On Tue, 6 Jan 2026 04:20:18 GMT, Koushik Muthukrishnan Thirupattur 
<[email protected]> wrote:

> The method ckAssertReturnValueOK will invoke ckAssertReturnValueOK2 which 
> makes multiple calls to JNI functions, such as FindClass or GetMethodID. 
> These calls would be unsafe as there may be a pending exception at this time.
> So adding exception check to return immediately and do not call any further 
> JNI functions when there is exception pending.

src/jdk.crypto.cryptoki/share/native/libj2pkcs11/p11_keymgmt.c line 963:

> 961:         goto cleanup;
> 962:     }
> 963:     if (ckAssertReturnValueOK(env, rv) != CK_ASSERT_OK) {

I think we should move this assertion right after the C_DeriveKey call above 
instead. No point in copying the keys if derivation fails.

Also, please update the copyright year.

-------------

PR Review Comment: https://git.openjdk.org/jdk/pull/29054#discussion_r2667542638

Reply via email to