Skip to content

chore(common)!: replace native-certs with platform-verifier#2078

Merged
gh-worker-dd-mergequeue-cf854d[bot] merged 5 commits into
mainfrom
vianney/use-platform-verifier
Jun 18, 2026
Merged

chore(common)!: replace native-certs with platform-verifier#2078
gh-worker-dd-mergequeue-cf854d[bot] merged 5 commits into
mainfrom
vianney/use-platform-verifier

Conversation

@VianneyRuhlmann

Copy link
Copy Markdown
Contributor

What does this PR do?

Replace rustls-native-certs with rustls-platform-verifier as recommended in rustls-native-certs.

Motivation

Potential fix to a crash in dd-trace-py on macos

Additional Notes

Anything else we should know when reviewing?

How to test the change?

Describe here in detail how the change can be validated.

@github-actions github-actions Bot added the common label Jun 4, 2026
@VianneyRuhlmann
VianneyRuhlmann force-pushed the vianney/use-platform-verifier branch from ff9b666 to 4b2028f Compare June 4, 2026 12:08
@github-actions

github-actions Bot commented Jun 4, 2026

Copy link
Copy Markdown
Contributor

Clippy Allow Annotation Report

Comparing clippy allow annotations between branches:

  • Base Branch: origin/main
  • PR Branch: origin/vianney/use-platform-verifier

Summary by Rule

Rule Base Branch PR Branch Change

Annotation Counts by File

File Base Branch PR Branch Change

Annotation Stats by Crate

Crate Base Branch PR Branch Change
clippy-annotation-reporter 5 5 No change (0%)
datadog-ffe-ffi 1 1 No change (0%)
datadog-ipc 22 21 ✅ -1 (-4.5%)
datadog-live-debugger 4 4 No change (0%)
datadog-live-debugger-ffi 10 10 No change (0%)
datadog-profiling-replayer 4 4 No change (0%)
datadog-sidecar 45 45 No change (0%)
libdd-common 13 13 No change (0%)
libdd-common-ffi 12 12 No change (0%)
libdd-data-pipeline 5 5 No change (0%)
libdd-ddsketch 2 2 No change (0%)
libdd-dogstatsd-client 1 1 No change (0%)
libdd-profiling 13 13 No change (0%)
libdd-remote-config 3 3 No change (0%)
libdd-telemetry 20 20 No change (0%)
libdd-tinybytes 4 4 No change (0%)
libdd-trace-normalization 2 2 No change (0%)
libdd-trace-obfuscation 3 3 No change (0%)
libdd-trace-stats 1 1 No change (0%)
libdd-trace-utils 11 11 No change (0%)
Total 181 180 ✅ -1 (-0.6%)

About This Report

This report tracks Clippy allow annotations for specific rules, showing how they've changed in this PR. Decreasing the number of these annotations generally improves code quality.

@datadog-datadog-prod-us1-2

datadog-datadog-prod-us1-2 Bot commented Jun 4, 2026

Copy link
Copy Markdown

Tests

🎉 All green!

🧪 All tests passed
❄️ No new flaky tests detected

🎯 Code Coverage (details)
Patch Coverage: 100.00%
Overall Coverage: 73.81% (-0.01%)

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: bf25811 | Docs | Datadog PR Page | Give us feedback!

@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 73.47%. Comparing base (48da0d8) to head (4b2028f).

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #2078      +/-   ##
==========================================
- Coverage   73.50%   73.47%   -0.03%     
==========================================
  Files         470      470              
  Lines       78398    78398              
==========================================
- Hits        57624    57602      -22     
- Misses      20774    20796      +22     
Components Coverage Δ
libdd-crashtracker 65.47% <ø> (ø)
libdd-crashtracker-ffi 37.68% <ø> (ø)
libdd-agent-client 83.79% <ø> (ø)
libdd-alloc 98.77% <ø> (ø)
libdd-data-pipeline 86.96% <ø> (-0.17%) ⬇️
libdd-data-pipeline-ffi 76.17% <ø> (-0.87%) ⬇️
libdd-common 79.89% <ø> (ø)
libdd-common-ffi 74.41% <ø> (ø)
libdd-telemetry 73.37% <ø> (+0.02%) ⬆️
libdd-telemetry-ffi 31.36% <ø> (ø)
libdd-dogstatsd-client 82.64% <ø> (ø)
datadog-ipc 76.22% <ø> (ø)
libdd-profiling 81.69% <ø> (-0.03%) ⬇️
libdd-profiling-ffi 64.79% <ø> (ø)
libdd-sampling 97.41% <ø> (ø)
datadog-sidecar 34.51% <ø> (-0.11%) ⬇️
datdog-sidecar-ffi 8.14% <ø> (-0.48%) ⬇️
spawn-worker 48.86% <ø> (ø)
libdd-tinybytes 93.80% <ø> (ø)
libdd-trace-normalization 81.71% <ø> (ø)
libdd-trace-obfuscation 87.30% <ø> (ø)
libdd-trace-protobuf 68.25% <ø> (ø)
libdd-trace-utils 89.29% <ø> (ø)
libdd-tracer-flare 86.88% <ø> (ø)
libdd-log 74.83% <ø> (ø)
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@dd-octo-sts

dd-octo-sts Bot commented Jun 4, 2026

Copy link
Copy Markdown
Contributor

Artifact Size Benchmark Report

aarch64-alpine-linux-musl
Artifact Baseline Commit Change
/aarch64-alpine-linux-musl/lib/libdatadog_profiling.so 7.76 MB 7.76 MB 0% (0 B) 👌
/aarch64-alpine-linux-musl/lib/libdatadog_profiling.a 84.02 MB 83.99 MB --.04% (-35.03 KB) 💪
aarch64-unknown-linux-gnu
Artifact Baseline Commit Change
/aarch64-unknown-linux-gnu/lib/libdatadog_profiling.so 10.36 MB 10.36 MB --.01% (-2.03 KB) 💪
/aarch64-unknown-linux-gnu/lib/libdatadog_profiling.a 95.12 MB 95.08 MB --.05% (-49.57 KB) 💪
libdatadog-x64-windows
Artifact Baseline Commit Change
/libdatadog-x64-windows/debug/dynamic/datadog_profiling_ffi.dll 24.93 MB 24.82 MB --.43% (-111.50 KB) 💪
/libdatadog-x64-windows/debug/dynamic/datadog_profiling_ffi.lib 87.33 KB 87.33 KB 0% (0 B) 👌
/libdatadog-x64-windows/debug/dynamic/datadog_profiling_ffi.pdb 181.50 MB 180.84 MB --.36% (-672.00 KB) 💪
/libdatadog-x64-windows/debug/static/datadog_profiling_ffi.lib 927.98 MB 927.95 MB -0% (-31.81 KB) 👌
/libdatadog-x64-windows/release/dynamic/datadog_profiling_ffi.dll 8.12 MB 8.10 MB --.32% (-27.00 KB) 💪
/libdatadog-x64-windows/release/dynamic/datadog_profiling_ffi.lib 87.33 KB 87.33 KB 0% (0 B) 👌
/libdatadog-x64-windows/release/dynamic/datadog_profiling_ffi.pdb 24.03 MB 23.96 MB --.29% (-72.00 KB) 💪
/libdatadog-x64-windows/release/static/datadog_profiling_ffi.lib 47.96 MB 47.83 MB --.27% (-137.04 KB) 💪
libdatadog-x86-windows
Artifact Baseline Commit Change
/libdatadog-x86-windows/debug/dynamic/datadog_profiling_ffi.dll 21.62 MB 21.51 MB --.48% (-107.00 KB) 💪
/libdatadog-x86-windows/debug/dynamic/datadog_profiling_ffi.lib 88.71 KB 88.71 KB 0% (0 B) 👌
/libdatadog-x86-windows/debug/dynamic/datadog_profiling_ffi.pdb 185.59 MB 184.79 MB --.43% (-824.00 KB) 💪
/libdatadog-x86-windows/debug/static/datadog_profiling_ffi.lib 921.12 MB 916.17 MB --.53% (-4.95 MB) 💪
/libdatadog-x86-windows/release/dynamic/datadog_profiling_ffi.dll 6.27 MB 6.25 MB --.26% (-17.00 KB) 💪
/libdatadog-x86-windows/release/dynamic/datadog_profiling_ffi.lib 88.71 KB 88.71 KB 0% (0 B) 👌
/libdatadog-x86-windows/release/dynamic/datadog_profiling_ffi.pdb 25.76 MB 25.69 MB --.27% (-72.00 KB) 💪
/libdatadog-x86-windows/release/static/datadog_profiling_ffi.lib 45.59 MB 45.47 MB --.25% (-119.25 KB) 💪
x86_64-alpine-linux-musl
Artifact Baseline Commit Change
/x86_64-alpine-linux-musl/lib/libdatadog_profiling.a 74.91 MB 74.87 MB --.05% (-41.92 KB) 💪
/x86_64-alpine-linux-musl/lib/libdatadog_profiling.so 8.61 MB 8.61 MB --.09% (-8.00 KB) 💪
x86_64-unknown-linux-gnu
Artifact Baseline Commit Change
/x86_64-unknown-linux-gnu/lib/libdatadog_profiling.a 90.33 MB 90.29 MB --.04% (-44.06 KB) 💪
/x86_64-unknown-linux-gnu/lib/libdatadog_profiling.so 10.48 MB 10.47 MB --.04% (-4.87 KB) 💪

@VianneyRuhlmann
VianneyRuhlmann force-pushed the vianney/use-platform-verifier branch from 4b2028f to 7a32a06 Compare June 10, 2026 14:11
@VianneyRuhlmann VianneyRuhlmann changed the title chore(common): replace native-certs with platform-verifier chore(common)!: replace native-certs with platform-verifier Jun 11, 2026
@VianneyRuhlmann
VianneyRuhlmann marked this pull request as ready for review June 11, 2026 16:20
@VianneyRuhlmann
VianneyRuhlmann requested a review from a team as a code owner June 11, 2026 16:20

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3078c4dc4d

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread libdd-common/Cargo.toml
@ivoanjo

ivoanjo commented Jun 11, 2026

Copy link
Copy Markdown
Member

Can you share a bit more on info on why we're doing this migration and why it is safe? Just to make sure I understand what changes here, as getting this wrong means customers not getting data (e.g. because some TLS connections fail due to missing certificates).

@VianneyRuhlmann

Copy link
Copy Markdown
Contributor Author

The main reason I'm trying to do it now is because it makes loading the certificate lazy on macos. This helps mitigating a bug in dd-trace-py due to the macos Security.framework api not being thread safe.
Still this is recommended by the rustls project to replace native-certs and is already used in profiling. It's still using native-certs under the hood for linux so behavior should stay the same.
That being said I'm not very familiar with the tls logic of ddcommon, so I'd appreciate any feedback you have.

@ivoanjo

ivoanjo commented Jun 12, 2026

Copy link
Copy Markdown
Member

That being said I'm not very familiar with the tls logic of ddcommon, so I'd appreciate any feedback you have.

I'm not very familiar with it either, which is why I was kinda pointing out that getting this wrong can have a very high cost (ask me how I know.... #1796 / DataDog/dd-trace-rb#5508 ) so it's worth being very careful with changes here.

@paullegranddc paullegranddc left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you test that https still works with either fips and normal https on linux?

let certs = load_root_certs()?;
let client_config = ClientConfig::builder()
.with_root_certificates(certs)
.with_platform_verifier()?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this will potentially change behavior for macOS and Windows users who use SSL_CERT_FILE and SSL_CERT_DIR? If a user is using a custom CA here it won't pick them up. This might be ok, since I don't think it's common for Windows to set this (worth checking with someone from .NET), and most macOS usage is for local dev, so the agent would be on localhost anyway and not using https?

At a minimum, it's worth verifying and documenting.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've checked with the dotnet guild and we don't support it (actually dotnet themselves refused to add support). Since profiling already switched to platform-verifier for the reqwest client I think it's fine to move on.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I agree, this isn't sustainable. I'll create a jira ticket to look into this deeper.

@ekump

ekump commented Jun 17, 2026

Copy link
Copy Markdown
Collaborator

Can you test that https still works with either fips and normal https on linux?

@paullegranddc @VianneyRuhlmann - I think it should work ok, and also shouldn't pull in ring as a dep. But, it's worth testing as Paul suggests. Since it's fips we'll need a separate step that has --no-default-features --features fips flags set.

roots.add(cert).ok();
}
if roots.is_empty() {
return Err(errors::Error::NoValidCertifacteRootsFound.into());

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can / should we remove this error type? It doesn't look like it's used anywhere anymore.

@ekump ekump left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not an area I'm an expert in, but looks reasonable. Let's just add some tests. Otherwise LGTM.

@VianneyRuhlmann
VianneyRuhlmann force-pushed the vianney/use-platform-verifier branch from 3078c4d to 287da1c Compare June 18, 2026 11:14
@VianneyRuhlmann
VianneyRuhlmann requested a review from a team as a code owner June 18, 2026 12:33
@gh-worker-dd-mergequeue-cf854d
gh-worker-dd-mergequeue-cf854d Bot merged commit 59db709 into main Jun 18, 2026
112 checks passed
@gh-worker-dd-mergequeue-cf854d
gh-worker-dd-mergequeue-cf854d Bot deleted the vianney/use-platform-verifier branch June 18, 2026 14:07
iunanua added a commit that referenced this pull request Jun 19, 2026
# Release proposal for libdd-remote-config and its dependencies

This PR contains version bumps based on public API changes and commits
since last release.

## libdd-common
**Next version:** `5.0.0`
**Semver bump:** `major`
**Tag:** `libdd-common-v5.0.0`

### Commits

- chore(profiling): Use SECURITY_ANONYMOUS when connecting to named pipe
server (#2134)
- fix: Fix http PathAndQuery Uri Parsing (#2122)
- chore(common)!: replace native-certs with platform-verifier (#2078)
- feat(data-pipeline)!: CSS Trace Filters (#1985)
- fix(libdd-common): Add fallback logic for resolving Azure Functions
instance name [SVLS-8931] (#2077)
- test: fix timeouts on heavily contended scenarios (#2093)

## libdd-remote-config
**Next version:** `1.0.0`
**Semver bump:** `major`
**Tag:** `libdd-remote-config-v1.0.0`

**Warning:** this is an initial release. Please verify that the version
and commits included are correct.

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: iunanua <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants