Skip to content

Move HMAC fallback logic to cryptobackend - #2511

Merged
Quim Muntal (qmuntal) merged 1 commit into
microsoft/mainfrom
dev/qmuntal/hmac-fallback
Sep 22, 2026
Merged

Quim Muntal (qmuntal) merged 1 commit into
microsoft/mainfrom
dev/qmuntal/hmac-fallback

Conversation

@qmuntal

Copy link
Copy Markdown
Member

Move HMAC backend selection and fallback into cryptobackend, following the SHA packages. This reduces the crypto/hmac integration to replacing its internal HMAC import while preserving FIPS-only checks.

Updates #2489.

Validation: HMAC tests with system crypto enabled and disabled, FIPS-enabled HMAC tests, FIPS-only enforcement, dependency checks, and standalone backend checks.

Move backend dispatch and pure-Go fallback into cryptobackend/hmac,
matching the SHA packages. Keep FIPS-only validation in crypto/hmac
and reduce the standard-library integration to an import change.

Updates #2489.
Copilot AI lite review requested due to automatic review settings September 22, 2026 10:30
@qmuntal
Quim Muntal (qmuntal) requested a review from a team as a code owner September 22, 2026 10:30
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

It changes cryptographic backend dispatch/fallback behavior and patch-vendored stdlib wiring, which warrants careful human validation across build tags and platforms.

Review effort: Lite
Findings: None

What changed in this PR

This PR moves HMAC backend selection + fallback into github.com/microsoft/go/cryptobackend/hmac, so the standard library crypto/hmac integration can be reduced to swapping the internal crypto/internal/fips140/hmac import for the corresponding cryptobackend package while keeping the existing FIPS-only enforcement logic in crypto/hmac.

Changes:

  • Add a cryptobackend/hmac.New wrapper that dispatches to a platform backend implementation when enabled, otherwise falls back (or panics outside msgostd).
  • Rename platform-specific exported New implementations to an unexported newBackendHMAC helper to avoid symbol conflicts and match the “wrapper + per-platform helper” pattern used elsewhere.
  • Update the patch set so src/crypto/hmac/hmac.go imports github.com/microsoft/go/cryptobackend/hmac instead of crypto/internal/fips140/hmac.

Patches are happy!

File Description
patches/​0002-Add-crypto-backends.patch Switch crypto/hmac to use cryptobackend/hmac instead of the internal fips140/hmac import.
patches/​0001-Vendor-external-dependencies.patch Vendor the new cryptobackend/hmac wrapper + build-tagged fallback/backend split into src/vendor.
cryptobackend/​hmac/​hmac.go New wrapper entrypoint that selects backend vs fallback.
cryptobackend/​hmac/​hmac_{darwin,windows,openssl}.go Rename backend entrypoints to newBackendHMAC.
cryptobackend/​hmac/​{hmac_msgostd,hmac_nomsgostd}.go Add fallback implementation for msgostd and panic stub for non-msgostd.
cryptobackend/​hmac/​nobackend.go Update stub to newBackendHMAC for non-systemcrypto builds.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@qmuntal
Quim Muntal (qmuntal) merged commit 0b57ae8 into microsoft/main Sep 22, 2026
59 checks passed
@qmuntal
Quim Muntal (qmuntal) deleted the dev/qmuntal/hmac-fallback branch September 22, 2026 12:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants