feat(M1): TCP/TLS control plane -- auth, channels, ephemeral text
Implements the full M1 milestone. Two clients authenticate over TLS 1.3
(guest + Argon2id password) and exchange channel + private text messages
through a real server. All five ctest --preset m1-dev tests pass in ~1 s.
Key components added:
- vcpkg baseline + m1-dev preset (protobuf/mbedTLS/libsodium/asio/sqlite3)
- FrameCodec feed+emit, encode/decode_envelope, protobuf codegen
- TcpServerConn with blocking TLS handshake thread + tls_read_loop
- TlsContext (mbedTLS 1.3, ECDSA-P256 self-signed cert, TOFU on client)
- WorkerPool (3 threads, used for Argon2id)
- Database: SQLite + libsodium Argon2id, account lifecycle, bootstrap admin
- ServerIdentityManager: Ed25519 key + cert generate/persist/fingerprint
- ConnSession state machine: WaitingHello -> WaitingAuth -> Authenticated
- SessionRegistry: channel tree, user map, text routing, broadcast
- vc_client full M1 C ABI: connect/TLS/handshake/auth/text/disconnect
- voicecat-admin CLI: account add/reset/del/list
- test_m1_integration: M1 exit criterion, verified green
Bug fixed: double-framing in ConnSession::send_envelope -- encode_envelope
was adding the [4-byte len] prefix, then TcpServerConn::send_frame added
a second one, causing the client to parse [len][proto] as protobuf (silent
failure). Fixed by serializing raw protobuf bytes in send_envelope and
letting send_frame apply the single length prefix.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-15 23:48:44 +02:00
|
|
|
# Tests use plain asserts + exit codes (no framework dep needed).
|
|
|
|
|
# Behavior tests — not just "it compiles" — are how milestones are judged (AGENTS.md).
|
scaffold: M0 skeleton + agent onboarding (build, architecture, progress)
Turn the design into a buildable, dependency-free M0 skeleton plus the
onboarding layer so a new agent can pick up instantly.
Build system:
- CMake + CMakePresets (dev = no deps; server-release = vcpkg) + vcpkg.json
- Skeleton builds with just a C++20 compiler; deps stay off until needed
- .gitattributes (LF), .gitignore, .clang-format
Core (libvoicecat):
- core/include/voicecat.h: full C ABI (the client/server contract), stubbed
- core/proto/voicecat.proto: control-plane wire format, matches docs/protocol.md
- src/{net,crypto,codec,protocol,session,audio,core}: subsystem stubs that
return VC_ERR_NOT_IMPLEMENTED, each pointing to its design doc
- server/ (voicecat-server) and tools/vccli/ link the core
- tests/: CTest smoke test asserting the C ABI contract (behavior, not just build)
- clients/{apple,windows}: M4 placeholders
Onboarding for agents:
- CLAUDE.md: hub — build/test commands, architecture at a glance, doc map, rules
- AGENTS.md: working method (behavior-driven; clean compile is the floor not the goal)
- PROGRESS.md: living tracker — M0 done, M1 task checklist, "where we left off"
Verified: cmake --preset dev && cmake --build --preset dev && ctest --preset dev → green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-15 21:09:09 +02:00
|
|
|
|
|
|
|
|
add_executable(test_smoke test_smoke.cpp)
|
|
|
|
|
target_link_libraries(test_smoke PRIVATE voicecat::voicecat)
|
|
|
|
|
target_compile_features(test_smoke PRIVATE cxx_std_20)
|
|
|
|
|
add_test(NAME smoke COMMAND test_smoke)
|
feat(M1): TCP/TLS control plane -- auth, channels, ephemeral text
Implements the full M1 milestone. Two clients authenticate over TLS 1.3
(guest + Argon2id password) and exchange channel + private text messages
through a real server. All five ctest --preset m1-dev tests pass in ~1 s.
Key components added:
- vcpkg baseline + m1-dev preset (protobuf/mbedTLS/libsodium/asio/sqlite3)
- FrameCodec feed+emit, encode/decode_envelope, protobuf codegen
- TcpServerConn with blocking TLS handshake thread + tls_read_loop
- TlsContext (mbedTLS 1.3, ECDSA-P256 self-signed cert, TOFU on client)
- WorkerPool (3 threads, used for Argon2id)
- Database: SQLite + libsodium Argon2id, account lifecycle, bootstrap admin
- ServerIdentityManager: Ed25519 key + cert generate/persist/fingerprint
- ConnSession state machine: WaitingHello -> WaitingAuth -> Authenticated
- SessionRegistry: channel tree, user map, text routing, broadcast
- vc_client full M1 C ABI: connect/TLS/handshake/auth/text/disconnect
- voicecat-admin CLI: account add/reset/del/list
- test_m1_integration: M1 exit criterion, verified green
Bug fixed: double-framing in ConnSession::send_envelope -- encode_envelope
was adding the [4-byte len] prefix, then TcpServerConn::send_frame added
a second one, causing the client to parse [len][proto] as protobuf (silent
failure). Fixed by serializing raw protobuf bytes in send_envelope and
letting send_frame apply the single length prefix.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-15 23:48:44 +02:00
|
|
|
|
|
|
|
|
# frame_codec has no third-party deps; runs under both dev and m1-dev.
|
|
|
|
|
# Needs core/src on the include path to reach internal headers (protocol/, session/, etc.).
|
|
|
|
|
add_executable(test_frame_codec test_frame_codec.cpp)
|
|
|
|
|
target_link_libraries(test_frame_codec PRIVATE voicecat::voicecat)
|
|
|
|
|
target_compile_features(test_frame_codec PRIVATE cxx_std_20)
|
|
|
|
|
target_include_directories(test_frame_codec PRIVATE ${CMAKE_SOURCE_DIR}/core/src)
|
|
|
|
|
add_test(NAME frame_codec COMMAND test_frame_codec)
|
|
|
|
|
|
|
|
|
|
if(VOICECAT_USE_VCPKG_DEPS)
|
|
|
|
|
set(VC_TEST_INTERNAL_INCLUDES
|
|
|
|
|
${CMAKE_SOURCE_DIR}/core/src
|
|
|
|
|
${CMAKE_SOURCE_DIR}/server/src
|
|
|
|
|
${CMAKE_BINARY_DIR}/core/generated) # protobuf-generated headers
|
|
|
|
|
|
|
|
|
|
add_executable(test_envelope test_envelope.cpp)
|
|
|
|
|
target_link_libraries(test_envelope PRIVATE voicecat::voicecat)
|
|
|
|
|
target_compile_features(test_envelope PRIVATE cxx_std_20)
|
|
|
|
|
target_include_directories(test_envelope PRIVATE ${VC_TEST_INTERNAL_INCLUDES})
|
|
|
|
|
add_test(NAME envelope COMMAND test_envelope)
|
|
|
|
|
|
|
|
|
|
add_executable(test_tls_loopback test_tls_loopback.cpp)
|
|
|
|
|
target_link_libraries(test_tls_loopback PRIVATE voicecat::voicecat)
|
|
|
|
|
target_compile_features(test_tls_loopback PRIVATE cxx_std_20)
|
|
|
|
|
target_include_directories(test_tls_loopback PRIVATE ${VC_TEST_INTERNAL_INCLUDES})
|
|
|
|
|
add_test(NAME tls_loopback COMMAND test_tls_loopback)
|
|
|
|
|
|
|
|
|
|
# Links voicecat::server (which pulls in voicecat::voicecat + all deps transitively).
|
|
|
|
|
add_executable(test_m1_integration test_m1_integration.cpp)
|
|
|
|
|
target_link_libraries(test_m1_integration PRIVATE voicecat::server)
|
|
|
|
|
target_compile_features(test_m1_integration PRIVATE cxx_std_20)
|
|
|
|
|
target_include_directories(test_m1_integration PRIVATE ${VC_TEST_INTERNAL_INCLUDES})
|
|
|
|
|
add_test(NAME m1_integration COMMAND test_m1_integration)
|
|
|
|
|
set_tests_properties(m1_integration PROPERTIES TIMEOUT 60)
|
feat(M2): UDP voice/media plane -- SFU relay, Opus, AEAD, jitter buffer
Adds the full voice pipeline: 14-byte binary frame header, ChaCha20-Poly1305
AEAD keyed from the TLS exporter, libopus encode/decode with FEC/PLC/DTX,
an adaptive per-ssrc jitter buffer, a miniaudio capture/playback engine, an
APM passthrough stub, and the UdpBinding/StreamAnnounce signaling chain
wired through ConnSession/SessionRegistry into a new server-side SFU
(MediaRelay) that decrypts and re-encrypts frames per channel member.
Exit criterion verified: test_m2_voice — two headless clients relay 50
encrypted Opus frames through the server; ctest --preset m1-dev is 9/9
green. Also corrects protocol.md's UdpBinding diagram, which described the
UDP-side binding packet as AEAD-sealed when it is in fact a plaintext
bootstrap frame (separate from the TCP/TLS UdpBinding ack).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-16 01:31:14 +02:00
|
|
|
|
|
|
|
|
# ── M2 unit tests ──────────────────────────────────────────────────────────
|
|
|
|
|
|
|
|
|
|
add_executable(test_voice_frame test_voice_frame.cpp)
|
|
|
|
|
target_link_libraries(test_voice_frame PRIVATE voicecat::voicecat)
|
|
|
|
|
target_compile_features(test_voice_frame PRIVATE cxx_std_20)
|
|
|
|
|
target_include_directories(test_voice_frame PRIVATE ${VC_TEST_INTERNAL_INCLUDES})
|
|
|
|
|
add_test(NAME voice_frame COMMAND test_voice_frame)
|
|
|
|
|
|
|
|
|
|
add_executable(test_media_aead test_media_aead.cpp)
|
|
|
|
|
target_link_libraries(test_media_aead PRIVATE voicecat::voicecat)
|
|
|
|
|
target_compile_features(test_media_aead PRIVATE cxx_std_20)
|
|
|
|
|
target_include_directories(test_media_aead PRIVATE ${VC_TEST_INTERNAL_INCLUDES})
|
|
|
|
|
add_test(NAME media_aead COMMAND test_media_aead)
|
|
|
|
|
|
|
|
|
|
add_executable(test_opus_codec test_opus_codec.cpp)
|
|
|
|
|
target_link_libraries(test_opus_codec PRIVATE voicecat::voicecat)
|
|
|
|
|
target_compile_features(test_opus_codec PRIVATE cxx_std_20)
|
|
|
|
|
target_include_directories(test_opus_codec PRIVATE ${VC_TEST_INTERNAL_INCLUDES})
|
|
|
|
|
add_test(NAME opus_codec COMMAND test_opus_codec)
|
|
|
|
|
|
|
|
|
|
# M2 exit criterion: two headless clients relay encrypted Opus frames via the SFU.
|
|
|
|
|
add_executable(test_m2_voice test_m2_voice.cpp)
|
|
|
|
|
target_link_libraries(test_m2_voice PRIVATE voicecat::server)
|
|
|
|
|
target_compile_features(test_m2_voice PRIVATE cxx_std_20)
|
|
|
|
|
target_include_directories(test_m2_voice PRIVATE ${VC_TEST_INTERNAL_INCLUDES})
|
|
|
|
|
add_test(NAME m2_voice COMMAND test_m2_voice)
|
|
|
|
|
set_tests_properties(m2_voice PROPERTIES TIMEOUT 120)
|
2026-06-16 02:12:50 +02:00
|
|
|
|
|
|
|
|
# Same exit criterion, but through the real C ABI (vc_client), not raw sockets —
|
|
|
|
|
# proves stream_start/stop/UDP-binding in core/src/core/client.cpp actually work.
|
|
|
|
|
add_executable(test_voice_client_abi test_voice_client_abi.cpp)
|
|
|
|
|
target_link_libraries(test_voice_client_abi PRIVATE voicecat::server)
|
|
|
|
|
target_compile_features(test_voice_client_abi PRIVATE cxx_std_20)
|
|
|
|
|
target_include_directories(test_voice_client_abi PRIVATE ${VC_TEST_INTERNAL_INCLUDES})
|
|
|
|
|
add_test(NAME voice_client_abi COMMAND test_voice_client_abi)
|
|
|
|
|
set_tests_properties(voice_client_abi PROPERTIES TIMEOUT 60)
|
feat(M1): TCP/TLS control plane -- auth, channels, ephemeral text
Implements the full M1 milestone. Two clients authenticate over TLS 1.3
(guest + Argon2id password) and exchange channel + private text messages
through a real server. All five ctest --preset m1-dev tests pass in ~1 s.
Key components added:
- vcpkg baseline + m1-dev preset (protobuf/mbedTLS/libsodium/asio/sqlite3)
- FrameCodec feed+emit, encode/decode_envelope, protobuf codegen
- TcpServerConn with blocking TLS handshake thread + tls_read_loop
- TlsContext (mbedTLS 1.3, ECDSA-P256 self-signed cert, TOFU on client)
- WorkerPool (3 threads, used for Argon2id)
- Database: SQLite + libsodium Argon2id, account lifecycle, bootstrap admin
- ServerIdentityManager: Ed25519 key + cert generate/persist/fingerprint
- ConnSession state machine: WaitingHello -> WaitingAuth -> Authenticated
- SessionRegistry: channel tree, user map, text routing, broadcast
- vc_client full M1 C ABI: connect/TLS/handshake/auth/text/disconnect
- voicecat-admin CLI: account add/reset/del/list
- test_m1_integration: M1 exit criterion, verified green
Bug fixed: double-framing in ConnSession::send_envelope -- encode_envelope
was adding the [4-byte len] prefix, then TcpServerConn::send_frame added
a second one, causing the client to parse [len][proto] as protobuf (silent
failure). Fixed by serializing raw protobuf bytes in send_envelope and
letting send_frame apply the single length prefix.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-15 23:48:44 +02:00
|
|
|
endif()
|