Refactor provider helpers and fix parameter handling - #683
Merged
Merged
Conversation
Whether a PKCS#11 operation is FIPS approved depends on the underlying PKCS#11 module, token, and operation parameters, which the provider cannot generally guarantee.
Member
Behavioral changes worth mentioning in the PR descriptionAlthough primarily a reorganization, the final commit includes functional changes:
These appear beneficial, but mean the change is not strictly behavior-neutral. They would be worth documenting and possibly also covering with focused tests. |
olszomal
force-pushed
the
provider_refactor
branch
from
September 7, 2026 12:41
b684729 to
703d996
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pull Request Type
Related Issue
Issue number: N/A
Current Behavior
Provider helper functions are reorganized for clarity.
Initialization parameters are applied consistently, RSA-PSS salt length values are validated, and signature output length is initialized from the supplied buffer capacity.
The
fips=yesproperty is removed, since FIPS approval depends on the PKCS#11 module, token, and operation parameters.EC private keys without an associated public point may trigger a NULL dereference in affected OpenSSL 3.x versions when public parameters are queried.
The test suite may also modify LD_LIBRARY_PATH before resolving all OpenSSL paths, causing system tools such as
pkg-configto load an incompatible libcrypto.New Behavior
Provider helper functions are reorganized for clarity.
The
fips=yesproperty is removed, since FIPS approval depends on the PKCS#11 module, token, and operation parameters.EC public-key parameter extraction avoids the affected OpenSSL NULL dereference for private-only EC keys.
OpenSSL paths used by the test suite are resolved before modifying
LD_LIBRARY_PATH.Scope of Changes
fips=yesfrom provider algorithm definitions.LD_LIBRARY_PATHin the test suite.Testing
Additional Notes
License Declaration