Browse Source

Add debug logs to Ed25519 self-sig flow: computation, verification, skip due to no key

topo_upd
Evgeny 2 months ago
parent
commit
58ad643516
  1. 1
      src/db_sync.c
  2. 8
      src/routing_layer/topo_group.c
  3. 3
      src/routing_layer/topo_node.c

1
src/db_sync.c

@ -1314,6 +1314,7 @@ static void db_sync_peer_check_cb(void* arg)
if (db_get_ed25519_pubkey(db, best->node_id, ek) == 0) {
best->sync_state = 1; db_sync_initiate_sync(si, best->node_id); total_synced++;
} else {
DEBUG_DEBUG(DEBUG_CATEGORY_DB_SYNC, "peer_check skip peer=%016llx — no Ed25519 pubkey yet", (unsigned long long)best->node_id);
best = NULL; total_skipped++;
}
}

8
src/routing_layer/topo_group.c

@ -605,13 +605,19 @@ int topo_group_process_nodeinfo(struct TOPO_GROUP* group, struct ETCP_CONN* from
/* verify Ed25519 self-signature: Ed25519_pubkey must sign X25519_pubkey */
{
uint64_t ekchk; memcpy(&ekchk, new_ni->ed25519_public_key, 8);
if (ekchk != 0 && sc_ed25519_verify(new_ni->ed25519_public_key, new_ni->public_key, SC_PUBKEY_SIZE, new_ni->x25519_self_sig) != SC_OK) {
if (ekchk == 0) {
DEBUG_DEBUG(DEBUG_CATEGORY_BGP, "NODEINFO x25519_self_sig SKIP (ed25519 key zero) node=%016llx from=%s",
(unsigned long long)node_id, from->log_name);
} else if (sc_ed25519_verify(new_ni->ed25519_public_key, new_ni->public_key, SC_PUBKEY_SIZE, new_ni->x25519_self_sig) != SC_OK) {
DEBUG_ERROR(DEBUG_CATEGORY_BGP, "NODEINFO x25519_self_sig VERIFY FAIL node=%016llx ed_pubkey=%016llx... from=%s — rejecting as forgery",
(unsigned long long)node_id, ekchk, from->log_name);
topo_node_free_raw(group->instance->topo_groups, new_ni);
u_free(new_subnets); u_free(new_tranzit); u_free(new_hop_list);
if (nodeinfo1) { queue_remove_data(group->nodes, &nodeinfo1->ll); queue_free(paths); queue_entry_free(&nodeinfo1->ll); }
return -1;
} else {
DEBUG_DEBUG(DEBUG_CATEGORY_BGP, "NODEINFO x25519_self_sig OK node=%016llx ed_pubkey=%016llx... from=%s",
(unsigned long long)node_id, ekchk, from->log_name);
}
}

3
src/routing_layer/topo_node.c

@ -666,7 +666,8 @@ int topo_group_update_my_nodeinfo(struct UTUN_INSTANCE* instance, struct TOPO_GR
ni->ver = (old_ver % 255) + 1;
memcpy(ni->public_key, instance->my_keys.public_key, SC_PUBKEY_SIZE);
memcpy(ni->ed25519_public_key, group->ed25519_public_key, SC_PUBKEY_SIZE);
sc_ed25519_sign(instance->my_ed25519_privkey, instance->my_keys.public_key, SC_PUBKEY_SIZE, ni->x25519_self_sig);
if (sc_ed25519_sign(instance->my_ed25519_privkey, instance->my_keys.public_key, SC_PUBKEY_SIZE, ni->x25519_self_sig) != SC_OK)
DEBUG_ERROR(DEBUG_CATEGORY_BGP, "Ed25519 self-sign FAILED for my node=%016llx", (unsigned long long)ni->node_id);
if (name_len) { ni->node_name = u_malloc(name_len + 1); if (ni->node_name) { memcpy(ni->node_name, instance->name, name_len); ni->node_name[name_len] = 0; } }
lq->node = topo_node_registry_acquire(instance->topo_groups, ni);

Loading…
Cancel
Save