feat(M4): Windows WinForms client, TOFU identity pinning, VAD threshold + always-on mode
Core ABI extensions (voicecat.h): - vc_list_channels / vc_list_users / vc_list_user_streams — pull-based snapshot getters for the channel-tree and user-list UI; session_model_mu_ guards cross-thread reads - VC_EVENT_JOIN_RESULT / vc_join_channel — channel join with optional password - VC_EVENT_SERVER_IDENTITY + vc_confirm_server_identity — TOFU gate that blocks io_thread_ until the UI approves or rejects; pins TLS leaf-cert SHA-256 (not declared Ed25519) - vc_get_server_identity_display — Ed25519 fingerprint for human-readable display only - VC_INPUT_ALWAYS_ON = 2 in vc_input_mode — transmit unconditionally, no VAD gate - vc_set_vad_threshold — live RMS threshold update (0.0–1.0); EnergyVadProcessor stores it atomically so the audio RT path reads without a lock C++ implementation: - SessionModel::apply_snapshot / apply_channel_event fixed to populate parent_id, password_protected, and max_users (were permanently zeroed) - TlsContext::peer_cert_fingerprint — SHA-256 of peer leaf cert DER via mbedTLS - TofuStore split into peek (read-only) + pin (write) so first-connect only persists after user approval; tofu_store_path in vc_config for per-user pin file location - TcpAcceptor uses dual-stack IPv6+IPv4 fallback (fixes localhost → ::1 on Windows) - windows-client CMake preset: Release shared DLL, static MinGW runtime, no tools/tests - New C++ tests: test_channel_user_list_abi, test_tofu_flow (14/14 green) Windows client (clients/windows/ — .NET 10 WinForms): - VoiceCat.Interop: LibraryImport P/Invoke surface, UnmanagedCallersOnly callbacks, Channel<VoiceCatEvent> event delivery drained by 30ms WinForms Timer - VoiceCat.App: ConnectDialog (saved servers, DPAPI password storage), ServerIdentity- Dialog (TOFU first-connect / mismatch warning), MainForm (channel TreeView, user ListBox, RichTextBox chat, voice controls, device pickers, VAD/PTT/always-on mode, per-user gain/mute/NR tuning, VAD sensitivity TrackBar, level meter ProgressBar) - PttKeyCaptureDialog — focus-scoped PTT key capture (documented limitation) - PerUserTuningDialog — real-time gain/mute/NR applied to all of a user's streams - Accessibility: explicit AccessibleName/Description on every control, & mnemonics, Activity log ListBox as durable screen-reader record, AutomationNotification for curated live announcements Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -283,6 +283,14 @@ bool TlsContext::export_keying_material(const char* label, const uint8_t* ctx, s
|
||||
ctx, ctx_len, ctx != nullptr) == 0;
|
||||
}
|
||||
|
||||
bool TlsContext::peer_cert_fingerprint(std::array<uint8_t, 32>& out) const {
|
||||
if (!ready_) return false;
|
||||
const mbedtls_x509_crt* peer = mbedtls_ssl_get_peer_cert(&ssl_);
|
||||
if (!peer) return false;
|
||||
mbedtls_sha256(peer->raw.p, peer->raw.len, out.data(), 0);
|
||||
return true;
|
||||
}
|
||||
|
||||
// ── SodiumMediaCrypto ─────────────────────────────────────────────────────────
|
||||
|
||||
SodiumMediaCrypto::SodiumMediaCrypto(
|
||||
|
||||
@@ -88,6 +88,13 @@ class TlsContext {
|
||||
bool export_keying_material(const char* label, const uint8_t* ctx, size_t ctx_len,
|
||||
uint8_t* out, size_t out_len);
|
||||
|
||||
// M4 TOFU: SHA-256 of the peer's leaf X.509 certificate (DER), valid only after a
|
||||
// successful Role::Client handshake(). This is the value vc_client pins — see
|
||||
// voicecat.h's vc_tofu_status doc comment for why the cert fingerprint is pinned instead
|
||||
// of the declared Ed25519 server_identity_fingerprint. Returns false if no peer cert is
|
||||
// available (e.g. Role::Server, or handshake() hasn't succeeded).
|
||||
bool peer_cert_fingerprint(std::array<uint8_t, 32>& out) const;
|
||||
|
||||
// Whether the handshake completed.
|
||||
bool ready() const { return ready_; }
|
||||
|
||||
|
||||
@@ -25,6 +25,21 @@ TofuResult TofuStore::check_and_pin(const std::string& host, uint16_t port,
|
||||
return (it->second == fingerprint) ? TofuResult::Matched : TofuResult::Mismatch;
|
||||
}
|
||||
|
||||
TofuResult TofuStore::peek(const std::string& host, uint16_t port,
|
||||
const std::array<uint8_t, 32>& fingerprint) const {
|
||||
std::lock_guard<std::mutex> lk(mu_);
|
||||
auto it = pins_.find(make_key(host, port));
|
||||
if (it == pins_.end()) return TofuResult::FirstConnect;
|
||||
return (it->second == fingerprint) ? TofuResult::Matched : TofuResult::Mismatch;
|
||||
}
|
||||
|
||||
void TofuStore::pin(const std::string& host, uint16_t port,
|
||||
const std::array<uint8_t, 32>& fingerprint) {
|
||||
std::lock_guard<std::mutex> lk(mu_);
|
||||
pins_[make_key(host, port)] = fingerprint;
|
||||
save();
|
||||
}
|
||||
|
||||
void TofuStore::remove(const std::string& host, uint16_t port) {
|
||||
std::lock_guard<std::mutex> lk(mu_);
|
||||
pins_.erase(make_key(host, port));
|
||||
|
||||
@@ -29,9 +29,21 @@ class TofuStore {
|
||||
|
||||
// Check the fingerprint for host:port. Stores on first connect.
|
||||
// Thread-safe (single-writer lock).
|
||||
// NOTE: kept for compatibility; the M4 gated-confirmation flow (vc_client) uses peek()
|
||||
// + pin() instead, since check_and_pin's unconditional first-connect write is wrong for a
|
||||
// flow where the application must approve the fingerprint before it's trusted/persisted.
|
||||
TofuResult check_and_pin(const std::string& host, uint16_t port,
|
||||
const std::array<uint8_t, 32>& fingerprint);
|
||||
|
||||
// Read-only — classifies the fingerprint against any existing pin WITHOUT writing to disk.
|
||||
// Use this before the application has had a chance to approve a first-connect/mismatch.
|
||||
TofuResult peek(const std::string& host, uint16_t port,
|
||||
const std::array<uint8_t, 32>& fingerprint) const;
|
||||
|
||||
// Persist the pin for host:port. Call only after the caller has accepted a FIRST_CONNECT
|
||||
// or MISMATCH classification from peek() — accepting a MATCHED result needs no call here.
|
||||
void pin(const std::string& host, uint16_t port, const std::array<uint8_t, 32>& fingerprint);
|
||||
|
||||
// Remove the pin for host:port (e.g. after user explicitly acknowledges a key change).
|
||||
void remove(const std::string& host, uint16_t port);
|
||||
|
||||
@@ -44,7 +56,7 @@ class TofuStore {
|
||||
void save() const;
|
||||
|
||||
std::filesystem::path path_;
|
||||
std::mutex mu_;
|
||||
mutable std::mutex mu_;
|
||||
std::unordered_map<std::string, std::array<uint8_t, 32>> pins_;
|
||||
};
|
||||
|
||||
|
||||
Reference in New Issue
Block a user