erldistpy/tests
russell@unturf.com 271d712237
phase 6: TLS dist via inet_tls_dist
make_dist_tls_context() builds an ssl.SSLContext tuned for OTP defaults
(verify_peer, mTLS, TLSv1.2 minimum). Node accepts tls_context= and
wraps the TCP socket in TLS before the v6 handshake runs.

Critical quirk found by experimentation: inet_tls_dist uses {packet, 4}
on the SSL socket during the handshake. Plain inet_tcp_dist uses
{packet, 2} for handshake then switches to {packet, 4} post-nodeup.
handshake() now takes a frame_size= kwarg (2 or 4); Node auto-selects 4
whenever tls_context is supplied.

Cert requirements (found by experimentation against Erlang E2E):
  - CA cert with basicConstraints CA:TRUE
  - Leaf certs with SAN including the dist hostname (and localhost)
  - extendedKeyUsage covering both serverAuth and clientAuth

Tests:
  - make_dist_tls_context unit tests
  - Live: spawn erl -proto_dist inet_tls with SAN-bearing certs,
    Node.call(gen_target, {ping, 99}) round-trips through the tunnel
  - Live negative: plaintext connection to TLS-only peer must fail
  - Live negative: client cert from a different CA must fail

115 tests green across 5 consecutive runs, lint clean.
2026-06-16 12:06:07 -04:00
..
__init__.py phase 0 + 1: repo bones and ETF codec 2026-06-16 10:39:01 -04:00
test_channel.py phase 4: distribution data channel 2026-06-16 11:23:16 -04:00
test_epmd.py phase 2: EPMD client 2026-06-16 11:00:00 -04:00
test_etf.py phase 0 + 1: repo bones and ETF codec 2026-06-16 10:39:01 -04:00
test_handshake.py phase 3: v6 distribution handshake 2026-06-16 11:08:28 -04:00
test_node.py phase 5: Node.call() gen_server protocol 2026-06-16 11:33:28 -04:00
test_tls.py phase 6: TLS dist via inet_tls_dist 2026-06-16 12:06:07 -04:00