Documentation
¶
Overview ¶
Package mbedtls wraps a vendored mbedTLS for the TinyGo Linux HTTPS backend.
TinyGo cannot link the OS OpenSSL at all: it emits no PT_INTERP, so dynamic relocations are never applied, and a static link needs roughly forty shim symbols whose set depends on how the distribution built OpenSSL. Compiling mbedTLS from source with TinyGo's own cgo sidesteps both problems, because the result is built against TinyGo's own musl and links statically.
The vendored sources and the transformations applied to them are described in PATCHES.md and reproduced by vendor.py.
This package is only built for TinyGo on Linux, or for host Go with the force_tinygo_logic tag. Everywhere else Supported reports false and the package contains no C.
Index ¶
Constants ¶
const ( BadCertExpired = 0x01 BadCertRevoked = 0x02 BadCertCNMismatch = 0x04 BadCertNotTrusted = 0x08 BadCertFuture = 0x200 )
X.509 verification flags, the subset worth distinguishing. mbedTLS reports every verification problem as one coarse status code, so this bitmask is the only way to tell an expired certificate from a name mismatch.
const Supported = false
Supported reports whether this build has the mbedTLS backend compiled in.
Variables ¶
This section is empty.
Functions ¶
Types ¶
type Class ¶
type Class int
Class is the coarse failure category reported by the C layer. The caller maps it, together with VerifyFlags, onto the package-level sentinels.
type Error ¶
type Error struct {
Class Class
Code int // negative mbedTLS status, zero when not applicable
VerifyFlags uint32
Err error // set only when there is no mbedTLS status to report
}
Error carries the class, the raw mbedTLS status, and the verification bitmask.
type Options ¶
type Options struct {
Host string
RootCAsPEM []byte
ClientCertPEM []byte
ClientKeyPEM []byte
SkipVerify bool
MinVersion uint16
}
Options mirrors the real type so callers compile everywhere.
type PrivateKey ¶
type PrivateKey struct{}
PrivateKey mirrors the real type so callers compile everywhere.
func ParsePrivateKey ¶
func ParsePrivateKey([]byte) (*PrivateKey, error)
ParsePrivateKey always fails in this build.
func (*PrivateKey) SignPKCS1v15SHA256 ¶
func (k *PrivateKey) SignPKCS1v15SHA256([]byte) ([]byte, error)
SignPKCS1v15SHA256 always fails in this build.