Skip to content

fix: distinguish clean TLS close from truncated EOF - #11

Merged
kentbull merged 1 commit into
release/v0.6.20from
p0/tls-receive-outcomes-v0.6.20
Aug 27, 2026
Merged

kentbull merged 1 commit into
release/v0.6.20from
p0/tls-receive-outcomes-v0.6.20

Conversation

@kentbull

@kentbull kentbull commented Aug 27, 2026 •

Copy link
Copy Markdown
Collaborator

What

  • Disable ragged-EOF suppression for ClientTls and RemoterTls.
  • Keep TLS WANT conditions retryable.
  • Distinguish authenticated close_notify, abrupt EOF, and fatal TLS/socket failures.
  • Make server removal safe after receive has already force-closed the TLS socket.

Why

Returning empty bytes for both authenticated closure and abrupt TCP EOF erases whether the protected stream ended cleanly or was truncated.

Background

Python normally suppresses ragged TLS EOF and returns empty bytes. Passing suppress_ragged_eofs=False exposes missing close_notify as an exception. This PR classifies the receive outcome; PR #15 later applies the negotiated TLS 1.2 or TLS 1.3 peer-close policy.

Boundary

TLS send classification, recurrent local shutdown through unwrap(), and negotiated-version peer-close policy remain separate changes.

Disable ragged-EOF suppression and distinguish retryable TLS WANT conditions, authenticated close_notify, and terminal truncation or socket failures on both ClientTls and RemoterTls. Fatal receive failures retain their cause and force close the unusable transport.

Real loopback tests cover abrupt EOF in both directions. Negotiated-version response to a clean close remains a separate policy PR.
@kentbull
kentbull merged commit 702a005 into release/v0.6.20 Aug 27, 2026
6 checks passed
@kentbull
kentbull deleted the p0/tls-receive-outcomes-v0.6.20 branch August 27, 2026 10:36
@kentbull

Copy link
Copy Markdown
Collaborator Author

Upstream prerequisites: accepted independent receive/transmit terminal state and retained terminal causes for both Client and Remoter—the behavioral foundations from #9 and #10. ioflo#163 currently supplies only part of the Remoter side.

Once that contract is merged, TLS receive handling can distinguish retryable WANT conditions, clean close_notify, ragged EOF, and fatal transport failure. Graceful TLS shutdown is not a prerequisite for this classification.

@kentbull

kentbull commented Aug 28, 2026 •

Copy link
Copy Markdown
Collaborator Author

Implements downstream receive classification for ioflo#173 by disabling ragged-EOF suppression and separating retryable WANT conditions, authenticated close_notify, abrupt EOF, and fatal TLS/socket failures for ClientTls and RemoterTls. #15 supplies negotiated-version peer-close policy, and #16 expands regression coverage.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant