Workshops aren't streamed/recorded, right?
Hey! Nope, workshops aren't streamed or recorded. Only the AI showcase will be recorded and uploaded afterward.
@borkdude with the new bb deps resolution in place, what's the current trick to make it like corporate certs?
set -gx CLJ_JVM_OPTS -Djavax.net.ssl.trustStoreType=KeychainStore
set -gx JAVA_TOOL_OPTIONS -Djavax.net.ssl.trustStoreType=KeychainStore
is what I have been usinghmm
it might be pebkac
have you tried passing those to bb itself?
not yet, but will try
possible pebkac, the bb command that fails due to this is executed by the zed editor for clojure-lsp or something similar
hmm no it doens't work from the shell either
you can put stuff in BABASHKA_PRELOADS like settings these properties, perhaps that helps?
oh if it doesn't work from the shell, then that won't help either
perhaps you can write an issue about this and how I might test a possible solution?
meanwhile you can use BABASHKA_DEPS_RESOLVER=jvm
I'm not sure how you'd test a possible solution if you aren't on a corp machine that is involved in tls spying via internal certs 😕
LLM suggestion. Worth a shot maybe,..
#!/usr/bin/env bb
(require '[babashka.process :as p]
'[babashka.fs :as fs])
(def out (str (fs/path (fs/home) ".keychain.p12")))
(def password (char-array "changeit"))
(def pem
(:out (p/shell {:out :bytes} "security" "find-certificate" "-a" "-p"
"/Library/Keychains/System.keychain"
"/System/Library/Keychains/SystemRootCertificates.keychain"
(str (fs/path (fs/home) "Library/Keychains/login.keychain-db")))))
(def certs
(.generateCertificates (java.security.cert.CertificateFactory/getInstance "X.509")
(java.io.ByteArrayInputStream. pem)))
(def ks (doto (java.security.KeyStore/getInstance "PKCS12")
(.load nil nil)))
(doseq [[i cert] (map-indexed vector certs)]
(.setCertificateEntry ks (str "cert-" i) cert))
(with-open [os (java.io.FileOutputStream. out)]
(.store ks os password))
(println "Wrote" (count certs) "certificates to" out)
Then set this in the shell:
export BABASHKA_PRELOADS='(System/setProperty "javax.net.ssl.trustStore" (str (System/getProperty "user.home") "/.keychain.p12")) (System/setProperty "javax.net.ssl.trustStorePassword" "changeit")'what's the new dep resolver btw?
is it running in the graal process?
(btw switching to the jvm resolver worked in the terminal)
the new dep resolver is running tools.deps from source (interpreted)
in the graal process, yes
I can try picking up on CLJ_JVM_OPTS and JAVA_TOOLS_OPTS and see if I can get something working for your machine that doesn't need any workarounds
I think you had mentioned earlier that this is not trivial with graal because it bakes certs in too early or something?
ah yes I think I found the thread, at the end of which I created https://github.com/babashka/babashka/wiki/Using-custom-certificates
can you try if bb - works?
if that works, then I can make that work with BABASHKA_PRELOADS (the order is currently wrong: the deps resolving happens before running the preloads)
let me try
eh
everything's cached now
-Sforce
let me see what I need to delete to make it break again
ah
bb -Sforce print-deps --format classpath is what I'm trying to make fail
rm -rf .cpcache/ didn't help
-Sdeps '{:mvn/local-repo "/tmp/dude"}'
cool, reproed
bb - works!
nice!
I'll try fixing it by reading from CLJ_JVM_OPTS
so you don't have to work around anymore
BB_JVM_OPTS perhaps? Not sure which one would be better
probably the BB one
well, deps.clj in bb already respected CLJ_JVM_OPTS when doing the mvn dance via java...
yeah but for clj tools I set CLJ_JVM_OPTS - which doesn't work with BB even with bb -D...
but yeah maybe it would be safer for bb
oh yes
so I'll need to use a differet one for bb
maybe babashka preloads would still be the right thing then
but it needs to be executed earlier
I kinda like the BB_JVM_OPTS idea. Here are the opts I always want to pass to bb. But I guess a 0-th step preloads is more powerful
the CLJ_JVM_OPTS variable is a fragment that is inserted "as is" when clj start a new JVM
bb would have to parse it and set those at runtime which may have a slightly different effect. E.g. I don't know if you can change -Xmx at runtime
what does bb - do then?
those options are parsed by the native-image itself
I see so that's before babashka starts, right?
yeah
before my code starts, basically
have you built bb locally before?
I'm wondering if there is something like NATIVE_IMAGE_JVM_OPTS that native image picks up
I haven't built it locally no
hmmm that would be the answer to our problems ;)
I think the only way to get that is to wrap bb in another launcher shell script
so BABASHKA_PRELOADS is the most honest option I think
let me link to you a CI binary where you can test this change
when it's done
sure thing, but no rush
looks like there isn't such an env var right now for native image https://github.com/oracle/graal/issues/9504
you are on mac m-series right?
I am
have bb installed via borkdude/brew
follow this build: https://github.com/babashka/babashka/actions/runs/36146042922/job/108107354071?pr=2173
when it's done, download the artifact and try setting the option in BABASHKA_PRELOADS
of course run bb via that download, not your global one :)
definitely
seems like it's working:
BABASHKA_PRELOADS='(System/setProperty "javax.net.ssl.trustStore" (str (System/getenv "JAVA_HOME") "/lib/security/cacerts"))' ~/Downloads/bb -Sdeps '{:mvn/local-repo "/tmp/dude2"}' -Sforce print-deps --format classpath
Downloading: org/clojure/clojure/1.12.5/clojure-1.12.5.pom from central
Downloading: org/clojure/spec.alpha/0.5.238/spec.alpha-0.5.238.pom from central
Downloading: org/clojure/core.specs.alpha/0.4.74/core.specs.alpha-0.4.74.pom from central
...
great :)
nice one
What's BABASHKA_PRELOADS_HOME btw? I saw it mentioned in the pr but it isn't on http://book.babashka.org
it's used in the tests but I'll change that
ah so it isn't for users, right?
So the wiki solution works then, with the new resolver, no changes needed there I guess documentation wise
that's my observation, yes
merged it. if you want you can install the dev build, but perhaps I'll make a new minor release this wee... oh it's already Friday :) well maybe soon
Not urgent, I can wait for it. Thank you!
it's funny that you wrote that page!
didn't realize it until now
you asked me to 🙂
it's a problem I keep facing again and again lol
Is anyone here using BABASHKA_PRELOADS and if so, what are you doing in it? I might change the order when this is executed, before deps fetching. Not sure if that bites anyone, but it lets us set the right JVM properties for certificates etc.
@jeroenvandijk @marcobiscaro2112 👎 means "don't do this", or "no, I'm not using it"?
Yeah not using it