fix: distinguish clean TLS close from truncated EOF - #11
Conversation
Disable ragged-EOF suppression and distinguish retryable TLS WANT conditions, authenticated close_notify, and terminal truncation or socket failures on both ClientTls and RemoterTls. Fatal receive failures retain their cause and force close the unusable transport. Real loopback tests cover abrupt EOF in both directions. Negotiated-version response to a clean close remains a separate policy PR.
|
Upstream prerequisites: accepted independent receive/transmit terminal state and retained terminal causes for both Client and Remoter—the behavioral foundations from #9 and #10. ioflo#163 currently supplies only part of the Remoter side. Once that contract is merged, TLS receive handling can distinguish retryable WANT conditions, clean |
|
Implements downstream receive classification for ioflo#173 by disabling ragged-EOF suppression and separating retryable WANT conditions, authenticated |
What
ClientTlsandRemoterTls.close_notify, abrupt EOF, and fatal TLS/socket failures.Why
Returning empty bytes for both authenticated closure and abrupt TCP EOF erases whether the protected stream ended cleanly or was truncated.
Background
Python normally suppresses ragged TLS EOF and returns empty bytes. Passing
suppress_ragged_eofs=Falseexposes missingclose_notifyas an exception. This PR classifies the receive outcome; PR #15 later applies the negotiated TLS 1.2 or TLS 1.3 peer-close policy.Boundary
TLS send classification, recurrent local shutdown through
unwrap(), and negotiated-version peer-close policy remain separate changes.