变更日志
- 09-07-2020: 初始草案
- 11-08-2020: 实现变更
状态
已接受,已实现背景
IBC 跨链同质化代币转账的规范 (ICS20) 需要 感知任意代币面额的来源,才能中继一个包含发送方和接收方地址的Packet,这些地址位于
FungibleTokenPacketData
中。
Packet 中继发送基于两种情况运作(依据
规范 和 Colin Axnér 的说明):
- 发送链充当源区(source zone)。代币会被转入发送链上的托管地址(即锁定),然后通过 IBC TAO 逻辑转移到接收链。预期接收链会向接收地址铸造凭证代币。
- 发送链充当汇区(sink zone)。代币(凭证)会在发送链上销毁,然后通过 IBC TAO 逻辑转移到接收链。预期此前发送过原始面额的接收链会将该同质化代币解托管,并发送到接收地址。
示例
假设存在如下通道连接,并且所有通道都使用端口 IDtransfer:
- 链
A与链B、链C分别有通道,ID 分别为channelToB和channelToC - 链
B与链A、链C分别有通道,ID 分别为channelToA和channelToC - 链
C与链A、链B分别有通道,ID 分别为channelToA和channelToB
A -> B -> C -> A -> C。具体如下:
A -> B:发送链是源区。A发送携带denom的 packet(在A上托管),B接收denom并铸造、发送凭证transfer/channelToA/denom给接收方。B -> C:发送链是源区。B发送携带transfer/channelToA/denom的 packet(在B上托管),C接收transfer/channelToA/denom并铸造、发送凭证transfer/channelToB/transfer/channelToA/denom给接收方。C -> A:发送链是源区。C发送携带transfer/channelToB/transfer/channelToA/denom的 packet(在C上托管),A接收transfer/channelToB/transfer/channelToA/denom并铸造、发送凭证transfer/channelToC/transfer/channelToB/transfer/channelToA/denom给接收方。A -> C:发送链是汇区。A发送携带transfer/channelToC/transfer/channelToB/transfer/channelToA/denom的 packet(在A上销毁),C接收transfer/channelToC/transfer/channelToB/transfer/channelToA/denom,并将transfer/channelToB/transfer/channelToA/denom解托管后发送给接收方。
C 上的最终面额为 transfer/channelToB/transfer/channelToA/denom,其中 transfer/channelToB/transfer/channelToA 是追踪信息。
在这个上下文中,当接收到跨链同质化代币转账时,如果发送链是该代币的源链,协议会按照以下格式,将端口和通道标识符前缀添加到面额前:
100 uatom 从 Hub 上的端口 HubPort 和通道 HubChannel 转到 Ethermint 的端口 EthermintPort 和通道 EthermintChannel,结果会得到 100 EthermintPort/EthermintChannel/uatom,其中 EthermintPort/EthermintChannel/uatom 是接收链上的新面额。
如果这些代币被转回 Hub(即 源 链),前缀会被裁剪掉,代币面额也会更新回原始值。
问题
向代币面额中添加额外信息的问题有两个方面:- 如果代币被转移到源链以外的其他 zone,长度会持续增长:
n 次,那么该代币的面额将包含 n 对前缀,如上面的格式示例所示。这会带来问题,因为虽然端口和通道标识符各自的最大长度都是 64,但 SDK 的 Coin 类型只接受长度不超过 64 个字符的面额。因此,一个跨链代币本身由端口与通道标识符再加上基础面额组成,就可能超过 SDK Coins 的长度校验限制。
这可能导致一些不期望的行为,例如如果面额超长,代币将无法继续转到多个汇链,或者由于接收链上的面额校验失败而出现意外的 panics。
- 面额中存在特殊字符和大写字母:
NewCoin 初始化一个 Coin 时,都会根据一个
Regex
对币种面额进行校验,其中只接受小写字母数字字符。对于原生面额来说,这有利于保持良好的 UX,但对于 IBC 来说则带来了挑战,因为根据 ICS 024 - Host
Requirements
规范,端口和通道可能会随机生成,并包含特殊字符和大写字符。
决策
上述问题只适用于基于 SDK 的链,因此所提出的解决方案不需要修改规范,也不会要求调整 ICS20 规范的其他实现。 提议的方案不是直接把标识符加到代币面额上,而是对面额前缀进行哈希,以便为所有跨链同质化代币得到一致的长度。 这只会用于内部存储;而当通过 IBC 转移到另一条链时,packet 数据中指定的面额仍会是完整的标识符前缀路径,以便按照 ICS20 的规定将代币追溯回其源链。 新的建议格式如下:DenomTrace 字段进行 SHA256 哈希:
IBCDenom 函数会在创建 ICS20 同质化代币 packet 数据时,构造所使用的 Coin 面额:
x/ibc-transfer 变更
为了从 IBC 面额中取回 trace 信息,需要在 ibc-transfer 模块中新增一个查找表。
这些值还需要在升级之间持久化,这意味着需要在模块中新增一个 []DenomTrace 的 GenesisState 字段:
MsgTransfer 会校验 Token 字段中的 Coin 面额:如果提供了 trace 信息,则其中必须包含有效哈希;否则必须与基础面额匹配:
- 接收方是源链:接收方创建了该代币,因此必须已经存储了 trace 查找信息(如有必要;例如原生代币场景就不需要查找)。
- 接收方不是源链:存储收到的信息。例如,在步骤 1 中,当链
B接收到transfer/channelToA/denom时。
FungibleTokenPacketData 将保持不变,也就是说仍然使用带前缀的完整面额,因为接收链可能不是基于 SDK 的链。
Coin 变更
Coin 面额校验需要更新以反映这些变化。具体来说,面额校验函数现在将:- 接受斜杠分隔符(
"/")和大写字符(因为HexBytes格式) - 将最大字符长度提升到 128,因为 Tendermint 的
HexBytes类型所使用的十六进制表示包含 64 个字符。
优点
- 更清晰地区分代币的来源追踪行为(transfer 前缀)与原始
Coin面额 Coin字段的校验更加一致(即不包含特殊字符、最大长度固定)- IBC 的
Coin和标准面额更简洁 - SDK 的
Coin无需新增字段
缺点
- 需要在
ibc-transfer模块存储中保存每一组 trace 面额标识 - 客户端每次通过 IBC 接收到新的中继同质化代币时,都必须获取其基础面额。可以通过在客户端侧使用映射或缓存已见过的哈希来缓解。其他缓解方式还包括建立 websocket 连接并订阅传入事件。
中性影响
- 与 ICS20 规范存在轻微差异
- 在
ibc-transfer模块中增加了针对 IBC Coin 的额外校验逻辑 - 增加了额外的创世字段
- 由于需要访问存储,跨链转账的 gas 使用量会略有增加。如果转账频繁,这部分应可通过区块间缓存进行优化。
参考资料
Changelog
- 09-07-2020: Initial Draft
- 11-08-2020: Implementation changes
Status
Accepted, ImplementedContext
The specification for IBC cross-chain fungible token transfers (ICS20), needs to be aware of the origin of any token denomination in order to relay aPacket which contains the sender
and recipient addresses in the
FungibleTokenPacketData.
The Packet relay sending works based in 2 cases (per
specification and Colin Axnér’s description):
- Sender chain is acting as the source zone. The coins are transferred to an escrow address (i.e locked) on the sender chain and then transferred to the receiving chain through IBC TAO logic. It is expected that the receiving chain will mint vouchers to the receiving address.
- Sender chain is acting as the sink zone. The coins (vouchers) are burned on the sender chain and then transferred to the receiving chain through IBC TAO logic. It is expected that the receiving chain, which had previously sent the original denomination, will unescrow the fungible token and send it to the receiving address.
Example
Assume the following channel connections exist and that all channels use the port IDtransfer:
- chain
Ahas channels with chainBand chainCwith the IDschannelToBandchannelToC, respectively - chain
Bhas channels with chainAand chainCwith the IDschannelToAandchannelToC, respectively - chain
Chas channels with chainAand chainBwith the IDschannelToAandchannelToB, respectively
A -> B -> C -> A -> C. In particular:
A -> B: sender chain is source zone.Asends packet withdenom(escrowed onA),Breceivesdenomand mints and sends vouchertransfer/channelToA/denomto recipient.B -> C: sender chain is source zone.Bsends packet withtransfer/channelToA/denom(escrowed onB),Creceivestransfer/channelToA/denomand mints and sends vouchertransfer/channelToB/transfer/channelToA/denomto recipient.C -> A: sender chain is source zone.Csends packet withtransfer/channelToB/transfer/channelToA/denom(escrowed onC),Areceivestransfer/channelToB/transfer/channelToA/denomand mints and sends vouchertransfer/channelToC/transfer/channelToB/transfer/channelToA/denomto recipient.A -> C: sender chain is sink zone.Asends packet withtransfer/channelToC/transfer/channelToB/transfer/channelToA/denom(burned onA),Creceivestransfer/channelToC/transfer/channelToB/transfer/channelToA/denom, and unescrows and sendstransfer/channelToB/transfer/channelToA/denomto recipient.
C of transfer/channelToB/transfer/channelToA/denom, where transfer/channelToB/transfer/channelToA is the trace information.
In this context, upon a receive of a cross-chain fungible token transfer, if the sender chain is the source of the token, the protocol prefixes the denomination with the port and channel identifiers in the following format:
100 uatom from port HubPort and channel HubChannel on the Hub to
Ethermint’s port EthermintPort and channel EthermintChannel results in 100 EthermintPort/EthermintChannel/uatom, where EthermintPort/EthermintChannel/uatom is the new
denomination on the receiving chain.
In the case those tokens are transferred back to the Hub (i.e the source chain), the prefix is
trimmed and the token denomination updated to the original one.
Problem
The problem of adding additional information to the coin denomination is twofold:- The ever increasing length if tokens are transferred to zones other than the source:
n times via IBC to a sink chain, the token denom will contain n pairs
of prefixes, as shown on the format example above. This poses a problem because, while port and
channel identifiers have a maximum length of 64 each, the SDK Coin type only accepts denoms up to
64 characters. Thus, a single cross-chain token, which again, is composed by the port and channels
identifiers plus the base denomination, can exceed the length validation for the SDK Coins.
This can result in undesired behaviours such as tokens not being able to be transferred to multiple
sink chains if the denomination exceeds the length or unexpected panics due to denomination
validation failing on the receiving chain.
- The existence of special characters and uppercase letters on the denomination:
Coin is initialized through the constructor function NewCoin, a validation
of a coin’s denom is performed according to a
Regex,
where only lowercase alphanumeric characters are accepted. While this is desirable for native denominations
to keep a clean UX, it presents a challenge for IBC as ports and channels might be randomly
generated with special and uppercase characters as per the ICS 024 - Host
Requirements
specification.
Decision
The issues outlined above, are applicable only to SDK-based chains, and thus the proposed solution are do not require specification changes that would result in modification to other implementations of the ICS20 spec. Instead of adding the identifiers on the coin denomination directly, the proposed solution hashes the denomination prefix in order to get a consistent length for all the cross-chain fungible tokens. This will be used for internal storage only, and when transferred via IBC to a different chain, the denomination specified on the packed data will be the full prefix path of the identifiers needed to trace the token back to the originating chain, as specified on ICS20. The new proposed format will be the following:DenomTrace:
IBCDenom function constructs the Coin denomination used when creating the ICS20 fungible token packet data:
x/ibc-transfer Changes
In order to retrieve the trace information from an IBC denomination, a lookup table needs to be
added to the ibc-transfer module. These values need to also be persisted between upgrades, meaning
that a new []DenomTrace GenesisState field state needs to be added to the module:
MsgTransfer will validate that the Coin denomination from the Token field contains a valid
hash, if the trace info is provided, or that the base denominations matches:
- Receiver is source chain: The receiver created the token and must have the trace lookup already stored (if necessary ie native token case wouldn’t need a lookup).
- Receiver is not source chain: Store the received info. For example, during step 1, when chain
Breceivestransfer/channelToA/denom.
FungibleTokenPacketData will remain the same, i.e with the prefixed full denomination, since the receiving chain may not be an SDK-based chain.
Coin Changes
The coin denomination validation will need to be updated to reflect these changes. In particular, the denomination validation function will now:- Accept slash separators (
"/") and uppercase characters (due to theHexBytesformat) - Bump the maximum character length to 128, as the hex representation used by Tendermint’s
HexBytestype contains 64 characters.
Positive
- Clearer separation of the source tracing behaviour of the token (transfer prefix) from the original
Coindenomination - Consistent validation of
Coinfields (i.e no special characters, fixed max length) - Cleaner
Coinand standard denominations for IBC - No additional fields to SDK
Coin
Negative
- Store each set of tracing denomination identifiers on the
ibc-transfermodule store - Clients will have to fetch the base denomination every time they receive a new relayed fungible token over IBC. This can be mitigated using a map/cache for already seen hashes on the client side. Other forms of mitigation, would be opening a websocket connection subscribe to incoming events.
Neutral
- Slight difference with the ICS20 spec
- Additional validation logic for IBC coins on the
ibc-transfermodule - Additional genesis fields
- Slightly increases the gas usage on cross-chain transfers due to access to the store. This should be inter-block cached if transfers are frequent.