Skip to content

test: pin the SNMPv3 engine under FIPS 140-only mode - #41

Merged
ilyam8 merged 1 commit into
engine-v3-e2efrom
engine-fips
Oct 11, 2026
Merged

ilyam8 merged 1 commit into
engine-v3-e2efrom
engine-fips

Conversation

@ilyam8

@ilyam8 ilyam8 commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Summary

Pins what the SNMPv3 request engine does when FIPS 140-only mode refuses an algorithm, so the engine's restructuring cannot change it unnoticed. Test files only, no library change.

  • engine_v3_fips_test.go: TestEngineV3FIPS140Only skips unless FIPS 140-only enforcement is on; CI's existing GODEBUG=fips140=only go test -run FIPS140Only . step selects it. It runs discovery and a Get for noAuth, MD5, SHA-1/AES, SHA-256/DES, SHA-256/AES and SHA-512/AES-256-C users, a second Get after a failed discovery and a preset engine ID. testdata/engine/v3-fips.golden holds the transcripts.
  • The fake agent and the key oracle of the v3 tests run without enforcement (they stand for the other side, not the client); testdata/engine/v3.golden is unchanged. The agent gets a SHA-256/AES user.

Known bugs pinned with known bug: notes: a failed key derivation (MD5, SHA-1) leaves the agent's engine ID adopted without keys, boots or time, so the next request skips the discovery and fails to encode; the key derivation error is ignored when the engine ID is known; AES-CFB panics and send recovers it into an error that carries the stack. DES is refused at encoding with the cipher's error.

Testing

  • GODEBUG=fips140=only go test -run FIPS140Only .: both FIPS tests pass, also with -race and on GOARCH=386; without enforcement the test skips and the suite passes.
  • Mutation probes under enforcement: restoring the engine ID after a failed derivation, setting boots and time before deriving, returning the ignored key error and removing send's recover are each caught; ignoring the discovery store error gives the same outcome here and is caught by v3.golden.
  • golangci-lint v2.14.0: 0 issues.

@ilyam8
ilyam8 added this pull request to stack #38 October 9, 2026 14:54
@ilyam8
ilyam8 force-pushed the engine-fips branch 2 times, most recently from 2cfc543 to 9b49847 Compare October 11, 2026 09:46
The engine's behavior when FIPS 140-only mode refuses an algorithm was pinned
nowhere: CI's GODEBUG=fips140=only step ran only the digest test.

TestEngineV3FIPS140Only (skipped unless enforcement is on; CI's
"-run FIPS140Only" step selects it) runs discovery and a Get for noAuth,
MD5, SHA-1/AES, SHA-256/DES, SHA-256/AES and SHA-512/AES-256-C users, a
second Get after a failed discovery and a preset engine ID, against the fake
agent, which runs without enforcement with the key oracle (it stands for the
other side). testdata/engine/v3-fips.golden holds the transcripts.

Known bugs pinned: a failed key derivation (MD5, SHA-1) leaves the agent's
engine ID adopted without keys, boots or time, so the next request skips the
discovery and fails to encode; the key derivation error is ignored when the
engine ID is known; AES-CFB panics and send recovers it into an error that
carries the stack. DES is refused at encoding with the cipher's error.
@ilyam8
ilyam8 merged commit 0328a53 into master Oct 11, 2026
21 checks passed
@ilyam8
ilyam8 deleted the engine-fips branch October 11, 2026 10:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants