Documentation
¶
Overview ¶
FIPS reporting, sourced from the runtime rather than from a build flag.
WHY THIS EXISTS: --version used to print the FIPS ldflag verbatim. That is a claim about how someone intended to build the binary, not a fact about the binary. `go build -ldflags "-X ...version.FIPS=true"` without GOFIPS140 set produces a binary that reports fips=true and contains no FIPS module at all. For a compliance product that is the worst possible failure: an auditor reads the claim off the box and it is false.
Everything here is read from the running binary. FIPS is the ldflag, kept as a cross-check: when the two disagree the binary says so instead of choosing the flattering answer.
Package version exposes build-time metadata for the openwatch binary.
All values are overridden via -ldflags at build time by the Makefile. The default values are used when building with bare `go build` (e.g., during local development or in IDE-driven builds).
Index ¶
Constants ¶
This section is empty.
Variables ¶
var ( // Version is the semver string (e.g., "0.1.0-dev"). Version = "dev" // Commit is the abbreviated git commit hash. Commit = "unknown" // BuildTime is an ISO-8601 timestamp. BuildTime = "unknown" // FIPS is "true" when built with the microsoft/go FIPS toolchain (Day 12). FIPS = "false" )
Build-time injected values. Default to placeholders that make it obvious when a binary was built without the Makefile.
Functions ¶
func FIPSClaimMismatch ¶ added in v0.8.0
func FIPSClaimMismatch() bool
FIPSClaimMismatch reports whether the build-time FIPS ldflag disagrees with the runtime. True means the binary was labeled FIPS but has no active module, or the reverse. Callers surface this loudly: a mislabelled binary is worse than an unlabelled one, because it is trusted.
func FIPSEnabled ¶ added in v0.8.0
func FIPSEnabled() bool
FIPSEnabled reports whether the FIPS 140-3 module is active in this binary, as the crypto runtime sees it. This is the authoritative answer.
func FIPSMode ¶ added in v0.8.0
func FIPSMode() string
FIPSMode returns the active enforcement mode: "off", "on", or "only".
The distinction matters operationally, not just cosmetically. In "only" mode the Go crypto runtime refuses every algorithm outside the validated set, and golang.org/x/crypto/ssh cannot complete a handshake because its AES-GCM path uses arbitrary IVs. An OpenWatch reaching for maximum assurance by setting fips140=only loses the ability to scan any host, so the mode has to be visible rather than inferred.
A GODEBUG environment setting overrides the value baked in at build time, which is why both are consulted in that order.
func FIPSModule ¶ added in v0.8.0
func FIPSModule() string
FIPSModule returns the FIPS module build tag linked into the binary, for example "fips140v1.0", or "" when no module is linked. Read from build info, so it reflects what GOFIPS140 actually selected at link time.
Types ¶
This section is empty.