On Tue, 6 Jan 2026 04:20:18 GMT, Koushik Muthukrishnan Thirupattur
<[email protected]> wrote:
> The method ckAssertReturnValueOK will invoke ckAssertReturnValueOK2 which
> makes multiple calls to JNI functions, such as FindClass or GetMethodID.
> These calls would be unsafe as there may be a pending exception at this time.
> So adding exception check to return immediately and do not call any further
> JNI functions when there is exception pending.
src/jdk.crypto.cryptoki/share/native/libj2pkcs11/p11_keymgmt.c line 963:
> 961: goto cleanup;
> 962: }
> 963: if (ckAssertReturnValueOK(env, rv) != CK_ASSERT_OK) {
I think we should move this assertion right after the C_DeriveKey call above
instead. No point in copying the keys if derivation fails.
Also, please update the copyright year.
-------------
PR Review Comment: https://git.openjdk.org/jdk/pull/29054#discussion_r2667542638