Conversation
Extract module, binary and token directory discovery from import-key-test-common.sh into a helper that other shell tests can source. Add a fail() helper for consistent error reporting, ignore the tokens-* directories the tests create, and force LF line endings on shell scripts so they run under bash on Windows.
Sign through the OpenSSL pkcs11-provider and require the openssl process to exit cleanly. Before softhsm#897 the provider's atexit cleanup called C_CloseSession on an already destroyed SoftHSM instance and crashed with SIGSEGV (issues softhsm#729 and softhsm#780). The test skips when OpenSSL has no provider support or the provider module cannot be found in MODULESDIR; PKCS11_PROVIDER_MODULE overrides the lookup. Install pkcs11-provider in the OpenSSL 3.0 CI job so the test runs there. Based on the test from softhsm#864. Co-authored-by: Roumen Petrov <softhsm@roumenpetrov.info>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (8)
Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review. 📝 WalkthroughWalkthroughThe change adds shared setup and failure helpers for SoftHSM shell tests, adds a test for signing through the OpenSSL PKCS#11 provider, and registers that test in the build and CI configuration. ChangesPKCS#11 provider test coverage
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Other Sequence Diagram(s)sequenceDiagram
participant Test as p11prov-test.sh
participant OpenSSL
participant SoftHSM as SoftHSM token
Test->>SoftHSM: Initialize token and import RSA key
Test->>OpenSSL: Sign data using PKCS#11 provider
OpenSSL->>SoftHSM: Request RSA signature
SoftHSM-->>OpenSSL: Return signature
Test->>OpenSSL: Verify signature using software key
Suggested reviewers: Merge Risk: ⚪ Minimal · up to The new test detects the targeted process crash, and the shared setup preserves the existing configuration-path behavior. No actionable merge-blocking issue remains. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 42.86% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 7 functions across 3 files. (5 skipped: 5 unsupported.)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Follow-up to #897, which fixed the crash from #729 and #780 where OpenSSL's atexit cleanup (via pkcs11-provider) called
C_CloseSessionon an already destroyed SoftHSM instance. That PR did not come with a test, so this adds one so we don't regress.The test is based on the script from #864 by @petrovr (added as co-author), reworked to fit the test infrastructure that has landed in
src/bin/util/testsince then:softhsm2-util/openssldiscovery and token directory setup are moved out ofimport-key-test-common.shinto a newtest-common.sh, so the import tests and this one share the same code (including the Windows handling). The import tests behave exactly as before.fail()reporting that dumps the token log.pkcs11.sois not inMODULESDIR.PKCS11_PROVIDER_MODULEcan override the lookup.SKIP_RETURN_CODE 77). The OpenSSL 3.0 CI job installs thepkcs11-providerpackage so the test actually runs there; the other jobs don't have a provider and skip..gitattributesforcing LF endings on*.sh(needed for bash on Windows) and ignores thetokens-*directories the tests create.Checked locally with OpenSSL 3.5 and pkcs11-provider 3.5.7 against
-O2builds: the test fails with exit status 139 on main before #897 and passes on current main. ML-DSA / ML-KEM import tests still pass after the refactor.Summary by CodeRabbit