mirror of
https://github.com/SirHumza/orbisRPC.git
synced 2026-10-06 11:00:57 +02:00
- BearSSL replaced with mbedTLS (TLSv1.3 passes Cloudflare) - 8MB frame cap + truncation-proof gateway op/seq scanner - Thread-safe compat, locked logging, atomic config with template - Daemon keeps last-good config, persistent presence timer - 256B token buffers, weak-libc shims, portable build preflights - Tests: gateway spoof + OOM cases pass Still open: display names fall back to titleId in sandbox, cover art needs shared Discord app assets. Backend fully functional.
25 lines
902 B
C
25 lines
902 B
C
/* tls.h - self-contained TLS client (mbedTLS, statically linked).
|
|
* No PS4 TLS-module dependency: works in payload and plugin processes.
|
|
* The validator parses the chain but does not validate it (no trust
|
|
* store on console), so this protects against passive sniffing,
|
|
* not active man-in-the-middle attacks. */
|
|
#ifndef TLS_H
|
|
#define TLS_H
|
|
#include <stddef.h>
|
|
|
|
/* Runs the full TLS handshake over an already-connected socket.
|
|
* Returns heap context, or NULL on failure (logged). */
|
|
typedef struct tls_ctx tls_ctx_t;
|
|
tls_ctx_t *tls_start(int fd, const char *host);
|
|
|
|
/* Returns decrypted bytes (>0), 0 if nothing available right now,
|
|
* <0 on close/error. Non-blocking: never waits for the peer. */
|
|
int tls_read(tls_ctx_t *t, void *buf, size_t cap);
|
|
|
|
/* Writes exactly len bytes; returns len or <0. */
|
|
int tls_write(tls_ctx_t *t, const void *buf, size_t len);
|
|
|
|
void tls_free(tls_ctx_t *t);
|
|
|
|
#endif
|