From 506fed297b11fc17a8e83b647469de1eb2db04f5 Mon Sep 17 00:00:00 2001 From: Sergei Dubov Date: Tue, 19 Nov 2024 03:16:16 +0100 Subject: [PATCH] [rdct] IJPL-166181. Disable using self-contained set of file systems with ebabled FIPS - Update scripts for launching backend to check for FIPS enabled in OS before importing self-contained libiries. (cherry picked from commit 2b86435ec1f91cb94546451a4ed9c46b5f6f47a4) IJ-CR-149619 GitOrigin-RevId: 44af0bc6125422043709c7e8ceba4c27e20b2887 --- native/XPlatLauncher/src/remote_dev.rs | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/native/XPlatLauncher/src/remote_dev.rs b/native/XPlatLauncher/src/remote_dev.rs index a550771f6e8d..405bbca7e0e4 100644 --- a/native/XPlatLauncher/src/remote_dev.rs +++ b/native/XPlatLauncher/src/remote_dev.rs @@ -517,6 +517,11 @@ fn preload_native_libs(ide_home_dir: &PathBuf) -> Result<()> { use std::collections::BTreeSet; use std::mem; + if is_fips() { + debug!("Unable to use libraries for self-contained distribution with FIPS enabled."); + return Ok(()); + } + let use_libs = parse_bool_env_var("REMOTE_DEV_SERVER_USE_SELF_CONTAINED_LIBS", true)?; if !use_libs { return Ok(()) @@ -614,3 +619,10 @@ fn is_wsl2() -> bool { .map(|x| x.contains("WSL2")) .unwrap_or(false) } + +#[cfg(target_os = "linux")] +fn is_fips() -> bool { + fs::read_to_string("/proc/sys/crypto/fips_enabled") + .map(|x| x.contains("1")) + .unwrap_or(false) +}