Skip to content

Honor explicit native HTTPS certificate trust - #255

Merged
relh merged 1 commit into
masterfrom
relh/native-tls-trust
Oct 3, 2026
Merged

relh merged 1 commit into
masterfrom
relh/native-tls-trust

Conversation

@relh

@relh relh commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Native inference and artifact HTTPS now explicitly honor SSL_CERT_FILE through libcurl CAINFO. Unconfigured processes retain system trust. Peer verification and hostname validation remain enabled.

Six actual HTTPS CPU cases passed: untrusted private CA rejected, configured CA accepted, and wrong hostname rejected, for both inference POST and artifact PUT. Tests create certificates in an owned temporary directory and never change global trust stores or deployed services.

Validation: Nim 2.2.4; nim c -d:release --threads:on --mm:orc tests/support/native_https_probe.nim; python3 tests/test_native_https.py <probe>. Zephyrus unit coworld-bitworld-tls-v1, 1 CPU/1 GiB/Nice 19/120-second limit, inactive exit 0. Proofs /tmp/coworld-bitworld-tls-trust. This proves transport trust configuration, not hosted platform receipt authority.

Primary libcurl docs: environment variables and CAINFO. CA variables supported by the curl command are not automatically libcurl application configuration.

Co-authored-by: GPT-6 <noreply@openai.com>
@relh
relh merged commit 393c7e8 into master Oct 3, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant