securetransport

package
v0.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: MIT Imports: 9 Imported by: 0

Documentation

Index

Constants

View Source
const (
	ChallengeSize = 56
	AuthSize      = 72
	HeaderSize    = 16
	TagSize       = 16
	// One bounded EPS2 header + 1024-byte payload. Independent of the legacy
	// buffered-display protocol; no silent fragmentation inside RecordStream.
	MaxPlaintext = 1056
	MaxEnvelope  = HeaderSize + MaxPlaintext + TagSize
)

Variables

View Source
var (
	ErrAuthentication = errors.New("secure transport: authentication failed")
	ErrBounds         = errors.New("secure transport: invalid bounds")
	ErrConfig         = errors.New("secure transport: invalid configuration")
	ErrSequence       = errors.New("secure transport: invalid sequence")
)

Functions

func NewHostSession

func NewHostSession(key Key, device DeviceID, wire []byte, nonce ClientNonce) (Auth, *Session, error)

Types

type Auth

type Auth [AuthSize]byte

type Challenge

type Challenge [ChallengeSize]byte

func NewChallenge

func NewChallenge(key Key, device DeviceID, epoch, session uint64) (Challenge, error)

type ClientNonce

type ClientNonce [32]byte

type DeviceID

type DeviceID [16]byte

type Key

type Key [32]byte

type ReadLimits

type ReadLimits struct {
	Idle, Active time.Duration
	SetDeadline  func(time.Time) error
}

ReadLimits separates idle waiting from one ciphertext record's total budget. SetDeadline must affect pending socket I/O, not merely record local timestamps.

type RecordStream

type RecordStream struct {
	// contains filtered or unexported fields
}

func HostHandshake

func HostHandshake(stream io.ReadWriter, key Key, device DeviceID, nonce ClientNonce) (*RecordStream, error)

func NewRecordStream

func NewRecordStream(stream io.ReadWriter, session *Session) *RecordStream

func ServerHandshake

func ServerHandshake(stream io.ReadWriter, key Key, device DeviceID, epoch, sessionNumber uint64) (*RecordStream, error)

func (*RecordStream) Read

func (s *RecordStream) Read(dst []byte) (int, error)

func (*RecordStream) ReadRecord

func (s *RecordStream) ReadRecord(dst []byte, limits ReadLimits) (n int, err error)

ReadRecord returns exactly one authenticated plaintext envelope. EPN2 binds this envelope to exactly one complete EPS2 record. TCP fragmentation remains arbitrary; splitting an EPS2 record across AEAD envelopes is not permitted. dst must have room for MaxPlaintext; reject before consuming any bytes. Do not mix with a partially consumed Read stream. Any error poisons this instance: close the physical transport, never retry at a guessed boundary.

func (*RecordStream) Write

func (s *RecordStream) Write(record []byte) (int, error)

type Session

type Session struct {
	// contains filtered or unexported fields
}

func NewDeviceSession

func NewDeviceSession(key Key, device DeviceID, challengeWire, authWire []byte) (*Session, error)

func (*Session) Open

func (s *Session) Open(dst, envelope []byte) (int, error)

func (*Session) Seal

func (s *Session) Seal(dst, plaintext []byte) (int, error)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL