github / github/copilot-sdk

Rust SDK hard-codes native-tls (OpenSSL); offer a rustls TLS backend so musl/static builds work

Aperta
#1,805 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
enhancement
Lingua principale
Java
Stelle
10.5k
Fork
1.5k
Merge medio
1g 11h
PR unite (30g)
127

Descrizione

### Summary

The Rust crate (`rust/Cargo.toml`) hard-codes the OpenSSL-backed `native-tls` stack for its HTTP and WebSocket clients, with no way to opt into rustls:

```toml
reqwest = { version = "0.12", default-features = false, features = ["stream", "http2", "default-tls"] }
tokio-tungstenite = { version = "0.24", default-features = false, features = ["connect", "native-tls"] }
```

`default-tls` (reqwest) and `native-tls` (tokio-tungstenite) both pull in `openssl-sys`, which links the system OpenSSL on Linux. These deps were introduced with the HTTP request callback support in #1689.

### Impact

- **musl / fully-static targets fail to build.** Cross-compiling to `*-unknown-linux-musl` fails in the `openssl-sys` build script with `Could not find openssl via pkg-config` / `Could not find directory of OpenSSL installation`, because there is no OpenSSL sysroot for the musl target. Consumers that ship static binaries (Alpine, distroless, hardened CI) cannot build the Rust SDK without vendoring OpenSSL.
- **glibc binaries gain a dynamic libssl runtime dependency.** Even where the build succeeds, the resulting binary now dynamically links `libssl.so.3` / `libcrypto.so.3`, narrowing portability for consumers that previously shipped self-contained rustls binaries.

### Request

Make the TLS backend rustls-based, or feature-gate it so consumers can choose. Two shapes:

1. **Default to rustls** — reqwest `rustls-tls` (or `rustls-tls-native-roots`) and tokio-tungstenite `rustls-tls-native-roots`. The `ring` / `aws-lc-rs` backends cross-compile to musl with no system OpenSSL, keeping the SDK OpenSSL-free out of the box.
2. **Expose cargo features** (e.g. `native-tls` vs `rustls-tls`) so downstreams pick a backend, while keeping native-tls available for those who want it.

Option 1 keeps the SDK cross-compilable by default; option 2 preserves choice. Happy to open a PR once you confirm the preferred shape.

### Repro

With `musl-tools` installed:

```
cargo build -p --target x86_64-unknown-linux-musl
```

fails in the `openssl-sys` build script.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Start by inspecting rust/Cargo.toml and running the stated cargo build for x86_64-unknown-linux-musl. Trace the reqwest and tokio-tungstenite TLS features, then confirm the chosen default or feature-gated backend builds without requiring system OpenSSL while preserving the requested client functionality.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
rust
Ambito
build-system, networking, security
Tipo di issue
Funzionalità
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Tranquilla
Chiarezza
Abbastanza chiara
Idoneità per principianti
52/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.