writeonce/runtime/test
shoney.arickathil 3a1ba15851 feat(tls): X.509 basicConstraints + EKU chain hardening (rv2 9 F3c-net decision 6)
- crypto.c: x509_find_ext (generic extension walker) + wo_x509_basic_constraints
  (cA / pathLenConstraint, absent => not a CA) + wo_x509_eku_serverauth_ok
  (EKU absent, serverAuth, or anyEKU => usable; else not)
- wo_tls_verify_chain enforces decision 6: the leaf must be server-usable
  (EKU), every server-sent issuer and the signing anchor must be a CA
  (basicConstraints CA:TRUE) with a pathLenConstraint covering the
  intermediates below it — stops a leaf masquerading as a CA
- gen_x509.py extended (folds in the wildcard leaf, adds EKU clientAuth-only,
  EKU serverAuth, a non-CA intermediate + a leaf issued under it); vectors
  regenerated
- KATs: extractors (test_crypto 104) + chain enforcement (test_tls 103) —
  EKU serverAuth accepted, clientAuth-only rejected, leaf-under-non-CA
  rejected though every signature verifies; existing chains still pass.
  ASan/UBSan clean

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
(cherry picked from commit 3811418014c2c8d9bc3a9464256f52104261b1b9)
2026-09-15 01:15:31 +02:00
..
.gitkeep feat(runtime): wovm VM core (Iteration 2) 2026-08-10 09:35:55 +02:00
cli_smoke.sh feat(runtime): wovm VM core (Iteration 2) 2026-08-10 09:35:55 +02:00
gen_tls_record.py feat(tls): TLS 1.3 record layer (rv2 9 phase F1) 2026-09-15 01:15:31 +02:00
gen_x509.py feat(tls): X.509 basicConstraints + EKU chain hardening (rv2 9 F3c-net decision 6) 2026-09-15 01:15:31 +02:00
mkwob.c feat(runtime): wovm VM core (Iteration 2) 2026-08-10 09:35:55 +02:00
t.h feat(runtime): wovm VM core (Iteration 2) 2026-08-10 09:35:55 +02:00
test_arena.c feat(runtime): wovm VM core (Iteration 2) 2026-08-10 09:35:55 +02:00
test_borrow.c feat(runtime): wovm VM core (Iteration 2) 2026-08-10 09:35:55 +02:00
test_builtin.c feat(runtime): wovm VM core (Iteration 2) 2026-08-10 09:35:55 +02:00
test_cont.c feat(runtime): wovm VM core (Iteration 2) 2026-08-10 09:35:55 +02:00
test_crypto.c feat(tls): X.509 basicConstraints + EKU chain hardening (rv2 9 F3c-net decision 6) 2026-09-15 01:15:31 +02:00
test_cycle.c feat(runtime): incremental tri-color mark-sweep replaces RC (7b Phase 3a) 2026-08-19 16:52:48 +02:00
test_fiber.c feat(runtime): fiber run queue + reduction budget (arc T2) 2026-08-20 07:03:40 +02:00
test_icall.c feat(runtime): wovm VM core (Iteration 2) 2026-08-10 09:35:55 +02:00
test_loader.c feat(runtime): wovm VM core (Iteration 2) 2026-08-10 09:35:55 +02:00
test_mailbox.c feat: bounded mailboxes + WO_T_ACTOR (trap 13); try-arm place-copy fix 2026-08-23 01:05:13 +02:00
test_obj.c feat(runtime): incremental tri-color mark-sweep replaces RC (7b Phase 3a) 2026-08-19 16:52:48 +02:00
test_objops.c feat(runtime): wovm VM core (Iteration 2) 2026-08-10 09:35:55 +02:00
test_proc.c feat(rt2): spawn_pty + resize — a child that believes it owns a terminal 2026-09-15 01:15:30 +02:00
test_rc.c feat(runtime): incremental tri-color mark-sweep replaces RC (7b Phase 3a) 2026-08-19 16:52:48 +02:00
test_table.c feat: O(1) read path — index probe wired end to end 2026-08-22 16:44:56 +02:00
test_term.c feat(rt2): term.size + term.width — the wmux ladder's last runtime asks 2026-09-15 01:15:30 +02:00
test_tls.c feat(tls): X.509 basicConstraints + EKU chain hardening (rv2 9 F3c-net decision 6) 2026-09-15 01:15:31 +02:00
test_unwind.c feat: retire RC from the emitter and the format — .wob v4 (7b Phase 3b) 2026-08-19 17:07:43 +02:00
test_vm.c feat(runtime): wovm VM core (Iteration 2) 2026-08-10 09:35:55 +02:00
test_wal.c docs(db2-migrate): close out iteration 12 2026-08-31 21:54:27 +02:00
test_wobbuild.c feat(runtime): wovm VM core (Iteration 2) 2026-08-10 09:35:55 +02:00
tls_driver_vectors.h feat(tls): sans-io TLS 1.3 client handshake driver (rv2 9 phase F3c-core) 2026-09-15 01:15:31 +02:00
tls_hs_vectors.h feat(tls): offline handshake verification (rv2 9 phase F3b) 2026-09-15 01:15:31 +02:00
tls_record_vectors.h feat(tls): TLS 1.3 record layer (rv2 9 phase F1) 2026-09-15 01:15:31 +02:00
wob_build.c feat: secondary indexes + @unique trap (iteration 9, Task 4; wob v3) 2026-08-15 12:57:32 +02:00
wob_build.h feat(runtime): wovm VM core (Iteration 2) 2026-08-10 09:35:55 +02:00
x509_vectors.h feat(tls): X.509 basicConstraints + EKU chain hardening (rv2 9 F3c-net decision 6) 2026-09-15 01:15:31 +02:00