crypto: log details of our public identity when we update it

For debugging, it's useful to have a record of what we believe our own public
cross-signing keys to be. Currently, we log the keys at startup if we restore
them from the database, but if we subsequently create, or download, a set of
keys, they aren't logged.
This commit is contained in:
Richard van der Hoff
2024-09-04 22:45:10 +01:00
committed by Richard van der Hoff
parent b9b8de7ff1
commit 2c2d8e9ff0
3 changed files with 38 additions and 0 deletions
@@ -126,6 +126,26 @@ impl CryptoStoreWrapper {
self.store.save_changes(changes).await?;
// If we updated our own public identity, log it for debugging purposes
if tracing::level_enabled!(tracing::Level::DEBUG) {
for updated_identity in
identities.new.iter().chain(identities.changed.iter()).filter_map(|id| id.own())
{
let master_key = updated_identity.master_key().get_first_key();
let user_signing_key = updated_identity.user_signing_key().get_first_key();
let self_signing_key = updated_identity.self_signing_key().get_first_key();
debug!(
?master_key,
?user_signing_key,
?self_signing_key,
previously_verified = updated_identity.was_previously_verified(),
verified = updated_identity.is_verified(),
"Stored our own identity"
);
}
}
if !room_key_updates.is_empty() {
// Ignore the result. It can only fail if there are no listeners.
let _ = self.room_keys_received_sender.send(room_key_updates);
@@ -2,6 +2,7 @@ use std::collections::btree_map::Iter;
use ruma::{encryption::KeyUsage, OwnedDeviceKeyId, UserId};
use serde::{Deserialize, Serialize};
use vodozemac::Ed25519PublicKey;
use super::{CrossSigningKey, SigningKey};
use crate::{
@@ -33,6 +34,14 @@ impl SelfSigningPubkey {
&self.0.usage
}
/// Get the first available self signing key.
///
/// There's usually only a single key so this will usually fetch the
/// only key.
pub fn get_first_key(&self) -> Option<Ed25519PublicKey> {
self.0.get_first_key_and_id().map(|(_, k)| k)
}
/// Verify that the [`DeviceKeys`] have a valid signature from this
/// self-signing key.
pub fn verify_device_keys(&self, device_keys: &DeviceKeys) -> Result<(), SignatureError> {
@@ -2,6 +2,7 @@ use std::collections::btree_map::Iter;
use ruma::{encryption::KeyUsage, OwnedDeviceKeyId, UserId};
use serde::{Deserialize, Serialize};
use vodozemac::Ed25519PublicKey;
use super::{CrossSigningKey, MasterPubkey, SigningKey};
use crate::{olm::VerifyJson, types::SigningKeys, SignatureError};
@@ -29,6 +30,14 @@ impl UserSigningPubkey {
&self.0.keys
}
/// Get the first available user-signing key.
///
/// There's usually only a single key so this will usually fetch the
/// only key.
pub fn get_first_key(&self) -> Option<Ed25519PublicKey> {
self.0.get_first_key_and_id().map(|(_, k)| k)
}
/// Check if the given master key is signed by this user signing key.
///
/// # Arguments