Fix X509 field bounds and optional-field consumption - #167
Merged
Merged
Conversation
…N-128..N-130, E-234) test_x509_field_bounds re-encodes real certificates with one field changed and parses each with _nx_secure_x509_certificate_parse() flush against 128 KB of PROT_NONE, one forked child per case, checking the status, that the whole certificate was consumed, and that the signature pointer is the signature field's. Seven cases: RSA and EC certificates as issued (the EC one generated by openssl, CN=n129.test, embedded); v3 certificates with a 4-byte and a 600-byte issuerUniqueID (both must parse whole); an empty EC public key, an empty signature bit string and an empty version (rejected). Pairs with tinic/netxduo zz9k/fix-n128-n130-x509 2cf6e412, off fork master 4ff7e4a4. Off main f215e30; the gitlink is NOT moved. Against 4ff7e4a4's x509.c 5 of the 7 fail (one faults past the certificate); with the fix all pass, 64- and 32-bit. Census 543 -> 544 (all hosts); if N-115's branch lands first it is 545. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Integrate independently reviewed NetX defce9ded517f092bb6c9acc9db4d3026b4269bd. Reject empty EC public keys, signatures and version fields before reading or subtracting their lengths; consume unique IDs exactly once and validate extension consumption. Adds the maintained field-bounds contract and preserves prior TLS contracts. Fresh focused ASan/UBSan tests: 7/7 passed. Production m68000 and m68020 compiles with Werror passed. Independent source/fixture review completed. Full required CI remains the merge gate. Coverage is bounded native parser contracts, not whole-handshake or target runtime proof.