4#ifndef PROTOCORE_DTLS_HANDSHAKE_H
5#define PROTOCORE_DTLS_HANDSHAKE_H
47#define PROTOCORE_DTLS_HS_HDR_LEN 12
51#define PROTOCORE_DTLS_HS_TYPE_MESSAGE_HASH 254
55#define PROTOCORE_DTLS_HS_REASM_MAX_RANGES 8
59#define PROTOCORE_DTLS_COOKIE_MAX 128
104 size_t (*header_parse)(uint8_t *,
const uint8_t *, size_t,
DtlsHsHeader *);
105 size_t (*frag_build)(uint8_t *, uint8_t, uint16_t, uint32_t, uint32_t,
const uint8_t *, uint32_t, uint8_t *,
107 void (*reasm_init)(uint8_t *,
DtlsHsReasm *, uint16_t, uint8_t *, size_t);
111 size_t (*cookie_make)(uint8_t *, uint8_t *,
const uint8_t *, uint64_t,
const uint8_t *, size_t,
const uint8_t *,
112 size_t, uint8_t *, size_t);
113 proto_bool (*cookie_verify)(uint8_t *, uint8_t *,
const uint8_t *, uint64_t, uint64_t,
const uint8_t *, size_t,
114 const uint8_t *, size_t, uint8_t *, size_t,
size_t *);
142 uint32_t frag_offset,
const uint8_t *frag, uint32_t frag_len, uint8_t *out,
183 size_t out_cap,
size_t *out_count);
199 uint64_t timestamp,
const uint8_t *payload,
size_t payload_len,
200 const uint8_t *client_addr,
size_t addr_len, uint8_t *out,
size_t out_cap);
218 uint64_t now, uint64_t max_age,
const uint8_t *client_addr,
219 size_t addr_len,
const uint8_t *cookie,
size_t cookie_len,
220 uint8_t *payload_out,
size_t payload_cap,
size_t *payload_len_out);
PROTOCORE_NS DtlsHandshakeNs DtlsHandshake PROTOCORE_UNUSED
Module namespace.
size_t protocore_dtls_handshake_reasm_add(uint8_t *work, DtlsHsReasm *r, const DtlsHsHeader *frag)
Add one fragment to the reassembly in progress.
proto_bool protocore_dtls_handshake_cookie_verify(uint8_t *work, uint8_t *mac_work, const uint8_t *protocore_hmac_key, uint64_t now, uint64_t max_age, const uint8_t *client_addr, size_t addr_len, const uint8_t *cookie, size_t cookie_len, uint8_t *payload_out, size_t payload_cap, size_t *payload_len_out)
The same cookie back, checking the address binding and the age .
proto_bool protocore_dtls_handshake_ack_parse(uint8_t *work, const uint8_t *body, size_t len, DtlsRecordNumber *out, size_t out_cap, size_t *out_count)
The same body back into at most out_cap record numbers.
size_t protocore_dtls_handshake_ack_build(uint8_t *work, const DtlsRecordNumber *nums, size_t count, uint8_t *out, size_t out_cap)
An ACK body (RFC 9147 sec 7) over count record numbers.
#define PROTOCORE_DTLS_HS_REASM_MAX_RANGES
Max distinct byte ranges tracked while reassembling one message (bounds the work an adversary can for...
void protocore_dtls_handshake_reasm_init(uint8_t *work, DtlsHsReasm *r, uint16_t msg_seq, uint8_t *buf, size_t buf_cap)
Bind a reassembler to a caller buffer for one message sequence .
size_t protocore_dtls_handshake_header_parse(uint8_t *work, const uint8_t *p, size_t len, DtlsHsHeader *out)
The 12-byte DTLS handshake header; bytes consumed, or 0 if truncated.
size_t protocore_dtls_handshake_frag_build(uint8_t *work, uint8_t msg_type, uint16_t msg_seq, uint32_t full_len, uint32_t frag_offset, const uint8_t *frag, uint32_t frag_len, uint8_t *out, size_t out_cap)
One handshake fragment, header and body; bytes written, or 0 on .
size_t protocore_dtls_handshake_cookie_make(uint8_t *work, uint8_t *mac_work, const uint8_t *protocore_hmac_key, uint64_t timestamp, const uint8_t *payload, size_t payload_len, const uint8_t *client_addr, size_t addr_len, uint8_t *out, size_t out_cap)
A stateless HelloRetryRequest cookie bound to the client address.
#define PROTOCORE_NS_LAYOUT(T,...)
Pin every dispatch slot of a table that is nothing but function pointers.
#define PROTOCORE_NS
Storage for a dispatch table. The const is load bearing.
Dispatch table. Addressed by offset, so the layout is asserted below.
size_t(* header_parse)(uint8_t *, const uint8_t *, size_t, DtlsHsHeader *)
Reassembles the fragments of a single handshake message into a contiguous body.
proto_bool active
false until the first fragment of the target message is seen
uint8_t range_count
number of active intervals
uint32_t length
full body length (from the first non-empty fragment)
uint8_t * buf
caller-provided body buffer (>= length bytes)
size_t buf_cap
capacity of buf
uint8_t msg_type
HandshakeType of the message being reassembled.
proto_bool have_len
true once a fragment established the full message length
uint16_t msg_seq
the message sequence number this reassembler accepts
A record identified for acknowledgement: (epoch, sequence_number), 8 bytes each on the wire (RFC 9147...
#define PROTOCORE_BEGIN_DECLS
Give a header's declarations C linkage, so their symbol names carry no parameter types.
_Bool proto_bool
The truth value.
#define PROTOCORE_END_DECLS