fix(tls): select ring explicitly across application entry points

Building easytier and easytier-web together enabled both ring and aws-lc
through reqwest 0.13. HTTPS endpoint discovery used rustls automatic
provider selection and could panic before sending a ClientHello.

Use reqwest rustls-no-provider to share ring, and explicitly install the
process default before starting CLI, GUI and web services. Initialize it
for standalone webhook construction too, retaining any provider already
selected by the host.

Pass ring directly to HTTPS discovery and WebSocket TLS builders so
library use is independent of application initialization order. Keep
existing certificate verification, SNI and protocol settings.

Add a duplex-stream regression that reproduces the original panic with
both backends enabled, and run it in CI. Explain provider selection and
feature-unification constraints next to the relevant code.

Validation: the new regression fails before the fix and passes after it.
Docker tests pass: 10 discovery, 13 webhook, 2 WebSocket, WSS three-node
AES-GCM relay, and WSS credential connectivity. Clippy with warnings
denied and fmt pass. GUI, browser, WASI, minimal native, endpoint-only
and WebSocket-only compile checks pass. Linux and Windows release
dependency trees contain only the ring runtime backend.

Fixes #2607
This commit is contained in:
KKRainbow committed 2026-10-08 23:14:40 +08:00
1 parent fd9e4ed418
commit 6154b550c1
10 files changed
+98 -19

No files matched your search

+7
View File
@@ -125,6 +125,13 @@ jobs:
- uses: taiki-e/install-action@nextest
- name: Test HTTPS discovery with both rustls backends
# Catch provider-selection panics even when release features use only ring.
run: >-
cargo test --locked --package easytier-core --lib
--features rustls/aws_lc_rs
https_fetch_reaches_tls_handshake_without_global_provider
- name: Archive test
run: >-
cargo nextest archive --archive-file tests.tar.zst