The extension's fallback transport (docs/05 §4). veloxd now also listens on 127.0.0.1, first free port in 52000-52016, and writes it to <runtime>/ws.port (0600). - rpc/ws_frame — RFC 6455 frame codec. Incremental; reassembles continuation frames; enforces "client frames MUST be masked" (§5.1); caps a reassembled message at 8 MiB. This is the attacker-adjacent parser, so it has its own test table. - rpc/ws_handshake — HTTP upgrade parse, Sec-WebSocket-Accept (SHA-1 + base64 via libcrypto), and the two non-negotiable checks: an Origin header must be present and must be moz-extension:// (a page cannot pair). Version must be 13. - rpc/ws_server — per-connection Handshake -> Open state machine on the shared EventLoop. Token gate: session.pair mints a token behind the approver + rate limiter; session.hello must present a valid one; every other method is -32002 until authed. Privileged methods are refused -32003 by the generated dispatch(). Ping -> Pong; Close echoed. session.hello major-version mismatch -> -32001. - rpc/pairing — PairingApprover interface + EnvAutoApprover dev stub (approves iff VELOX_PAIR_AUTO=1); PairingRateLimiter (5 failures / 60 s per origin, then 60 s lockout -> -32014, survives reconnect); a four-digit code generator. - store/pairings — the pairings table: create() returns the plaintext token once and stores only its SHA-256; find_active_by_token, touch, revoke, list_active. - util/crypto — sha1 / sha256_hex / base64 / random_token over libcrypto. - store/sqlite — pin the DB file (and -wal/-shm) to 0600. - runtime_dir — resolve_data_dir() for $XDG_DATA_HOME/velox (velox.db). - main.cpp — opens + migrates velox.db, starts both transports; a WS bind failure is logged, not fatal (capture must fail open, the Unix socket still serves the GUI/CLI). Real gap, flagged not hidden: the pairing prompt is EnvAutoApprover for now — a GUI dialog / desktop notification is build step 7. Pairing needs VELOX_PAIR_AUTO=1 until then. Tests (ASan+UBSan and TSan clean): veloxd.ws_frame (codec + handshake vectors incl. the RFC 6455 §1.3 accept sample), veloxd.pairings (token create/find/revoke, hash-not-token, rate-limit window + lockout + per-origin isolation + success reset), veloxd.ws_server (full flow: 101 handshake, -32002 gate, deny-then-approve pairing, hello-with-token, -32003 privileged refusal, real download.list). 27 daemon/cli tests green; full tree green. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01Upd9WhG9oppieig5nRDLig
76 lines
3.1 KiB
CMake
76 lines
3.1 KiB
CMake
# daemon/ produces the veloxd binary and the static libraries it is built from.
|
|
# Owned by lane DAEMON. Wired in by PKG via add_subdirectory(daemon) in the root file,
|
|
# guarded on this file existing.
|
|
#
|
|
# Layering (CLAUDE.md §3): depends on velox::core and velox::proto. No Qt. The engine
|
|
# (velox::core) is not linked yet — it arrives when sched/ and the task glue land. This
|
|
# drop is the RPC transports (Unix socket + loopback WebSocket), the SQLite store, and a
|
|
# dispatcher skeleton so the CLI and GUI have a real server to talk to.
|
|
|
|
if(NOT TARGET nlohmann_json::nlohmann_json)
|
|
find_package(nlohmann_json 3.11 REQUIRED)
|
|
endif()
|
|
find_package(Threads REQUIRED)
|
|
find_package(SQLite3 REQUIRED)
|
|
find_package(OpenSSL REQUIRED) # libcrypto: WebSocket accept hash, pairing token hash
|
|
|
|
# --- generated: migrations_embedded.hpp from src/store/migrations/*.sql ---------------
|
|
set(_mig_dir ${CMAKE_CURRENT_SOURCE_DIR}/src/store/migrations)
|
|
set(_mig_hdr ${CMAKE_CURRENT_BINARY_DIR}/generated/migrations_embedded.hpp)
|
|
file(GLOB _mig_srcs ${_mig_dir}/*.sql)
|
|
add_custom_command(
|
|
OUTPUT ${_mig_hdr}
|
|
COMMAND ${CMAKE_COMMAND} -DMIG_DIR=${_mig_dir} -DOUT=${_mig_hdr}
|
|
-P ${CMAKE_CURRENT_SOURCE_DIR}/cmake/embed_migrations.cmake
|
|
DEPENDS ${_mig_srcs} ${CMAKE_CURRENT_SOURCE_DIR}/cmake/embed_migrations.cmake
|
|
COMMENT "Embedding SQL migrations"
|
|
VERBATIM)
|
|
add_custom_target(veloxd_migrations_hdr DEPENDS ${_mig_hdr})
|
|
|
|
# --- veloxd_store — SQLite store, migrations, crypto helpers --------------------------
|
|
add_library(veloxd_store STATIC
|
|
src/util/crypto.cpp
|
|
src/store/sqlite.cpp
|
|
src/store/migrations.cpp
|
|
src/store/pairings.cpp
|
|
${_mig_hdr}
|
|
)
|
|
add_library(velox::daemon_store ALIAS veloxd_store)
|
|
target_include_directories(veloxd_store
|
|
PUBLIC ${CMAKE_CURRENT_SOURCE_DIR}/src
|
|
PRIVATE ${CMAKE_CURRENT_BINARY_DIR}/generated
|
|
)
|
|
target_compile_features(veloxd_store PUBLIC cxx_std_23)
|
|
target_compile_options(veloxd_store PRIVATE -Wall -Wextra -Wpedantic -Werror)
|
|
target_link_libraries(veloxd_store PUBLIC SQLite::SQLite3 PRIVATE OpenSSL::Crypto)
|
|
|
|
# --- veloxd_rpc — the RPC transports + dispatcher ------------------------------------
|
|
add_library(veloxd_rpc STATIC
|
|
src/rpc/runtime_dir.cpp
|
|
src/rpc/event_loop.cpp
|
|
src/rpc/uds_server.cpp
|
|
src/rpc/ws_frame.cpp
|
|
src/rpc/ws_handshake.cpp
|
|
src/rpc/ws_server.cpp
|
|
src/rpc/pairing.cpp
|
|
src/rpc/dispatcher.cpp
|
|
)
|
|
add_library(velox::daemon_rpc ALIAS veloxd_rpc)
|
|
|
|
target_include_directories(veloxd_rpc PUBLIC ${CMAKE_CURRENT_SOURCE_DIR}/src)
|
|
target_compile_features(veloxd_rpc PUBLIC cxx_std_23)
|
|
target_compile_options(veloxd_rpc PRIVATE -Wall -Wextra -Wpedantic -Werror)
|
|
target_link_libraries(veloxd_rpc
|
|
PUBLIC velox::proto veloxd_store nlohmann_json::nlohmann_json Threads::Threads
|
|
)
|
|
|
|
# --- veloxd — the daemon binary -------------------------------------------------------
|
|
add_executable(veloxd src/main.cpp)
|
|
target_compile_features(veloxd PRIVATE cxx_std_23)
|
|
target_compile_options(veloxd PRIVATE -Wall -Wextra -Wpedantic -Werror)
|
|
target_link_libraries(veloxd PRIVATE veloxd_rpc)
|
|
|
|
if(VELOX_BUILD_TESTS AND EXISTS ${CMAKE_CURRENT_SOURCE_DIR}/tests/CMakeLists.txt)
|
|
add_subdirectory(tests)
|
|
endif()
|