Research platform-native TLS trust configuration
維護者通常 1 天內回覆
還沒有人認領這個 Issue。
評估
- 難度
- 5/5
- 預估耗時
- 一週以上
- 新手友好度
- 32/100
- Issue 類型
- 文件
- 描述清晰度
- 基本清楚
- 活躍度
- 冷清
- 技術堆疊
- rust
- 領域
- cli, documentation, security
研究方向
檢視 src/http.rs 和 Cargo.toml,以確認目前的內建根設定,然後閱讀相關 issue #448、#438 和 #445。比較所列信任策略在支援的 target 及指定憑證案例中的情況。完成的標準是:有一份記錄在案的建議、理由、可執行的失敗行為,以及實作和測試的後續事項,並且已更新 runtime 文件。
由索引模型根據 Issue 內容生成。
描述
Context
The HTTP host currently builds its TLS connector with with_webpki_roots() in src/http.rs, while Cargo.toml enables the webpki-tokio feature. This embeds the Mozilla root set in every basic-cli application and does not use trust configured by the operating system.
Bundled roots make static applications self-contained and allow public HTTPS to work in minimal environments without a system CA bundle. However, a general-purpose CLI may need to honor:
- enterprise TLS interception and private certificate authorities;
- locally trusted development certificates;
- administrator trust and distrust policy;
- operating-system certificate updates;
- standard CA bundle overrides such as
SSL_CERT_FILEandSSL_CERT_DIR.
Research questions
Investigate and document the tradeoffs between:
- a platform verifier;
- loading native roots into rustls;
- retaining only bundled WebPKI roots;
- combining or falling back between native and bundled roots;
- exposing an application-level custom CA configuration.
The investigation should cover:
- x64 and arm64 macOS, x64 Windows, and x64 and arm64 Linux musl;
- static linking, cross-compilation, binary size, and startup/runtime cost;
- minimal containers or hosts with no usable native certificate store;
- whether fallback to bundled roots could bypass an intentional OS distrust decision;
- actionable errors when roots cannot be loaded or a certificate is rejected;
- private CA, public CA, missing-store, and invalid-store test cases.
Desired outcome
Record a recommended trust policy for basic-cli and the rationale behind it. If a change is recommended, define implementation and test follow-ups that provide predictable behavior on every supported target without requiring users to disable certificate verification.
Keep the public runtime documentation updated with the chosen behavior.
Related work
- #448 documents the current bundled-root behavior.
- #438 tracks stable HTTP transport error classification, including TLS failures.
- #445 tracks dependency advisories and rebuild expectations for statically linked applications.
- 主要語言
- Rust
- 星號
- 121
- 分支
- 45
- 平均合併
- 19 小時 1 分鐘
- 30 天內合併 PR
- 16
環境準備
- 沒有 Dockerfile 或 Docker Compose 檔案
- 沒有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
roc-lang/basic-cli 的其他 Issue
-
難度 3/5 1-2 天 新手友好度 45/100
維護者通常 1 天內回覆
-
難度 5/5 一週以上 新手友好度 25/100
維護者通常 1 天內回覆
-
難度 4/5 3-5 天 新手友好度 45/100
維護者通常 1 天內回覆
-
難度 3/5 1-2 天 新手友好度 52/100
維護者通常 1 天內回覆
-
enhancement
難度 5/5 一週以上 新手友好度 45/100
roc-lang/basic-cli#455 · 1 則留言 ·
維護者通常 1 天內回覆
查看 roc-lang/basic-cli 的全部 Issue
相似的 Issue
-
bug
難度 2/5 1-3 小時 新手友好度 78/100
stellar/stellar-cli#2773 ·
維護者通常 2 天內回覆
-
bug
難度 2/5 1-3 小時 新手友好度 85/100
voidzero-dev/oxc-angular-compiler#511 ·
維護者通常 1 天內回覆
-
難度 1/5 1-3 小時 新手友好度 86/100
yantrikos/yantrik-os#539 ·
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 82/100
維護者通常 1 天內回覆
-
documentation station:mac ui-dashboard
難度 2/5 1-3 小時 新手友好度 86/100
rolter-ai/rolter#2490 · 1 則留言 ·
維護者通常 1 天內回覆