Describe the bug
On a FIPS-hardened system where OpenSSL refuses MD5, aws exits during import, before running any command (including aws --version):
File ".../awscli/botocore/compat.py", line 152, in <module>
hashlib.md5()
AttributeError: module 'hashlib' has no attribute 'md5'
The MD5 availability probe in awscli/botocore/compat.py expects ValueError:
# Checks to see if md5 is available on this system. A given system might not
# have access to it for various reasons, such as FIPS mode being enabled.
try:
hashlib.md5()
MD5_AVAILABLE = True
except ValueError:
MD5_AVAILABLE = False
In CPython 3.14, if OpenSSL refuses MD5 and the interpreter has no builtin _md5 fallback (hardened distributions commonly build with --with-builtin-hashlib-hashes excluding md5), hashlib never defines an md5 attribute: at import it logs code for hash md5 was not found and skips the name. Calling hashlib.md5() therefore raises AttributeError, which escapes the except clause. The comment above the probe says it exists for exactly this case.
Regression Issue
Expected Behavior
MD5_AVAILABLE = False, and the CLI runs. Commands that genuinely need MD5 fail with the existing "MD5 unavailable" handling.
Current Behavior
Every aws invocation exits with AttributeError: module 'hashlib' has no attribute 'md5' at import time.
Reproduction Steps
- A Linux system whose OpenSSL (4.0.x here) has a FIPS provider active and the
legacy provider disabled, and a CPython 3.14 built without the builtin md5 fallback. We reproduced it with the Wolfi/Chainguard aws-cli-2 package on a FIPS-hardened OpenSSL 4 base image.
- Run
aws --version.
Possible Solution
except (ValueError, AttributeError):, or check hasattr(hashlib, "md5") first. We verified the first form locally: with MD5 refused, s3 ls, multipart s3 cp (both directions, byte-identical), s3 sync, s3api head-object and s3 rm all work.
Additional Information/Context
Related feature request (client-side cryptography on a FIPS-validated module): #10734
CLI version used
2.37.9
Environment details (OS name and version, etc.)
Wolfi-based FIPS container image; OpenSSL 4.0.3 with a FIPS provider, legacy provider disabled; Python 3.14.8 (no builtin md5); Linux x86_64 and aarch64.
Describe the bug
On a FIPS-hardened system where OpenSSL refuses MD5,
awsexits during import, before running any command (includingaws --version):The MD5 availability probe in
awscli/botocore/compat.pyexpectsValueError:In CPython 3.14, if OpenSSL refuses MD5 and the interpreter has no builtin
_md5fallback (hardened distributions commonly build with--with-builtin-hashlib-hashesexcluding md5),hashlibnever defines anmd5attribute: at import it logscode for hash md5 was not foundand skips the name. Callinghashlib.md5()therefore raisesAttributeError, which escapes theexceptclause. The comment above the probe says it exists for exactly this case.Regression Issue
Expected Behavior
MD5_AVAILABLE = False, and the CLI runs. Commands that genuinely need MD5 fail with the existing "MD5 unavailable" handling.Current Behavior
Every
awsinvocation exits withAttributeError: module 'hashlib' has no attribute 'md5'at import time.Reproduction Steps
legacyprovider disabled, and a CPython 3.14 built without the builtin md5 fallback. We reproduced it with the Wolfi/Chainguardaws-cli-2package on a FIPS-hardened OpenSSL 4 base image.aws --version.Possible Solution
except (ValueError, AttributeError):, or checkhasattr(hashlib, "md5")first. We verified the first form locally: with MD5 refused,s3 ls, multiparts3 cp(both directions, byte-identical),s3 sync,s3api head-objectands3 rmall work.Additional Information/Context
Related feature request (client-side cryptography on a FIPS-validated module): #10734
CLI version used
2.37.9
Environment details (OS name and version, etc.)
Wolfi-based FIPS container image; OpenSSL 4.0.3 with a FIPS provider, legacy provider disabled; Python 3.14.8 (no builtin md5); Linux x86_64 and aarch64.