1dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley/* Copyright (c) 2014, Google Inc.
2dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley *
3dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley * Permission to use, copy, modify, and/or distribute this software for any
4dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley * purpose with or without fee is hereby granted, provided that the above
5dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley * copyright notice and this permission notice appear in all copies.
6dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley *
7dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
8dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
9dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY
10dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
11dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION
12dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN
13dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */
14dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
15dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley#include <stdint.h>
16dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley#include <stdio.h>
17dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley#include <stdlib.h>
18dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley#include <string.h>
19dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
20dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley#include <openssl/aead.h>
21a70c75cfc0ca32a43985e3f24d737ca9cafcb910David Benjamin#include <openssl/crypto.h>
22dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
23dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley/* This program tests an AEAD against a series of test vectors from a file. The
24dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley * test vector file consists of key-value lines where the key and value are
25dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley * separated by a colon and optional whitespace. The keys are listed in
26dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley * |NAMES|, below. The values are hex-encoded data.
27dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley *
28dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley * After a number of key-value lines, a blank line or EOF indicates the end of
29dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley * the test case.
30dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley *
31dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley * For example, here's a valid test case:
32dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley *
33dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley *   KEY: 5a19f3173586b4c42f8412f4d5a786531b3231753e9e00998aec12fda8df10e4
34dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley *   NONCE: 978105dfce667bf4
35dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley *   IN: 6a4583908d
36dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley *   AD: b654574932
37dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley *   CT: 5294265a60
38dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley *   TAG: 1d45758621762e061368e68868e2f929
39dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley */
40dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
41dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley#define BUF_MAX 512
42dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
43dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley/* These are the different types of line that are found in the input file. */
44dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langleyenum {
45dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  KEY = 0, /* hex encoded key. */
46dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  NONCE,   /* hex encoded nonce. */
47dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  IN,      /* hex encoded plaintext. */
48dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  AD,      /* hex encoded additional data. */
49dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  CT,      /* hex encoded ciphertext (not including the authenticator,
50dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley              which is next). */
51dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  TAG,     /* hex encoded authenticator. */
52dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  NUM_TYPES,
53dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley};
54dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
55dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langleystatic const char NAMES[6][NUM_TYPES] = {
56dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    "KEY", "NONCE", "IN", "AD", "CT", "TAG",
57dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley};
58dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
59dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langleystatic unsigned char hex_digit(char h) {
60dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  if (h >= '0' && h <= '9') {
61dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    return h - '0';
62dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  } else if (h >= 'a' && h <= 'f') {
63dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    return h - 'a' + 10;
64dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  } else if (h >= 'A' && h <= 'F') {
65dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    return h - 'A' + 10;
66dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  } else {
67dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    return 16;
68dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  }
69dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley}
70dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
71dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langleystatic int run_test_case(const EVP_AEAD *aead,
72dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley                         unsigned char bufs[NUM_TYPES][BUF_MAX],
73dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley                         const unsigned int lengths[NUM_TYPES],
74dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley                         unsigned int line_no) {
75dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  EVP_AEAD_CTX ctx;
76dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  size_t ciphertext_len, plaintext_len;
77dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  unsigned char out[BUF_MAX + EVP_AEAD_MAX_OVERHEAD], out2[BUF_MAX];
78dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
79dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  if (!EVP_AEAD_CTX_init(&ctx, aead, bufs[KEY], lengths[KEY], lengths[TAG],
80dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley                         NULL)) {
81dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    fprintf(stderr, "Failed to init AEAD on line %u\n", line_no);
82dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    return 0;
83dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  }
84dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
85dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  if (!EVP_AEAD_CTX_seal(&ctx, out, &ciphertext_len, sizeof(out), bufs[NONCE],
86dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley                         lengths[NONCE], bufs[IN], lengths[IN], bufs[AD],
87dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley                         lengths[AD])) {
88dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    fprintf(stderr, "Failed to run AEAD on line %u\n", line_no);
89dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    return 0;
90dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  }
91dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
92dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  if (ciphertext_len != lengths[CT] + lengths[TAG]) {
93dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    fprintf(stderr, "Bad output length on line %u: %u vs %u\n", line_no,
94dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley            (unsigned)ciphertext_len, (unsigned)(lengths[CT] + lengths[TAG]));
95dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    return 0;
96dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  }
97dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
98dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  if (memcmp(out, bufs[CT], lengths[CT]) != 0) {
99dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    fprintf(stderr, "Bad output on line %u\n", line_no);
100dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    return 0;
101dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  }
102dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
103dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  if (memcmp(out + lengths[CT], bufs[TAG], lengths[TAG]) != 0) {
104dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    fprintf(stderr, "Bad tag on line %u\n", line_no);
105dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    return 0;
106dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  }
107dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
10845ec21b99c144643dec9e953a3b8ba44870f5cacAdam Langley  /* The "stateful" AEADs for implementing pre-AEAD cipher suites need to be
10945ec21b99c144643dec9e953a3b8ba44870f5cacAdam Langley   * reset after each operation. */
11045ec21b99c144643dec9e953a3b8ba44870f5cacAdam Langley  EVP_AEAD_CTX_cleanup(&ctx);
11145ec21b99c144643dec9e953a3b8ba44870f5cacAdam Langley  if (!EVP_AEAD_CTX_init(&ctx, aead, bufs[KEY], lengths[KEY], lengths[TAG],
11245ec21b99c144643dec9e953a3b8ba44870f5cacAdam Langley                         NULL)) {
11345ec21b99c144643dec9e953a3b8ba44870f5cacAdam Langley    fprintf(stderr, "Failed to init AEAD on line %u\n", line_no);
11445ec21b99c144643dec9e953a3b8ba44870f5cacAdam Langley    return 0;
11545ec21b99c144643dec9e953a3b8ba44870f5cacAdam Langley  }
11645ec21b99c144643dec9e953a3b8ba44870f5cacAdam Langley
117dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  if (!EVP_AEAD_CTX_open(&ctx, out2, &plaintext_len, lengths[IN], bufs[NONCE],
118dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley                         lengths[NONCE], out, ciphertext_len, bufs[AD],
119dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley                         lengths[AD])) {
120dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    fprintf(stderr, "Failed to decrypt on line %u\n", line_no);
121dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    return 0;
122dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  }
123dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
124dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  if (plaintext_len != lengths[IN]) {
125dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    fprintf(stderr, "Bad decrypt on line %u: %u\n", line_no,
126dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley            (unsigned)ciphertext_len);
127dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    return 0;
128dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  }
129dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
13045ec21b99c144643dec9e953a3b8ba44870f5cacAdam Langley  /* The "stateful" AEADs for implementing pre-AEAD cipher suites need to be
13145ec21b99c144643dec9e953a3b8ba44870f5cacAdam Langley   * reset after each operation. */
13245ec21b99c144643dec9e953a3b8ba44870f5cacAdam Langley  EVP_AEAD_CTX_cleanup(&ctx);
13345ec21b99c144643dec9e953a3b8ba44870f5cacAdam Langley  if (!EVP_AEAD_CTX_init(&ctx, aead, bufs[KEY], lengths[KEY], lengths[TAG],
13445ec21b99c144643dec9e953a3b8ba44870f5cacAdam Langley                         NULL)) {
13545ec21b99c144643dec9e953a3b8ba44870f5cacAdam Langley    fprintf(stderr, "Failed to init AEAD on line %u\n", line_no);
13645ec21b99c144643dec9e953a3b8ba44870f5cacAdam Langley    return 0;
13745ec21b99c144643dec9e953a3b8ba44870f5cacAdam Langley  }
13845ec21b99c144643dec9e953a3b8ba44870f5cacAdam Langley
139dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  out[0] ^= 0x80;
140dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  if (EVP_AEAD_CTX_open(&ctx, out2, &plaintext_len, lengths[IN], bufs[NONCE],
141dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley                        lengths[NONCE], out, ciphertext_len, bufs[AD],
142dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley                        lengths[AD])) {
143dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    fprintf(stderr, "Decrypted bad data on line %u\n", line_no);
144dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    return 0;
145dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  }
146dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
147dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  EVP_AEAD_CTX_cleanup(&ctx);
148dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  return 1;
149dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley}
150dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
151dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langleyint main(int argc, char **argv) {
152dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  FILE *f;
153dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  const EVP_AEAD *aead = NULL;
154dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  unsigned int line_no = 0, num_tests = 0, j;
155dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
156dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  unsigned char bufs[NUM_TYPES][BUF_MAX];
157dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  unsigned int lengths[NUM_TYPES];
158dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
159a70c75cfc0ca32a43985e3f24d737ca9cafcb910David Benjamin  CRYPTO_library_init();
160a70c75cfc0ca32a43985e3f24d737ca9cafcb910David Benjamin
161dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  if (argc != 3) {
162dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    fprintf(stderr, "%s <aead> <test file.txt>\n", argv[0]);
163dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    return 1;
164dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  }
165dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
166dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  if (strcmp(argv[1], "aes-128-gcm") == 0) {
167dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    aead = EVP_aead_aes_128_gcm();
168dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  } else if (strcmp(argv[1], "aes-256-gcm") == 0) {
169dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    aead = EVP_aead_aes_256_gcm();
170de0b2026841c34193cacf5c97646b38439e13200Adam Langley  } else if (strcmp(argv[1], "chacha20-poly1305") == 0) {
171de0b2026841c34193cacf5c97646b38439e13200Adam Langley    aead = EVP_aead_chacha20_poly1305();
17245ec21b99c144643dec9e953a3b8ba44870f5cacAdam Langley  } else if (strcmp(argv[1], "rc4-md5") == 0) {
17345ec21b99c144643dec9e953a3b8ba44870f5cacAdam Langley    aead = EVP_aead_rc4_md5_tls();
17493a3dcd57262f5bbd84adaa5565abb14f95d79aeAdam Langley  } else if (strcmp(argv[1], "aes-128-key-wrap") == 0) {
17593a3dcd57262f5bbd84adaa5565abb14f95d79aeAdam Langley    aead = EVP_aead_aes_128_key_wrap();
17693a3dcd57262f5bbd84adaa5565abb14f95d79aeAdam Langley  } else if (strcmp(argv[1], "aes-256-key-wrap") == 0) {
17793a3dcd57262f5bbd84adaa5565abb14f95d79aeAdam Langley    aead = EVP_aead_aes_256_key_wrap();
178dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  } else {
179dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    fprintf(stderr, "Unknown AEAD: %s\n", argv[1]);
180dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    return 2;
181dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  }
182dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
183dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  f = fopen(argv[2], "r");
184dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  if (f == NULL) {
185dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    perror("failed to open input");
186dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    return 1;
187dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  }
188dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
189dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  for (j = 0; j < NUM_TYPES; j++) {
190dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    lengths[j] = 0;
191dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  }
192dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
193dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  for (;;) {
194dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    char line[4096];
195dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    unsigned int i, type_len = 0;
196dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
197dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    unsigned char *buf = NULL;
198dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    unsigned int *buf_len = NULL;
199dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
200dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    if (!fgets(line, sizeof(line), f)) {
201d54dc249ead32282d4d1d5588a24822752d92a51Adam Langley      line[0] = 0;
202dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    }
203dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
204dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    line_no++;
205dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    if (line[0] == '#') {
206dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      continue;
207dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    }
208dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
209dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    if (line[0] == '\n' || line[0] == 0) {
210dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      /* Run a test, if possible. */
211dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      char any_values_set = 0;
212dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      for (j = 0; j < NUM_TYPES; j++) {
213dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley        if (lengths[j] != 0) {
214dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley          any_values_set = 1;
215dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley          break;
216dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley        }
217dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      }
218dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
219d54dc249ead32282d4d1d5588a24822752d92a51Adam Langley      if (any_values_set) {
220d54dc249ead32282d4d1d5588a24822752d92a51Adam Langley        if (!run_test_case(aead, bufs, lengths, line_no)) {
221d54dc249ead32282d4d1d5588a24822752d92a51Adam Langley          return 4;
222d54dc249ead32282d4d1d5588a24822752d92a51Adam Langley        }
223dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
224d54dc249ead32282d4d1d5588a24822752d92a51Adam Langley        for (j = 0; j < NUM_TYPES; j++) {
225d54dc249ead32282d4d1d5588a24822752d92a51Adam Langley          lengths[j] = 0;
226d54dc249ead32282d4d1d5588a24822752d92a51Adam Langley        }
227dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
228d54dc249ead32282d4d1d5588a24822752d92a51Adam Langley        num_tests++;
229dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      }
230dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
231d54dc249ead32282d4d1d5588a24822752d92a51Adam Langley      if (line[0] == 0) {
232d54dc249ead32282d4d1d5588a24822752d92a51Adam Langley        break;
233d54dc249ead32282d4d1d5588a24822752d92a51Adam Langley      }
234dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      continue;
235dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    }
236dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
237dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    /* Each line looks like:
238dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley     *   TYPE: 0123abc
239dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley     * Where "TYPE" is the type of the data on the line,
240dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley     * e.g. "KEY". */
241dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    for (i = 0; line[i] != 0 && line[i] != '\n'; i++) {
242dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      if (line[i] == ':') {
243dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley        type_len = i;
244dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley        break;
245dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      }
246dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    }
247dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    i++;
248dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
249dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    if (type_len == 0) {
250dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      fprintf(stderr, "Parse error on line %u\n", line_no);
251dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      return 3;
252dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    }
253dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
254dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    /* After the colon, there's optional whitespace. */
255dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    for (; line[i] != 0 && line[i] != '\n'; i++) {
256dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      if (line[i] != ' ' && line[i] != '\t') {
257dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley        break;
258dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      }
259dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    }
260dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
261dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    line[type_len] = 0;
262dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    for (j = 0; j < NUM_TYPES; j++) {
263dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      if (strcmp(line, NAMES[j]) != 0) {
264dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley        continue;
265dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      }
266dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      if (lengths[j] != 0) {
267dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley        fprintf(stderr, "Duplicate value on line %u\n", line_no);
268dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley        return 3;
269dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      }
270dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      buf = bufs[j];
271dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      buf_len = &lengths[j];
272dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    }
273dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
274dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    if (buf == NULL) {
275dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      fprintf(stderr, "Unknown line type on line %u\n", line_no);
276dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      return 3;
277dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    }
278dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
279dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    j = 0;
280dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    for (; line[i] != 0 && line[i] != '\n'; i++) {
281dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      unsigned char v, v2;
282dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      v = hex_digit(line[i++]);
283dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      if (line[i] == 0 || line[i] == '\n') {
284dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley        fprintf(stderr, "Odd-length hex data on line %u\n", line_no);
285dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley        return 3;
286dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      }
287dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      v2 = hex_digit(line[i]);
288dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      if (v > 15 || v2 > 15) {
289dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley        fprintf(stderr, "Invalid hex char on line %u\n", line_no);
290dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley        return 3;
291dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      }
292dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      v <<= 4;
293dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      v |= v2;
294dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
295dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      if (j == BUF_MAX) {
296dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley        fprintf(stderr, "Too much hex data on line %u (max is %u bytes)\n",
297dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley                line_no, (unsigned)BUF_MAX);
298dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley        return 3;
299dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      }
300dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      buf[j++] = v;
301dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley      *buf_len = *buf_len + 1;
302dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley    }
303dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  }
304dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
305dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  printf("Completed %u test cases\n", num_tests);
306dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  printf("PASS\n");
307dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  fclose(f);
308dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley
309dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley  return 0;
310dfe3053086465ddc0700b2826e99ca02cc67f43fAdam Langley}
311