Skip to content

fix: wait for peer close_notify before retrying TLS unwrap - #16

Merged
kentbull merged 4 commits into
release/v0.6.20from
test/tls-shutdown-oracles
Aug 27, 2026
Merged

kentbull merged 4 commits into
release/v0.6.20from
test/tls-shutdown-oracles

Conversation

@kentbull

@kentbull kentbull commented Aug 27, 2026 •

Copy link
Copy Markdown
Collaborator

Production change

Prevent ClientTls and RemoterTls from retrying unwrap() after WANT_READ until receive processing records authenticated peer closure. This avoids racing peer close_notify and TLS 1.3 application data arriving after local shutdown begins.

Coverage added

  • Typed WANT_READ and WANT_WRITE behavior for TLS receive and send on both endpoint roles.
  • Real TLS 1.3 plaintext arriving while local close waits for peer input.
  • Raw Client peer write shutdown, late send, recurrent-close ordering, and directional aliases.
  • Scheduler-like close plumbing documenting TLS-version policy and shutdown recurrence.

Why

A scheduler recurrence may service receives without making progress. Retrying unwrap() immediately can spin or mishandle final plaintext. The production guard preserves close progress until the receive path records the event required for the next shutdown step.

Boundary

The production change is a small guard in each TLS endpoint. The remaining changes strengthen regression coverage; they do not introduce another shutdown design.

Add a real TLS 1.3 loopback oracle proving that ClientTls and RemoterTls preserve application data sent after local unwrap has entered WANT_READ.

Complete the typed WANT matrix for TLS receive and send paths so both WANT_READ and WANT_WRITE remain explicitly retryable without losing queued output.
Replace mock-only confidence with socket-pair coverage proving that peer EOF leaves Client transmit available for a late response.

Exercise recurrent close ordering and directional shutdown behavior so queued output drains before local write EOF while final peer input remains readable.
Extract the scheduler-like TLS close driver and rename the complex shutdown tests around the contracts they prove, making recurrent completion and version policy visible before reviewers enter each test body.

Add concise RFC context and inline phase anchors for close_notify consumption, nonblocking unwrap advancement, plaintext preservation, and independent TCP half-close directions without changing production code.
Keep ClientTls and RemoterTls in receive service after unwrap returns WANT_READ until peer close_notify is actually observed. This prevents racing TLS 1.3 application data from being consumed inside OpenSSL shutdown and misclassified as APPLICATION_DATA_AFTER_CLOSE_NOTIFY.

Extend the recurrent-close oracle to prove that a no-progress receive does not retry unwrap, then complete only after a scripted peer close_notify arrives.
@kentbull
kentbull merged commit 59f6284 into release/v0.6.20 Aug 27, 2026
6 checks passed
@kentbull
kentbull deleted the test/tls-shutdown-oracles branch August 27, 2026 18:28
@kentbull

Copy link
Copy Markdown
Collaborator Author

Upstream prerequisites: the behaviors exercised here must already exist—Client half-close from #9, TLS receive/send classification from #11/#12, raw recurrent close from #13, and recurrent/version-aware TLS shutdown from #14/#15.

This PR is not entirely test-only: it also fixes the unwrap() retry race by waiting for receive processing to consume peer close_notify. That production fix cannot be upstreamed before the #14/#15-equivalent shutdown machinery exists.

@kentbull kentbull changed the title Test TLS shutdown and Client half-close oracles fix: wait for peer close_notify before retrying TLS unwrap Aug 28, 2026
@kentbull

Copy link
Copy Markdown
Collaborator Author

Adds the typed WANT and real-loopback abrupt-EOF regression coverage for ioflo#173, validating the TLS receive-outcome implementation merged in #11.

@kentbull

Copy link
Copy Markdown
Collaborator Author

Adds the typed WANT and terminal TLS data-plane regression coverage for ioflo#174, validating the send-outcome implementation merged in #12 across both ClientTls and RemoterTls.

@kentbull

Copy link
Copy Markdown
Collaborator Author

Adds the real-socket close-ordering regression coverage for ioflo#175, validating the recurrent raw-TCP close implementation merged in #13.

@kentbull

Copy link
Copy Markdown
Collaborator Author

Completes the downstream fix for ioflo#176 by preventing premature unwrap() retries after a no-progress WANT_READ receive cycle. It also supplies deterministic and real-loopback coverage for pending and racing plaintext while shutdown waits for peer close_notify.

@kentbull

Copy link
Copy Markdown
Collaborator Author

Completes the downstream coverage and shutdown mechanics for ioflo#177 by preventing premature unwrap() retries after WANT_READ and exercising version-aware close behavior with deterministic and real TLS loopback tests.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant