feat(M1): TCP/TLS control plane -- auth, channels, ephemeral text
Implements the full M1 milestone. Two clients authenticate over TLS 1.3 (guest + Argon2id password) and exchange channel + private text messages through a real server. All five ctest --preset m1-dev tests pass in ~1 s. Key components added: - vcpkg baseline + m1-dev preset (protobuf/mbedTLS/libsodium/asio/sqlite3) - FrameCodec feed+emit, encode/decode_envelope, protobuf codegen - TcpServerConn with blocking TLS handshake thread + tls_read_loop - TlsContext (mbedTLS 1.3, ECDSA-P256 self-signed cert, TOFU on client) - WorkerPool (3 threads, used for Argon2id) - Database: SQLite + libsodium Argon2id, account lifecycle, bootstrap admin - ServerIdentityManager: Ed25519 key + cert generate/persist/fingerprint - ConnSession state machine: WaitingHello -> WaitingAuth -> Authenticated - SessionRegistry: channel tree, user map, text routing, broadcast - vc_client full M1 C ABI: connect/TLS/handshake/auth/text/disconnect - voicecat-admin CLI: account add/reset/del/list - test_m1_integration: M1 exit criterion, verified green Bug fixed: double-framing in ConnSession::send_envelope -- encode_envelope was adding the [4-byte len] prefix, then TcpServerConn::send_frame added a second one, causing the client to parse [len][proto] as protobuf (silent failure). Fixed by serializing raw protobuf bytes in send_envelope and letting send_frame apply the single length prefix. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -1,38 +1,42 @@
|
||||
/*
|
||||
* server.h — voicecat-server skeleton.
|
||||
* server/server.h — VoiceCat server entry point.
|
||||
*
|
||||
* Design: docs/architecture.md §5, docs/deployment.md. Headless process that links the core.
|
||||
* Responsibilities: connection manager (TLS), session registry, channel manager, text router,
|
||||
* voice SFU relay, SQLite persistence. Zero-config: self-provisions Ed25519 identity + cert
|
||||
* on first run, embedded SQLite, guests on by default.
|
||||
*
|
||||
* STATUS: M0 stub — prints config and exits; does not yet listen.
|
||||
* Design: docs/architecture.md §5. Headless process: TLS control listener,
|
||||
* session registry, text relay, SQLite persistence. Zero-config first-run.
|
||||
*/
|
||||
#ifndef VOICECAT_SERVER_SERVER_H
|
||||
#define VOICECAT_SERVER_SERVER_H
|
||||
|
||||
#include <cstdint>
|
||||
#include <functional>
|
||||
#include <mutex>
|
||||
#include <string>
|
||||
|
||||
namespace voicecat::server {
|
||||
|
||||
struct Config {
|
||||
std::string server_name = "VoiceCat Server";
|
||||
std::string data_dir = "voicecat-data";
|
||||
uint16_t bind_port = 8384; // TCP + UDP (docs/deployment.md §2)
|
||||
bool allow_guests = true;
|
||||
std::string data_dir = "voicecat-data";
|
||||
uint16_t bind_port = 8384; // 0 = let OS pick (useful for tests)
|
||||
bool allow_guests = true;
|
||||
// Called with the actual bound port once the acceptor is ready (m1-dev only).
|
||||
std::function<void(uint16_t)> on_ready;
|
||||
};
|
||||
|
||||
class Server {
|
||||
public:
|
||||
explicit Server(Config cfg) : cfg_(std::move(cfg)) {}
|
||||
|
||||
// TODO(M1): bind TLS control listener + UDP media socket; run the Asio loop until stop.
|
||||
// Returns process exit code.
|
||||
// Block until the server shuts down. Returns process exit code.
|
||||
int run();
|
||||
|
||||
// Thread-safe stop: unblocks run() from any thread. No-op if not running.
|
||||
void stop();
|
||||
|
||||
private:
|
||||
Config cfg_;
|
||||
Config cfg_;
|
||||
std::mutex stop_mutex_;
|
||||
std::function<void()> stop_fn_;
|
||||
};
|
||||
|
||||
} // namespace voicecat::server
|
||||
|
||||
Reference in New Issue
Block a user