Skip to content

fix(packaged): forward NODE_EXTRA_CA_CERTS to sidecars - #8559

Draft
leorivastech wants to merge 1 commit into
nexu-io:mainfrom
leorivastech:fix/8157-forward-extra-ca-certs
Draft

leorivastech wants to merge 1 commit into
nexu-io:mainfrom
leorivastech:fix/8157-forward-extra-ca-certs

Conversation

@leorivastech

Copy link
Copy Markdown
Contributor

Fixes #8157

Why

Behind a TLS-inspecting proxy (Cato in the report), every BYOK "Fetch models" and "Test" request in the desktop app fails with SELF_SIGNED_CERT_IN_CHAIN, even when the app is launched with NODE_EXTRA_CA_CERTS pointing at the corporate root CA. As @lefarcen found in the issue, the packaged app builds the daemon's environment from an allowlist, and NODE_EXTRA_CA_CERTS wasn't on it. So the daemon, which is what makes those requests, never got the CA bundle. #6802 fixed the same handoff for OD_ALLOWED_INTERNAL_HOSTS.

What users will see

If the app is started with NODE_EXTRA_CA_CERTS set, BYOK model discovery and the connection test trust that CA on top of the normal ones. Nothing changes for anyone who doesn't set it.

On macOS, apps opened from Finder don't get your shell's variables, so it has to be set for the session first, for example launchctl setenv NODE_EXTRA_CA_CERTS /path/to/corp-ca.pem and then open the app, or run the binary from a terminal with the variable set.

Surface area

  • CLI / env var: the packaged app now passes the standard Node NODE_EXTRA_CA_CERTS to its sidecars. No new OD_* variable.

Screenshots

No UI change.

Bug fix verification

  • Test: apps/packaged/tests/sidecars.test.ts, "forwards NODE_EXTRA_CA_CERTS to the daemon without forwarding TLS or runtime overrides". It calls resolvePackagedChildBaseEnv with the same arguments the daemon spawn uses.
  • Red on main, green here: yes. A second test checks that an empty value isn't forwarded; that one already passes on main and is just a guard.

This only adds a CA bundle. Verification stays on: NODE_TLS_REJECT_UNAUTHORIZED and NODE_OPTIONS are still dropped, and the test checks that. --use-system-ca is left out, like the issue says.

I also checked the runtime by hand, since on macOS and Windows the daemon runs as Electron in run-as-node mode. With Electron 41.3.0 and a local HTTPS server signed by a throwaway CA, fetch and an undici Agent failed with UNABLE_TO_VERIFY_LEAF_SIGNATURE without the variable and returned 200 with it, including with a path that has spaces. Setting it after startup didn't help, so it has to be in the spawn env, which is what this does. A missing file only prints a Node warning and the daemon keeps running. On Linux the daemon runs on the bundled Node, which reads the variable the same way.

Validation

  • pnpm --filter @open-design/packaged test (24 files, 356 tests)
  • pnpm typecheck
  • pnpm guard

The packaged daemon is spawned with an allowlisted environment, so an
extra CA bundle set for the app never reached the process that makes
BYOK model-discovery and connection-test requests. Behind a
TLS-inspecting proxy those requests failed with SELF_SIGNED_CERT_IN_CHAIN.

Forward NODE_EXTRA_CA_CERTS only. Certificate verification stays on;
NODE_OPTIONS and NODE_TLS_REJECT_UNAUTHORIZED are still dropped.

Fixes nexu-io#8157
@leorivastech
leorivastech requested a review from a team as a code owner October 1, 2026 17:10
@lefarcen lefarcen added risk/high High risk: apps/desktop, daemon, auth, migration, workflows, package deps size/S PR changes 20-100 lines type/bugfix Bug fix labels Oct 1, 2026
@lefarcen

lefarcen commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Thanks @leorivastech — the narrow allowlist change and focused regression coverage make the intent easy to follow. I've routed this to a reviewer.

@lefarcen
lefarcen requested a review from nettee October 1, 2026 17:14
@lefarcen lefarcen added the needs-validation Runtime change detected; needs human or /explore agent validation. label Oct 1, 2026
@lefarcen

lefarcen commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

This change affects BYOK model discovery and connection testing, so it is queued for QA validation before merge. Nothing is needed from you right now; we’ll update the PR once validation is complete.

@leorivastech

Copy link
Copy Markdown
Contributor Author

Thanks @lefarcen!

@nettee nettee left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@leorivastech

This correctly forwards NODE_EXTRA_CA_CERTS through the packaged child allowlist, so the daemon receives an explicitly configured corporate CA bundle while unsafe TLS and runtime overrides remain excluded. I traced the resolver through the daemon spawn path and reviewed the focused regression coverage. Thanks for keeping this compatibility fix narrow and well-covered.

🔁 Powered by Looper · runner=reviewer · agent=codex · An autonomous AI dev team for your GitHub repos.

@lefarcen
lefarcen requested a review from AmyShang-alt October 2, 2026 04:11
@lefarcen
lefarcen marked this pull request as draft October 4, 2026 17:51

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-validation Runtime change detected; needs human or /explore agent validation. risk/high High risk: apps/desktop, daemon, auth, migration, workflows, package deps size/S PR changes 20-100 lines type/bugfix Bug fix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: BYOK provider requests fail with SELF_SIGNED_CERT_IN_CHAIN behind corporate TLS inspection; app ignores NODE_EXTRA_CA_CERTS

3 participants