fix: add recurrent TLS close_notify shutdown - #14
Merged
Merged
Conversation
Implement nonblocking TLS close as a recurrent unwrap exchange on ClientTls and RemoterTls. The close waits for accepted output, rejects later writes, retries WANT_READ and WANT_WRITE, preserves pending plaintext, bypasses unwrap after fatal transport state, and closes the raw socket returned on success. Route all shutdown entry points through that exchange without hiding TLS errors. Negotiated TLS 1.2 versus 1.3 behavior after peer close_notify remains a separate policy PR.
Collaborator
Author
|
Upstream prerequisites: #11-equivalent clean-versus-truncated TLS receive classification, #12-equivalent terminal TLS send handling, and #13-equivalent recurrent close ownership, all implemented against the accepted directional-state contract. With those merged, |
This was referenced Aug 28, 2026
Collaborator
Author
|
Implements the primary downstream fix for ioflo#176: recurrent TLS |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
ClientTlsandRemoterTlsshutdown throughSSLSocket.unwrap().unwrap().Why
Closing the underlying socket directly can truncate accepted output and bypass authenticated TLS shutdown. A nonblocking endpoint cannot assume OpenSSL completes shutdown in one scheduler cycle.
Background
SSLSocket.unwrap()drives OpenSSL's shutdown state and returns the underlying socket when that operation completes. The protocol meaning of peerclose_notifyis version-specific; PR #15 supplies that TLS 1.2 versus TLS 1.3 policy.Boundary
PR #16 later prevents premature
unwrap()retry after a no-progress WANT_READ cycle. Owners remain responsible for recurring close, applying deadlines, and choosing force-close.