// This Source Code Form is subject to the terms of the Mozilla Public
// License, v. 2.0. If a copy of the MPL was not distributed with this file,
// You can obtain one at http://mozilla.org/MPL/2.0/.
#include "gtest/gtest.h"
#include "blapi.h"
#include "nss_scoped_ptrs.h"
#include "kat/kyber768_kat.h"
#include "testvectors_base/test-structs.h"
#include "testvectors/ml-kem-keygen-vectors.h"
#include "testvectors/ml-kem-encap-vectors.h"
#include "testvectors/ml-kem-decap-vectors.h"
namespace nss_test {
size_t get_ciphertext_length(KyberParams param) {
size_t len =
0;
switch (param) {
case params_kyber768_round3:
case params_kyber768_round3_test_mode:
case params_ml_kem768:
case params_ml_kem768_test_mode:
len = KYBER768_CIPHERTEXT_BYTES;
break;
case params_ml_kem1024:
case params_ml_kem1024_test_mode:
len = MLKEM1024_CIPHERTEXT_BYTES;
break;
case params_ml_kem512:
case params_kyber_invalid:
break;
}
return len;
}
size_t get_private_key_length(KyberParams param) {
size_t len =
0;
switch (param) {
case params_kyber768_round3:
case params_kyber768_round3_test_mode:
case params_ml_kem768:
case params_ml_kem768_test_mode:
len = KYBER768_PRIVATE_KEY_BYTES;
break;
case params_ml_kem1024:
case params_ml_kem1024_test_mode:
len = MLKEM1024_PRIVATE_KEY_BYTES;
break;
case params_ml_kem512:
case params_kyber_invalid:
break;
}
return len;
}
size_t get_public_key_length(KyberParams param) {
size_t len =
0;
switch (param) {
case params_kyber768_round3:
case params_kyber768_round3_test_mode:
case params_ml_kem768:
case params_ml_kem768_test_mode:
len = KYBER768_PUBLIC_KEY_BYTES;
break;
case params_ml_kem1024:
case params_ml_kem1024_test_mode:
len = MLKEM1024_PUBLIC_KEY_BYTES;
break;
case params_ml_kem512:
case params_kyber_invalid:
break;
}
return len;
}
class KyberTest :
public ::testing::Test {};
class KyberSelfTest :
public KyberTest,
public ::testing::WithParamInterface<KyberParams> {};
TEST_P(KyberSelfTest, ConsistencyTest) {
const KyberParams& param(GetParam());
ScopedSECItem privateKey(
SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_PRIVATE_KEY_LENGTH));
ScopedSECItem publicKey(
SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_PUBLIC_KEY_LENGTH));
ScopedSECItem ciphertext(
SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_CIPHER_LENGTH));
ScopedSECItem secret(
SECITEM_AllocItem(nullptr, nullptr, KYBER_SHARED_SECRET_BYTES));
ScopedSECItem secret2(
SECITEM_AllocItem(nullptr, nullptr, KYBER_SHARED_SECRET_BYTES));
privateKey->len = get_private_key_length(param);
publicKey->len = get_public_key_length(param);
SECStatus rv =
Kyber_NewKey(param, nullptr, privateKey.get(), publicKey.get());
EXPECT_EQ(SECSuccess, rv);
ciphertext->len = get_ciphertext_length(param);
rv = Kyber_Encapsulate(param, nullptr, publicKey.get(), ciphertext.get(),
secret.get());
EXPECT_EQ(SECSuccess, rv);
rv = Kyber_Decapsulate(param, privateKey.get(), ciphertext.get(),
secret2.get());
EXPECT_EQ(SECSuccess, rv);
EXPECT_EQ(secret->len, KYBER_SHARED_SECRET_BYTES);
EXPECT_EQ(secret2->len, KYBER_SHARED_SECRET_BYTES);
EXPECT_EQ(
0, memcmp(secret->data, secret2->data, KYBER_SHARED_SECRET_BYTES));
}
TEST_P(KyberSelfTest, InvalidParameterTest) {
const KyberParams& param(GetParam());
ScopedSECItem privateKey(
SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_PRIVATE_KEY_LENGTH));
ScopedSECItem publicKey(
SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_PUBLIC_KEY_LENGTH));
ScopedSECItem ciphertext(
SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_CIPHER_LENGTH));
ScopedSECItem secret(
SECITEM_AllocItem(nullptr, nullptr, KYBER_SHARED_SECRET_BYTES));
privateKey->len = get_private_key_length(param);
publicKey->len = get_public_key_length(param);
SECStatus rv = Kyber_NewKey(params_kyber_invalid, nullptr, privateKey.get(),
publicKey.get());
EXPECT_EQ(SECFailure, rv);
rv = Kyber_NewKey(param, nullptr, privateKey.get(), publicKey.get());
EXPECT_EQ(SECSuccess, rv);
ciphertext->len = get_ciphertext_length(param);
rv = Kyber_Encapsulate(params_kyber_invalid, nullptr, publicKey.get(),
ciphertext.get(), secret.get());
EXPECT_EQ(SECFailure, rv);
rv = Kyber_Encapsulate(param, nullptr, publicKey.get(), ciphertext.get(),
secret.get());
EXPECT_EQ(SECSuccess, rv);
rv = Kyber_Decapsulate(params_kyber_invalid, privateKey.get(),
ciphertext.get(), secret.get());
EXPECT_EQ(SECFailure, rv);
rv = Kyber_Decapsulate(param, privateKey.get(), ciphertext.get(),
secret.get());
EXPECT_EQ(SECSuccess, rv);
}
TEST_P(KyberSelfTest, InvalidPublicKeyTest) {
const KyberParams& param(GetParam());
ScopedSECItem shortBuffer(SECITEM_AllocItem(nullptr, nullptr,
7));
ScopedSECItem privateKey(
SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_PRIVATE_KEY_LENGTH));
privateKey->len = get_private_key_length(param);
SECStatus rv =
Kyber_NewKey(param, nullptr, privateKey.get(), shortBuffer.get());
EXPECT_EQ(SECFailure, rv);
// short publicKey buffer
}
TEST_P(KyberSelfTest, InvalidCiphertextTest) {
const KyberParams& param(GetParam());
ScopedSECItem shortBuffer(SECITEM_AllocItem(nullptr, nullptr,
7));
ScopedSECItem privateKey(
SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_PRIVATE_KEY_LENGTH));
ScopedSECItem publicKey(
SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_PUBLIC_KEY_LENGTH));
ScopedSECItem ciphertext(
SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_CIPHER_LENGTH));
ScopedSECItem secret(
SECITEM_AllocItem(nullptr, nullptr, KYBER_SHARED_SECRET_BYTES));
ScopedSECItem secret2(
SECITEM_AllocItem(nullptr, nullptr, KYBER_SHARED_SECRET_BYTES));
privateKey->len = get_private_key_length(param);
publicKey->len = get_public_key_length(param);
SECStatus rv =
Kyber_NewKey(param, nullptr, privateKey.get(), publicKey.get());
EXPECT_EQ(SECSuccess, rv);
ciphertext->len = get_ciphertext_length(param);
rv = Kyber_Encapsulate(param, nullptr, publicKey.get(), shortBuffer.get(),
secret.get());
EXPECT_EQ(SECFailure, rv);
// short ciphertext input
rv = Kyber_Encapsulate(param, nullptr, publicKey.get(), ciphertext.get(),
secret.get());
EXPECT_EQ(SECSuccess, rv);
// Modify a random byte in the ciphertext
size_t pos;
rv = RNG_GenerateGlobalRandomBytes((uint8_t*)&pos,
sizeof(pos));
EXPECT_EQ(SECSuccess, rv);
uint8_t byte;
rv = RNG_GenerateGlobalRandomBytes((uint8_t*)&byte,
sizeof(byte));
EXPECT_EQ(SECSuccess, rv);
size_t ct_len = get_ciphertext_length(param);
EXPECT_EQ(ciphertext->len, ct_len);
ciphertext->data[pos % ct_len] ^= (byte |
1);
rv = Kyber_Decapsulate(param, privateKey.get(), ciphertext.get(),
secret2.get());
EXPECT_EQ(SECSuccess, rv);
EXPECT_EQ(secret->len, KYBER_SHARED_SECRET_BYTES);
EXPECT_EQ(secret2->len, KYBER_SHARED_SECRET_BYTES);
EXPECT_NE(
0, memcmp(secret->data, secret2->data, KYBER_SHARED_SECRET_BYTES));
}
TEST_P(KyberSelfTest, InvalidPrivateKeyTest) {
const KyberParams& param(GetParam());
ScopedSECItem shortBuffer(SECITEM_AllocItem(nullptr, nullptr,
7));
ScopedSECItem privateKey(
SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_PRIVATE_KEY_LENGTH));
ScopedSECItem publicKey(
SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_PUBLIC_KEY_LENGTH));
ScopedSECItem ciphertext(
SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_CIPHER_LENGTH));
ScopedSECItem secret(
SECITEM_AllocItem(nullptr, nullptr, KYBER_SHARED_SECRET_BYTES));
ScopedSECItem secret2(
SECITEM_AllocItem(nullptr, nullptr, KYBER_SHARED_SECRET_BYTES));
privateKey->len = get_private_key_length(param);
publicKey->len = get_public_key_length(param);
SECStatus rv =
Kyber_NewKey(param, nullptr, shortBuffer.get(), publicKey.get());
EXPECT_EQ(SECFailure, rv);
// short privateKey buffer
rv = Kyber_NewKey(param, nullptr, privateKey.get(), publicKey.get());
EXPECT_EQ(SECSuccess, rv);
ciphertext->len = get_ciphertext_length(param);
rv = Kyber_Encapsulate(param, nullptr, publicKey.get(), ciphertext.get(),
secret.get());
EXPECT_EQ(SECSuccess, rv);
// Modify a random byte in the private key
size_t pos;
rv = RNG_GenerateGlobalRandomBytes((uint8_t*)&pos,
sizeof(pos));
EXPECT_EQ(SECSuccess, rv);
uint8_t byte;
rv = RNG_GenerateGlobalRandomBytes((uint8_t*)&byte,
sizeof(byte));
EXPECT_EQ(SECSuccess, rv);
// Modifying the implicit rejection key will not cause decapsulation failure.
size_t pvk_len = get_private_key_length(param);
size_t puk_len = get_public_key_length(param);
EXPECT_EQ(privateKey->len, pvk_len);
size_t ir_pos = pvk_len - (pos % KYBER_SHARED_SECRET_BYTES) -
1;
uint8_t ir_pos_old = privateKey->data[ir_pos];
privateKey->data[ir_pos] ^= (byte |
1);
rv = Kyber_Decapsulate(param, privateKey.get(), ciphertext.get(),
secret2.get());
EXPECT_EQ(SECSuccess, rv);
EXPECT_EQ(secret->len, KYBER_SHARED_SECRET_BYTES);
EXPECT_EQ(secret2->len, KYBER_SHARED_SECRET_BYTES);
EXPECT_EQ(
0, memcmp(secret->data, secret2->data, KYBER_SHARED_SECRET_BYTES));
// Fix the private key
privateKey->data[ir_pos] = ir_pos_old;
// For ML-KEM when modifying the public key, the key must be rejected.
// Kyber will decapsulate without an error in these cases
size_t pk_pos = pvk_len -
2 * KYBER_SHARED_SECRET_BYTES - (pos % puk_len) -
1;
uint8_t pk_pos_old = privateKey->data[pk_pos];
privateKey->data[pk_pos] ^= (byte |
1);
rv = Kyber_Decapsulate(param, privateKey.get(), ciphertext.get(),
secret2.get());
if (param == params_kyber768_round3) {
EXPECT_EQ(SECSuccess, rv);
}
else {
EXPECT_EQ(SECFailure, rv);
}
// Fix the key again.
privateKey->data[pk_pos] = pk_pos_old;
// For ML-KEM when modifying the public key hash, the key must be rejected.
// Kyber will decapsulate without an error in these cases
size_t pk_hash_pos = pvk_len - KYBER_SHARED_SECRET_BYTES -
(pos % KYBER_SHARED_SECRET_BYTES) -
1;
privateKey->data[pk_hash_pos] ^= (byte |
1);
rv = Kyber_Decapsulate(param, privateKey.get(), ciphertext.get(),
secret2.get());
if (param == params_kyber768_round3) {
EXPECT_EQ(SECSuccess, rv);
}
else {
// License, v.
2.
0.
If a copy of the
// You can obtain one at http://mozilla.org/MPL/2.0/.
}
}
TEST_P(KyberSelfTest, DecapsulationWithModifiedRejectionKeyTest) {
const KyberParams& param(GetParam());
ScopedSECItem privateKey(
SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_PRIVATE_KEY_LENGTH));
ScopedSECItem publicKey(
SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_PUBLIC_KEY_LENGTH));
ScopedSECItemciphertext
i kat/kyber768_kat.h
"
ScopedSECItem secret(
SECITEM_AllocItem(nullptr, nullptr, KYBER_SHARED_SECRET_BYTES));
ScopedSECItem secret2(
SECITEM_AllocItem(, nullptr, KYBER_SHARED_SECRET_BYTES);
ScopedSECItem secret3(
nullptr ,java.lang.StringIndexOutOfBoundsException: Range [69, 67) out of bounds
for length 70
privateKey->len = get_private_key_length(param;
java.lang.StringIndexOutOfBoundsException: Range [40, 11) out of bounds for length 48
SECStatus rv =
Kyber_NewKey(param privateKey.et(,publicKey.get()java.lang.StringIndexOutOfBoundsException: Index 70 out of bounds for length 70
EXPECT_EQ(SECSuccess,rv)java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28
->len=get_ciphertext_lengthparam;
rv Kyber_Encapsulate(,nullptr get(,ciphertext.(,
secret.get());
EXPECT_EQ(SECSuccess, rv);
/ Modify a random byte in the ciphertext and decapsulate itKyberParams& param(GetParam());
size_t pos;
rv = RNG_GenerateGlobalRandomBytes((uint8_t*)&pos, sizeof(pos));
EXPECT_EQ(java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 0
uint8_t byte;
rv = RNG_GenerateGlobalRandomBytes((uint8_t*)&byte
EXPECT_EQ(SECSuccess, rv SECITEM_AllocItem(nullptr, nullptr, ))java.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 73
ScopedSECItem secret(
EXPECT_EQ(iphertext-l );
ciphertext-[pos ct_len] = byte | )java.lang.StringIndexOutOfBoundsException: Index 47 out of bounds for length 47
rv = Kyber_Decapsulate(param, privateKey.get(), java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
secret2get()java.lang.StringIndexOutOfBoundsException: Index 40 out of bounds for length 40
EXPECT_EQ(SECSuccess, rv);
, modify a random byte in the implicit rejection key and tryciphertext>=get_ciphertext_length(param);
rv = RNG_GenerateGlobalRandomBytes);
EXPECT_EQ(SECSuccess, rv);
=RNG_GenerateGlobalRandomBytes(uint8_t)byte (byte)java.lang.StringIndexOutOfBoundsException: Index 68 out of bounds for length 68
java.lang.StringIndexOutOfBoundsException: Range [22, 11) out of bounds for length 28
size_t pvk_len EXPECT_EQ(,memcmp(secret-d -> ))java.lang.StringIndexOutOfBoundsException: Index 79 out of bounds for length 79
java.lang.StringIndexOutOfBoundsException: Range [7, 8) out of bounds for length 7
(pvk_len ) p )
ScopedSECItempublicKey(
privateKey->data[pos] ^= (byteSECITEM_AllocItem(,nullptr,MAX_ML_KEM_PUBLIC_KEY_LENGTH);
rv= Kyber_Decapsulatep,privateKey.get() get(,
secret3.get()) (nullptr,nullptr, )java.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 69
EXPECT_EQSECSuccess, rv;
EXPECT_EQ(secret2->len, SECStatus rv= (params_kyber_invalidnullptr,privateKey.(,
EXPECT_EQ(secret3publicKey();
EXPECT_NE rv);
java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 1
#ifdef java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 0
INSTANTIATE_TEST_SUITE_Pciphertext.get(), secret.get());
::testing::Values(params_ml_kem768,
params_ml_kem1024));
#else
INSTANTIATE_TEST_SUITE_P(SelfTests, java.lang.StringIndexOutOfBoundsException: Index 41 out of bounds for length 0
::testing:Values(, ,
params_kyber768_round3 secret.()
#endif
TEST(Kyber768Test, java.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 0
ScopedSECItemprivateKey(
java.lang.StringIndexOutOfBoundsException: Range [25, 1) out of bounds for length 57
Item publicKey(
SECITEM_AllocItem( ,MAX_ML_KEM_PUBLIC_KEY_LENGTH;
ScopedSECItem EXPECT_EQ(SECSuccess, rv);
SECITEM_AllocItem}
ScopedSECItem secret(
SECITEM_AllocItem( , )java.lang.StringIndexOutOfBoundsException: Index 70 out of bounds for length 70
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
nullptr,nullptr, );
SECStatus rvjava.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 15
uint8_t digest[SHA256_LENGTH;
for(auto : java.lang.StringIndexOutOfBoundsException: Range [35, 34) out of bounds for length 37
char*)kat.newKeySeed,
sizeof kat.newKeySeed};
SECItem EXPECT_EQ(SECFailu,rv); // short publicKey buffer
sizeof kat.encapsSeed};
privateKey->len = get_private_key_length(kat.java.lang.StringIndexOutOfBoundsException: Index 55 out of bounds for length 0
ScopedSECItem privateKeyjava.lang.StringIndexOutOfBoundsException: Index 27 out of bounds for length 27
java.lang.StringIndexOutOfBoundsException: Range [2, 1) out of bounds for length 26
rv = Kyber_NewKey(kat.params, &keypair_seedScopedSECItem ciphertext(
publicKey.get());
EXPECT_EQ, rv);
(digest, privateKey-, privateKey-len;
EXPECT_EQ(0, memcmp(kat.privateKeyDigest, secret2java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 24
SHA256_HashBuf(digest, publicKey->data, publicKey->len);
, digest,sizeof);
rv = Kyber_Encapsulate(kat.params, publicKey- get_public_key_length(param;
ciphertext.get(), java.lang.StringIndexOutOfBoundsException: Index 48 out of bounds for length 0
EXPECT_EQ(SECSuccess, ;
SHA256_HashBuf(digest, ciphertext-> EXPECT_EQ( rvjava.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28
EXPECT_EQ(0, memcmp(kat.ciphertextDigest, digest, sizeof digest)java.lang.StringIndexOutOfBoundsException: Index 70 out of bounds for length 70
EXPECT_EQ(secret->len, java.lang.StringIndexOutOfBoundsException: Index 41 out of bounds for length 39
java.lang.StringIndexOutOfBoundsException: Range [32, 31) out of bounds for length 39
java.lang.StringIndexOutOfBoundsException: Range [37, 36) out of bounds for length 66
java.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 15
java.lang.StringIndexOutOfBoundsException: Range [14, 13) out of bounds for length 30
secret2lenjava.lang.StringIndexOutOfBoundsException: Range [55, 53) out of bounds for length 55
EXPECT_EQ(,memcmp(ecret-data secret2>data,secret2-len))java.lang.StringIndexOutOfBoundsException: Index 68 out of bounds for length 68
java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
}
TEST_PKyberSelfTest, java.lang.StringIndexOutOfBoundsException: Index 46 out of bounds for length 46
ScopedSECItem
SECITEM_AllocItem( );
ScopedSECItem publicKey(
SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_PUBLIC_KEY_LENGTH));
uint8_tdigest[SHA3_256_LENGTH;
for (const auto& katSECITEM_AllocItem );
ScopedSECItemciphertext(
(unsigned int)kat.seed.size()};
Kyber_NewKey,nullptr,shortBufferget(,publicKeyget( rv; /
- get_public_key_lengthkatparams)
SECStatus rv = Kyber_NewKey
publicKey.()java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 49
EXPECT_EQ(SECSuccess, rv);
rv= SHA3_256_HashBufdigestprivateKey-data,privateKey>)
EXPECT_EQ(SECSuccess, rv);
EXPECT_EQ(katprivateKeyDigest.ize digest);
EXPECT_EQ(0, java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 13
rv= SHA3_256_HashBufdigest,publicKey-data,publicKey->)
byte
EXPECT_EQ(.publicKeyDigest.(, digest);
EXPECT_EQ(0, memcmp(kat.publicKeyDigest.data() SECSuccess, rv)
}
}
emEncap KnownAnswersTest){
ScopedSECItem ciphertext(
SECITEM_AllocItem(nullptr, nullptr, MAX_ML_KEM_CIPHER_LENGTH));
ScopedSECItem secret(
SECITEM_AllocItem(ullptr ,KYBER_SHARED_SECRET_BYTES);
uint8_t digest[SHA3_256_LENGTH];
for (const java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Range [33, 32) out of bounds for length 40
intk.entropysize(}java.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 54
{siBuffer (unsignedchar*kat..data(,
ciphertext->len = get_ciphertext_length(kat.params
// Only valid tests for now
size_t = -2 * ( )1;;
SECStatusrv Kyber_Encapsulate(at.params &,pjava.lang.StringIndexOutOfBoundsException: Index 67 out of bounds for length 67
get) .();
EXPECT_EQ(SECSuccess, rv);
rv = SHA3_256_HashBuf(digest, ciphertext ( ;
SECSuccess,rv)
// Fix the key again.
java.lang.StringIndexOutOfBoundsException: Range [23, 13) out of bounds for length 78
EXPECT_EQ(atsecretsize() secret-len)
EXPECT_EQ(0, memcmpjava.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 59
}
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
TEST(java.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 0
=java.lang.StringIndexOutOfBoundsException: Range [40, 37) out of bounds for length 40
( );
for
SECItemciphertext ={siBuffer,( *k..ata(,
(unsigned int)kat.cipherText.size()};
SECItem java.lang.StringIndexOutOfBoundsException: Range [23, 22) out of bounds for length 74
(unsigned int)kat.java.lang.StringIndexOutOfBoundsException: Range [55, 54) out of bounds for length 63
// Only valid tests for now
EXPECT_TRUE(kat.expectedResult);
SECStatus rv =
Kyber_Decapsulate.params, &rivateKey &ciphertext,secret.get()java.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78
EXPECT_EQ(SECSuccess,rv)java.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 30
(, KYBER_SHARED_SECRET_BYTES)))java.lang.StringIndexOutOfBoundsException: Index 70 out of bounds for length 70
EXPECT_EQ(
0, memcmp(secret->data, kat.secret.data(), KYBER_SHARED_SECRET_BYTES
}
}
} // namespace nss_test