writeonce/scripts
shoney.arickathil e1d29d63e4 feat(tls): net.accept_tls — inbound TLS 1.3 termination (rv2 9 phase G3)
- net.accept_tls(listener, certfile, keyfile) -> Int (id 118, WO_B_MAX->118):
  accept (parks like net.accept), load+cache the server identity per path in
  the shard, run the blocking deadline-bounded server handshake, return a TLS
  conn fd. Real clients terminate against the runtime — no front proxy
- wo_tls_conn refactored: holds the negotiated application keys (not an
  embedded driver), so read_tls/write_tls serve both client and server
  connections via the record layer; the handshake drivers are transient
  (heap, ~100KB, freed after). net.close drains a TLS conn's inbound before
  close() so it sends FIN not RST (clients send close_notify)
- server handshake loops past the client's change_cipher_spec (TLS 1.3
  middlebox-compat) before its Finished — the openssl-interop fix
- private-key file loading: wo_tls_pem_one (any-label PEM block) +
  wo_pkey_parse; per-shard identity cache (vm->tls_id), freed in reap
- docs/examples/tls-server + `just tls-server`: openssl s_client validates
  our hand-rolled server (EC + RSA certs) and gets the reply — 4/0; the
  outbound `just tls` gate stays 5/0 through the refactor
- wiring: wob.h, loader.c, builtin.c dispatch, types.ml, vm.h

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
(cherry picked from commit 2d4c30033c36c88de5b7ab7cc1042c9537238297)
2026-09-15 01:16:13 +02:00
..
chat-accept.sh feat(gates): example apps log to /tmp/<example-app>.log so it can be tailed 2026-08-27 23:53:10 +02:00
db-actor-accept.sh fix(lang41): an unadopted shard must not impersonate shard 0 2026-09-15 01:15:30 +02:00
db-bench.py feat(db2-keys): gate the residency measurement, close out task 7 2026-08-30 20:38:03 +02:00
deps-accept.sh test: deps-accept — iteration 15's gate (Task 4) 2026-08-19 19:21:32 +02:00
employee-accept.sh feat: FK restrict on delete + employee sample runs; group-by parked (9b) 2026-08-16 18:37:23 +02:00
fibers-accept.sh feat: cross-shard actors — placement, envelopes, home-routed frees, WO-E222 (arc T6) 2026-08-20 12:06:13 +02:00
install-accept.sh feat: installable toolchain — version, wovm self-locate, dist tarball 2026-08-18 01:19:20 +02:00
install-readme.tmpl.md feat: installable toolchain — version, wovm self-locate, dist tarball 2026-08-18 01:19:20 +02:00
linkcheck.py docs: audit all markdown against the code, fix findings, flatten status folders 2026-08-26 19:20:22 +02:00
log-watcher-accept.sh feat(gates): example apps log to /tmp/<example-app>.log so it can be tailed 2026-08-27 23:53:10 +02:00
mkdist.sh feat: installable toolchain — version, wovm self-locate, dist tarball 2026-08-18 01:19:20 +02:00
oop-e2e.sh feat: cross-shard actors — placement, envelopes, home-routed frees, WO-E222 (arc T6) 2026-08-20 12:06:13 +02:00
residency-accept.sh fix(db2-delta): refuse resident:keys with no WO_DATA at runtime 2026-08-30 20:38:03 +02:00
single-binary-smoke.sh feat: milestone 1 complete — .wob emitter, conformance corpus, single binary; GC redesign specced 2026-08-11 19:31:26 +02:00
site-accept.sh refactor(site-submodule): docs/examples/site becomes a submodule 2026-08-30 22:02:55 +02:00
skill-catalog-accept.sh feat(query-corpus): iteration 9g corpus #1 — skillhost needs no new query grammar 2026-09-15 01:15:30 +02:00
subprocess-accept.sh feat(lang42): subprocess example + gate 2026-09-01 22:19:25 +02:00
tls-accept.sh test(tls): live acceptance gate for net.connect_tls (rv2 9 F3c-net phase 4) 2026-09-15 01:15:52 +02:00
tls-server-accept.sh feat(tls): net.accept_tls — inbound TLS 1.3 termination (rv2 9 phase G3) 2026-09-15 01:16:13 +02:00
web-app-accept.sh fix(porch-store): gate legs pin the header-case and cross-path digest bugs 2026-09-15 01:15:30 +02:00