macula_tls_posture (macula v13.2.1)

View Source

The TLS posture handshake v5 depends on, checked before peering starts (plans/DESIGN_NEIGHBOUR_CHANNEL_BINDING.md sections 3 and 6). v5 lets QUIC's AEAD authenticate every frame after the session proofs, which holds only if the session's keys come from a hybrid ML-KEM exchange and no frame travels in replayable 0-RTT. So both ends offer exactly SecP384r1MLKEM1024 then SecP256r1MLKEM768, neither offers nor accepts early data or sends tickets, a second handshake between the same configurations is a full one, and the dialler's own setting holds too: against a listener that does issue tickets, its second handshake is also full.

This proves the posture the configurations have, as macula_quic:tls_posture/0 reads it from the NIF, not the group any one connection negotiated; since only hybrid groups are offered, no handshake can negotiate another.

Summary

Functions

The first field of Posture that departs from the one handshake v5 depends on, or ok.

Check this build's posture, and raise naming the first departure. Called where peering starts, so a node with another posture does not run.

Types

posture/0

-type posture() ::
          #{dialler_second_handshake := full | resumed,
            client_groups := [non_neg_integer()],
            server_groups := [non_neg_integer()],
            client_early_data := 0 | 1,
            server_max_early_data := non_neg_integer(),
            server_tickets := non_neg_integer(),
            second_handshake := full | resumed}.

Functions

check(Posture)

-spec check(posture()) -> ok | {error, {tls_posture, atom(), term()}}.

The first field of Posture that departs from the one handshake v5 depends on, or ok.

ensure()

-spec ensure() -> ok.

Check this build's posture, and raise naming the first departure. Called where peering starts, so a node with another posture does not run.