Skip to content

digest: MAC test helpers also check that a wrong tag is rejected - #2496

Open
ivmat wants to merge 1 commit into
RustCrypto:masterfrom
ivmat:dev-mac-test-reject-wrong-tag
Open

ivmat wants to merge 1 commit into
RustCrypto:masterfrom
ivmat:dev-mac-test-reject-wrong-tag

Conversation

@ivmat

@ivmat ivmat commented Oct 9, 2026

Copy link
Copy Markdown

What it changes. initialized_mac_test and reset_mac_test in digest/src/dev/mac.rs (used by new_mac_test!) now also check that the matching verify_* method rejects the tag with its first byte flipped, and with its last byte flipped. initialized_mac_test also verifies the correct tag once over the whole input. Before this change, in initialized_mac_test an input shorter than 2 bytes never reached verify_*, because the chunk loop 1..min(64, input.len()) was empty (reset_mac_test already verified through its "after reset" check). Two small private helpers (verify, check_wrong_tags) keep the new code short. No public API change and no allocation. One CHANGELOG line.

What it tests, precisely. Every RustCrypto MAC gets verify_slice / verify_truncated_left / verify_truncated_right from the blanket Mac impl in digest/src/mac.rs, and the existing "whole message" check already compares the tag. So the new checks do not test MAC algorithms. They test digest's own shared verification: the comparison, including both ends of the compared range, for full and truncated tags. They run against every crate's real vectors, plus any future hand-written Mac impl. If you would rather have this as a direct unit test of verify_* in digest/tests/, it can be reworked that way.

Why. Three deliberately wrong versions of digest's verification pass the RustCrypto/MACs test suite today:

  • compare only the first byte;
  • compare only the last byte;
  • always return Ok.

With this change, they fail with "wrong tag accepted". With the correct verification, everything still passes:

Suite (against the patched digest via [patch.crates-io]) Result
RustCrypto/MACs workspace (belt-mac, cmac, hmac ×4, pmac, cbc-mac, retail-mac), default and all features 38 passed
RustCrypto/hashes blake2 (default, reset, no-default, all features) 12 passed each
RustCrypto/hashes workspace, all features 231 passed
MACs PR #268 (GMAC) and PR #221 (KMAC) unchanged (52 and 58 passed)

cargo fmt --all --check passes, and cargo clippy -p digest --all-features --tests -D warnings is clean on stable. A trivial CHANGELOG conflict with #2477 is possible; both add a 0.11.4 (UNRELEASED) section.

Example acceptance file for this PR: acceptance.toml for hmac 0.13.0. It is the package where this gap was first found: the shipped hmac tests accept a verifier that compares only the first tag byte.


if youd rather not add any of the updates, we simply drop this PR.

disclamer: this pr is prepared by AI and is part of my wider campaignt to promote a format and protocol ive been developing: acceptance format. for now its shown use as a good internal tracking tool of semantic code coverage while also "testing" the test cases by giving only weight to test cases that can be shown to be able to fail. The goal of protocl is wider: a consumer-producer "contract" (legal,monetary not part of it) - you can see in the repo. i take responsibility for this PR and will answer review comments myself.

who i am: https://github.com/ivmat

`initialized_mac_test` and `reset_mac_test` now check that the `verify_*`
method selected by `MacTruncSide` rejects the tag with its first byte
changed and with its last byte changed. `initialized_mac_test` also
verifies the correct tag once over the whole input, so inputs shorter
than 2 bytes reach `verify_*` too.

These checks exercise digest's shared tag verification against every
crate's real vectors. A verification that compares only the first byte,
only the last byte, or always returns Ok passes the current helpers and
fails the new ones.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant