2017-07-14 23:22:15 +02:00
|
|
|
// +build !without_openssl
|
|
|
|
|
2016-05-04 22:34:52 +02:00
|
|
|
// We compare against Go's built-in GCM implementation. Since stupidgcm only
|
|
|
|
// supports 128-bit IVs and Go only supports that from 1.5 onward, we cannot
|
|
|
|
// run these tests on older Go versions.
|
2016-05-01 22:26:47 +02:00
|
|
|
package stupidgcm
|
|
|
|
|
|
|
|
import (
|
|
|
|
"bytes"
|
|
|
|
"crypto/aes"
|
|
|
|
"crypto/cipher"
|
|
|
|
"crypto/rand"
|
|
|
|
"encoding/hex"
|
2016-12-10 11:50:16 +01:00
|
|
|
"log"
|
2016-05-01 22:26:47 +02:00
|
|
|
"testing"
|
|
|
|
)
|
|
|
|
|
|
|
|
// Get "n" random bytes from /dev/urandom or panic
|
|
|
|
func randBytes(n int) []byte {
|
|
|
|
b := make([]byte, n)
|
|
|
|
_, err := rand.Read(b)
|
|
|
|
if err != nil {
|
2016-12-10 11:50:16 +01:00
|
|
|
log.Panic("Failed to read random bytes: " + err.Error())
|
2016-05-01 22:26:47 +02:00
|
|
|
}
|
|
|
|
return b
|
|
|
|
}
|
|
|
|
|
|
|
|
// TestEncryptDecrypt encrypts and decrypts using both stupidgcm and Go's built-in
|
|
|
|
// GCM implemenatation and verifies that the results are identical.
|
|
|
|
func TestEncryptDecrypt(t *testing.T) {
|
|
|
|
key := randBytes(32)
|
2017-04-08 02:09:28 +02:00
|
|
|
sGCM := New(key, false)
|
2016-05-01 22:26:47 +02:00
|
|
|
authData := randBytes(24)
|
|
|
|
iv := randBytes(16)
|
|
|
|
dst := make([]byte, 71) // 71 = random length
|
|
|
|
|
|
|
|
gAES, err := aes.NewCipher(key)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
gGCM, err := cipher.NewGCMWithNonceSize(gAES, 16)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Check all block sizes from 1 to 5000
|
|
|
|
for i := 1; i < 5000; i++ {
|
|
|
|
in := make([]byte, i)
|
|
|
|
|
|
|
|
sOut := sGCM.Seal(dst, iv, in, authData)
|
|
|
|
gOut := gGCM.Seal(dst, iv, in, authData)
|
|
|
|
|
|
|
|
// Ciphertext must be identical to Go GCM
|
2016-09-25 19:48:21 +02:00
|
|
|
if !bytes.Equal(sOut, gOut) {
|
2016-05-01 22:26:47 +02:00
|
|
|
t.Fatalf("Compare failed for encryption, size %d", i)
|
|
|
|
t.Log("sOut:")
|
|
|
|
t.Log("\n" + hex.Dump(sOut))
|
|
|
|
t.Log("gOut:")
|
|
|
|
t.Log("\n" + hex.Dump(gOut))
|
|
|
|
}
|
|
|
|
|
|
|
|
sOut2, sErr := sGCM.Open(dst, iv, sOut[len(dst):], authData)
|
|
|
|
if sErr != nil {
|
|
|
|
t.Fatal(sErr)
|
|
|
|
}
|
|
|
|
gOut2, gErr := gGCM.Open(dst, iv, gOut[len(dst):], authData)
|
|
|
|
if gErr != nil {
|
|
|
|
t.Fatal(gErr)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Plaintext must be identical to Go GCM
|
2016-09-25 19:48:21 +02:00
|
|
|
if !bytes.Equal(sOut2, gOut2) {
|
2016-05-01 22:26:47 +02:00
|
|
|
t.Fatalf("Compare failed for decryption, size %d", i)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2017-06-29 18:52:33 +02:00
|
|
|
// Seal re-uses the "dst" buffer it is large enough.
|
|
|
|
// Check that this works correctly by testing different "dst" capacities from
|
|
|
|
// 5000 to 16 and "in" lengths from 1 to 5000.
|
|
|
|
func TestInplaceSeal(t *testing.T) {
|
|
|
|
key := randBytes(32)
|
|
|
|
sGCM := New(key, false)
|
|
|
|
authData := randBytes(24)
|
|
|
|
iv := randBytes(16)
|
|
|
|
|
|
|
|
gAES, err := aes.NewCipher(key)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
gGCM, err := cipher.NewGCMWithNonceSize(gAES, 16)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
max := 5016
|
|
|
|
// Check all block sizes from 1 to 5000
|
|
|
|
for i := 1; i < max-16; i++ {
|
|
|
|
in := make([]byte, i)
|
|
|
|
dst := make([]byte, max-i)
|
|
|
|
dst = dst[:16]
|
|
|
|
|
|
|
|
sOut := sGCM.Seal(dst, iv, in, authData)
|
|
|
|
dst2 := make([]byte, 16)
|
|
|
|
gOut := gGCM.Seal(dst2, iv, in, authData)
|
|
|
|
|
|
|
|
// Ciphertext must be identical to Go GCM
|
|
|
|
if !bytes.Equal(sOut, gOut) {
|
|
|
|
t.Fatalf("Compare failed for encryption, size %d", i)
|
|
|
|
t.Log("sOut:")
|
|
|
|
t.Log("\n" + hex.Dump(sOut))
|
|
|
|
t.Log("gOut:")
|
|
|
|
t.Log("\n" + hex.Dump(gOut))
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2017-06-30 23:24:12 +02:00
|
|
|
// Open re-uses the "dst" buffer it is large enough.
|
|
|
|
// Check that this works correctly by testing different "dst" capacities from
|
|
|
|
// 5000 to 16 and "in" lengths from 1 to 5000.
|
|
|
|
func TestInplaceOpen(t *testing.T) {
|
2017-07-01 09:55:14 +02:00
|
|
|
key := randBytes(32)
|
|
|
|
sGCM := New(key, false)
|
|
|
|
authData := randBytes(24)
|
|
|
|
iv := randBytes(16)
|
|
|
|
|
|
|
|
gAES, err := aes.NewCipher(key)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
gGCM, err := cipher.NewGCMWithNonceSize(gAES, 16)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
max := 5016
|
|
|
|
// Check all block sizes from 1 to 5000
|
|
|
|
for i := 1; i < max-16; i++ {
|
|
|
|
in := make([]byte, i)
|
|
|
|
|
|
|
|
gCiphertext := gGCM.Seal(iv, iv, in, authData)
|
|
|
|
|
|
|
|
dst := make([]byte, max-i)
|
|
|
|
// sPlaintext ... stupidgcm plaintext
|
|
|
|
sPlaintext, err := sGCM.Open(dst[:0], iv, gCiphertext[16:], authData)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Plaintext must be identical to Go GCM
|
|
|
|
if !bytes.Equal(in, sPlaintext) {
|
|
|
|
t.Fatalf("Compare failed, i=%d", i)
|
|
|
|
}
|
|
|
|
}
|
2017-06-30 23:24:12 +02:00
|
|
|
}
|
|
|
|
|
2016-05-01 22:26:47 +02:00
|
|
|
// TestCorruption verifies that changes in the ciphertext result in a decryption
|
|
|
|
// error
|
|
|
|
func TestCorruption(t *testing.T) {
|
|
|
|
key := randBytes(32)
|
2017-04-08 02:09:28 +02:00
|
|
|
sGCM := New(key, false)
|
2016-05-01 22:26:47 +02:00
|
|
|
authData := randBytes(24)
|
|
|
|
iv := randBytes(16)
|
|
|
|
|
|
|
|
in := make([]byte, 354)
|
|
|
|
sOut := sGCM.Seal(nil, iv, in, authData)
|
|
|
|
sOut2, sErr := sGCM.Open(nil, iv, sOut, authData)
|
|
|
|
if sErr != nil {
|
|
|
|
t.Fatal(sErr)
|
|
|
|
}
|
2016-09-25 19:48:21 +02:00
|
|
|
if !bytes.Equal(in, sOut2) {
|
2016-05-01 22:26:47 +02:00
|
|
|
t.Fatalf("Compare failed")
|
|
|
|
}
|
|
|
|
|
|
|
|
// Corrupt first byte
|
|
|
|
sOut[0]++
|
|
|
|
sOut2, sErr = sGCM.Open(nil, iv, sOut, authData)
|
|
|
|
if sErr == nil || sOut2 != nil {
|
|
|
|
t.Fatalf("Should have gotten error")
|
|
|
|
}
|
|
|
|
sOut[0]--
|
|
|
|
|
|
|
|
// Corrupt last byte
|
|
|
|
sOut[len(sOut)-1]++
|
|
|
|
sOut2, sErr = sGCM.Open(nil, iv, sOut, authData)
|
|
|
|
if sErr == nil || sOut2 != nil {
|
|
|
|
t.Fatalf("Should have gotten error")
|
|
|
|
}
|
|
|
|
sOut[len(sOut)-1]--
|
|
|
|
|
|
|
|
// Append one byte
|
|
|
|
sOut = append(sOut, 0)
|
|
|
|
sOut2, sErr = sGCM.Open(nil, iv, sOut, authData)
|
|
|
|
if sErr == nil || sOut2 != nil {
|
|
|
|
t.Fatalf("Should have gotten error")
|
|
|
|
}
|
|
|
|
}
|