{"record":{"id":"6c47e583cc131d39","repo":"slint-ui/slint","slug":"failed-to-install-the-rustls-crypto-provider","errorCode":null,"errorMessage":"failed to install the rustls crypto provider","messagePattern":"failed to install the rustls crypto provider","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"tools/figma_import/src/main.rs","lineNumber":111,"sourceCode":"                file.write_all(&(bytes?)).await?;\n            }\n            Result::<(), Box<dyn std::error::Error>>::Ok(())\n        })\n        .buffer_unordered(8);\n    while let Some(x) = images.next().await {\n        x?\n    }\n\n    Ok(r)\n}\n\n#[tokio::main]\nasync fn main() -> Result<(), Box<dyn std::error::Error>> {\n    // reqwest's rustls is compiled without any crypto provider (see Cargo.toml);\n    // register ring as the process-wide provider before the first Client is built.\n    rustls::crypto::ring::default_provider()\n        .install_default()\n        .expect(\"failed to install the rustls crypto provider\");\n\n    let opt = Opt::parse();\n\n    let r = if !opt.read_from_cache {\n        load_from_network(&opt).await?\n    } else {\n        let full_doc = std::fs::read(\"figma_output/cache.json\")?;\n        serde_json::from_slice(&full_doc)?\n    };\n\n    let mut nodeHash = HashMap::new();\n    fill_hash(&mut nodeHash, &r.document);\n    let doc = rendered::Document { nodeHash };\n\n    if let figmatypes::Node::DOCUMENT(document) = &r.document\n        && let figmatypes::Node::CANVAS { node, prototypeStartNodeID, backgroundColor, .. } =\n            &document.children[0]\n    {","sourceCodeStart":93,"sourceCodeEnd":129,"githubUrl":"https://github.com/slint-ui/slint/blob/bb937076de3f7919766c1f25e2e969367cf77e9a/tools/figma_import/src/main.rs#L93-L129","documentation":"The Figma import CLI registers the `ring` rustls crypto provider at process start because its reqwest build uses rustls without a default provider. `install_default()` returns `Err` if a provider was already installed, and the code panics on that. The error means the process already set up a different `CryptoProvider` (e.g. via the `aws-lc-rs` feature pulled in transitively or a prior `install_default` call) before `main` ran.","triggerScenarios":"Running the figma_import binary when a rustls crypto provider is already installed process-wide: another dependency with `ring`/`aws-lc-rs` rustls features initialized one first (e.g. through a lazy static, another library's init, or a test harness that shares the process), or the binary itself is invoked twice within the same process.","commonSituations":"Developers embedding figma_import's main logic into a larger binary or test where reqwest was already used with a provider installed; cargo feature unification pulling in `rustls` with `aws-lc-rs` default provider enabled; running the tool in-process from a plugin.","solutions":["Guard the install: ignore `AlreadyInstalled` instead of expecting — `let _ = rustls::crypto::ring::default_provider().install_default();`","Audit `Cargo.toml` features to ensure no dependency enables rustls' default crypto provider before main runs","Ensure no other initialization code (or earlier in a shared binary) installs a provider first","If embedding the tool, move provider installation to your binary's start and remove it from the library path"],"exampleFix":"// before\nrustls::crypto::ring::default_provider()\n    .install_default()\n    .expect(\"failed to install the rustls crypto provider\");\n// after\nlet _ = rustls::crypto::ring::default_provider().install_default(); // ok if already installed","handlingStrategy":"try-catch","validationCode":"let _ = rustls::crypto::ring::default_provider().install_default(); // ignore AlreadyInstalled","typeGuard":null,"tryCatchPattern":"match rustls::crypto::ring::default_provider().install_default() {\n    Ok(()) | Err(rustls::client::NoInitialClientCert) => {}, // treat any error as already-installed\n    Err(_) => {},\n}\n// idiomatic: if let Err(e) = provider.install_default() { log::debug!(\"provider: {e}\"); }","preventionTips":["Never `.expect()` on install_default — treat 'already installed' as success","Check cargo feature unification for rustls provider features across dependencies","Install the provider once, at the earliest point of your binary's entrypoint"],"tags":["rust","tls","rustls","crypto","cli"],"backgroundTag":"module-init-failed","analyzedSha":"bb937076de3f7919766c1f25e2e969367cf77e9a","analyzedAt":"2026-09-16T01:37:20.251Z","contentChangedAt":"2026-09-16T01:37:20.251Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}