From 0eed74b065a173efc1468e121f7f29fa58dd60b4 Mon Sep 17 00:00:00 2001 From: primoco <58369875+primoco@users.noreply.github.com> Date: Thu, 25 Jun 2026 12:41:50 +0200 Subject: [PATCH 1/2] =?UTF-8?q?chore:=20replace=20OpenSSL=20with=20rustls?= =?UTF-8?q?=20=E2=80=94=20eliminates=20C=20compilation=20on=20all=20target?= =?UTF-8?q?s?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Switching from native-tls/openssl-vendored to rustls (pure Rust TLS): - reqwest: default-features=false + rustls-tls (drops native-tls) - teloxide: default-features=false + rustls (drops native-tls) - Remove openssl vendored dep entirely Benefits: - Windows: cold build ~3-4 min instead of ~12 min (no MSVC OpenSSL compilation) - ARM64 Linux: no vendored OpenSSL needed, Cross.toml can be empty/removed - All targets: warm cache will be ~1 min - Zero C compilation on any platform --- Cargo.toml | 16 +++++----------- Cross.toml | 1 + 2 files changed, 6 insertions(+), 11 deletions(-) diff --git a/Cargo.toml b/Cargo.toml index f467c62..ff0d188 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "eullm-agent" -version = "0.1.2" +version = "0.1.4" edition = "2021" license = "Apache-2.0" description = "EULLM Agent — autonomous ReAct agent with multi-provider LLM support" @@ -16,16 +16,16 @@ clap = { version = "4", features = ["derive", "env"] } # Async runtime tokio = { version = "1", features = ["full"] } -# HTTP -reqwest = { version = "0.12", features = ["json"] } +# HTTP — rustls-tls: pure Rust TLS, no system OpenSSL required on any platform +reqwest = { version = "0.12", default-features = false, features = ["json", "rustls-tls"] } # Serialization serde = { version = "1", features = ["derive"] } serde_json = "1" serde_yaml = "0.9" -# Telegram bot -teloxide = { version = "0.12", features = ["macros"] } +# Telegram bot — rustls: pure Rust TLS, mirrors reqwest above +teloxide = { version = "0.12", default-features = false, features = ["macros", "rustls", "auto-send", "ctrlc_handler"] } # Error handling anyhow = "1" @@ -37,11 +37,5 @@ async-trait = "0.1" tracing = "0.1" tracing-subscriber = { version = "0.3", features = ["env-filter"] } -# Vendored OpenSSL: compiles from source, no system libssl required. -# Required for cross-compilation to aarch64-unknown-linux-gnu (cross container -# uses Ubuntu Xenial which only provides OpenSSL 1.0.2g, incompatible with -# openssl-sys v0.9.x which requires >=1.1.0). -openssl = { version = "0.10", features = ["vendored"] } - [dev-dependencies] tokio-test = "0.4" diff --git a/Cross.toml b/Cross.toml index 1c0cf87..3806fce 100644 --- a/Cross.toml +++ b/Cross.toml @@ -1 +1,2 @@ +# Cross.toml — no pre-build hooks needed: rustls is pure Rust, no system OpenSSL required. [target.aarch64-unknown-linux-gnu] From e8741a0ca38d07fa50caba99f65b9a42289c0dc3 Mon Sep 17 00:00:00 2001 From: primoco <58369875+primoco@users.noreply.github.com> Date: Thu, 25 Jun 2026 12:46:05 +0200 Subject: [PATCH 2/2] fix: add contents:write permission to release job softprops/action-gh-release@v2 requires explicit contents:write when the org default token permissions are read-only. Without this the release job fails with "Resource not accessible by integration". --- .github/workflows/release.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 2a44f93..7f4a6a3 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -101,6 +101,8 @@ jobs: needs: build runs-on: ubuntu-latest if: ${{ !cancelled() }} + permissions: + contents: write steps: - uses: actions/download-artifact@v4 with: