feat(pusher): opt-in event type in event_id_only push notifications #2171
Closed
mmaudet
wants to merge 1 commit from
mmaudet/continuwuity:feat/pusher-eio-type-upstream into main
pull from: mmaudet/continuwuity:feat/pusher-eio-type-upstream
merge into: continuwuation:main
continuwuation:main
continuwuation:renovate/cargo-bins-cargo-binstall-1.x
continuwuation:aranje/illegal-car-mods
continuwuation:renovate/rust-1.x
continuwuation:morgan/arm64-runner
continuwuation:renovate/rand_core-0.x
continuwuation:renovate/ipaddress-0.x
continuwuation:renovate/base64-0.x
continuwuation:renovate/ruma-digest
continuwuation:next/meta/disable-ci-build-cache
continuwuation:fix/26.7.3
continuwuation:nex/feat/msc-fed-bidi-ping
continuwuation:nex/feat/backwards-compat-invites
continuwuation:1235-add-arm-deb
continuwuation:nex/feat/admin-api
continuwuation:nex/meta/release-schedule
continuwuation:nex/feat/centralise-remote-memberships
continuwuation:nex/feat/pdu-versions
continuwuation:ginger/revert-direct-tls
continuwuation:nex/fix/federated-invite-revoke
continuwuation:nex/fix/plunger
continuwuation:jade/perf/gme-rebased
continuwuation:nex/perf/get-missing-events2
continuwuation:nex/backport/v0.5.11
continuwuation:nex/backport/v0.5.10-backport
continuwuation:nex/feat/msc4491-invite-reasons-in-room-creation
continuwuation:nex/feat/deprecated-room-versions
continuwuation:release/v0.5.9
continuwuation:nex/feat/enable-debug-log-release-builds
continuwuation:nex/feat/room-purging
continuwuation:nex/feat/room-shutdown
continuwuation:ginger/ruma-upstreaming
continuwuation:jade/tls-backends
continuwuation:ginger/email-fixes
continuwuation:jade/changelog-labels
continuwuation:nex/fix/v12-publishing
continuwuation:jade/build-info
continuwuation:jade/purge-sync-tokens
continuwuation:ginger/terms-and-conditions
continuwuation:ginger/remove-sliding-sync-proxy
continuwuation:nex/fix/pusher-association
continuwuation:ginger/email-support
continuwuation:jade/community-guidelines
continuwuation:nex/fix/federation-format
continuwuation:jade/git-deps-updates
continuwuation:jade/changelog-check
continuwuation:jade/rust-1-92
continuwuation:ginger/password-reset
continuwuation:nex/experiment/push-gateway-logs
continuwuation:ginger/msc3575-obliteration
continuwuation:nex/feat/block-busted-rooms
continuwuation:nex/fix/informative-startup-errs
continuwuation:ginger/no-left-room-initial-sync
continuwuation:jade/docker-entrypoint
continuwuation:jade/dehydrated-devices
continuwuation:ginger/complement-fixes
continuwuation:nex/fix/stale-destination-cache
continuwuation:nex/experiment/sync-mutex
continuwuation:tcpipuk/docker-docs
continuwuation:jade/snafu
continuwuation:jade/rand-update
continuwuation:nex/stateres-refactor
continuwuation:ginger/779-in-troubleshooting
continuwuation:jade/liveit-guide
continuwuation:jade/http3
continuwuation:nex/feat/admin-hide-empty-rooms
continuwuation:ginger/oobe
continuwuation:nex/fix/debian-thingy
continuwuation:jade/ldap-admin-check
continuwuation:nex/fix/remote-restricted-joins
continuwuation:nex/feat/msc4406-sender-ignored
continuwuation:jade/deadlock-detection
continuwuation:jade/get-started
continuwuation:jade/docs-guide
continuwuation:ginger/fix-local-invites
continuwuation:nex/fix/tpi
continuwuation:nex/feat/room-deletion
continuwuation:nex/feat/msc4322-media-redaction
continuwuation:ginger/stitched-order
continuwuation:ginger/deps/update-rspress
continuwuation:jade/admin-announce-improvements
continuwuation:ginger/xtask-improvements
continuwuation:jade/improve-admin-config-display
continuwuation:nex/fix/better-stateres-error-logs
continuwuation:jade/sender-timeouts
continuwuation:nex/feat/custom-v12-room-ids
continuwuation:ginger/update-metadata
continuwuation:nex/feat/admin-force-logout
continuwuation:tom/max-perf-docs
continuwuation:nex/fix/invalid-appservice-reg
continuwuation:nex/feat/antispam
continuwuation:nex/feat/account-locking
continuwuation:jade/logging-cleanup
continuwuation:jade/remove-legacy-appservice-auth
continuwuation:nex/fix/key-query
continuwuation:jade/update-prek
continuwuation:nex/fix/room-summaries
continuwuation:ginger/restrict-admin-commands
continuwuation:ginger/enable-console-by-default
continuwuation:jade/tag-fixes
continuwuation:jade/otlp
continuwuation:nex/meta/pull-req-template
continuwuation:nex/fix/fed-invite-compliance
continuwuation:nex/feat/build-commit
continuwuation:nex/feat/join-logging
continuwuation:jade/mailmap-updates
continuwuation:jade/hack-ci-tmp
continuwuation:jade/v12-stable
continuwuation:jade/relations
continuwuation:ginger/database-refactor
continuwuation:jade/fix-ldap-uiaa
continuwuation:nex/fix/validation
continuwuation:ginger/nuke-invalid-msc4133-fields-in-migration
continuwuation:ginger/downgrade-artifact-actions
continuwuation:oddlid/reload-fix
continuwuation:jade/fix-assert
continuwuation:ginger/sync-v3-cleanup
continuwuation:ginger/remove-absolute-action-urls
continuwuation:jade/website
continuwuation:nex/fix/backoff
continuwuation:ginger/fix-mdbook-for-0.5
continuwuation:ginger/no-docker-on-prs
continuwuation:backport/v0.5.0-rc.8-1
continuwuation:nex/fed-improvements
continuwuation:jade/rust-1.90
continuwuation:jade/mirror-dockerhub
continuwuation:jade/clippy-fixes
continuwuation:jade/fix-support
continuwuation:jade/clean-images
continuwuation:jade/wal-compression-type
continuwuation:jade/flake-clone
continuwuation:ginger/upload-rpms-on-schedule
continuwuation:nex/fix/incoming-fetch
continuwuation:nex/fix/upgrade
continuwuation:tom/ci-fedora-rpm
continuwuation:jade/ci-release-fix
continuwuation:jade/rocksdb-10-5
continuwuation:ginger/fix-msc4133-migration
continuwuation:ginger/migrate-busted-tz
continuwuation:hydra/public
continuwuation:nex/feat/manual-extremities
continuwuation:nex/feat/async-media
continuwuation:nex/feat/fast-joins-hack-do-not-use-DO-NOT-USE
continuwuation:nex/feat/better-logging
continuwuation:trigger-ci-so-latest-isnt-on-illegal-car-mods
continuwuation:nex/feat/pins-backfill
continuwuation:jade/tuwunel-2025-06-old
continuwuation:jade/ai-slop-db-docs
continuwuation:nex/fix-create-auth
continuwuation:jade/version-stats
continuwuation:jade/read-receipts
continuwuation:jade/rust-toolchain-no-targets
continuwuation:jade/logging-features
continuwuation:jade/syncv5-typing
continuwuation:jade/msc2815
continuwuation:morguldir/see-eye
continuwuation:jade/css-small-screen
continuwuation:nex/wip-751
continuwuation:tuwunel-rebase
continuwuation:test
continuwuation:oddlid/rename-admin-room-bot
continuwuation:strawberry/nix-ci-stuff
continuwuation:strawberry/valgrind
continuwuation:phonemain
continuwuation:strawberry/morgs-snake-sync-jason-main
continuwuation:newer-media-endpoints
continuwuation:folly-coroutines-async-io
continuwuation:federation-retry-timer-port
continuwuation:bad-attempt-at-extracting-homeserver-signing-key
continuwuation:room-deletion-attempt-do-not-use
No reviewers
Labels
Clear labels
Abandoned
This pull request appears to be abandoned by its author.
Blocked
This pull request or issue is currently blocked from being merged/closed
Bug
Something isn't working as intended
Changelog
Added
Changelog entry added
Changelog
Missing
No changelog when one is needed
Changelog
None
Changelog is unnecesary for this change
Cherry-picking
Commits picked from other conduit projects
Database
This requires or includes changes to the database
Dependencies
Something dependency related
Dependencies/Renovate
Automatic dependency upgrades by Renovate
Difficulty
Easy
Low difficulty to implement - touches few parts of the codebase, low complexity
Difficulty
Hard
High difficulty to implement - touches many parts of the codebase, high complexity
Difficulty
Medium
Medium difficulty to implement - touches more parts of the codebase, higher complexity
Documentation
Improvements or additions to documentation
Enhancement
New feature or request
Good first issue
Good for newcomers
Help wanted
Additional eyes and keyboards are required for this one
Inherited
Issues that have been inhereted from the project pre-fork
Matrix/Administration
Features pertaining to homeserver administration
Matrix/Appservices
Features pertaining to the appservice API
Matrix/Auth
Features pertaining to authentication
Matrix/Client
Features pertaining to client-to-server interactions
Matrix/Core
Issues relating to core matrix functionality, such as state resolution and PDU formats
Matrix/E2EE
Issues related to end to end encryption
Matrix/Federation
Features pertaining to server-to-server interactions
Matrix/Hydra
Issues related to room version 12 and related changes (temporary label)
Matrix/MSC
Features pertaining to unstable matrix features
Matrix/Media
Features pertaining to media interactions
Matrix/T&S
Changes or issues related to trust & safety tooling
Merge
This PR is ready to be merged
Merge/Manual
This PR should be manually merged
Merge/Squash
This PR should be squashed when it is merged
Meta
Related to housekeeping, maintenance, or other repo-meta.
Meta/CI
Issues related to CI changes
Meta/Packaging
Packaging
Priority
Blocking
This issue is blocking the next release
Priority
High
This issue is very important
Priority
Low
This issue is of a rather low priority
Security
This item is related to general security
Status
Confirmed
This issue has enough information and is confirmed
Status
Duplicate
This issue or pull request already exists
Status
Invalid
This issue doesn't seem right
Status
Needs Investigation
This issue needs further investigation
Support
Questions or support requests
bob the builder
pdu logic rewrite starring nexus nicholson
No labels
Abandoned
Blocked
Bug
Changelog
Added
Changelog
Missing
Changelog
None
Cherry-picking
Database
Dependencies
Dependencies/Renovate
Difficulty
Easy
Difficulty
Hard
Difficulty
Medium
Documentation
Enhancement
Good first issue
Help wanted
Inherited
Matrix/Administration
Matrix/Appservices
Matrix/Auth
Matrix/Client
Matrix/Core
Matrix/E2EE
Matrix/Federation
Matrix/Hydra
Matrix/MSC
Matrix/Media
Matrix/T&S
Merge
Merge/Manual
Merge/Squash
Meta
Meta/CI
Meta/Packaging
Priority
Blocking
Priority
High
Priority
Low
Security
Status
Confirmed
Status
Duplicate
Status
Invalid
Status
Needs Investigation
Support
bob the builder
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set.
Reference
continuwuation/continuwuity!2171
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "mmaudet/continuwuity:feat/pusher-eio-type-upstream"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This pull request adds a config option,
pusher_event_id_only_include_event_type(default:false), that makes push notifications for HTTP pushers registered withdata.format = "event_id_only"carry the event'stype(e.g.m.call.invite) in addition to the event ID, room ID and counts. Nothing changes unless the option is enabled: the default behaviour is byte-for-byte what continuwuity sends today.Motivation
event_id_onlyis the format a privacy-conscious client picks so that the push gateway — typically a third party such as Sygnal, and beyond it FCM or APNs — learns as little as possible. Continuwuity honours it strictly: the notification carries onlyevent_id,room_idandcounts.That strictness has a cost for VoIP. On iOS, every PushKit push must be reported to CallKit immediately; a client that cannot tell an incoming call from an ordinary message without fetching the event over the network cannot decide whether to report an incoming call or a generic notification. A single fetch under push time pressure is exactly what VoIP pushes cannot afford, and on a bad network it loses the call.
With the event
type, the gateway can forward (and the client can act on) "this ism.call.invite" — while still seeing no content, no sender, no display name, no room name. The event type is routing metadata, not content.Why opt-in rather than unconditional
Changing the default payload shape would surprise gateways and clients that key on today's minimal shape — some gateway implementations choose their
event_id_onlycode path precisely by the absence oftype. An opt-in config flag lets an operator adopt this deliberately, with no effect for anyone else.Change
src/core/config/mod.rs: new booleanpusher_event_id_only_include_event_type, defaultfalse, documented next to the other pusher options.src/service/pusher/mod.rs: insend_notice, when the pusher isevent_id_onlyand the option is enabled, setnotify.event_type = Some(event.kind().to_owned()). Nothing else is added: sender, content, display names, room name/alias and tweaks stay stripped.conduwuit-example.toml: regenerated (it is a build artifact of the config doc comments).changelog.d/+pusher-event-id-only-event-type.feature.md.Verification
Built from this branch and probed with a recording HTTP gateway, a callee registered with two pushers — one
data.format = "event_id_only", one full format — and two events sent by the caller: anm.room.message(control) and anm.call.invite.Flag off (default): the
event_id_onlynotifications carry exactlyevent_id,room_id,counts,devices— the same key set as the unpatched server:Flag on: the same notifications additionally carry
"type"— and nothing else:The control message carries
"type": "m.room.message"; the call carries"type": "m.call.invite". Nosender,content,sender_display_name,room_name,room_aliasortweaksappear in either run, and the full-format pusher's payload is identical in both runs.Privacy note
The option is off by default and server-wide. An operator enabling it discloses, to the push gateways their users registered, only the event type of notifying events — the minimum metadata a VoIP push path needs. Users of servers that leave it off see no change at all.
Pull request checklist:
mainbranch, and the branch is named something other thanmain.cargo +nightly fmt --checkclean.)prek runon the changed files: all hooks pass.)cargo check --workspaceis green and the behaviour was verified live with the recording-gateway probe described above (flag off vs flag on, message vs call invite).Hey there. This seems like it should have an associated matrix spec poposal.
f7e7796d99d0a5bdc445@Jade wrote in #2171 (comment):
Agreed : this changes a payload the spec defines, so it belongs in an MSC rather than in a server option alone. I'll write one.
The constraint I'm trying to name, in case it's useful for the proposal: on iOS, a PushKit VoIP push must report an incoming call to CallKit before the handler returns, or the system terminates the app. There is no room for a network round-trip to /event first. With event_id_only the gateway cannot tell a call invite from a message, so a privacy-preserving push format and a working VoIP path are currently exclusive on that platform. The event type alone is the smallest thing that resolves it : no content, no sender, no room name.
Whichever you prefer: I can keep this open as a reference implementation while the MSC is discussed, or close it and reopen alongside the proposal. Say the word and I'll follow.
(I've also amended the commit : it carried a test-harness author identity by mistake.
You can use this as an example implementation even with it closed.
Pull request closed