41#define PROTOCORE_ESP_HDR_LEN 8
44#define PROTOCORE_ESP_IV_LEN 8
47#define PROTOCORE_ESP_SALT_LEN 4
50#define PROTOCORE_ESP_ICV_LEN 16
53#define PROTOCORE_ESP_KEY_LEN 32
56#define PROTOCORE_ESP_REPLAY_WINDOW 64
69 size_t (*gcm_encapsulate)(uint8_t *, uint32_t, uint32_t,
const uint8_t *,
const uint8_t *,
const uint8_t *, uint8_t,
70 const uint8_t *, size_t, uint8_t *, size_t);
71 proto_bool (*gcm_decapsulate)(uint8_t *,
const uint8_t *,
const uint8_t *, uint8_t *, size_t, uint32_t *,
72 uint32_t *, uint8_t *,
const uint8_t **,
size_t *);
94 const uint8_t *iv, uint8_t next_header,
const uint8_t *payload,
size_t payload_len,
95 uint8_t *out,
size_t out_cap);
111 size_t len, uint32_t *spi_out, uint32_t *seq_out, uint8_t *next_header_out,
112 const uint8_t **payload_out,
size_t *payload_len_out);
void protocore_esp_replay_init(uint8_t *work, EspReplay *r)
Reset an anti-replay window (no packets seen yet).
proto_bool protocore_esp_replay_check(uint8_t *work, EspReplay *r, uint32_t seq)
Anti-replay check + record for a received sequence number seq (RFC .
PROTOCORE_NS EspNs Esp PROTOCORE_UNUSED
Module namespace.
size_t protocore_esp_gcm_encapsulate(uint8_t *work, uint32_t spi, uint32_t seq, const uint8_t *key, const uint8_t *salt, const uint8_t *iv, uint8_t next_header, const uint8_t *payload, size_t payload_len, uint8_t *out, size_t out_cap)
Encapsulate payload in an RFC 4303 ESP packet with AES-256-GCM. .
proto_bool protocore_esp_gcm_decapsulate(uint8_t *work, const uint8_t *key, const uint8_t *salt, uint8_t *packet, size_t len, uint32_t *spi_out, uint32_t *seq_out, uint8_t *next_header_out, const uint8_t **payload_out, size_t *payload_len_out)
Verify + decapsulate an ESP packet in place (the ciphertext is .
#define PROTOCORE_NS_LAYOUT(T,...)
Pin every dispatch slot of a table that is nothing but function pointers.
#define PROTOCORE_NS
Storage for a dispatch table. The const is load bearing.
Dispatch table. Addressed by offset, so the layout is asserted below.
size_t(* gcm_encapsulate)(uint8_t *, uint32_t, uint32_t, const uint8_t *, const uint8_t *, const uint8_t *, uint8_t, const uint8_t *, size_t, uint8_t *, size_t)
Anti-replay sliding-window state for one inbound SA (zero-heap).
uint64_t bitmap
bit i set = (highest - i) already accepted (bit 0 = highest itself)
uint32_t highest
highest accepted sequence number so far
proto_bool seen_any
false until the first packet is accepted
#define PROTOCORE_BEGIN_DECLS
Give a header's declarations C linkage, so their symbol names carry no parameter types.
_Bool proto_bool
The truth value.
#define PROTOCORE_END_DECLS