xtest: Add Application Secrets TA testsuite - #815
Conversation
The suite covers seal/unseal round-trips at 1-byte and maximum plaintext sizes, randomized sealing (IV uniqueness), rejection of malformed and tampered ciphertext, and binding to the caller's login identity. Sealing overhead is measured at runtime via a one-byte probe seal instead of being hardcoded, so the max-plaintext subcase remains valid across changes to TA-side overhead. The same probe also detects TA absence: TEEC_ERROR_ITEM_NOT_FOUND from the probe skips the suite, any other probe error fails it. A subcase that seals under one uid and unseals under another uid is not included because that would require external orchestration outside this test case. The analogous gid subcase is present, but skipped at runtime when the caller is member of only one group. The login-method-mismatch subcase still verifies that login type is part of the binding. Signed-off-by: Tuomas Salokanto <tuomas.salokanto@vaisala.com>
|
This pull request has been marked as a stale pull request because it has been open (more than) 30 days with no activity. Remove the stale label or add a comment, otherwise this pull request will automatically be closed in 5 days. Note that you can always re-open a closed pull request at any time. |
|
keep-alive |
|
This pull request has been marked as a stale pull request because it has been open (more than) 30 days with no activity. Remove the stale label or add a comment, otherwise this pull request will automatically be closed in 5 days. Note that you can always re-open a closed pull request at any time. |
|
keep-alive |
|
Seal path is kinda easy to test as only input is given from user space but unseal path could have some extra tests. |
|
Please added unseal test that magic is invalid. |
|
Please add unseal test that version is invalid... I suppose 0 and 2 could be tested and why not (unsiged)-1. |
|
Please add unseal test that has extra bytes added and over the range test. |
|
Please add unseal test for valid input but too small output buffer |
Related optee_os PR: OP-TEE/optee_os#7769
Addresses issue: OP-TEE/optee_os#7768