Preserve TLS 1.3 builder errors and packet ownership (N107–N109) - #165
Merged
Merged
Conversation
_nx_secure_tls_1_3_transcript_hash_save on a real TLS 1.3 session, with
the five transcript-hash rows and the first 64 bytes of
nx_secure_tls_handshake_cache after them guard-filled:
- index 4, SHA-256: saves SHA-256("abc") (FIPS 180-2 B.1) into row 4
only;
- index 5: NX_INVALID_PARAMETERS, nothing written;
- a SHA-384 ciphersuite hash: NX_INVALID_PARAMETERS, nothing written.
Labels carry an "n108:" prefix. Needs tinic/netxduo bda9d37d: on
5f6906db "index 5 refused", "index 5 leaves the cache intact" and
"SHA-384 refused" fail. The gitlink stays at 0fb76b63, which lacks
bda9d37d; the vendor integration has to merge bda9d37d onto 0fb76b63.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…07/N-109)
Drive the two TLS 1.3 handshake drivers in the states that reach the
three client builders (send_certificate, send_certificate_verify,
send_finished) and the four server builders (send_certificate_request,
send_certificate, send_certificate_verify, send_finished) against a
minimal stub surface, and assert the benign-fault contract for each:
* the driver returns the failed builder's status unchanged,
* the packet allocated for the failed builder is released exactly
once by the caller (no leak, no double-free), and
* no record is sent for the failed builder.
A record-send failure is injected separately and asserts the driver does
NOT release the packet itself (the record layer owns that release).
Links ONLY the two drivers under test against hand-written stubs -- no
NX_PACKET pools, no record layer, no ThreadX scheduler, no broad
netstack/guest. Fails against the current netxduo pin (0fb76b63) and
passes once pinned to bda9d37d.
Co-Authored-By: Claude Code <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes
Verification and limits
Primary independently reviewed source, caller/record ownership and complete fixtures. SAME shipping-layout fault fixture: old current-main parser fails 12 assertions across eight cases; fixed passes all eight with assertions and ASan/UBSan active. Optional client-certificate fixture passes nine cases; old comparison with only local assertion suppression fails 15 assertions (the original optional CertificateRequest assertion otherwise spins). No assertion suppression in maintained tests or shipping code. Old transcript test triggers UBSan on row index 5; fixed accepts SHA-256 control and rejects oversized/index boundaries. Combined six focused sanitizer CTests passed. Actual production m68000 and m68020 Werror compiles passed for all three source files.
Independent zz9k source/ownership/fixture review: no production blocker; separate shipping fixture was added following its coverage suggestion, amendment review pending. Required exact PR CI must pass before merge.
These are selected driver states with benign builder/record stubs, not complete handshakes, live traffic or real packet-pool execution. Server CertificateRequest is compiled out of shipping configuration and covered separately. Transcript index/long-hash guards are latent under current literal indices and own SHA-256 suites. No emulator/hardware, public ABI, toolchain or release change.