fix(cli): trust system and explicit CAs, explain login failures, fix custom installer paths (0.38.2) - #1716
Merged
Conversation
added 3 commits
September 30, 2026 23:59
… custom installer paths - #1708: one process-wide TLS trust (bundled Mozilla + lazily loaded OS store honouring SSL_CERT_FILE/SSL_CERT_DIR + additive NYXID_CA_CERT) for every HTTP and WSS client, Sigstore TUF downloads included; broken explicit CA configuration fails closed; node daemon, auto-update scheduler and node docker forward CA paths (never proxy variables). - #1709: login keeps its codes, messages and exit statuses and adds a sanitized error.diagnostic (stage, timeout, status, endpoint, causes, hint) for login_unavailable/storage; doctor gains Network/TLS and NyxID API (/health, --base-url/--profile) sections with the same classifier. - #1710: install.sh stages the cargo-dist installer privately, installs into the versioned root and atomically links NYXID_ACTIVE_SYMLINK; Rust source fallback only when no prebuilt installer could be obtained or run.
📊 Code coverage
Gate: line coverage must stay at or above the threshold. Ratchet plan (W21): Backend → 55%, CLI → 50%, Frontend → 30% by quarter end. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Fixes three CLI problems reported from a Linux cloud workspace behind an HTTPS proxy with a custom trusted CA (0.38.2).
Closes #1708, closes #1709, closes #1710.
#1708 — the CLI now trusts system and explicit CAs
Cause. The CLI's HTTP client used reqwest's
rustls-tlsfeature, i.e. only the bundled Mozilla roots. It ignoredSSL_CERT_FILE,SSL_CERT_DIRand the OS store. The node andnyxid sshWebSocket paths used the OS store only, so the two halves of the CLI trusted different sets.Fix.
cli/src/tls.rsbuilds one process-wide trust set, used by every HTTP and WSS client in the CLI and node agent:SSL_CERT_FILE/SSL_CERT_DIR: used when set.NYXID_CA_CERT: a new PEM file of extra trusted CAs, always added on top.Verification is never weakened. Hostname checks still apply with a trusted CA. There is no bypass switch.
Failure behaviour.
Where the settings apply.
tough::Transport. TUF signature, expiry, hash and length checks are unchanged. The embedded bootstrap root is byte-identical to sigstore 0.13.0's.nyxid node daemon install,nyxid update auto enableandnyxid node docker start/restartcarry the CA paths. Docker gets read-only bind mounts plus container-local variables. Proxy variables are never persisted.nyxid node startfails fast on a broken CA setting instead of reconnecting forever.nyxid --helpandnyxid login --helplist the variables.#1709 —
login_unavailablesays whyUnchanged. Error codes, messages and exit statuses are exactly as before; pending, denied, expired, rate-limited and similar outcomes produce byte-identical JSON.
Added.
login_unavailableandlogin_storage_failedgain an additiveerror.diagnostic:stage:config,connect,proxy,tls,request,response,validationorstorage.timeout:connectorrequest, when a timeout occurred.http_status/server_error_code: the HTTP status, plus the server's numeric error code only.endpoint: the URL without userinfo, query or fragment.causes: de-duplicated and bounded.hint: depends on the failure. For TLS, an unknown issuer, a hostname mismatch and an expired certificate each get their own hint.Redaction. Tokens, codes, polling secrets, Authorization headers, proxy credentials and query strings are removed, and tests cover this.
Where else the classifier is used.
nyxid doctorNetwork / TLS section: trust sources and counts,NYXID_CA_CERTstatus, proxy variables shown without credentials, andNO_PROXYpatterns.nyxid doctorNyxID API section: checksGET {base}/healthusing--base-url, else the--profilesaved URL, else the default.#1710 —
install.shwith a customNYXID_ACTIVE_SYMLINKCause. The cargo-dist installer always writes to
$HOME/.local/bin, but the wrapper only looked at$NYXID_ACTIVE_SYMLINK. With a custom path it misread a successful install as "no prebuilt" and started rustup and cargo.Fix.
NYXID_CLI_UNMANAGED_INSTALL). It clears theNYXID_CLI_INSTALL_DIR/CARGO_DIST_FORCE_INSTALL_DIRoverrides, which would otherwise take precedence.--version, installs intoNYXID_INSTALL_ROOT/vX.Y.Zand atomically linksNYXID_ACTIVE_SYMLINK.skills/nyxid/scripts/**now triggers the CLI tests.Docs
docs/site/cli/guides/network.md(Network, proxies and TLS), linked from the docs nav.docs/RELEASING.md, and the skill references (device-login.md,nodes.md).Verification
cargo fmt --checkandcargo clippy --workspace --all-targets -D warningspass.cargo test -p nyxid-clipasses with no failures and no ignored tests. 82 test names were added and none removed.NYXID_CA_CERTorSSL_CERT_FILE, rejection on hostname mismatch and of a self-signed leaf, and the lazy OS-store fallback running exactly once.curl,uname,cargoandrustupcovers default, custom-HOME, custom-root, custom-symlink, both-custom and XDG layouts, the no-fallback failure cases and reruns.openssl s_serverprivate CA: untrusted gives stagetlswith the CA hint; a wrong host gives the hostname hint; trusted passes TLS.proxy, with credentials redacted.nyxid doctorreports thathttps://nyx-api.chrono-ai.fun/healthreturned 200.nyxid update --version 0.37.1verified the release attestation through the new TUF transport against the live Sigstore CDN.