Add build-time FIPS crypto profile #1999
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: | |
| - master | |
| pull_request: | |
| types: [ opened, synchronize, reopened ] | |
| workflow_dispatch: | |
| jobs: | |
| formatting: | |
| name: Check formatting | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - name: Check formatting | |
| shell: pwsh | |
| run: | | |
| Write-Host "Check formatting" | |
| cargo fmt --all -- --check | |
| if ($LastExitCode -eq 1) { | |
| throw "Bad formatting, please run 'cargo +stable fmt --all'" | |
| } | |
| lints: | |
| name: Lints [${{ matrix.os }}] | |
| runs-on: ${{ matrix.runner }} | |
| needs: formatting | |
| strategy: | |
| fail-fast: true | |
| matrix: | |
| os: [ win, osx, linux ] | |
| include: | |
| - os: win | |
| runner: windows-2022 | |
| additional-args: --features tsssp | |
| - os: osx | |
| runner: macos-14 | |
| - os: linux | |
| runner: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v6 | |
| # Compiling the ffi module is enough to lint the whole sspi workspace | |
| - name: Check clippy | |
| env: | |
| AWS_LC_SYS_NO_ASM: true | |
| run: cargo clippy --manifest-path ffi/Cargo.toml ${{ matrix.additional-args }} -- -D warnings -D clippy::print_stdout | |
| tests: | |
| name: Tests [${{ matrix.os }}] [${{ matrix.crate-name }}] | |
| runs-on: ${{ matrix.runner }} | |
| needs: formatting | |
| env: | |
| SSPI_RS_IS_RUNNING_TESTS: true | |
| strategy: | |
| fail-fast: true | |
| matrix: | |
| os: [ win, osx, linux ] | |
| manifest: | |
| - Cargo.toml | |
| - ffi/Cargo.toml | |
| - crates/dpapi/Cargo.toml | |
| - crates/winscard/Cargo.toml | |
| - crates/dpapi-pdu/Cargo.toml | |
| - crates/ffi-types/Cargo.toml | |
| - crates/dpapi-core/Cargo.toml | |
| - crates/dpapi-transport/Cargo.toml | |
| - crates/dpapi-native-transport/Cargo.toml | |
| include: | |
| # Map runner per OS | |
| - os: win | |
| runner: windows-2022 | |
| - os: osx | |
| runner: macos-14 | |
| - os: linux | |
| runner: ubuntu-latest | |
| # Map crate name per manifest | |
| - manifest: Cargo.toml | |
| crate-name: sspi | |
| - manifest: ffi/Cargo.toml | |
| crate-name: sspi-ffi | |
| - manifest: crates/dpapi/Cargo.toml | |
| crate-name: dpapi | |
| - manifest: crates/winscard/Cargo.toml | |
| crate-name: winscard | |
| - manifest: crates/dpapi-pdu/Cargo.toml | |
| crate-name: dpapi-pdu | |
| - manifest: crates/ffi-types/Cargo.toml | |
| crate-name: ffi-types | |
| - manifest: crates/dpapi-core/Cargo.toml | |
| crate-name: dpapi-core | |
| - manifest: crates/dpapi-transport/Cargo.toml | |
| crate-name: dpapi-transport | |
| - manifest: crates/dpapi-native-transport/Cargo.toml | |
| crate-name: dpapi-native-transport | |
| # Per-OS feature overrides for specific manifests. | |
| # `__test-data` enables the `tests/sspi/client_server` suite (gated on | |
| # `all(network_client, __test-data)`), which otherwise never runs in CI. | |
| - os: win | |
| manifest: Cargo.toml | |
| additional-args: --features network_client,dns_resolver,scard,tsssp,__test-data | |
| - os: osx | |
| manifest: Cargo.toml | |
| additional-args: --features network_client,scard,__test-data | |
| - os: linux | |
| manifest: Cargo.toml | |
| additional-args: --features network_client,dns_resolver,scard,__test-data | |
| - os: win | |
| manifest: ffi/Cargo.toml | |
| additional-args: --features tsssp | |
| - os: win | |
| manifest: crates/dpapi/Cargo.toml | |
| additional-args: --features tsssp | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - name: Test | |
| env: | |
| AWS_LC_SYS_NO_ASM: true | |
| run: cargo test --manifest-path ${{ matrix.manifest }} ${{ matrix.additional-args }} | |
| fips: | |
| name: FIPS feature boundary | |
| runs-on: ubuntu-latest | |
| needs: formatting | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - name: Check and test FIPS provider profile | |
| run: | | |
| cargo check -p sspi --no-default-features --features fips | |
| cargo test -p sspi --no-default-features --features fips | |
| - name: Check individual SSP features | |
| shell: pwsh | |
| run: | | |
| foreach ($feature in @('ntlm', 'kerberos', 'pku2u', 'negotiate', 'credssp')) { | |
| cargo check -p sspi --no-default-features --features $feature | |
| if ($LASTEXITCODE -ne 0) { throw "feature '$feature' failed to compile" } | |
| } | |
| - name: Reject legacy crypto in FIPS dependency tree | |
| shell: pwsh | |
| run: | | |
| $tree = cargo tree -p sspi --no-default-features --features fips --edges normal --prefix none | |
| $banned = @( | |
| 'crypto-bigint', | |
| 'crypto-mac', | |
| 'hmac', | |
| 'md-5', | |
| 'md4', | |
| 'picky-krb', | |
| 'rsa', | |
| 'sha1' | |
| ) | |
| foreach ($crate in $banned) { | |
| if ($tree -match "(?m)^$([regex]::Escape($crate)) v") { | |
| throw "FIPS dependency tree contains banned crate: $crate" | |
| } | |
| } | |
| $pickyFeatures = (cargo tree -p sspi --no-default-features --features fips --edges features -i picky) -join "`n" | |
| $rustlsFeatures = (cargo tree -p sspi --no-default-features --features fips --edges features -i rustls) -join "`n" | |
| if ($pickyFeatures -notmatch 'picky feature "fips-aws-lc"') { throw "picky/fips-aws-lc is not enabled" } | |
| if ($pickyFeatures -match 'picky feature "rustcrypto"') { throw "picky/rustcrypto is enabled" } | |
| if ($rustlsFeatures -notmatch 'rustls feature "fips"') { throw "rustls/fips is not enabled" } | |
| - name: Reject incompatible FIPS feature combinations | |
| shell: pwsh | |
| run: | | |
| $incompatible = @( | |
| 'all-ssps', | |
| 'ntlm', | |
| 'kerberos', | |
| 'pku2u', | |
| 'negotiate', | |
| 'credssp', | |
| 'network_client', | |
| 'dns_resolver', | |
| 'scard', | |
| 'tsssp', | |
| 'aws-lc-rs', | |
| 'ring' | |
| ) | |
| foreach ($feature in $incompatible) { | |
| cargo check -p sspi --no-default-features --features "fips,$feature" 2>$null | |
| if ($LASTEXITCODE -eq 0) { throw "fips + $feature unexpectedly compiled" } | |
| } | |
| cargo check -p sspi --features fips 2>$null | |
| if ($LASTEXITCODE -eq 0) { throw "fips + default aws-lc-rs unexpectedly compiled" } | |
| miri: | |
| name: Miri FFI tests | |
| runs-on: ubuntu-latest | |
| needs: formatting | |
| env: | |
| SSPI_RS_IS_RUNNING_TESTS: true | |
| steps: | |
| - uses: actions/checkout@v6 | |
| # NOTE: Pinned to a specific nightly version for reproducibility. | |
| # Update this manually on a regular basis. | |
| - name: Install nightly toolchain and Miri | |
| run: | | |
| rustup toolchain install nightly-2026-02-11 --component miri | |
| rustup override set nightly-2026-02-11 | |
| - name: Test | |
| run: cargo miri test --manifest-path ffi/Cargo.toml --no-default-features --features ring | |
| wasm: | |
| name: WASM target | |
| runs-on: ubuntu-latest | |
| needs: formatting | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - name: Prepare runner | |
| run: sudo apt-get install wabt | |
| - name: Check | |
| shell: pwsh | |
| run: ./tools/wasm-testcompile/check.ps1 | |
| build-native: | |
| name: Build native | |
| needs: formatting | |
| uses: ./.github/workflows/build-native.yml | |
| success: | |
| name: Success | |
| runs-on: ubuntu-latest | |
| if: ${{ always() }} | |
| needs: | |
| - formatting | |
| - lints | |
| - tests | |
| - fips | |
| - miri | |
| - wasm | |
| - build-native | |
| steps: | |
| - name: CI succeeded | |
| id: succeeded | |
| if: ${{ !contains(needs.*.result, 'failure') }} | |
| run: exit 0 | |
| - name: CI failed | |
| if: ${{ steps.succeeded.outcome == 'skipped' }} | |
| run: exit 1 |