-
-
Notifications
You must be signed in to change notification settings - Fork 2.1k
Un-authable membership events can corrupt HS room state (SYN-735) #1571
Comments
Links exported from Jira: relates to #1574 |
From Dylanger:
So Dylanger has convinced his own HS that he has admin, and used that to generate a kick event, which has then been sent to Yaniel's, which has then accepted the kick despite the broken auth chain. -- @richvdh |
I think the spoofed event ID here is $14691813430ugbai:onedefence.com -- @dbkr |
From [~erikj]:
-- @richvdh |
This is probably #1935 |
hrm... maybe not. |
I'm reasonably sure this has been fixed by things like #10225. |
See https://vector.im/develop/#/room/!DgvjtOljKujDBrxyHk:matrix.org/$1469181498665GNapO:kolm.io for scrollback of me trying to figure out why Yaniel can't speak in Matrix HQ.
Matrix.org seemed to get a consistent membership event for him but his HS is having none of it and will not let him join nor leave. I see a lot of the classic, "Event content has been tampered, redacting" log lines on both servers (and not for the un-authable event).
(Imported from https://matrix.org/jira/browse/SYN-735)
(Reported by @dbkr)
The text was updated successfully, but these errors were encountered: