Skip to content

Accept zero-length ciphertext in TSIP AES-GCM decrypt - #11679

Merged
philljj merged 2 commits into
wolfSSL:masterfrom
miyazakh:f13116_tsipzero
Oct 8, 2026
Merged

philljj merged 2 commits into
wolfSSL:masterfrom
miyazakh:f13116_tsipzero

Conversation

@miyazakh

@miyazakh miyazakh commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Description

wc_tsip_AesGcmDecrypt() rejected sz == 0, so AAD-only (GMAC) decrypt failed.
It now accepts a zero-length ciphertext and skips the zero-size buffer
allocation and copies, matching wc_tsip_AesGcmEncrypt().

Testing

Added zero-length decrypt cases to tsip_aesgcm_zerolen_test():

  • empty payload with AAD, round trip
  • corrupted tag must fail
  • empty payload and empty AAD, round trip

Verified on RX72N EnvisionKit (TSIP); all TSIP unit tests pass.

Checklist

  • added tests
  • updated/added doxygen
  • updated appropriate READMEs
  • Updated manual and documentation

 - Add zero-length decrypt cases to the RX72N TSIP unit test.
Copilot AI balanced review requested due to automatic review settings October 7, 2026 02:34
@miyazakh miyazakh self-assigned this Oct 7, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The new behavior is tested only with AES-128 despite using distinct TSIP AES-256 entry points.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Enables TSIP AES-GCM decryption for zero-length ciphertexts, supporting GMAC/AAD-only operations.

Changes:

  • Allows null input/output when ciphertext length is zero.
  • Avoids zero-size allocations and copies.
  • Adds round-trip and corrupted-tag tests.
File Description
wolfcrypt/​src/​port/​Renesas/​renesas_tsip_aes.c Handles zero-length TSIP AES-GCM decrypt input.
IDE/​Renesas/​e2studio/​RX72N/​EnvisionKit/​wolfssl_demo/​wolfssl_tsip_unit_test.c Adds zero-length AES-GCM regression cases.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

MemBrowse Memory Report

gcc-arm-cortex-m4-openssl-compat

  • FLASH: .text +128 B (+0.0%, 792,412 B / 1,048,576 B, total: 76% used)

gcc-arm-cortex-m4-pkcs7

  • FLASH: .text +64 B (+0.0%, 221,790 B / 262,144 B, total: 85% used)

gcc-arm-cortex-m4-pq

  • FLASH: .text +64 B (+0.0%, 308,656 B / 1,048,576 B, total: 29% used)

gcc-arm-cortex-m7

  • FLASH: .text +64 B (+0.0%, 207,852 B / 262,144 B, total: 79% used)

linuxkm-standard

@miyazakh miyazakh assigned wolfSSL-Bot and unassigned miyazakh Oct 8, 2026
@philljj philljj self-assigned this Oct 8, 2026
@philljj
philljj merged commit b81d604 into wolfSSL:master Oct 8, 2026
404 of 405 checks passed
@miyazakh
miyazakh deleted the f13116_tsipzero branch October 8, 2026 21:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants