Skip to content

Issue 75: Fix for DH/ECDH key exchange tests fail on OpenSSL 3.x when salt is not used - #76

Merged
riwoh merged 5 commits into
rdkcentral:mainfrom
seanjin99:fix/hkdf-null-salt-openssl3
Sep 2, 2026
Merged

riwoh merged 5 commits into
rdkcentral:mainfrom
seanjin99:fix/hkdf-null-salt-openssl3

Conversation

@seanjin99

@seanjin99 seanjin99 commented Mar 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Fix 8 DH/ECDH key exchange test failures on OpenSSL 3.x when useSalt=SEC_FALSE.

Problem

The hkdf() function in exchange.cpp passes nullptr to
EVP_PKEY_CTX_set1_hkdf_salt() when no salt is used. OpenSSL 3.x rejects
a NULL pointer even with length 0, causing all testKeyExchangeDH and
testKeyExchangeECDH tests with SEC_FALSE to fail.

Fix

Replace nullptr with "" (empty string) for the no-salt case. This provides
a valid non-NULL pointer with length 0, which both OpenSSL 1.1.x and 3.x accept.
The version-specific #if/#else guard for this call is no longer needed and
has been removed.

Also added descriptive comments to all remaining #if/#else/#endif blocks.

Testing

Verified 8/8 affected tests pass on:

  • OpenSSL 1.1.1w
  • OpenSSL 3.0.15
  • OpenSSL 3.0.18
  • OpenSSL 3.6.1

Fixes #75

Test Results: DH/ECDH Key Exchange (Tests 1193–1207)

Affected Tests

Test # Function Key Type Salt Type
1193 testKeyExchangeDH AES_128 SEC_FALSE DH
1195 testKeyExchangeDH AES_256 SEC_FALSE DH
1197 testKeyExchangeDH HMAC_128 SEC_FALSE DH
1199 testKeyExchangeDH HMAC_256 SEC_FALSE DH
1201 testKeyExchangeECDH AES_128 SEC_FALSE ECDH
1203 testKeyExchangeECDH AES_256 SEC_FALSE ECDH
1205 testKeyExchangeECDH HMAC_128 SEC_FALSE ECDH
1207 testKeyExchangeECDH HMAC_256 SEC_FALSE ECDH

Results Matrix

Without fix (main branch)

Platform OpenSSL Result
macOS (ARM64) 1.1.1w 8/8 passed
macOS (ARM64) 3.0.15 8/8 passed
macOS (ARM64) 3.0.18 0/8 passed
macOS (ARM64) 3.6.1 0/8 passed
ARM32 device 3.0.18 0/8 passed

With fix (PR #76)

Platform OpenSSL Result
macOS (ARM64) 1.1.1w 8/8 passed
macOS (ARM64) 3.0.15 8/8 passed
macOS (ARM64) 3.0.18 8/8 passed
macOS (ARM64) 3.6.1 8/8 passed
ARM32 device 3.0.18 8/8 passed
ARM32 device 3.6.1 8/8 passed

@seanjin99
seanjin99 force-pushed the fix/hkdf-null-salt-openssl3 branch 3 times, most recently from de88a89 to 4e74881 Compare March 6, 2026 21:35
…ests

OpenSSL 3.x rejects a NULL pointer passed to EVP_PKEY_CTX_set1_hkdf_salt()
even with length 0. Use an empty string "" instead of nullptr when
useSalt is false. This works on both OpenSSL 1.1.x and 3.x.

Also added version-guard comments to all #if/#else/#endif blocks for clarity.

Fixes rdkcentral#75
@seanjin99
seanjin99 force-pushed the fix/hkdf-null-salt-openssl3 branch from 4e74881 to 610caf8 Compare March 6, 2026 22:33
Comment thread test/main/cpp/exchange.cpp
@riwoh
riwoh requested a review from mhabrat March 11, 2026 14:10
Copilot AI lite review requested due to automatic review settings April 13, 2026 18:27

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes HKDF salt handling in the OpenSSL-backed hkdf() helper used by DH/ECDH key exchange tests so that the no-salt (useSalt=SEC_FALSE) path works on OpenSSL 3.x.

Changes:

  • Avoid passing a NULL salt pointer to EVP_PKEY_CTX_set1_hkdf_salt() by using an empty string pointer with length 0.
  • Remove the OpenSSL-version conditional around the salt setter call.
  • Update the file copyright header year range.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread test/main/cpp/exchange.cpp
Comment thread test/main/cpp/exchange.cpp
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Copilot AI review requested due to automatic review settings September 2, 2026 22:51

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The change is minimal, localized, and directly addresses the OpenSSL 3.x NULL-salt failure mode without altering the intended salt length semantics.

Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

@riwoh riwoh changed the title Fix/hkdf null salt openssl3 Issue 75: Fix for DH/ECDH key exchange tests fail on OpenSSL 3.x when salt is not used Sep 2, 2026
@riwoh
riwoh merged commit 117e93d into rdkcentral:main Sep 2, 2026
4 checks passed
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 2, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: DH/ECDH key exchange tests fail on OpenSSL 3.x when salt is not used

5 participants