fix(media): stop permanent voice loss after bad-network blip (protocol v2)
A bad UDP packet on a flaky link could permanently wedge the voice path, unrecoverable even across app restarts. Three defects: 1. Anti-replay window was advanced from the UNAUTHENTICATED header seq before the AEAD tag was checked, and not rolled back on failure. One corrupted/forged frame shoved recv_highest_ far ahead, after which every legitimate frame was rejected as "too old" forever. Reorder to replay-check -> authenticate -> update (RFC 3711 3.3); the window now moves only after a successful tag check. 2. The wire seq was only the low 16 bits of the nonce counter (zero-extended on receive). After 65,536 frames the nonce desynced and all frames failed auth. Widen the voice frame seq u16 -> u64 (header 14 -> 20 bytes). The core owns all UDP framing, so Swift/C# clients need only a rebuild. This is a versioned wire change: VOICECAT_PROTOCOL_VERSION 1 -> 2, handshake rejects on mismatch. 3. Server leaked per-session UDP state on disconnect; unregister_session now frees udp_endpoints_/udp_tokens_/ssrc_to_session_. Also add rate-limited dropped-frame logging to MediaRelay so a wedged media path is observable. New regression tests in test_media_aead.cpp cover the poison (fails on old code) and the 16-bit wrap. ctest --preset dev -E external_pcm: 22/22 pass (external_pcm aborts on a pre-existing CoreAudio shutdown race, unrelated).
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* test_voice_frame — serialize/parse round-trips for the 14-byte UDP media header.
|
||||
* test_voice_frame — serialize/parse round-trips for the 20-byte UDP media header.
|
||||
*/
|
||||
#include <cassert>
|
||||
#include <cstdio>
|
||||
@@ -24,7 +24,7 @@ static void test_header_round_trip() {
|
||||
f.flags = kFlagMarker | kFlagFecPresent;
|
||||
f.codec = kCodecOpus;
|
||||
f.ssrc = 0xDEADBEEF;
|
||||
f.seq = 0xAB12;
|
||||
f.seq = 0x0123456789ABCDEFULL; // full 64-bit range (protocol v2)
|
||||
f.timestamp = 0x12345678;
|
||||
|
||||
uint8_t buf[kVoiceHeaderSize];
|
||||
@@ -97,18 +97,19 @@ static void test_parse_too_short() {
|
||||
static void test_big_endian_layout() {
|
||||
VoiceFrame f;
|
||||
f.ssrc = 0x01020304;
|
||||
f.seq = 0x0506;
|
||||
f.timestamp = 0x0708090A;
|
||||
f.seq = 0x05060708090A0B0CULL;
|
||||
f.timestamp = 0x0D0E0F10;
|
||||
|
||||
uint8_t buf[kVoiceHeaderSize];
|
||||
serialize_header(f, buf);
|
||||
|
||||
// ssrc at [4..7]
|
||||
CHECK(buf[4] == 0x01 && buf[5] == 0x02 && buf[6] == 0x03 && buf[7] == 0x04);
|
||||
// seq at [8..9]
|
||||
CHECK(buf[8] == 0x05 && buf[9] == 0x06);
|
||||
// timestamp at [10..13]
|
||||
CHECK(buf[10] == 0x07 && buf[11] == 0x08 && buf[12] == 0x09 && buf[13] == 0x0A);
|
||||
// seq (u64) at [8..15]
|
||||
CHECK(buf[8] == 0x05 && buf[9] == 0x06 && buf[10] == 0x07 && buf[11] == 0x08 &&
|
||||
buf[12] == 0x09 && buf[13] == 0x0A && buf[14] == 0x0B && buf[15] == 0x0C);
|
||||
// timestamp at [16..19]
|
||||
CHECK(buf[16] == 0x0D && buf[17] == 0x0E && buf[18] == 0x0F && buf[19] == 0x10);
|
||||
}
|
||||
|
||||
int main() {
|
||||
|
||||
Reference in New Issue
Block a user