false
false
0
The new Blockscout UI is now open source! Learn how to
deploy it here
Taiko Internal L1 Devnet
Blockchain
Blocks
Blocks
Uncles
Forked Blocks (Reorgs)
Transactions
Validated
Pending
Verified contracts
Tokens
All
ETH
APIs
GraphQL
RPC
Eth RPC
Internal L1 Devnet
Testnets
Taiko Internal L2 Devnet
/
Search
/
Search
Connection Lost
New Solidity Smart Contract Verification
Contract Address
The 0x address supplied on contract creation.
Is Yul contract
No
Yes
Select Yes if you want to verify Yul contract.
Contract Name
Must match the name specified in the code. For example, in
contract MyContract {..}
MyContract
is the contract name.
Include nightly builds
No
Yes
Select yes if you want to show nightly builds.
Compiler
v0.8.37+commit.f401782d
v0.8.36+commit.8a079791
v0.8.35+commit.47b9dedd
v0.8.35-pre.1+commit.a99b6d8c
v0.8.34+commit.80d5c536
v0.8.33+commit.64118f21
v0.8.32+commit.ebbd65e5
v0.8.31+commit.fd3a2265
v0.8.31-pre.1+commit.b59566f6
v0.8.30+commit.73712a01
v0.8.29+commit.ab55807c
v0.8.28+commit.7893614a
v0.8.27+commit.40a35a09
v0.8.26+commit.8a97fa7a
v0.8.25+commit.b61c2a91
v0.8.24+commit.e11b9ed9
v0.8.23+commit.f704f362
v0.8.22+commit.4fc1097e
v0.8.21+commit.d9974bed
v0.8.20+commit.a1b79de6
v0.8.19+commit.7dd6d404
v0.8.18+commit.87f61d96
v0.8.17+commit.8df45f5f
v0.8.16+commit.07a7930e
v0.8.15+commit.e14f2714
v0.8.14+commit.80d49f37
v0.8.13+commit.abaa5c0e
v0.8.12+commit.f00d7308
v0.8.11+commit.d7f03943
v0.8.10+commit.fc410830
v0.8.9+commit.e5eed63a
v0.8.8+commit.dddeac2f
v0.8.7+commit.e28d00a7
v0.8.6+commit.11564f7e
v0.8.5+commit.a4f2e591
v0.8.4+commit.c7e474f2
v0.8.3+commit.8d00100c
v0.8.2+commit.661d1103
v0.8.1+commit.df193b15
v0.8.0+commit.c7dfd78e
v0.7.6+commit.7338295f
v0.7.5+commit.eb77ed08
v0.7.4+commit.3f05b770
v0.7.3+commit.9bfce1f6
v0.7.2+commit.51b20bc0
v0.7.1+commit.f4a555be
v0.7.0+commit.9e61f92b
v0.6.12+commit.27d51765
v0.6.11+commit.5ef660b1
v0.6.10+commit.00c0fcaf
v0.6.9+commit.3e3065ac
v0.6.8+commit.0bbfe453
v0.6.7+commit.b8d736ae
v0.6.6+commit.6c089d02
v0.6.5+commit.f956cc89
v0.6.4+commit.1dca32f3
v0.6.3+commit.8dda9521
v0.6.2+commit.bacdbe57
v0.6.1+commit.e6f7d5a4
v0.6.0+commit.26b70077
v0.5.17+commit.d19bba13
v0.5.16+commit.9c3226ce
v0.5.15+commit.6a57276f
v0.5.14+commit.01f1aaa4
v0.5.13+commit.5b0b510c
v0.5.12+commit.7709ece9
v0.5.11+commit.22be8592
v0.5.10+commit.5a6ea5b1
v0.5.9+commit.c68bc34e
v0.5.8+commit.23d335f2
v0.5.7+commit.6da8b019
v0.5.6+commit.b259423e
v0.5.5+commit.47a71e8f
v0.5.4+commit.9549d8ff
v0.5.3+commit.10d17f24
v0.5.2+commit.1df8f40c
v0.5.1+commit.c8a2cb62
v0.5.0+commit.1d4f565a
v0.4.26+commit.4563c3fc
v0.4.25+commit.59dbf8f1
v0.4.24+commit.e67f0147
v0.4.23+commit.124ca40d
v0.4.22+commit.4cb486ee
v0.4.21+commit.dfe3193c
v0.4.20+commit.3155dd80
v0.4.19+commit.c4cbbb05
v0.4.18+commit.9cf6e910
v0.4.17+commit.bdeb9e52
v0.4.16+commit.d7661dd9
v0.4.15+commit.8b45bddb
v0.4.14+commit.c2215d46
v0.4.13+commit.0fb4cb1a
v0.4.12+commit.194ff033
v0.4.11+commit.68ef5810
v0.4.10+commit.9e8cc01b
The compiler version is specified in
pragma solidity X.X.X
. Use the compiler version rather than the nightly build. If using the Solidity compiler, run
solc —version
to check.
EVM Version
homestead
tangerineWhistle
spuriousDragon
byzantium
constantinople
petersburg
istanbul
berlin
london
paris
shanghai
cancun
default
The EVM version the contract is written for. If the bytecode does not match the version, we try to verify using the latest EVM version.
EVM version details
.
Optimization
No
Yes
If you enabled optimization during compilation, select yes.
Optimization runs
Enter the Solidity Contract Code
// SPDX-License-Identifier: MIT pragma solidity ^0.8.26; import { SgxVerifier } from "./SgxVerifier.sol"; import { TCBStatus } from "@automata-network/on-chain-pccs/helpers/FmspcTcbHelper.sol"; /// @title SecureSgxVerifier /// @notice SGX verifier for mainnet/production: the strict TCB-status policy plus a per-MRENCLAVE /// ATTRIBUTES pin. On top of the universal forbidden-attribute floor enforced by `SgxVerifier` /// (DEBUG / PROVISION_KEY / EINITTOKEN_KEY), every allowlisted enclave measurement must declare the /// exact ATTRIBUTES profile it is allowed to register with. Registration of an enclave with no /// configured policy fails closed, so permissionless registration cannot admit an attribute /// combination (e.g. a reserved bit, or a missing INIT/MODE64BIT) that the global deny-mask alone /// would not catch. /// @custom:security-contact security@taiko.xyz contract SecureSgxVerifier is SgxVerifier { /// @notice The ATTRIBUTES profile an allowlisted enclave measurement is pinned to. A /// registering quote is accepted only when `quoteAttributes & mask == expected`. A zero `mask` /// means no policy is configured and registration for that MRENCLAVE is rejected. /// @param mask The ATTRIBUTES bits that are checked. /// @param expected The required value of the checked bits (must have no bit set outside `mask`). struct AttributePolicy { bytes16 mask; bytes16 expected; } /// @notice The ATTRIBUTES pin for each allowlisted application-enclave measurement. mapping(bytes32 mrEnclave => AttributePolicy policy) public enclaveAttributePolicy; /// @notice A security delay between a non-owner registration via `registerInstance` and the /// instance becoming usable for proof verification. It gives off-chain monitoring a window to /// evict a rogue self-registered instance (via `deleteInstances`) before it can prove. Owner /// registrations — `addInstances`, or `registerInstance` called by the owner — are NOT delayed. /// Set once at construction (mainnet/testnet deployments use 24 hours); it must be non-zero and /// must not exceed `INSTANCE_EXPIRY`. uint64 public immutable instanceValidityDelay; /// @notice Emitted when an MRENCLAVE's ATTRIBUTES pin is set or updated. /// @param mrEnclave The application-enclave measurement. /// @param mask The checked ATTRIBUTES bits. /// @param expected The required value of the checked bits. /// @param version The new policy version; instances registered under this pin record it and are /// revoked once it no longer matches. event EnclaveAttributePolicySet( bytes32 indexed mrEnclave, bytes16 mask, bytes16 expected, uint32 version ); /// @notice Emitted when an MRENCLAVE's ATTRIBUTES pin is removed. /// @param mrEnclave The application-enclave measurement. event EnclaveAttributePolicyRemoved(bytes32 indexed mrEnclave); constructor( uint64 _taikoChainId, address _owner, address _automataDcapAttestation, address _registrar, uint64 _instanceValidityDelay ) SgxVerifier(_taikoChainId, _owner, _automataDcapAttestation, _registrar) { // The delay must be positive (a zero delay defeats the monitoring window) and no longer than // the validity window itself. require( _instanceValidityDelay > 0 && _instanceValidityDelay <= INSTANCE_EXPIRY, SGX_INVALID_VALIDITY_DELAY() ); instanceValidityDelay = _instanceValidityDelay; } /// @dev Restricts a call to the owner or `_addr` (used for `removeEnclaveAttributePolicy` with /// the registrar). /// @param _addr The additional address allowed alongside the owner. modifier onlyOwnerOr(address _addr) { require(msg.sender == owner() || msg.sender == _addr, SGX_NOT_AUTHORIZED()); _; } /// @notice Sets (or updates) the ATTRIBUTES pin for an allowlisted enclave measurement. /// @dev The mask must cover every universally-forbidden bit and the expected value must clear /// them, so a per-enclave pin can never re-admit a debug/provisioning/launch enclave; the /// expected value must not assert any bit outside the mask. /// @param _mrEnclave The application-enclave measurement to pin. /// @param _mask The ATTRIBUTES bits to check (must be non-zero and cover the forbidden bits). /// @param _expected The required value of the checked bits. function setEnclaveAttributePolicy( bytes32 _mrEnclave, bytes16 _mask, bytes16 _expected ) external onlyOwner { // A non-zero mask is what marks the policy as configured. require(_mask != bytes16(0), SGX_INVALID_ATTRIBUTE_POLICY()); // The expected value must not assert any bit the mask does not check. require(_expected & ~_mask == bytes16(0), SGX_INVALID_ATTRIBUTE_POLICY()); // The mask must check every universally-forbidden bit and the expected value must clear // them: the per-enclave pin can never re-admit a debug/provisioning/launch enclave. require( _mask & SGX_FORBIDDEN_ATTRIBUTE_MASK == SGX_FORBIDDEN_ATTRIBUTE_MASK, SGX_INVALID_ATTRIBUTE_POLICY() ); require( _expected & SGX_FORBIDDEN_ATTRIBUTE_MASK == bytes16(0), SGX_INVALID_ATTRIBUTE_POLICY() ); // Bump the version on every set (including an in-place edit) so any change revokes instances // registered under the previous pin. The counter is never reset, so a removed-then-re-added // pin gets a brand-new version and cannot re-enable previously registered instances. The // version shares the per-MRENCLAVE slot with the allowlist flag, so `verifyProof` reads both // in one SLOAD. uint32 version = mrEnclaveState[_mrEnclave].policyVersion + 1; mrEnclaveState[_mrEnclave].policyVersion = version; enclaveAttributePolicy[_mrEnclave] = AttributePolicy(_mask, _expected); emit EnclaveAttributePolicySet(_mrEnclave, _mask, _expected, version); } /// @notice Returns the current per-MRENCLAVE policy version (the generation an instance must still /// match to verify proofs). Zero means the pin was never set. /// @param _mrEnclave The application-enclave measurement. /// @return The current policy version. function enclaveAttributePolicyVersion(bytes32 _mrEnclave) external view returns (uint32) { return mrEnclaveState[_mrEnclave].policyVersion; } /// @notice Removes the ATTRIBUTES pin for an enclave measurement. Registration for that MRENCLAVE /// then fails closed until a new pin is set, and — because `verifyProof` re-checks the current pin /// — every instance already registered under it is revoked (invalidated, not deleted) and can no /// longer verify proofs. /// @dev Callable by the owner or the `registrar` (the SGX-instance registrar set at /// construction); the registrar can only remove pins, so it can fail-close a compromised enclave /// but cannot relax or re-admit one. When `registrar` is `address(0)`, removal is owner-only. /// Removal bumps the monotonic policy version (so `verifyProof` needs only a single version /// comparison to reject revoked instances) and the counter is never reset, so a later re-add gets /// a fresh version and cannot re-enable the revoked instances. /// @param _mrEnclave The application-enclave measurement whose pin is removed. function removeEnclaveAttributePolicy(bytes32 _mrEnclave) external onlyOwnerOr(registrar) { require( enclaveAttributePolicy[_mrEnclave].mask != bytes16(0), SGX_ATTRIBUTE_POLICY_NOT_SET() ); // Bump the version so every instance registered under this pin is revoked at proof time by a // single version mismatch; no live instance can hold the bumped version because registration // for this MRENCLAVE is now fail-closed until a new pin is set (which bumps again). mrEnclaveState[_mrEnclave].policyVersion += 1; delete enclaveAttributePolicy[_mrEnclave]; emit EnclaveAttributePolicyRemoved(_mrEnclave); } /// @inheritdoc SgxVerifier /// @dev Strict policy: accept the TCB statuses whose platform microcode is up to date — `OK`, /// `TCB_SW_HARDENING_NEEDED` and `TCB_CONFIGURATION_AND_SW_HARDENING_NEEDED` (their mitigations /// live in configuration / enclave software pinned by the MRENCLAVE allowlist, not in microcode). /// The out-of-date statuses (`TCB_OUT_OF_DATE`, `TCB_OUT_OF_DATE_CONFIGURATION_NEEDED`) are /// rejected, where the platform may be missing the microcode that patches SGX key-extraction /// vulnerabilities (so the in-enclave signing key could be extractable); `TCB_CONFIGURATION_NEEDED`, /// `TCB_REVOKED` and `TCB_UNRECOGNIZED` are rejected too. The policy is expressed against the /// attestation's `TCBStatus` enum so an enum reorder is caught at compile time. function isTcbStatusAccepted(uint8 _status) public pure override returns (bool) { return _status == uint8(TCBStatus.OK) || _status == uint8(TCBStatus.TCB_SW_HARDENING_NEEDED) || _status == uint8(TCBStatus.TCB_CONFIGURATION_AND_SW_HARDENING_NEEDED); } /// @inheritdoc SgxVerifier /// @dev Fail-closed per-MRENCLAVE ATTRIBUTES pin: the enclave must have a configured policy and /// its attested ATTRIBUTES must match the pinned profile over the checked bits. Returns the /// current policy version so it is recorded on the instance for the `verifyProof` re-check. function _validateEnclaveAttributes( bytes32 _mrEnclave, bytes16 _attributes ) internal view override returns (uint32 policyVersion_) { AttributePolicy memory policy = enclaveAttributePolicy[_mrEnclave]; require(policy.mask != bytes16(0), SGX_ATTRIBUTE_POLICY_NOT_SET()); require(_attributes & policy.mask == policy.expected, SGX_ATTRIBUTE_MISMATCH()); return mrEnclaveState[_mrEnclave].policyVersion; } /// @inheritdoc SgxVerifier /// @dev Additionally requires the per-MRENCLAVE pin that gated registration to still be in force: /// any edit, or a removal (which bumps the version too), changes the version so the recorded /// version no longer matches and the instance is revoked. Owner-added instances (`mrEnclave == 0`) /// are exempt, and the base trusted-MRENCLAVE/MRSIGNER allowlist re-check still applies on top. /// Reads the per-MRENCLAVE slot once: it carries both the current version and the allowlist flag. function _isEnclaveStillTrusted(Instance memory _instance) internal view override returns (bool) { if (_instance.mrEnclave == bytes32(0)) return true; MrEnclaveState memory state = mrEnclaveState[_instance.mrEnclave]; if (state.policyVersion != _instance.policyVersion) return false; if (!checkLocalEnclaveReport) return true; return state.trusted && trustedUserMrSigner[_instance.mrSigner]; } /// @inheritdoc SgxVerifier function _validityDelay() internal view override returns (uint64) { return instanceValidityDelay; } // --------------------------------------------------------------- // Custom Errors // --------------------------------------------------------------- error SGX_ATTRIBUTE_POLICY_NOT_SET(); error SGX_ATTRIBUTE_MISMATCH(); error SGX_INVALID_ATTRIBUTE_POLICY(); error SGX_NOT_AUTHORIZED(); error SGX_INVALID_VALIDITY_DELAY(); }
We recommend using flattened code. This is necessary if your code utilizes a library or inherits dependencies. Use the
POA solidity flattener or the
truffle flattener
.
Try to fetch constructor arguments automatically
No
Yes
ABI-encoded Constructor Arguments (if required by the contract)
0x0000000000000000000000000000000000000000000000000000000000028c590000000000000000000000004779d18931b35540f84b0cd0e9633855b84df7b8000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000015180
Add arguments in
ABI hex encoded form
. Constructor arguments are written right to left, and will be found at the end of the input created bytecode. They may also be
parsed here.
Add Contract Libraries
Contract Libraries
Library 1 Name
A library name called in the .sol file. Multiple libraries (up to 10) may be added for each contract. Click the Add Library button to add an additional one.
Library 1 Address
The 0x library address. This can be found in the generated json file or Truffle output (if using truffle).
Library 2 Name
Library 2 Address
Library 3 Name
Library 3 Address
Library 4 Name
Library 4 Address
Library 5 Name
Library 5 Address
Library 6 Name
Library 6 Address
Library 7 Name
Library 7 Address
Library 8 Name
Library 8 Address
Library 9 Name
Library 9 Address
Library 10 Name
Library 10 Address
Add Library
Loading...
Verify & publish
Cancel
Ok
Ok
Ok
No
Yes