From b7da11c2bf4e003412da08d9d404591b1ba2183a Mon Sep 17 00:00:00 2001 From: Evgeny Date: Fri, 24 Apr 2026 16:03:07 +0300 Subject: [PATCH] Crypto: Refactored ETCP header size calculations with offsetof-based defines, increased CCM tag to 16 bytes --- src/etcp.c | 7 ++++++- src/etcp_connections.h | 7 +++++++ src/secure_channel.h | 2 +- 3 files changed, 14 insertions(+), 2 deletions(-) diff --git a/src/etcp.c b/src/etcp.c index 1e6bfcf8..308cdd86 100644 --- a/src/etcp.c +++ b/src/etcp.c @@ -846,7 +846,12 @@ struct ETCP_DGRAM* etcp_request_pkt(struct ETCP_CONN* etcp) { int data_len=0; if (inf_pkt) data_len=inf_pkt->ll.len; - int remain_len=link->mtu -28/*udp headers*/ -13-8-4/*sc_nonce+tag size+crc*/ -11/*hdr[3] + min ack[8]*/ -5/*payload hdr*/ - data_len; + int remain_len = link->mtu + - 28 /*udp headers*/ + - SC_NONCE_SIZE - SC_TAG_SIZE - SC_CRC32_SIZE + - (ETCP_ENCRYPTED_HDR_SIZE + ETCP_ACK_BASE_SIZE) + - (1 + sizeof(inf_pkt->seq)) /*payload hdr*/ + - data_len; // DEBUG_ERROR(DEBUG_CATEGORY_CRYPTO, "remain_len= %d pl=%d", remain_len, data_len); // добавим опциональные заголовки diff --git a/src/etcp_connections.h b/src/etcp_connections.h index 23afede6..d184cb31 100644 --- a/src/etcp_connections.h +++ b/src/etcp_connections.h @@ -8,6 +8,7 @@ #include "../lib/socket_compat.h" #include "../lib/swm_min.h" #include +#include #define UDP_HDR_SIZE 28// размер udp header + ethernet заголовков (ipv4) [для ipv6 = 48 байт] #define UDP_SC_HDR_SIZE (13+8+4 + 5)// 13+8+4 - sc_nonce+tag size+crc, 5 - payload hdr @@ -35,6 +36,12 @@ struct ETCP_DGRAM {// пакет (незашифрованный) }; #pragma pack(pop) +/* Размер зашифрованного заголовка ETCP_DGRAM (timestamp + flag_up + padding) */ +#define ETCP_ENCRYPTED_HDR_SIZE (offsetof(struct ETCP_DGRAM, data) - offsetof(struct ETCP_DGRAM, timestamp)) + +/* Размер базового ACK: type(1) + count(1) + last_delivered_id(4) + rx_dup_count(2) */ +#define ETCP_ACK_BASE_SIZE (2 + 4 + 2) + typedef void (*etcp_ping_callback_t)(int success, uint16_t rtt, void* arg, uint64_t nonce, const uint8_t* resp_data, size_t resp_data_len); struct PING_CONTEXT { diff --git a/src/secure_channel.h b/src/secure_channel.h index 7697b875..e3189c77 100644 --- a/src/secure_channel.h +++ b/src/secure_channel.h @@ -12,7 +12,7 @@ #define SC_NONCE_SIZE 13 // CCM requires exactly 13 bytes #define SC_SHARED_SECRET_SIZE SC_HASH_SIZE #define SC_SESSION_KEY_SIZE 16 -#define SC_TAG_SIZE 8 +#define SC_TAG_SIZE 16 #define SC_CRC32_SIZE 4 // Шифрование pubkey при передаче (salt + double SHA256 XOR)