Skip to content

GODEBUG=fips140=only Importing github.com/vmware/govmomi/simulator panics #3766

@michel-laterman

Description

@michel-laterman

Tests that import github.com/vmware/govmomi/simulator will panic when loading if GODEBUG=fips140=only is set.

This is due to SHA-1 usage in simulator/vpx

InstanceUuid: uuid.NewSHA1(uuid.NameSpaceOID, uuid.NodeID()).String(),

This failure is also present when running unit tests for simulator:

simulator|main ⇒ GODEBUG=fips140=only go test ./...
panic: crypto/sha1: use of SHA-1 is not allowed in FIPS 140-only mode

goroutine 1 [running]:
crypto/sha1.(*digest).checkSum(0x10145ca80?)
	/usr/local/go/src/crypto/sha1/sha1.go:160 +0x180
crypto/sha1.(*digest).Sum(0x140000928c0, {0x0, 0x0, 0x0})
	/usr/local/go/src/crypto/sha1/sha1.go:154 +0x6c
github.com/google/uuid.NewHash({0x10167d000, 0x140000928c0}, {0x6b, 0xa7, 0xb8, 0x12, 0x9d, 0xad, 0x11, 0xd1, ...}, ...)
	/Users/mlaterman/go/pkg/mod/github.com/google/uuid@v1.6.0/hash.go:37 +0xbc
github.com/google/uuid.NewSHA1({0x6b, 0xa7, 0xb8, 0x12, 0x9d, 0xad, 0x11, 0xd1, 0x80, 0xb4, ...}, ...)
	/Users/mlaterman/go/pkg/mod/github.com/google/uuid@v1.6.0/hash.go:58 +0x98
github.com/vmware/govmomi/simulator/vpx.init()
	/Users/mlaterman/git/govmomi/simulator/vpx/service_content.go:32 +0x2d8
FAIL	github.com/vmware/govmomi/simulator	0.521s
?   	github.com/vmware/govmomi/simulator/esx	[no test files]
?   	github.com/vmware/govmomi/simulator/internal	[no test files]
?   	github.com/vmware/govmomi/simulator/vpx	[no test files]
FAIL

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions