feat(M1): TCP/TLS control plane -- auth, channels, ephemeral text

Implements the full M1 milestone. Two clients authenticate over TLS 1.3
(guest + Argon2id password) and exchange channel + private text messages
through a real server. All five ctest --preset m1-dev tests pass in ~1 s.

Key components added:
- vcpkg baseline + m1-dev preset (protobuf/mbedTLS/libsodium/asio/sqlite3)
- FrameCodec feed+emit, encode/decode_envelope, protobuf codegen
- TcpServerConn with blocking TLS handshake thread + tls_read_loop
- TlsContext (mbedTLS 1.3, ECDSA-P256 self-signed cert, TOFU on client)
- WorkerPool (3 threads, used for Argon2id)
- Database: SQLite + libsodium Argon2id, account lifecycle, bootstrap admin
- ServerIdentityManager: Ed25519 key + cert generate/persist/fingerprint
- ConnSession state machine: WaitingHello -> WaitingAuth -> Authenticated
- SessionRegistry: channel tree, user map, text routing, broadcast
- vc_client full M1 C ABI: connect/TLS/handshake/auth/text/disconnect
- voicecat-admin CLI: account add/reset/del/list
- test_m1_integration: M1 exit criterion, verified green

Bug fixed: double-framing in ConnSession::send_envelope -- encode_envelope
was adding the [4-byte len] prefix, then TcpServerConn::send_frame added
a second one, causing the client to parse [len][proto] as protobuf (silent
failure). Fixed by serializing raw protobuf bytes in send_envelope and
letting send_frame apply the single length prefix.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-06-15 23:48:44 +02:00
parent b332b0972b
commit 63f457fc54
42 changed files with 4180 additions and 190 deletions

View File

@@ -25,19 +25,35 @@ set_target_properties(voicecat PROPERTIES
VISIBILITY_INLINES_HIDDEN ON)
if(VOICECAT_USE_VCPKG_DEPS)
# Wire real dependencies here as each subsystem is implemented. Example (uncomment
# the ones a subsystem needs; see docs/tech-stack.md and core/proto for protobuf):
# find_package(unofficial-sodium CONFIG REQUIRED) # crypto/ (libsodium)
# find_package(MbedTLS CONFIG REQUIRED) # crypto/ (TLS 1.3)
# find_package(Opus CONFIG REQUIRED) # codec/
# find_package(protobuf CONFIG REQUIRED) # protocol/
# find_package(asio CONFIG REQUIRED) # net/
# find_package(unofficial-sqlite3 CONFIG REQUIRED) # server persistence
# find_package(spdlog CONFIG REQUIRED)
# target_link_libraries(voicecat PRIVATE Opus::opus protobuf::libprotobuf ...)
#
# protobuf codegen (when protocol/ is implemented):
# find_package(Protobuf CONFIG REQUIRED)
# protobuf_generate(TARGET voicecat PROTOS proto/voicecat.proto LANGUAGE cpp)
message(STATUS "voicecat: deps ON — add find_package()/link calls here as subsystems land")
find_package(protobuf CONFIG REQUIRED)
find_package(unofficial-sodium CONFIG REQUIRED)
find_package(MbedTLS CONFIG REQUIRED)
find_package(asio CONFIG REQUIRED)
find_package(unofficial-sqlite3 CONFIG REQUIRED)
find_package(spdlog CONFIG REQUIRED)
# Generate C++ from voicecat.proto into the build tree.
protobuf_generate(
TARGET voicecat
PROTOS proto/voicecat.proto
LANGUAGE cpp
IMPORT_DIRS ${CMAKE_CURRENT_SOURCE_DIR}/proto
PROTOC_OUT_DIR ${CMAKE_CURRENT_BINARY_DIR}/generated/proto)
# Generated .pb.h files are included by protocol/envelope.h (consumed by tests and server),
# so the generated dir and protobuf itself must be PUBLIC.
target_include_directories(voicecat PUBLIC ${CMAKE_CURRENT_BINARY_DIR}/generated)
target_link_libraries(voicecat
PUBLIC protobuf::libprotobuf
PRIVATE unofficial-sodium::sodium
MbedTLS::mbedtls MbedTLS::mbedcrypto MbedTLS::mbedx509
asio::asio unofficial::sqlite3::sqlite3 spdlog::spdlog)
if(WIN32)
# AcceptEx / GetAcceptExSockaddrs live in mswsock; ws2_32 covers the base Winsock API.
target_link_libraries(voicecat PRIVATE ws2_32 mswsock)
endif()
# Signal to C++ code that the real networking/crypto stack is available.
target_compile_definitions(voicecat PUBLIC VOICECAT_HAS_NET)
endif()