Skip to content

fix: bound native frame parsing before allocation - #161

Merged
RobLe3 merged 1 commit into
mainfrom
codex/pre1-native-frame-hardening
Aug 28, 2026
Merged

RobLe3 merged 1 commit into
mainfrom
codex/pre1-native-frame-hardening

Conversation

@RobLe3

@RobLe3 RobLe3 commented Aug 28, 2026

Copy link
Copy Markdown
Owner

Summary

  • enforce the payload-only 16 MiB frame limit before allocation and before encoding
  • reject unsupported header and negotiated versions
  • require INIT before application frames and reject duplicate INIT
  • make network-facing response encoding fallible rather than panic on handler output
  • consume the updated portable negative vectors

Local verification

  • cargo fmt --all -- --check
  • cargo clippy --locked --all-targets --all-features -- -D warnings
  • cargo test --locked --all-features

Boundary

This hardens the optional development TCP binding. It does not claim a production TLS boundary, resolve the relay opcode collision, qualify native TCP for stable use, or implement QUIC.

Refs #158
Refs #159

@RobLe3
RobLe3 merged commit 3b22946 into main Aug 28, 2026
1 check passed
@RobLe3
RobLe3 deleted the codex/pre1-native-frame-hardening branch August 28, 2026 13:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant