Skip to content

crypto: use current FIPS state for availability - #66160

Merged
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
panva:webcrypto-runtime-capabilities
Sep 23, 2026
Merged

nodejs-github-bot merged 1 commit into
nodejs:mainfrom
panva:webcrypto-runtime-capabilities

Conversation

@panva

@panva panva commented Sep 20, 2026

Copy link
Copy Markdown
Member

Refresh conditional algorithm registration on FIPS changes and use the current state for parameter restrictions.

Use per-algorithm availability checks in normalization and native named key generation.

Enable supports() tests under FIPS and cover state transitions.

Refresh conditional algorithm registration on FIPS changes and use the
current state for parameter restrictions.

Use per-algorithm availability checks in normalization and native named
key generation. Remove getPqcKeyTypes().

Enable supports() tests under FIPS and cover state transitions in warmed
workers.

Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Codex
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/crypto
  • @nodejs/gyp
  • @nodejs/security-wg

@nodejs-github-bot nodejs-github-bot added lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. labels Sep 20, 2026
@panva panva added author ready PRs with CI started, the required approvals, and no outstanding review comments. request-ci Add this label to start a Jenkins CI on a PR. Only starts once the PR has an approving review. labels Sep 20, 2026
@github-actions github-actions Bot removed the request-ci Add this label to start a Jenkins CI on a PR. Only starts once the PR has an approving review. label Sep 20, 2026
@nodejs-github-bot

This comment was marked as outdated.

@codecov

codecov Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 92.56198% with 9 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.29%. Comparing base (8f480a2) to head (e66d15c).
⚠️ Report is 39 commits behind head on main.

Files with missing lines Patch % Lines
lib/internal/crypto/util.js 93.68% 6 Missing ⚠️
src/crypto/crypto_keys.cc 77.77% 0 Missing and 2 partials ⚠️
lib/internal/crypto/webidl.js 75.00% 1 Missing ⚠️
Additional details and impacted files
@@           Coverage Diff           @@
##             main   #66160   +/-   ##
=======================================
  Coverage   90.29%   90.29%           
=======================================
  Files         790      789    -1     
  Lines      271982   272009   +27     
  Branches    51917    51928   +11     
=======================================
+ Hits       245587   245619   +32     
+ Misses      16901    16891   -10     
- Partials     9494     9499    +5     
Files with missing lines Coverage Δ
lib/internal/crypto/keygen.js 92.63% <100.00%> (-0.31%) ⬇️
lib/internal/crypto/webcrypto.js 97.95% <ø> (-0.01%) ⬇️
src/crypto/crypto_keygen.cc 86.20% <100.00%> (+2.53%) ⬆️
src/crypto/crypto_sig.cc 68.69% <ø> (ø)
lib/internal/crypto/webidl.js 97.18% <75.00%> (+0.11%) ⬆️
src/crypto/crypto_keys.cc 72.64% <77.77%> (-0.01%) ⬇️
lib/internal/crypto/util.js 98.26% <93.68%> (+0.70%) ⬆️

... and 24 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@panva panva added the commit-queue PRs queued for automated landing through the Commit Queue. label Sep 20, 2026
@nodejs-github-bot nodejs-github-bot added the lacks-second-approval Commit Queue PRs awaiting a second collaborator approval or completion of the required wait. label Sep 22, 2026

@mcollina mcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@nodejs-github-bot
nodejs-github-bot merged commit 18c2b33 into nodejs:main Sep 23, 2026
101 of 104 checks passed
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Landed in 18c2b33

@nodejs-github-bot nodejs-github-bot removed commit-queue PRs queued for automated landing through the Commit Queue. lacks-second-approval Commit Queue PRs awaiting a second collaborator approval or completion of the required wait. labels Sep 23, 2026
@panva
panva deleted the webcrypto-runtime-capabilities branch September 23, 2026 08:55
aduh95 pushed a commit that referenced this pull request Sep 27, 2026
Refresh conditional algorithm registration on FIPS changes and use the
current state for parameter restrictions.

Use per-algorithm availability checks in normalization and native named
key generation. Remove getPqcKeyTypes().

Enable supports() tests under FIPS and cover state transitions in warmed
workers.

Signed-off-by: Filip Skokan <panva.ip@gmail.com>
Assisted-by: Codex
PR-URL: #66160
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author ready PRs with CI started, the required approvals, and no outstanding review comments. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants