package main // RFC 5869 HKDF-SHA256 test vector harness. // Proves that hkdf.Expand produces byte-identical output to the published // vectors — i.e. that the realloc-leak refactor in web/common/crypto/hkdf // did not alter observable behaviour. import ( "smesh.lol/web/common/crypto/hkdf" "smesh.lol/web/common/helpers" ) type vec struct { name string ikm string salt string info string length int expectPRK string expectOKM string } var vectors = []vec{ { name: "RFC5869 #1", ikm: "0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b", salt: "000102030405060708090a0b0c", info: "f0f1f2f3f4f5f6f7f8f9", length: 42, expectPRK: "077709362c2e32df0ddc3f0dc47bba6390b6c73bb50f9c3122ec844ad7c2b3e5", expectOKM: "3cb25f25faacd57a90434f64d0362f2a2d2d0a90cf1a5a4c5db02d56ecc4c5bf34007208d5b887185865", }, { name: "RFC5869 #2 (82-byte OKM, 3 HMAC blocks)", ikm: "000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f202122232425262728292a2b2c2d2e2f303132333435363738393a3b3c3d3e3f404142434445464748494a4b4c4d4e4f", salt: "606162636465666768696a6b6c6d6e6f707172737475767778797a7b7c7d7e7f808182838485868788898a8b8c8d8e8f909192939495969798999a9b9c9d9e9fa0a1a2a3a4a5a6a7a8a9aaabacadaeaf", info: "b0b1b2b3b4b5b6b7b8b9babbbcbdbebfc0c1c2c3c4c5c6c7c8c9cacbcccdcecfd0d1d2d3d4d5d6d7d8d9dadbdcdddedfe0e1e2e3e4e5e6e7e8e9eaebecedeeeff0f1f2f3f4f5f6f7f8f9fafbfcfdfeff", length: 82, expectPRK: "06a6b88c5853361a06104c9ceb35b45cef760014904671014a193f40c15fc244", expectOKM: "b11e398dc80327a1c8e7f78c596a49344f012eda2d4efad8a050cc4c19afa97c59045a99cac7827271cb41c65e590e09da3275600c2f09b8367793a9aca3db71cc30c58179ec3e87c14c01d5c1f3434f1d87", }, { name: "RFC5869 #3 (no salt, no info)", ikm: "0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b", salt: "", info: "", length: 42, expectPRK: "19ef24a32c717b167f33a91d6f648bdf96596776afdb6377ac434c1c293ccb04", expectOKM: "8da4e775a563c18f715f802a063c5a31b8a11f5c5ee1879ec3454e5f3c738d2d9d201395faa4b61a96c8", }, } func main() { pass := 0 fail := 0 for i := 0; i < len(vectors); i++ { v := vectors[i] ikm := helpers.HexDecode(v.ikm) salt := helpers.HexDecode(v.salt) info := helpers.HexDecode(v.info) prk := hkdf.Extract(salt, ikm) prkHex := helpers.HexEncode(prk[:]) if prkHex != v.expectPRK { println("FAIL", v.name, "PRK:") println(" got ", prkHex) println(" expected", v.expectPRK) fail++ continue } okm := hkdf.Expand(prk[:], info, v.length) okmHex := helpers.HexEncode(okm) if okmHex != v.expectOKM { println("FAIL", v.name, "OKM:") println(" got ", okmHex) println(" expected", v.expectOKM) fail++ continue } if len(okm) != v.length { println("FAIL", v.name, "length mismatch:", len(okm), "vs", v.length) fail++ continue } println("PASS", v.name) pass++ } println("---") println("total pass:", pass, "fail:", fail) if fail > 0 { panic("hkdf test vectors failed") } }