From d73eec656c71bdb809bb59747a446ae9f575d45b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Manuel=20P=C3=A9gouri=C3=A9-Gonnard?= Date: Wed, 10 Jun 2026 09:57:20 +0200 Subject: [PATCH] psa: test buffer sized just for actual plaintext MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Manuel Pégourié-Gonnard --- tests/suites/test_suite_psa_crypto.function | 17 +++++++++++++++-- 1 file changed, 15 insertions(+), 2 deletions(-) diff --git a/tests/suites/test_suite_psa_crypto.function b/tests/suites/test_suite_psa_crypto.function index 6d560928b9..c73aa9ad86 100644 --- a/tests/suites/test_suite_psa_crypto.function +++ b/tests/suites/test_suite_psa_crypto.function @@ -8744,6 +8744,12 @@ void asymmetric_encrypt_decrypt(int key_type_arg, TEST_LE_U(output_size, PSA_ASYMMETRIC_ENCRYPT_OUTPUT_MAX_SIZE); TEST_CALLOC(output, output_size); + /* We want the function to work with an output buffer that's just the size + * of the actual plaintext. The PSA spec actually requires callers to pass + * a buffer that's the maximum possible plaintext size, given by + * PSA_ASYMMETRIC_DECRYPT_OUTPUT_SIZE(). But historically we've accepted + * smaller sizes if the actual plaintext fits. People might depend on this + * (our TLS code does), so let's preserve this behaviour in LTS branches. */ output2_size = input_data->len; TEST_LE_U(output2_size, PSA_ASYMMETRIC_DECRYPT_OUTPUT_SIZE(key_type, key_bits, alg)); @@ -8813,8 +8819,15 @@ void asymmetric_decrypt(int key_type_arg, PSA_ASSERT(psa_get_key_attributes(key, &attributes)); key_bits = psa_get_key_bits(&attributes); - /* Determine the maximum ciphertext length */ - output_size = PSA_ASYMMETRIC_DECRYPT_OUTPUT_SIZE(key_type, key_bits, alg); + /* We want the function to work with an output buffer that's just the size + * of the actual plaintext. The PSA spec actually requires callers to pass + * a buffer that's the maximum possible plaintext size, given by + * PSA_ASYMMETRIC_DECRYPT_OUTPUT_SIZE(). But historically we've accepted + * smaller sizes if the actual plaintext fits. People might depend on this + * (our TLS code does), so let's preserve this behaviour in LTS branches. */ + output_size = expected_data->len; + TEST_LE_U(output_size, + PSA_ASYMMETRIC_DECRYPT_OUTPUT_SIZE(key_type, key_bits, alg)); TEST_LE_U(output_size, PSA_ASYMMETRIC_DECRYPT_OUTPUT_MAX_SIZE); TEST_CALLOC(output, output_size);