Resolve the cert-type negotiation gap (review 001 §U-3, OQ-TLS-10) by deviation from alknet: the gap was a defect in the prior art (alknet's code never delivered its spec's raw-key-over-TCP promise — ADR-082 "works for both QUIC and TCP+TLS"), not behavior to preserve. - FingerprintPinVerifier::requires_raw_public_keys() derives from the pin format: ed25519: -> true (offer [RawPublicKey]), SHA256: -> false (X.509 offer). Crate pin client now completes against the crate raw-key server; SHA256: pins negotiate unchanged. - RawKeyClientCertResolver presents the SPKI under the X.509 offer (only_raw_public_keys() == false): a raw-only client offer can only negotiate against a requires_raw server verifier, and AcceptAnyCertVerifier correctly stays on the default (accepts both cert types). The server extracts the ed25519: fingerprint from the SPKI bytes either way. - Fail-closed preserved and strengthened: an ed25519: pin against an X.509 server now aborts at negotiation (suite 2b), never a downgrade; no API change (no public signature affected; the fix is invisible to consumers apart from working handshakes). - tests/handshake_behavior.rs: suite 3 now runs crate-native (no custom iroh-shaped verifier), new negotiation fail-closed suite, suite 3b inverted to end-to-end success; invariant_pins.rs resolver-offer assertions flipped; unused imports dropped. - Docs: ADR-007 written; OQ-TLS-10 -> resolved-by-deviation; client.md/server.md/overview/README/task postscript synced (incl. the strict-foreign-server limit in ADR-007 §Limits). Verification: cargo test 81 / --features tcp 94 / --all-features 105 green; clippy -D warnings clean (default + all-features); fmt clean; cargo doc warning-free.
status, last_updated
| status | last_updated |
|---|---|
| reviewed | 2026-09-10 |
alktls — Architecture
The authoritative architecture spec for the alktls crate (Phase 1 of the SDD process). The spec docs advanced Draft → Reviewed at the Phase 2 implementation review gate (see the lifecycle note at the end); statuses update here as docs advance.
All docs follow the SDD process conventions: specs reference ADRs and
OQs by number, ADRs explain WHY, open-questions.md tracks what is
unresolved.
Documents
| Doc | Status | Scope |
|---|---|---|
| overview.md | Reviewed | Purpose, transport picture, API surface, ADR/OQ index |
| server.md | Reviewed | TlsServerConfig, resolvers, ACME path, server invariants |
| client.md | Reviewed | TlsClientConfig, verifier selection, client auth, root-store fallback |
| open-questions.md | live | The authoritative OQ tracker (all Phase 0 OQs resolved at entry) |
ADRs
| ADR | Status | Decision |
|---|---|---|
| 001 | Accepted | Inherit the alknet TLS design as the baseline; deviations recorded as alktls ADRs |
| 002 | Accepted | TlsError: the ADR-088 six-variant shape from day one; config-construction scope boundary |
| 003 | Accepted | The QUIC feature is noq (iroh's extracted fork), not quinn; iroh stays key-not-config |
| 004 | Accepted | Complete accessors: for_tcp_tls() adopted; server borrows, client consumes |
| 005 | Accepted | Identity + credentials + fingerprint types move into alktls; auth layer stays out |
| 006 | Accepted | Eight-module layout; seed tests + integration invariant pins |
| 007 | Accepted | RFC 7250 cert-type negotiation: the offer follows the identity (deviation from alknet; resolves OQ-TLS-10) |
Lifecycle
Docs move Draft → Reviewed when their open questions are resolved
and the architecture review reports zero critical issues; ADRs are
Accepted at write time and never revert (supersede instead).
open-questions.md is the authoritative tracker; the Phase 0 doc's
OQ statuses are the historical record.
API-freeze note (2026-09-10): the Phase 2 implementation review
gate (tasks/review-impl.md) passed with zero un-pinned divergences
(two ADR amendments recorded — 002's verifier-error path, 003's noq
provider feature). The public API surface — the lib.rs re-export
block per ADR-004/005/006 — is frozen as of that review; the alknet
rewrite compiles against it. Additive evolution only.
Phase status
- Phase 0 (complete, 2026-09-10):
docs/research/phase-0.md— extraction inventory, verified invariants, gaps, noq investigation, OQ-TLS-01..08. - Phase 1 (this directory): all Phase 0 OQs resolved at entry — six via ADR-001..006, two as documented behavior (OQ-TLS-02, OQ-TLS-06). Reviewed 2026-09-10 at the Phase 2 gate.
- Phase 2 (complete, 2026-09-10): decomposition into
tasks/+ execution — the eight-task port graph landed crate-init → port-identity/fingerprint/pem-signing → port-server/port-client → integration-suite → this review gate. The crate is ready for the rewrite to consume.