From e235ff1892a1aea2e08fa3f97af06fd05e2a8d80 Mon Sep 17 00:00:00 2001 From: yuhan6665 <1588741+yuhan6665@users.noreply.github.com> Date: Thu, 10 Sep 2026 23:09:13 -0400 Subject: [PATCH] crypto/tls: document that ConnectionState is valid only after handshake Conn.ConnectionState reports details that are only populated once the TLS handshake has completed. Callers that read it immediately after Accept (for example via tls.NewListener) instead observe an unpopulated ConnectionState whose HandshakeComplete field is false. Document this precondition on Conn.ConnectionState and point to ConnectionState.HandshakeComplete and Conn.Handshake, which the first Conn.Read or Conn.Write runs automatically. Fixes #79828. Change-Id: Iad8a446ae45c7eb45efba6f8c1ce50fa727db989 GitHub-Last-Rev: a9ea872 GitHub-Pull-Request: #80081 Reviewed-on: https://go-review.googlesource.com/c/go/+/792720 Reviewed-by: Roland Shoemaker LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com Auto-Submit: Filippo Valsorda Reviewed-by: Filippo Valsorda Reviewed-by: Dmitri Shuralyov --- conn.go | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/conn.go b/conn.go index 7bfac68..d75b48d 100644 --- a/conn.go +++ b/conn.go @@ -1672,6 +1672,12 @@ func (c *Conn) handshakeContext(ctx context.Context) (ret error) { } // ConnectionState returns basic TLS details about the connection. +// +// The returned [ConnectionState] is only meaningful after the handshake has +// completed, as reported by [ConnectionState.HandshakeComplete]; before then +// its fields are not populated. The handshake is run automatically by the +// first [Conn.Read] or [Conn.Write], or it can be triggered explicitly with +// [Conn.Handshake]. func (c *Conn) ConnectionState() ConnectionState { c.handshakeMutex.Lock() defer c.handshakeMutex.Unlock()