Skip to content

CLI exits at import when MD5 is unavailable: botocore/compat.py catches ValueError but hashlib raises AttributeError #10733

Description

@jacob-ablowitz

Describe the bug

On a FIPS-hardened system where OpenSSL refuses MD5, aws exits during import, before running any command (including aws --version):

File ".../awscli/botocore/compat.py", line 152, in <module>
    hashlib.md5()
AttributeError: module 'hashlib' has no attribute 'md5'

The MD5 availability probe in awscli/botocore/compat.py expects ValueError:

# Checks to see if md5 is available on this system. A given system might not
# have access to it for various reasons, such as FIPS mode being enabled.
try:
    hashlib.md5()
    MD5_AVAILABLE = True
except ValueError:
    MD5_AVAILABLE = False

In CPython 3.14, if OpenSSL refuses MD5 and the interpreter has no builtin _md5 fallback (hardened distributions commonly build with --with-builtin-hashlib-hashes excluding md5), hashlib never defines an md5 attribute: at import it logs code for hash md5 was not found and skips the name. Calling hashlib.md5() therefore raises AttributeError, which escapes the except clause. The comment above the probe says it exists for exactly this case.

Regression Issue

  • Select this option if this issue appears to be a regression.

Expected Behavior

MD5_AVAILABLE = False, and the CLI runs. Commands that genuinely need MD5 fail with the existing "MD5 unavailable" handling.

Current Behavior

Every aws invocation exits with AttributeError: module 'hashlib' has no attribute 'md5' at import time.

Reproduction Steps

  1. A Linux system whose OpenSSL (4.0.x here) has a FIPS provider active and the legacy provider disabled, and a CPython 3.14 built without the builtin md5 fallback. We reproduced it with the Wolfi/Chainguard aws-cli-2 package on a FIPS-hardened OpenSSL 4 base image.
  2. Run aws --version.

Possible Solution

except (ValueError, AttributeError):, or check hasattr(hashlib, "md5") first. We verified the first form locally: with MD5 refused, s3 ls, multipart s3 cp (both directions, byte-identical), s3 sync, s3api head-object and s3 rm all work.

Additional Information/Context

Related feature request (client-side cryptography on a FIPS-validated module): #10734

CLI version used

2.37.9

Environment details (OS name and version, etc.)

Wolfi-based FIPS container image; OpenSSL 4.0.3 with a FIPS provider, legacy provider disabled; Python 3.14.8 (no builtin md5); Linux x86_64 and aarch64.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions