Research platform-native TLS trust configuration
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 32/100
- issue の種類
- ドキュメント
- 明瞭さ
- おおむね明確
- 活発さ
- 静か
- 技術スタック
- rust
- 領域
- cli, documentation, security
調査の方向性
src/http.rs と Cargo.toml を確認して現在のバンドルされた root の設定を確定し、その後、関連する issue #448、#438、#445 を読みます。サポート対象の target と指定された証明書ケース全体で、列挙された trust 戦略を比較します。文書化された推奨事項、根拠、実行可能な失敗時の動作、実装およびテストのフォローアップが示され、runtime のドキュメントが更新されていれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Context
The HTTP host currently builds its TLS connector with with_webpki_roots() in src/http.rs, while Cargo.toml enables the webpki-tokio feature. This embeds the Mozilla root set in every basic-cli application and does not use trust configured by the operating system.
Bundled roots make static applications self-contained and allow public HTTPS to work in minimal environments without a system CA bundle. However, a general-purpose CLI may need to honor:
- enterprise TLS interception and private certificate authorities;
- locally trusted development certificates;
- administrator trust and distrust policy;
- operating-system certificate updates;
- standard CA bundle overrides such as
SSL_CERT_FILEandSSL_CERT_DIR.
Research questions
Investigate and document the tradeoffs between:
- a platform verifier;
- loading native roots into rustls;
- retaining only bundled WebPKI roots;
- combining or falling back between native and bundled roots;
- exposing an application-level custom CA configuration.
The investigation should cover:
- x64 and arm64 macOS, x64 Windows, and x64 and arm64 Linux musl;
- static linking, cross-compilation, binary size, and startup/runtime cost;
- minimal containers or hosts with no usable native certificate store;
- whether fallback to bundled roots could bypass an intentional OS distrust decision;
- actionable errors when roots cannot be loaded or a certificate is rejected;
- private CA, public CA, missing-store, and invalid-store test cases.
Desired outcome
Record a recommended trust policy for basic-cli and the rationale behind it. If a change is recommended, define implementation and test follow-ups that provide predictable behavior on every supported target without requiring users to disable certificate verification.
Keep the public runtime documentation updated with the chosen behavior.
Related work
- #448 documents the current bundled-root behavior.
- #438 tracks stable HTTP transport error classification, including TLS failures.
- #445 tracks dependency advisories and rebuild expectations for statically linked applications.
- 主要言語
- Rust
- スター
- 121
- フォーク
- 45
- 平均マージ
- 19時間 1分
- マージ済み PR(30日)
- 16
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
roc-lang/basic-cli のほかの issue
-
Unix socket supportオープン
難易度 3/5 1〜2日 初心者へのやさしさ 45/100
メンテナーはふだん 1 日以内に返信
-
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
メンテナーはふだん 1 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 45/100
メンテナーはふだん 1 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 52/100
メンテナーはふだん 1 日以内に返信
-
enhancement
難易度 5/5 1週間以上 初心者へのやさしさ 45/100
roc-lang/basic-cli#455 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
roc-lang/basic-cli の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
trezor/trezor-firmware#7997 ·
メンテナーはふだん 2 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
smol-machines/smolvm#1489 · コメント 1 件 · リアクション 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
メンテナーはふだん 1 日以内に返信