Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[package]
name = "authenticator"
version = "0.6.0"
version = "0.6.1"
authors = [ "Dana Keeler <dkeeler@mozilla.com>", "J.C. Jones <jc@mozilla.com>", "John Schanck <jschanck@mozilla.com>", "Kyle Machulis <kyle@nonpolynomial.com>", "Martin Sirringhaus <martin.sirringhaus@suse.com", "Tim Taubert <ttaubert@mozilla.com>" ]
keywords = ["ctap2", "u2f", "fido", "webauthn"]
categories = ["cryptography", "hardware-support", "os"]
Expand Down
6 changes: 3 additions & 3 deletions src/crypto/nss.rs
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ use nss_rs::p11::{
};

// nss-rs exposes these as raw bindgen u32 constants; shadow as usize for ergonomic use.
const AES_BLOCK_SIZE: usize = nss_rs::p11::AES_BLOCK_SIZE as usize;
const AES_BLOCK_SIZE: usize = 16;

@micolous micolous Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit: I wonder if this is a similar issue to https://bugzilla.mozilla.org/show_bug.cgi?id=2071649, triggered by https://phabricator.services.mozilla.com/D319399, and needs a fix in nss-rs instead?

(Though this would also need an nss-rs release with that fix, so we can accept this for 0.16.1.)

const SHA256_LENGTH: usize = nss_rs::p11::SHA256_LENGTH as usize;
use nss_rs::nss_prelude::PRBool;
use nss_rs::{IntoResult, SECItem, SECItemBorrowed, ScopedSECItem};
Expand Down Expand Up @@ -109,7 +109,7 @@ pub fn gen_p256() -> Result<(Vec<u8>, Vec<u8>)> {
pkcs8_priv_item.into_vec()
};

let sec1_pub = client_public.key_data()?;
let sec1_pub = client_public.key_data()?.to_vec();

Ok((pkcs8_priv, sec1_pub))
}
Expand Down Expand Up @@ -165,7 +165,7 @@ pub fn ecdhe_p256_raw(peer: &super::COSEEC2Key) -> Result<(Vec<u8>, Vec<u8>)> {

let shared_point = ecdh_nss_raw(client_private, peer_public)?;

Ok((shared_point, client_public.key_data()?))
Ok((shared_point, client_public.key_data()?.to_vec()))
}

/// AES-256-CBC encryption for data that is a multiple of the AES block size (16 bytes) in length.
Expand Down
Loading