Design
Design calls that were deliberate, are not obvious from the code, and would otherwise be
re-litigated every time someone new reads it. Invariants carries the
rules; this section carries the reasoning behind the ones that cost something, including the
holes left open on purpose and the measurement behind each one.
The canonical text is DESIGN.md. What follows is the same set of
entries, grouped by the subsystem they are about, each summarising the call, what it
cost, and what was rejected, with a link to the full argument.
How to read an entry
Every entry opens with a one-line status — Accepted, Accepted, knowing what it
costs, Accepted, and it changes records (or verdicts, or openssl_linkage),
Accepted, and it changes no record, or Documented, not fixed — and then answers
the same questions: what the call is, why, what it costs, what was rejected and why, and
what would make it worth revisiting.
Two habits in that file are worth knowing before you read it:
- Claims are measured, not asserted. Nearly every entry carries a reproduction, usually
a pair contrasting one approach with another over a real or synthesised object.
- What is left open is stated as plainly as what is closed. An entry that ends with a
residual has one because closing it needs a bigger change than this tool's scope covers
today, and it says so.
| Entry |
Status |
A needed entry is bundled by what it resolves to, not by whether its name was renamed |
Accepted, and it changes openssl_linkage and one finding |
A needed match and a definition inside one object are both true, so the object is mixed |
Accepted, and it changes openssl_linkage |
An OpenSSL crate with no other evidence reads unknown, not none |
Accepted, and it changes openssl_linkage |
| A version banner beside imports from the system library is header text, not a copy |
Accepted, and it changes openssl_linkage |
A version banner with no dependency and no build strings reads unknown, not static |
Accepted, and it changes openssl_linkage |
OpenSSL-named definitions beside AWS-LC or BoringSSL read unknown, not static |
Accepted, and it changes openssl_linkage |
An object that read unknown withholds DERIVED_SYSTEM_OPENSSL_ONLY; the field stays system |
Accepted, and it changes verdicts |
An SBOM naming an OpenSSL crate reads unknown, not none |
Accepted, and it changes openssl_linkage |
| Entry |
Status |
openssl_banner names every major digit, not the majors that shipped |
Accepted |
| Two kinds of list: a field's spellings and an entity list |
Accepted |
| Crates are read from every cargo source layout, and a vendored crate has no version |
Accepted, and it changes records |
| A Go FIPS build is told from a stock one by its build settings |
Accepted |
| A static OpenSSL's legacy primitives lead the headline |
Accepted, knowing what it costs |
| Suppression is keyed on rule, subject and object |
Accepted |
| An AWS-LC FIPS build is told from a stock one by its symbol prefix |
Accepted |
| A BoringSSL FIPS module is told from a stock build by its integrity test |
Accepted |
| Every symbol group is read by a rule, or says it is evidence only |
Accepted, and it changes verdicts |
| The ruleset cites a standard and the record carries only the pointer |
Accepted, and it changes records |
relation and the verdict class are checked against each other at load time |
Accepted |
family is the FIPS-agnostic axis; category stays the FIPS one |
Accepted, and it changes records |
| SHA-1 is restricted, not refused |
Accepted, and it changes verdicts |
| Entry |
Status |
| A recording cap is not a partial read |
Accepted |
| A cap bounds the record, it does not pick the evidence |
Accepted, and it changes records |
| A cap bounds the record, not the evaluation |
Accepted, and it changes verdicts |
binaries[] keeps what a finding points at, before filling the rest |
Accepted, and it changes records |
| A symbol name is capped the way PE's are |
Accepted |
caps.cap scans ordered again instead of materialising pinned/rest/leftovers |
Accepted. Performance and memory, not correctness |
bundled_libs and errors[] get their own caps, not binaries_truncated's |
Accepted, and it changes records |
skipped and symlinks reuse caps.cap, not a plain prefix |
Accepted, and it changes records |