Skip to content

Commit 407ee3c

Browse files
Ruby Martinrlm2002
authored andcommitted
add API unit test for XChacha20-Poly1305
Expand XChacha20-Poly1305 unit test
1 parent 62ca344 commit 407ee3c

File tree

4 files changed

+306
-3
lines changed

4 files changed

+306
-3
lines changed

tests/api.c

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31093,7 +31093,7 @@ TEST_CASE testCases[] = {
3109331093
TEST_CHACHA_DECLS,
3109431094
/* Poly1305 */
3109531095
TEST_POLY1305_DECLS,
31096-
/* Chacha20-Poly1305 */
31096+
/* Chacha20-Poly1305 and Xchacha20-Poly1305 */
3109731097
TEST_CHACHA20_POLY1305_DECLS,
3109831098
/* Camellia */
3109931099
TEST_CAMELLIA_DECLS,

tests/api/test_chacha20_poly1305.c

Lines changed: 129 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -154,3 +154,132 @@ int test_wc_ChaCha20Poly1305_aead(void)
154154
return EXPECT_RESULT();
155155
} /* END test_wc_ChaCha20Poly1305_aead */
156156

157+
/*
158+
* Testing wc_XChaCha20Poly1305_Encrypt() and wc_XChaCha20Poly1305_Decrypt()
159+
* Test vector from Draft IRTF CFRG XChaCha Appendix A.3
160+
*/
161+
int test_wc_XChaCha20Poly1305_aead(void)
162+
{
163+
EXPECT_DECLS;
164+
#if defined(HAVE_CHACHA) && defined(HAVE_POLY1305) && defined(HAVE_XCHACHA)
165+
const byte key[] = {
166+
0x80, 0x81, 0x82, 0x83, 0x84, 0x85, 0x86, 0x87,
167+
0x88, 0x89, 0x8a, 0x8b, 0x8c, 0x8d, 0x8e, 0x8f,
168+
0x90, 0x91, 0x92, 0x93, 0x94, 0x95, 0x96, 0x97,
169+
0x98, 0x99, 0x9a, 0x9b, 0x9c, 0x9d, 0x9e, 0x9f
170+
};
171+
/* XChaCha uses a 24-byte nonce */
172+
const byte nonce[] = {
173+
0x40, 0x41, 0x42, 0x43, 0x44, 0x45, 0x46, 0x47,
174+
0x48, 0x49, 0x4a, 0x4b, 0x4c, 0x4d, 0x4e, 0x4f,
175+
0x50, 0x51, 0x52, 0x53, 0x54, 0x55, 0x56, 0x57
176+
};
177+
const byte plaintext[] = {
178+
0x4c, 0x61, 0x64, 0x69, 0x65, 0x73, 0x20, 0x61,
179+
0x6e, 0x64, 0x20, 0x47, 0x65, 0x6e, 0x74, 0x6c,
180+
0x65, 0x6d, 0x65, 0x6e, 0x20, 0x6f, 0x66, 0x20,
181+
0x74, 0x68, 0x65, 0x20, 0x63, 0x6c, 0x61, 0x73,
182+
0x73, 0x20, 0x6f, 0x66, 0x20, 0x27, 0x39, 0x39,
183+
0x3a, 0x20, 0x49, 0x66, 0x20, 0x49, 0x20, 0x63,
184+
0x6f, 0x75, 0x6c, 0x64, 0x20, 0x6f, 0x66, 0x66,
185+
0x65, 0x72, 0x20, 0x79, 0x6f, 0x75, 0x20, 0x6f,
186+
0x6e, 0x6c, 0x79, 0x20, 0x6f, 0x6e, 0x65, 0x20,
187+
0x74, 0x69, 0x70, 0x20, 0x66, 0x6f, 0x72, 0x20,
188+
0x74, 0x68, 0x65, 0x20, 0x66, 0x75, 0x74, 0x75,
189+
0x72, 0x65, 0x2c, 0x20, 0x73, 0x75, 0x6e, 0x73,
190+
0x63, 0x72, 0x65, 0x65, 0x6e, 0x20, 0x77, 0x6f,
191+
0x75, 0x6c, 0x64, 0x20, 0x62, 0x65, 0x20, 0x69,
192+
0x74, 0x2e
193+
};
194+
const byte aad[] = {
195+
0x50, 0x51, 0x52, 0x53, 0xc0, 0xc1, 0xc2, 0xc3,
196+
0xc4, 0xc5, 0xc6, 0xc7
197+
};
198+
/* Expected combined ciphertext + 16-byte tag */
199+
const byte expected[] = {
200+
0xbd, 0x6d, 0x17, 0x9d, 0x3e, 0x83, 0xd4, 0x3b, 0x95, 0x76, 0x57, 0x94,
201+
0x93, 0xc0, 0xe9, 0x39, 0x57, 0x2a, 0x17, 0x00, 0x25, 0x2b, 0xfa, 0xcc,
202+
0xbe, 0xd2, 0x90, 0x2c, 0x21, 0x39, 0x6c, 0xbb, 0x73, 0x1c, 0x7f, 0x1b,
203+
0x0b, 0x4a, 0xa6, 0x44, 0x0b, 0xf3, 0xa8, 0x2f, 0x4e, 0xda, 0x7e, 0x39,
204+
0xae, 0x64, 0xc6, 0x70, 0x8c, 0x54, 0xc2, 0x16, 0xcb, 0x96, 0xb7, 0x2e,
205+
0x12, 0x13, 0xb4, 0x52, 0x2f, 0x8c, 0x9b, 0xa4, 0x0d, 0xb5, 0xd9, 0x45,
206+
0xb1, 0x1b, 0x69, 0xb9, 0x82, 0xc1, 0xbb, 0x9e, 0x3f, 0x3f, 0xac, 0x2b,
207+
0xc3, 0x69, 0x48, 0x8f, 0x76, 0xb2, 0x38, 0x35, 0x65, 0xd3, 0xff, 0xf9,
208+
0x21, 0xf9, 0x66, 0x4c, 0x97, 0x63, 0x7d, 0xa9, 0x76, 0x88, 0x12, 0xf6,
209+
0x15, 0xc6, 0x8b, 0x13, 0xb5, 0x2e,
210+
/* Authentication Tag */
211+
0xc0, 0x87, 0x59, 0x24, 0xc1, 0xc7, 0x98, 0x79, 0x47, 0xde, 0xaf, 0xd8,
212+
0x78, 0x0a, 0xcf, 0x49
213+
};
214+
215+
byte out[256];
216+
byte plain_out[256];
217+
word32 outLen = sizeof(plaintext) + 16;
218+
219+
XMEMSET(out, 0, sizeof(out));
220+
XMEMSET(plain_out, 0, sizeof(plain_out));
221+
222+
/* Test Encrypt (One-shot) */
223+
ExpectIntEQ(wc_XChaCha20Poly1305_Encrypt(out, sizeof(out), plaintext,
224+
sizeof(plaintext), aad, sizeof(aad), nonce, sizeof(nonce),
225+
key, sizeof(key)), 0);
226+
ExpectIntEQ(XMEMCMP(out, expected, outLen), 0);
227+
228+
/* Test Decrypt (One-shot) */
229+
ExpectIntEQ(wc_XChaCha20Poly1305_Decrypt(plain_out, sizeof(plain_out), out,
230+
outLen, aad, sizeof(aad), nonce, sizeof(nonce),
231+
key, sizeof(key)), 0);
232+
ExpectIntEQ(XMEMCMP(plain_out, plaintext, sizeof(plaintext)), 0);
233+
234+
/* Test Encrypt bad args. */
235+
ExpectIntEQ(wc_XChaCha20Poly1305_Encrypt(NULL, sizeof(out), plaintext,
236+
sizeof(plaintext), aad, sizeof(aad), nonce, sizeof(nonce),
237+
key, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
238+
ExpectIntEQ(wc_XChaCha20Poly1305_Encrypt(out, sizeof(out), NULL,
239+
sizeof(plaintext), aad, sizeof(aad), nonce, sizeof(nonce),
240+
key, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
241+
ExpectIntEQ(wc_XChaCha20Poly1305_Encrypt(out, sizeof(out), plaintext,
242+
sizeof(plaintext), NULL, sizeof(aad), nonce, sizeof(nonce),
243+
key, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
244+
ExpectIntEQ(wc_XChaCha20Poly1305_Encrypt(out, sizeof(out), plaintext,
245+
sizeof(plaintext), aad, sizeof(aad), NULL, sizeof(nonce),
246+
key, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
247+
ExpectIntEQ(wc_XChaCha20Poly1305_Encrypt(out, sizeof(out), plaintext,
248+
sizeof(plaintext), aad, sizeof(aad), nonce, sizeof(nonce),
249+
NULL, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
250+
/* Wrong nonce size (12 instead of 24) */
251+
ExpectIntEQ(wc_XChaCha20Poly1305_Encrypt(out, sizeof(out), plaintext,
252+
sizeof(plaintext), aad, sizeof(aad), nonce, 12,
253+
key, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
254+
/* Wrong key size */
255+
ExpectIntEQ(wc_XChaCha20Poly1305_Encrypt(out, sizeof(out), plaintext,
256+
sizeof(plaintext), aad, sizeof(aad), nonce, sizeof(nonce),
257+
key, 16), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
258+
259+
/* Test Decrypt bad args. */
260+
ExpectIntEQ(wc_XChaCha20Poly1305_Decrypt(NULL, sizeof(plain_out), out,
261+
outLen, aad, sizeof(aad), nonce, sizeof(nonce),
262+
key, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
263+
ExpectIntEQ(wc_XChaCha20Poly1305_Decrypt(plain_out, sizeof(plain_out), NULL,
264+
outLen, aad, sizeof(aad), nonce, sizeof(nonce),
265+
key, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
266+
ExpectIntEQ(wc_XChaCha20Poly1305_Decrypt(plain_out, sizeof(plain_out), out,
267+
outLen, NULL, sizeof(aad), nonce, sizeof(nonce),
268+
key, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
269+
ExpectIntEQ(wc_XChaCha20Poly1305_Decrypt(plain_out, sizeof(plain_out), out,
270+
outLen, aad, sizeof(aad), NULL, sizeof(nonce),
271+
key, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
272+
ExpectIntEQ(wc_XChaCha20Poly1305_Decrypt(plain_out, sizeof(plain_out), out,
273+
outLen, aad, sizeof(aad), nonce, sizeof(nonce),
274+
NULL, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
275+
/* Wrong nonce size (12 instead of 24) */
276+
ExpectIntEQ(wc_XChaCha20Poly1305_Decrypt(plain_out, sizeof(plain_out), out,
277+
outLen, aad, sizeof(aad), nonce, 12,
278+
key, sizeof(key)), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
279+
/* Wrong key size */
280+
ExpectIntEQ(wc_XChaCha20Poly1305_Decrypt(plain_out, sizeof(plain_out), out,
281+
outLen, aad, sizeof(aad), nonce, sizeof(nonce),
282+
key, 16), WC_NO_ERR_TRACE(BAD_FUNC_ARG));
283+
#endif
284+
return EXPECT_RESULT();
285+
} /* END test_wc_XChaCha20Poly1305_aead */

tests/api/test_chacha20_poly1305.h

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -25,8 +25,10 @@
2525
#include <tests/api/api_decl.h>
2626

2727
int test_wc_ChaCha20Poly1305_aead(void);
28+
int test_wc_XChaCha20Poly1305_aead(void);
2829

29-
#define TEST_CHACHA20_POLY1305_DECLS \
30-
TEST_DECL_GROUP("chacha20-poly1305", test_wc_ChaCha20Poly1305_aead)
30+
#define TEST_CHACHA20_POLY1305_DECLS \
31+
TEST_DECL_GROUP("chacha20-poly1305", test_wc_ChaCha20Poly1305_aead), \
32+
TEST_DECL_GROUP("xchacha20-poly1305", test_wc_XChaCha20Poly1305_aead)
3133

3234
#endif /* WOLFCRYPT_TEST_CHACHA20_POLY1305_H */

wolfcrypt/test/test.c

Lines changed: 172 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19844,6 +19844,7 @@ WOLFSSL_TEST_SUBROUTINE wc_test_ret_t XChaCha20Poly1305_test(void) {
1984419844
};
1984519845

1984619846
wc_test_ret_t ret;
19847+
ChaChaPoly_Aead aead;
1984719848

1984819849

1984919850
#if defined(WOLFSSL_SMALL_STACK) && !defined(WOLFSSL_NO_MALLOC)
@@ -19886,6 +19887,177 @@ WOLFSSL_TEST_SUBROUTINE wc_test_ret_t XChaCha20Poly1305_test(void) {
1988619887
if (XMEMCMP(buf2, Plaintext, sizeof Plaintext))
1988719888
ERROR_OUT(WC_TEST_RET_ENC_NC, out);
1988819889

19890+
/* Test wc_XChaCha20Poly1305_Init bad parameters */
19891+
ret = wc_XChaCha20Poly1305_Init(NULL, AAD, sizeof AAD,
19892+
IV, sizeof IV,
19893+
Key, sizeof Key, 1);
19894+
if (ret == 0)
19895+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19896+
19897+
ret = wc_XChaCha20Poly1305_Init(&aead, AAD, sizeof AAD,
19898+
NULL, sizeof IV,
19899+
Key, sizeof Key, 1);
19900+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19901+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19902+
19903+
ret = wc_XChaCha20Poly1305_Init(&aead, AAD, sizeof AAD,
19904+
IV, sizeof IV,
19905+
NULL, sizeof Key, 1);
19906+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19907+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19908+
19909+
/* Wrong nonce size (12 instead of 24) */
19910+
ret = wc_XChaCha20Poly1305_Init(&aead, AAD, sizeof AAD,
19911+
IV, CHACHA20_POLY1305_AEAD_IV_SIZE,
19912+
Key, sizeof Key, 1);
19913+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19914+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19915+
19916+
/* Wrong key size (16 instead of 32) */
19917+
ret = wc_XChaCha20Poly1305_Init(&aead, AAD, sizeof AAD,
19918+
IV, sizeof IV,
19919+
Key, 16, 1);
19920+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19921+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19922+
19923+
/* Test wc_XChaCha20Poly1305_Encrypt bad parameters */
19924+
ret = wc_XChaCha20Poly1305_Encrypt(NULL, sizeof Ciphertext + sizeof Tag,
19925+
Plaintext, sizeof Plaintext,
19926+
AAD, sizeof AAD,
19927+
IV, sizeof IV,
19928+
Key, sizeof Key);
19929+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19930+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19931+
19932+
ret = wc_XChaCha20Poly1305_Encrypt(buf1, sizeof Ciphertext + sizeof Tag,
19933+
NULL, sizeof Plaintext,
19934+
AAD, sizeof AAD,
19935+
IV, sizeof IV,
19936+
Key, sizeof Key);
19937+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19938+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19939+
19940+
ret = wc_XChaCha20Poly1305_Encrypt(buf1, sizeof Ciphertext + sizeof Tag,
19941+
Plaintext, sizeof Plaintext,
19942+
NULL, sizeof AAD,
19943+
IV, sizeof IV,
19944+
Key, sizeof Key);
19945+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19946+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19947+
19948+
ret = wc_XChaCha20Poly1305_Encrypt(buf1, sizeof Ciphertext + sizeof Tag,
19949+
Plaintext, sizeof Plaintext,
19950+
AAD, sizeof AAD,
19951+
NULL, sizeof IV,
19952+
Key, sizeof Key);
19953+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19954+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19955+
19956+
ret = wc_XChaCha20Poly1305_Encrypt(buf1, sizeof Ciphertext + sizeof Tag,
19957+
Plaintext, sizeof Plaintext,
19958+
AAD, sizeof AAD,
19959+
IV, sizeof IV,
19960+
NULL, sizeof Key);
19961+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19962+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19963+
19964+
/* Wrong nonce size (12 instead of 24) */
19965+
ret = wc_XChaCha20Poly1305_Encrypt(buf1, sizeof Ciphertext + sizeof Tag,
19966+
Plaintext, sizeof Plaintext,
19967+
AAD, sizeof AAD,
19968+
IV, CHACHA20_POLY1305_AEAD_IV_SIZE,
19969+
Key, sizeof Key);
19970+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19971+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19972+
19973+
/* Wrong key size (16 instead of 32) */
19974+
ret = wc_XChaCha20Poly1305_Encrypt(buf1, sizeof Ciphertext + sizeof Tag,
19975+
Plaintext, sizeof Plaintext,
19976+
AAD, sizeof AAD,
19977+
IV, sizeof IV,
19978+
Key, 16);
19979+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19980+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19981+
19982+
/* Insufficient buffer space */
19983+
ret = wc_XChaCha20Poly1305_Encrypt(buf1, sizeof Plaintext,
19984+
Plaintext, sizeof Plaintext,
19985+
AAD, sizeof AAD,
19986+
IV, sizeof IV,
19987+
Key, sizeof Key);
19988+
if (ret != WC_NO_ERR_TRACE(BUFFER_E))
19989+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19990+
19991+
/* Test wc_XChaCha20Poly1305_Decrypt bad parameters */
19992+
ret = wc_XChaCha20Poly1305_Decrypt(NULL, sizeof Plaintext,
19993+
buf1, sizeof Ciphertext + sizeof Tag,
19994+
AAD, sizeof AAD,
19995+
IV, sizeof IV,
19996+
Key, sizeof Key);
19997+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
19998+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
19999+
20000+
ret = wc_XChaCha20Poly1305_Decrypt(buf2, sizeof Plaintext,
20001+
NULL, sizeof Ciphertext + sizeof Tag,
20002+
AAD, sizeof AAD,
20003+
IV, sizeof IV,
20004+
Key, sizeof Key);
20005+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
20006+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
20007+
20008+
ret = wc_XChaCha20Poly1305_Decrypt(buf2, sizeof Plaintext,
20009+
buf1, sizeof Ciphertext + sizeof Tag,
20010+
NULL, sizeof AAD,
20011+
IV, sizeof IV,
20012+
Key, sizeof Key);
20013+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
20014+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
20015+
20016+
ret = wc_XChaCha20Poly1305_Decrypt(buf2, sizeof Plaintext,
20017+
buf1, sizeof Ciphertext + sizeof Tag,
20018+
AAD, sizeof AAD,
20019+
NULL, sizeof IV,
20020+
Key, sizeof Key);
20021+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
20022+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
20023+
20024+
ret = wc_XChaCha20Poly1305_Decrypt(buf2, sizeof Plaintext,
20025+
buf1, sizeof Ciphertext + sizeof Tag,
20026+
AAD, sizeof AAD,
20027+
IV, sizeof IV,
20028+
NULL, sizeof Key);
20029+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
20030+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
20031+
20032+
/* Wrong nonce size (12 instead of 24) */
20033+
ret = wc_XChaCha20Poly1305_Decrypt(buf2, sizeof Plaintext,
20034+
buf1, sizeof Ciphertext + sizeof Tag,
20035+
AAD, sizeof AAD,
20036+
IV, CHACHA20_POLY1305_AEAD_IV_SIZE,
20037+
Key, sizeof Key);
20038+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
20039+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
20040+
20041+
/* Wrong key size (16 instead of 32) */
20042+
ret = wc_XChaCha20Poly1305_Decrypt(buf2, sizeof Plaintext,
20043+
buf1, sizeof Ciphertext + sizeof Tag,
20044+
AAD, sizeof AAD,
20045+
IV, sizeof IV,
20046+
Key, 16);
20047+
if (ret != WC_NO_ERR_TRACE(BAD_FUNC_ARG))
20048+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
20049+
20050+
/* Insufficient buffer space */
20051+
ret = wc_XChaCha20Poly1305_Decrypt(buf2, sizeof Plaintext - 1,
20052+
buf1, sizeof Ciphertext + sizeof Tag,
20053+
AAD, sizeof AAD,
20054+
IV, sizeof IV,
20055+
Key, sizeof Key);
20056+
if (ret != WC_NO_ERR_TRACE(BUFFER_E))
20057+
ERROR_OUT(WC_TEST_RET_ENC_EC(ret), out);
20058+
20059+
ret = 0;
20060+
1988920061
out:
1989020062

1989120063
#if defined(WOLFSSL_SMALL_STACK) && !defined(WOLFSSL_NO_MALLOC)

0 commit comments

Comments
 (0)