feat(reality): warn when target cert chain is too small for ML-DSA-65 (#6470)

* feat(reality): warn when target cert chain is too small for ML-DSA-65

Expose peer cert-chain DER size from the REALITY scanner and surface a UI
warning when ML-DSA-65 is enabled but the chain is under xray-core's 3500-byte
minimum, so silent fallback failures are easier to catch.

Fixes #5973

* fix(reality): gate scanner ML-DSA tag and sync docs OpenAPI

Only warn on short cert chains in the target scanner when ML-DSA-65 is
enabled. Copy frontend/public/openapi.json to docs/public/openapi.json
and fix oxfmt wrapping in the new test.

---------

Co-authored-by: mrchatam <287639636+mrchatam@users.noreply.github.com>
This commit is contained in:
mrchatam
2026-09-12 12:43:45 +03:30
committed by GitHub
parent 5fbd2b490c
commit b467d4c676
23 changed files with 221 additions and 5 deletions
+8
View File
@@ -3710,6 +3710,11 @@
"example": "h2",
"type": "string"
},
"certChainBytes": {
"description": "CertChainBytes is the sum of DER lengths of the presented peer chain.\nxray-core ML-DSA-65 REALITY needs >= 3500 bytes (constant lives in xray-core).",
"example": 3427,
"type": "integer"
},
"certChainValid": {
"description": "CertChainValid ignores the name: a trusted chain presented for other names\nstill has serverNames the panel can offer instead of the failing SNI.",
"example": true,
@@ -3792,6 +3797,7 @@
},
"required": [
"alpn",
"certChainBytes",
"certChainValid",
"certIssuer",
"certSubject",
@@ -7240,6 +7246,7 @@
"success": true,
"obj": {
"alpn": "h2",
"certChainBytes": 3427,
"certChainValid": true,
"certIssuer": "Google Trust Services",
"certSubject": "cloudflare.com",
@@ -7319,6 +7326,7 @@
"obj": [
{
"alpn": "h2",
"certChainBytes": 3427,
"certChainValid": true,
"certIssuer": "Google Trust Services",
"certSubject": "cloudflare.com",