Page MenuHomeFreeBSD

ktls: Add padding tests for AES-CBC MTE cipher suites.
ClosedPublic

Authored by jhb on Nov 5 2021, 12:00 AM.
Tags
None
Referenced Files
F133542640: D32840.diff
Sun, Oct 26, 1:15 PM
Unknown Object (File)
Fri, Oct 24, 8:41 PM
Unknown Object (File)
Fri, Oct 17, 6:43 AM
Unknown Object (File)
Aug 14 2025, 11:53 PM
Unknown Object (File)
Jun 18 2025, 1:18 AM
Unknown Object (File)
Jun 17 2025, 8:56 AM
Unknown Object (File)
Jun 15 2025, 1:30 PM
Unknown Object (File)
Jun 14 2025, 9:03 PM
Subscribers

Details

Summary

For each AES-CBC MTE cipher suite, test sending records with 1 to 16
bytes of payload. This ensures that all of the potential padding
values are covered.

Sponsored by: Netflix

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Passed
Unit
No Test Coverage
Build Status
Buildable 42590
Build 39478: arc lint + arc unit

Event Timeline

jhb requested review of this revision.Nov 5 2021, 12:00 AM
markj added inline comments.
tests/sys/kern/ktls_test.c
1104

Does it make sense to test a message of length 0? I'm not sure if empty records are permitted (though ISTR they are used in TLS 1.0).

This revision is now accepted and ready to land.Nov 13 2021, 2:35 AM
jhb marked an inline comment as done.Nov 15 2021, 7:20 PM
jhb added inline comments.
tests/sys/kern/ktls_test.c
1104

I did that in a followup set of tests for TLS 1.0. :)

This revision was automatically updated to reflect the committed changes.
jhb marked an inline comment as done.