Skip to content

Fix X509 field bounds and optional-field consumption - #167

Merged
tinic merged 2 commits into
mainfrom
codex/audit-x509-field-bounds
Oct 3, 2026
Merged

tinic merged 2 commits into
mainfrom
codex/audit-x509-field-bounds

Conversation

@tinic

@tinic tinic commented Oct 3, 2026

Copy link
Copy Markdown
Owner

Integrate independently reviewed NetX defce9ded517f092bb6c9acc9db4d3026b4269bd. Reject empty EC public keys, signatures and version fields before reading or subtracting their lengths; consume unique IDs exactly once and validate extension consumption. Adds the maintained field-bounds contract and preserves prior TLS contracts. Fresh focused ASan/UBSan tests: 7/7 passed. Production m68000 and m68020 compiles with Werror passed. Independent source/fixture review completed. Full required CI remains the merge gate. Coverage is bounded native parser contracts, not whole-handshake or target runtime proof.

tinic and others added 2 commits October 2, 2026 16:39
…N-128..N-130, E-234)

test_x509_field_bounds re-encodes real certificates with one field changed
and parses each with _nx_secure_x509_certificate_parse() flush against
128 KB of PROT_NONE, one forked child per case, checking the status, that
the whole certificate was consumed, and that the signature pointer is the
signature field's.  Seven cases: RSA and EC certificates as issued (the
EC one generated by openssl, CN=n129.test, embedded); v3 certificates with a
4-byte and a 600-byte issuerUniqueID (both must parse whole); an empty EC
public key, an empty signature bit string and an empty version (rejected).

Pairs with tinic/netxduo zz9k/fix-n128-n130-x509 2cf6e412, off fork
master 4ff7e4a4.  Off main f215e30; the gitlink is NOT moved.  Against
4ff7e4a4's x509.c 5 of the 7 fail (one faults past the certificate);
with the fix all pass, 64- and 32-bit.  Census 543 -> 544 (all hosts); if
N-115's branch lands first it is 545.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@tinic
tinic merged commit 2b3413f into main Oct 3, 2026
42 of 43 checks passed
@tinic
tinic deleted the codex/audit-x509-field-bounds branch October 3, 2026 01:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant