Public bug reported:

Ubuntu’s Go source packages modify the metadata of the bundled FIPS
snapshot ZIPs without updating `fips140.sum`. Compared with the original
Go archives, the packaged ZIPs have changed timestamps and entry order,
while their decompressed file contents remain identical.

**Affected packages**

| Ubuntu release | Package | Version |
|---|---|---|
| 22.04 | golang-1.24-src | 1.24.13-2~22.04.1 |
| 24.04 | golang-1.24-src | 1.24.13-2~24.04.1 |
| 26.04 | golang-1.24-src | 1.24.13-2 |
| 26.04 | golang-1.25-src | 1.25.7-2 |
| 26.04 | golang-1.26-src | 1.26.0-1 |
| 26.10 development | golang-1.25-src | 1.25.12-1 |
| 26.10 development | golang-1.26-src | 1.26.8-1 |
| 26.10 development | golang-1.27-src | 1.27.1-1 |

All eight packages have snapshot checksum mismatches. Every ZIP entry
timestamp changed: 225 entries in `v1.0.0-c2097c7c.zip` and 231 entries
in `v1.26.0.zip`.

**Observed behavior**

- **Go 1.24–1.26: incorrect archive digest, successful functional tests.** 
Representative tests using Go 1.24.13, 1.25.12, and 1.26.8 with fresh build and 
module caches compiled and ran successfully. Assertions checking 
`fips140.Enabled()`, the SHA-256 result, and the selected snapshot version 
passed. These compilers do not verify the ZIP against `fips140.sum` during 
compilation.
- **Go 1.27.1: incorrect archive digest, failed checksum verification.** The 
compiler verifies the archive before unpacking it into an empty module cache. 
The mismatch aborts compilation and causes the integration test to fail before 
the program or its assertions execute. An already populated module cache can 
bypass this verification. [Go 
source](https://github.com/golang/go/blob/go1.27.1/src/cmd/go/internal/fips140/fips140.go#L229-L240).

For `golang-1.27-src_1.27.1-1_all.deb`, the certified snapshot is
`v1.0.0-c2097c7c.zip`:

```text
Expected SHA-256:
daf3614e0406f67ae6323c902db3f953a1effb199142362a039e7526dfb9368b

Actual SHA-256:
d2aba72aad61d3c8376ea26ce35cdb2d2d0c6be98539c25111ebf5b2eba89da9
```

**Reproduction**

Install the matching Go compiler and source packages, then run:

```bash
cat >/tmp/fips-check.go <<'EOF'
package main

import (
        "crypto/fips140"
        "fmt"
)

func main() {
        if !fips140.Enabled() {
                panic("FIPS mode is disabled")
        }
        fmt.Println("FIPS mode enabled")
}
EOF

GOFIPS140=v1.0.0 GOTOOLCHAIN=local CGO_ENABLED=0 GODEBUG= \
  GOPATH="$(mktemp -d)" GOCACHE="$(mktemp -d)" \
  /usr/lib/go-1.27/bin/go run /tmp/fips-check.go
```

Go 1.27 fails with a snapshot checksum mismatch. Replacing the compiler
path with the tested Go 1.24–1.26 versions produces a successful run
despite their incorrect archive digests.

**Expected behavior and suggested fix**

The packages should preserve the original FIPS snapshot ZIPs byte-for-
byte so that their hashes match `fips140.sum`.

The packaging rules invoke `dh_strip_nondeterminism` without excluding
`lib/fips140`, which is consistent with the observed metadata changes.
Excluding these archives from normalization should preserve their
original checksums. Restoring the original certified ZIP, without
changing `fips140.sum`, was verified to resolve the Go 1.27 build
failure.

** Affects: golang (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2169165

Title:
  fips snapshots have mismatched checksums

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/golang/+bug/2169165/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to