NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #1731 most downloaded on crates.io
A pure Rust implementation of the TLS (de)serialization
Last release 2 months ago
13 Jul 2026
Release timing varies
gaps range from 3 weeks to 1.4 years
Some releases are documented
notes for 4 of 10 stable releases
2 versions withdrawn
withdrawn after publishing
5 years old
27 releases · first in 2021
One column per quarter.
tls_codec: update version to 0.5.0
tls_codec: update version to 0.5.0 (#2381)
SerializeBytes::tls_serialize to SerializeBytes::tls_serialize_bytes to resolve a method-name collision with Serialize::tls_serialize (this matches the existing DeserializeBytes::tls_deserialize_bytes convention). Any type using #[tls_codec(with = "...")] together with TlsSerializeBytes must rename its module's tls_serialize function to tls_serialize_bytes accordingly.Size, SerializeBytes, and DeserializeBytes for String (and Size/SerializeBytes for str / &str), encoding the UTF-8 bytes as a VLByteVec. Also implement SerializeBytes for ContentLength and VLByteSlice.VLByteVec and SecretVLByteVec, which are #[serde(transparent)] wrappers serializing via serde_bytes. They produce a much more compact representation in serde formats that distinguish byte arrays from sequences of u8 (e.g. CBOR, MessagePack, bincode). Their serde output is not compatible with VLBytes / SecretVLBytes, but their Deserialize impls are backwards-compatible: in self-describing serde formats they also accept the legacy VLBytes / SecretVLBytes encoding (a struct with a vec field containing a sequence of u8). VLBytes and SecretVLBytes will be deprecated in future in favour of VLByteVec and SecretVLByteVec.TlsVarInt type for variable-length integers.zeroize 1.8 → 1.9, serde 1.0.184 → 1.0.228, serde_bytes 0.11.17 → 0.11.19.write_all everywhere instead of write to prevent partial writes from going undetected. The Error::InvalidWriteLength variant is deprecated as it is no longer returned.Vec<T>, TlsVecU*<T>, SecretTlsVecU*<T>), for both the Deserialize (std::io::Read) and DeserializeBytes implementations, now measures actual byte consumption instead of relying on tls_serialized_len() and enforces the declared length exactly. This makes the two implementations agree for non-canonical inner encodings (e.g. non-minimal varint lengths) and rejects input whose elements overshoot the declared vector boundary.
DeserializeBytes for TlsByteVecU* now uses checked_add when computing the content range, returning Error::InvalidVectorLength instead of overflowing usize on targets where the length field is as wide as the pointer width. (The VLBytes / VLByteVec deserialization paths were unaffected: the byte-slice path slices via get(..length) and the Read path bounds allocation via isize::MAX, so neither computes an overflowing sum.)TlsByteVecU*, VLBytes, VLByteVec) no longer eagerly allocates a buffer sized by the untrusted length field, avoiding large allocations from bogus length prefixes. The serde Deserialize for VLByteVec / SecretVLByteVec likewise caps the initial allocation derived from an untrusted size_hint.isize::MAX (returning Error::InvalidVectorLength) instead of panicking in Vec::with_capacity; reachable on 32-bit targets.Deserializable* / Undeserializable* type aliases generated by #[conditionally_deserializable].tls_codec_derive-generated Size impls) can now return Error::InvalidVectorLength where the length sum previously wrapped usize and produced a truncated, mismatched length prefix on the wire.Add future_deprecations and don't deprecate VLBytes
fix some bugs on large inputs primarily for 32-bit systems
- #1628 Bump MSRV to 1.74
Nothing published for this version
- #1284: implement U24. A U24 integer type can be used for length encoding in three bytes. - #1159: Read and write all available data in VLBytes. Befo
U24. A U24 integer type can be used for length encoding in three bytes.VLBytes. Before this change the read or write may have failed when it couldn't be read/written all at once.#[tls_codec(cd_field)] macro. It can be used alongside the #[conditionally_deserializable] macro to mark fields that are also conditionally deserializable and that internally need to have the const generic added.Nothing published for this version
### Changed - #1251: Add _bytes suffix to function names in the DeserializeBytes trait to avoid collisions with function names in the Deserialize trai
_bytes suffix to function names in the DeserializeBytes trait to avoid collisions with function names in the Deserialize traitno_std support for the derive crate. This requires the std feature to be enabled when using derive with Serialize and Deserialize.tls_deserialize_bytes function from the Deserialize traitNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →