fix(media): stop permanent voice loss after bad-network blip (protocol v2)
A bad UDP packet on a flaky link could permanently wedge the voice path, unrecoverable even across app restarts. Three defects: 1. Anti-replay window was advanced from the UNAUTHENTICATED header seq before the AEAD tag was checked, and not rolled back on failure. One corrupted/forged frame shoved recv_highest_ far ahead, after which every legitimate frame was rejected as "too old" forever. Reorder to replay-check -> authenticate -> update (RFC 3711 3.3); the window now moves only after a successful tag check. 2. The wire seq was only the low 16 bits of the nonce counter (zero-extended on receive). After 65,536 frames the nonce desynced and all frames failed auth. Widen the voice frame seq u16 -> u64 (header 14 -> 20 bytes). The core owns all UDP framing, so Swift/C# clients need only a rebuild. This is a versioned wire change: VOICECAT_PROTOCOL_VERSION 1 -> 2, handshake rejects on mismatch. 3. Server leaked per-session UDP state on disconnect; unregister_session now frees udp_endpoints_/udp_tokens_/ssrc_to_session_. Also add rate-limited dropped-frame logging to MediaRelay so a wedged media path is observable. New regression tests in test_media_aead.cpp cover the poison (fails on old code) and the 16-bit wrap. ctest --preset dev -E external_pcm: 22/22 pass (external_pcm aborts on a pre-existing CoreAudio shutdown race, unrelated).
This commit is contained in:
@@ -49,10 +49,20 @@ class MediaRelay {
|
||||
private:
|
||||
void on_udp_frame(const uint8_t* data, size_t len, asio::ip::udp::endpoint sender);
|
||||
|
||||
// Count a dropped inbound voice frame (by reason) and emit a rate-limited summary
|
||||
// to stderr. Runs on the io thread, so plain counters are safe.
|
||||
void note_drop(const char* reason);
|
||||
|
||||
asio::io_context& io_;
|
||||
std::shared_ptr<SessionRegistry> registry_;
|
||||
voicecat::net::UdpMediaChannel udp_;
|
||||
|
||||
// Diagnostics: dropped-frame counters so a wedged media path is observable.
|
||||
uint64_t drop_no_endpoint_ = 0; // voice from an unmapped UDP endpoint
|
||||
uint64_t drop_no_crypto_ = 0; // session has no recv_crypto yet
|
||||
uint64_t drop_open_failed_ = 0; // AEAD auth failure or replay reject
|
||||
int64_t last_drop_log_ms_ = 0;
|
||||
|
||||
// Scratch buffer for re-encrypted payloads (size = max_frame + 16 MAC)
|
||||
static constexpr size_t kMaxPayload = 1500;
|
||||
std::vector<uint8_t> seal_buf_ = std::vector<uint8_t>(kMaxPayload + 16, uint8_t{0});
|
||||
|
||||
Reference in New Issue
Block a user