Add encrypted UDP voice (OCB2-AES128) with TCP fallback

- Port of Mumble's CryptStateOCB2 (XEX* counter-measures, late/lost/replay
  handling, nonce resync), verified against Mumble's OCB2 test vectors
- UDP channel per connection in the main process, to the address the TLS
  connection reached; used only while the server answers UDP pings, falls back
  to the TCP tunnel automatically; "voice over TCP only" setting
- Voice statistics show the live transport
- Information dialog no longer infers the transport from ping counters
- Message box: no padding, input fills the bar; Edit HTML only in descriptions

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-01 01:14:36 +02:00
co-authored by Claude Opus 5.5
parent 9a3aeb29ad
commit b44b8230d4
19 changed files with 616 additions and 48 deletions
+12
View File
@@ -4,6 +4,18 @@ export interface Transport {
close(): void;
onData: ((chunk: Uint8Array) => void) | null;
onClose: ((reason: string) => void) | null;
// Encrypted UDP for voice, where the platform has it (desktop); absent on the web
udp?: UdpChannel;
}
export interface UdpChannel {
setup(key: Uint8Array, clientNonce: Uint8Array, serverNonce: Uint8Array, protobuf: boolean): void;
setServerNonce(nonce: Uint8Array): void;
clientNonce(): Promise<Uint8Array | null>;
send(plain: Uint8Array): void;
onVoice: ((plain: Uint8Array) => void) | null;
onState: ((ok: boolean, rtt: number) => void) | null;
onResync: (() => void) | null;
}
export interface ConnectTarget {