镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

tls: add tlsSocket.socket, to access the raw stream beneath TLS - #66598

Open
pimterry wants to merge 1 commit into
nodejs:mainfrom
pimterry:tls-parent-socket
Open

pimterry wants to merge 1 commit into
nodejs:mainfrom
pimterry:tls-parent-socket

Conversation

@pimterry

@pimterry pimterry commented Oct 8, 2026

Copy link
Copy Markdown
Member

If you created a TLS socket on top of an existing socket or duplex stream (new tls.TLSSocket(socket), tls.connect({ socket }), tlsServer.emit('connection', socket)) it's not possible to get the underlying socket back from the TLS socket through any public APIs.

Currently the only route to do this is the private _parent and _handle._parentWrap references, both of which are used in the ecosystem (including by my code) to workaround this issue. It would be nice if that wasn't necessary.

This PR adds a .socket property to TLS sockets, matching httpReq.socket and http2Session.socket. In reality in all 3 cases this might not actually be an actual socket - all 3 can run over any duplex - but the consistency is nice (it matches the option naming too) and it's clear enough imo.

There is notably one common case where this is still null: TLS client connections, made directly like tls.connect{ host, port }) (not using an existing socket). In this case there's no underlying net.Socket or stream object created, so there's nothing to expose. I think that's OK: the TLSSocket itself here is the raw socket, so there's no parent to reach and null is correct. It's noted in the docs here.

End result: when layering protocols on top of each other (e.g. H2 over TLS over H1 CONNECT), with this change you can just loop up the .socket references and you'll always (I think) eventually reach the real socket instance.

Signed-off-by: Tim Perry <pimterry@gmail.com>
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/crypto
  • @nodejs/net

@nodejs-github-bot nodejs-github-bot added needs-ci PRs that need a full CI run. tls Issues and PRs related to the tls subsystem. labels Oct 8, 2026
@codecov

codecov Bot commented Oct 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 90.44%. Comparing base (6d5e309) to head (20f2a00).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main   #66598      +/-   ##
==========================================
- Coverage   90.44%   90.44%   -0.01%     
==========================================
  Files         791      791              
  Lines      276562   276565       +3     
  Branches    53126    53119       -7     
==========================================
- Hits       250130   250127       -3     
+ Misses      16846    16844       -2     
- Partials     9586     9594       +8     
Files with missing lines Coverage Δ
lib/internal/tls/wrap.js 95.62% <100.00%> (+<0.01%) ⬆️

... and 28 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-ci PRs that need a full CI run. tls Issues and PRs related to the tls subsystem.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants