code wiki / _hdl_build / nx_acme_dns01_propagation_gate.nx
nx_acme_dns01_propagation_gate.nx
buildroot/runtime/_hdl_build/nx_acme_dns01_propagation_gate.nx
about
nx_acme_dns01_propagation_gate.nx -- LIVE proof for the DNS-01 TXT
propagation poll that replaces the fixed sys_sleep_ms(360000) in
nx_acme_dns01_issue.
Rows:
1. SET a UNIQUE _acme-challenge.nishifamily.com TXT at Porkbun (TLS 1.2).
2. POLL nx_dns01_wait_txt_propagated -> assert it returns VISIBLE(1)
within a bounded window, and report how long it took (this is the
"trigger as soon as propagated, not after a fixed 6 min" win).
3. DELETE the TXT (ALWAYS runs -> guaranteed cleanup, fully reversible).
4. NEG-CONTROL: poll for a value that was NEVER set, with a SHORT
timeout -> assert it returns TIMED-OUT(0) and is BOUNDED (does not
hang). This proves the ceiling path.
AUTHORIZED scope: ONE Porkbun TXT set + delete (cleaned up), read-only DNS
queries. NO Let's Encrypt challenge is triggered.
Creds: ./_offc/nx_secret_cli.elf get porkbun (/tmp/nxsecret.out; BOM stripped).
expect_exit: 0
license_tier: ORIGINAL
dependencies 5 imports · 0 importers
imports: nx_syscalls.nxnx_x509_trust_store.nxnx_trust_store_load_from_certdata.nxnx_acme_porkbun.nxnx_acme_dns01_propagation.nx
imported by: nobody (leaf or entry point)
call flow from main pre-order; caps 40 nodes / depth 6 declared; ↻ = already shown
structs
| none |
consts
| none |
functions
| 29 | func p_w(s: *u8) -> i64 { var n: i64=0; while s[n]!=(0 as u8){n=n+1} sys_write(1,s,n); return 0 } |
| 30 | func p_n(v: i64) -> i64 |
| 40 | func p_row(id: *u8, ok: i64, pass: *i64) -> i64 |
| 45 | func p_dec(buf: *u8, off: i64, v: i64) -> i64 |
| 54 | func p_read_file(path: *u8, out: *u8, cap: i64) -> i64 |
| 62 | func main() -> i64 |