From dd8db2ea2b37b4b20e2249b1e47dea271146f0c8 Mon Sep 17 00:00:00 2001 From: Tim Ruffing Date: Thu, 5 Mar 2026 09:34:07 +0100 Subject: [PATCH] ecdsa_adaptor: Run tests with default and overflowing nonce function --- src/modules/ecdsa_adaptor/tests_impl.h | 39 +++++++++++++++++--------- 1 file changed, 25 insertions(+), 14 deletions(-) diff --git a/src/modules/ecdsa_adaptor/tests_impl.h b/src/modules/ecdsa_adaptor/tests_impl.h index c9bf0dac..6176faec 100644 --- a/src/modules/ecdsa_adaptor/tests_impl.h +++ b/src/modules/ecdsa_adaptor/tests_impl.h @@ -803,6 +803,7 @@ static void test_ecdsa_adaptor_api(void) { unsigned char msg[32]; unsigned char asig[162]; unsigned char deckey[32]; + unsigned char zeros162[162] = { 0 }; /** setup **/ testrand256(sk); @@ -821,6 +822,14 @@ static void test_ecdsa_adaptor_api(void) { CHECK_ILLEGAL(CTX, secp256k1_ecdsa_adaptor_encrypt(CTX, asig, sk, NULL, msg, NULL, NULL)); CHECK_ILLEGAL(CTX, secp256k1_ecdsa_adaptor_encrypt(CTX, asig, sk, &zero_pk, msg, NULL, NULL)); + /* Test bad nonce functions */ + memset(asig, 1, sizeof(asig)); + CHECK(secp256k1_ecdsa_adaptor_encrypt(CTX, asig, sk, &enckey, msg, ecdsa_adaptor_nonce_function_failing, NULL) == 0); + CHECK(secp256k1_memcmp_var(asig, zeros162, sizeof(asig)) == 0); + memset(asig, 1, sizeof(asig)); + CHECK(secp256k1_ecdsa_adaptor_encrypt(CTX, asig, sk, &enckey, msg, ecdsa_adaptor_nonce_function_0, NULL) == 0); + CHECK(secp256k1_memcmp_var(asig, zeros162, sizeof(asig)) == 0); + CHECK(secp256k1_ecdsa_adaptor_encrypt(CTX, asig, sk, &enckey, msg, NULL, NULL) == 1); CHECK(secp256k1_ecdsa_adaptor_verify(CTX, asig, &pubkey, msg, &enckey) == 1); CHECK_ILLEGAL(CTX, secp256k1_ecdsa_adaptor_verify(CTX, NULL, &pubkey, msg, &enckey)); @@ -846,7 +855,7 @@ static void test_ecdsa_adaptor_api(void) { CHECK_ILLEGAL(CTX, secp256k1_ecdsa_adaptor_recover(CTX, deckey, &sig, asig, &zero_pk)); } -static void adaptor_tests_internal(void) { +static void adaptor_tests_internal_impl(secp256k1_nonce_function_hardened_ecdsa_adaptor noncefp, void* ndata) { unsigned char seckey[32]; secp256k1_pubkey pubkey; unsigned char msg[32]; @@ -864,23 +873,15 @@ static void adaptor_tests_internal(void) { CHECK(secp256k1_ec_pubkey_create(CTX, &pubkey, seckey) == 1); CHECK(secp256k1_ec_pubkey_create(CTX, &enckey, deckey) == 1); - CHECK(secp256k1_ecdsa_adaptor_encrypt(CTX, adaptor_sig, seckey, &enckey, msg, NULL, NULL) == 1); + CHECK(secp256k1_ecdsa_adaptor_encrypt(CTX, adaptor_sig, seckey, &enckey, msg, noncefp, ndata) == 1); { + unsigned char adaptor_sig_tmp[162] = { 0 }; + /* Test overflowing seckey */ memset(big, 0xFF, 32); - CHECK(secp256k1_ecdsa_adaptor_encrypt(CTX, adaptor_sig, big, &enckey, msg, NULL, NULL) == 0); - CHECK(secp256k1_memcmp_var(adaptor_sig, zeros162, sizeof(adaptor_sig)) == 0); - - /* Test different nonce functions */ - memset(adaptor_sig, 1, sizeof(adaptor_sig)); - CHECK(secp256k1_ecdsa_adaptor_encrypt(CTX, adaptor_sig, seckey, &enckey, msg, ecdsa_adaptor_nonce_function_failing, NULL) == 0); - CHECK(secp256k1_memcmp_var(adaptor_sig, zeros162, sizeof(adaptor_sig)) == 0); - memset(&adaptor_sig, 1, sizeof(adaptor_sig)); - CHECK(secp256k1_ecdsa_adaptor_encrypt(CTX, adaptor_sig, seckey, &enckey, msg, ecdsa_adaptor_nonce_function_0, NULL) == 0); - CHECK(secp256k1_memcmp_var(adaptor_sig, zeros162, sizeof(adaptor_sig)) == 0); - CHECK(secp256k1_ecdsa_adaptor_encrypt(CTX, adaptor_sig, seckey, &enckey, msg, ecdsa_adaptor_nonce_function_overflowing, NULL) == 1); - CHECK(secp256k1_memcmp_var(adaptor_sig, zeros162, sizeof(adaptor_sig)) != 0); + CHECK(secp256k1_ecdsa_adaptor_encrypt(CTX, adaptor_sig_tmp, big, &enckey, msg, NULL, NULL) == 0); + CHECK(secp256k1_memcmp_var(adaptor_sig_tmp, zeros162, sizeof(adaptor_sig)) == 0); } { /* Test adaptor_sig_serialize roundtrip */ @@ -1040,6 +1041,16 @@ static void adaptor_tests_internal(void) { } } +static void adaptor_tests_internal(void) { + adaptor_tests_internal_impl(NULL, NULL); + /* Since the same nonce function with different algo arguments is used + * both for the adaptor sig secret nonce and the dleq secret nonce, + * but ecdsa_adaptor_nonce_function_overflowing ignores the algo arg + * (in violation of the documented API contract), the resulting secret + * nonces will be the same. */ + adaptor_tests_internal_impl(ecdsa_adaptor_nonce_function_overflowing, NULL); +} + static void multi_hop_lock_tests_internal(void) { unsigned char seckey_a[32]; unsigned char seckey_b[32];