|  | @@ -65,6 +65,7 @@ type AuthenticationReader struct {
 | 
	
		
			
				|  |  |  	buffer     *buf.Buffer
 | 
	
		
			
				|  |  |  	reader     io.Reader
 | 
	
		
			
				|  |  |  	sizeParser ChunkSizeDecoder
 | 
	
		
			
				|  |  | +	size       int
 | 
	
		
			
				|  |  |  }
 | 
	
		
			
				|  |  |  
 | 
	
		
			
				|  |  |  const (
 | 
	
	
		
			
				|  | @@ -77,56 +78,98 @@ func NewAuthenticationReader(auth Authenticator, sizeParser ChunkSizeDecoder, re
 | 
	
		
			
				|  |  |  		buffer:     buf.NewLocal(readerBufferSize),
 | 
	
		
			
				|  |  |  		reader:     reader,
 | 
	
		
			
				|  |  |  		sizeParser: sizeParser,
 | 
	
		
			
				|  |  | +		size:       -1,
 | 
	
		
			
				|  |  |  	}
 | 
	
		
			
				|  |  |  }
 | 
	
		
			
				|  |  |  
 | 
	
		
			
				|  |  | -func (r *AuthenticationReader) readChunk() error {
 | 
	
		
			
				|  |  | -	if err := r.buffer.Reset(buf.ReadFullFrom(r.reader, r.sizeParser.SizeBytes())); err != nil {
 | 
	
		
			
				|  |  | -		return err
 | 
	
		
			
				|  |  | +func (r *AuthenticationReader) readSize() error {
 | 
	
		
			
				|  |  | +	if r.size >= 0 {
 | 
	
		
			
				|  |  | +		return nil
 | 
	
		
			
				|  |  | +	}
 | 
	
		
			
				|  |  | +
 | 
	
		
			
				|  |  | +	sizeBytes := r.sizeParser.SizeBytes()
 | 
	
		
			
				|  |  | +	if r.buffer.Len() < sizeBytes {
 | 
	
		
			
				|  |  | +		r.buffer.Reset(buf.ReadFrom(r.buffer))
 | 
	
		
			
				|  |  | +		delta := sizeBytes - r.buffer.Len()
 | 
	
		
			
				|  |  | +		if err := r.buffer.AppendSupplier(buf.ReadAtLeastFrom(r.reader, delta)); err != nil {
 | 
	
		
			
				|  |  | +			return err
 | 
	
		
			
				|  |  | +		}
 | 
	
		
			
				|  |  |  	}
 | 
	
		
			
				|  |  | -	size, err := r.sizeParser.Decode(r.buffer.Bytes())
 | 
	
		
			
				|  |  | +	size, err := r.sizeParser.Decode(r.buffer.BytesTo(sizeBytes))
 | 
	
		
			
				|  |  |  	if err != nil {
 | 
	
		
			
				|  |  |  		return err
 | 
	
		
			
				|  |  |  	}
 | 
	
		
			
				|  |  | -	if size > readerBufferSize {
 | 
	
		
			
				|  |  | -		return newError("size too large ", size).AtWarning()
 | 
	
		
			
				|  |  | +	r.size = int(size)
 | 
	
		
			
				|  |  | +	r.buffer.SliceFrom(sizeBytes)
 | 
	
		
			
				|  |  | +	return nil
 | 
	
		
			
				|  |  | +}
 | 
	
		
			
				|  |  | +
 | 
	
		
			
				|  |  | +func (r *AuthenticationReader) readChunk(waitForData bool) ([]byte, error) {
 | 
	
		
			
				|  |  | +	if err := r.readSize(); err != nil {
 | 
	
		
			
				|  |  | +		return nil, err
 | 
	
		
			
				|  |  | +	}
 | 
	
		
			
				|  |  | +	if r.size > readerBufferSize-r.sizeParser.SizeBytes() {
 | 
	
		
			
				|  |  | +		return nil, newError("size too large ", r.size).AtWarning()
 | 
	
		
			
				|  |  |  	}
 | 
	
		
			
				|  |  |  
 | 
	
		
			
				|  |  | -	if int(size) == r.auth.Overhead() {
 | 
	
		
			
				|  |  | -		return io.EOF
 | 
	
		
			
				|  |  | +	if r.size == r.auth.Overhead() {
 | 
	
		
			
				|  |  | +		return nil, io.EOF
 | 
	
		
			
				|  |  |  	}
 | 
	
		
			
				|  |  |  
 | 
	
		
			
				|  |  | -	if err := r.buffer.Reset(buf.ReadFullFrom(r.reader, int(size))); err != nil {
 | 
	
		
			
				|  |  | -		return err
 | 
	
		
			
				|  |  | +	if r.buffer.Len() < r.size {
 | 
	
		
			
				|  |  | +		if !waitForData {
 | 
	
		
			
				|  |  | +			return nil, io.ErrNoProgress
 | 
	
		
			
				|  |  | +		}
 | 
	
		
			
				|  |  | +		r.buffer.Reset(buf.ReadFrom(r.buffer))
 | 
	
		
			
				|  |  | +
 | 
	
		
			
				|  |  | +		delta := r.size - r.buffer.Len()
 | 
	
		
			
				|  |  | +		if err := r.buffer.AppendSupplier(buf.ReadAtLeastFrom(r.reader, delta)); err != nil {
 | 
	
		
			
				|  |  | +			return nil, err
 | 
	
		
			
				|  |  | +		}
 | 
	
		
			
				|  |  |  	}
 | 
	
		
			
				|  |  |  
 | 
	
		
			
				|  |  | -	b, err := r.auth.Open(r.buffer.BytesTo(0), r.buffer.Bytes())
 | 
	
		
			
				|  |  | +	b, err := r.auth.Open(r.buffer.BytesTo(0), r.buffer.BytesTo(r.size))
 | 
	
		
			
				|  |  |  	if err != nil {
 | 
	
		
			
				|  |  | -		return err
 | 
	
		
			
				|  |  | +		return nil, err
 | 
	
		
			
				|  |  |  	}
 | 
	
		
			
				|  |  | -	r.buffer.Slice(0, len(b))
 | 
	
		
			
				|  |  | -	return nil
 | 
	
		
			
				|  |  | +	r.buffer.SliceFrom(r.size)
 | 
	
		
			
				|  |  | +	r.size = -1
 | 
	
		
			
				|  |  | +	return b, nil
 | 
	
		
			
				|  |  |  }
 | 
	
		
			
				|  |  |  
 | 
	
		
			
				|  |  |  func (r *AuthenticationReader) Read() (buf.MultiBuffer, error) {
 | 
	
		
			
				|  |  | -	if r.buffer.IsEmpty() {
 | 
	
		
			
				|  |  | -		if err := r.readChunk(); err != nil {
 | 
	
		
			
				|  |  | -			return nil, err
 | 
	
		
			
				|  |  | -		}
 | 
	
		
			
				|  |  | +	b, err := r.readChunk(true)
 | 
	
		
			
				|  |  | +	if err != nil {
 | 
	
		
			
				|  |  | +		return nil, err
 | 
	
		
			
				|  |  |  	}
 | 
	
		
			
				|  |  |  
 | 
	
		
			
				|  |  |  	mb := buf.NewMultiBuffer()
 | 
	
		
			
				|  |  | -	for !r.buffer.IsEmpty() {
 | 
	
		
			
				|  |  | -		b := buf.New()
 | 
	
		
			
				|  |  | -		b.AppendSupplier(buf.ReadFrom(r.buffer))
 | 
	
		
			
				|  |  | -		mb.Append(b)
 | 
	
		
			
				|  |  | +
 | 
	
		
			
				|  |  | +	appendBytes := func(b []byte) {
 | 
	
		
			
				|  |  | +		for len(b) > 0 {
 | 
	
		
			
				|  |  | +			buffer := buf.New()
 | 
	
		
			
				|  |  | +			n, _ := buffer.Write(b)
 | 
	
		
			
				|  |  | +			b = b[n:]
 | 
	
		
			
				|  |  | +			mb.Append(buffer)
 | 
	
		
			
				|  |  | +		}
 | 
	
		
			
				|  |  | +	}
 | 
	
		
			
				|  |  | +	appendBytes(b)
 | 
	
		
			
				|  |  | +
 | 
	
		
			
				|  |  | +	for r.buffer.Len() >= r.sizeParser.SizeBytes() {
 | 
	
		
			
				|  |  | +		b, err := r.readChunk(false)
 | 
	
		
			
				|  |  | +		if err != nil {
 | 
	
		
			
				|  |  | +			break
 | 
	
		
			
				|  |  | +		}
 | 
	
		
			
				|  |  | +		appendBytes(b)
 | 
	
		
			
				|  |  |  	}
 | 
	
		
			
				|  |  | +
 | 
	
		
			
				|  |  |  	return mb, nil
 | 
	
		
			
				|  |  |  }
 | 
	
		
			
				|  |  |  
 | 
	
		
			
				|  |  |  type AuthenticationWriter struct {
 | 
	
		
			
				|  |  |  	auth       Authenticator
 | 
	
		
			
				|  |  | -	buffer     []byte
 | 
	
		
			
				|  |  | +	payload    []byte
 | 
	
		
			
				|  |  | +	buffer     *buf.Buffer
 | 
	
		
			
				|  |  |  	writer     io.Writer
 | 
	
		
			
				|  |  |  	sizeParser ChunkSizeEncoder
 | 
	
		
			
				|  |  |  }
 | 
	
	
		
			
				|  | @@ -134,37 +177,51 @@ type AuthenticationWriter struct {
 | 
	
		
			
				|  |  |  func NewAuthenticationWriter(auth Authenticator, sizeParser ChunkSizeEncoder, writer io.Writer) *AuthenticationWriter {
 | 
	
		
			
				|  |  |  	return &AuthenticationWriter{
 | 
	
		
			
				|  |  |  		auth:       auth,
 | 
	
		
			
				|  |  | -		buffer:     make([]byte, 32*1024),
 | 
	
		
			
				|  |  | +		payload:    make([]byte, 1024),
 | 
	
		
			
				|  |  | +		buffer:     buf.NewLocal(readerBufferSize),
 | 
	
		
			
				|  |  |  		writer:     writer,
 | 
	
		
			
				|  |  |  		sizeParser: sizeParser,
 | 
	
		
			
				|  |  |  	}
 | 
	
		
			
				|  |  |  }
 | 
	
		
			
				|  |  |  
 | 
	
		
			
				|  |  | -func (w *AuthenticationWriter) writeInternal(b []byte) error {
 | 
	
		
			
				|  |  | -	sizeBytes := w.sizeParser.SizeBytes()
 | 
	
		
			
				|  |  | -	cipherChunk, err := w.auth.Seal(w.buffer[sizeBytes:sizeBytes], b)
 | 
	
		
			
				|  |  | -	if err != nil {
 | 
	
		
			
				|  |  | -		return err
 | 
	
		
			
				|  |  | -	}
 | 
	
		
			
				|  |  | +func (w *AuthenticationWriter) append(b []byte) {
 | 
	
		
			
				|  |  | +	encryptedSize := len(b) + w.auth.Overhead()
 | 
	
		
			
				|  |  | +
 | 
	
		
			
				|  |  | +	w.buffer.AppendSupplier(func(bb []byte) (int, error) {
 | 
	
		
			
				|  |  | +		w.sizeParser.Encode(uint16(encryptedSize), bb[:0])
 | 
	
		
			
				|  |  | +		return w.sizeParser.SizeBytes(), nil
 | 
	
		
			
				|  |  | +	})
 | 
	
		
			
				|  |  | +
 | 
	
		
			
				|  |  | +	w.buffer.AppendSupplier(func(bb []byte) (int, error) {
 | 
	
		
			
				|  |  | +		w.auth.Seal(bb[:0], b)
 | 
	
		
			
				|  |  | +		return encryptedSize, nil
 | 
	
		
			
				|  |  | +	})
 | 
	
		
			
				|  |  | +}
 | 
	
		
			
				|  |  |  
 | 
	
		
			
				|  |  | -	w.sizeParser.Encode(uint16(len(cipherChunk)), w.buffer[:0])
 | 
	
		
			
				|  |  | -	_, err = w.writer.Write(w.buffer[:sizeBytes+len(cipherChunk)])
 | 
	
		
			
				|  |  | +func (w *AuthenticationWriter) flush() error {
 | 
	
		
			
				|  |  | +	_, err := w.writer.Write(w.buffer.Bytes())
 | 
	
		
			
				|  |  | +	w.buffer.Clear()
 | 
	
		
			
				|  |  |  	return err
 | 
	
		
			
				|  |  |  }
 | 
	
		
			
				|  |  |  
 | 
	
		
			
				|  |  |  func (w *AuthenticationWriter) Write(mb buf.MultiBuffer) error {
 | 
	
		
			
				|  |  |  	defer mb.Release()
 | 
	
		
			
				|  |  |  
 | 
	
		
			
				|  |  | -	const StartIndex = 17 * 1024
 | 
	
		
			
				|  |  |  	for {
 | 
	
		
			
				|  |  | -		payloadLen, _ := mb.Read(w.buffer[StartIndex:])
 | 
	
		
			
				|  |  | -		err := w.writeInternal(w.buffer[StartIndex : StartIndex+payloadLen])
 | 
	
		
			
				|  |  | -		if err != nil {
 | 
	
		
			
				|  |  | -			return err
 | 
	
		
			
				|  |  | +		n, _ := mb.Read(w.payload)
 | 
	
		
			
				|  |  | +		w.append(w.payload[:n])
 | 
	
		
			
				|  |  | +		if w.buffer.Len() > readerBufferSize-2*1024 {
 | 
	
		
			
				|  |  | +			if err := w.flush(); err != nil {
 | 
	
		
			
				|  |  | +				return err
 | 
	
		
			
				|  |  | +			}
 | 
	
		
			
				|  |  |  		}
 | 
	
		
			
				|  |  |  		if mb.IsEmpty() {
 | 
	
		
			
				|  |  |  			break
 | 
	
		
			
				|  |  |  		}
 | 
	
		
			
				|  |  |  	}
 | 
	
		
			
				|  |  | +
 | 
	
		
			
				|  |  | +	if !w.buffer.IsEmpty() {
 | 
	
		
			
				|  |  | +		return w.flush()
 | 
	
		
			
				|  |  | +	}
 | 
	
		
			
				|  |  |  	return nil
 | 
	
		
			
				|  |  |  }
 |