little-petabyte-55176
10/02/2025, 2:05 PM$ pants package ::
13:29:39.22 [INFO] Initializing scheduler...
13:29:39.34 [INFO] Scheduler initialized.
13:29:39.41 [INFO] Completed: Scheduling: Building 1 requirement for faas_repository.pex from the python-default.lock resolve: boto3==1.40.43
13:29:39.41 [INFO] Completed: Scheduling: Build python_aws_lambda_function artifact for lambda_functions/create_grafana:lambda
13:29:39.43 [ERROR] 1 Exception encountered:
Engine traceback:
in `package` goal
IntrinsicError: Error setting permissions on /lambdas/dist/lambda_functions.create_grafana/lambda.zip: Permission denied (os error 13)
I can't bypass this. Anyone knows how to overcome this issue?wide-midnight-78598
10/02/2025, 3:14 PMscie-pants worked? Or are you pulling it down separately?
https://github.com/pantsbuild/scie-pantswide-midnight-78598
10/02/2025, 3:15 PMlittle-petabyte-55176
10/02/2025, 3:17 PMscie-pants doesn't work on my Mac, because of custom SSL. In Docker container it does.little-petabyte-55176
10/02/2025, 3:22 PMscie-pants doesn't work on my Mac, because it fails on downloading cpython PEX files from Github releases. It throws exception of SSL certificate validationwide-midnight-78598
10/02/2025, 3:32 PMlittle-petabyte-55176
10/02/2025, 7:12 PMwide-midnight-78598
10/02/2025, 7:14 PMwide-midnight-78598
10/02/2025, 7:15 PMlittle-petabyte-55176
10/02/2025, 7:38 PMSSL_CERT_FILE worked for me inside a Docker container, but it didn't solve the problem on my Mac.
By the way - the Docker container is running on the same Mac I have the first problemlittle-petabyte-55176
10/02/2025, 7:40 PM<https://github.com/pantsbuild/pants/releases/download/release_2.28.0/pants.2.28.0-cp311-darwin_arm64.pex>
I could also dig by myself to lookup for a solution that might work on my Mac behind the firewallwide-midnight-78598
10/02/2025, 8:20 PMwide-midnight-78598
10/02/2025, 8:22 PMwide-midnight-78598
10/03/2025, 11:58 AMfresh-mechanic-68429
03/06/2026, 4:23 AMSSL_CERT_FILE issue too, though not with scie-pants but the tools that pants downloads via rust (like ruff). My hopythesis here is that rust isn't respecting the env var
I've got a reproduction for mac using https://mitmproxy.org/ here https://github.com/chris-smith-zocdoc/pants-mitm-issue Though you should be able to adopt it for linux easily (mitmproxy is cross platform)
[DEBUG] Error while downloading <https://github.com/astral-sh/ruff/releases/download/0.13.0/ruff-aarch64-apple-darwin.tar.gz>: Error downloading file: error sending request for url (<https://github.com/astral-sh/ruff/releases/download/0.13.0/ruff-aarch64-apple-darwin.tar.gz>) (retryable)
IntrinsicError: Error downloading file: error sending request for url (<https://github.com/astral-sh/ruff/releases/download/0.13.0/ruff-aarch64-apple-darwin.tar.gz>)
mitmproxy reports
Client TLS handshake failed. The client does not trust the proxy's certificate for <http://github.com|github.com> (tlsv1 alert unknown ca)fresh-mechanic-68429
03/06/2026, 4:27 AM[GLOBAL]
ca_certs_path = <path>
Does allow it to work though. Should that be required? The docs state
By default, Pants will respect and pass through theWhich is why I didn't set that initially https://www.pantsbuild.org/stable/docs/using-pants/restricted-internet-access#setting-up-a-certificate-authorityandSSL_CERT_DIRenvironment variables.SSL_CERT_FILE
brief-scientist-13682
03/06/2026, 5:06 AM--no-pantsd and the env vars then work (not that you should do things this way, but just to prove out a debugging point). If so, same as here: https://github.com/pantsbuild/pants/issues/22932fresh-mechanic-68429
03/06/2026, 5:15 AM--no-pantsd alreadybrief-scientist-13682
03/06/2026, 5:15 AM