Skip to content

Commit f7b5f00

Browse files
Merge pull request #9710 from rlm2002/xChaCha20_Poly1305_unitTest
Unit test updates for XChacha20-Poly1305
2 parents 4f84be8 + 38cb14f commit f7b5f00

4 files changed

Lines changed: 306 additions & 3 deletions

File tree

tests/api.c

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31209,7 +31209,7 @@ TEST_CASE testCases[] = {
3120931209
TEST_CHACHA_DECLS,
3121031210
/* Poly1305 */
3121131211
TEST_POLY1305_DECLS,
31212-
/* Chacha20-Poly1305 */
31212+
/* Chacha20-Poly1305 and Xchacha20-Poly1305 */
3121331213
TEST_CHACHA20_POLY1305_DECLS,
3121431214
/* Camellia */
3121531215
TEST_CAMELLIA_DECLS,

tests/api/test_chacha20_poly1305.c

Lines changed: 129 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -154,3 +154,132 @@ int test_wc_ChaCha20Poly1305_aead(void)
154154
return EXPECT_RESULT();
155155
} /* END test_wc_ChaCha20Poly1305_aead */
156156

157+
/*
158+
* Testing wc_XChaCha20Poly1305_Encrypt() and wc_XChaCha20Poly1305_Decrypt()
159+
* Test vector from Draft IRTF CFRG XChaCha Appendix A.3
160+
*/
161+
int test_wc_XChaCha20Poly1305_aead(void)
162+
{
163+
EXPECT_DECLS;
164+
#if defined(HAVE_POLY1305) && defined(HAVE_XCHACHA)
165+
const byte key[] = {
166+
0x80, 0x81, 0x82, 0x83, 0x84, 0x85, 0x86, 0x87,
167+
0x88, 0x89, 0x8a, 0x8b, 0x8c, 0x8d, 0x8e, 0x8f,
168+
0x90, 0x91, 0x92, 0x93, 0x94, 0x95, 0x96, 0x97,
169+
0x98, 0x99, 0x9a, 0x9b, 0x9c, 0x9d, 0x9e, 0x9f
170+
};
171+
/* XChaCha uses a 24-byte nonce */
172+
const byte nonce[] = {
173+
0x40, 0x41, 0x42, 0x43, 0x44, 0x45, 0x46, 0x47,
174+
0x48, 0x49, 0x4a, 0x4b, 0x4c, 0x4d, 0x4e, 0x4f,
175+
0x50, 0x51, 0x52, 0x53, 0x54, 0x55, 0x56, 0x57
176+
};
177+
const byte plaintext[] = {
178+
0x4c, 0x61, 0x64, 0x69, 0x65, 0x73, 0x20, 0x61,
179+
0x6e, 0x64, 0x20, 0x47, 0x65, 0x6e, 0x74, 0x6c,
180+
0x65, 0x6d, 0x65, 0x6e, 0x20, 0x6f, 0x66, 0x20,
181+
0x74, 0x68, 0x65, 0x20, 0x63, 0x6c, 0x61, 0x73,
182+
0x73, 0x20, 0x6f, 0x66, 0x20, 0x27, 0x39, 0x39,
183+
0x3a, 0x20, 0x49, 0x66, 0x20, 0x49, 0x20, 0x63,
184+
0x6f, 0x75, 0x6c, 0x64, 0x20, 0x6f, 0x66, 0x66,
185+
0x65, 0x72, 0x20, 0x79, 0x6f, 0x75, 0x20, 0x6f,
186+
0x6e, 0x6c, 0x79, 0x20, 0x6f, 0x6e, 0x65, 0x20,
187+
0x74, 0x69, 0x70, 0x20, 0x66, 0x6f, 0x72, 0x20,
188+
0x74, 0x68, 0x65, 0x20, 0x66, 0x75, 0x74, 0x75,
189+
0x72, 0x65, 0x2c, 0x20, 0x73, 0x75, 0x6e, 0x73,
190+
0x63, 0x72, 0x65, 0x65, 0x6e, 0x20, 0x77, 0x6f,
191+
0x75, 0x6c, 0x64, 0x20, 0x62, 0x65, 0x20, 0x69,
192+
0x74, 0x2e
193+
};
194+
const byte aad[] = {
195+
0x50, 0x51, 0x52, 0x53, 0xc0, 0xc1, 0xc2, 0xc3,
196+
0xc4, 0xc5, 0xc6, 0xc7
197+
};
198+
/* Expected combined ciphertext + 16-byte tag */
199+
const byte expected[] = {
200+
0xbd, 0x6d, 0x17, 0x9d, 0x3e, 0x83, 0xd4, 0x3b, 0x95, 0x76, 0x57, 0x94,
201+
0x93, 0xc0, 0xe9, 0x39, 0x57, 0x2a, 0x17, 0x00, 0x25, 0x2b, 0xfa, 0xcc,
202+
0xbe, 0xd2, 0x90, 0x2c, 0x21, 0x39, 0x6c, 0xbb, 0x73, 0x1c, 0x7f, 0x1b,
203+
0x0b, 0x4a, 0xa6, 0x44, 0x0b, 0xf3, 0xa8, 0x2f, 0x4e, 0xda, 0x7e, 0x39,
204+
0xae, 0x64, 0xc6, 0x70, 0x8c, 0x54, 0xc2, 0x16, 0xcb, 0x96, 0xb7, 0x2e,
205+
0x12, 0x13, 0xb4, 0x52, 0x2f, 0x8c, 0x9b, 0xa4, 0x0d, 0xb5, 0xd9, 0x45,
206+
0xb1, 0x1b, 0x69, 0xb9, 0x82, 0xc1, 0xbb, 0x9e, 0x3f, 0x3f, 0xac, 0x2b,
207+
0xc3, 0x69, 0x48, 0x8f, 0x76, 0xb2, 0x38, 0x35, 0x65, 0xd3, 0xff, 0xf9,
208+
0x21, 0xf9, 0x66, 0x4c, 0x97, 0x63, 0x7d, 0xa9, 0x76, 0x88, 0x12, 0xf6,
209+
0x15, 0xc6, 0x8b, 0x13, 0xb5, 0x2e,
210+
/* Authentication Tag */
211+
0xc0, 0x87, 0x59, 0x24, 0xc1, 0xc7, 0x98, 0x79, 0x47, 0xde, 0xaf, 0xd8,
212+
0x78, 0x0a, 0xcf, 0x49
213+
};
214+
215+
byte out[256];
216+
byte plain_out[256];
217+
word32 outLen = sizeof(plaintext) + 16;
218+
219+
XMEMSET(out, 0, sizeof(out));
220+
XMEMSET(plain_out, 0, sizeof(plain_out));
221+
222+
/* Test Encrypt (One-shot) */
223+
ExpectIntEQ(wc_XChaCha20Poly1305_Encrypt(out, sizeof(out), plaintext,
224+
sizeof(plaintext), aad, sizeof(aad), nonce, sizeof(nonce),
225+
key, sizeof(key)), 0);
226+
ExpectIntEQ(XMEMCMP(out, expected, outLen), 0);
227+
228+
/* Test Decrypt (One-shot) */
229+
ExpectIntEQ(wc_XChaCha20Poly1305_Decrypt(plain_out, sizeof(plain_out), out,
230+
outLen, aad, sizeof(aad), nonce, sizeof(nonce),
231+
key, sizeof(key)), 0);
232+
ExpectIntEQ(XMEMCMP(plain_out, plaintext, sizeof(plaintext)), 0);
233+
234+
/* Test Encrypt bad args. */
235+
ExpectIntEQ(wc_XChaCha20Poly1305_Encrypt(NULL, sizeof(out), plaintext,
236+
sizeof(plaintext), aad, sizeof(aad), nonce, sizeof(nonce),
237+
key, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
238+
ExpectIntEQ(wc_XChaCha20Poly1305_Encrypt(out, sizeof(out), NULL,
239+
sizeof(plaintext), aad, sizeof(aad), nonce, sizeof(nonce),
240+
key, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
241+
ExpectIntEQ(wc_XChaCha20Poly1305_Encrypt(out, sizeof(out), plaintext,
242+
sizeof(plaintext), NULL, sizeof(aad), nonce, sizeof(nonce),
243+
key, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
244+
ExpectIntEQ(wc_XChaCha20Poly1305_Encrypt(out, sizeof(out), plaintext,
245+
sizeof(plaintext), aad, sizeof(aad), NULL, sizeof(nonce),
246+
key, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
247+
ExpectIntEQ(wc_XChaCha20Poly1305_Encrypt(out, sizeof(out), plaintext,
248+
sizeof(plaintext), aad, sizeof(aad), nonce, sizeof(nonce),
249+
NULL, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
250+
/* Wrong nonce size (12 instead of 24) */
251+
ExpectIntEQ(wc_XChaCha20Poly1305_Encrypt(out, sizeof(out), plaintext,
252+
sizeof(plaintext), aad, sizeof(aad), nonce, 12,
253+
key, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
254+
/* Wrong key size */
255+
ExpectIntEQ(wc_XChaCha20Poly1305_Encrypt(out, sizeof(out), plaintext,
256+
sizeof(plaintext), aad, sizeof(aad), nonce, sizeof(nonce),
257+
key, 16), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
258+
259+
/* Test Decrypt bad args. */
260+
ExpectIntEQ(wc_XChaCha20Poly1305_Decrypt(NULL, sizeof(plain_out), out,
261+
outLen, aad, sizeof(aad), nonce, sizeof(nonce),
262+
key, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
263+
ExpectIntEQ(wc_XChaCha20Poly1305_Decrypt(plain_out, sizeof(plain_out), NULL,
264+
outLen, aad, sizeof(aad), nonce, sizeof(nonce),
265+
key, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
266+
ExpectIntEQ(wc_XChaCha20Poly1305_Decrypt(plain_out, sizeof(plain_out), out,
267+
outLen, NULL, sizeof(aad), nonce, sizeof(nonce),
268+
key, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
269+
ExpectIntEQ(wc_XChaCha20Poly1305_Decrypt(plain_out, sizeof(plain_out), out,
270+
outLen, aad, sizeof(aad), NULL, sizeof(nonce),
271+
key, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
272+
ExpectIntEQ(wc_XChaCha20Poly1305_Decrypt(plain_out, sizeof(plain_out), out,
273+
outLen, aad, sizeof(aad), nonce, sizeof(nonce),
274+
NULL, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
275+
/* Wrong nonce size (12 instead of 24) */
276+
ExpectIntEQ(wc_XChaCha20Poly1305_Decrypt(plain_out, sizeof(plain_out), out,
277+
outLen, aad, sizeof(aad), nonce, 12,
278+
key, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
279+
/* Wrong key size */
280+
ExpectIntEQ(wc_XChaCha20Poly1305_Decrypt(plain_out, sizeof(plain_out), out,
281+
outLen, aad, sizeof(aad), nonce, sizeof(nonce),
282+
key, 16), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
283+
#endif
284+
return EXPECT_RESULT();
285+
} /* END test_wc_XChaCha20Poly1305_aead */

tests/api/test_chacha20_poly1305.h

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -25,8 +25,10 @@
2525
#include <tests/api/api_decl.h>
2626

2727
int test_wc_ChaCha20Poly1305_aead(void);
28+
int test_wc_XChaCha20Poly1305_aead(void);
2829

29-
#define TEST_CHACHA20_POLY1305_DECLS \
30-
TEST_DECL_GROUP("chacha20-poly1305", test_wc_ChaCha20Poly1305_aead)
30+
#define TEST_CHACHA20_POLY1305_DECLS \
31+
TEST_DECL_GROUP("chacha20-poly1305", test_wc_ChaCha20Poly1305_aead), \
32+
TEST_DECL_GROUP("xchacha20-poly1305", test_wc_XChaCha20Poly1305_aead)
3133

3234
#endif /* WOLFCRYPT_TEST_CHACHA20_POLY1305_H */

wolfcrypt/test/test.c

Lines changed: 172 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19873,6 +19873,7 @@ WOLFSSL_TEST_SUBROUTINE wc_test_ret_t XChaCha20Poly1305_test(void) {
1987319873
};
1987419874

1987519875
wc_test_ret_t ret;
19876+
ChaChaPoly_Aead aead;
1987619877

1987719878

1987819879
#if defined(WOLFSSL_SMALL_STACK) && !defined(WOLFSSL_NO_MALLOC)
@@ -19915,6 +19916,177 @@ WOLFSSL_TEST_SUBROUTINE wc_test_ret_t XChaCha20Poly1305_test(void) {
1991519916
if (XMEMCMP(buf2, Plaintext, sizeof Plaintext))
1991619917
ERROR_OUT(WC_TEST_RET_ENC_NC, out);
1991719918

19919+
/* Test wc_XChaCha20Poly1305_Init bad parameters */
19920+
ret = wc_XChaCha20Poly1305_Init(NULL, AAD, sizeof AAD,
19921+
IV, sizeof IV,
19922+
Key, sizeof Key, 1);
19923+
if (ret == 0)
19924+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19925+
19926+
ret = wc_XChaCha20Poly1305_Init(&aead, AAD, sizeof AAD,
19927+
NULL, sizeof IV,
19928+
Key, sizeof Key, 1);
19929+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19930+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19931+
19932+
ret = wc_XChaCha20Poly1305_Init(&aead, AAD, sizeof AAD,
19933+
IV, sizeof IV,
19934+
NULL, sizeof Key, 1);
19935+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19936+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19937+
19938+
/* Wrong nonce size (12 instead of 24) */
19939+
ret = wc_XChaCha20Poly1305_Init(&aead, AAD, sizeof AAD,
19940+
IV, CHACHA20_POLY1305_AEAD_IV_SIZE,
19941+
Key, sizeof Key, 1);
19942+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19943+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19944+
19945+
/* Wrong key size (16 instead of 32) */
19946+
ret = wc_XChaCha20Poly1305_Init(&aead, AAD, sizeof AAD,
19947+
IV, sizeof IV,
19948+
Key, 16, 1);
19949+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19950+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19951+
19952+
/* Test wc_XChaCha20Poly1305_Encrypt bad parameters */
19953+
ret = wc_XChaCha20Poly1305_Encrypt(NULL, sizeof Ciphertext + sizeof Tag,
19954+
Plaintext, sizeof Plaintext,
19955+
AAD, sizeof AAD,
19956+
IV, sizeof IV,
19957+
Key, sizeof Key);
19958+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19959+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19960+
19961+
ret = wc_XChaCha20Poly1305_Encrypt(buf1, sizeof Ciphertext + sizeof Tag,
19962+
NULL, sizeof Plaintext,
19963+
AAD, sizeof AAD,
19964+
IV, sizeof IV,
19965+
Key, sizeof Key);
19966+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19967+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19968+
19969+
ret = wc_XChaCha20Poly1305_Encrypt(buf1, sizeof Ciphertext + sizeof Tag,
19970+
Plaintext, sizeof Plaintext,
19971+
NULL, sizeof AAD,
19972+
IV, sizeof IV,
19973+
Key, sizeof Key);
19974+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19975+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19976+
19977+
ret = wc_XChaCha20Poly1305_Encrypt(buf1, sizeof Ciphertext + sizeof Tag,
19978+
Plaintext, sizeof Plaintext,
19979+
AAD, sizeof AAD,
19980+
NULL, sizeof IV,
19981+
Key, sizeof Key);
19982+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19983+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19984+
19985+
ret = wc_XChaCha20Poly1305_Encrypt(buf1, sizeof Ciphertext + sizeof Tag,
19986+
Plaintext, sizeof Plaintext,
19987+
AAD, sizeof AAD,
19988+
IV, sizeof IV,
19989+
NULL, sizeof Key);
19990+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19991+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19992+
19993+
/* Wrong nonce size (12 instead of 24) */
19994+
ret = wc_XChaCha20Poly1305_Encrypt(buf1, sizeof Ciphertext + sizeof Tag,
19995+
Plaintext, sizeof Plaintext,
19996+
AAD, sizeof AAD,
19997+
IV, CHACHA20_POLY1305_AEAD_IV_SIZE,
19998+
Key, sizeof Key);
19999+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
20000+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
20001+
20002+
/* Wrong key size (16 instead of 32) */
20003+
ret = wc_XChaCha20Poly1305_Encrypt(buf1, sizeof Ciphertext + sizeof Tag,
20004+
Plaintext, sizeof Plaintext,
20005+
AAD, sizeof AAD,
20006+
IV, sizeof IV,
20007+
Key, 16);
20008+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
20009+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
20010+
20011+
/* Insufficient buffer space */
20012+
ret = wc_XChaCha20Poly1305_Encrypt(buf1, sizeof Plaintext,
20013+
Plaintext, sizeof Plaintext,
20014+
AAD, sizeof AAD,
20015+
IV, sizeof IV,
20016+
Key, sizeof Key);
20017+
if (ret != WC_NO_ERR_TRACE(BUFFER_E))
20018+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
20019+
20020+
/* Test wc_XChaCha20Poly1305_Decrypt bad parameters */
20021+
ret = wc_XChaCha20Poly1305_Decrypt(NULL, sizeof Plaintext,
20022+
buf1, sizeof Ciphertext + sizeof Tag,
20023+
AAD, sizeof AAD,
20024+
IV, sizeof IV,
20025+
Key, sizeof Key);
20026+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
20027+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
20028+
20029+
ret = wc_XChaCha20Poly1305_Decrypt(buf2, sizeof Plaintext,
20030+
NULL, sizeof Ciphertext + sizeof Tag,
20031+
AAD, sizeof AAD,
20032+
IV, sizeof IV,
20033+
Key, sizeof Key);
20034+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
20035+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
20036+
20037+
ret = wc_XChaCha20Poly1305_Decrypt(buf2, sizeof Plaintext,
20038+
buf1, sizeof Ciphertext + sizeof Tag,
20039+
NULL, sizeof AAD,
20040+
IV, sizeof IV,
20041+
Key, sizeof Key);
20042+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
20043+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
20044+
20045+
ret = wc_XChaCha20Poly1305_Decrypt(buf2, sizeof Plaintext,
20046+
buf1, sizeof Ciphertext + sizeof Tag,
20047+
AAD, sizeof AAD,
20048+
NULL, sizeof IV,
20049+
Key, sizeof Key);
20050+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
20051+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
20052+
20053+
ret = wc_XChaCha20Poly1305_Decrypt(buf2, sizeof Plaintext,
20054+
buf1, sizeof Ciphertext + sizeof Tag,
20055+
AAD, sizeof AAD,
20056+
IV, sizeof IV,
20057+
NULL, sizeof Key);
20058+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
20059+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
20060+
20061+
/* Wrong nonce size (12 instead of 24) */
20062+
ret = wc_XChaCha20Poly1305_Decrypt(buf2, sizeof Plaintext,
20063+
buf1, sizeof Ciphertext + sizeof Tag,
20064+
AAD, sizeof AAD,
20065+
IV, CHACHA20_POLY1305_AEAD_IV_SIZE,
20066+
Key, sizeof Key);
20067+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
20068+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
20069+
20070+
/* Wrong key size (16 instead of 32) */
20071+
ret = wc_XChaCha20Poly1305_Decrypt(buf2, sizeof Plaintext,
20072+
buf1, sizeof Ciphertext + sizeof Tag,
20073+
AAD, sizeof AAD,
20074+
IV, sizeof IV,
20075+
Key, 16);
20076+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
20077+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
20078+
20079+
/* Insufficient buffer space */
20080+
ret = wc_XChaCha20Poly1305_Decrypt(buf2, sizeof Plaintext - 1,
20081+
buf1, sizeof Ciphertext + sizeof Tag,
20082+
AAD, sizeof AAD,
20083+
IV, sizeof IV,
20084+
Key, sizeof Key);
20085+
if (ret != WC_NO_ERR_TRACE(BUFFER_E))
20086+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
20087+
20088+
ret = 0;
20089+
1991820090
out:
1991920091

1992020092
#if defined(WOLFSSL_SMALL_STACK) && !defined(WOLFSSL_NO_MALLOC)

0 commit comments

Comments
 (0)