Browse Source

Диагностика: WARN при мутации конфига (ключи/node_id) + детали при invalid sig в JOIN/CHANNEL_INFO_RESP + предупреждение при расхождении node_id инвайта и ETCP

topo_upd
Evgeny 3 months ago
parent
commit
da86841516
  1. 9
      src/config_updater.c
  2. 27
      tools/chatgui/transport/chat_sync.c

9
src/config_updater.c

@ -304,6 +304,7 @@ int config_ensure_keys_and_node_id(const char *filename) {
if (need_priv_key) {
// Generate new keypair if private key is invalid
DEBUG_WARN(DEBUG_CATEGORY_CONFIG, "Generating NEW keypair — private key was invalid/missing in %s", filename);
struct SC_MYKEYS mykeys;
if (sc_generate_keypair(&mykeys) != SC_OK) {
DEBUG_ERROR(DEBUG_CATEGORY_CONFIG, "Failed to generate keypair");
@ -318,6 +319,7 @@ int config_ensure_keys_and_node_id(const char *filename) {
} else if (need_pub_key) {
// Compute public key from existing private key
DEBUG_WARN(DEBUG_CATEGORY_CONFIG, "Computing public key from existing private key (pubkey was invalid/missing in %s)", filename);
uint8_t priv_bin[SC_PRIVKEY_SIZE];
uint8_t pub_bin[SC_PUBKEY_SIZE];
@ -357,6 +359,8 @@ int config_ensure_keys_and_node_id(const char *filename) {
return -1;
}
new_node_id &= 0x7FFFFFFFFFFFFFFF;
DEBUG_WARN(DEBUG_CATEGORY_CONFIG, "Generating NEW random node_id=%016llx (old=%016llx). WARNING: existing invites will break! file=%s",
(unsigned long long)new_node_id, (unsigned long long)global->my_node_id, filename);
}
free_config(config);
@ -389,6 +393,7 @@ int config_ensure_keys_and_node_id(const char *filename) {
if (need_node_id) {
char node_id_hex[HEXNODEID_LEN + 1];
snprintf(node_id_hex, sizeof(node_id_hex), "%016llx", (unsigned long long)new_node_id);
DEBUG_WARN(DEBUG_CATEGORY_CONFIG, "Writing my_node_id=%s to %s", node_id_hex, filename);
if (insert_or_replace_option(&work_buf, &work_len, &buf_capacity, "my_node_id", node_id_hex) < 0) {
ret = -1;
@ -396,12 +401,14 @@ int config_ensure_keys_and_node_id(const char *filename) {
}
if (need_priv_key && ret == 0) {
DEBUG_WARN(DEBUG_CATEGORY_CONFIG, "Writing my_private_key to %s", filename);
if (insert_or_replace_option(&work_buf, &work_len, &buf_capacity, "my_private_key", new_priv_key) < 0) {
ret = -1;
}
}
if (need_pub_key && ret == 0) {
DEBUG_WARN(DEBUG_CATEGORY_CONFIG, "Writing my_public_key to %s", filename);
if (insert_or_replace_option(&work_buf, &work_len, &buf_capacity, "my_public_key", new_pub_key) < 0) {
ret = -1;
}
@ -415,7 +422,7 @@ int config_ensure_keys_and_node_id(const char *filename) {
ret = -1;
} else {
DEBUG_DEBUG(DEBUG_CATEGORY_CONFIG, "Successfully updated config file: %s", filename);
DEBUG_WARN(DEBUG_CATEGORY_CONFIG, "Config file updated: %s (gen_priv=%d gen_pub=%d gen_nodeid=%d)", filename, need_priv_key, need_pub_key, need_node_id);
}
}

27
tools/chatgui/transport/chat_sync.c

@ -499,6 +499,9 @@ static void cs_on_conn_up(struct ETCP_CONN* conn, void* arg) {
if (g_cs->pending_invite_ch_id != 0 && !g_cs->info_req_timer) {
DEBUG_INFO(DEBUG_CATEGORY_CONNECTIVITY, "%s: conn_up invite path peer=%016llx ch=%llu",
CS_ID, (unsigned long long)peer, (unsigned long long)g_cs->pending_invite_ch_id);
if (g_cs->pending_invite_node_id != 0 && g_cs->pending_invite_node_id != peer)
DEBUG_WARN(DEBUG_CATEGORY_DEBUG, "%s: invite node_id MISMATCH: invite=0x%016llx ETCP_peer=0x%016llx — invite is STALE!",
CS_ID, (unsigned long long)g_cs->pending_invite_node_id, (unsigned long long)peer);
g_cs->pending_invite_node_id = peer;
char ch_id_str[64];
snprintf(ch_id_str, sizeof(ch_id_str), "%llu",
@ -785,6 +788,9 @@ static void cs_handle_channel_info_req(struct chat_sync* cs, uint64_t peer,
return;
}
uint64_t myid = cs->inst->node_id;
if (memcmp(cs->inst->my_keys.public_key, x25519, 32) != 0)
DEBUG_WARN(DEBUG_CATEGORY_CONNECTIVITY, "%s: CHANNEL_INFO_RESP pubkey MISMATCH: my=%016llx ch=%016llx — channel was created with DIFFERENT keys!",
CS_ID, *(const uint64_t*)cs->inst->my_keys.public_key, *(const uint64_t*)x25519);
uint8_t my_join_sig[64] = {0};
uint8_t join_msg[256]; size_t mlen = 0;
mlen += snprintf((char*)join_msg + mlen, sizeof(join_msg) - mlen, "%s", ch_id) + 1;
@ -793,6 +799,9 @@ static void cs_handle_channel_info_req(struct chat_sync* cs, uint64_t peer,
{ const char* nm = cs->inst->name[0] ? cs->inst->name : "";
size_t nl = strlen(nm); memcpy(join_msg + mlen, nm, nl); mlen += nl; join_msg[mlen++] = '\0'; }
cs_ed25519_sign(cs->inst->my_ed25519_privkey, join_msg, mlen, my_join_sig);
DEBUG_DEBUG(DEBUG_CATEGORY_DEBUG, "%s: CHANNEL_INFO_RESP signed my_join_sig: myid=%016llx my_pub=%016llx ch_pub=%016llx name=%s",
CS_ID, (unsigned long long)myid, *(const uint64_t*)cs->inst->my_keys.public_key,
*(const uint64_t*)x25519, cs->inst->name);
uint8_t buf[1024]; size_t boff = 0;
buf[boff++] = CS_MSG_CHANNEL_INFO_RESP;
@ -823,6 +832,10 @@ static void cs_handle_channel_info_resp(struct chat_sync* cs, uint64_t peer,
const uint8_t* ch_sig = p; p += 64;
const uint8_t* inviter_join_sig = p;
DEBUG_DEBUG(DEBUG_CATEGORY_DEBUG, "%s: CHANNEL_INFO_RESP from peer=%016llx owner=%016llx ch_x25519=%016llx ch_ed=%016llx name=%s",
CS_ID, (unsigned long long)peer, (unsigned long long)owner,
*(const uint64_t*)x25519, *(const uint64_t*)ed_pub, name);
/* verify channel signature */
uint8_t vmsg[1024]; size_t vlen = 0;
vlen += snprintf((char*)vmsg + vlen, sizeof(vmsg) - vlen, "%s", ch_id) + 1;
@ -855,10 +868,11 @@ static void cs_handle_channel_info_resp(struct chat_sync* cs, uint64_t peer,
memcpy(ivmsg + ilen, &peer, 8); ilen += 8;
memcpy(ivmsg + ilen, x25519, 32); ilen += 32;
{ char nnm[64] = ""; _get_node_name(vdb, peer, nnm, sizeof(nnm));
size_t nl = strlen(nnm); memcpy(ivmsg + ilen, nnm, nl); ilen += nl; ivmsg[ilen++] = '\0'; }
if (cs_ed25519_verify(inv_ed, ivmsg, ilen, inviter_join_sig) != 0) {
DEBUG_ERROR(DEBUG_CATEGORY_CONNECTIVITY, "%s: CHANNEL_INFO_RESP invalid inviter_join_sig peer=%016llx",
CS_ID, (unsigned long long)peer);
size_t nl = strlen(nnm); memcpy(ivmsg + ilen, nnm, nl); ilen += nl; ivmsg[ilen++] = '\0';
if (cs_ed25519_verify(inv_ed, ivmsg, ilen, inviter_join_sig) != 0) {
DEBUG_ERROR(DEBUG_CATEGORY_CONNECTIVITY, "%s: CHANNEL_INFO_RESP invalid inviter_join_sig peer=%016llx x25519=%016llx inv_ed=%016llx name=%s",
CS_ID, (unsigned long long)peer, *(const uint64_t*)x25519, *(const uint64_t*)inv_ed, nnm);
}
}
}
@ -946,8 +960,9 @@ static void cs_handle_channel_join(struct chat_sync* cs, uint64_t peer,
{ sqlite3* tdb = cs->inst->topo_groups->topo_sqlite_db; char nnm[64] = ""; _get_node_name(tdb, node_id, nnm, sizeof(nnm));
size_t nl = strlen(nnm); memcpy(vmsg + vlen, nnm, nl); vlen += nl; vmsg[vlen++] = '\0'; }
if (cs_ed25519_verify(ed_pub, vmsg, vlen, join_sig) != 0) {
DEBUG_ERROR(DEBUG_CATEGORY_CONNECTIVITY, "%s: JOIN invalid sig node=0x%016llx ch=%s", CS_ID,
(unsigned long long)node_id, ch_id);
DEBUG_ERROR(DEBUG_CATEGORY_CONNECTIVITY, "%s: JOIN invalid sig node=0x%016llx ch=%s — signed(node=%016llx x25519=%016llx ed=%016llx)", CS_ID,
(unsigned long long)node_id, ch_id,
(unsigned long long)node_id, *(const uint64_t*)x25519, *(const uint64_t*)ed_pub);
return;
}

Loading…
Cancel
Save