aboutsummaryrefslogtreecommitdiffhomepage
path: root/crates/shirabe-external-packages/src/composer/ca_bundle/ca_bundle.rs
blob: 3c372cb15f2fb74d4ef067aa3e1d34d4be2bd3f0 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
//! ref: composer/vendor/composer/ca-bundle/src/CaBundle.php

#[derive(Debug)]
pub struct CaBundle;

impl CaBundle {
    // TODO(plugin): unused for now; kept for API parity.
    // TODO(phase-c): The original inspects the linked OpenSSL version to decide
    // whether openssl_x509_parse can be called safely. Certificate handling is
    // slated to move to reqwest, so this dummy always reports safe.
    pub fn is_openssl_parse_safe() -> bool {
        true
    }

    // The original `$logger` parameter (PSR LoggerInterface) is replaced by a
    // `()` placeholder: CaBundle is expected to be subsumed by a Rust TLS
    // library and removed, so it does not need a real logger.
    //
    // TODO(phase-c): Dummy stand-in until HTTP handling moves to reqwest, which
    // discovers the system CA bundle itself. This probes the SSL_CERT_FILE /
    // SSL_CERT_DIR environment variables and the common distribution CA
    // locations, returning the first that exists. Unlike the original it does
    // not consult OpenSSL's default cert locations, does not validate the
    // candidate before returning it, and has no bundled cacert.pem fallback.
    pub fn get_system_ca_root_bundle_path(_logger: ()) -> String {
        if let Ok(file) = std::env::var("SSL_CERT_FILE")
            && std::path::Path::new(&file).is_file()
        {
            return file;
        }

        const CA_FILE_PATHS: &[&str] = &[
            "/etc/pki/tls/certs/ca-bundle.crt",
            "/etc/ssl/certs/ca-certificates.crt",
            "/etc/ssl/ca-bundle.pem",
            "/usr/local/share/certs/ca-root-nss.crt",
            "/usr/ssl/certs/ca-bundle.crt",
            "/opt/local/share/curl/curl-ca-bundle.crt",
            "/usr/local/share/curl/curl-ca-bundle.crt",
            "/usr/share/ssl/certs/ca-bundle.crt",
            "/etc/ssl/cert.pem",
            "/usr/local/etc/ssl/cert.pem",
            "/usr/local/etc/openssl/cert.pem",
            "/usr/local/etc/openssl@1.1/cert.pem",
        ];
        for path in CA_FILE_PATHS {
            if std::path::Path::new(path).is_file() {
                return path.to_string();
            }
        }

        if let Ok(dir) = std::env::var("SSL_CERT_DIR")
            && std::path::Path::new(&dir).is_dir()
        {
            return dir;
        }

        const CA_DIR_PATHS: &[&str] = &["/etc/pki/tls/certs", "/etc/ssl/certs"];
        for path in CA_DIR_PATHS {
            if std::path::Path::new(path).is_dir() {
                return path.to_string();
            }
        }

        String::new()
    }

    // TODO(phase-c): Dummy stand-in until reqwest validates certificates itself.
    // The original parses the file with OpenSSL and rejects malformed or expired
    // bundles; here we only require the file to exist and be non-empty.
    pub fn validate_ca_file(ca_file: &str, _logger: ()) -> bool {
        std::fs::read(ca_file)
            .map(|c| !c.is_empty())
            .unwrap_or(false)
    }
}