docs(rv2-aead): rv2 8 phase A (ChaCha20-Poly1305) landed
- status -> in-progress; phase A marked landed (matches RFC 8439 §2.8.2, KAT-gated in test_crypto, ASan clean). Remaining B/C/D/E. Board synced (cherry picked from commit db5bdf3c3cac31c0d2be60027e0e2bf9fe8309c1)
This commit is contained in:
parent
ac52c3fdb5
commit
da840a5be6
2 changed files with 3 additions and 3 deletions
|
|
@ -1542,7 +1542,7 @@ starts. Edges in [dependency graph section 6](../00-dependency-graph.md).
|
|||
| 5 | [fd passing](runtime-v2/05-fd-passing.md) | ✅ **DONE 2026-09-02** — `net.send_fd`/`recv_fd`/`connect_unix`; a tty crossed the socket, was raw'd through the received copy and restored at destroy — the wmux handover in miniature |
|
||||
| 6 | [term.size + term.width](runtime-v2/06-term-size-width.md) | ✅ **DONE 2026-09-02** — TIOCGWINSZ read twin (nil = not a tty) and libc wcwidth under C.UTF-8; the only runtime work the whole wmux parity ladder needs |
|
||||
| 7 | [observability](runtime-v2/07-observability.md) | ⬜ `refine` — **moved here 2026-09-06** from language iteration 30 (`was_language_iteration: 30`). Runtime metrics/gauges, a `pprof`-equivalent profile, stack-trace-on-trap; consumers named (porch [8](porch/08-static-and-lifecycle.md)/[39](language-runtime-database/39-web-framework-parity.md), databasev2 [5](databasev2/05-bounded-tables-eviction.md), the limiter's lazy expiry). Forks: counters-only vs profiling, exposition format, pull vs push, trace-on-trap as a separable first slice. Stretches the track's charter (instrumentation, not processes/terminals/signals) — noted in the story |
|
||||
| 8 | [symmetric cipher (AEAD)](runtime-v2/08-symmetric-cipher.md) | ✅ **`ready` 2026-09-08** — the **first rung of the TLS ladder** (gates rv2 9). Locked: **both** AES-GCM (128/256, TLS-mandatory) **and** ChaCha20-Poly1305; **AES-NI/ARMv8 hardware + bitsliced software fallback** (constant-time, zero dep); **caller-supplied nonce** (`seal(key,nonce,aad,pt)`/`open`→`?Bytes`), AES variant by key length; raw key + length check; hand-rolled. Phases: A ChaCha → B hardware AES-GCM → C software AES → D cookie wrapper (random nonce via `random_bytes`) → E gate (RFC 8439 + NIST vectors, ASan). Consumers: rv2 9 TLS + porch encrypted cookies. New ids from 111 |
|
||||
| 8 | [symmetric cipher (AEAD)](runtime-v2/08-symmetric-cipher.md) | 🔄 **in-progress** — the **first rung of the TLS ladder** (gates rv2 9). **Phase A (ChaCha20-Poly1305) LANDED 2026-09-08**: `chacha20poly1305_seal`/`open` (ids 111/112), hand-rolled, matches RFC 8439 §2.8.2 byte-for-byte, KAT-gated in test_crypto (24/0), ASan/UBSan clean. Remaining: B hardware AES-GCM → C software AES → D cookie wrapper → E gate. Also locked: both ciphers, AES-NI+bitslice fallback, caller-supplied nonce, raw key. Consumers: rv2 9 TLS + porch encrypted cookies |
|
||||
| 9 | [in-process TLS](runtime-v2/09-in-process-tls.md) | ✅ **`ready` 2026-09-07** — TLS **both directions**, **retiring the "TLS is the proxy's job" doctrine** (34/38/porch). Locked: **hand-roll TLS 1.3** (no vendored lib — keeps the zero-dep binary, raises the risk), **1.3-only**, **RSA+ECDSA+full X.509** cert verification (to reach real APIs). Decomposed into a bottom-up **phase ladder**: A AEAD (=rv2 8, forces AES-GCM there) → B HKDF → C X25519 → D signatures/RSA → E ASN.1/X.509 → F record+FSM client → G server. The project's **highest-risk** work; mandatory reference-tested/constant-time/negative-test gates. `net.connect` (110) landed; C/D/E may each split into own iterations |
|
||||
|
||||
### ▸ wmux — the terminal multiplexer track
|
||||
|
|
|
|||
|
|
@ -1,7 +1,7 @@
|
|||
---
|
||||
track: runtime-v2
|
||||
iteration: "8"
|
||||
status: pending
|
||||
status: in-progress
|
||||
readiness: ready
|
||||
---
|
||||
|
||||
|
|
@ -78,7 +78,7 @@ work; TLS's ChaCha suite and the cookie consumer unblock at phase A.
|
|||
|
||||
| Phase | Delivers |
|
||||
| --- | --- |
|
||||
| A — ChaCha20-Poly1305 | `chacha20poly1305_seal`/`open` (RFC 8439), the easy constant-time cipher; unblocks cookies and TLS's ChaCha suite |
|
||||
| A — ChaCha20-Poly1305 | ✅ **LANDED 2026-09-08** — `chacha20poly1305_seal`/`open` (ids 111/112, bare-name crypto family). Hand-rolled ChaCha20 + poly1305-donna-32 + the RFC 8439 §2.8 AEAD, caller-supplied 12-byte nonce, 32-byte key, constant-time tag compare, `open` returns nil on auth failure. Matches the RFC 8439 §2.8.2 vector byte-for-byte; gated in `test/test_crypto.c` (§2.5.2 Poly1305 + §2.8.2 seal/open/tamper), ASan/UBSan clean |
|
||||
| B — AES-GCM via hardware | `aes_gcm_seal`/`open` on AES-NI + CLMUL (x86-64) / ARMv8 crypto ext — constant-time by hardware; TLS's mandatory suite |
|
||||
| C — AES-GCM software fallback | bitsliced constant-time AES + constant-time GHASH for CPUs without the extension; same builtins, dispatched at runtime |
|
||||
| D — the cookie wrapper | an `encryptcookie`-equivalent on porch [2](../porch/02-randomness-and-cookies.md)'s cookie machinery: random nonce (from `random_bytes`) prepended to the ciphertext, default ChaCha |
|
||||
|
|
|
|||
Loading…
Reference in a new issue