scaffold: M0 skeleton + agent onboarding (build, architecture, progress)
Turn the design into a buildable, dependency-free M0 skeleton plus the
onboarding layer so a new agent can pick up instantly.
Build system:
- CMake + CMakePresets (dev = no deps; server-release = vcpkg) + vcpkg.json
- Skeleton builds with just a C++20 compiler; deps stay off until needed
- .gitattributes (LF), .gitignore, .clang-format
Core (libvoicecat):
- core/include/voicecat.h: full C ABI (the client/server contract), stubbed
- core/proto/voicecat.proto: control-plane wire format, matches docs/protocol.md
- src/{net,crypto,codec,protocol,session,audio,core}: subsystem stubs that
return VC_ERR_NOT_IMPLEMENTED, each pointing to its design doc
- server/ (voicecat-server) and tools/vccli/ link the core
- tests/: CTest smoke test asserting the C ABI contract (behavior, not just build)
- clients/{apple,windows}: M4 placeholders
Onboarding for agents:
- CLAUDE.md: hub — build/test commands, architecture at a glance, doc map, rules
- AGENTS.md: working method (behavior-driven; clean compile is the floor not the goal)
- PROGRESS.md: living tracker — M0 done, M1 task checklist, "where we left off"
Verified: cmake --preset dev && cmake --build --preset dev && ctest --preset dev → green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-15 21:09:09 +02:00
|
|
|
|
/*
|
|
|
|
|
|
* voicecat.h — the C ABI for libvoicecat.
|
|
|
|
|
|
*
|
|
|
|
|
|
* This is the single boundary every front-end calls: Swift (macOS/iOS) and C# (Windows)
|
|
|
|
|
|
* both bind to this header, and the server links the same core. It is C-linkage and
|
|
|
|
|
|
* handle-based so it is stable and trivially bindable from any language.
|
|
|
|
|
|
*
|
|
|
|
|
|
* Design: docs/architecture.md §4. Everything here is async + event-driven — calls return
|
|
|
|
|
|
* immediately and results/state changes arrive via the vc_callbacks.on_event callback.
|
|
|
|
|
|
*
|
build(cmake): clean up presets, add release/apple presets, cross-platform triplets
Rationalize the preset set to match the project's actual state (past M5):
- Rename dev->skeleton (no-deps stub smoke), m1-dev->dev (default dev preset)
- Drop m2-dev (cache-identical to m1-dev)
- Add release preset (optimized + tests on, symbols kept)
- Strip server-release binaries (-s linker flag)
- Add apple-dev/apple-ios/apple-ios-sim scaffolding presets for XCFramework
Add cmake/voicecat-toolchain.cmake wrapper that auto-resolves the vcpkg
triplet from the host platform (x64-mingw-static/x64-linux/arm64-osx) so
the main presets work on Windows/Linux/macOS without per-OS variants.
Update all docs (building.md, CLAUDE.md, README.md, AGENTS.md, deployment.md,
tech-stack.md, client READMEs) and stale preset-name references in code
comments. No C++ behavior changes — the core was already portable.
2026-06-18 03:16:01 +02:00
|
|
|
|
* STATUS: real, behind VOICECAT_HAS_NET (the `dev`/`release`/`server-release` presets —
|
|
|
|
|
|
* vcpkg deps on; see docs/building.md). As of M3, control plane, voice, multi-stream, device
|
docs: add build/manual-testing guide, fix stale M0 stub claims in headers
- docs/building.md: explains what each CMake preset (dev, m1-dev, m2-dev,
server-release) is actually for, and how to build voicecat-server + vccli
for manual testing. Linked from CLAUDE.md's doc index.
- core/include/voicecat.h, core/src/voicecat.cpp, core/src/protocol/protocol.h,
server/src/main.cpp: doc-header comments still claimed M0-skeleton/stub
behavior (VC_ERR_NOT_IMPLEMENTED everywhere, "prints what it would do",
protobuf codegen "commented") that M1-M3 made real. Updated to describe
current behavior, with the dev-preset stub fallback noted explicitly where
it still applies.
2026-06-16 16:30:07 +02:00
|
|
|
|
* enumeration, VAD/PTT, and stereo playback all work for real via core/src/core/client.cpp.
|
build(cmake): clean up presets, add release/apple presets, cross-platform triplets
Rationalize the preset set to match the project's actual state (past M5):
- Rename dev->skeleton (no-deps stub smoke), m1-dev->dev (default dev preset)
- Drop m2-dev (cache-identical to m1-dev)
- Add release preset (optimized + tests on, symbols kept)
- Strip server-release binaries (-s linker flag)
- Add apple-dev/apple-ios/apple-ios-sim scaffolding presets for XCFramework
Add cmake/voicecat-toolchain.cmake wrapper that auto-resolves the vcpkg
triplet from the host platform (x64-mingw-static/x64-linux/arm64-osx) so
the main presets work on Windows/Linux/macOS without per-OS variants.
Update all docs (building.md, CLAUDE.md, README.md, AGENTS.md, deployment.md,
tech-stack.md, client READMEs) and stale preset-name references in code
comments. No C++ behavior changes — the core was already portable.
2026-06-18 03:16:01 +02:00
|
|
|
|
* The no-deps `skeleton` preset still links a stub vc_client that returns VC_ERR_NOT_IMPLEMENTED
|
docs: add build/manual-testing guide, fix stale M0 stub claims in headers
- docs/building.md: explains what each CMake preset (dev, m1-dev, m2-dev,
server-release) is actually for, and how to build voicecat-server + vccli
for manual testing. Linked from CLAUDE.md's doc index.
- core/include/voicecat.h, core/src/voicecat.cpp, core/src/protocol/protocol.h,
server/src/main.cpp: doc-header comments still claimed M0-skeleton/stub
behavior (VC_ERR_NOT_IMPLEMENTED everywhere, "prints what it would do",
protobuf codegen "commented") that M1-M3 made real. Updated to describe
current behavior, with the dev-preset stub fallback noted explicitly where
it still applies.
2026-06-16 16:30:07 +02:00
|
|
|
|
* for everything below `connect`, purely to keep that skeleton build green. webrtc AEC/NS/AGC
|
|
|
|
|
|
* remains an inert passthrough regardless of preset (no Windows/MSVC port upstream —
|
|
|
|
|
|
* docs/voice.md §8/§11, PROGRESS.md).
|
scaffold: M0 skeleton + agent onboarding (build, architecture, progress)
Turn the design into a buildable, dependency-free M0 skeleton plus the
onboarding layer so a new agent can pick up instantly.
Build system:
- CMake + CMakePresets (dev = no deps; server-release = vcpkg) + vcpkg.json
- Skeleton builds with just a C++20 compiler; deps stay off until needed
- .gitattributes (LF), .gitignore, .clang-format
Core (libvoicecat):
- core/include/voicecat.h: full C ABI (the client/server contract), stubbed
- core/proto/voicecat.proto: control-plane wire format, matches docs/protocol.md
- src/{net,crypto,codec,protocol,session,audio,core}: subsystem stubs that
return VC_ERR_NOT_IMPLEMENTED, each pointing to its design doc
- server/ (voicecat-server) and tools/vccli/ link the core
- tests/: CTest smoke test asserting the C ABI contract (behavior, not just build)
- clients/{apple,windows}: M4 placeholders
Onboarding for agents:
- CLAUDE.md: hub — build/test commands, architecture at a glance, doc map, rules
- AGENTS.md: working method (behavior-driven; clean compile is the floor not the goal)
- PROGRESS.md: living tracker — M0 done, M1 task checklist, "where we left off"
Verified: cmake --preset dev && cmake --build --preset dev && ctest --preset dev → green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-15 21:09:09 +02:00
|
|
|
|
*/
|
|
|
|
|
|
#ifndef VOICECAT_H
|
|
|
|
|
|
#define VOICECAT_H
|
|
|
|
|
|
|
|
|
|
|
|
#include <stddef.h>
|
|
|
|
|
|
#include <stdint.h>
|
|
|
|
|
|
|
|
|
|
|
|
#if defined(__cplusplus)
|
|
|
|
|
|
extern "C" {
|
|
|
|
|
|
#endif
|
|
|
|
|
|
|
|
|
|
|
|
/* ── Export macro ─────────────────────────────────────────────────────────── */
|
|
|
|
|
|
#if defined(VOICECAT_STATIC)
|
|
|
|
|
|
#define VC_API
|
|
|
|
|
|
#elif defined(_WIN32)
|
|
|
|
|
|
#if defined(VOICECAT_BUILDING)
|
|
|
|
|
|
#define VC_API __declspec(dllexport)
|
|
|
|
|
|
#else
|
|
|
|
|
|
#define VC_API __declspec(dllimport)
|
|
|
|
|
|
#endif
|
|
|
|
|
|
#else
|
|
|
|
|
|
#if defined(VOICECAT_BUILDING)
|
|
|
|
|
|
#define VC_API __attribute__((visibility("default")))
|
|
|
|
|
|
#else
|
|
|
|
|
|
#define VC_API
|
|
|
|
|
|
#endif
|
|
|
|
|
|
#endif
|
|
|
|
|
|
|
|
|
|
|
|
/* ── Version ──────────────────────────────────────────────────────────────── */
|
|
|
|
|
|
#define VOICECAT_VERSION_MAJOR 0
|
|
|
|
|
|
#define VOICECAT_VERSION_MINOR 0
|
|
|
|
|
|
#define VOICECAT_VERSION_PATCH 1
|
|
|
|
|
|
|
|
|
|
|
|
/* The control-protocol version this build speaks (docs/protocol.md §4). */
|
|
|
|
|
|
#define VOICECAT_PROTOCOL_VERSION 1
|
|
|
|
|
|
|
|
|
|
|
|
/* ── Result codes ─────────────────────────────────────────────────────────── */
|
|
|
|
|
|
typedef enum vc_result {
|
|
|
|
|
|
VC_OK = 0,
|
|
|
|
|
|
VC_ERR_NOT_IMPLEMENTED = 1, /* skeleton stub */
|
|
|
|
|
|
VC_ERR_INVALID_ARG = 2,
|
|
|
|
|
|
VC_ERR_NOT_CONNECTED = 3,
|
|
|
|
|
|
VC_ERR_ALREADY = 4,
|
|
|
|
|
|
VC_ERR_AUTH_FAILED = 5,
|
|
|
|
|
|
VC_ERR_PERMISSION_DENIED = 6,
|
|
|
|
|
|
VC_ERR_TIMEOUT = 7,
|
|
|
|
|
|
VC_ERR_IO = 8,
|
|
|
|
|
|
VC_ERR_PROTOCOL = 9,
|
|
|
|
|
|
VC_ERR_CRYPTO = 10,
|
|
|
|
|
|
VC_ERR_AUDIO = 11,
|
|
|
|
|
|
VC_ERR_INTERNAL = 12,
|
|
|
|
|
|
} vc_result;
|
|
|
|
|
|
|
|
|
|
|
|
typedef enum vc_log_level {
|
|
|
|
|
|
VC_LOG_TRACE = 0,
|
|
|
|
|
|
VC_LOG_DEBUG = 1,
|
|
|
|
|
|
VC_LOG_INFO = 2,
|
|
|
|
|
|
VC_LOG_WARN = 3,
|
|
|
|
|
|
VC_LOG_ERROR = 4,
|
|
|
|
|
|
VC_LOG_OFF = 5,
|
|
|
|
|
|
} vc_log_level;
|
|
|
|
|
|
|
|
|
|
|
|
typedef enum vc_connection_state {
|
|
|
|
|
|
VC_STATE_DISCONNECTED = 0,
|
|
|
|
|
|
VC_STATE_CONNECTING = 1,
|
|
|
|
|
|
VC_STATE_TLS_HANDSHAKE = 2,
|
|
|
|
|
|
VC_STATE_AUTHENTICATING = 3,
|
|
|
|
|
|
VC_STATE_CONNECTED = 4,
|
feat(M4): Windows WinForms client, TOFU identity pinning, VAD threshold + always-on mode
Core ABI extensions (voicecat.h):
- vc_list_channels / vc_list_users / vc_list_user_streams — pull-based snapshot getters
for the channel-tree and user-list UI; session_model_mu_ guards cross-thread reads
- VC_EVENT_JOIN_RESULT / vc_join_channel — channel join with optional password
- VC_EVENT_SERVER_IDENTITY + vc_confirm_server_identity — TOFU gate that blocks io_thread_
until the UI approves or rejects; pins TLS leaf-cert SHA-256 (not declared Ed25519)
- vc_get_server_identity_display — Ed25519 fingerprint for human-readable display only
- VC_INPUT_ALWAYS_ON = 2 in vc_input_mode — transmit unconditionally, no VAD gate
- vc_set_vad_threshold — live RMS threshold update (0.0–1.0); EnergyVadProcessor stores
it atomically so the audio RT path reads without a lock
C++ implementation:
- SessionModel::apply_snapshot / apply_channel_event fixed to populate parent_id,
password_protected, and max_users (were permanently zeroed)
- TlsContext::peer_cert_fingerprint — SHA-256 of peer leaf cert DER via mbedTLS
- TofuStore split into peek (read-only) + pin (write) so first-connect only persists
after user approval; tofu_store_path in vc_config for per-user pin file location
- TcpAcceptor uses dual-stack IPv6+IPv4 fallback (fixes localhost → ::1 on Windows)
- windows-client CMake preset: Release shared DLL, static MinGW runtime, no tools/tests
- New C++ tests: test_channel_user_list_abi, test_tofu_flow (14/14 green)
Windows client (clients/windows/ — .NET 10 WinForms):
- VoiceCat.Interop: LibraryImport P/Invoke surface, UnmanagedCallersOnly callbacks,
Channel<VoiceCatEvent> event delivery drained by 30ms WinForms Timer
- VoiceCat.App: ConnectDialog (saved servers, DPAPI password storage), ServerIdentity-
Dialog (TOFU first-connect / mismatch warning), MainForm (channel TreeView, user
ListBox, RichTextBox chat, voice controls, device pickers, VAD/PTT/always-on mode,
per-user gain/mute/NR tuning, VAD sensitivity TrackBar, level meter ProgressBar)
- PttKeyCaptureDialog — focus-scoped PTT key capture (documented limitation)
- PerUserTuningDialog — real-time gain/mute/NR applied to all of a user's streams
- Accessibility: explicit AccessibleName/Description on every control, & mnemonics,
Activity log ListBox as durable screen-reader record, AutomationNotification for
curated live announcements
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-17 00:35:16 +02:00
|
|
|
|
/* M4: between TLS_HANDSHAKE and AUTHENTICATING — the handshake succeeded and the core is
|
|
|
|
|
|
* waiting for vc_confirm_server_identity() (see VC_EVENT_SERVER_IDENTITY below). Appended
|
|
|
|
|
|
* at the end (not inserted) to keep existing enum values stable — additive-only ABI. */
|
|
|
|
|
|
VC_STATE_VERIFYING_IDENTITY = 5,
|
scaffold: M0 skeleton + agent onboarding (build, architecture, progress)
Turn the design into a buildable, dependency-free M0 skeleton plus the
onboarding layer so a new agent can pick up instantly.
Build system:
- CMake + CMakePresets (dev = no deps; server-release = vcpkg) + vcpkg.json
- Skeleton builds with just a C++20 compiler; deps stay off until needed
- .gitattributes (LF), .gitignore, .clang-format
Core (libvoicecat):
- core/include/voicecat.h: full C ABI (the client/server contract), stubbed
- core/proto/voicecat.proto: control-plane wire format, matches docs/protocol.md
- src/{net,crypto,codec,protocol,session,audio,core}: subsystem stubs that
return VC_ERR_NOT_IMPLEMENTED, each pointing to its design doc
- server/ (voicecat-server) and tools/vccli/ link the core
- tests/: CTest smoke test asserting the C ABI contract (behavior, not just build)
- clients/{apple,windows}: M4 placeholders
Onboarding for agents:
- CLAUDE.md: hub — build/test commands, architecture at a glance, doc map, rules
- AGENTS.md: working method (behavior-driven; clean compile is the floor not the goal)
- PROGRESS.md: living tracker — M0 done, M1 task checklist, "where we left off"
Verified: cmake --preset dev && cmake --build --preset dev && ctest --preset dev → green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-15 21:09:09 +02:00
|
|
|
|
} vc_connection_state;
|
|
|
|
|
|
|
|
|
|
|
|
typedef enum vc_text_scope {
|
|
|
|
|
|
VC_TEXT_CHANNEL = 0,
|
|
|
|
|
|
VC_TEXT_PRIVATE = 1,
|
|
|
|
|
|
VC_TEXT_SERVER = 2,
|
|
|
|
|
|
} vc_text_scope;
|
|
|
|
|
|
|
|
|
|
|
|
typedef enum vc_device_kind {
|
|
|
|
|
|
VC_DEVICE_INPUT = 0,
|
|
|
|
|
|
VC_DEVICE_OUTPUT = 1,
|
|
|
|
|
|
} vc_device_kind;
|
|
|
|
|
|
|
|
|
|
|
|
typedef enum vc_stream_kind {
|
|
|
|
|
|
VC_STREAM_MIC = 0,
|
|
|
|
|
|
VC_STREAM_SCREEN_AUDIO = 1, /* system/desktop audio (docs/voice.md §9) */
|
|
|
|
|
|
VC_STREAM_AUX_DEVICE = 2,
|
|
|
|
|
|
} vc_stream_kind;
|
|
|
|
|
|
|
|
|
|
|
|
/* Send-side input gate (docs/voice.md §11). */
|
|
|
|
|
|
typedef enum vc_input_mode {
|
|
|
|
|
|
VC_INPUT_VOICE_ACTIVATION = 0,
|
|
|
|
|
|
VC_INPUT_PUSH_TO_TALK = 1,
|
feat(M4): Windows WinForms client, TOFU identity pinning, VAD threshold + always-on mode
Core ABI extensions (voicecat.h):
- vc_list_channels / vc_list_users / vc_list_user_streams — pull-based snapshot getters
for the channel-tree and user-list UI; session_model_mu_ guards cross-thread reads
- VC_EVENT_JOIN_RESULT / vc_join_channel — channel join with optional password
- VC_EVENT_SERVER_IDENTITY + vc_confirm_server_identity — TOFU gate that blocks io_thread_
until the UI approves or rejects; pins TLS leaf-cert SHA-256 (not declared Ed25519)
- vc_get_server_identity_display — Ed25519 fingerprint for human-readable display only
- VC_INPUT_ALWAYS_ON = 2 in vc_input_mode — transmit unconditionally, no VAD gate
- vc_set_vad_threshold — live RMS threshold update (0.0–1.0); EnergyVadProcessor stores
it atomically so the audio RT path reads without a lock
C++ implementation:
- SessionModel::apply_snapshot / apply_channel_event fixed to populate parent_id,
password_protected, and max_users (were permanently zeroed)
- TlsContext::peer_cert_fingerprint — SHA-256 of peer leaf cert DER via mbedTLS
- TofuStore split into peek (read-only) + pin (write) so first-connect only persists
after user approval; tofu_store_path in vc_config for per-user pin file location
- TcpAcceptor uses dual-stack IPv6+IPv4 fallback (fixes localhost → ::1 on Windows)
- windows-client CMake preset: Release shared DLL, static MinGW runtime, no tools/tests
- New C++ tests: test_channel_user_list_abi, test_tofu_flow (14/14 green)
Windows client (clients/windows/ — .NET 10 WinForms):
- VoiceCat.Interop: LibraryImport P/Invoke surface, UnmanagedCallersOnly callbacks,
Channel<VoiceCatEvent> event delivery drained by 30ms WinForms Timer
- VoiceCat.App: ConnectDialog (saved servers, DPAPI password storage), ServerIdentity-
Dialog (TOFU first-connect / mismatch warning), MainForm (channel TreeView, user
ListBox, RichTextBox chat, voice controls, device pickers, VAD/PTT/always-on mode,
per-user gain/mute/NR tuning, VAD sensitivity TrackBar, level meter ProgressBar)
- PttKeyCaptureDialog — focus-scoped PTT key capture (documented limitation)
- PerUserTuningDialog — real-time gain/mute/NR applied to all of a user's streams
- Accessibility: explicit AccessibleName/Description on every control, & mnemonics,
Activity log ListBox as durable screen-reader record, AutomationNotification for
curated live announcements
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-17 00:35:16 +02:00
|
|
|
|
/* Transmit unconditionally — no VAD gate. Added at the end to keep existing values stable. */
|
|
|
|
|
|
VC_INPUT_ALWAYS_ON = 2,
|
scaffold: M0 skeleton + agent onboarding (build, architecture, progress)
Turn the design into a buildable, dependency-free M0 skeleton plus the
onboarding layer so a new agent can pick up instantly.
Build system:
- CMake + CMakePresets (dev = no deps; server-release = vcpkg) + vcpkg.json
- Skeleton builds with just a C++20 compiler; deps stay off until needed
- .gitattributes (LF), .gitignore, .clang-format
Core (libvoicecat):
- core/include/voicecat.h: full C ABI (the client/server contract), stubbed
- core/proto/voicecat.proto: control-plane wire format, matches docs/protocol.md
- src/{net,crypto,codec,protocol,session,audio,core}: subsystem stubs that
return VC_ERR_NOT_IMPLEMENTED, each pointing to its design doc
- server/ (voicecat-server) and tools/vccli/ link the core
- tests/: CTest smoke test asserting the C ABI contract (behavior, not just build)
- clients/{apple,windows}: M4 placeholders
Onboarding for agents:
- CLAUDE.md: hub — build/test commands, architecture at a glance, doc map, rules
- AGENTS.md: working method (behavior-driven; clean compile is the floor not the goal)
- PROGRESS.md: living tracker — M0 done, M1 task checklist, "where we left off"
Verified: cmake --preset dev && cmake --build --preset dev && ctest --preset dev → green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-15 21:09:09 +02:00
|
|
|
|
} vc_input_mode;
|
|
|
|
|
|
|
|
|
|
|
|
typedef enum vc_event_type {
|
|
|
|
|
|
VC_EVENT_CONNECTION_STATE = 0, /* connection_state set */
|
|
|
|
|
|
VC_EVENT_AUTH_RESULT = 1, /* result set; user_id = self on success */
|
|
|
|
|
|
VC_EVENT_CHANNEL_LIST = 2, /* channel tree snapshot/delta available */
|
|
|
|
|
|
VC_EVENT_USER_JOINED = 3, /* user_id, channel_id, text = nickname */
|
|
|
|
|
|
VC_EVENT_USER_LEFT = 4, /* user_id */
|
|
|
|
|
|
VC_EVENT_USER_UPDATED = 5, /* user_id */
|
|
|
|
|
|
VC_EVENT_TEXT_MESSAGE = 6, /* text_scope, user_id (sender), channel_id, text */
|
|
|
|
|
|
VC_EVENT_STREAM_STARTED = 7, /* user_id, stream_id */
|
|
|
|
|
|
VC_EVENT_STREAM_STOPPED = 8, /* user_id, stream_id */
|
|
|
|
|
|
VC_EVENT_TALK_STATE = 9, /* user_id, stream_id, u32a = talking(0/1) */
|
|
|
|
|
|
VC_EVENT_ERROR = 10, /* result, text */
|
|
|
|
|
|
VC_EVENT_DISCONNECTED = 11, /* result, text = reason */
|
M5: moderation, permissions, channel CRUD, in-app account management
- Server-side moderation & permissions (kick/ban/move/server-mute, channel CRUD).
- Database schema v2: channels, bans; BLAKE2b channel passwords, Argon2id accounts.
- C ABI additions and client-side handling (vc_kick_user, vc_ban_user, vc_set_permission, vc_set_server_mute, vc_move_user, vc_create/edit/delete_channel, vc_create/reset/delete/list_account).
- vccli flags for all M5 operations plus --username/--password auth.
- Four new tests covering permissions, kick/ban/move/mute, admin accounts, channel CRUD.
- Docs: protocol.md envelope updates, security.md channel-password hashing, PROGRESS.md.
2026-06-17 15:08:05 +02:00
|
|
|
|
/* M4 additions — appended, not inserted, to keep existing enum values stable. */
|
feat(M4): Windows WinForms client, TOFU identity pinning, VAD threshold + always-on mode
Core ABI extensions (voicecat.h):
- vc_list_channels / vc_list_users / vc_list_user_streams — pull-based snapshot getters
for the channel-tree and user-list UI; session_model_mu_ guards cross-thread reads
- VC_EVENT_JOIN_RESULT / vc_join_channel — channel join with optional password
- VC_EVENT_SERVER_IDENTITY + vc_confirm_server_identity — TOFU gate that blocks io_thread_
until the UI approves or rejects; pins TLS leaf-cert SHA-256 (not declared Ed25519)
- vc_get_server_identity_display — Ed25519 fingerprint for human-readable display only
- VC_INPUT_ALWAYS_ON = 2 in vc_input_mode — transmit unconditionally, no VAD gate
- vc_set_vad_threshold — live RMS threshold update (0.0–1.0); EnergyVadProcessor stores
it atomically so the audio RT path reads without a lock
C++ implementation:
- SessionModel::apply_snapshot / apply_channel_event fixed to populate parent_id,
password_protected, and max_users (were permanently zeroed)
- TlsContext::peer_cert_fingerprint — SHA-256 of peer leaf cert DER via mbedTLS
- TofuStore split into peek (read-only) + pin (write) so first-connect only persists
after user approval; tofu_store_path in vc_config for per-user pin file location
- TcpAcceptor uses dual-stack IPv6+IPv4 fallback (fixes localhost → ::1 on Windows)
- windows-client CMake preset: Release shared DLL, static MinGW runtime, no tools/tests
- New C++ tests: test_channel_user_list_abi, test_tofu_flow (14/14 green)
Windows client (clients/windows/ — .NET 10 WinForms):
- VoiceCat.Interop: LibraryImport P/Invoke surface, UnmanagedCallersOnly callbacks,
Channel<VoiceCatEvent> event delivery drained by 30ms WinForms Timer
- VoiceCat.App: ConnectDialog (saved servers, DPAPI password storage), ServerIdentity-
Dialog (TOFU first-connect / mismatch warning), MainForm (channel TreeView, user
ListBox, RichTextBox chat, voice controls, device pickers, VAD/PTT/always-on mode,
per-user gain/mute/NR tuning, VAD sensitivity TrackBar, level meter ProgressBar)
- PttKeyCaptureDialog — focus-scoped PTT key capture (documented limitation)
- PerUserTuningDialog — real-time gain/mute/NR applied to all of a user's streams
- Accessibility: explicit AccessibleName/Description on every control, & mnemonics,
Activity log ListBox as durable screen-reader record, AutomationNotification for
curated live announcements
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-17 00:35:16 +02:00
|
|
|
|
VC_EVENT_JOIN_RESULT = 12, /* result (VC_OK/VC_ERR_*), channel_id, text = error on
|
|
|
|
|
|
failure. Reply to vc_join_channel(). */
|
|
|
|
|
|
VC_EVENT_SERVER_IDENTITY = 13, /* u32a = vc_tofu_status, text = hex-encoded TLS leaf-cert
|
|
|
|
|
|
SHA-256 fingerprint (the value being pinned — see
|
|
|
|
|
|
vc_confirm_server_identity). Emitted once per connect
|
|
|
|
|
|
attempt, right after the TLS handshake succeeds. The
|
|
|
|
|
|
connection is held open until vc_confirm_server_identity()
|
|
|
|
|
|
is called. */
|
M5: moderation, permissions, channel CRUD, in-app account management
- Server-side moderation & permissions (kick/ban/move/server-mute, channel CRUD).
- Database schema v2: channels, bans; BLAKE2b channel passwords, Argon2id accounts.
- C ABI additions and client-side handling (vc_kick_user, vc_ban_user, vc_set_permission, vc_set_server_mute, vc_move_user, vc_create/edit/delete_channel, vc_create/reset/delete/list_account).
- vccli flags for all M5 operations plus --username/--password auth.
- Four new tests covering permissions, kick/ban/move/mute, admin accounts, channel CRUD.
- Docs: protocol.md envelope updates, security.md channel-password hashing, PROGRESS.md.
2026-06-17 15:08:05 +02:00
|
|
|
|
/* M5 additions — appended, not inserted. */
|
|
|
|
|
|
VC_EVENT_GENERIC_RESULT = 14, /* result, u32a = server error code, text = message. Reply
|
|
|
|
|
|
to vc_kick_user/vc_ban_user/vc_set_permission/
|
|
|
|
|
|
vc_move_user/vc_create_channel/vc_edit_channel/
|
|
|
|
|
|
vc_delete_channel/vc_create_account/vc_reset_password/
|
|
|
|
|
|
vc_delete_account. */
|
|
|
|
|
|
VC_EVENT_ACCOUNT_LIST = 15, /* Reply to vc_list_accounts. */
|
scaffold: M0 skeleton + agent onboarding (build, architecture, progress)
Turn the design into a buildable, dependency-free M0 skeleton plus the
onboarding layer so a new agent can pick up instantly.
Build system:
- CMake + CMakePresets (dev = no deps; server-release = vcpkg) + vcpkg.json
- Skeleton builds with just a C++20 compiler; deps stay off until needed
- .gitattributes (LF), .gitignore, .clang-format
Core (libvoicecat):
- core/include/voicecat.h: full C ABI (the client/server contract), stubbed
- core/proto/voicecat.proto: control-plane wire format, matches docs/protocol.md
- src/{net,crypto,codec,protocol,session,audio,core}: subsystem stubs that
return VC_ERR_NOT_IMPLEMENTED, each pointing to its design doc
- server/ (voicecat-server) and tools/vccli/ link the core
- tests/: CTest smoke test asserting the C ABI contract (behavior, not just build)
- clients/{apple,windows}: M4 placeholders
Onboarding for agents:
- CLAUDE.md: hub — build/test commands, architecture at a glance, doc map, rules
- AGENTS.md: working method (behavior-driven; clean compile is the floor not the goal)
- PROGRESS.md: living tracker — M0 done, M1 task checklist, "where we left off"
Verified: cmake --preset dev && cmake --build --preset dev && ctest --preset dev → green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-15 21:09:09 +02:00
|
|
|
|
} vc_event_type;
|
|
|
|
|
|
|
feat(M4): Windows WinForms client, TOFU identity pinning, VAD threshold + always-on mode
Core ABI extensions (voicecat.h):
- vc_list_channels / vc_list_users / vc_list_user_streams — pull-based snapshot getters
for the channel-tree and user-list UI; session_model_mu_ guards cross-thread reads
- VC_EVENT_JOIN_RESULT / vc_join_channel — channel join with optional password
- VC_EVENT_SERVER_IDENTITY + vc_confirm_server_identity — TOFU gate that blocks io_thread_
until the UI approves or rejects; pins TLS leaf-cert SHA-256 (not declared Ed25519)
- vc_get_server_identity_display — Ed25519 fingerprint for human-readable display only
- VC_INPUT_ALWAYS_ON = 2 in vc_input_mode — transmit unconditionally, no VAD gate
- vc_set_vad_threshold — live RMS threshold update (0.0–1.0); EnergyVadProcessor stores
it atomically so the audio RT path reads without a lock
C++ implementation:
- SessionModel::apply_snapshot / apply_channel_event fixed to populate parent_id,
password_protected, and max_users (were permanently zeroed)
- TlsContext::peer_cert_fingerprint — SHA-256 of peer leaf cert DER via mbedTLS
- TofuStore split into peek (read-only) + pin (write) so first-connect only persists
after user approval; tofu_store_path in vc_config for per-user pin file location
- TcpAcceptor uses dual-stack IPv6+IPv4 fallback (fixes localhost → ::1 on Windows)
- windows-client CMake preset: Release shared DLL, static MinGW runtime, no tools/tests
- New C++ tests: test_channel_user_list_abi, test_tofu_flow (14/14 green)
Windows client (clients/windows/ — .NET 10 WinForms):
- VoiceCat.Interop: LibraryImport P/Invoke surface, UnmanagedCallersOnly callbacks,
Channel<VoiceCatEvent> event delivery drained by 30ms WinForms Timer
- VoiceCat.App: ConnectDialog (saved servers, DPAPI password storage), ServerIdentity-
Dialog (TOFU first-connect / mismatch warning), MainForm (channel TreeView, user
ListBox, RichTextBox chat, voice controls, device pickers, VAD/PTT/always-on mode,
per-user gain/mute/NR tuning, VAD sensitivity TrackBar, level meter ProgressBar)
- PttKeyCaptureDialog — focus-scoped PTT key capture (documented limitation)
- PerUserTuningDialog — real-time gain/mute/NR applied to all of a user's streams
- Accessibility: explicit AccessibleName/Description on every control, & mnemonics,
Activity log ListBox as durable screen-reader record, AutomationNotification for
curated live announcements
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-17 00:35:16 +02:00
|
|
|
|
/* TOFU server-identity classification (M4) — see VC_EVENT_SERVER_IDENTITY and
|
|
|
|
|
|
* vc_confirm_server_identity. Pins the TLS leaf certificate's own SHA-256 fingerprint
|
|
|
|
|
|
* (verifiable directly from the handshake), NOT the declared Ed25519
|
|
|
|
|
|
* server_identity_fingerprint from ServerHello — the TLS cert and the server's Ed25519
|
|
|
|
|
|
* identity key are generated independently with no cryptographic binding between them today
|
|
|
|
|
|
* (docs/security.md §1.1), so pinning the self-declared value would be circular. The Ed25519
|
|
|
|
|
|
* fingerprint is still available for human-readable display via
|
|
|
|
|
|
* vc_get_server_identity_display(), it just isn't the value this gate accepts/rejects on. */
|
|
|
|
|
|
typedef enum vc_tofu_status {
|
|
|
|
|
|
VC_TOFU_FIRST_CONNECT = 0, /* no pin on file yet for this host:port */
|
|
|
|
|
|
VC_TOFU_MATCHED = 1, /* matches the previously pinned fingerprint */
|
|
|
|
|
|
VC_TOFU_MISMATCH = 2, /* DIFFERENT from the pinned fingerprint — possible MITM or a
|
|
|
|
|
|
legitimate server key rotation; warn loudly */
|
|
|
|
|
|
} vc_tofu_status;
|
|
|
|
|
|
|
scaffold: M0 skeleton + agent onboarding (build, architecture, progress)
Turn the design into a buildable, dependency-free M0 skeleton plus the
onboarding layer so a new agent can pick up instantly.
Build system:
- CMake + CMakePresets (dev = no deps; server-release = vcpkg) + vcpkg.json
- Skeleton builds with just a C++20 compiler; deps stay off until needed
- .gitattributes (LF), .gitignore, .clang-format
Core (libvoicecat):
- core/include/voicecat.h: full C ABI (the client/server contract), stubbed
- core/proto/voicecat.proto: control-plane wire format, matches docs/protocol.md
- src/{net,crypto,codec,protocol,session,audio,core}: subsystem stubs that
return VC_ERR_NOT_IMPLEMENTED, each pointing to its design doc
- server/ (voicecat-server) and tools/vccli/ link the core
- tests/: CTest smoke test asserting the C ABI contract (behavior, not just build)
- clients/{apple,windows}: M4 placeholders
Onboarding for agents:
- CLAUDE.md: hub — build/test commands, architecture at a glance, doc map, rules
- AGENTS.md: working method (behavior-driven; clean compile is the floor not the goal)
- PROGRESS.md: living tracker — M0 done, M1 task checklist, "where we left off"
Verified: cmake --preset dev && cmake --build --preset dev && ctest --preset dev → green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-15 21:09:09 +02:00
|
|
|
|
/* ── Structs ──────────────────────────────────────────────────────────────── */
|
|
|
|
|
|
|
|
|
|
|
|
/*
|
|
|
|
|
|
* An event delivered to vc_callbacks.on_event. Pointer fields are owned by the core and
|
|
|
|
|
|
* valid ONLY for the duration of the callback — copy what you need. Which fields are
|
|
|
|
|
|
* meaningful depends on `type` (see vc_event_type comments above).
|
|
|
|
|
|
*/
|
|
|
|
|
|
typedef struct vc_event {
|
|
|
|
|
|
vc_event_type type;
|
|
|
|
|
|
vc_connection_state connection_state;
|
|
|
|
|
|
int32_t result; /* vc_result */
|
|
|
|
|
|
uint32_t user_id;
|
|
|
|
|
|
uint32_t channel_id;
|
|
|
|
|
|
uint32_t stream_id;
|
|
|
|
|
|
vc_text_scope text_scope;
|
|
|
|
|
|
uint32_t u32a; /* generic small payload, meaning per event type */
|
|
|
|
|
|
const char* text;
|
|
|
|
|
|
uint64_t timestamp_unix_ms;
|
|
|
|
|
|
} vc_event;
|
|
|
|
|
|
|
|
|
|
|
|
typedef struct vc_callbacks {
|
|
|
|
|
|
/* State changes, messages, presence. Called on the core's event thread. */
|
|
|
|
|
|
void (*on_event)(void* user, const vc_event* ev);
|
|
|
|
|
|
/* Throttled level meter (RMS 0..1) for a local or remote stream; may be NULL. */
|
|
|
|
|
|
void (*on_level)(void* user, uint32_t stream_id, float rms);
|
|
|
|
|
|
void* user;
|
|
|
|
|
|
} vc_callbacks;
|
|
|
|
|
|
|
|
|
|
|
|
typedef struct vc_config {
|
|
|
|
|
|
const char* client_name; /* e.g. "VoiceCat-macOS" */
|
|
|
|
|
|
const char* client_version; /* e.g. "0.0.1" */
|
|
|
|
|
|
vc_log_level log_level;
|
feat(M4): Windows WinForms client, TOFU identity pinning, VAD threshold + always-on mode
Core ABI extensions (voicecat.h):
- vc_list_channels / vc_list_users / vc_list_user_streams — pull-based snapshot getters
for the channel-tree and user-list UI; session_model_mu_ guards cross-thread reads
- VC_EVENT_JOIN_RESULT / vc_join_channel — channel join with optional password
- VC_EVENT_SERVER_IDENTITY + vc_confirm_server_identity — TOFU gate that blocks io_thread_
until the UI approves or rejects; pins TLS leaf-cert SHA-256 (not declared Ed25519)
- vc_get_server_identity_display — Ed25519 fingerprint for human-readable display only
- VC_INPUT_ALWAYS_ON = 2 in vc_input_mode — transmit unconditionally, no VAD gate
- vc_set_vad_threshold — live RMS threshold update (0.0–1.0); EnergyVadProcessor stores
it atomically so the audio RT path reads without a lock
C++ implementation:
- SessionModel::apply_snapshot / apply_channel_event fixed to populate parent_id,
password_protected, and max_users (were permanently zeroed)
- TlsContext::peer_cert_fingerprint — SHA-256 of peer leaf cert DER via mbedTLS
- TofuStore split into peek (read-only) + pin (write) so first-connect only persists
after user approval; tofu_store_path in vc_config for per-user pin file location
- TcpAcceptor uses dual-stack IPv6+IPv4 fallback (fixes localhost → ::1 on Windows)
- windows-client CMake preset: Release shared DLL, static MinGW runtime, no tools/tests
- New C++ tests: test_channel_user_list_abi, test_tofu_flow (14/14 green)
Windows client (clients/windows/ — .NET 10 WinForms):
- VoiceCat.Interop: LibraryImport P/Invoke surface, UnmanagedCallersOnly callbacks,
Channel<VoiceCatEvent> event delivery drained by 30ms WinForms Timer
- VoiceCat.App: ConnectDialog (saved servers, DPAPI password storage), ServerIdentity-
Dialog (TOFU first-connect / mismatch warning), MainForm (channel TreeView, user
ListBox, RichTextBox chat, voice controls, device pickers, VAD/PTT/always-on mode,
per-user gain/mute/NR tuning, VAD sensitivity TrackBar, level meter ProgressBar)
- PttKeyCaptureDialog — focus-scoped PTT key capture (documented limitation)
- PerUserTuningDialog — real-time gain/mute/NR applied to all of a user's streams
- Accessibility: explicit AccessibleName/Description on every control, & mnemonics,
Activity log ListBox as durable screen-reader record, AutomationNotification for
curated live announcements
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-17 00:35:16 +02:00
|
|
|
|
/* M4, optional (added at the end — existing brace-initialized callers default this to
|
|
|
|
|
|
* NULL, no source change needed). Path to the TOFU pin file (see VC_EVENT_SERVER_IDENTITY/
|
|
|
|
|
|
* vc_confirm_server_identity). NULL = a built-in relative default
|
|
|
|
|
|
* ("./voicecat_tofu_pins.txt") so existing tests need no real persistence. A real app
|
|
|
|
|
|
* (e.g. the Windows client) should pass an explicit per-user path, e.g.
|
|
|
|
|
|
* "%AppData%\VoiceCat\tofu_pins.txt". */
|
|
|
|
|
|
const char* tofu_store_path;
|
scaffold: M0 skeleton + agent onboarding (build, architecture, progress)
Turn the design into a buildable, dependency-free M0 skeleton plus the
onboarding layer so a new agent can pick up instantly.
Build system:
- CMake + CMakePresets (dev = no deps; server-release = vcpkg) + vcpkg.json
- Skeleton builds with just a C++20 compiler; deps stay off until needed
- .gitattributes (LF), .gitignore, .clang-format
Core (libvoicecat):
- core/include/voicecat.h: full C ABI (the client/server contract), stubbed
- core/proto/voicecat.proto: control-plane wire format, matches docs/protocol.md
- src/{net,crypto,codec,protocol,session,audio,core}: subsystem stubs that
return VC_ERR_NOT_IMPLEMENTED, each pointing to its design doc
- server/ (voicecat-server) and tools/vccli/ link the core
- tests/: CTest smoke test asserting the C ABI contract (behavior, not just build)
- clients/{apple,windows}: M4 placeholders
Onboarding for agents:
- CLAUDE.md: hub — build/test commands, architecture at a glance, doc map, rules
- AGENTS.md: working method (behavior-driven; clean compile is the floor not the goal)
- PROGRESS.md: living tracker — M0 done, M1 task checklist, "where we left off"
Verified: cmake --preset dev && cmake --build --preset dev && ctest --preset dev → green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-15 21:09:09 +02:00
|
|
|
|
} vc_config;
|
|
|
|
|
|
|
|
|
|
|
|
typedef struct vc_stream_desc {
|
|
|
|
|
|
vc_stream_kind kind;
|
|
|
|
|
|
const char* device_id; /* NULL = default device for this kind */
|
|
|
|
|
|
const char* label; /* human label, e.g. "Microphone" */
|
|
|
|
|
|
} vc_stream_desc;
|
|
|
|
|
|
|
feat(M3): multi-stream & per-channel tuning
Implements docs/roadmap.md M3: multiple concurrent streams per user (MIC +
SCREEN_AUDIO + AUX_DEVICE), independent per-stream receiver gain/mute/noise-
reduction, talk indicators, and enforced per-channel Opus configurability
(mono/stereo, bitrate, frame size, FEC/DTX, application).
Bugs fixed along the way (found while implementing, not pre-existing scope):
- Server hard-coded stream_id=1 for every announce, so a second stream from
the same user silently overwrote the first in SessionRegistry::set_user_stream.
Now a per-session counter (ConnSession::next_stream_id_); handle_stream_stop
validates against announced_stream_ids_ before clearing.
- Client dropped mode/dtx/complexity/application from effective_audio even for
the single M2 stream -- only sample_rate/bitrate_bps/frame_ms/fec were ever
applied to OpusParams. Fixed on both the send (handle_stream_announce_result)
and receive (sync_remote_streams) paths via a shared
opus_params_from_audio_config() helper.
- OpusEncoder always used OPUS_APPLICATION_VOIP; added OpusParams::application
and wired it through.
- on_playback's per-stream decode passed the wrong frame_size to opus_decode
(total samples instead of samples-per-channel), which would have overflowed
the decode buffer for any stereo stream.
- teardown_voice() raced when called concurrently from run_io()'s own cleanup
and from disconnect() on a different thread -- both could see
udp_thread_/talk_timer_thread_ as joinable() at once and race to join() the
same std::thread (intermittent std::system_error under ctest). Fixed with a
teardown_mu_ guard instead of carrying the flake forward.
New:
- Per-channel AudioConfig: SessionRegistry now seeds Lobby (mono/24kbps/VOIP/
FEC+DTX) and a new "Music Room" channel (stereo/128kbps/AUDIO/no DTX);
handle_stream_announce enforces the channel's config, clamping (not
overriding) bitrate_bps to its ceiling.
- core/src/core/client.h/.cpp: local-stream state is now a
std::unordered_map<int, LocalStream> keyed by vc_stream_kind, with
request_id-correlated announce/result handling (request_id already
round-tripped on the wire; just wasn't read before). on_capture_frame is
kind-aware and upmixes mono capture to stereo when a stream's config calls
for it. set_self_mute's mic_muted now only gates the MIC kind. NS is wired
through set_remote_stream. New run_talk_timer() thread emits
VC_EVENT_TALK_STATE from both remote and local edge detection.
- core/src/audio/audio_engine.h/.cpp: kind-keyed injection taps
(inject_capture), stereo-to-mono downmix at the decode/mix boundary,
RemoteStream gains recv_ns (lazy ApmProcessor) + noise_reduction_enabled
and last_voice_ms/talking; new set_stream_noise_reduction() and
poll_talk_transitions().
- core/src/session/session.h/.cpp: Stream now carries the full AudioConfig,
not just sample_rate/frame_ms.
- New additive C ABI (core/include/voicecat.h): vc_audio_config +
vc_get_stream_audio_config (effective Opus config for any stream you own or
a peer's); vc_test_inject_capture (test-only synthetic PCM injection,
clearly marked, mirrors AudioEngine::inject_capture).
- tests/test_m3_multistream.cpp: the M3 exit criterion through the real ABI
(mirrors test_voice_client_abi.cpp's approach, not raw sockets) -- two
concurrent local streams, independent gain/mute/NS control, per-channel
config divergence via vc_get_stream_audio_config, talk indicators.
Explicitly out of scope for this pass (tracked in PROGRESS.md, not silently
dropped): VAD/PTT input gate + device enumeration; real WASAPI loopback
capture for SCREEN_AUDIO (synthetic injection only); true stereo playback
output (AudioEngine's mixer/output device stays mono -- Opus itself is fully
stereo-correct on the wire).
ctest --test-dir build/m1-dev: 11/11 green, verified across 3 consecutive
full-suite runs plus 8 standalone runs of the new test.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-16 14:12:37 +02:00
|
|
|
|
/* The effective Opus configuration in use for a stream — for a stream you own, this is
|
|
|
|
|
|
* StreamAnnounceResult.effective_audio (channel-enforced, docs/voice.md §3); for a remote
|
|
|
|
|
|
* stream, it's the peer's broadcast StreamInfo.audio. See vc_get_stream_audio_config. */
|
|
|
|
|
|
typedef struct vc_audio_config {
|
|
|
|
|
|
uint32_t codec; /* 0 = OPUS */
|
|
|
|
|
|
uint32_t mode; /* 0 = mono, 1 = stereo */
|
|
|
|
|
|
uint32_t sample_rate;
|
|
|
|
|
|
uint32_t bitrate_bps;
|
|
|
|
|
|
uint32_t frame_ms;
|
|
|
|
|
|
uint32_t application; /* 0 = VOIP, 1 = AUDIO, 2 = LOWDELAY */
|
|
|
|
|
|
int fec; /* bool */
|
|
|
|
|
|
uint32_t expected_packet_loss; /* % 0..100 */
|
|
|
|
|
|
int dtx; /* bool */
|
|
|
|
|
|
uint32_t complexity; /* 0..10 */
|
|
|
|
|
|
} vc_audio_config;
|
|
|
|
|
|
|
M5: moderation, permissions, channel CRUD, in-app account management
- Server-side moderation & permissions (kick/ban/move/server-mute, channel CRUD).
- Database schema v2: channels, bans; BLAKE2b channel passwords, Argon2id accounts.
- C ABI additions and client-side handling (vc_kick_user, vc_ban_user, vc_set_permission, vc_set_server_mute, vc_move_user, vc_create/edit/delete_channel, vc_create/reset/delete/list_account).
- vccli flags for all M5 operations plus --username/--password auth.
- Four new tests covering permissions, kick/ban/move/mute, admin accounts, channel CRUD.
- Docs: protocol.md envelope updates, security.md channel-password hashing, PROGRESS.md.
2026-06-17 15:08:05 +02:00
|
|
|
|
/* M5: permission bitset (mirrors protocol Permissions). */
|
|
|
|
|
|
typedef struct vc_permissions {
|
|
|
|
|
|
int can_create_temp_channel; /* bool */
|
|
|
|
|
|
int can_kick; /* bool */
|
|
|
|
|
|
int can_ban; /* bool */
|
|
|
|
|
|
int can_move_users; /* bool */
|
|
|
|
|
|
int can_admin_accounts; /* bool */
|
|
|
|
|
|
int is_admin; /* bool */
|
|
|
|
|
|
} vc_permissions;
|
|
|
|
|
|
|
2026-06-17 16:31:29 +02:00
|
|
|
|
/* M5: account entry (reply to vc_list_accounts / vc_get_account_list). */
|
|
|
|
|
|
typedef struct vc_account {
|
|
|
|
|
|
const char* username;
|
|
|
|
|
|
int is_admin; /* bool */
|
|
|
|
|
|
uint64_t created_at_unix_ms;
|
|
|
|
|
|
uint64_t last_login_unix_ms;
|
|
|
|
|
|
} vc_account;
|
|
|
|
|
|
|
|
|
|
|
|
typedef struct vc_account_list {
|
|
|
|
|
|
vc_account* items;
|
|
|
|
|
|
size_t count;
|
|
|
|
|
|
} vc_account_list;
|
|
|
|
|
|
|
M5: moderation, permissions, channel CRUD, in-app account management
- Server-side moderation & permissions (kick/ban/move/server-mute, channel CRUD).
- Database schema v2: channels, bans; BLAKE2b channel passwords, Argon2id accounts.
- C ABI additions and client-side handling (vc_kick_user, vc_ban_user, vc_set_permission, vc_set_server_mute, vc_move_user, vc_create/edit/delete_channel, vc_create/reset/delete/list_account).
- vccli flags for all M5 operations plus --username/--password auth.
- Four new tests covering permissions, kick/ban/move/mute, admin accounts, channel CRUD.
- Docs: protocol.md envelope updates, security.md channel-password hashing, PROGRESS.md.
2026-06-17 15:08:05 +02:00
|
|
|
|
/* M5: channel creation/edition descriptor. */
|
|
|
|
|
|
typedef struct vc_channel_info {
|
|
|
|
|
|
uint32_t id; /* 0 = new channel for create */
|
|
|
|
|
|
uint32_t parent_id; /* 0 = root */
|
|
|
|
|
|
const char* name;
|
|
|
|
|
|
const char* topic;
|
|
|
|
|
|
int password_protected; /* bool */
|
|
|
|
|
|
const char* password; /* nullable; ignored if password_protected == 0 */
|
|
|
|
|
|
uint32_t max_users; /* 0 = unlimited */
|
|
|
|
|
|
uint32_t sort_order;
|
|
|
|
|
|
/* Audio config — 0/NULL fields use server defaults. */
|
|
|
|
|
|
vc_audio_config audio;
|
|
|
|
|
|
} vc_channel_info;
|
|
|
|
|
|
|
scaffold: M0 skeleton + agent onboarding (build, architecture, progress)
Turn the design into a buildable, dependency-free M0 skeleton plus the
onboarding layer so a new agent can pick up instantly.
Build system:
- CMake + CMakePresets (dev = no deps; server-release = vcpkg) + vcpkg.json
- Skeleton builds with just a C++20 compiler; deps stay off until needed
- .gitattributes (LF), .gitignore, .clang-format
Core (libvoicecat):
- core/include/voicecat.h: full C ABI (the client/server contract), stubbed
- core/proto/voicecat.proto: control-plane wire format, matches docs/protocol.md
- src/{net,crypto,codec,protocol,session,audio,core}: subsystem stubs that
return VC_ERR_NOT_IMPLEMENTED, each pointing to its design doc
- server/ (voicecat-server) and tools/vccli/ link the core
- tests/: CTest smoke test asserting the C ABI contract (behavior, not just build)
- clients/{apple,windows}: M4 placeholders
Onboarding for agents:
- CLAUDE.md: hub — build/test commands, architecture at a glance, doc map, rules
- AGENTS.md: working method (behavior-driven; clean compile is the floor not the goal)
- PROGRESS.md: living tracker — M0 done, M1 task checklist, "where we left off"
Verified: cmake --preset dev && cmake --build --preset dev && ctest --preset dev → green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-15 21:09:09 +02:00
|
|
|
|
typedef struct vc_device {
|
|
|
|
|
|
const char* id;
|
|
|
|
|
|
const char* name;
|
|
|
|
|
|
int is_default; /* bool */
|
|
|
|
|
|
} vc_device;
|
|
|
|
|
|
|
|
|
|
|
|
typedef struct vc_device_list {
|
|
|
|
|
|
vc_device* items;
|
|
|
|
|
|
size_t count;
|
|
|
|
|
|
} vc_device_list;
|
|
|
|
|
|
|
feat(M4): Windows WinForms client, TOFU identity pinning, VAD threshold + always-on mode
Core ABI extensions (voicecat.h):
- vc_list_channels / vc_list_users / vc_list_user_streams — pull-based snapshot getters
for the channel-tree and user-list UI; session_model_mu_ guards cross-thread reads
- VC_EVENT_JOIN_RESULT / vc_join_channel — channel join with optional password
- VC_EVENT_SERVER_IDENTITY + vc_confirm_server_identity — TOFU gate that blocks io_thread_
until the UI approves or rejects; pins TLS leaf-cert SHA-256 (not declared Ed25519)
- vc_get_server_identity_display — Ed25519 fingerprint for human-readable display only
- VC_INPUT_ALWAYS_ON = 2 in vc_input_mode — transmit unconditionally, no VAD gate
- vc_set_vad_threshold — live RMS threshold update (0.0–1.0); EnergyVadProcessor stores
it atomically so the audio RT path reads without a lock
C++ implementation:
- SessionModel::apply_snapshot / apply_channel_event fixed to populate parent_id,
password_protected, and max_users (were permanently zeroed)
- TlsContext::peer_cert_fingerprint — SHA-256 of peer leaf cert DER via mbedTLS
- TofuStore split into peek (read-only) + pin (write) so first-connect only persists
after user approval; tofu_store_path in vc_config for per-user pin file location
- TcpAcceptor uses dual-stack IPv6+IPv4 fallback (fixes localhost → ::1 on Windows)
- windows-client CMake preset: Release shared DLL, static MinGW runtime, no tools/tests
- New C++ tests: test_channel_user_list_abi, test_tofu_flow (14/14 green)
Windows client (clients/windows/ — .NET 10 WinForms):
- VoiceCat.Interop: LibraryImport P/Invoke surface, UnmanagedCallersOnly callbacks,
Channel<VoiceCatEvent> event delivery drained by 30ms WinForms Timer
- VoiceCat.App: ConnectDialog (saved servers, DPAPI password storage), ServerIdentity-
Dialog (TOFU first-connect / mismatch warning), MainForm (channel TreeView, user
ListBox, RichTextBox chat, voice controls, device pickers, VAD/PTT/always-on mode,
per-user gain/mute/NR tuning, VAD sensitivity TrackBar, level meter ProgressBar)
- PttKeyCaptureDialog — focus-scoped PTT key capture (documented limitation)
- PerUserTuningDialog — real-time gain/mute/NR applied to all of a user's streams
- Accessibility: explicit AccessibleName/Description on every control, & mnemonics,
Activity log ListBox as durable screen-reader record, AutomationNotification for
curated live announcements
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-17 00:35:16 +02:00
|
|
|
|
/* ── Channel / user / stream snapshots (M4 — for the channel-tree/user-list UI) ───────────
|
|
|
|
|
|
* Pull-based: re-call after VC_EVENT_CHANNEL_LIST / VC_EVENT_USER_JOINED / _LEFT / _UPDATED to
|
|
|
|
|
|
* refresh — there is no push variant; those events just mean "go look". Same ownership
|
|
|
|
|
|
* contract as vc_device/vc_device_list above: core-allocated, caller frees with the matching
|
|
|
|
|
|
* vc_free_*, items' const char* fields are invalid after that call. */
|
|
|
|
|
|
typedef struct vc_channel {
|
|
|
|
|
|
uint32_t id;
|
|
|
|
|
|
uint32_t parent_id; /* 0 = root */
|
|
|
|
|
|
const char* name;
|
2026-06-17 16:31:29 +02:00
|
|
|
|
const char* topic;
|
feat(M4): Windows WinForms client, TOFU identity pinning, VAD threshold + always-on mode
Core ABI extensions (voicecat.h):
- vc_list_channels / vc_list_users / vc_list_user_streams — pull-based snapshot getters
for the channel-tree and user-list UI; session_model_mu_ guards cross-thread reads
- VC_EVENT_JOIN_RESULT / vc_join_channel — channel join with optional password
- VC_EVENT_SERVER_IDENTITY + vc_confirm_server_identity — TOFU gate that blocks io_thread_
until the UI approves or rejects; pins TLS leaf-cert SHA-256 (not declared Ed25519)
- vc_get_server_identity_display — Ed25519 fingerprint for human-readable display only
- VC_INPUT_ALWAYS_ON = 2 in vc_input_mode — transmit unconditionally, no VAD gate
- vc_set_vad_threshold — live RMS threshold update (0.0–1.0); EnergyVadProcessor stores
it atomically so the audio RT path reads without a lock
C++ implementation:
- SessionModel::apply_snapshot / apply_channel_event fixed to populate parent_id,
password_protected, and max_users (were permanently zeroed)
- TlsContext::peer_cert_fingerprint — SHA-256 of peer leaf cert DER via mbedTLS
- TofuStore split into peek (read-only) + pin (write) so first-connect only persists
after user approval; tofu_store_path in vc_config for per-user pin file location
- TcpAcceptor uses dual-stack IPv6+IPv4 fallback (fixes localhost → ::1 on Windows)
- windows-client CMake preset: Release shared DLL, static MinGW runtime, no tools/tests
- New C++ tests: test_channel_user_list_abi, test_tofu_flow (14/14 green)
Windows client (clients/windows/ — .NET 10 WinForms):
- VoiceCat.Interop: LibraryImport P/Invoke surface, UnmanagedCallersOnly callbacks,
Channel<VoiceCatEvent> event delivery drained by 30ms WinForms Timer
- VoiceCat.App: ConnectDialog (saved servers, DPAPI password storage), ServerIdentity-
Dialog (TOFU first-connect / mismatch warning), MainForm (channel TreeView, user
ListBox, RichTextBox chat, voice controls, device pickers, VAD/PTT/always-on mode,
per-user gain/mute/NR tuning, VAD sensitivity TrackBar, level meter ProgressBar)
- PttKeyCaptureDialog — focus-scoped PTT key capture (documented limitation)
- PerUserTuningDialog — real-time gain/mute/NR applied to all of a user's streams
- Accessibility: explicit AccessibleName/Description on every control, & mnemonics,
Activity log ListBox as durable screen-reader record, AutomationNotification for
curated live announcements
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-17 00:35:16 +02:00
|
|
|
|
int password_protected; /* bool */
|
|
|
|
|
|
uint32_t max_users; /* 0 = unlimited */
|
|
|
|
|
|
} vc_channel;
|
|
|
|
|
|
|
|
|
|
|
|
typedef struct vc_channel_list {
|
|
|
|
|
|
vc_channel* items;
|
|
|
|
|
|
size_t count;
|
|
|
|
|
|
} vc_channel_list;
|
|
|
|
|
|
|
|
|
|
|
|
typedef struct vc_user {
|
|
|
|
|
|
uint32_t id;
|
|
|
|
|
|
const char* nickname;
|
|
|
|
|
|
int is_guest; /* bool */
|
|
|
|
|
|
uint32_t channel_id;
|
2026-06-17 16:31:29 +02:00
|
|
|
|
int self_mic_muted; /* bool */
|
|
|
|
|
|
int self_deafened; /* bool */
|
|
|
|
|
|
int server_muted; /* bool */
|
|
|
|
|
|
int server_deafened; /* bool */
|
feat(M4): Windows WinForms client, TOFU identity pinning, VAD threshold + always-on mode
Core ABI extensions (voicecat.h):
- vc_list_channels / vc_list_users / vc_list_user_streams — pull-based snapshot getters
for the channel-tree and user-list UI; session_model_mu_ guards cross-thread reads
- VC_EVENT_JOIN_RESULT / vc_join_channel — channel join with optional password
- VC_EVENT_SERVER_IDENTITY + vc_confirm_server_identity — TOFU gate that blocks io_thread_
until the UI approves or rejects; pins TLS leaf-cert SHA-256 (not declared Ed25519)
- vc_get_server_identity_display — Ed25519 fingerprint for human-readable display only
- VC_INPUT_ALWAYS_ON = 2 in vc_input_mode — transmit unconditionally, no VAD gate
- vc_set_vad_threshold — live RMS threshold update (0.0–1.0); EnergyVadProcessor stores
it atomically so the audio RT path reads without a lock
C++ implementation:
- SessionModel::apply_snapshot / apply_channel_event fixed to populate parent_id,
password_protected, and max_users (were permanently zeroed)
- TlsContext::peer_cert_fingerprint — SHA-256 of peer leaf cert DER via mbedTLS
- TofuStore split into peek (read-only) + pin (write) so first-connect only persists
after user approval; tofu_store_path in vc_config for per-user pin file location
- TcpAcceptor uses dual-stack IPv6+IPv4 fallback (fixes localhost → ::1 on Windows)
- windows-client CMake preset: Release shared DLL, static MinGW runtime, no tools/tests
- New C++ tests: test_channel_user_list_abi, test_tofu_flow (14/14 green)
Windows client (clients/windows/ — .NET 10 WinForms):
- VoiceCat.Interop: LibraryImport P/Invoke surface, UnmanagedCallersOnly callbacks,
Channel<VoiceCatEvent> event delivery drained by 30ms WinForms Timer
- VoiceCat.App: ConnectDialog (saved servers, DPAPI password storage), ServerIdentity-
Dialog (TOFU first-connect / mismatch warning), MainForm (channel TreeView, user
ListBox, RichTextBox chat, voice controls, device pickers, VAD/PTT/always-on mode,
per-user gain/mute/NR tuning, VAD sensitivity TrackBar, level meter ProgressBar)
- PttKeyCaptureDialog — focus-scoped PTT key capture (documented limitation)
- PerUserTuningDialog — real-time gain/mute/NR applied to all of a user's streams
- Accessibility: explicit AccessibleName/Description on every control, & mnemonics,
Activity log ListBox as durable screen-reader record, AutomationNotification for
curated live announcements
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-17 00:35:16 +02:00
|
|
|
|
} vc_user;
|
|
|
|
|
|
|
|
|
|
|
|
typedef struct vc_user_list {
|
|
|
|
|
|
vc_user* items;
|
|
|
|
|
|
size_t count;
|
|
|
|
|
|
} vc_user_list;
|
|
|
|
|
|
|
|
|
|
|
|
/* Per-user stream summary — lighter than vc_audio_config; for the full effective Opus config
|
|
|
|
|
|
* of a specific (user_id, stream_id), use the existing vc_get_stream_audio_config. */
|
|
|
|
|
|
typedef struct vc_stream_summary {
|
|
|
|
|
|
uint32_t stream_id;
|
|
|
|
|
|
vc_stream_kind kind;
|
|
|
|
|
|
const char* label;
|
|
|
|
|
|
} vc_stream_summary;
|
|
|
|
|
|
|
|
|
|
|
|
typedef struct vc_stream_summary_list {
|
|
|
|
|
|
vc_stream_summary* items;
|
|
|
|
|
|
size_t count;
|
|
|
|
|
|
} vc_stream_summary_list;
|
|
|
|
|
|
|
2026-06-18 02:06:44 +02:00
|
|
|
|
/* Receive-side state the local listener has chosen for a specific remote stream — the
|
|
|
|
|
|
* counterpart to vc_set_remote_stream, so a UI can reopen its per-mix controls at the
|
|
|
|
|
|
* listener's actual current settings. All LOCAL (no protocol traffic) — docs/voice.md §10.
|
|
|
|
|
|
* If (user_id, stream_id) is known but the listener has never called vc_set_remote_stream on
|
|
|
|
|
|
* it, the defaults are gain=1.0, muted=0, noise_reduction=0 (matching a fresh RemoteStream). */
|
|
|
|
|
|
typedef struct vc_remote_stream_state {
|
|
|
|
|
|
float gain; /* 0.0–… ; default 1.0 */
|
|
|
|
|
|
int muted; /* bool */
|
|
|
|
|
|
int noise_reduction; /* bool */
|
|
|
|
|
|
} vc_remote_stream_state;
|
|
|
|
|
|
|
scaffold: M0 skeleton + agent onboarding (build, architecture, progress)
Turn the design into a buildable, dependency-free M0 skeleton plus the
onboarding layer so a new agent can pick up instantly.
Build system:
- CMake + CMakePresets (dev = no deps; server-release = vcpkg) + vcpkg.json
- Skeleton builds with just a C++20 compiler; deps stay off until needed
- .gitattributes (LF), .gitignore, .clang-format
Core (libvoicecat):
- core/include/voicecat.h: full C ABI (the client/server contract), stubbed
- core/proto/voicecat.proto: control-plane wire format, matches docs/protocol.md
- src/{net,crypto,codec,protocol,session,audio,core}: subsystem stubs that
return VC_ERR_NOT_IMPLEMENTED, each pointing to its design doc
- server/ (voicecat-server) and tools/vccli/ link the core
- tests/: CTest smoke test asserting the C ABI contract (behavior, not just build)
- clients/{apple,windows}: M4 placeholders
Onboarding for agents:
- CLAUDE.md: hub — build/test commands, architecture at a glance, doc map, rules
- AGENTS.md: working method (behavior-driven; clean compile is the floor not the goal)
- PROGRESS.md: living tracker — M0 done, M1 task checklist, "where we left off"
Verified: cmake --preset dev && cmake --build --preset dev && ctest --preset dev → green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-15 21:09:09 +02:00
|
|
|
|
/* Opaque client handle. */
|
|
|
|
|
|
typedef struct vc_client vc_client;
|
|
|
|
|
|
|
|
|
|
|
|
/* ── Lifecycle ────────────────────────────────────────────────────────────── */
|
|
|
|
|
|
VC_API const char* vc_version_string(void);
|
|
|
|
|
|
VC_API const char* vc_result_string(vc_result code);
|
|
|
|
|
|
|
|
|
|
|
|
VC_API vc_client* vc_client_create(const vc_config* cfg, vc_callbacks cb);
|
|
|
|
|
|
VC_API void vc_client_destroy(vc_client* c);
|
|
|
|
|
|
|
|
|
|
|
|
/* ── Connection & auth (async; results via on_event) ──────────────────────── */
|
|
|
|
|
|
VC_API vc_result vc_connect(vc_client* c, const char* host, uint16_t port);
|
|
|
|
|
|
VC_API vc_result vc_disconnect(vc_client* c);
|
|
|
|
|
|
VC_API vc_result vc_authenticate_guest(vc_client* c, const char* nickname);
|
|
|
|
|
|
VC_API vc_result vc_authenticate_user(vc_client* c, const char* username,
|
|
|
|
|
|
const char* password);
|
|
|
|
|
|
|
|
|
|
|
|
/* ── Channels ─────────────────────────────────────────────────────────────── */
|
feat(M4): Windows WinForms client, TOFU identity pinning, VAD threshold + always-on mode
Core ABI extensions (voicecat.h):
- vc_list_channels / vc_list_users / vc_list_user_streams — pull-based snapshot getters
for the channel-tree and user-list UI; session_model_mu_ guards cross-thread reads
- VC_EVENT_JOIN_RESULT / vc_join_channel — channel join with optional password
- VC_EVENT_SERVER_IDENTITY + vc_confirm_server_identity — TOFU gate that blocks io_thread_
until the UI approves or rejects; pins TLS leaf-cert SHA-256 (not declared Ed25519)
- vc_get_server_identity_display — Ed25519 fingerprint for human-readable display only
- VC_INPUT_ALWAYS_ON = 2 in vc_input_mode — transmit unconditionally, no VAD gate
- vc_set_vad_threshold — live RMS threshold update (0.0–1.0); EnergyVadProcessor stores
it atomically so the audio RT path reads without a lock
C++ implementation:
- SessionModel::apply_snapshot / apply_channel_event fixed to populate parent_id,
password_protected, and max_users (were permanently zeroed)
- TlsContext::peer_cert_fingerprint — SHA-256 of peer leaf cert DER via mbedTLS
- TofuStore split into peek (read-only) + pin (write) so first-connect only persists
after user approval; tofu_store_path in vc_config for per-user pin file location
- TcpAcceptor uses dual-stack IPv6+IPv4 fallback (fixes localhost → ::1 on Windows)
- windows-client CMake preset: Release shared DLL, static MinGW runtime, no tools/tests
- New C++ tests: test_channel_user_list_abi, test_tofu_flow (14/14 green)
Windows client (clients/windows/ — .NET 10 WinForms):
- VoiceCat.Interop: LibraryImport P/Invoke surface, UnmanagedCallersOnly callbacks,
Channel<VoiceCatEvent> event delivery drained by 30ms WinForms Timer
- VoiceCat.App: ConnectDialog (saved servers, DPAPI password storage), ServerIdentity-
Dialog (TOFU first-connect / mismatch warning), MainForm (channel TreeView, user
ListBox, RichTextBox chat, voice controls, device pickers, VAD/PTT/always-on mode,
per-user gain/mute/NR tuning, VAD sensitivity TrackBar, level meter ProgressBar)
- PttKeyCaptureDialog — focus-scoped PTT key capture (documented limitation)
- PerUserTuningDialog — real-time gain/mute/NR applied to all of a user's streams
- Accessibility: explicit AccessibleName/Description on every control, & mnemonics,
Activity log ListBox as durable screen-reader record, AutomationNotification for
curated live announcements
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-17 00:35:16 +02:00
|
|
|
|
/* Result arrives as VC_EVENT_JOIN_RESULT, not a return value beyond "request queued". `password`
|
|
|
|
|
|
* is forwarded to the server's JoinChannelRequest.password for channels with
|
|
|
|
|
|
* vc_channel.password_protected set; NOTE (M4): no in-tree channel currently has a server-side
|
|
|
|
|
|
* password to check against — channel creation/passwords are a future (M5+) feature, so this
|
|
|
|
|
|
* path is wired but not yet exercisable end-to-end. */
|
scaffold: M0 skeleton + agent onboarding (build, architecture, progress)
Turn the design into a buildable, dependency-free M0 skeleton plus the
onboarding layer so a new agent can pick up instantly.
Build system:
- CMake + CMakePresets (dev = no deps; server-release = vcpkg) + vcpkg.json
- Skeleton builds with just a C++20 compiler; deps stay off until needed
- .gitattributes (LF), .gitignore, .clang-format
Core (libvoicecat):
- core/include/voicecat.h: full C ABI (the client/server contract), stubbed
- core/proto/voicecat.proto: control-plane wire format, matches docs/protocol.md
- src/{net,crypto,codec,protocol,session,audio,core}: subsystem stubs that
return VC_ERR_NOT_IMPLEMENTED, each pointing to its design doc
- server/ (voicecat-server) and tools/vccli/ link the core
- tests/: CTest smoke test asserting the C ABI contract (behavior, not just build)
- clients/{apple,windows}: M4 placeholders
Onboarding for agents:
- CLAUDE.md: hub — build/test commands, architecture at a glance, doc map, rules
- AGENTS.md: working method (behavior-driven; clean compile is the floor not the goal)
- PROGRESS.md: living tracker — M0 done, M1 task checklist, "where we left off"
Verified: cmake --preset dev && cmake --build --preset dev && ctest --preset dev → green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-15 21:09:09 +02:00
|
|
|
|
VC_API vc_result vc_join_channel(vc_client* c, uint32_t channel_id,
|
|
|
|
|
|
const char* password /* nullable */);
|
|
|
|
|
|
VC_API vc_result vc_leave_channel(vc_client* c);
|
|
|
|
|
|
|
|
|
|
|
|
/* ── Local media streams (mic / screen audio / aux) ───────────────────────── */
|
|
|
|
|
|
VC_API vc_result vc_stream_start(vc_client* c, const vc_stream_desc* desc,
|
|
|
|
|
|
uint32_t* out_stream_id);
|
|
|
|
|
|
VC_API vc_result vc_stream_stop(vc_client* c, uint32_t stream_id);
|
|
|
|
|
|
VC_API vc_result vc_set_input_device(vc_client* c, uint32_t stream_id,
|
|
|
|
|
|
const char* device_id);
|
|
|
|
|
|
|
|
|
|
|
|
/* Send-side: input gate mode + PTT key state, and self mute/deafen. */
|
|
|
|
|
|
VC_API vc_result vc_set_input_mode(vc_client* c, vc_input_mode mode);
|
feat(M4): Windows WinForms client, TOFU identity pinning, VAD threshold + always-on mode
Core ABI extensions (voicecat.h):
- vc_list_channels / vc_list_users / vc_list_user_streams — pull-based snapshot getters
for the channel-tree and user-list UI; session_model_mu_ guards cross-thread reads
- VC_EVENT_JOIN_RESULT / vc_join_channel — channel join with optional password
- VC_EVENT_SERVER_IDENTITY + vc_confirm_server_identity — TOFU gate that blocks io_thread_
until the UI approves or rejects; pins TLS leaf-cert SHA-256 (not declared Ed25519)
- vc_get_server_identity_display — Ed25519 fingerprint for human-readable display only
- VC_INPUT_ALWAYS_ON = 2 in vc_input_mode — transmit unconditionally, no VAD gate
- vc_set_vad_threshold — live RMS threshold update (0.0–1.0); EnergyVadProcessor stores
it atomically so the audio RT path reads without a lock
C++ implementation:
- SessionModel::apply_snapshot / apply_channel_event fixed to populate parent_id,
password_protected, and max_users (were permanently zeroed)
- TlsContext::peer_cert_fingerprint — SHA-256 of peer leaf cert DER via mbedTLS
- TofuStore split into peek (read-only) + pin (write) so first-connect only persists
after user approval; tofu_store_path in vc_config for per-user pin file location
- TcpAcceptor uses dual-stack IPv6+IPv4 fallback (fixes localhost → ::1 on Windows)
- windows-client CMake preset: Release shared DLL, static MinGW runtime, no tools/tests
- New C++ tests: test_channel_user_list_abi, test_tofu_flow (14/14 green)
Windows client (clients/windows/ — .NET 10 WinForms):
- VoiceCat.Interop: LibraryImport P/Invoke surface, UnmanagedCallersOnly callbacks,
Channel<VoiceCatEvent> event delivery drained by 30ms WinForms Timer
- VoiceCat.App: ConnectDialog (saved servers, DPAPI password storage), ServerIdentity-
Dialog (TOFU first-connect / mismatch warning), MainForm (channel TreeView, user
ListBox, RichTextBox chat, voice controls, device pickers, VAD/PTT/always-on mode,
per-user gain/mute/NR tuning, VAD sensitivity TrackBar, level meter ProgressBar)
- PttKeyCaptureDialog — focus-scoped PTT key capture (documented limitation)
- PerUserTuningDialog — real-time gain/mute/NR applied to all of a user's streams
- Accessibility: explicit AccessibleName/Description on every control, & mnemonics,
Activity log ListBox as durable screen-reader record, AutomationNotification for
curated live announcements
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-17 00:35:16 +02:00
|
|
|
|
/* VAD threshold: normalized RMS 0.0–1.0; default ~0.025. Takes effect immediately —
|
|
|
|
|
|
* recreates the VAD gate if a MIC stream is already active. No-op when mode != VOICE_ACTIVATION
|
|
|
|
|
|
* (value is remembered and applied if the mode switches back). */
|
|
|
|
|
|
VC_API vc_result vc_set_vad_threshold(vc_client* c, float threshold);
|
scaffold: M0 skeleton + agent onboarding (build, architecture, progress)
Turn the design into a buildable, dependency-free M0 skeleton plus the
onboarding layer so a new agent can pick up instantly.
Build system:
- CMake + CMakePresets (dev = no deps; server-release = vcpkg) + vcpkg.json
- Skeleton builds with just a C++20 compiler; deps stay off until needed
- .gitattributes (LF), .gitignore, .clang-format
Core (libvoicecat):
- core/include/voicecat.h: full C ABI (the client/server contract), stubbed
- core/proto/voicecat.proto: control-plane wire format, matches docs/protocol.md
- src/{net,crypto,codec,protocol,session,audio,core}: subsystem stubs that
return VC_ERR_NOT_IMPLEMENTED, each pointing to its design doc
- server/ (voicecat-server) and tools/vccli/ link the core
- tests/: CTest smoke test asserting the C ABI contract (behavior, not just build)
- clients/{apple,windows}: M4 placeholders
Onboarding for agents:
- CLAUDE.md: hub — build/test commands, architecture at a glance, doc map, rules
- AGENTS.md: working method (behavior-driven; clean compile is the floor not the goal)
- PROGRESS.md: living tracker — M0 done, M1 task checklist, "where we left off"
Verified: cmake --preset dev && cmake --build --preset dev && ctest --preset dev → green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-15 21:09:09 +02:00
|
|
|
|
VC_API vc_result vc_set_push_to_talk(vc_client* c, int active /* bool */);
|
|
|
|
|
|
VC_API vc_result vc_set_self_mute(vc_client* c, int mic_muted, int deafened);
|
|
|
|
|
|
|
|
|
|
|
|
/* Receive-side, per remote stream, all LOCAL (no protocol traffic) — docs/voice.md §10:
|
|
|
|
|
|
* gain (0..) , mute, and listener-chosen noise reduction on a specific user's stream. */
|
|
|
|
|
|
VC_API vc_result vc_set_remote_stream(vc_client* c, uint32_t user_id, uint32_t stream_id,
|
2026-06-18 02:06:44 +02:00
|
|
|
|
float gain, int muted, int noise_reduction);
|
|
|
|
|
|
|
|
|
|
|
|
/* Reads back the receive-side state last set on (user_id, stream_id) via
|
|
|
|
|
|
* vc_set_remote_stream (or the defaults if never set). VC_ERR_INVALID_ARG if the user/stream
|
|
|
|
|
|
* isn't known. */
|
|
|
|
|
|
VC_API vc_result vc_get_remote_stream(vc_client* c, uint32_t user_id, uint32_t stream_id,
|
|
|
|
|
|
vc_remote_stream_state* out);
|
scaffold: M0 skeleton + agent onboarding (build, architecture, progress)
Turn the design into a buildable, dependency-free M0 skeleton plus the
onboarding layer so a new agent can pick up instantly.
Build system:
- CMake + CMakePresets (dev = no deps; server-release = vcpkg) + vcpkg.json
- Skeleton builds with just a C++20 compiler; deps stay off until needed
- .gitattributes (LF), .gitignore, .clang-format
Core (libvoicecat):
- core/include/voicecat.h: full C ABI (the client/server contract), stubbed
- core/proto/voicecat.proto: control-plane wire format, matches docs/protocol.md
- src/{net,crypto,codec,protocol,session,audio,core}: subsystem stubs that
return VC_ERR_NOT_IMPLEMENTED, each pointing to its design doc
- server/ (voicecat-server) and tools/vccli/ link the core
- tests/: CTest smoke test asserting the C ABI contract (behavior, not just build)
- clients/{apple,windows}: M4 placeholders
Onboarding for agents:
- CLAUDE.md: hub — build/test commands, architecture at a glance, doc map, rules
- AGENTS.md: working method (behavior-driven; clean compile is the floor not the goal)
- PROGRESS.md: living tracker — M0 done, M1 task checklist, "where we left off"
Verified: cmake --preset dev && cmake --build --preset dev && ctest --preset dev → green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-15 21:09:09 +02:00
|
|
|
|
|
feat(M3): multi-stream & per-channel tuning
Implements docs/roadmap.md M3: multiple concurrent streams per user (MIC +
SCREEN_AUDIO + AUX_DEVICE), independent per-stream receiver gain/mute/noise-
reduction, talk indicators, and enforced per-channel Opus configurability
(mono/stereo, bitrate, frame size, FEC/DTX, application).
Bugs fixed along the way (found while implementing, not pre-existing scope):
- Server hard-coded stream_id=1 for every announce, so a second stream from
the same user silently overwrote the first in SessionRegistry::set_user_stream.
Now a per-session counter (ConnSession::next_stream_id_); handle_stream_stop
validates against announced_stream_ids_ before clearing.
- Client dropped mode/dtx/complexity/application from effective_audio even for
the single M2 stream -- only sample_rate/bitrate_bps/frame_ms/fec were ever
applied to OpusParams. Fixed on both the send (handle_stream_announce_result)
and receive (sync_remote_streams) paths via a shared
opus_params_from_audio_config() helper.
- OpusEncoder always used OPUS_APPLICATION_VOIP; added OpusParams::application
and wired it through.
- on_playback's per-stream decode passed the wrong frame_size to opus_decode
(total samples instead of samples-per-channel), which would have overflowed
the decode buffer for any stereo stream.
- teardown_voice() raced when called concurrently from run_io()'s own cleanup
and from disconnect() on a different thread -- both could see
udp_thread_/talk_timer_thread_ as joinable() at once and race to join() the
same std::thread (intermittent std::system_error under ctest). Fixed with a
teardown_mu_ guard instead of carrying the flake forward.
New:
- Per-channel AudioConfig: SessionRegistry now seeds Lobby (mono/24kbps/VOIP/
FEC+DTX) and a new "Music Room" channel (stereo/128kbps/AUDIO/no DTX);
handle_stream_announce enforces the channel's config, clamping (not
overriding) bitrate_bps to its ceiling.
- core/src/core/client.h/.cpp: local-stream state is now a
std::unordered_map<int, LocalStream> keyed by vc_stream_kind, with
request_id-correlated announce/result handling (request_id already
round-tripped on the wire; just wasn't read before). on_capture_frame is
kind-aware and upmixes mono capture to stereo when a stream's config calls
for it. set_self_mute's mic_muted now only gates the MIC kind. NS is wired
through set_remote_stream. New run_talk_timer() thread emits
VC_EVENT_TALK_STATE from both remote and local edge detection.
- core/src/audio/audio_engine.h/.cpp: kind-keyed injection taps
(inject_capture), stereo-to-mono downmix at the decode/mix boundary,
RemoteStream gains recv_ns (lazy ApmProcessor) + noise_reduction_enabled
and last_voice_ms/talking; new set_stream_noise_reduction() and
poll_talk_transitions().
- core/src/session/session.h/.cpp: Stream now carries the full AudioConfig,
not just sample_rate/frame_ms.
- New additive C ABI (core/include/voicecat.h): vc_audio_config +
vc_get_stream_audio_config (effective Opus config for any stream you own or
a peer's); vc_test_inject_capture (test-only synthetic PCM injection,
clearly marked, mirrors AudioEngine::inject_capture).
- tests/test_m3_multistream.cpp: the M3 exit criterion through the real ABI
(mirrors test_voice_client_abi.cpp's approach, not raw sockets) -- two
concurrent local streams, independent gain/mute/NS control, per-channel
config divergence via vc_get_stream_audio_config, talk indicators.
Explicitly out of scope for this pass (tracked in PROGRESS.md, not silently
dropped): VAD/PTT input gate + device enumeration; real WASAPI loopback
capture for SCREEN_AUDIO (synthetic injection only); true stereo playback
output (AudioEngine's mixer/output device stays mono -- Opus itself is fully
stereo-correct on the wire).
ctest --test-dir build/m1-dev: 11/11 green, verified across 3 consecutive
full-suite runs plus 8 standalone runs of the new test.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-16 14:12:37 +02:00
|
|
|
|
/* Effective Opus config in use for (user_id, stream_id) — your own stream or a peer's.
|
|
|
|
|
|
* VC_ERR_INVALID_ARG if the user/stream isn't known. */
|
|
|
|
|
|
VC_API vc_result vc_get_stream_audio_config(vc_client* c, uint32_t user_id, uint32_t stream_id,
|
|
|
|
|
|
vc_audio_config* out);
|
|
|
|
|
|
|
|
|
|
|
|
/* TEST-ONLY — not for production use. Bypasses the real capture device, injecting raw PCM
|
|
|
|
|
|
* directly into the named local stream's encode pipeline (see AudioEngine::inject_capture).
|
|
|
|
|
|
* Exists so automated tests can drive the real vc_client/ABI path end-to-end without a
|
|
|
|
|
|
* microphone. `stream_id` is the id returned by vc_stream_start. */
|
|
|
|
|
|
VC_API vc_result vc_test_inject_capture(vc_client* c, uint32_t stream_id, const int16_t* pcm,
|
|
|
|
|
|
size_t samples);
|
|
|
|
|
|
|
feat(ios): audio overhaul, Join/Leave Voice, channel-id sync fix, stereo mic capture
Three iOS client problems fixed plus a new core stereo-mic capture ABI:
1. Channel-id sync bug (mic button permanently dimmed): SessionState never
synced currentChannelId from the self user's channelId on connect, so the
mic button (gated on currentChannelId == 0) stayed dimmed. Added
syncSelfChannel() (mirrors macOS MainWindowController.swift:461,491,522);
called from init/.channelList/.userJoined/.userLeft/.userUpdated/.joinResult.
Added applyServerMuteState() + serverMuted/serverDeafened to VoiceState.
2. Join/Leave Voice button: replaced icon-only mic toggle with explicit
text button (parity with macOS). Mute/deafen disable when not in voice.
3. IOSAudioRouter.swift (new): full AVAudioSession routing layer — input
port selection, built-in mic orientation/polar patterns, Bluetooth
HFP/A2DP/Off modes, Standard/Raw mic processing, stereo capture, AirPlay,
UserDefaults persistence. AudioSessionManager delegates to it.
4. Core stereo-mic capture (append-only ABI): vc_set_capture_channels()
lets the core open the mic device in stereo (2-ch interleaved). LocalStream
gains capture_channels; ensure_audio_running reads it; audio_engine.cpp
capture_accum_ + on_capture updated to channel-aware accumulation. Test
test_stereo_mic_capture (headless, L!=R stereo round-trip). Swift wrapper
VoiceCatClient.setCaptureChannels.
5. Settings UI rework: AVAudioSession-derived input/output tree replaces
miniaudio device picker.
6. iOS deployment target raised to 18.0 (Package.swift + project.pbxproj).
swift-tools-version 6.0 with swiftLanguageModes .v5.
Docs: tech-stack.md, architecture.md, voice.md, roadmap.md, building.md
updated; stale 'vc_audio_suspend/resume deferred' claims corrected.
Verified: ctest --preset dev 21/21 green; swift test 6/6 green;
xcodebuild -target VoiceCatiOS -sdk iphonesimulator BUILD SUCCEEDED.
2026-06-19 13:17:52 +02:00
|
|
|
|
/* Set the capture channel count for a local MIC stream (1 = mono, 2 = stereo interleaved).
|
2026-06-19 17:39:23 +02:00
|
|
|
|
* Must be called after vc_stream_start. Stores the value; it takes effect on the next engine
|
|
|
|
|
|
* (re)start. Does NOT restart the engine itself — the caller must follow up with
|
|
|
|
|
|
* vc_audio_restart() after AVAudioSession routing has settled (iOS) or after any platform
|
|
|
|
|
|
* audio-session reconfiguration. On iOS the Swift AVAudioSession routing layer enables stereo
|
|
|
|
|
|
* built-in mic capture by switching the built-in mic's data source to the .stereo polar
|
|
|
|
|
|
* pattern (setPreferredDataSource + setPreferredPolarPattern(.stereo) + setPreferredInput +
|
|
|
|
|
|
* setInputDataSource), calls this to record the desired channel count, and then calls
|
|
|
|
|
|
* vc_audio_restart() so the core reopens capture and playback against the new route.
|
|
|
|
|
|
* VC_ERR_INVALID_ARG if stream_id is unknown or channels is not 1 or 2. */
|
feat(ios): audio overhaul, Join/Leave Voice, channel-id sync fix, stereo mic capture
Three iOS client problems fixed plus a new core stereo-mic capture ABI:
1. Channel-id sync bug (mic button permanently dimmed): SessionState never
synced currentChannelId from the self user's channelId on connect, so the
mic button (gated on currentChannelId == 0) stayed dimmed. Added
syncSelfChannel() (mirrors macOS MainWindowController.swift:461,491,522);
called from init/.channelList/.userJoined/.userLeft/.userUpdated/.joinResult.
Added applyServerMuteState() + serverMuted/serverDeafened to VoiceState.
2. Join/Leave Voice button: replaced icon-only mic toggle with explicit
text button (parity with macOS). Mute/deafen disable when not in voice.
3. IOSAudioRouter.swift (new): full AVAudioSession routing layer — input
port selection, built-in mic orientation/polar patterns, Bluetooth
HFP/A2DP/Off modes, Standard/Raw mic processing, stereo capture, AirPlay,
UserDefaults persistence. AudioSessionManager delegates to it.
4. Core stereo-mic capture (append-only ABI): vc_set_capture_channels()
lets the core open the mic device in stereo (2-ch interleaved). LocalStream
gains capture_channels; ensure_audio_running reads it; audio_engine.cpp
capture_accum_ + on_capture updated to channel-aware accumulation. Test
test_stereo_mic_capture (headless, L!=R stereo round-trip). Swift wrapper
VoiceCatClient.setCaptureChannels.
5. Settings UI rework: AVAudioSession-derived input/output tree replaces
miniaudio device picker.
6. iOS deployment target raised to 18.0 (Package.swift + project.pbxproj).
swift-tools-version 6.0 with swiftLanguageModes .v5.
Docs: tech-stack.md, architecture.md, voice.md, roadmap.md, building.md
updated; stale 'vc_audio_suspend/resume deferred' claims corrected.
Verified: ctest --preset dev 21/21 green; swift test 6/6 green;
xcodebuild -target VoiceCatiOS -sdk iphonesimulator BUILD SUCCEEDED.
2026-06-19 13:17:52 +02:00
|
|
|
|
VC_API vc_result vc_set_capture_channels(vc_client* c, uint32_t stream_id, uint32_t channels);
|
|
|
|
|
|
|
scaffold: M0 skeleton + agent onboarding (build, architecture, progress)
Turn the design into a buildable, dependency-free M0 skeleton plus the
onboarding layer so a new agent can pick up instantly.
Build system:
- CMake + CMakePresets (dev = no deps; server-release = vcpkg) + vcpkg.json
- Skeleton builds with just a C++20 compiler; deps stay off until needed
- .gitattributes (LF), .gitignore, .clang-format
Core (libvoicecat):
- core/include/voicecat.h: full C ABI (the client/server contract), stubbed
- core/proto/voicecat.proto: control-plane wire format, matches docs/protocol.md
- src/{net,crypto,codec,protocol,session,audio,core}: subsystem stubs that
return VC_ERR_NOT_IMPLEMENTED, each pointing to its design doc
- server/ (voicecat-server) and tools/vccli/ link the core
- tests/: CTest smoke test asserting the C ABI contract (behavior, not just build)
- clients/{apple,windows}: M4 placeholders
Onboarding for agents:
- CLAUDE.md: hub — build/test commands, architecture at a glance, doc map, rules
- AGENTS.md: working method (behavior-driven; clean compile is the floor not the goal)
- PROGRESS.md: living tracker — M0 done, M1 task checklist, "where we left off"
Verified: cmake --preset dev && cmake --build --preset dev && ctest --preset dev → green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-15 21:09:09 +02:00
|
|
|
|
/* ── Text ─────────────────────────────────────────────────────────────────── */
|
|
|
|
|
|
VC_API vc_result vc_send_text(vc_client* c, vc_text_scope scope, uint32_t target_id,
|
|
|
|
|
|
const char* utf8);
|
|
|
|
|
|
|
|
|
|
|
|
/* ── Device enumeration (for UI pickers) ──────────────────────────────────── */
|
|
|
|
|
|
VC_API vc_result vc_list_devices(vc_client* c, vc_device_kind kind, vc_device_list* out);
|
|
|
|
|
|
VC_API void vc_free_device_list(vc_device_list* list);
|
|
|
|
|
|
|
feat(M4): Windows WinForms client, TOFU identity pinning, VAD threshold + always-on mode
Core ABI extensions (voicecat.h):
- vc_list_channels / vc_list_users / vc_list_user_streams — pull-based snapshot getters
for the channel-tree and user-list UI; session_model_mu_ guards cross-thread reads
- VC_EVENT_JOIN_RESULT / vc_join_channel — channel join with optional password
- VC_EVENT_SERVER_IDENTITY + vc_confirm_server_identity — TOFU gate that blocks io_thread_
until the UI approves or rejects; pins TLS leaf-cert SHA-256 (not declared Ed25519)
- vc_get_server_identity_display — Ed25519 fingerprint for human-readable display only
- VC_INPUT_ALWAYS_ON = 2 in vc_input_mode — transmit unconditionally, no VAD gate
- vc_set_vad_threshold — live RMS threshold update (0.0–1.0); EnergyVadProcessor stores
it atomically so the audio RT path reads without a lock
C++ implementation:
- SessionModel::apply_snapshot / apply_channel_event fixed to populate parent_id,
password_protected, and max_users (were permanently zeroed)
- TlsContext::peer_cert_fingerprint — SHA-256 of peer leaf cert DER via mbedTLS
- TofuStore split into peek (read-only) + pin (write) so first-connect only persists
after user approval; tofu_store_path in vc_config for per-user pin file location
- TcpAcceptor uses dual-stack IPv6+IPv4 fallback (fixes localhost → ::1 on Windows)
- windows-client CMake preset: Release shared DLL, static MinGW runtime, no tools/tests
- New C++ tests: test_channel_user_list_abi, test_tofu_flow (14/14 green)
Windows client (clients/windows/ — .NET 10 WinForms):
- VoiceCat.Interop: LibraryImport P/Invoke surface, UnmanagedCallersOnly callbacks,
Channel<VoiceCatEvent> event delivery drained by 30ms WinForms Timer
- VoiceCat.App: ConnectDialog (saved servers, DPAPI password storage), ServerIdentity-
Dialog (TOFU first-connect / mismatch warning), MainForm (channel TreeView, user
ListBox, RichTextBox chat, voice controls, device pickers, VAD/PTT/always-on mode,
per-user gain/mute/NR tuning, VAD sensitivity TrackBar, level meter ProgressBar)
- PttKeyCaptureDialog — focus-scoped PTT key capture (documented limitation)
- PerUserTuningDialog — real-time gain/mute/NR applied to all of a user's streams
- Accessibility: explicit AccessibleName/Description on every control, & mnemonics,
Activity log ListBox as durable screen-reader record, AutomationNotification for
curated live announcements
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-17 00:35:16 +02:00
|
|
|
|
/* ── Channel / user / stream enumeration (M4; mirrors vc_list_devices above) ─────────────── */
|
|
|
|
|
|
VC_API vc_result vc_list_channels(vc_client* c, vc_channel_list* out);
|
|
|
|
|
|
VC_API void vc_free_channel_list(vc_channel_list* list);
|
|
|
|
|
|
|
|
|
|
|
|
VC_API vc_result vc_list_users(vc_client* c, vc_user_list* out);
|
|
|
|
|
|
VC_API void vc_free_user_list(vc_user_list* list);
|
|
|
|
|
|
|
|
|
|
|
|
/* Streams currently owned by user_id (their mic/screen-audio/aux), per the last snapshot/
|
|
|
|
|
|
* event. VC_ERR_INVALID_ARG if user_id is unknown. */
|
|
|
|
|
|
VC_API vc_result vc_list_user_streams(vc_client* c, uint32_t user_id,
|
|
|
|
|
|
vc_stream_summary_list* out);
|
|
|
|
|
|
VC_API void vc_free_stream_summary_list(vc_stream_summary_list* list);
|
|
|
|
|
|
|
|
|
|
|
|
/* ── TOFU server-identity confirmation (M4) — see VC_EVENT_SERVER_IDENTITY/vc_tofu_status ── */
|
|
|
|
|
|
/* Accept or reject the pending server-identity check for the in-progress connect(). Must be
|
|
|
|
|
|
* called after a VC_EVENT_SERVER_IDENTITY event; the io_thread_ holds the connection open
|
|
|
|
|
|
* (ClientHello/auth deferred) until this is called, up to a generous internal timeout (after
|
|
|
|
|
|
* which it's treated as a reject). accept=0 aborts the connection (emits
|
|
|
|
|
|
* VC_EVENT_DISCONNECTED, result=VC_ERR_CRYPTO) and does NOT update the pin file. accept=1 on
|
|
|
|
|
|
* FIRST_CONNECT/MISMATCH updates the pin file to the new fingerprint and proceeds; accept=1 on
|
|
|
|
|
|
* MATCHED is a no-op confirmation (always safe) and proceeds. VC_ERR_INVALID_ARG if no
|
|
|
|
|
|
* identity confirmation is currently pending. */
|
|
|
|
|
|
VC_API vc_result vc_confirm_server_identity(vc_client* c, int accept /* bool */);
|
|
|
|
|
|
|
|
|
|
|
|
/* The Ed25519 identity fingerprint from ServerHello, hex-formatted for display (e.g. "this
|
|
|
|
|
|
* server also identifies as <hex>"). Purely informational — NOT the value
|
|
|
|
|
|
* vc_confirm_server_identity gates on (see vc_tofu_status's doc comment). Empty string if not
|
|
|
|
|
|
* yet available. Pass out_buf=NULL to query the required buffer size via *out_len first;
|
|
|
|
|
|
* otherwise out_buf must be >= *out_len + 1 bytes (NUL-terminated UTF-8/ASCII hex). */
|
|
|
|
|
|
VC_API vc_result vc_get_server_identity_display(vc_client* c, char* out_buf, size_t buf_cap,
|
|
|
|
|
|
size_t* out_len);
|
|
|
|
|
|
|
M5: moderation, permissions, channel CRUD, in-app account management
- Server-side moderation & permissions (kick/ban/move/server-mute, channel CRUD).
- Database schema v2: channels, bans; BLAKE2b channel passwords, Argon2id accounts.
- C ABI additions and client-side handling (vc_kick_user, vc_ban_user, vc_set_permission, vc_set_server_mute, vc_move_user, vc_create/edit/delete_channel, vc_create/reset/delete/list_account).
- vccli flags for all M5 operations plus --username/--password auth.
- Four new tests covering permissions, kick/ban/move/mute, admin accounts, channel CRUD.
- Docs: protocol.md envelope updates, security.md channel-password hashing, PROGRESS.md.
2026-06-17 15:08:05 +02:00
|
|
|
|
/* ── M5: Moderation & admin ─────────────────────────────────────────────────
|
|
|
|
|
|
* All calls are async; the result arrives as VC_EVENT_GENERIC_RESULT (or
|
|
|
|
|
|
* VC_EVENT_ACCOUNT_LIST for vc_list_accounts). They require VC_STATE_CONNECTED and,
|
|
|
|
|
|
* on the server side, the appropriate permission. */
|
|
|
|
|
|
|
|
|
|
|
|
VC_API vc_result vc_kick_user(vc_client* c, uint32_t user_id, const char* reason);
|
|
|
|
|
|
VC_API vc_result vc_ban_user(vc_client* c, uint32_t user_id, const char* reason,
|
|
|
|
|
|
uint64_t expires_unix_ms);
|
|
|
|
|
|
VC_API vc_result vc_set_permission(vc_client* c, uint32_t user_id,
|
|
|
|
|
|
const vc_permissions* perms);
|
|
|
|
|
|
VC_API vc_result vc_set_server_mute(vc_client* c, uint32_t user_id, int muted, int deafened);
|
|
|
|
|
|
VC_API vc_result vc_move_user(vc_client* c, uint32_t user_id, uint32_t channel_id);
|
|
|
|
|
|
|
|
|
|
|
|
VC_API vc_result vc_create_channel(vc_client* c, const vc_channel_info* info);
|
|
|
|
|
|
VC_API vc_result vc_edit_channel(vc_client* c, const vc_channel_info* info);
|
|
|
|
|
|
VC_API vc_result vc_delete_channel(vc_client* c, uint32_t channel_id);
|
|
|
|
|
|
|
|
|
|
|
|
VC_API vc_result vc_create_account(vc_client* c, const char* username, const char* password);
|
|
|
|
|
|
VC_API vc_result vc_reset_password(vc_client* c, const char* username,
|
|
|
|
|
|
const char* new_password);
|
|
|
|
|
|
VC_API vc_result vc_delete_account(vc_client* c, const char* username);
|
|
|
|
|
|
VC_API vc_result vc_list_accounts(vc_client* c);
|
|
|
|
|
|
|
2026-06-17 16:31:29 +02:00
|
|
|
|
/* Pull the last received account list (populated when VC_EVENT_ACCOUNT_LIST fires).
|
|
|
|
|
|
* Caller must free the list with vc_free_account_list. */
|
|
|
|
|
|
VC_API vc_result vc_get_account_list(vc_client* c, vc_account_list* out);
|
|
|
|
|
|
VC_API void vc_free_account_list(vc_account_list* list);
|
|
|
|
|
|
|
M5: moderation, permissions, channel CRUD, in-app account management
- Server-side moderation & permissions (kick/ban/move/server-mute, channel CRUD).
- Database schema v2: channels, bans; BLAKE2b channel passwords, Argon2id accounts.
- C ABI additions and client-side handling (vc_kick_user, vc_ban_user, vc_set_permission, vc_set_server_mute, vc_move_user, vc_create/edit/delete_channel, vc_create/reset/delete/list_account).
- vccli flags for all M5 operations plus --username/--password auth.
- Four new tests covering permissions, kick/ban/move/mute, admin accounts, channel CRUD.
- Docs: protocol.md envelope updates, security.md channel-password hashing, PROGRESS.md.
2026-06-17 15:08:05 +02:00
|
|
|
|
/* Pull the caller's own permissions (from the last AuthResult). */
|
|
|
|
|
|
VC_API vc_result vc_get_permissions(vc_client* c, vc_permissions* out);
|
|
|
|
|
|
|
2026-06-19 02:10:25 +02:00
|
|
|
|
/* AVAudioSession interruption hooks (iOS M6). Pause/resume miniaudio device I/O for
|
|
|
|
|
|
* AVAudioSession interruptions (phone call, Siri, etc.) and backgrounding. Call
|
|
|
|
|
|
* vc_audio_suspend() when an interruption begins; call vc_audio_resume() after the
|
|
|
|
|
|
* session is re-activated. No-op if the audio engine is not running. */
|
|
|
|
|
|
VC_API vc_result vc_audio_suspend(vc_client* c);
|
|
|
|
|
|
VC_API vc_result vc_audio_resume(vc_client* c);
|
|
|
|
|
|
|
2026-06-19 16:58:21 +02:00
|
|
|
|
/* Full audio engine restart (iOS M6). Unlike vc_audio_suspend/resume which only stop/start
|
|
|
|
|
|
* the existing miniaudio devices (leaving them bound to the route that was active when they
|
|
|
|
|
|
* were opened), vc_audio_restart() uninitializes and re-initializes the capture and playback
|
|
|
|
|
|
* devices so they pick up a new AVAudioSession route. Call this from the Swift layer AFTER
|
|
|
|
|
|
* reconfiguring AVAudioSession (setCategory, setPreferredInput, setPreferredPolarPattern, etc.)
|
2026-06-20 03:03:34 +02:00
|
|
|
|
* so the core's devices reopen against the new route.
|
2026-06-19 16:58:21 +02:00
|
|
|
|
* Safe to call when the engine is not running (it will just start it). */
|
|
|
|
|
|
VC_API vc_result vc_audio_restart(vc_client* c);
|
|
|
|
|
|
|
scaffold: M0 skeleton + agent onboarding (build, architecture, progress)
Turn the design into a buildable, dependency-free M0 skeleton plus the
onboarding layer so a new agent can pick up instantly.
Build system:
- CMake + CMakePresets (dev = no deps; server-release = vcpkg) + vcpkg.json
- Skeleton builds with just a C++20 compiler; deps stay off until needed
- .gitattributes (LF), .gitignore, .clang-format
Core (libvoicecat):
- core/include/voicecat.h: full C ABI (the client/server contract), stubbed
- core/proto/voicecat.proto: control-plane wire format, matches docs/protocol.md
- src/{net,crypto,codec,protocol,session,audio,core}: subsystem stubs that
return VC_ERR_NOT_IMPLEMENTED, each pointing to its design doc
- server/ (voicecat-server) and tools/vccli/ link the core
- tests/: CTest smoke test asserting the C ABI contract (behavior, not just build)
- clients/{apple,windows}: M4 placeholders
Onboarding for agents:
- CLAUDE.md: hub — build/test commands, architecture at a glance, doc map, rules
- AGENTS.md: working method (behavior-driven; clean compile is the floor not the goal)
- PROGRESS.md: living tracker — M0 done, M1 task checklist, "where we left off"
Verified: cmake --preset dev && cmake --build --preset dev && ctest --preset dev → green.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-15 21:09:09 +02:00
|
|
|
|
#if defined(__cplusplus)
|
|
|
|
|
|
} /* extern "C" */
|
|
|
|
|
|
#endif
|
|
|
|
|
|
|
|
|
|
|
|
#endif /* VOICECAT_H */
|