From 2c2d8e9ff00146346b3348bb031c042bf13c4a47 Mon Sep 17 00:00:00 2001 From: Richard van der Hoff Date: Wed, 4 Sep 2024 22:45:10 +0100 Subject: [PATCH] crypto: log details of our public identity when we update it For debugging, it's useful to have a record of what we believe our own public cross-signing keys to be. Currently, we log the keys at startup if we restore them from the database, but if we subsequently create, or download, a set of keys, they aren't logged. --- .../src/store/crypto_store_wrapper.rs | 20 +++++++++++++++++++ .../src/types/cross_signing/self_signing.rs | 9 +++++++++ .../src/types/cross_signing/user_signing.rs | 9 +++++++++ 3 files changed, 38 insertions(+) diff --git a/crates/matrix-sdk-crypto/src/store/crypto_store_wrapper.rs b/crates/matrix-sdk-crypto/src/store/crypto_store_wrapper.rs index 00965e216..a2d1f8fb4 100644 --- a/crates/matrix-sdk-crypto/src/store/crypto_store_wrapper.rs +++ b/crates/matrix-sdk-crypto/src/store/crypto_store_wrapper.rs @@ -126,6 +126,26 @@ impl CryptoStoreWrapper { self.store.save_changes(changes).await?; + // If we updated our own public identity, log it for debugging purposes + if tracing::level_enabled!(tracing::Level::DEBUG) { + for updated_identity in + identities.new.iter().chain(identities.changed.iter()).filter_map(|id| id.own()) + { + let master_key = updated_identity.master_key().get_first_key(); + let user_signing_key = updated_identity.user_signing_key().get_first_key(); + let self_signing_key = updated_identity.self_signing_key().get_first_key(); + + debug!( + ?master_key, + ?user_signing_key, + ?self_signing_key, + previously_verified = updated_identity.was_previously_verified(), + verified = updated_identity.is_verified(), + "Stored our own identity" + ); + } + } + if !room_key_updates.is_empty() { // Ignore the result. It can only fail if there are no listeners. let _ = self.room_keys_received_sender.send(room_key_updates); diff --git a/crates/matrix-sdk-crypto/src/types/cross_signing/self_signing.rs b/crates/matrix-sdk-crypto/src/types/cross_signing/self_signing.rs index 5419f5438..88661cc10 100644 --- a/crates/matrix-sdk-crypto/src/types/cross_signing/self_signing.rs +++ b/crates/matrix-sdk-crypto/src/types/cross_signing/self_signing.rs @@ -2,6 +2,7 @@ use std::collections::btree_map::Iter; use ruma::{encryption::KeyUsage, OwnedDeviceKeyId, UserId}; use serde::{Deserialize, Serialize}; +use vodozemac::Ed25519PublicKey; use super::{CrossSigningKey, SigningKey}; use crate::{ @@ -33,6 +34,14 @@ impl SelfSigningPubkey { &self.0.usage } + /// Get the first available self signing key. + /// + /// There's usually only a single key so this will usually fetch the + /// only key. + pub fn get_first_key(&self) -> Option { + self.0.get_first_key_and_id().map(|(_, k)| k) + } + /// Verify that the [`DeviceKeys`] have a valid signature from this /// self-signing key. pub fn verify_device_keys(&self, device_keys: &DeviceKeys) -> Result<(), SignatureError> { diff --git a/crates/matrix-sdk-crypto/src/types/cross_signing/user_signing.rs b/crates/matrix-sdk-crypto/src/types/cross_signing/user_signing.rs index a4f17be55..393ce863c 100644 --- a/crates/matrix-sdk-crypto/src/types/cross_signing/user_signing.rs +++ b/crates/matrix-sdk-crypto/src/types/cross_signing/user_signing.rs @@ -2,6 +2,7 @@ use std::collections::btree_map::Iter; use ruma::{encryption::KeyUsage, OwnedDeviceKeyId, UserId}; use serde::{Deserialize, Serialize}; +use vodozemac::Ed25519PublicKey; use super::{CrossSigningKey, MasterPubkey, SigningKey}; use crate::{olm::VerifyJson, types::SigningKeys, SignatureError}; @@ -29,6 +30,14 @@ impl UserSigningPubkey { &self.0.keys } + /// Get the first available user-signing key. + /// + /// There's usually only a single key so this will usually fetch the + /// only key. + pub fn get_first_key(&self) -> Option { + self.0.get_first_key_and_id().map(|(_, k)| k) + } + /// Check if the given master key is signed by this user signing key. /// /// # Arguments