Add in-place TLS socket upgrade - #7514
Open
tim-smart wants to merge 8 commits into
Open
Conversation
🦋 Changeset detectedLatest commit: 64cc46b The changes in this PR will be included in the next version bump. This PR includes changesets to release 30 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
Contributor
Bundle Size AnalysisGenerated from PR build output; treat the content below as untrusted.
|
fubhy
requested changes
Aug 28, 2026
IMax153
reviewed
Aug 28, 2026
tim-smart
commented
Aug 29, 2026
tim-smart
commented
Aug 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds in-place TLS wrapping to the
Readeracquired fromsocket.reader. Each reader exposes{ pull, upgrade }, keeping the upgrade operation in the same scoped connection region as its pull.Socket.makenow accepts that complete reader acquisition directly; transports that cannot wrap useSocketUpgradeError.unsupported.The Node adapter keeps the current pull and writer while replacing the live duplex after the handshake. Inbound server sockets use the server TLS role;
makeNetand rawfromDuplexsockets use the client role. Handshake failures retain the original cause.readerBytesandreaderStringkeep their pull-only return contract while adapting the new reader internally. Channel and stream adapters, WebSocket and TransformStream adapters, Node/Deno/Bun consumers, OpenAI realtime, RPC, tests, benchmarks, and socket type tests are updated for the new reader shape.Checks run:
nix develop -c pnpm vitest run packages/effect/test/unstable/socket/Socket.test.ts packages/platform/node/test/NodeSocket.test.tsnix develop -c pnpm tstyche --target '>=5.9' packages/effect/typetest/unstable/socket/Socket.tst.tsnix develop -c pnpm checkCloses EFF-965