Repository navigation
Eliminate transitive OpenSSL dependency; unblock CI/release - #324
pizzle85-maker wants to merge 2 commits into
Conversation
teller-providers depended on both vaultrs (which already defaults to the rustls TLS backend) and rustify directly. rustify was left on its own default features, which select reqwest's native-tls backend. Since Cargo unifies features across a dependency graph, this silently pulled openssl-sys/native-tls back into the final binary even though vaultrs had already opted out of it. Pin both vaultrs and rustify to their rustls feature explicitly and disable default features, so the whole dependency tree is TLS-backend consistent. Confirmed openssl-sys no longer appears anywhere in `cargo tree`, and the resulting release binary has zero libssl runtime dependency (checked with ldd). This is the actual fix for tellerops#290 ("Deprecated OpenSSL 1.1.1 Dependency on Linux") - the released v2.0.7 binary links against libssl.so.1.1 because it happened to be built on an ubuntu-20.04 runner (system OpenSSL 1.1.1), not because any dependency requires OpenSSL 1.1.1 specifically. With this change, no OpenSSL version is linked at all. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
master's CI has been red since the last "fix build" commits in January, which is very likely why no release has shipped since v2.0.7 (2024-05-20) despite real fixes landing on master since then: - actions-rs/toolchain and actions-rs/cargo are from an org archived since November 2021; replaced with dtolnay/rust-toolchain and plain `cargo` invocations in both build.yml and release.yml. - actions/upload-artifact@v2 and actions/download-artifact@v2 stopped working entirely on 2025-01-30 (GitHub fully shut off the v1/v2 APIs) - release.yml's Dist/Publish jobs cannot currently complete even if a tag is pushed. Bumped to v4, including download-artifact's `pattern` input to preserve the per-platform directory layout the publish script expects. - release.yml's x86_64-linux Dist job pinned `ubuntu-20.04`, a runner image GitHub has since retired. Bumped to `ubuntu-22.04`. (This was also the direct cause of the OpenSSL 1.1.1 linking in the v2.0.7 release binary - ubuntu-20.04's system OpenSSL is 1.1.1 - though the previous commit's fix means the runner's OpenSSL version no longer matters either way.) - Replaced the deprecated `::set-output::` workflow command in release.yml's publish job with $GITHUB_OUTPUT. - Fixed the 3 cargo clippy errors (-D warnings with pedantic/nursery enabled) and 1 stale rustfmt formatting spot that were failing the Lints job, and one stale trycmd test snapshot (delete.trycmd) that no longer matched current error-message formatting, failing the Test Suite job. Verified locally: `cargo fmt --all -- --check`, `cargo clippy --all-features -- -D warnings -W clippy::pedantic -W clippy::nursery -W rust-2018-idioms`, and `cargo test --all-features --all` (for teller/teller-core/teller-providers) all pass cleanly. The one remaining test failure is providers::etcd::tests::sanity_test, which is unrelated to this change: Bitnami removed the `bitnami/etcd` image from Docker Hub entirely in their 2025 catalog restructuring (zero tags now exist for bitnami/etcd), so that integration test needs a different image - a separate, maintainer judgment call left out of scope here. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
@jondot — flagging this directly since I know GitHub notifications are easy to miss. This closes out #290 (OpenSSL 1.1.1 dependency, open since June 2024) and, maybe more usefully, fixes the exact CI breakage you were fighting on Jan 27 (the "fix build?" commits) — Also worth knowing regardless of what happens with this PR: Everything's built, tested, and verified locally (details in the PR description) — happy to split into smaller PRs, adjust anything, or just answer questions if that helps it move. |
What
Closes #290 (Deprecated OpenSSL 1.1.1 Dependency on Linux) and gets CI/release infrastructure back into a working state, which appears to be why no release has shipped since v2.0.7 (2024-05-20) despite real fixes landing on
mastersince then.Commit 1 — the actual OpenSSL fix
teller-providersdepends on bothvaultrs(which already defaults to therustlsTLS backend) andrustifydirectly.rustifywas left on its own default features, which selectreqwest'snative-tlsbackend. Because Cargo unifies features across the whole dependency graph, this silently pulledopenssl-sys/native-tlsback into the final binary even thoughvaultrshad already opted out of it.Pinning both
vaultrsandrustifyto theirrustls/rustls-tlsfeatures (and disabling default features) removesopenssl-sysfrom the dependency tree entirely — confirmed withcargo tree --invert openssl-sys(zero matches) andlddon the resulting release binary (nolibssldependency at all, vs. today'sv2.0.7binary which requires the long-EOLlibssl.so.1.1).This also explains why the released binary links 1.1.1 specifically: the
x86_64-linuxDist job runs onubuntu-20.04, whose system OpenSSL is 1.1.1 —native-tlsjust links whatever the build host has. It was never an intentional pin to 1.1.1.Commit 2 — unblock CI so a release can actually be cut
actions-rs/toolchain/actions-rs/cargoare from an org archived since November 2021 — replaced withdtolnay/rust-toolchain+ plaincargoinvocations. This is almost certainly the real cause of the "fix build?" commits in January not sticking —master's CI has been red since then.actions/upload-artifact@v2/actions/download-artifact@v2stopped working entirely on 2025-01-30 (GitHub fully shut off the v1/v2 APIs). Bumped to v4 inrelease.yml— without this, the Dist/Publish jobs cannot complete even if a tag is pushed today.release.yml'sx86_64-linuxDist job was pinned toubuntu-20.04, a runner image GitHub has since retired. Bumped toubuntu-22.04.::set-output::workflow command with$GITHUB_OUTPUT.cargo clippyerrors and 1 stalerustfmtspot that were failing the Lints job, plus one staletrycmdtest snapshot (delete.trycmd) that no longer matched current error-message formatting.Verification
Built and tested locally end-to-end (Rust 1.98, protoc installed):
cargo build --release --locked -p teller— succeeds;ldd target/release/tellershows nolibssl*dependency.cargo fmt --all -- --check— clean.cargo clippy --all-features -- -D warnings -W clippy::pedantic -W clippy::nursery -W rust-2018-idioms— clean.cargo test --all-features --all(teller / teller-core / teller-providers) — all green, exceptproviders::etcd::tests::sanity_test, which is unrelated to this PR: Bitnami removed thebitnami/etcdimage from Docker Hub entirely in their 2025 catalog restructuring (bitnami/etcdnow has zero tags on Docker Hub at all — confirmed via the registry API). That test needs a different container image; left out of scope here since it's a separate maintainer judgment call, not a build/OpenSSL issue.Happy to split this into two PRs (fix vs. CI) if that's easier to review, or to open a separate issue for the etcd/Bitnami test breakage if useful.
🤖 Generated with Claude Code