1 # The module cache copy of a FIPS snapshot is used only if the module
2 # cache records the module zip hash from GOROOT/lib/fips140/fips140.sum
3 # for it, the way downloaded modules are checked against go.sum.
4 # Otherwise it is discarded and the snapshot is unpacked again.
5 #
6 # This detects a cache entry that was not unpacked from the bundled
7 # snapshot (or whose hash record is missing). Like go.sum, it does not
8 # protect the module cache from being modified in place: the replaced
9 # source file below stands in for stale contents, not an attacker.
10
11 env snap=v1.26.0
12 env GOFIPS140=$snap
13 env GOMODCACHE=$WORK/modcache
14 env GOFLAGS=-modcacherw
15
16 # Go+BoringCrypto conflicts with GOFIPS140.
17 [GOEXPERIMENT:boringcrypto] skip
18
19 env ziphash=$GOMODCACHE/cache/download/golang.org/fips140/@v/$snap.ziphash
20 env srcfile=$GOMODCACHE/golang.org/fips140@$snap/fips140/$snap/sha256/sha256.go
21
22 # unpacking the snapshot records its module zip hash in the module cache
23 go list -f '{{.DefaultGODEBUG}}'
24 stdout fips140=on
25 exists $ziphash
26 exists $srcfile
27 grep '^h1:dtoPX1ALGGp4rMLzyh6oqIkYRXnXxRkpPWu56l5DFpM=$' $ziphash
28 cp $ziphash good.ziphash
29
30 # a recorded hash that does not match fips140.sum
31 # discards the cached copy and unpacks the snapshot again
32 cp bad.ziphash $ziphash
33 rm $srcfile
34 cp stale/sha256.go $srcfile
35 go list -f '{{.DefaultGODEBUG}}'
36 stdout fips140=on
37 exists $srcfile
38 ! grep stale $srcfile
39 cmp $ziphash good.ziphash
40
41 # so does a missing hash
42 rm $ziphash
43 rm $srcfile
44 cp stale/sha256.go $srcfile
45 go list -f '{{.DefaultGODEBUG}}'
46 stdout fips140=on
47 exists $srcfile
48 ! grep stale $srcfile
49 cmp $ziphash good.ziphash
50
51 -- go.mod --
52 module m
53 -- x.go --
54 package main
55 import _ "crypto/sha256"
56 func main() {
57 }
58 -- bad.ziphash --
59 h1:AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=
60 -- stale/sha256.go --
61 package sha256 // stale
62
View as plain text