diff --git a/src/db_sync.c b/src/db_sync.c index 8551406e..431ae87f 100644 --- a/src/db_sync.c +++ b/src/db_sync.c @@ -1314,6 +1314,7 @@ static void db_sync_peer_check_cb(void* arg) if (db_get_ed25519_pubkey(db, best->node_id, ek) == 0) { best->sync_state = 1; db_sync_initiate_sync(si, best->node_id); total_synced++; } else { + DEBUG_DEBUG(DEBUG_CATEGORY_DB_SYNC, "peer_check skip peer=%016llx — no Ed25519 pubkey yet", (unsigned long long)best->node_id); best = NULL; total_skipped++; } } diff --git a/src/routing_layer/topo_group.c b/src/routing_layer/topo_group.c index daf708c8..a7e7abfe 100644 --- a/src/routing_layer/topo_group.c +++ b/src/routing_layer/topo_group.c @@ -605,13 +605,19 @@ int topo_group_process_nodeinfo(struct TOPO_GROUP* group, struct ETCP_CONN* from /* verify Ed25519 self-signature: Ed25519_pubkey must sign X25519_pubkey */ { uint64_t ekchk; memcpy(&ekchk, new_ni->ed25519_public_key, 8); - if (ekchk != 0 && sc_ed25519_verify(new_ni->ed25519_public_key, new_ni->public_key, SC_PUBKEY_SIZE, new_ni->x25519_self_sig) != SC_OK) { + if (ekchk == 0) { + DEBUG_DEBUG(DEBUG_CATEGORY_BGP, "NODEINFO x25519_self_sig SKIP (ed25519 key zero) node=%016llx from=%s", + (unsigned long long)node_id, from->log_name); + } else if (sc_ed25519_verify(new_ni->ed25519_public_key, new_ni->public_key, SC_PUBKEY_SIZE, new_ni->x25519_self_sig) != SC_OK) { DEBUG_ERROR(DEBUG_CATEGORY_BGP, "NODEINFO x25519_self_sig VERIFY FAIL node=%016llx ed_pubkey=%016llx... from=%s — rejecting as forgery", (unsigned long long)node_id, ekchk, from->log_name); topo_node_free_raw(group->instance->topo_groups, new_ni); u_free(new_subnets); u_free(new_tranzit); u_free(new_hop_list); if (nodeinfo1) { queue_remove_data(group->nodes, &nodeinfo1->ll); queue_free(paths); queue_entry_free(&nodeinfo1->ll); } return -1; + } else { + DEBUG_DEBUG(DEBUG_CATEGORY_BGP, "NODEINFO x25519_self_sig OK node=%016llx ed_pubkey=%016llx... from=%s", + (unsigned long long)node_id, ekchk, from->log_name); } } diff --git a/src/routing_layer/topo_node.c b/src/routing_layer/topo_node.c index 4e7ba309..31d034e2 100644 --- a/src/routing_layer/topo_node.c +++ b/src/routing_layer/topo_node.c @@ -666,7 +666,8 @@ int topo_group_update_my_nodeinfo(struct UTUN_INSTANCE* instance, struct TOPO_GR ni->ver = (old_ver % 255) + 1; memcpy(ni->public_key, instance->my_keys.public_key, SC_PUBKEY_SIZE); memcpy(ni->ed25519_public_key, group->ed25519_public_key, SC_PUBKEY_SIZE); - sc_ed25519_sign(instance->my_ed25519_privkey, instance->my_keys.public_key, SC_PUBKEY_SIZE, ni->x25519_self_sig); + if (sc_ed25519_sign(instance->my_ed25519_privkey, instance->my_keys.public_key, SC_PUBKEY_SIZE, ni->x25519_self_sig) != SC_OK) + DEBUG_ERROR(DEBUG_CATEGORY_BGP, "Ed25519 self-sign FAILED for my node=%016llx", (unsigned long long)ni->node_id); if (name_len) { ni->node_name = u_malloc(name_len + 1); if (ni->node_name) { memcpy(ni->node_name, instance->name, name_len); ni->node_name[name_len] = 0; } } lq->node = topo_node_registry_acquire(instance->topo_groups, ni);