Skip to main content

newton_cli/commands/
policy_files.rs

1use clap::{Parser, Subcommand};
2use eyre::{Context, Result};
3use newton_prover_core::config::NewtonAvsConfig;
4use serde::{Deserialize, Serialize};
5use std::path::PathBuf;
6use tracing;
7
8use crate::config::NewtonCliConfig;
9
10/// Policy files commands
11#[derive(Debug, Parser)]
12#[command(name = "policy-files")]
13pub struct PolicyFilesCommand {
14    #[command(subcommand)]
15    pub subcommand: PolicyFilesSubcommand,
16}
17
18#[derive(Debug, Subcommand)]
19pub enum PolicyFilesSubcommand {
20    /// Generate CIDs for policy files
21    #[command(name = "generate-cids")]
22    GenerateCids(GenerateCidsCommand),
23}
24
25/// Generate CIDs command
26#[derive(Debug, Parser)]
27pub struct GenerateCidsCommand {
28    /// Directory containing policy files (defaults to policy-files)
29    #[arg(short, long, default_value = "policy-files")]
30    directory: PathBuf,
31
32    /// Entrypoint (e.g., "newton_trading_agent.allow")
33    #[arg(long)]
34    entrypoint: String,
35
36    /// Pinata JWT (or set PINATA_JWT env var)
37    #[arg(long, env = "PINATA_JWT")]
38    pinata_jwt: Option<String>,
39
40    /// Pinata Gateway (or set PINATA_GATEWAY env var)
41    #[arg(long, env = "PINATA_GATEWAY")]
42    pinata_gateway: Option<String>,
43
44    /// Output file path (defaults to policy-files/policy_cids.json)
45    #[arg(short, long, default_value = "policy-files/policy_cids.json")]
46    output: PathBuf,
47}
48
49#[derive(Debug, Serialize, Deserialize)]
50#[allow(non_snake_case)]
51struct PolicyCids {
52    wasmCid: String,
53    policyCid: String,
54    schemaCid: String,
55    attester: String,
56    entrypoint: String,
57    policyMetadataCid: String,
58    policyDataMetadataCid: String,
59}
60
61#[derive(Debug)]
62struct FileUpload {
63    name: String,
64    path: PathBuf,
65    mime_type: String,
66    default_name_prefix: String,
67    header: String,
68    json_key: String, // Key in the PolicyCids struct
69}
70
71impl GenerateCidsCommand {
72    /// Upload a file to Pinata IPFS
73    pub async fn upload_file_to_pinata(
74        file: PathBuf,
75        jwt: String,
76        file_name: String,
77        mime_type: &str,
78    ) -> Result<String> {
79        // Check if file exists
80        if !file.exists() {
81            eyre::bail!("Error: file not found: {:?}", file);
82        }
83
84        // Read file
85        let file_data = std::fs::read(&file).with_context(|| format!("Failed to read file: {:?}", file))?;
86
87        // Get file name from path
88        let file_name_from_path = file.file_name().and_then(|n| n.to_str()).unwrap_or("file");
89
90        // Create multipart form
91        let form = reqwest::multipart::Form::new()
92            .text("pinataOptions", r#"{"cidVersion":1}"#)
93            .text("pinataMetadata", format!(r#"{{"name":"{}"}}"#, file_name))
94            .part(
95                "file",
96                reqwest::multipart::Part::bytes(file_data)
97                    .file_name(file_name_from_path.to_string())
98                    .mime_str(mime_type)
99                    .unwrap(),
100            );
101
102        // Upload to Pinata
103        let client = reqwest::Client::new();
104        let response = client
105            .post("https://api.pinata.cloud/pinning/pinFileToIPFS")
106            .header("Authorization", format!("Bearer {}", jwt))
107            .multipart(form)
108            .send()
109            .await
110            .context("Failed to send request to Pinata")?;
111
112        if !response.status().is_success() {
113            let status = response.status();
114            let error_text = response.text().await.unwrap_or_default();
115            eyre::bail!("Pinata upload failed with status {}: {}", status, error_text);
116        }
117
118        // Parse response
119        let response_json: serde_json::Value = response.json().await.context("Failed to parse Pinata response")?;
120
121        // Extract IPFS hash
122        let ipfs_hash = response_json
123            .get("IpfsHash")
124            .and_then(|v| v.as_str())
125            .ok_or_else(|| eyre::eyre!("IPFS hash not found in response"))?;
126
127        Ok(ipfs_hash.to_string())
128    }
129
130    /// Display upload results
131    pub fn display_upload_results(ipfs_hash: &str, gateway: &str) {
132        tracing::info!("\n=== IPFS Upload Results ===");
133        tracing::info!("IPFS Hash: {}", ipfs_hash);
134        // Construct gateway links
135        let gateway_link = if gateway.ends_with('/') {
136            format!("{}{}", gateway, ipfs_hash)
137        } else {
138            format!("{}/{}", gateway, ipfs_hash)
139        };
140
141        tracing::info!(gateway_link = %gateway_link, "Direct IPFS Link");
142        tracing::info!("Public IPFS Link: https://ipfs.io/ipfs/{}", ipfs_hash);
143    }
144
145    /// Execute the generate-cids command
146    pub async fn execute(self: Box<Self>, _config: NewtonAvsConfig<NewtonCliConfig>) -> Result<()> {
147        // Get Pinata credentials
148        let jwt = self
149            .pinata_jwt
150            .ok_or_else(|| eyre::eyre!("Pinata JWT is required. Set PINATA_JWT env var or use --pinata-jwt"))?;
151
152        let gateway = self.pinata_gateway.ok_or_else(|| {
153            eyre::eyre!("Pinata Gateway is required. Set PINATA_GATEWAY env var or use --pinata-gateway")
154        })?;
155
156        // Define all files to upload in the correct order
157        let files_to_upload = vec![
158            FileUpload {
159                name: "policy.wasm".to_string(),
160                path: self.directory.join("policy.wasm"),
161                mime_type: "application/wasm".to_string(),
162                default_name_prefix: "newton-policy-wasm".to_string(),
163                header: "============ Upload policy.wasm ================".to_string(),
164                json_key: "wasmCid".to_string(),
165            },
166            FileUpload {
167                name: "policy.rego".to_string(),
168                path: self.directory.join("policy.rego"),
169                mime_type: "text/plain".to_string(),
170                default_name_prefix: "newton-policy".to_string(),
171                header: "============== Upload policy.rego ==============".to_string(),
172                json_key: "policyCid".to_string(),
173            },
174            FileUpload {
175                name: "params_schema.json".to_string(),
176                path: self.directory.join("params_schema.json"),
177                mime_type: "application/json".to_string(),
178                default_name_prefix: "newton-policy-schema".to_string(),
179                header: "========== Upload params_schema.json ===========".to_string(),
180                json_key: "schemaCid".to_string(),
181            },
182            FileUpload {
183                name: "policy_metadata.json".to_string(),
184                path: self.directory.join("policy_metadata.json"),
185                mime_type: "application/json".to_string(),
186                default_name_prefix: "newton-policy-metadata".to_string(),
187                header: "========== Upload policy_metadata.json =========".to_string(),
188                json_key: "policyMetadataCid".to_string(),
189            },
190            FileUpload {
191                name: "policy_data_metadata.json".to_string(),
192                path: self.directory.join("policy_data_metadata.json"),
193                mime_type: "application/json".to_string(),
194                default_name_prefix: "newton-policy-data-metadata".to_string(),
195                header: "======== Upload policy_data_metadata.json ======".to_string(),
196                json_key: "policyDataMetadataCid".to_string(),
197            },
198        ];
199
200        tracing::info!("================================================");
201        tracing::info!("========== Uploading All Policy Files ==========");
202        tracing::info!("================================================");
203        tracing::info!("Directory: {:?}", self.directory);
204        tracing::info!("");
205        let mut ipfs_hashes: std::collections::HashMap<String, String> = std::collections::HashMap::new();
206        // Upload each file and collect IPFS hashes
207        for file_upload in files_to_upload {
208            tracing::info!("================================================");
209            tracing::info!("{}", file_upload.header);
210            tracing::info!("================================================");
211
212            // Check if file exists
213            if !file_upload.path.exists() {
214                eyre::bail!("Error: {} not found in {:?}", file_upload.name, self.directory);
215            }
216
217            // Generate file name
218            let file_name = format!(
219                "{}-{}",
220                file_upload.default_name_prefix,
221                chrono::Utc::now().format("%Y%m%d-%H%M%S")
222            );
223
224            tracing::info!(path = %file_upload.path.display(), "Uploading to Pinata IPFS");
225
226            match Self::upload_file_to_pinata(file_upload.path.clone(), jwt.clone(), file_name, &file_upload.mime_type)
227                .await
228            {
229                Ok(ipfs_hash) => {
230                    Self::display_upload_results(&ipfs_hash, &gateway);
231                    ipfs_hashes.insert(file_upload.json_key.clone(), ipfs_hash);
232                }
233                Err(e) => {
234                    eyre::bail!("Error uploading {}: {}", file_upload.name, e);
235                }
236            }
237            tracing::info!("");
238        }
239
240        // Create PolicyCids struct
241        let policy_cids = PolicyCids {
242            wasmCid: ipfs_hashes
243                .get("wasmCid")
244                .ok_or_else(|| eyre::eyre!("Missing wasmCid"))?
245                .clone(),
246            policyCid: ipfs_hashes
247                .get("policyCid")
248                .ok_or_else(|| eyre::eyre!("Missing policyCid"))?
249                .clone(),
250            schemaCid: ipfs_hashes
251                .get("schemaCid")
252                .ok_or_else(|| eyre::eyre!("Missing schemaCid"))?
253                .clone(),
254            attester: "0x4883282094755C01cd0d15dFE74753c9E189d194".to_string(),
255            entrypoint: self.entrypoint.clone(),
256            policyMetadataCid: ipfs_hashes
257                .get("policyMetadataCid")
258                .ok_or_else(|| eyre::eyre!("Missing policyMetadataCid"))?
259                .clone(),
260            policyDataMetadataCid: ipfs_hashes
261                .get("policyDataMetadataCid")
262                .ok_or_else(|| eyre::eyre!("Missing policyDataMetadataCid"))?
263                .clone(),
264        };
265
266        // Write to JSON file
267        let json_content =
268            serde_json::to_string_pretty(&policy_cids).context("Failed to serialize policy_cids to JSON")?;
269
270        // Create parent directory if it doesn't exist
271        if let Some(parent) = self.output.parent() {
272            std::fs::create_dir_all(parent).with_context(|| format!("Failed to create directory: {:?}", parent))?;
273        }
274
275        std::fs::write(&self.output, json_content)
276            .with_context(|| format!("Failed to write to file: {:?}", self.output))?;
277
278        tracing::info!("================================================");
279        tracing::info!("========== Created policy_cids.json ============");
280        tracing::info!("================================================");
281        tracing::info!("Output file: {:?}", self.output);
282        tracing::info!("");
283        tracing::info!("{}", std::fs::read_to_string(&self.output)?);
284
285        tracing::info!("Successfully created policy_cids.json");
286
287        Ok(())
288    }
289}
290
291impl PolicyFilesCommand {
292    /// Execute the policy-files command
293    pub async fn execute(self: Box<Self>, config: NewtonAvsConfig<NewtonCliConfig>) -> eyre::Result<()> {
294        match self.subcommand {
295            PolicyFilesSubcommand::GenerateCids(command) => {
296                Box::new(command).execute(config).await?;
297            }
298        }
299        Ok(())
300    }
301}