android / android (push) Has been cancelled
apple / screenshots (push) Has been cancelled
apple / swift (push) Has been cancelled
arch / build-publish (push) Has been cancelled
audit / bun-audit (push) Failing after 13s
audit / cargo-audit (push) Has been cancelled
ci / bench (push) Has been cancelled
ci / docs-site (push) Has been cancelled
ci / rust (push) Has been cancelled
ci / web (push) Has been cancelled
deb / build-publish (push) Has been cancelled
deb / build-publish-host (push) Has been cancelled
decky / build-publish (push) Has been cancelled
docker / build-push (ci, ci/rust-ci.Dockerfile, punktfunk-rust-ci) (push) Has been cancelled
docker / build-push (docs-site, docs-site/Dockerfile, punktfunk-docs) (push) Has been cancelled
docker / deploy-docs (push) Has been cancelled
docker / build-push (--build-arg FEDORA_VERSION=44, ci, ci/fedora-rpm.Dockerfile, punktfunk-fedora44-rpm) (push) Has been cancelled
docker / build-push (ci, ci/fedora-rpm.Dockerfile, punktfunk-fedora-rpm) (push) Has been cancelled
docker / build-push (ci, ci/rust-ci-noble.Dockerfile, punktfunk-rust-ci-noble) (push) Has been cancelled
docker / build-push (., web/Dockerfile, punktfunk-web) (push) Has been cancelled
flatpak / build-publish (push) Has been cancelled
release / apple (push) Successful in 10m1s
windows-host / package (push) Successful in 11m20s
windows-msix / package (arm64, C:\Users\Public\ffmpeg-arm64, --no-default-features, aarch64-pc-windows-msvc, C:\t-a64) (push) Successful in 3m29s
windows-msix / package (x64, C:\Users\Public\ffmpeg, , x86_64-pc-windows-msvc, C:\t) (push) Successful in 4m14s
rpm / build-publish (44, fedora-44, punktfunk-fedora44-rpm) (push) Successful in 22m16s
rpm / build-publish (43, bazzite, punktfunk-fedora-rpm) (push) Successful in 22m27s
windows / build (aarch64-pc-windows-msvc) (push) Successful in 5m28s
windows / build (x86_64-pc-windows-msvc) (push) Successful in 6m39s
Lifts the ~100 Mbps decrypt ceiling on clients without hardware AES — the armv7 soft-AES targets (webOS TVs), where AES-128-GCM resolves to fixsliced software AES + software GHASH (~50-100 cpb) while ChaCha20-Poly1305's ARX construction runs ~10-17 cpb portable, a 4-7x lift that PyroWave-on-TV needs (design/chacha20-session-cipher.md). Phase 1 (core crypto, no wire change): SessionKey merges cipher choice and key material (invalid combinations unrepresentable, zeroize + redacted-Debug discipline kept); SessionCrypto dispatches both aead-0.5 ciphers per call — the salt||seq nonce scheme, per-direction salts, seq-as-AAD and replay window carry over verbatim (same 96-bit nonce / 16-byte tag, const-asserted). Config.key becomes SessionKey; validate's zero-key rejection follows the active variant. The C ABI keeps its fixed 16-byte key mapped to AES — no ABI_VERSION bump. Phase 2 (negotiation): VIDEO_CAP_CHACHA20 (0x40) — support-plus-request in one bit, the VIDEO_CAP_444 precedent. Welcome grows cipher@68 + key_chacha@69..101, emitted only when non-zero so an AES session's Welcome stays byte-identical to the pre-cipher form; decode is fail-closed (short key or unknown id -> Err, never a silent AES fallback). No WIRE_VERSION bump; downgrade resistance inherited from the pinned-TLS control channel. Phase 3 (host): grant only when the client advertised the bit and the PUNKTFUNK_CHACHA20 kill-switch (default on, documented) allows; fresh 32-byte per-session key from the same RNG discipline, legacy key field stays independently random; resolved cipher logged at session start. Verification: seal/open suites parameterized over both ciphers + a cross-cipher tamper case; Welcome roundtrip/truncation/fail-closed tests; ChaCha lossy-loopback soak (loss/replay is cipher-independent); bench gains _chacha20 series (AES ids unchanged for CI history) — host-side sealing line-rate-trivial on both x86 (~640 MiB/s) and Apple Silicon (~535 MiB/s). punktfunk-probe drives the interop matrix via PUNKTFUNK_CLIENT_CHACHA20=1 and logs the negotiated cipher. Phase 4 (pf-webos pin bump + unconditional cap bit) follows the next core release. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
112 lines
4.3 KiB
Rust
112 lines
4.3 KiB
Rust
//! `loss-harness` — sweep packet loss against the FEC and report recovery (plan §10).
|
|
//!
|
|
//! Drives access units through the in-process loopback at increasing loss rates, for
|
|
//! both FEC schemes, and prints how many frames survive. A pure-software stand-in for
|
|
//! `tc netem` that needs no network and runs anywhere `punktfunk_core` builds. The real punktfunk/1
|
|
//! harness adds `tc netem` jitter/reorder on the UDP path.
|
|
|
|
use punktfunk_core::config::{Config, FecConfig, FecScheme, ProtocolPhase, Role};
|
|
use punktfunk_core::crypto::SessionKey;
|
|
use punktfunk_core::error::PunktfunkError;
|
|
use punktfunk_core::session::Session;
|
|
use punktfunk_core::transport::loopback_pair;
|
|
|
|
fn config(role: Role, scheme: FecScheme, drop_period: u32) -> Config {
|
|
Config {
|
|
role,
|
|
phase: match scheme {
|
|
FecScheme::Gf8 => ProtocolPhase::P1GameStream,
|
|
FecScheme::Gf16 => ProtocolPhase::P2Punktfunk,
|
|
},
|
|
fec: FecConfig {
|
|
scheme,
|
|
fec_percent: 25,
|
|
max_data_per_block: 64,
|
|
},
|
|
shard_payload: 1024,
|
|
max_frame_bytes: 8 * 1024 * 1024,
|
|
encrypt: false,
|
|
key: SessionKey::Aes128Gcm([0u8; 16]),
|
|
salt: [0u8; 4],
|
|
loopback_drop_period: drop_period,
|
|
}
|
|
}
|
|
|
|
/// Returns (frames_completed, frames_attempted) for a loss setting. `streamed` feeds each AU
|
|
/// through the VIDEO_CAP_STREAMED_AU path (three encoder-chunk pushes + finish — sentinel
|
|
/// blocks then real totals) instead of one whole-AU submit, so the two wire shapes' recovery
|
|
/// curves can be compared directly (the Phase-2 "more, smaller units must not regress FEC" gate).
|
|
fn run(
|
|
scheme: FecScheme,
|
|
drop_period: u32,
|
|
frames: usize,
|
|
frame_len: usize,
|
|
streamed: bool,
|
|
) -> (usize, usize) {
|
|
let (h, c) = loopback_pair(drop_period, 0);
|
|
let mut host = Session::new(config(Role::Host, scheme, drop_period), Box::new(h)).unwrap();
|
|
let mut client = Session::new(config(Role::Client, scheme, drop_period), Box::new(c)).unwrap();
|
|
|
|
let send_wires = |host: &mut Session, wires: Vec<Vec<u8>>| {
|
|
let refs: Vec<&[u8]> = wires.iter().map(|w| w.as_slice()).collect();
|
|
host.send_sealed(&refs).unwrap();
|
|
drop(refs);
|
|
host.reclaim_wires(wires);
|
|
};
|
|
let mut completed = 0;
|
|
for f in 0..frames {
|
|
let frame: Vec<u8> = (0..frame_len).map(|b| (b ^ f) as u8).collect();
|
|
if streamed {
|
|
let mut au = host.begin_streamed_frame_at(f as u64, 0, f as u32).unwrap();
|
|
for chunk in frame.chunks(frame_len / 3 + 1) {
|
|
let wires = host.seal_streamed_chunk(&mut au, chunk).unwrap();
|
|
send_wires(&mut host, wires);
|
|
}
|
|
let wires = host.seal_streamed_finish(au).unwrap();
|
|
send_wires(&mut host, wires);
|
|
} else {
|
|
host.submit_frame(&frame, f as u64, 0).unwrap();
|
|
}
|
|
match client.poll_frame() {
|
|
Ok(got) => {
|
|
if got.data == frame {
|
|
completed += 1;
|
|
}
|
|
}
|
|
Err(PunktfunkError::NoFrame) => {} // unrecoverable at this loss rate
|
|
Err(e) => panic!("unexpected error: {e}"),
|
|
}
|
|
}
|
|
(completed, frames)
|
|
}
|
|
|
|
fn main() {
|
|
let frames = 50;
|
|
let frame_len = 100_000; // ~98 shards across 2 FEC blocks
|
|
let periods = [0u32, 32, 16, 8, 6, 4, 3, 2];
|
|
|
|
println!("punktfunk loss-harness — 25% FEC, {frames} frames of {frame_len} bytes");
|
|
println!("(GF8 = P1/GameStream-compat, GF16 = P2/wall-breaker, strm = streamed-AU wire)\n");
|
|
println!(
|
|
"{:>10} {:>9} {:>14} {:>14} {:>14}",
|
|
"drop 1/N", "~loss %", "GF8 recovered", "GF16 recovered", "GF16 strm"
|
|
);
|
|
println!("{}", "-".repeat(72));
|
|
for &p in &periods {
|
|
let loss = if p == 0 { 0.0 } else { 100.0 / p as f64 };
|
|
let (g8, n) = run(FecScheme::Gf8, p, frames, frame_len, false);
|
|
let (g16, _) = run(FecScheme::Gf16, p, frames, frame_len, false);
|
|
let (g16s, _) = run(FecScheme::Gf16, p, frames, frame_len, true);
|
|
let label = if p == 0 {
|
|
"none".to_string()
|
|
} else {
|
|
format!("1/{p}")
|
|
};
|
|
println!(
|
|
"{label:>10} {loss:>8.1}% {:>11}/{n} {:>11}/{n} {:>11}/{n}",
|
|
g8, g16, g16s
|
|
);
|
|
}
|
|
println!("\nNote: recovery drops off once per-block loss exceeds the 25% recovery budget.");
|
|
}
|