[Pkg-freeipa-devel] [Git][freeipa-team/jss][upstream] 79 commits: Update version number to 5.10.0-alpha1

Timo Aaltonen (@tjaalton) gitlab at salsa.debian.org
Sun Sep 27 08:05:10 BST 2026



Timo Aaltonen pushed to branch upstream at FreeIPA packaging / jss


Commits:
ca596e99 by Marco Fargetta at 2026-01-15T16:27:22+01:00
Update version number to 5.10.0-alpha1

- - - - -
7228b499 by Marco Fargetta at 2026-01-15T16:50:04+01:00
update pom.xml version

- - - - -
9af1e2b9 by Marco Fargetta at 2026-01-16T12:01:05+01:00
Fix spec file error blocking the build

- - - - -
6c33e42f by Endi S. Dewata at 2026-01-22T15:34:41-06:00
Clean up RPM spec

- - - - -
8e0658f0 by Endi S. Dewata at 2026-01-22T15:34:45-06:00
Fix CI for Fedora 42

- - - - -
e4d073eb by Endi S. Dewata at 2026-01-22T16:33:36-06:00
Fix typos

- - - - -
1c27f8a8 by Endi S. Dewata at 2026-01-27T00:01:50+07:00
Fix Tomcat tests

The Tomcat tests have been updated to work with the latest
Tomcat and OpenSSL on Fedora 42 and 43.

- - - - -
6aba7c4c by Endi S. Dewata at 2026-01-26T11:26:52-06:00
Fix Azure pipeline

- - - - -
f3d05b27 by Jack Magne at 2026-01-26T17:30:05-08:00
Fix inconsistent template for lunasa when generating tempoary private key as part of recovering private key for the kra.

- - - - -
84277e4c by Marco Fargetta at 2026-02-04T09:34:16+01:00
Customisable SSL buffer size

Buffer size for RSA and EC could be too small for PQC algorithms with
problem to read SSL packets.

The buffer size has been made customisable using the java option
`jdk.tls.maxHandshakeMessageSize` but the default value has not been
modified.

Additionally, in case the buffer become full and the communication
is not working because the packet cannot stay in the buffer, an SSL
exception is raised with a proper message so the admin can modify
the configuration.

Assisted-by: Claude

- - - - -
4ce26f72 by Endi S. Dewata at 2026-02-09T14:40:06-06:00
Add test-init.sh

The test-init.sh has been added to initialize the default
values of some environment variables in several branches.
This way the same code can be used in multiple branches
which simplifies the branching process.

- - - - -
a62ef754 by Endi S. Dewata at 2026-02-10T17:33:57-06:00
Fix default values in test-init.sh

The test-init.sh has been updated to set the default values
of environment variables properly for all branches.

- - - - -
da0bd3d0 by Endi S. Dewata at 2026-02-10T19:20:32-06:00
Fix default values for v5.9 branch

- - - - -
5c441656 by Marco Fargetta at 2026-02-19T17:28:26+01:00
Fix application data send with multiple packets

The additional check for buffer size to avoid looping in case of big
handshake packets was blocking also the application data to be sent.

To avoid limiting the application data an additional check on the
handshake status is included. If the handshake is complete then the
buffer size can contain the handshake packets and there is no need to
perform additional checks.

- - - - -
d903f927 by Vladimir Petko at 2026-03-17T10:00:00+01:00
fix: use size_t in call to JSS_FromByteArray

- - - - -
ebf29b79 by Vladimir Petko at 2026-03-17T10:00:00+01:00
fix: add overflow check.

- - - - -
c527e376 by Endi S. Dewata at 2026-03-19T12:04:44-05:00
Use Java 21 on Fedora 43

- - - - -
7eb0818c by Endi S. Dewata at 2026-03-23T08:49:52-07:00
Fix race condition segfault in JSSEngineReferenceImpl cleanup

The finalizer thread was experiencing segfaults during PR.Shutdown()
calls due to a race condition where multiple threads could execute
cleanup operations simultaneously on the same object.

Root cause:
- cleanup(), closeInbound(), closeOutbound(), and tryCleanup()
  methods were not synchronized
- Multiple threads could simultaneously check and modify the boolean
  flags (closed_fd, is_inbound_closed, is_outbound_closed)
- One thread could close/free ssl_fd while another thread was still
  using it in PR.Shutdown(), causing SIGSEGV in NSS memcpy

Changes:
- Add synchronized modifier to closeInbound(), closeOutbound(),
  cleanup(), and tryCleanup() methods
- The synchronized keyword provides both mutual exclusion (only one
  thread can execute these methods at a time) and memory visibility
  (changes to fields are visible to other threads)

This prevents concurrent cleanup operations from corrupting the native
PRFileDesc pointer and eliminates the segfault during finalization.

Assisted-by: Claude Sonnet 4.5

- - - - -
cc889974 by Endi S. Dewata at 2026-04-03T10:17:13-05:00
Update Password.readPasswordFromConsole()

The Password.readPasswordFromConsole() has been modified to
read the password from the standard input in case the system
console is not available (e.g. in CI environment).

Assisted-by: Gemini Code Assist

- - - - -
bd994f97 by Endi S. Dewata at 2026-04-06T19:09:26+00:00
Clean up exception messages in PKCS7.parse()

- - - - -
3a9ef779 by Endi S. Dewata at 2026-04-21T19:40:37-04:00
Fix TOCTOU race condition in JSSEngineReferenceImpl cleanup

The finalizer thread was still experiencing segfaults after the initial
synchronization fix (7eb0818c) due to a time-of-check to time-of-use
race condition in cleanupSSLFD().

Root cause:
- The closed_fd flag was set in the finally block AFTER native resources
  were freed (ssl_fd.close())
- Another thread could call closeInbound()/closeOutbound(), check
  !closed_fd (still false), and attempt PR.Shutdown() on the already-freed
  ssl_fd pointer, causing SIGSEGV in NSS memcpy

The fix:
- Set closed_fd = true BEFORE freeing native resources
- This ensures the guard checks in closeInbound()/closeOutbound() will
  prevent any concurrent PR.Shutdown() calls on ssl_fd that is being freed
- Remove finally block since closed_fd is now set before exception can occur

This completes the fix for the race condition segfault in cleanup.

Assisted-by: Claude Sonnet 4.5

- - - - -
5e4a2cc2 by Endi S. Dewata at 2026-04-24T15:46:42-04:00
Update Tomcat cipher test

Due to recent changes in Tomcat the cipher test needs to be
updated to configure the TLS 1.2 ciphers and TLS 1.3 cipher
suites in separate attributes in server.xml.

- - - - -
a537df46 by Endi S. Dewata at 2026-04-27T09:07:37-05:00
Update CryptoManager.findCertByNickname() to require nickname

- - - - -
fccefb9e by Endi S. Dewata at 2026-04-29T13:43:39-05:00
Update RPM spec to use %autochangelog

- - - - -
f1afa0ef by Marco Fargetta at 2026-05-07T11:28:18+02:00
Enable ML-DSA key pair initialisation with named parameter

JSR spec 497 [1] define key pair generation using named paramter for
ML-DSA but current implementation was using only key strength to
follow NSS implementation. Therefore, the initialisation with named
parameter is enabled.  Note, named parameter for ML-DSA are defined
only for java >= 24, if used with previous version the parameter has
to be defined.

Additionally, fix jss.map version for MLDSA related method.

1. https://openjdk.org/jeps/497

- - - - -
f1bbb636 by Marco Fargetta at 2026-05-07T11:28:18+02:00
Add ML-KEM key pair generation

Key pair generation now support ML-KEM key type. The support follows
the JEP#496 [1]. The key generation instance has to be requested for
the algorithm "ML-KEM" or one of its variants ("ML-KEM-512",
"ML-KEM-768" or "ML-KEM-1024"). If the generic algorithm is used and
it is not followed by initialisation then the key will be
"ML-KEM-768".

Initialisation can be done with a NamedParameterSpec indicating the
variant ("ML-KEM-512", "ML-KEM-768" or "ML-KEM-1024") or with the
related strength (512, 768 or 1024).

1. https://openjdk.org/jeps/496

- - - - -
ab957594 by Marco Fargetta at 2026-05-07T11:28:18+02:00
Add ML-KEM KeyType support with JNI bindings

Add MLKEM KeyType to KeyType.java and corresponding JNI mappings in
PK11PrivKey/PK11PubKey for kyberKey handling. Includes test coverage
for ML-KEM-768 and ML-KEM-1024 key pair generation.

- - - - -
52534e7e by jmagne at 2026-05-11T17:53:16-07:00
Add PBMAC1 ASN.1 structures and configuration API.
Assisted-by: Claude Sonnet 4.5

- - - - -
48a3fe8e by jmagne at 2026-05-11T17:53:16-07:00
Implement PBMAC1 MAC computation for PKCS#12:
Assisted by: Claude Sonnet 4.5

- - - - -
c8c42bca by jmagne at 2026-05-11T17:53:16-07:00
Add PBMAC1 test suite and CI integration:
Assisted-by: Claude Sonnet 4.5

- - - - -
49f2ceb5 by Marco Fargetta at 2026-05-12T19:57:16+02:00
Add ML-KEM encapsulation and decapsulation support

Implements KEMSpi with JNI bindings to NSS PK11_Encapsulate and
PK11_Decapsulate. Adds support for ML-KEM-512, ML-KEM-768, and
ML-KEM-1024 variants with HKDF key derivation for AES algorithms.

Bumps Java version requirement to 21 for KEM API support.

Assisted-By: Claude Sonnet 4.5 <noreply at anthropic.com>

- - - - -
1ab79fe5 by Marco Fargetta at 2026-05-12T19:57:16+02:00
Add check for matching key with KEM algorithm

JEP #496 [1] requires that key algorithm have to match KEM algorithm
if a specific strngth is requested. The check is implemented in
JSSKEMSpi when a new encapsulator or decapsualtor is generated.

1. https://openjdk.org/jeps/496

- - - - -
45862bd3 by Marco Fargetta at 2026-05-12T19:57:16+02:00
Add ML-KEM encapsulation and decapsulation tests

Implements comprehensive test coverage for ML-KEM key encapsulation
mechanism, validating encapsulate/decapsulate operations across
multiple parameter sets (ML-KEM-768, ML-KEM-1024) and AES key sizes.

ML-KEM Key strength has to match with KEM algorithm. The test also
verify this control is enforced.

Assisted-By: Claude Sonnet 4.5 <noreply at anthropic.com>

- - - - -
2cec7180 by Marco Fargetta at 2026-05-12T19:57:16+02:00
Update PKCS11 constatnt to NSS 3.123

Fix: #1092

- - - - -
f7d68cbf by Endi S. Dewata at 2026-05-12T18:18:42-05:00
Define OIDs for ML-KEM

The AlgorithmId has been updated to define the OIDs for ML-KEM
algorithms. They are needed for certificate enrollments with
ML-KEM keys.

https://csrc.nist.gov/projects/computer-security-objects-register/algorithm-registration

- - - - -
fce63513 by Marco Fargetta at 2026-05-14T17:19:46+02:00
Update java build to java jdk 25

KEM algorithms are supported from Java 23 so the jdk has to be updated in order to build the code.

- - - - -
2502b23b by Christina Fu at 2026-05-14T08:57:44-07:00
Add ML-KEM and ML-DSA key archival and recovery support (#1098)

This commit adds support for ML-KEM (Module-Lattice-Based Key
Encapsulation Mechanism) and ML-DSA (Module-Lattice-Based Digital
Signature Algorithm) key archival and recovery in JSS.

- JSSProvider.java: Add KeyFactory.ML-KEM and KeyFactory.ML-DSA
  generic aliases for KeyFactory support

- PrivateKey.java:
  * Add top-level constants for both ML-KEM and ML-DSA
    (MLKEM512, MLKEM768, MLKEM, MLKEM1024, MLDSA44, MLDSA65, MLDSA, MLDSA87)
  * Add javadoc documenting generic aliases (MLKEM→MLKEM768, MLDSA→MLDSA65)

- PK11KeyWrapper.java:
  * Add unified ML-KEM and ML-DSA public key extraction using SubjectPublicKeyInfo
    (de-duplicated into single branch for easier maintenance)
  * Add BIT_STRING padding verification to ensure byte-alignment per FIPS 203/204
  * Update algFromType() to return MLKEMFamily and MLDSAFamily
  * Fix leading-zero stripping to only apply to RSA/DSA (preserves EC/PQC bytes)
  * Catch specific InvalidBERException instead of generic Exception

- PK11KeyWrapper.c:
  * Add workarounds for NSS PK11_GetKeyType() not mapping ML-KEM and ML-DSA mechanisms
  * Add CKK_ML_KEM case with CKA_DECAPSULATE attribute per PKCS#11 v3.2
    (KEMs use CKA_DECAPSULATE, similar to DH/ECDH using CKA_DERIVE)
  * Add CKK_ML_DSA case with CKA_SIGN attribute per PKCS#11 v3.2
    (ML-DSA is a signature algorithm)

ML-KEM support has been tested and verified to work with hsmCompatVerify tool.
ML-DSA support is added for forward-thinking purposes. It is untested but
follows the same pattern as ML-KEM.

IDM-5475 IDM-5817 IDM-6295
Assisted-by: Claude
- - - - -
990d7291 by Marco Fargetta at 2026-05-18T11:51:20+02:00
Add ML-DSA and ML-KEM algorithm parameter support

- Update PrivateKey interface documentation to include ML-DSA and ML-KEM
- Fix exception handling in PK11PrivKey.getType() to throw KeyException
  instead of PK11Exception for unsupported parameter sets
- Implement getParams() to return NamedParameterSpec for ML-DSA and ML-KEM keys
- Update getAlgorithm() to use getKeyType() to avoid exception in call path
- Handle KeyException in JSSKEMSpi key validation

These changes complete the ML-KEM integration by properly exposing
algorithm parameters and aligning exception types with the interface
contract.

Assisted-By: Claude Sonnet 4.5 <noreply at anthropic.com>

- - - - -
9bc42c31 by Marco Fargetta at 2026-05-18T11:51:20+02:00
Fix CMake build error

If the build is done with CMake, without PQC enabled there is an error
the file `PK11PrivKey.c` does not compile because the variable
`paramSet` result undefined. The definition is moved outside the macro
to be always available.

- - - - -
6b5b699e by Marco Fargetta at 2026-05-18T11:51:20+02:00
Revert Java minimum version to 21

- - - - -
143d98c9 by Christina Fu at 2026-05-18T09:08:31-07:00
Add JSS unit tests for ML-KEM key wrapping with AES-KWP (#1100)

* Fix PQC key wrapping support in JSS native code

- Update MAX_WRAPPED_KEY_LEN comment to document PQC key size requirements.
  Existing 4096 bytes is sufficient for ML-KEM-1024 (~3280 bytes wrapped).

- Fix PK11PrivKey.c compilation: Move paramSet variable declaration outside
  ifdef to prevent "undeclared identifier" error on line 276 return statement.

These fixes enable wrapping/unwrapping of post-quantum cryptographic keys
including ML-KEM-1024 and ML-DSA-44.

Note: ML-DSA-44 is currently the largest ML-DSA variant that NSS can wrap.
Larger variants (ML-DSA-65, ML-DSA-87) fail in NSS with SEC_ERROR_OUTPUT_LEN
even with larger buffers - this is an NSS limitation, not a buffer size issue.

IDM-5475 IDM-5817
Assisted-by: Claude

* Add JSS unit tests for ML-KEM key wrapping with AES-KWP

This commit adds comprehensive unit tests for post-quantum key wrapping
functionality using ML-KEM (FIPS 203) for key encapsulation and AES-KWP
(RFC 5649) for key wrapping.

Test coverage:
- ML-KEM-768 encapsulation to derive AES-256 wrapping key
- Wrapping/unwrapping RSA-2048, EC P-256, ML-KEM-1024, and ML-DSA-44
  private keys using AES-KWP (CKM_AES_KEY_WRAP_KWP)
- Cryptographic verification of unwrapped keys via sign/verify operations
- Decapsulation verification proving recovered key matches wrapping key

Implementation:
- Test suite with 4 test cases in MLKEMKeyWrapping.java
- Registered for both regular and FIPS mode testing
- Uses java.security configuration for database location
- StandardCharsets.UTF_8 for consistent string encoding
- sensitivePairs(true) for FIPS mode compatibility
- Updated Disable_FipsMODE dependencies to include PQC FIPS tests

Requirements:
- NSS 3.123+ with PQC support
- Build with -DENABLE_NSS_VERSION_PQC_DEF=ON to enable tests
- Tests are optional and won't break builds on older NSS versions

Note: ML-DSA-44 is currently the largest ML-DSA variant that NSS can
successfully wrap. Larger variants (ML-DSA-65, ML-DSA-87) fail with
SEC_ERROR_OUTPUT_LEN.

IDM-6295
Assisted-by: Claude
- - - - -
51b2e0c6 by Endi S. Dewata at 2026-05-18T23:22:05+00:00
Fix build warnings in sslget.c

- Replace pointer-to-int cast warnings with proper %p format specifiers
- Remove unused SECStatus result variable
- Remove unused getIPAddress function

Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>

- - - - -
c83dd712 by Endi S. Dewata at 2026-05-18T23:58:19+00:00
Fix build warnings in SessionKey.cpp

- Fix infinite recursion in JSS_PK11_wrapSymKey by adding forward declaration
  and calling the 3-parameter overload instead of calling itself
- Fix strncpy truncation warnings by using KEYNAMELENGTH-1 and explicit
  null termination to ensure proper string handling

Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>

- - - - -
c260855b by Endi S. Dewata at 2026-05-19T00:21:02+00:00
Fix build warnings in SymKey.cpp

- Remove unused count variables in DeleteKey and ListSymmetricKeys functions
- Remove unnecessary NULL check for local array fullNewMasterKeyName
- Fix strncpy truncation warning by using KEYNAMELENGTH-1 and explicit
  null termination to ensure proper string handling

Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>

- - - - -
c5d810a1 by Endi S. Dewata at 2026-05-19T00:23:26+00:00
Fix build warning in p7tool secpwd.c

- Add proper error handling for fgets return value in SEC_GetPassword
- Check for NULL return from QUIET_FGETS and return early on EOF/error
- Add length check before removing newline to prevent buffer underrun
- This resolves the [-Wunused-result] warning for fgets

Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>

- - - - -
c0d1dae6 by Endi S. Dewata at 2026-05-19T01:15:01+00:00
Fix build warnings in p7tool secutil.c

- Add proper error handling for PK11_InitPin return value in SECU_ChangePW
- Replace deprecated CERTDB_VALID_PEER with CERTDB_TERMINAL_RECORD
- Fix pointer-to-int cast warnings by using uintptr_t intermediate cast
- Add stdint.h include for uintptr_t type
- This resolves unused variable, deprecation, and cast warnings

Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>

- - - - -
f3dab745 by Endi S. Dewata at 2026-05-19T01:15:01+00:00
Fix build warnings in p7tool.c

- Add error checking for fwrite() return value to resolve unused variable warning
  in DecodeAndPrintFile function - now properly reports write failures
- Change prefix parameter and variable to const char* to resolve const qualifier
  warning when assigning from optstate->value
- This improves error handling and type safety

Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>

- - - - -
0bac6a12 by Endi S. Dewata at 2026-05-19T01:15:01+00:00
Fix Javadoc errors in multiple Java files

- CryptoManager.java: Fix missing parameter name in @param tag
- DirStrConverter.java: Remove invalid @param, @return, @throws tags from field documentation
- JSSContext.java: Fix missing class references and correct method signatures
- JSSNioEndpoint.java: Fix malformed {@link} tag with text outside braces
- JSSSecureNioChannel.java: Fix malformed {@link} tag with text outside braces
- MacData.java: Correct @param tags to match actual method parameters
- PKCS9Attribute.java: Fix incorrect parameter name in @param tag
- PKCS9Attributes.java: Fix incorrect parameter name in @param tag

These fixes resolve Javadoc generation warnings and improve documentation accuracy.

Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>

- - - - -
b0b79c93 by Endi S. Dewata at 2026-05-19T18:29:13+00:00
Add Maven build option to jss.spec

Add %bcond_without maven option to allow optional CMake-only builds. By
default, Maven builds Java code and CMake builds native code. When
--without maven is specified, CMake builds everything including Java code.

Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>

- - - - -
36995fb5 by Marco Fargetta at 2026-05-21T09:55:18+02:00
Fix default ML-DSA signing

According to JEP 497 [1], the ML-DSA signature algorithm should behave
as follows:
- When instantiated as "ML-DSA" (generic), it accepts any ML-DSA-44,
  ML-DSA-65, or ML-DSA-87 key and uses the key's variant
- When instantiated with a specific variant (e.g., "ML-DSA-65"), it
  only accepts keys of that variant, throwing InvalidKeyException
  otherwise

Previously, the generic "ML-DSA" was hardcoded to "ML-DSA-65", which
worked in practice because NSS uses the key's variant regardless of
the signature algorithm parameter. However, this violated the JEP
497 specification.

This commit implements the correct behavior:
- Generic ML-DSA signature extracts the variant from the key
  (NamedParameterSpec for private keys, OID from X.509 encoding for
  public keys)
- Specific ML-DSA variants validate that the key matches

1. https://openjdk.org/jeps/497

- - - - -
5e7980a7 by Marco Fargetta at 2026-05-25T10:23:25+02:00
Force SHA-512 digest algorithm for ML-DSA in CMS SignerInfo

Per RFC 9882 Section 4 [1], ML-DSA signatures in CMS must use SHA-512
as the digest algorithm identifier in the SignerInfo structure. This
applies both when signed attributes are absent (pure signatures) and
when they are present.

ML-DSA (FIPS 204) is a pure signature algorithm that does not have an
associated digest algorithm like traditional composite signature
algorithms (e.g., RSASignatureWithSHA256). However, RFC 9882 mandates
that the digestAlgorithm field in SignerInfo MUST be set to id-sha512
to ensure proper CMS structure and interoperability.

This change explicitly sets the digest algorithm to SHA-512 when
ML-DSA signature algorithms is ML-DSA-44, ML-DSA-65 or ML-DSA-87).

1. RFC 9882 - Using ML-DSA in the Cryptographic Message Syntax (CMS)
   (https://www.rfc-editor.org/rfc/rfc9882)

Assisted-By: Claude Sonnet 4.5 <noreply at anthropic.com>

- - - - -
77142a0e by Endi S. Dewata at 2026-05-29T14:40:45-05:00
Clean up exception messages in PK11KeyPairGenerator

- - - - -
c0712b03 by Endi S. Dewata at 2026-06-01T19:48:02-05:00
Add build options for ML-DSA and ML-KEM

The build scripts have been updated to provide options to build
without ML-DSA or ML-KEM since some platforms might only have a
partial or no support of PQC. Note that if ML-DSA is disabled
ML-KEM will be disabled as well, but ML-KEM can be disabled
without affecting ML-DSA.

The following params have been replaced with more specific
params:
- ENABLE_NSS_VERSION_PQC_DEF
- NSS_VERSION_PQC_DEF
- test.NSS_PQC

- - - - -
a653cf48 by Endi S. Dewata at 2026-06-02T10:42:06-05:00
Temporarily enable ML-KEM on RHEL using NSS COPR build

- - - - -
1bd6762c by Endi S. Dewata at 2026-06-03T10:26:31-05:00
Update version number to 5.10.0-beta2

- - - - -
a74e29ac by Endi S. Dewata at 2026-06-04T15:21:18-05:00
Update build scripts to use Java 21

- - - - -
2c7c207a by Endi S. Dewata at 2026-06-04T15:21:18-05:00
Clean up test messages

- - - - -
c60862c9 by Endi S. Dewata at 2026-06-04T15:21:18-05:00
Clean up build messages

- - - - -
10c7772b by Endi S. Dewata at 2026-06-05T15:11:06-05:00
Cleean up Maven scripts

- - - - -
d6a6c687 by Endi S. Dewata at 2026-06-08T10:15:30-05:00
Update publish job to use Java 21

- - - - -
0a988763 by Marco Fargetta at 2026-06-11T10:01:37+02:00
Increase TLS buffer size for ML-DSA certificates

ML-DSA certificates require ~50KB for handshake (vs 18KB default). Add
automatic detection of PQC keys and increase buffer to 64KB when
needed. Respects jdk.tls.maxHandshakeMessageSize system property.

Assisted-By: Claude Sonnet 4.5 <noreply at anthropic.com>

- - - - -
95c1c839 by Marco Fargetta at 2026-06-12T13:18:19+02:00
Fix use-after-free crash in JSSEngineReferenceImpl finalizer

Set `closed_fd` before calling `closeInbound()/closeOutbound()` in
cleanup() to prevent them from calling `PR.Shutdown()` on `ssl_fd`
that is being freed. This fixes a SIGSEGV crash where `PR.Shutdown()`
attempted to write TLS close_notify alerts to NSS buffers during
cleanup.

The crash occurred because `cleanup()` called `closeOutbound()` which
checked `!closed_fd` and invoked `PR.Shutdown()`, but `cleanupSSLFD()` set
`closed_fd` too late. Moving `closed_fd = true` to the start of `cleanup()`
prevents the native `PR.Shutdown()` call while still freeing all
resources properly.

Assisted-by: Claude Sonnet 4.5 <noreply at anthropic.com>

- - - - -
ce561a0b by Marco Fargetta at 2026-06-12T13:18:19+02:00
Show pki core dumps in case of segmentation fault

PKI CLI could crash during TLS operations if not properly managed.
The stack dump of the crash is stored in a file from the JVM and it is
shown.

- - - - -
85998301 by Endi S. Dewata at 2026-06-16T11:16:15-05:00
Update tests to use actions/cache at v5

- - - - -
eb86b549 by jmagne at 2026-06-16T12:55:56-07:00
First cut of using Cleaner object to eliminate the SSLEngine finalizer problem.

Some cleanup suggested by review bots.

Assisted-by: claude Sonnet 4.5.

- - - - -
80d1aa54 by Endi S. Dewata at 2026-06-16T15:45:09-05:00
Fix warnings due to deprecated --pkcs12-password option

- - - - -
3de433a3 by Endi S. Dewata at 2026-06-16T15:45:09-05:00
Update version number to 5.10.0

The obsolete TestPKCS11Constants has been removed.

- - - - -
a06e29f5 by freddy at 2026-06-18T12:06:57+02:00
Allow for encrypting with CKM_AES_KEY_WRAP_KWP

- - - - -
5678fbc2 by Freddy113-x at 2026-06-18T12:06:57+02:00
Update base/src/main/java/org/mozilla/jss/crypto/EncryptionAlgorithm.java

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
- - - - -
0aade72d by Endi S. Dewata at 2026-06-18T12:47:19-05:00
Update tests to use actions/checkout at v7

- - - - -
e0b60ceb by Endi S. Dewata at 2026-06-18T12:47:19-05:00
Update tests to use docker/setup-buildx-action at v4

- - - - -
2198c4e0 by Endi S. Dewata at 2026-06-18T12:47:19-05:00
Update tests to use docker/setup-buildx-action at v7

- - - - -
df1f507d by Endi S. Dewata at 2026-06-22T13:24:00-05:00
Update tests to use lewagon/wait-on-check-action at v1.8.0

- - - - -
938858d5 by Endi S. Dewata at 2026-06-23T09:02:55-05:00
Update tests to use actions/setup-java at v5

- - - - -
4d1a4b7c by Endi S. Dewata at 2026-06-23T10:43:51-05:00
Update tests to use docker/login-action at v4

- - - - -
50772d66 by Endi S. Dewata at 2026-06-23T15:49:22-05:00
Update tests to use actions/upload-artifact at v7

- - - - -
d9345d51 by Marco Fargetta at 2026-07-24T18:32:44+02:00
Validate PK11Context before use in PK11Cipher native calls

JSS_PK11_getCipherContext extracted the PK11Context pointer from a
CipherContextProxy without checking it for NULL, unlike the analogous
JSS_PK11_getSigContext used by PK11Signature. If the underlying
context was ever invalid (e.g. already released), the NULL pointer
was passed straight into PK11_CipherOp/PK11_DigestFinal, crashing the
whole JVM with a SIGSEGV instead of failing the single operation.

Now a NULL context throws a catchable TokenException at the JSS/NSS
boundary, matching PK11Signature's existing behavior.

Assisted-by: Claude Sonnet 5 <noreply at anthropic.com>

- - - - -
b5e5dd75 by Marco Fargetta at 2026-07-27T16:29:40+02:00
Remove finalize() from PK11Cipher to prevent premature GC race

PK11Cipher's native methods (updateContext, finalizeContext) are
declared static, so the JVM does not pin the PK11Cipher instance
during JNI execution. Under GC pressure the JIT can determine the
PK11Cipher is unreachable while a static native call is in progress,
triggering finalize() on the finalizer thread. This calls close()
which calls contextProxy.close(), destroying the native PK11Context
and nulling mPointer while the worker thread still holds a JNI
reference to the same CipherContextProxy. The subsequent
JSS_getPtrFromProxy reads NULL, and PK11_DigestFinal(NULL) crashes
with SIGSEGV.

Removing finalize() breaks this chain. Native resource cleanup is
still guaranteed by CipherContextProxy's own NativeProxy.finalize(),
which only runs when the proxy itself is unreachable (no JNI local
refs), so no race is possible. Explicit cleanup via AutoCloseable
close() is preserved.

Assisted-by: Claude Opus 4.6 <noreply at anthropic.com>

- - - - -
5d141d57 by Marco Fargetta at 2026-07-28T18:04:07+02:00
Updating version to v5.10.1

- - - - -


143 changed files:

- .github/workflows/build-tests.yml
- .github/workflows/build.yml
- .github/workflows/code-analysis-pull.yml
- .github/workflows/code-analysis.yml
- .github/workflows/external-application-connection-tests.yml
- .github/workflows/known_failures.yml
- .github/workflows/pkcs11-tests.yml
- .github/workflows/pki-build-test.yml
- .github/workflows/pki-ca-test.yml
- .github/workflows/pki-tests.yml
- .github/workflows/pki-tools-test.yml
- .github/workflows/pki-tps-test.yml
- .github/workflows/publish.yml
- .github/workflows/tomcat-basic-test.yml
- .github/workflows/tomcat-https-ciphers-test.yml
- .github/workflows/tomcat-https-default-test.yml
- .github/workflows/tomcat-https-multi-certificate-test.yml
- .github/workflows/tomcat-https-tls13-test.yml
- .github/workflows/tomcat-tests.yml
- CMakeLists.txt
- README.md
- azure-pipelines.yml
- base/pom.xml
- base/src/main/java/org/mozilla/jss/CryptoManager.java
- base/src/main/java/org/mozilla/jss/JSSProvider.java
- base/src/main/java/org/mozilla/jss/asn1/OBJECT_IDENTIFIER.java
- base/src/main/java/org/mozilla/jss/crypto/Algorithm.java
- base/src/main/java/org/mozilla/jss/crypto/EncryptionAlgorithm.java
- + base/src/main/java/org/mozilla/jss/crypto/KEMAlgorithm.java
- base/src/main/java/org/mozilla/jss/crypto/KeyPairAlgorithm.java
- base/src/main/java/org/mozilla/jss/crypto/PrivateKey.java
- base/src/main/java/org/mozilla/jss/crypto/SignatureAlgorithm.java
- base/src/main/java/org/mozilla/jss/netscape/security/pkcs/PKCS12Util.java
- base/src/main/java/org/mozilla/jss/netscape/security/pkcs/PKCS7.java
- base/src/main/java/org/mozilla/jss/netscape/security/pkcs/PKCS9Attribute.java
- base/src/main/java/org/mozilla/jss/netscape/security/pkcs/PKCS9Attributes.java
- base/src/main/java/org/mozilla/jss/netscape/security/util/Cert.java
- base/src/main/java/org/mozilla/jss/netscape/security/x509/AlgorithmId.java
- base/src/main/java/org/mozilla/jss/netscape/security/x509/DirStrConverter.java
- base/src/main/java/org/mozilla/jss/pkcs11/KeyType.java
- base/src/main/java/org/mozilla/jss/pkcs11/PK11Cipher.java
- + base/src/main/java/org/mozilla/jss/pkcs11/PK11DSAParams.java
- base/src/main/java/org/mozilla/jss/pkcs11/PK11DSAPrivateKey.java
- base/src/main/java/org/mozilla/jss/pkcs11/PK11KeyPairGenerator.java
- base/src/main/java/org/mozilla/jss/pkcs11/PK11KeyWrapper.java
- base/src/main/java/org/mozilla/jss/pkcs11/PK11PrivKey.java
- base/src/main/java/org/mozilla/jss/pkcs11/PKCS11Constants.java
- base/src/main/java/org/mozilla/jss/pkcs12/MacData.java
- + base/src/main/java/org/mozilla/jss/pkcs12/MacType.java
- base/src/main/java/org/mozilla/jss/pkcs12/PFX.java
- base/src/main/java/org/mozilla/jss/pkix/cms/SignerInfo.java
- + base/src/main/java/org/mozilla/jss/pkix/primitive/PBMAC1Params.java
- base/src/main/java/org/mozilla/jss/provider/java/security/JSSKeyPairGeneratorSpi.java
- base/src/main/java/org/mozilla/jss/provider/java/security/JSSSignatureSpi.java
- + base/src/main/java/org/mozilla/jss/provider/javax/crypto/JSSKEMDecapsulatorSpi.java
- + base/src/main/java/org/mozilla/jss/provider/javax/crypto/JSSKEMEncapsulatorSpi.java
- + base/src/main/java/org/mozilla/jss/provider/javax/crypto/JSSKEMSpi.java
- base/src/main/java/org/mozilla/jss/ssl/javax/JSSEngine.java
- base/src/main/java/org/mozilla/jss/ssl/javax/JSSEngineReferenceImpl.java
- base/src/main/java/org/mozilla/jss/ssl/javax/JSSSession.java
- base/src/main/java/org/mozilla/jss/util/Password.java
- base/src/test/java/org/mozilla/jss/tests/BMPStringTest.java
- base/src/test/java/org/mozilla/jss/tests/ChainSortingTest.java
- base/src/test/java/org/mozilla/jss/tests/GenerateTestCert.java
- base/src/test/java/org/mozilla/jss/tests/GenericValueConverterTest.java
- base/src/test/java/org/mozilla/jss/tests/IA5StringConverterTest.java
- base/src/test/java/org/mozilla/jss/tests/IA5StringTest.java
- base/src/test/java/org/mozilla/jss/tests/JCASigTest.java
- + base/src/test/java/org/mozilla/jss/tests/KeyEncapsulating.java
- + base/src/test/java/org/mozilla/jss/tests/MLKEMKeyWrapping.java
- + base/src/test/java/org/mozilla/jss/tests/PBMAC1Test.java
- base/src/test/java/org/mozilla/jss/tests/PrintableConverterTest.java
- base/src/test/java/org/mozilla/jss/tests/PrintableStringTest.java
- base/src/test/java/org/mozilla/jss/tests/TeletexStringTest.java
- base/src/test/java/org/mozilla/jss/tests/TestKeyGen.java
- − base/src/test/java/org/mozilla/jss/tests/TestPKCS11Constants.java
- base/src/test/java/org/mozilla/jss/tests/TestSSLEngine.java
- base/src/test/java/org/mozilla/jss/tests/UTF8StringTest.java
- base/src/test/java/org/mozilla/jss/tests/UniversalStringTest.java
- build.sh
- cmake/JSSCommon.cmake
- cmake/JSSConfig.cmake
- cmake/JSSTests.cmake
- cmake/Java.cmake
- docs/changes/v5.9.0/Algorithm-Changes.adoc
- docs/legacy_building.md
- docs/pkcs11_constants.md
- examples/pom.xml
- jss.spec
- lib/jss.map
- native/pom.xml
- native/src/main/native/org/mozilla/jss/PK11Finder.c
- native/src/main/native/org/mozilla/jss/crypto/Algorithm.c
- native/src/main/native/org/mozilla/jss/crypto/Algorithm.h
- native/src/main/native/org/mozilla/jss/crypto/JSSOAEPParameterSpec.c
- native/src/main/native/org/mozilla/jss/crypto/KBKDF.c
- native/src/main/native/org/mozilla/jss/pkcs11/PK11Cipher.c
- native/src/main/native/org/mozilla/jss/pkcs11/PK11KeyGenerator.c
- native/src/main/native/org/mozilla/jss/pkcs11/PK11KeyPairGenerator.c
- native/src/main/native/org/mozilla/jss/pkcs11/PK11KeyWrapper.c
- native/src/main/native/org/mozilla/jss/pkcs11/PK11PrivKey.c
- native/src/main/native/org/mozilla/jss/pkcs11/PK11PubKey.c
- native/src/main/native/org/mozilla/jss/pkcs11/PK11Store.c
- + native/src/main/native/org/mozilla/jss/provider/javax/crypto/JSSKEMDecapsulatorSpi.c
- + native/src/main/native/org/mozilla/jss/provider/javax/crypto/JSSKEMEncapsulatorSpi.c
- native/src/main/native/org/mozilla/jss/ssl/SSLCipher.c
- native/src/main/native/org/mozilla/jss/util/java_ids.h
- native/src/main/native/org/mozilla/jss/util/jssutil.c
- native/src/main/native/org/mozilla/jss/util/jssver.h.in
- pom.xml
- revert_update_version.sh
- symkey/pom.xml
- symkey/src/main/native/org/mozilla/jss/symkey/SessionKey.cpp
- symkey/src/main/native/org/mozilla/jss/symkey/SymKey.cpp
- tests/bin/ds-artifacts-save.sh
- tests/bin/ds-create.sh
- tests/bin/ds-remove.sh
- tests/bin/ds-start.sh
- tests/bin/ds-stop.sh
- tests/bin/pki-artifacts-save.sh
- tests/bin/rpminspect.sh
- tests/bin/runner-init.sh
- + tests/bin/test-init.sh
- tests/bin/tomcat-start-wait.sh
- tomcat-10.1/pom.xml
- tomcat-10.1/src/main/java/org/dogtagpki/jss/tomcat/JSSContext.java
- tomcat-10.1/src/main/java/org/dogtagpki/jss/tomcat/JSSNioEndpoint.java
- tomcat-10.1/src/main/java/org/dogtagpki/jss/tomcat/JSSSecureNioChannel.java
- tomcat-9.0/pom.xml
- tomcat/pom.xml
- tools/Dockerfiles/fedora_rawhide
- tools/common_roots.sh
- tools/reproducible_jar.sh
- tools/run_container.sh
- tools/run_test.sh.in
- tools/src/main/native/p12tool/p12tool.c
- tools/src/main/native/p12tool/p12tool.h
- tools/src/main/native/p12tool/secutil.h
- tools/src/main/native/p7tool/p7tool.c
- tools/src/main/native/p7tool/secpwd.c
- tools/src/main/native/p7tool/secutil.c
- tools/src/main/native/sslget/sslget.c
- update_version.sh


The diff was not included because it is too large.


View it on GitLab: https://salsa.debian.org/freeipa-team/jss/-/compare/814f94a5e3127f3a8211204be283e66c347e9fb6...5d141d57f04095b1100e4eececca46fa980117fc

-- 
View it on GitLab: https://salsa.debian.org/freeipa-team/jss/-/compare/814f94a5e3127f3a8211204be283e66c347e9fb6...5d141d57f04095b1100e4eececca46fa980117fc
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/pkg-freeipa-devel/attachments/20260927/4e1c6092/attachment-0001.htm>


More information about the Pkg-freeipa-devel mailing list