Talon 6071c8e238 fix(media): stop permanent voice loss after bad-network blip (protocol v2)
A bad UDP packet on a flaky link could permanently wedge the voice path,
unrecoverable even across app restarts. Three defects:

1. Anti-replay window was advanced from the UNAUTHENTICATED header seq
   before the AEAD tag was checked, and not rolled back on failure. One
   corrupted/forged frame shoved recv_highest_ far ahead, after which every
   legitimate frame was rejected as "too old" forever. Reorder to
   replay-check -> authenticate -> update (RFC 3711 3.3); the window now
   moves only after a successful tag check.

2. The wire seq was only the low 16 bits of the nonce counter (zero-extended
   on receive). After 65,536 frames the nonce desynced and all frames failed
   auth. Widen the voice frame seq u16 -> u64 (header 14 -> 20 bytes). The
   core owns all UDP framing, so Swift/C# clients need only a rebuild. This
   is a versioned wire change: VOICECAT_PROTOCOL_VERSION 1 -> 2, handshake
   rejects on mismatch.

3. Server leaked per-session UDP state on disconnect; unregister_session now
   frees udp_endpoints_/udp_tokens_/ssrc_to_session_.

Also add rate-limited dropped-frame logging to MediaRelay so a wedged media
path is observable. New regression tests in test_media_aead.cpp cover the
poison (fails on old code) and the 16-bit wrap. ctest --preset dev
-E external_pcm: 22/22 pass (external_pcm aborts on a pre-existing CoreAudio
shutdown race, unrelated).
2026-06-21 17:45:28 +02:00

VoiceCat

Self-hosted, native voice & text chat in the spirit of classic TeamSpeak / Mumble — channel-based voice, channel + private text, one server you run yourself. Plain TCP (control) and UDP (media), no WebRTC. Encrypted by default. A shared C++ core (libvoicecat) drives native clients (Swift on macOS/iOS, C# on Windows) and the server.

Status: Design complete in docs/. M1M5 are implemented — real TLS control plane, encrypted UDP voice (Opus), multi-stream, TOFU identity pinning, channel tree, permissions, moderation, disconnect/keepalive/reaper. Windows WinForms C# client shipped (M4). macOS/iOS Swift client is next. See PROGRESS.md and docs/roadmap.md.

Read the design first

The docs/ folder is the source of truth. Start at docs/README.md, then architectureprotocolvoicesecuritytech-stackdeploymentroadmap.

Build

The default development preset is dev — it builds everything (server + tools + tests) with real vcpkg deps. It works on Windows, Linux, and macOS (vcpkg triplet auto-resolved).

# one-time vcpkg setup:
git clone https://github.com/microsoft/vcpkg && ./vcpkg/bootstrap-vcpkg.sh  # .bat on Windows
export VCPKG_ROOT=/path/to/vcpkg            # Linux/macOS; or $env:VCPKG_ROOT on PowerShell

# configure + build + test:
cmake --preset dev
cmake --build --preset dev
ctest --preset dev                          # 21 behavior tests

Artifacts land in build/dev/bin/ (voicecat-server, vccli, voicecat-admin).

The skeleton preset (no vcpkg deps, stubs only) is a fast smoke check that needs no third-party libraries:

cmake --preset skeleton && cmake --build --preset skeleton && ctest --preset skeleton

See docs/building.md for the full preset matrix (including release, server-release, windows-client, and Apple platform scaffolding).

Layout

docs/         design spec (read this)
core/         libvoicecat — the shared C++ core
  include/    voicecat.h  (the C ABI all clients call)
  proto/      voicecat.proto  (control-plane wire format, source of truth)
  src/        net/ crypto/ codec/ protocol/ session/ audio/  (stubs today)
server/       voicecat-server (headless; links the core)
tools/vccli/  headless test client — drives the protocol from M1 on
clients/      apple/ (Swift, M4)   windows/ (C#, M4)   — placeholders for now
tests/        CTest targets

License

Permissive-only dependencies (no GPL/LGPL) so the project can be redistributed freely, including closed-source. Project license: TBD (see docs/tech-stack.md §5).

Description
Native voice chat server and client
Readme 12 MiB
Languages
C++ 43.9%
Swift 30.6%
C# 17.5%
Shell 3.6%
CMake 2.1%
Other 2.3%