35#ifndef PROTOCORE_DTLS_CONN_H
36#define PROTOCORE_DTLS_CONN_H
40#if PROTOCORE_ENABLE_DTLS
55#define PROTOCORE_DTLS_CONN_REASM_CAP 1024
59#define PROTOCORE_DTLS_CONN_MSG_CAP 1024
62#define PROTOCORE_DTLS_PEER_ADDR_MAX 18
67#define PROTOCORE_DTLS_CONN_LOCAL_CID_LEN 4
71#define PROTOCORE_DTLS_FLIGHT_MSGS 16
76#define PROTOCORE_DTLS_REC_OVERHEAD_MAX (1 + PROTOCORE_DTLS_CID_MAX + 2 + 2 + PROTOCORE_DTLS_TAG_LEN)
80#define PROTOCORE_DTLS_FLIGHT_CAP (PROTOCORE_DTLS_CONN_MSG_CAP + 512)
84#define PROTOCORE_DTLS_PTO_INITIAL_MS 1000u
85#define PROTOCORE_DTLS_PTO_MAX_MS 60000u
86#define PROTOCORE_DTLS_MAX_RETRANSMITS 8
100 DTLS_CONN_STATE_START,
101 DTLS_CONN_STATE_WAIT_FINISHED,
102 DTLS_CONN_STATE_DONE,
103 DTLS_CONN_STATE_FAILED
115 const uint8_t *cert_der;
117 const uint8_t *ed25519_seed;
118 const uint8_t *ephemeral_priv;
119 const uint8_t *server_random;
120 const uint8_t *cookie_key;
127 DtlsServerConfig cfg;
146 uint8_t hs_finished_hash[TLS13_SECRET_MAX];
153 uint16_t next_recv_msg_seq;
158 uint8_t peer_addr[PROTOCORE_DTLS_PEER_ADDR_MAX];
159 uint8_t peer_addr_len;
165 uint8_t peer_cid_len;
168 uint8_t local_cid_len;
172 DtlsFlightMsg flight_msgs[PROTOCORE_DTLS_FLIGHT_MSGS];
174 flight_rec[PROTOCORE_DTLS_FLIGHT_MSGS];
175 uint8_t flight_count;
181 uint32_t flight_sent_ms;
184 uint8_t reasm_buf[4 + PROTOCORE_DTLS_CONN_REASM_CAP];
185 uint8_t msgbuf[PROTOCORE_DTLS_CONN_MSG_CAP];
187 flight_buf[PROTOCORE_DTLS_FLIGHT_CAP];
194 const DtlsServerConfig *cfg;
195 const uint8_t *peer_addr;
196 size_t peer_addr_len;
203 const uint8_t *dgram;
207} DtlsServerProcessArgs;
213} DtlsServerTimeoutMsArgs;
221} DtlsServerOnTimeoutArgs;
227} DtlsServerEstablishedArgs;
233} DtlsServerAlertArgs;
239} DtlsServerAppWriteKeysArgs;
245} DtlsServerAppReadKeysArgs;
252} DtlsServerLocalCidArgs;
263} DtlsServerOpenAppArgs;
273} DtlsServerSealAppArgs;
320 DtlsServerInitArgs init_args;
321 DtlsServerProcessArgs process_args;
322 DtlsServerTimeoutMsArgs timeout_ms_args;
323 DtlsServerOnTimeoutArgs on_timeout_args;
324 DtlsServerEstablishedArgs established_args;
325 DtlsServerAlertArgs alert_args;
326 DtlsServerAppWriteKeysArgs app_write_keys_args;
327 DtlsServerAppReadKeysArgs app_read_keys_args;
328 DtlsServerLocalCidArgs local_cid_args;
329 DtlsServerOpenAppArgs open_app_args;
330 DtlsServerSealAppArgs seal_app_args;
338extern DtlsServerVars DtlsServerV;
343 void (*
const init)(uint8_t *work);
344 void (*
const process)(uint8_t *work);
345 void (*
const timeout_ms)(uint8_t *work);
346 void (*
const on_timeout)(uint8_t *work);
347 void (*
const established)(uint8_t *work);
348 void (*
const alert)(uint8_t *work);
349 void (*
const app_write_keys)(uint8_t *work);
350 void (*
const app_read_keys)(uint8_t *work);
351 void (*
const local_cid)(uint8_t *work);
352 void (*
const open_app)(uint8_t *work);
353 void (*
const seal_app)(uint8_t *work);
358void protocore_dtls_server_init(uint8_t *work);
359void protocore_dtls_server_process(uint8_t *work);
360void protocore_dtls_server_timeout_ms(uint8_t *work);
361void protocore_dtls_server_on_timeout(uint8_t *work);
362void protocore_dtls_server_established(uint8_t *work);
363void protocore_dtls_server_alert(uint8_t *work);
364void protocore_dtls_server_app_write_keys(uint8_t *work);
365void protocore_dtls_server_app_read_keys(uint8_t *work);
366void protocore_dtls_server_local_cid(uint8_t *work);
367void protocore_dtls_server_open_app(uint8_t *work);
368void protocore_dtls_server_seal_app(uint8_t *work);
374static const DtlsConnNs DtlsServer __attribute__((unused)) = {
375 .init = protocore_dtls_server_init,
376 .process = protocore_dtls_server_process,
377 .timeout_ms = protocore_dtls_server_timeout_ms,
378 .on_timeout = protocore_dtls_server_on_timeout,
379 .established = protocore_dtls_server_established,
380 .alert = protocore_dtls_server_alert,
381 .app_write_keys = protocore_dtls_server_app_write_keys,
382 .app_read_keys = protocore_dtls_server_app_read_keys,
383 .local_cid = protocore_dtls_server_local_cid,
384 .open_app = protocore_dtls_server_open_app,
385 .seal_app = protocore_dtls_server_seal_app,
PROTO_ENUM_PACKED
Application protocol spoken on a listener port or connection slot.
DTLS 1.3 handshake framing and reliability (RFC 9147 §5, §7).
DTLS 1.3 record layer (RFC 9147 §4).
#define PROTOCORE_DTLS_CID_MAX
Largest connection id carried in a DTLSCiphertext header (RFC 9146 / RFC 9147 §9)....
#define PROTOCORE_SHA512_BORROW
#define PROTOCORE_TLS13_KS_BORROW
#define PROTOCORE_HMAC_SHA256_BORROW
#define PROTOCORE_TLS13_TRANSCRIPT_BORROW
TLS 1.3 key schedule (RFC 8446 sec 7.1) for the QUIC handshake.
Reassembles the fragments of a single handshake message into a contiguous body.
One direction's record-protection keys for one epoch (RFC 9147 §4).
A record identified for acknowledgement: (epoch, sequence_number), 8 bytes each on the wire (RFC 9147...
64-record sliding replay window over the highest sequence number accepted in an epoch.
#define PROTOCORE_BEGIN_DECLS
Give a header's declarations C linkage, so their symbol names carry no parameter types.
_Bool proto_bool
The truth value.
#define PROTOCORE_END_DECLS