From 42dd645e4a271e5531b4e88479c857b27feafad0 Mon Sep 17 00:00:00 2001 From: jrtxio Date: Thu, 1 Oct 2026 15:32:07 +0800 Subject: [PATCH] distribution: drop crypto/all; pin the provider to libcrypto MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Requiring crypto/all loads every factory module, and some of them run their FFI loads in their module bodies — the gmp factory kills the process at import time on hosts without libgmp. Rivet's manifest needs only SHA-256 and Ed25519, which the libcrypto provider (bundled by the official Racket distributions on every desktop target) fully satisfies, so the provider set is pinned there and crypto/all is gone entirely. Found packaging a real app for macOS: the CI-built bundle died at boot on a clean install before any manifest code ran. --- rivet/distribution/crypto.rkt | 25 ++++++++++++------------- 1 file changed, 12 insertions(+), 13 deletions(-) diff --git a/rivet/distribution/crypto.rkt b/rivet/distribution/crypto.rkt index 8430372..952a579 100644 --- a/rivet/distribution/crypto.rkt +++ b/rivet/distribution/crypto.rkt @@ -1,7 +1,7 @@ #lang racket/base (require crypto - crypto/all + (only-in crypto/libcrypto libcrypto-factory) net/base64 racket/file racket/port @@ -22,20 +22,19 @@ ;; provider that lacks it fails closed instead of falling back to another ;; signature scheme. ;; -;; Instantiate exactly the factories that satisfy that pin. use-all-factories! -;; would also probe the gmp factory, whose FFI load kills the process at -;; module-import time on hosts without libgmp — every embedded app that -;; merely verifies a manifest would ship that landmine (found by packaging a -;; real app for macOS, where the CI-built bundle would not start). -(crypto-factories (list libcrypto-factory sodium-factory decaf-factory)) +;; Rivet's manifest crypto is exactly SHA-256 digests and Ed25519 +;; sign/verify, so the provider set is pinned to libcrypto alone: the +;; official Racket distributions bundle OpenSSL on every desktop target. +;; Requiring crypto/all (or instantiating more factories) would drag in +;; factory modules whose FFI loads run at module-import time — the gmp +;; factory kills the process there on hosts without libgmp, and every +;; embedded app that merely verifies a manifest shipped that landmine +;; (found by packaging a real app for macOS, where the CI-built bundle +;; would not start). +(crypto-factories (list libcrypto-factory)) -;; libgcrypt advertises Ed25519 on some Linux distributions but older -;; combinations fail at signing time with "Invalid object". Rivet release -;; manifests use providers whose Ed25519 implementation is exercised by the -;; upstream crypto library on our desktop targets. This also makes an -;; unsupported host fail while importing the key, before a release is built. (define ed25519-factories - (list libcrypto-factory sodium-factory decaf-factory)) + (list libcrypto-factory)) (define (bytes->base64-string value) (bytes->string/utf-8 (base64-encode value #"")))