feat(M1): TCP/TLS control plane -- auth, channels, ephemeral text

Implements the full M1 milestone. Two clients authenticate over TLS 1.3
(guest + Argon2id password) and exchange channel + private text messages
through a real server. All five ctest --preset m1-dev tests pass in ~1 s.

Key components added:
- vcpkg baseline + m1-dev preset (protobuf/mbedTLS/libsodium/asio/sqlite3)
- FrameCodec feed+emit, encode/decode_envelope, protobuf codegen
- TcpServerConn with blocking TLS handshake thread + tls_read_loop
- TlsContext (mbedTLS 1.3, ECDSA-P256 self-signed cert, TOFU on client)
- WorkerPool (3 threads, used for Argon2id)
- Database: SQLite + libsodium Argon2id, account lifecycle, bootstrap admin
- ServerIdentityManager: Ed25519 key + cert generate/persist/fingerprint
- ConnSession state machine: WaitingHello -> WaitingAuth -> Authenticated
- SessionRegistry: channel tree, user map, text routing, broadcast
- vc_client full M1 C ABI: connect/TLS/handshake/auth/text/disconnect
- voicecat-admin CLI: account add/reset/del/list
- test_m1_integration: M1 exit criterion, verified green

Bug fixed: double-framing in ConnSession::send_envelope -- encode_envelope
was adding the [4-byte len] prefix, then TcpServerConn::send_frame added
a second one, causing the client to parse [len][proto] as protobuf (silent
failure). Fixed by serializing raw protobuf bytes in send_envelope and
letting send_frame apply the single length prefix.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-06-15 23:48:44 +02:00
parent b332b0972b
commit 63f457fc54
42 changed files with 4180 additions and 190 deletions

View File

@@ -1,8 +1,87 @@
#include "session/session.h"
#include <algorithm>
namespace voicecat::session {
// M0 stub. Channel tree, users, streams, permissions, and ephemeral text relay land in M1.
// See docs/protocol.md §5.
const Channel* SessionModel::find_channel(uint32_t id) const {
for (auto& ch : channels_) if (ch.id == id) return &ch;
return nullptr;
}
const User* SessionModel::find_user(uint32_t id) const {
for (auto& u : users_) if (u.id == id) return &u;
return nullptr;
}
#ifdef VOICECAT_HAS_NET
void SessionModel::apply_snapshot(const voicecat::v1::ServerStateSnapshot& snap) {
channels_.clear();
for (const auto& pb : snap.channels()) {
Channel ch;
ch.id = pb.id();
ch.name = pb.name();
channels_.push_back(std::move(ch));
}
users_.clear();
for (const auto& pb : snap.users()) {
User u;
u.id = pb.id();
u.nickname = pb.nickname();
u.is_guest = pb.is_guest();
u.channel_id = pb.channel_id();
users_.push_back(std::move(u));
}
}
void SessionModel::apply_user_event(const voicecat::v1::UserEvent& ev) {
using Kind = voicecat::v1::UserEvent;
if (ev.kind() == Kind::JOINED || ev.kind() == Kind::UPDATED) {
const auto& pb = ev.user();
User u;
u.id = pb.id();
u.nickname = pb.nickname();
u.is_guest = pb.is_guest();
u.channel_id = pb.channel_id();
auto it = std::find_if(users_.begin(), users_.end(),
[&](const User& x) { return x.id == u.id; });
if (it != users_.end()) *it = std::move(u);
else users_.push_back(std::move(u));
} else if (ev.kind() == Kind::LEFT) {
uint32_t uid = ev.user().id();
users_.erase(std::remove_if(users_.begin(), users_.end(),
[uid](const User& x) { return x.id == uid; }),
users_.end());
}
}
void SessionModel::apply_channel_event(const voicecat::v1::ChannelEvent& ev) {
using Kind = voicecat::v1::ChannelEvent;
if (ev.kind() == Kind::CREATED || ev.kind() == Kind::UPDATED) {
const auto& pb = ev.channel();
Channel ch;
ch.id = pb.id();
ch.name = pb.name();
auto it = std::find_if(channels_.begin(), channels_.end(),
[&](const Channel& x) { return x.id == ch.id; });
if (it != channels_.end()) *it = std::move(ch);
else channels_.push_back(std::move(ch));
} else if (ev.kind() == Kind::DELETED) {
uint32_t cid = ev.channel().id();
channels_.erase(std::remove_if(channels_.begin(), channels_.end(),
[cid](const Channel& x) { return x.id == cid; }),
channels_.end());
}
}
#endif // VOICECAT_HAS_NET
} // namespace voicecat::session