Files
SirHumza--orbisRPC/orbisrpc/tls.h
T
SirHumza bf5579d6da Stable gateway backend: mbedTLS, 8MB READY, JSON-safe parsing
- BearSSL replaced with mbedTLS (TLSv1.3 passes Cloudflare)
- 8MB frame cap + truncation-proof gateway op/seq scanner
- Thread-safe compat, locked logging, atomic config with template
- Daemon keeps last-good config, persistent presence timer
- 256B token buffers, weak-libc shims, portable build preflights
- Tests: gateway spoof + OOM cases pass

Still open: display names fall back to titleId in sandbox,
cover art needs shared Discord app assets. Backend fully functional.
2026-09-19 01:03:17 +02:00

25 lines
902 B
C

/* tls.h - self-contained TLS client (mbedTLS, statically linked).
* No PS4 TLS-module dependency: works in payload and plugin processes.
* The validator parses the chain but does not validate it (no trust
* store on console), so this protects against passive sniffing,
* not active man-in-the-middle attacks. */
#ifndef TLS_H
#define TLS_H
#include <stddef.h>
/* Runs the full TLS handshake over an already-connected socket.
* Returns heap context, or NULL on failure (logged). */
typedef struct tls_ctx tls_ctx_t;
tls_ctx_t *tls_start(int fd, const char *host);
/* Returns decrypted bytes (>0), 0 if nothing available right now,
* <0 on close/error. Non-blocking: never waits for the peer. */
int tls_read(tls_ctx_t *t, void *buf, size_t cap);
/* Writes exactly len bytes; returns len or <0. */
int tls_write(tls_ctx_t *t, const void *buf, size_t len);
void tls_free(tls_ctx_t *t);
#endif