fix(gateway): stop exporting fallback CA bundles on import

This commit is contained in:
ethernet
2026-09-24 09:09:03 -04:00
parent ff14aaecc0
commit 3071d0bec8
3 changed files with 126 additions and 49 deletions

View File

@@ -1523,49 +1523,6 @@ def _collect_history_media_paths(agent_history: List[Dict[str, Any]]) -> set:
break
return paths
def _ensure_ssl_certs() -> None:
"""Set SSL_CERT_FILE when the system hides CA certs from Python (NixOS etc.); must run BEFORE any
HTTP library is imported. A set-but-missing path breaks every later httpx client: treat as unset."""
configured_cert = os.environ.get("SSL_CERT_FILE")
if configured_cert:
if os.path.exists(configured_cert):
return # user already configured it to a real file
logging.getLogger(__name__).warning(
"Ignoring stale SSL_CERT_FILE=%r because the path does not exist", configured_cert)
os.environ.pop("SSL_CERT_FILE", None)
import ssl
# 1. Python's compiled-in defaults
paths = ssl.get_default_verify_paths()
for candidate in (paths.cafile, paths.openssl_cafile):
if candidate and os.path.exists(candidate):
os.environ["SSL_CERT_FILE"] = candidate
return
# 2. certifi (ships its own Mozilla bundle)
try:
import certifi
os.environ["SSL_CERT_FILE"] = certifi.where()
return
except ImportError:
pass
# 3. Common distro / macOS locations
for candidate in (
"/etc/ssl/certs/ca-certificates.crt", # Debian/Ubuntu/Gentoo
"/etc/pki/tls/certs/ca-bundle.crt", # RHEL/CentOS 7
"/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem", # RHEL/CentOS 8+
"/etc/ssl/ca-bundle.pem", # SUSE/OpenSUSE
"/etc/ssl/cert.pem", # Alpine / macOS
"/etc/pki/tls/cert.pem", # Fedora
"/usr/local/etc/openssl@1.1/cert.pem", # macOS Homebrew Intel
"/opt/homebrew/etc/openssl@1.1/cert.pem", # macOS Homebrew ARM
):
if os.path.exists(candidate):
os.environ["SSL_CERT_FILE"] = candidate
return
def _home_target_env_var(platform_name: str) -> str:
"""Home-target env var: built-in ``_HOME_TARGET_ENV_VARS``, plugin registry, then
``<PLATFORM>_HOME_CHANNEL``."""
@@ -1595,8 +1552,6 @@ def _planned_restart_notification_pending() -> bool:
# Gateway marker so a lazily imported cli.py load_cli_config() doesn't clobber TERMINAL_CWD.
os.environ["_HERMES_GATEWAY"] = "1"
_ensure_ssl_certs()
sys.path.insert(0, str(Path(__file__).parent.parent))
from hermes_constants import get_hermes_home, get_hermes_home_override, get_process_hermes_home