Linux Test Project
 help / color / mirror / Atom feed
From: Cyril Hrubis <chrubis@suse.cz>
To: Petr Vorel <pvorel@suse.cz>
Cc: ltp@lists.linux.it
Subject: Re: [LTP] [PATCH v3 28/36] keyctl32: Test KEYCTL_PKEY_SIGN and VERIFY
Date: Fri, 18 Sep 2026 17:25:04 +0200	[thread overview]
Message-ID: <aq1X0HEKH3jRx5e4@yuki.lan> (raw)
In-Reply-To: <20260916140402.1797325-29-pvorel@suse.cz>

Hi!
> +/*\
> + * Test ``KEYCTL_PKEY_SIGN`` and ``KEYCTL_PKEY_VERIFY`` of :manpage:`keyctl(2)`.
> + *
> + * ``KEYCTL_PKEY_SIGN`` signs a digest using an asymmetric private key and
> + * ``KEYCTL_PKEY_VERIFY`` verifies the signature using the matching public key.
> + *
> + * Requires root (CAP_SYS_MODULE) to load the ``x509_key_parser`` and
> + * ``pkcs8_key_parser`` modules.
> + *
> + * [Algorithm]
> + *
> + * - sign a 32-byte digest using an RSA-2048 PKCS#8 private key with
> + *   ``enc=pkcs1 hash=sha256``
> + * - verify the 256-byte signature using the matching X.509 public key
> + * - verify a mismatched digest fails verification with ``EKEYREJECTED``
> + */
> +
> +#include "keyctl_common.h"
> +#include "keyctl_pkey_data.h"
> +#include "tst_module.h"
> +
> +#define DIGEST_SIZE	32
> +#define SIG_SIZE	256
> +
> +static const unsigned char digest[DIGEST_SIZE] = {
> +	0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07,
> +	0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f,
> +	0x10, 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17,
> +	0x18, 0x19, 0x1a, 0x1b, 0x1c, 0x1d, 0x1e, 0x1f,
> +};
> +
> +static unsigned char sig[SIG_SIZE];
> +static unsigned char wrong_digest[DIGEST_SIZE];

Here as well, these buffers should ideally be in the guarded buffers.

Otherwise:

Reviewed-by: Cyril Hrubis <chrubis@suse.cz>

-- 
Cyril Hrubis
chrubis@suse.cz

-- 
Mailing list info: https://lists.linux.it/listinfo/ltp

  reply	other threads:[~2026-09-18 15:25 UTC|newest]

Thread overview: 79+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-16 14:03 [LTP] [PATCH v3 00/36] Improve coverage for keyctl() syscall Petr Vorel
2026-09-16 14:03 ` [LTP] [PATCH v3 01/36] lapi/keyctl.h: Add fallback definitions for extended ops Petr Vorel
2026-09-17  9:35   ` Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 02/36] lapi/keyctl.h: Add SAFE_ADD_KEY() Petr Vorel
2026-09-17  9:38   ` Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 03/36] tree: keyctl: Use SAFE_ADD_KEY() Petr Vorel
2026-09-17  9:43   ` Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 04/36] keyctl10: Test KEYCTL_DESCRIBE format parsing Petr Vorel
2026-09-17  9:54   ` Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 05/36] keyctl11: Test KEYCTL_DESCRIBE with exact buffer size Petr Vorel
2026-09-16 18:19   ` [LTP] lapi/keyctl.h: Add fallback definitions for extended ops linuxtestproject.agent
2026-09-17 11:07   ` [LTP] [PATCH v3 05/36] keyctl11: Test KEYCTL_DESCRIBE with exact buffer size Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 06/36] keyctl12: Test KEYCTL_DESCRIBE with too small buffer Petr Vorel
2026-09-17 11:14   ` Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 07/36] keyctl13: Test KEYCTL_DESCRIBE size query Petr Vorel
2026-09-17 11:32   ` Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 08/36] keyctl14: Negative tests for KEYCTL_DESCRIBE Petr Vorel
2026-09-18 15:42   ` Petr Vorel
2026-09-16 14:03 ` [LTP] [PATCH v3 09/36] keyctl15: Test KEYCTL_GET_SECURITY label retrieval Petr Vorel
2026-09-17  8:54   ` Li Wang
2026-09-17 11:50     ` Cyril Hrubis
2026-09-18  5:01       ` Li Wang
2026-09-18  9:50         ` Cyril Hrubis
2026-09-18 10:59           ` Petr Vorel
2026-09-16 14:03 ` [LTP] [PATCH v3 10/36] keyctl16: Test KEYCTL_GET_SECURITY truncated copy Petr Vorel
2026-09-17 14:01   ` Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 11/36] keyctl17: Negative tests for KEYCTL_GET_SECURITY Petr Vorel
2026-09-16 14:03 ` [LTP] [PATCH v3 12/36] keyctl18: Test basic KEYCTL_MOVE Petr Vorel
2026-09-17  9:51   ` Li Wang
2026-09-17 14:37   ` Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 13/36] keyctl19: Test KEYCTL_MOVE with same source and destination Petr Vorel
2026-09-17  9:37   ` Li Wang
2026-09-16 14:03 ` [LTP] [PATCH v3 14/36] keyctl20: Test KEYCTL_MOVE displacement Petr Vorel
2026-09-17  9:38   ` Li Wang
2026-09-16 14:03 ` [LTP] [PATCH v3 15/36] keyctl21: Negative and boundary tests for KEYCTL_MOVE Petr Vorel
2026-09-18 11:24   ` Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 16/36] keyctl22: Test KEYCTL_RESTRICT_KEYRING reject-all Petr Vorel
2026-09-18 11:29   ` Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 17/36] lib: tst_test: Move the iterations to struct tst_test Petr Vorel
2026-09-16 14:03 ` [LTP] [PATCH v3 18/36] keyctl23: Test KEYCTL_RESTRICT_KEYRING builtin_trusted Petr Vorel
2026-09-18 11:51   ` Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 19/36] keyctl24: Negative tests for KEYCTL_RESTRICT_KEYRING Petr Vorel
2026-09-18 12:08   ` Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 20/36] keyctl25: Test KEYCTL_DH_COMPUTE shared secret computation Petr Vorel
2026-09-18 12:14   ` Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 21/36] keyctl26: Test KEYCTL_DH_COMPUTE size query Petr Vorel
2026-09-18 12:16   ` Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 22/36] keyctl27: Test KEYCTL_DH_COMPUTE KDF key derivation Petr Vorel
2026-09-16 14:03 ` [LTP] [PATCH v3 23/36] keyctl28: Negative and boundary tests for KEYCTL_DH_COMPUTE Petr Vorel
2026-09-16 14:03 ` [LTP] [PATCH v3 24/36] lapi/keyctl.h: Add fallback definitions for public key ops Petr Vorel
2026-09-18 12:31   ` Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 25/36] keyctl29: Test KEYCTL_PKEY_QUERY on public key Petr Vorel
2026-09-18 14:42   ` Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 26/36] keyctl30: Test KEYCTL_PKEY_QUERY on private key Petr Vorel
2026-09-18 14:50   ` Cyril Hrubis
2026-09-18 16:55     ` Petr Vorel
2026-09-16 14:03 ` [LTP] [PATCH v3 27/36] keyctl31: Test KEYCTL_PKEY_ENCRYPT and KEYCTL_PKEY_DECRYPT Petr Vorel
2026-09-18 15:17   ` Cyril Hrubis
2026-09-18 15:53     ` Petr Vorel
2026-09-18 17:01     ` Petr Vorel
2026-09-16 14:03 ` [LTP] [PATCH v3 28/36] keyctl32: Test KEYCTL_PKEY_SIGN and VERIFY Petr Vorel
2026-09-18 15:25   ` Cyril Hrubis [this message]
2026-09-16 14:03 ` [LTP] [PATCH v3 29/36] keyctl33: Negative tests for KEYCTL_PKEY_* Petr Vorel
2026-09-18 15:31   ` Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 30/36] lapi/keyctl.h: Add capability fallback defines Petr Vorel
2026-09-18 15:32   ` Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 31/36] keyctl34: Test KEYCTL_CAPABILITIES flag retrieval Petr Vorel
2026-09-18 15:36   ` Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 32/36] keyctl35: Test KEYCTL_CAPABILITIES size query Petr Vorel
2026-09-18 15:37   ` Cyril Hrubis
2026-09-16 14:03 ` [LTP] [PATCH v3 33/36] keyctl36: Test KEYCTL_CAPABILITIES buffer sizing Petr Vorel
2026-09-18 15:44   ` Cyril Hrubis
2026-09-16 14:04 ` [LTP] [PATCH v3 34/36] keyctl37: Negative tests for KEYCTL_CAPABILITIES Petr Vorel
2026-09-16 14:04 ` [LTP] [PATCH v3 35/36] keyctl38: Test KEYCTL_WATCH_KEY add and remove Petr Vorel
2026-09-18 15:53   ` Cyril Hrubis
2026-09-16 14:04 ` [LTP] [PATCH v3 36/36] keyctl39: Negative tests for KEYCTL_WATCH_KEY Petr Vorel
2026-09-17 10:11 ` [LTP] [PATCH v3 00/36] Improve coverage for keyctl() syscall Li Wang
2026-09-18 14:39   ` Petr Vorel
2026-09-19  0:18     ` Li Wang

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=aq1X0HEKH3jRx5e4@yuki.lan \
    --to=chrubis@suse.cz \
    --cc=ltp@lists.linux.it \
    --cc=pvorel@suse.cz \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox