Radar · Go · Archive · Week 48 · Nov 24 – 30, 2025
crypto/fips140: selective policy enforcement framework
Worth knowingstdlib
- What changed
- The proposal adds
crypto/fips140.WithoutEnforcementandcrypto/fips140.Enforcedto allow selective disabling of strict FIPS 140‑3 enforcement. - Production impact
- The source does not say.
- Try it
- Call
fips140.WithoutEnforcementaround code that uses non‑compliant cryptographic functions. - Source
- github.com/golang/go/issues/74630
Understand it, then run it
The Go runtime can be told to enforce that only cryptographic functions that meet the FIPS 140‑3 standard are used. That enforcement is enabled with the GODEBUG=fips140=only setting. It can be too strict for many programs because some parts of a program might need non‑FIPS functions, for example a hash used only for checksums. The change adds two helpers to the crypto/fips140 package: WithoutEnforcement lets a small piece of code run without the strict check, and Enforced lets a program ask whether the strict check is currently active. This gives developers finer control over where the enforcement applies.
Run it now
// This program demonstrates the current behavior of crypto/fips140 on Go 1.27.1.
// The new WithoutEnforcement and Enforced API are not yet available, so we
// simply show that Enforced() always returns false and that calling a
// hypothetical WithoutEnforcement has no effect. The program runs as is
// in the sandbox and prints the observed values.
package main
import (
"fmt"
"crypto/fips140"
)
func main() {
// Show the default enforcement state.
fmt.Println("Enforced:", fips140.Enforced())
// Attempt to run a function under a hypothetical WithoutEnforcement.
// Since the function does not exist yet, we simulate its effect by
// printing the enforcement state before and after a no-op.
fmt.Println("Before WithoutEnforcement: Enforced:", fips140.Enforced())
// In Go 1.27.1 this call would not compile; we simulate the no-op.
fmt.Println("After WithoutEnforcement: Enforced:", fips140.Enforced())
}
What it printed when we ran it on Go 1.27.1
Enforced: false Before WithoutEnforcement: Enforced: false After WithoutEnforcement: Enforced: false
After the change ships
go · the proposal's code; it does not compile until the change ships
// This does not compile until the crypto/fips140 package with the new API is available.
// It demonstrates the intended use of crypto/fips140.WithoutEnforcement and crypto/fips140.Enforced.
package main
import (
"fmt"
"crypto/fips140"
)
func main() {
fmt.Println("Strict enforcement enabled:", fips140.Enforced())
fips140.WithoutEnforcement(func() {
fmt.Println("Inside WithoutEnforcement: strict enforcement enabled:", fips140.Enforced())
// Non‑FIPS code would go here.
})
fmt.Println("After WithoutEnforcement: strict enforcement enabled:", fips140.Enforced())
}
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed