Skip to content

Validate TLS ClientHello group and signature lists (N115) - #164

Merged
tinic merged 2 commits into
mainfrom
codex/audit-clienthello-lists
Oct 2, 2026
Merged

tinic merged 2 commits into
mainfrom
codex/audit-clienthello-lists

Conversation

@tinic

@tinic tinic commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Changes

  • Pin reviewed NetX Duo 76c67564, preserving the HKDF and certificate-parser repairs.
  • Require whole, even group/signature lists before walking them; do not interpret the group-list length as a group. Propagate the internal TLS 1.3 helper error without changing public ABI.
  • Add the maintained ClientHello contract and one test to the census; concise user-facing changelog only.

Verification

Primary independently read the exact production change, complete maintained fixture and all internal helper references. The SAME ASan/UBSan no-recover fixture fails 6/9 cases on current main’s 4ff7e4a4 parser and passes 9/9 on the reviewed integration. Combined X.509, CertificateRequest, Certificate and ClientHello focused CTest: 4/4 passed. Actual production m68000 and m68020 compile commands with -Wall -Wextra -Werror passed; bash -n and diff check passed.

These are bounded local guard-page contracts with valid negotiation controls, not live network or full handshake/cryptographic verification. Additional independent source review and ordinary exact PR CI are required before merging. No emulator/hardware, toolchain, release or public API change.

tinic and others added 2 commits October 2, 2026 14:50
…115)

test_clienthello_lists drives _nx_secure_tls_proc_clienthello_sec_sa_extension()
with one extension flush against a PROT_NONE page, one forked child per
case.  Nine cases: supported_groups well-formed (P-256 chosen over P-384),
odd at the end, longer than the extension, and twelve unsupported groups
whose list length 0x0018 must not be read as P-384; TLS 1.2 and 1.3
signature_algorithms well-formed (ECDSA-SHA256 chosen), odd at the end, and
(1.3) longer than the extension.

Pairs with tinic/netxduo zz9k/fix-n115-clienthello-lists cb9bb2e7.
Stacked on fix/n116-remote-cert-bounds afa1f76; the gitlink is NOT moved.
Against the unfixed parser (fork master a2d8512e) 6 of the 9 fail (3 fault
past the extension, 3 accept a malformed list or pick the phantom P-384);
with the fix all pass.  Census 543 -> 544, all hosts.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@tinic
tinic merged commit 5f93a1a into main Oct 2, 2026
42 of 43 checks passed
@tinic
tinic deleted the codex/audit-clienthello-lists branch October 2, 2026 22:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant