On Tue, 16 Apr 2024 00:15:34 GMT, Valerie Peng <valer...@openjdk.org> wrote:

> It is reported that some PKCS#11 library/vendor reports major version 3, but 
> doesn't implement the C_GetInterface function and the resulting 'interface' 
> variable value may be NULL and cause unexpected crash later.
> 
> This PR would check the 'interface' variable value to be non-NULL.
> Reproducing this would require certain 3rd party PKCS#11 library, and thus 
> the noreg-hard label.
> 
> Thanks~
> FYI, I will be on vacation starting 4/17 and will address the review comments 
> upon return. 
> Valerie

LGTM.

src/jdk.crypto.cryptoki/unix/native/libj2pkcs11/p11_md.c line 221:

> 219:         goto cleanup;
> 220:     }
> 221:     if (((CK_VERSION *)moduleData->ckFunctionListPtr)->major == 3 &&

(preexisting) you could remove the assignment in line 214 above

-------------

Marked as reviewed by djelinski (Reviewer).

PR Review: https://git.openjdk.org/jdk/pull/18789#pullrequestreview-2002643288
PR Review Comment: https://git.openjdk.org/jdk/pull/18789#discussion_r1566750152

Reply via email to