igneum/tools/exec-attacks/run_all.sh
igneum-labs 017314f52d exec-attacks: execution-layer attack suite (tools + bench log)
Adversarial robustness and conformance tests of the execution layer against a
throwaway 3-node simnet on ports 27600+. Six scenarios, each a runnable command
with a design-derived pass criterion and a measured result: malformed/boundary
txs, nonce games across parallel blocks, RPC fuzz, pgas exhaustion, reorgs under
execution, and developer-registry abuse. 98 checks, 0 failures, 0 node panics.

Two findings filed in the bench-log entry: the mempool admits txs with gas_limit
above B_e (low), and an over-pgas-budget tx is executed natively in full before
being skipped for no fee (medium, griefing).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-03 22:57:19 +00:00

36 lines
1.5 KiB
Bash
Executable file

#!/usr/bin/env bash
# Runs every execution-layer attack in priority order (1, 2, 5, 3, 6, 4), starting and stopping the right network
# for each, and prints a one-line pass/fail per scenario. Detail in results/*.json.
set -u
HERE="$(cd "$(dirname "$0")" && pwd)"
cd "$HERE"
mkdir -p results
wait_rpc() { local t=0; until [ "$(curl -s -m2 -X POST http://127.0.0.1:$1 -H 'content-type: application/json' -d '{"jsonrpc":"2.0","id":1,"method":"eth_blockNumber","params":[]}' | grep -o '0x[0-9a-f]*' | head -1)" != "0x0" ] 2>/dev/null || [ $t -ge 40 ]; do sleep 2; t=$((t+2)); done; }
echo "== build check =="
test -x ../../vendor/igneum-node-exec-attacks/target/release/igneum-inject || { echo "build igneum-inject first (see README)"; exit 1; }
node compile.mjs >/dev/null
# Scenarios 1, 2, 5, 3 run on the hub network with one honest miner.
./net.sh stop >/dev/null 2>&1
./net.sh start 1 >/dev/null 2>&1
wait_rpc 27690
for s in scenario1_malformed scenario2_nonce scenario5_rpcfuzz scenario3_pgas; do
echo "== $s =="
node $s.mjs | tail -1
done
./net.sh stop >/dev/null 2>&1
# Scenario 6 manages its own split network across several partition depths.
echo "== scenario6_reorg =="
./run_scenario6.sh | tail -2
# Scenario 4 needs the single-miner hub (sender = payee = miner for self-dealing).
./net.sh start 1 >/dev/null 2>&1
wait_rpc 27690
echo "== scenario4_registry =="
node scenario4_registry.mjs | tail -1
./net.sh stop >/dev/null 2>&1
echo "== done; see results/*.json =="