Skip to content

GODEBUG=fips140=only Importing github.com/vmware/govmomi/simulator panics #3766

@michel-laterman

Description

@michel-laterman

Tests that import github.com/vmware/govmomi/simulator will panic when loading if GODEBUG=fips140=only is set.

This is due to SHA-1 usage in simulator/vpx

InstanceUuid: uuid.NewSHA1(uuid.NameSpaceOID, uuid.NodeID()).String(),

This failure is also present when running unit tests for simulator:

simulator|main ⇒ GODEBUG=fips140=only go test ./...
panic: crypto/sha1: use of SHA-1 is not allowed in FIPS 140-only mode

goroutine 1 [running]:
crypto/sha1.(*digest).checkSum(0x10145ca80?)
	/usr/local/go/src/crypto/sha1/sha1.go:160 +0x180
crypto/sha1.(*digest).Sum(0x140000928c0, {0x0, 0x0, 0x0})
	/usr/local/go/src/crypto/sha1/sha1.go:154 +0x6c
github.com/google/uuid.NewHash({0x10167d000, 0x140000928c0}, {0x6b, 0xa7, 0xb8, 0x12, 0x9d, 0xad, 0x11, 0xd1, ...}, ...)
	/Users/mlaterman/go/pkg/mod/github.com/google/[email protected]/hash.go:37 +0xbc
github.com/google/uuid.NewSHA1({0x6b, 0xa7, 0xb8, 0x12, 0x9d, 0xad, 0x11, 0xd1, 0x80, 0xb4, ...}, ...)
	/Users/mlaterman/go/pkg/mod/github.com/google/[email protected]/hash.go:58 +0x98
github.com/vmware/govmomi/simulator/vpx.init()
	/Users/mlaterman/git/govmomi/simulator/vpx/service_content.go:32 +0x2d8
FAIL	github.com/vmware/govmomi/simulator	0.521s
?   	github.com/vmware/govmomi/simulator/esx	[no test files]
?   	github.com/vmware/govmomi/simulator/internal	[no test files]
?   	github.com/vmware/govmomi/simulator/vpx	[no test files]
FAIL

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions