From nobody Tue Sep 22 03:47:28 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; arc=pass (i=1 dmarc=pass fromdomain=aspeedtech.com); dmarc=pass(p=quarantine dis=none) header.from=aspeedtech.com ARC-Seal: i=2; a=rsa-sha256; t=1784014214; cv=pass; d=zohomail.com; s=zohoarc; b=fCUIRVZxMpJeMVO1EG0CRnBBEnqKeziKxlw7J14tPHop0wJdG/Eb6zJ2DrTKSHg0sSu1nJ2TMTdJBvlUDHl/2LqLk+51T/9nR761WOjcW8yeaEqKoZd9D8+FsY79R8I3Bhk/pggXOPZUU+ElPWw469WtcpWermgGCcGwcfdS/5Q= ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784014214; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=rlBFGs54UoThOO851Ni3gdt9GIL3kDsixPun6fa2TKA=; b=cKUxQHpzVTI6Fhz5xUBL7LT7Y/HnNf3gZwcqDgSnrQurgHcvpbKUt5pcdHRmVzuTzcKdaFaQJ+CJ0D/ZKLAIZ/wj+mgFBwIcAid/EMYnyiWbeHZLGyW2IDQDwJEEUoaBia5mYfJS03t6wzsX1UhvdEVdXbPfw6NKJq5vk8lTYXg= ARC-Authentication-Results: i=2; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; arc=pass (i=1 dmarc=pass fromdomain=aspeedtech.com); dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784014214373103.84599762596929; Tue, 14 Jul 2026 00:30:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wjXaM-0005y1-TQ; Tue, 14 Jul 2026 03:29:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wjXa7-0005rF-Cz; Tue, 14 Jul 2026 03:29:31 -0400 Received: from mail-japaneastazlp170120005.outbound.protection.outlook.com ([2a01:111:f403:c405::5] helo=TYPPR03CU001.outbound.protection.outlook.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wjXa5-0006WV-CN; Tue, 14 Jul 2026 03:29:31 -0400 Received: from TYZPR06MB4980.apcprd06.prod.outlook.com (2603:1096:400:1cc::10) by SEZPR06MB6117.apcprd06.prod.outlook.com (2603:1096:101:f3::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.202.18; Tue, 14 Jul 2026 07:29:16 +0000 Received: from TYZPR06MB4980.apcprd06.prod.outlook.com ([fe80::ea8a:7cb7:4822:2fb3]) by TYZPR06MB4980.apcprd06.prod.outlook.com ([fe80::ea8a:7cb7:4822:2fb3%6]) with mapi id 15.21.0202.014; Tue, 14 Jul 2026 07:29:16 +0000 ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=gJaUgWUZduLLL58tYuFe/ytKnuBksQkprXNQSUbYL5VY4aDY6jhaMNRYJUzW3XV2UvAX+j4grE8SnQwm3nHNHdfP58fAmnrheJWof7d0iKM3pHGlQVZH4exvMQW3HqlVjiCuUUp+vvfOCxGuMFgsRD2E0HDXKkYcfMiOqPu06gMPD1dy0bOLHClY1NHtfMHWSNwhD8x4ZO9teQQCx2chYgq+T0WuF0f/wD/Se6gSnu6yFrw75E8YKpg7c7gc5BJF44JVX5WsOa04D8AT/duXr7NM+iEkTcK6xaeD1pZaMAbUKP3CaDXdJWZljfag5C2XIzViOfbWtpPzqKfOtTDYlg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=rlBFGs54UoThOO851Ni3gdt9GIL3kDsixPun6fa2TKA=; b=MXbC+dPRxV9czBOnGnodSVAVGdrJms1Pba+AgVJq5N+GnYNMESa8YI863w8PE507n0aMPiXvt6QXzijpqpTh2HRZjjVbnudm0/5Tvh9+g+sEyMBdoSO07vQjxZ8QF2/Il7te4jpyKHaNJXfelGeHHNXep+jRNzPjw/EkC83Zkg+PMAaL6SKi3X3ZyfMghW+PQWDJKU2alXGw9FfqjwspFshE0ebFpAVYl5CMrEeQ8Lrexk/H4v1wQXk5ypKbOVSTd0le7h8fA3fVSVbQfZp6v+LxAU9M2WalwqXQnkDdFqJtOib/4Spjeu9Gj/hMixrkcXfKlvE9Y6GzVWReE74iKA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=aspeedtech.com; dmarc=pass action=none header.from=aspeedtech.com; dkim=pass header.d=aspeedtech.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=aspeedtech.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=rlBFGs54UoThOO851Ni3gdt9GIL3kDsixPun6fa2TKA=; b=f/yMp6I23JJtxDrJOz0eJN4RTqLueWfZkwyxIV/Fi5MLPdy4C+Km4pUhOZ+Pdk7LLFrdSQzlmL7kNWyM556HMuWt70LGbpNbSfJUkPbWUVc0O2VWEQllZrg19EjqeH3IUj9elNh4vtSIzsscDOgv3JCYlkVqwCyncrpbVdEkf91Gk3xDE0HZXneKSsYD2JBOgfO1WpS1yH1ogJYdJaVxVQhQEVt4eh2j0q/TTd45aDA9s9zjRPiSSrnXJ3rRYW8Y1T73QxgSYrldYdCwZijzesD4CdnCnxz7609BXKOTElPyerY998Z8AOjJxGza+HOkiYdc9mjuf8tZO9oZazjCDQ== From: Jamin Lin To: =?iso-8859-1?Q?Daniel_P=2E_Berrang=E9?= , =?iso-8859-1?Q?C=E9dric_Le_Goater?= , Peter Maydell , Steven Lee , Troy Lee , Kane Chen , Andrew Jeffery , Joel Stanley , Eric Blake , Markus Armbruster , Fabiano Rosas , Laurent Vivier , Paolo Bonzini , "open list:All patches CC here" , "open list:ASPEED BMCs" CC: Jamin Lin , Troy Lee Subject: [PATCH v1 10/15] tests/unit/test-crypto-cipher: Test AES-GCM mode Thread-Topic: [PATCH v1 10/15] tests/unit/test-crypto-cipher: Test AES-GCM mode Thread-Index: AQHdE2J505CR9pw4e0ypJ8VqHy00VQ== Date: Tue, 14 Jul 2026 07:29:16 +0000 Message-ID: <20260714072900.3023742-11-jamin_lin@aspeedtech.com> References: <20260714072900.3023742-1-jamin_lin@aspeedtech.com> In-Reply-To: <20260714072900.3023742-1-jamin_lin@aspeedtech.com> Accept-Language: zh-TW, en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=aspeedtech.com; x-ms-publictraffictype: Email x-ms-traffictypediagnostic: TYZPR06MB4980:EE_|SEZPR06MB6117:EE_ x-ms-office365-filtering-correlation-id: b3d1e4fb-ee18-404c-97c1-08dee1799c85 x-ms-exchange-senderadcheck: 1 x-ms-exchange-antispam-relay: 0 x-microsoft-antispam: BCL:0; ARA:13230040|366016|23010399003|7416014|376014|1800799024|921020|38070700021|6133799003|18002099003|22082099003|56012099006; x-microsoft-antispam-message-info: REdITh6RANthFAsrxIYUbqaFx/5APXmuOW0FcOueMD5dODbLQ7LaN2hLHADCqf73tH8FuryPwAFDc3XGd/+mlVeKZt+HXfuym7d2a2Gat/zjQPHHkpc/GxuivlzaJfQbrSavEOf5QiBJ4XramRSS0zLBwoXUWl1VoVSG5qtqxCd5vsQkf4KinNpGpMOM3qXWKeyuhhn8RmyiHjWb7olpTGrTEZrz/fxQa2hB8sfxQtndhEz5lM935t+V1hAwjr7g7J3+blszJPWTFrzMOdu3d++fOABL3MH+W1XmL2y3k7hv3fM6N+wPOf67zGFsOiW6nMMoZzjeYNnLf3+MFSLDD7Ngt6f/GwBJvHMvPDNBFTqpkwhu8jAhLBzjy3CLMXzNSsTsHhtmlTKlKKkT8rz+hgIuhl3gGZo21dE4MQTFgLOy2SdrtcguWGwhWPvocfXDBOACXMj+vZIBQVQfKXO/oi+c6HB48RBozuMZM6AQ+g3ROKMlhr9D2wKCziqEoP3qpWlft2ni79oUEnAOcjZdMf5wKZ8dLrDSoI0AeTNuIcmYiAeDQwDXodrNn/VnyHoGhz7U2bvGz2a5e+fmmZldtGJ5c3xxxPbHuZTjDQLVzZBhzI8zHhhElNWpoohhpb/BIMxUhL15FQCnP8Xn5S3PEiE7VRRENJLAQ3ZCNOtZyYIbVYHcN5BfxuhzTRr1ks9a1atL12nGnINTweTcOUjLNJSU9Mo9rIQ98zGHrTTRCj3Ba+KwnV79f6Ka7UOa4cMZ x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:TYZPR06MB4980.apcprd06.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230040)(366016)(23010399003)(7416014)(376014)(1800799024)(921020)(38070700021)(6133799003)(18002099003)(22082099003)(56012099006); DIR:OUT; SFP:1102; x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?iso-8859-1?Q?TNz08gIwq8JJXP1JgbdSJgX3iHQLZzatXSj2FkpVvuS8Pb5tnsYcJ19OrI?= =?iso-8859-1?Q?zob4OQpZgcZXD8uqasFpIfNeukW1h30eVvtO+OmMWkuqXP+Fo8llljmwdu?= =?iso-8859-1?Q?qMFWAFb344qJPNH6QMVQdi2mrxxqvJ6LiWyOJPUI5mIhm3GH6+9qogF2gN?= =?iso-8859-1?Q?/RlW9kaDNnYFk7YQMIYSbhBPSEAam2CaV1xBNHTsLzOnWjASrNUziM28IE?= =?iso-8859-1?Q?0alrNY7P6EkEsKSCJAu1A0xK4e7pNwb/BeMQMnpLvRJHvjedhsSD5GDWPi?= =?iso-8859-1?Q?qMJO2ZMgdla8KU+yKmhPrX1afEy8X4DUuYWUv5Kthfdt+HTZVNZBMes/hs?= =?iso-8859-1?Q?Dc+lI1aO5w0L0pMvFNn4hph9rv9yQe77lktVnvSOfUV6CqFslRw300AYkG?= =?iso-8859-1?Q?W3PI6z2BP3sVpJqT5L79GYKjP8IZAWIiqWlf5a4Hh1WeAemk9hdW7ByDkS?= =?iso-8859-1?Q?GnRj70q71GCk8QhrC+bA7pQ8T4QQ+eqAdtItmVbgsfP/Z1gn62ko7XHJiP?= =?iso-8859-1?Q?njCn0sDZJ3csSGuOeu4WaCAlh07yqsKxK70VdkGQebx3RWxoOQe+snrTI3?= =?iso-8859-1?Q?hsO96UiotMDI8L9YEXd1WC54ypjh5qtDMmFcWI+KdLBWMgiz40nZs53r44?= =?iso-8859-1?Q?FUsQguF8zVKF54rKM3sKhcCb+os75/M5Zy1qZ6t/pSRexi9Xp7GhK7QnsE?= =?iso-8859-1?Q?gtqHL+Z+dyCJBXpKFSXtCCIKeeF1FvU9abCDeR9p/oPreG4zpk7z8T0/FU?= =?iso-8859-1?Q?3u7/fOuaXVTyQkzEJTs6rbJbi19oDX0tDrjXxxlxmO+MSk1/WBI1fu4Q/e?= =?iso-8859-1?Q?OuzvnOGSWIAGf07kepvgl0JgpPykr8BnH6wct7VxhbSYAfISbKZB0HuOb1?= =?iso-8859-1?Q?IXM1yYTY1fYyTOF34ChHPln4M/4bP34m6iv4rvdIzcXvttPdWmfiv91yPt?= =?iso-8859-1?Q?+vKdHwCBIIEu5j7x0cLpWxak/gN+5HC/O39ykSQ+YDFt5XoUrXDpf++Clf?= =?iso-8859-1?Q?rZbfRogdgMOLjfZHjW20pRbkCjFtd80Rj9wudn0gXa6aj7/8cl/nX4Go0n?= =?iso-8859-1?Q?1qYrPLUgFPbR/uoaOUokt5/NMPTYDnNqx28qkn5ocvS/pGzGeyOFqn5kLX?= =?iso-8859-1?Q?mnrMyh1G+0dkd6xQj58kFL7I5fCPejB+ZQnfUd5WmQAtJ+YUf86+nztPGY?= =?iso-8859-1?Q?NrBX9TEdp4YwB/+4WzA6WsyFQbHhnlTKT1iynXFfjS6UMDbdBC/35gj7GY?= =?iso-8859-1?Q?sehZ1k8jrDZW2fF9AvwlYWsMJVBjebwjpb3UEa7aDUshChEvgBTiG0a4ja?= =?iso-8859-1?Q?VP1qq4e7X2q+1O5JzYIu7G5hFekSQOPGPeo8FHO8y+fSwAL9kOwppfOfxt?= =?iso-8859-1?Q?SBU2qpUa58NfG5rqKp3JxQnQfeb409YG/oaXTGlMiFe9lw2pEvC7G12EB8?= =?iso-8859-1?Q?pqenFlYiWxYxD8K3nHowyyu1sPcFjIvkgE85XTcjuc0nIctIYiAsgYGt3o?= =?iso-8859-1?Q?EbflGAMSVYAOaWA48+bq3TXRltu3LH+BO1t1jsVOImxWpFCkaApOPyaEe6?= =?iso-8859-1?Q?dObzfBWvl5BGFF3LmMPcSfY7JxsPo3DDTumhFk8C4s0kV/vgzOjTGtLv3A?= =?iso-8859-1?Q?cBjjp5RtFJd8tIZeRmawSbnvlGL8p+p+uvk+vlhWAuH5yf8dV4XCOB9DuP?= =?iso-8859-1?Q?NNPTrRK2SooX6YYreReZPa5JPL7s/XoZbbzWcyyNrBXg6dWmxLBQ8rtE/g?= =?iso-8859-1?Q?TcakddxxLPwZSfP6JweY/295mOj/5VxlsW4lLfmqT7hGOAjJhgkC9kzaML?= =?iso-8859-1?Q?pYeX+kLwqw=3D=3D?= Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-Exchange-RoutingPolicyChecked: DeGsDIjBElf3aKEGSOTLt7+bUTzvZmllmNvhzmVx3lYfo9mA5rhG1BYDShq0VrxtFXiRcoWnVgSZWRZ1cShjoRS5kCZJKlLGKfjjnPWtwleLiYmFedAgWKacb+WB9hSSY2u+tAkn6GpVufs3fZbabSQsQ68rMjX6UdBl7JhqEm+50pULrba/D+0s6g7r4vDyKuYOUpUOdtt2S13m//s8LPEpxqWsZD0j30+RvV2MS5+a26/plbFJ32s94dt2V5u+zA3aR1nqjCRmJnnEabhVzz95+UgqTE53Lc1zyHiWKbFAT5IdbvZJ8bCEpTZqvTnTndU7qoLJIaIrTCzBs0z0Sw== X-OriginatorOrg: aspeedtech.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: TYZPR06MB4980.apcprd06.prod.outlook.com X-MS-Exchange-CrossTenant-Network-Message-Id: b3d1e4fb-ee18-404c-97c1-08dee1799c85 X-MS-Exchange-CrossTenant-originalarrivaltime: 14 Jul 2026 07:29:16.5492 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 43d4aa98-e35b-4575-8939-080e90d5a249 X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: yXVenEcNXU/HvbkofNk80yet4GinIC/wloQnd75R8CbApn2oprcpgQK1vjcFQFXRFCVQ1J78Fl3AJg7dkHSHznO2Kxt9aFOdlRUOpuFGoe4= X-MS-Exchange-Transport-CrossTenantHeadersStamped: SEZPR06MB6117 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a01:111:f403:c405::5; envelope-from=jamin_lin@aspeedtech.com; helo=TYPPR03CU001.outbound.protection.outlook.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @aspeedtech.com) X-ZM-MESSAGEID: 1784014217229158500 Content-Type: text/plain; charset="utf-8" Exercise the new GCM mode and the setaad/gettag helpers with the canonical AES-GCM test vectors from the GCM specification (McGrew & Viega, also NIST SP 800-38D): AES-128 and AES-256, with and without associated data. Each vector is run through encrypt (checking the ciphertext and the generated tag) and decrypt (checking the recovered plaintext and the recomputed tag). Signed-off-by: Jamin Lin --- tests/unit/test-crypto-cipher.c | 240 ++++++++++++++++++++++++++++++++ 1 file changed, 240 insertions(+) diff --git a/tests/unit/test-crypto-cipher.c b/tests/unit/test-crypto-ciphe= r.c index 1331d558cf..670262b39e 100644 --- a/tests/unit/test-crypto-cipher.c +++ b/tests/unit/test-crypto-cipher.c @@ -810,6 +810,230 @@ static void test_cipher_short_plaintext(void) qcrypto_cipher_free(cipher); } =20 +typedef struct QCryptoCipherGcmTestData QCryptoCipherGcmTestData; +struct QCryptoCipherGcmTestData { + const char *path; + QCryptoCipherAlgo alg; + const char *key; + const char *iv; + /* associated data, or NULL for none */ + const char *aad; + const char *plaintext; + const char *ciphertext; + const char *tag; +}; + +/* + * AES-GCM test vectors from "The Galois/Counter Mode of Operation (GCM)" + * (McGrew & Viega, also NIST SP 800-38D), with a 96-bit IV and a 128-bit + * tag. Each entry's "Test case N" label is the numbered test case from th= at + * document (Appendix B / the GCM specification's test vectors). + */ +static QCryptoCipherGcmTestData gcm_test_data[] =3D { + { + /* Test case 2 */ + .path =3D "/crypto/cipher/aes-128-gcm/2", + .alg =3D QCRYPTO_CIPHER_ALGO_AES_128, + .key =3D "00000000000000000000000000000000", + .iv =3D "000000000000000000000000", + .plaintext =3D "00000000000000000000000000000000", + .ciphertext =3D "0388dace60b6a392f328c2b971b2fe78", + .tag =3D "ab6e47d42cec13bdf53a67b21257bddf", + }, + { + /* Test case 3 (no AAD) */ + .path =3D "/crypto/cipher/aes-128-gcm/3", + .alg =3D QCRYPTO_CIPHER_ALGO_AES_128, + .key =3D "feffe9928665731c6d6a8f9467308308", + .iv =3D "cafebabefacedbaddecaf888", + .plaintext =3D + "d9313225f88406e5a55909c5aff5269a" + "86a7a9531534f7da2e4c303d8a318a72" + "1c3c0c95956809532fcf0e2449a6b525" + "b16aedf5aa0de657ba637b391aafd255", + .ciphertext =3D + "42831ec2217774244b7221b784d0d49c" + "e3aa212f2c02a4e035c17e2329aca12e" + "21d514b25466931c7d8f6a5aac84aa05" + "1ba30b396a0aac973d58e091473f5985", + .tag =3D "4d5c2af327cd64a62cf35abd2ba6fab4", + }, + { + /* Test case 4 (with AAD) */ + .path =3D "/crypto/cipher/aes-128-gcm/4", + .alg =3D QCRYPTO_CIPHER_ALGO_AES_128, + .key =3D "feffe9928665731c6d6a8f9467308308", + .iv =3D "cafebabefacedbaddecaf888", + .aad =3D "feedfacedeadbeeffeedfacedeadbeefabaddad2", + .plaintext =3D + "d9313225f88406e5a55909c5aff5269a" + "86a7a9531534f7da2e4c303d8a318a72" + "1c3c0c95956809532fcf0e2449a6b525" + "b16aedf5aa0de657ba637b39", + .ciphertext =3D + "42831ec2217774244b7221b784d0d49c" + "e3aa212f2c02a4e035c17e2329aca12e" + "21d514b25466931c7d8f6a5aac84aa05" + "1ba30b396a0aac973d58e091", + .tag =3D "5bc94fbc3221a5db94fae95ae7121a47", + }, + { + /* Test case 15 (AES-256, no AAD) */ + .path =3D "/crypto/cipher/aes-256-gcm/15", + .alg =3D QCRYPTO_CIPHER_ALGO_AES_256, + .key =3D + "feffe9928665731c6d6a8f9467308308" + "feffe9928665731c6d6a8f9467308308", + .iv =3D "cafebabefacedbaddecaf888", + .plaintext =3D + "d9313225f88406e5a55909c5aff5269a" + "86a7a9531534f7da2e4c303d8a318a72" + "1c3c0c95956809532fcf0e2449a6b525" + "b16aedf5aa0de657ba637b391aafd255", + .ciphertext =3D + "522dc1f099567d07f47f37a32a84427d" + "643a8cdcbfe5c0c97598a2bd2555d1aa" + "8cb08e48590dbb3da7b08b1056828838" + "c5f61e6393ba7a0abcc9f662898015ad", + .tag =3D "b094dac5d93471bdec1a502270e3cc6c", + }, + { + /* Test case 16 (AES-256, with AAD) */ + .path =3D "/crypto/cipher/aes-256-gcm/16", + .alg =3D QCRYPTO_CIPHER_ALGO_AES_256, + .key =3D + "feffe9928665731c6d6a8f9467308308" + "feffe9928665731c6d6a8f9467308308", + .iv =3D "cafebabefacedbaddecaf888", + .aad =3D "feedfacedeadbeeffeedfacedeadbeefabaddad2", + .plaintext =3D + "d9313225f88406e5a55909c5aff5269a" + "86a7a9531534f7da2e4c303d8a318a72" + "1c3c0c95956809532fcf0e2449a6b525" + "b16aedf5aa0de657ba637b39", + .ciphertext =3D + "522dc1f099567d07f47f37a32a84427d" + "643a8cdcbfe5c0c97598a2bd2555d1aa" + "8cb08e48590dbb3da7b08b1056828838" + "c5f61e6393ba7a0abcc9f662", + .tag =3D "76fc6ece0f4e1768cddf8853bb2d551b", + }, +}; + +static void test_cipher_gcm(const void *opaque) +{ + const QCryptoCipherGcmTestData *data =3D opaque; + g_autofree uint8_t *key =3D NULL; + g_autofree uint8_t *iv =3D NULL; + g_autofree uint8_t *aad =3D NULL; + g_autofree uint8_t *ptext =3D NULL; + g_autofree uint8_t *ctext =3D NULL; + g_autofree uint8_t *tagexp =3D NULL; + g_autofree uint8_t *out =3D NULL; + uint8_t tag[16]; + size_t nkey; + size_t niv; + size_t naad =3D 0; + size_t nptext; + size_t nctext; + size_t ntag; + QCryptoCipher *cipher; + + nkey =3D unhex_string(data->key, &key); + niv =3D unhex_string(data->iv, &iv); + nptext =3D unhex_string(data->plaintext, &ptext); + nctext =3D unhex_string(data->ciphertext, &ctext); + ntag =3D unhex_string(data->tag, &tagexp); + if (data->aad) { + naad =3D unhex_string(data->aad, &aad); + } + + g_assert_cmpint(nptext, =3D=3D, nctext); + g_assert_cmpint(ntag, =3D=3D, sizeof(tag)); + out =3D g_new0(uint8_t, nptext); + + /* Encrypt: plaintext -> ciphertext, then read back the tag. */ + cipher =3D qcrypto_cipher_new(data->alg, QCRYPTO_CIPHER_MODE_GCM, + key, nkey, &error_abort); + g_assert(cipher !=3D NULL); + g_assert(qcrypto_cipher_setiv(cipher, iv, niv, &error_abort) =3D=3D 0); + if (naad) { + g_assert(qcrypto_cipher_setaad(cipher, aad, naad, &error_abort) = =3D=3D 0); + } + g_assert(qcrypto_cipher_encrypt(cipher, ptext, out, nptext, + &error_abort) =3D=3D 0); + g_assert_cmpmem(out, nptext, ctext, nctext); + g_assert(qcrypto_cipher_gettag(cipher, tag, sizeof(tag), + &error_abort) =3D=3D 0); + g_assert_cmpmem(tag, sizeof(tag), tagexp, ntag); + qcrypto_cipher_free(cipher); + + /* Decrypt: ciphertext -> plaintext, recomputed tag must match. */ + memset(out, 0, nptext); + cipher =3D qcrypto_cipher_new(data->alg, QCRYPTO_CIPHER_MODE_GCM, + key, nkey, &error_abort); + g_assert(cipher !=3D NULL); + g_assert(qcrypto_cipher_setiv(cipher, iv, niv, &error_abort) =3D=3D 0); + if (naad) { + g_assert(qcrypto_cipher_setaad(cipher, aad, naad, &error_abort) = =3D=3D 0); + } + g_assert(qcrypto_cipher_decrypt(cipher, ctext, out, nctext, + &error_abort) =3D=3D 0); + g_assert_cmpmem(out, nctext, ptext, nptext); + g_assert(qcrypto_cipher_gettag(cipher, tag, sizeof(tag), + &error_abort) =3D=3D 0); + g_assert_cmpmem(tag, sizeof(tag), tagexp, ntag); + qcrypto_cipher_free(cipher); +} + +/* + * Corrupt one ciphertext byte and confirm the recomputed GCM tag no longer + * matches: the authentication tag must detect tampering. + */ +static void test_cipher_gcm_tamper(const void *opaque) +{ + const QCryptoCipherGcmTestData *data =3D opaque; + g_autofree uint8_t *key =3D NULL; + g_autofree uint8_t *iv =3D NULL; + g_autofree uint8_t *aad =3D NULL; + g_autofree uint8_t *ctext =3D NULL; + g_autofree uint8_t *tagexp =3D NULL; + g_autofree uint8_t *out =3D NULL; + uint8_t tag[16]; + size_t nkey; + size_t niv; + size_t naad =3D 0; + size_t nctext; + size_t ntag; + QCryptoCipher *cipher; + + nkey =3D unhex_string(data->key, &key); + niv =3D unhex_string(data->iv, &iv); + nctext =3D unhex_string(data->ciphertext, &ctext); + ntag =3D unhex_string(data->tag, &tagexp); + if (data->aad) { + naad =3D unhex_string(data->aad, &aad); + } + out =3D g_new0(uint8_t, nctext); + + /* Flip one ciphertext bit before decrypting. */ + ctext[0] ^=3D 0x01; + + cipher =3D qcrypto_cipher_new(data->alg, QCRYPTO_CIPHER_MODE_GCM, + key, nkey, &error_abort); + g_assert(cipher !=3D NULL); + g_assert(qcrypto_cipher_setiv(cipher, iv, niv, &error_abort) =3D=3D 0); + if (naad) { + g_assert(qcrypto_cipher_setaad(cipher, aad, naad, &error_abort) = =3D=3D 0); + } + g_assert(qcrypto_cipher_decrypt(cipher, ctext, out, nctext, + &error_abort) =3D=3D 0); + g_assert(qcrypto_cipher_gettag(cipher, tag, sizeof(tag), + &error_abort) =3D=3D 0); + g_assert(memcmp(tag, tagexp, ntag) !=3D 0); + qcrypto_cipher_free(cipher); +} + int main(int argc, char **argv) { size_t i; @@ -828,6 +1052,22 @@ int main(int argc, char **argv) } } =20 + for (i =3D 0; i < G_N_ELEMENTS(gcm_test_data); i++) { + if (qcrypto_cipher_supports(gcm_test_data[i].alg, + QCRYPTO_CIPHER_MODE_GCM)) { + g_autofree char *tamper =3D g_strdup_printf("%s/tamper", + gcm_test_data[i].pat= h); + + g_test_add_data_func(gcm_test_data[i].path, &gcm_test_data[i], + test_cipher_gcm); + g_test_add_data_func(tamper, &gcm_test_data[i], + test_cipher_gcm_tamper); + } else { + g_printerr("# skip unsupported %s:gcm\n", + QCryptoCipherAlgo_str(gcm_test_data[i].alg)); + } + } + if (qcrypto_cipher_supports(QCRYPTO_CIPHER_ALGO_AES_256, QCRYPTO_CIPHER_MODE_CBC)) { g_test_add_func("/crypto/cipher/null-iv", --=20 2.43.0