Browse Source

fix: demote 6 crypto diagnostic logs from INFO to DEBUG

ECDH, ENCRYPT, DECRYPT, INIT_SEND, NORM_DECRYPT_TRY, INIT_DECRYPT_TRY
all moved to DEBUG_DEBUG — visible only with debug=crypto=debug
topo_upd
Evgeny 3 months ago
parent
commit
db67767405
  1. 6
      src/etcp_connections.c
  2. 6
      src/secure_channel.c

6
src/etcp_connections.c

@ -162,7 +162,7 @@ static void etcp_link_send_init(struct ETCP_LINK* link, uint8_t reset, uint8_t c
uint8_t obfuscated_pubkey[SC_PUBKEY_SIZE]; uint8_t obfuscated_pubkey[SC_PUBKEY_SIZE];
sc_obfuscate_pubkey(salt, link->etcp->crypto_ctx.peer_public_key, sc_obfuscate_pubkey(salt, link->etcp->crypto_ctx.peer_public_key,
link->etcp->instance->my_keys.public_key, obfuscated_pubkey); link->etcp->instance->my_keys.public_key, obfuscated_pubkey);
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "INIT_SEND: salt=%02x%02x%02x%02x%02x%02x%02x%02x obf_pub=%02x%02x%02x%02x peer_pub=%02x%02x%02x%02x my_pub=%02x%02x%02x%02x seskey=%02x%02x%02x%02x", DEBUG_DEBUG(DEBUG_CATEGORY_CRYPTO, "INIT_SEND: salt=%02x%02x%02x%02x%02x%02x%02x%02x obf_pub=%02x%02x%02x%02x peer_pub=%02x%02x%02x%02x my_pub=%02x%02x%02x%02x seskey=%02x%02x%02x%02x",
salt[0], salt[1], salt[2], salt[3], salt[4], salt[5], salt[6], salt[7], salt[0], salt[1], salt[2], salt[3], salt[4], salt[5], salt[6], salt[7],
obfuscated_pubkey[0], obfuscated_pubkey[1], obfuscated_pubkey[2], obfuscated_pubkey[3], obfuscated_pubkey[0], obfuscated_pubkey[1], obfuscated_pubkey[2], obfuscated_pubkey[3],
link->etcp->crypto_ctx.peer_public_key[0], link->etcp->crypto_ctx.peer_public_key[1], link->etcp->crypto_ctx.peer_public_key[0], link->etcp->crypto_ctx.peer_public_key[1],
@ -1556,7 +1556,7 @@ void etcp_connections_read_callback_socket(socket_t sock, void* arg) {
// } // }
if (link!=NULL && link->etcp!=NULL && link->etcp->crypto_ctx.session_ready) { if (link!=NULL && link->etcp!=NULL && link->etcp->crypto_ctx.session_ready) {
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "NORM_DECRYPT_TRY: seskey=%02x%02x%02x%02x recv_len=%zd rx=%llu", DEBUG_DEBUG(DEBUG_CATEGORY_CRYPTO, "NORM_DECRYPT_TRY: seskey=%02x%02x%02x%02x recv_len=%zd rx=%llu",
link->etcp->crypto_ctx.session_key[0], link->etcp->crypto_ctx.session_key[1], link->etcp->crypto_ctx.session_key[0], link->etcp->crypto_ctx.session_key[1],
link->etcp->crypto_ctx.session_key[2], link->etcp->crypto_ctx.session_key[3], link->etcp->crypto_ctx.session_key[2], link->etcp->crypto_ctx.session_key[3],
recv_len, (unsigned long long)link->etcp->crypto_ctx.rx_counter); recv_len, (unsigned long long)link->etcp->crypto_ctx.rx_counter);
@ -1596,7 +1596,7 @@ void etcp_connections_read_callback_socket(socket_t sock, void* arg) {
goto ec_fr; goto ec_fr;
} }
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "X25519 decrypt OK from %s", sockaddr_storage_to_str(&addr).str); DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "X25519 decrypt OK from %s", sockaddr_storage_to_str(&addr).str);
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "INIT_DECRYPT_TRY: seskey=%02x%02x%02x%02x recv_len=%zd strip40=%zd salt=%02x%02x%02x%02x%02x%02x%02x%02x enc_pub=%02x%02x%02x%02x", DEBUG_DEBUG(DEBUG_CATEGORY_CRYPTO, "INIT_DECRYPT_TRY: seskey=%02x%02x%02x%02x recv_len=%zd strip40=%zd salt=%02x%02x%02x%02x%02x%02x%02x%02x enc_pub=%02x%02x%02x%02x",
sc.session_key[0], sc.session_key[1], sc.session_key[2], sc.session_key[3], sc.session_key[0], sc.session_key[1], sc.session_key[2], sc.session_key[3],
recv_len, recv_len - SC_PUBKEY_ENC_SIZE, recv_len, recv_len - SC_PUBKEY_ENC_SIZE,
salt[0], salt[1], salt[2], salt[3], salt[4], salt[5], salt[6], salt[7], salt[0], salt[1], salt[2], salt[3], salt[4], salt[5], salt[6], salt[7],

6
src/secure_channel.c

@ -225,7 +225,7 @@ sc_status_t sc_set_peer_public_key(sc_context_t *ctx, const uint8_t *peer_public
} }
sc_derive_session_key(shared_secret, ctx->session_key); sc_derive_session_key(shared_secret, ctx->session_key);
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "ECDH: priv=%02x%02x%02x%02x peer_pub=%02x%02x%02x%02x shared=%02x%02x%02x%02x%02x%02x%02x%02x seskey=%02x%02x%02x%02x", DEBUG_DEBUG(DEBUG_CATEGORY_CRYPTO, "ECDH: priv=%02x%02x%02x%02x peer_pub=%02x%02x%02x%02x shared=%02x%02x%02x%02x%02x%02x%02x%02x seskey=%02x%02x%02x%02x",
ctx->pk->private_key[0], ctx->pk->private_key[1], ctx->pk->private_key[2], ctx->pk->private_key[3], ctx->pk->private_key[0], ctx->pk->private_key[1], ctx->pk->private_key[2], ctx->pk->private_key[3],
peer_public_key[0], peer_public_key[1], peer_public_key[2], peer_public_key[3], peer_public_key[0], peer_public_key[1], peer_public_key[2], peer_public_key[3],
shared_secret[0], shared_secret[1], shared_secret[2], shared_secret[3], shared_secret[0], shared_secret[1], shared_secret[2], shared_secret[3],
@ -273,7 +273,7 @@ sc_status_t sc_encrypt(sc_context_t *ctx, const uint8_t *plaintext, size_t plain
size_t total_plaintext_len = plaintext_len + SC_CRC32_SIZE; size_t total_plaintext_len = plaintext_len + SC_CRC32_SIZE;
uint8_t nonce[SC_NONCE_SIZE]; uint8_t nonce[SC_NONCE_SIZE];
sc_build_nonce(ctx->tx_counter, nonce); sc_build_nonce(ctx->tx_counter, nonce);
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "ENCRYPT: seskey=%02x%02x%02x%02x tx=%llu nonce=%02x%02x%02x%02x data[0..3]=%02x%02x%02x%02x", DEBUG_DEBUG(DEBUG_CATEGORY_CRYPTO, "ENCRYPT: seskey=%02x%02x%02x%02x tx=%llu nonce=%02x%02x%02x%02x data[0..3]=%02x%02x%02x%02x",
ctx->session_key[0], ctx->session_key[1], ctx->session_key[2], ctx->session_key[3], ctx->session_key[0], ctx->session_key[1], ctx->session_key[2], ctx->session_key[3],
(unsigned long long)ctx->tx_counter, (unsigned long long)ctx->tx_counter,
nonce[0], nonce[1], nonce[2], nonce[3], nonce[0], nonce[1], nonce[2], nonce[3],
@ -311,7 +311,7 @@ sc_status_t sc_decrypt(sc_context_t *ctx, const uint8_t *ciphertext, size_t ciph
uint8_t nonce[SC_NONCE_SIZE]; uint8_t nonce[SC_NONCE_SIZE];
memcpy(nonce, ciphertext, SC_NONCE_SIZE); memcpy(nonce, ciphertext, SC_NONCE_SIZE);
DEBUG_INFO(DEBUG_CATEGORY_CRYPTO, "DECRYPT: seskey=%02x%02x%02x%02x nonce=%02x%02x%02x%02x ct_len=%zu", DEBUG_DEBUG(DEBUG_CATEGORY_CRYPTO, "DECRYPT: seskey=%02x%02x%02x%02x nonce=%02x%02x%02x%02x ct_len=%zu",
ctx->session_key[0], ctx->session_key[1], ctx->session_key[2], ctx->session_key[3], ctx->session_key[0], ctx->session_key[1], ctx->session_key[2], ctx->session_key[3],
nonce[0], nonce[1], nonce[2], nonce[3], nonce[0], nonce[1], nonce[2], nonce[3],
ciphertext_len); ciphertext_len);

Loading…
Cancel
Save