Conversation
…r from package:boring
Replaces the internal `_Scope` arena with `BoringArena` from package:boring: - `_Scope.sync` / `_Scope.async` -> `BoringArena.run`, which releases after a returned Future completes (the old `assert(T is! Future)` guard was a no-op), and `_Scope.stream` -> `BoringArena.stream`. - `dataAsPointer` -> `copyBytes`, `createCBS` / `createCBB` -> `cbs` / `cbb`, `CBB.copy()` -> `CBB.toBytes()`, and `defer(() => X_free(p))` -> `using(p, X_free)`. `move` is unchanged. - Keeps a small `create()` extension that maps `nullptr` to OperationError. - `checkErrorStack` uses `extractBoringSslError()`, which removes the last use of package:ffi, so the dependency is dropped.
- Remove the update-boringssl workflow. It ran tool/bump-boringssl-revision.sh and read tool/REVISION, which this PR deletes along with the vendored BoringSSL. BoringSSL bumps now happen in package:boring, and Dependabot's pub config picks up boring releases. - Declare boring as a hosted `^0.4.0` dependency and pin the unreleased commit with dependency_overrides, fixing the invalid_dependency warning that failed the lints job. The example app needs the same override because overrides don't propagate through its path dependency. - Bump the pin to 60072877, whose CI runs the Wycheproof and x509-limbo conformance suites. lib/, hook/ and src/ are unchanged since 410fae8e.
The TODO in checkErrorStack proposed clearing BoringSSL errors in every finally via BoringArena and asserting that none are left. That doesn't work in Dart: the error queue is thread-local and an isolate may resume on a different OS thread after an await, so a clear or assert at arena release can miss errors or see another isolate's. Errors are already consumed right after each failing call (_checkOp, _checkData, and the explicit clear in _verifyStream), and checkErrorStack already fails tests that leave errors behind. Replace both TODOs with comments saying so, and state the rule once above _checkOp.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Switches
package:webcrypto's native BoringSSL dependency and FFI bindings topackage:boring^0.4.0.Key Changes
hook/build.dartandsrc/webcrypto.{c,h}in favor ofpackage:boring's native asset build and link hooks (which fetch prebuilt binaries for desktop targets or build from source, and tree-shake unused BoringSSL symbols via@RecordUse()in AOT/release builds).lib/src/boringssl/withpackage:boring/bindings.dart, which exposesssl.addresses.*(NativeFinalizerFunctionpointers for all*_free/*_cleanupfunctions, annotated with@RecordUse()viaSymbolAddresses).NativeHandle<EVP_PKEY>: Replaces the custom_EvpPKeyfinalizer wrapper and its four.invokereachability extensions withNativeHandle(pkey, ssl.addresses.EVP_PKEY_free)frompackage:boring.BoringArenareplaces_Scope: The internal_Scopearena,dataAsPointer,createCBS/createCBB, andCBB.copy()moved topackage:boringasBoringArena(run,stream,using,move),copyBytes,cbs()/cbb(), andCBB.toBytes(). webcrypto keeps only a smallcreate()extension that mapsnullptrtoOperationError.BoringArena.runreleases after a returnedFuturecompletes; the oldassert(T is! Future)guard in_Scope.sync/_Scope.asyncwas a no-op.opensslAllocator&extractBoringSslError(): Usesssl.opensslAllocator(OPENSSL_malloc+OPENSSL_cleanse+OPENSSL_free) andssl.extractBoringSslError()frompackage:boring/bindings.dart, including in thecheckErrorStacktest helper, sopackage:ffiis no longer a dependency.CI
.github/workflows/update-boringssl.yml: it rantool/bump-boringssl-revision.shand readtool/REVISION, both deleted here. BoringSSL revision bumps now happen weekly on CI inpackage:boring(same script), and the existing Dependabotpubconfig will pick up newboringreleases.package:boring: its CI runs Project Wycheproof (32 vector files) and x509-limbo path validation directly against the raw bindings.