NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #3509 most downloaded on crates.io
wrap incoming Stream of connections in TLS
Last release 10 months ago
22 Nov 2025
Release timing varies
gaps range from 3 weeks to 10 months
Most releases are documented
notes for 18 of 23 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
23 releases · first in 2019
Add cfg cond for unix on UnixListener
feat: Add listener() method by @tmccombs in #55
.listener() in the axum example by @SabrinaJewson in #56Full Changelog: v0.11.0...v0.11.1
One column per quarter.
Add listener() method
Accept_generator fn
Add AsyncListener trait
Axum support
Breaking change : Minimum supported version of tokio-rustls is 0.26
Full Changelog: v0.10.3...v0.11.0
Update thiserror requirement from 1.0.30 to 2.0.3 by @dependabot in #48
Full Changelog: v0.10.2...v0.10.3-1
Stop automatically pulling in aws-lc as a dependency by @OverShifted in #46
Full Changelog: v0.10.1...v0.10.2
Allow using tokio-rustls 0.26 by @tmccombs in #45
Versions prior to this using the default configuration are vulnerable to a Slowloris attack.
Versions prior to this using the default configuration are vulnerable to a Slowloris attack.
This version mitigates the vulnerability.
Previous versions can mitigate the vulnerability by increasing the value passed to Builder::max_handshakes to a large
number (such as usize::MAX). Decreasing the handshake_timeout can also help, although it is still strongly recommended
to increase the max_handshakes more than the current default.
poll_accept not to have a limit on the number of pending handshakes in the queue,Builder::max_handshakes with Builder::accept_batch_size.### Miscellaneous Tasks - Update tokio-rustls
BREAKING CHANGE: remove until from AsyncAccept trait. Use StreamExt.take_until on the TlsListener instead.
until from AsyncAccept trait. Use
StreamExt.take_until on the TlsListener instead.accept fn on AsyncAccept trait no longer returns an
Optionaccept fn on TlsListener no longer returns an OptionThis is a backwards incompatible release. The main change is that accepting a new connection now returns a tuple of the new connection, and the peer a…
This is a backwards incompatible release. The main change is that accepting a new connection now returns a tuple of the new connection, and the peer
address. The AsyncAccept trait was also changed similarly. The Error enum was also changed to provide more details about the error. And if
the handshake times out, it now returns an error instead of silently waiting for the next connection.
[breaking] Add a new error type for handshake timeouts
[breaking] Yield remote address upon accepting a connection, and include it in errors.
Error::ListenerError is now struct-like instead of tuple-like, and is non_exhaustive like the enum itself.Error now has three type parameters, not two.TlsListener::accept and <TlsListener as Stream>::next yields a tuple of (connection, remote address), not just the connection.AsyncAccept now has an associated type Address, which poll_accept must now return along with the accepted connection.[breaking] More changes for including peer address in response
Increase tokio-rustls version to 0.24.0
Increased default handshake timeout to 10 seconds (technically a breaking change)
Fixed compilation on non-unix environments, where tokio-net doesn't include unix sockets
opensslSpawningHandshakes will abort the tasks for pending connections when the linked futures are dropped. This should allow timeouts to cause the connectionto be closed.Backwards incompatible: AsyncAccept::poll_accept now returns, Poll >> instead of Poll >. This allows the incoming stream of connections to stop, for e…
AsyncAccept::until] method, that creates a new AsyncAccept that will stop accepting connections after another future finishes.hyper submodule to add additional support for hyper. Specifically, a newtype for the hyper Accept trait for AsyncAccept.SpawningHandshakes struct behind the rt feature flag. This allows you to perform multiple handshakes in parallel with a multi-threaded runtime.AsyncAccept::poll_accept now returns, Poll<Option<Result<...>>> instead of Poll<Result<...>>. This allows the incoming stream of connections to stop, for example, if a graceful shutdown has been initiated. impls provided by this crate have been updated, but custom implementations of AsyncAccept, or direct usage of the trait may break.Added TlsListener::replace_accept_pin() function to allow replacing the listener certificate at runtime, when the listener is pinned.
TlsListener::replace_accept_pin() function to allow replacing the listener certificate at runtime, when the listener is pinned.Added TlsListener::replace_acceptor() function to allow replacing the listener certificate at runtime.
TlsListener::replace_acceptor() function to allow replacing the listener certificate at runtime.This in turn allows TlsListener to be Send when using the native-tls feature. Technically, this is a breaking change. However, in practice it is unlik…
AsyncTls for tokio_native_tls::TlsAcceptor now requires the connection type to implement Send. This in turn allows TlsListener to be Send when using the native-tls feature. Technically, this is a breaking change. However, in practice it is unlikely to break existing code and makes using TlsListener much easier to use when native-tls is enabled.NOTE: This release contains several breaking changes.
NOTE: This release contains several breaking changes.
native-tls.AsyncTls trait.
rustls or native-tls features to get support for a tls backend.TlsListener.TlsListener stream now returns a tls_listener::Error instead of std::io::Error type.TcpListener::new() and builder() have changed to now take an argument of the TLS type rather than a rustls::ServerConfig,
to update existing calls, replace builder(config) with builder(Arc::new(config).into()).tokio/time and hyper/tcp
features.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →