keyring.py 33 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923
  1. # Copyright 2014-2021 The Matrix.org Foundation C.I.C.
  2. #
  3. # Licensed under the Apache License, Version 2.0 (the "License");
  4. # you may not use this file except in compliance with the License.
  5. # You may obtain a copy of the License at
  6. #
  7. # http://www.apache.org/licenses/LICENSE-2.0
  8. #
  9. # Unless required by applicable law or agreed to in writing, software
  10. # distributed under the License is distributed on an "AS IS" BASIS,
  11. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. # See the License for the specific language governing permissions and
  13. # limitations under the License.
  14. import abc
  15. import logging
  16. from typing import TYPE_CHECKING, Callable, Dict, Iterable, List, Optional, Tuple
  17. import attr
  18. from signedjson.key import (
  19. decode_verify_key_bytes,
  20. encode_verify_key_base64,
  21. get_verify_key,
  22. is_signing_algorithm_supported,
  23. )
  24. from signedjson.sign import (
  25. SignatureVerifyException,
  26. encode_canonical_json,
  27. signature_ids,
  28. verify_signed_json,
  29. )
  30. from signedjson.types import VerifyKey
  31. from unpaddedbase64 import decode_base64
  32. from twisted.internet import defer
  33. from synapse.api.errors import (
  34. Codes,
  35. HttpResponseException,
  36. RequestSendFailed,
  37. SynapseError,
  38. )
  39. from synapse.config.key import TrustedKeyServer
  40. from synapse.events import EventBase
  41. from synapse.events.utils import prune_event_dict
  42. from synapse.logging.context import make_deferred_yieldable, run_in_background
  43. from synapse.storage.keys import FetchKeyResult
  44. from synapse.types import JsonDict
  45. from synapse.util import unwrapFirstError
  46. from synapse.util.async_helpers import yieldable_gather_results
  47. from synapse.util.batching_queue import BatchingQueue
  48. from synapse.util.retryutils import NotRetryingDestination
  49. if TYPE_CHECKING:
  50. from synapse.server import HomeServer
  51. logger = logging.getLogger(__name__)
  52. @attr.s(slots=True, frozen=True, cmp=False, auto_attribs=True)
  53. class VerifyJsonRequest:
  54. """
  55. A request to verify a JSON object.
  56. Attributes:
  57. server_name: The name of the server to verify against.
  58. get_json_object: A callback to fetch the JSON object to verify.
  59. A callback is used to allow deferring the creation of the JSON
  60. object to verify until needed, e.g. for events we can defer
  61. creating the redacted copy. This reduces the memory usage when
  62. there are large numbers of in flight requests.
  63. minimum_valid_until_ts: time at which we require the signing key to
  64. be valid. (0 implies we don't care)
  65. key_ids: The set of key_ids to that could be used to verify the JSON object
  66. """
  67. server_name: str
  68. get_json_object: Callable[[], JsonDict]
  69. minimum_valid_until_ts: int
  70. key_ids: List[str]
  71. @staticmethod
  72. def from_json_object(
  73. server_name: str,
  74. json_object: JsonDict,
  75. minimum_valid_until_ms: int,
  76. ) -> "VerifyJsonRequest":
  77. """Create a VerifyJsonRequest to verify all signatures on a signed JSON
  78. object for the given server.
  79. """
  80. key_ids = signature_ids(json_object, server_name)
  81. return VerifyJsonRequest(
  82. server_name,
  83. lambda: json_object,
  84. minimum_valid_until_ms,
  85. key_ids=key_ids,
  86. )
  87. @staticmethod
  88. def from_event(
  89. server_name: str,
  90. event: EventBase,
  91. minimum_valid_until_ms: int,
  92. ) -> "VerifyJsonRequest":
  93. """Create a VerifyJsonRequest to verify all signatures on an event
  94. object for the given server.
  95. """
  96. key_ids = list(event.signatures.get(server_name, []))
  97. return VerifyJsonRequest(
  98. server_name,
  99. # We defer creating the redacted json object, as it uses a lot more
  100. # memory than the Event object itself.
  101. lambda: prune_event_dict(event.room_version, event.get_pdu_json()),
  102. minimum_valid_until_ms,
  103. key_ids=key_ids,
  104. )
  105. class KeyLookupError(ValueError):
  106. pass
  107. @attr.s(slots=True, frozen=True, auto_attribs=True)
  108. class _FetchKeyRequest:
  109. """A request for keys for a given server.
  110. We will continue to try and fetch until we have all the keys listed under
  111. `key_ids` (with an appropriate `valid_until_ts` property) or we run out of
  112. places to fetch keys from.
  113. Attributes:
  114. server_name: The name of the server that owns the keys.
  115. minimum_valid_until_ts: The timestamp which the keys must be valid until.
  116. key_ids: The IDs of the keys to attempt to fetch
  117. """
  118. server_name: str
  119. minimum_valid_until_ts: int
  120. key_ids: List[str]
  121. class Keyring:
  122. """Handles verifying signed JSON objects and fetching the keys needed to do
  123. so.
  124. """
  125. def __init__(
  126. self, hs: "HomeServer", key_fetchers: "Optional[Iterable[KeyFetcher]]" = None
  127. ):
  128. if key_fetchers is None:
  129. # Always fetch keys from the database.
  130. mutable_key_fetchers: List[KeyFetcher] = [StoreKeyFetcher(hs)]
  131. # Fetch keys from configured trusted key servers, if any exist.
  132. key_servers = hs.config.key.key_servers
  133. if key_servers:
  134. mutable_key_fetchers.append(PerspectivesKeyFetcher(hs))
  135. # Finally, fetch keys from the origin server directly.
  136. mutable_key_fetchers.append(ServerKeyFetcher(hs))
  137. self._key_fetchers: Iterable[KeyFetcher] = tuple(mutable_key_fetchers)
  138. else:
  139. self._key_fetchers = key_fetchers
  140. self._fetch_keys_queue: BatchingQueue[
  141. _FetchKeyRequest, Dict[str, Dict[str, FetchKeyResult]]
  142. ] = BatchingQueue(
  143. "keyring_server",
  144. clock=hs.get_clock(),
  145. # The method called to fetch each key
  146. process_batch_callback=self._inner_fetch_key_requests,
  147. )
  148. self._is_mine_server_name = hs.is_mine_server_name
  149. # build a FetchKeyResult for each of our own keys, to shortcircuit the
  150. # fetcher.
  151. self._local_verify_keys: Dict[str, FetchKeyResult] = {}
  152. for key_id, key in hs.config.key.old_signing_keys.items():
  153. self._local_verify_keys[key_id] = FetchKeyResult(
  154. verify_key=key, valid_until_ts=key.expired
  155. )
  156. vk = get_verify_key(hs.signing_key)
  157. self._local_verify_keys[f"{vk.alg}:{vk.version}"] = FetchKeyResult(
  158. verify_key=vk,
  159. valid_until_ts=2**63, # fake future timestamp
  160. )
  161. async def verify_json_for_server(
  162. self,
  163. server_name: str,
  164. json_object: JsonDict,
  165. validity_time: int,
  166. ) -> None:
  167. """Verify that a JSON object has been signed by a given server
  168. Completes if the the object was correctly signed, otherwise raises.
  169. Args:
  170. server_name: name of the server which must have signed this object
  171. json_object: object to be checked
  172. validity_time: timestamp at which we require the signing key to
  173. be valid. (0 implies we don't care)
  174. """
  175. request = VerifyJsonRequest.from_json_object(
  176. server_name,
  177. json_object,
  178. validity_time,
  179. )
  180. return await self.process_request(request)
  181. def verify_json_objects_for_server(
  182. self, server_and_json: Iterable[Tuple[str, dict, int]]
  183. ) -> List["defer.Deferred[None]"]:
  184. """Bulk verifies signatures of json objects, bulk fetching keys as
  185. necessary.
  186. Args:
  187. server_and_json:
  188. Iterable of (server_name, json_object, validity_time)
  189. tuples.
  190. validity_time is a timestamp at which the signing key must be
  191. valid.
  192. Returns:
  193. For each input triplet, a deferred indicating success or failure to
  194. verify each json object's signature for the given server_name. The
  195. deferreds run their callbacks in the sentinel logcontext.
  196. """
  197. return [
  198. run_in_background(
  199. self.process_request,
  200. VerifyJsonRequest.from_json_object(
  201. server_name,
  202. json_object,
  203. validity_time,
  204. ),
  205. )
  206. for server_name, json_object, validity_time in server_and_json
  207. ]
  208. async def verify_event_for_server(
  209. self,
  210. server_name: str,
  211. event: EventBase,
  212. validity_time: int,
  213. ) -> None:
  214. await self.process_request(
  215. VerifyJsonRequest.from_event(
  216. server_name,
  217. event,
  218. validity_time,
  219. )
  220. )
  221. async def process_request(self, verify_request: VerifyJsonRequest) -> None:
  222. """Processes the `VerifyJsonRequest`. Raises if the object is not signed
  223. by the server, the signatures don't match or we failed to fetch the
  224. necessary keys.
  225. """
  226. if not verify_request.key_ids:
  227. raise SynapseError(
  228. 400,
  229. f"Not signed by {verify_request.server_name}",
  230. Codes.UNAUTHORIZED,
  231. )
  232. found_keys: Dict[str, FetchKeyResult] = {}
  233. # If we are the originating server, short-circuit the key-fetch for any keys
  234. # we already have
  235. if self._is_mine_server_name(verify_request.server_name):
  236. for key_id in verify_request.key_ids:
  237. if key_id in self._local_verify_keys:
  238. found_keys[key_id] = self._local_verify_keys[key_id]
  239. key_ids_to_find = set(verify_request.key_ids) - found_keys.keys()
  240. if key_ids_to_find:
  241. # Add the keys we need to verify to the queue for retrieval. We queue
  242. # up requests for the same server so we don't end up with many in flight
  243. # requests for the same keys.
  244. key_request = _FetchKeyRequest(
  245. server_name=verify_request.server_name,
  246. minimum_valid_until_ts=verify_request.minimum_valid_until_ts,
  247. key_ids=list(key_ids_to_find),
  248. )
  249. found_keys_by_server = await self._fetch_keys_queue.add_to_queue(
  250. key_request, key=verify_request.server_name
  251. )
  252. # Since we batch up requests the returned set of keys may contain keys
  253. # from other servers, so we pull out only the ones we care about.
  254. found_keys.update(found_keys_by_server.get(verify_request.server_name, {}))
  255. # Verify each signature we got valid keys for, raising if we can't
  256. # verify any of them.
  257. verified = False
  258. for key_id in verify_request.key_ids:
  259. key_result = found_keys.get(key_id)
  260. if not key_result:
  261. continue
  262. if key_result.valid_until_ts < verify_request.minimum_valid_until_ts:
  263. continue
  264. await self._process_json(key_result.verify_key, verify_request)
  265. verified = True
  266. if not verified:
  267. raise SynapseError(
  268. 401,
  269. f"Failed to find any key to satisfy: {key_request}",
  270. Codes.UNAUTHORIZED,
  271. )
  272. async def _process_json(
  273. self, verify_key: VerifyKey, verify_request: VerifyJsonRequest
  274. ) -> None:
  275. """Processes the `VerifyJsonRequest`. Raises if the signature can't be
  276. verified.
  277. """
  278. try:
  279. verify_signed_json(
  280. verify_request.get_json_object(),
  281. verify_request.server_name,
  282. verify_key,
  283. )
  284. except SignatureVerifyException as e:
  285. logger.debug(
  286. "Error verifying signature for %s:%s:%s with key %s: %s",
  287. verify_request.server_name,
  288. verify_key.alg,
  289. verify_key.version,
  290. encode_verify_key_base64(verify_key),
  291. str(e),
  292. )
  293. raise SynapseError(
  294. 401,
  295. "Invalid signature for server %s with key %s:%s: %s"
  296. % (
  297. verify_request.server_name,
  298. verify_key.alg,
  299. verify_key.version,
  300. str(e),
  301. ),
  302. Codes.UNAUTHORIZED,
  303. )
  304. async def _inner_fetch_key_requests(
  305. self, requests: List[_FetchKeyRequest]
  306. ) -> Dict[str, Dict[str, FetchKeyResult]]:
  307. """Processing function for the queue of `_FetchKeyRequest`.
  308. Takes a list of key fetch requests, de-duplicates them and then carries out
  309. each request by invoking self._inner_fetch_key_request.
  310. Args:
  311. requests: A list of requests for homeserver verify keys.
  312. Returns:
  313. {server name: {key id: fetch key result}}
  314. """
  315. logger.debug("Starting fetch for %s", requests)
  316. # First we need to deduplicate requests for the same key. We do this by
  317. # taking the *maximum* requested `minimum_valid_until_ts` for each pair
  318. # of server name/key ID.
  319. server_to_key_to_ts: Dict[str, Dict[str, int]] = {}
  320. for request in requests:
  321. by_server = server_to_key_to_ts.setdefault(request.server_name, {})
  322. for key_id in request.key_ids:
  323. existing_ts = by_server.get(key_id, 0)
  324. by_server[key_id] = max(request.minimum_valid_until_ts, existing_ts)
  325. deduped_requests = [
  326. _FetchKeyRequest(server_name, minimum_valid_ts, [key_id])
  327. for server_name, by_server in server_to_key_to_ts.items()
  328. for key_id, minimum_valid_ts in by_server.items()
  329. ]
  330. logger.debug("Deduplicated key requests to %s", deduped_requests)
  331. # For each key we call `_inner_verify_request` which will handle
  332. # fetching each key. Note these shouldn't throw if we fail to contact
  333. # other servers etc.
  334. results_per_request = await yieldable_gather_results(
  335. self._inner_fetch_key_request,
  336. deduped_requests,
  337. )
  338. # We now convert the returned list of results into a map from server
  339. # name to key ID to FetchKeyResult, to return.
  340. to_return: Dict[str, Dict[str, FetchKeyResult]] = {}
  341. for request, results in zip(deduped_requests, results_per_request):
  342. to_return_by_server = to_return.setdefault(request.server_name, {})
  343. for key_id, key_result in results.items():
  344. existing = to_return_by_server.get(key_id)
  345. if not existing or existing.valid_until_ts < key_result.valid_until_ts:
  346. to_return_by_server[key_id] = key_result
  347. return to_return
  348. async def _inner_fetch_key_request(
  349. self, verify_request: _FetchKeyRequest
  350. ) -> Dict[str, FetchKeyResult]:
  351. """Attempt to fetch the given key by calling each key fetcher one by one.
  352. If a key is found, check whether its `valid_until_ts` attribute satisfies the
  353. `minimum_valid_until_ts` attribute of the `verify_request`. If it does, we
  354. refrain from asking subsequent fetchers for that key.
  355. Even if the above check fails, we still return the found key - the caller may
  356. still find the invalid key result useful. In this case, we continue to ask
  357. subsequent fetchers for the invalid key, in case they return a valid result
  358. for it. This can happen when fetching a stale key result from the database,
  359. before querying the origin server for an up-to-date result.
  360. Args:
  361. verify_request: The request for a verify key. Can include multiple key IDs.
  362. Returns:
  363. A map of {key_id: the key fetch result}.
  364. """
  365. logger.debug("Starting fetch for %s", verify_request)
  366. found_keys: Dict[str, FetchKeyResult] = {}
  367. missing_key_ids = set(verify_request.key_ids)
  368. for fetcher in self._key_fetchers:
  369. if not missing_key_ids:
  370. break
  371. logger.debug("Getting keys from %s for %s", fetcher, verify_request)
  372. keys = await fetcher.get_keys(
  373. verify_request.server_name,
  374. list(missing_key_ids),
  375. verify_request.minimum_valid_until_ts,
  376. )
  377. for key_id, key in keys.items():
  378. if not key:
  379. continue
  380. # If we already have a result for the given key ID, we keep the
  381. # one with the highest `valid_until_ts`.
  382. existing_key = found_keys.get(key_id)
  383. if existing_key and existing_key.valid_until_ts > key.valid_until_ts:
  384. continue
  385. # Check if this key's expiry timestamp is valid for the verify request.
  386. if key.valid_until_ts >= verify_request.minimum_valid_until_ts:
  387. # Stop looking for this key from subsequent fetchers.
  388. missing_key_ids.discard(key_id)
  389. # We always store the returned key even if it doesn't meet the
  390. # `minimum_valid_until_ts` requirement, as some verification
  391. # requests may still be able to be satisfied by it.
  392. found_keys[key_id] = key
  393. return found_keys
  394. class KeyFetcher(metaclass=abc.ABCMeta):
  395. def __init__(self, hs: "HomeServer"):
  396. self._queue = BatchingQueue(
  397. self.__class__.__name__, hs.get_clock(), self._fetch_keys
  398. )
  399. async def get_keys(
  400. self, server_name: str, key_ids: List[str], minimum_valid_until_ts: int
  401. ) -> Dict[str, FetchKeyResult]:
  402. results = await self._queue.add_to_queue(
  403. _FetchKeyRequest(
  404. server_name=server_name,
  405. key_ids=key_ids,
  406. minimum_valid_until_ts=minimum_valid_until_ts,
  407. )
  408. )
  409. return results.get(server_name, {})
  410. @abc.abstractmethod
  411. async def _fetch_keys(
  412. self, keys_to_fetch: List[_FetchKeyRequest]
  413. ) -> Dict[str, Dict[str, FetchKeyResult]]:
  414. pass
  415. class StoreKeyFetcher(KeyFetcher):
  416. """KeyFetcher impl which fetches keys from our data store"""
  417. def __init__(self, hs: "HomeServer"):
  418. super().__init__(hs)
  419. self.store = hs.get_datastores().main
  420. async def _fetch_keys(
  421. self, keys_to_fetch: List[_FetchKeyRequest]
  422. ) -> Dict[str, Dict[str, FetchKeyResult]]:
  423. key_ids_to_fetch = (
  424. (queue_value.server_name, key_id)
  425. for queue_value in keys_to_fetch
  426. for key_id in queue_value.key_ids
  427. )
  428. res = await self.store.get_server_keys_json(key_ids_to_fetch)
  429. keys: Dict[str, Dict[str, FetchKeyResult]] = {}
  430. for (server_name, key_id), key in res.items():
  431. keys.setdefault(server_name, {})[key_id] = key
  432. return keys
  433. class BaseV2KeyFetcher(KeyFetcher):
  434. def __init__(self, hs: "HomeServer"):
  435. super().__init__(hs)
  436. self.store = hs.get_datastores().main
  437. async def process_v2_response(
  438. self, from_server: str, response_json: JsonDict, time_added_ms: int
  439. ) -> Dict[str, FetchKeyResult]:
  440. """Parse a 'Server Keys' structure from the result of a /key request
  441. This is used to parse either the entirety of the response from
  442. GET /_matrix/key/v2/server, or a single entry from the list returned by
  443. POST /_matrix/key/v2/query.
  444. Checks that each signature in the response that claims to come from the origin
  445. server is valid, and that there is at least one such signature.
  446. Stores the json in server_keys_json so that it can be used for future responses
  447. to /_matrix/key/v2/query.
  448. Args:
  449. from_server: the name of the server producing this result: either
  450. the origin server for a /_matrix/key/v2/server request, or the notary
  451. for a /_matrix/key/v2/query.
  452. response_json: the json-decoded Server Keys response object
  453. time_added_ms: the timestamp to record in server_keys_json
  454. Returns:
  455. Map from key_id to result object
  456. """
  457. ts_valid_until_ms = response_json["valid_until_ts"]
  458. # start by extracting the keys from the response, since they may be required
  459. # to validate the signature on the response.
  460. verify_keys = {}
  461. for key_id, key_data in response_json["verify_keys"].items():
  462. if is_signing_algorithm_supported(key_id):
  463. key_base64 = key_data["key"]
  464. key_bytes = decode_base64(key_base64)
  465. verify_key = decode_verify_key_bytes(key_id, key_bytes)
  466. verify_keys[key_id] = FetchKeyResult(
  467. verify_key=verify_key, valid_until_ts=ts_valid_until_ms
  468. )
  469. server_name = response_json["server_name"]
  470. verified = False
  471. for key_id in response_json["signatures"].get(server_name, {}):
  472. key = verify_keys.get(key_id)
  473. if not key:
  474. # the key may not be present in verify_keys if:
  475. # * we got the key from the notary server, and:
  476. # * the key belongs to the notary server, and:
  477. # * the notary server is using a different key to sign notary
  478. # responses.
  479. continue
  480. verify_signed_json(response_json, server_name, key.verify_key)
  481. verified = True
  482. break
  483. if not verified:
  484. raise KeyLookupError(
  485. "Key response for %s is not signed by the origin server"
  486. % (server_name,)
  487. )
  488. for key_id, key_data in response_json["old_verify_keys"].items():
  489. if is_signing_algorithm_supported(key_id):
  490. key_base64 = key_data["key"]
  491. key_bytes = decode_base64(key_base64)
  492. verify_key = decode_verify_key_bytes(key_id, key_bytes)
  493. verify_keys[key_id] = FetchKeyResult(
  494. verify_key=verify_key, valid_until_ts=key_data["expired_ts"]
  495. )
  496. key_json_bytes = encode_canonical_json(response_json)
  497. await make_deferred_yieldable(
  498. defer.gatherResults(
  499. [
  500. run_in_background(
  501. self.store.store_server_keys_json,
  502. server_name=server_name,
  503. key_id=key_id,
  504. from_server=from_server,
  505. ts_now_ms=time_added_ms,
  506. ts_expires_ms=ts_valid_until_ms,
  507. key_json_bytes=key_json_bytes,
  508. )
  509. for key_id in verify_keys
  510. ],
  511. consumeErrors=True,
  512. ).addErrback(unwrapFirstError)
  513. )
  514. return verify_keys
  515. class PerspectivesKeyFetcher(BaseV2KeyFetcher):
  516. """KeyFetcher impl which fetches keys from the "perspectives" servers"""
  517. def __init__(self, hs: "HomeServer"):
  518. super().__init__(hs)
  519. self.clock = hs.get_clock()
  520. self.client = hs.get_federation_http_client()
  521. self.key_servers = hs.config.key.key_servers
  522. async def _fetch_keys(
  523. self, keys_to_fetch: List[_FetchKeyRequest]
  524. ) -> Dict[str, Dict[str, FetchKeyResult]]:
  525. """see KeyFetcher._fetch_keys"""
  526. async def get_key(key_server: TrustedKeyServer) -> Dict:
  527. try:
  528. return await self.get_server_verify_key_v2_indirect(
  529. keys_to_fetch, key_server
  530. )
  531. except KeyLookupError as e:
  532. logger.warning(
  533. "Key lookup failed from %r: %s", key_server.server_name, e
  534. )
  535. except Exception as e:
  536. logger.exception(
  537. "Unable to get key from %r: %s %s",
  538. key_server.server_name,
  539. type(e).__name__,
  540. str(e),
  541. )
  542. return {}
  543. results = await make_deferred_yieldable(
  544. defer.gatherResults(
  545. [run_in_background(get_key, server) for server in self.key_servers],
  546. consumeErrors=True,
  547. ).addErrback(unwrapFirstError)
  548. )
  549. union_of_keys: Dict[str, Dict[str, FetchKeyResult]] = {}
  550. for result in results:
  551. for server_name, keys in result.items():
  552. union_of_keys.setdefault(server_name, {}).update(keys)
  553. return union_of_keys
  554. async def get_server_verify_key_v2_indirect(
  555. self, keys_to_fetch: List[_FetchKeyRequest], key_server: TrustedKeyServer
  556. ) -> Dict[str, Dict[str, FetchKeyResult]]:
  557. """
  558. Args:
  559. keys_to_fetch:
  560. the keys to be fetched.
  561. key_server: notary server to query for the keys
  562. Returns:
  563. Map from server_name -> key_id -> FetchKeyResult
  564. Raises:
  565. KeyLookupError if there was an error processing the entire response from
  566. the server
  567. """
  568. perspective_name = key_server.server_name
  569. logger.info(
  570. "Requesting keys %s from notary server %s",
  571. keys_to_fetch,
  572. perspective_name,
  573. )
  574. request: JsonDict = {}
  575. for queue_value in keys_to_fetch:
  576. # there may be multiple requests for each server, so we have to merge
  577. # them intelligently.
  578. request_for_server = {
  579. key_id: {
  580. "minimum_valid_until_ts": queue_value.minimum_valid_until_ts,
  581. }
  582. for key_id in queue_value.key_ids
  583. }
  584. request.setdefault(queue_value.server_name, {}).update(request_for_server)
  585. logger.debug("Request to notary server %s: %s", perspective_name, request)
  586. try:
  587. query_response = await self.client.post_json(
  588. destination=perspective_name,
  589. path="/_matrix/key/v2/query",
  590. data={"server_keys": request},
  591. )
  592. except (NotRetryingDestination, RequestSendFailed) as e:
  593. # these both have str() representations which we can't really improve upon
  594. raise KeyLookupError(str(e))
  595. except HttpResponseException as e:
  596. raise KeyLookupError("Remote server returned an error: %s" % (e,))
  597. logger.debug(
  598. "Response from notary server %s: %s", perspective_name, query_response
  599. )
  600. keys: Dict[str, Dict[str, FetchKeyResult]] = {}
  601. added_keys: Dict[Tuple[str, str], FetchKeyResult] = {}
  602. time_now_ms = self.clock.time_msec()
  603. assert isinstance(query_response, dict)
  604. for response in query_response["server_keys"]:
  605. # do this first, so that we can give useful errors thereafter
  606. server_name = response.get("server_name")
  607. if not isinstance(server_name, str):
  608. raise KeyLookupError(
  609. "Malformed response from key notary server %s: invalid server_name"
  610. % (perspective_name,)
  611. )
  612. try:
  613. self._validate_perspectives_response(key_server, response)
  614. processed_response = await self.process_v2_response(
  615. perspective_name, response, time_added_ms=time_now_ms
  616. )
  617. except KeyLookupError as e:
  618. logger.warning(
  619. "Error processing response from key notary server %s for origin "
  620. "server %s: %s",
  621. perspective_name,
  622. server_name,
  623. e,
  624. )
  625. # we continue to process the rest of the response
  626. continue
  627. for key_id, key in processed_response.items():
  628. dict_key = (server_name, key_id)
  629. if dict_key in added_keys:
  630. already_present_key = added_keys[dict_key]
  631. logger.warning(
  632. "Duplicate server keys for %s (%s) from perspective %s (%r, %r)",
  633. server_name,
  634. key_id,
  635. perspective_name,
  636. already_present_key,
  637. key,
  638. )
  639. if already_present_key.valid_until_ts > key.valid_until_ts:
  640. # Favour the entry with the largest valid_until_ts,
  641. # as `old_verify_keys` are also collected from this
  642. # response.
  643. continue
  644. added_keys[dict_key] = key
  645. keys.setdefault(server_name, {}).update(processed_response)
  646. await self.store.store_server_signature_keys(
  647. perspective_name, time_now_ms, added_keys
  648. )
  649. return keys
  650. def _validate_perspectives_response(
  651. self, key_server: TrustedKeyServer, response: JsonDict
  652. ) -> None:
  653. """Optionally check the signature on the result of a /key/query request
  654. Args:
  655. key_server: the notary server that produced this result
  656. response: the json-decoded Server Keys response object
  657. """
  658. perspective_name = key_server.server_name
  659. perspective_keys = key_server.verify_keys
  660. if perspective_keys is None:
  661. # signature checking is disabled on this server
  662. return
  663. if (
  664. "signatures" not in response
  665. or perspective_name not in response["signatures"]
  666. ):
  667. raise KeyLookupError("Response not signed by the notary server")
  668. verified = False
  669. for key_id in response["signatures"][perspective_name]:
  670. if key_id in perspective_keys:
  671. verify_signed_json(response, perspective_name, perspective_keys[key_id])
  672. verified = True
  673. if not verified:
  674. raise KeyLookupError(
  675. "Response not signed with a known key: signed with: %r, known keys: %r"
  676. % (
  677. list(response["signatures"][perspective_name].keys()),
  678. list(perspective_keys.keys()),
  679. )
  680. )
  681. class ServerKeyFetcher(BaseV2KeyFetcher):
  682. """KeyFetcher impl which fetches keys from the origin servers"""
  683. def __init__(self, hs: "HomeServer"):
  684. super().__init__(hs)
  685. self.clock = hs.get_clock()
  686. self.client = hs.get_federation_http_client()
  687. async def get_keys(
  688. self, server_name: str, key_ids: List[str], minimum_valid_until_ts: int
  689. ) -> Dict[str, FetchKeyResult]:
  690. results = await self._queue.add_to_queue(
  691. _FetchKeyRequest(
  692. server_name=server_name,
  693. key_ids=key_ids,
  694. minimum_valid_until_ts=minimum_valid_until_ts,
  695. ),
  696. key=server_name,
  697. )
  698. return results.get(server_name, {})
  699. async def _fetch_keys(
  700. self, keys_to_fetch: List[_FetchKeyRequest]
  701. ) -> Dict[str, Dict[str, FetchKeyResult]]:
  702. """
  703. Args:
  704. keys_to_fetch:
  705. the keys to be fetched. server_name -> key_ids
  706. Returns:
  707. Map from server_name -> key_id -> FetchKeyResult
  708. """
  709. results = {}
  710. async def get_keys(key_to_fetch_item: _FetchKeyRequest) -> None:
  711. server_name = key_to_fetch_item.server_name
  712. try:
  713. keys = await self.get_server_verify_keys_v2_direct(server_name)
  714. results[server_name] = keys
  715. except KeyLookupError as e:
  716. logger.warning("Error looking up keys from %s: %s", server_name, e)
  717. except Exception:
  718. logger.exception("Error getting keys from %s", server_name)
  719. await yieldable_gather_results(get_keys, keys_to_fetch)
  720. return results
  721. async def get_server_verify_keys_v2_direct(
  722. self, server_name: str
  723. ) -> Dict[str, FetchKeyResult]:
  724. """
  725. Args:
  726. server_name: Server to request keys from
  727. Returns:
  728. Map from key ID to lookup result
  729. Raises:
  730. KeyLookupError if there was a problem making the lookup
  731. """
  732. time_now_ms = self.clock.time_msec()
  733. try:
  734. response = await self.client.get_json(
  735. destination=server_name,
  736. path="/_matrix/key/v2/server",
  737. ignore_backoff=True,
  738. # we only give the remote server 10s to respond. It should be an
  739. # easy request to handle, so if it doesn't reply within 10s, it's
  740. # probably not going to.
  741. #
  742. # Furthermore, when we are acting as a notary server, we cannot
  743. # wait all day for all of the origin servers, as the requesting
  744. # server will otherwise time out before we can respond.
  745. #
  746. # (Note that get_json may make 4 attempts, so this can still take
  747. # almost 45 seconds to fetch the headers, plus up to another 60s to
  748. # read the response).
  749. timeout=10000,
  750. )
  751. except (NotRetryingDestination, RequestSendFailed) as e:
  752. # these both have str() representations which we can't really improve
  753. # upon
  754. raise KeyLookupError(str(e))
  755. except HttpResponseException as e:
  756. raise KeyLookupError("Remote server returned an error: %s" % (e,))
  757. assert isinstance(response, dict)
  758. if response["server_name"] != server_name:
  759. raise KeyLookupError(
  760. "Expected a response for server %r not %r"
  761. % (server_name, response["server_name"])
  762. )
  763. return await self.process_v2_response(
  764. from_server=server_name,
  765. response_json=response,
  766. time_added_ms=time_now_ms,
  767. )