Skip to content

Pin aws-lc-rs <1.18 to retain AWS-LC-FIPS 3.x, redux - #173

Open
lucaspimentel wants to merge 1 commit into
mainfrom
lpimentel/revert-rustls
Open

lucaspimentel wants to merge 1 commit into
mainfrom
lpimentel/revert-rustls

Conversation

@lucaspimentel

@lucaspimentel lucaspimentel commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

What does this PR do?

Adds an explicit optional aws-lc-rs = { version = ">=1, <1.18" } dependency to datadog-fips and activates it from the fips feature, replacing the previous rustls upper bound (rustls <0.23.45), and regenerates the lockfile to the latest compatible versions.

This follows the backend-pinning approach from DataDog/saluki#2348: capping rustls does not reliably constrain the transitive crypto backend (rustls 0.23.37 still accepts aws-lc-rs 1.18.x), so the backend itself is pinned as a direct dependency even though the crate does not call aws-lc-rs APIs directly.

Resolved versions:

Package Before After
rustls 0.23.45 0.23.43
rustls-webpki 0.103.15 0.103.13
aws-lc-rs 1.18.1 1.17.4
aws-lc-fips-sys 0.14.2 0.13.17
aws-lc-sys 0.45.0 0.45.0 (unchanged)

Motivation

Restores consistency between the manifest and lockfile after #172: the manifest capped rustls below 0.23.45 but the lockfile (updated in #171) pinned rustls 0.23.45 / aws-lc-rs 1.18.1, so cargo metadata --locked failed. aws-lc-rs 1.18 switches to AWS-LC-FIPS 4.x, which is pending FIPS 140-3 certification, so the resolved backend must stay on the AWS-LC-FIPS 3.x line (aws-lc-fips-sys 0.13.x).

Note: this change does not fix RUSTSEC-2026-0285 or establish FIPS certification; the existing advisory waiver in .cargo/audit.toml is intentionally preserved.

Additional Notes

  • No source-code changes; crates/datadog-fips/src/reqwest_adapter.rs behavior is unchanged.
  • Lift the aws-lc-rs <1.18 bound (and remove the advisory waiver) once AWS-LC-FIPS 4.x certification is verified.

Describe how to test/QA your changes

  • cargo metadata --locked --format-version 1 and cargo metadata --locked --all-features --format-version 1 succeed without modifying the lockfile (previously failed).
  • cargo tree --locked -p datadog-fips --no-default-features --features fips -e features -i aws-lc-rs shows the fips feature activating aws-lc-rs 1.17.4 and its fips feature, resolving to aws-lc-fips-sys 0.13.17.
  • cargo check --workspace --locked, cargo fmt --all -- --check, and cargo clippy --workspace --all-features --locked -- -D warnings pass.
  • cargo audit passes with the existing RUSTSEC-2026-0285 waiver.
  • cargo nextest run --workspace --locked --no-fail-fast: 407 passed, 1 failed. The single failure (datadog-trace-agent::integration_test::test_mini_agent_tcp_handles_requests) is pre-existing and reproduces on main at 8156757; it is unrelated (plain TCP /info endpoint test, no TLS involvement).

Add an explicit optional aws-lc-rs dependency to datadog-fips and
activate it from the fips feature. Capping rustls does not reliably
constrain the crypto backend, so a future `cargo update` can re-bump
aws-lc-rs to 1.18, which pulls in AWS-LC-FIPS 4.x pending FIPS 140-3
certification. Restore rustls to its ordinary semver requirement and
regenerate the lockfile to the latest compatible versions (rustls
0.23.43, rustls-webpki 0.103.13, aws-lc-rs 1.17.4,
aws-lc-fips-sys 0.13.17), making the manifest and lockfile consistent
again under --locked.
@lucaspimentel
lucaspimentel marked this pull request as ready for review September 24, 2026 16:43
Copilot AI lite review requested due to automatic review settings September 24, 2026 16:43
@lucaspimentel
lucaspimentel requested review from a team as code owners September 24, 2026 16:43
@lucaspimentel
lucaspimentel requested review from DarcyRaynerDD and Lewis-E and removed request for a team September 24, 2026 16:43
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-24T16:46:14.874374Z d76e19a Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Retain the Rustls upper bound or enforce an equivalent guardrail to prevent AWS-LC-FIPS 4.x from entering the FIPS dependency graph.

Review effort: Lite
Findings: None

What changed in this PR

Pins aws-lc-rs below 1.18 to retain AWS-LC-FIPS 3.x compatibility and regenerates the lockfile.

Changes:

  • Adds the optional backend dependency to the fips feature.
  • Resolves compatible Rustls and AWS-LC versions.
  • Preserves the existing advisory waiver.
File Description
crates/​datadog-fips/​Cargo.toml Adds the FIPS backend constraint and activation. Retain the rustls <0.23.45 cap or an equivalent CI/lockfile guardrail.
Cargo.lock Resolves compatible AWS-LC, Rustls, and webpki versions.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@lucaspimentel lucaspimentel changed the title Pin aws-lc-rs <1.18 to retain AWS-LC-FIPS 3.x Pin aws-lc-rs <1.18 to retain AWS-LC-FIPS 3.x, redux Sep 24, 2026
@lucaspimentel

Copy link
Copy Markdown
Member Author

@DataDog review

@datadog-official datadog-official Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bits Code Review: PASS

More details

The optional aws-lc-rs bound is part of the fips feature. The lockfile resolves aws-lc-rs 1.17.4 and aws-lc-fips-sys 0.13.17.

Was this helpful? React 👍 or 👎

Open Bits AI session

🤖 Bits Code Review · Commit d76e19a · @DataDog review to ask questions

@lucaspimentel lucaspimentel changed the title Pin aws-lc-rs <1.18 to retain AWS-LC-FIPS 3.x, redux Pin aws-lc-rs <1.18 to retain AWS-LC-FIPS 3.x, redux Sep 25, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants