Skip to content

fix: install ring as the default rustls provider - #62

Merged
WeissDev merged 1 commit into
mainfrom
fix/no-provider-set
Sep 30, 2026
Merged

WeissDev merged 1 commit into
mainfrom
fix/no-provider-set

Conversation

@WeissDev

Copy link
Copy Markdown
Member

No description provided.

@mkarimv

mkarimv commented Sep 29, 2026

Copy link
Copy Markdown

Thanks, confirmed on our end.

  • Host repro, red → green (rev 1c44fb66): a minimal binary that only calls matrix_sdk::Client::builder().homeserver_url(..).build() panics in reqwest 0.13.5 ("No rustls crypto provider is configured") with the current patch, and builds the client with fix: install ring as the default rustls provider #62's native.rs hunk.
  • Coverage: HttpSettings::make_client is the only non-test place a reqwest::Client is built (the FFI only uses reqwest::Certificate), and the install also runs before the Android WebPkiServerVerifier builder.
  • Android device (Galaxy S23 FE, Android 15): I built matrix-sdk-ffi for arm64-v8a with the full patch (ring only, no aws-lc-rs; exported FFI symbols identical to the published 0.10.1 lib) and swapped it into 0.10.1 in our app. Cold-start restore of an existing session — the case that failed in 0.10.1: every HTTP request fails with "No provider set" (ring patch installs no rustls CryptoProvider) #61 — now works: sliding sync, /versions, profile and keys/query all 200, no "No provider set".

Not tested: iOS, and a full ubrn package build (I swapped the .so only). Happy to re-check the release build on device once it's out.

@WeissDev
WeissDev merged commit 6cc5cc7 into main Sep 30, 2026
4 checks passed
@vb1704

vb1704 commented Sep 30, 2026

Copy link
Copy Markdown

Following up on #63 as promised: we tested the published 0.10.2 release (prebuilt binaries, no local build) and it works for us on both platforms.

Setup: React Native 0.84 (New Architecture, Hermes), Android 16 on a physical arm64-v8a device, and an iOS 26.2 simulator.

On both platforms, these all worked against a Synapse homeserver with sliding sync:

  • building the client and restoring an existing session
  • sync service with the room list (native sliding sync)
  • encryption().recover() with a recovery key
  • timeline pagination with decryption
  • room.sendRaw() with a custom msgtype, read correctly by another client
  • timeline.sendFile() for an encrypted attachment

There's no crash on the first HTTPS request (the aws-lc issue we saw on 0.10.0) and no "No provider set" (#61). The Android .so contains no aws-lc code. Thanks for the quick fix and release!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants