code wiki / _hdl_build / nx_tls12_porkbun_e2e_gate.nx
nx_tls12_porkbun_e2e_gate.nx
buildroot/runtime/_hdl_build/nx_tls12_porkbun_e2e_gate.nx
about
nx_tls12_porkbun_e2e_gate.nx -- PHASE 3 (final) LIVE e2e gate for the
sovereign TLS 1.3 -> 1.2 fallback transport.
PROVES the exact capability the expired nishifamily.com wildcard cert
renewal needs: drive the REAL Porkbun DNS API over sovereign TLS 1.2 to
1. CREATE a UNIQUE test TXT record _acme-challenge.nishifamily.com
-> assert the Porkbun API returns status SUCCESS (over TLS 1.2), then
2. DELETE it -> assert SUCCESS. The delete ALWAYS runs (guaranteed
cleanup -- the test record is fully reversible).
The Porkbun calls go through nx_acme_req, which tries TLS 1.3 first, sees
api.porkbun.com refuse 1.3 (version-negotiation alert), reconnects, and
completes over the proven sovereign TLS 1.2 client.
REGRESSION row 0: a TLS 1.3 host (the Let's Encrypt directory) must STILL
work through the SAME transport -- a harmless read-only GET (no account,
order, or challenge is created) that proves the 1.3 path is intact and the
1.3-vs-1.2 selection is correct. This gate NEVER triggers an ACME
challenge; it stays entirely in the Porkbun / TLS layer.
Creds come from the sovereign vault: run
./_offc/nx_secret_cli.elf get porkbun
first (writes /tmp/nxsecret.out: line1=apikey, line2=secretapikey); this
gate reads that file (never a flat-file secret store, never hardcoded).
expect_exit: 0
license_tier: ORIGINAL
dependencies 6 imports · 0 importers
imports: nx_syscalls.nxnx_x509_trust_store.nxnx_trust_store_load_from_certdata.nxnx_acme_http.nxnx_acme_porkbun.nxnx_http_response_parse.nx
imported by: nobody (leaf or entry point)
call flow from main pre-order; caps 40 nodes / depth 6 declared; ↻ = already shown
structs
| none |
consts
| none |
functions
| 35 | func g_w(s: *u8) -> i64 { var n: i64=0; while s[n]!=(0 as u8){n=n+1} sys_write(1,s,n); return 0 } |
| 36 | func g_n(v: i64) -> i64 |
| 46 | func g_row(id: *u8, ok: i64, pass: *i64) -> i64 calls 1: g_w |
| 52 | func g_dec(buf: *u8, off: i64, v: i64) -> i64 calls 1: sys_mmap |
| 62 | func e2e_read_file(path: *u8, out: *u8, cap: i64) -> i64 |
| 70 | func e2e_print_body(label: *u8, resp: *u8, n: i64) -> i64 |
| 84 | func main() -> i64 |