Documentation
¶
Index ¶
- Constants
- Variables
- func NewHostSession(key Key, device DeviceID, wire []byte, nonce ClientNonce) (Auth, *Session, error)
- type Auth
- type Challenge
- type ClientNonce
- type DeviceID
- type Key
- type ReadLimits
- type RecordStream
- func HostHandshake(stream io.ReadWriter, key Key, device DeviceID, nonce ClientNonce) (*RecordStream, error)
- func NewRecordStream(stream io.ReadWriter, session *Session) *RecordStream
- func ServerHandshake(stream io.ReadWriter, key Key, device DeviceID, epoch, sessionNumber uint64) (*RecordStream, error)
- type Session
Constants ¶
View Source
const ( ChallengeSize = 56 AuthSize = 72 HeaderSize = 16 TagSize = 16 // One bounded EPS2 header + 1024-byte payload. Independent of the legacy // buffered-display protocol; no silent fragmentation inside RecordStream. MaxPlaintext = 1056 MaxEnvelope = HeaderSize + MaxPlaintext + TagSize )
Variables ¶
Functions ¶
func NewHostSession ¶
Types ¶
type Challenge ¶
type Challenge [ChallengeSize]byte
type ClientNonce ¶
type ClientNonce [32]byte
type ReadLimits ¶
ReadLimits separates idle waiting from one ciphertext record's total budget. SetDeadline must affect pending socket I/O, not merely record local timestamps.
type RecordStream ¶
type RecordStream struct {
// contains filtered or unexported fields
}
func HostHandshake ¶
func HostHandshake(stream io.ReadWriter, key Key, device DeviceID, nonce ClientNonce) (*RecordStream, error)
func NewRecordStream ¶
func NewRecordStream(stream io.ReadWriter, session *Session) *RecordStream
func ServerHandshake ¶
func ServerHandshake(stream io.ReadWriter, key Key, device DeviceID, epoch, sessionNumber uint64) (*RecordStream, error)
func (*RecordStream) ReadRecord ¶
func (s *RecordStream) ReadRecord(dst []byte, limits ReadLimits) (n int, err error)
ReadRecord returns exactly one authenticated plaintext envelope. EPN2 binds this envelope to exactly one complete EPS2 record. TCP fragmentation remains arbitrary; splitting an EPS2 record across AEAD envelopes is not permitted. dst must have room for MaxPlaintext; reject before consuming any bytes. Do not mix with a partially consumed Read stream. Any error poisons this instance: close the physical transport, never retry at a guessed boundary.
type Session ¶
type Session struct {
// contains filtered or unexported fields
}
func NewDeviceSession ¶
Click to show internal directories.
Click to hide internal directories.