Skip to content

Allow resigning of events with a new signing key - #19668

Merged
sandhose merged 13 commits into
developfrom
quenting/resign-background-update
Apr 14, 2026
Merged

Allow resigning of events with a new signing key#19668
sandhose merged 13 commits into
developfrom
quenting/resign-background-update

Conversation

@sandhose

@sandhose sandhose commented Apr 8, 2026

Copy link
Copy Markdown
Member

This adds a way to re-sign all locally-created events with a new signing key, which is useful when rotating server signing keys.

This doesn't trigger automatically, instead needs to be triggered when needed via the admin API.

c.f. https://github.com/matrix-org/internal-config/issues/1670#issuecomment-4206020126 for internal discussion.

@sandhose
sandhose requested a review from a team as a code owner April 8, 2026 11:41
@sandhose
sandhose force-pushed the quenting/resign-background-update branch from 73940ac to c6cde8d Compare April 8, 2026 11:44
sandhose and others added 4 commits April 8, 2026 13:46
Add `resign_event` and `event_needs_resigning` utility functions to
`event_signing.py`, and a `_resign_events` background update handler
that iterates through locally-sent events and re-signs any that aren't
signed with the current signing key.

Co-Authored-By: Kegan Dougall <kegan@element.io>
Co-Authored-By: Erik Johnston <erikj@element.io>
Allow admins to trigger the event re-signing background update via
POST /_synapse/admin/v1/background_updates/start_job with
job_name "event_resign".
Add unit tests for `resign_event` and `event_needs_resigning` in
test_event_signing.py, and an integration test for the event_resign
background update in test_events_bg_updates.py.
@sandhose
sandhose force-pushed the quenting/resign-background-update branch from c6cde8d to 4a6e6d5 Compare April 8, 2026 11:49
Comment thread synapse/storage/databases/main/events_bg_updates.py Outdated
Comment thread synapse/crypto/event_signing.py
sandhose added 3 commits April 8, 2026 15:58
Use -(1 << 31) as the initial stream position instead of 0, matching
the precedent set by POPULATE_STREAM_ORDERING2. This ensures events
with negative stream orderings (from backfill) are also covered.
Allow filtering which events to re-sign:
- old_key_id: only re-sign events signed with a specific key (filtered
  in Python since signatures are stored as JSON)
- before_ts: only re-sign events with received_ts < value (filtered in
  SQL alongside the existing stream_ordering scan)

These parameters are passed through the admin API POST body and
preserved in the background update progress across batches.
Comment thread synapse/storage/databases/main/events_bg_updates.py
sandhose and others added 2 commits April 8, 2026 16:54
Instead of matching on the key ID string, accept the full public key
(format: "algorithm:key_id base64key") and verify the event signature
against it. This is more secure as it ensures we only re-sign events
genuinely signed by the specified key.

Events without a signature for the key ID are fast-path skipped.
A warning is logged if a signature exists but fails verification.
Co-authored-by: Erik Johnston <erikj@element.io>
@sandhose
sandhose force-pushed the quenting/resign-background-update branch from 4f9eade to 7521e11 Compare April 8, 2026 15:00
@sandhose
sandhose requested a review from erikjohnston April 8, 2026 15:02
Comment thread synapse/storage/databases/main/events_bg_updates.py Outdated
@sandhose
sandhose enabled auto-merge (squash) April 13, 2026 13:56
@reivilibre reivilibre self-assigned this Apr 14, 2026
@sandhose
sandhose merged commit bed00bb into develop Apr 14, 2026
82 of 84 checks passed
@sandhose
sandhose deleted the quenting/resign-background-update branch April 14, 2026 16:44
FrenchGithubUser pushed a commit to famedly/synapse-upstreaming that referenced this pull request Jun 12, 2026
This adds a way to re-sign all locally-created events with a new signing
key, which is useful when rotating server signing keys.

This doesn't trigger automatically, instead needs to be triggered when
needed via the admin API.

c.f.
https://github.com/matrix-org/internal-config/issues/1670#issuecomment-4206020126
for internal discussion.

---------

Co-authored-by: Kegan Dougall <kegan@element.io>
Co-authored-by: Erik Johnston <erikj@element.io>
netbsd-srcmastr pushed a commit to NetBSD/pkgsrc that referenced this pull request Jul 7, 2026
Tested on NetBSD 10 amd64 with 2026Q2 environment.

# Synapse 1.156.0 (2026-07-07)

## Features

- Expose [MSC4354 Sticky Events](matrix-org/matrix-spec-proposals#4354) over [MSC4186 (Simplified) Sliding Sync](matrix-org/matrix-spec-proposals#4186). ([\#19591](element-hq/synapse#19591))
- Stabilize support for sending ephemeral events to application services, as per [MSC2409](matrix-org/matrix-spec-proposals#2409). Contributed by @jason-famedly @ Famedly. ([\#19758](element-hq/synapse#19758))
- Include `allowed_room_ids` in the `/summary` client-server API response for rooms with restricted join rules, as required by Matrix 1.15.
  Contributed by @FrenchGithubUser @famedly. ([\#19762](element-hq/synapse#19762))
- [MSC4140: Cancellable delayed events](matrix-org/matrix-spec-proposals#4140): Allow authentication on delayed event management endpoints (such as `/restart`) to bypass ratelimits for unauthenticated requests based on the client IP address. ([\#19794](element-hq/synapse#19794))
- Add new metric `synapse_non_deactivated_user_count` which tracks the number of non-deactivated users in the database, split by `app_service`. ([\#19848](element-hq/synapse#19848))
- The `GET /_matrix/client/unstable/org.matrix.msc1763/retention/configuration` endpoint is now provided when retention
  is enabled and `experimental_features.msc1763_enabled` is enabled, based on
  [MSC1763](matrix-org/matrix-spec-proposals#1763). ([\#19853](element-hq/synapse#19853))
- Add experimental support for [MSC4491: Invite reasons in room creation](matrix-org/matrix-spec-proposals#4491). ([\#19874](element-hq/synapse#19874))


# Synapse 1.155.0 (2026-06-16)


# Synapse 1.154.0 (2026-06-04)

## Features

- Add support for [MSC4452: Preview URL capabilities API](matrix-org/matrix-spec-proposals#4452) which exposes a `io.element.msc4452.preview_url` capability.
  If `experimental_features.msc4452_enabled` is `true`, the `/_matrix/(client/v1/media|media/v3)/preview_url` endpoint
  now responds with a 403 status code when the capability is disabled. ([\#19715](element-hq/synapse#19715))


# Synapse 1.153.0 (2026-05-19)

## Features

- Make ACLs apply to EDUs per [MSC4163](matrix-org/matrix-spec-proposals#4163). ([\#18475](element-hq/synapse#18475))
- Stabilize [MSC3266: Room summary API](matrix-org/matrix-spec-proposals#3266), removing the experimental config flag `msc3266_enabled`. Contributed by @dasha-uwu. ([\#19720](element-hq/synapse#19720))
- Partial [MSC4311](matrix-org/matrix-spec-proposals#4311) implementation: `m.room.create` is now a required part of stripped `invite_state`/`knock_state` . Contributed by @FrenchGithubUser @famedly. ([\#19722](element-hq/synapse#19722))
- Expose `tombstoned` and `replacement_room` in room details on admin API endpoint `GET /_synapse/admin/v1/rooms/<room_id>`. Contributed by Noah Markert. ([\#19737](element-hq/synapse#19737))


# Synapse 1.152.1 (2026-05-07)


# Synapse 1.152.0 (2026-04-28)

## Features

- Add a ["Listing quarantined media changes" Admin API](https://element-hq.github.io/synapse/latest/admin_api/media_admin_api.html#listing-quarantined-media-changes) for retrieving a paginated record of when media became (un)quarantined. ([\#19558](element-hq/synapse#19558), [\#19677](element-hq/synapse#19677), [\#19694](element-hq/synapse#19694))
- Advertise [MSC4445](matrix-org/matrix-spec-proposals#4445) sync timeline order in `unstable_features`. ([\#19642](element-hq/synapse#19642))
- Report the Rust compiler version used in the Prometheus metrics. Contributed by Noah Markert. ([\#19643](element-hq/synapse#19643))
- Passthrough 'article' and 'profile' OpenGraph metadata on URL preview requests. ([\#19659](element-hq/synapse#19659))
- Add a way to re-sign local events with a new signing key. ([\#19668](element-hq/synapse#19668))
- Support [MSC4450: Identity Provider selection for User-Interactive Authentication with Legacy Single Sign-On](matrix-org/matrix-spec-proposals#4450). ([\#19693](element-hq/synapse#19693))
- Add experimental support for [MSC4242](matrix-org/matrix-spec-proposals#4242): State DAGs. Excludes federation support. ([\#19424](element-hq/synapse#19424))
- Adds [Admin API](https://element-hq.github.io/synapse/latest/usage/administration/admin_api/index.html) endpoints to
  list, fetch and delete user reports. ([\#19657](element-hq/synapse#19657))
- Reduce database disk space usage by pruning old rows from `device_lists_changes_in_room`. ([\#19473](element-hq/synapse#19473), [\#19709](element-hq/synapse#19709))


# Synapse 1.151.0 (2026-04-07)

## Features

- Add stable support for [MSC4284](matrix-org/matrix-spec-proposals#4284) Policy Servers. ([\#19503](element-hq/synapse#19503))
- Update and stabilize support for [MSC2666](matrix-org/matrix-spec-proposals#2666): Get rooms in common with another user. Contributed by @tulir @ Beeper. ([\#19511](element-hq/synapse#19511))
- Updated experimental support for [MSC4388: Secure out-of-band channel for sign in with QR](matrix-org/matrix-spec-proposals#4388). ([\#19573](element-hq/synapse#19573))
- Stabilize `room_version` and `encryption` fields in the space/room `/hierarchy` API (part of [MSC3266](matrix-org/matrix-spec-proposals#3266)). ([\#19576](element-hq/synapse#19576))
- Introduce a [configuration option](https://element-hq.github.io/synapse/latest/usage/configuration/config_documentation.html#matrix_authentication_service) to allow using HTTP/2 over plaintext when Synapse connects to Matrix Authentication Service. ([\#19586](element-hq/synapse#19586))

## Deprecations and Removals

- Remove support for [MSC3852: Expose user agent information on Device](matrix-org/matrix-spec-proposals#3852) as the MSC was closed. ([\#19430](element-hq/synapse#19430))


# Synapse 1.150.0 (2026-03-24)

## Features

- Add experimental support for the [MSC4370](matrix-org/matrix-spec-proposals#4370) Federation API `GET /extremities` endpoint. ([\#19314](element-hq/synapse#19314))
- [MSC4140: Cancellable delayed events](matrix-org/matrix-spec-proposals#4140): When persisting a delayed event to the timeline, include its `delay_id` in the event's `unsigned` section in `/sync` responses to the event sender. ([\#19479](element-hq/synapse#19479))
- Expose [MSC4354 Sticky Events](matrix-org/matrix-spec-proposals#4354) over the legacy (v3) /sync API. ([\#19487](element-hq/synapse#19487))
- When Matrix Authentication Service (MAS) integration is enabled, allow MAS to set the user locked status in Synapse. ([\#19554](element-hq/synapse#19554))
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants