Draft: Export GOFIPS140 once for all Go builds

What does this MR do?

Each Go software definition exported GOFIPS140. The author of a new Go component must remember that line. If the author forgets it, the build makes a non-FIPS binary and gives no warning. This is how the build missed registry, gitlab-kas and gitlab-elasticsearch-indexer.

This MR exports GOFIPS140 one time. omnibus.rb calls Build::Check.export_go_fips_module_env!. The omnibus CLI loads omnibus.rb before it evaluates the project and the software definitions. A definition merges its env hash over the process environment, and does not replace it. Thus every build command gets GOFIPS140, and no component opts in.

The change also puts the other Go components under the toggle: consul, prometheus, the exporters, cosign, go-crond and fast-stats. These components never had the line.

A component can only opt out. The definition sets GOFIPS140 to off, gives the reason in a comment, and goes into the allowlist in spec/lib/gitlab/build/go_fips_definitions_spec.rb. That spec fails for each definition that sets GOFIPS140 but is not in the allowlist.

gitlab-pages no longer sets GOEXPERIMENT=boringcrypto. Its own Makefile.build.mk chooses between the native module and boringcrypto, keyed on go env GOFIPS140, so the recipe duplicated that decision and could only get it wrong. See gitlab-pages!1296 (merged).

That leaves Build::Check.boringcrypto_supported? with no callers, so this MR removes it. It could not answer the question anyway: it probes with go version, which never initializes FIPS configuration, and so succeeds on every toolchain, upstream Go included.

🛑 Merge order

This MR is last of three. Two MRs block it:

  1. !9771 (closed) gives the seven Go components the per-recipe line. It closes the live gap in three shipped binaries.
  2. !9774 (closed) makes USE_GO_FIPS_MODULE the default. Its evidence covers the seven components of !9771 (closed).

This MR then replaces the seven lines with one central export, and adds the other Go components. The order keeps each step on its own evidence.

The branch is on top of !9771 (closed). The diff against master shows no change to registry.rb, gitlab-kas.rb and gitlab-elasticsearch-indexer.rb, because the addition and the removal cancel. This MR does not change the USE_GO_FIPS_MODULE row in doc/development/ci-variables.md, because !9774 (closed) rewrites that row.

Validation

A local probe loads the real omnibus.rb with Omnibus.load_configuration, which is the call the omnibus CLI makes. The probe then runs a build command through a real Omnibus::Builder.

Build environment Process env Recipe sets no env Recipe sets other env Recipe sets off
Toggle on v1.0.0 v1.0.0 v1.0.0 off
USE_SYSTEM_SSL only unset unset unset off
No toggle unset unset unset off
GO_FIPS_MODULE_VERSION=v1.2.3 v1.2.3 v1.2.3 v1.2.3 off

bundle exec rspec spec/lib gives 602 examples and 0 failures. Rubocop is clean. The guard spec was also tested in both failure directions.

The CI test is the toggle harness on this branch. Bust the component cache for that run. Omnibus keys git_cache on the definition file and the command descriptions, not on environment variables. A cached non-FIPS binary can hide the result. The harness must run on this branch. The evidence for !9774 (closed) comes from the branch of !9771 (closed), which does not have the central export or the other Go components.

Two points for review

  1. Blast radius. consul, prometheus, the exporters, cosign, go-crond and fast-stats get GOFIPS140 for the first time. GOFIPS140=v1.0.0 also makes the default GODEBUG of those binaries fips140=on. This is a change of runtime behavior, not only of the build. After !9774 (closed) this applies to every FIPS build, not only to a manual toggle.
  2. Log visibility. Omnibus writes only the recipe env hash to the build log. Thus the log no longer shows GOFIPS140="v1.0.0", as it did in https://gitlab.com/gitlab-org/omnibus-gitlab/-/jobs/16399836115. Validation must now use the binaries.

Closes #10091 (closed)

Related to #10002 (closed)

Checklist

See Definition of done.

Required

  • MR title and description are up to date, accurate, and descriptive.
  • MR targeting the appropriate branch.
  • Latest Merge Result pipeline is green.
  • When ready for review, MR is labeled workflowready for review.
  • UBT: not applicable.

For GitLab team members

  • The manual Trigger:ee-package jobs have a green pipeline against the latest commit.
  • config/software is changed, so the build-package-on-all-os job in the Trigger:ee-package downstream pipeline must succeed.
  • This MR changes SSL and FIPS behavior, so the Trigger:package:fips manual job must succeed.

Expected

  • Documentation updated.
  • Tests added.
  • Test plan: see Validation above.
  • Chart equivalent: not applicable. The Go FIPS work for CNG is in gitlab-org#22761 (closed).
Edited by Jason Plum

Merge request reports

Loading
Loading