mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-28 19:37:32 +09:00
re-introduce old nss im too tired for this
This commit is contained in:
parent
3c46be320d
commit
3a838106b9
2871 changed files with 1374431 additions and 1762417 deletions
|
|
@ -1,5 +1,4 @@
|
|||
/* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */
|
||||
/* vim: set ts=2 et sw=2 tw=80: */
|
||||
/* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this file,
|
||||
* You can obtain one at http://mozilla.org/MPL/2.0/. */
|
||||
|
|
@ -14,69 +13,58 @@
|
|||
#include "util.h"
|
||||
|
||||
namespace nss_test {
|
||||
class Pkcs11SeedTest : public ::testing::Test {
|
||||
class Pkcs11SeedCbcTest : public ::testing::Test {
|
||||
protected:
|
||||
void EncryptDecryptSeed(SECStatus expected, unsigned int input_size,
|
||||
unsigned int output_size,
|
||||
CK_MECHANISM_TYPE mech = CKM_SEED_CBC) {
|
||||
enum class Action { Encrypt, Decrypt };
|
||||
|
||||
SECStatus EncryptDecryptSeed(Action action, unsigned int input_size,
|
||||
unsigned int output_size) {
|
||||
// Generate a random key.
|
||||
ScopedPK11SlotInfo slot(PK11_GetInternalSlot());
|
||||
ScopedPK11SymKey sym_key(
|
||||
PK11_KeyGen(slot.get(), mech, nullptr, 16, nullptr));
|
||||
PK11_KeyGen(slot.get(), kMech, nullptr, 16, nullptr));
|
||||
EXPECT_TRUE(!!sym_key);
|
||||
|
||||
std::vector<uint8_t> plaintext(input_size, 0xFF);
|
||||
std::vector<uint8_t> data(input_size);
|
||||
std::vector<uint8_t> init_vector(16);
|
||||
std::vector<uint8_t> ciphertext(output_size, 0);
|
||||
SECItem iv_param = {siBuffer, init_vector.data(),
|
||||
(unsigned int)init_vector.size()};
|
||||
std::vector<uint8_t> decrypted(output_size, 0);
|
||||
std::vector<uint8_t> output(output_size);
|
||||
SECItem params = {siBuffer, init_vector.data(),
|
||||
(unsigned int)init_vector.size()};
|
||||
|
||||
// Try to encrypt, decrypt if positive test.
|
||||
// Try to encrypt/decrypt.
|
||||
unsigned int output_len = 0;
|
||||
EXPECT_EQ(expected,
|
||||
PK11_Encrypt(sym_key.get(), mech, &iv_param, ciphertext.data(),
|
||||
&output_len, output_size, plaintext.data(),
|
||||
plaintext.size()));
|
||||
|
||||
if (expected == SECSuccess) {
|
||||
EXPECT_EQ(expected,
|
||||
PK11_Decrypt(sym_key.get(), mech, &iv_param, decrypted.data(),
|
||||
&output_len, output_size, ciphertext.data(),
|
||||
output_len));
|
||||
decrypted.resize(output_len);
|
||||
EXPECT_EQ(plaintext, decrypted);
|
||||
if (action == Action::Encrypt) {
|
||||
return PK11_Encrypt(sym_key.get(), kMech, ¶ms, output.data(),
|
||||
&output_len, output_size, data.data(), data.size());
|
||||
} else {
|
||||
return PK11_Decrypt(sym_key.get(), kMech, ¶ms, output.data(),
|
||||
&output_len, output_size, data.data(), data.size());
|
||||
}
|
||||
}
|
||||
const CK_MECHANISM_TYPE kMech = CKM_SEED_CBC;
|
||||
};
|
||||
|
||||
#ifndef NSS_DISABLE_DEPRECATED_SEED
|
||||
// The intention here is to test the arguments of these functions
|
||||
// The resulted content is already tested in EncryptDeriveTests.
|
||||
// SEED_CBC needs an IV of 16 bytes.
|
||||
// The input data size must be multiple of 16.
|
||||
// If not, some padding should be added.
|
||||
// The output size must be at least the size of input data.
|
||||
TEST_F(Pkcs11SeedTest, CBC_ValidArgs) {
|
||||
EncryptDecryptSeed(SECSuccess, 16, 16);
|
||||
TEST_F(Pkcs11SeedCbcTest, SeedCBC_ValidArgs) {
|
||||
EXPECT_EQ(SECSuccess, EncryptDecryptSeed(Action::Encrypt, 16, 16));
|
||||
EXPECT_EQ(SECSuccess, EncryptDecryptSeed(Action::Decrypt, 16, 16));
|
||||
// No problem if maxLen is bigger than input data.
|
||||
EncryptDecryptSeed(SECSuccess, 16, 32);
|
||||
EXPECT_EQ(SECSuccess, EncryptDecryptSeed(Action::Encrypt, 16, 32));
|
||||
EXPECT_EQ(SECSuccess, EncryptDecryptSeed(Action::Decrypt, 16, 32));
|
||||
}
|
||||
|
||||
TEST_F(Pkcs11SeedTest, CBC_InvalidArgs) {
|
||||
TEST_F(Pkcs11SeedCbcTest, SeedCBC_InvalidArgs) {
|
||||
// maxLen lower than input data.
|
||||
EncryptDecryptSeed(SECFailure, 16, 10);
|
||||
EXPECT_EQ(SECFailure, EncryptDecryptSeed(Action::Encrypt, 16, 10));
|
||||
EXPECT_EQ(SECFailure, EncryptDecryptSeed(Action::Decrypt, 16, 10));
|
||||
// input data not multiple of SEED_BLOCK_SIZE (16)
|
||||
EncryptDecryptSeed(SECFailure, 17, 32);
|
||||
EXPECT_EQ(SECFailure, EncryptDecryptSeed(Action::Encrypt, 17, 32));
|
||||
EXPECT_EQ(SECFailure, EncryptDecryptSeed(Action::Decrypt, 17, 32));
|
||||
}
|
||||
|
||||
TEST_F(Pkcs11SeedTest, ECB_Singleblock) {
|
||||
EncryptDecryptSeed(SECSuccess, 16, 16, CKM_SEED_ECB);
|
||||
}
|
||||
|
||||
TEST_F(Pkcs11SeedTest, ECB_Multiblock) {
|
||||
EncryptDecryptSeed(SECSuccess, 64, 64, CKM_SEED_ECB);
|
||||
}
|
||||
#endif
|
||||
|
||||
} // namespace nss_test
|
||||
} // namespace nss_test
|
||||
Loading…
Add table
Add a link
Reference in a new issue