RFR: 8367024: JNI exception pending in Java_sun_security_pkcs11_wrapper_PKCS11_C_1DeriveKey of p11_keymgmt.c:950 [v3]

Valerie Peng valeriep at openjdk.org
Wed Jan 14 18:22:08 UTC 2026


On Wed, 14 Jan 2026 03:48:01 GMT, Koushik Muthukrishnan Thirupattur <duke at openjdk.org> wrote:

>> The method ckAssertReturnValueOK will invoke ckAssertReturnValueOK2 which makes multiple calls to JNI functions, such as FindClass or GetMethodID. These calls would be unsafe as there may be a pending exception at this time.
>> So adding exception check to return immediately and do not call any further JNI functions when there is exception pending.
>
> Koushik Muthukrishnan Thirupattur has updated the pull request incrementally with one additional commit since the last revision:
> 
>   8367024: Addressing review comments

Changes look good, have you run the security regression tests?

-------------

Marked as reviewed by valeriep (Reviewer).

PR Review: https://git.openjdk.org/jdk/pull/29054#pullrequestreview-3662148293


More information about the security-dev mailing list