docs(rv2-tls): brainstorm §F3c-net to ready — four integration forks locked
- §F3c-net rewritten to READY (decisions locked 2026-09-09), grounded in
the runtime not assumed:
1. blocking connect+handshake then park the data plane (mirrors
net.connect's own "tolerable while rare" stance); park-based
handshake a named follow-up
2. per-shard fd-keyed wo_tls_conn slot table, no locks (the wo_child /
one-thread-per-shard pattern); slot holds driver state + partial-record
+ leftover-plaintext buffers
3. failures trap WO_T_IO loudly incl. chain + hostname (no silent nil)
4. per-shard lazy read-only CA bundle (/etc/ssl/certs, WO_CA_BUNDLE)
- builtin surface: net.connect_tls/read_tls/write_tls (ids 115-117,
WO_B_MAX->117), acceptance criteria (incl. concurrent-shard TSan),
out-of-scope (park handshake, TlsConn object, HTTP layer, inbound G)
- frontmatter review_pending + phase-F row + status NEXT PLAN updated:
F3c-net spec ready, next action is BUILD (live-gated)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
(cherry picked from commit 8b6e72171c5db9dfe5b7a5122be123bf7cc3cdd9)