Skip to content

v2.0a2

Choose a tag to compare

@github-actions github-actions released this 08 Sep 10:05
· 37 commits to main since this release

Fixed

  • FIPS fetch pin is Linux-only (#3364). Under
    KLANGKD_FIPS_MODE, the startup step that pins ambient OpenSSL
    fetches to fips=yes (#3350) now runs only on Linux, where
    OpenSSL's FIPS provider exists. On other platforms the step is
    skipped and the regular process-posture check still governs
    startup; on macOS the previous ctypes load of the system libcrypto
    aborted the whole process at load time.
  • FIPS images pin ambient OpenSSL fetches to fips=yes (#3359).
    The activation config in the FIPS workspace and FIPS host images
    now sets default_properties = fips=yes, so every process in the
    container requires the fips property on provider-less algorithm
    fetches, and Node's crypto.getFips() reports FIPS mode as active.
    In the FIPS workspace image this un-breaks the pi coding agent:
    jiti (its TypeScript extension loader) chooses its cache-key hash
    from crypto.getFips() and previously picked MD5 — refused by the
    fips provider — which failed every extension load with
    error:0308010C until pi -ne was used. The configs also set
    config_diagnostics = 1: a config that fails to parse now aborts
    the process instead of silently falling back to the default
    provider.