Skip to content

fix: pass usedforsecurity=False to md5/sha1 calls (FIPS crash) - #127211

Open
ahisblessed wants to merge 1 commit into
NousResearch:mainfrom
ahisblessed:fix/hashlib-fips-usedforsecurity-skills-hub-web
Open

ahisblessed wants to merge 1 commit into
NousResearch:mainfrom
ahisblessed:fix/hashlib-fips-usedforsecurity-skills-hub-web

Conversation

@ahisblessed

Copy link
Copy Markdown

Summary

hashlib.md5() / hashlib.sha1() raise ValueError: [digital envelope routines] disabled for FIPS on FIPS-enabled platforms (e.g. RHEL 8/9 with FIPS mode) unless usedforsecurity=False is passed. Seven call sites across the codebase call these constructors without the flag. All of them are non-security uses (cache-key digests and short display digests), so the fix is to pass usedforsecurity=False — behavior is unchanged everywhere else.

This continues the earlier FIPS sweeps (#56715, #56716, #56719, #62654, #64062, #64808, #66857, #73278), which left these files uncovered.

Changes

File Site Use
tools/skills_hub_clawhub.py 2x hashlib.md5 ClawHub search listing/catalog cache keys
tools/skills_hub_sources.py hashlib.md5 well-known index memo key
tools/skills_hub_skillssh.py 2x hashlib.md5 search cache key + skill detail key
hermes_cli/web_server_profiles.py hashlib.sha1 short profile-path digest
hermes_cli/web_routers/mcp.py hashlib.sha1 short server-name digest
plugins/platforms/wecom/media.py hashlib.md5 WeCom upload init payload md5 field
tui_gateway/server.py hashlib.sha1 revision source digest

SHA-256 calls are FIPS-approved and intentionally untouched, as are hmac.new(hashlib.sha1, ...) constructor references.

Test plan

  • ast.parse clean on all 7 changed files
  • pytest tests/tools/test_skills_hub_clawhub.py tests/tools/test_skills_hub_browse_sh.py tests/tools/test_clawhub_owner_http.py tests/tools/test_clawhub_zip_stream.py tests/tools/test_skills_hub.py — 150 passed, 1 skipped
  • grep confirms no remaining direct hashlib.md5/hashlib.sha1 calls without the flag in the touched files

hashlib.md5() and hashlib.sha1() raise ValueError ("disabled for
FIPS") on FIPS-enabled platforms (RHEL 8/9 with FIPS mode) unless
usedforsecurity=False is passed. Every call site touched here is
non-security: cache-key digests and short display digests, so the
flag is safe and behavior is unchanged elsewhere.

Sites fixed (all previously without the flag):
- tools/skills_hub_clawhub.py: cache keys for ClawHub search listing/catalog
- tools/skills_hub_sources.py: well-known index memo key
- tools/skills_hub_skillssh.py: search cache key + skill detail key
- hermes_cli/web_server_profiles.py: short profile-path digest
- hermes_cli/web_routers/mcp.py: short server-name digest
- plugins/platforms/wecom/media.py: WeCom upload init payload md5
- tui_gateway/server.py: revision source digest

SHA-256 calls are FIPS-approved and intentionally untouched, as are
hmac.new(hashlib.sha1, ...) constructor references.

Verified: ast.parse on all 7 files; tests/tools/test_skills_hub*.py,
test_clawhub_*.py -> 150 passed, 1 skipped.
@alt-glitch alt-glitch added type/security Security vulnerability or hardening P3 Low — cosmetic, nice to have comp/cli CLI entry point, hermes_cli/, setup wizard comp/plugins Plugin system and bundled plugins comp/tui Terminal UI (ui-tui/ + tui_gateway/) tool/skills Skills system (list, view, manage) platform/wecom WeCom / WeChat Work adapter sweeper:risk-compatibility Sweeper risk: may break existing users, config, migrations, defaults, or upgrades labels Sep 29, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp/cli CLI entry point, hermes_cli/, setup wizard comp/plugins Plugin system and bundled plugins comp/tui Terminal UI (ui-tui/ + tui_gateway/) P3 Low — cosmetic, nice to have platform/wecom WeCom / WeChat Work adapter sweeper:risk-compatibility Sweeper risk: may break existing users, config, migrations, defaults, or upgrades tool/skills Skills system (list, view, manage) type/security Security vulnerability or hardening

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants