]> git.ipfire.org Git - thirdparty/knot-dns.git/commitdiff
contrib: upgrade embedded library ngtcp2 to v0.16.0
authorDaniel Salzman <daniel.salzman@nic.cz>
Mon, 5 Jun 2023 07:06:32 +0000 (09:06 +0200)
committerDaniel Salzman <daniel.salzman@nic.cz>
Mon, 5 Jun 2023 07:06:32 +0000 (09:06 +0200)
20 files changed:
src/contrib/Makefile.inc
src/contrib/libngtcp2/ngtcp2/crypto/gnutls.c
src/contrib/libngtcp2/ngtcp2/crypto/shared.c
src/contrib/libngtcp2/ngtcp2/crypto/shared.h
src/contrib/libngtcp2/ngtcp2/lib/ngtcp2_acktr.c
src/contrib/libngtcp2/ngtcp2/lib/ngtcp2_cc.h
src/contrib/libngtcp2/ngtcp2/lib/ngtcp2_conn.c
src/contrib/libngtcp2/ngtcp2/lib/ngtcp2_conn.h
src/contrib/libngtcp2/ngtcp2/lib/ngtcp2_crypto.c
src/contrib/libngtcp2/ngtcp2/lib/ngtcp2_crypto.h
src/contrib/libngtcp2/ngtcp2/lib/ngtcp2_log.c
src/contrib/libngtcp2/ngtcp2/lib/ngtcp2_net.h
src/contrib/libngtcp2/ngtcp2/lib/ngtcp2_pkt.c
src/contrib/libngtcp2/ngtcp2/lib/ngtcp2_pktns_id.h [new file with mode: 0644]
src/contrib/libngtcp2/ngtcp2/lib/ngtcp2_qlog.c
src/contrib/libngtcp2/ngtcp2/lib/ngtcp2_rtb.h
src/contrib/libngtcp2/ngtcp2/ngtcp2.h
src/contrib/libngtcp2/ngtcp2/ngtcp2_crypto.h
src/contrib/libngtcp2/ngtcp2/ngtcp2_crypto_gnutls.h
src/contrib/libngtcp2/ngtcp2/version.h

index e086bae60db1f4ae555c45ced5d8c60e08a907ae..fd61bfbe85e58fec1e3e5d883fee305b253697fc 100644 (file)
@@ -181,6 +181,7 @@ libembngtcp2_la_SOURCES = \
        contrib/libngtcp2/ngtcp2/lib/ngtcp2_path.h \
        contrib/libngtcp2/ngtcp2/lib/ngtcp2_pkt.c \
        contrib/libngtcp2/ngtcp2/lib/ngtcp2_pkt.h \
+       contrib/libngtcp2/ngtcp2/lib/ngtcp2_pktns_id.h \
        contrib/libngtcp2/ngtcp2/lib/ngtcp2_pmtud.c \
        contrib/libngtcp2/ngtcp2/lib/ngtcp2_pmtud.h \
        contrib/libngtcp2/ngtcp2/lib/ngtcp2_ppe.c \
index b9f1afe29ece35545e6d01da8b5e8bf5f6abd961..297044c3b37efa9ca1c0f235d5e3821320e2625b 100644 (file)
@@ -411,17 +411,18 @@ int ngtcp2_crypto_hp_mask(uint8_t *dest, const ngtcp2_crypto_cipher *hp,
   return 0;
 }
 
-ngtcp2_crypto_level ngtcp2_crypto_gnutls_from_gnutls_record_encryption_level(
+ngtcp2_encryption_level
+ngtcp2_crypto_gnutls_from_gnutls_record_encryption_level(
     gnutls_record_encryption_level_t gtls_level) {
   switch (gtls_level) {
   case GNUTLS_ENCRYPTION_LEVEL_INITIAL:
-    return NGTCP2_CRYPTO_LEVEL_INITIAL;
+    return NGTCP2_ENCRYPTION_LEVEL_INITIAL;
   case GNUTLS_ENCRYPTION_LEVEL_HANDSHAKE:
-    return NGTCP2_CRYPTO_LEVEL_HANDSHAKE;
+    return NGTCP2_ENCRYPTION_LEVEL_HANDSHAKE;
   case GNUTLS_ENCRYPTION_LEVEL_APPLICATION:
-    return NGTCP2_CRYPTO_LEVEL_APPLICATION;
+    return NGTCP2_ENCRYPTION_LEVEL_1RTT;
   case GNUTLS_ENCRYPTION_LEVEL_EARLY:
-    return NGTCP2_CRYPTO_LEVEL_EARLY;
+    return NGTCP2_ENCRYPTION_LEVEL_0RTT;
   default:
     assert(0);
     abort();
@@ -429,15 +430,16 @@ ngtcp2_crypto_level ngtcp2_crypto_gnutls_from_gnutls_record_encryption_level(
 }
 
 gnutls_record_encryption_level_t
-ngtcp2_crypto_gnutls_from_ngtcp2_level(ngtcp2_crypto_level crypto_level) {
-  switch (crypto_level) {
-  case NGTCP2_CRYPTO_LEVEL_INITIAL:
+ngtcp2_crypto_gnutls_from_ngtcp2_encryption_level(
+    ngtcp2_encryption_level encryption_level) {
+  switch (encryption_level) {
+  case NGTCP2_ENCRYPTION_LEVEL_INITIAL:
     return GNUTLS_ENCRYPTION_LEVEL_INITIAL;
-  case NGTCP2_CRYPTO_LEVEL_HANDSHAKE:
+  case NGTCP2_ENCRYPTION_LEVEL_HANDSHAKE:
     return GNUTLS_ENCRYPTION_LEVEL_HANDSHAKE;
-  case NGTCP2_CRYPTO_LEVEL_APPLICATION:
+  case NGTCP2_ENCRYPTION_LEVEL_1RTT:
     return GNUTLS_ENCRYPTION_LEVEL_APPLICATION;
-  case NGTCP2_CRYPTO_LEVEL_EARLY:
+  case NGTCP2_ENCRYPTION_LEVEL_0RTT:
     return GNUTLS_ENCRYPTION_LEVEL_EARLY;
   default:
     assert(0);
@@ -445,16 +447,17 @@ ngtcp2_crypto_gnutls_from_ngtcp2_level(ngtcp2_crypto_level crypto_level) {
   }
 }
 
-int ngtcp2_crypto_read_write_crypto_data(ngtcp2_conn *conn,
-                                         ngtcp2_crypto_level crypto_level,
-                                         const uint8_t *data, size_t datalen) {
+int ngtcp2_crypto_read_write_crypto_data(
+    ngtcp2_conn *conn, ngtcp2_encryption_level encryption_level,
+    const uint8_t *data, size_t datalen) {
   gnutls_session_t session = ngtcp2_conn_get_tls_native_handle(conn);
   int rv;
 
   if (datalen > 0) {
     rv = gnutls_handshake_write(
-        session, ngtcp2_crypto_gnutls_from_ngtcp2_level(crypto_level), data,
-        datalen);
+        session,
+        ngtcp2_crypto_gnutls_from_ngtcp2_encryption_level(encryption_level),
+        data, datalen);
     if (rv != 0) {
       if (!gnutls_error_is_fatal(rv)) {
         return 0;
@@ -526,7 +529,7 @@ static int secret_func(gnutls_session_t session,
                        size_t secretlen) {
   ngtcp2_crypto_conn_ref *conn_ref = gnutls_session_get_ptr(session);
   ngtcp2_conn *conn = conn_ref->get_conn(conn_ref);
-  ngtcp2_crypto_level level =
+  ngtcp2_encryption_level level =
       ngtcp2_crypto_gnutls_from_gnutls_record_encryption_level(gtls_level);
 
   if (rx_secret &&
@@ -550,7 +553,7 @@ static int read_func(gnutls_session_t session,
                      size_t datalen) {
   ngtcp2_crypto_conn_ref *conn_ref = gnutls_session_get_ptr(session);
   ngtcp2_conn *conn = conn_ref->get_conn(conn_ref);
-  ngtcp2_crypto_level level =
+  ngtcp2_encryption_level level =
       ngtcp2_crypto_gnutls_from_gnutls_record_encryption_level(gtls_level);
   int rv;
 
@@ -587,7 +590,7 @@ static int tp_recv_func(gnutls_session_t session, const uint8_t *data,
   ngtcp2_conn *conn = conn_ref->get_conn(conn_ref);
   int rv;
 
-  rv = ngtcp2_conn_decode_remote_transport_params(conn, data, datalen);
+  rv = ngtcp2_conn_decode_and_set_remote_transport_params(conn, data, datalen);
   if (rv != 0) {
     ngtcp2_conn_set_tls_error(conn, rv);
     return -1;
index cd224c7501a1c2c84eeeef2fdda736806078b5cf..67045c0d2b5cca19a1fd0e881a46c5181ad23b57 100644 (file)
@@ -64,8 +64,6 @@ int ngtcp2_crypto_hkdf_expand_label(uint8_t *dest, size_t destlen,
                                    (size_t)(p - info));
 }
 
-#define NGTCP2_CRYPTO_INITIAL_SECRETLEN 32
-
 int ngtcp2_crypto_derive_initial_secrets(uint8_t *rx_secret, uint8_t *tx_secret,
                                          uint8_t *initial_secret,
                                          uint32_t version,
@@ -217,7 +215,7 @@ int ngtcp2_crypto_update_traffic_secret(uint8_t *dest, uint32_t version,
 
 int ngtcp2_crypto_derive_and_install_rx_key(ngtcp2_conn *conn, uint8_t *key,
                                             uint8_t *iv, uint8_t *hp_key,
-                                            ngtcp2_crypto_level level,
+                                            ngtcp2_encryption_level level,
                                             const uint8_t *secret,
                                             size_t secretlen) {
   const ngtcp2_crypto_ctx *ctx;
@@ -233,7 +231,7 @@ int ngtcp2_crypto_derive_and_install_rx_key(ngtcp2_conn *conn, uint8_t *key,
   ngtcp2_crypto_ctx cctx;
   uint32_t version;
 
-  if (level == NGTCP2_CRYPTO_LEVEL_EARLY && !ngtcp2_conn_is_server(conn)) {
+  if (level == NGTCP2_ENCRYPTION_LEVEL_0RTT && !ngtcp2_conn_is_server(conn)) {
     return 0;
   }
 
@@ -248,13 +246,13 @@ int ngtcp2_crypto_derive_and_install_rx_key(ngtcp2_conn *conn, uint8_t *key,
   }
 
   switch (level) {
-  case NGTCP2_CRYPTO_LEVEL_EARLY:
+  case NGTCP2_ENCRYPTION_LEVEL_0RTT:
     ngtcp2_crypto_ctx_tls_early(&cctx, tls);
-    ngtcp2_conn_set_early_crypto_ctx(conn, &cctx);
-    ctx = ngtcp2_conn_get_early_crypto_ctx(conn);
+    ngtcp2_conn_set_0rtt_crypto_ctx(conn, &cctx);
+    ctx = ngtcp2_conn_get_0rtt_crypto_ctx(conn);
     version = ngtcp2_conn_get_client_chosen_version(conn);
     break;
-  case NGTCP2_CRYPTO_LEVEL_HANDSHAKE:
+  case NGTCP2_ENCRYPTION_LEVEL_HANDSHAKE:
     if (ngtcp2_conn_is_server(conn) &&
         !ngtcp2_conn_get_negotiated_version(conn)) {
       rv = ngtcp2_crypto_set_remote_transport_params(conn, tls);
@@ -263,7 +261,7 @@ int ngtcp2_crypto_derive_and_install_rx_key(ngtcp2_conn *conn, uint8_t *key,
       }
     }
     /* fall through */
-  default:
+  case NGTCP2_ENCRYPTION_LEVEL_1RTT:
     ctx = ngtcp2_conn_get_crypto_ctx(conn);
     version = ngtcp2_conn_get_negotiated_version(conn);
 
@@ -272,6 +270,9 @@ int ngtcp2_crypto_derive_and_install_rx_key(ngtcp2_conn *conn, uint8_t *key,
       ngtcp2_conn_set_crypto_ctx(conn, &cctx);
       ctx = ngtcp2_conn_get_crypto_ctx(conn);
     }
+    break;
+  default:
+    return -1;
   }
 
   aead = &ctx->aead;
@@ -293,20 +294,20 @@ int ngtcp2_crypto_derive_and_install_rx_key(ngtcp2_conn *conn, uint8_t *key,
   }
 
   switch (level) {
-  case NGTCP2_CRYPTO_LEVEL_EARLY:
-    rv = ngtcp2_conn_install_early_key(conn, &aead_ctx, iv, ivlen, &hp_ctx);
+  case NGTCP2_ENCRYPTION_LEVEL_0RTT:
+    rv = ngtcp2_conn_install_0rtt_key(conn, &aead_ctx, iv, ivlen, &hp_ctx);
     if (rv != 0) {
       goto fail;
     }
     break;
-  case NGTCP2_CRYPTO_LEVEL_HANDSHAKE:
+  case NGTCP2_ENCRYPTION_LEVEL_HANDSHAKE:
     rv = ngtcp2_conn_install_rx_handshake_key(conn, &aead_ctx, iv, ivlen,
                                               &hp_ctx);
     if (rv != 0) {
       goto fail;
     }
     break;
-  case NGTCP2_CRYPTO_LEVEL_APPLICATION:
+  case NGTCP2_ENCRYPTION_LEVEL_1RTT:
     if (!ngtcp2_conn_is_server(conn)) {
       rv = ngtcp2_crypto_set_remote_transport_params(conn, tls);
       if (rv != 0) {
@@ -358,7 +359,7 @@ static int crypto_set_local_transport_params(ngtcp2_conn *conn, void *tls) {
 
 int ngtcp2_crypto_derive_and_install_tx_key(ngtcp2_conn *conn, uint8_t *key,
                                             uint8_t *iv, uint8_t *hp_key,
-                                            ngtcp2_crypto_level level,
+                                            ngtcp2_encryption_level level,
                                             const uint8_t *secret,
                                             size_t secretlen) {
   const ngtcp2_crypto_ctx *ctx;
@@ -374,7 +375,7 @@ int ngtcp2_crypto_derive_and_install_tx_key(ngtcp2_conn *conn, uint8_t *key,
   ngtcp2_crypto_ctx cctx;
   uint32_t version;
 
-  if (level == NGTCP2_CRYPTO_LEVEL_EARLY && ngtcp2_conn_is_server(conn)) {
+  if (level == NGTCP2_ENCRYPTION_LEVEL_0RTT && ngtcp2_conn_is_server(conn)) {
     return 0;
   }
 
@@ -389,13 +390,13 @@ int ngtcp2_crypto_derive_and_install_tx_key(ngtcp2_conn *conn, uint8_t *key,
   }
 
   switch (level) {
-  case NGTCP2_CRYPTO_LEVEL_EARLY:
+  case NGTCP2_ENCRYPTION_LEVEL_0RTT:
     ngtcp2_crypto_ctx_tls_early(&cctx, tls);
-    ngtcp2_conn_set_early_crypto_ctx(conn, &cctx);
-    ctx = ngtcp2_conn_get_early_crypto_ctx(conn);
+    ngtcp2_conn_set_0rtt_crypto_ctx(conn, &cctx);
+    ctx = ngtcp2_conn_get_0rtt_crypto_ctx(conn);
     version = ngtcp2_conn_get_client_chosen_version(conn);
     break;
-  case NGTCP2_CRYPTO_LEVEL_HANDSHAKE:
+  case NGTCP2_ENCRYPTION_LEVEL_HANDSHAKE:
     if (ngtcp2_conn_is_server(conn) &&
         !ngtcp2_conn_get_negotiated_version(conn)) {
       rv = ngtcp2_crypto_set_remote_transport_params(conn, tls);
@@ -404,7 +405,7 @@ int ngtcp2_crypto_derive_and_install_tx_key(ngtcp2_conn *conn, uint8_t *key,
       }
     }
     /* fall through */
-  default:
+  case NGTCP2_ENCRYPTION_LEVEL_1RTT:
     ctx = ngtcp2_conn_get_crypto_ctx(conn);
     version = ngtcp2_conn_get_negotiated_version(conn);
 
@@ -413,6 +414,9 @@ int ngtcp2_crypto_derive_and_install_tx_key(ngtcp2_conn *conn, uint8_t *key,
       ngtcp2_conn_set_crypto_ctx(conn, &cctx);
       ctx = ngtcp2_conn_get_crypto_ctx(conn);
     }
+    break;
+  default:
+    return -1;
   }
 
   aead = &ctx->aead;
@@ -434,13 +438,13 @@ int ngtcp2_crypto_derive_and_install_tx_key(ngtcp2_conn *conn, uint8_t *key,
   }
 
   switch (level) {
-  case NGTCP2_CRYPTO_LEVEL_EARLY:
-    rv = ngtcp2_conn_install_early_key(conn, &aead_ctx, iv, ivlen, &hp_ctx);
+  case NGTCP2_ENCRYPTION_LEVEL_0RTT:
+    rv = ngtcp2_conn_install_0rtt_key(conn, &aead_ctx, iv, ivlen, &hp_ctx);
     if (rv != 0) {
       goto fail;
     }
     break;
-  case NGTCP2_CRYPTO_LEVEL_HANDSHAKE:
+  case NGTCP2_ENCRYPTION_LEVEL_HANDSHAKE:
     rv = ngtcp2_conn_install_tx_handshake_key(conn, &aead_ctx, iv, ivlen,
                                               &hp_ctx);
     if (rv != 0) {
@@ -453,7 +457,7 @@ int ngtcp2_crypto_derive_and_install_tx_key(ngtcp2_conn *conn, uint8_t *key,
     }
 
     break;
-  case NGTCP2_CRYPTO_LEVEL_APPLICATION:
+  case NGTCP2_ENCRYPTION_LEVEL_1RTT:
     rv = ngtcp2_conn_install_tx_key(conn, secret, secretlen, &aead_ctx, iv,
                                     ivlen, &hp_ctx);
     if (rv != 0) {
@@ -920,13 +924,15 @@ ngtcp2_ssize ngtcp2_crypto_generate_retry_token(
   ngtcp2_crypto_md md;
   ngtcp2_crypto_aead_ctx aead_ctx;
   size_t plaintextlen;
-  uint8_t aad[sizeof(version) + sizeof(ngtcp2_sockaddr_storage) +
-              NGTCP2_MAX_CIDLEN];
+  uint8_t
+      aad[sizeof(version) + sizeof(ngtcp2_sockaddr_union) + NGTCP2_MAX_CIDLEN];
   size_t aadlen;
   uint8_t *p = plaintext;
   ngtcp2_tstamp ts_be = ngtcp2_htonl64(ts);
   int rv;
 
+  assert((size_t)remote_addrlen <= sizeof(ngtcp2_sockaddr_union));
+
   memset(plaintext, 0, sizeof(plaintext));
 
   *p++ = (uint8_t)odcid->datalen;
@@ -997,8 +1003,8 @@ int ngtcp2_crypto_verify_retry_token(
   ngtcp2_crypto_aead_ctx aead_ctx;
   ngtcp2_crypto_aead aead;
   ngtcp2_crypto_md md;
-  uint8_t aad[sizeof(version) + sizeof(ngtcp2_sockaddr_storage) +
-              NGTCP2_MAX_CIDLEN];
+  uint8_t
+      aad[sizeof(version) + sizeof(ngtcp2_sockaddr_union) + NGTCP2_MAX_CIDLEN];
   size_t aadlen;
   const uint8_t *rand_data;
   const uint8_t *ciphertext;
@@ -1007,6 +1013,8 @@ int ngtcp2_crypto_verify_retry_token(
   int rv;
   ngtcp2_tstamp gen_ts;
 
+  assert((size_t)remote_addrlen <= sizeof(ngtcp2_sockaddr_union));
+
   if (tokenlen != NGTCP2_CRYPTO_MAX_RETRY_TOKENLEN ||
       token[0] != NGTCP2_CRYPTO_TOKEN_MAGIC_RETRY) {
     return -1;
@@ -1344,8 +1352,8 @@ int ngtcp2_crypto_client_initial_cb(ngtcp2_conn *conn, void *user_data) {
     return NGTCP2_ERR_CALLBACK_FAILURE;
   }
 
-  if (ngtcp2_crypto_read_write_crypto_data(conn, NGTCP2_CRYPTO_LEVEL_INITIAL,
-                                           NULL, 0) != 0) {
+  if (ngtcp2_crypto_read_write_crypto_data(
+          conn, NGTCP2_ENCRYPTION_LEVEL_INITIAL, NULL, 0) != 0) {
     return NGTCP2_ERR_CALLBACK_FAILURE;
   }
 
@@ -1411,15 +1419,15 @@ void ngtcp2_crypto_delete_crypto_cipher_ctx_cb(
 }
 
 int ngtcp2_crypto_recv_crypto_data_cb(ngtcp2_conn *conn,
-                                      ngtcp2_crypto_level crypto_level,
+                                      ngtcp2_encryption_level encryption_level,
                                       uint64_t offset, const uint8_t *data,
                                       size_t datalen, void *user_data) {
   int rv;
   (void)offset;
   (void)user_data;
 
-  if (ngtcp2_crypto_read_write_crypto_data(conn, crypto_level, data, datalen) !=
-      0) {
+  if (ngtcp2_crypto_read_write_crypto_data(conn, encryption_level, data,
+                                           datalen) != 0) {
     rv = ngtcp2_conn_get_tls_error(conn);
     if (rv) {
       return rv;
index 641cfcc5d7f3512153f88d94c7a7523e9c50d11f..e617d19d50cd00477237e19041e198c94a316a28 100644 (file)
 #define NGTCP2_CRYPTO_MAX_DECRYPTION_FAILURE_CHACHA20_POLY1305 (1ULL << 36)
 #define NGTCP2_CRYPTO_MAX_DECRYPTION_FAILURE_AES_CCM (2965820ULL)
 
+/**
+ * @macro
+ *
+ * :macro:`NGTCP2_CRYPTO_INITIAL_SECRETLEN` is the length of secret
+ * for Initial packets.
+ */
+#define NGTCP2_CRYPTO_INITIAL_SECRETLEN 32
+
+/**
+ * @macro
+ *
+ * :macro:`NGTCP2_CRYPTO_INITIAL_KEYLEN` is the length of key for
+ * Initial packets.
+ */
+#define NGTCP2_CRYPTO_INITIAL_KEYLEN 16
+
+/**
+ * @macro
+ *
+ * :macro:`NGTCP2_CRYPTO_INITIAL_IVLEN` is the length of IV for
+ * Initial packets.
+ */
+#define NGTCP2_CRYPTO_INITIAL_IVLEN 12
+
 /**
  * @function
  *
@@ -106,6 +130,25 @@ ngtcp2_crypto_aead *ngtcp2_crypto_aead_init(ngtcp2_crypto_aead *aead,
  */
 ngtcp2_crypto_aead *ngtcp2_crypto_aead_retry(ngtcp2_crypto_aead *aead);
 
+/**
+ * @enum
+ *
+ * :type:`ngtcp2_crypto_side` indicates which side the application
+ * implements; client or server.
+ */
+typedef enum ngtcp2_crypto_side {
+  /**
+   * :enum:`NGTCP2_CRYPTO_SIDE_CLIENT` indicates that the application
+   * is client.
+   */
+  NGTCP2_CRYPTO_SIDE_CLIENT,
+  /**
+   * :enum:`NGTCP2_CRYPTO_SIDE_SERVER` indicates that the application
+   * is server.
+   */
+  NGTCP2_CRYPTO_SIDE_SERVER
+} ngtcp2_crypto_side;
+
 /**
  * @function
  *
@@ -347,4 +390,18 @@ ngtcp2_crypto_aead *ngtcp2_crypto_aead_aes_128_gcm(ngtcp2_crypto_aead *aead);
  */
 int ngtcp2_crypto_random(uint8_t *data, size_t datalen);
 
+/**
+ * @function
+ *
+ * `ngtcp2_crypto_hkdf_expand_label` performs HKDF expand label.  The
+ * result is |destlen| bytes long, and is stored to the buffer pointed
+ * by |dest|.
+ *
+ * This function returns 0 if it succeeds, or -1.
+ */
+int ngtcp2_crypto_hkdf_expand_label(uint8_t *dest, size_t destlen,
+                                    const ngtcp2_crypto_md *md,
+                                    const uint8_t *secret, size_t secretlen,
+                                    const uint8_t *label, size_t labellen);
+
 #endif /* NGTCP2_SHARED_H */
index 3f1f9b3f1321ddddee241b71f97824b2f1f9a8bf..a3b4e409db13a03531da1b7613e177411841b940 100644 (file)
@@ -66,7 +66,7 @@ int ngtcp2_acktr_init(ngtcp2_acktr *acktr, ngtcp2_log *log,
   rv = ngtcp2_ringbuf_init(&acktr->acks, 32, sizeof(ngtcp2_acktr_ack_entry),
                            mem);
   if (rv != 0) {
-    return rv;
+    goto fail_acks_init;
   }
 
   ngtcp2_ksl_init(&acktr->ents, greater, sizeof(int64_t), mem);
@@ -78,6 +78,10 @@ int ngtcp2_acktr_init(ngtcp2_acktr *acktr, ngtcp2_log *log,
   acktr->rx_npkt = 0;
 
   return 0;
+
+fail_acks_init:
+  ngtcp2_objalloc_free(&acktr->objalloc);
+  return rv;
 }
 
 void ngtcp2_acktr_free(ngtcp2_acktr *acktr) {
index 4e476950326cf60cf1b34aeaec86d2f9f3ca3f21..9b978181b8a237d84da691a406f71bc98c18bc98 100644 (file)
@@ -31,6 +31,8 @@
 
 #include <ngtcp2/ngtcp2.h>
 
+#include "ngtcp2_pktns_id.h"
+
 #define NGTCP2_LOSS_REDUCTION_FACTOR_BITS 1
 #define NGTCP2_PERSISTENT_CONGESTION_THRESHOLD 3
 
index 2874a5c608f2fcfb839c1fecc159c626f3adf5a3..fa68e451d8b99d51159e5cf9253e92221a26c6f6 100644 (file)
@@ -63,6 +63,14 @@ static int conn_local_stream(ngtcp2_conn *conn, int64_t stream_id) {
  */
 static int bidi_stream(int64_t stream_id) { return (stream_id & 0x2) == 0; }
 
+static void conn_update_timestamp(ngtcp2_conn *conn, ngtcp2_tstamp ts) {
+  assert(conn->log.last_ts <= ts);
+  assert(conn->qlog.last_ts <= ts);
+
+  conn->log.last_ts = ts;
+  conn->qlog.last_ts = ts;
+}
+
 /*
  * conn_is_tls_handshake_completed returns nonzero if TLS handshake
  * has completed and 1 RTT keys are available.
@@ -121,14 +129,14 @@ static int conn_call_recv_stream_data(ngtcp2_conn *conn, ngtcp2_strm *strm,
 }
 
 static int conn_call_recv_crypto_data(ngtcp2_conn *conn,
-                                      ngtcp2_crypto_level crypto_level,
+                                      ngtcp2_encryption_level encryption_level,
                                       uint64_t offset, const uint8_t *data,
                                       size_t datalen) {
   int rv;
 
   assert(conn->callbacks.recv_crypto_data);
 
-  rv = conn->callbacks.recv_crypto_data(conn, crypto_level, offset, data,
+  rv = conn->callbacks.recv_crypto_data(conn, encryption_level, offset, data,
                                         datalen, conn->user_data);
   switch (rv) {
   case 0:
@@ -308,10 +316,10 @@ static int conn_call_select_preferred_addr(ngtcp2_conn *conn,
   }
 
   assert(conn->remote.transport_params);
-  assert(conn->remote.transport_params->preferred_address_present);
+  assert(conn->remote.transport_params->preferred_addr_present);
 
   rv = conn->callbacks.select_preferred_addr(
-      conn, dest, &conn->remote.transport_params->preferred_address,
+      conn, dest, &conn->remote.transport_params->preferred_addr,
       conn->user_data);
   if (rv != 0) {
     return NGTCP2_ERR_CALLBACK_FAILURE;
@@ -572,7 +580,7 @@ static int conn_call_recv_datagram(ngtcp2_conn *conn,
   }
 
   if (!conn_is_tls_handshake_completed(conn)) {
-    flags |= NGTCP2_DATAGRAM_FLAG_EARLY;
+    flags |= NGTCP2_DATAGRAM_FLAG_0RTT;
   }
 
   rv = conn->callbacks.recv_datagram(conn, flags, data, datalen,
@@ -619,7 +627,8 @@ static int conn_call_version_negotiation(ngtcp2_conn *conn, uint32_t version,
   return 0;
 }
 
-static int conn_call_recv_rx_key(ngtcp2_conn *conn, ngtcp2_crypto_level level) {
+static int conn_call_recv_rx_key(ngtcp2_conn *conn,
+                                 ngtcp2_encryption_level level) {
   int rv;
 
   if (!conn->callbacks.recv_rx_key) {
@@ -634,7 +643,8 @@ static int conn_call_recv_rx_key(ngtcp2_conn *conn, ngtcp2_crypto_level level) {
   return 0;
 }
 
-static int conn_call_recv_tx_key(ngtcp2_conn *conn, ngtcp2_crypto_level level) {
+static int conn_call_recv_tx_key(ngtcp2_conn *conn,
+                                 ngtcp2_encryption_level level) {
   int rv;
 
   if (!conn->callbacks.recv_tx_key) {
@@ -1075,7 +1085,7 @@ static int conn_new(ngtcp2_conn **pconn, const ngtcp2_cid *dcid,
          (!server && !params->original_dcid_present));
   assert(!params->initial_scid_present);
   assert(server || !params->stateless_reset_token_present);
-  assert(server || !params->preferred_address_present);
+  assert(server || !params->preferred_addr_present);
   assert(server || !params->retry_scid_present);
   assert(server || callbacks->client_initial);
   assert(!server || callbacks->recv_client_initial);
@@ -1132,7 +1142,7 @@ static int conn_new(ngtcp2_conn **pconn, const ngtcp2_cid *dcid,
 
   ngtcp2_log_init(&(*pconn)->log, scid, settings->log_printf,
                   settings->initial_ts, user_data);
-  ngtcp2_qlog_init(&(*pconn)->qlog, settings->qlog.write, settings->initial_ts,
+  ngtcp2_qlog_init(&(*pconn)->qlog, settings->qlog_write, settings->initial_ts,
                    user_data);
   if ((*pconn)->qlog.write) {
     buf = ngtcp2_mem_malloc(mem, NGTCP2_QLOG_BUFLEN);
@@ -1269,6 +1279,9 @@ static int conn_new(ngtcp2_conn **pconn, const ngtcp2_cid *dcid,
     (*pconn)->vneg.preferred_versionslen = settings->preferred_versionslen;
   }
 
+  (*pconn)->local.settings.preferred_versions = NULL;
+  (*pconn)->local.settings.preferred_versionslen = 0;
+
   if (settings->available_versionslen) {
     if (!server && !ngtcp2_is_reserved_version(client_chosen_version)) {
       for (i = 0; i < settings->available_versionslen; ++i) {
@@ -1320,6 +1333,9 @@ static int conn_new(ngtcp2_conn **pconn, const ngtcp2_cid *dcid,
     (*pconn)->vneg.available_versionslen = sizeof(uint32_t);
   }
 
+  (*pconn)->local.settings.available_versions = NULL;
+  (*pconn)->local.settings.available_versionslen = 0;
+
   (*pconn)->client_chosen_version = client_chosen_version;
 
   conn_set_local_transport_params(*pconn, params);
@@ -1343,8 +1359,13 @@ static int conn_new(ngtcp2_conn **pconn, const ngtcp2_cid *dcid,
 
   conn_reset_ecn_validation_state(*pconn);
 
-  ngtcp2_qlog_start(&(*pconn)->qlog, server ? &settings->qlog.odcid : dcid,
-                    server);
+  ngtcp2_qlog_start(
+      &(*pconn)->qlog,
+      server ? ((*pconn)->local.transport_params.retry_scid_present
+                    ? &(*pconn)->local.transport_params.retry_scid
+                    : &(*pconn)->local.transport_params.original_dcid)
+             : dcid,
+      server);
 
   return 0;
 
@@ -1640,27 +1661,7 @@ static ngtcp2_duration conn_compute_ack_delay(ngtcp2_conn *conn) {
                     conn->cstat.smoothed_rtt / 8);
 }
 
-/*
- * conn_create_ack_frame creates ACK frame, and assigns its pointer to
- * |*pfr| if there are any received packets to acknowledge.  If there
- * are no packets to acknowledge, this function returns 0, and |*pfr|
- * is untouched.  The caller is advised to set |*pfr| to NULL before
- * calling this function, and check it after this function returns.
- * If |nodelay| is nonzero, delayed ACK timer is ignored.
- *
- * The memory for ACK frame is dynamically allocated by this function.
- * A caller is responsible to free it.
- *
- * Call ngtcp2_acktr_commit_ack after a created ACK frame is
- * successfully serialized into a packet.
- *
- * This function returns 0 if it succeeds, or one of the following
- * negative error codes:
- *
- * NGTCP2_ERR_NOMEM
- *     Out of memory.
- */
-static int conn_create_ack_frame(ngtcp2_conn *conn, ngtcp2_frame **pfr,
+int ngtcp2_conn_create_ack_frame(ngtcp2_conn *conn, ngtcp2_frame **pfr,
                                  ngtcp2_pktns *pktns, uint8_t type,
                                  ngtcp2_tstamp ts, ngtcp2_duration ack_delay,
                                  uint64_t ack_delay_exponent) {
@@ -1721,6 +1722,13 @@ static int conn_create_ack_frame(ngtcp2_conn *conn, ngtcp2_frame **pfr,
     ack->largest_ack = rpkt->pkt_num;
     ack->first_ack_range = rpkt->len - 1;
 
+    ngtcp2_ksl_it_next(&it);
+  } else if (rpkt->pkt_num + 1 == pktns->rx.max_pkt_num) {
+    last_pkt_num = rpkt->pkt_num - (int64_t)(rpkt->len - 1);
+    largest_ack_ts = pktns->rx.max_pkt_ts;
+    ack->largest_ack = pktns->rx.max_pkt_num;
+    ack->first_ack_range = rpkt->len;
+
     ngtcp2_ksl_it_next(&it);
   } else {
     assert(rpkt->pkt_num < pktns->rx.max_pkt_num);
@@ -2615,9 +2623,9 @@ conn_write_handshake_pkt(ngtcp2_conn *conn, ngtcp2_pkt_info *pi, uint8_t *dest,
     return 0;
   }
 
-  rv = conn_create_ack_frame(conn, &ackfr, pktns, type, ts,
-                             /* ack_delay = */ 0,
-                             NGTCP2_DEFAULT_ACK_DELAY_EXPONENT);
+  rv = ngtcp2_conn_create_ack_frame(conn, &ackfr, pktns, type, ts,
+                                    /* ack_delay = */ 0,
+                                    NGTCP2_DEFAULT_ACK_DELAY_EXPONENT);
   if (rv != 0) {
     ngtcp2_frame_chain_list_objalloc_del(frq, &conn->frc_objalloc, conn->mem);
     return rv;
@@ -2874,8 +2882,8 @@ static ngtcp2_ssize conn_write_ack_pkt(ngtcp2_conn *conn, ngtcp2_pkt_info *pi,
   }
 
   ackfr = NULL;
-  rv = conn_create_ack_frame(conn, &ackfr, pktns, type, ts, ack_delay,
-                             ack_delay_exponent);
+  rv = ngtcp2_conn_create_ack_frame(conn, &ackfr, pktns, type, ts, ack_delay,
+                                    ack_delay_exponent);
   if (rv != 0) {
     return rv;
   }
@@ -3651,9 +3659,9 @@ static ngtcp2_ssize conn_write_pkt(ngtcp2_conn *conn, ngtcp2_pkt_info *pi,
       }
     }
 
-    rv = conn_create_ack_frame(conn, &ackfr, pktns, type, ts,
-                               conn_compute_ack_delay(conn),
-                               conn->local.transport_params.ack_delay_exponent);
+    rv = ngtcp2_conn_create_ack_frame(
+        conn, &ackfr, pktns, type, ts, conn_compute_ack_delay(conn),
+        conn->local.transport_params.ack_delay_exponent);
     if (rv != 0) {
       assert(ngtcp2_err_is_fatal(rv));
       return rv;
@@ -5778,10 +5786,10 @@ decrypt_hp(ngtcp2_pkt_hd *hd, uint8_t *dest, const ngtcp2_crypto_cipher *hp,
  * NGTCP2_ERR_CRYPTO
  *     TLS backend reported error
  */
-static int conn_emit_pending_crypto_data(ngtcp2_conn *conn,
-                                         ngtcp2_crypto_level crypto_level,
-                                         ngtcp2_strm *strm,
-                                         uint64_t rx_offset) {
+static int
+conn_emit_pending_crypto_data(ngtcp2_conn *conn,
+                              ngtcp2_encryption_level encryption_level,
+                              ngtcp2_strm *strm, uint64_t rx_offset) {
   size_t datalen;
   const uint8_t *data;
   int rv;
@@ -5801,7 +5809,8 @@ static int conn_emit_pending_crypto_data(ngtcp2_conn *conn,
     offset = rx_offset;
     rx_offset += datalen;
 
-    rv = conn_call_recv_crypto_data(conn, crypto_level, offset, data, datalen);
+    rv = conn_call_recv_crypto_data(conn, encryption_level, offset, data,
+                                    datalen);
     if (rv != 0) {
       return rv;
     }
@@ -6019,17 +6028,7 @@ static int pktns_pkt_num_is_duplicate(ngtcp2_pktns *pktns, int64_t pkt_num) {
 static int pktns_commit_recv_pkt_num(ngtcp2_pktns *pktns, int64_t pkt_num,
                                      int ack_eliciting, ngtcp2_tstamp ts) {
   int rv;
-
-  if (ack_eliciting && pktns->rx.max_ack_eliciting_pkt_num + 1 != pkt_num) {
-    ngtcp2_acktr_immediate_ack(&pktns->acktr);
-  }
-  if (pktns->rx.max_pkt_num < pkt_num) {
-    pktns->rx.max_pkt_num = pkt_num;
-    pktns->rx.max_pkt_ts = ts;
-  }
-  if (ack_eliciting && pktns->rx.max_ack_eliciting_pkt_num < pkt_num) {
-    pktns->rx.max_ack_eliciting_pkt_num = pkt_num;
-  }
+  ngtcp2_range r;
 
   rv = ngtcp2_gaptr_push(&pktns->rx.pngap, (uint64_t)pkt_num, 1);
   if (rv != 0) {
@@ -6040,6 +6039,30 @@ static int pktns_commit_recv_pkt_num(ngtcp2_pktns *pktns, int64_t pkt_num,
     ngtcp2_gaptr_drop_first_gap(&pktns->rx.pngap);
   }
 
+  if (ack_eliciting) {
+    if (pktns->rx.max_ack_eliciting_pkt_num != -1) {
+      if (pkt_num < pktns->rx.max_ack_eliciting_pkt_num) {
+        ngtcp2_acktr_immediate_ack(&pktns->acktr);
+      } else if (pkt_num > pktns->rx.max_ack_eliciting_pkt_num) {
+        r = ngtcp2_gaptr_get_first_gap_after(
+            &pktns->rx.pngap, (uint64_t)pktns->rx.max_ack_eliciting_pkt_num);
+
+        if (r.begin < (uint64_t)pkt_num) {
+          ngtcp2_acktr_immediate_ack(&pktns->acktr);
+        }
+      }
+    }
+
+    if (pktns->rx.max_ack_eliciting_pkt_num < pkt_num) {
+      pktns->rx.max_ack_eliciting_pkt_num = pkt_num;
+    }
+  }
+
+  if (pktns->rx.max_pkt_num < pkt_num) {
+    pktns->rx.max_pkt_num = pkt_num;
+    pktns->rx.max_pkt_ts = ts;
+  }
+
   return 0;
 }
 
@@ -6100,7 +6123,8 @@ static int vneg_available_versions_includes(const uint8_t *available_versions,
   return 0;
 }
 
-static int conn_recv_crypto(ngtcp2_conn *conn, ngtcp2_crypto_level crypto_level,
+static int conn_recv_crypto(ngtcp2_conn *conn,
+                            ngtcp2_encryption_level encryption_level,
                             ngtcp2_strm *strm, const ngtcp2_crypto *fr);
 
 static ngtcp2_ssize conn_recv_pkt(ngtcp2_conn *conn, const ngtcp2_path *path,
@@ -6167,7 +6191,7 @@ conn_recv_handshake_pkt(ngtcp2_conn *conn, const ngtcp2_path *path,
   ngtcp2_decrypt decrypt;
   ngtcp2_pktns *pktns;
   ngtcp2_strm *crypto;
-  ngtcp2_crypto_level crypto_level;
+  ngtcp2_encryption_level encryption_level;
   int invalid_reserved_bits = 0;
 
   if (pktlen == 0) {
@@ -6406,7 +6430,7 @@ conn_recv_handshake_pkt(ngtcp2_conn *conn, const ngtcp2_path *path,
 
     pktns = conn->in_pktns;
     crypto = &pktns->crypto.strm;
-    crypto_level = NGTCP2_CRYPTO_LEVEL_INITIAL;
+    encryption_level = NGTCP2_ENCRYPTION_LEVEL_INITIAL;
 
     if (hd.version == conn->client_chosen_version) {
       ckm = pktns->crypto.rx.ckm;
@@ -6445,7 +6469,7 @@ conn_recv_handshake_pkt(ngtcp2_conn *conn, const ngtcp2_path *path,
 
     pktns = conn->hs_pktns;
     crypto = &pktns->crypto.strm;
-    crypto_level = NGTCP2_CRYPTO_LEVEL_HANDSHAKE;
+    encryption_level = NGTCP2_ENCRYPTION_LEVEL_HANDSHAKE;
     ckm = pktns->crypto.rx.ckm;
     hp_ctx = &pktns->crypto.rx.hp_ctx;
 
@@ -6636,7 +6660,7 @@ conn_recv_handshake_pkt(ngtcp2_conn *conn, const ngtcp2_path *path,
                         conn->negotiated_version);
       }
 
-      rv = conn_recv_crypto(conn, crypto_level, crypto, &fr->crypto);
+      rv = conn_recv_crypto(conn, encryption_level, crypto, &fr->crypto);
       if (rv != 0) {
         return rv;
       }
@@ -6897,7 +6921,7 @@ static int conn_emit_pending_stream_data(ngtcp2_conn *conn, ngtcp2_strm *strm,
       sdflags |= NGTCP2_STREAM_DATA_FLAG_FIN;
     }
     if (!handshake_completed) {
-      sdflags |= NGTCP2_STREAM_DATA_FLAG_EARLY;
+      sdflags |= NGTCP2_STREAM_DATA_FLAG_0RTT;
     }
 
     rv = conn_call_recv_stream_data(conn, strm, sdflags, offset, data, datalen);
@@ -6914,8 +6938,9 @@ static int conn_emit_pending_stream_data(ngtcp2_conn *conn, ngtcp2_strm *strm,
  * |rx_offset_base| is the offset in the entire TLS handshake stream.
  * fr->offset specifies the offset in each encryption level.
  * |max_rx_offset| is, if it is nonzero, the maximum offset in the
- * entire TLS handshake stream that |fr| can carry.  |crypto_level| is
- * the encryption level where this data is received.
+ * entire TLS handshake stream that |fr| can carry.
+ * |encryption_level| is the encryption level where this data is
+ * received.
  *
  * This function returns 0 if it succeeds, or one of the following
  * negative error codes:
@@ -6931,7 +6956,8 @@ static int conn_emit_pending_stream_data(ngtcp2_conn *conn, ngtcp2_strm *strm,
  * NGTCP2_ERR_CALLBACK_FAILURE
  *     User-defined callback function failed.
  */
-static int conn_recv_crypto(ngtcp2_conn *conn, ngtcp2_crypto_level crypto_level,
+static int conn_recv_crypto(ngtcp2_conn *conn,
+                            ngtcp2_encryption_level encryption_level,
                             ngtcp2_strm *crypto, const ngtcp2_crypto *fr) {
   uint64_t fr_end_offset;
   uint64_t rx_offset;
@@ -6952,7 +6978,7 @@ static int conn_recv_crypto(ngtcp2_conn *conn, ngtcp2_crypto_level crypto_level,
   if (fr_end_offset <= rx_offset) {
     if (conn->server &&
         !(conn->flags & NGTCP2_CONN_FLAG_HANDSHAKE_EARLY_RETRANSMIT) &&
-        crypto_level == NGTCP2_CRYPTO_LEVEL_INITIAL) {
+        encryption_level == NGTCP2_ENCRYPTION_LEVEL_INITIAL) {
       /* recovery draft: Speeding Up Handshake Completion
 
          When a server receives an Initial packet containing duplicate
@@ -6989,12 +7015,14 @@ static int conn_recv_crypto(ngtcp2_conn *conn, ngtcp2_crypto_level crypto_level,
       return rv;
     }
 
-    rv = conn_call_recv_crypto_data(conn, crypto_level, offset, data, datalen);
+    rv = conn_call_recv_crypto_data(conn, encryption_level, offset, data,
+                                    datalen);
     if (rv != 0) {
       return rv;
     }
 
-    rv = conn_emit_pending_crypto_data(conn, crypto_level, crypto, rx_offset);
+    rv = conn_emit_pending_crypto_data(conn, encryption_level, crypto,
+                                       rx_offset);
     if (rv != 0) {
       return rv;
     }
@@ -7213,7 +7241,7 @@ static int conn_recv_stream(ngtcp2_conn *conn, const ngtcp2_stream *fr) {
         sdflags |= NGTCP2_STREAM_DATA_FLAG_FIN;
       }
       if (!conn_is_tls_handshake_completed(conn)) {
-        sdflags |= NGTCP2_STREAM_DATA_FLAG_EARLY;
+        sdflags |= NGTCP2_STREAM_DATA_FLAG_0RTT;
       }
       rv = conn_call_recv_stream_data(conn, strm, sdflags, offset, data,
                                       (size_t)datalen);
@@ -8186,7 +8214,7 @@ static int conn_recv_handshake_done(ngtcp2_conn *conn, ngtcp2_tstamp ts) {
 
   assert(conn->remote.transport_params);
 
-  if (conn->remote.transport_params->preferred_address_present) {
+  if (conn->remote.transport_params->preferred_addr_present) {
     rv = conn_select_preferred_addr(conn);
     if (rv != 0) {
       return rv;
@@ -8231,6 +8259,8 @@ static int conn_key_phase_changed(ngtcp2_conn *conn, const ngtcp2_pkt_hd *hd) {
          !(hd->flags & NGTCP2_PKT_FLAG_KEY_PHASE);
 }
 
+static int conn_initiate_key_update(ngtcp2_conn *conn, ngtcp2_tstamp ts);
+
 /*
  * conn_prepare_key_update installs new updated keys.
  */
@@ -8247,7 +8277,7 @@ static int conn_prepare_key_update(ngtcp2_conn *conn, ngtcp2_tstamp ts) {
 
   if ((conn->flags & NGTCP2_CONN_FLAG_HANDSHAKE_CONFIRMED) &&
       tx_ckm->use_count >= pktns->crypto.ctx.max_encryption &&
-      ngtcp2_conn_initiate_key_update(conn, ts) != 0) {
+      conn_initiate_key_update(conn, ts) != 0) {
     return NGTCP2_ERR_AEAD_LIMIT_REACHED;
   }
 
@@ -8740,11 +8770,11 @@ conn_allow_path_change_under_disable_active_migration(ngtcp2_conn *conn,
   /* If local address changes, it must be one of the preferred
      addresses. */
 
-  if (!conn->local.transport_params.preferred_address_present) {
+  if (!conn->local.transport_params.preferred_addr_present) {
     return 0;
   }
 
-  paddr = &conn->local.transport_params.preferred_address;
+  paddr = &conn->local.transport_params.preferred_addr;
 
   if (paddr->ipv4_present) {
     ngtcp2_addr_init(&addr, (const ngtcp2_sockaddr *)&paddr->ipv4,
@@ -9188,7 +9218,7 @@ static ngtcp2_ssize conn_recv_pkt(ngtcp2_conn *conn, const ngtcp2_path *path,
       non_probing_pkt = 1;
       break;
     case NGTCP2_FRAME_CRYPTO:
-      rv = conn_recv_crypto(conn, NGTCP2_CRYPTO_LEVEL_APPLICATION,
+      rv = conn_recv_crypto(conn, NGTCP2_ENCRYPTION_LEVEL_1RTT,
                             &pktns->crypto.strm, &fr->crypto);
       if (rv != 0) {
         return rv;
@@ -9881,8 +9911,7 @@ int ngtcp2_conn_read_pkt_versioned(ngtcp2_conn *conn, const ngtcp2_path *path,
 
   assert(!(conn->flags & NGTCP2_CONN_FLAG_PPE_PENDING));
 
-  conn->log.last_ts = ts;
-  conn->qlog.last_ts = ts;
+  conn_update_timestamp(conn, ts);
 
   ngtcp2_log_info(&conn->log, NGTCP2_LOG_EVENT_CON, "recv packet len=%zu",
                   pktlen);
@@ -10187,10 +10216,10 @@ static ngtcp2_ssize conn_write_handshake(ngtcp2_conn *conn, ngtcp2_pkt_info *pi,
 
     assert(conn->remote.transport_params);
 
-    if (conn->remote.transport_params->preferred_address_present) {
+    if (conn->remote.transport_params->preferred_addr_present) {
       assert(!ngtcp2_ringbuf_full(&conn->dcid.unused.rb));
 
-      paddr = &conn->remote.transport_params->preferred_address;
+      paddr = &conn->remote.transport_params->preferred_addr;
       dcid = ngtcp2_ringbuf_push_back(&conn->dcid.unused.rb);
       ngtcp2_dcid_init(dcid, 1, &paddr->cid, paddr->stateless_reset_token);
 
@@ -10599,7 +10628,7 @@ int ngtcp2_conn_install_rx_handshake_key(
 
   pktns->crypto.rx.hp_ctx = *hp_ctx;
 
-  rv = conn_call_recv_rx_key(conn, NGTCP2_CRYPTO_LEVEL_HANDSHAKE);
+  rv = conn_call_recv_rx_key(conn, NGTCP2_ENCRYPTION_LEVEL_HANDSHAKE);
   if (rv != 0) {
     ngtcp2_crypto_km_del(pktns->crypto.rx.ckm, conn->mem);
     pktns->crypto.rx.ckm = NULL;
@@ -10638,7 +10667,7 @@ int ngtcp2_conn_install_tx_handshake_key(
     }
   }
 
-  rv = conn_call_recv_tx_key(conn, NGTCP2_CRYPTO_LEVEL_HANDSHAKE);
+  rv = conn_call_recv_tx_key(conn, NGTCP2_ENCRYPTION_LEVEL_HANDSHAKE);
   if (rv != 0) {
     ngtcp2_crypto_km_del(pktns->crypto.tx.ckm, conn->mem);
     pktns->crypto.tx.ckm = NULL;
@@ -10651,10 +10680,10 @@ int ngtcp2_conn_install_tx_handshake_key(
   return 0;
 }
 
-int ngtcp2_conn_install_early_key(ngtcp2_conn *conn,
-                                  const ngtcp2_crypto_aead_ctx *aead_ctx,
-                                  const uint8_t *iv, size_t ivlen,
-                                  const ngtcp2_crypto_cipher_ctx *hp_ctx) {
+int ngtcp2_conn_install_0rtt_key(ngtcp2_conn *conn,
+                                 const ngtcp2_crypto_aead_ctx *aead_ctx,
+                                 const uint8_t *iv, size_t ivlen,
+                                 const ngtcp2_crypto_cipher_ctx *hp_ctx) {
   int rv;
 
   assert(ivlen >= 8);
@@ -10672,9 +10701,9 @@ int ngtcp2_conn_install_early_key(ngtcp2_conn *conn,
   conn->flags |= NGTCP2_CONN_FLAG_EARLY_KEY_INSTALLED;
 
   if (conn->server) {
-    rv = conn_call_recv_rx_key(conn, NGTCP2_CRYPTO_LEVEL_EARLY);
+    rv = conn_call_recv_rx_key(conn, NGTCP2_ENCRYPTION_LEVEL_0RTT);
   } else {
-    rv = conn_call_recv_tx_key(conn, NGTCP2_CRYPTO_LEVEL_EARLY);
+    rv = conn_call_recv_tx_key(conn, NGTCP2_ENCRYPTION_LEVEL_0RTT);
   }
   if (rv != 0) {
     ngtcp2_crypto_km_del(conn->early.ckm, conn->mem);
@@ -10723,7 +10752,7 @@ int ngtcp2_conn_install_rx_key(ngtcp2_conn *conn, const uint8_t *secret,
     }
   }
 
-  rv = conn_call_recv_rx_key(conn, NGTCP2_CRYPTO_LEVEL_APPLICATION);
+  rv = conn_call_recv_rx_key(conn, NGTCP2_ENCRYPTION_LEVEL_1RTT);
   if (rv != 0) {
     ngtcp2_crypto_km_del(pktns->crypto.rx.ckm, conn->mem);
     pktns->crypto.rx.ckm = NULL;
@@ -10769,7 +10798,7 @@ int ngtcp2_conn_install_tx_key(ngtcp2_conn *conn, const uint8_t *secret,
     conn_discard_early_key(conn);
   }
 
-  rv = conn_call_recv_tx_key(conn, NGTCP2_CRYPTO_LEVEL_APPLICATION);
+  rv = conn_call_recv_tx_key(conn, NGTCP2_ENCRYPTION_LEVEL_1RTT);
   if (rv != 0) {
     ngtcp2_crypto_km_del(pktns->crypto.tx.ckm, conn->mem);
     pktns->crypto.tx.ckm = NULL;
@@ -10782,7 +10811,7 @@ int ngtcp2_conn_install_tx_key(ngtcp2_conn *conn, const uint8_t *secret,
   return 0;
 }
 
-int ngtcp2_conn_initiate_key_update(ngtcp2_conn *conn, ngtcp2_tstamp ts) {
+static int conn_initiate_key_update(ngtcp2_conn *conn, ngtcp2_tstamp ts) {
   ngtcp2_tstamp confirmed_ts = conn->crypto.key_update.confirmed_ts;
   ngtcp2_duration pto = conn_compute_pto(conn, &conn->pktns);
 
@@ -10801,6 +10830,12 @@ int ngtcp2_conn_initiate_key_update(ngtcp2_conn *conn, ngtcp2_tstamp ts) {
   return 0;
 }
 
+int ngtcp2_conn_initiate_key_update(ngtcp2_conn *conn, ngtcp2_tstamp ts) {
+  conn_update_timestamp(conn, ts);
+
+  return conn_initiate_key_update(conn, ts);
+}
+
 /*
  * conn_retire_stale_bound_dcid retires stale destination connection
  * ID in conn->dcid.bound to keep some unused destination connection
@@ -10947,7 +10982,11 @@ ngtcp2_tstamp ngtcp2_conn_get_expiry(ngtcp2_conn *conn) {
 
 int ngtcp2_conn_handle_expiry(ngtcp2_conn *conn, ngtcp2_tstamp ts) {
   int rv;
-  ngtcp2_duration pto = conn_compute_pto(conn, &conn->pktns);
+  ngtcp2_duration pto;
+
+  conn_update_timestamp(conn, ts);
+
+  pto = conn_compute_pto(conn, &conn->pktns);
 
   assert(!(conn->flags & NGTCP2_CONN_FLAG_PPE_PENDING));
 
@@ -11151,8 +11190,7 @@ conn_client_validate_transport_params(ngtcp2_conn *conn,
     return NGTCP2_ERR_TRANSPORT_PARAM;
   }
 
-  if (params->preferred_address_present &&
-      conn->dcid.current.cid.datalen == 0) {
+  if (params->preferred_addr_present && conn->dcid.current.cid.datalen == 0) {
     return NGTCP2_ERR_TRANSPORT_PARAM;
   }
 
@@ -11175,8 +11213,8 @@ conn_client_validate_transport_params(ngtcp2_conn *conn,
 
       /* QUIC v1 (and the supported draft versions) are treated
          specially.  If version_info is missing, no further validation
-         is necessary.
-         https://datatracker.ietf.org/doc/html/draft-ietf-quic-version-negotiation-10#section-8
+         is necessary.  See
+         https://datatracker.ietf.org/doc/html/rfc9368#section-8
        */
       if (conn->client_chosen_version == NGTCP2_PROTO_VER_V1 ||
           (NGTCP2_PROTO_VER_DRAFT_MIN <= conn->client_chosen_version &&
@@ -11187,8 +11225,8 @@ conn_client_validate_transport_params(ngtcp2_conn *conn,
       return NGTCP2_ERR_VERSION_NEGOTIATION_FAILURE;
     }
 
-    /* Server choose original version after Version Negotiation.
-       Draft does not say this particular case, but this smells like
+    /* Server choose original version after Version Negotiation.  RFC
+       9368 does not say this particular case, but this smells like
        misbehaved server because server should accept original_version
        in the original connection. */
     if (conn->local.settings.original_version ==
@@ -11265,7 +11303,7 @@ int ngtcp2_conn_set_remote_transport_params(
   if (conn->server) {
     if (params->original_dcid_present ||
         params->stateless_reset_token_present ||
-        params->preferred_address_present || params->retry_scid_present) {
+        params->preferred_addr_present || params->retry_scid_present) {
       return NGTCP2_ERR_TRANSPORT_PARAM;
     }
 
@@ -11339,9 +11377,9 @@ int ngtcp2_conn_set_remote_transport_params(
   return 0;
 }
 
-int ngtcp2_conn_decode_remote_transport_params(ngtcp2_conn *conn,
-                                               const uint8_t *data,
-                                               size_t datalen) {
+int ngtcp2_conn_decode_and_set_remote_transport_params(ngtcp2_conn *conn,
+                                                       const uint8_t *data,
+                                                       size_t datalen) {
   ngtcp2_transport_params params;
   int rv;
 
@@ -11362,9 +11400,9 @@ ngtcp2_conn_get_remote_transport_params(ngtcp2_conn *conn) {
   return conn->remote.transport_params;
 }
 
-ngtcp2_ssize ngtcp2_conn_encode_early_transport_params(ngtcp2_conn *conn,
-                                                       uint8_t *dest,
-                                                       size_t destlen) {
+ngtcp2_ssize ngtcp2_conn_encode_0rtt_transport_params(ngtcp2_conn *conn,
+                                                      uint8_t *dest,
+                                                      size_t destlen) {
   ngtcp2_transport_params params, *src;
 
   if (conn->server) {
@@ -11397,9 +11435,9 @@ ngtcp2_ssize ngtcp2_conn_encode_early_transport_params(ngtcp2_conn *conn,
   return ngtcp2_transport_params_encode(dest, destlen, &params);
 }
 
-int ngtcp2_conn_decode_early_transport_params(ngtcp2_conn *conn,
-                                              const uint8_t *data,
-                                              size_t datalen) {
+int ngtcp2_conn_decode_and_set_0rtt_transport_params(ngtcp2_conn *conn,
+                                                     const uint8_t *data,
+                                                     size_t datalen) {
   ngtcp2_transport_params params;
   int rv;
 
@@ -11408,10 +11446,10 @@ int ngtcp2_conn_decode_early_transport_params(ngtcp2_conn *conn,
     return rv;
   }
 
-  return ngtcp2_conn_set_early_remote_transport_params(conn, &params);
+  return ngtcp2_conn_set_0rtt_remote_transport_params(conn, &params);
 }
 
-int ngtcp2_conn_set_early_remote_transport_params(
+int ngtcp2_conn_set_0rtt_remote_transport_params(
     ngtcp2_conn *conn, const ngtcp2_transport_params *params) {
   ngtcp2_transport_params *p;
 
@@ -11511,16 +11549,16 @@ int ngtcp2_conn_commit_local_transport_params(ngtcp2_conn *conn) {
   params->initial_scid_present = 1;
 
   if (conn->oscid.datalen == 0) {
-    params->preferred_address_present = 0;
+    params->preferred_addr_present = 0;
   }
 
-  if (conn->server && params->preferred_address_present) {
+  if (conn->server && params->preferred_addr_present) {
     scident = ngtcp2_mem_malloc(mem, sizeof(*scident));
     if (scident == NULL) {
       return NGTCP2_ERR_NOMEM;
     }
 
-    ngtcp2_scid_init(scident, 1, &params->preferred_address.cid);
+    ngtcp2_scid_init(scident, 1, &params->preferred_addr.cid);
 
     rv = ngtcp2_ksl_insert(&conn->scid.set, NULL, &scident->cid, scident);
     if (rv != 0) {
@@ -11784,8 +11822,7 @@ ngtcp2_ssize ngtcp2_conn_write_vmsg(ngtcp2_conn *conn, ngtcp2_path *path,
   ngtcp2_rtb_entry *rtbent;
   (void)pkt_info_version;
 
-  conn->log.last_ts = ts;
-  conn->qlog.last_ts = ts;
+  conn_update_timestamp(conn, ts);
 
   if (path) {
     ngtcp2_path_copy(path, &conn->dcid.current.ps.path);
@@ -12196,9 +12233,6 @@ ngtcp2_ssize ngtcp2_conn_write_connection_close_pkt(
   ngtcp2_ssize nwrite;
   uint64_t server_tx_left;
 
-  conn->log.last_ts = ts;
-  conn->qlog.last_ts = ts;
-
   if (conn_check_pkt_num_exhausted(conn)) {
     return NGTCP2_ERR_PKT_NUM_EXHAUSTED;
   }
@@ -12261,9 +12295,6 @@ ngtcp2_ssize ngtcp2_conn_write_application_close_pkt(
   ngtcp2_frame fr;
   uint64_t server_tx_left;
 
-  conn->log.last_ts = ts;
-  conn->qlog.last_ts = ts;
-
   if (conn_check_pkt_num_exhausted(conn)) {
     return NGTCP2_ERR_PKT_NUM_EXHAUSTED;
   }
@@ -12401,6 +12432,8 @@ ngtcp2_ssize ngtcp2_conn_write_connection_close_versioned(
     const ngtcp2_ccerr *ccerr, ngtcp2_tstamp ts) {
   (void)pkt_info_version;
 
+  conn_update_timestamp(conn, ts);
+
   switch (ccerr->type) {
   case NGTCP2_CCERR_TYPE_TRANSPORT:
     return ngtcp2_conn_write_connection_close_pkt(
@@ -12415,11 +12448,11 @@ ngtcp2_ssize ngtcp2_conn_write_connection_close_versioned(
   }
 }
 
-int ngtcp2_conn_is_in_closing_period(ngtcp2_conn *conn) {
+int ngtcp2_conn_in_closing_period(ngtcp2_conn *conn) {
   return conn->state == NGTCP2_CS_CLOSING;
 }
 
-int ngtcp2_conn_is_in_draining_period(ngtcp2_conn *conn) {
+int ngtcp2_conn_in_draining_period(ngtcp2_conn *conn) {
   return conn->state == NGTCP2_CS_DRAINING;
 }
 
@@ -12528,10 +12561,11 @@ static int conn_shutdown_stream_read(ngtcp2_conn *conn, ngtcp2_strm *strm,
   return conn_stop_sending(conn, strm, app_error_code);
 }
 
-int ngtcp2_conn_shutdown_stream(ngtcp2_conn *conn, int64_t stream_id,
-                                uint64_t app_error_code) {
+int ngtcp2_conn_shutdown_stream(ngtcp2_conn *conn, uint32_t flags,
+                                int64_t stream_id, uint64_t app_error_code) {
   int rv;
   ngtcp2_strm *strm;
+  (void)flags;
 
   strm = ngtcp2_conn_find_stream(conn, stream_id);
   if (strm == NULL) {
@@ -12555,9 +12589,11 @@ int ngtcp2_conn_shutdown_stream(ngtcp2_conn *conn, int64_t stream_id,
   return 0;
 }
 
-int ngtcp2_conn_shutdown_stream_write(ngtcp2_conn *conn, int64_t stream_id,
+int ngtcp2_conn_shutdown_stream_write(ngtcp2_conn *conn, uint32_t flags,
+                                      int64_t stream_id,
                                       uint64_t app_error_code) {
   ngtcp2_strm *strm;
+  (void)flags;
 
   if (!bidi_stream(stream_id) && !conn_local_stream(conn, stream_id)) {
     return NGTCP2_ERR_INVALID_ARGUMENT;
@@ -12571,9 +12607,11 @@ int ngtcp2_conn_shutdown_stream_write(ngtcp2_conn *conn, int64_t stream_id,
   return conn_shutdown_stream_write(conn, strm, app_error_code);
 }
 
-int ngtcp2_conn_shutdown_stream_read(ngtcp2_conn *conn, int64_t stream_id,
+int ngtcp2_conn_shutdown_stream_read(ngtcp2_conn *conn, uint32_t flags,
+                                     int64_t stream_id,
                                      uint64_t app_error_code) {
   ngtcp2_strm *strm;
+  (void)flags;
 
   if (!bidi_stream(stream_id) && conn_local_stream(conn, stream_id)) {
     return NGTCP2_ERR_INVALID_ARGUMENT;
@@ -12632,6 +12670,10 @@ int ngtcp2_conn_extend_max_stream_offset(ngtcp2_conn *conn, int64_t stream_id,
     return 0;
   }
 
+  if (!bidi_stream(stream_id) && conn_local_stream(conn, stream_id)) {
+    return NGTCP2_ERR_INVALID_ARGUMENT;
+  }
+
   return conn_extend_max_stream_offset(conn, strm, datalen);
 }
 
@@ -12725,7 +12767,7 @@ static void conn_discard_early_data_state(ngtcp2_conn *conn) {
   }
 }
 
-int ngtcp2_conn_early_data_rejected(ngtcp2_conn *conn) {
+int ngtcp2_conn_tls_early_data_rejected(ngtcp2_conn *conn) {
   if (conn->flags & NGTCP2_CONN_FLAG_EARLY_DATA_REJECTED) {
     return 0;
   }
@@ -12734,14 +12776,14 @@ int ngtcp2_conn_early_data_rejected(ngtcp2_conn *conn) {
 
   conn_discard_early_data_state(conn);
 
-  if (conn->callbacks.early_data_rejected) {
-    return conn->callbacks.early_data_rejected(conn, conn->user_data);
+  if (conn->callbacks.tls_early_data_rejected) {
+    return conn->callbacks.tls_early_data_rejected(conn, conn->user_data);
   }
 
   return 0;
 }
 
-int ngtcp2_conn_get_early_data_rejected(ngtcp2_conn *conn) {
+int ngtcp2_conn_get_tls_early_data_rejected(ngtcp2_conn *conn) {
   return (conn->flags & NGTCP2_CONN_FLAG_EARLY_DATA_REJECTED) != 0;
 }
 
@@ -12934,9 +12976,6 @@ int ngtcp2_conn_on_loss_detection_timer(ngtcp2_conn *conn, ngtcp2_tstamp ts) {
   ngtcp2_tstamp earliest_loss_time;
   ngtcp2_pktns *loss_pktns = NULL;
 
-  conn->log.last_ts = ts;
-  conn->qlog.last_ts = ts;
-
   switch (conn->state) {
   case NGTCP2_CS_CLOSING:
   case NGTCP2_CS_DRAINING:
@@ -13029,7 +13068,7 @@ static int conn_buffer_crypto_data(ngtcp2_conn *conn, const uint8_t **pdata,
 }
 
 int ngtcp2_conn_submit_crypto_data(ngtcp2_conn *conn,
-                                   ngtcp2_crypto_level crypto_level,
+                                   ngtcp2_encryption_level encryption_level,
                                    const uint8_t *data, const size_t datalen) {
   ngtcp2_pktns *pktns;
   ngtcp2_frame_chain *frc;
@@ -13040,16 +13079,16 @@ int ngtcp2_conn_submit_crypto_data(ngtcp2_conn *conn,
     return 0;
   }
 
-  switch (crypto_level) {
-  case NGTCP2_CRYPTO_LEVEL_INITIAL:
+  switch (encryption_level) {
+  case NGTCP2_ENCRYPTION_LEVEL_INITIAL:
     assert(conn->in_pktns);
     pktns = conn->in_pktns;
     break;
-  case NGTCP2_CRYPTO_LEVEL_HANDSHAKE:
+  case NGTCP2_ENCRYPTION_LEVEL_HANDSHAKE:
     assert(conn->hs_pktns);
     pktns = conn->hs_pktns;
     break;
-  case NGTCP2_CRYPTO_LEVEL_APPLICATION:
+  case NGTCP2_ENCRYPTION_LEVEL_1RTT:
     pktns = &conn->pktns;
     break;
   default:
@@ -13123,16 +13162,16 @@ int ngtcp2_conn_tx_strmq_push(ngtcp2_conn *conn, ngtcp2_strm *strm) {
   return ngtcp2_pq_push(&conn->tx.strmq, &strm->pe);
 }
 
-static int conn_has_uncommited_preferred_address_cid(ngtcp2_conn *conn) {
+static int conn_has_uncommited_preferred_addr_cid(ngtcp2_conn *conn) {
   return conn->server &&
          !(conn->flags & NGTCP2_CONN_FLAG_LOCAL_TRANSPORT_PARAMS_COMMITTED) &&
          conn->oscid.datalen &&
-         conn->local.transport_params.preferred_address_present;
+         conn->local.transport_params.preferred_addr_present;
 }
 
 size_t ngtcp2_conn_get_num_scid(ngtcp2_conn *conn) {
   return ngtcp2_ksl_len(&conn->scid.set) +
-         (size_t)conn_has_uncommited_preferred_address_cid(conn);
+         (size_t)conn_has_uncommited_preferred_addr_cid(conn);
 }
 
 size_t ngtcp2_conn_get_scid(ngtcp2_conn *conn, ngtcp2_cid *dest) {
@@ -13146,8 +13185,8 @@ size_t ngtcp2_conn_get_scid(ngtcp2_conn *conn, ngtcp2_cid *dest) {
     *dest++ = scid->cid;
   }
 
-  if (conn_has_uncommited_preferred_address_cid(conn)) {
-    *dest++ = conn->local.transport_params.preferred_address.cid;
+  if (conn_has_uncommited_preferred_addr_cid(conn)) {
+    *dest++ = conn->local.transport_params.preferred_addr.cid;
   }
 
   return (size_t)(dest - origdest);
@@ -13282,8 +13321,7 @@ int ngtcp2_conn_initiate_immediate_migration(ngtcp2_conn *conn,
 
   assert(!conn->server);
 
-  conn->log.last_ts = ts;
-  conn->qlog.last_ts = ts;
+  conn_update_timestamp(conn, ts);
 
   rv = conn_initiate_migration_precheck(conn, &path->local);
   if (rv != 0) {
@@ -13341,8 +13379,7 @@ int ngtcp2_conn_initiate_migration(ngtcp2_conn *conn, const ngtcp2_path *path,
 
   assert(!conn->server);
 
-  conn->log.last_ts = ts;
-  conn->qlog.last_ts = ts;
+  conn_update_timestamp(conn, ts);
 
   rv = conn_initiate_migration_precheck(conn, &path->local);
   if (rv != 0) {
@@ -13481,12 +13518,12 @@ const ngtcp2_crypto_ctx *ngtcp2_conn_get_crypto_ctx(ngtcp2_conn *conn) {
   return &conn->pktns.crypto.ctx;
 }
 
-void ngtcp2_conn_set_early_crypto_ctx(ngtcp2_conn *conn,
-                                      const ngtcp2_crypto_ctx *ctx) {
+void ngtcp2_conn_set_0rtt_crypto_ctx(ngtcp2_conn *conn,
+                                     const ngtcp2_crypto_ctx *ctx) {
   conn->early.ctx = *ctx;
 }
 
-const ngtcp2_crypto_ctx *ngtcp2_conn_get_early_crypto_ctx(ngtcp2_conn *conn) {
+const ngtcp2_crypto_ctx *ngtcp2_conn_get_0rtt_crypto_ctx(ngtcp2_conn *conn) {
   return &conn->early.ctx;
 }
 
@@ -13546,6 +13583,8 @@ void ngtcp2_conn_update_pkt_tx_time(ngtcp2_conn *conn, ngtcp2_tstamp ts) {
   double pacing_rate;
   ngtcp2_duration interval;
 
+  conn_update_timestamp(conn, ts);
+
   if (conn->tx.pacing.pktlen == 0) {
     return;
   }
index 9b3bbfdc7521bea4040d51042abf6878ac756c6e..da68b2e57cb49081addcda30576d328548189fd1 100644 (file)
@@ -222,14 +222,6 @@ void ngtcp2_path_challenge_entry_init(ngtcp2_path_challenge_entry *pcent,
    endpoint has initiated key update. */
 #define NGTCP2_CONN_FLAG_KEY_UPDATE_INITIATOR 0x10000u
 
-typedef struct ngtcp2_crypto_data {
-  ngtcp2_buf buf;
-  /* pkt_type is the type of packet to send data in buf.  If it is 0,
-     it must be sent in Short packet.  Otherwise, it is sent the long
-     packet type denoted by pkt_type. */
-  uint8_t pkt_type;
-} ngtcp2_crypto_data;
-
 typedef struct ngtcp2_pktns {
   struct {
     /* last_pkt_num is the packet number which the local endpoint sent
@@ -1126,7 +1118,7 @@ int ngtcp2_conn_set_remote_transport_params(
 /**
  * @function
  *
- * `ngtcp2_conn_set_early_remote_transport_params` sets |params| as
+ * `ngtcp2_conn_set_0rtt_remote_transport_params` sets |params| as
  * transport parameters previously received from a server.  The
  * parameters are used to send early data.  QUIC requires that client
  * application should remember transport parameters along with a
@@ -1159,7 +1151,29 @@ int ngtcp2_conn_set_remote_transport_params(
  * :macro:`NGTCP2_ERR_NOMEM`
  *     Out of memory.
  */
-int ngtcp2_conn_set_early_remote_transport_params(
+int ngtcp2_conn_set_0rtt_remote_transport_params(
     ngtcp2_conn *conn, const ngtcp2_transport_params *params);
 
+/*
+ * ngtcp2_conn_create_ack_frame creates ACK frame, and assigns its
+ * pointer to |*pfr| if there are any received packets to acknowledge.
+ * If there are no packets to acknowledge, this function returns 0,
+ * and |*pfr| is untouched.  The caller is advised to set |*pfr| to
+ * NULL before calling this function, and check it after this function
+ * returns.
+ *
+ * Call ngtcp2_acktr_commit_ack after a created ACK frame is
+ * successfully serialized into a packet.
+ *
+ * This function returns 0 if it succeeds, or one of the following
+ * negative error codes:
+ *
+ * NGTCP2_ERR_NOMEM
+ *     Out of memory.
+ */
+int ngtcp2_conn_create_ack_frame(ngtcp2_conn *conn, ngtcp2_frame **pfr,
+                                 ngtcp2_pktns *pktns, uint8_t type,
+                                 ngtcp2_tstamp ts, ngtcp2_duration ack_delay,
+                                 uint64_t ack_delay_exponent);
+
 #endif /* NGTCP2_CONN_H */
index 419abddcddddf89c4da751e073f28affa0e6c034..e199f4eb9fe486a9df30027fccc716fc55970da2 100644 (file)
@@ -179,12 +179,12 @@ ngtcp2_ssize ngtcp2_transport_params_encode_versioned(
            NGTCP2_STATELESS_RESET_TOKENLEN;
   }
 
-  if (params->preferred_address_present) {
-    assert(params->preferred_address.cid.datalen >= NGTCP2_MIN_CIDLEN);
-    assert(params->preferred_address.cid.datalen <= NGTCP2_MAX_CIDLEN);
+  if (params->preferred_addr_present) {
+    assert(params->preferred_addr.cid.datalen >= NGTCP2_MIN_CIDLEN);
+    assert(params->preferred_addr.cid.datalen <= NGTCP2_MAX_CIDLEN);
     preferred_addrlen = 4 /* ipv4Address */ + 2 /* ipv4Port */ +
                         16 /* ipv6Address */ + 2 /* ipv6Port */
-                        + 1 + params->preferred_address.cid.datalen /* CID */ +
+                        + 1 + params->preferred_addr.cid.datalen /* CID */ +
                         NGTCP2_STATELESS_RESET_TOKENLEN;
     len += ngtcp2_put_uvarintlen(NGTCP2_TRANSPORT_PARAM_PREFERRED_ADDRESS) +
            ngtcp2_put_uvarintlen(preferred_addrlen) + preferred_addrlen;
@@ -291,12 +291,12 @@ ngtcp2_ssize ngtcp2_transport_params_encode_versioned(
                       sizeof(params->stateless_reset_token));
   }
 
-  if (params->preferred_address_present) {
+  if (params->preferred_addr_present) {
     p = ngtcp2_put_uvarint(p, NGTCP2_TRANSPORT_PARAM_PREFERRED_ADDRESS);
     p = ngtcp2_put_uvarint(p, preferred_addrlen);
 
-    if (params->preferred_address.ipv4_present) {
-      sa_in = &params->preferred_address.ipv4;
+    if (params->preferred_addr.ipv4_present) {
+      sa_in = &params->preferred_addr.ipv4;
       p = ngtcp2_cpymem(p, &sa_in->sin_addr, sizeof(sa_in->sin_addr));
       p = ngtcp2_put_uint16(p, sa_in->sin_port);
     } else {
@@ -304,8 +304,8 @@ ngtcp2_ssize ngtcp2_transport_params_encode_versioned(
       p = ngtcp2_put_uint16(p, 0);
     }
 
-    if (params->preferred_address.ipv6_present) {
-      sa_in6 = &params->preferred_address.ipv6;
+    if (params->preferred_addr.ipv6_present) {
+      sa_in6 = &params->preferred_addr.ipv6;
       p = ngtcp2_cpymem(p, &sa_in6->sin6_addr, sizeof(sa_in6->sin6_addr));
       p = ngtcp2_put_uint16(p, sa_in6->sin6_port);
     } else {
@@ -313,13 +313,13 @@ ngtcp2_ssize ngtcp2_transport_params_encode_versioned(
       p = ngtcp2_put_uint16(p, 0);
     }
 
-    *p++ = (uint8_t)params->preferred_address.cid.datalen;
-    if (params->preferred_address.cid.datalen) {
-      p = ngtcp2_cpymem(p, params->preferred_address.cid.data,
-                        params->preferred_address.cid.datalen);
+    *p++ = (uint8_t)params->preferred_addr.cid.datalen;
+    if (params->preferred_addr.cid.datalen) {
+      p = ngtcp2_cpymem(p, params->preferred_addr.cid.data,
+                        params->preferred_addr.cid.datalen);
     }
-    p = ngtcp2_cpymem(p, params->preferred_address.stateless_reset_token,
-                      sizeof(params->preferred_address.stateless_reset_token));
+    p = ngtcp2_cpymem(p, params->preferred_addr.stateless_reset_token,
+                      sizeof(params->preferred_addr.stateless_reset_token));
   }
 
   if (params->retry_scid_present) {
@@ -548,7 +548,7 @@ int ngtcp2_transport_params_decode_versioned(int transport_params_version,
   params->max_udp_payload_size = NGTCP2_DEFAULT_MAX_RECV_UDP_PAYLOAD_SIZE;
   params->ack_delay_exponent = NGTCP2_DEFAULT_ACK_DELAY_EXPONENT;
   params->stateless_reset_token_present = 0;
-  params->preferred_address_present = 0;
+  params->preferred_addr_present = 0;
   params->disable_active_migration = 0;
   params->max_ack_delay = NGTCP2_DEFAULT_MAX_ACK_DELAY;
   params->max_idle_timeout = 0;
@@ -659,7 +659,7 @@ int ngtcp2_transport_params_decode_versioned(int transport_params_version,
         return NGTCP2_ERR_MALFORMED_TRANSPORT_PARAM;
       }
 
-      sa_in = &params->preferred_address.ipv4;
+      sa_in = &params->preferred_addr.ipv4;
 
       p = ngtcp2_get_bytes(&sa_in->sin_addr, p, sizeof(sa_in->sin_addr));
       p = ngtcp2_get_uint16be(&sa_in->sin_port, p);
@@ -667,10 +667,10 @@ int ngtcp2_transport_params_decode_versioned(int transport_params_version,
       if (sa_in->sin_port || memcmp(empty_address, &sa_in->sin_addr,
                                     sizeof(sa_in->sin_addr)) != 0) {
         sa_in->sin_family = AF_INET;
-        params->preferred_address.ipv4_present = 1;
+        params->preferred_addr.ipv4_present = 1;
       }
 
-      sa_in6 = &params->preferred_address.ipv6;
+      sa_in6 = &params->preferred_addr.ipv6;
 
       p = ngtcp2_get_bytes(&sa_in6->sin6_addr, p, sizeof(sa_in6->sin6_addr));
       p = ngtcp2_get_uint16be(&sa_in6->sin6_port, p);
@@ -678,27 +678,27 @@ int ngtcp2_transport_params_decode_versioned(int transport_params_version,
       if (sa_in6->sin6_port || memcmp(empty_address, &sa_in6->sin6_addr,
                                       sizeof(sa_in6->sin6_addr)) != 0) {
         sa_in6->sin6_family = AF_INET6;
-        params->preferred_address.ipv6_present = 1;
+        params->preferred_addr.ipv6_present = 1;
       }
 
       /* cid */
-      params->preferred_address.cid.datalen = *p++;
-      len += params->preferred_address.cid.datalen;
+      params->preferred_addr.cid.datalen = *p++;
+      len += params->preferred_addr.cid.datalen;
       if (valuelen != len ||
-          params->preferred_address.cid.datalen > NGTCP2_MAX_CIDLEN ||
-          params->preferred_address.cid.datalen < NGTCP2_MIN_CIDLEN) {
+          params->preferred_addr.cid.datalen > NGTCP2_MAX_CIDLEN ||
+          params->preferred_addr.cid.datalen < NGTCP2_MIN_CIDLEN) {
         return NGTCP2_ERR_MALFORMED_TRANSPORT_PARAM;
       }
-      if (params->preferred_address.cid.datalen) {
-        p = ngtcp2_get_bytes(params->preferred_address.cid.data, p,
-                             params->preferred_address.cid.datalen);
+      if (params->preferred_addr.cid.datalen) {
+        p = ngtcp2_get_bytes(params->preferred_addr.cid.data, p,
+                             params->preferred_addr.cid.datalen);
       }
 
       /* stateless reset token */
       p = ngtcp2_get_bytes(
-          params->preferred_address.stateless_reset_token, p,
-          sizeof(params->preferred_address.stateless_reset_token));
-      params->preferred_address_present = 1;
+          params->preferred_addr.stateless_reset_token, p,
+          sizeof(params->preferred_addr.stateless_reset_token));
+      params->preferred_addr_present = 1;
       break;
     case NGTCP2_TRANSPORT_PARAM_DISABLE_ACTIVE_MIGRATION:
       if (decode_varint(&valuelen, &p, end) != 0) {
index 3b91ce948e935234cd9a0be6942d74daadea460e..71f9e350a9efb9fd16c287d8644761b31b93568d 100644 (file)
@@ -64,8 +64,7 @@ typedef enum ngtcp2_transport_param_id {
   /* https://datatracker.ietf.org/doc/html/rfc9221 */
   NGTCP2_TRANSPORT_PARAM_MAX_DATAGRAM_FRAME_SIZE = 0x0020,
   NGTCP2_TRANSPORT_PARAM_GREASE_QUIC_BIT = 0x2ab2,
-  /* https://datatracker.ietf.org/doc/html/draft-ietf-quic-version-negotiation-14
-   */
+  /* https://datatracker.ietf.org/doc/html/rfc9368 */
   NGTCP2_TRANSPORT_PARAM_VERSION_INFORMATION = 0x11,
 } ngtcp2_transport_param_id;
 
index 606302b5780acc712113ec96132e196a80c322ba..06f060c78058538f6049d316cf5d5ee92e8b89a0 100644 (file)
@@ -617,9 +617,9 @@ void ngtcp2_log_remote_tp(ngtcp2_log *log,
                                         sizeof(params->stateless_reset_token)));
   }
 
-  if (params->preferred_address_present) {
-    if (params->preferred_address.ipv4_present) {
-      sa_in = &params->preferred_address.ipv4;
+  if (params->preferred_addr_present) {
+    if (params->preferred_addr.ipv4_present) {
+      sa_in = &params->preferred_addr.ipv4;
 
       log->log_printf(log->user_data,
                       (NGTCP2_LOG_TP " preferred_address.ipv4_addr=%s"),
@@ -631,8 +631,8 @@ void ngtcp2_log_remote_tp(ngtcp2_log *log,
                       NGTCP2_LOG_TP_HD_FIELDS, ngtcp2_ntohs(sa_in->sin_port));
     }
 
-    if (params->preferred_address.ipv6_present) {
-      sa_in6 = &params->preferred_address.ipv6;
+    if (params->preferred_addr.ipv6_present) {
+      sa_in6 = &params->preferred_addr.ipv6;
 
       log->log_printf(log->user_data,
                       (NGTCP2_LOG_TP " preferred_address.ipv6_addr=%s"),
@@ -647,15 +647,15 @@ void ngtcp2_log_remote_tp(ngtcp2_log *log,
     log->log_printf(
         log->user_data, (NGTCP2_LOG_TP " preferred_address.cid=0x%s"),
         NGTCP2_LOG_TP_HD_FIELDS,
-        (const char *)ngtcp2_encode_hex(cid, params->preferred_address.cid.data,
-                                        params->preferred_address.cid.datalen));
+        (const char *)ngtcp2_encode_hex(cid, params->preferred_addr.cid.data,
+                                        params->preferred_addr.cid.datalen));
     log->log_printf(
         log->user_data,
         (NGTCP2_LOG_TP " preferred_address.stateless_reset_token=0x%s"),
         NGTCP2_LOG_TP_HD_FIELDS,
         (const char *)ngtcp2_encode_hex(
-            token, params->preferred_address.stateless_reset_token,
-            sizeof(params->preferred_address.stateless_reset_token)));
+            token, params->preferred_addr.stateless_reset_token,
+            sizeof(params->preferred_addr.stateless_reset_token)));
   }
 
   if (params->original_dcid_present) {
index cd73d2b6f3524821a83923747679d3faf3ae021d..bf69792735185108106b6e51ef5d0764ee0788cf 100644 (file)
 #  include <sys/endian.h>
 #endif /* HAVE_SYS_ENDIAN_H */
 
-#include <ngtcp2/ngtcp2.h>
+#if defined(__APPLE__)
+#  include <libkern/OSByteOrder.h>
+#endif // __APPLE__
 
-#if defined(HAVE_BSWAP_64) ||                                                  \
-    (defined(HAVE_DECL_BSWAP_64) && HAVE_DECL_BSWAP_64 > 0)
-#  define ngtcp2_bswap64 bswap_64
-#else /* !HAVE_BSWAP_64 */
-#  define ngtcp2_bswap64(N)                                                    \
-    ((uint64_t)(ngtcp2_ntohl((uint32_t)(N))) << 32 |                           \
-     ngtcp2_ntohl((uint32_t)((N) >> 32)))
-#endif /* !HAVE_BSWAP_64 */
+#include <ngtcp2/ngtcp2.h>
 
 #if defined(HAVE_BE64TOH) ||                                                   \
     (defined(HAVE_DECL_BE64TOH) && HAVE_DECL_BE64TOH > 0)
 #    define ngtcp2_ntohl64(N) (N)
 #    define ngtcp2_htonl64(N) (N)
 #  else /* !WORDS_BIGENDIAN */
+#    if defined(HAVE_BSWAP_64) ||                                              \
+        (defined(HAVE_DECL_BSWAP_64) && HAVE_DECL_BSWAP_64 > 0)
+#      define ngtcp2_bswap64 bswap_64
+#    elif defined(WIN32)
+#      define ngtcp2_bswap64 _byteswap_uint64
+#    elif defined(__APPLE__)
+#      define ngtcp2_bswap64 OSSwapInt64
+#    else /* !HAVE_BSWAP_64 && !WIN32 && !__APPLE__ */
+#      define ngtcp2_bswap64(N)                                                \
+        ((uint64_t)(ngtcp2_ntohl((uint32_t)(N))) << 32 |                       \
+         ngtcp2_ntohl((uint32_t)((N) >> 32)))
+#    endif /* !HAVE_BSWAP_64 && !WIN32 && !__APPLE__ */
 #    define ngtcp2_ntohl64(N) ngtcp2_bswap64(N)
 #    define ngtcp2_htonl64(N) ngtcp2_bswap64(N)
 #  endif /* !WORDS_BIGENDIAN */
index 7ca63b34f8596a577cfcfd4702b81df3252fb232..29a31d3015ce1f095cad9e0917f644587410f0cf 100644 (file)
@@ -164,8 +164,6 @@ void ngtcp2_pkt_hd_init(ngtcp2_pkt_hd *hd, uint8_t flags, uint8_t type,
   hd->len = len;
 }
 
-static int has_mask(uint8_t b, uint8_t mask) { return (b & mask) == mask; }
-
 ngtcp2_ssize ngtcp2_pkt_decode_hd_long(ngtcp2_pkt_hd *dest, const uint8_t *pkt,
                                        size_t pktlen) {
   uint8_t type;
@@ -542,7 +540,7 @@ ngtcp2_ssize ngtcp2_pkt_decode_frame(ngtcp2_frame *dest, const uint8_t *payload,
     return ngtcp2_pkt_decode_datagram_frame(&dest->datagram, payload,
                                             payloadlen);
   default:
-    if (has_mask(type, NGTCP2_FRAME_STREAM)) {
+    if ((type & ~(NGTCP2_FRAME_STREAM - 1)) == NGTCP2_FRAME_STREAM) {
       return ngtcp2_pkt_decode_stream_frame(&dest->stream, payload, payloadlen);
     }
     return NGTCP2_ERR_FRAME_ENCODING;
diff --git a/src/contrib/libngtcp2/ngtcp2/lib/ngtcp2_pktns_id.h b/src/contrib/libngtcp2/ngtcp2/lib/ngtcp2_pktns_id.h
new file mode 100644 (file)
index 0000000..66b0ee9
--- /dev/null
@@ -0,0 +1,62 @@
+/*
+ * ngtcp2
+ *
+ * Copyright (c) 2023 ngtcp2 contributors
+ *
+ * Permission is hereby granted, free of charge, to any person obtaining
+ * a copy of this software and associated documentation files (the
+ * "Software"), to deal in the Software without restriction, including
+ * without limitation the rights to use, copy, modify, merge, publish,
+ * distribute, sublicense, and/or sell copies of the Software, and to
+ * permit persons to whom the Software is furnished to do so, subject to
+ * the following conditions:
+ *
+ * The above copyright notice and this permission notice shall be
+ * included in all copies or substantial portions of the Software.
+ *
+ * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
+ * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
+ * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
+ * NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
+ * LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
+ * OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
+ * WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
+ */
+#ifndef NGTCP2_PKTNS_ID_H
+#define NGTCP2_PKTNS_ID_H
+
+#ifdef HAVE_CONFIG_H
+#  include <config.h>
+#endif /* HAVE_CONFIG_H */
+
+#include <ngtcp2/ngtcp2.h>
+
+/**
+ * @enum
+ *
+ * :type:`ngtcp2_pktns_id` defines packet number space identifier.
+ */
+typedef enum ngtcp2_pktns_id {
+  /**
+   * :enum:`NGTCP2_PKTNS_ID_INITIAL` is the Initial packet number
+   * space.
+   */
+  NGTCP2_PKTNS_ID_INITIAL,
+  /**
+   * :enum:`NGTCP2_PKTNS_ID_HANDSHAKE` is the Handshake packet number
+   * space.
+   */
+  NGTCP2_PKTNS_ID_HANDSHAKE,
+  /**
+   * :enum:`NGTCP2_PKTNS_ID_APPLICATION` is the Application data
+   * packet number space.
+   */
+  NGTCP2_PKTNS_ID_APPLICATION,
+  /**
+   * :enum:`NGTCP2_PKTNS_ID_MAX` is defined to get the number of
+   * packet number spaces.
+   */
+  NGTCP2_PKTNS_ID_MAX
+} ngtcp2_pktns_id;
+
+#endif /* NGTCP2_PKTNS_ID_H */
index 5fda97b2d382fb1cf9bca187d840559b2faf6bd8..ba7c28044a61c64570c6510fa107f4950bb81a24 100644 (file)
@@ -1000,9 +1000,9 @@ void ngtcp2_qlog_parameters_set_transport_params(
   *p++ = ',';
   p = write_pair_number(p, "initial_max_streams_uni",
                         params->initial_max_streams_uni);
-  if (params->preferred_address_present) {
+  if (params->preferred_addr_present) {
     *p++ = ',';
-    paddr = &params->preferred_address;
+    paddr = &params->preferred_addr;
     p = write_string(p, "preferred_address");
     *p++ = ':';
     *p++ = '{';
index 47a0590400c6015b3bb1d068bd9a53d2b724f503..24efa172b8ef0630cc2543d50a26987c372e6cbd 100644 (file)
@@ -35,6 +35,7 @@
 #include "ngtcp2_ksl.h"
 #include "ngtcp2_pq.h"
 #include "ngtcp2_objalloc.h"
+#include "ngtcp2_pktns_id.h"
 
 typedef struct ngtcp2_conn ngtcp2_conn;
 typedef struct ngtcp2_pktns ngtcp2_pktns;
index ce4909d299e9398e071c359a8335f3a956afee5d..1343249f016de6cbe310af54cf0c1fe1c269218a 100644 (file)
 #  ifdef WIN32
 #    ifndef WIN32_LEAN_AND_MEAN
 #      define WIN32_LEAN_AND_MEAN
-#    endif
+#    endif /* WIN32_LEAN_AND_MEAN */
 #    include <ws2tcpip.h>
-#  else
+#  else /* !WIN32 */
 #    include <sys/socket.h>
 #    include <netinet/in.h>
-#  endif
-#endif
+#  endif /* !WIN32 */
+#endif   /* NGTCP2_USE_GENERIC_SOCKADDR */
 
 #ifdef AF_INET
 #  define NGTCP2_AF_INET AF_INET
-#else
+#else /* !AF_INET */
 #  define NGTCP2_AF_INET 2
-#endif
+#endif /* !AF_INET */
 
 #ifdef AF_INET6
 #  define NGTCP2_AF_INET6 AF_INET6
-#else
+#else /* !AF_INET6 */
 #  define NGTCP2_AF_INET6 23
 #  define NGTCP2_USE_GENERIC_IPV6_SOCKADDR
-#endif
+#endif /* !AF_INET6 */
 
 #include <ngtcp2/version.h>
 
@@ -223,7 +223,8 @@ typedef struct ngtcp2_mem {
 /**
  * @macro
  *
- * :macro:`NGTCP2_SECONDS` is a count of tick which corresponds to 1 second.
+ * :macro:`NGTCP2_SECONDS` is a count of tick which corresponds to 1
+ * second.
  */
 #define NGTCP2_SECONDS ((ngtcp2_duration)1000000000ULL)
 
@@ -267,9 +268,8 @@ typedef struct ngtcp2_mem {
 /**
  * @macro
  *
- * :macro:`NGTCP2_PROTO_VER_V2` is the QUIC version 2.
- *
- * https://quicwg.org/quic-v2/draft-ietf-quic-v2.html
+ * :macro:`NGTCP2_PROTO_VER_V2` is the QUIC version 2.  See
+ * :rfc:`9369`.
  */
 #define NGTCP2_PROTO_VER_V2 ((uint32_t)0x6b3343cfu)
 
@@ -323,7 +323,7 @@ typedef struct ngtcp2_mem {
  * @macro
  *
  * :macro:`NGTCP2_MAX_UDP_PAYLOAD_SIZE` is the default maximum UDP
- * datagram payload size that this endpoint transmits.
+ * datagram payload size that the local endpoint transmits.
  */
 #define NGTCP2_MAX_UDP_PAYLOAD_SIZE 1200
 
@@ -361,7 +361,7 @@ typedef struct ngtcp2_mem {
  * @macro
  *
  * :macro:`NGTCP2_MIN_STATELESS_RESET_RANDLEN` is the minimum length
- * of random bytes (Unpredictable Bits) in Stateless Reset packet
+ * of random bytes (Unpredictable Bits) in Stateless Reset packet.
  */
 #define NGTCP2_MIN_STATELESS_RESET_RANDLEN 5
 
@@ -403,8 +403,8 @@ typedef struct ngtcp2_mem {
 /**
  * @macro
  *
- * :macro:`NGTCP2_RETRY_NONCE_V1` is nonce used when generating integrity
- * tag of Retry packet.  It is used for QUIC v1.
+ * :macro:`NGTCP2_RETRY_NONCE_V1` is nonce used when generating
+ * integrity tag of Retry packet.  It is used for QUIC v1.
  */
 #define NGTCP2_RETRY_NONCE_V1 "\x46\x15\x99\xd3\x5d\x63\x2b\xf2\x23\x98\x25\xbb"
 
@@ -412,9 +412,8 @@ typedef struct ngtcp2_mem {
  * @macro
  *
  * :macro:`NGTCP2_RETRY_KEY_V2` is an encryption key to create
- * integrity tag of Retry packet.  It is used for QUIC v2.
- *
- * https://quicwg.org/quic-v2/draft-ietf-quic-v2.html
+ * integrity tag of Retry packet.  It is used for QUIC v2.  See
+ * :rfc:`9369`.
  */
 #define NGTCP2_RETRY_KEY_V2                                                    \
   "\x8f\xb4\xb0\x1b\x56\xac\x48\xe2\x60\xfb\xcb\xce\xad\x7c\xcc\x92"
@@ -423,9 +422,8 @@ typedef struct ngtcp2_mem {
  * @macro
  *
  * :macro:`NGTCP2_RETRY_NONCE_V2` is nonce used when generating
- * integrity tag of Retry packet.  It is used for QUIC v2.
- *
- * https://quicwg.org/quic-v2/draft-ietf-quic-v2.html
+ * integrity tag of Retry packet.  It is used for QUIC v2.  See
+ * :rfc:`9369`.
  */
 #define NGTCP2_RETRY_NONCE_V2 "\xd8\x69\x69\xbc\x2d\x7c\x6d\x99\x90\xef\xb0\x4a"
 
@@ -525,8 +523,8 @@ typedef struct ngtcp2_mem {
  */
 typedef struct NGTCP2_ALIGN(8) ngtcp2_pkt_info {
   /**
-   * :member:`ecn` is ECN marking and when passing
-   * `ngtcp2_conn_read_pkt()`, and it should be either
+   * :member:`ecn` is ECN marking, and when it is passed to
+   * `ngtcp2_conn_read_pkt()`, it should be either
    * :macro:`NGTCP2_ECN_NOT_ECT`, :macro:`NGTCP2_ECN_ECT_1`,
    * :macro:`NGTCP2_ECN_ECT_0`, or :macro:`NGTCP2_ECN_CE`.
    */
@@ -671,8 +669,8 @@ typedef struct NGTCP2_ALIGN(8) ngtcp2_pkt_info {
 /**
  * @macro
  *
- * :macro:`NGTCP2_ERR_STREAM_NOT_FOUND` indicates that a stream was not
- * found.
+ * :macro:`NGTCP2_ERR_STREAM_NOT_FOUND` indicates that a stream was
+ * not found.
  */
 #define NGTCP2_ERR_STREAM_NOT_FOUND -222
 /**
@@ -882,7 +880,7 @@ typedef enum ngtcp2_pkt_type {
    */
   NGTCP2_PKT_INITIAL = 0x10,
   /**
-   * :enum:`NGTCP2_PKT_0RTT` indicates 0RTT packet.
+   * :enum:`NGTCP2_PKT_0RTT` indicates 0-RTT packet.
    */
   NGTCP2_PKT_0RTT = 0x11,
   /**
@@ -1052,9 +1050,7 @@ typedef enum ngtcp2_pkt_type {
  * @macro
  *
  * :macro:`NGTCP2_VERSION_NEGOTIATION_ERROR` is QUIC transport error
- * code ``VERSION_NEGOTIATION_ERROR``.
- *
- * https://datatracker.ietf.org/doc/html/draft-ietf-quic-version-negotiation-14
+ * code ``VERSION_NEGOTIATION_ERROR``.  See :rfc:`9368`.
  */
 #define NGTCP2_VERSION_NEGOTIATION_ERROR 0x11
 
@@ -1086,7 +1082,8 @@ typedef enum ngtcp2_path_validation_result {
  * @typedef
  *
  * :type:`ngtcp2_tstamp` is a timestamp with nanosecond resolution.
- * ``UINT64_MAX`` is an invalid value.
+ * ``UINT64_MAX`` is an invalid value, and it is often used to
+ * indicate that no value is set.
  */
 typedef uint64_t ngtcp2_tstamp;
 
@@ -1094,7 +1091,8 @@ typedef uint64_t ngtcp2_tstamp;
  * @typedef
  *
  * :type:`ngtcp2_duration` is a period of time in nanosecond
- * resolution.  ``UINT64_MAX`` is an invalid value.
+ * resolution.  ``UINT64_MAX`` is an invalid value, and it is often
+ * used to indicate that no value is set.
  */
 typedef uint64_t ngtcp2_duration;
 
@@ -1169,12 +1167,13 @@ typedef struct ngtcp2_pkt_hd {
    */
   int64_t pkt_num;
   /**
-   * :member:`token` contains token for Initial
-   * packet.
+   * :member:`token` contains token.  Only Initial packet may contain
+   * token.  NULL if no token is present.
    */
   const uint8_t *token;
   /**
-   * :member:`tokenlen` is the length of :member:`token`.
+   * :member:`tokenlen` is the length of :member:`token`.  0 if no
+   * token is present.
    */
   size_t tokenlen;
   /**
@@ -1192,8 +1191,10 @@ typedef struct ngtcp2_pkt_hd {
    */
   uint32_t version;
   /**
-   * :member:`type` is a type of QUIC packet.  See
-   * :type:`ngtcp2_pkt_type`.
+   * :member:`type` is a type of QUIC packet.  This field does not
+   * have a QUIC packet type defined for a specific QUIC version.
+   * Instead, it contains version independent packet type defined by
+   * this library.  See :type:`ngtcp2_pkt_type`.
    */
   uint8_t type;
   /**
@@ -1282,8 +1283,11 @@ typedef struct ngtcp2_pkt_stateless_reset {
 #define NGTCP2_TLSEXT_QUIC_TRANSPORT_PARAMETERS_DRAFT 0xffa5u
 
 #ifdef NGTCP2_USE_GENERIC_SOCKADDR
+typedef unsigned short int ngtcp2_sa_family;
+typedef uint16_t ngtcp2_in_port;
+
 typedef struct ngtcp2_sockaddr {
-  uint16_t sa_family;
+  ngtcp2_sa_family sa_family;
   uint8_t sa_data[14];
 } ngtcp2_sockaddr;
 
@@ -1292,33 +1296,14 @@ typedef struct ngtcp2_in_addr {
 } ngtcp2_in_addr;
 
 typedef struct ngtcp2_sockaddr_in {
-  uint16_t sin_family;
-  uint16_t sin_port;
+  ngtcp2_sa_family sin_family;
+  ngtcp2_in_port sin_port;
   ngtcp2_in_addr sin_addr;
   uint8_t sin_zero[8];
 } ngtcp2_sockaddr_in;
 
-#  define NGTCP2_SS_MAXSIZE 128
-#  define NGTCP2_SS_ALIGNSIZE (sizeof(uint64_t))
-#  define NGTCP2_SS_PAD1SIZE (NGTCP2_SS_ALIGNSIZE - sizeof(uint16_t))
-#  define NGTCP2_SS_PAD2SIZE                                                   \
-    (NGTCP2_SS_MAXSIZE -                                                       \
-     (sizeof(uint16_t) + NGTCP2_SS_PAD1SIZE + NGTCP2_SS_ALIGNSIZE))
-
-typedef struct ngtcp2_sockaddr_storage {
-  uint16_t ss_family;
-  uint8_t _ss_pad1[NGTCP2_SS_PAD1SIZE];
-  uint64_t _ss_align;
-  uint8_t _ss_pad2[NGTCP2_SS_PAD2SIZE];
-} ngtcp2_sockaddr_storage;
-
-#  undef NGTCP2_SS_PAD2SIZE
-#  undef NGTCP2_SS_PAD1SIZE
-#  undef NGTCP2_SS_ALIGNSIZE
-#  undef NGTCP2_SS_MAXSIZE
-
 typedef uint32_t ngtcp2_socklen;
-#else
+#else  /* !NGTCP2_USE_GENERIC_SOCKADDR */
 /**
  * @typedef
  *
@@ -1327,15 +1312,6 @@ typedef uint32_t ngtcp2_socklen;
  * the generic struct sockaddr defined in ngtcp2.h.
  */
 typedef struct sockaddr ngtcp2_sockaddr;
-/**
- * @typedef
- *
- * :type:`ngtcp2_sockaddr_storage` is typedefed to struct
- * sockaddr_storage.  If :macro:`NGTCP2_USE_GENERIC_SOCKADDR` is
- * defined, it is typedefed to the generic struct sockaddr_storage
- * defined in ngtcp2.h.
- */
-typedef struct sockaddr_storage ngtcp2_sockaddr_storage;
 /**
  * @typedef
  *
@@ -1352,7 +1328,7 @@ typedef struct sockaddr_in ngtcp2_sockaddr_in;
  * uint32_t.
  */
 typedef socklen_t ngtcp2_socklen;
-#endif
+#endif /* !NGTCP2_USE_GENERIC_SOCKADDR */
 
 #if defined(NGTCP2_USE_GENERIC_SOCKADDR) ||                                    \
     defined(NGTCP2_USE_GENERIC_IPV6_SOCKADDR)
@@ -1361,13 +1337,14 @@ typedef struct ngtcp2_in6_addr {
 } ngtcp2_in6_addr;
 
 typedef struct ngtcp2_sockaddr_in6 {
-  uint16_t sin6_family;
-  uint16_t sin6_port;
+  ngtcp2_sa_family sin6_family;
+  ngtcp2_in_port sin6_port;
   uint32_t sin6_flowinfo;
   ngtcp2_in6_addr sin6_addr;
   uint32_t sin6_scope_id;
 } ngtcp2_sockaddr_in6;
-#else
+#else  /* !defined(NGTCP2_USE_GENERIC_SOCKADDR) &&                             \
+          !defined(NGTCP2_USE_GENERIC_IPV6_SOCKADDR) */
 /**
  * @typedef
  *
@@ -1376,7 +1353,8 @@ typedef struct ngtcp2_sockaddr_in6 {
  * to the generic struct sockaddr_in6 defined in ngtcp2.h.
  */
 typedef struct sockaddr_in6 ngtcp2_sockaddr_in6;
-#endif
+#endif /* !defined(NGTCP2_USE_GENERIC_SOCKADDR) &&                             \
+          !defined(NGTCP2_USE_GENERIC_IPV6_SOCKADDR) */
 
 /**
  * @struct
@@ -1406,7 +1384,7 @@ typedef struct ngtcp2_preferred_addr {
    */
   ngtcp2_sockaddr_in ipv4;
   /**
-   * :member:`ipv6` contains IPv4 address and port.
+   * :member:`ipv6` contains IPv6 address and port.
    */
   ngtcp2_sockaddr_in6 ipv6;
   /**
@@ -1429,7 +1407,7 @@ typedef struct ngtcp2_preferred_addr {
  * @struct
  *
  * :type:`ngtcp2_version_info` represents version_information
- * structure.
+ * structure.  See :rfc:`9368`.
  */
 typedef struct ngtcp2_version_info {
   /**
@@ -1463,10 +1441,10 @@ typedef struct ngtcp2_version_info {
  */
 typedef struct ngtcp2_transport_params {
   /**
-   * :member:`preferred_address` contains preferred address if
-   * :member:`preferred_address_present` is nonzero.
+   * :member:`preferred_addr` contains preferred address if
+   * :member:`preferred_addr_present` is nonzero.
    */
-  ngtcp2_preferred_addr preferred_address;
+  ngtcp2_preferred_addr preferred_addr;
   /**
    * :member:`original_dcid` is the Destination Connection ID field
    * from the first Initial packet from client.  Server must specify
@@ -1479,41 +1457,42 @@ typedef struct ngtcp2_transport_params {
   ngtcp2_cid original_dcid;
   /**
    * :member:`initial_scid` is the Source Connection ID field from the
-   * first Initial packet the endpoint sends.  Application should not
-   * specify this field.  If :member:`initial_scid_present` is set to
-   * nonzero, it indicates this field is set.
+   * first Initial packet the local endpoint sends.  Application
+   * should not specify this field.  If :member:`initial_scid_present`
+   * is set to nonzero, it indicates this field is set.
    */
   ngtcp2_cid initial_scid;
   /**
    * :member:`retry_scid` is the Source Connection ID field from Retry
    * packet.  Only server uses this field.  If server application
-   * received Initial packet with retry token from client and server
-   * verified its token, server application must set Destination
-   * Connection ID field from the Initial packet to this field and set
-   * :member:`retry_scid_present` to nonzero.  Server application must
-   * verify that the Destination Connection ID from Initial packet was
-   * sent in Retry packet by, for example, including the Connection ID
-   * in a token, or including it in AAD when encrypting a token.
+   * received Initial packet with retry token from client, and server
+   * successfully verified its token, server application must set
+   * Destination Connection ID field from the Initial packet to this
+   * field, and set :member:`retry_scid_present` to nonzero.  Server
+   * application must verify that the Destination Connection ID from
+   * Initial packet was sent in Retry packet by, for example,
+   * including the Connection ID in a token, or including it in AAD
+   * when encrypting a token.
    */
   ngtcp2_cid retry_scid;
   /**
    * :member:`initial_max_stream_data_bidi_local` is the size of flow
    * control window of locally initiated stream.  This is the number
-   * of bytes that the remote endpoint can send and the local endpoint
-   * must ensure that it has enough buffer to receive them.
+   * of bytes that the remote endpoint can send, and the local
+   * endpoint must ensure that it has enough buffer to receive them.
    */
   uint64_t initial_max_stream_data_bidi_local;
   /**
    * :member:`initial_max_stream_data_bidi_remote` is the size of flow
    * control window of remotely initiated stream.  This is the number
-   * of bytes that the remote endpoint can send and the local endpoint
-   * must ensure that it has enough buffer to receive them.
+   * of bytes that the remote endpoint can send, and the local
+   * endpoint must ensure that it has enough buffer to receive them.
    */
   uint64_t initial_max_stream_data_bidi_remote;
   /**
    * :member:`initial_max_stream_data_uni` is the size of flow control
    * window of remotely initiated unidirectional stream.  This is the
-   * number of bytes that the remote endpoint can send and the local
+   * number of bytes that the remote endpoint can send, and the local
    * endpoint must ensure that it has enough buffer to receive them.
    */
   uint64_t initial_max_stream_data_uni;
@@ -1538,8 +1517,8 @@ typedef struct ngtcp2_transport_params {
    */
   ngtcp2_duration max_idle_timeout;
   /**
-   * :member:`max_udp_payload_size` is the maximum datagram size that
-   * the endpoint can receive.
+   * :member:`max_udp_payload_size` is the maximum UDP payload size
+   * that the local endpoint can receive.
    */
   uint64_t max_udp_payload_size;
   /**
@@ -1554,12 +1533,12 @@ typedef struct ngtcp2_transport_params {
   uint64_t ack_delay_exponent;
   /**
    * :member:`max_ack_delay` is the maximum acknowledgement delay by
-   * which the endpoint will delay sending acknowledgements.
+   * which the local endpoint will delay sending acknowledgements.
    */
   ngtcp2_duration max_ack_delay;
   /**
    * :member:`max_datagram_frame_size` is the maximum size of DATAGRAM
-   * frame that this endpoint willingly receives.  Specifying 0
+   * frame that the local endpoint willingly receives.  Specifying 0
    * disables DATAGRAM support.  See :rfc:`9221`.
    */
   uint64_t max_datagram_frame_size;
@@ -1569,8 +1548,8 @@ typedef struct ngtcp2_transport_params {
    */
   uint8_t stateless_reset_token_present;
   /**
-   * :member:`disable_active_migration` is nonzero if the endpoint
-   * does not support active connection migration.
+   * :member:`disable_active_migration` is nonzero if the local
+   * endpoint does not support active connection migration.
    */
   uint8_t disable_active_migration;
   /**
@@ -1589,10 +1568,10 @@ typedef struct ngtcp2_transport_params {
    */
   uint8_t retry_scid_present;
   /**
-   * :member:`preferred_address_present` is nonzero if
+   * :member:`preferred_addr_present` is nonzero if
    * :member:`preferred_address` is set.
    */
-  uint8_t preferred_address_present;
+  uint8_t preferred_addr_present;
   /**
    * :member:`stateless_reset_token` contains stateless reset token.
    */
@@ -1626,34 +1605,6 @@ typedef struct ngtcp2_transport_params {
   uint64_t placeholder_field2;
 } ngtcp2_transport_params;
 
-/**
- * @enum
- *
- * :type:`ngtcp2_pktns_id` defines packet number space identifier.
- */
-typedef enum ngtcp2_pktns_id {
-  /**
-   * :enum:`NGTCP2_PKTNS_ID_INITIAL` is the Initial packet number
-   * space.
-   */
-  NGTCP2_PKTNS_ID_INITIAL,
-  /**
-   * :enum:`NGTCP2_PKTNS_ID_HANDSHAKE` is the Handshake packet number
-   * space.
-   */
-  NGTCP2_PKTNS_ID_HANDSHAKE,
-  /**
-   * :enum:`NGTCP2_PKTNS_ID_APPLICATION` is the Application data
-   * packet number space.
-   */
-  NGTCP2_PKTNS_ID_APPLICATION,
-  /**
-   * :enum:`NGTCP2_PKTNS_ID_MAX` is defined to get the number of
-   * packet number spaces.
-   */
-  NGTCP2_PKTNS_ID_MAX
-} ngtcp2_pktns_id;
-
 #define NGTCP2_CONN_INFO_V1 1
 #define NGTCP2_CONN_INFO_VERSION NGTCP2_CONN_INFO_V1
 
@@ -1777,26 +1728,6 @@ typedef struct ngtcp2_rand_ctx {
 typedef void (*ngtcp2_qlog_write)(void *user_data, uint32_t flags,
                                   const void *data, size_t datalen);
 
-/**
- * @struct
- *
- * :type:`ngtcp2_qlog_settings` is a set of settings for qlog.
- */
-typedef struct ngtcp2_qlog_settings {
-  /**
-   * :member:`odcid` is Original Destination Connection ID sent by
-   * client.  It is used as group_id and ODCID fields.  Client ignores
-   * this field and uses dcid parameter passed to
-   * `ngtcp2_conn_client_new()`.
-   */
-  ngtcp2_cid odcid;
-  /**
-   * :member:`write` is a callback function to write qlog.  Setting
-   * ``NULL`` disables qlog.
-   */
-  ngtcp2_qlog_write write;
-} ngtcp2_qlog_settings;
-
 #define NGTCP2_SETTINGS_V1 1
 #define NGTCP2_SETTINGS_VERSION NGTCP2_SETTINGS_V1
 
@@ -1807,9 +1738,10 @@ typedef struct ngtcp2_qlog_settings {
  */
 typedef struct ngtcp2_settings {
   /**
-   * :member:`qlog` is qlog settings.
+   * :member:`qlog_write` is a callback function to write qlog.
+   * Setting ``NULL`` disables qlog.
    */
-  ngtcp2_qlog_settings qlog;
+  ngtcp2_qlog_write qlog_write;
   /**
    * :member:`cc_algo` specifies congestion control algorithm.
    */
@@ -1831,8 +1763,8 @@ typedef struct ngtcp2_settings {
   ngtcp2_printf log_printf;
   /**
    * :member:`max_tx_udp_payload_size` is the maximum size of UDP
-   * datagram payload that this endpoint transmits.  It is used by
-   * congestion controller to compute congestion window.
+   * datagram payload that the local endpoint transmits.  It is used
+   * by congestion controller to compute congestion window.
    */
   size_t max_tx_udp_payload_size;
   /**
@@ -1846,10 +1778,13 @@ typedef struct ngtcp2_settings {
    *
    * `ngtcp2_conn_server_new` and `ngtcp2_conn_client_new` make a copy
    * of token.
+   *
+   * Set NULL if there is no token.
    */
   const uint8_t *token;
   /**
-   * :member:`tokenlen` is the length of :member:`token`.
+   * :member:`tokenlen` is the length of :member:`token`.  Set 0 if
+   * there is no token.
    */
   size_t tokenlen;
   /**
@@ -1880,16 +1815,17 @@ typedef struct ngtcp2_settings {
   uint64_t max_stream_window;
   /**
    * :member:`ack_thresh` is the minimum number of the received ACK
-   * eliciting packets that triggers the immediate acknowledgement.
+   * eliciting packets that trigger the immediate acknowledgement from
+   * the local endpoint.
    */
   size_t ack_thresh;
   /**
    * :member:`no_tx_udp_payload_size_shaping`, if set to nonzero,
    * instructs the library not to limit the UDP payload size to
    * :macro:`NGTCP2_MAX_UDP_PAYLOAD_SIZE` (which can be extended by
-   * Path MTU Discovery) and instead use the mininum size among the
+   * Path MTU Discovery), and instead use the minimum size among the
    * given buffer size, :member:`max_tx_udp_payload_size`, and the
-   * received max_udp_payload QUIC transport parameter.
+   * received max_udp_payload_size QUIC transport parameter.
    */
   uint8_t no_tx_udp_payload_size_shaping;
   /**
@@ -1914,8 +1850,8 @@ typedef struct ngtcp2_settings {
    * If there is no overlap, but the client chosen version is
    * supported by the library, the server chooses the client chosen
    * version as the negotiated version.  This version set corresponds
-   * to Offered Versions in QUIC Version Negotiation draft, and it
-   * should be included in Version Negotiation packet.
+   * to Offered Versions described in :rfc:`9368`, and it should be
+   * included in Version Negotiation packet.
    *
    * Client uses this field and :member:`original_version` to prevent
    * version downgrade attack if it reacted upon Version Negotiation
@@ -1936,9 +1872,9 @@ typedef struct ngtcp2_settings {
    * <ngtcp2_version_info.available_versions>` field of outgoing
    * version_information QUIC transport parameter.
    *
-   * For server, this corresponds to Fully-Deployed Versions in QUIC
-   * Version Negotiation draft.  If this field is set not, it is set
-   * to :member:`preferred_versions` internally if
+   * For server, this corresponds to Fully-Deployed Versions described
+   * in :rfc:`9368`.  If this field is not set, it is set to
+   * :member:`preferred_versions` internally if
    * :member:`preferred_versionslen` is not zero.  If this field is
    * not set, and :member:`preferred_versionslen` is zero, this field
    * is set to :macro:`NGTCP2_PROTO_VER_V1` internally.
@@ -1984,7 +1920,8 @@ typedef struct ngtcp2_addr {
    */
   ngtcp2_sockaddr *addr;
   /**
-   * :member:`addrlen` is the length of addr.
+   * :member:`addrlen` is the length of :member:`addr`.  It must not
+   * be longer than sizeof(:type:`ngtcp2_sockaddr_union`).
    */
   ngtcp2_socklen addrlen;
 } ngtcp2_addr;
@@ -2011,7 +1948,7 @@ typedef struct ngtcp2_path {
    * Note that :type:`ngtcp2_path` is generally passed to
    * :type:`ngtcp2_conn` by an application, and :type:`ngtcp2_conn`
    * stores their copies.  Unfortunately, there is no way for the
-   * application to know when :type:`ngtcp2_conn` finishes using a
+   * application to know when :type:`ngtcp2_conn` finished using a
    * specific :type:`ngtcp2_path` object in mid connection, which
    * means that the application cannot free the data pointed by this
    * field.  Therefore, it is advised to use this field only when the
@@ -2126,8 +2063,9 @@ typedef struct ngtcp2_crypto_cipher_ctx {
  * :type:`ngtcp2_crypto_ctx` is a convenient structure to bind all
  * crypto related objects in one place.  Use
  * `ngtcp2_crypto_ctx_initial` to initialize this struct for Initial
- * packet encryption.  For Handshake and 1RTT packets, use
- * `ngtcp2_crypto_ctx_tls`.
+ * packet encryption.  For Handshake and 1-RTT packets, use
+ * `ngtcp2_crypto_ctx_tls`.  For 0-RTT packets, use
+ * `ngtcp2_crypto_ctx_tls_early`.
  */
 typedef struct ngtcp2_crypto_ctx {
   /**
@@ -2164,7 +2102,7 @@ typedef struct ngtcp2_crypto_ctx {
  * returns the number of bytes required to store the encoded transport
  * parameters.
  *
- * This function returns the number of written, or one of the
+ * This function returns the number of bytes written, or one of the
  * following negative error codes:
  *
  * :macro:`NGTCP2_ERR_NOBUF`
@@ -2181,8 +2119,7 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_transport_params_encode_versioned(
  * |data| of length |datalen|, and stores the result in the object
  * pointed by |params|.
  *
- * If the optional parameters are missing, the default value is
- * assigned.
+ * If an optional parameter is missing, the default value is assigned.
  *
  * The following fields may point to somewhere inside the buffer
  * pointed by |data| of length |datalen|:
@@ -2293,15 +2230,16 @@ typedef struct ngtcp2_version_cid {
  * QUIC version.
  *
  * If the given packet is Long header packet, this function extracts
- * the version from the packet and assigns it to
+ * the version from the packet, and assigns it to
  * :member:`dest->version <ngtcp2_version_cid.version>`.  It also
  * extracts the pointer to the Destination Connection ID and its
- * length and assigns them to :member:`dest->dcid
+ * length, and assigns them to :member:`dest->dcid
  * <ngtcp2_version_cid.dcid>` and :member:`dest->dcidlen
  * <ngtcp2_version_cid.dcidlen>` respectively.  Similarly, it extracts
- * the pointer to the Source Connection ID and its length and assigns
+ * the pointer to the Source Connection ID and its length, and assigns
  * them to :member:`dest->scid <ngtcp2_version_cid.scid>` and
  * :member:`dest->scidlen <ngtcp2_version_cid.scidlen>` respectively.
+ * |short_dcidlen| is ignored.
  *
  * If the given packet is Short header packet, :member:`dest->version
  * <ngtcp2_version_cid.version>` will be 0, :member:`dest->scid
@@ -2310,7 +2248,7 @@ typedef struct ngtcp2_version_cid {
  * Because the Short header packet does not have the length of
  * Destination Connection ID, the caller has to pass the length in
  * |short_dcidlen|.  This function extracts the pointer to the
- * Destination Connection ID and assigns it to :member:`dest->dcid
+ * Destination Connection ID, and assigns it to :member:`dest->dcid
  * <ngtcp2_version_cid.dcid>`.  |short_dcidlen| is assigned to
  * :member:`dest->dcidlen <ngtcp2_version_cid.dcidlen>`.
  *
@@ -2370,12 +2308,12 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_pkt_decode_hd_long(ngtcp2_pkt_hd *dest,
 /**
  * @function
  *
- * `ngtcp2_pkt_decode_hd_short` decodes QUIC short header packet
- * header in |pkt| of length |pktlen|.  |dcidlen| is the length of
- * DCID in packet header.  Short header packet does not encode the
- * length of connection ID, thus we need the input from the outside.
- * This function only parses the input just before packet number
- * field.  This function can handle Connection ID up to
+ * `ngtcp2_pkt_decode_hd_short` decodes QUIC short header in |pkt| of
+ * length |pktlen|.  Short header packet does not encode the length of
+ * Connection ID, thus we need the input from the outside.  |dcidlen|
+ * is the length of Destination Connection ID in packet header.  This
+ * function only parses the input just before packet number field.
+ * This function can handle Connection ID up to
  * :macro:`NGTCP2_MAX_CIDLEN`.  Consider to use
  * `ngtcp2_pkt_decode_version_cid` to get longer Connection ID.  It
  * stores the result in the object pointed by |dest|, and returns the
@@ -2423,13 +2361,13 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_pkt_write_stateless_reset(
  *
  * `ngtcp2_pkt_write_version_negotiation` writes Version Negotiation
  * packet in the buffer pointed by |dest| whose length is |destlen|.
- * |unused_random| should be generated randomly.  |dcid| is the
- * destination connection ID which appears in a packet as a source
- * connection ID sent by client which caused version negotiation.
- * Similarly, |scid| is the source connection ID which appears in a
- * packet as a destination connection ID sent by client.  |sv| is a
- * list of supported versions, and |nsv| specifies the number of
- * supported versions included in |sv|.
+ * |unused_random| should be generated randomly.  |dcid| is a
+ * Connection ID which appeared in a packet as a Source Connection ID
+ * sent by client which caused version negotiation.  Similarly, |scid|
+ * is a Connection ID which appeared in a packet as a Destination
+ * Connection ID sent by client.  |sv| is a list of supported
+ * versions, and |nsv| specifies the number of supported versions
+ * included in |sv|.
  *
  * This function returns the number of bytes written to the buffer, or
  * one of the following negative error codes:
@@ -2456,7 +2394,7 @@ typedef struct ngtcp2_conn ngtcp2_conn;
  * asks TLS stack to produce first TLS cryptographic handshake data.
  *
  * This implementation of this callback must get the first handshake
- * data from TLS stack and pass it to ngtcp2 library using
+ * data from TLS stack, and pass it to ngtcp2 library using
  * `ngtcp2_conn_submit_crypto_data` function.  Make sure that before
  * calling `ngtcp2_conn_submit_crypto_data` function, client
  * application must create initial packet protection keys and IVs, and
@@ -2476,9 +2414,9 @@ typedef int (*ngtcp2_client_initial)(ngtcp2_conn *conn, void *user_data);
  * Initial packet from client.  An server application must implement
  * this callback, and generate initial keys and IVs for both
  * transmission and reception.  Install them using
- * `ngtcp2_conn_install_initial_key`.  |dcid| is the destination
- * connection ID which client generated randomly.  It is used to
- * derive initial packet protection keys.
+ * `ngtcp2_conn_install_initial_key`.  |dcid| is the Destination
+ * Connection ID in Initial packet received from client.  It is used
+ * to derive initial packet protection keys.
  *
  * The callback function must return 0 if it succeeds.  If an error
  * occurs, return :macro:`NGTCP2_ERR_CALLBACK_FAILURE` which makes the
@@ -2491,45 +2429,42 @@ typedef int (*ngtcp2_recv_client_initial)(ngtcp2_conn *conn,
 /**
  * @enum
  *
- * :type:`ngtcp2_crypto_level` is encryption level.
+ * :type:`ngtcp2_encryption_level` is QUIC encryption level.
  */
-typedef enum ngtcp2_crypto_level {
+typedef enum ngtcp2_encryption_level {
   /**
-   * :enum:`NGTCP2_CRYPTO_LEVEL_INITIAL` is Initial Keys encryption
+   * :enum:`NGTCP2_ENCRYPTION_LEVEL_INITIAL` is Initial encryption
    * level.
    */
-  NGTCP2_CRYPTO_LEVEL_INITIAL,
+  NGTCP2_ENCRYPTION_LEVEL_INITIAL,
   /**
-   * :enum:`NGTCP2_CRYPTO_LEVEL_HANDSHAKE` is Handshake Keys
-   * encryption level.
+   * :enum:`NGTCP2_ENCRYPTION_LEVEL_HANDSHAKE` is Handshake encryption
+   * level.
    */
-  NGTCP2_CRYPTO_LEVEL_HANDSHAKE,
+  NGTCP2_ENCRYPTION_LEVEL_HANDSHAKE,
   /**
-   * :enum:`NGTCP2_CRYPTO_LEVEL_APPLICATION` is Application Data
-   * (1-RTT) Keys encryption level.
+   * :enum:`NGTCP2_ENCRYPTION_LEVEL_1RTT` is 1-RTT encryption level.
    */
-  NGTCP2_CRYPTO_LEVEL_APPLICATION,
+  NGTCP2_ENCRYPTION_LEVEL_1RTT,
   /**
-   * :enum:`NGTCP2_CRYPTO_LEVEL_EARLY` is Early Data (0-RTT) Keys
-   * encryption level.
+   * :enum:`NGTCP2_ENCRYPTION_LEVEL_0RTT` is 0-RTT encryption level.
    */
-  NGTCP2_CRYPTO_LEVEL_EARLY
-} ngtcp2_crypto_level;
+  NGTCP2_ENCRYPTION_LEVEL_0RTT
+} ngtcp2_encryption_level;
 
 /**
  * @functypedef
  *
  * :type`ngtcp2_recv_crypto_data` is invoked when crypto data is
- * received.  The received data is pointed to by |data|, and its
- * length is |datalen|.  The |offset| specifies the offset where
- * |data| is positioned.  |user_data| is the arbitrary pointer passed
- * to `ngtcp2_conn_client_new` or `ngtcp2_conn_server_new`.  The
- * ngtcp2 library ensures that the crypto data is passed to the
- * application in the increasing order of |offset|.  |datalen| is
- * always strictly greater than 0.  |crypto_level| indicates the
- * encryption level where this data is received.  Crypto data can
- * never be received in
- * :enum:`ngtcp2_crypto_level.NGTCP2_CRYPTO_LEVEL_EARLY`.
+ * received.  The received data is pointed by |data|, and its length
+ * is |datalen|.  The |offset| specifies the offset where |data| is
+ * positioned.  |user_data| is the arbitrary pointer passed to
+ * `ngtcp2_conn_client_new` or `ngtcp2_conn_server_new`.  The ngtcp2
+ * library ensures that the crypto data is passed to the application
+ * in the increasing order of |offset|.  |datalen| is always strictly
+ * greater than 0.  |encryption_level| indicates the encryption level
+ * where this data is received.  Crypto data can never be received in
+ * :enum:`ngtcp2_encryption_level.NGTCP2_ENCRYPTION_LEVEL_0RTT`.
  *
  * The application should provide the given data to TLS stack.
  *
@@ -2553,7 +2488,7 @@ typedef enum ngtcp2_crypto_level {
  * return immediately.
  */
 typedef int (*ngtcp2_recv_crypto_data)(ngtcp2_conn *conn,
-                                       ngtcp2_crypto_level crypto_level,
+                                       ngtcp2_encryption_level encryption_level,
                                        uint64_t offset, const uint8_t *data,
                                        size_t datalen, void *user_data);
 
@@ -2607,9 +2542,9 @@ typedef int (*ngtcp2_recv_version_negotiation)(ngtcp2_conn *conn,
  * This callback is client use only.
  *
  * Application must regenerate packet protection key, IV, and header
- * protection key for Initial packets using the destination connection
- * ID obtained by :member:`hd->scid <ngtcp2_pkt_hd.scid>` and install
- * them by calling `ngtcp2_conn_install_initial_key()`.
+ * protection key for Initial packets using the Destination Connection
+ * ID obtained by :member:`hd->scid <ngtcp2_pkt_hd.scid>`, and install
+ * them by calling `ngtcp2_conn_install_initial_key`.
  *
  * 0-RTT data accepted by the ngtcp2 library will be automatically
  * retransmitted as 0-RTT data by the library.
@@ -2628,12 +2563,12 @@ typedef int (*ngtcp2_recv_retry)(ngtcp2_conn *conn, const ngtcp2_pkt_hd *hd,
  * application to encrypt packet payload.  The packet payload to
  * encrypt is passed as |plaintext| of length |plaintextlen|.  The
  * AEAD cipher is |aead|.  |aead_ctx| is the AEAD cipher context
- * object which is initialized with encryption key.  The nonce is
- * passed as |nonce| of length |noncelen|.  The Additional
+ * object which is initialized with the specific encryption key.  The
+ * nonce is passed as |nonce| of length |noncelen|.  The Additional
  * Authenticated Data is passed as |aad| of length |aadlen|.
  *
  * The implementation of this callback must encrypt |plaintext| using
- * the negotiated cipher suite and write the ciphertext into the
+ * the negotiated cipher suite, and write the ciphertext into the
  * buffer pointed by |dest|.  |dest| has enough capacity to store the
  * ciphertext and any additional AEAD tag data.
  *
@@ -2656,12 +2591,12 @@ typedef int (*ngtcp2_encrypt)(uint8_t *dest, const ngtcp2_crypto_aead *aead,
  * application to decrypt packet payload.  The packet payload to
  * decrypt is passed as |ciphertext| of length |ciphertextlen|.  The
  * AEAD cipher is |aead|.  |aead_ctx| is the AEAD cipher context
- * object which is initialized with decryption key.  The nonce is
- * passed as |nonce| of length |noncelen|.  The Additional
+ * object which is initialized with the specific decryption key.  The
+ * nonce is passed as |nonce| of length |noncelen|.  The Additional
  * Authenticated Data is passed as |aad| of length |aadlen|.
  *
  * The implementation of this callback must decrypt |ciphertext| using
- * the negotiated cipher suite and write the ciphertext into the
+ * the negotiated cipher suite, and write the ciphertext into the
  * buffer pointed by |dest|.  |dest| has enough capacity to store the
  * cleartext.
  *
@@ -2684,12 +2619,12 @@ typedef int (*ngtcp2_decrypt)(uint8_t *dest, const ngtcp2_crypto_aead *aead,
  * :type:`ngtcp2_hp_mask` is invoked when the ngtcp2 library asks the
  * application to produce a mask to encrypt or decrypt packet header.
  * The encryption cipher is |hp|.  |hp_ctx| is the cipher context
- * object which is initialized with header protection key.  The sample
- * is passed as |sample| which is :macro:`NGTCP2_HP_SAMPLELEN` bytes
- * long.
+ * object which is initialized with the specific header protection
+ * key.  The sample is passed as |sample| which is
+ * :macro:`NGTCP2_HP_SAMPLELEN` bytes long.
  *
  * The implementation of this callback must produce a mask using the
- * header protection cipher suite specified by QUIC specification and
+ * header protection cipher suite specified by QUIC specification, and
  * write the result into the buffer pointed by |dest|.  The length of
  * the mask must be at least :macro:`NGTCP2_HP_MASKLEN`.  The library
  * only uses the first :macro:`NGTCP2_HP_MASKLEN` bytes of the
@@ -2708,7 +2643,7 @@ typedef int (*ngtcp2_hp_mask)(uint8_t *dest, const ngtcp2_crypto_cipher *hp,
 /**
  * @macrosection
  *
- * Stream data flags
+ * STREAM frame data flags
  */
 
 /**
@@ -2729,11 +2664,11 @@ typedef int (*ngtcp2_hp_mask)(uint8_t *dest, const ngtcp2_crypto_cipher *hp,
 /**
  * @macro
  *
- * :macro:`NGTCP2_STREAM_DATA_FLAG_EARLY` indicates that this chunk of
- * data contains data received in 0RTT packet and the handshake has
+ * :macro:`NGTCP2_STREAM_DATA_FLAG_0RTT` indicates that this chunk of
+ * data contains data received in 0-RTT packet, and the handshake has
  * not completed yet, which means that the data might be replayed.
  */
-#define NGTCP2_STREAM_DATA_FLAG_EARLY 0x02u
+#define NGTCP2_STREAM_DATA_FLAG_0RTT 0x02u
 
 /**
  * @functypedef
@@ -2749,9 +2684,9 @@ typedef int (*ngtcp2_hp_mask)(uint8_t *dest, const ngtcp2_crypto_cipher *hp,
  * overlap.  The data is passed as |data| of length |datalen|.
  * |datalen| may be 0 if and only if |fin| is nonzero.
  *
- * If :macro:`NGTCP2_STREAM_DATA_FLAG_EARLY` is set in |flags|, it
- * indicates that a part of or whole data was received in 0RTT packet
- * and a handshake has not completed yet.
+ * If :macro:`NGTCP2_STREAM_DATA_FLAG_0RTT` is set in |flags|, it
+ * indicates that a part of or whole data was received in 0-RTT
+ * packet, and a handshake has not completed yet.
  *
  * The callback function must return 0 if it succeeds, or
  * :macro:`NGTCP2_ERR_CALLBACK_FAILURE` which makes the library return
@@ -2766,9 +2701,9 @@ typedef int (*ngtcp2_recv_stream_data)(ngtcp2_conn *conn, uint32_t flags,
  * @functypedef
  *
  * :type:`ngtcp2_stream_open` is a callback function which is called
- * when remote stream is opened by peer.  This function is not called
- * if stream is opened by implicitly (we might reconsider this
- * behaviour).
+ * when remote stream is opened by a remote endpoint.  This function
+ * is not called if stream is opened by implicitly (we might
+ * reconsider this behaviour later).
  *
  * The implementation of this callback should return 0 if it succeeds.
  * Returning :macro:`NGTCP2_ERR_CALLBACK_FAILURE` makes the library
@@ -2845,16 +2780,19 @@ typedef int (*ngtcp2_stream_reset)(ngtcp2_conn *conn, int64_t stream_id,
  * @functypedef
  *
  * :type:`ngtcp2_acked_stream_data_offset` is a callback function
- * which is called when stream data is acked, and application can free
- * the data.  The acked range of data is [offset, offset + datalen).
- * For a given stream_id, this callback is called sequentially in
- * increasing order of |offset| without any overlap.  |datalen| is
- * normally strictly greater than 0.  One exception is that when a
- * packet which includes STREAM frame which has fin flag set, and 0
- * length data, this callback is invoked with 0 passed as |datalen|.
- *
- * If a stream is closed prematurely and stream data is still
+ * which is called when stream data in range [|offset|, |offset| +
+ * |datalen|) is acknowledged, and application can free the portion of
+ * data.  For a given |stream_id|, this callback is called
+ * sequentially in increasing order of |offset| without any overlap.
+ * |datalen| is normally strictly greater than 0.  One exception is
+ * that when a STREAM frame has fin flag set and 0 length data, this
+ * callback is invoked with |datalen| == 0.
+ *
+ * If a stream is closed prematurely, and stream data is still
  * in-flight, this callback function is not called for those data.
+ * After :member:`ngtcp2_callbacks.stream_close` is called for a
+ * particular stream, |conn| does not touch data for the closed stream
+ * again, and application can free all unacknowledged stream data.
  *
  * The implementation of this callback should return 0 if it succeeds.
  * Returning :macro:`NGTCP2_ERR_CALLBACK_FAILURE` makes the library
@@ -2900,7 +2838,7 @@ typedef int (*ngtcp2_extend_max_streams)(ngtcp2_conn *conn,
  * :type:`ngtcp2_extend_max_stream_data` is a callback function which
  * is invoked when max stream data is extended.  |stream_id|
  * identifies the stream.  |max_data| is a cumulative number of bytes
- * the endpoint can send on this stream.
+ * an endpoint can send on this stream.
  *
  * The callback function must return 0 if it succeeds.  Returning
  * :macro:`NGTCP2_ERR_CALLBACK_FAILURE` makes the library call return
@@ -2914,10 +2852,10 @@ typedef int (*ngtcp2_extend_max_stream_data)(ngtcp2_conn *conn,
 /**
  * @functypedef
  *
- * :type:`ngtcp2_rand` is a callback function to get randomized byte
- * string from application.  Application must fill random |destlen|
- * bytes to the buffer pointed by |dest|.  The generated bytes are
- * used only in non-cryptographic context.
+ * :type:`ngtcp2_rand` is a callback function to get random data of
+ * length |destlen|.  Application must fill random |destlen| bytes to
+ * the buffer pointed by |dest|.  The generated data is used only in
+ * non-cryptographic context.
  */
 typedef void (*ngtcp2_rand)(uint8_t *dest, size_t destlen,
                             const ngtcp2_rand_ctx *rand_ctx);
@@ -2927,11 +2865,11 @@ typedef void (*ngtcp2_rand)(uint8_t *dest, size_t destlen,
  *
  * :type:`ngtcp2_get_new_connection_id` is a callback function to ask
  * an application for new connection ID.  Application must generate
- * new unused connection ID with the exact |cidlen| bytes and store it
- * in |cid|.  It also has to generate stateless reset token into
- * |token|.  The length of stateless reset token is
+ * new unused connection ID with the exact |cidlen| bytes, and store
+ * it in |cid|.  It also has to generate a stateless reset token, and
+ * store it in |token|.  The length of stateless reset token is
  * :macro:`NGTCP2_STATELESS_RESET_TOKENLEN` and it is guaranteed that
- * the buffer pointed by |cid| has the sufficient space to store the
+ * the buffer pointed by |token| has the sufficient space to store the
  * token.
  *
  * The callback function must return 0 if it succeeds.  Returning
@@ -2947,7 +2885,9 @@ typedef int (*ngtcp2_get_new_connection_id)(ngtcp2_conn *conn, ngtcp2_cid *cid,
  *
  * :type:`ngtcp2_remove_connection_id` is a callback function which
  * notifies the application that connection ID |cid| is no longer used
- * by remote endpoint.
+ * by a remote endpoint.  This Connection ID was previously offered by
+ * a local endpoint, and a remote endpoint could use it as Destination
+ * Connection ID when sending QUIC packet.
  *
  * The callback function must return 0 if it succeeds.  Returning
  * :macro:`NGTCP2_ERR_CALLBACK_FAILURE` makes the library call return
@@ -2967,15 +2907,15 @@ typedef int (*ngtcp2_remove_connection_id)(ngtcp2_conn *conn,
  * |current_tx_secret| of length |secretlen|.  They are decryption and
  * encryption secrets respectively.
  *
- * The application has to generate new secrets and keys for both
- * encryption and decryption, and write decryption secret and IV to
- * the buffer pointed by |rx_secret| and |rx_iv| respectively.  It
- * also has to create new AEAD cipher context object with new
- * decryption key and initialize |rx_aead_ctx| with it.  Similarly,
- * write encryption secret and IV to the buffer pointed by |tx_secret|
- * and |tx_iv|.  Create new AEAD cipher context object with new
- * encryption key and initialize |tx_aead_ctx| with it.  All given
- * buffers have the enough capacity to store secret, key and IV.
+ * The application must generate new secrets and keys for both
+ * encryption and decryption.  It must write decryption secret and IV
+ * to the buffer pointed by |rx_secret| and |rx_iv| respectively.  It
+ * also must create new AEAD cipher context object with new decryption
+ * key and initialize |rx_aead_ctx| with it.  Similarly, write
+ * encryption secret and IV to the buffer pointed by |tx_secret| and
+ * |tx_iv|.  Create new AEAD cipher context object with new encryption
+ * key and initialize |tx_aead_ctx| with it.  All given buffers have
+ * the enough capacity to store secret, key and IV.
  *
  * The callback function must return 0 if it succeeds.  Returning
  * :macro:`NGTCP2_ERR_CALLBACK_FAILURE` makes the library call return
@@ -3014,8 +2954,8 @@ typedef int (*ngtcp2_update_key)(
  * @macro
  *
  * :macro:`NGTCP2_PATH_VALIDATION_FLAG_NEW_TOKEN` indicates that
- * server should send NEW_TOKEN for the new remote address.  This flag
- * is only set for server.
+ * server should send NEW_TOKEN frame for the new remote address.
+ * This flag is only set for server.
  */
 #define NGTCP2_PATH_VALIDATION_FLAG_NEW_TOKEN 0x02u
 
@@ -3023,12 +2963,12 @@ typedef int (*ngtcp2_update_key)(
  * @functypedef
  *
  * :type:`ngtcp2_path_validation` is a callback function which tells
- * the application the outcome of path validation.  |flags| is zero or
+ * an application the outcome of path validation.  |flags| is zero or
  * more of :macro:`NGTCP2_PATH_VALIDATION_FLAG_*
  * <NGTCP2_PATH_VALIDATION_FLAG_NONE>`.  |path| is the path that was
- * validated.  |old_path| is the path that is previsouly used before
- * the endpoint has migrated to |path| if |old_path| is not NULL.  If
- * |res| is
+ * validated.  |old_path| is the path that is previously used before a
+ * local endpoint has migrated to |path| if |old_path| is not NULL.
+ * If |res| is
  * :enum:`ngtcp2_path_validation_result.NGTCP2_PATH_VALIDATION_RESULT_SUCCESS`,
  * the path validation succeeded.  If |res| is
  * :enum:`ngtcp2_path_validation_result.NGTCP2_PATH_VALIDATION_RESULT_FAILURE`,
@@ -3061,10 +3001,10 @@ typedef int (*ngtcp2_path_validation)(ngtcp2_conn *conn, uint32_t flags,
  * from `ngtcp2_conn_get_path()`.  Both :member:`dest->local.addr
  * <ngtcp2_addr.addr>` and :member:`dest->remote.addr
  * <ngtcp2_addr.addr>` point to buffers which are at least
- * ``sizeof(struct sockaddr_storage)`` bytes long, respectively.  If
+ * sizeof(:type:`ngtcp2_sockaddr_union`) bytes long, respectively.  If
  * an application denies the preferred addresses, just leave |dest|
  * unmodified (or set :member:`dest->remote.addrlen
- * <ngtcp2_addr.addrlen>` to 0) and return 0.
+ * <ngtcp2_addr.addrlen>` to 0), and return 0.
  *
  * The callback function must return 0 if it succeeds.  Returning
  * :macro:`NGTCP2_ERR_CALLBACK_FAILURE` makes the library call return
@@ -3084,12 +3024,12 @@ typedef int (*ngtcp2_select_preferred_addr)(ngtcp2_conn *conn,
 typedef enum ngtcp2_connection_id_status_type {
   /**
    * :enum:`NGTCP2_CONNECTION_ID_STATUS_TYPE_ACTIVATE` indicates that
-   * a local endpoint starts using new destination Connection ID.
+   * a local endpoint starts using new Destination Connection ID.
    */
   NGTCP2_CONNECTION_ID_STATUS_TYPE_ACTIVATE,
   /**
    * :enum:`NGTCP2_CONNECTION_ID_STATUS_TYPE_DEACTIVATE` indicates
-   * that a local endpoint stops using a given destination Connection
+   * that a local endpoint stops using a given Destination Connection
    * ID.
    */
   NGTCP2_CONNECTION_ID_STATUS_TYPE_DEACTIVATE
@@ -3099,9 +3039,9 @@ typedef enum ngtcp2_connection_id_status_type {
  * @functypedef
  *
  * :type:`ngtcp2_connection_id_status` is a callback function which is
- * called when the status of Connection ID changes.
+ * called when the status of Destination Connection ID changes.
  *
- * |token| is the associated stateless reset token and it is ``NULL``
+ * |token| is the associated stateless reset token, and it is ``NULL``
  * if no token is present.
  *
  * |type| is the one of the value defined in
@@ -3120,7 +3060,8 @@ typedef int (*ngtcp2_connection_id_status)(
  * @functypedef
  *
  * :type:`ngtcp2_recv_new_token` is a callback function which is
- * called when new token is received from server.
+ * called when new token is received from server.  This callback is
+ * client use only.
  *
  * |token| is the received token of length |tokenlen| bytes long.
  *
@@ -3157,7 +3098,7 @@ typedef void (*ngtcp2_delete_crypto_cipher_ctx)(
 /**
  * @macrosection
  *
- * Datagram flags
+ * DATAGRAM frame flags
  */
 
 /**
@@ -3170,11 +3111,11 @@ typedef void (*ngtcp2_delete_crypto_cipher_ctx)(
 /**
  * @macro
  *
- * :macro:`NGTCP2_DATAGRAM_FLAG_EARLY` indicates that DATAGRAM frame
- * is received in 0RTT packet and the handshake has not completed yet,
+ * :macro:`NGTCP2_DATAGRAM_FLAG_0RTT` indicates that DATAGRAM frame is
+ * received in 0-RTT packet, and the handshake has not completed yet,
  * which means that the data might be replayed.
  */
-#define NGTCP2_DATAGRAM_FLAG_EARLY 0x01u
+#define NGTCP2_DATAGRAM_FLAG_0RTT 0x01u
 
 /**
  * @functypedef
@@ -3183,8 +3124,8 @@ typedef void (*ngtcp2_delete_crypto_cipher_ctx)(
  * received.  |flags| is bitwise-OR of zero or more of
  * :macro:`NGTCP2_DATAGRAM_FLAG_* <NGTCP2_DATAGRAM_FLAG_NONE>`.
  *
- * If :macro:`NGTCP2_DATAGRAM_FLAG_EARLY` is set in |flags|, it
- * indicates that DATAGRAM frame was received in 0RTT packet and a
+ * If :macro:`NGTCP2_DATAGRAM_FLAG_0RTT` is set in |flags|, it
+ * indicates that DATAGRAM frame was received in 0-RTT packet, and a
  * handshake has not completed yet.
  *
  * The callback function must return 0 if it succeeds, or
@@ -3230,8 +3171,8 @@ typedef int (*ngtcp2_lost_datagram)(ngtcp2_conn *conn, uint64_t dgram_id,
  *
  * :type:`ngtcp2_get_path_challenge_data` is a callback function to
  * ask an application for new data that is sent in PATH_CHALLENGE
- * frame.  Application must generate new unpredictable exactly
- * :macro:`NGTCP2_PATH_CHALLENGE_DATALEN` bytes of random data and
+ * frame.  Application must generate new unpredictable, exactly
+ * :macro:`NGTCP2_PATH_CHALLENGE_DATALEN` bytes of random data, and
  * store them into the buffer pointed by |data|.
  *
  * The callback function must return 0 if it succeeds.  Returning
@@ -3269,8 +3210,9 @@ typedef int (*ngtcp2_stream_stop_sending)(ngtcp2_conn *conn, int64_t stream_id,
  * server, it is called once when the version is negotiated.
  *
  * The implementation of this callback must install new Initial keys
- * for |version|.  Use `ngtcp2_conn_install_vneg_initial_key` to
- * install keys.
+ * for |version| and Destination Connection ID |client_dcid| from
+ * client.  Use `ngtcp2_conn_install_vneg_initial_key` to install
+ * keys.
  *
  * The callback function must return 0 if it succeeds.  Returning
  * :macro:`NGTCP2_ERR_CALLBACK_FAILURE` makes the library call return
@@ -3290,20 +3232,22 @@ typedef int (*ngtcp2_version_negotiation)(ngtcp2_conn *conn, uint32_t version,
  * :macro:`NGTCP2_ERR_CALLBACK_FAILURE` makes the library call return
  * immediately.
  */
-typedef int (*ngtcp2_recv_key)(ngtcp2_conn *conn, ngtcp2_crypto_level level,
+typedef int (*ngtcp2_recv_key)(ngtcp2_conn *conn, ngtcp2_encryption_level level,
                                void *user_data);
 
 /**
  * @functypedef
  *
- * :type:`ngtcp2_early_data_rejected` is invoked when early data was
- * rejected by server, or client decided not to attempt early data.
+ * :type:`ngtcp2_tls_early_data_rejected` is invoked when early data
+ * was rejected by server during TLS handshake, or client decided not
+ * to attempt early data.
  *
  * The callback function must return 0 if it succeeds.  Returning
  * :macro:`NGTCP2_ERR_CALLBACK_FAILURE` makes the library call return
  * immediately.
  */
-typedef int (*ngtcp2_early_data_rejected)(ngtcp2_conn *conn, void *user_data);
+typedef int (*ngtcp2_tls_early_data_rejected)(ngtcp2_conn *conn,
+                                              void *user_data);
 
 #define NGTCP2_CALLBACKS_V1 1
 #define NGTCP2_CALLBACKS_VERSION NGTCP2_CALLBACKS_V1
@@ -3323,8 +3267,9 @@ typedef struct ngtcp2_callbacks {
   ngtcp2_client_initial client_initial;
   /**
    * :member:`recv_client_initial` is a callback function which is
-   * invoked when a server receives the first packet from client.
-   * This callback function must be specified for a server application.
+   * invoked when a server receives the first Initial packet from
+   * client.  This callback function must be specified for a server
+   * application.
    */
   ngtcp2_recv_client_initial recv_client_initial;
   /**
@@ -3358,23 +3303,23 @@ typedef struct ngtcp2_callbacks {
   ngtcp2_decrypt decrypt;
   /**
    * :member:`hp_mask` is a callback function which is invoked to get
-   * a mask to encrypt or decrypt packet header.  This callback
+   * a mask to encrypt or decrypt QUIC packet header.  This callback
    * function must be specified.
    */
   ngtcp2_hp_mask hp_mask;
   /**
    * :member:`recv_stream_data` is a callback function which is
-   * invoked when STREAM data, which includes application data, is
+   * invoked when stream data, which includes application data, is
    * received.  This callback function is optional.
    */
   ngtcp2_recv_stream_data recv_stream_data;
   /**
    * :member:`acked_stream_data_offset` is a callback function which
-   * is invoked when STREAM data, which includes application data, is
+   * is invoked when stream data, which includes application data, is
    * acknowledged by a remote endpoint.  It tells an application the
-   * largest offset of acknowledged STREAM data without a gap so that
-   * application can free memory for the data.  This callback function
-   * is optional.
+   * largest offset of acknowledged stream data without a gap so that
+   * application can free memory for the data up to that offset.  This
+   * callback function is optional.
    */
   ngtcp2_acked_stream_data_offset acked_stream_data_offset;
   /**
@@ -3416,8 +3361,8 @@ typedef struct ngtcp2_callbacks {
   ngtcp2_extend_max_streams extend_max_local_streams_uni;
   /**
    * :member:`rand` is a callback function which is invoked when the
-   * library needs sequence of random data.  This callback function
-   * must be specified.
+   * library needs random data.  This callback function must be
+   * specified.
    */
   ngtcp2_rand rand;
   /**
@@ -3435,7 +3380,7 @@ typedef struct ngtcp2_callbacks {
   /**
    * :member:`update_key` is a callback function which is invoked when
    * the library tells an application that it must update keying
-   * materials and install new keys.  This callback function must be
+   * materials, and install new keys.  This callback function must be
    * specified.
    */
   ngtcp2_update_key update_key;
@@ -3448,8 +3393,8 @@ typedef struct ngtcp2_callbacks {
   /**
    * :member:`select_preferred_addr` is a callback function which is
    * invoked when the library asks a client to select preferred
-   * address presented by a server.  This callback function is
-   * optional.
+   * address presented by a server.  If not set, client ignores
+   * preferred addresses.  This callback function is optional.
    */
   ngtcp2_select_preferred_addr select_preferred_addr;
   /**
@@ -3474,24 +3419,24 @@ typedef struct ngtcp2_callbacks {
   ngtcp2_extend_max_streams extend_max_remote_streams_uni;
   /**
    * :member:`extend_max_stream_data` is callback function which is
-   * invoked when the maximum offset of STREAM data that a local
+   * invoked when the maximum offset of stream data that a local
    * endpoint can send is increased.  This callback function is
    * optional.
    */
   ngtcp2_extend_max_stream_data extend_max_stream_data;
   /**
    * :member:`dcid_status` is a callback function which is invoked
-   * when the new destination Connection ID is activated or the
-   * activated destination Connection ID is now deactivated.  This
+   * when the new Destination Connection ID is activated, or the
+   * activated Destination Connection ID is now deactivated.  This
    * callback function is optional.
    */
   ngtcp2_connection_id_status dcid_status;
   /**
    * :member:`handshake_confirmed` is a callback function which is
    * invoked when both endpoints agree that handshake has finished.
-   * This field is ignored by server because handshake_completed
-   * indicates the handshake confirmation for server.  This callback
-   * function is optional.
+   * This field is ignored by server because
+   * :member:`handshake_completed` also indicates the handshake
+   * confirmation for server.  This callback function is optional.
    */
   ngtcp2_handshake_confirmed handshake_confirmed;
   /**
@@ -3520,20 +3465,20 @@ typedef struct ngtcp2_callbacks {
   ngtcp2_recv_datagram recv_datagram;
   /**
    * :member:`ack_datagram` is a callback function which is invoked
-   * when a packet containing DATAGRAM frame is acknowledged.  This
-   * callback function is optional.
+   * when a QUIC packet containing DATAGRAM frame is acknowledged by a
+   * remote endpoint.  This callback function is optional.
    */
   ngtcp2_ack_datagram ack_datagram;
   /**
    * :member:`lost_datagram` is a callback function which is invoked
-   * when a packet containing DATAGRAM frame is declared lost.  This
-   * callback function is optional.
+   * when a QUIC packet containing DATAGRAM frame is declared lost.
+   * This callback function is optional.
    */
   ngtcp2_lost_datagram lost_datagram;
   /**
    * :member:`get_path_challenge_data` is a callback function which is
-   * invoked when the library needs new PATH_CHALLENGE data.  This
-   * callback must be specified.
+   * invoked when the library needs new data sent along with
+   * PATH_CHALLENGE frame.  This callback must be specified.
    */
   ngtcp2_get_path_challenge_data get_path_challenge_data;
   /**
@@ -3553,23 +3498,23 @@ typedef struct ngtcp2_callbacks {
    * :member:`recv_rx_key` is a callback function which is invoked
    * when a new key for decrypting packets is installed during QUIC
    * cryptographic handshake.  It is not called for
-   * :enum:`ngtcp2_crypto_level.NGTCP2_CRYPTO_LEVEL_INITIAL`.
+   * :enum:`ngtcp2_encryption_level.NGTCP2_ENCRYPTION_LEVEL_INITIAL`.
    */
   ngtcp2_recv_key recv_rx_key;
   /**
    * :member:`recv_tx_key` is a callback function which is invoked
    * when a new key for encrypting packets is installed during QUIC
    * cryptographic handshake.  It is not called for
-   * :enum:`ngtcp2_crypto_level.NGTCP2_CRYPTO_LEVEL_INITIAL`.
+   * :enum:`ngtcp2_encryption_level.NGTCP2_ENCRYPTION_LEVEL_INITIAL`.
    */
   ngtcp2_recv_key recv_tx_key;
   /**
-   * :member:`ngtcp2_early_data_rejected` is a callback function which
-   * is invoked when an attempt to send early data by client was
-   * rejected by server, or client decided not to attempt early data.
-   * This callback function is only used by client.
+   * :member:`tls_early_data_rejected` is a callback function which is
+   * invoked when server rejected early data during TLS handshake, or
+   * client decided not to attempt early data.  This callback function
+   * is only used by client.
    */
-  ngtcp2_early_data_rejected early_data_rejected;
+  ngtcp2_tls_early_data_rejected tls_early_data_rejected;
 } ngtcp2_callbacks;
 
 /**
@@ -3583,7 +3528,7 @@ typedef struct ngtcp2_callbacks {
  *
  * The primary use case of this function is for server to send
  * CONNECTION_CLOSE frame in Initial packet to close connection
- * without committing the state when validating Retry token fails.
+ * without committing any state when validating Retry token fails.
  *
  * This function returns the number of bytes written if it succeeds,
  * or one of the following negative error codes:
@@ -3605,11 +3550,11 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_pkt_write_connection_close(
  * @function
  *
  * `ngtcp2_pkt_write_retry` writes Retry packet in the buffer pointed
- * by |dest| whose length is |destlen|.  |dcid| is the destination
- * connection ID which appeared in a packet as a source connection ID
- * sent by client.  |scid| is a server chosen source connection ID.
- * |odcid| specifies Original Destination Connection ID which appeared
- * in a packet as a destination connection ID sent by client.  |token|
+ * by |dest| whose length is |destlen|.  |dcid| is the Connection ID
+ * which appeared in a packet as a Source Connection ID sent by
+ * client.  |scid| is a server chosen Source Connection ID.  |odcid|
+ * specifies Original Destination Connection ID which appeared in a
+ * packet as a Destination Connection ID sent by client.  |token|
  * specifies Retry Token, and |tokenlen| specifies its length.  |aead|
  * must be AEAD_AES_128_GCM.  |aead_ctx| must be initialized with
  * :macro:`NGTCP2_RETRY_KEY` as an encryption key.
@@ -3636,10 +3581,10 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_pkt_write_retry(
  *
  * `ngtcp2_accept` is used by server implementation, and decides
  * whether packet |pkt| of length |pktlen| from client is acceptable
- * for the very initial packet to a connection.
+ * for the very first packet to a connection.
  *
  * If |dest| is not ``NULL`` and the function returns 0, the decoded
- * packet header is stored to the object pointed by |dest|.
+ * packet header is stored in the object pointed by |dest|.
  *
  * This function returns 0 if it succeeds, or one of the following
  * negative error codes:
@@ -3655,17 +3600,21 @@ NGTCP2_EXTERN int ngtcp2_accept(ngtcp2_pkt_hd *dest, const uint8_t *pkt,
  * @function
  *
  * `ngtcp2_conn_client_new` creates new :type:`ngtcp2_conn`, and
- * initializes it as client.  |dcid| is randomized destination
- * connection ID.  |scid| is source connection ID.
- * |client_chosen_version| is a QUIC version that a client chooses.
- * |path| is the network path where this QUIC connection is being
- * established and must not be ``NULL``.  |callbacks|, |settings|, and
- * |params| must not be ``NULL``, and the function make a copy of each
- * of them.  |params| is local QUIC transport parameters and sent to a
- * remote endpoint during handshake.  |user_data| is the arbitrary
- * pointer which is passed to the user-defined callback functions.  If
- * |mem| is ``NULL``, the memory allocator returned by
- * `ngtcp2_mem_default()` is used.
+ * initializes it as client.  On success, it stores the pointer to the
+ * newly allocated object in |*pconn|.  |dcid| is a randomized
+ * Destination Connection ID which must be longer than or equal to
+ * :macro:`NGTCP2_MIN_INITIAL_DCIDLEN`.  |scid| is a Source Connection
+ * ID chosen by client.  |client_chosen_version| is a QUIC version
+ * that a client chooses.  |path| is the network path where this QUIC
+ * connection is being established, and must not be ``NULL``.
+ * |callbacks|, |settings|, and |params| must not be ``NULL``, and the
+ * function makes a copy of each of them.  |params| is a local QUIC
+ * transport parameters, and sent to a remote endpoint during
+ * handshake.  |user_data| is the arbitrary pointer which is passed to
+ * the user-defined callback functions.  If |mem| is ``NULL``, the
+ * memory allocator returned by `ngtcp2_mem_default()` is used.
+ *
+ * Call `ngtcp2_conn_del` to free memory allocated for |*pconn|.
  *
  * This function returns 0 if it succeeds, or one of the following
  * negative error codes:
@@ -3685,16 +3634,22 @@ NGTCP2_EXTERN int ngtcp2_conn_client_new_versioned(
  * @function
  *
  * `ngtcp2_conn_server_new` creates new :type:`ngtcp2_conn`, and
- * initializes it as server.  |dcid| is a destination connection ID.
- * |scid| is a source connection ID.  |path| is the network path where
- * this QUIC connection is being established and must not be ``NULL``.
- * |client_chosen_version| is a QUIC version that a client chooses.
- * |callbacks|, |settings|, and |params| must not be ``NULL``, and the
- * function make a copy of each of them.  |params| is local QUIC
- * transport parameters and sent to a remote endpoint during
- * handshake.  |user_data| is the arbitrary pointer which is passed to
- * the user-defined callback functions.  If |mem| is ``NULL``, the
- * memory allocator returned by `ngtcp2_mem_default()` is used.
+ * initializes it as server.  On success, it stores the pointer to the
+ * newly allocated object in |*pconn|.  |dcid| is a Destination
+ * Connection ID, and is usually the Connection ID that appears in
+ * client Initial packet as Source Connection ID.  |scid| is a Source
+ * Connection ID chosen by server.  |path| is the network path where
+ * this QUIC connection is being established, and must not be
+ * ``NULL``.  |client_chosen_version| is a QUIC version that a client
+ * chooses.  |callbacks|, |settings|, and |params| must not be
+ * ``NULL``, and the function makes a copy of each of them.  |params|
+ * is a local QUIC transport parameters, and sent to a remote endpoint
+ * during handshake.  |user_data| is the arbitrary pointer which is
+ * passed to the user-defined callback functions.  If |mem| is
+ * ``NULL``, the memory allocator returned by `ngtcp2_mem_default()`
+ * is used.
+ *
+ * Call `ngtcp2_conn_del` to free memory allocated for |*pconn|.
  *
  * This function returns 0 if it succeeds, or one of the following
  * negative error codes:
@@ -3732,15 +3687,17 @@ NGTCP2_EXTERN void ngtcp2_conn_del(ngtcp2_conn *conn);
  *
  * This function returns 0 if it succeeds, or negative error codes.
  * If :macro:`NGTCP2_ERR_RETRY` is returned, application must be a
- * server and it must perform address validation by sending Retry
- * packet and discard the connection state.  If
+ * server, and it must perform address validation by sending Retry
+ * packet (see `ngtcp2_crypto_write_retry` and
+ * `ngtcp2_pkt_write_retry`), and discard the connection state.  If
  * :macro:`NGTCP2_ERR_DROP_CONN` is returned, server application must
  * drop the connection silently (without sending any CONNECTION_CLOSE
- * frame) and discard connection state.  If
+ * frame), and discard connection state.  If
  * :macro:`NGTCP2_ERR_DRAINING` is returned, a connection has entered
  * the draining state, and no further packet transmission is allowed.
  * If :macro:`NGTCP2_ERR_CRYPTO` is returned, the error happened in
- * TLS stack and `ngtcp2_conn_get_tls_alert` returns TLS alert if set.
+ * TLS stack, and `ngtcp2_conn_get_tls_alert` returns TLS alert if
+ * set.
  *
  * If any other negative errors are returned, call
  * `ngtcp2_conn_write_connection_close` to get terminal packet, and
@@ -3756,8 +3713,8 @@ ngtcp2_conn_read_pkt_versioned(ngtcp2_conn *conn, const ngtcp2_path *path,
  * @function
  *
  * `ngtcp2_conn_write_pkt` is equivalent to calling
- * `ngtcp2_conn_writev_stream` with -1 as stream_id, no stream data, and
- * :macro:`NGTCP2_WRITE_STREAM_FLAG_NONE` as flags.
+ * `ngtcp2_conn_writev_stream` with -1 as |stream_id|, no stream data,
+ * and :macro:`NGTCP2_WRITE_STREAM_FLAG_NONE` as flags.
  */
 NGTCP2_EXTERN ngtcp2_ssize ngtcp2_conn_write_pkt_versioned(
     ngtcp2_conn *conn, ngtcp2_path *path, int pkt_info_version,
@@ -3776,8 +3733,8 @@ NGTCP2_EXTERN void ngtcp2_conn_tls_handshake_completed(ngtcp2_conn *conn);
 /**
  * @function
  *
- * `ngtcp2_conn_get_handshake_completed` returns nonzero if QUIC handshake
- * has completed.
+ * `ngtcp2_conn_get_handshake_completed` returns nonzero if QUIC
+ * handshake has completed.
  */
 NGTCP2_EXTERN int ngtcp2_conn_get_handshake_completed(ngtcp2_conn *conn);
 
@@ -3786,11 +3743,11 @@ NGTCP2_EXTERN int ngtcp2_conn_get_handshake_completed(ngtcp2_conn *conn);
  *
  * `ngtcp2_conn_install_initial_key` installs packet protection keying
  * materials for Initial packets.  |rx_aead_ctx| is AEAD cipher
- * context object and must be initialized with a decryption key.
+ * context object, and must be initialized with a decryption key.
  * |rx_iv| is IV of length |rx_ivlen| for decryption.  |rx_hp_ctx| is
  * a packet header protection cipher context object for decryption.
  * Similarly, |tx_aead_ctx|, |tx_iv| and |tx_hp_ctx| are for
- * encrypting outgoing packets and are the same length with the
+ * encrypting outgoing packets, and are the same length with the
  * decryption counterpart .  If they have already been set, they are
  * overwritten.
  *
@@ -3799,14 +3756,16 @@ NGTCP2_EXTERN int ngtcp2_conn_get_handshake_completed(ngtcp2_conn *conn);
  *
  * If this function succeeds, |conn| takes ownership of |rx_aead_ctx|,
  * |rx_hp_ctx|, |tx_aead_ctx|, and |tx_hp_ctx|.
- * :type:`ngtcp2_delete_crypto_aead_ctx` and
- * :type:`ngtcp2_delete_crypto_cipher_ctx` will be called to delete
- * these objects when they are no longer used.  If this function
- * fails, the caller is responsible to delete them.
- *
- * After receiving Retry packet, the DCID most likely changes.  In
- * that case, client application must generate these keying materials
- * again based on new DCID and install them again.
+ * :member:`ngtcp2_callbacks.delete_crypto_aead_ctx` and
+ * :member:`ngtcp2_callbacks.delete_crypto_cipher_ctx` will be called
+ * to delete these objects when they are no longer used.  If this
+ * function fails, the caller is responsible to delete them.
+ *
+ * After receiving Retry packet, a Destination Connection ID that
+ * client sends in Initial packet most likely changes.  In that case,
+ * client application must generate these keying materials again based
+ * on new Destination Connection ID, and install them again with this
+ * function.
  *
  * This function returns 0 if it succeeds, or one of the following
  * negative error codes:
@@ -3826,11 +3785,11 @@ NGTCP2_EXTERN int ngtcp2_conn_install_initial_key(
  * `ngtcp2_conn_install_vneg_initial_key` installs packet protection
  * keying materials for Initial packets on compatible version
  * negotiation for |version|.  |rx_aead_ctx| is AEAD cipher context
- * object and must be initialized with a decryption key.  |rx_iv| is
+ * object, and must be initialized with a decryption key.  |rx_iv| is
  * IV of length |rx_ivlen| for decryption.  |rx_hp_ctx| is a packet
  * header protection cipher context object for decryption.  Similarly,
  * |tx_aead_ctx|, |tx_iv| and |tx_hp_ctx| are for encrypting outgoing
- * packets and are the same length with the decryption counterpart .
+ * packets, and are the same length with the decryption counterpart.
  * If they have already been set, they are overwritten.
  *
  * |ivlen| must be the minimum length of AEAD nonce, or 8 bytes if
@@ -3838,10 +3797,10 @@ NGTCP2_EXTERN int ngtcp2_conn_install_initial_key(
  *
  * If this function succeeds, |conn| takes ownership of |rx_aead_ctx|,
  * |rx_hp_ctx|, |tx_aead_ctx|, and |tx_hp_ctx|.
- * :type:`ngtcp2_delete_crypto_aead_ctx` and
- * :type:`ngtcp2_delete_crypto_cipher_ctx` will be called to delete
- * these objects when they are no longer used.  If this function
- * fails, the caller is responsible to delete them.
+ * :member:`ngtcp2_callbacks.delete_crypto_aead_ctx` and
+ * :member:`ngtcp2_callbacks.delete_crypto_cipher_ctx` will be called
+ * to delete these objects when they are no longer used.  If this
+ * function fails, the caller is responsible to delete them.
  *
  * This function returns 0 if it succeeds, or one of the following
  * negative error codes:
@@ -3869,10 +3828,10 @@ NGTCP2_EXTERN int ngtcp2_conn_install_vneg_initial_key(
  * that is larger.
  *
  * If this function succeeds, |conn| takes ownership of |aead_ctx|,
- * and |hp_ctx|.  :type:`ngtcp2_delete_crypto_aead_ctx` and
- * :type:`ngtcp2_delete_crypto_cipher_ctx` will be called to delete
- * these objects when they are no longer used.  If this function
- * fails, the caller is responsible to delete them.
+ * and |hp_ctx|.  :member:`ngtcp2_callbacks.delete_crypto_aead_ctx`
+ * and :member:`ngtcp2_callbacks.delete_crypto_cipher_ctx` will be
+ * called to delete these objects when they are no longer used.  If
+ * this function fails, the caller is responsible to delete them.
  *
  * This function returns 0 if it succeeds, or one of the following
  * negative error codes:
@@ -3897,10 +3856,10 @@ NGTCP2_EXTERN int ngtcp2_conn_install_rx_handshake_key(
  * that is larger.
  *
  * If this function succeeds, |conn| takes ownership of |aead_ctx| and
- * |hp_ctx|.  :type:`ngtcp2_delete_crypto_aead_ctx` and
- * :type:`ngtcp2_delete_crypto_cipher_ctx` will be called to delete
- * these objects when they are no longer used.  If this function
- * fails, the caller is responsible to delete them.
+ * |hp_ctx|.  :member:`ngtcp2_callbacks.delete_crypto_aead_ctx` and
+ * :member:`ngtcp2_callbacks.delete_crypto_cipher_ctx` will be called
+ * to delete these objects when they are no longer used.  If this
+ * function fails, the caller is responsible to delete them.
  *
  * This function returns 0 if it succeeds, or one of the following
  * negative error codes:
@@ -3915,19 +3874,19 @@ NGTCP2_EXTERN int ngtcp2_conn_install_tx_handshake_key(
 /**
  * @function
  *
- * `ngtcp2_conn_install_early_key` installs packet protection AEAD
+ * `ngtcp2_conn_install_0rtt_key` installs packet protection AEAD
  * cipher context object |aead_ctx|, IV |iv| of length |ivlen|, and
  * packet header protection cipher context object |hp_ctx| to encrypt
- * (for client) or decrypt (for server) 0RTT packets.
+ * (for client) or decrypt (for server) 0-RTT packets.
  *
  * |ivlen| must be the minimum length of AEAD nonce, or 8 bytes if
  * that is larger.
  *
  * If this function succeeds, |conn| takes ownership of |aead_ctx| and
- * |hp_ctx|.  :type:`ngtcp2_delete_crypto_aead_ctx` and
- * :type:`ngtcp2_delete_crypto_cipher_ctx` will be called to delete
- * these objects when they are no longer used.  If this function
- * fails, the caller is responsible to delete them.
+ * |hp_ctx|.  :member:`ngtcp2_callbacks.delete_crypto_aead_ctx` and
+ * :member:`ngtcp2_callbacks.delete_crypto_cipher_ctx` will be called
+ * to delete these objects when they are no longer used.  If this
+ * function fails, the caller is responsible to delete them.
  *
  * This function returns 0 if it succeeds, or one of the following
  * negative error codes:
@@ -3935,7 +3894,7 @@ NGTCP2_EXTERN int ngtcp2_conn_install_tx_handshake_key(
  * :macro:`NGTCP2_ERR_NOMEM`
  *     Out of memory.
  */
-NGTCP2_EXTERN int ngtcp2_conn_install_early_key(
+NGTCP2_EXTERN int ngtcp2_conn_install_0rtt_key(
     ngtcp2_conn *conn, const ngtcp2_crypto_aead_ctx *aead_ctx,
     const uint8_t *iv, size_t ivlen, const ngtcp2_crypto_cipher_ctx *hp_ctx);
 
@@ -3943,7 +3902,7 @@ NGTCP2_EXTERN int ngtcp2_conn_install_early_key(
  * @function
  *
  * `ngtcp2_conn_install_rx_key` installs packet protection keying
- * materials for decrypting Short header packets.  |secret| of length
+ * materials for decrypting 1-RTT packets.  |secret| of length
  * |secretlen| is the decryption secret which is used to derive keying
  * materials passed to this function.  |aead_ctx| is AEAD cipher
  * context object which must be initialized with a decryption key.
@@ -3954,10 +3913,10 @@ NGTCP2_EXTERN int ngtcp2_conn_install_early_key(
  * that is larger.
  *
  * If this function succeeds, |conn| takes ownership of |aead_ctx| and
- * |hp_ctx|.  :type:`ngtcp2_delete_crypto_aead_ctx` and
- * :type:`ngtcp2_delete_crypto_cipher_ctx` will be called to delete
- * these objects when they are no longer used.  If this function
- * fails, the caller is responsible to delete them.
+ * |hp_ctx|.  :member:`ngtcp2_callbacks.delete_crypto_aead_ctx` and
+ * :member:`ngtcp2_callbacks.delete_crypto_cipher_ctx` will be called
+ * to delete these objects when they are no longer used.  If this
+ * function fails, the caller is responsible to delete them.
  *
  * This function returns 0 if it succeeds, or one of the following
  * negative error codes:
@@ -3974,7 +3933,7 @@ NGTCP2_EXTERN int ngtcp2_conn_install_rx_key(
  * @function
  *
  * `ngtcp2_conn_install_tx_key` installs packet protection keying
- * materials for encrypting Short header packets.  |secret| of length
+ * materials for encrypting 1-RTT packets.  |secret| of length
  * |secretlen| is the encryption secret which is used to derive keying
  * materials passed to this function.  |aead_ctx| is AEAD cipher
  * context object which must be initialized with an encryption key.
@@ -3985,10 +3944,10 @@ NGTCP2_EXTERN int ngtcp2_conn_install_rx_key(
  * that is larger.
  *
  * If this function succeeds, |conn| takes ownership of |aead_ctx| and
- * |hp_ctx|.  :type:`ngtcp2_delete_crypto_aead_ctx` and
- * :type:`ngtcp2_delete_crypto_cipher_ctx` will be called to delete
- * these objects when they are no longer used.  If this function
- * fails, the caller is responsible to delete them.
+ * |hp_ctx|.  :member:`ngtcp2_callbacks.delete_crypto_aead_ctx` and
+ * :member:`ngtcp2_callbacks.delete_crypto_cipher_ctx` will be called
+ * to delete these objects when they are no longer used.  If this
+ * function fails, the caller is responsible to delete them.
  *
  * This function returns 0 if it succeeds, or one of the following
  * negative error codes:
@@ -4024,10 +3983,12 @@ NGTCP2_EXTERN int ngtcp2_conn_initiate_key_update(ngtcp2_conn *conn,
  * is defined as NGTCP2_ERR_* macro, such as
  * :macro:`NGTCP2_ERR_DECRYPT`).  In general, error code should be
  * propagated via return value, but sometimes ngtcp2 API is called
- * inside callback function of TLS stack and it does not allow to
+ * inside callback function of TLS stack, and it does not allow to
  * return ngtcp2 error code directly.  In this case, implementation
  * can set the error code (e.g.,
  * :macro:`NGTCP2_ERR_MALFORMED_TRANSPORT_PARAM`) using this function.
+ *
+ * See also `ngtcp2_conn_get_tls_error`.
  */
 NGTCP2_EXTERN void ngtcp2_conn_set_tls_error(ngtcp2_conn *conn, int liberr);
 
@@ -4044,7 +4005,9 @@ NGTCP2_EXTERN int ngtcp2_conn_get_tls_error(ngtcp2_conn *conn);
  * @function
  *
  * `ngtcp2_conn_set_tls_alert` sets a TLS alert |alert| generated by a
- * local endpoint to |conn|.
+ * TLS stack of a local endpoint to |conn|.
+ *
+ * See also `ngtcp2_conn_get_tls_alert`.
  */
 NGTCP2_EXTERN void ngtcp2_conn_set_tls_alert(ngtcp2_conn *conn, uint8_t alert);
 
@@ -4063,7 +4026,7 @@ NGTCP2_EXTERN uint8_t ngtcp2_conn_get_tls_alert(ngtcp2_conn *conn);
  * `ngtcp2_conn_set_keep_alive_timeout` sets keep-alive timeout.  If
  * nonzero value is given, after a connection is idle at least in a
  * given amount of time, a keep-alive packet is sent.  If 0 is set,
- * keep-alive functionality is disabled and this is the default.
+ * keep-alive functionality is disabled, and this is the default.
  */
 NGTCP2_EXTERN void ngtcp2_conn_set_keep_alive_timeout(ngtcp2_conn *conn,
                                                       ngtcp2_duration timeout);
@@ -4074,16 +4037,16 @@ NGTCP2_EXTERN void ngtcp2_conn_set_keep_alive_timeout(ngtcp2_conn *conn,
  * `ngtcp2_conn_get_expiry` returns the next expiry time.  It returns
  * ``UINT64_MAX`` if there is no next expiry.
  *
- * Call `ngtcp2_conn_handle_expiry()` and `ngtcp2_conn_write_pkt` (or
- * `ngtcp2_conn_writev_stream`) if expiry time is passed.
+ * Call `ngtcp2_conn_handle_expiry` and then
+ * `ngtcp2_conn_writev_stream` (or `ngtcp2_conn_writev_datagram`) when
+ * the expiry time has passed.
  */
 NGTCP2_EXTERN ngtcp2_tstamp ngtcp2_conn_get_expiry(ngtcp2_conn *conn);
 
 /**
  * @function
  *
- * `ngtcp2_conn_handle_expiry` handles expired timer.  It does nothing
- * if timer is not expired.
+ * `ngtcp2_conn_handle_expiry` handles expired timer.
  */
 NGTCP2_EXTERN int ngtcp2_conn_handle_expiry(ngtcp2_conn *conn,
                                             ngtcp2_tstamp ts);
@@ -4098,9 +4061,9 @@ NGTCP2_EXTERN ngtcp2_duration ngtcp2_conn_get_pto(ngtcp2_conn *conn);
 /**
  * @function
  *
- * `ngtcp2_conn_decode_remote_transport_params` decodes QUIC transport
- * parameters from the buffer pointed by |data| of length |datalen|,
- * and sets the result to |conn|.
+ * `ngtcp2_conn_decode_and_set_remote_transport_params` decodes QUIC
+ * transport parameters from the buffer pointed by |data| of length
+ * |datalen|, and sets the result to |conn|.
  *
  * This function returns 0 if it succeeds, or one of the following
  * negative error codes:
@@ -4116,9 +4079,8 @@ NGTCP2_EXTERN ngtcp2_duration ngtcp2_conn_get_pto(ngtcp2_conn *conn);
  * :macro:`NGTCP2_ERR_CALLBACK_FAILURE`
  *     User callback failed
  */
-NGTCP2_EXTERN int
-ngtcp2_conn_decode_remote_transport_params(ngtcp2_conn *conn,
-                                           const uint8_t *data, size_t datalen);
+NGTCP2_EXTERN int ngtcp2_conn_decode_and_set_remote_transport_params(
+    ngtcp2_conn *conn, const uint8_t *data, size_t datalen);
 
 /**
  * @function
@@ -4133,26 +4095,26 @@ ngtcp2_conn_get_remote_transport_params(ngtcp2_conn *conn);
 /**
  * @function
  *
- * `ngtcp2_conn_encode_early_transport_params` encodes the QUIC
- * transport parameters that are used for early data in the buffer
- * pointed by |dest| of length |destlen|.  The subset includes at
- * least the following fields:
+ * `ngtcp2_conn_encode_0rtt_transport_params` encodes the QUIC
+ * transport parameters that are used for 0-RTT data in the buffer
+ * pointed by |dest| of length |destlen|.  It includes at least the
+ * following fields:
  *
- * - initial_max_stream_id_bidi
- * - initial_max_stream_id_uni
- * - initial_max_stream_data_bidi_local
- * - initial_max_stream_data_bidi_remote
- * - initial_max_stream_data_uni
- * - initial_max_data
- * - active_connection_id_limit
- * - max_datagram_frame_size
+ * - :member:`ngtcp2_transport_params.initial_max_streams_bidi`
+ * - :member:`ngtcp2_transport_params.initial_max_streams_uni`
+ * - :member:`ngtcp2_transport_params.initial_max_stream_data_bidi_local`
+ * - :member:`ngtcp2_transport_params.initial_max_stream_data_bidi_remote`
+ * - :member:`ngtcp2_transport_params.initial_max_stream_data_uni`
+ * - :member:`ngtcp2_transport_params.initial_max_data`
+ * - :member:`ngtcp2_transport_params.active_connection_id_limit`
+ * - :member:`ngtcp2_transport_params.max_datagram_frame_size`
  *
  * If |conn| is initialized as server, the following additional fields
  * are also included:
  *
- * - max_idle_timeout
- * - max_udp_payload_size
- * - disable_active_migration
+ * - :member:`ngtcp2_transport_params.max_idle_timeout`
+ * - :member:`ngtcp2_transport_params.max_udp_payload_size`
+ * - :member:`ngtcp2_transport_params.disable_active_migration`
  *
  * If |conn| is initialized as client, these parameters are
  * synthesized from the remote transport parameters received from
@@ -4166,30 +4128,31 @@ ngtcp2_conn_get_remote_transport_params(ngtcp2_conn *conn);
  *     Buffer is too small.
  */
 NGTCP2_EXTERN
-ngtcp2_ssize ngtcp2_conn_encode_early_transport_params(ngtcp2_conn *conn,
-                                                       uint8_t *dest,
-                                                       size_t destlen);
+ngtcp2_ssize ngtcp2_conn_encode_0rtt_transport_params(ngtcp2_conn *conn,
+                                                      uint8_t *dest,
+                                                      size_t destlen);
 
 /**
  * @function
  *
- * `ngtcp2_conn_decode_early_transport_params` decodes QUIC transport
- * parameters from |data| of length |datalen|, which is assumed to be
- * the parameters received from the server in the previous connection,
- * and sets it to |conn|.  These parameters are used to send early
- * data.  QUIC requires that client application should remember
- * transport parameters along with a session ticket.
- *
- * At least following fields should be set:
- *
- * - initial_max_stream_id_bidi
- * - initial_max_stream_id_uni
- * - initial_max_stream_data_bidi_local
- * - initial_max_stream_data_bidi_remote
- * - initial_max_stream_data_uni
- * - initial_max_data
- * - active_connection_id_limit
- * - max_datagram_frame_size (if DATAGRAM extension was negotiated)
+ * `ngtcp2_conn_decode_and_set_0rtt_transport_params` decodes QUIC
+ * transport parameters from |data| of length |datalen|, which is
+ * assumed to be the parameters received from the server in the
+ * previous connection, and sets it to |conn|.  These parameters are
+ * used to send 0-RTT data.  QUIC requires that client application
+ * should remember transport parameters along with a session ticket.
+ *
+ * At least following fields should be included:
+ *
+ * - :member:`ngtcp2_transport_params.initial_max_streams_bidi`
+ * - :member:`ngtcp2_transport_params.initial_max_streams_uni`
+ * - :member:`ngtcp2_transport_params.initial_max_stream_data_bidi_local`
+ * - :member:`ngtcp2_transport_params.initial_max_stream_data_bidi_remote`
+ * - :member:`ngtcp2_transport_params.initial_max_stream_data_uni`
+ * - :member:`ngtcp2_transport_params.initial_max_data`
+ * - :member:`ngtcp2_transport_params.active_connection_id_limit`
+ * - :member:`ngtcp2_transport_params.max_datagram_frame_size` (if
+ *   DATAGRAM extension was negotiated)
  *
  * This function must only be used by client.
  *
@@ -4201,9 +4164,8 @@ ngtcp2_ssize ngtcp2_conn_encode_early_transport_params(ngtcp2_conn *conn,
  * :macro:`NGTCP2_ERR_MALFORMED_TRANSPORT_PARAM`
  *     The input is malformed.
  */
-NGTCP2_EXTERN int ngtcp2_conn_decode_early_transport_params(ngtcp2_conn *conn,
-                                                            const uint8_t *data,
-                                                            size_t datalen);
+NGTCP2_EXTERN int ngtcp2_conn_decode_and_set_0rtt_transport_params(
+    ngtcp2_conn *conn, const uint8_t *data, size_t datalen);
 
 /**
  * @function
@@ -4213,7 +4175,7 @@ NGTCP2_EXTERN int ngtcp2_conn_decode_early_transport_params(ngtcp2_conn *conn,
  * Although the local transport parameters are passed to
  * `ngtcp2_conn_server_new`, server might want to update them after
  * ALPN is chosen.  In that case, server can update the transport
- * parameter with this function.  Server must call this function
+ * parameters with this function.  Server must call this function
  * before calling `ngtcp2_conn_install_tx_handshake_key`.
  *
  * This function returns 0 if it succeeds, or one of the following
@@ -4241,7 +4203,7 @@ ngtcp2_conn_get_local_transport_params(ngtcp2_conn *conn);
  * `ngtcp2_conn_encode_local_transport_params` encodes the local QUIC
  * transport parameters in |dest| of length |destlen|.
  *
- * This function returns the number of written, or one of the
+ * This function returns the number of bytes written, or one of the
  * following negative error codes:
  *
  * :macro:`NGTCP2_ERR_NOBUF`
@@ -4255,16 +4217,16 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_conn_encode_local_transport_params(
  *
  * `ngtcp2_conn_open_bidi_stream` opens new bidirectional stream.  The
  * |stream_user_data| is the user data specific to the stream.  The
- * open stream ID is stored in |*pstream_id|.
+ * stream ID of the opened stream is stored in |*pstream_id|.
  *
  * Application can call this function before handshake completes.  For
- * 0RTT packet, application can call this function after calling
- * `ngtcp2_conn_decode_early_transport_params`.  For 1RTT packet,
- * application can call this function after calling
- * `ngtcp2_conn_decode_remote_transport_params` and
+ * 0-RTT packet, application can call this function after calling
+ * `ngtcp2_conn_decode_and_set_0rtt_transport_params`.  For 1-RTT
+ * packet, application can call this function after calling
+ * `ngtcp2_conn_decode_and_set_remote_transport_params` and
  * `ngtcp2_conn_install_tx_key`.  If ngtcp2 crypto support library is
  * used, application can call this function after calling
- * `ngtcp2_crypto_derive_and_install_tx_key` for 1RTT packet.
+ * `ngtcp2_crypto_derive_and_install_tx_key` for 1-RTT packet.
  *
  * This function returns 0 if it succeeds, or one of the following
  * negative error codes:
@@ -4272,7 +4234,7 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_conn_encode_local_transport_params(
  * :macro:`NGTCP2_ERR_NOMEM`
  *     Out of memory
  * :macro:`NGTCP2_ERR_STREAM_ID_BLOCKED`
- *     The remote peer does not allow |stream_id| yet.
+ *     The remote endpoint does not allow |stream_id| yet.
  */
 NGTCP2_EXTERN int ngtcp2_conn_open_bidi_stream(ngtcp2_conn *conn,
                                                int64_t *pstream_id,
@@ -4283,16 +4245,16 @@ NGTCP2_EXTERN int ngtcp2_conn_open_bidi_stream(ngtcp2_conn *conn,
  *
  * `ngtcp2_conn_open_uni_stream` opens new unidirectional stream.  The
  * |stream_user_data| is the user data specific to the stream.  The
- * open stream ID is stored in |*pstream_id|.
+ * stream ID of the opened stream is stored in |*pstream_id|.
  *
  * Application can call this function before handshake completes.  For
- * 0RTT packet, application can call this function after calling
- * `ngtcp2_conn_decode_early_transport_params`.  For 1RTT packet,
- * application can call this function after calling
- * `ngtcp2_conn_decode_remote_transport_params` and
+ * 0-RTT packet, application can call this function after calling
+ * `ngtcp2_conn_decode_and_set_0rtt_transport_params`.  For 1-RTT
+ * packet, application can call this function after calling
+ * `ngtcp2_conn_decode_and_set_remote_transport_params` and
  * `ngtcp2_conn_install_tx_key`.  If ngtcp2 crypto support library is
  * used, application can call this function after calling
- * `ngtcp2_crypto_derive_and_install_tx_key` for 1RTT packet.
+ * `ngtcp2_crypto_derive_and_install_tx_key` for 1-RTT packet.
  *
  * This function returns 0 if it succeeds, or one of the following
  * negative error codes:
@@ -4300,7 +4262,7 @@ NGTCP2_EXTERN int ngtcp2_conn_open_bidi_stream(ngtcp2_conn *conn,
  * :macro:`NGTCP2_ERR_NOMEM`
  *     Out of memory
  * :macro:`NGTCP2_ERR_STREAM_ID_BLOCKED`
- *     The remote peer does not allow |stream_id| yet.
+ *     The remote endpoint does not allow |stream_id| yet.
  */
 NGTCP2_EXTERN int ngtcp2_conn_open_uni_stream(ngtcp2_conn *conn,
                                               int64_t *pstream_id,
@@ -4309,12 +4271,12 @@ NGTCP2_EXTERN int ngtcp2_conn_open_uni_stream(ngtcp2_conn *conn,
 /**
  * @function
  *
- * `ngtcp2_conn_shutdown_stream` closes stream denoted by |stream_id|
- * abruptly.  |app_error_code| is one of application error codes, and
- * indicates the reason of shutdown.  Successful call of this function
- * does not immediately erase the state of the stream.  The actual
- * deletion is done when the remote endpoint sends acknowledgement.
- * Calling this function is equivalent to call
+ * `ngtcp2_conn_shutdown_stream` closes a stream denoted by
+ * |stream_id| abruptly.  |app_error_code| is one of application error
+ * codes, and indicates the reason of shutdown.  Successful call of
+ * this function does not immediately erase the state of the stream.
+ * The actual deletion is done when the remote endpoint sends
+ * acknowledgement.  Calling this function is equivalent to call
  * `ngtcp2_conn_shutdown_stream_read`, and
  * `ngtcp2_conn_shutdown_stream_write` sequentially with the following
  * differences.  If |stream_id| refers to a local unidirectional
@@ -4322,25 +4284,29 @@ NGTCP2_EXTERN int ngtcp2_conn_open_uni_stream(ngtcp2_conn *conn,
  * |stream_id| refers to a remote unidirectional stream, this function
  * only shutdowns read side of the stream.
  *
+ * |flags| is currently unused, and should be set to 0.
+ *
  * This function returns 0 if it succeeds, or one of the following
  * negative error codes:
  *
  * :macro:`NGTCP2_ERR_NOMEM`
  *     Out of memory
  */
-NGTCP2_EXTERN int ngtcp2_conn_shutdown_stream(ngtcp2_conn *conn,
+NGTCP2_EXTERN int ngtcp2_conn_shutdown_stream(ngtcp2_conn *conn, uint32_t flags,
                                               int64_t stream_id,
                                               uint64_t app_error_code);
 
 /**
  * @function
  *
- * `ngtcp2_conn_shutdown_stream_write` closes write-side of stream
+ * `ngtcp2_conn_shutdown_stream_write` closes write-side of stream
  * denoted by |stream_id| abruptly.  |app_error_code| is one of
  * application error codes, and indicates the reason of shutdown.  If
- * this function succeeds, no application data is sent to the remote
- * endpoint.  It discards all data which has not been acknowledged
- * yet.
+ * this function succeeds, no further application data is sent to the
+ * remote endpoint.  It discards all data which has not been
+ * acknowledged yet.
+ *
+ * |flags| is currently unused, and should be set to 0.
  *
  * This function returns 0 if it succeeds, or one of the following
  * negative error codes:
@@ -4351,17 +4317,20 @@ NGTCP2_EXTERN int ngtcp2_conn_shutdown_stream(ngtcp2_conn *conn,
  *     |stream_id| refers to a remote unidirectional stream.
  */
 NGTCP2_EXTERN int ngtcp2_conn_shutdown_stream_write(ngtcp2_conn *conn,
+                                                    uint32_t flags,
                                                     int64_t stream_id,
                                                     uint64_t app_error_code);
 
 /**
  * @function
  *
- * `ngtcp2_conn_shutdown_stream_read` closes read-side of stream
+ * `ngtcp2_conn_shutdown_stream_read` closes read-side of stream
  * denoted by |stream_id| abruptly.  |app_error_code| is one of
  * application error codes, and indicates the reason of shutdown.  If
- * this function succeeds, no application data is forwarded to an
- * application layer.
+ * this function succeeds, no further application data is forwarded to
+ * an application layer.
+ *
+ * |flags| is currently unused, and should be set to 0.
  *
  * This function returns 0 if it succeeds, or one of the following
  * negative error codes:
@@ -4372,6 +4341,7 @@ NGTCP2_EXTERN int ngtcp2_conn_shutdown_stream_write(ngtcp2_conn *conn,
  *     |stream_id| refers to a local unidirectional stream.
  */
 NGTCP2_EXTERN int ngtcp2_conn_shutdown_stream_read(ngtcp2_conn *conn,
+                                                   uint32_t flags,
                                                    int64_t stream_id,
                                                    uint64_t app_error_code);
 
@@ -4392,15 +4362,15 @@ NGTCP2_EXTERN int ngtcp2_conn_shutdown_stream_read(ngtcp2_conn *conn,
  * @macro
  *
  * :macro:`NGTCP2_WRITE_STREAM_FLAG_MORE` indicates that more data may
- * come and should be coalesced into the same packet if possible.
+ * come, and should be coalesced into the same packet if possible.
  */
 #define NGTCP2_WRITE_STREAM_FLAG_MORE 0x01u
 
 /**
  * @macro
  *
- * :macro:`NGTCP2_WRITE_STREAM_FLAG_FIN` indicates that the passed
- * data is the final part of a stream.
+ * :macro:`NGTCP2_WRITE_STREAM_FLAG_FIN` indicates that a passed data
+ * is the final part of a stream.
  */
 #define NGTCP2_WRITE_STREAM_FLAG_FIN 0x02u
 
@@ -4421,7 +4391,7 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_conn_write_stream_versioned(
  * @function
  *
  * `ngtcp2_conn_writev_stream` writes a packet containing stream data
- * of stream denoted by |stream_id|.  The buffer of the packet is
+ * of stream denoted by |stream_id|.  The buffer of the packet is
  * pointed by |dest| of length |destlen|.  This function performs QUIC
  * handshake as well.
  *
@@ -4431,10 +4401,11 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_conn_write_stream_versioned(
  * Specifying -1 to |stream_id| means no new stream data to send.
  *
  * If |path| is not ``NULL``, this function stores the network path
- * with which the packet should be sent.  Each addr field must point
- * to the buffer which should be at least ``sizeof(struct
- * sockaddr_storage)`` bytes long.  The assignment might not be done
- * if nothing is written to |dest|.
+ * with which the packet should be sent.  Each addr field
+ * (:member:`ngtcp2_path.local` and :member:`ngtcp2_path.remote`) must
+ * point to the buffer which should be at least
+ * sizeof(:type:`sockaddr_union`) bytes long.  The assignment might
+ * not be done if nothing is written to |dest|.
  *
  * If |pi| is not ``NULL``, this function stores packet metadata in it
  * if it succeeds.  The metadata includes ECN markings.  When calling
@@ -4442,7 +4413,10 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_conn_write_stream_versioned(
  * :macro:`NGTCP2_ERR_WRITE_MORE`, caller must pass the same |pi| to
  * this function.
  *
- * If the all given data is encoded as STREAM frame in |dest|, and if
+ * Stream data is specified as vector of data |datav|.  |datavcnt|
+ * specifies the number of :type:`ngtcp2_vec` that |datav| includes.
+ *
+ * If all given data is encoded as STREAM frame in |dest|, and if
  * |flags| & :macro:`NGTCP2_WRITE_STREAM_FLAG_FIN` is nonzero, fin
  * flag is set to outgoing STREAM frame.  Otherwise, fin flag in
  * STREAM frame is not set.
@@ -4459,24 +4433,23 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_conn_write_stream_versioned(
  * The number of data encoded in STREAM frame is stored in |*pdatalen|
  * if it is not ``NULL``.  The caller must keep the portion of data
  * covered by |*pdatalen| bytes in tact until
- * :type:`ngtcp2_acked_stream_data_offset` indicates that they are
- * acknowledged by a remote endpoint or the stream is closed.
- *
- * If |flags| equals to :macro:`NGTCP2_WRITE_STREAM_FLAG_NONE`, this
- * function produces a single payload of UDP packet.  If the given
- * stream data is small (e.g., few bytes), the packet might be
- * severely under filled.  Too many small packet might increase
- * overall packet processing costs.  Unless there are retransmissions,
- * by default, application can only send 1 STREAM frame in one QUIC
- * packet.  In order to include more than 1 STREAM frame in one QUIC
- * packet, specify :macro:`NGTCP2_WRITE_STREAM_FLAG_MORE` in |flags|.
- * This is analogous to ``MSG_MORE`` flag in :manpage:`send(2)`.  If
- * the :macro:`NGTCP2_WRITE_STREAM_FLAG_MORE` is used, there are 4
+ * :member:`ngtcp2_callbacks.acked_stream_data_offset` indicates that
+ * they are acknowledged by a remote endpoint or the stream is closed.
+ *
+ * If the given stream data is small (e.g., few bytes), the packet
+ * might be severely under filled.  Too many small packet might
+ * increase overall packet processing costs.  Unless there are
+ * retransmissions, by default, application can only send 1 STREAM
+ * frame in one QUIC packet.  In order to include more than 1 STREAM
+ * frame in one QUIC packet, specify
+ * :macro:`NGTCP2_WRITE_STREAM_FLAG_MORE` in |flags|.  This is
+ * analogous to ``MSG_MORE`` flag in :manpage:`send(2)`.  If the
+ * :macro:`NGTCP2_WRITE_STREAM_FLAG_MORE` is used, there are 4
  * outcomes:
  *
  * - The function returns the written length of packet just like
  *   without :macro:`NGTCP2_WRITE_STREAM_FLAG_MORE`.  This is because
- *   packet is nearly full and the library decided to make a complete
+ *   packet is nearly full, and the library decided to make a complete
  *   packet.  |*pdatalen| might be -1 or >= 0.  It may return 0 which
  *   indicates that no packet transmission is possible at the moment
  *   for some reason.
@@ -4492,7 +4465,7 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_conn_write_stream_versioned(
  *
  * - The function returns one of the following negative error codes:
  *   :macro:`NGTCP2_ERR_STREAM_DATA_BLOCKED`,
- *   :macro:`NGTCP2_ERR_STREAM_NOT_FOUND`,
+ *   :macro:`NGTCP2_ERR_STREAM_NOT_FOUND`, or
  *   :macro:`NGTCP2_ERR_STREAM_SHUT_WR`.  In this case, |*pdatalen| ==
  *   -1 is asserted.  Application can still write the stream data of
  *   the other streams by calling this function (or
@@ -4510,10 +4483,9 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_conn_write_stream_versioned(
  * least once, it must not call other ngtcp2 API functions
  * (application can still call `ngtcp2_conn_write_connection_close` to
  * handle error from this function), just keep calling this function
- * (or `ngtcp2_conn_write_pkt`, or `ngtcp2_conn_writev_datagram`)
- * until it returns 0, a positive number (which indicates a complete
- * packet is ready), or the error codes other than
- * :macro:`NGTCP2_ERR_WRITE_MORE`,
+ * (or `ngtcp2_conn_writev_datagram`) until it returns 0, a positive
+ * number (which indicates a complete packet is ready), or the error
+ * codes other than :macro:`NGTCP2_ERR_WRITE_MORE`,
  * :macro:`NGTCP2_ERR_STREAM_DATA_BLOCKED`,
  * :macro:`NGTCP2_ERR_STREAM_NOT_FOUND`, and
  * :macro:`NGTCP2_ERR_STREAM_SHUT_WR`.  If there is no stream data to
@@ -4556,7 +4528,7 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_conn_write_stream_versioned(
  * In general, if the error code which satisfies
  * `ngtcp2_err_is_fatal(err) <ngtcp2_err_is_fatal>` != 0 is returned,
  * the application should just close the connection by calling
- * `ngtcp2_conn_write_connection_close` or just delete the QUIC
+ * `ngtcp2_conn_write_connection_close`, or just delete the QUIC
  * connection using `ngtcp2_conn_del`.  It is undefined to call the
  * other library functions.
  */
@@ -4583,7 +4555,7 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_conn_writev_stream_versioned(
  * @macro
  *
  * :macro:`NGTCP2_WRITE_DATAGRAM_FLAG_MORE` indicates that more data
- * may come and should be coalesced into the same packet if possible.
+ * may come, and should be coalesced into the same packet if possible.
  */
 #define NGTCP2_WRITE_DATAGRAM_FLAG_MORE 0x01u
 
@@ -4601,20 +4573,23 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_conn_writev_stream_versioned(
  * For |path| and |pi| parameters, refer to
  * `ngtcp2_conn_writev_stream`.
  *
+ * Stream data is specified as vector of data |datav|.  |datavcnt|
+ * specifies the number of :type:`ngtcp2_vec` that |datav| includes.
+ *
  * If the given data is written to the buffer, nonzero value is
  * assigned to |*paccepted| if it is not NULL.  The data in DATAGRAM
  * frame cannot be fragmented; writing partial data is not possible.
  *
  * |dgram_id| is an opaque identifier which should uniquely identify
- * the given DATAGRAM.  It is passed to :type:`ngtcp2_ack_datagram`
- * callback when a packet that contains DATAGRAM frame is
- * acknowledged.  It is passed to :type:`ngtcp2_lost_datagram`
- * callback when a packet that contains DATAGRAM frame is declared
- * lost.  If an application uses neither of those callbacks, it can
- * sets 0 to this parameter.
+ * the given DATAGRAM data.  It is passed to
+ * :member:`ngtcp2_callbacks.ack_datagram` callback when a packet that
+ * contains DATAGRAM frame is acknowledged.  It is also passed to
+ * :member:`ngtcp2_callbacks.lost_datagram` callback when a packet
+ * that contains DATAGRAM frame is declared lost.  If an application
+ * uses neither of those callbacks, it can sets 0 to this parameter.
  *
- * This function might write other frames other than DATAGRAM, just
- * like `ngtcp2_conn_writev_stream`.
+ * This function might write other frames other than DATAGRAM frame,
+ * just like `ngtcp2_conn_writev_stream`.
  *
  * If the function returns 0, it means that no more data cannot be
  * sent because of congestion control limit; or, data does not fit
@@ -4645,10 +4620,9 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_conn_writev_stream_versioned(
  * When application sees :macro:`NGTCP2_ERR_WRITE_MORE`, it must not
  * call other ngtcp2 API functions (application can still call
  * `ngtcp2_conn_write_connection_close` to handle error from this
- * function).  Just keep calling `ngtcp2_conn_writev_datagram`,
- * `ngtcp2_conn_writev_stream` or `ngtcp2_conn_write_pkt` until it
- * returns a positive number (which indicates a complete packet is
- * ready).
+ * function).  Just keep calling this function (or
+ * `ngtcp2_conn_writev_stream`) until it returns a positive number
+ * (which indicates a complete packet is ready).
  *
  * This function returns the number of bytes written in |dest| if it
  * succeeds, or one of the following negative error codes:
@@ -4672,7 +4646,7 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_conn_writev_stream_versioned(
  * In general, if the error code which satisfies
  * `ngtcp2_err_is_fatal(err) <ngtcp2_err_is_fatal>` != 0 is returned,
  * the application should just close the connection by calling
- * `ngtcp2_conn_write_connection_close` or just delete the QUIC
+ * `ngtcp2_conn_write_connection_close`, or just delete the QUIC
  * connection using `ngtcp2_conn_del`.  It is undefined to call the
  * other library functions.
  */
@@ -4685,30 +4659,34 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_conn_writev_datagram_versioned(
 /**
  * @function
  *
- * `ngtcp2_conn_is_in_closing_period` returns nonzero if |conn| is in
- * the closing period.
+ * `ngtcp2_conn_in_closing_period` returns nonzero if |conn| is in the
+ * closing period.
  */
-NGTCP2_EXTERN int ngtcp2_conn_is_in_closing_period(ngtcp2_conn *conn);
+NGTCP2_EXTERN int ngtcp2_conn_in_closing_period(ngtcp2_conn *conn);
 
 /**
  * @function
  *
- * `ngtcp2_conn_is_in_draining_period` returns nonzero if |conn| is in
+ * `ngtcp2_conn_in_draining_period` returns nonzero if |conn| is in
  * the draining period.
  */
-NGTCP2_EXTERN int ngtcp2_conn_is_in_draining_period(ngtcp2_conn *conn);
+NGTCP2_EXTERN int ngtcp2_conn_in_draining_period(ngtcp2_conn *conn);
 
 /**
  * @function
  *
- * `ngtcp2_conn_extend_max_stream_offset` extends stream's max stream
- * data value by |datalen|.
+ * `ngtcp2_conn_extend_max_stream_offset` extends the maximum stream
+ * data that a remote endpoint can send by |datalen|.  |stream_id|
+ * specifies the stream ID.  This function only extends stream-level
+ * flow control window.
  *
  * This function returns 0 if it succeeds, or one of the following
  * negative error codes:
  *
  * :macro:`NGTCP2_ERR_NOMEM`
  *     Out of memory.
+ * :macro:`NGTCP2_ERR_INVALID_ARGUMENT`
+ *     |stream_id| refers to a local unidirectional stream.
  */
 NGTCP2_EXTERN int ngtcp2_conn_extend_max_stream_offset(ngtcp2_conn *conn,
                                                        int64_t stream_id,
@@ -4718,7 +4696,8 @@ NGTCP2_EXTERN int ngtcp2_conn_extend_max_stream_offset(ngtcp2_conn *conn,
  * @function
  *
  * `ngtcp2_conn_extend_max_offset` extends max data offset by
- * |datalen|.
+ * |datalen|.  This function only extends connection-level flow
+ * control window.
  */
 NGTCP2_EXTERN void ngtcp2_conn_extend_max_offset(ngtcp2_conn *conn,
                                                  uint64_t datalen);
@@ -4727,12 +4706,13 @@ NGTCP2_EXTERN void ngtcp2_conn_extend_max_offset(ngtcp2_conn *conn,
  * @function
  *
  * `ngtcp2_conn_extend_max_streams_bidi` extends the number of maximum
- * local bidirectional streams that a remote endpoint can open by |n|.
+ * remote bidirectional streams that a remote endpoint can open by
+ * |n|.
  *
  * The library does not increase maximum stream limit automatically.
  * The exception is when a stream is closed without
- * :type:`ngtcp2_stream_open` callback being called.  In this case,
- * stream limit is increased automatically.
+ * :member:`ngtcp2_callbacks.stream_open` callback being called.  In
+ * this case, stream limit is increased automatically.
  */
 NGTCP2_EXTERN void ngtcp2_conn_extend_max_streams_bidi(ngtcp2_conn *conn,
                                                        size_t n);
@@ -4741,13 +4721,13 @@ NGTCP2_EXTERN void ngtcp2_conn_extend_max_streams_bidi(ngtcp2_conn *conn,
  * @function
  *
  * `ngtcp2_conn_extend_max_streams_uni` extends the number of maximum
- * local unidirectional streams that a remote endpoint can open by
+ * remote unidirectional streams that a remote endpoint can open by
  * |n|.
  *
  * The library does not increase maximum stream limit automatically.
  * The exception is when a stream is closed without
- * :type:`ngtcp2_stream_open` callback being called.  In this case,
- * stream limit is increased automatically.
+ * :member:`ngtcp2_callbacks.stream_open` callback being called.  In
+ * this case, stream limit is increased automatically.
  */
 NGTCP2_EXTERN void ngtcp2_conn_extend_max_streams_uni(ngtcp2_conn *conn,
                                                       size_t n);
@@ -4755,9 +4735,10 @@ NGTCP2_EXTERN void ngtcp2_conn_extend_max_streams_uni(ngtcp2_conn *conn,
 /**
  * @function
  *
- * `ngtcp2_conn_get_dcid` returns the non-NULL pointer to destination
- * connection ID.  If no destination connection ID is present, the
- * return value is not ``NULL``, and its datalen field is 0.
+ * `ngtcp2_conn_get_dcid` returns the non-NULL pointer to the current
+ * Destination Connection ID.  If no Destination Connection ID is
+ * present, the return value is not ``NULL``, and its :member:`datalen
+ * <ngtcp2_cid.datalen>` field is 0.
  */
 NGTCP2_EXTERN const ngtcp2_cid *ngtcp2_conn_get_dcid(ngtcp2_conn *conn);
 
@@ -4766,7 +4747,9 @@ NGTCP2_EXTERN const ngtcp2_cid *ngtcp2_conn_get_dcid(ngtcp2_conn *conn);
  *
  * `ngtcp2_conn_get_client_initial_dcid` returns the non-NULL pointer
  * to the Destination Connection ID that client sent in its Initial
- * packet.
+ * packet.  If the Destination Connection ID is not present, the
+ * return value is not ``NULL``, and its :member:`datalen
+ * <ngtcp2_cid.datalen>` field is 0.
  */
 NGTCP2_EXTERN const ngtcp2_cid *
 ngtcp2_conn_get_client_initial_dcid(ngtcp2_conn *conn);
@@ -4774,20 +4757,20 @@ ngtcp2_conn_get_client_initial_dcid(ngtcp2_conn *conn);
 /**
  * @function
  *
- * `ngtcp2_conn_get_num_scid` returns the number of source connection
- * IDs which the local endpoint has provided to the peer and have not
- * retired.
+ * `ngtcp2_conn_get_num_scid` returns the number of Source Connection
+ * IDs which a local endpoint has provided to a remote endpoint, and
+ * are not retired.
  */
 NGTCP2_EXTERN size_t ngtcp2_conn_get_num_scid(ngtcp2_conn *conn);
 
 /**
  * @function
  *
- * `ngtcp2_conn_get_scid` writes the all source connection IDs which
- * the local endpoint has provided to the peer and have not retired in
- * |dest|.  The buffer pointed by |dest| must have
- * ``sizeof(ngtcp2_cid) * n`` bytes available, where n is the return
- * value of `ngtcp2_conn_get_num_scid()`.
+ * `ngtcp2_conn_get_scid` writes the all Source Connection IDs which a
+ * local endpoint has provided to a remote endpoint, and are not
+ * retired in |dest|.  The buffer pointed by |dest| must have
+ * sizeof(:type:`ngtcp2_cid`) * n bytes available, where n is the
+ * return value of `ngtcp2_conn_get_num_scid`.
  */
 NGTCP2_EXTERN size_t ngtcp2_conn_get_scid(ngtcp2_conn *conn, ngtcp2_cid *dest);
 
@@ -4795,7 +4778,7 @@ NGTCP2_EXTERN size_t ngtcp2_conn_get_scid(ngtcp2_conn *conn, ngtcp2_cid *dest);
  * @function
  *
  * `ngtcp2_conn_get_num_active_dcid` returns the number of the active
- * destination connection ID.
+ * Destination Connection ID.
  */
 NGTCP2_EXTERN size_t ngtcp2_conn_get_num_active_dcid(ngtcp2_conn *conn);
 
@@ -4815,8 +4798,8 @@ typedef struct ngtcp2_cid_token {
    */
   ngtcp2_cid cid;
   /**
-   * :member:`ps` is the path which is associated to this Connection
-   * ID.
+   * :member:`ps` is the path which this Connection ID is associated
+   * with.
    */
   ngtcp2_path_storage ps;
   /**
@@ -4834,10 +4817,11 @@ typedef struct ngtcp2_cid_token {
 /**
  * @function
  *
- * `ngtcp2_conn_get_active_dcid` writes the all active destination
- * connection IDs and tokens to |dest|.  The buffer pointed by |dest|
- * must have ``sizeof(ngtcp2_cid_token) * n`` bytes available, where n
- * is the return value of `ngtcp2_conn_get_num_active_dcid()`.
+ * `ngtcp2_conn_get_active_dcid` writes the all active Destination
+ * Connection IDs and their tokens to |dest|.  The buffer pointed by
+ * |dest| must have sizeof(:type:`ngtcp2_cid_token`) * n bytes
+ * available, where n is the return value of
+ * `ngtcp2_conn_get_num_active_dcid`.
  */
 NGTCP2_EXTERN size_t ngtcp2_conn_get_active_dcid(ngtcp2_conn *conn,
                                                  ngtcp2_cid_token *dest);
@@ -4853,7 +4837,8 @@ NGTCP2_EXTERN uint32_t ngtcp2_conn_get_client_chosen_version(ngtcp2_conn *conn);
 /**
  * @function
  *
- * `ngtcp2_conn_get_negotiated_version` returns the negotiated version.
+ * `ngtcp2_conn_get_negotiated_version` returns the negotiated
+ * version.
  *
  * Until the version is negotiated, this function returns 0.
  */
@@ -4862,18 +4847,19 @@ NGTCP2_EXTERN uint32_t ngtcp2_conn_get_negotiated_version(ngtcp2_conn *conn);
 /**
  * @function
  *
- * `ngtcp2_conn_early_data_rejected` tells |conn| that early data was
- * rejected by a server, or client decided not to attempt early data
- * for some reason.  |conn| discards the following connection states:
+ * `ngtcp2_conn_tls_early_data_rejected` tells |conn| that early data
+ * was rejected by a server during TLS handshake, or client decided
+ * not to attempt early data for some reason.  |conn| discards the
+ * following connection states:
  *
- * - Any opended streams.
+ * - Any opened streams.
  * - Stream identifier allocations.
  * - Max data extended by `ngtcp2_conn_extend_max_offset`.
  * - Max bidi streams extended by `ngtcp2_conn_extend_max_streams_bidi`.
  * - Max uni streams extended by `ngtcp2_conn_extend_max_streams_uni`.
  *
  * Application which wishes to retransmit early data, it has to open
- * streams and send stream data again.
+ * streams, and send stream data again.
  *
  * This function returns 0 if it succeeds, or one of the following
  * negative error codes:
@@ -4881,15 +4867,15 @@ NGTCP2_EXTERN uint32_t ngtcp2_conn_get_negotiated_version(ngtcp2_conn *conn);
  * :macro:`NGTCP2_ERR_CALLBACK_FAILURE`
  *     User callback failed
  */
-NGTCP2_EXTERN int ngtcp2_conn_early_data_rejected(ngtcp2_conn *conn);
+NGTCP2_EXTERN int ngtcp2_conn_tls_early_data_rejected(ngtcp2_conn *conn);
 
 /**
  * @function
  *
- * `ngtcp2_conn_get_early_data_rejected` returns nonzero if
- * `ngtcp2_conn_early_data_rejected` has been called.
+ * `ngtcp2_conn_get_tls_early_data_rejected` returns nonzero if
+ * `ngtcp2_conn_tls_early_data_rejected` has been called.
  */
-NGTCP2_EXTERN int ngtcp2_conn_get_early_data_rejected(ngtcp2_conn *conn);
+NGTCP2_EXTERN int ngtcp2_conn_get_tls_early_data_rejected(ngtcp2_conn *conn);
 
 /**
  * @function
@@ -4904,16 +4890,16 @@ NGTCP2_EXTERN void ngtcp2_conn_get_conn_info_versioned(ngtcp2_conn *conn,
 /**
  * @function
  *
- * `ngtcp2_conn_submit_crypto_data` submits crypto stream data |data|
- * of length |datalen| to the library for transmission.  The
- * encryption level is given in |crypto_level|.
+ * `ngtcp2_conn_submit_crypto_data` submits crypto data |data| of
+ * length |datalen| to the library for transmission.
+ * |encryption_level| specifies the encryption level of data.
  *
  * The library makes a copy of the buffer pointed by |data| of length
  * |datalen|.  Application can discard |data|.
  */
 NGTCP2_EXTERN int
 ngtcp2_conn_submit_crypto_data(ngtcp2_conn *conn,
-                               ngtcp2_crypto_level crypto_level,
+                               ngtcp2_encryption_level encryption_level,
                                const uint8_t *data, const size_t datalen);
 
 /**
@@ -5003,7 +4989,8 @@ ngtcp2_conn_get_path_max_tx_udp_payload_size(ngtcp2_conn *conn);
  * :macro:`NGTCP2_ERR_CONN_ID_BLOCKED`
  *     No unused connection ID is available.
  * :macro:`NGTCP2_ERR_INVALID_ARGUMENT`
- *     |local_addr| equals the current local address.
+ *     :member:`local <ngtcp2_path.local>` field of |path| equals the
+ *     current local address.
  * :macro:`NGTCP2_ERR_NOMEM`
  *     Out of memory
  */
@@ -5016,7 +5003,7 @@ NGTCP2_EXTERN int ngtcp2_conn_initiate_immediate_migration(
  * `ngtcp2_conn_initiate_migration` starts connection migration to the
  * given |path|.  Only client can initiate migration.  Unlike
  * `ngtcp2_conn_initiate_immediate_migration`, this function starts a
- * path validation with a new path and migrate to the new path after
+ * path validation with a new path, and migrate to the new path after
  * successful path validation.
  *
  * This function returns 0 if it succeeds, or one of the following
@@ -5028,7 +5015,8 @@ NGTCP2_EXTERN int ngtcp2_conn_initiate_immediate_migration(
  * :macro:`NGTCP2_ERR_CONN_ID_BLOCKED`
  *     No unused connection ID is available.
  * :macro:`NGTCP2_ERR_INVALID_ARGUMENT`
- *     |local_addr| equals the current local address.
+ *     :member:`local <ngtcp2_path.local>` field of |path| equals the
+ *     current local address.
  * :macro:`NGTCP2_ERR_NOMEM`
  *     Out of memory
  */
@@ -5040,7 +5028,8 @@ NGTCP2_EXTERN int ngtcp2_conn_initiate_migration(ngtcp2_conn *conn,
  * @function
  *
  * `ngtcp2_conn_get_max_data_left` returns the number of bytes that
- * this local endpoint can send in this connection.
+ * this local endpoint can send in this connection without violating
+ * connection-level flow control.
  */
 NGTCP2_EXTERN uint64_t ngtcp2_conn_get_max_data_left(ngtcp2_conn *conn);
 
@@ -5049,7 +5038,8 @@ NGTCP2_EXTERN uint64_t ngtcp2_conn_get_max_data_left(ngtcp2_conn *conn);
  *
  * `ngtcp2_conn_get_max_stream_data_left` returns the number of bytes
  * that this local endpoint can send to a stream identified by
- * |stream_id|.  If no such stream is found, this function returns 0.
+ * |stream_id| without violating stream-level flow control.  If no
+ * such stream is found, this function returns 0.
  */
 NGTCP2_EXTERN uint64_t ngtcp2_conn_get_max_stream_data_left(ngtcp2_conn *conn,
                                                             int64_t stream_id);
@@ -5105,7 +5095,7 @@ ngtcp2_conn_get_initial_crypto_ctx(ngtcp2_conn *conn);
 /**
  * @function
  *
- * `ngtcp2_conn_set_crypto_ctx` sets |ctx| for Handshake/1RTT packet
+ * `ngtcp2_conn_set_crypto_ctx` sets |ctx| for Handshake/1-RTT packet
  * encryption.  The passed data will be passed to
  * :type:`ngtcp2_encrypt`, :type:`ngtcp2_decrypt` and
  * :type:`ngtcp2_hp_mask` callbacks.
@@ -5116,69 +5106,68 @@ NGTCP2_EXTERN void ngtcp2_conn_set_crypto_ctx(ngtcp2_conn *conn,
 /**
  * @function
  *
- * `ngtcp2_conn_get_tls_native_handle` returns TLS native handle set by
- * `ngtcp2_conn_set_tls_native_handle()`.
+ * `ngtcp2_conn_get_crypto_ctx` returns :type:`ngtcp2_crypto_ctx`
+ * object for Handshake/1-RTT packet encryption.
  */
-NGTCP2_EXTERN void *ngtcp2_conn_get_tls_native_handle(ngtcp2_conn *conn);
+NGTCP2_EXTERN const ngtcp2_crypto_ctx *
+ngtcp2_conn_get_crypto_ctx(ngtcp2_conn *conn);
 
 /**
  * @function
  *
- * `ngtcp2_conn_set_tls_native_handle` sets TLS native handle
- * |tls_native_handle| to |conn|.  Internally, it is used as an opaque
- * pointer.
+ * `ngtcp2_conn_set_0rtt_crypto_ctx` sets |ctx| for 0-RTT packet
+ * encryption.  The passed data will be passed to
+ * :type:`ngtcp2_encrypt`, :type:`ngtcp2_decrypt` and
+ * :type:`ngtcp2_hp_mask` callbacks.
  */
-NGTCP2_EXTERN void ngtcp2_conn_set_tls_native_handle(ngtcp2_conn *conn,
-                                                     void *tls_native_handle);
+NGTCP2_EXTERN void
+ngtcp2_conn_set_0rtt_crypto_ctx(ngtcp2_conn *conn,
+                                const ngtcp2_crypto_ctx *ctx);
 
 /**
  * @function
  *
- * `ngtcp2_conn_set_retry_aead` sets |aead| and |aead_ctx| for Retry
- * integrity tag verification.  |aead| must be AEAD_AES_128_GCM.
- * |aead_ctx| must be initialized with :macro:`NGTCP2_RETRY_KEY` as
- * encryption key.  This function must be called if |conn| is
- * initialized as client.  Server does not verify the tag and has no
- * need to call this function.
- *
- * If this function succeeds, |conn| takes ownership of |aead_ctx|.
- * :type:`ngtcp2_delete_crypto_aead_ctx` will be called to delete this
- * object when it is no longer used.  If this function fails, the
- * caller is responsible to delete it.
+ * `ngtcp2_conn_get_0rtt_crypto_ctx` returns :type:`ngtcp2_crypto_ctx`
+ * object for 0-RTT packet encryption.
  */
-NGTCP2_EXTERN void
-ngtcp2_conn_set_retry_aead(ngtcp2_conn *conn, const ngtcp2_crypto_aead *aead,
-                           const ngtcp2_crypto_aead_ctx *aead_ctx);
+NGTCP2_EXTERN const ngtcp2_crypto_ctx *
+ngtcp2_conn_get_0rtt_crypto_ctx(ngtcp2_conn *conn);
 
 /**
  * @function
  *
- * `ngtcp2_conn_get_crypto_ctx` returns :type:`ngtcp2_crypto_ctx`
- * object for Handshake/1RTT packet encryption.
+ * `ngtcp2_conn_get_tls_native_handle` returns TLS native handle set
+ * by `ngtcp2_conn_set_tls_native_handle`.
  */
-NGTCP2_EXTERN const ngtcp2_crypto_ctx *
-ngtcp2_conn_get_crypto_ctx(ngtcp2_conn *conn);
+NGTCP2_EXTERN void *ngtcp2_conn_get_tls_native_handle(ngtcp2_conn *conn);
 
 /**
  * @function
  *
- * `ngtcp2_conn_set_early_crypto_ctx` sets |ctx| for 0RTT packet
- * encryption.  The passed data will be passed to
- * :type:`ngtcp2_encrypt`, :type:`ngtcp2_decrypt` and
- * :type:`ngtcp2_hp_mask` callbacks.
+ * `ngtcp2_conn_set_tls_native_handle` sets TLS native handle
+ * |tls_native_handle| to |conn|.  Internally, it is used as an opaque
+ * pointer.
  */
-NGTCP2_EXTERN void
-ngtcp2_conn_set_early_crypto_ctx(ngtcp2_conn *conn,
-                                 const ngtcp2_crypto_ctx *ctx);
+NGTCP2_EXTERN void ngtcp2_conn_set_tls_native_handle(ngtcp2_conn *conn,
+                                                     void *tls_native_handle);
 
 /**
  * @function
  *
- * `ngtcp2_conn_get_early_crypto_ctx` returns
- * :type:`ngtcp2_crypto_ctx` object for 0RTT packet encryption.
+ * `ngtcp2_conn_set_retry_aead` sets |aead| and |aead_ctx| for Retry
+ * integrity tag verification.  |aead| must be AEAD_AES_128_GCM.
+ * |aead_ctx| must be initialized with :macro:`NGTCP2_RETRY_KEY` as
+ * encryption key.  This function must be called if |conn| is
+ * initialized as client.  Server does not verify the tag, and has no
+ * need to call this function.
+ *
+ * |conn| takes ownership of |aead_ctx|.
+ * :member:`ngtcp2_callbacks.delete_crypto_aead_ctx` will be called to
+ * delete this object when it is no longer used.
  */
-NGTCP2_EXTERN const ngtcp2_crypto_ctx *
-ngtcp2_conn_get_early_crypto_ctx(ngtcp2_conn *conn);
+NGTCP2_EXTERN void
+ngtcp2_conn_set_retry_aead(ngtcp2_conn *conn, const ngtcp2_crypto_aead *aead,
+                           const ngtcp2_crypto_aead_ctx *aead_ctx);
 
 /**
  * @enum
@@ -5213,8 +5202,8 @@ typedef enum ngtcp2_ccerr_type {
 /**
  * @struct
  *
- * :type:`ngtcp2_ccerr` contains connection error code, its type, and
- * the optional reason phrase.
+ * :type:`ngtcp2_ccerr` contains connection error code, its type, a
+ * frame type that caused this error, and the optional reason phrase.
  */
 typedef struct ngtcp2_ccerr {
   /**
@@ -5283,23 +5272,26 @@ NGTCP2_EXTERN void ngtcp2_ccerr_set_transport_error(ngtcp2_ccerr *ccerr,
  * `ngtcp2_ccerr_set_liberr` sets type and error_code based on
  * |liberr|.
  *
+ * |reason| is the reason phrase of length |reasonlen|.  This function
+ * does not make a copy of the reason phrase.
+ *
  * If |liberr| is :macro:`NGTCP2_ERR_RECV_VERSION_NEGOTIATION`,
  * :member:`ccerr->type <ngtcp2_ccerr.type>` is set to
  * :enum:`ngtcp2_ccerr_type.NGTCP2_CCERR_TYPE_VERSION_NEGOTIATION`,
  * and :member:`ccerr->error_code <ngtcp2_ccerr.error_code>` to
- * :macro:`NGTCP2_NO_ERROR`.  If |liberr| is
- * :macro:`NGTCP2_ERR_IDLE_CLOSE`, :member:`ccerr->type
+ * :macro:`NGTCP2_NO_ERROR`.
+ *
+ * If |liberr| is :macro:`NGTCP2_ERR_IDLE_CLOSE`, :member:`ccerr->type
  * <ngtcp2_ccerr.type>` is set to
  * :enum:`ngtcp2_ccerr_type.NGTCP2_CCERR_TYPE_IDLE_CLOSE`, and
  * :member:`ccerr->error_code <ngtcp2_ccerr.error_code>` to
- * :macro:`NGTCP2_NO_ERROR`.  Otherwise, :member:`ccerr->type
- * <ngtcp2_ccerr.type>` is set to
+ * :macro:`NGTCP2_NO_ERROR`.
+ *
+ * Otherwise, :member:`ccerr->type <ngtcp2_ccerr.type>` is set to
  * :enum:`ngtcp2_ccerr_type.NGTCP2_CCERR_TYPE_TRANSPORT`, and
  * :member:`ccerr->error_code <ngtcp2_ccerr.error_code>` is set to an
  * error code inferred by |liberr| (see
- * `ngtcp2_err_infer_quic_transport_error_code`).  |reason| is the
- * reason phrase of length |reasonlen|.  This function does not make a
- * copy of the reason phrase.
+ * `ngtcp2_err_infer_quic_transport_error_code`).
  */
 NGTCP2_EXTERN void ngtcp2_ccerr_set_liberr(ngtcp2_ccerr *ccerr, int liberr,
                                            const uint8_t *reason,
@@ -5348,9 +5340,9 @@ NGTCP2_EXTERN void ngtcp2_ccerr_set_application_error(ngtcp2_ccerr *ccerr,
  *
  * If |path| is not ``NULL``, this function stores the network path
  * with which the packet should be sent.  Each addr field must point
- * to the buffer which should be at least ``sizeof(struct
- * sockaddr_storage)`` bytes long.  The assignment might not be done
- * if nothing is written to |dest|.
+ * to the buffer which should be at least
+ * sizeof(:type:`ngtcp2_sockaddr_union`) bytes long.  The assignment
+ * might not be done if nothing is written to |dest|.
  *
  * If |pi| is not ``NULL``, this function stores packet metadata in it
  * if it succeeds.  The metadata includes ECN markings.
@@ -5378,7 +5370,8 @@ NGTCP2_EXTERN void ngtcp2_ccerr_set_application_error(ngtcp2_ccerr *ccerr,
  * :macro:`NGTCP2_ERR_NOBUF`
  *     Buffer is too small
  * :macro:`NGTCP2_ERR_INVALID_STATE`
- *     The current state does not allow sending CONNECTION_CLOSE.
+ *     The current state does not allow sending CONNECTION_CLOSE
+ *     frame.
  * :macro:`NGTCP2_ERR_PKT_NUM_EXHAUSTED`
  *     Packet number is exhausted, and cannot send any more packet.
  * :macro:`NGTCP2_ERR_CALLBACK_FAILURE`
@@ -5393,15 +5386,16 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_conn_write_connection_close_versioned(
  * @function
  *
  * `ngtcp2_conn_get_ccerr` returns the received connection close
- * error.
+ * error.  If no connection error is received, it returns
+ * :type:`ngtcp2_ccerr` that is initialized by `ngtcp2_ccerr_default`.
  */
 NGTCP2_EXTERN const ngtcp2_ccerr *ngtcp2_conn_get_ccerr(ngtcp2_conn *conn);
 
 /**
  * @function
  *
- * `ngtcp2_conn_is_local_stream` returns nonzero if |stream_id| denotes the
- * stream which a local endpoint issues.
+ * `ngtcp2_conn_is_local_stream` returns nonzero if |stream_id|
+ * denotes a locally initiated stream.
  */
 NGTCP2_EXTERN int ngtcp2_conn_is_local_stream(ngtcp2_conn *conn,
                                               int64_t stream_id);
@@ -5418,7 +5412,7 @@ NGTCP2_EXTERN int ngtcp2_conn_is_server(ngtcp2_conn *conn);
  * @function
  *
  * `ngtcp2_conn_after_retry` returns nonzero if |conn| as a client has
- * received Retry packet from server and successfully validated it.
+ * received Retry packet from server, and successfully validated it.
  */
 NGTCP2_EXTERN int ngtcp2_conn_after_retry(ngtcp2_conn *conn);
 
@@ -5442,11 +5436,11 @@ NGTCP2_EXTERN int ngtcp2_conn_set_stream_user_data(ngtcp2_conn *conn,
  * @function
  *
  * `ngtcp2_conn_update_pkt_tx_time` sets the time instant of the next
- * packet transmission.  This function must be called after (multiple
- * invocation of) `ngtcp2_conn_writev_stream`.  If packet aggregation
- * (e.g., packet batching, GSO) is used, call this function after all
- * aggregated datagrams are sent, which indicates multiple invocation
- * of `ngtcp2_conn_writev_stream`.
+ * packet transmission to pace packets.  This function must be called
+ * after (multiple invocation of) `ngtcp2_conn_writev_stream`.  If
+ * packet aggregation (e.g., packet batching, GSO) is used, call this
+ * function after all aggregated datagrams are sent, which indicates
+ * multiple invocation of `ngtcp2_conn_writev_stream`.
  */
 NGTCP2_EXTERN void ngtcp2_conn_update_pkt_tx_time(ngtcp2_conn *conn,
                                                   ngtcp2_tstamp ts);
@@ -5476,8 +5470,8 @@ NGTCP2_EXTERN size_t ngtcp2_conn_get_stream_loss_count(ngtcp2_conn *conn,
  *
  * `ngtcp2_strerror` returns the text representation of |liberr|.
  * |liberr| must be one of ngtcp2 library error codes (which is
- * defined as NGTCP2_ERR_* macro, such as
- * :macro:`NGTCP2_ERR_DECRYPT`).
+ * defined as :macro:`NGTCP2_ERR_* <NGTCP2_ERR_INVALID_ARGUMENT>`
+ * macros).
  */
 NGTCP2_EXTERN const char *ngtcp2_strerror(int liberr);
 
@@ -5486,8 +5480,8 @@ NGTCP2_EXTERN const char *ngtcp2_strerror(int liberr);
  *
  * `ngtcp2_err_is_fatal` returns nonzero if |liberr| is a fatal error.
  * |liberr| must be one of ngtcp2 library error codes (which is
- * defined as NGTCP2_ERR_* macro, such as
- * :macro:`NGTCP2_ERR_DECRYPT`).
+ * defined as :macro:`NGTCP2_ERR_* <NGTCP2_ERR_INVALID_ARGUMENT>`
+ * macros).
  */
 NGTCP2_EXTERN int ngtcp2_err_is_fatal(int liberr);
 
@@ -5497,7 +5491,7 @@ NGTCP2_EXTERN int ngtcp2_err_is_fatal(int liberr);
  * `ngtcp2_err_infer_quic_transport_error_code` returns a QUIC
  * transport error code which corresponds to |liberr|.  |liberr| must
  * be one of ngtcp2 library error codes (which is defined as
- * NGTCP2_ERR_* macro, such as :macro:`NGTCP2_ERR_DECRYPT`).
+ * :macro:`NGTCP2_ERR_* <NGTCP2_ERR_INVALID_ARGUMENT>` macros).
  */
 NGTCP2_EXTERN uint64_t ngtcp2_err_infer_quic_transport_error_code(int liberr);
 
@@ -5550,7 +5544,7 @@ NGTCP2_EXTERN void ngtcp2_path_storage_zero(ngtcp2_path_storage *ps);
  * @function
  *
  * `ngtcp2_settings_default` initializes |settings| with the default
- * values.  First this function fills |settings| with 0 and set the
+ * values.  First this function fills |settings| with 0, and set the
  * default value to the following fields:
  *
  * * :type:`cc_algo <ngtcp2_settings.cc_algo>` =
@@ -5570,7 +5564,7 @@ NGTCP2_EXTERN void ngtcp2_settings_default_versioned(int settings_version,
  * @function
  *
  * `ngtcp2_transport_params_default` initializes |params| with the
- * default values.  First this function fills |params| with 0 and set
+ * default values.  First this function fills |params| with 0, and set
  * the default value to the following fields:
  *
  * * :type:`max_udp_payload_size
@@ -5613,7 +5607,7 @@ NGTCP2_EXTERN const ngtcp2_mem *ngtcp2_mem_default(void);
 /**
  * @struct
  *
- * :type:`ngtcp2_info` is what `ngtcp2_version()` returns.  It holds
+ * :type:`ngtcp2_info` is what `ngtcp2_version` returns.  It holds
  * information about the particular ngtcp2 version.
  */
 typedef struct ngtcp2_info {
@@ -5625,12 +5619,12 @@ typedef struct ngtcp2_info {
   int age;
   /**
    * :member:`version_num` is the :macro:`NGTCP2_VERSION_NUM` number
-   * (since age ==1)
+   * (since :member:`age` ==1)
    */
   int version_num;
   /**
    * :member:`version_str` points to the :macro:`NGTCP2_VERSION`
-   * string (since age ==1)
+   * string (since :member:`age` ==1)
    */
   const char *version_str;
   /* -------- the above fields all exist when age == 1 */
@@ -5639,10 +5633,10 @@ typedef struct ngtcp2_info {
 /**
  * @function
  *
- * `ngtcp2_version` returns a pointer to a ngtcp2_info struct with
- * version information about the run-time library in use.  The
+ * `ngtcp2_version` returns a pointer to a :type:`ngtcp2_info` struct
+ * with version information about the run-time library in use.  The
  * |least_version| argument can be set to a 24 bit numerical value for
- * the least accepted version number and if the condition is not met,
+ * the least accepted version number, and if the condition is not met,
  * this function will return a ``NULL``.  Pass in 0 to skip the
  * version checking.
  */
@@ -5677,12 +5671,12 @@ NGTCP2_EXTERN int ngtcp2_path_eq(const ngtcp2_path *a, const ngtcp2_path *b);
 /**
  * @function
  *
- * `ngtcp2_is_supported_version` returns nonzero if the library supports
- * QUIC version |version|.
+ * `ngtcp2_is_supported_version` returns nonzero if the library
+ * supports QUIC version |version|.
  */
 NGTCP2_EXTERN int ngtcp2_is_supported_version(uint32_t version);
 
-/*
+/**
  * @function
  *
  * `ngtcp2_is_reserved_version` returns nonzero if |version| is a
@@ -5698,9 +5692,9 @@ NGTCP2_EXTERN int ngtcp2_is_reserved_version(uint32_t version);
  * |preferred_versions| of |preferred_versionslen| elements specifies
  * the preference of versions, which is sorted in the order of
  * preference.  All versions included in |preferred_versions| must be
- * supported by the library, that is, passing a version to
- * `ngtcp2_is_supported_version` must return nonzero.  This function
- * is intended to be used by client when it receives Version
+ * supported by the library, that is, passing any version in the array
+ * to `ngtcp2_is_supported_version` must return nonzero.  This
+ * function is intended to be used by client when it receives Version
  * Negotiation packet.  If no version is selected, this function
  * returns 0.
  */
index 4736b51c3cb48dcde9f7cd2c0bdee2440e647e9d..f8d55a0fdb7088c9da67c8a544f972e0313749e6 100644 (file)
@@ -38,37 +38,13 @@ extern "C" {
 #  include <ws2tcpip.h>
 #endif /* WIN32 */
 
-/**
- * @macro
- *
- * :macro:`NGTCP2_CRYPTO_INITIAL_SECRETLEN` is the length of secret
- * for Initial packets.
- */
-#define NGTCP2_CRYPTO_INITIAL_SECRETLEN 32
-
-/**
- * @macro
- *
- * :macro:`NGTCP2_CRYPTO_INITIAL_KEYLEN` is the length of key for
- * Initial packets.
- */
-#define NGTCP2_CRYPTO_INITIAL_KEYLEN 16
-
-/**
- * @macro
- *
- * :macro:`NGTCP2_CRYPTO_INITIAL_IVLEN` is the length of IV for
- * Initial packets.
- */
-#define NGTCP2_CRYPTO_INITIAL_IVLEN 12
-
 /**
  * @function
  *
  * `ngtcp2_crypto_ctx_tls` initializes |ctx| by extracting negotiated
  * ciphers and message digests from native TLS session
  * |tls_native_handle|.  This is used for encrypting/decrypting
- * Handshake and Short header packets.
+ * Handshake and 1-RTT packets.
  *
  * If libngtcp2_crypto_openssl is linked, |tls_native_handle| must be
  * a pointer to SSL object.
@@ -81,7 +57,7 @@ NGTCP2_EXTERN ngtcp2_crypto_ctx *ngtcp2_crypto_ctx_tls(ngtcp2_crypto_ctx *ctx,
  *
  * `ngtcp2_crypto_ctx_tls_early` initializes |ctx| by extracting early
  * ciphers and message digests from native TLS session
- * |tls_native_handle|.  This is used for encrypting/decrypting 0RTT
+ * |tls_native_handle|.  This is used for encrypting/decrypting 0-RTT
  * packets.
  *
  * If libngtcp2_crypto_openssl is linked, |tls_native_handle| must be
@@ -134,10 +110,12 @@ ngtcp2_crypto_aead_noncelen(const ngtcp2_crypto_aead *aead);
 /**
  * @function
  *
- * `ngtcp2_crypto_hkdf_extract` performs HKDF extract operation.  The
- * result is the length of |md| and is stored to the buffer pointed by
- * |dest|.  The caller is responsible to specify the buffer that can
- * store the output.
+ * `ngtcp2_crypto_hkdf_extract` performs HKDF extract operation.
+ *
+ * The length of output is `ngtcp2_crypto_md_hashlen(md)
+ * <ngtcp2_crypto_md_hashlen>`.  The output is stored in the buffer
+ * pointed by |dest|.  The caller is responsible to specify the buffer
+ * that has enough capacity to store the output.
  *
  * This function returns 0 if it succeeds, or -1.
  */
@@ -150,7 +128,7 @@ ngtcp2_crypto_hkdf_extract(uint8_t *dest, const ngtcp2_crypto_md *md,
  * @function
  *
  * `ngtcp2_crypto_hkdf_expand` performs HKDF expand operation.  The
- * result is |destlen| bytes long and is stored to the buffer pointed
+ * result is |destlen| bytes long, and is stored in the buffer pointed
  * by |dest|.
  *
  * This function returns 0 if it succeeds, or -1.
@@ -166,7 +144,8 @@ NGTCP2_EXTERN int ngtcp2_crypto_hkdf_expand(uint8_t *dest, size_t destlen,
  * @function
  *
  * `ngtcp2_crypto_hkdf` performs HKDF operation.  The result is
- * |destlen| bytes long and is stored to the buffer pointed by |dest|.
+ * |destlen| bytes long, and is stored in the buffer pointed by
+ * |dest|.
  *
  * This function returns 0 if it succeeds, or -1.
  */
@@ -176,41 +155,6 @@ NGTCP2_EXTERN int ngtcp2_crypto_hkdf(uint8_t *dest, size_t destlen,
                                      const uint8_t *salt, size_t saltlen,
                                      const uint8_t *info, size_t infolen);
 
-/**
- * @function
- *
- * `ngtcp2_crypto_hkdf_expand_label` performs HKDF expand label.  The
- * result is |destlen| bytes long and is stored to the buffer pointed
- * by |dest|.
- *
- * This function returns 0 if it succeeds, or -1.
- */
-NGTCP2_EXTERN int ngtcp2_crypto_hkdf_expand_label(uint8_t *dest, size_t destlen,
-                                                  const ngtcp2_crypto_md *md,
-                                                  const uint8_t *secret,
-                                                  size_t secretlen,
-                                                  const uint8_t *label,
-                                                  size_t labellen);
-
-/**
- * @enum
- *
- * :type:`ngtcp2_crypto_side` indicates which side the application
- * implements; client or server.
- */
-typedef enum ngtcp2_crypto_side {
-  /**
-   * :enum:`NGTCP2_CRYPTO_SIDE_CLIENT` indicates that the application
-   * is client.
-   */
-  NGTCP2_CRYPTO_SIDE_CLIENT,
-  /**
-   * :enum:`NGTCP2_CRYPTO_SIDE_SERVER` indicates that the application
-   * is server.
-   */
-  NGTCP2_CRYPTO_SIDE_SERVER
-} ngtcp2_crypto_side;
-
 /**
  * @function
  *
@@ -225,11 +169,10 @@ ngtcp2_crypto_packet_protection_ivlen(const ngtcp2_crypto_aead *aead);
  *
  * `ngtcp2_crypto_encrypt` encrypts |plaintext| of length
  * |plaintextlen| and writes the ciphertext into the buffer pointed by
- * |dest|.  The length of ciphertext is plaintextlen +
+ * |dest|.  The length of ciphertext is |plaintextlen| +
  * :member:`aead->max_overhead <ngtcp2_crypto_aead.max_overhead>`
  * bytes long.  |dest| must have enough capacity to store the
- * ciphertext.  It is allowed to specify the same value to |dest| and
- * |plaintext|.
+ * ciphertext.  |dest| and |plaintext| may point to the same buffer.
  *
  * This function returns 0 if it succeeds, or -1.
  */
@@ -263,11 +206,10 @@ ngtcp2_crypto_encrypt_cb(uint8_t *dest, const ngtcp2_crypto_aead *aead,
  *
  * `ngtcp2_crypto_decrypt` decrypts |ciphertext| of length
  * |ciphertextlen| and writes the plaintext into the buffer pointed by
- * |dest|.  The length of plaintext is ciphertextlen -
+ * |dest|.  The length of plaintext is |ciphertextlen| -
  * :member:`aead->max_overhead <ngtcp2_crypto_aead.max_overhead>`
  * bytes long.  |dest| must have enough capacity to store the
- * plaintext.  It is allowed to specify the same value to |dest| and
- * |ciphertext|.
+ * plaintext.  |dest| and |ciphertext| may point to the same buffer.
  *
  * This function returns 0 if it succeeds, or -1.
  */
@@ -299,7 +241,7 @@ ngtcp2_crypto_decrypt_cb(uint8_t *dest, const ngtcp2_crypto_aead *aead,
 /**
  * @function
  *
- * `ngtcp2_crypto_hp_mask` generates mask which is used in packet
+ * `ngtcp2_crypto_hp_mask` generates mask which is used in packet
  * header encryption.  The mask is written to the buffer pointed by
  * |dest|.  The sample is passed as |sample| which is
  * :macro:`NGTCP2_HP_SAMPLELEN` bytes long.  The length of mask must
@@ -333,15 +275,14 @@ ngtcp2_crypto_hp_mask_cb(uint8_t *dest, const ngtcp2_crypto_cipher *hp,
 /**
  * @function
  *
- * `ngtcp2_crypto_derive_and_install_rx_key` derives the rx keys from
- * |secret| and installs new keys to |conn|.
+ * `ngtcp2_crypto_derive_and_install_rx_key` derives the decryption
+ * keying materials from |secret|, and installs them to |conn|.
  *
- * If |key| is not NULL, the derived packet protection key for
- * decryption is written to the buffer pointed by |key|.  If |iv| is
- * not NULL, the derived packet protection IV for decryption is
- * written to the buffer pointed by |iv|.  If |hp| is not NULL, the
- * derived header protection key for decryption is written to the
- * buffer pointed by |hp|.
+ * If |key| is not NULL, the derived packet protection key is written
+ * to the buffer pointed by |key|.  If |iv| is not NULL, the derived
+ * packet protection IV is written to the buffer pointed by |iv|.  If
+ * |hp| is not NULL, the derived header protection key is written to
+ * the buffer pointed by |hp|.
  *
  * |secretlen| specifies the length of |secret|.
  *
@@ -351,44 +292,44 @@ ngtcp2_crypto_hp_mask_cb(uint8_t *dest, const ngtcp2_crypto_cipher *hp,
  * `ngtcp2_crypto_packet_protection_ivlen(ctx->aead)
  * <ngtcp2_crypto_packet_protection_ivlen>` where ctx is obtained by
  * `ngtcp2_crypto_ctx_tls` (or `ngtcp2_crypto_ctx_tls_early` if
- * |level| == :enum:`ngtcp2_crypto_level.NGTCP2_CRYPTO_LEVEL_EARLY`).
+ * |level| ==
+ * :enum:`ngtcp2_encryption_level.NGTCP2_ENCRYPTION_LEVEL_0RTT`).
  *
  * In the first call of this function, it calls
  * `ngtcp2_conn_set_crypto_ctx` (or `ngtcp2_conn_set_early_crypto_ctx`
  * if |level| ==
- * :enum:`ngtcp2_crypto_level.NGTCP2_CRYPTO_LEVEL_EARLY`) to set
- * negotiated AEAD and message digest algorithm.  After the successful
- * call of this function, application can use
+ * :enum:`ngtcp2_encryption_level.NGTCP2_ENCRYPTION_LEVEL_0RTT`) to
+ * set negotiated AEAD and message digest algorithm.  After the
+ * successful call of this function, application can use
  * `ngtcp2_conn_get_crypto_ctx` (or `ngtcp2_conn_get_early_crypto_ctx`
  * if |level| ==
- * :enum:`ngtcp2_crypto_level.NGTCP2_CRYPTO_LEVEL_EARLY`) to get
- * :type:`ngtcp2_crypto_ctx`.
+ * :enum:`ngtcp2_encryption_level.NGTCP2_ENCRYPTION_LEVEL_0RTT`) to
+ * get :type:`ngtcp2_crypto_ctx`.
  *
  * If |conn| is initialized as client, and |level| is
- * :enum:`ngtcp2_crypto_level.NGTCP2_CRYPTO_LEVEL_APPLICATION`, this
+ * :enum:`ngtcp2_encryption_level.NGTCP2_ENCRYPTION_LEVEL_1RTT`, this
  * function retrieves a remote QUIC transport parameters extension
- * from an object obtained by `ngtcp2_conn_get_tls_native_handle` and
+ * from an object obtained by `ngtcp2_conn_get_tls_native_handle`, and
  * sets it to |conn| by calling
- * `ngtcp2_conn_decode_remote_transport_params`.
+ * `ngtcp2_conn_decode_and_set_remote_transport_params`.
  *
  * This function returns 0 if it succeeds, or -1.
  */
 NGTCP2_EXTERN int ngtcp2_crypto_derive_and_install_rx_key(
     ngtcp2_conn *conn, uint8_t *key, uint8_t *iv, uint8_t *hp,
-    ngtcp2_crypto_level level, const uint8_t *secret, size_t secretlen);
+    ngtcp2_encryption_level level, const uint8_t *secret, size_t secretlen);
 
 /**
  * @function
  *
- * `ngtcp2_crypto_derive_and_install_tx_key` derives the tx keys from
- * |secret| and installs new keys to |conn|.
+ * `ngtcp2_crypto_derive_and_install_tx_key` derives the encryption
+ * keying materials from |secret|, and installs new keys to |conn|.
  *
- * If |key| is not NULL, the derived packet protection key for
- * encryption is written to the buffer pointed by |key|.  If |iv| is
- * not NULL, the derived packet protection IV for encryption is
- * written to the buffer pointed by |iv|.  If |hp| is not NULL, the
- * derived header protection key for encryption is written to the
- * buffer pointed by |hp|.
+ * If |key| is not NULL, the derived packet protection key is written
+ * to the buffer pointed by |key|.  If |iv| is not NULL, the derived
+ * packet protection IV is written to the buffer pointed by |iv|.  If
+ * |hp| is not NULL, the derived header protection key is written to
+ * the buffer pointed by |hp|.
  *
  * |secretlen| specifies the length of |secret|.
  *
@@ -398,58 +339,59 @@ NGTCP2_EXTERN int ngtcp2_crypto_derive_and_install_rx_key(
  * `ngtcp2_crypto_packet_protection_ivlen(ctx->aead)
  * <ngtcp2_crypto_packet_protection_ivlen>` where ctx is obtained by
  * `ngtcp2_crypto_ctx_tls` (or `ngtcp2_crypto_ctx_tls_early` if
- * |level| == :enum:`ngtcp2_crypto_level.NGTCP2_CRYPTO_LEVEL_EARLY`).
+ * |level| ==
+ * :enum:`ngtcp2_encryption_level.NGTCP2_ENCRYPTION_LEVEL_0RTT`).
  *
  * In the first call of this function, it calls
  * `ngtcp2_conn_set_crypto_ctx` (or `ngtcp2_conn_set_early_crypto_ctx`
  * if |level| ==
- * :enum:`ngtcp2_crypto_level.NGTCP2_CRYPTO_LEVEL_EARLY`) to set
- * negotiated AEAD and message digest algorithm.  After the successful
- * call of this function, application can use
+ * :enum:`ngtcp2_encryption_level.NGTCP2_ENCRYPTION_LEVEL_0RTT`) to
+ * set negotiated AEAD and message digest algorithm.  After the
+ * successful call of this function, application can use
  * `ngtcp2_conn_get_crypto_ctx` (or `ngtcp2_conn_get_early_crypto_ctx`
  * if |level| ==
- * :enum:`ngtcp2_crypto_level.NGTCP2_CRYPTO_LEVEL_EARLY`) to get
- * :type:`ngtcp2_crypto_ctx`.
+ * :enum:`ngtcp2_encryption_level.NGTCP2_ENCRYPTION_LEVEL_0RTT`) to
+ * get :type:`ngtcp2_crypto_ctx`.
  *
  * If |conn| is initialized as server, and |level| is
- * :enum:`ngtcp2_crypto_level.NGTCP2_CRYPTO_LEVEL_APPLICATION`, this
+ * :enum:`ngtcp2_encryption_level.NGTCP2_ENCRYPTION_LEVEL_1RTT`, this
  * function retrieves a remote QUIC transport parameters extension
- * from an object obtained by `ngtcp2_conn_get_tls_native_handle` and
+ * from an object obtained by `ngtcp2_conn_get_tls_native_handle`, and
  * sets it to |conn| by calling
- * `ngtcp2_conn_decode_remote_transport_params`.
+ * `ngtcp2_conn_decode_and_set_remote_transport_params`.
  *
  * This function returns 0 if it succeeds, or -1.
  */
 NGTCP2_EXTERN int ngtcp2_crypto_derive_and_install_tx_key(
     ngtcp2_conn *conn, uint8_t *key, uint8_t *iv, uint8_t *hp,
-    ngtcp2_crypto_level level, const uint8_t *secret, size_t secretlen);
+    ngtcp2_encryption_level level, const uint8_t *secret, size_t secretlen);
 
 /**
  * @function
  *
  * `ngtcp2_crypto_update_key` updates traffic keying materials.
  *
- * The new traffic secret for decryption is written to the buffer
- * pointed by |rx_secret|.  The length of secret is |secretlen| bytes,
- * and |rx_secret| must point to the buffer which has enough capacity.
+ * The new decryption traffic secret is written to the buffer pointed
+ * by |rx_secret|.  The length of secret is |secretlen| bytes, and
+ * |rx_secret| must point to the buffer which has enough capacity.
  *
- * The new traffic secret for encryption is written to the buffer
- * pointed by |tx_secret|.  The length of secret is |secretlen| bytes,
- * and |tx_secret| must point to the buffer which has enough capacity.
+ * The new encryption traffic secret is written to the buffer pointed
+ * by |tx_secret|.  The length of secret is |secretlen| bytes, and
+ * |tx_secret| must point to the buffer which has enough capacity.
  *
- * The derived packet protection key for decryption is written to the
- * buffer pointed by |rx_key|.  The derived packet protection IV for
- * decryption is written to the buffer pointed by |rx_iv|.
- * |rx_aead_ctx| must be constructed with |rx_key|.
+ * The derived decryption packet protection key is written to the
+ * buffer pointed by |rx_key|.  The derived decryption packet
+ * protection IV is written to the buffer pointed by |rx_iv|.
+ * |rx_aead_ctx| is initialized with the derived key and IV.
  *
- * The derived packet protection key for encryption is written to the
- * buffer pointed by |tx_key|.  The derived packet protection IV for
- * encryption is written to the buffer pointed by |tx_iv|.
- * |tx_aead_ctx| must be constructed with |rx_key|.
+ * The derived encryption packet protection key is written to the
+ * buffer pointed by |tx_key|.  The derived encryption packet
+ * protection IV is written to the buffer pointed by |tx_iv|.
+ * |tx_aead_ctx| is initialized with the derived key and IV.
  *
- * |current_rx_secret| and |current_tx_secret| are the current traffic
- * secrets for decryption and encryption.  |secretlen| specifies the
- * length of |rx_secret| and |tx_secret|.
+ * |current_rx_secret| and |current_tx_secret| are the current
+ * decryption and encryption traffic secrets respectively.  They share
+ * the same length with |rx_secret| and |tx_secret|.
  *
  * The length of packet protection key and header protection key is
  * `ngtcp2_crypto_aead_keylen(ctx->aead) <ngtcp2_crypto_aead_keylen>`,
@@ -488,7 +430,7 @@ NGTCP2_EXTERN int ngtcp2_crypto_update_key_cb(
  * @function
  *
  * `ngtcp2_crypto_client_initial_cb` installs initial secrets and
- * encryption keys and sets QUIC transport parameters.
+ * encryption keys, and sets QUIC transport parameters.
  *
  * This function can be directly passed to
  * :member:`ngtcp2_callbacks.client_initial` field.  It is only used
@@ -507,8 +449,8 @@ NGTCP2_EXTERN int ngtcp2_crypto_client_initial_cb(ngtcp2_conn *conn,
  * response to incoming Retry packet.
  *
  * This function can be directly passed to
- * :member:`ngtcp2_callbacks.recv_retry` field.  It is only used
- * by client.
+ * :member:`ngtcp2_callbacks.recv_retry` field.  It is only used by
+ * client.
  *
  * This function returns 0 if it succeeds, or
  * :macro:`NGTCP2_ERR_CALLBACK_FAILURE`.
@@ -525,8 +467,8 @@ NGTCP2_EXTERN int ngtcp2_crypto_recv_retry_cb(ngtcp2_conn *conn,
  * transport parameters.
  *
  * This function can be directly passed to
- * :member:`ngtcp2_callbacks.recv_client_initial` field.  It is
- * only used by server.
+ * :member:`ngtcp2_callbacks.recv_client_initial` field.  It is only
+ * used by server.
  *
  * This function returns 0 if it succeeds, or
  * :macro:`NGTCP2_ERR_CALLBACK_FAILURE`.
@@ -539,11 +481,11 @@ NGTCP2_EXTERN int ngtcp2_crypto_recv_client_initial_cb(ngtcp2_conn *conn,
  * @function
  *
  * `ngtcp2_crypto_read_write_crypto_data` reads CRYPTO data |data| of
- * length |datalen| in encryption level |crypto_level| and may feed
- * outgoing CRYPTO data to |conn|.  This function can drive handshake.
- * This function can be also used after handshake completes.  It is
- * allowed to call this function with |datalen| == 0.  In this case,
- * no additional read operation is done.
+ * length |datalen| in an encryption level |encryption_level|, and may
+ * feed outgoing CRYPTO data to |conn|.  This function can drive
+ * handshake.  This function can be also used after handshake
+ * completes.  It is allowed to call this function with |datalen| ==
+ * 0.  In this case, no additional read operation is done.
  *
  * This function returns 0 if it succeeds, or a negative error code.
  * The generic error code is -1 if a specific error code is not
@@ -553,7 +495,7 @@ NGTCP2_EXTERN int ngtcp2_crypto_recv_client_initial_cb(ngtcp2_conn *conn,
  */
 NGTCP2_EXTERN int
 ngtcp2_crypto_read_write_crypto_data(ngtcp2_conn *conn,
-                                     ngtcp2_crypto_level crypto_level,
+                                     ngtcp2_encryption_level encryption_level,
                                      const uint8_t *data, size_t datalen);
 
 /**
@@ -570,17 +512,17 @@ ngtcp2_crypto_read_write_crypto_data(ngtcp2_conn *conn,
  * codes.
  */
 NGTCP2_EXTERN int ngtcp2_crypto_recv_crypto_data_cb(
-    ngtcp2_conn *conn, ngtcp2_crypto_level crypto_level, uint64_t offset,
-    const uint8_t *data, size_t datalen, void *user_data);
+    ngtcp2_conn *conn, ngtcp2_encryption_level encryption_level,
+    uint64_t offset, const uint8_t *data, size_t datalen, void *user_data);
 
 /**
  * @function
  *
  *  `ngtcp2_crypto_generate_stateless_reset_token` generates a
  *  stateless reset token using HKDF extraction using the given |cid|
- *  and static key |secret| as input.  The token will be written to
- *  the buffer pointed by |token| and it must have a capacity of at
- *  least :macro:`NGTCP2_STATELESS_RESET_TOKENLEN` bytes.
+ *  and |secret| as input.  The token will be written to the buffer
+ *  pointed by |token|, and it must have a capacity of at least
+ *  :macro:`NGTCP2_STATELESS_RESET_TOKENLEN` bytes.
  *
  * This function returns 0 if it succeeds, or -1.
  */
@@ -644,12 +586,12 @@ NGTCP2_EXTERN int ngtcp2_crypto_generate_stateless_reset_token(
  * :macro:`NGTCP2_CRYPTO_MAX_RETRY_TOKENLEN` bytes long.  The
  * successfully generated token starts with
  * :macro:`NGTCP2_CRYPTO_TOKEN_MAGIC_RETRY`.  |secret| of length
- * |secretlen| is an initial keying material to generate keys to
- * encrypt the token.  |version| is QUIC version.  |remote_addr| of
- * length |remote_addrlen| is an address of client.  |retry_scid| is a
- * Source Connection ID chosen by server and set in Retry packet.
- * |odcid| is a Destination Connection ID in Initial packet sent by
- * client.  |ts| is the timestamp when the token is generated.
+ * |secretlen| is a keying material to generate keys to encrypt the
+ * token.  |version| is QUIC version.  |remote_addr| of length
+ * |remote_addrlen| is an address of client.  |retry_scid| is a Source
+ * Connection ID chosen by server, and set in Retry packet.  |odcid|
+ * is a Destination Connection ID in Initial packet sent by client.
+ * |ts| is the timestamp when the token is generated.
  *
  * This function returns the length of generated token if it succeeds,
  * or -1.
@@ -664,16 +606,16 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_crypto_generate_retry_token(
  *
  * `ngtcp2_crypto_verify_retry_token` verifies Retry token stored in
  * the buffer pointed by |token| of length |tokenlen|.  |secret| of
- * length |secretlen| is an initial keying material to generate keys
- * to decrypt the token.  |version| is QUIC version of the Initial
- * packet that contains this token.  |remote_addr| of length
- * |remote_addrlen| is an address of client.  |dcid| is a Destination
- * Connection ID in Initial packet sent by client.  |timeout| is the
- * period during which the token is valid.  |ts| is the current
- * timestamp.  When validation succeeds, the extracted Destination
- * Connection ID (which is the Destination Connection ID in Initial
- * packet sent by client that triggered Retry packet) is stored to the
- * buffer pointed by |odcid|.
+ * length |secretlen| is a keying material to generate keys to decrypt
+ * the token.  |version| is QUIC version of the Initial packet that
+ * contains this token.  |remote_addr| of length |remote_addrlen| is
+ * an address of client.  |dcid| is a Destination Connection ID in
+ * Initial packet sent by client.  |timeout| is the period during
+ * which the token is valid.  |ts| is the current timestamp.  When
+ * validation succeeds, the extracted Destination Connection ID (which
+ * is the Destination Connection ID in Initial packet sent by client
+ * that triggered Retry packet) is stored in the buffer pointed by
+ * |odcid|.
  *
  * This function returns 0 if it succeeds, or -1.
  */
@@ -692,10 +634,9 @@ NGTCP2_EXTERN int ngtcp2_crypto_verify_retry_token(
  * :macro:`NGTCP2_CRYPTO_MAX_REGULAR_TOKENLEN` bytes long.  The
  * successfully generated token starts with
  * :macro:`NGTCP2_CRYPTO_TOKEN_MAGIC_REGULAR`.  |secret| of length
- * |secretlen| is an initial keying material to generate keys to
- * encrypt the token.  |remote_addr| of length |remote_addrlen| is an
- * address of client.  |ts| is the timestamp when the token is
- * generated.
+ * |secretlen| is a keying material to generate keys to encrypt the
+ * token.  |remote_addr| of length |remote_addrlen| is an address of
+ * client.  |ts| is the timestamp when the token is generated.
  *
  * This function returns the length of generated token if it succeeds,
  * or -1.
@@ -710,8 +651,8 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_crypto_generate_regular_token(
  *
  * `ngtcp2_crypto_verify_regular_token` verifies a regular token
  * stored in the buffer pointed by |token| of length |tokenlen|.
- * |secret| of length |secretlen| is an initial keying material to
- * generate keys to decrypt the token.  |remote_addr| of length
+ * |secret| of length |secretlen| is a keying material to generate
+ * keys to decrypt the token.  |remote_addr| of length
  * |remote_addrlen| is an address of client.  |timeout| is the period
  * during which the token is valid.  |ts| is the current timestamp.
  *
@@ -750,9 +691,12 @@ NGTCP2_EXTERN ngtcp2_ssize ngtcp2_crypto_write_connection_close(
  * @function
  *
  * `ngtcp2_crypto_write_retry` writes Retry packet to the buffer
- * pointed by |dest| of length |destlen|.  |odcid| specifies Original
- * Destination Connection ID.  |token| specifies Retry Token, and
- * |tokenlen| specifies its length.
+ * pointed by |dest| of length |destlen|.  |dcid| is the Connection ID
+ * which appeared in a packet as a Source Connection ID sent by
+ * client.  |scid| is a server chosen Source Connection ID.  |odcid|
+ * specifies Original Destination Connection ID which appeared in a
+ * packet as a Destination Connection ID sent by client.  |token|
+ * specifies Retry Token, and |tokenlen| specifies its length.
  *
  * This function wraps around `ngtcp2_pkt_write_retry` for easier use.
  *
@@ -783,7 +727,7 @@ ngtcp2_crypto_aead_ctx_encrypt_init(ngtcp2_crypto_aead_ctx *aead_ctx,
  *
  * `ngtcp2_crypto_aead_ctx_decrypt_init` initializes |aead_ctx| with
  * new AEAD cipher context object for decryption which is constructed
- * to use |key| as encryption key.  |aead| specifies AEAD cipher to
+ * to use |key| as decryption key.  |aead| specifies AEAD cipher to
  * use.  |noncelen| is the length of nonce.
  *
  * This function returns 0 if it succeeds, or -1.
@@ -806,7 +750,8 @@ ngtcp2_crypto_aead_ctx_free(ngtcp2_crypto_aead_ctx *aead_ctx);
 /**
  * @function
  *
- * `ngtcp2_crypto_delete_crypto_aead_ctx_cb` deletes the given |aead_ctx|.
+ * `ngtcp2_crypto_delete_crypto_aead_ctx_cb` deletes the given
+ * |aead_ctx|.
  *
  * This function can be directly passed to
  * :member:`ngtcp2_callbacks.delete_crypto_aead_ctx` field.
@@ -845,7 +790,8 @@ NGTCP2_EXTERN int ngtcp2_crypto_get_path_challenge_data_cb(ngtcp2_conn *conn,
  *
  * `ngtcp2_crypto_version_negotiation_cb` installs Initial keys for
  * |version| which is negotiated or being negotiated.  |client_dcid|
- * is the destination connection ID in first Initial packet of client.
+ * is the destination connection ID in first Initial packet from
+ * client.
  *
  * This function can be directly passed to
  * :member:`ngtcp2_callbacks.version_negotiation` field.
index af5503f5a2df3b86bc277656e4bb24e22434fd21..5d4b9d962b77992fd84e3eedaf609b71deb02967 100644 (file)
@@ -37,22 +37,23 @@ extern "C" {
  * @function
  *
  * `ngtcp2_crypto_gnutls_from_gnutls_record_encryption_level`
- * translates |gtls_level| to :type:`ngtcp2_crypto_level`.  This
+ * translates |gtls_level| to :type:`ngtcp2_encryption_level`.  This
  * function is only available for GnuTLS backend.
  */
-NGTCP2_EXTERN ngtcp2_crypto_level
+NGTCP2_EXTERN ngtcp2_encryption_level
 ngtcp2_crypto_gnutls_from_gnutls_record_encryption_level(
     gnutls_record_encryption_level_t gtls_level);
 
 /**
  * @function
  *
- * `ngtcp2_crypto_gnutls_from_ngtcp2_crypto_level` translates
- * |crypto_level| to gnutls_record_encryption_level_t.  This function
- * is only available for GnuTLS backend.
+ * `ngtcp2_crypto_gnutls_from_ngtcp2_encryption_level` translates
+ * |encryption_level| to gnutls_record_encryption_level_t.  This
+ * function is only available for GnuTLS backend.
  */
 NGTCP2_EXTERN gnutls_record_encryption_level_t
-ngtcp2_crypto_gnutls_from_ngtcp2_level(ngtcp2_crypto_level crypto_level);
+ngtcp2_crypto_gnutls_from_ngtcp2_encryption_level(
+    ngtcp2_encryption_level encryption_level);
 
 /**
  * @function
index d21bb10e0276aeeeee3217d6237d019bea22905a..dbf7f12a2bd43829dff427bcfe46e23e6c070400 100644 (file)
@@ -36,7 +36,7 @@
  *
  * Version number of the ngtcp2 library release.
  */
-#define NGTCP2_VERSION "0.15.0"
+#define NGTCP2_VERSION "0.16.0"
 
 /**
  * @macro
@@ -46,6 +46,6 @@
  * number, 8 bits for minor and 8 bits for patch. Version 1.2.3
  * becomes 0x010203.
  */
-#define NGTCP2_VERSION_NUM 0x000f00
+#define NGTCP2_VERSION_NUM 0x001000
 
 #endif /* VERSION_H */