Skip to content

Expose the active reactor and support native StreamWriter.start_tls() - #108

Merged
egorsmkv merged 1 commit into
masterfrom
fix/runtime-reactor-writer-start-tls
Oct 10, 2026
Merged

egorsmkv merged 1 commit into
masterfrom
fix/runtime-reactor-writer-start-tls

Conversation

@egorsmkv

Copy link
Copy Markdown
Contributor

Refs #106, specifically the author's additional observations about reactor diagnostics and the missing native StreamWriter.start_tls(). Read cancellation is handled separately in #107.

The build-time reactor label cannot identify automatic io_uring fallback. Native stream writers also lacked the stream-level TLS upgrade API, and the existing low-level upgrade did not transfer accepted-connection accounting, leaving server.wait_closed() waiting after an upgrade.

This PR:

  • Adds loop.runtime_info()["reactor"], sourced from that loop's constructed driver, including fallback to mio/epoll. It is None before first run and after close, remains available while stopped, and does not initialize/probe a runtime. build_info() retains its compile-time meaning for compatibility.
  • Implements await writer.start_tls(), including drain, client/server inference, hostname and handshake/shutdown timeout forwarding, and replacement of writer/reader/protocol transports.
  • Prevents a second server callback during transport replacement. Handler errors/cancellation close the current TLS transport.
  • Transfers server connection accounting across the plaintext/TLS handoff, releasing it on failure or final closure.
  • Finishes stream waiters after failed/cancelled upgrades and disposes of late handshake results without reviving a cancelled connection.
  • Adds API documentation, typing coverage, runtime lifecycle tests, real STARTTLS comparisons, and deterministic late-completion tests.

Validation performed locally on Linux, CPython 3.14.7, Rust nightly-2026-09-25, and uvloop 0.23.0:

  • The new runtime API test and native STARTTLS round-trip test both fail against base f16e637 with AttributeError, reproducing both missing APIs.
  • Targeted runtime/STARTTLS tests: 15 passed, 14 deselected. Encrypted bidirectional traffic and EOF pass with asyncio, rsloop and uvloop, with both client-first and server-first handshake ordering. Native tests cover handler failure/cancellation, handshake failure, cancellation cleanup, late results and server shutdown.
  • Full default Python selection: 284 passed, 2 failed, 3 skipped, 98 deselected. Both failures are AF_UNIX PermissionError (EPERM), also reproduced on the base checkout.
  • Rust default: 320 passed, 15 failed. Rust --all-features: 416 passed, 19 failed. Failures encounter EPERM creating io_uring drivers or Unix sockets in this environment; these are not green full-suite runs.
  • cargo clippy --all-targets --all-features -- -D warnings, cargo fmt --check, Ruff on changed Python files, focused Pyright and git diff --check passed.
  • Observed runtime diagnostics: build_info()["reactor"] == "io_uring", but runtime_info()["reactor"] == "mio" while running/stopped, and None before initialization/after close.

Actual io_uring execution, macOS, Windows, other Python versions and free-threaded builds were not run locally. Differential tests skip stdlib STARTTLS on Python 3.10 and only pass ssl_shutdown_timeout where that reference API supports it. No new performance claim is made for this API addition.

@egorsmkv
egorsmkv merged commit 439d288 into master Oct 10, 2026
27 of 39 checks passed
@egorsmkv
egorsmkv deleted the fix/runtime-reactor-writer-start-tls branch October 10, 2026 08:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant