Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -247,3 +247,5 @@
- Share exact owned source buffers on matching `node:vm` compilation-cache entries while preserving cold misses, cached-data validation, per-script origins and the existing byte budget.

- Name package-target resolution options explicitly to satisfy the Rust Mordant lint without changing resolution behavior.

- Destroy Duplex-backed TLS transports without calling `end()`, preserve wrapped-socket close ordering, and honor half-open shutdown like Node.js. Ports HTTP/2 teardown from [oven-sh/bun#38195](https://github.com/oven-sh/bun/pull/38195) and adapts coverage from [oven-sh/bun#38154](https://github.com/oven-sh/bun/pull/38154); thanks @robobun!
6 changes: 6 additions & 0 deletions docs/runtime/nodejs-compat.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -266,6 +266,12 @@ Native `fetch()` uses `tls.setDefaultCACertificates()` overrides for new TLS con

TLS starts reading paused Duplex and HTTP CONNECT transports after installing its listeners, including handshake bytes buffered before adoption.

Destroying a TLS socket destroys its underlying Duplex transport without calling `end()`, matching Node.js. Graceful TLS shutdown still ends the transport after sending its TLS shutdown data.

A TLS socket over a Duplex inherits the transport's `allowHalfOpen` setting. A peer TLS shutdown ends the readable side. With `allowHalfOpen: true`, the writable side remains available until the application calls `end()`.

Destroying an HTTP/2 session releases its TLS transport without waiting for the peer to end its writable side. The session emits its final events after the transport closes.

🟡 Missing `pskCallback`, OCSP stapling (`requestOCSP`), the server `'newSession'`/`'resumeSession'` events and session ticket keys (`ticketKeys` is ignored). As a result, session resumption does not work across processes. Bun uses BoringSSL, so `tlsSocket.renegotiate()` always fails and `getEphemeralKeyInfo()`/`getSharedSigalgs()` return no information.

### [`node:util`](https://nodejs.org/api/util.html)
Expand Down
1 change: 1 addition & 0 deletions src/http/ProxyTunnel.rs
Original file line number Diff line number Diff line change
Expand Up @@ -605,6 +605,7 @@ impl ProxyTunnel {
on_data,
on_handshake,
on_close,
on_end: None,
write: write_encrypted,
// fetch's proxy tunnel surfaces no 'session'/'keylog' events;
// opting out keeps its SSL off the parked queues entirely.
Expand Down
1 change: 1 addition & 0 deletions src/http_jsc/websocket_client/WebSocketProxyTunnel.rs
Original file line number Diff line number Diff line change
Expand Up @@ -183,6 +183,7 @@ impl WebSocketProxyTunnel {
on_data: Self::on_data,
on_handshake: Self::on_handshake,
on_close: Self::on_close,
on_end: None,
write: Self::write_encrypted,
// No JS TLSSocket fronts the tunnel; opting out keeps the
// SSL off the parked session/keylog queues entirely.
Expand Down
Loading
Loading