1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
|
//! ref: composer/vendor/composer/ca-bundle/src/CaBundle.php
#[derive(Debug)]
pub struct CaBundle;
impl CaBundle {
// TODO(plugin): unused for now; kept for API parity.
// TODO(phase-c): The original inspects the linked OpenSSL version to decide
// whether openssl_x509_parse can be called safely. Certificate handling is
// slated to move to reqwest, so this dummy always reports safe.
pub fn is_openssl_parse_safe() -> bool {
true
}
// The original `$logger` parameter (PSR LoggerInterface) is replaced by a
// `()` placeholder: CaBundle is expected to be subsumed by a Rust TLS
// library and removed, so it does not need a real logger.
//
// TODO(phase-c): Dummy stand-in until HTTP handling moves to reqwest, which
// discovers the system CA bundle itself. This probes the SSL_CERT_FILE /
// SSL_CERT_DIR environment variables and the common distribution CA
// locations, returning the first that exists. Unlike the original it does
// not consult OpenSSL's default cert locations, does not validate the
// candidate before returning it, and has no bundled cacert.pem fallback.
pub fn get_system_ca_root_bundle_path(_logger: ()) -> String {
if let Ok(file) = std::env::var("SSL_CERT_FILE")
&& std::path::Path::new(&file).is_file()
{
return file;
}
const CA_FILE_PATHS: &[&str] = &[
"/etc/pki/tls/certs/ca-bundle.crt",
"/etc/ssl/certs/ca-certificates.crt",
"/etc/ssl/ca-bundle.pem",
"/usr/local/share/certs/ca-root-nss.crt",
"/usr/ssl/certs/ca-bundle.crt",
"/opt/local/share/curl/curl-ca-bundle.crt",
"/usr/local/share/curl/curl-ca-bundle.crt",
"/usr/share/ssl/certs/ca-bundle.crt",
"/etc/ssl/cert.pem",
"/usr/local/etc/ssl/cert.pem",
"/usr/local/etc/openssl/cert.pem",
"/usr/local/etc/openssl@1.1/cert.pem",
];
for path in CA_FILE_PATHS {
if std::path::Path::new(path).is_file() {
return path.to_string();
}
}
if let Ok(dir) = std::env::var("SSL_CERT_DIR")
&& std::path::Path::new(&dir).is_dir()
{
return dir;
}
const CA_DIR_PATHS: &[&str] = &["/etc/pki/tls/certs", "/etc/ssl/certs"];
for path in CA_DIR_PATHS {
if std::path::Path::new(path).is_dir() {
return path.to_string();
}
}
String::new()
}
// TODO(phase-c): Dummy stand-in until reqwest validates certificates itself.
// The original parses the file with OpenSSL and rejects malformed or expired
// bundles; here we only require the file to exist and be non-empty.
pub fn validate_ca_file(ca_file: &str, _logger: ()) -> bool {
std::fs::read(ca_file)
.map(|c| !c.is_empty())
.unwrap_or(false)
}
}
|