0.00% Lines (0/4)
0.00% Functions (0/2)
| TLA | Baseline | Branch | ||||||
|---|---|---|---|---|---|---|---|---|
| Line | Hits | Code | Line | Hits | Code | |||
| 1 | // | 1 | // | |||||
| 2 | // Copyright (c) 2025 Vinnie Falco (vinnie.falco@gmail.com) | 2 | // Copyright (c) 2025 Vinnie Falco (vinnie.falco@gmail.com) | |||||
| 3 | // Copyright (c) 2026 Michael Vandeberg | 3 | // Copyright (c) 2026 Michael Vandeberg | |||||
| 4 | // Copyright (c) 2026 Steve Gerbino | 4 | // Copyright (c) 2026 Steve Gerbino | |||||
| 5 | // | 5 | // | |||||
| 6 | // Distributed under the Boost Software License, Version 1.0. (See accompanying | 6 | // Distributed under the Boost Software License, Version 1.0. (See accompanying | |||||
| 7 | // file LICENSE_1_0.txt or copy at http://www.boost.org/LICENSE_1_0.txt) | 7 | // file LICENSE_1_0.txt or copy at http://www.boost.org/LICENSE_1_0.txt) | |||||
| 8 | // | 8 | // | |||||
| 9 | // Official repository: https://github.com/cppalliance/corosio | 9 | // Official repository: https://github.com/cppalliance/corosio | |||||
| 10 | // | 10 | // | |||||
| 11 | 11 | |||||||
| 12 | #ifndef BOOST_COROSIO_TLS_STREAM_HPP | 12 | #ifndef BOOST_COROSIO_TLS_STREAM_HPP | |||||
| 13 | #define BOOST_COROSIO_TLS_STREAM_HPP | 13 | #define BOOST_COROSIO_TLS_STREAM_HPP | |||||
| 14 | 14 | |||||||
| 15 | #include <boost/corosio/detail/config.hpp> | 15 | #include <boost/corosio/detail/config.hpp> | |||||
| 16 | #include <boost/capy/buffers.hpp> | 16 | #include <boost/capy/buffers.hpp> | |||||
| 17 | #include <boost/capy/detail/buffer_array.hpp> | 17 | #include <boost/capy/detail/buffer_array.hpp> | |||||
| 18 | #include <boost/capy/io/any_stream.hpp> | 18 | #include <boost/capy/io/any_stream.hpp> | |||||
| 19 | #include <boost/capy/io_task.hpp> | 19 | #include <boost/capy/io_task.hpp> | |||||
| 20 | 20 | |||||||
| 21 | #include <cstddef> | 21 | #include <cstddef> | |||||
| 22 | #include <string_view> | 22 | #include <string_view> | |||||
| 23 | 23 | |||||||
| 24 | namespace boost::corosio { | 24 | namespace boost::corosio { | |||||
| 25 | 25 | |||||||
| 26 | /** TLS handshake role. | 26 | /** TLS handshake role. | |||||
| 27 | 27 | |||||||
| 28 | Specifies whether to perform the TLS handshake as a client or server. | 28 | Specifies whether to perform the TLS handshake as a client or server. | |||||
| 29 | 29 | |||||||
| 30 | @see tls_stream::handshake | 30 | @see tls_stream::handshake | |||||
| 31 | */ | 31 | */ | |||||
| 32 | enum class tls_role | 32 | enum class tls_role | |||||
| 33 | { | 33 | { | |||||
| 34 | /// Perform handshake as the connecting client. | 34 | /// Perform handshake as the connecting client. | |||||
| 35 | client, | 35 | client, | |||||
| 36 | 36 | |||||||
| 37 | /// Perform handshake as the accepting server. | 37 | /// Perform handshake as the accepting server. | |||||
| 38 | server | 38 | server | |||||
| 39 | }; | 39 | }; | |||||
| 40 | 40 | |||||||
| 41 | - | /** Abstract base class for TLS streams. | 41 | + | /** Reads, writes, and manages the handshake lifecycle of a TLS | |||
| 42 | + | session over an underlying stream. | ||||||
| 42 | 43 | |||||||
| 43 | This class provides a runtime-polymorphic interface for TLS | 44 | This class provides a runtime-polymorphic interface for TLS | |||||
| 44 | - | implementations. Derived classes (openssl_stream, wolfssl_stream) | 45 | + | implementations. Derived classes (`openssl_stream`, `wolfssl_stream`) | |||
| 45 | implement the virtual functions to provide backend-specific | 46 | implement the virtual functions to provide backend-specific | |||||
| 46 | TLS functionality. | 47 | TLS functionality. | |||||
| 47 | 48 | |||||||
| 48 | - | Unlike @ref io_stream which represents OS-level I/O completed | 49 | + | An @ref io_stream represents OS-level I/O completed by the kernel. | |||
| 49 | - | by the kernel, TLS streams are coroutine-based: their operations | 50 | + | TLS streams are coroutine-based instead: their operations are | |||
| 50 | - | are implemented as coroutines that orchestrate sub-operations | 51 | + | coroutines that orchestrate sub-operations on the underlying stream. | |||
| 51 | - | on the underlying stream. | ||||||
| 52 | 52 | |||||||
| 53 | The non-virtual template wrappers (`read_some`, `write_some`) | 53 | The non-virtual template wrappers (`read_some`, `write_some`) | |||||
| 54 | satisfy the `capy::Stream` concept, enabling TLS streams to | 54 | satisfy the `capy::Stream` concept, enabling TLS streams to | |||||
| 55 | be used anywhere a Stream is expected. | 55 | be used anywhere a Stream is expected. | |||||
| 56 | 56 | |||||||
| 57 | @par Thread Safety | 57 | @par Thread Safety | |||||
| 58 | Distinct objects: Safe.@n | 58 | Distinct objects: Safe.@n | |||||
| 59 | Shared objects: Unsafe, with one exception: one read operation and | 59 | Shared objects: Unsafe, with one exception: one read operation and | |||||
| 60 | one write operation may be in flight simultaneously. `shutdown()` | 60 | one write operation may be in flight simultaneously. `shutdown()` | |||||
| 61 | - | may overlap a pending read. When the execution context runs on | 61 | + | may overlap a pending read. On a multi-threaded execution context, | |||
| 62 | - | multiple threads, all operations on one stream must be performed | 62 | + | all operations on one stream must run within the same | |||
| 63 | - | within the same `capy::strand` (or otherwise never run | 63 | + | `capy::strand`, or must otherwise never run concurrently. A | |||
| 64 | - | concurrently); a single-threaded context needs no strand. | 64 | + | single-threaded context needs no strand. | |||
| 65 | 65 | |||||||
| 66 | @see openssl_stream, wolfssl_stream | 66 | @see openssl_stream, wolfssl_stream | |||||
| 67 | */ | 67 | */ | |||||
| 68 | class BOOST_COROSIO_DECL tls_stream | 68 | class BOOST_COROSIO_DECL tls_stream | |||||
| 69 | { | 69 | { | |||||
| 70 | public: | 70 | public: | |||||
| 71 | /// Destroy the TLS stream. | 71 | /// Destroy the TLS stream. | |||||
| 72 | virtual ~tls_stream() = default; | 72 | virtual ~tls_stream() = default; | |||||
| 73 | 73 | |||||||
| 74 | - | tls_stream(tls_stream const&) = delete; | 74 | + | /// Copy construction is disabled; copying a stream would slice the derived session. | |||
| 75 | + | tls_stream(tls_stream const&) = delete; | ||||||
| 76 | + | /// Copy assignment is disabled; copying a stream would slice the derived session. | ||||||
| 75 | tls_stream& operator=(tls_stream const&) = delete; | 77 | tls_stream& operator=(tls_stream const&) = delete; | |||||
| 76 | 78 | |||||||
| 77 | /** Initiate an asynchronous read operation. | 79 | /** Initiate an asynchronous read operation. | |||||
| 78 | 80 | |||||||
| 79 | Reads decrypted data into the provided buffer sequence. The | 81 | Reads decrypted data into the provided buffer sequence. The | |||||
| 80 | - | operation completes when at least one byte has been read, | 82 | + | operation completes when it reads at least one byte, | |||
| 81 | or an error occurs. | 83 | or an error occurs. | |||||
| 82 | 84 | |||||||
| 83 | This non-virtual template wrapper satisfies the `capy::Stream` | 85 | This non-virtual template wrapper satisfies the `capy::Stream` | |||||
| 84 | concept by delegating to the virtual `do_read_some`. | 86 | concept by delegating to the virtual `do_read_some`. | |||||
| 85 | 87 | |||||||
| 86 | @par Thread Safety | 88 | @par Thread Safety | |||||
| 87 | May run concurrently with one operation in the other | 89 | May run concurrently with one operation in the other | |||||
| 88 | direction, subject to the class-level threading contract. | 90 | direction, subject to the class-level threading contract. | |||||
| 89 | Two concurrent operations in the same direction are | 91 | Two concurrent operations in the same direction are | |||||
| 90 | undefined. | 92 | undefined. | |||||
| 91 | 93 | |||||||
| 92 | @param buffers The buffer sequence to read data into. | 94 | @param buffers The buffer sequence to read data into. | |||||
| 93 | 95 | |||||||
| 94 | @return An awaitable yielding `(error_code,std::size_t)`. | 96 | @return An awaitable yielding `(error_code,std::size_t)`. | |||||
| 95 | */ | 97 | */ | |||||
| 96 | template<capy::MutableBufferSequence Buffers> | 98 | template<capy::MutableBufferSequence Buffers> | |||||
| MISUBC | 97 | ✗ | [[nodiscard]] auto read_some(Buffers const& buffers) | 99 | ✗ | [[nodiscard]] auto read_some(Buffers const& buffers) | ||
| 98 | { | 100 | { | |||||
| MISUBC | 99 | ✗ | return do_read_some(buffers); | 101 | ✗ | return do_read_some(buffers); | ||
| 100 | } | 102 | } | |||||
| 101 | 103 | |||||||
| 102 | /** Initiate an asynchronous write operation. | 104 | /** Initiate an asynchronous write operation. | |||||
| 103 | 105 | |||||||
| 104 | Encrypts and writes data from the provided buffer sequence. | 106 | Encrypts and writes data from the provided buffer sequence. | |||||
| 105 | - | The operation completes when at least one byte has been | 107 | + | The operation completes when it writes at least one byte, | |||
| 106 | - | written, or an error occurs. | 108 | + | or an error occurs. | |||
| 107 | 109 | |||||||
| 108 | This non-virtual template wrapper satisfies the `capy::Stream` | 110 | This non-virtual template wrapper satisfies the `capy::Stream` | |||||
| 109 | concept by delegating to the virtual `do_write_some`. | 111 | concept by delegating to the virtual `do_write_some`. | |||||
| 110 | 112 | |||||||
| 111 | @par Thread Safety | 113 | @par Thread Safety | |||||
| 112 | May run concurrently with one operation in the other | 114 | May run concurrently with one operation in the other | |||||
| 113 | direction, subject to the class-level threading contract. | 115 | direction, subject to the class-level threading contract. | |||||
| 114 | Two concurrent operations in the same direction are | 116 | Two concurrent operations in the same direction are | |||||
| 115 | undefined. | 117 | undefined. | |||||
| 116 | 118 | |||||||
| 117 | @param buffers The buffer sequence containing data to write. | 119 | @param buffers The buffer sequence containing data to write. | |||||
| 118 | 120 | |||||||
| 119 | @return An awaitable yielding `(error_code,std::size_t)`. | 121 | @return An awaitable yielding `(error_code,std::size_t)`. | |||||
| 120 | */ | 122 | */ | |||||
| 121 | template<capy::ConstBufferSequence Buffers> | 123 | template<capy::ConstBufferSequence Buffers> | |||||
| MISUBC | 122 | ✗ | [[nodiscard]] auto write_some(Buffers const& buffers) | 124 | ✗ | [[nodiscard]] auto write_some(Buffers const& buffers) | ||
| 123 | { | 125 | { | |||||
| MISUBC | 124 | ✗ | return do_write_some(buffers); | 126 | ✗ | return do_write_some(buffers); | ||
| 125 | } | 127 | } | |||||
| 126 | 128 | |||||||
| 127 | /** Asynchronously perform the TLS handshake. | 129 | /** Asynchronously perform the TLS handshake. | |||||
| 128 | 130 | |||||||
| 129 | Initiates the TLS handshake process. For client connections, | 131 | Initiates the TLS handshake process. For client connections, | |||||
| 130 | this sends the ClientHello and processes the server's response. | 132 | this sends the ClientHello and processes the server's response. | |||||
| 131 | For server connections, this waits for the ClientHello and | 133 | For server connections, this waits for the ClientHello and | |||||
| 132 | sends the server's response. | 134 | sends the server's response. | |||||
| 133 | 135 | |||||||
| 134 | - | A handshake attempt, successful or not, consumes the stream | 136 | + | A handshake attempt consumes the stream state, whether it | |||
| 135 | - | state: a subsequent call behaves as if `reset()` had been | 137 | + | succeeds or not. A subsequent call behaves as if `reset()` ran | |||
| 136 | - | called first and performs a fresh handshake using the | 138 | + | first, and performs a fresh handshake using the current | |||
| 137 | - | current configuration. | 139 | + | configuration. | |||
| 138 | 140 | |||||||
| 139 | - | @par Preconditions | 141 | + | @pre The underlying stream must be connected. No other TLS | |||
| 140 | - | The underlying stream must be connected. No other TLS | 142 | + | operation may be in progress on this stream. | |||
| 141 | - | operation may be in progress on this stream. | ||||||
| 142 | 143 | |||||||
| 143 | @param role The handshake role, client or server. | 144 | @param role The handshake role, client or server. | |||||
| 144 | 145 | |||||||
| 145 | @return An awaitable yielding `(error_code)`. | 146 | @return An awaitable yielding `(error_code)`. | |||||
| 146 | */ | 147 | */ | |||||
| 147 | [[nodiscard]] virtual capy::io_task<> handshake(tls_role role) = 0; | 148 | [[nodiscard]] virtual capy::io_task<> handshake(tls_role role) = 0; | |||||
| 148 | 149 | |||||||
| 149 | /** Asynchronously perform a graceful TLS shutdown. | 150 | /** Asynchronously perform a graceful TLS shutdown. | |||||
| 150 | 151 | |||||||
| 151 | Initiates the TLS shutdown sequence by sending a close_notify | 152 | Initiates the TLS shutdown sequence by sending a close_notify | |||||
| 152 | alert and waiting for the peer's close_notify response. | 153 | alert and waiting for the peer's close_notify response. | |||||
| 153 | 154 | |||||||
| 154 | - | @par Preconditions | 155 | + | @pre A handshake must have completed successfully. May overlap | |||
| 155 | - | A handshake must have completed successfully. May overlap | 156 | + | a pending read. No concurrent write may be in progress. | |||
| 156 | - | a pending read. No concurrent write may be in progress. | ||||||
| 157 | 157 | |||||||
| 158 | @par Postconditions | 158 | @par Postconditions | |||||
| 159 | - | If the transport ends before the peer's close_notify is | 159 | + | If the transport ends before the peer's close_notify arrives, | |||
| 160 | - | received, the result is `capy::error::stream_truncated`, not | 160 | + | the result is `capy::error::stream_truncated`, not success. An | |||
| 161 | - | success: an unannounced close is indistinguishable from a | 161 | + | unannounced close is indistinguishable from a truncation attack, | |||
| 162 | - | truncation attack and must not be reported as a clean | 162 | + | so it must not be reported as a clean shutdown. A shutdown | |||
| 163 | - | shutdown. A shutdown stopped mid-flight reports canceled; | 163 | + | stopped mid-flight reports canceled. Any other transport | |||
| 164 | - | any other transport error propagates unchanged. | 164 | + | error propagates unchanged. | |||
| 165 | 165 | |||||||
| 166 | @return An awaitable yielding `(error_code)`. | 166 | @return An awaitable yielding `(error_code)`. | |||||
| 167 | */ | 167 | */ | |||||
| 168 | [[nodiscard]] virtual capy::io_task<> shutdown() = 0; | 168 | [[nodiscard]] virtual capy::io_task<> shutdown() = 0; | |||||
| 169 | 169 | |||||||
| 170 | /** Reset TLS session state for reuse. | 170 | /** Reset TLS session state for reuse. | |||||
| 171 | 171 | |||||||
| 172 | Releases TLS session state including session keys and peer | 172 | Releases TLS session state including session keys and peer | |||||
| 173 | certificates, returning the stream to a state where | 173 | certificates, returning the stream to a state where | |||||
| 174 | `handshake()` can be called again. Internal memory | 174 | `handshake()` can be called again. Internal memory | |||||
| 175 | allocations (I/O buffers) are preserved. | 175 | allocations (I/O buffers) are preserved. | |||||
| 176 | 176 | |||||||
| 177 | Calling `handshake()` on a previously-used stream | 177 | Calling `handshake()` on a previously-used stream | |||||
| 178 | implicitly performs a reset first, so explicit calls | 178 | implicitly performs a reset first, so explicit calls | |||||
| 179 | are only needed to eagerly release session state. | 179 | are only needed to eagerly release session state. | |||||
| 180 | 180 | |||||||
| 181 | - | @par Preconditions | 181 | + | @pre No TLS operation (handshake, read, write, shutdown) is | |||
| 182 | - | No TLS operation (handshake, read, write, shutdown) is | 182 | + | in progress. | |||
| 183 | - | in progress. | ||||||
| 184 | 183 | |||||||
| 185 | @par Thread Safety | 184 | @par Thread Safety | |||||
| 186 | Not thread safe. The caller must ensure no concurrent | 185 | Not thread safe. The caller must ensure no concurrent | |||||
| 187 | operations are in progress on this stream. | 186 | operations are in progress on this stream. | |||||
| 188 | 187 | |||||||
| 189 | @note If called mid-session before `shutdown()`, pending | 188 | @note If called mid-session before `shutdown()`, pending | |||||
| 190 | - | TLS data is discarded and the peer will observe a | 189 | + | TLS data is discarded and the peer observes a | |||
| 191 | truncated stream. | 190 | truncated stream. | |||||
| 192 | */ | 191 | */ | |||||
| 193 | virtual void reset() = 0; | 192 | virtual void reset() = 0; | |||||
| 194 | 193 | |||||||
| 195 | /** Set the peer hostname for SNI and certificate verification. | 194 | /** Set the peer hostname for SNI and certificate verification. | |||||
| 196 | 195 | |||||||
| 197 | Configures the hostname sent in the TLS Server Name | 196 | Configures the hostname sent in the TLS Server Name | |||||
| 198 | Indication extension and matched against the peer | 197 | Indication extension and matched against the peer | |||||
| 199 | certificate during verification. The value takes effect | 198 | certificate during verification. The value takes effect | |||||
| 200 | at the next `handshake()`; an established session is not | 199 | at the next `handshake()`; an established session is not | |||||
| 201 | affected. It persists across `reset()`, so a stream reused | 200 | affected. It persists across `reset()`, so a stream reused | |||||
| 202 | to reach a different host must set the new name before | 201 | to reach a different host must set the new name before | |||||
| 203 | handshaking again. | 202 | handshaking again. | |||||
| 204 | 203 | |||||||
| 205 | An empty hostname (the default) disables SNI and hostname | 204 | An empty hostname (the default) disables SNI and hostname | |||||
| 206 | verification. | 205 | verification. | |||||
| 207 | 206 | |||||||
| 208 | If `hostname` is an IP literal (IPv4 or IPv6), it is matched | 207 | If `hostname` is an IP literal (IPv4 or IPv6), it is matched | |||||
| 209 | - | against the certificate's iPAddress entries instead of its | 208 | + | against the certificate's iPAddress entries instead of its DNS | |||
| 210 | - | DNS names, and no SNI is sent (RFC 6066 excludes literals). | 209 | + | names. No SNI is sent, because RFC 6066 excludes literals. | |||
| 211 | A backend build that cannot match iPAddress entries fails the | 210 | A backend build that cannot match iPAddress entries fails the | |||||
| 212 | handshake with `std::errc::function_not_supported` rather | 211 | handshake with `std::errc::function_not_supported` rather | |||||
| 213 | than skip verification. | 212 | than skip verification. | |||||
| 214 | 213 | |||||||
| 215 | @par Postconditions | 214 | @par Postconditions | |||||
| 216 | The next `handshake()` uses `hostname` for SNI and | 215 | The next `handshake()` uses `hostname` for SNI and | |||||
| 217 | certificate verification, or neither if it is empty. | 216 | certificate verification, or neither if it is empty. | |||||
| 218 | 217 | |||||||
| 219 | @note The hostname is used for client handshakes only; | 218 | @note The hostname is used for client handshakes only; | |||||
| 220 | it is ignored when handshaking as a server. | 219 | it is ignored when handshaking as a server. | |||||
| 221 | 220 | |||||||
| 222 | @param hostname The peer hostname, or empty to disable. | 221 | @param hostname The peer hostname, or empty to disable. | |||||
| 223 | */ | 222 | */ | |||||
| 224 | virtual void set_hostname(std::string_view hostname) = 0; | 223 | virtual void set_hostname(std::string_view hostname) = 0; | |||||
| 225 | 224 | |||||||
| 226 | /** Return a reference to the underlying stream. | 225 | /** Return a reference to the underlying stream. | |||||
| 227 | 226 | |||||||
| 228 | Provides access to the type-erased underlying stream for | 227 | Provides access to the type-erased underlying stream for | |||||
| 229 | operations like cancellation or accessing native handles. | 228 | operations like cancellation or accessing native handles. | |||||
| 230 | 229 | |||||||
| 231 | @warning Do not reseat (assign to) the returned reference. | 230 | @warning Do not reseat (assign to) the returned reference. | |||||
| 232 | The TLS implementation holds internal state bound to | 231 | The TLS implementation holds internal state bound to | |||||
| 233 | the original stream. Replacing it causes undefined | 232 | the original stream. Replacing it causes undefined | |||||
| 234 | behavior. | 233 | behavior. | |||||
| 235 | 234 | |||||||
| 236 | @return Reference to the wrapped stream. | 235 | @return Reference to the wrapped stream. | |||||
| 237 | */ | 236 | */ | |||||
| 238 | virtual capy::any_stream& next_layer() noexcept = 0; | 237 | virtual capy::any_stream& next_layer() noexcept = 0; | |||||
| 239 | 238 | |||||||
| 240 | /** Return a const reference to the underlying stream. | 239 | /** Return a const reference to the underlying stream. | |||||
| 241 | 240 | |||||||
| 242 | @return Const reference to the wrapped stream. | 241 | @return Const reference to the wrapped stream. | |||||
| 243 | */ | 242 | */ | |||||
| 244 | virtual capy::any_stream const& next_layer() const noexcept = 0; | 243 | virtual capy::any_stream const& next_layer() const noexcept = 0; | |||||
| 245 | 244 | |||||||
| 246 | /** Return the name of the TLS backend. | 245 | /** Return the name of the TLS backend. | |||||
| 247 | 246 | |||||||
| 248 | @return A string identifying the TLS implementation, | 247 | @return A string identifying the TLS implementation, | |||||
| 249 | such as "openssl" or "wolfssl". | 248 | such as "openssl" or "wolfssl". | |||||
| 250 | */ | 249 | */ | |||||
| 251 | virtual std::string_view name() const noexcept = 0; | 250 | virtual std::string_view name() const noexcept = 0; | |||||
| 252 | 251 | |||||||
| 253 | /** Return the ALPN protocol negotiated during the handshake. | 252 | /** Return the ALPN protocol negotiated during the handshake. | |||||
| 254 | 253 | |||||||
| 255 | Application-Layer Protocol Negotiation selects a single | 254 | Application-Layer Protocol Negotiation selects a single | |||||
| 256 | application protocol (for example `"h2"` or `"http/1.1"`) | 255 | application protocol (for example `"h2"` or `"http/1.1"`) | |||||
| 257 | during the TLS handshake, from the list supplied via | 256 | during the TLS handshake, from the list supplied via | |||||
| 258 | @ref tls_context::set_alpn. | 257 | @ref tls_context::set_alpn. | |||||
| 259 | 258 | |||||||
| 260 | - | @return The negotiated protocol, or an empty view if no | 259 | + | @return The negotiated protocol, or an empty view. It is empty | |||
| 261 | - | protocol was negotiated, ALPN was not offered, the | 260 | + | if no protocol was negotiated or ALPN was not offered. It is | |||
| 262 | - | handshake has not completed, or the backend/build does | 261 | + | also empty if the handshake has not completed, or if the build | |||
| 263 | - | not support ALPN. | 262 | + | lacks ALPN support. | |||
| 264 | 263 | |||||||
| 265 | @par Thread Safety | 264 | @par Thread Safety | |||||
| 266 | Safe to call after the handshake completes; not safe to call | 265 | Safe to call after the handshake completes; not safe to call | |||||
| 267 | concurrently with a handshake or reset. | 266 | concurrently with a handshake or reset. | |||||
| 268 | */ | 267 | */ | |||||
| 269 | virtual std::string_view alpn_protocol() const noexcept | 268 | virtual std::string_view alpn_protocol() const noexcept | |||||
| 270 | { | 269 | { | |||||
| 271 | return {}; | 270 | return {}; | |||||
| 272 | } // LCOV_EXCL_LINE every concrete stream overrides this; the base default is never called | 271 | } // LCOV_EXCL_LINE every concrete stream overrides this; the base default is never called | |||||
| 273 | 272 | |||||||
| 274 | protected: | 273 | protected: | |||||
| 274 | + | /// Default construct; a derived class supplies the session. | ||||||
| 275 | tls_stream() = default; | 275 | tls_stream() = default; | |||||
| 276 | 276 | |||||||
| 277 | - | /** Virtual read implementation. | 277 | + | /** Perform the backend-specific decrypted read. | |||
| 278 | 278 | |||||||
| 279 | Derived classes override this to perform TLS decryption | 279 | Derived classes override this to perform TLS decryption | |||||
| 280 | and read operations. | 280 | and read operations. | |||||
| 281 | 281 | |||||||
| 282 | @param buffers Buffer sequence to read into. | 282 | @param buffers Buffer sequence to read into. | |||||
| 283 | 283 | |||||||
| 284 | @return An awaitable yielding `(error_code,std::size_t)`. | 284 | @return An awaitable yielding `(error_code,std::size_t)`. | |||||
| 285 | */ | 285 | */ | |||||
| 286 | virtual capy::io_task<std::size_t> do_read_some( | 286 | virtual capy::io_task<std::size_t> do_read_some( | |||||
| 287 | capy::detail::mutable_buffer_array<capy::detail::max_iovec_> | 287 | capy::detail::mutable_buffer_array<capy::detail::max_iovec_> | |||||
| 288 | buffers) = 0; | 288 | buffers) = 0; | |||||
| 289 | 289 | |||||||
| 290 | - | /** Virtual write implementation. | 290 | + | /** Perform the backend-specific encrypted write. | |||
| 291 | 291 | |||||||
| 292 | Derived classes override this to perform TLS encryption | 292 | Derived classes override this to perform TLS encryption | |||||
| 293 | and write operations. | 293 | and write operations. | |||||
| 294 | 294 | |||||||
| 295 | @param buffers Buffer sequence to write from. | 295 | @param buffers Buffer sequence to write from. | |||||
| 296 | 296 | |||||||
| 297 | @return An awaitable yielding `(error_code,std::size_t)`. | 297 | @return An awaitable yielding `(error_code,std::size_t)`. | |||||
| 298 | */ | 298 | */ | |||||
| 299 | virtual capy::io_task<std::size_t> do_write_some( | 299 | virtual capy::io_task<std::size_t> do_write_some( | |||||
| 300 | capy::detail::const_buffer_array<capy::detail::max_iovec_> buffers) = 0; | 300 | capy::detail::const_buffer_array<capy::detail::max_iovec_> buffers) = 0; | |||||
| 301 | }; | 301 | }; | |||||
| 302 | 302 | |||||||
| 303 | } // namespace boost::corosio | 303 | } // namespace boost::corosio | |||||
| 304 | 304 | |||||||
| 305 | #endif | 305 | #endif | |||||