Skip to content

Add build-time FIPS crypto profile #1999

Add build-time FIPS crypto profile

Add build-time FIPS crypto profile #1999

Workflow file for this run

name: CI
on:
push:
branches:
- master
pull_request:
types: [ opened, synchronize, reopened ]
workflow_dispatch:
jobs:
formatting:
name: Check formatting
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- name: Check formatting
shell: pwsh
run: |
Write-Host "Check formatting"
cargo fmt --all -- --check
if ($LastExitCode -eq 1) {
throw "Bad formatting, please run 'cargo +stable fmt --all'"
}
lints:
name: Lints [${{ matrix.os }}]
runs-on: ${{ matrix.runner }}
needs: formatting
strategy:
fail-fast: true
matrix:
os: [ win, osx, linux ]
include:
- os: win
runner: windows-2022
additional-args: --features tsssp
- os: osx
runner: macos-14
- os: linux
runner: ubuntu-latest
steps:
- uses: actions/checkout@v6
# Compiling the ffi module is enough to lint the whole sspi workspace
- name: Check clippy
env:
AWS_LC_SYS_NO_ASM: true
run: cargo clippy --manifest-path ffi/Cargo.toml ${{ matrix.additional-args }} -- -D warnings -D clippy::print_stdout
tests:
name: Tests [${{ matrix.os }}] [${{ matrix.crate-name }}]
runs-on: ${{ matrix.runner }}
needs: formatting
env:
SSPI_RS_IS_RUNNING_TESTS: true
strategy:
fail-fast: true
matrix:
os: [ win, osx, linux ]
manifest:
- Cargo.toml
- ffi/Cargo.toml
- crates/dpapi/Cargo.toml
- crates/winscard/Cargo.toml
- crates/dpapi-pdu/Cargo.toml
- crates/ffi-types/Cargo.toml
- crates/dpapi-core/Cargo.toml
- crates/dpapi-transport/Cargo.toml
- crates/dpapi-native-transport/Cargo.toml
include:
# Map runner per OS
- os: win
runner: windows-2022
- os: osx
runner: macos-14
- os: linux
runner: ubuntu-latest
# Map crate name per manifest
- manifest: Cargo.toml
crate-name: sspi
- manifest: ffi/Cargo.toml
crate-name: sspi-ffi
- manifest: crates/dpapi/Cargo.toml
crate-name: dpapi
- manifest: crates/winscard/Cargo.toml
crate-name: winscard
- manifest: crates/dpapi-pdu/Cargo.toml
crate-name: dpapi-pdu
- manifest: crates/ffi-types/Cargo.toml
crate-name: ffi-types
- manifest: crates/dpapi-core/Cargo.toml
crate-name: dpapi-core
- manifest: crates/dpapi-transport/Cargo.toml
crate-name: dpapi-transport
- manifest: crates/dpapi-native-transport/Cargo.toml
crate-name: dpapi-native-transport
# Per-OS feature overrides for specific manifests.
# `__test-data` enables the `tests/sspi/client_server` suite (gated on
# `all(network_client, __test-data)`), which otherwise never runs in CI.
- os: win
manifest: Cargo.toml
additional-args: --features network_client,dns_resolver,scard,tsssp,__test-data
- os: osx
manifest: Cargo.toml
additional-args: --features network_client,scard,__test-data
- os: linux
manifest: Cargo.toml
additional-args: --features network_client,dns_resolver,scard,__test-data
- os: win
manifest: ffi/Cargo.toml
additional-args: --features tsssp
- os: win
manifest: crates/dpapi/Cargo.toml
additional-args: --features tsssp
steps:
- uses: actions/checkout@v6
- name: Test
env:
AWS_LC_SYS_NO_ASM: true
run: cargo test --manifest-path ${{ matrix.manifest }} ${{ matrix.additional-args }}
fips:
name: FIPS feature boundary
runs-on: ubuntu-latest
needs: formatting
steps:
- uses: actions/checkout@v6
- name: Check and test FIPS provider profile
run: |
cargo check -p sspi --no-default-features --features fips
cargo test -p sspi --no-default-features --features fips
- name: Check individual SSP features
shell: pwsh
run: |
foreach ($feature in @('ntlm', 'kerberos', 'pku2u', 'negotiate', 'credssp')) {
cargo check -p sspi --no-default-features --features $feature
if ($LASTEXITCODE -ne 0) { throw "feature '$feature' failed to compile" }
}
- name: Reject legacy crypto in FIPS dependency tree
shell: pwsh
run: |
$tree = cargo tree -p sspi --no-default-features --features fips --edges normal --prefix none
$banned = @(
'crypto-bigint',
'crypto-mac',
'hmac',
'md-5',
'md4',
'picky-krb',
'rsa',
'sha1'
)
foreach ($crate in $banned) {
if ($tree -match "(?m)^$([regex]::Escape($crate)) v") {
throw "FIPS dependency tree contains banned crate: $crate"
}
}
$pickyFeatures = (cargo tree -p sspi --no-default-features --features fips --edges features -i picky) -join "`n"
$rustlsFeatures = (cargo tree -p sspi --no-default-features --features fips --edges features -i rustls) -join "`n"
if ($pickyFeatures -notmatch 'picky feature "fips-aws-lc"') { throw "picky/fips-aws-lc is not enabled" }
if ($pickyFeatures -match 'picky feature "rustcrypto"') { throw "picky/rustcrypto is enabled" }
if ($rustlsFeatures -notmatch 'rustls feature "fips"') { throw "rustls/fips is not enabled" }
- name: Reject incompatible FIPS feature combinations
shell: pwsh
run: |
$incompatible = @(
'all-ssps',
'ntlm',
'kerberos',
'pku2u',
'negotiate',
'credssp',
'network_client',
'dns_resolver',
'scard',
'tsssp',
'aws-lc-rs',
'ring'
)
foreach ($feature in $incompatible) {
cargo check -p sspi --no-default-features --features "fips,$feature" 2>$null
if ($LASTEXITCODE -eq 0) { throw "fips + $feature unexpectedly compiled" }
}
cargo check -p sspi --features fips 2>$null
if ($LASTEXITCODE -eq 0) { throw "fips + default aws-lc-rs unexpectedly compiled" }
miri:
name: Miri FFI tests
runs-on: ubuntu-latest
needs: formatting
env:
SSPI_RS_IS_RUNNING_TESTS: true
steps:
- uses: actions/checkout@v6
# NOTE: Pinned to a specific nightly version for reproducibility.
# Update this manually on a regular basis.
- name: Install nightly toolchain and Miri
run: |
rustup toolchain install nightly-2026-02-11 --component miri
rustup override set nightly-2026-02-11
- name: Test
run: cargo miri test --manifest-path ffi/Cargo.toml --no-default-features --features ring
wasm:
name: WASM target
runs-on: ubuntu-latest
needs: formatting
steps:
- uses: actions/checkout@v6
- name: Prepare runner
run: sudo apt-get install wabt
- name: Check
shell: pwsh
run: ./tools/wasm-testcompile/check.ps1
build-native:
name: Build native
needs: formatting
uses: ./.github/workflows/build-native.yml
success:
name: Success
runs-on: ubuntu-latest
if: ${{ always() }}
needs:
- formatting
- lints
- tests
- fips
- miri
- wasm
- build-native
steps:
- name: CI succeeded
id: succeeded
if: ${{ !contains(needs.*.result, 'failure') }}
run: exit 0
- name: CI failed
if: ${{ steps.succeeded.outcome == 'skipped' }}
run: exit 1