Skip to content

Strip sql:/dbm: prefix from NSS configdir - #219

Open
MarkAtwood wants to merge 1 commit into
wolfSSL:masterfrom
MarkAtwood:nss-configdir-prefix
Open

MarkAtwood wants to merge 1 commit into
wolfSSL:masterfrom
MarkAtwood:nss-configdir-prefix

Conversation

@MarkAtwood

Copy link
Copy Markdown
Contributor

NSS passes the token its db location with a type prefix: sql:/path, dbm:/path or extern:/path (e.g. certutil -d sql:/path, Chromium's sql:$HOME/.pki/nssdb). wolfPKCS11 uses that string as the directory, so the store ends up looking for a directory named sql:/path, which doesn't exist. Nothing gets written; C_InitToken and C_InitPIN fail and certutil -N fails.

This strips the prefix before using the path. Upstream's NSS CI uses certutil -d /path without a prefix, so CI never hit it.

Test: nss_configdir_prefix_test. Fails on master, passes with the fix.

NSS passes the database directory to C_Initialize with its database
type prefix when the application uses one ("certutil -d sql:/path",
Chromium's sql:$HOME/.pki/nssdb). The prefix became part of the token
store path, so no token could be stored and C_InitPIN failed with
CKR_FUNCTION_FAILED. Strip the sql:, dbm: and extern: prefixes.

Add tests/nss_configdir_prefix_test.c.
Copilot AI balanced review requested due to automatic review settings October 2, 2026 20:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused fix is correct and covered, with only a minor test skip-reporting convention remaining.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Strips NSS database-type prefixes before configuring wolfPKCS11’s token-store directory.

Changes:

  • Handles sql:, dbm:, and extern: prefixes.
  • Adds regression coverage for prefixed and unprefixed paths.
  • Registers the test with Automake.
File Description
src/​wolfpkcs11.c Strips NSS database prefixes.
tests/​nss_configdir_prefix_test.c Tests token storage paths.
tests/​include.am Builds and runs the regression test.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

(void)argc;
(void)argv;
printf("NSS build with a token store not configured, skipping test\n");
return 0;
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants