Repository navigation
[Bug]: GitHub PR sync fails behind TLS-inspecting proxy since nightly 20261006.2752 #16703
Copy link
Copy link
Open
Labels
bugSomething is broken or behaving incorrectly.Something is broken or behaving incorrectly.via-triageFiled through npx t3 triageFiled through npx t3 triage
Description
Activity
- addedbugSomething is broken or behaving incorrectly.Something is broken or behaving incorrectly.needs-triageIssue needs maintainer review and initial categorization.Issue needs maintainer review and initial categorization.
on Oct 7, 2026 Note
Grok responding on behalf of Julius.
Thanks for the careful regression report — the nightly window and stack trace line up with a real change on main.
What we verified
- Between
0.0.46-nightly.20261006.2735and…2752, main picked up the GitHub API stack (feat(server): GitHub API transport that uses gh only for the token #16319 transport, feat(server): pull requests talk to GitHub's API instead of the gh CLI #16320 PR layer, plus feat(server): source control, media and discovery use GitHub's API instead of gh #16321/feat: choose the GitHub account per host, save a GitHub token, and fewer reads per PR action #16322). PR sync now goes through in-processGitHubApi.send→ EffectFetchHttpClient(Nodefetch) instead of shelling out togh. That matches theGitHubApi.send (getPullRequestSummary, POST /graphql)/self-signed certificate in certificate chainfailure you are seeing onPullRequestSyncReactor.sweep. - Desktop still only imports a short allowlist from the login shell (
LOGIN_SHELL_ENV_NAMESinDesktopShellEnvironment.ts) and only forwards a separate allowlist into WSL (WSL_FORWARDED_ENV_NAMESinDesktopBackendConfiguration.ts). Both includeT3CODE_TELEMETRY_ENABLEDafter fix(desktop): honor the telemetry opt-out from the shell profile #16563, but neither includesNODE_EXTRA_CA_CERTS/SSL_CERT_FILE. So a CA path exported in.bashrc/.zshrcnever reaches the desktop-launched WSL server — consistent with your observation and with analytics already failing the same way on 2735 (Nodefetchpath never trusted the proxy CA;ghdid via the OS store). - No open PR found that already fixes this exact TLS-inspecting-proxy / PR-sync failure. Related but not the same: [Bug]: Android app does not trust user-installed CA certificates #5639 (Android user CAs), open fix(server): merge T3-home service.env into the background launcher #12633 (
service.envmerge for the background service launcher — Linux service path, not the Windows→WSL desktop spawn).
Likely fix direction (not committed yet): forward
NODE_EXTRA_CA_CERTS(and possiblySSL_CERT_FILE/NODE_OPTIONSfor--use-system-ca) the same way #16563 did for telemetry, and/or teach the GitHub HTTP client to use the system trust store when the runtime supports it. A dedicated “extra trusted CAs” setting is a longer-term option.Leaving this open as a confirmed regression for Windows desktop + WSL behind TLS-inspecting proxies since the in-process GitHub client landed. Triage labels:
bug,via-triage.- Between
- addedvia-triageFiled through npx t3 triageFiled through npx t3 triageand removedneeds-triageIssue needs maintainer review and initial categorization.Issue needs maintainer review and initial categorization.
on Oct 7, 2026
Metadata
Metadata
Assignees
Labels
bugSomething is broken or behaving incorrectly.Something is broken or behaving incorrectly.via-triageFiled through npx t3 triageFiled through npx t3 triage
Before submitting
Area
apps/server
Steps to reproduce
NODE_EXTRA_CA_CERTSin the WSL shell profile (.bashrc/.zshrc), pointing to the proxy CA certificate.0.0.46-nightly.20261006.2752.openin T3 Code and the thread does not auto-settle. The server trace repeatedly reports the TLS error below.The same setup works with
0.0.46-nightly.20261006.2735.Expected behavior
GitHub PR synchronization succeeds behind the proxy using the configured trusted CA. Linked PRs update to
merged, allowing otherwise eligible threads to auto-settle, as in nightly 2735.Actual behavior
Linked PRs remain
openafter merging on GitHub, preventing automatic thread settlement. Background synchronization repeatedly fails withself-signed certificate in certificate chain.The desktop-launched WSL server does not have
NODE_EXTRA_CA_CERTSin its environment, despite the variable being exported in the WSL shell profile.A separate Node
fetchtest againsthttps://api.github.comsucceeds whenNODE_EXTRA_CA_CERTSis supplied and fails with the certificate error when it is absent.Likely cause
#16319 / #16320 moved GitHub PR operations from the
ghCLI to in-process HTTP requests. In this environment,ghaccepts the proxy CA through the OS trust store, while the new Node request path does not trust it under the desktop server's launch configuration.This is consistent with the version regression and the controlled
fetchtest, but the specific introducing change has not been bisected.Possible fixes
--use-system-cawhere supported by the server runtime.NODE_EXTRA_CA_CERTSwhen starting the desktop/WSL server, using fix(desktop): honor the telemetry opt-out from the shell profile #16563's telemetry environment-variable handling as a precedent. ConsiderSSL_CERT_FILEwhere applicable.Impact
Minor bug or occasional failure
Version or commit
0.0.46-nightly.20261006.2752
Environment
Windows 11 desktop app with a WSL 3 runtime, behind a corporate TLS-inspecting proxy. The proxy's root CA is installed in the WSL system trust store.
NODE_EXTRA_CA_CERTSis exported in the WSL shell profile (.bashrc/.zshrc).Logs or stack traces
PullRequestSyncReactor.sweep: pull request sync skipped reason: Pull request operation summary failed: Could not reach GitHub at github.com. GitHubApi.send (getPullRequestSummary, POST /graphql) HttpClientError: Transport error (POST https://api.github.com/graphql) TypeError: fetch failed Error: self-signed certificate in certificate chainAdditional observation: anonymous usage-data uploads through
AnalyticsService.sendBatchfail with the same certificate error on nightly 2735 as well. That failure predates this PR-sync regression.Screenshots, recordings, or supporting files
No response
Workaround
Nightly
0.0.46-nightly.20261006.2735works in the same environment.Supplying
NODE_EXTRA_CA_CERTSfixes the standalone Nodefetchtest, but exporting it in the WSL shell profile does not reach the desktop-launched server. A workaround for the desktop launch on nightly 2752 has not been verified.