screenpeer

package
v0.1.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: MIT Imports: 7 Imported by: 0

Documentation

Overview

Package screenpeer authenticates EPN2 connections before EPS2 ownership. TCP connection direction does not change the cryptographic device/host roles.

Index

Constants

View Source
const HandshakeTimeout = 15 * time.Second

Variables

This section is empty.

Functions

func Device

func Device(socket Socket, key securetransport.Key, id securetransport.DeviceID,
	lifetime *network.Lifetime, now time.Time,
) (stream *securetransport.RecordStream, err error)

Device consumes a durable-epoch session number BEFORE any bytes are written. The manager supplies the random nonce; Pico needs uniqueness, not a weak RNG. https://www.rfc-editor.org/rfc/rfc5116.html#section-3.1

func Manager

Manager selects a key by the public preface, then verifies the HMAC binding before sending authentication. A successful return, not the untrusted ID, grants permission to open a screen session. No EPS1/legacy downgrade exists.

Types

type HostScreen

type HostScreen struct {
	// contains filtered or unexported fields
}

HostScreen adapts complete EPN2 reply envelopes to screenclient's USB-style io.ReadWriter without losing message boundaries. One request/one reply only.

func NewHostScreen

func NewHostScreen(socket Socket, records *securetransport.RecordStream) (*HostScreen, error)

func (*HostScreen) Read

func (s *HostScreen) Read(dst []byte) (int, error)

func (*HostScreen) Write

func (s *HostScreen) Write(p []byte) (int, error)

type Socket

type Socket interface {
	io.ReadWriteCloser
	SetDeadline(time.Time) error
}

Socket deadlines must interrupt pending I/O. Its owner must close on every subsequent record error and set per-exchange deadlines after authentication. A RecordStream is half-duplex: concurrent Read/Write share bounded scratch.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL