feat(M4): Windows WinForms client, TOFU identity pinning, VAD threshold + always-on mode

Core ABI extensions (voicecat.h):
- vc_list_channels / vc_list_users / vc_list_user_streams — pull-based snapshot getters
  for the channel-tree and user-list UI; session_model_mu_ guards cross-thread reads
- VC_EVENT_JOIN_RESULT / vc_join_channel — channel join with optional password
- VC_EVENT_SERVER_IDENTITY + vc_confirm_server_identity — TOFU gate that blocks io_thread_
  until the UI approves or rejects; pins TLS leaf-cert SHA-256 (not declared Ed25519)
- vc_get_server_identity_display — Ed25519 fingerprint for human-readable display only
- VC_INPUT_ALWAYS_ON = 2 in vc_input_mode — transmit unconditionally, no VAD gate
- vc_set_vad_threshold — live RMS threshold update (0.0–1.0); EnergyVadProcessor stores
  it atomically so the audio RT path reads without a lock

C++ implementation:
- SessionModel::apply_snapshot / apply_channel_event fixed to populate parent_id,
  password_protected, and max_users (were permanently zeroed)
- TlsContext::peer_cert_fingerprint — SHA-256 of peer leaf cert DER via mbedTLS
- TofuStore split into peek (read-only) + pin (write) so first-connect only persists
  after user approval; tofu_store_path in vc_config for per-user pin file location
- TcpAcceptor uses dual-stack IPv6+IPv4 fallback (fixes localhost → ::1 on Windows)
- windows-client CMake preset: Release shared DLL, static MinGW runtime, no tools/tests
- New C++ tests: test_channel_user_list_abi, test_tofu_flow (14/14 green)

Windows client (clients/windows/ — .NET 10 WinForms):
- VoiceCat.Interop: LibraryImport P/Invoke surface, UnmanagedCallersOnly callbacks,
  Channel<VoiceCatEvent> event delivery drained by 30ms WinForms Timer
- VoiceCat.App: ConnectDialog (saved servers, DPAPI password storage), ServerIdentity-
  Dialog (TOFU first-connect / mismatch warning), MainForm (channel TreeView, user
  ListBox, RichTextBox chat, voice controls, device pickers, VAD/PTT/always-on mode,
  per-user gain/mute/NR tuning, VAD sensitivity TrackBar, level meter ProgressBar)
- PttKeyCaptureDialog — focus-scoped PTT key capture (documented limitation)
- PerUserTuningDialog — real-time gain/mute/NR applied to all of a user's streams
- Accessibility: explicit AccessibleName/Description on every control, & mnemonics,
  Activity log ListBox as durable screen-reader record, AutomationNotification for
  curated live announcements

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-06-17 00:35:16 +02:00
parent 5be869c61a
commit 63b241cc2e
56 changed files with 4685 additions and 35 deletions

View File

@@ -283,6 +283,14 @@ bool TlsContext::export_keying_material(const char* label, const uint8_t* ctx, s
ctx, ctx_len, ctx != nullptr) == 0;
}
bool TlsContext::peer_cert_fingerprint(std::array<uint8_t, 32>& out) const {
if (!ready_) return false;
const mbedtls_x509_crt* peer = mbedtls_ssl_get_peer_cert(&ssl_);
if (!peer) return false;
mbedtls_sha256(peer->raw.p, peer->raw.len, out.data(), 0);
return true;
}
// ── SodiumMediaCrypto ─────────────────────────────────────────────────────────
SodiumMediaCrypto::SodiumMediaCrypto(

View File

@@ -88,6 +88,13 @@ class TlsContext {
bool export_keying_material(const char* label, const uint8_t* ctx, size_t ctx_len,
uint8_t* out, size_t out_len);
// M4 TOFU: SHA-256 of the peer's leaf X.509 certificate (DER), valid only after a
// successful Role::Client handshake(). This is the value vc_client pins — see
// voicecat.h's vc_tofu_status doc comment for why the cert fingerprint is pinned instead
// of the declared Ed25519 server_identity_fingerprint. Returns false if no peer cert is
// available (e.g. Role::Server, or handshake() hasn't succeeded).
bool peer_cert_fingerprint(std::array<uint8_t, 32>& out) const;
// Whether the handshake completed.
bool ready() const { return ready_; }

View File

@@ -25,6 +25,21 @@ TofuResult TofuStore::check_and_pin(const std::string& host, uint16_t port,
return (it->second == fingerprint) ? TofuResult::Matched : TofuResult::Mismatch;
}
TofuResult TofuStore::peek(const std::string& host, uint16_t port,
const std::array<uint8_t, 32>& fingerprint) const {
std::lock_guard<std::mutex> lk(mu_);
auto it = pins_.find(make_key(host, port));
if (it == pins_.end()) return TofuResult::FirstConnect;
return (it->second == fingerprint) ? TofuResult::Matched : TofuResult::Mismatch;
}
void TofuStore::pin(const std::string& host, uint16_t port,
const std::array<uint8_t, 32>& fingerprint) {
std::lock_guard<std::mutex> lk(mu_);
pins_[make_key(host, port)] = fingerprint;
save();
}
void TofuStore::remove(const std::string& host, uint16_t port) {
std::lock_guard<std::mutex> lk(mu_);
pins_.erase(make_key(host, port));

View File

@@ -29,9 +29,21 @@ class TofuStore {
// Check the fingerprint for host:port. Stores on first connect.
// Thread-safe (single-writer lock).
// NOTE: kept for compatibility; the M4 gated-confirmation flow (vc_client) uses peek()
// + pin() instead, since check_and_pin's unconditional first-connect write is wrong for a
// flow where the application must approve the fingerprint before it's trusted/persisted.
TofuResult check_and_pin(const std::string& host, uint16_t port,
const std::array<uint8_t, 32>& fingerprint);
// Read-only — classifies the fingerprint against any existing pin WITHOUT writing to disk.
// Use this before the application has had a chance to approve a first-connect/mismatch.
TofuResult peek(const std::string& host, uint16_t port,
const std::array<uint8_t, 32>& fingerprint) const;
// Persist the pin for host:port. Call only after the caller has accepted a FIRST_CONNECT
// or MISMATCH classification from peek() — accepting a MATCHED result needs no call here.
void pin(const std::string& host, uint16_t port, const std::array<uint8_t, 32>& fingerprint);
// Remove the pin for host:port (e.g. after user explicitly acknowledges a key change).
void remove(const std::string& host, uint16_t port);
@@ -44,7 +56,7 @@ class TofuStore {
void save() const;
std::filesystem::path path_;
std::mutex mu_;
mutable std::mutex mu_;
std::unordered_map<std::string, std::array<uint8_t, 32>> pins_;
};