GNUnet 0.28.1-dev.4-24-g0cf3356dd
 
Loading...
Searching...
No Matches
pils_api.c
Go to the documentation of this file.
1/*
2 This file is part of GNUnet.
3 Copyright (C) 2024, 2026 GNUnet e.V.
4
5 GNUnet is free software: you can redistribute it and/or modify it
6 under the terms of the GNU Affero General Public License as published
7 by the Free Software Foundation, either version 3 of the License,
8 or (at your option) any later version.
9
10 GNUnet is distributed in the hope that it will be useful, but
11 WITHOUT ANY WARRANTY; without even the implied warranty of
12 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
13 Affero General Public License for more details.
14
15 You should have received a copy of the GNU Affero General Public License
16 along with this program. If not, see <http://www.gnu.org/licenses/>.
17
18 SPDX-License-Identifier: AGPL3.0-or-later
19 */
20
33#include <string.h>
34#include <stdint.h>
35#include "gnunet_common.h"
36#include "gnunet_protocols.h"
37#include "gnunet_signatures.h"
38#include "gnunet_util_lib.h"
40#include "gnunet_pils_service.h"
41#include "pils.h"
42
43/* Shorthand for Logging */
44#define LOG(kind, ...) GNUNET_log_from (kind, "pils-api", __VA_ARGS__)
45
46
48{
49 // DLL
51
52 // DLL
54
55 // Service handle
57
58 // Decaps callback
60
61 // Ecdh callback
63
64 // Sign callback
66
67 // Decaps callback closure
68 void *cb_cls;
69
70 /* The request, kept for as long as the operation is outstanding so that
71 #flush_ops() can send it again after a reconnect. The service answers
72 a request and forgets it, so a request that was in flight when the
73 connection broke is simply lost -- and its callback would never run,
74 leaving the caller waiting forever. */
76
77 // Op ID
78 uint32_t op_id;
79};
80
81
86{
87 /* The handle to the configuration */
89
90 /* Callback called with the new peer id */
92
93 /* Closure to the #pid_change_cb callback */
95
96 /* Task regularly trying to connect to the service */
98
99 /* Delay until the next reconnect */
101
102 /* Handle to the mq to communicate with the service */
104
105 /* The current peer_id */
107
108 /* The current peer id hash */
110
111 /* The hash from the last set of addresses fed to PILS. */
113
114 /* The peer's master key, as loaded from [PEER]/PRIVATE_KEY. Only
115 valid if @e have_ikm is true. */
116 unsigned char initial_key_material[256 / 8];
117
118 /* The private key of the current peer identity, derived from
119 @e initial_key_material and @e hash. NULL if local key access was
120 not enabled, or if no peer identity is known yet. */
122
123 /* Did we load @e initial_key_material (i.e. was
124 #GNUNET_PILS_enable_private_key() called successfully)? */
126
131
136
141
142};
143
144
185
197static void
199{
200 struct GNUNET_PILS_Handle *h = op->h;
201
202 if (NULL == h->mq)
203 {
205 "Not connected to PILS, deferring request %u\n",
206 (unsigned int) op->op_id);
207 return;
208 }
210 GNUNET_MQ_msg_copy (op->req));
211}
212
213
226static void
228{
229 for (struct GNUNET_PILS_Operation *op = h->op_head;
230 NULL != op;
231 op = op->next)
232 transmit_op (op);
233}
234
235
245static struct GNUNET_PILS_Operation *
248{
250
252 op->h = h;
253 op->req = req;
255 h->op_tail,
256 op);
257 return op;
258}
259
260
266static void
268{
269 struct GNUNET_PILS_Handle *h = op->h;
270
272 h->op_tail,
273 op);
274 GNUNET_free (op->req);
275 GNUNET_free (op);
276}
277
278
286static struct GNUNET_PILS_Operation *
287find_op (struct GNUNET_PILS_Handle *h, uint32_t rid)
288{
290
291 for (op = h->op_head; op != NULL; op = op->next)
292 if (op->op_id == rid)
293 return op;
295 "Finding request with id %u was unsuccessful\n",
296 rid);
297 return NULL;
298}
299
300
307static int
308check_peer_id (void *cls, const struct PeerIdUpdateMessage *msg)
309{
310 size_t msg_size;
311 uint32_t block_bytes;
312 (void) cls;
313
314 msg_size = ntohs (msg->header.size);
315 block_bytes = ntohl (msg->block_len);
316 if (msg_size != sizeof (*msg) + block_bytes)
317 {
319 "The msg_size (%lu) is not %lu (header) + %u (block)\n",
320 msg_size,
321 sizeof (*msg),
322 block_bytes);
323 return GNUNET_SYSERR;
324 }
325 return GNUNET_OK;
326
327}
328
329
346static void
348{
349 struct GNUNET_PeerIdentity pid;
350
351 if (! h->have_ikm)
352 return;
353 if (NULL == h->private_key)
354 h->private_key = GNUNET_new (struct GNUNET_CRYPTO_EddsaPrivateKey);
355 GNUNET_PILS_derive_pid (sizeof (h->initial_key_material),
356 h->initial_key_material,
357 &h->hash,
358 h->private_key);
360 &pid.public_key);
361 if (0 != GNUNET_memcmp (&pid,
362 h->peer_id))
363 {
365 "Locally derived peer identity %s does not match %s announced by the service; check [PEER]/PRIVATE_KEY\n",
366 GNUNET_i2s (&pid),
367 GNUNET_i2s (h->peer_id));
368 GNUNET_CRYPTO_zero_keys (h->private_key,
369 sizeof (*h->private_key));
370 GNUNET_free (h->private_key);
371 h->private_key = NULL;
372 return;
373 }
375 "Derived private key for peer identity %s\n",
376 GNUNET_i2s (h->peer_id));
377}
378
379
386static void
387handle_peer_id (void *cls, const struct PeerIdUpdateMessage *pid_msg)
388{
389 struct GNUNET_PILS_Handle *h = cls;
390 struct GNUNET_HELLO_Parser *parser;
391 uint32_t block_bytes;
392
393 h->reconnect_delay = GNUNET_TIME_UNIT_ZERO;
394 block_bytes = ntohl (pid_msg->block_len);
395 parser = GNUNET_HELLO_parser_from_block (&pid_msg[1],
396 block_bytes);
397 if (NULL == parser)
398 {
400 "Error parsing Hello block from PILS!\n");
401 return;
402 }
403
404 if (NULL == h->peer_id)
405 h->peer_id = GNUNET_new (struct GNUNET_PeerIdentity);
406
407 memcpy (&h->hash, &pid_msg->hash, sizeof (struct GNUNET_HashCode));
408 memcpy (h->peer_id, GNUNET_HELLO_parser_get_id (parser),
409 sizeof (struct GNUNET_PeerIdentity));
410 GNUNET_CRYPTO_hash (h->peer_id, sizeof (struct GNUNET_PeerIdentity),
411 &h->peer_hash);
413
414 if (NULL != h->pid_change_cb)
415 {
416 h->pid_change_cb (h->pid_change_cb_cls,
417 parser,
418 &pid_msg->hash);
419 }
421}
422
423
430static void
431handle_sign_result (void *cls, const struct SignResultMessage *msg)
432{
433 struct GNUNET_PILS_Handle *h = cls;
435
436 h->reconnect_delay = GNUNET_TIME_UNIT_ZERO;
437 op = find_op (h, ntohl (msg->rid));
438
440 "Received SIGN_RESULT message from service\n");
441
442 if (NULL == op)
443 {
445 "Didn't find the operation corresponding to id %u\n",
446 ntohl (msg->rid));
447 return;
448 }
449 if (NULL != op->sign_cb)
450 {
451 // FIXME maybe return NULL of key is 0ed
452 // as this indicates an error
453 op->sign_cb (op->cb_cls,
454 &msg->peer_id,
455 &msg->sig);
456 }
457 op_destroy (op);
458}
459
460
467static void
469{
470 struct GNUNET_PILS_Handle *h = cls;
472
474 "Received KEM_DECAPS result from service!\n");
475
476 h->reconnect_delay = GNUNET_TIME_UNIT_ZERO;
477 op = find_op (h, ntohl (msg->rid));
478
479 if (NULL == op)
480 {
482 "Didn't find the operation corresponding to id %u\n",
483 ntohl (msg->rid));
484 return;
485 }
486 if (NULL != op->decaps_cb)
487 {
488 // FIXME maybe return NULL of key is 0ed
489 // as this indicates an error
490 op->decaps_cb (op->cb_cls,
491 &msg->key);
492 }
493 op_destroy (op);
494}
495
496
503static void
504handle_ecdh_result (void *cls, const struct EcdhResultMessage *msg)
505{
506 struct GNUNET_PILS_Handle *h = cls;
508
510 "Received ECDH result from service!\n");
511
512 h->reconnect_delay = GNUNET_TIME_UNIT_ZERO;
513 op = find_op (h, ntohl (msg->rid));
514
515 if (NULL == op)
516 {
518 "Didn't find the operation corresponding to id %u\n",
519 ntohl (msg->rid));
520 return;
521 }
522 if (NULL != op->ecdh_cb)
523 op->ecdh_cb (op->cb_cls,
524 &msg->key);
525 op_destroy (op);
526}
527
528
534static void
535reconnect (void *cls);
536
537
545static void
546mq_error_handler (void *cls, enum GNUNET_MQ_Error error)
547{
548 struct GNUNET_PILS_Handle *h = cls;
549 (void) error;
550
551 // TODO logging
553 "Connection to pils service failed!\n");
555 h->mq = NULL;
556 /* NOTE: @e op_head is deliberately left alone. The requests in it died
557 with the connection, but their callers are still waiting for the
558 callbacks -- #flush_ops() re-sends them once we are back. Dropping
559 them here silently (as this used to do) leaves e.g. CORE holding a
560 half-finished handshake and a TRANSPORT flow control credit it never
561 returns. */
563 GNUNET_SCHEDULER_add_delayed (h->reconnect_delay, &reconnect, h);
564 h->reconnect_delay = GNUNET_TIME_STD_BACKOFF (h->reconnect_delay);
565}
566
567
573static void
574reconnect (void *cls)
575{
576 struct GNUNET_PILS_Handle *h = cls;
580 struct PeerIdUpdateMessage,
581 h),
582 GNUNET_MQ_hd_fixed_size (decaps_result,
584 struct DecapsResultMessage,
585 h),
586 GNUNET_MQ_hd_fixed_size (ecdh_result,
588 struct EcdhResultMessage,
589 h),
590 GNUNET_MQ_hd_fixed_size (sign_result,
592 struct SignResultMessage,
593 h),
595 };
596
597 h->reconnect_task = NULL;
599 "Connecting to peer identity lifecycle service.\n");
600 GNUNET_assert (NULL == h->mq);
602 "pils",
603 handlers,
605 h);
606 if (NULL == h->mq)
607 {
609 "Failed to connect.\n");
610 {
612 GNUNET_SCHEDULER_add_delayed (h->reconnect_delay, &reconnect, h);
613 h->reconnect_delay = GNUNET_TIME_STD_BACKOFF (h->reconnect_delay);
614 }
615 return;
616 }
618 "Connection to service successful!\n");
619 flush_ops (h);
620}
621
622
623struct GNUNET_PILS_Handle *
626 void *cls)
627{
628 struct GNUNET_PILS_Handle *h;
629
631 h->cfg = cfg;
632 h->pid_change_cb = pid_change_cb;
633 h->pid_change_cb_cls = cls;
634 h->reconnect_delay = GNUNET_TIME_UNIT_ZERO;
635 reconnect (h);
636 return h;
637}
638
639
646void
648{
650
651 GNUNET_assert (NULL != handle);
653 "Disonnecting from peer identity lifecycle service.\n");
654 if (NULL != handle->reconnect_task)
655 {
656 GNUNET_SCHEDULER_cancel (handle->reconnect_task);
657 handle->reconnect_task = NULL;
658 }
659 if (NULL != handle->mq)
660 {
662 handle->mq = NULL;
663 }
664 LOG (GNUNET_ERROR_TYPE_DEBUG, "Cleaning up\n");
665 while (NULL != (op = handle->op_head))
666 op_destroy (op);
667 if (handle->peer_id)
668 GNUNET_free (handle->peer_id);
669 if (NULL != handle->private_key)
670 {
671 GNUNET_CRYPTO_zero_keys (handle->private_key,
672 sizeof (*handle->private_key));
673 GNUNET_free (handle->private_key);
674 }
675 GNUNET_CRYPTO_zero_keys (handle->initial_key_material,
676 sizeof (handle->initial_key_material));
678}
679
680
693 const struct
696 void *cb_cls)
697
698{
700 struct SignRequestMessage *msg;
701 size_t plen = ntohl (purpose->size);
702
703 GNUNET_assert (sizeof (*msg) + plen <= UINT16_MAX);
704 msg = GNUNET_malloc (sizeof (*msg) + plen);
706 msg->header.size = htons (sizeof (*msg) + plen);
707 msg->rid = htonl (handle->op_id_counter++);
708 memcpy (&msg[1], purpose, plen);
709 op = op_start (handle, &msg->header);
710 op->sign_cb = cb;
711 op->cb_cls = cb_cls;
712 op->op_id = ntohl (msg->rid);
713 transmit_op (op);
714 return op;
715}
716
717
729 const struct GNUNET_CRYPTO_HpkeEncapsulation *c,
731 void *cb_cls)
732{
734 struct DecapsMessage *msg;
735
736 msg = GNUNET_new (struct DecapsMessage);
738 msg->header.size = htons (sizeof (*msg));
739 msg->c = *c;
740 msg->rid = htonl (handle->op_id_counter++);
741 op = op_start (handle, &msg->header);
742 op->decaps_cb = cb;
743 op->cb_cls = cb_cls;
744 op->op_id = ntohl (msg->rid);
745 transmit_op (op);
746 return op;
747}
748
749
752 const struct GNUNET_CRYPTO_EcdhePublicKey *pub,
754 void *cb_cls)
755{
757 struct EcdhMessage *msg;
758
759 GNUNET_assert ((handle) && (pub));
760
761 msg = GNUNET_new (struct EcdhMessage);
762 msg->header.type = htons (GNUNET_MESSAGE_TYPE_PILS_ECDH);
763 msg->header.size = htons (sizeof (*msg));
764 msg->pub = *pub;
765 msg->rid = htonl (handle->op_id_counter++);
766 op = op_start (handle, &msg->header);
767 op->ecdh_cb = cb;
768 op->cb_cls = cb_cls;
769 op->op_id = ntohl (msg->rid);
770 transmit_op (op);
771 return op;
772}
773
774
775void
780
781
782void
783GNUNET_PILS_derive_pid (size_t seed_key_bytes,
784 const uint8_t seed_key[seed_key_bytes],
785 const struct GNUNET_HashCode *addrs_hash,
786 struct GNUNET_CRYPTO_EddsaPrivateKey *outkey)
787{
788 struct GNUNET_ShortHashCode prk;
789
797 addrs_hash,
798 sizeof *addrs_hash,
799 seed_key,
800 seed_key_bytes));
809 outkey,
810 sizeof *outkey,
811 &prk,
812 GNUNET_CRYPTO_kdf_arg_string ("gnunet-pils-ephemeral-peer-key"));
813}
814
815
816void
818 const struct GNUNET_HELLO_Builder *builder)
819{
821 struct GNUNET_MQ_Envelope *env;
822 size_t block_bytes;
823
825 // TODO check whether the new hash and the 'current' hash are the same -
826 // nothing to do in that case (directly return the peer id?)
828 block_bytes,
830 msg->block_len = htonl (block_bytes);
832 builder,
833 NULL,
834 NULL,
836 (char*) &msg[1]);
838}
839
840
852 const struct GNUNET_HELLO_Builder *builder,
853 struct GNUNET_TIME_Absolute et,
855 void *cb_cls)
856{
857 struct PilsHelloSignaturePurpose hsp = {
858 .purpose.size = htonl (sizeof (hsp)),
859 .purpose.purpose = htonl (GNUNET_SIGNATURE_PURPOSE_HELLO),
860 .expiration_time = GNUNET_TIME_absolute_hton (et)
861 };
863 &hsp.h_addrs);
865 "Address hash is %s\n",
866 GNUNET_h2s_full (&hsp.h_addrs));
868 &hsp.purpose,
869 cb,
870 cb_cls);
871}
872
873
874const struct GNUNET_PeerIdentity*
876{
878
879 return handle->peer_id;
880}
881
882
883const struct GNUNET_HashCode*
885{
887
888 if (NULL == handle->peer_id)
889 return NULL;
890
891 return &handle->peer_hash;
892}
893
894
897{
898 char *keyfile;
900
902 if (handle->have_ikm)
903 return GNUNET_OK; /* already enabled */
904 if (GNUNET_OK !=
906 "PEER",
907 "PRIVATE_KEY",
908 &keyfile))
909 {
911 "PEER",
912 "PRIVATE_KEY");
913 return GNUNET_SYSERR;
914 }
915 if (GNUNET_SYSERR ==
918 &key))
919 {
921 "Failed to load the peer's private key from `%s'\n",
922 keyfile);
923 GNUNET_free (keyfile);
924 return GNUNET_SYSERR;
925 }
926 GNUNET_free (keyfile);
927 GNUNET_assert (sizeof (handle->initial_key_material) == sizeof (key.d));
928 memcpy (handle->initial_key_material,
929 key.d,
930 sizeof (handle->initial_key_material));
932 sizeof (key));
933 handle->have_ikm = true;
934 /* If the service already told us our identity, catch up now so that
935 callers do not have to wait for the next PID change. */
936 if (NULL != handle->peer_id)
938 return GNUNET_OK;
939}
940
941
944{
946
947 return handle->private_key;
948}
949
950
951void
952pid_change_cb (void *cls,
953 GNUNET_UNUSED const struct GNUNET_HELLO_Parser *parser,
954 const struct GNUNET_HashCode *addr_hash)
955{
958
959 GNUNET_assert ((cls) && (addr_hash));
960
961 key_ring = cls;
962
964 "Got PID to derive from `%s':\n",
965 GNUNET_h2s (addr_hash));
966 if (NULL == key_ring->private_key)
967 {
970 }
971 else
973
976 addr_hash,
981 sizeof (key_ring->identity),
982 &(key_ring->hash));
983
984
986 &(key_ring->identity)));
987
988 if (GNUNET_YES != initialized)
989 return;
990
991 GNUNET_log (GNUNET_ERROR_TYPE_DEBUG, "Initialize key ring\n");
992
993 if (key_ring->init_cb)
995}
996
997
1007struct GNUNET_PILS_KeyRing*
1010 void *cls)
1011{
1012 char *keyfile;
1014
1016
1017 LOG (GNUNET_ERROR_TYPE_DEBUG, "Create key ring!\n");
1018
1019 if (GNUNET_OK !=
1021 "PEER",
1022 "PRIVATE_KEY",
1023 &keyfile))
1024 {
1026 "PEER",
1027 "PRIVATE_KEY");
1028 return NULL;
1029 }
1030
1031 if (GNUNET_SYSERR ==
1033 GNUNET_YES,
1034 &key))
1035 {
1037 "Failed to setup peer's private key\n");
1038 GNUNET_free (keyfile);
1039 return NULL;
1040 }
1041
1042 GNUNET_free (keyfile);
1043
1046 if (NULL == key_ring)
1047 return NULL;
1049 key_ring->cls = cls;
1050
1051 GNUNET_assert (sizeof (key_ring->initial_key_material) == sizeof key.d);
1052
1054 if (NULL == key_ring->pils)
1055 {
1057 return NULL;
1058 }
1059
1060 memcpy (key_ring->initial_key_material, key.d,
1061 sizeof (key_ring->initial_key_material));
1062
1063 return key_ring;
1064}
1065
1066
1067void
1088
1089
1098
1099
1100/* end of pils_api.c */
struct GNUNET_MQ_MessageHandlers handlers[]
Definition 003.c:1
struct GNUNET_MessageHeader * msg
Definition 005.c:2
struct GNUNET_MQ_Envelope * env
Definition 005.c:1
static struct GNUNET_ARM_Operation * op
Current operation.
Definition gnunet-arm.c:143
static struct GNUNET_ARM_Handle * h
Connection with ARM.
Definition gnunet-arm.c:98
static struct GNUNET_CONFIGURATION_Handle * cfg
Our configuration.
Definition gnunet-arm.c:108
static char * peer_id
Option –peer.
static struct GNUNET_PILS_KeyRing * key_ring
For PILS.
static struct HostSet * builder
NULL if we are not currently iterating over peer information.
struct GNUNET_HashCode key
The key used in the DHT.
static uint8_t seed_key[256/8]
static struct GNUNET_CRYPTO_EddsaPublicKey pub
static struct GNUNET_VPN_Handle * handle
Handle to vpn service.
Definition gnunet-vpn.c:35
commonly used definitions; globals in this file are exempt from the rule that the module name ("commo...
Helper library for handling HELLO URIs.
void(* GNUNET_PILS_PidChangeCallback)(void *cls, const struct GNUNET_HELLO_Parser *parser, const struct GNUNET_HashCode *hash)
A handler/callback to be called on the change of the peer id.
void(* GNUNET_PILS_DecapsResultCallback)(void *cls, const struct GNUNET_ShortHashCode *key)
A handler/callback to be called for decaps.
void(* GNUNET_PILS_EcdhResultCallback)(void *cls, const struct GNUNET_HashCode *key)
A handler/callback to be called for ecdh.
void(* GNUNET_PILS_SignResultCallback)(void *cls, const struct GNUNET_PeerIdentity *pid, const struct GNUNET_CRYPTO_EddsaSignature *sig)
A handler/callback to be called for signatures.
Constants for network protocols.
#define GNUNET_SIGNATURE_PURPOSE_HELLO
Signature by which a peer affirms its address.
struct GNUNET_MQ_Handle * GNUNET_CLIENT_connect(const struct GNUNET_CONFIGURATION_Handle *cfg, const char *service_name, const struct GNUNET_MQ_MessageHandler *handlers, GNUNET_MQ_ErrorHandler error_handler, void *error_handler_cls)
Create a message queue to connect to a GNUnet service.
Definition client.c:1182
enum GNUNET_GenericReturnValue GNUNET_CONFIGURATION_get_value_filename(const struct GNUNET_CONFIGURATION_Handle *cfg, const char *section, const char *option, char **value)
Get a configuration value that should be the name of a file or directory.
enum GNUNET_GenericReturnValue GNUNET_CRYPTO_eddsa_key_from_file(const char *filename, int do_create, struct GNUNET_CRYPTO_EddsaPrivateKey *pkey)
Create a new private key by reading it from a file.
void GNUNET_CRYPTO_eddsa_key_get_public(const struct GNUNET_CRYPTO_EddsaPrivateKey *priv, struct GNUNET_CRYPTO_EddsaPublicKey *pub)
Extract the public key for the given private key.
Definition crypto_ecc.c:202
void GNUNET_CRYPTO_zero_keys(void *buffer, size_t length)
Zero out buffer, securely against compiler optimizations.
#define GNUNET_CONTAINER_DLL_remove(head, tail, element)
Remove an element from a DLL.
#define GNUNET_CONTAINER_DLL_insert(head, tail, element)
Insert an element at the head of a DLL.
enum GNUNET_GenericReturnValue GNUNET_CRYPTO_hkdf_extract(struct GNUNET_ShortHashCode *prk, const void *salt, size_t salt_len, const void *ikm, size_t ikm_len)
HKDF-Extract using SHA256.
void GNUNET_CRYPTO_hash(const void *block, size_t size, struct GNUNET_HashCode *ret)
Compute hash of a given block.
Definition crypto_hash.c:40
#define GNUNET_CRYPTO_hkdf_expand(result, out_len, prk,...)
HKDF-Expand using SHA256.
void GNUNET_HELLO_parser_free(struct GNUNET_HELLO_Parser *parser)
Release resources of a builder.
Definition hello-uri.c:380
void GNUNET_HELLO_builder_to_block(const struct GNUNET_HELLO_Builder *builder, const struct GNUNET_PeerIdentity *pid, const struct GNUNET_CRYPTO_EddsaSignature *sig, struct GNUNET_TIME_Absolute expiration_time, char *outbuf)
Generate DHT block from a builder.
Definition hello-uri.c:1309
size_t GNUNET_HELLO_get_builder_to_block_size(const struct GNUNET_HELLO_Builder *builder)
Get projected block size for builder.
Definition hello-uri.c:1377
const struct GNUNET_PeerIdentity * GNUNET_HELLO_parser_get_id(const struct GNUNET_HELLO_Parser *parser)
Get the PeerIdentity for this builder.
Definition hello-uri.c:354
struct GNUNET_HELLO_Parser * GNUNET_HELLO_parser_from_block(const void *block, size_t block_size)
Parse block.
Definition hello-uri.c:569
void GNUNET_HELLO_builder_hash_addresses(const struct GNUNET_HELLO_Builder *builder, struct GNUNET_HashCode *hash)
Compute hash over addresses in builder.
Definition hello-uri.c:1198
uint16_t type
The type of the message (GNUNET_MESSAGE_TYPE_XXXX), in big-endian format.
#define GNUNET_log(kind,...)
#define GNUNET_CRYPTO_kdf_arg_string(d)
#define GNUNET_memcmp(a, b)
Compare memory in a and b, where both must be of the same pointer type.
#define GNUNET_UNUSED
gcc-ism to document unused arguments
GNUNET_GenericReturnValue
Named constants for return values.
uint16_t size
The length of the struct (in bytes, including the length field itself), in big-endian format.
@ GNUNET_OK
@ GNUNET_YES
@ GNUNET_NO
@ GNUNET_SYSERR
const char * GNUNET_i2s(const struct GNUNET_PeerIdentity *pid)
Convert a peer identity to a string (for printing debug messages).
const char * GNUNET_h2s_full(const struct GNUNET_HashCode *hc)
Convert a hash value to a string (for printing debug messages).
#define GNUNET_assert(cond)
Use this for fatal errors that cannot be handled.
const char * GNUNET_h2s(const struct GNUNET_HashCode *hc)
Convert a hash value to a string (for printing debug messages).
void GNUNET_log_config_missing(enum GNUNET_ErrorType kind, const char *section, const char *option)
Log error message about missing configuration option.
@ GNUNET_ERROR_TYPE_WARNING
@ GNUNET_ERROR_TYPE_ERROR
@ GNUNET_ERROR_TYPE_DEBUG
#define GNUNET_new(type)
Allocate a struct or union of the given type.
#define GNUNET_malloc(size)
Wrapper around malloc.
#define GNUNET_free(ptr)
Wrapper around free.
struct GNUNET_MQ_Envelope * GNUNET_MQ_msg_copy(const struct GNUNET_MessageHeader *hdr)
Create a new envelope by copying an existing message.
Definition mq.c:582
GNUNET_MQ_Error
Error codes for the queue.
void GNUNET_MQ_send(struct GNUNET_MQ_Handle *mq, struct GNUNET_MQ_Envelope *ev)
Send a message with the given message queue.
Definition mq.c:337
#define GNUNET_MQ_handler_end()
End-marker for the handlers array.
#define GNUNET_MQ_msg_extra(mvar, esize, type)
Allocate an envelope, with extra space allocated after the space needed by the message struct.
#define GNUNET_MQ_hd_var_size(name, code, str, ctx)
#define GNUNET_MQ_hd_fixed_size(name, code, str, ctx)
void GNUNET_MQ_destroy(struct GNUNET_MQ_Handle *mq)
Destroy the message queue.
Definition mq.c:732
#define GNUNET_MESSAGE_TYPE_PILS_ECDH_RESULT
Ecdh result.
#define GNUNET_MESSAGE_TYPE_PILS_SIGN_REQUEST
The client requests data to be signed with the peer identity.
#define GNUNET_MESSAGE_TYPE_PILS_ECDH
Ecdh request.
#define GNUNET_MESSAGE_TYPE_PILS_KEM_DECAPS
Decaps request.
#define GNUNET_MESSAGE_TYPE_PILS_FEED_ADDRESSES
The client (core) provides new addresses to the service, so the service can generate the new peer id.
#define GNUNET_MESSAGE_TYPE_PILS_DECAPS_RESULT
Decaps result.
#define GNUNET_MESSAGE_TYPE_PILS_PEER_ID
Message passing the new peer id from the service to the client.
#define GNUNET_MESSAGE_TYPE_PILS_SIGN_RESULT
The service sends the requested signature to the client.
void * GNUNET_SCHEDULER_cancel(struct GNUNET_SCHEDULER_Task *task)
Cancel the task with the specified identifier.
Definition scheduler.c:986
void(* GNUNET_SCHEDULER_TaskCallback)(void *cls)
Signature of the main function of a task.
struct GNUNET_SCHEDULER_Task * GNUNET_SCHEDULER_add_delayed(struct GNUNET_TIME_Relative delay, GNUNET_SCHEDULER_TaskCallback task, void *task_cls)
Schedule a new task to be run with a specified delay.
Definition scheduler.c:1283
struct GNUNET_TIME_Absolute GNUNET_TIME_relative_to_absolute(struct GNUNET_TIME_Relative rel)
Convert relative time to an absolute time in the future.
Definition time.c:316
#define GNUNET_TIME_UNIT_ZERO
Relative time zero.
struct GNUNET_TIME_AbsoluteNBO GNUNET_TIME_absolute_hton(struct GNUNET_TIME_Absolute a)
Convert absolute time to network byte order.
Definition time.c:636
#define GNUNET_TIME_STD_BACKOFF(r)
Perform our standard exponential back-off calculation, starting at 1 ms and then going by a factor of...
Common type definitions for the peer identity lifecycle service and API.
void pid_change_cb(void *cls, const struct GNUNET_HELLO_Parser *parser, const struct GNUNET_HashCode *addr_hash)
Definition pils_api.c:952
enum GNUNET_GenericReturnValue GNUNET_PILS_enable_private_key(struct GNUNET_PILS_Handle *handle)
Enable local access to the private key of the current peer identity.
Definition pils_api.c:896
static void op_destroy(struct GNUNET_PILS_Operation *op)
Remove op from its handle and free it.
Definition pils_api.c:267
static void transmit_op(struct GNUNET_PILS_Operation *op)
Send the request of op to the service, if we are connected.
Definition pils_api.c:198
static void handle_peer_id(void *cls, const struct PeerIdUpdateMessage *pid_msg)
Handles peer ids sent from the service.
Definition pils_api.c:387
static struct GNUNET_PILS_Operation * find_op(struct GNUNET_PILS_Handle *h, uint32_t rid)
Find the op that matches the rid.
Definition pils_api.c:287
struct GNUNET_PILS_Handle * GNUNET_PILS_connect(const struct GNUNET_CONFIGURATION_Handle *cfg, GNUNET_PILS_PidChangeCallback pid_change_cb, void *cls)
Connect to the PILS service.
Definition pils_api.c:624
void GNUNET_PILS_disconnect(struct GNUNET_PILS_Handle *handle)
Disconnect from the PILS service.
Definition pils_api.c:647
const struct GNUNET_HashCode * GNUNET_PILS_get_identity_hash(const struct GNUNET_PILS_Handle *handle)
Return the hash of the current peer identity from a given handle.
Definition pils_api.c:884
void GNUNET_PILS_derive_pid(size_t seed_key_bytes, const uint8_t seed_key[seed_key_bytes], const struct GNUNET_HashCode *addrs_hash, struct GNUNET_CRYPTO_EddsaPrivateKey *outkey)
Generate the peer id from the addresses hash and the initial secret key.
Definition pils_api.c:783
struct GNUNET_PILS_Operation * GNUNET_PILS_ecdh(struct GNUNET_PILS_Handle *handle, const struct GNUNET_CRYPTO_EcdhePublicKey *pub, GNUNET_PILS_EcdhResultCallback cb, void *cb_cls)
Derive key material from a ECDH public key and our private key.
Definition pils_api.c:751
struct GNUNET_PILS_Operation * GNUNET_PILS_sign_hello(struct GNUNET_PILS_Handle *handle, const struct GNUNET_HELLO_Builder *builder, struct GNUNET_TIME_Absolute et, GNUNET_PILS_SignResultCallback cb, void *cb_cls)
Create HELLO signature.
Definition pils_api.c:851
const struct GNUNET_CRYPTO_EddsaPrivateKey * GNUNET_PILS_get_private_key(const struct GNUNET_PILS_Handle *handle)
Return the private key of the current peer identity.
Definition pils_api.c:943
void GNUNET_PILS_cancel(struct GNUNET_PILS_Operation *op)
Cancel request.
Definition pils_api.c:776
static void handle_sign_result(void *cls, const struct SignResultMessage *msg)
Handles sign result.
Definition pils_api.c:431
static void handle_ecdh_result(void *cls, const struct EcdhResultMessage *msg)
Handles ecdh result.
Definition pils_api.c:504
struct GNUNET_PILS_Operation * GNUNET_PILS_sign_by_peer_identity(struct GNUNET_PILS_Handle *handle, const struct GNUNET_CRYPTO_SignaturePurpose *purpose, GNUNET_PILS_SignResultCallback cb, void *cb_cls)
Sign data with the peer id.
Definition pils_api.c:692
static void mq_error_handler(void *cls, enum GNUNET_MQ_Error error)
Handles errors with the mq.
Definition pils_api.c:546
static void flush_ops(struct GNUNET_PILS_Handle *h)
(Re-)transmit every outstanding request of h.
Definition pils_api.c:227
struct GNUNET_PILS_KeyRing * GNUNET_PILS_create_key_ring(const struct GNUNET_CONFIGURATION_Handle *cfg, GNUNET_SCHEDULER_TaskCallback init_cb, void *cls)
Get the initial secret key for generating the peer id.
Definition pils_api.c:1008
static void handle_decaps_result(void *cls, const struct DecapsResultMessage *msg)
Handles decaps result.
Definition pils_api.c:468
void GNUNET_PILS_destroy_key_ring(struct GNUNET_PILS_KeyRing *key_ring)
Destroy a key ring handle and free its memory.
Definition pils_api.c:1068
const struct GNUNET_PeerIdentity * GNUNET_PILS_get_identity(const struct GNUNET_PILS_Handle *handle)
Return the current peer identity of a given handle.
Definition pils_api.c:875
static void derive_private_key(struct GNUNET_PILS_Handle *h)
Re-derive the private key of the current peer identity of h.
Definition pils_api.c:347
const struct GNUNET_CRYPTO_EddsaPrivateKey * GNUNET_PILS_key_ring_get_private_key(const struct GNUNET_PILS_KeyRing *key_ring)
Return the current private key of a given key ring handle.
Definition pils_api.c:1091
struct GNUNET_PILS_Operation * GNUNET_PILS_kem_decaps(struct GNUNET_PILS_Handle *handle, const struct GNUNET_CRYPTO_HpkeEncapsulation *c, GNUNET_PILS_DecapsResultCallback cb, void *cb_cls)
Decaps an encapsulated key with our private key.
Definition pils_api.c:728
#define LOG(kind,...)
Definition pils_api.c:44
void GNUNET_PILS_feed_addresses(struct GNUNET_PILS_Handle *handle, const struct GNUNET_HELLO_Builder *builder)
Feed a set of addresses to pils so that it will generate a new peer id based on the given set of addr...
Definition pils_api.c:817
static int check_peer_id(void *cls, const struct PeerIdUpdateMessage *msg)
Handles sign result.
Definition pils_api.c:308
static struct GNUNET_PILS_Operation * op_start(struct GNUNET_PILS_Handle *h, struct GNUNET_MessageHeader *req)
Set up a new operation for h and start transmitting req.
Definition pils_api.c:246
static int initialized
Have we been initialized?
Definition plugin.c:57
static void reconnect(void)
Adjust exponential back-off and reconnect to the service.
Message to request a decapsulation from PILS.
Definition pils.h:142
struct GNUNET_CRYPTO_HpkeEncapsulation c
Encapsulation to decapsulate.
Definition pils.h:151
Message containing the decapsulated key.
Definition pils.h:163
Message requesting a signature on data with the current peer id.
Definition pils.h:122
struct GNUNET_MQ_Handle * mq
Our connection to the ARM service.
Definition arm_api.c:107
const struct GNUNET_CONFIGURATION_Handle * cfg
The configuration that we are using.
Definition arm_api.c:112
struct GNUNET_SCHEDULER_Task * reconnect_task
ID of the reconnect task (if any).
Definition arm_api.c:147
struct GNUNET_ARM_Operation * next
This is a doubly-linked list.
Definition arm_api.c:45
struct GNUNET_ARM_Handle * h
ARM handle.
Definition arm_api.c:55
Public ECC key (always for Curve25519) encoded in a format suitable for network transmission and encr...
Private ECC key encoded for transmission.
HPKE DHKEM encapsulation (X25519) See RFC 9180.
header of what an ECC signature signs this must be followed by "size - 8" bytes of the actual signed ...
uint32_t size
How many bytes does this signature sign? (including this purpose header); in network byte order (!...
Context for building (or parsing) HELLO URIs.
Definition hello-uri.c:185
Context for parsing HELLOs.
Definition hello-uri.c:233
A 512-bit hashcode.
Handle to a message queue.
Definition mq.c:87
Message handler for a specific message type.
Header for all communications.
A handle for the PILS service.
Definition pils_api.c:86
struct GNUNET_PILS_Operation * op_head
DLL.
Definition pils_api.c:130
const struct GNUNET_CONFIGURATION_Handle * cfg
Definition pils_api.c:88
void * pid_change_cb_cls
Definition pils_api.c:94
struct GNUNET_HashCode peer_hash
Definition pils_api.c:109
uint32_t op_id_counter
Op ID counter.
Definition pils_api.c:140
struct GNUNET_SCHEDULER_Task * reconnect_task
Definition pils_api.c:97
struct GNUNET_CRYPTO_EddsaPrivateKey * private_key
Definition pils_api.c:121
struct GNUNET_TIME_Relative reconnect_delay
Definition pils_api.c:100
struct GNUNET_PILS_Operation * op_tail
DLL.
Definition pils_api.c:135
struct GNUNET_HashCode hash
Definition pils_api.c:112
GNUNET_PILS_PidChangeCallback pid_change_cb
Definition pils_api.c:91
struct GNUNET_PeerIdentity * peer_id
Definition pils_api.c:106
struct GNUNET_MQ_Handle * mq
Definition pils_api.c:103
unsigned char initial_key_material[256/8]
Definition pils_api.c:116
A simplified handle for using the peer identity key.
Definition pils_api.c:149
struct GNUNET_CRYPTO_EddsaPrivateKey * private_key
Private key.
Definition pils_api.c:173
GNUNET_SCHEDULER_TaskCallback init_cb
Initial callback.
Definition pils_api.c:158
struct GNUNET_HashCode hash
Hash of peer identity.
Definition pils_api.c:183
struct GNUNET_PeerIdentity identity
Peer identity.
Definition pils_api.c:178
unsigned char initial_key_material[256/8]
Initial key material.
Definition pils_api.c:168
void * cls
Closure for initial callback.
Definition pils_api.c:163
struct GNUNET_PILS_Handle * pils
PILS handle.
Definition pils_api.c:153
struct GNUNET_PILS_Operation * next
Definition pils_api.c:50
struct GNUNET_PILS_Handle * h
Definition pils_api.c:56
GNUNET_PILS_SignResultCallback sign_cb
Definition pils_api.c:65
GNUNET_PILS_EcdhResultCallback ecdh_cb
Definition pils_api.c:62
struct GNUNET_MessageHeader * req
Definition pils_api.c:75
GNUNET_PILS_DecapsResultCallback decaps_cb
Definition pils_api.c:59
struct GNUNET_PILS_Operation * prev
Definition pils_api.c:53
The identity of the host (wraps the signing key of the peer).
struct GNUNET_CRYPTO_EddsaPublicKey public_key
Entry in list of pending tasks.
Definition scheduler.c:141
A 256-bit hashcode.
Time for absolute times used by GNUnet, in microseconds.
Time for relative time used by GNUnet, in microseconds.
const struct GNUNET_CONFIGURATION_Handle * cfg
Configuration we use.
Definition vpn_api.c:39
struct GNUNET_MQ_Handle * mq
Connection to VPN service.
Definition vpn_api.c:44
Message containing the current peer id and the hash from which it was generated.
Definition pils.h:40
struct GNUNET_HashCode hash
The hash from which the peer id was generated.
Definition pils.h:49
uint32_t block_len
Length of the HELLO block in bytes.
Definition pils.h:54
Message signed as part of a HELLO block/URL.
Definition hello-uri.c:51
struct GNUNET_HashCode h_addrs
Hash over all addresses.
Definition hello-uri.c:65
struct GNUNET_CRYPTO_SignaturePurpose purpose
Purpose must be GNUNET_SIGNATURE_PURPOSE_HELLO.
Definition hello-uri.c:55
Message to request a signature from PILS.
Definition pils.h:248
Message containing the signature.
Definition pils.h:220
static void init_cb(void *cls, const struct GNUNET_PeerIdentity *my_identity)