Re: Updated plans for NSPR: merge into NSS

Kai Engert <[email protected]> Thu, 16 Apr 2026 16:20:34 +0200
Newsgroups gmane.comp.mozilla.crypto
Message-ID <[email protected]>
--------------IU2N2iPhZGbMGFipczNc0uxs
Sig: t=p; b=
 wnsEABYIACMWIQTbU6PYxn9IFjJ1R6JpevsbNyK8BAUCaeDwMwUDAAAAAAAKCRBpevsbNyK8BOXR
 AP9zDW2huPf99ii9ODuSd1IBdDZ2roAkfMrI+fzzaqf1gQEA00MQXkGdUpP1DKIVlZLFzoPl39dI
 ueIn7KwA+97bqAc=
Message-ID: <[email protected]>
Date: Thu, 16 Apr 2026 16:20:34 +0200
MIME-Version: 1.0
User-Agent: Thunderbird Daily
Subject: Re: [dev-tech-crypto] Updated plans for NSPR: merge into NSS
Content-Language: en-US
To: Robert Relyea <[email protected]>, [email protected]
References: <[email protected]>
 <[email protected]>
 <[email protected]>
From: Kai Engert <[email protected]>
Autocrypt: [email protected]; keydata=
 xsFNBE8oE/UBEAC/Vx4tHVkfPdGf0BFMGcidXzAXKQ4+gI2F5rPBoV9fEtYngLHzm7+a6DL2
 v5Jl5b4by9KtUbfIJysR1iniLWMJVPXZcyC4ovGouZ4MGK5cD9kMy+JdwebCs5/tj51vcvrS
 08dP7r9Q0f0H7tsqhtVWuPFt+ZZEj8fIxjMgE3Z5BcyoGT1mXQ544RA0vr0fB9MngvfteD3L
 /wL2miDnYVtwB+VHC6kEB75Pte/yz1kFc/TDqKT8F45M3invhccY8Zwe7F88+uS+tgR5B3Ga
 RMc9WChZr5ed5vRxSLrGqBGSWBKomKuWXNFVMrZAOaq+W/+kOdNSXLdJSvXIAgV4Gywf1D0r
 ZTi8V+UoiTY8eDfT4OlBJrbbkge92/lrqaorAsuo/DVmfv7ARk7q2jvbSZD39zkWpLNsAulz
 gZOr+ffEHKy0f9fNwzenHpKvNtTUWGChEyDf7a6EtTBZsxAYco0xAtFOoQVwx5UzZk4tMVhv
 lrATrvmFdK5SLroDuwtSLUBJ5MhICyaB1kN7YSatQs33D+M5oPKVC+mn1WB/nznU475cssBW
 Asw+/K4VtXN08HxVFEvpV5MtpoYGe/cqsV87aVr/Igg45DVKtMMK8W5AmJDdGru3caxdVkkW
 fis9F1GBkk7ZPgip4cprh3KicuKsXhVrjk2mC/kCR+mrlY8ncQARAQABzRlLYWkgRW5nZXJ0
 IDxLYWlFQGt1aXguZGU+wsGXBBMBCABBAhsDBQsJCAcDBRUKCQgLBRYCAwEAAh4BAheAAhkB
 FiEEIdFuZ+GDmMjand8uHCdCNyUAdyQFAmm9Kt8FCRzF/OsACgkQHCdCNyUAdyQkjw/9GdUH
 bmB9+tTLMpnr5rmJkIqZ8pXQQXEi/pKENGSNzaGHSeXAIptGH7DWKa3DfGHR3TsaREz9RiW9
 vK7jQBzPUZpx4Jne5vpNEpe0U0vjxRpehO6tjn0MIsxa4dlwk3+VZG7CJuOCbyDHLhmz+uTn
 MpaZB96mtLtBcNA5vjroR0mcuc1K9CPaD6+RfUHgoE0/AJGnhdH4WbwCAZ3iMEAqkPXSqifJ
 7R8257wbYdigbKXybdu5qHc0t4EjnPAfYE5Q+2SIYS2F/Y9wJhBdZDak3fiiLFhNBGK/yiWT
 IRarP+lqCSUDQ7wYJuh0J9HrblraiFWErPI2OI9fS0Pd19U8jwb6jdz4maGNz8UUs+JOxKzL
 AZ7voNZvno4tci7mRBOVPtisD0m3Kh93sF7JVYjp2SYUZFgP2BIbaHDLWgKONrn87VmQrNVn
 z7fLvFvg372A8wNaXUZMcDmduTxco5EHI0+O3TKdK6uor9opydONcrpfm1JaN+Fp4diWhgUc
 qaT5R2UHzcGHHztiayfJlm+UvSVO3P68iTZI9i07MWkXdQu65N57OgWLGNB/5S5ms+gm0lSV
 D3Ph6q0X9ZV3hFc5cDiDUyMofMFyJWk7bC4CqZxvOBabkmVErYb2wvUYLwmR99xqQxvQ+7hZ
 XqbSHhZhs93KR1JsHhkdIjSO5A/SgQDOOARmQ8MuEgorBgEEAZdVAQUBAQdAc9UYbulbMQUm
 5xftvu1VkBrFWKTLmD4udR62yP2IfzkDAQgHwsF8BBgBCAAmAhsMFiEEIdFuZ+GDmMjand8u
 HCdCNyUAdyQFAmm9KvYFCQWqTbIACgkQHCdCNyUAdyRvJw//SHoUu7H+GxnXFtIAhW0nlES6
 QHgpd1BQV014ueG3HxqXhdHEz2wqsdP0qnqUOn7uWH0+MR2BF5h4DCWfYhHnNDliZGq7Sug3
 I5a7AuLFZZTTv4O1GE2jwbwnFS+4mZiMdz0XayHMB2FjeSInOiuIfBf//20utFPwzLPaXQdR
 qPRJ51DU1HhRNs8H0Wh3sSkrtfFQvIzLuqoDzvpXInh1t9Brq1nDbdEYJTnu2kVgDaNbFG16
 DN/phEOTTOZKLbbE97mIzc9wizNJTT3TjLHu7CKeFKfLyc3usEVR0QiyOqtvlnPlKj+sMgR3
 egStlen7ipre7lug+W/QBY4hK4+S0C9rkAMOiWUMJytJZK9gDoQv8ubeeAdo4SLaMd2VzD2k
 bIPNk5RKQjprWhe+CivNBZdooQNZ06NTzaIvHNlbspI+e2UF5zKJuMlVou+ulnq5lUiqW+R3
 IjqszzokTUmoDXoUbt+a+q5PYD/ijkznGWhi+OE/4+mWMnx8JVEaPm2Kttoyy+CS/5Dt6Acn
 8FjxlxaMAm6aFota+Y53X81cS7oixz8sLgg5D8JBHV3D+P1iyrgiZRbD5+LtCED1jh2Xjs24
 rj9eXJn/AZG7ixR9D1ijhbG7ZjOtrWes7LipBueYZkoLew7drDNHKEFKSGFvbaatyQdb7sIt
 v57v8GkeKAs=
In-Reply-To: <[email protected]>
Content-Type: text/plain; charset="UTF-8"; format=flowed; hp=clear

On 4/15/26 19:35, 'Robert Relyea' via [email protected] wrote:
> This would be a nightmare for us. Any kind of rollout for us will need 
> to maintain both symbols and library sets.

As I understand it, renaming is necessary to ensure that accidentally 
loading an old NSPR library into the same process will not result in the 
wrong symbols being used - on systems that have multiple copies of the 
NSPR libraries.


> Basically to make this work, we would have to maintain both and the 
> ability for Firefox and NSS to use both, or we need to create 
> compatibilty layers (old nspr libraries with the old names calling the 
> new nspr library).

Introducing shim libraries (named like the old NSPR libraries) that 
export the old symbols, which forward calls to the new functions in the 
new library, might be doable on your side?

Over time, when functionality gets removed, the shim could be changed to 
return a failure for the removed APIs.


>> MPR code that isn't required by either NSS or Firefox would then get 
>> removed over time.
> This is probabably doable. There are other users of NSPR in our OS, but 
> those can get transitioned over time, as long as the phase out is a 
> compile time option.

I think it wouldn't be a compile time option of MPR. The intention is 
that the feature set of MPR is no longer promised to remain stable.

If a consumer needs old NSPR code that newest NSS no longer requires and 
is removed from MPR, and I think you'd have to find another way to 
provide that old API. Potentially by tweaking the NSPR shim library to 
provide it.


>> This means APIs can get removed from the MPR library between releases. 
>> We haven't discussed this detail yet, but if this is a problem for 
>> external consumers, maybe we could define that the MPR major library 
>> version is increased whenever functions are removed?
> 
> Err, only if the API can be compiled out over releases. As long as both 
> Firefox and NSS depend on NSPR (or MPR), then we have the long term 
> support issues. Dropping NSPR as a separate project doesn't stop it from 
> being a separate library, and it would be difficult to not export the 
> NSPR interface because that's is how applications use NSS to do thing 
> like SSL, so even applications that aren't using NSPR per se, still uses 
> NSPR if they are doing NSS.
The shim library would provide the interfaces with the old name. I guess 
you'd have to replace the single copy of the NSPR libraries on the 
system with the replacement shim libraries (nspr4 + plc4 + plds4).

So applications that aren't relinked/rebuilt, and don't depend on the 
removed APIs should continue to work?

Regards,
Kai

-- 
You received this message because you are subscribed to the Google Groups "[email protected]" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion visit https://groups.google.com/a/mozilla.org/d/msgid/dev-tech-crypto/7d0dae6b-dd78-4596-90b3-91d2d15665c3%40kuix.de.

--------------IU2N2iPhZGbMGFipczNc0uxs--