Backport upstream TLS record ownership fix - #172
Merged
Merged
Conversation
netxduo 9663fe4b -> 7bf58f91: upstream 5128818d. The NX_SECURE_KEY_CLEAR wipe in _nx_secure_tls_send_record() runs only when nx_tcp_socket_send() failed; once TCP has accepted the chain the record path no longer touches it. tests/x509/test_send_record_ownership compiles the send path against stubs. An accepted chain is stamped and snapshotted by the TCP stub and must be identical after the call; a refused one (not connected, window overflow, queue full) must come back wiped with the TCP status; an inactive session wipes nothing. Nothing is released, so the old code runs safely: 9663fe4b 21 checks, 2 failures (both accepted cases). Here: 0. Host census 550 -> 551. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Backport upstream 5128818d5efd1b1e3bc8c0014140c0e2600fe3c6 for GHSA-8w5x-ff58-2fr2. With NX_SECURE_KEY_CLEAR enabled, a successful TCP send transfers ownership of the record packet chain; TLS must not wipe it afterward. Failed-send key clearing and status propagation remain intact.
Exact vendor tip: 7bf58f91a53ad6d73ccad2da7edfbaaac21f430f. Maintained benign ownership contract stamps and snapshots still-allocated packets; no freed-memory or intrusive reproduction. Focused owner evidence inspected by primary: strict m32 and LP64 ASan/UBSan 21 checks / 0 failures; safe old-source controls 21 / 2 (successful send ownership violations); changed-file m68k Werror compile passed. Registered test census increases from 550 to 551; only the focused test was executed locally.
Independent exact-diff review and normal required CI pending. Standalone vendor regression CI remains a separately assigned build-repair task; these focused results are not a standalone regression pass. Full upstream release integration remains subsequent reviewed work.