From 10840ec1fd7f1140305449fc94175d60998572c1 Mon Sep 17 00:00:00 2001 From: nsfisis Date: Sat, 20 Jun 2026 22:33:31 +0900 Subject: feat(ca-bundle): replace CaBundle todo!() with dummy implementations CaBundle is slated for removal once HTTP handling moves to reqwest, which discovers the system CA bundle itself. Until then, fill the three methods with reasonable stand-ins: get_system_ca_root_bundle_path probes the SSL_CERT_FILE/SSL_CERT_DIR env vars and common distro CA locations, validate_ca_file requires a non-empty readable file, and is_openssl_parse_safe reports safe. The simplifications versus the original are noted with TODO(phase-c). Co-Authored-By: Claude Opus 4.8 (1M context) --- .../src/composer/ca_bundle/ca_bundle.rs | 63 ++++++++++++++++++++-- 1 file changed, 59 insertions(+), 4 deletions(-) (limited to 'crates') diff --git a/crates/shirabe-external-packages/src/composer/ca_bundle/ca_bundle.rs b/crates/shirabe-external-packages/src/composer/ca_bundle/ca_bundle.rs index 8bd9bb5..187950a 100644 --- a/crates/shirabe-external-packages/src/composer/ca_bundle/ca_bundle.rs +++ b/crates/shirabe-external-packages/src/composer/ca_bundle/ca_bundle.rs @@ -4,18 +4,73 @@ pub struct CaBundle; impl CaBundle { + // TODO(plugin): unused for now; kept for API parity. + // TODO(phase-c): The original inspects the linked OpenSSL version to decide + // whether openssl_x509_parse can be called safely. Certificate handling is + // slated to move to reqwest, so this dummy always reports safe. pub fn is_openssl_parse_safe() -> bool { - todo!() + true } // The original `$logger` parameter (PSR LoggerInterface) is replaced by a // `()` placeholder: CaBundle is expected to be subsumed by a Rust TLS // library and removed, so it does not need a real logger. + // + // TODO(phase-c): Dummy stand-in until HTTP handling moves to reqwest, which + // discovers the system CA bundle itself. This probes the SSL_CERT_FILE / + // SSL_CERT_DIR environment variables and the common distribution CA + // locations, returning the first that exists. Unlike the original it does + // not consult OpenSSL's default cert locations, does not validate the + // candidate before returning it, and has no bundled cacert.pem fallback. pub fn get_system_ca_root_bundle_path(_logger: ()) -> String { - todo!() + if let Ok(file) = std::env::var("SSL_CERT_FILE") { + if std::path::Path::new(&file).is_file() { + return file; + } + } + + const CA_FILE_PATHS: &[&str] = &[ + "/etc/pki/tls/certs/ca-bundle.crt", + "/etc/ssl/certs/ca-certificates.crt", + "/etc/ssl/ca-bundle.pem", + "/usr/local/share/certs/ca-root-nss.crt", + "/usr/ssl/certs/ca-bundle.crt", + "/opt/local/share/curl/curl-ca-bundle.crt", + "/usr/local/share/curl/curl-ca-bundle.crt", + "/usr/share/ssl/certs/ca-bundle.crt", + "/etc/ssl/cert.pem", + "/usr/local/etc/ssl/cert.pem", + "/usr/local/etc/openssl/cert.pem", + "/usr/local/etc/openssl@1.1/cert.pem", + ]; + for path in CA_FILE_PATHS { + if std::path::Path::new(path).is_file() { + return path.to_string(); + } + } + + if let Ok(dir) = std::env::var("SSL_CERT_DIR") { + if std::path::Path::new(&dir).is_dir() { + return dir; + } + } + + const CA_DIR_PATHS: &[&str] = &["/etc/pki/tls/certs", "/etc/ssl/certs"]; + for path in CA_DIR_PATHS { + if std::path::Path::new(path).is_dir() { + return path.to_string(); + } + } + + String::new() } - pub fn validate_ca_file(_ca_file: &str, _logger: ()) -> bool { - todo!() + // TODO(phase-c): Dummy stand-in until reqwest validates certificates itself. + // The original parses the file with OpenSSL and rejects malformed or expired + // bundles; here we only require the file to exist and be non-empty. + pub fn validate_ca_file(ca_file: &str, _logger: ()) -> bool { + std::fs::read(ca_file) + .map(|c| !c.is_empty()) + .unwrap_or(false) } } -- cgit v1.3.1