diff --git a/docs/00-dependency-graph.md b/docs/00-dependency-graph.md index ec3e29e..6aefa4c 100644 --- a/docs/00-dependency-graph.md +++ b/docs/00-dependency-graph.md @@ -160,12 +160,12 @@ flowchart TD XFF["X-Forwarded-For/-Proto parsing"]:::ready ACCEPT["Accept-driven negotiation"]:::ready - NETSEAM["GATE: net runtime seams (timeouts, unix socket, peer address)"]:::gate + NETSEAM["GATE: net runtime seams (timeouts, unix socket, peer address) โ€” story 35 owns"]:::gate TMOUT["read/write/idle timeouts"]:::blocked UNIX["unix socket binding"]:::blocked PEERV["trusted-proxy PEER verification"]:::blocked - CRYPTO["GATE: crypto fork โ€” C builtins vs language bit ops (brainstorm); digests want iteration 19's Bytes"]:::gate + CRYPTO["GATE: story 34 crypto โ€” C builtins vs pure-.wo (bitwise landed with 36, both possible; brainstorm decides); carriers (Bytes, base64) landed with 19"]:::gate SHA["SHA-256/512, HMAC, CRC32"]:::blocked ETAG["ETag + conditional requests"]:::blocked COOKIE["signed cookies"]:::blocked @@ -175,7 +175,7 @@ flowchart TD JWT["JWT HS256 (HARD STOP after)"]:::blocked RADIX["radix-tree routing"]:::blocked - I9E3["GATE: 22 measures the linear scan"]:::gate + I9E3["GATE: router scan unmeasured โ€” 22's harness landed but benched the DB, not the router; perf-targets entry first"]:::gate STORAGE["storage-integration rows: migrations (future story), eager loading + tenant roots (query-surface work, 9-series)"]:::blocked diff --git a/docs/examples/writeonce-framework/README.md b/docs/examples/writeonce-framework/README.md index 4dd6220..588b043 100644 --- a/docs/examples/writeonce-framework/README.md +++ b/docs/examples/writeonce-framework/README.md @@ -82,16 +82,16 @@ first (pure `.wo` cannot express it yet). | --- | --- | | HTTP/1.1 parsing | ๐Ÿ”ถ parses + 400-and-survive; STRICT ambiguity rejection (duplicate/conflicting `Content-Length`, oversize checks beyond BODY_MAX) not audited โ€” hardening slice | | Keep-alive | โœ… pipelined-serve / close-when-idle (arc landed 2026-08-21; retirement of close-when-idle rides iteration 24's fiber-per-connection slice) | -| Read/write/idle timeouts | ๐Ÿ”ง `net` has no timeout surface โ€” runtime seam, then a framework knob | +| Read/write/idle timeouts | ๐Ÿ”ง `net` has no timeout surface โ€” story 35 owns the seam (park_deadline infra already exists for sleeps), then a framework knob | | Request size limits | โœ… BODY_MAX bounds headers AND body | -| Unix socket binding | ๐Ÿ”ง `net.listen` is TCP-only โ€” runtime seam | +| Unix socket binding | ๐Ÿ”ง `net.listen` is TCP-only โ€” story 35 owns the seam | | Graceful SIGTERM | โœ… in-flight request completes (blocking model), listener + fds closed, storage is per-commit durable (WAL fdatasync โ€” nothing to checkpoint) | ### Routing | Item | State | | --- | --- | -| Path matching | ๐Ÿ”ถ linear scan, first-match-wins; a radix tree is a performance slice that waits for iteration 22 to MEASURE it first | +| Path matching | ๐Ÿ”ถ linear scan, first-match-wins; a radix tree waits on a MEASUREMENT first โ€” 22's harness landed (benched the DB, not the router); needs a perf-targets register entry | | Method dispatch ยท path params ยท 404 ยท 405+`Allow` | โœ… | | Wildcards | โฌœ only `:param` today; `*rest` capture is a candidate slice | | Precedence rules | ๐Ÿ”ถ registration order IS the rule (documented); specificity-based precedence unneeded until wildcards exist | @@ -104,10 +104,10 @@ first (pure `.wo` cannot express it yet). | Case-insensitive headers ยท query parsing | โœ… (names lowercased on read) | | JSON ยท form-urlencoded ยท multipart | โœ… all three hooks (`json.decode`, `form_values`, `multipart_parts`) | | Content negotiation | ๐Ÿ”ถ `media_type(req)` covers the request side; `Accept`-driven response negotiation โฌœ | -| Trusted-proxy client IP | ๐Ÿ”ถ `X-Forwarded-For/-Proto` parsing is expressible (candidate slice); VERIFYING the peer is the trusted proxy needs a peer-address runtime seam ๐Ÿ”ง | +| Trusted-proxy client IP | ๐Ÿ”ถ `X-Forwarded-For/-Proto` parsing is expressible (candidate slice); VERIFYING the peer is the trusted proxy needs a peer-address seam ๐Ÿ”ง โ€” story 35 owns it | | Status/header setting ยท redirects | โœ… builders + `set_header` | | Lazy body streaming + backpressure ยท streaming responses ยท explicit commit point | โธ UNBLOCKED by the arc (8/11 landed 2026-08-21) โ€” stays parked until its own slice | -| ETag + conditional requests | โฌœ candidate; wants the crypto slice's hashing | +| ETag + conditional requests | โฌœ candidate; wants story 34's digests (bitwise landed with 36 โ€” pure-`.wo` vs C-builtin is 34's brainstorm) | ### Context & middleware diff --git a/docs/stories/language-runtime-database/refine/34-crypto-builtins.md b/docs/stories/language-runtime-database/refine/34-crypto-builtins.md index 4b060ab..e583676 100644 --- a/docs/stories/language-runtime-database/refine/34-crypto-builtins.md +++ b/docs/stories/language-runtime-database/refine/34-crypto-builtins.md @@ -9,13 +9,14 @@ status: refine > [Story โ€” one language, one runtime, one database, one binary](../00-story.md). > > **Inserted 2026-08-22** โ€” the framework ledger's oldest unowned gap -> gets an owner. The language has NO bitwise operators (a settled -> surface decision), so digests cannot be written in `.wo`; the -> ledger's recorded resolution stands: hand-rolled C builtins in the -> runtime โ€” the libc-only doctrine permits hand-rolled crypto, and the -> code is bounded and well-specified. Off the concurrency chain but -> **gates chain position 4**: iteration 24's WebSocket handshake needs -> SHA-1 before chat can land. +> gets an owner. PREMISE UPDATE (same day, post-merge): iteration 36 +> landed bitwise `& | ^ << >>` + hex literals, so digests ARE now +> expressible in pure `.wo` โ€” the original "no bitwise" impossibility +> is gone. The fork is now a real choice for this story's brainstorm: +> hand-rolled C builtins (bounded, fast, libc-only doctrine permits) vs +> pure-`.wo` (no runtime surface growth; interpreter-speed hashing). +> Off the concurrency chain but **gates chain position 4**: iteration +> 24's WebSocket handshake needs SHA-1 before chat can land. ## Why this iteration exists @@ -37,7 +38,8 @@ only the digests are missing. existing builtin). - **HMAC-SHA256** (`key: Bytes, msg: Bytes -> Bytes`) โ€” the one composition real services need (signed tokens, webhook signatures); - writing HMAC in `.wo` is impossible for the same no-bitwise reason. + expressible in `.wo` since iteration 36's bitwise set โ€” C-builtin vs + pure-`.wo` is this story's brainstorm call. - **Test vectors are the acceptance**: FIPS 180 / RFC 2202 / RFC 4231 vectors in a corpus fixture โ€” a digest that "looks right" is worth nothing.