Rust SDK hard-codes native-tls (OpenSSL); offer a rustls TLS backend so musl/static builds work
- Ngôn ngữ chính
- Java
- Star
- 10.5k
- Fork
- 1.5k
- Merge trung bình
- 1 ngày 11 giờ
- Pull request đã merge (30 ngày)
- 128
Mô tả
### Summary
The Rust crate (`rust/Cargo.toml`) hard-codes the OpenSSL-backed `native-tls` stack for its HTTP and WebSocket clients, with no way to opt into rustls:
```toml
reqwest = { version = "0.12", default-features = false, features = ["stream", "http2", "default-tls"] }
tokio-tungstenite = { version = "0.24", default-features = false, features = ["connect", "native-tls"] }
```
`default-tls` (reqwest) and `native-tls` (tokio-tungstenite) both pull in `openssl-sys`, which links the system OpenSSL on Linux. These deps were introduced with the HTTP request callback support in #1689.
### Impact
- **musl / fully-static targets fail to build.** Cross-compiling to `*-unknown-linux-musl` fails in the `openssl-sys` build script with `Could not find openssl via pkg-config` / `Could not find directory of OpenSSL installation`, because there is no OpenSSL sysroot for the musl target. Consumers that ship static binaries (Alpine, distroless, hardened CI) cannot build the Rust SDK without vendoring OpenSSL.
- **glibc binaries gain a dynamic libssl runtime dependency.** Even where the build succeeds, the resulting binary now dynamically links `libssl.so.3` / `libcrypto.so.3`, narrowing portability for consumers that previously shipped self-contained rustls binaries.
### Request
Make the TLS backend rustls-based, or feature-gate it so consumers can choose. Two shapes:
1. **Default to rustls** — reqwest `rustls-tls` (or `rustls-tls-native-roots`) and tokio-tungstenite `rustls-tls-native-roots`. The `ring` / `aws-lc-rs` backends cross-compile to musl with no system OpenSSL, keeping the SDK OpenSSL-free out of the box.
2. **Expose cargo features** (e.g. `native-tls` vs `rustls-tls`) so downstreams pick a backend, while keeping native-tls available for those who want it.
Option 1 keeps the SDK cross-compilable by default; option 2 preserves choice. Happy to open a PR once you confirm the preferred shape.
### Repro
With `musl-tools` installed:
```
cargo build -p --target x86_64-unknown-linux-musl
```
fails in the `openssl-sys` build script.
Hướng dẫn đóng góp
Hướng nghiên cứu
Bắt đầu bằng cách kiểm tra rust/Cargo.toml và chạy cargo build đã nêu cho x86_64-unknown-linux-musl. Theo dõi các TLS features của reqwest và tokio-tungstenite, sau đó xác nhận rằng backend mặc định hoặc được bật bằng feature đã chọn có thể build mà không yêu cầu OpenSSL của hệ thống, đồng thời vẫn giữ nguyên chức năng client được yêu cầu.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- rust
- Lĩnh vực
- build-system, networking, security
- Loại issue
- Tính năng
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức độ hoạt động
- Ít trao đổi
- Độ rõ ràng
- Khá rõ ràng
- Mức phù hợp với người mới
- 52/100