Skip to content

feat: select HTTPS certificates by TLS server name (SNI) - #746

Merged
logbie merged 7 commits into
mainfrom
codex/tls-sni-certificates
Sep 23, 2026
Merged

logbie merged 7 commits into
mainfrom
codex/tls-sni-certificates

Conversation

@logbie

@logbie logbie commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

Behavior

A secured WFL listener currently serves one certificate regardless of the requested domain. This change lets one HTTPS port select the appropriate certificate using TLS SNI:

listen on port 8443 secured with
    certificate "one.pem" and key "one.key" for "one.example.com"
    and certificate "two.pem" and key "two.key" for "two.example.com" as secure_server

Named-only listeners reject unknown or missing SNI. An unnamed certificate/key pair placed first provides an explicit fallback. Existing single-certificate and bare secured forms retain their behavior.

All named pairs are validated before binding: exact DNS names, case-insensitive duplicate detection, key/certificate consistency, certificate hostname coverage, and a 128-entry limit. Selection uses Rustls's SNI resolver and keeps the existing transport/lifecycle implementation. HTTP Host/path routing remains application-controlled.

Includes parser/analyzer/typechecker/linter integration, documentation, WFL regression programs, retained parser fuzz seeds, and a dev diary.

Test evidence

  • Risk: R3 — TLS, untrusted input, and language compatibility.
  • Red → Green: test-first commit 6ad75a47 precedes implementation b1f8d747; original failure chronology and rebase provenance are retained in the evidence record.
  • Ten new tests cover verified TLS against the real binary, exact peer certificates for two names on one port, fallback, rejection, invalid configuration, operand validation, malformed/oversized syntax, stalled clients, shutdown, operand evaluation order/short-circuiting, incompatible named-key rejection without fallback, and real CLI unused-variable analysis.
  • Local development checks passed: 2,431 Rust tests, Clippy, formatting, release/LSP builds, locked fuzz compilation, all three web-suite scenarios, 38 documentation examples, MCP validation, and the 305-second execution-budget test.
  • Local environment limitation: the release program sweep reported 165 passed / 1 failed / 24 existing exclusions. The existing file-I/O program recursively encountered an inaccessible artifact directory created before this work. The unchanged program passed in an isolated directory. The original failure is preserved in the evidence rather than treated as a clean suite result.
  • The branch was rebased onto current main to exclude unrelated ES256 work from the original checkout. Post-rebase and review-fix validation passed all 37 focused TLS tests and 38 analyzer tests, Clippy, formatting, and static hygiene. Operand-order regression: Red 02972e3a → fix b1de5a4f. Unused-variable regression: Red 70745701 → fix 9c7cd998. Final-head CI, Docker validation, and config lint all passed on 9c7cd998. Fresh general and security-focused reviews completed without new findings; all inline findings are resolved.
  • No dependencies, lockfiles, certificate files, or external configuration are changed. Reverting the feature restores the prior syntax; applications using named pairs must use a single certificate or proxy on an older binary.
  • Independent R3 review and clean Linux/Windows CI are complete on the final commit. The PR remains open for maintainer merge.

Devin Review

Summary by CodeRabbit

  • New Features
    • HTTPS listeners now support up to 128 domain-specific TLS certificates on a single port, selected by the requested domain name. An optional default certificate can serve as a fallback; without one, connections with missing or unrecognized domain names are rejected.
    • Certificate configuration is validated when the listener starts, including domain names and certificate/key pairs.
  • Documentation
    • Added configuration guidance and examples for hosting multiple domains over HTTPS, including fallback behavior and the distinction between TLS certificate selection and HTTP routing or authorization.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-23T07:12:10.429318Z 9c7cd99 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 571c9db4-1adf-4ad5-b8ef-83d9e6dbfe63

📥 Commits

Reviewing files that changed from the base of the PR and between 9c7c8f5 and 69a49ea.

📒 Files selected for processing (20)
  • Docs/04-advanced-features/web-servers.md
  • Docs/reference/configuration-reference.md
  • Docs/reference/keyword-reference.md
  • Docs/reference/reserved-keywords.md
  • Engineering/evidence/2026-09-23-tls-sni.md
  • History/dev-diary/2026/2026-09-23-tls-sni.md
  • TestPrograms/docs_examples/_meta/manifest.json
  • TestPrograms/docs_examples/tls_sni/multiple_domains.wfl
  • TestPrograms/tls_sni/startup.test.wfl
  • fuzz/seeds/fuzz_parser/seed_tls_sni.wfl
  • fuzz/seeds/fuzz_parser/seed_tls_sni_default.wfl
  • fuzz/seeds/fuzz_parser/seed_tls_sni_incomplete.wfl
  • src/analyzer/mod.rs
  • src/interpreter/mod.rs
  • src/interpreter/tls.rs
  • src/linter/layout.rs
  • src/parser/ast.rs
  • src/parser/stmt/web.rs
  • src/typechecker/mod.rs
  • tests/web_server_sni_test.rs

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Secured listeners can now use named certificate/key pairs selected by the TLS ClientHello SNI hostname. A listener can also specify an optional default pair. Parser, static validation, runtime TLS setup, tests, examples, and documentation cover the new configuration.

Changes

TLS SNI certificate selection

Layer / File(s) Summary
SNI syntax and expression validation
src/parser/ast.rs, src/parser/stmt/web.rs, src/analyzer/mod.rs, src/typechecker/mod.rs, src/linter/layout.rs, tests/web_server_sni_test.rs, fuzz/seeds/fuzz_parser/*
Adds named certificate/key clauses with a 128-entry limit. Analyzer, type checker, and linter now process hostname and path expressions. Tests and fuzz seeds cover clause parsing and expression validation.
Certificate loading and SNI selection
src/interpreter/mod.rs, src/interpreter/tls.rs, tests/web_server_sni_test.rs, TestPrograms/tls_sni/startup.test.wfl
The interpreter evaluates named certificate settings and passes them to TLS setup. TLS setup validates hostnames and certificate/key pairs, then selects the matching certificate or an explicit default. Tests cover handshakes, invalid configuration, default handling, and connection cancellation.
Documentation and examples
Docs/04-advanced-features/web-servers.md, Docs/reference/*, TestPrograms/docs_examples/tls_sni/*, Engineering/evidence/2026-09-23-tls-sni.md, History/dev-diary/2026/2026-09-23-tls-sni.md
Documents syntax, validation, fallback behavior, and the distinction between TLS certificate selection and HTTP routing or authorization. Adds an example and records test results and limitations.

Priority: ⬇️ Low

Estimated code review effort: 4 (Complex) | ~50 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant WFLInterpreter
  participant TLSConfigLoader
  participant TLSClient
  participant CertificateResolver
  WFLInterpreter->>TLSConfigLoader: Load default and named certificate configuration
  TLSClient->>CertificateResolver: Send ClientHello with SNI hostname
  CertificateResolver->>TLSClient: Return matching certificate or explicit default
Loading

Merge Risk: ⚪ Minimal · up to 69a49

Secured listeners can now serve different certificates for different domains on one HTTPS port. Listeners with only named certificates reject unknown or missing names, and an optional first unnamed certificate serves as the fallback. Existing single-certificate and configuration-based setups keep their behavior. Invalid certificate configurations fail at startup, before the listener binds. No concrete defects remain, so the change is ready to merge once the normal CI checks pass.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 38.10% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 21 functions across 6 files. (14 skipped:… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: selecting HTTPS certificates by TLS server name (SNI).
Full details: Docstring Coverage

Explanation

Docstring coverage is 38.10% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 21 functions across 6 files. (14 skipped: 12 unsupported, 2 too large.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

Devin Review

Comment thread src/interpreter/mod.rs Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 69a49ea8c4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/interpreter/tls.rs

logbie commented Sep 23, 2026

Copy link
Copy Markdown
Collaborator Author

@codex review

Please review final head b1de5a4. The operand-order finding is fixed with retained Red → Green evidence. The fallback concern is addressed with a verified TLS regression demonstrating that the locked Rustls resolver does not fall back for a known incompatible key; details are in that review thread. Local validation: all 36 focused TLS tests, formatting, Clippy, and static hygiene passed.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b1de5a4fff

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/parser/stmt/web.rs

logbie commented Sep 23, 2026

Copy link
Copy Markdown
Collaborator Author

@codex review

Please review head 9c7cd99. The new unused-variable finding is fixed with retained Red/Green CLI and analyzer regressions (7074570 → 9c7cd99). Earlier operand-order and TLS fallback review dispositions remain covered. All 38 analyzer tests and all 37 TLS tests pass locally; final-head CI is being followed.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. What shall we delve into next?

Reviewed commit: 9c7cd998d3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

logbie commented Sep 23, 2026

Copy link
Copy Markdown
Collaborator Author

@codex security review

Please examine final head 9c7cd99 for the R3 security-focused review required by testing.md: SNI hostname/config validation, certificate/key consistency and coverage, explicit-default-only fallback, malformed input limits, and TLS lifecycle. The fresh general review completed without findings; security regression evidence is in Engineering/evidence/2026-09-23-tls-sni.md and tests/web_server_sni_test.rs.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. What shall we delve into next?

Reviewed commit: 9c7cd998d3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

logbie commented Sep 23, 2026

Copy link
Copy Markdown
Collaborator Author

Final validation for 9c7cd99:

  • CI run 2014: all 11 validation jobs passed, including Linux/Windows WFL program and integration suites, both 305-second execution-budget checks, Rust tests/Clippy, extension checks, fuzz compilation, database tests, release scripts, and repository hygiene. The workflow's version-bump job is intentionally skipped for PRs.
  • Docker Runtime Validation: passed.
  • WFL Config Lint: passed.
  • Fresh general review and the requested security-focused review both completed on this exact commit without new findings. All three inline review threads are resolved; CodeRabbit's commit status is successful. Its general docstring-coverage warning remains advisory; it did not identify a missing public contract or blocking code issue.
  • Fixed source-order evaluation and false unused-variable diagnostics with retained test-only Red commits and passing regressions. The incompatible-key/default concern is covered by a verified TLS regression demonstrating the pinned resolver already rejects that case.
  • Local focused validation: 37 TLS tests, 38 analyzer tests, Clippy, formatting, and static hygiene passed. The previously recorded local full program-sweep filesystem limitation is preserved in the evidence; both clean CI platform program suites passed.

The branch is clean and the PR has no merge conflicts. Left open for maintainer merge; no merge or deployment performed.

@logbie
logbie merged commit d256f94 into main Sep 23, 2026
19 checks passed
@logbie
logbie deleted the codex/tls-sni-certificates branch September 23, 2026 07:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant