Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
17 commits
Select commit Hold shift + click to select a range
bc8a9fa
Refactor wolfSSL_EVP_DigestUpdate into a chunked function so sizes ab…
kareem-wolfssl Aug 15, 2026
50c9ecb
Always use new key in wc_ecc_decrypt to avoid freeing passed in key. …
kareem-wolfssl Aug 15, 2026
878d558
Zero out the digest in SHA256/512 generation functions. (F-7135)
kareem-wolfssl Aug 15, 2026
07a5464
Zero out SRP user and key when overwriting them. (F-7400)
kareem-wolfssl Aug 15, 2026
bde5e2f
Use subtraction-based comparison in EVP fillBuff. (F-7446)
kareem-wolfssl Aug 15, 2026
b334acb
Correct decOidSz in wc_ecc_get_curve_id_from_oid. (F-7623)
kareem-wolfssl Aug 15, 2026
2343823
Avoid clamping in EncodeAttributes when attribute size exceeds capaci…
kareem-wolfssl Aug 15, 2026
3c54695
Clear hash in EVP_CIPHER_MD_CTX_copy_ex before all possible returns. …
kareem-wolfssl Aug 15, 2026
6851003
Correct size documentation for wc_AesCfb1Encrypt and wc_AesCfb1Decryp…
kareem-wolfssl Aug 15, 2026
208bf80
Code review feedback
kareem-wolfssl Aug 17, 2026
ec2e05c
Correct ordering of added EVP_DigestUpdate checks to match OpenSSL's …
kareem-wolfssl Aug 17, 2026
63bb10b
Fix failing test
kareem-wolfssl Aug 18, 2026
e1a0915
Code review feedback
kareem-wolfssl Aug 21, 2026
2f4ad07
Fix wc_PKCS7_EncodeContentStream for sizes above BER_OCTET_LENGTH
kareem-wolfssl Aug 22, 2026
2c0f460
Fix undersized buffers and incorrect read lengths for the file read c…
kareem-wolfssl Aug 28, 2026
3bfdf35
Avoid suppressing errors from wc_rng_bank_checkin in wc_rng_bank_rese…
kareem-wolfssl Oct 2, 2026
592c478
Code review feedback: Preserve error return code and continue running…
kareem-wolfssl Oct 2, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 8 additions & 5 deletions doc/dox_comments/header_files/ecc.h
Original file line number Diff line number Diff line change
Expand Up @@ -2267,9 +2267,9 @@ int wc_ecc_encrypt_ex(ecc_key* privKey, ecc_key* pubKey, const byte* msg,
the encryption type specified by ctx.

\return 0 Returned upon successfully decrypting the input message
\return BAD_FUNC_ARG Returned if privKey, pubKey, msg, msgSz, out,
or outSz are NULL, or the ctx object specifies an unsupported
encryption type
\return BAD_FUNC_ARG Returned if privKey, msg, msgSz, out, or outSz
are NULL (or pubKey is NULL when built with WOLFSSL_ECIES_OLD), or
the ctx object specifies an unsupported encryption type
\return BAD_ENC_STATE_E Returned if the ctx object given is in
a state that is not appropriate for decryption
\return BUFFER_E Returned if the supplied output buffer is too
Expand All @@ -2282,8 +2282,11 @@ int wc_ecc_encrypt_ex(ecc_key* privKey, ecc_key* pubKey, const byte* msg,

\param privKey pointer to the ecc_key object containing the private
key to use for decryption
\param pubKey pointer to the ecc_key object containing the public
key of the peer with whom one wishes to communicate
\param pubKey only used when built with WOLFSSL_ECIES_OLD: pointer to
the ecc_key object containing the public key of the peer with whom one
wishes to communicate. In the default message format the sender's
ephemeral public key is read from the start of msg instead and pubKey
is ignored (it may be NULL and is left unmodified)
\param msg pointer to the buffer holding the ciphertext to decrypt
\param msgSz size of the buffer to decrypt
\param out pointer to the buffer in which to store the decrypted plaintext
Expand Down
105 changes: 105 additions & 0 deletions tests/api/test_ecc.c
Original file line number Diff line number Diff line change
Expand Up @@ -2008,6 +2008,93 @@ int test_wc_ecc_encryptDecrypt(void)
return EXPECT_RESULT();
} /* END test_wc_ecc_encryptDecrypt */

/*
* In the default ECIES message format the sender's ephemeral public key is
* carried in the message, so wc_ecc_decrypt() must not free or overwrite a
* caller-supplied pubKey object. Confirm the object is byte-for-byte preserved
* across a decrypt.
*/
int test_wc_ecc_decrypt_pubkey_preserved(void)
{
EXPECT_DECLS;
#if defined(HAVE_ECC) && defined(HAVE_ECC_ENCRYPT) && !defined(WC_NO_RNG) && \
!defined(WOLFSSL_ECIES_OLD) && defined(HAVE_ECC_KEY_EXPORT) && \
defined(HAVE_ECC_KEY_IMPORT) && \
(defined(HAVE_AES_CBC) || \
(defined(HAVE_AESGCM) && (defined(WOLFSSL_ECIES_GEN_IV) || \
defined(WOLFSSL_ECIES_STATIC_GCM_NONCE)))) && defined(WOLFSSL_AES_128)
ecc_key cliKey;
ecc_key srvKey;
ecc_key pubKey;
WC_RNG rng;
const char* msg = "EccBlock Size 16";
word32 msgSz = (word32)XSTRLEN("EccBlock Size 16");
#ifdef WOLFSSL_ECIES_GEN_IV
/* GEN_IV mode carries the nonce in the message as well */
byte out[KEY20 * 2 + 1 + AES_BLOCK_SIZE +
(sizeof("EccBlock Size 16") - 1) + WC_SHA256_DIGEST_SIZE];
#else
byte out[KEY20 * 2 + 1 + (sizeof("EccBlock Size 16") - 1) +
WC_SHA256_DIGEST_SIZE];
#endif
word32 outSz = (word32)sizeof(out);
byte plain[sizeof("EccBlock Size 16")];
word32 plainSz = (word32)sizeof(plain);
byte before[ECC_BUFSIZE];
byte after[ECC_BUFSIZE];
word32 beforeSz = (word32)sizeof(before);
word32 afterSz = (word32)sizeof(after);

XMEMSET(&rng, 0, sizeof(rng));
XMEMSET(&cliKey, 0, sizeof(cliKey));
XMEMSET(&srvKey, 0, sizeof(srvKey));
XMEMSET(&pubKey, 0, sizeof(pubKey));

ExpectIntEQ(wc_InitRng(&rng), 0);
ExpectIntEQ(wc_ecc_init(&cliKey), 0);
ExpectIntEQ(wc_ecc_make_key(&rng, KEY20, &cliKey), 0);
ExpectIntEQ(wc_ecc_init(&srvKey), 0);
ExpectIntEQ(wc_ecc_make_key(&rng, KEY20, &srvKey), 0);
ExpectIntEQ(wc_ecc_init(&pubKey), 0);
/* Load a public key distinct from the sender's ephemeral (embedded in the
* message) so that overwriting pubKey would be detectable. */
ExpectIntEQ(wc_ecc_export_x963(&srvKey, before, &beforeSz), 0);
ExpectIntEQ(wc_ecc_import_x963(before, beforeSz, &pubKey), 0);

#if defined(ECC_TIMING_RESISTANT) && (!defined(HAVE_FIPS) || \
(!defined(HAVE_FIPS_VERSION) || (HAVE_FIPS_VERSION != 2))) && \
!defined(HAVE_SELFTEST)
ExpectIntEQ(wc_ecc_set_rng(&srvKey, &rng), 0);
ExpectIntEQ(wc_ecc_set_rng(&cliKey, &rng), 0);
#endif

ExpectIntEQ(wc_ecc_encrypt(&cliKey, &srvKey, (byte*)msg, msgSz, out,
&outSz, NULL), 0);
ExpectIntEQ(wc_ecc_decrypt(&srvKey, &pubKey, out, outSz, plain, &plainSz,
NULL), 0);
ExpectIntEQ(XMEMCMP(msg, plain, msgSz), 0);

/* the caller's pubKey object must be unchanged after the decrypt */
ExpectIntEQ(wc_ecc_export_x963(&pubKey, after, &afterSz), 0);
ExpectIntEQ(afterSz, beforeSz);
ExpectIntEQ(XMEMCMP(before, after, beforeSz), 0);

/* pubKey is optional in this format: NULL must decrypt too */
XMEMSET(plain, 0, sizeof(plain));
plainSz = (word32)sizeof(plain);
ExpectIntEQ(wc_ecc_decrypt(&srvKey, NULL, out, outSz, plain, &plainSz,
NULL), 0);
ExpectIntEQ(plainSz, msgSz);
ExpectIntEQ(XMEMCMP(msg, plain, msgSz), 0);

wc_ecc_free(&pubKey);
wc_ecc_free(&srvKey);
wc_ecc_free(&cliKey);
DoExpectIntEQ(wc_FreeRng(&rng), 0);
#endif
return EXPECT_RESULT();
} /* END test_wc_ecc_decrypt_pubkey_preserved */

/*
* Testing ECIES with the AES-256-GCM DEM. Exercises, each with its own
* single-use client/server ctx pair:
Expand Down Expand Up @@ -3318,6 +3405,24 @@ int test_wc_ecc_get_curve_id_from_oid(void)
ExpectIntEQ(wc_ecc_get_curve_id_from_oid(oid, 0), ECC_CURVE_INVALID);
/* Good Case */
ExpectIntEQ(wc_ecc_get_curve_id_from_oid(oid, len), ECC_SECP256R1);

#ifdef HAVE_OID_DECODING
{
/* Length must stay just over the array's element capacity but under
* MAX_OID_SZ, or a byte-sized limit would also accept it. */
#define ECC_OID_ELEMS (MAX_OID_SZ / (int)sizeof(word16))
byte longOid[ECC_OID_ELEMS + 3];
word32 i;

longOid[0] = 0x2A; /* two arcs */
for (i = 1; i < (word32)sizeof(longOid); i++)
longOid[i] = 0x01; /* one arc each */

ExpectIntEQ(wc_ecc_get_curve_id_from_oid(longOid, sizeof(longOid)),
WC_NO_ERR_TRACE(BUFFER_E));
#undef ECC_OID_ELEMS
}
#endif
#endif
return EXPECT_RESULT();
} /* END test_wc_ecc_get_curve_id_from_oid */
Expand Down
2 changes: 2 additions & 0 deletions tests/api/test_ecc.h
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,7 @@ int test_wc_ecc_ctx_set_peer_salt(void);
int test_wc_ecc_ctx_set_info(void);
int test_wc_ecc_ctx_getters(void);
int test_wc_ecc_encryptDecrypt(void);
int test_wc_ecc_decrypt_pubkey_preserved(void);
int test_wc_ecc_ecies_gcm(void);
int test_wc_ecc_ecies_gcm_no_rng(void);
int test_wc_ecc_ecies_cryptocb(void);
Expand Down Expand Up @@ -109,6 +110,7 @@ int test_wc_EccDecisionCoverage4(void);
TEST_DECL_GROUP("ecc", test_wc_ecc_ctx_set_info), \
TEST_DECL_GROUP("ecc", test_wc_ecc_ctx_getters), \
TEST_DECL_GROUP("ecc", test_wc_ecc_encryptDecrypt), \
TEST_DECL_GROUP("ecc", test_wc_ecc_decrypt_pubkey_preserved), \
TEST_DECL_GROUP("ecc", test_wc_ecc_ecies_gcm), \
TEST_DECL_GROUP("ecc", test_wc_ecc_ecies_gcm_no_rng), \
TEST_DECL_GROUP("ecc", test_wc_ecc_ecies_cryptocb), \
Expand Down
9 changes: 4 additions & 5 deletions tests/api/test_ossl_p7p12.c
Original file line number Diff line number Diff line change
Expand Up @@ -1045,25 +1045,24 @@ int test_wolfSSL_PEM_write_bio_PKCS7(void)
XMEMCPY(key, client_key_der_1024, keySz);
XMEMCPY(cert, client_cert_der_1024, certSz);
#else
unsigned char cert[ONEK_BUF];
/* cert file is larger than ONEK_BUF */
unsigned char cert[TWOK_BUF];
unsigned char key[ONEK_BUF];
XFILE fp = XBADFILE;
int certSz;
int keySz;

ExpectTrue((fp = XFOPEN("./certs/1024/client-cert.der", "rb")) !=
XBADFILE);
ExpectIntGT(certSz = (int)XFREAD(cert, 1, sizeof_client_cert_der_1024,
fp), 0);
ExpectIntGT(certSz = (int)XFREAD(cert, 1, sizeof(cert), fp), 0);
if (fp != XBADFILE) {
XFCLOSE(fp);
fp = XBADFILE;
}

ExpectTrue((fp = XFOPEN("./certs/1024/client-key.der", "rb")) !=
XBADFILE);
ExpectIntGT(keySz = (int)XFREAD(key, 1, sizeof_client_key_der_1024, fp),
0);
ExpectIntGT(keySz = (int)XFREAD(key, 1, sizeof(key), fp), 0);
if (fp != XBADFILE) {
XFCLOSE(fp);
fp = XBADFILE;
Expand Down
Loading
Loading