fix(http): fall back to bundled Mozilla roots when the system CA store is empty - #2295
Conversation
Native binary sizes (
|
| Artifact | Format | Base | PR | Change |
|---|---|---|---|---|
vp (Linux x64) |
Binary | 10.38 MiB | 10.51 MiB | +132.02 KiB (+1.24%) |
vp (Linux x64) |
gzip -9 | 4.45 MiB | 4.55 MiB | +98.23 KiB (+2.15%) |
| NAPI (Linux x64) | Binary | 33.48 MiB | 33.60 MiB | +128.06 KiB (+0.37%) |
| NAPI (Linux x64) | gzip -9 | 12.93 MiB | 13.02 MiB | +97.95 KiB (+0.74%) |
vp (macOS ARM64) |
Binary | 7.70 MiB | 7.83 MiB | +129.02 KiB (+1.64%) |
vp (macOS ARM64) |
gzip -9 | 3.86 MiB | 3.95 MiB | +96.28 KiB (+2.44%) |
| NAPI (macOS ARM64) | Binary | 40.79 MiB | 40.92 MiB | +129.00 KiB (+0.31%) |
| NAPI (macOS ARM64) | gzip -9 | 17.15 MiB | 17.24 MiB | +93.31 KiB (+0.53%) |
vp (Windows x64) |
Binary | 8.42 MiB | 8.42 MiB | +512 B (+0.01%) |
vp (Windows x64) |
gzip -9 | 3.66 MiB | 3.66 MiB | +223 B (+0.01%) |
| NAPI (Windows x64) | Binary | 27.76 MiB | 27.76 MiB | 0 B (0.00%) |
| NAPI (Windows x64) | gzip -9 | 10.86 MiB | 10.86 MiB | +289 B (+0.00%) |
| Trampoline (Windows x64) | Binary | 203.00 KiB | 203.00 KiB | 0 B (0.00%) |
| Trampoline (Windows x64) | gzip -9 | 97.91 KiB | 97.91 KiB | -1 B (-0.00%) |
| Installer (Windows x64) | Binary | 4.47 MiB | 4.47 MiB | +512 B (+0.01%) |
| Installer (Windows x64) | gzip -9 | 2.09 MiB | 2.09 MiB | +164 B (+0.01%) |
|
@codex review |
|
Codex Review: Didn't find any major issues. Bravo. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Registry bridge build (
|
| Package | Version |
|---|---|
vite-plus |
0.0.0-commit.175538b184911b9af6584b86bb2a9a7079b1ae25 |
@voidzero-dev/vite-plus-core |
0.0.0-commit.175538b184911b9af6584b86bb2a9a7079b1ae25 |
Install the Vite+ CLI built from this commit, then migrate a project:
# macOS / Linux
curl -fsSL https://vite.plus | VP_PR_VERSION=2295 bash# Windows (PowerShell)
$env:VP_PR_VERSION="2295"; irm https://vite.plus/ps1 | iexAfter installing, upgrade the current project's vite-plus to this test build with:
vp migrateOr point your package manager at the bridge registry https://registry-bridge.viteplus.dev/:
| Package manager | Registry config |
|---|---|
| npm / pnpm / Bun | .npmrc: registry=https://registry-bridge.viteplus.dev/ |
| Yarn (v2+) | .yarnrc.yml: npmRegistryServer: "https://registry-bridge.viteplus.dev/" |
Then pin the build (vite aliases to vite-plus-core; pnpm can use a catalog, npm an overrides entry):
{
"devDependencies": {
"vite-plus": "0.0.0-commit.175538b184911b9af6584b86bb2a9a7079b1ae25",
"vite": "npm:@voidzero-dev/vite-plus-core@0.0.0-commit.175538b184911b9af6584b86bb2a9a7079b1ae25"
}
}
🐳 Docker preview imageBuilt from this PR's registry bridge build:
# remove any stale local copy from a previous run, then pull fresh
docker rmi ghcr.io/voidzero-dev/vite-plus:pr-2295 2>/dev/null; docker pull ghcr.io/voidzero-dev/vite-plus:pr-2295Quick check: docker run --rm ghcr.io/voidzero-dev/vite-plus:pr-2295 vp --versionSee docs/guide/docker.md for usage. |
c78a484 to
6e68170
Compare
✅ Deploy Preview for viteplus-preview canceled.
|
|
✅ Staging deployment successful! Preview: https://viteplus-staging.void.app/ |
|
Verified the registry-bridge build (
|
…e is empty When the shared HTTP client cannot be built because the trust store is empty (Debian slim and distroless images ship no ca-certificates package), retry once with the webpki-root-certs Mozilla list merged in, like Node's own bundled roots. A populated system store keeps sole authority; failures the bundle cannot fix still surface the original error. Windows keeps native-tls/SChannel and skips the fallback. Closes #2278
On Windows native-tls rejects the invalid-DER PEM at parse time, so the bad bundle is skipped with a warning, the build succeeds against SChannel, and the is_err assertion fails. The bundled-roots retry the test guards is compiled out on Windows anyway.
Regression test for the #2278 fallback: build the global vp inside a bookworm container so its glibc floor matches the runtime image, then run vp env list-remote in node:24-bookworm-slim, which ships no ca-certificates package. The job asserts the CA bundle is really absent so the check keeps guarding if the base image changes.
Both build-failure tests carried the same temp PEM write, env set/unset, and cleanup scaffold; with_invalid_ssl_cert_file now owns it.
Mount the host rustup home so the container picks up the pinned nightly that setup-rust installed instead of downloading it on every run; rustup show still installs it if the mount misses.
6e68170 to
b0682df
Compare
…t variable renames, and install fixes (#2325) Release vite-plus v0.2.8: monorepo target resolution, breaking `VP_*` environment variable renames, and install fixes. Bare `vp dev`/`build`/`preview`/`pack` at a monorepo root now resolve a target package instead of silently running against the root, and three Vite+-specific environment variables move to the `VP_*` prefix without compatibility aliases. Two failures that broke Vite+ before it could run are also fixed: the crash on container images that ship no CA certificates, and the missing Rolldown binding under pnpm's global virtual store. ### Breaking Changes - Rename three Vite+-specific environment variables to the `VP_*` prefix, with no compatibility aliases, so the old names stop working ([#2312](#2312)), by @jong-kyung: | Old | New | | --- | --- | | `VITE_LOG` | `VP_LOG` | | `VITE_GLOBAL_CLI_JS_SCRIPTS_DIR` | `VP_GLOBAL_CLI_JS_SCRIPTS_DIR` | | `VITE_UPDATE_TASK_TYPES` | `VP_UPDATE_TASK_TYPES` | Update any shell profile, CI job, or Dockerfile that sets the old names. ### Highlights - Resolve a target package for `vp dev`, `build`, `preview`, and `pack` at a monorepo root: interactive shells get a fuzzy package picker, non-interactive runs list the candidates and exit 1 instead of building the root, and a new global `-C <dir>` flag or a `defaultPackage` setting (a single directory, or an object mapping each of the four commands to its own directory) skips the prompt ([#2031](#2031), [#2305](#2305)), by @fengmk2 - Stop aborting with exit 134 on container images that ship no CA certificates (Debian slim, distroless): the shared HTTP client now retries once with the bundled Mozilla root list, like Node's own bundled roots, and reports a real error instead of panicking when it still cannot be built ([#2273](#2273), [#2295](#2295)), by @jbmusso and @fengmk2 - Resolve the bundled Rolldown binding through platform packages instead of an undeclared require back into `vite-plus`, fixing `Cannot find module 'vite-plus/binding'` under pnpm `enable-global-virtual-store` and in standalone `@voidzero-dev/vite-plus-core` installs ([#2313](#2313)), by @fengmk2 - Add `vp pm ci` for reproducible frozen-lockfile installs, and `vp pm patch` / `vp pm patch-commit` for editing dependencies in place on pnpm, bun, and Yarn Berry (npm and Yarn Classic warn and exit successfully) ([#2082](#2082), [#2308](#2308)), by @forehalo and @jong-kyung ### Features - Upgrade the bundled toolchain: vite `8.1.5` -> `8.2.0`, rolldown `1.2.0` -> `1.2.2`, oxlint `1.75.0` -> `1.76.0`, oxfmt `0.60.0` -> `0.61.0`, and Vite DevTools `0.4.5` -> `0.4.10` ([#2302](#2302), [#2311](#2311)), by @voidzero-guard[bot]. The new oxfmt and oxlint can flag code that passed before, so run `vp fmt` after upgrading if your CI runs `vp check`. - Read the Node.js version from `.nvmrc` when no other version source is present ([#2244](#2244)), by @BlankParticle - Support pnpm v12, which ships as a native binary: Vite+ now downloads the platform-specific `@pnpm/exe.*` package and generates native shims, so `pnpm` and `pnpx` work instead of failing to exec ([#2289](#2289)), by @jong-kyung - Verify the downloaded bun platform tarball against the registry `dist.integrity` hash ([#2310](#2310)), by @jong-kyung ### Fixes & Enhancements - Let `vp config` install the Git hook dispatcher without creating or modifying project hook scripts or staged-file configuration, so a custom `.vite-hooks/pre-commit` survives ([#2280](#2280)), by @TheAlexLichter - Nest immutable global package installs under `packages/<package>/<uuid>` instead of using `#` in the path, which Node treated as a URL fragment and which broke dynamic imports inside installed packages ([#2222](#2222)), by @liangmiQwQ - Keep the recorded version spec on global installs, so `vp update -g` follows a dist tag or range instead of silently resolving back to `latest`, `vp outdated -g` reports Wanted versus Latest, and `vp update -g --latest` explicitly moves packages back to `latest` ([#2249](#2249)), by @TheAlexLichter - Stop deleting a managed Node.js runtime that another process is concurrently installing ([#2248](#2248)), by @shulaoda - Preserve the real exit code when a spawned process is terminated by a signal on Unix ([#2154](#2154)), by @liangmiQwQ - Honor an explicit `vp create --package-manager` outside monorepos instead of inheriting the manager from a non-monorepo ancestor directory ([#2226](#2226)), by @jong-kyung - Scaffold the `vite:library` template into a directory that contains only `.git`, while still refusing to overwrite existing user files ([#2287](#2287)), by @RSS1102 - Render help for delegated commands from the local CLI, so `vp <command> --help` matches the installed toolchain instead of drifting ([#2184](#2184)), by @liangmiQwQ - Resolve `typeAware` and `typeCheck` options inherited through Oxlint `extends`, so `vp check --no-lint` runs and classifies type checking correctly ([#2228](#2228)), by @jong-kyung - Report `(no version)` instead of `unknown` when globally installing a local package that has no `version` field ([#2232](#2232)), by @liangmiQwQ ### Refactor - Rename the Git hooks environment variable to `VP_GIT_HOOKS`, keeping `VITE_GIT_HOOKS` working as a deprecated alias ([#2195](#2195)), by @dennybiasiolli - Consolidate the package manager infrastructure so typed command arguments are the source of truth for per-manager compatibility ([#2140](#2140)), by @forehalo - Generate the Zed language settings from a language list instead of 17 near-identical blocks ([#2294](#2294)), by @jong-kyung - Share the agent-file detect and write traversal helpers so both passes apply identical rules ([#2296](#2296)), by @jong-kyung - Drop redundant clippy allow attributes in the global CLI ([#2235](#2235)), by @shulaoda ### Docs - Avoid a duplicate `vp` installation step in the onboarding prompt ([#2291](#2291)), by @Arcadi4 - Recommend stacked pull requests for submitting changes ([#2281](#2281)), by @fengmk2 - Correct stale delegation comments in the global CLI ([#2236](#2236)), by @shulaoda - Improve the release draft review guidance in the release-manager skill ([#2285](#2285)), by @wan9chi ### Chore - Stop emitting unmet peer warnings for the `vite-plus` peer of oxfmt and oxlint on every install ([#2321](#2321)), by @fengmk2 - Remove duplicate direct dependency declarations so each build dependency is owned by one workspace ([#2318](#2318)), by @jong-kyung - Declare `@emnapi` peers where `@napi-rs/cli` is used ([#2319](#2319)), by @jong-kyung - Exclude `rollup-tests` from the workspace and update `basic-ftp` ([#2322](#2322)), by @fengmk2 - Remove unused `EnvConfig` fields ([#2320](#2320)), by @jong-kyung - Remove the obsolete peer dependency merger tool ([#2303](#2303)), by @jong-kyung - Stop the staging deploy from triggering on external pull requests ([#2293](#2293)), by @BlankParticle - Kill the real `vp` process, and kill it before its children, in the `env_install_interrupt` snapshot test ([#2299](#2299), [#2316](#2316)), by @fengmk2 - Suppress racy optimizer logs in the `vitest_browser_mode` snapshot test ([#2297](#2297)), by @fengmk2 - Remove the obsolete auto-install environment from the snapshot tests ([#2163](#2163)), by @liangmiQwQ ### Bundled Versions | Tool | Version | Source | | --------------- | ---------- | ------------------------------------------------------------------------------------------------- | | vite | `8.2.0` | [`fa79f9a`](vitejs/vite@fa79f9a) | | rolldown | `1.2.2` | [`872b98a`](rolldown/rolldown@872b98a) | | tsdown | `0.22.14` | [npm](https://npmx.dev/package/tsdown/v/0.22.14) | | vitest | `4.1.10` | [npm](https://npmx.dev/package/vitest/v/4.1.10) | | oxlint | `1.76.0` | [npm](https://npmx.dev/package/oxlint/v/1.76.0) | | oxlint-tsgolint | `7.0.2001` | [npm](https://npmx.dev/package/oxlint-tsgolint/v/7.0.2001) | | oxfmt | `0.61.0` | [npm](https://npmx.dev/package/oxfmt/v/0.61.0) | ### Upgrade ```bash vp upgrade ``` ### New Contributors @jbmusso, @Arcadi4, @dennybiasiolli, @RSS1102 **Full Changelog**: v0.2.7...v0.2.8 --- Merging this PR will trigger the release workflow. --------- Co-authored-by: voidzero-guard[bot] <278573678+voidzero-guard[bot]@users.noreply.github.com> Co-authored-by: MK <fengmk2@gmail.com>
When the shared HTTP client cannot be built because the trust store is
empty (Debian slim and distroless images ship no ca-certificates
package), retry once with the webpki-root-certs Mozilla list merged in,
like Node's own bundled roots. A populated system store keeps sole
authority; failures the bundle cannot fix still surface the original
error. Windows keeps native-tls/SChannel and skips the fallback.
Closes #2278
Stack created with GitHub Stacks CLI • Give Feedback 💬