keyring.py 32 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879
  1. # -*- coding: utf-8 -*-
  2. # Copyright 2014-2016 OpenMarket Ltd
  3. # Copyright 2017, 2018 New Vector Ltd
  4. #
  5. # Licensed under the Apache License, Version 2.0 (the "License");
  6. # you may not use this file except in compliance with the License.
  7. # You may obtain a copy of the License at
  8. #
  9. # http://www.apache.org/licenses/LICENSE-2.0
  10. #
  11. # Unless required by applicable law or agreed to in writing, software
  12. # distributed under the License is distributed on an "AS IS" BASIS,
  13. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  14. # See the License for the specific language governing permissions and
  15. # limitations under the License.
  16. import logging
  17. from collections import defaultdict
  18. import six
  19. from six.moves import urllib
  20. import attr
  21. from signedjson.key import (
  22. decode_verify_key_bytes,
  23. encode_verify_key_base64,
  24. is_signing_algorithm_supported,
  25. )
  26. from signedjson.sign import (
  27. SignatureVerifyException,
  28. encode_canonical_json,
  29. signature_ids,
  30. verify_signed_json,
  31. )
  32. from unpaddedbase64 import decode_base64
  33. from twisted.internet import defer
  34. from synapse.api.errors import (
  35. Codes,
  36. HttpResponseException,
  37. RequestSendFailed,
  38. SynapseError,
  39. )
  40. from synapse.logging.context import (
  41. LoggingContext,
  42. PreserveLoggingContext,
  43. make_deferred_yieldable,
  44. preserve_fn,
  45. run_in_background,
  46. )
  47. from synapse.storage.keys import FetchKeyResult
  48. from synapse.util import unwrapFirstError
  49. from synapse.util.async_helpers import yieldable_gather_results
  50. from synapse.util.metrics import Measure
  51. from synapse.util.retryutils import NotRetryingDestination
  52. logger = logging.getLogger(__name__)
  53. @attr.s(slots=True, cmp=False)
  54. class VerifyJsonRequest(object):
  55. """
  56. A request to verify a JSON object.
  57. Attributes:
  58. server_name(str): The name of the server to verify against.
  59. key_ids(set[str]): The set of key_ids to that could be used to verify the
  60. JSON object
  61. json_object(dict): The JSON object to verify.
  62. minimum_valid_until_ts (int): time at which we require the signing key to
  63. be valid. (0 implies we don't care)
  64. key_ready (Deferred[str, str, nacl.signing.VerifyKey]):
  65. A deferred (server_name, key_id, verify_key) tuple that resolves when
  66. a verify key has been fetched. The deferreds' callbacks are run with no
  67. logcontext.
  68. If we are unable to find a key which satisfies the request, the deferred
  69. errbacks with an M_UNAUTHORIZED SynapseError.
  70. """
  71. server_name = attr.ib()
  72. json_object = attr.ib()
  73. minimum_valid_until_ts = attr.ib()
  74. request_name = attr.ib()
  75. key_ids = attr.ib(init=False)
  76. key_ready = attr.ib(default=attr.Factory(defer.Deferred))
  77. def __attrs_post_init__(self):
  78. self.key_ids = signature_ids(self.json_object, self.server_name)
  79. class KeyLookupError(ValueError):
  80. pass
  81. class Keyring(object):
  82. def __init__(self, hs, key_fetchers=None):
  83. self.clock = hs.get_clock()
  84. if key_fetchers is None:
  85. key_fetchers = (
  86. StoreKeyFetcher(hs),
  87. PerspectivesKeyFetcher(hs),
  88. ServerKeyFetcher(hs),
  89. )
  90. self._key_fetchers = key_fetchers
  91. # map from server name to Deferred. Has an entry for each server with
  92. # an ongoing key download; the Deferred completes once the download
  93. # completes.
  94. #
  95. # These are regular, logcontext-agnostic Deferreds.
  96. self.key_downloads = {}
  97. def verify_json_for_server(
  98. self, server_name, json_object, validity_time, request_name
  99. ):
  100. """Verify that a JSON object has been signed by a given server
  101. Args:
  102. server_name (str): name of the server which must have signed this object
  103. json_object (dict): object to be checked
  104. validity_time (int): timestamp at which we require the signing key to
  105. be valid. (0 implies we don't care)
  106. request_name (str): an identifier for this json object (eg, an event id)
  107. for logging.
  108. Returns:
  109. Deferred[None]: completes if the the object was correctly signed, otherwise
  110. errbacks with an error
  111. """
  112. req = VerifyJsonRequest(server_name, json_object, validity_time, request_name)
  113. requests = (req,)
  114. return make_deferred_yieldable(self._verify_objects(requests)[0])
  115. def verify_json_objects_for_server(self, server_and_json):
  116. """Bulk verifies signatures of json objects, bulk fetching keys as
  117. necessary.
  118. Args:
  119. server_and_json (iterable[Tuple[str, dict, int, str]):
  120. Iterable of (server_name, json_object, validity_time, request_name)
  121. tuples.
  122. validity_time is a timestamp at which the signing key must be
  123. valid.
  124. request_name is an identifier for this json object (eg, an event id)
  125. for logging.
  126. Returns:
  127. List<Deferred[None]>: for each input triplet, a deferred indicating success
  128. or failure to verify each json object's signature for the given
  129. server_name. The deferreds run their callbacks in the sentinel
  130. logcontext.
  131. """
  132. return self._verify_objects(
  133. VerifyJsonRequest(server_name, json_object, validity_time, request_name)
  134. for server_name, json_object, validity_time, request_name in server_and_json
  135. )
  136. def _verify_objects(self, verify_requests):
  137. """Does the work of verify_json_[objects_]for_server
  138. Args:
  139. verify_requests (iterable[VerifyJsonRequest]):
  140. Iterable of verification requests.
  141. Returns:
  142. List<Deferred[None]>: for each input item, a deferred indicating success
  143. or failure to verify each json object's signature for the given
  144. server_name. The deferreds run their callbacks in the sentinel
  145. logcontext.
  146. """
  147. # a list of VerifyJsonRequests which are awaiting a key lookup
  148. key_lookups = []
  149. handle = preserve_fn(_handle_key_deferred)
  150. def process(verify_request):
  151. """Process an entry in the request list
  152. Adds a key request to key_lookups, and returns a deferred which
  153. will complete or fail (in the sentinel context) when verification completes.
  154. """
  155. if not verify_request.key_ids:
  156. return defer.fail(
  157. SynapseError(
  158. 400,
  159. "Not signed by %s" % (verify_request.server_name,),
  160. Codes.UNAUTHORIZED,
  161. )
  162. )
  163. logger.debug(
  164. "Verifying %s for %s with key_ids %s, min_validity %i",
  165. verify_request.request_name,
  166. verify_request.server_name,
  167. verify_request.key_ids,
  168. verify_request.minimum_valid_until_ts,
  169. )
  170. # add the key request to the queue, but don't start it off yet.
  171. key_lookups.append(verify_request)
  172. # now run _handle_key_deferred, which will wait for the key request
  173. # to complete and then do the verification.
  174. #
  175. # We want _handle_key_request to log to the right context, so we
  176. # wrap it with preserve_fn (aka run_in_background)
  177. return handle(verify_request)
  178. results = [process(r) for r in verify_requests]
  179. if key_lookups:
  180. run_in_background(self._start_key_lookups, key_lookups)
  181. return results
  182. @defer.inlineCallbacks
  183. def _start_key_lookups(self, verify_requests):
  184. """Sets off the key fetches for each verify request
  185. Once each fetch completes, verify_request.key_ready will be resolved.
  186. Args:
  187. verify_requests (List[VerifyJsonRequest]):
  188. """
  189. try:
  190. ctx = LoggingContext.current_context()
  191. # map from server name to a set of outstanding request ids
  192. server_to_request_ids = {}
  193. for verify_request in verify_requests:
  194. server_name = verify_request.server_name
  195. request_id = id(verify_request)
  196. server_to_request_ids.setdefault(server_name, set()).add(request_id)
  197. # Wait for any previous lookups to complete before proceeding.
  198. yield self.wait_for_previous_lookups(server_to_request_ids.keys())
  199. # take out a lock on each of the servers by sticking a Deferred in
  200. # key_downloads
  201. for server_name in server_to_request_ids.keys():
  202. self.key_downloads[server_name] = defer.Deferred()
  203. logger.debug("Got key lookup lock on %s", server_name)
  204. # When we've finished fetching all the keys for a given server_name,
  205. # drop the lock by resolving the deferred in key_downloads.
  206. def drop_server_lock(server_name):
  207. d = self.key_downloads.pop(server_name)
  208. d.callback(None)
  209. def lookup_done(res, verify_request):
  210. server_name = verify_request.server_name
  211. server_requests = server_to_request_ids[server_name]
  212. server_requests.remove(id(verify_request))
  213. # if there are no more requests for this server, we can drop the lock.
  214. if not server_requests:
  215. with PreserveLoggingContext(ctx):
  216. logger.debug("Releasing key lookup lock on %s", server_name)
  217. # ... but not immediately, as that can cause stack explosions if
  218. # we get a long queue of lookups.
  219. self.clock.call_later(0, drop_server_lock, server_name)
  220. return res
  221. for verify_request in verify_requests:
  222. verify_request.key_ready.addBoth(lookup_done, verify_request)
  223. # Actually start fetching keys.
  224. self._get_server_verify_keys(verify_requests)
  225. except Exception:
  226. logger.exception("Error starting key lookups")
  227. @defer.inlineCallbacks
  228. def wait_for_previous_lookups(self, server_names):
  229. """Waits for any previous key lookups for the given servers to finish.
  230. Args:
  231. server_names (Iterable[str]): list of servers which we want to look up
  232. Returns:
  233. Deferred[None]: resolves once all key lookups for the given servers have
  234. completed. Follows the synapse rules of logcontext preservation.
  235. """
  236. loop_count = 1
  237. while True:
  238. wait_on = [
  239. (server_name, self.key_downloads[server_name])
  240. for server_name in server_names
  241. if server_name in self.key_downloads
  242. ]
  243. if not wait_on:
  244. break
  245. logger.info(
  246. "Waiting for existing lookups for %s to complete [loop %i]",
  247. [w[0] for w in wait_on],
  248. loop_count,
  249. )
  250. with PreserveLoggingContext():
  251. yield defer.DeferredList((w[1] for w in wait_on))
  252. loop_count += 1
  253. def _get_server_verify_keys(self, verify_requests):
  254. """Tries to find at least one key for each verify request
  255. For each verify_request, verify_request.key_ready is called back with
  256. params (server_name, key_id, VerifyKey) if a key is found, or errbacked
  257. with a SynapseError if none of the keys are found.
  258. Args:
  259. verify_requests (list[VerifyJsonRequest]): list of verify requests
  260. """
  261. remaining_requests = set(
  262. (rq for rq in verify_requests if not rq.key_ready.called)
  263. )
  264. @defer.inlineCallbacks
  265. def do_iterations():
  266. with Measure(self.clock, "get_server_verify_keys"):
  267. for f in self._key_fetchers:
  268. if not remaining_requests:
  269. return
  270. yield self._attempt_key_fetches_with_fetcher(f, remaining_requests)
  271. # look for any requests which weren't satisfied
  272. with PreserveLoggingContext():
  273. for verify_request in remaining_requests:
  274. verify_request.key_ready.errback(
  275. SynapseError(
  276. 401,
  277. "No key for %s with ids in %s (min_validity %i)"
  278. % (
  279. verify_request.server_name,
  280. verify_request.key_ids,
  281. verify_request.minimum_valid_until_ts,
  282. ),
  283. Codes.UNAUTHORIZED,
  284. )
  285. )
  286. def on_err(err):
  287. # we don't really expect to get here, because any errors should already
  288. # have been caught and logged. But if we do, let's log the error and make
  289. # sure that all of the deferreds are resolved.
  290. logger.error("Unexpected error in _get_server_verify_keys: %s", err)
  291. with PreserveLoggingContext():
  292. for verify_request in remaining_requests:
  293. if not verify_request.key_ready.called:
  294. verify_request.key_ready.errback(err)
  295. run_in_background(do_iterations).addErrback(on_err)
  296. @defer.inlineCallbacks
  297. def _attempt_key_fetches_with_fetcher(self, fetcher, remaining_requests):
  298. """Use a key fetcher to attempt to satisfy some key requests
  299. Args:
  300. fetcher (KeyFetcher): fetcher to use to fetch the keys
  301. remaining_requests (set[VerifyJsonRequest]): outstanding key requests.
  302. Any successfully-completed requests will be removed from the list.
  303. """
  304. # dict[str, dict[str, int]]: keys to fetch.
  305. # server_name -> key_id -> min_valid_ts
  306. missing_keys = defaultdict(dict)
  307. for verify_request in remaining_requests:
  308. # any completed requests should already have been removed
  309. assert not verify_request.key_ready.called
  310. keys_for_server = missing_keys[verify_request.server_name]
  311. for key_id in verify_request.key_ids:
  312. # If we have several requests for the same key, then we only need to
  313. # request that key once, but we should do so with the greatest
  314. # min_valid_until_ts of the requests, so that we can satisfy all of
  315. # the requests.
  316. keys_for_server[key_id] = max(
  317. keys_for_server.get(key_id, -1),
  318. verify_request.minimum_valid_until_ts,
  319. )
  320. results = yield fetcher.get_keys(missing_keys)
  321. completed = list()
  322. for verify_request in remaining_requests:
  323. server_name = verify_request.server_name
  324. # see if any of the keys we got this time are sufficient to
  325. # complete this VerifyJsonRequest.
  326. result_keys = results.get(server_name, {})
  327. for key_id in verify_request.key_ids:
  328. fetch_key_result = result_keys.get(key_id)
  329. if not fetch_key_result:
  330. # we didn't get a result for this key
  331. continue
  332. if (
  333. fetch_key_result.valid_until_ts
  334. < verify_request.minimum_valid_until_ts
  335. ):
  336. # key was not valid at this point
  337. continue
  338. with PreserveLoggingContext():
  339. verify_request.key_ready.callback(
  340. (server_name, key_id, fetch_key_result.verify_key)
  341. )
  342. completed.append(verify_request)
  343. break
  344. remaining_requests.difference_update(completed)
  345. class KeyFetcher(object):
  346. def get_keys(self, keys_to_fetch):
  347. """
  348. Args:
  349. keys_to_fetch (dict[str, dict[str, int]]):
  350. the keys to be fetched. server_name -> key_id -> min_valid_ts
  351. Returns:
  352. Deferred[dict[str, dict[str, synapse.storage.keys.FetchKeyResult|None]]]:
  353. map from server_name -> key_id -> FetchKeyResult
  354. """
  355. raise NotImplementedError
  356. class StoreKeyFetcher(KeyFetcher):
  357. """KeyFetcher impl which fetches keys from our data store"""
  358. def __init__(self, hs):
  359. self.store = hs.get_datastore()
  360. @defer.inlineCallbacks
  361. def get_keys(self, keys_to_fetch):
  362. """see KeyFetcher.get_keys"""
  363. keys_to_fetch = (
  364. (server_name, key_id)
  365. for server_name, keys_for_server in keys_to_fetch.items()
  366. for key_id in keys_for_server.keys()
  367. )
  368. res = yield self.store.get_server_verify_keys(keys_to_fetch)
  369. keys = {}
  370. for (server_name, key_id), key in res.items():
  371. keys.setdefault(server_name, {})[key_id] = key
  372. return keys
  373. class BaseV2KeyFetcher(object):
  374. def __init__(self, hs):
  375. self.store = hs.get_datastore()
  376. self.config = hs.get_config()
  377. @defer.inlineCallbacks
  378. def process_v2_response(self, from_server, response_json, time_added_ms):
  379. """Parse a 'Server Keys' structure from the result of a /key request
  380. This is used to parse either the entirety of the response from
  381. GET /_matrix/key/v2/server, or a single entry from the list returned by
  382. POST /_matrix/key/v2/query.
  383. Checks that each signature in the response that claims to come from the origin
  384. server is valid, and that there is at least one such signature.
  385. Stores the json in server_keys_json so that it can be used for future responses
  386. to /_matrix/key/v2/query.
  387. Args:
  388. from_server (str): the name of the server producing this result: either
  389. the origin server for a /_matrix/key/v2/server request, or the notary
  390. for a /_matrix/key/v2/query.
  391. response_json (dict): the json-decoded Server Keys response object
  392. time_added_ms (int): the timestamp to record in server_keys_json
  393. Returns:
  394. Deferred[dict[str, FetchKeyResult]]: map from key_id to result object
  395. """
  396. ts_valid_until_ms = response_json["valid_until_ts"]
  397. # start by extracting the keys from the response, since they may be required
  398. # to validate the signature on the response.
  399. verify_keys = {}
  400. for key_id, key_data in response_json["verify_keys"].items():
  401. if is_signing_algorithm_supported(key_id):
  402. key_base64 = key_data["key"]
  403. key_bytes = decode_base64(key_base64)
  404. verify_key = decode_verify_key_bytes(key_id, key_bytes)
  405. verify_keys[key_id] = FetchKeyResult(
  406. verify_key=verify_key, valid_until_ts=ts_valid_until_ms
  407. )
  408. server_name = response_json["server_name"]
  409. verified = False
  410. for key_id in response_json["signatures"].get(server_name, {}):
  411. # each of the keys used for the signature must be present in the response
  412. # json.
  413. key = verify_keys.get(key_id)
  414. if not key:
  415. raise KeyLookupError(
  416. "Key response is signed by key id %s:%s but that key is not "
  417. "present in the response" % (server_name, key_id)
  418. )
  419. verify_signed_json(response_json, server_name, key.verify_key)
  420. verified = True
  421. if not verified:
  422. raise KeyLookupError(
  423. "Key response for %s is not signed by the origin server"
  424. % (server_name,)
  425. )
  426. for key_id, key_data in response_json["old_verify_keys"].items():
  427. if is_signing_algorithm_supported(key_id):
  428. key_base64 = key_data["key"]
  429. key_bytes = decode_base64(key_base64)
  430. verify_key = decode_verify_key_bytes(key_id, key_bytes)
  431. verify_keys[key_id] = FetchKeyResult(
  432. verify_key=verify_key, valid_until_ts=key_data["expired_ts"]
  433. )
  434. key_json_bytes = encode_canonical_json(response_json)
  435. yield make_deferred_yieldable(
  436. defer.gatherResults(
  437. [
  438. run_in_background(
  439. self.store.store_server_keys_json,
  440. server_name=server_name,
  441. key_id=key_id,
  442. from_server=from_server,
  443. ts_now_ms=time_added_ms,
  444. ts_expires_ms=ts_valid_until_ms,
  445. key_json_bytes=key_json_bytes,
  446. )
  447. for key_id in verify_keys
  448. ],
  449. consumeErrors=True,
  450. ).addErrback(unwrapFirstError)
  451. )
  452. return verify_keys
  453. class PerspectivesKeyFetcher(BaseV2KeyFetcher):
  454. """KeyFetcher impl which fetches keys from the "perspectives" servers"""
  455. def __init__(self, hs):
  456. super(PerspectivesKeyFetcher, self).__init__(hs)
  457. self.clock = hs.get_clock()
  458. self.client = hs.get_http_client()
  459. self.key_servers = self.config.key_servers
  460. @defer.inlineCallbacks
  461. def get_keys(self, keys_to_fetch):
  462. """see KeyFetcher.get_keys"""
  463. @defer.inlineCallbacks
  464. def get_key(key_server):
  465. try:
  466. result = yield self.get_server_verify_key_v2_indirect(
  467. keys_to_fetch, key_server
  468. )
  469. return result
  470. except KeyLookupError as e:
  471. logger.warning(
  472. "Key lookup failed from %r: %s", key_server.server_name, e
  473. )
  474. except Exception as e:
  475. logger.exception(
  476. "Unable to get key from %r: %s %s",
  477. key_server.server_name,
  478. type(e).__name__,
  479. str(e),
  480. )
  481. return {}
  482. results = yield make_deferred_yieldable(
  483. defer.gatherResults(
  484. [run_in_background(get_key, server) for server in self.key_servers],
  485. consumeErrors=True,
  486. ).addErrback(unwrapFirstError)
  487. )
  488. union_of_keys = {}
  489. for result in results:
  490. for server_name, keys in result.items():
  491. union_of_keys.setdefault(server_name, {}).update(keys)
  492. return union_of_keys
  493. @defer.inlineCallbacks
  494. def get_server_verify_key_v2_indirect(self, keys_to_fetch, key_server):
  495. """
  496. Args:
  497. keys_to_fetch (dict[str, dict[str, int]]):
  498. the keys to be fetched. server_name -> key_id -> min_valid_ts
  499. key_server (synapse.config.key.TrustedKeyServer): notary server to query for
  500. the keys
  501. Returns:
  502. Deferred[dict[str, dict[str, synapse.storage.keys.FetchKeyResult]]]: map
  503. from server_name -> key_id -> FetchKeyResult
  504. Raises:
  505. KeyLookupError if there was an error processing the entire response from
  506. the server
  507. """
  508. perspective_name = key_server.server_name
  509. logger.info(
  510. "Requesting keys %s from notary server %s",
  511. keys_to_fetch.items(),
  512. perspective_name,
  513. )
  514. try:
  515. query_response = yield self.client.post_json(
  516. destination=perspective_name,
  517. path="/_matrix/key/v2/query",
  518. data={
  519. "server_keys": {
  520. server_name: {
  521. key_id: {"minimum_valid_until_ts": min_valid_ts}
  522. for key_id, min_valid_ts in server_keys.items()
  523. }
  524. for server_name, server_keys in keys_to_fetch.items()
  525. }
  526. },
  527. )
  528. except (NotRetryingDestination, RequestSendFailed) as e:
  529. # these both have str() representations which we can't really improve upon
  530. raise KeyLookupError(str(e))
  531. except HttpResponseException as e:
  532. raise KeyLookupError("Remote server returned an error: %s" % (e,))
  533. keys = {}
  534. added_keys = []
  535. time_now_ms = self.clock.time_msec()
  536. for response in query_response["server_keys"]:
  537. # do this first, so that we can give useful errors thereafter
  538. server_name = response.get("server_name")
  539. if not isinstance(server_name, six.string_types):
  540. raise KeyLookupError(
  541. "Malformed response from key notary server %s: invalid server_name"
  542. % (perspective_name,)
  543. )
  544. try:
  545. self._validate_perspectives_response(key_server, response)
  546. processed_response = yield self.process_v2_response(
  547. perspective_name, response, time_added_ms=time_now_ms
  548. )
  549. except KeyLookupError as e:
  550. logger.warning(
  551. "Error processing response from key notary server %s for origin "
  552. "server %s: %s",
  553. perspective_name,
  554. server_name,
  555. e,
  556. )
  557. # we continue to process the rest of the response
  558. continue
  559. added_keys.extend(
  560. (server_name, key_id, key) for key_id, key in processed_response.items()
  561. )
  562. keys.setdefault(server_name, {}).update(processed_response)
  563. yield self.store.store_server_verify_keys(
  564. perspective_name, time_now_ms, added_keys
  565. )
  566. return keys
  567. def _validate_perspectives_response(self, key_server, response):
  568. """Optionally check the signature on the result of a /key/query request
  569. Args:
  570. key_server (synapse.config.key.TrustedKeyServer): the notary server that
  571. produced this result
  572. response (dict): the json-decoded Server Keys response object
  573. """
  574. perspective_name = key_server.server_name
  575. perspective_keys = key_server.verify_keys
  576. if perspective_keys is None:
  577. # signature checking is disabled on this server
  578. return
  579. if (
  580. "signatures" not in response
  581. or perspective_name not in response["signatures"]
  582. ):
  583. raise KeyLookupError("Response not signed by the notary server")
  584. verified = False
  585. for key_id in response["signatures"][perspective_name]:
  586. if key_id in perspective_keys:
  587. verify_signed_json(response, perspective_name, perspective_keys[key_id])
  588. verified = True
  589. if not verified:
  590. raise KeyLookupError(
  591. "Response not signed with a known key: signed with: %r, known keys: %r"
  592. % (
  593. list(response["signatures"][perspective_name].keys()),
  594. list(perspective_keys.keys()),
  595. )
  596. )
  597. class ServerKeyFetcher(BaseV2KeyFetcher):
  598. """KeyFetcher impl which fetches keys from the origin servers"""
  599. def __init__(self, hs):
  600. super(ServerKeyFetcher, self).__init__(hs)
  601. self.clock = hs.get_clock()
  602. self.client = hs.get_http_client()
  603. def get_keys(self, keys_to_fetch):
  604. """
  605. Args:
  606. keys_to_fetch (dict[str, iterable[str]]):
  607. the keys to be fetched. server_name -> key_ids
  608. Returns:
  609. Deferred[dict[str, dict[str, synapse.storage.keys.FetchKeyResult|None]]]:
  610. map from server_name -> key_id -> FetchKeyResult
  611. """
  612. results = {}
  613. @defer.inlineCallbacks
  614. def get_key(key_to_fetch_item):
  615. server_name, key_ids = key_to_fetch_item
  616. try:
  617. keys = yield self.get_server_verify_key_v2_direct(server_name, key_ids)
  618. results[server_name] = keys
  619. except KeyLookupError as e:
  620. logger.warning(
  621. "Error looking up keys %s from %s: %s", key_ids, server_name, e
  622. )
  623. except Exception:
  624. logger.exception("Error getting keys %s from %s", key_ids, server_name)
  625. return yieldable_gather_results(get_key, keys_to_fetch.items()).addCallback(
  626. lambda _: results
  627. )
  628. @defer.inlineCallbacks
  629. def get_server_verify_key_v2_direct(self, server_name, key_ids):
  630. """
  631. Args:
  632. server_name (str):
  633. key_ids (iterable[str]):
  634. Returns:
  635. Deferred[dict[str, FetchKeyResult]]: map from key ID to lookup result
  636. Raises:
  637. KeyLookupError if there was a problem making the lookup
  638. """
  639. keys = {} # type: dict[str, FetchKeyResult]
  640. for requested_key_id in key_ids:
  641. # we may have found this key as a side-effect of asking for another.
  642. if requested_key_id in keys:
  643. continue
  644. time_now_ms = self.clock.time_msec()
  645. try:
  646. response = yield self.client.get_json(
  647. destination=server_name,
  648. path="/_matrix/key/v2/server/"
  649. + urllib.parse.quote(requested_key_id),
  650. ignore_backoff=True,
  651. # we only give the remote server 10s to respond. It should be an
  652. # easy request to handle, so if it doesn't reply within 10s, it's
  653. # probably not going to.
  654. #
  655. # Furthermore, when we are acting as a notary server, we cannot
  656. # wait all day for all of the origin servers, as the requesting
  657. # server will otherwise time out before we can respond.
  658. #
  659. # (Note that get_json may make 4 attempts, so this can still take
  660. # almost 45 seconds to fetch the headers, plus up to another 60s to
  661. # read the response).
  662. timeout=10000,
  663. )
  664. except (NotRetryingDestination, RequestSendFailed) as e:
  665. # these both have str() representations which we can't really improve
  666. # upon
  667. raise KeyLookupError(str(e))
  668. except HttpResponseException as e:
  669. raise KeyLookupError("Remote server returned an error: %s" % (e,))
  670. if response["server_name"] != server_name:
  671. raise KeyLookupError(
  672. "Expected a response for server %r not %r"
  673. % (server_name, response["server_name"])
  674. )
  675. response_keys = yield self.process_v2_response(
  676. from_server=server_name,
  677. response_json=response,
  678. time_added_ms=time_now_ms,
  679. )
  680. yield self.store.store_server_verify_keys(
  681. server_name,
  682. time_now_ms,
  683. ((server_name, key_id, key) for key_id, key in response_keys.items()),
  684. )
  685. keys.update(response_keys)
  686. return keys
  687. @defer.inlineCallbacks
  688. def _handle_key_deferred(verify_request):
  689. """Waits for the key to become available, and then performs a verification
  690. Args:
  691. verify_request (VerifyJsonRequest):
  692. Returns:
  693. Deferred[None]
  694. Raises:
  695. SynapseError if there was a problem performing the verification
  696. """
  697. server_name = verify_request.server_name
  698. with PreserveLoggingContext():
  699. _, key_id, verify_key = yield verify_request.key_ready
  700. json_object = verify_request.json_object
  701. try:
  702. verify_signed_json(json_object, server_name, verify_key)
  703. except SignatureVerifyException as e:
  704. logger.debug(
  705. "Error verifying signature for %s:%s:%s with key %s: %s",
  706. server_name,
  707. verify_key.alg,
  708. verify_key.version,
  709. encode_verify_key_base64(verify_key),
  710. str(e),
  711. )
  712. raise SynapseError(
  713. 401,
  714. "Invalid signature for server %s with key %s:%s: %s"
  715. % (server_name, verify_key.alg, verify_key.version, str(e)),
  716. Codes.UNAUTHORIZED,
  717. )