Closed Bug 311577 Opened 20 years ago Closed 4 months ago

PK11_InitPin sets slot->lastLoginCheck without holding a lock

Categories

(NSS :: Libraries, defect, P3)

3.11

Tracking

(nss 3.125)

RESOLVED FIXED
Tracking Status
nss --- 3.125

People

(Reporter: wtc, Assigned: leggert)

References

Details

Attachments

(2 files, 1 obsolete file)

When I read the code in lib/pk11wrap/pk11auth.c, I got the impression that slot->lastLoginCheck is always set while we are holding the slot lock or a RW session, with only one exception: In PK11_InitPin, we have: /* get a rwsession */ rwsession = PK11_GetRWSession(slot); if (rwsession == CK_INVALID_SESSION) { PORT_SetError(SEC_ERROR_BAD_DATA); slot->lastLoginCheck = 0; return rv; } Should the "slot->lastLoginCheck = 0;" statement be removed or be done inside a PK11_EnterSlotMonitor(slot) PK11_ExitSlotMonitor(slot) block? Compare PK11_InitPin with PK11_CheckSSOPassword, which has a similar structure. The corresponding code in PK11_CheckSSOPassword is: /* get a rwsession */ rwsession = PK11_GetRWSession(slot); if (rwsession == CK_INVALID_SESSION) { PORT_SetError(SEC_ERROR_BAD_DATA); return rv; }
QA Contact: jason.m.reid → libraries
Flags: in-testsuite?
Flags: in-moztrap?
Flags: in-testsuite?
Flags: in-moztrap?
Severity: trivial → S4

The bug assignee is inactive on Bugzilla, so the assignee is being reset.

Assignee: wtc → nobody
Priority: -- → P3

PK11_IsLoggedIn reads slot->lastLoginCheck under PK11_EnterSlotMonitor, but
PK11_InitPin writes it in three places without holding the monitor, causing a
data race. Wrap all three writes with PK11_EnterSlotMonitor/PK11_ExitSlotMonitor.

Blocks: 2044134

Pushed by jschanck@mozilla.com:
https://hg.mozilla.org/projects/nss/rev/a8286355abeb
PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor r=jschanck,nss-reviewers

Status: NEW → RESOLVED
Closed: 4 months ago
Resolution: --- → FIXED
Assignee: nobody → leggert
status-nss: --- → 3.125
Duplicate of this bug: 2041888
Pushed by jschanck@mozilla.com: https://hg.mozilla.org/projects/nss/rev/80c777852ce1 drop slot monitor in PK11_ResetToken before calling PK11_InitToken. r=nss-reviewers,keeler

A patch has been attached on this bug, which was already closed. Filing a separate bug will ensure better tracking. If this was not by mistake and further action is needed, please alert the appropriate party. (Or: if the patch doesn't change behavior -- e.g. landing a test case, or fixing a typo -- then feel free to disregard this message)

Attachment #9593215 - Attachment is obsolete: true
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: