Repository navigation
Own LINE crypto by session and login attempt - #253
Conversation
db96479 to
9a9abc6
Compare
|
All clear! No issues remaining. 🎉 3 issues already resolved
All CI checks passed on
Select any unchecked box below to run or rerun that agent. Passed (1)
|
Keep the established manual reconnect fallback for a verified same account with stored keys. Cancellation, deadlines, terminal crypto errors, forced full verification and account mismatches still reject completion.
…h errors Preserve staged token publication for the verified same account when existing key metadata is reusable and the active owner remains usable. Failed fresh-key validation does not publish partial key metadata. Cancellation, retirement, forced verification and terminal crypto failures still stop recovery.
| if res.Certificate != "" { | ||
| meta.Certificate = res.Certificate | ||
| if keyErr != nil { | ||
| if isTerminalCryptoError(keyErr) || errors.Is(keyErr, context.Canceled) || errors.Is(keyErr, context.DeadlineExceeded) || res.Mid != string(lc.UserLogin.ID) || res.Mid != meta.Mid || !shouldPreserveExistingE2EEKeys(false, meta) || lc.E2EE == nil { |
There was a problem hiding this comment.
| if isTerminalCryptoError(keyErr) || errors.Is(keyErr, context.Canceled) || errors.Is(keyErr, context.DeadlineExceeded) || res.Mid != string(lc.UserLogin.ID) || res.Mid != meta.Mid || !shouldPreserveExistingE2EEKeys(false, meta) || lc.E2EE == nil { | |
| if isTerminalCryptoError(keyErr) || errors.Is(keyErr, context.Canceled) || errors.Is(keyErr, context.DeadlineExceeded) || res.Mid != string(lc.UserLogin.ID) || res.Mid != meta.Mid || !shouldPreserveExistingE2EEKeys(false, meta) { |
| if err := lc.admitRecoveredLogin(ctx, res); err != nil { | ||
| return err | ||
| } | ||
| if keyErr != nil { |
There was a problem hiding this comment.
| if keyErr != nil { | |
| if keyErr != nil && lc.E2EE != nil { |
| line.InvalidateOBSTokenCache() | ||
| if mgr != nil { | ||
| if err := mgr.SaveSecureDataToFile(loginSecureDataID(&staged, string(lc.UserLogin.ID)), map[string]any{"exportedKeyMap": exported}); err != nil { | ||
| return fmt.Errorf("save recovered E2EE secure data: %w", err) |
There was a problem hiding this comment.
a failure to save the secure data file should not fail the login and surface as badcredentials.
A warning should be logged instead with the return being nil
| } else if ctx.Err() != nil { | ||
| return ctx.Err() | ||
| } else if lc.isLoggedOut(err) || errors.Is(err, errLineSessionInvalidated) { | ||
| } else if lc.isLoggedOut(err) || errors.Is(err, errLineSessionInvalidated) || errors.Is(err, errLineClientSuperseded) || errors.Is(err, context.Canceled) || errors.Is(err, context.DeadlineExceeded) { |
There was a problem hiding this comment.
| } else if lc.isLoggedOut(err) || errors.Is(err, errLineSessionInvalidated) || errors.Is(err, errLineClientSuperseded) || errors.Is(err, context.Canceled) || errors.Is(err, context.DeadlineExceeded) { | |
| } else if lc.isLoggedOut(err) || errors.Is(err, errLineSessionInvalidated) || errors.Is(err, errLineClientSuperseded) || errors.Is(err, context.Canceled) { |
a refresh timeout would fail here and skip the relogin its supposed to follow
| if shouldPreserveExistingE2EEKeys(exportedKeys, ll.ExistingMetadata) { | ||
| loginManager, err := ll.fetchLoginKeys(res, meta, client) | ||
| if err != nil { | ||
| if isTerminalCryptoError(err) || errors.Is(err, context.Canceled) || errors.Is(err, context.DeadlineExceeded) || !sameAccount || !shouldPreserveExistingE2EEKeys(false, ll.ExistingMetadata) { |
There was a problem hiding this comment.
Same timeout issue as previous comment
| if err := mgr.LoadMyKeyFromExportedMap(exported); err != nil { | ||
| keyErr = fmt.Errorf("validate recovered E2EE keys: %w", err) | ||
| } else { | ||
| applyExportedLoginE2EEKeys(&staged, res, exported) |
There was a problem hiding this comment.
| applyExportedLoginE2EEKeys(&staged, res, exported) | |
| lc.applyRefreshedLoginE2EEKeys(&staged, res, exported) |
| case <-done: | ||
| return nil, context.Canceled | ||
| case <-ctx.Done(): | ||
| ll.Cancel() |
There was a problem hiding this comment.
A client or HTTP timeout shorter than PIN entry permanently cancels the login. Is that intended?
Distinguish individual HTTP timeouts from expired caller or login-attempt contexts. Allow stored-key fallback during startup before an E2EE manager exists. Reset missing-key notification state only after fresh keys, database metadata and live tokens are published successfully. Keep post-publication secure-file failures warning-only.
LINE managers currently share one process-global crypto heap. Replacing or deleting a session leaves its keys and channels in that heap, and overlapping logins overwrite the same login/storage state. Recovering an authoritative allocator abort also leaves stale handles usable.
Give each session and login attempt its own Runner. Carry the attempt through PIN verification, confirmation and key export, then close it on completion/cancellation. Disconnect closes the session owner after draining workers and recovery. Closed or aborted owners reject native and cached-Go operations without invoking destructors on a damaged heap.
Also reuse identical own-key imports, preserve distinct historical keys only for the verified same account, propagate aborts after partially successful batch loads, and reject retired/canceled clients before initial and retry RPCs. Terminal crypto failures cannot downgrade group sends to plaintext. Generated registration keys have tracked temporary ownership and are released after wrapping, before the registration RPC.
Requires canonical
maunium.net/go/mautrix v0.31.1-0.20261005174338-57e1ea5dd74d, containing the merged upstream cancellation-admission fix. No framework fork or replacement is used.Rebased on current LINE main, retaining #256's bounded group-key eviction and locking. Eviction now follows the same terminal-owner gate and stops at the first native destruction failure instead of continuing cleanup on a possibly damaged heap.
Follow-up #254 keeps full registration generation/wrapping on a disposable heap. Megabridge #39 adopts the final source stack.