37#ifndef PROTOCORE_TLS_RECORD_H
38#define PROTOCORE_TLS_RECORD_H
44#if PROTOCORE_ENABLE_TLS
53#define PROTOCORE_TLS_CT_CHANGE_CIPHER_SPEC 20
54#define PROTOCORE_TLS_CT_ALERT 21
55#define PROTOCORE_TLS_CT_HANDSHAKE 22
56#define PROTOCORE_TLS_CT_APPLICATION_DATA 23
60#define PROTOCORE_TLS_LEGACY_VERSION 0x0303
63#define PROTOCORE_TLS_PLAINTEXT_HDR_LEN 5
66#define PROTOCORE_TLS_TAG_LEN 16
69#define PROTOCORE_TLS_MAX_PLAINTEXT 16384
77#define PROTOCORE_TLS_MAX_CIPHERTEXT (PROTOCORE_TLS_MAX_PLAINTEXT + 1 + PROTOCORE_TLS_TAG_LEN)
84 TLS_CIPHER_AES_128_GCM_SHA256 = 0,
85 TLS_CIPHER_AES_256_GCM_SHA384 = 1
90proto_bool protocore_tls_cipher_is384(TlsCipher c);
93uint16_t protocore_tls_cipher_code(TlsCipher c);
97#define PROTOCORE_TLS_RECORD_IV_LEN 12
112 uint8_t iv[PROTOCORE_TLS_RECORD_IV_LEN];
113 uint8_t nonce[PROTOCORE_TLS_RECORD_IV_LEN];
121 uint8_t content_type;
122 const uint8_t *fragment;
129 uint8_t content_type;
138 const uint8_t *secret;
144 const uint8_t *fragment;
198 uint8_t content_type;
200 TlsPlaintextArgs plain;
201 TlsCiphertextArgs sealed;
202 TlsRecordOut out_args;
208extern TlsRecordVars TlsRecordV;
213 void (*
const keys_derive)(uint8_t *work);
214 void (*
const plaintext_build)(uint8_t *work);
215 void (*
const plaintext_parse)(uint8_t *work);
216 void (*
const protect)(uint8_t *work);
217 void (*
const unprotect)(uint8_t *work);
218 void (*
const keys_wipe)(uint8_t *work);
223void protocore_tls_record_keys_derive(uint8_t *work);
224void protocore_tls_record_plaintext_build(uint8_t *work);
225void protocore_tls_record_plaintext_parse(uint8_t *work);
226void protocore_tls_record_protect(uint8_t *work);
227void protocore_tls_record_unprotect(uint8_t *work);
228void protocore_tls_record_keys_wipe(uint8_t *work);
234static const TlsRecordNs TlsRecord __attribute__((unused)) = {
235 .keys_derive = protocore_tls_record_keys_derive,
236 .plaintext_build = protocore_tls_record_plaintext_build,
237 .plaintext_parse = protocore_tls_record_plaintext_parse,
238 .protect = protocore_tls_record_protect,
239 .unprotect = protocore_tls_record_unprotect,
240 .keys_wipe = protocore_tls_record_keys_wipe,
AEAD_AES_128_GCM (RFC 5116) - keyed, detached tag - and the AES-128 block it is built on.
AES-256-GCM AEAD (RFC 5116) - keyed, detached tag.
PROTO_ENUM_PACKED
Application protocol spoken on a listener port or connection slot.
#define PROTOCORE_TLS_RECORD_AEAD_BORROW
TLS 1.3 handshake messages for the QUIC handshake (RFC 8446 sec 4).
#define PROTOCORE_BEGIN_DECLS
Give a header's declarations C linkage, so their symbol names carry no parameter types.
_Bool proto_bool
The truth value.
#define PROTOCORE_END_DECLS