From 7db327c588c0c811458080ce0ebe06c85b8ccc04 Mon Sep 17 00:00:00 2001 From: TolaMironcenko Date: Sun, 30 Aug 2026 05:40:44 +0700 Subject: [PATCH] added omemo2 --- AGENTS.md | 6 +- Docs/ARCHITECTURE.md | 13 + Luma.xcodeproj/project.pbxproj | 39 +- .../xcshareddata/swiftpm/Package.resolved | 11 +- Makefile | 12 +- Scripts/patch-xcodeproj.py | 54 + Scripts/regenerate-project.command | 3 + Scripts/verify.sh | 16 + .../Shared/Services/PhoneWatchBridge.swift | 108 +- Sources/Shared/UI/ServerInfoView.swift | 12 +- Sources/Shared/XMPP/LumaOMEMO2Module.swift | 839 +++++++++++++ Sources/Shared/XMPP/XMPPService.swift | 252 +++- Tests/LumaOMEMO2Tests.swift | 317 +++++ ThirdParty/MartinOMEMO/.github/FUNDING.yml | 3 + ThirdParty/MartinOMEMO/.gitignore | 6 + ThirdParty/MartinOMEMO/LICENSE | 674 ++++++++++ ThirdParty/MartinOMEMO/Package.swift | 31 + ThirdParty/MartinOMEMO/README.md | 7 + .../Sources/MartinOMEMO/Identity.swift | 40 + .../Sources/MartinOMEMO/IdentityStatus.swift | 108 ++ .../Sources/MartinOMEMO/OMEMOModule.swift | 1101 +++++++++++++++++ .../Sources/MartinOMEMO/SignalAddress.swift | 82 ++ .../Sources/MartinOMEMO/SignalContext.swift | 238 ++++ .../MartinOMEMO/SignalCryptoProvider.swift | 175 +++ .../Sources/MartinOMEMO/SignalError.swift | 54 + .../MartinOMEMO/SignalIdentityKey.swift | 75 ++ .../MartinOMEMO/SignalIdentityKeyPair.swift | 133 ++ .../MartinOMEMO/SignalPreKeyBundle.swift | 87 ++ .../MartinOMEMO/SignalSessionBuilder.swift | 51 + .../MartinOMEMO/SignalSessionCipher.swift | 142 +++ .../Sources/MartinOMEMO/SignalStorage.swift | 396 ++++++ .../Sources/MartinOMEMO/TigaseSwift_OMEMO.h | 37 + ThirdParty/MartinOMEMO/Tests/LinuxMain.swift | 7 + .../MartinOMEMOTests/MartinOMEMOTests.swift | 15 + .../MartinOMEMOTests/XCTestManifests.swift | 9 + project.yml | 3 +- 36 files changed, 5042 insertions(+), 114 deletions(-) create mode 100644 Scripts/patch-xcodeproj.py create mode 100644 Sources/Shared/XMPP/LumaOMEMO2Module.swift create mode 100644 Tests/LumaOMEMO2Tests.swift create mode 100644 ThirdParty/MartinOMEMO/.github/FUNDING.yml create mode 100644 ThirdParty/MartinOMEMO/.gitignore create mode 100644 ThirdParty/MartinOMEMO/LICENSE create mode 100644 ThirdParty/MartinOMEMO/Package.swift create mode 100644 ThirdParty/MartinOMEMO/README.md create mode 100644 ThirdParty/MartinOMEMO/Sources/MartinOMEMO/Identity.swift create mode 100644 ThirdParty/MartinOMEMO/Sources/MartinOMEMO/IdentityStatus.swift create mode 100644 ThirdParty/MartinOMEMO/Sources/MartinOMEMO/OMEMOModule.swift create mode 100644 ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalAddress.swift create mode 100644 ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalContext.swift create mode 100644 ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalCryptoProvider.swift create mode 100644 ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalError.swift create mode 100644 ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalIdentityKey.swift create mode 100644 ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalIdentityKeyPair.swift create mode 100644 ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalPreKeyBundle.swift create mode 100644 ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalSessionBuilder.swift create mode 100644 ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalSessionCipher.swift create mode 100644 ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalStorage.swift create mode 100644 ThirdParty/MartinOMEMO/Sources/MartinOMEMO/TigaseSwift_OMEMO.h create mode 100644 ThirdParty/MartinOMEMO/Tests/LinuxMain.swift create mode 100644 ThirdParty/MartinOMEMO/Tests/MartinOMEMOTests/MartinOMEMOTests.swift create mode 100644 ThirdParty/MartinOMEMO/Tests/MartinOMEMOTests/XCTestManifests.swift diff --git a/AGENTS.md b/AGENTS.md index 70ad0b6..295c951 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -19,8 +19,10 @@ and the Martin / MartinOMEMO libraries. The Xcode project is generated from macOS Telegram Desktop-style split view (`MainSplitView`: sidebar with menu/search/list plus a chat detail pane). - `XMPP/` — `XMPPService` (MAM/OMEMO/MUC), `LumaCallEngine`, OMEMO store, - `SASLprep` (RFC 4013), SCRAM-SHA-512 mechanism, SASL failure - observer/messages. + `LumaOMEMO2Module` (urn:xmpp:omemo:2 wire format: AES-256-CBC + HMAC + payload, SCE envelope, device/bundle PEP nodes — shares the Double + Ratchet sessions with the legacy module), `SASLprep` (RFC 4013), + SCRAM-SHA-512 mechanism, SASL failure observer/messages. - `Persistence/` — `ArchiveStore` (per-account SwiftData container), `ArchiveMetadataRecord` (durable MAM checkpoint metadata), `LegacyArchiveImporter` (one-time legacy JSON snapshot migration), diff --git a/Docs/ARCHITECTURE.md b/Docs/ARCHITECTURE.md index 6fead05..ec026cc 100644 --- a/Docs/ARCHITECTURE.md +++ b/Docs/ARCHITECTURE.md @@ -39,6 +39,19 @@ XEP-0045-комнатами в отдельном разделе «Группо fallback на plaintext. UI сразу показывает optimistic message и обновляет состояние по результату записи/receipt. +## OMEMO 2 + +Помимо legacy `eu.siacs.conversations.axolotl` (MartinOMEMO) поддерживается +`urn:xmpp:omemo:2` (XEP-0384 0.8.3) через собственный модуль +`LumaOMEMO2Module`: payload — AES-256-CBC + HMAC-SHA-256 (HKDF, info +«OMEMO Payload»), plaintext — SCE-envelope (XEP-0420); device list и bundle +публикуются в PEP-узлах `urn:xmpp:omemo:2:devices` / +`urn:xmpp:omemo:2:bundles`. Double Ratchet-сессии общие с legacy-модулем +(тот же `LumaOMEMOStore`). Исходящие предпочитают OMEMO 2, когда у собеседника +есть OMEMO 2-устройства (в группах — только если устройства есть у всех +участников), иначе используется legacy. MartinOMEMO завендорен в +`ThirdParty/` с точечными патчами видимости (см. `THIRD_PARTY_NOTICES.md`). + Входящая stanza может прийти напрямую, через carbons или MAM. Сервис определяет peer, расшифровывает payload, использует `origin-id`/stanza id для дедупликации и передаёт value-type envelope в `AppModel`. Дедупликация выполняется по diff --git a/Luma.xcodeproj/project.pbxproj b/Luma.xcodeproj/project.pbxproj index f5009d5..770ea4b 100644 --- a/Luma.xcodeproj/project.pbxproj +++ b/Luma.xcodeproj/project.pbxproj @@ -36,6 +36,7 @@ 1B20F2D3E4F18E6094B103BF /* LumaOMEMOStore.swift in Sources */ = {isa = PBXBuildFile; fileRef = 24A68154C2D2B3E9AB0C145F /* LumaOMEMOStore.swift */; }; 1B7C9F60AA7BFF6A2C0FE45D /* SASLprepTests.swift in Sources */ = {isa = PBXBuildFile; fileRef = 13EFA01112297641B9B0EBC5 /* SASLprepTests.swift */; }; 1BD84AA796838F48F847D192 /* AudioMessageRecorder.swift in Sources */ = {isa = PBXBuildFile; fileRef = 7BD0A69BACDF8F0C43218AEB /* AudioMessageRecorder.swift */; }; + 1C78234B3FA4E528C7F701B7 /* LumaOMEMO2Module.swift in Sources */ = {isa = PBXBuildFile; fileRef = 6C8698ED5D720AC876F51EE3 /* LumaOMEMO2Module.swift */; }; 1CB1DAF27B8632B2E071338E /* VideoNoteRecorder.swift in Sources */ = {isa = PBXBuildFile; fileRef = 5BB168F9AD341C35EADACF10 /* VideoNoteRecorder.swift */; }; 1D5B3487BDC63B051A33D874 /* VideoNoteRecordingLifecycle.swift in Sources */ = {isa = PBXBuildFile; fileRef = 96829BDC257FD8D61083DA4D /* VideoNoteRecordingLifecycle.swift */; }; 1E239B9338CEEA7EA704626C /* ChatTimelineEntry.swift in Sources */ = {isa = PBXBuildFile; fileRef = 13E35F7F0CB0243311FCDD61 /* ChatTimelineEntry.swift */; }; @@ -170,6 +171,7 @@ A2AF2B19A1E9D9B8D6E1CD63 /* AvatarView.swift in Sources */ = {isa = PBXBuildFile; fileRef = 6EA8DF39BD360C0F8BA5F62F /* AvatarView.swift */; }; A4A742F3BBEFCAFD29975968 /* SaslFailureMessage.swift in Sources */ = {isa = PBXBuildFile; fileRef = 69F4FFBFD65C218FF6505844 /* SaslFailureMessage.swift */; }; A69C1CD6CC1FF13631044BA3 /* GeoLocationTests.swift in Sources */ = {isa = PBXBuildFile; fileRef = 37C24C432306C3FDF7F7DB7D /* GeoLocationTests.swift */; }; + A87AB7D40BD589F5EBCCBD6F /* LumaOMEMO2Tests.swift in Sources */ = {isa = PBXBuildFile; fileRef = 4170740AD7BA5D0EC8C870F0 /* LumaOMEMO2Tests.swift */; }; A90142509385DE6E83818953 /* MessageBubble.swift in Sources */ = {isa = PBXBuildFile; fileRef = 03AC6BC7FC7CFFD69A20DA17 /* MessageBubble.swift */; }; ABAFC50EF551861779FFD9A1 /* RootView.swift in Sources */ = {isa = PBXBuildFile; fileRef = 515DD6F1F80A848C39EBAE84 /* RootView.swift */; }; AC242F69C28F69A001D6559D /* MediaViewerDismissGestureTests.swift in Sources */ = {isa = PBXBuildFile; fileRef = 6DCB924748780145A707D890 /* MediaViewerDismissGestureTests.swift */; }; @@ -222,6 +224,7 @@ E2245416CB055ECEF0C5F81D /* SettingsView.swift in Sources */ = {isa = PBXBuildFile; fileRef = 9A338A8EB30206647BDD922F /* SettingsView.swift */; }; E42A674072CE5D3AF1F5848D /* Conversation.swift in Sources */ = {isa = PBXBuildFile; fileRef = 7846C2EEE2551C6690A4FDC6 /* Conversation.swift */; }; E449F2B17E6D5053EBA7F6A8 /* Shared.xcassets in Resources */ = {isa = PBXBuildFile; fileRef = 7C9866558B72CB1909A01EEC /* Shared.xcassets */; }; + E4B1FDFFD3BFFC47B5F154DE /* LumaOMEMO2Module.swift in Sources */ = {isa = PBXBuildFile; fileRef = 6C8698ED5D720AC876F51EE3 /* LumaOMEMO2Module.swift */; }; E582A0424A63CA16DDA4E984 /* CryptoKitAESGCMEngine.swift in Sources */ = {isa = PBXBuildFile; fileRef = 1A017D8B164B1107299F6781 /* CryptoKitAESGCMEngine.swift */; }; E65D356ABC5320BBFB3E2F6E /* VideoNoteRecordingLifecycleTests.swift in Sources */ = {isa = PBXBuildFile; fileRef = D9FCE089ABBF05EF9F55D451 /* VideoNoteRecordingLifecycleTests.swift */; }; E67E0D2C3FBA2C3739B692E0 /* VideoAttachmentPreview.swift in Sources */ = {isa = PBXBuildFile; fileRef = A88E48AAC10463764CAD9835 /* VideoAttachmentPreview.swift */; }; @@ -340,6 +343,7 @@ 3BA0E25A2B52BDED1C8B3B1B /* ArchiveStore.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = ArchiveStore.swift; sourceTree = ""; }; 3C0E3C6F60C3D4D6C565CA0A /* MediaPreviewProcessor.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = MediaPreviewProcessor.swift; sourceTree = ""; }; 3CDA85EA65BC449733C67084 /* ArchiveMessageBatchPolicy.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = ArchiveMessageBatchPolicy.swift; sourceTree = ""; }; + 4170740AD7BA5D0EC8C870F0 /* LumaOMEMO2Tests.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = LumaOMEMO2Tests.swift; sourceTree = ""; }; 4380219D3AF1D75EDF4D3167 /* MediaViewer.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = MediaViewer.swift; sourceTree = ""; }; 43A4CE3E678096BA76F2988C /* NewChatView.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = NewChatView.swift; sourceTree = ""; }; 47680B7C615374A8C245818F /* AppLockPolicy.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = AppLockPolicy.swift; sourceTree = ""; }; @@ -359,6 +363,7 @@ 6597326A509F73A2993A6B80 /* LayoutCheckUITests.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = LayoutCheckUITests.swift; sourceTree = ""; }; 6773F87EE60F91BBDCA4B1F5 /* GroupConversationTests.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = GroupConversationTests.swift; sourceTree = ""; }; 69F4FFBFD65C218FF6505844 /* SaslFailureMessage.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = SaslFailureMessage.swift; sourceTree = ""; }; + 6C8698ED5D720AC876F51EE3 /* LumaOMEMO2Module.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = LumaOMEMO2Module.swift; sourceTree = ""; }; 6DCB924748780145A707D890 /* MediaViewerDismissGestureTests.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = MediaViewerDismissGestureTests.swift; sourceTree = ""; }; 6DDD7A997EF0AF7DA9C3478B /* MessageReplyFallback.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = MessageReplyFallback.swift; sourceTree = ""; }; 6E25F876C75CC5FCDDCB5906 /* NotificationPolicy.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = NotificationPolicy.swift; sourceTree = ""; }; @@ -401,6 +406,7 @@ ABB0729C69630AE38C2D7BBF /* ArchiveStoreTests.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = ArchiveStoreTests.swift; sourceTree = ""; }; B1E6875B522254FFB5FA880E /* MediaPickerSelectionPolicy.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = MediaPickerSelectionPolicy.swift; sourceTree = ""; }; B2446F6A1D00ADAD261D4CCD /* SASLprep.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = SASLprep.swift; sourceTree = ""; }; + B2DC8B629E8D4F078B192FAB /* MartinOMEMO */ = {isa = PBXFileReference; lastKnownFileType = folder; name = MartinOMEMO; path = ThirdParty/MartinOMEMO; sourceTree = SOURCE_ROOT; }; B38702A403DA3E943525FB62 /* MediaPickerSelectionPolicyTests.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = MediaPickerSelectionPolicyTests.swift; sourceTree = ""; }; B8F7B01C59E9667ADAFABBAC /* MediaViewerItem.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = MediaViewerItem.swift; sourceTree = ""; }; B96E7970930AB7F09CB5DA9C /* LocationMessagePreview.swift */ = {isa = PBXFileReference; lastKnownFileType = sourcecode.swift; path = LocationMessagePreview.swift; sourceTree = ""; }; @@ -476,6 +482,7 @@ 1A017D8B164B1107299F6781 /* CryptoKitAESGCMEngine.swift */, 72EC7DC2FE873C0BA4321496 /* LumaCallEngine.swift */, 8F8DE3CE0E26DEA21A27CF67 /* LumaConnectionStatsModule.swift */, + 6C8698ED5D720AC876F51EE3 /* LumaOMEMO2Module.swift */, 24A68154C2D2B3E9AB0C145F /* LumaOMEMOStore.swift */, E9F226A1F8D82B39630F9CEB /* LumaRoomStore.swift */, F92830FB64B5BD0A06BC828D /* LumaRosterStore.swift */, @@ -604,6 +611,7 @@ CD286F7AF06DFC5488FF0CEA /* EncryptionPreferenceTests.swift */, 37C24C432306C3FDF7F7DB7D /* GeoLocationTests.swift */, 6773F87EE60F91BBDCA4B1F5 /* GroupConversationTests.swift */, + 4170740AD7BA5D0EC8C870F0 /* LumaOMEMO2Tests.swift */, 772A4F24CAF527E328657749 /* MediaFileIOTests.swift */, A127BF01F5C488CD3E053379 /* MediaMetadataTests.swift */, B38702A403DA3E943525FB62 /* MediaPickerSelectionPolicyTests.swift */, @@ -666,6 +674,7 @@ 751CBF99010567D043B5DA42 = { isa = PBXGroup; children = ( + FFFA7B7564720060678770FC /* Packages */, D1D74E43299CD30D89B80F74 /* Resources */, 2A98AB59ED6FB8802C301CF4 /* Sources */, 4D0D58FD94D94B4D409033AF /* Tests */, @@ -744,6 +753,14 @@ path = Components; sourceTree = ""; }; + FFFA7B7564720060678770FC /* Packages */ = { + isa = PBXGroup; + children = ( + B2DC8B629E8D4F078B192FAB /* MartinOMEMO */, + ); + name = Packages; + sourceTree = ""; + }; /* End PBXGroup section */ /* Begin PBXNativeTarget section */ @@ -881,8 +898,8 @@ minimizedProjectReferenceProxies = 1; packageReferences = ( 277642F04D20E1E2B6BE565F /* XCRemoteSwiftPackageReference "Martin" */, - 43A0FD3A38EEEB7A14708794 /* XCRemoteSwiftPackageReference "MartinOMEMO" */, 251B06A6CDEEC0297E9E6836 /* XCRemoteSwiftPackageReference "WebRTC" */, + 3B2A3CB97916A28030D0A4E0 /* XCLocalSwiftPackageReference "ThirdParty/MartinOMEMO" */, ); preferredProjectObjectVersion = 77; productRefGroup = 90CFB4B53B5F9EF91D718FC2 /* Products */; @@ -986,6 +1003,7 @@ 2D83457A8857592E23289EF7 /* LumaApp.swift in Sources */, 5415AF453AB8FCDA55FB59AD /* LumaCallEngine.swift in Sources */, 5459CF1808474747AF46A366 /* LumaConnectionStatsModule.swift in Sources */, + 1C78234B3FA4E528C7F701B7 /* LumaOMEMO2Module.swift in Sources */, FB1052104B90994CF03FE6A2 /* LumaOMEMOStore.swift in Sources */, CBED8565C1313DC03D21A105 /* LumaRoomStore.swift in Sources */, F1713D1CD4E019540BFA78FE /* LumaRosterStore.swift in Sources */, @@ -1099,6 +1117,7 @@ 7F012252FA73A8282B92323C /* LumaApp.swift in Sources */, 7F211C3BBA81E5D43D3A88AE /* LumaCallEngine.swift in Sources */, B13513FE5DAD462086B8B0B0 /* LumaConnectionStatsModule.swift in Sources */, + E4B1FDFFD3BFFC47B5F154DE /* LumaOMEMO2Module.swift in Sources */, 1B20F2D3E4F18E6094B103BF /* LumaOMEMOStore.swift in Sources */, 03C65C3DAA1D8776AF496EFA /* LumaRoomStore.swift in Sources */, 7F4C00E98574C8E5193F442E /* LumaRosterStore.swift in Sources */, @@ -1167,6 +1186,7 @@ 03F2CD213153D0EF5CBC8021 /* EncryptionPreferenceTests.swift in Sources */, A69C1CD6CC1FF13631044BA3 /* GeoLocationTests.swift in Sources */, 60CE79BB4D0FB53E126354AA /* GroupConversationTests.swift in Sources */, + A87AB7D40BD589F5EBCCBD6F /* LumaOMEMO2Tests.swift in Sources */, DC4FAE63AB8AF89C30512763 /* MediaFileIOTests.swift in Sources */, 10C5382981A87A2963DD397C /* MediaMetadataTests.swift in Sources */, 958FD3CBEC600651E1171B55 /* MediaPickerSelectionPolicyTests.swift in Sources */, @@ -1606,6 +1626,13 @@ }; /* End XCConfigurationList section */ +/* Begin XCLocalSwiftPackageReference section */ + 3B2A3CB97916A28030D0A4E0 /* XCLocalSwiftPackageReference "ThirdParty/MartinOMEMO" */ = { + isa = XCLocalSwiftPackageReference; + relativePath = ThirdParty/MartinOMEMO; + }; +/* End XCLocalSwiftPackageReference section */ + /* Begin XCRemoteSwiftPackageReference section */ 251B06A6CDEEC0297E9E6836 /* XCRemoteSwiftPackageReference "WebRTC" */ = { isa = XCRemoteSwiftPackageReference; @@ -1623,14 +1650,6 @@ version = 3.2.4; }; }; - 43A0FD3A38EEEB7A14708794 /* XCRemoteSwiftPackageReference "MartinOMEMO" */ = { - isa = XCRemoteSwiftPackageReference; - repositoryURL = "https://github.com/tigase/MartinOMEMO.git"; - requirement = { - kind = exactVersion; - version = 2.2.3; - }; - }; /* End XCRemoteSwiftPackageReference section */ /* Begin XCSwiftPackageProductDependency section */ @@ -1641,7 +1660,6 @@ }; 371134B6F3E284082E28FE08 /* MartinOMEMO */ = { isa = XCSwiftPackageProductDependency; - package = 43A0FD3A38EEEB7A14708794 /* XCRemoteSwiftPackageReference "MartinOMEMO" */; productName = MartinOMEMO; }; 4BD4324EE01A6DD46EBE7FDA /* Martin */ = { @@ -1656,7 +1674,6 @@ }; 7A670E49149C9C7E13F0A6A2 /* MartinOMEMO */ = { isa = XCSwiftPackageProductDependency; - package = 43A0FD3A38EEEB7A14708794 /* XCRemoteSwiftPackageReference "MartinOMEMO" */; productName = MartinOMEMO; }; EFCAF9B0DE67466AF22E76C3 /* WebRTC */ = { diff --git a/Luma.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved b/Luma.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved index 8546218..59f32d7 100644 --- a/Luma.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved +++ b/Luma.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved @@ -1,5 +1,5 @@ { - "originHash" : "a9b7decfad90e115a57d2c941faf30bf1f041c5fcd0d87ea51c92b76dfac7ca8", + "originHash" : "477b2c6d92d18b2c389859e6415d1fb6bb6cc275812c439725cc2ce4fa0b02a7", "pins" : [ { "identity" : "libsignal", @@ -19,15 +19,6 @@ "version" : "3.2.4" } }, - { - "identity" : "martinomemo", - "kind" : "remoteSourceControl", - "location" : "https://github.com/tigase/MartinOMEMO.git", - "state" : { - "revision" : "3c162154d646aa258c9a86c0a07655a536e55a94", - "version" : "2.2.3" - } - }, { "identity" : "tigase-logging.swift", "kind" : "remoteSourceControl", diff --git a/Makefile b/Makefile index dd871b4..14e9b1f 100644 --- a/Makefile +++ b/Makefile @@ -1,8 +1,9 @@ -.PHONY: project open verify clean +.PHONY: project open verify clean reset project: @command -v xcodegen >/dev/null || (echo "Install XcodeGen first: brew install xcodegen" && exit 1) xcodegen generate + @python3 Scripts/patch-xcodeproj.py open: project open Luma.xcodeproj @@ -13,3 +14,12 @@ verify: clean: rm -rf Luma.xcodeproj DerivedData .build +# Fixes Xcode GUI "Missing package product" errors: the GUI caches the +# SwiftPM package graph in DerivedData, which goes stale when packages +# change (e.g. the remote -> vendored local MartinOMEMO switch). Quit Xcode +# first, run this, then reopen Luma.xcodeproj and let it re-resolve. +reset: + rm -rf ~/Library/Developer/Xcode/DerivedData/Luma-* + rm -f Luma.xcodeproj/project.xcworkspace/xcshareddata/swiftpm/Package.resolved + @echo "Xcode package state cleared. Reopen Luma.xcodeproj to re-resolve packages." + diff --git a/Scripts/patch-xcodeproj.py b/Scripts/patch-xcodeproj.py new file mode 100644 index 0000000..0e79a4e --- /dev/null +++ b/Scripts/patch-xcodeproj.py @@ -0,0 +1,54 @@ +#!/usr/bin/env python3 +"""Post-generation fix for XcodeGen issue #1549: XcodeGen does not link +XCSwiftPackageProductDependency entries to local (path-based) Swift packages, +which makes the Xcode GUI report "Missing package product". This script +attaches the MartinOMEMO product dependencies to the vendored local package +reference in the generated project file. + +Run after every `xcodegen generate` (see the Makefile `project` target). +""" +import sys + +PBXPROJ = "Luma.xcodeproj/project.pbxproj" + + +def main() -> int: + with open(PBXPROJ, encoding="utf-8") as handle: + text = handle.read() + + # Find the object id of the local package reference. + ref_id = None + for line in text.splitlines(): + marker = " /* XCLocalSwiftPackageReference \"ThirdParty/MartinOMEMO\" */ = {" + if marker in line: + ref_id = line.split(" /*")[0].strip() + break + if ref_id is None: + print("patch-xcodeproj: local package reference not found; nothing to do") + return 0 + + needle = ( + "/* MartinOMEMO */ = {\n" + "\t\t\tisa = XCSwiftPackageProductDependency;\n" + "\t\t\tproductName = MartinOMEMO;" + ) + patch = ( + "/* MartinOMEMO */ = {\n" + "\t\t\tisa = XCSwiftPackageProductDependency;\n" + "\t\t\tpackage = " + ref_id + " /* XCLocalSwiftPackageReference \"ThirdParty/MartinOMEMO\" */;\n" + "\t\t\tproductName = MartinOMEMO;" + ) + + count = text.count(needle) + if count == 0: + print("patch-xcodeproj: MartinOMEMO product dependencies already linked") + return 0 + patched = text.replace(needle, patch) + with open(PBXPROJ, "w", encoding="utf-8") as handle: + handle.write(patched) + print("patch-xcodeproj: linked " + str(count) + " MartinOMEMO product dependencies") + return 0 + + +if __name__ == "__main__": + sys.exit(main()) diff --git a/Scripts/regenerate-project.command b/Scripts/regenerate-project.command index 2e9d5bb..a71511d 100755 --- a/Scripts/regenerate-project.command +++ b/Scripts/regenerate-project.command @@ -10,4 +10,7 @@ if ! command -v xcodegen >/dev/null; then fi xcodegen generate +# XcodeGen issue #1549: link the vendored local package to its product +# dependencies, otherwise the Xcode GUI reports "Missing package product". +python3 Scripts/patch-xcodeproj.py open Luma.xcodeproj diff --git a/Scripts/verify.sh b/Scripts/verify.sh index d1d9c67..61cc885 100755 --- a/Scripts/verify.sh +++ b/Scripts/verify.sh @@ -302,6 +302,22 @@ grep -q 'toolbar(.hidden, for: .tabBar)' Sources/Shared/UI/ChatView.swift || { echo "The tab bar must be hidden inside a pushed chat" exit 1 } +grep -q 'PhoneWatchMessageData' Sources/Shared/Services/PhoneWatchBridge.swift || { + echo "The watch bridge must snapshot SwiftData models on the main actor" + exit 1 +} +grep -q 'urn:xmpp:omemo:2' Sources/Shared/XMPP/LumaOMEMO2Module.swift || { + echo "OMEMO 2 must be implemented by the app-level module" + exit 1 +} +grep -q 'decodeOmemo2OffMain' Sources/Shared/XMPP/XMPPService.swift || { + echo "Incoming messages must route OMEMO 2 payloads to the OMEMO 2 module" + exit 1 +} +grep -q 'package = .*XCLocalSwiftPackageReference .ThirdParty/MartinOMEMO.' Luma.xcodeproj/project.pbxproj || { + echo "The vendored MartinOMEMO package must stay linked in the generated project (run make project)" + exit 1 +} grep -q '@Query' Sources/Shared/UI/ChatView.swift || { echo "Chat timeline must be SwiftData @Query-driven" exit 1 diff --git a/Sources/Shared/Services/PhoneWatchBridge.swift b/Sources/Shared/Services/PhoneWatchBridge.swift index 4d856f2..f84e98c 100644 --- a/Sources/Shared/Services/PhoneWatchBridge.swift +++ b/Sources/Shared/Services/PhoneWatchBridge.swift @@ -19,6 +19,24 @@ struct PhoneWatchSnapshot: Codable { let chats: [Chat] } +/// Plain-value snapshots of the SwiftData models, taken on the main actor +/// before the background queue builds the watch payload. Reading @Model +/// properties off the main actor crashes with EXC_BAD_ACCESS. +private struct PhoneWatchChatData { + let jid: String + let name: String + let unread: Int +} + +private struct PhoneWatchMessageData { + let id: String + let conversationID: String + let body: String + let timestamp: Date + let outgoing: Bool + let encrypted: Bool +} + struct WatchVoiceMessage: Sendable { let transferID: String let jid: String @@ -59,18 +77,33 @@ final class PhoneWatchBridge: NSObject, WCSessionDelegate { session?.activate() } + @MainActor func update(conversations: [Conversation], messages: [ChatMessage]) { guard let session else { return } - // Copy-on-write snapshots are cheap here; the filtering, sorting and - // JSON encoding are not. Keep that work away from SwiftUI's main run - // loop, especially immediately after a MAM page is committed. + // SwiftData models must never be read off the main actor: snapshot + // the fields the watch needs here, then hand plain values to the + // background queue for the filtering, sorting and JSON encoding. + let chats = conversations.map { conversation in + PhoneWatchChatData( + jid: conversation.jid, + name: conversation.displayName, + unread: conversation.unreadCount + ) + } + let entries = messages.map { message in + PhoneWatchMessageData( + id: message.clientID, + conversationID: message.conversationID, + body: message.previewText, + timestamp: message.timestamp, + outgoing: message.direction == .outgoing, + encrypted: message.security == .omemo + ) + } snapshotQueue.async { [weak self, weak session] in guard let self, let session, - let data = Self.makeSnapshotData( - conversations: conversations, - messages: messages - ), + let data = Self.makeSnapshotData(chats: chats, entries: entries), data != self.latestSnapshot else { return } self.latestSnapshot = data self.publishLatestSnapshot(using: session) @@ -78,57 +111,56 @@ final class PhoneWatchBridge: NSObject, WCSessionDelegate { } private static func makeSnapshotData( - conversations: [Conversation], - messages: [ChatMessage] + chats: [PhoneWatchChatData], + entries: [PhoneWatchMessageData] ) -> Data? { - let visibleConversations = Array(conversations.prefix(20)) - let visibleConversationIDs = Set(visibleConversations.map(\.jid)) - var recentMessagesByConversation: [String: [ChatMessage]] = [:] + let visibleChats = Array(chats.prefix(20)) + let visibleChatIDs = Set(visibleChats.map(\.jid)) + var recentMessagesByChat: [String: [PhoneWatchMessageData]] = [:] // Keep a bounded, chronologically sorted window. MAM can append an old // overlapping stanza after a newer live message, so array order alone // cannot identify the latest messages reliably. - for message in messages where visibleConversationIDs.contains(message.conversationID) { - var recent = recentMessagesByConversation[message.conversationID] ?? [] - let insertionIndex = Self.insertionIndex(for: message, in: recent) - recent.insert(message, at: insertionIndex) + for entry in entries where visibleChatIDs.contains(entry.conversationID) { + var recent = recentMessagesByChat[entry.conversationID] ?? [] + let insertionIndex = Self.insertionIndex(for: entry, in: recent) + recent.insert(entry, at: insertionIndex) if recent.count > 20 { recent.removeFirst(recent.count - 20) } - recentMessagesByConversation[message.conversationID] = recent + recentMessagesByChat[entry.conversationID] = recent } - let chats = visibleConversations.map { conversation in + let snapshotChats = visibleChats.map { chat in PhoneWatchSnapshot.Chat( - jid: conversation.jid, - name: conversation.displayName, - unread: conversation.unreadCount, - messages: (recentMessagesByConversation[conversation.jid] ?? []) - .map { - PhoneWatchSnapshot.Message( - id: $0.clientID, - body: $0.previewText, - timestamp: $0.timestamp, - outgoing: $0.direction == .outgoing, - encrypted: $0.security == .omemo - ) - } + jid: chat.jid, + name: chat.name, + unread: chat.unread, + messages: (recentMessagesByChat[chat.jid] ?? []).map { entry in + PhoneWatchSnapshot.Message( + id: entry.id, + body: entry.body, + timestamp: entry.timestamp, + outgoing: entry.outgoing, + encrypted: entry.encrypted + ) + } ) } - return try? JSONEncoder.watchEncoder.encode(PhoneWatchSnapshot(chats: chats)) + return try? JSONEncoder.watchEncoder.encode(PhoneWatchSnapshot(chats: snapshotChats)) } private static func insertionIndex( - for message: ChatMessage, - in sortedMessages: [ChatMessage] + for entry: PhoneWatchMessageData, + in sorted: [PhoneWatchMessageData] ) -> Int { var lowerBound = 0 - var upperBound = sortedMessages.count + var upperBound = sorted.count while lowerBound < upperBound { let middle = lowerBound + (upperBound - lowerBound) / 2 - let existing = sortedMessages[middle] - let existingComesFirst = existing.timestamp < message.timestamp - || (existing.timestamp == message.timestamp && existing.clientID < message.clientID) + let existing = sorted[middle] + let existingComesFirst = existing.timestamp < entry.timestamp + || (existing.timestamp == entry.timestamp && existing.id < entry.id) if existingComesFirst { lowerBound = middle + 1 } else { diff --git a/Sources/Shared/UI/ServerInfoView.swift b/Sources/Shared/UI/ServerInfoView.swift index a187d13..9bd3cf0 100644 --- a/Sources/Shared/UI/ServerInfoView.swift +++ b/Sources/Shared/UI/ServerInfoView.swift @@ -8,13 +8,13 @@ struct ServerInfoView: View { @State private var isLoading = false var body: some View { - List { + Form { if let info = model.serverInformation { - Section { + Section("Это статистика вашего соединения.") { statisticsEntries(info) - } header: { - Text("Это статистика вашего соединения.") - } + } //header: { +// Text("Это статистика вашего соединения.") +// } Section { softwareEntry(info) @@ -255,7 +255,7 @@ struct ServerInfoView: View { .font(.caption) .foregroundStyle(.secondary) } - .frame(maxWidth: .infinity, alignment: .leading) +// .frame(maxWidth: .infinity, alignment: .leading) .listRowBackground(status.color) } diff --git a/Sources/Shared/XMPP/LumaOMEMO2Module.swift b/Sources/Shared/XMPP/LumaOMEMO2Module.swift new file mode 100644 index 0000000..b318e03 --- /dev/null +++ b/Sources/Shared/XMPP/LumaOMEMO2Module.swift @@ -0,0 +1,839 @@ +import Foundation +import Combine +import CommonCrypto +import CryptoKit +import os +import Martin +import MartinOMEMO + +extension XmppModuleIdentifier { + static var omemo2: XmppModuleIdentifier { + LumaOMEMO2Module.IDENTIFIER + } +} + +/// OMEMO 2 (XEP-0384 0.8.3, urn:xmpp:omemo:2) support built on the +/// MartinOMEMO signal stack. Wire format implemented here: +/// - payload: AES-256-CBC + HMAC-SHA-256 keyed via HKDF ("OMEMO Payload"), +/// plaintext is a Stanza Content Encryption `` (XEP-0420); +/// - header: `` groups with `` elements; +/// - device list node `urn:xmpp:omemo:2:devices` (`` element); +/// - bundle node `urn:xmpp:omemo:2:bundles` (one item per device id, +/// `` with `///`). +/// The Double Ratchet sessions are shared with the legacy OMEMO module +/// through the same SignalStorage. +final class LumaOMEMO2Module: AbstractPEPModule, XmppModule { + public static let ID = "omemo2" + public static let IDENTIFIER = XmppModuleIdentifier() + public static let XMLNS = "urn:xmpp:omemo:2" + public static let DEVICES_LIST_NODE = "urn:xmpp:omemo:2:devices" + public static let BUNDLES_NODE = "urn:xmpp:omemo:2:bundles" + public static let SCE_XMLNS = "urn:xmpp:sce:1" + public static let HKDF_INFO = "OMEMO Payload" + + public let id: String = ID + public let criteria = Criteria.empty() + public let features: [String] = [LumaOMEMO2Module.DEVICES_LIST_NODE + "+notify"] + + public let signalContext: SignalContext + public let storage: SignalStorage + private let devicesQueue = DispatchQueue(label: "app.luma.omemo2.devices") + private var devices: [BareJID: [Int32]] = [:] + private var devicesFetchError: [BareJID: [Int32]] = [:] + + /// True once our device id has been published to the OMEMO 2 device + /// list and our bundle is on the server. Drives the UI readiness flag. + @Published public private(set) var isReady: Bool = false + + public override var isPepAvailable: Bool { + didSet { + if isPepAvailable { + publishBundleIfNeeded { [weak self] in + self?.publishDeviceListIfNeeded() + } + } + } + } + + public init(signalContext: SignalContext, signalStorage: SignalStorage) { + self.signalContext = signalContext + self.storage = signalStorage + super.init() + } + + public func process(stanza: Stanza) throws { + // Decryption is driven explicitly by XMPPService decode calls; + // PEP notifications arrive through onItemNotification. + } + + // MARK: - Device list + + public func devices(for jid: BareJID) -> [Int32]? { + let known = devicesQueue.sync { devices[jid] } + guard let known else { return nil } + guard let failed = devicesFetchError[jid] else { return known } + return known.filter { !failed.contains($0) } + } + + public func isAvailable(for jid: BareJID) -> Bool { + !(devicesQueue.sync { devices[jid] }?.isEmpty ?? true) + || !storage.sessionStore.allDevices(for: jid.stringValue, activeAndTrusted: true).isEmpty + } + + private func publishDeviceListIfNeeded() { + guard isPepAvailable, let context else { return } + let pepJid = context.userBareJid + context.module(.pubsub).retrieveItems( + from: pepJid, + for: Self.DEVICES_LIST_NODE, + limit: .lastItems(1) + ) { [weak self] result in + switch result { + case .success(let items): + self?.processDeviceList(jid: pepJid, payload: items.items.first?.payload) + case .failure(let error): + guard error.error == .item_not_found || error.error == .internal_server_error() else { return } + self?.processDeviceList(jid: pepJid, payload: nil) + } + } + } + + private func processDeviceList(jid: BareJID, payload input: Element?) { + guard let context else { return } + var list = input + if list?.name != "devices" || list?.xmlns != Self.XMLNS { + list = Element(name: "devices", xmlns: Self.XMLNS) + } + guard let list else { return } + + let isOwn = jid == context.userBareJid + let ourID = String(storage.identityKeyStore.localRegistrationId()) + var changed = false + if isOwn, + list.findChild(where: { $0.name == "device" && $0.getAttribute("id") == ourID }) == nil + { + list.addChild(Element(name: "device", attributes: ["id": ourID, "label": "Luma"])) + changed = true + } + + if isOwn, changed { + let options = PubSubNodeConfig() + options.accessModel = .open + context.module(.pubsub).publishItem( + at: jid, + to: Self.DEVICES_LIST_NODE, + itemId: "current", + payload: list, + publishOptions: options + ) { [weak self] result in + switch result { + case .success: + Logger(subsystem: "Luma", category: "omemo2") + .info("device list published jid=\(jid.stringValue)") + self?.isReady = true + case .failure(let error): + Logger(subsystem: "Luma", category: "omemo2") + .warning("device list publish failed: \(error.error)") + guard error.error == .conflict() else { return } + context.module(.pubsub).retrieveNodeConfiguration( + from: jid, + node: Self.DEVICES_LIST_NODE + ) { result in + guard case .success(let form) = result else { return } + form.accessModel = .open + context.module(.pubsub).configureNode( + at: jid, + node: Self.DEVICES_LIST_NODE, + with: form + ) { _ in + context.module(.pubsub).publishItem( + at: jid, + to: Self.DEVICES_LIST_NODE, + itemId: "current", + payload: list, + publishOptions: options + ) { result in + if case .success = result { self?.isReady = true } + } + } + } + } + } + } else if isOwn { + isReady = true + } + + // Track known devices and align identity states with the list. + let known = list.mapChildren(transform: { $0.getAttribute("id").flatMap(Int32.init) }) + devicesQueue.async { [weak self] in self?.devices[jid] = known } + let active = storage.sessionStore.allDevices(for: jid.stringValue, activeAndTrusted: true) + active.filter { !known.contains($0) }.forEach { + _ = storage.identityKeyStore.setStatus(active: false, forIdentity: SignalAddress(name: jid.stringValue, deviceId: $0)) + } + known.filter { !active.contains($0) }.forEach { + _ = storage.identityKeyStore.setStatus(active: true, forIdentity: SignalAddress(name: jid.stringValue, deviceId: $0)) + } + } + + override func onItemNotification(notification: PubSubModule.ItemNotification) { + guard notification.node == Self.DEVICES_LIST_NODE, let context else { return } + switch notification.action { + case .published(let item): + let from = notification.message.from?.bareJid ?? context.userBareJid + processDeviceList(jid: from, payload: item.payload) + default: + break + } + } + + // MARK: - Bundle + + func publishBundleIfNeeded(completionHandler: (() -> Void)?) { + guard isPepAvailable, let context else { + completionHandler?() + return + } + let deviceID = String(storage.identityKeyStore.localRegistrationId()) + context.module(.pubsub).retrieveItems( + from: context.userBareJid, + for: Self.BUNDLES_NODE, + limit: .items(withIds: [deviceID]) + ) { [weak self] result in + switch result { + case .success(let items): + self?.publishBundle(current: items.items.first?.payload, completionHandler: completionHandler) + case .failure(let error): + guard error.error == .item_not_found || error.error == .internal_server_error() else { + completionHandler?() + return + } + self?.publishBundle(current: nil, completionHandler: completionHandler) + } + } + } + + private func signedPreKey(regenerate: Bool = false) -> SignalSignedPreKey? { + let signedPreKeyId = storage.signedPreKeyStore.countSignedPreKeys() + var signedPreKey: SignalSignedPreKey? + if !regenerate, signedPreKeyId != 0, + let data = signalContext.storage.signedPreKeyStore.loadSignedPreKey(withId: UInt32(signedPreKeyId)) + { + signedPreKey = SignalSignedPreKey(fromSerializedData: data) + } + if signedPreKey == nil { + guard let identityKeyPair = storage.identityKeyStore.keyPair() else { return nil } + signedPreKey = signalContext.generateSignedPreKey( + withIdentity: identityKeyPair, + signedPreKeyId: UInt32(signedPreKeyId + 1) + ) + guard let signedPreKey, let serialized = signedPreKey.serializedData else { return nil } + guard signalContext.storage.signedPreKeyStore.storeSignedPreKey(serialized, withId: signedPreKey.preKeyId) else { + return nil + } + } + return signedPreKey + } + + private func publishBundle(current input: Element?, completionHandler: (() -> Void)?) { + guard let identityKeyPair = storage.identityKeyStore.keyPair(), + let identityPublicKey = identityKeyPair.publicKey + else { + completionHandler?() + return + } + + var flush = input == nil + if !flush { + flush = identityPublicKey.base64EncodedString() != input?.findChild(name: "ik")?.value + } + + guard let signedPreKey = signedPreKey(regenerate: flush) else { + completionHandler?() + return + } + let signedPublicBase64 = signedPreKey.publicKeyData?.base64EncodedString() ?? "" + let signatureBase64 = signedPreKey.signature.base64EncodedString() + var changed = flush + || signedPublicBase64 != input?.findChild(name: "spk")?.value + || signatureBase64 != input?.findChild(name: "spks")?.value + + let currentIDs = input?.findChild(name: "prekeys")?.mapChildren(transform: { + $0.getAttribute("id").flatMap(UInt32.init) + }) ?? [] + var validKeys = currentIDs.compactMap { id -> SignalPreKey? in + guard let data = storage.preKeyStore.loadPreKey(withId: id) else { return nil } + return SignalPreKey(fromSerializedData: data) + } + let needKeys = 100 - validKeys.count + if needKeys > 0 { + changed = true + let start = storage.preKeyStore.currentPreKeyId() + 1 + let newKeys = signalContext.generatePreKeys(withStartingPreKeyId: start, count: UInt32(needKeys)) + validKeys += newKeys.filter { key in + guard let serialized = key.serializedData else { return false } + return storage.preKeyStore.storePreKey(serialized, withId: key.preKeyId) + } + } + + if changed { + publishBundle( + signedPreKey: signedPreKey, + identityKey: identityPublicKey, + preKeys: validKeys, + completionHandler: completionHandler + ) + } else { + completionHandler?() + } + } + + private func publishBundle( + signedPreKey: SignalSignedPreKey, + identityKey: Data, + preKeys: [SignalPreKey], + completionHandler: (() -> Void)? + ) { + guard let context, let signedPreKeyPublic = signedPreKey.publicKeyData else { + completionHandler?() + return + } + + let bundleEl = Element(name: "bundle", xmlns: Self.XMLNS) + bundleEl.addChild(Element( + name: "spk", + cdata: signedPreKeyPublic.base64EncodedString(), + attributes: ["id": String(signedPreKey.preKeyId)] + )) + bundleEl.addChild(Element(name: "spks", cdata: signedPreKey.signature.base64EncodedString())) + bundleEl.addChild(Element(name: "ik", cdata: identityKey.base64EncodedString())) + let pkElements = preKeys.map { preKey -> Element in + let publicData = preKey.serializedPublicKey?.base64EncodedString() ?? "" + return Element(name: "pk", cdata: publicData, attributes: ["id": String(preKey.preKeyId)]) + } + bundleEl.addChild(Element(name: "prekeys", children: pkElements)) + + let options = PubSubNodeConfig() + options.accessModel = .open + options.maxItems = .max + + let deviceID = String(storage.identityKeyStore.localRegistrationId()) + context.module(.pubsub).publishItem( + at: nil, + to: Self.BUNDLES_NODE, + itemId: deviceID, + payload: bundleEl, + publishOptions: options + ) { result in + switch result { + case .success: + Logger(subsystem: "Luma", category: "omemo2") + .info("bundle published deviceID=\(deviceID)") + case .failure(let error): + Logger(subsystem: "Luma", category: "omemo2") + .warning("bundle publish failed: \(error.error)") + } + completionHandler?() + } + } + + // MARK: - Session building + + func buildSession(forAddress address: SignalAddress, completionHandler: (() -> Void)? = nil) { + guard let context else { + completionHandler?() + return + } + let pepJid = BareJID(address.name) + context.module(.pubsub).retrieveItems( + from: pepJid, + for: Self.BUNDLES_NODE, + limit: .items(withIds: [String(address.deviceId)]) + ) { [weak self] result in + defer { completionHandler?() } + guard let self, case .success(let items) = result, + let bundle = OMEMO2Bundle(from: items.items.first?.payload) + else { + self?.markDeviceAsFailed(for: pepJid, andDeviceId: address.deviceId) + return + } + guard let preKey = bundle.preKeys.randomElement(), + let preKeyBundle = SignalPreKeyBundle( + registrationId: 0, + deviceId: address.deviceId, + preKeyId: preKey.id, + preKeyPublic: preKey.data, + signedPreKeyId: bundle.signedPreKeyId, + signedPreKeyPublic: bundle.signedPreKeyPublic, + signedPreKeySignature: bundle.signedPreKeySignature, + identityKey: bundle.identityKey + ), + let builder = SignalSessionBuilder(withAddress: address, andContext: self.signalContext) + else { + self.markDeviceAsFailed(for: pepJid, andDeviceId: address.deviceId) + return + } + _ = builder.processPreKeyBundle(bundle: preKeyBundle) + } + } + + private func markDeviceAsFailed(for jid: BareJID, andDeviceId deviceId: Int32) { + var failed = devicesFetchError[jid] ?? [] + if !failed.contains(deviceId) { + failed.append(deviceId) + devicesFetchError[jid] = failed + } + } + + // MARK: - Decode + + public func decode(message: Message, from: BareJID, serverMsgId: String? = nil) -> DecryptionResult { + guard context != nil else { return .failure(.unknown) } + guard let encryptedEl = message.findChild(name: "encrypted", xmlns: Self.XMLNS), + let headerEl = encryptedEl.findChild(name: "header"), + let sid = UInt32(headerEl.getAttribute("sid") ?? "") + else { + return .failure(.notEncrypted) + } + + let localDeviceID = String(storage.identityKeyStore.localRegistrationId()) + let ownJID = context!.userBareJid.stringValue.lowercased() + + // Collect candidate keys for our device: prefer the 0.8.3 + // `` grouping, fall back to direct `` children. + var keyElements: [Element] = [] + for keysEl in headerEl.getChildren(where: { $0.name == "keys" }) { + guard keysEl.getAttribute("jid")?.lowercased() == ownJID else { continue } + keyElements.append(contentsOf: keysEl.getChildren(where: { $0.name == "key" })) + } + if keyElements.isEmpty { + keyElements = headerEl.getChildren(where: { $0.name == "key" }) + } + let ours = keyElements.filter { $0.getAttribute("rid") == localDeviceID } + guard !ours.isEmpty else { + Logger(subsystem: "Luma", category: "omemo2") + .warning("message not encrypted for us: from=\(from.stringValue) sid=\(sid) ourRid=\(localDeviceID) keyCount=\(keyElements.count) hasPayload=\(encryptedEl.findChild(name: "payload") != nil)") + guard context!.userBareJid != from || sid != storage.identityKeyStore.localRegistrationId() else { + return .failure(.duplicateMessage) + } + guard encryptedEl.findChild(name: "payload") != nil else { + return .failure(.duplicateMessage) + } + return .failure(.invalidMessage) + } + + let address = SignalAddress(name: from.stringValue, deviceId: Int32(bitPattern: sid)) + var lastError: SignalError = .unknown + for keyEl in ours { + guard let base64 = keyEl.value, let keyData = Data(base64Encoded: base64), + let cipher = SignalSessionCipher(withAddress: address, andContext: signalContext) + else { + Logger(subsystem: "Luma", category: "omemo2") + .warning("unusable key element from=\(from.stringValue) sid=\(sid)") + continue + } + let kexRaw = keyEl.getAttribute("kex") ?? "" + let isKex = kexRaw == "true" || kexRaw == "1" + || keyEl.getAttribute("prekey") == "true" || keyEl.getAttribute("prekey") == "1" + // Trust the kex attribute first; some clients mislabel the key + // element, so retry with the opposite interpretation before + // giving up on the message. + var elementError: SignalError = .unknown + for prekey in [isKex, !isKex] { + let result = cipher.decrypt(key: SignalSessionCipher.Key( + key: keyData, + deviceId: Int32(bitPattern: sid), + prekey: prekey + )) + switch result { + case .success(let combined): + Logger(subsystem: "Luma", category: "omemo2") + .info("key decrypted from=\(from.stringValue) sid=\(sid) prekey=\(prekey)") + return finishDecode( + message: message, + encryptedEl: encryptedEl, + combined: combined, + address: address, + isKex: prekey + ) + case .failure(let error): + elementError = error + } + } + lastError = elementError + Logger(subsystem: "Luma", category: "omemo2") + .warning("key decrypt failed: error=\(elementError) from=\(from.stringValue) sid=\(sid) kexAttr=\(kexRaw)") + } + + Logger(subsystem: "Luma", category: "omemo2") + .warning("decode failed: error=\(lastError) from=\(from.stringValue) sid=\(sid)") + if (lastError == .noSession || lastError == .invalidMessage), serverMsgId != nil { + buildSession(forAddress: address) + } + return .failure(lastError) + } + + private func finishDecode( + message: Message, + encryptedEl: Element, + combined: Data, + address: SignalAddress, + isKex: Bool + ) -> DecryptionResult { + message.removeChild(encryptedEl) + + // A consumed prekey must leave our published bundle. + if isKex, storage.preKeyStore.flushDeletedPreKeys() { + publishBundleIfNeeded(completionHandler: nil) + } + + guard let payloadValue = encryptedEl.findChild(name: "payload")?.value, + let ciphertext = Data(base64Encoded: payloadValue) + else { + // Empty message: session management, nothing to display. + return .successTransportKey(combined, iv: Data()) + } + + // combined = key (32) || truncated HMAC (16) + guard combined.count >= 48 else { return .failure(.invalidMac) } + let key = combined.subdata(in: 0..<32) + let expectedMAC = combined.subdata(in: 32..<48) + guard let derived = Self.derivePayloadKeys(from: key) else { return .failure(.invalidMac) } + let computedMAC = Data(HMAC.authenticationCode( + for: ciphertext, + using: SymmetricKey(data: derived.authKey) + ).prefix(16)) + guard Self.constantTimeEquals(computedMAC, expectedMAC) else { + Logger(subsystem: "Luma", category: "omemo2") + .warning("payload HMAC mismatch from=\(address.name) device=\(address.deviceId)") + return .failure(.invalidMac) + } + + guard let plaintext = Self.aes256CBCDecrypt(ciphertext, key: derived.encryptionKey, iv: derived.iv), + let plaintextString = String(data: plaintext, encoding: .utf8), + let envelope = Element.from(string: plaintextString), + envelope.name == "envelope" + else { + Logger(subsystem: "Luma", category: "omemo2") + .warning("payload envelope parse failed from=\(address.name) device=\(address.deviceId)") + return .failure(.invalidMessage) + } + + if let content = envelope.findChild(name: "content"), + let bodyEl = content.findChild(name: "body"), + let body = bodyEl.value, !body.isEmpty + { + message.body = body + } + + Logger(subsystem: "Luma", category: "omemo2") + .info("decoded message from=\(address.name) device=\(address.deviceId) bodyLen=\(message.body?.count ?? 0)") + _ = storage.identityKeyStore.setStatus(active: true, forIdentity: address) + return .successMessage( + message, + fingerprint: storage.identityKeyStore.identityFingerprint(forAddress: address) + ) + } + + // MARK: - Encode + + public func encode( + message: Message, + withStoreHint: Bool = true, + completionHandler: @escaping (EncryptionResult) -> Void + ) { + guard let jid = message.to?.bareJid else { + completionHandler(.failure(.noDestination)) + return + } + encode(message: message, for: [jid], withStoreHint: withStoreHint, completionHandler: completionHandler) + } + + public func addresses( + for jids: [BareJID], + completionHandler: @escaping (Result<[SignalAddress], SignalError>) -> Void + ) { + guard let pubsub = context?.module(.pubsub) else { + completionHandler(.failure(.unknown)) + return + } + let group = DispatchGroup() + var addresses: [SignalAddress] = [] + for jid in jids { + if let known = devices(for: jid) { + let knownAddresses = known.map { SignalAddress(name: jid.stringValue, deviceId: $0) } + addresses.append(contentsOf: knownAddresses) + for address in knownAddresses where !storage.sessionStore.containsSessionRecord(forAddress: address) { + group.enter() + buildSession(forAddress: address) { group.leave() } + } + } else { + group.enter() + pubsub.retrieveItems(from: jid, for: Self.DEVICES_LIST_NODE, limit: .lastItems(1)) { [weak self] result in + defer { group.leave() } + guard let self, case .success(let items) = result, + let listEl = items.items.first?.payload, + listEl.name == "devices", listEl.xmlns == Self.XMLNS + else { return } + let known = listEl.mapChildren(transform: { $0.getAttribute("id").flatMap(Int32.init) }) + self.devicesQueue.async { self.devices[jid] = known } + let knownAddresses = known.map { SignalAddress(name: jid.stringValue, deviceId: $0) } + addresses.append(contentsOf: knownAddresses) + for address in knownAddresses where !self.storage.sessionStore.containsSessionRecord(forAddress: address) { + group.enter() + self.buildSession(forAddress: address) { group.leave() } + } + } + } + } + group.notify(queue: .main) { + completionHandler(.success(addresses)) + } + } + + public func encode( + message: Message, + for jids: [BareJID], + withStoreHint: Bool = true, + completionHandler: @escaping (EncryptionResult) -> Void + ) { + addresses(for: jids) { result in + switch result { + case .failure(let error): + completionHandler(.failure(error)) + case .success(let addresses): + if addresses.isEmpty { + completionHandler(.failure(.noSession)) + } else { + self.encode(message: message, forAddresses: addresses, withStoreHint: withStoreHint, completionHandler: completionHandler) + } + } + } + } + + public func encode( + message: Message, + forAddresses addresses: [SignalAddress], + roomJID: BareJID? = nil, + withStoreHint: Bool = true, + completionHandler: @escaping (EncryptionResult) -> Void + ) { + let result = encodeMessage(message: message, for: addresses, roomJID: roomJID) + switch result { + case .successMessage(let encoded, _): + if withStoreHint { + encoded.addChild(Element(name: "store", xmlns: "urn:xmpp:hints")) + } + default: + break + } + completionHandler(result) + } + + private func encodeMessage( + message: Message, + for remoteAddresses: [SignalAddress], + roomJID: BareJID? + ) -> EncryptionResult { + guard let context else { return .failure(.unknown) } + + let localAddresses = storage.sessionStore + .allDevices(for: context.userBareJid.stringValue, activeAndTrusted: true) + .map { SignalAddress(name: context.userBareJid.stringValue, deviceId: $0) } + let destinations = Set(remoteAddresses + localAddresses) + + // Stanza Content Encryption envelope (XEP-0420) as the plaintext. + let envelopeXML = Self.envelopeXML( + body: message.body, + from: context.userBareJid.stringValue, + to: roomJID?.stringValue + ) + guard let plaintext = envelopeXML.data(using: .utf8) else { return .failure(.unknown) } + + var key = Data(count: 32) + key.withUnsafeMutableBytes { bytes in + _ = SecRandomCopyBytes(kSecRandomDefault, 32, bytes.baseAddress!) + } + guard let derived = Self.derivePayloadKeys(from: key) else { return .failure(.unknown) } + guard let ciphertext = Self.aes256CBCEncrypt(plaintext, key: derived.encryptionKey, iv: derived.iv) else { + return .failure(.unknown) + } + let mac = Data(HMAC.authenticationCode( + for: ciphertext, + using: SymmetricKey(data: derived.authKey) + ).prefix(16)) + var combinedKey = key + combinedKey.append(mac) + + let encryptedEl = Element(name: "encrypted", xmlns: Self.XMLNS) + let header = Element(name: "header") + header.setAttribute("sid", value: String(storage.identityKeyStore.localRegistrationId())) + encryptedEl.addChild(header) + + var keysByJID: [String: [Element]] = [:] + for address in destinations { + guard let cipher = SignalSessionCipher(withAddress: address, andContext: signalContext) else { continue } + switch cipher.encrypt(data: combinedKey) { + case .success(let output): + let keyEl = Element(name: "key", cdata: output.key.base64EncodedString()) + keyEl.setAttribute("rid", value: String(output.deviceId)) + if output.prekey { keyEl.setAttribute("kex", value: "true") } + keysByJID[address.name.lowercased(), default: []].append(keyEl) + case .failure: + break + } + } + for (jid, keys) in keysByJID { + let keysEl = Element(name: "keys") + keysEl.setAttribute("jid", value: jid) + keysEl.addChildren(keys) + header.addChild(keysEl) + } + + encryptedEl.addChild(Element(name: "payload", cdata: ciphertext.base64EncodedString())) + message.body = nil + message.addChild(encryptedEl) + + let fingerprint = storage.identityKeyStore.identityFingerprint( + forAddress: SignalAddress( + name: context.userBareJid.stringValue, + deviceId: Int32(bitPattern: storage.identityKeyStore.localRegistrationId()) + ) + ) + return .successMessage(message, fingerprint: fingerprint) + } + + // MARK: - Crypto helpers (internal for unit tests) + + struct PayloadKeys: Equatable { + let encryptionKey: Data + let authKey: Data + let iv: Data + } + + static func derivePayloadKeys(from key: Data) -> PayloadKeys? { + guard key.count == 32 else { return nil } + let salt = Data(count: 32) // 256 zero bits + let material = HKDF.deriveKey( + inputKeyMaterial: SymmetricKey(data: key), + salt: salt, + info: Data(HKDF_INFO.utf8), + outputByteCount: 80 + ) + let bytes = material.withUnsafeBytes { Data($0) } + return PayloadKeys( + encryptionKey: bytes.subdata(in: 0..<32), + authKey: bytes.subdata(in: 32..<64), + iv: bytes.subdata(in: 64..<80) + ) + } + + static func aes256CBCEncrypt(_ plaintext: Data, key: Data, iv: Data) -> Data? { + crypt(operation: CCOperation(kCCEncrypt), data: plaintext, key: key, iv: iv) + } + + static func aes256CBCDecrypt(_ ciphertext: Data, key: Data, iv: Data) -> Data? { + crypt(operation: CCOperation(kCCDecrypt), data: ciphertext, key: key, iv: iv) + } + + private static func crypt(operation: CCOperation, data: Data, key: Data, iv: Data) -> Data? { + guard key.count == kCCKeySizeAES256, iv.count == kCCBlockSizeAES128 else { return nil } + let bufferSize = data.count + kCCBlockSizeAES128 + var buffer = Data(count: bufferSize) + var moved = 0 + let status = key.withUnsafeBytes { keyBytes in + iv.withUnsafeBytes { ivBytes in + data.withUnsafeBytes { dataBytes in + buffer.withUnsafeMutableBytes { outBytes in + CCCrypt( + operation, + CCAlgorithm(kCCAlgorithmAES), + CCOptions(kCCOptionPKCS7Padding), + keyBytes.baseAddress, key.count, + ivBytes.baseAddress, + dataBytes.baseAddress, data.count, + outBytes.baseAddress, bufferSize, + &moved + ) + } + } + } + } + guard status == kCCSuccess else { return nil } + buffer.removeSubrange(moved.. Bool { + guard lhs.count == rhs.count else { return false } + var difference: UInt8 = 0 + for index in 0.. String { + var content = "" + if let body, !body.isEmpty { + content += "" + escapeXML(body) + "" + } + let alphabet = Array("abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789") + let rpadLength = Int.random(in: 12...96) + let rpad = String((0.." + result += "" + rpad + "" + result += "" + if let toJID { + result += "" + } + result += "" + return result + } + + static func escapeXML(_ value: String) -> String { + value + .replacingOccurrences(of: "&", with: "&") + .replacingOccurrences(of: "<", with: "<") + .replacingOccurrences(of: ">", with: ">") + } +} + +/// Parsed `urn:xmpp:omemo:2` bundle (`///`). +struct OMEMO2Bundle { + let signedPreKeyId: UInt32 + let signedPreKeyPublic: Data + let signedPreKeySignature: Data + let identityKey: Data + let preKeys: [(id: UInt32, data: Data)] + + init?(from element: Element?) { + guard let element, + element.name == "bundle", element.xmlns == LumaOMEMO2Module.XMLNS, + let spk = element.findChild(name: "spk"), + let spkID = spk.getAttribute("id").flatMap(UInt32.init), + let spkValue = spk.value, + let spkData = Data(base64Encoded: spkValue), + let spks = element.findChild(name: "spks")?.value, + let spksData = Data(base64Encoded: spks), + let ik = element.findChild(name: "ik")?.value, + let ikData = Data(base64Encoded: ik), + let preKeysEl = element.findChild(name: "prekeys") + else { return nil } + + let parsedPreKeys = preKeysEl.mapChildren(transform: { pk -> (UInt32, Data)? in + guard pk.name == "pk", + let id = pk.getAttribute("id").flatMap(UInt32.init), + let value = pk.value, + let data = Data(base64Encoded: value) + else { return nil } + return (id, data) + }) + guard !parsedPreKeys.isEmpty else { return nil } + + signedPreKeyId = spkID + signedPreKeyPublic = spkData + signedPreKeySignature = spksData + identityKey = ikData + preKeys = parsedPreKeys + } +} diff --git a/Sources/Shared/XMPP/XMPPService.swift b/Sources/Shared/XMPP/XMPPService.swift index e5e149c..db8d439 100644 --- a/Sources/Shared/XMPP/XMPPService.swift +++ b/Sources/Shared/XMPP/XMPPService.swift @@ -854,14 +854,28 @@ final class XMPPService { addReply(replyTo, fallback: replyFallback, to: message) if !encrypted, let outOfBandURL { message.oob = outOfBandURL } if encrypted { - guard let omemo = client.moduleOrNil(.omemo), omemo.isReady else { - throw LumaXMPPError.omemoNotReady - } let recipients = try await groupOMEMORecipients( in: room, using: muc, client: client ) + // OMEMO 2 only when every member publishes OMEMO 2 devices; + // otherwise the legacy protocol keeps legacy members readable. + if let omemo2 = client.moduleOrNil(.omemo2), + omemo2.isReady, + recipients.allSatisfy({ omemo2.devices(for: $0)?.isEmpty == false }) { + let encryptedMessage = try await encrypt( + message, + forGroupRecipients: recipients, + using: omemo2, + roomJID: roomJID + ) + try await room.send(message: encryptedMessage.message) + return encryptedMessage.fingerprint + } + guard let omemo = client.moduleOrNil(.omemo), omemo.isReady else { + throw LumaXMPPError.omemoNotReady + } let encryptedMessage = try await encrypt( message, forGroupRecipients: recipients, @@ -893,6 +907,15 @@ final class XMPPService { message.oob = outOfBandURL } if encrypted { + // Prefer OMEMO 2 when the peer publishes OMEMO 2 devices; legacy + // OMEMO stays as the fallback for legacy-only contacts. + if let omemo2 = client.moduleOrNil(.omemo2), + omemo2.isReady, + omemo2.devices(for: peer)?.isEmpty == false { + let encryptedMessage = try await encrypt(message, using: omemo2) + try await chat.send(message: encryptedMessage.message) + return encryptedMessage.fingerprint + } guard let omemo = client.moduleOrNil(.omemo), omemo.isReady else { throw LumaXMPPError.omemoNotReady } @@ -1699,6 +1722,12 @@ final class XMPPService { signalStorage: omemoStorage ) ) + // OMEMO 2 (urn:xmpp:omemo:2) shares the signal storage with the + // legacy module: Double Ratchet sessions are per-device and + // namespace-agnostic. + _ = client.modulesManager.register( + LumaOMEMO2Module(signalContext: signalContext, signalStorage: omemoStorage) + ) } private func configureConnection( @@ -1873,14 +1902,20 @@ final class XMPPService { } .store(in: &cancellables) - client.module(.omemo).$isReady - .removeDuplicates() - .receive(on: DispatchQueue.main) - .sink { [weak self] ready in - self?.eventHandler?( - .omemo(ready: ready, ownFingerprint: omemoStorage.ownFingerprint)) - } - .store(in: &cancellables) + // The UI is ready for encrypted messaging once either protocol + // has published its keys. + Publishers.CombineLatest( + client.module(.omemo).$isReady, + client.module(.omemo2).$isReady + ) + .map { legacyReady, omemo2Ready in legacyReady || omemo2Ready } + .removeDuplicates() + .receive(on: DispatchQueue.main) + .sink { [weak self] ready in + self?.eventHandler?( + .omemo(ready: ready, ownFingerprint: omemoStorage.ownFingerprint)) + } + .store(in: &cancellables) } private func deliverOrDelayDirect(_ message: Message, timestamp: Date) async { @@ -1936,6 +1971,22 @@ final class XMPPService { } } + /// OMEMO 2 twin of `decodeOmemoOffMain`. + private func decodeOmemo2OffMain( + _ message: Message, + from sender: BareJID, + serverMsgId: String?, + module: LumaOMEMO2Module + ) async -> DecryptionResult { + let queue = omemoDecodeQueue + return await withCheckedContinuation { continuation in + queue.async { + let result = module.decode(message: message, from: sender, serverMsgId: serverMsgId) + continuation.resume(returning: result) + } + } + } + private func handle(state: XMPPClient.State) { switch state { case .connecting, .disconnecting: @@ -1988,12 +2039,22 @@ final class XMPPService { let security: ChatMessage.Security let fingerprint: String? let contentMessage: Message? - switch await decodeOmemoOffMain( - message, - from: sender, - serverMsgId: archiveID, - module: client.module(.omemo) - ) { + let decryptionResult = await ( + Self.isOMEMO2Payload(message) + ? decodeOmemo2OffMain( + message, + from: sender, + serverMsgId: archiveID, + module: client.module(.omemo2) + ) + : decodeOmemoOffMain( + message, + from: sender, + serverMsgId: archiveID, + module: client.module(.omemo) + ) + ) + switch decryptionResult { case .successMessage(let decodedMessage, let value): security = .omemo fingerprint = value @@ -2003,18 +2064,9 @@ final class XMPPService { case .failure(let error): switch error { case .notEncrypted: - if Self.isOMEMO2Payload(message), message.body?.isEmpty != false { - // OMEMO 2 (urn:xmpp:omemo:2) is not implemented by the - // pinned MartinOMEMO library; show the honest - // undecryptable state instead of an empty bubble. - security = .decryptionFailed - fingerprint = nil - contentMessage = nil - } else { - security = .plaintext - fingerprint = nil - contentMessage = message - } + security = .plaintext + fingerprint = nil + contentMessage = message default: // Some clients include a plaintext fallback alongside the // OMEMO payload. When decryption fails, prefer that @@ -2231,6 +2283,7 @@ final class XMPPService { : (stanzaID ?? message.originId ?? message.id ?? UUID().uuidString) let encrypted = message.firstChild(name: "encrypted", xmlns: OMEMOModule.XMLNS) != nil + || message.firstChild(name: "encrypted", xmlns: LumaOMEMO2Module.XMLNS) != nil let realSender: BareJID? if outgoing { realSender = client.userBareJid @@ -2252,12 +2305,22 @@ final class XMPPService { let fingerprint: String? let contentMessage: Message? if let realSender { - switch await decodeOmemoOffMain( - message, - from: realSender, - serverMsgId: stanzaID, - module: client.module(.omemo) - ) { + let decryptionResult = await ( + Self.isOMEMO2Payload(message) + ? decodeOmemo2OffMain( + message, + from: realSender, + serverMsgId: stanzaID, + module: client.module(.omemo2) + ) + : decodeOmemoOffMain( + message, + from: realSender, + serverMsgId: stanzaID, + module: client.module(.omemo) + ) + ) + switch decryptionResult { case .successMessage(let decodedMessage, let value): security = .omemo fingerprint = value @@ -2267,15 +2330,9 @@ final class XMPPService { case .failure(let error): switch error { case .notEncrypted: - if Self.isOMEMO2Payload(message), message.body?.isEmpty != false { - security = .decryptionFailed - fingerprint = nil - contentMessage = nil - } else { - security = .plaintext - fingerprint = nil - contentMessage = message - } + security = .plaintext + fingerprint = nil + contentMessage = message case .duplicateMessage: emitGroupEchoIfPossible( roomJID: roomJID, @@ -2871,6 +2928,113 @@ final class XMPPService { } } + /// OMEMO 2 twin of `encrypt(_:using:)`. + private func encrypt( + _ message: Message, + using omemo: LumaOMEMO2Module + ) async throws -> (message: Message, fingerprint: String?) { + try await withCheckedThrowingContinuation { continuation in + omemo.encode(message: message, withStoreHint: true) { result in + switch result { + case .successMessage(let message, let fingerprint): + continuation.resume(returning: (message, fingerprint)) + case .failure(let error): + continuation.resume( + throwing: LumaXMPPError.omemoEncryptionFailed(error.rawValue)) + } + } + } + } + + /// OMEMO 2 twin of `encrypt(_:forGroupRecipients:using:)`. Keys are + /// nested in `` groups, so the per-device validation walks the + /// header's groups. + private func encrypt( + _ message: Message, + forGroupRecipients recipients: [BareJID], + using omemo: LumaOMEMO2Module, + roomJID: BareJID + ) async throws -> (message: Message, fingerprint: String?) { + let fetchedAddresses: [SignalAddress] = try await withCheckedThrowingContinuation { + continuation in + omemo.addresses(for: recipients) { result in + switch result { + case .success(let addresses): + continuation.resume(returning: addresses) + case .failure(let error): + continuation.resume( + throwing: LumaXMPPError.omemoEncryptionFailed(error.rawValue)) + } + } + } + let addresses = Array(Set(fetchedAddresses)) + + let availableJIDs = Set(addresses.map { $0.name.lowercased() }) + let missingJIDs = + recipients + .map(\.stringValue) + .filter { !availableJIDs.contains($0.lowercased()) } + guard missingJIDs.isEmpty else { + throw LumaXMPPError.groupOMEMODevicesUnavailable(missingJIDs.sorted()) + } + + let addressesWithoutSessions = addresses.filter { + omemoStorage?.hasSession(for: $0) != true + } + guard addressesWithoutSessions.isEmpty else { + throw LumaXMPPError.groupOMEMOSessionsUnavailable( + addressesWithoutSessions + .map { "\($0.name)/\($0.deviceId)" } + .sorted() + ) + } + + let encryptedMessage: (message: Message, fingerprint: String?) = + try await withCheckedThrowingContinuation { continuation in + omemo.encode( + message: message, + forAddresses: addresses, + roomJID: roomJID, + withStoreHint: true + ) { result in + switch result { + case .successMessage(let message, let fingerprint): + continuation.resume(returning: (message, fingerprint)) + case .failure(let error): + continuation.resume( + throwing: LumaXMPPError.omemoEncryptionFailed(error.rawValue)) + } + } + } + + var encryptedKeyCounts: [Int32: Int] = [:] + if let encrypted = encryptedMessage.message.firstChild( + name: "encrypted", xmlns: LumaOMEMO2Module.XMLNS + ), let header = encrypted.findChild(name: "header") { + var keyElements: [Element] = [] + for keysEl in header.getChildren(where: { $0.name == "keys" }) { + keyElements.append(contentsOf: keysEl.getChildren(where: { $0.name == "key" })) + } + keyElements + .compactMap { $0.getAttribute("rid").flatMap(Int32.init) } + .forEach { encryptedKeyCounts[$0, default: 0] += 1 } + } + + var unavailableAddresses: [String] = [] + for address in addresses { + let availableCount = encryptedKeyCounts[address.deviceId, default: 0] + if availableCount > 0 { + encryptedKeyCounts[address.deviceId] = availableCount - 1 + } else { + unavailableAddresses.append("\(address.name)/\(address.deviceId)") + } + } + guard unavailableAddresses.isEmpty else { + throw LumaXMPPError.groupOMEMOSessionsUnavailable(unavailableAddresses.sorted()) + } + return encryptedMessage + } + private func encrypt( _ message: Message, forGroupRecipients recipients: [BareJID], diff --git a/Tests/LumaOMEMO2Tests.swift b/Tests/LumaOMEMO2Tests.swift new file mode 100644 index 0000000..8f6d248 --- /dev/null +++ b/Tests/LumaOMEMO2Tests.swift @@ -0,0 +1,317 @@ +import XCTest +import Foundation +import CryptoKit +@testable import Luma +import Martin +import MartinOMEMO + +final class LumaOMEMO2Tests: XCTestCase { + + // MARK: - Payload crypto (XEP-0384 0.8.3, section 4.4) + + func testDerivePayloadKeysHasStableStructure() throws { + let key = Data(repeating: 0x42, count: 32) + let derived = try XCTUnwrap(LumaOMEMO2Module.derivePayloadKeys(from: key)) + XCTAssertEqual(derived.encryptionKey.count, 32) + XCTAssertEqual(derived.authKey.count, 32) + XCTAssertEqual(derived.iv.count, 16) + + // Deterministic and key-dependent. + XCTAssertEqual(derived, LumaOMEMO2Module.derivePayloadKeys(from: key)) + let other = try XCTUnwrap(LumaOMEMO2Module.derivePayloadKeys(from: Data(repeating: 0x43, count: 32))) + XCTAssertNotEqual(derived, other) + + // Wrong input size is rejected. + XCTAssertNil(LumaOMEMO2Module.derivePayloadKeys(from: Data([1, 2, 3]))) + } + + func testCBCRoundTrip() throws { + let key = Data(repeating: 0x11, count: 32) + let iv = Data(repeating: 0x22, count: 16) + let plaintext = Data("OMEMO 2 payload".utf8) + + let ciphertext = try XCTUnwrap(LumaOMEMO2Module.aes256CBCEncrypt(plaintext, key: key, iv: iv)) + XCTAssertNotEqual(ciphertext, plaintext) + let recovered = try XCTUnwrap(LumaOMEMO2Module.aes256CBCDecrypt(ciphertext, key: key, iv: iv)) + XCTAssertEqual(recovered, plaintext) + + // A wrong key never recovers the plaintext: the padding check may + // either reject the result or yield garbage, but never the content. + // Integrity itself is guaranteed by the HMAC step in finishDecode. + let wrongKey = Data(repeating: 0x12, count: 32) + let wrong = LumaOMEMO2Module.aes256CBCDecrypt(ciphertext, key: wrongKey, iv: iv) + if let wrong { + XCTAssertNotEqual(wrong, plaintext) + } + + // PKCS#7 padding rounds up to a whole block. + XCTAssertEqual(ciphertext.count % 16, 0) + } + + func testHMACTruncationMatchesManualComputation() throws { + let authKey = Data(repeating: 0x33, count: 32) + let message = Data("authenticate me".utf8) + let full = Data(HMAC.authenticationCode(for: message, using: SymmetricKey(data: authKey))) + XCTAssertEqual(full.count, 32) + // The wire format keeps the first 16 bytes ("cutting off excess + // bytes from the end" in the spec). + let truncated = Data(full.prefix(16)) + XCTAssertEqual(truncated.count, 16) + XCTAssertEqual(LumaOMEMO2Module.constantTimeEquals(truncated, full.subdata(in: 0..<16)), true) + XCTAssertFalse(LumaOMEMO2Module.constantTimeEquals(truncated, Data(repeating: 0, count: 16))) + XCTAssertFalse(LumaOMEMO2Module.constantTimeEquals(truncated, Data([1]))) + } + + // MARK: - SCE envelope (XEP-0420) + + func testEnvelopeRoundTrip() throws { + let xml = LumaOMEMO2Module.envelopeXML( + body: "Привет & <тест>", + from: "user@example.org", + to: nil + ) + let envelope = try XCTUnwrap(Element.from(string: xml)) + XCTAssertEqual(envelope.name, "envelope") + XCTAssertEqual(envelope.xmlns, "urn:xmpp:sce:1") + + let content = try XCTUnwrap(envelope.findChild(name: "content")) + let body = try XCTUnwrap(content.findChild(name: "body")) + XCTAssertEqual(body.value, "Привет & <тест>") + XCTAssertEqual(body.xmlns, "jabber:client") + + // rpad must be present and non-empty. + let rpad = try XCTUnwrap(envelope.findChild(name: "rpad")?.value) + XCTAssertFalse(rpad.isEmpty) + + // from affix is mandatory. + XCTAssertEqual(envelope.findChild(name: "from")?.getAttribute("jid"), "user@example.org") + // No without a MUC. + XCTAssertNil(envelope.findChild(name: "to")) + } + + func testEnvelopeIncludesToAffixForMUC() throws { + let xml = LumaOMEMO2Module.envelopeXML( + body: "hi", + from: "user@example.org", + to: "room@conference.example.org" + ) + let envelope = try XCTUnwrap(Element.from(string: xml)) + XCTAssertEqual( + envelope.findChild(name: "to")?.getAttribute("jid"), + "room@conference.example.org" + ) + } + + // MARK: - Bundle parsing + + func testBundleParsing() throws { + let bundle = Element(name: "bundle", xmlns: "urn:xmpp:omemo:2") + bundle.addChild(Element(name: "spk", cdata: Data([1, 2, 3]).base64EncodedString(), attributes: ["id": "7"])) + bundle.addChild(Element(name: "spks", cdata: Data([4, 5, 6]).base64EncodedString())) + bundle.addChild(Element(name: "ik", cdata: Data([7, 8, 9]).base64EncodedString())) + let prekeys = Element(name: "prekeys") + prekeys.addChild(Element(name: "pk", cdata: Data([10, 11]).base64EncodedString(), attributes: ["id": "11"])) + prekeys.addChild(Element(name: "pk", cdata: Data([12, 13]).base64EncodedString(), attributes: ["id": "12"])) + bundle.addChild(prekeys) + + let parsed = try XCTUnwrap(OMEMO2Bundle(from: bundle)) + XCTAssertEqual(parsed.signedPreKeyId, 7) + XCTAssertEqual(parsed.signedPreKeyPublic, Data([1, 2, 3])) + XCTAssertEqual(parsed.signedPreKeySignature, Data([4, 5, 6])) + XCTAssertEqual(parsed.identityKey, Data([7, 8, 9])) + XCTAssertEqual(parsed.preKeys.count, 2) + + // Wrong namespace is rejected. + bundle.xmlns = "urn:xmpp:omemo:0" + XCTAssertNil(OMEMO2Bundle(from: bundle)) + } + + // MARK: - Double Ratchet round trip (shared with the legacy module) + + func testRatchetSessionRoundTrip() throws { + let alice = try makeStorage() + let bob = try makeStorage() + + let aliceContext = try XCTUnwrap(SignalContext(withStorage: alice)) + let bobContext = try XCTUnwrap(SignalContext(withStorage: bob)) + + let aliceDevice = Int32(bitPattern: alice.identities.localRegistrationId()) + let aliceAddress = SignalAddress(name: "alice@example.org", deviceId: aliceDevice) + let bobAddress = SignalAddress(name: "bob@example.org", deviceId: Int32(bitPattern: bob.identities.localRegistrationId())) + + // Bob builds a session with Alice from her published bundle. + let preKey = try XCTUnwrap(alice.preKeys.loadPreKey(withId: 1)) + let preKeyRecord = try XCTUnwrap(SignalPreKey(fromSerializedData: preKey)) + let signedPreKey = try XCTUnwrap(alice.signedPreKeys.loadSignedPreKey(withId: 1)) + let signedPreKeyRecord = try XCTUnwrap(SignalSignedPreKey(fromSerializedData: signedPreKey)) + let identityKey = try XCTUnwrap(alice.identities.keyPair()?.publicKey) + let bundle = try XCTUnwrap(SignalPreKeyBundle( + registrationId: 0, + deviceId: aliceDevice, + preKeyId: 1, + preKeyPublic: try XCTUnwrap(preKeyRecord.serializedPublicKey), + signedPreKeyId: 1, + signedPreKeyPublic: try XCTUnwrap(signedPreKeyRecord.publicKeyData), + signedPreKeySignature: signedPreKeyRecord.signature, + identityKey: identityKey + )) + let builder = try XCTUnwrap(SignalSessionBuilder(withAddress: aliceAddress, andContext: bobContext)) + XCTAssertTrue(builder.processPreKeyBundle(bundle: bundle)) + + // The 48-byte combined key (payload key + truncated HMAC) travels + // through the ratchet exactly like in LumaOMEMO2Module. + var combined = Data(repeating: 0x5A, count: 32) + combined.append(Data(repeating: 0x3C, count: 16)) + + let bobCipher = try XCTUnwrap(SignalSessionCipher(withAddress: aliceAddress, andContext: bobContext)) + let encryptedKey = try bobCipher.encrypt(data: combined).get() + XCTAssertTrue(encryptedKey.prekey) + + let aliceCipher = try XCTUnwrap(SignalSessionCipher(withAddress: bobAddress, andContext: aliceContext)) + let decrypted = try aliceCipher.decrypt(key: SignalSessionCipher.Key( + key: encryptedKey.key, + deviceId: Int32(bitPattern: bob.identities.localRegistrationId()), + prekey: true + )).get() + XCTAssertEqual(decrypted, combined) + } +} + +// MARK: - In-memory signal stores + +private final class TestOMEMOStorage: SignalStorage { + let sessions = InMemorySessionStore() + let preKeys = InMemoryPreKeyStore() + let signedPreKeys = InMemorySignedPreKeyStore() + let identities = InMemoryIdentityKeyStore() + let senderKeys = InMemorySenderKeyStore() + + init() { + super.init( + sessionStore: sessions, + preKeyStore: preKeys, + signedPreKeyStore: signedPreKeys, + identityKeyStore: identities, + senderKeyStore: senderKeys + ) + } + + override func setup(withContext context: SignalContext) { + identities.registrationID = context.generateRegistrationId() + if let pair = SignalIdentityKeyPair.generateKeyPair(context: context) { + identities.keyPairData = pair.serialized() + } + if let identityKeyPair = identities.keyPair(), + let signedPreKey = context.generateSignedPreKey(withIdentity: identityKeyPair, signedPreKeyId: 1), + let serialized = signedPreKey.serializedData { + _ = signedPreKeys.storeSignedPreKey(serialized, withId: 1) + } + let generated = context.generatePreKeys(withStartingPreKeyId: 1, count: 1) + for preKey in generated { + if let serialized = preKey.serializedData { + _ = preKeys.storePreKey(serialized, withId: preKey.preKeyId) + } + } + super.setup(withContext: context) + } +} + +private final class InMemorySessionStore: SignalSessionStoreProtocol { + private var records: [String: Data] = [:] + func sessionRecord(forAddress address: SignalAddress) -> Data? { + records["\(address.name)|\(address.deviceId)"] + } + func allDevices(for name: String, activeAndTrusted: Bool) -> [Int32] { [] } + func storeSessionRecord(_ data: Data, forAddress address: SignalAddress) -> Bool { + records["\(address.name)|\(address.deviceId)"] = data + return true + } + func containsSessionRecord(forAddress address: SignalAddress) -> Bool { + sessionRecord(forAddress: address) != nil + } + func deleteSessionRecord(forAddress address: SignalAddress) -> Bool { + records.removeValue(forKey: "\(address.name)|\(address.deviceId)") != nil + } + func deleteAllSessions(for name: String) -> Bool { + records.removeAll() + return true + } +} + +private final class InMemoryPreKeyStore: SignalPreKeyStoreProtocol { + private var keys: [UInt32: Data] = [:] + private var pendingDeletion: Set = [] + func currentPreKeyId() -> UInt32 { keys.keys.max() ?? 0 } + func loadPreKey(withId id: UInt32) -> Data? { keys[id] } + func storePreKey(_ data: Data, withId id: UInt32) -> Bool { + keys[id] = data + return true + } + func containsPreKey(withId id: UInt32) -> Bool { keys[id] != nil } + func deletePreKey(withId id: UInt32) -> Bool { + pendingDeletion.insert(id) + return true + } + func flushDeletedPreKeys() -> Bool { + let ids = pendingDeletion + pendingDeletion.removeAll() + ids.forEach { keys.removeValue(forKey: $0) } + return !ids.isEmpty + } +} + +private final class InMemorySignedPreKeyStore: SignalSignedPreKeyStoreProtocol { + private var keys: [UInt32: Data] = [:] + func countSignedPreKeys() -> Int { keys.count } + func loadSignedPreKey(withId id: UInt32) -> Data? { keys[id] } + func storeSignedPreKey(_ data: Data, withId id: UInt32) -> Bool { + keys[id] = data + return true + } + func containsSignedPreKey(withId id: UInt32) -> Bool { keys[id] != nil } + func deleteSignedPreKey(withId id: UInt32) -> Bool { + keys.removeValue(forKey: id) != nil + } +} + +private final class InMemoryIdentityKeyStore: SignalIdentityKeyStoreProtocol { + var registrationID: UInt32 = 0 + var keyPairData: Data? + private var identities: [String: Data] = [:] + func keyPair() -> SignalIdentityKeyPairProtocol? { + guard let keyPairData else { return nil } + return SignalIdentityKeyPair(fromKeyPairData: keyPairData) + } + func localRegistrationId() -> UInt32 { registrationID } + func save(identity: SignalAddress, key: SignalIdentityKeyProtocol?) -> Bool { + save(identity: identity, publicKeyData: key?.publicKey) + } + func isTrusted(identity: SignalAddress, key: SignalIdentityKeyProtocol?) -> Bool { + isTrusted(identity: identity, publicKeyData: key?.publicKey) + } + func save(identity: SignalAddress, publicKeyData: Data?) -> Bool { + guard let publicKeyData else { return false } + identities["\(identity.name)|\(identity.deviceId)"] = publicKeyData + return true + } + func isTrusted(identity: SignalAddress, publicKeyData: Data?) -> Bool { true } + func setStatus(_ status: IdentityStatus, forIdentity identity: SignalAddress) -> Bool { true } + func setStatus(active: Bool, forIdentity identity: SignalAddress) -> Bool { true } + func identities(forName name: String) -> [Identity] { [] } + func identityFingerprint(forAddress address: SignalAddress) -> String? { nil } +} + +private final class InMemorySenderKeyStore: SignalSenderKeyStoreProtocol { + private var keys: [String: Data] = [:] + func storeSenderKey(_ key: Data, address: SignalAddress?, groupId: String?) -> Bool { + keys["\(address?.name ?? "-")|\(groupId ?? "-")"] = key + return true + } + func loadSenderKey(forAddress address: SignalAddress?, groupId: String?) -> Data? { + keys["\(address?.name ?? "-")|\(groupId ?? "-")"] + } +} + +private func makeStorage() throws -> TestOMEMOStorage { + TestOMEMOStorage() +} diff --git a/ThirdParty/MartinOMEMO/.github/FUNDING.yml b/ThirdParty/MartinOMEMO/.github/FUNDING.yml new file mode 100644 index 0000000..69bde74 --- /dev/null +++ b/ThirdParty/MartinOMEMO/.github/FUNDING.yml @@ -0,0 +1,3 @@ +# These are supported funding model platforms + +github: [tigase] diff --git a/ThirdParty/MartinOMEMO/.gitignore b/ThirdParty/MartinOMEMO/.gitignore new file mode 100644 index 0000000..6cb6e6f --- /dev/null +++ b/ThirdParty/MartinOMEMO/.gitignore @@ -0,0 +1,6 @@ +.DS_Store +/.build +/.swiftpm +/Packages +/*.xcodeproj +xcuserdata/ diff --git a/ThirdParty/MartinOMEMO/LICENSE b/ThirdParty/MartinOMEMO/LICENSE new file mode 100644 index 0000000..aa08301 --- /dev/null +++ b/ThirdParty/MartinOMEMO/LICENSE @@ -0,0 +1,674 @@ +GNU GENERAL PUBLIC LICENSE +Version 3, 29 June 2007 + +Copyright (C) 2007 Free Software Foundation, Inc. +Everyone is permitted to copy and distribute verbatim copies +of this license document, but changing it is not allowed. + +Preamble + +The GNU General Public License is a free, copyleft license for +software and other kinds of works. + +The licenses for most software and other practical works are designed +to take away your freedom to share and change the works. By contrast, +the GNU General Public License is intended to guarantee your freedom to +share and change all versions of a program--to make sure it remains free +software for all its users. We, the Free Software Foundation, use the +GNU General Public License for most of our software; it applies also to +any other work released this way by its authors. You can apply it to +your programs, too. + +When we speak of free software, we are referring to freedom, not +price. Our General Public Licenses are designed to make sure that you +have the freedom to distribute copies of free software (and charge for +them if you wish), that you receive source code or can get it if you +want it, that you can change the software or use pieces of it in new +free programs, and that you know you can do these things. + +To protect your rights, we need to prevent others from denying you +these rights or asking you to surrender the rights. Therefore, you have +certain responsibilities if you distribute copies of the software, or if +you modify it: responsibilities to respect the freedom of others. + +For example, if you distribute copies of such a program, whether +gratis or for a fee, you must pass on to the recipients the same +freedoms that you received. You must make sure that they, too, receive +or can get the source code. And you must show them these terms so they +know their rights. + +Developers that use the GNU GPL protect your rights with two steps: +(1) assert copyright on the software, and (2) offer you this License +giving you legal permission to copy, distribute and/or modify it. + +For the developers' and authors' protection, the GPL clearly explains +that there is no warranty for this free software. For both users' and +authors' sake, the GPL requires that modified versions be marked as +changed, so that their problems will not be attributed erroneously to +authors of previous versions. + +Some devices are designed to deny users access to install or run +modified versions of the software inside them, although the manufacturer +can do so. This is fundamentally incompatible with the aim of +protecting users' freedom to change the software. The systematic +pattern of such abuse occurs in the area of products for individuals to +use, which is precisely where it is most unacceptable. Therefore, we +have designed this version of the GPL to prohibit the practice for those +products. If such problems arise substantially in other domains, we +stand ready to extend this provision to those domains in future versions +of the GPL, as needed to protect the freedom of users. + +Finally, every program is threatened constantly by software patents. +States should not allow patents to restrict development and use of +software on general-purpose computers, but in those that do, we wish to +avoid the special danger that patents applied to a free program could +make it effectively proprietary. To prevent this, the GPL assures that +patents cannot be used to render the program non-free. + +The precise terms and conditions for copying, distribution and +modification follow. + +TERMS AND CONDITIONS + +0. Definitions. + +"This License" refers to version 3 of the GNU General Public License. + +"Copyright" also means copyright-like laws that apply to other kinds of +works, such as semiconductor masks. + +"The Program" refers to any copyrightable work licensed under this +License. Each licensee is addressed as "you". "Licensees" and +"recipients" may be individuals or organizations. + +To "modify" a work means to copy from or adapt all or part of the work +in a fashion requiring copyright permission, other than the making of an +exact copy. The resulting work is called a "modified version" of the +earlier work or a work "based on" the earlier work. + +A "covered work" means either the unmodified Program or a work based +on the Program. + +To "propagate" a work means to do anything with it that, without +permission, would make you directly or secondarily liable for +infringement under applicable copyright law, except executing it on a +computer or modifying a private copy. Propagation includes copying, +distribution (with or without modification), making available to the +public, and in some countries other activities as well. + +To "convey" a work means any kind of propagation that enables other +parties to make or receive copies. Mere interaction with a user through +a computer network, with no transfer of a copy, is not conveying. + +An interactive user interface displays "Appropriate Legal Notices" +to the extent that it includes a convenient and prominently visible +feature that (1) displays an appropriate copyright notice, and (2) +tells the user that there is no warranty for the work (except to the +extent that warranties are provided), that licensees may convey the +work under this License, and how to view a copy of this License. If +the interface presents a list of user commands or options, such as a +menu, a prominent item in the list meets this criterion. + +1. Source Code. + +The "source code" for a work means the preferred form of the work +for making modifications to it. "Object code" means any non-source +form of a work. + +A "Standard Interface" means an interface that either is an official +standard defined by a recognized standards body, or, in the case of +interfaces specified for a particular programming language, one that +is widely used among developers working in that language. + +The "System Libraries" of an executable work include anything, other +than the work as a whole, that (a) is included in the normal form of +packaging a Major Component, but which is not part of that Major +Component, and (b) serves only to enable use of the work with that +Major Component, or to implement a Standard Interface for which an +implementation is available to the public in source code form. A +"Major Component", in this context, means a major essential component +(kernel, window system, and so on) of the specific operating system +(if any) on which the executable work runs, or a compiler used to +produce the work, or an object code interpreter used to run it. + +The "Corresponding Source" for a work in object code form means all +the source code needed to generate, install, and (for an executable +work) run the object code and to modify the work, including scripts to +control those activities. However, it does not include the work's +System Libraries, or general-purpose tools or generally available free +programs which are used unmodified in performing those activities but +which are not part of the work. For example, Corresponding Source +includes interface definition files associated with source files for +the work, and the source code for shared libraries and dynamically +linked subprograms that the work is specifically designed to require, +such as by intimate data communication or control flow between those +subprograms and other parts of the work. + +The Corresponding Source need not include anything that users +can regenerate automatically from other parts of the Corresponding +Source. + +The Corresponding Source for a work in source code form is that +same work. + +2. Basic Permissions. + +All rights granted under this License are granted for the term of +copyright on the Program, and are irrevocable provided the stated +conditions are met. This License explicitly affirms your unlimited +permission to run the unmodified Program. The output from running a +covered work is covered by this License only if the output, given its +content, constitutes a covered work. This License acknowledges your +rights of fair use or other equivalent, as provided by copyright law. + +You may make, run and propagate covered works that you do not +convey, without conditions so long as your license otherwise remains +in force. You may convey covered works to others for the sole purpose +of having them make modifications exclusively for you, or provide you +with facilities for running those works, provided that you comply with +the terms of this License in conveying all material for which you do +not control copyright. Those thus making or running the covered works +for you must do so exclusively on your behalf, under your direction +and control, on terms that prohibit them from making any copies of +your copyrighted material outside their relationship with you. + +Conveying under any other circumstances is permitted solely under +the conditions stated below. Sublicensing is not allowed; section 10 +makes it unnecessary. + +3. Protecting Users' Legal Rights From Anti-Circumvention Law. + +No covered work shall be deemed part of an effective technological +measure under any applicable law fulfilling obligations under article +11 of the WIPO copyright treaty adopted on 20 December 1996, or +similar laws prohibiting or restricting circumvention of such +measures. + +When you convey a covered work, you waive any legal power to forbid +circumvention of technological measures to the extent such circumvention +is effected by exercising rights under this License with respect to +the covered work, and you disclaim any intention to limit operation or +modification of the work as a means of enforcing, against the work's +users, your or third parties' legal rights to forbid circumvention of +technological measures. + +4. Conveying Verbatim Copies. + +You may convey verbatim copies of the Program's source code as you +receive it, in any medium, provided that you conspicuously and +appropriately publish on each copy an appropriate copyright notice; +keep intact all notices stating that this License and any +non-permissive terms added in accord with section 7 apply to the code; +keep intact all notices of the absence of any warranty; and give all +recipients a copy of this License along with the Program. + +You may charge any price or no price for each copy that you convey, +and you may offer support or warranty protection for a fee. + +5. Conveying Modified Source Versions. + +You may convey a work based on the Program, or the modifications to +produce it from the Program, in the form of source code under the +terms of section 4, provided that you also meet all of these conditions: + +a) The work must carry prominent notices stating that you modified +it, and giving a relevant date. + +b) The work must carry prominent notices stating that it is +released under this License and any conditions added under section +7. This requirement modifies the requirement in section 4 to +"keep intact all notices". + +c) You must license the entire work, as a whole, under this +License to anyone who comes into possession of a copy. This +License will therefore apply, along with any applicable section 7 +additional terms, to the whole of the work, and all its parts, +regardless of how they are packaged. This License gives no +permission to license the work in any other way, but it does not +invalidate such permission if you have separately received it. + +d) If the work has interactive user interfaces, each must display +Appropriate Legal Notices; however, if the Program has interactive +interfaces that do not display Appropriate Legal Notices, your +work need not make them do so. + +A compilation of a covered work with other separate and independent +works, which are not by their nature extensions of the covered work, +and which are not combined with it such as to form a larger program, +in or on a volume of a storage or distribution medium, is called an +"aggregate" if the compilation and its resulting copyright are not +used to limit the access or legal rights of the compilation's users +beyond what the individual works permit. Inclusion of a covered work +in an aggregate does not cause this License to apply to the other +parts of the aggregate. + +6. Conveying Non-Source Forms. + +You may convey a covered work in object code form under the terms +of sections 4 and 5, provided that you also convey the +machine-readable Corresponding Source under the terms of this License, +in one of these ways: + +a) Convey the object code in, or embodied in, a physical product +(including a physical distribution medium), accompanied by the +Corresponding Source fixed on a durable physical medium +customarily used for software interchange. + +b) Convey the object code in, or embodied in, a physical product +(including a physical distribution medium), accompanied by a +written offer, valid for at least three years and valid for as +long as you offer spare parts or customer support for that product +model, to give anyone who possesses the object code either (1) a +copy of the Corresponding Source for all the software in the +product that is covered by this License, on a durable physical +medium customarily used for software interchange, for a price no +more than your reasonable cost of physically performing this +conveying of source, or (2) access to copy the +Corresponding Source from a network server at no charge. + +c) Convey individual copies of the object code with a copy of the +written offer to provide the Corresponding Source. This +alternative is allowed only occasionally and noncommercially, and +only if you received the object code with such an offer, in accord +with subsection 6b. + +d) Convey the object code by offering access from a designated +place (gratis or for a charge), and offer equivalent access to the +Corresponding Source in the same way through the same place at no +further charge. You need not require recipients to copy the +Corresponding Source along with the object code. If the place to +copy the object code is a network server, the Corresponding Source +may be on a different server (operated by you or a third party) +that supports equivalent copying facilities, provided you maintain +clear directions next to the object code saying where to find the +Corresponding Source. Regardless of what server hosts the +Corresponding Source, you remain obligated to ensure that it is +available for as long as needed to satisfy these requirements. + +e) Convey the object code using peer-to-peer transmission, provided +you inform other peers where the object code and Corresponding +Source of the work are being offered to the general public at no +charge under subsection 6d. + +A separable portion of the object code, whose source code is excluded +from the Corresponding Source as a System Library, need not be +included in conveying the object code work. + +A "User Product" is either (1) a "consumer product", which means any +tangible personal property which is normally used for personal, family, +or household purposes, or (2) anything designed or sold for incorporation +into a dwelling. In determining whether a product is a consumer product, +doubtful cases shall be resolved in favor of coverage. For a particular +product received by a particular user, "normally used" refers to a +typical or common use of that class of product, regardless of the status +of the particular user or of the way in which the particular user +actually uses, or expects or is expected to use, the product. A product +is a consumer product regardless of whether the product has substantial +commercial, industrial or non-consumer uses, unless such uses represent +the only significant mode of use of the product. + +"Installation Information" for a User Product means any methods, +procedures, authorization keys, or other information required to install +and execute modified versions of a covered work in that User Product from +a modified version of its Corresponding Source. The information must +suffice to ensure that the continued functioning of the modified object +code is in no case prevented or interfered with solely because +modification has been made. + +If you convey an object code work under this section in, or with, or +specifically for use in, a User Product, and the conveying occurs as +part of a transaction in which the right of possession and use of the +User Product is transferred to the recipient in perpetuity or for a +fixed term (regardless of how the transaction is characterized), the +Corresponding Source conveyed under this section must be accompanied +by the Installation Information. But this requirement does not apply +if neither you nor any third party retains the ability to install +modified object code on the User Product (for example, the work has +been installed in ROM). + +The requirement to provide Installation Information does not include a +requirement to continue to provide support service, warranty, or updates +for a work that has been modified or installed by the recipient, or for +the User Product in which it has been modified or installed. Access to a +network may be denied when the modification itself materially and +adversely affects the operation of the network or violates the rules and +protocols for communication across the network. + +Corresponding Source conveyed, and Installation Information provided, +in accord with this section must be in a format that is publicly +documented (and with an implementation available to the public in +source code form), and must require no special password or key for +unpacking, reading or copying. + +7. Additional Terms. + +"Additional permissions" are terms that supplement the terms of this +License by making exceptions from one or more of its conditions. +Additional permissions that are applicable to the entire Program shall +be treated as though they were included in this License, to the extent +that they are valid under applicable law. If additional permissions +apply only to part of the Program, that part may be used separately +under those permissions, but the entire Program remains governed by +this License without regard to the additional permissions. + +When you convey a copy of a covered work, you may at your option +remove any additional permissions from that copy, or from any part of +it. (Additional permissions may be written to require their own +removal in certain cases when you modify the work.) You may place +additional permissions on material, added by you to a covered work, +for which you have or can give appropriate copyright permission. + +Notwithstanding any other provision of this License, for material you +add to a covered work, you may (if authorized by the copyright holders of +that material) supplement the terms of this License with terms: + +a) Disclaiming warranty or limiting liability differently from the +terms of sections 15 and 16 of this License; or + +b) Requiring preservation of specified reasonable legal notices or +author attributions in that material or in the Appropriate Legal +Notices displayed by works containing it; or + +c) Prohibiting misrepresentation of the origin of that material, or +requiring that modified versions of such material be marked in +reasonable ways as different from the original version; or + +d) Limiting the use for publicity purposes of names of licensors or +authors of the material; or + +e) Declining to grant rights under trademark law for use of some +trade names, trademarks, or service marks; or + +f) Requiring indemnification of licensors and authors of that +material by anyone who conveys the material (or modified versions of +it) with contractual assumptions of liability to the recipient, for +any liability that these contractual assumptions directly impose on +those licensors and authors. + +All other non-permissive additional terms are considered "further +restrictions" within the meaning of section 10. If the Program as you +received it, or any part of it, contains a notice stating that it is +governed by this License along with a term that is a further +restriction, you may remove that term. If a license document contains +a further restriction but permits relicensing or conveying under this +License, you may add to a covered work material governed by the terms +of that license document, provided that the further restriction does +not survive such relicensing or conveying. + +If you add terms to a covered work in accord with this section, you +must place, in the relevant source files, a statement of the +additional terms that apply to those files, or a notice indicating +where to find the applicable terms. + +Additional terms, permissive or non-permissive, may be stated in the +form of a separately written license, or stated as exceptions; +the above requirements apply either way. + +8. Termination. + +You may not propagate or modify a covered work except as expressly +provided under this License. Any attempt otherwise to propagate or +modify it is void, and will automatically terminate your rights under +this License (including any patent licenses granted under the third +paragraph of section 11). + +However, if you cease all violation of this License, then your +license from a particular copyright holder is reinstated (a) +provisionally, unless and until the copyright holder explicitly and +finally terminates your license, and (b) permanently, if the copyright +holder fails to notify you of the violation by some reasonable means +prior to 60 days after the cessation. + +Moreover, your license from a particular copyright holder is +reinstated permanently if the copyright holder notifies you of the +violation by some reasonable means, this is the first time you have +received notice of violation of this License (for any work) from that +copyright holder, and you cure the violation prior to 30 days after +your receipt of the notice. + +Termination of your rights under this section does not terminate the +licenses of parties who have received copies or rights from you under +this License. If your rights have been terminated and not permanently +reinstated, you do not qualify to receive new licenses for the same +material under section 10. + +9. Acceptance Not Required for Having Copies. + +You are not required to accept this License in order to receive or +run a copy of the Program. Ancillary propagation of a covered work +occurring solely as a consequence of using peer-to-peer transmission +to receive a copy likewise does not require acceptance. However, +nothing other than this License grants you permission to propagate or +modify any covered work. These actions infringe copyright if you do +not accept this License. Therefore, by modifying or propagating a +covered work, you indicate your acceptance of this License to do so. + +10. Automatic Licensing of Downstream Recipients. + +Each time you convey a covered work, the recipient automatically +receives a license from the original licensors, to run, modify and +propagate that work, subject to this License. You are not responsible +for enforcing compliance by third parties with this License. + +An "entity transaction" is a transaction transferring control of an +organization, or substantially all assets of one, or subdividing an +organization, or merging organizations. If propagation of a covered +work results from an entity transaction, each party to that +transaction who receives a copy of the work also receives whatever +licenses to the work the party's predecessor in interest had or could +give under the previous paragraph, plus a right to possession of the +Corresponding Source of the work from the predecessor in interest, if +the predecessor has it or can get it with reasonable efforts. + +You may not impose any further restrictions on the exercise of the +rights granted or affirmed under this License. For example, you may +not impose a license fee, royalty, or other charge for exercise of +rights granted under this License, and you may not initiate litigation +(including a cross-claim or counterclaim in a lawsuit) alleging that +any patent claim is infringed by making, using, selling, offering for +sale, or importing the Program or any portion of it. + +11. Patents. + +A "contributor" is a copyright holder who authorizes use under this +License of the Program or a work on which the Program is based. The +work thus licensed is called the contributor's "contributor version". + +A contributor's "essential patent claims" are all patent claims +owned or controlled by the contributor, whether already acquired or +hereafter acquired, that would be infringed by some manner, permitted +by this License, of making, using, or selling its contributor version, +but do not include claims that would be infringed only as a +consequence of further modification of the contributor version. For +purposes of this definition, "control" includes the right to grant +patent sublicenses in a manner consistent with the requirements of +this License. + +Each contributor grants you a non-exclusive, worldwide, royalty-free +patent license under the contributor's essential patent claims, to +make, use, sell, offer for sale, import and otherwise run, modify and +propagate the contents of its contributor version. + +In the following three paragraphs, a "patent license" is any express +agreement or commitment, however denominated, not to enforce a patent +(such as an express permission to practice a patent or covenant not to +sue for patent infringement). To "grant" such a patent license to a +party means to make such an agreement or commitment not to enforce a +patent against the party. + +If you convey a covered work, knowingly relying on a patent license, +and the Corresponding Source of the work is not available for anyone +to copy, free of charge and under the terms of this License, through a +publicly available network server or other readily accessible means, +then you must either (1) cause the Corresponding Source to be so +available, or (2) arrange to deprive yourself of the benefit of the +patent license for this particular work, or (3) arrange, in a manner +consistent with the requirements of this License, to extend the patent +license to downstream recipients. "Knowingly relying" means you have +actual knowledge that, but for the patent license, your conveying the +covered work in a country, or your recipient's use of the covered work +in a country, would infringe one or more identifiable patents in that +country that you have reason to believe are valid. + +If, pursuant to or in connection with a single transaction or +arrangement, you convey, or propagate by procuring conveyance of, a +covered work, and grant a patent license to some of the parties +receiving the covered work authorizing them to use, propagate, modify +or convey a specific copy of the covered work, then the patent license +you grant is automatically extended to all recipients of the covered +work and works based on it. + +A patent license is "discriminatory" if it does not include within +the scope of its coverage, prohibits the exercise of, or is +conditioned on the non-exercise of one or more of the rights that are +specifically granted under this License. You may not convey a covered +work if you are a party to an arrangement with a third party that is +in the business of distributing software, under which you make payment +to the third party based on the extent of your activity of conveying +the work, and under which the third party grants, to any of the +parties who would receive the covered work from you, a discriminatory +patent license (a) in connection with copies of the covered work +conveyed by you (or copies made from those copies), or (b) primarily +for and in connection with specific products or compilations that +contain the covered work, unless you entered into that arrangement, +or that patent license was granted, prior to 28 March 2007. + +Nothing in this License shall be construed as excluding or limiting +any implied license or other defenses to infringement that may +otherwise be available to you under applicable patent law. + +12. No Surrender of Others' Freedom. + +If conditions are imposed on you (whether by court order, agreement or +otherwise) that contradict the conditions of this License, they do not +excuse you from the conditions of this License. If you cannot convey a +covered work so as to satisfy simultaneously your obligations under this +License and any other pertinent obligations, then as a consequence you may +not convey it at all. For example, if you agree to terms that obligate you +to collect a royalty for further conveying from those to whom you convey +the Program, the only way you could satisfy both those terms and this +License would be to refrain entirely from conveying the Program. + +13. Use with the GNU Affero General Public License. + +Notwithstanding any other provision of this License, you have +permission to link or combine any covered work with a work licensed +under version 3 of the GNU Affero General Public License into a single +combined work, and to convey the resulting work. The terms of this +License will continue to apply to the part which is the covered work, +but the special requirements of the GNU Affero General Public License, +section 13, concerning interaction through a network will apply to the +combination as such. + +14. Revised Versions of this License. + +The Free Software Foundation may publish revised and/or new versions of +the GNU General Public License from time to time. Such new versions will +be similar in spirit to the present version, but may differ in detail to +address new problems or concerns. + +Each version is given a distinguishing version number. If the +Program specifies that a certain numbered version of the GNU General +Public License "or any later version" applies to it, you have the +option of following the terms and conditions either of that numbered +version or of any later version published by the Free Software +Foundation. If the Program does not specify a version number of the +GNU General Public License, you may choose any version ever published +by the Free Software Foundation. + +If the Program specifies that a proxy can decide which future +versions of the GNU General Public License can be used, that proxy's +public statement of acceptance of a version permanently authorizes you +to choose that version for the Program. + +Later license versions may give you additional or different +permissions. However, no additional obligations are imposed on any +author or copyright holder as a result of your choosing to follow a +later version. + +15. Disclaimer of Warranty. + +THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY +APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT +HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY +OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, +THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR +PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM +IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF +ALL NECESSARY SERVICING, REPAIR OR CORRECTION. + +16. Limitation of Liability. + +IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING +WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS +THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY +GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE +USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF +DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD +PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), +EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF +SUCH DAMAGES. + +17. Interpretation of Sections 15 and 16. + +If the disclaimer of warranty and limitation of liability provided +above cannot be given local legal effect according to their terms, +reviewing courts shall apply local law that most closely approximates +an absolute waiver of all civil liability in connection with the +Program, unless a warranty or assumption of liability accompanies a +copy of the Program in return for a fee. + +END OF TERMS AND CONDITIONS + +How to Apply These Terms to Your New Programs + +If you develop a new program, and you want it to be of the greatest +possible use to the public, the best way to achieve this is to make it +free software which everyone can redistribute and change under these terms. + +To do so, attach the following notices to the program. It is safest +to attach them to the start of each source file to most effectively +state the exclusion of warranty; and each file should have at least +the "copyright" line and a pointer to where the full notice is found. + + +Copyright (C) + +This program is free software: you can redistribute it and/or modify +it under the terms of the GNU General Public License as published by +the Free Software Foundation, either version 3 of the License, or +(at your option) any later version. + +This program is distributed in the hope that it will be useful, +but WITHOUT ANY WARRANTY; without even the implied warranty of +MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +GNU General Public License for more details. + +You should have received a copy of the GNU General Public License +along with this program. If not, see . + +Also add information on how to contact you by electronic and paper mail. + +If the program does terminal interaction, make it output a short +notice like this when it starts in an interactive mode: + + Copyright (C) +This program comes with ABSOLUTELY NO WARRANTY; for details type `show w'. +This is free software, and you are welcome to redistribute it +under certain conditions; type `show c' for details. + +The hypothetical commands `show w' and `show c' should show the appropriate +parts of the General Public License. Of course, your program's commands +might be different; for a GUI interface, you would use an "about box". + +You should also get your employer (if you work as a programmer) or school, +if any, to sign a "copyright disclaimer" for the program, if necessary. +For more information on this, and how to apply and follow the GNU GPL, see +. + +The GNU General Public License does not permit incorporating your program +into proprietary programs. If your program is a subroutine library, you +may consider it more useful to permit linking proprietary applications with +the library. If this is what you want to do, use the GNU Lesser General +Public License instead of this License. But first, please read +. diff --git a/ThirdParty/MartinOMEMO/Package.swift b/ThirdParty/MartinOMEMO/Package.swift new file mode 100644 index 0000000..c0c5c71 --- /dev/null +++ b/ThirdParty/MartinOMEMO/Package.swift @@ -0,0 +1,31 @@ +// swift-tools-version:5.6 +// The swift-tools-version declares the minimum version of Swift required to build this package. + +import PackageDescription + +let package = Package( + name: "MartinOMEMO", + platforms: [.iOS(.v13), .macOS(.v10_15)], + products: [ + // Products define the executables and libraries produced by a package, and make them visible to other packages. + .library( + name: "MartinOMEMO", + targets: ["MartinOMEMO"]), + ], + dependencies: [ + // Dependencies declare other packages that this package depends on. + // .package(url: /* package url */, from: "1.0.0"), + .package(url: "https://github.com/tigase/Martin", from: "3.2.4"), + .package(url: "https://github.com/tigase/libsignal", from: "1.0.0") + ], + targets: [ + // Targets are the basic building blocks of a package. A target can define a module or a test suite. + // Targets can depend on other targets in this package, and on products in packages which this package depends on. + .target( + name: "MartinOMEMO", + dependencies: ["Martin", "libsignal"]), + .testTarget( + name: "MartinOMEMOTests", + dependencies: ["MartinOMEMO"]), + ] +) diff --git a/ThirdParty/MartinOMEMO/README.md b/ThirdParty/MartinOMEMO/README.md new file mode 100644 index 0000000..247de63 --- /dev/null +++ b/ThirdParty/MartinOMEMO/README.md @@ -0,0 +1,7 @@ +

+ Martin - OMEMO support +

+ +# What it is + +Martin is an [XMPP](https://xmpp.org) client library written in a [Swift](https://swift.org) programming language. This project is an extension for that library providing support for OMEMO extension providing multi-end message and object encryption. diff --git a/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/Identity.swift b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/Identity.swift new file mode 100644 index 0000000..6314ede --- /dev/null +++ b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/Identity.swift @@ -0,0 +1,40 @@ +// +// Identity.swift +// +// TigaseSwift OMEMO +// Copyright (C) 2019 "Tigase, Inc." +// +// This program is free software: you can redistribute it and/or modify +// it under the terms of the GNU General Public License as published by +// the Free Software Foundation, either version 3 of the License, or +// (at your option) any later version. +// +// This program is distributed in the hope that it will be useful, +// but WITHOUT ANY WARRANTY; without even the implied warranty of +// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +// GNU General Public License for more details. +// +// You should have received a copy of the GNU General Public License +// along with this program. Look for COPYING file in the top folder. +// If not, see https://www.gnu.org/licenses/. +// + +import Foundation + +public class Identity { + + public let address: SignalAddress; + public let status: IdentityStatus; + public let fingerprint: String; + public let key: Data; + public let own: Bool; + + public init(address: SignalAddress, status: IdentityStatus, fingerprint: String, key: Data, own: Bool) { + self.address = address; + self.status = status; + self.fingerprint = fingerprint; + self.key = key; + self.own = own; + } + +} diff --git a/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/IdentityStatus.swift b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/IdentityStatus.swift new file mode 100644 index 0000000..7487684 --- /dev/null +++ b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/IdentityStatus.swift @@ -0,0 +1,108 @@ +// +// IdentityStatus.swift +// +// TigaseSwift OMEMO +// Copyright (C) 2019 "Tigase, Inc." +// +// This program is free software: you can redistribute it and/or modify +// it under the terms of the GNU General Public License as published by +// the Free Software Foundation, either version 3 of the License, or +// (at your option) any later version. +// +// This program is distributed in the hope that it will be useful, +// but WITHOUT ANY WARRANTY; without even the implied warranty of +// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +// GNU General Public License for more details. +// +// You should have received a copy of the GNU General Public License +// along with this program. Look for COPYING file in the top folder. +// If not, see https://www.gnu.org/licenses/. +// + +import Foundation + +public enum IdentityStatus: Int { + case compromisedActive = -2 + case compromisedInactive = -1 + case undecidedActive = 0 + case undecidedInactive = 1 + case trustedActive = 2 + case trustedInactive = 3 + case verifiedActive = 4 + case verifiedInactive = 5 + + public var trust: Trust { + switch self { + case .compromisedActive, .compromisedInactive: + return .compromised; + case .undecidedActive, .undecidedInactive: + return .undecided; + case .trustedActive, .trustedInactive: + return .trusted; + case .verifiedActive, .verifiedInactive: + return .verified; + } + } + + public var isActive: Bool { + switch self { + case .compromisedActive, .undecidedActive, .trustedActive, .verifiedActive: + return true; + case .compromisedInactive, .undecidedInactive, .trustedInactive, .verifiedInactive: + return false; + } + } + + public func toActive() -> IdentityStatus { + guard !self.isActive else { + return self; + } + + return make(active: true, trust: self.trust); + } + + public func toInactive() -> IdentityStatus { + guard self.isActive else { + return self; + } + + return make(active: false, trust: self.trust); + } + + public func toTrust(_ trust: Trust) -> IdentityStatus { + return make(active: isActive, trust: trust); + } + + public func make(active: Bool, trust: Trust) -> IdentityStatus { + if active { + switch trust { + case .compromised: + return .compromisedActive; + case .undecided: + return .undecidedActive; + case .trusted: + return .trustedActive; + case .verified: + return .verifiedActive; + } + } else { + switch trust { + case .compromised: + return .compromisedInactive; + case .undecided: + return .undecidedInactive; + case .trusted: + return .trustedInactive; + case .verified: + return .verifiedInactive; + } + } + } +} + +public enum Trust { + case compromised + case undecided + case trusted + case verified +} diff --git a/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/OMEMOModule.swift b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/OMEMOModule.swift new file mode 100644 index 0000000..1921289 --- /dev/null +++ b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/OMEMOModule.swift @@ -0,0 +1,1101 @@ +// +// OMEMOModule.swift +// +// TigaseSwift OMEMO +// Copyright (C) 2019 "Tigase, Inc." +// +// This program is free software: you can redistribute it and/or modify +// it under the terms of the GNU General Public License as published by +// the Free Software Foundation, either version 3 of the License, or +// (at your option) any later version. +// +// This program is distributed in the hope that it will be useful, +// but WITHOUT ANY WARRANTY; without even the implied warranty of +// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +// GNU General Public License for more details. +// +// You should have received a copy of the GNU General Public License +// along with this program. Look for COPYING file in the top folder. +// If not, see https://www.gnu.org/licenses/. +// + +import Foundation +import Martin +import libsignal +import Combine + +extension XmppModuleIdentifier { + public static var omemo: XmppModuleIdentifier { + return OMEMOModule.IDENTIFIER; + } +} + +struct KeyDecryptionResult { + let result: Result; + let address: SignalAddress; + let isPrekey: Bool; + + var isSuccess: Bool { + switch result { + case .success(_): + return true; + case .failure(_): + return false; + } + } +} + +open class OMEMOModule: AbstractPEPModule, XmppModule, Resetable { + + public static let ID = "omemo"; + public static let IDENTIFIER = XmppModuleIdentifier(); + public static let XMLNS = "eu.siacs.conversations.axolotl"; + public static let DEVICES_LIST_NODE = "eu.siacs.conversations.axolotl.devicelist"; + + public let id: String = ID; + + // Default body to set for OMEMO encrypted messages + open var defaultBody: String? = "I sent you an OMEMO encrypted message but your client doesn’t seem to support that."; + + public override var isPepAvailable: Bool { + didSet { + if isPepAvailable { + publishDeviceBundleIfNeeded() { + self.publishDeviceIdIfNeeded(); + if let context = self.context { + context.sessionObject.setProperty(OMEMOModule.XMLNS + ".bundle", value: true); + } + } + } + } + } + + public let criteria = Criteria.empty(); + + public let features: [String] = [OMEMOModule.DEVICES_LIST_NODE + "+notify"]; + + public let engine: AES_GCM_Engine; + public let signalContext: SignalContext; + public let storage: SignalStorage; + fileprivate let devicesQueue: DispatchQueue = DispatchQueue(label: "omemo_devices_dispatch_queue"); + fileprivate var devices: [BareJID: [Int32]] = [:]; + fileprivate var devicesFetchError: [BareJID: [Int32]] = [:]; + private var ownBrokenDevices: [Int32] = []; + + @Published + public private(set) var isReady: Bool = false; + + public let activeDevicesPublisher = PassthroughSubject(); + + public func isAvailable(for jid: BareJID) -> Bool { + return (!(self.devicesQueue.sync(execute: { self.devices[jid] })?.isEmpty ?? true)) || !self.storage.sessionStore.allDevices(for: jid.stringValue, activeAndTrusted: true).isEmpty; + } + + public init(aesGCMEngine: AES_GCM_Engine, signalContext: SignalContext, signalStorage: SignalStorage) { + self.signalContext = signalContext; + self.storage = signalStorage; + self.engine = aesGCMEngine; + super.init(); + } + + public func reset(scopes: Set) { + if scopes.contains(.session) { + self.isReady = false; + self.devicesQueue.async { + self.devices.removeAll(); + } + } + } + + public func regenerateKeys(wipe: Bool = false) -> Bool { + let regenerated = self.storage.regenerateKeys(wipe: wipe); + if regenerated && isPepAvailable { + self.publishDeviceBundle(currentBundle: nil) { + self.publishDeviceIdIfNeeded(); + } + } + return regenerated; + } + + public func devices(for jid: BareJID) -> [Int32]? { + guard let devices = self.devicesQueue.sync(execute: { self.devices[jid] }) else { + return nil; + } + guard let failed = self.devicesFetchError[jid] else { + return devices; + } + return devices.filter({ (deviceId) -> Bool in + return !failed.contains(deviceId); + }); + } + + + public func process(stanza: Stanza) throws { + throw ErrorCondition.feature_not_implemented; + } + + public func decode(message: Message, serverMsgId: String? = nil) -> DecryptionResult { + guard let from = message.from?.bareJid else { + return .failure(.invalidArgument); + } + return self.decode(message: message, from: from, serverMsgId: serverMsgId); + } + + + public func decode(message: Message, from: BareJID, serverMsgId: String? = nil) -> DecryptionResult { + guard let context = context else { + return .failure(.unknown); + } + + guard let encryptedEl = message.findChild(name: "encrypted", xmlns: OMEMOModule.XMLNS) else { + return .failure(SignalError.notEncrypted); + } + + guard let headerEl = encryptedEl.findChild(name: "header"), let sid = UInt32(headerEl.getAttribute("sid") ?? "") else { + return .failure(.invalidArgument); + } + + let localDeviceIdStr = String(signalContext.storage.identityKeyStore.localRegistrationId()); + + guard headerEl.findChild(where: { (el) -> Bool in + return el.name == "key" && el.getAttribute("rid") == localDeviceIdStr; + }) != nil else { + guard context.userBareJid != from || sid != signalContext.storage.identityKeyStore.localRegistrationId() else { + return .failure(.duplicateMessage); + } + guard encryptedEl.findChild(name: "payload") != nil else { + return .failure(.duplicateMessage); + } + return .failure(.invalidMessage); + } + + let possibleKeys = headerEl.getChildren(where: { (el) -> Bool in + return el.name == "key" && el.getAttribute("rid") == localDeviceIdStr; + }).map({ (keyEl) -> KeyDecryptionResult in + let prekey = "true" == keyEl.getAttribute("prekey") || keyEl.getAttribute("prekey") == "1"; + let address = SignalAddress(name: from.stringValue, deviceId: Int32(bitPattern: sid)); + guard let keyElValue = keyEl.value, let key = Data(base64Encoded: keyElValue) else { + return .init(result: .failure(.invalidArgument), address: address, isPrekey: prekey); + } + guard let session = SignalSessionCipher(withAddress: address, andContext: self.signalContext) else { + return .init(result: .failure(SignalError.noMemory), address: address, isPrekey: prekey); + } + return .init(result: session.decrypt(key: SignalSessionCipher.Key(key: key,deviceId: Int32(bitPattern: sid), prekey: prekey)), address: address, isPrekey: prekey); + }); + + guard let possibleKey = possibleKeys.first(where: { $0.isSuccess }) else { + if let key = possibleKeys.first { + switch key.result { + case .failure(let error): + switch error { + case .noSession, .invalidMessage: + if serverMsgId != nil { + if !postponeHealing(for: message.type == .groupchat ? message.from?.bareJid : nil, address: key.address) { + self.buildSession(forAddress: key.address, completionHandler: { + self.completeSession(forAddress: key.address); + }); + } + } + default: + break; + } + return .failure(error); + case .success(_): + return .failure(.unknown); + } + } else { + guard encryptedEl.findChild(name: "payload") != nil else { + return .failure(.duplicateMessage); + } + return .failure(.invalidMessage); + } + } + + switch possibleKey.result { + case .failure(let error): + return .failure(error); + case .success(let data): + message.removeChild(encryptedEl); + + let address = possibleKey.address; + let prekey = possibleKey.isPrekey; + var decodedKey = data; + + if prekey { + // pre key was removed so we need to republish the bundle! + if !postponeSession(for: message.type == .groupchat ? message.from?.bareJid : nil, address: address) { + if self.storage.preKeyStore.flushDeletedPreKeys() { + self.publishDeviceBundleIfNeeded(completionHandler: nil); + } + } + } + + var auth: Data? = nil; + if decodedKey.count >= 32 { + auth = decodedKey.subdata(in: 16..)->Void) { + guard let jid = message.to?.bareJid else { + completionHandler(.failure(.noDestination)); + return; + } + + encode(message: message, for: [jid], withStoreHint: withStoreHint, completionHandler: completionHandler); + } + + public func addresses(for jids: [BareJID], completionHandler: @escaping(Result<[SignalAddress],SignalError>)->Void) { + guard let pubsubModule: PubSubModule = context?.module(.pubsub) else { + completionHandler(.failure(.unknown)); + return; + } + let group = DispatchGroup(); + var addresses: [SignalAddress] = []; + for jid in jids { + if let devices = self.devices(for: jid) { + addresses.append(contentsOf: devices.map({ SignalAddress(name: jid.stringValue, deviceId: $0) })); + for address in addresses.filter({ !self.storage.sessionStore.containsSessionRecord(forAddress: $0) }) { + group.enter(); + self.buildSession(forAddress: address, completionHandler: { + group.leave(); + }) + } + } else { + group.enter(); + pubsubModule.retrieveItems(from: jid, for: OMEMOModule.DEVICES_LIST_NODE, limit: .lastItems(1), completionHandler: { result in + switch result { + case .success(let items): + print("got published devices from:", jid, ", ", items.items.first as Any); + if let listEl = items.items.first?.payload, listEl.name == "list" && listEl.xmlns == "eu.siacs.conversations.axolotl" { + let knownActiveDevices: [Int32] = listEl.mapChildren(transform: { $0.getAttribute("id") }).compactMap({ Int32($0) }); + + + let allDevices = self.storage.sessionStore.allDevices(for: jid.stringValue, activeAndTrusted: true); + allDevices.filter { (id) -> Bool in + return !knownActiveDevices.contains(id); + }.forEach { (deviceId) in + _ = self.storage.identityKeyStore.setStatus(active: false, forIdentity: SignalAddress(name: jid.stringValue, deviceId: deviceId)); + } + + knownActiveDevices.filter { (id) -> Bool in + return !allDevices.contains(id); + }.forEach { (deviceId) in + // TODO: we should enable this device key if we have its identity! + _ = self.storage.identityKeyStore.setStatus(active: true, forIdentity: SignalAddress(name: jid.stringValue, deviceId: deviceId)); + } + addresses.append(contentsOf: knownActiveDevices.map({ SignalAddress(name: jid.stringValue, deviceId: $0) })); + } + + // should we start fetching sessions here? without waiting for all JIDs to return? should improve performance + for address in addresses.filter({ !self.storage.sessionStore.containsSessionRecord(forAddress: $0) }) { + group.enter(); + self.buildSession(forAddress: address, completionHandler: { + group.leave(); + }) + } + case .failure(_): + break; + } + group.leave(); + }) + } + } + group.notify(queue: DispatchQueue.main, execute: { + // we finished address retrieval.. + completionHandler(.success(addresses)); + }) + } + + public func encode(message: Message, for jids: [BareJID], withStoreHint: Bool = true, completionHandler: @escaping (EncryptionResult)->Void) { + + addresses(for: jids, completionHandler: { result in + switch result { + case .failure(let error): + completionHandler(.failure(error)); + case .success(let addresses): + if addresses.isEmpty { + completionHandler(.failure(.noSession)); + } else { + self.encode(message: message, forAddresses: addresses, withStoreHint: withStoreHint, completionHandler: completionHandler); + } + } + + }) + } + + public func encode(message: Message, forAddresses addresses: [SignalAddress], withStoreHint: Bool = true, completionHandler: @escaping (EncryptionResult)->Void) { + + let result = self._encode(message: message, for: addresses); + + switch result { + case .successMessage(let encodedMessage, _): + encodedMessage.body = self.defaultBody; + if withStoreHint { + encodedMessage.addChild(Element(name: "store", xmlns: "urn:xmpp:hints")); + } + default: + break; + } + + completionHandler(result); + } + + public func decryptFile(url localUrl: URL, fragment: String) -> Result { + guard let data = try? Data(contentsOf: localUrl) else { + return .failure(ErrorCondition.item_not_found); + } + + return decryptFile(data: data, fragment: fragment); + } + + public func decryptFile(data inData: Data, fragment: String) -> Result { + guard fragment.count % 2 == 0 && fragment.count > 64 && inData.count > 32 else { + return .failure(.not_acceptable); + } + + let fragmentData = fragment.map { (c) -> UInt8 in + return UInt8(c.hexDigitValue ?? 0); + }; + + let ivLen = fragmentData.count - (32 * 2); + + var iv = Data(); + var key = Data(); + + for i in 0..<(ivLen/2) { + iv.append(fragmentData[i*2]*16 + fragmentData[i*2+1]); + } + for i in (ivLen/2)..<(fragmentData.count/2) { + key.append(fragmentData[i*2]*16 + fragmentData[i*2+1]); + } + + let tag = inData.subdata(in: inData.count-16.. Result<(Data, String),ErrorCondition> { + guard let data = try? Data(contentsOf: url) else { + return .failure(ErrorCondition.item_not_found); + } + + return encryptFile(data: data); + } + + public func encryptFile(data: Data) -> Result<(Data, String),ErrorCondition> { + var iv = Data(count: 12); + iv.withUnsafeMutableBytes { (bytes) -> Void in + _ = SecRandomCopyBytes(kSecRandomDefault, 12, bytes.baseAddress!); + } + + var key = Data(count: 32); + key.withUnsafeMutableBytes { (bytes) -> Void in + _ = SecRandomCopyBytes(kSecRandomDefault, 32, bytes.baseAddress!); + } + + var encryptedBody = Data(); + var tag = Data(); + + guard engine.encrypt(iv: iv, key: key, message: data, output: &encryptedBody, tag: &tag) else { + return .failure(.not_acceptable); + } + + let combinedKey = iv + key; + + return .success((encryptedBody + tag, combinedKey.map({ String(format: "%02x", $0) }).joined())); + } + + private func _encode(message: Message, for remoteAddresses: [SignalAddress], forSelf: Bool = true) -> EncryptionResult { + guard let context = self.context else { + return .failure(.unknown); + } + + var iv = Data(count: 12); + iv.withUnsafeMutableBytes { (bytes) -> Void in + _ = SecRandomCopyBytes(kSecRandomDefault, 12, bytes.baseAddress!); + } + + var key = Data(count: 16); + key.withUnsafeMutableBytes { (bytes) -> Void in + _ = SecRandomCopyBytes(kSecRandomDefault, 16, bytes.baseAddress!); + } + + var tag = Data(); + var combinedKey = key; + + let encryptedEl = Element(name: "encrypted", xmlns: OMEMOModule.XMLNS); + + if let data = message.body?.data(using: .utf8) { + var encryptedBody = Data(); + guard engine.encrypt(iv: iv, key: key, message: data, output: &encryptedBody, tag: &tag) else { + return .failure(.notEncrypted); + } + encryptedEl.addChild(Element(name: "payload", cdata: encryptedBody.base64EncodedString())); + } + + combinedKey.append(tag); + + let header = Element(name: "header"); + header.setAttribute("sid", value: String(signalContext.storage.identityKeyStore.localRegistrationId())); + encryptedEl.addChild(header); + + let localAddresses = forSelf ? storage.sessionStore.allDevices(for: context.userBareJid.stringValue, activeAndTrusted: true).map({ (deviceId) -> SignalAddress in + return SignalAddress(name: context.userBareJid.stringValue, deviceId: deviceId); + }) : []; + let destinations: Set = Set(remoteAddresses + localAddresses); + header.addChildren(destinations.map({ (addr) -> Result in + // TODO: maybe we should cache this session? + guard let session = SignalSessionCipher(withAddress: addr, andContext: self.signalContext) else { + return .failure(.noMemory); + } + return session.encrypt(data: combinedKey); + }).map({ (result) -> Element? in + switch result { + case .success(let key): + let keyEl = Element(name: "key", cdata: key.key.base64EncodedString()); + keyEl.setAttribute("rid", value: String(key.deviceId)); + if key.prekey { + keyEl.setAttribute("prekey", value: "true"); + } + return keyEl; + case .failure(_): + return nil; + } + }).filter({ (el) -> Bool in + return el != nil; + }).map({ el -> Element in + return el!; + })); + header.addChild(Element(name: "iv", cdata: iv.base64EncodedString())); + + message.body = nil; + message.addChild(Element(name: "store", xmlns: "urn:xmpp:hints")); + message.addChild(encryptedEl); + + let fingerprint = storage.identityKeyStore.identityFingerprint(forAddress: SignalAddress(name: context.userBareJid.stringValue, deviceId: Int32(bitPattern: storage.identityKeyStore.localRegistrationId()))); + + return .successMessage(message, fingerprint: fingerprint); + } + + private var mamSyncsInProgress: Set = []; + + open func mamSyncStarted(for jid: BareJID?) { + self.devicesQueue.sync { + self.mamSyncsInProgress.insert(jid); + self.postponedSessions[jid] = []; + } + } + + open func mamSyncFinished(for jid: BareJID?) { + self.devicesQueue.sync { + self.mamSyncsInProgress.remove(jid); + self.processPostponed(for: jid); + } + } + + open override func onItemNotification(notification: PubSubModule.ItemNotification) { + if notification.node == OMEMOModule.DEVICES_LIST_NODE, let context = self.context { + switch notification.action { + case .published(let item): + let from = notification.message.from?.bareJid ?? context.userBareJid; + checkAndPublishDevicesListIfNeeded(jid: from, list: item.payload) + default: + break; + } + } + } + + func publishDeviceIdIfNeeded(removeDevicesWithIds: [UInt32]? = nil) { + guard isPepAvailable, let context = context else { + return; + } + let pepJid = context.userBareJid; + context.module(.pubsub).retrieveItems(from: pepJid, for: OMEMOModule.DEVICES_LIST_NODE, limit: .lastItems(1), completionHandler: { result in + switch result { + case .success(let items): + print("got published devices:", items.items.first as Any); + self.checkAndPublishDevicesListIfNeeded(jid: pepJid, list: items.items.first?.payload, removeDevicesWithIds: removeDevicesWithIds); + case .failure(let pubsubError): + guard pubsubError.error == .item_not_found || pubsubError.error == .internal_server_error() else { + return; + } + self.checkAndPublishDevicesListIfNeeded(jid: pepJid, list: nil); + } + }); + } + + fileprivate func checkAndPublishDevicesListIfNeeded(jid: BareJID, list input: Element?, removeDevicesWithIds: [UInt32]? = nil) { + guard let context = context else { + return; + } + + let pubsubModule = context.module(.pubsub); + var listEl = input; + + if listEl?.name != "list" || listEl?.xmlns != "eu.siacs.conversations.axolotl" { + listEl = Element(name: "list", xmlns: "eu.siacs.conversations.axolotl"); + } + + + let me = context.userBareJid == jid; + + if me { + var changed = false; + + if removeDevicesWithIds != nil && listEl != nil { + let deviceIds = removeDevicesWithIds!.map { (deviceId) -> String in + return String(deviceId); + } + listEl!.removeChildren(where: { (el) -> Bool in + guard let id = el.getAttribute("id") else { + return false; + } + return deviceIds.contains(id); + }); + changed = true; + } + + let ourDeviceId = self.storage.identityKeyStore.localRegistrationId(); + let ourDeviceIdStr = String(ourDeviceId); + if listEl?.findChild(where: { (deviceEl) -> Bool in + deviceEl.getAttribute("id") == ourDeviceIdStr; + }) == nil { + listEl?.addChild(Element(name: "device", attributes: ["id": ourDeviceIdStr])); + changed = true; + } + + if changed { + let publishOptions = PubSubNodeConfig(); + publishOptions.accessModel = .open + pubsubModule.publishItem(at: jid, to: OMEMOModule.DEVICES_LIST_NODE, itemId: "current", payload: listEl!, publishOptions: publishOptions, completionHandler: { result in + switch result { + case .success(_): + self.isReady = true; + print("device id:", ourDeviceIdStr, " successfully registered!"); + case .failure(let pubsubError): + print("item registration failed!"); + if pubsubError.error == .conflict() { + pubsubModule.retrieveNodeConfiguration(from: jid, node: OMEMOModule.DEVICES_LIST_NODE, resultHandler: { result in + switch result { + case .success(let form): + form.accessModel = .open; + pubsubModule.configureNode(at: jid, node: OMEMOModule.DEVICES_LIST_NODE, with: form, completionHandler: { result in + switch result { + case .success(_): + pubsubModule.publishItem(at: jid, to: OMEMOModule.DEVICES_LIST_NODE, itemId: "current", payload: listEl!, publishOptions: publishOptions, completionHandler: { result in + switch result { + case .success(_): + self.isReady = true; + print("device id:", ourDeviceIdStr, " successfully registered 2!"); + case .failure(let error): + print("item registration failed 2! \(error)"); + } + }); + case .failure(let error): + print("node reconfiguration failed! \(error)"); + } + }); + case .failure(let error): + print("node configuration retrieval failed! \(error)"); + } + }); + } + } + }); + } else { + self.isReady = true; + context.sessionObject.setProperty(OMEMOModule.DEVICES_LIST_NODE, value: true); + } + } + + let knownActiveDevices = listEl!.mapChildren(transform: { (el) -> Int32? in + guard let id = el.getAttribute("id") else { + return nil; + } + return Int32(id); + }); + + let allDevices = storage.sessionStore.allDevices(for: jid.stringValue, activeAndTrusted: true); + allDevices.filter { (id) -> Bool in + return !knownActiveDevices.contains(id); + }.forEach { (deviceId) in + _ = storage.identityKeyStore.setStatus(active: false, forIdentity: SignalAddress(name: jid.stringValue, deviceId: deviceId)); + } + + knownActiveDevices.filter { (id) -> Bool in + return !allDevices.contains(id); + }.forEach { (deviceId) in + // TODO: we should enable this device key if we have its identity! + _ = storage.identityKeyStore.setStatus(active: true, forIdentity: SignalAddress(name: jid.stringValue, deviceId: deviceId)); + } + + if me { + let group = DispatchGroup(); + group.notify(queue: self.devicesQueue, execute: { + let brokenIds = self.ownBrokenDevices; + guard !brokenIds.isEmpty else { + return; + } + + self.ownBrokenDevices.removeAll(); + + print("removing own devices with ids \(brokenIds) as there are no bundles for them!") + self.removeDevices(withIds: brokenIds); + }) + + group.enter(); + knownActiveDevices.forEach { (deviceId) in + guard deviceId != self.storage.identityKeyStore.localRegistrationId() else { + return; + } + let address = SignalAddress(name: jid.stringValue, deviceId: deviceId); + if !self.storage.sessionStore.containsSessionRecord(forAddress: address) { + // we do not have a session, so we need to build one! + group.enter(); + self.buildSession(forAddress: address, completionHandler: { + group.leave(); + }); + } + } + group.leave(); + } + self.devicesQueue.async { + self.devices[jid] = knownActiveDevices; + self.activeDevicesPublisher.send(AvailabilityChanged(jid: jid, activeDevices: knownActiveDevices)); + self.fire(AvailabilityChangedEvent(sessionObject: context.sessionObject, jid: jid)); + } + } + + func publishDeviceBundleIfNeeded(completionHandler: (()->Void)?) { + guard let pepJid = context?.userBareJid, let pubsubModule = context?.module(.pubsub) else { + return; + } + + pubsubModule.retrieveItems(from: pepJid, for: bundleNode(for: storage.identityKeyStore.localRegistrationId()), limit: .items(withIds: ["current"]), completionHandler: { result in + switch result { + case .success(let items): + self.publishDeviceBundle(currentBundle: items.items.first?.payload, completionHandler: completionHandler); + case .failure(let pubsubError): + guard pubsubError.error == .item_not_found || pubsubError.error == .internal_server_error() else { + return; + } + self.publishDeviceBundle(currentBundle: nil, completionHandler: completionHandler); + } + }); + } + + public func removeDevices(withIds: [Int32]) { + guard let pepJid = context?.userBareJid, let pubsubModule = context?.module(.pubsub) else { + return; + } + + let ids = withIds.map { (deviceId) -> UInt32 in + return UInt32(bitPattern: deviceId); + } + + withIds.forEach { deviceId in + _ = self.storage.identityKeyStore.setStatus(active: false, forIdentity: SignalAddress(name: pepJid.stringValue, deviceId: deviceId)); + + pubsubModule.deleteNode(from: pepJid, node: bundleNode(for: UInt32(bitPattern: deviceId)), completionHandler: nil); + } + + self.publishDeviceIdIfNeeded(removeDevicesWithIds: ids); + } + + private var postponedSessions: [BareJID?:[SignalAddress]] = [:]; + private var postponedHealing: [BareJID?:[SignalAddress]] = [:]; + + private func postponeSession(for jid: BareJID?, address: SignalAddress) -> Bool { + return devicesQueue.sync { + if mamSyncsInProgress.contains(jid) { + if var tmp = postponedSessions[jid] { + tmp.append(address); + postponedSessions[jid] = tmp; + return true; + } + } + if mamSyncsInProgress.contains(nil) { + if var tmp = postponedSessions[nil] { + tmp.append(address); + postponedSessions[nil] = tmp; + return true; + } + } + return false; + } + } + + private func postponeHealing(for jid: BareJID?, address: SignalAddress) -> Bool { + return devicesQueue.sync { + if mamSyncsInProgress.contains(jid) { + if var tmp = postponedHealing[jid] { + tmp.append(address); + postponedHealing[jid] = tmp; + return true; + } + } + if mamSyncsInProgress.contains(nil) { + if var tmp = postponedHealing[nil] { + tmp.append(address); + postponedHealing[nil] = tmp; + return true; + } + } + return false; + } + } + + private func processPostponed(for jid: BareJID?) { + if let sessions = postponedSessions.removeValue(forKey: jid) { + if !sessions.isEmpty { + if self.storage.preKeyStore.flushDeletedPreKeys() { + self.publishDeviceBundleIfNeeded(completionHandler: nil); + } + } + + for address in sessions { + self.completeSession(forAddress: address); + } + } + if let healings = postponedHealing.removeValue(forKey: jid) { + for healing in healings { + self.buildSession(forAddress: healing, completionHandler: { + self.completeSession(forAddress: healing); + }) + } + } + } + + fileprivate func signedPreKey(regenerate: Bool = false) -> SignalSignedPreKey? { + let signedPreKeyId = storage.signedPreKeyStore.countSignedPreKeys(); + var signedPreKey: SignalSignedPreKey? = nil; + if (!regenerate) && (signedPreKeyId != 0) { + if let data = signalContext.storage.signedPreKeyStore.loadSignedPreKey(withId: UInt32(signedPreKeyId)) { + signedPreKey = SignalSignedPreKey(fromSerializedData: data); + } + } + + if signedPreKey == nil { + let identityKeyPair = storage.identityKeyStore.keyPair()!; + print("regenerating signed pre key!"); + signedPreKey = signalContext.generateSignedPreKey(withIdentity: identityKeyPair, signedPreKeyId: UInt32(signedPreKeyId + 1)) + guard signedPreKey != nil else { + return nil; + } + guard signalContext.storage.signedPreKeyStore.storeSignedPreKey(signedPreKey!.serializedData!, withId: signedPreKey!.preKeyId) else { + return nil; + } + } + return signedPreKey; + } + +// fileprivate func publishDeviceBundleNoKeys(regenerate: Bool = false, completionHandler: @escaping ()->Void) { +// if let signedPreKey = signedPreKey(regenerate: regenerate) { +// let preKeys = signalContext.generatePreKeys(withStartingPreKeyId: 0, count: 20); +// preKeys.forEach { (preKey) in +// _ = self.storage.preKeyStore.storePreKey(preKey.serializedData!, withId: preKey.preKeyId); +// } +// publishDeviceBundle(signedPreKey: signedPreKey, preKeys: preKeys, completionHandler: completionHandler); +// } +// } + + fileprivate func publishDeviceBundle(currentBundle: Element?, completionHandler: (()->Void)?) { + guard let identityPublicKey = storage.identityKeyStore.keyPair()?.publicKey?.base64EncodedString() else { + completionHandler?(); + return; + } + + var flush: Bool = currentBundle == nil; + if !flush { + flush = identityPublicKey != currentBundle?.findChild(name: "identityKey")?.value; + } + + if let signedPreKey = self.signedPreKey(regenerate: flush), let signedPreKeyBase64 = signedPreKey.publicKeyData?.base64EncodedString() { + let signatureBase64 = signedPreKey.signature.base64EncodedString(); + var changed = flush || signedPreKeyBase64 != currentBundle?.findChild(name: "signedPreKeyPublic")?.value || signatureBase64 != currentBundle?.findChild(name: "signedPreKeySignature")?.value; + + let currentKeys = currentBundle?.findChild(name: "prekeys")?.mapChildren(transform: { (preKeyEl) -> UInt32? in + guard let preKeyId = preKeyEl.getAttribute("preKeyId") else { + return nil; + } + return UInt32(preKeyId); + }); + + var validKeys = currentKeys?.map({ (preKeyId) -> SignalPreKey? in + guard let key = self.storage.preKeyStore.loadPreKey(withId: preKeyId) else { + return nil; + } + return SignalPreKey(fromSerializedData: key); + }).filter({ (preKey) -> Bool in + return preKey != nil; + }).map({ preKey -> SignalPreKey in + return preKey!; + }) ?? []; + let needKeys = 100 - validKeys.count; + if needKeys > 0 { + changed = true; + let currentPreKeyId = self.storage.preKeyStore.currentPreKeyId(); + var newKeys = self.signalContext.generatePreKeys(withStartingPreKeyId: currentPreKeyId + 1, count: UInt32(needKeys)); + newKeys = newKeys.filter { (key) in + self.storage.preKeyStore.storePreKey(key.serializedData!, withId: key.preKeyId); + }; + validKeys = validKeys + newKeys; + } + + if changed { + // something has changed, we need to publish new bundle! + publishDeviceBundle(signedPreKey: signedPreKey, preKeys: validKeys, completionHandler: completionHandler); + } else { + completionHandler?(); + } + } + } + + func publishDeviceBundle(signedPreKey: SignalSignedPreKey, preKeys: [SignalPreKey], completionHandler: (()->Void)?) { + let identityKeyPair = storage.identityKeyStore.keyPair()!; + + let bundleEl = Element(name: "bundle", xmlns: OMEMOModule.XMLNS); + bundleEl.addChild(Element(name: "signedPreKeyPublic", cdata: signedPreKey.publicKeyData!.base64EncodedString(), attributes: ["signedPreKeyId": String(signedPreKey.preKeyId)])); + bundleEl.addChild(Element(name: "signedPreKeySignature", cdata: signedPreKey.signature.base64EncodedString())); + bundleEl.addChild(Element(name: "identityKey", cdata: identityKeyPair.publicKey!.base64EncodedString())); + let preKeysElems = preKeys.map({ (preKey) -> Element in + return Element(name: "preKeyPublic", cdata: preKey.serializedPublicKey!.base64EncodedString(), attributes: ["preKeyId": String(preKey.preKeyId)]); + }); + bundleEl.addChild(Element(name: "prekeys", children: preKeysElems)); + + let publishOptions = PubSubNodeConfig(); + publishOptions.accessModel = .open; + + guard let pubsubModule = context?.module(.pubsub) else { + return; + } + pubsubModule.publishItem(at: nil, to: bundleNode(for: storage.identityKeyStore.localRegistrationId()), itemId: "current", payload: bundleEl, publishOptions: publishOptions, completionHandler: { result in + switch result { + case .success(_): + print("published public keys!"); + completionHandler?(); + case .failure(let pubsubError): + print("cound not publish keys:", pubsubError); + } + }); + } + + private func completeSession(forAddress address: SignalAddress) { + let message = Message() + message.type = .chat; + message.to = JID(address.name); + let result = self._encode(message: message, for: [address], forSelf: false); + switch result { + case .successMessage(let message, _): + message.hints = [.store]; + self.write(message); + case .failure(let error): + print("failed to complete session for address: \(address), error: \(error)"); + } + } + + open func buildSession(forAddress address: SignalAddress, completionHandler: (()->Void)? = nil) { + let pepJid = BareJID(address.name); + guard let pubsubModule: PubSubModule = context?.module(.pubsub) else { + return; + } + pubsubModule.retrieveItems(from: pepJid, for: bundleNode(for: UInt32(bitPattern: address.deviceId)), limit: .lastItems(1), completionHandler: { result in + switch result { + case .success(let items): + guard let bundle = OMEMOBundle(from: items.items.first?.payload) else { + print("could not create a bundle!"); + self.markDeviceAsFailed(for: pepJid, andDeviceId: address.deviceId); + completionHandler?(); + return; + } + + let preKey = bundle.preKeys[Int.random(in: 0.. String { + return "eu.siacs.conversations.axolotl.bundles:\(deviceId)"; + } + + open class OMEMOBundle { + + let preKeys: [OMEMOPreKey]; + + let signedPreKeyId: UInt32; + let signedPreKeyPublic: Data; + let identityKey: Data; + let signature: Data; + + init?(from: Element?) { + guard let el = from, el.name == "bundle" && el.xmlns == OMEMOModule.XMLNS else { + return nil; + } + + guard let preKeys = el.findChild(name: "prekeys")?.mapChildren(transform: { (el) -> OMEMOPreKey? in + return OMEMOPreKey(from: el); + }), !preKeys.isEmpty else { + return nil; + } + + guard let signedKeyPublic = el.findChild(name: "signedPreKeyPublic"), let signedPreKeyIdStr = signedKeyPublic.getAttribute("signedPreKeyId"), let signedPreKeyId = UInt32(signedPreKeyIdStr), let signedKeyPublicValue = signedKeyPublic.value, let signedKeyPublicData = Data(base64Encoded: signedKeyPublicValue, options: [.ignoreUnknownCharacters]) else { + return nil; + } + + guard let identityKeyValue = el.findChild(name: "identityKey")?.value, let identityKeyData = Data(base64Encoded: identityKeyValue, options: [.ignoreUnknownCharacters]) else { + return nil; + } + + guard let signatureValue = el.findChild(name: "signedPreKeySignature")?.value, let signatureData = Data(base64Encoded: signatureValue, options: [.ignoreUnknownCharacters]) else { + return nil; + } + + self.signedPreKeyId = signedPreKeyId; + self.signedPreKeyPublic = signedKeyPublicData; + self.signature = signatureData; + self.identityKey = identityKeyData; + self.preKeys = preKeys; + } + + } + + open class OMEMOPreKey { + + public let preKeyId: UInt32; + public let data: Data; + + public convenience init?(from: Element) { + guard from.name == "preKeyPublic", let value = from.value, let preKeyIdStr = from.getAttribute("preKeyId") else { + return nil; + } + guard let data = Data(base64Encoded: value, options: [.ignoreUnknownCharacters]), let preKeyId = UInt32(preKeyIdStr) else { + return nil; + } + + self.init(data: data, preKeyId: preKeyId); + } + + public init(data: Data, preKeyId: UInt32) { + self.data = data; + self.preKeyId = preKeyId; + } + + } + + public struct AvailabilityChanged { + + public let jid: BareJID; + public let activeDevices: [Int32]; + + } + + open class AvailabilityChangedEvent: Event { + + public static let TYPE = AvailabilityChangedEvent(); + + public let type = "OMEMOAvailabilityChangedEvent"; + + public let sessionObject: SessionObject!; + public var account: BareJID { + return sessionObject.context.userBareJid; + } + public let jid: BareJID!; + + init() { + self.sessionObject = nil; + self.jid = nil; + } + + public init(sessionObject: SessionObject, jid: BareJID) { + self.sessionObject = sessionObject; + self.jid = jid; + } + + } +} + +public protocol AES_GCM_Engine { + + func encrypt(iv: Data, key: Data, message: Data, output: UnsafeMutablePointer?, tag: UnsafeMutablePointer?) -> Bool; + + func decrypt(iv: Data, key: Data, encoded: Data, auth tag: Data?, output: UnsafeMutablePointer?) -> Bool; + +} + +public enum EncryptionResult { + case successMessage(_ success: Success, fingerprint: String?) + case failure(_ error: Failure) +} + +public enum DecryptionResult { + case successMessage(_ success: Success, fingerprint: String?) + case successTransportKey(_ key: Data, iv: Data) + case failure(_ error: Failure) +} diff --git a/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalAddress.swift b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalAddress.swift new file mode 100644 index 0000000..6cd78a1 --- /dev/null +++ b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalAddress.swift @@ -0,0 +1,82 @@ +// +// SignalAddress.swift +// +// TigaseSwift OMEMO +// Copyright (C) 2019 "Tigase, Inc." +// +// This program is free software: you can redistribute it and/or modify +// it under the terms of the GNU General Public License as published by +// the Free Software Foundation, either version 3 of the License, or +// (at your option) any later version. +// +// This program is distributed in the hope that it will be useful, +// but WITHOUT ANY WARRANTY; without even the implied warranty of +// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +// GNU General Public License for more details. +// +// You should have received a copy of the GNU General Public License +// along with this program. Look for COPYING file in the top folder. +// If not, see https://www.gnu.org/licenses/. +// + +import Foundation +import libsignal + +open class SignalAddress: Hashable, CustomStringConvertible { + + public static func == (lhs: SignalAddress, rhs: SignalAddress) -> Bool { + return lhs.name == rhs.name && lhs.deviceId == rhs.deviceId; + } + + public func hash(into hasher: inout Hasher) { + hasher.combine(name); + hasher.combine(deviceId); + } + + public let name: String; + public let deviceId: Int32; + + fileprivate let nameBytes: UnsafeMutablePointer; + public let address: UnsafeMutablePointer; + + public var description: String { + return "(name: \(name), deviceId: \(deviceId) or \(UInt32(bitPattern: deviceId))"; + } + + public init(name: String, deviceId: Int32) { + self.name = name; + self.deviceId = deviceId; + + let rawPointer = malloc(MemoryLayout.size)!.assumingMemoryBound(to: signal_protocol_address.self); + rawPointer.pointee.device_id = deviceId; + let tmp = self.name.utf8CString; + self.nameBytes = tmp.withUnsafeBytes { (inBuf) -> UnsafeMutablePointer in + let outBuf = malloc(tmp.count)!.assumingMemoryBound(to: Int8.self); + memcpy(outBuf, inBuf.baseAddress!, tmp.count); + return outBuf; + } + + rawPointer.pointee.name = UnsafePointer(nameBytes); + self.address = rawPointer; + } + + deinit { + free(address); + free(nameBytes); + } + + public convenience init?(from: UnsafePointer?) { + guard let namePtr = from?.pointee.name, let name = String(validatingUTF8: namePtr), let deviceId = from?.pointee.device_id else { + return nil; + } + + self.init(name: name, deviceId: deviceId); + } + + public convenience init?(from: UnsafePointer?) { + guard var addr = from?.pointee else { + return nil; + } + self.init(from: &addr); + } +} diff --git a/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalContext.swift b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalContext.swift new file mode 100644 index 0000000..6d1e588 --- /dev/null +++ b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalContext.swift @@ -0,0 +1,238 @@ +// +// SignalContext.swift +// +// TigaseSwift OMEMO +// Copyright (C) 2019 "Tigase, Inc." +// +// This program is free software: you can redistribute it and/or modify +// it under the terms of the GNU General Public License as published by +// the Free Software Foundation, either version 3 of the License, or +// (at your option) any later version. +// +// This program is distributed in the hope that it will be useful, +// but WITHOUT ANY WARRANTY; without even the implied warranty of +// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +// GNU General Public License for more details. +// +// You should have received a copy of the GNU General Public License +// along with this program. Look for COPYING file in the top folder. +// If not, see https://www.gnu.org/licenses/. +// + +import Foundation +import libsignal + +open class SignalContext { + + public fileprivate(set) var globalContext: OpaquePointer?; + fileprivate let provider: SignalCryptoProvider = SignalCryptoProvider(); + fileprivate let lock: NSRecursiveLock = NSRecursiveLock(); + public let storage: SignalStorage; + + public init?(withStorage: SignalStorage) { + self.storage = withStorage; + + guard signal_context_create(&globalContext, SignalContext.bridge(self)) == 0 else { + return nil; + } + + var provider = self.provider.provider; + signal_context_set_crypto_provider(globalContext, &provider) + + signal_context_set_locking_functions(globalContext, signalLock, signalUnlock) + signal_context_set_log_function(globalContext, signalLog); + + self.storage.setup(withContext: self); + } + + open func generateRegistrationId() -> UInt32 { + var regId: UInt32 = 0; + let res = signal_protocol_key_helper_generate_registration_id(®Id, 1, self.globalContext!); + guard res >= 0 else { + return 0; + } + return regId; + } + + open func generatePreKeys(withStartingPreKeyId preKeyId: UInt32, count: UInt32) -> [SignalPreKey] { + var head: OpaquePointer? = nil; + guard signal_protocol_key_helper_generate_pre_keys(&head, preKeyId, count, globalContext) >= 0 && head != nil else { + return []; + } + var keys: [SignalPreKey] = []; + while (head != nil) { + if let pre_key = signal_protocol_key_helper_key_list_element(head) { + keys.append(SignalPreKey(fromPreKey: pre_key)); + } + head = signal_protocol_key_helper_key_list_next(head); + } + return keys; + } + + open func generateSignedPreKey(withIdentity identity: SignalIdentityKeyPairProtocol, signedPreKeyId: UInt32, timestamp: Date = Date()) -> SignalSignedPreKey? { + guard let keyPair = identity.keyPairPointer else { + return nil; + } + + var signed_pre_key: OpaquePointer?; + guard signal_protocol_key_helper_generate_signed_pre_key(&signed_pre_key, keyPair, signedPreKeyId, UInt64(timestamp.timeIntervalSince1970) * 1000, globalContext) >= 0 && signed_pre_key != nil else { + return nil; + } + + return SignalSignedPreKey(fromSignedPreKey: signed_pre_key!); + } + + static func bridge(_ obj : T) -> UnsafeMutableRawPointer { + return Unmanaged.passUnretained(obj).toOpaque(); + } + + static func bridge(_ ptr : UnsafeMutableRawPointer) -> T { + return Unmanaged.fromOpaque(ptr).takeUnretainedValue(); + } + + static func bridge(fromPointer ptr : UnsafeMutableRawPointer) -> AnyObject { + return Unmanaged.fromOpaque(ptr).takeUnretainedValue(); + } + +} + +fileprivate func signalLock(_ userData: UnsafeMutableRawPointer?) { + let ctx: SignalContext = SignalContext.bridge(userData!); + ctx.lock.lock(); +} + +fileprivate func signalUnlock(_ userData: UnsafeMutableRawPointer?) { + let ctx: SignalContext = SignalContext.bridge(userData!); + ctx.lock.unlock(); +} + +fileprivate func signalLog(level: CInt, message: UnsafePointer?, len: Int, userData: UnsafeMutableRawPointer?) { + print("SignalProtocol:", level, String(validatingUTF8: message!) as Any); +} + +open class SignalSignedPreKey { + + fileprivate let signedPreKey: OpaquePointer; + + public var preKeyId: UInt32 { + return session_signed_pre_key_get_id(signedPreKey); + } + + public var timestamp: Date { + return Date(timeIntervalSince1970: TimeInterval(session_signed_pre_key_get_timestamp(signedPreKey) / 1000)); + } + + public var signature: Data { + let sigBytes = session_signed_pre_key_get_signature(signedPreKey); + let sigLen = session_signed_pre_key_get_signature_len(signedPreKey); + return Data(bytes: sigBytes!, count: sigLen); + } + + public var serializedData: Data? { + var buf: OpaquePointer?; + guard session_signed_pre_key_serialize(&buf, signedPreKey) == 0 && buf != nil else { + return nil; + } + + defer { + signal_buffer_free(buf); + } + return Data(bytes: signal_buffer_data(buf), count: signal_buffer_len(buf)); + } + + public var publicKeyData: Data? { + guard let keyPair = session_signed_pre_key_get_key_pair(signedPreKey) else { + return nil; + } + guard let publicKey = ec_key_pair_get_public(keyPair) else { + return nil; + } + var buf: OpaquePointer?; + guard ec_public_key_serialize(&buf, publicKey) >= 0 && buf != nil else { + return nil; + } + + defer { + signal_buffer_free(buf); + } + return Data(bytes: signal_buffer_data(buf), count: signal_buffer_len(buf)); + } + + public init(fromSignedPreKey: OpaquePointer) { + self.signedPreKey = fromSignedPreKey; + signal_type_ref(signedPreKey); + } + + public convenience init?(fromSerializedData: Data) { + guard let preKey: OpaquePointer = fromSerializedData.withUnsafeBytes({ (bytes) -> OpaquePointer? in + var tmp: OpaquePointer?; + guard session_signed_pre_key_deserialize(&tmp, bytes.baseAddress!.assumingMemoryBound(to: UInt8.self), fromSerializedData.count, nil) >= 0 else { + return nil; + } + return tmp; + }) else { + return nil; + } + self.init(fromSignedPreKey: preKey); + } + + deinit { + signal_type_unref(signedPreKey); + } +} + +open class SignalPreKey { + + fileprivate let preKey: OpaquePointer; + + public var preKeyId: UInt32 { + return session_pre_key_get_id(preKey); + } + + public var serializedData: Data? { + var buf: OpaquePointer?; + guard session_pre_key_serialize(&buf, preKey) == 0 && buf != nil else { + return nil; + } + + defer { + signal_buffer_free(buf); + } + return Data(bytes: signal_buffer_data(buf), count: signal_buffer_len(buf)); + } + + public var serializedPublicKey: Data? { + let keyPair = session_signed_pre_key_get_key_pair(preKey); + var buf: OpaquePointer?; + guard ec_public_key_serialize(&buf, ec_key_pair_get_public(keyPair)) >= 0 else { + return nil; + } + defer { + signal_buffer_free(buf); + } + return Data(bytes: signal_buffer_data(buf), count: signal_buffer_len(buf)); + } + + public init(fromPreKey: OpaquePointer) { + self.preKey = fromPreKey; + signal_type_ref(self.preKey); + } + + public convenience init?(fromSerializedData: Data) { + guard let preKey: OpaquePointer = fromSerializedData.withUnsafeBytes({ (bytes) -> OpaquePointer? in + var tmp: OpaquePointer?; + guard session_pre_key_deserialize(&tmp, bytes.baseAddress!.assumingMemoryBound(to: UInt8.self), fromSerializedData.count, nil) >= 0 else { + return nil; + } + return tmp; + }) else { + return nil; + } + self.init(fromPreKey: preKey); + } + + deinit { + signal_type_unref(preKey); + } + +} diff --git a/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalCryptoProvider.swift b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalCryptoProvider.swift new file mode 100644 index 0000000..e0bd765 --- /dev/null +++ b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalCryptoProvider.swift @@ -0,0 +1,175 @@ +// +// SignalCryptoProvider.swift +// +// TigaseSwift OMEMO +// Copyright (C) 2019 "Tigase, Inc." +// +// This program is free software: you can redistribute it and/or modify +// it under the terms of the GNU General Public License as published by +// the Free Software Foundation, either version 3 of the License, or +// (at your option) any later version. +// +// This program is distributed in the hope that it will be useful, +// but WITHOUT ANY WARRANTY; without even the implied warranty of +// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +// GNU General Public License for more details. +// +// You should have received a copy of the GNU General Public License +// along with this program. Look for COPYING file in the top folder. +// If not, see https://www.gnu.org/licenses/. +// + +import Foundation +import CommonCrypto +import libsignal + +public class SignalCryptoProvider { + + public fileprivate(set) var provider: signal_crypto_provider; + + init() { + provider = signal_crypto_provider(); + provider.random_func = random_func; + provider.hmac_sha256_init_func = hmac_sha256_init_func; + provider.hmac_sha256_update_func = hmac_sha256_update_func; + provider.hmac_sha256_final_func = hmac_sha256_final_func; + provider.hmac_sha256_cleanup_func = hmac_sha256_cleanup_func; + provider.sha512_digest_init_func = sha512_digest_init_func; + provider.sha512_digest_update_func = sha512_digest_update_func; + provider.sha512_digest_final_func = sha512_digest_final_func; + provider.sha512_digest_cleanup_func = sha512_digest_cleanup_func; + provider.encrypt_func = encrypt_func; + provider.decrypt_func = decrypt_func; + provider.user_data = SignalContext.bridge(self); + } +} + +fileprivate func random_func(data: UnsafeMutablePointer?, len: Int, ctx: UnsafeMutableRawPointer?) -> CInt { + guard CCRandomGenerateBytes(data, len) == kCCSuccess else { + return SG_ERR_INVAL; + } + return SG_SUCCESS; +} + +fileprivate func hmac_sha256_init_func(hmacCtx: UnsafeMutablePointer?, key: UnsafePointer?, keyLen: Int, ctx: UnsafeMutableRawPointer?) -> CInt { + guard hmacCtx != nil && key != nil else { + return SG_ERR_INVAL; + } + + guard let ctx: UnsafeMutablePointer = malloc(MemoryLayout.size)?.assumingMemoryBound(to: CCHmacContext.self) else { + return SG_ERR_NOMEM; + } + + CCHmacInit(ctx, CCHmacAlgorithm(kCCHmacAlgSHA256), key, keyLen); + hmacCtx!.initialize(to: ctx); + return SG_SUCCESS; +} + +fileprivate func hmac_sha256_update_func(hmacCtx: UnsafeMutableRawPointer?, data: UnsafePointer?, dataLen: Int, ctx: UnsafeMutableRawPointer?) -> CInt { + guard hmacCtx != nil && data != nil else { + return SG_ERR_INVAL; + } + CCHmacUpdate(hmacCtx?.assumingMemoryBound(to: CCHmacContext.self), data!, dataLen); + return SG_SUCCESS; +} + +fileprivate func hmac_sha256_final_func(hmacCtx: UnsafeMutableRawPointer?, output: UnsafeMutablePointer?, ctx: UnsafeMutableRawPointer?) -> CInt { + guard hmacCtx != nil && output != nil else { + return SG_ERR_INVAL; + } + + let length = Int(CC_SHA256_DIGEST_LENGTH); + var data = Data(capacity: length); + data.withUnsafeMutableBytes({ (ptr: UnsafeMutableRawBufferPointer) -> Void in + CCHmacFinal(hmacCtx?.assumingMemoryBound(to: CCHmacContext.self), ptr.baseAddress) + return; + }); + output!.initialize(to: data.withUnsafeBytes({ (ptr: UnsafeRawBufferPointer) -> OpaquePointer in + return signal_buffer_create(ptr.baseAddress?.assumingMemoryBound(to: UInt8.self), length); + })); + return SG_SUCCESS; +} + +fileprivate func hmac_sha256_cleanup_func(hmacCtx: UnsafeMutableRawPointer?, ctx: UnsafeMutableRawPointer?) { + guard hmacCtx != nil else { + return; + } + free(hmacCtx!); +} + +fileprivate func sha512_digest_init_func(digestCtx: UnsafeMutablePointer?, ctx: UnsafeMutableRawPointer?) -> CInt { + guard digestCtx != nil else { + return SG_ERR_INVAL; + } + + guard let ctx: UnsafeMutablePointer = malloc(MemoryLayout.size)?.assumingMemoryBound(to: CC_SHA512_CTX.self) else { + return SG_ERR_NOMEM; + } + + CC_SHA512_Init(ctx); + digestCtx!.initialize(to: ctx); + return SG_SUCCESS; +} + +fileprivate func sha512_digest_update_func(digestCtx: UnsafeMutableRawPointer?, data: UnsafePointer?, dataLen: Int, ctx: UnsafeMutableRawPointer?) -> CInt { + guard digestCtx != nil && data != nil else { + return SG_ERR_INVAL; + } + CC_SHA512_Update(digestCtx!.assumingMemoryBound(to: CC_SHA512_CTX.self), data, UInt32(dataLen)); + return SG_SUCCESS; +} + +fileprivate func sha512_digest_final_func(digestCtx: UnsafeMutableRawPointer?, output: UnsafeMutablePointer?, ctx: UnsafeMutableRawPointer?) -> CInt { + guard digestCtx != nil && output != nil else { + return SG_ERR_INVAL; + } + + let length = Int(CC_SHA512_DIGEST_LENGTH); + var data = Data(capacity: length); + data.withUnsafeMutableBytes({ (ptr: UnsafeMutableRawBufferPointer) -> Void in + CC_SHA512_Final(ptr.baseAddress?.assumingMemoryBound(to: UInt8.self), digestCtx?.assumingMemoryBound(to: CC_SHA512_CTX.self)) + return; + }); + output!.initialize(to: data.withUnsafeBytes({ (ptr: UnsafeRawBufferPointer) -> OpaquePointer in + return signal_buffer_create(ptr.baseAddress?.assumingMemoryBound(to: UInt8.self), length); + })); + return SG_SUCCESS; +} + +fileprivate func sha512_digest_cleanup_func(digestCtx: UnsafeMutableRawPointer?, ctx: UnsafeMutableRawPointer?) { + guard digestCtx != nil else { + return; + } + free(digestCtx!); +} + +fileprivate func encrypt_func(output: UnsafeMutablePointer?, cipher: CInt, key: UnsafePointer?, keyLen: Int, iv: UnsafePointer?, ivLen: Int, plaintext: UnsafePointer?, plaintextLen: Int, ctx: UnsafeMutableRawPointer?) -> CInt { + guard cipher == SG_CIPHER_AES_CBC_PKCS5 else { + return SG_ERR_INVAL; + } + + var outLen: Int = 0; + var bytes = Array(repeating: UInt8(0), count: kCCBlockSizeAES128 + plaintextLen); + let result = CCCrypt(CCOperation(kCCEncrypt), CCAlgorithm(kCCAlgorithmAES), CCOptions(kCCOptionPKCS7Padding), key, keyLen, iv, plaintext, plaintextLen, &bytes, bytes.count, &outLen); + guard result == kCCSuccess else { + return SG_ERR_UNKNOWN; + } + + output?.initialize(to: signal_buffer_create(&bytes, outLen)); + return SG_SUCCESS; +} + +fileprivate func decrypt_func(output: UnsafeMutablePointer?, cipher: CInt, key: UnsafePointer?, keyLen: Int, iv: UnsafePointer?, ivLen: Int, ciphertext: UnsafePointer?, ciphertextLen: Int, ctx: UnsafeMutableRawPointer?) -> CInt { + guard cipher == SG_CIPHER_AES_CBC_PKCS5 else { + return SG_ERR_INVAL; + } + + var outLen: Int = 0; + var bytes = Array(repeating: UInt8(0), count: ciphertextLen + kCCBlockSizeAES128); + guard CCCrypt(CCOperation(kCCDecrypt), CCAlgorithm(kCCAlgorithmAES), CCOptions(kCCOptionPKCS7Padding), key, keyLen, iv, ciphertext, ciphertextLen, &bytes, bytes.count, &outLen) == kCCSuccess else { + return SG_ERR_UNKNOWN; + } + + output?.initialize(to: signal_buffer_create(&bytes, outLen)); + return SG_SUCCESS; +} diff --git a/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalError.swift b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalError.swift new file mode 100644 index 0000000..687fb42 --- /dev/null +++ b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalError.swift @@ -0,0 +1,54 @@ +// +// SignalError.swift +// +// TigaseSwift OMEMO +// Copyright (C) 2019 "Tigase, Inc." +// +// This program is free software: you can redistribute it and/or modify +// it under the terms of the GNU General Public License as published by +// the Free Software Foundation, either version 3 of the License, or +// (at your option) any later version. +// +// This program is distributed in the hope that it will be useful, +// but WITHOUT ANY WARRANTY; without even the implied warranty of +// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +// GNU General Public License for more details. +// +// You should have received a copy of the GNU General Public License +// along with this program. Look for COPYING file in the top folder. +// If not, see https://www.gnu.org/licenses/. +// + +import Foundation + +public enum SignalError: Int, Error { + + // custom error code, not from libsignal but required for internal use to mark that message was not encrypted + case notEncrypted = -100000; + case noDestination = -100001; + + case noMemory = -12; + case invalidArgument = -22; + case unknown = -1000; + case duplicateMessage = -1001; + case invalidKey = -1002; + case invalidKeyId = -1003; + case invalidMac = -1004; + case invalidMessage = -1005; + case invalidVersion = -1006; + case legacyMessage = -1007; + case noSession = -1008; + case staleKeyExchange = -1009; + case unstrustedIdentity = -1010; + case signatureVerificationFailed = -1011; + case invalidProtoBuf = -1100; + case fpInvalidVersion = -1200; + case fpIdentityMismatch = -1201; + + public static func from(code: Int32) -> SignalError? { + guard code < 0 else { + return nil; + } + return SignalError(rawValue: Int(code)) ?? .unknown; + } +} diff --git a/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalIdentityKey.swift b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalIdentityKey.swift new file mode 100644 index 0000000..069c168 --- /dev/null +++ b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalIdentityKey.swift @@ -0,0 +1,75 @@ +// +// SignalIdentityKey.swift +// +// TigaseSwift OMEMO +// Copyright (C) 2019 "Tigase, Inc." +// +// This program is free software: you can redistribute it and/or modify +// it under the terms of the GNU General Public License as published by +// the Free Software Foundation, either version 3 of the License, or +// (at your option) any later version. +// +// This program is distributed in the hope that it will be useful, +// but WITHOUT ANY WARRANTY; without even the implied warranty of +// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +// GNU General Public License for more details. +// +// You should have received a copy of the GNU General Public License +// along with this program. Look for COPYING file in the top folder. +// If not, see https://www.gnu.org/licenses/. +// + +import Foundation +import libsignal + +open class SignalIdentityKey: SignalIdentityKeyProtocol { + + public static func publicKey(from publicKey: Data) -> OpaquePointer? { + return publicKey.withUnsafeBytes({ (bytes) -> OpaquePointer? in + var tmp: OpaquePointer?; + guard curve_decode_point(&tmp, bytes.baseAddress!.assumingMemoryBound(to: UInt8.self), publicKey.count, nil) >= 0 else { + return nil; + } + return tmp; + }); + } + + public let publicKeyPointer: OpaquePointer; + + fileprivate var _publicKey: Data?; + public var publicKey: Data? { + if _publicKey == nil { + var buffer: OpaquePointer?; + guard ec_public_key_serialize(&buffer, publicKeyPointer) == 0 && buffer != nil else { + return nil; + } + _publicKey = Data(bytes: signal_buffer_data(buffer), count: signal_buffer_len(buffer)); + signal_buffer_bzero_free(buffer); + } + return _publicKey; + } + + public convenience init?(publicKey: Data?) { + guard publicKey != nil else { + return nil; + } + guard let publicKeyPointer = SignalIdentityKey.publicKey(from: publicKey!) else { + return nil; + } + + self.init(publicKeyPointer: publicKeyPointer); + } + + public init(publicKeyPointer: OpaquePointer) { + self.publicKeyPointer = publicKeyPointer; + signal_type_ref(self.publicKeyPointer); + } + + deinit { + signal_type_unref(publicKeyPointer); + } + + open func serialized() -> Data { + return publicKey!; + } +} diff --git a/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalIdentityKeyPair.swift b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalIdentityKeyPair.swift new file mode 100644 index 0000000..05a4191 --- /dev/null +++ b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalIdentityKeyPair.swift @@ -0,0 +1,133 @@ +// +// SignalIdentityKeyPair.swift +// +// TigaseSwift OMEMO +// Copyright (C) 2019 "Tigase, Inc." +// +// This program is free software: you can redistribute it and/or modify +// it under the terms of the GNU General Public License as published by +// the Free Software Foundation, either version 3 of the License, or +// (at your option) any later version. +// +// This program is distributed in the hope that it will be useful, +// but WITHOUT ANY WARRANTY; without even the implied warranty of +// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +// GNU General Public License for more details. +// +// You should have received a copy of the GNU General Public License +// along with this program. Look for COPYING file in the top folder. +// If not, see https://www.gnu.org/licenses/. +// + +import Foundation +import libsignal + +open class SignalIdentityKeyPair: SignalIdentityKey, SignalIdentityKeyPairProtocol { + + public let privateKeyPointer: OpaquePointer; + + fileprivate var _keyPairPointer: OpaquePointer?; + public var keyPairPointer: OpaquePointer? { + if _keyPairPointer == nil { + ec_key_pair_create(&_keyPairPointer, publicKeyPointer, privateKeyPointer); + } + return _keyPairPointer; + } + + fileprivate var _privateKey: Data?; + public var privateKey: Data? { + if _privateKey == nil { + var buffer: OpaquePointer?; + guard ec_private_key_serialize(&buffer, privateKeyPointer) == 0 && buffer != nil else { + return nil; + } + _privateKey = Data(bytes: signal_buffer_data(buffer), count: signal_buffer_len(buffer)); + signal_buffer_bzero_free(buffer); + } + return _privateKey; + } + + public var keyPair: Data? { + guard let keyPairPointer = self.keyPairPointer else { + return nil; + } + var buffer: OpaquePointer?; + guard ratchet_identity_key_pair_serialize(&buffer, keyPairPointer) == 0 && buffer != nil else { + return nil; + } + defer { + signal_buffer_bzero_free(buffer); + } + return Data(bytes: signal_buffer_data(buffer), count: signal_buffer_len(buffer)); + } + + public init?(publicKey: Data?, privateKey: Data?) { + guard publicKey != nil && privateKey != nil else { + return nil; + } + + guard let privateKeyPointer = privateKey!.withUnsafeBytes({ (bytes) -> OpaquePointer? in + var tmp: OpaquePointer?; + guard curve_decode_private_point(&tmp, bytes.baseAddress!.assumingMemoryBound(to: UInt8.self), privateKey!.count, nil) >= 0 else { + return nil; + } + return tmp; + }) else { + return nil; + } + + guard let publicKeyPointer = publicKey!.withUnsafeBytes({ (bytes) -> OpaquePointer? in + var tmp: OpaquePointer?; + guard curve_decode_point(&tmp, bytes.baseAddress!.assumingMemoryBound(to: UInt8.self), publicKey!.count, nil) >= 0 else { + return nil; + } + return tmp; + }) else { + return nil; + } + + self.privateKeyPointer = privateKeyPointer; + signal_type_ref(self.privateKeyPointer); + super.init(publicKeyPointer: publicKeyPointer); + } + + public init(withKeyPair keyPair: OpaquePointer) { + privateKeyPointer = ratchet_identity_key_pair_get_private(keyPair); + signal_type_ref(self.privateKeyPointer); + super.init(publicKeyPointer: ratchet_identity_key_pair_get_public(keyPair)); + } + + public convenience init?(fromKeyPairData data: Data) { + guard let keyPair = data.withUnsafeBytes({ (bytes) -> OpaquePointer? in + var tmp: OpaquePointer?; + guard ratchet_identity_key_pair_deserialize(&tmp, bytes.baseAddress!.assumingMemoryBound(to: UInt8.self), data.count, nil) >= 0 && tmp != nil else { + return nil; + } + return tmp; + }) else { + return nil; + } + self.init(withKeyPair: keyPair); + } + + deinit { + signal_type_unref(privateKeyPointer); + if keyPairPointer != nil { + signal_type_unref(keyPairPointer); + _keyPairPointer = nil; + } + } + + public static func generateKeyPair(context: SignalContext) -> SignalIdentityKeyPair? { + var keyPair: OpaquePointer? = nil; + let result = signal_protocol_key_helper_generate_identity_key_pair(&keyPair, context.globalContext); + guard result >= 0 && keyPair != nil else { + return nil; + } + return SignalIdentityKeyPair(withKeyPair: keyPair!); + } + + override open func serialized() -> Data { + return keyPair!; + } +} diff --git a/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalPreKeyBundle.swift b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalPreKeyBundle.swift new file mode 100644 index 0000000..b366411 --- /dev/null +++ b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalPreKeyBundle.swift @@ -0,0 +1,87 @@ +// +// SignalPreKeyBundle.swift +// +// TigaseSwift OMEMO +// Copyright (C) 2019 "Tigase, Inc." +// +// This program is free software: you can redistribute it and/or modify +// it under the terms of the GNU General Public License as published by +// the Free Software Foundation, either version 3 of the License, or +// (at your option) any later version. +// +// This program is distributed in the hope that it will be useful, +// but WITHOUT ANY WARRANTY; without even the implied warranty of +// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +// GNU General Public License for more details. +// +// You should have received a copy of the GNU General Public License +// along with this program. Look for COPYING file in the top folder. +// If not, see https://www.gnu.org/licenses/. +// + +import Foundation +import libsignal + +public class SignalPreKeyBundle { + + let bundle: OpaquePointer; + + public convenience init?(registrationId: UInt32, deviceId: Int32, preKey: OMEMOModule.OMEMOPreKey, bundle: OMEMOModule.OMEMOBundle) { + self.init( + registrationId: registrationId, + deviceId: deviceId, + preKeyId: preKey.preKeyId, + preKeyPublic: preKey.data, + signedPreKeyId: bundle.signedPreKeyId, + signedPreKeyPublic: bundle.signedPreKeyPublic, + signedPreKeySignature: bundle.signature, + identityKey: bundle.identityKey + ) + } + + /// Raw-data initializer added by Luma so an OMEMO 2 bundle (the + /// `urn:xmpp:omemo:2` format) can be turned into a Signal prekey bundle + /// without routing through the legacy bundle types. + public init?( + registrationId: UInt32, + deviceId: Int32, + preKeyId: UInt32, + preKeyPublic: Data, + signedPreKeyId: UInt32, + signedPreKeyPublic: Data, + signedPreKeySignature: Data, + identityKey: Data + ) { + guard let preKeyPublicKey = SignalIdentityKey.publicKey(from: preKeyPublic) else { + return nil; + } + guard let signedPreKeyPublicKey = SignalIdentityKey.publicKey(from: signedPreKeyPublic) else { + signal_type_unref(preKeyPublicKey); + return nil; + } + guard let identityKeyKey = SignalIdentityKey.publicKey(from: identityKey) else { + signal_type_unref(preKeyPublicKey); + signal_type_unref(signedPreKeyPublicKey); + return nil; + } + + var bundlePtr: OpaquePointer?; + guard signedPreKeySignature.withUnsafeBytes({ (bytes) -> Bool in + let result = session_pre_key_bundle_create(&bundlePtr, registrationId, deviceId, preKeyId, preKeyPublicKey, signedPreKeyId, signedPreKeyPublicKey, bytes.baseAddress?.assumingMemoryBound(to: UInt8.self), signedPreKeySignature.count, identityKeyKey); + signal_type_unref(preKeyPublicKey); + signal_type_unref(signedPreKeyPublicKey); + signal_type_unref(identityKeyKey); + + return result >= 0; + }) else { + return nil; + } + + self.bundle = bundlePtr!; + } + + deinit { + signal_type_unref(bundle); + } + +} diff --git a/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalSessionBuilder.swift b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalSessionBuilder.swift new file mode 100644 index 0000000..8dab36f --- /dev/null +++ b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalSessionBuilder.swift @@ -0,0 +1,51 @@ +// +// SignalSessioBuilder.swift +// +// TigaseSwift OMEMO +// Copyright (C) 2019 "Tigase, Inc." +// +// This program is free software: you can redistribute it and/or modify +// it under the terms of the GNU General Public License as published by +// the Free Software Foundation, either version 3 of the License, or +// (at your option) any later version. +// +// This program is distributed in the hope that it will be useful, +// but WITHOUT ANY WARRANTY; without even the implied warranty of +// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +// GNU General Public License for more details. +// +// You should have received a copy of the GNU General Public License +// along with this program. Look for COPYING file in the top folder. +// If not, see https://www.gnu.org/licenses/. +// + +import Foundation +import libsignal + +open class SignalSessionBuilder { + + fileprivate let builder: OpaquePointer; + fileprivate let address: SignalAddress; + fileprivate let context: SignalContext; + + public init?(withAddress addr: SignalAddress, andContext ctx: SignalContext) { + var builder: OpaquePointer?; + guard session_builder_create(&builder, ctx.storage.storeContext!, addr.address, ctx.globalContext) >= 0 && builder != nil else { + return nil; + } + self.address = addr; + self.context = ctx; + self.builder = builder!; + } + + deinit { + session_builder_free(builder); + } + + public func processPreKeyBundle(bundle: SignalPreKeyBundle) -> Bool { + guard session_builder_process_pre_key_bundle(builder, bundle.bundle) >= 0 else { + return false; + } + return true; + } +} diff --git a/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalSessionCipher.swift b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalSessionCipher.swift new file mode 100644 index 0000000..30afd0b --- /dev/null +++ b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalSessionCipher.swift @@ -0,0 +1,142 @@ +// +// SignalSessionCipher.swift +// +// TigaseSwift OMEMO +// Copyright (C) 2019 "Tigase, Inc." +// +// This program is free software: you can redistribute it and/or modify +// it under the terms of the GNU General Public License as published by +// the Free Software Foundation, either version 3 of the License, or +// (at your option) any later version. +// +// This program is distributed in the hope that it will be useful, +// but WITHOUT ANY WARRANTY; without even the implied warranty of +// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +// GNU General Public License for more details. +// +// You should have received a copy of the GNU General Public License +// along with this program. Look for COPYING file in the top folder. +// If not, see https://www.gnu.org/licenses/. +// + +import Foundation +import libsignal + +open class SignalSessionCipher { + + fileprivate var cipher: OpaquePointer; + fileprivate let context: SignalContext; + fileprivate let address: SignalAddress; + + public init?(withAddress address: SignalAddress, andContext context: SignalContext) { + var cipher: OpaquePointer?; + self.address = address; + guard session_cipher_create(&cipher, context.storage.storeContext, self.address.address, context.globalContext) >= 0 && cipher != nil else { + return nil; + } + self.context = context; + self.cipher = cipher!; + } + + deinit { + session_cipher_free(cipher); + } + + public func encrypt(data: Data) -> Result { + var message: OpaquePointer?; + let error = data.withUnsafeBytes({ (bytes) -> SignalError? in + return SignalError.from(code : session_cipher_encrypt(cipher, bytes.baseAddress!.assumingMemoryBound(to: UInt8.self), data.count, &message)); + }) + guard error == nil && message != nil else { + return .failure(error ?? .unknown); + } + + let serialized = ciphertext_message_get_serialized(message); + let result = Data(bytes: signal_buffer_data(serialized), count: signal_buffer_len(serialized)); + + defer { + signal_type_unref(message); + } + return .success(Key(key: result, deviceId: address.deviceId, prekey: ciphertext_message_get_type(message) == CIPHERTEXT_PREKEY_TYPE)); + } + + public func decrypt(key: Key) -> Result { + if key.prekey { + return decryptPreKeyMessage(key: key); + } else { + return decryptSignalMessage(key: key); + } + } + + fileprivate func decryptPreKeyMessage(key: Key) -> Result { + let result = key.key.withUnsafeBytes({ (bytes) -> Result in + var output: OpaquePointer?; + var preKeySignalMessage: OpaquePointer?; + + var error = SignalError.from(code: pre_key_signal_message_deserialize(&preKeySignalMessage, bytes.baseAddress!.assumingMemoryBound(to: UInt8.self), key.key.count, self.context.globalContext)); + guard error == nil && preKeySignalMessage != nil else { + return .failure(error ?? .unknown); + } + defer { + signal_type_unref(preKeySignalMessage); + } + error = SignalError.from(code: session_cipher_decrypt_pre_key_signal_message(cipher, preKeySignalMessage, nil, &output)); + guard error == nil && output != nil else { + return .failure(error ?? .unknown); + } + return .success(output!); + }) + switch result { + case .failure(let error): + return .failure(error); + case .success(let preKeySignalMessage): + defer { + signal_buffer_free(preKeySignalMessage); + } + return .success(Data(bytes: signal_buffer_data(preKeySignalMessage), count: signal_buffer_len(preKeySignalMessage))); + } + } + + fileprivate func decryptSignalMessage(key: Key) -> Result { + let result = key.key.withUnsafeBytes({ (bytes) -> Result in + var output: OpaquePointer?; + var signalMessage: OpaquePointer?; + var error = SignalError.from(code: signal_message_deserialize(&signalMessage, bytes.baseAddress!.assumingMemoryBound(to: UInt8.self), key.key.count, self.context.globalContext)); + guard error == nil && signalMessage != nil else { + return .failure(error ?? .unknown); + } + defer { + signal_type_unref(signalMessage); + } + error = SignalError.from(code: session_cipher_decrypt_signal_message(cipher, signalMessage, nil, &output)); + guard error == nil && output != nil else { + return .failure(error ?? .unknown); + } + return .success(output!); + }); + switch result { + case .failure(let error): + return .failure(error); + case .success(let signalMessage): + defer { + signal_buffer_free(signalMessage); + } + return .success(Data(bytes: signal_buffer_data(signalMessage), count: signal_buffer_len(signalMessage))); + } + } + + open class Key { + + public let key: Data; + public let deviceId: Int32; + public let prekey: Bool; + + public init(key: Data, deviceId: Int32, prekey: Bool) { + self.key = key; + self.deviceId = deviceId; + self.prekey = prekey; + } + + } + +} diff --git a/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalStorage.swift b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalStorage.swift new file mode 100644 index 0000000..7cdc309 --- /dev/null +++ b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/SignalStorage.swift @@ -0,0 +1,396 @@ +// +// SignalStorage.swift +// +// TigaseSwift OMEMO +// Copyright (C) 2019 "Tigase, Inc." +// +// This program is free software: you can redistribute it and/or modify +// it under the terms of the GNU General Public License as published by +// the Free Software Foundation, either version 3 of the License, or +// (at your option) any later version. +// +// This program is distributed in the hope that it will be useful, +// but WITHOUT ANY WARRANTY; without even the implied warranty of +// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +// GNU General Public License for more details. +// +// You should have received a copy of the GNU General Public License +// along with this program. Look for COPYING file in the top folder. +// If not, see https://www.gnu.org/licenses/. +// + +import Foundation +import libsignal + +open class SignalStorage { + + public let sessionStore: SignalSessionStoreProtocol; + public let preKeyStore: SignalPreKeyStoreProtocol; + public let signedPreKeyStore: SignalSignedPreKeyStoreProtocol; + public let identityKeyStore: SignalIdentityKeyStoreProtocol; + public let senderKeyStore: SignalSenderKeyStoreProtocol; + + fileprivate(set) var storeContext: OpaquePointer?; + + public init(sessionStore: SignalSessionStoreProtocol, preKeyStore: SignalPreKeyStoreProtocol, signedPreKeyStore: SignalSignedPreKeyStoreProtocol, identityKeyStore: SignalIdentityKeyStoreProtocol, senderKeyStore: SignalSenderKeyStoreProtocol) { + self.sessionStore = sessionStore; + self.preKeyStore = preKeyStore; + self.signedPreKeyStore = signedPreKeyStore; + self.identityKeyStore = identityKeyStore; + self.senderKeyStore = senderKeyStore; + } + + deinit { + if storeContext != nil { + signal_protocol_store_context_destroy(storeContext); + } + storeContext = nil; + } + + open func setup(withContext context: SignalContext) { + signal_protocol_store_context_create(&storeContext, context.globalContext); + + var sessionStoreCallbacks = signal_protocol_session_store(); + sessionStoreCallbacks.load_session_func = load_session_func; + sessionStoreCallbacks.get_sub_device_sessions_func = get_sub_device_sessions_func; + sessionStoreCallbacks.store_session_func = store_session_func; + sessionStoreCallbacks.contains_session_func = contains_session_func; + sessionStoreCallbacks.delete_session_func = delete_session_func; + sessionStoreCallbacks.delete_all_sessions_func = delete_all_sessions_func; + sessionStoreCallbacks.destroy_func = destroy_func; + sessionStoreCallbacks.user_data = SignalContext.bridge(self.sessionStore as AnyObject); + + signal_protocol_store_context_set_session_store(storeContext, &sessionStoreCallbacks); + + var preKeyStoreCallbacks = signal_protocol_pre_key_store(); + preKeyStoreCallbacks.load_pre_key = load_pre_key; + preKeyStoreCallbacks.store_pre_key = store_pre_key; + preKeyStoreCallbacks.contains_pre_key = contains_pre_key; + preKeyStoreCallbacks.remove_pre_key = remove_pre_key; + preKeyStoreCallbacks.destroy_func = destroy_func; + preKeyStoreCallbacks.user_data = SignalContext.bridge(self.preKeyStore as AnyObject); + + signal_protocol_store_context_set_pre_key_store(storeContext, &preKeyStoreCallbacks); + + var signedPreKeyStoreCallbacks = signal_protocol_signed_pre_key_store(); + signedPreKeyStoreCallbacks.load_signed_pre_key = load_signed_pre_key; + signedPreKeyStoreCallbacks.store_signed_pre_key = store_signed_pre_key; + signedPreKeyStoreCallbacks.contains_signed_pre_key = contains_signed_pre_key; + signedPreKeyStoreCallbacks.remove_signed_pre_key = remove_signed_pre_key; + signedPreKeyStoreCallbacks.destroy_func = destroy_func; + signedPreKeyStoreCallbacks.user_data = SignalContext.bridge(self.signedPreKeyStore as AnyObject); + + signal_protocol_store_context_set_signed_pre_key_store(storeContext, &signedPreKeyStoreCallbacks); + + var identityKeyStoreCallbacks = signal_protocol_identity_key_store(); + identityKeyStoreCallbacks.get_identity_key_pair = get_identity_key_pair; + identityKeyStoreCallbacks.get_local_registration_id = get_local_registration_id; + identityKeyStoreCallbacks.save_identity = save_identity; + identityKeyStoreCallbacks.is_trusted_identity = is_trusted_identity; + identityKeyStoreCallbacks.destroy_func = destroy_func; + identityKeyStoreCallbacks.user_data = SignalContext.bridge(self.identityKeyStore as AnyObject); + + signal_protocol_store_context_set_identity_key_store(storeContext, &identityKeyStoreCallbacks); + + var senderKeyStoreCallbacks = signal_protocol_sender_key_store(); + senderKeyStoreCallbacks.store_sender_key = store_sender_key; + senderKeyStoreCallbacks.load_sender_key = load_sender_key; + senderKeyStoreCallbacks.destroy_func = destroy_func; + identityKeyStoreCallbacks.user_data = SignalContext.bridge(self.senderKeyStore as AnyObject); + + signal_protocol_store_context_set_sender_key_store(storeContext, &senderKeyStoreCallbacks); + } + + open func regenerateKeys(wipe: Bool = false) -> Bool { + return false; + }; +} + +public protocol SignalSessionStoreProtocol: AnyObject { + + func sessionRecord(forAddress address: SignalAddress) -> Data?; + + func allDevices(for: String, activeAndTrusted: Bool) -> [Int32]; + + func storeSessionRecord(_ data: Data, forAddress: SignalAddress) -> Bool; + + func containsSessionRecord(forAddress: SignalAddress) -> Bool; + + func deleteSessionRecord(forAddress: SignalAddress) -> Bool; + + func deleteAllSessions(for: String) -> Bool; +} + +public protocol SignalPreKeyStoreProtocol: AnyObject { + + func currentPreKeyId() -> UInt32; + + func loadPreKey(withId: UInt32) -> Data?; + + func storePreKey(_ data: Data, withId: UInt32) -> Bool; + + func containsPreKey(withId: UInt32) -> Bool; + + func deletePreKey(withId: UInt32) -> Bool; + + func flushDeletedPreKeys() -> Bool; +} + +public protocol SignalSignedPreKeyStoreProtocol: AnyObject { + + func countSignedPreKeys() -> Int; + + func loadSignedPreKey(withId: UInt32) -> Data?; + + func storeSignedPreKey(_ data: Data, withId: UInt32) -> Bool; + + func containsSignedPreKey(withId: UInt32) -> Bool; + + func deleteSignedPreKey(withId: UInt32) -> Bool; +} + +public protocol SignalIdentityKeyStoreProtocol: AnyObject { + + func keyPair() -> SignalIdentityKeyPairProtocol?; + func localRegistrationId() -> UInt32; + + func save(identity: SignalAddress, key: SignalIdentityKeyProtocol?) -> Bool; + func isTrusted(identity: SignalAddress, key: SignalIdentityKeyProtocol?) -> Bool; + func save(identity: SignalAddress, publicKeyData: Data?) -> Bool; + func isTrusted(identity: SignalAddress, publicKeyData: Data?) -> Bool; + + func setStatus(_ status: IdentityStatus, forIdentity: SignalAddress) -> Bool; + func setStatus(active: Bool, forIdentity: SignalAddress) -> Bool; + + func identities(forName: String) -> [Identity]; + func identityFingerprint(forAddress address: SignalAddress) -> String? +} + +public protocol SignalIdentityKeyProtocol: AnyObject { + var publicKeyPointer: OpaquePointer { get } + var publicKey: Data? { get } + + func serialized() -> Data; +} + +public protocol SignalIdentityKeyPairProtocol: SignalIdentityKeyProtocol { + var keyPairPointer: OpaquePointer? { get } + var keyPair: Data? { get } + var privateKeyPointer: OpaquePointer { get } + var privateKey: Data? { get } +} + +public protocol SignalSenderKeyStoreProtocol: AnyObject { + + func storeSenderKey(_ key: Data, address: SignalAddress?, groupId: String?) -> Bool; + func loadSenderKey(forAddress: SignalAddress?, groupId: String?) -> Data?; +} + +fileprivate func load_session_func(record: UnsafeMutablePointer?, userRecord: UnsafeMutablePointer?, address: UnsafePointer?, userData: UnsafeMutableRawPointer?) -> CInt { + let sessionStore: SignalSessionStoreProtocol = SignalContext.bridge(fromPointer: userData!) as! SignalSessionStoreProtocol; + guard let addr = SignalAddress(from: address) else { + return -1; + } + + guard let data = sessionStore.sessionRecord(forAddress: addr) else { + return 0; + } + + data.withUnsafeBytes({ (ptr: UnsafeRawBufferPointer) -> Void in + record?.initialize(to: signal_buffer_create(ptr.baseAddress!.assumingMemoryBound(to: UInt8.self), data.count)); + }) + return 1; +} + +fileprivate func get_sub_device_sessions_func(sessions: UnsafeMutablePointer?, name namePtr: UnsafePointer?, nameLen: Int, userData: UnsafeMutableRawPointer?) -> CInt { + let sessionStore: SignalSessionStoreProtocol = SignalContext.bridge(fromPointer: userData!) as! SignalSessionStoreProtocol; + guard let name = String(validatingUTF8: namePtr!) else { + return -1; + } + let devices = sessionStore.allDevices(for: name, activeAndTrusted: false); + guard let list = signal_int_list_alloc() else { + return -1; + } + + devices.forEach { device in + signal_int_list_push_back(list, device); + } + return CInt(devices.count); +} + +fileprivate func store_session_func(address: UnsafePointer?, record: UnsafeMutablePointer?, recordLen: Int, userRecord: UnsafeMutablePointer?, userRecordLen: Int, userData: UnsafeMutableRawPointer?) -> CInt { + let sessionStore: SignalSessionStoreProtocol = SignalContext.bridge(fromPointer: userData!) as! SignalSessionStoreProtocol; + guard let addr = SignalAddress(from: address) else { + return -1; + } + let data = Data(bytes: record!, count: recordLen); + return sessionStore.storeSessionRecord(data, forAddress: addr) ? 0 : -1; +} + +fileprivate func contains_session_func(address: UnsafePointer?, userData: UnsafeMutableRawPointer?) -> CInt { + let sessionStore: SignalSessionStoreProtocol = SignalContext.bridge(fromPointer: userData!) as! SignalSessionStoreProtocol; + guard let addr = SignalAddress(from: address) else { + return -1; + } + return sessionStore.containsSessionRecord(forAddress: addr) ? 1 : 0; +} + +fileprivate func delete_session_func(address: UnsafePointer?, userData: UnsafeMutableRawPointer?) -> CInt { + let sessionStore: SignalSessionStoreProtocol = SignalContext.bridge(fromPointer: userData!) as! SignalSessionStoreProtocol; + guard let addr = SignalAddress(from: address) else { + return -1; + } + return sessionStore.deleteSessionRecord(forAddress: addr) ? 1 : 0; +} + +fileprivate func delete_all_sessions_func(name namePtr: UnsafePointer?, nameLen: Int, userData: UnsafeMutableRawPointer?) -> CInt { + let sessionStore: SignalSessionStoreProtocol = SignalContext.bridge(fromPointer: userData!) as! SignalSessionStoreProtocol; + guard let name = String(validatingUTF8: namePtr!) else { + return -1; + } + + return sessionStore.deleteAllSessions(for: name) ? 1 : 0; +} + +fileprivate func destroy_func(userData: UnsafeMutableRawPointer?) { + +} + +fileprivate func load_pre_key(record: UnsafeMutablePointer?, preKeyId: UInt32, userData: UnsafeMutableRawPointer?) -> CInt { + let preKeyStore: SignalPreKeyStoreProtocol = SignalContext.bridge(fromPointer: userData!) as! SignalPreKeyStoreProtocol; + guard let preKey = preKeyStore.loadPreKey(withId: preKeyId) else { + return SG_ERR_INVALID_KEY_ID; + } + + preKey.withUnsafeBytes({ (bytes: UnsafeRawBufferPointer)->Void in + let buffer = signal_buffer_create(bytes.baseAddress!.assumingMemoryBound(to: UInt8.self), preKey.count); + record?.initialize(to: buffer); + }) + return SG_SUCCESS; +} + +fileprivate func store_pre_key(preKeyId: UInt32, record: UnsafeMutablePointer?, recordLen: Int, userData: UnsafeMutableRawPointer?) -> CInt { + let preKeyStore: SignalPreKeyStoreProtocol = SignalContext.bridge(fromPointer: userData!) as! SignalPreKeyStoreProtocol; + let data = Data(bytes: record!, count: recordLen); + return preKeyStore.storePreKey(data, withId: preKeyId) ? 0 : -1; +} + +fileprivate func contains_pre_key(preKeyId: UInt32, userData: UnsafeMutableRawPointer?) -> CInt { + let preKeyStore: SignalPreKeyStoreProtocol = SignalContext.bridge(fromPointer: userData!) as! SignalPreKeyStoreProtocol; + return preKeyStore.containsPreKey(withId: preKeyId) ? 1 : 0; +} + +fileprivate func remove_pre_key(preKeyId: UInt32, userData: UnsafeMutableRawPointer?) -> CInt { + let preKeyStore: SignalPreKeyStoreProtocol = SignalContext.bridge(fromPointer: userData!) as! SignalPreKeyStoreProtocol; + return preKeyStore.deletePreKey(withId: preKeyId) ? 0 : -1; +} + +fileprivate func load_signed_pre_key(record: UnsafeMutablePointer?, signedPreKeyId: UInt32, userData: UnsafeMutableRawPointer?) -> CInt { + let signedPreKeyStore: SignalSignedPreKeyStoreProtocol = SignalContext.bridge(fromPointer: userData!) as! SignalSignedPreKeyStoreProtocol; + guard let preKey = signedPreKeyStore.loadSignedPreKey(withId: signedPreKeyId) else { + return SG_ERR_INVALID_KEY_ID; + } + + preKey.withUnsafeBytes({ (bytes: UnsafeRawBufferPointer)->Void in + let buffer = signal_buffer_create(bytes.baseAddress!.assumingMemoryBound(to: UInt8.self), preKey.count); + record?.initialize(to: buffer); + }) + return SG_SUCCESS; +} + +fileprivate func store_signed_pre_key(signedPreKeyId: UInt32, record: UnsafeMutablePointer?, recordLen: Int, userData: UnsafeMutableRawPointer?) -> CInt { + let signedPreKeyStore: SignalSignedPreKeyStoreProtocol = SignalContext.bridge(fromPointer: userData!) as! SignalSignedPreKeyStoreProtocol; + let data = Data(bytes: record!, count: recordLen); + return signedPreKeyStore.storeSignedPreKey(data, withId: signedPreKeyId) ? 0 : -1; +} + +fileprivate func contains_signed_pre_key(signedPreKeyId: UInt32, userData: UnsafeMutableRawPointer?) -> CInt { + let signedPreKeyStore: SignalSignedPreKeyStoreProtocol = SignalContext.bridge(fromPointer: userData!) as! SignalSignedPreKeyStoreProtocol; + return signedPreKeyStore.containsSignedPreKey(withId: signedPreKeyId) ? 1 : 0; +} + +fileprivate func remove_signed_pre_key(signedPreKeyId: UInt32, userData: UnsafeMutableRawPointer?) -> CInt { + let signedPreKeyStore: SignalSignedPreKeyStoreProtocol = SignalContext.bridge(fromPointer: userData!) as! SignalSignedPreKeyStoreProtocol; + return signedPreKeyStore.deleteSignedPreKey(withId: signedPreKeyId) ? 0 : -1; +} + +fileprivate func get_identity_key_pair(publicData: UnsafeMutablePointer?, privateData: UnsafeMutablePointer?, userData: UnsafeMutableRawPointer?) -> CInt { + let identityKeyStore: SignalIdentityKeyStoreProtocol = SignalContext.bridge(fromPointer: userData!) as! SignalIdentityKeyStoreProtocol; + guard let keyPair = identityKeyStore.keyPair() else { + return -1; + } + + if let publicKey = keyPair.publicKey { + publicKey.withUnsafeBytes { (bytes: UnsafeRawBufferPointer) -> Void in + let buffer = signal_buffer_create(bytes.baseAddress!.assumingMemoryBound(to: UInt8.self), publicKey.count); + publicData?.initialize(to: buffer); + } + } + + if let privateKey = keyPair.privateKey { + privateKey.withUnsafeBytes { (bytes: UnsafeRawBufferPointer) -> Void in + let buffer = signal_buffer_create(bytes.baseAddress!.assumingMemoryBound(to: UInt8.self), privateKey.count); + privateData?.initialize(to: buffer); + } + } + + return 0; +} + +fileprivate func get_local_registration_id(userData: UnsafeMutableRawPointer?, registrationId: UnsafeMutablePointer?) -> CInt { + let identityKeyStore: SignalIdentityKeyStoreProtocol = SignalContext.bridge(fromPointer: userData!) as! SignalIdentityKeyStoreProtocol; + let regId = identityKeyStore.localRegistrationId(); + if regId > 0 { + registrationId?.initialize(to: regId); + return 0; + } else { + return -1; + } +} + +fileprivate func save_identity(address: UnsafePointer?, keyData: UnsafeMutablePointer?, keyLen: Int, userData: UnsafeMutableRawPointer?) -> CInt { + let identityKeyStore: SignalIdentityKeyStoreProtocol = SignalContext.bridge(fromPointer: userData!) as! SignalIdentityKeyStoreProtocol; + guard let addr = SignalAddress(from: address) else { + return -1; + } + return identityKeyStore.save(identity: addr, publicKeyData: keyData == nil ? nil : Data(bytes: keyData!, count: keyLen)) ? 0 : -1; +} + +fileprivate func is_trusted_identity(address: UnsafePointer?, keyData: UnsafeMutablePointer?, keyLen: Int, userData: UnsafeMutableRawPointer?) -> CInt { + let identityKeyStore: SignalIdentityKeyStoreProtocol = SignalContext.bridge(fromPointer: userData!) as! SignalIdentityKeyStoreProtocol; + guard let addr = SignalAddress(from: address) else { + return -1; + } + return identityKeyStore.isTrusted(identity: addr, publicKeyData: Data(bytes: keyData!, count: keyLen)) ? 1 : 0; +} + +fileprivate func store_sender_key(senderKeyName: UnsafePointer?, record: UnsafeMutablePointer?, recordLen: Int, userRecord: UnsafeMutablePointer?, userRecordLen: Int, userData: UnsafeMutableRawPointer?) -> CInt { + let senderKeyStore: SignalSenderKeyStoreProtocol = SignalContext.bridge(fromPointer: userData!) as! SignalSenderKeyStoreProtocol; + + var sender = senderKeyName?.pointee.sender; + let groupId = senderKeyName?.pointee.group_id; + let group = groupId != nil ? String(validatingUTF8: groupId!) : nil; + let addr = SignalAddress(from: &sender) + let key = Data(bytes: record!, count: recordLen); + + return senderKeyStore.storeSenderKey(key, address: addr, groupId: group) ? 0 : -1; +} + +fileprivate func load_sender_key(record: UnsafeMutablePointer?, userRecord: UnsafeMutablePointer?, senderKeyName: UnsafePointer?, userData: UnsafeMutableRawPointer?) -> CInt { + let senderKeyStore: SignalSenderKeyStoreProtocol = SignalContext.bridge(fromPointer: userData!) as! SignalSenderKeyStoreProtocol; + + var sender = senderKeyName?.pointee.sender; + let groupId = senderKeyName?.pointee.group_id; + let group = groupId != nil ? String(validatingUTF8: groupId!) : nil; + let addr = SignalAddress(from: &sender) + + if let key = senderKeyStore.loadSenderKey(forAddress: addr, groupId: group) { + key.withUnsafeBytes({ (bytes: UnsafeRawBufferPointer) -> Void in + let buffer = signal_buffer_create(bytes.baseAddress!.assumingMemoryBound(to: UInt8.self), key.count); + record?.initialize(to: buffer); + }); + return 1; + } else { + return 0; + } +} diff --git a/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/TigaseSwift_OMEMO.h b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/TigaseSwift_OMEMO.h new file mode 100644 index 0000000..2357a4d --- /dev/null +++ b/ThirdParty/MartinOMEMO/Sources/MartinOMEMO/TigaseSwift_OMEMO.h @@ -0,0 +1,37 @@ +// +// TigaseSwift_OMEMO.h +// +// TigaseSwift OMEMO +// Copyright (C) 2019 "Tigase, Inc." +// +// This program is free software: you can redistribute it and/or modify +// it under the terms of the GNU General Public License as published by +// the Free Software Foundation, either version 3 of the License, or +// (at your option) any later version. +// +// This program is distributed in the hope that it will be useful, +// but WITHOUT ANY WARRANTY; without even the implied warranty of +// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +// GNU General Public License for more details. +// +// You should have received a copy of the GNU General Public License +// along with this program. Look for COPYING file in the top folder. +// If not, see https://www.gnu.org/licenses/. +// +// + +#import "protocol.h" +#import "signal_protocol.h" +#import "key_helper.h" +#import "session_builder.h" +#import "session_cipher.h" + +//! Project version number for TigaseSwift_OMEMO. +//FOUNDATION_EXPORT double TigaseSwift_OMEMOVersionNumber; + +//! Project version string for TigaseSwift_OMEMO. +//FOUNDATION_EXPORT const unsigned char TigaseSwift_OMEMOVersionString[]; + +// In this header, you should import all the public headers of your framework using statements like #import + + diff --git a/ThirdParty/MartinOMEMO/Tests/LinuxMain.swift b/ThirdParty/MartinOMEMO/Tests/LinuxMain.swift new file mode 100644 index 0000000..effe3b6 --- /dev/null +++ b/ThirdParty/MartinOMEMO/Tests/LinuxMain.swift @@ -0,0 +1,7 @@ +import XCTest + +import MartinOMEMOTests + +var tests = [XCTestCaseEntry]() +tests += MartinOMEMOTests.allTests() +XCTMain(tests) diff --git a/ThirdParty/MartinOMEMO/Tests/MartinOMEMOTests/MartinOMEMOTests.swift b/ThirdParty/MartinOMEMO/Tests/MartinOMEMOTests/MartinOMEMOTests.swift new file mode 100644 index 0000000..2290bb5 --- /dev/null +++ b/ThirdParty/MartinOMEMO/Tests/MartinOMEMOTests/MartinOMEMOTests.swift @@ -0,0 +1,15 @@ +import XCTest +@testable import MartinOMEMO + +final class MartinOMEMOTests: XCTestCase { + func testExample() { + // This is an example of a functional test case. + // Use XCTAssert and related functions to verify your tests produce the correct + // results. + + } + + static var allTests = [ + ("testExample", testExample), + ] +} diff --git a/ThirdParty/MartinOMEMO/Tests/MartinOMEMOTests/XCTestManifests.swift b/ThirdParty/MartinOMEMO/Tests/MartinOMEMOTests/XCTestManifests.swift new file mode 100644 index 0000000..ba24694 --- /dev/null +++ b/ThirdParty/MartinOMEMO/Tests/MartinOMEMOTests/XCTestManifests.swift @@ -0,0 +1,9 @@ +import XCTest + +#if !canImport(ObjectiveC) +public func allTests() -> [XCTestCaseEntry] { + return [ + testCase(MartinOMEMOTests.allTests), + ] +} +#endif diff --git a/project.yml b/project.yml index 7894880..bf81831 100644 --- a/project.yml +++ b/project.yml @@ -31,8 +31,7 @@ packages: url: https://github.com/tigase/Martin.git exactVersion: 3.2.4 MartinOMEMO: - url: https://github.com/tigase/MartinOMEMO.git - exactVersion: 2.2.3 + path: ThirdParty/MartinOMEMO WebRTC: url: https://github.com/stasel/WebRTC.git exactVersion: 150.0.0