Port FIPS usage to labkit v2 fips/sshalgo packages

What does this MR do?

Ports gitlab-shell off the deprecated labkit v1 fips package to the v2 scheme introduced in labkit!595 (merged) and released in labkit v2.35.0, which splits FIPS into two packages:

  • gitlab.com/gitlab-org/labkit/v2/fips — stdlib-only posture detection. Check() is replaced by LogStatus(*slog.Logger), plus the new ActiveBackend() returning BackendNone / BackendBoringCrypto / BackendNativeGo. Enabled() is now derived from ActiveBackend().
  • gitlab.com/gitlab-org/labkit/v2/fips/sshalgo — the SSH algorithm sets (DefaultAlgorithms(), SupportedAlgorithms()) that depend on x/crypto, split out so posture-only callers avoid that dependency.

Call-site changes

Old (labkit/fips) New
fips.Check() fips.LogStatus(slog.Default()), gated on fips.Enabled() (see below)
fips.Enabled() fips.Enabled() (now v2/fips)
fips.DefaultAlgorithms() sshalgo.DefaultAlgorithms()

Touched: cmd/gitlab-shell/main.go, internal/sshd/server_config.go, internal/sshd/server_config_test.go, go.mod, go.sum, .tool-versions.

Behavior changes worth reviewing

  • FIPS status logging is now gated on fips.Enabled(). v2's fips.LogStatus always emits an info record, including "binary was not compiled with FIPS support" for ordinary non-FIPS builds, whereas v1's fips.Check was silent in that case. gitlab-shell runs once per git operation, so logging unconditionally would add a line to every push and pull on non-FIPS installs. Gating restores the v1 behavior: log only when a FIPS backend is active.
  • FIPS pubkey-auth algorithms are now actually filtered. v2 sshalgo.DefaultAlgorithms() seeds PublicKeyAuths from the FIPS-filtered supported set. v1 left the field nil because ssh.Config.SetDefaults never populates PublicKeyAuthAlgorithms, so the pubkey-auth policy silently never applied. Under FIPS, gitlab-shell now advertises [ssh-ed25519 ecdsa-sha2-nistp256 ecdsa-sha2-nistp384 ecdsa-sha2-nistp521 rsa-sha2-256 rsa-sha2-512] and drops the SHA-1 ssh-rsa and ssh-dss signature algorithms (RSA keys still work via rsa-sha2-256/rsa-sha2-512). TestFipsDefaultAlgorithms and a stale comment were updated to match.

Dependency / toolchain notes

  • labkit/v2 bumped v2.3.0 → v2.35.0 (the release containing the FIPS v2 packages). Some transitive deps moved as a result (otel, grpc-gateway, genproto, …).
  • v2.35.0 requires Go 1.25.10, so the go directive moves 1.25.8 → 1.25.10 and .tool-versions moves golang 1.25.9 → 1.25.10. CI's 1.25/1.26 build images already satisfy this (the test/race/fips jobs pass under GOTOOLCHAIN: local).

Testing

  • go build ./..., go vet ./..., and go vet -tags fips ./... pass.
  • go test ./internal/sshd/... passes (non-FIPS path); go test -tags fips ./internal/sshd/... passes.
  • make lint passes; the lint baseline needs no changes (main refactored server_config_test.go to use constants, so the added import shifts no goconst line numbers).
  • The FIPS-only assertions in TestFipsDefaultAlgorithms are exercised by the tests:fips CI job.

Notes

nilaway and check_gitaly_version fail but are non-blocking (allow_failure: true) and pre-existing / unrelated to this MR.

Edited by Stan Hu

Merge request reports

Loading
Loading