v0.18.0 — dds::security (HMAC, AES-256-GCM, topic ACL, anti-replay)
dds::security — HMAC-SHA-256, AES-256-GCM, topic ACL, anti-replay
Implements the next Tier-2 roadmap item: a C++ port of go-DDS's security package (security/security.go, access.go, replay.go), immediately following the already-completed ddssafety/E2E item (v0.17.0).
Added
dds::security::HMACPlugin— HMAC-SHA-256 message authentication (plaintext || HMAC[32])dds::security::AESGCMPlugin— AES-256-GCM authenticated encryption (nonce[12] || ciphertext || tag[16])dds::security::AccessPolicy/Permission/Rule— per-topic ACL, first-match-wins glob rules (byte-oriented port of Go'spath.Match)dds::security::ReplayGuard— sliding-window anti-replay sequence-number enforcement
HMACPlugin/AESGCMPlugin wire formats are byte-for-byte identical to go-DDS's, verified against reference vectors independently derived from a fresh go-DDS clone. No external crypto dependency is fetched for this project, so SHA-256/HMAC/AES-256/GCM are implemented from scratch under src/security/crypto/ (internal, non-public) and independently verified byte-exact against FIPS 180-4 / RFC 4231 / NIST SP 800-38A known-answer test vectors, the classic McGrew-Viega/NIST AES-256-GCM all-zero test vector, and Go's actual crypto/aes + crypto/cipher + crypto/hmac stdlib output.
Scope: internal, additive — dds::security::Plugin is a standalone seal/open library, not wired into dds::adapt(), dds::mock, or the RTPS transport, matching dds::safety::E2EPublisher's own precedent. go-DDS's security.cert/security.discovery are out of scope, matching the E2E item's precedent.
Adds REQ-SECURITY-001 through REQ-SECURITY-009, traced and tested. Checks off the security item in ROADMAP.md.
Verification
- Release C++17/C++20 builds clean across Linux/macOS/Windows, zero warnings
- 381/381 tests pass (44 new)
- Gcc-12 ASan+UBSan clean (reproduced locally in a matching Ubuntu-22.04 Docker container before pushing, after fixing a genuine UBSan finding — see
7a7cf27) relay conform/relay interop --protocol DDSpass unchangedcpfusa check/cyber/vuln/qualifyall green
Full Changelog: v0.17.0...v0.18.0