mbedtls

package
v1.3.3 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 29, 2026 License: Apache-2.0, Apache-2.0, GPL-2.0 Imports: 2 Imported by: 0

Documentation

Overview

Package mbedtls wraps a vendored mbedTLS for the TinyGo Linux HTTPS backend.

TinyGo cannot link the OS OpenSSL at all: it emits no PT_INTERP, so dynamic relocations are never applied, and a static link needs roughly forty shim symbols whose set depends on how the distribution built OpenSSL. Compiling mbedTLS from source with TinyGo's own cgo sidesteps both problems, because the result is built against TinyGo's own musl and links statically.

The vendored sources and the transformations applied to them are described in PATCHES.md and reproduced by vendor.py.

This package is only built for TinyGo on Linux, or for host Go with the force_tinygo_logic tag. Everywhere else Supported reports false and the package contains no C.

Index

Constants

View Source
const (
	BadCertExpired    = 0x01
	BadCertRevoked    = 0x02
	BadCertCNMismatch = 0x04
	BadCertNotTrusted = 0x08
	BadCertFuture     = 0x200
)

X.509 verification flags, the subset worth distinguishing. mbedTLS reports every verification problem as one coarse status code, so this bitmask is the only way to tell an expired certificate from a name mismatch.

View Source
const Supported = false

Supported reports whether this build has the mbedTLS backend compiled in.

Variables

This section is empty.

Functions

func HWCaps

func HWCaps() int

HWCaps reports that the concept does not apply in this build.

func Handshake

func Handshake(fd int, opt Options, timeoutNanos int64) (*Session, *Error)

Handshake always fails in this build.

func SelfTest

func SelfTest() error

SelfTest reports that there is nothing to test in this build.

Types

type Class

type Class int

Class is the coarse failure category reported by the C layer. The caller maps it, together with VerifyFlags, onto the package-level sentinels.

const (
	ClassOK Class = iota
	ClassAlloc
	ClassSetup
	ClassCA
	ClassClientCert
	ClassHandshake
	ClassTimeout
	ClassIO
	ClassClosed
)

func (Class) String

func (c Class) String() string

type Error

type Error struct {
	Class       Class
	Code        int // negative mbedTLS status, zero when not applicable
	VerifyFlags uint32
	Err         error // set only when there is no mbedTLS status to report
}

Error carries the class, the raw mbedTLS status, and the verification bitmask.

func (*Error) Error

func (e *Error) Error() string

func (*Error) Timeout

func (e *Error) Timeout() bool

Timeout reports whether this was a deadline expiry.

type Options

type Options struct {
	Host          string
	RootCAsPEM    []byte
	ClientCertPEM []byte
	ClientKeyPEM  []byte
	SkipVerify    bool
	MinVersion    uint16
}

Options mirrors the real type so callers compile everywhere.

type PrivateKey

type PrivateKey struct{}

PrivateKey mirrors the real type so callers compile everywhere.

func ParsePrivateKey

func ParsePrivateKey([]byte) (*PrivateKey, error)

ParsePrivateKey always fails in this build.

func (*PrivateKey) Bits

func (k *PrivateKey) Bits() int

Bits always reports zero in this build.

func (*PrivateKey) Close

func (k *PrivateKey) Close() error

Close is a no-op in this build.

func (*PrivateKey) SignPKCS1v15SHA256

func (k *PrivateKey) SignPKCS1v15SHA256([]byte) ([]byte, error)

SignPKCS1v15SHA256 always fails in this build.

type Session

type Session struct{}

Session is a placeholder on platforms without the backend.

func (*Session) Close

func (s *Session) Close()

func (*Session) Read

func (s *Session) Read(p []byte, timeoutNanos int64) (int, *Error)

func (*Session) Write

func (s *Session) Write(p []byte, timeoutNanos int64) (int, *Error)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL