feat: wss for the realtime connection with a local CA bundle #3
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/ota-wss"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
wss for the realtime connection, with a local CA bundle
Implements the communicator-sailfish side of the OTA design
(
starfleet/crew:docs/specs/2026-09-10-ota-design.md, §8) — plan 4 of 4(crew, computer, communicator-esp32, communicator-sailfish).
The realtime WebSocket moves from plaintext
ws://towss://, validatedagainst the same local CA the other Starfleet clients pin (the crew/computer
TLS cutover, spec §10).
What this adds
qml/py/backend.py): the backend resolves a CA bundlefrom
STARFLEET_CA_BUNDLE, else a CA shipped in app resources atqml/py/starfleet-ca.pem; when a CA is present it connectswss://withssl.create_default_context(cafile=...)(hostname verification left on).When no CA is configured it stays plaintext
ws://— the dev default.that fails to load, surfaces a
connect_errorand aborts instead offalling back to plaintext.
INSTALLSrule (src/src.pro) shipsqml/py/starfleet-ca.pemwhen present, so release RPMs carry the trustanchor while CA-less dev builds still build. The real CA is rollout
material and is gitignored.
wss://handshakes — a cert signed bythe test CA is accepted, an untrusted cert is rejected (test keys generated
at test time; only a public cert is committed).
Note on branch contents
feat/ota-wsswas branched frommain, which carried one pre-existingunpushed commit unrelated to OTA —
abf3d07 fix: keep reconnecting after server restart instead of giving up(which is why the test baseline grewfrom 26 to 27). That commit is included in this PR.
Follow-ups
AGENTS.mdstill records the pre-change test count (30); the suite is now35.
now pins that, but a stray real
qml/py/starfleet-ca.pemon a dev machinewill still switch the singleton to
wss://.