aboutsummaryrefslogtreecommitdiffhomepage
path: root/crates/shirabe-external-packages
diff options
context:
space:
mode:
authornsfisis <nsfisis@gmail.com>2026-06-20 22:33:31 +0900
committernsfisis <nsfisis@gmail.com>2026-06-20 22:33:31 +0900
commit10840ec1fd7f1140305449fc94175d60998572c1 (patch)
treeae1121e7a7bd3ede0bb5416b15324cffc9351d76 /crates/shirabe-external-packages
parent8538a375a4ddcfad3fabc8d19ca41c148136b63b (diff)
downloadphp-shirabe-10840ec1fd7f1140305449fc94175d60998572c1.tar.gz
php-shirabe-10840ec1fd7f1140305449fc94175d60998572c1.tar.zst
php-shirabe-10840ec1fd7f1140305449fc94175d60998572c1.zip
feat(ca-bundle): replace CaBundle todo!() with dummy implementations
CaBundle is slated for removal once HTTP handling moves to reqwest, which discovers the system CA bundle itself. Until then, fill the three methods with reasonable stand-ins: get_system_ca_root_bundle_path probes the SSL_CERT_FILE/SSL_CERT_DIR env vars and common distro CA locations, validate_ca_file requires a non-empty readable file, and is_openssl_parse_safe reports safe. The simplifications versus the original are noted with TODO(phase-c). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Diffstat (limited to 'crates/shirabe-external-packages')
-rw-r--r--crates/shirabe-external-packages/src/composer/ca_bundle/ca_bundle.rs63
1 files changed, 59 insertions, 4 deletions
diff --git a/crates/shirabe-external-packages/src/composer/ca_bundle/ca_bundle.rs b/crates/shirabe-external-packages/src/composer/ca_bundle/ca_bundle.rs
index 8bd9bb5..187950a 100644
--- a/crates/shirabe-external-packages/src/composer/ca_bundle/ca_bundle.rs
+++ b/crates/shirabe-external-packages/src/composer/ca_bundle/ca_bundle.rs
@@ -4,18 +4,73 @@
pub struct CaBundle;
impl CaBundle {
+ // TODO(plugin): unused for now; kept for API parity.
+ // TODO(phase-c): The original inspects the linked OpenSSL version to decide
+ // whether openssl_x509_parse can be called safely. Certificate handling is
+ // slated to move to reqwest, so this dummy always reports safe.
pub fn is_openssl_parse_safe() -> bool {
- todo!()
+ true
}
// The original `$logger` parameter (PSR LoggerInterface) is replaced by a
// `()` placeholder: CaBundle is expected to be subsumed by a Rust TLS
// library and removed, so it does not need a real logger.
+ //
+ // TODO(phase-c): Dummy stand-in until HTTP handling moves to reqwest, which
+ // discovers the system CA bundle itself. This probes the SSL_CERT_FILE /
+ // SSL_CERT_DIR environment variables and the common distribution CA
+ // locations, returning the first that exists. Unlike the original it does
+ // not consult OpenSSL's default cert locations, does not validate the
+ // candidate before returning it, and has no bundled cacert.pem fallback.
pub fn get_system_ca_root_bundle_path(_logger: ()) -> String {
- todo!()
+ if let Ok(file) = std::env::var("SSL_CERT_FILE") {
+ if std::path::Path::new(&file).is_file() {
+ return file;
+ }
+ }
+
+ const CA_FILE_PATHS: &[&str] = &[
+ "/etc/pki/tls/certs/ca-bundle.crt",
+ "/etc/ssl/certs/ca-certificates.crt",
+ "/etc/ssl/ca-bundle.pem",
+ "/usr/local/share/certs/ca-root-nss.crt",
+ "/usr/ssl/certs/ca-bundle.crt",
+ "/opt/local/share/curl/curl-ca-bundle.crt",
+ "/usr/local/share/curl/curl-ca-bundle.crt",
+ "/usr/share/ssl/certs/ca-bundle.crt",
+ "/etc/ssl/cert.pem",
+ "/usr/local/etc/ssl/cert.pem",
+ "/usr/local/etc/openssl/cert.pem",
+ "/usr/local/etc/openssl@1.1/cert.pem",
+ ];
+ for path in CA_FILE_PATHS {
+ if std::path::Path::new(path).is_file() {
+ return path.to_string();
+ }
+ }
+
+ if let Ok(dir) = std::env::var("SSL_CERT_DIR") {
+ if std::path::Path::new(&dir).is_dir() {
+ return dir;
+ }
+ }
+
+ const CA_DIR_PATHS: &[&str] = &["/etc/pki/tls/certs", "/etc/ssl/certs"];
+ for path in CA_DIR_PATHS {
+ if std::path::Path::new(path).is_dir() {
+ return path.to_string();
+ }
+ }
+
+ String::new()
}
- pub fn validate_ca_file(_ca_file: &str, _logger: ()) -> bool {
- todo!()
+ // TODO(phase-c): Dummy stand-in until reqwest validates certificates itself.
+ // The original parses the file with OpenSSL and rejects malformed or expired
+ // bundles; here we only require the file to exist and be non-empty.
+ pub fn validate_ca_file(ca_file: &str, _logger: ()) -> bool {
+ std::fs::read(ca_file)
+ .map(|c| !c.is_empty())
+ .unwrap_or(false)
}
}