1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
// Copyright (c) Microsoft Corporation.
// Licensed under the MIT License.
//! Direct Schannel TLS implementation (Windows-only).
//!
//! This module is the in-tree replacement for the Windows path of the
//! `native-tls` / `schannel` crate stack. It exists because the upstream
//! `schannel` crate's `validate()` unconditionally calls
//! `CertGetCertificateChain` + `CertVerifyCertificateChainPolicy`, even when
//! the caller would like to skip chain validation entirely (the case ODBC
//! satisfies for `TrustServerCertificate=Yes`). On cold-CAPI2 machines that
//! chain build can stall ~15s, which manifested as Adam Machanic's bulkcopy
//! timeout regression — see
//! `.github/prompts/plan-decoupleTlsBackendSchannelOdbcParity.prompt.md`.
//!
//! Layering:
//! ```text
//! AsyncRead/AsyncWrite (stream)
//! │
//! ▼
//! sync Schannel handshake + records (handshake + record_layer)
//! │
//! ▼
//! raw SSPI FFI + cred cache (sspi + cred)
//! ```
//!
//! The whole stack — FFI plumbing, credential cache, handshake, record
//! layer, async wrapper, validation, and the engine impl — lands together
//! and is wired into [`super::super::tls::default_engine`] as the default
//! Windows TLS engine.
pub
pub
pub
pub
pub
pub
pub
pub
pub
pub