Skip to content

Update FIPS build to include fix for Golang FIPS support#26431

Closed
saiarcot895 wants to merge 1 commit intosonic-net:masterfrom
saiarcot895:update-fips-for-golang
Closed

Update FIPS build to include fix for Golang FIPS support#26431
saiarcot895 wants to merge 1 commit intosonic-net:masterfrom
saiarcot895:update-fips-for-golang

Conversation

@saiarcot895
Copy link
Copy Markdown
Contributor

@saiarcot895 saiarcot895 commented Mar 27, 2026

Why I did it

Update the FIPS package to fix symcrypt FIPS not getting loaded in Golang. This brings in all changes in sonic-net/sonic-fips#78, including sonic-net/sonic-fips@c56b560.

Work item tracking
  • Microsoft ADO (number only):

How I did it

Upload a new FIPS package with the fix, and update buildiamge to point to that.

How to verify it

Golang packages built for Trixie and that use SSL/crypto operations will have the symcrypt module loaded.

Which release branch to backport (provide reason below if selected)

  • 202305
  • 202311
  • 202405
  • 202411
  • 202505
  • 202511

Tested branch (Please provide the tested image version)

Description for the changelog

Link to config_db schema for YANG module changes

A picture of a cute animal (not mandatory but encouraged)

Signed-off-by: Saikrishna Arcot <sarcot@microsoft.com>
Copilot AI review requested due to automatic review settings March 27, 2026 01:55
@mssonicbld
Copy link
Copy Markdown
Collaborator

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the SONiC build system’s pinned FIPS bundle version for the trixie build environment so builds pull the newer published FIPS artifacts (including the Golang FIPS support fix referenced by the PR title).

Changes:

  • Bump FIPS_VERSION for BLDENV=trixie from 1.8.0-24-gd744cf2 to 1.8.0-24-gd744cf2-2.

sigabrtv1-ui pushed a commit to sigabrtv1-ui/sonic-buildimage that referenced this pull request Mar 27, 2026
Cherry-pick the FIPS version bump from PR sonic-net#26431 to pick up
the rebuilt trixie FIPS Go packages with sonic_fips detection
and symcryptprovider patches correctly applied.

Signed-off-by: Dawei Huang <daweihuang@microsoft.com>
sigabrtv1-ui pushed a commit to sigabrtv1-ui/sonic-buildimage that referenced this pull request Mar 27, 2026
Cherry-pick the FIPS version bump from PR sonic-net#26431 to pick up
the rebuilt trixie FIPS Go packages with sonic_fips detection
and symcryptprovider patches correctly applied.

Signed-off-by: Dawei Huang <daweihuang@microsoft.com>
hdwhdw added a commit to hdwhdw/sonic-buildimage that referenced this pull request Apr 1, 2026
Cherry-pick the FIPS version bump from PR sonic-net#26431 to pick up
the rebuilt trixie FIPS Go packages with sonic_fips detection
and symcryptprovider patches correctly applied.

Signed-off-by: Dawei Huang <daweihuang@microsoft.com>
@saiarcot895
Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines
Copy link
Copy Markdown

Azure Pipelines successfully started running 1 pipeline(s).

@saiarcot895
Copy link
Copy Markdown
Contributor Author

Done in #25957

@saiarcot895 saiarcot895 closed this Apr 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants