Repository navigation
Validate attribute templates before changing objects - #235
Open
aidangarske wants to merge 97 commits into
Open
aidangarske wants to merge 97 commits into
aidangarske wants to merge 97 commits into
Conversation
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
The storage-decoding tests contain a false-negative realloc check, and the documented PR scope omits substantial public behavior changes.
3 open findings
What changed in this PR
Hardens attribute validation while also expanding storage, session lifecycle, token information, and mechanism behavior.
Changes:
- Validates complete attribute templates before mutation.
- Improves persistence, PIN, operation, and mechanism handling.
- Adds broad regression tests and CI configurations.
| File | Description |
|---|---|
wolfpkcs11/pkcs11.h |
Adds operation-cancellation error code. |
wolfpkcs11/internal.h |
Adds limits and internal lifecycle APIs. |
src/wolfpkcs11.c |
Updates initialization, finalization, and info handling. |
src/slot.c |
Corrects token information and mechanism metadata. |
tests/attribute_validation_test.c |
Tests template validation behavior. |
tests/ec_derive_test.c |
Tests ECDH derivation invariants. |
tests/info_mech_table_test.c |
Tests information and mechanism tables. |
tests/login_pin_state_test.c |
Tests login, PIN, and concurrency state. |
tests/object_store_decode_test.c |
Tests corrupted storage records. |
tests/token_store_test.c |
Tests persistence failure handling. |
tests/pkcs11test.c |
Updates core behavioral expectations. |
tests/pkcs11mtt.c |
Updates multithreaded cancellation expectations. |
tests/include.am |
Registers the new test programs. |
.github/workflows/unit-test.yml |
Adds TPM-debug and no-environment coverage. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+902
to
+910
| static void* scan_realloc(void* ptr, size_t sz) | ||
| { | ||
| int i = track_find(ptr); | ||
| void* newPtr = realloc(ptr, sz); | ||
|
|
||
| if (newPtr != NULL) { | ||
| if (i >= 0) | ||
| tracked[i].ptr = NULL; | ||
| track_add(newPtr, sz); |
| WP11_Library_Final(); | ||
|
|
||
| ret = CKR_OK; | ||
| ret = WP11_Library_Final() == 0 ? CKR_OK : CKR_FUNCTION_FAILED; |
| (void)argc; | ||
| (void)argv; | ||
| printf("File-backed token storage not available, skipping test\n"); | ||
| return 0; |
18 tasks
aidangarske
force-pushed
the
fenrir-fixes-11503-11511
branch
2 times, most recently
from
October 9, 2026 02:00
b37f8d4 to
e5d5892
Compare
aidangarske
force-pushed
the
fenrir-fixes-11503-11511
branch
from
October 10, 2026 03:20
e5d5892 to
79fa060
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


F-11503- 2d3a23c - The companion RSA public key created by unwrap now defaults to a session object instead of using a NULL CKA_TOKEN value.F-12460- b75d25d - CKA_TOKEN is now validated as a boolean attribute, requiring a non-NULL value of the right length.F-5255- 11a07dc - SetAttributeValue now returns CKR_ARGUMENTS_BAD when the attribute count is above INT_MAX.F-5254- cca0440 - C_GetAttributeValue now returns CKR_ARGUMENTS_BAD when the attribute count is above INT_MAX.F-5256- 4f0f2a3 - The C_FindObjects loop index is now a CK_ULONG.F-13831- 5d67738 - New CheckCopyOnlyAttributes, called from C_SetAttributeValue, rejects changes to CKA_TOKEN, CKA_PRIVATE and CKA_MODIFIABLE on an existing object, and the attribute count is limited to INT_MAX.F-11511- 0325022 - CKA_ALWAYS_SENSITIVE and CKA_NEVER_EXTRACTABLE are now rejected in creation templates as well as updates.F-8670- bcfc52f - A creation template can no longer change the object class after type storage has been allocated, and returns CKR_TEMPLATE_INCONSISTENT.F-13242- ed659cd - CheckAttributeUpdate now runs over the whole template before any change is applied, and again just before each write of a one-way attribute.F-4268- ffa5b74 - CheckAttributes now rejects data attributes longer than INT_MAX before reading them, and the int cast on the value length in SetAttributeValue is removed.F-2773- f8dd329 - Setting CKA_ALWAYS_AUTHENTICATE to TRUE now returns CKR_ATTRIBUTE_VALUE_INVALID on create and set, while FALSE is still accepted.F-11517- 55cec79 - CheckAttributes now rejects a NULL value with a non-zero length for data attributes, and WP11_Object_SetData and WP11_Object_SetKeyId check for NULL.F-6234- 1b666cd - An empty CKA_START_DATE or CKA_END_DATE is now accepted and clears the date.F-12462- d01a7ac - WP11_Object_SetKeyId and WP11_Object_SetData now allocate and copy the new value before freeing the old one.F-2030- e5d5892 - WP11_Object_SetAttr now reads CKA_CERTIFICATE_CATEGORY as a full CK_ULONG before narrowing it.