writeonce/docs
shoney.arickathil e1d29d63e4 feat(tls): net.accept_tls — inbound TLS 1.3 termination (rv2 9 phase G3)
- net.accept_tls(listener, certfile, keyfile) -> Int (id 118, WO_B_MAX->118):
  accept (parks like net.accept), load+cache the server identity per path in
  the shard, run the blocking deadline-bounded server handshake, return a TLS
  conn fd. Real clients terminate against the runtime — no front proxy
- wo_tls_conn refactored: holds the negotiated application keys (not an
  embedded driver), so read_tls/write_tls serve both client and server
  connections via the record layer; the handshake drivers are transient
  (heap, ~100KB, freed after). net.close drains a TLS conn's inbound before
  close() so it sends FIN not RST (clients send close_notify)
- server handshake loops past the client's change_cipher_spec (TLS 1.3
  middlebox-compat) before its Finished — the openssl-interop fix
- private-key file loading: wo_tls_pem_one (any-label PEM block) +
  wo_pkey_parse; per-shard identity cache (vm->tls_id), freed in reap
- docs/examples/tls-server + `just tls-server`: openssl s_client validates
  our hand-rolled server (EC + RSA certs) and gets the reply — 4/0; the
  outbound `just tls` gate stays 5/0 through the refactor
- wiring: wob.h, loader.c, builtin.c dispatch, types.ml, vm.h

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
(cherry picked from commit 2d4c30033c36c88de5b7ab7cc1042c9537238297)
2026-09-15 01:16:13 +02:00
..
examples feat(tls): net.accept_tls — inbound TLS 1.3 termination (rv2 9 phase G3) 2026-09-15 01:16:13 +02:00
guides docs(site-update): guide for changing the site application 2026-09-15 01:15:30 +02:00
plan docs: jarvis track, runtime-v2 7/8/9, lang-41 fix design, fiber scope-gap 2026-09-15 01:15:31 +02:00
stories docs(rv2-tls): phase G2 server FSM landed 2026-09-15 01:15:52 +02:00
superpowers docs(rt2): close out runtime-v2 1-5 2026-09-15 01:15:30 +02:00
00-code-review.md docs: audit all markdown against the code, fix findings, flatten status folders 2026-08-26 19:20:22 +02:00
00-databasev2-chain-review.md fix(db2-keys): delete on a keys-resident table was memory corruption 2026-08-30 20:37:27 +02:00
00-dependency-graph.md docs(rv2-tls): rv2 9 phase D complete (RSA + ECDSA-P256 verify) 2026-09-15 01:15:31 +02:00
00-doc-audit.md refactor(porch): name the web framework porch, fix the wo.toml identifier claim 2026-08-26 19:36:34 +02:00
00-git-commit-history.md docs(rt2): track-wide brainstorm — all five iterations ready, graph remapped 2026-09-15 01:15:30 +02:00
00-link-audit.md docs: audit all markdown against the code, fix findings, flatten status folders 2026-08-26 19:20:22 +02:00
00-principles.md docs: amend principle 7 — the log is authoritative, residency is declared 2026-08-26 22:42:27 +02:00
01-problem.md docs: remove stale old-runtime docs; abandon the ##ui frontend track 2026-08-17 20:06:36 +02:00
08-project-structure.md docs: audit all markdown against the code, fix findings, flatten status folders 2026-08-26 19:20:22 +02:00
2026-08-27-chat-drain-finding.md fix(chat gate): every leg starts its own server — and it found a real bug 2026-08-27 23:27:46 +02:00