Skip to content

Correct RFC citations and stale docs - #226

Merged
Xor-el merged 2 commits into
deep-audit-fixesfrom
audit-doc-citations
Oct 7, 2026
Merged

Xor-el merged 2 commits into
deep-audit-fixesfrom
audit-doc-citations

Conversation

@Xor-el

@Xor-el Xor-el commented Oct 7, 2026

Copy link
Copy Markdown
Owner

A review checked every RFC citation in the tree against the RFC text. Most were right. This fixes the ones that were not, and the docs that had drifted from the code.

  • Citations that pointed at the wrong section or RFC: the MD5/SHA-1 rule is RFC 8446 4.4.2.4, the ticket-age freshness window is 8.3, pinning is RFC 7469 2.6, the ECH SvcParamKey is RFC 9848, the ECDSA curve rules are RFC 8422 5.3, the ALPN and ECH sections moved to where the RFC puts them, and so on. A few cited an RFC for something it does not define (an asynchronous certificate verdict).
  • RFC 6125 is replaced by RFC 9525, which obsoletes it. The README no longer says CN matching is off by default; the library matches SANs only.
  • Comments that named another implementation's helpers, narrated history or described a return value are cut down to the reason.
  • Docs: SecP256r1MLKEM768 is added to the preset group lists and the supported signature schemes, imported PSKs are documented as needing both peers to implement RFC 9258, two cookbook examples are fixed (one leaked, one took the wrong first argument), and the README lists the extensions the library handles.
  • bogo-shim-config.json: description text only.

Comments and docs only, plus one resourcestring citation in the FclNet adapter. FPC x86_64 and i386 1464, Delphi Win32 1464, comment-lint and guid-lint clean.

Xor-el added 2 commits October 7, 2026 02:08
…nd docs

A closing review checked every RFC citation in the tree against the RFC text.
Most were right; this fixes the ones that were not:

- Section numbers that pointed at the wrong place (RFC 8446 4.4.2 for the
  MD5/SHA-1 rule is 4.4.2.4, the ticket-age freshness window is 8.3 not 8.2,
  RFC 7469 pinning is 2.6, the ECH SvcParamKey is RFC 9848, RFC 8422's curve
  rules are 5.3, and so on), and a few citations of an RFC for something it
  does not define (an asynchronous verdict, a tag in a test string).
- RFC 6125 is replaced by RFC 9525, which obsoletes it. The README no longer
  says CN matching is off by default; there is no CN matching at all.
- Comments that named another implementation's helpers, or described a
  mechanism rather than the reason, are cut down to the reason.
- Docs: add SecP256r1MLKEM768 to the preset group lists and the supported
  signature schemes, state that imported PSKs need both peers to implement
  RFC 9258, fix two examples that leaked or took the wrong first argument,
  and list the extensions the library actually handles.

Comments, docs and one resourcestring only; no behaviour changes.
…round them

RFC 8422 2.1 is the ECDHE_ECDSA rule (not 2.2), the CRL point check cites only
the cRLIssuer rule it applies, a missed RFC 9846 reference is RFC 8446 again,
and a secure-connection renegotiation refusal rests on RFC 5246 7.2.2 alone
(RFC 5746 4.2 and 4.4 cover other cases). Drop two stretched citations, a
comment that narrated history and one that described a return value, and
rewrap the longest added lines.
@Xor-el
Xor-el merged commit 3417e2e into deep-audit-fixes Oct 7, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant