Repository navigation
feat(aws): sign SigV4 requests through the system OpenSSL - #1351
Conversation
aws_sigv4_sign computed its HMAC-SHA256 through the aws-sigv4 crate, which hard-wires the pure-Rust hmac/sha2 crates and offers no way to substitute them, so the filter had to be left out of the FIPS build. Move the SigV4 canonicalization and key derivation in-tree and compute SHA-256 and HMAC-SHA256 through the OpenSSL EVP seam in praxis_ai_apis::hash. aws-sigv4 becomes a dev-dependency: a differential test checks every header the signer emits against it, alongside the AWS published vectors. Add aws-sigv4-filter to the FIPS feature set and a test-fips-provider target that runs the unit tests with the RHEL FIPS provider active. Filter configuration and behaviour are unchanged. Refs praxis-proxy#814 Signed-off-by: szedan <szedan@redhat.com>
leseb
left a comment
There was a problem hiding this comment.
P1 — Restore Amazon’s copyright attribution. signing.rs ports substantial aws-sigv4 code nearly line-for-line but replaces its Amazon copyright notice. Apache 2.0 §4 requires retaining applicable notices in derivative source. Keep the Amazon notice and identify Praxis’s modifications before merging. Apache License §4
There was a problem hiding this comment.
Yes, missed that one. Dropped SigV4 from the list in 09a2745.
…comment Signed-off-by: szedan <szedan@redhat.com>
|
Fair point on the attribution. 09a2745 restores the Amazon notice in signing.rs and states what was ported (path normalization, encoding set, excluded headers, canonical request assembly from aws-sigv4 1.5.3 / aws-smithy-http 0.64.0) and what changed (the crypto now goes through the system OpenSSL). |
alexsnaps
left a comment
There was a problem hiding this comment.
aws-sigv4 (+ transitive hmac/sha2) 🔥 Good stuff!
| /// duplicate and excluded headers, spaces, query ordering, ports, | ||
| /// tokens, regions, services and dates). | ||
| #[expect(clippy::too_many_lines, reason = "test data: one entry per canonicalization edge")] | ||
| fn differential_cases() -> Vec<Oracle<'static>> { |
There was a problem hiding this comment.
Might want to eventually harden this around canonical_query edges maybe, but I think that's not a real problem right now.
| if written != SHA256_LEN { | ||
| // Cannot happen for SHA-256; treat it as the library misbehaving | ||
| // rather than returning a truncated tag. | ||
| return Err(ErrorStack::get()); |
There was a problem hiding this comment.
This is purely hypothetical as of now... wondering how much a static message would read better than an empty stack. But, again, purely hypothetical (
The test-fips-provider target passed OPENSSL_CONF through cargo's runner, which OpenSSL ignores when the path is wrong, so the tests could run on the default provider and still pass. The run now also sets PRAXIS_TEST_FIPS_PROVIDER, and the apis and filters test processes assert that OpenSSL reports FIPS-approved default properties and refuses MD5. The UBI 9 report stage runs the hash and signing tests the same way, so CI covers the provider-active path. Also: HmacError with a static message for the impossible tag length, stale test comments in sigv4.rs, the report description in docs/developing/fips.md, and test-fips-provider in make help. Signed-off-by: szedan <szedan@redhat.com>
|
Wrapping up the second round, all in 22a8e47:
Verified with clippy, make lint, make test-fips-provider and make fips-check on UBI 9 (31 tests on the provider, report clean). |
Brings in AWS SigV4 signing through the system OpenSSL (praxis-proxy#1351) on top of the OpenAI Responses filter rename. Resolved docs/features.md, docs/fips.md, and Makefile by keeping both the renamed filter names and the AWS/FIPS additions. Signed-off-by: Sébastien Han <seb@redhat.com>
Summary
aws_sigv4_signnow computes its signature through the system OpenSSL(EVP digest and signing APIs), so it can ship in the FIPS build. The
aws-sigv4crate hard-wires RustCryptohmac/sha2with no backendseam and keeps its canonical-request types private, so the SigV4
protocol steps move into
filters/src/aws/signing.rsand the cratebecomes a dev-dependency used as the test oracle.
praxis_ai_apis::hash::HmacSha256next to the existing OpenSSLSha256aws-sigv4-filteradded toFIPS_FEATURESandContainerfile.fipsmake test-fips-provider: unit tests with the RHEL FIPS provider activedocs/fips.md,docs/features.md, FIPS tooling)No change to filter configuration, headers set, or error handling.
Related issue
Refs #814
Validation
aws::unit tests, including a 14-case differential test thatcompares every emitted header byte-for-byte with
aws-sigv4, the AWSpublished IAM key-derivation vector and the S3 example
make lint(includesfips-deps: no denied crate with the filter enabled)aws_sigv4make test-fipsstill fails the 14 pre-existingagentic_looptests, whichfail on main as well (see #1335).
Breaking changes
None.