Skip to content

Eliminate transitive OpenSSL dependency; unblock CI/release - #324

Open
pizzle85-maker wants to merge 2 commits into
tellerops:masterfrom
pizzle85-maker:fix/eliminate-openssl-dependency
Open

pizzle85-maker wants to merge 2 commits into
tellerops:masterfrom
pizzle85-maker:fix/eliminate-openssl-dependency

Conversation

@pizzle85-maker

Copy link
Copy Markdown

What

Closes #290 (Deprecated OpenSSL 1.1.1 Dependency on Linux) and gets CI/release infrastructure back into a working state, which appears to be why no release has shipped since v2.0.7 (2024-05-20) despite real fixes landing on master since then.

Commit 1 — the actual OpenSSL fix

teller-providers depends on both vaultrs (which already defaults to the rustls TLS backend) and rustify directly. rustify was left on its own default features, which select reqwest's native-tls backend. Because Cargo unifies features across the whole dependency graph, this silently pulled openssl-sys/native-tls back into the final binary even though vaultrs had already opted out of it.

Pinning both vaultrs and rustify to their rustls/rustls-tls features (and disabling default features) removes openssl-sys from the dependency tree entirely — confirmed with cargo tree --invert openssl-sys (zero matches) and ldd on the resulting release binary (no libssl dependency at all, vs. today's v2.0.7 binary which requires the long-EOL libssl.so.1.1).

This also explains why the released binary links 1.1.1 specifically: the x86_64-linux Dist job runs on ubuntu-20.04, whose system OpenSSL is 1.1.1 — native-tls just links whatever the build host has. It was never an intentional pin to 1.1.1.

Commit 2 — unblock CI so a release can actually be cut

  • actions-rs/toolchain/actions-rs/cargo are from an org archived since November 2021 — replaced with dtolnay/rust-toolchain + plain cargo invocations. This is almost certainly the real cause of the "fix build?" commits in January not sticking — master's CI has been red since then.
  • actions/upload-artifact@v2 / actions/download-artifact@v2 stopped working entirely on 2025-01-30 (GitHub fully shut off the v1/v2 APIs). Bumped to v4 in release.yml — without this, the Dist/Publish jobs cannot complete even if a tag is pushed today.
  • release.yml's x86_64-linux Dist job was pinned to ubuntu-20.04, a runner image GitHub has since retired. Bumped to ubuntu-22.04.
  • Replaced the deprecated ::set-output:: workflow command with $GITHUB_OUTPUT.
  • Fixed the 3 cargo clippy errors and 1 stale rustfmt spot that were failing the Lints job, plus one stale trycmd test snapshot (delete.trycmd) that no longer matched current error-message formatting.

Verification

Built and tested locally end-to-end (Rust 1.98, protoc installed):

  • cargo build --release --locked -p teller — succeeds; ldd target/release/teller shows no libssl* dependency.
  • cargo fmt --all -- --check — clean.
  • cargo clippy --all-features -- -D warnings -W clippy::pedantic -W clippy::nursery -W rust-2018-idioms — clean.
  • cargo test --all-features --all (teller / teller-core / teller-providers) — all green, except providers::etcd::tests::sanity_test, which is unrelated to this PR: Bitnami removed the bitnami/etcd image from Docker Hub entirely in their 2025 catalog restructuring (bitnami/etcd now has zero tags on Docker Hub at all — confirmed via the registry API). That test needs a different container image; left out of scope here since it's a separate maintainer judgment call, not a build/OpenSSL issue.

Happy to split this into two PRs (fix vs. CI) if that's easier to review, or to open a separate issue for the etcd/Bitnami test breakage if useful.

🤖 Generated with Claude Code

pizzle85-maker and others added 2 commits September 22, 2026 10:30
teller-providers depended on both vaultrs (which already defaults to
the rustls TLS backend) and rustify directly. rustify was left on its
own default features, which select reqwest's native-tls backend. Since
Cargo unifies features across a dependency graph, this silently pulled
openssl-sys/native-tls back into the final binary even though vaultrs
had already opted out of it.

Pin both vaultrs and rustify to their rustls feature explicitly and
disable default features, so the whole dependency tree is TLS-backend
consistent. Confirmed openssl-sys no longer appears anywhere in
`cargo tree`, and the resulting release binary has zero libssl runtime
dependency (checked with ldd).

This is the actual fix for tellerops#290 ("Deprecated OpenSSL 1.1.1 Dependency
on Linux") - the released v2.0.7 binary links against libssl.so.1.1
because it happened to be built on an ubuntu-20.04 runner (system
OpenSSL 1.1.1), not because any dependency requires OpenSSL 1.1.1
specifically. With this change, no OpenSSL version is linked at all.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
master's CI has been red since the last "fix build" commits in
January, which is very likely why no release has shipped since v2.0.7
(2024-05-20) despite real fixes landing on master since then:

- actions-rs/toolchain and actions-rs/cargo are from an org archived
  since November 2021; replaced with dtolnay/rust-toolchain and plain
  `cargo` invocations in both build.yml and release.yml.
- actions/upload-artifact@v2 and actions/download-artifact@v2 stopped
  working entirely on 2025-01-30 (GitHub fully shut off the v1/v2
  APIs) - release.yml's Dist/Publish jobs cannot currently complete
  even if a tag is pushed. Bumped to v4, including download-artifact's
  `pattern` input to preserve the per-platform directory layout the
  publish script expects.
- release.yml's x86_64-linux Dist job pinned `ubuntu-20.04`, a runner
  image GitHub has since retired. Bumped to `ubuntu-22.04`. (This was
  also the direct cause of the OpenSSL 1.1.1 linking in the v2.0.7
  release binary - ubuntu-20.04's system OpenSSL is 1.1.1 - though the
  previous commit's fix means the runner's OpenSSL version no longer
  matters either way.)
- Replaced the deprecated `::set-output::` workflow command in
  release.yml's publish job with $GITHUB_OUTPUT.
- Fixed the 3 cargo clippy errors (-D warnings with pedantic/nursery
  enabled) and 1 stale rustfmt formatting spot that were failing the
  Lints job, and one stale trycmd test snapshot (delete.trycmd) that
  no longer matched current error-message formatting, failing the
  Test Suite job.

Verified locally: `cargo fmt --all -- --check`, `cargo clippy
--all-features -- -D warnings -W clippy::pedantic -W clippy::nursery
-W rust-2018-idioms`, and `cargo test --all-features --all` (for
teller/teller-core/teller-providers) all pass cleanly. The one
remaining test failure is providers::etcd::tests::sanity_test, which
is unrelated to this change: Bitnami removed the `bitnami/etcd` image
from Docker Hub entirely in their 2025 catalog restructuring (zero
tags now exist for bitnami/etcd), so that integration test needs a
different image - a separate, maintainer judgment call left out of
scope here.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@pizzle85-maker

Copy link
Copy Markdown
Author

@jondot — flagging this directly since I know GitHub notifications are easy to miss. This closes out #290 (OpenSSL 1.1.1 dependency, open since June 2024) and, maybe more usefully, fixes the exact CI breakage you were fighting on Jan 27 (the "fix build?" commits) — actions-rs/toolchain/actions-rs/cargo are from an org archived since 2021, and that's what's been making master's Build workflow flaky/red since then.

Also worth knowing regardless of what happens with this PR: release.yml can't currently produce a release even with a clean tag push — actions/upload-artifact@v2/download-artifact@v2 were fully shut off by GitHub on 2025-01-30 (not just deprecated, the API calls fail outright). That's independent of this PR and would block v2.0.8 either way, so I bumped those to v4 here too.

Everything's built, tested, and verified locally (details in the PR description) — happy to split into smaller PRs, adjust anything, or just answer questions if that helps it move.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Deprecated OpenSSL 1.1.1 Dependency on Linux

1 participant