Commit 8c4531b

Browse files
panvaaduh95
authored andcommitted
src: report why --enable-fips failed
The startup failure always appended the OpenSSL error queue, so when Node.js itself detected the missing fips provider it printed an error header followed by nothing. Report the reason instead. Signed-off-by: Filip Skokan <panva.ip@gmail.com> PR-URL: #64979 Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com> Reviewed-By: Richard Lau <richard.lau@ibm.com> Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
1 parent 28cad47 commit 8c4531b

4 files changed

Lines changed: 45 additions & 21 deletions

File tree

β€Žsrc/crypto/crypto_util.ccβ€Ž

Lines changed: 27 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -99,20 +99,36 @@ int NoPasswordCallback(char* buf, int size, int rwflag, void* u) {
9999
return0;
100100
}
101101

102-
boolProcessFipsOptions() {
103-
/* Override FIPS settings in configuration file, if needed. */
104-
if (per_process::cli_options->enable_fips_crypto ||
105-
per_process::cli_options->force_fips_crypto) {
102+
std::optional<std::string> ProcessFipsOptions() {
103+
constbool enable_fips = per_process::cli_options->enable_fips_crypto;
104+
constbool force_fips = per_process::cli_options->force_fips_crypto;
105+
if (!enable_fips && !force_fips) return std::nullopt;
106+
106107
#if OPENSSL_VERSION_MAJOR >= 3
107-
if (!ncrypto::testFipsEnabled()) returnfalse;
108-
returnncrypto::setFipsEnabled(true, nullptr);
109-
#else
110-
// TODO(@jasnell): Remove this ifdef branch when openssl 1.1.1 is
111-
// no longer supported.
112-
if (FIPS_mode() == 0) returnFIPS_mode_set(1);
108+
// Whether FIPS-approved implementations are reachable is decided by the
109+
// OpenSSL configuration, not by Node.js. Refuse to start rather than
110+
// restrict the default property query to a provider that is not there,
111+
// which would leave every operation failing as unsupported.
112+
if (!ncrypto::testFipsEnabled()) {
113+
const std::string option = force_fips ? "--force-fips" : "--enable-fips";
114+
return option + " requires an active OpenSSL provider named \"fips\". "
115+
"FIPS mode is configured through OpenSSL; see "
116+
"https://nodejs.org/api/crypto.html#fips-mode";
117+
}
113118
#endif
119+
120+
CryptoErrorList errors{CryptoErrorList::Option::NONE};
121+
if (!ncrypto::setFipsEnabled(true, &errors)) {
122+
std::string error = "OpenSSL error when trying to enable FIPS";
123+
if (!errors.empty()) error += ':';
124+
for (constauto& openssl_error : errors) {
125+
error += '\n';
126+
error += openssl_error;
127+
}
128+
return error;
114129
}
115-
returntrue;
130+
131+
return std::nullopt;
116132
}
117133

118134
boolInitCryptoOnce(Isolate* isolate) {

β€Žsrc/crypto/crypto_util.hβ€Ž

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,10 @@ constexpr T NumBitsToBytes(T bits) {
6262
return (bits / CHAR_BIT) + ((CHAR_BIT - 1 + (bits % CHAR_BIT)) / CHAR_BIT);
6363
}
6464

65-
boolProcessFipsOptions();
65+
// Applies the FIPS related command line options. Returns a description of
66+
// what went wrong, or std::nullopt when there was nothing to do or the
67+
// options were applied successfully.
68+
std::optional<std::string> ProcessFipsOptions();
6669

6770
boolInitCryptoOnce(v8::Isolate* isolate);
6871
voidInitCryptoOnce();

β€Žsrc/node.ccβ€Ž

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1168,6 +1168,7 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
11681168
if (!(flags & ProcessInitializationFlags::kNoInitOpenSSL)) {
11691169
#if HAVE_OPENSSL
11701170
#ifndef OPENSSL_IS_BORINGSSL
1171+
#if OPENSSL_VERSION_MAJOR >= 3
11711172
auto GetOpenSSLErrorString = []() -> std::string {
11721173
std::string ret;
11731174
ERR_print_errors_cb(
@@ -1183,7 +1184,6 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
11831184

11841185
// In the case of FIPS builds we should make sure
11851186
// the random source is properly initialized first.
1186-
#if OPENSSL_VERSION_MAJOR >= 3
11871187
// Call OPENSSL_init_crypto to initialize OPENSSL_INIT_LOAD_CONFIG to
11881188
// avoid the default behavior where errors raised during the parsing of the
11891189
// OpenSSL configuration file are not propagated and cannot be detected.
@@ -1244,12 +1244,10 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
12441244
OPENSSL_init();
12451245
}
12461246
#endif
1247-
if (!crypto::ProcessFipsOptions()) {
1247+
if (auto fips_error = crypto::ProcessFipsOptions()) {
12481248
result->exit_code_ = ExitCode::kGenericUserError;
12491249
result->early_return_ = true;
1250-
result->errors_.emplace_back(
1251-
"OpenSSL error when trying to enable FIPS:\n" +
1252-
GetOpenSSLErrorString());
1250+
result->errors_.emplace_back(std::move(*fips_error));
12531251
return result;
12541252
}
12551253

β€Žtest/parallel/test-crypto-fips.jsβ€Ž

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,14 @@ const FIPS_ERROR_STRING2 =
2121
'Error [ERR_CRYPTO_FIPS_FORCED]: Cannot set FIPS mode, it was forced with '+
2222
'--force-fips at startup.';
2323
constFIPS_UNSUPPORTED_ERROR_STRING='fips mode not supported';
24-
constFIPS_ENABLE_ERROR_STRING='OpenSSL error when trying to enable FIPS:';
24+
constFIPS_ENABLE_ERROR_STRING=
25+
hasOpenSSL3 ?
26+
'--enable-fips requires an active OpenSSL provider named "fips"' :
27+
'OpenSSL error when trying to enable FIPS:';
28+
constFIPS_FORCE_ERROR_STRING=
29+
hasOpenSSL3 ?
30+
'--force-fips requires an active OpenSSL provider named "fips"' :
31+
'OpenSSL error when trying to enable FIPS:';
2532

2633
constCNF_FIPS_ON=fixtures.path('openssl_fips_enabled.cnf');
2734
constCNF_FIPS_OFF=fixtures.path('openssl_fips_disabled.cnf');
@@ -75,16 +82,16 @@ testHelper(
7582
['--enable-fips'],
7683
testFipsCrypto() ? kNoFailure : kGenericUserError,
7784
testFipsCrypto() ? FIPS_ENABLED : FIPS_ENABLE_ERROR_STRING,
78-
'process.versions',
85+
'require("crypto").getFips()',
7986
process.env);
8087

8188
// --force-fips should raise an error if OpenSSL is not FIPS enabled.
8289
testHelper(
8390
testFipsCrypto() ? 'stdout' : 'stderr',
8491
['--force-fips'],
8592
testFipsCrypto() ? kNoFailure : kGenericUserError,
86-
testFipsCrypto() ? FIPS_ENABLED : FIPS_ENABLE_ERROR_STRING,
87-
'process.versions',
93+
testFipsCrypto() ? FIPS_ENABLED : FIPS_FORCE_ERROR_STRING,
94+
'require("crypto").getFips()',
8895
process.env);
8996

9097
// By default FIPS should be off in both FIPS and non-FIPS builds

0 commit comments

Comments
Β (0)
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Commit 8c4531b

Browse files
panvaaduh95
authored andcommitted
src: report why --enable-fips failed
The startup failure always appended the OpenSSL error queue, so when Node.js itself detected the missing fips provider it printed an error header followed by nothing. Report the reason instead. Signed-off-by: Filip Skokan <panva.ip@gmail.com> PR-URL: #64979 Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com> Reviewed-By: Richard Lau <richard.lau@ibm.com> Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
1 parent 28cad47 commit 8c4531b

4 files changed

Lines changed: 45 additions & 21 deletions

File tree

β€Žsrc/crypto/crypto_util.ccβ€Ž

Lines changed: 27 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -99,20 +99,36 @@ int NoPasswordCallback(char* buf, int size, int rwflag, void* u) {
9999
return0;
100100
}
101101

102-
boolProcessFipsOptions() {
103-
/* Override FIPS settings in configuration file, if needed. */
104-
if (per_process::cli_options->enable_fips_crypto ||
105-
per_process::cli_options->force_fips_crypto) {
102+
std::optional<std::string> ProcessFipsOptions() {
103+
constbool enable_fips = per_process::cli_options->enable_fips_crypto;
104+
constbool force_fips = per_process::cli_options->force_fips_crypto;
105+
if (!enable_fips && !force_fips) return std::nullopt;
106+
106107
#if OPENSSL_VERSION_MAJOR >= 3
107-
if (!ncrypto::testFipsEnabled()) returnfalse;
108-
returnncrypto::setFipsEnabled(true, nullptr);
109-
#else
110-
// TODO(@jasnell): Remove this ifdef branch when openssl 1.1.1 is
111-
// no longer supported.
112-
if (FIPS_mode() == 0) returnFIPS_mode_set(1);
108+
// Whether FIPS-approved implementations are reachable is decided by the
109+
// OpenSSL configuration, not by Node.js. Refuse to start rather than
110+
// restrict the default property query to a provider that is not there,
111+
// which would leave every operation failing as unsupported.
112+
if (!ncrypto::testFipsEnabled()) {
113+
const std::string option = force_fips ? "--force-fips" : "--enable-fips";
114+
return option + " requires an active OpenSSL provider named \"fips\". "
115+
"FIPS mode is configured through OpenSSL; see "
116+
"https://nodejs.org/api/crypto.html#fips-mode";
117+
}
113118
#endif
119+
120+
CryptoErrorList errors{CryptoErrorList::Option::NONE};
121+
if (!ncrypto::setFipsEnabled(true, &errors)) {
122+
std::string error = "OpenSSL error when trying to enable FIPS";
123+
if (!errors.empty()) error += ':';
124+
for (constauto& openssl_error : errors) {
125+
error += '\n';
126+
error += openssl_error;
127+
}
128+
return error;
114129
}
115-
returntrue;
130+
131+
return std::nullopt;
116132
}
117133

118134
boolInitCryptoOnce(Isolate* isolate) {

β€Žsrc/crypto/crypto_util.hβ€Ž

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,10 @@ constexpr T NumBitsToBytes(T bits) {
6262
return (bits / CHAR_BIT) + ((CHAR_BIT - 1 + (bits % CHAR_BIT)) / CHAR_BIT);
6363
}
6464

65-
boolProcessFipsOptions();
65+
// Applies the FIPS related command line options. Returns a description of
66+
// what went wrong, or std::nullopt when there was nothing to do or the
67+
// options were applied successfully.
68+
std::optional<std::string> ProcessFipsOptions();
6669

6770
boolInitCryptoOnce(v8::Isolate* isolate);
6871
voidInitCryptoOnce();

β€Žsrc/node.ccβ€Ž

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1168,6 +1168,7 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
11681168
if (!(flags & ProcessInitializationFlags::kNoInitOpenSSL)) {
11691169
#if HAVE_OPENSSL
11701170
#ifndef OPENSSL_IS_BORINGSSL
1171+
#if OPENSSL_VERSION_MAJOR >= 3
11711172
auto GetOpenSSLErrorString = []() -> std::string {
11721173
std::string ret;
11731174
ERR_print_errors_cb(
@@ -1183,7 +1184,6 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
11831184

11841185
// In the case of FIPS builds we should make sure
11851186
// the random source is properly initialized first.
1186-
#if OPENSSL_VERSION_MAJOR >= 3
11871187
// Call OPENSSL_init_crypto to initialize OPENSSL_INIT_LOAD_CONFIG to
11881188
// avoid the default behavior where errors raised during the parsing of the
11891189
// OpenSSL configuration file are not propagated and cannot be detected.
@@ -1244,12 +1244,10 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
12441244
OPENSSL_init();
12451245
}
12461246
#endif
1247-
if (!crypto::ProcessFipsOptions()) {
1247+
if (auto fips_error = crypto::ProcessFipsOptions()) {
12481248
result->exit_code_ = ExitCode::kGenericUserError;
12491249
result->early_return_ = true;
1250-
result->errors_.emplace_back(
1251-
"OpenSSL error when trying to enable FIPS:\n" +
1252-
GetOpenSSLErrorString());
1250+
result->errors_.emplace_back(std::move(*fips_error));
12531251
return result;
12541252
}
12551253

β€Žtest/parallel/test-crypto-fips.jsβ€Ž

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,14 @@ const FIPS_ERROR_STRING2 =
2121
'Error [ERR_CRYPTO_FIPS_FORCED]: Cannot set FIPS mode, it was forced with '+
2222
'--force-fips at startup.';
2323
constFIPS_UNSUPPORTED_ERROR_STRING='fips mode not supported';
24-
constFIPS_ENABLE_ERROR_STRING='OpenSSL error when trying to enable FIPS:';
24+
constFIPS_ENABLE_ERROR_STRING=
25+
hasOpenSSL3 ?
26+
'--enable-fips requires an active OpenSSL provider named "fips"' :
27+
'OpenSSL error when trying to enable FIPS:';
28+
constFIPS_FORCE_ERROR_STRING=
29+
hasOpenSSL3 ?
30+
'--force-fips requires an active OpenSSL provider named "fips"' :
31+
'OpenSSL error when trying to enable FIPS:';
2532

2633
constCNF_FIPS_ON=fixtures.path('openssl_fips_enabled.cnf');
2734
constCNF_FIPS_OFF=fixtures.path('openssl_fips_disabled.cnf');
@@ -75,16 +82,16 @@ testHelper(
7582
['--enable-fips'],
7683
testFipsCrypto() ? kNoFailure : kGenericUserError,
7784
testFipsCrypto() ? FIPS_ENABLED : FIPS_ENABLE_ERROR_STRING,
78-
'process.versions',
85+
'require("crypto").getFips()',
7986
process.env);
8087

8188
// --force-fips should raise an error if OpenSSL is not FIPS enabled.
8289
testHelper(
8390
testFipsCrypto() ? 'stdout' : 'stderr',
8491
['--force-fips'],
8592
testFipsCrypto() ? kNoFailure : kGenericUserError,
86-
testFipsCrypto() ? FIPS_ENABLED : FIPS_ENABLE_ERROR_STRING,
87-
'process.versions',
93+
testFipsCrypto() ? FIPS_ENABLED : FIPS_FORCE_ERROR_STRING,
94+
'require("crypto").getFips()',
8895
process.env);
8996

9097
// By default FIPS should be off in both FIPS and non-FIPS builds

0 commit comments

Comments
Β (0)
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Commit 8c4531b

Browse files
panvaaduh95
authored andcommitted
src: report why --enable-fips failed
The startup failure always appended the OpenSSL error queue, so when Node.js itself detected the missing fips provider it printed an error header followed by nothing. Report the reason instead. Signed-off-by: Filip Skokan <panva.ip@gmail.com> PR-URL: #64979 Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com> Reviewed-By: Richard Lau <richard.lau@ibm.com> Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
1 parent 28cad47 commit 8c4531b

4 files changed

Lines changed: 45 additions & 21 deletions

File tree

β€Žsrc/crypto/crypto_util.ccβ€Ž

Lines changed: 27 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -99,20 +99,36 @@ int NoPasswordCallback(char* buf, int size, int rwflag, void* u) {
9999
return0;
100100
}
101101

102-
boolProcessFipsOptions() {
103-
/* Override FIPS settings in configuration file, if needed. */
104-
if (per_process::cli_options->enable_fips_crypto ||
105-
per_process::cli_options->force_fips_crypto) {
102+
std::optional<std::string> ProcessFipsOptions() {
103+
constbool enable_fips = per_process::cli_options->enable_fips_crypto;
104+
constbool force_fips = per_process::cli_options->force_fips_crypto;
105+
if (!enable_fips && !force_fips) return std::nullopt;
106+
106107
#if OPENSSL_VERSION_MAJOR >= 3
107-
if (!ncrypto::testFipsEnabled()) returnfalse;
108-
returnncrypto::setFipsEnabled(true, nullptr);
109-
#else
110-
// TODO(@jasnell): Remove this ifdef branch when openssl 1.1.1 is
111-
// no longer supported.
112-
if (FIPS_mode() == 0) returnFIPS_mode_set(1);
108+
// Whether FIPS-approved implementations are reachable is decided by the
109+
// OpenSSL configuration, not by Node.js. Refuse to start rather than
110+
// restrict the default property query to a provider that is not there,
111+
// which would leave every operation failing as unsupported.
112+
if (!ncrypto::testFipsEnabled()) {
113+
const std::string option = force_fips ? "--force-fips" : "--enable-fips";
114+
return option + " requires an active OpenSSL provider named \"fips\". "
115+
"FIPS mode is configured through OpenSSL; see "
116+
"https://nodejs.org/api/crypto.html#fips-mode";
117+
}
113118
#endif
119+
120+
CryptoErrorList errors{CryptoErrorList::Option::NONE};
121+
if (!ncrypto::setFipsEnabled(true, &errors)) {
122+
std::string error = "OpenSSL error when trying to enable FIPS";
123+
if (!errors.empty()) error += ':';
124+
for (constauto& openssl_error : errors) {
125+
error += '\n';
126+
error += openssl_error;
127+
}
128+
return error;
114129
}
115-
returntrue;
130+
131+
return std::nullopt;
116132
}
117133

118134
boolInitCryptoOnce(Isolate* isolate) {

β€Žsrc/crypto/crypto_util.hβ€Ž

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,10 @@ constexpr T NumBitsToBytes(T bits) {
6262
return (bits / CHAR_BIT) + ((CHAR_BIT - 1 + (bits % CHAR_BIT)) / CHAR_BIT);
6363
}
6464

65-
boolProcessFipsOptions();
65+
// Applies the FIPS related command line options. Returns a description of
66+
// what went wrong, or std::nullopt when there was nothing to do or the
67+
// options were applied successfully.
68+
std::optional<std::string> ProcessFipsOptions();
6669

6770
boolInitCryptoOnce(v8::Isolate* isolate);
6871
voidInitCryptoOnce();

β€Žsrc/node.ccβ€Ž

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1168,6 +1168,7 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
11681168
if (!(flags & ProcessInitializationFlags::kNoInitOpenSSL)) {
11691169
#if HAVE_OPENSSL
11701170
#ifndef OPENSSL_IS_BORINGSSL
1171+
#if OPENSSL_VERSION_MAJOR >= 3
11711172
auto GetOpenSSLErrorString = []() -> std::string {
11721173
std::string ret;
11731174
ERR_print_errors_cb(
@@ -1183,7 +1184,6 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
11831184

11841185
// In the case of FIPS builds we should make sure
11851186
// the random source is properly initialized first.
1186-
#if OPENSSL_VERSION_MAJOR >= 3
11871187
// Call OPENSSL_init_crypto to initialize OPENSSL_INIT_LOAD_CONFIG to
11881188
// avoid the default behavior where errors raised during the parsing of the
11891189
// OpenSSL configuration file are not propagated and cannot be detected.
@@ -1244,12 +1244,10 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
12441244
OPENSSL_init();
12451245
}
12461246
#endif
1247-
if (!crypto::ProcessFipsOptions()) {
1247+
if (auto fips_error = crypto::ProcessFipsOptions()) {
12481248
result->exit_code_ = ExitCode::kGenericUserError;
12491249
result->early_return_ = true;
1250-
result->errors_.emplace_back(
1251-
"OpenSSL error when trying to enable FIPS:\n" +
1252-
GetOpenSSLErrorString());
1250+
result->errors_.emplace_back(std::move(*fips_error));
12531251
return result;
12541252
}
12551253

β€Žtest/parallel/test-crypto-fips.jsβ€Ž

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,14 @@ const FIPS_ERROR_STRING2 =
2121
'Error [ERR_CRYPTO_FIPS_FORCED]: Cannot set FIPS mode, it was forced with '+
2222
'--force-fips at startup.';
2323
constFIPS_UNSUPPORTED_ERROR_STRING='fips mode not supported';
24-
constFIPS_ENABLE_ERROR_STRING='OpenSSL error when trying to enable FIPS:';
24+
constFIPS_ENABLE_ERROR_STRING=
25+
hasOpenSSL3 ?
26+
'--enable-fips requires an active OpenSSL provider named "fips"' :
27+
'OpenSSL error when trying to enable FIPS:';
28+
constFIPS_FORCE_ERROR_STRING=
29+
hasOpenSSL3 ?
30+
'--force-fips requires an active OpenSSL provider named "fips"' :
31+
'OpenSSL error when trying to enable FIPS:';
2532

2633
constCNF_FIPS_ON=fixtures.path('openssl_fips_enabled.cnf');
2734
constCNF_FIPS_OFF=fixtures.path('openssl_fips_disabled.cnf');
@@ -75,16 +82,16 @@ testHelper(
7582
['--enable-fips'],
7683
testFipsCrypto() ? kNoFailure : kGenericUserError,
7784
testFipsCrypto() ? FIPS_ENABLED : FIPS_ENABLE_ERROR_STRING,
78-
'process.versions',
85+
'require("crypto").getFips()',
7986
process.env);
8087

8188
// --force-fips should raise an error if OpenSSL is not FIPS enabled.
8289
testHelper(
8390
testFipsCrypto() ? 'stdout' : 'stderr',
8491
['--force-fips'],
8592
testFipsCrypto() ? kNoFailure : kGenericUserError,
86-
testFipsCrypto() ? FIPS_ENABLED : FIPS_ENABLE_ERROR_STRING,
87-
'process.versions',
93+
testFipsCrypto() ? FIPS_ENABLED : FIPS_FORCE_ERROR_STRING,
94+
'require("crypto").getFips()',
8895
process.env);
8996

9097
// By default FIPS should be off in both FIPS and non-FIPS builds

0 commit comments

Comments
Β (0)
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Commit 8c4531b

Browse files
panvaaduh95
authored andcommitted
src: report why --enable-fips failed
The startup failure always appended the OpenSSL error queue, so when Node.js itself detected the missing fips provider it printed an error header followed by nothing. Report the reason instead. Signed-off-by: Filip Skokan <panva.ip@gmail.com> PR-URL: #64979 Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com> Reviewed-By: Richard Lau <richard.lau@ibm.com> Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
1 parent 28cad47 commit 8c4531b

4 files changed

Lines changed: 45 additions & 21 deletions

File tree

β€Žsrc/crypto/crypto_util.ccβ€Ž

Lines changed: 27 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -99,20 +99,36 @@ int NoPasswordCallback(char* buf, int size, int rwflag, void* u) {
9999
return0;
100100
}
101101

102-
boolProcessFipsOptions() {
103-
/* Override FIPS settings in configuration file, if needed. */
104-
if (per_process::cli_options->enable_fips_crypto ||
105-
per_process::cli_options->force_fips_crypto) {
102+
std::optional<std::string> ProcessFipsOptions() {
103+
constbool enable_fips = per_process::cli_options->enable_fips_crypto;
104+
constbool force_fips = per_process::cli_options->force_fips_crypto;
105+
if (!enable_fips && !force_fips) return std::nullopt;
106+
106107
#if OPENSSL_VERSION_MAJOR >= 3
107-
if (!ncrypto::testFipsEnabled()) returnfalse;
108-
returnncrypto::setFipsEnabled(true, nullptr);
109-
#else
110-
// TODO(@jasnell): Remove this ifdef branch when openssl 1.1.1 is
111-
// no longer supported.
112-
if (FIPS_mode() == 0) returnFIPS_mode_set(1);
108+
// Whether FIPS-approved implementations are reachable is decided by the
109+
// OpenSSL configuration, not by Node.js. Refuse to start rather than
110+
// restrict the default property query to a provider that is not there,
111+
// which would leave every operation failing as unsupported.
112+
if (!ncrypto::testFipsEnabled()) {
113+
const std::string option = force_fips ? "--force-fips" : "--enable-fips";
114+
return option + " requires an active OpenSSL provider named \"fips\". "
115+
"FIPS mode is configured through OpenSSL; see "
116+
"https://nodejs.org/api/crypto.html#fips-mode";
117+
}
113118
#endif
119+
120+
CryptoErrorList errors{CryptoErrorList::Option::NONE};
121+
if (!ncrypto::setFipsEnabled(true, &errors)) {
122+
std::string error = "OpenSSL error when trying to enable FIPS";
123+
if (!errors.empty()) error += ':';
124+
for (constauto& openssl_error : errors) {
125+
error += '\n';
126+
error += openssl_error;
127+
}
128+
return error;
114129
}
115-
returntrue;
130+
131+
return std::nullopt;
116132
}
117133

118134
boolInitCryptoOnce(Isolate* isolate) {

β€Žsrc/crypto/crypto_util.hβ€Ž

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,10 @@ constexpr T NumBitsToBytes(T bits) {
6262
return (bits / CHAR_BIT) + ((CHAR_BIT - 1 + (bits % CHAR_BIT)) / CHAR_BIT);
6363
}
6464

65-
boolProcessFipsOptions();
65+
// Applies the FIPS related command line options. Returns a description of
66+
// what went wrong, or std::nullopt when there was nothing to do or the
67+
// options were applied successfully.
68+
std::optional<std::string> ProcessFipsOptions();
6669

6770
boolInitCryptoOnce(v8::Isolate* isolate);
6871
voidInitCryptoOnce();

β€Žsrc/node.ccβ€Ž

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1168,6 +1168,7 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
11681168
if (!(flags & ProcessInitializationFlags::kNoInitOpenSSL)) {
11691169
#if HAVE_OPENSSL
11701170
#ifndef OPENSSL_IS_BORINGSSL
1171+
#if OPENSSL_VERSION_MAJOR >= 3
11711172
auto GetOpenSSLErrorString = []() -> std::string {
11721173
std::string ret;
11731174
ERR_print_errors_cb(
@@ -1183,7 +1184,6 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
11831184

11841185
// In the case of FIPS builds we should make sure
11851186
// the random source is properly initialized first.
1186-
#if OPENSSL_VERSION_MAJOR >= 3
11871187
// Call OPENSSL_init_crypto to initialize OPENSSL_INIT_LOAD_CONFIG to
11881188
// avoid the default behavior where errors raised during the parsing of the
11891189
// OpenSSL configuration file are not propagated and cannot be detected.
@@ -1244,12 +1244,10 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
12441244
OPENSSL_init();
12451245
}
12461246
#endif
1247-
if (!crypto::ProcessFipsOptions()) {
1247+
if (auto fips_error = crypto::ProcessFipsOptions()) {
12481248
result->exit_code_ = ExitCode::kGenericUserError;
12491249
result->early_return_ = true;
1250-
result->errors_.emplace_back(
1251-
"OpenSSL error when trying to enable FIPS:\n" +
1252-
GetOpenSSLErrorString());
1250+
result->errors_.emplace_back(std::move(*fips_error));
12531251
return result;
12541252
}
12551253

β€Žtest/parallel/test-crypto-fips.jsβ€Ž

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,14 @@ const FIPS_ERROR_STRING2 =
2121
'Error [ERR_CRYPTO_FIPS_FORCED]: Cannot set FIPS mode, it was forced with '+
2222
'--force-fips at startup.';
2323
constFIPS_UNSUPPORTED_ERROR_STRING='fips mode not supported';
24-
constFIPS_ENABLE_ERROR_STRING='OpenSSL error when trying to enable FIPS:';
24+
constFIPS_ENABLE_ERROR_STRING=
25+
hasOpenSSL3 ?
26+
'--enable-fips requires an active OpenSSL provider named "fips"' :
27+
'OpenSSL error when trying to enable FIPS:';
28+
constFIPS_FORCE_ERROR_STRING=
29+
hasOpenSSL3 ?
30+
'--force-fips requires an active OpenSSL provider named "fips"' :
31+
'OpenSSL error when trying to enable FIPS:';
2532

2633
constCNF_FIPS_ON=fixtures.path('openssl_fips_enabled.cnf');
2734
constCNF_FIPS_OFF=fixtures.path('openssl_fips_disabled.cnf');
@@ -75,16 +82,16 @@ testHelper(
7582
['--enable-fips'],
7683
testFipsCrypto() ? kNoFailure : kGenericUserError,
7784
testFipsCrypto() ? FIPS_ENABLED : FIPS_ENABLE_ERROR_STRING,
78-
'process.versions',
85+
'require("crypto").getFips()',
7986
process.env);
8087

8188
// --force-fips should raise an error if OpenSSL is not FIPS enabled.
8289
testHelper(
8390
testFipsCrypto() ? 'stdout' : 'stderr',
8491
['--force-fips'],
8592
testFipsCrypto() ? kNoFailure : kGenericUserError,
86-
testFipsCrypto() ? FIPS_ENABLED : FIPS_ENABLE_ERROR_STRING,
87-
'process.versions',
93+
testFipsCrypto() ? FIPS_ENABLED : FIPS_FORCE_ERROR_STRING,
94+
'require("crypto").getFips()',
8895
process.env);
8996

9097
// By default FIPS should be off in both FIPS and non-FIPS builds

0 commit comments

Comments
Β (0)
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Commit 8c4531b

Browse files
panvaaduh95
authored andcommitted
src: report why --enable-fips failed
The startup failure always appended the OpenSSL error queue, so when Node.js itself detected the missing fips provider it printed an error header followed by nothing. Report the reason instead. Signed-off-by: Filip Skokan <panva.ip@gmail.com> PR-URL: #64979 Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com> Reviewed-By: Richard Lau <richard.lau@ibm.com> Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
1 parent 28cad47 commit 8c4531b

4 files changed

Lines changed: 45 additions & 21 deletions

File tree

β€Žsrc/crypto/crypto_util.ccβ€Ž

Lines changed: 27 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -99,20 +99,36 @@ int NoPasswordCallback(char* buf, int size, int rwflag, void* u) {
9999
return0;
100100
}
101101

102-
boolProcessFipsOptions() {
103-
/* Override FIPS settings in configuration file, if needed. */
104-
if (per_process::cli_options->enable_fips_crypto ||
105-
per_process::cli_options->force_fips_crypto) {
102+
std::optional<std::string> ProcessFipsOptions() {
103+
constbool enable_fips = per_process::cli_options->enable_fips_crypto;
104+
constbool force_fips = per_process::cli_options->force_fips_crypto;
105+
if (!enable_fips && !force_fips) return std::nullopt;
106+
106107
#if OPENSSL_VERSION_MAJOR >= 3
107-
if (!ncrypto::testFipsEnabled()) returnfalse;
108-
returnncrypto::setFipsEnabled(true, nullptr);
109-
#else
110-
// TODO(@jasnell): Remove this ifdef branch when openssl 1.1.1 is
111-
// no longer supported.
112-
if (FIPS_mode() == 0) returnFIPS_mode_set(1);
108+
// Whether FIPS-approved implementations are reachable is decided by the
109+
// OpenSSL configuration, not by Node.js. Refuse to start rather than
110+
// restrict the default property query to a provider that is not there,
111+
// which would leave every operation failing as unsupported.
112+
if (!ncrypto::testFipsEnabled()) {
113+
const std::string option = force_fips ? "--force-fips" : "--enable-fips";
114+
return option + " requires an active OpenSSL provider named \"fips\". "
115+
"FIPS mode is configured through OpenSSL; see "
116+
"https://nodejs.org/api/crypto.html#fips-mode";
117+
}
113118
#endif
119+
120+
CryptoErrorList errors{CryptoErrorList::Option::NONE};
121+
if (!ncrypto::setFipsEnabled(true, &errors)) {
122+
std::string error = "OpenSSL error when trying to enable FIPS";
123+
if (!errors.empty()) error += ':';
124+
for (constauto& openssl_error : errors) {
125+
error += '\n';
126+
error += openssl_error;
127+
}
128+
return error;
114129
}
115-
returntrue;
130+
131+
return std::nullopt;
116132
}
117133

118134
boolInitCryptoOnce(Isolate* isolate) {

β€Žsrc/crypto/crypto_util.hβ€Ž

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,10 @@ constexpr T NumBitsToBytes(T bits) {
6262
return (bits / CHAR_BIT) + ((CHAR_BIT - 1 + (bits % CHAR_BIT)) / CHAR_BIT);
6363
}
6464

65-
boolProcessFipsOptions();
65+
// Applies the FIPS related command line options. Returns a description of
66+
// what went wrong, or std::nullopt when there was nothing to do or the
67+
// options were applied successfully.
68+
std::optional<std::string> ProcessFipsOptions();
6669

6770
boolInitCryptoOnce(v8::Isolate* isolate);
6871
voidInitCryptoOnce();

β€Žsrc/node.ccβ€Ž

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1168,6 +1168,7 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
11681168
if (!(flags & ProcessInitializationFlags::kNoInitOpenSSL)) {
11691169
#if HAVE_OPENSSL
11701170
#ifndef OPENSSL_IS_BORINGSSL
1171+
#if OPENSSL_VERSION_MAJOR >= 3
11711172
auto GetOpenSSLErrorString = []() -> std::string {
11721173
std::string ret;
11731174
ERR_print_errors_cb(
@@ -1183,7 +1184,6 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
11831184

11841185
// In the case of FIPS builds we should make sure
11851186
// the random source is properly initialized first.
1186-
#if OPENSSL_VERSION_MAJOR >= 3
11871187
// Call OPENSSL_init_crypto to initialize OPENSSL_INIT_LOAD_CONFIG to
11881188
// avoid the default behavior where errors raised during the parsing of the
11891189
// OpenSSL configuration file are not propagated and cannot be detected.
@@ -1244,12 +1244,10 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
12441244
OPENSSL_init();
12451245
}
12461246
#endif
1247-
if (!crypto::ProcessFipsOptions()) {
1247+
if (auto fips_error = crypto::ProcessFipsOptions()) {
12481248
result->exit_code_ = ExitCode::kGenericUserError;
12491249
result->early_return_ = true;
1250-
result->errors_.emplace_back(
1251-
"OpenSSL error when trying to enable FIPS:\n" +
1252-
GetOpenSSLErrorString());
1250+
result->errors_.emplace_back(std::move(*fips_error));
12531251
return result;
12541252
}
12551253

β€Žtest/parallel/test-crypto-fips.jsβ€Ž

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,14 @@ const FIPS_ERROR_STRING2 =
2121
'Error [ERR_CRYPTO_FIPS_FORCED]: Cannot set FIPS mode, it was forced with '+
2222
'--force-fips at startup.';
2323
constFIPS_UNSUPPORTED_ERROR_STRING='fips mode not supported';
24-
constFIPS_ENABLE_ERROR_STRING='OpenSSL error when trying to enable FIPS:';
24+
constFIPS_ENABLE_ERROR_STRING=
25+
hasOpenSSL3 ?
26+
'--enable-fips requires an active OpenSSL provider named "fips"' :
27+
'OpenSSL error when trying to enable FIPS:';
28+
constFIPS_FORCE_ERROR_STRING=
29+
hasOpenSSL3 ?
30+
'--force-fips requires an active OpenSSL provider named "fips"' :
31+
'OpenSSL error when trying to enable FIPS:';
2532

2633
constCNF_FIPS_ON=fixtures.path('openssl_fips_enabled.cnf');
2734
constCNF_FIPS_OFF=fixtures.path('openssl_fips_disabled.cnf');
@@ -75,16 +82,16 @@ testHelper(
7582
['--enable-fips'],
7683
testFipsCrypto() ? kNoFailure : kGenericUserError,
7784
testFipsCrypto() ? FIPS_ENABLED : FIPS_ENABLE_ERROR_STRING,
78-
'process.versions',
85+
'require("crypto").getFips()',
7986
process.env);
8087

8188
// --force-fips should raise an error if OpenSSL is not FIPS enabled.
8289
testHelper(
8390
testFipsCrypto() ? 'stdout' : 'stderr',
8491
['--force-fips'],
8592
testFipsCrypto() ? kNoFailure : kGenericUserError,
86-
testFipsCrypto() ? FIPS_ENABLED : FIPS_ENABLE_ERROR_STRING,
87-
'process.versions',
93+
testFipsCrypto() ? FIPS_ENABLED : FIPS_FORCE_ERROR_STRING,
94+
'require("crypto").getFips()',
8895
process.env);
8996

9097
// By default FIPS should be off in both FIPS and non-FIPS builds

0 commit comments

Comments
Β (0)
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Commit 8c4531b

Browse files
panvaaduh95
authored andcommitted
src: report why --enable-fips failed
The startup failure always appended the OpenSSL error queue, so when Node.js itself detected the missing fips provider it printed an error header followed by nothing. Report the reason instead. Signed-off-by: Filip Skokan <panva.ip@gmail.com> PR-URL: #64979 Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com> Reviewed-By: Richard Lau <richard.lau@ibm.com> Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
1 parent 28cad47 commit 8c4531b

4 files changed

Lines changed: 45 additions & 21 deletions

File tree

β€Žsrc/crypto/crypto_util.ccβ€Ž

Lines changed: 27 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -99,20 +99,36 @@ int NoPasswordCallback(char* buf, int size, int rwflag, void* u) {
9999
return0;
100100
}
101101

102-
boolProcessFipsOptions() {
103-
/* Override FIPS settings in configuration file, if needed. */
104-
if (per_process::cli_options->enable_fips_crypto ||
105-
per_process::cli_options->force_fips_crypto) {
102+
std::optional<std::string> ProcessFipsOptions() {
103+
constbool enable_fips = per_process::cli_options->enable_fips_crypto;
104+
constbool force_fips = per_process::cli_options->force_fips_crypto;
105+
if (!enable_fips && !force_fips) return std::nullopt;
106+
106107
#if OPENSSL_VERSION_MAJOR >= 3
107-
if (!ncrypto::testFipsEnabled()) returnfalse;
108-
returnncrypto::setFipsEnabled(true, nullptr);
109-
#else
110-
// TODO(@jasnell): Remove this ifdef branch when openssl 1.1.1 is
111-
// no longer supported.
112-
if (FIPS_mode() == 0) returnFIPS_mode_set(1);
108+
// Whether FIPS-approved implementations are reachable is decided by the
109+
// OpenSSL configuration, not by Node.js. Refuse to start rather than
110+
// restrict the default property query to a provider that is not there,
111+
// which would leave every operation failing as unsupported.
112+
if (!ncrypto::testFipsEnabled()) {
113+
const std::string option = force_fips ? "--force-fips" : "--enable-fips";
114+
return option + " requires an active OpenSSL provider named \"fips\". "
115+
"FIPS mode is configured through OpenSSL; see "
116+
"https://nodejs.org/api/crypto.html#fips-mode";
117+
}
113118
#endif
119+
120+
CryptoErrorList errors{CryptoErrorList::Option::NONE};
121+
if (!ncrypto::setFipsEnabled(true, &errors)) {
122+
std::string error = "OpenSSL error when trying to enable FIPS";
123+
if (!errors.empty()) error += ':';
124+
for (constauto& openssl_error : errors) {
125+
error += '\n';
126+
error += openssl_error;
127+
}
128+
return error;
114129
}
115-
returntrue;
130+
131+
return std::nullopt;
116132
}
117133

118134
boolInitCryptoOnce(Isolate* isolate) {

β€Žsrc/crypto/crypto_util.hβ€Ž

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,10 @@ constexpr T NumBitsToBytes(T bits) {
6262
return (bits / CHAR_BIT) + ((CHAR_BIT - 1 + (bits % CHAR_BIT)) / CHAR_BIT);
6363
}
6464

65-
boolProcessFipsOptions();
65+
// Applies the FIPS related command line options. Returns a description of
66+
// what went wrong, or std::nullopt when there was nothing to do or the
67+
// options were applied successfully.
68+
std::optional<std::string> ProcessFipsOptions();
6669

6770
boolInitCryptoOnce(v8::Isolate* isolate);
6871
voidInitCryptoOnce();

β€Žsrc/node.ccβ€Ž

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1168,6 +1168,7 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
11681168
if (!(flags & ProcessInitializationFlags::kNoInitOpenSSL)) {
11691169
#if HAVE_OPENSSL
11701170
#ifndef OPENSSL_IS_BORINGSSL
1171+
#if OPENSSL_VERSION_MAJOR >= 3
11711172
auto GetOpenSSLErrorString = []() -> std::string {
11721173
std::string ret;
11731174
ERR_print_errors_cb(
@@ -1183,7 +1184,6 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
11831184

11841185
// In the case of FIPS builds we should make sure
11851186
// the random source is properly initialized first.
1186-
#if OPENSSL_VERSION_MAJOR >= 3
11871187
// Call OPENSSL_init_crypto to initialize OPENSSL_INIT_LOAD_CONFIG to
11881188
// avoid the default behavior where errors raised during the parsing of the
11891189
// OpenSSL configuration file are not propagated and cannot be detected.
@@ -1244,12 +1244,10 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
12441244
OPENSSL_init();
12451245
}
12461246
#endif
1247-
if (!crypto::ProcessFipsOptions()) {
1247+
if (auto fips_error = crypto::ProcessFipsOptions()) {
12481248
result->exit_code_ = ExitCode::kGenericUserError;
12491249
result->early_return_ = true;
1250-
result->errors_.emplace_back(
1251-
"OpenSSL error when trying to enable FIPS:\n" +
1252-
GetOpenSSLErrorString());
1250+
result->errors_.emplace_back(std::move(*fips_error));
12531251
return result;
12541252
}
12551253

β€Žtest/parallel/test-crypto-fips.jsβ€Ž

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,14 @@ const FIPS_ERROR_STRING2 =
2121
'Error [ERR_CRYPTO_FIPS_FORCED]: Cannot set FIPS mode, it was forced with '+
2222
'--force-fips at startup.';
2323
constFIPS_UNSUPPORTED_ERROR_STRING='fips mode not supported';
24-
constFIPS_ENABLE_ERROR_STRING='OpenSSL error when trying to enable FIPS:';
24+
constFIPS_ENABLE_ERROR_STRING=
25+
hasOpenSSL3 ?
26+
'--enable-fips requires an active OpenSSL provider named "fips"' :
27+
'OpenSSL error when trying to enable FIPS:';
28+
constFIPS_FORCE_ERROR_STRING=
29+
hasOpenSSL3 ?
30+
'--force-fips requires an active OpenSSL provider named "fips"' :
31+
'OpenSSL error when trying to enable FIPS:';
2532

2633
constCNF_FIPS_ON=fixtures.path('openssl_fips_enabled.cnf');
2734
constCNF_FIPS_OFF=fixtures.path('openssl_fips_disabled.cnf');
@@ -75,16 +82,16 @@ testHelper(
7582
['--enable-fips'],
7683
testFipsCrypto() ? kNoFailure : kGenericUserError,
7784
testFipsCrypto() ? FIPS_ENABLED : FIPS_ENABLE_ERROR_STRING,
78-
'process.versions',
85+
'require("crypto").getFips()',
7986
process.env);
8087

8188
// --force-fips should raise an error if OpenSSL is not FIPS enabled.
8289
testHelper(
8390
testFipsCrypto() ? 'stdout' : 'stderr',
8491
['--force-fips'],
8592
testFipsCrypto() ? kNoFailure : kGenericUserError,
86-
testFipsCrypto() ? FIPS_ENABLED : FIPS_ENABLE_ERROR_STRING,
87-
'process.versions',
93+
testFipsCrypto() ? FIPS_ENABLED : FIPS_FORCE_ERROR_STRING,
94+
'require("crypto").getFips()',
8895
process.env);
8996

9097
// By default FIPS should be off in both FIPS and non-FIPS builds

0 commit comments

Comments
Β (0)
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Commit 8c4531b

Browse files
panvaaduh95
authored andcommitted
src: report why --enable-fips failed
The startup failure always appended the OpenSSL error queue, so when Node.js itself detected the missing fips provider it printed an error header followed by nothing. Report the reason instead. Signed-off-by: Filip Skokan <panva.ip@gmail.com> PR-URL: #64979 Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com> Reviewed-By: Richard Lau <richard.lau@ibm.com> Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
1 parent 28cad47 commit 8c4531b

4 files changed

Lines changed: 45 additions & 21 deletions

File tree

β€Žsrc/crypto/crypto_util.ccβ€Ž

Lines changed: 27 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -99,20 +99,36 @@ int NoPasswordCallback(char* buf, int size, int rwflag, void* u) {
9999
return0;
100100
}
101101

102-
boolProcessFipsOptions() {
103-
/* Override FIPS settings in configuration file, if needed. */
104-
if (per_process::cli_options->enable_fips_crypto ||
105-
per_process::cli_options->force_fips_crypto) {
102+
std::optional<std::string> ProcessFipsOptions() {
103+
constbool enable_fips = per_process::cli_options->enable_fips_crypto;
104+
constbool force_fips = per_process::cli_options->force_fips_crypto;
105+
if (!enable_fips && !force_fips) return std::nullopt;
106+
106107
#if OPENSSL_VERSION_MAJOR >= 3
107-
if (!ncrypto::testFipsEnabled()) returnfalse;
108-
returnncrypto::setFipsEnabled(true, nullptr);
109-
#else
110-
// TODO(@jasnell): Remove this ifdef branch when openssl 1.1.1 is
111-
// no longer supported.
112-
if (FIPS_mode() == 0) returnFIPS_mode_set(1);
108+
// Whether FIPS-approved implementations are reachable is decided by the
109+
// OpenSSL configuration, not by Node.js. Refuse to start rather than
110+
// restrict the default property query to a provider that is not there,
111+
// which would leave every operation failing as unsupported.
112+
if (!ncrypto::testFipsEnabled()) {
113+
const std::string option = force_fips ? "--force-fips" : "--enable-fips";
114+
return option + " requires an active OpenSSL provider named \"fips\". "
115+
"FIPS mode is configured through OpenSSL; see "
116+
"https://nodejs.org/api/crypto.html#fips-mode";
117+
}
113118
#endif
119+
120+
CryptoErrorList errors{CryptoErrorList::Option::NONE};
121+
if (!ncrypto::setFipsEnabled(true, &errors)) {
122+
std::string error = "OpenSSL error when trying to enable FIPS";
123+
if (!errors.empty()) error += ':';
124+
for (constauto& openssl_error : errors) {
125+
error += '\n';
126+
error += openssl_error;
127+
}
128+
return error;
114129
}
115-
returntrue;
130+
131+
return std::nullopt;
116132
}
117133

118134
boolInitCryptoOnce(Isolate* isolate) {

β€Žsrc/crypto/crypto_util.hβ€Ž

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,10 @@ constexpr T NumBitsToBytes(T bits) {
6262
return (bits / CHAR_BIT) + ((CHAR_BIT - 1 + (bits % CHAR_BIT)) / CHAR_BIT);
6363
}
6464

65-
boolProcessFipsOptions();
65+
// Applies the FIPS related command line options. Returns a description of
66+
// what went wrong, or std::nullopt when there was nothing to do or the
67+
// options were applied successfully.
68+
std::optional<std::string> ProcessFipsOptions();
6669

6770
boolInitCryptoOnce(v8::Isolate* isolate);
6871
voidInitCryptoOnce();

β€Žsrc/node.ccβ€Ž

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1168,6 +1168,7 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
11681168
if (!(flags & ProcessInitializationFlags::kNoInitOpenSSL)) {
11691169
#if HAVE_OPENSSL
11701170
#ifndef OPENSSL_IS_BORINGSSL
1171+
#if OPENSSL_VERSION_MAJOR >= 3
11711172
auto GetOpenSSLErrorString = []() -> std::string {
11721173
std::string ret;
11731174
ERR_print_errors_cb(
@@ -1183,7 +1184,6 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
11831184

11841185
// In the case of FIPS builds we should make sure
11851186
// the random source is properly initialized first.
1186-
#if OPENSSL_VERSION_MAJOR >= 3
11871187
// Call OPENSSL_init_crypto to initialize OPENSSL_INIT_LOAD_CONFIG to
11881188
// avoid the default behavior where errors raised during the parsing of the
11891189
// OpenSSL configuration file are not propagated and cannot be detected.
@@ -1244,12 +1244,10 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
12441244
OPENSSL_init();
12451245
}
12461246
#endif
1247-
if (!crypto::ProcessFipsOptions()) {
1247+
if (auto fips_error = crypto::ProcessFipsOptions()) {
12481248
result->exit_code_ = ExitCode::kGenericUserError;
12491249
result->early_return_ = true;
1250-
result->errors_.emplace_back(
1251-
"OpenSSL error when trying to enable FIPS:\n" +
1252-
GetOpenSSLErrorString());
1250+
result->errors_.emplace_back(std::move(*fips_error));
12531251
return result;
12541252
}
12551253

β€Žtest/parallel/test-crypto-fips.jsβ€Ž

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,14 @@ const FIPS_ERROR_STRING2 =
2121
'Error [ERR_CRYPTO_FIPS_FORCED]: Cannot set FIPS mode, it was forced with '+
2222
'--force-fips at startup.';
2323
constFIPS_UNSUPPORTED_ERROR_STRING='fips mode not supported';
24-
constFIPS_ENABLE_ERROR_STRING='OpenSSL error when trying to enable FIPS:';
24+
constFIPS_ENABLE_ERROR_STRING=
25+
hasOpenSSL3 ?
26+
'--enable-fips requires an active OpenSSL provider named "fips"' :
27+
'OpenSSL error when trying to enable FIPS:';
28+
constFIPS_FORCE_ERROR_STRING=
29+
hasOpenSSL3 ?
30+
'--force-fips requires an active OpenSSL provider named "fips"' :
31+
'OpenSSL error when trying to enable FIPS:';
2532

2633
constCNF_FIPS_ON=fixtures.path('openssl_fips_enabled.cnf');
2734
constCNF_FIPS_OFF=fixtures.path('openssl_fips_disabled.cnf');
@@ -75,16 +82,16 @@ testHelper(
7582
['--enable-fips'],
7683
testFipsCrypto() ? kNoFailure : kGenericUserError,
7784
testFipsCrypto() ? FIPS_ENABLED : FIPS_ENABLE_ERROR_STRING,
78-
'process.versions',
85+
'require("crypto").getFips()',
7986
process.env);
8087

8188
// --force-fips should raise an error if OpenSSL is not FIPS enabled.
8289
testHelper(
8390
testFipsCrypto() ? 'stdout' : 'stderr',
8491
['--force-fips'],
8592
testFipsCrypto() ? kNoFailure : kGenericUserError,
86-
testFipsCrypto() ? FIPS_ENABLED : FIPS_ENABLE_ERROR_STRING,
87-
'process.versions',
93+
testFipsCrypto() ? FIPS_ENABLED : FIPS_FORCE_ERROR_STRING,
94+
'require("crypto").getFips()',
8895
process.env);
8996

9097
// By default FIPS should be off in both FIPS and non-FIPS builds

0 commit comments

Comments
Β (0)
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Commit 8c4531b

Browse files
panvaaduh95
authored andcommitted
src: report why --enable-fips failed
The startup failure always appended the OpenSSL error queue, so when Node.js itself detected the missing fips provider it printed an error header followed by nothing. Report the reason instead. Signed-off-by: Filip Skokan <panva.ip@gmail.com> PR-URL: #64979 Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com> Reviewed-By: Richard Lau <richard.lau@ibm.com> Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
1 parent 28cad47 commit 8c4531b

4 files changed

Lines changed: 45 additions & 21 deletions

File tree

β€Žsrc/crypto/crypto_util.ccβ€Ž

Lines changed: 27 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -99,20 +99,36 @@ int NoPasswordCallback(char* buf, int size, int rwflag, void* u) {
9999
return0;
100100
}
101101

102-
boolProcessFipsOptions() {
103-
/* Override FIPS settings in configuration file, if needed. */
104-
if (per_process::cli_options->enable_fips_crypto ||
105-
per_process::cli_options->force_fips_crypto) {
102+
std::optional<std::string> ProcessFipsOptions() {
103+
constbool enable_fips = per_process::cli_options->enable_fips_crypto;
104+
constbool force_fips = per_process::cli_options->force_fips_crypto;
105+
if (!enable_fips && !force_fips) return std::nullopt;
106+
106107
#if OPENSSL_VERSION_MAJOR >= 3
107-
if (!ncrypto::testFipsEnabled()) returnfalse;
108-
returnncrypto::setFipsEnabled(true, nullptr);
109-
#else
110-
// TODO(@jasnell): Remove this ifdef branch when openssl 1.1.1 is
111-
// no longer supported.
112-
if (FIPS_mode() == 0) returnFIPS_mode_set(1);
108+
// Whether FIPS-approved implementations are reachable is decided by the
109+
// OpenSSL configuration, not by Node.js. Refuse to start rather than
110+
// restrict the default property query to a provider that is not there,
111+
// which would leave every operation failing as unsupported.
112+
if (!ncrypto::testFipsEnabled()) {
113+
const std::string option = force_fips ? "--force-fips" : "--enable-fips";
114+
return option + " requires an active OpenSSL provider named \"fips\". "
115+
"FIPS mode is configured through OpenSSL; see "
116+
"https://nodejs.org/api/crypto.html#fips-mode";
117+
}
113118
#endif
119+
120+
CryptoErrorList errors{CryptoErrorList::Option::NONE};
121+
if (!ncrypto::setFipsEnabled(true, &errors)) {
122+
std::string error = "OpenSSL error when trying to enable FIPS";
123+
if (!errors.empty()) error += ':';
124+
for (constauto& openssl_error : errors) {
125+
error += '\n';
126+
error += openssl_error;
127+
}
128+
return error;
114129
}
115-
returntrue;
130+
131+
return std::nullopt;
116132
}
117133

118134
boolInitCryptoOnce(Isolate* isolate) {

β€Žsrc/crypto/crypto_util.hβ€Ž

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,10 @@ constexpr T NumBitsToBytes(T bits) {
6262
return (bits / CHAR_BIT) + ((CHAR_BIT - 1 + (bits % CHAR_BIT)) / CHAR_BIT);
6363
}
6464

65-
boolProcessFipsOptions();
65+
// Applies the FIPS related command line options. Returns a description of
66+
// what went wrong, or std::nullopt when there was nothing to do or the
67+
// options were applied successfully.
68+
std::optional<std::string> ProcessFipsOptions();
6669

6770
boolInitCryptoOnce(v8::Isolate* isolate);
6871
voidInitCryptoOnce();

β€Žsrc/node.ccβ€Ž

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1168,6 +1168,7 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
11681168
if (!(flags & ProcessInitializationFlags::kNoInitOpenSSL)) {
11691169
#if HAVE_OPENSSL
11701170
#ifndef OPENSSL_IS_BORINGSSL
1171+
#if OPENSSL_VERSION_MAJOR >= 3
11711172
auto GetOpenSSLErrorString = []() -> std::string {
11721173
std::string ret;
11731174
ERR_print_errors_cb(
@@ -1183,7 +1184,6 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
11831184

11841185
// In the case of FIPS builds we should make sure
11851186
// the random source is properly initialized first.
1186-
#if OPENSSL_VERSION_MAJOR >= 3
11871187
// Call OPENSSL_init_crypto to initialize OPENSSL_INIT_LOAD_CONFIG to
11881188
// avoid the default behavior where errors raised during the parsing of the
11891189
// OpenSSL configuration file are not propagated and cannot be detected.
@@ -1244,12 +1244,10 @@ InitializeOncePerProcessInternal(const std::vector<std::string>& args,
12441244
OPENSSL_init();
12451245
}
12461246
#endif
1247-
if (!crypto::ProcessFipsOptions()) {
1247+
if (auto fips_error = crypto::ProcessFipsOptions()) {
12481248
result->exit_code_ = ExitCode::kGenericUserError;
12491249
result->early_return_ = true;
1250-
result->errors_.emplace_back(
1251-
"OpenSSL error when trying to enable FIPS:\n" +
1252-
GetOpenSSLErrorString());
1250+
result->errors_.emplace_back(std::move(*fips_error));
12531251
return result;
12541252
}
12551253

β€Žtest/parallel/test-crypto-fips.jsβ€Ž

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,14 @@ const FIPS_ERROR_STRING2 =
2121
'Error [ERR_CRYPTO_FIPS_FORCED]: Cannot set FIPS mode, it was forced with '+
2222
'--force-fips at startup.';
2323
constFIPS_UNSUPPORTED_ERROR_STRING='fips mode not supported';
24-
constFIPS_ENABLE_ERROR_STRING='OpenSSL error when trying to enable FIPS:';
24+
constFIPS_ENABLE_ERROR_STRING=
25+
hasOpenSSL3 ?
26+
'--enable-fips requires an active OpenSSL provider named "fips"' :
27+
'OpenSSL error when trying to enable FIPS:';
28+
constFIPS_FORCE_ERROR_STRING=
29+
hasOpenSSL3 ?
30+
'--force-fips requires an active OpenSSL provider named "fips"' :
31+
'OpenSSL error when trying to enable FIPS:';
2532

2633
constCNF_FIPS_ON=fixtures.path('openssl_fips_enabled.cnf');
2734
constCNF_FIPS_OFF=fixtures.path('openssl_fips_disabled.cnf');
@@ -75,16 +82,16 @@ testHelper(
7582
['--enable-fips'],
7683
testFipsCrypto() ? kNoFailure : kGenericUserError,
7784
testFipsCrypto() ? FIPS_ENABLED : FIPS_ENABLE_ERROR_STRING,
78-
'process.versions',
85+
'require("crypto").getFips()',
7986
process.env);
8087

8188
// --force-fips should raise an error if OpenSSL is not FIPS enabled.
8289
testHelper(
8390
testFipsCrypto() ? 'stdout' : 'stderr',
8491
['--force-fips'],
8592
testFipsCrypto() ? kNoFailure : kGenericUserError,
86-
testFipsCrypto() ? FIPS_ENABLED : FIPS_ENABLE_ERROR_STRING,
87-
'process.versions',
93+
testFipsCrypto() ? FIPS_ENABLED : FIPS_FORCE_ERROR_STRING,
94+
'require("crypto").getFips()',
8895
process.env);
8996

9097
// By default FIPS should be off in both FIPS and non-FIPS builds

0 commit comments

Comments
Β (0)