SSL.QUIC (ex_ssl v0.16.7)

Copy Markdown View Source

Caller-owned TLS 1.3 certificate handshake for QUIC CRYPTO streams.

Feed only new contiguous handshake bytes at the level reported by info/1. Process returned actions in list order. Emitted bytes are committed to the caller's reliable send queue; retransmission reuses them without another TLS call. This API implements no sockets, records, QUIC packets or HANDSHAKE_DONE. See docs/QUIC_TLS_INTERFACE.md for the ownership and authentication boundary.

Summary

Types

action()

@type action() ::
  SSL.QUIC.Secret.t()
  | {:emit, level(), binary()}
  | {:peer_transport_parameters, binary(), :unverified | :authenticated}
  | {:peer_authenticated, :server}
  | {:negotiated_alpn, binary()}
  | :handshake_complete
  | {:error, SSL.QUIC.Error.t()}

level()

@type level() :: :initial | :handshake | :application

result()

@type result() ::
  {:ok, state(), [action()]} | {:error, SSL.QUIC.Error.t(), state(), [action()]}

state()

@opaque state()

Functions

abort(state, reason)

@spec abort(state(), atom()) :: state()

capabilities()

@spec capabilities() :: %{
  cipher_suites: [any()],
  groups: [map()],
  hello_retry_request: true,
  quic_packet_protection: false,
  resumption: false,
  roles: %{client: map(), server: map()},
  server_mtls: false,
  signatures: [map()],
  tls_records: false,
  tls_versions: [772, ...],
  zero_rtt: false
}

feed(state, level, bytes)

@spec feed(state(), level(), binary()) :: result()

info(state)

@spec info(state()) :: map()

new(role, options)

@spec new(:client | :server, keyword()) ::
  {:ok, state(), [action()]} | {:error, SSL.QUIC.Error.t()}