1 // Copyright 2015 Brian Smith.
2 //
3 // Permission to use, copy, modify, and/or distribute this software for any
4 // purpose with or without fee is hereby granted, provided that the above
5 // copyright notice and this permission notice appear in all copies.
6 //
7 // THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHORS DISCLAIM ALL WARRANTIES
8 // WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
9 // MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHORS BE LIABLE FOR ANY
10 // SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
11 // WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION
12 // OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN
13 // CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
14 
15 use ring::{digest, error, hkdf, test, test_file};
16 
17 #[cfg(target_arch = "wasm32")]
18 use wasm_bindgen_test::{wasm_bindgen_test, wasm_bindgen_test_configure};
19 
20 #[cfg(target_arch = "wasm32")]
21 wasm_bindgen_test_configure!(run_in_browser);
22 
23 #[test]
24 #[cfg_attr(target_arch = "wasm32", wasm_bindgen_test)]
hkdf_tests()25 fn hkdf_tests() {
26     test::run(test_file!("hkdf_tests.txt"), |section, test_case| {
27         assert_eq!(section, "");
28         let alg = {
29             let digest_alg = test_case
30                 .consume_digest_alg("Hash")
31                 .ok_or(error::Unspecified)?;
32             if digest_alg == &digest::SHA256 {
33                 hkdf::HKDF_SHA256
34             } else {
35                 // TODO: add test vectors for other algorithms
36                 panic!("unsupported algorithm: {:?}", digest_alg);
37             }
38         };
39         let secret = test_case.consume_bytes("IKM");
40         let salt = test_case.consume_bytes("salt");
41         let info = test_case.consume_bytes("info");
42         let _ = test_case.consume_bytes("PRK");
43         let expected_out = test_case.consume_bytes("OKM");
44 
45         let salt = hkdf::Salt::new(alg, &salt);
46 
47         // TODO: test multi-part info, especially with empty parts.
48         let My(out) = salt
49             .extract(&secret)
50             .expand(&[&info], My(expected_out.len()))
51             .unwrap()
52             .into();
53         assert_eq!(out, expected_out);
54 
55         Ok(())
56     });
57 }
58 
59 #[test]
60 #[cfg_attr(target_arch = "wasm32", wasm_bindgen_test)]
hkdf_output_len_tests()61 fn hkdf_output_len_tests() {
62     for &alg in &[hkdf::HKDF_SHA256, hkdf::HKDF_SHA384, hkdf::HKDF_SHA512] {
63         const MAX_BLOCKS: usize = 255;
64 
65         let salt = hkdf::Salt::new(alg, &[]);
66         let prk = salt.extract(&[]); // TODO: enforce minimum length.
67 
68         {
69             // Test zero length.
70             let okm = prk.expand(&[b"info"], My(0)).unwrap();
71             let result: My<Vec<u8>> = okm.into();
72             assert_eq!(&result.0, &[]);
73         }
74 
75         let max_out_len = MAX_BLOCKS * alg.hmac_algorithm().digest_algorithm().output_len;
76 
77         {
78             // Test maximum length output succeeds.
79             let okm = prk.expand(&[b"info"], My(max_out_len)).unwrap();
80             let result: My<Vec<u8>> = okm.into();
81             assert_eq!(result.0.len(), max_out_len);
82         }
83 
84         {
85             // Test too-large output fails.
86             assert!(prk.expand(&[b"info"], My(max_out_len + 1)).is_err());
87         }
88 
89         {
90             // Test length mismatch (smaller).
91             let okm = prk.expand(&[b"info"], My(2)).unwrap();
92             let mut buf = [0u8; 1];
93             assert_eq!(okm.fill(&mut buf), Err(error::Unspecified));
94         }
95 
96         {
97             // Test length mismatch (larger).
98             let okm = prk.expand(&[b"info"], My(2)).unwrap();
99             let mut buf = [0u8; 3];
100             assert_eq!(okm.fill(&mut buf), Err(error::Unspecified));
101         }
102 
103         {
104             // Control for above two tests.
105             let okm = prk.expand(&[b"info"], My(2)).unwrap();
106             let mut buf = [0u8; 2];
107             assert_eq!(okm.fill(&mut buf), Ok(()));
108         }
109     }
110 }
111 
112 /// Generic newtype wrapper that lets us implement traits for externally-defined
113 /// types.
114 #[derive(Debug, PartialEq)]
115 struct My<T: core::fmt::Debug + PartialEq>(T);
116 
117 impl hkdf::KeyType for My<usize> {
len(&self) -> usize118     fn len(&self) -> usize {
119         self.0
120     }
121 }
122 
123 impl From<hkdf::Okm<'_, My<usize>>> for My<Vec<u8>> {
from(okm: hkdf::Okm<My<usize>>) -> Self124     fn from(okm: hkdf::Okm<My<usize>>) -> Self {
125         let mut r = vec![0u8; okm.len().0];
126         okm.fill(&mut r).unwrap();
127         My(r)
128     }
129 }
130