mirror of
https://github.com/varun-r-mallya/py-libp2p.git
synced 2025-12-31 20:36:24 +00:00
Compare commits
13 Commits
333d56dc00
...
dependency
| Author | SHA1 | Date | |
|---|---|---|---|
| ad63dcf85e | |||
| e9de16a6ae | |||
| b88bc50513 | |||
| 278d6206ab | |||
| 82cda6818c | |||
| 81259f7912 | |||
| f3a3a10251 | |||
| 356192d793 | |||
| 58b33ba2e8 | |||
| 00ba846f7b | |||
| 007527ef75 | |||
| 98438916ad | |||
| 966cef58de |
@ -24,8 +24,13 @@ async def main():
|
|||||||
noise_transport = NoiseTransport(
|
noise_transport = NoiseTransport(
|
||||||
# local_key_pair: The key pair used for libp2p identity and authentication
|
# local_key_pair: The key pair used for libp2p identity and authentication
|
||||||
libp2p_keypair=key_pair,
|
libp2p_keypair=key_pair,
|
||||||
|
# noise_privkey: The private key used for Noise protocol encryption
|
||||||
noise_privkey=key_pair.private_key,
|
noise_privkey=key_pair.private_key,
|
||||||
# TODO: add early data
|
# early_data: Optional data to send during the handshake
|
||||||
|
# (None means no early data)
|
||||||
|
early_data=None,
|
||||||
|
# with_noise_pipes: Whether to use Noise pipes for additional security features
|
||||||
|
with_noise_pipes=False,
|
||||||
)
|
)
|
||||||
|
|
||||||
# Create a security options dictionary mapping protocol ID to transport
|
# Create a security options dictionary mapping protocol ID to transport
|
||||||
|
|||||||
@ -28,7 +28,9 @@ async def main():
|
|||||||
noise_privkey=key_pair.private_key,
|
noise_privkey=key_pair.private_key,
|
||||||
# early_data: Optional data to send during the handshake
|
# early_data: Optional data to send during the handshake
|
||||||
# (None means no early data)
|
# (None means no early data)
|
||||||
# TODO: add early data
|
early_data=None,
|
||||||
|
# with_noise_pipes: Whether to use Noise pipes for additional security features
|
||||||
|
with_noise_pipes=False,
|
||||||
)
|
)
|
||||||
|
|
||||||
# Create a security options dictionary mapping protocol ID to transport
|
# Create a security options dictionary mapping protocol ID to transport
|
||||||
|
|||||||
@ -31,7 +31,9 @@ async def main():
|
|||||||
noise_privkey=key_pair.private_key,
|
noise_privkey=key_pair.private_key,
|
||||||
# early_data: Optional data to send during the handshake
|
# early_data: Optional data to send during the handshake
|
||||||
# (None means no early data)
|
# (None means no early data)
|
||||||
# TODO: add early data
|
early_data=None,
|
||||||
|
# with_noise_pipes: Whether to use Noise pipes for additional security features
|
||||||
|
with_noise_pipes=False,
|
||||||
)
|
)
|
||||||
|
|
||||||
# Create a security options dictionary mapping protocol ID to transport
|
# Create a security options dictionary mapping protocol ID to transport
|
||||||
|
|||||||
@ -28,7 +28,9 @@ async def main():
|
|||||||
noise_privkey=key_pair.private_key,
|
noise_privkey=key_pair.private_key,
|
||||||
# early_data: Optional data to send during the handshake
|
# early_data: Optional data to send during the handshake
|
||||||
# (None means no early data)
|
# (None means no early data)
|
||||||
# TODO: add early data
|
early_data=None,
|
||||||
|
# with_noise_pipes: Whether to use Noise pipes for additional security features
|
||||||
|
with_noise_pipes=False,
|
||||||
)
|
)
|
||||||
|
|
||||||
# Create a security options dictionary mapping protocol ID to transport
|
# Create a security options dictionary mapping protocol ID to transport
|
||||||
|
|||||||
@ -1,68 +0,0 @@
|
|||||||
from abc import ABC, abstractmethod
|
|
||||||
|
|
||||||
from libp2p.abc import IRawConnection
|
|
||||||
from libp2p.custom_types import TProtocol
|
|
||||||
from libp2p.peer.id import ID
|
|
||||||
|
|
||||||
from .pb import noise_pb2 as noise_pb
|
|
||||||
|
|
||||||
|
|
||||||
class EarlyDataHandler(ABC):
|
|
||||||
"""Interface for handling early data during Noise handshake"""
|
|
||||||
|
|
||||||
@abstractmethod
|
|
||||||
async def send(
|
|
||||||
self, conn: IRawConnection, peer_id: ID
|
|
||||||
) -> noise_pb.NoiseExtensions | None:
|
|
||||||
"""Called to generate early data to send during handshake"""
|
|
||||||
pass
|
|
||||||
|
|
||||||
@abstractmethod
|
|
||||||
async def received(
|
|
||||||
self, conn: IRawConnection, extensions: noise_pb.NoiseExtensions | None
|
|
||||||
) -> None:
|
|
||||||
"""Called when early data is received during handshake"""
|
|
||||||
pass
|
|
||||||
|
|
||||||
|
|
||||||
class TransportEarlyDataHandler(EarlyDataHandler):
|
|
||||||
"""Default early data handler for muxer negotiation"""
|
|
||||||
|
|
||||||
def __init__(self, supported_muxers: list[TProtocol]):
|
|
||||||
self.supported_muxers = supported_muxers
|
|
||||||
self.received_muxers: list[TProtocol] = []
|
|
||||||
|
|
||||||
async def send(
|
|
||||||
self, conn: IRawConnection, peer_id: ID
|
|
||||||
) -> noise_pb.NoiseExtensions | None:
|
|
||||||
"""Send our supported muxers list"""
|
|
||||||
if not self.supported_muxers:
|
|
||||||
return None
|
|
||||||
|
|
||||||
extensions = noise_pb.NoiseExtensions()
|
|
||||||
# Convert TProtocol to string for serialization
|
|
||||||
extensions.stream_muxers[:] = [str(muxer) for muxer in self.supported_muxers]
|
|
||||||
return extensions
|
|
||||||
|
|
||||||
async def received(
|
|
||||||
self, conn: IRawConnection, extensions: noise_pb.NoiseExtensions | None
|
|
||||||
) -> None:
|
|
||||||
"""Store received muxers list"""
|
|
||||||
if extensions and extensions.stream_muxers:
|
|
||||||
self.received_muxers = [
|
|
||||||
TProtocol(muxer) for muxer in extensions.stream_muxers
|
|
||||||
]
|
|
||||||
|
|
||||||
def match_muxers(self, is_initiator: bool) -> TProtocol | None:
|
|
||||||
"""Find first common muxer between local and remote"""
|
|
||||||
if is_initiator:
|
|
||||||
# Initiator: find first local muxer that remote supports
|
|
||||||
for local_muxer in self.supported_muxers:
|
|
||||||
if local_muxer in self.received_muxers:
|
|
||||||
return local_muxer
|
|
||||||
else:
|
|
||||||
# Responder: find first remote muxer that we support
|
|
||||||
for remote_muxer in self.received_muxers:
|
|
||||||
if remote_muxer in self.supported_muxers:
|
|
||||||
return remote_muxer
|
|
||||||
return None
|
|
||||||
@ -30,9 +30,6 @@ from libp2p.security.secure_session import (
|
|||||||
SecureSession,
|
SecureSession,
|
||||||
)
|
)
|
||||||
|
|
||||||
from .early_data import (
|
|
||||||
EarlyDataHandler,
|
|
||||||
)
|
|
||||||
from .exceptions import (
|
from .exceptions import (
|
||||||
HandshakeHasNotFinished,
|
HandshakeHasNotFinished,
|
||||||
InvalidSignature,
|
InvalidSignature,
|
||||||
@ -48,7 +45,6 @@ from .messages import (
|
|||||||
make_handshake_payload_sig,
|
make_handshake_payload_sig,
|
||||||
verify_handshake_payload_sig,
|
verify_handshake_payload_sig,
|
||||||
)
|
)
|
||||||
from .pb import noise_pb2 as noise_pb
|
|
||||||
|
|
||||||
|
|
||||||
class IPattern(ABC):
|
class IPattern(ABC):
|
||||||
@ -66,8 +62,7 @@ class BasePattern(IPattern):
|
|||||||
noise_static_key: PrivateKey
|
noise_static_key: PrivateKey
|
||||||
local_peer: ID
|
local_peer: ID
|
||||||
libp2p_privkey: PrivateKey
|
libp2p_privkey: PrivateKey
|
||||||
initiator_early_data_handler: EarlyDataHandler | None
|
early_data: bytes | None
|
||||||
responder_early_data_handler: EarlyDataHandler | None
|
|
||||||
|
|
||||||
def create_noise_state(self) -> NoiseState:
|
def create_noise_state(self) -> NoiseState:
|
||||||
noise_state = NoiseState.from_name(self.protocol_name)
|
noise_state = NoiseState.from_name(self.protocol_name)
|
||||||
@ -78,50 +73,11 @@ class BasePattern(IPattern):
|
|||||||
raise NoiseStateError("noise_protocol is not initialized")
|
raise NoiseStateError("noise_protocol is not initialized")
|
||||||
return noise_state
|
return noise_state
|
||||||
|
|
||||||
async def make_handshake_payload(
|
def make_handshake_payload(self) -> NoiseHandshakePayload:
|
||||||
self, conn: IRawConnection, peer_id: ID, is_initiator: bool
|
|
||||||
) -> NoiseHandshakePayload:
|
|
||||||
signature = make_handshake_payload_sig(
|
signature = make_handshake_payload_sig(
|
||||||
self.libp2p_privkey, self.noise_static_key.get_public_key()
|
self.libp2p_privkey, self.noise_static_key.get_public_key()
|
||||||
)
|
)
|
||||||
|
return NoiseHandshakePayload(self.libp2p_privkey.get_public_key(), signature)
|
||||||
# NEW: Get early data from appropriate handler
|
|
||||||
extensions = None
|
|
||||||
if is_initiator and self.initiator_early_data_handler:
|
|
||||||
extensions = await self.initiator_early_data_handler.send(conn, peer_id)
|
|
||||||
elif not is_initiator and self.responder_early_data_handler:
|
|
||||||
extensions = await self.responder_early_data_handler.send(conn, peer_id)
|
|
||||||
|
|
||||||
# NEW: Serialize extensions into early_data field
|
|
||||||
early_data = None
|
|
||||||
if extensions:
|
|
||||||
early_data = extensions.SerializeToString()
|
|
||||||
|
|
||||||
return NoiseHandshakePayload(
|
|
||||||
self.libp2p_privkey.get_public_key(),
|
|
||||||
signature,
|
|
||||||
early_data, # ← This is the key addition
|
|
||||||
)
|
|
||||||
|
|
||||||
async def handle_received_payload(
|
|
||||||
self, conn: IRawConnection, payload: NoiseHandshakePayload, is_initiator: bool
|
|
||||||
) -> None:
|
|
||||||
"""Process early data from received payload"""
|
|
||||||
if not payload.early_data:
|
|
||||||
return
|
|
||||||
|
|
||||||
# Deserialize the NoiseExtensions from early_data field
|
|
||||||
try:
|
|
||||||
extensions = noise_pb.NoiseExtensions.FromString(payload.early_data)
|
|
||||||
except Exception:
|
|
||||||
# Invalid extensions, ignore silently
|
|
||||||
return
|
|
||||||
|
|
||||||
# Pass to appropriate handler
|
|
||||||
if is_initiator and self.initiator_early_data_handler:
|
|
||||||
await self.initiator_early_data_handler.received(conn, extensions)
|
|
||||||
elif not is_initiator and self.responder_early_data_handler:
|
|
||||||
await self.responder_early_data_handler.received(conn, extensions)
|
|
||||||
|
|
||||||
|
|
||||||
class PatternXX(BasePattern):
|
class PatternXX(BasePattern):
|
||||||
@ -130,15 +86,13 @@ class PatternXX(BasePattern):
|
|||||||
local_peer: ID,
|
local_peer: ID,
|
||||||
libp2p_privkey: PrivateKey,
|
libp2p_privkey: PrivateKey,
|
||||||
noise_static_key: PrivateKey,
|
noise_static_key: PrivateKey,
|
||||||
initiator_early_data_handler: EarlyDataHandler | None,
|
early_data: bytes | None = None,
|
||||||
responder_early_data_handler: EarlyDataHandler | None,
|
|
||||||
) -> None:
|
) -> None:
|
||||||
self.protocol_name = b"Noise_XX_25519_ChaChaPoly_SHA256"
|
self.protocol_name = b"Noise_XX_25519_ChaChaPoly_SHA256"
|
||||||
self.local_peer = local_peer
|
self.local_peer = local_peer
|
||||||
self.libp2p_privkey = libp2p_privkey
|
self.libp2p_privkey = libp2p_privkey
|
||||||
self.noise_static_key = noise_static_key
|
self.noise_static_key = noise_static_key
|
||||||
self.initiator_early_data_handler = initiator_early_data_handler
|
self.early_data = early_data
|
||||||
self.responder_early_data_handler = responder_early_data_handler
|
|
||||||
|
|
||||||
async def handshake_inbound(self, conn: IRawConnection) -> ISecureConn:
|
async def handshake_inbound(self, conn: IRawConnection) -> ISecureConn:
|
||||||
noise_state = self.create_noise_state()
|
noise_state = self.create_noise_state()
|
||||||
@ -152,23 +106,18 @@ class PatternXX(BasePattern):
|
|||||||
|
|
||||||
read_writer = NoiseHandshakeReadWriter(conn, noise_state)
|
read_writer = NoiseHandshakeReadWriter(conn, noise_state)
|
||||||
|
|
||||||
# 1. Consume msg#1 (just empty bytes)
|
# Consume msg#1.
|
||||||
await read_writer.read_msg()
|
await read_writer.read_msg()
|
||||||
|
|
||||||
# 2. Send msg#2 with our payload INCLUDING EARLY DATA
|
# Send msg#2, which should include our handshake payload.
|
||||||
our_payload = await self.make_handshake_payload(
|
our_payload = self.make_handshake_payload()
|
||||||
conn,
|
|
||||||
self.local_peer, # We send our own peer ID in responder role
|
|
||||||
is_initiator=False,
|
|
||||||
)
|
|
||||||
msg_2 = our_payload.serialize()
|
msg_2 = our_payload.serialize()
|
||||||
await read_writer.write_msg(msg_2)
|
await read_writer.write_msg(msg_2)
|
||||||
|
|
||||||
# 3. Receive msg#3
|
# Receive and consume msg#3.
|
||||||
msg_3 = await read_writer.read_msg()
|
msg_3 = await read_writer.read_msg()
|
||||||
peer_handshake_payload = NoiseHandshakePayload.deserialize(msg_3)
|
peer_handshake_payload = NoiseHandshakePayload.deserialize(msg_3)
|
||||||
|
|
||||||
# Extract remote pubkey from noise handshake state
|
|
||||||
if handshake_state.rs is None:
|
if handshake_state.rs is None:
|
||||||
raise NoiseStateError(
|
raise NoiseStateError(
|
||||||
"something is wrong in the underlying noise `handshake_state`: "
|
"something is wrong in the underlying noise `handshake_state`: "
|
||||||
@ -177,31 +126,14 @@ class PatternXX(BasePattern):
|
|||||||
)
|
)
|
||||||
remote_pubkey = self._get_pubkey_from_noise_keypair(handshake_state.rs)
|
remote_pubkey = self._get_pubkey_from_noise_keypair(handshake_state.rs)
|
||||||
|
|
||||||
# 4. Verify signature (unchanged)
|
|
||||||
if not verify_handshake_payload_sig(peer_handshake_payload, remote_pubkey):
|
if not verify_handshake_payload_sig(peer_handshake_payload, remote_pubkey):
|
||||||
raise InvalidSignature
|
raise InvalidSignature
|
||||||
|
|
||||||
# NEW: Process early data from msg#3 AFTER signature verification
|
|
||||||
await self.handle_received_payload(
|
|
||||||
conn, peer_handshake_payload, is_initiator=False
|
|
||||||
)
|
|
||||||
|
|
||||||
remote_peer_id_from_pubkey = ID.from_pubkey(peer_handshake_payload.id_pubkey)
|
remote_peer_id_from_pubkey = ID.from_pubkey(peer_handshake_payload.id_pubkey)
|
||||||
|
|
||||||
if not noise_state.handshake_finished:
|
if not noise_state.handshake_finished:
|
||||||
raise HandshakeHasNotFinished(
|
raise HandshakeHasNotFinished(
|
||||||
"handshake is done but it is not marked as finished in `noise_state`"
|
"handshake is done but it is not marked as finished in `noise_state`"
|
||||||
)
|
)
|
||||||
|
|
||||||
# NEW: Get negotiated muxer for connection state
|
|
||||||
# negotiated_muxer = None
|
|
||||||
if self.responder_early_data_handler and hasattr(
|
|
||||||
self.responder_early_data_handler, "match_muxers"
|
|
||||||
):
|
|
||||||
# negotiated_muxer =
|
|
||||||
# self.responder_early_data_handler.match_muxers(is_initiator=False)
|
|
||||||
pass
|
|
||||||
|
|
||||||
transport_read_writer = NoiseTransportReadWriter(conn, noise_state)
|
transport_read_writer = NoiseTransportReadWriter(conn, noise_state)
|
||||||
return SecureSession(
|
return SecureSession(
|
||||||
local_peer=self.local_peer,
|
local_peer=self.local_peer,
|
||||||
@ -210,8 +142,6 @@ class PatternXX(BasePattern):
|
|||||||
remote_permanent_pubkey=remote_pubkey,
|
remote_permanent_pubkey=remote_pubkey,
|
||||||
is_initiator=False,
|
is_initiator=False,
|
||||||
conn=transport_read_writer,
|
conn=transport_read_writer,
|
||||||
# NOTE: negotiated_muxer would need to be added to SecureSession constructor
|
|
||||||
# For now, store it in connection metadata or similar
|
|
||||||
)
|
)
|
||||||
|
|
||||||
async def handshake_outbound(
|
async def handshake_outbound(
|
||||||
@ -228,27 +158,24 @@ class PatternXX(BasePattern):
|
|||||||
if handshake_state is None:
|
if handshake_state is None:
|
||||||
raise NoiseStateError("Handshake state is not initialized")
|
raise NoiseStateError("Handshake state is not initialized")
|
||||||
|
|
||||||
# 1. Send msg#1 (empty) - no early data possible in XX pattern
|
# Send msg#1, which is *not* encrypted.
|
||||||
msg_1 = b""
|
msg_1 = b""
|
||||||
await read_writer.write_msg(msg_1)
|
await read_writer.write_msg(msg_1)
|
||||||
|
|
||||||
# 2. Read msg#2 from responder
|
# Read msg#2 from the remote, which contains the public key of the peer.
|
||||||
msg_2 = await read_writer.read_msg()
|
msg_2 = await read_writer.read_msg()
|
||||||
peer_handshake_payload = NoiseHandshakePayload.deserialize(msg_2)
|
peer_handshake_payload = NoiseHandshakePayload.deserialize(msg_2)
|
||||||
|
|
||||||
# Extract remote pubkey from noise handshake state
|
|
||||||
if handshake_state.rs is None:
|
if handshake_state.rs is None:
|
||||||
raise NoiseStateError(
|
raise NoiseStateError(
|
||||||
"something is wrong in the underlying noise `handshake_state`: "
|
"something is wrong in the underlying noise `handshake_state`: "
|
||||||
"we received and consumed msg#2, which should have included the "
|
"we received and consumed msg#3, which should have included the "
|
||||||
"remote static public key, but it is not present in the handshake_state"
|
"remote static public key, but it is not present in the handshake_state"
|
||||||
)
|
)
|
||||||
remote_pubkey = self._get_pubkey_from_noise_keypair(handshake_state.rs)
|
remote_pubkey = self._get_pubkey_from_noise_keypair(handshake_state.rs)
|
||||||
|
|
||||||
# Verify signature BEFORE processing early data (security)
|
|
||||||
if not verify_handshake_payload_sig(peer_handshake_payload, remote_pubkey):
|
if not verify_handshake_payload_sig(peer_handshake_payload, remote_pubkey):
|
||||||
raise InvalidSignature
|
raise InvalidSignature
|
||||||
|
|
||||||
remote_peer_id_from_pubkey = ID.from_pubkey(peer_handshake_payload.id_pubkey)
|
remote_peer_id_from_pubkey = ID.from_pubkey(peer_handshake_payload.id_pubkey)
|
||||||
if remote_peer_id_from_pubkey != remote_peer:
|
if remote_peer_id_from_pubkey != remote_peer:
|
||||||
raise PeerIDMismatchesPubkey(
|
raise PeerIDMismatchesPubkey(
|
||||||
@ -257,15 +184,8 @@ class PatternXX(BasePattern):
|
|||||||
f"remote_peer_id_from_pubkey={remote_peer_id_from_pubkey}"
|
f"remote_peer_id_from_pubkey={remote_peer_id_from_pubkey}"
|
||||||
)
|
)
|
||||||
|
|
||||||
# NEW: Process early data from msg#2 AFTER verification
|
# Send msg#3, which includes our encrypted payload and our noise static key.
|
||||||
await self.handle_received_payload(
|
our_payload = self.make_handshake_payload()
|
||||||
conn, peer_handshake_payload, is_initiator=True
|
|
||||||
)
|
|
||||||
|
|
||||||
# 3. Send msg#3 with our payload INCLUDING EARLY DATA
|
|
||||||
our_payload = await self.make_handshake_payload(
|
|
||||||
conn, remote_peer, is_initiator=True
|
|
||||||
)
|
|
||||||
msg_3 = our_payload.serialize()
|
msg_3 = our_payload.serialize()
|
||||||
await read_writer.write_msg(msg_3)
|
await read_writer.write_msg(msg_3)
|
||||||
|
|
||||||
@ -273,16 +193,6 @@ class PatternXX(BasePattern):
|
|||||||
raise HandshakeHasNotFinished(
|
raise HandshakeHasNotFinished(
|
||||||
"handshake is done but it is not marked as finished in `noise_state`"
|
"handshake is done but it is not marked as finished in `noise_state`"
|
||||||
)
|
)
|
||||||
|
|
||||||
# NEW: Get negotiated muxer
|
|
||||||
# negotiated_muxer = None
|
|
||||||
if self.initiator_early_data_handler and hasattr(
|
|
||||||
self.initiator_early_data_handler, "match_muxers"
|
|
||||||
):
|
|
||||||
pass
|
|
||||||
# negotiated_muxer =
|
|
||||||
# self.initiator_early_data_handler.match_muxers(is_initiator=True)
|
|
||||||
|
|
||||||
transport_read_writer = NoiseTransportReadWriter(conn, noise_state)
|
transport_read_writer = NoiseTransportReadWriter(conn, noise_state)
|
||||||
return SecureSession(
|
return SecureSession(
|
||||||
local_peer=self.local_peer,
|
local_peer=self.local_peer,
|
||||||
@ -291,8 +201,6 @@ class PatternXX(BasePattern):
|
|||||||
remote_permanent_pubkey=remote_pubkey,
|
remote_permanent_pubkey=remote_pubkey,
|
||||||
is_initiator=True,
|
is_initiator=True,
|
||||||
conn=transport_read_writer,
|
conn=transport_read_writer,
|
||||||
# NOTE: negotiated_muxer would need to be added to SecureSession constructor
|
|
||||||
# For now, store it in connection metadata or similar
|
|
||||||
)
|
)
|
||||||
|
|
||||||
@staticmethod
|
@staticmethod
|
||||||
|
|||||||
@ -1,13 +1,8 @@
|
|||||||
syntax = "proto2";
|
syntax = "proto3";
|
||||||
package pb;
|
package pb;
|
||||||
|
|
||||||
message NoiseExtensions {
|
|
||||||
repeated bytes webtransport_certhashes = 1;
|
|
||||||
repeated string stream_muxers = 2;
|
|
||||||
}
|
|
||||||
|
|
||||||
message NoiseHandshakePayload {
|
message NoiseHandshakePayload {
|
||||||
optional bytes identity_key = 1;
|
bytes identity_key = 1;
|
||||||
optional bytes identity_sig = 2;
|
bytes identity_sig = 2;
|
||||||
optional bytes data = 3;
|
bytes data = 3;
|
||||||
}
|
}
|
||||||
|
|||||||
@ -13,15 +13,13 @@ _sym_db = _symbol_database.Default()
|
|||||||
|
|
||||||
|
|
||||||
|
|
||||||
DESCRIPTOR = _descriptor_pool.Default().AddSerializedFile(b'\n$libp2p/security/noise/pb/noise.proto\x12\x02pb\"I\n\x0fNoiseExtensions\x12\x1f\n\x17webtransport_certhashes\x18\x01 \x03(\x0c\x12\x15\n\rstream_muxers\x18\x02 \x03(\t\"Q\n\x15NoiseHandshakePayload\x12\x14\n\x0cidentity_key\x18\x01 \x01(\x0c\x12\x14\n\x0cidentity_sig\x18\x02 \x01(\x0c\x12\x0c\n\x04\x64\x61ta\x18\x03 \x01(\x0c')
|
DESCRIPTOR = _descriptor_pool.Default().AddSerializedFile(b'\n$libp2p/security/noise/pb/noise.proto\x12\x02pb\"Q\n\x15NoiseHandshakePayload\x12\x14\n\x0cidentity_key\x18\x01 \x01(\x0c\x12\x14\n\x0cidentity_sig\x18\x02 \x01(\x0c\x12\x0c\n\x04\x64\x61ta\x18\x03 \x01(\x0c\x62\x06proto3')
|
||||||
|
|
||||||
_builder.BuildMessageAndEnumDescriptors(DESCRIPTOR, globals())
|
_builder.BuildMessageAndEnumDescriptors(DESCRIPTOR, globals())
|
||||||
_builder.BuildTopDescriptorsAndMessages(DESCRIPTOR, 'libp2p.security.noise.pb.noise_pb2', globals())
|
_builder.BuildTopDescriptorsAndMessages(DESCRIPTOR, 'libp2p.security.noise.pb.noise_pb2', globals())
|
||||||
if _descriptor._USE_C_DESCRIPTORS == False:
|
if _descriptor._USE_C_DESCRIPTORS == False:
|
||||||
|
|
||||||
DESCRIPTOR._options = None
|
DESCRIPTOR._options = None
|
||||||
_NOISEEXTENSIONS._serialized_start=44
|
_NOISEHANDSHAKEPAYLOAD._serialized_start=44
|
||||||
_NOISEEXTENSIONS._serialized_end=117
|
_NOISEHANDSHAKEPAYLOAD._serialized_end=125
|
||||||
_NOISEHANDSHAKEPAYLOAD._serialized_start=119
|
|
||||||
_NOISEHANDSHAKEPAYLOAD._serialized_end=200
|
|
||||||
# @@protoc_insertion_point(module_scope)
|
# @@protoc_insertion_point(module_scope)
|
||||||
|
|||||||
@ -4,34 +4,12 @@ isort:skip_file
|
|||||||
"""
|
"""
|
||||||
|
|
||||||
import builtins
|
import builtins
|
||||||
import collections.abc
|
|
||||||
import google.protobuf.descriptor
|
import google.protobuf.descriptor
|
||||||
import google.protobuf.internal.containers
|
|
||||||
import google.protobuf.message
|
import google.protobuf.message
|
||||||
import typing
|
import typing
|
||||||
|
|
||||||
DESCRIPTOR: google.protobuf.descriptor.FileDescriptor
|
DESCRIPTOR: google.protobuf.descriptor.FileDescriptor
|
||||||
|
|
||||||
@typing.final
|
|
||||||
class NoiseExtensions(google.protobuf.message.Message):
|
|
||||||
DESCRIPTOR: google.protobuf.descriptor.Descriptor
|
|
||||||
|
|
||||||
WEBTRANSPORT_CERTHASHES_FIELD_NUMBER: builtins.int
|
|
||||||
STREAM_MUXERS_FIELD_NUMBER: builtins.int
|
|
||||||
@property
|
|
||||||
def webtransport_certhashes(self) -> google.protobuf.internal.containers.RepeatedScalarFieldContainer[builtins.bytes]: ...
|
|
||||||
@property
|
|
||||||
def stream_muxers(self) -> google.protobuf.internal.containers.RepeatedScalarFieldContainer[builtins.str]: ...
|
|
||||||
def __init__(
|
|
||||||
self,
|
|
||||||
*,
|
|
||||||
webtransport_certhashes: collections.abc.Iterable[builtins.bytes] | None = ...,
|
|
||||||
stream_muxers: collections.abc.Iterable[builtins.str] | None = ...,
|
|
||||||
) -> None: ...
|
|
||||||
def ClearField(self, field_name: typing.Literal["stream_muxers", b"stream_muxers", "webtransport_certhashes", b"webtransport_certhashes"]) -> None: ...
|
|
||||||
|
|
||||||
global___NoiseExtensions = NoiseExtensions
|
|
||||||
|
|
||||||
@typing.final
|
@typing.final
|
||||||
class NoiseHandshakePayload(google.protobuf.message.Message):
|
class NoiseHandshakePayload(google.protobuf.message.Message):
|
||||||
DESCRIPTOR: google.protobuf.descriptor.Descriptor
|
DESCRIPTOR: google.protobuf.descriptor.Descriptor
|
||||||
@ -45,11 +23,10 @@ class NoiseHandshakePayload(google.protobuf.message.Message):
|
|||||||
def __init__(
|
def __init__(
|
||||||
self,
|
self,
|
||||||
*,
|
*,
|
||||||
identity_key: builtins.bytes | None = ...,
|
identity_key: builtins.bytes = ...,
|
||||||
identity_sig: builtins.bytes | None = ...,
|
identity_sig: builtins.bytes = ...,
|
||||||
data: builtins.bytes | None = ...,
|
data: builtins.bytes = ...,
|
||||||
) -> None: ...
|
) -> None: ...
|
||||||
def HasField(self, field_name: typing.Literal["data", b"data", "identity_key", b"identity_key", "identity_sig", b"identity_sig"]) -> builtins.bool: ...
|
|
||||||
def ClearField(self, field_name: typing.Literal["data", b"data", "identity_key", b"identity_key", "identity_sig", b"identity_sig"]) -> None: ...
|
def ClearField(self, field_name: typing.Literal["data", b"data", "identity_key", b"identity_key", "identity_sig", b"identity_sig"]) -> None: ...
|
||||||
|
|
||||||
global___NoiseHandshakePayload = NoiseHandshakePayload
|
global___NoiseHandshakePayload = NoiseHandshakePayload
|
||||||
|
|||||||
@ -14,7 +14,6 @@ from libp2p.peer.id import (
|
|||||||
ID,
|
ID,
|
||||||
)
|
)
|
||||||
|
|
||||||
from .early_data import EarlyDataHandler, TransportEarlyDataHandler
|
|
||||||
from .patterns import (
|
from .patterns import (
|
||||||
IPattern,
|
IPattern,
|
||||||
PatternXX,
|
PatternXX,
|
||||||
@ -27,40 +26,35 @@ class Transport(ISecureTransport):
|
|||||||
libp2p_privkey: PrivateKey
|
libp2p_privkey: PrivateKey
|
||||||
noise_privkey: PrivateKey
|
noise_privkey: PrivateKey
|
||||||
local_peer: ID
|
local_peer: ID
|
||||||
supported_muxers: list[TProtocol]
|
early_data: bytes | None
|
||||||
initiator_early_data_handler: EarlyDataHandler | None
|
with_noise_pipes: bool
|
||||||
responder_early_data_handler: EarlyDataHandler | None
|
|
||||||
|
|
||||||
def __init__(
|
def __init__(
|
||||||
self,
|
self,
|
||||||
libp2p_keypair: KeyPair,
|
libp2p_keypair: KeyPair,
|
||||||
noise_privkey: PrivateKey,
|
noise_privkey: PrivateKey,
|
||||||
supported_muxers: list[TProtocol] | None = None,
|
early_data: bytes | None = None,
|
||||||
initiator_handler: EarlyDataHandler | None = None,
|
with_noise_pipes: bool = False,
|
||||||
responder_handler: EarlyDataHandler | None = None,
|
|
||||||
) -> None:
|
) -> None:
|
||||||
self.libp2p_privkey = libp2p_keypair.private_key
|
self.libp2p_privkey = libp2p_keypair.private_key
|
||||||
self.noise_privkey = noise_privkey
|
self.noise_privkey = noise_privkey
|
||||||
self.local_peer = ID.from_pubkey(libp2p_keypair.public_key)
|
self.local_peer = ID.from_pubkey(libp2p_keypair.public_key)
|
||||||
self.supported_muxers = supported_muxers or []
|
self.early_data = early_data
|
||||||
|
self.with_noise_pipes = with_noise_pipes
|
||||||
|
|
||||||
# Create default handlers for muxer negotiation if none provided
|
if self.with_noise_pipes:
|
||||||
if initiator_handler is None and self.supported_muxers:
|
raise NotImplementedError
|
||||||
initiator_handler = TransportEarlyDataHandler(self.supported_muxers)
|
|
||||||
if responder_handler is None and self.supported_muxers:
|
|
||||||
responder_handler = TransportEarlyDataHandler(self.supported_muxers)
|
|
||||||
|
|
||||||
self.initiator_early_data_handler = initiator_handler
|
|
||||||
self.responder_early_data_handler = responder_handler
|
|
||||||
|
|
||||||
def get_pattern(self) -> IPattern:
|
def get_pattern(self) -> IPattern:
|
||||||
return PatternXX(
|
if self.with_noise_pipes:
|
||||||
self.local_peer,
|
raise NotImplementedError
|
||||||
self.libp2p_privkey,
|
else:
|
||||||
self.noise_privkey,
|
return PatternXX(
|
||||||
self.initiator_early_data_handler,
|
self.local_peer,
|
||||||
self.responder_early_data_handler,
|
self.libp2p_privkey,
|
||||||
)
|
self.noise_privkey,
|
||||||
|
self.early_data,
|
||||||
|
)
|
||||||
|
|
||||||
async def secure_inbound(self, conn: IRawConnection) -> ISecureConn:
|
async def secure_inbound(self, conn: IRawConnection) -> ISecureConn:
|
||||||
pattern = self.get_pattern()
|
pattern = self.get_pattern()
|
||||||
|
|||||||
1
newsfragments/732.deprecation.rst
Normal file
1
newsfragments/732.deprecation.rst
Normal file
@ -0,0 +1 @@
|
|||||||
|
update cryptographic dependencies: pycryptodome to ≥3.19.1, pynacl to ≥1.5.0, coincurve to ≥21.0.0
|
||||||
@ -17,7 +17,7 @@ maintainers = [
|
|||||||
]
|
]
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"base58>=1.0.3",
|
"base58>=1.0.3",
|
||||||
"coincurve>=10.0.0",
|
"coincurve>=21.0.0",
|
||||||
"exceptiongroup>=1.2.0; python_version < '3.11'",
|
"exceptiongroup>=1.2.0; python_version < '3.11'",
|
||||||
"grpcio>=1.41.0",
|
"grpcio>=1.41.0",
|
||||||
"lru-dict>=1.1.6",
|
"lru-dict>=1.1.6",
|
||||||
@ -28,7 +28,7 @@ dependencies = [
|
|||||||
"protobuf>=4.25.0,<5.0.0",
|
"protobuf>=4.25.0,<5.0.0",
|
||||||
"pycryptodome>=3.9.2",
|
"pycryptodome>=3.9.2",
|
||||||
"pymultihash>=0.8.2",
|
"pymultihash>=0.8.2",
|
||||||
"pynacl>=1.3.0",
|
"pynacl>=1.5.0",
|
||||||
"rpcudp>=3.0.0",
|
"rpcudp>=3.0.0",
|
||||||
"trio-typing>=0.0.4",
|
"trio-typing>=0.0.4",
|
||||||
"trio>=0.26.0",
|
"trio>=0.26.0",
|
||||||
|
|||||||
@ -1,13 +0,0 @@
|
|||||||
from libp2p.security.noise.pb import noise_pb2 as noise_pb
|
|
||||||
|
|
||||||
|
|
||||||
def test_noise_extensions_serialization():
|
|
||||||
# Test NoiseExtensions
|
|
||||||
ext = noise_pb.NoiseExtensions()
|
|
||||||
ext.stream_muxers.append("/mplex/6.7.0")
|
|
||||||
ext.stream_muxers.append("/yamux/1.0.0")
|
|
||||||
|
|
||||||
# Serialize and deserialize
|
|
||||||
data = ext.SerializeToString()
|
|
||||||
ext2 = noise_pb.NoiseExtensions.FromString(data)
|
|
||||||
assert list(ext2.stream_muxers) == ["/mplex/6.7.0", "/yamux/1.0.0"]
|
|
||||||
@ -173,7 +173,8 @@ def noise_transport_factory(key_pair: KeyPair) -> ISecureTransport:
|
|||||||
return NoiseTransport(
|
return NoiseTransport(
|
||||||
libp2p_keypair=key_pair,
|
libp2p_keypair=key_pair,
|
||||||
noise_privkey=noise_static_key_factory(),
|
noise_privkey=noise_static_key_factory(),
|
||||||
# TODO: add early data
|
early_data=None,
|
||||||
|
with_noise_pipes=False,
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user