Skip to content

How to work with ncrypto? #7

Description

@panva

How is the workflow of making changes to node:crypto or WebCryptoAPI supposed to work now?

I've had branches ready to go that are now invalid with ncrypto being in place (i'm revisiting some many months old work)

  • How are updates to ncrypto propagated to nodejs/node?
  • What is the release process like? Who controls it?
  • Given I need to make changes to ncrypto as well as node's src & lib how am I to proceed?

Activity

  1. panva commented on Mar 2, 2025

    @panva
    MemberAuthor

    cc @jasnell @anonrig @codebytere as the currently only contributors in the commit list

  2. jasnell commented on Mar 2, 2025

    @jasnell
    Member

    Within the next day or two I'll have a PR that switches the deps/ncrypto to the one that is in the repo along with integrating it into the update deps. Between now and then, opening PRs against the one in deps/ncrypto is fine and I'll open the corresponding PR ni the ncrypto repo.

    Overall, however, I've been thinking we need a nodejs/ncrypto team to manage the longer term changes in ncrypto.

  3. panva commented on Mar 2, 2025

    @panva
    MemberAuthor

    I'm at a loss trying to reconcile with the added hurdle in having to work on different repos, waiting for deps PRs and only then working on node:crypto or node's WebCryptoAPI. I don't see many (if any) benefits for the nodejs project here. I understand the benefits of ncrypto for other runtimes tho, so wouldn't a process where nodejs/ncrypto is capturing snapshots of nodejs/node deps/ncrypto when node is released be more efficient?

  4. panva commented on Mar 2, 2025

    @panva
    MemberAuthor

    Not to mention that any changes made to ncrypto do not get tested with the massive crypto test suite and WPTs of nodejs/node until a deps update PR is opened. There's even no way to test work in progress in CI.

    As such I think switching ncrypto to be a full blown dependency is still a long way off. Setting up a process where nodejs/node latest releases get pulled to and tagged in nodejs/ncrypto seems more appropriate to me given current state of affairs.

  5. jasnell commented on Mar 2, 2025

    @jasnell
    Member

    As I suggested, making your edits in the deps/ncrypto directory under the node repo is appropriate for the time being.

  6. panva commented on Mar 2, 2025

    @panva
    MemberAuthor

    @jasnell It's exactly because your timeline is the next day or two that I raise my concerns. nodejs/ncrypto related workflows after said switch are not set up for healthy, welcoming, and hurdle-free contributions to the nodejs/node project.

  7. anonrig commented on Mar 2, 2025

    @anonrig
    Member

    @panva I'm working on adding a GitHub workflow to ncrypto to run nodejs test suite on every pr to ncrypto.

  8. mhdawson commented on Mar 5, 2025

    @mhdawson
    Member

    @jasnell, just to confirm, I assume you are planning an updater in https://github.com/nodejs/node/tree/main/tools/dep_updaters like we have for all other dependencies to do the updates ?

  9. jasnell commented on Mar 5, 2025

    @jasnell
    Member

    Yep

  10. ranisalt commented on Mar 20, 2025

    @ranisalt
    Contributor

    I'm curious why the choice for Bazel here, so far I'm finding it a massive pain to understand and use, and ncrypto is using workspaces which is an already deprecated, scheduled for removal feature, dead on arrival 😞

    Could something like CMake+vcpkg or meson be used instead, with better support and more developers with experience to contribute?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions