code wiki / _hdl_build / nx_tls12_porkbun_e2e_gate.nx

nx_tls12_porkbun_e2e_gate.nx

buildroot/runtime/_hdl_build/nx_tls12_porkbun_e2e_gate.nx

9776 B205 linesdepth 21pulls 137 transitivereach 0 importersview sourcekind gate/prooftopic tls12
docsdependenciesstructsconstsfunctions

about

nx_tls12_porkbun_e2e_gate.nx -- PHASE 3 (final) LIVE e2e gate for the sovereign TLS 1.3 -> 1.2 fallback transport. PROVES the exact capability the expired nishifamily.com wildcard cert renewal needs: drive the REAL Porkbun DNS API over sovereign TLS 1.2 to 1. CREATE a UNIQUE test TXT record _acme-challenge.nishifamily.com -> assert the Porkbun API returns status SUCCESS (over TLS 1.2), then 2. DELETE it -> assert SUCCESS. The delete ALWAYS runs (guaranteed cleanup -- the test record is fully reversible). The Porkbun calls go through nx_acme_req, which tries TLS 1.3 first, sees api.porkbun.com refuse 1.3 (version-negotiation alert), reconnects, and completes over the proven sovereign TLS 1.2 client. REGRESSION row 0: a TLS 1.3 host (the Let's Encrypt directory) must STILL work through the SAME transport -- a harmless read-only GET (no account, order, or challenge is created) that proves the 1.3 path is intact and the 1.3-vs-1.2 selection is correct. This gate NEVER triggers an ACME challenge; it stays entirely in the Porkbun / TLS layer. Creds come from the sovereign vault: run ./_offc/nx_secret_cli.elf get porkbun first (writes /tmp/nxsecret.out: line1=apikey, line2=secretapikey); this gate reads that file (never a flat-file secret store, never hardcoded). expect_exit: 0 license_tier: ORIGINAL

dependencies 6 imports · 0 importers

nx_syscalls.nx nx_x509_trust_store.nx nx_trust_store_load_from_certdata. nx_acme_http.nx nx_acme_porkbun.nx nx_http_response_parse.nx nx_tls12_porkbun_e2e_gate.nx

imports: nx_syscalls.nxnx_x509_trust_store.nxnx_trust_store_load_from_certdata.nxnx_acme_http.nxnx_acme_porkbun.nxnx_http_response_parse.nx

imported by: nobody (leaf or entry point)

call flow from main pre-order; caps 40 nodes / depth 6 declared; ↻ = already shown

main sys_mmap g_w sys_write nx_trust_store_load_from_c sys_mmap ↻ sys_read_file sys_openat_rd sys_lseek sys_mmap ↻ sys_read sys_close nx_nss_certdata_parse sys_mmap ↻ _pat_class_cert _pat_value_octal _pat_end _find_newline _starts_with _parse_octal_line sys_mmap ↻ _is_space _decode_octal_escape _is_octal trust_store_alloc sys_mmap ↻ nx_x509_trust_store_load sys_mmap ↻ x509_parse sys_mmap ↻ asn1_cursor_init asn1_expect_tag sys_mmap ↻ asn1_read_tlv_header asn1_read_tag asn1_read_length asn1_read_length ↻ x509_read_tlv sys_mmap ↻ asn1_expect_tag ↻

structs

none

consts

none

functions

35func g_w(s: *u8) -> i64 { var n: i64=0; while s[n]!=(0 as u8){n=n+1} sys_write(1,s,n); return 0 }
36func g_n(v: i64) -> i64
called by 1: main calls 3: g_wsys_mmapsys_write
46func g_row(id: *u8, ok: i64, pass: *i64) -> i64
calls 1: g_w
52func g_dec(buf: *u8, off: i64, v: i64) -> i64
calls 1: sys_mmap
62func e2e_read_file(path: *u8, out: *u8, cap: i64) -> i64
called by 1: main calls 3: sys_openat_rdsys_readsys_close
70func e2e_print_body(label: *u8, resp: *u8, n: i64) -> i64
84func main() -> i64