feat(M1): TCP/TLS control plane -- auth, channels, ephemeral text

Implements the full M1 milestone. Two clients authenticate over TLS 1.3
(guest + Argon2id password) and exchange channel + private text messages
through a real server. All five ctest --preset m1-dev tests pass in ~1 s.

Key components added:
- vcpkg baseline + m1-dev preset (protobuf/mbedTLS/libsodium/asio/sqlite3)
- FrameCodec feed+emit, encode/decode_envelope, protobuf codegen
- TcpServerConn with blocking TLS handshake thread + tls_read_loop
- TlsContext (mbedTLS 1.3, ECDSA-P256 self-signed cert, TOFU on client)
- WorkerPool (3 threads, used for Argon2id)
- Database: SQLite + libsodium Argon2id, account lifecycle, bootstrap admin
- ServerIdentityManager: Ed25519 key + cert generate/persist/fingerprint
- ConnSession state machine: WaitingHello -> WaitingAuth -> Authenticated
- SessionRegistry: channel tree, user map, text routing, broadcast
- vc_client full M1 C ABI: connect/TLS/handshake/auth/text/disconnect
- voicecat-admin CLI: account add/reset/del/list
- test_m1_integration: M1 exit criterion, verified green

Bug fixed: double-framing in ConnSession::send_envelope -- encode_envelope
was adding the [4-byte len] prefix, then TcpServerConn::send_frame added
a second one, causing the client to parse [len][proto] as protobuf (silent
failure). Fixed by serializing raw protobuf bytes in send_envelope and
letting send_frame apply the single length prefix.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-06-15 23:48:44 +02:00
parent b332b0972b
commit 63f457fc54
42 changed files with 4180 additions and 190 deletions

View File

@@ -1,8 +1,42 @@
# Tests use plain asserts + exit codes for now (no framework dependency in the skeleton).
# A real framework (e.g. Catch2/GoogleTest via vcpkg) can be added when VOICECAT_USE_VCPKG_DEPS
# is on. Behavior tests — not just "it compiles" — are how milestones are judged (AGENTS.md).
# Tests use plain asserts + exit codes (no framework dep needed).
# Behavior tests — not just "it compiles" — are how milestones are judged (AGENTS.md).
add_executable(test_smoke test_smoke.cpp)
target_link_libraries(test_smoke PRIVATE voicecat::voicecat)
target_compile_features(test_smoke PRIVATE cxx_std_20)
add_test(NAME smoke COMMAND test_smoke)
# frame_codec has no third-party deps; runs under both dev and m1-dev.
# Needs core/src on the include path to reach internal headers (protocol/, session/, etc.).
add_executable(test_frame_codec test_frame_codec.cpp)
target_link_libraries(test_frame_codec PRIVATE voicecat::voicecat)
target_compile_features(test_frame_codec PRIVATE cxx_std_20)
target_include_directories(test_frame_codec PRIVATE ${CMAKE_SOURCE_DIR}/core/src)
add_test(NAME frame_codec COMMAND test_frame_codec)
if(VOICECAT_USE_VCPKG_DEPS)
set(VC_TEST_INTERNAL_INCLUDES
${CMAKE_SOURCE_DIR}/core/src
${CMAKE_SOURCE_DIR}/server/src
${CMAKE_BINARY_DIR}/core/generated) # protobuf-generated headers
add_executable(test_envelope test_envelope.cpp)
target_link_libraries(test_envelope PRIVATE voicecat::voicecat)
target_compile_features(test_envelope PRIVATE cxx_std_20)
target_include_directories(test_envelope PRIVATE ${VC_TEST_INTERNAL_INCLUDES})
add_test(NAME envelope COMMAND test_envelope)
add_executable(test_tls_loopback test_tls_loopback.cpp)
target_link_libraries(test_tls_loopback PRIVATE voicecat::voicecat)
target_compile_features(test_tls_loopback PRIVATE cxx_std_20)
target_include_directories(test_tls_loopback PRIVATE ${VC_TEST_INTERNAL_INCLUDES})
add_test(NAME tls_loopback COMMAND test_tls_loopback)
# Links voicecat::server (which pulls in voicecat::voicecat + all deps transitively).
add_executable(test_m1_integration test_m1_integration.cpp)
target_link_libraries(test_m1_integration PRIVATE voicecat::server)
target_compile_features(test_m1_integration PRIVATE cxx_std_20)
target_include_directories(test_m1_integration PRIVATE ${VC_TEST_INTERNAL_INCLUDES})
add_test(NAME m1_integration COMMAND test_m1_integration)
set_tests_properties(m1_integration PROPERTIES TIMEOUT 60)
endif()