From 58a4caea89a0d597436ab83cf5d7d89093f52b8c Mon Sep 17 00:00:00 2001 From: achicu Date: Mon, 5 Oct 2026 02:23:15 +0000 Subject: [PATCH] rust: make the request-handler TLS backend a feature (default rustls) Cargo unifies features across the dependency graph, so the hard-coded reqwest/native-tls feature flipped reqwest's TlsBackend::default() to native-tls for every reqwest client in a consumer's whole binary, not just the SDK's request-handler transport. Introduce rustls (default, aws-lc-rs via reqwest's rustls feature) and native-tls (opt-in) features instead. Fixes #1805 --- rust/Cargo.toml | 16 +++++++++++++--- rust/README.md | 2 ++ 2 files changed, 15 insertions(+), 3 deletions(-) diff --git a/rust/Cargo.toml b/rust/Cargo.toml index 0b5c85e472..eba36dd403 100644 --- a/rust/Cargo.toml +++ b/rust/Cargo.toml @@ -28,8 +28,18 @@ include = [ name = "github_copilot_sdk" [features] -default = ["bundled-cli"] +default = ["bundled-cli", "rustls"] runtime = [] +# TLS backend for the `CopilotRequestHandler` HTTP/WebSocket forwarding +# transport. Exactly one is normally enabled. `rustls` (default) uses +# reqwest's rustls stack (aws-lc-rs provider, matching the Copilot runtime) +# with no system OpenSSL; `native-tls` opts into the platform-native stack +# (OpenSSL on Linux). These are deliberately opt-in features rather than +# hard-coded dependency features: Cargo unifies features, so a hard-coded +# `reqwest/native-tls` flips `reqwest`'s default TLS backend to native-tls for +# every reqwest client in the consumer's whole dependency graph. +rustls = ["reqwest/rustls", "tokio-tungstenite/rustls-tls-native-roots"] +native-tls = ["reqwest/native-tls", "tokio-tungstenite/native-tls"] bundled-cli = ["runtime", "dep:tar", "dep:flate2", "dep:zip"] in-process = ["runtime", "dep:libloading"] local-runtime = ["in-process"] @@ -68,8 +78,8 @@ base64 = "0.23" bytes = "1" http = "1" futures-util = "0.3" -reqwest = { version = "0.13", default-features = false, features = ["stream", "http2", "native-tls"] } -tokio-tungstenite = { version = "0.28.0", default-features = false, features = ["connect", "native-tls"] } +reqwest = { version = "0.13", default-features = false, features = ["stream", "http2"] } +tokio-tungstenite = { version = "0.28.0", default-features = false, features = ["connect"] } [target.'cfg(windows)'.dependencies] zip = { version = "7.2.0", default-features = false, features = ["deflate"], optional = true } diff --git a/rust/README.md b/rust/README.md index 6198f55b90..3e58261c4e 100644 --- a/rust/README.md +++ b/rust/README.md @@ -1595,6 +1595,8 @@ and `CARGO_CFG_TARGET_ENV` (cross-compilation works). | `in-process` | — | Enables `Transport::InProcess` while preserving the selected runtime acquisition policy. | | `local-runtime` | — | Enables `in-process` and, when `bundled-cli` is disabled, disables SDK-managed runtime download, extraction, and embedding. The application must supply a compatible runtime package through `COPILOT_CLI_PATH`. | | `bundled-in-process` | — | Enables `in-process`, implies `bundled-cli`, and additionally embeds the platform-native runtime library. | +| `rustls` | ✓ | TLS for the `CopilotRequestHandler` HTTP/WebSocket forwarding transport via rustls (aws-lc-rs provider, OS trust store). No system OpenSSL required, so musl/static targets build. | +| `native-tls` | — | Platform-native TLS (OpenSSL on Linux, Secure Transport on macOS, SChannel on Windows) for the request-handler transport instead of rustls. With `default-features = false`, enable one of `rustls` / `native-tls` if you register a `request_handler` that forwards to HTTPS/WSS upstreams. | | `derive` | — | `schema_for::()` for generating JSON Schema from Rust types (adds `schemars`). | ```toml