Skip to content

rust: make the request-handler TLS backend a feature (default rustls) - #2811

Open
achicu wants to merge 1 commit into
github:mainfrom
achicu:rust-rustls-default
Open

achicu wants to merge 1 commit into
github:mainfrom
achicu:rust-rustls-default

Conversation

@achicu

@achicu achicu commented Oct 5, 2026

Copy link
Copy Markdown

Summary

Fixes #1805. Supersedes the stale draft #1851, which targets reqwest 0.12 and now conflicts with main. This version also uses aws-lc-rs, which answers the review question on #1851 about standardizing on one crypto stack with the runtime.

rust/Cargo.toml hard-codes native-tls on the request-handler transport's reqwest and tokio-tungstenite dependencies. This does more than link OpenSSL. Cargo unifies features across the whole dependency graph, and reqwest 0.13's TlsBackend::default() picks NativeTls whenever __native-tls is enabled. So simply depending on github-copilot-sdk switches every reqwest::Client in the consumer's binary from rustls to OpenSSL, including clients that have nothing to do with the SDK. We hit this in a large workspace: bumping the SDK silently moved ~450 unrelated HTTP clients to OpenSSL and broke TLS against a test CA. Consumers have no way to opt out today.

Change

  • New rustls feature, on by default: reqwest/rustls (the aws-lc-rs provider, same as the runtime) and tokio-tungstenite/rustls-tls-native-roots. No system OpenSSL is needed, so musl and static targets build.
  • New opt-in native-tls feature: the previous platform-native stack.
  • The base reqwest and tokio-tungstenite dependencies no longer hard-code a TLS feature. The transport code is already backend-agnostic, so no source changes were needed.
  • The README features table documents both. Consumers using default-features = false must enable one of them if they register a request_handler that forwards to HTTPS/WSS.

The build-time CLI download ([build-dependencies] ureq/native-tls) is unchanged. It is a separate build-script graph and does not affect the consumer's runtime features.

Validation

Built inside a consumer workspace with default-features = false, features = ["runtime", "rustls"]. cargo tree -i hyper-tls no longer reaches reqwest 0.13, and the consumer crates compile.

Cargo unifies features across the dependency graph, so the hard-coded
reqwest/native-tls feature flipped reqwest's TlsBackend::default() to
native-tls for every reqwest client in a consumer's whole binary, not just
the SDK's request-handler transport. Introduce rustls (default, aws-lc-rs
via reqwest's rustls feature) and native-tls (opt-in) features instead.

Fixes github#1805
@achicu
achicu requested a review from a team as a code owner October 5, 2026 08:27

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Rust SDK hard-codes native-tls (OpenSSL); offer a rustls TLS backend so musl/static builds work

1 participant