Skip to content

Commit aaf407b

Browse files
Update Rust crate aws-lc-rs to v1.18.0 (#2569)
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [aws-lc-rs](https://redirect.github.com/aws/aws-lc-rs) | workspace.dependencies | minor | `1.17.3` → `1.18.0` | --- ### Release Notes <details> <summary>aws/aws-lc-rs (aws-lc-rs)</summary> ### [`v1.18.0`](https://redirect.github.com/aws/aws-lc-rs/releases/tag/v1.18.0): aws-lc-rs v1.18.0 [Compare Source](https://redirect.github.com/aws/aws-lc-rs/compare/v1.17.3...v1.18.0) #### AWS-LC-FIPS module updated to 4.x This release switches `aws-lc-fips-sys` (used via the `fips` feature) from the AWS-LC-FIPS 3.x branch to [AWS-LC-FIPS 4.0](https://redirect.github.com/aws/aws-lc/releases/tag/v4.0.0). - **If your project requires FIPS compliance, please consult your local FIPS compliance experts before upgrading.** The FIPS v3 module shipped in aws-lc-rs v1.17.x is FIPS 140-3 validated ([Certificate #&#8203;5314](https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/5314) static, [Certificate #&#8203;5298](https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/5298) dynamic). The 4.x module has completed validation testing by an accredited lab and has been submitted to NIST for certification. Refer to the [CMVP Modules In Progress List](https://csrc.nist.gov/Projects/cryptographic-module-validation-program/modules-in-process/Modules-In-Process-List) for its current status, and to [FIPS.md](https://redirect.github.com/aws/aws-lc/blob/main/crypto/fipsmodule/FIPS.md) for security policies and supported operating environments. - Consumers who need to remain on the FIPS 3.x module should pin `aws-lc-rs` to `<1.18.0`. See the Cargo Book on [Specifying Dependencies](https://doc.rust-lang.org/cargo/reference/specifying-dependencies.html). | AWS-LC-FIPS module | aws-lc-rs | | ------------------ | --------- | | 2.0.x | <1.12.0 | | 3.0.x | <1.18.0 | | 4.x | *latest* | #### What's Changed - Switch `aws-lc-fips-sys` to AWS-LC's "FIPS 4.0" branch by [@&#8203;justsmth](https://redirect.github.com/justsmth) in [#&#8203;1185](https://redirect.github.com/aws/aws-lc-rs/pull/1185) - `aws-lc-fips-sys` v0.13.16 -> v0.14.0. Please see the call-out above. - **The ML-DSA signature APIs are now stable** 🎉 by [@&#8203;justsmth](https://redirect.github.com/justsmth) in [#&#8203;1188](https://redirect.github.com/aws/aws-lc-rs/pull/1188) and [#&#8203;1189](https://redirect.github.com/aws/aws-lc-rs/pull/1189) - `PqdsaKeyPair`, `PqdsaPublicKey`, `PqdsaPrivateKey`, `PqdsaSigningAlgorithm`, `PqdsaVerificationAlgorithm`, and the `ML_DSA_44` / `ML_DSA_65` / `ML_DSA_87` algorithms (and their `_SIGNING` counterparts) now live in `aws_lc_rs::signature`. ML-DSA no longer requires the `unstable` feature, and is now available under `fips` -- the FIPS 4.0 module provides ML-DSA, which is what had kept these APIs unstable. See our updated [API documentation](https://docs.rs/aws-lc-rs/latest/aws_lc_rs/signature/index.html). - Please migrate any use of `aws_lc_rs::unstable::signature` to `aws_lc_rs::signature`. The `unstable::signature` module remains as deprecated aliases and will be removed in a future release. - `PqdsaKeyPair::to_pkcs8` has been renamed to `to_pkcs8v1`, since elsewhere in the module an unqualified `to_pkcs8` means [PKCS#8](https://redirect.github.com/PKCS/aws-lc-rs/issues/8) v2. A deprecated `to_pkcs8` alias remains available under the `unstable` feature. - Existing `unstable` consumers continue to compile, with deprecation warnings. Two cases need a source change: builds using `#![deny(warnings)]`, and code that glob-imports both `signature::*` and `unstable::signature::*`, which now needs an explicit import to disambiguate. - **Behavior change:** `PqdsaVerificationAlgorithm::parsed_verify_digest_sig` now always returns `Unspecified`. Digest-then-verify is not an operation defined by FIPS 204 -- pure ML-DSA signs the message itself, and the pre-hash variant (HashML-DSA) uses a distinct domain separator that this API does not implement. - Add out-of-place AEAD sealing by [@&#8203;iainmcgin](https://redirect.github.com/iainmcgin) in [#&#8203;1183](https://redirect.github.com/aws/aws-lc-rs/pull/1183) - Adds `seal_separate_out_of_place` to `LessSafeKey` and `TlsRecordSealingKey`. Every sealing entry point was previously in-place, so a caller whose plaintext was borrowed or shared had to copy it into a scratch buffer purely to make it mutable. This mirrors the existing `open_separate_gather`, so the sealing and opening directions now match. - Add `rsa::KeyPair::from_components` for constructing RSA key pairs from raw components by [@&#8203;justsmth](https://redirect.github.com/justsmth) in [#&#8203;1175](https://redirect.github.com/aws/aws-lc-rs/pull/1175) - Adds `rsa::KeyPairComponents` and `rsa::KeyPair::from_components`, matching ring 0.17, so a signing key can be built from formats such as JWK without first encoding the components as DER. Unlike ring, `d` and the CRT parameters are validated at construction using `RSA_check_key`, so keys with inconsistent or placeholder values that ring accepts may be rejected. Unnecessary generic bounds were also removed from `PublicKeyComponents`. - Automatically optimize aws-lc for size when opt-level is "s" or "z" by [@&#8203;justsmth](https://redirect.github.com/justsmth) in [#&#8203;1159](https://redirect.github.com/aws/aws-lc-rs/pull/1159) - The builder now enables AWS-LC's size-optimized configuration (`OPENSSL_SMALL`, and no AVX-512 assembly on x86\_64) whenever Cargo is already building for size. In CI, a small binary exercising SHA-256, AES-256-GCM, and ECDSA P-256 is **36-50% smaller** at `opt-level=z` than at `opt-level=3`: 50% on x86\_64 Linux, 48% on aarch64 macOS, 39% on x86\_64 Windows, 36% on aarch64 Linux. Your own savings depend on how much of AWS-LC your binary retains. - No algorithms are removed and outputs are unchanged; the trade-off is slower elliptic-curve performance. Set `AWS_LC_SYS_SMALL=1`/`=0` to force it on or off independently of opt-level. - FIPS builds do not opt in automatically: `aws-lc-fips-sys` requires an explicit `AWS_LC_FIPS_SYS_SMALL=1`, and warns when it is set. - Partially addresses [#&#8203;745](https://redirect.github.com/aws/aws-lc-rs/issues/745); the default size under `opt-level=3` footprint is unchanged. - Export native library build metadata from the -sys crates by [@&#8203;justsmth](https://redirect.github.com/justsmth) in [#&#8203;1187](https://redirect.github.com/aws/aws-lc-rs/pull/1187), including original commits from [@&#8203;glebpom](https://redirect.github.com/glebpom) in [#&#8203;1184](https://redirect.github.com/aws/aws-lc-rs/pull/1184) - Downstream build scripts compiling C code against AWS-LC can now locate our artifacts via `DEP_AWS_LC_*` / `DEP_AWS_LC_FIPS_*` (`libdir`, `libcrypto_path`, `link_kind`, and `libssl_path` with `ssl`), consistently across the CC, CMake, and system-library build paths. Existing linker directives are unchanged. On Windows, the `*_path` values are the link-time artifact (import library), not the runtime DLL. - Key wrap hardening by [@&#8203;justsmth](https://redirect.github.com/justsmth) in [#&#8203;1190](https://redirect.github.com/aws/aws-lc-rs/pull/1190) and [#&#8203;1191](https://redirect.github.com/aws/aws-lc-rs/pull/1191) - `KeyEncryptionKey::unwrap` no longer underflows on ciphertexts shorter than 8 bytes. Since the ciphertext is untrusted input, builds with `overflow-checks = true` would panic instead of returning the documented `Err(Unspecified)`; default release builds were unaffected. - `KeyEncryptionKey` now zeroizes its key material on drop, consistent with the other key types in this crate. - docs(signature): correct outdated note about signing a separate digest by [@&#8203;WesleyRosenblum](https://redirect.github.com/WesleyRosenblum) in [#&#8203;1186](https://redirect.github.com/aws/aws-lc-rs/pull/1186) ##### Upstream AWS-LC (v5.5.0) `aws-lc-sys` v0.44.0 aligns with [AWS-LC v5.5.0](https://redirect.github.com/aws/aws-lc/releases/tag/v5.5.0) (previously v5.2.0). See also the release notes for [v5.3.0](https://redirect.github.com/aws/aws-lc/releases/tag/v5.3.0) and [v5.4.0](https://redirect.github.com/aws/aws-lc/releases/tag/v5.4.0). ##### Build Improvements - Fix bindings copy from read-only prebuilt AWS-LC install by [@&#8203;justsmth](https://redirect.github.com/justsmth) in [#&#8203;1194](https://redirect.github.com/aws/aws-lc-rs/pull/1194) - Copies into `OUT_DIR` now remove any stale destination first and leave the fresh copy writable, so building against a read-only prebuilt install (e.g. the Nix store) no longer fails with `Permission denied` on a build-script rerun. An `OUT_DIR` already poisoned by an earlier build now recovers without a `cargo clean`. ##### Issues Being Closed - ML-DSA stabilization? -- [#&#8203;964](https://redirect.github.com/aws/aws-lc-rs/issues/964) - Expose out-of-place AEAD sealing -- [#&#8203;1182](https://redirect.github.com/aws/aws-lc-rs/issues/1182) - Construct an RSA Key pair from raw private components -- [#&#8203;791](https://redirect.github.com/aws/aws-lc-rs/issues/791) - aws-lc-sys build script fails to copy bindings from read only prebuild aws-lc on repeat runs -- [#&#8203;1193](https://redirect.github.com/aws/aws-lc-rs/issues/1193) #### Other Merged PRs - ci: fix mdbook test failure and run docs checks on PRs by [@&#8203;justsmth](https://redirect.github.com/justsmth) in [#&#8203;1181](https://redirect.github.com/aws/aws-lc-rs/pull/1181) - Publish script fixes: cargo clean failure, and verify aws-lc-rs against minimum published sys crates by [@&#8203;justsmth](https://redirect.github.com/justsmth) in [#&#8203;1179](https://redirect.github.com/aws/aws-lc-rs/pull/1179) - Prepare aws-lc-sys v0.44.0 by [@&#8203;justsmth](https://redirect.github.com/justsmth) in [#&#8203;1199](https://redirect.github.com/aws/aws-lc-rs/pull/1199) - Prepare aws-lc-rs v1.18.0 by [@&#8203;justsmth](https://redirect.github.com/justsmth) in [#&#8203;1200](https://redirect.github.com/aws/aws-lc-rs/pull/1200) #### New Contributors - [@&#8203;iainmcgin](https://redirect.github.com/iainmcgin) made their first contribution in [#&#8203;1183](https://redirect.github.com/aws/aws-lc-rs/pull/1183) - [@&#8203;glebpom](https://redirect.github.com/glebpom) made their first contribution in [#&#8203;1184](https://redirect.github.com/aws/aws-lc-rs/pull/1184) (landed via [#&#8203;1187](https://redirect.github.com/aws/aws-lc-rs/pull/1187)) **Full Changelog**: <aws/aws-lc-rs@v1.17.3...v1.18.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - Between 12:00 AM and 03:59 AM, only on Monday (`* 0-3 * * 1`) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/j178/prek). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yOS41IiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJpbnRlcm5hbCJdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
1 parent 3ddddfd commit aaf407b

1 file changed

Lines changed: 4 additions & 4 deletions

File tree

Cargo.lock

Lines changed: 4 additions & 4 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)