gabriel / muse public
fix minor task/fix-presigned-upload-macos #1 / 1
gabriel · 169 days ago · Apr 12, 2026 · Diff

fix: use curl for presigned PUT uploads on macOS

OpenSSL 3.6.x / Python 3.14 on Homebrew has a TLS 1.3 bug that causes SSLV3_ALERT_BAD_RECORD_MAC on direct PUT requests to Cloudflare R2. The bug is in the OpenSSL build, not in our code or R2.

Linux (staging/prod Docker) uses a different OpenSSL build and is unaffected — urllib continues to be used there.

On macOS, dispatch to curl which uses SecureTransport/LibreSSL (the macOS system TLS stack), bypassing the broken Homebrew OpenSSL entirely. No security settings are changed; TLS 1.3 + cert validation still runs via SecureTransport.

sha256:76b358caeca8a3640561420963a6b9eef3b8843b596fc981bf93eeda73098c38 sha
+4 ~1 symbols
sha256:5634cdad86598b02ff10f0154386d3848fe73155f6511ebf6ef05c7ec1626a6c snapshot
+4
symbols added
~1
symbol modified
0
dead code introduced
Semantic Changes 5 symbols
~ muse/cli/commands/push.py .py 4 symbols added, 1 symbol modified
+ _upload_presigned_curl function function _upload_presigned_curl L170–199
+ _upload_presigned_urllib function function _upload_presigned_urllib L202–230
+ platform import import platform L72–72
+ subprocess import import subprocess L73–73
← Older Oldest on task/fix-presigned-upload-macos
All commits
Newer → Latest on task/fix-presigned-upload-macos

0 comments

No comments yet. Be the first to start the discussion.

To add a comment, use the Muse CLI: muse hub commit comment sha256:76b358caeca8a3640561420963a6b9eef3b8843b596fc981bf93eeda73098c38 --body "your comment"