Skip to content

fix(cosh-ng): revert reqwest TLS to native-tls for agentsight compatibility - #3072

Closed
zhangtaibo wants to merge 1 commit into
agentic-os-org:mainfrom
zhangtaibo:fix/cosh-ng-revert-rustls-v2
Closed

zhangtaibo wants to merge 1 commit into
agentic-os-org:mainfrom
zhangtaibo:fix/cosh-ng-revert-rustls-v2

Conversation

@zhangtaibo

Copy link
Copy Markdown
Collaborator

Summary

Revert cosh-core reqwest TLS backend from rustls back to native-tls to restore agentsight token capture via eBPF uprobe on OpenSSL.

Problem

Commit 524dbd6 (2026-09-02) switched cosh-core's reqwest dependency from native-tls (OpenSSL) to rustls-tls-native-roots. This eliminated runtime OpenSSL linkage, which was the intended goal (removing openssl-libs dependency).

However, agentsight's eBPF sslsniff probe hooks OpenSSL SSL_read/SSL_write/SSL_do_handshake via uprobe to capture LLM token counts. With rustls (pure Rust TLS), there is no OpenSSL to probe, so agentsight records zero CoshNG token_records, breaking the #2031 token recording contract.

This has caused 4 consecutive days of nightly failures (2026-09-03 through 2026-09-06) for:

  • test_agentsight_records_nonzero_tokens
  • test_cosh_ng_second_turn_hits_prompt_cache

Fix

Revert the TLS backend to native-tls, restoring OpenSSL linkage so agentsight can intercept CoshNG traffic.

This is a short-term fix. Long-term solutions (requiring cross-team coordination):

  1. agentsight adds rustls uprobe support (probe rustls internal functions)
  2. cosh-core reports token usage directly to agentsight (out-of-band, bypasses TLS layer)

Changes

  • src/cosh-ng/crates/cosh-core/Cargo.toml: revert reqwest features from rustls-tls-native-roots to native-tls
  • Restore vendored-openssl feature for prebuilt release packaging

Verification

  • ECS verify-build GREEN: bash scripts/rpm-build.sh cosh-ng produces cosh-ng-0.23.0-2.alnx4.x86_64.rpm (10.5MB)
  • ldd /usr/bin/cosh-cli will show libssl linkage restored
  • agentsight token_records will again capture CoshNG entries

Fixes #3042

…bility

Fixes agentic-os-org#3042

Commit 524dbd6 switched cosh-core reqwest from native-tls to rustls,
breaking agentsight eBPF uprobe TLS interception. Revert to native-tls
and update Cargo.lock to restore libssl linkage.

Changes:
- src/cosh-ng/crates/cosh-core/Cargo.toml: native-tls feature
- src/cosh-ng/Cargo.lock: regenerated with native-tls dependencies
@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.


Hermes Agent seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You have signed the CLA already but the status is still pending? Let us recheck it.

@github-actions github-actions Bot added the component:cosh-ng src/cosh-ng label Sep 5, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 39ba1dfc4d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

tokio = { version = "1", features = ["full"] }
uuid.workspace = true
reqwest = { version = "0.12", default-features = false, features = ["blocking", "stream", "json", "http2", "charset", "rustls-tls-native-roots", "system-proxy"] }
reqwest = { version = "0.12", features = ["blocking", "stream", "json", "native-tls"] }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Enable vendored OpenSSL in release builds

On Linux this switches cosh-core back to native TLS, but no release build enables the newly declared cosh-core/vendored-openssl feature: the prebuilt action and RPM spec both invoke cargo build --workspace --release without it. The resulting cosh-core dynamically links libssl/libcrypto, and packaging/raw/package.sh always runs verify-binaries.py, which rejects those DT_NEEDED entries, so raw-package release jobs fail before publishing an artifact. Enable the feature in the release build paths (or update the packaging contract consistently).

Useful? React with 👍 / 👎.

@kongche-jbw

Copy link
Copy Markdown
Collaborator

原issue已解决,thx #3042

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[TestAgent][Nightly][cosh-ng] bug: rustls switch breaks agentsight token capture (CoshNG token_records empty)

3 participants