Repository navigation
Conversation
`initialized_mac_test` and `reset_mac_test` now check that the `verify_*` method selected by `MacTruncSide` rejects the tag with its first byte changed and with its last byte changed. `initialized_mac_test` also verifies the correct tag once over the whole input, so inputs shorter than 2 bytes reach `verify_*` too. These checks exercise digest's shared tag verification against every crate's real vectors. A verification that compares only the first byte, only the last byte, or always returns Ok passes the current helpers and fails the new ones.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What it changes.
initialized_mac_testandreset_mac_testindigest/src/dev/mac.rs(used bynew_mac_test!) now also check that the matchingverify_*method rejects the tag with its first byte flipped, and with its last byte flipped.initialized_mac_testalso verifies the correct tag once over the whole input. Before this change, ininitialized_mac_testan input shorter than 2 bytes never reachedverify_*, because the chunk loop1..min(64, input.len())was empty (reset_mac_testalready verified through its "after reset" check). Two small private helpers (verify,check_wrong_tags) keep the new code short. No public API change and no allocation. One CHANGELOG line.What it tests, precisely. Every RustCrypto MAC gets
verify_slice/verify_truncated_left/verify_truncated_rightfrom the blanketMacimpl indigest/src/mac.rs, and the existing "whole message" check already compares the tag. So the new checks do not test MAC algorithms. They test digest's own shared verification: the comparison, including both ends of the compared range, for full and truncated tags. They run against every crate's real vectors, plus any future hand-writtenMacimpl. If you would rather have this as a direct unit test ofverify_*indigest/tests/, it can be reworked that way.Why. Three deliberately wrong versions of digest's verification pass the RustCrypto/MACs test suite today:
With this change, they fail with "wrong tag accepted". With the correct verification, everything still passes:
[patch.crates-io])blake2(default,reset, no-default, all features)cargo fmt --all --checkpasses, andcargo clippy -p digest --all-features --tests -D warningsis clean on stable. A trivial CHANGELOG conflict with #2477 is possible; both add a0.11.4 (UNRELEASED)section.Example acceptance file for this PR: acceptance.toml for hmac 0.13.0. It is the package where this gap was first found: the shipped hmac tests accept a verifier that compares only the first tag byte.
if youd rather not add any of the updates, we simply drop this PR.
disclamer: this pr is prepared by AI and is part of my wider campaignt to promote a format and protocol ive been developing: acceptance format. for now its shown use as a good internal tracking tool of semantic code coverage while also "testing" the test cases by giving only weight to test cases that can be shown to be able to fail. The goal of protocl is wider: a consumer-producer "contract" (legal,monetary not part of it) - you can see in the repo. i take responsibility for this PR and will answer review comments myself.
who i am: https://github.com/ivmat