Skip to content

Preserve TLS 1.3 builder errors and packet ownership (N107–N109) - #165

Merged
tinic merged 3 commits into
mainfrom
codex/audit-tls13-builder-contract
Oct 2, 2026
Merged

tinic merged 3 commits into
mainfrom
codex/audit-tls13-builder-contract

Conversation

@tinic

@tinic tinic commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Changes

  • Pin reviewed NetX Duo 2f9be697, preserving earlier parser and key-schedule repairs. Check failed server builders, release caller-owned unsent packets, and bound transcript digest rows.
  • Add maintained benign driver-fault contracts in separate shipping and optional client-certificate configurations, plus transcript boundary/valid SHA-256 controls. Census 544 → 546; no weakened CI.
  • Concise user-facing changelog only.

Verification and limits

Primary independently reviewed source, caller/record ownership and complete fixtures. SAME shipping-layout fault fixture: old current-main parser fails 12 assertions across eight cases; fixed passes all eight with assertions and ASan/UBSan active. Optional client-certificate fixture passes nine cases; old comparison with only local assertion suppression fails 15 assertions (the original optional CertificateRequest assertion otherwise spins). No assertion suppression in maintained tests or shipping code. Old transcript test triggers UBSan on row index 5; fixed accepts SHA-256 control and rejects oversized/index boundaries. Combined six focused sanitizer CTests passed. Actual production m68000 and m68020 Werror compiles passed for all three source files.

Independent zz9k source/ownership/fixture review: no production blocker; separate shipping fixture was added following its coverage suggestion, amendment review pending. Required exact PR CI must pass before merge.

These are selected driver states with benign builder/record stubs, not complete handshakes, live traffic or real packet-pool execution. Server CertificateRequest is compiled out of shipping configuration and covered separately. Transcript index/long-hash guards are latent under current literal indices and own SHA-256 suites. No emulator/hardware, public ABI, toolchain or release change.

tinic and others added 3 commits October 2, 2026 15:22
_nx_secure_tls_1_3_transcript_hash_save on a real TLS 1.3 session, with
the five transcript-hash rows and the first 64 bytes of
nx_secure_tls_handshake_cache after them guard-filled:

- index 4, SHA-256: saves SHA-256("abc") (FIPS 180-2 B.1) into row 4
  only;
- index 5: NX_INVALID_PARAMETERS, nothing written;
- a SHA-384 ciphersuite hash: NX_INVALID_PARAMETERS, nothing written.

Labels carry an "n108:" prefix.  Needs tinic/netxduo bda9d37d: on
5f6906db "index 5 refused", "index 5 leaves the cache intact" and
"SHA-384 refused" fail.  The gitlink stays at 0fb76b63, which lacks
bda9d37d; the vendor integration has to merge bda9d37d onto 0fb76b63.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…07/N-109)

Drive the two TLS 1.3 handshake drivers in the states that reach the
three client builders (send_certificate, send_certificate_verify,
send_finished) and the four server builders (send_certificate_request,
send_certificate, send_certificate_verify, send_finished) against a
minimal stub surface, and assert the benign-fault contract for each:

  * the driver returns the failed builder's status unchanged,
  * the packet allocated for the failed builder is released exactly
    once by the caller (no leak, no double-free), and
  * no record is sent for the failed builder.

A record-send failure is injected separately and asserts the driver does
NOT release the packet itself (the record layer owns that release).

Links ONLY the two drivers under test against hand-written stubs -- no
NX_PACKET pools, no record layer, no ThreadX scheduler, no broad
netstack/guest. Fails against the current netxduo pin (0fb76b63) and
passes once pinned to bda9d37d.

Co-Authored-By: Claude Code <noreply@anthropic.com>
@tinic
tinic merged commit a0a13f3 into main Oct 2, 2026
42 of 43 checks passed
@tinic
tinic deleted the codex/audit-tls13-builder-contract branch October 2, 2026 22:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant