slint-ui/slint · error

failed to install the rustls crypto provider

Error message

failed to install the rustls crypto provider

What it means

The Figma import CLI registers the `ring` rustls crypto provider at process start because its reqwest build uses rustls without a default provider. `install_default()` returns `Err` if a provider was already installed, and the code panics on that. The error means the process already set up a different `CryptoProvider` (e.g. via the `aws-lc-rs` feature pulled in transitively or a prior `install_default` call) before `main` ran.

Solutions

  1. Guard the install: ignore `AlreadyInstalled` instead of expecting — `let _ = rustls::crypto::ring::default_provider().install_default();`
  2. Audit `Cargo.toml` features to ensure no dependency enables rustls' default crypto provider before main runs
  3. Ensure no other initialization code (or earlier in a shared binary) installs a provider first
  4. If embedding the tool, move provider installation to your binary's start and remove it from the library path

Example fix

// before
rustls::crypto::ring::default_provider()
    .install_default()
    .expect("failed to install the rustls crypto provider");
// after
let _ = rustls::crypto::ring::default_provider().install_default(); // ok if already installed
Defensive patterns

Strategy: try-catch

Validate before calling

let _ = rustls::crypto::ring::default_provider().install_default(); // ignore AlreadyInstalled

Try / catch

match rustls::crypto::ring::default_provider().install_default() {
    Ok(()) | Err(rustls::client::NoInitialClientCert) => {}, // treat any error as already-installed
    Err(_) => {},
}
// idiomatic: if let Err(e) = provider.install_default() { log::debug!("provider: {e}"); }

Prevention

When it happens

Trigger: Running the figma_import binary when a rustls crypto provider is already installed process-wide: another dependency with `ring`/`aws-lc-rs` rustls features initialized one first (e.g. through a lazy static, another library's init, or a test harness that shares the process), or the binary itself is invoked twice within the same process.

Common situations: Developers embedding figma_import's main logic into a larger binary or test where reqwest was already used with a provider installed; cargo feature unification pulling in `rustls` with `aws-lc-rs` default provider enabled; running the tool in-process from a plugin.

Related errors


AI-assisted analysis of slint-ui/slint@bb937076de (2026-09-16). Data as JSON: /api/errors/6c47e583cc131d39. Report an issue: GitHub.

Appendix: source

Thrown at tools/figma_import/src/main.rs:111

                file.write_all(&(bytes?)).await?;
            }
            Result::<(), Box<dyn std::error::Error>>::Ok(())
        })
        .buffer_unordered(8);
    while let Some(x) = images.next().await {
        x?
    }

    Ok(r)
}

#[tokio::main]
async fn main() -> Result<(), Box<dyn std::error::Error>> {
    // reqwest's rustls is compiled without any crypto provider (see Cargo.toml);
    // register ring as the process-wide provider before the first Client is built.
    rustls::crypto::ring::default_provider()
        .install_default()
        .expect("failed to install the rustls crypto provider");

    let opt = Opt::parse();

    let r = if !opt.read_from_cache {
        load_from_network(&opt).await?
    } else {
        let full_doc = std::fs::read("figma_output/cache.json")?;
        serde_json::from_slice(&full_doc)?
    };

    let mut nodeHash = HashMap::new();
    fill_hash(&mut nodeHash, &r.document);
    let doc = rendered::Document { nodeHash };

    if let figmatypes::Node::DOCUMENT(document) = &r.document
        && let figmatypes::Node::CANVAS { node, prototypeStartNodeID, backgroundColor, .. } =
            &document.children[0]
    {

View on GitHub (pinned to bb937076de)