fix(cosh-ng): revert reqwest TLS to native-tls for agentsight compatibility - #3072
zhangtaibo wants to merge 1 commit into
Conversation
…bility Fixes agentic-os-org#3042 Commit 524dbd6 switched cosh-core reqwest from native-tls to rustls, breaking agentsight eBPF uprobe TLS interception. Revert to native-tls and update Cargo.lock to restore libssl linkage. Changes: - src/cosh-ng/crates/cosh-core/Cargo.toml: native-tls feature - src/cosh-ng/Cargo.lock: regenerated with native-tls dependencies
|
Hermes Agent seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account. You have signed the CLA already but the status is still pending? Let us recheck it. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 39ba1dfc4d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| tokio = { version = "1", features = ["full"] } | ||
| uuid.workspace = true | ||
| reqwest = { version = "0.12", default-features = false, features = ["blocking", "stream", "json", "http2", "charset", "rustls-tls-native-roots", "system-proxy"] } | ||
| reqwest = { version = "0.12", features = ["blocking", "stream", "json", "native-tls"] } |
There was a problem hiding this comment.
Enable vendored OpenSSL in release builds
On Linux this switches cosh-core back to native TLS, but no release build enables the newly declared cosh-core/vendored-openssl feature: the prebuilt action and RPM spec both invoke cargo build --workspace --release without it. The resulting cosh-core dynamically links libssl/libcrypto, and packaging/raw/package.sh always runs verify-binaries.py, which rejects those DT_NEEDED entries, so raw-package release jobs fail before publishing an artifact. Enable the feature in the release build paths (or update the packaging contract consistently).
Useful? React with 👍 / 👎.
|
原issue已解决,thx #3042 |
Summary
Revert cosh-core reqwest TLS backend from rustls back to native-tls to restore agentsight token capture via eBPF uprobe on OpenSSL.
Problem
Commit 524dbd6 (2026-09-02) switched cosh-core's reqwest dependency from
native-tls(OpenSSL) torustls-tls-native-roots. This eliminated runtime OpenSSL linkage, which was the intended goal (removing openssl-libs dependency).However, agentsight's eBPF sslsniff probe hooks OpenSSL
SSL_read/SSL_write/SSL_do_handshakevia uprobe to capture LLM token counts. With rustls (pure Rust TLS), there is no OpenSSL to probe, so agentsight records zero CoshNG token_records, breaking the #2031 token recording contract.This has caused 4 consecutive days of nightly failures (2026-09-03 through 2026-09-06) for:
test_agentsight_records_nonzero_tokenstest_cosh_ng_second_turn_hits_prompt_cacheFix
Revert the TLS backend to native-tls, restoring OpenSSL linkage so agentsight can intercept CoshNG traffic.
This is a short-term fix. Long-term solutions (requiring cross-team coordination):
Changes
src/cosh-ng/crates/cosh-core/Cargo.toml: revert reqwest features fromrustls-tls-native-rootstonative-tlsvendored-opensslfeature for prebuilt release packagingVerification
bash scripts/rpm-build.sh cosh-ngproducescosh-ng-0.23.0-2.alnx4.x86_64.rpm(10.5MB)Fixes #3042