }, null, 1) + '\n');
console.log(file, 'creation bytes', c.evm.bytecode.object.length / 2);
};
write('PgasBomb.json', 'PgasBomb.sol', 'PgasBomb');
write('Worker.json', 'RegistryAbuse.sol', 'Worker');
write('Factory.json', 'RegistryAbuse.sol', 'Factory');
console.log('solc', solc.version());