Repository navigation
test: pin the SNMPv3 engine under FIPS 140-only mode - #41
Merged
Merged
Conversation
ilyam8
added this pull request to stack #38
October 9, 2026 14:54
ilyam8
force-pushed
the
engine-fips
branch
2 times, most recently
from
October 11, 2026 09:46
2cfc543 to
9b49847
Compare
The engine's behavior when FIPS 140-only mode refuses an algorithm was pinned nowhere: CI's GODEBUG=fips140=only step ran only the digest test. TestEngineV3FIPS140Only (skipped unless enforcement is on; CI's "-run FIPS140Only" step selects it) runs discovery and a Get for noAuth, MD5, SHA-1/AES, SHA-256/DES, SHA-256/AES and SHA-512/AES-256-C users, a second Get after a failed discovery and a preset engine ID, against the fake agent, which runs without enforcement with the key oracle (it stands for the other side). testdata/engine/v3-fips.golden holds the transcripts. Known bugs pinned: a failed key derivation (MD5, SHA-1) leaves the agent's engine ID adopted without keys, boots or time, so the next request skips the discovery and fails to encode; the key derivation error is ignored when the engine ID is known; AES-CFB panics and send recovers it into an error that carries the stack. DES is refused at encoding with the cipher's error.
stelfrag
approved these changes
Oct 11, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Pins what the SNMPv3 request engine does when FIPS 140-only mode refuses an algorithm, so the engine's restructuring cannot change it unnoticed. Test files only, no library change.
engine_v3_fips_test.go:TestEngineV3FIPS140Onlyskips unless FIPS 140-only enforcement is on; CI's existingGODEBUG=fips140=only go test -run FIPS140Only .step selects it. It runs discovery and a Get for noAuth, MD5, SHA-1/AES, SHA-256/DES, SHA-256/AES and SHA-512/AES-256-C users, a second Get after a failed discovery and a preset engine ID.testdata/engine/v3-fips.goldenholds the transcripts.testdata/engine/v3.goldenis unchanged. The agent gets a SHA-256/AES user.Known bugs pinned with
known bug:notes: a failed key derivation (MD5, SHA-1) leaves the agent's engine ID adopted without keys, boots or time, so the next request skips the discovery and fails to encode; the key derivation error is ignored when the engine ID is known; AES-CFB panics andsendrecovers it into an error that carries the stack. DES is refused at encoding with the cipher's error.Testing
GODEBUG=fips140=only go test -run FIPS140Only .: both FIPS tests pass, also with-raceand onGOARCH=386; without enforcement the test skips and the suite passes.send's recover are each caught; ignoring the discovery store error gives the same outcome here and is caught byv3.golden.