feat(M1): TCP/TLS control plane -- auth, channels, ephemeral text
Implements the full M1 milestone. Two clients authenticate over TLS 1.3 (guest + Argon2id password) and exchange channel + private text messages through a real server. All five ctest --preset m1-dev tests pass in ~1 s. Key components added: - vcpkg baseline + m1-dev preset (protobuf/mbedTLS/libsodium/asio/sqlite3) - FrameCodec feed+emit, encode/decode_envelope, protobuf codegen - TcpServerConn with blocking TLS handshake thread + tls_read_loop - TlsContext (mbedTLS 1.3, ECDSA-P256 self-signed cert, TOFU on client) - WorkerPool (3 threads, used for Argon2id) - Database: SQLite + libsodium Argon2id, account lifecycle, bootstrap admin - ServerIdentityManager: Ed25519 key + cert generate/persist/fingerprint - ConnSession state machine: WaitingHello -> WaitingAuth -> Authenticated - SessionRegistry: channel tree, user map, text routing, broadcast - vc_client full M1 C ABI: connect/TLS/handshake/auth/text/disconnect - voicecat-admin CLI: account add/reset/del/list - test_m1_integration: M1 exit criterion, verified green Bug fixed: double-framing in ConnSession::send_envelope -- encode_envelope was adding the [4-byte len] prefix, then TcpServerConn::send_frame added a second one, causing the client to parse [len][proto] as protobuf (silent failure). Fixed by serializing raw protobuf bytes in send_envelope and letting send_frame apply the single length prefix. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -1,10 +1,11 @@
|
||||
/*
|
||||
* net/transport.h — TCP control channel + UDP media channel.
|
||||
*
|
||||
* Design: docs/architecture.md (Net thread), docs/protocol.md §1 (framing), docs/voice.md §2
|
||||
* (UDP frame). Implementation will use standalone Asio (one reactor) for sockets/timers.
|
||||
* Design: docs/architecture.md (Net thread), docs/protocol.md §1 (framing).
|
||||
* Implementation uses standalone Asio for sockets and timers.
|
||||
*
|
||||
* STATUS: M0 stub — interfaces only, no Asio yet.
|
||||
* The real classes are compiled only when VOICECAT_HAS_NET is defined (m1-dev+).
|
||||
* The dev-preset stub definitions below keep the skeleton build green.
|
||||
*/
|
||||
#ifndef VOICECAT_NET_TRANSPORT_H
|
||||
#define VOICECAT_NET_TRANSPORT_H
|
||||
@@ -12,22 +13,161 @@
|
||||
#include <cstdint>
|
||||
#include <string>
|
||||
|
||||
#ifdef VOICECAT_HAS_NET
|
||||
|
||||
#define ASIO_STANDALONE 1
|
||||
#include <asio.hpp>
|
||||
|
||||
#include <atomic>
|
||||
#include <deque>
|
||||
#include <functional>
|
||||
#include <memory>
|
||||
#include <mutex>
|
||||
#include <thread>
|
||||
#include <vector>
|
||||
|
||||
#include "protocol/protocol.h"
|
||||
|
||||
// Forward-declare TlsContext so transport.h does not pull in mbedTLS headers.
|
||||
namespace voicecat::crypto { class TlsContext; }
|
||||
|
||||
namespace voicecat::net {
|
||||
|
||||
// Length-prefixed [u32 length][payload] framing over a TLS 1.3 byte stream (protocol.md §1).
|
||||
class TcpControlChannel {
|
||||
public:
|
||||
// TODO(M1): connect(host, port), TLS handshake, send/recv framed Envelopes.
|
||||
bool connected() const { return connected_; }
|
||||
|
||||
private:
|
||||
bool connected_ = false;
|
||||
// Callbacks delivered on the net thread. Callers must not block inside them.
|
||||
struct TcpChannelCallbacks {
|
||||
std::function<void()> on_connected;
|
||||
std::function<void(std::error_code)> on_connect_error;
|
||||
std::function<void(std::vector<uint8_t>)> on_frame; // one decoded frame payload
|
||||
std::function<void(std::error_code)> on_error;
|
||||
std::function<void()> on_disconnected;
|
||||
};
|
||||
|
||||
// UDP media channel: encrypted voice frames (voice.md §2), bound to a session via token.
|
||||
// ── Client-side: owns an io_context + dedicated net thread ──────────────────
|
||||
class TcpControlChannel {
|
||||
public:
|
||||
explicit TcpControlChannel(TcpChannelCallbacks cbs);
|
||||
~TcpControlChannel();
|
||||
|
||||
// Async connect; calls on_connected or on_connect_error on the net thread.
|
||||
void async_connect(const std::string& host, uint16_t port);
|
||||
|
||||
// Queue a framed send (thread-safe; callable from any thread).
|
||||
void send_frame(std::vector<uint8_t> payload);
|
||||
|
||||
// Graceful close; safe to call from any thread. Waits for the net thread to join.
|
||||
void close();
|
||||
|
||||
bool connected() const { return connected_.load(std::memory_order_acquire); }
|
||||
|
||||
// Access the io_context so callers can post work back to the net thread.
|
||||
asio::io_context& io() { return io_; }
|
||||
|
||||
private:
|
||||
void run_loop();
|
||||
void start_read();
|
||||
void handle_length(std::error_code ec, std::size_t n);
|
||||
void handle_body(uint32_t length, std::error_code ec, std::size_t n);
|
||||
void do_send();
|
||||
|
||||
asio::io_context io_;
|
||||
asio::executor_work_guard<asio::io_context::executor_type> work_guard_;
|
||||
asio::ip::tcp::socket socket_;
|
||||
asio::strand<asio::io_context::executor_type> strand_;
|
||||
std::thread net_thread_;
|
||||
|
||||
TcpChannelCallbacks cbs_;
|
||||
protocol::FrameCodec codec_;
|
||||
|
||||
uint8_t len_buf_[4]{};
|
||||
std::vector<uint8_t> body_buf_;
|
||||
std::deque<std::vector<uint8_t>> send_queue_;
|
||||
bool sending_{false};
|
||||
std::atomic<bool> connected_{false};
|
||||
std::atomic<bool> closing_{false};
|
||||
};
|
||||
|
||||
// ── Server-side: one per accepted socket, shares the server's io_context ────
|
||||
class TcpServerConn : public std::enable_shared_from_this<TcpServerConn> {
|
||||
public:
|
||||
// Plain TCP constructor (no TLS — for tests or future plaintext paths).
|
||||
TcpServerConn(asio::ip::tcp::socket socket, TcpChannelCallbacks cbs);
|
||||
|
||||
// TLS constructor: takes ownership of a TlsContext; start() will run the
|
||||
// handshake on a temporary thread then switch to a TLS I/O thread.
|
||||
TcpServerConn(asio::ip::tcp::socket socket, TcpChannelCallbacks cbs,
|
||||
std::unique_ptr<voicecat::crypto::TlsContext> tls);
|
||||
|
||||
~TcpServerConn();
|
||||
|
||||
// Begin reading; must be called once after construction (on the io thread).
|
||||
void start();
|
||||
|
||||
// Thread-safe send (safe to call from the server's io thread or another strand).
|
||||
void send_frame(std::vector<uint8_t> payload);
|
||||
|
||||
// Close the connection (safe from any thread).
|
||||
void close();
|
||||
|
||||
bool connected() const { return connected_.load(std::memory_order_acquire); }
|
||||
|
||||
private:
|
||||
// ── Asio path (no TLS) ───────────────────────────────────────────────────
|
||||
void start_read();
|
||||
void handle_length(std::error_code ec, std::size_t n);
|
||||
void handle_body(uint32_t length, std::error_code ec, std::size_t n);
|
||||
void do_send();
|
||||
|
||||
// ── TLS path ─────────────────────────────────────────────────────────────
|
||||
void tls_read_loop();
|
||||
void tls_drain_sends();
|
||||
|
||||
asio::ip::tcp::socket socket_;
|
||||
asio::strand<asio::any_io_executor> strand_;
|
||||
TcpChannelCallbacks cbs_;
|
||||
protocol::FrameCodec codec_;
|
||||
|
||||
uint8_t len_buf_[4]{};
|
||||
std::vector<uint8_t> body_buf_;
|
||||
std::deque<std::vector<uint8_t>> send_queue_;
|
||||
bool sending_{false};
|
||||
std::atomic<bool> connected_{false};
|
||||
std::atomic<bool> closing_{false};
|
||||
|
||||
// TLS members (null in plain-TCP mode)
|
||||
std::unique_ptr<voicecat::crypto::TlsContext> tls_;
|
||||
std::thread tls_thread_;
|
||||
std::mutex tls_send_mutex_;
|
||||
std::deque<std::vector<uint8_t>> tls_send_queue_;
|
||||
};
|
||||
|
||||
// ── Server-side acceptor ─────────────────────────────────────────────────────
|
||||
// Spawns a TcpServerConn (via factory) for each accepted TCP connection.
|
||||
class TcpAcceptor {
|
||||
public:
|
||||
using ConnFactory = std::function<std::shared_ptr<TcpServerConn>(asio::ip::tcp::socket)>;
|
||||
|
||||
TcpAcceptor(asio::io_context& io, uint16_t port, ConnFactory factory);
|
||||
|
||||
// Start accepting. Call once; re-arms itself automatically.
|
||||
void start();
|
||||
|
||||
// Stop accepting (does not close existing connections).
|
||||
void stop();
|
||||
|
||||
// Actual bound port (useful when bind_port=0 lets the OS pick).
|
||||
uint16_t local_port() const { return static_cast<uint16_t>(acceptor_.local_endpoint().port()); }
|
||||
|
||||
private:
|
||||
void do_accept();
|
||||
|
||||
asio::ip::tcp::acceptor acceptor_;
|
||||
ConnFactory factory_;
|
||||
bool stopped_{false};
|
||||
};
|
||||
|
||||
// ── UDP media channel (M2) ───────────────────────────────────────────────────
|
||||
class UdpMediaChannel {
|
||||
public:
|
||||
// TODO(M2): bind, send/recv AEAD-sealed voice frames, keepalive.
|
||||
bool bound() const { return bound_; }
|
||||
|
||||
private:
|
||||
@@ -36,4 +176,21 @@ class UdpMediaChannel {
|
||||
|
||||
} // namespace voicecat::net
|
||||
|
||||
#else // !VOICECAT_HAS_NET — skeleton stubs for the dev preset
|
||||
|
||||
namespace voicecat::net {
|
||||
|
||||
class TcpControlChannel {
|
||||
public:
|
||||
bool connected() const { return false; }
|
||||
};
|
||||
|
||||
class UdpMediaChannel {
|
||||
public:
|
||||
bool bound() const { return false; }
|
||||
};
|
||||
|
||||
} // namespace voicecat::net
|
||||
|
||||
#endif // VOICECAT_HAS_NET
|
||||
#endif // VOICECAT_NET_TRANSPORT_H
|
||||
|
||||
Reference in New Issue
Block a user