nupp.io.tls.spi

Implementation interface for TLS transports.

The facade selects during initialization, retains the provider, and supplies its explicit receiver. The provider wraps an opaque network stream handle, so its transport representation must agree with the selected nupp.io.net.spi implementation.

Wrapping creates TLS state; handshake and I/O then report pending work to the facade, which drives readiness. Verification is a policy input and an observable session result. Do not report a verified peer merely because a handshake completed with verification disabled. ALPN protocol text describes the negotiated result; resumed is an optional observation.

closeNotify sends the TLS shutdown notification and may need further progress. destroy releases session state and the transport it owns. No method may resolve or switch providers.

Module contents

Types

TypeKindDescription
Providerinterface

Types#

Providerinterface#

interface Provider ...

Members

NameKindDescription
priorityfield
wrapmethodCreates session state over a compatible network handle.
handshakemethodReturns true when ready, false while pending, or nil and an error.
verifiedmethodReports whether peer verification succeeded for this session.
resumedfieldOptionally reports whether this session resumed prior TLS state.
readmethodReturns at most wanted bytes, nil while pending, an empty string at EOF, or nil and an error.
writemethodReturns a positive byte count no greater than the input length, nil while pending, or nil and an error.
flushedmethodReturns true when encrypted output has drained, false while pending, or false with an error on failure.
closeNotifymethodStarts or continues orderly TLS shutdown; true means complete, or that the bounded time a drain may take is spent,...
destroymethodReleases TLS session state and its owned transport.
connectedmethodReports whether the session remains connected.
protocolmethodReturns the negotiated ALPN protocol, or nil when none is available.

priorityfield#

priority: integer?
@readonly

wrapmethod#

wrap: function(
    self: Provider,
    handle: any,
    server: boolean,
    hostname: string,
    certificate: string,
    privateKey: string,
    authority: string?,
    protocols: string,
    verify: boolean
): (any?, string?)
@readonly

Creates session state over a compatible network handle. The provider consumes the handle on success and failure.

Certificate, private key, authority, hostname, and ALPN options follow the public TLS API. Returns the session or nil and an error.

Arguments
NameTypeDescription
selfProvider
handleany
serverboolean
hostnamestring
certificatestring
privateKeystring
authoritystring?
protocolsstring
verifyboolean
Returns
TypeDescription
any?
string?

handshakemethod#

handshake: function(self: Provider, session: any): (boolean?, string?)
@readonly

Returns true when ready, false while pending, or nil and an error.

Arguments
NameTypeDescription
selfProvider
sessionany
Returns
TypeDescription
boolean?
string?

verifiedmethod#

verified: function(self: Provider, session: any): boolean
@readonly

Reports whether peer verification succeeded for this session.

Arguments
NameTypeDescription
selfProvider
sessionany
Returns
TypeDescription
boolean

resumedfield#

resumed: (function(self: Provider, session: any): boolean)?
@readonly

Optionally reports whether this session resumed prior TLS state.

readmethod#

read: function(self: Provider, session: any, wanted: integer): (string?, string?)
@readonly

Returns at most wanted bytes, nil while pending, an empty string at EOF, or nil and an error.

Arguments
NameTypeDescription
selfProvider
sessionany
wantedinteger
Returns
TypeDescription
string?
string?

writemethod#

write: function(self: Provider, session: any, bytes: string): (integer?, string?)
@readonly

Returns a positive byte count no greater than the input length, nil while pending, or nil and an error.

Arguments
NameTypeDescription
selfProvider
sessionany
bytesstring
Returns
TypeDescription
integer?
string?

flushedmethod#

flushed: function(self: Provider, session: any): (boolean, string?)
@readonly

Returns true when encrypted output has drained, false while pending, or false with an error on failure.

Arguments
NameTypeDescription
selfProvider
sessionany
Returns
TypeDescription
boolean
string?

closeNotifymethod#

closeNotify: function(self: Provider, session: any): (boolean, string?)
@readonly

Starts or continues orderly TLS shutdown; true means complete, or that the bounded time a drain may take is spent, and false means pending unless accompanied by an error.

Arguments
NameTypeDescription
selfProvider
sessionany
Returns
TypeDescription
boolean
string?

destroymethod#

destroy: function(self: Provider, session: any): nil
@readonly

Releases TLS session state and its owned transport.

Arguments
NameTypeDescription
selfProvider
sessionany
Returns
TypeDescription
nil

connectedmethod#

connected: function(self: Provider, session: any): boolean
@readonly

Reports whether the session remains connected.

Arguments
NameTypeDescription
selfProvider
sessionany
Returns
TypeDescription
boolean

protocolmethod#

protocol: function(self: Provider, session: any): string?
@readonly

Returns the negotiated ALPN protocol, or nil when none is available.

Arguments
NameTypeDescription
selfProvider
sessionany
Returns
TypeDescription
string?