Skip to content

release: strict X.509 compatibility for Hermes Python 3.13 - #72

Merged
ak5 merged 1 commit into
mainfrom
dev
Oct 4, 2026
Merged

ak5 merged 1 commit into
mainfrom
dev

Conversation

@ak5

@ak5 ak5 commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Release

Included changes

  • Release source SHA: c82eb635d7b39f2b5513ab3e0263b1aba199e22e.
  • Fix generated interception chains for Hermes Python 3.13.5/HTTPX 0.28.1 strict X.509 verification: issuer-linked leaf AKI, explicit non-CA constraints/signature usage/server EKU/SKI, and generated CA critical signing usage/identifiers.
  • Required exact-version urllib/HTTPX CONNECT regression in local mise run check and Linux CI, certificate-extension/role assertions, and Infra CA regeneration/trust guidance.
  • Only change since the previous main release: reviewed PR fix: strict X.509 certificate chains for Hermes Python 3.13 #71. Policy, signed/workload listeners, credential mediation, upstream validation, ALPN and separate Hermes admission remain compatible.
  • Known limitation: updating the image cannot fix an installed CA that lacks required extensions. Infra must regenerate it with the corrected binary and distribute matching public trust before acceptance. No client strict/certificate/hostname or upstream validation is relaxed.

Release checks

  • Base main, head dev; normal staged release path.
  • Dev tree matches reviewed all-green fix: strict X.509 certificate chains for Hermes Python 3.13 #71; final local mise run check passes. Fresh release CI must pass on this source.
  • Documentation and security-impact notes are current. Implementing-agent source review recorded on fix: strict X.509 certificate chains for Hermes Python 3.13 #71; no independent audit is claimed.
  • Merge commit required; no squash/rebase release.
  • git merge-base --is-ancestor c82eb635d7b39f2b5513ab3e0263b1aba199e22e origin/main succeeds. Main merge commit cbec5aa4a65e3de2960afce627cf8c6cf083bd6e has two parents and matches the reviewed source tree.

Risk and rollback

  • Risk: Infra owns certificate/key/public-trust lifecycle and its isolated acceptance. Default strict validation must remain enabled. Existing deficient roots require regeneration; external CA chains must also meet strict requirements.
  • Rollback: preserve installed image/layout/config and matching CA/key/trust bundles together; preserve egress isolation and the convergence guard. An incompatible certificate/image rollback does not restore strict Python compatibility.
  • No Infra changes, deployment, issue creation or cutover. After trusted main CI/publication, record actual immutable GHCR digest and run a Charon-only isolated Linux Python 3.13.5/HTTPX 0.28.1 OS-trust proof against the released image so Infra can rerun acceptance.

* fix: generate strict X.509 chains for Hermes clients

* test: declare secure TLS floor in strict client probe

@ak5 ak5 left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Release review: c82eb63 is tree-identical to all-green reviewed #71 and is the only dev change since main d17a865. Reviewed complete generated CA/leaf profile, real strict Python 3.13.5/HTTPX 0.28.1 regression, certificate-role/identifier assertions, unchanged upstream trust/policy/mediation, and CA regeneration/public-trust handoff. Final mise run check and documentation parity pass. No unresolved source-review findings; implementing-agent review, not independent audit. Fresh release checks must pass before an ancestry-preserving merge commit. No Infra edit/deploy or issue creation; actual registry digest and isolated released-image proof will follow trusted main CI/publication.

@ak5
ak5 merged commit cbec5aa into main Oct 4, 2026
14 checks passed
@ak5

ak5 commented Oct 4, 2026

Copy link
Copy Markdown
Owner Author

Certificate compatibility release completed through reviewed dev PR #71 and merge-commit release #72.

Main: cbec5aa4a65e3de2960afce627cf8c6cf083bd6e. Reviewed dev source c82eb635d7b39f2b5513ab3e0263b1aba199e22e is an ancestor and has the same tree.

Immutable gateway pin, verified from GHCR:

ghcr.io/ak5/charon:sha-cbec5aa4a65e3de2960afce627cf8c6cf083bd6e@sha256:28d285a1eab1e2d9c51b548322d01a29e04dd1a7e206b0f1a6c7e6dd06f48fc2

The OCI index contains a linux/amd64 manifest and attestation manifest. Trusted main CI and publication succeeded.

Evidence:

  • Final mise run check passed, including the mandatory Python strict gate. All fresh dev/release/main CI, CodeQL, dependency policy, images and Hermes compatibility passed.
  • Real generated-CA CONNECT regression: Python 3.13.5 urllib and HTTPX 0.28.1 retain strict verification, certificate validation and hostname checking; trusted requests/reuse succeed, denied operations remain denied, untrusted CA and wrong hostname fail, and provider lookup count remains zero.
  • Actual served CA/leaf parsed for critical Basic Constraints/Key Usage, exact DNS SAN, server-only EKU, noncritical key identifiers and AKI/SKI agreement. Existing mediation/protocol/upstream-trust tests remain green.
  • Before fix: real Python test fails with Missing Authority Key Identifier; AKI-only repair exposes CA cert does not include key usage extension. The complete chain repair passes.
  • Charon-only Docker proof reproduced the old immutable image's missing AKI under isolated Linux OS CA trust. Against the new digest-pinned image it reports:
PASS: isolated Linux Python 3.13.5 HTTPX 0.28.1 OpenSSL 3.0.16 11 Feb 2025 OS CA trust and real released gateway GET /zen; denied /user; no provider environment

The new image itself generated the synthetic CA, only its public certificate entered the client, the client had only an internal Docker network, and the production gateway verified real upstream TLS. No real credentials, verification bypass or Infra edits/deployment were used. Disposable Docker resources were removed.

Infra handoff: regenerate any installed CA missing required extensions with this corrected binary and distribute its matching public trust before rerunning acceptance. The image cannot rewrite an installed CA. Keep the convergence guard and egress isolation in place; retain installed image/layout/config/CA-key-trust bundles for rollback. No live cutover or GitHub issue was created. Infra draft #257 was only referenced; all work occurred in Charon.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant