Repository navigation
Bound TLS retry cookies and ClientHello cache (N112/N120/N121) - #166
Merged
Merged
Conversation
…121) test_tls_x509 gains two sections on a zeroed TLS 1.3 session, no traffic. _nx_secure_tls_send_clienthello_extensions() directly: first ClientHello and a cookie-0 retry are byte-identical and fit exactly; a 200-byte cookie fits exactly, then with available_size ending at the cookie it is written to the byte and nothing past it, one byte short or header-only it is rejected with NX_SECURE_TLS_PACKET_BUFFER_TOO_SMALL and nothing at or past the cookie offset is written; a key_share one byte short returns that error (N-120); a 0xFFFF cookie is rejected. _nx_secure_tls_send_handshake_record() with the record layer stubbed: a ClientHello into an empty cache is cached as sent; a prefilled cache takes it exactly; one byte over, a 501-byte ClientHello, and a corrupt cache length above 500 are rejected, the record is not sent, the packet is not released, and everything from nx_secure_tls_handshake_cache_length to the end of the key material is unchanged. The stubs of _nx_secure_tls_send_record and _nx_packet_release live in the test, which keeps nx_secure_tls_send_record.o out of the link. TOPIC-TIP PIN FOR REVIEW ONLY: the gitlink moves to tinic/netxduo fix/hrr-cookie-cache-bounds f5f129d2 so the test passes. Against the current pin 4ff7e4a4, 7 checks fail and the 0xFFFF cookie case faults. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pin reviewed NetX Duo 56f6e58c. Bound the HRR cookie echo and fixed ClientHello cache with subtraction-safe checks; propagate key-share builder failure. No cache expansion, public ABI, hardware, toolchain or release change.
Primary reviewed complete source and maintained fixture, including initial/HRR caller packet ownership and cache reset before retry. SAME maintained fixture against old current-main source fails seven assertions, then ASan refuses the oversized cookie copy (rc134); fixed passes. Combined six focused ASan/UBSan CTests passed. Production m68000 and m68020 Werror compiles passed for both changed files. Independent deepseek-v4 exact review: no blocker.
Conflict resolution retains all previous transcript/key-schedule tests and adds the HRR tests; no CI weakening. Short user-facing changelog only. Required exact PR checks must pass before merge.
Limits: benign native builder/cache tests with record/release stubs, not complete handshakes or live transport. Single-packet cache fixture does not measure chained packets. Small-capacity key-share behavior is qualified by our ordinary pool. Pre-existing TLS1.2 HelloRequest and HRR record-send error ownership issues are separate, not closed by this patch.