[Bug]: Antigravity turns fail on NixOS: embedded Python can't verify TLS (empty CA store) -> 502
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 78/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- typescript
- Lĩnh vực
- backend
Hướng nghiên cứu
Bắt đầu tại apps/server, nơi runtime ACP của Antigravity được khởi tạo — tìm phần chuẩn bị env đã được thực hiện ở đó (ANTIGRAVITY_HARNESS_PATH, GEMINI_HOME, extendEnv: false). Đọc vị trí spawn đó để xem cách các biến môi trường theo từng process được dựng, rồi thêm SSL_CERT_FILE (hoặc SSL_CERT_DIR) chỉ khi người dùng chưa đặt chúng và một trong các bundle Linux được liệt kê tồn tại. Kết quả mong đợi: các prompt chạy thành công sau proxy với đường dẫn CA nhúng trống, và các biến CA do người dùng cung cấp vẫn thắng; xác minh bằng repro NixOS hoặc bằng cách assert env được dựng trong các test sẵn có quanh spawn của ACP.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Before submitting
- I searched existing issues and did not find a duplicate.
- I included enough detail to reproduce or investigate the problem.
Area
apps/server
Steps to reproduce
- On NixOS (any distro without the CA paths the bundled Python expects), install T3 Code and set up Google Antigravity (
oauth-personal) with the managed ACP runtime (1.3.0). - Start a thread with any Gemini model and send any prompt.
- The turn never produces output:
session/promptstays open until cancelled, or the turn ends with the raw text below.
Expected behavior
The agent establishes TLS to the CCPA API using the system trust store (or an env-provided CA bundle) and answers normally.
Actual behavior
Every TLS handshake from the embedded Python fails:
E1007 00:57:44.712115 proxy_server.py:222] Proxy failed to connect to CCPA API:
Network connection failed to CCPA API: [SSL: CERTIFICATE_VERIFY_FAILED]
CERTIFICATE_VERIFY_FAILED: unable to get local issuer certificate (_ssl.c:1104)
...
File ".../acp_server/ccpa_connection/ccpa_client.py", line 173, in stream_generate_content
res = urllib.request.urlopen(req, timeout=_DEFAULT_TIMEOUT_SECONDS)
(from agy_acp_server.par.*.log.ERROR; ccpa_client.stream_generate_content
uses urllib with the default SSL context). The local proxy converts that into
502 Failed to connect to backend API, so the user-visible symptom is identical
to #16010 — but the disease is different: the agent can never open TLS at all
here, not a transient upstream reset. curl, the agy CLI, and system Python
reach Google's APIs fine from the same machine; only agy_acp_server.par fails,
because its baked-in CA default paths don't exist on NixOS and its trust store
ends up effectively empty.
Impact
Blocks work completely
Version or commit
v0.0.46-nightly.20261006.2752
Environment
Linux x86_64 (NixOS 25.05), T3 Code Desktop, Provider: Google Antigravity (ACP) 1.3.0, oauth-personal. Models tried: gemini-3.8-flash-low, gemini-3.8-flash-medium (identical failure).
Logs or stack traces
Full traceback (proxy_server.py:222 → ccpa_client.py:196 → urllib →
ssl.SSLCertVerificationError) available in the agent glog quoted above.
No tokens or credentials involved — the failure happens before any auth header
is sent.
Suggested fix
T3 already curates the agent environment (GEMINI_HOME, per-process TMPDIR,
ANTIGRAVITY_HARNESS_PATH, AGY_ACP_FORCE_FILE_STORAGE, extendEnv: false).
On Linux, set SSL_CERT_FILE (or SSL_CERT_DIR) from the first existing
well-known system bundle when spawning the Antigravity runtime:
/etc/ssl/certs/ca-bundle.crt/etc/ssl/certs/ca-certificates.crt/etc/pki/tls/certs/ca-bundle.crt
Verified locally: launching the same binary with SSL_CERT_FILE pointed at the
system bundle (which the embedded CPython honors) makes prompts succeed
immediately — same account, model, and machine. Only apply when the user hasn't
set SSL_CERT_FILE/SSL_CERT_DIR themselves, so custom CAs and TLS-inspecting
proxies keep working (cf. #16703).
Workaround
Point the Antigravity instance's Binary path at a wrapper that exports
SSL_CERT_FILE before exec'ing the managed agy_acp_server.par.
Relationship to #16010
Same user-visible symptom (502 / model unreachable), different root cause:
#16010 is transient upstream resets killing an already-running turn; this is
the agent never being able to open TLS on distros without the expected CA
paths. Linking for visibility; happy to split or merge as maintainers prefer.
Related TLS-trust handling: #16703 (different subsystem — T3's own GitHub sync).
- Ngôn ngữ chính
- TypeScript
- Star
- 24.8k
- Fork
- 6.4k
- Merge trung bình
- 8 giờ 34 phút
- Pull request đã merge (30 ngày)
- 243
Chuẩn bị môi trường
Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của pingdotgg/t3code
-
[Bug]: Dead-key apostrophe inserts extra quotes in the composerCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mởbug via-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
pingdotgg/t3code#16859 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug via-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
pingdotgg/t3code#16822 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug via-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
pingdotgg/t3code#16821 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug via-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 66/100
pingdotgg/t3code#16810 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug via-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
pingdotgg/t3code#16737 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của pingdotgg/t3code
Issue tương tự
-
ble-needs-fable-review bug mobile priority:P2
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
ColeMurray/background-agents#2305 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug from-studio
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 63/100
esengine/DeepSeek-Reasonix#12355 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
oblien/openship#1086 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày