Public bug reported: Ubuntu’s Go source packages modify the metadata of the bundled FIPS snapshot ZIPs without updating `fips140.sum`. Compared with the original Go archives, the packaged ZIPs have changed timestamps and entry order, while their decompressed file contents remain identical.
**Affected packages** | Ubuntu release | Package | Version | |---|---|---| | 22.04 | golang-1.24-src | 1.24.13-2~22.04.1 | | 24.04 | golang-1.24-src | 1.24.13-2~24.04.1 | | 26.04 | golang-1.24-src | 1.24.13-2 | | 26.04 | golang-1.25-src | 1.25.7-2 | | 26.04 | golang-1.26-src | 1.26.0-1 | | 26.10 development | golang-1.25-src | 1.25.12-1 | | 26.10 development | golang-1.26-src | 1.26.8-1 | | 26.10 development | golang-1.27-src | 1.27.1-1 | All eight packages have snapshot checksum mismatches. Every ZIP entry timestamp changed: 225 entries in `v1.0.0-c2097c7c.zip` and 231 entries in `v1.26.0.zip`. **Observed behavior** - **Go 1.24–1.26: incorrect archive digest, successful functional tests.** Representative tests using Go 1.24.13, 1.25.12, and 1.26.8 with fresh build and module caches compiled and ran successfully. Assertions checking `fips140.Enabled()`, the SHA-256 result, and the selected snapshot version passed. These compilers do not verify the ZIP against `fips140.sum` during compilation. - **Go 1.27.1: incorrect archive digest, failed checksum verification.** The compiler verifies the archive before unpacking it into an empty module cache. The mismatch aborts compilation and causes the integration test to fail before the program or its assertions execute. An already populated module cache can bypass this verification. [Go source](https://github.com/golang/go/blob/go1.27.1/src/cmd/go/internal/fips140/fips140.go#L229-L240). For `golang-1.27-src_1.27.1-1_all.deb`, the certified snapshot is `v1.0.0-c2097c7c.zip`: ```text Expected SHA-256: daf3614e0406f67ae6323c902db3f953a1effb199142362a039e7526dfb9368b Actual SHA-256: d2aba72aad61d3c8376ea26ce35cdb2d2d0c6be98539c25111ebf5b2eba89da9 ``` **Reproduction** Install the matching Go compiler and source packages, then run: ```bash cat >/tmp/fips-check.go <<'EOF' package main import ( "crypto/fips140" "fmt" ) func main() { if !fips140.Enabled() { panic("FIPS mode is disabled") } fmt.Println("FIPS mode enabled") } EOF GOFIPS140=v1.0.0 GOTOOLCHAIN=local CGO_ENABLED=0 GODEBUG= \ GOPATH="$(mktemp -d)" GOCACHE="$(mktemp -d)" \ /usr/lib/go-1.27/bin/go run /tmp/fips-check.go ``` Go 1.27 fails with a snapshot checksum mismatch. Replacing the compiler path with the tested Go 1.24–1.26 versions produces a successful run despite their incorrect archive digests. **Expected behavior and suggested fix** The packages should preserve the original FIPS snapshot ZIPs byte-for- byte so that their hashes match `fips140.sum`. The packaging rules invoke `dh_strip_nondeterminism` without excluding `lib/fips140`, which is consistent with the observed metadata changes. Excluding these archives from normalization should preserve their original checksums. Restoring the original certified ZIP, without changing `fips140.sum`, was verified to resolve the Go 1.27 build failure. ** Affects: golang (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2169165 Title: fips snapshots have mismatched checksums To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/golang/+bug/2169165/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
