Start porting box_easy test

This doesn't have the same output as you'd find at:

https://github.com/jedisct1/libsodium/blob/master/test/default/box_easy.exp

I don't know why, but I'm confident that I'm doing something wrong. I'm
very concerned about why my test has `c` with a length of 146 (which is
the length of the message plus 16 bytes for the HMAC) but the original
test has an *extra* 16 bytes... for another HMAC? I don't know.
This commit is contained in:
Christian Bundy 2020-08-28 15:27:29 -07:00
parent 2e9a73a0cf
commit f36deb3334
2 changed files with 137 additions and 7 deletions

View File

@ -36,7 +36,8 @@ module.exports = {
crypto_box_BOXZEROBYTES,
crypto_box_SEALBYTES,
crypto_box_SEEDBYTES,
crypto_box_BEFORENMBYTES
crypto_box_BEFORENMBYTES,
crypto_box_MACBYTES
}
function crypto_box_keypair (pk, sk) {
@ -124,7 +125,9 @@ function crypto_box_beforenm (k, pk, sk) {
return -1
}
return xsalsa20.core_hsalsa20(k, zero, s, null)
xsalsa20.core_hsalsa20(k, zero, s, xsalsa20.SIGMA)
return 0
}
// int
@ -167,6 +170,8 @@ function crypto_box_detached (c, mac, m, n, pk, sk) {
return -1
}
cleanup(k)
return crypto_box_detached_afternm(c, mac, m, n, k)
}
@ -182,9 +187,12 @@ function crypto_box_detached (c, mac, m, n, pk, sk) {
// pk, sk);
// }
function crypto_box_easy (c, m, n, pk, sk) {
assert(c.length <= crypto_box_MESSAGEBYTES_MAX, "m should not be more than 'crypto_box_MESSAGEBYTESMAX' bytes")
assert(c.length === m.length + crypto_box_MACBYTES, "c should be a buffer of length 'm.length + crypto_box_MACBYTES'")
console.log({ c, m, crypto_box_MACBYTES })
console.log('yep')
assert(c.byteLength <= crypto_box_MESSAGEBYTES_MAX, "m should not be more than 'crypto_box_MESSAGEBYTES_MAX' bytes")
return crypto_box_detached(c + crypto_box_MACBYTES, c, m, n, pk, sk)
return crypto_box_detached(c.subarray(crypto_box_MACBYTES), c.subarray(0, crypto_box_MACBYTES), m, n, pk, sk)
}
// int
// crypto_box_open_detached_afternm(unsigned char *m, const unsigned char *c,
@ -228,6 +236,8 @@ function crypto_box_open_detached (m, c, mac, n, pk, sk) {
return -1
}
cleanup(k)
return crypto_box_open_detached_afternm(m, c, mac, n, k)
}
@ -244,7 +254,6 @@ function crypto_box_open_detached (m, c, mac, n, pk, sk) {
// n, pk, sk);
// }
function crypto_box_open_easy (m, c, n, pk, sk) {
check(m, crypto_box_MACBYTES)
check(n, crypto_box_NONCEBYTES)
check(pk, crypto_box_PUBLICKEYBYTES)
check(sk, crypto_box_SECRETKEYBYTES)
@ -252,8 +261,7 @@ function crypto_box_open_easy (m, c, n, pk, sk) {
if (c.length < crypto_box_MACBYTES) {
return -1
}
return crypto_box_open_detached(m, c + crypto_box_MACBYTES, c, n, pk, sk)
return crypto_box_open_detached(m, c.subarray(crypto_box_MACBYTES), n, pk, sk)
}
function check (buf, len) {

122
test_box_easy.js Normal file
View File

@ -0,0 +1,122 @@
/* eslint-disable camelcase */
const { crypto_box_easy, crypto_box_MACBYTES } = require('./crypto_box')
// static unsigned char alicesk[32] = { 0x77, 0x07, 0x6d, 0x0a, 0x73, 0x18, 0xa5,
// 0x7d, 0x3c, 0x16, 0xc1, 0x72, 0x51, 0xb2,
// 0x66, 0x45, 0xdf, 0x4c, 0x2f, 0x87, 0xeb,
// 0xc0, 0x99, 0x2a, 0xb1, 0x77, 0xfb, 0xa5,
// 0x1d, 0xb9, 0x2c, 0x2a };
//
const alicesk = new Uint8Array([
0x77, 0x07, 0x6d, 0x0a, 0x73, 0x18, 0xa5,
0x7d, 0x3c, 0x16, 0xc1, 0x72, 0x51, 0xb2,
0x66, 0x45, 0xdf, 0x4c, 0x2f, 0x87, 0xeb,
0xc0, 0x99, 0x2a, 0xb1, 0x77, 0xfb, 0xa5,
0x1d, 0xb9, 0x2c, 0x2a
])
// static unsigned char bobpk[32] = { 0xde, 0x9e, 0xdb, 0x7d, 0x7b, 0x7d, 0xc1,
// 0xb4, 0xd3, 0x5b, 0x61, 0xc2, 0xec, 0xe4,
// 0x35, 0x37, 0x3f, 0x83, 0x43, 0xc8, 0x5b,
// 0x78, 0x67, 0x4d, 0xad, 0xfc, 0x7e, 0x14,
// 0x6f, 0x88, 0x2b, 0x4f };
//
const bobpk = new Uint8Array([
0xde, 0x9e, 0xdb, 0x7d, 0x7b, 0x7d, 0xc1,
0xb4, 0xd3, 0x5b, 0x61, 0xc2, 0xec, 0xe4,
0x35, 0x37, 0x3f, 0x83, 0x43, 0xc8, 0x5b,
0x78, 0x67, 0x4d, 0xad, 0xfc, 0x7e, 0x14,
0x6f, 0x88, 0x2b, 0x4f
])
// static unsigned char nonce[24] = { 0x69, 0x69, 0x6e, 0xe9, 0x55, 0xb6,
// 0x2b, 0x73, 0xcd, 0x62, 0xbd, 0xa8,
// 0x75, 0xfc, 0x73, 0xd6, 0x82, 0x19,
// 0xe0, 0x03, 0x6b, 0x7a, 0x0b, 0x37 };
//
const nonce = new Uint8Array([
0x69, 0x69, 0x6e, 0xe9, 0x55, 0xb6,
0x2b, 0x73, 0xcd, 0x62, 0xbd, 0xa8,
0x75, 0xfc, 0x73, 0xd6, 0x82, 0x19,
0xe0, 0x03, 0x6b, 0x7a, 0x0b, 0x37
])
// static unsigned char m[131] = {
// 0xbe, 0x07, 0x5f, 0xc5, 0x3c, 0x81, 0xf2, 0xd5, 0xcf, 0x14, 0x13, 0x16,
// 0xeb, 0xeb, 0x0c, 0x7b, 0x52, 0x28, 0xc5, 0x2a, 0x4c, 0x62, 0xcb, 0xd4,
// 0x4b, 0x66, 0x84, 0x9b, 0x64, 0x24, 0x4f, 0xfc, 0xe5, 0xec, 0xba, 0xaf,
// 0x33, 0xbd, 0x75, 0x1a, 0x1a, 0xc7, 0x28, 0xd4, 0x5e, 0x6c, 0x61, 0x29,
// 0x6c, 0xdc, 0x3c, 0x01, 0x23, 0x35, 0x61, 0xf4, 0x1d, 0xb6, 0x6c, 0xce,
// 0x31, 0x4a, 0xdb, 0x31, 0x0e, 0x3b, 0xe8, 0x25, 0x0c, 0x46, 0xf0, 0x6d,
// 0xce, 0xea, 0x3a, 0x7f, 0xa1, 0x34, 0x80, 0x57, 0xe2, 0xf6, 0x55, 0x6a,
// 0xd6, 0xb1, 0x31, 0x8a, 0x02, 0x4a, 0x83, 0x8f, 0x21, 0xaf, 0x1f, 0xde,
// 0x04, 0x89, 0x77, 0xeb, 0x48, 0xf5, 0x9f, 0xfd, 0x49, 0x24, 0xca, 0x1c,
// 0x60, 0x90, 0x2e, 0x52, 0xf0, 0xa0, 0x89, 0xbc, 0x76, 0x89, 0x70, 0x40,
// 0xe0, 0x82, 0xf9, 0x37, 0x76, 0x38, 0x48, 0x64, 0x5e, 0x07, 0x05
// };
const m = new Uint8Array([
0xbe, 0x07, 0x5f, 0xc5, 0x3c, 0x81, 0xf2, 0xd5, 0xcf, 0x14, 0x13, 0x16,
0xeb, 0xeb, 0x0c, 0x7b, 0x52, 0x28, 0xc5, 0x2a, 0x4c, 0x62, 0xcb, 0xd4,
0x4b, 0x66, 0x84, 0x9b, 0x64, 0x24, 0x4f, 0xfc, 0xe5, 0xec, 0xba, 0xaf,
0x33, 0xbd, 0x75, 0x1a, 0x1a, 0xc7, 0x28, 0xd4, 0x5e, 0x6c, 0x61, 0x29,
0x6c, 0xdc, 0x3c, 0x01, 0x23, 0x35, 0x61, 0xf4, 0x1d, 0xb6, 0x6c, 0xce,
0x31, 0x4a, 0xdb, 0x31, 0x0e, 0x3b, 0xe8, 0x25, 0x0c, 0x46, 0xf0, 0x6d,
0xce, 0xea, 0x3a, 0x7f, 0xa1, 0x34, 0x80, 0x57, 0xe2, 0xf6, 0x55, 0x6a,
0xd6, 0xb1, 0x31, 0x8a, 0x02, 0x4a, 0x83, 0x8f, 0x21, 0xaf, 0x1f, 0xde,
0x04, 0x89, 0x77, 0xeb, 0x48, 0xf5, 0x9f, 0xfd, 0x49, 0x24, 0xca, 0x1c,
0x60, 0x90, 0x2e, 0x52, 0xf0, 0xa0, 0x89, 0xbc, 0x76, 0x89, 0x70, 0x40,
0xe0, 0x82, 0xf9, 0x37, 0x76, 0x38, 0x48, 0x64, 0x5e, 0x07, 0x05
])
// static unsigned char c[147 + crypto_box_MACBYTES];
// TODO: Is this supposed to diverge?! The original doesn't seem to match the crypto_box_easy docs.
const c = new Uint8Array(147)
//
// int
// main(void)
// {
// size_t i;
// int ret;
let i
let ret
//
// ret = crypto_box_easy(c, m, 131, nonce, bobpk, alicesk);
// assert(ret == 0);
ret = crypto_box_easy(c, m, nonce, bobpk, alicesk)
// for (i = 0; i < 131 + crypto_box_MACBYTES; ++i) {
// printf(",0x%02x", (unsigned int) c[i]);
// }
for (i = 0; i < 131 + crypto_box_MACBYTES; ++i) {
const hex = c[i].toString(16).padStart(2, '0')
process.stdout.write(`,0x${hex}`)
}
// printf("\n");
process.stdout.write('\n')
//
// /* Null message */
//
// ret = crypto_box_easy(c, guard_page, 0, nonce, bobpk, alicesk);
// assert(ret == 0);
// for (i = 0; i < 1 + crypto_box_MACBYTES; ++i) {
// printf(",0x%02x", (unsigned int) c[i]);
// }
// printf("\n");
//
// ret =
// crypto_box_open_easy(c, c, crypto_box_MACBYTES, nonce, bobpk, alicesk);
// assert(ret == 0);
// for (i = 0; i < 1 + crypto_box_MACBYTES; ++i) {
// printf(",0x%02x", (unsigned int) c[i]);
// }
// printf("\n");
// c[randombytes_uniform(crypto_box_MACBYTES)]++;
// ret = crypto_box_open_easy(c, c, crypto_box_MACBYTES, nonce, bobpk, alicesk);
// assert(ret == -1);
//
// return 0;
// }
if (typeof window !== 'undefined') window.close()