docs(rv2-tls): rv2 9 phase B (HKDF key schedule) landed
- HKDF-Extract/Expand + Expand-Label over hmac_sha256, KAT-gated (RFC 5869 + 8446); status -> in-progress; ladder A+B done. Board synced (cherry picked from commit e24b8ec6d838fc66848864c2a0974205aaa9b4be)
This commit is contained in:
parent
36ce2332ef
commit
aff8ffdf14
2 changed files with 3 additions and 3 deletions
|
|
@ -1543,7 +1543,7 @@ starts. Edges in [dependency graph section 6](../00-dependency-graph.md).
|
|||
| 6 | [term.size + term.width](runtime-v2/06-term-size-width.md) | ✅ **DONE 2026-09-02** — TIOCGWINSZ read twin (nil = not a tty) and libc wcwidth under C.UTF-8; the only runtime work the whole wmux parity ladder needs |
|
||||
| 7 | [observability](runtime-v2/07-observability.md) | ⬜ `refine` — **moved here 2026-09-06** from language iteration 30 (`was_language_iteration: 30`). Runtime metrics/gauges, a `pprof`-equivalent profile, stack-trace-on-trap; consumers named (porch [8](porch/08-static-and-lifecycle.md)/[39](language-runtime-database/39-web-framework-parity.md), databasev2 [5](databasev2/05-bounded-tables-eviction.md), the limiter's lazy expiry). Forks: counters-only vs profiling, exposition format, pull vs push, trace-on-trap as a separable first slice. Stretches the track's charter (instrumentation, not processes/terminals/signals) — noted in the story |
|
||||
| 8 | [symmetric cipher (AEAD)](runtime-v2/08-symmetric-cipher.md) | 🔄 **in-progress** — the **first rung of the TLS ladder** (gates rv2 9). **Phases A + B + C LANDED 2026-09-08**: A ChaCha20-Poly1305 (ids 111/112, RFC 8439 §2.8.2); B AES-128/256-GCM (ids 113/114) via AES-NI+PCLMULQDQ; C portable constant-time software AES-GCM fallback (S-box via GF-inverse ladder, bit-by-bit GHASH) — AES-GCM now on any CPU, dispatched hw-or-sw. All hand-rolled, constant-time, both AES paths NIST cases 4 & 16 byte-exact, KAT-gated in test_crypto (**48/0**), ASan/UBSan clean. Remaining: D cookie wrapper → E gate (ARMv8 hw path deferred). Consumers: rv2 9 TLS + porch encrypted cookies |
|
||||
| 9 | [in-process TLS](runtime-v2/09-in-process-tls.md) | ✅ **`ready` 2026-09-07** — TLS **both directions**, **retiring the "TLS is the proxy's job" doctrine** (34/38/porch). Locked: **hand-roll TLS 1.3** (no vendored lib — keeps the zero-dep binary, raises the risk), **1.3-only**, **RSA+ECDSA+full X.509** cert verification (to reach real APIs). Decomposed into a bottom-up **phase ladder**: A AEAD (=rv2 8, forces AES-GCM there) → B HKDF → C X25519 → D signatures/RSA → E ASN.1/X.509 → F record+FSM client → G server. The project's **highest-risk** work; mandatory reference-tested/constant-time/negative-test gates. `net.connect` (110) landed; C/D/E may each split into own iterations |
|
||||
| 9 | [in-process TLS](runtime-v2/09-in-process-tls.md) | 🔄 **in-progress** (`ready` 2026-09-07) — TLS **both directions**, **retiring the "TLS is the proxy's job" doctrine** (34/38/porch). Locked: **hand-roll TLS 1.3**, **1.3-only**, **RSA+ECDSA+full X.509**. Ladder: **A AEAD ✅ (=rv2 8 A–C) → B HKDF ✅ (2026-09-08, RFC 5869 + 8446 Expand-Label, KAT-gated)** → C X25519 → D signatures/RSA → E ASN.1/X.509 → F record+FSM client → G server. `net.connect` (110) landed. The project's **highest-risk** work; mandatory reference-tested/constant-time/negative-test gates; C/D/E may each split into own iterations |
|
||||
|
||||
### ▸ wmux — the terminal multiplexer track
|
||||
|
||||
|
|
|
|||
|
|
@ -1,7 +1,7 @@
|
|||
---
|
||||
track: runtime-v2
|
||||
iteration: "9"
|
||||
status: pending
|
||||
status: in-progress
|
||||
readiness: ready
|
||||
---
|
||||
|
||||
|
|
@ -74,7 +74,7 @@ they may split into their own runtime-v2 iterations as they are picked up.
|
|||
| Phase | Delivers | Notes |
|
||||
| --- | --- | --- |
|
||||
| A — AEAD | AES-128/256-GCM (TLS 1.3 mandates AES-128-GCM) and ChaCha20-Poly1305 | **is runtime-v2 [8](08-symmetric-cipher.md)** — so 8 must include AES-GCM, not only ChaCha; this rung consumes it |
|
||||
| B — key schedule | HKDF-Extract/Expand on iteration 34's HMAC, HKDF-Expand-Label, the TLS 1.3 secret derivation | pure `.wo`-adjacent C over existing HMAC |
|
||||
| B — key schedule | ✅ **LANDED 2026-09-08** — `wo_hkdf_sha256_extract`/`expand` (RFC 5869) + `expand_label` (RFC 8446 §7.1), internal C over `hmac_sha256`; SHA-256 (the mandatory suites' hash; SHA-384 a later add). KAT-gated in `test_crypto.c` (RFC 5869 case 1 + Expand-Label vectors), ASan/UBSan clean. No builtin, no compiler change |
|
||||
| C — key exchange | X25519 (RFC 7748), constant-time | new primitive; the ECDHE shared secret feeding B |
|
||||
| D — signatures | RSA-PSS / RSA-PKCS#1v1.5 (bignum modexp) + ECDSA-P256, over the transcript and the chain | the hardest rung; RSA bignum + constant-time |
|
||||
| E — X.509 | ASN.1/DER parser, chain validation to a trust anchor, dates, hostname/SAN, system CA bundle | notoriously bug-prone; consumes D |
|
||||
|
|
|
|||
Loading…
Reference in a new issue