Skip to content

biscuit-capi: record the error when returning NULL from biscuit_from … - #344

Merged
divarvel merged 1 commit into
eclipse-biscuit:mainfrom
aojea:capi-record-errors
Sep 29, 2026
Merged

divarvel merged 1 commit into
eclipse-biscuit:mainfrom
aojea:capi-record-errors

Conversation

@aojea

@aojea aojea commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

…and the build functions

biscuit_from, biscuit_builder_build, biscuit_authorizer, authorizer_builder_build and authorizer_builder_build_unauthenticated converted the Result with .ok() without calling update_last_error, so a caller receiving NULL found error_kind() == None and error_message() == NULL. biscuit_from is the function every binding calls on untrusted input, so an invalid or forged token produced no diagnostic at all. biscuit_builder_build also returned NULL silently when the seed was not 32 bytes.

Record the underlying error in each of these paths and add a C test that checks biscuit_from on garbage reports
FormatDeserializationError and a short seed reports InvalidArgument.

Assisted by AI

…and the build functions

`biscuit_from`, `biscuit_builder_build`, `biscuit_authorizer`,
`authorizer_builder_build` and `authorizer_builder_build_unauthenticated`
converted the `Result` with `.ok()` without calling `update_last_error`,
so a caller receiving NULL found `error_kind() == None` and
`error_message() == NULL`. `biscuit_from` is the function every binding
calls on untrusted input, so an invalid or forged token produced no
diagnostic at all. `biscuit_builder_build` also returned NULL silently
when the seed was not 32 bytes.

Record the underlying error in each of these paths and add a C test
that checks `biscuit_from` on garbage reports
`FormatDeserializationError` and a short seed reports `InvalidArgument`.
@aojea
aojea force-pushed the capi-record-errors branch from 3dd1234 to f6f2950 Compare September 29, 2026 19:23
@divarvel

Copy link
Copy Markdown
Contributor

Thanks!

Note that the capi module is not used a lot right now, all the implementations using the rust lib through FFI now use dedicated bindings

@divarvel

divarvel commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

a doctest failed because of a timeout. While adding larger timeouts to regular tests is fine, I'm a bit more reluctant to modify doctests the same way

@divarvel
divarvel merged commit 01778d2 into eclipse-biscuit:main Sep 29, 2026
6 of 7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants