Skip to content

0.10.1: every HTTP request fails with "No provider set" (ring patch installs no rustls CryptoProvider) #61

Description

@mkarimv

Summary

In 0.10.1, restoring a session (and, as far as we can tell, building any client) fails on Android with
No provider set. No crash occurs, but no request can be made. 0.9.1 on the same device and with the same
stored session works.

Environment

  • @unomed/react-native-matrix-sdk 0.10.1, from npm (bundled matrix-sdk-0.18.0, rev 1c44fb66)
  • React Native 0.86.2, New Architecture, Expo SDK 57
  • Samsung Galaxy S23 (SM-S711B), Android 15, arm64-v8a, debug build
  • Homeserver: Synapse behind nginx over TLS

Steps to reproduce

  1. Sign in with 0.9.1 and let the session persist.
  2. Upgrade to 0.10.1, rebuild natively, and install over the app without clearing its data.
  3. Cold-start the app. It calls ClientBuilder…build() or restores the session.

Expected

The client builds and the session restores, as on 0.9.1.

Actual

Every attempt rejects with No provider set:

[Auth] Restore attempt 1/3 failed: No provider set
[Auth] Restore attempt 2/3 failed: No provider set
[Auth] Restore attempt 3/3 failed: No provider set

Changing only the SDK version back to 0.9.1, with nothing else touched, restores the same session.

Likely cause

patches/matrix-rust-sdk-ring-provider.patch (commit 4b26856) makes these changes:

  • It switches reqwest from the rustls feature to rustls-no-provider.
  • It adds rustls with default-features = false, features = ["ring", …].

With rustls-no-provider, reqwest does not bring a crypto provider. It expects the process-wide default to
be installed already; otherwise ClientBuilder::build() returns the builder error No provider set. The
string is present in the shipped android/src/main/jniLibs/arm64-v8a/libmatrix_sdk_ffi.so.

The patch changes only Cargo.toml. As far as we can see, nothing in the bindings or in matrix-rust-sdk
calls rustls::crypto::CryptoProvider::install_default(). A code search of matrix-rust-sdk finds
install_default only in crypto x509 code and tests. Upstream matrix-rust-sdk relied on reqwest's
default rustls feature to supply aws-lc as the provider.

The patch applies to all non-wasm targets, so we expect iOS to be affected in the same way. We have not
built iOS to confirm.

Suggested fix

Install ring as the process default once, before any client is built. Possible places are the FFI
init_platform, the start of ClientBuilder::build, or a small wrapper-side init:

let _ = rustls::crypto::ring::default_provider().install_default();

(install_default returns Err if a provider is already installed, so ignoring the result is safe.)

Thanks for the quick 0.10.1 fix for the aws-lc SIGSEGV (matrix-org/matrix-rust-sdk#6442). This looks like
the one missing piece of it.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions