refactor(proxy): drop tautological fips probe test and satisfy CodeQL return checks

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
yucheng 2026-09-23 07:45:39 +00:00
parent 5c237840f4
commit 6ae5df66c1
2 changed files with 10 additions and 25 deletions

View file

@ -121,9 +121,9 @@ def enforce_fips_boot_verdict(verdict: FipsBootVerdict, announce: Callable[[str]
def render_refusal(refusal: FipsBootRefusal) -> str:
match refusal:
case MalformedFipsMode(value=value):
case MalformedFipsMode():
return (
f"{REFUSAL_PREFIX}: {FIPS_MODE_ENV_VAR}={value} is not a boolean.\n"
f"{REFUSAL_PREFIX}: {FIPS_MODE_ENV_VAR}={refusal.value} is not a boolean.\n"
f"Set {FIPS_MODE_ENV_VAR} to true or false, or unset it."
)
case ProviderDoesNotEnforceFips():
@ -133,21 +133,18 @@ def render_refusal(refusal: FipsBootRefusal) -> str:
"protected with algorithms the FIPS 140-3 policy forbids. Run the proxy from a FIPS image whose\n"
f"OpenSSL FIPS provider is enabled, or unset {FIPS_MODE_ENV_VAR} on a non-FIPS runtime."
)
case TlsVerificationDisabled(sources=sources):
case TlsVerificationDisabled():
return (
f"{REFUSAL_PREFIX}: {FIPS_MODE_ENV_VAR} is on but TLS certificate verification is disabled by "
f"{' and '.join(sources)}.\nFIPS deployments must verify upstream certificates, so remove the "
f"{' and '.join(refusal.sources)}.\nFIPS deployments must verify upstream certificates, so remove the "
"override or point ssl_verify at a CA bundle instead."
)
case _:
assert_never(refusal)
return assert_never(refusal)
def _is_off(value: object) -> bool:
match value:
case bool():
return value is False
case str():
return str_to_bool(value) is False
case _:
return False
if isinstance(value, bool):
return value is False
if isinstance(value, str):
return str_to_bool(value) is False
return False

View file

@ -1,5 +1,3 @@
import hashlib
import pytest
from litellm.proxy.common_utils.fips import (
@ -12,7 +10,6 @@ from litellm.proxy.common_utils.fips import (
enforce_fips_boot_verdict,
fips_boot_verdict,
is_fips_mode,
openssl_enforces_fips,
parse_fips_mode,
)
@ -107,12 +104,3 @@ def test_verified_or_custom_bundle_tls_settings_are_not_treated_as_disabled(ssl_
def test_disabled_tls_is_reported_before_the_provider_so_operators_see_config_mistakes_first():
assert _verdict("true", enforcing=False, ssl_env="false") == TlsVerificationDisabled(sources=("SSL_VERIFY",))
assert _verdict("true", enforcing=False) == ProviderDoesNotEnforceFips()
def test_provider_probe_agrees_with_whether_md5_is_usable_for_security_here():
try:
hashlib.md5(b"", usedforsecurity=True)
except ValueError:
assert openssl_enforces_fips() is True
else:
assert openssl_enforces_fips() is False