Repository navigation
Feature-gate schannel and windows-sys deps for windows-static-ssl only - #668
Open
ns-ylambert wants to merge 1 commit into
Open
ns-ylambert wants to merge 1 commit into
ns-ylambert wants to merge 1 commit into
Conversation
…cert-store The `schannel` and `windows-sys` crates are used only by `src/easy/windows.rs` to bridge Windows' ROOT cert store into OpenSSL's SSL_CTX trust store. That bridge is only meaningful when curl is built against OpenSSL on Windows via the `windows-static-ssl` feature: - Under `ssl` on Windows, libcurl uses Schannel, which reads the Windows trust store natively. No OpenSSL SSL_CTX bridge is needed. - Under `rustls`, there is no OpenSSL SSL_CTX at all. - Under bare (no TLS) builds, same: no OpenSSL, no bridge needed. Introduce a `windows-cert-store` intermediate feature that opts in both crates via `dep:` and have `windows-static-ssl` enable it. Tighten the `#[cfg]` guards on `windows.rs` to require the feature so the entire schannel-crate-based code path compiles out for `ssl`, `rustls`, and bare builds.
ns-ylambert
force-pushed
the
fix-schannel-gate
branch
2 times, most recently
from
October 2, 2026 19:46
87fd781 to
60b8cb4
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
schannelandwindows-sysare unconditional[target.'cfg(target_env = "msvc")'.dependencies]in thecurlwrapper crate. Both crates are consumed only bysrc/easy/windows.rs, which enumerates the WindowsROOTcert store and injects the DER-encoded certs into an OpenSSLSSL_CTXat TLS context creation time.This bridge is only meaningful when curl is compiled against OpenSSL on Windows (i.e.
windows-static-ssl):sslon Windows, libcurl uses Schannel as the TLS backend, which reads the Windows trust store natively. NoSSL_CTXbridge is needed and the code path is never called.rustls, there is no OpenSSLSSL_CTXat all.Yet both crates are currently compiled into every MSVC build regardless of the active TLS backend, inflating the dep graph and the final binary.
Change
Introduce a
windows-cert-storeintermediate feature that opts in both crates viadep:(making them optional), and havewindows-static-sslenable it. Tighten the#[cfg]guards onwindows.rsto require the feature, so the entire schannel-crate-based code path compiles out underssl,rustls, and bare builds.Verification
cargo check --target x86_64-pc-windows-msvc --features windows-static-sslcontinues to compile thewindows.rsbridge.cargo check --target x86_64-pc-windows-msvc(defaultssl, Schannel path) andcargo check --target x86_64-pc-windows-msvc --features rustls,static-curlcompile.schannelis removed from the dep graph; the wrapper crate'swindows-sysfeatures (Cryptography/LibraryLoader) are removed;curl-sysretains its ownwindows-sysdep for Winsock types and that is out of scope.CI coverage for
windows-static-sslbuilds is kept out of this PR to keep the diff minimal. It is available in the companionfix-windows-static-sslbranch (#666).Related
windows-static-sslfeature (curl+OpenSSL on Windows) #666. It makeswindows-static-sslbuilds functional (vcpkg include-path fix,OPENSSL_DIRprobe, mutual-exclusion guard). This PR is standalone at the code level butwindows-cert-storeis only exercised oncewindows-static-sslbuilds actually work.