tornado-core/test/ERC20Tornado.test.js

506 lines
22 KiB
JavaScript
Raw Normal View History

2019-08-20 22:39:21 +02:00
/* global artifacts, web3, contract */
2021-02-11 07:23:18 +01:00
require('chai').use(require('bn-chai')(web3.utils.BN)).use(require('chai-as-promised')).should()
2019-08-20 22:39:21 +02:00
const fs = require('fs')
2019-11-28 09:04:09 +01:00
const { toBN } = require('web3-utils')
2020-08-01 04:28:14 +02:00
const { takeSnapshot, revertSnapshot } = require('../scripts/ganacheHelper')
2019-08-20 22:39:21 +02:00
2019-12-13 14:49:19 +01:00
const Tornado = artifacts.require('./ERC20Tornado.sol')
const BadRecipient = artifacts.require('./BadRecipient.sol')
2019-08-20 22:39:21 +02:00
const Token = artifacts.require('./ERC20Mock.sol')
2019-08-30 12:06:17 +02:00
const USDTToken = artifacts.require('./IUSDT.sol')
2019-11-02 13:35:22 +01:00
const { ETH_AMOUNT, TOKEN_AMOUNT, MERKLE_TREE_HEIGHT, ERC20_TOKEN } = process.env
2019-08-20 22:39:21 +02:00
const websnarkUtils = require('websnark/src/utils')
const buildGroth16 = require('websnark/src/groth16')
const stringifyBigInts = require('websnark/tools/stringifybigint').stringifyBigInts
const snarkjs = require('snarkjs')
const bigInt = snarkjs.bigInt
const crypto = require('crypto')
const circomlib = require('circomlib')
2020-07-31 19:38:50 +02:00
const MerkleTree = require('fixed-merkle-tree')
2019-08-20 22:39:21 +02:00
const rbigint = (nbytes) => snarkjs.bigInt.leBuff2int(crypto.randomBytes(nbytes))
const pedersenHash = (data) => circomlib.babyJub.unpackPoint(circomlib.pedersenHash.hash(data))[0]
2021-02-11 07:23:18 +01:00
const toFixedHex = (number, length = 32) =>
'0x' +
bigInt(number)
.toString(16)
.padStart(length * 2, '0')
2019-11-28 05:52:17 +01:00
const getRandomRecipient = () => rbigint(20)
2019-08-20 22:39:21 +02:00
function generateDeposit() {
let deposit = {
secret: rbigint(31),
nullifier: rbigint(31),
}
const preimage = Buffer.concat([deposit.nullifier.leInt2Buff(31), deposit.secret.leInt2Buff(31)])
deposit.commitment = pedersenHash(preimage)
return deposit
}
2021-02-11 07:23:18 +01:00
contract('ERC20Tornado', (accounts) => {
2019-12-13 14:49:19 +01:00
let tornado
2019-08-20 22:39:21 +02:00
let token
2019-08-30 12:06:17 +02:00
let usdtToken
let badRecipient
2019-08-20 22:39:21 +02:00
const sender = accounts[0]
const operator = accounts[0]
const levels = MERKLE_TREE_HEIGHT || 16
2019-08-30 12:06:17 +02:00
let tokenDenomination = TOKEN_AMOUNT || '1000000000000000000' // 1 ether
2019-08-20 22:39:21 +02:00
let snapshotId
let tree
2019-08-27 22:42:24 +02:00
const fee = bigInt(ETH_AMOUNT).shr(1) || bigInt(1e17)
const refund = ETH_AMOUNT || '1000000000000000000' // 1 ether
let recipient = getRandomRecipient()
2019-08-20 22:39:21 +02:00
const relayer = accounts[1]
let groth16
let circuit
let proving_key
before(async () => {
2020-07-31 19:38:50 +02:00
tree = new MerkleTree(levels)
2019-12-13 14:49:19 +01:00
tornado = await Tornado.deployed()
2019-08-30 12:06:17 +02:00
if (ERC20_TOKEN) {
token = await Token.at(ERC20_TOKEN)
usdtToken = await USDTToken.at(ERC20_TOKEN)
} else {
token = await Token.deployed()
await token.mint(sender, tokenDenomination)
}
badRecipient = await BadRecipient.new()
2019-08-20 22:39:21 +02:00
snapshotId = await takeSnapshot()
groth16 = await buildGroth16()
circuit = require('../build/circuits/withdraw.json')
proving_key = fs.readFileSync('build/circuits/withdraw_proving_key.bin').buffer
})
describe('#constructor', () => {
it('should initialize', async () => {
2019-12-13 14:49:19 +01:00
const tokenFromContract = await tornado.token()
2019-08-20 22:39:21 +02:00
tokenFromContract.should.be.equal(token.address)
})
})
describe('#deposit', () => {
2019-08-24 12:18:52 +02:00
it('should work', async () => {
2019-11-04 22:04:22 +01:00
const commitment = toFixedHex(43)
2019-12-13 14:49:19 +01:00
await token.approve(tornado.address, tokenDenomination)
2019-08-20 22:39:21 +02:00
2019-12-13 14:49:19 +01:00
let { logs } = await tornado.deposit(commitment, { from: sender })
2019-08-20 22:39:21 +02:00
logs[0].event.should.be.equal('Deposit')
2019-11-04 22:04:22 +01:00
logs[0].args.commitment.should.be.equal(commitment)
logs[0].args.leafIndex.should.be.eq.BN(0)
2019-08-20 22:39:21 +02:00
})
it('should not allow to send ether on deposit', async () => {
2019-11-04 22:04:22 +01:00
const commitment = toFixedHex(43)
2019-12-13 14:49:19 +01:00
await token.approve(tornado.address, tokenDenomination)
2019-12-13 14:49:19 +01:00
let error = await tornado.deposit(commitment, { from: sender, value: 1e6 }).should.be.rejected
error.reason.should.be.equal('ETH value is supposed to be 0 for ERC20 instance')
})
2019-08-20 22:39:21 +02:00
})
2019-08-24 12:18:52 +02:00
describe('#withdraw', () => {
it('should work', async () => {
const deposit = generateDeposit()
const user = accounts[4]
2020-07-31 19:38:50 +02:00
tree.insert(deposit.commitment)
2019-08-27 22:42:24 +02:00
await token.mint(user, tokenDenomination)
2019-08-24 12:18:52 +02:00
const balanceUserBefore = await token.balanceOf(user)
2019-12-13 14:49:19 +01:00
await token.approve(tornado.address, tokenDenomination, { from: user })
2019-08-24 12:18:52 +02:00
// Uncomment to measure gas usage
2019-12-13 14:49:19 +01:00
// let gas = await tornado.deposit.estimateGas(toBN(deposit.commitment.toString()), { from: user, gasPrice: '0' })
2019-08-24 12:18:52 +02:00
// console.log('deposit gas:', gas)
2019-12-13 14:49:19 +01:00
await tornado.deposit(toFixedHex(deposit.commitment), { from: user, gasPrice: '0' })
2019-08-24 12:18:52 +02:00
const balanceUserAfter = await token.balanceOf(user)
2019-08-27 22:42:24 +02:00
balanceUserAfter.should.be.eq.BN(toBN(balanceUserBefore).sub(toBN(tokenDenomination)))
2019-08-24 12:18:52 +02:00
2020-07-31 19:38:50 +02:00
const { pathElements, pathIndices } = tree.path(0)
2019-08-24 12:18:52 +02:00
// Circuit input
const input = stringifyBigInts({
// public
2020-07-31 19:38:50 +02:00
root: tree.root(),
2019-08-24 12:18:52 +02:00
nullifierHash: pedersenHash(deposit.nullifier.leInt2Buff(31)),
2019-09-10 15:31:34 +02:00
relayer,
2019-11-07 08:04:29 +01:00
recipient,
2019-08-24 12:18:52 +02:00
fee,
refund,
2019-08-24 12:18:52 +02:00
// private
nullifier: deposit.nullifier,
secret: deposit.secret,
2020-07-31 19:38:50 +02:00
pathElements: pathElements,
pathIndices: pathIndices,
2019-08-24 12:18:52 +02:00
})
2019-10-04 17:20:20 +02:00
const proofData = await websnarkUtils.genWitnessAndProve(groth16, input, circuit, proving_key)
2019-11-04 20:42:41 +01:00
const { proof } = websnarkUtils.toSolidityInput(proofData)
2019-08-24 12:18:52 +02:00
2019-12-13 14:49:19 +01:00
const balanceTornadoBefore = await token.balanceOf(tornado.address)
2019-08-24 12:18:52 +02:00
const balanceRelayerBefore = await token.balanceOf(relayer)
2021-10-31 15:07:39 +01:00
const balanceReceiverBefore = await token.balanceOf(toFixedHex(recipient, 20))
2019-10-17 18:19:35 +02:00
const ethBalanceOperatorBefore = await web3.eth.getBalance(operator)
2021-10-31 15:07:39 +01:00
const ethBalanceReceiverBefore = await web3.eth.getBalance(toFixedHex(recipient, 20))
2019-10-17 18:19:35 +02:00
const ethBalanceRelayerBefore = await web3.eth.getBalance(relayer)
2019-12-13 14:49:19 +01:00
let isSpent = await tornado.isSpent(toFixedHex(input.nullifierHash))
2019-08-24 12:18:52 +02:00
isSpent.should.be.equal(false)
// Uncomment to measure gas usage
2019-12-13 14:49:19 +01:00
// gas = await tornado.withdraw.estimateGas(proof, publicSignals, { from: relayer, gasPrice: '0' })
2019-08-24 12:18:52 +02:00
// console.log('withdraw gas:', gas)
2019-11-04 20:42:41 +01:00
const args = [
toFixedHex(input.root),
toFixedHex(input.nullifierHash),
2019-11-07 08:04:29 +01:00
toFixedHex(input.recipient, 20),
2019-11-04 20:42:41 +01:00
toFixedHex(input.relayer, 20),
toFixedHex(input.fee),
2021-02-11 07:23:18 +01:00
toFixedHex(input.refund),
2019-11-04 20:42:41 +01:00
]
2019-12-13 14:49:19 +01:00
const { logs } = await tornado.withdraw(proof, ...args, { value: refund, from: relayer, gasPrice: '0' })
2019-08-24 12:18:52 +02:00
2019-12-13 14:49:19 +01:00
const balanceTornadoAfter = await token.balanceOf(tornado.address)
2019-08-24 12:18:52 +02:00
const balanceRelayerAfter = await token.balanceOf(relayer)
2019-08-27 22:42:24 +02:00
const ethBalanceOperatorAfter = await web3.eth.getBalance(operator)
2021-10-31 15:07:39 +01:00
const balanceReceiverAfter = await token.balanceOf(toFixedHex(recipient, 20))
const ethBalanceReceiverAfter = await web3.eth.getBalance(toFixedHex(recipient, 20))
2019-10-17 18:19:35 +02:00
const ethBalanceRelayerAfter = await web3.eth.getBalance(relayer)
2019-08-24 12:18:52 +02:00
const feeBN = toBN(fee.toString())
2019-12-13 14:49:19 +01:00
balanceTornadoAfter.should.be.eq.BN(toBN(balanceTornadoBefore).sub(toBN(tokenDenomination)))
2019-09-10 15:31:34 +02:00
balanceRelayerAfter.should.be.eq.BN(toBN(balanceRelayerBefore).add(feeBN))
2021-10-31 15:07:39 +01:00
balanceReceiverAfter.should.be.eq.BN(
toBN(balanceReceiverBefore).add(toBN(tokenDenomination).sub(feeBN)),
2021-02-11 07:23:18 +01:00
)
2019-10-17 18:19:35 +02:00
ethBalanceOperatorAfter.should.be.eq.BN(toBN(ethBalanceOperatorBefore))
2021-10-31 15:07:39 +01:00
ethBalanceReceiverAfter.should.be.eq.BN(toBN(ethBalanceReceiverBefore).add(toBN(refund)))
2019-10-17 18:19:35 +02:00
ethBalanceRelayerAfter.should.be.eq.BN(toBN(ethBalanceRelayerBefore).sub(toBN(refund)))
2019-08-30 12:06:17 +02:00
2019-11-01 02:12:32 +01:00
logs[0].event.should.be.equal('Withdrawal')
2019-11-04 22:04:22 +01:00
logs[0].args.nullifierHash.should.be.equal(toFixedHex(input.nullifierHash))
2019-09-10 15:31:34 +02:00
logs[0].args.relayer.should.be.eq.BN(relayer)
2019-08-30 12:06:17 +02:00
logs[0].args.fee.should.be.eq.BN(feeBN)
2019-12-13 14:49:19 +01:00
isSpent = await tornado.isSpent(toFixedHex(input.nullifierHash))
2019-08-30 12:06:17 +02:00
isSpent.should.be.equal(true)
})
it('should return refund to the relayer is case of fail', async () => {
const deposit = generateDeposit()
const user = accounts[4]
recipient = bigInt(badRecipient.address)
2020-07-31 19:38:50 +02:00
tree.insert(deposit.commitment)
await token.mint(user, tokenDenomination)
const balanceUserBefore = await token.balanceOf(user)
2019-12-13 14:49:19 +01:00
await token.approve(tornado.address, tokenDenomination, { from: user })
await tornado.deposit(toFixedHex(deposit.commitment), { from: user, gasPrice: '0' })
const balanceUserAfter = await token.balanceOf(user)
balanceUserAfter.should.be.eq.BN(toBN(balanceUserBefore).sub(toBN(tokenDenomination)))
2020-07-31 19:38:50 +02:00
const { pathElements, pathIndices } = tree.path(0)
// Circuit input
const input = stringifyBigInts({
// public
2020-07-31 19:38:50 +02:00
root: tree.root(),
nullifierHash: pedersenHash(deposit.nullifier.leInt2Buff(31)),
relayer,
recipient,
fee,
refund,
// private
nullifier: deposit.nullifier,
secret: deposit.secret,
2020-07-31 19:38:50 +02:00
pathElements: pathElements,
pathIndices: pathIndices,
})
const proofData = await websnarkUtils.genWitnessAndProve(groth16, input, circuit, proving_key)
const { proof } = websnarkUtils.toSolidityInput(proofData)
2019-12-13 14:49:19 +01:00
const balanceTornadoBefore = await token.balanceOf(tornado.address)
const balanceRelayerBefore = await token.balanceOf(relayer)
2021-10-31 15:07:39 +01:00
const balanceReceiverBefore = await token.balanceOf(toFixedHex(recipient, 20))
const ethBalanceOperatorBefore = await web3.eth.getBalance(operator)
2021-10-31 15:07:39 +01:00
const ethBalanceReceiverBefore = await web3.eth.getBalance(toFixedHex(recipient, 20))
const ethBalanceRelayerBefore = await web3.eth.getBalance(relayer)
2019-12-13 14:49:19 +01:00
let isSpent = await tornado.isSpent(toFixedHex(input.nullifierHash))
isSpent.should.be.equal(false)
const args = [
toFixedHex(input.root),
toFixedHex(input.nullifierHash),
toFixedHex(input.recipient, 20),
toFixedHex(input.relayer, 20),
toFixedHex(input.fee),
2021-02-11 07:23:18 +01:00
toFixedHex(input.refund),
]
2019-12-13 14:49:19 +01:00
const { logs } = await tornado.withdraw(proof, ...args, { value: refund, from: relayer, gasPrice: '0' })
2019-12-13 14:49:19 +01:00
const balanceTornadoAfter = await token.balanceOf(tornado.address)
const balanceRelayerAfter = await token.balanceOf(relayer)
const ethBalanceOperatorAfter = await web3.eth.getBalance(operator)
2021-10-31 15:07:39 +01:00
const balanceReceiverAfter = await token.balanceOf(toFixedHex(recipient, 20))
const ethBalanceReceiverAfter = await web3.eth.getBalance(toFixedHex(recipient, 20))
const ethBalanceRelayerAfter = await web3.eth.getBalance(relayer)
const feeBN = toBN(fee.toString())
2019-12-13 14:49:19 +01:00
balanceTornadoAfter.should.be.eq.BN(toBN(balanceTornadoBefore).sub(toBN(tokenDenomination)))
balanceRelayerAfter.should.be.eq.BN(toBN(balanceRelayerBefore).add(feeBN))
2021-10-31 15:07:39 +01:00
balanceReceiverAfter.should.be.eq.BN(
toBN(balanceReceiverBefore).add(toBN(tokenDenomination).sub(feeBN)),
2021-02-11 07:23:18 +01:00
)
ethBalanceOperatorAfter.should.be.eq.BN(toBN(ethBalanceOperatorBefore))
2021-10-31 15:07:39 +01:00
ethBalanceReceiverAfter.should.be.eq.BN(toBN(ethBalanceReceiverBefore))
ethBalanceRelayerAfter.should.be.eq.BN(toBN(ethBalanceRelayerBefore))
logs[0].event.should.be.equal('Withdrawal')
logs[0].args.nullifierHash.should.be.equal(toFixedHex(input.nullifierHash))
logs[0].args.relayer.should.be.eq.BN(relayer)
logs[0].args.fee.should.be.eq.BN(feeBN)
2019-12-13 14:49:19 +01:00
isSpent = await tornado.isSpent(toFixedHex(input.nullifierHash))
isSpent.should.be.equal(true)
})
2019-10-17 18:19:35 +02:00
it('should reject with wrong refund value', async () => {
const deposit = generateDeposit()
const user = accounts[4]
2020-07-31 19:38:50 +02:00
tree.insert(deposit.commitment)
2019-10-17 18:19:35 +02:00
await token.mint(user, tokenDenomination)
2019-12-13 14:49:19 +01:00
await token.approve(tornado.address, tokenDenomination, { from: user })
await tornado.deposit(toFixedHex(deposit.commitment), { from: user, gasPrice: '0' })
2019-10-17 18:19:35 +02:00
2020-07-31 19:38:50 +02:00
const { pathElements, pathIndices } = tree.path(0)
2019-10-17 18:19:35 +02:00
// Circuit input
const input = stringifyBigInts({
// public
2020-07-31 19:38:50 +02:00
root: tree.root(),
2019-10-17 18:19:35 +02:00
nullifierHash: pedersenHash(deposit.nullifier.leInt2Buff(31)),
relayer,
2019-11-07 08:04:29 +01:00
recipient,
2019-10-17 18:19:35 +02:00
fee,
refund,
// private
nullifier: deposit.nullifier,
secret: deposit.secret,
2020-07-31 19:38:50 +02:00
pathElements: pathElements,
pathIndices: pathIndices,
2019-10-17 18:19:35 +02:00
})
const proofData = await websnarkUtils.genWitnessAndProve(groth16, input, circuit, proving_key)
2019-11-04 20:42:41 +01:00
const { proof } = websnarkUtils.toSolidityInput(proofData)
const args = [
toFixedHex(input.root),
toFixedHex(input.nullifierHash),
2019-11-07 08:04:29 +01:00
toFixedHex(input.recipient, 20),
2019-11-04 20:42:41 +01:00
toFixedHex(input.relayer, 20),
toFixedHex(input.fee),
2021-02-11 07:23:18 +01:00
toFixedHex(input.refund),
2019-11-04 20:42:41 +01:00
]
2021-02-11 07:23:18 +01:00
let { reason } = await tornado.withdraw(proof, ...args, { value: 1, from: relayer, gasPrice: '0' })
.should.be.rejected
2019-10-17 18:19:35 +02:00
reason.should.be.equal('Incorrect refund amount received by the contract')
2021-02-11 07:23:18 +01:00
;({ reason } = await tornado.withdraw(proof, ...args, {
value: toBN(refund).mul(toBN(2)),
from: relayer,
gasPrice: '0',
}).should.be.rejected)
2019-10-17 18:19:35 +02:00
reason.should.be.equal('Incorrect refund amount received by the contract')
})
2019-08-30 12:06:17 +02:00
it.skip('should work with REAL USDT', async () => {
// dont forget to specify your token in .env
// USDT decimals is 6, so TOKEN_AMOUNT=1000000
// and sent `tokenDenomination` to accounts[0] (0x90F8bf6A479f320ead074411a4B0e7944Ea8c9C1)
// run ganache as
// ganache-cli --fork https://kovan.infura.io/v3/27a9649f826b4e31a83e07ae09a87448@13147586 -d --keepAliveTimeout 20
const deposit = generateDeposit()
const user = accounts[4]
const userBal = await usdtToken.balanceOf(user)
console.log('userBal', userBal.toString())
const senderBal = await usdtToken.balanceOf(sender)
console.log('senderBal', senderBal.toString())
2020-07-31 19:38:50 +02:00
tree.insert(deposit.commitment)
2019-08-30 12:06:17 +02:00
await usdtToken.transfer(user, tokenDenomination, { from: sender })
console.log('transfer done')
const balanceUserBefore = await usdtToken.balanceOf(user)
console.log('balanceUserBefore', balanceUserBefore.toString())
2019-12-13 14:49:19 +01:00
await usdtToken.approve(tornado.address, tokenDenomination, { from: user })
2019-08-30 12:06:17 +02:00
console.log('approve done')
2019-12-13 14:49:19 +01:00
const allowanceUser = await usdtToken.allowance(user, tornado.address)
2019-08-30 12:06:17 +02:00
console.log('allowanceUser', allowanceUser.toString())
2019-12-13 14:49:19 +01:00
await tornado.deposit(toFixedHex(deposit.commitment), { from: user, gasPrice: '0' })
2019-08-30 12:06:17 +02:00
console.log('deposit done')
const balanceUserAfter = await usdtToken.balanceOf(user)
balanceUserAfter.should.be.eq.BN(toBN(balanceUserBefore).sub(toBN(tokenDenomination)))
2020-07-31 19:38:50 +02:00
const { pathElements, pathIndices } = tree.path(0)
2019-08-30 12:06:17 +02:00
// Circuit input
const input = stringifyBigInts({
// public
2020-07-31 19:38:50 +02:00
root: tree.root(),
2019-08-30 12:06:17 +02:00
nullifierHash: pedersenHash(deposit.nullifier.leInt2Buff(31)),
2019-09-06 22:54:37 +02:00
relayer: operator,
2019-11-07 08:04:29 +01:00
recipient,
2019-08-30 12:06:17 +02:00
fee,
refund,
2019-08-30 12:06:17 +02:00
// private
nullifier: deposit.nullifier,
secret: deposit.secret,
2020-07-31 19:38:50 +02:00
pathElements: pathElements,
pathIndices: pathIndices,
2019-08-30 12:06:17 +02:00
})
2019-10-04 17:20:20 +02:00
const proofData = await websnarkUtils.genWitnessAndProve(groth16, input, circuit, proving_key)
2019-11-04 20:42:41 +01:00
const { proof } = websnarkUtils.toSolidityInput(proofData)
2019-08-30 12:06:17 +02:00
2019-12-13 14:49:19 +01:00
const balanceTornadoBefore = await usdtToken.balanceOf(tornado.address)
2019-08-30 12:06:17 +02:00
const balanceRelayerBefore = await usdtToken.balanceOf(relayer)
const ethBalanceOperatorBefore = await web3.eth.getBalance(operator)
2021-10-31 15:07:39 +01:00
const balanceReceiverBefore = await usdtToken.balanceOf(toFixedHex(recipient, 20))
const ethBalanceReceiverBefore = await web3.eth.getBalance(toFixedHex(recipient, 20))
2019-12-13 14:49:19 +01:00
let isSpent = await tornado.isSpent(input.nullifierHash.toString(16).padStart(66, '0x00000'))
2019-08-30 12:06:17 +02:00
isSpent.should.be.equal(false)
// Uncomment to measure gas usage
2019-12-13 14:49:19 +01:00
// gas = await tornado.withdraw.estimateGas(proof, publicSignals, { from: relayer, gasPrice: '0' })
2019-08-30 12:06:17 +02:00
// console.log('withdraw gas:', gas)
2019-11-04 20:42:41 +01:00
const args = [
toFixedHex(input.root),
toFixedHex(input.nullifierHash),
2019-11-07 08:04:29 +01:00
toFixedHex(input.recipient, 20),
2019-11-04 20:42:41 +01:00
toFixedHex(input.relayer, 20),
toFixedHex(input.fee),
2021-02-11 07:23:18 +01:00
toFixedHex(input.refund),
2019-11-04 20:42:41 +01:00
]
2019-12-13 14:49:19 +01:00
const { logs } = await tornado.withdraw(proof, ...args, { value: refund, from: relayer, gasPrice: '0' })
2019-08-30 12:06:17 +02:00
2019-12-13 14:49:19 +01:00
const balanceTornadoAfter = await usdtToken.balanceOf(tornado.address)
2019-08-30 12:06:17 +02:00
const balanceRelayerAfter = await usdtToken.balanceOf(relayer)
const ethBalanceOperatorAfter = await web3.eth.getBalance(operator)
2021-10-31 15:07:39 +01:00
const balanceReceiverAfter = await usdtToken.balanceOf(toFixedHex(recipient, 20))
const ethBalanceReceiverAfter = await web3.eth.getBalance(toFixedHex(recipient, 20))
2019-08-30 12:06:17 +02:00
const feeBN = toBN(fee.toString())
2019-12-13 14:49:19 +01:00
balanceTornadoAfter.should.be.eq.BN(toBN(balanceTornadoBefore).sub(toBN(tokenDenomination)))
2019-08-30 12:06:17 +02:00
balanceRelayerAfter.should.be.eq.BN(toBN(balanceRelayerBefore))
ethBalanceOperatorAfter.should.be.eq.BN(toBN(ethBalanceOperatorBefore).add(feeBN))
2021-10-31 15:07:39 +01:00
balanceReceiverAfter.should.be.eq.BN(toBN(balanceReceiverBefore).add(toBN(tokenDenomination)))
ethBalanceReceiverAfter.should.be.eq.BN(toBN(ethBalanceReceiverBefore).add(toBN(refund)).sub(feeBN))
2019-08-30 12:06:17 +02:00
2019-11-01 02:12:32 +01:00
logs[0].event.should.be.equal('Withdrawal')
2019-08-30 12:06:17 +02:00
logs[0].args.nullifierHash.should.be.eq.BN(toBN(input.nullifierHash.toString()))
2019-09-06 22:54:37 +02:00
logs[0].args.relayer.should.be.eq.BN(operator)
2019-08-30 12:06:17 +02:00
logs[0].args.fee.should.be.eq.BN(feeBN)
2019-12-13 14:49:19 +01:00
isSpent = await tornado.isSpent(input.nullifierHash.toString(16).padStart(66, '0x00000'))
2019-08-30 12:06:17 +02:00
isSpent.should.be.equal(true)
})
it.skip('should work with REAL DAI', async () => {
// dont forget to specify your token in .env
2019-09-06 23:22:30 +02:00
// and send `tokenDenomination` to accounts[0] (0x90F8bf6A479f320ead074411a4B0e7944Ea8c9C1)
2019-08-30 12:06:17 +02:00
// run ganache as
2019-09-06 23:22:30 +02:00
// npx ganache-cli --fork https://kovan.infura.io/v3/27a9649f826b4e31a83e07ae09a87448@13146218 -d --keepAliveTimeout 20
2019-08-30 12:06:17 +02:00
const deposit = generateDeposit()
const user = accounts[4]
const userBal = await token.balanceOf(user)
console.log('userBal', userBal.toString())
const senderBal = await token.balanceOf(sender)
console.log('senderBal', senderBal.toString())
2020-07-31 19:38:50 +02:00
tree.insert(deposit.commitment)
2019-08-30 12:06:17 +02:00
await token.transfer(user, tokenDenomination, { from: sender })
console.log('transfer done')
const balanceUserBefore = await token.balanceOf(user)
console.log('balanceUserBefore', balanceUserBefore.toString())
2019-12-13 14:49:19 +01:00
await token.approve(tornado.address, tokenDenomination, { from: user })
2019-08-30 12:06:17 +02:00
console.log('approve done')
2019-12-13 14:49:19 +01:00
await tornado.deposit(toFixedHex(deposit.commitment), { from: user, gasPrice: '0' })
2019-08-30 12:06:17 +02:00
console.log('deposit done')
const balanceUserAfter = await token.balanceOf(user)
balanceUserAfter.should.be.eq.BN(toBN(balanceUserBefore).sub(toBN(tokenDenomination)))
2020-07-31 19:38:50 +02:00
const { pathElements, pathIndices } = tree.path(0)
2019-08-30 12:06:17 +02:00
// Circuit input
const input = stringifyBigInts({
// public
2020-07-31 19:38:50 +02:00
root: tree.root(),
2019-08-30 12:06:17 +02:00
nullifierHash: pedersenHash(deposit.nullifier.leInt2Buff(31)),
2019-09-06 22:54:37 +02:00
relayer: operator,
2019-11-07 08:04:29 +01:00
recipient,
2019-08-30 12:06:17 +02:00
fee,
refund,
2019-08-30 12:06:17 +02:00
// private
nullifier: deposit.nullifier,
secret: deposit.secret,
2020-07-31 19:38:50 +02:00
pathElements: pathElements,
pathIndices: pathIndices,
2019-08-30 12:06:17 +02:00
})
2019-10-04 17:20:20 +02:00
const proofData = await websnarkUtils.genWitnessAndProve(groth16, input, circuit, proving_key)
2019-11-04 20:42:41 +01:00
const { proof } = websnarkUtils.toSolidityInput(proofData)
2019-08-30 12:06:17 +02:00
2019-12-13 14:49:19 +01:00
const balanceTornadoBefore = await token.balanceOf(tornado.address)
2019-08-30 12:06:17 +02:00
const balanceRelayerBefore = await token.balanceOf(relayer)
const ethBalanceOperatorBefore = await web3.eth.getBalance(operator)
2021-10-31 15:07:39 +01:00
const balanceReceiverBefore = await token.balanceOf(toFixedHex(recipient, 20))
const ethBalanceReceiverBefore = await web3.eth.getBalance(toFixedHex(recipient, 20))
2019-12-13 14:49:19 +01:00
let isSpent = await tornado.isSpent(input.nullifierHash.toString(16).padStart(66, '0x00000'))
2019-08-30 12:06:17 +02:00
isSpent.should.be.equal(false)
// Uncomment to measure gas usage
2019-12-13 14:49:19 +01:00
// gas = await tornado.withdraw.estimateGas(proof, publicSignals, { from: relayer, gasPrice: '0' })
2019-08-30 12:06:17 +02:00
// console.log('withdraw gas:', gas)
2019-11-04 20:42:41 +01:00
const args = [
toFixedHex(input.root),
toFixedHex(input.nullifierHash),
2019-11-07 08:04:29 +01:00
toFixedHex(input.recipient, 20),
2019-11-04 20:42:41 +01:00
toFixedHex(input.relayer, 20),
toFixedHex(input.fee),
2021-02-11 07:23:18 +01:00
toFixedHex(input.refund),
2019-11-04 20:42:41 +01:00
]
2019-12-13 14:49:19 +01:00
const { logs } = await tornado.withdraw(proof, ...args, { value: refund, from: relayer, gasPrice: '0' })
2019-08-30 12:06:17 +02:00
console.log('withdraw done')
2019-12-13 14:49:19 +01:00
const balanceTornadoAfter = await token.balanceOf(tornado.address)
2019-08-30 12:06:17 +02:00
const balanceRelayerAfter = await token.balanceOf(relayer)
const ethBalanceOperatorAfter = await web3.eth.getBalance(operator)
2021-10-31 15:07:39 +01:00
const balanceReceiverAfter = await token.balanceOf(toFixedHex(recipient, 20))
const ethBalanceReceiverAfter = await web3.eth.getBalance(toFixedHex(recipient, 20))
2019-08-30 12:06:17 +02:00
const feeBN = toBN(fee.toString())
2019-12-13 14:49:19 +01:00
balanceTornadoAfter.should.be.eq.BN(toBN(balanceTornadoBefore).sub(toBN(tokenDenomination)))
2019-08-24 12:18:52 +02:00
balanceRelayerAfter.should.be.eq.BN(toBN(balanceRelayerBefore))
2019-08-27 22:42:24 +02:00
ethBalanceOperatorAfter.should.be.eq.BN(toBN(ethBalanceOperatorBefore).add(feeBN))
2021-10-31 15:07:39 +01:00
balanceReceiverAfter.should.be.eq.BN(toBN(balanceReceiverBefore).add(toBN(tokenDenomination)))
ethBalanceReceiverAfter.should.be.eq.BN(toBN(ethBalanceReceiverBefore).add(toBN(refund)).sub(feeBN))
2019-08-24 12:18:52 +02:00
2019-11-01 02:12:32 +01:00
logs[0].event.should.be.equal('Withdrawal')
2019-08-24 12:18:52 +02:00
logs[0].args.nullifierHash.should.be.eq.BN(toBN(input.nullifierHash.toString()))
2019-09-06 22:54:37 +02:00
logs[0].args.relayer.should.be.eq.BN(operator)
2019-08-24 12:18:52 +02:00
logs[0].args.fee.should.be.eq.BN(feeBN)
2019-12-13 14:49:19 +01:00
isSpent = await tornado.isSpent(input.nullifierHash.toString(16).padStart(66, '0x00000'))
2019-08-24 12:18:52 +02:00
isSpent.should.be.equal(true)
})
})
2019-08-20 22:39:21 +02:00
afterEach(async () => {
await revertSnapshot(snapshotId.result)
// eslint-disable-next-line require-atomic-updates
snapshotId = await takeSnapshot()
2020-07-31 19:38:50 +02:00
tree = new MerkleTree(levels)
2019-08-20 22:39:21 +02:00
})
})