Repository navigation
parallel.test-crypto-rsa-dsa fails with Missing expected exception #52537
Description
Activity
- addedflaky-testIssues and PRs involving tests that fail intermittently in CI.Issues and PRs involving tests that fail intermittently in CI.
on Apr 15, 2024 - addedlinuxIssues and PRs related to the Linux platform.Issues and PRs related to the Linux platform.
on Apr 15, 2024 The stack is pointing at the test added in 54cd268 for https://hackerone.com/reports/2269177.
IIRC ubi81_sharedlibs_openssl111fips_x64 builds against the system OpenSSL (i.e. the one in UBI 8). The container was recently redeployed -- I'm wondering if that has picked up a patched system OpenSSL that the test case doesn't pass with.
cc @mhdawson
The code does a runtime check for whether the OpenSSL implementation supports implicit rejection and conditionally throws an exception based on the check:
node/src/crypto/crypto_cipher.cc
Lines 1081 to 1095 in f098b7a
int rsa_pkcs1_implicit_rejection = EVP_PKEY_CTX_ctrl_str(ctx.get(), "rsa_pkcs1_implicit_rejection", "1"); // From the doc -2 means that the option is not supported. // The default for the option is enabled and if it has been // specifically disabled we want to respect that so we will // not throw an error if the option is supported regardless // of how it is set. The call to set the value // will not affect what is used since a different context is // used in the call if the option is supported if (rsa_pkcs1_implicit_rejection <= 0) { return THROW_ERR_INVALID_ARG_VALUE( env, "RSA_PKCS1_PADDING is no longer supported for private decryption," " this can be reverted with --security-revert=CVE-2024-PEND"); }
However the test looks to be always expecting the exception. It may not be easy for the test to do the feature detection without native code.@mhdawson Thoughts? Perhaps as a short term fix we can skip the test if built with a dynamically linked OpenSSL?
I presume we'd expect to have to update the test in the future when we update the statically linked OpenSSL to a version that supports the implicit rejection.
This is a similar problem to #52196
richardlau commented
on Apr 15, 2024 on Apr 15, 2024 · Hidden as outdatedAuthorshow commentMore actionsI also rebuilt test-digitalocean-ubi81_container-x64-1 (and all other containers on that host) today.
I had a quick discussion with @mhdawson who is going to look at if there's a way for the test to detect if the underlying OpenSSL implementation supports implicit rejections.
As a temporary fix to unblock the CI, I've opened #52542 to skip that part of the test if Node.js has been dynamically linked against OpenSSL.
- added a commit that references this issue
on Apr 15, 2024 - added 2 commits that reference this issue
on Apr 17, 2024 - added a commit that references this issue
on Apr 23, 2024 - added a commit that references this issue
on May 1, 2024 - added a commit that references this issue
on May 6, 2024 - added a commit that references this issue
on May 8, 2024 - added a commit that references this issue
on Jun 17, 2024 - added a commit that references this issue
on Jun 20, 2024
Test
test-crypto-rsa-dsa
Platform
Linux x64
Console output
Build links
Additional information
Looks like this test is constantly failing on test-ibm-ubi81_container-x64-1 since yesterday.