mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-03 02:22:24 +00:00
refactor(proxy): drop tautological fips probe test and satisfy CodeQL return checks
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
parent
5c237840f4
commit
6ae5df66c1
2 changed files with 10 additions and 25 deletions
|
|
@ -121,9 +121,9 @@ def enforce_fips_boot_verdict(verdict: FipsBootVerdict, announce: Callable[[str]
|
|||
|
||||
def render_refusal(refusal: FipsBootRefusal) -> str:
|
||||
match refusal:
|
||||
case MalformedFipsMode(value=value):
|
||||
case MalformedFipsMode():
|
||||
return (
|
||||
f"{REFUSAL_PREFIX}: {FIPS_MODE_ENV_VAR}={value} is not a boolean.\n"
|
||||
f"{REFUSAL_PREFIX}: {FIPS_MODE_ENV_VAR}={refusal.value} is not a boolean.\n"
|
||||
f"Set {FIPS_MODE_ENV_VAR} to true or false, or unset it."
|
||||
)
|
||||
case ProviderDoesNotEnforceFips():
|
||||
|
|
@ -133,21 +133,18 @@ def render_refusal(refusal: FipsBootRefusal) -> str:
|
|||
"protected with algorithms the FIPS 140-3 policy forbids. Run the proxy from a FIPS image whose\n"
|
||||
f"OpenSSL FIPS provider is enabled, or unset {FIPS_MODE_ENV_VAR} on a non-FIPS runtime."
|
||||
)
|
||||
case TlsVerificationDisabled(sources=sources):
|
||||
case TlsVerificationDisabled():
|
||||
return (
|
||||
f"{REFUSAL_PREFIX}: {FIPS_MODE_ENV_VAR} is on but TLS certificate verification is disabled by "
|
||||
f"{' and '.join(sources)}.\nFIPS deployments must verify upstream certificates, so remove the "
|
||||
f"{' and '.join(refusal.sources)}.\nFIPS deployments must verify upstream certificates, so remove the "
|
||||
"override or point ssl_verify at a CA bundle instead."
|
||||
)
|
||||
case _:
|
||||
assert_never(refusal)
|
||||
return assert_never(refusal)
|
||||
|
||||
|
||||
def _is_off(value: object) -> bool:
|
||||
match value:
|
||||
case bool():
|
||||
return value is False
|
||||
case str():
|
||||
return str_to_bool(value) is False
|
||||
case _:
|
||||
return False
|
||||
if isinstance(value, bool):
|
||||
return value is False
|
||||
if isinstance(value, str):
|
||||
return str_to_bool(value) is False
|
||||
return False
|
||||
|
|
|
|||
|
|
@ -1,5 +1,3 @@
|
|||
import hashlib
|
||||
|
||||
import pytest
|
||||
|
||||
from litellm.proxy.common_utils.fips import (
|
||||
|
|
@ -12,7 +10,6 @@ from litellm.proxy.common_utils.fips import (
|
|||
enforce_fips_boot_verdict,
|
||||
fips_boot_verdict,
|
||||
is_fips_mode,
|
||||
openssl_enforces_fips,
|
||||
parse_fips_mode,
|
||||
)
|
||||
|
||||
|
|
@ -107,12 +104,3 @@ def test_verified_or_custom_bundle_tls_settings_are_not_treated_as_disabled(ssl_
|
|||
def test_disabled_tls_is_reported_before_the_provider_so_operators_see_config_mistakes_first():
|
||||
assert _verdict("true", enforcing=False, ssl_env="false") == TlsVerificationDisabled(sources=("SSL_VERIFY",))
|
||||
assert _verdict("true", enforcing=False) == ProviderDoesNotEnforceFips()
|
||||
|
||||
|
||||
def test_provider_probe_agrees_with_whether_md5_is_usable_for_security_here():
|
||||
try:
|
||||
hashlib.md5(b"", usedforsecurity=True)
|
||||
except ValueError:
|
||||
assert openssl_enforces_fips() is True
|
||||
else:
|
||||
assert openssl_enforces_fips() is False
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue