Skip to content

feat(calltx): add CALL account-access attack contract - #291

Open
LouisTsai-Csie wants to merge 3 commits into
ethpandaops:masterfrom
LouisTsai-Csie:calltx-attack-contract
Open

LouisTsai-Csie wants to merge 3 commits into
ethpandaops:masterfrom
LouisTsai-Csie:calltx-attack-contract

Conversation

@LouisTsai-Csie

@LouisTsai-Csie LouisTsai-Csie commented Sep 18, 2026 •

Copy link
Copy Markdown

Summary

Adds the CALL account-access attack contract: a port of the
opcode = CALL, overhead_baseline = False arm of test_account_access from
execution-specs,
as a minimal geas contract plus a matching callAttack function on the existing
solidity controller.

It targets the CREATE2 addresses deployed by the factorydeploytx scenario and
derives them on-chain, so a run carries three inputs - factory, initcode hash
and salt range - rather than a list of addresses.

File
contracts/ContractCallAttack.geas runtime, 60 bytes of bytecode
contracts/ContractCallAttackCtor.geas deploy code
contracts/ContractReadAttackController.sol callAttack + receive(), the readable twin

Design

The memory layout is byte-for-byte the Create2PreimageLayout(offset=0) of
execution-specs:

mem[0x0b]       = 0xff
mem[0x0c..0x1f] = factory
mem[0x20..0x3f] = salt          <- rewritten every iteration
mem[0x40..0x5f] = initCodeHash
target = keccak256(mem[0x0b], 85)

The salt walk is monotonic - startSalt, startSalt + 1, ... with no
wrap-around - matching its increment_salt_op, so keeping the walk inside the
deployed range is the caller's job. Following the upstream Op.CALL defaults
(kwargs_defaults={"gas": GAS}), the call is
CALL(gas(), target, callValue, 0, 0, 0, 0).

Both implementations share one ABI, so the same arguments drive either:

callAttack(address factory, bytes32 initCodeHash, uint256 startSalt, uint256 callValue, uint256 gasBuffer)

callValue selects the two arms the benchmark parametrises: 0 measures the
cold account access alone, 1 adds the value transfer.

Notes

The README documents the contract with --call-fn-sig / --call-args, which
works on master as it stands. #290 adds a --targets-file option to calltx
that generates the same call data from a CREATE2 receiver list and advances
startSalt per transaction; the two are independent and can land in either
order.

@LouisTsai-Csie
LouisTsai-Csie marked this pull request as ready for review September 29, 2026 09:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant