All six tasks are done: - core/connection-credentials: ConnectionCredentials + RemoteIdentity in alknet-core - tls/crate-init: alknet-tls crate skeleton with deps and feature flags - tls/server-extract: server-side TLS code extracted into alknet-tls - tls/client-extract: client-side TLS code extracted into alknet-tls - tls/tests: 34 TLS tests moved and adapted into alknet-tls - tls/review-tls: spec conformance review passed, all feature combos green
5.1 KiB
5.1 KiB
id, name, status, depends_on, scope, risk, impact, level
| id | name | status | depends_on | scope | risk | impact | level | |
|---|---|---|---|---|---|---|---|---|
| tls/review-tls | Review alknet-tls implementation for spec conformance, deduplication, and test coverage | completed |
|
moderate | low | phase | review |
Description
Phase 1 review checkpoint. Verify the alknet-tls crate is spec-conformant,
self-contained, and ready for downstream consumption by alknet-endpoint (Phase 2)
and alknet-client (Phase 3).
Review Checklist
-
Crate structure:
- Module layout matches spec:
server.rs,client.rs,signing.rs,pem.rs - Public API types:
TlsServerConfig,TlsClientConfig,TlsError,Ed25519SigningKey - Re-exports in
lib.rsare correct and minimal
- Module layout matches spec:
-
Server-side conformance:
TlsServerConfig::new()accepts&TlsIdentity+&[Vec<u8>]and returnsResult<Self, TlsError>TlsServerConfig::for_quinn()converts toquinn::ServerConfig(feature-gated)RawKeyCertResolverimplementsResolvesServerCertwithonly_raw_public_keys() == trueAcceptAnyCertVerifierimplementsClientCertVerifierin "request-but-don't-require" modeSelfSignedCertgeneration usesrcgen- ACME path (
TlsSetup::new_acme) is feature-gated onacme build_iroh_endpointis either extracted (feature-gated oniroh) or deferred with a TODO
-
Client-side conformance:
TlsClientConfig::new()accepts&ConnectionCredentials+&[u8]and returnsResult<Self, TlsError>TlsClientConfig::for_quinn()converts toquinn::ClientConfig(feature-gated)FingerprintPinVerifierimplementsServerCertVerifierwith fingerprint matchingselect_server_verifierlogic:Some→ fingerprint pin,None→ CA verification (ADR-034 §3)RawKeyClientCertResolverimplementsResolvesClientCertwithonly_raw_public_keys()detectionNoClientCertResolverimplementsResolvesClientCertwithhas_certs() == falseload_platform_root_cert_storeincludeswebpki-rootsfallback (ADR-088 §5)
-
Shared code deduplication:
Ed25519SigningKeyis defined once insigning.rs, used by both server and clientload_cert_chain/load_private_keyare defined once inpem.rs, used by both- No duplicate
Ed25519SigningKeyor PEM loaders between server and client modules
-
Dependency hygiene:
rustls-native-certsandwebpki-rootsare always-present (not feature-gated) per ADR-088 §5quinnis optional, gated behindquinnfeaturetokio-rustlsis optional, gated behindtcpfeaturerustls-acmeis optional, gated behindacmefeature- No unexpected heavy deps
-
Error handling:
TlsErrorhasConfig,Io,Certvariants- All public fallible functions return
Result<_, TlsError>(no rawStringerrors) - Error messages are descriptive
-
Test coverage:
- All 22 server-side tests pass
- All 10 client-side tests pass
Ed25519SigningKeytests (6) pass- PEM loader tests (3) pass
- Tests exercise error paths (missing files, wrong fingerprints, etc.)
- Feature-gated tests are correctly annotated
-
Cross-cutting checks:
cargo build -p alknet-tlssucceeds (all feature combos)cargo test -p alknet-tlssucceeds (all feature combos)cargo clippy -p alknet-tls --all-targetssucceeds with no warningscargo fmt --check -p alknet-tlspassescargo build --workspacestill succeeds (old code untouched)cargo test --workspacestill succeeds (old tests untouched)
Acceptance Criteria
- Crate structure matches spec (4 modules, public API types)
TlsServerConfigAPI correct and feature-gatedTlsClientConfigAPI correct and feature-gatedEd25519SigningKeydeduplicated (one copy insigning.rs)load_cert_chain/load_private_keydeduplicated (one copy inpem.rs)webpki-rootsfallback present inload_platform_root_cert_storerustls-native-certs+webpki-rootsalways-present (not feature-gated)- All 41 tests pass (22 server + 10 client + 6 signing + 3 pem)
cargo build -p alknet-tlssucceeds (all feature combos)cargo test -p alknet-tlssucceeds (all feature combos)cargo clippy -p alknet-tls --all-targetssucceeds with no warningscargo fmt --check -p alknet-tlspasses- Workspace still green:
cargo build --workspace+cargo test --workspacepass
References
- docs/research/alknet-crate-extraction/findings.md — Phase 1
- docs/architecture/decisions/088-webpki-roots-fallback.md — ADR-088 §5
- docs/architecture/decisions/034-outgoing-only-x509-and-three-peer-roles.md — ADR-034 §3
- tasks/tls/crate-init.md
- tasks/tls/server-extract.md
- tasks/tls/client-extract.md
- tasks/tls/tests.md
Notes
This review gates Phase 1 completion. The crate must be self-contained and spec-conformant before Phase 2 (
alknet-endpoint) and Phase 3 (alknet-client) begin, since both depend onalknet-tls. The old code in core and call is intentionally still present (duplicated) — the prunes happen in Phases 4-5. If deviations are found, document and fix before proceeding to Phase 2.
Summary
To be filled on completion