fix(federation): sign restricted join events before verification #1997

Merged
nex merged 1 commit from eleboucher/continuwuity:fix-federation-signature into main 2026-07-16 19:56:33 +00:00
Contributor

Restricted room joins over federation between two continuwuity servers fail with M_INVALID_PARAM: Signature verification failed on membership event: Could not find signatures for entity.

Move the resident server's signing to the send_join route handler, before calling validate_any_membership_event with skip_verification=true. Then verify only the sender's signature via a new verify_event_for_server method.

Spec reference

The resident server which owns the provided user ID must have a valid signature on the event. If the resident server is receiving the /send_join request, the signature must be added before sending or persisting the event to other servers.

Pull request checklist:

  • This pull request targets the main branch, and the branch is named something other than
    main.
  • I have written an appropriate pull request title and my description is clear.
  • I understand I am responsible for the contents of this pull request.
  • I have followed the contributing guidelines:
<!-- In order to help reviewers know what your pull request does at a glance, you should ensure that 1. Your PR title is a short, single sentence describing what you changed 2. You have described in more detail what you have changed, why you have changed it, what the intended effect is, and why you think this will be beneficial to the project. If you have made any potentially strange/questionable design choices, but didn't feel they'd benefit from code comments, please don't mention them here - after opening your pull request, go to "files changed", and click on the "+" symbol in the line number gutter, and attach comments to the lines that you think would benefit from some clarification. --> Restricted room joins over federation between two continuwuity servers fail with M_INVALID_PARAM: Signature verification failed on membership event: Could not find signatures for entity. Move the resident server's signing to the send_join route handler, before calling validate_any_membership_event with skip_verification=true. Then verify only the sender's signature via a new verify_event_for_server method. Spec reference > The resident server which owns the provided user ID must have a valid signature on the event. If the resident server is receiving the /send_join request, the signature must be added before sending or persisting the event to other servers. <!-- Example: This pull request allows us to warp through time and space ten times faster than before by double-inverting the warp drive with hyperheated jump fluid, both making the drive faster and more efficient. This resolves the common issue where we have to wait more than 10 milliseconds to engage, use, and disengage the warp drive when travelling between galaxies. --> <!-- Closes: #... --> <!-- Fixes: #... --> <!-- Uncomment the above line(s) if your pull request fixes an issue or closes another pull request by superseding it. Replace `#...` with the issue/pr number, such as `#123`. --> **Pull request checklist:** <!-- You need to complete these before your PR can be considered. If you aren't sure about some, feel free to ask for clarification in #dev:continuwuity.org. --> - [x] This pull request targets the `main` branch, and the branch is named something other than `main`. - [x] I have written an appropriate pull request title and my description is clear. - [x] I understand I am responsible for the contents of this pull request. - I have followed the [contributing guidelines][c1]: - [x] My contribution follows the [code style][c2], if applicable. - [x] I ran [pre-commit checks][c1pc] before opening/drafting this pull request. - [x] I have [tested my contribution][c1t] (or proof-read it for documentation-only changes) myself, if applicable. This includes ensuring code compiles. - [x] My commit messages follow the [commit message format][c1cm] and are descriptive. <!-- Notes on these requirements: - While not required, we encourage you to sign your commits with GPG or SSH to attest the authenticity of your changes. - While we allow LLM-assisted contributions, we do not appreciate contributions that are low quality, which is typical of machine-generated contributions that have not had a lot of love and care from a human. Please do not open a PR if all you have done is asked ChatGPT to tidy up the codebase with a +-100,000 diff. - In the case of code style violations, reviewers may leave review comments/change requests indicating what the ideal change would look like. For example, a reviewer may suggest you lower a log level, or use `match` instead of `if/else` etc. - In the case of code style violations, pre-commit check failures, minor things like typos/spelling errors, and in some cases commit format violations, reviewers may modify your branch directly, typically by making changes and adding a commit. Particularly in the latter case, a reviewer may rebase your commits to squash "spammy" ones (like "fix", "fix", "actually fix"), and reword commit messages that don't satisfy the format. - Pull requests MUST pass the `Checks` CI workflows to be capable of being merged. This can only be bypassed in exceptional circumstances. If your CI flakes, let us know in matrix:r/dev:continuwuity.org. - Pull requests have to be based on the latest `main` commit before being merged. If the main branch changes while you're making your changes, you should make sure you rebase on main before opening a PR. Your branch will be rebased on main before it is merged if it has fallen behind. - We typically only do fast-forward merges, so your entire commit log will be included. Once in main, it's difficult to get out cleanly, so put on your best dress, smile for the cameras! --> [c1]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md [c2]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/docs/development/code_style.mdx [c1pc]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#pre-commit-checks [c1t]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#running-tests-locally [c1cm]: https://forgejo.ellis.link/continuwuation/continuwuity/src/branch/main/CONTRIBUTING.md#commit-messages
fix(federation): Sign restricted join events before verification
Some checks failed
Auto Labeler / Apply labels based on changed files (pull_request_target) Successful in 3s
Checks / Changelog / Check changelog is added (pull_request_target) Failing after 7s
Documentation / Build and Deploy Documentation (pull_request) Has been cancelled
Checks / Prek / Pre-commit & Formatting (pull_request) Has been cancelled
Checks / Prek / Check changed files (pull_request) Has been cancelled
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
ab165deb52
@ -250,1 +244,4 @@
// Verify only the sender's signature before adding our own for restricted
// joins. The full signature check (including the authorising server's) is
// done by other servers when they receive the event via /send.
Owner

This comment is unnecessary/lacks sufficient context

This comment is unnecessary/lacks sufficient context
Author
Contributor

sorry i should have started as draft this was my chain of thought comments :D

sorry i should have started as draft this was my chain of thought comments :D
nex marked this conversation as resolved
eleboucher force-pushed fix-federation-signature from ab165deb52
Some checks failed
Auto Labeler / Apply labels based on changed files (pull_request_target) Successful in 3s
Checks / Changelog / Check changelog is added (pull_request_target) Failing after 7s
Documentation / Build and Deploy Documentation (pull_request) Has been cancelled
Checks / Prek / Pre-commit & Formatting (pull_request) Has been cancelled
Checks / Prek / Check changed files (pull_request) Has been cancelled
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
to 1a2468bd3a
Some checks failed
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 6s
Documentation / Build and Deploy Documentation (pull_request) Has been cancelled
Checks / Prek / Pre-commit & Formatting (pull_request) Has been cancelled
Checks / Prek / Check changed files (pull_request) Has been cancelled
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
2026-07-15 19:44:39 +00:00
Compare
eleboucher force-pushed fix-federation-signature from 1a2468bd3a
Some checks failed
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 6s
Documentation / Build and Deploy Documentation (pull_request) Has been cancelled
Checks / Prek / Pre-commit & Formatting (pull_request) Has been cancelled
Checks / Prek / Check changed files (pull_request) Has been cancelled
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
to 67866ebd5d
Some checks failed
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 6s
Documentation / Build and Deploy Documentation (pull_request) Has been cancelled
Checks / Prek / Pre-commit & Formatting (pull_request) Has been cancelled
Checks / Prek / Check changed files (pull_request) Has been cancelled
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
2026-07-15 19:45:12 +00:00
Compare
@ -120,3 +116,1 @@
.map_err(|e| {
err!(Request(InvalidParam(warn!("Failed to sign send_join event: {e}"))))
})?;
// The event was already signed by us in create_join_event_v2_route.
Owner

I'm not really sure this is a sensible change. Moving the signature to earlier the call chain requires we parse the event a second time, and runs the risk of potentially leaking a signature on an invalid event (which we've had 2 CVEs for already)

I'm not really sure this is a sensible change. Moving the signature to earlier the call chain requires we parse the event a second time, and runs the risk of potentially leaking a signature on an invalid event (which we've had 2 CVEs for already)
Author
Contributor

okay let me change the logic quickly, it was my first draft which should make it better for this concern

okay let me change the logic quickly, it was my first draft which should make it better for this concern
Author
Contributor

here is my minimal implementation

here is my minimal implementation
nex marked this conversation as resolved
@ -260,0 +257,4 @@
.verify_event_for_server(sender.server_name(), &value)
.await
.map_err(|e| {
err!(Request(InvalidParam("Signature verification failed on membership event: {e}")))
Owner

Not a huge fan of decentralising signature checks, the signature rules have changed before and it's plausible this code could fall behind. Can't we just sign the event before checking signatures? If the origin's signature is invalid it'll still error out, while retaining the herd safety of being checked by a central function

Not a huge fan of decentralising signature checks, the signature rules have changed before and it's plausible this code could fall behind. Can't we just sign the event before checking signatures? If the origin's signature is invalid it'll still error out, while retaining the herd safety of being checked by a central function
eleboucher marked this conversation as resolved
eleboucher force-pushed fix-federation-signature from 67866ebd5d
Some checks failed
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 6s
Documentation / Build and Deploy Documentation (pull_request) Has been cancelled
Checks / Prek / Pre-commit & Formatting (pull_request) Has been cancelled
Checks / Prek / Check changed files (pull_request) Has been cancelled
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
to e576fb2efa
Some checks failed
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 6s
Documentation / Build and Deploy Documentation (pull_request) Has been cancelled
Checks / Prek / Pre-commit & Formatting (pull_request) Has been cancelled
Checks / Prek / Check changed files (pull_request) Has been cancelled
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
2026-07-15 19:53:12 +00:00
Compare
eleboucher force-pushed fix-federation-signature from e576fb2efa
Some checks failed
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 6s
Documentation / Build and Deploy Documentation (pull_request) Has been cancelled
Checks / Prek / Pre-commit & Formatting (pull_request) Has been cancelled
Checks / Prek / Check changed files (pull_request) Has been cancelled
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
to 23cb74b948
Some checks failed
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 6s
Documentation / Build and Deploy Documentation (pull_request) Has been cancelled
Checks / Prek / Pre-commit & Formatting (pull_request) Has been cancelled
Checks / Prek / Check changed files (pull_request) Has been cancelled
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
2026-07-15 19:55:39 +00:00
Compare
eleboucher force-pushed fix-federation-signature from 23cb74b948
Some checks failed
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 6s
Documentation / Build and Deploy Documentation (pull_request) Has been cancelled
Checks / Prek / Pre-commit & Formatting (pull_request) Has been cancelled
Checks / Prek / Check changed files (pull_request) Has been cancelled
Checks / Prek / Clippy and Cargo Tests (pull_request) Has been cancelled
to 944e6de4af
All checks were successful
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Prek / Check changed files (pull_request) Successful in 6s
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 6s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 2m14s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 9m1s
2026-07-16 15:00:43 +00:00
Compare
nex requested review from nex 2026-07-16 17:21:50 +00:00
nex approved these changes 2026-07-16 17:23:21 +00:00
Dismissed
nex left a comment

I think this is fine, assuming callers of validate_any_membership_event correctly abort when the incoming event is found to be invalid later on (which I think they all do). I'll improve this whole system later to avoid this possibility in the first place

I think this is fine, assuming callers of `validate_any_membership_event` correctly abort when the incoming event is found to be invalid later on (which I think they all do). I'll improve this whole system later to avoid this possibility in the first place
nex scheduled this pull request to auto merge when all checks succeed 2026-07-16 17:24:38 +00:00
nex canceled auto merging this pull request when all checks succeed 2026-07-16 17:24:57 +00:00
eleboucher force-pushed fix-federation-signature from 944e6de4af
All checks were successful
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Prek / Check changed files (pull_request) Successful in 6s
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 6s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 2m14s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 9m1s
to 3c607eea46
All checks were successful
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 6s
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Prek / Check changed files (pull_request) Successful in 5s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m32s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 8m5s
2026-07-16 18:11:14 +00:00
Compare
nex approved these changes 2026-07-16 18:48:52 +00:00
nex scheduled this pull request to auto merge when all checks succeed 2026-07-16 18:49:00 +00:00
eleboucher force-pushed fix-federation-signature from 3c607eea46
All checks were successful
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 6s
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Prek / Check changed files (pull_request) Successful in 5s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 1m32s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 8m5s
to 8945cc9e10
Some checks failed
Documentation / Build and Deploy Documentation (pull_request) Has been skipped
Checks / Prek / Check changed files (pull_request) Successful in 6s
Checks / Changelog / Check changelog is added (pull_request_target) Successful in 6s
Checks / Prek / Pre-commit & Formatting (pull_request) Successful in 3m6s
Checks / Prek / Clippy and Cargo Tests (pull_request) Successful in 9m38s
Documentation / Build and Deploy Documentation (push) Successful in 1m15s
Checks / Prek / Check changed files (push) Successful in 4s
Checks / Prek / Pre-commit & Formatting (push) Successful in 2m55s
Checks / Prek / Clippy and Cargo Tests (push) Successful in 9m33s
Release Docker Image / Build linux-amd64 (release) (push) Successful in 13m56s
Release Docker Image / Build linux-arm64 (release) (push) Successful in 11m0s
Release Docker Image / Create Multi-arch Release Manifest (push) Successful in 16s
Release Docker Image / Build linux-amd64 (max-perf) (push) Failing after 2m45s
Release Docker Image / Build linux-arm64 (max-perf) (push) Successful in 35m22s
Release Docker Image / Create Max-Perf Manifest (push) Has been skipped
Release Docker Image / Mirror Images (push) Has been skipped
Release Docker Image / Release Binaries (push) Has been skipped
2026-07-16 19:46:44 +00:00
Compare
nex merged commit 8945cc9e10 into main 2026-07-16 19:56:33 +00:00
nex deleted branch fix-federation-signature 2026-07-16 19:56:33 +00:00
Sign in to join this conversation.
No reviewers
nex
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
continuwuation/continuwuity!1997
No description provided.