net/http: give the HTTPS client trust roots on darwin - #75
Open
yohimik wants to merge 1 commit into
Open
Conversation
The client dialled TLS with a nil config, which leaves RootCAs nil, which sends crypto/x509 to the platform verifier on darwin. crypto/x509/internal/macos in TinyGo is a stub, so every HTTPS request to a real server failed verification as soon as the package compiled against the standard library crypto/tls and not against the no-op stub. Give the dial a config from defaultTLSConfig. Off darwin that is still nil, because crypto/x509 finds the system roots in the usual files. On darwin it carries a pool that is read once from $SSL_CERT_FILE, or from the bundle of macOS at /etc/ssl/cert.pem. A non-nil pool makes x509 build the chain in pure Go instead of a call to the stubbed verifier. If no file can be read, the config has no roots, so the result is an ordinary verification error and not a check that is silently skipped. A direct tls.Dial with a nil config still fails on darwin for the same reason. A caller that does not use this package supplies its own RootCAs.
This was referenced Aug 30, 2026
Author
|
tinygo-org/net main has not moved since this branch was opened. It is still |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
net/http: give the HTTPS client trust roots on darwin
Repository tinygo-org/net. Branch
upstream-pr/http-darwin-roots, basemain.What this does
The client dialled TLS with a nil config, which leaves
RootCAsnil, whichsends
crypto/x509to the platform verifier on darwin.crypto/x509/internal/macosin TinyGo is a stub, so every HTTPS request to areal server fails verification as soon as the package compiles against the
standard library
crypto/tlsand not against the no-op stub.The dial now takes a config from
defaultTLSConfig.crypto/x509finds the system roots inthe usual files.
$SSL_CERT_FILE, or fromthe bundle of macOS at
/etc/ssl/cert.pem. A non-nil pool makesx509buildthe chain in pure Go instead of a call to the stubbed verifier.
verification error and not a check that is silently skipped.
Evidence
There is no CI in this repository. Checked by hand on macOS 26.6 arm64 with a
TinyGo build that carries the matching toolchain change.
http.Get("https://example.com/")completes with a verified chain.A downstream product ships binaries built with these changes in a production
release. dispat v1.4.0 is published and is not a prerelease. It carries
dispat-tiny-linux-amd64anddispat-tiny-linux-arm64, built by the forkrelease v0.42.0-net.4 from sha256-pinned tarballs and smoke-executed under
binfmt before upload, beside six binaries from the gc toolchain.
https://github.com/yohimik/dispat/releases/tag/services%2Fdispat%2Fv1.4.0
The acceptance record of that repository is committed at
packages/docs/docs/internals/tinygo.md. It reports the net.2 to net.4acceptance history, an integration suite of 694 rows that passes with 0 failures
and 1 documented skip on darwin, and a size table of 0.58x to 0.63x against the
gc equivalents with TinyGo
-opt=z -no-debugagainstgo build -trimpath -ldflags "-s -w". Those figures come from that document. They are not ameasurement of this branch.
The self-update path of that program runs over real TLS against a live host, and
its suite has negative rows as well. An unknown CA is refused, and a plaintext
server on a TLS port is refused. The shipped binaries in that release are for
linux. The darwin evidence is the acceptance record and the check above.
Dependencies
crypto/tlson hosted targets. See the tinygo PR "loader: use the realcrypto/tls on hosted linux and darwin". With the TLS stub the change is
harmless and has no effect.
http/client.gois also touched by "net/http: follow redirects in the clientagain" in this series. The two merge without a conflict, but take the redirect
PR first and rebase this one on it, or the reverse, to keep the diff small.
Known gaps
tls.Dialwith a nil config still fails on darwin for the samereason. A caller that does not use this package supplies its own
RootCAs.crypto/x509/internal/macosin TinyGo.This is the client-side workaround until then.
Related pull requests
This change is part of one body of work. Together the changes make programs that use the network and child processes work on hosted linux and macOS. A full CLI was tested end to end with all of them and ships binaries built this way, see dispat v1.4.0 in the evidence section.
In tinygo-org/tinygo
In this repository
A merge order that works. The three bug fixes are independent. tinygo-org/tinygo#5633 goes before tinygo-org/tinygo#5635. HTTPS on linux needs only tinygo-org/tinygo#5633 and tinygo-org/tinygo#5635. Full darwin support also needs tinygo-org/tinygo#5636, the net changes and a new src/net submodule pin.