Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 19 additions & 5 deletions .github/workflows/test-rust-core.yml
Original file line number Diff line number Diff line change
Expand Up @@ -134,7 +134,7 @@ jobs:
shared-key: "no-protobuf"

- name: Build sf_core without protobuf feature
run: cargo build --locked --package sf_core --no-default-features --features fips
run: cargo build --locked --package sf_core --no-default-features --features fips-tls

# Compile-test the library's unit tests (tests inside sf_core/src/*) to catch
# modules that use protobuf types without a `#[cfg(feature = "protobuf")]` guard.
Expand All @@ -144,8 +144,17 @@ jobs:
# tracked separately; this check still catches the more impactful class of bugs
# (accidentally exposing protobuf-dependent code in the library's public surface).
# --no-run skips execution so this lane stays fast and doesn't need network access.
#
# Which also means the `fips-tls` assertions in tls::fips_tests are compiled
# here but never executed: this step and the build above are the only places
# the feature is turned on, and neither runs a test. The assertions exist --
# `cargo test --features fips-tls --lib` runs them locally -- but no CI lane
# executes them, so a regression in provider installation or
# `ClientConfig::fips()` would not be caught here. The lanes that will run
# them are added with the FIPS release pipelines, which need the pinned
# GCC 13 toolchain `aws-lc-fips-sys` requires.
- name: Compile library unit tests without protobuf feature
run: cargo test --locked --no-run --lib --package sf_core --no-default-features --features fips
run: cargo test --locked --no-run --lib --package sf_core --no-default-features --features fips-tls

- name: Clean up python_bridge artifacts from target
if: always()
Expand Down Expand Up @@ -392,12 +401,17 @@ jobs:
# library machine type 'x64' conflicts with target machine type 'ARM64'
# Evidence points to aws-lc-fips-sys Windows build env setup:
# builder/printenv.bat calls vcvarsall.bat x64, overriding ARM64 toolchain env.
# Workaround: do not enable fips on this lane.
# Workaround: do not enable fips-tls on this lane.
# Upstream issue: https://github.com/aws/aws-lc-rs/issues/1057
# Repro job: https://github.com/snowflakedb/drivers/actions/runs/22779459689/job/66081199710
# TODO: re-enable --all-features after fix.
# The test suite is identical with and without fips — no tests are gated
# behind cfg(feature = "fips"). Only the linked TLS crypto backend differs
# Coverage note: the only tests gated behind cfg(feature = "fips-tls") are the
# tls::fips_tests assertions, which verify FIPS-ness end to end: the linked
# aws-lc module reports FIPS mode, and the installed rustls provider /
# ClientConfig are FIPS (approved cipher suites only). All of that is
# meaningless on this non-FIPS lane by construction, so
# skipping them here loses no coverage. Every other test runs identically with
Comment thread
sfc-gh-pfus marked this conversation as resolved.
# and without fips-tls; only the linked TLS crypto backend differs
# (aws-lc-sys vs aws-lc-fips-sys).
test_windows_arm64_nonfips:
needs: load-core-matrix
Expand Down
99 changes: 19 additions & 80 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 4 additions & 0 deletions jdbc_bridge/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,10 @@ crate-type = ["cdylib"]
[features]
# Static OpenSSL for the release fat-jar libs (dev/test builds link system OpenSSL).
vendored-openssl = ["sf_core/vendored-openssl"]
# Links the FIPS-validated TLS backend (aws-lc-fips-sys) instead of aws-lc-sys.
# Covers TLS only, which is what the name says -- see the `fips-tls` feature
# comment in sf_core/Cargo.toml for why this is not a FIPS artifact on its own.
fips-tls = ["sf_core/fips-tls"]

[dependencies]
sf_core = { path = "../sf_core" }
Expand Down
6 changes: 6 additions & 0 deletions nodejs_bridge/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,12 @@ publish = false
name = "nodejs_bridge"
crate-type = ["cdylib"]

[features]
# Links the FIPS-validated TLS backend (aws-lc-fips-sys) instead of aws-lc-sys.
# Covers TLS only, which is what the name says -- see the `fips-tls` feature
# comment in sf_core/Cargo.toml for why this is not a FIPS artifact on its own.
fips-tls = ["sf_core/fips-tls"]

[dependencies]
sf_core = { path = "../sf_core" }
sf_types = { path = "../sf_types" }
Expand Down
4 changes: 4 additions & 0 deletions odbc/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,10 @@ default = ["sonic-json"]
sonic-json = ["sf_core/sonic-json"]
perf_timing = ["sf_core/perf_timing"]
vendored-openssl = ["sf_core/vendored-openssl"]
# Links the FIPS-validated TLS backend (aws-lc-fips-sys) instead of aws-lc-sys.
# Covers TLS only, which is what the name says -- see the `fips-tls` feature
# comment in sf_core/Cargo.toml for why this is not a FIPS artifact on its own.
fips-tls = ["sf_core/fips-tls"]
# Exposes `bench_support` (doc-hidden) so the `conversion` criterion bench can
# reach the otherwise-private fetch-conversion pipeline. Off by default; not
# part of the public API.
Expand Down
Loading