Repository navigation
An unchanged ureq and rustls client on a ring fork fetches byte-exact over TLS 1.3 in a guest, trusting the Mozilla roots every image carries with their licence's text - #810
Conversation
…n a guest ring is ToyOSOrg/ring's toyos-0.17.14, pinned by the lock: the published 0.17.14 package imported byte for byte, a build script that tells a packaged tree from a source tree by `pregenerated/` instead of `.git` (so as a git dependency it uses the package's assembly, runs no perl, and leaves C asserts and warnings-as-errors off, so nothing calls `__assert_fail`), and `toyos` in its Linux-ABI and getrandom lists. The root workspace and the guest test crate both patch it; the test crate also takes the getrandom 0.2 fork, which reaches SYS_RANDOM. The build writes webpki-root-certs' Mozilla roots to every ROOT as /system/etc/ssl/cert.pem (build::TRUST_ROOTS). A test image stages that file whole, the build's roots with its harness's authority after them, and the build refuses one that does not start with its own. A test crate's C is compiled by the toolchain's clang against libc's sysroot, as a program's is: TestBuild hands cargo the cc crate's variables. https_fetch boots tests/netcase with three rustls servers on the host, each under an authority made for the run: https_get, ureq 3 on rustls 0.23 with the roots file and the project's User-Agent, fetches 384 KiB over TLS 1.3 and its ring SHA-256 matches the harness's sha2 one; it refuses a certificate for another address and one from an authority the file does not hold, by name. ring_kat runs on the shared boot: ring against RFC and NIST known answers. doom's build script downloads with ureq on ring and the project's User-Agent; nothing names rustls-rustcrypto. Filed: a refused connection's close that never reached the host's peer, and the roots being data no licence gate reads. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
…ody reads clippy denies the unread field. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
…etcase boot is filed The handshake is rustls on ring at both ends, so it alone would pass a ring wrong at both; ring's known answers are the oracle, and ring picks its code by the CPU's features, so they run on the same guest CPU as the fetch. ring_kat's shared run stays the T14's. The whole suite went red once on netstack_socket_churn: the firmware cleared the screen and said nothing more for 487 s under a load average near 90, and the test was green alone. Filed with the load, as a red under load is. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
|
The
The import against the crate, The two edits, whole ( diff --git a/build.rs b/build.rs
index 9843ad8aa..ec69e41c9 100644
--- a/build.rs
+++ b/build.rs
@@ -254,6 +254,7 @@ const LINUX_ABI: &[&str] = &[
"linux",
"redox",
"solaris",
+ "toyos",
];
const WIN32N: &str = "win32n";
@@ -310,16 +311,21 @@ fn ring_build_rs_main(c_root_dir: &Path, core_name_and_version: &str) {
let endian = env::var("CARGO_CFG_TARGET_ENDIAN").unwrap();
let is_little_endian = endian == "little";
- let is_git = fs::metadata(c_root_dir.join(".git")).is_ok();
+ // `pregenerated/` is made by `mk/package.sh` and is never committed, so it
+ // exists exactly in a packaged tree. A packaged tree may still have a
+ // `.git` of its own, e.g. when it is consumed as a Cargo `git` dependency
+ // from a repository that commits the package's contents, so `.git` does
+ // not tell the two cases apart.
+ let is_packaged = c_root_dir.join(PREGENERATED).is_dir();
// Published builds are always built in release mode.
- let is_debug = is_git && env::var("DEBUG").unwrap() != "false";
+ let is_debug = !is_packaged && env::var("DEBUG").unwrap() != "false";
// During local development, force warnings in non-Rust code to be treated
// as errors. Since warnings are highly compiler-dependent and compilers
// don't maintain backward compatibility w.r.t. which warnings they issue,
// don't do this for packaged builds.
- let force_warnings_into_errors = is_git;
+ let force_warnings_into_errors = !is_packaged;
let target = Target {
arch,
@@ -337,15 +343,15 @@ fn ring_build_rs_main(c_root_dir: &Path, core_name_and_version: &str) {
None
};
- // If `.git` exists then assume this is the "local hacking" case where
- // we want to make it easy to build *ring* using `cargo build`/`cargo test`
- // without a prerequisite `package` step, at the cost of needing additional
- // tools like `Perl` and/or `nasm`.
+ // If `pregenerated/` doesn't exist then assume this is the "local hacking"
+ // case where we want to make it easy to build *ring* using `cargo build`/
+ // `cargo test` without a prerequisite `package` step, at the cost of
+ // needing additional tools like `Perl` and/or `nasm`.
//
- // If `.git` doesn't exist then assume that this is a packaged build where
+ // If `pregenerated/` exists then assume that this is a packaged build where
// we want to optimize for minimizing the build tools required: No Perl,
// no nasm, etc.
- let generated_dir = if !is_git {
+ let generated_dir = if is_packaged {
c_root_dir.join(PREGENERATED)
} else {
generate_sources_and_preassemble(
diff --git a/src/rand.rs b/src/rand.rs
index a451c8f6a..5580447fb 100644
--- a/src/rand.rs
+++ b/src/rand.rs
@@ -139,6 +139,7 @@ impl crate::sealed::Sealed for SystemRandom {}
target_os = "openbsd",
target_os = "redox",
target_os = "solaris",
+ target_os = "toyos",
target_os = "vita",
target_os = "windows",
all(The edit as a The control: the import alone ( |
|
Negative controls at the head, #!/bin/sh
# usage: mutate.sh <patch> <log> -- <command...>: apply, show it builds and runs, record the exit, restore.
W=<dev>/toyos-tls
patch=$1; log=$2; shift 3
cd $W || exit 9
[ -z "$(git status --porcelain --ignore-submodules=none)" ] || { echo "tree not clean" > $log; exit 9; }
git apply --check "$patch" && git apply "$patch" || { echo "patch does not apply" > $log; exit 9; }
{ echo "head: $(git rev-parse HEAD)"; echo "patch: $(basename $patch)"; git diff; echo "--- run: $*"; } > $log
"$@" >> $log 2>&1; code=$?
echo "MUTANT_EXIT=$code" >> $log
git apply -R "$patch"
echo "restored: [$(git status --porcelain --ignore-submodules=none)]" >> $logcontrol-m1-client-trusts-any-certificate.logcontrol-m2-client-sends-ureqs-own-user-agent.logcontrol-m3-roots-file-holds-the-other-authority.logcontrol-m4-server-flips-one-body-byte.logcontrol-m5-server-speaks-tls12-alone.logcontrol-m6-roots-writer-breaks-no-line.logcontrol-m7-a-known-answer-one-bit-off.log |
|
guest-https-fetch-6.logThe known answers checked against |
|
The whole guest suite at The harness's part of its output, from its first guest-suite-3.raw, lines 500–end
|
|
|
|
What The experiment: experiment-close-wait.logThe same client and server both on the host (macOS): a scratch crate with //! The harness's server and the guest's client, both on this host: what the
//! server sees of each refusal when the client's stack is the host's.
#[path = "https.rs"]
#[allow(dead_code)]
mod https;
use std::process::Command;
use std::sync::Arc;
use std::time::{Duration, Instant};
fn main() {
let client = std::env::args().nth(1).expect("the https_get binary");
let trusted = https::Authority::new("t");
let stranger = https::Authority::new("s");
let body = Arc::new(https::body());
let lo: std::net::IpAddr = "127.0.0.1".parse().unwrap();
let servers = [
("trusted", https::Server::start(trusted.leaf(lo), body.clone()).unwrap()),
("wrong-name", https::Server::start(trusted.leaf([192, 0, 2, 1].into()), body.clone()).unwrap()),
("untrusted", https::Server::start(stranger.leaf(lo), body).unwrap()),
];
let roots = std::env::temp_dir().join(format!("hostprobe-roots-{}.pem", std::process::id()));
std::fs::write(&roots, trusted.pem()).unwrap();
for (what, server) in &servers {
let out = Command::new(&client).arg(format!("https://127.0.0.1:{}/body", server.port)).arg(&roots).output().unwrap();
let t0 = Instant::now();
let seen = server.next(Duration::from_secs(30));
println!("{what}: client {:?} {:?}; server after {:?}: {seen:?}", out.status.code(), String::from_utf8_lossy(&out.stdout).trim(), t0.elapsed());
}
std::fs::remove_file(&roots).unwrap();
} |
|
What Its harness report from the first guest-suite-1.raw, lines 500–endThe silent boot's whole 16550 file, 58 bytes ( The same test alone a minute later, |
|
The earlier host-gate runs. At The roots file's host test, first run ( |
|
Review of #810 at Net lines ( Posted logs: all eight comments checked. No home-directory path, user name or machine identifier. Paths read Fork: BLOCKER
NOTE
SEND BACK |
…nd's order (#803) and the .local name's probing (#800), into the HTTPS client ring_kat's line in DRIVEN_AND_SHARED met random_draws' there; the merge keeps main's, and the next commit decides ring_kat's place. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
…s them, and ring_kat holds RSA, P-384 and SHA-384 to published answers The owner allowed CDLA-Permissive-2.0 for the Mozilla roots. The licence gate now judges them: by the licence of the crate the build copies them out of (`build::TRUST_ROOTS_CRATE`), as data, the one place `licence::DATA_ONLY` passes, and refused unless the text the image carries beside them, /system/etc/ssl/CDLA-Permissive-2.0.txt, is that crate's own LICENSE byte for byte. The licence asks for the text to travel with the data; it is committed under licenses/ and NOTICE names it. The tooling issue that tracked the gap is closed. The `font: bool` the gate threaded through `refused`, `judge_licence` and `Report::judge` becomes `Scope`, since a licence allowed for data alone is a third case. `https_fetch` stages the roots and its harness's authority under a name of its own and passes that path, so `build_and_assemble` writes the roots unconditionally and the test-only match and assert go. The C environment is `GuestEnv`'s, applied by `cargo_build` to every guest build, so `build_programs` and `TestBuild` no longer each derive it. `trust_roots` writes PEM with `pem`, already in the lock through rcgen, and the hand-written encoder, `base64` and the test of the encoder's round trip go. `ring_kat` adds SHA-384 of "abc" (FIPS 180-2 D.1), ECDSA P-384 with SHA-384 (RFC 6979 A.2.6), and RSA PKCS#1 v1.5 and PSS with SHA-256 at 2048 bits (the first passing `[mod = 2048]` SHA256 vector of NIST CAVP's FIPS 186-3 SigVer15 and SigVerPSS), each signature refused with a bit flipped. It runs in `https_fetch` alone now: the shared boot ran it on the same QEMU CPU model as the fetch's boot, so the second run bought nothing, and the fetch's run keeps the oracle beside the handshake it vouches for. The host-tools rows name the host `cc` compiling ring for doom's build script and the toolchain's clang compiling a test crate's ring, and the lost-FIN issue says slirp is not ruled out. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
The gate globs every section's path through git before it reads a section as prose, and /system/etc/ssl/cert.pem is a path on ROOT, not in the tree: the licence step of `cargo run -- --ci host` was red on it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
…een clears `https_fetch` alone at 216f33b, at load 89 to 99, timed out waiting for ===READY=== after 64 s with the same 58 bytes of firmware escapes on its 16550 and nothing after them. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
|
Negative controls, round 2. Each log is the whole of one #!/bin/sh
# usage: mutate.sh <patch> <log> -- <command...>: apply, build and run, record the exit, restore.
W=<dev>/toyos-tls
patch=$1; log=$2; shift 3
cd $W || exit 9
[ -z "$(git status --porcelain --ignore-submodules=none)" ] || { echo "tree not clean" > $log; exit 9; }
git apply --check "$patch" && git apply "$patch" || { echo "patch does not apply" > $log; exit 9; }
{ echo "head: $(git rev-parse HEAD)"; echo "patch: $(basename $patch)"; git diff; echo "--- run: $*"; } > $log
"$@" >> $log 2>&1; code=$?
echo "MUTANT_EXIT=$code" >> $log
git apply -R "$patch"
echo "restored: [$(git status --porcelain --ignore-submodules=none)]" >> $logWhere the new known answers come from, fetched with the project User-Agent, sha256 of each download: control-g0-the-gate-on-this-tree.logcontrol-g1-cdla-not-allowed-as-data.logcontrol-g2-another-licence-text-beside-the-roots.logcontrol-m1-client-trusts-any-certificate.logcontrol-m2-client-sends-ureqs-own-user-agent.logcontrol-m3-roots-file-holds-the-other-authority.logcontrol-m4-server-flips-one-body-byte.logcontrol-m5-server-speaks-tls12-alone.logcontrol-m7-a-known-answer-one-bit-off.logcontrol-m8-rsa-signature-one-bit-off.log |
|
fetch2.logThe red before it, at Its 16550 file, fetch.log |
|
The log is 471,672 bytes, over a comment's size: below is every line that carries host3.log, the [ci] lines
buildonly.log |
|
The whole guest suite at Part 2 of 2, from guest2.log, lines 501–end |
|
The whole guest suite at guest2.log, lines 1–500 |
|
The first whole guest suite of this round, at From guest.log, lines 507–end |
|
Review of #810 at Net lines ( Round-1 BLOCKERs
BLOCKERNone open. NOTE
LAND AFTER NAMED CHANGES |
… document it already holds `judge_trust_roots_of` ran a fourth `cargo metadata --locked` over the root workspace and built a `Graph` over it only to find one package by name. `judge` already holds a document of that workspace: the one whose `members` holds the root `Cargo.toml`. `webpki-root-certs` is a non-optional dependency of the root package, so whichever feature set that document was resolved with, it resolves the crate, and the gate reads it from there. A shipped tree with no crate in the root workspace is refused by name rather than guessed at. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C
|
Round 3: the gate's controls at control-g0-the-gate-on-this-tree.logcontrol-g1-cdla-not-allowed-as-data.logcontrol-g2-another-licence-text-beside-the-roots.log |
|
Round 3 gates at host.log, the [ci] linesbuildonly.log |
|
CI at |
Stage 3 of
issues/the-internet-clients-work-unchanged.md, without its metal row: an unchangedureq3.4.2 onrustls0.23.45 client, on aringfork, builds forx86_64-unknown-toyosand fetches byte-exact over TLS 1.3 in a QEMU guest from a server the harness runs on the host, sends exactly the project'sUser-Agent, and refuses a wrong name and an untrusted root by name. Every image carries the Mozilla roots at/system/etc/ssl/cert.pemwith their licence's text beside them, under a licence gate that reads both.Head:
88d5c7c0f,origin/mainatd6298c83emerged (#800, #802, #803). #801 had not landed when the measurements below were taken. Round 3 changed onlyjudge_trust_roots_of(below); the guest runs are ate3b11331e, the commit before it, since that change is in the host-side licence gate and no guest image reads it. Fork:ToyOSOrg/ringtoyos-0.17.14at34818c4599e7d6233cf42e80de5cd309190e523c, unchanged this round, named by both lockfiles.What changed, per decision
The
ringfork. Branchtoyos-0.17.14onToyOSOrg/ring, three commits on upstream's2723abbca(the commit the package was cut from, per its.cargo_vcs_info.json):e0626e4e0imports the publishedring-0.17.14.cratebyte for byte (SHA-256a4689e6c2294d81e88dc6261c768b63bc4fcdb852be6d1352498b114f61383b7, the checksummain'sCargo.lockcarried).39eff8204, the ruled build-script edit, written for upstream:is_packaged = c_root_dir.join(PREGENERATED).is_dir()replaces the.gittest for all three decisions (pregenerated assembly versus perlasm, C asserts in debug, C warnings as errors). Upstream's own tree has nopregenerated/, so its behaviour is unchanged.34818c459:"toyos"inLINUX_ABIandtarget_os = "toyos"insrc/rand.rs'sgetrandomlist. The random source is thegetrandom0.2 fork's ToyOS arm,SYS_RANDOM, which The kernel's random bytes come from a ChaCha20 generator keyed from the loader's seed and the CPU's sources, and 17 of the AArch64 guest tests run under HVF #802 now serves from its ChaCha20 generator; every run below is on that kernel.Pinned in
[patch.crates-io]bybranch, like every other fork there, with the commit in both lockfiles. With asserts off nothing references__assert_fail.The trust roots and their licence (
src/build.rs,src/licence.rs,NOTICE,licenses/). The owner, asked whether to allow CDLA-Permissive-2.0 for the Mozilla roots, answered "Allow it". So:build::trust_roots()writeswebpki-root-certs' roots as PEM withpem4 (already in the lock throughrcgen);build_and_assembleputs them on every ROOT atetc/ssl/cert.pem, unconditionally, and beside themetc/ssl/CDLA-Permissive-2.0.txt, the licence's text, which its section 2.1 asks to travel with the data. The text is committed aslicenses/CDLA-Permissive-2.0-webpki-root-certs.txt(the crate'sLICENSE, sha256e271993808fec50ab29350b39539cdec611a9103f827e0aa26d61da70e2d33f8), andNOTICEhas a prose section for it.judge_trust_roots_offindsbuild::TRUST_ROOTS_CRATEin thecargo metadatadocumentjudgealready holds for the build's own workspace (the one whosemembersholds the rootCargo.toml; the crate is a non-optional dependency of the root package, so any feature set resolves it), with nocargo metadatacall of its own, and judges itslicenseas data, the one place the newDATA_ONLY = ["CDLA-Permissive-2.0"]passes, asFONTS_ONLYpasses OFL only for a font; and refuses unless the shipped text is that crate'sLICENSE, byte for byte. The ruling is scoped as given: CDLA is not inALLOWED, and no crate an image links passes under it. The gate'sfont: boolbecomesScope { Code, Font, Data }.issues/the-trust-roots-ship-in-every-image-and-no-licence-gate-reads-them.mdis closed (deleted); its rule is insrc/licence.rs's header. No citation of it remains (git grep).The test's roots (
tests/toyos.rs).https_fetchstages the build's roots plus its harness's authority asetc/ssl/harness-cert.pemand passes that path in argv. Thematchonextra_filesand its assert are gone.One C environment (
src/build.rs).GuestEnv::new(sysroot, arch)holdsCSysroot::cc_env()andcargo_buildapplies it to every guest build, sobuild_programs' andTestBuild's copies are gone. The variables are suffixed by the userland triple, so the kernel's and the loader's builds (other triples) read none of them.ring_kat(tests/toyos-rust-tests/src/bin/ring_kat.rs). Now covers what the shipped roots need too: SHA-384("abc") (FIPS 180-2 D.1); ECDSA P-384 with SHA-384, RFC 6979 A.2.6, "sample"; RSA PKCS#1 v1.5 and RSA-PSS with SHA-256 at 2048 bits, the first passing[mod = 2048]SHA256 vector of NIST CAVP's FIPS 186-3SigVer15_186-3.rspandSigVerPSS_186-3.rsp(PSS salt 32 bytes, the lengthringverifies). Each signature is also refused with one bit flipped. A digest has nothing to refuse, so SHA-384 gets no flipped-bit case. Where each vector comes from, with the downloads' hashes, is in the controls comment.ring_katruns once, inhttps_fetch(RUST_SKIP). In round 1 it ran twice per QEMU suite: once on the shared boot and once inhttps_fetch. Both runs were on the sameArch::cpu(accel),qemu64under TCG andhostunder KVM, so the second bought nothing. The T14 reason given for the shared run was never measured, and I keep the run inside the fetch for two reasons: it puts the oracle on the boot whose handshake it vouches for, and a filteredcargo test -- https_fetchstill carries it. The cost is that the T14's shared boot no longer runs it. The code paths TCG never takes (ADX/BMI2 Montgomery, AES-NI, AVX2) are reached on CI's KVM through-cpu host; that measurement is below, still to come.doom (
userland/doom/build.rs,Cargo.toml).ureqwith itsrustlsfeature (ring, webpki roots) replacesrustls-no-provider+rustls-rustcrypto+webpki-roots, and the download sends the projectUser-Agent. No manifest namesrustls-rustcrypto.Issues.
the-build-runs-host-tools-outside-rust-and-qemu.md: the hostccrow now also names ring compiled for doom's build script. The toolchainclangrow now names every guest crate's C throughGuestEnv, ring inhttps_getandring_katamong them.a-guest-close-after-a-refused-handshake-can-leave-its-peer-waiting.md: says slirp is not ruled out, since no capture was taken of the guest's side, and names a QEMUfilter-dumpon the netcase NIC as the measurement that answers it.a-netcase-boot-under-host-load-said-nothing-past-the-firmwares-screen-clears.md: a second occurrence this round, recorded with its load (below).New dependencies
webpki-root-certs1.0.9 (build): the rustls project's publication of the Mozilla set as whole certificates.webpki-rootscarries trust anchors, which no certificate file takes.pem4 (build, already in the lock throughrcgen): writes the PEM. It replaces round 1'sbase64and the hand-written encoder.rcgen0.14 (harness, dev): an authority and IP-SAN leaves per run.rustls(harness, dev, already in the lock): the server.ureq,rustls,ring, at the root lock's versions.Checks of a trust boundary
Independent oracles. Two oracles do not depend on
ring:ring_kat, now RSA PKCS#1 v1.5, RSA-PSS and P-384 too. They run on the boot and CPU of the fetch.sha2, the guest withring.The server is not an oracle, since it is
rustlsonringtoo. Before the guest, the new vectors were checked against crates.ioring0.17.14 on the host (aarch64), EXIT=0. In the guest every line passed (https_fetchlog).Negative controls, each a checked patch applied, built, run and reversed by one script, tree clean after (
restored: []). The logs and patches are in the controls comment. m1–m5, m7 and m8 ran ate3b11331e, eachcargo test --test toyos-build -- https_fetch. g0–g2 ran at88d5c7c0f(round 3; round 2's run at216f33b35gave the same verdicts), eachcargo test --lib -p toyos-build licence::tests::the_gate_on_this_tree, a test the patch adds that runslicence::judgeon the tree..disable_verification(true)the server named for another address: the client ended Some(0) and was to end 2.user_agentsaw Served { … user_agents: ["ureq/3.4.2"] }the trusted server: the client ended Some(2) and was to end 0saw Served { version: Some(TLSv1_2), … }ring_kat ended Some(101)ring_kat ended Some(101),rsa pkcs#1 v1.5 sha-256 2048 cavp SigVer15 does not verifyDATA_ONLYemptycrate webpki-root-certs 1.0.9, the data of etc/ssl/cert.pem is "CDLA-Permissive-2.0": not allowed: CDLA-Permissive-2.0; pulled in by build::trust_rootslicenses/MIT-PhosphorIcons.txtshipped instead… ships etc/ssl/CDLA-Permissive-2.0.txt beside them, which is not its LICENSERound 1's m6 tested the hand-written encoder's round trip (
the_trust_roots_read_back_as_the_published_set). Both are gone. What is left of that test ispem's encoding andureq's parsing, which are not ours. The bytes are unchanged: 181,603 in both rounds'--build-only. The gate's logic also has a host unit test,the_trust_roots_pass_only_with_their_crates_licence_text, covering a matching text, another text, and another licence.The ruled fork edit, both arms, from round 1, unchanged fork: at
toyos-0.17.14withPERL_EXECUTABLE=/nonexistent/perlthe build gave EXIT=0; ate0626e4e0it gave EXIT=101 running perl.Gates
Logs are in the comments below, scrubbed of home-directory paths. The full logs are under the orchestrator's
tls/r2/logs/andtls/r3/logs/.At
88d5c7c0f:cargo run -- --ci host: EXIT=0,78 step(s), all green; the licence step says6 exception(s) stand, and nothing else is refused.cargo run -- --build-only: EXIT=0. ROOT hasetc/ssl/cert.pem(181,603 bytes) andetc/ssl/CDLA-Permissive-2.0.txt(2,371 bytes).At
e3b11331e:cargo run -- --ci host: EXIT=0,78 step(s), all green. Load 45.32→54.59 on 14 cores.cargo test --no-fail-fast(whole guest suite): EXIT=0.toyos-buildgave42 passed, 42 total,https_fetchamong them, andtoyos-checks39 passed (suite_splitholdsring_kat's move toRUST_SKIP).uptimebefore: 55.66 55.89 66.50; after: 86.43 65.59 68.97.cargo test --test toyos-build -- https_fetch --nocapture: EXIT=0,PASS https_fetch (23s), everyring_katline and the threehttps_getlines in the log. Load 42.53→47.98.cargo run -- --build-only: EXIT=0. ROOT hasetc/ssl/cert.pem(181,603 bytes) andetc/ssl/CDLA-Permissive-2.0.txt(2,371 bytes).CI's KVM
guest / suiteThe run where
ringtakes its ADX/BMI2 Montgomery, AES-NI and AVX2 paths, which TCG'sqemu64never runs, and on which the new RSA and P-384 answers are the only oracle. The branch lands only once it is green.88d5c7c0fguest / suite113949123414, under KVM)PASS https_fetch (6s), which runsring_kat(SHA-384, ECDSA P-384, RSA PKCS#1 v1.5 and PSS known answers) and the HTTPS fetch on the KVM CPU;[ci] the suite: test result: ok. 42 passed, 42 total;[ci] Guest: 5 step(s), all greenring_katlines are not in it; the test passes only if every answer holds).host: 79 steps all green.Reds in round 2, recorded.
2f7b0eada, load 58.49→84.83: 41 of 42, red onvirt_mask_windows(STALLED: waiting for the boot's last word). Its console ends atspawn: /system/bin/test_rs_counters_read, the signatureissues/a-counters-read-under-host-load-can-go-silent-for-15-s.mdrecords. It is an AArch64virtsmpcaseboot, and this branch changes nothing that boot's kernel, case or binaries are built from beyond the C variables, which are suffixed by the toyos triple.https_fetchalone at216f33b35, load 89→99, beside this tree's own--ci host:Boot timed out waiting for ===READY===; the console carried: nothing at all. Its 16550 file holds the same 58 bytes of firmware escapes as the netcase issue's first case, so I added it to that issue.--ci hostat2f7b0eada: red on the licence step alone. NOTICE's new section was headed by a ROOT path, which the gate'sgit ls-filesglob refused; fixed in216f33b35.--ci hostat216f33b35: void. The machine's disk was full, and all three red steps sayNo space left on device.Why a QEMU guest test
https_fetch's behaviour is a list of things with no host build and no type that holds them:ring's ToyOS build and assemblygetrandomreachingSYS_RANDOMnetstackThe T14 is the cheaper tier and the stage's exit, but its row needs a server the harness runs on the bench, which the brief puts outside this stage. Until then QEMU is the only tier that reaches the fetch.
ring_katalone is reachable by a host test only for the host'sring, never the guest's build of it.Net lines
git diff --shortstat origin/main...88d5c7c0f: 19 files, +1502 −437.src/build.rs+38 −11 (roots writer, their ROOT entries,GuestEnv's C environment),src/licence.rs+128 −20 (the roots' judgement,Scope, and their unit tests),Cargo.toml+9, doom +4 −16.licenses/CDLA-…txt+61,NOTICE+14.tests/common/https.rs+164,https_get.rs+77,ring_kat.rs+251,tests/toyos.rs+98.Unsure
ring_katrun. I chose the fetch's run over the shared boot's. If the T14 is wanted, it is one line back intoDRIVEN_AND_SHARED.aarch64-unknown-toyosbuildsringthrough the same arms, but no guest ran it), the T14, and CI's KVM (its section above).🤖 Generated with Claude Code
https://claude.ai/code/session_017cSFvbD35xJ2kGANVdm23C