HORIZON HASKELLDocslts/ghc-9.10.x248f8f02026-10-05Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · 248f8f0 · 2026-10-05

Moduletls-2.1.6Haskell2010

Network.TLS.QUIC

API to run the TLS handshake establishing a QUIC connection.

On the northbound API:

TLS invokes QUIC callbacks to use the QUIC transport

  • TLS uses quicSend and quicRecv to send and receive handshake message fragments.

  • TLS calls quicInstallKeys to provide to QUIC the traffic secrets it should use for encryption/decryption.

  • TLS calls quicNotifyExtensions to notify to QUIC the transport parameters exchanged through the handshake protocol.

  • TLS calls quicDone when the handshake is done.

  • 16 types
  • 12 values
  • Packagetls-2.1.6
  • Exports29
  • LanguageHaskell2010
  • LicenceBSD-3-Clause
  • SourceQUIC.hs

Handshakers

2 declarations

Start a TLS handshake thread for a QUIC client. The client will use the specified TLS parameters and call the provided callback functions to send and receive handshake data.

Start a TLS handshake thread for a QUIC server. The server will use the specified TLS parameters and call the provided callback functions to send and receive handshake data.

Callback

3 declarations
datadata QUICCallbacks
#

Callbacks implemented by QUIC and to be called by TLS at specific points during the handshake. TLS may invoke them from external threads but calls are not concurrent. Only a single callback function is called at a given point in time.

Constructors

  • QUICCallbacks
    • quicSend :: [(CryptLevel, ByteString)] -> IO ()

      Called by TLS so that QUIC sends one or more handshake fragments. The content transiting on this API is the plaintext of the fragments and QUIC responsability is to encrypt this payload with the key material given for the specified level and an appropriate encryption scheme.

      The size of the fragments may exceed QUIC datagram limits so QUIC may break them into smaller fragments.

      The handshake protocol sometimes combines content at two levels in a single flight. The TLS library does its best to provide this in the same quicSend call and with a multi-valued argument. QUIC can then decide how to transmit this optimally.

    • quicRecv :: CryptLevel -> IO (Either TLSError ByteString)

      Called by TLS to receive from QUIC the next plaintext handshake fragment. The argument specifies with which encryption level the fragment should be decrypted.

      QUIC may return partial fragments to TLS. TLS will then call quicRecv again as long as necessary. Note however that fragments must be returned in the correct sequence, i.e. the order the TLS peer emitted them.

      The function may return an error to TLS if end of stream is reached or if a protocol error has been received, believing the handshake cannot proceed any longer. If the TLS handshake protocol cannot recover from this error, the failure condition will be reported back to QUIC through the control interface.

    • quicInstallKeys :: Context -> KeyScheduleEvent -> IO ()

      Called by TLS when new encryption material is ready to be used in the handshake. The next quicSend or quicRecv may now use the associated encryption level (although the previous level is also possible: directions Send/Recv do not change at the same time).

    • quicNotifyExtensions :: Context -> [ExtensionRaw] -> IO ()

      Called by TLS when QUIC-specific extensions have been received from the peer.

    • quicDone :: Context -> IO ()

      Called when handshake is done. tlsQUICServer is finished after calling this hook. tlsQUICClient calls recvData after calling this hook to wait for new session tickets.

Secrets

9 declarations
datadata EarlySecret
#

Phantom type indicating early traffic secret.

Instances2HasCryptLevel, LogLabel
newtypenewtype ServerTrafficSecret a
#

A server traffic secret, typed with a parameter indicating a step in the TLS key schedule.

Instances4Show, LogLabel, TrafficSecret
newtypenewtype ClientTrafficSecret a
#

A client traffic secret, typed with a parameter indicating a step in the TLS key schedule.

Instances5Show, LogLabel, TrafficSecret

Negotiated parameters

2 declarations

Extensions

3 declarations

Errors

5 declarations
valueerrorTLS :: String -> IO a
#

Can be used by callbacks to signal an unexpected condition. This will then generate an "internal_error" alert in the TLS stack.

Hash

3 declarations

Constants

1 declaration

Supported

1 declaration