feat(M4): Windows WinForms client, TOFU identity pinning, VAD threshold + always-on mode
Core ABI extensions (voicecat.h):
- vc_list_channels / vc_list_users / vc_list_user_streams — pull-based snapshot getters
for the channel-tree and user-list UI; session_model_mu_ guards cross-thread reads
- VC_EVENT_JOIN_RESULT / vc_join_channel — channel join with optional password
- VC_EVENT_SERVER_IDENTITY + vc_confirm_server_identity — TOFU gate that blocks io_thread_
until the UI approves or rejects; pins TLS leaf-cert SHA-256 (not declared Ed25519)
- vc_get_server_identity_display — Ed25519 fingerprint for human-readable display only
- VC_INPUT_ALWAYS_ON = 2 in vc_input_mode — transmit unconditionally, no VAD gate
- vc_set_vad_threshold — live RMS threshold update (0.0–1.0); EnergyVadProcessor stores
it atomically so the audio RT path reads without a lock
C++ implementation:
- SessionModel::apply_snapshot / apply_channel_event fixed to populate parent_id,
password_protected, and max_users (were permanently zeroed)
- TlsContext::peer_cert_fingerprint — SHA-256 of peer leaf cert DER via mbedTLS
- TofuStore split into peek (read-only) + pin (write) so first-connect only persists
after user approval; tofu_store_path in vc_config for per-user pin file location
- TcpAcceptor uses dual-stack IPv6+IPv4 fallback (fixes localhost → ::1 on Windows)
- windows-client CMake preset: Release shared DLL, static MinGW runtime, no tools/tests
- New C++ tests: test_channel_user_list_abi, test_tofu_flow (14/14 green)
Windows client (clients/windows/ — .NET 10 WinForms):
- VoiceCat.Interop: LibraryImport P/Invoke surface, UnmanagedCallersOnly callbacks,
Channel<VoiceCatEvent> event delivery drained by 30ms WinForms Timer
- VoiceCat.App: ConnectDialog (saved servers, DPAPI password storage), ServerIdentity-
Dialog (TOFU first-connect / mismatch warning), MainForm (channel TreeView, user
ListBox, RichTextBox chat, voice controls, device pickers, VAD/PTT/always-on mode,
per-user gain/mute/NR tuning, VAD sensitivity TrackBar, level meter ProgressBar)
- PttKeyCaptureDialog — focus-scoped PTT key capture (documented limitation)
- PerUserTuningDialog — real-time gain/mute/NR applied to all of a user's streams
- Accessibility: explicit AccessibleName/Description on every control, & mnemonics,
Activity log ListBox as durable screen-reader record, AutomationNotification for
curated live announcements
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-17 00:35:16 +02:00
|
|
|
using VoiceCat.Interop;
|
|
|
|
|
|
|
|
|
|
namespace VoiceCat.App.Forms;
|
|
|
|
|
|
|
|
|
|
/// <summary>
|
chore: comment cleanup pass ahead of open-sourcing
Removes leftover debug scaffolding (stray Console.WriteLine/NSLog traces,
dead nick_buf_ptr, a no-op --print-config flag now implemented for real),
fixes stale/misleading comments (channel passwords are no longer a "future
M5+" feature, a wrong cross-reference, a stale TlsContext::close() mention,
an incomplete BanRecord::subject_type doc, and a smoke test pointing at a
build/m1-dev preset that no longer exists), strips internal M1-M5 milestone
jargon from comments now that the roadmap is done, trims comments that just
restated the following line, and consolidates a few "why" explanations that
were duplicated 2-3 times in the same file.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-03 10:20:18 +01:00
|
|
|
/// TOFU server-identity confirmation. Shown only for VcTofuStatus.FirstConnect/Mismatch
|
feat(M4): Windows WinForms client, TOFU identity pinning, VAD threshold + always-on mode
Core ABI extensions (voicecat.h):
- vc_list_channels / vc_list_users / vc_list_user_streams — pull-based snapshot getters
for the channel-tree and user-list UI; session_model_mu_ guards cross-thread reads
- VC_EVENT_JOIN_RESULT / vc_join_channel — channel join with optional password
- VC_EVENT_SERVER_IDENTITY + vc_confirm_server_identity — TOFU gate that blocks io_thread_
until the UI approves or rejects; pins TLS leaf-cert SHA-256 (not declared Ed25519)
- vc_get_server_identity_display — Ed25519 fingerprint for human-readable display only
- VC_INPUT_ALWAYS_ON = 2 in vc_input_mode — transmit unconditionally, no VAD gate
- vc_set_vad_threshold — live RMS threshold update (0.0–1.0); EnergyVadProcessor stores
it atomically so the audio RT path reads without a lock
C++ implementation:
- SessionModel::apply_snapshot / apply_channel_event fixed to populate parent_id,
password_protected, and max_users (were permanently zeroed)
- TlsContext::peer_cert_fingerprint — SHA-256 of peer leaf cert DER via mbedTLS
- TofuStore split into peek (read-only) + pin (write) so first-connect only persists
after user approval; tofu_store_path in vc_config for per-user pin file location
- TcpAcceptor uses dual-stack IPv6+IPv4 fallback (fixes localhost → ::1 on Windows)
- windows-client CMake preset: Release shared DLL, static MinGW runtime, no tools/tests
- New C++ tests: test_channel_user_list_abi, test_tofu_flow (14/14 green)
Windows client (clients/windows/ — .NET 10 WinForms):
- VoiceCat.Interop: LibraryImport P/Invoke surface, UnmanagedCallersOnly callbacks,
Channel<VoiceCatEvent> event delivery drained by 30ms WinForms Timer
- VoiceCat.App: ConnectDialog (saved servers, DPAPI password storage), ServerIdentity-
Dialog (TOFU first-connect / mismatch warning), MainForm (channel TreeView, user
ListBox, RichTextBox chat, voice controls, device pickers, VAD/PTT/always-on mode,
per-user gain/mute/NR tuning, VAD sensitivity TrackBar, level meter ProgressBar)
- PttKeyCaptureDialog — focus-scoped PTT key capture (documented limitation)
- PerUserTuningDialog — real-time gain/mute/NR applied to all of a user's streams
- Accessibility: explicit AccessibleName/Description on every control, & mnemonics,
Activity log ListBox as durable screen-reader record, AutomationNotification for
curated live announcements
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-17 00:35:16 +02:00
|
|
|
/// — never Matched (that's the silent-success "subsequent connects verify the pin" path
|
|
|
|
|
/// docs/security.md describes; showing a dialog on every routine reconnect would be exactly
|
|
|
|
|
/// the "overly chatty" experience this project avoids elsewhere too).
|
|
|
|
|
/// DialogResult.OK = accept (and the caller should call ConfirmServerIdentity(true) and, for
|
|
|
|
|
/// FirstConnect/Mismatch, the core persists the new pin); DialogResult.Cancel = reject.
|
|
|
|
|
/// </summary>
|
|
|
|
|
public partial class ServerIdentityDialog : Form
|
|
|
|
|
{
|
|
|
|
|
public ServerIdentityDialog(VcTofuStatus status, string certFingerprintHex, string identityDisplayHex)
|
|
|
|
|
{
|
|
|
|
|
InitializeComponent();
|
|
|
|
|
|
|
|
|
|
string formattedCertFp = FormatFingerprint(certFingerprintHex);
|
|
|
|
|
string formattedIdentityFp = string.IsNullOrEmpty(identityDisplayHex)
|
|
|
|
|
? "(not yet available)"
|
|
|
|
|
: FormatFingerprint(identityDisplayHex);
|
|
|
|
|
|
|
|
|
|
if (status == VcTofuStatus.Mismatch)
|
|
|
|
|
{
|
|
|
|
|
Text = "WARNING: Server identity changed";
|
|
|
|
|
lblWarning.Text =
|
|
|
|
|
"WARNING: This server's identity has CHANGED since you last connected.\r\n\r\n" +
|
|
|
|
|
"This could mean the server was reinstalled, OR that someone is intercepting " +
|
|
|
|
|
"your connection. If you did not expect this server's identity to change, " +
|
|
|
|
|
"choose Cancel.";
|
|
|
|
|
lblFingerprint.Text = $"New certificate fingerprint:\r\n{formattedCertFp}\r\n\r\n" +
|
|
|
|
|
$"Server also identifies as:\r\n{formattedIdentityFp}";
|
|
|
|
|
btnAccept.Text = "&Trust the new identity anyway";
|
|
|
|
|
}
|
|
|
|
|
else
|
|
|
|
|
{
|
|
|
|
|
Text = "New server — verify identity";
|
|
|
|
|
lblWarning.Text =
|
|
|
|
|
"You have not connected to this server before. If you have verified its " +
|
|
|
|
|
"fingerprint with the server operator through another channel, choose Trust " +
|
|
|
|
|
"and connect. Otherwise, choose Cancel.";
|
|
|
|
|
lblFingerprint.Text = $"Certificate fingerprint:\r\n{formattedCertFp}\r\n\r\n" +
|
|
|
|
|
$"Server also identifies as:\r\n{formattedIdentityFp}";
|
|
|
|
|
btnAccept.Text = "&Trust and connect";
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
protected override void OnShown(EventArgs e)
|
|
|
|
|
{
|
|
|
|
|
base.OnShown(e);
|
|
|
|
|
// Force a screen reader to read the warning text immediately on dialog activation,
|
|
|
|
|
// rather than landing focus straight on a button and silently skipping it.
|
|
|
|
|
lblWarning.Focus();
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
private static string FormatFingerprint(string hex)
|
|
|
|
|
{
|
|
|
|
|
// Groups of 4 hex chars, like a product key — easier to read/dictate/compare than one
|
|
|
|
|
// unbroken 64-character string.
|
|
|
|
|
var groups = new List<string>();
|
|
|
|
|
for (int i = 0; i < hex.Length; i += 4)
|
|
|
|
|
groups.Add(hex.Substring(i, Math.Min(4, hex.Length - i)));
|
|
|
|
|
return string.Join(' ', groups);
|
|
|
|
|
}
|
|
|
|
|
}
|