Loading
Port FIPS usage to labkit v2 fips/sshalgo packages
What does this MR do?
Ports gitlab-shell off the deprecated labkit v1 fips package to the v2 scheme introduced in labkit!595 (merged) and released in labkit v2.35.0, which splits FIPS into two packages:
gitlab.com/gitlab-org/labkit/v2/fips— stdlib-only posture detection.Check()is replaced byLogStatus(*slog.Logger), plus the newActiveBackend()returningBackendNone/BackendBoringCrypto/BackendNativeGo.Enabled()is now derived fromActiveBackend().gitlab.com/gitlab-org/labkit/v2/fips/sshalgo— the SSH algorithm sets (DefaultAlgorithms(),SupportedAlgorithms()) that depend onx/crypto, split out so posture-only callers avoid that dependency.
Call-site changes
Old (labkit/fips) |
New |
|---|---|
fips.Check() |
fips.LogStatus(slog.Default()), gated on fips.Enabled() (see below) |
fips.Enabled() |
fips.Enabled() (now v2/fips) |
fips.DefaultAlgorithms() |
sshalgo.DefaultAlgorithms() |
Touched: cmd/gitlab-shell/main.go, internal/sshd/server_config.go, internal/sshd/server_config_test.go, go.mod, go.sum, .tool-versions.
Behavior changes worth reviewing
- FIPS status logging is now gated on
fips.Enabled(). v2'sfips.LogStatusalways emits an info record, including"binary was not compiled with FIPS support"for ordinary non-FIPS builds, whereas v1'sfips.Checkwas silent in that case.gitlab-shellruns once per git operation, so logging unconditionally would add a line to every push and pull on non-FIPS installs. Gating restores the v1 behavior: log only when a FIPS backend is active. - FIPS pubkey-auth algorithms are now actually filtered. v2
sshalgo.DefaultAlgorithms()seedsPublicKeyAuthsfrom the FIPS-filtered supported set. v1 left the field nil becausessh.Config.SetDefaultsnever populatesPublicKeyAuthAlgorithms, so the pubkey-auth policy silently never applied. Under FIPS,gitlab-shellnow advertises[ssh-ed25519 ecdsa-sha2-nistp256 ecdsa-sha2-nistp384 ecdsa-sha2-nistp521 rsa-sha2-256 rsa-sha2-512]and drops the SHA-1ssh-rsaandssh-dsssignature algorithms (RSA keys still work viarsa-sha2-256/rsa-sha2-512).TestFipsDefaultAlgorithmsand a stale comment were updated to match.
Dependency / toolchain notes
labkit/v2bumpedv2.3.0 → v2.35.0(the release containing the FIPS v2 packages). Some transitive deps moved as a result (otel, grpc-gateway, genproto, …).- v2.35.0 requires Go 1.25.10, so the
godirective moves1.25.8 → 1.25.10and.tool-versionsmovesgolang 1.25.9 → 1.25.10. CI's1.25/1.26build images already satisfy this (the test/race/fips jobs pass underGOTOOLCHAIN: local).
Testing
go build ./...,go vet ./..., andgo vet -tags fips ./...pass.go test ./internal/sshd/...passes (non-FIPS path);go test -tags fips ./internal/sshd/...passes.make lintpasses; the lint baseline needs no changes (main refactoredserver_config_test.goto use constants, so the added import shifts nogoconstline numbers).- The FIPS-only assertions in
TestFipsDefaultAlgorithmsare exercised by thetests:fipsCI job.
Notes
nilaway and check_gitaly_version fail but are non-blocking (allow_failure: true) and pre-existing / unrelated to this MR.
Edited by Stan Hu