From fe42b5d9d6d00b2bd285a6d8a0cd55cf17982b7d Mon Sep 17 00:00:00 2001 From: Robin Krahl Date: Tue, 2 Jun 2026 12:41:45 +0200 Subject: [PATCH] Add test for invalid key size for AEAD mechanisms This patch adds a test for the panic on an invalid key size for AEAD mechanisms that was reported by @MG3004 in GHSA-32mp-78p5-q55v and fixed in #224. --- Cargo.toml | 4 ++++ tests/aead.rs | 25 +++++++++++++++++++++++++ 2 files changed, 29 insertions(+) create mode 100644 tests/aead.rs diff --git a/Cargo.toml b/Cargo.toml index 764ccb84724..b76f92a6fe4 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -157,6 +157,10 @@ ui-client = ["trussed-core/ui-client"] test-attestation-cert-ids = [] test-increased-interchange-size = [] +[[test]] +name = "aead" +required-features = ["crypto-client", "virt"] + [[test]] name = "aes256cbc" required-features = ["crypto-client", "default-mechanisms", "virt"] diff --git a/tests/aead.rs b/tests/aead.rs new file mode 100644 index 00000000000..f775d0cd6fa --- /dev/null +++ b/tests/aead.rs @@ -0,0 +1,25 @@ +use trussed_core::{ + syscall, try_syscall, + types::{Location, Mechanism}, + CryptoClient, Error, +}; + +mod client; + +const MECHANISMS: &[Mechanism] = &[ + #[cfg(feature = "chacha8-poly1305")] + Mechanism::Chacha8Poly1305, + #[cfg(feature = "aes256-gcm")] + Mechanism::Aes256Gcm, +]; + +#[test] +fn test_invalid_key_size() { + client::get(|client| { + for mechanism in MECHANISMS { + let key = syscall!(client.generate_secret_key(16, Location::Volatile)).key; + let result = try_syscall!(client.encrypt(*mechanism, key, &[], &[], None)); + assert_eq!(result, Err(Error::WrongKeyKind)); + } + }); +}