1c0a1d0db0
Two bugs a stranger can reach, both on the seam V-515 is about to put on the network. The netaddr token handshake ran inline in Listener.Accept, so a peer that connected and never spoke was owed the full 5s handshake timeout, and no other connection could be accepted during it. One unauthenticated stranger holding a socket froze the seam. Accept now reads authorized conns off a channel fed by a loop that greets each one in its own goroutine, and Close releases what is still queued. A unix seam delegates straight through and grows nothing. webauthn kept regs and asserts as bare maps, driven from four HTTP handlers. A concurrent map write is a fatal runtime error rather than a recovered panic, so two browsers beginning a challenge at once take the web daemon down, from an endpoint that answers before any credential is proven. A mutex covers every access, and lookup and delete fold into takeReg and takeAssert. That fold is a security fix in its own right. Two replays of one response both found the challenge before either deleted it, so a challenge was not single-use. The clientDataJSON comparison is constant time now. Checked and already right: every gating value comes from crypto/rand, expiry is checked on use rather than on issue, readFrame caps at 4 MiB before allocating, and internal/auth fails closed on every arm including AuthStepUp with a nil session. stepUpOK's fail-open and fail-closed story rests on package behaviour, since a nil PasskeySession returns false from IsStepUp. (V-581)