Source file src/crypto/internal/fips140/fips140.go
1 // Copyright 2024 The Go Authors. All rights reserved. 2 // Use of this source code is governed by a BSD-style 3 // license that can be found in the LICENSE file. 4 5 package fips140 6 7 import ( 8 "crypto/internal/fips140deps/godebug" 9 "errors" 10 "runtime" 11 ) 12 13 var Enabled bool 14 15 var debug bool 16 17 func init() { 18 v := godebug.Value("#fips140") 19 switch v { 20 case "on", "only": 21 Enabled = true 22 case "debug": 23 Enabled = true 24 debug = true 25 case "off", "": 26 default: 27 panic("fips140: unknown GODEBUG setting fips140=" + v) 28 } 29 } 30 31 // Supported returns an error if FIPS 140-3 mode can't be enabled. 32 func Supported() error { 33 // Keep this in sync with internal/platform.FIPS140Supported and 34 // cmd/dist.tester.fips140Supported. 35 36 // The purego tag changes too much of the implementation to claim the 37 // validation still applies. 38 if puregoEnabled { 39 return errors.New("FIPS 140-3 mode is incompatible with the purego build tag") 40 } 41 42 // ASAN disapproves of reading swaths of global memory in fips140/check. 43 // One option would be to expose runtime.asanunpoison through 44 // crypto/internal/fips140deps and then call it to unpoison the range 45 // before reading it, but it is unclear whether that would then cause 46 // false negatives. For now, FIPS+ASAN doesn't need to work. 47 if asanEnabled { 48 return errors.New("FIPS 140-3 mode is incompatible with ASAN") 49 } 50 51 // See EnableFIPS in cmd/internal/obj/fips.go for commentary. 52 // Also, js/wasm and windows/386 don't have good enough timers 53 // for the CPU jitter entropy source. 54 switch { 55 case runtime.GOARCH == "wasm", 56 runtime.GOOS == "windows" && runtime.GOARCH == "386", 57 runtime.GOOS == "openbsd", // due to -fexecute-only, see #70880 58 runtime.GOOS == "aix": 59 return errors.New("FIPS 140-3 mode is not supported on " + runtime.GOOS + "-" + runtime.GOARCH) 60 } 61 62 if boringEnabled { 63 return errors.New("FIPS 140-3 mode is incompatible with GOEXPERIMENT=boringcrypto") 64 } 65 66 return nil 67 } 68 69 func Name() string { 70 return "Go Cryptographic Module" 71 } 72 73 // Version returns the formal version (such as "v1.0.0") if building against a 74 // frozen module with GOFIPS140. Otherwise, it returns "latest". 75 func Version() string { 76 // This return value is replaced by mkzip.go, it must not be changed or 77 // moved to a different file. 78 return "latest" //mkzip:version 79 } 80