libs/tls
Cryptography Suite & TLS 1.3 Handshake
Systems-level cryptographic operations and secure transport protocol written directly in Kale. Provides state-of-the-art cipher suites, ECDH key exchange over Curve25519, and full TLS 1.3 connection negotiation.

High-Throughput Systems Foundation
Engineered to maximize CPU instruction pipelining and data cache locality. Every algorithm avoids heap pointer indirection wherever contiguous stack or arena buffers can be employed.

import "libs/tls/client.kl" as tls;
import "libs/net/socket.kl" as sock;
fn main() -> int32 {
let raw_sock: sock.Socket = sock.connect("api.github.com", 443);
let session: tls.TLSSession = tls.handshake(&raw_sock, "api.github.com");
tls.write(&session, "GET / HTTP/1.1\r\nHost: api.github.com\r\n\r\n");
let response: string = tls.read_all(&session);
tls.close(&session);
return 0;
}Deterministic command-line invocations to build, link native dynamic dependencies, and run automated regression tests:
kale build tests/test_tls.kl -o bin/test_tls.exe./bin/test_tls.exeGPG Key 1B917D4779A6102E • Continuous integration with automated symbol verification.
Engineered to prevent side-channel and timing attacks during arithmetic and authentication checks.
1-RTT handshake protocol handling ServerHello, encrypted extensions, certificate verification, and finished tokens.
Secure memory scrubbing for secret keys, pre-shared keys, and master session secrets.