Repository navigation
Conversation
There was a problem hiding this comment.
🤖 AI Review
Both independent reviews were available. Confirmed the privilege-drop edge case and the missing process-wiring test. The libcurl finding remains uncertain because the bundled extensions, library configuration, and startup wrapper are unavailable in this checkout. All three findings are preserved; none overlap.
Findings
| Severity | Location | Category | Sources | Claim |
|---|---|---|---|---|
| 🟠 MAJOR | packages/stack/src/services/Database.ts:438 |
correctness |
codex | Setting SSL_CERT_FILE or SSL_CERT_DIR does not fix HTTPS verification in http and pg_net when their libcurl uses a compiled-in CA bundle path. |
| 🟡 MINOR | packages/stack/src/services/Database.ts:429 |
correctness |
claude | Exported SSL_CERT_FILE or SSL_CERT_DIR paths bypass the system-bundle fallback without checking whether the lower-privilege PostgreSQL user can access them. |
| ⚪ NIT | packages/stack/src/services/Database.unit.test.ts:24 |
test-coverage |
claude | The new tests exercise nativeTrustStore only in isolation and would still pass if its result stopped being forwarded to native PostgreSQL. |
Stats
Claude findings: 2 · Codex findings: 1 · Confirmed: 2 · Refuted: 0 · Uncertain: 1
Models: claude-opus-5-5 + gpt-6.1-sol · Trigger: auto · Workflow run
This review runs once per PR. A maintainer can request another with a /ai-review comment.
jgoux
left a comment
There was a problem hiding this comment.
Thanks for tracking this down. Passing the CA settings to native PostgreSQL is the right fix. Comments are inline: the main one asks for coverage at the real boundary; the other two are smaller edge cases.
…ostgres-http-pg_net-fails
…ostgres-http-pg_net-fails
jgoux
left a comment
There was a problem hiding this comment.
Forwarding the host trust store to native postgres is correct, the native integration test proves http and pg_net verify against the forwarded CA, and all earlier feedback is addressed. Two small follow-ups below.
TL;DR
fixes https requests from
httpandpg_netfailing certificate verification on the native runtime on macOS arm64.whats broken?
the OpenSSL bundled with native postgres looks for its CA bundle under
/nix, which a macOS host does not have, sohttp_getto an https url failed withunable to get local issuer certificate.the native launcher also kept a host
SSL_CERT_FILEaway from postgres, so exporting one did not help.now fixed by:
the native postgres launch now forwards an exported
SSL_CERT_FILEandSSL_CERT_DIR, and whenSSL_CERT_FILEis not exported it uses the first CA bundle on the host,/etc/ssl/cert.pemon macOS.ref: