Summary
In 0.10.1, restoring a session (and, as far as we can tell, building any client) fails on Android with
No provider set. No crash occurs, but no request can be made. 0.9.1 on the same device and with the same
stored session works.
Environment
@unomed/react-native-matrix-sdk 0.10.1, from npm (bundled matrix-sdk-0.18.0, rev 1c44fb66)
- React Native 0.86.2, New Architecture, Expo SDK 57
- Samsung Galaxy S23 (SM-S711B), Android 15, arm64-v8a, debug build
- Homeserver: Synapse behind nginx over TLS
Steps to reproduce
- Sign in with 0.9.1 and let the session persist.
- Upgrade to 0.10.1, rebuild natively, and install over the app without clearing its data.
- Cold-start the app. It calls
ClientBuilder…build() or restores the session.
Expected
The client builds and the session restores, as on 0.9.1.
Actual
Every attempt rejects with No provider set:
[Auth] Restore attempt 1/3 failed: No provider set
[Auth] Restore attempt 2/3 failed: No provider set
[Auth] Restore attempt 3/3 failed: No provider set
Changing only the SDK version back to 0.9.1, with nothing else touched, restores the same session.
Likely cause
patches/matrix-rust-sdk-ring-provider.patch (commit 4b26856) makes these changes:
- It switches
reqwest from the rustls feature to rustls-no-provider.
- It adds
rustls with default-features = false, features = ["ring", …].
With rustls-no-provider, reqwest does not bring a crypto provider. It expects the process-wide default to
be installed already; otherwise ClientBuilder::build() returns the builder error No provider set. The
string is present in the shipped android/src/main/jniLibs/arm64-v8a/libmatrix_sdk_ffi.so.
The patch changes only Cargo.toml. As far as we can see, nothing in the bindings or in matrix-rust-sdk
calls rustls::crypto::CryptoProvider::install_default(). A code search of matrix-rust-sdk finds
install_default only in crypto x509 code and tests. Upstream matrix-rust-sdk relied on reqwest's
default rustls feature to supply aws-lc as the provider.
The patch applies to all non-wasm targets, so we expect iOS to be affected in the same way. We have not
built iOS to confirm.
Suggested fix
Install ring as the process default once, before any client is built. Possible places are the FFI
init_platform, the start of ClientBuilder::build, or a small wrapper-side init:
let _ = rustls::crypto::ring::default_provider().install_default();
(install_default returns Err if a provider is already installed, so ignoring the result is safe.)
Thanks for the quick 0.10.1 fix for the aws-lc SIGSEGV (matrix-org/matrix-rust-sdk#6442). This looks like
the one missing piece of it.
Summary
In 0.10.1, restoring a session (and, as far as we can tell, building any client) fails on Android with
No provider set. No crash occurs, but no request can be made. 0.9.1 on the same device and with the samestored session works.
Environment
@unomed/react-native-matrix-sdk0.10.1, from npm (bundledmatrix-sdk-0.18.0, rev1c44fb66)Steps to reproduce
ClientBuilder…build()or restores the session.Expected
The client builds and the session restores, as on 0.9.1.
Actual
Every attempt rejects with
No provider set:Changing only the SDK version back to 0.9.1, with nothing else touched, restores the same session.
Likely cause
patches/matrix-rust-sdk-ring-provider.patch(commit 4b26856) makes these changes:reqwestfrom therustlsfeature torustls-no-provider.rustlswithdefault-features = false, features = ["ring", …].With
rustls-no-provider, reqwest does not bring a crypto provider. It expects the process-wide default tobe installed already; otherwise
ClientBuilder::build()returns the builder errorNo provider set. Thestring is present in the shipped
android/src/main/jniLibs/arm64-v8a/libmatrix_sdk_ffi.so.The patch changes only
Cargo.toml. As far as we can see, nothing in the bindings or in matrix-rust-sdkcalls
rustls::crypto::CryptoProvider::install_default(). A code search of matrix-rust-sdk findsinstall_defaultonly in crypto x509 code and tests. Upstream matrix-rust-sdk relied on reqwest'sdefault
rustlsfeature to supply aws-lc as the provider.The patch applies to all non-wasm targets, so we expect iOS to be affected in the same way. We have not
built iOS to confirm.
Suggested fix
Install ring as the process default once, before any client is built. Possible places are the FFI
init_platform, the start ofClientBuilder::build, or a small wrapper-side init:(
install_defaultreturnsErrif a provider is already installed, so ignoring the result is safe.)Thanks for the quick 0.10.1 fix for the aws-lc SIGSEGV (matrix-org/matrix-rust-sdk#6442). This looks like
the one missing piece of it.