Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

[Bug]: Antigravity turns fail on NixOS: embedded Python can't verify TLS (empty CA store) -> 502

Đang mở Phù hợp với người mới
#16,742 1 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
78/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
typescript
Lĩnh vực
backend

Hướng nghiên cứu

Bắt đầu tại apps/server, nơi runtime ACP của Antigravity được khởi tạo — tìm phần chuẩn bị env đã được thực hiện ở đó (ANTIGRAVITY_HARNESS_PATH, GEMINI_HOME, extendEnv: false). Đọc vị trí spawn đó để xem cách các biến môi trường theo từng process được dựng, rồi thêm SSL_CERT_FILE (hoặc SSL_CERT_DIR) chỉ khi người dùng chưa đặt chúng và một trong các bundle Linux được liệt kê tồn tại. Kết quả mong đợi: các prompt chạy thành công sau proxy với đường dẫn CA nhúng trống, và các biến CA do người dùng cung cấp vẫn thắng; xác minh bằng repro NixOS hoặc bằng cách assert env được dựng trong các test sẵn có quanh spawn của ACP.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

bug via-triage
Before submitting
  • I searched existing issues and did not find a duplicate.
  • I included enough detail to reproduce or investigate the problem.
Area

apps/server

Steps to reproduce
  1. On NixOS (any distro without the CA paths the bundled Python expects), install T3 Code and set up Google Antigravity (oauth-personal) with the managed ACP runtime (1.3.0).
  2. Start a thread with any Gemini model and send any prompt.
  3. The turn never produces output: session/prompt stays open until cancelled, or the turn ends with the raw text below.
Expected behavior

The agent establishes TLS to the CCPA API using the system trust store (or an env-provided CA bundle) and answers normally.

Actual behavior

Every TLS handshake from the embedded Python fails:

E1007 00:57:44.712115 proxy_server.py:222] Proxy failed to connect to CCPA API:
Network connection failed to CCPA API: [SSL: CERTIFICATE_VERIFY_FAILED]
CERTIFICATE_VERIFY_FAILED: unable to get local issuer certificate (_ssl.c:1104)
...
File ".../acp_server/ccpa_connection/ccpa_client.py", line 173, in stream_generate_content
    res = urllib.request.urlopen(req, timeout=_DEFAULT_TIMEOUT_SECONDS)

(from agy_acp_server.par.*.log.ERROR; ccpa_client.stream_generate_content
uses urllib with the default SSL context). The local proxy converts that into
502 Failed to connect to backend API, so the user-visible symptom is identical
to #16010 — but the disease is different: the agent can never open TLS at all
here, not a transient upstream reset. curl, the agy CLI, and system Python
reach Google's APIs fine from the same machine; only agy_acp_server.par fails,
because its baked-in CA default paths don't exist on NixOS and its trust store
ends up effectively empty.

Impact

Blocks work completely

Version or commit

v0.0.46-nightly.20261006.2752

Environment

Linux x86_64 (NixOS 25.05), T3 Code Desktop, Provider: Google Antigravity (ACP) 1.3.0, oauth-personal. Models tried: gemini-3.8-flash-low, gemini-3.8-flash-medium (identical failure).

Logs or stack traces

Full traceback (proxy_server.py:222 → ccpa_client.py:196 → urllib →
ssl.SSLCertVerificationError) available in the agent glog quoted above.
No tokens or credentials involved — the failure happens before any auth header
is sent.

Suggested fix

T3 already curates the agent environment (GEMINI_HOME, per-process TMPDIR,
ANTIGRAVITY_HARNESS_PATH, AGY_ACP_FORCE_FILE_STORAGE, extendEnv: false).
On Linux, set SSL_CERT_FILE (or SSL_CERT_DIR) from the first existing
well-known system bundle when spawning the Antigravity runtime:

  • /etc/ssl/certs/ca-bundle.crt
  • /etc/ssl/certs/ca-certificates.crt
  • /etc/pki/tls/certs/ca-bundle.crt

Verified locally: launching the same binary with SSL_CERT_FILE pointed at the
system bundle (which the embedded CPython honors) makes prompts succeed
immediately — same account, model, and machine. Only apply when the user hasn't
set SSL_CERT_FILE/SSL_CERT_DIR themselves, so custom CAs and TLS-inspecting
proxies keep working (cf. #16703).

Workaround

Point the Antigravity instance's Binary path at a wrapper that exports
SSL_CERT_FILE before exec'ing the managed agy_acp_server.par.

Relationship to #16010

Same user-visible symptom (502 / model unreachable), different root cause:
#16010 is transient upstream resets killing an already-running turn; this is
the agent never being able to open TLS on distros without the expected CA
paths. Linking for visibility; happy to split or merge as maintainers prefer.

Related TLS-trust handling: #16703 (different subsystem — T3's own GitHub sync).

Ngôn ngữ chính
TypeScript
Star
24.8k
Fork
6.4k
Merge trung bình
8 giờ 34 phút
Pull request đã merge (30 ngày)
243

Chuẩn bị môi trường

Mở trong Codespaces

Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của pingdotgg/t3code

Tất cả issue của pingdotgg/t3code

Issue tương tự

Thêm issue về TypeScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.