slint-ui/slint · error
failed to install the rustls crypto provider
Error message
failed to install the rustls crypto provider
What it means
The Figma import CLI registers the `ring` rustls crypto provider at process start because its reqwest build uses rustls without a default provider. `install_default()` returns `Err` if a provider was already installed, and the code panics on that. The error means the process already set up a different `CryptoProvider` (e.g. via the `aws-lc-rs` feature pulled in transitively or a prior `install_default` call) before `main` ran.
Solutions
- Guard the install: ignore `AlreadyInstalled` instead of expecting — `let _ = rustls::crypto::ring::default_provider().install_default();`
- Audit `Cargo.toml` features to ensure no dependency enables rustls' default crypto provider before main runs
- Ensure no other initialization code (or earlier in a shared binary) installs a provider first
- If embedding the tool, move provider installation to your binary's start and remove it from the library path
Example fix
// before
rustls::crypto::ring::default_provider()
.install_default()
.expect("failed to install the rustls crypto provider");
// after
let _ = rustls::crypto::ring::default_provider().install_default(); // ok if already installed Defensive patterns
Strategy: try-catch
Validate before calling
let _ = rustls::crypto::ring::default_provider().install_default(); // ignore AlreadyInstalled
Try / catch
match rustls::crypto::ring::default_provider().install_default() {
Ok(()) | Err(rustls::client::NoInitialClientCert) => {}, // treat any error as already-installed
Err(_) => {},
}
// idiomatic: if let Err(e) = provider.install_default() { log::debug!("provider: {e}"); } Prevention
- Never `.expect()` on install_default — treat 'already installed' as success
- Check cargo feature unification for rustls provider features across dependencies
- Install the provider once, at the earliest point of your binary's entrypoint
When it happens
Trigger: Running the figma_import binary when a rustls crypto provider is already installed process-wide: another dependency with `ring`/`aws-lc-rs` rustls features initialized one first (e.g. through a lazy static, another library's init, or a test harness that shares the process), or the binary itself is invoked twice within the same process.
Common situations: Developers embedding figma_import's main logic into a larger binary or test where reqwest was already used with a provider installed; cargo feature unification pulling in `rustls` with `aws-lc-rs` default provider enabled; running the tool in-process from a plugin.
Related errors
- a setter belongs to a field
- an identifier
- attempt to multiply with overflow
- binding was of the wrong type
- Called a not-implemented method
AI-assisted analysis of slint-ui/slint@bb937076de (2026-09-16).
Data as JSON: /api/errors/6c47e583cc131d39.
Report an issue: GitHub.
Appendix: source
Thrown at tools/figma_import/src/main.rs:111
file.write_all(&(bytes?)).await?;
}
Result::<(), Box<dyn std::error::Error>>::Ok(())
})
.buffer_unordered(8);
while let Some(x) = images.next().await {
x?
}
Ok(r)
}
#[tokio::main]
async fn main() -> Result<(), Box<dyn std::error::Error>> {
// reqwest's rustls is compiled without any crypto provider (see Cargo.toml);
// register ring as the process-wide provider before the first Client is built.
rustls::crypto::ring::default_provider()
.install_default()
.expect("failed to install the rustls crypto provider");
let opt = Opt::parse();
let r = if !opt.read_from_cache {
load_from_network(&opt).await?
} else {
let full_doc = std::fs::read("figma_output/cache.json")?;
serde_json::from_slice(&full_doc)?
};
let mut nodeHash = HashMap::new();
fill_hash(&mut nodeHash, &r.document);
let doc = rendered::Document { nodeHash };
if let figmatypes::Node::DOCUMENT(document) = &r.document
&& let figmatypes::Node::CANVAS { node, prototypeStartNodeID, backgroundColor, .. } =
&document.children[0]
{View on GitHub (pinned to bb937076de)