Skip to content

8336499: Failure when creating non-CRT RSA private keys in SunPKCS11 #2979

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed

Conversation

Sorna-Sarathi
Copy link

@Sorna-Sarathi Sorna-Sarathi commented Oct 21, 2024

Hi all,
This pull request contains a backport of commit 3251eea from the openjdk/jdk repository.
I've also resolved a build failure with the latest version of gtest(In JDK17) by backporting the fix.
Thanks!

JBS Issue: JDK-8336499


Progress

  • Change must not contain extraneous whitespace
  • JDK-8336499 needs maintainer approval
  • Commit message must refer to an issue

Issue

  • JDK-8336499: Failure when creating non-CRT RSA private keys in SunPKCS11 (Bug - P4 - Approved)

Reviewing

Using git

Checkout this PR locally:
$ git fetch https://git.openjdk.org/jdk17u-dev.git pull/2979/head:pull/2979
$ git checkout pull/2979

Update a local copy of the PR:
$ git checkout pull/2979
$ git pull https://git.openjdk.org/jdk17u-dev.git pull/2979/head

Using Skara CLI tools

Checkout this PR locally:
$ git pr checkout 2979

View PR using the GUI difftool:
$ git pr show -t 2979

Using diff file

Download this PR as a diff file:
https://git.openjdk.org/jdk17u-dev/pull/2979.diff

Using Webrev

Link to Webrev Comment

@bridgekeeper bridgekeeper bot added the oca Needs verification of OCA signatory status label Oct 21, 2024
@bridgekeeper
Copy link

bridgekeeper bot commented Oct 21, 2024

Hi @Sorna-Sarathi, welcome to this OpenJDK project and thanks for contributing!

We do not recognize you as Contributor and need to ensure you have signed the Oracle Contributor Agreement (OCA). If you have not signed the OCA, please follow the instructions. Please fill in your GitHub username in the "Username" field of the application. Once you have signed the OCA, please let us know by writing /signed in a comment in this pull request.

If you already are an OpenJDK Author, Committer or Reviewer, please click here to open a new issue so that we can record that fact. Please use "Add GitHub user Sorna-Sarathi" as summary for the issue.

If you are contributing this work on behalf of your employer and your employer has signed the OCA, please let us know by writing /covered in a comment in this pull request.

@openjdk
Copy link

openjdk bot commented Oct 21, 2024

@Sorna-Sarathi This change now passes all automated pre-integration checks.

ℹ️ This project also has non-automated pre-integration requirements. Please see the file CONTRIBUTING.md for details.

After integration, the commit message for the final commit will be:

8336499: Failure when creating non-CRT RSA private keys in SunPKCS11

You can use pull request commands such as /summary, /contributor and /issue to adjust it as needed.

At the time when this comment was updated there had been 38 new commits pushed to the master branch:

As there are no conflicts, your changes will automatically be rebased on top of these commits when integrating. If you prefer to avoid this automatic rebasing, please check the documentation for the /integrate command for further details.

As you do not have Committer status in this project an existing Committer must agree to sponsor your change.

➡️ To flag this PR as ready for integration with the above commit message, type /integrate in a new comment. (Afterwards, your sponsor types /sponsor in a new comment to perform the integration).

@openjdk openjdk bot changed the title Backport 3251eea1f4289a0505052be204407c02ca38b0ad 8336499: Failure when creating non-CRT RSA private keys in SunPKCS11 Oct 21, 2024
@openjdk
Copy link

openjdk bot commented Oct 21, 2024

This backport pull request has now been updated with issue from the original commit.

@openjdk openjdk bot added backport Port of a pull request already in a different code base clean Identical backport; no merge resolution required labels Oct 21, 2024
@Sorna-Sarathi
Copy link
Author

/covered

@bridgekeeper bridgekeeper bot added the oca-verify Needs verification of OCA signatory status label Oct 21, 2024
@bridgekeeper
Copy link

bridgekeeper bot commented Oct 21, 2024

Thank you! Please allow for a few business days to verify that your employer has signed the OCA. Also, please note that pull requests that are pending an OCA check will not usually be evaluated, so your patience is appreciated!

@bridgekeeper bridgekeeper bot removed oca Needs verification of OCA signatory status oca-verify Needs verification of OCA signatory status labels Oct 22, 2024
@openjdk
Copy link

openjdk bot commented Oct 22, 2024

⚠️ @Sorna-Sarathi This change is now ready for you to apply for maintainer approval. This can be done directly in each associated issue or by using the /approval command.

@openjdk openjdk bot added the rfr Pull request is ready for review label Oct 22, 2024
@mlbridge
Copy link

mlbridge bot commented Oct 22, 2024

Webrevs

@offamitkumar
Copy link
Member

Here also, GHA is not enabled.

@bridgekeeper
Copy link

bridgekeeper bot commented Nov 20, 2024

@Sorna-Sarathi This pull request has been inactive for more than 4 weeks and will be automatically closed if another 4 weeks passes without any activity. To avoid this, simply add a new comment to the pull request. Feel free to ask for assistance if you need help with progressing this pull request towards integration!

@Sorna-Sarathi
Copy link
Author

/approval request fixes failure when creating non-CRT RSA private keys in SunPKCS11. Backporting it.

@openjdk
Copy link

openjdk bot commented Nov 20, 2024

@Sorna-Sarathi
8336499: The approval request has been created successfully.

@openjdk openjdk bot added the approval Requires approval; will be removed when approval is received label Nov 20, 2024
@openjdk openjdk bot removed the approval Requires approval; will be removed when approval is received label Dec 12, 2024
@bridgekeeper
Copy link

bridgekeeper bot commented Dec 18, 2024

@Sorna-Sarathi This pull request has been inactive for more than 4 weeks and will be automatically closed if another 4 weeks passes without any activity. To avoid this, simply add a new comment to the pull request. Feel free to ask for assistance if you need help with progressing this pull request towards integration!

@Sorna-Sarathi
Copy link
Author

Working on the unsuccessful tests

@bridgekeeper
Copy link

bridgekeeper bot commented Feb 10, 2025

@Sorna-Sarathi This pull request has been inactive for more than 4 weeks and will be automatically closed if another 4 weeks passes without any activity. To avoid this, simply add a new comment to the pull request. Feel free to ask for assistance if you need help with progressing this pull request towards integration!

@Sorna-Sarathi
Copy link
Author

Sorna-Sarathi commented Feb 26, 2025

Hi @GoeLin,
I had tested Tier 2 level tests for this change and it ended with few failures. I also checked with them and they're not related to the current backport changes.
Regarding the GHA failures, the "xcode-select: error: invalid developer directory '/Applications/Xcode_14.3.1.app/Contents/Developer'" issue which has been resolved by 82a609d.

@Sorna-Sarathi
Copy link
Author

/approval request fixes failure when a non-CRT key is created in a token, the query including all attributes will fail and CKA_MODULUS and CKA_PRIVATE_EXPONENT will not be available and will throw an error. Backporting it.

@openjdk
Copy link

openjdk bot commented Feb 26, 2025

@Sorna-Sarathi
8336499: The approval request has been updated successfully.

@openjdk openjdk bot added the approval Requires approval; will be removed when approval is received label Feb 26, 2025
@Sorna-Sarathi
Copy link
Author

Sorna-Sarathi commented Mar 3, 2025

Hi @GoeLin,

Fix Request 17u

Backporting this patch to fix the issue described. The patch applies cleanly.

Risk is medium. It changes the critical component security-libs. No regressions observed in jdk/sun/security/pkcs11 . A regression test is hard to test for pre PKCS 11 standard v2.40 explained in the JBS comment.

Ran the tier 1-2 tests. Tier 2 ended with few failures and they aren't related to the current changes.

Thanks,
Sorna Sarathi.

@GoeLin
Copy link
Member

GoeLin commented Mar 14, 2025

Hi @Sorna-Sarathi
Thanks for testing etc.
Basically this is good to go now. I ran it through our testing without issues.
But I think we should await till this has some live coverage. So I'll label jdk17u-defer-next and approve it some later.
Thanks.

@bridgekeeper
Copy link

bridgekeeper bot commented Apr 11, 2025

@Sorna-Sarathi This pull request has been inactive for more than 4 weeks and will be automatically closed if another 4 weeks passes without any activity. To avoid this, simply add a new comment to the pull request. Feel free to ask for assistance if you need help with progressing this pull request towards integration!

@bridgekeeper
Copy link

bridgekeeper bot commented May 9, 2025

@Sorna-Sarathi This pull request has been inactive for more than 8 weeks and will now be automatically closed. If you would like to continue working on this pull request in the future, feel free to reopen it! This can be done using the /open pull request command.

@bridgekeeper bridgekeeper bot closed this May 9, 2025
@Sorna-Sarathi
Copy link
Author

/open

@openjdk openjdk bot reopened this May 14, 2025
@openjdk
Copy link

openjdk bot commented May 14, 2025

@Sorna-Sarathi This pull request is now open

@bridgekeeper
Copy link

bridgekeeper bot commented Jun 11, 2025

@Sorna-Sarathi This pull request has been inactive for more than 4 weeks and will be automatically closed if another 4 weeks passes without any activity. To avoid this, simply issue a /touch or /keepalive command to the pull request. Feel free to ask for assistance if you need help with progressing this pull request towards integration!

@GoeLin
Copy link
Member

GoeLin commented Jun 16, 2025

Hi @Sorna-Sarathi
I think it is time now to push this. Can you please merge head for new testing?

@Sorna-Sarathi
Copy link
Author

Hi @Sorna-Sarathi I think it is time now to push this. Can you please merge head for new testing?

Hi @GoeLin
Merged and the tests were also passed.

@openjdk openjdk bot added ready Pull request is ready to be integrated and removed approval Requires approval; will be removed when approval is received labels Jun 26, 2025
@Sorna-Sarathi
Copy link
Author

/integrate

@openjdk openjdk bot added the sponsor Pull request is ready to be sponsored label Jun 26, 2025
@openjdk
Copy link

openjdk bot commented Jun 26, 2025

@Sorna-Sarathi
Your change (at version 0e73df1) is now ready to be sponsored by a Committer.

@phohensee
Copy link
Member

/sponsor

@openjdk
Copy link

openjdk bot commented Jun 26, 2025

Going to push as commit 2a9bba2.
Since your change was applied there have been 40 commits pushed to the master branch:

Your commit was automatically rebased without conflicts.

@openjdk openjdk bot added the integrated Pull request has been integrated label Jun 26, 2025
@openjdk openjdk bot closed this Jun 26, 2025
@openjdk openjdk bot removed ready Pull request is ready to be integrated rfr Pull request is ready for review sponsor Pull request is ready to be sponsored labels Jun 26, 2025
@openjdk
Copy link

openjdk bot commented Jun 26, 2025

@phohensee @Sorna-Sarathi Pushed as commit 2a9bba2.

💡 You may see a message that your pull request was closed with unmerged commits. This can be safely ignored.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backport Port of a pull request already in a different code base clean Identical backport; no merge resolution required integrated Pull request has been integrated
Development

Successfully merging this pull request may close these issues.

4 participants