Validate TLS ClientHello group and signature lists (N115) - #164
Merged
Merged
Conversation
…115) test_clienthello_lists drives _nx_secure_tls_proc_clienthello_sec_sa_extension() with one extension flush against a PROT_NONE page, one forked child per case. Nine cases: supported_groups well-formed (P-256 chosen over P-384), odd at the end, longer than the extension, and twelve unsupported groups whose list length 0x0018 must not be read as P-384; TLS 1.2 and 1.3 signature_algorithms well-formed (ECDSA-SHA256 chosen), odd at the end, and (1.3) longer than the extension. Pairs with tinic/netxduo zz9k/fix-n115-clienthello-lists cb9bb2e7. Stacked on fix/n116-remote-cert-bounds afa1f76; the gitlink is NOT moved. Against the unfixed parser (fork master a2d8512e) 6 of the 9 fail (3 fault past the extension, 3 accept a malformed list or pick the phantom P-384); with the fix all pass. Census 543 -> 544, all hosts. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes
Verification
Primary independently read the exact production change, complete maintained fixture and all internal helper references. The SAME ASan/UBSan no-recover fixture fails 6/9 cases on current main’s 4ff7e4a4 parser and passes 9/9 on the reviewed integration. Combined X.509, CertificateRequest, Certificate and ClientHello focused CTest: 4/4 passed. Actual production m68000 and m68020 compile commands with -Wall -Wextra -Werror passed; bash -n and diff check passed.
These are bounded local guard-page contracts with valid negotiation controls, not live network or full handshake/cryptographic verification. Additional independent source review and ordinary exact PR CI are required before merging. No emulator/hardware, toolchain, release or public API change.