fix(impl_jni): configure RSA-PSS parameters after initialization - #375
Open
mfazrinizar wants to merge 1 commit into
Open
fix(impl_jni): configure RSA-PSS parameters after initialization#375mfazrinizar wants to merge 1 commit into
mfazrinizar wants to merge 1 commit into
Conversation
mfazrinizar
marked this pull request as ready for review
August 23, 2026 18:35
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
PSSParameterSpecafterSignature.initSignorSignature.initVerify.Root Cause
The tested Android JCA provider resets its active RSA-PSS parameters during signature initialization. The previous order configured
PSSParameterSpecbefore initialization, so the provider replaced the requested values with its defaults.The backend now obtains and initializes
Signaturebefore applying the requested parameters. This PR does not change generated bindings or persistent key ownership.Issue #371 tracks API 24-26 providers that return non-CRT private-key wrappers and block the shared RSA tests before the PSS operation runs.
Testing
Desktop JNI setup, if needed:
dart run jni:setupVerified with:
dart format --output=none --set-exit-if-changed lib/src/impl_jni/impl_jni.rsapss.dartgit diff --checkdart analyze lib/src/impl_jni/impl_jni.rsapss.dart test/impl_jni_rsapss_test.dartdart test test/impl_jni_rsapss_test.dartdart test test/webcrypto_test.dart -p vm -n 'RSA-PSS'flutter test integration_test/webcrypto_test.dart -d emulator-name --name 'RSA-PSS'fromexample/webcrypto_demo_flutter_appThe focused desktop suite passes 3 cases, the shared desktop RSA-PSS selection passes 366 cases, and the tested Android API 36 x86_64 provider passes all 366 shared RSA-PSS cases. API 24-26 remain blocked by the separate RSA private-key import issue.
Follow-up to #341.