mirror of
https://github.com/saphid/frame-control.git
synced 2026-10-06 02:00:19 +02:00
Bundle a CA list so HTTPS works from Python on fresh Windows
The bundled Python only trusts roots already in the Windows certificate store, which Windows fills lazily, so on a new install Steam store search, F-Droid downloads and the compat DB failed with CERTIFICATE_VERIFY_FAILED. fetch-deps.js now also bundles curl's pinned copy of Mozilla's CA list, and the server adds it to the default HTTPS context on top of the system certificates (before any urlopen, since urllib keeps the context it first builds). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
1a0e54d8bd
commit
770f26c703
5 files changed
+40
-8
No files matched your search
+10
-4
@@ -1,7 +1,7 @@
|
||||
// Downloads what the app bundles so users install nothing else: a standalone
|
||||
// Python (python-build-standalone) and adb (Android platform-tools). Each goes in
|
||||
// build/deps/<os>-<arch>/{python,tools}, which package.json copies into the app's
|
||||
// resources. Everything is pinned by version and SHA-256.
|
||||
// Python (python-build-standalone), adb (Android platform-tools) and a CA
|
||||
// bundle. Each goes in build/deps/<os>-<arch>/{python,tools}, which package.json
|
||||
// copies into the app's resources. Everything is pinned by version and SHA-256.
|
||||
// node build/fetch-deps.js mac arm64 | win x64 | linux x64 arm64
|
||||
const crypto = require("crypto");
|
||||
const fs = require("fs");
|
||||
@@ -29,6 +29,11 @@ const TOOLS = {
|
||||
linux: ["linux", "d230f13842f60f782a8645f9c813f8f845bf36089ea7289f28c48f17979313f1", ["adb"]],
|
||||
};
|
||||
|
||||
// Mozilla's CA list, as curl publishes it: Python on Windows only trusts roots
|
||||
// already in the Windows store (see frame_host.trust_bundled_cas).
|
||||
const CA = "2026-09-25";
|
||||
const CA_SHA256 = "a41b5d356aea97a529fe27e0f7316d2f9d946d75927476cf9cf1b90637d00505";
|
||||
|
||||
// Parts of Python the server never imports (GUI, tests, packaging, headers).
|
||||
const PRUNE = [
|
||||
"include", "share", "Scripts", "libs", "tcl", "lib/pkgconfig", "lib/itcl4", "lib/tcl8", "lib/tcl8.6",
|
||||
@@ -79,7 +84,7 @@ async function fetch(os, arch) {
|
||||
if (!PYTHON[key]) throw new Error(`no bundle for ${key}`);
|
||||
const out = path.join(__dirname, "deps", key);
|
||||
const stamp = path.join(out, ".version");
|
||||
const version = `python ${PY}, platform-tools ${PT}`;
|
||||
const version = `python ${PY}, platform-tools ${PT}, CA ${CA}`;
|
||||
if (fs.existsSync(stamp) && fs.readFileSync(stamp, "utf8") === version) {
|
||||
console.log(`${key}: already fetched (${version})`);
|
||||
return;
|
||||
@@ -107,6 +112,7 @@ async function fetch(os, arch) {
|
||||
if (os !== "win") fs.chmodSync(path.join(tools, "adb"), 0o755);
|
||||
fs.rmSync(tmp, { recursive: true, force: true });
|
||||
}
|
||||
await download(`https://curl.se/ca/cacert-${CA}.pem`, CA_SHA256, path.join(tools, "cacert.pem"));
|
||||
fs.writeFileSync(stamp, version);
|
||||
console.log(`${key}: ${version} -> ${out}`);
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user